Protecting Networks: Firewalls · 保护网络:防火墙
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| firewall/ˈfaɪəwɔːl/ | 防火墙 | fáng huǒ qiáng |
| stateless/ˈsteɪtləs/ | 无状态 | wú zhuàng tài |
| stateful/ˈsteɪtfl/ | 有状态 | yǒu zhuàng tài |
| access control list/ˈækses kənˈtrəʊl lɪst/ | 访问控制列表 | fǎng wèn kòng zhì liè biǎo |
What a firewall does
- A firewall 防火墙 allows or denies traffic in or out of a network.
- Stateless 无状态 filters on packet headers alone.
- Stateful 有状态 also tracks each connection's state.
防火墙做什么
- 防火墙(firewall)允许或拒绝进出网络的流量。
- 无状态(stateless)只按数据包头部过滤。
- 有状态(stateful)还跟踪每个连接的状态。
The ACL and first match
- A firewall follows an access control list (ACL) 访问控制列表.
- Rules are checked in order; the first match wins.
- So the order of rules changes which traffic gets through.
ACL与首次匹配
- 防火墙遵循访问控制列表(access control list)。
- 规则按顺序检查;首次匹配获胜。
- 所以规则的顺序改变哪些流量能通过。
Which firewall rule fires first? · 哪条防火墙规则最先执行?
A firewall checks its ACL top-to-bottom and applies the first rule that matches the packet. · 防火墙自上而下检查其ACL,并应用第一个匹配该数据包规则的条目。
In a firewall ACL, which rule is applied to a packet? · 在防火墙ACL中,哪条规则应用于数据包?
The first matching rule wins. · 第一个匹配的规则生效。
A firewall that tracks the state of each connection is... · 跟踪每个连接状态的防火墙是……
Stateful firewalls track connections. · 有状态防火墙跟踪连接。
A firewall's ordered set of permit/deny rules is called an . · 防火墙有序排列的允许/拒绝规则集称为。
The ACL (access control list) drives the firewall. · ACL(访问控制列表)驱动防火墙。
Where firewalls belong
- At every gateway between the internal network and the internet.
- At the boundary of each network segment.
- Each firewall's security level can be set independently.
防火墙应放在哪里
- 在内部网络和互联网之间的每个网关处。
- 在每个网络分段的边界处。
- 每个防火墙的安全级别可以独立设置。
Rule order is everything. A Deny rule placed above an Allow rule for the same traffic blocks it — even though the Allow exists lower down. Read an ACL top-to-bottom and stop at the first match.
规则顺序至关重要。对同一流量,放在允许规则之上的拒绝规则会阻止它——即使允许规则在下方存在。从上到下读ACL,并在首次匹配处停止。
Placing a DENY rule above an ALLOW rule for the same traffic blocks that traffic. · 在同一流量的DENY规则位于ALLOW规则之上,则该流量被阻止。
First match wins — the DENY fires first. · 先匹配原则生效——DENY优先执行。
A packet is TCP 443. Order the rules by which is checked first. · 一个数据包为TCP 443。按检查顺序排列规则。
Rules are checked top-down; the packet is denied at Rule 2 before reaching Rule 3. · 规则自上而下检查;数据包在规则 2 被拒绝,未到达规则 3。
Rule 1: ALLOW TCP 22; Rule 2: DENY TCP 22. SSH traffic hits Rule 1 first, so it is allowed. Swap them, and now Rule 1 denies it — the same two rules give opposite results just by changing the order.
规则1:允许 TCP 22;规则2:拒绝 TCP 22。SSH流量先命中规则1,所以被允许。交换它们,现在规则1拒绝它——仅仅改变顺序,同样的两条规则就给出相反的结果。
A firewall permits or denies traffic using an ordered ACL, where the first matching rule wins — so rule order decides the outcome. Firewalls belong at every internet gateway and segment boundary. Stateful firewalls track connections; stateless ones only read headers.
防火墙用有序的ACL允许或拒绝流量,其中首次匹配的规则获胜——所以规则顺序决定结果。防火墙应放在每个互联网网关和分段边界。有状态防火墙跟踪连接;无状态的只读头部。