Lesson 2 Flashcards
Firewall operations are historically based on one of the following technologies
Packet filtering – Application proxies or proxy servers (not to be confused with proxy firewalls ) – Network Address Translation – Stateful packet inspection – Next - generation context - aware firewalls
Resides at layer 3 & 4 of the OSI Stack
.
Packet Filters
________ or_________,are devices that operate as intermediary agents on behalf of clients that are on a private or protected network
Application proxies ,or proxy servers (typically Web proxies)
A _________is an Internet-facing proxy used to retrieve from a wide range of sources.
forward proxy
A ___________ is usually an Internet-facing proxy used as a front-end to control and protect access to a server on a private network.A reverse proxy commonly also performs tasks such as load-balancing, authentication, decryption orcaching.
reverse proxy
A Stateful Packet Filtering firewall maintains state information in a state table, referred to as a _________
.
connection table
Can perform stateful packet inspection as well as application layer inspection.
Application - level Proxy Firewall
A _____________ is a hardware - or software - based network security system that is able to detect and block sophisticated attacks by enforcing security policies at the application level, as well as at the port and protocol level.
next - generation firewall (NGFW)
___________ firewalls provide granular control of applications, comprehensive user identification, and location - based control.
Context - aware
_________ to secure TCP connections
________ for authenticating telnet, HTTP, and FTP connections
– Sequence Number Randomization ( SNR )
– Cut - through Proxy (CTP)
All _________ through the appliance are denied unless specifically permitted.
ICMP packets
The reason is that once you configure an IP address on the appliance’s interface, the appliance automatically creates a static route for the specified network address and associates it with the configured interface. This is referred to as a ________
connected route