12
C
HAPTER
2: I
NSTALLING
THE
F
IREWALL
C
LIENT
The 3Com Embedded Firewall Policy Server and Management Console (sold
separately) is used by the security administrator to define and control the security
policies that are executed by the server, desktop, and notebook firewalls. This
central management console also provides security logging capabilities, giving
administrators the ability to view logs and perform troubleshooting.
The 3Com Embedded Firewall Client Devices (available in desktop and server PCI,
as well as laptop-based Cardbus) receive security policies from the policy server.
This security processor on each of these firewalls examines the traffic passing
through the device and blocks traffic that falls outside of the security policy.
Firewall PC Card
The 3Com Embedded Firewall solution applies security policy enforcement
capabilities to all traffic transmitted from and received by an individual laptop,
desktop, or server.
The Firewall Client Device provides transparent packet filtering in accordance with
the rules that are setup by a security administrator. The rules are defined through a
centralized management console and are communicated to the firewall client
devices via the policy server.
Like traditional perimeter firewalls, the 3Com Embedded Firewall solution is
capable of classifying and acting upon packets based on the following criteria:
•
Source IP Address
•
Source IP Mask
•
Source Port
•
Destination IP Address
•
Destination IP Mask
•
Destination Port
•
IP Protocol (TCP, UDP, etc.)
•
Direction (Inbound, Outbound, both)
Once the traffic has been classified, actions that may be taken on the packet are:
•
Allow
•
Allow and Audit
•
Deny
•
Deny and Audit
Optional Control
Headers
The 3Com Firewall PC Card includes optional controls for the following:
No Sniffing
--Prevents the Firewall Client Device from sniffing traffic addressed to
other devices on your network.
No Spoofing
--Prevents the Firewall Client Device from sending packets on the
network with forged source IP addresses.
Non-IP Traffic
--Denies Non-IP Traffic such as IPX or NetBEUI.
Содержание 3CRFW102
Страница 14: ...10 CHAPTER 1 INSTALLING THE PC CARD AND DRIVERS ...
Страница 28: ...24 CHAPTER 5 DATA ENCRYPTION OFFLOAD ...
Страница 32: ...A Technical Support 28 ...