Re: Loadbalancer without using a Firewall...

Bill Blackford <[email protected]> Fri, 18 Dec 2009 10:05:16 -0800
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
PCI requires "firewalling" to be done between "DMZs". IOW, web front ends
and DB nodes have to be walled off from each other not just inbound
connections. Makes a good case for a solution such as FWSM or VLAN silos
seperated by strong firewall policies.

-b

On Fri, Dec 18, 2009 at 9:26 AM, John Wobus <[email protected]> wrote:

> I don't know the audit standards for financial ebank sites, but:
>
> Load balancers vary.  Some load balancers have functions that are identical
> with
> some firewall functions.  If those are the firewall functions you need,
> then it can serve the
> purpose.  I recall hearing of requirements within some regulations for a
> "stateful firewall"
> without comment about exactly how you must set it up.  At least some load
> balancers
> maintain the state of every tcp connection through it.
>
> However, it may be that administration of the load balancer and firewall
> function has to
> be given to different groups within the organization, and the organization
> may not
> want someone to have access to the firewall function every time the load
> balancing
> function needs adjustment.  Also, vendors may sell a firewall with some
> assurance that
> it protects but make no such claims regarding their load balancer, and such
> a claim may be
> important to your organization.  After the break-in, if the vendor says "we
> don't sell that
> device as a firewall", it can make matters more complicated for the
> organization.
>
> John
>
>
> On Dec 18, 2009, at 9:13 AM, Cihan Subasi (Garanti Teknoloji) wrote:
>
>  Hi all,
>>
>> I would like to know whether using only "a loadbalancer and an IPS" is
>> compliant with audit standards as far as an financial ebank site is
>> concerned. I have heard some portal sites use a loadbalancer without using a
>> network firewall in front. And this setup is recommended with an IPS because
>> a firewall is much more vulnerable to a DOS/DDOS and SYN attacks. I would
>> appreciate your opinions about compliancy of this setup and pros/cons.
>> Thanks
>>
>> This message and attachments are confidential and intended solely for the
>> individual(s) stated in this
>> message. If you received this message although you are not the addressee,
>> you are responsible to keep the
>> message confidential. The sender has no responsibility for the accuracy or
>> correctness of the
>> information in the message and its attachments. Our company shall have no
>> liability for any changes
>> or late receiving, loss of integrity and confidentiality, viruses and any
>> damages caused in
>> anyway to your computer system.
>>
>> Bu mesaj ve ekleri, mesajda gonderildigi belirtilen kisi/kisilere ozeldir
>> ve gizlidir. Bu mesajin muhatabi
>> olmamaniza ragmen tarafiniza ulasmis olmasi halinde mesaj iceriginin
>> gizliligi ve bu gizlilik yukumlulugune
>> uyulmasi zorunlulugu tarafiniz icin de soz konusudur. Mesaj ve eklerinde
>> yer alan bilgilerin dogrulugu ve
>> guncelligi konusunda gonderenin ya da sirketimizin herhangi bir
>> sorumlulugu bulunmamaktadir. Sirketimiz
>> mesajin ve bilgilerinin size degisiklige ugrayarak veya gec ulasmasindan,
>> butunlugunun ve gizliliginin
>> korunamamasindan, virus icermesinden ve bilgisayar sisteminize
>> verebilecegi herhangi bir zarardan
>> sorumlu tutulamaz.
>>
>> <ATT00001.c>
>>
>
> _______________________________________________
> lb-l mailing list
> [email protected]
> http://vegan.net/mailman/listinfo/lb-l
> Searchable Archive: http://vegan.net/lb/archive
> http://lbdigest.com Load Balancing Digest
> http://lbwiki.com Load Balancing Wiki
>



-- 
Bill Blackford
Network Engineer

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki