Firewall
BAT54-Rail/F..
Release
7.54
06/08
8.2
What is a Firewall?
257
This porter is making a definite better job. When somebody in this company
orders a courier, he must also inform the porter that he is expecting a courier,
when he will be arriving and what information should be found on the delivery
note. Only when this information matches the logbook entries of the porter,
the courier may pass. If the courier brings not only one packet, but rather two,
only the one with the correct delivery note will pass. Likewise, a second cou-
rier demanding access to the employee will be rejected, too.
U Application Gateway
By checking of contents on application level, Application Gateways increase
the address checking of the packet filters and the connection monitoring of
the Stateful Packet Inspection. The Application Gateway runs mostly on a
separate workstation, because of the high demands to the hardware perfor-
mance. This workstation is between the local network and the Internet. Seen
from both directions, this workstation is the only possibility to exchange data
with the respective other network. There doesn’t exist any direct connection
between these two networks, but just to the Application Gateway.
The Application Gateway is thus a kind of proxy for each of the two networks.
Another term for this constellation is the “dualhomed gateway”, because this
workstation is so to speak at home in two networks.
For each application to be allowed through this gateway, an own service will
be set up, e.g. SMTP for mail, HTTP for surfing the Internet or FTP for data
downloads.
Internet
Application gateway
Local network