background image

Cerberus P 6391 

 

46

Security / Advanced Security 

Using the Advanced Security page, you can protect the router from being attacked by TCP-
SYN Flood, UDP Flood and ICMP-Flood. 

 

 

Packets Statistic interval (5~60)

 - The default value is 10. Select a value between 5 and 60 

seconds in the pull-down list. The Packets Statistic interval is a sampling interval that affects 
how data is sampled before it is checked for signs of flooding. This value is used to filter 
against SYN Flood, UDP Flood and ICMP-Flood attacks.  

DoS protection

 - 

Enable

 or 

Disable

 DoS protection. This option disables all DoS filters when 

Disable

 is selected.  

Enable ICMP-FLOOD Attack Filtering

 - 

Enable

 or 

Disable

 the ICMP-FLOOD Attack 

Filtering. 

ICMP-FLOOD Packets threshold (5~3600)

 - The default value is 50. Enter a value between 

5 ~ 3600 packets. When the current ICMP-FLOOD Packets number is beyond the set value 
the router will startup the blocking function immediately. 

Enable UDP-FLOOD Filtering

 - 

Enable

 or 

Disable

 the UDP-FLOOD Filtering. 

UDP-FLOOD Packets threshold (5~3600)

 - The default value is 50. Enter a value between 5 

~ 3600 packets. When the current UPD-FLOOD Packets number is beyond the set value the 
router will startup the blocking function immediately. 

Enable TCP-SYN-FLOOD Attack Filtering

 - 

Enable

 or 

Disable 

the TCP-SYN-FLOOD Attack 

Filtering. 

TCP-SYN-FLOOD Packets threshold (5~3600)

 - The default value is 50. Enter a value 

between 5 ~ 3600 packets. When the current TCP-SYN-FLOOD Packets number is beyond 
the set value the router will start the blocking function. 

Ignore Ping Packet from WAN Port

 - 

Enable

 or 

Disable

 ignore ping packet from WAN port. 

The default is disabled. If this option is enabled the ping packet cannot access the router from 
the Internet. 

Forbid Ping Packet from LAN Port

 - 

Enable

 or 

Disable

 forbidding the ping packet from 

accessing the router through the LAN ports. The default value is disabled. If this option is 
enabled the ping packet cannot access the router from the LAN. (Defends against some 
viruses). 

Summary of Contents for Cerberus P6391

Page 1: ...Installation and Operation Manual PENTAGRAM Cerberus P6391 The latest versions of manual drivers and applications are available on www pentagram eu 2008 10 07 ...

Page 2: ...OTE Any information and technical data are subject to change without prior notification and or indication in this manual 2008 PENTAGRAM All rights reserved copying and reproduction is strictly forbidden ...

Page 3: ...NG 37 FORWARDING DMZ 39 FORWARDING UPNP 39 SECURITY FIREWALL 40 SECURITY IP ADDRESS FILTERING 41 SECURITY DOMAIN FILTERING 43 SECURITY MAC ADDRESS FILTERING 44 SECURITY REMOTE MANAGEMENT 45 SECURITY ADVANCED SECURITY 46 STATIC ROUTING 47 IP MAC BINDING BINDING SETTINGS 48 IP MAC BINDING ARP LIST 49 DYNAMIC DNS 49 SYSTEM TOOLS TIME SETTINGS 50 SYSTEM TOOLS FIRMWARE UPGRADE 51 SYSTEM TOOLS FACTORY D...

Page 4: ...Cerberus P 6391 4 ...

Page 5: ...uto MDI MDIX Adopts 2x to 3x eXtended Range and 108M Super G wireless LAN transmission technology Supports 108 54 48 36 24 18 12 9 6Mbps or 11 5 5 3 2 1Mbps data transfer rates Provides WPA WPA2 WPA PSK WPA2 PSK authentication TKIP AES encryption security Shares data and Internet access for users supporting PPPoE Dynamic IP Static IP L2TP PPTP BigPond Cable Internet access Supports Virtual Server ...

Page 6: ... product and all accessories outdoors Place the router on a stable surface Only use the power adapter that comes with the package Using a different voltage rating power adaptor may damage the router Front Panel LED Action Description Not lit No Power PWR Lit up Power on Lit up The router is initializing Flashing The router is working properly SYS Not lit The router has a hardware error Not lit The...

Page 7: ...dress Pool 100 IP addresses from 192 168 1 101 IP Address Lease Time 7200 seconds 2 hours User Name admin Password pentagram It is recommended to change User Name and Password as soon as possible If you ever forget the password to log in you may need to restore the factory default settings This procedure is described on the next page Resetting router Use the Factory Defaults function on System Too...

Page 8: ... second in EIA TIA 568B After connecting the device to one of the ports corresponding LED will begin to blink That signals the process of the auto checking of port and the negotiation of connection speed rate Connecting via WLAN Interface Wireless Card To connect PC to Cerberus via WLAN Wireless Adapter must be properly installed and configured and both router and PC must be in the same subnet Con...

Page 9: ...click Continue Administrator user or select Administrator user and enter valid password Standard user 1 Click Start Control Panel 2 Click View network status and tasks 3 Click View status for appropriate connection 4 On General tab Click the Properties button 5 On General tab select Internet Protocol Version 4 TCP IPv4 and click Properties ...

Page 10: ...ly 7 Click OK to save settings and close Internet Protocol Version 4 TCP IPv4 Properties window Note In some cases Windows Vista cannot obtain an IP address from certain router s DHCP server If you encounter this follow this steps to resolve this problem Microsoft Support page http support microsoft com kb 928233 en us ...

Page 11: ...d then Network Connections icon XP Default view 2 Double click the Local Area Connection icon 3 On General tab Click the Properties button 4 On General tab select Internet Protocol TCP IP and click Properties 5 On General tab select Obtain an IP address automatically and DNS server address automatically 6 Click OK to save settings and close Internet Protocol TCP IP Properties window ...

Page 12: ...elect Obtain an IP address automatically 4 On DNS Configuration tab select Disable DNS 5 Click OK to save settings and close TCP IP Properties window To make sure that network adapter properly obtained an IP address from router s DHCP server 1 click Start Run 2 type cmd Win 2000 XP or command Win 95 98 ME and press Enter 3 in command line type ipconfig all and press Enter 4 check if the IP Address...

Page 13: ... can be configured via web browser which is usually integrated with operating system Router offers clear and simple interface Login 1 Launch the Web browser 2 In address bar enter the default IP address http 192 168 1 100 3 Enter username and password default admin pentagram ...

Page 14: ...Cerberus P 6391 14 Navigation Left pane Navigation menu Center pane Contents of element selected from navigation menu Right pane Online help concerning contents of the center pane ...

Page 15: ...uter in LAN IP Address IP address used by router in LAN Subnet Mask LAN subnet mask Wireless Wireless Radio Built in Access Point status Enabled or Disabled Name SSID Name of wireless network created by router Channel Channel on which wireless network operates Mode Current wireless mode 108Mbps Dynamic 108Mbps Static 54Mbps 802 11g or 11Mbps 802 11b ...

Page 16: ...Setup e basic network parameters W N IP Subnet mask Subnet mask assigned for WAN port Default Gateway The IP address of the default g DNS Server The IP address of the DNS server B Quick Setup menu will help you to configure th To begin configuration click the Next button uick Setup Choose WAN Connection Type Q Select WAN Connection Type your ISP is using and click the Next button to configure it n...

Page 17: ...p Wireless Wireless Radio Indicates if the Access Point feature of the router is Enabled or Disabled If disabled the WLAN LED on the front panel will not be lit and the wireless stations will not be able to access the router If enabled the WLAN LED will be lit up and wireless stations will be able to access the router SSID Enter a value of up to 32 characters The same SSID must be assigned to all ...

Page 18: ...mode The options are 108Mbps Dynamic Super G 802 11g and 802 11b wireless stations can connect to the router 108Mbps Static Only Super G wireless stations can connect to the router 54Mbps 802 11g Both 802 11g and 802 11b wireless stations can connect to the router 11Mbps 802 11b Only 802 11b wireless stations can connect to the router Click the Next button to continue Quick Setup Finish Click the ...

Page 19: ...u need reduce the MTU But this is rarely required and should not be done unless you are sure it is necessary for your ISP connection Use These DNS Servers If your ISP gives you one or two DNS IP addresses select this option and enter the primary and secondary addresses into the correct fields Otherwise the DNS servers will be assigned dynamically from ISP Primary DNS Secondary DNS Optional Enter t...

