Re: Third party certifications for LB
Kenneth Salchow <[email protected]>
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <4B18A8F75A6384449755BC7784073E935FEFF0222D@exch11.olympus.f5net.com> |
Absolutely-there is no separating these things from security. In fact-looking at the landscape-I've published a couple papers and done several presentations about what I might call the "dynamic perimeter". Basically-when you attempt to access an application, something like an ADC is the intermediary which determines where your request will be serviced (load distribution across datacenters-clouds-as well as servers), how your request will be serviced (do you need compression, what priority is the traffic, etc.), and finally what the security requirements of your request are (is it allowed, does it need to be encrypted, should it be run through IDS). So-for every application-you get a dynamically created perimeter that stretches from the server all the way to your device and it is context aware of the user, device, network, resource and business objectives. If you're interested (http://www.f5.com/pdf/white-papers/unifiedaccess-wp.pdf) is one of the original papers from 3 years ago-it's fairly high-level and vendor neutral; there should be others shortly. So-back to question at hand though-this is what I meant about the difficulty in creating an ADC certification. Some vendors might decide that IDS functionality belongs directly in the ADC whereas others might feel that it should be a separate device that the ADC routes traffic through on a dynamic, ad-hoc and policy driven basis. There are really good arguments either way-but the question is that if one vendor decides to put IDS in the box-does that mean the ADC certification needs to include IDS testing? The same thing would go for AV, firewalls, WAF, routing, etc. What happens if a vendor provides a platform and opens it up for 3rd-party plug-ins to run on the ADC (something that becomes even more likely with virtualization technologies-like Cisco ISRs running MS Domain controllers)? Who would be the final arbiter of 'what constitutes an ADC'? Anyway-I totally agree with you that, especially from the customer perspective, there continues to be a need for 3rd-party certification/verification; I'm just not convinced that we will ever see a complete, soup-to-nuts 'ADC' certification. For the foreseeable future, I think it is still too much of a moving target. But-that's just one nuts opinion, right? J KJ (Ken) Salchow, Jr. | Manager, Technical Marketing From: [email protected] [mailto:[email protected]] On Behalf Of Ravi Kumar Sent: Thursday, March 26, 2009 12:17 AM To: Load Balancing Mailing List Subject: Re: [load balancing] Third party certifications for LB Hi Ken, I agree with you. As of now, the individual modules like application firewall, protocol anomaly detection engines that are part of ADCs should be independently certified until some third party vendor comes up with a complete test suite tailored for ADCs. These certifications are must keeping in mind the rules set by Jericho forum <http://www.theopengroup.org/jericho/index.htm> . They believe in the De-perimeterisation <http://en.wikipedia.org/wiki/De-perimeterisation> of network security and its moving closer to the servers. In coming days, ADCs hold prominent rule to the security of server applications as they understand application better than edge network security devices. Thanks, -Ravi Chunduru 2009/3/25 Kenneth Salchow <[email protected]> Ravi, I think you are spot on, however, I also think this is a pretty daunting task. As you suggest, the number of features/functions being added into the ADC realm is becoming pretty significant. There are some pretty significant 'scope' issues here: no one agrees on which features should be or are incorporated into ADC. Personally, I would think that relying on the same certifications as the originating product/feature set is the first place to start. If an ADC incorporates a web-application firewall or a network-layer firewall, then that component should probably continue to participate in the same certification programs. The difficulty, of course, is that once all these features are put together, you can start doing new and interesting things that simply couldn't be done before. It's when these once disparate features start to intermingle that we start to have a really big problem-as there won't be any set standards at all. An interesting discussion though-I guess it boils down to this: do we need to test/certify the entire suite of functionality/features or should we test/certify agreed upon functionality separately? KJ (Ken) Salchow, Jr. | Manager, Technical Marketing From: [email protected] [mailto:[email protected]] On Behalf Of Ravi Kumar Sent: Tuesday, March 24, 2009 3:50 AM To: [email protected] Subject: Re: [load balancing] Third party certifications for LB With LBs evolving into ADCs, I believe thrid party certifications are needed. I have written in more detail about the need for certification. http://netlb.blogspot.com/2009/03/need-for-third-party-certification.html Thanks, -Ravi Chunduru On 3/23/09, Ravi Kumar <[email protected]> wrote: Hi List, Are there any third party certifications for the load balancers? I came across Tolly group which conducts tests when the vendor requests them. That too, Tolly group just concentrates on a given set of tests and will not cover entire box and features wide. And there is Gartner group classifying the lbs into magic quadrants based on the feature set but does not depend on the test results. The LB market lacks a genuine third party certification like NSS for Intrusion prevention systems. The third party certifications will help the customers to choose the best LB based on the performance and test results rather than carried away with the feature rich and marketing terminology. Let me know if you come across such certifications or call up the need with your reason for the certification of LB devices. Thanks, -Ravi Chunduru _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki
smime.p7s
(application/x-pkcs7-signature, 3 KB) - not displayed