Games There's fail, there's epic fail, and then there's Sony. You may've thought it wasn't possible, but Sony has just outdone itself on the fail scale, forcing us to add yet another notch. During the congressional testimony this morning, Dr Gene Spafford of Purdue University revealed just how badly Sony managed its Playstation Network servers. It's... Bad.
by WereCatf on Fri 6th May 2011 15:32 UTC
They don't, in general. It's perfectly possible to make a server secure, from the network perspective, without a firewall. In fact, if a firewall is necessary the person who installed the server didn't do his job. Almost all properly designed software has built-in features for configuring access (tcpwrappers, apache allow/deny etc) and those features should be used.
In a properly configured server the firewall is an optional layer that increases security but isn't a necessity for the secure operation of the server.

Sadly, a lot of people seem to think that a firewall is a magic bullet that will protect your server from all harm and that it is somehow essential.

Of course, application security is an entirely different ballgame.

Installing a firewall is not about protecting the server per se, it's about protecting the network from the server.

