Avaya Business Secure Router 222 Configuration - Basics Instrukcja Użytkownika Strona 169

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 168
Chapter 10 Firewalls 169
Nortel Business Secure Router 222 Configuration — Basics
Packet filtering vs. firewall
Below are some comparisons between the filtering and firewall functions of the
Business Secure Router.
Packet filtering:
The router filters packets as they pass through the routers interface according
to the filter rules you designed.
Packet filtering is a powerful tool, yet can be complex to configure and
maintain, especially if you need a chain of rules to filter a service.
Packet filtering only checks the header portion of an IP packet.
When to use filtering
1 To block or allow LAN packets by their MAC addresses.
2 To block or allow special IP packets that are neither TCP nor UDP, nor ICMP
packets.
3 To block or allow both inbound (WAN to LAN) and outbound (LAN to WAN)
traffic between the specific inside host or network A and outside host or
network B. If the filter blocks the traffic from A to B, it also blocks the traffic
from B to A. Filters cannot distinguish traffic originating from an inside host
or an outside host by IP address.
4 To block or allow IP trace route.
Firewall
The firewall inspects packet contents as well as their source and destination
addresses. Firewalls of this type employ an inspection module, applicable to
all protocols, that understands data in the packet is intended for other layers,
from the network layer (IP headers) up to the application layer.
The firewall performs stateful inspection. It takes into account the state of the
connections it handles, so that, for example, a legitimate incoming packet can
be matched with the outbound request for that packet and allowed in.
Conversely, an incoming packet masquerading as a response to a nonexistent
outbound request can be blocked.
Przeglądanie stron 168
1 2 ... 164 165 166 167 168 169 170 171 172 173 174 ... 450 451

Komentarze do niniejszej Instrukcji

Brak uwag