Firewall Wizards mailing list archives

Re: segmentation of DMZs


From: Carson Gaspar <carson () taltos org>
Date: Sun, 17 Nov 2002 00:35:34 -0500



--On Sunday, November 17, 2002 12:56 AM +0100 Mikael Olsson <mikael.olsson () clavister com> wrote:

High operational / debugging complexity

Why? All of a sudden I can even get logs of all connections opening
and closing, which I couldn't easily get before.  I can even do
monitoring and alerting when connections that I expect to happen
suddenly _aren't_ happening between two boxes!

True, if you run all of (Network, Hosts, Firewalls). If 3 (or more) different groups run them, it becomes nasty - fingerpointing fiesta. Also, any complex config has a larger chance of bit rot as change management happens, especially with staff turnover.

--
Carson

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: