Page 146 / 296 Scroll up to view Page 141 - 145
Chapter 13 Firewall
NBG334W User’s Guide
146
The following table describes the labels in this screen.
13.4
Services Screen
Click
Security
>
Firewall
>
Services
. The screen appears as shown next.
If an outside user attempts to probe an unsupported port on your NBG334W, an ICMP
response packet is automatically returned. This allows the outside user to know the NBG334W
exists. Use this screen to prevent the ICMP response packet from being sent. This keeps
outsiders from discovering your NBG334W when unsupported ports are probed.
You can also use this screen to enable service blocking, enter/delete/modify the services you
want to block and the date/time you want to block them.
Figure 81
Security > Firewall > Services
Table 55
Security > Firewall > General
LABEL
DESCRIPTION
Enable Firewall
Select this check box to activate the firewall. The NBG334W performs access
control and protects against Denial of Service (DoS) attacks when the firewall is
activated.
Packet Direction
This is the direction of travel of packets.
Firewall rules are grouped based on the direction of travel of packets to which they
apply.
Log
Select whether to create a log for packets that are traveling in the selected
direction when the packets are blocked (
Log All
) or forwarded (
Log Forward
). Or
select
Not Log
to not log any records.
To log packets related to firewall rules, make sure that
Access Control
under
Log
is selected in the
Logs
>
Log Settings
screen.
Apply
Click
Apply
to save the settings.
Reset
Click
Reset
to start configuring this screen again.
Page 147 / 296
Chapter 13 Firewall
NBG334W User’s Guide
147
The following table describes the labels in this screen.
Table 56
Security > Firewall > Services
LABEL
DESCRIPTION
ICMP
Internet Control Message Protocol is a message control and error-reporting
protocol between a host server and a gateway to the Internet. ICMP uses Internet
Protocol (IP) datagrams, but the messages are processed by the TCP/IP software
and directly apparent to the application user.
Respond to Ping
on
The NBG334W will not respond to any incoming Ping requests when
Disable
is
selected. Select
LAN
to reply to incoming LAN Ping requests.
Select
WAN
to reply
to incoming WAN Ping requests. Select
Guest WLAN
to reply to incoming Guest
WLAN Ping requests.
Otherwise select
LAN & WAN & Guest WLAN
to reply to all
incoming LAN, WAN and Guest WLAN Ping requests.
Do not respond to
requests for
unauthorized
services
Select this option to prevent hackers from finding the NBG334W by probing for
unused ports. If you select this option, the NBG334W will not respond to port
request(s) for unused ports, thus leaving the unused ports and the NBG334W
unseen. By default this option is not selected and the NBG334W will reply with an
ICMP Port Unreachable packet for a port probe on its unused UDP ports, and a
TCP Reset packet for a port probe on its unused TCP ports.
Note that the probing packets must first traverse the NBG334W's firewall
mechanism before reaching this anti-probing mechanism. Therefore if the firewall
mechanism blocks a probing packet, the NBG334W reacts based on the firewall
policy, which by default, is to send a TCP reset packet for a blocked TCP packet.
You can use the command "sys firewall tcprst rst [on|off]" to change this policy.
When the firewall mechanism blocks a UDP packet, it drops the packet without
sending a response packet.
Service Setup
Enable Services
Blocking
Select this check box to enable this feature.
Available Services
This is a list of pre-defined services (ports) you may prohibit your LAN computers
from using. Select the port you want to block using the drop-down list and click
Add
to add the port to the
Blocked Services
field.
Blocked Services
This is a list of services (ports) that will be inaccessible to computers on your LAN
once you enable service blocking.
Custom Port
A custom port is a service that is not available in the pre-defined
Available
Services
list and you must define using the next two fields.
Type
Choose the IP port (
TCP
or
UDP
) that defines your customized port from the drop
down list box.
Port Number
Enter the port number range that defines the service. For example, if you want to
define the Gnutella service, then select
TCP
type and enter a port range from
6345 to 6349.
Add
Select a service from the
Available Services
drop-down list and then click
Add
to
add a service to the
Blocked Services
Delete
Select a service from the
Blocked Services
list and then click
Delete
to remove
this service from the list.
Clear All
Click
Clear All
to empty the
Blocked Services
.
Schedule to Block
Day to Block:
Select a check box to configure which days of the week (or everyday) you want
service blocking to be active.
Time of Day to
Block (24-Hour
Format)
Select the time of day you want service blocking to take effect. Configure blocking
to take effect all day by selecting
All Day
. You can also configure specific times by
selecting
From
and entering the start time in the
Start (hour)
and
Start (min)
fields and the end time in the
End (hour)
and
End (min)
fields. Enter times in 24-
hour format, for example, "3:00pm" should be entered as "15:00".
Page 148 / 296
Chapter 13 Firewall
NBG334W User’s Guide
148
Misc setting
Bypass Triangle
Route
Select this check box to have the NBG334W firewall ignore the use of triangle
route topology on the network.
Max NAT/Firewall
Session Per User
Type a number ranging from 1 to 2048 to limit the number of NAT/firewall sessions
that a host can create.
Apply
Click
Apply
to save the settings.
Reset
Click
Reset
to start configuring this screen again.
Table 56
Security > Firewall > Services
LABEL
DESCRIPTION
Page 149 / 296
NBG334W User’s Guide
149
C
HAPTER
14
Content Filtering
This chapter provides a brief overview of content filtering using the embedded web GUI.
14.1
Introduction to Content Filtering
Internet content filtering allows you to create and enforce Internet access policies tailored to
your needs. Content filtering is the ability to block certain web features or specific URL
keywords.
14.2
Restrict Web Features
The NBG334W can block web features such as ActiveX controls, Java applets, cookies and
disable web proxies.
14.3
Days and Times
The NBG334W also allows you to define time periods and days during which the NBG334W
performs content filtering
.
14.4
Filter Screen
Click
Security
>
Content Filter
to open the
Filter
screen.
Page 150 / 296
Chapter 14 Content Filtering
NBG334W User’s Guide
150
Figure 82
Security > Content Filter > Filter
The following table describes the labels in this screen.
Table 57
Security > Content Filter > Filter
LABEL
DESCRIPTION
Trusted Computer
IP Address
To enable this feature, type an IP address of any one of the computers in your
network that you want to have as a trusted computer. This allows the trusted
computer to have full access to all features that are configured to be blocked by
content filtering.
Leave this field blank to have no trusted computers.
Restrict Web
Features
Select the box(es) to restrict a feature. When you download a page containing a
restricted feature, that part of the web page will appear blank or grayed out.
ActiveX
A tool for building dynamic and active Web pages and distributed object
applications. When you visit an ActiveX Web site, ActiveX controls are
downloaded to your browser, where they remain in case you visit the site again.
Java
A programming language and development environment for building
downloadable Web components or Internet and intranet business applications of
all kinds.
Cookies
Used by Web servers to track usage and provide service based on ID.
Web Proxy
A server that acts as an intermediary between a user and the Internet to provide
security, administrative control, and caching service. When a proxy server is
located on the WAN it is possible for LAN users to circumvent content filtering by
pointing to this proxy server.
Keyword Blocking
Enable URL
Keyword Blocking
The NBG334W can block Web sites with URLs that contain certain keywords in
the domain name or IP address. For example, if the keyword "bad" was enabled,
all sites containing this keyword in the domain name or IP address will be
blocked, e.g., URL http://www.website.com/bad.html would be blocked. Select
this check box to enable this feature.

Rate

4 / 5 based on 1 vote.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top