Documentation31 August 202673 min read14619 words

SignLogger Router Mode and Firewall Management User Guide

A complete operator guide to enabling SignLogger's Router Mode and configuring all twelve Firewall Management pages, with field references, defaults, troubleshooting, and Law 5651 record generation.

#router mode#signrouter#firewall management#zone#NAT#SD-WAN#law 5651#captive portal
SignLogger Router Mode and Firewall Management User Guide

About this guide

This document answers two questions together: “what am I looking at on screen?” and “how do I get the result I want?” For each module page, it first explains the page's purpose and the meaning of the on-screen fields, then walks through the step-by-step workflow and the pitfalls specific to that page.

Throughout the guide, menu paths are shown in the form Firewall Management › Rules. The screen figures present a simplified view of the interface's current structure; colors and badges carry the same meaning they do in the product.

This guide covers

  • Enabling, confirming and disabling Router Mode
  • All 12 pages under Firewall Management
  • Field-by-field reference tables, boundary values and defaults
  • The meaning of error messages and how to resolve them
  • End-to-end setup scenarios

What is outside this guide

  • Captive portal design, language and guest-user management (Hotspot Management)
  • Searching logs received from external firewalls (Firewall Log Search)
  • Licensing, backup, disk and user management (System Management)
  • Reports and automatic report definitions

Tip: On every page in the product, the ? button at the top right opens the help panel specific to that page. On top of that help, this guide adds the relationships between pages and the end-to-end workflows.

What is Router Mode?

By default, SignLogger runs in passive mode: it collects, signs and stores logs coming from other devices on the network (firewall, wireless controller, switch). In this mode the device carries no one's traffic; it only records what others report.

Router Mode (also referred to as SignRouter in the product) changes this role. When the mode is turned on, the device becomes the network's transit point: traffic between the internal network and the internet physically flows through the device. As a result, the record stops being a second-hand report and is instead generated from the traffic the device itself sees.

What you gain when the mode is on

CapabilityWhat it providesRelated page
First-hand Law 5651 recordsThe pass-through traffic log is generated directly from the device's own data plane, without trusting an intermediary device.Log Settings
Zone-based security policyAllow/deny is written between logical zones instead of interfaces; the policy stays readable.Zones · Rules
NAT and port forwardingThe internal network exits through a single external address; required services are exposed surgically.NAT / Port Forwarding
Address distributionDHCP server or relay on internal interfaces; MAC → IP reservation.DHCP & DNS
Captive portalAuthentication is enforced on the guest network; sessions are tied to records.Zones › Captive
Multiple internet linesLine performance is measured continuously; which traffic exits over which line is set by rule.SD-WAN
Live visibilityConnections passing at that moment, open sessions, the most-talked-to destinations.Monitor

Critical point: The Firewall Management menu appears only while router mode is on and is listed only for administrator accounts that are members of the root domain. If you cannot find the menu, first check the mode's state from the Dashboard › Status screen.

The mode's three states

BadgeMeaningTraffic
ActiveRouting is running, the configuration is permanent.Passing through the device
Awaiting confirmationThe configuration has been applied but not yet confirmed. If the time expires, it is rolled back automatically.Passing temporarily
DisabledRouter mode is off. Settings are kept but not applied.Not passing

How traffic flows

In router mode, a packet's journey through the device always follows the same order. The fastest way to understand why a setting isn't having the effect you expect is to know where in this chain the setting sits.

Clients PC · phone · IoT eth1 SignLogger · Router Mode Interface IP · VLAN zone assignment Rules zone → zone first match wins NAT SNAT / DNAT address translation Line selection SD-WAN rule / Distance Record generation — Law 5651 pass-through traffic log one row for each permitted connection · written to file to be signed eth0 Internet WAN line

Diagram — The packet's journey · from the internal network to the internet

Practical takeaway: When someone says “I wrote the rule but the traffic isn't passing,” the order to check is always the same: 1) is the interface in the right zone, 2) does a rule cover this zone pair, 3) is NAT defined, 4) is the line healthy.

Prerequisites and permissions

Hardware and network

RequirementWhy it is needed
At least two physical interfacesOne carries the internet line (WAN), the other the internal network. Routing cannot be done with a single interface.
A separate interface for WANThe management interface you are connected to the device through is not accepted as the uplink. If you assign the management interface to the WAN zone, the mode will not turn on.
An IP (L3) on the internal interfaceThe IP of the internal zone interface becomes the gateway for the clients on that network. The mode will not turn on with an internal interface that has no IP.
A valid licenseRouting continues even without a license, but the captive portal and compliance records stop.
A second access pathIf your connection is lost during activation, the rollback mechanism kicks in; even so, a backup access path (console or a second management interface) is recommended.

Administrator permissions

PermissionWhat it unlocks
View the state/settings of router (gateway) modeOpening the Firewall Management pages, reading the Monitor and Overview data.
Enable/configure router (gateway) mode — a critical network operationTurning the mode on/off, saving zone, rule, NAT, DHCP, SD-WAN and log settings.

On an account without the permission, the relevant page request is denied and the message Settings could not be retrieved. or Monitor data could not be retrieved. appears on screen.

Maintenance window: Enabling router mode changes the network configuration; a brief outage may occur. Do it during an off-hours maintenance window and at a time when you can be at the device.

Turning router mode on

Menu path ·

The on/off control for router mode is in a single place: the Router Mode row on the main Status panel and the activation wizard it opens. The “Apply Configuration” form and the “Stop Routing” card that used to be on the Overview page have been removed — being able to start activation from two separate places could spawn two confirmation flows at the same time.

Screen — Dashboard › Status

Activation flow

  1. Open the Status page

    Dashboard › Status → find the Router Mode row in the System Information card. If the switch in the row is off, the mode is disabled.

  2. Turn the switch on; the wizard opens

    The Enable Router Mode window shows the current interface–zone assignments and any blockers. At this point nothing has been applied yet.

  3. If there is a blocker, resolve it first

    If the window shows the warning “Router mode cannot be enabled right now”, the text below it tells you what is missing. Check its counterpart in the readiness-checks table. If there are multiple interfaces, the wizard lets you fix it from the same screen via the Change interface–zone assignments section; you save the change first with Save Assignments.

  4. Set the upstream DNS (optional)

    If left blank, the existing upstream is used: with PPPoE, the service provider's DNS servers, otherwise public servers. Separate multiple servers with commas.

  5. Read the access preview

    The Access after enabling section shows which management ports will stay open on which interface. This is only a preview and has not been applied — but it is the only place where you can see, before enabling, whether you are locking yourself out.

  6. Choose the confirmation time

    The default is 120 seconds; the range accepted on screen is 30–900 seconds. This time is the window you are given to say “my access is still working” before the configuration is rolled back automatically.

  7. Confirm

    In the “Do you confirm enabling router mode?” prompt the warning is clear: The network configuration will change. If your connection is lost, the change is rolled back automatically. Once you confirm, the interfaces, firewall and address distribution are applied in sequence. The PPPoE dial alone can take 25 seconds; it is normal for the window to say “Completing activation…”.

  8. Click “Confirm and Make Permanent”

    When the apply is done, the mode is in the Awaiting confirmation state and a countdown begins. If your access is still working, press the confirm button; the state becomes Router mode enabled and permanent.

Don't forget to confirm: If the countdown ends, the configuration is rolled back automatically and the device returns to its previous working state. This is not a fault — it is the lockout protection doing its job.

Readiness checks

At the very top of the Firewall Management › Overview page, next to the status badge, there is always a sentence. Seeing text there does not by itself mean there is a problem — first read what the sentence says.

If there is no blocker, the ready notice appears: “Ready: a WAN plus an internal-zone interface with an IP exists, router mode can be enabled.”

Text you see on screenMeaningResolution
No interface is assigned to the WAN zone. The interface carrying the internet line is not attached to any WAN-type zone. On the Interfaces page, assign the uplink interface to the WAN zone.
The interface in the WAN zone cannot be the management interface — assign a separate interface for the uplink. You have made the interface that carries your management access the WAN interface. The assignment is not blocked but it is not accepted as the uplink. Set aside another interface for the internet line. In a setup whose only connection is the management port, the mode will not turn on.
An IP (L3) must be assigned to at least one internal-zone interface. The interface facing the internal network has no IP; the clients' gateway cannot be formed. Interfaces → the relevant interface → Addressing Manual, then enter the IP Address and Prefix (/bits).

Which interface counts as the “management interface”?: If there is an interface assigned to the MGMT zone, that is it. If there is no such assignment, the interface carrying the default route is accepted as the management interface. On VLAN sub-interfaces this check is re-derived from the physical interface above them.

Also, the interface you are currently connected through cannot be moved into the WAN zone whatever zone it is in — this is direct lockout protection.

The confirmation window and rollback

The classic risk of changing the network configuration remotely is that the change cuts off your own access. SignLogger solves this with a two-stage apply.

The configuration is written and takes effect immediately, but it is not marked “permanent.” The confirmation time begins.

