Kendrick

Firewall Explain in Detail

A firewall is a hardware or software appliance that sits between a computer and the Internet. The firewall protects the computer by blocking unauthorized access to the computer’s network resources.

A firewall is composed of three main components: the firewalling engine, the management interface, and the firewall rulebase. The firewalling engine is responsible for analyzing incoming traffic and deciding which traffic should be allowed through the firewall and which should be blocked.

The management interface allows the firewall administrator to configure and manage the firewall. The firewall rulebase stores all the firewall rules that have been configured by the administrator.

When a computer is connected to the Internet, the firewall must decide which traffic to allow and which traffic to block. The firewall can do this by analyzing the traffic itself, by inspecting the packets that are being sent, or by using a combination of both methods.

The firewall can block traffic based on the following criteria:

Domain Name System (DNS) lookup

IP address

Port number

Protocol

The firewall can also block traffic based on the following criteria:

User name

Domain name

Source IP

Destination IP

IP address range

Port number range

Action

The action can be:

Allow

Block

Allow is the default action and means that the traffic will be allowed through the firewall.

Block means that the traffic will be blocked and will not be allowed through the firewall.

Deny means that the traffic will be blocked and will not be allowed through the firewall.

Allow Any is the default action and means that the firewall will allow any traffic that is not specifically blocked.

Time

The time can be:

Now

In Progress

Completed

Type of traffic

The type of traffic can be:

HTTP

HTTPS

SMTP

Telnet

User ID.