防火墙技术类型及优缺点(Types and advantages and disadvantages of firewall technology).doc
文本预览下载声明
防火墙技术类型及优缺点(Types and advantages and disadvantages of firewall technology)
First, the basic classification of firewalls
1. packet filter firewall
The first generation firewall and the most basic form firewall check each passing packet, either discard, or release, depending on the set of rules established. This is called packet filter firewall.
In essence, packet filtering firewalls are multiple access, indicating that it has two or more than two network adapters or interfaces. For example, as a firewall device, there may be two network cards (NIC), one connected to the internal network and one connected to the public Internet. The task of firewalls is to serve as communications police to guide packages and intercept dangerous packages.
The packet filter firewall checks each incoming packet to see the basic information available in the package (source address and destination address, port number, protocol, and so on). Then, compare the information with the rules set up. If the telnet connection has been set up and the destination port of the package is 23, the packet will be discarded. If the incoming Web connection is allowed and the destination port is 80, the package will be released.
A combination of multiple complex rules is also possible. If the Web connection is allowed, but only for a particular server, the destination port and the destination address, the two must match the rule before passing the packet.
Finally, you can determine what happens next when a package arrives and if there are no rules defined for the package. Usually, for security reasons, packets that do not match the incoming rules are discarded. If you have reason to let the package pass, you must establish rules to handle it.
Examples of building packet filter firewall rules are as follows:
Packets from private networks only allow packets from an internal address to pass because other packages contain incorrect Baotou information. This rule prevents anyone inside the network from attacking a
显示全部