CHAPTER 23. Firewall NAT
234
© SAMSUNG Electronics Co., Ltd.
Figure 23.2 Three Legged Firewall Network
Access Policy Database
Access Policy Database is firewall’s central database, commonly referred as
policy database. This database makes use of all the other databases in firewall
and enables in deciding whether a datagram needs to be allowed or denied and
other actions associated to processing.
A policy is nothing but a rule that defines from host A to host B what action
needs to be taken. Every time a new connection comes from host A to host B,
this policy will be referred and the corresponding action will be taken.
This policy is available on network basis and within that direction. Currently
supported policy categories are
Outbound: Policies that govern traffic originated from one map to the
external world.
Inbound-Policies that govern traffic bound to map from the external world.
internet
PAT
Reverse
NAT
Wan interface
ethernet 0/2
interface
FIREWALL ethernet 0/4
interface
corp
dmz
Host1
Host3
Host2
Web-server
Mail-server
Summary of Contents for Ubigate iBG3026
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 72: ......
Page 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 110: ......
Page 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 262: ......
Page 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 346: ......
Page 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 718: ...EQBD 000026 Ed 00 ...