12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

28 Network security overviewManagement scenariosManaged security gateway (through another security gateway)In some situations, it may be necessary to manage a security gateway that is protected by another securitygateway. This final scenario presents a unique challenge; each security gateway listens for managementrequests and must understand whether the request was truly directed to itself, or another security gatewayon the protected network. Figure 2-5 shows an external SGMI that manages both security gateways.Figure 2-5Managed security gateway through another security gatewaySGMIRouter<strong>Security</strong>Gateway<strong>Security</strong>GatewayThe problem this scenario presents is a function of how the security gateway handles requests. Regardlessof the destination, all requests that go through the security gateway initially have their destination addresschanged to that of the security gateway to force them up the stack for processing. If the request is foranother system, and the connection request meets all requirements, a new connection is created to thedestination address.For management connections, however, the security gateway sees that the destination address is thesecurity gateway and the destination port is 2456, and intercepts the packet as a request to manage locally.Management requests are caught by the management server prior to when the security gateway creates thenew connection, so without modification, any management request sent to or through the security gatewayis processed by the first security gateway encountered.There are two different approaches to resolving this issue, depending on whether or not the IP address ofthe second security gateway is routable.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!