Re: Loadbalancer without using a Firewall...

Dane Ruyle <[email protected]> Fri, 18 Dec 2009 18:55:36 -0500
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
I run without a FW infront.  The LB's are only open on the ports you configure them for, they ignore everything else.   FW adds some latency too (although, that is probably hardly measurable).   If you terminate SSL on the LB, that's cool too.   Only port 80 is open to the back-end webservers.

 

Not sure what OS you use but here's what I'd do -

 

Internet to LB.  LB to switch.  Servers connect to switch.   Servers have dedicated NIC for internet traffic (this is also the server's default gateway).  Disable Netbios on this NIC, everything but TCP/IP and port 80.   Server's second NIC goes to seperate switch.  Assign static routes to access back-end servers...  The switch is either locked down by ACLs, or in the case of a Financial scenario, the switch should uplink to a FW separating the web servers from the back end servers.  Wheeee  Switches all over the place.  Then again, for financial maybe I would add a FW in front.  Looks better on diagrams and in meeetings where they kind of expect you to have one; legacy.   If it came down to 2 company's - one had a FW in front and the other didn't, I bet the one with the FW would win.

 

Team the NICs, stack the switches if not using a chassis.

 

Some, if not all of the LBs can scan for malformed incoming traffic and drop it too.

 

That's my 2 cents. 

 


 


From: [email protected]
To: [email protected]
Date: Fri, 18 Dec 2009 16:13:51 +0200
Subject: [load balancing] Loadbalancer without using a Firewall...


Hi all,
 
I would like to know whether using only "a loadbalancer and an IPS" is compliant with audit standards as far as an financial ebank site is concerned. I have heard some portal sites use a loadbalancer without using a network firewall in front. And this setup is recommended with an IPS because a firewall is much more vulnerable to a DOS/DDOS and SYN attacks. I would appreciate your opinions about compliancy of this setup and pros/cons. Thanks





This message and attachments are confidential and intended solely for the individual(s) stated in this
message. If you received this message although you are not the addressee, you are responsible to keep the
message confidential. The sender has no responsibility for the accuracy or correctness of the
information in the message and its attachments. Our company shall have no liability for any changes
or late receiving, loss of integrity and confidentiality, viruses and any damages caused in
anyway to your computer system.





Bu mesaj ve ekleri, mesajda gonderildigi belirtilen kisi/kisilere ozeldir ve gizlidir. Bu mesajin muhatabi
olmamaniza ragmen tarafiniza ulasmis olmasi halinde mesaj iceriginin gizliligi ve bu gizlilik yukumlulugune
uyulmasi zorunlulugu tarafiniz icin de soz konusudur. Mesaj ve eklerinde yer alan bilgilerin dogrulugu ve
guncelligi konusunda gonderenin ya da sirketimizin herhangi bir sorumlulugu bulunmamaktadir. Sirketimiz
mesajin ve bilgilerinin size degisiklige ugrayarak veya gec ulasmasindan, butunlugunun ve gizliliginin
korunamamasindan, virus icermesinden ve bilgisayar sisteminize verebilecegi herhangi bir zarardan
sorumlu tutulamaz. 		 	   		  
_________________________________________________________________
Hotmail: Trusted email with powerful SPAM protection.
http://clk.atdmt.com/GBL/go/177141665/direct/01/

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki