background image

WaveData

18

         Although the forwarding policy is reject by default, packet is forwarded if 

match a Forwarding Traffic Rule or Port Forwarding rule. Figure show how 

IPSec is enabled to traverse from WAN to LAN.

         Packet is forwarded if match an active connection (packet belong to a valid 

Connection with ESTABLISHED or RELATED states on Connection tracking). 

Most of the WAN to LAN traffic belongs to this category.

         Inter-zone forwarding: Packet is forwarded if is enabled to traverse between 

zones. Most of the Traffic from WAN to LAN do not need enable inter-zone 

forwarding since is related with an active connection but LAN packets to 

WAN destination need to be enabled to forward since connections are 

started from LAN.

LAN Zone

LAN zone covers all traffic from and to local interfaces.
         When router receives a packet from LAN, default policy is accept input and 

output traffic to CPU. Local host have access to router services like web or 

SSH without any restrictions.

         Default policy to Forward traffic is reject traffic from unknown zones. Use 

Inter-Zone Forwarding to enable forwarding to/from another zones or add 

custom Traffic Rules.

Normally packet comes from a network covered by a zone, but if router receives 

a packet from interface what is not covered by a firewall zone, applies default 

policies.
By default Firewall defines two zones
        

 LAN  zone

: Default policy is accept all traffic to CPU (Input and Output) and 

reject Forward.

         

WAN zone

: Default policy is accept only Output. Input and Forward are 

rejected. WAN zone also enable Masquerading (NAT) and MSS Clamping. 

This policy rejects all input and forwarding traffic but some exceptions are 

added like Port Forwarding and Traffic Rules (open Web or SSH ports by 

example).

WAN Zone

        WAN zone covers WAN and WAN6 network interfaces.
         Default policy for WAN is reject input traffic (to avoid hack router services) 

and accept all output from CPU to WAN.

         Forwarding to unknown zones is rejected but you can use Inter-Zone 

Forwarding to enable forwarding to/from another zones.

         Although the input policy is reject by default, policy is override by custom 

rules. Figure shows some input rules defined for WAN zone that accept 

some input protocols like ping or DHCP.

Содержание 769001

Страница 1: ...User Guide WaveData AP MyNETWiFi w w w t e l e v e s c o m Refs 769001 769002 Art Nr WAVEDATAP WAVEDATAS...

Страница 2: ......

Страница 3: ...6 Installing WaveData 7 Installation example Ref 769001 7 Installation example Ref 769002 7 Connect to WaveData 8 WaveData access via SSH 8 WaveData access via Web 8 Web Login 8 Configure WaveData 9 D...

Страница 4: ...e Wi Fi standard It can reach maximum throughputs well above a Gigabit per second The 802 11ac specification mandates operation in the 5 GHz band where there is relatively less interference and more c...

Страница 5: ...dissipation slots on external plastic chassis should be ventilated and air flow through device Place device on a clear location in order to guarantee Wi Fi coverage Device must be placed on location...

Страница 6: ...s Frontal RGB Led Device has a frontal RGB Led to indicate device status RBG Led Functions Device Activity LED Pattern System boot up kernel stage Blink Orange AP is Broadcasting SSIDs Fixed Green myN...

Страница 7: ...N PoE WAN PoE WaveData 769001 WaveData 769001 WaveData 769001 WAN PoE WaveData 769001 WAN PoE WaveData 769001 WAN PoE WaveData 769001 WAN PoE WaveData 769001 WAN PoE WaveData 769001 Internet Installat...

Страница 8: ...als Default IP LAN 169 254 1 254 LAN_DHCP DHCP client username root Password 76Wave90Data01 WaveData access via SSH SSH Terminal can execute any command on the WaveData such as install new packages re...

Страница 9: ...NTP Server Candidates Input valid NTP servers to configure time System Logging WaveData keeps an event log By default the data is not stored in a file it is stored in a circular buffer As new entries...

Страница 10: ...dit Interface Change interface settings When changes are made to the configuration of several interfaces it is advisable to save the changes in the configuration first to subsequently apply them toget...

Страница 11: ...le options are available DHCP Client Hostname Use this field to set a custom hostname other than default on system when send DHCP requests PPPoE Client Create a new PPPoE connection with a PPPoE serve...

Страница 12: ...u want DHCP server not provide IP Configuration on this interface Start First valid DHCP IP address as offset of network address Limit Max Number of DHCP Address Lease Time Expiry time of leased addre...

Страница 13: ...the configuration on the interface with which we connect to device the change may lead to a connection lost Router Mode firewall WAN zone If theWAN network on which the device operates is not secure i...

Страница 14: ...m Wi Fi to see Wi Fi interfaces list Interface offers following buttons per interface Scan Scan network for available AP Add Create a new VAP And following buttons per VAP Virtual Access Point Disable...

Страница 15: ...of Channel Set channel ofWi Fi device Auto let driver to choose best channel Width Bandwith of Wi Fi channel 20 40 80 MHz Power Transmit power of Wi Fi channel Interface Configuration section configur...

Страница 16: ...ettings 802 1h Enable IEEE 802 1h amendment added to the IEEE 802 11 standard for Spectrum and Transmit Power Management Extensions It solves problems like interference with satellites and radar using...

Страница 17: ...AN to WAN Create VLAN to tag traffic from Wi Fi User can add more VLANs according to the needs of the network The following example shows how to add VLAN10 tag to traffic coming from Wi Fi interfaces...

Страница 18: ...s reject traffic from unknown zones Use Inter Zone Forwarding to enable forwarding to from another zones or add custom Traffic Rules Normally packet comes from a network covered by a zone but if route...

Страница 19: ...from WAN if match a active Connection or Port Forwarding Rule WAN zone rejects forwarding from LAN When LAN users start connections no State is available so enable forwarding from LAN to WAN in order...

Страница 20: ...ime protocol OFDM Orthogonal Frequency Division Multiplexing PAP CHAP Password Authentication Protocol Challenge Handshake Authentication Protocol PoE Power over Ethernet PPPoE Point to Point Protocol...

Страница 21: ...nas 4xDual Band Antenna Polarization Linear Beamforming Antenna Gain 2 4 GHz 4dBi 5 GHz 4dBi Security Encryption Open WEP WPA PSK 802 1X WPA EAP Ciphers TKIP AES CCMP AES GCMP Leds RGB Led Tri color t...

Страница 22: ...WaveData 22...

Страница 23: ...EN 23...

Страница 24: ...769001 769002_001_EN Manufacturer Televes S A U R a B de Conxo 17 15706 Santiago de Compostela A Coru a Spain www televes com...

Отзывы: