Cisco PIX 525 Spezifikationen Seite 35

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 604
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 34
1-3
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 1 Introduction to the Security Appliance
Firewall Functional Overview
Applying HTTP, HTTPS, or FTP Filtering
Although you can use access lists to prevent outbound access to specific websites or FTP servers,
configuring and managing web usage this way is not practical because of the size and dynamic nature of
the Internet. We recommend that you use the security appliance in conjunction with a separate server
running one of the following Internet filtering products:
Websense Enterprise
Sentian by N2H2
Applying Application Inspection
Inspection engines are required for services that embed IP addressing information in the user data packet
or that open secondary channels on dynamically assigned ports. These protocols require the security
appliance to do a deep packet inspection.
Applying QoS Policies
Some network traffic, such as voice and streaming video, cannot tolerate long latency times. QoS is a
network feature that lets you give priority to these types of traffic. QoS refers to the capability of a
network to provide better service to selected network traffic over various technologies, including Frame
Relay, ATM, Ethernet and 802.1 networks, SONET, and IP routed networks, that may use any or all of these
underlying technologies.
Applying Connection Limits and TCP Normalization
You can limit TCP and UDP connections and embryonic connections. Limiting the number of
connections and embryonic connections protects you from a DoS attack. The security appliance uses the
embryonic limit to trigger TCP Intercept, which protects inside systems from a DoS attack perpetrated
by flooding an interface with TCP SYN packets. An embryonic connection is a connection request that
has not finished the necessary handshake between source and destination.
TCP normalization is a feature consisting of advanced TCP connection settings designed to drop packets
that do not appear normal.
Firewall Mode Overview
The security appliance runs in two different firewall modes:
Routed
Transparent
In routed mode, the security appliance is considered to be a router hop in the network.
In transparent mode, the security appliance acts like a “bump in the wire,” or a “stealth firewall,” and is
not considered a router hop. The security appliance connects to the same network on its inside and
outside interfaces.
You might use a transparent firewall to simplify your network configuration. Transparent mode is also
useful if you want the firewall to be invisible to attackers. You can also use a transparent firewall for
traffic that would otherwise be blocked in routed mode. For example, a transparent firewall can allow
multicast streams using an EtherType access list.
Seitenansicht 34
1 2 ... 30 31 32 33 34 35 36 37 38 39 40 ... 603 604

Kommentare zu diesen Handbüchern

Keine Kommentare