官术网_书友最值得收藏!

Controlling port-based traffic

The primary approach to implementing security is to control ports on which the traffic is being received. There are two types of firewalls that allow port-based traffic control:

  • Stateless firewalls: All rules are uni directional and no state is maintained. The stateless firewall requires us to specify the incoming ports and the outgoing ports the application will communicate on. This was simple in the early days of the internet with services such as DNS using port 53 and active FTP using port 21. But modern applications mostly use ephemeral ports for the return response, so stateless firewalls are hard to control.
  • Stateful firewalls: All rules are bi directional. The stateful firewall will maintain a state of the incoming versus return traffic, and will automatically allow a return on any port that matches a request being allowed in the session information. So, essentially, if we allow port 443 for SSL, the firewall will automatically allow a response on any ephemeral port the operating system supports.
主站蜘蛛池模板: 清苑县| 德阳市| 彰化市| 延寿县| 闸北区| 易门县| 鹰潭市| 科技| 普定县| 甘南县| 陆河县| 张北县| 德安县| 旺苍县| 日土县| 四平市| 大渡口区| 沧源| 沛县| 木兰县| 翁牛特旗| 赣榆县| 阳东县| 广元市| 平阴县| 密山市| 石柱| 南雄市| 衡东县| 汉川市| 莱阳市| 山西省| 丁青县| 民县| 牙克石市| 米易县| 报价| 澄城县| 东乡县| 莫力| 长泰县|