Copyright ©ZYCOO All rights reserved. V1.0
72
Dest Mask
Set the destination address’ mask. For example, 255.255.255.255 means just point
to one host; 255.255.255.0 means point to a network which network ID is C type.
Click the
Add
button
if you want to add a new output rule.
Then enable out access, and click the Apply button.
So when devices execute to ping 192.168.1.118, system will deny the request to send icmp request to
192.168.1.118 for the out access rule. But if devices ping other devices which network ID is 192.168.1.0, it will
be normal.
Click the
Delete
button to delete the selected rule.
8.2.7.3
NAT
NAT is abbreviated from Net Address Translation; it’s a protocol responsible for IP address translation. In other
word, it is responsible for transforming IP and port of private network to public, also is the IP address mapping
which we usually say.
DMZ config:
In order to make some intranet equipment support better service for extranet, and make internal network security
more effectively, these equipment open to extranet need be separated from the other equipment not open to
extranet by the corresponding isolation method according to different demands. We can provide the different
security level protection in terms of the different resources by building a DMZ region which can provide the
network level protection for the equipment environment, reduce the risk which is caused by providing service to
distrust customer, and is the best position to put public information
The following chart describes the network access control of DMZ.
Содержание COOFONE-D60
Страница 1: ......
Страница 58: ...Copyright ZYCOO All rights reserved V1 0 54 ...