ESR-Series. User manual
79
•
•
•
•
•
•
•
•
for ESR-1500: GigabitEthernet 1/0/2-8, TengigabitEthernet 1/0/3-4;
for ESR-1511: GigabitEthernet 1/0/2-8, TengigabitEthernet 1/0/1-4;
for ESR-1700: GigabitEthernet 1/0/2-4, TengigabitEthernet 1/0/3-12;
for ESR-3100: GigabitEthernet 1/0/2-8, TengigabitEthernet 1/0/3-8.
Zone interfaces are grouped into a single L2 segment via
Bridge 1
network bridge.
On the
Bridge 2
interface, DHCP client is enabled to obtain dynamic IP address from the provider. On
Bridge 1
interface, static IP address 192.168.1.1/24 is configured. Created IP address acts as a gateway for LAN
clients. For LAN clients, DHCP address pool 192.168.1.2-192.168.1.254 is configured with the mask
255.255.255.0. For clients in order to access the Internet, the router should have Source NAT service enabled.
Security zone policies have the following configuration:
Table 44 – Security zone policy description
Traffic origin zone
Traffic destination zone
Traffic type
Action
Trusted
Untrusted
TCP, UDP, ICMP
enabled
Trusted
Trusted
TCP, UDP, ICMP
enabled
Trusted
self
TCP/22 (SSH), ICMP, UDP/67 (DHCP Server), UDP/123
(NTP)
enabled
Untrusted
self
UDP/68 (DHCP Client)
enabled
5.2 Router connection and configuration
ESR series routers are intended to perform border gateway functions and securing the user network when it is
connected to public data networks.
Basic router configuration should include:
Assigning IP addresses (static or dynamic) to the interfaces that participate in data routing;
Creation of security zones and distribution of interfaces between these zones;
Creation of policies governing data transfer through these zones;
Configuration of services that accompany the data routing (NAT, Firewall, etc.).
Advanced settings depend on the requirements of the specific device application pattern and may be easily
added or modified with the existing management interfaces.
5.2.1 Connection to the router
There are several device connection options:
To enable device configuration on the first startup, 'admin' account has been created in the router
configuration. The user will be prompted to change administrator password during the initial
configuration of the router.
To enable network access to the router on the first startup, static IP address 192.168.1.1/24 has
been configured on Bridge 1 interface.
Содержание ESR Series
Страница 218: ...ESR Series User manual 218 ...
Страница 234: ...ESR Series User manual 234 In addition to RIP protocol configuration open UDP port 520 in the firewall ...
Страница 306: ...ESR Series User manual 306 Parameter targeted LDP Hold timer 45 seconds Keepalive holdtime 180 seconds ...
Страница 452: ...ESR Series User manual 452 Step Description Command Keys 4 Enable Tracking object esr config tracking enable ...
Страница 514: ...ESR Series User manual 514 esr show ntp peers ...