Newsletters Welcome, Guest Log In | Register


Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Currently Being Moderated

Definitions: Firewall

0

Created on: Jan 25, 2009 7:02 PM by CrystalBedell - Last Modified:  Jan 25, 2009 7:05 PM by CrystalBedell

Definition

A firewall is a system consisting of hardware, software or  both designed to prevent unauthorized traffic from entering a private network.  The firewall examines  all packets to determine whether they should be allowed through based on  pre-defined policies.

 

Business applications

Network firewalls have long been considered a necessary  component of a network security strategy. They are most commonly implemented at  the network gateway to prevent unauthorized traffic from the public Internet  from entering the private intranet. However, they can also be implemented  between network segments to enforce varying levels of trust. You might, for  example, choose to filter traffic coming into the sales department’s portion of  the network to ensure that users from other departments are not accessing  sales-related resources.

 

Deployment Concerns

As the network’s first line of defense, a network firewall  is inarguably important. But an organization’s security efforts should not stop  there. There are many threats that a firewall cannot stop, including distributed denial-of-service  attacks, spam and data leakage. Even though firewall manufacturers are  continually updating their technology to keep up with the barrage of threats, experts strongly  recommend implementing a layered  defense that includes antivirus, intrusion detection and content filtering.

 

Also, a network firewall is only as good as the policies it  enforces. Best practices advise implementing “default-deny” rules in which the  firewall denies all network connections by default unless a connection is  specifically allowed. However, given the number of endpoints and applications  accessing the network on a daily basis, it is much more practical – and  therefore more common – for organizations to implement “default-allow” rules.  In this case, all network connections are allowed unless explicitly denied or  blocked.

 

Technical details

Firewalls can filter traffic a number of ways and may incorporate multiple  methods.  In addition to packet filtering  in which the firewall inspects individual packets attempting to enter the  network, a firewall might serve as a proxy, executing requests on behalf of  internal users. This frees users from connecting directly to the Internet.  Bastion hosts, on the other hand, intercept all network connections coming from  the Internet. Some firewalls also use network address translation, which helps  organizations conserve the number of IP addresses they need while protecting  sensitive hosts by changing public-facing IP addresses.

Average User Rating
(0 ratings)




Add a comment Leave some feedback about this document.

There are no comments on this document

Six Sigma Framework for IT

This collection of tutorials, calculators, and templates will show you how to apply Six Sigma thinking to IT service management.

Learn more >

ITIL V3 Foundation - Complete Certification Kit

Enhance your IT career by getting your ITIL Foundation Certificate. It's fast and easy with this complete resource. The 186-page eBook and companion online training course is guaranteed to help you pass the ITIL exam.

Learn more >

Service Oriented Architecture (SOA)

Service-Oriented Architecture is the catalyst that allows today’s companies to respond to business demands faster and more effectively than ever.

Business Intelligence

Best-practice tools, strategies and technologies for determining and managing the data you need to make better business decisions.

Applications for Mid-size Businesses

Applications that mid-sized businesses can use to improve operational efficiency, accelerate growth, and maintain profitability.

Decision Management

Applications, management tools and industry advice on how to optimize your data for better business decisions.

Three Things You May Not Know about HP SiteScope

Access this webinar to learn three interesting ways to use HP SiteScope that can lower your IT cost for managing IT environments and is flexible to meet the needs of your changing IT environment.

Preventing Data Corruption in the Event of an Extended Power Outage

This white paper discusses various power management software configurations, and presents best practices aimed at ensuring system uptime.