
Bypassing the Firewall to Access Hosts on LAN
155
BODi rS BD1000 User Manual
C • Applications
Bypassing the Firewall to Access Hosts on LAN
Scenario
There are times when remote access to computers on the LAN is desirable; for example, when hosting websites,
online businesses and FTP download and upload areas, etc. In such cases, it may be appropriate to create an
inbound NAT mapping for the network to allow some hosts on the LAN to be accessible from outside of the
firewall.
Solution
Web Admin Interface can be used for adding an inbound NAT Mapping to a host and to bind the host to the
WAN connections, via
Network > NAT Mappings > Add NAT Rule
. For example, you may add the host,
with IP address 192.168.1.102 to an Inbound Mapping, and bind the host to the default IP and
211.123.123.100 of WAN1.
Inbound Access Restriction
Scenario
A firewall is required to protect the network from potential hacker attacks and other Internet security threats.
Solution
Firewall functionality is built into the BD1000. By default, inbound access is unrestricted. Enabling a basic
level of protection involves setting up firewall rules. For example, to set up a firewall rule between the Internet
and the private network that monitors Web access from the Internet, click the
Add Rule
button in the
Inbound Firewall Rules
table. Use the following settings for the new rule:
•
Protocol:
TCP <- HTTP
•
Source IP & Port:
Any Address, Any Port
•
Destination IP & Port:
Any Address, Single Port, Port 80
•
Action:
Allow
After the fields have been entered, click
Save
to add the rule. Then, change the default inbound rule to
Deny
by clicking the
Default
rule in the
Inbound Firewall Rules
table.