background image

 Gigabit Multi-Homing VPN Security Router User’s Manual 

11.1.2 Port Range Forwarding 

 

Setting up a Port Forwarding Virtual Host: If the server function (which means the server for an external 

service such as WWW, FTP, Mail, etc) is contained in the network, we recommend that users use the firewall 

function to set up the host as a virtual host, and then convert the actual IP addresses (the Internet IP 

addresses) with Port 80 (the service port of WWW is Port 80) to access the internal server directly. In the 

configuration page, if a web server address such as 192.168.1.50 and the Port 80 has been set up in the 

configuration, this web page will be accessible from the Internet by keying in the device actual IP address 

such as, http://211.243.220.43.   

 

At this moment, the device actual IP will be converted into “192.168.1.50” by Port 80 to access the web page.   

 

In the same way, to set up other services, please input the server TCP or UDP port number and the virtual 

host IP addresses. 

 

 

 

 

 

- 109 -

Summary of Contents for MH-3400

Page 1: ...Gigabit Multi Homing VPN Security Router User s Manual User s Manual MH 3400 Gigabit Multi Homing VPN Security Router 1...

Page 2: ...PLANET PLANET assumes no responsibility for any inaccuracies that may be contained in this User s Manual PLANET makes no commitment to update or keep current the information in this User s Manual and...

Page 3: ...nt and human health as a result of the presence of hazardous substances in electrical and electronic equipment end users of electrical and electronic equipment should understand the meaning of the cro...

Page 4: ...U 9 UCHAPTER 4 LOGIN VPN SECURITY ROUTERU 11 APTER 5 SYSTEM STATUSU 13 1 HOME PAGEU 13 U5 1 1 WAN StatusU 13 U5 1 2 Physical Port StatusU 14 U5 1 3 System InformationU 15 U5 1 4 Firewall StatusU 15 U5...

Page 5: ...ress 73 U8 2 SESSION CONTROLU 74 APTER 9 FIREWALLU 76 U9 1 GENERAL POLICY 76 U 2 ACCESS RULE 79 U 9 2 1 Default Rule 79 U U U9 2 2 Add New Access Rule 80 U9 3 URL FILTERU 82 APTER 10 VPN VIRTUAL PRIVA...

Page 6: ...24 UCH UAP USTEP 5 SEND SYSTEM LOG VIA SMS MESSAGEU 150 APTER 13 LOGU 129 U13 1 SYSTEM LOGU 129 U13 2 SYSTEM STATISTICU 134 U13 3 TRAFFIC STATISTICU 135 U13 4 IP PORT STATISTICU 137 PENDIX A CONFIGURE...

Page 7: ...d Balance Unbinding WAN Balance and Strategy Routing User can also configure which IP or TCP UDP type of traffic use which WAN port to connect Inbound Load Balancing The MH 3400 provides the Inbound L...

Page 8: ...Mirror Port to connect with monitoring devices to monitor online behavior It also supporting remote management by web browser with user name and password to realize router management from remote place...

Page 9: ...t the IP address even the port has been connected Steady on LAN port has been connected LAN Link Act Green Blinking Transmit data Green Steady On Works on 1000M Amber Steady On Works on 100M LAN WAN D...

Page 10: ...z Port based QoS z QoS Schedule Firewall Security z NAT z One to One NAT z Multiple to One NAT z Stateful Packet Inspection SPI Firewall z Denial of Service DoS prevention z IP Port filtering z Block...

Page 11: ...MP v1 v2c z Monitoring Logging and Alarms of system activities z Firmware upgrade through Web browser VPN tunnel z Supports max 200 IPSec VPN Tunnels z Supports max 60 PPTP VPN Tunnels IPSec VPN z IPS...

Page 12: ...Through the process settings users can install and operate VPN Router easily This simplifies the management and maintenance making the user network settings be done at one time The main process is as...

Page 13: ...HCP IP allocation to meet different needs IP group will simplize the management work 6 Set QoS bandwidth management avoid bandwidth occupation Restrict bandwidth and session of WAN ports LAN IP and ap...

Page 14: ...User s Manual Network function setting e g PPTP different application environment 11 Logout Close configuration window Logout VPN Router web based UI We will follow the process flow to complete the ne...

