Multi-firewall defense in depth

Reply

Join Date: Oct 2009
Posts: 1
Reputation: latin is an unknown quantity at this point 
Solved Threads: 0
latin latin is offline Offline
Newbie Poster

Multi-firewall defense in depth

 
0
  #1
Oct 5th, 2009
I have simple question which is regarding firewall deployment in defense in depth strategy.

I want to install multiple firewall on my network I want to know should all the firewall placed on different segment of the network be "all configured in fail close fashion". In this case would this create a single point of failure if all the devices were to fail at one time. Would it make your network inaccessible to the rest of the network.

Secondly, the other concern of using multiple layer firewall is the duplication of policies. In my experience even working with two or more firewall in one environment is enough to create a management nightmare. Is duplication an option which should be considered like a best practice approach or when you have consistent hardware environment (juniper , juniper , pix , pix etc).
With duplication you eliminate the degree of uncertainty of speculation or assumption of firewall at different layer would have a certain policy to block certain service/ port but in actuality its quiet the opposite where the service is not being stopped or disallowed by the firewall. Duplication would solve the problem but than as i said it again it has to do with interoperability among other issues. Can someone please like to comment on the scenario

thank you.
Last edited by latin; Oct 5th, 2009 at 7:45 am.
Reply With Quote Quick reply to this message  
Join Date: Sep 2009
Posts: 113
Reputation: ov3rcl0ck is an unknown quantity at this point 
Solved Threads: 14
ov3rcl0ck ov3rcl0ck is offline Offline
Junior Poster
 
0
  #2
Oct 6th, 2009
question is why have a firewall layering a firewall?
NOTE: sudo doesn't apply to real life situations.
Reply With Quote Quick reply to this message  
Reply

Message:



Similar Threads
Other Threads in the Network Security Forum


Views: 630 | Replies: 1
Thread Tools Search this Thread



Tag cloud for Network Security
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC