Ubigate iBG3026 Configuration Guide
© SAMSUNG Electronics Co., Ltd.
231
CHAPTER 23.
Firewall NAT
Overview
Security module in Ubigate iBG3026 consists of various components such as
Stateful inspection firewall, IPSec VPN, Public Key Infrastructure and Access
Control List(ACL). This chapter introduces Ubigate iBG3026’s firewall and
its typical configuration.
The Ubigate iBG3026 has Smart Forwarder as a dataplane forwarding engine.
So, the forwarding of packets in security module is performed in the context
of Smart Forwarder task. The components of security module may have
control plane such as IKE(Internet Key Exchange) for VPN, SCEP for
certificate enrollment in PKI, etc. These control plane activities are performed
in the context of separate tasks such as IKES, SCEP, etc.
Whenever an IP packet in transit gets to Smart Forwarder, it checks whether
the interface on which the packet arrived is registered for security processing
or not. If registered, it is processed for security. Otherwise, it is put through
regular IP forwarding. Similarly, whenever a packet gets to the Smart
Forwarder from the local TCP/IP stack, it is checked if the outbound interface
is registered with security and if so, it is processed for security.
The firewall in security module is a Stateful inspection firewall for IPv4.
In this, packets are allowed or denied to be forwarded through the system
based on pre-defined policies. When a packet is allowed by the firewall policy,
in real time, an association with limited lifetime is created for the packet with
the combination of various fields in the packet such as Source IP, Source port,
Destination IP, Destination port, Protocol, etc. Based on the protocol type, the
association maintains a state or pseudo-state.
Содержание Ubigate iBG3026
Страница 1: ......
Страница 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 34: ......
Страница 42: ...CHAPTER 1 Basic Configuration 8 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 70: ...CHAPTER 5 RMON Configuration 36 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 72: ......
Страница 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 110: ......
Страница 126: ...CHAPTER 10 Layer 2 Switching 88 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 260: ...CHAPTER 20 VLAN forwarding with QoS 222 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 262: ......
Страница 268: ...CHAPTER 21 Authentication Authorization Accounting 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 346: ......
Страница 378: ...CHAPTER 27 VoIP Gateway Management 336 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 716: ...CHAPTER 37 Survivable Telephony 674 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 718: ...EQBD 000026 Ed 00 ...