13 Networking Services - Firewalling
242
/ 362
3EC 17766 AAAA TCZZA Ed. 01
13.5 Firewalling and NAPT
NAT (Network Address Translation), is the translation of an IP
address used within one network to another IP address, known
within another network.
NAPT (Network Address and Port Translation) uses a combination
of IP addressing and port number mapping to create unique
combinations. That way, the
STWireless
can determine which
packet, sourced by the WAN, is destined to which device on your
local (W)LAN, and vice versa, without revealing the internal device
information towards the remote side.
The position of the
Input, NAPT, Forward
and
Output
logical
processing modules in the overall
STWireless
Firewall model is
relative to the traffic direction. In contrast, the
STWireless
's WAN
and (W)LAN interfaces are physical" interfaces; their position is
not relative to the traffic direction.
The NAPT module is situated between the Forward and Output
hook (See
STWireless
Firewall model). Since the traffic direction
will determine input, and output, the NAPT module can always be
positioned between the Forward and Output module.
If you set rules on a hook, you should know if the packets that
pass through that hook contain IP addresses that are
NAPTĆtranslated or not.
If rules are set on the Output hook and NAPT is active, the IP
packets that pass that hook will contain
translated
IP addresses. If
you want to avoid certain traffic, by setting rules that filter on
certain (ranges of) IP addresses, you should be aware of the
location where the rule will be verified, since, depending on the
hook, another IP address will be seen by the Firewall.
As a conclusion: if NAPT is activated, the IP address that identifies
a local device, will be different depending on the direction of the
traffic.
Summary of Contents for Speed Touch Wireless
Page 1: ......
Page 8: ...Contents 3EC 17766 AAAA TCZZA Ed 01 8 362...
Page 12: ...12 362 3EC 17766 AAAA TCZZA Ed 01...
Page 26: ...1 Speed Touch Wireless Quick Guide 26 362 3EC 17766 AAAA TCZZA Ed 01...
Page 27: ...27 362 3EC 17766 AAAA TCZZA Ed 01 Speed Touch Wireless Wiring Guide...
Page 28: ...28 362 3EC 17766 AAAA TCZZA Ed 01...
Page 34: ...2 Wiring Guide ADSL Power and Console 34 362 3EC 17766 AAAA TCZZA Ed 01...
Page 45: ...45 362 3EC 17766 AAAA TCZZA Ed 01 Speed Touch Wireless Data Services...
Page 46: ...46 362 3EC 17766 AAAA TCZZA Ed 01...
Page 58: ...4 Data Services Packet Services 58 362 3EC 17766 AAAA TCZZA Ed 01...
Page 88: ...6 Data Services MAC Encapsulated Routing 88 362 3EC 17766 AAAA TCZZA Ed 01...
Page 122: ...7 Data Services PPPoA to PPTP Relaying 122 362 3EC 17766 AAAA TCZZA Ed 01...
Page 148: ...8 Data Services PPP IP Routing 148 362 3EC 17766 AAAA TCZZA Ed 01...
Page 175: ...175 362 3EC 17766 AAAA TCZZA Ed 01 Speed Touch Wireless Networking Services...
Page 176: ...176 362 3EC 17766 AAAA TCZZA Ed 01...
Page 192: ...10 Networking Services ATM 192 362 3EC 17766 AAAA TCZZA Ed 01...
Page 231: ...12 Networking Services DNS 231 362 3EC 17766 AAAA TCZZA Ed 01...
Page 247: ...247 362 3EC 17766 AAAA TCZZA Ed 01 Speed Touch Wireless Wireless LAN Services...
Page 248: ...248 362 3EC 17766 AAAA TCZZA Ed 01...
Page 253: ...253 362 3EC 17766 AAAA TCZZA Ed 01 Speed Touch Wireless Maintenance...
Page 254: ...254 362 3EC 17766 AAAA TCZZA Ed 01...
Page 262: ...15 Maintenance Software Upgrade 262 362 3EC 17766 AAAA TCZZA Ed 01...
Page 266: ...16 Maintenance Speed Touch Wireless Security 266 362 3EC 17766 AAAA TCZZA Ed 01...
Page 284: ...18 Maintenance Speed Touch Wireless Web Interface 284 362 3EC 17766 AAAA TCZZA Ed 01...
Page 297: ...297 362 3EC 17766 AAAA TCZZA Ed 01 Speed Touch Wireless Appendices...
Page 298: ...298 362 3EC 17766 AAAA TCZZA Ed 01...
Page 352: ...AppendixF Hardware Reference 352 362 3EC 17766 AAAA TCZZA Ed 01...
Page 362: ...AppendixH Safety and Agency Regulatory Notices 362 362 3EC 17766 AAAA TCZZA Ed 01...