Huawei Aolynk DR814, Aolynk DR811 user manual Security Policy

Page 33

User Manual

 

Aolynk DR811/DR814 ADSL2+Broadband Router

4 Web-based Management

Where item0 is the virtual interface added at the last step.

Then, enter the Port Filters page of external-dmz (refer to 4.9 Security Policy), configure to ensure that users under the external interface can access the Internet services the DMZ zone specifies such as http, ftp, telnet, and so on. Meanwhile, configure port filtering policies for external-internal to disable users under the external interface from accessing host services under the internal interface.

Finally, configure to allow DMZ hosts to access DMZ zone. Make sure the IP address of the DMZ host is in the same segment as that of the above configured virtual interface (for example, configure the IP address as 172.16.1.100, the mask as 255.255.0.0), enable the corresponding Internet service, and then connect the host to the LAN port of the router, and configure the corresponding virtual server. As such, DMZ is completely and securely configured.

4.9 Security Policy

A policy is the collective term for the rules that apply to incoming and outgoing traffic between two interface types. Firewall must be enabled before you can create policies.

Click Security in the Main menu and choose the Policy tab in the Main Frame to open the Security Policy Configuration page.

Figure 4-20Security policy configuration

This page allows you to:

Edit a security policy present in the Current Security Policies list.

To edit an existing security policy, click the label to open the web page Port

Filter to configure the port filter rules, and/or click the label to open the web page Host Validators to configure the host validator rules.

30

Image 33
Contents Huawei Aolynk DR811/DR814 ADSL2+Broadband Router All Rights Reserved Trademarks Table of Contents IP Addresses, Network Masks, and Subnets Introductions Product OverviewModel Difference Appearance Front ViewStatus Description Features Interface Quantity Connector DescriptionRear View Interface Quantity Parts CheckConnecting Your Device OverviewSteps Finish Getting Started with the Web Pages Accessing the Web PagesLAN Settings button Web Page Layout Button Function Commonly Used ButtonsBehavior Testing Your SetupDefault Device Settings Option Default Setting Explanation/InstructionEnabled with Web-based Management Quick SetupOpen the WAN Connection Configuration WAN SettingWAN setting DNS Relay DNS relay LAN SettingLAN setting Dhcp Route Aolynk DR811/DR814 ADSL2+Broadband Router 12Create routes Security Interface Labeled Enabled/Disabled Aolynk DR811/DR814 ADSL2+Broadband Router DMZ Configuration 19Add a security interface Security Policy Definition Trigger24 Add trigger Aolynk DR811/DR814 ADSL2+Broadband Router 25Delete trigger Click the button to delete this trigger 11 IDSSntp 26 IDS settingZipb 27 Sntp setting28 Zipb setting Remote Access Password32 Restart Restart RouterConfiguration Backup/Restore Aolynk DR811/DR814 ADSL2+Broadband Router 37Restore configuration UpgradeStatus 39 Status 20 Log 41 Log PVC ScanSave Configure Configuring Ethernet PCs Configuring Your ComputersBefore You Begin Windows XP PCsWindows 2000 PCs Windows 95, 98 PCs Windows Me PCsWindows NT 4.0 Workstations Assigning Static Internet Information to Your PCs Configuring a PC Connected by USB Port Connecting a Computer to the USB Port by a USB cableInstalling the USB Driver 2Found new hardware New hardware installed and ready to use Configuring IP Properties on PC Connected by USB Port IP Addresses, Network Masks, and Subnets IP AddressesStructure of an IP Address Subnet Masks Network ClassesClass Field1 Field2 Field3 Field4 Aolynk DR811/DR814 ADSL2+Broadband Router Configuration Overview Service ConfigurationConnectionPureBridge PureBridgeIPoA DHCP/StaticIPPPPoE PPPoAPPPoE Troubleshooting Troubleshooting SuggestionsProblem Troubleshooting Suggestion To see if the Adsl line is connected correctly Diagnosing Problem Using IP Utilities PingPing Nslookup NslookupAppendix Glossary Domain Dhcp serverName DownloadHub HostInternet IntranetPacket Network Network maskPort Protocol Remote RJ-11Routing RJ-45Subnet Subnet maskWeb browser WebWeb site