background image

 

Introduction to Firewalls 

A firewall is a device that sits between your computer and the Internet 

that prevents unauthorized access to or from your network. A firewall can 
be a computer using firewall software or a special piece of hardware built 
specifically to act as a firewall. In most circumstances, a firewall is used to 
prevent unauthorized Internet users from accessing private networks such 
as corporate LAN’s and Intranets.   

A firewall watches all of the information moving to and from your 

network and analyzes each piece of data. Each piece of data is checked 
against a set of criteria that the administrator configures. If any data does 
not meet the criteria, that data is blocked and discarded. If the data meets 
the criteria, the data is passed through. This method is called packet 
filtering. 

A firewall can also run specific security functions based on the type of 

application or type of port that is being used. For example, a firewall can 
be configured to work with an FTP or Telnet server. Or a firewall can be 
configured to work with specific UDP or TCP ports to allow certain 
applications or games to work properly over the Internet. 

 

Summary of Contents for DI-713P

Page 1: ...D Link DI 713P Wireless Broadband Router User s Manual ...

Page 2: ...less Networking 10 Chapter 2 Hardware Installation 12 Procedure for Hardware Installation 12 Package Contents 14 LED Panel 15 Rear Panel 16 Chapter 3 Basic Broadband Router Configuration 17 Start up and Log in 17 Device Information 19 Useful Tools 20 Setup 24 Static IP Address 25 Dynamic IP Address 26 PPP over Ethernet 27 Dial up Network 29 DHCP 31 Wireless 33 Print Server 34 Chapter 4 Advanced Br...

Page 3: ...r 5 Console Mode 51 Chapter 6 Troubleshooting 53 Basic Functions 53 LAN Connection Problems 55 ISP Connection Problems 57 Internet Application Problems 58 Wireless Troubleshooting 60 Appendix 1 Using PING 61 Appendix 2 Using WINIPCFG 63 Contacting Technical Support 67 Technical Specifications 68 D Link Offices 70 Limited Warranty 71 Registration Card 79 Rev 2001 03 15 ...

Page 4: ...less Broadband Router provides two levels of security support First it masks local users IP addresses from others on the Internet making it much more difficult for a hacker to target a machine on your network Secondly it can block and redirect certain ports to limit the services that outside users can access Specific ports can be opened by the user to ensure that games and other Internet applicati...

Page 5: ...outer Also the Wireless Broadband Router like broadband is always on removing the need to constantly boot a software server when access is desired from a client Integrated DHCP services allow up to 252 users to get their IP address automatically on boot up from the Wireless Broadband Router Client machines require no software simply set them to accept a dynamically assigned IP address and reboot E...

Page 6: ...is moved from your computer to the server using routers A router also determines the best route that your information should follow to ensure that the information is delivered properly A router controls the amount of data that is sent through your network by eliminating information that shouldn t be there This provides security for the computers behind your router because computers from the outsid...

Page 7: ...ion moving to and from your network and analyzes each piece of data Each piece of data is checked against a set of criteria that the administrator configures If any data does not meet the criteria that data is blocked and discarded If the data meets the criteria the data is passed through This method is called packet filtering A firewall can also run specific security functions based on the type o...

Page 8: ...hich communicates the data between computers A NIC is usually a 10Mbps network card 10 100Mbps network card or a wireless network card Most networks use hardware devices such as hubs or switches that each cable can be connected to in order to continue the connection between computers A hub simply takes any data arriving through each port and forwards the data to all other ports A switch is more so...

Page 9: ...means of connecting two private networks over the Internet PPTP is a way of securing the information that is communicated between networks PPTP secures information by encrypting the data inside of a packet IP Security IPSec IPSec provides a more secure network to network connection across the Internet or a Wide Area Network WAN IPSec encrypts all communication between the client and server whereas...

Page 10: ...fer large files quickly or even watch a Movie in MPEG format over your network without noticeable delays This technology works by using multiple frequencies in the 2 4GHz range utilizing Direct Sequence Spread Spectrum DSSS technology D Link Air products will automatically sense the best possible connection speed to ensure the greatest speed and range possible with the technology Installation Cons...

Page 11: ...num studs may have a negative effect on range Again try to position Access Points Residential Gateways and Computers so that the signal passes through drywall or open doorways and not other materials 4 Make sure that the antenna is positioned for best reception by using the software signal strength tools included with your product 5 Keep your product away at least 1 2 meters from electrical device...

Page 12: ...the unit Self adhesive rubber feet are provided to stick on the bottom of the unit to protect the surface where you have placed the unit 2 Setup LAN connection a Wired LAN connection connect an Ethernet cable from your computer s Ethernet port to one of the LAN ports of the DI 713 b Wireless LAN connection make sure the antennas are in a vertical position if not rotate over 90 degrees 3 Setup WAN ...

Page 13: ... printer Use the printer cable to connect your printer to the printer port of this product 5 Power on Connect the power cord to a power outlet and turn the power switch to the on position the DI 713P will automatically enter the self test phase When it is in the self test phase the indicators M1 and ...

Page 14: ...ation has finished Finally the M1 will continuously flash once per second to indicate that the DI 713 is in normal operation Package Contents The D Link DI 713P package should include the following items DI 713P Broadband router User s Manual Quick Install Guide Power Adapter CAT 5 UTP Cable Print Server Software ...

Page 15: ... On The DI 713P is working for some service M2 System status 2 Orange Blinking The DI 713P is being configured or upgraded Don t turn it off On The WAN port is linked WAN WAN port activity Green Blinking The WAN port is sending or receiving data On An active station is connected to the corresponding LAN port Link Act 1 3 Link status Green Blinking The corresponding LAN port is sending or receiving...

Page 16: ...d to connect an external analog backup modem LPT Port used to connect a printer LAN 1 3 The RJ 45 Ethernet ports used to connect computers with network adapters directly to the DI 713P WAN The RJ 45 Ethernet port labeled WAN is used to connect your DI 713P to your DSL or Cable modem Reset Resets the configuration to default settings 12VDC Power inlet DC 12V 1 2A minimum ...

Page 17: ...eb Configuration interface and how to use different options and settings Although you can change the IP address of your Broadband Router to meet your needs this manual will assume that the defaults are left in place This means that the IP address of your Broadband Router will be 192 168 0 1 If you have changed the IP address scheme please substitute 192 168 0 1 with the IP address scheme that you ...

Page 18: ... a secure connection to your Broadband Router The Tools section described later in this manual describes how to change the password Once you have input the correct password and logged in the screen will change to the Device Information screen If you are having problems logging in and you are sure that the password you are using is correct check the top right hand corner of your keyboard to make su...

Page 19: ...ll guide to setup your Internet Connection you should see a Renew button Click the Renew button to renew your connection with your ISP The Modem Status box displays the status of your dial up connection while using an external modem The Firmware Version box shows the current firmware version of your Broadband Router To upgrade your Broadband Router visit www dlink com and follow the links to downl...

Page 20: ...Then click inside of the New Password box and type the password that you would like to change to Next click inside of the Reconfirm box and type in the new password again Click OK to save the new password or click the Clear button to remove the passwords you just typed in To ensure that you use a password that is effective follow these simple rules 1 Choose a password that would be hard for someon...

Page 21: ...13 20 DHCP discover 259 dh bb1 12 01 13 16 DHCP discover 259 dh aa1 300 01 13 16 DHCP offer 192 177 81 9 01 13 16 DHCP request 192 177 81 47 271 dh aa2 300 01 13 15 DHCP ack DOL 64800 T1 32400 T2 56700 00 55 18 192 168 0 184 logged out 00 47 38 192 168 0 184 login successful The Reboot button will reboot your Broadband Router This is helpful when you have changed some settings and need to reboot y...

Page 22: ...ture is needed to connect to the Internet The Restore Defaults button will restore all of the settings you have changed within your Broadband Router Web Configuration Interface to the default settings used when you first purchased the unit This can be helpful when you want to restore all of the settings to default to ensure that your connection is secure and working properly When the Firmware Upgr...

Page 23: ...rt web site to ensure that your Broadband Router is upgraded properly and to ensure proper operation While upgrading the firmware DO NOT turn the power off Turning the unit off while upgrading could render the unit inoperable ...

