Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, February 04, 2007

Checkpoint: Performance Tuning

Here is the link:
http://www.checkpoint.com/techsupport/documentation/FW-1_VPN-1_performance.html

This guide combines the Solaris performance and security tuning guides, but focuses specifically on the settings that effect your firewall performance.

Settings like:
  • Tuning the STREAMS queues for high-throughput VPN-1 gateways
    • set sq_max_size = 100 (for a Solaris gateway with 256MB RAM)
  • Tuning the TCP hiwater parameters for maximal throughput
    • ndd -set /dev/tcp tcp_xmit_hiwat 65535 (default 8192)
    • ndd -set /dev/tcp tcp_recv_hiwat 65535 (default 8192)
  • Tuning the TCP Slow Start and TCP queue sizes
    • set tcp:tcp_conn_hash_size = 16384
    • ndd -set /dev/tcp tcp_slow_start_initial 2 (default 1)
    • ndd -set /dev/tcp tcp_conn_req_max_q 1024 (default 128)
    • ndd -set /dev/tcp tcp_conn_req_max_q0 4096 (dafault 1024)
    • ndd -set /dev/tcp tcp_time_wait_interval 60000 (default 240000)

Saturday, February 03, 2007

Solaris: Kernel Tuning for Security

The guide is here:
http://www.securityfocus.com/infocus/1385

This is specifically about tuning your network setting to prevent network based attacks. For example:

Worried about ARP attacks:

# ndd -set /dev/arp arp_cleanup_interval
# ndd -set /dev/ip ip_ire_flush_interval

How about IP forwarding or SRC routing:

# ndd -set /dev/ip ip_forwarding 0
# ndd -set /dev/ip ip_strict_dst_multihoming 0

# ndd -set /dev/ip ip_forward_directed_broadcasts 0
#
ndd -set /dev/ip ip_forward_src_routed 0

How about SYN Floods? First you need to get a baseline of SYNs . Either of these commands will do:

# netstat -an -f inet | grep SYN_RCVD | wc -l
# netstat -s -P tcp

Then you need to read the guide

NMAP: More port scanning techniques

This is the guide to nmap: http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1195745,00.html

Explains how to use Nmap's:

TCP Null (option –sN), FIN (option –sF) and Xmas (option –sX) scans to get through non-statful firewalls and packet filtering routers.

IPID Idle scan (option -sI) to to map out IP-based trust relationships between machines, and get through firewalls.

TCP ACK scan (option -sA), to help map out firewall rule sets.

As well as many other ways to test firewall configurations.