Can the ProjectWise handshake be standardized?
As discussed in Case CS0088762, ProjectWise has a handshake that is “wrapped into proprietary protocol (additional ACKs for confirming reception).”
We currently use a Cisco firewall with SNORT 2.0. When we upgrade to SNORT 3.0, however, ProjectWise ceases to work. As summarized by our firewall team that investigated the issue with Cisco, this is because the ProjectWise handshake is not standard:
“ProjectWise traffic is arriving out of order according to Cisco. Ex. The FTD receives the Client Hello packet and expects to see the rest of the handshake prior to data packets coming through however the way ProjectWise is sending data we're seeing the client hello, then data packets immediately afterwards, before the handshake is completed. Basically; the handshake is not happening per specifications.”
As a result, we are not able to upgrade to the latest version of SNORT. If it becomes industry standard to require standard handshakes, this may potentially cause more problems in the future with firewalls.