Firewall Wizards mailing list archives
Re: Multiple small switches vs. a single big one; Granularity of control
From: Brian Ford <brford () cisco com>
Date: Tue, 02 Mar 2004 14:36:30 -0500
Simon,You said "resets" and then you said "otherwise changes". Those are very different things. If you reset any security device to the default configuration it is a very bad thing. If you gain access to any Firewall or other security device so that you can change the devices configuration it's game over.
I don't see how this goes back to your original query about whether to use one big switch or several small switches or to the granularity of control. You are defining an out of control situation.
This all comes back to the basic security policy questions of "what is risk?" and "how much risk can I tolerate?".
Liberty for All, Brian At 12:00 PM 3/2/2004 -0500, firewall-wizards-request () honor icsalabs com wrote:
Message: 3 From: "Shimon Silberschlag" <shimons () bll co il> To: "David Lang" <david.lang () digitalinsight com> Cc: <firewall-wizards () honor icsalabs com>Subject: Re: [fw-wiz] Multiple small switches vs. a single big one; Granularity of controlDate: Mon, 1 Mar 2004 13:33:16 +0200 Lets take it to the extreme: someone (accidentally or intentionally) resets (or otherwise changes) the switch configuration. With separate switches, each segment can talk freely to all other servers on the segment but not outside, since the FW watches that route. For one big switch connected to an outside FW, all segments can talk to all segments (if the switch behaves as a L2 one). What about 6500 with FWSM? does resetting the config prevents it from seeing any traffic? Shimon Silberschlag +972-3-9351572 +972-51-207130
Brian Ford Consulting Engineer, Security & Integrity Specialist Office of Strategic Technology Planning Cisco Systems Inc. http://www.cisco.com/go/safe/The opinions expressed in this message are those of the author and not necessarily those of Cisco Systems, Inc..
This email address is transmitted from San Jose, California, U.S.A.. _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: Multiple small switches vs. a single big one; Granularity of control Brian Ford (Mar 02)
