BB005x Installation and Configuration Guide
43
Layer Gateways (ALGs). These features ensure secure and effective access for
many popular Internet applications. The BB005x can also function as an IGD
(Internet Gateway Device) in accordance with the Universal Plug and Play
(UPnP) standards. This capability further enhances the flexibility of the unit to
support secure access for a large number of applications.
Security Interfaces
One important concept that relates to NAT and the security capabilities of
BB005x is the concept of security interface.
The configuration process requires that security is enabled and security
interfaces be added before NAT or firewall features can be configured. The
BB005x supports 3 types of security interfaces: external, DMZ (demilitarized
zone) and internal. Each interface can be adjusted to allow or block certain
protocols or types of access.
In order for NAT or firewall triggers to be configured, at least one of the
following pair of interfaces needs to be defined.
•
•
•
External – Internal
External – DMZ
DMZ - Internal
The DMZ is normally a network area that is protected from unauthorized access
coming from the external network so that certain computer hosts (for example,
a Web Server) can be placed on the DMZ where they can be accessed by
requests from the outside world and still be protected against many security
threats.
Any of the 3 pairs of interfaces above can be configured for NAT operation. The
figure below illustrates security interfaces of the BB005x. Please note that
BB005x has no distinct physical Ethernet port for the DMZ and the distinction
between computer hosts belonging to the internal network and those on the
DMZ in entirely implemented in firmware.
DMZ
BB005x
Adding a Security Interface
Internal
Security
Interface
To add a Security Interface:
►
1. Click on
Advanced Configuration
and the
ecurity
. The following
screen will appear:
n on
S
External
Security
Interface
DMZ
Security
Interface
Internal Network