| Key Features |
| Basic Functionality |
Operation mode: NAT/PAT, route and hybrid mode |
| Internet access type: PPPoE, static IP and dynamic IP |
| Intelligent NAT |
NAT (network address translation) |
| PAT (port address translation) |
| Multi-NAT |
| Port range forwarding (up to 20) |
| DMZ (Demilitarized Zone) Host |
| NAT traversal |
| NAT ALG (ICMP, FTP, GRE, PPTP, ESP) |
| Strong Firewall |
IP packet filtering (up to 100): IP address, protocol and TCP/UDP port filtering |
| Web content filtering: URL and keyword filtering |
| Filtering based on schedule |
| IM (instant messenger) control: block or allow IM application, e.g., MSN/QQ Messenger |
| P2P (peer-to-peer) control: block or allow P2P application, e.g., BitTorrent |
| Policy database of firewall, policy database online update |
| Popular Attack Defense |
Defense against ARP spoofing, IP address spoofing |
| Defense against DoS/DDoS attack, e.g., SYN flood, UDP flood, ICMP flood, TCP/UDP port scan |
| Defense against worm viruses |
| Enable/disable WAN ping |
| IP/MAC Binding |
IP/MAC address binding (up to 53) |
| Blacklist and whitelist Setting |
| IP/MAC address intelligent binding: automatic binding and batch binding |
| Bandwidth Management |
Based on CBT (credit-based traffic control) algorithm |
| Ingress and egress bandwidth management |
| Guarantee bandwidth for each LAN connected PC |
| Maximum bandwidth for each LAN connected PC |
| NAT session limitation for each LAN connected PC |
| VPN |
Global Features |
Protocols: IPSec, L2TP and PPTP |
| FQDN (fully qualified domain name) support for dynamic IP address VPN connections |
| Site-to-site VPN, remote access VPN (client-to-site) |
| Hub-spoke and mesh connections |
| VPN pass-through of L2TP, PPTP, IPSec |
| L2TP over IPSec and IPSec over L2TP |
| L2TP/PPTP |
L2TP server/client |
| PPTP server/client |
| PAP and CHAP authentication |
| IPSec |
AutoIKE key based on pre-shared key tunnels |
| Manual key tunnels |
| ESP and AH protocols |
| DES, 3DES and AES 128/192/256 encryption algorithm |
| MD5 and SHA-1 hash algorithm |
| Diffie-Hellman group 1, 2 and 5 |
| Main mode and aggressive mode |
| Anti-replay |
| DPD (dead peer detection) |
| IPSec client software for windows |
| Network Protocol |
IP Routing |
Static routing (up to 64 entries) |
| Dynamic routing: RIPv1 and RIPv2 |
| DHCP |
DHCP client |
| DHCP server |
| DHCP manual bindings (up to 53) |
| ARP |
Dynamic ARP |
| Static ARP |
| ARP proxy |
| Free ARP |
| DNS |
DDNS (dynamic DNS) client |
| DNS proxy |
| Other Functionality |
MAC address clone |
| Port-based VLAN |
| UPnP (universal plug and play) |
| Port mirroring |
| SNTP (simple network time protocol) |
| Schedule setting (up to 10) |
| Address group setting (up to 20) |
| System Management |
Web user interface |
| Quick start wizard |
| Command line interface (Telnet) |
| Remote management via Web or CLI |
| Firmware upgrade via TFTP or Web |
| Configuration file backup/restore |
| Factory default configuration restore |
| Built-in diagnostic tool: ping, traceroute, nslookup |
| SNMP v1/v2c support |
| SYSLOG support |
| Real-time monitoring, logging, alarms of system activities |
| Multi-level administration privileges |
| Xport HiPER manager software |