Tavve Zone Ranger

15
ZoneRanger Management Through Firewalls Jeff Olson Regional Sales Manager Jeff[email protected] Improve Security. Remove Complexity. Reduce Cost.

description

What is a ZoneRanger

Transcript of Tavve Zone Ranger

Page 1: Tavve   Zone Ranger

ZoneRanger Management Through Firewalls

Jeff OlsonRegional Sales Manager

[email protected]

Improve Security. Remove Complexity. Reduce Cost.

Page 2: Tavve   Zone Ranger

2

Network Management Evolution

In the “Golden Era” of Network Management, everything was connected and specific protocols

weren’t restricted

Page 3: Tavve   Zone Ranger

3

True Security = No Traffic

The only completely risk-free solution is NOT passing any protocols through the firewall.

Remedy

Concord

CiscoWorks

NNM

Trusted Network

DMZ / Untrusted Network

SNMP

ICMP

Syslog

Netflow

X

X

X

X

X

X

X

X

Page 4: Tavve   Zone Ranger

4

Security Analysis of Management Protocols

ICMP NoneAuthentication Encryption Easy to Spoof

None YesSNMP v1 / v2c Yes

SSH Good Good No

FTP In the Clear None No

Syslog None None YesNetFlow None None Yes

sFlow None None YesTFTP None None Yes

HTTPS Good Good No

HTTP In the Clear None No

SNMP v3Simplistic

GoodNoneGood No

Page 5: Tavve   Zone Ranger

5

Defining DMZ / Untrusted Network

A DMZ is any network separated from the corporate network by a firewall

DMZ’s may be separated from the corporate network by multiple firewalls

Includes Virtual DMZ’s

A DMZ can be used internally to separate business functions from malicious attacks and cyber crime

Due to security concerns, DMZ’s are often difficult to manage from the corporate network (or NOC)

Page 6: Tavve   Zone Ranger

6

Industry Choice 1: Define Firewall Rules

DMZ

HPNNMCorporate Network

OtherMgmt.App.

• Define firewall rules to allow traditional management protocols to pass through the firewall (restricted to management application servers).

• Traditional management protocols are not particularly secure.

• Time consuming, error-prone, more rules than you think!

• Process and efforts is repeated for each firewall / DMZ

• Define firewall rules to allow traditional management protocols to pass through the firewall (restricted to management application servers).

• Traditional management protocols are not particularly secure.

• Time consuming, error-prone, more rules than you think!

• Process and efforts is repeated for each firewall / DMZ

Opsware

Page 7: Tavve   Zone Ranger

7

Firewall Rules - 1

Management Application

Server

DMZDevice

The simplified view… The reality

Management Application

Server

DMZDevice

ICMPSNMPSyslogSSH

NetFlowsFlow

Page 8: Tavve   Zone Ranger

8

Simplifying Firewall Configuration - 2

Management Application

Servers

DMZDevices

Management Application

Servers

DMZDevices

ZoneRanger

RangerGateway

Page 9: Tavve   Zone Ranger

9

Proxy Firewall Example: SNMP Get/Set

Get Request

Get Response

ManagementApplication

Server

DMZDevice

Get Request

Get Response

ManagementApplication

Server

DMZDevice

Get Response

ProxyFirewall

Get Request

Page 10: Tavve   Zone Ranger

10

Proxy Firewall Example: Syslog Forwarding

SyslogMessage

ManagementApplication

Server

DMZDevice

SyslogMessage

ManagementApplication

Server

DMZDevice

SyslogMessage

ProxyFirewall

Page 11: Tavve   Zone Ranger

11

ZR Supported Outbound Requests

• ICMP – “ping”• TCP – Transmission Control Protocol• SNMP v1 / v2c / v3 – Simple Network Management Protocol

– v3 – enable v3 for selected DMZ devices (DMZ router) without upgrading the entire DMZ or trusted side

• HTTPS – Secure Hypertext Transfer Protocol• TFTP – Trivial File Transfer Protocol• SSH – Secure Shell• SOCKS – SOCKetS (secure proxy)• FTP – File Transfer Protocol• ICMP/SNMP Proxy Caching

Page 12: Tavve   Zone Ranger

12

ZR Supported Inbound Requests

• UDP – Unreliable Datagram Protocol

• SNMP Traps

• NetFlow – network performance

• Syslog – “system logging” protocol

• TACACS+ - authentication, authorization and accounting

• Radius - authentication, authorization and accounting

• NTP – Network Time Protocol

Page 13: Tavve   Zone Ranger

13

Transparent Applications

• Fault (Network Management System – NMS)

HP OpenView NNM, IBM Tivoli NetView, OpenNMS, MS-Mom, Solarwinds, CA Unicenter

• Fault (Systems Management)

Entuity, SiteScope, EMC Smarts, IBM Tivoli Netcool, Bladelogic

• Configuration

Voyence, OpsWare, HP NCM, Cisco NCM, CiscoWorks

• Accounting

NetQoS, Fluke/Crannog NetFlow Tracker, Cisco ACS

• Performance

CA eHealth, InfoVista, PRTG, MRTG, HP OVPI, SevOne, OPNET

• Security

Cisco MARS, Arcsight, enterasys Dragon (DSCC)

Page 14: Tavve   Zone Ranger

14

ZoneRanger Business Case

Eliminate the human error (risk) of firewall rules and reduce the open firewall ports

Increase access to DMZ devices and at the same time increase overall network security

Reduce labor to create and maintain extensive firewall rules for DMZ(s)

Address compliance requirements of SOX, PKI, ISO 27001, HIPAA

Page 15: Tavve   Zone Ranger

15

Select Tavve Customers