Firewall Wizards mailing list archives
Re: Firewall Primitives
From: Crispin Cowan <crispin () wirex com>
Date: Tue, 05 Nov 2002 21:55:28 -0800
George Capehart wrote:
As I was taught, "switch" ::= "level 3" and "router" ::= "level 4". Firewalls are "whatever freakin' level you like" (see my previous rant on "intrusion prevention is really firewalls in drag" <http://lists.insecure.org/firewall-wizards/2002/Aug/0137.html>) so it amounts to the same thing.Crispin Cowan wrote:George Capehart wrote:This is interesting. So, a firewall really should/could/might be a multi-layer, multi-protocol switch . . .But of course. That's all firewalls ever were, but marketing hates it when people discover that :)Doh! OK, I'll buy that. I'd really (in my own way) seen firewalls as being more like band-pass filters. But that's probably another discussion. When I wrote "switch" I was really thinking "router." :/g/switch/s//router/g
And from a security or functionality perspective, why would we care about the difference?It really did seem that he was suggesting that the firewall actually actively route, as opposed to "look at the packet and drop it if it doesn't like it . . ." ;-]
The "routing" function I had in mind was for "service networks", i.e. DMZ's as served off a firewall with 3 NICs.So, I really meant to use the term router. That is a step beyond the "throw it in the bit bucket if I don't like it" function
Crispin -- Crispin Cowan, Ph.D. Chief Scientist, WireX http://wirex.com/~crispin/ Security Hardened Linux Distribution: http://immunix.org Available for purchase: http://wirex.com/Products/Immunix/purchase.html Just say ".Nyet"
Attachment:
_bin
Description:
Current thread:
- Firewall Primitives Cat Okita (Nov 01)
- Message not available
- Re: Firewall Primitives Marcus J. Ranum (Nov 04)
- Re: Firewall Primitives George Capehart (Nov 04)
- Re: Firewall Primitives Victoria of Borg (Nov 05)
- Re: Firewall Primitives Magosányi Árpád (Nov 05)
- Re: Firewall Primitives Crispin Cowan (Nov 05)
- Re: Firewall Primitives George Capehart (Nov 05)
- Re: Firewall Primitives Crispin Cowan (Nov 06)
- Re: Firewall Primitives Marcus J. Ranum (Nov 06)
- Re: Firewall Primitives Devdas Bhagat (Nov 06)
- Re: Firewall Primitives Marcus J. Ranum (Nov 06)
- Re: Firewall Primitives Devdas Bhagat (Nov 07)
- Re: Firewall Primitives Adam Shostack (Nov 09)
- BS claims (was Re: Firewall Primitives) Marcus J. Ranum (Nov 09)
- Re: Firewall Primitives Marcus J. Ranum (Nov 04)
- Re: Firewall Primitives Mikael Olsson (Nov 09)
- Re: Firewall Primitives Marcus J. Ranum (Nov 09)
- Re: Firewall Primitives Christopher Hicks (Nov 10)
- Re: Firewall Primitives Predrag Zivic (Nov 10)
- Message not available