Page 24: ... able to access the Internet If you are not sure which settings should be used please contact your ISP The LAN IP Address field is the IP address that your Broadband Router is set to In most circumstances the LAN IP Address can be left alone although it can be changed to meet your needs If you do change the LAN IP Address be aware that all of your clients will need to be restarted if they are usin...

Page 25: ...ype field will display the Change WAN Type screen shown below Static IP Address The Static IP Address field should be checked if your ISP assigns you an IP address This means that your ISP has given you an IP address that you will use to connect to the Internet through their service Once you have selected Static IP Address you will be shown the following screen ...

Page 26: ...es click Save and reboot your Broadband Router for the changes to take affect Dynamic IP Address The Dynamic IP Address field should be checked if your ISP has not given you a unique IP address and you receive an automatic IP address each time you connect to your ISP The rest of the settings related to your connection are retrieved automatically each time you connect to the Internet Once you have ...

Page 27: ... of the correct values click Save and reboot your Broadband Router for the changes to take affect PPP over Ethernet The PPP over Ethernet field should be checked if your ISP uses the Point to Point over Ethernet protocol to authenticate a username and password and then automatically assign you an IP Address PPP over Ethernet PPPoE is a non standard method of connecting to your ISP to gain an IP ad...

Page 28: ...heck is to call your ISP or read the documentation provided when you signed up for your Internet service Once you have selected PPP over Ethernet you will be shown the following screen You will need to input the correct values in each of the blank fields Your ISP may have provided each of these values for you Or you may have written them down while you followed the Quick Install Guide If ...

Page 29: ... inputted in the Primary and Secondary DNS fields these values will be retrieved from your ISP automatically After you have input all of the correct values click Save and reboot your Broadband Router for the changes to take affect Dial up Network The Dial up Network field should be used if you use an external modem or PSTN ISDN Once you have selected Dial up Network you will be shown the following...

Page 30: ...etrieved from your ISP automatically In the Maximum Idle Time field input the maximum time that your connection can be used before your ISP disconnects you Select the correct Baud Rate that your modem is set to If any extra settings are needed for your external modem to operate correctly input the correct values in the Extra Settings field Refer to your modem documentation and your ISP to determin...

Page 31: ...n provide all of the required information automatically each time a client computer on your network boots up The DHCP Server screen enables you to configure these settings You can change whether the DHCP Server is running by choosing Disable or Enable If you choose Disable each computer on your network will need to be configured separately in order for them to access the Internet If Enable is chos...

Page 32: ...can also restrict the number of computers that the Broadband Router can support in DHCP by limiting the pool of IP addresses For example if you only want 10 IP address s to be provided to clients on your network you can set the Starting address to 100 and the Ending address to 109 Doing this will limit the number of clients that can automatically receive an IP address from the Broadband Router The...

Page 33: ...e same name that your wireless adapters use in their network settings The Channel field must also be set to the same settings as your wireless adapter The Security field enables you to set security keys so that your wireless network is secure When Enable insecure access is selected your data is transferred without extra security This allows your data to be intercepted and examined by intruders Whe...

Page 34: ... security key that you use must be the same as your wireless adapter Print Server The DI 713P provides the function of a network print server for Microsoft Window 98 Windows ME Windows NT and Windows 2000 Please refer to the Print Server Quick Install Guide for installing the port and printer installation ...

Page 35: ...servers to operate correctly It is recommended that separate computers run each service Special Applications Allows games and video conferencing applications to operate correctly Access Control Allows the definition of access rights and security policies by groups For example you may want certain users to have access to the Internet while others cannot Or you can block certain services such as FTP...

Page 36: ...36 To access the Advanced Router Configuration screens click the Advanced link below If at any time you wish to return to the Basic Configuration screens click the Basic Link below ...

Page 37: ...rom a computer on your network and you may want those services to be accessible to users outside of your network The Virtual Server screen allows you to configure specific computers on your network to provide these services to remote users Each service uses a specific port that is used ...

Page 38: ...lay a list of popular services Choose the service you wish to configure by clicking on that service Next click the ID box and select the ID row that you wish to configure Once the service and the ID number are selected click the Copy to button to copy the settings to the Virtual Server table Next you will need to specify the IP Address of the computer that is running the service by typing the IP a...

Page 39: ...lick the Reboot button to reboot the Broadband Router for the changes to take effect You can also click the Undo button to undo your changes Note Only one TCP IP address can be assigned to each service port ...

Page 40: ...thout special settings The Special Applications screen allows you to specify which ports should be opened and allowed to communicate with computers outside of your network In situations where some games just won t work the DMZ Host settings can be used which is found in the Misc Items section The Triggerfield is the initial outbound port number that the application such as a game uses to contact a...

Page 41: ...a list of popular applications Choose the application you wish to configure by clicking on that application Next click the ID box and select the ID row that you wish to configure Once the application and the ID number are selected click the Copy to button to copy the settings to the Special Applications table After you have configured the Special Applications settings click the Save button The fol...

Page 42: ...42 changes Note Only one TCP IP address can be assigned to each service port ...

Page 43: ...rights To enable access control click the checkbox next to Enable in the Access Control field Next you can define the access control of all users not assigned in groups 1 through 3 For example you can block all users from using port 21 FTP by specifying port 21 in the Default Group field Next determine which users need to be blocked or allowed different ports and define them in groups 1 2 or 3 ...

Page 44: ... port 25 receive mail port 110 and browse the Internet port 80 Port 53 DNS is necessary to resolve the domain name Group 2 has 50 members 192 168 0 150 192 168 0 199 They can do anything except read net news port 119 and transfer files via FTP port 21 Group 3 has 2 members 192 168 0 10 and 192 168 0 20 They can fully access the Internet Block nothing After the Access Control settings have been con...

Page 45: ...45 take effect immediately ...

Page 46: ...e same name that your wireless adapters use in their network settings The Channelfield must also be set to the same settings as your wireless adapter The Security field enables you to set security keys so that your wireless network is secure When Enable insecure access is selected your data is transferred without extra security This allows your data to be intercepted and examined by intruders When...

Page 47: ...47 Wireless Broadband Router must decode each piece of data moving to and from your wireless adapter The security key that you use must be the same as your wireless adapter ...

Page 48: ... unrestricted two way communication outside of your network To enable DMZ type the IP address in the box provided Then click the checkbox to the right of the IP address Only one computer can use DMZ at a time Please note that enabling DMZ removes the protection of the firewall which exposes the computer to intrusion Use DMZ only when needed and not for extended periods of time In some circumstance...

Page 49: ...is enabled the web port will be shifted to port 88 This is a security precaution to prevent an indiscriminate port scan which could find the web configuration interface and hack into your connection In order for the remote administrator to access the web configuration interface the user must input the IP address that has been given to the WAN port of the Broadband Router found in the Device Inform...

Page 50: ...50 Click the Reboot button to reboot the Broadband Router for make the changes to take effect You can also click the Undo button to undo your changes ...

Page 51: ...ecting the null modem cable to your computer make a note of which COM port you use you will need this information when you setup the connection in HyperTerminal To use the Console Mode follow these steps 1 Connect the null modem cable from your Broadband Router s COM port to your computers COM port 2 Open HyperTerminal by clicking on Start Programs Accessories Communications HyperTerminal 3 Setup ...

Page 52: ...ch the LED s on the Broadband Router closely so that you press the ENTER key at the correct time 5 The command list shows the commands that you can use The Current Settings portion shows the current configuration Type the command and press the ENTER key to execute that command For example if you wanted to change the IP address and the Password from the current setting to IP address 192 168 200 210...

Page 53: ...The phone numbers for Technical Support are in the appendix of this manual under D Link Offices Basic Functions My Broadband Router will not turn on No LED s light up Cause The power is not connected or the power switch is set to Off Resolution Connect the power adapter to your Broadband Router and plug it into the power outlet Make sure that the power switch is set to On Note Only use the power a...

Page 54: ...Resolution Make sure that both ends of the cable are connected Try using another cable If you are using a straight through cable try a patch cable and vice versa Sometimes my Broadband Router stops working or locks up Cause Someone has attempted to hack into someone on your LAN The Broadband Router has detected harmful data trying to access your LAN The NAT table is full Resolution Reboot the Broa...

Page 55: ...o upgrade the firmware LAN Connection Problems I can t access my Broadband Router Cause The unit is not turned on There is not a network connection The computer you are using does not have a compatible IP Address Resolution Make sure your Broadband Router is turned on Make sure that there is a physical connection between your computer and the Broadband Router and that the Link light is on Use the ...

