User's Manual

46
D-Link DGL-5500 User Manual
Section 3 - Conguration
SPI (Stateful Packet Inspection, also known as dynamic packet ltering) helps
to prevent cyber attacks by tracking more state per session. It validates that
the trac passing through the session conforms to the protocol.
Select one of the following for TCP and UDP ports:
Endpoint Independent - Any incoming trac sent to an open port will be
forwarded to the application that opened the port. The port will close if idle
for 5 minutes.
Address Restricted - Incoming traffic must match the IP address of the
outgoing connection.
Port and Address Restricted - Incoming trac must match the IP address and
port of the outgoing connection.
Enable this feature to protect your network from certain kinds of spoong” attacks.
Allows multiple machines on the LAN to connect to their corporate network using PPTP protocol.
Allows multiple VPN clients to connect to their corporate network using IPSec. Some VPN clients support traversal of IPSec through
NAT. This ALG may interfere with the operation of such VPN clients. If you are having trouble connecting with your corporate network,
try turning this ALG o. Please check with the system administrator of your corporate network whether your VPN client supports
NAT traversal.
Enable SPI:
NAT Endpoint
Filtering:
Anti-Spoof
Checking:
PPTP:
IPSec (VPN):
Firewall Settings
A rewall protects your network from the outside world. The DGL-5500 oers a rewall type functionality. The SPI feature helps
prevent cyber attacks. Sometimes you may want a computer exposed to the outside world for certain types of applications.
If you choose to expose a computer, you can enable DMZ. DMZ is short for Demilitarized Zone. This option will expose the
chosen computer completely to the outside world.