Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Tricks You Can Do If Your Firewall Is a Bridge

Firewalls that forward packets like a bridge, rather than as a router, have many operational benefits. By decoupling routing from filtering, the firewall becomes a pure filter, unburdened by routing table or interface configuration. The result is increased flexibility. This paper explores some of the benefits we have found. Most of the benefits stem from the fact that a bridged firewall requires fewer transit subnets. Sometimes transit subnets are completely eliminated. It can be placed between any two network devices and act like a line filter without needing to change the logical routing of the network. It is easy to put one in series with another firewall for testing. Our examples include replacing an old firewall with a new one, moving a firewall from one router to another with zero downtime, firewalling off an individual office or lab, and others. In many cases topology changes are made without service interruptions. The operational procedures become much more simple. The paper also suggests future directions for research in this area.

Thomas A. Limoncelli, Lucent Technologies

BibTeX
@inproceedings {271761,
author = {Thomas A. Limoncelli},
title = {Tricks You Can Do If Your Firewall Is a Bridge},
booktitle = {1st Conference on Network Administration (NETA 99)},
year = {1999},
address = {Santa Clara, CA},
url = {https://www.usenix.org/conference/neta-99/tricks-you-can-do-if-your-firewall-bridge},
publisher = {USENIX Association},
month = apr
}
Download

Links

Paper: 
http://www.usenix.org/publications/library/proceedings/neta99/full_papers/limoncelli/limoncelli.pdf
Paper (HTML): 
http://www.usenix.org/publications/library/proceedings/neta99/full_papers/limoncelli/limoncelli_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us