According to the way the firewall is implemented, what types of firewalls can be divided into?

Source: Internet
Author: User
Tags stateful firewall

1. Packet filter Firewall

2, Proxy-type firewall

3. State Detection Firewall

Specific Description:

1, packet filtering firewall uses the specific rules defined to filter the packet, the firewall directly obtains the packet IP source address, the destination address, the TCP/UDP source port and the TCP/UDP destination port.

Use some or all of the above information to compare by fraud rules, filtering packets through the firewall. The rules are defined according to the characteristics of IP packets, which can be used to define the conditions through which the firewall packets are defined by the above four conditions.

Packet filtering firewalls are simple, but lack flexibility. In addition, packet filtering firewall is a policy check for each package, too many policies can lead to a sharp decline in performance.

2, proxy Firewall is the firewall as an intermediate node of access, the firewall is a server for the client, the firewall is a client for the server.

Proxy firewall security is high, but the development cost is very large, for each application to develop a proxy service is difficult to do, so proxy-type firewall can not support a very rich business, only for some applications to provide proxy services.

3, stateful detection firewall is a kind of advanced communication filtering. He examines the application layer protocol information and oversees the connection-based application layer protocol status. Stateful firewalls dynamically determine the connection state of several TCP/UDP connections by detecting

Whether the message can pass through the firewall. In a stateful firewall, a session table entry is maintained, and the session table entry allows you to determine which connections are legitimate and which are illegal. Now the main firewall products for the status detection firewall.

According to the way the firewall is implemented, what types of firewalls can be divided into?

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.