RFC 7288: Reflections on Host Firewalls
In plain English — editorial summary, not part of the RFC
In today's Internet, the need for firewalls is generally accepted in the industry, and indeed firewalls are widely deployed in practice. Unlike traditional firewalls that protect network links, host firewalls run in end-user systems. Often the result is that software may be running and potentially consuming resources, but then communication is blocked by a host firewall. It's taken for granted that this end state is either desirable or the best that can be achieved in practice, rather than (for example) an end state where the relevant software is not running or is running in a way that would not result in unwanted communication. In this document, we explore the issues behind these assumptions and provide suggestions on improving the architecture going forward.
Document record
- Document ID
- RFC7288
- Published
- June 2014
- Authors
- D. Thaler
- Status
- INFORMATIONAL
- Stream
- IAB
- Area
- —
- Pages
- 13
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7754Technical Considerations for Internet Service Blocking and FilteringCurrent
March 2016
- RFC 6785Support for Internet Message Access Protocol (IMAP) Events in SieveCurrent
November 2012
- RFC 6727Definitions of Managed Objects for Packet SamplingCurrent
October 2012
- RFC 6615Definitions of Managed Objects for IP Flow Information ExportCurrent
June 2012
- RFC 6192Protecting the Router Control PlaneCurrent
March 2011
- RFC 6092Recommended Simple Security Capabilities in Customer Premises Equipment (CPE) for Providing Residential IPv6 Internet ServiceCurrent
January 2011
- RFC 5815Definitions of Managed Objects for IP Flow Information ExportObsoleted
April 2010
- RFC 8768Constrained Application Protocol (CoAP) Hop-Limit OptionCurrent
March 2020
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?