Top Banner
Henry Lo Field Application Engineer Session 2 Controlling IP Connectivity These are NOT confidential sessions – please DO consider to streaming, blogging, or taking pictures
73

Session 3 DrayTek Training at ABP Technology

Jul 04, 2015

Download

Technology

ABP Technology

Presentation 3 from DrayTek Technical router, firewall and advanced configuration training held at ABP Technology on 2/25/14 - 2/26/14. Session 3 includes details on controlling IP connectivity. More information on DrayTek training and webinars at http://www.abptech.com/info/registration/draytek_info.html
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Session 3 DrayTek Training at ABP Technology

Henry&Lo&&

Field&Application&Engineer

Session 2 Controlling IP Connectivity

These&are&NOT&confidential&sessions&–&please&DO&consider&to&streaming,&blogging,&or&taking&pictures&

Page 2: Session 3 DrayTek Training at ABP Technology

Firewall Rules Web Content Filter User Management

Schedule

Page 3: Session 3 DrayTek Training at ABP Technology

Firewall Rules Web Content Filter User Management

Schedule

Page 4: Session 3 DrayTek Training at ABP Technology

Outline• General&Setup&• Filter&Setup&

- Call&Filter&- Data&Filter&

• DoS&Defense&• Application&Notes

Page 5: Session 3 DrayTek Training at ABP Technology

General Setup

• Apply to ALL!• Prevent unwanted IPv6 WAN incoming traffics

Page 6: Session 3 DrayTek Training at ABP Technology

General Setup• APPE / URL / WCF Filter!• Apply to ALL!

Page 7: Session 3 DrayTek Training at ABP Technology

Outline• General&Setup&• Filter&Setup&

- Call&Filter&- Data&Filter&

• DoS&Defense&• Application&Notes

Page 8: Session 3 DrayTek Training at ABP Technology

Filter Setup

More&Data&Filter

Page 9: Session 3 DrayTek Training at ABP Technology

Filter SetupDrayTek• Edit&Criteria&

F Source&IP&F Dest&IP&F Service&Type

Page 10: Session 3 DrayTek Training at ABP Technology

Filter SetupDrayTek• Edit&Criteria&

F Source&IP&F Dest&IP&F Service&Type

• Filter&AcJon&F User&Management&

F APP&Enforce&F URL&Filter&F WCF

Page 11: Session 3 DrayTek Training at ABP Technology

Outline• General&Setup&• Filter&Setup&

- Call&Filter&- Data&Filter&

• DoS&Defense&• Application&Notes

Page 12: Session 3 DrayTek Training at ABP Technology

DoS Defense

• Mind the Rate

Page 13: Session 3 DrayTek Training at ABP Technology

DoS Defense• DoS Alert Logs

Page 14: Session 3 DrayTek Training at ABP Technology

ApplicaJon&note

•DoS&Defense&Filter hNp://www.draytek.com.tw/index.php?opJon=com_k2&view=item&id=5315&Itemid=293&lang=en

