About this guide
This document answers two questions together: “what am I looking at on screen?” and “how do I get the result I want?” For each module page, it first explains the page's purpose and the meaning of the on-screen fields, then walks through the step-by-step workflow and the pitfalls specific to that page.
Throughout the guide, menu paths are shown in the form Firewall Management › Rules. The screen figures present a simplified view of the interface's current structure; colors and badges carry the same meaning they do in the product.
This guide covers
- Enabling, confirming and disabling Router Mode
- All 12 pages under Firewall Management
- Field-by-field reference tables, boundary values and defaults
- The meaning of error messages and how to resolve them
- End-to-end setup scenarios
What is outside this guide
- Captive portal design, language and guest-user management (
Hotspot Management) - Searching logs received from external firewalls (
Firewall Log Search) - Licensing, backup, disk and user management (
System Management) - Reports and automatic report definitions
Tip: On every page in the product, the ? button at the top right opens the help panel specific to that page. On top of that help, this guide adds the relationships between pages and the end-to-end workflows.
What is Router Mode?
By default, SignLogger runs in passive mode: it collects, signs and stores logs coming from other devices on the network (firewall, wireless controller, switch). In this mode the device carries no one's traffic; it only records what others report.
Router Mode (also referred to as SignRouter in the product) changes this role. When the mode is turned on, the device becomes the network's transit point: traffic between the internal network and the internet physically flows through the device. As a result, the record stops being a second-hand report and is instead generated from the traffic the device itself sees.
What you gain when the mode is on
| Capability | What it provides | Related page |
|---|---|---|
| First-hand Law 5651 records | The pass-through traffic log is generated directly from the device's own data plane, without trusting an intermediary device. | Log Settings |
| Zone-based security policy | Allow/deny is written between logical zones instead of interfaces; the policy stays readable. | Zones · Rules |
| NAT and port forwarding | The internal network exits through a single external address; required services are exposed surgically. | NAT / Port Forwarding |
| Address distribution | DHCP server or relay on internal interfaces; MAC → IP reservation. | DHCP & DNS |
| Captive portal | Authentication is enforced on the guest network; sessions are tied to records. | Zones › Captive |
| Multiple internet lines | Line performance is measured continuously; which traffic exits over which line is set by rule. | SD-WAN |
| Live visibility | Connections passing at that moment, open sessions, the most-talked-to destinations. | Monitor |
Critical point: The Firewall Management menu appears only while router mode is on and is listed only for administrator accounts that are members of the root domain. If you cannot find the menu, first check the mode's state from the
Dashboard › Statusscreen.
The mode's three states
| Badge | Meaning | Traffic |
|---|---|---|
| Active | Routing is running, the configuration is permanent. | Passing through the device |
| Awaiting confirmation | The configuration has been applied but not yet confirmed. If the time expires, it is rolled back automatically. | Passing temporarily |
| Disabled | Router mode is off. Settings are kept but not applied. | Not passing |
How traffic flows
In router mode, a packet's journey through the device always follows the same order. The fastest way to understand why a setting isn't having the effect you expect is to know where in this chain the setting sits.
Diagram — The packet's journey · from the internal network to the internet
Practical takeaway: When someone says “I wrote the rule but the traffic isn't passing,” the order to check is always the same: 1) is the interface in the right zone, 2) does a rule cover this zone pair, 3) is NAT defined, 4) is the line healthy.
Prerequisites and permissions
Hardware and network
| Requirement | Why it is needed |
|---|---|
| At least two physical interfaces | One carries the internet line (WAN), the other the internal network. Routing cannot be done with a single interface. |
| A separate interface for WAN | The management interface you are connected to the device through is not accepted as the uplink. If you assign the management interface to the WAN zone, the mode will not turn on. |
| An IP (L3) on the internal interface | The IP of the internal zone interface becomes the gateway for the clients on that network. The mode will not turn on with an internal interface that has no IP. |
| A valid license | Routing continues even without a license, but the captive portal and compliance records stop. |
| A second access path | If your connection is lost during activation, the rollback mechanism kicks in; even so, a backup access path (console or a second management interface) is recommended. |
Administrator permissions
| Permission | What it unlocks |
|---|---|
| View the state/settings of router (gateway) mode | Opening the Firewall Management pages, reading the Monitor and Overview data. |
| Enable/configure router (gateway) mode — a critical network operation | Turning the mode on/off, saving zone, rule, NAT, DHCP, SD-WAN and log settings. |
On an account without the permission, the relevant page request is denied and the message Settings could not be retrieved. or Monitor data could not be retrieved. appears on screen.
Maintenance window: Enabling router mode changes the network configuration; a brief outage may occur. Do it during an off-hours maintenance window and at a time when you can be at the device.
Turning router mode on
Menu path ·The on/off control for router mode is in a single place: the Router Mode row on the main Status panel and the activation wizard it opens. The “Apply Configuration” form and the “Stop Routing” card that used to be on the Overview page have been removed — being able to start activation from two separate places could spawn two confirmation flows at the same time.
Screen — Dashboard › Status
Activation flow
- Open the Status page
Dashboard › Status→ find the Router Mode row in the System Information card. If the switch in the row is off, the mode is disabled. - Turn the switch on; the wizard opens
The Enable Router Mode window shows the current interface–zone assignments and any blockers. At this point nothing has been applied yet.
- If there is a blocker, resolve it first
If the window shows the warning “Router mode cannot be enabled right now”, the text below it tells you what is missing. Check its counterpart in the readiness-checks table. If there are multiple interfaces, the wizard lets you fix it from the same screen via the Change interface–zone assignments section; you save the change first with Save Assignments.
- Set the upstream DNS (optional)
If left blank, the existing upstream is used: with PPPoE, the service provider's DNS servers, otherwise public servers. Separate multiple servers with commas.
- Read the access preview
The Access after enabling section shows which management ports will stay open on which interface. This is only a preview and has not been applied — but it is the only place where you can see, before enabling, whether you are locking yourself out.
- Choose the confirmation time
The default is 120 seconds; the range accepted on screen is 30–900 seconds. This time is the window you are given to say “my access is still working” before the configuration is rolled back automatically.
- Confirm
In the “Do you confirm enabling router mode?” prompt the warning is clear: The network configuration will change. If your connection is lost, the change is rolled back automatically. Once you confirm, the interfaces, firewall and address distribution are applied in sequence. The PPPoE dial alone can take 25 seconds; it is normal for the window to say “Completing activation…”.
- Click “Confirm and Make Permanent”
When the apply is done, the mode is in the Awaiting confirmation state and a countdown begins. If your access is still working, press the confirm button; the state becomes Router mode enabled and permanent.
Don't forget to confirm: If the countdown ends, the configuration is rolled back automatically and the device returns to its previous working state. This is not a fault — it is the lockout protection doing its job.
Readiness checks
At the very top of the Firewall Management › Overview page, next to the status badge, there is always a sentence. Seeing text there does not by itself mean there is a problem — first read what the sentence says.
If there is no blocker, the ready notice appears: “Ready: a WAN plus an internal-zone interface with an IP exists, router mode can be enabled.”
| Text you see on screen | Meaning | Resolution |
|---|---|---|
| No interface is assigned to the WAN zone. | The interface carrying the internet line is not attached to any WAN-type zone. | On the Interfaces page, assign the uplink interface to the WAN zone. |
| The interface in the WAN zone cannot be the management interface — assign a separate interface for the uplink. | You have made the interface that carries your management access the WAN interface. The assignment is not blocked but it is not accepted as the uplink. | Set aside another interface for the internet line. In a setup whose only connection is the management port, the mode will not turn on. |
| An IP (L3) must be assigned to at least one internal-zone interface. | The interface facing the internal network has no IP; the clients' gateway cannot be formed. | Interfaces → the relevant interface → Addressing Manual, then enter the IP Address and Prefix (/bits). |
Which interface counts as the “management interface”?: If there is an interface assigned to the MGMT zone, that is it. If there is no such assignment, the interface carrying the default route is accepted as the management interface. On VLAN sub-interfaces this check is re-derived from the physical interface above them.
Also, the interface you are currently connected through cannot be moved into the WAN zone whatever zone it is in — this is direct lockout protection.
The confirmation window and rollback
The classic risk of changing the network configuration remotely is that the change cuts off your own access. SignLogger solves this with a two-stage apply.
The configuration is written and takes effect immediately, but it is not marked “permanent.” The confirmation time begins.
On the Firewall Management › Overview page you press the Confirm and Make Permanent button in the yellow-bordered card. The configuration becomes permanent.
When the time expires, the device rolls back the configuration on its own and returns to the previous working state. You do not need to go to the console.
| Setting | Value |
|---|---|
| Default confirmation time | 120 seconds |
| Range accepted on screen | 30 – 900 seconds |
| Server-side upper limit | 900 seconds |
| If an invalid/blank value is submitted | 120 seconds is used |
Frequently asked
- If I refresh the page, do I lose my chance to confirm? No. The card is rebuilt with the remaining time. When the countdown resets, the page state refreshes on its own.
- What does the “No confirmation token, refresh the page.” error mean? The confirmation information was dropped while the page stayed open. Press the refresh button at the top right; when the card reappears, confirm.
- What if I am connecting from behind a router? In that case the “interface you are connected through” match cannot be established; the protection relies entirely on the countdown-based confirmation. As long as you do not confirm, the change does not become permanent.
Turning router mode off
Turning it off is done from the same place: turn off the Dashboard › Status › Router Mode switch. When it is turned off:
Preserved
- All zone, rule, NAT, route, DHCP and SD-WAN settings are kept
- The interface list and IP assignments remain visible
- Previously generated logs stay in place
Stopped
- Traffic no longer passes through the device; the firewall becomes Passive
- Line probing stops and the accumulated measurement state is cleared
- The captive portal is not enforced; DHCP distribution does not happen
- The Firewall Management menu disappears
Good news: Setting changes made while the mode is off are not lost. When you save, you get the message “…(will be applied when router becomes active)”; when the mode is turned on again, they all take effect.
The Firewall Management menu
The menu consists of 12 pages. The first two are monitoring, the rest are configuration pages. When looking for a setting, the fastest way to find the right page is the table below.
| Page | What it is used for | Type |
|---|---|---|
| Overview | “Is the box configured correctly and running healthy?” Warnings, health boxes, configuration summary, record generation, live status. | Monitoring only |
| Monitor | “Who is connected right now, what is flowing?” Live connections, sessions, user/device/destination breakdown, DHCP leases, route table. | Monitoring only |
| Interfaces | Zone assignment of the physical ports, IP-acquisition method, VLAN sub-interfaces. | Configuration |
| Zones | Policy groups; access to the device (management ports), intra-zone traffic, Captive/RADIUS/Syslog permissions, captive portal. | Configuration |
| Addresses | Named IP objects: host, subnet, range, group. | Object |
| Services | Named protocol+port objects and service groups. | Object |
| Rules | Zone → zone allow/deny policy, order, implicit deny. | Configuration |
| NAT / Port Forwarding | Source NAT (masquerade/SNAT) and inbound-to-internal port forwarding (DNAT). | Configuration |
| SD-WAN | Multiple WAN lines: priority (Distance), performance measurement (SLA), line selection rules. | Configuration |
| Static Routes | Manual route definitions to networks that are not directly connected. | Configuration |
| DHCP & DNS | DNS servers, per-interface DHCP pools, active leases, MAC → IP reservations. | Configuration |
| Log Settings | Which record types are generated; preserving the mandatory Law 5651 record. | Configuration |
The single-place rule across pages: Each piece of information is edited on a single page: interface → zone assignment only on Interfaces, allow between zones only on Rules, address distribution only on DHCP. They are deliberately separated this way so the same question is never answered differently in two places.
Recommended configuration order
On a from-scratch setup, following the order below means you never have to backtrack on any of the interdependent settings.
- Interfaces
Assign the uplink interface to the WAN zone and the internal interface(s) to the LAN/GUEST/DMZ zones; give the internal interface a manual IP.
- Zones
Add new zones if needed; set each zone's access to the device (management ports) and its Captive/RADIUS/Syslog permissions.
- DHCP & DNS
Define the address pool, lease time, gateway and DNS values for the internal interfaces.
- Enable router mode
Status › Router Mode→ wizard → Confirm and Make Permanent. - Addresses and Services
Define the named objects you will use in the rules now; this saves you from having to fix rules later.
- Rules
Write the policy with narrow-scope denies at the top and broad allows at the bottom.
- NAT / Port Forwarding
If there are services that need to be exposed, add the port forwards.
- SD-WAN
If there are multiple lines, set the Distances, tune the SLA targets to your environment, and write the line-selection rules.
- Log Settings
Keep the noise scope (device traffic) off; leave the DHCP allocation events and the destination domain name on.
- Verify with Overview
No warnings, the internet-line box says Internet present, and the Pass-through traffic count must be greater than zero.
1 · Overview
Menu path · ·This page answers a single question: “is the box configured correctly and running healthy?” Who is connected and what is flowing at that moment is the Monitor page's job.
No settings are edited on the page. The only exception is the Confirm and Make Permanent button that appears if there is a configuration awaiting confirmation.
Screen — Firewall Management › Overview
Top card: status and readiness message
Next to the badge there is always a sentence; this sentence tells you whether the mode is ready to be enabled. Seeing text there does not by itself mean there is a problem. For the blocker texts and their resolutions, see the Readiness checks section.
While the router is Active, three summary fields appear on the card: WAN (the name of the uplink interface), Internal Zone (interface) and Rule count. When the mode is not active, this information is hidden.
Warnings
At the very top of the page, ahead of the boxes, there is a warnings section. If no problem is found, a green confirmation appears. All warnings except the connection-count warning are generated only while the router is active.
| Warning | Level | Meaning and what you should do |
|---|---|---|
| Router appears active but the firewall is not loaded | Critical | Routing rules are not being applied. You need to re-enable the configuration. |
| There is a DHCP-enabled zone but the DHCP service is not running | Critical | Clients cannot get an address; they cannot reach the network even with a cable plugged in. |
| The PPPoE connection is not established | Critical | There is no internet access. Check the line username/password and the line status on the operator side. |
| The PPPoE service is not running | Critical | Even if the connection drops, it cannot be re-established. |
| A WAN line whose internet access cannot be verified | Warning / Critical | The interface may be up but there is no exit to the outside. It is shown as a warning if only some lines are unhealthy, and as critical if all lines are unhealthy. |
| Fewer than two interfaces have a cable/link | Warning | Routing requires at least one WAN and one internal interface. |
| License invalid / expired | Warning | Routing continues; the captive portal and compliance records stop. |
| There is a captive-enabled zone but the captive license is not valid | Warning | It means user authentication is not being enforced. |
| Records are being generated but no pass-through traffic is visible at all | Warning | Client traffic may not be passing through the box; review the placement and the default gateway setting. |
| N recorded sessions have no authorization on the firewall | Warning | These users, who appear authenticated on the portal, cannot actually reach the internet. |
Health boxes
| Box | What it shows |
|---|---|
| Firewall | Whether the rule engine is loaded (On/Off). While the router is not active, no costly check is performed and it is shown definitively as Off. |
| DHCP service | The status of the service distributing addresses. If DHCP is not enabled on any zone, the box carries no color and “No DHCP-enabled zone” is written beneath it — this is not a fault. |
| Connectivity | “interfaces with a cable / total interfaces.” Only physical interfaces are counted; VLAN sub-interfaces are excluded so they don't inflate the count. If fewer than two, the box turns to the critical color. |
| License | Valid, Expired or Undefined. |
| PPPoE connection | Appears only if an interface is configured with PPPoE. If Connected, the local IP the line received is written beneath it; if Down, a “username/password or line” hint is written. |
| Internet line · interface | A separate box for each WAN line. It answers not “is the cable plugged in” but can it actually reach the outside. If Internet present, the average latency and loss rate are written beneath it; if No internet, the first 60 characters of the last error text are written. |
How internet-line probing works:
- Each line is probed over its own interface; the backup line's measurement cannot go out over the active line and produce a false “healthy” result.
- The probe is a short TCP connection attempt to the targets — it is not a ping and it generates no traffic. The default targets are
1.1.1.1:443,8.8.8.8:443and8.8.8.8:53. A different provider and a different port are deliberately used; if any of the targets responds, the line is considered healthy.- By default it is tried every 20 seconds, with a 4-second timeout. 3 consecutive failures mark the line unhealthy, 2 consecutive successes make it healthy again.
- Latency is the average of the successful attempts, and loss is the failure rate over the last 15-sample (≈5-minute) window.
- When a line is probed for the first time it is assumed healthy; otherwise it would raise a false alarm on every startup. Until the first result is produced, the box does not appear at all.
- The settings are changed from the SD-WAN › Performance SLA section; no restart is required.
What these boxes do and don't do: The page detects and reports a line; it does not bring a line up or down. The only automatic effect is this: if a rule on the SD-WAN page sends specific traffic over a specific line, that routing is not applied for as long as the line is found unhealthy and the traffic falls back to the default exit. Beyond that, there is no automatic failover or load sharing between lines.
Configuration Summary
This section answers the “what has been defined” question. The numbers are neutral, carry no good/bad meaning, and are therefore shown without color: Zone (with the captive-enabled count beneath), Rule, NAT/Forwarding (port + SNAT breakdown), Static route, Object (address + service breakdown), DHCP (reservation count), Shaping (On/Off + class count), Interface (including VLAN sub-interfaces).
Record Generation
Shows whether the evidence under Law 5651 is actually being written.
| Field | Meaning |
|---|---|
| Pass-through traffic | The number of records for the traffic the box passes through it. This is the legal evidence; being zero is a problem and therefore carries color. |
| Device traffic | Records for the traffic to/from the box itself. Beneath it, whether the scope is On/Off is written (default Off). |
| Event | The number of records for DHCP allocation, user and system events. |
| Record file | The space the generated record occupies; with the “before signing” note. |
The counts here are not the total of all history: they are a representative sample taken from the last portion of the current record (roughly the last 4 MB). The aim is not an exact count but to answer the “is generation flowing” question cheaply.
Live Status
Instantaneous values refreshed every four seconds: WAN Download/Upload (computed from the difference of two measurements; may show 0 on the first read), Active Sessions (“—” if it cannot be measured, warning color above 8000), DHCP Leases, Firewall (Active/Passive) and Router Status. The list beneath shows, for each interface, the Interface (the management interface with an MGMT label), Zone (with the number in a VLAN), IP and Connectivity.
While router mode is off, this section does not error out and does not stay empty; the only certain things are that Firewall = Passive and Router Status = Disabled are shown.
Refresh behavior
| Section | Refresh |
|---|---|
| Live Status boxes and interface list | Every 4 seconds |
| Warnings, health, configuration summary, record generation | Every 20 seconds |
| Status badge and readiness message | On page load and with Refresh |
| The Refresh button at the top right | Updates them all at once |
When you switch to another page, the periodic updates stop.
This page does
- Compares the configuration with the running system and writes any inconsistency as a warning
- Measures whether each WAN line actually reaches the outside
- Shows whether the Law 5651 record is being generated
- Lets you make a configuration awaiting confirmation permanent
This page does not
- Show who is connected or who is going where → Monitor
- Edit interface, zone, rule, NAT or DHCP settings
- Turn router mode on/off →
Status - Disable a line it found unhealthy
The order to follow when hunting for a problem:
- Look at the Warnings section — if there is a problem, the cause is written there.
- Read the Internet line boxes: if it says “No internet,” the problem is most likely on the line/operator side.
- Verify the firewall, DHCP and license status from the Health boxes.
- If “Pass-through traffic” is zero in the Record Generation section, client traffic is not passing through the box; check the placement and the clients' gateway.
- In the Live Status list, verify that the interface you expect is Connected and in the right zone.
2 · Monitor
Menu path · ·Monitor shows the current state on the device on a single screen: live connections, open sessions, users and devices that have traffic in the selected range, the most-talked-to destinations, distributed DHCP addresses and the route table. The screen is view-only — you cannot close a session or change a setting from here.
Screen — Firewall Management › Monitor Last 15 minutes
Top strip indicators
| Indicator | Meaning and limit |
|---|---|
| Download | Total data coming to the clients in the selected range. The “right now” beneath it is the WAN interface's instantaneous rate and the interface name. |
| Upload | Total data going out from the clients in the same range; the instantaneous rate is again beneath it. |
| Open sessions | The number of authenticated and unexpired sessions. It counts up to 500 at most; if exceeded, it stays at 500 and gives the lower bound, not the actual total. |
| Users | The number of distinct users seen to have traffic in the selected range. |
| Devices | The number of distinct client addresses seen to have traffic in the selected range. |
| Connections | The number of connections the system is tracking at that moment (instantaneous). “—” if it cannot be read. |
Beneath the indicators is the window information: Window: 15 min, followed by the first and last activity time actually seen in that range and the flow count. If there is no traffic at all in the range, it says “No traffic in this range.”
Time range and refresh
- Options: Last 5 minutes · 15 minutes · 1 hour · 6 hours · 24 hours. The default is 15 minutes. A request outside these five values is not accepted by the server and is reduced to 15 minutes.
- Auto refresh comes on by default; the page is refreshed every 10 seconds. If you turn it off, data comes only with Refresh or when the range changes.
- When you leave the page, auto refresh stops; on each entry the tab returns to Live Traffic and the range to the default.
- Because the instantaneous rate is computed from the difference of two measurements, it may show 0 B/s on the first load.
The range fully determines the top strip and the Users / Devices / Destinations tabs. On the Sessions tab, which sessions are listed and the remaining times are not affected by the range (they are always live), but the Traffic values on the same tab are the total for the selected range. Only the DHCP tab is entirely independent of the range.
Tabs
| Tab | Content and limits |
|---|---|
| Live Traffic | Read from the kernel's connection table, sorted from the one carrying the most data. It does not require a captive portal or session record; the rows arise from the traffic itself. Columns: Source (identity + address:port if any), NAT, Destination, Service, Protocol, State, Timeout, Traffic. The Pass-through traffic only toggle hides the box's own connections. The list shows at most 300 connections; the counter writes “shown / total.” It also works while router mode is off. |
| Sessions | Open and unexpired sessions: User, IP, MAC, Device, Zone, Remaining time, Traffic, State. If there is no username, it says unidentified (MAC). Remaining time turns to warning color below 15 min and critical below 5 min. The No-authorization badge in the State field says that, although the session appears open, the transit permission is not present in the data plane and it should be examined. At most 500 sessions. |
| Users | Users with traffic in the range, sorted by total data. The IPs it logged in on field lists all the addresses that user appeared on in the same range. At most 15 records. |
| Devices | Device name, IP, User/MAC, flow count and traffic. At most 15 records. |
| Destinations | The most-talked-to destinations. If the domain name is known, grouping is by domain name; if not, the destination address is used. At most 15 records. |
| DHCP | Addresses distributed by the router's own DHCP service: IP, MAC, Device name, Remaining time. For fixed allocations, it says fixed instead of a time. |
| Routes | The route table: Network (default = default route), Gateway, Interface, Type (static manually written, kernel/connected a directly connected network, dhcp learned) and Metric. It is view-only; to add a route, use Static Routes. |
Warning and error messages
| Message | Meaning |
|---|---|
| Router mode is not active — live data may be limited. | The session list and traffic breakdown may be empty or incomplete; the authorization status cannot be verified. |
| Monitor data could not be retrieved. | The request went unanswered or was denied. Your session may have dropped or you may lack permission. The screen keeps the previous content. If auto refresh is off, you need to press Refresh. |
This screen does
- Answers the “what is happening right now” question
- Shows whether the session is actually authorized on the firewall
- Reads the route table and the DHCP leases
This screen does not
- There is no session termination, blocking or rule changing
- It is not a historical report — the longest range is 24 hours
- Under very heavy traffic, totals over long ranges may be incomplete; the actual scope is written in the window information
- Lists are limited to the first 15 (300 for connections, 500 for sessions)
3 · Interfaces
Menu path · ·The page where you manage the device's physical network cards (NIC). You assign each interface to a security zone (zone) and determine how it will get an IP address. Which cable faces the internal network and which faces the internet is defined here.
Screen — Firewall Management › Interfaces
Basic concepts
- Interface (NIC): The physical network port on the back of the device. Each port connects to a cable (internal network or internet line).
- Zone: The interface's security role. LAN is the internal network you trust, WAN is the internet side. Since rules work on a zone basis, the correct assignment is critical.
IP-acquisition methods
| Method | When it is used |
|---|---|
| Static / Manual | You write the IP address and the prefix (prefix, e.g. /24) by hand. This IP you give for an internal zone becomes the gateway of the devices on that network. The valid prefix range is 8–32; if left blank, 24 is used. |
| DHCP client | The interface gets its IP address automatically from the upstream provider. Usually on the WAN side, to get an IP from the modem/ISP. |
| PPPoE | If the internet line connects with a username and password (as with many DSL/fiber subscriptions), you choose this method and enter the credentials. |
VLAN sub-interface
If you want to carry more than one logical network over a single physical port, you can add a VLAN sub-interface. 802.1q tagging is used; networks separated by different VLAN IDs are carried over the same cable. Each VLAN sub-interface has its own zone and IP setting. The VLAN number is in the range 1–4094.
Lockout protection: The management (mgmt) interface through which you connect to and manage the device is specially protected: this interface cannot be moved to WAN and a WAN VLAN cannot be defined on it. This prevents you from accidentally assigning the management port to the internet side and losing access to the device.
Don't confuse them: The DHCP server settings are not on this page. To distribute IPs automatically to devices on the internal network, use the DHCP & DNS page. The “DHCP client” option here is about the interface itself getting an IP.
How to do it
- Select the interface
Click the interface you want to edit from the list.
- Assign a zone
LAN (or GUEST/DMZ) for the internal network, WAN for the internet.
- Choose the IP-acquisition method
Static, DHCP client or PPPoE.
- Enter the values
If you chose Static, the IP and its prefix; if you chose PPPoE, the username and password.
- Add a VLAN if needed
Define the 802.1q sub-interface with Add VLAN; give it its own zone and IP as well.
- Save and verify
The changes take effect when router mode is enabled/re-applied. Verify from the Overview › Live Status list that the interface is Connected and in the right zone.
4 · Zones (Policy Groups)
Menu path · ·A zone is a structure that groups multiple network interfaces under a single logical policy group. Since security rules are written between zones rather than individual interfaces, your policy stays clean and readable. On this page you create zones, set each zone's access to the box permissions, and enable the Captive Portal for the guest network.
Default policy: Egress from an internal zone to WAN is allowed; transit between zones (for example GUEST → LAN) is blocked.
Screen — Firewall Management › Zones
Built-in zones
| Zone | Its role | Deletable? |
|---|---|---|
| WAN | The internet uplink. It is singular, no new one can be added. | No |
| LAN | The internal secure network. | No |
| DMZ | Externally exposed servers. | No |
| GUEST | The guest network. | No |
| MGMT | Management. It is singular, no new one can be added. | No |
| Custom | Zones you add yourself. | Yes |
Add Zone
- Add Zone
Click the button at the top right.
- Enter a name
1–32 characters; only letters, digits, underscore and hyphen. Otherwise you get the warning “Zone name must be 1-32 characters, letters/digits/_/-”. If a zone with the same name exists, it says “A zone with this name already exists.”
- Select a type
Custom, LAN, DMZ or Guest. WAN and MGMT cannot be selected; if a type not in the list is submitted, it is automatically taken as Custom.
- Save
Two things happen automatically: a visible default internet permission is created (“Default: <name> → WAN (internet)”) and the zone is created with Syslog listening on.
Adding a new zone does not by itself change live traffic; its effect begins when you assign an interface to it from the Interfaces page.
Zone Settings (shield icon)
The shield icon at the end of the row opens three sections for that zone. Which sections appear depends on the zone type.
A · Intra-zone Traffic
“Interfaces within the same zone can communicate with each other” — default on. If you turn it off, the zone goes into full isolation. This section appears on internal zones (LAN / DMZ / Guest / Custom); it does not appear on WAN and MGMT.
Know its limit: This setting is only meaningful if the zone has two or more interfaces. In a single-interface zone, devices already reach each other directly, the traffic does not pass through the box; this switch cannot separate them. If you need to isolate guest devices from each other, the isolation must be done on the wireless access point side.
B · Access to the Device (Management Ports)
Whether the users in this zone can reach the box's own management services: HTTPS, HTTP, SSH, Telnet, Ping (ICMP).
| Zone type | Behavior |
|---|---|
| Internal zones | All on by default. The port of a service you turn off is dropped only on that zone's interfaces. |
| WAN | All off by default. The moment the window opens, a red warning appears regardless of the state of the switches. Every service you turn on here exposes the box directly to the internet. |
| MGMT | This section is not shown. The management ports are never restricted on that interface — this is the escape route that keeps you from locking yourself out. |
| Captive-enabled interface | The switches are invalid: from that interface only name resolution, address distribution and portal-page access to the box are open; everything else is dropped. |
The Telnet switch comes on by default on internal zones, but no telnet server runs on the box; having it on does not open a door in practice.
C · External Device Access (Captive / RADIUS / Syslog)
This section appears on every zone — including WAN and MGMT. It opens the services through which external devices can connect to the box.
| Service | Ports | Default |
|---|---|---|
| Captive Portal | 8080, 8081, 8084, 8086 | Off. Turn it on explicitly if guest login will be used. |
| RADIUS | 1812, 1813 | Off. Turn it on for authentication/accounting traffic. |
| Syslog | 514 (UDP and TCP) | On on zones other than WAN. It is off on WAN and is recommended to stay that way. |
The Trusted Hosts gate — the #1 reason for “I turned it on but it doesn't work”: The Captive Portal, RADIUS and Syslog permissions are, together with your turning the switch on, also subject to a source-address check. The source list is managed from the Trusted Hosts page:
- If there are specific addresses/network blocks in the list, access is granted only to those sources.
- If
0.0.0.0/0is in the list, no source restriction is applied.- If the list is empty or cannot be read, no permission is generated at all. Even if the switch in the zone setting appears on, the traffic does not pass.
Why Syslog matters: The logs of your firewall and network devices come through this gate. If Syslog is off on the relevant zone, the logs are dropped without producing any error; no warning appears on screen, only the log flow stops. This is the first place to look for the complaint “the logs aren't coming.” If you turn off Syslog on a zone, your decision is permanent; the system does not turn it back on by itself.
What the message you get on save means
| Message | What actually happened |
|---|---|
| Zone settings saved and applied to the active router | Router mode is active; the rule is in effect immediately. |
| Zone settings saved (will be applied when router becomes active) | Router mode is off; the setting was stored, the live behavior did not change. |
| Settings saved BUT could not be applied to the live router: … | The setting was stored but the rules could not be loaded; the live behavior continues in its old form. Do not consider the operation finished — try applying again. |
| Zone not found | The zone may have been deleted in the meantime; refresh the page with Refresh. |
Lockout protection
You cannot turn off HTTPS / HTTP / SSH access over the interface of the zone through which you are currently connected for management. If you try, you get the warning: “You are currently connected for management over this zone (…) — if you restrict HTTPS/HTTP/SSH access from here you may lock yourself out. Make this change from the management (mgmt) interface.” The protection works for the underlying interface carrying your connection; you can connect from another interface and make the change.
The MGMT zone is no longer privileged
In terms of routing, address translation and spoof-source protection, MGMT is now an internal zone like LAN; only its name is different.
- When you assign an interface to the MGMT zone and give it an IP, it behaves like the other internal zones. As long as you do not give it an IP, no behavior changes.
- Assigning the management interface to the WAN zone is no longer blocked at the assignment stage; however it is not accepted as the uplink. When you try to enable router mode, it stops with the error “The interface in the WAN zone (…) is the management interface — assign a separate interface for the uplink.”
- On the MGMT zone, Zone Settings shows only the Captive / RADIUS / Syslog section.
Captive Portal (wireless icon)
The Captive Portal is an interface feature: you select the zone, then determine on which interface within that zone the portal will run. The portal runs on the single interface you select as Interface in the window. This button exists only on LAN / DMZ / Guest / Custom zones; on WAN and MGMT it shows “—”.
| Field | Description |
|---|---|
| Interface | One of the interfaces within the zone. If the zone is empty, it says “No interface in this zone — assign one from the Interfaces page.” |
| Captive portal active | Turns the portal on/off on this interface. |
| Network (automatic) | Gateway IP, Prefix (/bits), DHCP start, DHCP end. Filled from the existing configuration; if there is no value, a suggestion is generated based on the zone. The prefix field suggests 8–30, and when saving the valid range is 8–32; if left blank, 24 is used. |
| Redirect URL | Optional. The address the user goes to after authentication. If empty, the user is redirected to the gateway. |
| Allowed Addresses | Optional. Addresses reachable before authentication. You can select a ready-made address object and/or type IP/CIDR by hand separated by commas. Name resolution is already allowed. |
On save: if you marked the portal active, the interface's network setting is written first (manual IP + address distribution), then the portal setting is saved. If Gateway IP is empty, you get the warning “Gateway IP required” and nothing is saved.
Banners that may appear at the top of the modal: “Router mode is not active — the setting is saved and will be applied when router becomes active.” · “License invalid — captive is not applied; traffic flows normally (fail-to-wire).” So a license issue does not cut guest traffic, it just means the portal does not kick in.
The portal's design, language, login method and users are managed not on this page but in the
Hotspot Management › Captive Portalsection.
Deleting a zone
The delete button appears only on zones you added yourself. Deletion is blocked in the following cases:
- “There are interface(s) assigned to this zone — first move/remove the interfaces to another zone.”
- “This zone is used in a security rule — first delete the relevant rules.”
Deletion is irreversible. Along with the zone, the default internet rule automatically created for that zone is also removed. The operation is written to the audit trail.
This page does
- Creates/deletes zones
- Sets intra-zone traffic, access to the device, and Captive/RADIUS/Syslog permissions
- Enables the captive portal on an interface and sets up its network automatically
This page does not
- Assign interfaces to a zone → Interfaces
- Write allow/deny between zones → Rules
- Change the rules of external firewalls
- Manage the portal content →
Hotspot Management
5 · Addresses
Menu path · ·Stores the IP definitions frequently used in security rules as named objects. You define it once and use it over and over in many rules. When you write “Accounting-Server” instead of 192.168.10.50, it is clear at a glance who the rule is talking about.
Its biggest advantage: if the address changes, you update it in a single place, and all rules using that object automatically stay current.
Screen — Firewall Management › Addresses
Address types
| Type | Definition | Example |
|---|---|---|
| Host | A single device's IP address (server, printer). | 10.0.0.5 |
| Subnet | An entire subnet, in CIDR notation. | 192.168.10.0/24 |
| Range | Consecutive IPs, as start–end. Useful when the block does not fit exactly into a full subnet. | 192.168.1.100 – 192.168.1.150 |
| Group | A collection that gathers multiple address objects under one roof. | Servers = {A, B, C} |
Why use an object?: When writing a rule you can also type CIDR by hand into the source/destination field; the system accepts it. However, using a named object is recommended for manageability: you don't repeat the same address in dozens of rules, no rule is left forgotten on a change, and the rules become readable for everyone on the team.
How to do it
- Add Address
Click the Add Address button on the page.
- Give a clear name
For example “Warehouse-Cameras.” Choose the name so that someone else will understand it six months later.
- Select a type
Host, Subnet, Range or Group.
- Enter the values
A single IP for Host,
network/maskfor Subnet, the start and end IP for Range. - If you chose Group, check the members
Select the address objects to include from the list.
- Save
The object can now be selected as a source/destination in rules and in SD-WAN rules.
If the address changes later, open the relevant object and update the value; all rules automatically use the new value.
6 · Services
Menu path · ·The place where you turn protocol + port combinations into named objects. A service defines the type of traffic; a port is not a separate object, it lives inside the service. This way, instead of writing “tcp/443” in rules, you just select HTTPS.
Screen — Firewall Management › Services
Predefined and custom services
- Predefined services: Frequently used protocols come defined in the system and can be used immediately. Built-in and in-use objects cannot be deleted.
- Custom services: You define the port/protocol your own application uses (e.g. a management panel's
tcp/8443). Creating a custom service for applications running on non-standard ports keeps the rules understandable. - Service groups: Gather multiple services into a single collection — for example Web = HTTP + HTTPS. When you update a service, all groups and rules using it automatically use the new definition.
How to do it
- Add Service
Click the New Service button on the Services tab.
- Give a name
Make it understandable: “App-Management.”
- Select a protocol
TCP, UDP or both (TCP_UDP). No port is used for ICMP.
- Enter a port or range
A single port, a comma-separated list or a range.
- Save
The service can now be selected in rules and groups.
- Create a group if needed
On the Service Groups tab, bring the relevant services together with New Service Group.
7 · Firewall Rules
Menu path · ·A security rule defines what will be done with traffic coming from which source, to which destination, with which service. Rules are evaluated top to bottom; the first match is applied, and traffic that matches none is denied.
Screen — Firewall Management › Rules
The parts of a rule
| Field | What is written |
|---|---|
| Source Zone → Destination Zone | The rule works in this direction. Example: LAN → WAN = from the internal network to the internet. It can also be same zone → same zone. By default, internet is open from internal zones to WAN; between zones (e.g. GUEST → LAN) it is closed by default. |
| Source / Destination Address | Address object (recommended) — Host, Subnet, Range, Group — or manual CIDR. If both are empty, any. Multiple addresses/groups can be selected for a rule. |
| Service | Select a service object or service group, or type a manual protocol+port. When you select an object, the manual fields become inactive. Empty = any. |
| Action | Allow · Block (silent drop) · Reject (drop and notify the sender). |
| Order | A smaller number is evaluated first; the first match is applied. |
| State | Disables the rule. Default rules cannot be deleted but can be turned off via State. |
Implicit Deny (∞): Traffic matching no rule is automatically denied. This row is shown read-only in the list; you cannot remove or change it. Your policy being “default closed” is thanks to this row.
Communication within the same zone is not managed from here: Whether the interfaces within the same zone see each other is now set separately for each zone:
Zones › the relevant zone › Zone Settings › Intra-zone Traffic.
How to do it
- Select the zone pair
Source Zone and Destination Zone. Direction matters; you do not need to write a separate rule for return traffic.
- Set the source/destination address
With + Select, object(s) or manual CIDR. Leaving it blank means “any.”
- Set the service
With + Select, service object(s) or manual protocol + port. Empty = any.
- Set the action and order
Put specific blocks at a low order and general allows at a high order.
- Save
If the router is active, the rule is applied immediately. Verify the behavior you expect with Monitor › Live Traffic.
Ordering habit: The “deny first, then allow” arrangement is readable: 100–499 for narrow-scope blocks, 500–999 for specific allows, 1000 and above for default broad allows. This way, when adding a new rule it is clear which band to use.
8 · NAT / Port Forwarding
Menu path · ·Manages how the device translates IP addresses between the internal network and the internet (WAN). NAT (Network Address Translation) determines how private internal addresses appear to the outside world.
Screen — Firewall Management › NAT / Port Forwarding
Source NAT (SNAT / Masquerade)
Changes the source IP address of traffic going out from the internal network to the internet. Devices on the internal network use private addresses; these are not valid on the internet. SNAT translates the source of this traffic to the device's WAN IP, letting it reach the outside.
| Option | When |
|---|---|
| Masquerade (default) | Whatever the WAN IP is (fixed or variable), all egress traffic is automatically translated to the WAN address. Sufficient for most sites. |
| Custom SNAT rule | When you want to translate a specific source (a single server or subnet) to a specific external IP. If you have multiple WAN IPs, you set here which traffic exits from which address. |
Port Forwarding (DNAT)
Delivers incoming traffic from outside to a server inside. It forwards a specific port of traffic arriving at WAN to an internal host:port address. The external port and the internal port can be different (external 8443 → internal 443).
Surgical transit (forward-accept): When you define a port forward, the firewall allows traffic only to that target host:port; the rest of the internal network is not opened. You expose a single service without putting the whole network at risk.
Things to watch:
- Port forwarding exposes the internal server to the internet — use it only for services that genuinely need to be reached from outside.
- The internal target host must use a fixed (static) IP; if its address changes via DHCP, the rule breaks. Define a MAC → IP reservation if needed.
- Two different internal targets cannot be defined for the same external port; each external port goes to a single target.
How to do it
- Open the page
Firewall Management › NAT / Port Forwarding. - For source NAT
On the SNAT / Source NAT tab, Add SNAT rule; leave masquerade or specify a source/external IP.
- For port forwarding
Click the Add Port Forwarding button.
- Enter the values
External port, protocol (tcp/udp), internal host and internal port.
- Save and test from outside
Be sure to test not from the internal network but from an external connection (such as mobile data).
9 · SD-WAN
Menu path · ·In setups with multiple internet lines (WAN), it gathers the lines' configuration, their real performance, and which traffic exits over which line in one place. Adding/removing a line is not done here; this page shows interfaces assigned to the WAN zone.
The page works with router mode. If the mode is off, the warning “Router mode is not active — lines are not configured.” appears at the top; the settings you make are saved but reach the field only when the mode is enabled.
Screen — Firewall Management › SD-WAN
Lines tab
| Column | Meaning |
|---|---|
| Interface | The line's actual egress interface. The line with the lowest Distance value is marked with the Primary badge. |
| Mode | The addressing mode: DHCP, STATIC or PPPOE. |
| IP / Gateway | The line's current address and the gateway coming from the provider. Read from the system; appears empty if PPPoE has not connected. |
| Distance | Line priority. Detailed below. |
| State | No line (the interface has not formed yet) · Measuring (not yet probed at all) · Working · No access. If you hover over the last badge, you see the last error text. |
| Latency / Loss | The average latency and loss rate in the last measurement window. Green below the warning threshold, yellow when the threshold is exceeded, red when it exceeds twice the threshold. For loss, any value above zero is at least yellow. |
| Routing | Whether source-based routing has been prepared for that line. If Ready, the line can actually work over its own path. If Waiting, the line's IP or gateway is not yet known. |
If no WAN interface is assigned, the list says “No interface assigned to the WAN zone.” In this case, first assign an interface to the WAN zone from the Interfaces / Zones screens.
What Distance is for
Distance is the line preference order: smaller value = preferred line. If left blank (0), it is considered “unspecified” and the line drops to the bottom of the list. On equal values, the interface name decides.
- The accepted range is 0–255. If you go outside it, you get the error “Distance must be in the 0-255 range.”
- Distance is only meaningful on interfaces in the WAN zone; if attempted for another interface, it returns “Distance is set only on interfaces in the WAN zone.”
- The value is saved the moment you type it into the box and leave the field; there is no separate save button.
- Distance does not by itself provide automatic line switching. When a line breaks, the system does not switch it for you.
When the new priority takes effect: A Distance change settles in two stages: the security and NAT handling is rewritten immediately, but the per-line routing arrangement is updated on the system's periodic refresh cycle that runs every 60 seconds. So the new priority fully settles within at most a minute. On PPPoE lines, for the Distance to take effect as the metric of the provider default route, the line needs to reconnect.
Capabilities card
Works
- Multi-line data plane — NAT and security rules cover all WAN lines
- Per-line routing — each line has its own table; the backup line does not fall into “got an IP but no traffic flows”
- Performance measurement — latency and loss are measured continuously
- Line-selection rules — egress line by source, destination, protocol and port
- Fallback within a rule — while the rule's line is unreachable, that traffic exits over a working line
- Adjustable measurement — targets, interval and thresholds from this page
Not yet
- Automatic switching for out-of-rule traffic — the default line for traffic that matches no rule does not change automatically; you set it with Distance
- Load sharing — there is no distributing traffic across multiple lines at once; a session exits over a single line
Performance SLA tab
Each line is probed separately over its own interface. The probe is a TCP connection attempt, not a ping; that is why the targets are given with an address and port. The probe works only while router mode is active.
Do not leave a field blank: If you clear a field, that setting is not treated as “unchanged”: the blank value is sent as zero and the system pulls it down to the field's smallest accepted value (interval 5 s, window 5 samples, timeout 1 s, threshold counters 1, latency threshold 10 ms, loss threshold 1%). Leave the fields you don't want to change as they are; don't delete them.
| Setting | Range | Recommended | Note |
|---|---|---|---|
| Measurement targets | at most 8 | 3 targets | In address:port form, comma-separated. If any of them responds, the line is considered working. Use a different provider and a different port — some upstreams block outgoing DNS. |
| Measurement interval (s) | 5 – 300 | 20 | How often the lines are probed, in seconds. |
| Timeout (s) | 1 – 30 | 4 | Must be shorter than the measurement interval; if not, it is rejected with the error “Timeout must be shorter than the measurement interval.” |
| Evaluation window | 5 – 120 | 15 samples | Over how many samples the loss and average latency are computed. With a 20 s interval, a ≈5-minute window. |
| How many failures for “no access” | 1 – 20 | 3 | How many consecutive failed probes before the line is considered unhealthy. |
| How many successes for “working” | 1 – 20 | 2 | These two values together prevent “flapping” behavior. |
| Latency warning threshold (ms) | 10 – 5000 | 250 | For display only. |
| Loss warning threshold (%) | 1 – 100 | 10 | For display only. |
Thresholds do not bring a line down: The warning thresholds determine color only. Whether a line is considered unhealthy is determined not by the thresholds but by the “how many failures for no access” counter. A line is not disabled just because the latency threshold was exceeded.
When you press Save, the values take effect immediately; no service restart is needed. The Restore recommended values button only fills in the form, it does not save. If you change the Evaluation window, the accumulated measurement history is reset and the values refill over a few cycles — this is temporary, not a fault.
Common SLA errors
| Message | Cause |
|---|---|
| Target must be in 'address:port' form — invalid: … | A target has no port or the format is broken. The invalid target is written in the message. |
| Target port invalid: … | The port is outside 1–65535. |
| At least one probe target is required | The target field was left blank. |
| At most 8 targets can be defined | Shorten the list. |
SD-WAN Rules tab
Rules make specific traffic exit over a specific line. Example: “let all traffic leaving the accounting network exit over the fiber line, and the guest network over the 4G line.”
Order matters: Rules are evaluated top to bottom and the first matching rule wins. Narrow-scope rules should be at the top, broad-scope ones at the bottom. The Move up / Move down arrows are not cosmetic but a behavior change and are applied immediately. A newly added rule is always added to the bottom of the list.
Rule fields
| Field | Description |
|---|---|
| Rule name | Required, at most 128 characters. If empty, “Rule name required.” |
| Enabled | If you turn it off, the rule is kept but not applied. It can also be changed with the on/off icon in the list; it takes effect immediately. |
| Send this traffic over this line | Required. The list comes only from the interfaces in the WAN zone; each option appears as “interface · zone · mode.” |
| Source / Destination address | With Select, an address object or a single IP / CIDR in the box. If both are empty, “all.” |
| Service | With Select, a service object or a protocol list (All / TCP / UDP / ICMP) + a port box. The port can be a single value (443), a comma-separated list (80,443) or a range (5060-5070). If ICMP is selected, the port is ignored; if the protocol is All and you write a port, the rule is applied for both TCP and UDP. |
Selecting an object locks manual entry: When you select an object, that field's manual-entry box is locked and its content cleared. Entering two criteria at once is deliberately prevented because it would make it ambiguous which one is in effect. If you want to type manually, first remove the selected objects.
The address and service objects come from the same pool as the security rules — what you define on the Addresses and Services screens is also selectable here.
If the rule's line is unreachable
If the rule's target line is in the No access state, that rule's routing is not set up: the traffic does not go to a “black hole,” it falls back to the working default line. When the line becomes healthy again, the rule comes back into effect on its own. The timing is two steps: first the line being considered unhealthy (how many failures for no access × measurement interval; ≈1 minute with the recommended values), then the next periodic refresh cycle (at most 1 minute). So the switch is typically within a few minutes.
If the rule's line is no longer in the WAN zone or the interface never formed, the Line information appears as a red “Line not found” — this means the rule is not being applied.
Rule scope
- Rules are applied to traffic going from inside to outside. Return traffic coming from outside is deliberately out of scope; otherwise sessions would break.
- Traffic the device itself generates (line probes, system updates) is not routed by these rules.
- If no internal interface is defined, the rules are ineffective.
Errors encountered on save
| Message | Cause / resolution |
|---|---|
| A rule must have at least one criterion (source, destination or service). | A rule with all three empty would pin all internal traffic to a single line. If you really want “everything exits over this line,” write a deliberate criterion such as giving the destination as 0.0.0.0/0. |
| Select a valid line / Select a line. | No line selected or it is not recognized. |
| The selected interface is not in the WAN zone | If a rule routes to an internal interface, the traffic would go nowhere; therefore it is rejected. |
| Source/Destination address invalid (IP or CIDR) | Only a single IPv4 address or CIDR notation is accepted. |
| Port invalid (e.g.: 80, 80,443, 1000-2000) | The port expression is broken, outside 1–65535, the end of the range is smaller than the start, or the expression exceeds 128 characters. |
| One of the selected address/service objects no longer exists | An object was deleted elsewhere while you were editing the rule. Press Refresh and make the selection again. |
Deletion: the trash can asks for confirmation and the rule is permanently deleted; it cannot be undone. The rule's address/service links are also cleared, so those objects can be freely deleted again.
Recommended setup order (SD-WAN):
- Assign the lines to the WAN zone.
- On the Lines tab, give each line a Distance; the smallest value to the primary. Wait a minute for it to take effect.
- Wait for Routing = Ready and State = Working. A persistent Waiting means the line has no IP or gateway.
- Tune the Performance SLA to your environment; raise the timeout and the failure count on satellite/mobile backup lines. Don't leave any field blank.
- Define the required Address and Service objects.
- Add and order the SD-WAN Rules starting from the narrowest scope.
- Verify the result from the Line information: a rule saying red Line not found is not being applied.
10 · Static Routes
Menu path · ·You manually define how the device will reach networks it is not directly connected to. Each static route specifies which gateway (next hop) to send traffic destined for a given network through; it is used to set up fixed paths without a dynamic routing protocol.
The device automatically recognizes networks connected to its own interfaces. For networks beyond those — for example another branch or a network behind another router — it does not know where to forward the traffic. A static route closes this gap.
| Field | Description |
|---|---|
| Destination Network (CIDR) | The network you want to reach, in network-address-and-mask form (e.g. 10.20.0.0/24). |
| Gateway | The next-hop IP to which traffic destined for the target is delivered. Usually the address of a neighboring router on the same local network as you. |
| Egress Interface | Optional. Selected if the gateway is not on a directly connected network; the route is set up as onlink over the specified interface. Any interface, including management (mgmt), can be selected. If the gateway is on an already connected network, leave it blank. |
| Metric | The priority if there are multiple paths to the same destination. A lower metric has higher priority. |
Lockout protection: Routes that cover the management path through which you access the device remotely are blocked. Also, a route covering the default route (
0.0.0.0/0) cannot be added. If you try to add such a route, the operation is rejected.
A route does not grant access: A static route only defines the path to the destination; access is still managed via Rules (zone → zone). If traffic still doesn't pass after adding a route, check whether there is an allow rule for the relevant zone pair.
How to do it
- Add Route
Click the button at the top right.
- Enter the destination network
As CIDR, as narrow as possible (e.g.
192.168.50.0/24). Avoid overly broad blocks. - Write the gateway
The next-hop IP. Make sure it is genuinely reachable and on the correct interface.
- Select an egress interface if needed
Specify it only when the gateway is not on a connected network; otherwise leave it blank.
- Set the metric
If there are multiple paths to the same destination, give a smaller value to the one you prefer.
- Save and verify
Check that the route appears with the
statictype on the Monitor › Routes tab.
11 · DHCP & DNS
Menu path · ·Manages the automatic IP address distribution to your internal-network (zone) interfaces and the DNS servers the device will use. It works independently of the interface settings; you choose a separate role for each interface.
Screen — Firewall Management › DHCP & DNS
Interface roles
| Role | Behavior |
|---|---|
| Off | No DHCP service is provided on this interface; clients must get their IPs manually. |
| DHCP Server | Automatically distributes settings such as address, gateway and DNS to the devices on this interface. |
| DHCP Relay | Does not give out addresses itself; forwards the requests to a central DHCP server on another network. When the address pool is managed from a single center, devices on remote networks can also get addresses from the same server. |
Server and Relay cannot be used together on the same interface.
DHCP server settings
| Setting | Description |
|---|---|
| Pool range | The start and end IP of the addresses to be distributed. |
| Lease time | How long a device will use the address it received; when the time expires, the address is renewed. |
| Gateway (opt 3) | The router address clients will use when going out. |
| DNS servers (opt 6) | The servers to be used for domain name resolution. |
| Domain (opt 15) | The domain suffix given to clients. |
| Excluded ranges | Addresses that, although within the pool, will not be distributed and are reserved for manual use. |
| Advanced options | Custom option codes: NTP (42) time server, WINS (44) name resolution, MTU (26) packet size, PXE (66-67) network boot, and general code-value pairs. |
Reservations and leases
- MAC → IP reservation: Ensures that a specific device gets the same fixed IP every time. The IP must be within the scope of a zone with the DHCP server on.
- Active leases: Shows the devices that currently have an address, their IPs and their lease end times.
Together with port forwarding: So that the address of the internal server you exposed does not change, define a MAC → IP reservation for that device. This way the port-forwarding rule is not broken by a DHCP renewal.
DNS servers
The servers you enter are used both for the device's own name resolution and for resolution on behalf of clients. Save is applied to both the WAN profile and the client resolver together. If left blank, they are chosen automatically: with PPPoE, the service provider's DNS servers, otherwise public servers. The upstream DNS you entered in the router-mode activation wizard also appears here.
How to do it
- Select the internal interface
Click Configure Pool in the row of the interface you want to configure.
- Set the role
Off, DHCP Server or DHCP Relay.
- If you chose Server, enter the basic values
Pool range, lease time, gateway and DNS.
- Define exclusions and advanced options
Exclude manually used addresses from the pool; add options such as NTP/PXE if needed.
- Add reservations
Define MAC → IP mappings for devices that need a fixed address.
- If you chose Relay
Enter the central DHCP server address(es).
- Save and verify
See that distribution is working from the Active Leases list.
12 · Log Settings
Menu path · ·Determines which log types the device will generate in its own firewall mode. The aim is to be able to take operational noise out of scope while preserving the legally mandated pass-through traffic log.
Screen — Firewall Management › Log Settings
If you can't find the page: This menu heading is not visible on every account: it is listed only while the device is on in its own firewall (router) mode and when logged in with an administrator account that is a member of the root domain.
Log types
| Type | Default | Description |
|---|---|---|
| Pass-through traffic | Mandatory | Traffic going from users to the internet. This is the actual evidence that must be kept under Law 5651; the switch is visible but cannot be clicked, and a request to turn it off is ignored even if sent from outside the interface. The log is generated from established (permitted) connections. |
| Traffic to/from the device | Off | The device's own connections (data store, search engine, syslog). Not required for Law 5651. In field measurement, about 99% of the total rows were this type — writing logs generates new connections, which were then logged. Turn it on temporarily while troubleshooting, and off when you're done. |
| DHCP allocation events | On | Which IP was given to which device (MAC) and when, released or denied. Because it strengthens identity determination, it is recommended to leave it on. Turning it off only stops these events from being written; it does not affect the DHCP service or the guest sessions. |
| User authentication events | On | Login and logout events from the captive portal. |
| System events | On | Interface state changes and configuration-apply records. |
| Add destination domain name | On | Adds the destination's domain name to the log row (the site name appears instead of the IP). The domain name comes from a temporary mapping kept from the device's DNS responses. |
The User authentication and System events switches store your selection and are shown as the current scope on the Overview screen; however, there is currently no source that produces a separate row in the firewall log file for these two types — turning the switches on and off makes no visible difference in the file.
The limits of the destination domain name:
- Browsing/visit history is not kept. DNS query rows in the form of “who asked for what” are deliberately ignored; only the destination of a connection that is actually established is written.
- If the client uses encrypted DNS (DoH/DoT), the domain name does not reach the device; in that case the domain is not written at all, and no guess is produced.
How the boxes are computed
- The Pass-through traffic / Device traffic / Event counts and percentages are counted from the last 4 MB portion of the current daily log file — a representative sample of the most recent period, not of all history.
- The Record file value is the current size of the entire file. That is why the percentages and the size do not come from the same scope.
- The values are retrospective: a switch change you just made is not immediately reflected in the boxes.
- If all boxes show 0, it means the day's log file has not yet formed or cannot be read — it does not mean the settings are broken.
When a change takes effect
It is in effect the moment you press Save; no service restart is needed. When the settings cannot be read, the system continues generating logs with the last known scope — that is, a failure to read the setting does not turn into a log interruption.
What is irreversible?: The setting itself can always be undone. However, logs not generated during the time it was off cannot be brought back later. Before turning a type off, consider whether there is an investigation you might need for that period.
In terms of Law 5651: what not to turn off
| Type | Recommendation |
|---|---|
| Pass-through traffic | Cannot be turned off anyway. This is what fulfills the legal obligation. |
| DHCP allocation events | Do not turn off. The IP–MAC–time mapping is the most direct way to show which device an IP belonged to at a given moment. |
| Add destination domain name | Turning it off does not create a legal gap, but it markedly reduces readability during an investigation. |
| Traffic to/from the device | It is not legal evidence; keeping it off is the expected use. |
Scope declaration: Shortly after midnight each day, the “how much log was generated, how much could not be generated” information for that day is written to the same file as an event row and signed. This row cannot be turned off with any switch and is included in the count in the Event box. Its purpose is that, if there is a gap during an audit, it can be declared.
Recommended use
- Look at the boxes: if the Pass-through traffic percentage is low and Device traffic is high, the noise scope has been left on
- Keep Traffic to/from the device off; turn it on only temporarily while troubleshooting
- Keep DHCP allocation events and Add destination domain name on
- Don't be in a hurry expecting the distribution to change until the next day after you save
This page does not
- Manage the log retention period, rotation, signing or archiving
- Affect logs coming from external firewalls
- Produce a “rejected” row for blocked traffic
- Offer a threshold that stops generation based on disk fullness
- Store visited sites as browsing history
Frequently seen messages
| Message | Meaning |
|---|---|
| Settings could not be retrieved. | The scope information could not be read. Your session may have dropped, you may lack view permission, or the backend service may be temporarily unreachable. Try with Refresh; if it persists, log out and back in. |
| Could not be saved. | The save request was not accepted; the reason appears in the rest of the message. For an authorization error, the enable/configure permission is required. |
| Log settings saved. | The scope was updated and took effect immediately. |
End-to-end scenarios
The flows below explain, from start to finish, the configurations most often set up in the field. Each step states which page it is done on.
Scenario A · Single WAN + single LAN basic setup
- Assign the uplink interface to WAN
Interfaces→ the interface where the internet cable is plugged in → Zone: WAN, Mode: DHCP client / Static / PPPoE depending on your ISP. Do not select your management interface. - Assign the internal interface to LAN and give it an IP
Zone: LAN, Addressing: Manual, IP:
192.168.100.1, Prefix:24. This IP will be the gateway of the internal network. - Define the DHCP pool
DHCP & DNS→ the eth1 row → Configure Pool → Role: DHCP Server, pool192.168.100.100 – .200, lease 12 hours, gateway192.168.100.1, enter the DNS servers. - Enable router mode
Status › Router Mode→ wizard → confirmation time 120 s → confirm → Confirm and Make Permanent. - Verify
Overview: no warnings, Internet present, Pass-through traffic > 0. Go out to the internet from a client and see the row onMonitor › Live Traffic.
Scenario B · Guest network over VLAN + captive portal
- Add a VLAN sub-interface
Interfaces→ Add VLAN → parent interface eth1, VLAN 30. (A WAN VLAN cannot be added on the management interface.) - Assign it to the guest zone
Set the new sub-interface's zone to GUEST; Addressing Manual, IP
192.168.130.1/24. - Turn on the captive portal
Zones→ the wireless icon on the Guest row → Interface: eth1.30 → Captive portal active → fill in the Gateway IP and DHCP range → Save. - Open captive access
In the same zone's Zone Settings › External Device Access section, turn on the Captive Portal switch; then make sure the relevant sources are in the
Trusted Hostslist. - Close the Guest → LAN transit
Rules→ add a low-order GUEST → LAN · Block rule. (It is blocked by default already; this rule explicitly documents your intent.) - Prepare the portal content
Set the design, language and login method from the
Hotspot Management › Captive Portaland Portal Design Management sections.
Warning: To prevent guest devices from seeing each other, the intra-zone switch is not enough — in a single-interface zone, the traffic never reaches the box. Do the isolation on the access-point side (client isolation).
Scenario C · Exposing an internal server
- Fix the server's address
DHCP & DNS › MAC → IP Reservations→ reserve192.168.100.10for the server's MAC (or give the server a static IP). - Define an address and a service object
Addresses→ “Web-Server” = Host192.168.100.10. If needed,Services→ a new service for the custom port. - Add the port forward
NAT / Port Forwarding→ Add Port Forwarding → prototcp, WAN port443, target192.168.100.10:443. - Test from outside
Verify access from an external connection such as mobile data. Thanks to surgical transit, only this host:port is opened.
- Narrow the source if needed
If access is wanted only from specific external addresses, write a rule in
Rulesin the WAN → DMZ/LAN direction that limits it with a source address object.
Scenario D · Adding a second internet line
- Assign the new line to the WAN zone
Interfaces→ the backup line's interface → Zone: WAN, Mode: PPPoE/DHCP/Static. - Give a Distance
SD-WAN › Lines→10for the primary line,20for the backup. Wait ~1 minute for it to fully take effect in routing. - Wait for the state to settle
For both lines you should see State: Working and Routing: Ready.
- Tune the SLA to your environment
On a mobile/satellite backup line, raising the timeout and the “how many failures for no access” value reduces false alarms.
- Write a line-selection rule
SD-WAN › SD-WAN Rules→ “Guest network over the backup line” → source: the guest subnet object, line: the backup interface. Keep the narrow-scope rule at the top of the list. - Verify the behavior
Make sure the rule's Line information does not say red Line not found.
Set the right expectation: The backup line kicks in automatically for traffic within the rule's scope. If the line of traffic outside the rule's scope breaks, the system does not switch to the other line on its own — you set the preference with Distance. There is no load sharing.
Scenario E · Making external firewall logs arrive
- Determine the zone of the log-sending device
The zone of whichever interface the device comes from.
- Check the Syslog switch
Zones › the relevant zone › Zone Settings › External Device Access→ Syslog must be on (it is on by default on non-WAN zones). - Verify the Trusted Hosts list
The address of the log-sending device must be in the list. If the list is empty, no permission is generated — even if the switch appears on, the traffic does not pass.
- Verify the flow
Check on the
Firewall Log Searchscreen whether records appear in the same time range.
Troubleshooting
A quick table that, starting from the symptom, points to the most likely cause and the page to look at.
| Symptom | Possible cause | Where to look |
|---|---|---|
| The Firewall Management menu is not visible | Router mode is off, or the account is not a member of the root domain / lacks permission. | Status › Router Mode |
| Router mode won't turn on: “management interface” error | The interface you assigned to the WAN zone is the management interface. It is not accepted as the uplink. | Readiness checks |
| Router mode won't turn on: “an IP must be assigned to an internal-zone interface” | The internal interface has no L3 address. | Interfaces |
| The mode turned on, then turned off on its own | Confirm and Make Permanent was not clicked within the confirmation time; lockout protection rolled it back. | The confirmation window |
| Clients can't get an IP | DHCP is on in the zone but the service is not running, or the role is Off/Relay. | DHCP & DNS · Overview › Health |
| No internet but the interface is “Connected” | The line is up but there is no exit to the outside (operator side). The probe sees this, the connectivity box does not. | Overview › Internet line |
| I wrote a rule but traffic doesn't pass | The interface is in the wrong zone, the rule order sits below a block higher up, or it falls into implicit deny. | Rules · Monitor |
| Port forwarding doesn't work | The internal target's IP changed via DHCP; or the same external port is defined for another target. | NAT · Reservations |
| I turned on Captive/RADIUS but there's no access | Trusted Hosts is empty or the source's address is not in the list. | Trusted Hosts |
| Firewall logs aren't arriving | Syslog is off on the relevant zone or Trusted Hosts is missing. The logs are dropped without producing an error. | Zone Settings |
| “Pass-through traffic” count is 0 | Client traffic is not passing through the box — a placement or default-gateway problem. It is not a settings problem. | Overview › Record Generation |
| The record file is growing rapidly | Traffic to/from the device was left on; this type produces ~99% of the rows. | Log Settings |
| Session is open but the user can't get out | The No-authorization badge in Monitor: the session exists, but there is no transit permission in the data plane. | Monitor › Sessions |
| The SD-WAN rule is not being applied | The rule's line was removed from the WAN zone or the interface never formed → Line not found. | SD-WAN Rules |
| The line seems to keep going up and down | The SLA thresholds are too aggressive. Raise the “how many failures for no access” and the timeout. | Performance SLA |
| “Settings saved BUT could not be applied to the live router” | The setting was stored, the rules could not be loaded. The live behavior is in its old form. Do not consider the operation finished. | Try applying again |
| I can't turn off management access | You are currently connected over that zone; lockout protection is preventing it. | Connect from the management interface and try again |
Law 5651 and record generation
The importance of router mode for compliance is this: the record now rests not on a report sent by another device but on the traffic SignLogger itself sees. This removes an intermediary layer from the chain of evidence.
| Topic | Status |
|---|---|
| Pass-through traffic log | It is mandatory and cannot be turned off. It appears locked in the interface; a request to turn it off is ignored even if sent from outside the interface. |
| Scope of the record | One row for each permitted (established) connection. No “rejected” row is produced for blocked traffic. |
| Identity mapping | DHCP allocation events tie the IP–MAC–time triple to the record; do not turn it off. |
| Readability | While Add destination domain name is on, the site name also appears instead of the IP. Browsing history is not stored separately. |
| Daily scope declaration | Every night, that day's generation/gap information is written as an event row and signed. It cannot be turned off. |
| License effect | If the license is invalid, routing continues but the captive portal and compliance records stop. |
| Retention and signing | Outside the scope of this page; retention period, rotation, signing and archiving are managed separately. |
The most common mistake: Leaving the Traffic to/from the device switch on. This type is not legal evidence, but in the distribution measured in the field it produces about 99% of the rows — the log file bloats, searches slow down, and the actual evidence gets buried in noise. Turn it on only temporarily while troubleshooting.
Appendix A · Defaults and limits
| Setting | Default | Limit / note |
|---|---|---|
| Confirmation time | 120 s | 30 – 900 s (server upper limit 900) |
| Zone name | — | 1–32 characters; letters, digits, _, - |
| VLAN number | — | 1 – 4094 |
| IP prefix | 24 | 8 – 32 (the form suggests 8–30) |
| Intra-zone traffic | On | Not present on WAN and MGMT |
| Internal-zone management ports | On | HTTPS · HTTP · SSH · Telnet · Ping |
| WAN-zone management ports | Off | Turning them on exposes the device directly to the internet |
| Captive Portal access (zone) | Off | Ports 8080, 8081, 8084, 8086 |
| RADIUS access (zone) | Off | Ports 1812, 1813 |
| Syslog access (zone) | On except WAN | Port 514, UDP + TCP |
| Distance | 0 (unspecified) | 0 – 255; smaller value is preferred |
| Distance propagation time | — | Security/NAT immediately, routing within at most 60 s |
| SLA measurement targets | 1.1.1.1:443 · 8.8.8.8:443 · 8.8.8.8:53 | at most 8 targets, address:port |
| SLA measurement interval | 20 s | 5 – 300 s |
| SLA timeout | 4 s | 1 – 30 s; must be shorter than the interval |
| SLA evaluation window | 15 samples | 5 – 120 samples |
| How many failures for “no access” | 3 | 1 – 20 |
| How many successes for “working” | 2 | 1 – 20 |
| Latency warning threshold | 250 ms | 10 – 5000 ms (display only) |
| Loss warning threshold | 10% | 1 – 100% (display only) |
| SD-WAN rule name | — | at most 128 characters |
| Monitor time range | Last 15 minutes | 5 min · 15 min · 1 hr · 6 hr · 24 hr |
| Monitor auto refresh | On | Every 10 seconds |
| Live Traffic list limit | 300 connections | The counter writes “shown / total” |
| Sessions list limit | 500 sessions | The “Open sessions” on the top strip is also subject to this limit |
| Users / Devices / Destinations | 15 records | Sorted by total data |
| Overview · live boxes | 4 s | Other sections 20 s |
| SD-WAN Lines / SLA refresh | 15 s | The rule list does not refresh on its own |
| Active session warning threshold | 8000 | Above it, turns to warning color |
| Log sampling window | last ~4 MB | The numbers in the boxes come from this sample |
| Device traffic log | Off | Produces ~99% of the rows |
| DHCP allocation / authentication / system events | On | Turning them off is not recommended |
| Pass-through traffic log | On | Locked — cannot be turned off |
Appendix B · Glossary
| Term | Meaning |
|---|---|
| Interface (NIC) | The device's physical network port. The cable plugs in here. |
| Zone | A policy group that holds together interfaces of a similar trust level. Rules are written between zones. |
| WAN | The zone carrying the internet uplink. It is singular. |
| MGMT | The management zone. The management ports are never restricted here. |
| Uplink | The line over which the device reaches the internet. |
| CIDR | Notation that expresses an IP range in network/mask form (192.168.10.0/24). |
| Prefix | The number of mask bits in the CIDR. /24 = a block of 256 addresses. |
| Gateway | The next-hop address to which traffic is delivered. |
| NAT | Network address translation. Determines how internal private addresses appear to the outside world. |
| SNAT / Masquerade | Source address translation. Translates the source of outgoing traffic to the WAN address. |
| DNAT / Port forwarding | Destination address translation. Forwards specific inbound port traffic to an internal host:port. |
| Implicit deny | The automatic rejection of traffic matching no rule. The basis of the policy's “default closed.” |
| Address object | A name given to an IP/network definition. Used in rules instead of a raw IP. |
| Service object | A name given to a protocol + port combination (HTTPS = tcp/443). |
| Captive Portal | The welcome page where a guest authenticates before reaching the internet. It is an interface feature. |
| Trusted Hosts | The list that determines from which source addresses the Captive / RADIUS / Syslog permissions are valid. If empty, no permission is generated. |
| Distance | Line preference order. A smaller value is the preferred line. |
| SLA probe | A short TCP connection attempt that measures whether the line actually reaches the outside. It is not a ping. |
| Hysteresis | The method of preventing flapping in the line's healthy/unhealthy decision with “how many failures / how many successes” thresholds. |
| Onlink | The route setup form in which the gateway is considered directly reachable over the specified interface. |
| Lease | The time a DHCP client can use the address it received. |
| DHCP Relay | The role that does not give out the address itself but forwards the requests to a central DHCP server. |
| 802.1q / VLAN | The standard for separating multiple logical networks over a single physical cable with tags. |
| Fail-to-wire | Traffic continuing to flow normally instead of being cut while the license or portal is disabled. |
| Lockout protection | The set of mechanisms that prevent a wrong setting from locking the administrator out of the device. |