3Com MSR 50 Series Configuration Manual page 1792

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

1792
C
94: F
HAPTER
IREWALL
C
ONFIGURATION
If a device is connected with the internal network and Internet and protects
servers on the internal network by means of an ASPF, the device's interface to the
internal network is the internal interface and the device's interface to the Internet
is the external interface.
When an ASPF is applied on the outbound direction of the external interface of a
router, a temporary channel can be opened on the firewall for return packets for
internal network users to access the Internet.
Basic idea of application layer protocol detection
Figure 520 Basic idea of application layer protocol detection
Client A
Client A initiates a session
Return packets of
permitted to pass
Clinet B
As shown above, to protect the internal network, it is usually necessary to
configure an ACL on the router for the purpose of permitting internal hosts to
access external networks while prohibiting hosts on external networks from
gaining access to the internal network. However, an ACL would filter out the
return packets after a user initiates a connection - as a result, the connection setup
would fail.
After application protocol detection is enabled on the device, the ASPF can detect
each application layer session and create a status table and a temporary access
control list (TACL). The status table is created when ASPF detects the first packet.
The ASPF uses this table to maintain the status of an ongoing session at a certain
point of time and detect whether the conversion of session status is correct.
The TACL is created at the same time the status table is created, and is deleted
when at the end of the session. It is equivalent to a permit statement in an
extended ACL. The TACL is mainly used to match all the return packets in a
session, and can set up a temporary return channel on the external interface of
the firewall for packets returned by an application.
An example of FTP detection is used in the following paragraphs to explain the
process of multi-channel application layer protocol detection.
Router
the session are
Protected network
Packets of other sessions are blocked
WAN
Server

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents