background image

CNet Technology Inc                                                                                      

Broadband Router User Guide

44

Security Groups

The 

Security Groups

 screen is reached from the 

Access Control

 link on the navigation bar. An

example screen is shown below.

Figure 25: Security Groups Screen

Note that the Security groups are pre-named "Everyone", "Group 1", "Group 2", "Group 3",
and "Group 4".

Operations

 

To Define a Security Group:

Select the group from the drop-down box, then enter the required data. If necessary, click

Clear Form

 to remove the existing information shown on screen.

Click the 

Save

 button when finished.

 

To Change Access for an Existing Group

:

Select the group from the drop-down box, click 

Get Data

 to view their information, then

change any fields you wish.
Click 

Save

 when finished.

 

To Assign PCs to a Security Group

All PCs are initially in the "Everyone" group. Use the 

PCs

 screen to move individual PCs

to other groups as required.

Summary of Contents for CNIG904S

Page 1: ...Broadband Router Shared Broadband Internet Access User s Guide ...

Page 2: ...sh Configuration 25 CHAPTER 5 DHCP 26 Overview 26 What DHCP Does 26 Using the Broadband Router s DHCP Server 26 Using another DHCP Server 26 To Configure your PCs to use DHCP 27 CHAPTER 6 ROUTING 28 Overview 28 Broadband Router Configuration 28 Router Configuration 30 Routing Example 30 CHAPTER 7 DEVICE OPTIONS 32 Overview 32 Password 32 NAT Network Address Translation 33 TFTP 33 Remote Management...

Page 3: ...ew 49 General Problems 49 Internet Access 50 APPENDIX B SPECIFICATIONS 51 Broadband Router 51 P N 9560DN0001 Copyright 2001 All Rights Reserved Document Version 1 0 All trademarks and trade names are the properties of their respective owners ...

Page 4: ...ates many advanced features carefully designed to provide sophisticated functions while being easy to use LAN Features 10 100BaseT Hub The Broadband Router includes a 4 port 10 100BaseT switching Hub allow connection of up to 4 PCs Both 10BaseT and 100BaseT connections can be used simultaneously DHCP Server Support Dynamic Host Configuration Protocol provides a dynamic IP address to PCs and other ...

Page 5: ... managed from a workstation anywhere on the LAN using a WEB browser Advanced Internet Functions Virtual Servers This feature allows Internet users to access Internet servers on your LAN The required setup is quick and easy User Defined Virtual Servers Internet users can access non standard Internet Servers on your LAN by using this feature Special Internet Applications Internet applications such a...

Page 6: ...ting the multiple internal IP addresses into a single external IP address For external requests any attempt to connect to local resources are blocked The Broadband Router will not reverse translate from a global IP address to a local IP address This type of natural firewall provides an impregnable barrier against malicious attacks Package Contents The following items should be included The Broadba...

Page 7: ... the WAN port Rear Panel Reset button 10 100 BaseT LAN Connectors Power Input WAN Uplink RESET WAN port DIP switches LAN Port LEDS 4 3 2 1 WAN port LED 1 2 3 4 Link Act 100 LAN Uplink port Figure 2 Rear Panel DIP switches Refer to the following table for DIP switch operation LAN Port LEDs Link Act On The Router is successfully connected to a device through the corresponding port 1 2 3 or 4 Flashin...

Page 8: ...n Restore Default IP Address and Clear Password If the Broadband Router s IP Address or password is lost the following procedure can be used to recover from this situation 1 Turn the power to the Broadband Router OFF 2 Set DIP switch 1 ON 3 Turn the power to the Broadband Router ON 4 Operate DIP switch 1 in the following sequence you have 15 seconds to complete the sequence OFF ON OFF 5 The Broadb...

Page 9: ...ation Diagram 1 Choose an Installation Site Select a suitable place on the network to install the Broadband Router Ensure the Broadband Router and the Cable DSL modem are powered OFF 2 Connect LAN Cables Use standard LAN cables to connect PCs to the Switching Hub ports LAN ports on the Broadband Router Both 10BaseT and 100BaseT connections can be used simultaneously If required connect the Broadba...

Page 10: ... use a standard LAN cable 4 Power Up Connect the supplied power adapter and power up Use only the power adapter provided Using a different one may cause hardware damage 5 Check the LEDs When the Broadband Router is powered On the DATA STATUS LAN LED should flash then turn on If it stays flashing in Green and Orange there is a hardware error For more information refer to Top Mounted LEDs in Chapter...

Page 11: ...ate detailed instructions for the required functions To Do this Refer to Configure PCs on your LAN Chapter 4 PC Configuration Learn more about using DHCP on the internal LAN Chapter 5 DHCP Configure the Broadband Router and routers for a LAN which has 1 or more routers Chapter 6 Routing Set a password for the Broadband Router or disable NAT Network Address Translation Chapter 7 Options Use any of ...

Page 12: ...he other device must be turned OFF until the Broadband Router is allocated a new IP Address during configuration Connecting to the Broadband Router To establish a connection from your PC to the device 1 After installing the Broadband Router in your LAN start your PC If your PC is already running restart it 2 Start your WEB browser 3 In the Address box enter HTTP and the IP Address of the Broadband...

Page 13: ... be within the range 192 168 0 2 to 192 168 0 254 to be compatible with the Broadband Router s default IP Address of 192 168 0 1 Also the Network Mask must be set to 255 255 255 0 See Chapter 4 PC Configuration for details on checking your PC s TCP IP settings Navigation Data Input Use the menu bar on the left of the screen and the Back button on your Browser for navigation Changing to another scr...

Page 14: ...Chapter 6 Routing Data LAN Screen TCP IP IP Address IP address for the Broadband Router Use the default value of 192 168 0 1 unless the address is already in use or your LAN is using a different IP address range In the latter case enter an unused IP Ad dress from within the range used by your LAN Network Mask The default value 255 255 255 0 is standard for small class C networks For other networks...

Page 15: ... This range also determines the number of DHCP clients supported Maximum 253 DNS Domain Name Server DNS Domain Name Server IP Addresses You do NOT need to enter DNS addresses UNLESS you are using a Fixed IP Address on the WAN port Your ISP has allocated you a fixed IP Address In this case your ISP should recommend a DNS You need to enter that address or addresses here If using a Dynamic IP Address...

Page 16: ... connection documentation does not refer to PPPoE select Direct Connection WAN Direct Connection Figure 7 WAN Direct Connection If you selected Direct Connection a screen like the example above will be shown Data WAN Direct Connection Device ID Device Host Name Normally there is no need to change the default name but if your ISP requests that you use a particular Hostname enter it here This name w...

Page 17: ...ecting to another LAN this must be a valid address on the ex ternal LAN Network Mask This must be compatible with the IP Address above Gateway IP Address The address of the router or gateway either on the external LAN or supplied by your ISP DNS IP Address At least 1 DNS IP Address is required and should be provided by your ISP DNS settings are on the LAN screen Buttons Retrieve Defaults Get the d...

Page 18: ...ynamic use this setting if your ISP did not provide an IP Address If your ISP did provide an IP Address select Fixed and enter the value they provided Options Idle Time out If an connection is inactive for longer than this time period it will be terminated If zero 0 then the connection will never be termi nated Connect on Demand Normally this should be Enabled If disabled you must use the Connect ...

Page 19: ... Address The IP Address of this device as seen by devices on the WAN This device has 2 IP Addresses one for the local LAN and another for the WAN port Network Mask The Network Mask for the above IP Address Default Gateway IP address of the Router Gateway on the WAN port DHCP Client Displays Enabled or Disabled indicating whether this device is acting as a DHCP client on the external LAN or WAN But...

Page 20: ...not the connection is currently established If the connection does not exist the Connect button can be used to establish a connection If the connection currently exists the Disconnect button can be used to break the connection Connection Log Log Data The Connection Log shows status messages relating to the existing connection The most common messages are listed in the following table Buttons Conne...

Page 21: ...he time period specified in the Idle Time out field The connection will now be terminated Disconnecting The current connection is being terminated due to either the Idle Time out above or Disconnect button being clicked Error Remote Server not found ISP s Server did not respond This could be a Server problem or a problem with the link to the Server Error PPP Connec tion failed Unable to establish ...

Page 22: ...ay Enabled NAT is On or Disabled NAT is Off LAN Port Physical Address The Hardware address of this device as seen by other devices on the Internal LAN IP Address The IP Address of this device as seen by other devices on the Inter nal LAN Network Mask The Network Mask Subnet Mask for the IP Address above DHCP Server This shows the status of the DHCP Server function The value will be Enabled or Disa...

Page 23: ... the IP Address is allocated to the device shown or Reserved the IP Address is not available Note The DHCP table will be empty unless the DHCP Server function is being used If not empty this table lists the devices on the LAN which have been allocated IP Addresses by the DHCP server function ...

Page 24: ... settings and the default Windows 95 98 TCP IP settings no changes need to be made By default the Broadband Router will act as a DHCP Server automatically providing a suitable IP Address to each PC when the PC boots The default Windows 95 98 TCP IP setting is to act as a DHCP client To check your PC s TCP IP Settings 1 Select Control Panel Network You should see a screen like the following Figure ...

Page 25: ...ettings Restart your PC to ensure it obtains an IP Address from the Broadband Router Using Specify an IP Address If your PC is already configured do NOT change the settings on the IP Address tab shown in Figure 13 above On the Gateway tab enter the Broadband Router s IP address in the New Gateway field and click Add Your LAN administrator can advise you of the IP Address they assigned to the Broad...

Page 26: ...ected If the DNS Server Search Order list is empty enter the DNS address provided by your ISP in the fields beside the Add button then click Add Figure 15 DNS Tab Win 95 98 If your LAN has a Router the LAN Adminis trator must re configure the Router itself Refer to Chapter 6 Routing for details ...

Page 27: ...hecked 6 Check the No option when prompted Do you want to set up an Internet mail account now 7 Click Finish to close the Internet Connection Wizard 8 Then simply use your Browser FTP client or other Internet client to connect to the desired Internet site Accessing AOL To access AOL America On Line through the Broadband Router the AOL for Windows software must be configured to use TCP IP network a...

Page 28: ...ntrol Panel 2 Select Ethernet from the Connect via pop up menu 3 Select Using DHCP Server from the Configure pop up menu The DHCP Client ID field can be left blank 4 Close the TCP IP panel saving your settings Note If using manually assigned IP addresses instead of DHCP the only change required is to set the Router Address field to the Broadband Router s IP Address ...

Page 29: ...efault Windows setting for TCP IP The Broadband Router can act as a DHCP server Using the Broadband Router s DHCP Server This is the default setting The DHCP Server settings are on the LAN screen On this screen you can Enable or Disable the Broadband Router s DHCP Server function Set the range of IP Addresses allocated to PCs by the DHCP Server function You can assign Fixed IP Addresses to some de...

Page 30: ...ure your PCs to use DHCP This is the default setting for TCP IP under Windows 95 98 ME In Windows the DHCP Client setting is called Obtain an IP Address Automatically See Chapter 4 PC Configuration for the procedure to check these settings ...

Page 31: ... Router correctly as described in the following sections See Routing Example later in this Chapter for an example of configuring both the Broadband Router and the Router Broadband Router Configuration The routing table is accessed by the Routing link on the Home screen An example screen is shown below Figure 16 Routing Screen Using this Screen Any existing entries are listed To view and edit the d...

Page 32: ... fields of this Destination IP Address The 4th last field can be left at 0 Network Mask The Network Mask used on the remote LAN segment For class C networks the standard Network Mask is 255 255 255 0 Gateway IP Address The IP Address of the Router on the LAN segment to which this device is attached NOT the router on the remote LAN segment Interface Select the appropriate interface LAN Internal LAN...

Page 33: ... documentation Gateway IP Address The IP Address of the Broadband Router Metric 1 Other Routers on the Local LAN Other routers on the local LAN must use the Broadband Router s Local Router as the Default Route The entries will be the same as the Broadband Router s local router with the exception of the Gateway IP Address For a router with a direct connection to the Broadband Router s local Router ...

Page 34: ...uter s local Router Interface LAN Metric 1 Entry 2 Segment 2 Destination IP Address 192 168 2 0 Network Mask 255 255 255 0 Gateway IP Address 192 168 0 100 Interface LAN Metric 2 For Router A s Default Route Destination IP Address 0 0 0 0 Network Mask 0 0 0 0 Gateway IP Address 192 168 0 1 Broadband Router s IP Ad dress For Router B s Default Route Destination IP Address 0 0 0 0 Network Mask 0 0 0...

Page 35: ...screen is shown below Figure 18 Options Screen Password Once a password is entered it is required in order to change the device configuration Pass words are case sensitive and can be up to 8 alphanumeric characters no spaces or punctuation To create or change the password enter the required password in both the New Password and Verify Password input fields When prompted for the password leave the ...

Page 36: ...agement Enable to allow management via the Internet If Disabled this device will ignore management connection attempts from the WAN port Port Number Enter a port number between 1024 and 65535 8080 is recom mended This port number must be specified when you connect see below Note The default port number for HTTP Web connections is port 80 but using port 80 here will prevent the use of a Web Virtual...

Page 37: ...ess the following advanced features are provided Special Internet Applications Virtual Servers DMZ This chapter contains details of the configuration and use of each of these features Advanced Internet Screen This screen provides access to the advanced Internet features and provides a convenient overview and control center An example screen is shown below Figure 19 Advanced Internet Screen On this...

Page 38: ...tion is unable to function correctly At any time only one 1 PC can use each Special Application Special Applications Screen This screen can be reached by selecting Special Internet Applications An example screen is shown below Figure 20 Special Applications Screen Using a Special Application Ensure that Special Applications has been enabled on the Advanced Internet screen Configure the Special App...

Page 39: ... identify this application entry Enable Use this to Enable or Disable support for this application as required Outgoing Protocol The protocol TCP or UDP used when you connect to the special applica tion service Port Range Start The beginning of the range of port numbers used by the application server for data you send to it If the application uses a single port number enter it in both the Start an...

Page 40: ... 168 0 20 LAN IP Address WAN IP Address Figure 21 Virtual Servers IP Address seen by Internet Users Note that in this illustration both Internet users are connecting to the same IP Address but using different protocols To Internet users all virtual Servers on your LAN have the same IP Address This IP Address is allocated by your ISP This address should be static rather than dynamic to make it easi...

Page 41: ...Address is allocated by your ISP It is better to have a fixed IP Address Type Select the type of Server you wish to use Enable Check to enable this Server LAN IP Address Enter the IP Address of a PC on your LAN You must install and configure the appropriate Server software on the PC entered here If using DHCP the LAN IP Address of a PC may change To solve this problem use either of these methods A...

Page 42: ... screen like the example below Figure 23 User Defined Virtual Servers To Create a new Server Click Clear Form Enter the required data See next section Click Add To Modify Edit a defined Server Select it from the drop down list Click Get Data Make any desired changes Note that you can Enable and Disable a Server using this process Click Update To Delete a defined Server Select it from the drop down...

Page 43: ...UDP used by the Server Internal Port Number Enter the port number used by the Server to connect to clients External Port Number The port number used by clients when connecting to the Server This is normally the same as the Internal Port Number If it is different this device will perform a mapping or translation function allowing the server to use one port address while clients use a different port...

Page 44: ... user connections such as Video conferencing which requires both users to run special software To allow unrestricted access the Firewall in this device is disabled creating a security risk You should use this feature only if the Special Applications feature is insuffi cient to allow an application to function correctly This feature should be turned ON only when needed and left OFF the rest of the ...

Page 45: ... that its IP Address is NOT within the address range allocated by the DHCP Server Reserve an IP Address for the DMZ PC in the DHCP Server using the Access Control PC screen WAN IP Address WAN IP Address This is the IP Address Internet users must use to connect to the DMZ PC This IP Address is allocated by your ISP It is better if you are using a fixed IP Address so that it never changes This will ...

Page 46: ... strictive group Additional access rights then have to be explicitly granted by assigning a user to a less restrictive group However if you wish to restrict only a small number of users it may be more conven ient to reverse this and make the Everyone group the least restrictive group Only users requiring restrictions need to be assigned to a more restrictive group Set the desired restrictions on t...

Page 47: ...ne a Security Group Select the group from the drop down box then enter the required data If necessary click Clear Form to remove the existing information shown on screen Click the Save button when finished To Change Access for an Existing Group Select the group from the drop down box click Get Data to view their information then change any fields you wish Click Save when finished To Assign PCs to ...

Page 48: ...the TCP Packets to Discard and UPD Packets to Discard column Packet Filter Table Applications to Block Any items checked will be blocked Users will not be able to use the application TCP Packets to Discard This lists any TCP filters you have defined on the Filters screen If no filters have been defined this is empty Multiple items can be selected or deselected by holding down the Ctrl key while se...

Page 49: ...ore the drop down box click the Clear Form button and enter the PC details in the fields provided Click Add when finished To Delete an Existing PC Select the PC from the drop down box click Get Data to view the information and confirm that this is the correct PC then click the Delete button To Change an Existing PC s Details Select the PC from the drop down box click Get Data to view their informa...

Page 50: ...s This relates to the entry above Enter the reserved address here This MUST be within the range used by the DHCP server set on the Device Internal LAN Port screen Security Group Select the security group for this PC If you only wish to reserve an IP Address and are not using the security access control features simply leave this at Everyone Filters The Filters screen is reached from the Access Con...

Page 51: ...e of packet This information can normally be provided by the service provider Otherwise a Network Analyzer or Packet Sniffer can be used to determine the correct port number UDP Filters Name Enter a descriptive name for this entry Port No Enter an integer representing the Port Number for this type of packet This information can normally be provided by the service provider Otherwise a Network Analy...

Page 52: ...m 1 Can t connect to the Broadband Router to configure it Solution 1 Check the following The Broadband Router is properly installed LAN connections are OK and it is powered ON Ensure that your PC and the Broadband Router are on the same network segment If you don t have a router this must be the case Ensure that your PC is using an IP Address within the range 192 168 0 2 to 192 168 0 254 and thus ...

Page 53: ...the LAN and power connections If the Broadband Router is configured correctly check your Internet connection DSL Cable modem etc to see that it is working correctly Problem 2 Some applications do not run properly when using the Broadband Router Solution 2 The Broadband Router processes the data passing through it so it is not transparent Use the Special Applications feature to allow the use of Int...

Page 54: ...for WAN LEDs 11 LEDs 1 WAN Link Green 4 LAN Link Act Green 4 LAN 100 Green 1 WAN Data Green 1 Data Status LAN Green Orange External Power Adapter 12 V DC 1 5A FCC Statement This device complies with Part 15 of the FCC Rules Operation is subject to the following two conditions 1 This device may not cause harmful interference 2 This device must accept any interference received including interference...

Reviews: