Firewall; Basics For Firewall - Draytek Vigor2950 Series User Manual

Dual-wan ssl vpn appliance
Hide thumbs Also See for Vigor2950 Series:
Table of Contents

Advertisement

Protocol
WAN Interface
WAN IP
Private IP
Subnet Mask
3
.
4
F
i
r
e
w
a
l
l
3
.
4
F
i
r
e
w
a
l
l
3
.
4
.
1
B
a
s
i
c
s
3
.
4
.
1
B
a
s
i
c
s
While the broadband users demand more bandwidth for multimedia, interactive applications,
or distance learning, security has been always the most concerned. The firewall of the Vigor
router helps to protect your local network against attack from unauthorized outsiders. It also
restricts users in the local network from accessing the Internet. Furthermore, it can filter out
specific packets that trigger the router to build an unwanted outgoing connection.
F
i
r
e
w
a
F
i
r
e
w
a
The users on the LAN are provided with secured protection by the following firewall
facilities:
User-configurable IP filter (Call Filter/ Data Filter).
Stateful Packet Inspection (SPI): tracks packets and denies unsolicited incoming data
Selectable Denial of Service (DoS) /Distributed DoS (DDoS) attacks protection
URL Content Filter
I
P
F
i
l
t
e
I
P
F
i
l
t
Depending on whether there is an existing Internet connection, or in other words "the WAN
link status is up or down", the IP filter architecture categorizes traffic into two: Call Filter
and Data Filter.
Call Filter - When there is no existing Internet connection, Call Filter is applied to all
traffic, all of which should be outgoing. It will check packets according to the filter
rules. If legal, the packet will pass. Then the router shall "initiate a call" to build the
Internet connection and send the packet to Internet.
Data Filter - When there is an existing Internet connection, Data Filter is applied to
incoming and outgoing traffic. It will check packets according to the filter rules. If legal,
the packet will pass the router.
Vigor2950 Series User's Guide
Specify the transport layer protocol. It could be TCP, UDP, or
ALL for selection.
Specify the WAN interface that will be used for this entry.
Select an IP address (the selections provided here are set in IP
Alias List of Network >>WAN interface). Local host can use this
IP to connect to Internet.
If you want to choose any on of the Public IP settings, you must
specify some IP addresses in the IP Alias List of the Static/DHCP
Configuration page first. If you did not type in any IP address in
the IP Alias List, the Public IP setting will be empty in this field.
When you click Apply, a message will appear to inform you.
Assign an IP address (e.g., 192.168.1.10) or a subnet to be
compared with the Public IP address for incoming packets.
Select a value of subnet mask for private IP address.
f
o
r
F
i
r
e
w
a
l
l
f
o
r
F
i
r
e
w
a
l
l
l
l
F
a
c
i
l
i
t
i
e
s
l
l
F
a
c
i
l
i
t
i
e
s
r
s
e
r
s
51

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vigor2950gVigor2950iVigor2950gi

Table of Contents