{"id":150,"date":"2025-12-23T09:48:51","date_gmt":"2025-12-23T09:48:51","guid":{"rendered":"https:\/\/eduardozimbron.com\/blog-c3ntro\/firewall-empresas\/"},"modified":"2026-08-06T00:14:18","modified_gmt":"2026-08-06T00:14:18","slug":"firewall-empresas","status":"publish","type":"post","link":"https:\/\/www.c3ntro.com\/blog\/firewall-empresas","title":{"rendered":"\u00bfQu\u00e9 tan fuerte es realmente un firewall en tu red?"},"content":{"rendered":"<p><span data-contrast=\"auto\">Hoy en d\u00eda,&nbsp;<\/span><strong><span data-contrast=\"auto\">el concepto de &#8216;per\u00edmetro&#8217; ha dejado de ser una l\u00ednea f\u00edsica para convertirse en un ecosistema difuso.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;En esta nueva arquitectura sin muros, la urgencia de blindar cada acceso es m\u00e1xima.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Antiguamente,&nbsp;<\/span><strong><span data-contrast=\"auto\">las empresas eran como castillos:<\/span><\/strong><span data-contrast=\"auto\">&nbsp;<\/span><strong><span data-contrast=\"auto\">todo lo valioso estaba dentro de las murallas<\/span><\/strong><span data-contrast=\"auto\">&nbsp;(la oficina)&nbsp;<\/span><strong><span data-contrast=\"auto\">y todo lo peligroso&nbsp;<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">estaba fuera<\/span><\/strong><span data-contrast=\"auto\">. Hoy, con la adopci\u00f3n masiva de&nbsp;<\/span><a data-uw-rm-kbnav=\"anohref\" href=\"\/soluciones\/cloud\" rel=\"noopener\" target=\"_blank\"><strong><span data-contrast=\"auto\">la nube<\/span><\/strong><\/a><span data-contrast=\"auto\">, el trabajo h\u00edbrido y los dispositivos&nbsp;IoT,<\/span><strong><span data-contrast=\"auto\">&nbsp;las murallas se han expandido y vuelto m\u00e1s porosas.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;Sin embargo, en medio de esta evoluci\u00f3n,&nbsp;<\/span><strong><span data-contrast=\"auto\">una pieza de tecnolog\u00eda se mantiene como la piedra angular inamovible de la <a href=\"\/soluciones\/ciberseguridad\" rel=\"noopener\" target=\"_blank\">ciberseguridad<\/a>: el&nbsp;f<\/span><\/strong><strong><i><span data-contrast=\"auto\">irewall<\/span><\/i><\/strong><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">A menudo,&nbsp;<\/span><strong><span data-contrast=\"auto\">los directivos asumen que tener un&nbsp;Cortafuegos&nbsp;instalado significa estar protegido.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;Esta es una verdad a medias peligrosa. Una barrera de seguridad perimetral&nbsp;mal configurada&nbsp;o desactualizada&nbsp;es tan \u00fatil como una puerta blindada sin cerrojo.&nbsp;<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">La pregunta que todo <a href=\"\/es-mx\/blog\/l\u00edderes-digitales-el-\u00e9xito-empresarial-de-la-transformaci\u00f3n-digital\" rel=\"noopener\" target=\"_blank\">CIO&nbsp;(Chief&nbsp;Information&nbsp;Officer)&nbsp;y responsable de&nbsp;TI<\/a> debe&nbsp;hacerse no es &#8220;\u00bfTenemos un&nbsp;<\/span><\/strong><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><strong><span data-contrast=\"auto\">?&#8221;<\/span><\/strong><span data-contrast=\"auto\">,<\/span><strong><span data-contrast=\"auto\">&nbsp;sino &#8220;\u00bfQu\u00e9 tan inteligente, capaz y gestionado est\u00e1 nuestro firewall?&#8221;.<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Con esta informaci\u00f3n&nbsp;<\/span><strong><span data-contrast=\"auto\">podremos explorar no solo qu\u00e9 es esta barrera tecnol\u00f3gica<\/span><\/strong><span data-contrast=\"auto\">, sino&nbsp;<\/span><strong><span data-contrast=\"auto\">c\u00f3mo funciona<\/span><\/strong><span data-contrast=\"auto\">,&nbsp;<\/span><strong><span data-contrast=\"auto\">por qu\u00e9 ha evolucionado hacia la &#8220;Pr\u00f3xima Generaci\u00f3n<\/span><\/strong><span data-contrast=\"auto\">&#8221; (NGFW) y por qu\u00e9, en&nbsp;<\/span><a data-uw-rm-kbnav=\"anohref\" href=\"\/\" rel=\"noopener\" target=\"_blank\"><strong><span data-contrast=\"auto\">C3ntro Telecom<\/span><\/strong><\/a><span data-contrast=\"auto\">, creemos que<\/span><strong><span data-contrast=\"auto\">&nbsp;la tecnolog\u00eda por s\u00ed sola no basta sin una gesti\u00f3n experta detr\u00e1s.<\/span><\/strong><\/p>\n<p style=\"font-size: 22px;font-weight: bold\">\u00cdndice<\/p>\n<p style=\"font-size: 16px;font-weight: normal\"><span style=\"color: #000000\">1.&nbsp;<\/span><a data-uw-rm-kbnav=\"anohref\" href=\"\/noticias-blog\/#C-1\" rel=\"noopener\"><span style=\"font-size: 16px;color: #000000\"><span style=\"color: #3574e3\">\u00bfC\u00f3mo&nbsp;funciona un&nbsp;firewall? El&nbsp;centinela de la&nbsp;red<\/span><\/span><\/a><\/p>\n<p style=\"font-size: 16px;font-weight: normal\"><span style=\"font-size: 16px;color: #000000\">2.&nbsp;<\/span><span style=\"color: #3574e3\"><a data-uw-rm-kbnav=\"anohref\" href=\"\/noticias-blog\/#T-2\" rel=\"noopener\" style=\"color: #3574e3\">Tipos de&nbsp;firewalls:&nbsp;de lo&nbsp;b\u00e1sico a lo&nbsp;avanzado<\/a><\/span><\/p>\n<p style=\"font-size: 16px;font-weight: normal\"><span style=\"color: #000000\">3.&nbsp;<\/span><span style=\"color: #3574e3\"><a data-uw-rm-kbnav=\"anohref\" href=\"\/noticias-blog\/#I-3\" rel=\"noopener\" style=\"color: #3574e3\"><span style=\"font-size: 16px\">Importancia de que las&nbsp;empresas&nbsp;cuenten con&nbsp;firewall<\/span><\/a><\/span><\/p>\n<p style=\"font-size: 16px;font-weight: normal\"><span style=\"font-size: 16px;color: #000000\">4.&nbsp;<\/span><span style=\"color: #3574e3\"><a data-uw-rm-kbnav=\"anohref\" href=\"\/noticias-blog\/#F-4\" rel=\"noopener\" style=\"color: #3574e3\">Funciones del&nbsp;firewall<\/a><\/span><\/p>\n<p style=\"font-size: 16px;font-weight: normal\"><span style=\"color: #000000\">5.&nbsp;<a data-uw-rm-kbnav=\"anohref\" href=\"\/noticias-blog\/#R-5\" rel=\"noopener\">4 reglas (acciones) del firewall en C3ntro Telecom<\/a><\/span><\/p>\n<p style=\"font-size: 16px;font-weight: normal\"><span style=\"color: #000000\">6.&nbsp;<a data-uw-rm-kbnav=\"anohref\" href=\"\/noticias-blog\/#Q-6\" rel=\"noopener\">\u00bfQu\u00e9 son los&nbsp;protocolos de&nbsp;firewall?<\/a><\/span><\/p>\n<p style=\"font-size: 16px;font-weight: normal\"><span style=\"color: #000000\">7.&nbsp;<a data-uw-rm-kbnav=\"anohref\" href=\"\/noticias-blog\/#L-7\" rel=\"noopener\">La&nbsp;tecnolog\u00eda es el&nbsp;m\u00fasculo, la&nbsp;gesti\u00f3n es el&nbsp;cerebro<\/a><\/span><\/p>\n<p><!--more--><\/p>\n<p><a data-uw-rm-kbnav=\"anohref\" id=\"C-1\" data-hs-anchor=\"true\"><\/a><\/p>\n<h2><span style=\"font-size: 25px;color: #000000\"><strong>1. \u00bfC\u00f3mo&nbsp;funciona un&nbsp;firewall? El&nbsp;centinela de la&nbsp;red<\/strong>&nbsp;<\/span><\/h2>\n<p><span data-contrast=\"auto\">Para entender su funcionamiento,&nbsp;<\/span><strong><span data-contrast=\"auto\">imaginemos un control fronterizo en un aeropuerto internacional de alta seguridad.<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">El&nbsp;<\/span><\/strong><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><strong><span data-contrast=\"auto\">&nbsp;se sit\u00faa en el punto exacto donde tu red <a href=\"\/soluciones\/lan-to-lan\" rel=\"noopener\" target=\"_blank\">privada interna (LAN)<\/a> se conecta con la red p\u00fablica externa (Internet).<\/span><\/strong><span data-contrast=\"auto\">&nbsp;<\/span><strong><span data-contrast=\"auto\">Todo el tr\u00e1fico de datos,&nbsp;<\/span><\/strong><span data-contrast=\"auto\">cada correo electr\u00f3nico, cada archivo descargado, cada solicitud a una p\u00e1gina web,&nbsp;<\/span><strong><span data-contrast=\"auto\">se divide en peque\u00f1os paquetes de informaci\u00f3n.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;El&nbsp;filtro de red&nbsp;act\u00faa&nbsp;como el agente de aduanas que inspecciona cada uno de estos paquetes antes de dejarlo pasar o rechazarlo.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Su funcionamiento&nbsp;<\/span><strong><span data-contrast=\"auto\">se basa en tres niveles de profundidad:<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3><span style=\"font-size: 22px;color: #000000\"><strong>Filtrado de&nbsp;paquetes (el&nbsp;pasaporte)<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">El&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;revisa la informaci\u00f3n b\u00e1sica del encabezado del paquete: \u00bfDe d\u00f3nde viene (IP origen)? \u00bfA d\u00f3nde va (IP destino)? \u00bfQu\u00e9 protocolo usa? Si las reglas dicen que no se admiten visitas de cierta regi\u00f3n, el paquete se bloquea.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3><span style=\"font-size: 22px;color: #000000\"><strong>Inspecci\u00f3n de&nbsp;estado (la&nbsp;memoria)<\/strong><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\"><\/span><\/h3>\n<p><span data-contrast=\"auto\">Los&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewalls<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;modernos recuerdan las conversaciones. Si t\u00fa iniciaste una solicitud a Google, el&nbsp;sistema de control de tr\u00e1fico de red&nbsp;recordar\u00e1 que la respuesta de Google es esperada y leg\u00edtima, dej\u00e1ndola pasar. Si Google intentara contactarte sin que t\u00fa lo pidieras,&nbsp;el&nbsp;<\/span><strong><span data-contrast=\"auto\">Gateway<\/span><\/strong><span data-contrast=\"auto\">&nbsp;de seguridad&nbsp;lo bloquear\u00eda.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Inspecci\u00f3n Profunda de Paquetes &#8211; DPI (el&nbsp;equipaje)<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">Aqu\u00ed es donde entran los Firewalls de Pr\u00f3xima Generaci\u00f3n (NGFW). No solo miran el encabezado, sino que &#8220;abren la maleta&#8221; para ver el contenido. Buscan patrones de virus,&nbsp;<\/span><i><span data-contrast=\"auto\">malware<\/span><\/i><span data-contrast=\"auto\">&nbsp;oculto o intentos de exfiltraci\u00f3n de datos sensibles dentro de aplicaciones aparentemente inofensivas.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\"><img decoding=\"async\" src=\"https:\/\/5505410.fs1.hubspotusercontent-na1.net\/hubfs\/5505410\/diagrama-seguridad-perimetral.webp\" width=\"500\" height=\"715\" loading=\"lazy\" alt=\"\u00bfQu\u00e9 es y para qu\u00e9 sirve un Firewall? \" style=\"height: auto;max-width: 100%;width: 500px;margin-left: auto;margin-right: auto;display: block\"><\/span><\/p>\n<hr>\n<p><a data-uw-rm-kbnav=\"anohref\" id=\"T-2\" data-hs-anchor=\"true\"><\/a><\/p>\n<h2 style=\"font-size: 25px\"><span style=\"color: #000000\"><strong>2. Tipos de&nbsp;firewalls:&nbsp;de lo&nbsp;b\u00e1sico a lo&nbsp;avanzado<\/strong>&nbsp;<\/span><\/h2>\n<p><span data-contrast=\"auto\">La tecnolog\u00eda de seguridad&nbsp;<\/span><strong><span data-contrast=\"auto\">ha tenido que evolucionar para mantenerse al d\u00eda con los atacantes.<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Firewall de filtrado de paquetes (Stateless)<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">La versi\u00f3n m\u00e1s antigua. Solo mira direcciones y puertos. Son r\u00e1pidos, pero ciegos al contexto y f\u00e1ciles de enga\u00f1ar hoy en d\u00eda.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Firewall de inspecci\u00f3n de estado (Stateful&nbsp;Inspection)<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">El est\u00e1ndar de la industria durante a\u00f1os. Monitorea el estado completo de las conexiones de red activas. Es m\u00e1s seguro que el filtrado de paquetes, pero a\u00fan limitado en visibilidad de aplicaciones.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Firewall de&nbsp;Pr\u00f3xima&nbsp;Generaci\u00f3n<\/strong><strong>&nbsp;(NGFW)<\/strong>&nbsp;<\/span><\/h3>\n<p><strong><span data-contrast=\"auto\">La especialidad de C3ntro Telecom.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;Estos dispositivos combinan las funciones tradicionales con sistemas de prevenci\u00f3n de intrusiones (IPS), inspecci\u00f3n profunda de paquetes (DPI), control de aplicaciones (capa 7) y, a menudo, inteligencia de amenazas en&nbsp;<\/span><strong><span data-contrast=\"auto\">la nube<\/span><\/strong><span data-contrast=\"auto\">. Pueden distinguir entre tr\u00e1fico leg\u00edtimo de Facebook y un juego dentro de Facebook que contiene&nbsp;<\/span><i><span data-contrast=\"auto\">malware<\/span><\/i><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>WAF (Web&nbsp;Application&nbsp;Firewall)<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">Dise\u00f1ado espec\u00edficamente para proteger servidores web y aplicaciones contra ataques como inyecciones&nbsp;<\/span><i><span data-contrast=\"auto\">SQL o Cross-Site Scripting (XSS)<\/span><\/i><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Firewall como&nbsp;Servicio&nbsp;(FWaaS)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">En la era de&nbsp;<\/span><strong><span data-contrast=\"auto\">la nube<\/span><\/strong><span data-contrast=\"auto\">,&nbsp;muchas empresas optan por no tener la caja f\u00edsica, sino contratar la seguridad perimetral alojada en la nube, ideal para conectar sucursales mediante&nbsp;<\/span><strong><span data-contrast=\"auto\"><a data-uw-rm-kbnav=\"anohref\" href=\"\/soluciones\/sd-wan\" rel=\"noopener\" target=\"_blank\">SD-WAN<\/a>.<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<hr>\n<p><a data-uw-rm-kbnav=\"anohref\" id=\"I-3\" data-hs-anchor=\"true\"><\/a><\/p>\n<h2><span style=\"font-size: 25px;color: #000000\"><strong>3. Importancia de que las&nbsp;empresas&nbsp;cuenten con&nbsp;firewall<\/strong>&nbsp;<\/span><\/h2>\n<p><strong><span data-contrast=\"auto\">Operar sin un&nbsp;<\/span><\/strong><strong><i><span data-contrast=\"auto\">firewall perimetral<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;robusto en la actualidad&nbsp;<\/span><strong><span data-contrast=\"auto\">es una negligencia empresarial.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;La importancia&nbsp;<\/span><strong><span data-contrast=\"auto\">radica en cuatro pilares cr\u00edticos<\/span><\/strong><span data-contrast=\"auto\">:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Continuidad del&nbsp;negocio<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">Un ataque de Denegaci\u00f3n de Servicio (DDoS) o una infecci\u00f3n de&nbsp;<\/span><strong><span data-contrast=\"auto\">Ransomware<\/span><\/strong><span data-contrast=\"auto\">&nbsp;puede paralizar las operaciones durante d\u00edas. El&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewall&nbsp;<\/span><\/i><\/strong><span data-contrast=\"auto\">es la primera l\u00ednea de defensa para mantener las luces encendidas.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3><span style=\"font-size: 22px;color: #000000\"><strong>Cumplimiento&nbsp;normativo (compliance)<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">Leyes como la LFPDPPP en M\u00e9xico o est\u00e1ndares como PCI-DSS (para tarjetas de cr\u00e9dito) exigen expl\u00edcitamente barreras de seguridad perimetral. No tenerlas implica multas millonarias.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Protecci\u00f3n de la&nbsp;propiedad&nbsp;intelectual<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">Los competidores desleales y hackers patrocinados por estados buscan robar secretos industriales. El&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;impide la salida no autorizada de esta informaci\u00f3n.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Control de&nbsp;productividad<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">M\u00e1s all\u00e1 de la seguridad, permite a las empresas gestionar el ancho de banda, priorizando aplicaciones cr\u00edticas (como el ERP o CRM) y limitando el uso de sitios de ocio (<\/span><i><span data-contrast=\"auto\">streaming<\/span><\/i><span data-contrast=\"auto\">, redes sociales) que saturan la red.<\/span><span style=\"font-weight: bold\"><\/span><\/p>\n<hr>\n<p><a data-uw-rm-kbnav=\"anohref\" id=\"F-4\" data-hs-anchor=\"true\"><\/a><\/p>\n<h2 style=\"font-size: 25px\"><span style=\"color: #000000\"><strong>4. Funciones del&nbsp;firewall<\/strong>&nbsp;<\/span><\/h2>\n<p><span data-contrast=\"auto\">Un NGFW moderno es una navaja suiza de seguridad.&nbsp;<\/span><strong><span data-contrast=\"auto\">Sus funciones van mucho m\u00e1s all\u00e1 de &#8220;bloquear y permitir&#8221;:<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>NAT (Traducci\u00f3n de Direcciones de Red)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">Oculta las direcciones IP reales de los dispositivos internos, presentando una \u00fanica IP p\u00fablica al exterior, lo que dificulta que los atacantes mapeen tu red interna.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>VPN (Red Privada Virtual)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">Permite crear t\u00faneles encriptados para que los empleados remotos se conecten a la oficina de forma segura, como si estuvieran sentados en su escritorio.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Prevenci\u00f3n de Intrusiones (IPS)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">Detecta y bloquea ataques basados en comportamientos an\u00f3malos o firmas conocidas de&nbsp;exploits&nbsp;en tiempo real.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Filtrado de&nbsp;contenido&nbsp;web<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">Categoriza millones de sitios web y permite bloquear el acceso a categor\u00edas peligrosas (pornograf\u00eda, hacking, apuestas) o inapropiadas para el trabajo.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Sandboxing<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">Env\u00eda archivos sospechosos a un entorno aislado en la nube para &#8220;detonarlos&#8221; y observar su comportamiento antes de dejarlos entrar a la red.<\/span><\/p>\n<hr>\n<p><a data-uw-rm-kbnav=\"anohref\" id=\"R-5\" data-hs-anchor=\"true\"><\/a><\/p>\n<h2 style=\"font-size: 25px\"><span style=\"color: #000000\"><strong>5. 4 reglas (acciones) del firewall en C3ntro Telecom<\/strong>&nbsp;<\/span><\/h2>\n<p><span data-contrast=\"auto\">Cuando los ingenieros de&nbsp;<\/span><a data-uw-rm-kbnav=\"anohref\" href=\"\/\" rel=\"noopener\" target=\"_blank\"><strong><span data-contrast=\"auto\">C3ntro Telecom<\/span><\/strong><\/a><span data-contrast=\"auto\">&nbsp;<\/span><strong><span data-contrast=\"auto\">configuran las pol\u00edticas de un&nbsp;<\/span><\/strong><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><strong><span data-contrast=\"auto\">, se basan en la l\u00f3gica de reglas.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;<\/span><strong><span data-contrast=\"auto\">Aunque las pol\u00edticas pueden ser miles<\/span><\/strong><span data-contrast=\"auto\">, todas&nbsp;<\/span><strong><span data-contrast=\"auto\">se reducen a cuatro acciones fundamentales que determinan el destino de un paquete de datos:<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h2 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Allow&nbsp;(Permitir)<\/strong><\/span><\/h2>\n<p><span data-contrast=\"auto\">Es la luz verde. El tr\u00e1fico cumple con los criterios de seguridad definidos (IP origen confiable, puerto correcto, aplicaci\u00f3n segura) y se le permite cruzar el per\u00edmetro hacia su destino.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Drop&nbsp;(Descartar\/denegar&nbsp;silenciosamente)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">Es la acci\u00f3n de seguridad m\u00e1s com\u00fan para el tr\u00e1fico no deseado. El&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;bloquea el paquete y lo &#8220;tira a la basura&#8221; sin notificar al remitente. Esto es estrat\u00e9gico: al no enviar respuesta, el atacante no sabe si el firewall existe o si la direcci\u00f3n IP est\u00e1 vac\u00eda, dificultando su reconocimiento.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Reject&nbsp;(Rechazar)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">El&nbsp;filtro de red<\/span><strong><i><span data-contrast=\"auto\">&nbsp;<\/span><\/i><\/strong><span data-contrast=\"auto\">bloquea el&nbsp;paquete,&nbsp;pero env\u00eda una respuesta de error al remitente (generalmente un mensaje&nbsp;ICMP&nbsp;\u201cProtocolo de Mensajes de Control de Internet\u201d, por sus siglas en ingl\u00e9s). Se usa raramente hacia internet (para no dar pistas a hackers), pero es \u00fatil en redes internas para que las aplicaciones no se queden &#8220;colgadas&#8221; esperando respuesta y sepan inmediatamente que el acceso est\u00e1 prohibido.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Log (Registrar)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">T\u00e9cnicamente es una acci\u00f3n complementaria.&nbsp;Independientemente de si se permite o bloquea, el firewall debe&nbsp;<\/span><i><span data-contrast=\"auto\">registrar<\/span><\/i><span data-contrast=\"auto\">&nbsp;el evento. Sin logs, no hay visibilidad, no hay an\u00e1lisis forense y no hay mejora continua. Un firewall que no registra es un guardia que no escribe reportes.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">Existe una &#8220;Regla de&nbsp;oro&#8221; impl\u00edcita en la configuraci\u00f3n profesional:<\/span><\/strong><span data-contrast=\"auto\">&nbsp;<\/span><strong><span data-contrast=\"auto\">&#8220;<em>Deny&nbsp;All<\/em>&#8221; (Denegar todo por defecto).<\/span><\/strong><span data-contrast=\"auto\">&nbsp;Al final de la lista de reglas, siempre debe haber una instrucci\u00f3n que bloquee cualquier cosa que no haya sido expl\u00edcitamente permitida.<\/span><\/p>\n<hr>\n<p><a data-uw-rm-kbnav=\"anohref\" id=\"Q-6\" data-hs-anchor=\"true\"><\/a><\/p>\n<h2 style=\"font-size: 25px\"><span style=\"color: #000000\"><strong>6. \u00bfQu\u00e9 son los&nbsp;protocolos de&nbsp;firewall?<\/strong>&nbsp;<\/span><\/h2>\n<p><span data-contrast=\"auto\">El&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;<\/span><strong><span data-contrast=\"auto\">no lee &#8220;espa\u00f1ol&#8221; o &#8220;ingl\u00e9s&#8221;, lee protocolos de comunicaci\u00f3n.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;Entender estos lenguajes es vital para configurar la seguridad:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>TCP (Transmission&nbsp;Control&nbsp;Protocol)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">Es&nbsp;el protocolo orientado a conexi\u00f3n. Antes de enviar datos, establece un &#8220;saludo&#8221; (handshake) de tres v\u00edas. Los&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewalls<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;aman TCP porque es f\u00e1cil rastrear el estado de la conexi\u00f3n (qui\u00e9n empez\u00f3, qu\u00e9 sigue). Es el protocolo usado para la web (HTTP\/HTTPS),&nbsp;correo y&nbsp;transferencia de archivos.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>UDP (User&nbsp;Datagram&nbsp;Protocol)<\/strong><\/span><\/h3>\n<p><span data-contrast=\"auto\">Es un protocolo &#8220;sin conexi\u00f3n&#8221;. Env\u00eda datos sin verificar si llegaron. Se usa para&nbsp;<\/span><i><span data-contrast=\"auto\">streaming<\/span><\/i><span data-contrast=\"auto\">&nbsp;de video, voz sobre IP (VoIP)&nbsp;y juegos en l\u00ednea, donde la velocidad importa m\u00e1s que la precisi\u00f3n.&nbsp;Los&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewalls<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;deben ser m\u00e1s inteligentes aqu\u00ed,&nbsp;usando tiempos de espera (timeouts) para decidir cu\u00e1ndo cerrar la &#8220;puerta&#8221; de esa conexi\u00f3n.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>ICMP&nbsp;(<\/strong><strong>Internet Control&nbsp;Message&nbsp;Protocol<\/strong><strong>)<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">Usado para diagn\u00f3sticos (como el comando&nbsp;<\/span><i><span data-contrast=\"auto\">ping<\/span><\/i><span data-contrast=\"auto\">). Aunque \u00fatil, es peligroso. Los atacantes&nbsp;usan&nbsp;<\/span><span data-contrast=\"auto\">ICMP&nbsp;(Protocolo de Mensajes de Control de Internet)&nbsp;para descubrir qu\u00e9 dispositivos est\u00e1n vivos en tu red. Un buen&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><span data-contrast=\"auto\">&nbsp;generalmente&nbsp;bloquea&nbsp;un&nbsp;protocolo de diagn\u00f3stico de red&nbsp;entrante desde internet.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 style=\"font-size: 22px\"><span style=\"color: #000000\"><strong>Protocolos de&nbsp;capa de&nbsp;aplicaci\u00f3n (<a href=\"\/es-mx\/blog\/que-hacer-ante-ciberataque\" rel=\"noopener\" target=\"_blank\">Layer&nbsp;7<\/a>)<\/strong>&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\">Los&nbsp;<\/span><strong><i><span data-contrast=\"auto\">firewalls<\/span><\/i><\/strong><strong><i><span data-contrast=\"auto\">&nbsp;<\/span><\/i><\/strong><span data-contrast=\"auto\">modernos entienden protocolos espec\u00edficos como DNS, SMTP, FTP y HTTP. Saben c\u00f3mo debe lucir una conversaci\u00f3n normal en estos lenguajes y pueden detectar si alguien est\u00e1 usando, por ejemplo, el protocolo DNS para colar datos robados (<\/span><i><span data-contrast=\"auto\">DNS&nbsp;Tunneling<\/span><\/i><span data-contrast=\"auto\">).<\/span><\/p>\n<hr>\n<p><a data-uw-rm-kbnav=\"anohref\" id=\"L-7\" data-hs-anchor=\"true\"><\/a><\/p>\n<h2 style=\"font-size: 25px\"><span style=\"color: #000000\"><strong>7. La&nbsp;tecnolog\u00eda es el&nbsp;m\u00fasculo, la&nbsp;gesti\u00f3n es el&nbsp;cerebro<\/strong>&nbsp;<\/span><\/h2>\n<p><span data-contrast=\"auto\">Hemos recorrido el&nbsp;<\/span><strong><span data-contrast=\"auto\">funcionamiento t\u00e9cnico<\/span><\/strong><span style=\"font-weight: bold\">, los&nbsp;tipos&nbsp;y las&nbsp;<\/span><strong><span data-contrast=\"auto\">reglas de un&nbsp;<\/span><\/strong><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><span data-contrast=\"auto\">. Ha quedado claro que&nbsp;<\/span><strong><span data-contrast=\"auto\">la seguridad perimetral es compleja y din\u00e1mica.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;Aqu\u00ed reside&nbsp;<\/span><strong><span data-contrast=\"auto\">el problema principal de muchas empresas: compran el&nbsp;escudo de protecci\u00f3n digital&nbsp;m\u00e1s costoso del mercado, lo conectan y lo olvidan.<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">Un&nbsp;<\/span><\/strong><strong><i><span data-contrast=\"auto\">firewall<\/span><\/i><\/strong><strong><span data-contrast=\"auto\">&nbsp;sin gesti\u00f3n es una entidad que se degrada con el tiempo<\/span><\/strong><span data-contrast=\"auto\">. Las amenazas cambian a diario, y las reglas que eran seguras hace un mes pueden ser vulnerables hoy.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">En&nbsp;<\/span><strong><span data-contrast=\"auto\">C3ntro Telecom<\/span><\/strong><span data-contrast=\"auto\">,&nbsp;<\/span><strong><span data-contrast=\"auto\">entendemos que la seguridad perimetral no es un producto, es un proceso.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;A trav\u00e9s de nuestras soluciones de&nbsp;<\/span><strong><span data-contrast=\"auto\">Seguridad Administrada<\/span><\/strong><span data-contrast=\"auto\">, no solo te proveemos la tecnolog\u00eda de Pr\u00f3xima Generaci\u00f3n (NGFW) de l\u00edderes mundiales; te brindamos el cerebro operativo.&nbsp;<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Nuestro&nbsp;<\/span><a data-uw-rm-kbnav=\"anohref\" href=\"\/es-mx\/blog\/soc\" rel=\"noopener\" target=\"_blank\"><strong><span data-contrast=\"auto\">Centro de Operaciones de Seguridad (SOC)<\/span><\/strong><\/a><span data-contrast=\"auto\">&nbsp;<\/span><strong><span data-contrast=\"auto\">monitorea tu per\u00edmetro 24\/7<\/span><\/strong><span data-contrast=\"auto\">, ajustando reglas, aplicando parches de seguridad y respondiendo a alertas antes de que se conviertan en incidentes.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">No dejes la puerta de tu empresa sin vigilancia.<\/span><\/strong><span data-contrast=\"auto\">&nbsp;Fortalece tu per\u00edmetro con la combinaci\u00f3n perfecta de tecnolog\u00eda avanzada y experiencia humana.&nbsp;<\/span><strong><span data-contrast=\"auto\">Cont\u00e1ctanos y descubre qu\u00e9 tan fuerte puede ser realmente tu seguridad.<\/span><\/strong><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p>{{cta(&#8216;eedea985-06f0-4f3a-9c85-6d9eafcd0430&#8242;,&#8217;justifycenter&#8217;)}}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Protege la red de tu empresa con seguridad perimetral avanzada. Descubre c\u00f3mo los firewalls gestionados de C3ntro Telecom te blindan ante ciberamenazas.<\/p>\n","protected":false},"author":2,"featured_media":866,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,1],"tags":[],"class_list":["post-150","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ciberseguridad","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/posts\/150","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/comments?post=150"}],"version-history":[{"count":1,"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/posts\/150\/revisions"}],"predecessor-version":[{"id":950,"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/posts\/150\/revisions\/950"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/media\/866"}],"wp:attachment":[{"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/media?parent=150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/categories?post=150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.c3ntro.com\/blog\/wp-json\/wp\/v2\/tags?post=150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}