background image

 

 

Page 48 

5: Security Management 

Overview 

 

Block URL 

 

Ability to block a specific website by configuring IP address, URL or Keywords. 

 

 

Access Filter 

– Ability to block all Internet access, a known port or user defined ports by group 

access.

 

 

Session Limit 

 

Ability to limit users Internet access when the device detects new sessions that 

exceed the maximum value in the sampling time, for example, virus, syn flood, etc.

 

 

SysFilter Exception 

– This feature allows you to configure an unrecognized port, allowing those 

packets to be processed, enabling some programs to run more smoothly. This is also applicable 
for some future applications that may need this mechanism in order to work well.

 

 

 

Block URL 

This feature allows you to block access to undesirable Web sites. You can block by URL, IP address, 
or Keyword.  You can also have different blocking settings for different groups of PCs.  

  In operation, every URL is searched to see if it matches or contains any of the URLs or keywords 

entered here. Then, after a DNS lookup, it determines the IP address of the requested site and 
checks it against IP address entries on this screen. 

  Note that a single IP address may host many Web sites (shared IP). Entering an IP address on 

this screen will block all Web sites that may be hosted on that IP address. 

 

 

Figure 5-1: Block URL 

 

Summary of Contents for X16-R

Page 1: ...MULTI WAN GATEWAY Model X16 R User s Guide...

Page 2: ...ii...

Page 3: ...oE 24 Advanced PPTP 25 4 ADVANCED SETUP 28 Overview 28 Host IP 28 Routing 30 Virtual Server 34 Special Application 37 Dynamic DNS 39 Multi DMZ 41 UPnP Setup 42 NAT Setup 43 Advanced Feature 45 5 SECUR...

Page 4: ...ICATIONS 69 APPENDIX B WINDOWS TCP IP SETUP 70 Overview 70 TCP IP Settings 70 APPENDIX C TROUBLESHOOTING 77 Overview 77 General Problems 77 Internet Access 78 Copyright 2006 XiNCOM LLC All Rights Rese...

Page 5: ...rnet Features Flexible use of WAN ports There are up to 8 WAN ports available for use on the MULTI WAN GATEWAY The user can decide how many WAN ports to use by changing settings in the web page setup...

Page 6: ...mapping sessions to selected PCs if desired Multiple IP Address Support If your ISP allocates you multiple IP addresses these are also supported and you can map IP addresses to selected PCs if desired...

Page 7: ...nication peers Other Features 16 Port Switching Hub The MULTI WAN GATEWAY incorporates a 16 port 10 100BaseT switching hub making it easy to create or extend your LAN as needed DHCP Server Support Dyn...

Page 8: ...ted when more than two WAN ports are enabled or if there is excessive ping notification Syslog This is a very useful feature for monitoring the device in that it can generate real time system informat...

Page 9: ...ove items are damaged or missing please contact your dealer immediately Physical Details Front Panel Figure 1 2 Front Panel Front Panel LED indication is as follows Power OFF No Power ON Normal Operat...

Page 10: ...another hub Reset Button When pressed and released the MULTI WAN GATEWAY will reboot restart within 1 second It will reset to default when pushed and held for more than 3 seconds Some Status and Error...

Page 11: ...work Mask of 255 255 255 0 DHCP Server is enabled User Name admin Password cleared no password TFTP Download This setting should be used only if your MULTI WAN GATEWAY becomes unusable and you are att...

Page 12: ...grade is finished the MULTI WAN GATEWAY should work normally The factory default settings will be applied Note The supplied Windows TFTP utility also allows you to perform three 3 additional operation...

Page 13: ...Use standard 10 100BaseT network UTP cables with RJ45 connectors TCP IP network protocol must be installed on all PCs Procedure 1 Configuring the MULTI WAN GATEWAY for your LAN 1 Use a standard LAN ca...

Page 14: ...rd You may do this using the Admin Setup screen 8 After logging in you will see the Administrator Password setup in the Admin Setup screen as shown below Assign a password by entering it in the Passwo...

Page 15: ...ou will find this setting in the LAN DHCP screen Your DHCP Server must be configured to provide the MULTI WAN GATEWAY s LAN IP Address as the Default Gateway Your DHCP Server must provide correct DNS...

Page 16: ...ment than the LAN segment It can still access the Internet through NAT DHCP Configuration Lease Time This is a finite period of time for a DHCP server to lease an IP address to a client DNS Server IP...

Page 17: ...Page 13 12 Save your data then go to Step 2 Installing the MULTI WAN GATEWAY in your LAN...

Page 18: ...cables to connect PCs to the LAN ports on the MULTI WAN GATEWAY Both 10BaseT and 100BaseT connections can be used simultaneously If you need to connect the MULTI WAN GATEWAY to another Hub just use a...

Page 19: ...p the WAN port numbers You can choose from two 2 up to eight 8 WAN ports Once you have selected how many ports you are going to use click on Submit You may then proceed to the Primary Setup page Figur...

Page 20: ...ct this if your ISP has provided a Fixed or Static IP address Enter the data into the Address Info fields Dynamic IP Select this if your ISP provides an IP address automatically when you connect You c...

Page 21: ...screen To use multiple PPPoE sessions on either port configure settings in the Advanced PPPoE screen DNS If using a Fixed IP address you MUST enter at least 1 DNS address If using a Dynamic IP PPPoE...

Page 22: ...dresses on your LAN or if you wish to check your TCP IP settings refer to Appendix B Windows TCP IP Setup Internet Access To configure your PCs to use the MULTI WAN GATEWAY for Internet access follow...

Page 23: ...the Network field Leave the Phone Number field blank Click Save then OK Configuration is now complete Before clicking Sign On always ensure that you are using the MULTI WAN GATEWAY location Macintosh...

Page 24: ...server settings are correct To act as a DHCP Client recommended The procedure below may vary depending on your version of Linux and X windows shell 1 Start your X Windows client 2 Select Control Pane...

Page 25: ...ing multiple WAN ports It allows you to determine the proportion of WAN traffic sent through each port Advanced PPPoE setup is required if you wish to use multiple sessions on each WAN port It can als...

Page 26: ...Health Check performs an ICMP echo packet request to the specific destination This could be either a URL or an IP Address specified by users in the Alive Indicator input box or WAN interface gateway...

Page 27: ...a load balancing mechanism for transparent bridge mode Traffic from bridge hosts eg transparent to WAN1 can go through any WAN interface eg WAN1 2 or other based on the loading mechanism specified in...

Page 28: ...The largest upload bandwidth Priority The highest priority Round Robin Continuously repeating sequence Weight Round Robin In sequence with weight placed accordingly Loading Share Enter the percentage...

Page 29: ...ort Session WAN Port Selected WAN port only using PPPoE connection PPPoE Session ISPs can usually provide multiple floating real IPs for PPPoE Each WAN port can have up to eight 8 PPPoE sessions each...

Page 30: ...WAN traffic is detected If not enabled you must establish a connection manually Disconnect after Idle This determines when an idle connection will be terminated Enter the required time period 1 Alway...

Page 31: ...ave a fixed IP address enter if here Otherwise this field should be left at 0 0 0 0 PPTP Auto Dialup Auto Dialup connect on demand If set to Enable a connection will be established whenever outgoing W...

Page 32: ...e Access Filter feature This requires that each PC is identified by using the Host IP screen You wish to have different Block URL settings for different PCs This requires that each PC is identified by...

Page 33: ...e MAC address of this Host Select Group Select the group you wish this Host to be included in Reserve in DHCP Select Enable to reserve a particular LAN IP address for a particular PC on your LAN This...

Page 34: ...he desired Port and Session Otherwise ignore these settings Note Multiple PPPoE sessions are defined on the Advanced PPPoE screen Buttons Add Use this to add a new entry to the database using the data...

Page 35: ...ss C LANs the network address is the first 3 fields of the Destination IP Address The 4th last field can be left at 0 Netmask The Network Mask for the remote LAN segment For class C networks the defau...

Page 36: ...uting Example Router B 192 168 2 90 192 168 3 70 Router A Segment 0 Segment 2 Segment 1 192 168 1 xx 192 168 2 xx 192 168 1 100 192 168 1 1 192 168 3 xx 192 168 2 80 Figure 4 3 Routing Example For the...

Page 37: ...1 100 Interface LAN Metric 3 For Router A s Default Route Destination IP Address 0 0 0 0 Network Mask 0 0 0 0 Gateway IP Address 192 168 1 1 Metric 2 For Router B s Default Route Destination IP Addre...

Page 38: ...r ftp 205 20 45 34 PC using Web Server http 205 20 45 34 Multi WAN Load Balancer Figure 4 4 Virtual Server Note that in this illustration both Internet users are connecting to the same IP Address but...

Page 39: ...nable or Disable each Virtual server as required Server Name Enter a suitable name for this server By default 12 well known virtual servers have been listed on the Custom Virtual Server List Protocol...

Page 40: ...e port is required enter it in both fields Allowed Remote IP It allows only a range of remote side IP addresses to access the virtual servers The default entry 0 0 0 0 0 0 0 0 means all remote side IP...

Page 41: ...to Enable or Disable the Special Application as required Name Enter a descriptive name to identify the Special Application Outgoing Protocol Select the protocol used by the application when sending d...

Page 42: ...modify its configuration data by selecting and clicking on a row Using a Special Application on your PC Once the Special Applications screen is configured correctly you can use the application on your...

Page 43: ...tandard client available at http www dyndns org Other sites may offer the same service but can not be guaranteed to work TZO at http www tzo com 3322 is available in China at http www 3322 org To use...

Page 44: ...lable in China It is similar to DynDNS User Defined DDNS Server This is the user defined DDNS server If the DDNS provider is other than TZO dyndns org or 3322 Additional Settings These options are ava...

Page 45: ...g with a particular LAN host There are a maximum 8 WAN ports which can be available Its connection type may change based on your WAN connection type Static DHCP PPPoE PPTP Name Enter a name to assist...

Page 46: ...PnP Setup UPnP Option If set to Enable UPnP this device will register on the local network You will find that there is an icon showing on the My Network Places in Window XP Each time you add a new ser...

Page 47: ...x If you disable the NAT checkbox it will act as a bridge or Static Router Most features will be unavailable TCP Timeout Enter the desired value to use on each WAN port The default is 300 UDP Timeout...

Page 48: ...ts as an alias of the host with Local LAN IP accessing the Internet via the specified WAN port for the specified protocol packets i e 1 1 NAT NAT Alias List NAT Alias List shows the list of all NAT al...

Page 49: ...received from the WAN port or not Interface Binding Use these settings to ensure that certain traffic is sent by a particular WAN port and thereby a particular ISP account These settings are only usef...

Page 50: ...u are using E mail accounts from different ISPs on each port you can ignore these settings Some ISPs configure their E mail Servers so they will not accept E mail from IP addresses not allocated by th...

Page 51: ...Page 47 Protocol Port Binding List This list shows the details of all protocol and port configuration data which are currently defined You can modify them by clicking on a selected row...

Page 52: ...to run more smoothly This is also applicable for some future applications that may need this mechanism in order to work well Block URL This feature allows you to block access to undesirable Web sites...

Page 53: ...ou keep it on Access Item White List If you are select White List type it will block the entire URL except you keep it on the Access Item Set Type Button Button to submit Black List or White List Acce...

Page 54: ...Page 50 Figure 5 2 Access Filter...

Page 55: ...elected on this screen are blocked You can block known services by using the checkboxes or you may define your own filters ICMP Filters If you enable ICMP Filter that means it will block ICMP request...

Page 56: ...e number of new sessions has been exceeded Default 65535 session sec Maximum of New Sessions for Host The maximum number of new sessions from the host which is acceptable in the sampling time Any new...

Page 57: ...select LAN any WAN port or ALL interfaces from which a packet originates Protocol The packet type selected in the above Interface which will be directly processed by this device Foreign Port Range Ent...

Page 58: ...ing up and enabling QoS Figure 6 1 QoS Setup Settings QoS Setup QoS Feature Enable QoS Checkbox allows users enable QoS mechanism If set to enable QoS QoS will allocate Inbound Outbound bandwidth to p...

Page 59: ...to classify the received packets based on the following types for your memory Local Remote Address Port Specify a packet based on Local Remote address or port Address has two types IP address and MAC...

Page 60: ...configuration and use of each of these features Admin Setup Remote Access Configuration This feature allows you to manage the MULTI WAN GATEWAY via the Internet You can restrict access to a specified...

Page 61: ...t enabled access is only available by a PC on the LAN Access port The port number used when connecting remotely The default port number is 8080 Allowed Remote IP Remote access is only available to the...

Page 62: ...ure 7 2 Email Alert Settings Email Alert Global Setting Notification on Link Down If set to Enable it will send a warning email to alert the administrator when any WAN port is disconnected Excessive P...

Page 63: ...sword A password for the sender Sender Address An email address that sends a warning email to a recipient Recipient Address An email address that a warning email will be sent to Usually this is a syst...

Page 64: ...e The name of this device Physical Location The location of the device Community Community Name This is a password or key used between this device and the management station The administrator manager...

Page 65: ...ows you to select whether to send the system information to another machine or not Up to three machines can be chosen to send the system log to Message Status Messages are only sent and kept when Keep...

Page 66: ...om Emergency to Debug The lower the level the more messages will be generated Emergency is the highest priority level and Debug is the lowest Log Priority for Modules By pressing the Expand button sel...

Page 67: ...wed by the port number e g HTTP 123 123 123 123 8080 This example assumes that the WAN IP Address is 123 123 123 123 and the port number is 8080 If using the Dynamic DNS feature you can connect using...

Page 68: ...m Configuration Save button This will save the system configuration for future use You also can upgrade the firmware by inputting the correct password browsing to the firmware upgrade file and then pr...

Page 69: ...nfigured operation is automatic However there are some situations where additional Internet configuration may be required Refer to Chapter 4 Advanced Setup for further details System Status Use the Sy...

Page 70: ...WAN GATEWAY gateway MAC Address The MAC physical address of the MULTI WAN GATEWAY as seen from the Internet LAN Interface IP Address The LAN IP Address of the MULTI WAN GATEWAY Subnet Mask The Network...

Page 71: ...ore the factory default settings See below for details Restore Factory Defaults When the Restore Factory Defaults button on the Status screen above is clicked the following screen is displayed Figure...

Page 72: ...current traffic loading on each WAN port Current Loading The number of current traffic Sessions Bytes and Packets being processed on each WAN port Current Bandwidth The current Download and Upload sp...

Page 73: ...nal AC 100V 240V 50 60 Hz FCC Statement This device complies with Part 15 of the FCC Rules Operation is subject to the following two conditions 1 This device may not cause harmful interference 2 This...

Page 74: ...boots For all non Server versions of Windows the default TCP IP setting is to act as a DHCP client If you wish to check your TCP IP settings the procedure is described in the following sections If you...

Page 75: ...Specify an IP Address If your PC is already configured check with your network administrator before making the following changes If the DNS Server fields are empty select Use the following DNS server...

Page 76: ...t is empty enter the DNS address provided by your ISP in the field beside the Add button then click Add Figure B 4 DNS Tab Win 95 98 Checking TCP IP Settings Windows 2000 1 Select Control Panel Networ...

Page 77: ...Page 73 Figure B 5 Network Configuration Win 2000 3 Select the TCP IP protocol for your network card 4 Click on the Properties button You should then see a screen like the following...

Page 78: ...ing a fixed IP Address Use the following IP Address If your PC is already configured check with your network administrator before making the following changes Enter the MULTI WAN GATEWAY s IP address...

Page 79: ...on 2 Right click the Local Area Connection and choose Properties You should see a screen like the following Figure B 7 Network Configuration Windows XP 3 Select the TCP IP protocol for your network ca...

Page 80: ...sing a fixed IP Address Use the following IP Address If your PC is already configured check with your network administrator before making the following changes Enter the MULTI WAN GATEWAY s IP address...

Page 81: ...t 1 2 of this device are WAN ports the others are LAN ports Otherwise you have changed Maximum WAN ports Ensure that your PC and the MULTI WAN GATEWAY are on the same network segment If you don t have...

Page 82: ...check its settings If you can t connect to it check the LAN and power connections If the MULTI WAN GATEWAY is configured correctly check your Internet connection DSL Cable modem etc to see if it is wo...

Reviews: