nanog mailing list archives
Re: which firewall product?
From: Owen DeLong <owen () delong com>
Date: Tue, 30 Jul 2013 15:57:41 -0700
On Jul 30, 2013, at 13:10 , Charles N Wyble <charles-lists () knownelement com> wrote:
Not sure how bsd handles ipip connections. If it breaks them out as a dedicated interface (like it does for openvpn connections) , then rules can be applied and pfsense would be quite useful. The UI is very simple.
That would only work if the firewall were terminating the tunnel instead of passing the tunneled traffic through still inside the tunnel. I believe Bill is looking for DPI on forwarded traffic and not to decapsulate the traffic prior to inspection. Owen
Warren Bailey <wbailey () satelliteintelligencegroup com> wrote:Look into pfsense. It's rock solid and bad based, and can be purchased as an appliance. (both real and vm) Sent from my Mobile Device. -------- Original message -------- From: William Herrin <bill () herrin us> Date: 07/30/2013 1:02 PM (GMT-08:00) To: nanog () nanog org Subject: which firewall product? Hi folks, I'm trying to identify a firewall appliance for one of my customers. The wrinkle is: it has to be able to inspect packets inside an IPIP tunnel and accept/reject based on IP address, TCP port number and standard things like that. On the packet carried *inside* the IPIP tunnel packet. From what I can tell, the Cisco ASA can't do this. Linux iptables can (with the u32 match module) but the customer wants an appliance, not a server. What appliances do you know of that can do this? Is there a different Cisco box? A Juniper firewall? Anything else? Thanks in advance, Bill Herrin -- William D. Herrin ................ herrin () dirtside com bill () herrin us 3005 Crane Dr. ...................... Web: <http://bill.herrin.us/> Falls Church, VA 22042-3004-- Sent from my Android device with K-9 Mail. Please excuse my brevity.
Current thread:
- which firewall product? William Herrin (Jul 30)
- RE: which firewall product? Warren Bailey (Jul 30)
- RE: which firewall product? Charles N Wyble (Jul 30)
- Re: which firewall product? Michael Brown (Jul 30)
- Re: which firewall product? William Herrin (Jul 30)
- Re: which firewall product? Blake Dunlap (Jul 30)
- Re: which firewall product? William Herrin (Jul 30)
- Re: which firewall product? Blake Dunlap (Jul 30)
- RE: which firewall product? Charles N Wyble (Jul 30)
- Re: which firewall product? Kinkaid, Kyle (Jul 30)
- RE: which firewall product? Warren Bailey (Jul 30)
- Re: which firewall product? Owen DeLong (Jul 30)
- Re: which firewall product? Christopher Morrow (Jul 31)
- Re: which firewall product? Richard Golodner (Jul 30)