FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] How should an Internet connection/firewall be designed?

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] How should an Internet connection/firewall be designed?
From: Carson Gaspar <carson@taltos.org>
Date: Sat, 20 Jan 2007 11:10:33 -0800
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <45AFCD0E.2000106@corecom.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <B52DBC14D694024689D053F520CCC899040597DC@expf.rl.gov> <45AFCD0E.2000106@corecom.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
User-agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1) Gecko/20061025 Thunderbird/2.0b1pre Mnenhy/0.7.4.0
Dave Piscitello wrote:
> Kaas, David D wrote:
>>
>> How many companies have an IPS/deep-packet-inspection device between the
>> firewall and the border router?
> 
> I honestly don't see a lot of this and unless there's a specific DOS 
> prevention issue, I don't see a lot of point in policing traffic that I 
> expect my firewall to block.

Back when I still did security for a living, I was a supporter of having 
an IDS device between your border router and your external firewall. 
However it was not for the reasons most folks might think. I wanted the 
external IDS in logging-only (no alarms) mode, purely for forensic and 
legal purposes. When we saw something funky on our internal/DMZ nets, we 
could look at the external logs to see if it was part of an attack pattern.

Of course there is a cost/benefit analysis that has to be done to 
determine if the data mining is worth the cost of the device.

I agree that anyone who has alarms enabled from an outside-the-firewall 
IDS probably ought to go see a professional about their paranoia issues...

-- 
Carson
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>