User Manual
Table Of Contents
- Introduction
- Front Panel
- Back Panel
- Installation Guidelines
- Wall Mounting
- Using the Setup Wizard
- Entering Login and Internet Connection Information
- Manually Connecting Your System
- Logging In
- Using the Getting Started Page
- Navigating through the Pages
- Saving Your Changes
- Viewing the Help Files
- Viewing the System Summary
- Viewing the Wireless Status
- Viewing the IPsec Connection Status
- Viewing the QuickVPN Connection Status
- Viewing Logs
- Viewing Available LAN Hosts
- Viewing the Port Triggering Status
- Viewing Port Statistics
- Configuring Networking
- Configuring the WAN for an IPv4 Network
- Configuring the WAN for an IPv6 Network
- Creating PPPoE Profiles
- Changing the Default Cisco RV 120W IP Address
- Configuring DHCP
- Configuring the LAN DNS Proxy
- Configuring Virtual LANs (VLANs)
- Configuring Port VLANs
- Configuring Multiple VLAN Subnets
- Configuring IPv6 LAN Properties
- Configuring LAN Groups
- Adding a Static IP Address for a Device on the LAN
- Configuring a DMZ Host
- Configuring Internet Group Management Protocol (IGMP)
- Choosing the Routing Mode
- Viewing Routing Information
- Configuring Static Routing
- Configuring Dynamic Routing
- Configuring the Routing Mode
- Configuring IPv6 Static Routing
- Configuring RIP next generation (RIPng)
- Configuring IPv6 to IPv4 Tunneling
- Configuring Router Advertisement
- Configuring the Wireless Network
- Wireless Security Tips
- General Network Security Guidelines
- Configuring the Group Key Refresh Interval
- Configuring RADIUS Authentication Parameters
- Enabling or Disabling APs
- Editing an AP’s Properties
- Using MAC Filtering
- Viewing AP Status
- Configuring the Firewall
- Protecting from Attacks
- Configuring Universal Plug and Play (UPnP)
- Enabling Session Initiation Protocol Application-Level Gateway (SIP ALG)
- Configuring the Default Outbound Policy
- Creating a Firewall Rule
- Managing Firewall Rules
- Creating Custom Services
- Blocking Web Applications and Components
- Adding Trusted Domains
- Adding Blocked Keywords
- Configuring MAC Address Filtering
- Configuring IP/MAC Address Binding
- Restricting Sessions
- Configuring Virtual Private Networks (VPNs) and Security
- Creating Cisco QuickVPN Client Users
- Using the VPN Wizard
- Viewing the Default Values
- Configuring IP Security Policies
- Configuring VPN Policies
- Configuring VPN Clients
- Monitoring VPN Tunnel Status
- Configuring IPsec Users
- Configuring VPN Passthrough
- Using Certificates for Authentication
- Using the Cisco RV 120W With a RADIUS Server
- Configuring 802.1x Port-Based Authentication
- Configuring Quality of Service (QoS)
- Configuring 802.1p to Queue Mapping
- Configuring 802.1p CoS to DSCP Remarking
- Administering Your Cisco RV 120W
- Editing SNMPv3 Users
- Adding SNMP Traps
- Configuring Access Control Rules
- Configuring Additional SNMP Information
- Using PING
- Using Trace Route
- Performing a DNS Lookup
- Capturing and Tracing Packets
- Configuring Local Logging
- Configuring Remote Logging
- Configuring the Logging Type and Notification
- Configuring E-Mailing of Log Events
- Configuring VLAN Associations
- Using Cisco QuickVPN for Windows 2000, XP, or Vista
- Installing from the CD-ROM
- Downloading and Installing from the Internet
- Where to Go From Here
Configuring the Firewall
Firewall Rule Examples
Cisco RV 120W Administration Guide 91
4
Example 3: Multi-NAT Configuration
In this example, you want to configure multi-NAT to support multiple public IP
addresses on one WAN port interface.
Create an inbound rule that configures the firewall to host an additional public IP
address. Associate this address with a web server on the DMZ. If you arrange with
your ISP to have more than one public IP address for your use, you can use the
additional public IP addresses to map to servers on your LAN. One of these public
IP addresses is used as the primary IP address of the router. This address is used
to provide Internet access to your LAN PCs through NAT. The other addresses are
available to map to your DMZ servers.
The following addressing scheme is used to illustrate this procedure:
• WAN IP address: 10.1.0.118
• LAN IP address: 192.168.1.1; subnet 255.255.255.0
• Web server PC in the DMZ, IP address: 192.168.1.2
• Access to Web server: (simulated) public IP address 10.1.0.52
Action Allow always
Send to Local Server (DNAT IP) 192.168.1.11
Destination Users Address Range
From 132.177.88.2
To 134.177.88.254
Enable Port Forwarding Yes (enabled)
Parameter Value
Parameter Value
From Zone Insecure (WAN1/WAN2)
To Z o n e P u b l i c ( D M Z )
Service HTTP
Action Allow always