background image

                                                   DG-BG4300N User Manual 

 

 

 

8. Firewall Setup 

Firewall contains several features that are used to deny or allow traffic from passing through the device. 

8.1 MAC Filtering 

 

The MAC filtering feature allows you to define rules to allow or deny frames through the device based on 

source MAC address, destination MAC address, and traffic direction.  

 

 

Fields on the first setting block: 

Field 

Description 

Outgoing Default Action 

Specify the default action on the LAN to WAN bridging/forwarding path. 

Incoming Default Action 

Specify the default action on the WAN to LAN bridging/forwarding path. 

 

Fields on the second setting block: 

Field 

Description 

Rule Action 

Deny or allow traffic when matching this rule. 

Direction 

Traffic bridging/forwarding direction. 

Source MAC Address 

The source MAC address. It must be xxxxxxxxxxxx format. Blanks can 
be used in the MAC address space and are considered as don’t care. 

Destination MAC Address 

The destination MAC address. It must be xxxxxxxxxxxx format. Blanks 
can be used in the MAC address space and are considered as don’t 

Содержание DG-BG4300N

Страница 1: ...DG BG4300N 300Mbps Wireless ADSL2 2 Broadband Router User Manual V1 0 2011 12 01 As our product undergoes continuous development the specifications are subject to change without prior notice...

Страница 2: ...y warranties merchantability or fitness for any particular purpose Any software described in this manual is sold or licensed as is Should the programs prove defective following their purchase the buye...

Страница 3: ...2 2 1 DHCP Server Configuration 33 5 2 2 2 DHCP Relay Configuration 34 5 2 3 DHCP Static Configuration 35 5 2 4 LAN IPV6 Configuration 36 5 3 Wireless Configuration 40 5 3 1 Basic Setting 40 5 3 2 Wi...

Страница 4: ...Configuration 78 7 4 DNS Setup 79 7 4 1 DNS Configuration 79 7 4 2 IPv6 DNS 80 7 5 Dynamic DNS 81 7 5 1 Dynamic DNS DDNS Configuration 81 8 Firewall Setup 83 8 1 MAC Filtering 83 8 2 IP Port Filtering...

Страница 5: ...iagnostic Setup 98 9 6 1 Ping Diagnostic 98 9 6 2 Ping6 Diagnostic 98 9 6 3 Traceroute Diagnostic 99 9 6 4 OAM Fault Management Connectivity Verification 99 9 6 5 ADSL Diagnostic 100 9 6 6 Diagnostic...

Страница 6: ...802 11n specifications WEP WPA and WPA2 security specifications You can configure the router by running the Setup Wizard in the CD ROM provided in the package The wizard provides quick setup for Inter...

Страница 7: ...ntenna and power supply are dangerous to small children KEEP THIS ROUTER OUT OF THE REACH OF CHILDREN 6 The Router will get heated up when used for long time This is normal and is not a malfunction DO...

Страница 8: ...4 7 or above Opera web browser or Safari web browser An available AC power socket 100 240V 50 60Hz 1 5 Package Contents Before you start using this router please check if there s anything missing in t...

Страница 9: ...negotiation is not enabled on the device WLAN Green ON WLAN connection is normal Blinking Data is being transmitted or received OFF Wireless is not enabled LAN 1 4 Green ON LAN connection is normal B...

Страница 10: ...vate the wireless functions WPS Press this button for less then 5 seconds to start WPS function Reset Press this button and hold for 10 seconds to restore all settings to factory defaults LAN 1 4 Loca...

Страница 11: ...he device and the Modem interface of the splitter with a telephone cable Connect the phone set to the Phone interface of the splitter through a telephone cable Connect the input cable to the Line inte...

Страница 12: ...the router Step 4 Please check all LEDs on the front panel Power LED should be steadily ON ADSL and LAN should be ON Check if the computer network device connected to the respective port of the route...

Страница 13: ...DG BG4300N User Manual 3 Software Installation Step 1 Insert the Setup CD into your CD ROM drive of notebook desktop computer Step 2 You will see the Autorun utilit Click Start to continue...

Страница 14: ...ep 3 Connect one end of the telephone cable RJ 11 into the ADSL port provided on the splitter from the service provider and connect other telephone cable from the splitter to the LINE port on the rout...

Страница 15: ...t all the LED s on the router are ON If not try the above steps again else click Next to continue Step 5 Connect one end of the network cable to one of the LAN ports 1 4 of the router and the other en...

Страница 16: ...ns are proper click Next to continue with the installation Step 8 Here you can configure the ADSL router Select the Country India and then select the service provider from the drop down list You can c...

Страница 17: ...is in the range of 32 to 65535 0 to 31 is reserved for local management of ATM traffic Note If ISP you are looking for is not listed in the dropdown list then you can add the parameters manually sele...

Страница 18: ...dial up access 1483 MER If you select 1483 MER as the WAN protocol the router obtains an IP address automatically 1483 Routed If you select 1483 Routed as the WAN protocol you can not use the DHCP se...

Страница 19: ...DG BG4300N User Manual Following page appears showing the WAN status...

Страница 20: ...than 0 0 0 0 then click Finish to complete the configuration Click Next to continue with the installation Step 11 In this page you can set the SSID for wireless network Step 12 Click Next and the fol...

Страница 21: ...more information about wireless security refer to the user manual Step 13 Click Next and the following page appears In this page you can view the configuration summary Step 14 Click Finish to save yo...

Страница 22: ...idge test by default The default configurations for the system are listed below LAN IP address 192 168 1 1 Netmask 255 255 255 0 Default VPI VCI for ATM maximum 8 sets 0 32 1 32 0 35 ADSL Line mode Au...

Страница 23: ...b Console Start your web browser Type the Ethernet IP address of the modem router on the address bar of the browser Default IP address is 192 168 1 1 Enter Password in the dialog box when it appears D...

Страница 24: ...information is read only except for the PPPoE PPPoA channel for which user can connect disconnect the channel on demand Click the Refresh button to update the status Function buttons in this page Con...

Страница 25: ...DG BG4300N User Manual To view the ADSL Configuration Status please click on ADSL To view the ADSL Statistics please click on Statistics...

Страница 26: ...DG BG4300N User Manual...

Страница 27: ...modem router supports 8 ATM Permanent Virtual Channels PVCs There are mainly three operations for each of the PVC channels add delete and modify And there are several channel modes to be selected for...

Страница 28: ...umn of the Current ATM VC Table before we can modify the PVC channel After selecting PVC channel we can modify the channel configuration at this page Click Modify to complete the channel modification...

Страница 29: ...ield Description VPI Virtual Path Identifier This is read only field and is selected on the Select column in the Current ATM VC Table VCI Virtual Channel Identifier This is read only field and is sele...

Страница 30: ...it Rate When rt VBR is selected the SCR and MBS fields are enabled PCR Peak Cell Rate measured in cells sec is the cell rate which the source may never exceed SCR Sustained Cell Rate measured in cells...

Страница 31: ...G dmt G 992 1 Annex A T1 413 T1 413 issue 2 ADSL2 G 992 3 Annex A ADSL2 G 992 5 Annex A AnnexL Option Enable Disable ADSL2 ADSL2 Annex L capability AnnexM Option Enable Disable ADSL2 ADSL2 Annex M ca...

Страница 32: ...ace in this page Fields in this page Field Description IP Address The IP address your LAN hosts use to identify the device s LAN port Subnet Mask LAN subnet mask IGMP Snooping Enable disable the IGMP...

Страница 33: ...ons for implementing it on your network by selecting the role of DHCP protocol that this device wants to play There are two different DHCP roles that this device can act as DHCP Server and DHCP Relay...

Страница 34: ...igned addresses from this pool Subnet mask A mask used to determine what subnet an IP address belongs to Default gateway On a typical small home or office LAN the existing routes that set up the defau...

Страница 35: ...ys assign the same IP address to a unique MAC address assigned to NIC Static IP is a manual way of obtaining an IP address for your computer where the IP address is pre determined and always the same...

Страница 36: ...DG BG4300N User Manual 5 2 4 LAN IPV6 Configuration IPv6 configuration is mostly the same as IPv4 configuration IPv4 uses only 32 bits for IP address space IPv6 allows 128 bits for IP address space...

Страница 37: ...er Advertisement message When set it indicates that the other configuration information is available via DHCPv6 Example of such information is DNS related information or information on other servers w...

Страница 38: ...cify the Prefix Address Prefix Length Preferred Time and Valid Time Prefix Address Specify one prefix address for the router to advertise via Router Advertisement The link local prefix should not be s...

Страница 39: ...DNS configurations On the Manual mode user should also specify the IPv6 Address Pool Prefix Length Preferred Time Valid Time and DNS Servers IPv6 Address Pool Specify the DHCPv6 address pool It can be...

Страница 40: ...es the wireless network settings for your WLAN interface The wireless interface enables the wireless AP function for ADSL modem 5 3 1 Basic Setting This page contains all of the wireless basic setting...

Страница 41: ...D to be able to communicate with your ADSL modem or AP Channel Number Select the appropriate channel from the list provided to correspond with your network settings You shall assign a different channe...

Страница 42: ...ion method and incorporates Message Integrity Code MIC to provide protection against hackers WPA2 AES WPA2 also known as 802 11i uses Advanced Encryption Standard AES for data encryption AES utilized...

Страница 43: ...this to enter the Pre Shared Key secret as hexadecimal secret Pre Shared Key Specify the shared secret used by this Pre Shared Key If the Pre Shared Key Format is specified as PassPhrase then it indic...

Страница 44: ...ws administrator to have access control by entering MAC address of client stations MAC address can be added into access control list and only those clients whose wireless MAC address are in the access...

Страница 45: ...e whose MAC addresses are in the current access control list will be able to connect to this device Deny Listed When this option is selected all wireless clients except those whose MAC addresses are i...

Страница 46: ...s page allows advanced users who have sufficient knowledge of wireless LAN to configure advanced settings These setting shall not be changed unless you know exactly what will happen from the changes y...

Страница 47: ...he AP and mobile wireless stations Make sure to select the appropriate preamble type Note that high network traffic areas should use the short preamble type CRC is a common technique for detecting dat...

Страница 48: ...Protected Setup WPS is designed to ease set up of security enabled Wi Fi networks and subsequently network management The largest difference between WPS enabled devices and legacy devices is that use...

Страница 49: ...could enter four digit PIN without checksum and then click Apply Changes However this would not be recommended since the registrar side needs to be supported with four digit PIN Push Button Configura...

Страница 50: ...c On your LAN hosts a default gateway directs all Internet traffic to the LAN port s on the DSL device Your LAN hosts know their default gateway either because you assigned it to them when you modifie...

Страница 51: ...need to define routes if your home setup includes two or more networks or subnets if you connect to two or more ISP services or if you connect to a remote corporate LAN Fields in this page Field Desc...

Страница 52: ...ines the number of hops between network nodes that data packets travel The default value is 0 which means that the subnet is directly one hop away on the local LAN network Interface The WAN interface...

Страница 53: ...ecause all Internet data from the network is sent to the same ISP gateway You may want to configure RIP if any of the following circumstances apply to your network o Your home network setup includes a...

Страница 54: ...cess of modifying IP address information in IP packet headers while in transit across a traffic routing device 6 2 1 DMZ Setup A DMZ Demilitarized Zone allows a single computer on your LAN to expose A...

Страница 55: ...e local host This feature sets a local host to be exposed to the Internet 6 2 2 Virtual Server Firewall keeps unwanted traffic from the Internet away from your LAN computers Add a Virtual Server entry...

Страница 56: ...ess WAN Interface Select the WAN interface on which the Virtual Server rule is to be applied WAN Port The destination port number that is made open for this application on the WAN side Local IP Addres...

Страница 57: ...ected Delete the selected rules from the table You can click Delete button from the Current virtual serve forwarding table Disable Without deleting the rule you can make specific virtual server entry...

Страница 58: ...low you to automatically redirect common network services to a specific machine behind the NAT firewall These settings are only necessary if you wish to host some sort of server like a web server or m...

Страница 59: ...pplication layer control data protocols such as IPSec L2TP PPTP FTP SIP RTSP etc In order for these protocols to work through NAT or a firewall either the application has to know about an address port...

Страница 60: ...n which outbound traffic on predetermined ports triggering ports causes inbound traffic to specific incoming ports to be dynamically forwarded to the initiating host while the outbound ports are in us...

Страница 61: ...of listening on a non standard control port other than TCP 21 When the policy associated with this non standard port is configured with the application ftp qualifier as configured in the solution to...

Страница 62: ...se this feature for outgoing traffic creating NAT IP MAPPING rules that divert all traffic that is destined for a certain IP address to a different IP address Entries in this table allows you to confi...

Страница 63: ...rule You can configure any or all field as needed in these two QoS blocks for a QoS rule Fields on the first setting block of this page Field Description IP QoS Enable Disable the IP QoS function Sour...

Страница 64: ...c that matches this classification rule The possible selections are in the descending priority p0 p1 p2 p3 IP Precedence Select this field to mark the IP precedence bits in the packet that match this...

Страница 65: ...4 CWMP Setup 6 4 1 TR 069 Configuration TR 069 is a protocol for communication between a CPE and Auto Configuration Server ACS The CPE TR 069 configuration should be well defined to be able to communi...

Страница 66: ...will send an Inform RPC to the ACS server at the system startup and will continue to send it periodically at an interval defined in Periodic Inform Interval field When this field is disabled the DSL d...

Страница 67: ...Device_IP Port Path Port The port of the device ConnectionRequestURL 6 5 Port Mapping Setup The DSL device provides multiple interface groups Up to five interface groups are supported including one d...

Страница 68: ...long to the default group and the other four groups are all empty It is possible to assign any interface to any group but only one group 6 5 1 Port Mapping Configuration Fields in this page Field Desc...

Страница 69: ...interface list and add it to the grouped available interface list using the arrow buttons to manipulate the required mapping of the ports Click Apply Changes button to save the changes 6 6 Others 6 6...

Страница 70: ...having seen a frame coming from a certain address the bridge will time out delete that address from Forwarding DataBase fdb 802 1d Spanning Tree Enable disable the spanning tree protocol 6 6 2 Client...

Страница 71: ...3 Tunnel Configuration This configuration provides a configuration for tunneling an IPv6 network and traffic through a pre existing IPv4 network This technique allows you to connect IPv6 sites over th...

Страница 72: ...access the Internet using half bridge mode as NAT is disabled Half bridge mode can only be used when a single IP address has been assigned by the ISP it is not suitable for services that provide mult...

Страница 73: ...g is useful when the same data needs to be sent to more than one hosts Using multicasting as opposed to sending the same data to the individual hosts uses less network bandwidth The multicast feature...

Страница 74: ...it sends IGMP REPORT message to the device s IGMP downstream interface The proxy sets up a multicast route for the interface and host requesting the video content It then forwards the Join to the ups...

Страница 75: ...proxy feature Proxy Interface The upstream WAN interface is selected here 7 1 2 MLD Configuration Multicast Listener Discovery MLD is a component of the Internet Protocol Version 6 IPv6 suite MLD is...

Страница 76: ...DG BG4300N User Manual similar to IGMPv2 and MLDv2 similar to IGMPv3...

Страница 77: ...rsal when an UPnP command is received to open ports in NAT the application translates the request into system commands to open the ports in NAT and the firewall The interface to open the ports is give...

Страница 78: ...ystem description of the DSL device System Contact Contact person and or contact information for the DSL device System Name An administratively assigned name for the DSL device System Location The phy...

Страница 79: ...B 7 4 DNS Setup 7 4 1 DNS Configuration This page is used to select the way to obtain the IP addresses of the DNS servers Fields in this page Field Description Attain DNS Automatically Select this ite...

Страница 80: ...ser Manual 7 4 2 IPv6 DNS IPv6 configuration is mostly the same as IPv4 configuration please refer to 6 4 1 DNS Configuration IPv4 uses only 32 bits for IP address space IPv6 allows 128 bits for IP ad...

Страница 81: ...r and access your device each time using the same host name The Dynamic DNS page allows you to enable disable the Dynamic DNS feature 7 5 1 Dynamic DNS DDNS Configuration On the Dynamic DNS page confi...

Страница 82: ...nual Interface This field defaults to your device s WAN interface over which your device will be accessed Username User name assigned by the DDNS service provider Password Password assigned by the DDN...

Страница 83: ...he default action on the LAN to WAN bridging forwarding path Incoming Default Action Specify the default action on the WAN to LAN bridging forwarding path Fields on the second setting block Field Desc...

Страница 84: ...y the default action on the WAN to LAN forwarding path Fields on the second setting block Field Description Rule Action Deny or allow traffic when matching this rule Direction Traffic forwarding direc...

Страница 85: ...DG BG4300N User Manual Destination Subnet Mask Subnet mask of the destination IP Destination Port Starting and ending destination port numbers...

Страница 86: ...anual 8 2 2 IPv6 Port Filtering IPv6 configuration is mostly the same as IPv4 configuration please refer to 8 2 1IP Port Filtering IPv4 uses only 32 bits for IP address space IPv6 allows 128 bits for...

Страница 87: ...ocked by specifying only a FQDN such as tw yahoo com The URL Blocking enforces a Web usage policy to control content downloaded from and uploaded to the Web 8 3 1 URL Blocking Configuration Fields in...

Страница 88: ...pecifies who is allowed to access this device If ACL is enabled all hosts cannot access this device except for the hosts with IP address in the ACL table 8 4 1 ACL Configuration 1 LAN You can enable L...

Страница 89: ...ual 8 4 2 IPv6 ACL Configuration IPv6 configuration is mostly the same as IPv4 configuration please refer to 7 4 1 ACL Configuration IPv4 uses only 32 bits for IP address space IPv6 allows 128 bits fo...

Страница 90: ...ed effectively unavailable Such attacks usually lead to a server overload In general terms DoS attacks are implemented by either forcing the targeted computer s to reset or consuming its resources so...

Страница 91: ...rmware To upgrade the firmware on the DSL device Click the Browse button to select the firmware file Confirm your selection Click the Upload button to start upgrading IMPORTANT Do not turn off your DS...

Страница 92: ...DG BG4300N User Manual 9 1 2 Backup Restore Settings This page allows you to backup and restore your configuration into and from file on your host PC...

Страница 93: ...DG BG4300N User Manual...

Страница 94: ...ou to change the password for administrator and user 9 2 1 User Account Configuration Fields in this page Field Description User Name Selection of user levels are admin and user Old Password Enter the...

Страница 95: ...boot Function buttons in this page 1 Save Current Configuration Save changes 2 Factory Default Configuration Restore router to factory default settings 3 Commit Changes Save the changes into flash mem...

Страница 96: ...Configuration Fields in this page Field Description System Time The current time of the specified time zone You can set the current time by yourself or configured by SNTP Time Zone Select The time zon...

Страница 97: ...DG BG4300N User Manual 9 5 Log Setup You can setup the system log file 9 5 1 Log Setting This page shows the system log...

Страница 98: ...request packets to the target host and waiting for an ICMP response In the process it measures the time from transmission to reception round trip time and records any packet loss 9 6 2 Ping6 Diagnost...

Страница 99: ...M OAM loopback cells to verify connectivity between VP VC endpoints as well as segment endpoints within the VP VC OAM F4 cells operate at the VP level They use the same VPI as the user cells however t...

Страница 100: ...Manual PTI 101 End to End OAM F5 cells which are only processed by end stations terminating an ATM link 9 6 5 ADSL Diagnostic This page shows the ADSL diagnostic result Click Start button to start the...

Страница 101: ...ts for the connectivity of the physical layer and protocol layer for both LAN and WAN sides Fields in this page Field Description Select the Internet Connection The available WAN side interfaces are l...

Страница 102: ...g reset button for over 10 seconds e Set your computer to obtain an IP address automatically DHCP and see if your computer can get an IP address f If you did a firmware upgrade and this happens contac...

Страница 103: ...re transferring files of big size other clients will get an impression that Internet is slow e If this has never happened before call your Internet service provider to know if there is something wrong...

Отзывы: