Allied Telesis Small Branch Office Router AT-AR320 AT-AR320 User Manual

Product codes
AT-AR320
Page of 4
AT-AR320 & AT-AR320S
Dual Ethernet Security Appliance Routers
DUAL ETHERNET SECURITY APPLIANCE ROUTERS
AT-AR320-xx
SOHO Internet Firewall
AT-AR320S-xx
Internet Firewall with Encryption
PEACE OF MIND SECURITY FOR THE
HOME AND OFFICE LAN
The Allied Telesyn AT-AR320 provides affordable, highly-
effective protection for your home or office LAN
against malicious attacks from the Internet and external
networks.The AT-AR320S also safeguards your data
across external networks by providing hardware-based
DES encryption, making it virtually impossible for a
third party to eavesdrop on your e-mails and sensitive
data.
INDUSTRIAL STRENGTH STATEFUL
INSPECTION FIREWALL
Both the AT-AR320 and AR320S are equipped with
Allied Telesyn’s leading-edge Stateful Inspection Firewall,
providing the most effective protection for your private
network. It inspects every packet and its associated
connection to decide whether to keep or discard the
packet and whether to allow or terminate the connec-
tion. Paladin requires no user intervention and will
automatically transmit e-mail alerts if an attack is
detected. It detects and protects against a wide range
of Denial of Service attacks including Ping of Death,
SYN/FIN Flooding, Smurf attacks, Port scans, FRAG
attack and IP Spoofing.
IDEAL FOR CABLE MODEM AND XDSL
APPLICATIONS
Cable and xDSL modems do not provide firewall pro-
tection, and because they offer an always-on connec-
tion, users are actually more at risk using these services
than with conventional modem dial-up. However, by
connecting the AT-AR320 between the cable or xDSL
modem and the private LAN, full site security is
restored, as well as full multi-protocol routing.The AT-
AR320 and AR320S can just as easily be connected
behind conventional router devices when required.
IPSEC AND ISAKMP SUPPORT FOR SECURE
VPN OPERATION
The AT-AR320S is designed to meet the IETF IPsec
RFC’s and ISAKMP specification, providing a standards-
based approach to user data security. IPsec uses
encryption technology to ensure confidentiality, integri-
ty, and authenticity of user data across public networks.
The AT-AR320S allows the creation of secure Virtual
Private Networks (VPNs) across public networks, per-
mitting low-cost Internet connections for use in place
of more costly dedicated links.
FLEXIBLE FIREWALL SECURITY POLICIES
A security policy outlines the rules that specify the
types of traffic that are allowed to pass through the
firewall. By default, all traffic flows originating on the pri-
vate LAN are allowed to pass to the Internet, while all
traffic flows originating from public network to the pri-
vate network are denied.Traffic flows can be based on
any or all of the following:
• The Ethernet interface on which the data is received
• Day of the week, date, or time of day
• Source and destination IP address
• IP protocol type (TCP, UDP, ICMP, EGP, OSPF, or any
decimal IP protocol number)
• Traffic direction
• Source and destination port for TCP and UDP
TELECOMMUTER SUPPORT
The AT-AR320 and AR320S support two asynchronous
ports that can be used for telecommuter access,
enabling remote workers to access local LAN services
or connect to the Internet or corporate networks.
Once attached, telecommuters are governed by the
same Firewall policies applied to local LAN users.
Additionally, these asynchronous ports can be used in
dial-out applications, providing either additional network
bandwidth or a back-up to the main link.
KEY FEATURES
Ideal for cable modem and xDSL applications
RIP, OSPF protocol support
PAP/CHAP, RADIUS/TACACS Authentication
Stateful Inspection Firewall 
IPSEC and ISAKMP VPN support with DES,
3DES encryption (AT-AR320S)
Dual Ethernet LAN Support
Dual modem ports 
SNMP and CLI management
Perfect Security solution for the SoHo or SMB,
or for offices needing to support secure tele-
workers access to the WAN