Subject: RARE user and assistance email list
List archive
- From: Frédéric LOUI <>
- To:
- Cc: "" <>, "" <>
- Subject: Re: [RARE-users] new feature is approaching: stateful firewall....
- Date: Tue, 8 Feb 2022 11:57:31 +0100
- Dkim-filter: OpenDKIM Filter v2.10.3 zmtaauth01.partage.renater.fr 9A4491402E7
Nice !
> try to imagine the wedge as a stateful firewall
Starting to chase into Palo Alto realm …
At the price of 100GE FW port processing (does it even exist ?) I presume
that WEDGE can be an interesting candidate.
Granted the fact that P4 FW profile can provide enough resources.
> Le 8 févr. 2022 à 11:45, mc36 <> a écrit :
>
> hi,
> yesterday i had a nice chat with a guy and he asked the right questions and
> then he allowed to use him as rubber-duck-debugger,
> so i got the idea, what if we introduce a new ace mode called 'punt' (while
> keeping the existing deny/permit)...
> then we'll have reflexive acls, but this punt functionality, later could be
> used (if programmed automatically) to do inspection...
> then, we can delay the programming of the inspect rules until we saw the
> tlc.sni to do domain based filtering, if needed...
> here is the proof-of-concept on dpdk, plus the export capability to
> freerouter:
> https://github.com/mc36/freeRouter/commit/8399d4e0c629b792f7e27f07945786ee6a4b90d5
> and the fixes needed to pass the testcase for racl:
> https://github.com/mc36/freeRouter/commit/71131ac28dff19289d8edbaebe3085e62175a2db
> it's racl so it'll go to tcam (and linearly searched in dpdk) but the
> concept seems to work,
> and the inspect sessions will be all-exact matches, that is, they'll
> consume sram (and binary search in dpdk) like the nat rules...
> next steps will be the bmv2 and tofino codebase to have the 'punt'
> functionality, then i'll proceed with the inspection....
> until that, try to imagine the wedge as a stateful firewall... :))
> regards,
> cs
- [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/08/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., Frédéric LOUI, 02/08/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/09/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/09/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/10/2022
- Re: [RARE-users] [rare-dev] new feature is approaching: stateful firewall...., Frédéric LOUI, 02/10/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/10/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/11/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/11/2022
- Message not available
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/11/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/10/2022
- Re: [RARE-users] new feature is approaching: stateful firewall...., mc36, 02/09/2022
Archive powered by MHonArc 2.6.19.