15-2
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 15 Firewall Mode Overview
Routed Mode Overview
•
An Outside User Attempts to Access an Inside Host, page 15-5
•
A DMZ User Attempts to Access an Inside Host, page 15-6
An Inside User Visits a Web Server
Figure 15-1
shows an inside user accessing an outside web server.
Figure 15-1
Inside to Outside
The following steps describe how data moves through the security appliance (see
Figure 15-1
):
1.
The user on the inside network requests a web page from www.example.com.
2.
The security appliance receives the packet and because it is a new session, the security appliance
verifies that the packet is allowed according to the terms of the security policy (access lists, filters,
AAA).
For multiple context mode, the security appliance first classifies the packet according to either a
unique interface or a unique destination address associated with a context; the destination address
is associated by matching an address translation in a context. In this case, the interface would be
unique; the www.example.com IP address does not have a current address translation in a context.
3.
The security appliance translates the local source address (10.1.2.27) to the global address
209.165.201.10, which is on the outside interface subnet.
The global address could be on any subnet, but routing is simplified when it is on the outside
interface subnet.
Web Server
10.1.1.3
www.example.com
User
10.1.2.27
209.165.201.2
10.1.1.1
10.1.2.1
Source Addr Translation
209.165.201.10
10.1.2.27
Outside
Inside
DMZ
92404
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......