How Many Network Users Can The Sua/Nat Support; What Are Device Filters And Protocol Filters; How Can I Protect Against Ip Spoofing Attacks - ZyXEL Communications P-661HW-D Series Support Note

802.11g wireless adsl2+ 4-port security gateway
Hide thumbs Also See for P-661HW-D Series:
Table of Contents

Advertisement

The following table summarizes the five types.
NAT Type
IP Mapping
One-to-One
ILA1<--->IGA1
ILA1<--->IGA1
Many-to-One
ILA2<--->IGA1
(SUA/PAT)
...
ILA1<--->IGA1
ILA2<--->IGA2
Many-to-Many
ILA3<--->IGA1
Overload
ILA4<--->IGA2
...
ILA1<--->IGA1
ILA2<--->IGA2
Many
ILA3<--->IGA3
One-to-One
ILA4<--->IGA4
...
Server 1 IP<--->IGA1
Server
Server 2 IP<--->IGA1

14. How many network users can the SUA/NAT support?

The Prestige does not limit the number of the users but the number of the
sessions. The P-661HW-D supports 1024 sessions that you can use the 'ip
nat session' command in CLI to see. You can also use 'ip nat hashTable
wanif0' to view the current active NAT sessions.

15. What are Device filters and Protocol filters?

In ZyNOS, the filters have been separated into two groups. One group is
called 'device filter group', and the other is called 'protocol filter
group'. Generic filters belong to the 'device filter group', TCP/IP and IPX filters
belong to the 'protocol filter group'. You can configure the filter rule in CLI.
Note: In ZyNOS, you can not mix different filter groups in the same filter set.

16. How can I protect against IP spoofing attacks?

The P-661HW-D's filter sets provide a means to protect against IP spoofing
attacks. The basic scheme is as follows:
For the input data filter:
• Deny packets from the outside that claim to be from the inside
All contents copyright © 2006 ZyXEL Communications Corporation.
P-661HW-D Series Support Notes
11

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents