18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IP Filter rule basics<br />

Figure 4-9. Example<br />

network<br />

4-32 Understanding Policy Configuration<br />

Note: NAT and redirection function independently <strong>of</strong> one another. For applications that<br />

allow either side <strong>of</strong> a connection to act as the client, you will generally create two rules: one<br />

using NAT, and one using redirection.<br />

Caution: Allowing IP Filter to pass traffic without NAT or redirection is possible assuming<br />

all addresses are routable. However, it is not recommended because it will expose internal<br />

addresses to the external side <strong>of</strong> your <strong>Sidewinder</strong> <strong>G2</strong>.<br />

When NAT or redirection is enabled in a rule, the source address in<br />

the rule is always protected, as follows:<br />

For a rule <strong>of</strong> source-> destination, enabling NAT will "hide" the<br />

source address from the destination for traffic originating from the<br />

source by translating that address to the external address <strong>of</strong> the<br />

<strong>Sidewinder</strong> <strong>G2</strong>.<br />

For a rule <strong>of</strong> source -> redirect address, the destination (or external<br />

<strong>Sidewinder</strong> <strong>G2</strong> address) will be redirected to the actual source<br />

address and hides the redirected address for traffic returning to the<br />

source.<br />

Note: NAT or redirection are not allowed for bi-directional TCP/UDP IP Filter rules with<br />

session tracking enabled.<br />

For the following scenarios, assume your network looks like this:<br />

172.17.0.0 internal<br />

network<br />

172.17.129.130 10.11.12.13<br />

<strong>Sidewinder</strong><br />

<strong>G2</strong><br />

Limitations <strong>of</strong> NAT for IP Filter TCP/UDP protocols<br />

192.101.0.0<br />

external network<br />

Note the following limitations when setting up rules involving address<br />

rewriting for TCP/UDP protocols.<br />

NAT and redirection are not allowed for bi-directional TCP/UDP IP<br />

Filter rules with session tracking enabled.<br />

For address rewrite rules with redirection to the source address,<br />

only uni-directional rules are allowed. Furthermore, the destination<br />

address in this type <strong>of</strong> rule must have a significant bits value <strong>of</strong> 32<br />

(that is, it must be a single host). This is because the redirect<br />

address must be a single host.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!