Connection state New
List box {Off; On}, default = "Off" - active only for TCP protocolRelates to the first packet when a
TCP connection starts (Request from TCP client to TCP server for opening a new TCP connection).
Used e.g. for allowing to open TCP only from M!DGE3 network to outside.
Connection state Established
List box {Off; On}, default = "Off" - active only for TCP protocolRelates to an already existing TCP
connection. Used e.g. for allowing to get replies for TCP connections created from M!DGE3 network
to outside.
Connection state Related
List box {Off; On} default = "Off", active only for TCP protocolA connection related to the "Established"
one. e.g. FTP typically uses 2 TCP connections control and data, where data connection is created
automatically by using dynamic ports.
Note
L2/L3 firewall settings do not impact the local ETH access, i.e. settings never deny access
to a locally connected M!DGE3 (web interface, ping, ...).
Note
Ports 443 and 8889 are used (by default, can be overridden) internally for service access.
Exercise caution when making rules which may affect datagrams to/from these ports in L3
Firewall settings. Management connection to a remote M!DGE3 may be lost, when another
M!DGE3 acts as a router along the management packets route and port 443 (or 8889) is
disabled in firewall settings of that routing M!DGE3 (M!DGE3 units uses iptables "forward").
Note
L3 Firewall settings do not impact packets received and redirected from/to Radio channel.
The problem described in NOTE 2 will not happen, if the affected M!DGE3 router is a radio
repeater, i.e. when it uses solely the radio channel for input and output.
7.3.3. NAT - Network address translation
Network address and port translation
(
NAPT
) is a method of mapping an IP address (or port) space
into another by modifying network address information in the IP header of packets while they are in
transit across a traffic routing device.
7.3.3.1. Source NAT
Source Network Address Translation (SNAT) - rewrites the source address and/or port within the
leaving connection and performs opposite changes for returning packets. SNAT:
• Allows to pretend, that the packets come from a device, that performs SNAT.
• Performs during packet output from a device (after routing and filtering in firewall) .
103
© RACOM s.r.o. – M!DGE3 Cellular Router
Settings
Содержание M!DGE3
Страница 2: ......
Страница 11: ...2 1 Dimensions Fig 2 1 M DGE3 dimensions 11 RACOM s r o M DGE3 Cellular Router Product...
Страница 116: ...M DGE3 Cellular Router RACOM s r o 116 Settings...
Страница 134: ...Tab 7 3 Configuration versions FW version CNF version 2 0 13 0 1 M DGE3 Cellular Router RACOM s r o 134 Settings...