![D-Link DFL-500 Скачать руководство пользователя страница 11](http://html.mh-extra.com/html/d-link/dfl-500/dfl-500_user-manual_75108011.webp)
addresses on the protected internal networks. Route mode policies route allowed connections between
firewall interfaces without performing network address translation.
Transparent mode
Transparent Mode is used to provide firewall protection to a pre-existing network with public addresses. The
internal and external network interfaces of the DFL-500 can be in the same network; therefore, the DFL-500
can be inserted into your network at any point without the need to make any changes to your network.
The following features are not supported in Transparent mode:
·
VPN
·
IP/MAC binding
·
Port forwarding
·
DHCP and PPPoE configuration of the external network address
Hacker prevention and network protection
The DFL-500 Network Intrusion Detection System (NIDS) is a real-time network intrusion detection sensor
that identifies and takes action against a wide variety of suspicious network activity. The NIDS uses intrusion
signatures, stored in the attack database, to identify the most common attacks. In response to an attack, the
NIDS protects the DFL-500 and the networks connected to it by:
·
Dropping the connection
·
Blocking packets from the location of the attack
·
Blocking network ports, protocols, or services being used by an attack
To notify system administrators of the attack, the NIDS records the attack and any suspicious traffic to the
attack log.
The attack database functions in a similar manner to an antivirus database. D-Link updates the attack
database periodically. You can download and install attack database updates manually. You can also
configure the DFL-500 to automatically check for and download IDS database updates.
VPN
Using DFL-500 virtual private networking (VPN), you can provide a secure connection between widely
separated office networks or securely link telecommuters or travellers to an office network.
The DFL-500 VPN features include:
·
Industry standard IPSec VPN including:
·
IPSec, ESP security in tunnel mode
·
DES and 3DES (triple-DES) hardware accelerated encryption
·
HMAC MD5 and HMAC SHA1 authentication and data integrity
·
AutoKey IKE and manual key exchange
·
PPTP for easy connectivity with the VPN standard supported by the most popular operating systems
·
L2TP for easy connectivity with a more secure VPN standard also supported by many popular operating
systems
·
IPSec and PPTP VPN pass through so that computers or subnets on your internal network can connect
to a VPN gateway on the Internet
DFL-500 User Manual
11
Содержание DFL-500
Страница 1: ...DFL 500 V2 27 User Manual D Link Systems Inc DFL 500 User Manual 1 ...
Страница 102: ...DFL 500 User Manual 102 ...
Страница 136: ...DFL 500 User Manual 136 ...
Страница 140: ...Registration Register the D Link DFL 500 Office Firewall online at http www dlink com sales reg DFL 500 User Manual 140 ...