The Network DNA · @thenetworkdna
4 followers · 96 posts · Server mastodon.world
The Network DNA · @thenetworkdna
1 followers · 40 posts · Server mastodon.world
Sheik · @sheikeinstein
60 followers · 49 posts · Server infosec.exchange

Firewalls can be divided into:
1. Stateful
1.1 Packet Filtering Firewall

2. Stateless
2.1 Packet Filtering Firewall/Routers
2.2 Circuit-level gateway Firewall/Proxy Servers
2.3 Application-level gateway

3. Next Generation Firewall

Depending on how vendors deliver their , firewalls can be of 3 types:

1. Hardware FW
Runs on hardware

2. Software FW
Runs on computers

3. Cloud FW
Provides Firewall-as-a-Service (FaaS)

Brief Details:

1. Stateful
Uses Stateful inspection , inspects inside packets, examines+catalogs patterns of its behavior, remembers this behaviour for future, so needs more memory

1.1 Stateful Packet filtering FW
Often a software Packet firewall acts like .
🛡️ that implement this FW: TCP
🛡️ List of stateful FW:
🔸 Defender Firewall ()
🔸Palo Alto Networks Firewall (Software/Hardware)
🔸's Fortigate NGFW (Software/Hardware)
🔸 ASA (Hardware)
🔸 Cloud-native firewall (Cloud)
🔸 Firewall (GCP)
🔸 Network Firewall (stateless + stateful) (Hardware/Software)
🔸 netfilter/iptables (Software)

2. Stateless FW / Router
Uses data packet's source, destination etc to find if the presents threat or not, uses ACL, doesn't look what's inside the packet (doesn't remember anything, so less memory & is faster)
🛡️ Protocols that implement this FW: DNS, UDP, HTTP
🛡️ List of Stateless FW:
🔸Any router can be operated as stateless firewall by defining an ACL

2.1 Circuit-level gateway / Proxy Server
Also a transparent proxy FW or Proxy Server, works as stateless, works at the transport+session layers, examines TCP handshake information found in /UDP packet headers that is sent between computers to verify that these exchange of packets are sequential, logical & if follows some legitimate rules. Do not inspect inside the packets.
🛡️ Protocols that implement this FW: SOCKS, SOCKS5
🛡️ List of VPNs who uses Socks5:
🔸Oxylabs
🔸Bright Data
🔸Rayobytes
🔸Smartproxy

2.2 Application-level gateway FW
A stateless firewall, also an Application-level proxy, sits between original server & external user, controls traffic, synchronization of information, resource allocation, software response control, does address & port translation.
🛡️ Protocols that implement this FW: SIP, FTP, Telnet, RTSP
🛡️ List of Application-level gateway FW:
🔸Azure Web Application Firewall (WAF) 
🔸AWS WAF
🔸Cloudflare Spectrum
🔸
🔸HAProxy
🔸Cloudflare WAF
🔸F5 BIG-IP Advanced WAF

3. Next-generation FW (More capable than stateful)
NGFWs has advanced functions including application awareness, Integrated intrusion prevention systems, identity awareness, bridged+routed modes, threat .
🛡️ List of :
🔸Fortinet FortiGate (7000 series) (Hardware/Software)
🔸Cisco FirePOWER Series (Hardware)
🔸Palo Alto Networks PA Series (Hardware)
🔸Juniper Networks SRX Series (Hardware)
🔸SonicWall NGFW TZ Series (Hardware)

#firewall #network #host #technology #filtering #stateful #protocol #windows #software #fortinet #cisco #azure #google #cloud #aws #linux #data #tcp #nginx #intelligence #ngfw

Last updated 2 years ago

infosec-jobs.com · @infosec_jobs
1273 followers · 14513 posts · Server mastodon.social