Moreover, if does not install the proxy procedure code for the specific application procedure, this kind of service will not be supported, cannot establish any connection. This establishment way refuses any not to be clear about the disposition the connection, thus has provided the extra security and the control.
For example, a user's Web browser possibly in 80 ports, but also frequently possibly is in 1080 ports, connected the internal network HTTP proxy firewall. The firewall will then accept this connection to request that and will change to it the Web server which requested.
This kind of connection and the shift to this user are transparent, because it is completely by acts the firewall automatic reduction.
Acts the firewall usual support some common application procedure to include:
HTTP
HTTPS/SSL
SMTP
POP3
IMAP
NNTP
TELNET
FTP
IRC
The application procedure proxy firewall may dispose the permission from internal network any connection, after it may also dispose the request user authentication, only then establishes the connection. The request authentication's way by for known user establishment connection's this kind of limit, has only provided the extra guarantee for the security. If the network receives the harm, this characteristic causes from the internal launching attacks possible big reduction.
4.NAT
Discusses firewall's subject, certainly must mention that has one kind of router, although technically speaking it simply is not the firewall. The network address transforms the (NAT) agreement to a public address to send the internal network many IP address translation on Internet.
NAT uses in small networks frequently and so on office, family, many user share sole IP address, and is the Internet connection provides some safety mechanisms.
When the internal user corresponds with a public main engine, the NAT tracing is the request which user does, the package which the revision spreads, such Bao Jiuxiang comes from the sole public IP address, then opens the connection again. Once has established the connection, back and forth flowed between the internal computer and the Web stand the correspondence is transparent.
When transmits one from the public network spreads to the connection without the request, NAT has set of rules to decide how to process it. If does not have to define the good rule beforehand, NAT is only simple discarding all spreads to the connection without the request, likely wraps such which the filtration firewall does.
But, looks like to the package of filtration firewall is the same, you may to accept the NAT disposition certain specific ports to transmit spread the connection, and delivers them a specific host address.
5. individual firewall
Now in the network is spreading many individual firewall softwares, it is the application procedure level. Individual firewall is one kind can protect the personal computer system safety the software, it may move directly on user's computer, the use and the condition/dynamic examination firewall same way, protects a computer to be exempt from the attack. Usually, these firewalls are install in the computer network connection clip on preliminarily, cause them to be possible to monitor spread spread network card's all network service.
Other pages: : <<Prev * 1 * 2 * 3 * 4 * 5 * 6 * 7 * Next>>
|