CHAPTER 23. Firewall NAT
238
© SAMSUNG Electronics Co., Ltd.
Configuring Firewalls
Typical topology diagram
Describe firewall configuration about firewall policy, dos-protect, filter, and
port-trigger, etc.
−
Network Address Translation(NAT) serves two purposes:
Allow LAN administrators to create secure, private, non-routable IP
networks behind firewalls
Stretch the number of available IP addresses by allowing LANs to use one
public(real) IP address as the gateway with a very large pool of NAT
addresses behind it.
In the most common NAT application(which is to provide secure networking
behind a firewall), the device(Ubigate iBG3026) that connects the user LAN
to the Internet will have two IP addresses:
A private IP address on the LAN side for the RFC 1918 address range
A public address, routable over the Internet, on the WAN side
Consider a PC on the LAN sending a packet destined for
some.server.com
.
The source IP address and port are in the packet together with the destination
IP address and port. When the packet arrives at the Ubigate iBG3026 it will be
de-encapsulated, modified, and re-encapsulated.
The re-encapsulated packet sent by the Ubigate iBG3026 destined for the
Internet contains the Ubigate iBG3026’s public IP address, a source port
allocated from its list of available ports, and the same destination IP address
and port number generated by the PC.
Name-DenyPut
IP Protocol-TCP
Application Port-21
Type-FTP
Action-Deny
Commands
STOR
Name-DenyJava
IP Protocol-TCP
Application Port-80
Type-HTTP
Action-Deny
Proxy-Denied
File Extensions
*.java
Name-AllowFax
IP Protocol-UDP
Application Port-111
Type-RPC
Action-Allow
Commands
12345678
FTP Control
HTTP Control
RPC Control
Содержание Ubigate iBG3026
Страница 1: ......
Страница 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 34: ......
Страница 42: ...CHAPTER 1 Basic Configuration 8 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 70: ...CHAPTER 5 RMON Configuration 36 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 72: ......
Страница 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 110: ......
Страница 126: ...CHAPTER 10 Layer 2 Switching 88 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 260: ...CHAPTER 20 VLAN forwarding with QoS 222 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 262: ......
Страница 268: ...CHAPTER 21 Authentication Authorization Accounting 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 346: ......
Страница 378: ...CHAPTER 27 VoIP Gateway Management 336 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 716: ...CHAPTER 37 Survivable Telephony 674 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 718: ...EQBD 000026 Ed 00 ...