操作系统防火墙中英文对照外文翻译文献.docx

上传人:b****1 文档编号:10182349 上传时间:2023-05-24 格式:DOCX 页数:18 大小:31.19KB
下载 相关 举报
操作系统防火墙中英文对照外文翻译文献.docx_第1页
第1页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第2页
第2页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第3页
第3页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第4页
第4页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第5页
第5页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第6页
第6页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第7页
第7页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第8页
第8页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第9页
第9页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第10页
第10页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第11页
第11页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第12页
第12页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第13页
第13页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第14页
第14页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第15页
第15页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第16页
第16页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第17页
第17页 / 共18页
操作系统防火墙中英文对照外文翻译文献.docx_第18页
第18页 / 共18页
亲,该文档总共18页,全部预览完了,如果喜欢就下载吧!
下载资源
资源描述

操作系统防火墙中英文对照外文翻译文献.docx

《操作系统防火墙中英文对照外文翻译文献.docx》由会员分享,可在线阅读,更多相关《操作系统防火墙中英文对照外文翻译文献.docx(18页珍藏版)》请在冰点文库上搜索。

操作系统防火墙中英文对照外文翻译文献.docx

操作系统防火墙中英文对照外文翻译文献

中英文对照外文翻译文献

(文档含英文原文和中文翻译)

 

原文:

LockingUpthePorts:

WindowsFirewall

OneofMicrosoft’sstrongestresponsestotheongoingbuffer-overflow-wormthreatwasacompleterewritingofthesoftwarefirewallincorporatedintoXP,2003,andR2.TheyrenamedthefirewallfromInternetConnectionFirewall(ICF)toWindowsFirewall(WF).TheyalsoaddedsomethingcalledIpsecbypassthatextendsthefirewall’sabilitytoallowyoutoeasilyrequireasecureservertoauthenticatenotjustincomingusers,butmachines.Inthischapter,you’llseewhatWFdoes,whatissuesitcanraise,andhowtoconfigureitsothatitsuitsyoursecurityneedsbest.

WhatIsWindowsFirewall?

Howcananoperatingsystemhavefirewall,anyway?

Isn’tafirewallaboxwithblinkinglightsandabunchofcablescomingoutofit?

Theansweristhatthetermfirewallreferstoanyofanumberofwaystoshieldacomputernetworkfromothernetworks,networksrifewithuntrustworthypeople—youknow,networksliketheInternet.Let’sdigdownabitfurther,however,andstartwithalookatwhatafirewallis,basically.

WhatFirewallsDo

WiththeadventoftheLndustrialRevolution,peoplestartedbuildingthingsdrivenbysteampower,suchaslocomotives,ships,andthelike.Creatingsteamrequiredfire,andfire’sascarything,atleastwhenitgetsoutofhand.Toprotectagainstfire-relatedproblems,thoselocomotives,ships,andthelikeweredesignedsothatathick,sturdy,nearlyfireproofwallexistedbetweenwhereverthefirewaskept—usuallyaboiler—andtherestofthevehicle.Thatway,ifsomethingcaughtfireintheboiler’scompartment,thentheonboardengineerswouldhaveabitmoretimetoputoutthefirewithouthavingtoworryaboutthefireimmediatelyspreadingtotherestofthecraft.Lateron,westartedusinginternalcombustionenginesanthey,too,cancatchfire,sothingslikeautimobilesandprivateaircrafthavefirewallsdesignedintothem.(Infact,the“wall”referredtowhenpeoplesaythatsomethingisrunning“ballstothewall”isthefirewall.Youcontrolasmallaircraft’senginespeedbymovingaball-shapedcontrolcalledthethrottle.Pullingitbacktowardyoureducestheengine’sspeed;pushingtheballforward—“tothefirewall”—increasesenginespeed.)

Basically,then,afirewall’sjobistocontainbadstuff.Butwhereenginefirewallscontainarelativelysmallspacesoastocontainafire,computernetworkfirewallsattempttocontainatrulyhugespacetheIneternet.Firewallsexisttomakeitharderfordirtbagstoattackournetworks.

HowFirewallswork

Firewallisoneoftheosewordsthatsoundssogood—justputoneboxbetweenyournetworkandtheInternet,andyou’resafefromallthebaddies—thatpeopleusethetermtomeanalotofthings.

PORT-FILTERINGFIREWALLS

TheearliestkindoffirewallwasaboxthatsatbetweenaninternalnetworkandtheInternet.Now,ifyouthinkaboutit,whatsortofboxnormallysitsbetweenournetworkandtheInternet?

Probablyarouterand,infact,manyfirewallsarejustrouterswithabitofinterlligenceadded.

Ontheleftyouseetheinternalnetwork(includingPCs,andservers),ontherighttheInternet.InbetweenistheIProuter,whichhasatleasttwointerfaces—theonethatconnectstotheInternet(whichmaybeanEthernetcable,awirelessconnectiong,amodem,anISDNconnection,aDSLconnection,aframerelay,orperhapsacablemodem),andtheonethatconnectstotheinternalnetwork(whichisusuallyanEthernetconnection).Therouterisaverysimplecomputerthatlistenstomessagessenttoiffromeithertheinternalorexternalinterface.

Yes,that’sright—arouterisacomputerrunningaverysimpleprogram,here’showitworks.SupposetheIPaddressesthatyouuseinyournetworkareonesintherangeof200.100.7to200.100.7.254.(Yes,thatisarangeofroutableaddresses.Nonroutableaddressesdidn’tappearintheInternetoriginally;we’llgetthatinaminute.)Herearetheinstructionsthatessentiallycapturearouter’sentireprogram:

●ListentoIPpacketssenttoeithertheinternalorexternalinterface.

●Ifapacketneedstogotoanaddressintherangeof200.100.7.1to200.100.7.254,thenresendthepacketontotheinternalnetwork.

●Ifapacketneedstogoanywherelse,assumethataddressisontheInternet,andresendthepacketontheexternalinterface.

That’sallthereistoit.Sure,routerscanactuallyhandlemorecomplicatedsetsof,“IfIgetamessagedestinedforIPrangeXthenIshouldresenditoninterfaceY,”butmyexampleencapsulatesenoughforourfirewalldiscussion.

Nowlet’smaketheroutherabitsmarter.Supposeyou’vegotsomejerktryingtoconnecttoyourserver—thebigPCinyournetwork—viaTCPport139,oneofthetiesuptheserver,andiftheytryloggingonwithenoughusernamesandpasswords,theymightfigureoutofyouraccounts.(Thisisasimpleexample,soimaginethattherearenoaccountlockouts.)Soyou(somehow)hacktheprograminyourroutherandgiveitanextrarule:

Ifapacketappearsontheexternalinterfacedestinedforanaddressontheinternalnetwork,andifthatpacketisdestinedforTCPport139,justdiscardthepacket;don’ttransmitit

Here,then,isanexampleofaworkingfirewall.Averysimpleone,tobesure,butaworkingfirewall.Becausethefirewall’sprogram(calledthefirewallrulesbymost)decideswhattopassandwhatnottopassbasedonthedestinationport,suchafirewalliscalledaport-filteringfirewall.

Now,inmyexampleIonlyblockedoneport.Butyoumayknowthatintherealworld,peopletendtoconfigureport-filteringrouterswithruleslike“blockallincomingtrafficonallportsexceptforsuch-and-suchportranges.”Additionally,considerthattheonerulethatI’veshownyou—”blockalltrafficdestinedforaninternalIPaddressonTCPport139”—refersonlytoincomingtraffic.Port-filteringfirewallscan,however,usuallyfilteroutgoingtrafficaswell.Forexample,yourfirmmighthavediscoveredatsometimethatemployeeswererunningwebsitesoftheirownthatfeatured,well,contentofquestionablelegalityandtaste,andsoyouwanttokeeppeoplefromrunningwebserversoneverycomputerexceptforyourofficialwebserver.Iftheofficialwebserverhadaddress200.100.7.33,thenyoucouldcreateafirewallrulethatsaid,“IfapacketappearsontheinternalinterfacedestinedforsomeaddressontheInternet,andifthepacketoriginatedfromport80,andifthepacket’ssourcedoesnothavetheIPaddress200.100.7.33,thendiscardit.”You’llsee,however,thatWFdoesnotofferyoutheoptiontoblockoutgoingtraffic,justincomingtraffic.

NATFirewalls

ForalmostanyonewhofirststarteddoingInternetnetworkingafterabout1996,thatexamplemighthaveseemedodd.Putroutableaddressestoeverydesktopmachine?

Crazy,youmightthink.ButthenotionofcreatinganinternalnetworkofIPaddressesintherangeof10.x.x.x,or192.168.x.x,ortherangeofIPaddressesfrom172.16.0.0through172.31.255.255firstappearedinMarch1994withRFC1597,“AddressAllocationforPrivateInternets.”TheideawasthatpeoplemightneedIPaddressestorunaTCP/IP-basednetworkbutmightnotneedaccesstothepublicInternet.Ofcourse,that’snotthecaseformostofus.YouwantlotsofIPaddresses,sothethreerangesof“privatenetworkaddresses”arewidelyused,butyoualsowanttobeabletohavethosenetworkstalktothepublicInternet,whichiswhereMay1994’sRFC1631,“TheIPNetworkAddressTranslator,”fillsthebill.

NATroutershaveatleasttwointerfaces,asdidthesimplerouter,butNATrouterscontainasomewhatmorecomplexroutingprogram.AsingleNATroutermayhaveonlyoneroutableIPaddressonitsexternalinterface,butthatrouter’salsocleverenoughtobeabletoallowallofthose“private”—nonroutable—addressestocarryonconversationswithsystemsontheInternetbysharingthatoneroutableIPaddress.(ThiswascoveredinmoredetailinChapter6ofMasteringWindowsServer2003.)ThetoughestpartofNATroutingisthatnotionthattheroutercancarryonabunchofdifferentconversationsbetweenitsinternalcomputersandvariousserversoutonthepublicInternet.Forexample,supposetensystemsbehindtheNATrouterwerealltalkingtoMicrosoft’swebserver.WhenMicrosoft’swebserverrespondstooneofthetensystems,howdoestheNATrouterknowwhichofitsinternalsystemsthisisdestinedfor?

TheansweristhateverysystemtalkingtoMicrosoft’swebservertalkstothatwebserveronport80,butthewebserverrespondstoeachofthosesystemsondifferentports.So,forexample,ifthewebserverweretorespondtoalltensystemsatthesametime,thentheIPpacketsthatcomprisethoseresponseswouldallspecifyasourceIPaddressofwhateverMicrosoft’swebserveris,andport80.ButwhilethedestinationIPaddresseswouldallbethesame—theroutableIPaddressoftheNATrouter—eachofthemwouldbedestinedforadifferentTCPportnumber.TheNATroutermust,then,keeptrackofthefactthatXmachineontheinsideintranetishavingaconversationwithYmachineontheInternet,andthatconversationusesZportnumber.Thatinformationiscalledthestate,andanyrouterthatkeepstrackofstatesofconversationsissaidtobeastatefulrouter.That’llbeusefullater.

ButhowdoInternetconversationsstartonaNATsystem?

Ineverycase,asystemontheintranetmustinitiatetheconversationbycontactingaserverontheInternet.That’sworthhighlighting:

NOTEInclient-servercommunications,whichisprettymuchtheonlykindofcommunicationswedoontheInternet,theclientstartstheconversationbysendinganunsolicitedrequesttotheserver.We’llreturntothisnotionabitlater,butfornow,rememberthatclientrequestsareseenasu

展开阅读全文
相关资源
猜你喜欢
相关搜索
资源标签

当前位置:首页 > 人文社科 > 法律资料

copyright@ 2008-2023 冰点文库 网站版权所有

经营许可证编号:鄂ICP备19020893号-2