Chapter 9 Firewall
NR2101 User’s Guide
87
About the NR2101 Firewall
The NR2101’s firewall feature physically separates the LAN and the WAN and acts as a secure gateway
for all data passing between the networks.
It is a stateful inspection firewall and is designed to protect against Denial of Service attacks when
activated (click
the
General
tab under
Firewall
and then click the
Enable
check box). The NR2101's
purpose is to allow a private Local Area Network (LAN) to be securely connected to the Internet. The
NR2101 can be used to prevent theft, destruction and modification of data, as well as log events, which
may be important to the security of your network.
The NR2101 is installed between the LAN and a broadband modem connecting to the Internet. This
allows it to act as a secure gateway for all data passing between the Internet and the LAN.
The LAN (Local Area Network) connects to a network of computers, which needs security from the
outside world. These computers will have access to Internet services such as e-mail, FTP and the World
Wide Web. However, "inbound access" is not allowed (by default) unless the remote host is authorized to
use a specific service.
Guidelines For Enhancing Security With Your Firewall
1
Change the default password via Web Configurator.
2
Think about access control before you connect to the network in any way, including attaching a
modem to the port.
3
Limit who can access your NR2101.
4
Don't enable any local service (such as NTP) that you don't use. Any enabled service could present a
potential security risk. A determined hacker might be able to find creative ways to misuse the enabled
services to access the firewall or the network.
5
For local services that are enabled, protect against misuse. Protect by configuring the services to
communicate only with specific peers, and protect by configuring rules to block packets for the services
at specific interfaces.
6
Protect against IP spoofing by making sure the firewall is active.
7
Keep the firewall in a secured (locked) room.
9.2 Firewall Settings
Click
FIREWALL SETTINGS
to open the following screen. Use this screen to enable or disable the NR2101’s
firewall, and set up firewall logs. Click
View Firewall Entries
to view or configure IPv4/IPv6 firewall entries.