Page 91 / 198 Scroll up to view Page 86 - 90
Chapter 8 NAT Configuration
F
IGURE
112 V
IRTUAL
S
ERVER
However, you may want to expose your network to the Internet in
limited and controlled ways in order to enable some applications
to work from the
LAN
(for example, game, voice, and chat ap-
plications) and to enable Internet access to servers in the home
network. The port forwarding feature supports both functionality.
This topic is also referred to as Local Servers.
The port forwarding page is used to define applications that require
special handling by the 931WII. All you need to do is to select the
application protocol and the local IP address of the computer that
is using or providing the service. You can also add new protocols,
besides the most common ones provided by the 931WII.
For example, if you want to use a File Transfer Protocol (
FTP
) appli-
cation on one of your PCs, simply select FTP from the list and enter
the local IP address or host name of the designated computer. All
FTP-related data arriving at the 931WII from the Internet hence-
forth is forwarded to the specific computer.
Similarly, you can grant Internet users access to servers inside
your home network, by identifying each service and the PC that
provides it. This is useful, for example, if you want to host a Web
server inside your home network.
When an Internet user points his/her browser to 931WII external
IP address, the gateway forwards the incoming
HTTP
request to
your web server. With one external IP address (the 931WII main
IP address), different applications can be assigned to your LAN
computers, however, each type of application is limited to use one
computer.
For example, you can define that FTP uses address X to reach com-
puter A and Telnet also uses address X to reach computer A. But
attempting to define FTP to use address X to reach both computer
A and B fails. The 931WII, therefore, provides the ability to add
additional public IP addresses to port forwarding rules, which you
must obtain from your ISP, and enter into the IP addresses pool.
Then, you can define FTP to use address X to reach computer A
and address Y to reach computer B.
Confidential and Proprietary Information of ZTE CORPORATION
85
Page 92 / 198
ZXDSL 931WII Operation manual
Additionally, port forwarding enables you to redirect traffic to a
different port instead of the one to which it was designated. For
example, if you have a Web server running on your PC on port
8080 and you want to grant access to this server to any one who
accesses the 931WII via HTTP, do as follows:
1.
Define a port forwarding rule for the HTTP service, with the PC
IP or host name.
2.
Specify 8080 in the Forward to Port’ field.
All incoming HTTP traffic is forwarded to the PC running the web
server on port 8080. When setting a port forwarding service, en-
sure that the port is not already used by another application, which
may stop functioning. A common example is when using SIP sig-
naling in Voice over IP, the port used by the gateway VoIP appli-
cation (5060) is the same port on which port forwarding is set for
LAN SIP agents.
Note:
Some applications, such as FTP, TFTP, PPTP, and H323, require the
support of special specific ALG modules in order to work inside the
home network.
Data packets associated with these applications
contain information that allows them to be routed correctly.
An
ALG is needed to handle these packets and ensure that they reach
their intended destinations. The 931WII is equipped with a robust
list of ALG modules in order to enable maximum functionality in
the home network.
The ALG is automatically assigned based on
the destination port.
Adding Port
Forwarding
1.
Select
Advanced Setup > NAT > Virtual Servers
to display
the interface as shown in
F
i
g
u
r
e
1
1
3
.
F
IGURE
113 V
IRTUAL
S
ERVERS
O
VERVIEW
2.
Click
Add
to display the interface as shown in
F
i
g
u
r
e
1
1
4
.
86
Confidential and Proprietary Information of ZTE CORPORATION
Page 93 / 198
Chapter 8 NAT Configuration
F
IGURE
114 A
DDING
V
IRTUAL
S
ERVERS
3.
Select the dedicated WAN interface to be
Use Interface
.
4.
Select a service or enter a custom server.
5.
Enter the
Server IP Address
of the computer that provides
the service (the server in the Local Host field).
Note:
Note that unless an additional external IP address is added,
only one LAN computer can be assigned to provide a specific
service or application.
6.
Set External Port Start and External Port End.
7.
Select Protocol.
8.
Set Internal Port Start and Internal Port End.
9.
Click
Save/Apply
to
save
the
configuration
so
that
the
changes can take effect.
Deleting Port
Forwarding
Select the
Remove
check box in the table and click
Remove
to
apply the settings.
Port Triggering
If you configure port triggering for a certain application, you need
to determine a trigger port and the protocol (
TCP
or
UDP
) that this
port uses. You then assign the public ports that are to be opened
Confidential and Proprietary Information of ZTE CORPORATION
87
Page 94 / 198
ZXDSL 931WII Operation manual
for the application to this trigger port. You can select known In-
ternet services or assign ports or port blocks manually.
Add
port
Triggering
1.
Select
Advanced Setup > NAT > Port Triggering
to display
the interface as shown in
F
i
g
u
r
e
1
1
5
.
F
IGURE
115 P
ORT
T
RIGGERING
O
VERVIEW
2.
Click
Add
to display the interface as shown in
F
i
g
u
r
e
1
1
6
.
F
IGURE
116 A
DDING
P
ORT
T
RIGGERING
3.
Select the dedicated WAN interface to be
Use Interface
.
4.
Select the required application from the
Select One Applica-
tion
drop-down list.
5.
You can also manually enter the information in the
Custom
application
field.
6.
T
a
b
l
e
1
7
is a description of the different options.
88
Confidential and Proprietary Information of ZTE CORPORATION
Page 95 / 198
Chapter 8 NAT Configuration
T
ABLE
17 C
USTOM
P
ORT
T
RIGGERING
C
ONFIGURATION
O
PTIONS
Field
Description
Trigger Port Start/Trigger Port
End
Enter the port that is to be
monitored for outgoing data
traffic.
Trigger Protocol
Select the protocol that is to
be monitored for outgoing data
traffic.
Open Protocol
Select the protocol that is to
be allowed for incoming data
traffic.
Open Port Start and Open Port
End
Enter the port that is to be
opened for incoming traffic.
Note:
You can use a single port number, several port numbers sepa-
rated by commas, port blocks consisting of two port numbers
separated by a dash, or any combina-tion of these, for exam-
ple 80, 90-140, 180.
7.
Click
Save/Apply
to
save
the
configuration
so
that
the
changes can take effect.
Removing Port
Triggering
Select the
Remove
check box in the table and click
Remove
to
apply the settings.
DMZ Host
The
DMZ
host feature allows one local computer to be exposed to
the Internet. This function is applicable for:
Users who want to use the Internet service for a special pur-
pose, such as an online game or video conferencing program,
that is not present in the Port Forwarding list and for which no
port range information is available.
Users who are not concerned with security and wish to expose
one computer to all services without restriction.
Confidential and Proprietary Information of ZTE CORPORATION
89

Rate

4 / 5 based on 1 vote.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top