Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Apple tops the $100B+ tech club
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Microsoft details Windows 8 for ARM devices
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise

A security primer

Today's breaking news
Send to a friendFeedback


To evaluate firewalls or virtual private networks (VPN), you have to learn a new vocabulary. Most of today's firewall products forward or block traffic by implementing application proxy, packet filtering or circuit-level gateways.

Application-level firewalls, commonly referred to as proxy-level firewalls, are generally thought to offer better security from hackers by providing application-level awareness. However, throughput may suffer while the firewall device conducts the analysis.

Packet-filtering firewalls are typically the fastest and can block or forward traffic by IP address, packet type or service. However, because packet filtering operates on a packet-by-packet basis, packet-filtering firewalls can't monitor connections or offer the data analysis that other technologies can.

Circuit-level gateways forward or block traffic at the session layer. Most applications use a well-known port, so a circuit-level gateway assumes that the port is being used by its associated application and forwards or blocks traffic based on requested port access. This assumption isn't always well founded because hackers can use trusted ports to mount sophisticated attacks for improper activities.

There are several proposed security standards for VPNs. IP Security (IPSec), an encryption scheme that uses 56-bit Digital Encryption Standard (DES) or 168-bit Triple-DES keys, is the most commonly used. While Triple-DES offers superior security, it may reduce throughput under heavy load.

Other proposed VPN standards include ISAKMP/Oakley, which adds key management to IPSec; and SKIP, which was developed by Sun and uses a hierarchy of constantly changing keys and key management.

Related Links


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.