PIX TCP sequence numbers checking and stateful failover performance
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2003 08:18 AM - edited 02-20-2020 10:36 PM
Hi!
PIX Admin. guide says: "The PIX Firewall checks TCP sequence number and
ensures that it fits within an acceptable range".
The questions are:
- does the PIX really do this?
- does "acceptable range" mean "within the window, but out-of-order TCP
segments are allowed"?
- does this checking mean that dedicated *Gig* ethernet interface is required
for stateful failover, provided that we use 535 with Gig interfaces for data
traffic. (If SEQs are really tracked by the (active) PIX it must send SEQ changes
to the standby for every data packet, isn't it? So, what about performance issues?)
Thank you,
Oleg Tipisov,
REDCENTER,
Moscow
- Labels:
-
Other Network Security Topics
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-10-2003 07:28 AM
For question 3: yes, Cisco seems to recommend as a rule that your stateful failover interface be as fast as your fastest interface in use.
