Are legacy firewalls still relevant?

r00igev@@r

Honorary Master
Joined
Dec 14, 2009
Messages
15,646
Reaction score
14,160
Location
Draadloos Bantha poo doo in 4ways
So just after Y2K I went and certified myself to the eyeballs on Checkpoint via Nokia Internet Education. I was drinking the firewall Kool-Aid.
Not so much anymore, so I decided to write up why I think their time is up and hoping to debate the issue.

 
So just after Y2K I went and certified myself to the eyeballs on Checkpoint via Nokia Internet Education. I was drinking the firewall Kool-Aid.
Not so much anymore, so I decided to write up why I think their time is up and hoping to debate the issue.


My head hurt reading your article , above my pay grade o_O:giggle:
 
Not sure if I am getting the underlying message right but selling SD-WAN as a firewall replacement doesn't seem like a good idea to me.

99% of the time I've seen things go through a firewall its because of config error, not the firewall itself.
 
Not sure if I am getting the underlying message right but selling SD-WAN as a firewall replacement doesn't seem like a good idea to me.

99% of the time I've seen things go through a firewall its because of config error, not the firewall itself.
SD-WAN has firewalls. Its a misnomer that it does not. Has the same firewall as all the cloud firewalls.

Yes, there are config errors but the point is that the vendors haven't implemented any mechanisms to mitigate them.
 
Last edited:
My head hurt reading your article , above my pay grade o_O:giggle:
As a non technical person I got the gist of of the article, and whilst there are technical bits, I think the message came across.

With regard to the topic itself: it is going to be hard changing people's mindset. Too many interest parties making money from this.
 
As a non technical person I got the gist of of the article, and whilst there are technical bits, I think the message came across.

With regard to the topic itself: it is going to be hard changing people's mindset. Too many interest parties making money from this.
True, its a money spinner and nothing brings this into stark contrast more than the vendors still miking the Windows AV market.

Its like this thing:

Washball.jpg
 
The proxy part is only IMO relevant for road warriors and not offices. Everyone is not a road warrior.
In Zero Trust, they kind of are. The perimeter of the trusted network reduces to practically nothing.
 
That is a very good paper and great find. The proxy part is only IMO relevant for road warriors and not offices. Everyone is not a road warrior.

Depends.

It’s easier to treat everyone as a road warrior/remote worker rather than an office bound one, especially at this point in time where they can be both on any given day.

So we treat our offices as nothing more than Load Shedding free internet connections and every end point is still protected as if remote.

That being said we have no local infrastructure which makes it a lot simpler, only a network stack so it was all planned like this from the start.

Even if I did have some local infrastructure I wouldn’t really do it any differently, my split tunnels would likely just be configured a bit more elaborately.

Definitely with you on the old school firewall front and plan to stop paying for the ludicrously expensive Fortigate support after the term ends and potentially replacing them with something else.

****

Small mistake; you wanted to say “architecturally flawed” not “architectural flawed” I would imagine.
 
Last edited:
Depends.

It’s easier to treat everyone as a road warrior/remote worker rather than an office bound one, especially at this point in time where they can be both on any given day.

So we treat our offices as nothing more than Load Shedding free internet connections and every end point is still protected as if remote.

That being said we have no local infrastructure which makes it a lot simpler, only a network stack so it was all planned like this from the start.

Even if I did have some local infrastructure I wouldn’t really do it any differently, my split tunnels would likely just be configured a bit more elaborately.

Definitely with you on the old school firewall front and plan to stop paying for the ludicrously expensive Fortigate support after the term ends and potentially replacing them with something else.

****

Small mistake; you wanted to say “architecturally flawed” not “architectural flawed” I would imagine.

good luck trying to find something at the same level at fortigate that is cheaper :confused:

Oh wait , i forgot you paying for the support.Best to learn how to manage a fortigate so you dont have to pay for support.I only pay for the hardware rental , and my external IT supplier hosts my forti anaylzer.Works out to be very cost effective.
 
Depends.

It’s easier to treat everyone as a road warrior/remote worker rather than an office bound one, especially at this point in time where they can be both on any given day.

So we treat our offices as nothing more than Load Shedding free internet connections and every end point is still protected as if remote.

That being said we have no local infrastructure which makes it a lot simpler, only a network stack so it was all planned like this from the start.

Even if I did have some local infrastructure I wouldn’t really do it any differently, my split tunnels would likely just be configured a bit more elaborately.

Definitely with you on the old school firewall front and plan to stop paying for the ludicrously expensive Fortigate support after the term ends and potentially replacing them with something else.

****

Small mistake; you wanted to say “architecturally flawed” not “architectural flawed” I would imagine.
Glad you realized that old school firewalls are taking you for a ride. There is no different if they from Silicon Valley or Latvia. :laugh:

To clarify my point about road warriors. My point is why do you need the proxy at an office that has a fancy pants firewall! Even less so when you have migrated your infrastructure to the cloud.

I've never liked proxies as they become an additional point of failure (often singular) and in my experience impact performance.

I prefer the use of VPNs with 2FA and in the case of OCSERV it is actually very good as each user runs in their own space. Protects users from other users as well as the infrastructure and there is no performance hit.

There is a certain bank that went TITSUP because their proxy went south. Man down at month end. I'll pass on drinking the proxy Kool-Aid. Single ISP connected to single proxy.:notworthy::ROFL:
 
good luck trying to find something at the same level at fortigate that is cheaper :confused:

Oh wait , i forgot you paying for the support.Best to learn how to manage a fortigate so you dont have to pay for support.I only pay for the hardware rental , and my external IT supplier hosts my forti anaylzer.Works out to be very cost effective.

That’s just the thing I hardly use it for anything more than the basics because all the extras as so expensive they don’t make sense.

And I know pretty full well how to manage them that the support really is just for the swop out warranty if one of them dies…and for the price I could literally have something else in the cupboard or just source it as required.

The very fact they expect me to pay for FortiAnalyzer to do very basic things is fundamentally my problem with them.

They really are not all that.
 
Glad you realized that old school firewalls are taking you for a ride. There is no different if they from Silicon Valley or Latvia. :laugh:

To clarify my point about road warriors. My point is why do you need the proxy at an office that has a fancy pants firewall! Even less so when you have migrated your infrastructure to the cloud.

I've never liked proxies as they become an additional point of failure (often singular) and in my experience impact performance.

I prefer the use of VPNs with 2FA and in the case of OCSERV it is actually very good as each user runs in their own space. Protects users from other users as well as the infrastructure and there is no performance hit.

There is a certain bank that went TITSUP because their proxy went south. Man down at month end. I'll pass on drinking the proxy Kool-Aid. Single ISP connected to single proxy.:notworthy::ROFL:

Oh I misunderstood.

You mean proxies running at the office that everyone is forced to connect through including remote people, yeah that makes no sense.

We technically do that with CloudFlare Gateway but only partially so being DNS based and all that and only proxy traffic that is our own via CloudFlared. Everything else goes to the internet straight from the endpoint.

So no performance issues, in fact internet is better for most users unless they are in the middle of bloody nowhere far away from a CF POP.

We kill off all the bad stuff before it even goes anywhere and pretty much job done and you can only get to our internal resources with a managed device after authentication.
 
Oh I misunderstood.

You mean proxies running at the office that everyone is forced to connect through including remote people, yeah that makes no sense.

We technically do that with CloudFlare Gateway but only partially so being DNS based and all that and only proxy traffic that is our own via CloudFlared. Everything else goes to the internet straight from the endpoint.
We are on the same page then.

When a bank says it had a glitch it means the proxy thunked.:eek:
 
good luck trying to find something at the same level at fortigate that is cheaper :confused:
Checkpoint would like to take you upon that!:laugh: https://www.checkpoint.com/comparison/check-point-vs-fortinet/
Clavister is also cost effective and has no backdoors.

But I think the biggest issue is the change itself to learn a new syntax. Probably the bigger consideration and barrier than price for many companies.
Oh wait , i forgot you paying for the support.Best to learn how to manage a fortigate so you dont have to pay for support.I only pay for the hardware rental , and my external IT supplier hosts my forti anaylzer.Works out to be very cost effective.
I have something better than fort analyzer that is priced better.:laugh:

Fort analyzer has that Siebel feel to it, like you just running a spreadsheet as the app.
 
In Zero Trust, they kind of are. The perimeter of the trusted network reduces to practically nothing.
Zero Trust is a term thrown around often. However, I see guys who talk about it but haven't implemented decent segmentation. Thats the start.
There should be a clear partitioning between management traffic and user traffic. Services should have a leg in each and changes to infrastructure should only be possible from the management interface. My preference is to have a VPN concentrator in the management plane and use that to force 2FA authentication using a SSL based VPN.
Most hacks are because the user and management plane are common.
I would take it a step further and segment the database, web and app layers. You don't even need to involve the firewall administrator on that one as its just the implementation of plain old vlans. Additionally, I would create a separate segmentation for backup/restore with an airgap for at least one copy of the data.
So in my opinion you wasting time with zero trust when you lack segmentation.
 
SD-WAN has firewalls. Its a misnomer that it does not. Has the same firewall as all the cloud firewalls.

Yes, there are config errors but the point is that the vendors haven't implemented any mechanisms to mitigate them.

The vendors firewalls that I've used over the years all have tools to mitigate these things.
Trying to protect your edge with an SD-WAN device still doesn't seem advisable to me.
Layer 4 opening and closing of ports is not the right way to do things.
Not sure what product you are referring to in this specifically but most of the SD-WAN vendors I've seen are ACLs with a nice GUI.

I don't disagree with you - I just don't fully agree :)
 
So just after Y2K I went and certified myself to the eyeballs on Checkpoint via Nokia Internet Education. I was drinking the firewall Kool-Aid.
Not so much anymore, so I decided to write up why I think their time is up and hoping to debate the issue.

I still have nightmares from SPLAT and the VRRP from hell.
 
Top
Sign up to the MyBroadband newsletter
X