- Home
- Our Services
- Firewalls Network Security
Firewalls & Intrusion Detection Systems
A firewall is a barrier to keep destructive forces away from your property — its job is similar to a physical firewall that keeps a fire from spreading from one area to the next. The bottom line: a firewall keeps hackers and intruders out.
Full Capabilities
A Single Point of Access Between You and "The Evil Internet"
A firewall is a network component that allows a single point of access between your internal network and the outside world. Most of the time you only need your network connected to the outside for a very small number of things.
The primary advantage is that your security officer can concentrate efforts on a single point of entry rather than hundreds or thousands of access points. The trade-off: if the firewall is ever compromised, or another access point is discovered, the internal network can be left wide open.
Firewalls are typically built from a workstation with two or more interfaces — anything from a PC with two ethernet cards to a dedicated hardware platform designed specifically for firewall applications.
Some examples of services an internal network might want to share with the outside world:
- News
- DNS
- Web
- Time Service
- Remote Access (Telnet, rlogin, etc.)
Two Approaches
Types of Firewalls
Firewalls generally fall into two categories, each with its own trade-offs.
Filtering Firewall
Decides whether to forward a packet based on criteria such as source, destination, packet type, and port number. Opening ports too broadly — for mail or web traffic, for example — can leave services directly exposed, so this approach requires careful rule design.
Proxy Firewall
Acts explicitly on behalf of internal or external machines — for example, a proxy mail gateway passes traffic on a message basis without outsiders connecting directly to your internal net. Proxy firewalls also enable much stronger logging and, for web traffic, can double as a caching server.
Good To Know
What a Firewall Can't Do Alone
Firewalls scale well and can be layered by service or protocol for better performance and security — but they aren’t a complete solution on their own.
Keep In Mind
- Firewalls are reactive and generally lag technology — it takes time before the latest protocol is recognized, filtered, or proxied
- Firewalls may give a false sense of security
- Firewalls require constant monitoring, updating, maintenance, and testing — configuration rules can be complex
- Firewalls do not relieve you of concern for internal host security
- Firewalls must be properly configured, well managed, and intensely monitored
Beyond the Firewall
Intrusion Detection Systems
The threat to networks posed by hackers is growing exponentially. You simply can’t have random people accessing your files at will — you wouldn’t buy a house without a front door, and the same logic applies to your network.
A firewall alone isn’t enough. It filters traffic based on defined rules, but has no real concept of what suspicious traffic looks like. Intrusion Detection Systems (IDS) sit on the network or host machines, checking all traffic and comparing it against a database of attack signatures — similar to how antivirus products work — to alert on and prevent an attack.
Our IDS Capabilities
Checkpoint & Symantec
We configure, implement, and update all types of IDS software from these vendors.
Attack Signature Matching
Traffic is compared against a database of known attack signatures to alert and prevent intrusion.
SonicWall HA Clusters
High Availability cluster support, firewall rules, and Deep Packet Inspection for SSL-encrypted connections.
How It Works
Getting Your Network Secured
From assessment to ongoing monitoring, security experts you can rely on.
1
Assess Your Network
We review your current access points and connection type — dialup to fiber.
2
Design the Architecture
We recommend filtering, proxy, or a layered approach based on your needs.
3
Implement & Configure
We build and configure firewall rules and IDS software from trusted vendors.
4
Monitor & Update
Ongoing monitoring, testing, and rule updates keep your defenses current.
Full Capabilities
Ready to Get Started?
Contact us today to discuss your IT needs and discover how Layer 4 Solutions, Inc. can help your business grow.