Firewall Overview; Packet Filter Firewall - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

94

Firewall Overview

Packet Filter Firewall

F
IREWALL
When configuring a firewall, go to these sections for information you are
interested in:
"Firewall Overview" on page 1789
"Configuring a Packet Filter Firewall" on page 1794
"Configuring an ASPF" on page 1798
A firewall blocks unauthorized accesses to a protected network from Internet
while allowing internal network users to access the Internet through WWW or
send E-mails. A firewall can also be used to control the Internet access right, for
example, to permit specific hosts within the organization to access the Internet.
Many of today's firewalls offer some other features, such as identity
discrimination, security processing (encryption) of information, and so on.
A firewall is used not only to monitor Internet connections, but also to protect
mainframes and important resources (such as data) on the internal network. Any
access to the protected data must be first filtered by the firewall, even if such an
access is initiated by a user within the internal network.
Presently firewalls on the device mainly perform packet filtering based on the
following:
Access control list (ACL), that is, ACL/packet filtering
Application specific packet filter (ASPF), that is, application layer status specific
packet filtering
Network Address translation (NAT)
n
For details about address translation, refer to
679. This chapter will focus on the description of ACL/packet filter firewall and
ASPF.
Introduction to Packet Filter Firewall
Packet filtering enables a device to filter data packets. A packet filter firewall
implements IP packet specific filtering. When the device needs to forward a
packet, the firewall first obtains the header information of the packet, including
the number of the upper layer protocol over the IP layer, the source address,
destination address, source port and destination port of the packet, and so on,
then compares the information with the preset ACL rule, and finally processes the
packet according to the comparison result.
C
ONFIGURATION
"NAT-PT Configuration" on page

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents