D-Link DWC-1000 User Manual - Page 46

Configurable Port: DMZ Setup

Page 46 highlights

Wireless Controller User Manual Edi t: Th e Ed it b u t t o n will lin k t o t h e Po rt VLA N Co n fig u rat io n p ag e, allo win g y o u t o make ch an g es t o t h e s elect ed p o rt VLA N at t rib u t es . Figure 21: M ultiple VLAN Subne ts 2.4 Configurable Port: DMZ Setup This controller s upports one of the physical ports (Option Ports) to be configured as a s eco n d ary Et h ern et p o rt o r a d ed icat ed DM Z p o rt . A DM Z is a s u b n et wo rk t h at is open to the public but behind the firewall. The DMZ adds an additional layer of s ecu rit y t o t h e LA N, as s p ecific s ervices/po rts t h at are exp o sed t o t h e in t ern et o n t h e DM Z d o n o t h av e t o b e exp o sed o n t h e LA N. It is reco mmen d ed t h at h o s t s t h at mu s t b e exp o s ed t o t h e in t ern et (s u ch as web o r email s erv ers ) b e p laced in t h e DM Z n et wo rk. Firewall ru les can b e allo wed t o p ermit access s p ecific s ervices/p o rt s t o t h e DM Z fro m b o t h t h e LA N o r Op t io n . In t h e ev en t o f an at t ack t o an y o f t h e DM Z n o d es , t h e LA N is n o t n eces s arily v u ln erab le as well. Setup > DMZ Setup > DMZ Setup Configuration DM Z co n fig u ratio n is id en tical t o t h e LA N co n fig u ratio n. Th ere are n o rest rictio ns on the IP addres s or s ubnet as signed to the DMZ port, other than the fact that it cannot b e id en t ical t o t h e IP ad d res s g iv en t o t h e LA N in t erface o f t h is g at eway . 44

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324

Wireless Controller
User Manual
44
Edi t
: The Edit button will link to the Port VLAN Configuration page, allowing you
to make changes to the selected port VLAN attributes.
Figure 21: Multiple VLAN Subnets
2.4
Configurable Port: DMZ Setup
This controller supports one of the physical ports (Option Ports) to be configured as a
secondary Ethernet port or a dedicated DMZ port. A DMZ is a subnetwork that is
open to the public but behind the firewall. The DMZ adds an additional layer of
security to the LAN, as specific services/ports that are exposed to the internet on the
DMZ do not have to be exposed on the LAN. It is recommended that hosts that must
be exposed to the internet (such as web or email servers) be placed in the DMZ
network. Firewall rules can be allowed to permit access specific services/ports to the
DMZ from both the LAN or Option. In the event of an attack to any of the DMZ
nodes, the LAN is not necessarily vulnerable as well.
Setup > DMZ Setup > DMZ Setup Configuration
DMZ configuration is identical to the LAN configuration. There are no restrictions on
the IP address or subnet assigned to the DMZ port, other than the fact that it cannot
be identical to the IP address given to the LAN interface of this gateway.