HOME LITERATURE MarketNotes
|
ZoneRanger: Secure ICMP Proxy (Ping Proxy) |
|
|
More often than not, the simplest way to verify that a network device is operating and reachable is the simple, ubiquitous ICMP echo request, more commonly referred to as “ping”. Applications for this simple but powerful protocol mechanism range from the familiar “ping” command, to sophisticated management applications that use ICMP echo requests to poll device status or measure network latency. The common industry practice where networks are partitioned into security zones using conventional firewalls creates a problem for users of these management applications, requiring them to choose between two equally unacceptable alternatives: prevent ICMP from passing through the firewall, accepting limited ability to manage the devices beyond, or allow ICMP to pass through the firewall, accepting the associated security risks. ZoneRanger resolves this dilemma, acting as an application-layer proxy firewall for ICMP echo request/response traffic, enabling management applications to extend their reach beyond firewalls, while mitigating the associated security risks. All ICMP echo request/response protocol traffic is carefully inspected by the ZoneRanger, and responses are matched with known outstanding requests, before being allowed to pass. 
ICMP is part of a growing suite of management protocols supported by ZoneRanger. Other supported protocols include:
|
|
How does ZoneRanger fit into your network?What others are saying..."Tavve has developed the ZoneRanger product, in order to enable companies to leverage their centralized management infrastructure across firewall-partitioned networks, while mitigating risks associated with management protocols." Tavve: ZoneRanger Subraya Mallya PrudentCloud.com "Without a more secure approach to managing the protocols and tools that manage the network - including the 'trusted' internal network - enterprises may be exposing themselves to more risk than they realize."
Scott Crawford, CISSP, ISSAP, ISSMP Senior Analyst, Enterprise Management Associates
"ZoneRanger effectively extends the reach of management applications to devices located beyond firewalls, eliminating the need for complicated firewall configurations, extensive agent deployments, or expensive application replication. ZoneRanger also provides security, acting as an application layer proxy firewall, inspecting and validating the traffic relayed between applications and devices."
Jim Doble, CISSP CTO, Tavve
|