An application layer gateway (ALG) is a
feature on ScreenOS gateways that enables the gateway to parse application
layer payloads and take decisions on them. Although there are other ScreenOS
features, such as deep inspection, in which the gateway inspects traffic at the
application layer, ALGs are typically employed to support applications that use
the application layer payload to communicate the dynamic Transmission Control
Protocol (TCP) or User Datagram Protocol (UDP) ports on which the applications
open data connections. Such applications include the File Transfer Protocol
(FTP) and various IP telephony protocols. The dynamic TCP, UDP, or other ports
that are opened by the ScreenOS gateway to permit these data or secondary
channels are referred to as pinholes, and are active strictly for the duration of
activity on the data channel.
0 comments:
Post a Comment