3Com 3CR858-91 Network Router User Manual


 
Firewall 51
Special Applications — Special Applications allows you to specify ports
to be open for specific applications to work properly with the Network
Address Translation (NAT) feature of the Router. See “Special
Applications” on page 54.
Virtual Servers — This function enables you to route external (Internet)
calls for services such as a web server, FTP server, or other applications
through your Router to your internal network. See “Virtual Servers”
on page 56
.
Client IP Filters — You can configure the Router to restrict access to
the Internet, e-mail or other network services at specific days and
times. Restriction can be set for a single computer, a range of
computers, or multiple computers. See “Client IP Filters”
on page 57.
MAC Address Filtering — This is a powerful security feature that
allows you to specify which computers are allowed on the network.
See “MAC Address Filtering”
on page 62.
DMZ (De-Militarized Zone) — If you have a client PC that cannot run
an Internet application properly from behind the firewall, you can use
DMZ to open the client up to unrestricted two-way Internet access.
See “DMZ”
on page 63.
CAUTION: DMZ reduces network security, and 3Com recommends you
only use it on a temporary basis.
SPI Stateful Packet Inspection (SPI) inspects, and if required blocks packets at
the application layer. SPI also maintains TCP and UDP session information,
including timeouts and the number of active sessions, and provides the
ability to detect and prevent certain types of network attacks such as DoS
attacks.
Denial of Service (DoS) attacks are aimed at devices and networks with a
connection to the Internet. The goal is not to steal information, but to
disable a device or network so users no longer have access to network
resources.