Firewall
Our Firewall Solution make it easy to communicate securely with customers,
partners, employees, and remote users. From advanced software solution to
all-in-one integrated security appliance, Firewall family provides the flexibility to
choose just the right levels of network protection.
|
Type of FIREWALL solutions
1. Network layer and packet filters
Network layer firewalls, also called packet
filters, operate at a relatively low level of the TCP/IP , not allowing packets
to pass through the firewall unless they match the established ruleset. The
firewall administrator may define the rules; or default rules may apply. The
term packet filter originated in the context of BSD operating
systems.
Network layer firewalls generally fall into two sub-categories,
stateful and stateless. Stateful firewalls maintain context about active
sessions, and use that "state information" to speed up packet processing. Any
existing network connection can be described by several properties, including
source and destination IP address, UDP or TCP ports, and the current stage of
the connection's lifetime including session initiation, handshaking, data
transfer, or completion connection . If a packet does not match an existing
connection, it will be evaluated according to the ruleset for new connections.
If a packet matches an existing connection based on comparison with the
firewall's state table, it will be allowed to pass without further
processing.
Stateless firewalls have packet-filtering capabilities, but
cannot make more complex decisions on what stage communications between hosts
have reached.
Modern firewalls can filter traffic based on many packet
attributes like source IP address , source port , destination IP address or
port, destination service like WWW or FTP. They can filter based on protocols,
TTL values, netblock of originator, domain name of the source, and many other
attributes.
Commonly used packet filters on various versions of Unix are ipf , ipfw , pf, and all other BSDs, iptables (Linux).
|