Re: L7 packet inspection
Surya ARBY <[email protected]> Sat, 23 Jan 2010 08:05:28 +0000 (GMT)
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0556994462== Content-Type: multipart/alternative; boundary="0-1088658226-1264233928=:62237" --0-1088658226-1264233928=:62237 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hello all. The L7 inspection feature on the ACE module/appliance is a multi protocol D= eep Packet Inspection (just similar to what is available in the Cisco ASA o= r any good network firewall). it supports DNS, HTTP, FTP, RTSP, SIP... it's limited for HTTP to the following implementation :=20 =0A=E2=80=A2 RFC compliance monitoring and RFC method filtering=0A=0A=0A=E2= =80=A2 Content, URL, and HTTP header length checks=0A=0A=0A=E2=80=A2 Transf= er-encoding methods=0A=0A=0A=E2=80=A2 Content type verification and filteri= ng=0A=0A=0A=E2=80=A2 Port 80 misuse=0A detailled configurations are found here : http://www.cisco.com/en/US/docs/i= nterfaces_modules/services_modules/ace/vA2_3_0/configuration/security/guide= /appinsp.html#wp1357262 About the Cisco WAF, Cisco sells a product called AXG which embeds a true H= TTP firewall (like imperva, denyall...) and a XML gateway providing XML tra= nsformation and security for SOAP/REST web services. Surya --- En date de=C2=A0: Ven 22.1.10, Tony Bourke <[email protected]> a =C3=A9cri= t=C2=A0: De: Tony Bourke <[email protected]> Objet: Re: [load balancing] L7 packet inspection =C3=80: "Load Balancing Mailing List" <[email protected]> Date: Vendredi 22 Janvier 2010, 22h06 Hello Stefan,=C2=A0 While the Cisco ACE does do some L7 inspection, that functionality is not m= eant as a true Web Application Firewall. =C2=A0Cisco has the ACE WAF (Web A= pplication Firewall) for that purpose, and is specifically a L7 firewall (s= crubbing HTTP messages as firewalls scrub IP packets). =C2=A0 There are als= o several other vendors (F5, etc.) that also sell stand-alone L7 firewalls.= =C2=A0 =C2=A0 Tony On Jan 22, 2010, at 3:28 AM, S. Stef=C3=A1n Sigur=C3=B0sson wrote: Hi, my company wants to start doing packet L7 inspection on all traffic goi= ng through the load balancer. =C2=A0Now=C2=A0my concern (cost aside) is how= will I get the best performance possible, ever ms counts. =C2=A0We are cur= rently =C2=A0using an Ace module to do our SLB and it has the option of L7 = inspect but will that perform any better than putting a good L7 firewall in= front of the ACE. =C2=A0We are still just in the concept stage of this pla= n so any advice or good idea would be greatly appreciated.. =C2=A0S. Stefan= _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive:=C2=A0http://vegan.net/lb/archive http://lbdigest.com=C2=A0Load Balancing Digest http://lbwiki.com=C2=A0Load Balancing Wiki -----La pi=C3=A8ce jointe associ=C3=A9e suit----- _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki =0A=0A=0A --0-1088658226-1264233928=:62237 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <table cellspacing=3D"0" cellpadding=3D"0" border=3D"0" ><tr><td valign=3D"= top" style=3D"font: inherit;">Hello all.<br><br>The L7 inspection feature o= n the ACE module/appliance is a multi protocol Deep Packet Inspection (just= similar to what is available in the Cisco ASA or any good network firewall= ). it supports DNS, HTTP, FTP, RTSP, SIP...<br><br>it's limited for HTTP to= the following implementation : <br><br><span class=3D"content"><p class=3D= "pBu1_Bullet1">=0A=E2=80=A2 RFC compliance monitoring and RFC method filter= ing=0A</p>=0A<a name=3D"wp1324625"></a><p class=3D"pBu1_Bullet1">=0A=E2=80= =A2 Content, URL, and HTTP header length checks=0A</p>=0A<a name=3D"wp13246= 26"></a><p class=3D"pBu1_Bullet1">=0A=E2=80=A2 Transfer-encoding methods=0A= </p>=0A<a name=3D"wp1324627"></a><p class=3D"pBu1_Bullet1">=0A=E2=80=A2 Con= tent type verification and filtering=0A</p>=0A<a name=3D"wp1324628"></a><p = class=3D"pBu1_Bullet1">=0A=E2=80=A2 Port 80 misuse=0A</p></span><br>detaill= ed configurations are found here : http://www.cisco.com/en/US/docs/interfac= es_modules/services_modules/ace/vA2_3_0/configuration/security/guide/appins= p.html#wp1357262<br><br>About the Cisco WAF, Cisco sells a product called A= XG which embeds a true HTTP firewall (like imperva, denyall...) and a XML g= ateway providing XML transformation and security for SOAP/REST web services= .