Firewalls — Evolve or Die

  • Authors:
  • D. J. Gooch;S. D. Hubbard;M. W. Moore;J. Hill

  • Affiliations:
  • -;-;-;-

  • Venue:
  • BT Technology Journal
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Businesses have traditionally relied on perimeter firewalls to enforce their security policy. However, perimeter controls do not provide a comprehensive solution to secure a private network connected to the Internet. This paper describes how the dynamic business environment and techniques, such as protocol tunnelling, have leveraged the use of IP networks. The use of these protocols and techniques means that perimeter firewalls alone no longer provide sufficient security. IPsec network security is reviewed and it is shown how its security services can be used to provide greater protection for the network by securing connections end to end. The paper also describes tools for firewall and VPN policy management that address the problem of managing the overall security policy with network implementations comprising multiple vendors' products. Finally, the paper proposes a vision of how future secure virtual networks will be established over existing infrastructures.