Re: L7 packet inspection
Ed Toro <[email protected]> Fri, 22 Jan 2010 09:44:17 -0500
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
Imperva has a L7 inspection device but it uses packet sniffing so it's = more like an active IDS that sends resets to close connections. I'm not = sure that model makes sense for security. You have to see the attack = pass through before taking action. They also have an in-line mode but = I'm not sure if it still lets attacks go through before stopping. = There's also the issue of packet fragmentation and other obfuscation = techniques that might get past a packet sniffing engine. F5, Cisco and NetScaler use a reverse proxy architecture where they = remove the traffic from the packet layer and inspect before sending to = the server. They also inspect server return traffic. Of course, you will = need to purchase hardware that can handle the load as Layer 7 inspection = requires a lot of logic and CPU power. That can get expensive. This = option probably also adds more latency than the Imperva model but I = would argue that it is also more secure. S. Stef=E1n Sigur=F0sson wrote: > > Hi, my company wants to start doing packet L7 inspection on all = > traffic going through the load balancer. > > = > > Now my concern (cost aside) is how will I get the best performance = > possible, ever ms counts. > > = > > We are currently using an Ace module to do our SLB and it has the = > option of L7 inspect but will that perform any better than putting a = > good L7 firewall in front of the ACE. > > = > > We are still just in the concept stage of this plan so any advice or = > good idea would be greatly appreciated.. > > = > > S. Stefan > _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki