nanog mailing list archives
Re: Dynamic routing on firewalls.
From: Rich Kulawiec <rsk () gsp org>
Date: Mon, 9 Feb 2015 03:59:52 -0500
On Sun, Feb 08, 2015 at 11:40:56AM -0200, BPNoC Group wrote:
Firewalls are firewalls. Routers are routers. Routers should do some very basic filtering (stateles, ACLs, data plane protection...) and firewalls should do basic static routing. And things should not go far beyond that.
This is, at a network level, an echo of the "Software Tools" philosophy that has served us exceedingly well for decades. Tools should do one thing, they should do it well, and if/when we need to do more than one thing, we should use tools in combination. There's another advantage to this: if firewalls and routers &etc are not the same system, then they can run different software on different operating systems on different architectures -- providing a significant measure of insulation against attacks unique to one particular combination. ---rsk
Current thread:
- Re: Dynamic routing on firewalls., (continued)
- Re: Dynamic routing on firewalls. Owen DeLong (Feb 05)
- Re: Dynamic routing on firewalls. Joe Hamelin (Feb 05)
- Re: Dynamic routing on firewalls. Jeff McAdams (Feb 05)
- Re: Dynamic routing on firewalls. Bill Thompson (Feb 06)
- Re: Dynamic routing on firewalls. Doug Barton (Feb 06)
- Re: Dynamic routing on firewalls. Owen DeLong (Feb 07)
- Re: Dynamic routing on firewalls. BPNoC Group (Feb 08)
- Re: Dynamic routing on firewalls. Jeff McAdams (Feb 08)
- Re: Dynamic routing on firewalls. BPNoC Group (Feb 08)
- Re: Dynamic routing on firewalls. Owen DeLong (Feb 08)
- Re: Dynamic routing on firewalls. Rich Kulawiec (Feb 09)
- Re: Dynamic routing on firewalls. Eugeniu Patrascu (Feb 09)
- Re: Dynamic routing on firewalls. Owen DeLong (Feb 05)
- Re: Dynamic routing on firewalls. Patrick Tracanelli (Feb 08)
- Re: Dynamic routing on firewalls. Owen DeLong (Feb 08)
- Re: Dynamic routing on firewalls. Patrick Tracanelli (Feb 09)
- Re: Dynamic routing on firewalls. Valdis . Kletnieks (Feb 09)
- Re: Dynamic routing on firewalls. Patrick Tracanelli (Feb 09)
- Re: Dynamic routing on firewalls. Valdis . Kletnieks (Feb 09)
- Re: Dynamic routing on firewalls. Patrick Tracanelli (Feb 09)