QuadroFXO Manual II: Administrator's Guide
Administrator’s Menus
QuadroFXO; SW Version 5.1.x
76
The easyDNS Partner text field is used for a special parameter required by the DynDNS provider easyDNS.
Selecting the Create Custom HTTP GET Request radio button will switch to the custom settings of the DynDNS service. Normally, the DynDNS
provider uses HTTP get requests to map dynamic IP addresses to host names. If the HTTP receive request is known to you, choose the Create
Custom HTTP GET Request radio button and enter the appropriate value into the URL text field.
The selection enables the following optional settings:
The URL text field requires the complete request to be sent to the DynDNS server. Normally it has the following format:
http://www.server.domain:port/scriptpath/scriptname?param1=value1¶m2=value2
The request modifies the nameserver database so that the hostname will be resolved to the new IP address.
The Basic Authentication checkbox enables the encoding of the username and password entered in the text fields above, and then uses the Basic
Authentication method to notify the provider about the user authentication settings.
Most of the DynDNS providers require an authentication for security. Authentication parameters can be provided in the URL text field to be used for
the HTTP get request. The Basic Authentication checkbox can be selected if no authentication parameters to be provided.
Firewall and NAT
The Firewall Configuration page allows setting up a firewall, configuring the security level and enabling the NAT and IDS services of Quadro.
A Firewall is a security service configured by the Quadro administrator based on various criteria. The firewall allows or blocks traffic based on
policies, services and/or IP addresses. The firewall has several levels of security policies (low, medium or high). The administrator may add
additional service-based rules. Filtering rules will take effect only if the Firewall has been enabled and are independent from the selected firewall
security level.
NAT (Network Address Translation) is used to allow Quadro LAN members to connect to the Internet using Quadro's WAN IP address. The
Quadro/NAT also handles forwarding incoming packets from the WAN to the PCs or devices on Quadro’s LAN.
The IDS (Intrusion Detection System) is a type of firewall, but together with deleting dangerous packets or packets containing intrusion attacks, IDS
generates a log file with information about these dropped packets and the senders responsible for those packets. The log can be viewed on the
page and notifications about them can be sent to the user in various ways such as e-mail, flashing LED and display notification.
The Firewall Configuration page offers the following
components:
The Enable IDS checkbox selection enables the Intrusion
Detection System. The Enable NAT checkbox selection enables
Network Address Translation.
The Enable Firewall checkbox selection enables the firewall
security service. The firewall security level has to be selected,
otherwise the firewall cannot be enabled.
The Firewall Security radio buttons are the following:
•
Low Security - Everything that is not explicitly forbidden
will be allowed. This security level doesn't block anything
by default. It is recommended if the device is already
located behind another firewall or if every filter has been
configured correctly.
•
Medium Security - Traffic originating from the LAN side
may pass and traffic from the WAN side will be blocked by
default. This is the recommended security level.
•
High Security - Everything that is not explicitly allowed will
be blocked, including traffic from the LAN side.
The
Quadro’s privacy can be configured.
The View Filter Rules link opens the
page.
Fig. II-134: Firewall and NAT Settings page
Advanced Firewall Settings
Advanced Firewall Settings are used to deny Ping and
Portscanning operations addressed towards the device. With
these features enabled, Quadro will answer with inscrutable
messages to the Ping and Portscanning operations.
Please Note:
Operations are available only when the firewall is
page.
This page offers the following components:
The Ping Stealth checkbox selection prohibits a Ping operation
toward Quadro from its WAN.
The Fool Portscanner checkbox selection prohibits Quadro
portscanning from its WAN. As a reply to a Portscanning
operation, "network unreachable" or "host unreachable"
feedback messages will be sent.
Fig. II-135: Advanced Firewall Settings page