Traditional Culture Encyclopedia - Traditional festivals - What are the two types of firewalls? Compare their advantages and disadvantages in maintaining network security.

What are the two types of firewalls? Compare their advantages and disadvantages in maintaining network security.

According to the traditional theory, firewalls can be divided into two types: packet filtering and application proxy.

1, packet filtering: packet filtering is usually installed on routers, and most commercial routers provide the function of packet filtering. In addition, packet filtering software can also be installed on PC. Packet filtering rules filter IP source address, IP destination address, encapsulation protocol (TCP/UDP/icmip tunnel), port number and so on according to IP packet information.

2. Proxy service: Proxy service firewall usually consists of two parts: server-side program and client-side program. The client program is connected to an intermediate node (proxy server), and the intermediate node is actually connected to the external server to be accessed. Unlike the packet filtering firewall, there is no direct connection between the internal network and the external network, and it also provides logging and auditing services.

3. Hybrid firewall: A new firewall can be formed by combining packet filtering with proxy service. The host used is called fortress host, which is responsible for providing proxy services.

4. Other firewalls: Routers and various hosts can form various types of firewalls according to their configurations and functions. The dual-host firewall fortress host acts as a gateway and runs firewall software on it. Internal network and external network can't communicate directly, but must pass through the fortress host. The firewall of shielded host is connected with a packet filtering router on the external network, and at the same time, a fortress host is installed on the internal network, so that the fortress host becomes the only node that can be reached by the external network and ensures that the internal network is not attacked by external unauthorized users. Encrypted router: Encrypted router encrypts and compresses the information flow passing through the router, and then transmits it to the destination through the external network for decompression and decryption.

In fact, there are many firewall products at present, and the criteria for division are quite complicated. The main categories are as follows:

1. From the form of software and hardware, it can be divided into software firewall, hardware firewall and chip-level firewall.

2. From the perspective of firewall technology, it can be divided into "packet filtering type" and "application proxy type".

3. According to the structure of firewall, it is divided into

4. According to the application and deployment location of firewalls, they can be divided into three categories: border firewalls, personal firewalls and mixed firewalls.

5. According to firewall performance, it can be divided into 100 megabit firewall and gigabit firewall.