[113378] in North American Network Operators' Group
Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?
daemon@ATHENA.MIT.EDU (Eugeniu Patrascu)
Fri Apr 10 12:29:39 2009
Date: Fri, 10 Apr 2009 19:27:19 +0300
From: Eugeniu Patrascu <eugen@imacandi.net>
To: Roland Dobbins <rdobbins@cisco.com>
In-Reply-To: <21D1384B-36D7-4A21-A4D0-FE077437C754@cisco.com>
Cc: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Roland Dobbins wrote:
>
> On Apr 9, 2009, at 11:48 PM, Lee, Steven (NSG Malaysia) wrote:
>
>> Please share your thought and thanks in advance :)
>
> No, IMHO. Most broadband operators don't insert firewalls inline in
> front of their subscribers, and wireless broadband is no different.
Some operators put firewalls to NAT their subscribers into smaller IP
address pools (I have put some for a particular one).
>
> The infrastructure itself must be protected via iACLs, the various
> vendor-specific control-plane protection mechanisms, and so forth, but
> inserting additional state in the middle of everything doesn't buy
> anything, and introduces additional constraints and concerns.
>
Yes.