Installation guide

Chapter 2: About the HSIM-W84
2-12 HSIM-W84 Installation Guide
IEEE 802.1d Bridging The HSIM-W84 supports the IEEE 802.1d standard for LAN to LAN
bridging. This bridging algorithm learns the low-level MAC addresses of each LAN constituent
and uses this information to decide whether to transmit the packet to another LAN via a WAN
connection, or keep it local. Part of the bridging standard used, called Spanning Tree Protocol,
supports multiple, redundant paths for LAN to LAN bridging, yet prevents data loops and
duplication. This adds fault tolerance to a system of LANs, since, if one WAN data path fails,
another may be substituted automatically.
IP Routing IP routing support provides the ability to process TCP/IP frames at the network
layer for routing. IP routing support includes the Routing Information Protocol (RIP) that allows
the exchange of routing information on a TCP/IP network. The HSIM-W84 receives and
broadcasts RIP messages to adjacent routers and workstations.
IPX Routing Internet Packet Exchange (IPX) routing support provides the ability to process
Novell proprietary frames at the network layer for routing. IPX routing support includes the
Routing Information Protocol (RIP) that allows the exchange of routing information on a Novell
NetWare network.
Bridging and Routing Protocol Filtering
Filtering is used to allow efficient usage of network resources and provide security for your
network and hosts.
IP Internet Firewall The HSIM-W84 supports IP Internet Firewall filtering to prevent
unauthorized access to your system and network resources from the Internet or a corporate
Intranet. Security can be configured to permit or deny IP traffic. The security is established by
configuring IP access filters, which are based on source IP address, source mask, destination IP
address, destination mask, protocol type, and application port identifiers for both the Transmission
Control Protocol (TCP) and User Datagram Protocol (UDP). These IP access filters allow
individual IP source and destination pair filtering as well as IP address ranges and wild carding to
match any IP address. These Firewall filters can be defined to allow inbound only, outbound only,
or bi-directional IP communication up to the UDP and TCP application port level. Firewall access
filters provide a lot of flexibility to establish a powerful IP security barrier.
The HSIM-W84 supports the IP Access Control (from the ctip-mib) Internet Firewall Filter.
Bridge Filtering Bridge filtering allows a network administrator to control the flow of packets
across the HSIM-W84. Bridge filtering can be used to “deny” or “allow” packets based on a
“matched pattern” using a specified position and hexadecimal content within the packet. This
enables restricting or forwarding of messages based on address, protocol, or data content.