- Blocking types of data within a network
- White-list
explicitly specify the "good" traffic
Blocks the rest - Black-lists
Explicity specify the "bad" traffic
Rest allowed
- Intrusion Detection System
A system that moitors traffic and alerts - Intrusion Prevention System
activly denies network traffic
Device Placement
- Stateless filtering
filter traffic based on layer 3 and 4 headers - Stateful filtering tracks the flags of a TCP packet to allow connections leaving the network but block incoming traffic