Page 20: ...e default gateway in dotted decimal notation provided by your ISP MTU Size The normal MTU Maximum Transmit Unit value for most Ethernet networks is 1500 Bytes For some ISPs you may need to modify the MTU But this is rarely required and should not be done unless you are sure it is necessary for your ISP connection Primary DNS Secondary DNS Optional Enter the DNS IP address in dotted decimal notatio...

Page 21: ...ecting You can configure the router to make it connect or disconnect based on time Enter the start time in HH MM for connecting and end time in HH MM for disconnecting in the Period of Time fields Note Only when you have set the system time on System Tools Time page the Time based Connecting function can take effect Connect Manually You can configure the router to make it connect or disconnect man...

Page 22: ... is 0 it means not detecting Use These DNS Servers If your ISP gives you one or two DNS IP addresses select this option and enter the primary and secondary addresses into the correct fields Otherwise the DNS servers will be assigned dynamically from ISP Primary DNS Secondary DNS Optional Enter the DNS IP address in dotted decimal notation provided by your ISP Note If you get Address not found erro...

Page 23: ...Enter the DNS IP address in dotted decimal notation provided by your ISP Note If you get Address not found errors when you go to a Web site it is likely that your DNS servers are set up improperly You should contact your ISP to get DNS server addresses Get IP with Unicast DHCP A few ISPs DHCP servers do not support the broadcast applications If you can t get the IP Address normally you can choose ...

Page 24: ...erver IP address or host name Auth Domain Type in the domain suffix server name based on your location eg NSW ACT nsw bigpond net au VIC TAS WA SA NT vic bigpond net au QLD qld bigpond net au MTU Size in bytes The default MTU size is 1500 bytes which is usually fine For some ISPs you need modify the MTU This should not be done unless you are sure it is necessary for your ISP Connect on Demand You ...

Page 25: ... Idle Time field Otherwise enter the number in minutes that you wish to have the Internet connecting last unless a new link requested Note Sometimes the connection cannot be disconnected although you specify a time to Max Idle Time because some applications visit the Internet continually in the background Click the Connect button to connect immediately Click the Disconnect button to disconnect imm...

Page 26: ...d click the radio button If you want your Internet connection to remain active at all times enter 0 in the Max Idle Time field Otherwise enter the number of minutes you want to have elapsed before your Internet connection terminates Note Sometimes the connection cannot be disconnected although you specify a time to Max Idle Time because some applications visit the Internet continually in the backg...

Page 27: ...n provided by your ISP Gateway Enter the gateway in dotted decimal notation provided by your ISP DNS Enter the DNS IP address in dotted decimal notation provided by your ISP Internet IP Address IP Address used in Internet Internet DNS IP Addresses of DNS Servers used in Internet MTU Size in bytes The default MTU size is 1420 bytes which is usually fine For some ISPs you need modify the MTU This sh...

Page 28: ...hat you wish to have the Internet connecting last unless a new link requested Note Sometimes the connection cannot be disconnected although you specify a time to Max Idle Time because some applications visit the Internet continually in the background Click the Save button to save this settings Network MAC Clone Some ISPs require that you register the MAC Address of your adapter which is connected ...

Page 29: ...f your country or region is not listed please contact your local government agency for assistance Note Some regions such as Israel may not use 108Mbps Mode since the operation for the wireless interface in 108Mbps Mode is illegal Channel This field determines which operating frequency will be used It is not necessary to change the wireless channel unless you notice interference problems with anoth...

Page 30: ...red to authenticate the wireless station Open system Any wireless station can connect to this wireless network WEP Key Format You can select ASCII or Hexadecimal format ASCII Format stands for any combination of keyboard characters in the specified length Hexadecimal format stands for any combination of hexadecimal digits 0 9 a f A F in the specified length Key Selected Select which of the four ke...

Page 31: ... group key update interval in seconds The value can be either 0 or at least 30 Enter 0 to disable the update Click the Save button to save this settings WPA PSK WPA2 PSK Security Option Select which WPA version will be used Automatic Used WPA version depends on the wireless station request WPA WPA2 Encryption Select encryption algorithm Automatic AES or TKIP PSK Passphrase You can enter a WPA pass...