Page 15: ...VPN Security Router User s Manual 2BChapter 3 Hardware Installation In this chapter we are going to introduce hardware interface as well as physical installation Safety Instruction 19B3 1 VPN Router...

Page 16: ...ernal router to connect to the Internet LAN Connection The LAN port can be connected to a Switching Hub or directly to a PC Users can use servers for monitoring or filtering through the port after Phy...

Page 17: ...ig for getting Default Gateway address as the graphic below 192 168 1 1 Make sure Default Gateway is also the default IP address of VPN QoS Router Attention When not getting IP address and default gat...

Page 18: ...e the login password in the setting later Attention For security we strongly suggest that users must change password after login Please keep the password safe or you can not login to VPN Router Press...

Page 19: ...ort Default Gateway Indicates current WAN gateway IP address from ISP DNS Indicates the current DNS IP configuration Downstream Bandwidth Usage Indicates the current downstream bandwidth usage for eac...

Page 20: ...tus summary and statisitcs of the selected port The current port setting status information will be shown in the Port Information Table Examples type 10Base T 100Base TX 1000Base T iniferface WAN LAN...

Page 21: ...urrent working mode Can be Gateway or Router mode The default is Gateway mode System active time Indicates how long the device has been running Serial Number This number is the device serial number Fi...

Page 22: ...Management Indicates if remote management is activated on or off Click the hyperlink to enter and manage the configuration The default configuration is Off Access Rule Indicates the number of access r...

Page 23: ...sword The default value for VPN Router username and password are both admin For security reasons we strongly recommend that you must change your password after first login Please keep the password saf...

Page 24: ...ve before Apply to save the configuration If users have already changed username and password they should login with current username and password and input admin as new username and password if they...

Page 25: ...you have your own preferred time server input the server IP address Apply After the changes are completed click Apply to save the configuration Cancel Click Cancel to leave without making any change...

Page 26: ...necting with the Internet However some users need advanced information from their ISP Please refer to the following descriptions for specific configurations 22B6 1 Network Connection 66B6 1 1 Host Nam...

Page 27: ...ent to setup This is configuration information for the device current LAN IP address The default configuration is 192 168 1 1 and the default Subnet Mask is 255 255 255 0 It can be changed according t...

Page 28: ...ranet the Internet is still accessible without making any changes to internal PCs Users can make changes according to their actual network structure Dynamic IP There are four set of Class C DHCP serve...

Page 29: ...advanced configuration Click Edit to enter the advanced configuration page Obtain an Automatic IP automatically This mode is often used in the connection mode to obtain an automatic DHCP IP This is th...

Page 30: ...er WAN to the Internet In this way the effect of any disconnection can be minimized Line Dropped Period Input the time rule for disconnection of this WAN service Line Dropped Scheduling Input how long...

Page 31: ...um acceptable is two IP groups Enable Line Dropped Scheduling The WAN disconnection schedule will be activated by checking this option In some areas there is a time limitation for WAN connection servi...

Page 32: ...packets The default is Disabled MTU MTU is abbreviation of Maximum Transmission Unit Auto and Manual can be chosen The default value is 1500 Different value could be set in different network environm...

Page 33: ...Although there is a standby system in the device at the moment of WAN disconnection all the external connections that go through this WAN will be disconnected too Only after the disconnected lines are...

Page 34: ...ress This option is to configure a static IP address The IP address to be configured could be one issued by ISP The IP address is usually provided by the ISP when the PC is installed Contact ISP for r...

Page 35: ...ernal connections that go through this WAN will be disconnected too Only after the disconnected lines are reconnected can they go through the standby system to connect with the Internet Therefore to a...

Page 36: ...t normally with the Internet while keeping the original Internet IP addresses in Intranet IP configuration If there are two WANs configured users still can select Transparent Bridge mode for WAN conne...

Page 37: ...ect with the Internet Therefore to avoid a huge number of disconnections users can activate this function to arrange new connections through another WAN to the Internet In this way the effect of any d...

Page 38: ...ress into a LAN PC and this PC can use this public IP address to reach the Internet Others PCs can use NAT mode to reach the Internet If this WAN network is enabled the Router plus NAT mode you can st...

Page 39: ...ected can they go through the standby system to connect with the Internet Therefore to avoid a huge number of disconnection users can activate this function to arrange new connections to be made throu...

Page 40: ...escription IP address Indicates the current default static IP address Config Indicates an advanced configuration modification Click Edit to enter the advanced configuration page The DMZ configuration...

Page 41: ...MZ IP ranges are the same with WAN IP ranges in Router Plus NAT mode Item Description LAN Default Gateway Enter the LAN Default Gateway that you configured at Router Plus NAT Mode LAN IP Range Enter t...

Page 42: ...By IP is selected the WAN bandwidth will automatically allocate connections based on IP amount to achieve network load balance Note For either session balancing or IP connection balancing collocation...

Page 43: ...ance Note Only when a device assignment is collocated with Protocol Binding can the balancing function be brought into full play For example an assignment requiring all Intranet IP addresses to go thr...

Page 44: ...define a name for the WAN grouping in the box such as Education etc The name is for recognizing different WAN groups Interface Check the boxes for the WANs to be added into this combination Add To Li...

Page 45: ...WAN ex WAN 1 or WAN grouping users designated to the Internet To build a policy document users can use a text based editor such as Notepad which is included with Windows system Follow the text format...

Page 46: ...banking encrypted connection Https or TCP443 is required to connect from the same WAN IP If one intranet IP visits web banking website and the connection is distributed into different WAN IP addresse...

Page 47: ...222 81 101 in the same Class B range the connection will also be through WAN1 200 10 10 1 If the destination is to other IP not in the same Class B range as 61 222 81 100 the session will be distribu...

Page 48: ...IP based on the first time learning Item Description User Define Dis Or Port Auto Binding Indicates that the intranet IP will connect through the same WAN IP when the service ports are self defined Y...

Page 49: ...stem for network external services If this option is selected information such Retry or Retry Timeout will be displayed If two WANs are used for external connection be sure to activate the NSD system...

Page 50: ...In this way when any of the WAN connections is broken other WANs can serve as a backup traffic can be shifted to a WAN that is still connected Default Gateway The local default communication gateway l...

Page 51: ...ffic will be shifted to the first WAN WAN1 In addition if the first WAN WAN1 is broken the traffic will be shifted to other WANs in turn For example the traffic will be shifted to WAN2 first if WAN2 i...

Page 52: ...and the application Service Ports that are not assigned to other WANs WAN2 WAN3 and WAN4 for external connections In other words the first WAN WAN1 cannot be configured with the Protocol Binding rule...

Page 53: ...ress 210 1 1 1 210 1 1 1 should be input If a range of destinations is to be assigned input the range such as 210 11 1 1 210 11 255 254 This means the Class B Network Segment of 210 11 x x will be res...

Page 54: ...s want to activate is not in the list users can add or remove service ports from Service Port Management to arrange the list as described in the following Item Description Service Name In this box inp...

Page 55: ...t IP addresses to specific destination application service ports or assign specific destination IP addresses to a WAN users choose for external connections Example 1 How do I set up Auto Load Balance...

Page 56: ...other services from going through WAN1 As in the figure below there are two rules to be configured The first rule select HTTP TCP 80 80 from the pull down option list Service and then in the boxes of...

Page 57: ...e specific WAN will only support those assigned Intranet IP addresses destination Service Ports or destination IP addresses Those which are not configured will go through other WANs for external conne...

Page 58: ...ule Select All Port TCP UDP 1 65535 from the pull down option list Service and then in the boxes of Source IP input 192 168 1 0 0 which means to include all Intranet IP addresses In the boxes for Dest...

Page 59: ...Gigabit Multi Homing VPN Security Router User s Manual 53...

Page 60: ...Mirror Port in Physical Port Status Home page Item Description Disabled This feature allows users turn on off the Ethernet port If selected the Ethernet port will be shut down immediately and no conn...

Page 61: ...each other Members in different VLAN will not know the existence of other members VLAN All Set VLAN All port to be the public area of VLAN so that it can be connected to other VLAN networks A server...

Page 62: ...lude receive transmit packet count receive transmit packet Byte count and error packet count Users may press the refresh button to update all real time messages 26B7 3 IP DHCP With an embedded DHCP se...

Page 63: ...utomatically leased by DHCP It means DHCP will start the lease from this IP The default initial IP is 192 168 1 100 Range End This is the end IP automatically leased by DHCP The default initial IP is...

Page 64: ...amic IP Used The amount of dynamic IP leased by DHCP Static IP Used The amount of static IP assigned by DHCP IP Available The amount of IP still available in the DHCP server Total IP The total IP whic...

Page 65: ...not add extra PCs for Internet access or change private IP addresses There are two methods for setting up this function Block MAC address not on the list This method only allows MAC addresses on the...

Page 66: ...Gigabit Multi Homing VPN Security Router User s Manual IP MAC Binding 60...

Page 67: ...configuration or modification to the list Delete selected item Remove the selected binding from the list Add Add new binding Block MAC address on the list with wrong IP address When this option is act...

Page 68: ...refers to WAN IP groups Local IP Group list will automatically learn IP addresses having packets that pass through firewall Moreover if user changes the IP address the IP in the list will change accor...

Page 69: ...umn Delete Group Choose the group that you would like to delete from the pull down list and push the Delete Group button System will ask you again if you would like to delete the group After pushing t...

Page 70: ...er remote IP group does not have automatically learning functions Instead you need to define addresses ranges and groups manually For example 220 130 188 1 to 200 range It is the same setting methods...

Page 71: ...setting name protocol and port range push this button to add the information into the Port list below This port can be from some port groups Group Name When you add new groups please note if the grou...

Page 72: ...riority to specific applications or services and also to enable other users to share bandwidth as well as to ensure stable and reliable network transmission To maximize the bandwidth efficiency networ...

Page 73: ...s it will guarantee a minimum rate of upstream and downstream for each IP and Service Port based on the total actual bandwidth of WAN1 and WAN2 For example if the upstream bandwidths of both WAN1 and...

Page 74: ...stream upstream speed with the unit KB 1KB 8Kbit 73B8 1 2 QoS To satisfy the bandwidth requirements of certain users the device enables users to set up QoS with Rate Control method Rate Control The ne...

Page 75: ...for Intranet IP Server in LAN Upstream If a Server for external connection has been built in the device this option is to control the bandwidth for the traffic coming from outside to this Server Serve...

Page 76: ...xed Enable Activate the rule Add to list Add this rule to the list Move up Move down QoS rules will be executed from the bottom of the list to the top of the list In other words the lower down the lis...

Page 77: ...ill remain When any IP uses more bandwidth than the above upstream or downstream settings the IP will be restricted for the following upstream or downstream bandwidth settings Enabled Penalty Mechanis...

Page 78: ...ertain percentage penalty mechanism will be actived Every __ second to detect whether internal IP s bandwidth are over than limit Detect usage of internal IP s bandwidth every __ secend If the punishe...

Page 79: ...Description WAN Select WAN ports Source IP Enter the exempted IP range or select the exempted IP group Do not control Direction Select do not control upload download or both of them Enabled Enable th...

Page 80: ...d Scheduling Item Description Disabled Disable Session Control function Single IP cannot exceed __ session This option enables the restriction of maximum external sessions to each Intranet PC When the...

Page 81: ...according to the configured range For example if the time control is from Monday to Friday 8 6 00pm users can refer to the following f Apply Click Apply to save the configuration Cancel Click Cancel t...

Page 82: ...will also perform an alarming function for application procedure Meanwhile the packet authentication firewall may decline the connections which use non standard communication protocol DoS Denial of S...

Page 83: ...irus Attack This feature is designed to prevent the intranet from being attacked by ARP spoofing causing the connection failure of the PC This ARP virus cheat mostly occurs in Internet cafes When atta...

Page 84: ...should be adjusted from high to low LAN Threshold When all packet values from internal attack or from single internal IP attack reach the maximum amount the default is 15000 packets Sec and 2000 packe...

Page 85: ...ault z All traffic from the WAN to the LAN is denied by default z All traffic from the LAN to the DMZ is allowed by default z All traffic from the DMZ to the LAN is denied by default z All traffic fro...

Page 86: ...s of packets not compliant with this control rule Service Port From the drop down menu select the service that users grant or do not give permission Service Port Management If the service that users w...

Page 87: ...heduling Select Always to apply the rule on a round the clock basis Select from and the operation will run according to the defined time Apply this rule Select Always to apply the rule on a round the...

