Reflections on Host Firewalls (RFC7288)

[BLOCK-FILTER] discusses the issue of blocking or filtering abusive or objectionable content and communications, and the effects on the overall Internet architecture. This document complements that discussion by focusing on the architectural effects of host firewalls on hosts and applications.

Internet Architecture Board (IAB)                              D. Thaler Request for Comments: 7288                                     Microsoft Category: Informational                                        June 2014 ISSN: 2070-1721

                      Reflections on Host Firewalls


   In today's Internet, the need for firewalls is generally accepted in    the industry, and indeed firewalls are widely deployed in practice.    Unlike traditional firewalls that protect network links, host    firewalls run in end-user systems.  Often the result is that software    may be running and potentially consuming resources, but then    communication is blocked by a host firewall.  It's taken for granted    that this end state is either desirable or the best that can be    achieved in practice, rather than (for example) an end state where    the relevant software is not running or is running in a way that    would not result in unwanted communication.  In this document, we    explore the issues behind these assumptions and provide suggestions    on improving the architecture going forward.

