Netgear SRX5308 SRX5308 Reference Manual - Page 75

Managing the Network Database, Network Configuration, LAN Settings, LAN Groups - specifications

Page 75 highlights

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual Some advantages of the network database are: • Generally, you do not need to enter either IP address or MAC addresses. Instead, you can just select the name of the desired PC or device. • There is no need to reserve an IP address for a PC in the DHCP server. All IP address assignments made by the DHCP server are maintained until the PC or device is removed from the network database, either by expiration (inactive for a long time) or by you. • There is no need to use a fixed IP address on a PCs. Because the IP address allocated by the DHCP server never changes, you do not need to assign a fixed IP address to a PC to ensure that it always has the same IP address. • A PC is identified by its MAC address-not by its IP address. The network database uses the MAC address to identify each PC or device. Therefore, changing a PC's IP address does not affect any restrictions applied to that PC. • Control over PCs can be assigned to groups and individuals: - You can assign PCs to groups (see "Managing the Network Database" on page 3-15" on this page) and apply restrictions (LAN WAN outbound rules, LAN DMZ outbound rules, LAN WAN inbound rules, and LAN DMZ inbound rules) to each group (see "Using Rules to Block or Allow Specific Kinds of Traffic" on page 4-2). - If necessary, you can also create firewall rules to apply to a single PC (see "Enabling Source MAC Filtering" on page 4-44). Because the MAC address is used to identify each PC, users cannot avoid these restrictions by changing their IP address. Managing the Network Database You can view the network database, manually add or remove database entries, and edit database entries. To view the network database: 1. Select Network Configuration > LAN Settings from the menu. The LAN Settings submenu tabs display, with the LAN Setup screen in view (see Figure 3-2 on page 3-6). 2. Click the LAN Groups submenu tab. The LAN Groups screen displays (see Figure 3-6 on page 3-16, which shows some examples in the Known PCs and Devices table). LAN Configuration v1.0, April 2010 3-15

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual
LAN Configuration
3-15
v1.0, April 2010
Some advantages of the network database are:
Generally, you do not need to enter either IP address or MAC addresses. Instead, you can just
select the name of the desired PC or device.
There is no need to reserve an IP address for a PC in the DHCP server. All IP address
assignments made by the DHCP server are maintained until the PC or device is removed from
the network database, either by expiration (inactive for a long time) or by you.
There is no need to use a fixed IP address on a PCs. Because the IP address allocated by the
DHCP server never changes, you do not need to assign a fixed IP address to a PC to ensure
that it always has the same IP address.
A PC is identified by its MAC address—not by its IP address. The network database uses the
MAC address to identify each PC or device. Therefore, changing a PC’s IP address does not
affect any restrictions applied to that PC.
Control over PCs can be assigned to groups and individuals:
You can assign PCs to groups (see
“Managing the Network Database” on page 3-15
” on
this page) and apply restrictions (LAN WAN outbound rules, LAN DMZ outbound rules,
LAN WAN inbound rules, and LAN DMZ inbound rules) to each group (see
“Using Rules
to Block or Allow Specific Kinds of Traffic” on page 4-2
).
If necessary, you can also create firewall rules to apply to a single PC (see
“Enabling
Source MAC Filtering” on page 4-44
). Because the MAC address is used to identify each
PC, users cannot avoid these restrictions by changing their IP address.
Managing the Network Database
You can view the network database, manually add or remove database entries, and edit database
entries.
To view the network database:
1.
Select
Network Configuration
>
LAN Settings
from the menu. The LAN Settings submenu
tabs display, with the LAN Setup screen in view (see
Figure 3-2 on page 3-6
).
2.
Click the
LAN Groups
submenu tab.
The LAN Groups screen displays (see
Figure 3-6 on
page 3-16
, which shows some examples in the Known PCs and Devices table).