Cato Targets Mid-Sized Businesses with Cloud Security
Location-based security has a hard time with cloud applications.
Location-based security has a hard time with cloud applications.
While the large data centers increasingly use BGP as the routing protocol within their fabrics, the enterprise engineers tend to shy away from that idea because they think BGP is too complex/scary/hard-to-configure/obsolete/unknown/whatever.
It’s time to fix that.
Read more ...I’m currently working on a design and needed to verify some failover behavior of the Cisco ASA firewall.
The ASA can run in active/active or active/standby mode where most deployments I see run in active/standby mode. When in a failover pair the firewalls will share an IP address and MAC address, very similar to HSRP or VRRP but it also synchronizes the state of TCP sessions, IPSec SA’s, routes and so on. The secondary firewall gets its config from the primary firewall so everything is configured exactly the same on both firewalls.
To verify if the other firewalls is reachable and to synchronize state, a failover link is used between the firewalls. The firewalls use a keepalive to verify if the other firewall is still there. This works just like any routing protocol running over a link where you expect to see a hello from your neighbor and if you miss 3 hello’s, the other firewall is gone. This timer can be configured and in my tests I used a hello of 333 ms and a holdtime of 999 ms which means that convergence should happen within one second.
The first scenario I was testing was to manually trigger a Continue reading
DDI company acquired IID. Yes they DID.
A buffer overflow problem prompted LinkedIn to build its own switch.
Moving away from the "big star" in mobile networks.