It's more likely that you'll need a router between your firewall and the Internet. In this location, a router can
screen out an Internet stream's obvious "junk traffic" before it reaches the firewall. You can use the router to apply broad firewall rules across the enterprise. For example, if you don't allow any SSH traffic through the firewall, you can drop all inbound port 22 traffic at the router, letting the firewall focus on arbitrating tougher decisions.
Some firewalls do act as proxy servers, but only if they are specifically designed as Layer 7, or application-layer firewalls. Consider the case where an internal user wishes to access an external Web site. The proxy firewall transparently inserts itself into the conversation, completing the three-way handshake with the end user, determining whether the traffic is allowed, and then completing a separate three-way handshake with the destination system.
Dig deeper on Network Firewalls, Routers and Switches
Related Q&A from Mike Chapple, Enterprise Compliance
Should companies obtain U.S. security clearance to join the Enhanced Cybersecurity Services program? Mike Chapple offers his perspective.continue reading
Does a Web application security assessment termed 'compliance ready' seem too good to be true? Learn its role in an enterprise compliance program.continue reading
Learn how hiring the right PCI DSS-compliant service providers, especially payment services providers, can reduce your compliance burden.continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.