Chapter 14 Firewall
VMG1312-T10C User’s Guide
167
1
Does this rule stop LAN users from accessing critical resources on the Internet? For example, if IRC
is blocked, are there users that require this service?
2
Is it possible to modify the rule to be more specific? For example, if IRC is blocked for all users, will
a rule that blocks just certain users be more effective?
3
Does a rule that allows Internet users access to resources on the LAN create a security
vulnerability? For example, if FTP ports (TCP 20, 21) are allowed from the Internet to the LAN,
Internet users may be able to connect to computers with running FTP servers.
4
Does this rule conflict with any existing rules?
Once these questions have been answered, adding rules is simply a matter of entering the
information into the correct fields in the web configurator screens.
14.6.4 Triangle Route
When the firewall is on, your Device acts as a secure gateway between your LAN and the Internet.
In an ideal network topology, all incoming and outgoing network traffic passes through the Device
to protect your LAN against attacks.
Figure 113
Ideal Firewall Setup
14.6.4.1 The “Triangle Route” Problem
A traffic route is a path for sending or receiving data packets between two Ethernet devices. You
may have more than one connection to the Internet (through one or more ISPs). If an alternate
gateway is on the LAN (and its IP address is in the same subnet as the Device’s LAN IP address),
the “triangle route” (also called asymmetrical route) problem may occur. The steps below describe
the “triangle route” problem.
1
A computer on the LAN initiates a connection by sending out a SYN packet to a receiving server on
the WAN.
2
The Device reroutes the SYN packet through Gateway
A
on the LAN to the WAN.
3
The reply from the WAN goes directly to the computer on the LAN without going through the
Device.
As a result, the Device resets the connection, as the connection has not been acknowledged.
1
2
WAN
LAN
Содержание VMG1312-T10C
Страница 4: ...Contents Overview VMG1312 T10C User s Guide 4 ...
Страница 12: ...Table of Contents VMG1312 T10C User s Guide 12 ...
Страница 13: ...13 PART I User s Guide ...
Страница 14: ...14 ...
Страница 20: ...Chapter 1 Introduction VMG1312 T10C User s Guide 20 ...
Страница 28: ...28 ...
Страница 34: ...Chapter 4 Connection Status and System Info VMG1312 T10C User s Guide 34 ...
Страница 39: ...Chapter 5 WAN Setup VMG1312 T10C User s Guide 39 Figure 19 Network Setting Broadband Internet Connection ...
Страница 106: ...Chapter 7 Home Networking VMG1312 T10C User s Guide 112 ...
Страница 144: ...Chapter 13 Filter VMG1312 T10C User s Guide 152 ...
Страница 164: ...Chapter 15 Parental Control VMG1312 T10C User s Guide 172 ...
Страница 172: ...Chapter 16 Certificates VMG1312 T10C User s Guide 180 ...
Страница 178: ...Chapter 17 System Monitor VMG1312 T10C User s Guide 186 ...
Страница 180: ...Chapter 18 User Account VMG1312 T10C User s Guide 188 ...
Страница 184: ...Chapter 20 System VMG1312 T10C User s Guide 192 ...
Страница 190: ...Chapter 22 Log Setting VMG1312 T10C User s Guide 198 ...
Страница 196: ...Chapter 24 Backup Restore VMG1312 T10C User s Guide 204 ...
Страница 208: ...Chapter 25 Remote Management VMG1312 T10C User s Guide 216 4 The command line interface displays ...
Страница 214: ...Chapter 26 Diagnostic VMG1312 T10C User s Guide 222 ...
Страница 232: ...Appendix B Legal Information VMG1312 T10C User s Guide 240 ...