<br><br>Surya<br><br>--- En date de : <b>Ven 22.1.10, Tony Bourke <i>= <[email protected]></i></b> a =C3=A9crit :<br><blockquote style=3D"= border-left: 2px solid rgb(16, 16, 255); margin-left: 5px; padding-left: 5p= x;"><br>De: Tony Bourke <[email protected]><br>Objet: Re: [load balancin= g] L7 packet inspection<br>=C3=80: "Load Balancing Mailing List" <lb-l@v= egan.net><br>Date: Vendredi 22 Janvier 2010, 22h06<br><br><div id=3D"yiv= 2014175807"><base>Hello Stefan, <div><br></div><div>While the Cisco AC= E does do some L7 inspection, that functionality is not meant as a true Web Application Firewall. Cisco has the ACE WAF (Web= Application Firewall) for that purpose, and is specifically a L7 firewall = (scrubbing HTTP messages as firewalls scrub IP packets). There are a= lso several other vendors (F5, etc.) that also sell stand-alone L7 firewall= s. </div><div><br></div><div>Tony</div><div><br></div><div><br= ></div><div><br></div><div><br><div><div>On Jan 22, 2010, at 3:28 AM, S. St= ef=C3=A1n Sigur=C3=B0sson wrote:</div><br class=3D"Apple-interchange-newlin= e"><blockquote type=3D"cite"><span class=3D"Apple-style-span" style=3D"bord= er-collapse: separate; font-family: Helvetica; font-size: medium; font-styl= e: normal; font-variant: normal; font-weight: normal; letter-spacing: norma= l; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none;= white-space: normal; widows: 2; word-spacing: 0px;"><div lang=3D"IS"><div = class=3D"Section1"><div style=3D"margin: 0cm 0cm 0.0001pt; font-size: 11pt;= font-family: Calibri,sans-serif;"><span lang=3D"EN-US">Hi, my company wants to start do= ing packet L7 inspection on all traffic going through the load balancer.</s= pan></div><div style=3D"margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-fam= ily: Calibri,sans-serif;"><span lang=3D"EN-US"> </span></div><div sty= le=3D"margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri,sans-= serif;"><span lang=3D"EN-US">Now<span class=3D"Apple-converted-space"> = ;</span><span style=3D"color: rgb(31, 73, 125);">m</span>y concern (cost as= ide) is how will I get the best performance possible, ever ms counts.</span= ></div><div style=3D"margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family= : Calibri,sans-serif;"><span lang=3D"EN-US"> </span></div><div style= =3D"margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri,sans-se= rif;"><span lang=3D"EN-US">We are currently using an Ace module to do= our SLB and it has the option of L7 inspect but will that perform any bett= er than putting a good L7 firewall in front of the ACE.</span></div><div style=3D"margin: = 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;"><span = lang=3D"EN-US"> </span></div><div style=3D"margin: 0cm 0cm 0.0001pt; = font-size: 11pt; font-family: Calibri,sans-serif;"><span lang=3D"EN-US">We = are still just in the concept stage of this plan so any advice or good idea= would be greatly appreciated..</span></div><div style=3D"margin: 0cm 0cm 0= .0001pt; font-size: 11pt; font-family: Calibri,sans-serif;"> </div><d= iv style=3D"margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri= ,sans-serif;">S. Stefan</div></div> _______________________________________= ________<br>lb-l mailing list<br><a rel=3D"nofollow" ymailto=3D"mailto:lb-l= @vegan.net" target=3D"_blank" href=3D"/mc/[email protected]" styl= e=3D"color: blue; text-decoration: underline;">[email protected]</a><br><a rel= =3D"nofollow" target=3D"_blank" href=3D"http://vegan.net/mailman/listinfo/l= b-l" style=3D"color: blue; text-decoration: underline;">http://vegan.net/mailman/listinfo/lb-l<= /a><br>Searchable Archive:<span class=3D"Apple-converted-space"> </spa= n><a rel=3D"nofollow" target=3D"_blank" href=3D"http://vegan.net/lb/archive= " style=3D"color: blue; text-decoration: underline;">http://vegan.net/lb/ar= chive</a><br><a rel=3D"nofollow" target=3D"_blank" href=3D"http://lbdigest.= com" style=3D"color: blue; text-decoration: underline;">http://lbdigest.com= </a><span class=3D"Apple-converted-space"> </span>Load Balancing Diges= t<br><a rel=3D"nofollow" target=3D"_blank" href=3D"http://lbwiki.com" style= =3D"color: blue; text-decoration: underline;">http://lbwiki.com</a><span cl= ass=3D"Apple-converted-space"> </span>Load Balancing Wiki<br></div></s= pan></blockquote></div><br></div></div><br>-----La pi=C3=A8ce jointe associ= =C3=A9e suit-----<br><br><div class=3D"plainMail">_________________________= ______________________<br>lb-l mailing list<br><a ymailto=3D"mailto:lb-l@ve= gan.net" href=3D"/mc/[email protected]">[email protected]</a><br><a href=3D"= http://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http://vegan.net/= mailman/listinfo/lb-l</a><br>Searchable Archive: <a href=3D"http://vegan.ne= t/lb/archive" target=3D"_blank">http://vegan.net/lb/archive</a><br><a href= =3D"http://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> Load Bal= ancing Digest<br><a href=3D"http://lbwiki.com" target=3D"_blank">http://lbw= iki.com</a> Load Balancing Wiki<br></div></blockquote></td></tr></table><br= >=0A=0A=0A=0A=0A --0-1088658226-1264233928=:62237-- --===============0556994462== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============0556994462==--