Firewall fault best practices: redundancy and monitoring

Source: Internet
Author: User

My company encountered a firewall fault recently, which caused the company to go down for several hours. Fortunately, we have a backup device that can be replaced. However, what suggestions or best practices do you have to properly manage unpredictable firewall failures?

Brad Casey:For firewall faults, I suggest two words: redundancy and monitoring.

Redundancy:This not only involves replacing the backup device when a firewall fails, but also ensures that the device can be automatically transferred.

For example, in a Cisco PIX environment, you should configure two PIX devices, one as an active device and the other as a backup device. In most cases, the only additional infrastructure required is the Failover Cable, which is a serial cable that connects two PIX devices after a fault occurs. In this configuration, the communication between two PIX devices is performed by sending an ACK message every three seconds. If the ACK message is not confirmed, the device retransmits the message. If the ACK message is not received after five retransmission, the active device is considered faulty and the standby device is started.

Monitoring:Enterprises should build some monitoring devices in the firewall infrastructure to ensure that the firewall works properly. This process can be completely passive. You only need to configure some alert mechanisms in the monitoring device. Once exceptions are detected, you can issue alerts in a timely manner.

For example, if your organization has a tight budget and cannot afford a new monitoring device, you can configure a monitoring port on or after your firewall, then, Wireshark captures all traffic flowing through the firewall. Although this is not a firewall fault management mechanism, it helps you determine whether some specific aspects of your firewall are faulty.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.