TRENDnet TW100-BRV324 manual Security Configuration, Rules Screen, Chapter, Overview

Page 60
Security Configuration

Chapter 7

7

Security Configuration

This Chapter explains the settings available via the security configuration section of the "Security" menu.

Overview

The following advanced configurations are provided.

Rules

Schedules

Log Setting

Services

Security

DMZ

E-Mail

Rules

For normal operation and LAN protection, it is not necessary to use this screen.

The Firewall will always block DoS (Denial of Service) attacks. A DoS attack does not attempt to steal data or damage your PCs, but overloads your Internet connection so you can not use it - the service is unavailable.

As well, you can use this screen to create Firewall rules to block or allow specific traffic. But incorrect configuration may cause serious problems.

This feature is for advanced administrators only!

Rules Screen

Click the Rules option on the Firewall menu to see a screen like the following example. This example contains two (2) rules for outgoing traffic.

Figure 35: Rules Screen

56

Image 60
Contents Page Page Table of Contents P/N 956YH10001 Copyright 2007. All Rights Reserved Document Version1.0Broadband VPN Gateway Features Internet Access FeaturesIntroduction ChapterLAN Features Configuration & ManagementPackage Contents Security FeaturesIPSec VPN Gateway Features Microsoft VPN Gateway SupportPhysical Details Front-mounted LEDsRear Panel Installation ProcedureRequirements The Power LED should be ON Installation5. Check the LEDs The WAN1 or WAN2 LED should be ONSetup OverviewThis Chapter provides Setup details of the Broadband VPN Gateway To Do thisConfiguration Program PreparationFigure 5 Password Dialog If you cant connectHome Screen Navigation & Data InputWAN Port Configuration WAN Port SettingsStatic IP Settings Data - WAN Port ScreenPPPoE Dial-up ButtonsPort Options Screen Data - Port Options ScreenPort Options Also called Network Adapter Address or Physical Address. This is aBind Service MTU SizePPPoE Connection Automatic Dial-upLAN Port Screen Data - LAN Port ScreenDHCP Using the Broadband VPN Gateway s DHCP ServerUsing another DHCP Server To Configure your PCs to use DHCPLoad/Backup Screen Data - Load/Backup ScreenAdministration Equilibrium Type has 2 optionsSetup PC Configuration TCP/IP Settings - OverviewWindows Clients Checking TCP/IP Settings - Windows 9x/ME Using DHCPUsing Specify an IP Address Figure 13 Gateway Tab Win 95/98 Figure 14 DNS Tab Win 95/98Checking TCP/IP Settings - Windows NT4.0 Figure 15 Windows NT4.0 - TCP/IPFigure 16 Windows NT4.0 - IP Address Obtain an IP address from a DHCP Server Specify an IP AddressFigure 17 - Windows NT4.0 - Add Gateway Figure 18 Windows NT4.0 - DNS Checking TCP/IP Settings - Windows Figure 19 Network Configuration Win1. Select Control Panel - Network and Dial-up Connection Figure 20 TCP/IP Properties WinUsing a fixed IP Address Use the following IP Address Checking TCP/IP Settings - Windows XP Figure 21 Network Configuration Windows XP1. Select Control Panel - Network Connection Figure 22 TCP/IP Properties Windows XP Checking TCP/IP Settings - Windows Vista PC Configuration Internet Access Accessing AOL1. Select Start Menu - Settings - Control Panel - Internet Options 2. Select Set up or change your Internet ConnectionMacintosh Clients Linux ClientsOther Unix Systems Fixed IP AddressOperation and Status OperationStatus Screen Figure 23 General Status Screen Operation and StatusWAN1/2 FirewallKernel SystemPort Status Data - Port Status ScreenPort Status Event Log Data - Event Log ScreenEvent Log URL Log Data - URL LogInternet System Log Data - System Log ScreenSystem Log Internet Features The following advanced features are provided Address List PC DatabaseURL Filter Dynamic DNS Static Routing QoS Address List Data - Address List ScreenAddress List PC Database PC Database ScreenData - PC Database Screen dress, IP Address and CertifyURL Filter Data - URL Filter ScreenFilter Strings To add an entry to the list, enter it here, and click the Add button Dynamic DNS Dynamic DNS ScreenData - Dynamic DNS Screen Web Site ButtonStatic Routing OverviewStatic Routing Screen Open Routing and Remote AccessData - Static Routing Screen Static RoutingConfiguring Other Routers on your LAN Local RouterOther Routers on the Local LAN Static Routing - Example For Router As Default RouteFor Router Bs Default Route For the Broadband VPN Gateway s Routing Table192.168.1.80 Broadband VPN Gateway s local routerData - QoS Screen Based on QoS rules set below Security Configuration RulesRules Screen Data - Rules Screen Outbound/Inbound ConnectionDefine Firewall Rule Inbound/Outbound Data - Define Firewall Rule ScreenLog Setting Dest IPAdvanced Rule Port Transfer ToSchedules Schedules ScreenFirewall -- Log Data - Log ScreenTime Zone Second Server Services Data - Services ScreenAvailable Services Add New Serviceif not required Security Data - Security ScreenMAX 3D Engine Options Maximum Con Figure 41 Multi-DMZ E-Mail Data - E-Mail ScreenE-Mail Alert E-Mail LogSelect the desired option for sending the log by E-mail VPN IPSec IPSecPolicies VPN Configuration VPN Endpointaddress Traffic SelectorCommon VPN Situations VPN Pass-throughClient PC to VPN Gateway Connecting 2 LANs via VPN Figure 45 Connecting 2 VPN GatewaysVPN Configuration Policies ScreenVPN List OperationsEnable/Disable CopyCheck Log Adding a New Policy Figure 47 VPN Wizard - Start Screen General Settings Enable PolicyAllow NetBIOS Authentication and EncryptionAuthentication Algorithm ESP AuthenticationESP Encryption Manual Key Encryptiontion is enabled ESP SPIThis is required if either ESP Encryption or ESP Authentica IKE Internet Key ExchangeAuthentication EncryptionExchange Mode IKE SA AggressiveExample 1 Connecting 2 Broadband VPN Gateways VPN ExamplesSetting LAN A GateIPSec SA Parameters Example 2 Windows 2000/XP Client to LAN Broadband VPN Gateway ConfigurationValue Windows Client Configuration Figure 50 Windows 2000/XP - Local Security SettingsDeselect Activate the default response rule. Click Next Figure 51 Windows 2000/XP - Policy Properties Figure 52 IP Filter ListFigure 53 Filter Properties Addressing 8. Enter the Source IP address and the Destination IP addressFigure 54 New Rule Properties IP Filter List Figure 55 New Rule Properties Filter Action Figure 56 Require Security Properties12. Select Negotiate security this selects IKE, then click Add VPN Setting Windows SettingFigure 57 Modify Security Method Figure 58 Require Security PropertiesFigure 59 Tunnel Setting Figure 60 Authentication MethodFigure 61 Windows 2000/XP Client to Broadband VPN Gateway Figure 62 Windows 2000/XP Client to Broadband VPN GatewayFigure 63 Filter Properties Addressing 22. Click OK to save your changes, then CloseFigure 64 Filter List Figure 65 Filter Action Figure 66 Security MethodsFigure 68 Tunnel Setting Figure 67 Modify Security MethodFigure 69 Authentication Method Figure 70 DUT to Win2K PropertiesFigure 72 Key Exchange Settings Figure 71 Properties - General Tab32. Click the Advanced button to see the screen below 33. Click the Methods button to see the screen belowExample 3 Windows 2000 Server to VPN Gateway Figure 74 IKE Security AlgorithmsFigure 75 Windows 2000/XP Client to Broadband VPN Gateway Figure 76 Broadband VPN Gateway to Windows 2000 ServerRemote IP addresses For a single client, this is the same as the Gateway addressSubnet address 11.5.0.0 Address range used on the remote LAN Windows 2000 Server Configuration Figure 77 Windows 2000 Server - AddressingCertificates Trusted CertificatesRequesting a Trusted Certificate Trusted CertificatesPrivate Certificate Data - Private Certificate ScreenPrivate Certificate Private Certificate RequestsRequesting a Private Certificate Upload ButtonNew Request ButtonSelect the desired option. RSA is recommended To add a New CRL VPN Status Data - VPN Status ScreenVPN Status Server Setup Microsoft VPNUser PPTP ServiceData - VPN Adapter Screen Data - User Screen Existing UsersProperties ButtonStatus Log Screen Service LogData - Status Log Screen Status LogWindows Client Setup Windows 98/ME1. Click Start - Settings - Dial-up Networking 2. Select Make New Connection2. Select Start - Settings - Dial-up Networking To establish a connectionWindows ME VPN Dialing Properties Windows Figure 92 Windows 2000 Network ConnectionFigure 93 Windows 2000 Public Network Figure 94 Windows 2000 VPN Host Figure 95 Windows 2000 Connection AvailabilityFigure 96 Windows 2000 Finish Wizard Windows XP Figure 97 Windows XP Network Connection TypeFigure 98 Windows XP Network Connection Figure 99 Windows XP Connection Name Figure 100 Windows XP Public NetworkFigure 101 Windows XP VPN Server Figure 102 Windows XP Connection Availability Other Features & Settings Diagnostics Data - Diagnostics ScreenPing DNS LookupSearch Button Password Screen PasswordData - Account Management Screen Web Management SettingsData - Web Management Screen To connect from a remote PC via the Internet HTTPS//123.123.123.1238080Firmware Upgrade Data - Firmware Upgrade ScreenTo perform the Firmware Upgrade Firmware UpgradeBackup/Restore Data - Backup/Restore ScreenDefault Configu- ration This will delete ALL of the existing settingsTroubleshooting General ProblemsInternet Access Appendix AIt is a security risk, since the firewall is disabled Appendix B Specifications Broadband VPN GatewayFCC Statement FCC Radiation Exposure StatementCE Marking Warning CE StandardsAppendix B - Specifications Broadband VPN Gateway User Guide
Related manuals
Manual 8 pages 5.73 Kb

TW100-BRV324 specifications

The TRENDnet TW100-BRV324 is a versatile broadband router designed to provide small to medium-sized businesses with reliable networking capabilities. One of its key features is its built-in firewall security, which ensures robust protection against unauthorized access and threats from the internet. This appliance uses Stateful Packet Inspection (SPI), providing a comprehensive barrier against a variety of cyber threats.

Equipped with a DHCP server, the TW100-BRV324 simplifies IP address assignment, allowing administrators to manage network resources efficiently. The device supports both DHCP and static IP configurations, making it flexible for various network setups. Additionally, it offers VPN pass-through capabilities, allowing secure remote access for users needing to connect to the corporate network from outside.

The TW100-BRV324 is noted for its impressive NAT (Network Address Translation) capabilities, which enable multiple devices on a local network to access the internet through a single public IP address. This feature is particularly beneficial in saving costs related to IP addresses while enhancing network management. Furthermore, it boasts an integrated 4-port switch, facilitating wired connections for several devices in a local area network (LAN).

In terms of connectivity, the router supports 10/100 Mbps Ethernet, providing sufficient bandwidth for most small business applications. The device is also easy to set up, thanks to its user-friendly web-based interface, which guides users through the configuration process. This simplicity makes it suitable for individuals with varying levels of networking expertise.

The TW100-BRV324 supports multiple connection types, including DSL and cable internet, ensuring compatibility with various ISPs. Additionally, it embeds Quality of Service (QoS) features, allowing network administrators to prioritize traffic. This is crucial for ensuring that bandwidth-intensive applications, such as video conferencing and VoIP, receive the necessary resources for optimal performance.

In summary, the TRENDnet TW100-BRV324 is a robust and feature-rich router well-suited for small to medium-sized businesses. With its combination of security features, flexible configurations, and user-friendly management tools, it offers a powerful solution for those seeking reliable network performance without the need for extensive technical knowledge.