Cirkuit Planet MH-2001 Manuale Utente

Pagina di 297
MH-2001 Multi-Homing Security Gateway User’s Manual 
Chapter 1: Introduction
 
As Internet become essential for your business, the only way to prevent your Internet connection from failure 
is to have more than one connection. PLANET’s Multi-Homing Security Gateway MH-2001 reduces the risk 
of potential shutdown if one of the Internet connections should fail. In addition, they allow you to perform 
load-balancing by distributing the traffic through two WAN connections.   
Not only is a multi-homing device, PLANET’s MH-2001 also provides a complete security solution in a box. 
The policy-based firewall, Intrusion detection and prevention, content filtering function and VPN connectivity 
with 3DES and AES encryption make it become a perfect product for your network security. No more 
complex connection and settings for integrating different security products on the network is required.     
Bandwidth management function is also supported on MH-2001 to offers network administrators an easy 
and powerful means to allocate network resources based on business priorities, and to shape and control 
bandwidth usage.   
 
1.1 Features 
‹ 
WAN Backup: The MH-2001 can monitor each WAN link status and automatically activate backup links 
when a failure is detected. The detection is based on the configurable target Internet addresses. 
‹ 
Outbound Load Balancing: The network sessions are assigned based on the user configurable load 
balancing mode, including “Auto”, “Round-Robin”, “By Traffic”, “By Session”, “By Packet”, “By Source IP” 
and “By Destination IP”. User can also configure which IP or TCP/UDP type of traffic use which WAN 
port to connect. 
‹ 
Policy-based Firewall: The built-in policy-based firewall prevent many known hacker attack including 
SYN attack, ICMP flood, UDP flood, Ping of Death, etc. The access control function allowed only 
specified WAN or LAN users to use only allowed network services on specified time. 
‹ 
VPN Connectivity: The security gateway support PPTP and IPSec VPN. With DES, 3DES and AES 
encryption and SHA-1 / MD5 authentication, the network traffic over public Internet is secured. 
‹ 
Content Filtering: The security gateway can block network connection based on URLs, Scripts (The 
Pop-up, Java Applet, cookies and Active X), P2P (eDonkey, Bit Torrent and WinMX), Instant Messaging 
(MSN, Yahoo Messenger, ICQ, QQ and Skype) and Download/Upload blocking. 
‹ 
Dynamic Host Control Protocol (DHCP) server: DHCP server can allocate up to 253 client IP 
addresses and distribute them including IP address, subnet mask as well as DNS IP address to local 
computers. It provides an easy way to manage the local IP network. 
‹ 
Web based GUI: MH-2001 supports web based GUI for configuration and management. It also supports 
multiple language including English, Traditional Chinese and Simplified Chinese. 
‹ 
User Authentication: User database can be configured on the devices, MH-2001 also supports the 
authenticated database through external RADIUS and POP3 server. 
‹ 
Bandwidth Management:    Network packets can be classified based on IP address, IP subnet and 
 
 
 
 
- 1 -