X3200
User’s Guide
303
Access Security
7
ported via the interface to the WAN partner that would be routed over the same
interface on the back route. You can therefore prevent packets with fake IP ad-
dresses being fed to your LAN – even without filters. This means you can easily
prevent known and as yet unknown Denial-of-Service and IP spoofing attacks.
To do
Proceed as follows to activate Back Route Verification for a WAN partner:
➤
Go to
WAN P
ARTNER
➧
E
DIT
➧
IP
➧
A
DVANCED
S
ETTINGS
.
➤
Activate Back Route Verify with
on.
➤
Confirm with OK.
7.2.11
TAF Agent
Personalized
authentication
The Token Authentication Firewall (TAF) function permits personal authentica-
tion of IP connection partners. BinTec’s solution integrates the Token Authenti-
cation mechanisms from Security Dynamics and does not allow data packets to
cross the router until the associated source address has been authenticated
successfully.
You can enable this function on BinTec’s corporate access routers and config-
ure the router as TAF agent. A detailed description of operation and the neces-
sary configuration steps are contained in BRICKware for Windows.
7.2.12
Extended IP Routing (XIPR)
In addition to the normal routing table,
X3200
can also make routing decisions
based on an additional table called the Extended Routing Table (Extended IP
Routing). Apart from the destination address,
X3200
can also include the pro-
tocol, source and destination port, type of service (TOS) and the status of the
destination interface in the decision. If there are entries in the Extended Routing
Table, these are treated preferentially compared with entries in the normal rout-
ing table.
Example
XIPR is useful, for example, if two networks are connected via ISDN with a LAN-
LAN connection, but certain services (e.g. telnet) should be routed over an X.25
link and not over an ISDN switched connection. By making entries in the Ex-
tended Routing Table, you can allow part of the IP traffic to run over the ISDN
Summary of Contents for X3200
Page 4: ...4 BinTec Communications AG...
Page 28: ...28 BinTec Communications AG Welcome 1...
Page 258: ...258 BinTec Communications AG Advanced Configuration 6...
Page 348: ...348 BinTec Communications AG Technical Data 10...
Page 369: ...X3200 User s Guide 369 12 BinTec Communications AG...
Page 393: ...X3200 User s Guide 393 12...
Page 394: ...394 BinTec Communications AG General Safety Precautions in 15 Different Languages 12...
Page 412: ...412 BinTec Communications AG Glossary...
Page 419: ...X3200 User s Guide 419 Index WINS 210 229 X X 31 TEI 182...