[120845] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: D/DoS mitigation hardware/software needed.

daemon@ATHENA.MIT.EDU (Dobbins, Roland)
Tue Jan 5 05:18:12 2010

From: "Dobbins, Roland" <rdobbins@arbor.net>
To: NANOG list <nanog@nanog.org>
Date: Tue, 5 Jan 2010 10:13:32 +0000
In-Reply-To: <5a318d411001050204w3b5f55a4q90c4062773c826c1@mail.gmail.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Jan 5, 2010, at 5:04 PM, Darren Bolding wrote:

> To reiterate- my entire point is that stateful firewalls are at least som=
etimes useful in front of large websites.=20

I understand completely; I simply disagree, stating my reasons for doing so=
 in detail inline.  It's my contention that under no circumstances are stat=
eful firewalls *ever* useful in front of *any* Web server, at *any* time, i=
n *any* deployment scenario, either public or private. =20

;>

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>

    Injustice is relatively easy to bear; what stings is justice.

                        -- H.L. Mencken





home help back first fref pref prev next nref lref last post