Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: reaching diminishing returns on firewalls - when?
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Date: Wed, 27 Mar 1996 14:01:49 -0500 (EST)
To: "Jeffrey C. Sedayao" <sedayao @ argus . intel . com>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <199603250732 . XAA17259 @ argus . intel . com>

On Sun, 24 Mar 1996, Jeffrey C. Sedayao wrote:

> Folks,
> 
> I remember this being discussed before, but I don't recall seeing any
> actually numbers of users being tossed out.  My question is this:
> 
> At what point does the number of users inside of a perimeter become so
> large that inside of the firewall becomes virtually indistinguishable 
> from outside of the firewall?  1,000 users?  10,000 users? 100,000
> users?  Is this point real or just imaginary?
> 
The answer is, of course, "it depends."

At what point are the assets going to require protection from others, 
even if the "others" are also members of the same organization?

Sounds like you need to determine of "security containers" are required, 
and if host-based security to enforce these containers will be enough. If 
you need more than host-based security, a firewall between internal 
partitions may be what you need. It isn't a "numbers" problem - even a 
thirty person company, with 10 users working on "project X" may need a 
firewall to keep the other 20 employees out.

Just my $.02

-r.w.
 


References:
Indexed By Date Previous: Re: Redundant Internet Connections
From: Bill Stout <bstout @ osc . hitachi . com>
Next: Re[2]: POINTCAST - Could it be a Trojan Hor
From: Messages_Roswell @ oxy . com (Messages Roswell)
Indexed By Thread Previous: Re: reaching diminishing returns on firewalls - when?
From: mdr @ vodka . sse . att . com
Next: Filtering ICMP packets ?
From: netmgt @ cnca . credit-agricole . fr (netmgt)

Google
 
Search Internet Search www.greatcircle.com