Firewall and Proxy Servers

Embed Size (px)

Citation preview

  • 7/29/2019 Firewall and Proxy Servers

    1/26

    Name: N.Rajeeva11B91D4006

  • 7/29/2019 Firewall and Proxy Servers

    2/26

    Firewall Proxy Server Relationship between Proxy Server and

    Firewall Types of Firewalls Hardware requirements Software requirements

    Conclusion

  • 7/29/2019 Firewall and Proxy Servers

    3/26

    A computer firewall is a router or othercommunications device which filters access to aprotected network.

    Firewall is also a program that screens allincoming traffic and protects the network fromunwelcome intruders.

  • 7/29/2019 Firewall and Proxy Servers

    4/26

    Firewalls can also be used as access controlmeasures to only allow certain people within theorganization access to the Internet. Many firewallsnow contain features to control, authenticate and

    secure users who may want to access a companyinternal data from the Internet or even anothercompany.

  • 7/29/2019 Firewall and Proxy Servers

    5/26

    Proxy Server is a computer programthat acts as an intermediary betweena web browser and a web server. Togive users rapid access to popularweb destinations

  • 7/29/2019 Firewall and Proxy Servers

    6/26

    Part of an overall Firewall strategy Sits between the local network and the external network

    Originally used primarily as a caching strategy to minimizeoutgoing URL requests and increase perceived browserperformance

    Primary mission is now to insure anonymity of internal users Still used for caching of frequently requested files

    Also used for content filtering

    Acts as a go-between, submitting your requests to theexternal network

    Requests are translated from your IP address to the Proxys IPaddress

    E-mail addresses of internal users are removed from requestheaders

    Cause an actual break in the flow of communications

  • 7/29/2019 Firewall and Proxy Servers

    7/26

    Internet Service Providers use proxy servers as"holding bins" to store frequently requested pages,rather than going out and fetching themrepeatedly from the Net

    Proxy server is also used to control and monitoroutbound traffic

  • 7/29/2019 Firewall and Proxy Servers

    8/26

    Proxy Server is associated with firewall and alsocaching program

    The functions of proxy, firewall, and caching can

    be in separate server programs or combined in asingle package.

    Proxy Server can be installed in the firewall toget a kind of proxy firewall

  • 7/29/2019 Firewall and Proxy Servers

    9/26

    Packet Filtering Firewalls

    Proxy Server Firewalls

  • 7/29/2019 Firewall and Proxy Servers

    10/26

  • 7/29/2019 Firewall and Proxy Servers

    11/26

    Application Proxy

    SOCKS Proxy

  • 7/29/2019 Firewall and Proxy Servers

    12/26

    As you telnet to the outside world the clientsend you to the proxy first. The proxy then

    connects to the server you requested (theoutside world) and returns the data to you

  • 7/29/2019 Firewall and Proxy Servers

    13/26

    SOCKS is networking proxy protocol thatenables hosts on one side of a SOCKS server togain full access to hosts on the other side of theSOCKS server without requiring direct IP

    reachability. SOCKS redirects connectionrequests from hosts on opposite sides of aSOCKS server. The SOCKS server authenticatesand authorizes the requests, establishes a proxy

    connection, and relays data

  • 7/29/2019 Firewall and Proxy Servers

    14/26

    Packet Filtering Firewalls

    Proxy Server Firewalls

  • 7/29/2019 Firewall and Proxy Servers

    15/26

    Filtering firewalls don't require fancy hardware.They are little more then simple routers a 486-DX66 with 32 meg of memory a 250m hard disk (500

    recommended) network connections (LAN Cards,

    Serial Ports, Wireless?) monitor and keyboard

  • 7/29/2019 Firewall and Proxy Servers

    16/26

    If you need a proxy server firewall to handle lotsof traffic, you should get the largest system youcan afford a Pentium II with 64meg of memory a two gig hard disk to store all the

    logs two network connections monitor and keyboard

  • 7/29/2019 Firewall and Proxy Servers

    17/26

    Packet Filtering Firewalls

    Proxy Server Firewalls

  • 7/29/2019 Firewall and Proxy Servers

    18/26

    To create a filtering firewall, you don't need anyspecial software. Linux will do

    The built-in Linux firewall has changed severaltimes, for the newer 2.4 kernel there is a newfirewall utility with more features

  • 7/29/2019 Firewall and Proxy Servers

    19/26

    If you want to setup a proxy server you will needone of these packages

    Squid

    The TIS (Trusted InformationSystem) Firewall Toolkit (FWTK)

    SOCKS

  • 7/29/2019 Firewall and Proxy Servers

    20/26

    Squid is a great package and works withLinux's Proxy feature

  • 7/29/2019 Firewall and Proxy Servers

    21/26

    The TIS Internet Firewall Toolkit is a set ofprograms and configuration practices

    designed to facilitate the building ofnetwork firewalls.

    The toolkit software is designed to run on

    UNIX systems

  • 7/29/2019 Firewall and Proxy Servers

    22/26

    SOCKS can be installed both in NTsystem and UNIX system

    RFC 1928 Not a true application layer proxy

    SOCKS protocol provides a framework

    for developing secure communicationsby easily integrating other securitytechnologies

  • 7/29/2019 Firewall and Proxy Servers

    23/26

    SOCKS includes two components SOCKS server

    implemented at the application layer

    SOCKS client

    implemented between the application and transportlayers

    The basic purpose of the protocol is toenable hosts on one side of a SOCKS server

    to gain access to hosts on the other side ofa SOCKS Server, without requiring direct IP-reachability.

  • 7/29/2019 Firewall and Proxy Servers

    24/26

  • 7/29/2019 Firewall and Proxy Servers

    25/26

  • 7/29/2019 Firewall and Proxy Servers

    26/26

    Both firewall and proxy server are usedfor net work security and facility

    Proxy server can be a part of firewall