
22 C
HAPTER
1: I
NTRODUCTION
Figure 2 Firewall Security Functions - Default Firewall Policy
The Firewall examines every packet that comes from outside the LAN and
discards any packet that has not been authorized from inside the LAN.
This is known as stateful packet inspection.
Users on the LAN have access to all resources on the Internet that are not
blocked by any of the filters.
Users on the Internet can access hosts on the DMZ, such as a Web server,
but cannot access any resources on the LAN unless they are authorized
remote users.
LAN DMZ WAN
STOP
DoS Attacks Blocked
Web Access Allowed
Unauthorised External Access Blocked
Authorised External Access using VPN (Encrypted)
STOP
STOP
Internet Access Filtered (optional)
LAN
Normal
Uplink
DMZ
Normal
Uplink
WAN
Normal
Uplink
DMZ Port - Connected
to public servers e.g.
Web, E-mail
Protected from DoS
attacks but visible from
outside your network.
LAN Port - Connected
to your internal
network e.g. network
servers, workstations.
Protected from DoS
attacks and invisible from
outside your network.
WAN Port - Connected to
an external network or
the Internet via an
Internet access device.
The other ports are
protected from DoS attacks
originating on this port.
DUA1611-0AAA02.book Page 22 Thursday, August 2, 2001 4:01 PM
Komentáře k této Příručce