Firewall Wizards mailing list archives

Re: Firewall routing thought...


From: Gwendolynn ferch Elydyr <gwen () reptiles org>
Date: Tue, 6 Jul 2004 13:50:18 -0400 (EDT)

On Fri, 2 Jul 2004, Eric Appelboom wrote:
If one has firewall A with external ip on the same subnet as firewall B.
How common is the practice of adding static routes on firewall A for The
networks protected by firewall B and the other way round.

Would this technique not lower the latency or overheads of not having the
packets en route from firewall A to firewall B being sent to its default
gateway to then be processed by the router and sent to firewall B. Thus the
traffic would be direct A<-->B

I think you're a bit confused about how routing/routers work, and what
the relative "costs" are.

Your network layout isn't really clear from your email, but as soon as
you make a change in broadcast domains, the router is going to be involved.

Besides being a tad messy would it be considered and at what traffic rate?

Well - I generally wouldn't consider it at any traffic rate.

First of all, it's not likely to improve your latency or overhead. The
packets are still going to be seen by the router.

Secondly, you've now added complexity to your network in the form of a
bunch of static routes in different places, all of which need to be
maintained - and almost certainly won't be, until some changes breaks
things.

"a tad messy" is almost always a signal to run away screaming.  That's
code for "unmaintainable" and "all-nighters".

Ranting briefly, a good design should be clear and easy to understand
and explain.  If you find yourself handwaving, or muttering quickly to
get past some point in your design [or adding in "here be dragons"],
you should stop and figure out why.

cheers!
==========================================================================
"A cat spends her life conflicted between a deep, passionate and profound
desire for fish and an equally deep, passionate and profound desire to
avoid getting wet.  This is the defining metaphor of my life right now."


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: