Application Layer Proxy Firewall
• An application layer firewall operates on OSI Layers 3, 4, 5, and 7.
• Advantages of application layer proxy firewalls:
- This firewall authenticates individuals, not devices.
- Hackers have a harder time with spoofing and implementing DoS attacks.
- This firewall can monitor and filter application data.
- This firewall can provide detailed logging.
|
Layer 7 |
Application |
|
Presentation |
|
|
Layer 5 |
Session |
|
Layer 4 |
Transport |
|
Layer 3 |
Network |
|
Layer 2 |
Data Link |
|
Layer 1 |
Physical |
Application layer firewalls filter information at Layers 3, 4, 5, and 7 of the OSI reference model. Because application layer firewalls process information at the application layer, they do most firewall control and filtering in the software. Locating the firewall at the application layer provides much more control over traffic than packet filtering, stateful, or application inspection firewalls do.
Sometimes, application layer firewalls support only a limited number of applications, or even just one application. Some of the more common applications that an application layer firewall might support include e-mail, web services, DNS, Telnet, FTP, USENET news, Lightweight Directory Access Protocol (LDAP), and finger.
Here are some of the advantages of application layer firewalls:
■ Application layer firewalls authenticate individuals, not devices: These firewalls typically allow you to authenticate connection requests before allowing traffic to an internal or external resource. This process enables you to authenticate the user requesting the connection instead of authenticating the device.
■ It is harder for hackers to spoof and implement DoS attacks: An application layer firewall enables you to prevent most spoofing attacks, and DoS attacks are limited to the application firewall itself. The application firewall can detect DoS attacks, reducing the burden on your internal resources.
■ Application layer firewalls can monitor and filter application data: You can monitor all data on a connection, so you can detect application attacks such as malformed URLs, buffer overflow attempts, unauthorized access, and more. You can even control what commands or functions you allow an individual to perform based on the authentication and authorization information.
© 2006 Cisco Systems, Inc. Cisco IOS Firewall Configuration 4-13
■ Application layer firewalls can provide detailed logging: Using application layer firewalls, you can generate very detailed logs and monitor the actual data that the individual is sending across a connection. This can be extremely useful if a hacker finds a new type of attack, because you can monitor what the hacker does and how the machine does it and then address the attack. Besides using logging for security purposes, you can use it for management purposes by keeping track of who is accessing what resources, how much bandwidth is used, and how often a user accesses the resources.
4-14 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.
Application Level Proxy Firewall
Application Level Proxy Firewall
The figure shows a simple device acting as an application level proxy server. Application level proxy servers run at the application level of the network protocol stack for each different type of service (for example FTP or HTTP). An application level proxy firewall controls how internal users access the outside world (the Internet) and how Internet users access the internal network. In some cases, the proxy server blocks all outside connections and only allows internal users to access the Internet. The only packets allowed back through the proxy server are those that return responses to requests from inside the firewall. In other cases, the firewall allows both inbound and outbound traffic under strictly controlled conditions. This setup is like a virtual gap that exists in the firewall between the inside and outside networks. The proxy servers bridge this gap by working as agents for internal or external users.
© 2006 Cisco Systems, Inc. Cisco IOS Firewall Configuration 4-15
Proxy Server: Dedicated Application Layer Filter (Proxy) for HTTP
Proxy Server: Dedicated Application Layer Filter (Proxy) for HTTP
1. Request
4. Repackaged Response
2. Repackaged Request
3. Response
Client
Web Server
2. Repackaged Request
3. Response
Client
Web Server
Continue reading here: Dynamic or Stateful Packet Filtering Firewalls
Was this article helpful?
Readers' Questions
-
dean10 months ago
- Reply
-
Filmon10 months ago
- Reply
-
Leonie10 months ago
- Reply
-
Regina10 months ago
- Reply
-
Akseli10 months ago
- Reply
-
Rufino10 months ago
- Reply
-
ERMA1 year ago
- Reply