Firewall Wizards mailing list archives

Re: SYN flood protection strategies (Was: Post connection SYN)


From: Chuck Swiger <chuck () codefab com>
Date: Fri, 17 Oct 2003 13:28:29 -0400

On Friday, October 17, 2003, at 01:19 PM, Paul Robertson wrote:
On Fri, 17 Oct 2003, Chuck Swiger wrote:
  Handling SYN floods at the firewall lets you conserve internal LAN
bandwidth even if your Internet pipe(s) are still going to suffer.

That would imply that you're letting external traffic hit your internal
LAN, instead of servers on the DMZ. I figured that particular lesson was
learned a good decade ago?

My use of the word "LAN" wasn't meant to reflect a particular network topology but local network cabling versus long-distance: if you've got three or four machines sitting in a cage in a hosting facility, there may not be a meaningful distinction between "DMZ" versus "internal LAN". If those machines need to talk to some backend application, such as a database, certainly it's better to do something like multihome them and have seperate subnets for Internet-bound traffic versus internal, and maybe others for out-of-band management via a terminal server for serial console access and backup traffic.

[ I've gotten a lot of mileage out of things like Sun's quad-fast-ethernet NICs configured pretty much as described here, but YMMV. ]

For the circumstances of a company with end-user workstations which also locally hosts their own mail, web, or other services, Paul is of course right-- what E. Zilwicky calls a "screened subnet architecture" is a much better design for security.

How many people have learned that lesson is another issue entirely, unfortunately.

--
-Chuck

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: