Firewall Wizards mailing list archives

Re: Multiple small switches vs. a single big one; Granularity of control


From: Brian Ford <brford () cisco com>
Date: Tue, 02 Mar 2004 14:36:30 -0500

Simon,

You said "resets" and then you said "otherwise changes". Those are very different things. If you reset any security device to the default configuration it is a very bad thing. If you gain access to any Firewall or other security device so that you can change the devices configuration it's game over.

I don't see how this goes back to your original query about whether to use one big switch or several small switches or to the granularity of control. You are defining an out of control situation.

This all comes back to the basic security policy questions of "what is risk?" and "how much risk can I tolerate?".

Liberty for All,

Brian


At 12:00 PM 3/2/2004 -0500, firewall-wizards-request () honor icsalabs com wrote:

Message: 3
From: "Shimon Silberschlag" <shimons () bll co il>
To: "David Lang" <david.lang () digitalinsight com>
Cc: <firewall-wizards () honor icsalabs com>
Subject: Re: [fw-wiz] Multiple small switches vs. a single big one; Granularity of control
Date: Mon, 1 Mar 2004 13:33:16 +0200

Lets take it to the extreme: someone (accidentally or intentionally) resets
(or otherwise changes) the switch configuration. With separate switches,
each segment can talk freely to all other servers on the segment but not
outside, since the FW watches that route. For one big switch connected to an
outside FW, all segments can talk to all segments (if the switch behaves as
a L2 one). What about 6500 with FWSM? does resetting the config prevents it
from seeing any traffic?

Shimon Silberschlag

+972-3-9351572
+972-51-207130


Brian Ford
Consulting Engineer, Security & Integrity Specialist
Office of Strategic Technology Planning
Cisco Systems Inc.
http://www.cisco.com/go/safe/

The opinions expressed in this message are those of the author and not necessarily those of Cisco Systems, Inc..

This email address is transmitted from San Jose, California, U.S.A..


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: