Difference between revisions of "Netband Project - IOS firewall"

From Teknologisk videncenter
Jump to: navigation, search
(Context Based Access Control (CBAC))
(Context Based Access Control (CBAC))
Line 5: Line 5:
 
*filters TCP and UDP packets based on application-layer protocol session information.
 
*filters TCP and UDP packets based on application-layer protocol session information.
 
*more flexible than access control lists, that checks packets at the network layer, or at most, the transport layer
 
*more flexible than access control lists, that checks packets at the network layer, or at most, the transport layer
 +
*inspects packet sequence numbers in TCP connections
 +
*detects unusually high rates of new connections and issue alert messages.
 +
*creates temporary openings in the return acl to allow traffic back in.
  
 
==Intrusion Detection Protection (IDS)==
 
==Intrusion Detection Protection (IDS)==

Revision as of 08:46, 27 April 2009

<accesscontrol>NetBand</accesscontrol> This page is part of the Netband Project

Context Based Access Control (CBAC)

  • filters TCP and UDP packets based on application-layer protocol session information.
  • more flexible than access control lists, that checks packets at the network layer, or at most, the transport layer
  • inspects packet sequence numbers in TCP connections
  • detects unusually high rates of new connections and issue alert messages.
  • creates temporary openings in the return acl to allow traffic back in.

Intrusion Detection Protection (IDS)

Authentication Proxy

Port to Application Mapping (PAM)

External Links

Cisco IOS Security Configuration Guide