18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 52: Example<br />

network<br />

Chapter 4: Understanding Policy Configuration<br />

IP Filter rule basics<br />

Using NAT and redirection for IP Filter rules<br />

Many organizations use network address translation (NAT) and/or redirection<br />

to prevent internal addresses from being visible to external users. On the<br />

<strong>Sidewinder</strong> <strong>G2</strong>, NAT refers to rewriting the source address <strong>of</strong> the packet to the<br />

external address <strong>of</strong> the <strong>Sidewinder</strong> <strong>G2</strong> (or an address you specify). This allows<br />

you to protect (or hide) the actual client source address, and in the case <strong>of</strong><br />

non-routable source addresses (such as 10.0.0.0) rewrite it to an address that<br />

can be routed on the Internet. Redirection refers to rewriting the destination<br />

address <strong>of</strong> an incoming packet to a redirect host for delivery.<br />

Note: NAT and redirection function independently <strong>of</strong> one another. For applications<br />

that allow either side <strong>of</strong> a connection to act as the client, you will generally create<br />

two rules: one using NAT, and one using redirection.<br />

Caution: Allowing IP Filter to pass traffic without NAT or redirection is possible<br />

assuming all addresses are routable. However, it is not recommended because it<br />

will expose internal addresses to the external side <strong>of</strong> your <strong>Sidewinder</strong> <strong>G2</strong> without<br />

the protection <strong>of</strong> a proxy.<br />

When NAT or redirection is enabled in a rule, the source address in the rule is<br />

always protected, as follows:<br />

• For a rule <strong>of</strong> source -> destination, enabling NAT will “hide” the source<br />

address from the destination for traffic originating from the source by<br />

translating that address to the external address <strong>of</strong> the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

• For a rule <strong>of</strong> source -> redirect address, the destination (or external<br />

<strong>Sidewinder</strong> <strong>G2</strong> address) will be redirected to the actual source address and<br />

hides the redirected address for traffic returning to the source.<br />

Note: NAT or redirection are not allowed for bi-directional IP Filter rules with<br />

stateful inspection enabled.<br />

For the following scenarios, assume your network looks like this:<br />

172.17.0.0<br />

internal network<br />

172.17.129.130 10.11.12.13<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

192.101.0.0<br />

external network<br />

125

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!