WesCorp segments net, runs multiple security apps to protect from attacks
Like many businesses, WesCorp Credit Union was worried that if worms and viruses got inside its firewall, they would run amok unchecked, so it sought a cost-effective way to contain them.
The $25 billion credit union and financial services provider to other credit unions knew it wanted a fairly large set of security technologies to identify and halt the spread of malicious activity, but it was concerned the costs would be prohibitive, says Chris Hoff, director of enterprise security services at the San Dimas, Calif., firm.
The strategy, implemented last year, called for breaking the internal network into about 30 virtual LANs (VLAN ) that would help the company cordon off chunks of the network and more readily help stem the spread of any attacks, he says. The strategy also required security applications in place to scan traffic between the VLANs. “At a minimum we wanted firewalling, intrusion detection and/or intrusion prevention, anti-virus for certain protocols, content filtering and caching for Web-based applications,” Hoff says.
Ultimately, WesCorp drew on security software from Check Point, Internet Security Systems, Trend Micro and WebSense, and Squid open source caching software, and saved more than $1 million by running them all on one Crossbeam X-80 chassis rather than individual hardware platforms, he says.
“What spurred all this was how we would deal with quarantine and containment,” Hoff says, on the chance that an attack made it through the network’s perimeter security. “What we really care about is that whatever you are accessing is authorized and is good traffic, not bad traffic.”
The traditional way of doing so would be to identify critical physical branches in the network – LAN segments or VLANs – and install security devices at each, which would have called for about 20 new devices on the network, he says.
“That would have meant separate or aggregating firewalls, intrusion-detection boxes, content filtering and caching. Plus, we would end up having to either scale or do clustering and load balancing to get the performance and reliability we need,” Hoff says. Using multiple hardware platforms to support all the applications now running on the Crossbeam platform would have cost $1.7 million, he says, while list price for the Crossbeam gear was about $600,000.
Using one Crossbeam X-80 application switch, the company instead added a device, which at first blush seems to be a potential single point of failure, but redundancies within the chassis itself make failure unlikely, Hoff says. The chassis includes four power supplies and back-up server blades that kick in when one fails. Individual blades can be clustered to perform load balancing and failover.
While the machine supports five security applications, Hoff didn’t necessarily want all traffic scanned by all five, so he designed different flow sequencing for different types of traffic.
“Based on the flow sequencing, when a packet comes in you can sent it to the IDS, then send it to the firewall; and when it’s done with the firewall, send it through the IDS again; and when it’s done going through the IDS, send it through the caching,” Hoff says. “You can basically send traffic through whatever stages of application inspection or filtering you want.”
The chassis can be configured to switch software on reserve blades as needed, Hoff says. For example, if a firewall blade fails, a reserve content-filtering blade can be rebooted automatically and brought back up as a firewall.
The major potential problem using Crossbeam gear, Hoff says, is organizational rather than technical. Network and security staff have to work together because placing the Crossbeam box in the network invades space traditionally managed only by the network staff, he says.
“We’re basically looking at the integration of Crossbeam in our core,” Hoff says. “We couldn’t get away with that if we had the traditional antagonistic relationship between network services and security services because the network services people would see it as a threat to how traffic gets from Point A to Point B.”
In the year since the Crossbeam X-80 was installed, it has detected a few new viruses and notified administrators to shut down the infected machines. “We haven’t had the grand test yet, and quite honestly we hope we never do,” Hoff says.




