Corporate Firewall is an excellent, cost effective firewall to protect publicly accessible web, email and extranet servers. Most such servers are normally accessed via a dedicated public IP address, the support of which requires the addition of Corporate Firewall's SmoothHost module.
SmoothHost allows you to configure multiple public IP addresses on the external (Red/Internet) network interface - no restriction is imposed on the number of public IP addresses that can be configured. Port Forward rules are then created to forward traffic from a port or port range on a public IP address through to the actual server operating behind the firewall. The servers themselves operate on private IP addresses which are not revealed beyond the firewall, thus disguising the true identity of the server from potential attackers. Normally these servers should be situated in a De-Militarized Zone (DMZ), as this isolates the servers from user computers and file/application servers upon which confidential information is stored. Corporate Firewall's Intrusion Detection System (IDS) checks incoming traffic to for any suspicious activity indicating that a server is under attack.
The Port Forward rules allow restrictions to be placed on the external source IP addresses from which data will be accepted, which can be used to block all access to extranet and web servers except from pre-configured locations like company offices. This facility can also be used to restrict external access to local network computers using remote assistance tools like VNC.
Static Network Address Translation (SNAT), often known as one-to-one NAT or source mapping, is another feature provided by SmoothHost. With SNAT, the firewall can be configured so that it will always send the outgoing traffic for one or more computers via a specific public IP address, rather than use the default IP address of the external (Red/Internet) network connection. This can be configured by either IP address, IP address range or network address for computers on the local protected network or DMZ. A typical use of SNAT is to ensure that outgoing mail from an SMTP mail-server originates from the correct public IP address, as specified by the DNS information for the mail-server.
SmoothHost is an integrated component of Advanced Firewall.
|