Re: L7 packet inspection
Surya ARBY <[email protected]> Sat, 30 Jan 2010 21:21:21 +0000 (GMT)
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0801298877== Content-Type: multipart/alternative; boundary="0-1676897632-1264886481=:32209" --0-1676897632-1264886481=:32209 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Hello Ali. I tried to explain this grossly. Just about the second point, I know there are some specific features (on fl= ows passing through device) processed in the control plane on the ACE appli= ance (all that can't be processed by the octeon micro engines reaches the c= ontrol plane, it follows a traditionnal design of a switch), I don't know h= ow ACE module is built :) Surya=20 --- En date de=A0: Sam 30.1.10, Ali Abbas <[email protected]> a =E9crit= =A0: De: Ali Abbas <[email protected]> Objet: Re: [load balancing] L7 packet inspection =C0: "Load Balancing Mailing List" <[email protected]> Date: Samedi 30 Janvier 2010, 21h46 Hi Surya, I appreciate your attempt to give a short intro to Layer 7 Inspection, but = I fear, some of your statements could be a bit miss-leading. Just for the s= ake of clarification ;-) =0A=0A=0A=0A=0A=0A Multiprotocol DPI (Deep Packet Inspection) : this is what you find in your = ACE, cisco ASA or any good network firewall. it works on multiple protocols= (FTP, SIP, DNS, RTSP, FTP...) and avoids protocol misuse and RFC complianc= e. =0A=0A=0A DPI is protocol independant... the type of payload you wishes to filter or = mine will only be a specification of the ability of the DPI engine running = on the network device. =0A=0A=A0=0A=0A=0A=0A =0A=0A=0AThis is "basic" L7 inspection and filtering but the strength is th= at=0A it's usually performed in hardware and it supports a lot of protocols= (in ACE it's performed by NPs and not the control plane I guess) Right, also I personally would not see how inspection would take place in t= he control plane. We are not concerned about routing/forwaring primarely he= re, so that's exclusively surely not the case . For your information, all i= nline packet inspections (dpi/stateful etc...) only take place on the NPs. =0A=0A =0A=0A Then you have "application firewalls" (or Web App FW). These are dedicated = features or appliances working only on HTTP(S) - and mainly on Web-based ap= plications, this is not relevant to XML web services - to avoid most of "We= b attacks". =0A=0A=0A First of all, they are 2 things, an Application Firewall and a WAF (Web App= lication Firewall). One is often just the appliance (the core), that is to = say, a firewall being able to work with the application layer of the TCP/IP= stack... in order words, a layer 7 firewall. So the AF would work with any= applications, not only restricted to http/https. =0A=0A A WAF on the order hand is often just a plugin of the AF. I know... I know,= some cheap brands out there advertize WAF as standalone appliance, but the= WAF is simple an AF with a filter. just though I should clarify those points. =0A=0A -- Ali Abbas Blog: http://alouche.net =0A=0A -----La pi=E8ce jointe associ=E9e suit----- _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki =0A=0A=0A --0-1676897632-1264886481=:32209 Content-Type: text/html; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable <table cellspacing=3D"0" cellpadding=3D"0" border=3D"0" ><tr><td valign=3D"= top" style=3D"font: inherit;">Hello Ali.<br><br>I tried to explain this gro= ssly.<br><br>Just about the second point, I know there are some specific fe= atures (on flows passing through device) processed in the control plane on = the ACE appliance (all that can't be processed by the octeon micro engines = reaches the control plane, it follows a traditionnal design of a switch), I= don't know how ACE module is built :)<br><br>Surya <br><br>--- En date de&= nbsp;: <b>Sam 30.1.10, Ali Abbas <i><[email protected]></i></b> a = =E9crit :<br><blockquote style=3D"border-left: 2px solid rgb(16, 16, 2= 55); margin-left: 5px; padding-left: 5px;"><br>De: Ali Abbas <alouche07@= gmail.com><br>Objet: Re: [load balancing] L7 packet inspection<br>=C0: "= Load Balancing Mailing List" <[email protected]><br>Date: Samedi 30 Janv= ier 2010, 21h46<br><br><div id=3D"yiv1741736201">Hi Surya,<br><br>I appreci= ate your attempt to give a short intro to Layer 7 Inspection, but I fear, some of y= our statements could be a bit miss-leading. Just for the sake of clarificat= ion ;-)<br><br><div class=3D"gmail_quote">=0A=0A<blockquote class=3D"gmail_= quote" style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt = 0pt 0.8ex; padding-left: 1ex;">=0A<table border=3D"0" cellpadding=3D"0" cel= lspacing=3D"0"><tbody><tr><td style=3D"font-family: inherit; font-style: in= herit; font-variant: inherit; font-weight: inherit; font-size: inherit; lin= e-height: inherit; font-size-adjust: inherit; font-stretch: inherit;" valig= n=3D"top">=0A=0A=0A<br><i><b>Multiprotocol DPI (Deep Packet Inspection) : t= his is what you find in your ACE, cisco ASA or any good network firewall. i= t works on multiple protocols (FTP, SIP, DNS, RTSP, FTP...) and avoids prot= ocol misuse and RFC compliance.