On the Firewall Management › Overview page you press the Confirm and Make Permanent button in the yellow-bordered card. The configuration becomes permanent.

When the time expires, the device rolls back the configuration on its own and returns to the previous working state. You do not need to go to the console.

SettingValue
Default confirmation time120 seconds
Range accepted on screen30 – 900 seconds
Server-side upper limit900 seconds
If an invalid/blank value is submitted120 seconds is used

Frequently asked

  • If I refresh the page, do I lose my chance to confirm? No. The card is rebuilt with the remaining time. When the countdown resets, the page state refreshes on its own.
  • What does the “No confirmation token, refresh the page.” error mean? The confirmation information was dropped while the page stayed open. Press the refresh button at the top right; when the card reappears, confirm.
  • What if I am connecting from behind a router? In that case the “interface you are connected through” match cannot be established; the protection relies entirely on the countdown-based confirmation. As long as you do not confirm, the change does not become permanent.

Turning router mode off

Turning it off is done from the same place: turn off the Dashboard › Status › Router Mode switch. When it is turned off:

Preserved

  • All zone, rule, NAT, route, DHCP and SD-WAN settings are kept
  • The interface list and IP assignments remain visible
  • Previously generated logs stay in place

Stopped

  • Traffic no longer passes through the device; the firewall becomes Passive
  • Line probing stops and the accumulated measurement state is cleared
  • The captive portal is not enforced; DHCP distribution does not happen
  • The Firewall Management menu disappears

Good news: Setting changes made while the mode is off are not lost. When you save, you get the message “…(will be applied when router becomes active)”; when the mode is turned on again, they all take effect.

The Firewall Management menu

The menu consists of 12 pages. The first two are monitoring, the rest are configuration pages. When looking for a setting, the fastest way to find the right page is the table below.

PageWhat it is used forType
Overview“Is the box configured correctly and running healthy?” Warnings, health boxes, configuration summary, record generation, live status.Monitoring only
Monitor“Who is connected right now, what is flowing?” Live connections, sessions, user/device/destination breakdown, DHCP leases, route table.Monitoring only
InterfacesZone assignment of the physical ports, IP-acquisition method, VLAN sub-interfaces.Configuration
ZonesPolicy groups; access to the device (management ports), intra-zone traffic, Captive/RADIUS/Syslog permissions, captive portal.Configuration
AddressesNamed IP objects: host, subnet, range, group.Object
ServicesNamed protocol+port objects and service groups.Object
RulesZone → zone allow/deny policy, order, implicit deny.Configuration
NAT / Port ForwardingSource NAT (masquerade/SNAT) and inbound-to-internal port forwarding (DNAT).Configuration
SD-WANMultiple WAN lines: priority (Distance), performance measurement (SLA), line selection rules.Configuration
Static RoutesManual route definitions to networks that are not directly connected.Configuration
DHCP & DNSDNS servers, per-interface DHCP pools, active leases, MAC → IP reservations.Configuration
Log SettingsWhich record types are generated; preserving the mandatory Law 5651 record.Configuration

The single-place rule across pages: Each piece of information is edited on a single page: interface → zone assignment only on Interfaces, allow between zones only on Rules, address distribution only on DHCP. They are deliberately separated this way so the same question is never answered differently in two places.

Recommended configuration order

On a from-scratch setup, following the order below means you never have to backtrack on any of the interdependent settings.

  1. Interfaces

    Assign the uplink interface to the WAN zone and the internal interface(s) to the LAN/GUEST/DMZ zones; give the internal interface a manual IP.

  2. Zones

    Add new zones if needed; set each zone's access to the device (management ports) and its Captive/RADIUS/Syslog permissions.

  3. DHCP & DNS

    Define the address pool, lease time, gateway and DNS values for the internal interfaces.

  4. Enable router mode

    Status › Router Mode → wizard → Confirm and Make Permanent.

  5. Addresses and Services

    Define the named objects you will use in the rules now; this saves you from having to fix rules later.

  6. Rules

    Write the policy with narrow-scope denies at the top and broad allows at the bottom.

  7. NAT / Port Forwarding

    If there are services that need to be exposed, add the port forwards.

  8. SD-WAN

    If there are multiple lines, set the Distances, tune the SLA targets to your environment, and write the line-selection rules.

  9. Log Settings

    Keep the noise scope (device traffic) off; leave the DHCP allocation events and the destination domain name on.

  10. Verify with Overview

    No warnings, the internet-line box says Internet present, and the Pass-through traffic count must be greater than zero.

1 · Overview

Menu path · ·

This page answers a single question: “is the box configured correctly and running healthy?” Who is connected and what is flowing at that moment is the Monitor page's job.

No settings are edited on the page. The only exception is the Confirm and Make Permanent button that appears if there is a configuration awaiting confirmation.

Screen — Firewall Management › Overview

Top card: status and readiness message

Next to the badge there is always a sentence; this sentence tells you whether the mode is ready to be enabled. Seeing text there does not by itself mean there is a problem. For the blocker texts and their resolutions, see the Readiness checks section.

While the router is Active, three summary fields appear on the card: WAN (the name of the uplink interface), Internal Zone (interface) and Rule count. When the mode is not active, this information is hidden.

Warnings

At the very top of the page, ahead of the boxes, there is a warnings section. If no problem is found, a green confirmation appears. All warnings except the connection-count warning are generated only while the router is active.

WarningLevelMeaning and what you should do
Router appears active but the firewall is not loadedCriticalRouting rules are not being applied. You need to re-enable the configuration.
There is a DHCP-enabled zone but the DHCP service is not runningCriticalClients cannot get an address; they cannot reach the network even with a cable plugged in.
The PPPoE connection is not establishedCriticalThere is no internet access. Check the line username/password and the line status on the operator side.
The PPPoE service is not runningCriticalEven if the connection drops, it cannot be re-established.
A WAN line whose internet access cannot be verifiedWarning / CriticalThe interface may be up but there is no exit to the outside. It is shown as a warning if only some lines are unhealthy, and as critical if all lines are unhealthy.
Fewer than two interfaces have a cable/linkWarningRouting requires at least one WAN and one internal interface.
License invalid / expiredWarningRouting continues; the captive portal and compliance records stop.
There is a captive-enabled zone but the captive license is not validWarningIt means user authentication is not being enforced.
Records are being generated but no pass-through traffic is visible at allWarningClient traffic may not be passing through the box; review the placement and the default gateway setting.
N recorded sessions have no authorization on the firewallWarningThese users, who appear authenticated on the portal, cannot actually reach the internet.

Health boxes

BoxWhat it shows
FirewallWhether the rule engine is loaded (On/Off). While the router is not active, no costly check is performed and it is shown definitively as Off.
DHCP serviceThe status of the service distributing addresses. If DHCP is not enabled on any zone, the box carries no color and “No DHCP-enabled zone” is written beneath it — this is not a fault.
Connectivity“interfaces with a cable / total interfaces.” Only physical interfaces are counted; VLAN sub-interfaces are excluded so they don't inflate the count. If fewer than two, the box turns to the critical color.
LicenseValid, Expired or Undefined.
PPPoE connectionAppears only if an interface is configured with PPPoE. If Connected, the local IP the line received is written beneath it; if Down, a “username/password or line” hint is written.
Internet line · interfaceA separate box for each WAN line. It answers not “is the cable plugged in” but can it actually reach the outside. If Internet present, the average latency and loss rate are written beneath it; if No internet, the first 60 characters of the last error text are written.

How internet-line probing works:

  • Each line is probed over its own interface; the backup line's measurement cannot go out over the active line and produce a false “healthy” result.
  • The probe is a short TCP connection attempt to the targets — it is not a ping and it generates no traffic. The default targets are 1.1.1.1:443, 8.8.8.8:443 and 8.8.8.8:53. A different provider and a different port are deliberately used; if any of the targets responds, the line is considered healthy.
  • By default it is tried every 20 seconds, with a 4-second timeout. 3 consecutive failures mark the line unhealthy, 2 consecutive successes make it healthy again.
  • Latency is the average of the successful attempts, and loss is the failure rate over the last 15-sample (≈5-minute) window.
  • When a line is probed for the first time it is assumed healthy; otherwise it would raise a false alarm on every startup. Until the first result is produced, the box does not appear at all.
  • The settings are changed from the SD-WAN › Performance SLA section; no restart is required.

What these boxes do and don't do: The page detects and reports a line; it does not bring a line up or down. The only automatic effect is this: if a rule on the SD-WAN page sends specific traffic over a specific line, that routing is not applied for as long as the line is found unhealthy and the traffic falls back to the default exit. Beyond that, there is no automatic failover or load sharing between lines.

Configuration Summary

This section answers the “what has been defined” question. The numbers are neutral, carry no good/bad meaning, and are therefore shown without color: Zone (with the captive-enabled count beneath), Rule, NAT/Forwarding (port + SNAT breakdown), Static route, Object (address + service breakdown), DHCP (reservation count), Shaping (On/Off + class count), Interface (including VLAN sub-interfaces).

Record Generation

Shows whether the evidence under Law 5651 is actually being written.

FieldMeaning
Pass-through trafficThe number of records for the traffic the box passes through it. This is the legal evidence; being zero is a problem and therefore carries color.
Device trafficRecords for the traffic to/from the box itself. Beneath it, whether the scope is On/Off is written (default Off).
EventThe number of records for DHCP allocation, user and system events.
Record fileThe space the generated record occupies; with the “before signing” note.

The counts here are not the total of all history: they are a representative sample taken from the last portion of the current record (roughly the last 4 MB). The aim is not an exact count but to answer the “is generation flowing” question cheaply.

Live Status

Instantaneous values refreshed every four seconds: WAN Download/Upload (computed from the difference of two measurements; may show 0 on the first read), Active Sessions (“—” if it cannot be measured, warning color above 8000), DHCP Leases, Firewall (Active/Passive) and Router Status. The list beneath shows, for each interface, the Interface (the management interface with an MGMT label), Zone (with the number in a VLAN), IP and Connectivity.

While router mode is off, this section does not error out and does not stay empty; the only certain things are that Firewall = Passive and Router Status = Disabled are shown.

Refresh behavior

SectionRefresh
Live Status boxes and interface listEvery 4 seconds
Warnings, health, configuration summary, record generationEvery 20 seconds
Status badge and readiness messageOn page load and with Refresh
The Refresh button at the top rightUpdates them all at once

When you switch to another page, the periodic updates stop.

This page does

  • Compares the configuration with the running system and writes any inconsistency as a warning
  • Measures whether each WAN line actually reaches the outside
  • Shows whether the Law 5651 record is being generated
  • Lets you make a configuration awaiting confirmation permanent

This page does not

  • Show who is connected or who is going where → Monitor
  • Edit interface, zone, rule, NAT or DHCP settings
  • Turn router mode on/off → Status
  • Disable a line it found unhealthy

The order to follow when hunting for a problem:

  1. Look at the Warnings section — if there is a problem, the cause is written there.
  2. Read the Internet line boxes: if it says “No internet,” the problem is most likely on the line/operator side.
  3. Verify the firewall, DHCP and license status from the Health boxes.
  4. If “Pass-through traffic” is zero in the Record Generation section, client traffic is not passing through the box; check the placement and the clients' gateway.
  5. In the Live Status list, verify that the interface you expect is Connected and in the right zone.

2 · Monitor

Menu path · ·

Monitor shows the current state on the device on a single screen: live connections, open sessions, users and devices that have traffic in the selected range, the most-talked-to destinations, distributed DHCP addresses and the route table. The screen is view-only — you cannot close a session or change a setting from here.

Screen — Firewall Management › Monitor Last 15 minutes

Top strip indicators

IndicatorMeaning and limit
DownloadTotal data coming to the clients in the selected range. The “right now” beneath it is the WAN interface's instantaneous rate and the interface name.
UploadTotal data going out from the clients in the same range; the instantaneous rate is again beneath it.
Open sessionsThe number of authenticated and unexpired sessions. It counts up to 500 at most; if exceeded, it stays at 500 and gives the lower bound, not the actual total.
UsersThe number of distinct users seen to have traffic in the selected range.
DevicesThe number of distinct client addresses seen to have traffic in the selected range.
ConnectionsThe number of connections the system is tracking at that moment (instantaneous). “—” if it cannot be read.

Beneath the indicators is the window information: Window: 15 min, followed by the first and last activity time actually seen in that range and the flow count. If there is no traffic at all in the range, it says “No traffic in this range.”

Time range and refresh

  • Options: Last 5 minutes · 15 minutes · 1 hour · 6 hours · 24 hours. The default is 15 minutes. A request outside these five values is not accepted by the server and is reduced to 15 minutes.
  • Auto refresh comes on by default; the page is refreshed every 10 seconds. If you turn it off, data comes only with Refresh or when the range changes.
  • When you leave the page, auto refresh stops; on each entry the tab returns to Live Traffic and the range to the default.
  • Because the instantaneous rate is computed from the difference of two measurements, it may show 0 B/s on the first load.

The range fully determines the top strip and the Users / Devices / Destinations tabs. On the Sessions tab, which sessions are listed and the remaining times are not affected by the range (they are always live), but the Traffic values on the same tab are the total for the selected range. Only the DHCP tab is entirely independent of the range.

Tabs

TabContent and limits
Live TrafficRead from the kernel's connection table, sorted from the one carrying the most data. It does not require a captive portal or session record; the rows arise from the traffic itself. Columns: Source (identity + address:port if any), NAT, Destination, Service, Protocol, State, Timeout, Traffic. The Pass-through traffic only toggle hides the box's own connections. The list shows at most 300 connections; the counter writes “shown / total.” It also works while router mode is off.
SessionsOpen and unexpired sessions: User, IP, MAC, Device, Zone, Remaining time, Traffic, State. If there is no username, it says unidentified (MAC). Remaining time turns to warning color below 15 min and critical below 5 min. The No-authorization badge in the State field says that, although the session appears open, the transit permission is not present in the data plane and it should be examined. At most 500 sessions.
UsersUsers with traffic in the range, sorted by total data. The IPs it logged in on field lists all the addresses that user appeared on in the same range. At most 15 records.
DevicesDevice name, IP, User/MAC, flow count and traffic. At most 15 records.
DestinationsThe most-talked-to destinations. If the domain name is known, grouping is by domain name; if not, the destination address is used. At most 15 records.
DHCPAddresses distributed by the router's own DHCP service: IP, MAC, Device name, Remaining time. For fixed allocations, it says fixed instead of a time.
RoutesThe route table: Network (default = default route), Gateway, Interface, Type (static manually written, kernel/connected a directly connected network, dhcp learned) and Metric. It is view-only; to add a route, use Static Routes.

Warning and error messages

MessageMeaning
Router mode is not active — live data may be limited.The session list and traffic breakdown may be empty or incomplete; the authorization status cannot be verified.
Monitor data could not be retrieved.The request went unanswered or was denied. Your session may have dropped or you may lack permission. The screen keeps the previous content. If auto refresh is off, you need to press Refresh.

This screen does

  • Answers the “what is happening right now” question
  • Shows whether the session is actually authorized on the firewall
  • Reads the route table and the DHCP leases

This screen does not

  • There is no session termination, blocking or rule changing
  • It is not a historical report — the longest range is 24 hours
  • Under very heavy traffic, totals over long ranges may be incomplete; the actual scope is written in the window information
  • Lists are limited to the first 15 (300 for connections, 500 for sessions)

3 · Interfaces

Menu path · ·

The page where you manage the device's physical network cards (NIC). You assign each interface to a security zone (zone) and determine how it will get an IP address. Which cable faces the internal network and which faces the internet is defined here.

Screen — Firewall Management › Interfaces

Basic concepts

  • Interface (NIC): The physical network port on the back of the device. Each port connects to a cable (internal network or internet line).
  • Zone: The interface's security role. LAN is the internal network you trust, WAN is the internet side. Since rules work on a zone basis, the correct assignment is critical.

IP-acquisition methods

MethodWhen it is used
Static / ManualYou write the IP address and the prefix (prefix, e.g. /24) by hand. This IP you give for an internal zone becomes the gateway of the devices on that network. The valid prefix range is 8–32; if left blank, 24 is used.
DHCP clientThe interface gets its IP address automatically from the upstream provider. Usually on the WAN side, to get an IP from the modem/ISP.
PPPoEIf the internet line connects with a username and password (as with many DSL/fiber subscriptions), you choose this method and enter the credentials.

VLAN sub-interface

If you want to carry more than one logical network over a single physical port, you can add a VLAN sub-interface. 802.1q tagging is used; networks separated by different VLAN IDs are carried over the same cable. Each VLAN sub-interface has its own zone and IP setting. The VLAN number is in the range 1–4094.

Lockout protection: The management (mgmt) interface through which you connect to and manage the device is specially protected: this interface cannot be moved to WAN and a WAN VLAN cannot be defined on it. This prevents you from accidentally assigning the management port to the internet side and losing access to the device.

Don't confuse them: The DHCP server settings are not on this page. To distribute IPs automatically to devices on the internal network, use the DHCP & DNS page. The “DHCP client” option here is about the interface itself getting an IP.

How to do it

  1. Select the interface

    Click the interface you want to edit from the list.

  2. Assign a zone

    LAN (or GUEST/DMZ) for the internal network, WAN for the internet.

  3. Choose the IP-acquisition method

    Static, DHCP client or PPPoE.

  4. Enter the values

    If you chose Static, the IP and its prefix; if you chose PPPoE, the username and password.

  5. Add a VLAN if needed

    Define the 802.1q sub-interface with Add VLAN; give it its own zone and IP as well.

  6. Save and verify

    The changes take effect when router mode is enabled/re-applied. Verify from the Overview › Live Status list that the interface is Connected and in the right zone.

4 · Zones (Policy Groups)

Menu path · ·

A zone is a structure that groups multiple network interfaces under a single logical policy group. Since security rules are written between zones rather than individual interfaces, your policy stays clean and readable. On this page you create zones, set each zone's access to the box permissions, and enable the Captive Portal for the guest network.

Default policy: Egress from an internal zone to WAN is allowed; transit between zones (for example GUEST → LAN) is blocked.

Screen — Firewall Management › Zones

Built-in zones

ZoneIts roleDeletable?
WANThe internet uplink. It is singular, no new one can be added.No
LANThe internal secure network.No
DMZExternally exposed servers.No
GUESTThe guest network.No
MGMTManagement. It is singular, no new one can be added.No
CustomZones you add yourself.Yes

Add Zone

  1. Add Zone

    Click the button at the top right.

  2. Enter a name

    1–32 characters; only letters, digits, underscore and hyphen. Otherwise you get the warning “Zone name must be 1-32 characters, letters/digits/_/-”. If a zone with the same name exists, it says “A zone with this name already exists.”

  3. Select a type

    Custom, LAN, DMZ or Guest. WAN and MGMT cannot be selected; if a type not in the list is submitted, it is automatically taken as Custom.

  4. Save

    Two things happen automatically: a visible default internet permission is created (“Default: <name> → WAN (internet)”) and the zone is created with Syslog listening on.

Adding a new zone does not by itself change live traffic; its effect begins when you assign an interface to it from the Interfaces page.

Zone Settings (shield icon)

The shield icon at the end of the row opens three sections for that zone. Which sections appear depends on the zone type.

A · Intra-zone Traffic

“Interfaces within the same zone can communicate with each other” — default on. If you turn it off, the zone goes into full isolation. This section appears on internal zones (LAN / DMZ / Guest / Custom); it does not appear on WAN and MGMT.

Know its limit: This setting is only meaningful if the zone has two or more interfaces. In a single-interface zone, devices already reach each other directly, the traffic does not pass through the box; this switch cannot separate them. If you need to isolate guest devices from each other, the isolation must be done on the wireless access point side.

B · Access to the Device (Management Ports)

Whether the users in this zone can reach the box's own management services: HTTPS, HTTP, SSH, Telnet, Ping (ICMP).

Zone typeBehavior
Internal zonesAll on by default. The port of a service you turn off is dropped only on that zone's interfaces.
WANAll off by default. The moment the window opens, a red warning appears regardless of the state of the switches. Every service you turn on here exposes the box directly to the internet.
MGMTThis section is not shown. The management ports are never restricted on that interface — this is the escape route that keeps you from locking yourself out.
Captive-enabled interfaceThe switches are invalid: from that interface only name resolution, address distribution and portal-page access to the box are open; everything else is dropped.

The Telnet switch comes on by default on internal zones, but no telnet server runs on the box; having it on does not open a door in practice.

C · External Device Access (Captive / RADIUS / Syslog)

This section appears on every zone — including WAN and MGMT. It opens the services through which external devices can connect to the box.

ServicePortsDefault
Captive Portal8080, 8081, 8084, 8086Off. Turn it on explicitly if guest login will be used.
RADIUS1812, 1813Off. Turn it on for authentication/accounting traffic.
Syslog514 (UDP and TCP)On on zones other than WAN. It is off on WAN and is recommended to stay that way.

The Trusted Hosts gate — the #1 reason for “I turned it on but it doesn't work”: The Captive Portal, RADIUS and Syslog permissions are, together with your turning the switch on, also subject to a source-address check. The source list is managed from the Trusted Hosts page:

  • If there are specific addresses/network blocks in the list, access is granted only to those sources.
  • If 0.0.0.0/0 is in the list, no source restriction is applied.
  • If the list is empty or cannot be read, no permission is generated at all. Even if the switch in the zone setting appears on, the traffic does not pass.

Why Syslog matters: The logs of your firewall and network devices come through this gate. If Syslog is off on the relevant zone, the logs are dropped without producing any error; no warning appears on screen, only the log flow stops. This is the first place to look for the complaint “the logs aren't coming.” If you turn off Syslog on a zone, your decision is permanent; the system does not turn it back on by itself.

What the message you get on save means

MessageWhat actually happened
Zone settings saved and applied to the active routerRouter mode is active; the rule is in effect immediately.
Zone settings saved (will be applied when router becomes active)Router mode is off; the setting was stored, the live behavior did not change.
Settings saved BUT could not be applied to the live router: …The setting was stored but the rules could not be loaded; the live behavior continues in its old form. Do not consider the operation finished — try applying again.
Zone not foundThe zone may have been deleted in the meantime; refresh the page with Refresh.

Lockout protection

You cannot turn off HTTPS / HTTP / SSH access over the interface of the zone through which you are currently connected for management. If you try, you get the warning: “You are currently connected for management over this zone (…) — if you restrict HTTPS/HTTP/SSH access from here you may lock yourself out. Make this change from the management (mgmt) interface.” The protection works for the underlying interface carrying your connection; you can connect from another interface and make the change.

The MGMT zone is no longer privileged

In terms of routing, address translation and spoof-source protection, MGMT is now an internal zone like LAN; only its name is different.

  • When you assign an interface to the MGMT zone and give it an IP, it behaves like the other internal zones. As long as you do not give it an IP, no behavior changes.
  • Assigning the management interface to the WAN zone is no longer blocked at the assignment stage; however it is not accepted as the uplink. When you try to enable router mode, it stops with the error “The interface in the WAN zone (…) is the management interface — assign a separate interface for the uplink.”
  • On the MGMT zone, Zone Settings shows only the Captive / RADIUS / Syslog section.

Captive Portal (wireless icon)

The Captive Portal is an interface feature: you select the zone, then determine on which interface within that zone the portal will run. The portal runs on the single interface you select as Interface in the window. This button exists only on LAN / DMZ / Guest / Custom zones; on WAN and MGMT it shows “—”.

FieldDescription
InterfaceOne of the interfaces within the zone. If the zone is empty, it says “No interface in this zone — assign one from the Interfaces page.”
Captive portal activeTurns the portal on/off on this interface.
Network (automatic)Gateway IP, Prefix (/bits), DHCP start, DHCP end. Filled from the existing configuration; if there is no value, a suggestion is generated based on the zone. The prefix field suggests 8–30, and when saving the valid range is 8–32; if left blank, 24 is used.
Redirect URLOptional. The address the user goes to after authentication. If empty, the user is redirected to the gateway.
Allowed AddressesOptional. Addresses reachable before authentication. You can select a ready-made address object and/or type IP/CIDR by hand separated by commas. Name resolution is already allowed.

On save: if you marked the portal active, the interface's network setting is written first (manual IP + address distribution), then the portal setting is saved. If Gateway IP is empty, you get the warning “Gateway IP required” and nothing is saved.

Banners that may appear at the top of the modal: “Router mode is not active — the setting is saved and will be applied when router becomes active.” · “License invalid — captive is not applied; traffic flows normally (fail-to-wire).” So a license issue does not cut guest traffic, it just means the portal does not kick in.

The portal's design, language, login method and users are managed not on this page but in the Hotspot Management › Captive Portal section.

Deleting a zone

The delete button appears only on zones you added yourself. Deletion is blocked in the following cases:

  • “There are interface(s) assigned to this zone — first move/remove the interfaces to another zone.”
  • “This zone is used in a security rule — first delete the relevant rules.”

Deletion is irreversible. Along with the zone, the default internet rule automatically created for that zone is also removed. The operation is written to the audit trail.

This page does

  • Creates/deletes zones
  • Sets intra-zone traffic, access to the device, and Captive/RADIUS/Syslog permissions
  • Enables the captive portal on an interface and sets up its network automatically

This page does not

  • Assign interfaces to a zone → Interfaces
  • Write allow/deny between zones → Rules
  • Change the rules of external firewalls
  • Manage the portal content → Hotspot Management

5 · Addresses

Menu path · ·

Stores the IP definitions frequently used in security rules as named objects. You define it once and use it over and over in many rules. When you write “Accounting-Server” instead of 192.168.10.50, it is clear at a glance who the rule is talking about.

Its biggest advantage: if the address changes, you update it in a single place, and all rules using that object automatically stay current.

Screen — Firewall Management › Addresses

Address types

TypeDefinitionExample
HostA single device's IP address (server, printer).10.0.0.5
SubnetAn entire subnet, in CIDR notation.192.168.10.0/24
RangeConsecutive IPs, as start–end. Useful when the block does not fit exactly into a full subnet.192.168.1.100 – 192.168.1.150
GroupA collection that gathers multiple address objects under one roof.Servers = {A, B, C}

Why use an object?: When writing a rule you can also type CIDR by hand into the source/destination field; the system accepts it. However, using a named object is recommended for manageability: you don't repeat the same address in dozens of rules, no rule is left forgotten on a change, and the rules become readable for everyone on the team.

How to do it

  1. Add Address

    Click the Add Address button on the page.

  2. Give a clear name

    For example “Warehouse-Cameras.” Choose the name so that someone else will understand it six months later.

  3. Select a type

    Host, Subnet, Range or Group.

  4. Enter the values

    A single IP for Host, network/mask for Subnet, the start and end IP for Range.

  5. If you chose Group, check the members

    Select the address objects to include from the list.

  6. Save

    The object can now be selected as a source/destination in rules and in SD-WAN rules.

If the address changes later, open the relevant object and update the value; all rules automatically use the new value.

6 · Services

Menu path · ·

The place where you turn protocol + port combinations into named objects. A service defines the type of traffic; a port is not a separate object, it lives inside the service. This way, instead of writing “tcp/443” in rules, you just select HTTPS.

Screen — Firewall Management › Services

Predefined and custom services

  • Predefined services: Frequently used protocols come defined in the system and can be used immediately. Built-in and in-use objects cannot be deleted.
  • Custom services: You define the port/protocol your own application uses (e.g. a management panel's tcp/8443). Creating a custom service for applications running on non-standard ports keeps the rules understandable.
  • Service groups: Gather multiple services into a single collection — for example Web = HTTP + HTTPS. When you update a service, all groups and rules using it automatically use the new definition.

How to do it

  1. Add Service

    Click the New Service button on the Services tab.

  2. Give a name

    Make it understandable: “App-Management.”

  3. Select a protocol

    TCP, UDP or both (TCP_UDP). No port is used for ICMP.

  4. Enter a port or range

    A single port, a comma-separated list or a range.

  5. Save

    The service can now be selected in rules and groups.

  6. Create a group if needed

    On the Service Groups tab, bring the relevant services together with New Service Group.

7 · Firewall Rules

Menu path · ·

A security rule defines what will be done with traffic coming from which source, to which destination, with which service. Rules are evaluated top to bottom; the first match is applied, and traffic that matches none is denied.

Screen — Firewall Management › Rules

The parts of a rule

FieldWhat is written
Source Zone → Destination ZoneThe rule works in this direction. Example: LAN → WAN = from the internal network to the internet. It can also be same zone → same zone. By default, internet is open from internal zones to WAN; between zones (e.g. GUEST → LAN) it is closed by default.
Source / Destination AddressAddress object (recommended) — Host, Subnet, Range, Group — or manual CIDR. If both are empty, any. Multiple addresses/groups can be selected for a rule.
ServiceSelect a service object or service group, or type a manual protocol+port. When you select an object, the manual fields become inactive. Empty = any.
ActionAllow · Block (silent drop) · Reject (drop and notify the sender).
OrderA smaller number is evaluated first; the first match is applied.
StateDisables the rule. Default rules cannot be deleted but can be turned off via State.

Implicit Deny (∞): Traffic matching no rule is automatically denied. This row is shown read-only in the list; you cannot remove or change it. Your policy being “default closed” is thanks to this row.

Communication within the same zone is not managed from here: Whether the interfaces within the same zone see each other is now set separately for each zone: Zones › the relevant zone › Zone Settings › Intra-zone Traffic.

How to do it

  1. Select the zone pair

    Source Zone and Destination Zone. Direction matters; you do not need to write a separate rule for return traffic.

  2. Set the source/destination address

    With + Select, object(s) or manual CIDR. Leaving it blank means “any.”

  3. Set the service

    With + Select, service object(s) or manual protocol + port. Empty = any.

  4. Set the action and order

    Put specific blocks at a low order and general allows at a high order.

  5. Save

    If the router is active, the rule is applied immediately. Verify the behavior you expect with Monitor › Live Traffic.

Ordering habit: The “deny first, then allow” arrangement is readable: 100–499 for narrow-scope blocks, 500–999 for specific allows, 1000 and above for default broad allows. This way, when adding a new rule it is clear which band to use.

8 · NAT / Port Forwarding

Menu path · ·

Manages how the device translates IP addresses between the internal network and the internet (WAN). NAT (Network Address Translation) determines how private internal addresses appear to the outside world.

Screen — Firewall Management › NAT / Port Forwarding

Source NAT (SNAT / Masquerade)

Changes the source IP address of traffic going out from the internal network to the internet. Devices on the internal network use private addresses; these are not valid on the internet. SNAT translates the source of this traffic to the device's WAN IP, letting it reach the outside.

OptionWhen
Masquerade (default)Whatever the WAN IP is (fixed or variable), all egress traffic is automatically translated to the WAN address. Sufficient for most sites.
Custom SNAT ruleWhen you want to translate a specific source (a single server or subnet) to a specific external IP. If you have multiple WAN IPs, you set here which traffic exits from which address.

Port Forwarding (DNAT)

Delivers incoming traffic from outside to a server inside. It forwards a specific port of traffic arriving at WAN to an internal host:port address. The external port and the internal port can be different (external 8443 → internal 443).

Surgical transit (forward-accept): When you define a port forward, the firewall allows traffic only to that target host:port; the rest of the internal network is not opened. You expose a single service without putting the whole network at risk.

Things to watch:

  • Port forwarding exposes the internal server to the internet — use it only for services that genuinely need to be reached from outside.
  • The internal target host must use a fixed (static) IP; if its address changes via DHCP, the rule breaks. Define a MAC → IP reservation if needed.
  • Two different internal targets cannot be defined for the same external port; each external port goes to a single target.

How to do it

  1. Open the page

    Firewall Management › NAT / Port Forwarding.

  2. For source NAT

    On the SNAT / Source NAT tab, Add SNAT rule; leave masquerade or specify a source/external IP.

  3. For port forwarding

    Click the Add Port Forwarding button.

  4. Enter the values

    External port, protocol (tcp/udp), internal host and internal port.

  5. Save and test from outside

    Be sure to test not from the internal network but from an external connection (such as mobile data).

9 · SD-WAN

Menu path · ·

In setups with multiple internet lines (WAN), it gathers the lines' configuration, their real performance, and which traffic exits over which line in one place. Adding/removing a line is not done here; this page shows interfaces assigned to the WAN zone.

The page works with router mode. If the mode is off, the warning “Router mode is not active — lines are not configured.” appears at the top; the settings you make are saved but reach the field only when the mode is enabled.

Screen — Firewall Management › SD-WAN

Lines tab

ColumnMeaning
InterfaceThe line's actual egress interface. The line with the lowest Distance value is marked with the Primary badge.
ModeThe addressing mode: DHCP, STATIC or PPPOE.
IP / GatewayThe line's current address and the gateway coming from the provider. Read from the system; appears empty if PPPoE has not connected.
DistanceLine priority. Detailed below.
StateNo line (the interface has not formed yet) · Measuring (not yet probed at all) · Working · No access. If you hover over the last badge, you see the last error text.
Latency / LossThe average latency and loss rate in the last measurement window. Green below the warning threshold, yellow when the threshold is exceeded, red when it exceeds twice the threshold. For loss, any value above zero is at least yellow.
RoutingWhether source-based routing has been prepared for that line. If Ready, the line can actually work over its own path. If Waiting, the line's IP or gateway is not yet known.

If no WAN interface is assigned, the list says “No interface assigned to the WAN zone.” In this case, first assign an interface to the WAN zone from the Interfaces / Zones screens.

What Distance is for

Distance is the line preference order: smaller value = preferred line. If left blank (0), it is considered “unspecified” and the line drops to the bottom of the list. On equal values, the interface name decides.

  • The accepted range is 0–255. If you go outside it, you get the error “Distance must be in the 0-255 range.”
  • Distance is only meaningful on interfaces in the WAN zone; if attempted for another interface, it returns “Distance is set only on interfaces in the WAN zone.”
  • The value is saved the moment you type it into the box and leave the field; there is no separate save button.
  • Distance does not by itself provide automatic line switching. When a line breaks, the system does not switch it for you.

When the new priority takes effect: A Distance change settles in two stages: the security and NAT handling is rewritten immediately, but the per-line routing arrangement is updated on the system's periodic refresh cycle that runs every 60 seconds. So the new priority fully settles within at most a minute. On PPPoE lines, for the Distance to take effect as the metric of the provider default route, the line needs to reconnect.

Capabilities card

Works

  • Multi-line data plane — NAT and security rules cover all WAN lines
  • Per-line routing — each line has its own table; the backup line does not fall into “got an IP but no traffic flows”
  • Performance measurement — latency and loss are measured continuously
  • Line-selection rules — egress line by source, destination, protocol and port
  • Fallback within a rule — while the rule's line is unreachable, that traffic exits over a working line
  • Adjustable measurement — targets, interval and thresholds from this page

Not yet

  • Automatic switching for out-of-rule traffic — the default line for traffic that matches no rule does not change automatically; you set it with Distance
  • Load sharing — there is no distributing traffic across multiple lines at once; a session exits over a single line

Performance SLA tab

Each line is probed separately over its own interface. The probe is a TCP connection attempt, not a ping; that is why the targets are given with an address and port. The probe works only while router mode is active.

