Re: L7 packet inspection
Surya ARBY <[email protected]> Thu, 28 Jan 2010 14:02:58 +0000 (GMT)
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0104175026== Content-Type: multipart/alternative; boundary="0-665994701-1264687378=:80605" --0-665994701-1264687378=:80605 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hello all. I'll jump into this discussion again to explain what is "L7 inspection" and= the associated products. Multiprotocol DPI (Deep Packet Inspection) : this is what you find in your = ACE, cisco ASA or any good network firewall. it works on multiple protocols= (FTP, SIP, DNS, RTSP, FTP...) and avoids protocol misuse and RFC complianc= e. Usually you can also filter requests/responses (for example with HTTP fixup= you can drop requests if the URL length is greater than n bytes, drop spec= ific HTTP methods (options, trace, connect, post...), looking for specific = patterns in the payload with regular expressions (if you want to drop reque= sts with specific headers, just build a custom rule to match the string of = character)... This is "basic" L7 inspection and filtering but the strength is that it's u= sually performed in hardware and it supports a lot of protocols (in ACE it'= s performed by NPs and not the control plane I guess) Then you have "application firewalls" (or Web App FW). These are dedicated = features or appliances working only on HTTP(S) - and mainly on Web-based ap= plications, this is not relevant to XML web services - to avoid most of "We= b attacks". What is usually implemented in these products are URL normalization, input = validation (against XSS or injection flaws for example), Referer check (aga= inst CSRF / forceful browsing), response rewriting, cryptography enforcemen= t (both at SSL and HTTP - cookies - layers), HTTP protocol and parameter en= forcement... Some LB vendors (F5, Citrix...) added these features (usually by adding a l= icense to your box) to their existing load balancers. Other vendors sell de= dicated appliances for this : Cisco (WAF/AXG), Denyall, Imperva... I talked only about Web based applications. Let's talk about Web services. = If you use massively XML with SOAP/REST architectures, some security needs = can come from this area. There are products enforcing XML security (it can = be embedded into the Application Firewalls feature described above) but als= o XML transformation. Cisco AXG (stands for XML Gateway) and IBM Datapower are the two players, t= heir products are some kind of "XML offload" platforms (XML security is onl= y a little part of what it does really, you can perform XML transformation,= XML routing...). Just a little overview of what can be embeded under "L7 inspection" :) regards, Surya --- En date de=C2=A0: Jeu 28.1.10, S. Stef=C3=A1n Sigur=C3=B0sson <stebbi@c= cpgames.com> a =C3=A9crit=C2=A0: De: S. Stef=C3=A1n Sigur=C3=B0sson <[email protected]> Objet: Re: [load balancing] L7 packet inspection =C3=80: "Load Balancing Mailing List" <[email protected]> Date: Jeudi 28 Janvier 2010, 11h52 =0A=0A=0A=0A=0A =0A=0A=0A=0A=0A=0A=0AWe are running MMO=0Ayou may have hear= d of www.eveonline.com,=0Anow our servers are spending a allot of power inv= estigating/authenticating=0Atraffic to make sure users are not modifying th= eir clients, trying sending inject=0Atheir own commands or trying to hack a= ccount.=C2=A0 We are looking into handing some=0Aof that work over to the S= LB or the network in front. Currently we are just=0Atrying to see what opti= ons we have and we don=E2=80=99t have any defined needs, we may=0Aeven repr= ogram some of our code to fit the L7 capabilities. =C2=A0=C2=A0Only thing I= can=0Asay for sure is that any increase in latency is really bad for us. = =0A=0A =C2=A0 =0A=0A =C2=A0 =0A=0A =C2=A0 =0A=0A =C2=A0 =0A=0A =C2=A0 =0A= =0A =C2=A0 =0A=0A=0A=0A=0A=0AFrom: [email protected]=0A[mailto:lb-l-bo= [email protected]] On Behalf Of Kenneth Salchow =0ASent: 27. jan=C3=BAar 2010 20:35 =0ATo: Load Balancing Mailing List =0ASubject: Re: [load balancing] L7 packet inspection =0A=0A=0A=0A=0A=0A = =C2=A0 =0A=0ASorry for delayed=0Aresponse=E2=80=94was having too much fun i= n Europe.=C2=A0 J =0A=0A =C2=A0 =0A=0APar usual, Ed, Tony=0Aand (increasing= ly) Surya have covered a lot of the bases here=E2=80=94what they didn=E2=80= =99t=0Aspecifically call out, but intimated, is that you really didn=E2=80= =99t specify *what*=0Ayou want to do at L7.=C2=A0 That=E2=80=99s a HUGE det= ermination in what you look for=0Aand who you but it from.=C2=A0 The produc= ts, prices and capabilities range=0Aquite widely=E2=80=94heck, even here at= F5 we have several different capabilities from=0Athe basic L7 capability i= n the ADC, to a protocol enforcement product to a=0Afull-fledged applicatio= n firewall.=C2=A0 Which solution makes the most sense=0Atotally depends on = what you want to do. =0A=0A =C2=A0 =0A=0AInstead of just=0Athrowing out var= ious products and vendors generically=E2=80=94can you narrow down your=0Ago= als a little?=C2=A0 =0A=0A =C2=A0 =0A=0AThanks, =0A=0A =C2=A0 =0A=0A=0A=0A= =0A =0A =0A KJ (Ken) Salchow, Jr. | Manager, Technical=0A Marketing =0A = =0A =0A =0A =0A D 651.423.1133 =0A =0A =0A M 612.868.1258 =0A =0A = =0A P 206.272.5555 =0A =0A =0A F 206.272.5555 =0A =0A =0A www.f5.com= =0A =0A =0A=0A=0A =C2=A0 =0A=0A =C2=A0 =0A=0A=0A=0A=0A=0AFrom:=0Alb-l-bou= [email protected] [mailto:[email protected]] On Behalf Of S.=0AStef=C3=A1= n Sigur=C3=B0sson =0ASent: Friday, January 22, 2010 5:28 AM =0ATo: [email protected] =0ASubject: [load balancing] L7 packet inspection =0A=0A=0A=0A=0A=0A =C2=A0= =0A=0AHi, my company=0Awants to start doing packet L7 inspection on all tr= affic going through the load=0Abalancer. =0A=0A =C2=A0 =0A=0ANow my concern= (cost aside) is how will I get the best=0Aperformance possible, ever ms co= unts. =0A=0A =C2=A0 =0A=0AWe are currently=0A=C2=A0using an Ace module to d= o our SLB and it has the option of L7 inspect but=0Awill that perform any b= etter than putting a good L7 firewall in front of the=0AACE. =0A=0A =C2=A0 = =0A=0AWe are still=0Ajust in the concept stage of this plan so any advice o= r good idea would be=0Agreatly appreciated.. =0A=0A =C2=A0 =0A=0AS. Stefan = =0A=0A=0A=0A=0A=0A =0A=0A -----La pi=C3=A8ce jointe associ=C3=A9e suit----- _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki =0A=0A=0A --0-665994701-1264687378=:80605 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <table cellspacing=3D"0" cellpadding=3D"0" border=3D"0" ><tr><td valign=3D"= top" style=3D"font: inherit;">Hello all.<br><br>I'll jump into this discuss= ion again to explain what is "L7 inspection" and the associated products.<b= r><br><br>Multiprotocol DPI (Deep Packet Inspection) : this is what you fin= d in your ACE, cisco ASA or any good network firewall. it works on multiple= protocols (FTP, SIP, DNS, RTSP, FTP...) and avoids protocol misuse and RFC= compliance.