FWX120 Operation Manual
91
4
Enhancing security
Allowing communication from registered
terminals only (DHCP authentication)
The product can be configured so that it allows only permitted clients (registered terminals) to
communicate via the product. As another applicable access management, you can also apply a
policy filter (page 80) to a group of IP addresses for registered terminals. You can then allow
only part of the registered terminals to access specific networks (such as an internal network with
a higher security level).
• By pre-defining MAC addresses in the product, IP addresses that are assigned by DHCP can be
reserved for registered terminals.
• Terminals with fixed IP addresses assigned can also be managed as registered terminals.
UP LINK
1
3
4
2
LAN
Provider
Registered
Registered
Registered
Unregistered
Unregistered
×
Prohibit
×
Prohibit
Fixed IP address
Fixed IP address
Fixed IP address
Fixed IP address
Assigned by DHCP
Assigned by DHCP
Registered
Internet
DOWNLOAD
POWER
STATUS
LAN 1
LAN 2
microSD
USB
LAN2
4
3
2
1
ON
STANDB
Y
CONSO
LE
LAN1
NOTE
T
he DHCP authentication function uses MAC address filtering together, which blocks communication
that is not allowed even if unregistered terminals have fixed IP addresses configured.
Tip
• You can configure two logical networks (primary and secondary networks) in one physical network that
clients connect to. In this situation, use the dhcp scope lease type command to assign IP addresses for
the primary network to registered terminals and ones for the secondary network to unregistered terminals.
By doing so, you can separate the registered and unregistered terminals.
• With this function, each client can be configured to have different access rights. For example, registered
terminals can be configured to allow access to all networks in and outside of the company, whereas
unregistered terminals can be configured to allow access to only specific segments in the company network.
• Refer to “Command reference” (included in the attached CD-ROM) for more details on the dhcp scope
lease type command.