Two questions:
1) I know that firewalls do packet inspection and extended access-list , of course will not but what exactly does packet inspection buy you? What are some examples of the kinds of packets a true firewall os would catch that an extended access-list would not?
2)Generally speaking, would an extended access-list on a router used in conjunction with other ios security enhancments (no ip http redirects, etc.) be secure enough in comparison to using a firewall ios? We also would have an ISS scanner in place to help catch problems.
Thanks,
1) I know that firewalls do packet inspection and extended access-list , of course will not but what exactly does packet inspection buy you? What are some examples of the kinds of packets a true firewall os would catch that an extended access-list would not?
2)Generally speaking, would an extended access-list on a router used in conjunction with other ios security enhancments (no ip http redirects, etc.) be secure enough in comparison to using a firewall ios? We also would have an ISS scanner in place to help catch problems.
Thanks,