Page 51 / 83 Scroll up to view Page 46 - 50
41
Improving Security
Linksys E-Series
How to control access to your wireless
network
For
ALL
Why would I need to control access to my wireless network?
If you used
Cisco Connect to configure your router, your wireless network is already secure°
By default, Cisco Connect enables industry-standard
WPA
(Wi-Fi Protected
Access) security using WPA2/WPA mixed mode° Cisco Connect configures your
network with a complex, 10-character password that is almost impossible
to compromise° If you set up your wireless network manually and have not
enabled wireless security, your wireless network will be an “open” network that
almost anyone nearby with a Wi-Fi-enabled device could access°
What is MAC filtering?
The best way to secure your wireless network is to use
Cisco Connect to automatically configure and secure it° However, if you choose
not to use the built-in security features of your router, you can still control
access to your wireless network using MAC filtering°
Every network device has a unique, 12-digit
MAC
(Media Access Control)
address° Using MAC filtering, you can allow only known MAC addresses onto
your network° You can also exclude specific MAC addresses or deny them
access to your wireless network°
Example
: Because each MAC filtering configuration is unique, the following
procedure uses the simplified example of setting up MAC filtering to allow one
wireless device access to the network°
To set up MAC filtering to allow one wireless device access to your
network:
Wireless > Wireless MAC Filter
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 22)°
2.
Click the
Wireless
tab, then click the
Wireless MAC Filter
page°
3.
Click
Enabled
°
4.
Select
Permit
°
TIP
You can also use MAC filtering to prevent specific PCs from
accessing your network by selecting
Prevent
° However, it’s easier
to permit only known devices than to exclude unknown devices°
5.
Click
Wireless Client List
° A separate window opens and displays the
currently connected devices° In the example below, the only device
permitted onto the network is the MacBook° However, two other devices
are also connected to the network°
6.
Next to the device entry, select
Save to MAC Address Filter List
, then
click
Add
° The Mac Address Filter List is updated with the MAC address of
the device you added°
Page 52 / 83
42
Improving Security
Linksys E-Series
7.
Click
Save Settings
at the bottom of the page°
8.
Click
Wireless Client List
again to check the updated device list° Only
the device you selected remains on the network°
How to improve security using the built-in firewall
Why would I need to change my security settings?
By default, the firewall
settings in your router have been optimized for most home environments, so
no changes are needed° The
SPI
(Stateful Packet Inspection) firewall is enabled
by default° In addition, anonymous Internet requests and IDENT requests are
filtered by default° All web filters are disabled, because enabling them may
cause problems for sites that depend on ActiveX controls, Java, or cookies°
General firewall settings
To change your firewall settings:
Security->Firewall
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 22)°
2.
Click the
Security
tab, then click the
Firewall
page°
3.
Select each setting that you want to change°
TIP
For descriptions of the filters, click
Help
on the right side of the
screen° More complete descriptions are included below°
SPI Firewall Protection
—This helps protect your local network from
Internet threats° This option is enabled by default° On some router
models, this setting is separated into IPv6 and IPv4 options so that
each can be handled separately°
CAUTION
To help protect your network, you should keep this option enabled°
Filter Anonymous Internet Requests
—This filter blocks Internet
requests from unknown sources such as ping requests° This option is
enabled by default°
Filter Multicast
—Multicasting allows a single transmission to
simultaneously reach specific recipients within your local network°
Select this option to block multicasting° This option is disabled by
default°
Filter Internet NAT Redirection for IPv4 Internet Only
—This filter
prevents a local computer from using a URL or Internet IP address
to access the local server° Select this option to enable the filter° This
option is disabled by default° On some router models, this setting
applies to IPv4 Internet only°
Page 53 / 83
43
Improving Security
Linksys E-Series
Filter IDENT (Port 113)
—This filter prevents port 113 from being
scanned by devices from the Internet° This option is enabled by
default°
Proxy
—This filter blocks the use of Internet proxy servers° To deny
proxy requests, select this option° Proxy access is allowed by default°
Java
—This filter blocks Java, so you may not be able to access Java
content on websites° To deny Java requests, select this option° Java
content is allowed by default°
ActiveX
—This filter blocks ActiveX, so you may not be able to access
ActiveX content on websites° To deny ActiveX requests, select this
option° ActiveX content is allowed by default°
Cookies
—This filter blocks cookies, which are data stored on your
computer and used by websites when you interact with them° To deny
cookie requests, select this option° Cookie usage is allowed by default°
4.
