Firewall Wizards mailing list archives
Re: Firewall administration.
From: Ted Doty <ted () iss net>
Date: Sun, 12 Oct 1997 10:57:05 -0400
At 06:18 AM 10/7/97 -0700, Bennett Todd wrote:
Ted Doty wrote:
[snip]
What's left out here is the cost of the expertise (*nix administration, fwtk administration, overall security cluefulness in general).
[snip]
It's pretty clear that the (proper) setup and administration of the
firewall
is several times more expensive than the firewall itself.Only if the policy is complex. Big complicated companies have complex
internal
organizations, with many different groups of people with different and incompatible security needs; this makes for complex security policies which require complex firewalls to implement --- to the degree, often nowhere near perfect, we can implement them at all. Your typical wee-teensy company will often, in my experience, have a truly trivial security policy that reflects the preferences of the only individual whose opinion matters, the boss.
[rest of good discussion of setting up a policy deleted] Let me clarify my earlier posting: what most customers don't realize is that the biggest part of the firewall's cost is the administration. Even if you assume a simple and unchanging policy, someone still needs to cruise thru the logs to see what's happening on the connection. They also need to periodically update the configuration just to protect against new forms of attacks. Never mind reading Bugtraq to see just what those new attacks are. This doesn't come for free. For a midling sized company, with a midling Internet feed (say dedicated 64 k), this can pretty easily average an hour a day for an administrator. If you assume that a decent admin will make around $60k a year (use $90 k for a burdened rate), one eighth of this is $10-$12k administration cost each year. Given that a low end Intel/NT-or-Linux firewall will cost less than $10k to install, and will last 3 years, the admin cost is at least 3 time the system cost. And this assumes that you get a decent admin; my experience is that most folks just don't have one. IMHO, this is the main reason that people get hacked through firewalls: they just can't run them. - Ted ---------------------------------------------------------------------------- Ted Doty, Internet Security Systems | Phone: +1 770 395 0150 41 Perimeter Center East | Fax: +1 770 395 1972 Atlanta, GA 30346 USA | Web: http://eng.iss.net/~tdoty ---------------------------------------------------------------------------- PGP key fingerprint: 362A EAC7 9E08 1689 FD0F E625 D525 E1BE
Current thread:
- RE: Firewall administration., (continued)
- RE: Firewall administration. Gary Crumrine (Oct 06)
- Re: Firewall administration. Bennett Todd (Oct 06)
- Re: Firewall administration. Adam Shostack (Oct 07)
- Re: Firewall administration. Bennett Todd (Oct 07)
- Re: Firewall administration. Marcus J. Ranum (Oct 07)
- Re: Small company question was Re: Firewall administration. Mark Teicher (Oct 09)
- Re: Small company question was Re: Firewall administration. Bennett Todd (Oct 10)
- Re: Firewall administration. Bennett Todd (Oct 06)
- Re: Firewall administration. Larry J. Hughes Jr. (Oct 09)
- RE: Firewall administration. Gary Crumrine (Oct 06)
- Re: Firewall administration. Ted Doty (Oct 07)
- Re: Firewall administration. Bennett Todd (Oct 07)
- Re: Firewall administration. Ted Doty (Oct 12)
- Re: Firewall administration. Bennett Todd (Oct 12)
- Re: Firewall administration. Ted Doty (Oct 12)
- Internet Security Review Mark Teicher (Oct 13)
- Re: Internet Security Review Bennett Todd (Oct 13)
- Re: Internet Security Review Marcus J. Ranum (Oct 14)
- Securing Staff (was Re: Internet Security Review) Jeff Sedayao (Oct 15)
- Re: Internet Security Review Steve Kruse (Oct 13)
- Re: Policy and administration was Re: Firewall administration. Ted Doty (Oct 13)
