Re: Process Switching vs. Fast/CEF Switching?



On Sun, 27 May 2007 19:53:10 GMT, asdf <asdf@xxxxxxxx> wrote for the entire planet to
see:
<snip>
I will be using a router to NAT outbound LAN web traffic using ext
access lists. This router will also destination NAT inbound traffic to
various web services based on ext access lists. If a packet doesn't get
NATed by the router, it won't have anywhere to arrive on my network.

Is what I am describing "Process Switching", or "Fast/CEF Switching"?
If it is Process Switching, the pdf would indicate it doesn't really
matter whether I get a 1720 or a 2621XM (other than that I have to deal
with counterfeit WIC-1ENET modules on eBay to give the 1700 two NAT sides).

NAT is handled by CEF on those models. Access lists too. These is some process
overhead to set up NAT and a flow, but only on the initial packets.


.



Relevant Pages

  • Re: Windows as Proxy Server vs. other firewall approaches.....
    ... NAT is stateful by definition. ... Here's how an incoming packet is handled: ... Where the SPI firewall becomes criticaly important is when the router is ... > knows that it is a proxy server. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Duane Arnold re: SPI
    ... > router's NAT, which has the ability to drop them. ... The NAT takes the packet that was sent to ... the router the packet belongs too. ... have SPI that didn't work and has been completely removed from the firmware. ...
    (comp.security.firewalls)
  • Re: NAT and Keep State IP Rule
    ... > My router is a NAT router, I can also set a number of IP rules and ... You need to understand what NAT and Stateful Packet Inspection does, ... traffic never becomes WAN traffic leaving the network out to the Internet ...
    (comp.security.firewalls)
  • Re: protocol xx unreachable
    ... a tcpdump on the external interface shows a "protocol xx ... The routers in between cannot decode/mangle the packet without the endpoints ... For IPSec you should look at NAT-T which more or less wraps ... The ICMP packets are sent by the source (your router?) as here is some ...
    (comp.os.linux.networking)
  • Re: protocol xx unreachable
    ... a tcpdump on the external interface shows a "protocol xx ... The routers in between cannot decode/mangle the packet without the endpoints ... For IPSec you should look at NAT-T which more or less wraps ... The ICMP packets are sent by the source (your router?) as here is some ...
    (comp.os.linux.security)