Page 32: ...bit or 128 bit or 152 bit means assigning a unique WEP key to access the router Description Select this radio button to display simple description of the wireless station WEP Key Select this radio button to display unique WEP key in the Hexadecimal format to access the router Modify Click Modify to open Add or Modify Wireless MAC Address Filtering entry page or Delete to delete entry Add New Click...

Page 33: ...If you select 64 bit or 128 bit or 152 bit in the Privilege field enter any combination of hexadecimal digits 0 9 a f A F in the specified length For example 2F34D20BE2 Status Select Enabled or Disabled for this entry on the pull down list Click the Save button to save this entry Wireless Wireless Statistics MAC Address Connected wireless station s MAC address Current Status Connected wireless sta...

Page 34: ...is the default start IP address End IP Address This field specifies the last of the addresses in the IP Address pool 192 168 1 200 is the default end IP address Address Lease Time The Address Lease Time is the amount of time a network user will be allowed connection to the router with their current DHCP Address Enter the amount of time in minutes that the user will be leased this DHCP Address The ...

Page 35: ...anent IP settings MAC Address The MAC Address of the PC Reserved IP Address The IP address assign to MAC Address Status The status of this entry either Enabled or Disabled Modify Click Modify to open Add or Modify a Address Reservation Entry page or Delete to delete entry Add New Click this button to open Add or Modify a Address Reservation Entry page Enable All Click this button to make all entri...

Page 36: ... the DHCP function Service Port The numbers of External Ports IP Address The IP address of the PC running the service application Protocol The protocol used for this application either TCP UDP or All Status The status of this entry either Enabled or Disabled Modify Click Modify to open Add or Modify a Virtual Server Entry page or Delete to delete entry Add New Click this button to open Add or Modi...

Page 37: ... router Port Triggering is used for some of these applications that can work with an NAT router Once configured operation is as follows A local host makes an outgoing connection to an external host using a destination port number defined in the Trigger Port field The router records this connection opens the incoming port or ports associated with this entry in the Port Triggering table and associat...

Page 38: ...elect the protocol used for Trigger Port from the pull down list either TCP UDP or All Incoming Ports Enter the range of port numbers used by the remote system when it responds to the PC s request You can input at most 5 groups of ports or port section Every group of ports must be apart with For example 2000 2038 2046 2050 2051 2085 3010 3030 Incoming Protocol Select the protocol used for Incoming...

Page 39: ...llows the devices such as Internet computers to access the local host resources or devices as needed UPnP devices can be automatically discovered by the UPnP service application on the LAN Note Enabling UPnP may cause router to be vulnerable to Flash UPnP attacks Current UPnP Status Click the respective button to Enable or Disable UPnP As allowing this may present a risk to security this feature i...

Page 40: ...ble Firewall The general firewall switch is on or off Enable IP Address Filtering Set IP Address Filtering is enabled or disabled There are two default filtering rules of IP Address Filtering either Allow or Deny not listed packets to pass through the router Enable Domain Filtering Set Domain Filtering is enabled or disabled Enable MAC Filtering Set MAC Address Filtering is enabled or disabled You...

Page 41: ... UDP or All all protocols supported by the router Action Selected Action Allow or Deny through the router for this entry only Status The status of this entry either Enabled or Disabled Modify Click Modify to open Add or Modify a IP Address Filtering Entry page or Delete to delete entry Add New Click this button to open Add or Modify a IP Address Filtering Entry page Enable All Click this button to...

Page 42: ...030 2000 Keep the field open which means all LAN ports have been put into the field WAN IP Address Enter a WAN IP address or a range of WAN IP addresses in the field in dotted decimal notation format For example 61 145 238 6 61 145 238 47 Keep the field open which means all WAN IP addresses have been put into the field WAN Port Enter a WAN port or a range of WAN ports in the field For example 25 1...

Page 43: ...ew Click this button to open Add or Modify a Domain Filtering Entry page Enable All Click this button to make all entries enabled Disable All Click this button to make all entries disabled Delete All Click this button to delete all entries Click the Next button to go to the next page or click the Previous button return to the previous page Add or Modify a Domain Filtering Entry Effective Time Ente...

Page 44: ...ed on Firewall page MAC Address Selected MAC Address Description Short description for entry Status The status of this entry either Enabled or Disabled Modify Click Modify to open Add or Modify a MAC Address Filtering Entry page or Delete to delete entry Add New Click this button to open Add or Modify a MAC Address Filtering Entry page Enable All Click this button to make all entries enabled Disab...

Page 45: ...ote management web interface to a custom port by entering that number in this box provided Choose a number between 1024 and 65534 but do not use the number of any common service port Remote Management IP Address This is the current address you will use when accessing your router from the Internet The default IP address is 0 0 0 0 It means this function is disabled To enable this function change th...

Page 46: ...e blocking function immediately Enable UDP FLOOD Filtering Enable or Disable the UDP FLOOD Filtering UDP FLOOD Packets threshold 5 3600 The default value is 50 Enter a value between 5 3600 packets When the current UPD FLOOD Packets number is beyond the set value the router will startup the blocking function immediately Enable TCP SYN FLOOD Attack Filtering Enable or Disable the TCP SYN FLOOD Attac...

Page 47: ...s is the IP address of the default gateway device that allows for contact between the router and the network or host Status The status of this entry either Enabled or Disabled Modify Click Modify to open Add or Modify a Static Route Entry page or Delete to delete entry Add New Click this button to open Add or Modify a Static Route Entry page Enable All Click this button to make all entries enabled...

Page 48: ... delete entry Add New Click this button to open IP MAC Binding Setting page Another way to add hosts to binding list is to use the Load or Load All button on ARP list Enable All Click this button to make all entries enabled Find Click this button to search for entries based on host MAC Address or IP Address Click the Next button to go to the next page or click the Previous button return to the pre...

Page 49: ...ad all item to the IP MAC Binding list Note An item could not be loaded to the IP MAC Binding list if the IP address of the item has been loaded before Error warning will prompt as well Likewise Load All only loads the items without interference to the IP MAC Binding list Dynamic DNS The router offers a Dynamic Domain Name System DDNS feature DDNS lets you assign a fixed host and domain name to a ...

Page 50: ...s option to enable use of Daylight Saving Time DST begin Enter date when Daylight Saving Time begins in this fields MM DD HH format DST end Enter date when Daylight Saving Time ends in this fields MM DD HH format Preferable NTP Server Enter IP Address of the primary and secondary NTP Server Get GMT Click this button to get GMT from Internet if you have connected to Internet Note Unsaved changes wi...

Page 51: ...in case of any damage System Tools Factory Defaults Restore Click this button to reset all configuration settings to their default values Note Any settings you have saved will be lost when the default settings are restored System Tools Backup and Restore Backup Click this button to save all configuration settings to your local computer as a file File click the Browse button to find the configurati...

Page 52: ... System Tools Password It is strongly recommended that you change the factory default user name and password of the router All users who try to access the router s web based utility will be prompted for the router s user name and password Old User Name Type old User Name in this field Old Password Type old Password in this field New User Name Type new User Name in this field New Password Type new ...

Page 53: ... of the last Packets Statistic interval seconds Current Statistic Status Enable or Disable The default value is disabled To enable click the Enable button If disabled the function of DoS protection in Security Advanced Security will be disabled Packets Statistic Interval The default value is 10 Select a value between 5 and 60 seconds in the pull down list The Packets Statistic interval value indic...

Page 54: ...ceived and transmitted in the last Packets Statistics interval seconds Current Bytes The total amount of bytes received and transmitted in the last Packets Statistics interval seconds Current ICMP Tx The total amount of the ICMP packets transmitted to WAN in the last Packets Statistics interval seconds Current UDP Tx The total amount of the UDP packets transmitted to WAN in the last Packets Statis...

Page 55: ...is case you should contact your vendor LAN LED The LAN LED on the front panel does not light up 1 Check the Ethernet cable connections between your router and the computer or hub 2 Check for faulty Ethernet cables 3 Make sure your computer s Ethernet card is working properly 4 If these steps fail to correct the problem contact your local distributor for assistance WAN LED The WAN LED on the front ...

Page 56: ...n the router s power until the SYS LED lights up about 3 seconds Last release the reset button and wait for the router to reboot Problems with LAN Interface I cannot access the router from the LAN or ping any computer on the LAN 1 Check the Ethernet LEDs on the front panel A LAN LED should be on for a port that has a PC connected If it is off check the cables between your router and the PC Make su...

Reviews: