CDRouter Support

Advanced DMZ testing

knowledge-base version 12.13

CDRouter contains a dmz.tcl test module that verifies DMZ functionality for a range of TCP and UDP ports. When testing the DMZ functionality on a router it is important to configure a CDRouter port range that contains all the services that you might expect to run in a DMZ.

As vendors have added special services to routers to handle new functionality such as TR-069 and SIP ALGs, the DMZ functionality can be inadvertently broken. We have seen cases where SIP does not work through a DMZ because the router’s SIP-ALG or SIP Proxy rejects certain packets from the WAN rather than passing them to a DMZ host.

There are two techniques you can use to improve your DMZ testing:

Large Port Range for DMZ Testing

Configure the entire port range when testing in a DMZ configuration. This will make sure all ports are getting through the DMZ. This can catch cases where new applications such as SIP do not actually make it through the DMZ.

testvar portScanStart 0
testvar portScanStop 65535

Back-to-Back Router Testing

CDRouter maked it easier to test two routers in a back-to-back configuration. This allows CDRouter to run more realistic application tests through the DMZ configuration of the router.

The first router is configured as the normal router under test. The second router should be placed in a DMZ configuration. Since the WAN interface of CDRouter actually connects to the LAN interface of the second router behind NAT, CDRouter can only use a single IP address for WAN connectivity.

This mode of operation can be enabled by configuring the remoteHostIp on the WAN side with an additional private IP address. When connecting from the LAN, clients will use the IP address remoteHostIp. However, the actual protocol stack will run using remoteHostPrivateIp. The second WAN router must be configured with a DMZ host that matches remoteHostPrivateIp.

testvar remoteHostIp
testvar remoteHostPrivateIp

When CDRouter is running in this type of configuration, several test cases that use multiple IP address on the WAN are skipped automatically. Only the remoteHostIp is used on the WAN side. Some test modules do not support this type of configuration.

Example Setup for Back-to-Back Routers

# -- the lanIp matches Router 1's LAN IP address
testvar lanIp      

# -- CDRouter WAN configuration matches LAN side of Router 2
testvar wanIspIp   
testvar wanIspAssignIp
testvar wanNatIp   
testvar wanMode              static

# -- the remoteHostIp matches Router 2 WAN side
testvar remoteHostIp

# -- the remoteHostPrivateIp is an IP on Router 2's LAN
testvar remoteHostPrivateIp

# -- adjust the HOP count based on the number of hops
testvar IPv4HopCount         2



About CDRouter

CDRouter is made by QA Cafe, a technology company based in Portsmouth, NH.

Get in touch via our Contact page or by following us on your favorite service: