4.5 Flashcards
Types of firewalls
Web App
unified threat management
next generation
Port
logical communication endpoints on a computer or server
Inbound port
listens for connections
outbound port
used to connect to a server
Port classification
Well known (0-1023)
registered (1024-49151)
dynamic and private
Protocols
rules governing device communication and data exchange
screened subnet
aka dual homed host
its a dmz and its a logical separated network area between internal network and internet
Types of firewalls
packet filtering
proxy
stateful
kernel proxy
packet filtering firewall
fastest because its only checking packet acts similar to a router
cannot prevent ip spoofing due to limited insepction
operates at layer 4 (transport layer)
stateful firewall
tracks connections and requests allowing return traffic for outbound requests
operates at layer 4 (transport layer)
Proxy firewall
makes connections on behalf of endpoints enhancing security
- very secure
- acts as an intermidiary
- operaties on app layer or session layer - 5
kernel proxy
full packet inspection at every layer
minimal impact on network performance
placed close to every system thy protect
NGFW
next generation firewall
- application aware (distinguishes different types of traffic)
-conducts deep packet analysis
-operates fast
UTM
unified threat management firewall
-combines multiple securty functions in a single device
- functions can include firewall, intrusion prevention, antivirus, and more
-single point of failure protection
WAF
web app firewall
–http traffic
-prevents SQL injections etc
In line WAF
live attack prevention
device sits between the network firewall and the web servers
Out of band WAF
device receives a mirrored copy of web server traffic
ACL
access control list
- essential for securing networks from unwanted traffic
consist of permit and deny statements often based on port numbers
the
place most specific rules at the top and generic at the bottom
ACL key pieces of information
type of traffic
source of traffic
destination of traffic
action to take against traffic
Hardware based firewall
a dedicated network security device that filers and controls network traffic at the hardware level
commonly used to protect an entire network or subnet