User Guide
135
CHAPTER 9
Configuring Proxied
Services
Proxy filtering goes a step beyond packet filtering by
examining a packet’s content, not just the packet’s
header. Consequently, the proxy determines whether a
forbidden content type is hidden or embedded in the
data payload. For example, an email proxy examines
all SMTP packets to determine whether they contain
forbidden content types, such as executable programs
or items written in scripting languages. Such items are
common methods of transmitting computer viruses.
The SMTP proxy knows these content types are not
allowed, while a packet filter would not detect the
unauthorized content in the packet’s data payload.
Proxies work at the application level, while packet fil-
ters work at the network and transport protocol level.
In other words, each packet processed by a proxy is
stripped of all network wrapping, analyzed,
rewrapped, and forwarded to the intended destina-
tion. This adds several layers of complexity and pro-
cessing beyond the packet filtering process. What this
means, of course, is that proxies use more processing
bandwidth than packet filters. On the other hand, they
Summary of Contents for Firebox X1000
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System...
Page 12: ...xii WatchGuard Firebox System...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System...
Page 61: ...Cabling the Firebox User Guide 39...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System...