D-Link DIR 601 Product Manual - Page 51

Firewall Settings - d link ip

Page 51 highlights

Section 3 - Configuration Firewall Settings A firewall protects your network from the outside world. The D-Link DIR-601 offers a firewall type functionality. The SPI feature helps prevent cyber attacks. Sometimes you may want a computer exposed to the outside world for certain types of applications. If you choose to expose a computer, you can enable DMZ. DMZ is short for Demilitarized Zone. This option will expose the chosen computer completely to the outside world. Enable SPI: SPI (Stateful Packet Inspection, also known as dynamic packet filtering) helps to prevent cyber attacks by tracking more state per session. It validates that the traffic passing through the session conforms to the protocol. NAT Endpoint Select one of the following for TCP and UDP ports: Filtering: Endpoint Independent - Any incoming traffic sent to an open port will be forwarded to the application that opened the port. The port will close if idle for 5 minutes. Address Restricted - Incoming traffic must match the IP address of the outgoing connection. Address + Port Restriction - Incoming traffic must match the IP address and port of the outgoing connection. Enable Anti-Spoof Enable this option to provide protection from certain kinds of "spoofing" Checking: attacks. Enable DMZ Host: If an application has trouble working from behind the router, you can expose one computer to the Internet and run the application on that computer. Note: Placing a computer in the DMZ may expose that computer to a variety of security risks. Use of this option is only recommended as a last resort. IP Address: Specify the IP address of the computer on the LAN that you want to have unrestricted Internet communication. If this computer obtains its IP address automatically using DHCP, be sure to make a static reservation on the System > Network Settings page so that the IP address of the DMZ machine does not change. D-Link DIR-601 User Manual 47

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120

´¶
D-L±nk DIR-601 User Manual
Sect±on ³ - Configurat±on
SPI (Stateful Packet Inspection, also known as dynamic packet filtering)
helps to prevent cyber attacks by tracking more state per session. It
validates that the traffic passing through the session conforms to the
protocol.
Select one of the following for TCP and UDP ports:
Endpoint.Independent.
- Any incoming traffic sent to an open port will
be forwarded to the application that opened the port. The port will close
if idle for 5 minutes.
Address.Restricted
- Incoming traffic must match the IP address of
the outgoing connection.
Address.+.Port.Restriction
- Incoming traffic must match the IP address
and port of the outgoing connection.
Enable this option to provide protection from certain kinds of “spoofing”
attacks.
If an application has trouble working from behind the router, you can
expose one computer to the Internet and run the application on that
computer.
Note:
Placing a computer in the DMZ may expose that computer to a
variety of security risks. Use of this option is only recommended as a
last resort.
Specify the IP address of the computer on the LAN that you want to have unrestricted Internet communication. If this
computer obtains its IP address automatically using DHCP, be sure to make a static reservation on the
System.>.Network.
Settings
page so that the IP address of the DMZ machine does not change.
Enable SPI:
NAT Endpoint
Filtering:
Enable Anti-Spoof
Checking:
Enable DMZ Host:
IP Address:
Firewall Settings
A firewall protects your network from the outside world. The D-Link DIR-601 offers a firewall type functionality. The SPI feature helps
prevent cyber attacks. Sometimes you may want a computer exposed to the outside world for certain types of applications. If you choose
to expose a computer, you can enable DMZ. DMZ is short for Demilitarized Zone. This option will expose the chosen computer completely
to the outside world.