The Experts below are selected from a list of 15 Experts worldwide ranked by ideXlab platform

Tan Zhiyuan - One of the best experts on this subject based on the ideXlab platform.

  • An improvement of tree-Rule Firewall for a large network: supporting large rule size and low delay
    IEEE Computer Society, 2016
    Co-Authors: Chomsiri Thawatchai, He Xiangjian, Nanda Priyadarsi, Tan Zhiyuan
    Abstract:

    Firewalls are important network devices which provide first hand defense against network threat. This level of defense is depended on Firewall rules. Traditional Firewalls, i.e., Cisco ACL, IPTABLES, Check Point and Juniper Netscreen Firewall use listed rule to regulate packet flows. However, the listed rules may lead to rule conflictions which make the Firewall to be less secure or even slowdown in performance. Based on our previous research works, we proposed the Tree-Rule Firewall which does not encounter such rule conflicts within its rule set and operates faster than the traditional Firewalls. However, in big or complex networks, the Tree-Rule Firewall still may face two main problems. 1. Firewall administrators may face difficulty to write big and complex rule. 2. Difficulty to select appropriate attribute column for the Root node. In this paper, we propose an improved model for the Tree-Rule Firewall by extending our previous models. We offer the use of combination between IN and OUT interfaces of the Firewall to separate a big rule to many small independent rules. Each separated rule then can be managed in an individual screen. Sequence of verifying attributes, i.e., Source IP, Destination IP and Destination Port numbers, can be ordered independently in each separated rule. We implement the two main schemes on Linux Cent OS 6.3. We found that the improved Tree-Rule Firewall can be managed easily with low processing delay

Tan Z - One of the best experts on this subject based on the ideXlab platform.

  • An improvement of tree-rule Firewall for a large network: Supporting large rule size and low delay
    'Institute of Electrical and Electronics Engineers (IEEE)', 2016
    Co-Authors: Chomsiri T, He X, Nanda P, Tan Z
    Abstract:

    © 2016 IEEE. Firewalls are important network devices which provide first hand defense against network threat. This level of defense is depended on Firewall rules. Traditional Firewalls, i.e., Cisco ACL, IPTABLES, Check Point and Juniper Netscreen Firewall use listed rule to regulate packet flows. However, the listed rules may lead to rule conflictions which make the Firewall to be less secure or even slowdown in performance. Based on our previous research works, we proposed the Tree-Rule Firewall which does not encounter such rule conflicts within its rule set and operates faster than the traditional Firewalls. However, in big or complex networks, the Tree-Rule Firewall still may face two main problems. 1. Firewall administrators may face difficulty to write big and complex rule. 2. Difficulty to select appropriate attribute column for the Root node. In this paper, we propose an improved model for the Tree-Rule Firewall by extending our previous models. We offer the use of combination between IN and OUT interfaces of the Firewall to separate a big rule to many small independent rules. Each separated rule then can be managed in an individual screen. Sequence of verifying attributes, i.e., Source IP, Destination IP and Destination Port numbers, can be ordered independently in each separated rule. We implement the two main schemes on Linux Cent OS 6.3. We found that the improved Tree-Rule Firewall can be managed easily with low processing delay

Chomsiri Thawatchai - One of the best experts on this subject based on the ideXlab platform.

  • An improvement of tree-Rule Firewall for a large network: supporting large rule size and low delay
    IEEE Computer Society, 2016
    Co-Authors: Chomsiri Thawatchai, He Xiangjian, Nanda Priyadarsi, Tan Zhiyuan
    Abstract:

    Firewalls are important network devices which provide first hand defense against network threat. This level of defense is depended on Firewall rules. Traditional Firewalls, i.e., Cisco ACL, IPTABLES, Check Point and Juniper Netscreen Firewall use listed rule to regulate packet flows. However, the listed rules may lead to rule conflictions which make the Firewall to be less secure or even slowdown in performance. Based on our previous research works, we proposed the Tree-Rule Firewall which does not encounter such rule conflicts within its rule set and operates faster than the traditional Firewalls. However, in big or complex networks, the Tree-Rule Firewall still may face two main problems. 1. Firewall administrators may face difficulty to write big and complex rule. 2. Difficulty to select appropriate attribute column for the Root node. In this paper, we propose an improved model for the Tree-Rule Firewall by extending our previous models. We offer the use of combination between IN and OUT interfaces of the Firewall to separate a big rule to many small independent rules. Each separated rule then can be managed in an individual screen. Sequence of verifying attributes, i.e., Source IP, Destination IP and Destination Port numbers, can be ordered independently in each separated rule. We implement the two main schemes on Linux Cent OS 6.3. We found that the improved Tree-Rule Firewall can be managed easily with low processing delay

Chomsiri T - One of the best experts on this subject based on the ideXlab platform.

  • An improvement of tree-rule Firewall for a large network: Supporting large rule size and low delay
    'Institute of Electrical and Electronics Engineers (IEEE)', 2016
    Co-Authors: Chomsiri T, He X, Nanda P, Tan Z
    Abstract:

    © 2016 IEEE. Firewalls are important network devices which provide first hand defense against network threat. This level of defense is depended on Firewall rules. Traditional Firewalls, i.e., Cisco ACL, IPTABLES, Check Point and Juniper Netscreen Firewall use listed rule to regulate packet flows. However, the listed rules may lead to rule conflictions which make the Firewall to be less secure or even slowdown in performance. Based on our previous research works, we proposed the Tree-Rule Firewall which does not encounter such rule conflicts within its rule set and operates faster than the traditional Firewalls. However, in big or complex networks, the Tree-Rule Firewall still may face two main problems. 1. Firewall administrators may face difficulty to write big and complex rule. 2. Difficulty to select appropriate attribute column for the Root node. In this paper, we propose an improved model for the Tree-Rule Firewall by extending our previous models. We offer the use of combination between IN and OUT interfaces of the Firewall to separate a big rule to many small independent rules. Each separated rule then can be managed in an individual screen. Sequence of verifying attributes, i.e., Source IP, Destination IP and Destination Port numbers, can be ordered independently in each separated rule. We implement the two main schemes on Linux Cent OS 6.3. We found that the improved Tree-Rule Firewall can be managed easily with low processing delay

Kenneth Tam - One of the best experts on this subject based on the ideXlab platform.

  • Troubleshooting the Netscreen Firewall
    Configuring NetScreen Firewalls, 2005
    Co-Authors: Rob Cameron, Christopher Cantrell, Dave Killion, Kevin Russell, Kenneth Tam
    Abstract:

    This chapter describes various ways to troubleshoot network traffic passing through the Netscreen Firewall. The chapter discusses the path a packet makes as it goes through the Firewall, various tools at disposal, and tips for troubleshooting different functions available through ScreenOS. There are several troubleshooting tools built into ScreenOS. Ping allows the testing of connectivity. Traceroute allows it to find the path a packet takes through a network. The get commands on the command-line interface (CLI) show the internal tables in memory. ScreenOS also has a complete debugging system that allows it to view what happens to a packet as it goes through the Firewall step by step. Snoop allows it to view the entire content of the packets that transverse the Firewall. Troubleshooting virtual private networks (VPNs) requires configuration settings to agree on both ends of the VPN. Most VPN issues are due to a misconfiguration of the VPN settings on one end of the tunnel. The outgoing interface of the VPN tunnel must be set in order for the VPN to work properly. Netscreen Redundancy Protocol (NSRP) is the Netscreen method of high availability. The heartbeat interval of the cluster can be tweaked to improve failover performance. Netscreen Firewalls support traffic prioritization. When troubleshooting traffic shaping, the guaranteed bandwidth of the policy should not exceed the maximum bandwidth of the outgoing interface.

  • Dissecting the Netscreen Firewall
    Configuring NetScreen Firewalls, 2005
    Co-Authors: Rob Cameron, Christopher Cantrell, Dave Killion, Kevin Russell, Kenneth Tam
    Abstract:

    This chapter takes a look at the various components that compose a Netscreen Firewall. The Netscreen security product line contains an various security products. The chapter describes the core technologies that make up the Netscreen Firewall product line. Zones are a core part of the Netscreen Firewall. They allow the administrator to divide networks into logical separations. This allows the simplification of the policy creation process by clearly allowing or denying access to different network segments based upon their applied zones. Netscreen bends the idea of a Firewall with the use of virtual routers. Virtual routers allow the separation of all of the routing domains into separate logical entities. This enables a Firewall to employ the Firewall as a true router without compromising security. The Netscreen Firewall product again bends the traditional look of a Firewall by acting as a transparent device in the network, providing full Firewalling features. Thus, the Netscreen Firewall product line provides a complete selection of Firewalling products that can cover any company's needs. Each product is tailored to provide exactly what is needed for almost every possible solution for an enterprises Firewall needs. The Netscreen Security Manager (NSM) product brings all of the Firewalls together to be managed under one single solution. It provides all of the various solutions to centrally manage the Firewall products.