TCP Intercept—With the TCP intercept feature, once the optional embryonic connection limit is reached, and
until the embryonic connection count falls below this threshold, every SYN bound for the affected server is
intercepted. For each SYN, PIX Firewall responds on behalf of the server with an empty SYN/ACK segment.
PIX Firewall retains pertinent state information, drops the packet, and waits for the client's acknowledgment. If
the ACK is received, then a copy of the client's SYN segment is sent to the server and the TCP three-way
handshake is performed between PIX Firewall and the server. If and only if, this three-way handshake completes,
may the connection resume as normal. If the client does not respond during any part of the connection phase, then
PIX Firewall retransmits the necessary segment using exponential back-offs.
TCP/IP—Transmission Control Protocol. Connection-oriented transport layer protocol that provides reliable
full-duplex data transmission. See also
IP
,
IP address
.
TFTP—Trivial File Transfer Protocol. TFTP is a simple protocol used to transfer files. It runs on UDP and is
explained in depth in Request For Comments (RFC) 1350. See also
Fixup
.
Translate, Translation, Address Translation—See
Xlate
.
U-Z
UDP—User Datagram Protocol. Connectionless transport layer protocol in the
TCP/IP
protocol that belongs to
the Internet protocol family.
URL—Universal Resource Locator. A standardized addressing scheme for accessing hypertext documents and
other services using a browser, for example,
http://www.cisco.com/go/pix.
Websense—A third party filtering application that works with the PIX Firewall to deny users access to web sites
based on the company security policy. Websense enables group and username authentication between a host and
a PIX Firewall. The PIX Firewall performs a username lookup, and then the Websense server handles URL
filtering and username logging. See
www.websense.com
.
WINS—Windows Internet Naming Service. A Windows system that determines the IP address associated with a
particular network computer.
Xlate—An xlate, also referred to as a translation entry, represents a mapping of one IP address to another, or a
mapping of one IP address/port pair to another. See also
NAT
,
PAT
,
Address Translation
,
IP Address
.
Copyright © 2001
Cisco Systems, Inc.
Содержание PIX 520 - PIX Firewall 520
Страница 45: ...Copyright 2001 Cisco Systems Inc ...
Страница 68: ...Copyright 2001 Cisco Systems Inc ...
Страница 74: ...Copyright 2001 Cisco Systems Inc ...
Страница 87: ...Copyright 2001 Cisco Systems Inc ...
Страница 92: ...Copyright 2001 Cisco Systems Inc ...
Страница 107: ...The panel has these buttons OK Exits the panel Help Provides more information Copyright 2001 Cisco Systems Inc ...
Страница 108: ......
Страница 184: ......
Страница 197: ...Copyright 2001 Cisco Systems Inc ...
Страница 200: ......
Страница 232: ...Copyright 2001 Cisco Systems Inc ...
Страница 246: ...Copyright 2001 Cisco Systems Inc ...