Great Circle Associates Firewalls
(February 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: B1 Firewall ?
From: Frank Wortner <frank @ prodigy . com>
Date: Wed, 22 Feb 1995 09:24:21 -0500 (EST)
To: firewalls @ greatcircle . com
In-reply-to: <9502220355 . AA14374 @ tis . com>

On Tue, 21 Feb 1995, Marcus J Ranum wrote:

> 	Really, you're right - a guard is a kind of firewall, where
> "firewall" is loosely defined: "a system or set of systems that
> implement access controls across a trust boundary." [my current
> favorite definition] But when someone asks for a "firewall" between
> his classified net and his SBU net he is not talking about the
> same kind of critter most of us are when we say "firewall"  :)

Too many people seem to have the idea that a firewall will protect a 
network against external threat.  IMHO, the only true protection is the 
system known as the AirGap (tm).  "Firewall" is a bad name, in the sense 
that it actually punches *controlled holes* through the boundary.  The 
user is trading some level of risk for some level of convenience.  So 
long as the risk is small, and the convenience relatively great, the 
tradeoff is worth making, but it's still a tradeoff.

Anyone considering or building a firewall should have that outlook.  
Any path that connects to the "outside world" is a risk, but is the risk 
worth taking?

'Nuf said;  I'm going back to work formatting floppy diskettes for 
management now.  :-)

					Frank

--
"Outside of a dog, a book is a man's best friend;
 inside of a dog, it's too dark to read."  -- Groucho Marx



References:
Indexed By Date Previous: Passwords
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Next: Re: Randon password generators (fwd)
From: William Gianopoulos {84718} <wag @ swl . msd . ray . com>
Indexed By Thread Previous: Re: B1 Firewall ?
From: Marcus J Ranum <mjr @ tis . com>
Next: Re: B1 Firewall ?
From: rmck @ sandfiddler . paragon-systems . com (Bob McKisson)

Google
 
Search Internet Search www.greatcircle.com