h3h5_in_the_lan.fm
A31003-H3590-S100-7-7620, 06/2012
HiPath 3000/5000 V9, Service documentation
13-31
Nur für den internen Gebrauch
HiPath 3000/5000 in the LAN Network
HG 1500 Board
13.6.8.2
Network Address Translation (NAT)
Network Address Translation (NAT) is the conversion of IP addresses in the LAN for the Inter-
net. HG 1500 provides NAT for Internet connections via a second Ethernet interface as well as
for PPP connections via B channels.
As far as the Internet is concerned, the entire LAN appears to be a single IP address and can
therefore use a common dial-up connection to an ISP, for example. Additionally, direct IP at-
tacks from the Internet on terminals in the LAN are not possible.
NAT can be enabled and disabled in the HG 1500. Certain services – such as VoIP or video
telephony – embed subscribers’ IP addresses in their data packets, however, instead of just
noting them in the packet headers. They are only compatible with NAT within a VPN.
13.6.8.3
Access Protection
A variety of security functions are available to prevent unauthorized usage:
Checking Caller Numbers
Connections from the PSTN can be checked against a list of known users using the caller num-
ber. Users whose connections do not transmit a caller number (for example analog telephones)
can call an MSN that is set up especially for them.
Callback
All users can be configured so that they can be called back. Thus, PPP connections are only
possible from a predefined connection.
User Account and Password
After setting up a connection, the user account and password can be checked using PAP
(Password Authentication Protocol), CHAP (Challenge Handshake Authentication Protocol) or
MSCHAP (Microsoft Challenge Handshake Authentication Protocol.
HG 1500 also supports these protocols as a client when dialing in to a RAS server (for example
with an ISP).
IP Address Filter for Communication with the LAN
IP address filters can be defined to prevent attacks on devices in the LAN, both from insecure
(external) networks and from within the LAN. When IP filtering is activated, access is only pos-
sible from address ranges that have explicit permission, and this access is only possible to
specified addresses. Optionally, access can be further limited to a specific protocol port.
Summary of Contents for HiPath 3000 Series
Page 1252: ......