%% You should probably cite rfc7288 instead of this I-D. @techreport{iab-host-firewalls-01, number = {draft-iab-host-firewalls-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-iab-host-firewalls/01/}, author = {Dave Thaler}, title = {{Reflections On Host Firewalls}}, pagetotal = 13, year = 2014, month = feb, day = 14, abstract = {In today's Internet, the need for firewalls is generally accepted in the industry and indeed firewalls are widely deployed in practice. Often the result is that software may be running and potentially consuming resources, but then communication is blocked by a firewall. It's taken for granted that this end state is either desirable or the best that can be achieved in practice, rather than (for example) an end state where the relevant software is not running or is running in a way that would not result in unwanted communication. In this document, we explore the issues behind these assumptions and provide suggestions on improving the architecture going forward.}, }