4 ms·
> there's still many firewall features that one wouldn't want to reimplement app-level each time like rate limiting, network access logging One of the major th
by dlitz 11y ago
> there's still many firewall features that one wouldn't want to reimplement app-level each time like rate limiting, network access logging
One of the major things that was learned in the NCP->TCP/IP transition was that it's better to put complex logic in the endpoints, rather than in the network.
> basic routing
Routing isn't what a "firewall" does. Routing is what a "router" does.
> I'm not sure what definition of "firewall" you all are thinking about.
I'm talking about packet filtering that looks at more than the source & destination addresses, stateful packet filtering, "deep packet inspection", etc., especially when they're set up as default-deny.
Application developers shouldn't have to worry that their packets will succeed or fail to be delivered depending on their content.