10.12.2012 Views

Administration HiPath 3000/5000 V7 IP systems

Administration HiPath 3000/5000 V7 IP systems

Administration HiPath 3000/5000 V7 IP systems

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>3000</strong>sb4.fm<br />

For internal use only <strong>HiPath</strong> <strong>3000</strong>/<strong>5000</strong> in the LAN Network<br />

HG 1500 V3.0<br />

4.5.9.2 Network Address Translation (NAT)<br />

Network Address Translation (NAT) is the conversion of <strong>IP</strong> addresses in the LAN for the Internet.<br />

HG 1500 V3.0 provides NAT for Internet connections via a second Ethernet interface as<br />

well as for PPP connections via B channels.<br />

As far as the Internet is concerned, the entire LAN appears to be a single <strong>IP</strong> address and can<br />

therefore use a common dial-up connection to an ISP, for example. Additionally, direct <strong>IP</strong> attacks<br />

from the Internet on terminals in the LAN are not possible.<br />

NAT can be enabled and disabled in the HG 1500 V3.0. Certain services – such as Vo<strong>IP</strong> or video<br />

telephony – embed subscribers’ <strong>IP</strong> addresses in their data packets, however, instead of just<br />

noting them in the packet headers. They are only compatible with NAT within a VPN.<br />

4.5.9.3 Access Protection<br />

A variety of security functions are available to prevent unauthorized usage:<br />

Checking Caller Numbers<br />

Connections from the PSTN can be checked against a list of known users using the caller number.<br />

Users whose connections do not transmit a caller number (for example analog telephones)<br />

can call an MSN that is set up especially for them.<br />

Callback<br />

All users can be configured so that they can be called back. Thus, PPP connections are only<br />

possible from a predefined connection.<br />

User Account and Password<br />

After setting up a connection, the user account and password can be checked using PAP (Password<br />

Authentication Protocol), CHAP (Challenge Handshake Authentication Protocol) or MSC-<br />

HAP (Microsoft Challenge Handshake Authentication Protocol.<br />

HG 1500 V3.0 also supports these protocols as a client when dialing in to a RAS server (for<br />

example with an ISP).<br />

<strong>IP</strong> Address Filter for Communication with the LAN<br />

<strong>IP</strong> address filters can be defined to prevent attacks on devices in the LAN, both from insecure<br />

(external) networks and from within the LAN. When <strong>IP</strong> filtering is activated, access is only possible<br />

from address ranges that have explicit permission, and this access is only possible to<br />

specified addresses. Optionally, access can be further limited to a specific protocol port.<br />

P31003-H3570-Y100-4-7618, 2007-10-31<br />

<strong>HiPath</strong> <strong>3000</strong>/<strong>5000</strong> <strong>V7</strong>, System Description 4-33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!