Page 88: ...web pages Only one of these two modes can be selected Block Forbidden Domain Fill in the complete website such as www sex com to have it blocked Item Description Domain Name Enter the websites to be c...

Page 89: ...xample If users enter the string sex any websites containing sex will be blocked Keywords Only for English keyword Enter keywords Add to List Add this new service item content to the list Delete selec...

Page 90: ...allowed domain name etc www google com Add to list Add the rule to list Delete selected item Users can select one or more rules and click to delete Apply Activate the function The default setting is D...

Page 91: ...lock basis Select from and the operation will run according to the defined time to Select Always to apply the rule on a round the clock basis If From is selected the activation time is introduced as b...

Page 92: ...VPN Summary This VPN Summary displays the real time data with regard to VPN status These data include all tunnel numbers setting parameters and Group VPN and so forth Detail Push this button to displa...

Page 93: ...ected is indicated as Waiting for Connection If users select Manual setting for IPSec setup the status message will display as Manual and there is no Tunnel test function available for this manual set...

Page 94: ...Description Group Name Displays the tunnel name of the Group VPN that is connected Connected Tunnels Displays the VPN Groups tunnel numbers Phase2 Encrypt Auth DH Displays settings such as encryption...

Page 95: ...devices via the Internet When a new tunnel is added the setting page for Gateway to Gateway or Client to Gateway will be displayed Gateway to Gateway Click Add to enter the setting page of Gateway to...

Page 96: ...te this tunnel feature Local VPN Group Setting This Local Security Gateway Type must be identical with that of the remote type Remote Security Gateway Type Item Description Local Security This local g...

Page 97: ...e for VPN connection this device will start authentication and respond to this VPN tunnel connection if users select this option to link to VPN please enter the domain name 5 Dynamic IP E mail Addr US...

Page 98: ...2 Subnet This option allows local computers in this subnet can be connected to the VPN tunnel Reference When this VPN tunnel is connected only computers with the session of 192 168 1 0 and with subne...

Page 99: ...mic IP E mail Addr USER FQDN Authentication Dynamic IP address Email address name 1 IP only If users select the IP Only type entering this IP allows users to gain access to this tunnel If the IP addre...

Page 100: ...omain name must be available on the Internet When users finish the setting the corresponding IP address will be displayed under the remote gateway of Summary 4 Dynamic IP Domain Name FQDN Authenticati...

Page 101: ...erence When this VPN tunnel is connected only computers with the session of 192 168 2 0 and with subnet mask as 255 255 255 0 can connect with remote VPN IPSec Setup If there is any encryption mechani...

Page 102: ...set this VPN tunnel to use any encryption mode Note that this parameter must be identical to that of the remote encryption parameter DES 64 bit encryption mode 3DES 128 bit encryption mode AES the sta...

Page 103: ...IP is used for connection Keep Alive If this option is selected VPN tunnel will keep this VPN connection This is mostly used to connect the remote node of the branch office and headquarter or used for...

Page 104: ...etect the location the server address is best to be fast and stable response proposal can fill in the VPN remote Sever LAN IP please do not enter the server address which can not respond to ICMP Time...

Page 105: ...led Interface Users may select which port to be the node for this VPN channel They can be applied for VPN connections Enabled Click to Enable to activate the VPN tunnel This option is set to Enable by...

Page 106: ...illed into this space Users don t need to do further settings 4 Dynamic IP Domain Name FQDN Authentication rs may select this option me If users use dynamic IP address to connect to the device use to...

Page 107: ...IP address of 192 168 1 0 can establish connection his option allows local computers in this subnet to be connected to the VPN tunnel Reference When this VPN tunnel is connected computers with the IP...

Page 108: ...urther settings 2 IP Domain Name FQDN Authentication If users select IP domain name type please enter the domain name and IP address The WAN IP address will be automatically filled into this space Use...

Page 109: ...t authentication and respond to VPN tunnel connection if users select this option to link to VPN enter E Mail address to the empty field for E Mail authentication IPSec Setup If there is any encryptio...

Page 110: ...64 bit encryption mode 3DES 128 bit encryption mode AES the standard of using security code to encrypt information It supports 128 bit 192 bit and 256 bit encryption keys Phase 1 Phase 2 Authenticatio...

