Current location - Quotes Website - Collection of slogans - The difference between gateway and firewall
The difference between gateway and firewall
The difference between gateway and firewall

1, application scenario difference

The application scenarios of gateway and firewall are different.

Firewall: There are already firewalls in the network to consider security issues, but the connectivity of the network must be ensured first, and then the security issues.

Gateway: Gateway exchanges data on the basis of ensuring security. The gateway is that two networks already exist. Now the two networks need to be interconnected, and the interconnection must be secure. Gateway is the only product with the safest network boundary security isolation. Only this product can solve this problem, so it must be used.

2. Hardware differences

Firewall is a single host architecture. Packet filtering technology was used in the early days. The gateway is a dual-host 2+ 1 architecture, and exchanges data through a private protocol ferry. Based on the session detection mechanism, because the gateway is a dual-host architecture, even if the external network is breached, there is no way to attack the internal network because of the internal use of private protocols. Firewall is a single host architecture. If it is attacked, the intranet will be completely exposed to others.

3. Functional differences

Gateway mainly includes two functions: access function and synchronization function. Access function is similar to firewall, and gateway is more secure than firewall.

(1) access class function

Agent mode:

At present, proxy mode is considered to be the safest mode, but firewall does not support proxy mode, and gateway does, so firewall cannot be used for security isolation of confidential and non-confidential networks, and gateway can.

(2) Synchronization function

File synchronization and database synchronization:

The working principle of firewall is that it is placed in the middle of the network, and the source side initiates access and the destination side accesses. When the firewall receives the verdict, I will give it to you. I took the initiative to grab the working principle of gateway and put it on the other side. There are file or database servers at both ends. In this process, the terminal does not know the existence of the gateway, because there is no open port, which is more secure. The port of the firewall is open to the outside world.