
Chapter 2
■ Pass the service through the firewall: Using what are typically
called “plugs,” most application gateway firewalls allow services
to be passed directly through the firewall with only minimal
packet filtering. This can limit some of the vulnerability but can
result in compromising the security of systems behind the firewall.
2
Low risk
When an inbound Internet service not supported by a proxy is
required to pass through the firewall, the firewall administrator
should define the configuration or plug that will allow the required
service. When a proxy is available from the firewall vendor, the plug
must be disabled and the proxy made operative. ...