
HY-LINE truecon Router Handbuch
HY-LINE Systems GmbH
Inselkammerstr. 10 82008 Unterhaching systems(at)hy-line.de www.hy-line.de/systems
Seite 29
F
F
o
o
r
r
t
t
s
s
e
e
t
t
z
z
.
.
:
:
F
F
i
i
r
r
e
e
w
w
a
a
l
l
l
l
:
:
The
firewall configuration
allows the opening and closing of specific services from the internet to the
router (arrows left) and from the router to the internet (arrows right).
C
C
o
o
n
n
t
t
i
i
n
n
u
u
e
e
:
:
F
F
i
i
r
r
e
e
w
w
a
a
l
l
l
l
:
:
Three standard profiles are available:
-
Default
– Standard, applicable for most uses
-
Custom
– Custom profile defined by user, must be set for user configuration
-
Minimum
– High security
Commit rules
: Commit the changes immediately to the firewall configuration when saving
Masquerading:
Set S-NAT routing options: if activated all data packets will be changed coming
f
rom the WAN interface to the local ethernet (eth0) router interface. The router will exchange the public ip
for forwarded packets with his own local ip address. This will be used to access devices on the router lan
subnet without having set a gateway address in this devices.
Outgoing traffic over standard gateway (HY-LINE Router LAN -> externe Gateway) :
Masquerade srcnet:
activate to allow TCP/IP packets to send over standard gateway (no modem
gateway)
Source net:
network ip-mask of outgoing traffic
Example:
172.1.2.0/8 - 255.0.0.0
172.1.0.0/16 - 255.255.0.0
172.0.0.0/24 - 255..255.255.0
Proxy-ARP:
Proxy-ARP function is enabled by default. Change configuration via Linux Shell in file: ../etc/amsel/systems.conf
ProxyArp active:
"echo 1 > /proc/sys/net/ipv4/conf/eth0/proxy_arp";
ProxyArp inactive:
"echo 0 > /proc/sys/net/ipv4/conf/eth0/proxy_arp";