Download Firewalls 24seven
Transcript
•486 or higher microprocessor Major Feature Set The major feature set for the IBM Firewall for AS/400 includes: •Packet Filter •Network Address Translator •Proxies for HTTP, SMTP •SOCKS proxy The packet filter is simple and stateless. It provides no functionality beyond the functionality provided by IP Chains or NT’s built-in packet filtering. Services can either be passed or blocked based on their TCP port number, and the filter can use the ACK bit to deny inbound connection attempts. The firewall is not normally configured to forward IP packets; rather, outbound connections are achieved via the circuit level gateway (i.e., SOCKS proxy) running at the Application Layer. This means that client software incompatible with SOCKS either cannot be used or relies upon the enabling of IP forwarding, which defeats many of the security features of the firewall. Support for real-time streaming multimedia protocols like RealAudio and H.323 also requires enabling of packet forwarding. Security proxy services are provided for HTTP and SMTP. All other TCP services must be SOCKS compatible in order to work with the firewall as its remaining functionality is provided by a SOCKS circuit level gateway. Minor Feature Set IBM Firewall for AS/400 provides the following minor feature: •Installs as standard AS/400 application The IBM Firewall for AS/400 installs as a normal AS/400 application, so AS/400 operators will be familiar with its operation. Interface Firewall administration is performed through a Web browser using an HTML-based administration tool. The tool is simple, but it provides an adequate interface to the firewall. Very little policy abstraction exists, so a strong knowledge of TCP/IP is required. Figure 15.3 shows the configuration interface running in a Web browser.