HiPath 3000/5000 in the LAN Network
Nur für den internen Gebrauch
A31003-H3590-S100-7-7620, 06/2012
13-46
HiPath 3000/5000 V9, Service documentation
h3h5_in_the_lan.fm
HG 1500 Board
Verification of the IP address (configurable) of internal LAN subscribers.
13.6.15.2
Firewall
A firewall is a barrier which protects against unauthorized access. In this case, the internal LAN
(LAN1), for example, is to be protected against external access (such as Internet-based access
via DSL).
The objective of a firewall configuration is to allow individual, specified computers to access an
insecure network (for example Internet). At the same time, it prevents access in the reverse
direction (from the Internet to these computers). The board features two different protection
mechanisms for implementing this security.
The firewall in this case is a so-called authorization firewall. In other words, as soon as the fire-
wall is activated, only configured components can access board services. All board services
are automatically denied to unregistered LAN components.
Firewall (Permit Firewall)
In the case of a permit firewall, only configured components can access board services (when
the firewall is activated). All board services are automatically denied to unregistered LAN com-
ponents. The board features different protection mechanisms for implementing this security.
●
Stateful packet filtering for communication with the LAN
Stateful packet filtering analyzes and, if necessary, rejects packets based on their source
and target IP address addresses and the ports used (TCP, UDP, and ICMP port firewall).
The IP addresses can be network addresses or individual hosts.
●
Denial of Service Protection
Denial of Service Protection offers protection against a broad variety of Denial of Service
attacks (and other attacks on the network gateway) such as SYN flooding, various frag-
mentation attacks, TCP hijacking (various active attacks, for example ARP spoofing),
LAND (identical source and destination IPs), Christmas Tree attacks (all TCP flags are
set), etc.
7
WARNING: The activation and deactivation of firewall parameters may severely re-
strict the functionality of the board (for example LAN-based administration may not
be possible any more) or may enable access to sensitive data.
Summary of Contents for HiPath 3000 Series
Page 1252: ......