[113349] in North American Network Operators' Group
RE: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?
daemon@ATHENA.MIT.EDU (Lee, Steven (NSG Malaysia))
Thu Apr 9 23:07:36 2009
From: "Lee, Steven (NSG Malaysia)" <kin-wei.lee@hp.com>
To: Charles Wyble <charles@thewybles.com>, Skywing
<Skywing@valhallalegends.com>
Date: Fri, 10 Apr 2009 02:57:49 +0000
In-Reply-To: <49DE7201.4070509@thewybles.com>
Cc: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Hi Charles/Skywing, is Verizon filter the unsolicated inbound traffic on th=
e firewall or on the border router?
Regards,
Steven Lee=20
-----Original Message-----
From: Charles Wyble [mailto:charles@thewybles.com]=20
Sent: Friday, April 10, 2009 6:09 AM
To: Skywing
Cc: NANOG list
Subject: Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?
Yep verizon does indeed filter all unsolicated inbound traffic to the=20
EVDO network. It can be a blessing or a curse. :)
Skywing wrote:
> Verizon filters unsolicited inbound traffic for their EVDO customers in m=
y experience.
>=20
> - S
>=20
> -----Original Message-----
> From: Roland Dobbins <rdobbins@cisco.com>
> Sent: Thursday, April 09, 2009 09:32
> To: NANOG list <nanog@nanog.org>
> Subject: Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?
>=20
>=20
> On Apr 9, 2009, at 11:48 PM, Lee, Steven (NSG Malaysia) wrote:
>=20
>> Please share your thought and thanks in advance :)
>=20
> No, IMHO. Most broadband operators don't insert firewalls inline in
> front of their subscribers, and wireless broadband is no different.
>=20
> The infrastructure itself must be protected via iACLs, the various
> vendor-specific control-plane protection mechanisms, and so forth, but
> inserting additional state in the middle of everything doesn't buy
> anything, and introduces additional constraints and concerns.
>=20
> -----------------------------------------------------------------------
> Roland Dobbins <rdobbins@cisco.com> // +852.9133.2844 mobile
>=20
> Our dreams are still big; it's just the future that got small.
>=20
> -- Jason Scott
>=20
>=20
>=20