Example 2: Firewall
configuration with
NA(P)T
More information
17 Security Services - Firewalling
228
/ 300
3EC 17766 AAAA TCZZA Ed. 04
Dynamic NA(P)T is applied for this DSL connection; all outgoing
Net10" IP addressed packets are translated into the
192.6.11.10 IP address. So the complete local (W)LAN is
presented towards the remote side as the single IP address
192.6.11.10.
In the following table, the rules to apply are summarized:
Flow Source
Dest.
Prot. Source
port
Dest.
port
ACK
=1
Action
Out
10.0.0.0/8
200.20.20.1 TCP
1024
65535
23
-
accept
In
200.20.20.1 192.6.11.10 TCP
23
1024
65535
Yes
accept
Any
External
Internal
Any
Any
Any
-
drop
For the
AST570
Firewall, this will result in the following CLI
configuration:
1.
A chain must be created, e.g. 'Telnet':
firewall chain create chain=Telnet
2.
Following rules must be created for that chain:
For the outgoing Telnet service packets:
firewall rule create chain=Telnet src=10.0.0.0/8
dst=200.20.20.1 srcintfgrp=lan prot=tcp
srcport=1024 srcportend=65535 dstport=23
action=accept
For incoming Telnet service reply packets:
firewall rule create chain=Telnet src=200.20.20.1
dst=192.6.11.10 srcintfgrp=wan prot=tcp srcport=23
dstport=1024 dstportend=65535 ack=yes
action=accept
For blocking all other services:
firewall rule create chain=Telnet action=drop
3.
The chain 'Telnet' must be assigned to the
input
hook:
firewall assign hook=input chain=Telnet
See chapter 22 for more information on
AST570
' Firewall CLI
configuration.
Summary of Contents for AST570
Page 1: ...3EC 17766 AAAA TCZZA Ed 04 SPEED TOUCH 570 User s Guide...
Page 10: ...10 300 3EC 17766 AAAA TCZZA Ed 04...
Page 25: ...25 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Wiring Guide...
Page 26: ...26 300 3EC 17766 AAAA TCZZA Ed 04...
Page 37: ...37 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 WLAN Guide...
Page 38: ...38 300 3EC 17766 AAAA TCZZA Ed 04...
Page 54: ...4 WLAN Guide Wireless LAN 54 300 3EC 17766 AAAA TCZZA Ed 04...
Page 55: ...55 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Configuration and Use...
Page 56: ...56 300 3EC 17766 AAAA TCZZA Ed 04...
Page 92: ...9 Configuration and Use Routed PPPoE 92 300 3EC 17766 AAAA TCZZA Ed 04...
Page 128: ...11 Configuration and Use Routed PPPoA 128 300 3EC 17766 AAAA TCZZA Ed 04...
Page 147: ...147 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Networking...
Page 148: ...148 300 3EC 17766 AAAA TCZZA Ed 04...
Page 196: ...14 Networking Services IP 196 300 3EC 17766 AAAA TCZZA Ed 04...
Page 203: ...203 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Security...
Page 204: ...204 300 3EC 17766 AAAA TCZZA Ed 04...
Page 229: ...229 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Maintenance...
Page 230: ...230 300 3EC 17766 AAAA TCZZA Ed 04...
Page 238: ...18 Maintenance Speed Touch Software 238 300 3EC 17766 AAAA TCZZA Ed 04...
Page 256: ...21 Maintenance Speed Touch Web Interface 256 300 3EC 17766 AAAA TCZZA Ed 04...
Page 266: ...22 Maintenance Speed Touch CLI 266 300 3EC 17766 AAAA TCZZA Ed 04...
Page 267: ...267 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Appendices...
Page 268: ...268 300 3EC 17766 AAAA TCZZA Ed 04...
Page 272: ...Abbreviations 272 300 3EC 17766 AAAA TCZZA Ed 04...
Page 292: ...AppendixE Speed Touch Default Assignments 292 300 3EC 17766 AAAA TCZZA Ed 04...