Technical information

Watson-SHDSL-Router-GUI-Manual.doc
Version 2.3-03
Watson SHDSL Router
Web-based Management Manual
Revision: 2012-02-29
8-33
Error: No memory - a message notifying that a new connection has not been
established because of lack of memory.
NAT Error : Connection pool is full - a message notifying that a connection has
not been created because the connection pool is full.
NAT Error: No free NAT IP - a message notifying that there is no free NAT IP,
therefore NAT has failed.
NAT Error: Conflict Mapping already exists - a message notifying that there is a
conflict since the NAT mapping already exists, therefore NAT has failed.
Malformed packet: Failed parsing - a packet has been blocked because it is
malformed.
Passive attack on ftp-server: Client attempted to open Server ports - a packet
has been blocked because of an unauthorized attempt to open a server port.
FTP port request to 3rd party is forbidden (Possible bounce attack) - a packet
has been blocked because of an unauthorized FTP port request.
Firewall Rules were changed - the firewall rule set has been modified.
User authentication - a message during login time, including both successful
and failed authentication.
First packet is Invalid - First packet in connection failed to pass firewall or NAT
8.2.11 Applying Corporate-Grade Security
The following set of instructions is designed to assist you in applying corporate-
grade security standards to your network. When implementing these instructions, it
is important to execute the configuration steps in the exact order they are present-
ed. To apply corporate-grade firewall security standards perform the following:
Do not allow non-administrative services access to the LAN:
1. Open a Telnet session from a LAN host that is connected to Watson.
2. Telnet to Watson at address 192.168.1.1.
3. Logon to Watson as an administrator (the default username is "admin" and the
password is "admin").
4. After logging on, issue the following command at the prompt:
Watson> conf set fw/protect/allow_rg_remote_administration_only 1
Watson> conf reconf 1
Watson> exit
Configure Watson to permit only HTTPS as means of remote administration:
1. Click the 'Management' tab under 'System'.
2. Click the 'Remote Administration' tab.
3. Enable the following check boxes:
4. Using Primary HTTPS Port (443)
5. Using Secondary HTTPS Port (8443)
6. Disable all other check boxes.