10.07.2015 Views

Data Communications Networking Devices - 4th Ed.pdf

Data Communications Networking Devices - 4th Ed.pdf

Data Communications Networking Devices - 4th Ed.pdf

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

802 ___________________________________________________________ SPECIALIZED DEVICESProxy servicesA proxy represents a code that performs handshaking for a speci®c application,such as FTP, Telnet, or HTTP. Through the proxy services capability of a ®rewall,speci®c users or groups of users can be allowed or denied access to a server or to asubset of a server's functionality. For example, through the use of FTP proxyservices, you may be able to enable or disable the use of GET, MGET, PUT,MPUT, and other FTP commands for all addresses or selected IP addresses. Thus,it is important to examine both the type of proxy services supported by a ®rewall aswell as the commands supported for each service.Note that proxy services can vary considerably between different ®rewallproducts. However, this functionality does not exist in routers, nor in ®rewalls thatsimply provide an expanded packet ®ltering capability. Thus, proxy servicesrepresent a feature that can be used to differentiate a more capable ®rewall from lesscapable products.To illustrate the con®guration of proxy services and some additional ®rewallfeatures, this author captured several con®guration screens generated by the TechnologicInterceptor ®rewall. Figure 7.43 illustrates the Interceptor's AdvancedPolicy Options screen in which the cursor is shown pointing to the HTTP BlockPut and Post entries that were selected. In examining Figure 7.43 and subsequentFigure7.43 Using the Technologic Interceptor ®rewall con®guration screen to block allFTP. Put commands

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!