republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Linksys » SPI?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Question about Incoming Log »
« Logging from Two BEFSR41 Routers to One PC?  
AuthorAll Replies


obtix
Obtix.Net

join:2000-11-26
West Harrison, NY
 reply to PapaDos
Re: SPI?

that still doesnt answer my question
--
vexation | vexation@epix.net


PapaDos
Cum Grano Salis
Premium,MVM
join:2001-02-08
Lasalle, QC
·Bell Sympatico

You mean about the forwarding ?
It is the normal behavior. If you can't configure the SPI to restrict its action somehow, it would conflict with the forwarding. So Linksys made it an exclusion choice.
--
Software & Russian roulette, Hm...


Bill_MI
Bill In Michigan
Premium,MVM
join:2001-01-03
Royal Oak, MI
·EarthLink


edited
reply to obtix
said by vexation:
that still doesnt answer my question
Stateful Packet Inspection, traditionally, is a form of routing that keeps track of connection states. For example, TCP has the "connected" state while UDP is connectionless so is virtually unaffected by SPI. Here's the way the internal workings *should* be:

With SPI
Outgoing connection attempted from LAN-A to SITE-B.
SITE-B responds, parameters exchanged.
TCP state is "connected".
While state is "connected" forward all SITE-B to LAN-A.
TCP disconnects, kill connection immediately.

Without SPI
Outgoing connection attempted from LAN-A to SITE-B.
For the next 4 minutes forward any SITE-B to LAN-A.
Any packets starts a new 4 minutes.
If no packets after 4 minutes, kill connection.

See the difference? SPI is one heck of a lot "smarter" and can do fancy things a LOT more efficiently and correctly.

Now... does LinkSys do this? Hmmmm... your guess is as good as mine. I still see no affect except it seems to be a global safety switch. Yes, enabling SPI turns off Port Forwarding, kills ping reply and the TCP "closed" reply. Someday I'll be playing with a packet generator and really see what it really does. Of course I'll post my results .

How's that?
--
Expert Opinions: $5... I Shut Up: $10

[text was edited by author 2001-07-11 14:36:27]


SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
·Comcast Formerly ..

Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL
Still, NAT itself keeps a connection cache and is very "stateful" in this respect, even for UDP and ICMP. It even dynamically "opens" secondary ports, such as used for ftp-data.

So, in the absence of port forwarding, nothing else is needed because NAT protection is very strong. It seems the SPI switch just ensures that NAT protection is not bypassed by disallowing port forwarding.

"Real" SPI, such as found on the Zywall 10, really shines on 1-1 mapped and DMZ hosts where NAT protection is NOT available.


Bill_MI
Bill In Michigan
Premium,MVM
join:2001-01-03
Royal Oak, MI
·EarthLink


edited
Hi Synack. I guess you cannot argue the Linky has a form of SPI because outbound TCP connections on port 21 (hehe.. ftp!) are decoded for the PORT command, the outbound PORT command is corrected and the LinkSys forwards accordingly. The ftp data then flows correctly.

But I can assure you this action is not at all linked to the "SPI" option. Besides, I want LinkSys to start doing this on other ports and perform a few PASVs too!

EDIT: In fact, I think this ftp PORT translation was done by LinkSys because it made the LinkSys look bad customers couldn't ftp anywhere with MSIE (instead of the truth - MSIE doesn't know what it's doing! ).
[text was edited by author 2001-07-11 20:37:43]


obtix
Obtix.Net

join:2000-11-26
West Harrison, NY

  Thx Bill, thats really what i wanted to know about it i'll play around with it too, i just wasnt to sure what it was ment to do cept seemed to mess the router up (now i know why)
--
vexation | vexation@epix.net
Forums » Equipment Support » Hardware By Brand » LinksysQuestion about Incoming Log »
« Logging from Two BEFSR41 Routers to One PC?  


Monday, 01-Dec 10:45:47 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [24] Comcast Tries To Slow Verizon's Philly Entry
· [6] AT&T Metered Billing Trial Hits Second Market
· [2] Embarq Rejected Higher Offer
Most people now reading
· Is this a good thing for the net? [news,99366]
· Upverting DVD players vs Blue ray DVD players. [General Questions]
· Best way to clean your screen [LCD] [General Questions]
· Why does the USA have such a high divorce rate? [General Questions]
· Coalition Government Possible? [TekSavvy]
· Computer sends data without any input from me. [Security]
· Yet ANOTHER new DIR-655 Firmware v1.21 2008/11/13 [D-Link]
· What is Going On Out of VHO8? (Box Reset) [Verizon FIOS TV]
· RR: When an Upgrade is a Downgrade: Pushing Caps & ETF Fees [Road Runner]
· Hacking router [Security]