Page 15: Session 3 DrayTek Training at ABP Technology

Firewall Rules Web Content Filter User Management

Schedule

Page 16: Session 3 DrayTek Training at ABP Technology

Web Content Filter• Web&UI&Overview&

• How&does&it&Work&

• What&does&it&Do&

• UpFtoFDate&Web&Categories&

• Monitor&Activities&with&Syslog&

• Configuration&• Application&Notes

Page 17: Session 3 DrayTek Training at ABP Technology

Web UI Overview• License&

InformaJon

• Profile&Table

• Cache&

F L1&IP&Cache1&second&

F L2&URL&Cache500/1000&entries

• Administrator&Message

Page 18: Session 3 DrayTek Training at ABP Technology

www.google.com

www.google.com

CYREN Server

Search Engines & PortalsPass

www.facebook.comwww.facebook.com

Social Networkingblock

How does it Work

Page 19: Session 3 DrayTek Training at ABP Technology

How does it Work

Page 20: Session 3 DrayTek Training at ABP Technology

•Home&–&Parental&Controls&to&children&

• Enterprise&–&Access&Control&to&employees&

• Schedule&the&blocking&

• UpFtoFdate&Web&categories&

• Monitor&acJviJes&with&Syslog

What does it Do

Page 21: Session 3 DrayTek Training at ABP Technology

ChildrenParents

Parental Controls

Page 22: Session 3 DrayTek Training at ABP Technology

Access Controls

Page 23: Session 3 DrayTek Training at ABP Technology

• Schedule&to&block&social&networks&for&homework&Jme

Parents Children

Schedule the Blocking

Page 24: Session 3 DrayTek Training at ABP Technology

• Check&URL&categories

www.facebook.comSocial Networking•Manually&suggest&

categories

• ReacJon&Jme&guaranteed

http://www.commtouch.com/url-miscat/

Up-to-Date Web Categories

Page 25: Session 3 DrayTek Training at ABP Technology

Monitor Activities with Syslog

Page 26: Session 3 DrayTek Training at ABP Technology

•Set&LAN2/SSID2&for&kids&

•Edit&WCF&Profile&

• Include&WCF&Profile&into&DNS&Filter&

•Set&Firewall&Rule&for&kids&

•Confirm&the&FuncJonality&

•Check&Syslog

Parental Controls

Page 27: Session 3 DrayTek Training at ABP Technology

• Set&LAN&2&for&SSID2

Parental Controls

Page 28: Session 3 DrayTek Training at ABP Technology

•Give&access&of&SSID2&to&kids

Parental Controls

Page 29: Session 3 DrayTek Training at ABP Technology

• Edit&WCF&Profile

Parental Controls

Page 30: Session 3 DrayTek Training at ABP Technology

• Edit&DNS&Filter

Parental Controls

F Specially&designed&to&block&hNps&websites

Page 31: Session 3 DrayTek Training at ABP Technology

• Set&Firewall&Rule&for&Children

Parental Controls

F Profile&Name

F LAN2&to&WAN

F Pass&Immediately

F Apply&WCF

Page 32: Session 3 DrayTek Training at ABP Technology

•Trouble&shooJng&–&confirm&the&funcJonality

Parental Controls

Page 33: Session 3 DrayTek Training at ABP Technology

•Trouble&shooJng&–&read&the&Syslog

Parental Controls

Page 34: Session 3 DrayTek Training at ABP Technology

ApplicaJon&note

•How&to&Use&WCF hNp://www.draytek.com.tw/index.php?opJon=com_k2&view=item&id=5369&Itemid=293&lang=en

Page 35: Session 3 DrayTek Training at ABP Technology

Firewall Rules Web Content Filter User Management

Schedule

Page 36: Session 3 DrayTek Training at ABP Technology

Outline• How&does&User&Management&Work&

– Rule&Base&

– User&Base&

• What&does&User&Management&Do&– For&Home,&limit&children&Internet&surfing&time&with&Parental&Control&&

– For&Business,&set&Landing&page&for&customers&

– For&Enterprise,&set&authorities&for&services&access&

• Configuration&

• Application&Notes

Page 37: Session 3 DrayTek Training at ABP Technology

Outline• How&does&User&Management&Work&

– Rule&Base&

– User&Base&

• What&does&User&Management&Do&– For&Home,&limit&children&Internet&surfing&time&with&Parental&Control&&

– For&Business,&set&Landing&page&for&customers&

– For&Enterprise,&set&authorities&for&services&access&

• Configuration&

• Application&Notes

Page 38: Session 3 DrayTek Training at ABP Technology

How does Rule-Based Work

• RuleFBased&is&a&management&method&based&on&firewall&rules,&that&Administrator&may&bind&a&user&profile&into&a&firewall&rule.

Page 39: Session 3 DrayTek Training at ABP Technology

How does User-Based Work

• UserFBased&is&a&management&method&based&on&user&profiles,&that&Administrator&may&bind&a&firewall&rule&into&a&user&profile.

Page 40: Session 3 DrayTek Training at ABP Technology

• Children&have&1&hour&time&quota&to&access&the&Internet&everyday&from&08:00~22:00.&

– Set&schedule&and&SSID2&for&kids.&

– Set&SSDI2&as&LAN2&member.&

• Web&Content&Filter&protects&children&from&inappropriate&contents.&

– Apply&WCF&to&LAN2&in&Firewall.&

• Auto&refill&time&quota&daily.

Parental Controls

Page 41: Session 3 DrayTek Training at ABP Technology

Parental Control Configuration• Edit&time&schedule&profile.

- Starts&from&08:00- Duration&is&14&hours&until&22:00- Force&On- Choose&days

Page 42: Session 3 DrayTek Training at ABP Technology

• Choose&RuleFBased. • Create&a&User&Profile&for&Son

- Name/Password

- Allow&at&most&1&user&to&log&in

- Apply&Schedule

- Initial/Refill&Time&Quota

• Create&another&User&Profile&for&Daughter

Parental Control Configuration

Page 43: Session 3 DrayTek Training at ABP Technology

• Create&a&user&group&for&Son&and&Daughter.&- Select&kids- Put&to&the&right&side&as&member

Parental Control Configuration

Page 44: Session 3 DrayTek Training at ABP Technology

• Create&WCF&profile&for&children.

Parental Control Configuration

Page 45: Session 3 DrayTek Training at ABP Technology

• Set&SSID2&as&LAN2&member&for&kids&– Give&kids&WiFi&password&for&SSID2&only.&

• Enable&SSID2.

• Enable&LAN&2.

Parental Control Configuration

Page 46: Session 3 DrayTek Training at ABP Technology

• Set&firewall&rule&for&kids&– LAN2&as&source&IP.&

– Choose&Pass&if&No&Further&Match.&

– Apply&children&group.&

– Apply&WCF&profile.

Parental Control Configuration

Page 47: Session 3 DrayTek Training at ABP Technology

Landing Page

Page 48: Session 3 DrayTek Training at ABP Technology

Landing Page Configuration

• Type&URL&as&Landing&Page.&• Redirect&to&specified&URL&after&login&with&user&account.

Page 49: Session 3 DrayTek Training at ABP Technology

Landing Page Configuration

• Tick&Landing&Page.

Page 50: Session 3 DrayTek Training at ABP Technology

Landing Page Configuration

• Redirected&to&Draytek&Homepage&after&login.

Page 51: Session 3 DrayTek Training at ABP Technology

Set Authorities for Services Access

• Different&authentications&for&different&groups.

group Authentication

Server x

Employee v

Guest v

Page 52: Session 3 DrayTek Training at ABP Technology

• Choose&UserFBased.

Set Authorities for Services Access Configuration

Page 53: Session 3 DrayTek Training at ABP Technology

• Filter&rules&process&– Block&all&outgoing&access&if&from&unauthorized&LAN&IP&range.&

– Allow&Server&to&pass.&

– Allow&Employee&to&pass&after&authentication.&

– Allow&Guests&to&pass&after&authentication.

Set Authorities for Services Access Configuration

Page 54: Session 3 DrayTek Training at ABP Technology

• Block&all&outgoing&access&if&from&unauthorized&IP&range&– Direction&is&LAN&to&WAN&

– !(IP&range):&if&outside&this&IP&range.& Click&Invert&Selection&

– Choose&Block&Immediately.

Set Authorities for Services Access Configuration

Page 55: Session 3 DrayTek Training at ABP Technology

• Allow&server&pass.&– LAN&to&WAN.&

– Type&Server&IP.&

– Pass&Immediately.

Set Authorities for Services Access Configuration

Page 56: Session 3 DrayTek Training at ABP Technology

• Allow&Employee&to&pass&after&authentication.&– Disable&this&rule,&and&will&be&applied&to&employee&user&profile.&

– LAN&to&WAN.&

– Set&IP&range&for&employee.&

– Pass&Immediately.

Set Authorities for Services Access Configuration

Page 57: Session 3 DrayTek Training at ABP Technology

Set Authorities for Services Access Configuration

• Allow&Guests&to&pass&after&authentication.&– Disable&this&rule,&and&will&be&applied&to&guests&user&profile.&

– LAN&to&WAN.&

– Set&IP&range&for&guests.&

– Pass&Immediately.

Page 58: Session 3 DrayTek Training at ABP Technology

• Create&Employee&user&profile.&– Username/Password.&

– Apply&firewall&rule&into&Policy.

