background image

 

Chapter 5 Firewall 

5.1    MAC/IP/Port Filtering 

You may set up firewall rules to protect your network from malicious activity on the Internet. It is also 
convenient for you to delete these settings. 

 

 

Basic Settings 

 

 

MAC/IP/Port Filtering:

 Enable or disable the MAC/IP/Port filtering function. 

 

 

Default Policy:

 The Packet that does not match any rules would be dropped or accepted. 

MAC/IP/Port Filter Settings 

 

 

MAC Address:

 Enter the MAC address that matches the source address of the packet (optional). 

 

 

Dest IP Address:

 Enter the IP address that matches the destination address of the packet 

(optional). 

 

33

Содержание WNRT-625

Страница 1: ...802 11n Wireless Broadband Router WNRT 625 User s Manual ...

Страница 2: ...spective holders Federal Communication Commission Interference Statement This equipment has been tested and found to comply with the limits for a Class B digital device pursuant to Part 15 of FCC Rules These limits are designed to provide reasonable protection against harmful interference in a residential installation This equipment generates uses and can radiate radio frequency energy and if not ...

Страница 3: ...nition of their conformity R TTE The R TTE Directive repeals and replaces in the directive 98 13 EEC Telecommunications Terminal Equipment and Satellite Earth Station Equipment As of April 8 2000 Safety This equipment is designed with the utmost care for the safety of those who install and use it However special attention must be paid to the dangers of electric shock and static electricity when wo...

Страница 4: ...ON MODE 14 3 3 INTERNET SETTINGS 15 3 3 1 WAN 15 3 3 2 LAN 21 3 3 3 DHCP clients 22 3 3 4 Advanced Routing 23 3 3 5 QoS 24 CHAPTER 4 WIRELESS SETTINGS 25 4 1 BASIC 25 4 2 ADVANCED WIRELESS SETTINGS 28 4 3 SECURITY 30 4 4 WPS 31 4 5 STATION LIST 32 CHAPTER 5 FIREWALL 33 5 1 MAC IP PORT FILTERING 33 5 2 PORT FORWARDING 34 5 3 DMZ 35 5 4 SYSTEM SECURITY SETTINGS 36 5 5 CONTENT FILTERING 37 CHAPTER 6 ...

Страница 5: ...5 6 4 STATUS 40 6 5 STATISTIC 41 6 6 SYSTEM LOG 42 ...

Страница 6: ...upported z Supports DHCP Server z System status monitoring includes Active DHCP Client Security Log and Device Connection Status z Web based GUI for and Wizard setup for easily configuration z Remote Management allows configuration and upgrades from a remote site z Supported Internet types Dynamic Static IP PPPoE PPTP L2TP z MAC IP filter access control URL blocking SPI firewall DoS prevention pro...

Страница 7: ...n Receiver Sensitivity 1 Mbps 94 dBm 2 Mbps 91 dBm 5 5 Mbps 89 dBm 11 Mbps 85 dBm 6 Mbps 90 dBm 9 Mbps 89 dBm 12 Mbps 86 dBm 18 Mbps 84 dBm 24 Mbps 81 dBm 36 Mbps 77 dBm 48 Mbps 73 dBm 54 Mbps 72 dBm 300Mbps 68dBm Session 3000 LED Indicators PWR WLAN WPS WAN 1 LAN 4 7 ...

Страница 8: ... Power Interface that connects to the power adapter 12 V DC 500mA WAN Ethernet RJ 45 interfaces that connect to the Internet LAN 1 4 Ethernet RJ 45 interfaces that connect to the Ethernet interface of the computer or Ethernet devices WPS WPS on or off switch 1 Locate an optimum location for the WNRT 625 The best place for your WNRT 625 is usually at the center of your wireless network with line of...

Страница 9: ... your modem please use a RJ 45 Ethernet cable 4 Connect all of your network devices to LAN port of WNRT 625 Connect all your computers network devices network enabled consumer devices other than computers like game console or switch hub Connect one of the LAN ports on WNRT 625 to your LAN switch hub or a computer with a RJ 45 cable 9 ...

Страница 10: ...cted to the respective port of the router is powered on and correctly connected If PWD LED is not on or any LED you expected is not on please recheck the cabling or jump to Troubleshooting for possible reasons and solution 1 ONLY use the power adapter supplied with the WNRT 625 Otherwise the product may be damaged 2 If you want to reset WNRT 625 to default settings press and hold the Reset button ...

Страница 11: ...N radio is off On WPS client registration is successful Blinks WPS client registration window is currently open WPS Green Off WPS is not available or WPS is not enabled or initialized On The device has successful Ethernet connections Blinks The device is receiving or sending data on WAN WAN Green Off The WAN is not connected On The device has successful Ethernet connections Blinks The device is re...

Страница 12: ...gs should be set to obtain an IP address from a DHCP server WNRT 625 automatically To verify your IP address please follow the steps below 1 Click on Start Run 2 In the run box type cmd and click OK Windows VistaR users type cmd in the Start Search box At the prompt 12 ...

Страница 13: ...tions Windows 2000 From the desktop right click My Network Places Properties 2 Right click on the Local Area Connection which represents your network adapter and select Properties 3 Highlight Internet Protocol TCP IP and click Properties 4 Click Use the following IP address and enter an IP address that is on the same subnet as your network or the LAN IP address on your router Example If LAN IP add...

Страница 14: ...ord as below User Name admin Password admin 4 Then you will see the WNRT 625 HOME screen as below 3 2 Operation Mode Choose Operation Mode and the following page appears In this page you can configure the operation mode according to your practice Bridge All Ethernet and wireless interfaces are bridged into a single bridge interface Gateway The first Ethernet interface is treated as WAN interface T...

Страница 15: ...you select Bridge operation mode WAN configuration in Internet Settings are not available Firewall functions on the left page are not available After finishing setting click Apply to save the settings and make the new configuration take effect Click Cancel to close without saving 3 3 Internet Settings 3 3 1 WAN The WAN Settings screen allows you to specify the type of Internet connection The WAN s...

Страница 16: ... port Default Gateway Enter the default gateway address of WAN port Primary DNS Server Primary DNS Server f of WAN port Secondary DNS Server Secondary DNS Server of WAN port MAC Clone MAC Clone provides WAN to connect to a MAC address Enabled Enable or disable MAC clone After finishing setting click Apply to save the settings and make the new configuration take effect Click Cancel to close without...

Страница 17: ... interface MAC Clone MAC Clone provides WAN to connect to a MAC address Enabled Enable or disable MAC clone After finishing setting click Apply to save the settings and make the new configuration take effect Click Cancel to close without saving PPPOE ADSL Select PPPoE ADSL in the WAN Connection Type drop down list and the following page appears If the WAN connection type is set to PPPoE ADSL you c...

Страница 18: ...reset idle time if AP does not detect the flow of the user continuously AP automatically stops the PPPOE connection Once it detects the flow e g accessing a webpage the router restarts the PPPOE dial up MAC Clone Enabled Enable or disable After finishing setting click Apply to save the settings and make the new configuration take effect Click Cancel to close without saving L2TP Select L2TP in the ...

Страница 19: ...s Keep Alive means keeping on line mode You can set the redial period in the field When the redial period expires AP will execute dial up again to keep online On Demand means executing dial up on demand Within the preset idle time if AP does not detect the flow of the user continuously AP automatically stops the PPPOE connection Once it detects the flow e g accessing a webpage the router restarts ...

Страница 20: ...es of operation modes Keep Alive means keeping on line mode You can set the redial period in the field When the redial period expires AP will execute dial up again to keep online On Demand means executing dial up on demand Within the preset idle time if AP does not detect the flow of the user continuously AP automatically stops the PPPOE connection Once it detects the flow e g accessing a webpage ...

Страница 21: ...k of LAN port MAC Address MAC address of LAN port Read only DHCP Type You can select Server or Disable If you select Disable the DHCP service of LAN port is disabled After selecting Server you can set the following items Start IP Address The first IP address that DHCP server assigns End IP Address The last IP address that DHCP server assigns Subnet Mask The subnet mask of dynamic IP Primary DNS Se...

Страница 22: ...select Enable or Disable IGMP Snooping You can select Enable or Disable UPNP Universal Plug and Play UPNP You can select Enable or Disable Router Advertisement You can select Enable or Disable PPPoE Relay You can select Enable or Disable DNS Proxy You can select Enable or Disable After finishing setting click Apply to save the settings and make the new configuration take effect Click Cancel to clo...

Страница 23: ...e for this route You can select LAN WAN and Custom Comment Add the description of this route After finishing the setting above click Apply to make the new routing rule take effect Otherwise click Reset to cancel the new routing rule Current Routing table in the system You can delete or reset the routing rules Dynamic Routing Settings You can enable or disable the RIP After finishing the setting ab...

Страница 24: ...elect the proper bandwidth in the drop down list The value is from 64K to 60M You can also set the bandwidth by selecting User defined and enter the proper bandwidth in the field Download Bandwidth You can select the proper bandwidth in the drop down list The value is from 64K to 60M You can also set the bandwidth by select User defined and enter the proper bandwidth in the field fter finishing th...

Страница 25: ... mode Network Name SSID The service set identification SSID is a unique name to identify the router in the wireless LAN Wireless stations associating to the router must have the same SSID Enter a descriptive name Its length is up to 32 characters Multiple SSID 1 2 3 4 5 6 7 There are 7 multiple SSIDs Enter their descriptive names that you want to use Broadcast Network Name SSID Select Enable to al...

Страница 26: ...wireless device Channels available depend on your geographical area You may have a choice of channels for your region and you should use a different channel from an adjacent AP to reduce the interference The Interference and degrading performance occurs when radio signals from different APs overlap Wireless Distribution System WDS WDS Mode There are four options including Disable Lazy Mode Bridge ...

Страница 27: ...t the same time A WDS link is bi directional so the AP must know the MAC address of the other AP and the other AP must have a WDS link back to the AP Dynamically assigned and rotated encryption key are not supported in a WDS connection This means that WPA and other dynamic key assignment technologies may not be used Only Static WEP keys may be used in a WDS connection including any STAs that are a...

Страница 28: ...Settings This page makes more detailed settings for the AP Advanced Wireless Settings page includes items that are not available in the Basic Wireless Settings page such as basic data rates beacon interval and data beacon rate Advanced Wireless BG Protection Mode It provides 3 options including Auto On and Off The default BG protection mode is Auto Beacon Interval The interval time range is betwee...

Страница 29: ... reach the RTS size Tx Power The Tx Power range is between 1 and 100 The default value is 100 Short Preamble Select Disable or Enable Short Slot Select Disable or Enable Tx Burst Select Disable or Enable Pkt_Aggregate Select Disable or Enable Country Code Select the region which area you are It provides six regions in the drop down list Wi Fi Multimedia WMM Capable Enable or disable WMM APSD Capab...

Страница 30: ...s Select SSID SSID choice Select SSID in the drop down list Security Security Mode There are 11 options including Disable OPEN SHARED WEPAUTO WPA WPA PSK WPA2 WPA2 PSK WPAPSKWPA2PSK WPA1WPA2 and 802 1X EXAMPLE Take 802 1x for example Select 802 1x in the Security Mode down list The page shown in the following page appears WEP Disable or enable WEP 30 ...

Страница 31: ...time interval Enter the proper value in the field Access Policy Policy There are three options including Disable Allow and Reject You can choose Disable Allow or Reject Select Allow only the clients whose MAC address is listed can access the router Select Reject the clients whose MAC address is listed are denied to access the router Add a station MAC If you want to add a station MAC enter the MAC ...

Страница 32: ...n PBC on the Wi Fi router If there is no button enter a 4 or 8 digit PIN code Each STA supporting WPS comes with a hard coded PIN code PIN If you select PIN mode you need enter the PIN number in the field WPS Status It displays the information about WPS status 4 5 Station list Through this page you can easily identify the connected wireless stations It automatically observes the ID of connected wi...

Страница 33: ...s Basic Settings MAC IP Port Filtering Enable or disable the MAC IP Port filtering function Default Policy The Packet that does not match any rules would be dropped or accepted MAC IP Port Filter Settings MAC Address Enter the MAC address that matches the source address of the packet optional Dest IP Address Enter the IP address that matches the destination address of the packet optional 33 ...

Страница 34: ...UPD or TCP source port range Action Select Drop or Accept in the drop down list Comment Add description for this rule Click Apply to make the configuration take effect Click Reset to cancel the new configuration The maximal rule number you can add is 32 Current MAC IP Port filtering rules in system If you want to delete some rules in the table above select the rules and then click Delete Selected ...

Страница 35: ... Comment Add description for this rule The maximal rule number you can add is 32 Click Apply to make the configuration take effect Click Reset to cancel the new configuration 5 3 DMZ This page allows you to set a De militarized Zone DMZ to separate internal network and Internet DMZ Settings Enable or disable this function After selecting Enable you can set the DMZ IP address DMZ IP Address Enter t...

Страница 36: ...agement via WAN Deny or allow remote management through web Ping from WAN Filter Ping from WAN Filter You may select enable or disable to determine whether to filter the ping package which comes from the external network Stateful Packet Inspection SPI SPI Firewall You may disable or enable the SPI firewall Click Apply to make the configuration take effect Click Reset to cancel the new configuratio...

Страница 37: ... filter to restrict the improper content access Current Webs URL Filters If you want to delete some filters in the table above select the rules and then click Delete Otherwise click Reset Add a URL filter URL Enter a URL filter Click Add to add a URL filter Otherwise click Reset to cancel the URL filter 37 ...

Страница 38: ... in the field NTP Settings Current Time Display the current date and time Click Sync with host the current time is synchronized by your PC which is connected to AP Time Zone Select the proper time zone in the drop down list NTP Server Enter the IP address or domain name of NTP server NTP Synchronization hours Enter the time interval for synchronization DDNS Settings Dynamic DNS Provider Select the...

Страница 39: ...this page you may upgrade the correct new version firmware to obtain new functionality It takes about 1 minute to upload upgrade flash If the firmware is uploaded in an improper way the system would core dump Update Firmware Location Click Browse to select the firmware file and click Apply to upgrade the firmware 6 3 Setting Management Choose Administration Settings Management and the following pa...

Страница 40: ...ort to upload the configuration file Click Cancel to cancel the uploading operation Load Factory Defaults Load Default Button Click Load Default to make AP return to the default settings 6 4 Status Choose Administration Status and the following page appears It displays the information about AP status including system information Internet configurations and local network 40 ...

Страница 41: ...6 5 Statistic Choose Administration Statistics and the following page appears This page shows all the statistics information about your AP 41 ...

Страница 42: ...6 6 System Log Choose Administration System Log and the following page appears You are allowed to view and clear the system log in this page Click Refresh to refresh the log Click Clear to clear the log 2 ...

Отзывы: