[113215] in North American Network Operators' Group
Re: ACLs vs. full firewalls
daemon@ATHENA.MIT.EDU (Karl Auer)
Tue Apr 7 19:22:46 2009
From: Karl Auer <kauer@biplane.com.au>
To: nanog@nanog.org
In-Reply-To: <49AE5A03-3EC8-46CE-84C0-CC1C2369AE6E@daork.net>
Date: Wed, 08 Apr 2009 09:20:34 +1000
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
--=-M9W2QRO3SmnvO5lt444A
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable
On Wed, 2009-04-08 at 10:46 +1200, Nathan Ward wrote:
> > I'd be interested to hear why people use firewalls.
> End hosts are not always trustworthy.
>=20
> If a host is compromised, should it be able to send anything and =20
> everything out to the public network?
A packet filter looks at the "top surface" of the packet, and processes
the packet accordingly - based on things like the protocol, the source
address, the destination address, the TCP flags and so on.
A firewall, on the other hand, makes decisions based on knowledge about
the data being carried.
I.e., firewall !=3D packet filter; my question related to firewalls.
Regards, K.
--=20
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Karl Auer (kauer@biplane.com.au) +61-2-64957160 (h)
http://www.biplane.com.au/~kauer/ +61-428-957160 (mob)
GPG fingerprint: 07F3 1DF9 9D45 8BCD 7DD5 00CE 4A44 6A03 F43A 7DEF
--=-M9W2QRO3SmnvO5lt444A
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQBJ29/CSkRqA/Q6fe8RAir+AKC4XCHvPJ5FSAoyaxz+362W0ec1igCdFjBH
rFbfkoxkI7A7xnOvWxHnXxg=
=WcuK
-----END PGP SIGNATURE-----
--=-M9W2QRO3SmnvO5lt444A--