PREPARED BY : PINA CHHATRALA 1
Firewall
Submitted By :- Submitted to:-
SHANAWAZ Mrs.Afra Fathima
Roll No.17MMCA003HY Dept. Of CS& IT
CONTAINTS
 What is firewall?
 Type of firewall?
 Advantage and Disadvantage of firewall?
WHAT IS FIREWALL?
A firewall can either be software-based or hardware-based and is used to
help keep a network secure .
A system designed to prevent network. Firewall can be implement both
hardware or software ,or a combination of both.
Milestone
 Types of Firewalls
. Packet filtering firewall
. Application proxy firewall
. Stateful inspection firewall
. Circuit – level proxy firewall
PREPARED BY : PINA CHHATRALA 2
Packet Filtering Fi rewall
4
Packet Filtering Fi rewall
 A packet filtering firewall applies a set of rules to each incoming
and outgoing IP packet and then forwards or discards the
packet.
 Filtering rules are based on information contained in a network
packet.
. Source IP address
. Destination IP address
. Source and destination transport level address
. IP protocol field
. Interface
5
Packet Filtering Fi rewall
 Two default policies are there to take default action to
determine whether to forward or discard the packet.
. Default = discard
. Default = forward
 Some possible attacks on firewall :
. IP address spoofing
. Source routing attacks
. Tiny fragment attacks
6
Packet Filtering Fi rewall
 Advantage :
. Cost
. Low resource usage
. Best suited for smaller network
 Disadvantage :
. Can work only on the network layer
. Do not support complex rule based support
. Vulnerable to spoofing
7
Application Proxy Fi rewall
8
Application Proxy Firewall
 An application – level gateway, also called an application proxy,
acts as a rely of application – level traffic.
 user requests service from proxy.
 proxy validates request as legal.
 then actions request and returns result to user.
 can log / audit traffic at application level.
9
Application Proxy Fi rewall
 Advantage :
. More secure than packet filter firewalls
. Easy to log and audit incoming traffic
 Disadvantage :
. Additional processing overhead on each connection
Firewall