I don't need no stinking firewall!

harbor235 harbor235 at gmail.com
Sat Jan 9 16:51:21 CST 2010

I think we are over looking what an enterprise class firewall accomplishes
from a security perspective and what a firewalls function is in the overall
security posture of a network.

First, statefull inspection by itself is not the only security feature of a
firewall, it is one security feature of a firewall. Couple that with other
security features and now you have a security device.

Other security features in an Enterprise Class firewall;
    -Inside source based NAT, reinforces secure traffic flow by allowing
outside to inside flows based on
        configured translations and allowed security policies
    -TCP sequence number randomization (to prevent TCP seq number guessing)
    -Intrusion Detection and Prevention (subset of most common signatures)
        recognize scanning attempts and mitigate
        recognize common attacks and mitigate
    -Deep packet inspection (application aware inspection for common network
    - Policy based tools for custom traffic classification and filtering
    -Layer 3 segmentation (creates inspection and enforcement points)
    -Full/Partial Proxy services with authentication
    - Alarm/Logging capabilities providing info on potential attacks
    -etc ......

Statefull inspection further enhances the security capabilities of a
firewall. Another point is
that a firewall by itself is not security, "Defense in Depth" means that
every node on the network has it's
role in the overall security architecture, no one or two devices is security
in itself.

You may choose not to use a firewall or implement a sound security posture
utilizing the "Defense in Depth" philosophy, however you chances of being
compromised are dramatically increased. So, I would be more interested in
implementing a sound security architecture than whether or not a firewall
provides security to my networks.

my two cents,


On Fri, Jan 8, 2010 at 11:18 PM, Joel Jaeggli <joelja at bogus.com> wrote:

