background image

Disabling this option, however, only disables VPN if the appropriate VPN ALG is also 
disabled. 

 Application Level Gateway (ALG) Configuration 

Here you can enable or disable ALGs. Some protocols and applications require special handling of the IP payload 

to make them work with network address translation (NAT). Each ALG provides special handling for a specific 
protocol or application. A number of ALGs for common applications are enabled by default. 

PPTP

Allows multiple machines on the LAN to connect to their corporate networks using PPTP 
protocol. When the PPTP ALG is enabled, LAN computers can establish PPTP VPN 

connections either with the same or with different VPN servers. When the PPTP ALG is 
disabled, the router allows VPN operation in a restricted way -- LAN computers are 

typically able to establish VPN tunnels to different VPN Internet servers but not to the 
same server. The advantage of disabling the PPTP ALG is to increase VPN performance. 

Enabling the PPTP ALG also allows incoming VPN connections to a LAN side VPN server 
(refer to Advanced Virtual Server). 

IPSec (VPN) 

Allows multiple VPN clients to connect to their corporate networks using IPSec. Some VPN 

clients support traversal of IPSec through NAT. This option may interfere with the 
operation of such VPN clients. If you are having trouble connecting with your corporate 

network, try disabling this option. 
Check with the system administrator of your corporate network whether your VPN client 
supports NAT traversal. 
Note that L2TP VPN connections typically use IPSec to secure the connection. To achieve 

multiple VPN pass-through in this case, the IPSec ALG must be enabled. 

RTSP

Allows applications that use Real Time Streaming Protocol to receive streaming media 
from the internet. QuickTime and Real Player are some of the common applications using 

this protocol. 

Windows/MSN 
Messenger 

Supports use on LAN computers of Microsoft Windows Messenger (the Internet 
messaging client that ships with Microsoft Windows) and MSN Messenger. The SIP ALG 

must also be enabled when the Windows Messenger ALG is enabled. 

FTP 

Allows FTP clients and servers to transfer data across NAT. Refer to the Advanced Virtual

 

Server page if you want to host an FTP server. 

H.323 

(Netmeeting) 

Allows H.323 (specifically Microsoft Netmeeting) clients to communicate across NAT. Note 

that if you want your buddies to call you, you should also set up a virtual server for 
NetMeeting. Refer to the Advanced Virtual Server page for information on how to set up

 

a virtual server. 

SIP

Allows devices and applications using VoIP (Voice over IP) to communicate across NAT. 
Some VoIP applications and devices have the ability to discover NAT devices and work 

around them. This ALG may interfere with the operation of such devices. If you are 
having trouble making VoIP calls, try turning this ALG off. 

Wake-On-LAN 

This feature enables forwarding of "magic packets" (that is, specially formatted wake-up 

packets) from the WAN to a LAN computer or other device that is "Wake on LAN" (WOL) 
capable. The WOL device must be defined as such on the Advanced Virtual Server page.

 

The LAN IP address for the virtual server is typically set to the broadcast address 
192.168.0.255. The computer on the LAN whose MAC address is contained in the magic 

packet will be awakened. 

MMS 

Allows Windows Media Player, using MMS protocol, to receive streaming media from the 
internet. 

Inbound Filter

When you use the Virtual Server, Port Forwarding, or Remote Administration features to open specific ports to 

traffic from the Internet, you could be increasing the exposure of your LAN to cyberattacks from the Internet. In 
these cases, you can use Inbound Filters to limit that exposure by specifying the IP addresses of internet hosts 

that you trust to access your LAN through the ports that you have opened. You might, for example, only allow 
access to a game server on your home LAN from the computers of friends whom you have invited to play the 

games on that server. 
Inbound Filters can be used for limiting access to a server on your network to a system or group of systems. 
Filter rules can be used with Virtual Server, Gaming, or Remote Administration features. Each filter can be used 

for several functions; for example a "Game Clan" filter might allow all of the members of a particular gaming 
group to play several different games for which gaming entries have been created. At the same time an "Admin" 

filter might only allows systems from your office network to access the WAN admin pages and an FTP server you 

Copyright © Genexis BV. All rights reserved

20

Summary of Contents for OCG-2018

Page 1: ...User Manual Routed Ethernet Gateway OCG 218 OCG 220 OCG 2018 OCG 2020 PRELIMINARY JAN 2011 Copyright Genexis BV All rights reserved 1 ...

