P a g e
|
116
GWN7000 User Manual
Version 1.0.6.28
Firewall Advanced Settings
Firewall Advanced Settings page provides the ability to setup input/output policies for each WAN interface
and LAN groups; as well as setting configuration for Static and Dynamic NAT.
General Settings
Click on next to a WAN interface or Network group to edit its input and output policies.
Refer to below table for general settings options:
Table 39: Firewall-General Settings
Input Policy
Select which action to apply to all incoming traffic to this interface/LAN
group, 3 actions are available: Accept, Reject and Drop.
Output Policy
Select which action to apply to all outgoing traffic from this interface/LAN
group, 3 actions are available: Accept, Reject and Drop.
IP Masquerading
Check to enable IP Masquerading, this will allow internal computers with
no known address outside their network, to communicate to the outside.
It allows one machine to act on behalf of other machines.
MSS Clamping
Check to enable MSS Clamping.
This will provide a method to prevent
fragmentation when the MTU value on the communication path is lower
than the MSS value.
Log Dropped and Reject
Traffic to Syslog
Check to send all rejected and dropped traffic logs to configured Syslog
Server.
Limit for Dropped and
Rejected Traffic
Specify the limit for dropped and reject traffic. The value format is N/unit,
where N is a digit number, and unit can either be in second, minute, hour
or day.
SNAT
Following actions are available for SNAT.
•
To add new SNAT entry, click on .
•
To edit a SNAT entry, click on .
•
To delete a SNAT rule, click on .
Refer to below table when creating or editing an SNAT entry:
Table 40: SNAT
Name
Specify a name for the SNAT entry
Enabled
Check to enable this SNAT entry.