<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regarding Packet Filtering Firewal using Router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037117#M878819</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All the router is doing is looking at the layer 4 TCP segment and checking if the destination port is 80 (HTTP). Its not going into the higher layers and inspecting the nitty gritty details of the HTTP protocol itself e.g. URL/host/encoding/content-type etc. You have to remember that the OSI model is merely a 'logical' model. Don't think too hard about it :). I would highly recommend to read the Doughlas Comer TCP/IP Book. It would help you build these basic concepts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Dec 2008 06:36:10 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-12-16T06:36:10Z</dc:date>
    <item>
      <title>Regarding Packet Filtering Firewal using Router</title>
      <link>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037112#M878808</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One small query--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read somewhere that Routers are packet Filtering Firewalls(which can process the traffic at Layer-3 and Layer-4)but when we configure access-lists in routers ,then we can even mention the upper layer protocols(http,ftp) in the access-lists,then how the router will process the packets of upper layer protocols if router is acting as Packet filtering firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037112#M878808</guid>
      <dc:creator>palsukh2002</dc:creator>
      <dc:date>2019-03-11T14:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding Packet Filtering Firewal using Router</title>
      <link>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037113#M878810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco routes have multiple solutions to provide access control. The following is their list:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Access-lists (Stateless Packet Filter)&lt;/P&gt;&lt;P&gt;easier to fool/spoof/compromise&lt;/P&gt;&lt;P&gt;very difficult to manage&lt;/P&gt;&lt;P&gt;stateless except some features like 'established' keyword that provide pseudo-stateful behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Reflexive ACLs (Stateful Filter without Application Inspection/Handling)&lt;/P&gt;&lt;P&gt;pretty easy to implement&lt;/P&gt;&lt;P&gt;less control on what to filter&lt;/P&gt;&lt;P&gt;break for most dynamic applications like multimedia,active ftp etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) CBAC (Stateful filter - Now called the classic firewall)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Zone-based Firewall (Stateful filter with enhanced zoning support)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per your question, even ACLs have limited viisbility into upper layer protocols now. But that is limited. As technologies grow, the line between stateful/stateless starts to blur a little bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2008 06:39:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037113#M878810</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-12-15T06:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding Packet Filtering Firewal using Router</title>
      <link>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037114#M878812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It means  we cannot say that Routers are packet filtering Firewalls.&lt;/P&gt;&lt;P&gt;Because if we are allowing http access from some source to destination in the router access-list,the access will be permitted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My actual doubt was why we are calling Routers as packet filetering firewalls&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for confusing-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2008 07:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037114#M878812</guid>
      <dc:creator>palsukh2002</dc:creator>
      <dc:date>2008-12-15T07:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding Packet Filtering Firewal using Router</title>
      <link>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037115#M878814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We can definitely say routers (can act as) packet filtering firewalls. This is exactly what access-lists do. Please see the following link for a definition of packet-filtering firewalls:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://en.wikipedia.org/wiki/Firewall" target="_blank"&gt;http://en.wikipedia.org/wiki/Firewall&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2008 09:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037115#M878814</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-12-15T09:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding Packet Filtering Firewal using Router</title>
      <link>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037116#M878816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is confusing---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a router access-list we can type&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test permit host 10.1.1.1 host 20.1.1.1 http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which will allow http access which is an Application layer protocol.It means the router can open the whole packet till application layer and can see that http access is needed.Then how we are saying Routers are Packet filtering firewalls(the packet filtering firewalls can see the information of Layer-3 and layer-4 proocols only) &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2008 23:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037116#M878816</guid>
      <dc:creator>palsukh2002</dc:creator>
      <dc:date>2008-12-15T23:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding Packet Filtering Firewal using Router</title>
      <link>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037117#M878819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All the router is doing is looking at the layer 4 TCP segment and checking if the destination port is 80 (HTTP). Its not going into the higher layers and inspecting the nitty gritty details of the HTTP protocol itself e.g. URL/host/encoding/content-type etc. You have to remember that the OSI model is merely a 'logical' model. Don't think too hard about it :). I would highly recommend to read the Doughlas Comer TCP/IP Book. It would help you build these basic concepts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Dec 2008 06:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-packet-filtering-firewal-using-router/m-p/1037117#M878819</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-12-16T06:36:10Z</dc:date>
    </item>
  </channel>
</rss>