Page 111: ...on DPD If this option is selected the connected VPN tunnel will regularly transmit HELLO ACK message packet to detect whether there is connection between the two ends of the VPN tunnel If one end is d...

Page 112: ...ntrance IP into the local network Enter Range Start Enter the value into the last field Enter Range End Enter the value into the last field Username Please enter the name of the remote user New Passwo...

Page 113: ...external VPN device PPTP Pass Through If this option is enabled the PC is allowed to use VPN PPTP packet to pass in order to connect with external VPN device L2TP Pass Through If this option is enabl...

Page 114: ...addresses such as network games We recommend that users map the device actual WAN IP addresses directly to the Intranet virtual IP addresses as follows If the DMZ Host function is selected to cancel...

Page 115: ...ternet IP addresses with Port 80 the service port of WWW is Port 80 to access the internal server directly In the configuration page if a web server address such as 192 168 1 50 and the Port 80 has be...

Page 116: ...ent Add or remove service ports from the list of service ports Add to list Add to the active service content Service Port Management The services in the list mentioned above are frequently used servic...

Page 117: ...niversal Plug and Play is a protocol set by Microsoft If the virtual host supports UPnP system such as Windows XP users could also activate the PC UPnP function to work with the device Item Descriptio...

Page 118: ...ons Apply Click Apply to save the network configuration modification 39B11 3 Routing In this chapter we introduce the Dynamic Routing Information Protocol and Static Routing Information Protocol 81B11...

Page 119: ...iption Working Mode Select the working mode of the device NAT mode or Router mode RIP Click Enabled to open the RIP function Receive RIP versions Use Up Down button to select one of None RIPv1 RIPv2 B...

Page 120: ...s is the router layer count for the IP If there are two routers under the device users should input 2 for the router layer the default is 1 Max is 15 Interface This is to select WAN port or LAN port f...

Page 121: ...n public IP addresses For example if there are more than 2 web servers requiring public IP addresses administrators can map several public IP addresses directly to internal private IP addresses Exampl...

Page 122: ...Public IP Range Begin Input the Public IP address for the Internet One to One NAT function Range Length The numbers of final IP addresses of actual Internet IP addresses Please do not include IP addr...

Page 123: ...l Multiple to One NAT Item Description Enable Multiple to One NAT Click to enable multiple to one NAT function Private IP Range Input intranet IPs for NAT mapping Respective Public IP Input the respec...

Page 124: ...actual IP address of an ADSL PPPoE time based system or the actual IP of a cable modem will be changed from time to time To overcome this problem for users who want to build services such as a website...

Page 125: ...website address such as abc abcddns org cn as a user name for abcDDNS Password The password which is set up for DDNS Host Name Input the website address which has been applied from DDNS Examples are a...

Page 126: ...an input the network card physical address MAC address 00 xx xx xx xx xx here The device will adopt this MAC address when requesting IP address from ISP Select the WAN port to which the configuration...

Page 127: ...lated problems This tool includes DNS Name Lookup Domain Name Inquiry Test and Ping Packet Delivery Reception Test DNS Name lookup On this test screen please enter the host name of the network users w...

Page 128: ...re firmware upgrade Users must not exit this screen during upgrade Otherwise the upgrade may fail 45B 1 12 3 Configuration Backup Import Configuration File This feature allows users to integrate all b...

Page 129: ...ctivate SNMP feature The default is activated System Name Set the name of the device such as Planet System Contact Set the name of the person who manages the device i e John System Location Define the...

Page 130: ...nt configuration before upgrading firmware After firmware upgraded import the configuration file after returning to factory default to ensure system stable Please refer to 12 3 48B12 6 High Availabili...

Page 131: ...eral backup mode The master device takes responsibility of network transmitting and the other one is set as idle When the master device fails transmitting it will send out the message to the idle devi...

Page 132: ...ors can login the device remotely to manage Remote Management should be enabled Status Abnormal indicates the backup device can not be detected or does exist and need to inspect the backup device actu...

Page 133: ...will return to Normal which the backup device remains idle Two devices are operating simultaneously Item Description Operation Master Mode Besides operating network with another device Master device i...

Page 134: ...ice is 192 168 1 1 and the subnet mask is 255 255 255 0 Salve device should be in the same subnet ex 192 168 1 2 WAN Backup The Checked WANs are not working in this device The checked WANs will works...

Page 135: ...ter 13 Log From the log management and look up we can see the relevant operation status which is convenient for us to facilitate the setup and operation 49B13 1 System Log Its system log offers three...

Page 136: ...e device provides the following warning message Click to activate these features Syn Flooding IP Spoofing Win Nuke Ping of Death Unauthorized Login Attempt Item Description Syn Flooding Bulky syn pack...

Page 137: ...f PPPoE and so on Deny Policies If remote users fail to enter the system because of the access rules for instance message will be recorded in the system log Allow Policies If remote users enter the sy...

Page 138: ...can be read online via the device They include All Log System Log Access Log Firewall Log and VPN log which is illustrated as below Outgoing Packet Log View system packet log which is sent out from t...

Page 139: ...og View system packet log of those entering the firewall The log includes information about the external source IP addresses destination IP addresses and service ports It is illustrated as below Clear...

Page 140: ...such as port location device name current WAN link status IP address MAC address subnet mask default gateway DNS number of received sent total packets number of received sent total Bytes Received and...

Page 141: ...and control By Inbound IP Address The figure displays the source IP address bytes per second and percentage By outbound IP Address The figure displays the source IP address bytes per second and perce...

Page 142: ...d and percentage By Outbound Session The figure displays the source IP address network protocol type source port destination IP address destination port bytes per second and percentage By Inbound Sess...

Page 143: ...WAN port rather than Multi WANs Administrators may find out the destination IP for protocol binding to solve this login problem For example when certain port software is denied inquiring about the IP...

Page 144: ...Gigabit Multi Homing VPN Security Router User s Manual Specific Port Status Enter the service port number in the field and IP that are currently used by this port will be displayed 138...

Page 145: ...onfiguration For Example AT T 3G connection the parameter as below z APN wap cingular z Dialup Number 99 z Username WAP CINGULARGPRS COM all uppercase z Password CINGULAR1 all uppercase Please follow...

Page 146: ...ecurity Router User s Manual Step 1 USB 3G Connection Setting Sidebar Menu Network Network Connection WAN Setting Select USB port for 3G 4G connection and enter detail setting after click hyper link E...

Page 147: ...isplays PUK PIN Unlocked Key when entering incorrect PIN code more than 3 times USB Connect Status The status filed will display specific description z 3G modem is connected and works normally z 3G mo...

Page 148: ...tting APN Access Point Network most carriers use Internet as default value Need to check with carrier provider for the correct value Dial Number Default value is 99 for WCDMA UMTS system User name Pas...

Page 149: ...ain Name Server Indicates the current DNS IP configuration Downstream Bandwidth Rate Indicates the current downstream bandwidth usage for USB port Upstream Bandwidth Rate Indicates the current upstrea...

Page 150: ...still connected via USB Port Enabled This 3G 4G deice still available wait to connect 55BStep 3 Check 3G Info from Service Provider Sidebar Menu USB Setting Item Description Interface Indicated Curren...

Page 151: ...onal fee after exceeding the preimum Auto Disconnect Auto isconnection function when user defines max accumulated traffic to aviod paying unplanned 3G service fee Previous Total Traffic Previous traff...

Page 152: ...uto disconnect Auto isconnection function when user defines max accumulated time to aviod paying unplanned 3G service fee Previous Cumulative Time Previous accumulated time record after clean button i...

Page 153: ...uding active mode power saving mode and power off mode z Scheduling mode 3G services can be automatically connected following the pre set time Performance mode The performance mode will keep 3G 4G ser...

Page 154: ...G dongle back to power saving mode Auto self test Item Description Interface USB Display USB interface USB 3G 4G dongle will be activated and run the connection test on a daily basis Add log for auto...

Page 155: ...lick NSD Start Failover checkbox before configuring the Threshold Start Load Balance settings 1 Configure Threshold Start Load Balance Take the above GUI screenshot for example when the router detects...

Page 156: ...Multi Homing VPN Security Router User s Manual 57BStep 5 Send System log Via SMS Message Sidebar Menu Log System Log Send SMS Router can send system log to mobile phones via SMS when events are trigge...

Reviews: