ZyXEL NBG-417N 사용자 설명서

다운로드
페이지 276
Chapter 13 Firewall
NBG-417N User’s Guide
134
• Use  the  Services screen (
) screen enable service 
blocking, enter/delete/modify the services you want to block and the date/time 
you want to block them. 
13.3  What You Need To Know About Firewall
The NBG-417N’s firewall feature physically separates the LAN and the WAN and 
acts as a secure gateway for all data passing between the networks.
13.3.1  What is a Firewall?
Originally, the term “firewall” referred to a construction technique designed to 
prevent the spread of fire from one room to another. The networking term 
"firewall" is a system or group of systems that enforces an access-control policy 
between two networks. It may also be defined as a mechanism used to protect a 
trusted network from a network that is not trusted. Of course, firewalls cannot 
solve every security problem. A firewall is one of the mechanisms used to 
establish a network security perimeter in support of a network security policy. It 
should never be the only mechanism or method employed. For a firewall to guard 
effectively, you must design and deploy it appropriately. This requires integrating 
the firewall into a broad information-security policy. In addition, specific policies 
must be implemented within the firewall itself. 
13.3.2  Stateful Inspection Firewall 
Stateful inspection firewalls restrict access by screening data packets against 
defined access rules. They make access control decisions based on IP address and 
protocol. They also "inspect" the session data to assure the integrity of the 
connection and to adapt to dynamic protocols. These firewalls generally provide 
the best speed and transparency; however, they may lack the granular application 
level access control or caching that some proxies support. Firewalls, of one type or 
another, have become an integral part of standard security solutions for 
enterprises.
13.3.3  About the NBG-417N Firewall
The NBG-417N firewall is a stateful inspection firewall and is designed to protect 
against Denial of Service attacks when activated (click the General tab under 
Firewall
 and then click the Enable Firewall check box). The NBG-417N's 
purpose is to allow a private Local Area Network (LAN) to be securely connected to 
the Internet. The NBG-417N can be used to prevent theft, destruction and 
modification of data, as well as log events, which may be important to the security 
of your network.