G.shdsl Router User Manual 152
97
After enabling the DMZ, shift the cursor to
address
and press enter.
----------------------------------------------------------------------
Command: setup ip_share dmz address <ip> <1~10>
Message: Please input the following information.
Virtual IP address:
192.168.0.251
Active interface number (Enter for default) <1>:
1
----------------------------------------------------------------------
Firewall
The product supports advanced firewall. To setup the advanced firewall, you can use
firewall
to
configure.
>> Level
Configure firewall security level
pkt_filter
Configure packet filter
dos_protection Configure DoS protection
There are three level of firewall which you can setup in this product.
Level one, basic, only enables the NAT firewall and the remote management security. The NAT
firewall will take effect if NAT function is enabled. The remote management security is default to
block any WAN side connection to the device. Non-empty legal IP pool in ADMIN will block all
remote management connection except those IPs specified in the pool.
Level two, automatic, enables basic firewall security, all DoS protection, and the SPI filter function.
Level three, advanced, is an advanced level of firewall where user can determine the security level
for special purpose, environment, and applications by configuring the DoS protection and defining
an extra packet filter with higher priority than the default SPI filter. Note that, an improper filter
policy may degrade the capability of the firewall and/or even block the normal network traffic.
The firewall security level can configure via
level
command.
Packet Filtering
Packet filtering function can be configured by
pkt_filter
command. Move the cursor to
pkt_filter
and press enter.
>> active
Tigger packet filtering function
drop_flag
Drop fragment packets
add
Add packet filtering rule
delete
Delete packet filtering rule
modify
Modify packet filtering rule
exchange
Exchange the filtering rule
list
Show packet filtering table
To enable the packet filtering function, you can use
active
command.
Add the packet filtering rule via
add
command.