Page 191 / 308 Scroll up to view Page 186 - 190
186
The following configuration page will appear to let you configure.
Interface:
Select from the drop-down menu the interface you want the virtual server(s) to apply.
WAN IP:
To specify the exact WAN IP address. It can be flexible while there are multiple WAN IPs
on one interface. If the WAN IP field is empty, 78VDP(O)X uses the current wan IP of this interface.
Server Name:
Select the server name from the drop-down menu.
Custom Service:
It is a kind of service to let users customize the service they want. Enter the user-
defined service name here. It is a parameter only available when users select
Custom Service
in
the above parameter.
Server IP Address:
Enter your server IP Address here. User can select from the list box for quick
setup.
External Port
Start:
Enter a port number as the external starting number for the range you want to give
access to internal network.
End:
Enter a port number as the external ending number for the range you want to give
access to internal network.
Internal Port
Start:
Enter a port number as the internal staring number.
End:
Here it will generate automatically according to the End port number of External port
and can’t be modified.
Protocol:
select the protocol this service used: TCP/UDP, TCP, UDP.
Time Schedule:
Select or set exactly when the Virtual Server works. When set to “Always On”, the
Virtual Server will work all time; and also you can set the precise time when Virtual Server works,
like 01:00 - 19:00 from Monday to Friday. Or you can select the already set timeslot in
Time
Schedule
during which the Virtual Server works. And when set to “Disable”, the rule is disabled and
there will be an icon
in the list table indicating the rule is disabled. See
Time Schedule
.
Exceptional Rule Group:
Select the exceptional group listed. It is to grant or block Virtual Server
access to a group of IPs. For example, as we set previously group 1 blocking access to
Page 192 / 308
187
172.16.1.102-172.16.1.106. If here you want to block Virtual Server access to this IP range, you can
select Group1.
Set up
1.
Select a Server Name from the drop-down menu, then the port will automatically appear, modify
some as you like, or you can just leave it as default. Remember to enter your server IP Address.
2.
Press
Apply
to conform, and the items will be list in the
Virtual Servers Setup
table.
Page 193 / 308
188
(
Means the rule is inactive)
Remove
If you don’t need a specified Server, you can remove it. Check the check box beside the item you
want to remove, then press
Remove
, it will be OK.
Page 194 / 308
189
DMZ Host
The DMZ Host is a local computer exposed to the Internet. When setting a particular internal IP
address as the DMZ Host, all incoming packets will be checked by Firewall and NAT algorithms
before being passed to the DMZ host, when a packet received does not use a port number used by
any other Virtual Server entries.
(Group Information)
DMZ Host IP Address:
Enter the IP Address of a host you want it to be a DMZ host. Select from the
list box to quick set the DMZ.
Time Schedule:
Select or set exactly when the DMZ works. When set to “Always On”, the DMZ will
work all time; and also you can set the precise time when DMZ works, like 01:00 - 19:00 from
Monday to Friday. Or you can select the already set timeslot in
Time Schedule
during which the
DMZ works. And when set to “Disable”, the DMZ Host
is disabled. See
Time Schedule
.
Exceptional Rule Group:
Select the exceptional group listed. It is to grant or block DMZ access to
a group of IPs. For example, as we set previously group 1 blocking access to 172.16.1.102-
172.16.1.106. If here you want to block DMZ Access to this IP range, you can select Group1.
Using port mapping does have security implications, since outside users are able to connect
to PCs on your network. For this reason you are advised to use specific Virtual Server
entries just for the ports your application requires instead of simply using DMZ or creating a
Virtual Server entry for “All” protocols, as doing so results in all connection attempts to your
public IP address accessing the specified PC.
Attention
If you have disabled the NAT option in the WAN-ISP section, the Virtual Server function will
hence be invalid.
If the DHCP server option is enabled, you have to be very careful in assigning the IP
addresses of the virtual servers in order to avoid conflicts. The easiest way of configuring
Virtual Servers is to manually assign static IP address to each virtual server PC, with an
address that does not fall into the range of IP addresses that are to be issued by the DHCP
server. You can configure the virtual server IP address manually, but it must still be in the
same subnet as the router.
Page 195 / 308
190
One-to-One NAT
One-to-One NAT maps a specific private/local address to a global/public IP address. If user has
multiple global/public IP addresses from your ISP, you are free to use one-to-one NAT to assign
some specific public IP for an internal IP like a public web server mapped with a global/public IP for
outside access.
Valid:
Check whether to valid the one-to-one NAT mapping rule.
WAN Interface:
Select one based WAN interface to configure the one-to-one NAT.
Global IP address:
The Global IP mapped to an internal device. It can be left empty, and under this
circumstance, it can be reached through the WAN IP of interface set in the field above.
Internal Address:
The IP address of an internal device in the LAN.
Exceptional Rule Group:
Select the exceptional group listed. It is to give or block access to a group
of IPs to the server after One-to-One NAT. For example, a server with 192.168.1.3 is mapped to
123.1.1.2 by One-to-One NAT, then the exceptional group can be designated to have or have not
access to 123.1.1.2.
For example,
you have an ADSL connection of pppoe_0_8_35/ppp0.1 interface with three fixed
global IP, and you then can assign the other two global IPs to two internal devices respectively.
If you have a WEB server (IP address: 192.168.1.3) and a FTP server (IP address: 192.168.1.4) in
local network, owning a public IP address range of 123.1.1.2 to 123.1.1.4 assigned by ISP. 123.1.1.2
is used as WAN IP address of the router, 123.1.1.3 is used for WEB server and 123.1.1.4 is used for
FTP server. With One-to-One NAT, the servers with private IP addresses can be accessed at the
corresponding valid public IP addresses.

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top