[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [OPSEC] culled from nanog 47 circumstances where stateful inspection is considered harmful...



On Oct 25, 2009, at 8:08 PM, Joel Jaeggli wrote:
I wonder:
if some of the efforts associated with stateful inspection requirements
in this space:
	 are working at cross-purposes
	preclude cost-effective network scaling beyond a certain level

I can't really speak to your second item
but I think that there's no question that the
first is true.  It's been clear for some time
that where crypto interferes with inspection
operators/enterprises will turn off the crypto
rather than get rid of (or modify) the firewall
or NAT.

Melinda