Making Firewall Do the Work: Stateful Packet Inspection
cj writes "Author: Curt Frierson, Gladiator Technology Services
April 27 2005
For many overburdened system administrators tasked with the duty of securing their network, the extent of their knowledge of how a firewall works is that it “keeps the bad guys out.” IT examiners, however, are no longer satisfied with financial institutions simply having a firewall in place to reactively block potential attacks. Auditors now want to know what classification of firewall you have, and the characteristics of how it does its job.
As anyone who is trying to secure a network knows, a firewall is an absolute necessity. A well configured firewall is arguably the most important layer of defense from Internet attacks. But, how does your firewall defend your internal network from intrusions and how is one type of firewall different from another? There are several classifications of firewalls, each with their own unique attributes which help “keep the bad guys out.” To simplify this discussion, we will examine the two most common – packet filtering and stateful packet inspection.