</b></i><br>=0A=0A=0A</td></tr></tbody></tab= le></blockquote><div><br>DPI is protocol independant... the type of payload= you wishes to filter or mine will only be a specification of the ability o= f the DPI engine running on the network device.<br>=0A=0A </div><block= quote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, 204, 2= 04); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">=0A<table border=3D"0" = cellpadding=3D"0" cellspacing=3D"0"><tbody><tr><td style=3D"font-family: in= herit; font-style: inherit; font-variant: inherit; font-weight: inherit; fo= nt-size: inherit; line-height: inherit; font-size-adjust: inherit; font-str= etch: inherit;" valign=3D"top">=0A=0A=0A<br></td></tr></tbody></table></blo= ckquote><blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid r= gb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"><table bo= rder=3D"0" cellpadding=3D"0" cellspacing=3D"0">=0A=0A=0A<tbody><tr><td styl= e=3D"font-family: inherit; font-style: inherit; font-variant: inherit; font= -weight: inherit; font-size: inherit; line-height: inherit; font-size-adjus= t: inherit; font-stretch: inherit;" valign=3D"top"><i><b>This is "basic" L7= inspection and filtering but the strength is that=0A it's usually performe= d in hardware and it supports a lot of protocols (in ACE it's performed by = NPs and not the control plane I guess)<br></b></i><br></td></tr></tbody></t= able></blockquote><div><br>Right, also I personally would not see how inspe= ction would take place in the control plane. We are not concerned about rou= ting/forwaring primarely here, so that's exclusively surely not the case . = For your information, all inline packet inspections (dpi/stateful etc...) o= nly take place on the NPs.<br>=0A=0A<br></div><blockquote class=3D"gmail_qu= ote" style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0p= t 0.8ex; padding-left: 1ex;"><table border=3D"0" cellpadding=3D"0" cellspac= ing=3D"0"><tbody><tr><td style=3D"font-family: inherit; font-style: inherit= ; font-variant: inherit; font-weight: inherit; font-size: inherit; line-hei= ght: inherit; font-size-adjust: inherit; font-stretch: inherit;" valign=3D"= top">=0A=0A<br><i><b>Then you have "application firewalls" (or Web App FW).= These are dedicated features or appliances working only on HTTP(S) - and m= ainly on Web-based applications, this is not relevant to XML web services -= to avoid most of "Web attacks".</b></i><br>=0A=0A=0A</td></tr></tbody></ta= ble></blockquote><div><br>First of all, they are 2 things, an Application F= irewall and a WAF (Web Application Firewall). One is often just the applian= ce (the core), that is to say, a firewall being able to work with the appli= cation layer of the TCP/IP stack... in order words, a layer 7 firewall. So = the AF would work with any applications, not only restricted to http/https.= <br>=0A=0A<br>A WAF on the order hand is often just a plugin of the AF. I k= now... I know, some cheap brands out there advertize WAF as standalone appl= iance, but the WAF is simple an AF with a filter.<br><br>just though I shou= ld clarify those points.<br>=0A=0A<br>--<br>Ali Abbas<br>Blog: <a rel=3D"no= follow" target=3D"_blank" href=3D"http://alouche.net">http://alouche.net</a= ><br><br>=0A</div></div>=0A</div><br>-----La pi=E8ce jointe associ=E9e suit= -----<br><br><div class=3D"plainMail">_____________________________________= __________<br>lb-l mailing list<br><a ymailto=3D"mailto:[email protected]" hre= f=3D"/mc/[email protected]">[email protected]</a><br><a href=3D"http= ://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http://vegan.net/mail= man/listinfo/lb-l</a><br>Searchable Archive: <a href=3D"http://vegan.net/lb= /archive" target=3D"_blank">http://vegan.net/lb/archive</a><br><a href=3D"h= ttp://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> Load Balancin= g Digest<br><a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.c= om</a> Load Balancing Wiki<br></div></blockquote></td></tr></table><br>=0A= =0A=0A=0A=0A --0-1676897632-1264886481=:32209-- --===============0801298877== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============0801298877==--