4.4 Firewall

Basics for Firewall

While the broadband users demand more bandwidth for multimedia, interactive applications, or distance learning, security has been always the most concerned. The firewall of the Vigor router helps to protect your local network against attack from unauthorized outsiders. It also restricts users in the local network from accessing the Internet. Furthermore, it can filter out specific packets that trigger the router to build an unwanted outgoing connection.

Denial of Service (DoS) Defense

The DoS Defense functionality helps you to detect and mitigate the DoS attack. The attacks are usually categorized into two types, the flooding-type attacks and the vulnerability attacks. The flooding-type attacks will attempt to exhaust all your system's resource while the vulnerability attacks will try to paralyze the system by offending the vulnerabilities of the protocol or operation system.

The DoS Defense function enables the Vigor router to inspect every incoming packet based on the attack signature database. Any malicious packet that might duplicate itself to paralyze the host in the secure LAN will be strictly blocked and a Syslog message will be sent as warning, if you set up Syslog server.

Also the Vigor router monitors the traffic. Any abnormal traffic flow violating the pre-defined parameter, such as the number of thresholds, is identified as an attack and the Vigor router will activate its defense mechanism to mitigate in a real-time manner.

Below shows the menu items for Firewall.

4.4.1 DoS Defense

Click Firewall and click DoS Defense to open the setup page. Storm control for the switch is configured on this page.

Frame Type

Set the Unicast storm rate control, multicast storm rate control,

 

and a broadcast storm rate control for your router.

Status

Check this box to enable storm control status for the frame type.

Rate

The unit is packet per second (pps). Use the drop down list to

 

set the rate for data transmission. The rate is 2^n, where n is

 

116

Vigor2130 Series User’s Guide

Page 124
Image 124
Draytek 2130 manual Basics for Firewall, Denial of Service DoS Defense

2130 specifications

The DrayTek Vigor 2130 is a versatile and powerful router known for its robust features and performance, making it ideal for small to medium-sized businesses and home offices. This dual WAN router stands out due to its reliability and extensive management capabilities, which cater to users seeking both performance and flexibility.

One of the hallmark features of the Vigor 2130 is its dual WAN support, allowing for load balancing and automatic failover. This means that users can connect two internet sources, such as DSL and fiber, to ensure continuous internet availability and enhance overall bandwidth. The router can intelligently distribute traffic across both connections or switch to a backup line seamlessly if one connection fails, ensuring uninterrupted online activities.

Additionally, the DrayTek Vigor 2130 incorporates advanced security features that are essential for protecting sensitive data in a business environment. It comes equipped with a stateful packet inspection firewall, intrusion detection and prevention systems, and Virtual Private Network (VPN) support, allowing secure remote access for employees and clients. The router supports multiple VPN protocols, including PPTP, L2TP, and IPSec, which enhances connectivity for users working from various locations.

The router also features Quality of Service (QoS) functionalities, enabling users to prioritize bandwidth for critical applications and services. This ensures that essential tasks like VoIP calls or video conferencing run smoothly without interruptions. The Vigor 2130 supports VLANs, allowing businesses to segment their networks for better resource management and security.

On the connectivity front, the Vigor 2130 offers multiple Ethernet ports, including gigabit LAN and WAN ports, providing ample opportunities for wired connections. For wireless needs, the router includes built-in wireless capabilities that support IEEE 802.11n, providing robust Wi-Fi coverage and decent speeds.

With a user-friendly interface and comprehensive logging features, network management becomes intuitive. The Vigor 2130 also supports remote management, enabling IT administrators to configure settings and monitor the network from anywhere, which is particularly useful for businesses with limited on-site IT staff.

In conclusion, the DrayTek Vigor 2130 is a reliable solution that combines performance, security, and ease of management. Its dual WAN capability, robust security features, and advanced management options train organizations to navigate the complexities of modern networking effortlessly. Whether for home use or a small business environment, the Vigor 2130 delivers a comprehensive set of features that meets the needs of modern users.