Manuals
/
D-Link
/
Computer Equipment
/
Network Card
D-Link
DFL-500
user manual
118
Models:
DFL-500
1
118
122
122
Download
122 pages
7.35 Kb
115
116
117
118
119
120
121
122
Install
Default policy
Login
Administration
Connecting to your networks
Warranty
Firewall configuration
Blocking access to URLs
Using the setup wizard
Setting the date and time
Page 118
Image 118
DFL-500
User Manual
118
Page 117
Page 119
Page 118
Image 118
Page 117
Page 119
Contents
Link DFL-500
Regulatory Compliance
Table of Contents
Firewall configuration
IPSec VPNs
Logging and reporting
Page
Transparent mode
NAT/Route mode and Transparent mode
NAT/Route mode
Introduction
For more information
Customer service and technical support
DFL-500 QuickStart Guide DFL-500 CLI Reference Guide
Getting started
Package contents
Mounting
Powering on
Initial configuration
Connecting to the web-based manager
DFL-500 login
Connecting to the command line interface CLI
Bits per second
Data bits Parity
Next steps
Stop bits Flow control
Preparing to configure NAT/Route mode
NAT/Route mode installation
NAT/Route mode settings
Starting the setup wizard
Using the setup wizard
Using the command line interface
Reconnecting to the web-based manager
Connecting to your networks
Set system route number 1 gw1
Setting the date and time
Configuring your internal network
Completing the configuration
DFL-500 NPG network connections
Changing to Transparent mode
Transparent mode installation
Preparing to configure Transparent mode
Transparent mode settings Administrator Password
Configuring the Transparent mode management IP address
Set system management ip 10.10.10.2
Connecting to your network
Setting the date and time
Configure the Transparent mode default gateway
DFL-500 network connections
Firewall configuration
Default policy
Changing to NAT/Route mode
Adding NAT/Route mode policies
Go to Firewall Policy
Dynamic IP Pool Fixed Port
Source Destination Schedule Service Action
Authentication
VPN Tunnel
Content filtering
Web filter
Source Destination Schedule Service
Adding Transparent mode policies
Adding a NAT/Route Int -Ext policy
Log Traffic Authentication Web filter
Adding a Transparent mode Int -Ext policy
Configuring policy lists
Policy matching in detail
Changing the order of policies in a policy list
Addresses
Enabling and disabling policies
Go to Firewall Address
Adding addresses
Deleting addresses
Adding a firewall address
Go to Firewall Address Group
Services
Organizing addresses into address groups
Adding an internal address group
Grouping services
Predefined services
Providing access to custom services
Go to Firewall Service Custom
Creating one-time schedules
Adding a service group
Schedules
Go to Firewall Schedule One-time
Adding a schedule to a policy
Virtual IPs
Creating recurring schedules
Go to Firewall Schedule Recurring
Go to Firewall Virtual IP
Adding static NAT virtual IPs
Static NAT Port Forwarding
Using port forwarding virtual IPs
Adding a static NAT virtual IP
Adding a Port Forwarding virtual IP
Adding policies with virtual IPs
Go to Firewall Policy Ext Int
Source
Authentication Log Traffic Web filter
Destination Schedule Service Action
IP pools
Go to Firewall IP/MAC Binding Static IP/MAC
Go to Firewall IP/MAC Binding Setting
IP/MAC binding
Adding an IP Pool
Configuring IP/MAC binding for packets going to the firewall
Adding IP/MAC addresses
Enabling IP/MAC binding
IP/MAC settings
Viewing the dynamic IP/MAC list
Go to Firewall IP/MAC Binding Dynamic IP/MAC
Adding user names and configuring authentication
Users and authentication
Setting authentication time out
Adding user names and configuring authentication
Deleting user names from the internal database
Disable
Adding a user name
Adding Radius servers
Configuring Radius support
Example Radius configuration
Deleting Radius servers
Configuring user groups
Adding user groups
Deleting user groups
Adding a user group
IPSec VPNs
Interoperability with IPSec VPN products
Configuring AutoIKE key IPSec VPN
See Adding a remote gateway
Configuring dialup VPN
Configuring manual key IPSec VPN
Configuring a VPN concentrator for hub and spoke VPN
Configuring the VPN concentrator
Configuring the member VPNs
Configuring IPSec redundancy
Go to VPN Ipsec Remote Gateway
Adding a remote gateway
Local ID
Nat-traversal Keepalive Frequency
About dialup VPN authentication
Adding a remote gateway Dialup User selected
Main mode with no user group selected
Local ID Empty
About DH groups
About the P1 proposal
Key
About NAT traversal
Adding an AutoIKE key VPN tunnel
Go to VPN Ipsec AutoIKE Key
Autokey Keep Alive Concentrator
About the P2 proposal
About replay detection
Adding an AutoIKE key VPN tunnel
About perfect forward secrecy PFS
Adding a manual key VPN tunnel
Go to VPN Ipsec Manual Key
Adding a VPN concentrator
Adding a manual key VPN tunnel
Adding an encrypt policy
Adding a VPN concentrator
Adding an encrypt policy
Go to Firewall Policy Int-Ext
VPN Tunnel Allow inbound
Viewing VPN tunnel status
Allow outbound Inbound
Viewing dialup VPN connection status
Testing a VPN
AutoIKE key tunnel status
Page
Pptp VPN configuration
Pptp and L2TP VPNs
Go to VPN Pptp Pptp Range
Configuring the DFL-500 NPG as a Pptp gateway
Pptp VPN between a Windows client and the DFL-500 NPG
Example Pptp Range configuration
Source Destination Service Action
Go to VPN L2TP L2TP Range
L2TP VPN configuration
Configuring the DFL-500 NPG as an L2TP gateway
L2TP VPN between a Windows client and the DFL-500 NPG
Sample L2TP address range configuration
Blocking web pages that contain unwanted content
Web content filtering
Enabling web content Filtering
Configuring content filtering
Clearing the banned word list
Changing the content block message
Backing up and restoring the banned word list
Configuring URL blocking
Blocking access to URLs
Go to Web Filter URL Block
Downloading the URL block list
Clearing the URL block list
Changing the URL block message
Uploading a URL block list
Removing scripts from web pages
Exempting URLs from content or URL blocking
Go to Web Filter Script Filter
Downloading the Exempt URL list
Adding URLs to the Exempt URL List
Clearing the Exempt URL list
Go to Web Filter Exempt URL
Uploading an Exempt URL list
Logging and reporting
Configuring Logging
Go to Log&Report Log setting
Recording logs on a remote computer
Example log settings
Configuring alert email
Selecting what to log
Configuring alert email
Go to System Network DNS
Administration
System status
Upgrading the DFL-500 NPG firmware
Execute ping
Enter Local Address
Enter Tftp Server Address
Enter File Name image.out
Restoring system settings to factory defaults
Backing up system settings
Restoring system settings
Displaying the DFL-500 NPG serial number
Changing to Transparent mode
Shutting down the DFL-500 NPG
Restarting the DFL-500 NPG
System status monitor
CPU usage Memory usage Up time Total Number of Sessions
Network configuration
System status monitor
Protocol From IP From Port To IP To Port Expire Clear
Configuring the internal interface
Configuring the internal interface
Configuring the external interface
Go to System Network Interface
Configuring the external interface with a static IP address
Configuring the external interface for PPPoE
Configuring the external interface
Https Ping SSH Snmp
Setting DNS server addresses
Configuring routing
Configuring the management interface Transparent mode
Adding routing gateways
Adding routes to the routing table
Adding a default route
Go to System Network Routing Table
Enabling RIP server support
Configuring the routing table
Adding routes Transparent mode
Go to System Network Routing
Go to System Network Dhcp
Providing Dhcp services to your internal network
Default Route Exclusion Range
Starting IP Ending IP Netmask Lease Duration Domain
Sample Dhcp settings
System configuration
Example Dynamic IP list
Go to System Config Time
Setting system date and time
Example date and time setting
Changing web-based manager options
Adding and editing administrator accounts
Go to System Config Admin
Read Write Only
Configuring Snmp
Go to System Config Snmp
100
Glossary
101
102
103
Index
104
CLI
105
Dhcp
106
Snmp
107
PFS
108
Transparent mode manual key Adding VPN tunnel IPSec VPN
109
NTP
110
Pptp
111
Smtp
112
VPN
113
IPSec VPN Remote Gateway user groups Deleting
114
115
Technical Support
116
Registration Card
117
118
Limited Warranty
119
120
121
Registration
122
Top
Page
Image
Contents