Re: Loadbalancer without using a Firewall...
Bill Blackford <[email protected]> Fri, 18 Dec 2009 10:05:16 -0800
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
PCI requires "firewalling" to be done between "DMZs". IOW, web front ends and DB nodes have to be walled off from each other not just inbound connections. Makes a good case for a solution such as FWSM or VLAN silos seperated by strong firewall policies. -b On Fri, Dec 18, 2009 at 9:26 AM, John Wobus <[email protected]> wrote: > I don't know the audit standards for financial ebank sites, but: > > Load balancers vary. Some load balancers have functions that are identical > with > some firewall functions. If those are the firewall functions you need, > then it can serve the > purpose. I recall hearing of requirements within some regulations for a > "stateful firewall" > without comment about exactly how you must set it up. At least some load > balancers > maintain the state of every tcp connection through it. > > However, it may be that administration of the load balancer and firewall > function has to > be given to different groups within the organization, and the organization > may not > want someone to have access to the firewall function every time the load > balancing > function needs adjustment. Also, vendors may sell a firewall with some > assurance that > it protects but make no such claims regarding their load balancer, and such > a claim may be > important to your organization. After the break-in, if the vendor says "we > don't sell that > device as a firewall", it can make matters more complicated for the > organization. > > John > > > On Dec 18, 2009, at 9:13 AM, Cihan Subasi (Garanti Teknoloji) wrote: > > Hi all, >> >> I would like to know whether using only "a loadbalancer and an IPS" is >> compliant with audit standards as far as an financial ebank site is >> concerned. I have heard some portal sites use a loadbalancer without using a >> network firewall in front. And this setup is recommended with an IPS because >> a firewall is much more vulnerable to a DOS/DDOS and SYN attacks. I would >> appreciate your opinions about compliancy of this setup and pros/cons. >> Thanks >> >> This message and attachments are confidential and intended solely for the >> individual(s) stated in this >> message. If you received this message although you are not the addressee, >> you are responsible to keep the >> message confidential. The sender has no responsibility for the accuracy or >> correctness of the >> information in the message and its attachments. Our company shall have no >> liability for any changes >> or late receiving, loss of integrity and confidentiality, viruses and any >> damages caused in >> anyway to your computer system. >> >> Bu mesaj ve ekleri, mesajda gonderildigi belirtilen kisi/kisilere ozeldir >> ve gizlidir. Bu mesajin muhatabi >> olmamaniza ragmen tarafiniza ulasmis olmasi halinde mesaj iceriginin >> gizliligi ve bu gizlilik yukumlulugune >> uyulmasi zorunlulugu tarafiniz icin de soz konusudur. Mesaj ve eklerinde >> yer alan bilgilerin dogrulugu ve >> guncelligi konusunda gonderenin ya da sirketimizin herhangi bir >> sorumlulugu bulunmamaktadir. Sirketimiz >> mesajin ve bilgilerinin size degisiklige ugrayarak veya gec ulasmasindan, >> butunlugunun ve gizliliginin >> korunamamasindan, virus icermesinden ve bilgisayar sisteminize >> verebilecegi herhangi bir zarardan >> sorumlu tutulamaz. >> >> <ATT00001.c> >> > > _______________________________________________ > lb-l mailing list > [email protected] > http://vegan.net/mailman/listinfo/lb-l > Searchable Archive: http://vegan.net/lb/archive > http://lbdigest.com Load Balancing Digest > http://lbwiki.com Load Balancing Wiki > -- Bill Blackford Network Engineer _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki