Bill Cheswick, a pioneer
in internet firewalls got, besides establishing what we today know as the
perimeter firewall, famous for the below quote to describe his ideas on
perimeter firewalls:
A sort of crunchy shell around a soft, chewy center.
The quote and metaphor is still used a lot by security professionals around
the world, to describe the state of the internal network behind the perimeter
firewall.
A crunchy shell in the 1990s was exactly the thing you needed to be more secure
from the threats found at that time. A lot of it was attacks against servers,
buffer and heap overflows on services directly exposed to the internet when not
consumed directly from the internet.
People could easily DoS or even better, hack, those services. Exposed sendmail
servers been a huge target at that time. Everything was exposed and routed, it is
hard to imagine today. The perimeter firewall did a great job and shielded the
vulnerable services from the evil internet and helped to secure them from the
outside world. The internet grew exponentially and threats changed quite
significantly and we all know that most threats today focus on endpoints rather
than datacenter services as a entry vector.