Operation Manual - Getting Started
H3C SecPath F1800-A Firewall
The stateful firewall can capture packets at network layer. Then the firewall
extracts the state information needed by security policy from application layer,
and saves it in the dynamic state tables. Finally it analyzes the state tables and
the subsequent connection request related to the data packet to make a proper
decision.
For the external network, the stateful firewall seems to act as a proxy system because
any external service request comes from the same host.
For the internal network, the stateful firewall seems to act as a packet filtering system
because internal users feel that they directly interwork with the external network.
The stateful firewall has the following advantages:
High speed
They can record the connection state of packets while performing ACL check on the
initial packets. ACL check is not required for the subsequent packets. Thus, the
firewall only needs to check the connection record of the packet based on the state
table. After passing the check, the connection state records will be refreshed. In this
case, packets with the same connection state are no longer repeatedly checked.
Different from fixed arrangement of ACL, the records in the connection state table can
be arranged randomly. Thus, the firewall can fast search the records using such
algorithms as binary tree or hash, so as to improve the transmission efficiency of the
system.
Reliable security
The connection state list is managed dynamically. After completing sessions, the
temporary return packet entry created on the firewall will be closed, so as to ensure
the security of internal networks. Meanwhile, in virtue of a realtime connection state
monitoring technology, the firewall can identify the connection state based on state
factors in the state table. Thus, the system security is enhanced.
1.3 Overview of the SecPath F1800-A
1.3.1 SecPath F1800-A
The SecPath F1800-A of Huawei-3Com is enhanced stateful firewall.
Combined with the Huawei-3Com ASPF technology, it is featured in:
High security of the proxy firewall
High speed of the stateful firewall
The SecPath F1800-A of Huawei-3Com adopt:
Specially designed and highly reliable hardware system
Dedicated operating system with independent intellectual property right
It is integrated with:
1-7
Chapter 1 Firewall Overview
Need help?
Do you have a question about the H3C SecPath F1800-A and is the answer not in the manual?