Re: L7 packet inspection
Ali Abbas <[email protected]> Sat, 30 Jan 2010 21:46:37 +0100
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0900360604== Content-Type: multipart/alternative; boundary=00151747688e5e813b047e67dac6 --00151747688e5e813b047e67dac6 Content-Type: text/plain; charset=ISO-8859-1 Hi Surya, I appreciate your attempt to give a short intro to Layer 7 Inspection, but I fear, some of your statements could be a bit miss-leading. Just for the sake of clarification ;-) > *Multiprotocol DPI (Deep Packet Inspection) : this is what you find in > your ACE, cisco ASA or any good network firewall. it works on multiple > protocols (FTP, SIP, DNS, RTSP, FTP...) and avoids protocol misuse and RFC > compliance.* > DPI is protocol independant... the type of payload you wishes to filter or mine will only be a specification of the ability of the DPI engine running on the network device. > > *This is "basic" L7 inspection and filtering but the strength is that it's > usually performed in hardware and it supports a lot of protocols (in ACE > it's performed by NPs and not the control plane I guess) > * > Right, also I personally would not see how inspection would take place in the control plane. We are not concerned about routing/forwaring primarely here, so that's exclusively surely not the case . For your information, all inline packet inspections (dpi/stateful etc...) only take place on the NPs. > *Then you have "application firewalls" (or Web App FW). These are > dedicated features or appliances working only on HTTP(S) - and mainly on > Web-based applications, this is not relevant to XML web services - to avoid > most of "Web attacks".* > First of all, they are 2 things, an Application Firewall and a WAF (Web Application Firewall). One is often just the appliance (the core), that is to say, a firewall being able to work with the application layer of the TCP/IP stack... in order words, a layer 7 firewall. So the AF would work with any applications, not only restricted to http/https. A WAF on the order hand is often just a plugin of the AF. I know... I know, some cheap brands out there advertize WAF as standalone appliance, but the WAF is simple an AF with a filter. just though I should clarify those points. -- Ali Abbas Blog: http://alouche.net --00151747688e5e813b047e67dac6 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Hi Surya,<br><br>I appreciate your attempt to give a short intro to Layer 7= Inspection, but I fear, some of your statements could be a bit miss-leadin= g. Just for the sake of clarification ;-)<br><br><div class=3D"gmail_quote"= > <blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, = 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"> <table border=3D"0" cellpadding=3D"0" cellspacing=3D"0"><tbody><tr><td styl= e=3D"font-family: inherit; font-style: inherit; font-variant: inherit; font= -weight: inherit; font-size: inherit; line-height: inherit; font-size-adjus= t: inherit; font-stretch: inherit;" valign=3D"top"> <br><i><b>Multiprotocol DPI (Deep Packet Inspection) : this is what you fin= d in your ACE, cisco ASA or any good network firewall. it works on multiple= protocols (FTP, SIP, DNS, RTSP, FTP...) and avoids protocol misuse and RFC= compliance.</b></i><br> </td></tr></tbody></table></blockquote><div><br>DPI is protocol independant= ... the type of payload you wishes to filter or mine will only be a specifi= cation of the ability of the DPI engine running on the network device.<br> =A0</div><blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid = rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"> <table border=3D"0" cellpadding=3D"0" cellspacing=3D"0"><tbody><tr><td styl= e=3D"font-family: inherit; font-style: inherit; font-variant: inherit; font= -weight: inherit; font-size: inherit; line-height: inherit; font-size-adjus= t: inherit; font-stretch: inherit;" valign=3D"top"> <br></td></tr></tbody></table></blockquote><blockquote class=3D"gmail_quote= " style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0= .8ex; padding-left: 1ex;"><table border=3D"0" cellpadding=3D"0" cellspacing= =3D"0"> <tbody><tr><td style=3D"font-family: inherit; font-style: inherit; font-var= iant: inherit; font-weight: inherit; font-size: inherit; line-height: inher= it; font-size-adjust: inherit; font-stretch: inherit;" valign=3D"top"><i><b= >This is "basic" L7 inspection and filtering but the strength is = that it's usually performed in hardware and it supports a lot of protocols = (in ACE it's performed by NPs and not the control plane I guess)<br></b= ></i><br></td></tr></tbody></table></blockquote><div><br>Right, also I pers= onally would not see how inspection would take place in the control plane. = We are not concerned about routing/forwaring primarely here, so that's = exclusively surely not the case . For your information, all inline packet i= nspections (dpi/stateful etc...) only take place on the NPs.<br> <br></div><blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid= rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"><table = border=3D"0" cellpadding=3D"0" cellspacing=3D"0"><tbody><tr><td style=3D"fo= nt-family: inherit; font-style: inherit; font-variant: inherit; font-weight= : inherit; font-size: inherit; line-height: inherit; font-size-adjust: inhe= rit; font-stretch: inherit;" valign=3D"top"> <br><i><b>Then you have "application firewalls" (or Web App FW). = These are dedicated features or appliances working only on HTTP(S) - and ma= inly on Web-based applications, this is not relevant to XML web services - = to avoid most of "Web attacks".</b></i><br> </td></tr></tbody></table></blockquote><div><br>First of all, they are 2 th= ings, an Application Firewall and a WAF (Web Application Firewall). One is = often just the appliance (the core), that is to say, a firewall being able = to work with the application layer of the TCP/IP stack... in order words, a= layer 7 firewall. So the AF would work with any applications, not only res= tricted to http/https.<br> <br>A WAF on the order hand is often just a plugin of the AF. I know... I k= now, some cheap brands out there advertize WAF as standalone appliance, but= the WAF is simple an AF with a filter.<br><br>just though I should clarify= those points.<br> <br>--<br>Ali Abbas<br>Blog: <a href=3D"http://alouche.net">http://alouche.= net</a><br><br> </div></div> --00151747688e5e813b047e67dac6-- --===============0900360604== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============0900360604==--