Do not leave a field blank: If you clear a field, that setting is not treated as “unchanged”: the blank value is sent as zero and the system pulls it down to the field's smallest accepted value (interval 5 s, window 5 samples, timeout 1 s, threshold counters 1, latency threshold 10 ms, loss threshold 1%). Leave the fields you don't want to change as they are; don't delete them.

SettingRangeRecommendedNote
Measurement targetsat most 83 targetsIn address:port form, comma-separated. If any of them responds, the line is considered working. Use a different provider and a different port — some upstreams block outgoing DNS.
Measurement interval (s)5 – 30020How often the lines are probed, in seconds.
Timeout (s)1 – 304Must be shorter than the measurement interval; if not, it is rejected with the error “Timeout must be shorter than the measurement interval.”
Evaluation window5 – 12015 samplesOver how many samples the loss and average latency are computed. With a 20 s interval, a ≈5-minute window.
How many failures for “no access”1 – 203How many consecutive failed probes before the line is considered unhealthy.
How many successes for “working”1 – 202These two values together prevent “flapping” behavior.
Latency warning threshold (ms)10 – 5000250For display only.
Loss warning threshold (%)1 – 10010For display only.

Thresholds do not bring a line down: The warning thresholds determine color only. Whether a line is considered unhealthy is determined not by the thresholds but by the “how many failures for no access” counter. A line is not disabled just because the latency threshold was exceeded.

When you press Save, the values take effect immediately; no service restart is needed. The Restore recommended values button only fills in the form, it does not save. If you change the Evaluation window, the accumulated measurement history is reset and the values refill over a few cycles — this is temporary, not a fault.

Common SLA errors

MessageCause
Target must be in 'address:port' form — invalid: …A target has no port or the format is broken. The invalid target is written in the message.
Target port invalid: …The port is outside 1–65535.
At least one probe target is requiredThe target field was left blank.
At most 8 targets can be definedShorten the list.

SD-WAN Rules tab

Rules make specific traffic exit over a specific line. Example: “let all traffic leaving the accounting network exit over the fiber line, and the guest network over the 4G line.”

Order matters: Rules are evaluated top to bottom and the first matching rule wins. Narrow-scope rules should be at the top, broad-scope ones at the bottom. The Move up / Move down arrows are not cosmetic but a behavior change and are applied immediately. A newly added rule is always added to the bottom of the list.

Rule fields

FieldDescription
Rule nameRequired, at most 128 characters. If empty, “Rule name required.”
EnabledIf you turn it off, the rule is kept but not applied. It can also be changed with the on/off icon in the list; it takes effect immediately.
Send this traffic over this lineRequired. The list comes only from the interfaces in the WAN zone; each option appears as “interface · zone · mode.”
Source / Destination addressWith Select, an address object or a single IP / CIDR in the box. If both are empty, “all.”
ServiceWith Select, a service object or a protocol list (All / TCP / UDP / ICMP) + a port box. The port can be a single value (443), a comma-separated list (80,443) or a range (5060-5070). If ICMP is selected, the port is ignored; if the protocol is All and you write a port, the rule is applied for both TCP and UDP.

Selecting an object locks manual entry: When you select an object, that field's manual-entry box is locked and its content cleared. Entering two criteria at once is deliberately prevented because it would make it ambiguous which one is in effect. If you want to type manually, first remove the selected objects.

The address and service objects come from the same pool as the security rules — what you define on the Addresses and Services screens is also selectable here.

If the rule's line is unreachable

If the rule's target line is in the No access state, that rule's routing is not set up: the traffic does not go to a “black hole,” it falls back to the working default line. When the line becomes healthy again, the rule comes back into effect on its own. The timing is two steps: first the line being considered unhealthy (how many failures for no access × measurement interval; ≈1 minute with the recommended values), then the next periodic refresh cycle (at most 1 minute). So the switch is typically within a few minutes.

If the rule's line is no longer in the WAN zone or the interface never formed, the Line information appears as a red “Line not found” — this means the rule is not being applied.

Rule scope

  • Rules are applied to traffic going from inside to outside. Return traffic coming from outside is deliberately out of scope; otherwise sessions would break.
  • Traffic the device itself generates (line probes, system updates) is not routed by these rules.
  • If no internal interface is defined, the rules are ineffective.

Errors encountered on save

MessageCause / resolution
A rule must have at least one criterion (source, destination or service).A rule with all three empty would pin all internal traffic to a single line. If you really want “everything exits over this line,” write a deliberate criterion such as giving the destination as 0.0.0.0/0.
Select a valid line / Select a line.No line selected or it is not recognized.
The selected interface is not in the WAN zoneIf a rule routes to an internal interface, the traffic would go nowhere; therefore it is rejected.
Source/Destination address invalid (IP or CIDR)Only a single IPv4 address or CIDR notation is accepted.
Port invalid (e.g.: 80, 80,443, 1000-2000)The port expression is broken, outside 1–65535, the end of the range is smaller than the start, or the expression exceeds 128 characters.
One of the selected address/service objects no longer existsAn object was deleted elsewhere while you were editing the rule. Press Refresh and make the selection again.

Deletion: the trash can asks for confirmation and the rule is permanently deleted; it cannot be undone. The rule's address/service links are also cleared, so those objects can be freely deleted again.

Recommended setup order (SD-WAN):

  1. Assign the lines to the WAN zone.
  2. On the Lines tab, give each line a Distance; the smallest value to the primary. Wait a minute for it to take effect.
  3. Wait for Routing = Ready and State = Working. A persistent Waiting means the line has no IP or gateway.
  4. Tune the Performance SLA to your environment; raise the timeout and the failure count on satellite/mobile backup lines. Don't leave any field blank.
  5. Define the required Address and Service objects.
  6. Add and order the SD-WAN Rules starting from the narrowest scope.
  7. Verify the result from the Line information: a rule saying red Line not found is not being applied.

10 · Static Routes

Menu path · ·

You manually define how the device will reach networks it is not directly connected to. Each static route specifies which gateway (next hop) to send traffic destined for a given network through; it is used to set up fixed paths without a dynamic routing protocol.

The device automatically recognizes networks connected to its own interfaces. For networks beyond those — for example another branch or a network behind another router — it does not know where to forward the traffic. A static route closes this gap.

FieldDescription
Destination Network (CIDR)The network you want to reach, in network-address-and-mask form (e.g. 10.20.0.0/24).
GatewayThe next-hop IP to which traffic destined for the target is delivered. Usually the address of a neighboring router on the same local network as you.
Egress InterfaceOptional. Selected if the gateway is not on a directly connected network; the route is set up as onlink over the specified interface. Any interface, including management (mgmt), can be selected. If the gateway is on an already connected network, leave it blank.
MetricThe priority if there are multiple paths to the same destination. A lower metric has higher priority.

Lockout protection: Routes that cover the management path through which you access the device remotely are blocked. Also, a route covering the default route (0.0.0.0/0) cannot be added. If you try to add such a route, the operation is rejected.

A route does not grant access: A static route only defines the path to the destination; access is still managed via Rules (zone → zone). If traffic still doesn't pass after adding a route, check whether there is an allow rule for the relevant zone pair.

How to do it

  1. Add Route

    Click the button at the top right.

  2. Enter the destination network

    As CIDR, as narrow as possible (e.g. 192.168.50.0/24). Avoid overly broad blocks.

  3. Write the gateway

    The next-hop IP. Make sure it is genuinely reachable and on the correct interface.

  4. Select an egress interface if needed

    Specify it only when the gateway is not on a connected network; otherwise leave it blank.

  5. Set the metric

    If there are multiple paths to the same destination, give a smaller value to the one you prefer.

  6. Save and verify

    Check that the route appears with the static type on the Monitor › Routes tab.

11 · DHCP & DNS

Menu path · ·

Manages the automatic IP address distribution to your internal-network (zone) interfaces and the DNS servers the device will use. It works independently of the interface settings; you choose a separate role for each interface.

Screen — Firewall Management › DHCP & DNS

Interface roles

RoleBehavior
OffNo DHCP service is provided on this interface; clients must get their IPs manually.
DHCP ServerAutomatically distributes settings such as address, gateway and DNS to the devices on this interface.
DHCP RelayDoes not give out addresses itself; forwards the requests to a central DHCP server on another network. When the address pool is managed from a single center, devices on remote networks can also get addresses from the same server.

Server and Relay cannot be used together on the same interface.

DHCP server settings

SettingDescription
Pool rangeThe start and end IP of the addresses to be distributed.
Lease timeHow long a device will use the address it received; when the time expires, the address is renewed.
Gateway (opt 3)The router address clients will use when going out.
DNS servers (opt 6)The servers to be used for domain name resolution.
Domain (opt 15)The domain suffix given to clients.
Excluded rangesAddresses that, although within the pool, will not be distributed and are reserved for manual use.
Advanced optionsCustom option codes: NTP (42) time server, WINS (44) name resolution, MTU (26) packet size, PXE (66-67) network boot, and general code-value pairs.

Reservations and leases

  • MAC → IP reservation: Ensures that a specific device gets the same fixed IP every time. The IP must be within the scope of a zone with the DHCP server on.
  • Active leases: Shows the devices that currently have an address, their IPs and their lease end times.

Together with port forwarding: So that the address of the internal server you exposed does not change, define a MAC → IP reservation for that device. This way the port-forwarding rule is not broken by a DHCP renewal.

DNS servers

The servers you enter are used both for the device's own name resolution and for resolution on behalf of clients. Save is applied to both the WAN profile and the client resolver together. If left blank, they are chosen automatically: with PPPoE, the service provider's DNS servers, otherwise public servers. The upstream DNS you entered in the router-mode activation wizard also appears here.

How to do it

  1. Select the internal interface

    Click Configure Pool in the row of the interface you want to configure.

  2. Set the role

    Off, DHCP Server or DHCP Relay.

  3. If you chose Server, enter the basic values

    Pool range, lease time, gateway and DNS.

  4. Define exclusions and advanced options

    Exclude manually used addresses from the pool; add options such as NTP/PXE if needed.

  5. Add reservations

    Define MAC → IP mappings for devices that need a fixed address.

  6. If you chose Relay

    Enter the central DHCP server address(es).

  7. Save and verify

    See that distribution is working from the Active Leases list.

12 · Log Settings

Menu path · ·

Determines which log types the device will generate in its own firewall mode. The aim is to be able to take operational noise out of scope while preserving the legally mandated pass-through traffic log.

Screen — Firewall Management › Log Settings

If you can't find the page: This menu heading is not visible on every account: it is listed only while the device is on in its own firewall (router) mode and when logged in with an administrator account that is a member of the root domain.

Log types

TypeDefaultDescription
Pass-through trafficMandatory Traffic going from users to the internet. This is the actual evidence that must be kept under Law 5651; the switch is visible but cannot be clicked, and a request to turn it off is ignored even if sent from outside the interface. The log is generated from established (permitted) connections.
Traffic to/from the deviceOff The device's own connections (data store, search engine, syslog). Not required for Law 5651. In field measurement, about 99% of the total rows were this type — writing logs generates new connections, which were then logged. Turn it on temporarily while troubleshooting, and off when you're done.
DHCP allocation eventsOn Which IP was given to which device (MAC) and when, released or denied. Because it strengthens identity determination, it is recommended to leave it on. Turning it off only stops these events from being written; it does not affect the DHCP service or the guest sessions.
User authentication eventsOn Login and logout events from the captive portal.
System eventsOn Interface state changes and configuration-apply records.
Add destination domain nameOn Adds the destination's domain name to the log row (the site name appears instead of the IP). The domain name comes from a temporary mapping kept from the device's DNS responses.

The User authentication and System events switches store your selection and are shown as the current scope on the Overview screen; however, there is currently no source that produces a separate row in the firewall log file for these two types — turning the switches on and off makes no visible difference in the file.

The limits of the destination domain name:

  • Browsing/visit history is not kept. DNS query rows in the form of “who asked for what” are deliberately ignored; only the destination of a connection that is actually established is written.
  • If the client uses encrypted DNS (DoH/DoT), the domain name does not reach the device; in that case the domain is not written at all, and no guess is produced.

How the boxes are computed

  • The Pass-through traffic / Device traffic / Event counts and percentages are counted from the last 4 MB portion of the current daily log file — a representative sample of the most recent period, not of all history.
  • The Record file value is the current size of the entire file. That is why the percentages and the size do not come from the same scope.
  • The values are retrospective: a switch change you just made is not immediately reflected in the boxes.
  • If all boxes show 0, it means the day's log file has not yet formed or cannot be read — it does not mean the settings are broken.

When a change takes effect

It is in effect the moment you press Save; no service restart is needed. When the settings cannot be read, the system continues generating logs with the last known scope — that is, a failure to read the setting does not turn into a log interruption.

What is irreversible?: The setting itself can always be undone. However, logs not generated during the time it was off cannot be brought back later. Before turning a type off, consider whether there is an investigation you might need for that period.

In terms of Law 5651: what not to turn off

TypeRecommendation
Pass-through trafficCannot be turned off anyway. This is what fulfills the legal obligation.
DHCP allocation eventsDo not turn off. The IP–MAC–time mapping is the most direct way to show which device an IP belonged to at a given moment.
Add destination domain nameTurning it off does not create a legal gap, but it markedly reduces readability during an investigation.
Traffic to/from the deviceIt is not legal evidence; keeping it off is the expected use.

Scope declaration: Shortly after midnight each day, the “how much log was generated, how much could not be generated” information for that day is written to the same file as an event row and signed. This row cannot be turned off with any switch and is included in the count in the Event box. Its purpose is that, if there is a gap during an audit, it can be declared.

Recommended use

  • Look at the boxes: if the Pass-through traffic percentage is low and Device traffic is high, the noise scope has been left on
  • Keep Traffic to/from the device off; turn it on only temporarily while troubleshooting
  • Keep DHCP allocation events and Add destination domain name on
  • Don't be in a hurry expecting the distribution to change until the next day after you save

This page does not

  • Manage the log retention period, rotation, signing or archiving
  • Affect logs coming from external firewalls
  • Produce a “rejected” row for blocked traffic
  • Offer a threshold that stops generation based on disk fullness
  • Store visited sites as browsing history

Frequently seen messages

MessageMeaning
Settings could not be retrieved.The scope information could not be read. Your session may have dropped, you may lack view permission, or the backend service may be temporarily unreachable. Try with Refresh; if it persists, log out and back in.
Could not be saved.The save request was not accepted; the reason appears in the rest of the message. For an authorization error, the enable/configure permission is required.
Log settings saved.The scope was updated and took effect immediately.

End-to-end scenarios

The flows below explain, from start to finish, the configurations most often set up in the field. Each step states which page it is done on.

Scenario A · Single WAN + single LAN basic setup

  1. Assign the uplink interface to WAN

    Interfaces → the interface where the internet cable is plugged in → Zone: WAN, Mode: DHCP client / Static / PPPoE depending on your ISP. Do not select your management interface.

  2. Assign the internal interface to LAN and give it an IP

    Zone: LAN, Addressing: Manual, IP: 192.168.100.1, Prefix: 24. This IP will be the gateway of the internal network.

  3. Define the DHCP pool

    DHCP & DNS → the eth1 row → Configure Pool → Role: DHCP Server, pool 192.168.100.100 – .200, lease 12 hours, gateway 192.168.100.1, enter the DNS servers.

  4. Enable router mode

    Status › Router Mode → wizard → confirmation time 120 s → confirm → Confirm and Make Permanent.

  5. Verify

    Overview: no warnings, Internet present, Pass-through traffic > 0. Go out to the internet from a client and see the row on Monitor › Live Traffic.

Scenario B · Guest network over VLAN + captive portal

  1. Add a VLAN sub-interface

    InterfacesAdd VLAN → parent interface eth1, VLAN 30. (A WAN VLAN cannot be added on the management interface.)

  2. Assign it to the guest zone

    Set the new sub-interface's zone to GUEST; Addressing Manual, IP 192.168.130.1/24.

  3. Turn on the captive portal

    Zones → the wireless icon on the Guest row → Interface: eth1.30Captive portal active → fill in the Gateway IP and DHCP range → Save.

  4. Open captive access

    In the same zone's Zone Settings › External Device Access section, turn on the Captive Portal switch; then make sure the relevant sources are in the Trusted Hosts list.

  5. Close the Guest → LAN transit

    Rules → add a low-order GUEST → LAN · Block rule. (It is blocked by default already; this rule explicitly documents your intent.)

  6. Prepare the portal content

    Set the design, language and login method from the Hotspot Management › Captive Portal and Portal Design Management sections.

Warning: To prevent guest devices from seeing each other, the intra-zone switch is not enough — in a single-interface zone, the traffic never reaches the box. Do the isolation on the access-point side (client isolation).

Scenario C · Exposing an internal server

  1. Fix the server's address

    DHCP & DNS › MAC → IP Reservations → reserve 192.168.100.10 for the server's MAC (or give the server a static IP).

  2. Define an address and a service object

    Addresses → “Web-Server” = Host 192.168.100.10. If needed, Services → a new service for the custom port.

  3. Add the port forward

    NAT / Port ForwardingAdd Port Forwarding → proto tcp, WAN port 443, target 192.168.100.10:443.

  4. Test from outside

    Verify access from an external connection such as mobile data. Thanks to surgical transit, only this host:port is opened.

  5. Narrow the source if needed

    If access is wanted only from specific external addresses, write a rule in Rules in the WAN → DMZ/LAN direction that limits it with a source address object.

Scenario D · Adding a second internet line

  1. Assign the new line to the WAN zone

    Interfaces → the backup line's interface → Zone: WAN, Mode: PPPoE/DHCP/Static.

  2. Give a Distance

    SD-WAN › Lines10 for the primary line, 20 for the backup. Wait ~1 minute for it to fully take effect in routing.

  3. Wait for the state to settle

    For both lines you should see State: Working and Routing: Ready.

  4. Tune the SLA to your environment

    On a mobile/satellite backup line, raising the timeout and the “how many failures for no access” value reduces false alarms.

  5. Write a line-selection rule

    SD-WAN › SD-WAN Rules → “Guest network over the backup line” → source: the guest subnet object, line: the backup interface. Keep the narrow-scope rule at the top of the list.

  6. Verify the behavior

    Make sure the rule's Line information does not say red Line not found.

Set the right expectation: The backup line kicks in automatically for traffic within the rule's scope. If the line of traffic outside the rule's scope breaks, the system does not switch to the other line on its own — you set the preference with Distance. There is no load sharing.

Scenario E · Making external firewall logs arrive

  1. Determine the zone of the log-sending device

    The zone of whichever interface the device comes from.

  2. Check the Syslog switch

    Zones › the relevant zone › Zone Settings › External Device AccessSyslog must be on (it is on by default on non-WAN zones).

  3. Verify the Trusted Hosts list

    The address of the log-sending device must be in the list. If the list is empty, no permission is generated — even if the switch appears on, the traffic does not pass.

  4. Verify the flow

    Check on the Firewall Log Search screen whether records appear in the same time range.

Troubleshooting

A quick table that, starting from the symptom, points to the most likely cause and the page to look at.

SymptomPossible causeWhere to look
The Firewall Management menu is not visibleRouter mode is off, or the account is not a member of the root domain / lacks permission.Status › Router Mode
Router mode won't turn on: “management interface” errorThe interface you assigned to the WAN zone is the management interface. It is not accepted as the uplink.Readiness checks
Router mode won't turn on: “an IP must be assigned to an internal-zone interface”The internal interface has no L3 address.Interfaces
The mode turned on, then turned off on its ownConfirm and Make Permanent was not clicked within the confirmation time; lockout protection rolled it back.The confirmation window
Clients can't get an IPDHCP is on in the zone but the service is not running, or the role is Off/Relay.DHCP & DNS · Overview › Health
No internet but the interface is “Connected”The line is up but there is no exit to the outside (operator side). The probe sees this, the connectivity box does not.Overview › Internet line
I wrote a rule but traffic doesn't passThe interface is in the wrong zone, the rule order sits below a block higher up, or it falls into implicit deny.Rules · Monitor
Port forwarding doesn't workThe internal target's IP changed via DHCP; or the same external port is defined for another target.NAT · Reservations
I turned on Captive/RADIUS but there's no accessTrusted Hosts is empty or the source's address is not in the list.Trusted Hosts
Firewall logs aren't arrivingSyslog is off on the relevant zone or Trusted Hosts is missing. The logs are dropped without producing an error.Zone Settings
“Pass-through traffic” count is 0Client traffic is not passing through the box — a placement or default-gateway problem. It is not a settings problem.Overview › Record Generation
The record file is growing rapidlyTraffic to/from the device was left on; this type produces ~99% of the rows.Log Settings
Session is open but the user can't get outThe No-authorization badge in Monitor: the session exists, but there is no transit permission in the data plane.Monitor › Sessions
The SD-WAN rule is not being appliedThe rule's line was removed from the WAN zone or the interface never formed → Line not found.SD-WAN Rules
The line seems to keep going up and downThe SLA thresholds are too aggressive. Raise the “how many failures for no access” and the timeout.Performance SLA
“Settings saved BUT could not be applied to the live router”The setting was stored, the rules could not be loaded. The live behavior is in its old form. Do not consider the operation finished.Try applying again
I can't turn off management accessYou are currently connected over that zone; lockout protection is preventing it.Connect from the management interface and try again

Law 5651 and record generation

The importance of router mode for compliance is this: the record now rests not on a report sent by another device but on the traffic SignLogger itself sees. This removes an intermediary layer from the chain of evidence.

TopicStatus
Pass-through traffic logIt is mandatory and cannot be turned off. It appears locked in the interface; a request to turn it off is ignored even if sent from outside the interface.
Scope of the recordOne row for each permitted (established) connection. No “rejected” row is produced for blocked traffic.
Identity mappingDHCP allocation events tie the IP–MAC–time triple to the record; do not turn it off.
ReadabilityWhile Add destination domain name is on, the site name also appears instead of the IP. Browsing history is not stored separately.
Daily scope declarationEvery night, that day's generation/gap information is written as an event row and signed. It cannot be turned off.
License effectIf the license is invalid, routing continues but the captive portal and compliance records stop.
Retention and signingOutside the scope of this page; retention period, rotation, signing and archiving are managed separately.

The most common mistake: Leaving the Traffic to/from the device switch on. This type is not legal evidence, but in the distribution measured in the field it produces about 99% of the rows — the log file bloats, searches slow down, and the actual evidence gets buried in noise. Turn it on only temporarily while troubleshooting.

Appendix A · Defaults and limits

SettingDefaultLimit / note
Confirmation time120 s30 – 900 s (server upper limit 900)
Zone name1–32 characters; letters, digits, _, -
VLAN number1 – 4094
IP prefix248 – 32 (the form suggests 8–30)
Intra-zone trafficOnNot present on WAN and MGMT
Internal-zone management portsOnHTTPS · HTTP · SSH · Telnet · Ping
WAN-zone management portsOffTurning them on exposes the device directly to the internet
Captive Portal access (zone)OffPorts 8080, 8081, 8084, 8086
RADIUS access (zone)OffPorts 1812, 1813
Syslog access (zone)On except WANPort 514, UDP + TCP
Distance0 (unspecified)0 – 255; smaller value is preferred
Distance propagation timeSecurity/NAT immediately, routing within at most 60 s
SLA measurement targets1.1.1.1:443 · 8.8.8.8:443 · 8.8.8.8:53at most 8 targets, address:port
SLA measurement interval20 s5 – 300 s
SLA timeout4 s1 – 30 s; must be shorter than the interval
SLA evaluation window15 samples5 – 120 samples
How many failures for “no access”31 – 20
How many successes for “working”21 – 20
Latency warning threshold250 ms10 – 5000 ms (display only)
Loss warning threshold10%1 – 100% (display only)
SD-WAN rule nameat most 128 characters
Monitor time rangeLast 15 minutes5 min · 15 min · 1 hr · 6 hr · 24 hr
Monitor auto refreshOnEvery 10 seconds
Live Traffic list limit300 connectionsThe counter writes “shown / total”
Sessions list limit500 sessionsThe “Open sessions” on the top strip is also subject to this limit
Users / Devices / Destinations15 recordsSorted by total data
Overview · live boxes4 sOther sections 20 s
SD-WAN Lines / SLA refresh15 sThe rule list does not refresh on its own
Active session warning threshold8000Above it, turns to warning color
Log sampling windowlast ~4 MBThe numbers in the boxes come from this sample
Device traffic logOffProduces ~99% of the rows
DHCP allocation / authentication / system eventsOnTurning them off is not recommended
Pass-through traffic logOnLocked — cannot be turned off

Appendix B · Glossary

TermMeaning
Interface (NIC)The device's physical network port. The cable plugs in here.
ZoneA policy group that holds together interfaces of a similar trust level. Rules are written between zones.
WANThe zone carrying the internet uplink. It is singular.
MGMTThe management zone. The management ports are never restricted here.
UplinkThe line over which the device reaches the internet.
CIDRNotation that expresses an IP range in network/mask form (192.168.10.0/24).
PrefixThe number of mask bits in the CIDR. /24 = a block of 256 addresses.
GatewayThe next-hop address to which traffic is delivered.
NATNetwork address translation. Determines how internal private addresses appear to the outside world.
SNAT / MasqueradeSource address translation. Translates the source of outgoing traffic to the WAN address.
DNAT / Port forwardingDestination address translation. Forwards specific inbound port traffic to an internal host:port.
Implicit denyThe automatic rejection of traffic matching no rule. The basis of the policy's “default closed.”
Address objectA name given to an IP/network definition. Used in rules instead of a raw IP.
Service objectA name given to a protocol + port combination (HTTPS = tcp/443).
Captive PortalThe welcome page where a guest authenticates before reaching the internet. It is an interface feature.
Trusted HostsThe list that determines from which source addresses the Captive / RADIUS / Syslog permissions are valid. If empty, no permission is generated.
DistanceLine preference order. A smaller value is the preferred line.
SLA probeA short TCP connection attempt that measures whether the line actually reaches the outside. It is not a ping.
HysteresisThe method of preventing flapping in the line's healthy/unhealthy decision with “how many failures / how many successes” thresholds.
OnlinkThe route setup form in which the gateway is considered directly reachable over the specified interface.
LeaseThe time a DHCP client can use the address it received.
DHCP RelayThe role that does not give out the address itself but forwards the requests to a central DHCP server.
802.1q / VLANThe standard for separating multiple logical networks over a single physical cable with tags.
Fail-to-wireTraffic continuing to flow normally instead of being cut while the license or portal is disabled.
Lockout protectionThe set of mechanisms that prevent a wrong setting from locking the administrator out of the device.

Didn't find what you were looking for?

Contact our technical support team