Section 3 – Configuration
D-Link DIR-320 User Manual
50
Firewall & DMZ
The Firewall & DMZ menu is used to define enforce specific predefined policies intended to
protect against certain common types of attacks.
A DoS "denial-of-service" attack is characterized by an explicit attempt by attackers to
prevent legitimate users of a service from using that service. Examples include: attempts to
"flood" a network, thereby preventing legitimate network traffic, attempts to disrupt
connections between two machines, thereby preventing access to a service, attempts to
prevent a particular individual from accessing a service, or, attempts to disrupt service to a
specific system or person. To enable this function, tick the
Enable DoS Prevention
checkbox.
Firewall Rules
To configure rules for the firewall, modify the following fields and click the
Save Settings
button at the top of the window to set the rule in the Routers memory. Newly configured
firewall rules will be displayed in the
Firewall Rules List
at the bottom of the window.
Internal Attack Prevention
This is used for ARP attacks. The router will drop ARP inquiry packets when it detects an
extraordinarily high volume of ARP requests.
DMZ Host
Firewalls may conflict with certain interactive applications such as video conferencing or
playing Internet video games. For these applications, a firewall bypass can be set up using
a DMZ IP address. The DMZ IP address is a “visible” address and does not benefit from the
full protection of the firewall function. Therefore it is advisable that other security
precautions be enabled to protect the other computers and devices on the LAN. It may be
wise to use isolate the device with the DMZ IP address from the rest of the LAN.
For example, if you want to use video conferencing and still use a firewall, you can place
the server in the DMZ. The IP address of this server will then be the DMZ IP address. You
can designate the server’s IP address as the DMZ by typing in the IP address in the
DMZ
IP Address
space provided and then enabling its status by ticking the
Enable DMZ Host
checkbox. Click the
Save Settings
button at the top of the window when you are finished.