
Configuring BaySecure FireWall-1
1-2
117384-D Rev 00
How the Firewall Software Works
The management station downloads the policy information to the stateful
inspection module in the Bay Networks router software. The stateful inspection
module inspects all data packets traveling between the data link and network
layers, and communicates the results to the management station. (Note that the
management station does not inspect the packets.) If the data packets meet the
security requirements specified in the security policy, the router forwards the data.
If the data packets violate the security policy, the router drops the data packets and
logs the information to the management station.
Using Backup Management Stations
You can use the Bay Command Console (BCC
™
) to configure up to two backup
management stations. Doing so provides the redundancy required to use
FireWall-1 in large enterprise networks. If your router loses communication with
its firewall management station, a backup firewall management station
automatically establishes communication with the router. As a result, firewall
security remains intact and firewall statistics logging continues.
BaySecure FireWall-1 does not require a backup management station to remain
dormant until called into service when the firewall management station fails. A
backup management station can simultaneously be a working firewall
management station for another firewall.
Comentários a estes Manuais