background image

D-Link Co.,_______________________________________________________________________ FAQ

FAQ: 4

b. Allow ICMP (including PING)

                Menu 21.1.2 - TCP/IP Filter Rule

                Filter #: 1,2
                Filter Type= TCP/IP Filter Rule
                Active= Yes
                IP Protocol= 1     IP Source Route= No
                ^^^^^^^^^^^^^^^

Destination:

IP Addr= 0.0.0.0
IP Mask= 0.0.0.0
Port #= 0
Port # Comp= None

      Source:

IP Addr= 0.0.0.0
IP Mask= 0.0.0.0
Port #= 0
Port # Comp= None

                 TCP Estab= N/A
                 More= No           Log= None
                 Action Matched= Forward
                                 ^^^^^^^^
                 Action Not Matched= Check Next Rule

c. Allow UDP traffic to ports > 1023

                Menu 21.1.3 - TCP/IP Filter Rule

                Filter #: 1,3
                Filter Type= TCP/IP Filter Rule
                Active= Yes
                IP Protocol= 17    IP Source Route= No
                ^^^^^^^^^^^^^^^

Destination:

IP Addr= 0.0.0.0
IP Mask= 0.0.0.0
Port #= 1023
          ^^^^
Port # Comp= Greater
                ^^^^^^^

      Source:

IP Addr= 0.0.0.0
IP Mask= 0.0.0.0
Port #= 0
Port # Comp= None

                 TCP Estab= N/A
                 More= No           Log= None
                 Action Matched= Forward
                                 ^^^^^^^
                 Action Not Matched= Check Next Rule

d. Allow TCP for ports > 1023, and drop all other packets.

                Menu 21.1.4 - TCP/IP Filter Rule

                Filter #: 1,4
                Filter Type= TCP/IP Filter Rule

Содержание DI-106 Series

Страница 1: ...s European switches DSS1 also used in other countries 1TR6 North American switches AT T NI1 Point to Point Point to Multipoint Northern Telecom DMS100 NI1 Custom The Router supports the PPP protocol i...

Страница 2: ...6 at Pacific Bell Furthermore the Router has been tested extensively with Cisco routers and Ascend routers both Max and Pipeline 6 How to do factory reset for the router There is a file called default...

Страница 3: ...er has easily customizable filter sets that you can use to set it up as an Internet Firewall To do this set the filters to do the following Allow ARP ICMP PING packets Allow TCP UDP traffic to ports 1...

Страница 4: ...More No Log None Action Matched Forward Action Not Matched Check Next Rule c Allow UDP traffic to ports 1023 Menu 21 1 3 TCP IP Filter Rule Filter 1 3 Filter Type TCP IP Filter Rule Active Yes IP Pro...

Страница 5: ...P Pr 0 SA 192 168 1 0 DA 0 0 0 0 N F N 2 Y IP Pr 1 SA 0 0 0 0 DA 0 0 0 0 N F N 3 Y IP Pr 17 SA 0 0 0 0 DA 0 0 0 0 DP 1023 N F N 4 Y IP Pr 6 SA 0 0 0 0 DA 0 0 0 0 DP 1023 N F D 5 N 6 N f Plug it to Men...

Страница 6: ...nal a menu driven user interface To configure the Router for use as a Remote Access Server follow these steps 4 a Windows 95 Remote User Configure all the necessary parameters in Menu 13 for the Windo...

Страница 7: ...and is indicated in the above diagram by B Note that the IP addresses on My net are hidden from the ISP and the rest of the Internet In Menu 1 Set Route IP to Yes In Menu 3 2 Set IP Address to an add...

Страница 8: ...IP to Yes In Menu 3 2 Set IP Address to an address on My net A In Menu 11 1 Set Route to IP Set Rem IP Addr to the IP address of the remote ISDN router B Select Yes to editing the IP options In Menu...

Страница 9: ...r of the remote network B The remote ISDN router Cisco Ascend etc will have to complete similar configuration changes in order to talk to the Router 2 Router on the NetWare client side My net Rem net...

