Chapter 7
Traffic Policy
102
Figure 7.39
Definition of a Full cone NAT traffic rule
•
Source
— IP address of an SIP telephone in the local network.
•
Destination
— name or IP address of an SIP server in the Internet.
Full cone NAT
will
apply only to connection with this server.
•
Service
—
SIP
service (for an SIP telephone).
Full cone NAT
will not apply to any other
services.
•
Action
— traffic must be allowed.
•
Translation
— select a source NAT method (see chapter
) and enable the
Allow
returning packets from any host (Full cone NAT)
option.
Figure 7.40
Enabling Full cone NAT in the traffic rule
Rule for
Full cone NAT
must precede the general rule with NAT allowing traffic from the local
network to the Internet.
7.9 Media hairpinning
WinRoute
allows to “arrange” traffic between two clients in the LAN which “know each other”
only from behind the firewall’s public IP address. This feature of the firewall is called
hairpin-
ning
(with the
hairpin
root suggesting the packet’s “U-turn” back to the local network). Used
especially for transmission of voice or visual data, it is also known as
media hairpinning
.
Содержание KERIO WINROUTE FIREWALL 6
Страница 1: ...Kerio WinRoute Firewall 6 Administrator s Guide Kerio Technologies s r o...
Страница 157: ...12 3 Content Rating System Kerio Web Filter 157 Figure 12 7 Kerio Web Filter rule...
Страница 189: ...14 4 URL Groups 189 Description The item s description comments and notes for the administrator...
Страница 247: ...19 4 Alerts 247 Figure 19 14 Details of a selected event...
Страница 330: ...Chapter 23 Kerio VPN 330 Figure 23 55 The Paris filial office VPN server configuration...
Страница 368: ...368...