官术网_书友最值得收藏!

Controlling port-based traffic

The primary approach to implementing security is to control ports on which the traffic is being received. There are two types of firewalls that allow port-based traffic control:

  • Stateless firewalls: All rules are uni directional and no state is maintained. The stateless firewall requires us to specify the incoming ports and the outgoing ports the application will communicate on. This was simple in the early days of the internet with services such as DNS using port 53 and active FTP using port 21. But modern applications mostly use ephemeral ports for the return response, so stateless firewalls are hard to control.
  • Stateful firewalls: All rules are bi directional. The stateful firewall will maintain a state of the incoming versus return traffic, and will automatically allow a return on any port that matches a request being allowed in the session information. So, essentially, if we allow port 443 for SSL, the firewall will automatically allow a response on any ephemeral port the operating system supports.
主站蜘蛛池模板: 栾城县| 山东省| 云梦县| 柘荣县| 沐川县| 柳林县| 高青县| 三都| 昌黎县| 大田县| 河源市| 东兴市| 夏邑县| 安庆市| 黄浦区| 荃湾区| 苍梧县| 富源县| 德安县| 通化市| 江孜县| 南漳县| 临洮县| 九江县| 金阳县| 阿坝| 勐海县| 宜川县| 革吉县| 错那县| 普安县| 合作市| 岐山县| 竹溪县| 平和县| 繁峙县| 永顺县| 博湖县| 根河市| 江阴市| 鄢陵县|