Upnp And Security; The Nsa's Services And Upnp - ZyXEL Communications NSA series User Manual

Hide thumbs Also See for NSA series:
Table of Contents

Advertisement

Chapter 8 Network
For example, if the NSA's IP address was 192.168.1.33 when you applied the UPnP Port Mapping
screen's settings and the NSA later gets a new IP address of 192.168.1.34 through DHCP, WAN
access stops working because the Internet gateway still tries to forward traffic to IP address
192.168.1.33. Since you can no longer access the NSA from the WAN, you would have to access
the NSA from the LAN and re-apply your UPnP Port Mapping screen settings to update the
Internet gateway's UPnP port mappings.
Figure 67 UPnP Using the Wrong IP Address
192.168.1.34
192.168.1.33

8.5.2 UPnP and Security

UPnP's automated nature makes it easier to use than manually configuring firewall and NAT rules,
but it is also less secure. Using UPnP may make your network more susceptible to snooping and
hacking attacks.

8.5.3 The NSA's Services and UPnP

This section introduces the NSA's services which an Internet gateway can use UPnP to allow access
to from the Internet.
CIFS (Windows File Sharing)
Common Internet File System (CIFS) is a standard protocol supported by most operating systems
in order to share files across the network. Using UPnP port mapping for CIFS allows users to
connect from the Internet and use programs like Windows Explorer to access the NSA's shares to
copy files from the NSA, delete files on the NSA, or upload files to the NSA from the Internet.
If you configure UPnP port mapping to allow CIFS access from the WAN but cannot get it to work,
you may also have to configure the Internet gateway to also allow NetBIOS traffic. See
on page 141
FTP
File Transfer Protocol is a standard file transfer service used on the Internet. Using UPnP port
mapping for FTP allows remote users to use FTP from the Internet to access the NSA's shares. A
user with read and write access to a share can copy files from the share, delete files from the share,
or upload files to the share. See
FTP access from the WAN, you may want to use a different WAN port number (instead of the default
of port 21) to make it more secure. Remember to tell the remote users to use the custom port
number when using FTP to access the NSA.
170
for more on CIFS.
Section 9.4 on page 177
a.b.c.d
for more on FTP. If you use UPnP to allow
Section 6.3
Media Server User's Guide

Advertisement

Table of Contents
loading

Table of Contents