Download Firewalls 24seven

Transcript
•486 or higher microprocessor
Major Feature Set
The major feature set for the IBM Firewall for AS/400 includes:
•Packet Filter
•Network Address Translator
•Proxies for HTTP, SMTP
•SOCKS proxy
The packet filter is simple and stateless. It provides no functionality beyond the functionality
provided by IP Chains or NT’s built-in packet filtering. Services can either be passed or blocked
based on their TCP port number, and the filter can use the ACK bit to deny inbound connection
attempts.
The firewall is not normally configured to forward IP packets; rather, outbound connections are
achieved via the circuit level gateway (i.e., SOCKS proxy) running at the Application Layer. This
means that client software incompatible with SOCKS either cannot be used or relies upon the
enabling of IP forwarding, which defeats many of the security features of the firewall. Support for
real-time streaming multimedia protocols like RealAudio and H.323 also requires enabling of packet
forwarding.
Security proxy services are provided for HTTP and SMTP. All other TCP services must be SOCKS
compatible in order to work with the firewall as its remaining functionality is provided by a SOCKS
circuit level gateway.
Minor Feature Set
IBM Firewall for AS/400 provides the following minor feature:
•Installs as standard AS/400 application
The IBM Firewall for AS/400 installs as a normal AS/400 application, so AS/400 operators will be
familiar with its operation.
Interface
Firewall administration is performed through a Web browser using an HTML-based administration
tool. The tool is simple, but it provides an adequate interface to the firewall. Very little policy
abstraction exists, so a strong knowledge of TCP/IP is required. Figure 15.3 shows the
configuration interface running in a Web browser.