Hello Technoslick,

Thursday, June 19, 2003, 4:22:06 AM, you wrote:

T> 'Port Triggering' is the feature present on this particular
T> router/gateway.

As you know, I have a great interest in app-aware firewalls. They are
useful in protecting against call-home threats. The possibility of
doing this with a single router protecting the local net was SO
intriguing to me I finally called Linksys tech support to find out how
the BEFSR41 really works. Here's what they said.

Port triggering works by opening a designated port from any port
request on the local net. The tech said it does NOT know, nor care
about, the app name that is requesting the port. It does not care
which local computer is requesting it either. It will work with any
computer on the local net. She said you do not even have to put app
names in the router setup table - it will work with just the port
designations. I went through, in detail, a few very specific scenarios
with multiple chat programs, multiple email pgms, and multiple
browsers, just to make sure I understood what she was saying.

When the BEFSR41 gets a request on a designated port, it opens the
port *for the packet* and immediately closes the port. The router
rapidly opens and closes the port as successive port requests are made
to the router.

This is nice, because the time the port is actually open is very
short. The good news for you is that the router should work with a
linux box quite well. I specifically asked the tech about this, and
was told the OS does not make any difference - all the router looks
for is a port request from the local net. The bad news, for me, is
that it is not really app-aware and can't provide the kind of
call-home protection I am looking for.

>> I am comforted by having the fw first check the md5 signature of
>> the designated app - if it's OK, then open the port for that app
>> only.

T> Your current firewall, you mean?

Yes. The app-aware fw actually checks the md5 to make sure nobody has
modified the app to sneak something through. A number of viruses and
trojans do modify apps (and might even replace them), and this
increases the protection quite a lot.

T> we use a hardware firewall (via router) and wish to open ports for
T> H.323 communications.

Looks like you should be able to do that.

T> If the router cannot open ports dynamically, it will require being
T> placed into DMZ mode

True - that particular computer would have little protection while in
the DMZ zone. On some routers, it is possible to designate just ONE of
the switch ports to be in the DMZ. This would allow all the other
computers to be protected, with just one comp in the DMZ.

T> I think what you are telling me, correctly so, is that *if* I had a
T> stateful inspection firewall running, and tweaked properly, I
T> wouldn't need the hardware firewall. To summarize, any SI firewall
T> operating behind one of these routers is at the mercy of that
T> router's capabilities.

I am talking about a single router/switch/SI-firewall box in which the
SI firewall is 'ahead' of the 'router', and actually protects the
router as well. This is particularly good since the NAT router
function is now also behind a firewall. SI firewalls do not need a lot
of tweaking to work well, although one can adjust to get just what you
want.

T> Getting back to the original topic, I'm hoping to find some way to
T> get my Linksys router to dynamically open ports for H.323
T> communication in Linux.

>From what tech support says, it should work fine. There may be
problems, though, if different ports need to be opened in receiving
data. This is a bit more complex, and I did not want to go through all
the possibilities with tech support. If you do call about this, it is
probably best to address a specific app, with specific ports needed
for transmit and receive, especially for a dynamic-port app such as
conferencing.

T> Specifying the app name doesn't seem to work.

May not need to worry about that, according to the Linksys tech.

T> Thanks for the interesting discussion on SI firewalls. :0)

You are quite welcome. I hope this helps in getting your app to work
as you would like.

I am still VERY interested in the app-aware firewall idea. Love to get
a linux solution.

-- 
Thank you,
 rikona                            mailto:[EMAIL PROTECTED]


Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com

Reply via email to