Solved

How Stateful Inspection handles ICMP, UDP.ESP and GRE Packets.

Posted on 2011-03-11
4
2,534 Views
Last Modified: 2012-05-11
so far I understand only TCP connection state  will be seen in connection table, or  stateful table will have track of all UDP,ESP,ICMP and GRE packets. which one is true ?

One more thing just wanna a know, whats a commands to see the stateful connection table  in firewalls (Checkpoint/Cisco ASA/Fortigate/Juniper)
 
What is DEEP inspection ???

0
Comment
Question by:tyrosec
  • 2
  • 2
4 Comments
 
LVL 68

Expert Comment

by:Qlemo
ID: 35115702
That are a lot of questions, and they can't be answered that simple. But I'll try.

Deep Inspection (DI) analyzes the payload of packets in addition to the header. SPI (stateful package inspection), which is what is done without DI, applies only on headers. With DI you can filter e.g. http traffic, inspecting and optionally removing any JavaScript contents.
SPI only cares if ingress traffic has been asked for, by comparing protocol, ports and IP addresses with its session table.

Regarding "see the stateful connection table", the command is similar but different for each firewall. I can tell only for ScreenOS (Juniper SSG/Netscreen), but expect it to be the same on Cisco and JunOS (Juniper SRX & Co):  show session . There are more options to restrict the output, and you can apply additional filter commands, but that is getting quite complex and very decice specific.

Stateful inspection and UDP: Connectionless session info is kept in the same session table as for TCP traffic. A timeout value allows for closing the session if either the application layer protocol is unknown, not allowing for terminating "commands", or on communication errors.
If an application layer gateway can be applied (the firewall knows about the protocol, and can hence "see" when a session is "closed"), the session will get closed out ASAP. E.g. for ICMP Echo Request (ping), the session info can be removed as soon as the ICMP Echo Reply, Timeout, Not Reachable etc. messages are received.
0
 

Author Comment

by:tyrosec
ID: 35115967
Hi  Qlemo... Certainly  I understand that ..one question i wanna understand

... we  have option that cisco firewalls  can be configured in stateful failover  i.e., HA(Active/standby)... standby Firewalls suppose to handle all the seesion when  active member goes down. Say  I have configured  IPsec Remote access VPN on active firewall &  I have connected VPN RA through my laptop,  tunnel is formed between my laptop &  active firewall , when failover happpen the standby member will be active,  AND Tunnel (my laptop and Firewall) will be remain undistrubed or  it will disconnet and we have manually connect  the RA VPN.

0
 
LVL 68

Accepted Solution

by:
Qlemo earned 500 total points
ID: 35115975
"stateful failover" implies that the state is failed over, too. Active/standby need to exchange session info all the time (from the active member to the passive). There might be a small lag, because failover does not work immediately (it needs a small amount of time to recognize the failure), but that should not be more than a short "hick-up". No service should break, including VPN.
0
 

Author Comment

by:tyrosec
ID: 35137633
But suggest some Materials to know boardly "How Stateful session handles the TCP/UDP/GRE/ICMP Protocol"  
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now