Firewall FAQ: Security is a maintained concept
Summary
Lutz Donnerhacke’s FAQ explains firewalls as a security concept that has to be maintained continuously and clears up common misconceptions about NAT, packet filters and desktop firewalls. The preserved page calls itself the FAQ of the newsgroup de.comp.security.firewall. The available version carries the version number 0.38.
Ideas
- A firewall combines organisational rules, technical separation and ongoing maintenance.
- Packet filters implement a security concept, but do not replace it.
- A DMZ mediates explicitly permitted services between separated networks.
- NAT solves addressing problems and does not provide a reliable security boundary.
- Open ports can only be assessed sensibly together with the services behind them.
- Security products can themselves encourage risky behaviour through risk compensation.
Insights
- Security comes from verifiable assumptions, not from the name of a purchased device.
- Connection direction and reachability prove neither intent nor trustworthiness.
- Ongoing maintenance matters more than the original choice of product.
Quotes
Ein NAT-Router ist deswegen keine Sicherheitskomponente.
(“That is why a NAT router is not a security component.”) – Lutz Donnerhacke
Habits
- The FAQ answers recurring Usenet questions with protocol knowledge and comprehensible counterexamples.
Facts
- Among other things, the FAQ covers DMZ, NAT, port scans, IPsec and personal firewalls.
References
- Lutz Donnerhacke: de.comp.security.firewall FAQ (German)
- Earliest archived copy found, from 9 April 2001
Critique
- Individual product references and protocol examples reflect the historical state of the FAQ.
- Modern cloud, container and zero trust architectures are not yet covered.
Remarks
- The post date refers to the earliest verifiable archived copy, not the first publication.
- Defining a firewall as a maintained concept remains remarkably relevant.
Recommendations
- First document protection requirements, data flows and responsibilities.
- Allow only justified connections and review rules regularly.
- Never treat NAT as a substitute for filtering and system hardening.
Links to the original source and the Web Archive open in a new tab.