ZyXEL Communications P-2602HW-63C Guía de usuario Pagina 203

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 465
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 202
Chapter 14 Firewalls
P-2602H(W)(L)-DxA User’s Guide
203
If an initiation packet originates on the LAN, this means that someone is trying to make a
connection from the LAN to the Internet. Assuming that this is an acceptable part of the
security policy (as is the case with the default policy), the connection will be allowed. A cache
entry is added which includes connection information such as IP addresses, TCP ports,
sequence numbers, etc.
When the ZyXEL Device receives any subsequent packet (from the Internet or from the LAN),
its connection information is extracted and checked against the cache. A packet is only
allowed to pass through if it corresponds to a valid connection (that is, if it is a response to a
connection which originated on the LAN).
14.5.4 UDP/ICMP Security
UDP and ICMP do not themselves contain any connection information (such as sequence
numbers). However, at the very minimum, they contain an IP address pair (source and
destination). UDP also contains port pairs, and ICMP has type and code information. All of
this data can be analyzed in order to build "virtual connections" in the cache.
For instance, any UDP packet that originates on the LAN will create a cache entry. Its IP
address and port pairs will be stored. For a short period of time, UDP packets from the WAN
that have matching IP and UDP information will be allowed back in through the firewall.
A similar situation exists for ICMP, except that the ZyXEL Device is even more restrictive.
Specifically, only outgoing echoes will allow incoming echo replies, outgoing address mask
requests will allow incoming address mask replies, and outgoing timestamp requests will
allow incoming timestamp replies. No other ICMP packets are allowed in through the firewall,
simply because they are too dangerous and contain too little tracking information. For
instance, ICMP redirect packets are never allowed in, since they could be used to reroute
traffic through attacking machines.
14.5.5 Upper Layer Protocols
Some higher layer protocols (such as FTP and RealAudio) utilize multiple network
connections simultaneously. In general terms, they usually have a "control connection" which
is used for sending commands between endpoints, and then "data connections" which are used
for transmitting bulk information.
Consider the FTP protocol. A user on the LAN opens a control connection to a server on the
Internet and requests a file. At this point, the remote server will open a data connection from
the Internet. For FTP to work properly, this connection must be allowed to pass through even
though a connection from the Internet would normally be rejected.
In order to achieve this, the ZyXEL Device inspects the application-level FTP data.
Specifically, it searches for outgoing "PORT" commands, and when it sees these, it adds a
cache entry for the anticipated data connection. This can be done safely, since the PORT
command contains address and port information, which can be used to uniquely identify the
connection.
Any protocol that operates in this way must be supported on a case-by-case basis. You can use
the web configurator’s Custom Ports feature to do this.
Vista de pagina 202
1 2 ... 198 199 200 201 202 203 204 205 206 207 208 ... 464 465

Comentarios a estos manuales

Sin comentarios

Husqvarna 324LDX-Series manuals

Owner’s manuals and user’s guides for Petrol tool Husqvarna 324LDX-Series.
We providing 1 pdf manuals Husqvarna 324LDX-Series for download free by document types: User Manual






More products and manuals for Petrol tool Husqvarna

Models Document Type
318 User Manual   Husqvarna 318 User Manual, 24 pages
372XP EPA II User Manual   Husqvarna 372XP EPA II User Manual, 44 pages
340 User Manual   Husqvarna 340 User Manual [en] , 52 pages
445 User Manual   Husqvarna 445 User Manual, 44 pages
355 User Manual   Husqvarna 355 User Manual, 36 pages
1153136-95 User Manual   Husqvarna 1153136-95 User Manual, 36 pages
1153158-95 User Manual   Husqvarna 1153158-95 User Manual, 44 pages
345e EPA III User Manual   Husqvarna 345e EPA III User Manual, 44 pages
55 User Manual   Husqvarna 55 User Manual, 40 pages
346XP 351 User Manual   Husqvarna 346XP 351 User Manual, 36 pages
339XP User Manual   Husqvarna 339XP User Manual, 44 pages
1153183-95 User Manual   Husqvarna 1153183-95 User Manual, 44 pages
325P4 User Manual   Husqvarna 325P4 User Manual, 28 pages
1153181-95 User Manual   Husqvarna 1153181-95 User Manual, 44 pages
335XPT User Manual   Husqvarna 335XPT User Manual, 36 pages
357XP User Manual   Husqvarna 357XP User Manual, 36 pages
346XP/ 351 User Manual   Husqvarna 346XP/ 351 User Manual, 44 pages
40 User Manual   Husqvarna 40 User Manual [en] , 36 pages
536 LIXP User Manual   Husqvarna 536 LIXP User Manual, 44 pages
140 User Manual       Husqvarna 140 User Manual, 420 pages