SlideShare a Scribd company logo
Firewall
Definition
A firewall is a hardware or software designed to permit or deny
network transmissions based upon a set of rules and is frequently used to
protect networks from unauthorized access while permitting legitimate
communications to pass.
Firewalls Can Perform Basic Routing Functions
Hardware & Software
Firewall
Figure 1: Hardware Firewall.
Hardware firewall providing protection
to a Local Area Network.
 
Figure 1: Hardware Firewall.
Hardware firewall providing protection
to a Local Area Network.
 
Figure 2: Computer with Firewall Software.
Computer running firewall software that
provide protection to PC..etc.,
 
Figure 2: Computer with Firewall Software.
Computer running firewall software that
provide protection to PC..etc.,
 
History
The Morris Worm spread itself through multiple
vulnerabilities in the machines of the time.
The Morris Worm was the first large scale attack on
Internet security; the online community was neither
expecting an attack nor prepared to deal with one.
First generation: Packet Filters
Second generation: Application Level Gateway
Third generation: "Stateful" Filters
First Generation : Packet Filters
( Relativesimplicity and easeof implementation. )
A packet is a series ofA packet is a series of
digital numbersdigital numbers
basically,basically,
a.a.The data,The data,
acknowledgment,acknowledgment,
request or commandrequest or command
from the originatingfrom the originating
systemsystem
b.b.The source IPThe source IP
address and portaddress and port
c.c.The destination IPThe destination IP
address and portaddress and port
d.d.Information aboutInformation about
the protocol (set ofthe protocol (set of
rules) by which therules) by which the
packet is to be handledpacket is to be handled
In packet filtering, only the protocol and the address
information of each packet is examined.
Its contents and context (its relation to other packets and
to the intended application) are ignored.
Filtering consists of examining incoming or outgoing packets
and allowing or disallowing their transmission or
acceptance on the basis of a set of configurable rules,
called policies.
Packet filtering policies may be based upon any of the
following:
Allowing or disallowing packets on the basis of the source IP
address
Allowing or disallowing packets on the basis of their
destination port
Allowing or disallowing packets according to protocol.
II Generation : Application level
Gateway ( Much moresecureand reliablecompared to packet
filter firewalls)
The key benefit of application layer
filtering is that it can "understand"
certain applications and protocols (such as
File Transfer Protocol, DNS, or web
browsing)
Works on all seven layers of the OSI
model, from the application down to the
physical Layer.
Good examples of application firewalls
are MS-ISA (Internet Security and
Acceleration) server, McAfee Firewall
Enterprise & Palo Alto PS Series firewalls.
An application firewall can filter higher-
layer protocols such as FTP, Telnet, DNS,
DHCP, HTTP, TCP, UDP and TFTP
For example, if an organization wants to block
all the information related to "fool" then
content filtering can be enabled on the firewall
to block that particular word.
Third Generation : Stateful Filters
From 1989-1990 three colleagues from AT&T Bell Laboratories, Dave Presetto,
Janardan Sharma, and Kshitij Nigam, developed the third generation of firewalls,
calling them Circuit Level Firewalls
This technology is generally referred to as a stateful packet inspection as it
maintains records of all connections passing through the firewall and is able to
determine whether
a packet is the start of a new connection,
a part of an existing connection, or
is an invalid packet.
This type of firewall can actually be exploited by certain Denial-of-service attacks
which can fill the connection tables with illegitimate connections.
Subsequent Developments
Methods to Attack or View Computer
Data:
Basic Types Of Firewalls:
Conceptually, there are two types of firewalls:
Network layer Application layer
Network layer Firewall :
Generally make their decisions based on the source, destination addresses and ports
in individual IP packets.
A simple router is the ``traditional'' network layer firewall
Many network layer firewalls is that they route traffic directly though them, so to
use one you either need to have a validly assigned IP address block or to use a
“private internet” address block .
Network layer firewalls tend to be very fast and tend to be very transparent to
users.
In a screened host firewall, access to and from a
single host is controlled by means of a router
operating at a network layer. The single host is a
bastion host; a highly-defended and secured strong-
point that (hopefully) can resist attack.
In a screened subnet firewall, access to and
from a whole network is controlled by means
of a router operating at a network layer. It is
similar to a screened host, except that it is,
effectively, a network of screened hosts.
Application Layer Firewall :
This can be used as network address
translators, since traffic goes in one ``side''
and out the other, after having passed
through an application that effectively masks
the origin of the initiating connection.
Not particularly transparent to end users and
may require some training.
Modern application layer firewalls are often
fully transparent.
Application layer firewalls tend to provide
more detailed audit reports and tend to
enforce more conservative security models
than network layer firewalls.
Example Application layer firewall: an
application layer firewall called a ``dual
homed gateway'' is represented. A dual
homed gateway is a highly secured host
that runs proxy software. It has two
network interfaces, one on each
network, and blocks all traffic passing
through it.
DMZ : Demilitarized Zone
It is a physical or logical subnetwork that contains and exposes an
organization's external services to a larger untrusted network, usually
the Internet.
It is sometimes referred to as a perimeter network
Hosts in the DMZ have limited connectivity to specific hosts in the
internal network, firewall controls the traffic between the DMZ
servers and the internal network clients.
A DMZ configuration typically provides security from external
attacks, but it typically has no bearing on internal attacks such as
sniffing communication via a packet analyzer or spoofing such as e-
mail spoofing.
Single Firewall & Dual
Firewall
I- ISP to Firewall
II- Internal Network
III- DMZ
The firewall becomes a single point of failure for
the network and must be able to handle all of the
traffic going to the DMZ as well as the internal
network.
3 interfaces
A more secure approach is to use two firewalls to create
a DMZ
The first firewall -"front-end" firewall
The second firewall - "back-end" firewall
This architecture is, of course, more costly. The
practice of using different firewalls from different
vendors is sometimes described as a component of a
"defence in depth" security strategy.
Top 10 Firewalls
Benefits of Firewall
Firewalls protect private local
area networks from hostile intrusion
from the Internet.
Firewalls allow network
administrators to offer access to
specific types of Internet services to
selected LAN users.
This selectivity is an essential part
of any information management
program, and involves not only
protecting private information
assets, but also knowing who has
access to what.
Privileges can be granted
according to job description and
need rather than on an all-or-nothing
basis.
Conclusion
A solid firewall will help you stop intruders from accessing your
system. we keep our internet link to the outside world but the outside
world can't view us unless we want them to.
With a firewall in place we will still have typical email access,
but chat and other interactive programs will require you to take an extra
step to grant access before we can use them. A firewall is powerful but
unobtrusive, just like a deadbolt lock inside a door.
Firewall
Firewall

More Related Content

What's hot

firewall and its types
firewall and its typesfirewall and its types
firewall and its types
Mohammed Maajidh
 
Firewall
FirewallFirewall
Firewall presentation
Firewall presentationFirewall presentation
Firewall presentation
gaurav96raj
 
firewall.ppt
firewall.pptfirewall.ppt
firewall.ppt
ssuser530a07
 
[9] Firewall.pdf
[9] Firewall.pdf[9] Firewall.pdf
[9] Firewall.pdf
lamtran367679
 
Next generation firewall(ngfw)feature and benefits
Next generation firewall(ngfw)feature and benefitsNext generation firewall(ngfw)feature and benefits
Next generation firewall(ngfw)feature and benefits
Anthony Daniel
 
Firewall ppt
Firewall pptFirewall ppt
Virtual Private Networks (VPN) ppt
Virtual Private Networks (VPN) pptVirtual Private Networks (VPN) ppt
Virtual Private Networks (VPN) ppt
OECLIB Odisha Electronics Control Library
 
Firewall
FirewallFirewall
Firewall
nayakslideshare
 
Firewall basics
Firewall basicsFirewall basics
Firewall basics
Fredrick Hall
 
Firewall protection
Firewall protectionFirewall protection
Firewall protection
VC Infotech
 
Firewall in Network Security
Firewall in Network SecurityFirewall in Network Security
Firewall in Network Security
lalithambiga kamaraj
 
Types of firewall
Types of firewallTypes of firewall
Types of firewall
Pina Parmar
 
Introduction of firewall slides
Introduction of firewall slidesIntroduction of firewall slides
Introduction of firewall slides
rahul kundu
 
Hardware firewall
Hardware firewallHardware firewall
Hardware firewall
Subrata Kumer Paul
 
Firewall
FirewallFirewall
Firewall
Mudasser Afzal
 
Firewall and its purpose
Firewall and its purposeFirewall and its purpose
Firewall and its purpose
Rohit Phulsunge
 
Wireless network security
Wireless network securityWireless network security
Wireless network security
Vishal Agarwal
 
Network Security
Network SecurityNetwork Security
Network Security
Manoj Singh
 
Firewalls in network security
Firewalls in network securityFirewalls in network security
Firewalls in network security
Vikram Khanna
 

What's hot (20)

firewall and its types
firewall and its typesfirewall and its types
firewall and its types
 
Firewall
FirewallFirewall
Firewall
 
Firewall presentation
Firewall presentationFirewall presentation
Firewall presentation
 
firewall.ppt
firewall.pptfirewall.ppt
firewall.ppt
 
[9] Firewall.pdf
[9] Firewall.pdf[9] Firewall.pdf
[9] Firewall.pdf
 
Next generation firewall(ngfw)feature and benefits
Next generation firewall(ngfw)feature and benefitsNext generation firewall(ngfw)feature and benefits
Next generation firewall(ngfw)feature and benefits
 
Firewall ppt
Firewall pptFirewall ppt
Firewall ppt
 
Virtual Private Networks (VPN) ppt
Virtual Private Networks (VPN) pptVirtual Private Networks (VPN) ppt
Virtual Private Networks (VPN) ppt
 
Firewall
FirewallFirewall
Firewall
 
Firewall basics
Firewall basicsFirewall basics
Firewall basics
 
Firewall protection
Firewall protectionFirewall protection
Firewall protection
 
Firewall in Network Security
Firewall in Network SecurityFirewall in Network Security
Firewall in Network Security
 
Types of firewall
Types of firewallTypes of firewall
Types of firewall
 
Introduction of firewall slides
Introduction of firewall slidesIntroduction of firewall slides
Introduction of firewall slides
 
Hardware firewall
Hardware firewallHardware firewall
Hardware firewall
 
Firewall
FirewallFirewall
Firewall
 
Firewall and its purpose
Firewall and its purposeFirewall and its purpose
Firewall and its purpose
 
Wireless network security
Wireless network securityWireless network security
Wireless network security
 
Network Security
Network SecurityNetwork Security
Network Security
 
Firewalls in network security
Firewalls in network securityFirewalls in network security
Firewalls in network security
 

Viewers also liked

Mime presentation
Mime presentationMime presentation
Mime presentation
abigail270595
 
Mime
MimeMime
Mime
pullel
 
Email Security Overview
Email Security OverviewEmail Security Overview
Email Security Overview
- Mark - Fullbright
 
Intruders
IntrudersIntruders
Intruders
techn
 
Pgp pretty good privacy
Pgp pretty good privacyPgp pretty good privacy
Pgp pretty good privacy
Pawan Arya
 
S/MIME & E-mail Security (Network Security)
S/MIME & E-mail Security (Network Security)S/MIME & E-mail Security (Network Security)
S/MIME & E-mail Security (Network Security)
Prafull Johri
 
Secure Socket Layer
Secure Socket LayerSecure Socket Layer
Secure Socket Layer
Naveen Kumar
 
Firewall
FirewallFirewall

Viewers also liked (8)

Mime presentation
Mime presentationMime presentation
Mime presentation
 
Mime
MimeMime
Mime
 
Email Security Overview
Email Security OverviewEmail Security Overview
Email Security Overview
 
Intruders
IntrudersIntruders
Intruders
 
Pgp pretty good privacy
Pgp pretty good privacyPgp pretty good privacy
Pgp pretty good privacy
 
S/MIME & E-mail Security (Network Security)
S/MIME & E-mail Security (Network Security)S/MIME & E-mail Security (Network Security)
S/MIME & E-mail Security (Network Security)
 
Secure Socket Layer
Secure Socket LayerSecure Socket Layer
Secure Socket Layer
 
Firewall
FirewallFirewall
Firewall
 

Similar to Firewall

Firewall.pdf
Firewall.pdfFirewall.pdf
Firewall.pdf
ImXaib
 
Firewall
FirewallFirewall
Firewall
Naga Dinesh
 
Firewalls
FirewallsFirewalls
Firewall
FirewallFirewall
Firewall
Netwax Lab
 
Firewall ppt
Firewall pptFirewall ppt
Firewall ppt
Revanth71
 
Note8
Note8Note8
internet-firewalls
internet-firewallsinternet-firewalls
internet-firewalls
Miftakhul Hijriyah
 
FIREWALLS BY SAIKIRAN PANJALA
FIREWALLS BY SAIKIRAN PANJALAFIREWALLS BY SAIKIRAN PANJALA
FIREWALLS BY SAIKIRAN PANJALA
Saikiran Panjala
 
Firewall
FirewallFirewall
Firewall
FirewallFirewall
Firewall
FirewallFirewall
Firewall
Ahmed Elnaggar
 
Firewall ,Its types and Working.pptx
Firewall ,Its types and Working.pptxFirewall ,Its types and Working.pptx
Firewall ,Its types and Working.pptx
ShrayamManandhar
 
Firewalls
FirewallsFirewalls
Firewalls
FirewallsFirewalls
Firewalls
Sonali Parab
 
Firewall
FirewallFirewall
Firewall
ArchanaMani2
 
firrewall and intrusion prevention system.pptx
firrewall and intrusion prevention system.pptxfirrewall and intrusion prevention system.pptx
firrewall and intrusion prevention system.pptx
fatimagull32
 
Firewall ppt
Firewall pptFirewall ppt
Firewall ppt
LakshmiSamivel
 
Firewalls
FirewallsFirewalls
Firewall
FirewallFirewall
Firewall
Shamima Akther
 
what is firewall in information security?
what is firewall in information security?what is firewall in information security?
what is firewall in information security?
haq107457
 

Similar to Firewall (20)

Firewall.pdf
Firewall.pdfFirewall.pdf
Firewall.pdf
 
Firewall
FirewallFirewall
Firewall
 
Firewalls
FirewallsFirewalls
Firewalls
 
Firewall
FirewallFirewall
Firewall
 
Firewall ppt
Firewall pptFirewall ppt
Firewall ppt
 
Note8
Note8Note8
Note8
 
internet-firewalls
internet-firewallsinternet-firewalls
internet-firewalls
 
FIREWALLS BY SAIKIRAN PANJALA
FIREWALLS BY SAIKIRAN PANJALAFIREWALLS BY SAIKIRAN PANJALA
FIREWALLS BY SAIKIRAN PANJALA
 
Firewall
FirewallFirewall
Firewall
 
Firewall
FirewallFirewall
Firewall
 
Firewall
FirewallFirewall
Firewall
 
Firewall ,Its types and Working.pptx
Firewall ,Its types and Working.pptxFirewall ,Its types and Working.pptx
Firewall ,Its types and Working.pptx
 
Firewalls
FirewallsFirewalls
Firewalls
 
Firewalls
FirewallsFirewalls
Firewalls
 
Firewall
FirewallFirewall
Firewall
 
firrewall and intrusion prevention system.pptx
firrewall and intrusion prevention system.pptxfirrewall and intrusion prevention system.pptx
firrewall and intrusion prevention system.pptx
 
Firewall ppt
Firewall pptFirewall ppt
Firewall ppt
 
Firewalls
FirewallsFirewalls
Firewalls
 
Firewall
FirewallFirewall
Firewall
 
what is firewall in information security?
what is firewall in information security?what is firewall in information security?
what is firewall in information security?
 

Recently uploaded

BRIGADA ESKWELA OPENING PROGRAM KICK OFF.pptx
BRIGADA ESKWELA OPENING PROGRAM KICK OFF.pptxBRIGADA ESKWELA OPENING PROGRAM KICK OFF.pptx
BRIGADA ESKWELA OPENING PROGRAM KICK OFF.pptx
kambal1234567890
 
Principles of Roods Approach!!!!!!!.pptx
Principles of Roods Approach!!!!!!!.pptxPrinciples of Roods Approach!!!!!!!.pptx
Principles of Roods Approach!!!!!!!.pptx
ibtesaam huma
 
Bedok NEWater Photostory - COM322 Assessment (Story 2)
Bedok NEWater Photostory - COM322 Assessment (Story 2)Bedok NEWater Photostory - COM322 Assessment (Story 2)
Bedok NEWater Photostory - COM322 Assessment (Story 2)
Liyana Rozaini
 
The membership Module in the Odoo 17 ERP
The membership Module in the Odoo 17 ERPThe membership Module in the Odoo 17 ERP
The membership Module in the Odoo 17 ERP
Celine George
 
How to Show Sample Data in Tree and Kanban View in Odoo 17
How to Show Sample Data in Tree and Kanban View in Odoo 17How to Show Sample Data in Tree and Kanban View in Odoo 17
How to Show Sample Data in Tree and Kanban View in Odoo 17
Celine George
 
L1 L2- NLC PPT for Grade 10 intervention
L1 L2- NLC PPT for Grade 10 interventionL1 L2- NLC PPT for Grade 10 intervention
L1 L2- NLC PPT for Grade 10 intervention
RHODAJANEAURESTILA
 
(T.L.E.) Agriculture: Essentials of Gardening
(T.L.E.) Agriculture: Essentials of Gardening(T.L.E.) Agriculture: Essentials of Gardening
(T.L.E.) Agriculture: Essentials of Gardening
MJDuyan
 
DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY N...
DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY N...DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY N...
DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY N...
thanhluan21
 
AI Risk Management: ISO/IEC 42001, the EU AI Act, and ISO/IEC 23894
AI Risk Management: ISO/IEC 42001, the EU AI Act, and ISO/IEC 23894AI Risk Management: ISO/IEC 42001, the EU AI Act, and ISO/IEC 23894
AI Risk Management: ISO/IEC 42001, the EU AI Act, and ISO/IEC 23894
PECB
 
SYBCOM SEM III UNIT 1 INTRODUCTION TO ADVERTISING
SYBCOM SEM III UNIT 1 INTRODUCTION TO ADVERTISINGSYBCOM SEM III UNIT 1 INTRODUCTION TO ADVERTISING
SYBCOM SEM III UNIT 1 INTRODUCTION TO ADVERTISING
Dr Vijay Vishwakarma
 
How to Install Theme in the Odoo 17 ERP
How to  Install Theme in the Odoo 17 ERPHow to  Install Theme in the Odoo 17 ERP
How to Install Theme in the Odoo 17 ERP
Celine George
 
Understanding and Interpreting Teachers’ TPACK for Teaching Multimodalities i...
Understanding and Interpreting Teachers’ TPACK for Teaching Multimodalities i...Understanding and Interpreting Teachers’ TPACK for Teaching Multimodalities i...
Understanding and Interpreting Teachers’ TPACK for Teaching Multimodalities i...
Neny Isharyanti
 
No, it's not a robot: prompt writing for investigative journalism
No, it's not a robot: prompt writing for investigative journalismNo, it's not a robot: prompt writing for investigative journalism
No, it's not a robot: prompt writing for investigative journalism
Paul Bradshaw
 
Credit limit improvement system in odoo 17
Credit limit improvement system in odoo 17Credit limit improvement system in odoo 17
Credit limit improvement system in odoo 17
Celine George
 
"DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY ...
"DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY ..."DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY ...
"DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY ...
thanhluan21
 
AI_in_HR_Presentation Part 1 2024 0703.pdf
AI_in_HR_Presentation Part 1 2024 0703.pdfAI_in_HR_Presentation Part 1 2024 0703.pdf
AI_in_HR_Presentation Part 1 2024 0703.pdf
SrimanigandanMadurai
 
