Netgear WNR834Bv2 WNR834Bv2 Reference Manual - Page 63

Disabling the SPI Firewall, Setting Up a Default DMZ Server - port forwarding

Page 63 highlights

NETGEAR RangeMax™ NEXT Wireless Router WNR834B User Manual Disabling the SPI Firewall The Stateful Packet Inspection (SPI) Firewall protects your network and computers against attacks and intrusions. A stateful packet firewall carefully inspects incoming traffic packets, looking for known exploits such as malformed, oversized, or out-of-sequence packets. The firewall should only be disabled in special circumstances, such as when troubleshooting application issues. Setting Up a Default DMZ Server The default DMZ server feature is helpful when using some online games and videoconferencing applications that are incompatible with Network Address Translation (NAT). The router is programmed to recognize some of these applications and to work properly with them, but there are other applications that may not function well. In some cases, one local computer can run the application properly if that computer's IP address is entered as the default DMZ server. Warning: DMZ servers pose a security risk. A computer designated as the default DMZ server loses much of the protection of the firewall, and is exposed to exploits from the Internet. If compromised, the DMZ server computer can be used to attack other computers on your network. Incoming traffic from the Internet is normally discarded by the router unless the traffic is a response to one of your local computers or a service that you have configured in the Port Forwarding/Port Triggering menu. Instead of discarding this traffic, you can have it forwarded to one computer on your network. This computer is called the Default DMZ Server. The WAN Setup menu lets you configure a Default DMZ Server. To assign a computer or server to be a Default DMZ server: 1. In the main menu, under Advanced, click WAN Setup. 2. Under Default DMZ Server, type the last digit of the IP address for that computer. To remove the default DMZ server, enter zero. 3. Select the checkbox for Default DMZ Server and click Apply. Responding to a Ping on the Internet WAN Port If you want the router to respond to a 'ping' from the Internet, select the checkbox for Respond to Ping on Internet WAN Port. This should only be used as a diagnostic tool, since it allows your router to be discovered by Internet scanners. Do not select this checkbox unless you have a specific reason to do so, such as when troubleshooting your connection. Customizing Your Network Settings 4-7 v2.1, July 2007

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128

NETGEAR RangeMax™ NEXT Wireless Router WNR834B User Manual
Customizing Your Network Settings
4-7
v2.1, July 2007
Disabling the SPI Firewall
The Stateful Packet Inspection (SPI) Firewall protects your network and computers against attacks
and intrusions. A stateful packet firewall carefully inspects incoming traffic packets, looking for
known exploits such as malformed, oversized, or out-of-sequence packets. The firewall should
only be disabled in special circumstances, such as when troubleshooting application issues.
Setting Up a Default DMZ Server
The default DMZ server feature is helpful when using some online games and videoconferencing
applications that are incompatible with Network Address Translation (NAT). The router is
programmed to recognize some of these applications and to work properly with them, but there are
other applications that may not function well. In some cases, one local computer can run the
application properly if that computer’s IP address is entered as the default DMZ server.
Incoming traffic from the Internet is normally discarded by the router unless the traffic is a
response to one of your local computers or a service that you have configured in the Port
Forwarding/Port Triggering menu. Instead of discarding this traffic, you can have it forwarded to
one computer on your network. This computer is called the Default DMZ Server.
The WAN Setup menu lets you configure a Default DMZ Server.
To assign a computer or server to be a Default DMZ server:
1.
In the main menu, under Advanced, click WAN Setup.
2.
Under Default DMZ Server, type the last digit of the IP address for that computer. To remove
the default DMZ server, enter zero.
3.
Select the checkbox for Default DMZ Server and click Apply.
Responding to a Ping on the Internet WAN Port
If you want the router to respond to a 'ping' from the Internet, select the checkbox for Respond to
Ping on Internet WAN Port. This should only be used as a diagnostic tool, since it allows your
router to be discovered by Internet scanners. Do not select this checkbox unless you have a
specific reason to do so, such as when troubleshooting your connection.
Warning:
DMZ servers pose a security risk. A computer designated as the default DMZ
server loses much of the protection of the firewall, and is exposed to exploits
from the Internet. If compromised, the DMZ server computer can be used to
attack other computers on your network.