From Managing Cisco Network Security


A firewall is a security mechanism located on a network that protects resources from other networks and individuals. A firewall controls access to a network and enforces a security policy that can be tailored to suit the needs of a company.

There is some confusion on the difference between a Cisco PIX firewall and a router. Both devices are capable of filtering traffic with access control lists, and both devices are capable of providing Network Address Translation (NAT). PIX, however, goes above and beyond simply filtering packets, based on source/destination IP addresses, as well as source/destination TCP/UDP port numbers. PIX is a dedicated hardware device built to provide security. Although a router can also provide some of the functions of a PIX by implementing access control lists, it also has to deal with routing packets from one network to another. Depending on what model of router is being used, access lists tend to burden the CPU, especially if there are numerous access lists that must be referenced for every packet that travels through the router. This can impact the performance of the router, causing other problems such as network convergence time.

Cisco Systems offers a number of security solutions for networks, including Cisco Secure PIX Firewall series. The PIX firewall is a dedicated hardware-based firewall that utilizes a version of the Cisco IOS for configuration and operation. This chapter will introduce and discuss security features, Network Address Translation (NAT), Network Address Port Translation (NAPT, or referred to as PAT...

Copyright Syngress Publishing, Inc. 2000 under license agreement with Books24x7

