Ubigate iBG3026 Configuration Guide
© SAMSUNG Electronics Co., Ltd.
231
CHAPTER 23.
Firewall NAT
Overview
Security module in Ubigate iBG3026 consists of various components such as
Stateful inspection firewall, IPSec VPN, Public Key Infrastructure and Access
Control List(ACL). This chapter introduces Ubigate iBG3026’s firewall and
its typical configuration.
The Ubigate iBG3026 has Smart Forwarder as a dataplane forwarding engine.
So, the forwarding of packets in security module is performed in the context
of Smart Forwarder task. The components of security module may have
control plane such as IKE(Internet Key Exchange) for VPN, SCEP for
certificate enrollment in PKI, etc. These control plane activities are performed
in the context of separate tasks such as IKES, SCEP, etc.
Whenever an IP packet in transit gets to Smart Forwarder, it checks whether
the interface on which the packet arrived is registered for security processing
or not. If registered, it is processed for security. Otherwise, it is put through
regular IP forwarding. Similarly, whenever a packet gets to the Smart
Forwarder from the local TCP/IP stack, it is checked if the outbound interface
is registered with security and if so, it is processed for security.
The firewall in security module is a Stateful inspection firewall for IPv4.
In this, packets are allowed or denied to be forwarded through the system
based on pre-defined policies. When a packet is allowed by the firewall policy,
in real time, an association with limited lifetime is created for the packet with
the combination of various fields in the packet such as Source IP, Source port,
Destination IP, Destination port, Protocol, etc. Based on the protocol type, the
association maintains a state or pseudo-state.
Summary of Contents for Ubigate iBG3026
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 72: ......
Page 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 110: ......
Page 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 262: ......
Page 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 346: ......
Page 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 718: ...EQBD 000026 Ed 00 ...