Firewall Wizards mailing list archives
Air Gap VS. Firewall
From: Campbell Family <home () campbell-fam com>
Date: Sun, 24 Sep 2000 19:07:59 -0500
Lo All - There seems to be a battle of definition going on about the differences between air-gap devices and firewalls. The purpose of the firewall, whether it be software or an appliance is pretty well known. We could go on all day about the different types and how they work. An aip-gap device is not actually much different by definition. The difference as it has been explained to me is in their application. The air-gap was originally introduced to me not as a replacement for a firewall . . . but, a device that has a different purpose. An air-gap is supposed to imperceptibly disconnect and reconnect trusted and untrusted networks for the purpose of transfer of data on known secure IP sessions. (Bear with me - I read the bulk of this from some security rag I cannot locate for reference.) For example: A web server transacts a ton of data on a local database table during a fixed period of time. At some defined moment the web server intends to checkpoint the data to another database on a secure network. The web server is connected to an air-gap device. When the web server attempts to open the TCP connection to the database to which it is to checkpoint, the air-gap device disconnects the web server from the external "untrusted" network and connects it to the "trusted" network where the other database server is located. Once the TCP session closes the disconnection/reconnection process is reversed. It was my understanding that the process was to occur without any perceptible change in network connectivity which the hosts would see ( other than a lack of connections in one direction or another for the period of connection/disconnection ). My question to the group is, "Is there any real benefit to this kind of operation?". Comments, questions, laughter . . . ??? bbc () un1x com _______________________________________________ Firewall-wizards mailing list Firewall-wizards () nfr net http://www.nfr.net/mailman/listinfo/firewall-wizards
Current thread:
- Air Gap vs. firewall a burbatsky (Sep 22)
- Re: Air Gap vs. firewall Marcus J. Ranum (Sep 22)
- Re: Air Gap vs. firewall Crispin Cowan (Sep 23)
- RE: Air Gap vs. firewall Ofir Arkin (Sep 23)
- Re: Air Gap vs. firewall Joseph S D Yao (Sep 23)
- <Possible follow-ups>
- Re: Air Gap vs. firewall Steven M. Bellovin (Sep 23)
- RE: Air Gap vs. firewall David Bovee (Sep 23)
- Air Gap VS. Firewall Campbell Family (Sep 25)
- Re: Air Gap VS. Firewall Crispin Cowan (Sep 26)
- Re: Air Gap VS. Firewall Marcus J. Ranum (Sep 26)
- Re: Air Gap VS. Firewall Crispin Cowan (Sep 26)
- RE: Air Gap VS. Firewall Paz (Sep 26)