The Jewish Trinity : Sabbath,Shekinah and Sanctuary 4.pdf
The Jewish Trinity : Sabbath,Shekinah and Sanctuary 4.pdfThe Jewish Trinity : Sabbath,Shekinah and Sanctuary 4.pdf
The Jewish Trinity : Sabbath,Shekinah and Sanctuary 4.pdf
JackieSparrow3
 
Is Email Marketing Really Effective In 2024?
Is Email Marketing Really Effective In 2024?Is Email Marketing Really Effective In 2024?
Is Email Marketing Really Effective In 2024?
Rakesh Jalan
 
Final_SD_Session3_Ferriols, Ador Dionisio, Fajardo.pptx
Final_SD_Session3_Ferriols, Ador Dionisio, Fajardo.pptxFinal_SD_Session3_Ferriols, Ador Dionisio, Fajardo.pptx
Final_SD_Session3_Ferriols, Ador Dionisio, Fajardo.pptx
shimeathdelrosario1
 
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
siemaillard
 

Recently uploaded (20)

BRIGADA ESKWELA OPENING PROGRAM KICK OFF.pptx
BRIGADA ESKWELA OPENING PROGRAM KICK OFF.pptxBRIGADA ESKWELA OPENING PROGRAM KICK OFF.pptx
BRIGADA ESKWELA OPENING PROGRAM KICK OFF.pptx
 
Principles of Roods Approach!!!!!!!.pptx
Principles of Roods Approach!!!!!!!.pptxPrinciples of Roods Approach!!!!!!!.pptx
Principles of Roods Approach!!!!!!!.pptx
 
Bedok NEWater Photostory - COM322 Assessment (Story 2)
Bedok NEWater Photostory - COM322 Assessment (Story 2)Bedok NEWater Photostory - COM322 Assessment (Story 2)
Bedok NEWater Photostory - COM322 Assessment (Story 2)
 
The membership Module in the Odoo 17 ERP
The membership Module in the Odoo 17 ERPThe membership Module in the Odoo 17 ERP
The membership Module in the Odoo 17 ERP
 
How to Show Sample Data in Tree and Kanban View in Odoo 17
How to Show Sample Data in Tree and Kanban View in Odoo 17How to Show Sample Data in Tree and Kanban View in Odoo 17
How to Show Sample Data in Tree and Kanban View in Odoo 17
 
L1 L2- NLC PPT for Grade 10 intervention
L1 L2- NLC PPT for Grade 10 interventionL1 L2- NLC PPT for Grade 10 intervention
L1 L2- NLC PPT for Grade 10 intervention
 
(T.L.E.) Agriculture: Essentials of Gardening
(T.L.E.) Agriculture: Essentials of Gardening(T.L.E.) Agriculture: Essentials of Gardening
(T.L.E.) Agriculture: Essentials of Gardening
 
DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY N...
DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY N...DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY N...
DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY N...
 
AI Risk Management: ISO/IEC 42001, the EU AI Act, and ISO/IEC 23894
AI Risk Management: ISO/IEC 42001, the EU AI Act, and ISO/IEC 23894AI Risk Management: ISO/IEC 42001, the EU AI Act, and ISO/IEC 23894
AI Risk Management: ISO/IEC 42001, the EU AI Act, and ISO/IEC 23894
 
SYBCOM SEM III UNIT 1 INTRODUCTION TO ADVERTISING
SYBCOM SEM III UNIT 1 INTRODUCTION TO ADVERTISINGSYBCOM SEM III UNIT 1 INTRODUCTION TO ADVERTISING
SYBCOM SEM III UNIT 1 INTRODUCTION TO ADVERTISING
 
How to Install Theme in the Odoo 17 ERP
How to  Install Theme in the Odoo 17 ERPHow to  Install Theme in the Odoo 17 ERP
How to Install Theme in the Odoo 17 ERP
 
Understanding and Interpreting Teachers’ TPACK for Teaching Multimodalities i...
Understanding and Interpreting Teachers’ TPACK for Teaching Multimodalities i...Understanding and Interpreting Teachers’ TPACK for Teaching Multimodalities i...
Understanding and Interpreting Teachers’ TPACK for Teaching Multimodalities i...
 
No, it's not a robot: prompt writing for investigative journalism
No, it's not a robot: prompt writing for investigative journalismNo, it's not a robot: prompt writing for investigative journalism
No, it's not a robot: prompt writing for investigative journalism
 
Credit limit improvement system in odoo 17
Credit limit improvement system in odoo 17Credit limit improvement system in odoo 17
Credit limit improvement system in odoo 17
 
"DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY ...
"DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY ..."DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY ...
"DANH SÁCH THÍ SINH XÉT TUYỂN SỚM ĐỦ ĐIỀU KIỆN TRÚNG TUYỂN ĐẠI HỌC CHÍNH QUY ...
 
AI_in_HR_Presentation Part 1 2024 0703.pdf
AI_in_HR_Presentation Part 1 2024 0703.pdfAI_in_HR_Presentation Part 1 2024 0703.pdf
AI_in_HR_Presentation Part 1 2024 0703.pdf
 
The Jewish Trinity : Sabbath,Shekinah and Sanctuary 4.pdf
The Jewish Trinity : Sabbath,Shekinah and Sanctuary 4.pdfThe Jewish Trinity : Sabbath,Shekinah and Sanctuary 4.pdf
The Jewish Trinity : Sabbath,Shekinah and Sanctuary 4.pdf
 
Is Email Marketing Really Effective In 2024?
Is Email Marketing Really Effective In 2024?Is Email Marketing Really Effective In 2024?
Is Email Marketing Really Effective In 2024?
 
Final_SD_Session3_Ferriols, Ador Dionisio, Fajardo.pptx
Final_SD_Session3_Ferriols, Ador Dionisio, Fajardo.pptxFinal_SD_Session3_Ferriols, Ador Dionisio, Fajardo.pptx
Final_SD_Session3_Ferriols, Ador Dionisio, Fajardo.pptx
 
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
 

Firewall

  • 2. Definition A firewall is a hardware or software designed to permit or deny network transmissions based upon a set of rules and is frequently used to protect networks from unauthorized access while permitting legitimate communications to pass. Firewalls Can Perform Basic Routing Functions
  • 3. Hardware & Software Firewall Figure 1: Hardware Firewall. Hardware firewall providing protection to a Local Area Network.   Figure 1: Hardware Firewall. Hardware firewall providing protection to a Local Area Network.   Figure 2: Computer with Firewall Software. Computer running firewall software that provide protection to PC..etc.,   Figure 2: Computer with Firewall Software. Computer running firewall software that provide protection to PC..etc.,  
  • 4. History The Morris Worm spread itself through multiple vulnerabilities in the machines of the time. The Morris Worm was the first large scale attack on Internet security; the online community was neither expecting an attack nor prepared to deal with one. First generation: Packet Filters Second generation: Application Level Gateway Third generation: "Stateful" Filters
  • 5. First Generation : Packet Filters ( Relativesimplicity and easeof implementation. ) A packet is a series ofA packet is a series of digital numbersdigital numbers basically,basically, a.a.The data,The data, acknowledgment,acknowledgment, request or commandrequest or command from the originatingfrom the originating systemsystem b.b.The source IPThe source IP address and portaddress and port c.c.The destination IPThe destination IP address and portaddress and port d.d.Information aboutInformation about the protocol (set ofthe protocol (set of rules) by which therules) by which the packet is to be handledpacket is to be handled In packet filtering, only the protocol and the address information of each packet is examined. Its contents and context (its relation to other packets and to the intended application) are ignored. Filtering consists of examining incoming or outgoing packets and allowing or disallowing their transmission or acceptance on the basis of a set of configurable rules, called policies. Packet filtering policies may be based upon any of the following: Allowing or disallowing packets on the basis of the source IP address Allowing or disallowing packets on the basis of their destination port Allowing or disallowing packets according to protocol.
  • 6. II Generation : Application level Gateway ( Much moresecureand reliablecompared to packet filter firewalls) The key benefit of application layer filtering is that it can "understand" certain applications and protocols (such as File Transfer Protocol, DNS, or web browsing) Works on all seven layers of the OSI model, from the application down to the physical Layer. Good examples of application firewalls are MS-ISA (Internet Security and Acceleration) server, McAfee Firewall Enterprise & Palo Alto PS Series firewalls. An application firewall can filter higher- layer protocols such as FTP, Telnet, DNS, DHCP, HTTP, TCP, UDP and TFTP For example, if an organization wants to block all the information related to "fool" then content filtering can be enabled on the firewall to block that particular word.
  • 7. Third Generation : Stateful Filters From 1989-1990 three colleagues from AT&T Bell Laboratories, Dave Presetto, Janardan Sharma, and Kshitij Nigam, developed the third generation of firewalls, calling them Circuit Level Firewalls This technology is generally referred to as a stateful packet inspection as it maintains records of all connections passing through the firewall and is able to determine whether a packet is the start of a new connection, a part of an existing connection, or is an invalid packet. This type of firewall can actually be exploited by certain Denial-of-service attacks which can fill the connection tables with illegitimate connections.
  • 9. Methods to Attack or View Computer Data:
  • 10. Basic Types Of Firewalls: Conceptually, there are two types of firewalls: Network layer Application layer Network layer Firewall : Generally make their decisions based on the source, destination addresses and ports in individual IP packets. A simple router is the ``traditional'' network layer firewall Many network layer firewalls is that they route traffic directly though them, so to use one you either need to have a validly assigned IP address block or to use a “private internet” address block . Network layer firewalls tend to be very fast and tend to be very transparent to users.
  • 11. In a screened host firewall, access to and from a single host is controlled by means of a router operating at a network layer. The single host is a bastion host; a highly-defended and secured strong- point that (hopefully) can resist attack. In a screened subnet firewall, access to and from a whole network is controlled by means of a router operating at a network layer. It is similar to a screened host, except that it is, effectively, a network of screened hosts.
  • 12. Application Layer Firewall : This can be used as network address translators, since traffic goes in one ``side'' and out the other, after having passed through an application that effectively masks the origin of the initiating connection. Not particularly transparent to end users and may require some training. Modern application layer firewalls are often fully transparent. Application layer firewalls tend to provide more detailed audit reports and tend to enforce more conservative security models than network layer firewalls. Example Application layer firewall: an application layer firewall called a ``dual homed gateway'' is represented. A dual homed gateway is a highly secured host that runs proxy software. It has two network interfaces, one on each network, and blocks all traffic passing through it.
  • 13. DMZ : Demilitarized Zone It is a physical or logical subnetwork that contains and exposes an organization's external services to a larger untrusted network, usually the Internet. It is sometimes referred to as a perimeter network Hosts in the DMZ have limited connectivity to specific hosts in the internal network, firewall controls the traffic between the DMZ servers and the internal network clients. A DMZ configuration typically provides security from external attacks, but it typically has no bearing on internal attacks such as sniffing communication via a packet analyzer or spoofing such as e- mail spoofing.
  • 14. Single Firewall & Dual Firewall I- ISP to Firewall II- Internal Network III- DMZ The firewall becomes a single point of failure for the network and must be able to handle all of the traffic going to the DMZ as well as the internal network. 3 interfaces A more secure approach is to use two firewalls to create a DMZ The first firewall -"front-end" firewall The second firewall - "back-end" firewall This architecture is, of course, more costly. The practice of using different firewalls from different vendors is sometimes described as a component of a "defence in depth" security strategy.
  • 16. Benefits of Firewall Firewalls protect private local area networks from hostile intrusion from the Internet. Firewalls allow network administrators to offer access to specific types of Internet services to selected LAN users. This selectivity is an essential part of any information management program, and involves not only protecting private information assets, but also knowing who has access to what. Privileges can be granted according to job description and need rather than on an all-or-nothing basis.
  • 17. Conclusion A solid firewall will help you stop intruders from accessing your system. we keep our internet link to the outside world but the outside world can't view us unless we want them to. With a firewall in place we will still have typical email access, but chat and other interactive programs will require you to take an extra step to grant access before we can use them. A firewall is powerful but unobtrusive, just like a deadbolt lock inside a door.