CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-27
Junior Member
 
Join Date: 2005-12-20
Posts: 24
Rep Power: 0
Westy has an average reputation (10+)
Default Are firewalls needed?

I'd like to pose this question to the members of the forum.
Are firewalls needed?

A colleague of mine who follows the security forums says that he's reading that firewalls being pulled out of some places. The reasons, the more sophisticated attacks are now taking place at the application layer? And, that with port 80 always open, attackers have a well known way through the firewalls anyway.
Reply With Quote
  #2 (permalink)  
Old 2005-12-28
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: Are firewalls needed?

A new market hype coming UTM (Unified Threat Management/Mitigation). Here is unified approach coming - one box do all (Firewall, VPN, IPS, Content Filtering, Anti Virus, Anti Spam). Checkpoint as well as other vendors moves towards this direction.
Try to read first UTM review at http://www.nss.co.uk/utm/index.htm and Gartner doc about place of each technology on the "hype curve"

http://www.ementor.no/upload/Events/...0cycle2005.pdf

Reply With Quote
  #3 (permalink)  
Old 2006-01-02
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: Are firewalls needed?

hahaha i love that graph

i won't be pulling firewalls ANY time soon..

any company that does is stupid..
it's like saying that home invasions are occuring through smashing windows, so there is no point locking doors now...
__________________
///M
Reply With Quote
  #4 (permalink)  
Old 2006-01-03
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,662
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Are firewalls needed?

Actually the Jericho forum published a good paper on de-perimeterizing the network.

As far as UTM goes, there is a lot of high-level annalists saying its not a good thing (eggs, one basket, etc).

That being said, FW1 with SmartDefense/Web Intelligence is application layer protection.

-jlh
Reply With Quote
  #5 (permalink)  
Old 2006-01-03
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: Are firewalls needed?

chilijim do you have a URL of that paper? i can't find it on the jericho page
__________________
///M
Reply With Quote
  #6 (permalink)  
Old 2006-01-03
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: Are firewalls needed?

ok i just http://www.opengroup.org/projects/je...esentation.pdf

I really don't think their offering many answers. are they just wanting to give in to threats and have a responsive approach?
the switch to data level authentication wouldn't be a small one either..

i call vapourware
__________________
///M
Reply With Quote
  #7 (permalink)  
Old 2006-01-04
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,662
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Are firewalls needed?

Yeah there is a lot missing here. Host-based IDS/IPS along with host-based firewalls (packet/application and OS level) will help. The Jericho paper isn't even to the level of vaporware. Maybe someday we'll get there, but we're nowhere close yet.

-jlh
Reply With Quote
  #8 (permalink)  
Old 2006-01-04
Junior Member
 
Join Date: 2005-09-30
Posts: 23
Rep Power: 0
justin.knox has an average reputation (10+)
Default Re: Are firewalls needed?

UTM is a wonderful idea, but as chillyjim noted: all eggs in one basket. I was initially quite skeptical of the deep-inspection firewall surge. This was due to the marketing hype (even by Check Point), such that the DPI (deep packet inspection) devices can take the place of a whole suite of products (firewall, ids, ips, vpn concentrator, etc). I come from the school of thought that a product should do one thing and do it well. Check Point's product line could easily be labelled as a case study in feature creep -- but that goes for most security products of today.

Ultimately what it comes down to is this: the Defense-in-Depth approach to network security has a place for UTM, however, relying on one product to do it all is clearly at odds with that approach.

just my $0.02.

[edit -- typo correction]
Reply With Quote
  #9 (permalink)  
Old 2006-01-04
Junior Member
 
Join Date: 2005-12-20
Posts: 24
Rep Power: 0
Westy has an average reputation (10+)
Default Re: Are firewalls needed?

Thanks everybody, for me this is very helpful, I'm hoping it is for other Junior members as well. I wasn't aware of UTM nor of the Jericho project. Hopefully we'll get a few more posts to keep the thread going so that we can all benefit a bit more.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:12.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0