Académique Documents
Professionnel Documents
Culture Documents
Q&A
Prerequisites
You will need 2 devices with IkarusOS loaded.
Configuration Steps
Step 1: Follow the Step By Step Wireless Bridge Setup example and create 2 wireless bridges.
Step 2: Configure the 1st device to operate in Access Point Mode.
Select Access Point from the Select Operational Mode Drop Down Menu.
Insert an essid string in the SSID box.
Step 3: Configure the 2nd device to operate in Access Point Client Mode and perform a Site Survey
action.
Select Access Point Client from the Select Operational Mode Drop Down Menu.
Click the Site Survey button
As soon as the devices get connected the connection status bar inform you about the link's quality and
the Signal's Level.
Firewall Scenarios
AP Mode:ip2
Host PC2:ip3
AP Client Mode:ip4
1.
2.
3.
4.
5.
6.
7.
8.
9.
6.
7.
In the pop-up window Insert in textboxes "Source IP", "Destination IP" the IPs of AP and of the
subnet the network is setted up (e.g. 192.168.1.0/24) respectively and from dropdown list next
to "ACTION" select "REJECT".
Go to "Advanced" Tab and from the dropdown list next to "Protocol" label select "TCP" protocol
8.
NAT Scenarios
Prerequisite Steps
From any PC of Private Subnet 192.168.5.x/24 you should be able to ping eth0 of AP Mode.
Right click to the Access Point node of the network topology and choose from the arised list
Advanced Network Configuration
From the top frame next to label "NAT kind" choose "SNAT" and click to the button with the "+"
sign.
Click the "submit" button and then the "tick" button to apply changes.
Try to ping from any Server behind the switch to ath0 of AP Mode.
Try to ping from any Server behind the switch to any HOST PC which is connected to AP Client
Mode.
The connection is established although you can not ping from any HOST PC to any Server.
In order to make this happen, we need the appropriate DNAT rule.
DNAT Configuration
Right click to the Access Point node of the network topology and choose from the arised list
Advanced Network Configuration
From the top frame next to label "NAT kind" choose "DNAT" and click to the button with the "+"
sign.
Click the "submit" button and then the "tick" button to apply changes.
Try to ping from any Host PC behind the switch to any Server.
The connection is established
For HTTP you should add another DNAT rule and specify in "Traslate Dest IP To" the ip of HTTP
Server, Destination Port 80 and in "Translate Port To" 80-80.
For FTP you should add another DNAT rule and specify in "Traslate Dest IP To" the ip of FTP
Server, Destination Port 22 and in "Translate Port To" 22-22.
For SIP you should add another DNAT rule and specify in "Traslate Dest IP To" the ip of SIP
Server, Destination Port 5060 and in "Translate Port To 5060-5060.