Great Circle Associates Firewalls
(January 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewalls-Digest V5 #51
From: mdr @ vodka . sse . att . com
Date: Tue, 23 Jan 1996 09:03:16 -0500 (EST)
To: dannyc @ gmap . leeds . ac . uk (Danny Cox)
Cc: firewalls @ greatcircle . com
In-reply-to: <10329 . 9601231017 @ gmap . leeds . ac . uk> from "Danny Cox" at Jan 23, 96 10:17:53 am

Danny writes:
> Interesting this .. is this the future as it's seen? That firewalls will become
> redundant technology ?  I'd better not setup as a purely firewall consultant
> then :)  Seriously, has anyone any further thoughts on this?  Will firewalls
> become redundant ?  And if so, how long d'you reckon it'll be before they are?
> 

An intersesting point to discuss.  Trying to mediate policy at the
host level is really completely unmanageable.  Each host would have to
manage complete lists of every other host to which they wish to
communicate.  That encourages people to open up their host to
everybody.  How would a security officer determine that all 10,000
hosts at his site are correctly configured?   

The notion of a "firewall" will definitely shift, but for the *better* 
as time goes on.  We need a mediator to determine what types of connections 
are allowable.  Adding better authentication at the end points makes 
firewalls *more* desirable, because now a single point of entry can 
enforce a policy based on better knowlege about the endpoints.   Encryption,
data stream integrity, and strong authentication will definitely have 
an impact on the definition of what a firewall is.  

Mark Riggins
Secure Systems Engineering
AT&T Bell Labs



References:
Indexed By Date Previous: re: Fault Tolerant Firewall
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Next: RE: remive me!
From: jwojn @ telxon . mis . telxon . com (Wojno, Jim)
Indexed By Thread Previous: Re: Firewalls-Digest V5 #51
From: Danny Cox <dannyc @ gmap . leeds . ac . uk>
Next: Re: Firewalls-Digest V5 #51
From: David Loysen <dwl @ hnc . com>

Google
 
Search Internet Search www.greatcircle.com