30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Traffic Policy<br />

Figure 7.37<br />

Service definition without inspector protocol<br />

Figure 7.38<br />

This traffic rule allows accessing service without protocol inspection<br />

Note: In the default configuration of the Traffic rules section, the Protocol inspector column<br />

is hidden. To show it, modify settings through the Modify columns dialog (see chapter 3.3).<br />

Warning:<br />

To disable a protocol inspector, it is not sufficient to define a service that would not use<br />

the inspector! Protocol inspectors are applied to all traffic performed by corresponding<br />

protocols by default. To disable a protocol inspector, special traffic rules must be defined.<br />

7.8 Use of Full cone NAT<br />

However, many applications (especially applications working with multimedia, Voice over IP<br />

technologies, etc.) use another traffic method where other clients can (with direct connection<br />

established) connect to a port “opened” by an outgoing packet. For these cases, <strong>Kerio</strong> Control<br />

includes a special mode of address translation, known as Full cone NAT. In this mode,<br />

opened port can be accessed from any IP address and the traffic is always redirected to<br />

a corresponding client in the local network.<br />

Use of Full cone NAT may bring certain security risk. Each connection established in this mode<br />

opens a possible passage from the Internet to the local network. To keep the security as high<br />

108

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!