Page 56: ...rt to the default settings I can t connect to other computers on my LAN Cause The IP Addresses of the computers are not set correctly Network cables are not connected properly Windows network settings are not set correctly Resolution Make sure that each computer has a unique IP Address If using DHCP through the Broadband Router make sure that each computer is set to Obtain an IP Address automatica...

Page 57: ...s their service Resolution Make sure that your DSL or Cable modem is running correctly and connected to the WAN port of the Broadband Router Make sure that the right connection type is used in the web configuration Make sure that the username and password used in the connection type is correct If using Home make sure that the computer name is input correctly Clone the MAC address using the web con...

Page 58: ...NAT table used in the Broadband Router can fill up and stop working temporarily Try using the DMZ host feature while connecting to game servers and then disabling DMZ while playing the game Turn the Broadband Router off and then on again to reset the NAT table Make sure that the correct ports have been opened in order for your specific game to operate correctly behind a firewall Consult your game ...

Page 59: ...omain Suffix address should appear similar to this dlink occa home com Find the Domain Suffix on your invoice or call your Internet Service Provider ISP to obtain it Can t connect to AOL Cause Your AOL software is not set correctly to use the Broadband Router Resolution Use your AOL software to change the location information to use TCP IP in the Network field Leave the phone number blank Save you...

Page 60: ...efault SSID and Channel that the Wireless Broadband Router uses is default and 6 respectively Make sure that your computer is within range and free from any strong electrical devices that may cause interference Refer to the section Introduction to Wireless Networking for tips to help make a good connection Check your IP Address to make sure that it is compatible with the Wireless Broadband Router ...

Page 61: ...et to a DOS prompt Type ping 192 168 0 1 which is the IP address of the Gateway in this case and hit the Enter key The following screen will be shown C ping 192 168 0 1 Pinging 192 168 0 1 with 32 bytes of data Reply from 192 168 0 1 bytes 32 time 130ms TTL 64 Reply from 192 168 0 1 bytes 32 time 10ms TTL 64 Reply from 192 168 0 1 bytes 32 time 20ms TTL 64 Reply from 192 168 0 1 bytes 32 time 10ms...

Page 62: ... your connection is setup correctly but there is a problem with your ISP or the Internet site you tried to PING is unavailable The screen shown below is an example of an unsuccessful PING C ping 192 168 0 1 Pinging 192 168 0 1 with 32 bytes of data Request timed out Request timed out Request timed out Request timed out Ping statistics for 192 168 0 1 Packets Sent 4 Received 0 Lost 4 100 loss Appro...

Page 63: ...led IPCONFIG that can be used to perform similar tasks Use the following steps to use the WINIPCFG utility Click on the Start button and click Run Type winipcfg in the Open box Click OK The IP Configuration screen will be displayed The IP address will be displayed in the IP Address box If you have more than one network card make sure that the network card that you are using is displayed in the whi...

Page 64: ...ur network settings make sure that the IP Address of your Broadband Router is set in the Gateway portion of the TCP IP settings in your network settings Click on More Info to display additional IP information The important settings to watch for in this screen are in the Host Information box Make sure that the DNS Servers box has the ...

Page 65: ...65 correct DNS information Also check the DHCP server box to make sure that you are connected to the right DHCP server ...

Page 66: ...66 ...

Page 67: ...www dlink com Email support dlink com Phone 949 788 0805 option 4 If you are a customer residing outside of the United States please refer to the list of D Link locations that is included in this manual Thank you for purchasing this product We like to receive feedback from our customers concerning our products Please take a moment to visit our web site You can register your purchase on line learn ...

Page 68: ...E TX Fast Ethernet ANSI IEEE 802 3 NWay auto negotiation Protocols Supported TCP IP NAT UDP PPPoE DHCP Client and Server Management Web Based Ports LAN NWay 10BASE T 100BASE TX Fast Ethernet WAN 10BASE T RS 232 DB 9 Serial Additional details available at D Link s web site www dlink com ...

Page 69: ...tions IEEE 802 11b Wireless LAN Wi Fi Compatible Access Point Frequency Band 2 4 2 4835 GHz subject to local regulation Access Point Number of Channel USA Canada 11 Access Point Frequency Range 5 Mbps Access Point Data Rate 11 Mbps 5 5 Mbps 2 Mbps 1 Mbps ...

Page 70: ...AIR LINE 00800 7250 8000 INDIA D LINK INDIA Plot No 5 Kurla Bandra Complex Road Off Cst Road Santacruz E Bombay 400 098 India TEL 91 22 652 6696 FAX 91 22 652 8914 URL www dlink india com E MAIL service dlink india com ITALY D LINK ITALIA Via Nino Bonnet No 6 b 20154 Milano Italy TEL 39 02 2900 0676 FAX 39 02 2900 1723 URL www dlink it E MAIL info dlink it JAPAN D LINK JAPAN 10F 8 8 15 Nishi Gotan...

Page 71: ...90 days after the date of original retail purchase of the Hardware If a completed Registration Card is not received by an authorized D Link Service Office within such ninety 90 day period then the Warranty Period shall be ninety 90 days from the date of purchase Product Type Warranty Period Product excluding power supplies and fans if purchased and delivered in the fifty 50 United States or the Di...

Page 72: ...nts that the software portion of the product Software will substantially conform to D Link s then current functional specifications for the Software as set forth in the applicable documentation from the date of original delivery of the Software for a period of ninety 90 days Warranty Period if the Software is properly installed on approved hardware and operated as contemplated in its documentation...

Page 73: ...ct within ninety 90 days after the product is purchased and or licensed The addresses telephone fax list of the nearest Authorized D Link Service Office is provided in the back of this manual FAILURE TO PROPERLY COMPLETE AND TIMELY RETURN THE REGISTRATION CARD MAY AFFECT THE WARRANTY FOR THIS PRODUCT Submitting A Claim Any claim under this limited warranty must be submitted in writing before the e...

Page 74: ... packaged and shipped in accordance with the foregoing requirements or that is determined by D Link not to be defective or non conforming What Is Not Covered This limited warranty provided by D Link does not cover Products that have been subjected to abuse accident alteration modification tampering negligence misuse faulty installation lack of reasonable care repair or service in any way that is n...

Page 75: ...ITED WARRANTY PROVIDED HEREIN THE ENTIRE RISK AS TO THE QUALITY SELECTION AND PERFORMANCE OF THE PRODUCT IS WITH THE PURCHASER OF THE PRODUCT Limitation of Liability TO THE MAXIMUM EXTENT PERMITTED BY LAW D LINK IS NOT LIABLE UNDER ANY CONTRACT NEGLIGENCE STRICT LIABILITY OR OTHER LEGAL OR EQUITABLE THEORY FOR ANY LOSS OF USE OF THE PRODUCT INCONVENIENCE OR DAMAGES OF ANY CHARACTER WHETHER DIRECT ...

Page 76: ...sts so the foregoing limitations and exclusions may not apply This limited warranty provides specific legal rights and the product owner may also have other rights which vary from state to state Trademarks Copyright 1999 D Link Corporation Contents subject to change without prior notice D Link is a registered trademark of D Link Corporation D Link Systems Inc All other trademarks belong to their r...

Page 77: ...erencias de radio en cuyo case puede requerirse al usuario para que adopte las medidas adecuadas Attention Ceci est un produit de classe B Dans un environnement domestique ce produit pourrait causer des interférences radio auquel cas l utilisateur devrait prendre les mesures adéquates Attenzione Il presente prodotto appartiene alla classe B Se utilizzato in ambiente domestico il prodotto può causa...

Page 78: ...ur in a particular installation If this equipment does cause harmful interference to radio or television reception which can be determined by turning the equipment off and on the user is encouraged to try to correct the interference by one or more of the following measures Reorient or relocate the receiving antenna Increase the separation between the equipment and receiver Connect the equipment in...

Page 79: ...t 1 Where and how will the product primarily be used oHome oOffice oTravel oCompany Business oHome Busi ness oPersonal Use 2 How many employees work at installation site o1 employee o2 9 o10 49 o50 99 o100 499 o500 999 o1000 or more 3 What network protocol s does your organization use oXNS IPX oTCP IP oDECnet oOthers_____________________________ 4 What network operating system s does your organiza...

Page 80: ...80 ...

Reviews: