LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-14-2007, 04:18 PM   #1
netlogic
Member
 
Registered: Jun 2007
Posts: 36

Rep: Reputation: 15
Any Deep Packet Inspection in Linux?


Any free solution for DI (Deep Inspection) firewall or routers available for Linux? Are there any plans for DI focus functions appear to the future IPTABLES? I know there are tools for most prevalent static internet protocol such as HTTP, SMTP, IMAP, POP, FTP, and DNS, but we live in a time, we need to go beyond them. I know there are products like Procera and Ellacoya, but there must be a free and open source solution to this problem, so things can be deployed faster based on the tech knowledge, not deep pockets.
 
Old 11-15-2007, 01:27 PM   #2
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by netlogic View Post
Any free solution for DI (Deep Inspection) firewall or routers available for Linux? Are there any plans for DI focus functions appear to the future IPTABLES? I know there are tools for most prevalent static internet protocol such as HTTP, SMTP, IMAP, POP, FTP, and DNS, but we live in a time, we need to go beyond them. I know there are products like Procera and Ellacoya, but there must be a free and open source solution to this problem, so things can be deployed faster based on the tech knowledge, not deep pockets.
A full-on firewall (or router), no, you're not going to find many and those that claim to do this are most likely selling snake oil, IMO. A firewall should permit or deny traffic based on things other than deep packet inspection. To have a firewall do things other than what a basic firewall is intended to do (free or commercial) is just asking for trouble. As it is, at work we always seem to have issues with the IPS/IDP platforms. They either die when updating policies or seize because something within a packet's payload clogs/blocks the system, sending CPU cycles to 100%. IMO, if an IPS has issues assessing packets at a deep level, a firewall is going to have similar issues. Even if there's nothing within packets that will seize or kill the inspection, can you imagine the load of CPU cycles that a busy perimeter firewall would have conducting deep packet inspection of every packet?? The load would be huge, even on a multiproc or multicore system...the load may be big enough to where the system would slow, fail, or begin dropping packets.

An IPS MAY do what you'd like, though. One free solution is snort-inline, I believe.

Last edited by unixfool; 11-15-2007 at 08:52 PM.
 
Old 11-15-2007, 04:39 PM   #3
osor
HCL Maintainer
 
Registered: Jan 2006
Distribution: (H)LFS, Gentoo
Posts: 2,450

Rep: Reputation: 78
What exactly are you trying to accomplish? Yes I have skimmed this article, but I don’t know exactly what you are seeking.

Will a concept as simple as l7-filter (with very complicated pattern definitions) be sufficient?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Device Profile: Bivio B7000 deep packet inspection appliance LXer Syndicated Linux News 0 03-12-2007 09:32 PM
Need an exit strategy...(in deep with Linux) southsibling Linux - Software 17 06-01-2005 06:05 PM
Stateful Packet Inspection Firewall (How could I tell)?? wardialer Linux - Security 9 02-10-2005 09:11 PM
Firewall with deep inspection Baltasar Linux - Networking 3 02-22-2004 09:07 PM
stateful packet inspection estranged0877 Linux - Security 1 01-28-2003 06:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration