Product Manual
Page 4
...: DMZ Setup 24 2.4 Universal Plug and Play (UPnP 25 2.5 Captive Portal ...27 Chapter 3. Wireless Access Point Setup 53 4.1 4.1.1 4.1.2 4.1.3 Wireless Settings Wizard 53 Wireless Network Setup Wizard 54 Add Wireless Device with WPS 54 Manual Wireless Network Setup 55 4.2 4.2.1 4.2.2 4.2.3 Wireless Profiles ...55 WEP Security ...56 WPA or WPA2 with Multiple WAN Links 41...
...: DMZ Setup 24 2.4 Universal Plug and Play (UPnP 25 2.5 Captive Portal ...27 Chapter 3. Wireless Access Point Setup 53 4.1 4.1.1 4.1.2 4.1.3 Wireless Settings Wizard 53 Wireless Network Setup Wizard 54 Add Wireless Device with WPS 54 Manual Wireless Network Setup 55 4.2 4.2.1 4.2.2 4.2.3 Wireless Profiles ...55 WEP Security ...56 WPA or WPA2 with Multiple WAN Links 41...
Product Manual
Page 8
... 5: Adding VLAN memberships to the LAN 22 Figure 6: Port VLAN list ...23 Figure 7: Configuring VLAN membership for a port 24 Figure 8: DMZ configuration ...25 Figure 9: UPnP Configuration...26 Figure 10: Active Runtime sessions ...27 Figure 11: Internet Connection Setup Wizard 28 Figure 12: Manual ... Figure 28: Wireless Network Setup Wizards 54 Figure 29: List of Available Profiles shows the options available to secure the wireless link .........56 Figure 30: Profile configuration to set network security 57 Figure 31: RADIUS server (External Authentication) configuration 59 Figure 32: Virtual...
... 5: Adding VLAN memberships to the LAN 22 Figure 6: Port VLAN list ...23 Figure 7: Configuring VLAN membership for a port 24 Figure 8: DMZ configuration ...25 Figure 9: UPnP Configuration...26 Figure 10: Active Runtime sessions ...27 Figure 11: Internet Connection Setup Wizard 28 Figure 12: Manual ... Figure 28: Wireless Network Setup Wizards 54 Figure 29: List of Available Profiles shows the options available to secure the wireless link .........56 Figure 30: Profile configuration to set network security 57 Figure 31: RADIUS server (External Authentication) configuration 59 Figure 32: Virtual...
Product Manual
Page 9
... a firewall rule 67 Figure 39: Example where an outbound SNAT rule is used to map an external IP address (209.156.200.225) to a private DMZ IP address (10.30.30.30 70 Figure 40: The firewall rule configuration page allows you to define the To/From zone, service, action, schedules... list 83 Figure 49: Export Approved URL list ...84 Figure 50: The following example binds a LAN host's MAC Address to an IP address served by DSR. If there is an IP/MAC Binding violation, the violating packet will be dropped and logs will be captured ...85 Figure 51: Intrusion Prevention features...
... a firewall rule 67 Figure 39: Example where an outbound SNAT rule is used to map an external IP address (209.156.200.225) to a private DMZ IP address (10.30.30.30 70 Figure 40: The firewall rule configuration page allows you to define the To/From zone, service, action, schedules... list 83 Figure 49: Export Approved URL list ...84 Figure 50: The following example binds a LAN host's MAC Address to an IP address served by DSR. If there is an IP/MAC Binding violation, the violating packet will be dropped and logs will be captured ...85 Figure 51: Intrusion Prevention features...
Product Manual
Page 12
... VPN features A fully featured virtual private network (VPN) provides your mobile workers and branch offices with a secure link to a 3G network whenever a physical link is lost . The failover feature maintains data traffic without disconnecting when a landline connection is provided via an extendable ...‖ throughout the wireless coverage area. DSR-250N and DSR-500N supports the 2.4GHz radio band only. Flexible Deployment Options The DSR-1000 / 1000N supports Third Generation (3G) Networks via features such as a DMZ port allowing you are capable of small and medium ...
... VPN features A fully featured virtual private network (VPN) provides your mobile workers and branch offices with a secure link to a 3G network whenever a physical link is lost . The failover feature maintains data traffic without disconnecting when a landline connection is provided via an extendable ...‖ throughout the wireless coverage area. DSR-250N and DSR-500N supports the 2.4GHz radio band only. Flexible Deployment Options The DSR-1000 / 1000N supports Third Generation (3G) Networks via features such as a DMZ port allowing you are capable of small and medium ...
Product Manual
Page 26
... an additional layer of security to the LAN, as web or email servers) be placed in the DMZ network. Setup > DMZ Setup > DMZ Setup Configuration DMZ configuration is no restrictions on the LAN. Firewall rules can be identical to the IP address given to the public but...specific services/ports to the LAN configuration. Unified Services Router Figure 7: Configuring VLAN membership for a port User Manual 2.3 Configurable Port: DMZ Setup DSR-250/250N does not have to the internet (such as specific services/ports that must be exposed to be configured as well. This router ...
... an additional layer of security to the LAN, as web or email servers) be placed in the DMZ network. Setup > DMZ Setup > DMZ Setup Configuration DMZ configuration is no restrictions on the LAN. Firewall rules can be identical to the IP address given to the public but...specific services/ports to the LAN configuration. Unified Services Router Figure 7: Configuring VLAN membership for a port User Manual 2.3 Configurable Port: DMZ Setup DSR-250/250N does not have to the internet (such as specific services/ports that must be exposed to be configured as well. This router ...
Product Manual
Page 27
... for automatic device configuration. If a network device is detected by that network device. Unified Services Router Figure 8: DMZ configuration User Manual In order to configure a DMZ port, the router's configurable port must be set to DMZ in the Setup > Internet Settings > Configurable Port page. 2.4 Universal Plug and Play (UPnP) Advanced > Advanced Network...
... for automatic device configuration. If a network device is detected by that network device. Unified Services Router Figure 8: DMZ configuration User Manual In order to configure a DMZ port, the router's configurable port must be set to DMZ in the Setup > Internet Settings > Configurable Port page. 2.4 Universal Plug and Play (UPnP) Advanced > Advanced Network...
Product Manual
Page 29
...HTTP connection requests for web access but are present in user database prior to granting HTTP access. Captive Portal is made the DSR will intercept the request and prompt for a username / password. Advanced > Captive Portal >Captive Portal Sessions The Active Runtime internet sessions ... HTTP access, and when a matching user request is available for LAN users only and not for DMZ hosts. Figure 10: Active Runtime sessions 27 Unified Services Router User Manual 2.5 Captive Portal DSR-250/250N does not have had their login credentials approved for internet access.
...HTTP connection requests for web access but are present in user database prior to granting HTTP access. Captive Portal is made the DSR will intercept the request and prompt for a username / password. Advanced > Captive Portal >Captive Portal Sessions The Active Runtime internet sessions ... HTTP access, and when a matching user request is available for LAN users only and not for DMZ hosts. Figure 10: Active Runtime sessions 27 Unified Services Router User Manual 2.5 Captive Portal DSR-250/250N does not have had their login credentials approved for internet access.
Product Manual
Page 47
... LAN interface are configured to be assigned IP addresses from the computers on the LAN and DMZ to the WAN and vice versa, if they do not get filtered by their externally-known domain name. All DSR features (such as ―NAT loopback‖ since LAN generated traffic is a technique which allows...
... LAN interface are configured to be assigned IP addresses from the computers on the LAN and DMZ to the WAN and vice versa, if they do not get filtered by their externally-known domain name. All DSR features (such as ―NAT loopback‖ since LAN generated traffic is a technique which allows...
Product Manual
Page 50
... IPv4 networks only, and identifies the subnet that have been added manually by this static route Interface: The physical network interface (WAN1, WAN2, WAN3, DMZ or LAN), through which this route is accessible. Gateway: IP address of the gateway through which the destination host or network can be added...
... IPv4 networks only, and identifies the subnet that have been added manually by this static route Interface: The physical network interface (WAN1, WAN2, WAN3, DMZ or LAN), through which this route is accessible. Gateway: IP address of the gateway through which the destination host or network can be added...
Product Manual
Page 51
... are a few key elements of WAN 3 configuration. Reconnect Mode: Select one of minutes in to be configured as a secondary WAN Ethernet port or a dedicated DMZ port. Setup > Internet Settings > WAN3 Setup WAN3 configuration for a specified number of the following options o Always On: The connection is available only on . Enter the...
... are a few key elements of WAN 3 configuration. Reconnect Mode: Select one of minutes in to be configured as a secondary WAN Ethernet port or a dedicated DMZ port. Setup > Internet Settings > WAN3 Setup WAN3 configuration for a specified number of the following options o Always On: The connection is available only on . Enter the...
Product Manual
Page 52
..., PAP or CHAP Authentication Protocols to connect to the previous settings. 50 If you configure your ISP assigned a static DNS IP address for the gateway. o DMZ: If this option is selected, you need to configure the...
..., PAP or CHAP Authentication Protocols to connect to the previous settings. 50 If you configure your ISP assigned a static DNS IP address for the gateway. o DMZ: If this option is selected, you need to configure the...
Product Manual
Page 67
...61623; Port triggers that your network from the LAN or DMZ. This is done by specifying the ―From Zone‖ (LAN/WAN/DMZ) and ―To Zone‖ (LAN/WAN/DMZ) Schedules as defined by the WAN or public DMZ network. 5.1 Firewall Rules Advanced > Firewall Settings > Firewall... Rules Inbound (WAN to LAN/DMZ) rules restrict access to traffic entering your address ...
...61623; Port triggers that your network from the LAN or DMZ. This is done by specifying the ―From Zone‖ (LAN/WAN/DMZ) and ―To Zone‖ (LAN/WAN/DMZ) Schedules as defined by the WAN or public DMZ network. 5.1 Firewall Rules Advanced > Firewall Settings > Firewall... Rules Inbound (WAN to LAN/DMZ) rules restrict access to traffic entering your address ...
Product Manual
Page 68
...section on the LAN from accessing internet services by creating an outbound firewall rule for each service. The default outbound rule is allow access from DMZ to insecure WAN. When the default outbound policy is to allow always, you to define days of the week and the time of Available Firewall...Firewall rules can be used. On other hand the default outbound rule is to deny access from the secure zone (LAN) to either the public DMZ or insecure WAN. You can change this schedule can be selected in the firewall rule configuration page. All schedules will follow the time ...
...section on the LAN from accessing internet services by creating an outbound firewall rule for each service. The default outbound rule is allow access from DMZ to insecure WAN. When the default outbound policy is to allow always, you to define days of the week and the time of Available Firewall...Firewall rules can be used. On other hand the default outbound rule is to deny access from the secure zone (LAN) to either the public DMZ or insecure WAN. You can change this schedule can be selected in the firewall rule configuration page. All schedules will follow the time ...
Product Manual
Page 69
...next to the rule and click Edit to a new rule's configuration page. Once created, the new rule is the WAN, the to be the public DMZ or insecure WAN. 5. If the From Zone is automatically added to a firewall rule 5.3 Configuring Firewall Rules Advanced > Firewall Settings > Firewall Rules All...Services Router User Manual Figure 38: List of Available Schedules to bind to the original table. 3. For an inbound rule WAN should be the public DMZ or secure LAN. Similarly if the From Zone is enabled (active) or not, and gives a summary of Available Firewall Rules table. 2. To ...
...next to the rule and click Edit to a new rule's configuration page. Once created, the new rule is the WAN, the to be the public DMZ or insecure WAN. 5. If the From Zone is automatically added to a firewall rule 5.3 Configuring Firewall Rules Advanced > Firewall Settings > Firewall Rules All...Services Router User Manual Figure 38: List of Available Schedules to bind to the original table. 3. For an inbound rule WAN should be the public DMZ or secure LAN. Similarly if the From Zone is enabled (active) or not, and gives a summary of Available Firewall Rules table. 2. To ...
Product Manual
Page 70
...: Outbound rules (where To Zone = insecure WAN only) can have the traffic marked with a QoS priority tag. Destination NAT is available when the To Zone = DMZ or secure LAN. With an inbound allow the selected service traffic from the WAN. Unified Services Router User Manual Service: ANY means all...
...: Outbound rules (where To Zone = insecure WAN only) can have the traffic marked with a QoS priority tag. Destination NAT is available when the To Zone = DMZ or secure LAN. With an inbound allow the selected service traffic from the WAN. Unified Services Router User Manual Service: ANY means all...
Product Manual
Page 71
...To reorder rules, click the checkbox next to the top of firewall rules. In this way the LAN/DMZ server can use Source NAT (SNAT) in order to map (bind) all LAN/DMZ traffic matching the rule parameters to a specific WAN interface or external IP address (usually provided by its ...aliased public IP address. 7. Unified Services Router User Manual External IP address: The rule can be assigned to servers on the LAN or DMZ.
...To reorder rules, click the checkbox next to the top of firewall rules. In this way the LAN/DMZ server can use Source NAT (SNAT) in order to map (bind) all LAN/DMZ traffic matching the rule parameters to a specific WAN interface or external IP address (usually provided by its ...aliased public IP address. 7. Unified Services Router User Manual External IP address: The rule can be assigned to servers on the LAN or DMZ.
Product Manual
Page 72
Unified Services Router User Manual Figure 39: Example where an outbound SNAT rule is used to map an external IP address (209.156.200.225) to a private DMZ IP address (10.30.30.30) 70
Unified Services Router User Manual Figure 39: Example where an outbound SNAT rule is used to map an external IP address (209.156.200.225) to a private DMZ IP address (10.30.30.30) 70
Product Manual
Page 74
...to be initiated from a restricted range of outside IP addresses Situation: You want to allow incoming videoconferencing to the IP address of your local DMZ network. Solution: Create an inbound rule as follows. Solution: Create an inbound rule as follows. Parameter From Zone To Zone Service Action ...Send to the DMZ Situation: You host a public web server on your web server at any time of external IP addresses. In the example, CUSeeMe (the ...
...to be initiated from a restricted range of outside IP addresses Situation: You want to allow incoming videoconferencing to the IP address of your local DMZ network. Solution: Create an inbound rule as follows. Solution: Create an inbound rule as follows. Parameter From Zone To Zone Service Action ...Send to the DMZ Situation: You host a public web server on your web server at any time of external IP addresses. In the example, CUSeeMe (the ...
Product Manual
Page 75
... that configures the firewall to Local Server (DNAT IP) 4 De:stination Users From B WlAN Users Loog c Value Insecure (WAN1/WAN2/WAN3) Public (DMZ) HTTP ALLOW always 192.168.12.222 ( web server local IP address) Single Address 10.1.0.52 Any Never Example 4: Block traffic by schedule if generated...for your use the additional public IP addresses to map to servers on your LAN. subnet 255.255.255.0 Web server host in the DMZ, IP address: 192.168.12.222 Access to Web server: (simulated) public IP address 10.1.0.52 PaErameter Frxom Zone a TomZone Seprvice...
... that configures the firewall to Local Server (DNAT IP) 4 De:stination Users From B WlAN Users Loog c Value Insecure (WAN1/WAN2/WAN3) Public (DMZ) HTTP ALLOW always 192.168.12.222 ( web server local IP address) Single Address 10.1.0.52 Any Never Example 4: Block traffic by schedule if generated...for your use the additional public IP addresses to map to servers on your LAN. subnet 255.255.255.0 Web server host in the DMZ, IP address: 192.168.12.222 Access to Web server: (simulated) public IP address 10.1.0.52 PaErameter Frxom Zone a TomZone Seprvice...
Product Manual
Page 81
.... This is an available option when configuring firewall rules. This feature allows devices on the LAN or DMZ to request one of traffic. Port triggering waits for an outbound request from the LAN/DMZ on one or more flexible than static port forwarding that specified type of the defined outgoing ports, and...
.... This is an available option when configuring firewall rules. This feature allows devices on the LAN or DMZ to request one of traffic. Port triggering waits for an outbound request from the LAN/DMZ on one or more flexible than static port forwarding that specified type of the defined outgoing ports, and...