官术网_书友最值得收藏!

Controlling port-based traffic

The primary approach to implementing security is to control ports on which the traffic is being received. There are two types of firewalls that allow port-based traffic control:

  • Stateless firewalls: All rules are uni directional and no state is maintained. The stateless firewall requires us to specify the incoming ports and the outgoing ports the application will communicate on. This was simple in the early days of the internet with services such as DNS using port 53 and active FTP using port 21. But modern applications mostly use ephemeral ports for the return response, so stateless firewalls are hard to control.
  • Stateful firewalls: All rules are bi directional. The stateful firewall will maintain a state of the incoming versus return traffic, and will automatically allow a return on any port that matches a request being allowed in the session information. So, essentially, if we allow port 443 for SSL, the firewall will automatically allow a response on any ephemeral port the operating system supports.
主站蜘蛛池模板: 沅陵县| 通辽市| 东乡| 米泉市| 泰和县| 霍州市| 湖南省| 翁牛特旗| 新邵县| 萨嘎县| 馆陶县| 南通市| 祁东县| 防城港市| 南华县| 博白县| 永川市| 灵璧县| 邵武市| 常宁市| 高碑店市| 淅川县| 井冈山市| 阿坝县| 建阳市| 岑巩县| 确山县| 墨脱县| 六安市| 安乡县| 镶黄旗| 新蔡县| 青州市| 洛浦县| 临邑县| 天津市| 武穴市| 竹山县| 珲春市| 沧源| 彭泽县|