User Manual

SPEEDLAN 9000 Series Installation and Operation User Guide Version 3.03
General Functions of the Configurator 3-61
Make sure you define at least one virtual address prior to using 1:1 NAT. To
define a virtual address, see Virtual Addresses, page 3-24.
The elements on this page are described below:
Interface and Host: This table lists the name of the interface and host IP
addresses assigned to the wired and wireless interfaces.
External Address: This lists the IP address on the "outside" network. (In the
previous figure, the user entered "13.13.13.14" for the virtual address.)
Internal Address: Enter the IP address for the inside or private network. This
address "hides" behind the public IP address you selected. (In the previous
figure, the user entered "192.168.69.88" for the internal IP address.)
Existing 1:1 NAT Mappings
To remove a 1:1 NAT mapping, select its check box and click Delete Selected. Click
All to select all 1:1 NAT mappings. Click None to clear all selections.
Firewall
The SPEEDLAN 9000 (via the SPEEDLAN 9000 Configurator) allows you to control
incoming and outgoing traffic.
A firewall prevents unauthorized access to a network. Utilizing the SPEEDLAN 9000
Configurator, SPEEDLAN 9000 routers can increase security and provide additional
support to the users of the network. In addition, it may help prevent dangerous packets
from intruding on a network that contains sensitive data. It does this by analyzing the
network traffic that is permitted or not permitted to enter the firewall based on
pre-established rules.
The firewall contains a checklist, and it filters traffic that enters and exits the firewall
based on the rules you set (e.g., allowing or denying certain source/destination
combinations). When traffic passes through the firewall, the firewall starts at the top of
its checklist and looks for the rule that matches its criteria. Traffic that meets the criteria
in the checklist will be permitted, and traffic that does not meet the criteria in the
checklist will be blocked. This feature allows you to restrict specific network packets
from entering or leaving your network.