D-Link DFL-1000 [11/168] Nat route mode

D-Link DFL-1000 [11/168] Nat route mode
DFL-1000 User Manual
11
control when individual policies are in effect,
accept or deny traffic to and from individual addresses,
control standard and user defined network services individually or in groups,
require users to authenticate before gaining access,
include traffic shaping to set access priorities and guarantee or limit bandwidth for each policy,
include logging to track connections for individual policies,
include Network address translation (NAT) mode and Route mode policies,
include Mixed NAT and Route mode policies.
The DFL-1000 firewall can operate in NAT/Route mode or Transparent mode.
NAT/Route mode
In NAT/Route mode, you can create NAT mode policies and Route mode policies.
NAT mode policies use network address translation to hide the addresses in a more secure
network from users in a less secure network.
Route mode policies accept or deny connections between networks without performing address
translation.
Transparent mode
Transparent mode provides the same basic firewall protection as NAT mode. Packets received by the
DFL-1000 NPG are intelligently forwarded or blocked according to firewall policies. The DFL-1000 NPG
can be inserted in your network at any point without the need to make changes to your network or any of
its components. However, VPN and some advanced firewall features are only available in NAT/Route
mode.
VPN
Using DFL-1000 virtual private networking (VPN), you can provide a secure connection between widely
separated office networks or securely link telecommuters or travellers to an office network.
The DFL-1000 VPN features include the following:
Industry-standard and IPSec VPN including:
IPSec, ESP security in tunnel mode,
DES and 3DES (triple-DES) hardware accelerated encryption,
HMAC MD5 and HMAC SHA1 authentication and data integrity,
AutoIKE key based on pre-shared key tunnels,
Manual Keys tunnels,
Diffie-Hellman groups 1, 2, and 5,
Aggressive and Main Mode,
Replay Detection,
Perfect Forward Secrecy.
PPTP for easy connectivity with the VPN standard supported by the most popular operating
systems.
L2TP for easy connectivity with a more secure VPN standard also supported by many popular
operating systems.
Firewall policy based control of IPSec VPN traffic.

Содержание

Скачать