Zone Based firewall comment

From: Chris Proctor <chris_at_cwproctor.net>
Date: Mon, 28 Feb 2011 01:44:39 -0500

Well, after beating my head against this for awhile I have come to three
conclusions (call it venting if you will):
1.) Security zones are cool
2.) Inspect maps are overly complex pieces of crap
3.) Specialized inspect maps are even bigger pieces of crap

I find myself hoping they won't get too carried away with this subject.
Working out all of the possible regex's, etc and nesting of
relationships could easily take me 20 hours for a complex enough
configuration. Can anyone tell me if I'm wasting my time going through
the lower levels of hell here?

-- 
Chris Proctor
--
This message was scanned by ESVA and is believed to be clean.
Blogs and organic groups at http://www.ccie.net
Received on Mon Feb 28 2011 - 01:44:39 ART

This archive was generated by hypermail 2.2.0 : Tue Mar 01 2011 - 07:01:50 ART