nanog mailing list archives

Re: I don't need no stinking firewall!


From: Rich Kulawiec <rsk () gsp org>
Date: Tue, 5 Jan 2010 21:20:31 -0500


A firewall is another layer in a defense-in-depth strategy, but tends
to only be truly effective if the first rule in it is

        deny all from any to any

which of course does not happen much of the time in the real world,
with predictable results.

Moreover, stateful packet inspection is not the end-all be-all: there's
a lot to be said for application-level proxying, and for quasi-realtime
traffic analysis.

I think of my firewalls as tools which reduce the overwhelming flood
of malicious and garbage traffic to a trickle -- which does not necessarily
reduce the attack surface or the threats to it, but may at least allow
me a better chance of seeing the threats and doing something useful
about them.

---Rsk


Current thread: