Sitecom WLR-4001 User Manual Download Page 41

 

41 

 

Denial of Service (DoS) 

 

The  Broadband  router's  firewall  can  block  common  hacker  attacks,  including 

Denial of Service, Ping of Death, Port Scan and Sync Flood. If Internet attacks 

occur the router can log the events. 

 

 

Ping of Death

 Protections from Ping of Death attack 

 

Discard Ping From WAN

 The router’s WAN port will not respond to any Ping 

requests 
 

Port Scan

 Protects the router from Port Scans. 

 

Sync Flood

 Protects the router from Sync Flood attack. 

 

Summary of Contents for WLR-4001

Page 1: ...WLR 4001 Wireless Gigabit Router 300N 802 11 b g n ...

Page 2: ...UP WLR 4001 16 11 CONFIGURATION WIZARD 25 12 WIRELESS SETTINGS 27 13 FIREWALL SETTINGS 39 14 ADVANCED SETTINGS 45 15 TOOLBOX SETTINGS 55 Revision 1 0 Sitecom Europe BV 2011 Note All the information contained in this manual was correct at the time of publication However as our engineers are always updating and improving the product your device s software may have a slightly different appearance or ...

Page 3: ...y to transmit multiple streams of data in a single wireless channel giving you seamless access to multimedia content The robust RF signal travels farther eliminates dead spots and extends the network range For data protection and privacy the WLR 4001 encodes all wireless transmissions with WEP WPA or WPA2 encryption With the inbuilt DHCP Server powerful SPI firewall the WLR 4001 protects your comp...

Page 4: ...ver Mapping DMZ IP Filter ICMP Blocking SPI Avoids the attacks of Hackers or Viruses from Internet Support 802 1x authenticator 802 11i WPA WPA2 AES VPN pass through Provide mutual authentication Client and dynamic encryption keys to enhance security WDS Wireless Distribution System Make wireless AP and Bridge mode simultaneously as a wireless repeater Theoretical wireless signal rate based on IEE...

Page 5: ...ms listed below are missing Do not discard the packing materials in case of return the unit must be shipped back in its original package 1 The WLR 4001 Router 2 A 110V 240V to 12V 1A Switching Power Adapter 3 A Quick Install Guide 4 A CD User s Manual 5 A Warranty card 6 An UTP cable ...

Page 6: ...uter yourself you might damage the router or endanger yourself 3 4 Disposing of the Router When you dispose of the router be sure to dispose it appropriately Some countries may regulate disposal of an electrical device please consult with your local authority 3 5 Others When using this router please do not let it come into contact with water or other liquids If water is accidentally spilled on the...

Page 7: ... 4 Product Layout Port Description Power connector Connect the 12V DC adapter to this port LAN Yellow Connect your PC s or network devices to this port WAN Blue Connect your ADSL Cable modem to this port ...

Page 8: ...bes the IP address login details SSID security code and WPS button functionality Button Description OPS BUTTON Press 2 seconds for OPS mode Press 10 seconds to reset the router Press 15 Seconds to reset the router to factory defaults ...

Page 9: ...he cable is connected LAN Blue Shows the cable is connected LAN Blue Shows the cable is connected LAN Blue Shows the cable is connected WAN Blue Shows the cable is connected WiFi Blue Shows WiFi activity Power Red Shows the device is turned on OPS Blue Shows OPS activity ...

Page 10: ...rt RJ 45 PC with a Web Browser Internet Explorer Safari Firefox Opera Ethernet compatible CAT5 cables 6 WLR 4001 Placement You can place the WLR 4001 on a desk or other flat surface or you can mount it on a wall For optimal performance place your Wireless Broadband Router in the center of your home or your office in a location that is away from any potential source of interference such as a metal ...

Page 11: ...11 7 Setup LAN WAN WAN connection LAN connection ...

Page 12: ...12 8 PC Network Adapter setup Windows XP Enter Start Menu select Control panel select Network Select Local Area Connection icon select properties ...

Page 13: ... Select Internet Protocol TCP IP Click Properties Select the General tab The router supports DHCP function please select both Obtain an IP address automatically and Obtain DNS server address automatically ...

Page 14: ...14 Windows Vista Seven Enter Start Menu select Control panel select View network status and tasks select Manage network connections Select Local Area Connection icon select properties ...

Page 15: ...t Internet Protocol Version 4 TCP IPv4 Click Properties Select the General tab The router supports DHCP function please select both Obtain an IP address automatically and Obtain DNS server address automatically ...

Page 16: ...utlet The WLR 4001 automatically enters the self test phase During self test phase the Power LED will be lit continuously to indicate that this product is in normal operation 10 Initial Setup WLR 4001 LOGIN procedure 1 OPEN your browser e g Internet Explorer 2 Type http 192 168 0 1 in the address bar and press Enter ...

Page 17: ...n admin 4 Click OK 5 You will see the home page of the WLR 4001 The System status section allows you to monitor the current status of your router the UP time hardware information serial number as well as firmware version information is displayed here ...

Page 18: ...fy a Subnet Mask for your LAN segment 802 1d Spanning Tree is Disabled by default If the 802 1d Spanning Tree function is enabled this router will use the spanning tree protocol to prevent network loops DHCP Server Enabled by default You can enable or disable the DHCP server When DHCP is disabled no ip addresses are assigned to clients and you have to use static ip addresses When DHCP server is en...

Page 19: ...riod is reached IP Address Pool You can select a particular IP address range for your DHCP server to issue IP addresses to your LAN Clients Note default IP range is 192 168 0 100 192 168 0 200 If you want your PC s to have a static fixed IP address then you ll have to choose an IP address outside this IP address Pool Domain Name You can specify a Domain Name for your LAN or just keep the default s...

Page 20: ...20 Device Status View the Broadband router s current configuration settings Device Status displays the configuration settings you ve configured in the Wizard Basic Settings Wireless Settings section ...

Page 21: ...isplays whether the WAN port is connected to a Cable DSL connection It also displays the router s WAN IP address Subnet Mask and ISP Gateway as well as MAC address the Primary DNS Press the Renew button to renew your WAN IP address ...

Page 22: ... address and expiration time for each DHCP leased client Use the Refresh button to update the available information You can check Enable Static DHCP IP It is possible to add more static DHCP IPs They are listed in the table Current Static DHCP Table IP can be deleted at will from the table Click apply button to save the changed configuration ...

Page 23: ...occurred after system start up At the bottom of the page the system log can be saved Save to a local file for further processing or the system log can be cleared Clear or it can be refreshed Refresh to get the most updated information When the system is powered down the system log will disappear if not saved to a local file ...

Page 24: ...24 Statistics Shows the counters of packets sent and received on WAN LAN WLAN ...

Page 25: ...ion Wizard Click Wizard to configure the router The Setup wizard will now be displayed check that the modem is connected and click Next Select your country from the Country list Select your internet provider Click Next ...

Page 26: ...the chosen provider you may need to enter your user name and password MAC address or hostname in the following window After you have entered the correct information click Next Click APPLY to complete the configuration ...

Page 27: ... that are used for the wireless stations to connect to this router The parameters include Mode ESSID Channel Number and Associated Client Wireless Function Enable or Disable Wireless function here Click Apply and wait for module to be ready loaded ...

Page 28: ...ow 80211b and 802 11g clients at the same time Enable SSID Allows you to enable up to four SSIDs for this router SSID This is the name of the wireless signal which is broadcasted All the devices in the same wireless LAN should have the same ESSID Channel The channel used by the wireless LAN All devices in the same wireless LAN should use the same channel ...

Page 29: ...s can associate with this wireless router without WEP encryption When you select Shared Key you should also setup a WEP key in the Encryption page After this has been done make sure the wireless clients that you want to connect to the device are also setup with the same encryption key Fragment Threshold Fragment Threshold specifies the maximum size of a packet during the fragmentation of data to b...

Page 30: ...ompliant wireless nodes Highest to lowest data rate can be fixed Channel Bandwidth is the range of frequencies that will be used Preamble Type The Long Preamble can provide better wireless LAN compatibility while the Short Preamble can provide better wireless LAN performance CTS Protection It is recommended to enable the protection mechanism This mechanism can decrease the rate of data collision b...

Page 31: ...ction and are setup with the same security key SSID Selection Here you choose the SSID for which you wish to set the security Broadcast ESSID If you enabled Broadcast ESSID every wireless station located within the coverage of this access point can discover this access point easily If you are building a public wireless network enabling this feature is recommended Disabling Broadcast ESSID can prov...

Page 32: ...1x Auth IEEE 802 1x is an authentication protocol Every user must use a valid account to login to this Access Point before accessing the wireless LAN The authentication is processed by a RADIUS server This mode only authenticates users by IEEE 802 1x but it does not encrypt the data during communication ...

Page 33: ...ll be the higher level of security is used but the throughput will be lower Key Format You may select ASCII Characters alphanumeric format or Hexadecimal Digits in the A F a f and 0 9 range to be the WEP Key Key1 Key4 The WEP keys are used to encrypt data transmitted in the wireless network Use the following rules to setup a WEP key on the device 64 bit WEP input 10 digits Hex values in the A F a ...

Page 34: ...eless stations and encrypt data during communication It uses TKIP or CCMP AES to change the encryption key frequently So the encryption key is not easy to be cracked by hackers This is the best security available WPA Radius Wi Fi Protected Access WPA is an advanced security standard You can use an external RADIUS server to authenticate wireless stations and provide the session key to encrypt data ...

Page 35: ...35 ...

Page 36: ... difficulties filling in the fields just click Clear and both MAC Address and Comment fields will be cleared Remove an address from the list If you want to remove a MAC address from the Current Access Control List select the MAC address that you want to remove in the list and then click Delete Selected If you want to remove all the MAC addresses from the list just click the Delete All button Click...

Page 37: ...s two types of WPS WPS via Push Button and WPS via PIN code If you want to use the Push Button you have to push a specific button on the wireless client or in the utility of the wireless client to start the WPS mode and switch the wireless router to WPS mode You can simply push the WPS button of the wireless router or click the Start to Process button in the web configuration interface If you want...

Page 38: ... name SSID of the router Authentication Mode It shows the active authentication mode for the wireless connection Passphrase Key It shows the passphrase key that is randomly generated by the wireless router during the WPS process You may need this information when using a device which doesn t support WPS WPS via Push Button Press the button to start the WPS process The router will wait for the WPS ...

Page 39: ...ers thus limiting the risk of hacker attacks and defending against a wide array of common Internet attacks However for applications that require unrestricted access to the Internet you can configure a specific client server as a Demilitarized Zone DMZ Note To enable the Firewall settings select Enable and click Apply ...

Page 40: ...at the virtual server re directs a particular service Internet application e g FTP websites to a particular LAN client server whereas DMZ re directs all packets regardless of services going to your WAN IP address to a particular LAN client server Enable DMZ Enable disable DMZ Public IP Address The IP address of the WAN port or any other Public IP addresses given to you by your ISP Client PC IP Add...

Page 41: ...of Death Port Scan and Sync Flood If Internet attacks occur the router can log the events Ping of Death Protections from Ping of Death attack Discard Ping From WAN The router s WAN port will not respond to any Ping requests Port Scan Protects the router from Port Scans Sync Flood Protects the router from Sync Flood attack ...

Page 42: ...l clients will be allowed to access Internet accept for the clients in the list below Allow If you select Allow then all clients will be denied to access Internet accept for the PCs in the list below Filter client PCs by IP Fill in IP Filtering Table to filter PC clients by IP Add PC You can click Add PC to add an access control rule for users by IP addresses Remove PC If you want to remove some P...

Page 43: ...dd If you find any typo before adding it and want to retype again just click Reset and the fields will be cleared Remove PC If you want to remove some PC from the MAC Filtering Table select the PC you want to remove in the table and then click Delete Selected If you want to remove all PCs from the table just click the Delete All button If you want to clear the selection and re select again just cl...

Page 44: ...RL address or the keyword of the web site you want to block Remove URL Keyword If you want to remove some URL keywords from the Current URL Blocking Table select the URL keyword you want to remove in the table and then click Delete Selected If you want remove all URL keywords from the table just click Delete All button If you want to clear the selection and re select again just click Reset Click A...

Page 45: ...s the Internet through a single Public IP Address or multiple Public IP Addresses NAT provides Firewall protection from hacker attacks and has the flexibility to allow you to map Private IP Addresses to Public IP Addresses for key services such as Websites and FTP Select Disable to disable the NAT function ...

Page 46: ...rwarding Private IP This is the private IP of the server behind the NAT firewall Type This is the protocol type to be forwarded You can choose to forward TCP or UDP packets only or select both to forward both TCP and UDP packets Port Range The range of ports to be forward to the private IP Comment description of this setting Add Port Forwarding Fill in the Private IP Type Port Range and Comment of...

Page 47: ...o remove a Port Forwarding setting from the Current Port Forwarding Table select the Port Forwarding setting that you want to remove in the table and then click Delete Selected If you want to remove all Port Forwarding settings from the table just click Delete All button Click Reset will clear your current selections ...

Page 48: ... port number from the Internet WAN Port to a particular LAN private IP address and its service port number Enable Virtual Server Enable Virtual Server Private IP This is the LAN client host IP address that the Public Port number packet will be sent to Private Port This is the port number of the above Private IP host that the below Public Port number will be changed to when the packet enters your L...

Page 49: ...d Then this Virtual Server setting will be added into the Current Virtual Server Table below Remove Virtual Server If you want to remove Virtual Server settings from the Current Virtual Server Table select the Virtual Server settings you want to remove in the table and then click Delete Selected If you want to remove all Virtual Server settings from the table just click the Delete All button Click...

Page 50: ...ons Enable Trigger Port Enable the Special Application function Trigger Port This is the out going Outbound range of port numbers for this particular application Trigger Type Select whether the outbound port protocol is TCP UDP or both Public Port Enter the In coming Inbound port or port range for this type of application e g 2300 2400 47624 Public Type Select the Inbound port protocol type TCP UD...

Page 51: ...l in the Trigger Port Trigger Type Public Port Public Type Public Port and Comment of the setting to be added and then click Add The Special Application setting will be added into the Current Trigger Port Table below If you happen to make a mistake just click Clear and the fields will be cleared Remove If you want to remove Special Application settings from the Current Trigger Port Table select th...

Page 52: ...le or Disable the UPnP feature here After you enable the UPnP feature all client systems that support UPnP like Windows XP can discover this router automatically and access the Internet through this router without having to configure anything The NAT Traversal function provided by UPnP can let applications that support UPnP connect to the internet without having to configure the virtual server sec...

Page 53: ...r experience in using critical real time services like Internet phone video conference etc All the applications not specified by you are classified as rule name Others The rule with a smaller priority number has a higher priority the rule with a larger priority number has a lower priority You can adjust the priority of the rules by moving them up or down Enable Disable QoS You can check Enable QoS...

Page 54: ...t click the Delete All button Clicking Reset will clear your current selections Edit a QoS rule Select the rule you want to edit and click Edit then enter the detail form of the QoS rule Click Apply after editing the form and the rule will be saved Adjust QoS rule priority You can select the rule and click Move Up to make its priority higher You also can select the rule and click Move Down to make...

Page 55: ...nt Passwords can contain 0 to 12 alphanumeric characters and are case sensitive Current Password Fill in the current password to allow changing to a new password New Password Enter your new password Confirmed Password Enter your new password again for verification purposes Click Apply at the bottom of the screen to save the above configurations ...

Page 56: ...r Address You can set an NTP server address Enable Daylight Savings The router can also take Daylight savings into account If you wish to use this function you must check tick the enable box to enable your daylight saving configuration below Start Daylight Savings Time Select the period in which you wish to start daylight Savings Time End Daylight Savings Time Select the period in which you wish t...

Page 57: ... the host in the Internet that will have management configuration access to the Broadband router from a remote site If the Host Address is left 0 0 0 0 this means anyone can access the router s web based configuration from a remote location providing they know the password Port The port number of the remote management web interface Enabled Select Enabled to enable the remote management function Cl...

Page 58: ... upgrade the firmware of your Broadband router you need to download the firmware file to your local hard disk and enter that file name and path in the appropriate field on this page You can also use the Browse button to find the firmware file on your PC Once you ve selected the new firmware file click Apply at the bottom of the screen to start the upgrade process ...

Page 59: ...Factory Defaults selection this will set all configurations to its original default settings e g when you first purchased the router Use the Backup tool to save the Broadband router current configuration to a file named config bin on your PC You can then use the Restore tool to restore the saved configuration to the Broadband router Alternatively you can use the Restore to Factory Defaults tool to...

Page 60: ...60 Reset You can reset the router s system should any problem exist The reset function essentially re boots your router s system ...

Page 61: ...r common DDNS service providers Enable Disable Enable or disable the DDNS function of this router Provider Select a DDNS service provider Domain name Fill in your static domain name that uses DDNS Account E mail The account that your DDNS service provider assigned to you Password Key The password you set for the DDNS service account above Click Apply at the bottom of the screen to save the above c...

Page 62: ...L PUBLIC LICENSE Version 2 June 1991 Copyright C 1989 1991 Free Software Foundation Inc 59 Temple Place Suite 330 Boston MA 02111 1307 USA Everyone is permitted to copy and distribute verbatim copies of this license document but changing it is not allowed Preamble The licenses for most software are designed to take away your freedom to share and change it By contrast the GNU General Public License...

Page 63: ...s License and to the absence of any warranty and give any other recipients of the Program a copy of this License along with the Program You may charge a fee for the physical act of transferring a copy and you may at your option offer warranty protection in exchange for a fee 2 You may modify your copy or copies of the Program or any portion of it thus forming a work based on the Program and copy a...

Page 64: ... are not required to accept this License since you have not signed it However nothing else grants you permission to modify or distribute the Program or its derivative works These actions are prohibited by law if you do not accept this License Therefore by modifying or distributing the Program or any work based on the Program you indicate your acceptance of this License to do so and all its terms a...

Page 65: ...ich is copyrighted by the Free Software Foundation write to the Free Software Foundation we sometimes make exceptions for this Our decision will be guided by the two goals of preserving the free status of all derivatives of our free software and of promoting the sharing and reuse of software generally NO WARRANTY 11 BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE THERE IS NO WARRANTY FOR THE PROGRA...

Reviews: