Re: L7 packet inspection

Surya ARBY <[email protected]> Sat, 30 Jan 2010 21:21:21 +0000 (GMT)
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
--===============0801298877==
Content-Type: multipart/alternative; boundary="0-1676897632-1264886481=:32209"

--0-1676897632-1264886481=:32209
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable

Hello Ali.

I tried to explain this grossly.

Just about the second point, I know there are some specific features (on fl=
ows passing through device) processed in the control plane on the ACE appli=
ance (all that can't be processed by the octeon micro engines reaches the c=
ontrol plane, it follows a traditionnal design of a switch), I don't know h=
ow ACE module is built :)

Surya=20

--- En date de=A0: Sam 30.1.10, Ali Abbas <[email protected]> a =E9crit=
=A0:

De: Ali Abbas <[email protected]>
Objet: Re: [load balancing] L7 packet inspection
=C0: "Load Balancing Mailing List" <[email protected]>
Date: Samedi 30 Janvier 2010, 21h46

Hi Surya,

I appreciate your attempt to give a short intro to Layer 7 Inspection, but =
I fear, some of your statements could be a bit miss-leading. Just for the s=
ake of clarification ;-)

=0A=0A=0A=0A=0A=0A
Multiprotocol DPI (Deep Packet Inspection) : this is what you find in your =
ACE, cisco ASA or any good network firewall. it works on multiple protocols=
 (FTP, SIP, DNS, RTSP, FTP...) and avoids protocol misuse and RFC complianc=
e.
=0A=0A=0A
DPI is protocol independant... the type of payload you wishes to filter or =
mine will only be a specification of the ability of the DPI engine running =
on the network device.
=0A=0A=A0=0A=0A=0A=0A
=0A=0A=0AThis is "basic" L7 inspection and filtering but the strength is th=
at=0A it's usually performed in hardware and it supports a lot of protocols=
 (in ACE it's performed by NPs and not the control plane I guess)


Right, also I personally would not see how inspection would take place in t=
he control plane. We are not concerned about routing/forwaring primarely he=
re, so that's exclusively surely not the case . For your information, all i=
nline packet inspections (dpi/stateful etc...) only take place on the NPs.
=0A=0A
=0A=0A
Then you have "application firewalls" (or Web App FW). These are dedicated =
features or appliances working only on HTTP(S) - and mainly on Web-based ap=
plications, this is not relevant to XML web services - to avoid most of "We=
b attacks".
=0A=0A=0A
First of all, they are 2 things, an Application Firewall and a WAF (Web App=
lication Firewall). One is often just the appliance (the core), that is to =
say, a firewall being able to work with the application layer of the TCP/IP=
 stack... in order words, a layer 7 firewall. So the AF would work with any=
 applications, not only restricted to http/https.
=0A=0A
A WAF on the order hand is often just a plugin of the AF. I know... I know,=
 some cheap brands out there advertize WAF as standalone appliance, but the=
 WAF is simple an AF with a filter.

just though I should clarify those points.
=0A=0A
--
Ali Abbas
Blog: http://alouche.net

=0A=0A
-----La pi=E8ce jointe associ=E9e suit-----

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki
=0A=0A=0A      
--0-1676897632-1264886481=:32209
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable

<table cellspacing=3D"0" cellpadding=3D"0" border=3D"0" ><tr><td valign=3D"=
top" style=3D"font: inherit;">Hello Ali.<br><br>I tried to explain this gro=
ssly.<br><br>Just about the second point, I know there are some specific fe=
atures (on flows passing through device) processed in the control plane on =
the ACE appliance (all that can't be processed by the octeon micro engines =
reaches the control plane, it follows a traditionnal design of a switch), I=
 don't know how ACE module is built :)<br><br>Surya <br><br>--- En date de&=
nbsp;: <b>Sam 30.1.10, Ali Abbas <i>&lt;[email protected]&gt;</i></b> a =
=E9crit&nbsp;:<br><blockquote style=3D"border-left: 2px solid rgb(16, 16, 2=
55); margin-left: 5px; padding-left: 5px;"><br>De: Ali Abbas &lt;alouche07@=
gmail.com&gt;<br>Objet: Re: [load balancing] L7 packet inspection<br>=C0: "=
Load Balancing Mailing List" &lt;[email protected]&gt;<br>Date: Samedi 30 Janv=
ier 2010, 21h46<br><br><div id=3D"yiv1741736201">Hi Surya,<br><br>I appreci=
ate your
 attempt to give a short intro to Layer 7 Inspection, but I fear, some of y=
our statements could be a bit miss-leading. Just for the sake of clarificat=
ion ;-)<br><br><div class=3D"gmail_quote">=0A=0A<blockquote class=3D"gmail_=
quote" style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt =
0pt 0.8ex; padding-left: 1ex;">=0A<table border=3D"0" cellpadding=3D"0" cel=
lspacing=3D"0"><tbody><tr><td style=3D"font-family: inherit; font-style: in=
herit; font-variant: inherit; font-weight: inherit; font-size: inherit; lin=
e-height: inherit; font-size-adjust: inherit; font-stretch: inherit;" valig=
n=3D"top">=0A=0A=0A<br><i><b>Multiprotocol DPI (Deep Packet Inspection) : t=
his is what you find in your ACE, cisco ASA or any good network firewall. i=
t works on multiple protocols (FTP, SIP, DNS, RTSP, FTP...) and avoids prot=
ocol misuse and RFC compliance.</b></i><br>=0A=0A=0A</td></tr></tbody></tab=
le></blockquote><div><br>DPI is protocol independant... the type of payload=
 you wishes to filter or mine will only be a specification of the ability o=
f the DPI engine running on the network device.<br>=0A=0A&nbsp;</div><block=
quote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, 204, 2=
04); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">=0A<table border=3D"0" =
cellpadding=3D"0" cellspacing=3D"0"><tbody><tr><td style=3D"font-family: in=
herit; font-style: inherit; font-variant: inherit; font-weight: inherit; fo=
nt-size: inherit; line-height: inherit; font-size-adjust: inherit; font-str=
etch: inherit;" valign=3D"top">=0A=0A=0A<br></td></tr></tbody></table></blo=
ckquote><blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid r=
gb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"><table bo=
rder=3D"0" cellpadding=3D"0" cellspacing=3D"0">=0A=0A=0A<tbody><tr><td styl=
e=3D"font-family: inherit; font-style: inherit; font-variant: inherit; font=
-weight: inherit; font-size: inherit; line-height: inherit; font-size-adjus=
t: inherit; font-stretch: inherit;" valign=3D"top"><i><b>This is "basic" L7=
 inspection and filtering but the strength is that=0A it's usually performe=
d in hardware and it supports a lot of protocols (in ACE it's performed by =
NPs and not the control plane I guess)<br></b></i><br></td></tr></tbody></t=
able></blockquote><div><br>Right, also I personally would not see how inspe=
ction would take place in the control plane. We are not concerned about rou=
ting/forwaring primarely here, so that's exclusively surely not the case . =
For your information, all inline packet inspections (dpi/stateful etc...) o=
nly take place on the NPs.<br>=0A=0A<br></div><blockquote class=3D"gmail_qu=
ote" style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0p=
t 0.8ex; padding-left: 1ex;"><table border=3D"0" cellpadding=3D"0" cellspac=
ing=3D"0"><tbody><tr><td style=3D"font-family: inherit; font-style: inherit=
; font-variant: inherit; font-weight: inherit; font-size: inherit; line-hei=
ght: inherit; font-size-adjust: inherit; font-stretch: inherit;" valign=3D"=
top">=0A=0A<br><i><b>Then you have "application firewalls" (or Web App FW).=
 These are dedicated features or appliances working only on HTTP(S) - and m=
ainly on Web-based applications, this is not relevant to XML web services -=
 to avoid most of "Web attacks".</b></i><br>=0A=0A=0A</td></tr></tbody></ta=
ble></blockquote><div><br>First of all, they are 2 things, an Application F=
irewall and a WAF (Web Application Firewall). One is often just the applian=
ce (the core), that is to say, a firewall being able to work with the appli=
cation layer of the TCP/IP stack... in order words, a layer 7 firewall. So =
the AF would work with any applications, not only restricted to http/https.=
<br>=0A=0A<br>A WAF on the order hand is often just a plugin of the AF. I k=
now... I know, some cheap brands out there advertize WAF as standalone appl=
iance, but the WAF is simple an AF with a filter.<br><br>just though I shou=
ld clarify those points.<br>=0A=0A<br>--<br>Ali Abbas<br>Blog: <a rel=3D"no=
follow" target=3D"_blank" href=3D"http://alouche.net">http://alouche.net</a=
><br><br>=0A</div></div>=0A</div><br>-----La pi=E8ce jointe associ=E9e suit=
-----<br><br><div class=3D"plainMail">_____________________________________=
__________<br>lb-l mailing list<br><a ymailto=3D"mailto:[email protected]" hre=
f=3D"/mc/[email protected]">[email protected]</a><br><a href=3D"http=
://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http://vegan.net/mail=
man/listinfo/lb-l</a><br>Searchable Archive: <a href=3D"http://vegan.net/lb=
/archive" target=3D"_blank">http://vegan.net/lb/archive</a><br><a href=3D"h=
ttp://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> Load Balancin=
g Digest<br><a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.c=
om</a> Load Balancing Wiki<br></div></blockquote></td></tr></table><br>=0A=
=0A=0A=0A=0A      
--0-1676897632-1264886481=:32209--

--===============0801298877==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0801298877==--