Gebruiksaanwijzing /service van het product P-2602 van de fabrikant ZyXEL Communications
Ga naar pagina of 427
P-2602HW(L) Series 802.1 1g Wireless ADSL2+ V oIP IAD P-2602H Series ADSL2+ V oIP IAD User ’ s Guide V ersion 3.40 7/2006 Edition 1.
.
P-2602H(W)(L)-DxA Ser ies User’s Guide Copyright 3 Copyright Copyright © 2006 by ZyXEL Communications Corpo ration. The contents of this publication may not be reprod uced in any part or as a wh ol.
P-2602H(W)(L)-DxA Series User’s Guide 4 Certifications Certifications Federal Communications Commissi on (FCC) Interference St atement This device complies with Part 15 of FCC rul es. Operation is subject to the following two conditions: • This device may not cause harmful interference.
P-2602H(W)(L)-DxA Ser ies User’s Guide Safety Warnings 5 Safety W arnings For your safety , be sure to read and fo llow all warning notices and instructions. • T o reduce the risk of fire, use only No. 26 A WG (American W ire Gauge) or larger telecommunication line cord.
P-2602H(W)(L)-DxA Series User’s Guide 6 ZyXEL Limited Warranty ZyXEL Limited W arranty ZyXEL warrants to the original en d user (purchaser) that this product is free from any defects in materials or workmansh ip for a period of up to two years from the date of purchase.
P-2602H(W)(L)-DxA Ser ies User’s Guide Customer Support 7 Customer Support Please have the following information r eady when you contact customer support. • Product model and serial number . • W arranty Information. • Date that you received your de vice.
P-2602H(W)(L)-DxA Series User’s Guide 8 Customer Suppo rt +” is the (prefix) number you enter to make an interna tional telephone call. NORWAY support@zyxel.no +47-22-80-61-80 www .zyxel.no ZyXEL Communications A/S Nils Hansens vei 13 0667 Oslo Norway sales@zyxel.
P-2602H(W)(L)-DxA Ser ies User’s Guide Table of Contents 9 T able of Content s Copyright .................................................. .......................................... ...................... 3 Certifications ..........................
P-2602H(W)(L)-DxA Series User’s Guide 10 Table of Contents 2.2.3 Main Window ...................... .................... ................... ................... ............ 55 2.2.4 S tatus Bar ..... ................ ................... ...........
P-2602H(W)(L)-DxA Ser ies User’s Guide Table of Contents 11 7.1.4 IP Address Assignment ............. ................... ................... ....................... ..95 7.1.4.1 IP Assignment with PPPoA or PPPoE Encapsulatio n ............ ........
P-2602H(W)(L)-DxA Series User’s Guide 12 Table of Contents 9.2 Wireless Security Overview ...................... ................... ....................... ............. 122 9.2.1 SSID ......... .................... ................... ............
P-2602H(W)(L)-DxA Ser ies User’s Guide Table of Contents 13 1 1.2.1 SIP Identities ..... ....................... ................... ................... ....................... 151 1 1.2.1.1 SIP Number .......... ................... ................
P-2602H(W)(L)-DxA Series User’s Guide 14 Table of Contents 1 1.15.3 USA T ype Supplement ary Services .... ................... ................... ..........170 1 1.15.3.1 USA Call H old ............... ................... ................... ......
P-2602H(W)(L)-DxA Ser ies User’s Guide Table of Contents 15 13.7 Packet Filtering Vs Fi rewall .. ................... ................... .................... ................ 191 13.7.1 Packet Filtering: ................ .................... ......
P-2602H(W)(L)-DxA Series User’s Guide 16 Table of Contents 16.1.1 IPSec ................... .................... ................... ................... .................... ...215 16.1.2 Security Associatio n ...... ................... ............
P-2602H(W)(L)-DxA Ser ies User’s Guide Table of Contents 17 17.18 T elecommuter VPN /IPSec Examples ........... ...................... ................... .......244 17.18.1 T elecommuters Shar ing One VPN Rule Example ..............................
P-2602H(W)(L)-DxA Series User’s Guide 18 Table of Contents 21.1.3 System Timeout ............... .................... ...................... ................... .......268 21.2 WWW ......... ...................... .................... ..............
P-2602H(W)(L)-DxA Ser ies User’s Guide Table of Contents 19 25.4 Firmware Upgrade Screen ....... ....... ............. ................... ................... ..........302 25.5 Backup and Restore ............ ............. ...... ..................
P-2602H(W)(L)-DxA Series User’s Guide 20 Table of Contents P-2602HWL Series Power Adaptor S pecificat ions .................. ................... ............ 336 Appendix B Splitters and Microfilters ................................................
P-2602H(W)(L)-DxA Ser ies User’s Guide Table of Contents 21 RADIUS ............ ................... ................... .................... ...................... .................... .. 366 T ypes of RADIUS Messages ............................ ..
P-2602H(W)(L)-DxA Series User’s Guide 22 Table of Contents Internal SPTGEN Overview ............. ....................... ................... ...................... ...... 395 The Configuration T ext File Format ............ ...................... .
P-2602H(W)(L)-DxA Ser ies User’s Guide List of Figure s 23 List of Figures Figure 1 Internet Access Applic ation ..... ....................... ................... .................... ................ 44 Figure 2 Internet T elephony Se rvic e Provider Application .
P-2602H(W)(L)-DxA Series User’s Guide 24 List of Figures Figure 39 Bandwidth Management Wizard: G eneral Information .................... ................... 80 Figure 40 Bandwidth Management Wizard: Serv ic e Configuration ..................... ...
P-2602H(W)(L)-DxA Ser ies User’s Guide List of Figure s 25 Figure 82 Port Forwarding Rule Setup ............. .................... ................... ................... ....... 148 Figure 83 Network > NA T > ALG .................... ........
P-2602H(W)(L)-DxA Series User’s Guide 26 List of Figures Figure 125 T wo Phases to Set Up the IPSec SA ................ ................... ................... .......... 234 Figure 126 Advanced VPN Policies .......... ................... ..........
P-2602H(W)(L)-DxA Ser ies User’s Guide List of Figure s 27 Figure 168 E-mail Log Example ............ .................... ...................... ....................... ............. 300 Figure 169 Firmware Upgrade ........... .....................
P-2602H(W)(L)-DxA Series User’s Guide 28 List of Figures Figure 21 1 Mac intosh OS X: Apple Menu ....................... ....................... ................... .......... 350 Figure 212 Macintosh OS X: Network ... ....................... ......
P-2602H(W)(L)-DxA Ser ies User’s Guide List of Tables 29 List of T ables T able 1 Models Cov ered ............. ................... ....................... ................... ....................... ... 37 T able 2 ADSL S tandards ............. ...
P-2602H(W)(L)-DxA Series User’s Guide 30 List of Tables T able 39 Wireless: WP A(2)-PSK .............. ................ ................................................ .......... 129 T able 40 Wireless: WP A(2) ............ ................... ....
P-2602H(W)(L)-DxA Ser ies User’s Guide List of Tables 31 T able 82 VPN and NA T .................. ................... ....................... ................... ....................... 226 T able 83 Local ID T ype and Content Fields ... ..........
P-2602H(W)(L)-DxA Series User’s Guide 32 List of Tables T able 125 Troubleshooting S tarting Up Y our Devi ce ...... .................... ................... ............. 319 T able 126 Troubleshooting the LAN .................. ...................
P-2602H(W)(L)-DxA Ser ies User’s Guide List of Tables 33 T able 168 RTP Logs ....... ................... .................... ................... ....................... ................... 38 9 T able 169 FSM Logs: Caller S ide ...... .............
P-2602H(W)(L)-DxA Series User’s Guide 34 List of Tables.
