【文章內(nèi)容簡(jiǎn)介】
? Disadvantages: 1. Difficulty of setting up packet filter walls. 2. Lack of Authentication. ApplicationLevelGateway ? Application Level Gateway Firewall. TELNET FTP SMTP HTTP Outside Connection Inside Connection Outside Host Inside Host Figure (Application Level Gateway). ApplicationLevelGateway ? Also called (Proxy Server). ? Acts as relay of application level traffic. ApplicationLevelGateway ? Advantages: 1. Higher security than packet filter 2. Only need securitize a few allowable applications. 3. Easy to log and audit all ining traffic. ? Disadvantages: Additional processing overhead on each connection (Gateway as splice point). Circuit Level Gateway ? Circuit Level Gateway. OUT OUT OUT OUT IN IN IN IN Outside host amp。 outside connection Inside host amp。 inside connection Circuit Level Gateway ? Standalone system or specialized function performed by Application level gateway. ? Sets up two TCP connections. ? The gateway typically relays TCP segments from one connection to the other without examining the contents. Circuit Level Gateway ? The security function consists of which connections to be allowed. ? Typica