Friday, October 24, 2008

Why should use a firewall? part 2

To prevent internal leakage of information:

By using a firewall on the internal network division, can focus on the internal network segment isolation, limiting the focus of local or network security issues sensitive to the impact of the global network. In addition, privacy is very concerned about the internal network, an internal network, not the details of the profile may contain a clue about security caused by external attacker interest, even while the storm omitted some of the internal network security holes . Use a firewall can be hidden within those disclose details such as Finger, DNS, and other services. Finger show hosts of all the registered user name, real name, the last time to log on and use the type of shell, and so on. Finger but very easy to show that the information was informed by the attacker. An attacker could use the system to know the frequency of the system if there is to connect Internet users, whether or not the system in the attack to draw attention, and so on. Similarly, the firewall can block related to the internal network of DNS information, so a host of domain names and IP addresses will not be understood by the outside world.
In addition to security, the firewall also has the support of Internet service characteristics of the enterprise network technology system VPN (virtual private network).
English firewall called "FireWall", it is one of the most important network of protective equipment. From a professional perspective, the firewall is located in two (or more) network, network access control between the set pieces Yi Zuzu.
In the network firewall is often shown in the chart below are two icons appear. The very image of the icon on the left, like a wall, like real. And the icon on the right side from the firewall to filter mechanism to visualize, there are icons in the icon of a diode. Diodes and we know that it is conducting a one-way, this is vividly illustrated with a single firewall wizard transparency. It now appears that some mechanism for filtering firewall conflicts, but it fully reflects the firewall in the early design idea, as well as a large extent reflects the current firewall filtering mechanisms. Fire because the initial design idea is always the internal network of trust, and the external network is not always trusted, so the firewall is only the first external filter incoming communications, and internal communications issued by the users not to limit . Of course, the current firewall filtering mechanism in the changes, not only for external communications issued by the network to connect to filter internal users to connect to issue some of the requests and needs of the same packet filtering firewall, but still only in line with the security strategy Communication through, it can be said to have "unilateral connecting" sexual.
Firewall refers to the original meaning of the ancient wooden structure of the building and use of housing, in order to prevent the occurrence and spread of fire, it will be solid and a pile of stones in the surrounding housing as a barrier, the protective structures to be known as the "firewall." In fact, the firewall and work together with the "door." If there are no doors, the people room how communication, the Room of these people, how can it get? When the fire broke out, those who fled the scene, how do? This is equivalent to the door on us by talking about the firewall "security strategy", so here we are talking about a firewall is not the actual wall solid walls, but with some small holes in the wall. These small hole is left to those used to allow communication in these small holes in the installation of a filtering mechanism, which is described above, "one of the universal guide."

No comments: