D-Link DFL-1000 [13/168] What s new in version 2 6

D-Link DFL-1000 [13/168] What s new in version 2 6
DFL-1000 User Manual
1
3
any network connected to the DFL-1000 NPG, including the Internet. Connecting to and using the DFL-
1000 CLI is described in the DFL-1000 CLI Reference Guide .
Logging and reporting
The DFL-1000 NPG supports logging of various categories of traffic and of configuration changes. You
can configure logging to:
report traffic that connects to the firewall,
report network services used,
report traffic permitted by firewall policies,
report traffic that was denied by firewall policies,
report events such as configuration changes and other management events, IPSec tunnel
negotiation, and web page blocking,
send alert email to system administrators to report firewall or VPN events or violations.
Logs can be sent to a remote syslog server or to a WebTrends NetIQ Security Reporting Center and
Firewall Suite server using the WebTrends enhanced log format. Some models can also save logs to an
optional internal hard drive. If a hard drive is not installed, you can configure most DFL-1000 NPGs to log
the most recent events to shared system memory.
What's new in Version 2.36
The following features are new in Version 2.36.
Policy-based NAT
When running the DFL-1000 NPG in NAT/Route mode, you can configure any firewall policy to be a NAT
mode policy or a Route mode policy. See Adding NAT/Route mode policies
.
Multiple IP pools for each interface
You can add multiple IP pool address ranges to each DFL-1000 interface. When you select IP pool in a
policy, the DFL-1000 NPG randomly changes the source address of packets to one of the addresses in
the IP pools added to the destination of the policy. See IP pools
.
Configure port forwarding by configuring virtual IPs
Port forwarding is now configured by adding virtual IPs that route packets with a destination address that
matches the IP address of the interface that receives the packets. See Virtual IPs
.
H.323 NAT traversal
By adding the H.323 server to firewall policies, DFL-1000 NPGs allow IP and other multi-media
communications to connect through the firewall. See Services
.
IPSec VPN improvements
The following new IPSec VPN features have been added to v2.36:
Encrypt firewall
policies
Add IPSec firewall policies to control VPN traffic. Using IPSec VPN Firewall policies you can
control the addresses of networks that can connect to a VPN tunnel and the direction of traffic
flow through the VPN tunnel. See Adding an encrypt policy
.
IPSec NAT traversal
Remote IPSec VPN gateways or clients behind a NAT can connect to an IPSec VPN tunnel.
See About NAT traversal
.

Содержание

Скачать