Re: L7 packet inspection

Ali Abbas <[email protected]> Sat, 30 Jan 2010 21:46:37 +0100
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
--===============0900360604==
Content-Type: multipart/alternative; boundary=00151747688e5e813b047e67dac6

--00151747688e5e813b047e67dac6
Content-Type: text/plain; charset=ISO-8859-1

Hi Surya,

I appreciate your attempt to give a short intro to Layer 7 Inspection, but I
fear, some of your statements could be a bit miss-leading. Just for the sake
of clarification ;-)


> *Multiprotocol DPI (Deep Packet Inspection) : this is what you find in
> your ACE, cisco ASA or any good network firewall. it works on multiple
> protocols (FTP, SIP, DNS, RTSP, FTP...) and avoids protocol misuse and RFC
> compliance.*
>

DPI is protocol independant... the type of payload you wishes to filter or
mine will only be a specification of the ability of the DPI engine running
on the network device.


>
> *This is "basic" L7 inspection and filtering but the strength is that it's
> usually performed in hardware and it supports a lot of protocols (in ACE
> it's performed by NPs and not the control plane I guess)
> *
>

Right, also I personally would not see how inspection would take place in
the control plane. We are not concerned about routing/forwaring primarely
here, so that's exclusively surely not the case . For your information, all
inline packet inspections (dpi/stateful etc...) only take place on the NPs.


> *Then you have "application firewalls" (or Web App FW). These are
> dedicated features or appliances working only on HTTP(S) - and mainly on
> Web-based applications, this is not relevant to XML web services - to avoid
> most of "Web attacks".*
>

First of all, they are 2 things, an Application Firewall and a WAF (Web
Application Firewall). One is often just the appliance (the core), that is
to say, a firewall being able to work with the application layer of the
TCP/IP stack... in order words, a layer 7 firewall. So the AF would work
with any applications, not only restricted to http/https.

A WAF on the order hand is often just a plugin of the AF. I know... I know,
some cheap brands out there advertize WAF as standalone appliance, but the
WAF is simple an AF with a filter.

just though I should clarify those points.

--
Ali Abbas
Blog: http://alouche.net

--00151747688e5e813b047e67dac6
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi Surya,<br><br>I appreciate your attempt to give a short intro to Layer 7=
 Inspection, but I fear, some of your statements could be a bit miss-leadin=
g. Just for the sake of clarification ;-)<br><br><div class=3D"gmail_quote"=
>

<blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, =
204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<table border=3D"0" cellpadding=3D"0" cellspacing=3D"0"><tbody><tr><td styl=
e=3D"font-family: inherit; font-style: inherit; font-variant: inherit; font=
-weight: inherit; font-size: inherit; line-height: inherit; font-size-adjus=
t: inherit; font-stretch: inherit;" valign=3D"top">


<br><i><b>Multiprotocol DPI (Deep Packet Inspection) : this is what you fin=
d in your ACE, cisco ASA or any good network firewall. it works on multiple=
 protocols (FTP, SIP, DNS, RTSP, FTP...) and avoids protocol misuse and RFC=
 compliance.</b></i><br>


</td></tr></tbody></table></blockquote><div><br>DPI is protocol independant=
... the type of payload you wishes to filter or mine will only be a specifi=
cation of the ability of the DPI engine running on the network device.<br>

=A0</div><blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid =
rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<table border=3D"0" cellpadding=3D"0" cellspacing=3D"0"><tbody><tr><td styl=
e=3D"font-family: inherit; font-style: inherit; font-variant: inherit; font=
-weight: inherit; font-size: inherit; line-height: inherit; font-size-adjus=
t: inherit; font-stretch: inherit;" valign=3D"top">


<br></td></tr></tbody></table></blockquote><blockquote class=3D"gmail_quote=
" style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0=
.8ex; padding-left: 1ex;"><table border=3D"0" cellpadding=3D"0" cellspacing=
=3D"0">


<tbody><tr><td style=3D"font-family: inherit; font-style: inherit; font-var=
iant: inherit; font-weight: inherit; font-size: inherit; line-height: inher=
it; font-size-adjust: inherit; font-stretch: inherit;" valign=3D"top"><i><b=
>This is &quot;basic&quot; L7 inspection and filtering but the strength is =
that
 it&#39;s usually performed in hardware and it supports a lot of protocols =
(in ACE it&#39;s performed by NPs and not the control plane I guess)<br></b=
></i><br></td></tr></tbody></table></blockquote><div><br>Right, also I pers=
onally would not see how inspection would take place in the control plane. =
We are not concerned about routing/forwaring primarely here, so that&#39;s =
exclusively surely not the case . For your information, all inline packet i=
nspections (dpi/stateful etc...) only take place on the NPs.<br>

<br></div><blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid=
 rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"><table =
border=3D"0" cellpadding=3D"0" cellspacing=3D"0"><tbody><tr><td style=3D"fo=
nt-family: inherit; font-style: inherit; font-variant: inherit; font-weight=
: inherit; font-size: inherit; line-height: inherit; font-size-adjust: inhe=
rit; font-stretch: inherit;" valign=3D"top">

<br><i><b>Then you have &quot;application firewalls&quot; (or Web App FW). =
These are dedicated features or appliances working only on HTTP(S) - and ma=
inly on Web-based applications, this is not relevant to XML web services - =
to avoid most of &quot;Web attacks&quot;.</b></i><br>


</td></tr></tbody></table></blockquote><div><br>First of all, they are 2 th=
ings, an Application Firewall and a WAF (Web Application Firewall). One is =
often just the appliance (the core), that is to say, a firewall being able =
to work with the application layer of the TCP/IP stack... in order words, a=
 layer 7 firewall. So the AF would work with any applications, not only res=
tricted to http/https.<br>

<br>A WAF on the order hand is often just a plugin of the AF. I know... I k=
now, some cheap brands out there advertize WAF as standalone appliance, but=
 the WAF is simple an AF with a filter.<br><br>just though I should clarify=
 those points.<br>

<br>--<br>Ali Abbas<br>Blog: <a href=3D"http://alouche.net">http://alouche.=
net</a><br><br>
</div></div>

--00151747688e5e813b047e67dac6--

--===============0900360604==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0900360604==--