Re: [fw-wiz] Real Traffic Testing

From: John Adams (jna_at_retina.net)
Date: 10/24/03

  • Next message: Luca Berra: "Re: [fw-wiz] Real Traffic Testing"
    To: Gianpiero Porchia <gianpiero.porchia@atsweb.it>
    Date: Fri, 24 Oct 2003 14:47:39 -0700 (PDT)
    
    

    > - Get traffic from OUTSIDE to INSIDE using TAP-1
    > - Get traffic from INSIDE to OUTSIDE using TAP-2

    This looks like asymmetric routing to me, and I don't see how you're going
    to make this work.

    Are these stateful firewalls? How are the two firewalls going to share the
    state table for inbound/outbound packets and handle them correctly?

    > The problems:
    > - The traffic is directed to the MAC address of FW, so FW-test will drop it;

    Well, the packets are rewritten by your outside router on the way in, and
    the router isn't going to know which firewall handled the transaction.

    > Have you some idea to get the objectives?

    You can't make this work unless the firewalls are in some sort of active,
    redundant configuraiton, with exactly the same configuartions and shared
    state tables.

     -john

    -- 
    J. Adams					http://www.retina.net/~jna
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Luca Berra: "Re: [fw-wiz] Real Traffic Testing"

    Relevant Pages

    • RE: Cant enter 2 XP machines into a Workgroup
      ... Firewalls like NIS modify Windows own security files. ... If a comsumer level router like those of Linksys and Netgear ...
      (microsoft.public.windowsxp.network_web)
    • RE: Cant enter 2 XP machines into a Workgroup
      ... I had my XP Home machine hard ... Firewalls like NIS modify Windows own security files. ... If a comsumer level router like those of Linksys and Netgear ...
      (microsoft.public.windowsxp.network_web)
    • Re: Ask EU Technical Section: Networking questions
      ... I have just added a new lapdog to my household and so needed to set up a wireless network, so that it could share the broadband connection with the main PC. ... The router is a Belkin N Wireless Modem Router. ... You need to set the software firewalls on each PC to allow the local network to connect to them. ... If you can't Share the folder, you will need to enable File Sharing for the machine as a whole. ...
      (uk.media.radio.archers)
    • RE: [fw-wiz] Firewalls v. Router ACLs
      ... people to take in consideration in network design and layout. ... here and the old firewalls list often emphasized an approach that avoided ... The logging alert features alone turn this layer into a IDS as ... > An appropriately sized router will not have any performance problems. ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Firewall routing thought...
      ... networks that the firewalls are protecting, ... and let the router sort out what networks are ... >>Your network layout isn't really clear from your email, ... >>you make a change in broadcast domains, the router is going to be involved. ...
      (Firewall-Wizards)