Re: [fw-wiz] Content Switch as security device?

From: Gary Flynn (flynngn@jmu.edu)
Date: 01/30/03


From: Gary Flynn <flynngn@jmu.edu>
To: Dave Mitchell <dmitchell@viawest.net>
Date: Thu Jan 30 09:41:26 2003

Dave Mitchell wrote:
> Michel,
>
> Depending on the type of switch, you might not even have an ASIC that can perform
> under a DDOS or other type of attack.

This also may be true of a firewall.

> Content switches only balance traffic based on source
> and dest IP/port, and uses a load balancing algorithm to point it at your particular farm
> or server. It does not perform any other packet inspection to prevent mailicious traffic
> like a SYN attack, replay, or any other you can think of.

The Cisco boxes also inspect URLs. They also advertise that
they protect from denial of service attacks. Of course, they
also advertise that they can load balance across firewalls. :)

Functionality is merging in firewalls, IDS, IDP, content
switch, etc. to prevent this:

Inet->anti-DDOS->firewall->anti-virus->IDS/IDP->loadbalance->SSL->content->systems

I suspect there may be applications where a "content
switch" with security features is a better fit for the
organization than certain types of firewalls.

-- 
Gary Flynn
Security Engineer - Technical Services
James Madison University


Relevant Pages

  • Re: [fw-wiz] Concentrator inside of paired failover firewalls.
    ... Firewalls External Burp(each firwall on a separate port on switch), ... Firewall Internal Burps, Hub (a hub for each burp, dmz etc..., a cable ... fails, it fails open and the internal secondary firewall begins handling ...
    (Firewall-Wizards)
  • Re: Workgroups and File/Printer Sharing
    ... and gateway manually I can then connect, but as soon as I switch off they ... Doug Sherman ... If neither of the above work, check your firewalls. ... When I look in the "view workgroup computers" window it shows my ...
    (microsoft.public.windowsxp.network_web)
  • Re: Looking to connect a second broadband connection for failover and add a second firewall, any su
    ... Or should we have the firewalls ... I think that adding another broadband connection is unnecessary at home, ... connected, and should that fail, unplug that and plug in the other. ... would think that if you put the two broadbands on a switch and plugged the ...
    (comp.security.firewalls)
  • Re: Needing to upgrade from AXP VMSv7.1-1h2
    ... with TCP/IP V5.3 ECO 2 with enhanced security over firewalls (one can ... switch that off with logicals). ...
    (comp.os.vms)
  • Re: thoughts on kernel security issues
    ... I'm pretty sure that you only get a 3 second delay on the specific ... as a test, switch to vc/0 and enter 'root', then press enter. ... Switch to vc/1, and enter 'root', then press enter. ... Automating an attack on about 10 different ssh connections shouldn't be ...
    (Linux-Kernel)