AST570 Firewall and
NAPT
17 Security Services - Firewalling
224
/ 300
3EC 17766 AAAA TCZZA Ed. 04
17.5 Firewalling and NAPT
The position of the
Input, Static NA(P)T, Dynamic NA(P)T, Forward
and
Output
logical processing modules in the overall
AST570
Firewall model is relative to the traffic direction. In contrast, the
AST570
' WAN and (W)LAN interfaces are physical interfaces;
their position is not relative to the traffic direction.
The Dynamic NA(P)T module is situated between the Forward and
Output hook (See
AST570
Firewall model). Since the traffic
direction will determine input, and output, the Dynamic NA(P)T
module can always be positioned between the Forward and
Output module.
If you set rules on a hook, you should know if the packets that
pass through that hook contain IP addresses that are
NA(P)Ttranslated or not.
If rules are set on the Output hook and NA(P)T is active, the IP
packets that pass that hook will contain
translated
IP addresses.
If you want to avoid certain traffic, by setting rules that filter on
certain (ranges of) IP addresses, you should be aware of the
location where the rule will be verified, since, depending on the
hook, another IP address will be seen by the Firewall.
As a conclusion: if NA(P)T is activated, the IP address that
identifies a local device, will be different depending on the
direction of the traffic.
Содержание AST570
Страница 1: ...3EC 17766 AAAA TCZZA Ed 04 SPEED TOUCH 570 User s Guide...
Страница 10: ...10 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 25: ...25 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Wiring Guide...
Страница 26: ...26 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 37: ...37 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 WLAN Guide...
Страница 38: ...38 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 54: ...4 WLAN Guide Wireless LAN 54 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 55: ...55 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Configuration and Use...
Страница 56: ...56 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 92: ...9 Configuration and Use Routed PPPoE 92 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 128: ...11 Configuration and Use Routed PPPoA 128 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 147: ...147 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Networking...
Страница 148: ...148 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 196: ...14 Networking Services IP 196 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 203: ...203 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Security...
Страница 204: ...204 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 229: ...229 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Maintenance...
Страница 230: ...230 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 238: ...18 Maintenance Speed Touch Software 238 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 256: ...21 Maintenance Speed Touch Web Interface 256 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 266: ...22 Maintenance Speed Touch CLI 266 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 267: ...267 300 3EC 17766 AAAA TCZZA Ed 04 Alcatel Speed Touch 570 Appendices...
Страница 268: ...268 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 272: ...Abbreviations 272 300 3EC 17766 AAAA TCZZA Ed 04...
Страница 292: ...AppendixE Speed Touch Default Assignments 292 300 3EC 17766 AAAA TCZZA Ed 04...