EnGenius Technologies ESR-9710 user manual Firewall

Page 58

ESR-9710 Wireless N Gigabit Router

Version 1.0

6.3.10Firewall

ƒThe device provides a tight firewall by virtue of the way NAT works. Unless you configure the router to the contrary, the NAT does not respond to unsolicited incoming requests on any port, thereby making your LAN invisible to Internet cyber attacks. However, some network applications cannot run with a tight firewall. Those applications need to selectively open ports in the firewall to function correctly. The options on this page control several ways of opening the firewall to address the needs of specific types of applications.

ƒEnable SPI: Place a check in this box to enable SPI. SPI ("stateful packet inspection" also known as "dynamic packet filtering") helps to prevent cyberattacks by tracking more state per session. It validates that the traffic passing through that session conforms to the protocol. When the protocol is TCP, SPI checks that packet sequence numbers are within the valid range for the session, discarding those packets that do not have valid sequence numbers. Whether SPI is enabled or not, the router always tracks TCP connection states and ensures that each TCP packet's flags are valid for the current state.

ƒTCP / UDP NAT Endpoint Filtering options control how the router's NAT manages incoming connection requests to ports that are already being used. Select one of the radio buttons.

o End Point Independent Once a LAN-side application has created a connection through a specific port, the NAT will forward any incoming connection requests with the same port to the LAN-side application regardless of their origin. This is the least restrictive option, giving the best connectivity and allowing some applications (P2P applications in particular) to behave almost as if they are directly connected to the Internet.

o Address Restricted The NAT forwards incoming connection requests to a LAN-side host only when they come from the same IP address with which a connection was established. This allows the remote application to send data back through a port different from the one used when the outgoing session was created.

o Port And Address Restricted The NAT does not forward any incoming connection requests with the same port address as an already establish connection.

58

Image 58
Contents Wireless N Gigabit Router User’s Manual Table of Contents Appendix a Glossary Appendix B Specifications Appendix C FCC Interference Statement Appendix D IndexRevision History Features & Benefits IntroductionPackage Contents Safety GuidelinesWlan LED Wireless Soho Router DescriptionWAN LED System Requirements ApplicationsNetwork Configuration Ad-hoc peer-to-peer ModeIP Address Configuration Hardware InstallationUnderstanding the Hardware PC IP address Internet Connection Wizard LoggingESR-9710 Wireless N Gigabit Router ESR-9710 Wireless N Gigabit Router Dhcp Connection Dynamic IP Address PPPoE Point-to-Point Protocol over Ethernet Pptp Point-to-Point Tunneling Protocol 4 L2TP Layer 2 Tunneling Protocol Static IP Address Configuration ESR-9710 Wireless N Gigabit Router BigPond Wi-Fi Protected Setup Wizard Add a Wireless DeviceUsing the PIN Using the Push Button Wireless Network Setup Wizard Wireless Network SetupAutomatic Network Setup Manual Network SetupESR-9710 Wireless N Gigabit Router Wireless Security Level Best WPA2 Wireless Security Level Better WPA Wireless Security Level Good WEP 64/128-bit Wireless Security Level None Security Disabled Advanced Web Configuration Bridge Mode WizardWirelessNetwork Settings BasicRouter Mode Wireless Settings Wireless Security Mode WEP Wired Equivalent PrivacyWPA Personal Wi-Fi Protected Access WPA Enterprise Wi-Fi Protected Access ESR-9710 Wireless N Gigabit Router WAN Settings Dhcp Connection Dynamic IP Address PPPoE Point-to-Point Protocol over Ethernet ESR-9710 Wireless N Gigabit Router Pptp Point-to-Point Tunneling Protocol 4.5 L2TP Layer 2 Tunneling Protocol Address ESR-9710 Wireless N Gigabit Router Advanced Wireless AdvancedVirtual Server Special Applications Port Forwarding StreamEngineESR-9710 Wireless N Gigabit Router ESR-9710 Wireless N Gigabit Router Access Control RoutingESR-9710 Wireless N Gigabit Router ESR-9710 Wireless N Gigabit Router Web Filter MAC Address FilterFirewall ESR-9710 Wireless N Gigabit Router ESR-9710 Wireless N Gigabit Router Inbound Filter Wish Wi-Fi Protected Setup Advanced Network UPNP, WAN Ping… ƒ Click on the Save Settings button to store these settings Time Zone Setting ToolsSave Configuration to a File SystemRestore the Configuration from a File Restore Settings to Default System RebootFirmware Upgrade System LogsDynamic DNS System CheckSchedules Status Wireless StatusLogs Status Statistics Wish Session Status Internet Session Status Adsl Appendix a GlossaryAscii Bootp CATDhcp DSL DMZDNS EAPHttp FTPGUI HttpsIKE IgmpIIS IPXLED L2TPLAN LPR/LPDNTP NATNIC OfdmPptp POP3PPP RadiusSnmp SIPSmtp SohoUDP TCP/IPTftp URLWEP WCNWDS WispAppendix B Specifications Hardware SummaryRouter and Gateway Management Environment & Physical Appendix C FCC Interference Statement Federal Communication Commission Interference StatementAppendix D Index CD-ROMSystem Reboot, 3, 69 System Requirements, 2