nanog mailing list archives

Re: Requirements for IPv6 Firewalls


From: "Dobbins, Roland" <rdobbins () arbor net>
Date: Sat, 19 Apr 2014 02:10:45 +0000


On Apr 19, 2014, at 9:04 AM, Jeff Kell <jeff-kell () utc edu> wrote:

It's how we provide access control.

Firewalls <> 'access control'.

Firewalls are one (generally, very poor and grossly misused) way of providing access control.  They're often wedged in 
where stateless ACLs in hardware-based routers and/or layer-3 switches would do a much better job, such as in front of 
servers:

<https://app.box.com/s/a3oqqlgwe15j8svojvzl>

-----------------------------------------------------------------------
Roland Dobbins <rdobbins () arbor net> // <http://www.arbornetworks.com>

          Luck is the residue of opportunity and design.

                       -- John Milton



Current thread: