![Alcatel-Lucent OmniAccess 700 Скачать руководство пользователя страница 676](http://html.mh-extra.com/html/alcatel-lucent/omniaccess-700/omniaccess-700_cli-configuration-manual_2891856676.webp)
Filter and Firewall
Left running head:
Chapter name (automatic)
650
Beta
Beta
CLI Configuration Guide
Alcatel-Lucent
F
IREWALL
M
ECHANISMS
This section provides details about firewall mechanisms.
•
“Packet Filtering”
•
“Stateful Inspection”
P
ACKET
F
ILTERING
This is a simple firewall solution that is usually implemented on devices like
routers that filter packets. The packet-headers are inspected when going through
the firewall. Packets are analyzed against a set of rules. Depending on these
rules, the packet is either accepted or denied.
Once a match is found, the rule action is obeyed. The rule action could be to drop
the packet, to forward the packet, or even to send an ICMP message back to the
originator. Only the first match counts, as the rules are searched in order. Hence,
the list of rules can be referred to as a ``rule chain''. On match, the specified action
is taken. Typical actions are deny/ allow / drop/ reject packets or reset connection.
S
TATEFUL
I
NSPECTION
This is an advanced implementation of packet filtering that inspects packets at
higher network layers, up to the application layer. Such filters interpret transport-
level information (such as TCP and UDP headers) to analyze and record all
current connections. This process is known as stateful inspection.
A stateful packet filter records the status of all connections and allows only those
packets that are associated with a current connection. Information traveling from
inside the firewall to the outside is monitored for specific defining characteristics.
The incoming information is then compared to these defining characteristics and
upon a reasonable match, the information is permitted, else it is denied.
When a computer in the protected network initiates a connection with an external
server, the stateful packet filter allows the server's response packets into the
protected network. When the original connection is closed, however, the packet
filter will block all further unsolicited packets from the untrusted zone. Stateful
firewalls are also known as "dynamic" packet filters.
Note:
OA-700 supports stateful and stateless inspection. By default, OA-700 firewall is
‘stateful’.
Содержание OmniAccess 700
Страница 38: ...Left running head Chapter name automatic 12 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 176: ...Left running head Chapter name automatic 150 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 224: ...Per VLAN Spanning Tree Left running head Chapter name automatic 198 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 258: ...Port Monitoring Left running head Chapter name automatic 232 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 260: ...Left running head Chapter name automatic 234 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 296: ...T1E1 Line Card Left running head Chapter name automatic 270 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 360: ...Point to Point Protocol Left running head Chapter name automatic 334 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 434: ...Left running head Chapter name automatic 408 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 462: ...Common Classifiers Left running head Chapter name automatic 436 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 464: ...Left running head Chapter name automatic 438 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 534: ...Border Gateway Protocol Left running head Chapter name automatic 508 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 638: ...Left running head Chapter name automatic 612 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 762: ...Filter and Firewall Left running head Chapter name automatic 736 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 890: ...Transparent Firewall Left running head Chapter name automatic 864 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 940: ...Left running head Chapter name automatic 914 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1000: ...Quality of Service Left running head Chapter name automatic 974 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1002: ...Left running head Chapter name automatic 976 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1044: ...DNS Domain Name Service Client Left running head Chapter name automatic 1018 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1046: ...Left running head Chapter name automatic 1020 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1058: ...Left running head Chapter name automatic 1032 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1074: ...Lifeline Left running head Chapter name automatic 1048 Beta Beta CLI Configuration Guide Alcatel Lucent line con 0 end ...
Страница 1076: ...Left running head Chapter name automatic 1050 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1118: ...Web Cache Server Left running head Chapter name automatic 1092 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1120: ...Left running head Chapter name automatic 2 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1140: ...QoS Values and Mnemonics Left running head Chapter name automatic 22 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1156: ...IPsec Interoperability of OA 700 Left running head Chapter name automatic 38 Beta Beta CLI Configuration Guide Alcatel Lucent ...