18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 4-8. IP Filtering on<br />

TCP/UDP packets<br />

TCP/UDP<br />

packet<br />

in<br />

does a<br />

session<br />

exist?<br />

yes<br />

translate as<br />

required<br />

perform<br />

session<br />

processing<br />

forward<br />

message w/o<br />

further<br />

processing<br />

no<br />

match<br />

“allow”<br />

rule?<br />

add a<br />

session<br />

perform<br />

additional<br />

processing<br />

Using NAT and redirection for IP Filter rules<br />

IP Filter rule basics<br />

Many organizations use network address translation (NAT) and/or<br />

redirection to prevent internal addresses from being visible to external<br />

users. On the <strong>Sidewinder</strong> <strong>G2</strong>, NAT refers to rewriting the source<br />

address <strong>of</strong> the packet to the external address <strong>of</strong> the <strong>Sidewinder</strong> <strong>G2</strong> (or<br />

an address you specify). This allows you to protect (or hide) the<br />

actual client source address, and in the case <strong>of</strong> non-routable source<br />

addresses (such as 10.0.0.0) rewrite it to an address that can be routed<br />

on the Internet. Redirection refers to rewriting the destination address<br />

<strong>of</strong> an incoming packet to a redirect host for delivery.<br />

yes<br />

no<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

out<br />

Understanding Policy Configuration 4-31

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!