ACL, NAT และ Firewall เป็นเทคโนโลยีที่พบได้บ่อยบน Network Edge และมักถูกเข้าใจว่าเป็นระบบรักษาความปลอดภัยแบบเดียวกัน แต่ในความเป็นจริงทั้งสามมีหน้าที่แตกต่างกัน: ACL ใช้กำหนดเงื่อนไขและกรอง Traffic, NAT ใช้แปลง Address ส่วน Stateful Firewall สามารถติดตามสถานะของ Connection เพื่อบังคับใช้ Security Policy ได้ละเอียดกว่า
บทความนี้จะเปรียบเทียบ Packet Filtering, Address Translation และ Stateful Inspection พร้อม Cisco Configuration, Packet Flow, Lab และ Troubleshooting เพื่อเตรียมพื้นฐานก่อนเข้าสู่ Cisco Zone-Based Firewall
สารบัญ
- ACL, NAT และ Firewall ต่างกันอย่างไร?
- ACL คืออะไร?
- Stateless Packet Filtering
- NAT คืออะไร?
- Firewall คืออะไร?
- Stateful Inspection คืออะไร?
- เปรียบเทียบ ACL vs NAT vs Firewall
- ตัวอย่าง Packet Flow
- Return Traffic ต่างกันอย่างไร?
- Lab 1: Extended ACL
- Lab 2: NAT/PAT
- ออกแบบ Internet Edge
- NAT ไม่ใช่ Firewall
- Troubleshooting
- Cisco Command Cheat Sheet
- FAQ
- บทสรุป
ภาค 1: ACL, NAT และ Firewall คืออะไร?
ACL, NAT และ Firewall ต่างกันอย่างไร?
เริ่มจากมองหน้าที่หลัก ของแต่ละเทคโนโลยี:
ACL
|
+-- Match / Permit / Deny Traffic
NAT
|
+-- Translate Address / Port
Firewall
|
+-- Enforce Security Policy
and often track sessions
ดังนั้นทั้งสามสามารถทำงานร่วมกันได้ โดยไม่จำเป็นต้องเลือกใช้ เพียงอย่างใดอย่างหนึ่ง
ตัวอย่าง Internet Edge:
Users
|
v
LAN
|
v
Router / Firewall
|
+-- Routing
|
+-- ACL / Policy
|
+-- NAT / PAT
|
+-- Stateful Inspection
|
v
ISP
|
v
Internet
ภาค 2: ACL และ Packet Filtering
ACL คืออะไร?
ACL — Access Control List คือชุดกฎที่ใช้ Match Traffic ตามข้อมูลบางอย่างใน Packet แล้วดำเนินการตามที่กำหนด เช่น Permit หรือ Deny
ตัวอย่าง Extended ACL:
ip access-list extended USERS-IN
permit tcp 192.168.10.0 0.0.0.255 any eq 443
permit udp 192.168.10.0 0.0.0.255 any eq 53
deny ip any any
ACL นี้แสดงแนวคิดว่า อนุญาต HTTPS และ DNS จาก Network ที่กำหนด จากนั้นปฏิเสธ IP Traffic อื่น ที่ไม่ Match Rule ก่อนหน้า
ACL ตรวจอะไรได้บ้าง?
Extended IPv4 ACL สามารถ Match ข้อมูลได้หลายประเภท เช่น:
- Protocol
- Source IP
- Destination IP
- TCP/UDP Port ตาม Syntax ที่รองรับ
- เงื่อนไขเพิ่มเติมบางประเภทตาม Platform
ตัวอย่าง:
Source:
192.168.10.10
Destination:
10.20.20.10
Protocol:
TCP
Destination Port:
443
ACL สามารถสร้าง Rule เช่น:
permit tcp 192.168.10.0 0.0.0.255 host 10.20.20.10 eq 443
Stateless Packet Filtering คืออะไร?
ACL แบบดั้งเดิมโดยทั่วไป พิจารณา Packet ตาม Rule ที่กำหนด โดยไม่ได้ทำ Stateful Session Tracking ในรูปแบบเดียวกับ Stateful Firewall
ตัวอย่าง:
Client
192.168.10.10
|
| TCP connection
v
Web Server
198.51.100.20:443
ขาออก:
192.168.10.10:51000
|
v
198.51.100.20:443
ขากลับ:
198.51.100.20:443
|
v
192.168.10.10:51000
ถ้ามี ACL กรองทั้งสองทิศทาง Administrator ต้องเข้าใจว่า Return Traffic จะ Match กฎใดในทิศทางกลับ
ACL อ่าน Rule จากบนลงล่าง
ตัวอย่าง:
10 permit tcp 192.168.10.0 0.0.0.255 any eq 443
20 deny ip 192.168.10.0 0.0.0.255 any
30 permit ip any any
Packet จะถูกตรวจตามลำดับ และเมื่อ Match Rule แล้ว จะใช้ Action ของ Rule นั้น โดยไม่ตรวจ Rule ถัดไป ใน ACL เดียวกันสำหรับ Packet นั้น
Packet
|
v
Rule 10 match?
|
NO
|
v
Rule 20 match?
|
YES
|
v
DENY
STOP
ท้าย ACL มีแนวคิด Implicit Deny หากไม่มี Rule ใด Match
ภาค 3: NAT และ Address Translation
NAT คืออะไร?
NAT — Network Address Translation ใช้แปลง Network Address ระหว่างเครือข่าย
ตัวอย่าง PAT:
192.168.10.10:51000
|
|
v
NAT
|
|
v
203.0.113.2:30001
|
v
Internet
NAT ไม่ได้มีหน้าที่หลัก ในการตัดสินว่า User คนใดควรเข้าถึง Application ใด
หน้าที่หลักคือ:
Before Translation
|
v
Address / Port
|
v
NAT
|
v
Translated Address / Port
ทำไม NAT ถึงใช้ ACL ได้?
ตัวอย่างจาก PAT:
access-list 10 permit 192.168.10.0 0.0.0.255
ip nat inside source list 10 interface GigabitEthernet0/1 overload
ACL หมายเลข 10 ในกรณีนี้ถูกใช้เพื่อ ระบุ Source Addresses ที่เข้าเงื่อนไข NAT
ไม่ได้หมายความว่า ACL นี้ เป็น Firewall Policy ที่อนุญาต Traffic ออก Internet ทั้งหมด
| ACL ถูกนำไปใช้กับ | ความหมาย |
|---|---|
| NAT | ใช้ Match Traffic ที่จะถูก Translation |
| Interface | ใช้ Permit/Deny Traffic ตามทิศทางที่ Apply |
| Routing/Security Feature | อาจใช้เป็น Classification ตาม Feature นั้น |
permit หรือ deny
ภาค 4: Stateful Firewall
Firewall คืออะไร?
Firewall เป็นระบบที่ใช้ บังคับใช้ Security Policy ระหว่าง Network, Zone, Host หรือ Application ตามความสามารถของอุปกรณ์
แนวคิดพื้นฐาน:
Trusted Network
|
v
+----------------+
| Firewall |
| Security Policy|
+----------------+
|
v
Untrusted Network
Firewall สมัยใหม่ อาจรองรับความสามารถหลายระดับ เช่น:
- Packet Filtering
- Stateful Inspection
- NAT
- Zone-Based Policy
- Application Awareness
- VPN
- Threat Inspection ตาม Platform
- Logging และ Monitoring
Stateful Inspection คืออะไร?
Stateful Firewall สามารถติดตามสถานะ ของ Connection หรือ Session ตาม Protocol และ Feature ที่รองรับ
ตัวอย่าง:
PC-A
192.168.10.10
|
| TCP SYN
v
Firewall
|
| Create / track state
v
Web Server
198.51.100.20:443
เมื่อ Response กลับมา:
Web Server
198.51.100.20:443
|
| Return Traffic
v
Firewall
|
| Existing valid state?
|
YES
|
v
PC-A
192.168.10.10
Firewall สามารถใช้ข้อมูล เกี่ยวกับ Session ที่เริ่มต้นไว้ ประกอบการตัดสินใจ กับ Return Traffic
ตัวอย่าง TCP Connection
Client Server
| |
| -------- SYN ---------> |
| |
| <----- SYN/ACK -------- |
| |
| -------- ACK ---------> |
| |
| ===== DATA FLOW ======= |
| |
Stateful Firewall ไม่ได้มองเพียง Source/Destination แบบแยก Packet เท่านั้น แต่สามารถรักษาข้อมูล State ที่เกี่ยวข้องกับ Flow ตามความสามารถของระบบ
ภาค 5: เปรียบเทียบ ACL, NAT และ Firewall
ตารางเปรียบเทียบ
| คุณสมบัติ | ACL | NAT/PAT | Stateful Firewall |
|---|---|---|---|
| หน้าที่หลัก | Match / Filter Traffic | Address Translation | Security Policy Enforcement |
| Permit / Deny | ได้เมื่อใช้ใน Filtering Context | ไม่ใช่หน้าที่หลัก | ได้ |
| แปลง IP | ไม่ใช่หน้าที่ | ใช่ | อาจรองรับ NAT |
| แปลง Port | ไม่ใช่หน้าที่ | PAT ทำได้ | อาจรองรับผ่าน NAT/PAT Feature |
| ติดตาม Session | Traditional ACL ไม่ได้ทำแบบ Stateful Firewall | มี Translation State แต่ไม่เท่ากับ Security Session Inspection | ใช่ ตาม Feature ที่รองรับ |
| Security Policy | พื้นฐาน | ไม่ใช่เป้าหมายหลัก | เป็นหน้าที่หลัก |
| Return Traffic | ต้องพิจารณา Rule/Direction | Translation Table ช่วย Mapping | สามารถใช้ Session State |
| ใช้ร่วมกันได้ | ได้ | ได้ | ได้ |
Translation State ไม่เท่ากับ Firewall State
นี่เป็นจุดที่สำคัญมาก
PAT มี Translation Table:
Inside Local
192.168.10.10:51000
<=>
Inside Global
203.0.113.2:30001
Table นี้ช่วย Router ทราบว่า Return Traffic ควรถูก Translate กลับไปหา Host ใด
แต่ไม่ควรสรุปว่า NAT Translation Table เท่ากับ Stateful Firewall
NAT State
|
+-- Translation mapping
Firewall State
|
+-- Security/session context
used for policy enforcement
ภาค 6: ตัวอย่าง Packet Flow
เมื่อ PC เปิด HTTPS ไป Internet เกิดอะไรขึ้น?
Topology:
PC-A
192.168.10.10
|
v
SW1
|
v
Router / Firewall
|
v
ISP
|
v
Internet Server
198.51.100.20
PC สร้าง Packet:
Source:
192.168.10.10:51000
Destination:
198.51.100.20:443
ใน Architecture หนึ่ง ระบบอาจต้องประเมินองค์ประกอบ เช่น:
Routing
|
Security Policy
|
NAT / PAT
|
Forwarding
|
Outside Network
แต่ลำดับ Processing จริง ไม่ควรอนุมานจาก Diagram นี้ โดยตรง
Return Traffic ต่างกันอย่างไร?
สมมติ Client เริ่ม HTTPS Session:
Client ---> Server
Traditional ACL
Outbound packet
|
v
ACL rule
|
Permit
|
v
Server
Return packet
|
v
Relevant ACL
|
v
Must match applicable rule
NAT/PAT
Outbound
192.168.10.10:51000
|
v
Translation
|
v
203.0.113.2:30001
Return
203.0.113.2:30001
|
v
Translation Table
|
v
192.168.10.10:51000
Stateful Firewall
Outbound session allowed
|
v
State created
|
v
Return traffic
|
v
Belongs to valid state?
|
YES
|
v
Process according to policy/state
ภาค 7: Cisco Lab — Extended ACL
Lab 1: จำกัด Guest Network
Topology:
Guest VLAN
192.168.30.0/24
|
v
R1
|
+------ Corporate LAN
|
+------ Internet
ต้องการ:
- Guest ห้ามเข้า Corporate Server 192.168.20.10
- Guest สามารถส่ง Traffic อื่นตาม Policy ที่กำหนด
ตัวอย่าง Named ACL:
ip access-list extended GUEST-IN
deny ip 192.168.30.0 0.0.0.255 host 192.168.20.10
permit ip 192.168.30.0 0.0.0.255 any
Apply Inbound:
interface GigabitEthernet0/0.30
ip access-group GUEST-IN in
ตรวจ:
show access-lists GUEST-IN
show ip interface GigabitEthernet0/0.30
ภาค 8: Cisco Lab — NAT/PAT
Lab 2: ให้ Users ออก Internet
Topology:
LAN
192.168.10.0/24
|
|
Gi0/0
NAT Inside
|
R1
|
Gi0/1
NAT Outside
|
|
ISP
LAN Interface:
interface GigabitEthernet0/0
ip address 192.168.10.1 255.255.255.0
ip nat inside
no shutdown
WAN Interface:
interface GigabitEthernet0/1
ip address 203.0.113.2 255.255.255.252
ip nat outside
no shutdown
NAT Classification:
access-list 10 permit 192.168.10.0 0.0.0.255
PAT:
ip nat inside source list 10 interface GigabitEthernet0/1 overload
Default Route:
ip route 0.0.0.0 0.0.0.0 203.0.113.1
ตรวจ:
show ip nat translations
show ip nat statistics
show access-lists
show ip route
203.0.113.0/24
เป็น Documentation Prefix
เหมาะสำหรับตัวอย่างและ Lab
ไม่ใช่ Public Address
สำหรับนำไป Deploy จริง
นำ ACL และ NAT มาใช้ร่วมกัน
สมมติ LAN ต้องการออก Internet
แต่ห้ามเข้าถึง Network
10.50.0.0/16
ผ่าน Interface ที่เกี่ยวข้อง
Filtering ACL:
ip access-list extended LAN-FILTER
deny ip 192.168.10.0 0.0.0.255 10.50.0.0 0.0.255.255
permit ip 192.168.10.0 0.0.0.255 any
Apply:
interface GigabitEthernet0/0
ip access-group LAN-FILTER in
NAT ACL:
access-list 10 permit 192.168.10.0 0.0.0.255
PAT:
ip nat inside source list 10 interface GigabitEthernet0/1 overload
จะเห็นว่า:
LAN-FILTER
|
+-- Security / filtering decision
ACL 10
|
+-- NAT classification
แม้ทั้งสองใช้ ACL แต่ทำหน้าที่คนละอย่าง เพราะถูก Reference จาก Feature คนละประเภท
ภาค 9: ออกแบบ Internet Edge
ACL + NAT + Firewall ใช้ร่วมกันอย่างไร?
ตัวอย่าง Architecture:
Internet
|
|
ISP
|
|
+--------------+
| Firewall |
| |
| Stateful |
| Policy |
| NAT / PAT |
+--------------+
/ \
/ \
DMZ LAN
| |
Web Server Users
ในระบบจริง Firewall อาจเป็นอุปกรณ์เฉพาะ หรือ Feature บนอุปกรณ์ Network Security Platform
อีก Architecture อาจแยก Router และ Firewall:
Internet
|
ISP
|
Edge Router
|
Firewall
|
Core
|
LAN
ไม่มี Topology เดียว ที่เหมาะกับทุกองค์กร การออกแบบขึ้นอยู่กับ:
- Security Requirements
- Internet Circuits
- High Availability
- Throughput
- VPN
- DMZ
- Public Services
- Operational Complexity
- Budget
ทำไม NAT ไม่ใช่ Firewall?
สมมติ PAT:
192.168.10.10
192.168.10.20
192.168.10.30
|
v
PAT
|
v
203.0.113.2
PAT ช่วย Translation และ Multiplex Sessions ผ่าน Global Address
แต่คำถามด้าน Security คือ:
Who may communicate?
To where?
Using which protocol?
Using which service?
From which zone?
Under which state?
Should it be logged?
Should content be inspected?
คำถามเหล่านี้เป็นเรื่อง Security Policy ไม่ใช่ Address Translation เพียงอย่างเดียว
Firewall ไม่ได้แทน Routing
แม้ Firewall จะอนุญาต Traffic แต่ถ้าไม่มี Route:
Policy = PERMIT
but
Route = NONE
|
v
Traffic cannot reach
the intended destination
เช่นเดียวกับ NAT:
NAT configured
+
ACL correct
+
Firewall permit
BUT
No route
=
Connectivity fails
ภาค 10: Troubleshooting
เมื่อ Internet ใช้งานไม่ได้ อย่าโทษ Firewall ก่อน
ควรตรวจอย่างเป็นระบบ:
Client
|
v
IP / Mask correct?
|
v
Default Gateway?
|
v
VLAN?
|
v
Layer 3 Routing?
|
v
ACL?
|
v
NAT?
|
v
Firewall Policy?
|
v
Default Route?
|
v
ISP?
|
v
Return Path?
|
v
DNS?
|
v
Application?
ปัญหา 1 — ACL Block Traffic
ตรวจ:
show access-lists
show ip interface
ดูว่า:
- ACL ถูก Apply ที่ Interface ใด
- Inbound หรือ Outbound
- Rule Order ถูกต้องหรือไม่
- Hit Counter เพิ่มหรือไม่
- มี Implicit Deny หรือไม่
ปัญหา 2 — NAT ไม่สร้าง Translation
ตรวจ:
show ip nat translations
show ip nat statistics
show access-lists
ตรวจต่อ:
- NAT Inside
- NAT Outside
- NAT ACL
- Source Network
- NAT Rule
- Routing
ปัญหา 3 — NAT ทำงาน แต่ Traffic ยังไม่ได้
ตรวจ:
show ip route
ping
traceroute
จากนั้นตรวจ:
- Firewall Policy
- Upstream Route
- Return Path
- Remote Service
- DNS
ปัญหา 4 — Outbound ใช้ได้ แต่ Inbound ไม่ได้
อย่าคาดหวังว่า PAT Outbound จะเปิด Inbound Service ให้ Server โดยอัตโนมัติ
หากต้อง Publish Server อาจต้องมี:
Public / Translated Address
+
Static NAT / Static PAT
+
Routing
+
Firewall Policy
+
Server Firewall
+
Application Service
ปัญหา 5 — เปิด Firewall แล้วก็ยังเข้าไม่ได้
Firewall Permit เป็นเพียงหนึ่งเงื่อนไข
Firewall = Permit
NAT = Wrong
|
v
FAIL
Firewall = Permit
Route = Missing
|
v
FAIL
Firewall = Permit
Server Service = Down
|
v
FAIL
แยกอาการให้ถูกว่าเป็น ACL, NAT หรือ Firewall
| อาการ | ควรตรวจ |
|---|---|
| Traffic ถูก Block ตาม Source/Destination | ACL / Firewall Policy |
| Private Address ไม่ถูก Translate | NAT Rule / NAT ACL / Inside-Outside |
| ไม่มี Translation Entry | NAT Configuration และ Traffic Match |
| Return Session ถูก Block | ACL Direction / Stateful Firewall / Routing |
| Policy Permit แต่ไปไม่ได้ | Routing / NAT / Upstream / Return Path |
| Public Server เข้าไม่ได้ | Static NAT/PAT, Firewall, Routing, Server Service |
| IP ใช้ได้แต่ Domain ไม่ได้ | DNS |
Cisco Command Cheat Sheet
| Command | ใช้ตรวจ |
|---|---|
show access-lists |
ACL Rules และ Counters |
show ip interface |
ACL ที่ Apply กับ Interface |
show ip interface brief |
Interface และ IP Status |
show ip route |
Routing Table |
show ip route <destination> |
Route ไปยัง Destination |
show ip nat translations |
NAT Translation Table |
show ip nat statistics |
NAT Statistics |
show running-config | include ip nat |
NAT Configuration บางส่วน |
ping |
Reachability Test |
traceroute |
Path Diagnosis โดยประมาณ |
ภาค 11: หลักการออกแบบ
อย่าใช้ NAT แทน Security Policy
แนวคิดที่ไม่ควรใช้:
"มี NAT แล้ว
Network ปลอดภัย"
ควรแยกหน้าที่:
Routing
|
+-- Find path
ACL
|
+-- Match / filter traffic
NAT
|
+-- Translate addresses
Firewall
|
+-- Enforce security policy
and inspect state
Least Privilege
Security Policy ที่ดี ควรอนุญาตเฉพาะ Traffic ที่จำเป็นตาม Requirement แทนการเปิดทุกอย่าง แล้วค่อย Block ภายหลัง เมื่อทำได้อย่างเหมาะสม
ตัวอย่าง:
Users
|
+--> DNS Required
|
+--> HTTPS Required
|
+--> Database Not required
|
+--> Admin SSH Not required
Policy ควรสะท้อน Business Requirement และ Network Architecture จริง
Network Segmentation
ตัวอย่าง Zone:
INTERNET
|
v
+---------+
|Firewall |
+---------+
/ | \
/ | \
v v v
LAN DMZ GUEST
แต่ละ Zone สามารถมี Trust Level และ Policy แตกต่างกัน
แนวคิดนี้เป็นพื้นฐานสำคัญ ก่อนเข้าสู่ Zone-Based Firewall
คำถามที่พบบ่อย — FAQ
ACL กับ Firewall เหมือนกันหรือไม่?
ไม่เหมือนกันทั้งหมด Traditional ACL ใช้ Match และ Filter Packet ตาม Rule ที่กำหนด ส่วน Stateful Firewall สามารถติดตาม Connection State และบังคับใช้ Security Policy ตามความสามารถของระบบ
NAT คือ Firewall หรือไม่?
ไม่ NAT มีหน้าที่หลัก ในการแปลง Address หรือ Address/Port ส่วน Firewall มีหน้าที่หลัก ในการบังคับใช้ Security Policy
PAT มี State แล้วทำไมไม่ถือว่าเป็น Stateful Firewall?
PAT ต้องมี Translation State เพื่อ Mapping Sessions กลับไปยัง Inside Host แต่ Translation State ไม่ได้เท่ากับ Security Inspection State และไม่ได้แทน Firewall Policy
ถ้ามี Firewall ยังต้องใช้ ACL หรือไม่?
ขึ้นอยู่กับ Architecture และ Platform ACL ยังสามารถใช้กับ Interface, NAT Classification, Routing Feature หรือ Security Feature อื่นได้ แม้ระบบจะมี Firewall อยู่แล้ว
ถ้ามี NAT แล้วจำเป็นต้องมี ACL หรือไม่?
ขึ้นอยู่กับ NAT Configuration และ Security Requirement บาง NAT Rule ใช้ ACL สำหรับ Classification แต่ ACL ดังกล่าว ไม่ได้หมายความว่าเป็น Security Filtering Policy เสมอไป
ACL Permit ใน NAT หมายความว่าอนุญาตผ่าน Firewall หรือไม่?
ไม่ ต้องดู Context ACL ที่ถูก Reference โดย NAT มักใช้เลือก Traffic ที่เข้าเงื่อนไข Translation ไม่ใช่การอนุญาตผ่าน Firewall Policy โดยอัตโนมัติ
Stateful Firewall รู้ได้อย่างไรว่า Return Traffic เกี่ยวข้องกับ Session เดิม?
Firewall เก็บ State Information ของ Flow หรือ Connection ตาม Protocol และ Feature ที่รองรับ แล้วใช้ข้อมูลนั้น ประกอบการตรวจสอบ Traffic ที่ตามมา
มี Firewall Permit แล้วทำไมยังใช้งานไม่ได้?
เพราะ Connectivity ยังขึ้นอยู่กับ Routing, NAT, VLAN, Gateway, Return Path, DNS, Server Service และองค์ประกอบอื่น Firewall Permit ไม่ได้สร้าง Route หรือแก้ Application Failure
ควรใช้ ACL หรือ Firewall ป้องกัน Guest Network?
ขึ้นอยู่กับ Requirement ACL สามารถใช้สร้าง Packet Filtering พื้นฐานได้ ส่วน Firewall เหมาะเมื่อ ต้องการ Stateful Policy, Zone Segmentation, Logging หรือ Security Functions เพิ่มเติมตาม Platform
Firewall สามารถทำ NAT ได้หรือไม่?
Firewall หลาย Platform รองรับ NAT/PAT แต่รายละเอียด Feature, Syntax และ Processing แตกต่างกันตามผู้ผลิต และ Software Version
ACL, NAT และ Firewall ควร Troubleshoot อะไรก่อน?
ควรเริ่มจาก Layer พื้นฐาน: IP Address, VLAN, Gateway, Interface และ Routing ก่อนตรวจ ACL, NAT, Firewall Policy, DNS และ Application ตามลำดับ ที่เหมาะกับ Topology
บทสรุป
ACL, NAT และ Firewall ทำงานเกี่ยวข้องกับ Packet เหมือนกัน แต่มีวัตถุประสงค์ต่างกัน
ACL
|
v
Which traffic matches?
Permit or deny?
NAT
|
v
Which address / port
should be translated?
Firewall
|
v
Should this communication
be allowed under
the security policy?
ACL:
Packet
|
v
Rules
|
+-- Permit
|
+-- Deny
NAT:
Private / Inside Address
|
v
Translation
|
v
Translated Address
Stateful Firewall:
Connection
|
v
Security Policy
|
v
Session State
|
v
Controlled Traffic Flow
จุดที่ควรจำมากที่สุดคือ:
NAT != Firewall
Translation State
!=
Firewall Security State
Permit in NAT ACL
!=
Firewall Permit
Network Edge ที่ออกแบบดี จึงต้องมองหลายองค์ประกอบร่วมกัน:
VLAN
+
Routing
+
ACL
+
NAT / PAT
+
Firewall
+
High Availability
+
Logging
+
Monitoring
เมื่อเข้าใจความแตกต่าง ระหว่าง ACL, NAT และ Firewall แล้ว หัวข้อถัดไปคือ Cisco Zone-Based Firewall (ZBF) ซึ่งจะนำแนวคิด Inside, Outside, Security Zone, Class Map, Policy Map, Zone Pair และ Stateful Inspection มาสร้าง Firewall Policy บน Cisco Router อย่างเป็นระบบ
Share your thoughts here
Join the conversation and share your perspective on this article.