nanog mailing list archives

Re: I don't need no stinking firewall!


From: Joe Maimon <jmaimon () ttec com>
Date: Thu, 14 Jan 2010 12:13:07 -0500



Dobbins, Roland wrote:

On Jan 10, 2010, at 1:22 PM, harbor235 wrote:

Again, a firewall has it's place just like any other device in the network, defense in>>>  depth is a prudent philosophy to 
reduce the chances of compromise, it does not>>>eliminate it nor does any architecture you can think of, period

What a ridiculous statement - of course it does.

*The place of the stateful firewall is in front of clients, not servers*.


Servers can also be clients who can benefit from state tracking.

The best answer I have to that scenario is to make the client path different than the server path.

Joe


Current thread: