tailieunhanh - Application Layer Filtering

Application Layer Filtering Application proxy firewalls are the most intelligent firewall architecture. | Application Layer Filtering Application proxy firewalls are the most intelligent firewall architecture. By intelligent we mean that an application proxy firewall can perform the most detailed inspection on data before making a filtering decision. An application proxy firewall can decode and process at the application layer the data contained in packets. Consequently application proxy firewalls can filter based on the actual application data content. For example with a packet-filtering firewall the firewall can merely permit or deny traffic based on data such as the IP protocol in use. So a packet-filtering firewall merely knows whether it should permit or deny HTTP traffic for example and processes the traffic accordingly. With an application proxy firewall however it not only knows whether it should permit or deny HTTP traffic it can also be configured to filter based on the type of HTTP traffic. Such a configuration allows an application proxy firewall to interrogate the data and identify malicious web traffic such as being able to distinguish between normal HTTP traffic and Code Red HTTP traffic and filter accordingly. This capability gives firewall administrators a tremendous amount of flexibility and control over exactly what traffic will and will not be permitted. How Application Filtering Works Application filtering typically functions through the use of processes known as application proxies application gateways service proxies application filters Microsoft ISA Server 2004 term or fixups Cisco term . These application filters typically provide stateful application layer filtering of the data that is traversing the firewall. Generally the application filters perform two functions Protocol access Protocol access provides a means of permitting secondary connections for protocols and applications that use multiple protocols for example FTP which uses separate and distinct control TCP port 21 and data TCP port 20 protocols . Protocol security Protocol security .

crossorigin="anonymous">
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.