Re: L7 packet inspection

Ed Toro <[email protected]> Fri, 22 Jan 2010 09:44:17 -0500
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
Imperva has a L7 inspection device but it uses packet sniffing so it's =

more like an active IDS that sends resets to close connections. I'm not =

sure that model makes sense for security. You have to see the attack =

pass through before taking action. They also have an in-line mode but =

I'm not sure if it still lets attacks go through before stopping. =

There's also the issue of packet fragmentation and other obfuscation =

techniques that might get past a packet sniffing engine.

F5, Cisco and NetScaler use a reverse proxy architecture where they =

remove the traffic from the packet layer and inspect before sending to =

the server. They also inspect server return traffic. Of course, you will =

need to purchase hardware that can handle the load as Layer 7 inspection =

requires a lot of logic and CPU power. That can get expensive. This =

option probably also adds more latency than the Imperva model but I =

would argue that it is also more secure.



S. Stef=E1n Sigur=F0sson wrote:
>
> Hi, my company wants to start doing packet L7 inspection on all =

> traffic going through the load balancer.
>
>  =

>
> Now my concern (cost aside) is how will I get the best performance =

> possible, ever ms counts.
>
>  =

>
> We are currently  using an Ace module to do our SLB and it has the =

> option of L7 inspect but will that perform any better than putting a =

> good L7 firewall in front of the ACE.
>
>  =

>
> We are still just in the concept stage of this plan so any advice or =

> good idea would be greatly appreciated..
>
>  =

>
> S. Stefan
>

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki