Go to page of
A good user manual
The rules should oblige the seller to give the purchaser an operating instrucion of Intel 9535, along with an item. The lack of an instruction or false information given to customer shall constitute grounds to apply for a complaint because of nonconformity of goods with the contract. In accordance with the law, a customer can receive an instruction in non-paper form; lately graphic and electronic forms of the manuals, as well as instructional videos have been majorly used. A necessary precondition for this is the unmistakable, legible character of an instruction.
What is an instruction?
The term originates from the Latin word „instructio”, which means organizing. Therefore, in an instruction of Intel 9535 one could find a process description. An instruction's purpose is to teach, to ease the start-up and an item's use or performance of certain activities. An instruction is a compilation of information about an item/a service, it is a clue.
Unfortunately, only a few customers devote their time to read an instruction of Intel 9535. A good user manual introduces us to a number of additional functionalities of the purchased item, and also helps us to avoid the formation of most of the defects.
What should a perfect user manual contain?
First and foremost, an user manual of Intel 9535 should contain:
- informations concerning technical data of Intel 9535
- name of the manufacturer and a year of construction of the Intel 9535 item
- rules of operation, control and maintenance of the Intel 9535 item
- safety signs and mark certificates which confirm compatibility with appropriate standards
Why don't we read the manuals?
Usually it results from the lack of time and certainty about functionalities of purchased items. Unfortunately, networking and start-up of Intel 9535 alone are not enough. An instruction contains a number of clues concerning respective functionalities, safety rules, maintenance methods (what means should be used), eventual defects of Intel 9535, and methods of problem resolution. Eventually, when one still can't find the answer to his problems, he will be directed to the Intel service. Lately animated manuals and instructional videos are quite popular among customers. These kinds of user manuals are effective; they assure that a customer will familiarize himself with the whole material, and won't skip complicated, technical information of Intel 9535.
Why one should read the manuals?
It is mostly in the manuals where we will find the details concerning construction and possibility of the Intel 9535 item, and its use of respective accessory, as well as information concerning all the functions and facilities.
After a successful purchase of an item one should find a moment and get to know with every part of an instruction. Currently the manuals are carefully prearranged and translated, so they could be fully understood by its users. The manuals will serve as an informational aid.
Table of contents for the manual
-
Page 1
DMZ Firewall Solution Intel Express Route rs 9515, 9525 an d 9535[...]
-
Page 2
INFORMATION IN THIS DOCUMENT IS PROVIDED IN CONNECT ION WITH INTEL PRODUCTS. NO L ICENSE, EXPRESS OR IMPLIED, BY ESTOPPEL OR OTHERWISE, TO ANY INTELLECTUAL PROPERT Y RIGHTS IS GRANTED BY TH IS DOCUMENT. EXCEPT AS PROVIDED IN INT ELS TERMS AND CONDITIONS OF SALE FOR SUCH PRODUCTS, INTEL ASSUMES NO L IABILITY WHATSOEV ER, AND INTEL DISCLAIMS ANY [...]
-
Page 3
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 2 Table of Contents 1 Introduction ............................................................................................................................ 3 1.1 About This Document .................................................................................................[...]
-
Page 4
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 3 1 Introduction 1.1 A bout This Document This docum ent explains h ow to config ure a secure I nternet solution u sing the se cond LAN interface of the I ntel Express router as a DMZ. The D MZ setup is exp lained th rough the use o f two exam ple soluti ons, a Sing le IP A ddre[...]
-
Page 5
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 4 The purpose of this se tup is to p rohibit any direct da ta transm ission betwee n the I nternet and the secure ne twork. Al l data m ust go thr ough proxy serv ers on the DMZ . We recom mend that y ou set up the DMZ on the LAN2 (10 Mb ps) port and your secure network on the LAN1 [...]
-
Page 6
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 5 2.2 Routing Setup Do not use R IP on the WAN interf ace or the D MZ in terface. This prev ents intr uders from corrupting the rou ting table. If there i s more th an one in ternal ne twork, the rou ter m ust not be used a s prim ary g ateway because the router conf ig ura tion onl[...]
-
Page 7
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 6 3 DMZ Single IP A ddress Solution This solu tion explains h ow to set up a D MZ solut ion when the I nternet serv ice provide r (ISP) has assigned a single I P address to y our netwo rk. Intel Express Router HTTP/FTP (Web) server 10.2.0.1 Mail server 10.5.0.1 HTTP/FTP proxy server[...]
-
Page 8
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 7 Note The order o f the NA T en tries is importan t. NAT entr ies are de fined as f ollows : Entry Functi on Settings 1 Directs all in coming HTTP requests to the Web server. Mapping type: Static Po rt (Sing le IP) Internal a ddress: 10.2.0.1 Internal po rt: 80 External I P address[...]
-
Page 9
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 8 Filters are de fined as fol lows: Filter Functi on Settings — Prohibit use rs on th e secure ne twork access to th e I nternet Default Action: Discar d 1 Allows access to t he HTTP /F TP proxy serv er on the DMZ . Action : Pass Protocol: A ll Dest. addr ess type: Host Dest. addr[...]
-
Page 10
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 9 Filter Functi on Settings Src. address : 10.2.0.2 Src. port: = 80 2 Allows FTP (on ly passiv e connections ) from secur e LAN to the F TP proxy server on the DMZ (see note 1). Two filte rs are req ui red. Action : Pass Protocol: TCP TCP flags: ACK Dest. addr ess type: All Dest. po[...]
-
Page 11
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 10 Filter Functi on Settings Dest. address : 10.5.0.2 Dest. port: > 1023 Src. addre ss type: Host Src. address : 10.2.0.4 Src. port: = 119 8 Sends all pack ets genera ted by the r outer to the se cure LAN (LA N1). Action : Pass Protocol: TCP TCP flags: All Dest. addr ess type: Al[...]
-
Page 12
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 11 Filters are de fined as fol lows: Filter Functi on Settings — Pass all pack ets dest ined for D MZ Default A ction: Pass 1 Prevents RI P updates from entering the DMZ network Acti on: Discar d Protocol: UDP Dest. addr ess type: All Dest. port: RIP Src. addre ss type: All Src. p[...]
-
Page 13
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 12 Filter Functi on Settings Scr. addre ss type: Host Src. address : <LAN1 I P address> Src. port : All 9 Discards all I CMP packets en tering th e DMZ network . This prev ents the ro uter from repor ting the I P netm ask. Acti on: Discar d Protocol: I CMP Dest. addr ess type:[...]
-
Page 14
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 13 3.3.3 Internet Co nnection Fi lters 3.3.3.1 Receive (Rx) Filters on the connection to the Interne t Configure these rece ive fil ters for the Intern et connect ion, shown as th ey appear in Adva nced Setup . × Filters are de fined as fol lows: Filter Functi on Settings — Prohi[...]
-
Page 15
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 14 Filter Functi on Settings 2 Allows FTP (bo th activ e and passiv e) from the I nterne t to the H TTP/F TP server on the DMZ . Three fi lters are r equired. Action : Pass Protocol: TCP TCP flags: All Dest. addr ess type: Host Dest. address : 10.2.0.1 Dest. port: = 21 Src. addre ss[...]
-
Page 16
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 15 Filter Functi on Settings Dest. address : 10.2.0.2 Dest. port > 1023 Src. addre ss type: All Src. port: > 1023 9 Allows D NS reply to the HT TP/F TP proxy serv er on the DMZ . Two filte rs are req u ired. Action : Pass Protocol: TCP TCP flags: ACK Dest. addr ess type: Host [...]
-
Page 17
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 16 Filter Functi on Settings Dest. addr ess type: Host Dest. address : 10.2.0.3 Dest. port > 1023 Src. addre ss type: All Src. port: = 25 15 Allows incom ing News (NNTP) from a specified external N ews serv er to the DMZ (see no te 2). Action : Pass Protocol: TCP TCP flags: All D[...]
-
Page 18
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 17 4 DMZ Multiple IP A ddress Solution This solu tion explains h ow to set up a D MZ when the I SP supplies y ou with mult iple IP addresses. I n the exam ple, the I SP has assig ned the si te a range o f IP addresses: 193.84 .251.0 to 193.84.251.7 (subne t mask 255.255.255.248). In[...]
-
Page 19
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 18 4.3 Network Address Trans lation (NA T) Because the se cure priv ate netwo rks on LAN1 use public IP addresses (8 9.20.0.0 and 90.20.0.0 ), configure N AT to tr anslate t hese addres ses to priv ate I P addresses. Fo r exam ple, NAT wil l translate the E-m ail server a ddress fr [...]
-
Page 20
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 19 Filters are de fined as fol lows: Filter Functi on Settings — Prohibit interna l users acc ess to the Int e r ne t Defaul t Action: Defaul t 1 Allow s access to the H TTP /FTP pro xy server on the DMZ . Action : Pass Protocol: A ll Dest. addr ess type: Host Dest. address : 193.[...]
-
Page 21
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 20 Filter Functi on Settings Src. port: = 80 2 Allows F TP (only pass ive conne ctions) from secur e LAN to the F TP proxy server on the DMZ (see note 1). Two filte rs are req ui red. Action : Pass Protocol: TCP TCP flags: ACK Dest. addr ess type: All Dest port: >1023 Src. addre [...]
-
Page 22
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 21 Filter Functi on Settings Dest. port: > 1023 Src. addre ss type: Host Src. address : 193.84.251.4 Src. port: 119 8 Sends a ll packets g enerated by the router to t he intern al LAN (LAN1 ). Action: Pass Protocol: TCP TCP flags: All Dest. addr ess type: All Dest. port: All Src.[...]
-
Page 23
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 22 Filter Functi on Settings Src. addre ss type: All Src. port: All 2 Prev ents tunnel p ackets from entering the DMZ network Acti on: Discar d Protocol: TCP Dest. addr ess type: All Dest port: Tunnel Src. addre ss type: All Src. port: All 3 Prev ents RSVP p ackets from enter ing th[...]
-
Page 24
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 23 Filter Functi on Settings 9 Discards all I CMP packets en tering th e DMZ network . This prev ents the ro uter from repor ting the I P netm ask. These filters m ust inc lude all I P addresses on the router, including the WAN IP address if the rou ter is usin g num bered links. Ac[...]
-
Page 25
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 24 4.4.2. 2 Transmit (Tx) filters on LAN2 Set the de fault ac tion to Pass . 4.4.3 Internet Co nnection Fi lters 4.4.3.1 Receive (Rx) Filters on the Connection to the Internet The requi red receiv e filters f or the I nternet connection, s hown as they appear in Advanced Setup . × [...]
-
Page 26
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 25 Filter Functi on Settings Src. port: > 1023 2 Allows F TP (both act ive and pass ive) from the I nterne t to the H TTP/F TP server on the DMZ . Three fi lters are r equired. Action : Pass Protocol: TCP TCP flags: All Dest. addr ess type: Host Dest. address : 193.84.251 .1 dest[...]
-
Page 27
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 26 Filter Functi on Settings Dest. addr ess type: Host Dest. address : 193.84.251.2 Dest. port > 1023 Src. addre ss type: All Src. port: = 21 9 Allow s DNS r eply to the HTTP /FTP proxy serv er on the DMZ . Two filte rs are req u ired. Action : Pass Protocol: TCP TCP flags: ACK D[...]
-
Page 28
DMZ Firewall Solution fo r the Express Router 07-12-99 Version 1.0 27 Filter Functi on Settings 14 Allows outg oing m ail (SMTP) to any host on th e Interne t from the DMZ. Action : Pass Protocol: TCP TCP flags: ACK Dest. addr ess type: Host Dest. address : 193.84.251.3 Dest. port > 1023 Src. addre ss type: All Src. port: = 25 15 Allows incoming[...]