Firewall Wizards mailing list archives

Re: Firewall administration.


From: Ted Doty <ted () iss net>
Date: Sun, 12 Oct 1997 10:57:05 -0400

At 06:18 AM 10/7/97 -0700, Bennett Todd wrote:
Ted Doty wrote:

[snip]

What's left out here is the cost of the expertise (*nix administration,
fwtk administration, overall security cluefulness in general).

[snip]

It's pretty clear that the (proper) setup and administration of the
firewall
is several times more expensive than the firewall itself.

Only if the policy is complex. Big complicated companies have complex
internal
organizations, with many different groups of people with different and
incompatible security needs; this makes for complex security policies which
require complex firewalls to implement --- to the degree, often nowhere near
perfect, we can implement them at all.

Your typical wee-teensy company will often, in my experience, have a truly
trivial security policy that reflects the preferences of the only individual
whose opinion matters, the boss.

[rest of good discussion of setting up a policy deleted]

Let me clarify my earlier posting: what most customers don't realize is
that the biggest part of the firewall's cost is the administration.  Even
if you assume a simple and unchanging policy, someone still needs to cruise
thru the logs to see what's happening on the connection.  They also need to
periodically update the configuration just to protect against new forms of
attacks.  Never mind reading Bugtraq to see just what those new attacks
are.  This doesn't come for free.

For a midling sized company, with a midling Internet feed (say dedicated 64
k), this can pretty easily average an hour a day for an administrator.  If
you assume that a decent admin will make around $60k a year (use $90 k for
a burdened rate), one eighth of this is $10-$12k administration cost each
year.

Given that a low end Intel/NT-or-Linux firewall will cost less than $10k to
install, and will last 3 years, the admin cost is at least 3 time the
system cost.  And this assumes that you get a decent admin; my experience
is that most folks just don't have one.

IMHO, this is the main reason that people get hacked through firewalls:
they just can't run them. 

- Ted

----------------------------------------------------------------------------
Ted Doty, Internet Security Systems | Phone: +1 770 395 0150
41 Perimeter Center East            | Fax:   +1 770 395 1972
Atlanta, GA 30346  USA              | Web: http://eng.iss.net/~tdoty
----------------------------------------------------------------------------
PGP key fingerprint: 362A EAC7 9E08 1689  FD0F E625 D525 E1BE



Current thread: