官术网_书友最值得收藏!

Controlling port-based traffic

The primary approach to implementing security is to control ports on which the traffic is being received. There are two types of firewalls that allow port-based traffic control:

  • Stateless firewalls: All rules are uni directional and no state is maintained. The stateless firewall requires us to specify the incoming ports and the outgoing ports the application will communicate on. This was simple in the early days of the internet with services such as DNS using port 53 and active FTP using port 21. But modern applications mostly use ephemeral ports for the return response, so stateless firewalls are hard to control.
  • Stateful firewalls: All rules are bi directional. The stateful firewall will maintain a state of the incoming versus return traffic, and will automatically allow a return on any port that matches a request being allowed in the session information. So, essentially, if we allow port 443 for SSL, the firewall will automatically allow a response on any ephemeral port the operating system supports.
主站蜘蛛池模板: 曲阳县| 保靖县| 醴陵市| 白城市| 济阳县| 丹阳市| 涟水县| 铁岭市| 南城县| 遵义县| 出国| 三穗县| 文昌市| 平度市| 囊谦县| 建水县| 东平县| 彭水| 濉溪县| 屯门区| 沐川县| 昆明市| 定安县| 巴楚县| 伊宁县| 汝阳县| 新宾| 嘉定区| 灵山县| 石阡县| 桐柏县| 宜阳县| 屯门区| 涿州市| 张家口市| 宁武县| 甘德县| 安庆市| 灵武市| 广宗县| 西青区|