Packet filtering solutions, such as routers, provide the most flexibility
as a firewall, but they have innate weaknesses. In this example, the router
permits some traffic to all hosts in the trusted network, exposing all hosts
to possible attacks. Also, the failure mode of packet filtering solutions
is poor-- if the packet filtering software is disabled, the trusted network
is left open to attack.