Re: [fw-wiz] OSPF on Firewall

From: Gary Flynn (flynngn_at_jmu.edu)
Date: 12/17/03

  • Next message: Carroll, Shawn: "RE: [fw-wiz] OSPF on Firewall"
    To: Shimon Silberschlag <shimons@bll.co.il>
    Date: Wed, 17 Dec 2003 17:09:01 -0500
    
    

    Shimon Silberschlag wrote:
    > Lets say that I have two routers (on an internal network) that talk OSPF
    > between them.
    >
    > Now I have to insert a firewall in-between the two routers.
    >
    > I am led to believe (by the Communications people I work with) that there is
    > no other option but to install OSPF on the firewall, which doesn't make me
    > feel easy about the solution.
    >
    > Is it true that there is no other way around this problem?

    One would assume a bridging firewall would pass the traffic
    but I'd check with the vendor. I installed an eval inline
    IDP box in a similar configuration a while ago and the link
    wouldn't come up due to OSPF not being passed...even with
    no rules applied. The vendor had to make a custom change
    to their underlying bridging configuration to get it to work.

    -- 
    Gary Flynn
    Security Engineer - Technical Services
    James Madison University
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Carroll, Shawn: "RE: [fw-wiz] OSPF on Firewall"

    Relevant Pages

    • Re: [fw-wiz] OSPF on Firewall
      ... > Now I have to insert a firewall in-between the two routers. ... Forward the OSPF traffic in bridge mode with MAC address, ... Do static routing between the routers, ...
      (Firewall-Wizards)
    • RE: [fw-wiz] OSPF on Firewall
      ... Being a dynamic routing protocol, I'm assuming you want to pass OSPF ... Cisco routers, you can use the "neighbor" command within OSPF ... From the firewall perspective, you would need to allow OSPF traffic to ...
      (Firewall-Wizards)
    • Re: [fw-wiz] OSPF on Firewall
      ... > Lets say that I have two routers (on an internal network) that talk OSPF ... > Now I have to insert a firewall in-between the two routers. ...
      (Firewall-Wizards)
    • RE: [fw-wiz] OSPF on Firewall
      ... it's even fairly safe as you can open the pass through for the ... specific IPs of both routers. ... Lets say that I have two routers that talk OSPF ... Now I have to insert a firewall in-between the two routers. ...
      (Firewall-Wizards)
    • Re: Misconceptions
      ... I admit Firewalls and Routers aren't the exact same thing (of ... Personal Firewall, I wonder if that program is any good? ... > handled by anti-virus programs, which should be on ... > A NIDS is just that. ...
      (comp.security.firewalls)