Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS

A security primer

Today's breaking news
Send to a friendFeedback


To evaluate firewalls or virtual private networks (VPN), you have to learn a new vocabulary. Most of today's firewall products forward or block traffic by implementing application proxy, packet filtering or circuit-level gateways.

Application-level firewalls, commonly referred to as proxy-level firewalls, are generally thought to offer better security from hackers by providing application-level awareness. However, throughput may suffer while the firewall device conducts the analysis.

Packet-filtering firewalls are typically the fastest and can block or forward traffic by IP address, packet type or service. However, because packet filtering operates on a packet-by-packet basis, packet-filtering firewalls can't monitor connections or offer the data analysis that other technologies can.

Circuit-level gateways forward or block traffic at the session layer. Most applications use a well-known port, so a circuit-level gateway assumes that the port is being used by its associated application and forwards or blocks traffic based on requested port access. This assumption isn't always well founded because hackers can use trusted ports to mount sophisticated attacks for improper activities.

There are several proposed security standards for VPNs. IP Security (IPSec), an encryption scheme that uses 56-bit Digital Encryption Standard (DES) or 168-bit Triple-DES keys, is the most commonly used. While Triple-DES offers superior security, it may reduce throughput under heavy load.

Other proposed VPN standards include ISAKMP/Oakley, which adds key management to IPSec; and SKIP, which was developed by Sun and uses a hierarchy of constantly changing keys and key management.

Related Links


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.