Oh puhleeze, peddle the old time religion somewhere else.
With respect, you dont know what the term means. From an operational risk perspective it is far preferable for an organisation to manage something it knows how to do properly than to attempt to manage something it knows little or nothing about. The potential risk of loss is a lot smaller.
You haven't answered the question.
Show me the free out of the box pf/ipfw/netfilter solution which can filter soap, xml & rpc. Pointing to an unsupportable netfilter hack someone has posted on sourceforge doesnt cut the mustard in an enterprise environment.
BWAHAHAHA! Oh Jesus wept... Shorewall .... Look do yourself a favour, I'll give you some hints Cisco Security Manager, Checkpoint Provider-1, Netscreen Security Manager just to name 3. Your lack of knowledge on the topic is just too embarrasing for words.
You dont comprehend the change management constraints which enterprises operate under.
The notion that risk management in any large organsiation would even contemplate permitting the roll of out netfilter 'helper' modules across a global network to selectively filter SOAP & RPC is hilarious.
Never mind rolling out hacks which run application layer filtering in kernel space.
Oh gawd. Open your eyes puhleeze. Crisco, Checkpoint and Netscreen can and do fixup 323 and other voip protocols.
Of course you did, you insisted
"BSD+ipfw/pf or Linux+netfilter would be the best choice, for obvious reasons."
without having any idea of what the client requirements were.
Again you make authoritiative claims without having a clue of the real world capabilities of the products in the market place. In the real world, there are 3 main players, Crisco, Juniper and & Checkpoint. They all provide L7 filtering in various forms.
The notion that
"*most* L7 protocol filtering is done using proxy firewalls"
is arrant nonsense.
ridiculously irrelevant. Show me a 1 meg LFS floppy disk with support for say OSPF, BGP, sparse PIM which can dynamically route several hundred market data feeds delivered though trunks running into a Cat 6509.
By that reasoning the same fallacious 'point' would apply to Splat Pro or Solaris.
Windows Server is *not* hard to secure. Whether you choose to believe that is not my problem.
You dont, it's painfully obvious that your exposure to anything other than soho solutions to security infrastructure delivery is extremely limited.
greg