background image

 

 

72 

 

8.

 

Firewall 

The Internet section allows you to set the access control and Firewall settings. 

8.1.

 

Enable 

This page allows you to Enable / Disable the Firewall features. 

When Enabled, Denial of Service (DoS) and SPI (Stateful Packet Inspection) features are also be enabled. 

 

Summary of Contents for ESR-1221N

Page 1: ...11N Wireless Router EnGenius Gold 11N Wireless Router V1 0 ...

Page 2: ... 1 5 Before you Begin 10 1 6 Considerations for Wireless Installation 10 2 Configure PC Laptop Network Interface 11 2 1 Windows XP Vista 11 2 2 Windows 7 14 2 3 Apple MacOS 16 3 Setup your Router 17 4 Manually enter Setup Wizard 20 5 System 32 5 1 Status 32 5 2 LAN 36 5 3 DHCP 40 5 4 Schedule 43 5 5 Log 45 ...

Page 3: ...ress 49 6 3 Static IP Address 51 6 4 PPP over Ethernet 52 7 Wireless 54 7 1 Status 54 7 2 Advanced 57 7 3 Security 59 7 4 Filter 65 7 5 Wi Fi Protected Setup WPS 67 7 6 Client List 70 7 7 Policy 71 8 Firewall 72 8 1 Enable 72 8 2 Advanced 73 8 3 DMZ 74 8 4 Denial of Service DoS 75 ...

Page 4: ...Port Mapping 80 9 3 Port Forwarding 81 9 4 Port Trigger 82 9 5 Application Layer Gateway ALG 83 9 6 Universal Plug and Play UPnP 84 9 7 Routing 85 10 Tools 87 10 1 Admin 87 10 2 Time 88 10 3 Dynamic DNS DDNS 89 10 4 DDNS Services work as follows 89 10 5 Power 90 10 6 Diagnosis 91 10 7 Firmware 92 10 8 Back up 93 ...

Page 5: ...set 94 Appendix A FCC Interference Statement 95 Appendix B Industry Canada statement 97 IMPORTANT NOTE 102 End Product Labeling 102 Plaque signalétique du produit final 103 Manual Information To the End User 103 ...

Page 6: ...5 Revision History Version Date Notes 1 0 2010 10 25 First Release ...

Page 7: ...6 ...

Page 8: ...rnet LAN Cable CD ROM with User Manual and Setup Utility Quick Guide 1 2 System Requirements RJ 45 Ethernet Based Internet ADSL or Cable Modem Computer with Wireless Network function Windows Mac OS or Linux based operating systems Internet Explorer or Firefox or Safari Web Browser Software ...

Page 9: ...nnected to the Internet through a DSL Cable modem at any available location It can even share the connection in your hotel s room if a RJ 45 network cable is used ENGENIUS GOLD ensures data transmission security by encrypting data It supports Wi Fi Protected Setup WPS for simple and easy setup of WPA2 encryption of the wireless signal It supports legacy encryption such as WEP and WPA ...

Page 10: ...s activated Blinks when Wireless data transfer Internet Color Blue Blinks when WPS handshake is initialized LAN Color Blue Lights when wired network device is connected to RJ 45 port Blinks when data transfer occurs on RJ 45 port Power Color Blue Lights when device is powered ON Blinks device is Reset ...

Page 11: ... are some key guidelines to ensure that you have the optimal wireless range Keep the number of walls and ceilings between the EnGenius access point and other network devices to a minimum Each wall or ceiling can reduce the signal strength the degradation depends on the building s material Building materials makes a difference A solid metal door or aluminum stubs may have a significant negative eff...

Page 12: ...11 2 Configure PC Laptop Network Interface 2 1 Windows XP Vista Click Start button and open Control Panel Windows XP Windows Vista ...

Page 13: ...12 Windows XP click Network Connection Right click on Local Area Connection and select Properties Windows Vista click View Network Status and Tasks then Manage Network Connections ...

Page 14: ... and Printer Sharing and Internet Protocol TCP IP is ticked If not please install them Select Obtain an IP Address automatically and Obtain DNS server address automatically Click OK when done Select Internet Protocol TCP IP and click Properties ...

Page 15: ...14 2 2 Windows 7 In the Start menu search box type ncpa cpl The Network Connections List appears Right click the Local Area Connection icon and click Properties ...

Page 16: ... click either Internet Protocol Version 4 TCP IPv4 or Internet Protocol Version 6 TCP IPv6 and then click Properties Select Obtain an IP Address automatically and Obtain DNS server address automatically Click OK when done Properties Button Internet Protocol Version 4 TCP IPv4 ...

Page 17: ...16 2 3 Apple MacOS Go to System Preferences Network Under Network setting select Using DHCP Click Apply when done ...

Page 18: ...17 3 Setup your Router ...

Page 19: ...18 ...

Page 20: ...19 ...

Page 21: ...P Address http 192 168 0 1 Note If you have changed the default LAN IP Address of the WIRELESS ROUTER ensure you enter the correct IP Address 2 The default username and password are admin Once you have entered the correct username and password click the OK button to open the web base configuration page ...

Page 22: ...21 3 You will see the following webpage if login successful ...

Page 23: ...22 4 Click Wizard to enter the Setup Wizard Then click Next to begin the wizard ...

Page 24: ...23 5 Select the Operation Mode Please ensure you have the proper cables connected as described in the Hardware Installation section ...

Page 25: ... device will now automatically search for the correct Internet settings b The most appropriate WAN type will be determined and selected automatically If it is incorrect please select Others to set up the WAN settings manually ...

Page 26: ...correct settings from your Internet Service Provider ISP Static IP Address If your ISP Provider has assigned you a fixed IP address enter the assigned IP address Subnet mask Default Gateway IP address and Primary DNS and Secondary DNS if available of your ISP provider ...

Page 27: ...ess of your computer s Ethernet LAN card please connect only the computer with the authorized MAC address and click the Clone MAC Address button This will replace the AP Router MAC address to the computer MAC address The correct MAC address is used to initiate the connection to the ISP Dynamic IP Address Hostname This is optional Only required if specified by ISP MAC The MAC Address that is used t...

Page 28: ...ername and password PPP over Ethernet Username Username assigned to you by the ISP Password Password for this username Service You can assign a name for this service Optional MTU The maximum size of packets Do not change unless mentioned by the ISP ...

Page 29: ...28 Point to Point Tunneling Protocol PPTP PPTP is used by some ISPs ...

Page 30: ...if specified by ISP MAC The MAC Address that is used to connect to the ISP PPTP Settings Login Username assigned to you by the ISP Password Password for this username Service IP Address The IP Address of the PPTP server Connection ID This is optional Only required if specified by ISP MTU The maximum size of packets Do not change unless mentioned by the ISP ...

Page 31: ...Genius recommends the Highest level of security to be used Note 802 11n wireless speeds may not be achievable if the security is setup to Lowest and Low level SSID Enter the name of your wireless network Key Enter the security key for your wireless network ...

Page 32: ...31 e Check the settings are correct and then click Reboot to apply the settings ...

Page 33: ... in which mode Uptime The duration about the device has been operating without powering down or reboot Current Date Time The device s system time If this is incorrect please set the time in the Tools Time page Hardware version and Serial Number Hardware information for this device Kernel and Application version Firmware information for this device ...

Page 34: ...ct to the Internet IP address The WAN IP Address of the device Subnet Mask The WAN Subnet Mask of the device MAC address The MAC address of the device s WAN Interface Primary and Secondary DNS Primary and Secondary DNS servers assigned to the WAN connection ...

Page 35: ...34 LAN Settings IP address The LAN IP Address of the device Subnet Mask The LAN Subnet Mask of the device DHCP Server Whether the DHCP server is Enabled or Disabled ...

Page 36: ...n use ESSID The SSID Network Name of the wireless network up to 4 SSID s are supported Security Wireless encryption is enabled for this SSID BSSID The MAC address of this SSID Associated Clients The number of wireless clients connected to this SSID ...

Page 37: ...36 5 2 LAN This page allows you to modify the device s LAN settings ...

Page 38: ...N IP IP address The LAN IP Address of this device IP Subnet Mask The LAN Subnet Mask of this device 802 1d Spanning Tree When Enabled the Spanning Tree protocol will prevent network loops in your LAN network ...

Page 39: ...locates IP addresses to your LAN devices Lease Time The duration of the DHCP server allocates each IP address to a LAN device Start End IP The range of IP addresses of the DHCP server will allocate to LAN devices Domain name The domain name for this LAN network ...

