G.shdsl Router User Manual
Internet
192.168.0.10:1025
192.168.0.11:4406
192.120.8.5
Firewall
Internal/Protected Network
External/Unprotected Network
PAT (Port Address Translation)
192.168.0.10
192.168.0.11
1025
4406
Client IP
Internal Port
External Port
2205
2206
192.120.8.5:2205
192.120.8.5:2206
Circuit Gateway
Also called a "Circuit Level Gateway," this is a firewall approach that validates connections before
allowing data to be exchanged. What this means is that the firewall doesn't simply allow or disallow
packets but also determines whether the connection between both ends is valid according to
configurable rules, then opens a session and permits traffic only from the allowed source and
possibly only for a limited period of time.
Level 5: Application
Level 4: TCP
Level 3: IP
Level 2: Data Link
Level 1: Physical
destination IP address and/or port
source IP address and/or port
time of day
protocol
user
password
Application Gateway
The Application Level Gateway acts as a proxy for applications, performing all data exchanges
with the remote system in their behalf. This can render a computer behind the firewall all but
invisible to the remote system. It can allow or disallow traffic according to very specific rules, for
instance permitting some commands to a server but not others, limiting file access to certain types,
varying rules according to authenticated users and so forth. This type of firewall may also perform
very detailed logging of traffic and monitoring of events on the host system, and can often be
instructed to sound alarms or notify an operator under defined conditions. Application-level
gateways are generally regarded as the most secure type of firewall. They certainly have the most
sophisticated capabilities.
7