![Samsung Ubigate iBG2016 Скачать руководство пользователя страница 282](http://html.mh-extra.com/html/samsung/ubigate-ibg2016/ubigate-ibg2016_configuration-manual_351244282.webp)
CHAPTER 3. Firewall NAT
232
© SAMSUNG Electronics Co., Ltd.
Firewall also offers a rich set of features such as protection against
DOS(Denial Of Service) attacks, Network Address Translation(NAT), etc.
Firewall policies are created by CLI/GUI and stored in the Firewall Policy
Data Base and dynamically created associations are stored in the Association
Data Base.
Firewall and VPN are tightly coupled together. Some of the dynamic
associations created are shared by the two modules. So, it is not possible to
use VPN without using firewall. However, firewall can be used without VPN
enabled-VPN in pass-through mode.
Virtual Firewall
Virtual Firewalls completely break the one-device/one-policy-database
constraint. Instead, many discrete firewalls can be run on a single device with
the Virtual Firewall capability. A Virtual Firewall(VF) provides multiple
logical firewalls for multiple networks, on one system.
This is accomplished by establishing firewall ‘maps’, with each map having
its own user defined security policy. Each map has its own outbound and
inbound policies and configuration objects. Maps can be added or removed to
provide scalability with the growth of subscriber networks.
Virtual firewall feature can be used to provide separate firewall policies as
shown in the following diagram
1.
Internet(
internet
) for the untrusted network.
2.
Corporation(
corp
) for the corporate network.
3.
Demilitarized Zone(
dmz
)for the server accessibility from the untrusted
side-or other user-defined network.
4.
Managing access to the box.
Содержание Ubigate iBG2016
Страница 1: ......
Страница 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 34: ......
Страница 42: ...CHAPTER 1 Basic Configuration 8 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 62: ...CHAPTER 4 System Logging 28 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 70: ......
Страница 108: ......
Страница 126: ...CHAPTER 1 Layer 2 Switching 90 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 140: ...CHAPTER 4 RIP 104 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 156: ...CHAPTER 6 BGP 120 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 176: ...CHAPTER 7 MultiCast Protocols 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 180: ...CHAPTER 8 VRRP 144 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 264: ...CHAPTER 10 QoS 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 270: ...CHAPTER 11 VLAN forwarding with QoS 234 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 272: ......
Страница 278: ...CHAPTER 1 Authentication Authorization Accounting 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 298: ...CHAPTER 3 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 356: ...CHAPTER 5 IPSEC 306 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 358: ......
Страница 390: ...CHAPTER 2 VoIP Gateway Management 336 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 514: ...CHAPTER 4 H 323 Gateway Management 460 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 670: ...CHAPTER 8 Routing and Digit Manipulation 616 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 744: ...EQBD 000071 Ed 00 ...