Re: distributed natd

From: John Van Boxtel (jvb@whoowl.com)
Date: 08/10/01


From: "John Van Boxtel" <jvb@whoowl.com>
Date: Fri, 10 Aug 2001 09:26:56 -0700


> Next, I don't know whether they should communicate over TCP or UDP. I
> would use UDP since it might be faster and it allows broadcasts (one
> firewall broadcasting changes to all others on the secure network) but is
> unreliable. A persistent TCP connection may be also considered.

The persistent TCP connection could be used well as if the connection
dropped this could signal that the other gateway is down for whatever
reason. This would not be useful for telling if that gateway no longer has
an upstream connection but it would definitely let you know that the gateway
is no longer availible (ie power lost, hardware failuer, etc)

> It is however not clean to me how and how often you want to check if
> firewall is alive.

See above, this would instantly, let you know it's gone, but it would only
tell you that the gateway is dead not when the gateway is up but its
upstream is down.

Interesting stuff :-)

JVB

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: WinRoute Pro Security Log entrie, could someone explain
    ... your Winroute gateway is sending out UDP broadcasts. ... a packet was sent using port 64123 on the gateway. ... Since the gateway will respond to broadcasts as well as to its assigned IP ...
    (comp.security.firewalls)
  • Re: udp ports thorugh a firewall
    ... Every once in a while I see portsentry triggering on a UDP ... packet coming in for port 32770. ... If I'm not explicitly forwarding ... these udp ports to the mail gateway, ...
    (comp.os.linux.networking)
  • Re: Strange attack question - seems udp
    ... > Well the Cisco 3750 is the gateway for my clients and not the ... > upload udp traffic. ...
    (Incidents)
  • Re: Gateway change
    ... Steve Riley ... > change there Gateway but i don't want to give them Administrator ... > only send TCP trafic after roundabout 10 min. it do not send UDP ...
    (microsoft.public.win2000.networking)