User guide

Rev 2.0 C Aug.10 63
7
7: Security Configuration
Port Forwarding
and DMZ
Port Filtering-
Inbound
Port Filtering-
Outbound
Trusted IPs -
Inbound
Trusted IPs -
Oubound
MAC Filtering
The Security tab that displays in ACEmanager, is applicable across
all Sierra Wireless AirLink devices.
The security tab covers firewall type functions, how data is routed or
restricted from one side of the Device to the other, from computers or
devices connected to the Device (LAN) and from computers or
devices contacting it from a remote source (WAN). These features
are set as “rules”.
Tip:
For additional security, it is recommended you change the default
password for ACEmanager. Refer to the Admin chapter.
Solicited vs Unsolicited
How the device responds to data being routed from one network
connection to the other depends on the origin of the data.
If a computer on the LAN initiates a contact to a WAN location
(such as a LAN connected computer accessing an Internet web
site), the response to that contact would be solicited.
If, however, a remote computer initiates the contact (such as a
computer on the Internet accessing a camera connected to the
device), the connection is considered unsolicited.
Port Forwarding and DMZ
In Port Forwarding, any unsolicited data coming in on a defined
Public Port will be routed to the corresponding Private Port and Host
IP of a device connected to the specified Physical Interface. In
addition to a single port forwarded, you can also forward a range of
ports.
DMZ defines a single LAN connected device where all unsolicited
data should be routed. Anything coming into the ALEOS device on a
public port will go directly to that LAN connected device using the
same private port.