CHAPTER 2 Access Control
CHAPTER 2 Access Control
CHAPTER 2 Access Control
w ---
Bob r file2 Bob r file2
--- r
rw r
Fred r file3 Fred --- file3
r r
Internal
Internet Firewall network
• No standard terminology
• Types of firewalls
– Packet filter works at network layer
– Stateful packet filter transport layer
– Application proxy application layer
– Personal firewall for single user, home network,
etc.
• Advantage application
– Speed
transport
• Disadvantages
– No state network
– Cannot see TCP connections
link
– Blind to application data
physical
• Advantages application
– Can do everything a packet filter can
transport
do plus...
– Keep track of ongoing connections
network
• Disadvantages
– Cannot see application data
link
– Slower than packet filtering
physical
letting it in
link
physical
physical
DMZ
FTP server
WWW server
DNS server
Intranet with
Packet Application Personal
Internet Filter Proxy Firewalls