Page 91 / 120
Scroll up to view Page 86 - 90
LTE/WiMAX DM Outdoor | User Manual
Dual Mode CPE7000 Manual
91
91
Firewall | L3 DATA Filter
Firewall > L3 DATA Filter
L3 DATA filter disallow/allows packets with designated ports and IP address to the device which is
not CPE.
Click
“
Add +
”
button to add a new rule, clicking
“
Delete
”
icon (
) to delete the rule.
Name:
The name of the rule.
Action:
“
Permit
”
or
“
Deny
”
allowing or rejecting the traffic.
Interface:
Select which interface users want to block/allow the traffic from. Available
options are
“
WAN
”
,
“
LAN
”
, or
“
BOTH
”
.
Log:
Select
“
Log
”
to have log records, or
“
No Log
”
to disable it. ( users will not see it , the log
is printed in the console.)
Protocol:
Protocol to filter. Available options are TCP, UDP, ICMP, or ANY.
Port:
The port number to filter.
Src IP:
The source IP to filter.
Page 92 / 120
LTE/WiMAX DM Outdoor | User Manual
Dual Mode CPE7000 Manual
92
92
Dst IP:
The destination IP to filter.
Src Mask:
It would be used with Src IP to form a subnet.
Dst Mask:
It would be used with Dst IP to form a subnet.
Enable:
Enable/Disable the rule.
Cancel button
Reset fields to the last saved values.
Apply button
Commit the changes made and save to the CPE device, some
services will be reloaded.
Page 93 / 120
LTE/WiMAX DM Outdoor | User Manual
Dual Mode CPE7000 Manual
93
93
Firewall | L2 Filter
Firewall > L2 Filter
L2 filter can filter packets in layer 2 of the 7-layer OSI model of computer network.
Click
“
Add +
”
button to add a new rule, clicking
“
Delete
”
icon (
) to delete the rule.
Name:
Enter the name of the rule.
Action:
Select
“
Permit
”
or
“
Deny
”
to allow or reject the traffic.
Interface:
only LAN.
Log:
Select
“
Log
”
to have log records, or
“
No Log
”
to disable it. (Users will not see it, the log
is printed in the console.)
Ether Type:
EtherType is a two-octet field in an Ethernet frame, which is used to indicate
which protocol is encapsulated in the payload of an Ethernet frame. Enter the Ether Type
code (Range: 0600~FFFF) according to the protocol you use.
Vlan ID:
IEEE 802.1Q is the networking standard that supports Virtual LANs (VLANs) in
Ethernet network; and VLAN ID is the identification of the VLAN. VLAN ID is a unique VLAN
Page 94 / 120
LTE/WiMAX DM Outdoor | User Manual
Dual Mode CPE7000 Manual
94
94
identifier, the number range is from 0 to 4095.
Port: The
port number to filter.
Src MAC:
The source MAC to filter.
Dst MAC:
The destination MAC to filter.
Src Mask:
The source Mask to filter.
Dst Mask:
The destination Mask to filter.
Enable:
Enable/Disable the rule.
Cancel button
Reset fields to the last saved values.
Apply button
Commit the changes made and save to the CPE device, some
services will be reloaded.
The format of MAC address should be XX:XX:XX:XX:XX:XX
Page 95 / 120
LTE/WiMAX DM Outdoor | User Manual
Dual Mode CPE7000 Manual
95
95
Firewall | Access Restriction
Firewall > Access Restriction
Access Restriction provides a comprehensive way to control the network. First, users can block all
the network traffic at certain time. For example, deny all the traffic from 10:00 to 12:00. Second,
users can deny devices with certain MAC address accessing the network. Third, users can deny
clients accessing certain URL.
Click
“
Add +
”
button to add a new rule, clicking
“
Delete
”
icon (
) to delete the rule.
After pressing
“
Apply
”
button, the access restriction rule is graphically presented in the
following manner. Click
to edit, and click
to fix it.
Firewall > Access Restriction (Digest)