Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Strong agree, network based firewalls don't make sense based on performance needs and placement at the edge of an increasingly ephemeral network perimeter.

Host and edge / stub firewalls with strong orchestration will be far more pervasive along with lots of network traffic auditing and anomaly detection that happens in near real-time, but out of the line of fire (out of band).



I haven't seen firewalls on the edge in ages. I guess it's more of a Fortune 500 attitude than tech company thing.

"Firewall" devices still have a place inside your network beyond the perimeter. Today they do ACL enforcement as well as DPI, IDP, IDS, tap data, etc. It's not unheard of to run a "firewall" in completely passive, monitor-only mode to generate telemetry data.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: