CHAPTER 23. Firewall NAT
238
© SAMSUNG Electronics Co., Ltd.
Configuring Firewalls
Typical topology diagram
Describe firewall configuration about firewall policy, dos-protect, filter, and
port-trigger, etc.
−
Network Address Translation(NAT) serves two purposes:
Allow LAN administrators to create secure, private, non-routable IP
networks behind firewalls
Stretch the number of available IP addresses by allowing LANs to use one
public(real) IP address as the gateway with a very large pool of NAT
addresses behind it.
In the most common NAT application(which is to provide secure networking
behind a firewall), the device(Ubigate iBG3026) that connects the user LAN
to the Internet will have two IP addresses:
A private IP address on the LAN side for the RFC 1918 address range
A public address, routable over the Internet, on the WAN side
Consider a PC on the LAN sending a packet destined for
some.server.com
.
The source IP address and port are in the packet together with the destination
IP address and port. When the packet arrives at the Ubigate iBG3026 it will be
de-encapsulated, modified, and re-encapsulated.
The re-encapsulated packet sent by the Ubigate iBG3026 destined for the
Internet contains the Ubigate iBG3026’s public IP address, a source port
allocated from its list of available ports, and the same destination IP address
and port number generated by the PC.
Name-DenyPut
IP Protocol-TCP
Application Port-21
Type-FTP
Action-Deny
Commands
STOR
Name-DenyJava
IP Protocol-TCP
Application Port-80
Type-HTTP
Action-Deny
Proxy-Denied
File Extensions
*.java
Name-AllowFax
IP Protocol-UDP
Application Port-111
Type-RPC
Action-Allow
Commands
12345678
FTP Control
HTTP Control
RPC Control
Summary of Contents for Ubigate iBG3026
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 72: ......
Page 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 110: ......
Page 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 262: ......
Page 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 346: ......
Page 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 718: ...EQBD 000026 Ed 00 ...