Download presentation
Presentation is loading. Please wait.
Published byAvis Cooper Modified over 9 years ago
1
Firewall Technology and InterCell Communication Peter T. Dinsmore Trusted Information Systems Network Associates Inc 3060 Washington Rd (Rt. 97) Glenwood, MD 21738 ptd@tis.com 301-854-5706
2
Overview Firewall Background –network architecture –firewall technologies –other features –policies DCE Communications Solutions?
3
What is a Firewall? Implements a communication policy between two networks Funnels communications to controlled point –incoming –outgoing Used to –protect –separate –restrict –log –control
4
Firewall Architectures Dual Homed Host Firewall Network ANetwork B firewall typically has addresses for interfaces may be multi-homed
5
Firewall Architectures Perimeter Network/DMZ Firewall Server Network APerimeter Net/DMZNetwork B server may provide DCE services server may use DCE services to reach info on Net B
6
Firewall Technologies Packet Filtering –based on IP headers, TCP/UDP headers, stateful (or not), appl info Circuit Gateway –terminates connection Application Gateway –application knowledge verifies format follows protocol authentication access control of application functions logging
7
Firewall Features Network Address Translation (NAT) Address hiding Virtual Private Networks (VPN) Content Scanning –virus scanning –integrity –proof of origin
8
Firewall Policies “that which is not expressly permitted is denied” “that which is not expressly denied is permitted” “all incoming connections are authenticated” “all incoming traffic is authenticated”
9
DCE Communications UDP - no state Dynamic port allocation Encrypted traffic Intrinsic authentication mechanism Network addresses in protocol messages Assumption of full network connectivity
10
Solutions? Restrict DCE to TCP Limit port range VPN DCE servers on firewall DCE servers in DMZ DCE knowledgeable proxies –handle message NAT –listen to ports dynamically –authentication –other access control
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.