翻訳と辞書
Words near each other
・ Egrek
・ EGREM
・ Egremni
・ Egremont
・ Egremont (UK Parliament constituency)
・ Egremont Castle
・ Egremont Rangers
・ Egremont Russet
・ Egremont, Alberta
・ Egremont, Cumbria
・ Egremont, Massachusetts
・ Egremont, Merseyside
・ Egremont, Mississippi
・ Egrespatak
・ Egress
Egress filtering
・ Egress Peak
・ Egress router
・ Egress Software
・ Egressive case
・ Egressive sound
・ Egressy
・ Egret
・ Egret-class sloop
・ Egretta
・ Egreš
・ Egreșu River
・ Egri
・ Egri Bikavér
・ Egri Bughaz


Dictionary Lists
翻訳と辞書 辞書検索 [ 開発暫定版 ]
スポンサード リンク

Egress filtering : ウィキペディア英語版
Egress filtering
In computer networking, egress filtering is the practice of monitoring and potentially restricting the flow of information outbound from one network to another. Typically it is information from a private TCP/IP computer network to the Internet that is controlled.
TCP/IP packets that are being sent out of the internal network are examined via a router, firewall, or similar edge device. Packets that do not meet security policies are not allowed to leave - they are denied "egress".〔Robert Gezelter (1995) ''Security on the Internet'' Chapter 23 in Hutt, Bosworth, and Hoytt (1995) "Computer Security Handbook, Third Edition", Wiley, section 23.6(b), pp 23-12, et seq.〕
Egress filtering helps ensure that unauthorized or malicious traffic never leaves the internal network.
In a corporate network, typical recommendations are that all traffic except that emerging from a select set of servers would be denied egress. Restrictions can further be made such that only select protocols such as HTTP, email, and DNS are allowed. User workstations would then need to be configured either manually or via proxy auto-config to use one of the allowed servers as a proxy.
Corporate networks also typically have a limited number of internal address blocks in use. An edge device at the boundary between the internal corporate network and external networks (such as the Internet) is used to perform egress checks against packets leaving the internal network, verifying that the source IP address in all outbound packets is within the range of allocated internal address blocks.
Egress filtering may require policy changes and administrative work whenever a new application requires external network access. For this reason egress filtering is an uncommon feature on consumer and very small business networks.
PCI DSS, requires egress filtering from any server in the card holder environment. This is seen in PCI-DSS v3.0, requirements 1.3.3.
==See also==

* Content-control software
* Ingress filtering
* Web Proxy Autodiscovery Protocol

抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)
ウィキペディアで「Egress filtering」の詳細全文を読む



スポンサード リンク
翻訳と辞書 : 翻訳のためのインターネットリソース

Copyright(C) kotoba.ne.jp 1997-2016. All Rights Reserved.