Firewalls Categorized by Generation

  • First-generation firewalls are static packet-filtering firewalls; that is, they are simple networking devices that filter packets per their headers as the packets travel to and from the organization’s networks.
  • Second-generation firewalls are application-level firewalls or proxy servers; that is, they are dedicated systems that are separate from the filtering router and that provide intermediate services for requestors.
  • Third-generation firewalls are stateful inspection firewalls, which monitor network connections between internal and external systems using state tables.
  • Fourth-generation firewalls are dynamic packet-filtering firewalls and allow only a packet with a source, destination, and port address to enter.
  • Fifth-generation firewalls are the kernel proxy, a specialized form that works under the Windows NT Executive, which is the kernel of Windows NT.

Firewalls Structures

  • Firewall appliances are stand-alone, self-contained systems that frequently have many of the features of a general-purpose computer with the addition of firmware-based instructions that increase their reliability and performance and minimize the likelihood of their being compromised.
  • A commercial-grade firewall system consists of firewall application software running on a general-purpose computer. Organizations can install firewall software on an existing general-purpose computer system, or they can purchase hardware that has been configured to the specifications that yield optimum performance for the firewall software.
  • SOHO and residential-grade firewall devices, also known as broadband gateways or DSL/cable modem routers, connect the user’s local area network or a specific computer system to the Internetworking device. The SOHO firewall serves first as a stateful firewall to enable inside-to-outside access, and it can be configured to allow limited TCP/IP port forwarding and/or screened subnet capabilities.
  • Residential-grade firewall software is installed directly on the user’s system. Some of these applications combine firewall services with other protections such as antivirus or intrusion detection. There are limits to the level of configurability and protection that software firewalls can provide.

Firewall Architectures

Each of the firewall devices noted earlier can be configured in a number of network connection architectures. The firewall configuration that works best for an organization depends on three factors: the objectives of the network, the organization’s ability to develop and implement the architectures, and the budget available for the function.

Although literally hundreds of variations exist, there are four common architectural implementations of firewalls:

  • Packet-filtering routers
  • Screened host firewalls
  • Dual-homed host firewalls
  • Screened subnet firewalls
Main Menu