Network Address Translation; Packet Filters; Session Redirectors; Valid Times - SMC Networks ELITECONNECT SMC2502W User Manual

Wlan security system
Hide thumbs Also See for ELITECONNECT SMC2502W:
Table of Contents

Advertisement

Passive Authentication
Alternatively, you can choose one of the following passive methods for user-level
authentication. The following all require user-level authentication and the
EliteConnect WLAN Security System can use these authentication services for its
own user authentication:
• NT/2000 domain login
• 802.1x authentication
• PPTP MS-CHAP, or MS-CHAP v2 authentication
• L2TP MS-CHAP or MS-CHAP v2 authentication
1.2.4
Rights
At any given time, for each client attached to a WLAN Access Manager, a certain
set of rights is in effect. These rights are based on the powerful packet-matching
language of the tcpdump utility program. A rights package contains the following
main components: Network Address Translation (NAT) setting, Mode Setting,
Packet Filters, and Session Redirectors. Each set of rights has a valid time.

Network Address Translation

A WLAN Access Manager provides Network Address Translation (NAT) services
for users who request DHCP IP address when they initiate connection to the
Access Manager.
When a client sends a packet through the WLAN Access Manager, the WLAN
Access Manager rewrites the IP address field and the port number field to a value
that is unique and that will identify any return packet.
Depending on the application, you can choose to use the NAT service or you can
choose to assign your own IP address. Following are some points in favor of and
against using NAT:
• NAT makes roaming much more efficient. The WLAN Security System can move
the entire connection state from one WLAN Access Manager to the roamed-to
WLAN Access Manager, and only tunnel open sessions back through the
original WLAN Access Manager. MobileIP as a solution to roaming suffers
because every connection has to be tunneled back through the original
connection point.
• NAT provides some amount of protection to a client since no device other than
the WLAN Access Manager can talk directly to the client. This provides
rudimentary firewall protection.
• Certain applications require a host or server system to know the actual IP
address of a client. Some examples include multi-player games, file transfer in
Instant Messenger applications, and other peer-to-peer applications.
1-6
Introduction

Advertisement

Table of Contents
loading

This manual is also suitable for:

Eliteconnect smc2504w2502w - annexe 12504w - annexe 1

Table of Contents