Chapter 11 Filter configuration
133
BCM50e Integrated Router Configuration - Advanced
Filter Types and NAT
There are two classes of filter rules,
Generic Filter
(Device) rules and protocol
filter (
TCP/IP
) rules. Generic filter rules act on the raw data that’s going through
between LAN and WAN. Protocol filter
rules act on the IP packets. Generic and
TCP/IP filter rules are discussed in more detail in the next section. When NAT
(Network Address Translation) is enabled, the inside IP address and port number
are replaced on a connection-by-connection basis, which makes it impossible to
know the exact address and port on the wire. Therefore, the Business Secure
Router applies the protocol filters to the native IP address and port number before
NAT for outgoing packets and after NAT for incoming packets. On the other
hand, the generic, or device filters are applied to the raw packets that appear on
the wire. They are applied at the point when the Business Secure Router is
receiving and sending the packets; for example. the interface. The interface can be
an Ethernet port or any other hardware port, as illustrated in
.
Figure 64
Protocol and Device Filter Sets
Firewall Versus Filters
Firewall configuration is discussed in
Chapter 10, “Introducing the firewall,” on
chapters
of this manual. Further comparisons are also made between
filtering, NAT and the firewall.
Содержание BCM50e
Страница 18: ...18 Figures N0115789 ...
Страница 22: ...22 Tables N0115789 ...
Страница 28: ...28 Preface N0115789 ...
Страница 38: ...38 Chapter 1 Getting to know your BCM50e Integrated Router N0115789 ...
Страница 44: ...44 Chapter 2 Introducing the SMT N0115789 SMT menus at a glance Figure 6 SMT overview ...
Страница 60: ...60 Chapter 4 LAN setup N0115789 ...
Страница 82: ...82 Chapter 6 Remote Node setup N0115789 ...
Страница 86: ...86 Chapter 7 IP Static Route Setup N0115789 ...
Страница 114: ...114 Chapter 9 Network Address Translation NAT N0115789 ...
Страница 136: ...136 Chapter 11 Filter configuration N0115789 ...
Страница 140: ...140 Chapter 12 SNMP Configuration N0115789 ...
Страница 144: ...144 Chapter 13 System security N0115789 ...
Страница 172: ...172 Chapter 15 Firmware and configuration file maintenance N0115789 ...
Страница 186: ...186 Chapter 17 Remote Management N0115789 ...
Страница 206: ...206 Appendix B Triangle Route N0115789 ...
Страница 226: ...226 Appendix D PPPoE N0115789 ...
Страница 232: ...232 Appendix F N0115789 ...
Страница 242: ...242 Appendix G IP subnetting N0115789 ...
Страница 304: ...304 Appendix K Log descriptions N0115789 ...
Страница 306: ...306 Appendix L Brute force password guessing protection N0115789 ...