Firewall Wizards mailing list archives
Re: fail-open firewalls...
From: Mikael Olsson <mikael.olsson () clavister com>
Date: Fri, 07 Jun 2002 21:37:37 +0200
Anton Chuvakin wrote:
I would be VERY happy to listen to all suggestions from the esteemed list members [on how firewalls can be made to fail open?]
In the general case, I doubt that pure packet flooding will make any firewall fail other than closed. At least for firewall built on top of general computers. Quirky stuff built on top of switch- like architectures _might_ be another story. State table flooding? Hmmm. Shouldn't cause anything to fail open, at least not because of design flaws. _MAYBE_ due to a bug, but, well, bugs can cause anything anywhere, so that doesn't really count. Causing the firewall to crash? Now there's another story entirely. Depending on the mechanisms the firewall uses to plug into the underlying architecture, and if the firewall is running on top of a general OS, a crash _could_ potentially cause it to fail open. (Think along the lines of it using a well-defined plug-in API into the lower layers, and a crash causing cleanup code to get executed, thus removing the firewall from the packet flow.) Border Manager definately gets unplugged from the packet flow when it crashes. (Recent report on Bugtraq) Expired licenses will cause FW-1's to fail open; this much I know from personal experience. (One would think it'd just stop forwarding packets altogether but noooooo.) Sending the computer to stand-by and bringing it up again can obviously also cause firewalls to fail open. There's a recent report on Bugtraq about BlackICE unplugging from the packet flow when the computer has been on standby. (Think people with roaming VPN connections here.) ... hmmm.. I think I had another idea or two when I started typing.. Can't seem to remember them now though. :/
I am curious, how one can _verify_ that the firewall is indeed made this way. [will fail closed]
Now THAT is a tricky question. I'm tempted to say "use the source, Luke", but that's usually not something you "can" do. (Either because you don't have the source, or because there's just too much to of it.) I'm sure the proxy firewall crowd will cheerfully tell you "proxies always fail closed". However, the Border Manager is mainly a proxy firewall. It has some packet filtering to block access to local ports. When it failed, it obviously stopped blocking said ports. If, by "verify", you really mean VERIFY, I'd say that one important aspect is that the firewalling process and the packet forwarding process be one and the same. If the firewall can fail independently from the packet forwarder (or local IP stack for that matter), I'd say it's impossible to really verify that it will fail closed. (Although I'm of the "don't build firewalls on general OSes" crowd, so I'm likely biased.) Regards, Mikael Olsson -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com _______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://list.nfr.com/mailman/listinfo/firewall-wizards
Current thread:
- fail-open firewalls... Anton Chuvakin (Jun 07)
- Re: fail-open firewalls... Frederick M Avolio (Jun 08)
- Re: fail-open firewalls... Mikael Olsson (Jun 08)
- Re: fail-open firewalls... B. Scott Harroff (Jun 08)
- Re: fail-open firewalls... R. DuFresne (Jun 08)