P-2602H(W)(L)-DxA Ser ies User’s Guide Preface 35 Preface Congratulations on your purchase of the P- 2602H(W)(L)-DxA 802.1 1g W ireless AD SL 2+ V oIP IAD (the “ZyXEL Device”).
P-2602H(W)(L)-DxA Series User’s Guide 36 Preface • Mouse action sequences are denoted using a ri ght angle bracket ( > ). For example , “In W indows, click St a r t > Settings > Contr ol Panel ” means first click the St a r t but ton, then point yo ur mouse pointer to Settings and then click Contr ol Panel .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 1 Getting To Know the ZyXEL Device 37 C HAPTER 1 Getting T o Know the ZyXEL Device This chapter describes the key features and applications of your device .
P-2602H(W)(L)-DxA Series User’s Guide 38 Chapter 1 Getting To Know the ZyXEL Device Models with “3” as the next to the last char acter (like the P-2602HWL-D3A) denote a device that works over ISDN (Integrated Services Digita l Network).
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 1 Getting To Know the ZyXEL Device 39 PSTN Line (“L” models only) Y ou can connect a PSTN line to your device. Y ou can receive incoming PSTN phone calls even while someone else is making V oIP phone ca lls.
P-2602H(W)(L)-DxA Series User’s Guide 40 Chapter 1 Getting To Know the ZyXEL Device Network Address T ranslation (NA T) Network Address T ranslation (NA T) allows the tr anslation of an Internet pro.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 1 Getting To Know the ZyXEL Device 41 Echo Cancellation Y ou device supports G .168, an ITU-T stan dard for eliminating the ec ho caused by the sound of your voice reverberating in th e telephone receiver while you talk.
P-2602H(W)(L)-DxA Series User’s Guide 42 Chapter 1 Getting To Know the ZyXEL Device Multiple P VC (Permanent Virtual Circuit s) Support Y our device supports up to 8 Permanen t V irtual Circuits (PVC’ s ). IP Alias IP alias allows you to partitio n a physical network into logi cal networks over the same Ethernet interface.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 1 Getting To Know the ZyXEL Device 43 Note: Y our device may be prone to RF (Radio Frequency) interference from other 2.4 GHz devices such as microwave ovens, wireless ph ones, Bluetooth enabled devices, and other wireless LANs.
P-2602H(W)(L)-DxA Series User’s Guide 44 Chapter 1 Getting To Know the ZyXEL Device 1.4 Applications for the ZyXEL Device Here are some example uses for wh ich the ZyXEL Device is well suited. 1.4.1 Internet Access Y our device is the ideal high-speed Internet ac cess solution.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 1 Getting To Know the ZyXEL Device 45 Figure 2 Internet T elephony Service Provider Application 1.4.3 Make Peer-to-peer Calls Y ou can call directly to someone’ s IP address without u sing a SIP proxy server .
P-2602H(W)(L)-DxA Series User’s Guide 46 Chapter 1 Getting To Know the ZyXEL Device Figure 4 Firewall Application 1.4.5 LAN to LAN Application Y ou can use your device to connect two geogra phically dispersed networks over the ADSL line. A typical LAN-to-LAN app lication is shown as follows.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 1 Getting To Know the ZyXEL Device 47 1.4.6 LEDs Figure 6 LEDs The following table describes your device’ s LEDs. Table 4 LEDs LED COLOR ST ATUS DESCRIPTION POWER Green On Y o ur device is receiving power and functioning properly .
P-2602H(W)(L)-DxA Series User’s Guide 48 Chapter 1 Getting To Know the ZyXEL Device Refer to the Quick S tart Guide for in formation on hard ware connections. DSL Green On Y o ur device has a DSL connection. Blinking Y our device is initi alizing the DSL line.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 2 Introducing the Web Configur ator 49 C HAPTER 2 Introducing the W eb Configurator This chapter describes how to access and navigate the web configurator .
P-2602H(W)(L)-DxA Series User’s Guide 50 Chapter 2 Introducing the Web Configurator Figure 7 Password Screen 5 The following screen displays if you have no t yet changed your password.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 2 Introducing the Web Configur ator 51 Note: For security reasons, the ZyXEL De vice automatically logs you out if you do not use the web configurator for five minutes. If this happens, log in again. Figure 9 Wizard or Advanced Screen 2.
P-2602H(W)(L)-DxA Series User’s Guide 52 Chapter 2 Introducing the Web Configurator 2.2 W eb Configurator Main Screen Figure 10 Main Screen As illustrated above, the main scr een is di vided into these parts: • A - title bar • B - navigation panel • C - main window • D - status bar 2.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 2 Introducing the Web Configur ator 53 The icons provide th e following functions. 2.2.2 Navigation Panel Use the men u items on the na vigation panel to open screens to conf igure ZyXEL Device features.
P-2602H(W)(L)-DxA Series User’s Guide 54 Chapter 2 Introducing the Web Configurator Phone Analog Phone Use this screen to set which ph one ports use which SIP accounts. Common Use this screen to configure general phone port settings. Region Use this screen to select your loca tion and call service mode.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 2 Introducing the Web Configur ator 55 2.2.3 Main Window The main window displays informa tion and configuration fields. It is discussed in the rest of this document. Right after you log in, the St a t u s screen is displayed.
P-2602H(W)(L)-DxA Series User’s Guide 56 Chapter 2 Introducing the Web Configurator.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 3 Internet an d Wireless Setup Wizard 57 C HAPTER 3 Internet and Wireless Setup Wi za r d This chapter provides informatio n on the W izard Se tup screens for Internet access in the web configurator . 3.
P-2602H(W)(L)-DxA Series User’s Guide 58 Chapter 3 Internet and Wireless Setup Wizar d Figure 12 Wizard Welcome 3 Y our ZyXEL device attempts to detect your DSL conn ection and your connection type. a The following screen appears if a connection is not detected.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 3 Internet an d Wireless Setup Wizard 59 Figure 14 Auto-Detection: PPPoE c The following screen appears if the ZyXEL device detects a connection but not the connectio n type. Click Next and refer to Section 3.
P-2602H(W)(L)-DxA Series User’s Guide 60 Chapter 3 Internet and Wireless Setup Wizar d SIP provider gave it to you. Le ave the defaults in any fields for which you were not given information. Figure 16 Internet Access Wizard Setup: ISP Parameters The following table describes the fields in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 3 Internet an d Wireless Setup Wizard 61 2 The next wizard screen varies depending on wh at mode and encapsulation ty pe you use. All screens shown are with routing mode. Configure the fields and click Next to continue.
P-2602H(W)(L)-DxA Series User’s Guide 62 Chapter 3 Internet and Wireless Setup Wizar d Figure 18 Internet Connection with RFC 1483 The following table describes the fields in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 3 Internet an d Wireless Setup Wizard 63 The following table describes the fields in this screen. Figure 20 Internet Connection with PPPoA The following table describes the fields in this screen.
P-2602H(W)(L)-DxA Series User’s Guide 64 Chapter 3 Internet and Wireless Setup Wizar d • If the user name and/or password you ente red for PPPoE or PPPoA connection are not correct, the screen displays as shown next. Click Back to Username and Password setup to go back to the screen where you can modify them.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 3 Internet an d Wireless Setup Wizard 65 3.3 Wireless Connection Wizard Setup After you configure the Internet access informatio n, use the following scr eens to set up your wireless LAN. 1 Select Ye s an d click Next to configure wireless settings.
P-2602H(W)(L)-DxA Series User’s Guide 66 Chapter 3 Internet and Wireless Setup Wizar d The following table describes the labels in this screen. 3 Configure your wireless settin gs in this screen. Click Next . Figure 25 Wireless LAN The following table describes the labels in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 3 Internet an d Wireless Setup Wizard 67 Note: The wireless stations and ZyXEL Device must use the sa me SSID, channel ID and WEP encryption key (if WEP is enabled), WP A-PSK (if WP A-PSK is enabled) for wireless communicatio n.
P-2602H(W)(L)-DxA Series User’s Guide 68 Chapter 3 Internet and Wireless Setup Wizar d The following table describes the labels in this screen. 3.3.2 Manually Assign a WEP key Choose Manually assign a WEP key to setup WEP Encryption parameters.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 3 Internet an d Wireless Setup Wizard 69 The following table describes the labels in this screen. 5 Click Apply to save your wireless LAN settings. Figure 28 Wireless LAN Setup 3 6 Use the read-only summary table to check whet her what you have configured is correct.
P-2602H(W)(L)-DxA Series User’s Guide 70 Chapter 3 Internet and Wireless Setup Wizar d Figure 29 Internet Access and WLAN Wizard Se tup Complete 7 Launch your web browser and navigate to www .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 4 VoIP Wizard And Example 71 C HAPTER 4 V oIP Wizard And Example This chapter shows you how to configure your SIP account(s) and make a V oIP phone call.
P-2602H(W)(L)-DxA Series User’s Guide 72 Chapter 4 VoIP Wizard And Example Figure 31 Select a Mode 2 Click V OICE OVER INTERNET SETUP to configure your SIP settings.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 4 VoIP Wizard And Example 73 3 Fill in the V OICE OVER INTERNET SETUP wizard screen with the information provided by your V oIP service provider . Y our V oIP service provider supplies you with the following information.
P-2602H(W)(L)-DxA Series User’s Guide 74 Chapter 4 VoIP Wizard And Example 4 Y our ZyXEL Device will attempt to register your SIP account with your V oIP service provider . When y our account is registered your PHONE 1 light will come on and you are ready to make and receive V oIP phone calls.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 4 VoIP Wizard And Example 75 Figure 35 V oIP Wizard Fail 6 This screen displays if your SIP ac count registration was successful. Click Return to Wiz ar d M a in Pa ge if you want to use another config uration wizard.
P-2602H(W)(L)-DxA Series User’s Guide 76 Chapter 4 VoIP Wizard And Example.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 5 Bandwidth Management Wiza rd 77 C HAPTER 5 Bandwid th Management Wizard This chapter shows you how to configure basic bandwidth management using th e wizard screens.
P-2602H(W)(L)-DxA Series User’s Guide 78 Chapter 5 Bandwidth Man agement Wizard 5.3 Bandwid th Management Wizard Setup 1 After you enter the password to access the web configurator , select Go to Wizard setup and click Apply . Otherwise, click the wiz ard icon ( ) in the top right corner of the web configurator to display the wiza rd main screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 5 Bandwidth Management Wiza rd 79 Figure 37 Select a Mode 2 Click BANDWIDTH MANAGEMENT SETUP . Figure 38 Wizard: Welcome 3 Activate bandwidth management and select to allocate bandwidth to packets based on the packet size or services.
P-2602H(W)(L)-DxA Series User’s Guide 80 Chapter 5 Bandwidth Man agement Wizard Figure 39 Bandwidt h Management Wizard: General In formation The following fields describe the label in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 5 Bandwidth Management Wiza rd 81 The following table describes the labels in this screen. 5 Follow the on-screen instructions and click Finish to complete the wizard setup and save your configuratio n.
P-2602H(W)(L)-DxA Series User’s Guide 82 Chapter 5 Bandwidth Man agement Wizard.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 6 Status Screens 83 C HAPTER 6 S t atus Screens Use the St a t u s screens to look at the current status of the device, sys tem resources, interfaces (LAN and W AN), and SIP accounts. Y ou can als o register and unregister SIP accounts.
P-2602H(W)(L)-DxA Series User’s Guide 84 Chapter 6 Sta tus Screens Each field is described in the following table. Table 21 Status Scree n LABEL DESCRIPTION Refresh Interval Enter how often you want the ZyXEL Device to update this screen. Apply Click this to update this screen immediately .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 6 Status Screens 85 Security Firewall This displays whether or not the ZyXEL Device’s firewall is activated. Click this to go to the screen where you can change it. Content Filter This displays whether or not the ZyXEL Device’s content filtering is activated.
P-2602H(W)(L)-DxA Series User’s Guide 86 Chapter 6 Sta tus Screens 6.2 Any IP T able Click S tatus > AnyIP T able to access this screen. Use this screen to view the IP addres s and MAC address of each computer that is using the ZyXEL Device but is in a different subnet than the ZyXEL Device.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 6 Status Screens 87 Each field is described in the following table. 6.3 WLAN S t atus (“W” models only) Click St a t u s > W L A N St a t u s to access this screen. Use this screen to view the wireless stations that are currently ass ociated to the ZyXEL Device.
P-2602H(W)(L)-DxA Series User’s Guide 88 Chapter 6 Sta tus Screens Figure 45 Packet S t atistics The following table describes th e fields in this screen. Table 24 Packet S tatistics LABEL DESCRIPTION System Monitor System up T ime This is the elapsed time the system has been up.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 6 Status Screens 89 6.5 V oIP St atistics Click St a t u s > V o I P St a t i s t i c s to access this screen. Figure 46 V oIP S tatistics Up T ime Th is field displays the elapsed time this port has been up.
P-2602H(W)(L)-DxA Series User’s Guide 90 Chapter 6 Sta tus Screens Each field is described in the following table. Table 25 VoIP Statistics LABEL DESCRIPTION SIP S t atus Account This column disp lays each SIP account in the ZyXEL Device. Registration This field displays the current registrati on status of the SIP account.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 6 Status Screens 91 Tx B/s This field displays how quickly the ZyXEL Device has transmitted p ackets in the current call. The rate is the average number of bytes transmitted per second. Rx B/s This field displays how quickly the Zy XEL Device has receiv ed pa ckets in the current call.
P-2602H(W)(L)-DxA Series User’s Guide 92 Chapter 6 Sta tus Screens.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 7 WAN Setup 93 C HAPTER 7 W AN Setup This chapter describes how to configure W A N settings. 7.1 W AN Overview A W AN (W ide Area Network) is an outside conn ection to another network or the Intern et. 7.
P-2602H(W)(L)-DxA Series User’s Guide 94 Chapter 7 WAN Setup By implementing PPPoE directly on the ZyXEL Device (rather than individual computers), the computers on the LAN do not need PPPoE software installed, since the ZyXEL Device does that part of the task.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 7 WAN Setup 95 7.1.4 IP Address Assignment A static IP is a fixed IP that your ISP gives you. A dynamic IP is not fixed; the ISP assigns you a different one each time. The Si ngle User Account feature can be enabled or disabled if you have either a dynamic or static IP .
P-2602H(W)(L)-DxA Series User’s Guide 96 Chapter 7 WAN Setup 7.2 Metric The metric represents the "cost of transmissi on". A router determines the best route for transmission by choosing a path with the lowest "cost".
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 7 WAN Setup 97 Maximum Burst Size (MBS) is the maximum numb er of cells that can be sent at the PCR. After MBS is reached, cell rates fall below SCR until cell rate averages to the SCR again. At this time, more cells (up to the MBS) can be sent at the PCR again.
P-2602H(W)(L)-DxA Series User’s Guide 98 Chapter 7 WAN Setup The VBR-nR T (non real-time V ariable Bit Rate) ty pe is used with bursty connections that do not require closely controlled delay and delay variation. It is commonly used for " bursty" traffic typical on LANs.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 7 WAN Setup 99 Figure 48 Internet Access Setup (PPPoE) The following table describes the labels in this screen. Table 26 Internet Access Setup LABEL DESCRIPTION General Mode Select Routing (default) from the drop-down list box if your ISP allows multiple computers to share an Inter net account.