Click
Save Settings
to update your changes°
IPv6 firewall settings
For
E1500
E2500
E3200
E4200
On some router models, the IPv6 firewall lets you customize IPv6 port services
for applications° When users send these types of requests to your network via
the Internet, the router will allow those requests to the appropriate computers°
NOTE
To use your router’s IPv6 Internet connectino settings, IPv6 service
from your ISP (Internet service provider) is required° For more
information on this service, ask your ISP°
To set IPv6 firewall settings:
Applications & Gaming->IPv6 Firewall
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 22)°
2.
Click the
Applications & Gaming
tab, then click the
IPv6 Firewall
page°
3.
Select each setting that you want to change°
Description
—Enter a description of the application°
IPv6 Address
—Enter the IPv6 address of the computer that should
receive the traffic°
Allow
—Select the protocol(s) and range of port(s) used by incoming
traffic°
4.
Click
Apply
to save your changes° The
Allowing Ports
section lists the
settings you have saved°
5.
To change a saved setting, click
Edit
° To delete a saved setting, click
Remove
°
Page 54 / 83
44
Using an External Drive
Linksys E-Series
44
How to configure storage
For
E3200
E4200
Why would I need to configure storage?
By default, when you connect a
storage device to your router, the entire contents of the device are available for
read and write access to anyone on your local network (no login credentials are
required)° However, you can also create shared folders that you can configure
to share only with specified groups°
To control access to the USB drive attached to your router, you need to
perform two tasks:
1.
Create one or more shared folders (see “How to create shared folders”
below)
2.
Manage group and User Access to Shared Folders (see “How to share
folders and set access rights” on page 49)
How to create shared folders
To create a shared folder:
Storage > Disk
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 22)°
2.
Click the
Storage
tab, then click the
Disk
page°
3.
Click
Create Share
next to the partition you want to share° The
Shared
Folder
screen opens°
4.
If you want to share the entire partition, select
Share Entire Partition
,
then click
Save Settings
at the bottom of the screen°
- OR –
If you want to share a specific folder:
a.
Enter a unique name in the
Display Name
field°
b.
Click
Select
next to the folder name you want to share°
To open a subfolder, click
Enter into Folder
°
To navigate to a previous folder, click
Return to Upper Folder
°
To create a new folder, type the name into the
New Folder
field,
then click
Create
°
Using an External Drive
Page 55 / 83
45
Using an External Drive
Linksys E-Series
c.
Click
Save Settings
at the bottom of the screen, then repeat the
above steps to add more folders that you want to share°
How to manage group and user access to shared
folders
To manage access to shared folders, you need to disable Anonymous Disk
Access, then create groups and user accounts on your router° Access to the
router is controlled by user accounts, but access to shared folders is controlled
by groups°
1.
Disable Anonymous Disk Access (see “How to disable anonymous disk
access” on page 45)°
2.
Create a group that you will use to assign rights to a shared folder°
3.
Create users and assign those users to the group°
4.
Add the group to the shared folder that you want to control°
How to disable anonymous disk access
By default, no password is needed for read and write access to the drive° Before
you can manage group and user access to shared folders, you must disable
anonymous disk access°
To disable anonymous disk access:
Storage > Administration
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 22)°
2.
Click the
Storage
tab, then click the
Administration
page°
3.
Next to
Anonymous Disk Access
, select
Disabled
°
4.
Click
Save Settings
at the bottom of the screen°
How to create a group
By default, the default Admin group has read and write access to all shared
folders° By default, the Guest group has read only access and has no access
rights to any of the shared folders°
IMPORTANT
More than one group can be configured with access to a shared
folder, but a user can be a member of only one group°
To create a group:
Storage > Administration
1.
Log into the browser-based utility (see “How to open the browser-based
utility” on page 22)°
2.
Click the
Storage
tab, then click the
Administration
page°

Rate

4 / 5 based on 1 vote.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top