D-Link DI-304M manual An Overview of the Firewall

Page 67

DI-304/DI-304M ISDN Remote Router

from accessing the Internet. Additionally, it can filter out specific packets to trigger the router to place an outgoing connection.

An Overview of the Firewall

The IP Filter/Firewall includes two types of filter: Call Filter and Data Filter. The former is designed to block or allow IP packets that will trigger the router to establish an outgoing connection. The latter is designed to block or allow which kind of IP packets are allowed to pass through the router when the WAN connection has been established. It works like this: when an outgoing packet is routed to the WAN, the IP Filter will decide if the packet should be forwarded to the Call Filter or Data Filter. If the WAN connection has not been established, the packet will enter the Call Filter. If the packet is not allowed to trigger router dialing, it will be dropped. Otherwise, it will initiate a call to establish the WAN connection.

If the WAN connection of the router has been established, the packet will pass through the Data Filter. Packets match the block rule will be dropped and the contrary will be sent to the WAN interface. Alternatively, if an incoming packet enters from the WAN interface, it will pass through the Data Filter directly. If the packets match the block rule, it will be dropped. Otherwise, it will be sent to the internal LAN. The filter architecture is shown as below.

The Following sections will explain more about IP Filter/Firewall Setup using Web Configurator. The Filter has 12 filter sets with 7 filter rules for each set. There are a total of 84 filter rules for the IP Filter/Firewall Setup. By default, the Call Filter rules are defined in filter set 1 and the Data Filter rules are defined in filter set 2.

59

Image 67
Contents DI-304/DI-304M Isdn Router User’s Guide CE Mark Warning FCC WarningHardware Link Offices for Registration and Warranty ServiceSoftware Page Wichtige Sicherheitshinweise Table of Contents Virtual TA Application Appendix C IP Protocol and Port Numbers Introduction Product FeaturesStandard Phone Jacks Just for DI-304M Ease of InstallationBuilt-in Switch Isdn Basic Rate Interface BRINetworking Compatibility Dhcp Support Dynamic Host Configuration ProtocolFirmware Upgrade Tftp Server Remote Access Server RASApplications for your DI-304/DI-304M Remote Dial-In Server What This Manual CoversNetwork Address Translation NAT LAN-to-LAN Enterprise ConnectionsOther Resources What This Manual Doesn’t CoverPacking List Additional Installation Requirements Before You Start Installation & SetupOrdering Your Isdn Line DI-304/DI-304M Front Panel Factory Default Settings Default IP Network SettingsDhcp Server Enabled Web ConfiguratorDI-304 DI-304M DI-304/DI-304M Rear Panel Connecting the Power Adapter Hardware InstallationConnecting to the Ethernet T-Interface Model Connecting to an Isdn BRI LineConnecting to a DSL/Cable Modem Setting Up a Management PCClick the Add button. The Select Network Component Checking the Network IP ConfigurationConfiguring the TCP/IP Protocol Checking TCP/IP Settings DI-304/DI-304M Isdn Remote Router Installing the Router Tools Using the Smart Start WizardDI-304/DI-304M Isdn Remote Router DI-304/DI-304M Isdn Remote Router DI-304/DI-304M Isdn Remote Router Connecting to the Web Configurator via a Web Browser Using the Web ConfiguratorBasic Setup Setup First Overview of the Web ConfiguratorQuick Setup System Management Advanced SetupDI-304/DI-304M Isdn Remote Router Changing the Administrator Password Basic Configuration and Internet AccessConfiguring Ethernet TCP/IP Address and Dhcp Server For IP Routing Usage Default Disable Router IP Network Configuration For NAT UsageDhcp Server Configuration Configuring the Isdn Interface Isdn Dial-up Internet Access Internet Access SetupDialing to a Single ISP PPP/MP Setup ISP Access SetupDialing to Dual ISPs IP Address Assignment Method IpcpDSL/Cable Modem Internet Access SetupIP Address Assignment Method Icpc PPPoE Setup Using PPPoE with a DSL ModemIsdn Dial Backup Setup Pptp Setup Using Pptp with a DSL ModemUsing a Static IP with a DSL/Cable Modem Configuring Isdn Dial Backup Access ControlIsdn Dial Backup Setup There are three options DI-304/DI-304M Isdn Remote Router Remote Dial-In Access Remote AccessIP Address Assignment for Dial-In Users Creating an Access Account for a Dial-in UserCallback Function LAN-to-LAN Access Activating the Remote Dial-In Capability Dial-In Service Enable Start IP Address Branch OfficeHead Office Creating a LAN-to-LAN Dialer Profile Dial-In Service Enable Start IP AddressDI-304/DI-304M Isdn Remote Router Dial-Out Settings Common SettingsDial-In Settings TCP/IP Network Settings Branch Office DI-304/DI-304M Isdn Remote Router Enabling the Remote Activation Function Advanced SetupBasic Setup Call Control SetupDial Retry and Dial Delay Interval PPP/MP Dial-Out SetupBandwidth On Demand BOD Setup Call Schedule Setup NAT Setup DMZ Host Setup Open Ports Setup Well-known Port Number List IP Filter/Firewall Setup Static Route SetupAn Overview of the Firewall General Setup DI-304/DI-304M Isdn Remote Router DI-304/DI-304M Isdn Remote Router Editing the Filter Rules Check to enable the Filter Rule Enable the filter ruleDI-304/DI-304M Isdn Remote Router Restricting Unauthorized Internet Services Virtual TA Application Quick Setup Virtual TA Remote Capi SetupVirtual TA Concepts Configuring a Virtual TA Client/Server Installing a Virtual TA ClientVirtual TA User Profiles Virtual TA ServerCreating a User Profile System Management Configuring the MSN NumberIsdn Status Online StatusLAN Status Time SetupWAN Status Management Setup Snmp Setup Management Port SetupISDN/PPPoE/PPTP Diagnostics Diagnostic ToolsTriggered Dial-out Packet Header Broadband AccessView Routing Table View Dhcp Assigned IP Addresses View ARP Cache TableView NAT Active Sessions Table View NAT Port Redirection Running TableSysLog Setting Reboot System Firmware Upgrade DI-304/DI-304M Isdn Remote Router Using the Telnet Terminal Commands Appendix a Troubleshooting and FAQsViewing Call Logs Command HelpRecall Commands Quitting the Telnet TerminalViewing WAN Logs Viewing Isdn LogsDetailed Isdn log example Viewing PPP LogsWhy cant I connect to the Web Configurator? FAQsWhat is the default IP address of the router? Why does the router dial out very often?IP Addresses Appendix B Basic IP ConceptsIP Network Classes Subnet Mask IP Protocol Numbers Appendix C IP Protocol and Port NumbersIP Port Numbers General Appendix D Technical SpecificationsCTR-3 PPP/MP IndexOffices Norway Link Norway Registration Card