Circuit-level gateway

A firewall or proxy working at the session layer that validates the setup of a connection, then relays its traffic without inspecting the application content inside.

A circuit-level gateway is a type of firewall that works at the session layer, layer 5 of the OSI model. It checks whether a requested connection is permitted, for example by validating the TCP session setup and the addresses involved, and once the session is approved it relays traffic between the two sides without examining what the traffic contains. Because the client connects to the gateway, and the gateway opens the onward connection, internal addresses are hidden from the outside. SOCKS, defined in version 5 by RFC 1928, is a common example.

It sits between the other firewall types candidates are expected to compare. A packet-filtering firewall judges each packet on its header alone. A stateful inspection firewall tracks the state of each connection. An application-level gateway understands the application protocol and can inspect and filter content. The circuit-level gateway knows about sessions but not about applications, so it is fast and protocol-independent, yet it will pass malicious content inside a permitted session. Both gateways are kinds of proxy server.

Exam relevance: a scenario is likely to describe a firewall by the layer it works at or by what it can see. Session setup with no content inspection points to a circuit-level gateway; content filtering for a specific protocol points to an application-level gateway.