EasyManuals Logo

ELTEX ESR-1511 User Manual

Default Icon
650 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #471 background imageLoading...
Page #471 background image
ESR series service routers.ESR-Series. User manual
471
Router always has a security zone named 'self'. When the traffic recipient is the router itself, i.e. traffic is not
transit, pass 'self' zone as a parameter. Create a pair of zones for traffic coming from 'WAN' zone into 'self'
zone. In order the router could response to the ICMP requests from 'WAN' zone, add a rule allowing ICMP
traffic transfer from R2 to ESR router:
esr(config)# security zone-pair WAN self
esr(config-zone-pair)# rule 1
esr(config-zone-pair-rule)# action permit
esr(config-zone-pair-rule)# match protocol icmp
esr(config-zone-pair-rule)# match destination-address WAN
esr(config-zone-pair-rule)# match source-address WAN_GATEWAY
esr(config-zone-pair-rule)# enable
esr(config-zone-pair-rule)# exit
esr(config-zone-pair)# exit
Create a pair of zones for traffic coming from 'LAN' zone into 'self' zone. In order the router could response to
the ICMP requests from 'LAN' zone, add a rule allowing ICMP traffic transfer from R1 to ESR:
esr(config)# security zone-pair LAN self
esr(config-zone-pair)# rule 1
esr(config-zone-pair-rule)# action permit
esr(config-zone-pair-rule)# match protocol icmp
esr(config-zone-pair-rule)# match destination-address LAN
esr(config-zone-pair-rule)# match source-address LAN_GATEWAY
esr(config-zone-pair-rule)# enable
esr(config-zone-pair-rule)# exit
esr(config-zone-pair)# exit
esr(config)# exit
To view port membership in zones, use the following command:
esr# show security zone
To view zone pairs and their configuration, use the following commands:
esr# show security zone-pair
esr# show security zone-pair configuration
To view active sessions, use the following commands:
esr# show ip firewall sessions
13.4.3 Configuration example of application filtering (DPI)
Objective:
Block access to such resources as youtube, bittorrent and facebook.
The use of application filtering mechanism reduces by several times the router performance because
of the need to check each packet. The performance decreases with an increase in amount of the
selected for filtration applications.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the ELTEX ESR-1511 and is the answer not in the manual?

ELTEX ESR-1511 Specifications

General IconGeneral
Device TypeRouter
WAN Ports1
LAN Ports4
Dimensions190 x 130 x 30 mm
Power Supply5V 1A
Flash Memory16 MB
Console PortNo
Operating Temperature0°C to +40°C
Weight0.25 kg
FirewallYes
QoSYes
Ethernet Ports4
USB Ports1
Ports5 (1 WAN + 4 LAN)
VPN SupportPPTP, L2TP
Storage Temperature-20°C to 70°C
Humidity10% to 90% (non-condensing)

Related product manuals