In most cases you will want to consult with Cipafilter support to decide what way the router can best be installed to meet your needs. A full over-the-phone consultation during installation is included in the standard one-year maintenance and service agreement that comes with your router.
10.1.2.3/8
assigned to its first Ethernet interface and 192.168.0.1/24
assigned to its second interface. If your network does not use 10.0.0.0/8
IP addresses, you can simply assign an IP like 10.1.2.1/8
(netmask 255.0.0.0
) to your workstation and plug the Cipafilter into your hub or switch.root
and the default password is derby
. The password can (and should) be changed on the Management Users page.Often you will find that the best way to install your Cipafilter is as a replacement for your current router. Cipafilter is a top-of-the-line router and implements virtually all of the functionality of other routing systems. In this case you would configure Cipafilter with the IP addresses, routes, and NAT settings currently on your router, and then replace your current router.
The easiest way to install your Cipafilter is as a bridge. Simply unplug your existing router from your switch bank, connect the Cipafilter to that port on your router via a cross-over cable, and then connect the cable that was plugged into your router to the other port on the Cipafilter. Lastly, enable the Interface Bridging option on the IP Settings page of the Web-based interface. Your network should now operate normally, and you can activate the Cipafilter's features one-by-one as you're ready to implement them.
If you do not wish to replace your current router, you can connect the Cipafilter and your existing router with a cross-over cable, and then connect the Cipafilter to the rest of your network. This essentially "splices" the Cipafilter into the cable running from your router to your network. To do this you must first pick a small subnet from a private range you aren't using. If you're using 10.0.0.0/8
you might pick 192.168.0.0/24
, for example. Assuming the default gateway you use for your clients is 10.0.0.1
, you would then:
Replace the 10.0.0.1/8
IP address on your main router with 192.168.0.1/24
.
Configure your Cipafilter with 192.168.0.2/24
on the outside interface and 10.0.0.1/8
on the inside interface.
Disconnect your main router from the hub, and run a cross-over cable from that Ethernet port on your main router to the outside Ethernet port on the Cipafilter.
Connect the inside Ethernet port on your Cipafilter to the port on your hub or switch where your router was connected.
Create a route for 10.0.0.1/8
with a gateway of 192.168.0.2
in your main router; alternatively, you can choose to activate NAT on the 10.0.0.0/8
subnet on the Cipafilter and not create a route. If you choose the NAT option be certain that the 192.168.0.2/24
interface is selected as the Primary Internet Connection.
Many features of the Cipafilter can be used simply by assigning the Cipafilter an IP address on your network and connecting it like any other server.
Transparent proxy will be unavailable.
The firewall function will be ineffective.
You will often need to add firewall rules to your existing router to force users to use the proxy server in order to make Cipafilter effective at protecting your network.
Bandwidth control will only be effective for Internet traffic working through the proxy server.
The bandwidth-reporting feature may not be able to monitor all traffic on your network.
The Cipafilter firmware is also available as an image suitable for use with a virtual-machine solution. VMware is the most common and best-supported vendor, although many others have been used successfully. Any of the four previous methods may be combined with the virtual-machine option.