background image

 

39 

 

12. 

[Save]: 

Save the RIP setting. This has no effect on the Static 

Routing Table. 

DMZ  

The DMZ PC will receive all incoming data where the destination 
PC (on the LAN) is unknown. 

z

  If you have only 1 WAN IP address, only DMZ 1 can be used. If 

you have multiple WAN IP addresses, you can bind each one 
to a PC. (Multiple DMZ function support two entries, can be 
support seven entries in the future.) 

z

  If an Internet application does not work, and it is not listed in 

Special Applications, try using the DMZ feature. 

z

  The DMZ PC is effectively outside the Firewall, so has less 

protection. Because of this, the DMZ should be enabled only 
when required. 

 

1. 

Enable:

 If enable, the DMZ PC will receive all “Unknown” 

connections and data. 

2. 

WAN IP Address:

 Enter a WAN IP Address for DMZ. 

3. 

PC:

 Select the PC for this DMZ. 

VLAN (Visual LAN) 

VLAN make several Computers (on the same Port) become a 
group and each group is protected from other Groups, so it will be 
safer. 

z

  VLAN make several Computers (on the same Port) become a 

Summary of Contents for BRL-04FM

Page 1: ......

Page 2: ...APTER 4 CONFIGURING THE BRL 04FM 18 LOGIN 18 INTERNET CONNECTION WIZARD 19 Normal Connect 19 PPPoE Connect 20 LOCAL NETWORK SETUP 22 ADVANCED SETUP 23 PC Database 23 Visual Server 26 Special Applications 27 Access Qualify 29 URL Filter 32 Security 33 Log 35 UPnP 37 Routing 37 DMZ 39 VLAN Visual LAN 39 MAC Address 40 Password 41 Remote Administer 41 Dynamic DNS 42 STATUS 43 WAN 43 LAN 46 System Dat...

Page 3: ...sed on its network The following functions of Windows Messenger a UPnP compliant application are supported by BRL 04FM Windows Messenger Instant Message Voice Chat Video Chat Receive Send Files Remote Assistance Application Sharing White Board the Place Call function is not supported z Supports Special Application feature When NAT IP masquerading is enabled applications whose send packets and rece...

Page 4: ...sent out in the form of syslog or E mail Detectable DoS Attacks IP Spoofing Land Attack Ping of Death Zero Length IP Smurf Attack UDP Port Loopback Snork Attack TCP null scan TCP Synflood z Controls access from the LAN side The product is capable of controlling access to the Internet from the LAN side The following access rules or filters can be assigned to each group of PC s attached to the LAN 1...

Page 5: ...e product s DHCP Server Client feature automatically 1 obtains an IP address from a DHCP server on the WAN side and 2 allocates an IP address to each client attached to its LAN ports z PPPoE Connectivity In addition to ordinary Ethernet static DHCP connection the product supports Point to Point Protocol over Ethernet PPPoE Since the BRL 04FM provides PPPoE client function by itself there is no nee...

Page 6: ...sh and Linux Note Some ISP s place limitations on the use of routers like this product or access to the Internet from multiple users Please be sure to verify the service agreement provided by your ISP bRoadLanner series products are not dial up routers Package List Before installing the BRL 04FM verify that you have the items listed under Package List Also be sure that you have the necessary cabli...

Page 7: ...esponding LAN hub port is active Off No active connection on the corresponding LAN hub port Flashing Data is Being transmitted or received via the corresponding LAN hub port 100 Orange On Corresponding LAN hub port is using 100BaseT Off Corresponding LAN hub port is using 10BaseT or no active connection WAN Green On Connection to the modem attached to the WAN Internet port is established Flashing ...

Page 8: ...et Button for a few seconds until the RED LED has flashed TWICE 4 Release the Reset Button The BRL 04FM is now using the factory default values WAN Connect the DSL or Cable Modem here If your modem came with a cable use the supplied cable Otherwise use a standard LAN cable LAN Use standard LAN cables RJ45 connectors to connect your PCs to these ports Note Any LAN port on the BRL 04FM will automati...

Page 9: ...utomatically function as an Uplink port when required 3 Connect WAN Cable Connect the DSL or Cable modem to the WAN port on the BRL 04FM Use the cable supplied with your DSL Cable modem If no cable was supplied use a standard cable 4 Power Up Power on the Cable or DSL modem Connect the supplied power adapter to the BRL 04FM and power up Use only the power adapter provided Using a different one may...

Page 10: ...e network settings of the computers on you LAN to use the same IP subnet as the BRL 04FM Windows 95 98 ME 1 From the Windows desktop click Start Settings Control Panel 2 Double click the Network icon 3 On the Network window Configuration tab double click the TCP IP entry for your network card 3 ...

Page 11: ...Click the IP Address tab If Obtain an IP address automatically is already checked your computer is already configured for DHCP 5 Click the Gateway tab and record the numbers listed under installed gateways ...

Page 12: ... DNS servers listed under DNS Server search Order Click OK 7 Windows may need your Windows 95 98 ME CD to copy some files After it finishes copying it will then prompt you to restart your system Click Yes and the computer will shut down and restart ...

Page 13: ...indows 2000 1 From the Windows desktop click Start Settings Control Panel 2 Double click the Network and Dial up Connections icon 3 Double click the icon that corresponds to the connection to your BRL 04FM ...

Page 14: ...12 4 Click Properties 5 Double click Internet Protocol TCP IP 6 Check Obtain an IP address automatically and check Obtain DNS server address automatically ...

Page 15: ...OK Click OK or Close to close each window Windows XP 1 From the Windows desktop click the start button Choose Control Panel 2 Select the Network and Internet Connections icon then click the Network Connection icon ...

Page 16: ...14 3 Double click on the LAN or High Speed Internet 4 Click Properties 5 Double click Internet Protocol TCP IP ...

Page 17: ...er address automatically 7 Click OK Click OK or Close to close each window Disable HTTP Proxy 1 Open Internet Explorer and click the stop button Click Tools then Internet Options 2 In the Internet Options window click the Connections tab Next click the LAN Settings button ...

Page 18: ...the start button Choose Run then enter the winipcfg and click OK button 2 Your IP Configuration window should appear 3 Select the appropriate Network Adapter from the drop down box 4 Check whether the 192 168 1 x 255 255 255 0 and 192 168 1 1 has already been got onto IP Address Subnet Mask and IP Gateway IP Address is within the range of 192 168 1 2 192 168 1 254 ...

Page 19: ... next step 4 Type the ipconfig release and click Enter The IP address will release 5 Type the ipconfig renew and click Enter The IP address will renew 6 The IP Address Subnet Mask and Default Gateway should been got to 192 168 1 x 255 255 255 0 and 192 168 1 1 7 Type the exit and click Enter will close this window There may be something wrong in your installation procedure Check the following item...

Page 20: ...e Navigator 4 0 or above Using the web management interface you may configure the BRL 04FM and view statistics to monitor network activity Login After installing the BRL 04FM in your LAN start your PC If your PC is already running restart it Start your WEB browser In the Address box enter HTTP and the IP Address of the BRL 04FM as in this example which uses the BRL 04FM s default IP Address HTTP 1...

Page 21: ...rmal Connect option and click Next to continue If ISP is provided dial up ADSL network connection Please select PPPoE Connect option and click Next to continue Normal Connect 1 If ISP is provide CATV or ADSL network connection Please click Next to continue 2 This page can be set Host Name Domain Name and MAC address Use the default values if your ISP did not provide this data Click Next to continu...

Page 22: ... the ISP DNS Address The DNS Address provide by the ISP Click Next to continue 4 This screen allowed set checkbox to Enable or Disable the Test Internet Connection Click Finish button will save data and commencing test Click Close when you wish to exit the Wizard PPPoE Connect 1 If ISP is provide dial up ADSL network connection Please select PPPoE Connect option and click Next to continue ...

Page 23: ...ically You can enable this function if your ISP disconnect this function will auto connect to your ISP z Disconnect automatically If enabled default is 15 minutes will be disconnect for leave unused z MSS Maximum segment Size MSS value should only be changed if advised to do by Technical Support Click Next to continue 3 What type of IP address was assigned by your ISP z IP address is assigned auto...

Page 24: ...address for the Broadband Router as seen from the local LAN Use the default value unless the address is already in use or your LAN is using a different IP address range In the latter case enter an unused IP Address from within the range used by your LAN z Subnet Mask The default value 255 255 255 0 is standard for small class C networks For other networks use the Network Mask for the LAN segment t...

Page 25: ...ws PCs act as DHCP clients z For DHCP clients the BRL 04FM will always allocate the same IP address There is no need to reserve an IP address for a PC to ensure that the PC s IP address does not change z The BRL 04FM uses the Physical Address to identify each PC not the name or IP address z This system means you do NOT need to use Fixed static IP addresses on your LAN However you can add PCs using...

