bk99.de entertain the web since 1997

Firewall FAQ: Security is a maintained concept

Summary

Lutz Donnerhacke’s FAQ explains firewalls as a security concept that has to be maintained continuously and clears up common misconceptions about NAT, packet filters and desktop firewalls. The preserved page calls itself the FAQ of the newsgroup de.comp.security.firewall. The available version carries the version number 0.38.

Ideas

  • A firewall combines organisational rules, technical separation and ongoing maintenance.
  • Packet filters implement a security concept, but do not replace it.
  • A DMZ mediates explicitly permitted services between separated networks.
  • NAT solves addressing problems and does not provide a reliable security boundary.
  • Open ports can only be assessed sensibly together with the services behind them.
  • Security products can themselves encourage risky behaviour through risk compensation.

Insights

  • Security comes from verifiable assumptions, not from the name of a purchased device.
  • Connection direction and reachability prove neither intent nor trustworthiness.
  • Ongoing maintenance matters more than the original choice of product.

Quotes

  • Ein NAT-Router ist deswegen keine Sicherheitskomponente. (“That is why a NAT router is not a security component.”) – Lutz Donnerhacke

Habits

  • The FAQ answers recurring Usenet questions with protocol knowledge and comprehensible counterexamples.

Facts

  • Among other things, the FAQ covers DMZ, NAT, port scans, IPsec and personal firewalls.

References

Critique

  • Individual product references and protocol examples reflect the historical state of the FAQ.
  • Modern cloud, container and zero trust architectures are not yet covered.

Remarks

  • The post date refers to the earliest verifiable archived copy, not the first publication.
  • Defining a firewall as a maintained concept remains remarkably relevant.

Recommendations

  • First document protection requirements, data flows and responsibilities.
  • Allow only justified connections and review rules regularly.
  • Never treat NAT as a substitute for filtering and system hardening.

Read the FAQ

Search the Web Archive