![Lightning SA MultiCom Скачать руководство пользователя страница 110](http://html1.mh-extra.com/html/lightning-sa/multicom/multicom_user-manual_1912263110.webp)
Chapter 6 Frequently Asked Questions
110 MultiCom Firewall
User’s Manual
rules are being used. Any Output NAT rules change the data after routing.
What happens if I turn off the SecureWall Firewall?
When the SecureWall Firewall is enabled for an interface all incoming
data-packets must have a matching NAT rule to allow them into the network,
either through the internal Connection Tracking table (which keeps track of all
outgoing requests to the Internet for data) or a fixed rule for services like
Virtual IP or Port Mapping to an internal computer or server. When the
SecureWall Firewall is turned off then data can come through with or without
matching a NAT rule and it is up to the Stateful Packet Inspection Firewall to
turn away data packets that you do not want.
If I use NAT to map a range of ports or IP addresses how does it choose?
Choosing ranges of port numbers or IP addresses tells NAT to randomly
choose a number in this range to use for its mapping. This is also known as
Round-Robin load-sharing.
Is it possible to assign more than 1 IP address to the WAN interface?
You can use NAT to have the Ethernet firewall accept data packets for an IP
address other than the one assigned to the WAN interface. ARP requests to
the WAN interface are only replied to when the requested IP address is the
one assigned to the WAN interface or if the ARP Proxy is configured to
respond to a chosen IP address. Otherwise no ARP replies will occur for the
other IP addresses using NAT. Check the Virtual IP section of the Reference
Manual.
If I am using NAT to redirect WAN data to an internal server can I also redirect
LAN requests?
Yes, you can redirect LAN and WAN data to the same server when you enter
in a NAT rule in the NAT Global panel and activate NAT on the LAN
interface. This is a common use when redirecting HTTP (web) traffic to a
publicly known IP address for users on the LAN... allowing them to use the
same IP address as the external or WAN users. Activating NAT on the LAN
interface will however make all traffic seem to originate from the LAN
interface itself and so possibly cause problems with any statistics logs you are
keeping. In this case it might be better to use the DNS server on the LAN
instead of activating NAT.
Can I reset the connection for my WAN port on the Ethernet firewall
For a static configuration you simply use the Web Interface to access and
Содержание MultiCom
Страница 1: ...For Firmware 3 7 10 19 04 MultiCom Firewall User s Manual ...
Страница 2: ...ii MultiCom Firewall User s Manual ...
Страница 4: ...iv MultiCom Firewall User s Manual ...
Страница 15: ...MultiCom Firewall User s Manual xv ...
Страница 16: ...xvi MultiCom Firewall User s Manual ...
Страница 26: ...Chapter 1 Preface 26 MultiCom Firewall User s Manual ...
Страница 38: ...Chapter 2 Introducing The MultiCom Firewalls 38 MultiCom Firewall User s Manual ...
Страница 94: ...Chapter 4 Maintenance 94 MultiCom Firewall User s Manual ...
Страница 141: ...MultiCom Firewall User s Manual 141 BSD Copyright ...
Страница 142: ...Appendix B Additional Licenses and Copyrights 142 MultiCom Firewall User s Manual ...
Страница 143: ...MultiCom Firewall User s Manual 143 BSD Copyright ...
Страница 144: ...Appendix B Additional Licenses and Copyrights 144 MultiCom Firewall User s Manual ...
Страница 145: ...MultiCom Firewall User s Manual 145 BSD Copyright ...
Страница 146: ...Appendix B Additional Licenses and Copyrights 146 MultiCom Firewall User s Manual ...
Страница 170: ...Glossary 170 Glossary User s Manual ...