D-Link DGL-4500 Product Manual - Page 50

Firewall Settings, Enable SPI, DMZ - d link port forwarding

Page 50 highlights

Section 3 - Configuration Firewall Settings A firewall protects your network from the outside world. The D-Link DGL-4500 offers a firewall type functionality. Enable SPI: SPI (Stateful Packet Inspection, also known as dynamic packet filtering) helps to prevent cyber attacks by tracking more state per session. It validates that the traffic passing through the session conforms to the protocol. NAT Endpoint Select one of the following for TCP and UDP ports: Filtering: Endpoint Independent - Any incoming traffic sent to an open port will be forwarded to the application that opened the port. The port will close if idle for 5 minutes. Address Restricted - Incoming traffic must match the IP address of the outgoing connection. Address and Port Restriction - Incoming traffic must match the IP address and port of the outgoing connection. Anti-Spoofing: Click to enable Anti-Spoofing protection. Enable DMZ Host: If an application has trouble working from behind the router, you can expose one computer to the Internet and run the application on that computer. Note: Placing a computer in the DMZ may expose that computer to a variety of security risks. Use of this option is only recommended as a last resort. IP Address: Specify the IP address of the computer on the LAN that you want to have unrestricted Internet communication. If this computer obtains it's IP address automatically using DHCP, be sure to make a static reservation on the Basic > DHCP page so that the IP address of the DMZ machine does not change. Non-UDP/TCP/ICMP Enable this feature to allow the router' NAT to track application that uses protocols other than UDP, TCP or ICMP. LAN Sessions: ALG: Check the PPTP, IPSec, RTSP, and SIP boxes to allow pass-through. D-Link DGL-4500 User Manual 45

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108

45
D-Link DGL-4500 User Manual
Section ³ - Configuration
SPI (Stateful Packet Inspection, also known as dynamic packet
filtering) helps to prevent cyber attacks by tracking more state per
session. It validates that the traffic passing through the session
conforms to the protocol.
Select one of the following for TCP and UDP ports:
Endpoint.Independent.
- Any incoming traffic sent to an open port
will be forwarded to the application that opened the port. The port
will close if idle for 5 minutes.
Address.Restricted
- Incoming traffic must match the IP address
of the outgoing connection.
Address.and.Port.Restriction
- Incoming traffic must match the
IP address and port of the outgoing connection.
Click to enable Anti-Spoofing protection.
If an application has trouble working from behind the router, you
can expose one computer to the Internet and run the application on
that computer.
Note:
Placing a computer in the DMZ may expose
that computer to a variety of security risks. Use of this option is only
recommended as a last resort.
Specify the IP address of the computer on the LAN that you want
to have unrestricted Internet communication. If this computer obtains it’s IP address automatically using DHCP, be sure to
make a static reservation on the
Basic
>
DHCP
page so that the IP address of the DMZ machine does not change.
Enable this feature to allow the router’ NAT to track application that uses protocols other than UDP, TCP or ICMP.
Check the PPTP, IPSec, RTSP, and SIP boxes to allow pass-through.
Enable SPI:
NAT Endpoint
Filtering:
Anti-Spoofing:
Enable DMZ Host:
IP Address:
Non-UDP/TCP/ICMP
LAN Sessions:
ALG:
Firewall Settings
A firewall protects your network from the outside world. The D-Link DGL-4500 offers a firewall type functionality.