background image

 
 
 VG211R User Manual

 

 

 

4.6.4. Intrusion Detection 

 

When the SPI (Stateful Packet Inspection) firewall feature is enabled, all packets can be 
blocked.  Stateful Packet Inspection (SPI) allows full support of different application types that are using 
dynamic port numbers.  For the applications checked in the list below, the product will support full 
operation as initiated from the local LAN. 
 
The product’s firewall can block common hacker attacks, including IP Spoofing, IP with zero length, IP 
With Option, Too Short ICMP, Too Short TCP, Too Short UDP, Tiny Fragment Attack, NewTear 
Attack, Smurf Attack, Land Attack, Ping of Death, UDP Loop Attack, Tear Drop Attack, Snork Attack, 
Winnuke Attack, Bonk Attack, ASCEND Probe Attack, Boink Attack, SYN Drop Attack, Empty 
Fragment Attack, Oshare Attack, TCP null scan, TCP Xmas scan, RIP defect, ICMP defect, TCP SYN 
flood, UDP flood 

 Fragmentation Flood

 

 

Intrusion Detection Features: 

 

SPI and Anti-DoS Firewall 
Protection 

Activate SPI and Anti-DoS 
protection 

RIP Defect

 

Reject the RIP packets from WAN 

Discard PING from WAN

 

Reject all the PING request to the 
WAN port 

 
 

 

 

When hacker tries to attack, VG211R can send e-mail alert to the specified user.  Enter related e-mail 
information such as e-mail address and SMTP server.  Some e-mail service providers require user to 
enter POP3 information when trying to send e-mail.  In this case, enter the POP3 server, user name and 
password; otherwise, you don’t need to enter POP3 related information. 

 

21 

Summary of Contents for VG211R

Page 1: ...VG211R User s Manual Rev 1 0 2003 5...

Page 2: ...Zone 6 4 1 2 Password Settings 6 4 1 3 Remote Management 6 4 2 VOIP SETTINGS 7 4 2 1 Dial Setting 7 4 2 2 Port Setting 8 4 2 3 Outgoing Mode 9 4 2 4 H 323 Setting 10 4 2 5 PBX ID Prefix Setting for I...

Page 3: ...7 1 CONFIGURATION TOOLS 23 7 2 FIRMWARE UPGRADE 24 7 3 RESET 24 8 STATUS 24 8 1 INTERNET CONNECTION 25 8 2 DEVICE STATUS 25 8 3 SECURITY LOG 25 8 4 DHCP CLIENT LOG 26 8 5 VOIP STATUS 26...

Page 4: ...anced features of this product This Package Contains One VG211R One Power Adapter One User Manual CD One Category 5 Fast Ethernet Cable Confirm That You Meet Installation Requirements Before proceedin...

Page 5: ...ce power on On Off hook Phone set B Phone Orange Flashing Phone port is receiving incoming ring On Off hook Line port C Line Orange Flashing Line port is receiving incoming ring D Relay Orange On Phon...

Page 6: ...Connecting Phone set Connect phone set directly to the VG211R on phone 2 Connecting PSTN Line Connect PSTN line directly to the VG211Ruter on Line 3 Connecting Computers Connect computers directly to...

Page 7: ...Ds flash your VG211R will be reset to factory default 2 2 Default Network setup LAN Setup WAN Setup IP Address 192 168 1 1 Subnet Mask 255 255 255 0 DHCP server Enable DHCP Client enabled DHCP IP rang...

Page 8: ...nternet Explorer or Netscape Navigator and click the stop button 2 In the Address field type http 192 168 1 1 and press ENTER 3 The VG211R login screen will appear Leave the Password field empty and c...

Page 9: ...d of the user The Idle Time Out value is used for VG211R to log out automatically when no access to the web after this timeout value 4 1 3 Remote Management The Remote Management feature can restrict...

Page 10: ...ber is 8080 4 2 VoIP Settings The VG211R provide Dial setting and Port setting for VoIP user 4 2 1 Dial Setting This page sets up the parameters related to the prefix of the phone numbers including In...

Page 11: ...Set and extension number is 1011 1012 But the real extension number will get from Service Center In the port3 and port4 we have Web Page as following The default setting is Relay mode Port3 will relay...

Page 12: ...ynamic IP users like DHCP PPPoE and PPTP users The system administrator must enter gatekeeper IP If the default gatekeeper is not able to normally operate The gateway system will automatically login t...

Page 13: ...ing in this page If you have any interoperability problem you must change some setting in this page We use the MAC address as H 323 ID Sometimes ITSP will ask you to change H 323 ID then you should di...

Page 14: ...this page The port1 and port2 use 319 as their number If port1 is busy system will ring port2 They use same PBX ID number as their number If you set port type to be dedicated line and want to make th...

Page 15: ...er management You can set user id and password here But that is number digit only 4 3 WAN Settings The VG211R supports 4 types of WAN connection Dynamic IP DHCP Client PPPoE Static IP and PPTP 4 3 1 D...

Page 16: ...during inactivity If the connection is inactive for longer than the Maximum Idle Time then it will be dropped You can enable the Auto reconnect option to automatically re establish the connection as s...

Page 17: ...conds to define a maximum period of time for which the Internet connection is maintained during inactivity If the connection is inactive for longer than the Maximum Idle Time then it will be dropped 4...

Page 18: ...the set of private IP addresses to the global IP address when accessing to the Internet This is very useful in the gaming and some particular multimedia applications 4 5 2 Virtual Server VG211R is a N...

Page 19: ...CP 1723 PC Anywhere TCP 5631 PC Anywhere UDP 5632 4 5 3 Special Application Some applications require multiple connections such as Internet gaming video conferencing Internet telephony and others Thes...

Page 20: ...all is enabled extra checking will be performed for each packets passing through the device the performance of the device will be greatly affected To enable the firewall feature select Enable from fir...

Page 21: ...locking function you need configure URL address first in URL Blocking Site page For scheduling function you also need configure schedule rule first in Schedule Rule page As shown above user enter Clie...

Page 22: ...ecify the particular PC go back to the Access Control page and check the box for Http with URL Blocking in the Normal Filtering Table As shown above all URL with sex cannot be accessed The users withi...

Page 23: ...page will show up Then when we go to Access Control page select Add PC in the bottom of the page Access Control Add PC the scheduling rule will show Office Hour as shown below If we setup the PC of fi...

Page 24: ...ack Tear Drop Attack Snork Attack Winnuke Attack Bonk Attack ASCEND Probe Attack Boink Attack SYN Drop Attack Empty Fragment Attack Oshare Attack TCP null scan TCP Xmas scan RIP defect ICMP defect TCP...

Page 25: ...ices required from both the external network and the secure network The services are typically HTTP FTP Web servers for public access an HTTP FTP proxy server an SMTP server and a News proxy server Ma...

Page 26: ...S provider and enables the DDNS service 7 Tools The tools feature provided by VG211R includes configuration tools save restore configuration and restore to factory defaults system log firmware upgrade...

Page 27: ...prompt message 7 3 Reset In the event that the system stops responding correctly or in some way stops functioning you can perform a reset Your settings will not be changed To perform the reset click o...

Page 28: ...to release and update WAN port IP 8 2 Device Status The Device Status page displays the current setting of this device including IP address Subnet mask DHCP server Firewall and UPnP 8 3 Security Log T...

Page 29: ...cords User can press Refresh to update current IP allocation records 8 5 VoIP Status This page displays the gateway status including Port Type Port Status time information of each call and Destination...

Page 30: ...VG211R User Manual User can press Refresh to update current VoIP status 27...

Reviews: