AST570 Firewall and
NAPT
17 Security Services - Firewalling
224
/ 300
3EC 17766 AAAA TCZZA Ed. 04
17.5 Firewalling and NAPT
The position of the
Input, Static NA(P)T, Dynamic NA(P)T, Forward
and
Output
logical processing modules in the overall
AST570
Firewall model is relative to the traffic direction. In contrast, the
AST570
' WAN and (W)LAN interfaces are physical interfaces;
their position is not relative to the traffic direction.
The Dynamic NA(P)T module is situated between the Forward and
Output hook (See
AST570
Firewall model). Since the traffic
direction will determine input, and output, the Dynamic NA(P)T
module can always be positioned between the Forward and
Output module.
If you set rules on a hook, you should know if the packets that
pass through that hook contain IP addresses that are
NA(P)Ttranslated or not.
If rules are set on the Output hook and NA(P)T is active, the IP
packets that pass that hook will contain
translated
IP addresses.
If you want to avoid certain traffic, by setting rules that filter on
certain (ranges of) IP addresses, you should be aware of the
location where the rule will be verified, since, depending on the
hook, another IP address will be seen by the Firewall.
As a conclusion: if NA(P)T is activated, the IP address that
identifies a local device, will be different depending on the
direction of the traffic.
Summary of Contents for AST570
Page 1: ...3EC 17766 AAAA TCZZA Ed 04 SPEED TOUCH 570 User s Guide...
Page 10: ...10 300 3EC 17766 AAAA TCZZA Ed 04...
Page 25: ...25 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Wiring Guide...
Page 26: ...26 300 3EC 17766 AAAA TCZZA Ed 04...
Page 37: ...37 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 WLAN Guide...
Page 38: ...38 300 3EC 17766 AAAA TCZZA Ed 04...
Page 54: ...4 WLAN Guide Wireless LAN 54 300 3EC 17766 AAAA TCZZA Ed 04...
Page 55: ...55 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Configuration and Use...
Page 56: ...56 300 3EC 17766 AAAA TCZZA Ed 04...
Page 92: ...9 Configuration and Use Routed PPPoE 92 300 3EC 17766 AAAA TCZZA Ed 04...
Page 128: ...11 Configuration and Use Routed PPPoA 128 300 3EC 17766 AAAA TCZZA Ed 04...
Page 147: ...147 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Networking...
Page 148: ...148 300 3EC 17766 AAAA TCZZA Ed 04...
Page 196: ...14 Networking Services IP 196 300 3EC 17766 AAAA TCZZA Ed 04...
Page 203: ...203 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Security...
Page 204: ...204 300 3EC 17766 AAAA TCZZA Ed 04...
Page 229: ...229 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Maintenance...
Page 230: ...230 300 3EC 17766 AAAA TCZZA Ed 04...
Page 238: ...18 Maintenance Speed Touch Software 238 300 3EC 17766 AAAA TCZZA Ed 04...
Page 256: ...21 Maintenance Speed Touch Web Interface 256 300 3EC 17766 AAAA TCZZA Ed 04...
Page 266: ...22 Maintenance Speed Touch CLI 266 300 3EC 17766 AAAA TCZZA Ed 04...
Page 267: ...267 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Appendices...
Page 268: ...268 300 3EC 17766 AAAA TCZZA Ed 04...
Page 272: ...Abbreviations 272 300 3EC 17766 AAAA TCZZA Ed 04...
Page 292: ...AppendixE Speed Touch Default Assignments 292 300 3EC 17766 AAAA TCZZA Ed 04...