Re: asymmetric routes/security concerns/Fortinet

2011-01-08 Thread Tarig Ahmed
Tarig Yassin Ahmed On Jan 7, 2011, at 10:45 PM, Anthony Pardini wrote: You can allow asymmetric traffic on the Fortinet, but you lose some functionality. Firewalls aren't routers and pretty much all of them behave in the similar manner. Hi I think u can solve this issue only by addin

Re: asymmetric routes/security concerns/Fortinet

2011-01-08 Thread Robert Bonomi

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Randy Bush
you have sent a message to me which seems to contain a legal warning on who can read it, or how it may be distributed, or whether it may be archived, etc. i do not accept such email. my mail user agent detected a legal notice when i was opening your mail, and automatically deleted it. so do not e

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread John Kristoff
On Fri, 7 Jan 2011 13:56:00 -0500 Greg Whynott wrote: > the localpref is something I'll look at, thanks for that. I'm not > a BGP expert by any stretch, and our requirements here are > "simple". we are not a transit.I've only attempted to make the > config safe, not efficient. I'm not

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Greg Whynott
Randy your assumptions are correct, all outbounds get that slapped on them, automagically. good thing you have read the same magic book and can counter! 8) I don't or ever did expect anything from you, not sure why you thought i might. do you think I should quit this organization because w

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Ken Chase
On Fri, Jan 07, 2011 at 03:13:02PM -0500, Greg Whynott said: >Thanks Ken, > >Some good stuff there, thanks. > >Since my original email, i think i've come up with a partial solution not requiring the far end's involvement. If not, at least it would get us into a better position to

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Greg Whynott
Thanks Ken, Some good stuff there, thanks. Since my original email, i think i've come up with a partial solution not requiring the far end's involvement. If not, at least it would get us into a better position to utilize the ORION network when possible. We peer over a L2 tunnel with a

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Anthony Pardini
You can allow asymmetric traffic on the Fortinet, but you lose some functionality. Firewalls aren't routers and pretty much all of them behave in the similar manner. On Fri, Jan 7, 2011 at 11:40 AM, Greg Whynott wrote: > > > Hello, > > we have multiple internet connections of which one is a res

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Ken Chase
On Fri, Jan 07, 2011 at 01:56:00PM -0500, Greg Whynott said: >Based on the fact that we access ORION via one of our ISPs (3rd party, we don't BGP/directly peer with ORION), I'm not sure if i can use this solution here. I could do that for the routes learned from that ISP, but we receive th

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Justin M. Streiner
> The admins at this university claim this is by design and for security reasons.. My response was the entire internet is asymmetrical and while this may of been a legitimate concern in the 90's, I don't think its a real concern anymore if things are set up correctly. They suggested we add

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Greg Whynott
Thanks John for your input. You are correct, ORION is a dedicated high speed research network. Based on the fact that we access ORION via one of our ISPs (3rd party, we don't BGP/directly peer with ORION), I'm not sure if i can use this solution here. I could do that for the routes learne

Re: asymmetric routes/security concerns/Fortinet

2011-01-07 Thread John Kristoff
On Fri, 7 Jan 2011 12:40:32 -0500 Greg Whynott wrote: > we have multiple internet connections of which one is a research > network where many medical institutions and universities are also > connected to threw out the country. This research network (ORION) > also has internet access but is not m

asymmetric routes/security concerns/Fortinet

2011-01-07 Thread Greg Whynott
Hello, we have multiple internet connections of which one is a research network where many medical institutions and universities are also connected to threw out the country. This research network (ORION) also has internet access but is not meant to be used as a primary path to the internet b