Why you have hardware firewalls

Apr 05, 2005 75 Replies

But any good firewall setup doesn't just block by IP, it considers the business needs and blocks everything else. As such, you don't give access to the world, which means people don't have access to proxy servers to bounce through. It's "Child's Play" to prevent people from using external proxy servers - since you shouldn't be allowing outbound access except to approved sites.

If you really think that white/black list, along with content filtering and real firewalls don't have a LOT to do with security, then you don't really understand security. Security starts at the border and then internal.

Cutting the cable is not security, that is only suggested by asinine people that try and make a point about something they don't understand.

You need to get over this idea that businesses need to provide full and unrestricted access to employees at work.

Just read an article where managers were spending an average of 56 minutes per day doing non-business related things on the Internet when they were using a unrestricted Internet connection - guess who pays for that 56 average minutes?

I've still not seen anyone post a valid reason to give unrestricted access to ALL employees in any business.

And, again, if you are not permitted access to those proxies from your company network then it doesn't mean a hill of beans. So, in a properly configured firewall solution, you don't have access to proxy servers (let alone any non-business sites), so you don't have to worry about your employees accessing anything you've mentioned.

Security is about controlling access and content - if you control access to sites, then you are concerned with security. If you block access to sites that are not needed, then you gain security. You should understand this as it will make your life easier once you get a job where security is important.

Suggest away, when you understand you may get it right. Real firewalls come in many forms, but they are all firewalls. I can secure a network using a Dedicated server with FW1 on it, with a number of open-source products, or with an Appliance. I can not secure a network with just a simple NAT device nor with a personal firewall application running on a users workstation.

Since you don't understand, it's clear that you don't see the benefits - but I really suspect that you just don't want to see it.

Limiting access is about security, the means to limit access is not important as it's the limiting that is important.

If I limit access outbound to 1 HTTP site, say a partners website, it also limits the ability of lamers to connect to proxy services in the public, which limits what they can do from their workstations, which limits exposure of the network, which limits security risks - understand now.

If you're requesting whitelist filtering, why not talking about "security", when the cable is cut with a knife?

It's completely ridiculous, what you're writing here, sorry.

Please let's get back talking about serious security issues, and not about building up private networks and so being "secure" against the Internet, because there is no Internet connection at all.

Otherwise, we could talk about security issues you have inside your private networks.

Yours, VB.

I don't have to detect a proxy, if you can't reach your proxy sites you can't use them - did you miss that? If you can't reach one of your precious sites, due to filtering, you can't use it can you?

I don't have to, based on you not being able to proxy out, you can't do anything I need to worry about - get it now?

How old are you? You said that "limiting access" is not the same as giving up connectivity and you don't see that it's the same?

It's obvious to me that you're trolling, as no-one could be this blind, so I'm done with you until you stop the word-games.

Let's see if I can explain this in simple terms for you:

1) I setup white and black lists in addition to content filters and category filtering of sites. 2) You try and access a site that is not on the white list, not in a black list, not in the category list - you don't get to it. 3) Since you can't get to the site, it's blocked. 4) You can't reach it because our security infrastructure does not permit access to the site - hence the blocking of it.

Now, lets say I don't use a white/black list, but I implement a category of content list and approve 3 of 60 categories for use. Since your proxy service is not in the 3, you still can't access them, so you are blocked again - you would also notice a messages on your browser that states "site BLOCKED by firewall content rules"

Since I'm starting to see you as a troll, instead of someone that understands the ideals behind security, and since I'm failing to see how you could think that people can't block your childish proxy methods, I'm starting to treat you like I would any troll - sorry if you don't like it.

Also, few ethical people would Tunnel/Proxy into their home systems or use company resources for non-company reasons.

If security was important to you, you would understand white/black/content filtering/blocking.

I don't think so. I personally think, that whitelisting only does not have to do with security, because this means to surrender and givin' up connectivity.

Whatever you mean with "real firewalls" (according to your postings here, I'd suggest, you could mean application gateways).

Yours, VB.

This is just wrong. Beside whitelisting, which is not a security feature, also with content filtering with application gateways it's very difficult to suppress proxying, especially, if it's done transparently in HTTP.

Content filtering means no endpoint to endpoint encryption BTW. I doubt, that this is a security feature in all cases.

Yours, VB.

And you don't seem to understand at all, so I don't expect it to make sense to you any more.

White and Black lists can be used for more than just Web experience, I have lists for HTTP, SSL, SMTP, IP, etc....

Think about it some more - maybe wake-up.

I would guess that you don't understand, and since you don't understand you're not going to understand it again. You can white list a site and still filter content and categories - I can let (example) google be white listed (or not black lists) and still limit access to approved content areas based on categories.

Thanks - I appreciate you bowing out of a conversation that you don't understand (which is really obvious) and hope you keep me in your kill file so that I don't have to read any more of your limited understandings.

Leythos wrote: [whitelisting]

You're not blocking something with whitelisting, but quitting connectivity to the Internet and building a private network.

As impolite as ever. You wouldn't believe that, but in my job security is important, beside my private dedication.

VB.

Since you're so clever, please explain:

1) How do you detect proxying? 2) How do you implement content filtering in an encrypted endpoint to endpoint connection? [whitelisting]

Whitelisting is not "limiting access". It's giving up connectivity to all but the whitelisted parts of your then private network.

VB.

Charles, what does this have to do with incompetent fools blocking access based on misunderstandings of the system. The local pizza klown was blocking based on the fact that the address was not in the local IP blocks used by Cox and QWorst, never mind the other 50 odd local ISPs in Phoenix. It's a pity, because they do build a pretty good pizza, but if the klown had someone who can actually _spell_ IP set up his site, he'd do better business.

Charles, I know it's really difficult for you to understand this technical stuff, but do go back to google and re-read the thread. Your microsoft approved "network training" really does put you at a disadvantage here, but we really did explain this four and a half months ago.

And I'd bet you are sure that traffic analysis (just looking at those IP addresses you don't understand) would NEVER detect this. By the way, you may want to grab a dictionary and look up that word "analysis". It's often used in accounting.

I guess your training really only did prepare you to be a data entry clerk - you certainly lack the thought processes for anything more complicated than that.

Old guy

Charles - your consistancy is amazing. You include this in your original post even though no-one else does, I guess you are hoping to avoid having people google on your handle and see the "quality" of your posts. But then you quote the entire thing including the material you don't want google to archive - but you do so without the XNA line. Hence, even if I didn't quote your entire load, every one can see you making a fool of yourself. By your own hand. Beautiful. One of these days, you may learn how to trim material you aren't responding to in your postings. But I'm certainly not holding my breath waiting for that.

And the incompetence of one organization compared to the skills of another is relevant exactly how?

script kiddies: pl.n.

  1. [very common] The lowest form of {cracker}; script kiddies do mischief with scripts and {rootkit}s written by others, often without understanding the {exploit} they are using. Used of people with limited technical expertise using easy-to-operate, pre-configured, and/or automated tools to conduct disruptive activities against networked systems. Since most of these tools are fairly well-known by the security community, the adverse impact of such actions is usually minimal.
  2. People who cannot program, but who create tacky HTML pages by copying JavaScript routines from other tacky HTML pages. More generally, a script kiddie writes (or more likely cuts and pastes) code without either having or desiring to have a mental model of what the code does; someone who thinks of code as magical incantations and asks only "what do I need to type to make this happen?"

And this pair of definitions (from Eric S. Raymond's "Jargon File") differ from your concept of what you are doing exactly how? You don't know what you are doing, and must search for turn-key solutions. You might try a search for a document...

Web Results 1 - 10 of about 167 for script-kiddy-HOWTO. (0.34 seconds)

Did you mean: script-kiddie-HOWTO

This , Like the world is only what you perceive it to be */ Q:"How ... /* This , Like the world is only what you perceive it to be */ Q:"How Do I Become A Hacker?" A: learn to code , install SunOS , get a SPARC , devote the ...

formatting link
- 8k - Cached - Similar pages

Bingo - first hit.

Old guy

Whitelisting in combination with blacklisting does not make sense at all.

Your users are not getting to sites, because they're _not_ blacklisted? This cannot be meant seriously, not even by you.

I'm assuming now, that you didn't understand, what people mean with whitelisting and blacklisting, because you're referencing content filtering now, what easily can be bypassed.

To make this clear: I've the feeling, that you don't understand anything about security at all. You're just babbling about "real firewalls", "1:1" for static NAT and other terms, which are fishy. Beside that, you're ignoring common terms like whitelisting, blacklisting, static or destination NAT, dynamic or source NAT and masquerading, and you're moaning and calling other people trolls, because you're in danger that anybody will notice your incompetence.

I have the feeling, for you a "real firewall" is something, which is expensive, and has a web interface or GUI, and you don't understand it.

This is totally ridiculous. Because you're running out of arguments, you're telling us now, why systems don't need to be secure. This you're telling us in a posting, where you're trying to explain, why tunneling is not possible, because you're claiming to have the perfect weapon against it (what of course just is nonsense).

In spite of your claims, that security is important to you, you don't understand white/black/content filtering/blocking, and you don't want to understand.

*PLONK*

VB.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required