[113212] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: ACLs vs. full firewalls

daemon@ATHENA.MIT.EDU (Michael Helmeste)
Tue Apr 7 18:31:34 2009

Date: Tue, 07 Apr 2009 15:29:27 -0700
From: Michael Helmeste <mhelmest@uvic.ca>
To: Eric Gauthier <eric@roxanne.org>
In-Reply-To: <20090407211806.GA31462@roxanne.org>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

While there are no specific audit requirements, overall traffic auditing
(not just for dropped packets) is definitely something I'm considering.
One way of gathering this data without using a firewall would seem to be
netflow; I don't think netflow specifically calls out (or even shows?)
traffic blocked by ACLs though, which could be a point for consideration.

Eric Gauthier wrote:
> Michael,
> 
> Do you have logging or audit requirements to your filters?
> We use ACLs almost everywhere for non-stateful filtering, but
> there are a few locations (e.g. HIPPA) that require an 
> audit trail which is perhaps better accomplished by a firewall.
> 
> Eric :)
> [...]


home help back first fref pref prev next nref lref last post