Tech Support > Computer Hardware > Routers > Is Cisco PIX Application level firewall or Packet level firewall?
Is Cisco PIX Application level firewall or Packet level firewall?
Posted by Learning Cisco on October 14th, 2005


I have a very basic question. Is cisco PIX an Application level
firewall or Packet level firewall?

Posted by Chris on October 14th, 2005



"Learning Cisco" <learningcisco@rediffmail.com> wrote in message
news:1129313718.731240.211800@g49g2000cwa.googlegr oups.com...
It's a Stateful Inspection firewall.

Chris.



Posted by coin on October 14th, 2005


Packet firewall

Posted by Walter Roberson on October 15th, 2005


In article <1129329784.242111.63930@g44g2000cwa.googlegroups. com>,
coin <ncointepoix@gmail.com> wrote, without providing any context

:Packet firewall

The question was whether the PIX was an application level firewall or
a packet firewall.

The answer is that it runs at layer 5 or so -- a protocol level firewall.
Most of what it does, it handles at layer 4, but there are some things
it handles at layer 5, such as SMTP inspection, FTP port handling,
and URL inspection. For SMTP and HTTP, it reassembles packets to prevent
attacks from slipping by by splitting them between packets. For SMTP,
it filters the complete layer 5 conversation, permitting only those
commands that are on its internal allowed list.

PIX 6.x has no anti-virus, and does not attempt to do anything like
validate SQL queries against an authorization schema.

--
Okay, buzzwords only. Two syllables, tops. -- Laurie Anderson