<br><br>Usually you can also filter requests/responses (for exa= mple with HTTP fixup you can drop requests if the URL length is greater tha= n <span style=3D"font-style: italic;">n</span> bytes, drop specific HTTP me= thods (options, trace, connect, post...), looking for specific patterns in = the payload with regular expressions (if you want to drop requests with spe= cific headers, just build a custom rule to match the string of character)..= .<br><br>This is "basic" L7 inspection and filtering but the strength is th= at it's usually performed in hardware and it supports a lot of protocols (in = ACE it's performed by NPs and not the control plane I guess)<br><br><br>The= n you have "application firewalls" (or Web App FW). These are dedicated fea= tures or appliances working only on HTTP(S) - and mainly on Web-based appli= cations, this is not relevant to XML web services - to avoid most of "Web a= ttacks".<br><br>What is usually implemented in these products are URL norma= lization, input validation (against XSS or injection flaws for example), Re= ferer check (against CSRF / forceful browsing), response rewriting, cryptog= raphy enforcement (both at SSL and HTTP - cookies - layers), HTTP protocol = and parameter enforcement...<br><br>Some LB vendors (F5, Citrix...) added t= hese features (usually by adding a license to your box) to their existing l= oad balancers. Other vendors sell dedicated appliances for this : Cisco (WA= F/AXG), Denyall, Imperva...<br><br><br>I talked only about Web based applications. Let's talk about Web services. If you use massively XML with= SOAP/REST architectures, some security needs can come from this area. Ther= e are products enforcing XML security (it can be embedded into the Applicat= ion Firewalls feature described above) but also XML transformation.<br><br>= Cisco AXG (stands for XML Gateway) and IBM Datapower are the two players, t= heir products are some kind of "XML offload" platforms (XML security is onl= y a little part of what it does really, you can perform XML transformation,= XML routing...).<br><br>Just a little overview of what can be embeded unde= r "L7 inspection" :)<br><br>regards,<br><br>Surya<br><br>--- En date de&nbs= p;: <b>Jeu 28.1.10, S. Stef=C3=A1n Sigur=C3=B0sson <i><[email protected]= om></i></b> a =C3=A9crit :<br><blockquote style=3D"border-left: 2px= solid rgb(16, 16, 255); margin-left: 5px; padding-left: 5px;"><br>De: S. S= tef=C3=A1n Sigur=C3=B0sson <[email protected]><br>Objet: Re: [load = balancing] L7 packet inspection<br>=C3=80: "Load Balancing Mailing List" <lb-l@vegan.= net><br>Date: Jeudi 28 Janvier 2010, 11h52<br><br><div id=3D"yiv81092580= 3">=0A=0A=0A=0A=0A =0A<style>=0A<!--=0A#yiv810925803 =0A _filtered #yiv810= 925803 {font-family:Wingdings;panose-1:5 0 0 0 0 0 0 0 0 0;}=0A _filtered #= yiv810925803 {font-family:"Cambria Math";panose-1:2 4 5 3 5 4 6 3 2 4;}=0A = _filtered #yiv810925803 {font-family:Calibri;panose-1:2 15 5 2 2 2 4 3 2 4;= }=0A _filtered #yiv810925803 {font-family:Tahoma;panose-1:2 11 6 4 3 5 4 4 = 2 4;}=0A#yiv810925803 =0A#yiv810925803 p.MsoNormal, #yiv810925803 li.MsoNo= rmal, #yiv810925803 div.MsoNormal=0A=09{margin:0cm;margin-bottom:.0001pt;fo= nt-size:11.0pt;font-family:"Calibri", "sans-serif";}=0A#yiv810925803 a:link= , #yiv810925803 span.MsoHyperlink=0A=09{color:blue;text-decoration:underlin= e;}=0A#yiv810925803 a:visited, #yiv810925803 span.MsoHyperlinkFollowed=0A= =09{color:purple;text-decoration:underline;}=0A#yiv810925803 span.EmailStyl= e17=0A=09{font-family:"Calibri", "sans-serif";color:windowtext;}=0A#yiv8109= 25803 span.EmailStyle18=0A=09{font-family:"Calibri", "sans-serif";color:#1F= 497D;}=0A#yiv810925803 span.EmailStyle19=0A=09{font-family:"Calibri", "sans= -serif";color:#1F497D;}=0A#yiv810925803 span.EmailStyle20=0A=09{font-family= :"Calibri", "sans-serif";color:#1F497D;}=0A#yiv810925803 .MsoChpDefault=0A= =09{font-size:10.0pt;}=0A _filtered #yiv810925803 {margin:70.85pt 70.85pt 7= 0.85pt 70.85pt;}=0A#yiv810925803 div.Section1=0A=09{}=0A-->=0A</style>=0A= =0A<div class=3D"Section1">=0A=0A<p class=3D"MsoNormal"><span style=3D"colo= r: rgb(31, 73, 125);" lang=3D"EN-US">We are running MMO=0Ayou may have hear= d of <a rel=3D"nofollow" target=3D"_blank" href=3D"http://www.eveonline.com= ">www.eveonline.com</a>,=0Anow our servers are spending a allot of power in= vestigating/authenticating=0Atraffic to make sure users are not modifying t= heir clients, trying sending inject=0Atheir own commands or trying to hack = account. We are looking into handing some=0Aof that work over to the = SLB or the network in front. Currently we are just=0Atrying to see what opt= ions we have and we don=E2=80=99t have any defined needs, we may=0Aeven rep= rogram some of our code to fit the L7 capabilities. Only thing = I can=0Asay for sure is that any increase in latency is really bad for us.<= /span></p> =0A=0A<p class=3D"MsoNormal"><span style=3D"color: rgb(31, 73, 1= 25);"> </span></p> =0A=0A<p class=3D"MsoNormal"><span style=3D"color:= rgb(31, 73, 125);"> </span></p> =0A=0A<p class=3D"MsoNormal"><span s= tyle=3D"color: rgb(31, 73, 125);"> </span></p> =0A=0A<p class=3D"MsoN= ormal"><span style=3D"color: rgb(31, 73, 125);"> </span></p> =0A=0A<p= class=3D"MsoNormal"><span style=3D"color: rgb(31, 73, 125);"> </span= ></p> =0A=0A<p class=3D"MsoNormal"><span style=3D"color: rgb(31, 73, 125);"= > </span></p> =0A=0A<div>=0A=0A<div style=3D"border-style: solid none= none; border-color: rgb(181, 196, 223) -moz-use-text-color -moz-use-text-c= olor; border-width: 1pt medium medium; padding: 3pt 0cm 0cm;">=0A=0A<p clas= s=3D"MsoNormal"><b><span style=3D"font-size: 10pt; font-family: "Tahom= a","sans-serif";" lang=3D"EN-US">From:</span></b><span style= =3D"font-size: 10pt; font-family: "Tahoma","sans-serif"= ;" lang=3D"EN-US"> [email protected]=0A[mailto:[email protected]]= <b>On Behalf Of </b>Kenneth Salchow<br>=0A<b>Sent:</b> 27. jan=C3=BAar 201= 0 20:35<br>=0A<b>To:</b> Load Balancing Mailing List<br>=0A<b>Subject:</b> = Re: [load balancing] L7 packet inspection</span></p> =0A=0A</div>=0A=0A</di= v>=0A=0A<p class=3D"MsoNormal"> </p> =0A=0A<p class=3D"MsoNormal"><sp= an style=3D"color: rgb(31, 73, 125);" lang=3D"EN-US">Sorry for delayed=0Are= sponse=E2=80=94was having too much fun in Europe. </span><span style= =3D"font-family: Wingdings; color: rgb(31, 73, 125);" lang=3D"EN-US">J</spa= n><span style=3D"color: rgb(31, 73, 125);" lang=3D"EN-US"></span></p> =0A= =0A<p class=3D"MsoNormal"><span style=3D"color: rgb(31, 73, 125);" lang=3D"= EN-US"> </span></p> =0A=0A<p class=3D"MsoNormal"><span style=3D"color= : rgb(31, 73, 125);" lang=3D"EN-US">Par usual, Ed, Tony=0Aand (increasingly= ) Surya have covered a lot of the bases here=E2=80=94what they didn=E2=80= =99t=0Aspecifically call out, but intimated, is that you really didn=E2=80= =99t specify *<b>what</b>*=0Ayou want to do at L7. That=E2=80=99s a H= UGE determination in what you look for=0Aand who you but it from. The= products, prices and capabilities range=0Aquite widely=E2=80=94heck, even = here at F5 we have several different capabilities from=0Athe basic L7 capab= ility in the ADC, to a protocol enforcement product to a=0Afull-fledged app= lication firewall. Which solution makes the most sense=0Atotally depe= nds on what you want to do.</span></p> =0A=0A<p class=3D"MsoNormal"><span s= tyle=3D"color: rgb(31, 73, 125);" lang=3D"EN-US"> </span></p> =0A=0A<= p class=3D"MsoNormal"><span style=3D"color: rgb(31, 73, 125);" lang=3D"EN-U= S">Instead of just=0Athrowing out various products and vendors generically= =E2=80=94can you narrow down your=0Agoals a little? </span></p> =0A= =0A<p class=3D"MsoNormal"><span style=3D"color: rgb(31, 73, 125);" lang=3D"= EN-US"> </span></p> =0A=0A<p class=3D"MsoNormal"><span style=3D"color= : rgb(31, 73, 125);" lang=3D"EN-US">Thanks,</span></p> =0A=0A<p class=3D"Ms= oNormal"><span style=3D"color: rgb(31, 73, 125);" lang=3D"EN-US"> </s= pan></p> =0A=0A<div>=0A=0A<table class=3D"MsoNormalTable" style=3D"width: 3= 18.75pt;" border=3D"0" cellpadding=3D"0" width=3D"425">=0A <tbody><tr>=0A = <td colspan=3D"5" style=3D"padding: 0.75pt;">=0A <p class=3D"MsoNormal"><b= ><span style=3D"font-size: 10pt; font-family: "Arial","sans-= serif"; color: rgb(31, 73, 125);">KJ (Ken) Salchow, Jr.</span></b><spa= n style=3D"font-size: 10pt; font-family: "Arial","sans-serif= "; color: rgb(31, 73, 125);"> | Manager, Technical=0A Marketing</span= ><span style=3D"font-size: 12pt; color: rgb(31, 73, 125);"></span></p> =0A = </td>=0A </tr>=0A <tr style=3D"height: 9pt;">=0A <td style=3D"padding: 0.= 75pt; width: 63pt; height: 9pt;" width=3D"84">=0A <p class=3D"MsoNormal" s= tyle=3D"line-height: 9pt;"><b><span style=3D"font-size: 7.5pt; font-family:= "Arial","sans-serif"; color: rgb(51, 51, 51);">D 651.4= 23.1133</span></b><span style=3D"font-size: 12pt; font-family: "Times = New Roman","serif"; color: rgb(31, 73, 125);"></span></p> = =0A </td>=0A <td style=3D"padding: 0.75pt; width: 63pt; height: 9pt;" wid= th=3D"84">=0A <p class=3D"MsoNormal" style=3D"line-height: 9pt;"><b><span = style=3D"font-size: 7.5pt; font-family: "Arial","sans-serif&= quot;; color: rgb(51, 51, 51);">M 612.868.1258</span></b><span style=3D"fon= t-size: 12pt; color: rgb(31, 73, 125);"></span></p> =0A </td>=0A <td styl= e=3D"padding: 0.75pt; width: 63pt; height: 9pt;" width=3D"84">=0A <p class= =3D"MsoNormal" style=3D"line-height: 9pt;"><b><span style=3D"font-size: 7.5= pt; font-family: "Arial","sans-serif"; color: rgb(51, 5= 1, 51);">P 206.272.5555</span></b><span style=3D"font-size: 12pt; color: rg= b(31, 73, 125);"></span></p> =0A </td>=0A <td style=3D"padding: 0.75pt; w= idth: 63pt; height: 9pt;" width=3D"84">=0A <p class=3D"MsoNormal" style=3D= "line-height: 9pt;"><b><span style=3D"font-size: 7.5pt; font-family: "= Arial","sans-serif"; color: rgb(51, 51, 51);">F 206.272.5555= </span></b><span style=3D"font-size: 12pt; color: rgb(31, 73, 125);"></span= ></p> =0A </td>=0A <td style=3D"padding: 0.75pt; width: 51.75pt; height: = 9pt;" width=3D"69">=0A <p class=3D"MsoNormal" style=3D"line-height: 9pt;">= <b><span style=3D"font-size: 7.5pt; font-family: "Arial","sa= ns-serif"; color: rgb(51, 51, 51);"><a rel=3D"nofollow" target=3D"_bla= nk" href=3D"http://www.f5.com/"><span style=3D"color: rgb(51, 51, 51);">www= .f5.com</span></a></span></b><span style=3D"font-size: 12pt; color: rgb(31,= 73, 125);"></span></p> =0A </td>=0A </tr>=0A</tbody></table>=0A=0A<p clas= s=3D"MsoNormal"><span style=3D"color: rgb(31, 73, 125);" lang=3D"EN-US"> &n= bsp;</span></p> =0A=0A<p class=3D"MsoNormal"><span style=3D"color: rgb(31, = 73, 125);" lang=3D"EN-US"> </span></p> =0A=0A<div>=0A=0A<div style=3D= "border-style: solid none none; border-color: rgb(181, 196, 223) -moz-use-t= ext-color -moz-use-text-color; border-width: 1pt medium medium; padding: 3p= t 0cm 0cm;">=0A=0A<p class=3D"MsoNormal" style=3D"margin-left: 36pt;"><b><s= pan style=3D"font-size: 10pt; font-family: "Tahoma","sans-se= rif";" lang=3D"EN-US">From:</span></b><span style=3D"font-size: 10pt; = font-family: "Tahoma","sans-serif";" lang=3D"EN-US">=0A= [email protected] [mailto:[email protected]] <b>On Behalf Of </b>= S.=0AStef=C3=A1n Sigur=C3=B0sson<br>=0A<b>Sent:</b> Friday, January 22, 201= 0 5:28 AM<br>=0A<b>To:</b> [email protected]<br>=0A<b>Subject:</b> [load balan= cing] L7 packet inspection</span></p> =0A=0A</div>=0A=0A</div>=0A=0A<p clas= s=3D"MsoNormal" style=3D"margin-left: 36pt;"><span lang=3D"EN-US"> </= span></p> =0A=0A<p class=3D"MsoNormal" style=3D"margin-left: 36pt;"><span l= ang=3D"EN-US">Hi, my company=0Awants to start doing packet L7 inspection on= all traffic going through the load=0Abalancer.</span></p> =0A=0A<p class= =3D"MsoNormal" style=3D"margin-left: 36pt;"><span lang=3D"EN-US"> </s= pan></p> =0A=0A<p class=3D"MsoNormal" style=3D"margin-left: 36pt;"><span la= ng=3D"EN-US">Now <span style=3D"color: rgb(31, 73, 125);">m</span>y concern= (cost aside) is how will I get the best=0Aperformance possible, ever ms co= unts.</span></p> =0A=0A<p class=3D"MsoNormal" style=3D"margin-left: 36pt;">= <span lang=3D"EN-US"> </span></p> =0A=0A<p class=3D"MsoNormal" style= =3D"margin-left: 36pt;"><span lang=3D"EN-US">We are currently=0A using= an Ace module to do our SLB and it has the option of L7 inspect but=0Awill= that perform any better than putting a good L7 firewall in front of the=0A= ACE.</span></p> =0A=0A<p class=3D"MsoNormal" style=3D"margin-left: 36pt;"><= span lang=3D"EN-US"> </span></p> =0A=0A<p class=3D"MsoNormal" style= =3D"margin-left: 36pt;"><span lang=3D"EN-US">We are still=0Ajust in the con= cept stage of this plan so any advice or good idea would be=0Agreatly appre= ciated..</span></p> =0A=0A<p class=3D"MsoNormal" style=3D"margin-left: 36pt= ;"> </p> =0A=0A<p class=3D"MsoNormal" style=3D"margin-left: 36pt;">S.= Stefan </p> =0A=0A</div>=0A=0A</div>=0A=0A =0A=0A</div><br>-----La pi=C3= =A8ce jointe associ=C3=A9e suit-----<br><br><div class=3D"plainMail">______= _________________________________________<br>lb-l mailing list<br><a ymailt= o=3D"mailto:[email protected]" href=3D"/mc/[email protected]">lb-l@v= egan.net</a><br><a href=3D"http://vegan.net/mailman/listinfo/lb-l" target= =3D"_blank">http://vegan.net/mailman/listinfo/lb-l</a><br>Searchable Archiv= e: <a href=3D"http://vegan.net/lb/archive" target=3D"_blank">http://vegan.n= et/lb/archive</a><br><a href=3D"http://lbdigest.com" target=3D"_blank">http= ://lbdigest.com</a> Load Balancing Digest<br><a href=3D"http://lbwiki.com" = target=3D"_blank">http://lbwiki.com</a> Load Balancing Wiki<br></div></bloc= kquote></td></tr></table><br>=0A=0A=0A=0A=0A --0-665994701-1264687378=:80605-- --===============0104175026== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============0104175026==--