Страница 10: ...r to negotiate IPX routing In this configuration the stations on the LAN My net will have access to the IPX NetWare server on their own network If the client stations on My net want to access the remo...

Страница 11: ...Router O O NetWare NetWare Server Client The Router can accept calls from a remote router to Bridge IPX packets In this configuration the stations on the remote network Rem net will have access to the...

Страница 12: ...changes in order to talk to the Router 5 f Windows 95 NT Dialing in for TCP IP My net O Router ISDN TA O O A A C Win 95 NT The Router can accept calls from a remote station equipped with remote access...

Страница 13: ...ources available on My net There are two ways to set the external network number for the remote station It can be set provided by the Router from a pool or it can be generated randomly In Menu 1 Set R...

Страница 14: ...t PAP Password to the appropriate login password If the Cisco router requests CHAP Note The Cisco device must be configured as a remote node and not a remote user In Menu 11 1 only if Call Direction i...

Страница 15: ...ISDN TA the Router is able to assign the IP address because it is the workstation that is doing the actual PPP IPCP negotiation 9 How can I prevent incoming telnet sessions to my Router The Router has...

Страница 16: ...o 0 0 0 0 filter ALL packets Also set the Idle Timeout of that remote node to zero To trigger the call in this scenario use the option in menu 24 4 5 manual call This way the call will never time out...

Страница 17: ...for the ISP remote node in the Call filter sets Menu 21 1 Filter Rules Summary A Type Filter Rules M m n 1 Y IP Pr 17 SA 0 0 0 0 SP 138 DA 0 0 0 0 N D N 2 Y IP Pr 17 SA 0 0 0 0 SP 137 DA 0 0 0 0 N D F...

Страница 18: ...e IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port 138 Port Comp Equal TCP Estab N A More No Log None Action Matched Drop Action Not Matched Check Next Rule Menu 21 1 2 TCP IP Filter Rule Filter 1 4 Filter Type T...

Страница 19: ...fset 12 Length 2 Mask ffff Value protocol ID More No Action Matched Drop Action Not Matched Forward If your filtering scheme requires you to block more specific packets you can determine the type of p...

Страница 20: ...eld blank or filled with 0 0 0 0 6 Why do I see garbage characters being printed out on my console This condition is due to data overflowing the UART You may not have a 16650 UART chip on your serial...

Страница 21: ...for the IP pool However you still need to have RIP turned on 10 How do I trace if my Router is doing callback on CLID 1 Set Menu 13 CLID authentication to Required 2 Go to Menu24 8 CI and type sys ev...

Страница 22: ...e Internet at the same time The legal gateway IP address can be statically assigned or the Router can dynamically ask the ISP for it The number of simultaneous users is limited by the fixed size trans...

Страница 23: ...oming Call 40001 timestamp line 1 channel 1 call 41 C01 ANSWER Connected 64K 40001 timestamp line 1 channel 1 call 41 C01 Incoming Call Call Terminated 6 How do I setup syslogd in UNIX to use Router b...

Страница 24: ...menu 2 and try again If X is any other code then check the ISDN switch type you have configured in menu 2 as well as the country code in menu 24 1 If these are correct then you need to turn on the pr...

Страница 25: ...ave been incremented by 3 If not then use ip route errcnt disp to determine the cause If it has been incremented then try lan cnt disp to check if there is a hardware problem Finally check for any fil...

Страница 26: ...ort SNMP The Router implements an SNMP agent which provides networking information to the SNMP manager applications running on other computers In addition to supporting the objects defined in the stan...

Страница 27: ...will do a callback without answering the incoming call To Win95 this is a call failure and Win95 will not reach to a state to wait for callback 16 Can I use the Router CLID callback feature to call b...

Страница 28: ...maintain that level of usage for the specified persist time before the second line is brought up or dropped 20 How do I setup Compression to work with Ascend Ascend supports 2 styles of Stac compressi...

Страница 29: ...o this question depends on the situation and the type of network in question Generally routing provides better security better prevention of unneeded traffic and more flexibility However bridging prov...

Отзывы: