Page 251 / 351 Scroll up to view Page 246 - 250
251
CONFIG Commands
Command Line Interface Preference Settings
You can set command line interface preferences to customize your environment.
set preference verbose { on | off }
Specifies whether you want command help and prompting information displayed. By
default, the command line interface verbose preference is turned off. If you turn it on, the
command line interface displays help for a node when you navigate to that node.
set preference more
lines
Specifies how many lines of information you want the command line interface to display at
one time. The lines argument specifies the number of lines you want to see at one time.
The range is 1-65535. By default, the command line interface shows you 22 lines of text
before displaying the prompt:
More …[y|n] ?
.
If you enter 1000 for the
lines
argument, the command line interface displays information
as an uninterrupted stream (which is useful for capturing information to a text file).
Page 252 / 351
252
Port Renumbering Settings
If you use NAT pinholes to forward HTTP or telnet traffic through your Motorola Netopia®
Gateway to an internal host, you must change the port numbers the Motorola Netopia®
Gateway uses for its own configuration traffic. For example, if you set up a NAT pinhole to
forward network traffic on Port 80 (HTTP) to another host, you would have to tell the Motor-
ola Netopia® Gateway to listen for configuration connection requests on a port number
other than 80, such as 6080.
After you have changed the port numbers the Motorola Netopia® Gateway uses for its con-
figuration traffic, you must use those port numbers instead of the standard numbers when
configuring the Motorola Netopia® Gateway. For example, if you move the router's Web ser-
vice to port “6080” on a box with a system (DNS) name of “superbox”, you would enter the
URL
http://superbox:6080
in a Web browser to open the Motorola Netopia® Gateway
graphical user interface. Similarly, you would have to configure your telnet application to
use the appropriate port when opening a configuration connection to your Motorola Neto-
pia® Gateway.
set servers web-http [ 1 - 65534 ]
Specifies the port number for HTTP (web) communication with the Motorola Netopia® Gate-
way. Because port numbers in the range 0-1024 are used by other protocols, you should
use numbers in the range 1025-65534 when assigning new port numbers to the Motorola
Netopia® Gateway web configuration interface. A setting of
0
(zero) will turn the server off.
set servers telnet-tcp [ 1 - 65534 ]
Specifies the port number for telnet (CLI) communication with the Motorola Netopia® Gate-
way. Because port numbers in the range 0-1024 are used by other protocols, you should
use numbers in the range 1025-65534 when assigning new port numbers to the Motorola
Netopia® Gateway telnet configuration interface. A setting of
0
(zero) will turn the server
off.
NOTE:
You cannot specify a port setting of
0
(zero) for both the web and telnet ports
at the same time. This would prevent you from accessing the Gateway.
Page 253 / 351
253
CONFIG Commands
Security Settings
Security settings include the Firewall, Packet Filtering, Stateful Inspection, and IPSec
parameters. Some of the security functionality is keyed.
Firewall Settings (for BreakWater Firewall)
set security firewall option [ ClearSailing | SilentRunning |
LANdLocked ]
BreakWater Basic Firewall.
BreakWater delivers an easily selectable set of pre-config-
ured firewall protection levels. For simple implementation these settings (comprised of
three levels) are readily available through Motorola Netopia®’s embedded web server
interface.
BreakWater Basic Firewall’s three settings are:
ClearSailing
ClearSailing, BreakWater's default setting, supports both inbound and outbound traffic.
It is the only basic firewall setting that fully interoperates with all other Motorola Neto-
pia® software features.
SilentRunning
Using this level of firewall protection allows transmission of outbound traffic on pre-con-
figured TCP/UDP ports. It disables any attempt for inbound traffic to identify the Gate-
way. This is the Internet equivalent of having an
unlisted number
.
LANdLocked
The third option available turns off all inbound and outbound traffic, isolating the LAN
and disabling all WAN traffic.
NOTE:
BreakWater Basic Firewall operates independent of the NAT functionality on
the Gateway.
Page 254 / 351
254
TIPS for making your BreakWater Basic Firewall Selection
Basic Firewall Background
As a device on the Internet, a Motorola Netopia® Gateway requires an IP address in order
to send or receive traffic.
The IP traffic sent or received have an associated application port which is dependent on
the nature of the connection request. In the IP protocol standard the following session
types are common applications:
By receiving a response to a scan from a port or series of ports (which is the expected
behavior according to the IP standard), hackers can identify an existing device and gain a
potential opening for access to an internet-connected device.
To protect LAN users and their network from these types of attacks, BreakWater offers
three levels of increasing protection.
The following tables indicate the
state of ports associated with session types
, both on
the WAN side and the LAN side of the Gateway.
Application
Select this Level
Other Considerations
Typical Internet usage
(browsing, e-mail)
SilentRunning
Multi-player online
gaming
ClearSailing
Set Pinholes
; once defined, pinholes will be
active whenever ClearSailing is set.
Restore SilentRunning
when finished.
Going on vacation
LANdLocked
Protects your connection while your away.
Finished online use for
the day
LANdLocked
This protects you instead of disconnecting your
Gateway connection.
Chatting online or using
instant messaging
ClearSailing
Set Pinholes
; once defined, pinholes will be
active whenever ClearSailing is set.
Restore
SilentRunning
when finished.
ICMP
HTTP
FTP
SNMP
telnet
DHCP
Page 255 / 351
255
CONFIG Commands
This table shows how inbound traffic is treated.
Inbound
means the traffic is coming from
the WAN into the WAN side of the Gateway.
This table shows how outbound traffic is treated.
Outbound
means the traffic is coming
from the LAN-side computers into the LAN side of the Gateway.
Gateway: WAN Side
BreakWater Setting >>
ClearSailing
SilentRunning
LANdLocked
Port
Session Type
--------------Port State-----------------------
20
ftp data
Enabled
Disabled
Disabled
21
ftp control
Enabled
Disabled
Disabled
23
telnet external
Enabled
Disabled
Disabled
23
telnet Motorola Netopia®
server
Enabled
Disabled
Disabled
80
http external
Enabled
Disabled
Disabled
80
http Motorola Netopia® server
Enabled
Disabled
Disabled
67
DHCP client
Enabled
Enabled
Disabled
68
DHCP server
Not Applicable
Not Applicable
Not Applicable
161
snmp
Enabled
Disabled
Disabled
ping (ICMP)
Enabled
Disabled
Disabled
Gateway: LAN Side
BreakWater Setting >>
ClearSailing
SilentRunning
LANdLocked
Port
Session Type
--------------Port State-----------------------
20
ftp data
Enabled
Enabled
Disabled
21
ftp control
Enabled
Enabled
Disabled
23
telnet external
Enabled
Enabled
Disabled
23
telnet Motorola Netopia®
server
Enabled
Enabled
Enabled
80
http external
Enabled
Enabled
Disabled
80
http Motorola Netopia® server
Enabled
Enabled
Enabled
67
DHCP client
Not Applicable
Not Applicable
Not Applicable

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top