Page 26: ...7 Generate Report Display a read only list showing full details of all entries in the PC database 8 Advanced Administration Click this to view the advanced PC Database screen Advanced Administration Any PC may be added edited or deleted If adding a PC which is not connected and on you must provide the MAC hardware address 1 Known PCs This lists all current entries PCs or network devices 2 Edit Use...

Page 27: ...his if the PC is using a Fixed Static IP address Enter the IP address allocated to the PC The PC must be configured to use this IP address 6 MAC Address Select the appropriate option Automatic discovery Select this to have the Broadband Router contact the PC and find its MAC address This is only possible if the PC is connected to the LAN and powered on Mac Address is Enter the MAC address on the P...

Page 28: ...net users to connect to your Servers you can use the DDNS feature This allows Internet users to connect to your Servers with a URL rather than an IP address This technology works even if your ISP allocates dynamic IP addresses IP address is allocated upon connection so it may change each time you connect 1 Servers This lists a number of pre defined Servers plus any Servers you have defined Details...

Page 29: ...data shown in the Properties area on screen The entry selected in the list is ignored and has no effect 9 Update Selected Server Update the current Virtual Server entry using the data shown in the Properties area on screen 10 Delete Delete the current Virtual Server entry Note that the pre defined Servers can not be deleted 11 Clear Form Clear all data from the Properties area ready for input of a...

Page 30: ...irewall z If an Internet application does not work you can try defining it here You will need detailed information about the application from the provider of the service or application z Note that the terms Incoming and Outgoing refer to traffic from the client PC viewpoint z If the application can t be made to work you could also try the DMZ feature 1 Application Name Enter a descriptive name to ...

Page 31: ...ses a single port number enter it in both the Start and Finish fields Access Qualify Configure LAN Host Internet Access Control z The Access Control feature allows administrators to restrict Internet Access by individual PCs These restrictions apply only to traffic on the WAN port local LAN traffic is not affected z PCs must be in the PC Database If required you can manually add PCs to the PC Data...

Page 32: ...to create the most restrictive group Block selected Services You can select which Services are to block Use this to gain fine control over the Internet access for a group 4 Block by Schedule If Internet access is being blocked you can choose to apply the blocking only during scheduled times If access is not blocked no Scheduling is possible and this setting has no effect 5 Define Schedule Button C...

Page 33: ...uring the scheduled time between the Start and Finish times Two 2 separate sessions or periods can be defined Times must be entered using a 24 hr clock If the time for a particular day is blank no action will be performed 1 Day Each day of the week can scheduled independently 2 Session 1 2 Two 2 separate sessions or periods can be defined Session 2 can be left blank if not required 3 Start Time En...

Page 34: ... field can be used to enter the end of range of port numbers This can be left blank if not required 7 ICMP Type If the Type above is ICMP enter the ICMP type here Otherwise this field should be left blank URL Filter When enabled a request is blocked if any of the Filter strings occur in the requested URL z This feature allows you to block access to Web sites by defining filter strings If the filte...

Page 35: ... e g ads Any URL which contains ANY entry ANYWHERE in the URL will be blocked 3 Delete Use these buttons to delete the selected entry or all entries as required Multiple entries can be selected by holding down the CTRL key while selecting On the Macintosh hold the SHIFT key while selecting 4 Delete Use these buttons to delete all entries 5 Add Use this to add the current Filter String to the site ...

Page 36: ... Server with a connection request but then does not reply to the Server s response While the optimum number of half open connections allowed the Threshold depends on many factors the most important factor is the available bandwidth of your Internet connection Select the setting to match the bandwidth of your Internet connection 3 Respond to Ping on WAN Interface The ICMP protocol is used by the pi...

Page 37: ...ing Internet connections are logged Normally the Internet Destination will be shown as a URL 2 Access Control If enabled the log will include attempted outgoing connections which have been blocked by the Access Control feature 3 Dos Attack If enabled this log will show details of DoS Denial ...

Page 38: ...e sent when the log is full which will depend on the volume of traffic Every day Every Monday The log is sent on the interval specified If Every day is selected the log is sent at the time specified If the day is specified the log is sent once per week on the specified day Select the time of day you wish the E mail to be sent If the log is full before the time specified to send it it will be sent ...

Page 39: ...tion only applies to users running Windows XP who access the Properties via UPnP e g Right click the Broadband Router in My Network Places and select Properties 3 Disable UPnP function when access Internet If checked then UPnP users can disable Internet access via this device If Disabled UPnP users can NOT disable Internet access via this device But currently this restriction only applies to users...

Page 40: ...default mask is 255 255 255 0 5 Gateway IP Address The IP Address of the Gateway or Router which the Broadband Router must use to communicate with the destination above NOT the router attached to the remote segment 6 Metric The number of hops routers to pass through to reach the remote LAN segment The shortest path will be used The default value is 1 7 Add Add a new entry to the Static Routing tab...

Page 41: ... Internet application does not work and it is not listed in Special Applications try using the DMZ feature z The DMZ PC is effectively outside the Firewall so has less protection Because of this the DMZ should be enabled only when required 1 Enable If enable the DMZ PC will receive all Unknown connections and data 2 WAN IP Address Enter a WAN IP Address for DMZ 3 PC Select the PC for this DMZ VLAN...

Page 42: ...icular MAC address z This address is a low level network identifier for this device It may be called MAC Address Hardware Address or Physical Address On a PC this address is associated with the Network card or adapter z The address here in on the WAN Internet port and has no effect on the LAN interface z If your ISP asks for the Network Adapter Address Physical Address Hardware Address or MAC Addr...

Page 43: ...d is set the password will be required in order to change the configuration 2 Verify Password Enter the new password here again This entry must match the value above Remote Administer If enabled this device can be administered via the Internet using your Web Browser See help for details of the Port Number 1 Enable Remote Management Check to allow administration management via the Internet To conne...

Page 44: ...e Internet IP address of this device port_number is the port number assigned on this screen 3 You should then be prompted for the password for this device You must assign a password Dynamic DNS Dynamic DNS allows you to provide Internet users with a domain name instead of an IP Address to access your Virtual Servers Register for this FREE service at http www dyndns org z This free service is very ...

Page 45: ...urn to http www dyndns org and use the Create New Host option to have your desired Domain name allocated to you 3 Details of your http www dyndns org account Name password Domain name must then be entered and saved on this screen 4 This device will then automatically ensure that your current IP Address is recorded at http www dyndns org 5 From the Internet users will now be able to connect to your...

Page 46: ...P s server If there is an error you can click the Connection Details button to find out more information 4 IP Address This IP Address is allocated by the ISP Internet Service Provider If using a dynamic IP address and no connection currently exists this information is unavailable 5 Connection Details Click this button to open a sub window and view a detailed description of the current connection D...

Page 47: ...to manually renew the lease immediately If Disabled the the Internet IP Address from your ISP is Fixed or Static In this case the Release Renew button is not operational 7 Release Renew This button is only useful if the IP address shown above is allocated automatically on connection Dynamic IP address Otherwise it has no effect This button will say Release if the Broadband Router is currently usin...

Page 48: ...ing connection The most common messages are listed in the table below The Clear Log button will restart the Log while the Refresh buton will update the messages shown on screen 6 Clear Log Delete all data currently in the Log This will make it easier to read new messages 7 Connect If not connected establish a connection to your ISP 8 Disconnect If connected to your ISP hang up the connection 9 Ref...

Page 49: ... Version The version of the current firmware installed 3 System Detail Click this button to open a sub window containing additional data about the system status and configuration Firmware Update Use this screen to upgrade your BRL 04FM firmware z You must download the required firmware file and store it on your PC z During the upgrade process all existing Internet connections will be terminated z ...

Page 50: ...ade file Select this file 3 Start Upgrade Click this button to start the Firmware upgrade Note than any users accessing the Internet via the BRL 04FM will lose their connection When the upgrade is finished the BRL 04FM will restart and this management connection will be unavailable during the restart 4 Cancel Cancel does NOT stop the Upgrade process if it has started It only clears the input for t...

Page 51: ...check the Properties for the TCP IP protocol Problem 2 When I enter a URL or IP address I get a time out error Solution 2 A number of things could be causing this Try the following troubleshooting steps Check if other PCs work If they do ensure that your PCs IP settings are correct If using a Fixed Static IP Address check the Network Mask Default gateway and DNS as well as the IP Address If the PC...

Page 52: ... on the LAN Multiple DMZ function support two entries can be support seven entries in the future Access Control By schedule time days of the week supports log output By service content supports log output URL filtering Firewall DoS attack detection supports log output and notification via syslog E mail SPI Stateful Packet Inspection Configuration Interface Web browser Log Management Log can be vie...

Page 53: ...net Internet BBS 25 SMTP Send mail 53 DNS 79 Finger 80 HTTP World Wide Web 110 POP3 Receive mail 113 AUTH Authentication 119 NNTP Net News 139 NETBIOS Session Service 161 SNMP 162 SNMP TRAP 443 HTTPS 500 ISAKMP 517 TALK 518 NTALK 1723 PPTP Microsoft VPN 2049 NFS Sun Network File System C ...

Reviews: