Showing posts with label Networking. Show all posts
Showing posts with label Networking. Show all posts

Thursday, 12 May 2016

How to Configuring Network Setting For TCP/IP Services

TCP/IP is the protocol of the Internet and the most versatile protocol that Windows NT supports. It can be manually configured or automatically configured using DHCP (Dynamic Host Configuration Protocol). Some applications require TCP/IP (such as Netscape), and it is routable, making it appropriate for networks of any size. To Install TCP/IP Protocol

(a) Click on Start >Settings > Control Panel.
(b) In the Control Panel dialog box double-click Network icon. The Network properties window Appears.
(c) Under the Protocols tab click on Add button to install new protocols.
(d) In the select network protocols list select TCP/IP and then click OK.
(e) The next dialog box prompts you to enter the path for the Windows NT installation files. Type F:\i386 and then click Continue.
(f) Windows will start copying files to the system.
(g) Then TCP/IP Properties dialog box appears, asking you to enter the IP address, subnet mask and default gateway.

(h) You can select the option obtain an IP address automatically, if you have a DHCP server installed in your network.

How to configure the TCP/IP

Configuring TCP/IP.

(a) Double-click on [My Computer]
(b) Double-click [Dial-Up Networking]
(c) A [Dial-Up Networking] window will appear; choose [Ok] to add an entry
(d) Enter "Transmission" for the [Name of the new phonebook entry]
(e) Click [Next]
(f) Check ALL of the following boxes under the [Server] window: [I am calling the Internet] [Send my plain text password] [The non-Windows NT server I am calling expects]
(g) Click [Next]
(h) Enter in the Transmission dial-up number for your area in the [Phone Number] entry field (e.g., 990-0900 - Salt Lake City)
(j) Click [Next]
(k) Select [Point-to-Point Protocol (PPP)] under the [Serial Line Protocol] window, then choose [Next]
(l) Select [None] under the [Logon Script] window, the click [Next]
(m) Under the [IP Address] window leave [My IP address] at “0.0.0.0" (unless Transmission Technical support instructed you to do otherwise), then click [Next]
(n) Under [DNS server] enter "198.60.22.2" and leave [WINS Server] at the  default of "0.0.0.0"
(o) Click [Next], then click [Finish]
(i) Hub to Hub Connectivity.

(ii) Hub to Transceiver or DNI Card Connectivity.

Wednesday, 11 May 2016

How to Setting Dial Up Connection For Access to RAS and Internet step by step

Checking To See If RAS Is Installed
(a) Using the [Start] menu, select [Settings] and choose [Control Panel].
(b) Open [Network].
(c) Choose the [Services] tab.
(d Look to see if [Remote Access Service] is in the [Network Services] box.
Note- If Remote Access is in the [Network Services] box, jump to Part 1.

1. Configuring RAS.
(a) If you do not see [Remote Access Service], select the [Add] button
(b) Scroll down to [Remote Access Service],
(c) Highlight it and Click [Ok]
(d) The next window will ask for your Windows NT disk4. Insert the Windows NT disk, and select [Continue]
(e) A window will ask you to add/choose a [RAS Capable Device]
(f) Select your modem, and click [Ok]
(g) Under the [Remote Access Setup] window, select [Configure]
(h) Under [Port Usage] select [Dial out only], then Click [Ok]
(i) Click [Network], make sure [TCP/IP] is the only protocol selected
(j) Choose [Ok], click [Continue], Note. Windows NT will update your[Bindings Configuration], and then prompt you to reboot your computer. You Must Reboot your computer NOW! Select [Yes] to reboot your computer.

2. Configuring Your Transmission Entry.
(a) Under the [Dial-Up Networking] window, select your "Transmission" entry
(b) Then click [More], and select [Edit entry and modem properties]
(c) Select the [Server] tab, make sure [TCP/IP] is the selected protocol
(d) UNCHECK [Enable software compression] and leave the rest of the settings at default
(e) The [TCP/IP Settings] button
(f) Choose sure to select both :-
(i) [Server assigned IP address]
(ii) [Specify name server addresses]
(g) Check and Edit the following entries:-
(i) [Primary DNS] - "198.60.22.2"
(ii) [Secondary DNS] - "198.60.22.22"
(h) UNCHECK the [Use IP header compression] box
(j) Leave the rest of the settings at default, and click [Ok]
(k) Choose on the [Script] tab and make sure [After Dialing (login)] is set to [None]
(l) Choose the [Security] tab and make sure that [Accept any authentication including clear text] is turned on
(m) Click [Ok] to finish

3. Logging On to Transmission.
(a) Open [My Computer].
(b) Open [Dial-Up Networking].
(c) Highlight the "Transmission" entry and click [Dial].
(d) Enter your username.
(e) Enter your password.
(f) Under the [Domain] entry, make sure the field is left blank! NOTE: If the Domain] field is not blank, you will not be able to connect to Transmission
(g) Click [Connect]NOTE: (Steps 4 & 5) your password is case sensitive, as well as your username, and your username should contain only lower case letters.

4. Disconnecting From Transmission.
(a) Double-click on the Phone Icon (in the lower right hand side of the [Start] bar)

(b) Then click the [Hang Up] button and choose your Transmission connection

How to know MAC Address of PC or Laptop

How to know MAC Address of PC or Laptop

(a) The chances are very good that you'll never see the MAC address for any of your equipment because the software that helps your computer communicate with a network takes care of matching the MAC address to a logical address. The logical address is what the network uses to pass information along to your computer.


(b) If you'd like to see the MAC address and logical address used by the Internet Protocol (IP) for your Windows computer, you can run a small program that Microsoft provides. Go to the "Start" menu, click on "Run," and in the window that appears, type WINIPCFG (IPCONFIG for Windows 2000/XP). When the gray window appears, click on "More Info" and you'll get this sort of information.

Monday, 9 May 2016

Routers And Dial-In-Server

Routers.
(a) The Internet is one of the 20th century's greatest communications developments. It allows people around the world to send e-mail to one another in a matter of seconds, and it lets you read, among other things. We're all used to seeing the various parts of the Internet that come into our homes and offices the Web pages, e-mail messages and downloaded files that make the Internet a dynamic and valuable medium. But none of these parts would ever make it to your computer without a piece of the Internet that you've probably never seen. In fact, most people have never stood "face to machine" with the technology most responsible for allowing the Internet to exist at all: the router.
(b) Routers are specialized computers that send your messages and those of every other Internet user speeding to their destinations along thousands of pathways.

Types of Routers. The router can be categorized on the basis of the configuration of the routing table. The two major types of routers
(a) Static routers. Static routers require an administrator to manually set up and configuration the routing table and to specify each route. This is very difficult and proper record keeping is must for maintenance of the network.
(b) Dynamic routers. Dynamic routers do an automatic discovery of routes and therefore have a minimal amount of set up and configuration. They are more sophisticated in that they examine information from other routers and make packetby- packet decisions about how to send data across the network. Dynamic router uses
dynamic protocol for discovery of the neighboring computers and routers.

 Keeping The Massages Moving.
(a) When you send to a friend on the other side of the country, how does themessage know to end up on your friend's computer, rather than on one of themillions of other computers in the world? Much of the work to get a message fromone computer to another is done by routers, because they're the crucial devices that
let messages flow between networks, rather than within networks.
(b) Let's look at what a very simple router might do. Imagine a small company that makes animated 3-D graphics for local television stations. There are 10 employees of the company, each with a computer. Four of the employees are animators, while the rest are in sales, accounting and management. The animators
will need to send lots of very large files back and forth to one another as they workon projects. To do this, they'll use a network.
(c) When one animator sends a file to another, the very large file will use upmost of the network's capacity, making the network run very slowly for other users.One of the reasons that a single intensive user can affect the entire network stemsfrom the way that Ethernet works. Each information packet sent from a computer is
seen by all the other computers on the local network. Each computer then examinesthe packet and decides whether it was meant for its address. This keeps the basic plan of the network simple, but has performance consequences as the size of thenetwork or level of network activity increases. To keep the animators' work from interfering with that of the folks in the front office, the company sets up two separate networks, one for the animators and one for the rest of the company. A router links the two networks and connects both networks to the Internet
(d) The router is the only device that sees every message sent by any computer on either of the company's networks. When an animator sends a huge file to another animator, the router looks at the recipient's address and keeps the traffic on the animator's network. When an animator, on the other hand, sends a message to the
bookkeeper asking about an expense-account check, then the router sees the recipient's address and forwards the message between the two networks.
(e) One of the tools a router uses to decide where a packet should go is a configuration table. A configuration table is a collection of information, including-
(i) Information on which connections lead to particular groups of  addresses.
(ii) Priorities for connections to be used.
(iii) Rules for handling both routine and special cases of traffic.
(f) A configuration table can be as simple as a half-dozen lines in the smallest routers, but can grow to massive size and complexity in the very large routers thathandle the bulk of Internet messages.
(g) A router, then, has two separate but related jobs-
(i) The router ensures that information doesn't go where it's not needed. This is crucial for keeping large volumes of data from clogging the connections of "innocent bystanders."
(ii) The router makes sure that information does make it to the intended destination.
(h) In performing these two jobs, a router is extremely useful in dealing with two separate computer networks. It joins the two networks, passing information from one to the other and, in some cases, performing translations of various protocols between the two networks. It also protects the networks from one another, preventing the traffic on one from unnecessarily spilling over to the other. As the number of networks attached to one another grows, the configuration table for handling traffic among them grows, and the processing power of the router is increased. Regardless of how many networks are attached, though, the basic operation and function of the router remains the same. Since the Internet is one huge network made up of tens of thousands of smaller networks, its use of routers is an absolute necessity.

Transmitting Packets.
(a) When you make a telephone call to someone on the other side of the country, the telephone system establishes a stable circuit between your telephone and the telephone you're calling. The circuit might involve a half dozen or more steps through copper cables, switches, fiber optics, microwaves and satellites, but those steps are established and remain constant for the duration of the call. This circuit approach means that the quality of the line between you and the person you're calling is consistent throughout the call, but a problem with any portion of the circuit -- maybe a tree falls across one of the lines used, or there's a power problem with a switch -- brings your call to an early and abrupt end. When you send an e-mail message with an attachment to the other side of the country, a very different process is used.
(b) Internet data, whether in the form of a Web page, a downloaded file or an email message, travels over a system known as a packet-switching network.
(c) In this system, the data in a message or file is broken up into packages about 1,500 long. Each of these packages gets a wrapper that includes information on the sender's address, the receiver's address, the package's place in the entire message,and how the receiving computer can be sure that the package arrived intact. Each data package, called a packet, is then sent off to its destination via the best available route -- a route that might be taken by all the other packets in the message or by none of the other packets in the message. This might seem very complicated compared to the circuit approach used by the telephone system, but in a network designed for data there are two huge advantages to the packet-switching plan:-
(i) The network can balance the load across various pieces of equipment on a millisecond-by-millisecond basis.
(ii) If there is a problem with one piece of equipment in the network while a message is being transferred, packets can be routed around the problem, ensuring the delivery of the entire message.
(d) The routers that make up the main part of the Internet can reconfigure the paths that packets take because they look at the information surrounding the data packet, and they tell each other about line conditions, such as delays in receiving and sending data and traffic on various pieces of the network. Not all routers do so
many jobs, however. Routers come in different sizes. For example :-
(i) If you have enabled Internet connection sharing between two Windows98-based computers, you're using one of the computers (the computer with the Internet connection) as a simple router. In this instance, the router does so little -- simply looking at data to see whether it's intended for one computer or the other -that it can operate in the background the system without significantly affecting the other programs you might be running.
(ii) Slightly larger routers, the sort used to connect a small office network to the Internet, will do a bit more. These routers frequently enforce rules concerning security for the office network (trying to secure the network from certain attacks). They handle enough traffic that they're generally stand-alone devices rather than software running on a server.
(iii) The largest routers, those used to handle data at the major traffic points on the Internet, handle millions of data packets every second and work to configure the network most efficiently. These routers are large stand-alone systems that have far more in common with supercomputers than with your office server.
(e) One of the crucial tasks for any router is knowing when a packet of information stays on its local network. For this, it uses a mechanism called a subnet mask.
(f) The subnet mask looks like an IP address and usually reads "255.255.255.0." This tells the router that all messages with the sender and receiver having an address sharing the first three groups of numbers are on the same network, and shouldn't be sent out to another network. Here's an example: The  computer at address 15.57.31.40 sends a request to the computer at 15.57.31.52. The router, which sees all the packets, matches the first three groups in the address of both sender and receiver (15.57.31), and keeps the packet on the local network. (You'll learn more about how the addresses work in the next section.)
(g) Between the time these words left the Howstuffworks.com server and the time they showed up on your monitor, they passed through several routers (it's impossible to know ahead of time exactly how many "several" might be) that helped them along the way. It's very similar to the process that gets a postal letter from your mailbox to the mailbox of a friend, with routers taking the place of the
mail sorters and handlers along the way. 24. Knowing Where To Send Data Routers are one of several types of devices that make up the "plumbing" of a computer network. Hubs, switches and routers all take signals from computers or networks and pass them along to other computers and networks, but a router is the only one of these devices that examines each bundle of data as it passes and makes a decision about exactly where it should go. To make these decisions, routers must first know about two kinds of information: addresses and

 Network structure.
(a) The address has several pieces, each of which helps the people in the postal service move the letter along to your house. The ZIP code can speed the process up; but even without the ZIP code, the card will get to your house as long as your friend includes your state, city and street address. You can think of this address as a logical address because it describes a way someone can get a message to you. This logical address is connected to a physical address that you generally only see when you're buying or selling a piece of property. The survey plat of the land and house, with latitude, longitude or section bearings, gives the legal description, or address, of the property.
(b) Every piece of equipment that connects to a network, whether an office network or the Internet, has a physical address. This is an address that's unique to the piece of equipment that's actually attached to the network cable. For example, if your desktop computer has a network interface card (NIC) in it, the NIC has a
physical address permanently stored in a special memory location. This physical address, which is also called the MAC address ( Media Access Control) has two parts, each 3
(c) The interesting thing is that your computer can have several logical addresses at the same time. Of course, you're used to having several "logical addresses" bring messages to one physical address. Your mailing address, telephone number (or numbers) and home e-mail address all work to bring messages to you when you're in your house. They are simply used for different types of messages -- different networks, so to speak.

(d) Logical addresses for computer networks work in exactly the same way. You may be using the addressing schemes, or protocols, from several different types of networks simultaneously. If you're connected to the Internet (and if you're  reading this, you probably are), then you have an address that's part of the TCP/IP network protocol. If you also have a small network set up to exchange files between several family computers, then you may also be using the Microsoft NetBEUI protocol. If you connect to your company's network from home, then your computer may have an address that follows Novell's IPX/SPX protocol. All of these can coexist on your computer. Since the driver software that allows your computer to communicate with each network uses resources like memory and CPU time, you don't want to load protocols you won't need, but there's no problem with having all the protocols your work requires running at the same time.

Sunday, 24 April 2016

Architecture of MS Exchange Server

1.         Overview
(a)        Sites are logical groupings of one or more Exchange server. Even though resources reside on different server in the site, the site groups all those resources without reference to their locations. This grouping makes using resources in the site very easy. For example, let us say that a certain mailbox physically resides on site server A. that site server is called the mailbox home server. Senders do not need to know the physical location of the mailbox in order to send messages to it. They simply see the mailbox in the site listing, and send it a message. The same principle applies to public folders in a site. The particular server a public folder is stored on is of no concern to the users wanting to access it. They simply see the public folder listed in their site and access it. This is called location transparency. From the user’s perspective a site creates a transparent messaging environment.

(b)        Exchange server comprises the final main structure in the Exchange hierarchy. These computers run the Windows NT server operating system and the Exchange server software. The Exchange servers are the physical location for mailboxes, folders, and other data and information for the site. Individual servers, while inheriting certain configuration parameters from the site (the parent), can also be individually configured. For example, even though recipients can be managed at the site level, they can also be managed at the server they were created on, their home server. All Exchange objects, as well as all related process, are created and managed by the software components that make up the Exchange product.

2.         Exchange Server Core Components.       The Exchange components are executable programs that perform the exchange functions. Some are in the form of EXE files, others are in the form of Dynamic Link Libraries (DLLs). They are referred to as core components because they are necessary for Exchange to be operational. They are also referred to as services, because they run as services on the Microsoft Windows NT server operating system. The core components include the following :-

(a)   Directory Service (DS) 
(b)   Information Store (IS) 
(c)   Message Transfer Agent (MTA) 
(d)   System Attendant (SA)

3.         Exchange Server Additional Components.    The additional components also called as Optional Components. As the name implies, are not necessary for the basic operation of Exchange. But these components could be needed for additional functionality in your Exchange environment. Optional components include the following :-

(a)        Connectors or gateways 
(b)        Outlook Web Access 
(c)        Chat Service 
(d)       Scripting Agent

(e)        Key Management

Friday, 15 April 2016

What is WWW (World Wide Web)?

(a)        WWW or W3 stands for the World Wide Web. The World Wide Web is an  information retrieval system based on a set of inter-linked hypertext documents             residing on HTTP servers all over the world.

            (b)        Hypertext Transfer Protocol (HTTP) is the protocol used on the World Wide Web to transport web pages and the data associated with them. A URL that begins

with httpretrieves a web page specified by the URL. For example, http://www.vispl.com is the World Wide Web address of VISPL.

            (c)        Tim Berners-Lee developed W3 in 1989 for the European Laboratory for   Particle                   Physics (CERN).

(d)       Hypertext words or areas on the screen are expandable, leading to more details about a subject. WWW hypertext documents contain embedded links to information spread throughout the world. As one link is selected and then another and another, a web of interrelated information gets built.
            (e)        The W3 uses Client-Server technology. Web servers distributed throughout the                       Internet, store hypertext documents, which contain links to additional Internet   resources. A             Client program, called a Web browser, downloads Web documents as   well as the codes                  required for accessing any links that appear in the document.

1.         File Transfer Protocol (FTP)              FTP was designed to move files between two computers on a TCP/IP network. IIS supports FTP through Windows Sockets. FTP uses TCP as its transport protocol for all communication and data exchanges between the client and the server. However, IIS communicates with Windows Sockets, and then Windows Sockets interfaces with TCP.

2.         Methods of Communicating on Net                 There are different "types of communication" available to Internet user with Internet account. They are :-
(a)   Electronic Mail (E-mail)
(b)   Newsgroups
(c)   Telnet  

Electronic Mail          It let's you send messages, documents, even voice and video to people, anywhere in the world. Many businesses are finding that E-mail is becoming more important than the Fax for them to stay in contact with their customers.

Newsgroups        They operate as Electronic Message Boards and discussion groups. Although they do not really contain news, newsgroup information on almost any subject.

Telnet          It is an Internet exploration tool that allows your computer to connect to another Network for remote terminal connection. By providing terminal emulation via TCP , it allows a user of one host to log in to a remote host and interact as a normal user there. It is widely used to access databases and explore public access computer systems.

3.         Dial-up Networking
(a)        Dial-up networking is a Win-98 component that allows connecting, to a      network by using modem.
(b)        To Install Dial-Up Networking, follow the steps-

(i)   On your desktop click the Start button; go to Settings and then Control Panel.
    
(ii)   In the Control Panel dialog box, select Add Remove Programs icon.

(aa)     In Add Remove Programs PropertiesDialog Box, choose Windows Setup Tab and then Communications option.

(ab)    Make sure that Dial-Up-Networking option is checked in the Communications box.

(c)   Click Apply to add the Dial-up Component.

4.         World Wide Web      The Internet is a global "Network of Networks". It is a massive collection of Computers that connects millions of Computers, People, Software Programs, Databases and Files

5.         Uses of WWW           Like many Internet tools, the WWW uses Client/Server Architecture Web servers distributed throughout the Internet store Hypertext documents, which contain links to additional Internet resources. A client program, called a Web Browser,  downloading Web documents, as well as the codes required accessing any links that appear in the document.

6.         Advantages of World Wide Web Include

(a)        A link in a Web Document can be used to open other documents.

(b)        Web Pages can contain pictures, buttons and even links to sound files, in addition to text, thus allowing Multimedia applications.

(c)        Sophisticated Web Documents allow the user to interact with the applications        through Dialog Boxes and Forms.

7.       WWW Browsers.

(a)        Web Browsers are Software Packages that display Web page containing Text, Graphics, Audio and Video files and links to various other pages, and makes the connection necessary to follow Hypertext Links.
(b)        The information returned using Browsers can be incorporated document or can be                 saved as files.
(c)        The best browsers have additional features that save time and make it         easier to                navigate and use the resources of the web.

8.       Browsers.

(a)        Graphic Oriented    Graphical browsers display images, as well as text, and offer Hyperlinks to multimedia resources, including sound and video files. For Example- Netscape Navigator , Internet Exp lorer , Mosaic, Eudora.
            (b)        Text-Oriented       Text oriented browsers enables us to follow web            Hypertext               links but do not display non-text web resources. For Example-Linux

9.       Browser plug-Ins.

(a)        Browser is capable of retrieving and displaying information in a variety of text and                  graphic formats. However the Internet’s Web servers may contain a wide      variety of file                   formats that are beyond a browser’s ability to handle. 
            (b)        There are two ways a browser can be modified to handle these diverse file                              formats
(i)   Helper Applications     It works as a distinct application, separate from           the              Browser.

            (ii)   Plug-In Application    Plug-in application actually expands the                                           functionality of the browser software as required to handle a particular file.

Internet


1.         Introduction

(a)        Internet is a worldwide collection of computers, networks and gateways . It consists of millions of computers connected to each other through telephone lines, fiber optics, satellite links or other communication lines. Each of these computers contains information that can be accessed by anybody with the right kind of equipment.

(b)        Once connected to the Net, you become a part of a community of millions who use computers to communicate with one another and share ideas and information.

(c)        Computers use protocols to communicate with one another. At the heart of the Internet are high-speed data Communications lines between major host computers, consisting of thousands of commercial, government, educational, and other computer systems that route data and messages.

(d)       Internet offers a range of benefits to users, such as E-Mail, Downloads,                                       Information, Products, Services and much more.

2.         Browsers

(a)    A browser is a client application used to access the information on the World Wide Web. The browser interprets the markup of files in HTML, formats them into Web Pages and displays them to the user. It also makes the connection necessary to follow Hypertext Links. These links bring you information from Web servers and other types of resources, which may be located anywhere on the Internet.

(b)    Browsers are either Graphical or Text oriented. The Graphical browsers display images, as well as text, and offer Hyperlinks to multimedia resources, including sound and video files.

(c)    The Text oriented browsers like the Lynx enables you to follow web hypertext links but do not display non-text web resources.


(d)    The best browsers have additional features that save time and make it easier to navigate and use the resources of the web. Look for one that is Forms capable and has some timesaving features. The most popular browsers available today are the Netscape Navigator and Microsoft Internet Explorer

Monday, 4 April 2016

How a Proxy Passes Traffic, Stateful inspection, Interfaces & Address Translation

How a Proxy Passes Traffic.

(a)        Unlike its packet-filtering counterparts, a proxy does not route any traffic. In fact, a properly configured proxy will have all routing functionality disabled. As its name implies, the proxy stands in or speaks for each system on each side of the firewall.

(b)       For an analogy, think of two people speaking through a language interpreter. While it is true these two people are carrying on a conversation, they never actually speak to one another.

(c)        All communication passes through the interpreter before being passed on to the other party. The interpreter might have to clean up some of the language used, or filter out comments or statements that might seem hostile. To see how this relates to network communications, refer to Figures.

(d)      Our internal host wishes to request a Web page from the remote server. It formulates the request and transmits the information to the gateway leading to the remote network, which in this case is the proxy server.

(e)        Stateful inspection of an application is unique for each application. Any non-predicted ports used by an application are validated and allowed through the firewall using stateful inspection. The following applications are inspected.

(f)        Connections are not only applied to an ACL, but are logged into a state table.

(g)        After a connection is established, all session data is compared to state table.

(i)         FTP
(ii)        TFTP
(iii)       RCMD
(iv)       SQLNETe.
(v)        VDOLive
(vi)       RealAudio.
(aa)      Connections are not only applied to an ACL, but are logged into a state table.

(ab)      After a connection is established, all session data is compared          to state table.

  Stateful inspection    

(a)        Some protocols are difficult to allow through a firewall securely using traditional filtering mechanisms. In FTP, for example, the control connection is typically created using a known port, but the data connection is over a random port. To allow an FTP data connection through a firewall without leaving a large number of open ports requires stateful inspection: packets are inspected at the application layer to determine which port the data connection is using. Traffic on that port can then be allowed to pass through the firewall for the duration of the FTP session.

(b)        Transport-level state inspection provides a number of ways to make TCP traffic more secure and more difficult for hackers to intercept. Stateful inspection of TCP consists of verifying the consistency of the TCP header as well as preventing
some well-known TCP attacks.

            (c)        Any non-predicted ports used by an application are validated and allowed             through the firewall using stateful inspection. The applications inspected are : FTP,       TFTP, RCMD, SQLNET, VDO Live and Real Audio.


 Interfaces      

(a)        The Secure IP Services Gateway can have many interfaces. Each tunnel (end user or branch office) is a virtual interface, and all gateways have two or more physical interfaces. Packets can be classified by the interface on which they arrive at the source interface or the interface on which they leave the (the destination interface).

(b)        The rules in a policy can be constructed to either use or ignore this classification. If the rule designates “Any” as an interface, the rule ignores this classification. If the rule designates an interface or group of interfaces, the rule uses this classification.

(c)        The rules in any policy can use the following terms to designate an interface:-

(i)         Any                 –          Any physical interface or tunnel.
(ii)        Trusted            –          Any private physical interface or tunnel.
(iii)       Untrusted        –          Any public physical interface.
(iv)       Tunnel             –          Any tunnel.

 Address Translation            When an IP address is converted from one value to another, it is called address translation. This feature has been implemented in most firewall products and is typically used when you do not wish to let remote systems know the true IP address of your internal systems.
Destination IP                         -           206.121.73.5  
Source port                  -          1058
Destination port          -           80

Address translation  
Source IP                    -           192.168.1.50  
Destination IP             -           206.121.73.5  
Sourceport                   -           1037
Destination port          -           80

Sunday, 20 March 2016

Firewall, Components, Purpose and Firewall Technology

Introduction         Firewall is the key equipment used for network parameters security. Function of a firewall is to permit or deny traffic that attempt to pass through it based on specific predefined rules.  Firewalls are similar to other network devices in that their purpose is to control the flow of traffic. Unlike other network devices, however, a firewall must control this traffic while taking into account that not all the packets of data it sees may be what they appear to be. For example, bridge filters traffic based on the destination MAC address.

Definition of a Firewall         If a host incorrectly labels the destination MAC address and the bridge inadvertently passes the packet to the wrong destination, the bridge is not seen as being faulty or inadequate. It is expected that the host will follow certain network rules, and if it fails to follow these rules, then the host is at fault, not the bridge. A firewall, however, must assume that hosts may try to fool it in order to sneak information past it. A firewall cannot use communication rules as a crutch; rather, it should expect that the rules will not be followed. This places a lot of pressure on the firewall design, which must plan for every contingency.

Access control policy      

(a)        An Access Control Policy is simply a corporate policy that states what type of access is allowed across an organization's network parameters. For example, your organization may have a policy that states, "Our internal users can access Internet Web sites and FTP sites or send SMTP mail, but we will only allow inbound SMTP mail from the Internet to our' internal network.

(b)        "An access control policy may also apply to different areas within an internal network. For example, your organization may have WAN links to supporting business partners. In this case, you might want to define a limited scope of access across this link to insure that it is only used for its intended purpose.

(c)        An access control policy simply defines the directions of data flow to and from different parts of the network. It will also specify what type of traffic is acceptable, assuming that all other data types will be blocked. When defining an access control policy, you can use a number of different parameters to describe traffic flow. Some common descriptors that can be implemented with a firewall are listed following.

(d)       A description of acceptable traffic flow based on direction. For example, traffic from the Internet to the internal network (inbound) or traffic from the internal network heading towards the Internet (outbound).       
           
(e)        The type of server application that will be accessed. For example, Web access (HTTP),File Transfer Protocol (FTP),Simple Mail Transfer Protocol (SMTP). Sometimes more granularity is required than simply specifying direction. For example, an organization may wish to allow inbound HTTP access, but to only a specific computer. Conversely, the organization may only have one business unit to which it wishes to grant Internet Web server access.

(f)        Many organizations have a business need to let only certain individuals perform specific activities but do not want to open up this type of .access to everyone. For example, the company CEO may need to be able to access internal resources from the Internet because she does a lot of traveling.        

(g)        In this case, the device enforcing the access control policy would authenticate anyone trying to gain access, to insure that only the CEO can get through. Sometimes an organization may wish to restrict access, but only during certain hours of the day.  For example, an access control policy may state, "Internal users can access Web servers on the Internet only between the hours of 5:00 PM and 7:00 AM. "At times it may be beneficial to use a public network (such as Frame Relay or the Internet) to transmit private data.

(h)        An access control policy may define that one or more types of information should be encrypted as that information passes between two specific hosts or entire network segments. An organization may wish to restrict access based on the amount of available bandwidth. For example, let's assume that an organization has a Web server that is accessible from the Internet and wants to insure that access to this system is always responsive.

(i)         The organization may have an access control policy that allows internal users to access the Internet, but at a restricted level of bandwidth if a potential client is currently accessing the Web server. When the client is done accessing the server, the internal users would have 100 percent of the bandwidth available to access Internet resources.

(j)         An access control policy may define that one or more types of information should be encrypted as that information passes between two specific hosts or entire network segments. An organization may wish to restrict access based on the amount of available bandwidth. For example, let's assume that an organization has a Web server that is accessible from the Internet and wants to insure that access to this system is always responsive.

(k)        The organization may have an access control policy that allows internal users to access the Internet, but at a restricted level of bandwidth if a potential client is currently accessing the Web server. When the client is done accessing the server, the internal users would have 100 percent of the bandwidth available to access Internet resources.

Fire wall Components.

(a)        Operating System Linux ES 3.0
(b)        Checkpoint Software NG AI at 24 Main Nodes loaded on HP Servers
(c)        Cluster XL configured at 24 Main Nodes
(d)       Smart Center Pro at AHQ and Chandimandir
(e)        Smart view Reporter and Monitor at AHQ, New Delhi

Check Point Firewall

(a)        Firewall Clusters at each Main Node
            (b)        Management server at AHQ & Chandimandir

Trend Micro Antivirus

(a)        Office Scan Server
(b)        Server Protect – Win / Linux
(c)        IMSS (Internet Messaging Security Suite)
(d)       IWSS (Internet Web Security Suite)
(e)        TMCM (Trend Micro Control Manager)]

ISS

(a)        Real Secure Server Sensor & Site Protector
(b)        Vulnerability Scanner

Purpose of the Firewalls.  

(a)        The Firewall provides a high level of security, the fastest runtime, and the flexibility to define the rules to fit your environment. The firewall delivers full firewall capabilities, assuring the highest level of network security. To do this, the firewall examines both incoming and outgoing packets running against a common security policy. All service rules are interpreted based on IP conversations (not packets) and are fully stateful. Security rules do not filter packets directly, but the firewall services determine how to process them based on the defined security policy.

(b)        Not all firewalls are built the same. A number of different technologies have been employed in order to control access across a network perimeter. The most popular are .Static packet filtering and dynamic packet filtering.

(c)        Not all firewalls are built the same. A number of different technologies have been employed in order to control access across a network perimeter. The most popular are .Static packet filtering and dynamic packet filtering.

Firewall Technology             .     There are three different types of firewall technologies

            (a)        Packet Filtering         A packet filtering firewall inspects the traffic at        transport layer for the following elements:

(i)         Source IP address
(ii)        Source port
(iii)       Destination IP address
(iv)       Destination port
(v)        Protocol.



            (b)        Proxy

(i)                 Authority to act for another

(ii)               A proxy firewall acts on behalf of hosts on the protected network segments.

(iii)             The protected host never make a connection with the outside world.

            (c)        Stateful Inspection

(i)         Connections are not only applied to an ACL, but are logged into a state     table.

(ii)        After a connection is established, all session data is compared to state table.

8.         Proxies and Additional Firewall Considerations Proxies.

(a)        A proxy server {sometimes referred to as an application gateway or forwarder} is an application that mediates traffic between two network segments. Proxies are often used instead of filtering to prevent traffic from passing directly between networks.

(b)        With the proxy acting as mediator, the source and destination systems never actually "connect" with each other. The proxy plays middleman in all connection attempts.

(c)        Unlike its packet-filtering counterparts, a proxy does not route any traffic. In fact, a properly configured proxy will have all routing functionality disabled. As its name implies, the proxy stands in or speaks for each system on each side of the firewall.

(d)                   For an analogy, think of two people speaking through a language interpreter. While it is true these two people are carrying on a conversation, they never actually speak to one another.

(e)        Unlike its packet-filtering counterparts, a proxy does not route any traffic. In fact, a properly configured proxy will have all routing functionality disabled. As its name implies, the proxy stands in or speaks for each system on each side of the firewall.



(f)        For an analogy, think of two people speaking through a language interpreter. While it is true these two people are carrying on a conversation, they never actually speak to one another.