Page 2: ...asic 11 Network Settings 11 Advanced 14 Virtual Server 14 Special Applications 15 Port Forwarding 16 Routing 16 Access Control 17 Website Filter 17 Firewall Settings 18 Inbound Filter 20 Advanced Network 21 Tools 22 Administrator Settings 22 Time 22 System 23 Dynamic DNS 23 System Check 23 Schedules 24 Status 25 Device Info 25 Routing 25 Logs 25 Statistics 25 Internet Sessions 26 Firewall Holes 26...

Page 3: ...nternet connection at maximum speeds This document describes how to install and how to configure the Genexis router Product overview The front of the router The front of the router is shown below The status LEDs on the front of the router can be used to get status information A short description is given in the table below Copyright Genexis BV All rights reserved 3 ...

Page 4: ...elow A short description of the port connections is given in the table below The presence of the POTS voice ports and the F connector for CATV are depending on the configuration of your router and may not be present Copyright Genexis BV All rights reserved 4 ...

Page 5: ...ence the following LEDs should be on PWR WAN M1 and M3 If any of above mentioned LEDs is off or blinking for more than 3 minutes after powering on the router please refer to the troubleshooting section Step 3 Connect a computer to one of the routed LAN port on the Genexis router using an Ethernet cable with a RJ 45 connector Your provider can tell you which ports routing is enabled Copyright Genex...

Page 6: ...vely A standard analog telephone can be connected to the active ports using a RJ 11 connector Step 5 This step is optional and is only relevant if the router has a CATV receiver The indicator RTV indicates if the radio and television signal is enabled LED ON Your radio or television can be connected using a coaxial cable with a male F connector Copyright Genexis BV All rights reserved 6 ...

Page 7: ...ctions The Network Connections window will appear Identify the correct network card and right click on correct Local Area Connection and click Properties Select Internet Protocol TCP IP Click on Properties Make sure Obtain an IP address automatically and Obtain DNS server address automatically are selected Save the settings by clicking OK Copyright Genexis BV All rights reserved 7 ...

Page 8: ...twork The Network window will appear Click on Ethernet Make sure Using DHCP is selected Save the settings by clicking Apply Step 2 Launch the web browser and check if your connection is working If your connection is not working please refer to the troubleshooting section Copyright Genexis BV All rights reserved 8 ...

Page 9: ...t settings Step 1 Launch the web browser on your computer and enter the router s default IP address 192 168 0 1 in the address field Step 2 Log in as Admin or User which both default to a blank password It is recommended to change the password after the first log in Step 3 Configure the router to the desired configuration Information about the settings can be found in the Router settings sections ...

Page 10: ...Troubleshooting Copyright Genexis BV All rights reserved 10 ...

Page 11: ...ters and hosts on the LAN Enable RIP Enable RIP if the LAN has multiple routers or if the LAN has other hosts that listen for RIP messages such as auto IP devices or the Windows XP RIP Listener Service Accept Updates The Accept Updates option controls whether the router updates its routing tables when it receives RIP messages from other LAN devices Disable Accept Updates if not needed or if RIP me...

Page 12: ...e DHCP Server Computers or devices that use addresses from these ranges are to be manually configured Suppose you have a web server computer that has a manually configured address of 192 168 0 100 Because this falls within the managed range be sure to create a reservation for this address and match it to the relevant computer see Static DHCP Client below DHCP Lease Time The amount of time that a c...

Page 13: ...ddress This may help you keep track of which computers are assigned this way Example Game Server IP Address The LAN address that you want to reserve MAC Address To input the MAC address of your system enter it in manually or connect to the router s Web Management interface from the system and click the Copy Your PC s MAC Address button A MAC address is usually located on a sticker on the bottom of...

Page 14: ...epeat these steps for each Virtual Server Rule you wish to add With this Virtual Server entry all Internet traffic on Port 8888 will be redirected to your internal web server on port 80 at IP Address 192 168 0 50 Add Edit Virtual Server Enable Specifies whether the entry will be active or inactive Name Assign a meaningful name to the virtual server for example Web Server Several well known types o...

