-----Original Message-----
From: OPSEC [mailto:[email protected]] On Behalf Of Simon Perreault
Sent: Monday, March 31, 2014 6:53 PM
To: [email protected]
Subject: Re: [OPSEC] comments for firewall draft

> Do you have specific things in mind that the draft should say on this topic?
>
> IMHO, the fact that NAT is common in firewall equipment is irrelevant.
> Many other functions are common: IPSEC gateway, SSL VPN, IDS, etc. etc.
> etc. A draft covering everything would be a huge effort with low chance of 
> success.
>
> I would prefer this draft to remain focused on the core firewall function.

Well, then the argument is: is NAT a central function in a firewall, especially 
in an IPv6 one?

I do believe NAT is a bit different than the others you mentioned, because in 
the great majority of circumstances you would really use a firewall to perform 
NAT.

In all of the other cases you mentioned (VPN, NIDS, etc.) they may be enabled 
with a license in environments where no better solution is desired, required or 
could be afforded; but they are really not central to a firewall, and are 
better performed with a dedicated system.

Mileage may vary with different firewall brands; e.g. with Juniper, SSL VPN is 
better provided by a dedicated security gateway appliance, while in Cisco or 
Palo Alto there is more convergence and this function is enabled by license. 
Anyway, all of them (thinking especially about NIDS/NIPS) are better provided 
by dedicated appliances and are not really so central for a firewall.

Worth to be noted, in the original RFP document I redacted, there were also all 
of these functions, but they were removed as it would have been too many things 
to discuss at once. However, I do think that NAT may have some special merit. 
Therefore it would be good to collect votes on that. So far I got 3+ and 1- if 
I am not wrong.


Marco Ermini 

Senior IT Security and Compliance Analyst
ResMed Germany Inc Fraunhofer Str. 16 - 82152 - Martinsried - Germany  
ResMed.com 

 ----------------------------------------------------------------------
Warning:  Copyright ResMed.  Where the contents of this email and/or attachment 
includes materials prepared by ResMed, the use of those
materials is subject exclusively to the conditions of engagement between ResMed 
and the intended recipient.  This communication is confidential and may contain 
legally privileged information.  By the use of email over the Internet or other 
communication systems, ResMed is not waiving either confidentiality of, or 
legal privilege in, the content of the email and of any attachments.  If the 
recipient of this message is not the intended addressee, please call ResMed 
immediately on  1 (800) 424-0737 USA.
 ----------------------------------------------------------------------

_______________________________________________
OPSEC mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/opsec

Reply via email to