Avaya B5800 User Manual Page 299

  • Download
  • Add to my manuals
  • Print
  • Page
    / 342
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 298
• Date flow 1: 172.16.16.14:1234 — 10.1.2.3:2345
• Date flow 2: 172.16.16.14:1235 — 10.1.2.3:2345
• Date flow 3: 172.16.16.14:1234 — 10.1.2.4:2345
Data flow 1 has two different port numbers and two different IP addresses and is a valid and
typical socket pair.
Data flow 2 has the same IP addresses and the same port number on the second IP address
as data flow 1, but since the port number on the first socket differs, the data flow is unique.
Therefore, if one IP address octet changes, or one port number changes, the data flow is
unique.
Socket example showing ingress and egress data flows from a PC to a web
server
Notice the client egress stream includes the client’s source IP and socket (1369) and the
destination IP and socket (80). The ingress stream has the source and destination information
reversed because the ingress is coming from the server.
Firewall types
There are three basic firewall types described below.
Packet filtering
Packet Filtering is the most basic form of the firewalls. Each packet that arrives or leaves the
network has its header fields examined against criterion to either drop the packet or let it
through. Routers configured with Access Control Lists (ACL) use packet filtering. An example
of packet filtering is preventing any source device on the Engineering subnet to telnet into any
device in the Accounting subnet.
Application level gateways
Application level gateways (ALG) act as a proxy, preventing a direct connection between the
foreign device and the internal destination device. ALGs filter each individual packet rather
than blindly copying bytes. ALGs can also send alerts via email, alarms or other methods and
keep log files to track significant events.
Hybrid
Hybrid firewalls are dynamic systems, tracking each connection traversing all interfaces of the
firewall and making sure they are valid. In addition to looking at headers, the content of the
Firewall types
Implementing the Avaya B5800 Branch Gateway November 2011 299
Page view 298
1 2 ... 294 295 296 297 298 299 300 301 302 303 304 ... 341 342

Comments to this Manuals

No comments