设为首页收藏本站language 语言切换
查看: 2093|回复: 3
收起左侧

[其他] 题库请教,关于stateful TCP checks

[复制链接]
回帖奖励 9 个鸿鹄币 回复本帖可获得 1 个鸿鹄币奖励! 每人限 1 次
发表于 2017-7-1 15:22:50 | 显示全部楼层 |阅读模式
大家好,请问下面这个题目为什么选择D,求详细解答,十分感谢。
- h& J& f3 T$ J+ r- z1 [' k1 M$ k
Which option is one way to mitigate symmetric routing on an active/active firewall setup for TCP-based
2 o3 k# E3 x' j* nconnections?
2 a8 u- T' i. L; K- F* QA. performing packet captures1 v/ N/ E& C3 ~/ D1 O$ S
B. disabling asr-group commands on interfaces that are likely to receive asymetric traffic+ `6 N. ^" J( @/ [! H2 n9 ^
C. replacing them with redundant routers and allowing load balancing
7 f) e1 B, Y$ MD. disabling stateful TCP checks7 g4 ?4 y" D. m, o0 S* l( ^- s8 \, f
Correct Answer: D
. Y( q9 N; D% D  V  R3 Q3 l" g5 E  Q7 Z. ^4 g7 n' ^0 X# a) ~
发表于 2017-7-1 17:50:16 | 显示全部楼层
兄台, 我來回答, 因我在香港, 所以用英文回答你, 希望你明白.
6 H! h9 c( X, D2 m+ O% }, y) @3 k4 Q' i7 w0 W" Q6 F
In Asymmetric routing, a packet traverses from a source to a destination in one path and takes a different path when it returns to the source. This is commonly seen in Layer-3 routed networks.3 @; Z$ J, q0 _& f5 B% d9 ?2 }
& ?* ?8 W5 l) |8 Y& O0 Z
Issues to Consider with Asymmetric Routing
8 `/ o8 ]! V( Q5 D. _& o
) q/ u" y* y+ N' wAsymmetric routing is not a problem by itself, but will cause problems when Network Address Translation (NAT) or firewalls are used in the routed path. For example, in firewalls, state information is built when the packets flow from a higher security domain to a lower security domain. The firewall will be an exit point from one security domain to the other. If the return path passes through another firewall, the packet will not be allowed to traverse the firewall from the lower to higher security domain because the firewall in the return path will not have any state information. The state information exists in the first firewall.3 i; ~  z; ]# l& J

2 K; D  X3 T6 S1 V, RReference: http://www.cisco.com/web/service ... rchives/200903.html
) ?1 m# w8 k( f0 [8 \& L; j6 s; z" V1 z% q5 o; K
Specifically for TCP-based connections, disabling stateful TCP checks can help mitigate asymmetric routing. When TCP state checks are disabled, the ASA can allow packets in a TCP connection even if the ASA didn’t see the entire TCP 3-way handshake. This feature is called TCP State Bypass.
5 m2 d/ P" @' i7 z2 \0 G& x  g% i- T, @6 |2 ]
Reference: https://supportforums.cisco.com/ ... ting-and-mitigation
, X0 \' B1 e; x1 Y) [% Q5 K9 O3 o; v5 C* z8 p# }
Note: The active/active firewall topology uses two firewalls that are both actively providing firewall services.
2 J& R  G, e. [6 \; a  ~* H. W- N4 z+ A
沙发 2017-7-1 17:50:16 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2017-7-1 20:18:32 | 显示全部楼层

回帖奖励 +1 个鸿鹄币

唉... 很多時回答問題, 都要等審核, 唉.0 q4 C) ~0 k% v2 ^- n, \

3 _  }0 t# `9 t再答一次吧:
' S* E. ^6 i" ]4 B# @% P& G$ A; g6 f/ x2 a
In Asymmetric routing, a packet traverses from a source to a destination in one path and takes a different path when it returns to the source. This is commonly seen in Layer-3 routed networks.
6 c/ k2 s8 n% K, G
, m4 z3 U$ g' ~$ q' F$ L9 d8 NIssues to Consider with Asymmetric Routing; P4 d% F: r" t

+ K, f2 O, X. |. {Asymmetric routing is not a problem by itself, but will cause problems when Network Address Translation (NAT) or firewalls are used in the routed path. For example, in firewalls, state information is built when the packets flow from a higher security domain to a lower security domain. The firewall will be an exit point from one security domain to the other. If the return path passes through another firewall, the packet will not be allowed to traverse the firewall from the lower to higher security domain because the firewall in the return path will not have any state information. The state information exists in the first firewall.8 V' X( E3 O. D* W& E( w
( p* S1 V1 R$ U" w2 K
Specifically for TCP-based connections, disabling stateful TCP checks can help mitigate asymmetric routing. When TCP state checks are disabled, the ASA can allow packets in a TCP connection even if the ASA didn’t see the entire TCP 3-way handshake. This feature is called TCP State Bypass.
7 ?8 l/ U" o  i$ N) E. P, D6 }; q% _. h2 C3 {
Note: The active/active firewall topology uses two firewalls that are both actively providing firewall services.
板凳 2017-7-1 20:18:32 回复 收起回复
回复 支持 反对

使用道具 举报

 楼主| 发表于 2017-7-2 14:51:50 | 显示全部楼层
感谢答复,欢迎大家继续回复,参与讨论喔。
地板 2017-7-2 14:51:50 回复 收起回复
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-4-27 20:03 , Processed in 0.079783 second(s), 25 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表