[113266] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?

daemon@ATHENA.MIT.EDU (Roland Dobbins)
Thu Apr 9 13:00:34 2009

From: Roland Dobbins <rdobbins@cisco.com>
To: NANOG list <nanog@nanog.org>
In-Reply-To: <200904091721.39555.alexander.harrowell@stlpartners.com>
Date: Fri, 10 Apr 2009 00:48:34 +0800
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Apr 10, 2009, at 12:21 AM, Alexander Harrowell wrote:

> I would think that, however you are providing IP addresses, any  
> ingress point
> to a GSM core network ought to be carefully policed on security  
> grounds.

Sure.  But stateful firewalls aren't required to protect that  
infrastructure, stateless ACLs in hardware will work quite well.

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@cisco.com> // +852.9133.2844 mobile

   Our dreams are still big; it's just the future that got small.

		   -- Jason Scott



home help back first fref pref prev next nref lref last post