Updating the Firewall Software

The final topic to consider when managing firewalls is updating the firewall software. There are two update the software. One reason is to take advantage of new capabilities added to newer software v reason is the need to fix bugs and vulnerabilities in the software. Like all software, firewall software contains many lines of code. The code in the firewall may have been rigorously tested, but there wil that the software developers did not consider or just outright overlooked. A corner case is a situatio outside of normal operations. Typically, corner cases arise when multiple conditions occur simultane extreme level. For example, a DHCP starvation attack (an attack where the attacker tries to exhausl ability to provide clients with leases by generating multiple requests for all the IP addresses in the D along with a distributed denial-of-service (DDoS) attack. The combination of these two attacks may exhaustion on the firewall or trip some other software bug that could make the firewall unusable. Th in the firewall resetting itself or may result in the firewall allowing invalid traffic through when it sho

Choosing the Correct Version

The first step in updating a firewall's software is determining the right version. This means determin will run on the firewall platform to be upgraded and which version provides all the capabilities desire firewall is licensed. On SOHO firewalls such as a Linksys device or the PIX 501/506E, the most recen the correct version to use. However, recently Cisco released PIX OS 7.0 for the PIX platform. This ve PIX platforms except for the PIX 501 and the 506E platforms. Take care when a new software versic manufacturer that the requirements for that version are met before attempting to upgrade the firew could result in the firewall being nonfunctional and requiring a software downgrade to a previous vei operation.

In the case of Linux NetFilter-based firewalls, the administrator must be careful to ensure that the N is compiled into the Linux kernel (either statically or as dynamically loaded modules). In the more re of the 2.6 series, the NetFilter is automatically included in the kernel configuration as dynamically lo

Reading the Release Notes

One of the first items to do when deciding with which software release to upgrade a firewall (or any matter) is to read the release notes for that version. The release notes typically include a detailed lis devices, new features in the release, and software bugs fixed in the release. In addition, some mani list of outstanding bugs that have not been addressed in the release at the time of shipment. The re represent a one-stop shop for much, if not all, of the necessary information needed to determine wh release being considered is appropriate for the firewall to be upgraded.

Defects and Bugs

Firewall software is complex and contains many subsystems and lines of code. Although the vendors to identify potential bugs or other errors in the software, not all possible cases can be discovered du the software is released to the general public. Therefore, possible bugs and vulnerabilities in the sof detected until after the software has been released.

Vulnerabilities

A vulnerability is a defect that might result in the potential exploitation of the firewall by an attacker denial-of-service (DoS) attack or to gain access to the firewall itself. A vulnerability can also be caus misconfiguration of the firewall. An example of a vulnerability in firewall software is the Cisco PIX Te described on SecurityFocus (http://www.securityfocus.com/bid/6110). This vulnerability, although n to the PIX itself, causes the PIX Telnet/SSH service to become nonresponsive. Cisco immediately rel problem in PIX OS 6.2.2.111.

A vulnerability due to a misconfiguration of the firewall can range from allowing access to Remote Pi ports on systems behind the firewall to not setting an access password on the device itself. These ty are not mitigated by software upgrades but rather by correcting the configuration of the device. One ways to find any ports that may be open due to a firewall misconfiguration is to use a network-scani Nmap (available at http://www.insecure.org) or Foundstone's Fscan (available from http://www.fou

Tracking a Defect

So, a bug or a vulnerability has been discovered in the software version running on your firewall. Wl If the vendor has released a version that resolves the bug or vulnerability, the simplest solution is to apply the patched software. If no fixed software is available, it is important to keep track of the bug workarounds the vendor has devised. Typically, vendors provide a portal on their websites that inclu information and whether a specific defect has been resolved. For Cisco PIX devices, the Product Seci Response Team provides security advisories that can be viewed on the Cisco website at http://www In addition, for registered users, a database of security-related and non-security-related defects is a devices, this section is part of their technical support website (http://www.linksys.com). Information the Linux kernel is available at the Linux Kernel Archives website (http://www.kernel.org). For Linux there is a specific bug-tracking system, http://bugzilla.kernel.org. For bugs that are NetFilter specifi NetFilter code in the kernel or the utilities used to manipulate the NetFilter firewall), there is http ://l Regardless of the device, it is important to be aware of bugs and other software issues to be prepari new vulnerabilities that they may introduce into the network.

4 PREY

Continue reading here: The Syslog Protocol

Was this article helpful?

0 0