
P-660HN Series Support Notes
10
All contents copyright © 2010 ZyXEL Communications Corporation.
ILA1<--->IGA1
ILA2<--->IGA2
ILA3<--->IGA1
ILA4<--->IGA2
...
ILA1<--->IGA1
ILA2<--->IGA2
ILA3<--->IGA3
ILA4<--->IGA4
...
Server 1 IP<--->IGA1
Server 2 IP<--->IGA1
13. How many network users can the SUA/NAT support?
The Prestige does not limit the number of the users but the number of the
sessions. The P-660HN-T1A supports 4k sessions that you can use the 'ip nat
session' command in CLI to see. You can also use „ip nat hashTable wanif0‟
to view the current active NAT sessions.
14. What are Device filters and Protocol filters?
The filters have been separated into two groups. One group is called 'device
filter group', and the other is called 'protocol filter group'. Generic filters
belong to the 'device filter group', TCP/IP and IPX filters belong to the 'protocol
filter group'. You can configure the filter rule in CLI.
15. How can I protect against IP spoofing attacks?
The P-660HN-T1A's filter sets provide a means to protect against IP spoofing
attacks. The basic scheme is as follows:
For the input data filter:
Deny packets from the outside that claim to be from the inside
Allow everything that is not spoofing us
Filter rule setup:
Filter type =TCP/IP Filter Rule
Active =Yes
Source IP Addr =a.b.c.d
Source IP Mask =w.x.y.z
Action Matched =Drop