Set Authorities for Services Access Configuration

Page 59: Session 3 DrayTek Training at ABP Technology

Set Authorities for Services Access Configuration

• Create&Guests&user&profile.&– Username/Password.&

– Apply&firewall&rule&into&Policy.

Page 60: Session 3 DrayTek Training at ABP Technology

Application Note

• How to Use User Management with User-Based Policyhttp://www.draytek.com.tw/index.php?option=com_k2&view=item&id=1842&Itemid=293&lang=en&

• How to use User Management with Rule-Based Policy&http://www.draytek.com.tw/index.php?

option=com_k2&view=item&id=1841&Itemid=293&lang=en

• How to use Landing Page Feature?http://www.draytek.com.tw/index.php?option=com_k2&view=item&id=1808:faq-

article-1808&lang=en

Page 61: Session 3 DrayTek Training at ABP Technology

Firewall Rules Web Content Filter User Management

Schedule

Page 62: Session 3 DrayTek Training at ABP Technology

Outline

• What does Schedule Do • Applications

– Schedule firewall rules to block Facebook on working hours

– Turn off WiFi at sleep time

Page 63: Session 3 DrayTek Training at ABP Technology

What does Schedule Do

• We&can&Schedule&Vigor&routers&to&– Enable&WAN&(PPPoE/PPTP/L2TP)&

– Execute&Firewall&rules&

– Apply&User&Profile&in&User&Management&

– Execute&Session/Bandwidth&Limit&

– Execute&LANFtoFLAN&VPN&profiles&

– Turn&off&WiFi&

– Reboot&automatically

Page 64: Session 3 DrayTek Training at ABP Technology

• Block&facebook&from&08:00~18:00&on&weekdays.

Schedule Firewall Rules

Page 65: Session 3 DrayTek Training at ABP Technology

• Set Schedule profile – Starts at 08:00 – Duration is 10 hours until 18:00

Schedule Firewall Rules Configuration

Page 66: Session 3 DrayTek Training at ABP Technology

• Create&a&WCF&profile.&– Choose&Social&Networking&to&block&Facebook.

Schedule Firewall Rules Configuration

Page 67: Session 3 DrayTek Training at ABP Technology

Schedule Firewall Rules Configuration

• Create&a&firewall&to&block&facebook.&– Apply&schedule.&

– Block&Immediately.&

– Apply&WCF&profile.

Page 68: Session 3 DrayTek Training at ABP Technology

• WiFi is OFF from 22:00~08:00 everyday. • Schedule is based on Per day.

– 2 separate schedules for overnight purpose. • WiFi is ON by default.

– Set action to force DOWN.

Turn Off WiFi at Sleep Time

Time 22:00~23:59 00:00~08:00

Action Force&Down Force&Down

Duration 2&hours 8&hours

Page 69: Session 3 DrayTek Training at ABP Technology

Turn Off WiFi at Sleep Time Configuration

• Create&a&schedule&profile.&– Starts&at&22:00&

– Duration&is&2&hours&until&23:59&

– Choose&Force&Down&

– Choose&Weekdays

c

c

Page 70: Session 3 DrayTek Training at ABP Technology

Schedule Internet Surfing Time Configuration

• Create&another&schedule&profile.&– Starts&at&00:00&

– Duration&is&8&hours&until&08:00&

– Choose&Force&Down&

– Choose&Weekdays

c

c

Page 71: Session 3 DrayTek Training at ABP Technology

Schedule Internet Surfing Time Configuration

• Apply Schedule profiles to Wireless LAN.

Page 72: Session 3 DrayTek Training at ABP Technology

Application Note

• How to Turn off Wi-Fi with Schedulehttp://www.draytek.com.tw/index.php?option=com_k2&view=item&id=5347:howFtoFturnFoffFwiFfiFwithFschedule&lang=en&

• How to Reboot Vigor Router with Schedule&http://www.draytek.com.tw/index.php?option=com_k2&view=item&id=1242:faqFarticleF1242&lang=en&

• How to use Call Schedule?&http://www.draytek.com.tw/index.php?

option=com_k2&view=item&id=1799:faqFarticleF1799&lang=en

Page 73: Session 3 DrayTek Training at ABP Technology

Q & A Thank You!