Page 40: ...ur modes available DNS Servers From ISP The DNS server IP address is assigned from your ISP User Defined The DNS server IP address is assigned manually DNS Relay LAN clients are assigned the device s IP address as the DNS server DNS requests are relayed to the ISP s DNS server ...

Page 41: ...40 5 3 DHCP This page shows the status of the DHCP server and also allows you to control how the IP addresses are allocated ...

Page 42: ...IP address from the DHCP Server DHCP Client Table IP address The LAN IP address of the client MAC address The MAC address of the client s LAN interface Expiration Time The time that the allocated IP address will expire Refresh Click this button to update the DHCP Client Table ...

Page 43: ...P address that will be allocated to a LAN client by associating the IP address with its MAC address Type the IP address you would like to manually assign to a specific MAC address and click Add to add the condition to the Static DHCP Table ...

Page 44: ...43 5 4 Schedule This page allows you to schedule times that the Firewall and Power Saving features will be activated deactivated Click Add to create a Schedule entry ...

Page 45: ...gn a name to the schedule Service The service provides for the schedule Days Define the Days to activate or deactivate the schedule Time of day Define the Time of day to activate or deactivated the schedule Please use 24 hour clock format ...

Page 46: ...45 5 5 Log This page displays the system log of the device When powered down or rebooted the log will be cleared Log Save Save the log to a file Clear Clears the log Refresh Updates the log ...

Page 47: ...46 5 6 Monitor This page shows a histogram of the WAN and Wireless LAN traffic The information is automatically updated every five seconds ...

Page 48: ...47 5 7 Language This page allows you to change the Language of the User Interface ...

Page 49: ...48 6 Internet The Internet section allows you to manually set the WAN type connection and its related settings 6 1 Status This page shows the current status of the device s WAN connection ...

Page 50: ... the MAC address does not match If your ISP has recorded the MAC address of your computer s Ethernet LAN card please connect only the computer with the authorized MAC address and click the Clone MAC Address button This will replace the AP Router MAC address to the computer MAC address The correct MAC address is used to initiate the connection to the ISP ...

Page 51: ...C address The MAC Address that is used to connect to the ISP DNS Servers Two DNS servers can be assigned for use by your LAN devices There are two modes available From ISP LAN devices are assigned the DNS server IP address of your ISP User Defined Set the DNS server IP address manually ...

Page 52: ...econdary DNS if available of your ISP provider Static IP Address IP address Assign an IP address Manually IP Subnet Mask Specify an IP address s subnet mask Default Gateway Specify the gateway of your network User Defined Set the DNS server IP address manually Primary DNS Specify the primary DNS server s IP address Secondary DNS Specify the second DNS server s IP address ...

Page 53: ...52 6 4 PPP over Ethernet ISP requires an account username and password ...

Page 54: ... the method that the router maintains connection with the ISP Keep Connection The device will maintain a constant connection with the ISP Automatic Connection The device will only initiate connection to the ISP when there is an Internet connection request made from a LAN device Manual Connection The user will need to manually connect to the ISP by clicking the Connect button Idle Timeout When the ...

Page 55: ...54 7 Wireless The Wireless section allows you to configure the Wireless settings 7 1 Status This page shows the current status of the device s Wireless settings ...

Page 56: ... s Wireless Network names you would like You can create up to 4 separate wireless networks SSID Enter the name of your wireless network You can use up to 32 characters Auto Channel When enabled the device will scan the wireless signals around your area and select the channel with the least interference Channel Manually select which channel the wireless signal will use Check Channel Time When Auto ...

Page 57: ...bility between different brands and models is not guaranteed It is recommended that the WDS network be created using the same models for maximum compatibility Also note that all Access Points in the WDS network needs to use the same Channel and Security settings To create a WDS network please enter the MAC addresses of the Access Points that you want included in the WDS There can be a maximum of f...

Page 58: ...57 7 2 Advanced This page allows you to configure wireless advance settings It is recommended the default settings are used unless the user has experience with these functions ...

Page 59: ...ndication Message informs all wireless clients that the access point will be sending Multi casted data N Data Rate You can limit the transfer rates between the device and wireless clients Each Modulation Coding Scheme MCS refers to a specific transfer speed Channel Bandwidth Set whether each channel uses 20 or 40Mhz To achieve 11n speeds 40Mhz channels must be used Preamble Type A preamble is a me...

Page 60: ... that the security settings will apply to Broadcast SSID If Disabled then the device will not be broadcasting the SSID Therefore it will be invisible to wireless clients WMM Wi Fi Multi Media is a Quality of Service protocol which prioritizes traffic in the order according to voice video best effort and background ...

Page 61: ...A RADIUS This version of WPA requires a Radius Server on your LAN to provide the client authentication according to the 802 1x standard Data transmissions are encrypted using the WPA standard If this option is selected This Access Point must have a client login on the Radius Server Each user must have a user login on the Radius Server Each user s wireless client must support 802 1x and provide the...

Page 62: ...61 802 1x Authentication RADIUS Server IP Address The IP Address of the RADIUS Server RADIUS Server port The port number of the RADIUS Server RADIUS Server password The RADIUS Server s password ...

Page 63: ...fault key before being transmitted You must enter at least the default key For 64 Bit Encryption the key size is 10 chars in HEX 0 9 and A F 128 Bit data is encrypted using the default key before being transmitted You must enter at least the default key For 128 Bit Encryption the key size is 26 chars in HEX 0 9 and A F Default Key Select the key you wish to be the default Transmitted data is ALWAY...

Page 64: ...re that your wireless clients use the same authentication type WPA type Select the WPA encryption you would like Please ensure that your wireless clients use the same settings Pre shared Key Type Select whether you would like to enter the Key in HEX or Passphrase format Pre shared Key Wireless clients must use the same key to associate the device If using passphrase format the Key must be from 8 t...

Page 65: ...e Please ensure that your wireless clients use the same settings RADIUS Server IP address Enter the IP address of the RADIUS Server RADIUS Server Port Enter the port number used for connections to the RADIUS server RADIUS Server password Enter the password required to connect to the RADIUS server ...

Page 66: ...65 7 4 Filter This page allows you to create filters to control which wireless clients can connect to this device by only allowing the MAC addresses entered into the Filtering Table ...

Page 67: ...ter the MAC address of the wireless client that you wish to allow connection Add Click this button to add the entry Reset Click this button if you have made a mistake and want to reset the MAC address and Description fields MAC Address Filtering Table Only clients listed in this table will be allowed access to the wireless network Delete Selected Delete the selected entries Delete All Delete all e...

Page 68: ...e WPS standard and it eases the set up of security enabled Wi Fi networks in the home and small office environment It reduces the user steps required to configure a network and supports two methods that are familiar to most consumers to configure a network and enable security ...

Page 69: ...ts SSID The SSID wireless network name used when connecting using WPS Authentication Mode Shows the encryption method used by the WPS process Passphrase Key This is the passphrase key that is randomly generated during the WPS process It is required if wireless clients that do not support WPS attempts to connect to the wireless network WPS Via Push Button Click this button to initialize WPS feature...

Page 70: ...ELESS ROUTER device Please use this Pin code to initialize the WPS process from the wireless client configuration utility This process will be different for each brand or model Please consult the user manual of the wireless client for more information ...

Page 71: ...70 7 6 Client List This page shows the wireless clients that are connected to the WIRELESS ROUTER device ...

Page 72: ... which typically is an Internet connection Communication between Wireless clients Whether each wireless client can communicate with each other in this SSID When Disabled the wireless clients will be isolated from each other Communication between Wireless clients and Wired clients Whether wireless clients on this SSID can communicate with computers attached to the wired LAN port ...

Page 73: ...ion allows you to set the access control and Firewall settings 8 1 Enable This page allows you to Enable Disable the Firewall features When Enabled Denial of Service DoS and SPI Stateful Packet Inspection features are also be enabled ...

Page 74: ...73 8 2 Advanced You can choose whether to allow VPN Virtual Private Network packets to pass through the Firewall ...

Page 75: ...lication to be used on the server The DMZ PC will receive all Unknown connections and data If the DMZ feature is enabled please enter the IP address of the PC to be used as the DMZ PC Note The DMZ PC is effectively outside the Firewall making it more vulnerable to attacks For this reason you should only enable the DMZ feature when required ...

Page 76: ...l of Service Denial of Service is a type of Internet attack that sends a high amount of data to you with the intent to overload your Internet connection Enable the DoS firewall feature to automatically detect and block these DoS attacks ...

Page 77: ...to Enable the MAC filtering feature Deny all clients with MAC addresses listed below to access the network When selected the computers listed in the MAC Filtering table will be Denied access to the Internet Allow all clients with MAC addresses listed below to access the network When selected only the computers listed in the MAC Filtering table will be Allowed access to the Internet ...

Page 78: ... the applications use IP Filter Enable IP filtering Tick this box to Enable the IP filtering feature Deny all clients with IP addresses listed below to access the network When selected the computers with IP addresses specified will be Denied access to the indicated Internet ports Allow all clients with IP addresses listed below to access the network When selected the computers with IP addresses sp...

Page 79: ... URL Filter You can deny access to certain websites by blocking keywords in the URL web address For example abc123 has been added to the URL Blocking Table Any web address that includes abc123 will be blocked ...

Page 80: ...ings of the router 9 1 Network Address Translation NAT This page allows you to Enable Disable the Network Address Translation NAT feature The NAT is required to share one Internet account with multiple LAN users It also is required for certain Firewall features to work properly ...

Page 81: ...the Internet on those ports it will be redirected to the Mail Server at IP address 192 168 0 150 Port Mapping Enable Port Mapping Tick this box to Enable the Port Mapping feature Description Enter a name or description to help you identify this entry Local IP The local IP address of the computer the server is hosted on Protocol Select to apply the feature to either TCP UDP or Both types of packet ...

Page 82: ...rt 30 it will be forwarded to the computer with the IP address 192 168 0 100 and changed to port 21 Port Forwarding Enable Port Forwarding Tick this box to Enable the Port Forwarding feature Description Enter a name or description to help you identify this entry Local IP The local IP address of the computer the server is hosted on Protocol Select to apply the feature to either TCP UDP or Both type...

Page 83: ...t Trigger feature Popular applications This is a list of some common applications with preset settings Select the application and click Add to automatically enter the settings Trigger port This is the outgoing outbound port numbers for this application Trigger type Select whether the application uses TCP UDP or Both types of protocols for outbound transmissions Public Port These are the inbound in...

Page 84: ... 9 5 Application Layer Gateway ALG Certain applications may require the use of ALG feature to function correctly If you use any of the applications listed please tick and select it to enable this feature ...

Page 85: ...orted applications to seamlessly bypass the Firewall Universal Plug and Play UPnP Enable the UPnP Feature Tick this box to Enable the UPnP feature to allow supported devices to be visible on the network Allow users to make port forwarding changes through UPnP Tick this box to allow applications to automatically set their port forwarding rules to bypass the firewall without any user set up ...

Page 86: ...d Static Routing Enable Static Routing Tick this box to Enable the Static Router feature Destination LAN IP Enter the IP address of the destination LAN Subnet Mask Enter the Subnet Mask of the destination LAN IP address Default Gateway Enter the IP address of the Default Gateway for this destination IP and Subnet Hops Specify the maximum number of Hops in the static routing rule Interface Select w...

Page 87: ... 168 0 0 255 255 255 0 192 168 123 103 1 LAN So if for example Client3 wants to send an IP data packet to 192 168 0 2 Client 2 it would use the above table to determine that it had to go via 192 168 123 103 Router 2 And if it sends Packets to 192 168 1 11 Client 1 will go via 192 168 123 216 Router 1 ...

Page 88: ...the current password New Password Enter your new password Repeat New Password Enter your new password again for verification Remote Management Host Address You can only perform remote management from the specified IP address Leave blank to allow any host to perform remote management Port Enter the port number you want to accept remote management connections Enable Tick to Enable the remote managem...

Page 89: ...thod you want to set the time Time Zone Select the time zone for your current location NTP Time Server Enter the address of the Network Time Protocol NTP Server to automatically synchronize with a server on the Internet Daylight Savings Check whether daylight savings applies to your area ...

Page 90: ...oviders 2 After registration use the Service provider s normal procedure to obtain your desired Domain name 3 Enter your DDNS data on the ETR 9305 s DDNS screen and enable the DDNS feature 4 The Wireless Router will then automatically ensure that your current IP Address is recorded at the DDNS service provider s Domain Name Server 5 From the Internet users will be able to connect to your Virtual S...

Page 91: ...90 10 5 Power This page allows you to Enable or Disable the wireless LAN power saving features ...

Page 92: ... allows you determine if the WIRELESS ROUTER device has an active Internet connection Diagnosis Address to Ping Enter the IP address you like to see if a successful connection can be made Ping Result The results of the Ping test ...

Page 93: ...utton and navigate to the location of the upgrade file 2 Select the upgrade file Its name will appear in the Upgrade File field 3 Click the Apply button to commence the firmware upgrade Note The Wireless Router is unavailable during the upgrade process and must restart when the upgrade is completed Any connections to or through the Wireless Router will be lost ...

Page 94: ...ault Restores the device to factory default settings Backup Settings Save the current configuration settings to a file Restore Settings Restores a previously saved configuration file Click Browse to select the file Then Upload to load the settings ...

Page 95: ...94 10 9 Reset In some circumstances it may be required to force the device to reboot ...

Page 96: ...in a particular installation If this equipment does cause harmful interference to radio or television reception which can be determined by turning the equipment off and on the user is encouraged to try to correct the interference by one of the following measures Reorient or relocate the receiving antenna Increase the separation between the equipment and receiver Connect the equipment into an outle...

Page 97: ...ent This equipment complies with FCC radiation exposure limits set forth for an uncontrolled environment This equipment should be installed and operated with minimum distance 20cm between the radiator your body We declare that the product is limited in CH1 CH11 by specified firmware controlled in the USA This transmitter must not be co located or operating in conjunction with any other antenna or ...

Page 98: ...ge préjudiciable et 2 ce dispositif doit accepter tout brouillage reçu y compris un brouillage susceptible de provoquer un fonctionnement indésirable IMPORTANT NOTE For mobile device use Radiation Exposure Statement This equipment complies with IC radiation exposure limits set forth for an uncontrolled environment This equipment should be installed and operated with minimum distance 20cm between t...

Page 99: ...nt et votre corps Avertissement Le dispositif fonctionnant dans la bande 5150 5250 MHz est réservé uniquement pour une utilisation à l intérieur afin de réduire les risques de brouillage préjudiciable aux systèmes de satellites mobiles utilisant les mêmes canaux Les utilisateurs de radars de haute puissance sont désignés utilisateurs principaux c à d qu ils ont la priorité pour les bandes 5250 535...

Page 100: ...nt isotropically radiated power e i r p is not more than that necessary for successful communication French translation Le manuel d utilisation de dispositifs émetteurs équipés d antennes amovibles doit contenir les informations suivantes dans un endroit bien en vue Ce dispositif a été conçu pour fonctionner avec une antenne ayant un gain maximal de dB x Une antenne à gain plus élevé est stricteme...

Page 101: ...rom the user body or set the device to lower output power if such function is available French translation NOTE IMPORTANTE Pour l utilisation des appareils portables Déclaration d exposition aux radiations Le produit est conforme aux limites d exposition pour les appareils portables RF pour les Etats Unis et le Canada établies pour un environnement non contrôlé Le produit est sûr pour un fonctionn...

Page 102: ...led French translation Cet appareil est conçu uniquement pour les intégrateurs OEM dans les conditions suivantes Pour utilisation de dispositif module 1 L antenne doit être installée de telle sorte qu une distance de 20 cm est respectée entre l antenne et les utilisateurs et 2 Le module émetteur peut ne pas être coïmplanté avec un autre émetteur ou antenne 3 Pour tous les produits vendus au Canada...

Page 103: ...tre satisfaites par exemple pour certaines configurations d ordinateur portable ou de certaines co localisation avec un autre émetteur l autorisation du Canada n est plus considéré comme valide et l ID IC ne peut pas être utilisé sur le produit final Dans ces circonstances l intégrateur OEM sera chargé de réévaluer le produit final y compris l émetteur et l obtention d une autorisation distincte a...

Page 104: ...on to the end user regarding how to install or remove this RF module in the user s manual of the end product which integrates this module The end user manual shall include all required regulatory information warning as show in this manual French translation Manuel d information à l utilisateur final L intégrateur OEM doit être conscient de ne pas fournir des informations à l utilisateur final quan...

Reviews: