
Packet filtering
System Administrator’s Guide
49
Packet filtering
By default, your Shiva VPN Gateway allows network traffic as follows:
You can configure your Shiva VPN Gateway with additional filter rules to allow or
restrict network traffic. These rules can match traffic based on the source and
destination address, the incoming and outgoing network port, and/or the services.
You can also configure your Shiva VPN Gateway to perform network address
translation (NAT). This may be in the form of source address NAT, destination address
NAT, or 1-to-1 NAT. Network address translation modifies the IP address and/or port
of traffic traversing the Shiva VPN Gateway.
The most common use of this is for port forwarding (aka PAT/Port Address
Translation) from ports on the Shiva VPN Gateway's WAN interface to ports on
machines on the LAN. This is the most common way for internal, masqueraded
servers to offer services to the outside world. Destination NAT rules are used for port
forwarding.
Source NAT rules are useful for masquerading one or more IP addresses behind a
single other IP address. This is the type of NAT used by the Shiva VPN Gateway to
masquerade your private network behind its public IP address.
1-to-1 NAT creates both Destination NAT and Source NAT rules for full IP address
translation in both directions. This can be useful if you have a range of IP addresses
that have been added as interface aliases on the Shiva VPN Gateway's WAN
interface, and want to associate one of these external alias IP addresses with a single
internal, masqueraded computer. This effectively allocates the internal computer its
own real world IP address, also known as a virtual DMZ.
Before configuring a filter or NAT rule, you need to define the addresses and service
groups.
Incoming Interface
Outgoing Interface
Action
LAN/VPN/Dial-In
Any
Accept
WAN
Any
Drop
Function
NAT Method
Port forwarding (PAT)
Destination NAT
Masquerading
Source NAT
Virtual DMZ
1-to-1 NAT
Содержание SHIVA 1100
Страница 1: ...Shiva VPN Gateway Model 500 and 1100 System Administrator s Guide Connecting People to Information...
Страница 38: ...QoS traffic shaping 38 System Administrator s Guide...
Страница 44: ...DHCP relay 44 System Administrator s Guide...
Страница 66: ...Access control 66 System Administrator s Guide...
Страница 122: ...Technical Support 122 System Administrator s Guide...
Страница 132: ...132 System Administrator s Guide...