[113262] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?

daemon@ATHENA.MIT.EDU (Roland Dobbins)
Thu Apr 9 12:34:38 2009

From: Roland Dobbins <rdobbins@cisco.com>
To: NANOG list <nanog@nanog.org>
In-Reply-To: <084962C061414240A0CDB4BE328A9B2D119F91724A@GVW1100EXC.americas.hpqcorp.net>
Date: Fri, 10 Apr 2009 00:20:13 +0800
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Apr 9, 2009, at 11:48 PM, Lee, Steven (NSG Malaysia) wrote:

> Please share your thought and thanks in advance :)

No, IMHO.  Most broadband operators don't insert firewalls inline in  
front of their subscribers, and wireless broadband is no different.

The infrastructure itself must be protected via iACLs, the various  
vendor-specific control-plane protection mechanisms, and so forth, but  
inserting additional state in the middle of everything doesn't buy  
anything, and introduces additional constraints and concerns.

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@cisco.com> // +852.9133.2844 mobile

   Our dreams are still big; it's just the future that got small.

		   -- Jason Scott



home help back first fref pref prev next nref lref last post