Does more processing and has more features
to support operations on typical networks
provides the most detailed level of control of traffic
checks for correct association of services with port numbers
Do not route packets between
source and destination
Always repackage the contents of incoming packets into
new packets that are generated and sent out from the proxy
The distinction of an application-level proxy firewall is that it actually
contains a complete OSI layer 7 client and server implementation for
every protocol it can support through the firewall.
Normally a machine would be just a client or a server
– an application-level proxy firewall has to be both.
This means the security can
be very fine grained, more
than for any other type of FW
For example a stateful
packet might allow HTTP
& Block FTP
an ALP can allow GTTP Get
but block HTTP Post
Or allow FTP Get but block
exe from being downloaded
Provides a greater level of control at a price
more processing = lowe performance
it must contain this functionality for every
protocol it may need to send between clients
& servers on opposite sides of the FW
the possibilities here mean that ALP
end up being extremely complex