Home
21.
Explain about Screening Router Architecture?

In this architecture a firewall consists of nothing more than a screening router. Host on the Local Network and hosts on the Internet are allowed to communicate directly. The communication is restricted to the type that is allowed by a screening router. The security of the whole Local Network depends on the correct ACL of the router and on the amount of services permitted.

22.
Circuit level gateway advantages and disadvantages ?
The following are the advantages of Circuit Level Gateways:
  1. Private network data hiding
  2. Avoidance of filtering individual packets
  3. Flexible in developing address schemes
  4. Don't need a separate proxy server for each application
  5. Simpler to implement
The following are the disadvantages of Circuit Level Gateways:
  1. Active content cannot be scanned or disallowed commands.
  2. Can only handle TCP connections – new extensions proposed for UDP
  3. TCP/IP stacks are mandatorily be modified by vendor for using CL Gateways.
23.
What is IP spoofing and how can it be prevented?
IP spoofing is a mechanism used by attackers to gain unauthorized access to a system. Here, the intruder sends messages to a computer with an IP address indicating that the message is coming from a trusted host. This is done by forging the header so it contains a different address and make it appear that the packet was sent by a different machine. Prevention:-
  1. Packet filtering: - to allow packets with recognized formats to enter the network
  2. Using special routers and firewalls
  3. Encrypting the session
24.
What is the use of area and perimeter?

A lot of times, area and perimeter is used to help with a lot of home improvement projects like carpeting and hardwood flooring and painting. This is used to help give a good estimate of how much material you would need for these sort of projects. To find out what the outside of the shape is (perimeter), and to find out the inside size (area).

25.
Can you explain screened subnet architecture?

A screened subnet (also known as a "triple-homed firewall") is a network architecture that uses a single firewall with three network interfaces.

The purpose of the screened subnet architecture is to isolate the DMZ and its publicly-accessible resources from the intranet, thereby focusing external attention and any possible attack on that subnet. The architecture also separates the intranet and DMZ networks, making it more difficult to attack the intranet itself. When a properly configured firewall is combined with the use of private IP addresses on one or both of these subnets, attack becomes that much more difficult.