<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall Management - All Access Pass? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-management-all-access-pass/m-p/2374133#M310117</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both philosophies are quite common, but it's obvious that the second group lives more secure. And even better in the second scenario if ports are not only just opened on demand, but if the needed traffic is also send through a L7-device like a filtering proxy for HTTP/HTTPS for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Oct 2013 16:59:51 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2013-10-29T16:59:51Z</dc:date>
    <item>
      <title>Firewall Management - All Access Pass?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-management-all-access-pass/m-p/2374132#M310114</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just wondering if the prevailing philosophy on firewall management is to 1) allow everything outbound and restrict inbound or 2) restrict both inbound and outbound?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a situation where we are getting hit with ZeroAccess Root Kit and it is occasionally changing the ports it uses.&amp;nbsp; I can create an ACL that blocks a port each time it changes but that begs the bigger question of should we just restrict everything inbound AND outbound.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp; All replies rated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:57:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-management-all-access-pass/m-p/2374132#M310114</guid>
      <dc:creator>angel-moon</dc:creator>
      <dc:date>2019-03-12T02:57:31Z</dc:date>
    </item>
    <item>
      <title>Firewall Management - All Access Pass?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-management-all-access-pass/m-p/2374133#M310117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both philosophies are quite common, but it's obvious that the second group lives more secure. And even better in the second scenario if ports are not only just opened on demand, but if the needed traffic is also send through a L7-device like a filtering proxy for HTTP/HTTPS for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 16:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-management-all-access-pass/m-p/2374133#M310117</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-10-29T16:59:51Z</dc:date>
    </item>
  </channel>
</rss>

