If the firewall implementation fails in an unsecure manner (open), unauthorized traffic originating externally to the enclave may enter, or the device may permit unauthorized information release. Fail secure is a condition achieved by employing information system mechanisms to ensure, in the event of an operational failure of the firewall implementation, it does not enter into an unsecure state where intended security properties no longer hold.
If the device fails, it must not fail in a manner that will allow unauthorized access. If the firewall or other device implementing an ACL fails for any reason, it must stop forwarding traffic altogether or maintain the configured security policies. If the device stops forwarding traffic, maintaining network availability would be achieved through firewall redundancy. |