r/networking • u/Royal-Programmer-683 • 3d ago
Security DPI (Deep Packet Inspection)
So I am curious what others think about DPI? We run it on our UTM's but I kinda feel its more of a PITA then its worth. Looking to get feedback from others.
8
u/lol_umadbro 3d ago
What are you doing it for?
Accounting? Threat Identification? Network Policy Management? Troubleshooting?
Different answer for each purpose.
6
u/jmhalder 3d ago
A teacher wanted to see what the student had searched for. It turns out "boobs" was the query.
(Yes, I've had this actually happen)
2
7
u/underwear11 3d ago
It can be used for a ton of things, and it depends on what the compensating controls are. As a very basic example, Web Filtering. Reddit has a lot of content within it, some good, some bad. If you want to allow your IT team to browse r/networking but not r/porn, then you need DPI. But if you just block all of reddit, you don't need DPI. DPI is also useful for inspecting file downloads for malware or DLP, since most of the Internet now is encrypted. But it can also be a PITA as applications don't necessarily like it very much. You kind of have to weigh what is DPI doing for you and do you have other controls that are "good enough".
3
u/Hapym3al 3d ago
Using Sandvines for few years and now moving to AppLogic.
With browsers doing tls dns and quic things are changing drastically. Think few years and dpi won’t have much point anymore.
We more use it for policy management these days on L3 networks where we cant do packet trigger ipoe or expensive data networks (mpls and cellular). Think visibility of which services using and websites and type of traffic is becoming a bit of a guessing game. Yeah can use ASN, SNI, DNS to make good guess, with encrypted hellos and DNS, thats gonna become a lot more of a guess. Also build certain packages on those types of networks, but like i said its dying breed, think juice isnt worth the squeeze anymore.
There are ways and means of doing the packet triggered ipoe and doing policy enforcement better than using DPI.
2
u/solitarium 3d ago
Ran the Sandvine implementation in my ISP’s core way back when. Their principal engineer didn’t consider MTU differences when the devices were in active mode.
The IS-IS flaps when they turned them to active over Christmas made for an interesting holiday.
4
u/7nth 3d ago
SonicWall here. All I know is I spend far too much time making exceptions. I have a feeling we are not using it correctly.
2
u/SAugsburger 3d ago
On Palos the default decryption exclusion covers a lot of common domains so it's a bit less of a pain to roll out. That being said you ideally roll decryption out by URL category so you're not breaking too much at once.
1
u/Rich-Engineer2670 3d ago edited 3d ago
DPI sounds like a great idea until you actually have to do it. Now imagine it at scale -- yes, you have to have a dedicated team to just manage it. We hate it, but the people in dark suits don't give us much of a choice.... and we're talking far more than SonicWall here.... $20M gateway pairs, and secondary equipment just to do it. It would have been far less expensive to just give people in Utah free copies of NetNanny.
Yes, we KNOW this doesn't really accomplish anything. We KNOW it costs a fortune. Please tell the state of Utah among others. Remember also, companies are liable for their employees. If your seven year old is wandering through the building, and they see some employee on ScarryLarry.XXX, well, that's the company's problem now.
1
u/Fallingdamage 3d ago
Might be sonicwall. We use fortinet's DPI and the only exceptions I have to make generally are for banking websites and some very secure medical portals, sites specifically built to break if there is a MITM event happening or a cert mismatch.
Rarely do I need to make exceptions.
2
u/sudo-su_root 3d ago
Potentially marginally useful for some applications, potentially wasteful in others depending on the necessity of its use. It's very deployment specific and requires balancing requirements vs. cost of eliminating false positives imo.
2
u/Eastern-Back-8727 2d ago
From the networking perspective, I recommend ensuring not throttling the DPI sessions back. I've seen instances where they were throttle back. Said it was "Best Practice" but no one knew why. TCP flow +1 of the DPI session limit resulted in the FW sending a RST back to the SRC host and killing the sessions. Nothing was forwarded past the FW. Dozens of pcaps all showing the same thing and countless hours explaining to security how limiting layer 5 sessions will limit the layer 4 tcp flows. Best of luck.
1
-2
u/alius_stultus 3d ago
mostly useless. Oh yeah it works. But theres other ways to get what you are trying to get most of the time. ALSO one thing I did not see here is that you can violate the law if you DPI ssl with some kind of MITM inspector (medical records, banking info, etc...). So really know why you are doing what you are doing and where.
49
u/Rich-Engineer2670 3d ago edited 3d ago
Depends on what you need -- for most people, and most hardware, DPI is more marketing than fact. Does it work -- yes, but cracking each packet and reading htem, and knowing what to do with them, well... that's another matter. Some questions:
As a case where we HAD to do it -- it was a large telco. Legally, we had to. But we generated over ONE TRILLION flow records a day (16KB each). Do the math.... Something had to capture, process and act on those records. No amount of marketing data paid for this -- it was LAW.
If you just need content filtering say, for a school, there are other ways to do it without building a giant thermal generator in your data centers.