Re: Third party certifications for LB

Kenneth Salchow <[email protected]>
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <4B18A8F75A6384449755BC7784073E935FEFF0222D@exch11.olympus.f5net.com>
Absolutely-there is no separating these things from security.  In
fact-looking at the landscape-I've published a couple papers and done
several presentations about what I might call the "dynamic perimeter".
Basically-when you attempt to access an application, something like an ADC
is the intermediary which determines where your request will be serviced
(load distribution across datacenters-clouds-as well as servers), how your
request will be serviced (do you need compression, what priority is the
traffic, etc.), and finally what the security requirements of your request
are (is it allowed, does it need to be encrypted, should it be run through
IDS).  So-for every application-you get a dynamically created perimeter that
stretches from the server all the way to your device and it is context aware
of the user, device, network, resource and business objectives.  If you're
interested (http://www.f5.com/pdf/white-papers/unifiedaccess-wp.pdf) is one
of the original papers from 3 years ago-it's fairly high-level and vendor
neutral; there should be others shortly.

 

So-back to question at hand though-this is what I meant about the difficulty
in creating an ADC certification.  Some vendors might decide that IDS
functionality belongs directly in the ADC whereas others might feel that it
should be a separate device that the ADC routes traffic through on a
dynamic, ad-hoc and policy driven basis.  There are really good arguments
either way-but the question is that if one vendor decides to put IDS in the
box-does that mean the ADC certification needs to include IDS testing?  The
same thing would go for AV, firewalls, WAF, routing, etc.  What happens if a
vendor provides a platform and opens it up for 3rd-party plug-ins to run on
the ADC (something that becomes even more likely with virtualization
technologies-like Cisco ISRs running MS Domain controllers)? Who would be
the final arbiter of 'what constitutes an ADC'?  

 

Anyway-I totally agree with you that, especially from the customer
perspective, there continues to be a need for 3rd-party
certification/verification; I'm just not convinced that we will ever see a
complete, soup-to-nuts 'ADC' certification.  For the foreseeable future, I
think it is still too much of a moving target.

 

But-that's just one nuts opinion, right?  J

 

KJ (Ken) Salchow, Jr.  |  Manager, Technical Marketing

 

From: [email protected] [mailto:[email protected]] On Behalf Of
Ravi Kumar
Sent: Thursday, March 26, 2009 12:17 AM
To: Load Balancing Mailing List
Subject: Re: [load balancing] Third party certifications for LB

 

Hi Ken,
  I agree with you. As of now, the individual modules like application
firewall, protocol anomaly detection engines that are part of ADCs should be
independently certified until some third party vendor comes up with a
complete test suite tailored for ADCs.

These certifications are must keeping in mind the rules set by Jericho forum
<http://www.theopengroup.org/jericho/index.htm> . They believe in  the
De-perimeterisation <http://en.wikipedia.org/wiki/De-perimeterisation>  of
network security and its moving closer to the servers. In coming days, ADCs
hold prominent rule to the security of server applications as they
understand application better than edge network security devices.

Thanks,
-Ravi Chunduru

2009/3/25 Kenneth Salchow <[email protected]>

Ravi,

 

I think you are spot on, however, I also think this is a pretty daunting
task.  As you suggest, the number of features/functions being added into the
ADC realm is becoming pretty significant.  There are some pretty significant
'scope' issues here: no one agrees on which features should be or are
incorporated into ADC.

 

Personally, I would think that relying on the same certifications as the
originating product/feature set is the first place to start.  If an ADC
incorporates a web-application firewall or a network-layer firewall, then
that component should probably continue to participate in the same
certification programs.  The difficulty, of course, is that once all these
features are put together, you can start doing new and interesting things
that simply couldn't be done before.  It's when these once disparate
features start to intermingle that we start to have a really big problem-as
there won't be any set standards at all.

 

An interesting discussion though-I guess it boils down to this: do we need
to test/certify the entire suite of functionality/features or should we
test/certify agreed upon functionality separately?

 

KJ (Ken) Salchow, Jr.  |  Manager, Technical Marketing

 

From: [email protected] [mailto:[email protected]] On Behalf Of
Ravi Kumar
Sent: Tuesday, March 24, 2009 3:50 AM
To: [email protected]
Subject: Re: [load balancing] Third party certifications for LB

 

With LBs evolving into ADCs, I believe thrid party certifications are
needed.

I have written in more detail about the need for certification.

http://netlb.blogspot.com/2009/03/need-for-third-party-certification.html

 

Thanks,

-Ravi Chunduru

 

On 3/23/09, Ravi Kumar <[email protected]> wrote: 

Hi List,
   Are there any third party certifications for the load balancers?

I came across Tolly group which conducts tests when the vendor requests
them.
That too, Tolly group just concentrates on a given set of tests and will not
cover entire box and features wide.
And there is Gartner group classifying the lbs into magic quadrants based on
the feature set but does not depend on the test results.

The LB market lacks a genuine third party certification like NSS for
Intrusion prevention systems.

The third party certifications will help the customers to choose the best LB
based on the performance and test results rather than carried away with the
feature rich and marketing terminology.

Let me know if you come across such certifications or call up the need with
your reason for the certification of LB devices.

Thanks,
-Ravi Chunduru

 


_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki
smime.p7s (application/x-pkcs7-signature, 3 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.