[113266] in North American Network Operators' Group
Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?
daemon@ATHENA.MIT.EDU (Roland Dobbins)
Thu Apr 9 13:00:34 2009
From: Roland Dobbins <rdobbins@cisco.com>
To: NANOG list <nanog@nanog.org>
In-Reply-To: <200904091721.39555.alexander.harrowell@stlpartners.com>
Date: Fri, 10 Apr 2009 00:48:34 +0800
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Apr 10, 2009, at 12:21 AM, Alexander Harrowell wrote:
> I would think that, however you are providing IP addresses, any
> ingress point
> to a GSM core network ought to be carefully policed on security
> grounds.
Sure. But stateful firewalls aren't required to protect that
infrastructure, stateless ACLs in hardware will work quite well.
-----------------------------------------------------------------------
Roland Dobbins <rdobbins@cisco.com> // +852.9133.2844 mobile
Our dreams are still big; it's just the future that got small.
-- Jason Scott