background image

 

72

Appendix A: Firewall 

 

Stateful Packet Inspection 

Refers to an architecture, where the firewall keeps track of packets on each 
connection traversing all its interfaces and makes sure they are valid. This is in 
contrast to static packet filtering which only examines a packet based on the 
information in the packet header. 
 
 

 

Denial of Service attack 

Is an incident in which a user or organization is deprived of the services of a 
resource they would normally expect to have. Various DoS attacks the device can 
withstand are: ARP Attack, Ping Attack, Ping of Death, Land, SYN Attack, Smurf 
Attack and Tear Drop. 
 
 

 

TCP/IP/Port/Interface filtering rules 

These rules help in the filtering of traffic at the Network layer i.e. Layer 3. 
When a Routing interface is created "Enable Firewall" must be checked. 
Navigate to Advanced Setup -> Security -> IP Filtering, web page. 
 
 

 

Outgoing IP Filtering:

 Helps in setting rules to DROP packets from the LAN  

interface. By default if Firewall is Enabled all IP traffic from LAN is allowed. By 
setting up one or more filters, particular packet types coming from the LAN can 
be dropped. 
 
   

Filter Name:

 User defined Filter Name. 

 
   

Protocol:

 Can take on any values from: TCP/UDP, TCP, UDP or ICMP 

 

 

Source IP Address/Source Subnet Mask:

 Packets with the particular  "Source 

IP Address/Source Subnet Mask" combination will be dropped. 
 
 

 

Source Port:

 This can take on either a single port number or a range of port 

numbers. Packets having a source port equal to this value or falling within the 
range of port numbers(portX : portY) will be dropped. 
 

 

 

Destination IP Address/Destination Subnet Mask:

 Packets with the 

particular "Destination IP Address/Destination Subnet Mask" combination will be 
dropped. 
 

 
Destination Port:

 This can take on either a single port number or a range 

of port numbers. Packets having a destination port equal to this value or falling 
within the range of port numbers(portX : portY) will be dropped. 
 

 

Содержание ct-5611

Страница 1: ...ADSL2 Combo Router User Manual Version A2 0 August 12 2008 261070 012...

Страница 2: ...ms should be placed on the cord In addition do not walk on step on or mistreat the cord z Use only the power cord and adapter that are shipped with this device z To safeguard the equipment against ove...

Страница 3: ...estic waste The cardboard box the plastic contained in the packaging and the parts that make up this router can be recycled in accordance with regionally established regulations Never dispose of this...

Страница 4: ...2 STATISTICS 22 4 2 1 LAN Statistics 22 4 2 2 WAN Statistics 23 4 2 3 ATM statistics 24 4 2 4 ADSL Statistics 26 4 3 ROUTE 28 4 4 ARP 28 4 5 DHCP 29 4 6 BRIDGING 30 4 7 IGMP PROXY 30 CHAPTER 5 QUICK S...

Страница 5: ...NAGEMENT 63 8 1 SETTINGS 63 8 1 1 Configuration Backup 64 8 1 2 Update Settings 64 8 1 3 Restore Default 65 8 2 SYSTEM LOG 66 8 3 INTERNET TIME 68 8 4 ACCESS CONTROL 68 8 4 1 Services 69 8 4 2 Access...

Страница 6: ...o has full routing capabilities to segment route IP protocol and supports advanced security functions 1 1 Features IP filtering SPI Stateful Packet Inspection DoS protection Static route Dynamic IP as...

Страница 7: ...6 1 2 Application The following diagram depicts the application of the Router...

Страница 8: ...ink The ADSL link is training or some traffic is passing through ADSL On A USB link is established Off A USB link is not established USB Green Green Blink Data transmitting or receiving over USB On Th...

Страница 9: ...turn the power switch to the on position After powering on the router performs a self test Wait for a few seconds until the test is finished then the router will be ready to operate Reset Button Resto...

Страница 10: ...dows XP 64 bit the driver needs to be installed manually please see section 2 3 below for details and the driver is also enclosed on the CD ROM To connect the router to a PC using the USB interface yo...

Страница 11: ...10 STEP 3 When the screen displays as below wait until the drivers are fully installed STEP 4 Click the Finish button when the screen displays as below...

Страница 12: ...11 STEP 5 Installation is complete...

Страница 13: ...g the USB interface you need to use a standard USB cable and install the USB interface software Follow the steps below STEP 1 Connect the USB router to the PC by plugging the flat connector of a stand...

Страница 14: ...ayed if the USB Driver has been previously un installed STEP 3 If you are installing the software from a disk insert the disk Note When the auto run screen pops up click Exit and continue with the man...

Страница 15: ...location of the file using the Browse button Normally the file is on the CD ROM shipped with the device STEP 5 Locate the Vista folder and click the OK button STEP 6 When the screen displays as below...

Страница 16: ...15...

Страница 17: ...16 STEP 7 Click the Finish button when the screen displays as below STEP 8 Installation is complete...

Страница 18: ...tic IP address within the 192 168 1 x subnet Follow the steps below to configure your PC IP address to use subnet 192 168 1 x STEP 1 Right click on the Local Area Connection under the Network and Dial...

Страница 19: ...rompted to enter your user name and password Type root in the user name field and 12345 in the password field and click OK These values can be changed later in the Web User Interface by selecting the...

Страница 20: ...ther by pushing the reset button for more than five seconds or by clicking the Restore Default Configuration option in the Restore Settings screen The following default settings are present when setti...

Страница 21: ...own Note For the Quick Setup option to be displayed on the menu the WAN needs to be removed All PVCs Then click Save Reboot then Quick Setup option will be displayed shown here Note The selections ava...

Страница 22: ...vice Shows the name for WAN connection Interface Shows connection interfaces Protocol Shows the connection type such as PPPoE PPPoA etc IGMP Shows the statue of the IGMP function Firewall Shows if the...

Страница 23: ...cs screens are updated every 15 seconds 4 2 1 LAN Statistics The Network Statistics screen shows interface statistics for Ethernet and USB interfaces The Network Statistics screen shows interface stat...

Страница 24: ...of the ATM VPI VCI Protocol Shows the connection type such as PPPoE PPPoA etc Interface Shows connection interfaces Received Transmitted Bytes Pkts Errs Drops Rx TX receive transmit packet in Byte Rx...

Страница 25: ...s If cells with undefined PTI values are discarded they are also counted here In Hec Errors Number of cells received with an ATM Cell Header HEX error In Invalid Vpi Vci Errors Number of cells receive...

Страница 26: ...Discards Number of received AAL5 AAL0 CPCS PDUs discarded due to an input buffer overflow condition Out Discards This field is not currently used ATM AAL5 LAYER STATISTICS FOR EACH VCC OVER ADSL INTER...

Страница 27: ...Statistics The following figure shows the ADSL Network Statistics screen Within the ADSL Statistics window a bit Error Rate Test can be started using the ADSL BER Test button The Reset button resets t...

Страница 28: ...ld obtain Rate Kbps Current sync rate Super Frames Total number of super frames Super Frame Errors Number of super frames received with errors RS Words Total number of Reed Solomon code errors RS Corr...

Страница 29: ...28 4 3 Route Choose Route to display the routes that the route information has learned 4 4 ARP Click ARP to display the ARP information...

Страница 30: ...29 4 5 DHCP Click DHCP to display the DHCP information...

Страница 31: ...30 4 6 Bridging Click Bridging to display the Bridging information 4 7 IGMP Proxy Click IGMP Proxy to display the list of IGMP Proxy entries...

Страница 32: ...run the PPPoE client The Router can support both cases simultaneously If some or none of the LAN side devices do not run PPPoE client then select PPPoE If every LAN side device is running a PPPoE cli...

Страница 33: ...r the Quick Setup option to be displayed on the menu the WAN needs to be removed Then click Save Reboot shown here 1 Select Quick Setup to display the DSL Quick Setup screen 2 Click Next to start the...

Страница 34: ...e manual configuration of the connection type STEP 2 Enter the Virtual Path Identifier VPI and Virtual Channel Identifier VCI Select Enable Quality Of Service if required Click Next STEP 3 Then choose...

Страница 35: ...z MER LLC SNAP BRIDGING VC MUX z IPoA LLC SNAP ROUTING VC MUX z Bridging LLC SNAP BRIDGING VC MUX STEP 4 Click Next to display the following screen Choosing different connection types pops up differe...

Страница 36: ...a maximum of 32 characters in PPP password Authentication Method Choose from AUTO PAP CHAP and MSCHAP Disconnect if no activity The CT 5611 can be configured to disconnect if there is no activity for...

Страница 37: ...ed on the LAN side i e the LAN side is using a public IP this checkbox should be de selected When the system comes back after reboot the NAT submenu will not be displayed on the left main panel Enable...

Страница 38: ...ss and DHCP leased time Note If the NAT function is enabled this DHCP Server Relay won t be displayed as an option The Device Setup page allows the user to configure the LAN interface IP address and D...

Страница 39: ...to modify the settings 5 After clicking Save Reboot the router will save the configuration to the flash memory and reboot The Web UI will not respond until the system is brought up again After the sy...

Страница 40: ...e WAN IP settings Notice DHCP Client can be enabled for PVC in MER mode if Obtain an IP address automatically is chosen Changing the default gateway or the DNS effects the whole system Configuring the...

Страница 41: ...u on the left side main panel will be displayed after system reboot The user can then configure firewall features after the system comes up If firewall is not used this checkbox should be de selected...

Страница 42: ...Note that the router s default IP address is 192 168 1 1 and the default private address range provided by the ISP server in the router is 192 168 1 2 through 192 168 1 254 Note Ethernet and USB inte...

Страница 43: ...e flash memory and reboot The Web UI will not respond until the system is brought up again After the system is up the Web UI will refresh to the Device Info page automatically The Router is ready for...

Страница 44: ...lues provided by the ISP and click Next 4 Select the IP over ATM IPoA radio button and click Next The following screen appears Notice that DHCP is not supported over IPoA The user must enter the IP ad...

Страница 45: ...will be displayed after system reboot The user can then configure firewall features after the system comes up If firewall is not used this checkbox should be de selected to free up system resources f...

Страница 46: ...range provided by ISP server in the router is 192 168 1 2 through 192 168 1 254 7 The WAN Setup Summary screen presents the entire configuration summary Click Save Reboot if the settings are correct C...

Страница 47: ...use the bridge service tick the checkbox Enable Bridge Service and enter the service name 5 Click the Next button to continue Enter the IP address for the LAN interface The default IP address is 192...

Страница 48: ...47 The WAN Setup Summary screen presents the entire configuration summary Click Save Reboot if the settings are correct Click Back if you wish to modify the settings...

Страница 49: ...WAN connection Interface Name of the interface for WAN Protocol Shows bridge or router mode IGMP Shows enable or disable IGMP proxy Firewall Shows if the Firewall enabled or disabled Nat Shows if the...

Страница 50: ...ion data and reboots the router to make the new configuration effective IP Address Enter the IP address for the LAN port Subnet Mask Enter the subnet mask for the LAN port To configure a secondary IP...

Страница 51: ...n the LAN side The Internal port is required only if the external port needs to be converted to a different port number used by the server on the LAN side A maximum 32 entries can be configured To add...

Страница 52: ...d Internal Port End Enter the internal port ending number when you select Custom Server When a service is selected the port ranges are automatically configured 6 3 2 Port Triggering Some applications...

Страница 53: ...number when you select custom application When an application is selected the port ranges are automatically configured Trigger Protocol User can select from TCP TCP UDP or UDP Open Port Start Enter t...

Страница 54: ...the WAN that do not belong to any of the applications configured in the Virtual Servers table to the DMZ host computer Enter the computer s IP address and click Apply to activate the DMZ host Clear th...

Страница 55: ...me and at least one condition below All of the specified conditions in this filter rule must be satisfied for the rule to take effect Click Save Apply to save and activate the filter OUTGOING Note The...

Страница 56: ...r destination IP address Destination Subnet Mask Enter destination subnet mask Destination port port or port port Enter destination port number INCOMING Note The default setting for all Incoming traff...

Страница 57: ...Internet use To add a parental control simply click the Add button The following screen will be displayed Username To set access Internet user name MAC To set what MAC to access Internet Mon Tue Wed T...

Страница 58: ...r will accept the first received default gateway assignment from one of the PPPoA PPPoE or MER DHCP enabled PVC s If the checkbox is not selected enter the static default gateway AND OR a WAN interfac...

Страница 59: ...tatic routes Choose Add or Remove to configure the static routes To add static route click the Add button to display the following screen Enter the destination network address subnet mask gateway AND...

Страница 60: ...ved DNS assignment from one of the PPPoA PPPoE or MER DHCP enabled PVC s during the connection establishment If the checkbox is not selected enter the primary and optional secondary DNS server IP addr...

Страница 61: ...ious locations on the Internet To add a dynamic DNS service simply click the Add button The following screen will be displayed D DNS provider Select a dynamic DNS provider from the list Hostname Enter...

Страница 62: ...e G Lite mode T1 413 Sets the T1 413 if you want the system to use only T1 413 mode ADSL2 Enabled The device can support the functions of the ADSL2 AnnexL Enabled The device can support enhance the lo...

Страница 63: ...esent and that this test is successful Fail Indicates that the DSL Router does not detect the Ethernet interface on your computer USB connection Pass Indicates that the USB interface from your compute...

Страница 64: ...the following maintenance functions and processes z Settings z System log z Internet Time z Access Control z Update software z Save Reboot 8 1 Settings The Settings option allows you to back up your...

Страница 65: ...k BACKUP Settings in the main window You will be prompted to define the location of the backup file to save After choosing the file location click Backup Settings Te file will then be saved to the ass...

Страница 66: ...ngs requires a system reboot This necessitates that the current Web UI session be closed and restarted Before restarting the connected PC must be configured with a static IP address in the 192 168 1 x...

Страница 67: ...n 2 Select from the desired Log options described in the following table and then click Save Apply Option Description Log Indicates whether the system is currently recording events The user can enable...

Страница 68: ...nstance if the log level is set to Debugging all the events from the lowest Debugging level to the most critical level Emergency level will be recorded If the log level is set to Error only Error and...

Страница 69: ...nding box displayed on the screen Then click Save Apply 8 4 Access Control The Access Control option under Management menu bar configures the access related parameters including three parts Services I...

Страница 70: ...g the item in the corresponding checkbox and then click Save Apply 8 4 2 Access IP Addresses The IP Addresses option limits the access by IP address If the Access Control Mode is enabled only the allo...

Страница 71: ...nrestricted access to change and view configuration of your DSL Router z support is used to allow an ISP technician to access your DSL Router for maintenance and to run diagnostics z user can access t...

Страница 72: ...location in the box below or click the Browse button to locate the image file Step 3 Click the Update Software button once to upload the new image file NOTE The update process takes about 2 minutes t...

Страница 73: ...tgoing IP Filtering Helps in setting rules to DROP packets from the LAN interface By default if Firewall is Enabled all IP traffic from LAN is allowed By setting up one or more filters particular pack...

Страница 74: ...s to ACCEPT packets from the WAN interface By default all incoming IP traffic from WAN is Blocked if the Firewall is Enabled By setting up one or more filters particular packet types coming from the W...

Страница 75: ...IP Address Sub Mask 210 168 219 45 16 and a source port in the range of 5060 to 6060 destined to 192 168 1 45 24 and a destination port in the range of 6060 to 7070 All other incoming packets on this...

Страница 76: ...side with a Dest MAC Addr of 00 12 34 56 78 irrespective of its Source MAC Addr on the br_0_34 WAN interface All other frames on this interface are forwarded 2 Global Policy Blocked Protocol Type PPPo...

Страница 77: ...into effect End Blocking Time The time when restrictions on the LAN device are lifted Example User Name FilterJohn Browser s MAC Address 00 25 46 78 63 21 Days of the Week Mon Wed Fri Start Blocking...

Страница 78: ...n Assignments Line port RJ11 Pin Definition Pin Definition 1 4 ADSL_TIP 2 5 3 ADSL_RING 6 LAN Port RJ45 Pin Definition Pin Definition 1 Transmit data 5 NC 2 Transmit data 6 Receive data 3 Receive data...

Страница 79: ...C 2516 PPPoE RFC 1577 IPoA Support PVCs 4 AAL type AAL5 ATM service class UBR CBR VBR ATM UNI support UNI3 1 4 0 OAM F4 F5 Yes Management SNMP Telnet Web based management Configuration backup and rest...

Страница 80: ...r 110 Vac or 220 Vac Environment Condition Operating temperature 0 50 degrees Celsius Relative humidity 5 90 non condensing Dimensions 92 mm W x 32 mm H x 114mm D Certifications CE Note Specifications...

Отзывы: