Zusammenfassung der Ressource
u9.3 Firewall Types P3.
Application Level Proxies
- Most complex of the 4 types
- Does more processing and has more features
to support operations on typical networks
- provides the most detailed level of control of traffic
- checks for correct association of services with port numbers
- Do not route packets between
source and destination
- Always repackage the contents of incoming packets into
new packets that are generated and sent out from the proxy
- The distinction of an application-level proxy firewall is that it actually
contains a complete OSI layer 7 client and server implementation for
every protocol it can support through the firewall.
- Normally a machine would be just a client or a server
– an application-level proxy firewall has to be both.
- This means the security can
be very fine grained, more
than for any other type of FW
- For example a stateful
packet might allow HTTP
& Block FTP
- an ALP can allow GTTP Get
but block HTTP Post
- Or allow FTP Get but block
exe from being downloaded
- Provides a greater level of control at a price
- more processing = lowe performance
- it must contain this functionality for every
protocol it may need to send between clients
& servers on opposite sides of the FW
- the possibilities here mean that ALP
end up being extremely complex