Firewall Wizards mailing list archives

Re: fail-open firewalls...


From: Mikael Olsson <mikael.olsson () clavister com>
Date: Fri, 07 Jun 2002 21:37:37 +0200


Anton Chuvakin wrote:

 I would be VERY happy to listen to all suggestions from the
esteemed list members [on how firewalls can be made to fail open?]

In the general case, I doubt that pure packet flooding will make 
any firewall fail other than closed. At least for firewall built
on top of general computers. Quirky stuff built on top of switch-
like architectures _might_ be another story.

State table flooding? Hmmm. Shouldn't cause anything to fail open,
at least not because of design flaws. _MAYBE_ due to a bug, but,
well, bugs can cause anything anywhere, so that doesn't really
count.

Causing the firewall to crash? Now there's another story entirely.
Depending on the mechanisms the firewall uses to plug into the 
underlying architecture, and if the firewall is running on top of
a general OS, a crash _could_ potentially cause it to fail open.
(Think along the lines of it using a well-defined plug-in API into
the lower layers, and a crash causing cleanup code to get executed,
thus removing the firewall from the packet flow.)
Border Manager definately gets unplugged from the packet flow
when it crashes. (Recent report on Bugtraq)

Expired licenses will cause FW-1's to fail open; this much I know
from personal experience. (One would think it'd just stop forwarding 
packets altogether but noooooo.)

Sending the computer to stand-by and bringing it up again can 
obviously also cause firewalls to fail open. There's a recent
report on Bugtraq about BlackICE unplugging from the packet flow
when the computer has been on standby. (Think people with roaming 
VPN connections here.)

... hmmm.. I think I had another idea or two when I started typing.. 
Can't seem to remember them now though. :/


I am curious, how one can _verify_ that the firewall is indeed made 
this way.  [will fail closed]

Now THAT is a tricky question. I'm tempted to say "use the 
source, Luke", but that's usually not something you "can" do.
(Either because you don't have the source, or because there's
just too much to of it.)

I'm sure the proxy firewall crowd will cheerfully tell you "proxies
always fail closed". However, the Border Manager is mainly a proxy 
firewall. It has some packet filtering to block access to local
ports. When it failed, it obviously stopped blocking said ports.

If, by "verify", you really mean VERIFY, I'd say that one important 
aspect is that the firewalling process and the packet forwarding 
process be one and the same. If the firewall can fail independently 
from the packet forwarder (or local IP stack for that matter), I'd say 
it's impossible to really verify that it will fail closed.
(Although I'm of the "don't build firewalls on general OSes" crowd, so
I'm likely biased.)

Regards,
Mikael Olsson

-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com
_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://list.nfr.com/mailman/listinfo/firewall-wizards


Current thread: