X4000
User’s Guide
335
Access Security
10
➤
Repeat these steps to define several entries for the selected NAT interface.
10.2.8
Filters (Access Lists)
IP filters (
➤➤
Access Lists
) in
X4000
are based on a concept of
➤➤
filters
,
rules and so-called chains. IP filters respond to incoming data packets, which
means they can allow or deny access to
X4000
for certain data.
Filters
A filter describes a certain part of the IP data traffic based on the source and/or
destination IP address,
➤➤
netmask
, protocol and source and/or destination
port. If you define a filter, you are telling
X4000
: "Watch out for all data packets
that match the following: ...".
Rule
You use a rule to tell
X4000
what to do with the data packets it has filtered out,
i.e. whether or not it should allow them to pass through. You can also define
several rules, which you arrange in the form of a chain to obtain a certain
sequence.
Chain
There are various approaches for the definition of rules and rule chains:
■
Allow all packets that are not explicitly prohibited, i.e.:
–
Deny all packets that match Filter 1.
–
Deny all packets that match Filter 2.
–
...
–
...
–
Allow the rest.
■
Allow only what is explicitly permitted, i.e.:
–
Allow all packets that match Filter 1.
–
Allow all packets that match Filter 2.
–
...
–
...
–
Deny the rest.
■
Combination of the two possibilities described above
Several rule chains can be created, either completely or partly separated
from each other. The common use of filters is possible and practicable.
Interface
You can also define a rule chain individually for each
X4000
interface.
Summary of Contents for X4000
Page 4: ...4 X4000 User s Guide...
Page 6: ...6 X4000 User s Guide Table of Contents...
Page 14: ...14 X4000 User s Guide Table of Contents...
Page 30: ...30 X4000 User s Guide Welcome 1...
Page 34: ...34 X4000 User s Guide General Safety Precautions 2...
Page 68: ...68 X4000 User s Guide Hardware Description and Installation 3...
Page 92: ...92 X4000 User s Guide Configuration Requirements 4...
Page 118: ...118 X4000 User s Guide Fast Configuration with the Configuration Wizard Basic Unit 6...
Page 362: ...362 X4000 User s Guide Configuration of Security Functions and Firewall 10...
Page 374: ...374 X4000 User s Guide Configuration Management 11...
Page 386: ...386 X4000 User s Guide Troubleshooting 12...
Page 433: ...X4000 User s Guide 433 15...
Page 449: ...X4000 User s Guide 449 15...
Page 468: ...468 X4000 User s Guide General Safety Precautions in 15 Different Languages 15...
Page 496: ...496 X4000 User s Guide Index...
Page 498: ...498 X4000 User s Guide Document 71000L Version1 3...