Hello Technoslick, Thursday, June 19, 2003, 4:22:06 AM, you wrote:
T> 'Port Triggering' is the feature present on this particular T> router/gateway. As you know, I have a great interest in app-aware firewalls. They are useful in protecting against call-home threats. The possibility of doing this with a single router protecting the local net was SO intriguing to me I finally called Linksys tech support to find out how the BEFSR41 really works. Here's what they said. Port triggering works by opening a designated port from any port request on the local net. The tech said it does NOT know, nor care about, the app name that is requesting the port. It does not care which local computer is requesting it either. It will work with any computer on the local net. She said you do not even have to put app names in the router setup table - it will work with just the port designations. I went through, in detail, a few very specific scenarios with multiple chat programs, multiple email pgms, and multiple browsers, just to make sure I understood what she was saying. When the BEFSR41 gets a request on a designated port, it opens the port *for the packet* and immediately closes the port. The router rapidly opens and closes the port as successive port requests are made to the router. This is nice, because the time the port is actually open is very short. The good news for you is that the router should work with a linux box quite well. I specifically asked the tech about this, and was told the OS does not make any difference - all the router looks for is a port request from the local net. The bad news, for me, is that it is not really app-aware and can't provide the kind of call-home protection I am looking for. >> I am comforted by having the fw first check the md5 signature of >> the designated app - if it's OK, then open the port for that app >> only. T> Your current firewall, you mean? Yes. The app-aware fw actually checks the md5 to make sure nobody has modified the app to sneak something through. A number of viruses and trojans do modify apps (and might even replace them), and this increases the protection quite a lot. T> we use a hardware firewall (via router) and wish to open ports for T> H.323 communications. Looks like you should be able to do that. T> If the router cannot open ports dynamically, it will require being T> placed into DMZ mode True - that particular computer would have little protection while in the DMZ zone. On some routers, it is possible to designate just ONE of the switch ports to be in the DMZ. This would allow all the other computers to be protected, with just one comp in the DMZ. T> I think what you are telling me, correctly so, is that *if* I had a T> stateful inspection firewall running, and tweaked properly, I T> wouldn't need the hardware firewall. To summarize, any SI firewall T> operating behind one of these routers is at the mercy of that T> router's capabilities. I am talking about a single router/switch/SI-firewall box in which the SI firewall is 'ahead' of the 'router', and actually protects the router as well. This is particularly good since the NAT router function is now also behind a firewall. SI firewalls do not need a lot of tweaking to work well, although one can adjust to get just what you want. T> Getting back to the original topic, I'm hoping to find some way to T> get my Linksys router to dynamically open ports for H.323 T> communication in Linux. >From what tech support says, it should work fine. There may be problems, though, if different ports need to be opened in receiving data. This is a bit more complex, and I did not want to go through all the possibilities with tech support. If you do call about this, it is probably best to address a specific app, with specific ports needed for transmit and receive, especially for a dynamic-port app such as conferencing. T> Specifying the app name doesn't seem to work. May not need to worry about that, according to the Linksys tech. T> Thanks for the interesting discussion on SI firewalls. :0) You are quite welcome. I hope this helps in getting your app to work as you would like. I am still VERY interested in the app-aware firewall idea. Love to get a linux solution. -- Thank you, rikona mailto:[EMAIL PROTECTED]
Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com