Page 15: ...r on the Internet Enable Specifies whether the entry will be active or inactive Name Enter a name for the Special Application Rule for example Game App which will help you identify the rule in the future Alternatively you can select from the Application Name list of common applications Application Name Instead of entering a name for the Special Application rule you can select from this list of com...

Page 16: ... rule is in effect If you do not see the schedule you need in the list of schedules go to the Tools Schedules screen and create a new schedule Inbound Filter Select a filter that controls access as needed for this rule If you do not see the filter you need in the list of filters go to the Advanced Inbound Filter screen and create a new filter Save Update Record the changes you have made into the f...

Page 17: ... out of devices on your network Use this feature as Parental Controls to only grant access to approved sites limit web access based on time or dates and or block access from applications such as peer to peer utilities or games Enable By default the Access Control feature is disabled If you need Access Control check this option Note When Access Control is disabled every device on the LAN has unrest...

Page 18: ... that are already being used Endpoint Independent Once a LAN side application has created a connection through a specific port the NAT will forward any incoming connection requests with the same port to the LAN side application regardless of their origin This is the least restrictive option giving the best connectivity and allowing some applications P2P applications in particular to behave almost ...

Page 19: ...ddress of the DMZ host However port numbers are not translated so applications on the DMZ host can depend on specific port numbers The DMZ capability is just one of several means for allowing incoming requests that might appear unsolicited to the NAT In general the DMZ host should be used only if there are no other alternatives because it is much more exposed to cyberattacks than any other system ...

Page 20: ...r page if you want to host an FTP server H 323 Netmeeting Allows H 323 specifically Microsoft Netmeeting clients to communicate across NAT Note that if you want your buddies to call you you should also set up a virtual server for NetMeeting Refer to the Advanced Virtual Server page for information on how to set up a virtual server SIP Allows devices and applications using VoIP Voice over IP to com...

Page 21: ...he related capability Deny All Prevent all WAN users from accessing the related capability LAN users are not affected by Inbound Filter Rules Advanced Network UPnP UPnP is short for Universal Plug and Play which is a networking architecture that provides compatibility among networking equipment software and peripherals This router has optional UPnP capability and can work with other UPnP devices a...

Page 22: ...ration option allows you to configure update and maintain the correct time on the router s internal system clock From this section you can set the time zone that you are in and set the Time Server Daylight saving can also be configured to automatically adjust the time when needed Time Configuration Current Router Time Displays the time currently maintained by the router If this is not correct use ...

Page 23: ...iends can enter your host name to connect to your server no matter what your IP address is Enable Dynamic DNS Enable this option only if you have purchased your own domain name and registered with a dynamic DNS service provider The following parameters are displayed when the option is enabled Server Address Select a dynamic DNS service provider from the pull down list Host Name Enter your host nam...

Page 24: ...rule Day s Place a checkmark in the boxes for the desired days or select the All Week radio button to select all seven days of the week All Day 24 hrs Select this option if you want this schedule in effect all day for the selected day s Start Time If you don t use the All Day option then you enter the time here The start time is entered in two fields The first box is for the hour and the second bo...

Page 25: ...e interest in its internal memory If there is not enough internal memory for all events logs of older events are deleted but logs of the latest events are retained The Logs option allows you to view the router logs You can define what types of events you want to view and the level of events to view This router also has external Syslog Server support so you can send the log files to a computer on y...

Page 26: ...igher priority Time Out The number of seconds of idle time until the router considers the session terminated The initial value of Time Out depends on the type and state of the connection 300 seconds UDP connections 240 seconds Reset or closed TCP connections The connection does not close instantly so that lingering packets can pass or the connection can be re established 7800 seconds Established o...

Page 27: ...n start a connection An entry of means any IP address A policy name entry means that the connection is limited to that policy Protocol The internet protocol that this connection is allowed to use Private Ports The LAN side ports used for the connection Public Ports The WAN side ports used for the connection Type Specifies both how the hole was created and what the hole is used for For example Virt...

Reviews: