Where are firewalls inserted? - Answers Between the local network and the internet to establish a
controlled link
What can firewalls look like? - Answers A single computer system or a set of two or more systems
working together
Firewalls are used as a perimeter defense and . . . - Answers A single choke point to impose security and
auditing, and insulated the internal systems from external networks
What are the design goals of a firewall? - Answers All traffic inside to outside, and vice versa, must pass
through the firewall. Only authorized traffic as defined by the local security policy will be allowed to
pass.
Should the firewall itself be immune to penetration? - Answers YES
Specifying a suitable access policy is a . . . - Answers Critical component in the planning and
implementation of a firewall
A firewall access policy may include . . . - Answers The types of traffic authorized to pass through the
firewall, as well as address ranges, protocols, applications, and content types
A firewall access policy should be developed from a broad specification of which traffic types the
organization needs to support then . . . - Answers Refined to detail the filter elements which can then be
implemented within an appropriate firewall topology
Characteristics that a firewall access policy could use to filter traffic include . . . - Answers IP address and
protocol values
Application protocol
User identity
Network activity
Firewall capabilities - Answers -Defines a single choke point
-Provides a location for monitoring security events
, -Convenient platform for several Internet functions that are not security related
-Can serve as the platform for IPSec
Firewall limits - Answers -Cannot protect against attacks bypassing firewall
-May not protect fully against internal threats
-Improperly secured wireless LAN can be accessed from outside the organization
-Laptop, PDA, or portable storage device may be infected outside the corporate network then used
internally
Packet Filtering Firewall - Answers - Applies rules to each incoming and outgoing IP packet
- Typically a list of rules based on information contained in a network packet (source IP, destination IP,
source and destination
- Forwards or discards the packet based on rules match
What are the 2 default policies of a packet filtering firewall? - Answers Discard - prohibit unless expressly
permitted
--> More conservative, controlled, visible to users
Forward - permit unless expressly prohibited
--> Easier to manage and use but less secure
Advantages of a packet filtering firewall - Answers - Simple
- Typically transparent to users and are very fast