[113215] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: ACLs vs. full firewalls

daemon@ATHENA.MIT.EDU (Karl Auer)
Tue Apr 7 19:22:46 2009

From: Karl Auer <kauer@biplane.com.au>
To: nanog@nanog.org
In-Reply-To: <49AE5A03-3EC8-46CE-84C0-CC1C2369AE6E@daork.net>
Date: Wed, 08 Apr 2009 09:20:34 +1000
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


--=-M9W2QRO3SmnvO5lt444A
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Wed, 2009-04-08 at 10:46 +1200, Nathan Ward wrote:
> > I'd be interested to hear why people use firewalls.

> End hosts are not always trustworthy.
>=20
> If a host is compromised, should it be able to send anything and =20
> everything out to the public network?

A packet filter looks at the "top surface" of the packet, and processes
the packet accordingly - based on things like the protocol, the source
address, the destination address, the TCP flags and so on.

A firewall, on the other hand, makes decisions based on knowledge about
the data being carried.

I.e., firewall !=3D packet filter; my question related to firewalls.

Regards, K.

--=20
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Karl Auer (kauer@biplane.com.au)                   +61-2-64957160 (h)
http://www.biplane.com.au/~kauer/                  +61-428-957160 (mob)

GPG fingerprint: 07F3 1DF9 9D45 8BCD 7DD5 00CE 4A44 6A03 F43A 7DEF

--=-M9W2QRO3SmnvO5lt444A
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQBJ29/CSkRqA/Q6fe8RAir+AKC4XCHvPJ5FSAoyaxz+362W0ec1igCdFjBH
rFbfkoxkI7A7xnOvWxHnXxg=
=WcuK
-----END PGP SIGNATURE-----

--=-M9W2QRO3SmnvO5lt444A--



home help back first fref pref prev next nref lref last post