Writers' Community!
Home Page Two Columnists Q&A Submit an Article FAQs Contact Author Login
Article Submission
We Need YOUR Articles!
We'll Promote Them for FREE!

Author Login

New Authors
Register Here


Now Serving 7,756 Authors
70,405 Quality Articles
& 3,099 Current Users Online!
Featured Authors
Ben Morrish (7,936)
Fran Larson (2,271)
Joel Hendon (16,285)
Shari Vaudo (418)
David Tanguay (9,577)
Michael Ramzy (633)
Missing Link (766)
E. Raymond Rock (3,068)
Gregory Lewis (1,603)
Nancy Daniels (1,550)
Mark Parsec (15,056)
Sandra E. Graham (7,883)
David Pekrul (3,696)
Ira Coffin (6,669)

View All Featured Authors
Most Recent
UK Based C Programming Courses - Thoughts

Discussions on Networking Training Uncovered

Finding The Right CompTIA Training Compared

Computer Training for Microsoft Systems Considered

Finding The Right MCSA Course Uncovered

Where To Do Your Adobe Web Design Course Clarified

Microsoft SQL Computer Training Companies Described

Considering Cisco CCNA Retraining Insights

Home Based MCSE Training Explained

Adobe CS4 Design Training Around The UK - Thoughts

Home » Categories » Computers & Networking » Technical Certification » CompTIA Security+ Article on Firewall Security Advantages and Firewall Functions » Printer Friendly

CompTIA Security+ Article on Firewall Security Advantages and Firewall Functions

Rated 2.5 out of 5
No Reader Ratings Available ?
Rate It  /  View Comments  /  View All Articles submitted by M. Aslam
Submitted Thursday, November 20, 2008
M. Aslam (315)

Log in to become a member of M. Aslam's Fan Club!


The firewall protects an internal network from malicious hackers or software on an external network. Firewalls filter potentially harmful incoming or outgoing traffic. Firewalls are used to subdivide internal networks on the Internet. It also protects individual computers. The five services that firewalls provide are packet filtering, application filtering, proxy server, circuit-level, and stateful inspection.

Packet Filtering: A packet filtering firewall checks each packet crossing the device. It also inspects the packet headers of all network packets going through the firewall.

Source IP Address: It identifies the host that is sending the packet. Attackers can modify this field in an attempt to conduct IP spoofing. Firewalls are configured to reject packets that arrive at the external interface, that is either an erroneous host configuration or an attempt at IP spoofing.

Destination IP Address: This is the IP address that the packet is trying to reach.

IP Protocol ID: Each IP header has a protocol ID that follows. For example, Transmission Control Protocol (TCP) is ID 6, User Datagram Protocol (UDP) is ID 17, and Internet Control Message Protocol (ICMP) is ID 1.

Fragmentation Flags: Firewalls examine and forward or reject fragmented packets. A successful fragmentation attack can allow an attacker to send packets that could compromise an internal host.

IP Options Setting: This field is used for diagnostics. The firewall is configured to drop network packets that use this field. Attackers can use this field in conjunction with IP spoofing to redirect network packets to their systems.

Application Filtering: This device will intercept connections and performs security inspections. The firewall acts as a proxy for connections between the internal and external network. The firewall enforce access control rules specific to the application. It is also use to check incoming e-mails for virus attachments. These firewalls are often called e-mail gateways.

Proxy Server: A proxy server takes on responsibility for providing services between the internal and external network. Proxy server can be used to hide the addressing scheme of the internal network. It can also be used to filter requests based on the protocol and address requested.

Circuit-Level: A circuit-level firewall controls TCP and UDP ports, but doesn't watch the data transferred over them. If a connection is established, the traffic is transferred without any further checking.

Stateful Inspection: An inspection firewall works at the Network layer. It assesses the IP header information. It also monitors the state of each connection. Connections are rejected if they attempt any actions that are not standard for the given protocol. These listed firewall features can be implemented in combination by a given firewall implementation. Placing a lot of firewalls in series is a common practice to increase security at the network perimeter.



tweet this!



Reprint Rights

Log in to become a member of M. Aslam's Fan Club!

No comments yet.


Was this article helpful to you? Leave a Public Comment or Question:

This Article has been viewed 74 times.
Article added to SearchWarp.com on 11/20/2008 2:53:15 AM.
View other articles written by M. Aslam (315)


If you found this article interesting, you may want to check out:

Disclaimer:  All information on this site is provided for informational purposes only! By no means is any information presented herein intended to substitute for the advice provided to you by any health care or other professional or organization.


Today's Most Popular
Cisco CCNA Exam Tutorial: Five OSPF Details You Must Know!

Cisco CCNA Certification Exam Tutorial: Route Summarization

Cisco CCNA Exam Tutorial: What's A Collision Domain?

How To Become A CCNA (Cisco Certified Network Associate)

Cisco CCNA Certification: Static And Default Static Routes

Cisco CCENT / CCNA Certification Exam Tutorial: Logging Synchronous And Exec-Timeout Commands

Cisco CCNA Exam Tutorial: The Best Time To Schedule Your Exam Is ....

Cisco CCNP / BSCI Exam Tutorial: EIGRP Route Summarization

Cisco Certification: Suggested Topologies For Your CCNA / CCNP Home Lab

Five Commands For Your Cisco CCNA/CCNP Home Practice Lab

Viewed from Cache. Load Time: 0.016.

Home  |  Page Two  |  FAQ's  |  Contact  |  Terms of Service  |  Article Submission Guidelines  |  Questions & Answers  |  Privacy  |  Mission / About
Copyright © 1999-2009 SearchWarp.com, All Rights Reserved - SearchWarp.com is an IcoLogic, Inc. Company