Firewall PC Card 13Fragmented Packets--Denies fragmented packets.IP Options--Denies packets with IP options. These packets are usually used fornetwork testing and debugging.In addition to these features, the Firewall PC Card products are also “locationaware”. This allows a security administrator to provide varying levels of securitydepending on where the notebook computer is located. A strict policy can beimplemented while the notebook computer is outside of the perimeter firewall,and a less restrictive one can be in place while the notebook is inside theperimeter.Enabling the Firewall Until you enable the firewall functionality of the 3Com Firewall PC Card with10/100LAN, it will emulate the functions of a standard network interface card.Enabling the firewall functionality requires the 3Com Embedded Firewall PolicyServer.The 3Com Embedded Firewall Policy Server allows you to create a cryptographicbinding between the Firewall Client Devices and the Policy Server. This preventssomeone from installing a central management console and taking control of yourFirewall Client Devices.When you create a customized installation package, the following cryptographicfunctions are preformed:1 When the Policy Server is installed, it generates an RSA 1024 Public/Private keypair.The public key is written to the Firewall Client Device flash memory.2 When the Firewall Client Device boots up, it generates a random 3DES session key,encrypts that key with the policy server’s public key, and then sends thatinformation to the policy server.3 The policy server decrypts the message using its private key, and then implementsthe random 3DES session key as communicated by the Firewall Client Device.4 This cryptographic binding adds to the tamper resistance of the 3Com EmbeddedFirewall solution. It encrypts the policy distribution traffic between your PolicyServer and the Firewall Client Devices. It also locks down your Firewall Clientdevices so they only accept policies from your specific Policy Server (because of thepublic/private keypair).Please see the 3Com Embedded Firewall Policy Server Administration Guide formore information on creating a customized installation package that will enablethe firewall functionality on your Firewall PC Card and cryptographically bind thecard to your Policy Server.Important Notes The 3Com Firewall Client provides state-of-the-art network security and isdesigned to be tamper resistant. Follow these simple procedures to avoidinadvertently triggering the tamper-resistance feature. Doing so will prevent atime-consuming recovery process.