
Configuration and Management
4.7.2 Application Level Gateways
From a security perspective, certain Internet applications, for example FTP
applications that open additional ports upon transfer, are especially
problematic to handle. An Application Level Gateway (ALG) provides a
translation and transportation service for such a specific application.
Incoming data packets are checked against existing NAT and packet
filtering rules, IP addresses are evaluated and a detailed packet analysis is
performed. If necessary, the contents of a packet are modified and if a
secondary port is required, the ALG will open one. The Ericsson W25
includes ALG support for the following applications:
Table 4 ALG Supported Applications
Application Protocol Port
number
File Transfer Protocol (FTP) TCP 21
Trivial File Transfer Protocol (TFTP) UDP 69
The ALG for each application does not require additional configuration. The
supported ALGs can be enabled and disabled individually. To disable an
ALG, clear the corresponding check box on the
NAT page and click
Apply .
4.7.3 Port Forwarding
Port forwarding (sometimes referred to as tunneling) is used to allow an
external user to reach a port on a private IP address (inside a LAN) from
the outside via a NAT-enabled router (Ericsson W25).
When a computer on the Internet sends data to the public IP address of
Ericsson W25, it needs to know what to do with the data. Port Forwarding
tells Ericsson W25 which computer on the local area network to send the
data to.
Note: Port forwarding requires a public IP address of the Ericsson W25.
The Ericsson W25 IP address is displayed on the
Internet page. A
private IP address usually begins with
10, 172, or 192. In this
case, no incoming access from the Internet is allowed. For more
information on public and private IP addresses, contact your
service provider.
38 5/1551-CRH 102 167 Uen Rev B 2007-02-01
Comentarios a estos manuales