Page 126 / 351 Scroll up to view Page 121 - 125
126
4.
Click on the radio button to select the protection level you want. Click
Submit
.
Changing the BreakWater setting does
not
require a restart to take effect. This makes
it easy to change the setting “on the fly,” as your needs change.
Page 127 / 351
127
Security
TIPS for making your BreakWater Basic Firewall Selection
Basic Firewall Background
As a device on the Internet, a Netopia Gateway requires an IP address in order to send or
receive traffic.
The IP traffic sent or received have an associated application port which is dependent on
the nature of the connection request. In the IP protocol standard the following session
types are common applications:
By receiving a response to a scan from a port or series of ports (which is the expected
behavior according to the IP standard), hackers can identify an existing device and gain a
potential opening for access to an internet-connected device.
To protect LAN users and their network from these types of attacks, BreakWater offers
three levels of increasing protection.
The following tables indicate the
state of ports associated with session types
, both on
the WAN side and the LAN side of the Gateway.
Application
Select this Level
Other Considerations
Typical Internet usage
(browsing, e-mail)
SilentRunning
Multi-player online
gaming
ClearSailing
Set Pinholes
; once defined, pinholes will be
active whenever ClearSailing is set.
Restore SilentRunning
when finished.
Going on vacation
LANdLocked
Protects your connection while your away.
Finished online use for
the day
LANdLocked
This protects you instead of disconnecting your
Gateway connection.
Chatting online or using
instant messaging
ClearSailing
Set Pinholes
; once defined, pinholes will be
active whenever ClearSailing is set.
Restore SilentRunning
when finished.
ICMP
HTTP
FTP
SNMP
telnet
DHCP
Page 128 / 351
128
This table shows how inbound traffic is treated.
Inbound
means the traffic is coming from
the WAN into the WAN side of the Gateway.
This table shows how outbound traffic is treated.
Outbound
means the traffic is coming
from the LAN-side computers into the LAN side of the Gateway.
Gateway: WAN Side
BreakWater Setting >>
ClearSailing
SilentRunning
LANdLocked
Port
Session Type
--------------Port State-----------------------
20
ftp data
Enabled
Disabled
Disabled
21
ftp control
Enabled
Disabled
Disabled
23
telnet external
Enabled
Disabled
Disabled
23
telnet Netopia server
Enabled
Disabled
Disabled
80
http external
Enabled
Disabled
Disabled
80
http Netopia server
Enabled
Disabled
Disabled
67
DHCP client
Enabled
Enabled
Disabled
68
DHCP server
Not Applicable
Not Applicable
Not Applicable
161
snmp
Enabled
Disabled
Disabled
ping (ICMP)
Enabled
Disabled
Disabled
Gateway: LAN Side
BreakWater Setting >>
ClearSailing
SilentRunning
LANdLocked
Port
Session Type
--------------Port State-----------------------
20
ftp data
Enabled
Enabled
Disabled
21
ftp control
Enabled
Enabled
Disabled
23
telnet external
Enabled
Enabled
Disabled
23
telnet Netopia server
Enabled
Enabled
Enabled
80
http external
Enabled
Enabled
Disabled
80
http Netopia server
Enabled
Enabled
Enabled
67
DHCP client
Not Applicable
Not Applicable
Not Applicable
68
DHCP server
Enabled
Enabled
Enabled
161
snmp
Enabled
Enabled
Enabled
ping (ICMP)
Enabled
Enabled
WAN
- Disabled
LAN
-
Local Address
Only
Page 129 / 351
129
Security
NOTE:
The Gateway’s WAN DHCP client port in SilentRunning mode is
enabled
. This
feature allows end users to continue using DHCP-served IP addresses from
their Service Providers, while having no identifiable presence on the Internet.
Page 130 / 351
130
Link:
IPSec
When you click on the
IPSec
link, the IPSec configuration screen appears.
Your Gateway can support two mechanisms for IPSec tunnels:
IPSec PassThrough
supports Virtual Private Network (VPN) clients running on LAN-
connected computers. Normally, this feature is enabled.
You can disable it if your LAN-side VPN client includes its own NAT interoperability
option.
Uncheck the
Enab
le IPSec P
assthr
ough
checkbox.
SafeHarbour VPN IPSec
is a keyed feature that you must purchase. (
See “Install
Keys” on page 184.
) It enables Gateway-terminated VPN support.

Rate

4.7 / 5 based on 3 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top