Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Point of no gain
From: "Marcus J. Ranum" <mjr @ clark . net>
Organization: V-One Corporation, Baltimore, MD Office
Date: Mon, 25 Mar 1996 17:56:03 -0500 (EST)
To: firewalls @ GreatCircle . COM
In-reply-to: <199603250900 . BAA05357 @ miles . greatcircle . com> from "owner-firewalls-digest @ uunet . uu . net" at Mar 25, 96 01:00:34 am
Phone: 410-889-8569
Reply-to: mjr @ v-one . com

>At what point does the number of users inside of a perimeter become so
>large that inside of the firewall becomes virtually indistinguishable 
>from outside of the firewall?  1,000 users?  10,000 users? 100,000
>users?  Is this point real or just imaginary?

	My take is it's less a matter of number of users than
it is number of network interconnects. Offhand, the problem is
one of those: "if you have to ask, you already know the answer"
kind of deals.
	Intranetwork firewalls are becoming a hot topic, and 
I worry that they won't be deployed sensibly, since most networks
are presently designed to be a single security domain with
no internal separation.
	If I were to tackle the problem, I'd say you need to
divide your users and their desktops up into the different
roles they play, sort the roles into security domains, then
develop access policies for controlling communication between
each domain. Those policies would be implemented with a
combination of routers, firewalls, virtual LANs and hubs,
or whatever. I actually have a short tutorial on how to
do this kind of analysis that I have been working on for
some time, but it's not quite good enough yet -- and every
time I present the concept people's response is invariably,
"reorganizing my network would take too much work!!"

mjr.


Follow-Ups:
Indexed By Date Previous: Re: DOS firewalls
From: "Marcus J. Ranum" <mjr @ clark . net>
Next: Re: Tired of the sick puppy defense
From: Mark Clayton <markc @ mentor . co . nz>
Indexed By Thread Previous: Re: What talks on port 113?
From: XINCLXFirewalls-ml @ scet . org . uk (Firewalls-ml Conference @ scet.org.uk)
Next: Re: Point of no gain
From: sedayao @ argus . intel . com (Jeffrey C. Sedayao)

Google
 
Search Internet Search www.greatcircle.com