Techerest

ACL, NAT และ Firewall ต่างกันอย่างไร? เข้าใจ Packet Filtering และ Stateful Firewall

ACL, NAT และ Firewall เป็นเทคโนโลยีที่พบได้บ่อยบน Network Edge และมักถูกเข้าใจว่าเป็นระบบรักษาความปลอดภัยแบบเดียวกัน แต่ในความเป็นจริงทั้งสามมีหน้าที่แตกต่างกัน: ACL ใช้กำหนดเงื่อนไขและกรอง Traffic, NAT ใช้แปลง Address ส่วน Stateful Firewall สามารถติดตามสถานะของ Connection เพื่อบังคับใช้ Security Policy ได้ละเอียดกว่า

บทความนี้จะเปรียบเทียบ Packet Filtering, Address Translation และ Stateful Inspection พร้อม Cisco Configuration, Packet Flow, Lab และ Troubleshooting เพื่อเตรียมพื้นฐานก่อนเข้าสู่ Cisco Zone-Based Firewall

ภาค 1: ACL, NAT และ Firewall คืออะไร?

ACL, NAT และ Firewall ต่างกันอย่างไร?

เริ่มจากมองหน้าที่หลัก ของแต่ละเทคโนโลยี:

ACL
 |
 +-- Match / Permit / Deny Traffic


NAT
 |
 +-- Translate Address / Port


Firewall
 |
 +-- Enforce Security Policy
     and often track sessions

ดังนั้นทั้งสามสามารถทำงานร่วมกันได้ โดยไม่จำเป็นต้องเลือกใช้ เพียงอย่างใดอย่างหนึ่ง

ตัวอย่าง Internet Edge:

Users
  |
  v
 LAN
  |
  v
Router / Firewall
  |
  +-- Routing
  |
  +-- ACL / Policy
  |
  +-- NAT / PAT
  |
  +-- Stateful Inspection
  |
  v
 ISP
  |
  v
Internet
ลำดับใน Diagram นี้ใช้เพื่ออธิบาย หน้าที่เชิงสถาปัตยกรรม ไม่ใช่ Packet Processing Order แบบตายตัว เพราะลำดับการประมวลผลจริง ขึ้นอยู่กับ Platform, Feature และ Software ของอุปกรณ์

ภาค 2: ACL และ Packet Filtering

ACL คืออะไร?

ACL — Access Control List คือชุดกฎที่ใช้ Match Traffic ตามข้อมูลบางอย่างใน Packet แล้วดำเนินการตามที่กำหนด เช่น Permit หรือ Deny

ตัวอย่าง Extended ACL:

ip access-list extended USERS-IN
 permit tcp 192.168.10.0 0.0.0.255 any eq 443
 permit udp 192.168.10.0 0.0.0.255 any eq 53
 deny ip any any

ACL นี้แสดงแนวคิดว่า อนุญาต HTTPS และ DNS จาก Network ที่กำหนด จากนั้นปฏิเสธ IP Traffic อื่น ที่ไม่ Match Rule ก่อนหน้า

ACL ตรวจอะไรได้บ้าง?

Extended IPv4 ACL สามารถ Match ข้อมูลได้หลายประเภท เช่น:

  • Protocol
  • Source IP
  • Destination IP
  • TCP/UDP Port ตาม Syntax ที่รองรับ
  • เงื่อนไขเพิ่มเติมบางประเภทตาม Platform

ตัวอย่าง:

Source:
192.168.10.10

Destination:
10.20.20.10

Protocol:
TCP

Destination Port:
443

ACL สามารถสร้าง Rule เช่น:

permit tcp 192.168.10.0 0.0.0.255 host 10.20.20.10 eq 443

Stateless Packet Filtering คืออะไร?

ACL แบบดั้งเดิมโดยทั่วไป พิจารณา Packet ตาม Rule ที่กำหนด โดยไม่ได้ทำ Stateful Session Tracking ในรูปแบบเดียวกับ Stateful Firewall

ตัวอย่าง:

Client
192.168.10.10

     |
     | TCP connection
     v

Web Server
198.51.100.20:443

ขาออก:

192.168.10.10:51000
        |
        v
198.51.100.20:443

ขากลับ:

198.51.100.20:443
        |
        v
192.168.10.10:51000

ถ้ามี ACL กรองทั้งสองทิศทาง Administrator ต้องเข้าใจว่า Return Traffic จะ Match กฎใดในทิศทางกลับ

อย่าสรุปว่า ACL ทุกชนิด บนทุก Cisco Platform เป็น Stateless เหมือนกันทั้งหมด Cisco มี Security Features หลายประเภทที่สามารถทำงาน ร่วมกับ ACL และ Session State ได้ บทความนี้กำลังเปรียบเทียบ Traditional ACL Packet Filtering กับ Stateful Firewall เป็นหลัก

ACL อ่าน Rule จากบนลงล่าง

ตัวอย่าง:

10 permit tcp 192.168.10.0 0.0.0.255 any eq 443
20 deny ip 192.168.10.0 0.0.0.255 any
30 permit ip any any

Packet จะถูกตรวจตามลำดับ และเมื่อ Match Rule แล้ว จะใช้ Action ของ Rule นั้น โดยไม่ตรวจ Rule ถัดไป ใน ACL เดียวกันสำหรับ Packet นั้น

Packet
  |
  v
Rule 10 match?
  |
 NO
  |
  v
Rule 20 match?
  |
 YES
  |
  v
DENY

STOP

ท้าย ACL มีแนวคิด Implicit Deny หากไม่มี Rule ใด Match

ภาค 3: NAT และ Address Translation

NAT คืออะไร?

NAT — Network Address Translation ใช้แปลง Network Address ระหว่างเครือข่าย

ตัวอย่าง PAT:

192.168.10.10:51000
        |
        |
        v
      NAT
        |
        |
        v
203.0.113.2:30001
        |
        v
     Internet

NAT ไม่ได้มีหน้าที่หลัก ในการตัดสินว่า User คนใดควรเข้าถึง Application ใด

หน้าที่หลักคือ:

Before Translation
        |
        v
Address / Port
        |
        v
NAT
        |
        v
Translated Address / Port

ทำไม NAT ถึงใช้ ACL ได้?

ตัวอย่างจาก PAT:

access-list 10 permit 192.168.10.0 0.0.0.255

ip nat inside source list 10 interface GigabitEthernet0/1 overload

ACL หมายเลข 10 ในกรณีนี้ถูกใช้เพื่อ ระบุ Source Addresses ที่เข้าเงื่อนไข NAT

ไม่ได้หมายความว่า ACL นี้ เป็น Firewall Policy ที่อนุญาต Traffic ออก Internet ทั้งหมด

ACL ถูกนำไปใช้กับ ความหมาย
NAT ใช้ Match Traffic ที่จะถูก Translation
Interface ใช้ Permit/Deny Traffic ตามทิศทางที่ Apply
Routing/Security Feature อาจใช้เป็น Classification ตาม Feature นั้น
ACL เป็นกลไก Match/Policy ที่นำไปใช้ได้หลาย Context ดังนั้นต้องดูว่า ACL ถูก Reference โดย Feature ใดก่อนตีความคำว่า permit หรือ deny

ภาค 4: Stateful Firewall

Firewall คืออะไร?

Firewall เป็นระบบที่ใช้ บังคับใช้ Security Policy ระหว่าง Network, Zone, Host หรือ Application ตามความสามารถของอุปกรณ์

แนวคิดพื้นฐาน:

Trusted Network
      |
      v
+----------------+
|    Firewall    |
| Security Policy|
+----------------+
      |
      v
Untrusted Network

Firewall สมัยใหม่ อาจรองรับความสามารถหลายระดับ เช่น:

  • Packet Filtering
  • Stateful Inspection
  • NAT
  • Zone-Based Policy
  • Application Awareness
  • VPN
  • Threat Inspection ตาม Platform
  • Logging และ Monitoring

Stateful Inspection คืออะไร?

Stateful Firewall สามารถติดตามสถานะ ของ Connection หรือ Session ตาม Protocol และ Feature ที่รองรับ

ตัวอย่าง:

PC-A
192.168.10.10
    |
    | TCP SYN
    v
Firewall
    |
    | Create / track state
    v
Web Server
198.51.100.20:443

เมื่อ Response กลับมา:

Web Server
198.51.100.20:443
    |
    | Return Traffic
    v
Firewall
    |
    | Existing valid state?
    |
   YES
    |
    v
PC-A
192.168.10.10

Firewall สามารถใช้ข้อมูล เกี่ยวกับ Session ที่เริ่มต้นไว้ ประกอบการตัดสินใจ กับ Return Traffic

ตัวอย่าง TCP Connection

Client                    Server
  |                         |
  | -------- SYN ---------> |
  |                         |
  | <----- SYN/ACK -------- |
  |                         |
  | -------- ACK ---------> |
  |                         |
  | ===== DATA FLOW ======= |
  |                         |

Stateful Firewall ไม่ได้มองเพียง Source/Destination แบบแยก Packet เท่านั้น แต่สามารถรักษาข้อมูล State ที่เกี่ยวข้องกับ Flow ตามความสามารถของระบบ

ภาค 5: เปรียบเทียบ ACL, NAT และ Firewall

ตารางเปรียบเทียบ

คุณสมบัติ ACL NAT/PAT Stateful Firewall
หน้าที่หลัก Match / Filter Traffic Address Translation Security Policy Enforcement
Permit / Deny ได้เมื่อใช้ใน Filtering Context ไม่ใช่หน้าที่หลัก ได้
แปลง IP ไม่ใช่หน้าที่ ใช่ อาจรองรับ NAT
แปลง Port ไม่ใช่หน้าที่ PAT ทำได้ อาจรองรับผ่าน NAT/PAT Feature
ติดตาม Session Traditional ACL ไม่ได้ทำแบบ Stateful Firewall มี Translation State แต่ไม่เท่ากับ Security Session Inspection ใช่ ตาม Feature ที่รองรับ
Security Policy พื้นฐาน ไม่ใช่เป้าหมายหลัก เป็นหน้าที่หลัก
Return Traffic ต้องพิจารณา Rule/Direction Translation Table ช่วย Mapping สามารถใช้ Session State
ใช้ร่วมกันได้ ได้ ได้ ได้

Translation State ไม่เท่ากับ Firewall State

นี่เป็นจุดที่สำคัญมาก

PAT มี Translation Table:

Inside Local
192.168.10.10:51000

       <=>

Inside Global
203.0.113.2:30001

Table นี้ช่วย Router ทราบว่า Return Traffic ควรถูก Translate กลับไปหา Host ใด

แต่ไม่ควรสรุปว่า NAT Translation Table เท่ากับ Stateful Firewall

NAT State
   |
   +-- Translation mapping


Firewall State
   |
   +-- Security/session context
       used for policy enforcement

ภาค 6: ตัวอย่าง Packet Flow

เมื่อ PC เปิด HTTPS ไป Internet เกิดอะไรขึ้น?

Topology:

PC-A
192.168.10.10
      |
      v
    SW1
      |
      v
Router / Firewall
      |
      v
     ISP
      |
      v
Internet Server
198.51.100.20

PC สร้าง Packet:

Source:
192.168.10.10:51000

Destination:
198.51.100.20:443

ใน Architecture หนึ่ง ระบบอาจต้องประเมินองค์ประกอบ เช่น:

Routing
   |
Security Policy
   |
NAT / PAT
   |
Forwarding
   |
Outside Network

แต่ลำดับ Processing จริง ไม่ควรอนุมานจาก Diagram นี้ โดยตรง

Return Traffic ต่างกันอย่างไร?

สมมติ Client เริ่ม HTTPS Session:

Client ---> Server

Traditional ACL

Outbound packet
     |
     v
ACL rule
     |
   Permit
     |
     v
Server


Return packet
     |
     v
Relevant ACL
     |
     v
Must match applicable rule

NAT/PAT

Outbound
192.168.10.10:51000
        |
        v
Translation
        |
        v
203.0.113.2:30001


Return
203.0.113.2:30001
        |
        v
Translation Table
        |
        v
192.168.10.10:51000

Stateful Firewall

Outbound session allowed
        |
        v
State created
        |
        v
Return traffic
        |
        v
Belongs to valid state?
        |
       YES
        |
        v
Process according to policy/state

ภาค 7: Cisco Lab — Extended ACL

Lab 1: จำกัด Guest Network

Topology:

Guest VLAN
192.168.30.0/24
      |
      v
     R1
      |
      +------ Corporate LAN
      |
      +------ Internet

ต้องการ:

  • Guest ห้ามเข้า Corporate Server 192.168.20.10
  • Guest สามารถส่ง Traffic อื่นตาม Policy ที่กำหนด

ตัวอย่าง Named ACL:

ip access-list extended GUEST-IN
 deny ip 192.168.30.0 0.0.0.255 host 192.168.20.10
 permit ip 192.168.30.0 0.0.0.255 any

Apply Inbound:

interface GigabitEthernet0/0.30
 ip access-group GUEST-IN in

ตรวจ:

show access-lists GUEST-IN
show ip interface GigabitEthernet0/0.30
Lab นี้ใช้เพื่ออธิบาย ACL เท่านั้น ใน Production Guest Segmentation อาจควรใช้ Firewall, VRF, Wireless Policy, NAC หรือ Security Architecture อื่นร่วมด้วยตามความเสี่ยง

ภาค 8: Cisco Lab — NAT/PAT

Lab 2: ให้ Users ออก Internet

Topology:

LAN
192.168.10.0/24
      |
      |
   Gi0/0
  NAT Inside
      |
     R1
      |
   Gi0/1
 NAT Outside
      |
      |
     ISP

LAN Interface:

interface GigabitEthernet0/0
 ip address 192.168.10.1 255.255.255.0
 ip nat inside
 no shutdown

WAN Interface:

interface GigabitEthernet0/1
 ip address 203.0.113.2 255.255.255.252
 ip nat outside
 no shutdown

NAT Classification:

access-list 10 permit 192.168.10.0 0.0.0.255

PAT:

ip nat inside source list 10 interface GigabitEthernet0/1 overload

Default Route:

ip route 0.0.0.0 0.0.0.0 203.0.113.1

ตรวจ:

show ip nat translations
show ip nat statistics
show access-lists
show ip route
203.0.113.0/24 เป็น Documentation Prefix เหมาะสำหรับตัวอย่างและ Lab ไม่ใช่ Public Address สำหรับนำไป Deploy จริง

นำ ACL และ NAT มาใช้ร่วมกัน

สมมติ LAN ต้องการออก Internet แต่ห้ามเข้าถึง Network 10.50.0.0/16 ผ่าน Interface ที่เกี่ยวข้อง

Filtering ACL:

ip access-list extended LAN-FILTER
 deny ip 192.168.10.0 0.0.0.255 10.50.0.0 0.0.255.255
 permit ip 192.168.10.0 0.0.0.255 any

Apply:

interface GigabitEthernet0/0
 ip access-group LAN-FILTER in

NAT ACL:

access-list 10 permit 192.168.10.0 0.0.0.255

PAT:

ip nat inside source list 10 interface GigabitEthernet0/1 overload

จะเห็นว่า:

LAN-FILTER
     |
     +-- Security / filtering decision


ACL 10
     |
     +-- NAT classification

แม้ทั้งสองใช้ ACL แต่ทำหน้าที่คนละอย่าง เพราะถูก Reference จาก Feature คนละประเภท

ภาค 9: ออกแบบ Internet Edge

ACL + NAT + Firewall ใช้ร่วมกันอย่างไร?

ตัวอย่าง Architecture:

                  Internet
                     |
                     |
                    ISP
                     |
                     |
              +--------------+
              |   Firewall   |
              |              |
              | Stateful     |
              | Policy       |
              | NAT / PAT    |
              +--------------+
                 /        \
                /          \
              DMZ          LAN
               |            |
          Web Server      Users

ในระบบจริง Firewall อาจเป็นอุปกรณ์เฉพาะ หรือ Feature บนอุปกรณ์ Network Security Platform

อีก Architecture อาจแยก Router และ Firewall:

Internet
   |
 ISP
   |
Edge Router
   |
Firewall
   |
Core
   |
LAN

ไม่มี Topology เดียว ที่เหมาะกับทุกองค์กร การออกแบบขึ้นอยู่กับ:

  • Security Requirements
  • Internet Circuits
  • High Availability
  • Throughput
  • VPN
  • DMZ
  • Public Services
  • Operational Complexity
  • Budget

ทำไม NAT ไม่ใช่ Firewall?

สมมติ PAT:

192.168.10.10
192.168.10.20
192.168.10.30
       |
       v
      PAT
       |
       v
203.0.113.2

PAT ช่วย Translation และ Multiplex Sessions ผ่าน Global Address

แต่คำถามด้าน Security คือ:

Who may communicate?

To where?

Using which protocol?

Using which service?

From which zone?

Under which state?

Should it be logged?

Should content be inspected?

คำถามเหล่านี้เป็นเรื่อง Security Policy ไม่ใช่ Address Translation เพียงอย่างเดียว

Firewall ไม่ได้แทน Routing

แม้ Firewall จะอนุญาต Traffic แต่ถ้าไม่มี Route:

Policy = PERMIT

but

Route = NONE

       |
       v

Traffic cannot reach
the intended destination

เช่นเดียวกับ NAT:

NAT configured
      +
ACL correct
      +
Firewall permit

BUT

No route

=

Connectivity fails

ภาค 10: Troubleshooting

เมื่อ Internet ใช้งานไม่ได้ อย่าโทษ Firewall ก่อน

ควรตรวจอย่างเป็นระบบ:

Client
  |
  v
IP / Mask correct?
  |
  v
Default Gateway?
  |
  v
VLAN?
  |
  v
Layer 3 Routing?
  |
  v
ACL?
  |
  v
NAT?
  |
  v
Firewall Policy?
  |
  v
Default Route?
  |
  v
ISP?
  |
  v
Return Path?
  |
  v
DNS?
  |
  v
Application?

ปัญหา 1 — ACL Block Traffic

ตรวจ:

show access-lists
show ip interface

ดูว่า:

  • ACL ถูก Apply ที่ Interface ใด
  • Inbound หรือ Outbound
  • Rule Order ถูกต้องหรือไม่
  • Hit Counter เพิ่มหรือไม่
  • มี Implicit Deny หรือไม่

ปัญหา 2 — NAT ไม่สร้าง Translation

ตรวจ:

show ip nat translations
show ip nat statistics
show access-lists

ตรวจต่อ:

  • NAT Inside
  • NAT Outside
  • NAT ACL
  • Source Network
  • NAT Rule
  • Routing

ปัญหา 3 — NAT ทำงาน แต่ Traffic ยังไม่ได้

ตรวจ:

show ip route
ping
traceroute

จากนั้นตรวจ:

  • Firewall Policy
  • Upstream Route
  • Return Path
  • Remote Service
  • DNS

ปัญหา 4 — Outbound ใช้ได้ แต่ Inbound ไม่ได้

อย่าคาดหวังว่า PAT Outbound จะเปิด Inbound Service ให้ Server โดยอัตโนมัติ

หากต้อง Publish Server อาจต้องมี:

Public / Translated Address
        +
Static NAT / Static PAT
        +
Routing
        +
Firewall Policy
        +
Server Firewall
        +
Application Service

ปัญหา 5 — เปิด Firewall แล้วก็ยังเข้าไม่ได้

Firewall Permit เป็นเพียงหนึ่งเงื่อนไข

Firewall = Permit

NAT = Wrong
        |
        v
FAIL


Firewall = Permit

Route = Missing
        |
        v
FAIL


Firewall = Permit

Server Service = Down
        |
        v
FAIL

แยกอาการให้ถูกว่าเป็น ACL, NAT หรือ Firewall

อาการ ควรตรวจ
Traffic ถูก Block ตาม Source/Destination ACL / Firewall Policy
Private Address ไม่ถูก Translate NAT Rule / NAT ACL / Inside-Outside
ไม่มี Translation Entry NAT Configuration และ Traffic Match
Return Session ถูก Block ACL Direction / Stateful Firewall / Routing
Policy Permit แต่ไปไม่ได้ Routing / NAT / Upstream / Return Path
Public Server เข้าไม่ได้ Static NAT/PAT, Firewall, Routing, Server Service
IP ใช้ได้แต่ Domain ไม่ได้ DNS

Cisco Command Cheat Sheet

Command ใช้ตรวจ
show access-lists ACL Rules และ Counters
show ip interface ACL ที่ Apply กับ Interface
show ip interface brief Interface และ IP Status
show ip route Routing Table
show ip route <destination> Route ไปยัง Destination
show ip nat translations NAT Translation Table
show ip nat statistics NAT Statistics
show running-config | include ip nat NAT Configuration บางส่วน
ping Reachability Test
traceroute Path Diagnosis โดยประมาณ
คำสั่ง Debug บน Router หรือ Firewall อาจสร้าง Load และ Log จำนวนมาก โดยเฉพาะ Production Network จึงควรใช้เฉพาะเมื่อเข้าใจผลกระทบ และมีขอบเขตการ Troubleshoot ที่ชัดเจน

ภาค 11: หลักการออกแบบ

อย่าใช้ NAT แทน Security Policy

แนวคิดที่ไม่ควรใช้:

"มี NAT แล้ว
Network ปลอดภัย"

ควรแยกหน้าที่:

Routing
  |
  +-- Find path


ACL
  |
  +-- Match / filter traffic


NAT
  |
  +-- Translate addresses


Firewall
  |
  +-- Enforce security policy
      and inspect state

Least Privilege

Security Policy ที่ดี ควรอนุญาตเฉพาะ Traffic ที่จำเป็นตาม Requirement แทนการเปิดทุกอย่าง แล้วค่อย Block ภายหลัง เมื่อทำได้อย่างเหมาะสม

ตัวอย่าง:

Users
  |
  +--> DNS       Required
  |
  +--> HTTPS     Required
  |
  +--> Database  Not required
  |
  +--> Admin SSH Not required

Policy ควรสะท้อน Business Requirement และ Network Architecture จริง

Network Segmentation

ตัวอย่าง Zone:

INTERNET
    |
    v
+---------+
|Firewall |
+---------+
 /   |    \
/    |     \
v    v      v
LAN  DMZ   GUEST

แต่ละ Zone สามารถมี Trust Level และ Policy แตกต่างกัน

แนวคิดนี้เป็นพื้นฐานสำคัญ ก่อนเข้าสู่ Zone-Based Firewall

คำถามที่พบบ่อย — FAQ

ACL กับ Firewall เหมือนกันหรือไม่?

ไม่เหมือนกันทั้งหมด Traditional ACL ใช้ Match และ Filter Packet ตาม Rule ที่กำหนด ส่วน Stateful Firewall สามารถติดตาม Connection State และบังคับใช้ Security Policy ตามความสามารถของระบบ

NAT คือ Firewall หรือไม่?

ไม่ NAT มีหน้าที่หลัก ในการแปลง Address หรือ Address/Port ส่วน Firewall มีหน้าที่หลัก ในการบังคับใช้ Security Policy

PAT มี State แล้วทำไมไม่ถือว่าเป็น Stateful Firewall?

PAT ต้องมี Translation State เพื่อ Mapping Sessions กลับไปยัง Inside Host แต่ Translation State ไม่ได้เท่ากับ Security Inspection State และไม่ได้แทน Firewall Policy

ถ้ามี Firewall ยังต้องใช้ ACL หรือไม่?

ขึ้นอยู่กับ Architecture และ Platform ACL ยังสามารถใช้กับ Interface, NAT Classification, Routing Feature หรือ Security Feature อื่นได้ แม้ระบบจะมี Firewall อยู่แล้ว

ถ้ามี NAT แล้วจำเป็นต้องมี ACL หรือไม่?

ขึ้นอยู่กับ NAT Configuration และ Security Requirement บาง NAT Rule ใช้ ACL สำหรับ Classification แต่ ACL ดังกล่าว ไม่ได้หมายความว่าเป็น Security Filtering Policy เสมอไป

ACL Permit ใน NAT หมายความว่าอนุญาตผ่าน Firewall หรือไม่?

ไม่ ต้องดู Context ACL ที่ถูก Reference โดย NAT มักใช้เลือก Traffic ที่เข้าเงื่อนไข Translation ไม่ใช่การอนุญาตผ่าน Firewall Policy โดยอัตโนมัติ

Stateful Firewall รู้ได้อย่างไรว่า Return Traffic เกี่ยวข้องกับ Session เดิม?

Firewall เก็บ State Information ของ Flow หรือ Connection ตาม Protocol และ Feature ที่รองรับ แล้วใช้ข้อมูลนั้น ประกอบการตรวจสอบ Traffic ที่ตามมา

มี Firewall Permit แล้วทำไมยังใช้งานไม่ได้?

เพราะ Connectivity ยังขึ้นอยู่กับ Routing, NAT, VLAN, Gateway, Return Path, DNS, Server Service และองค์ประกอบอื่น Firewall Permit ไม่ได้สร้าง Route หรือแก้ Application Failure

ควรใช้ ACL หรือ Firewall ป้องกัน Guest Network?

ขึ้นอยู่กับ Requirement ACL สามารถใช้สร้าง Packet Filtering พื้นฐานได้ ส่วน Firewall เหมาะเมื่อ ต้องการ Stateful Policy, Zone Segmentation, Logging หรือ Security Functions เพิ่มเติมตาม Platform

Firewall สามารถทำ NAT ได้หรือไม่?

Firewall หลาย Platform รองรับ NAT/PAT แต่รายละเอียด Feature, Syntax และ Processing แตกต่างกันตามผู้ผลิต และ Software Version

ACL, NAT และ Firewall ควร Troubleshoot อะไรก่อน?

ควรเริ่มจาก Layer พื้นฐาน: IP Address, VLAN, Gateway, Interface และ Routing ก่อนตรวจ ACL, NAT, Firewall Policy, DNS และ Application ตามลำดับ ที่เหมาะกับ Topology

บทสรุป

ACL, NAT และ Firewall ทำงานเกี่ยวข้องกับ Packet เหมือนกัน แต่มีวัตถุประสงค์ต่างกัน

ACL
 |
 v
Which traffic matches?
Permit or deny?


NAT
 |
 v
Which address / port
should be translated?


Firewall
 |
 v
Should this communication
be allowed under
the security policy?

ACL:

Packet
  |
  v
Rules
  |
  +-- Permit
  |
  +-- Deny

NAT:

Private / Inside Address
        |
        v
   Translation
        |
        v
Translated Address

Stateful Firewall:

Connection
     |
     v
Security Policy
     |
     v
Session State
     |
     v
Controlled Traffic Flow

จุดที่ควรจำมากที่สุดคือ:

NAT != Firewall

Translation State
      !=
Firewall Security State

Permit in NAT ACL
      !=
Firewall Permit

Network Edge ที่ออกแบบดี จึงต้องมองหลายองค์ประกอบร่วมกัน:

VLAN
  +
Routing
  +
ACL
  +
NAT / PAT
  +
Firewall
  +
High Availability
  +
Logging
  +
Monitoring

เมื่อเข้าใจความแตกต่าง ระหว่าง ACL, NAT และ Firewall แล้ว หัวข้อถัดไปคือ Cisco Zone-Based Firewall (ZBF) ซึ่งจะนำแนวคิด Inside, Outside, Security Zone, Class Map, Policy Map, Zone Pair และ Stateful Inspection มาสร้าง Firewall Policy บน Cisco Router อย่างเป็นระบบ

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.