P-2602H(W)(L)-DxA Series User’s Guide 100 Chapter 7 WAN Setup VCI The valid range for the VCI is 32 to 65535 (0 to 31 is reserved for local management of A TM traffic). Enter the VCI assigned to you. IP Address IP Address This optio n is avail able if yo u select Rout ing in the Mode field.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 7 WAN Setup 101 7.5.1 Advanced Internet Access Setup T o edit your ZyXEL Device's ad vanced W AN settings, click the Advanced Setup button in the Internet Access Setup screen. The screen appears as shown.
P-2602H(W)(L)-DxA Series User’s Guide 102 Chapter 7 WAN Setup 7.6 W AN More Connections The ZyXEL Device allows you to configure more than one Internet access connection. T o configure additional Internet access connections click Network > W AN > More Connections .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 7 WAN Setup 103 Figure 50 W AN More Connections The following table describes the labels in this screen. 7.7 T raffic Redirect T raf fic redirect forwards traf fic to a backup gateway when the ZyXEL Device cannot connect to the Internet.
P-2602H(W)(L)-DxA Series User’s Guide 104 Chapter 7 WAN Setup Figure 51 T raf fic Redirect Example The following network topology allows you to avoid triangle route security issues when the backup gateway is co nnected to the LAN.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 7 WAN Setup 105 7.8 W AN Backup Setup T o configu re your ZyXEL Device’ s W AN backup, click Network > W AN > W AN Backup Setup .
P-2602H(W)(L)-DxA Series User’s Guide 106 Chapter 7 WAN Setup T imeout T y pe the number of seconds (3 recommended) for your ZyXEL Device to wait for a ping response from one of the IP addresses in the Check W AN IP Address field before timing out the re quest.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 8 LAN Setup 107 C HAPTER 8 LAN Setup This chapter describes how to configure LAN settings. 8.1 LAN Overview A Local Area Network (LAN) is a shared comm unication system to which many computers are attached.
P-2602H(W)(L)-DxA Series User’s Guide 108 Chapter 8 LAN Se tup 8.1.2 DHCP Setup DHCP (Dynamic Host Configuration Protocol , RFC 2131 and RFC 2132) allows indiv idual clients to obtain TCP/IP configuration at start-up from a server . Y ou can configure the ZyXEL Device as a DHCP server or disable it.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 8 LAN Setup 109 8.1.4 DNS Server Address Assignment Use DNS (Domain Name System) to map a domain name to its corresponding IP address and vice versa. The DNS server is extremely important because wit hout it, you must k now the IP address of a computer before you can access it.
P-2602H(W)(L)-DxA Series User’s Guide 110 Chapter 8 LAN Se tup 8.2.1.1 Private IP Addresses Every machine on the Internet must ha ve a unique address. If your network s are isolated from the Internet, for example, only between your two branch of fices, you can assign any IP addresses to the hosts without problems.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 8 LAN Setup 111 8.2.3 Multicast T raditionally , IP packets are transmitted in one of either two ways - Unicast (1 sender - 1 recipient) or Broadcast (1 sender - everybody on the network). Multicast delivers IP packets to a group of host s on the networ k - not everybody and not just 1.
P-2602H(W)(L)-DxA Series User’s Guide 112 Chapter 8 LAN Se tup Figure 54 Any IP Example The Any IP fe ature does n ot apply to a computer u sing either a dynami c IP address or a static IP address tha t is in the sa me subnet as the ZyXEL Devi ce’ s IP address.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 8 LAN Setup 113 After all the routing information is updated, the computer can access the ZyXEL Device and the Internet as if it is in th e same subnet as the ZyXEL Device. 8.3 Configuring LAN IP Click Network > LAN to open the IP screen.
P-2602H(W)(L)-DxA Series User’s Guide 114 Chapter 8 LAN Se tup Figure 56 Advanced LAN Setup The following table describes the labels in this screen. Table 31 Advanced LAN Setup LABEL DESCRIPTION RIP & Multicast Setup RIP Direction Se lect the RIP direction from None , Both , In Only and Out Only .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 8 LAN Setup 115 8.4 DHCP Setup Click Network > D HCP Setup to open this screen. Use this screen to configure the DNS server information that the ZyXEL Device sends to the DHCP client devi ces on the LAN.
P-2602H(W)(L)-DxA Series User’s Guide 116 Chapter 8 LAN Se tup 8.5 LAN Client List This table allows you to assign IP addresses on the LAN to specific individual computers based on their MAC Addresses. Every Ethernet device has a unique MAC (Med ia Access Control) addre ss.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 8 LAN Setup 117 The following table describes the labels in this screen. 8.6 LAN IP Alias IP alias allows you to partition a physical network into dif fer ent logical networks over the same Ethernet interface.
P-2602H(W)(L)-DxA Series User’s Guide 118 Chapter 8 LAN Se tup Figure 59 Physical Network & Partitioned Logical Networks Click Network > LAN > IP Alias to open the following screen. Use this screen to change your ZyXEL Device’ s IP alias settings.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 8 LAN Setup 119 RIP Direction RIP (Routing Information Protocol , RFC 1058 and RFC 1389) all ows a router to exchange routing informatio n with other routers. The RIP Direction field cont rols the sending and receiving of RIP packe ts.
P-2602H(W)(L)-DxA Series User’s Guide 120 Chapter 8 LAN Se tup.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 121 C HAPTER 9 W ireless LAN This chapter discusses how to configure the wire less network settings in your ZyXEL Device. See the appendices for more detailed informatio n about wireless networks.
P-2602H(W)(L)-DxA Series User’s Guide 122 Chapter 9 Wireless LAN Like radio stations or television channels, e ach wireless network uses a specific channel, or frequency , to send and receive information. • Every device in the same wireless networ k must use security compatible with the AP .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 123 9.2.3 User Authentication Authentication is the process of verifying whet her a wireless device is allowed to use the wireless network. Y ou can make every user log in to the wireless network before they can use it.
P-2602H(W)(L)-DxA Series User’s Guide 124 Chapter 9 Wireless LAN When you select WP A2 or WP A2-PSK in your ZyXEL Device, you ca n also select an option ( WP A compatible ) to support WP A as well.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 125 9.4 Additional Wireless T erms The following table describes wireless networ k terms and acronyms used in the ZyXEL Device.
P-2602H(W)(L)-DxA Series User’s Guide 126 Chapter 9 Wireless LAN Figure 62 Wireless LAN: General The following table describes the general wireless LAN labels in this screen. 9.5.1 No Security Select No Security to allow wireless stations to commun icate with the access points without any data encryption.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 127 Note: If you do not enable an y wireless security on your ZyXEL Device, your network is accessible to any wireless network ing device tha t is within range. Figure 63 Wireless: No Security The following table describes the labels in this screen.
P-2602H(W)(L)-DxA Series User’s Guide 128 Chapter 9 Wireless LAN Figure 64 Wireless: S tatic WEP Encryption The following table describes the wireless LAN security labels in this screen. 9.5.3 WP A(2)-PSK In order to configure and enable WP A-PSK authentication; click Network > Wireless LAN to display the General screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 129 Figure 65 Wireless: WP A(2)-PSK The following table describes the wireless LAN security labels in this screen. Table 39 Wireless: WPA(2)-PSK LABEL DESCRIPTION Security Mode Choose WP A-PSK or WP A2-PSK from the drop-down list box.
P-2602H(W)(L)-DxA Series User’s Guide 130 Chapter 9 Wireless LAN 9.5.4 WP A(2) Au thentication Screen In order to configure and enable WP A Authentication; click the Wireless LAN link under Network to display the Wir eless screen. Sele ct WP A or WP A2 from the Security list.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 131 9.5.5 Wireless LAN Advanced Setup T o configure advanced wi reless settings, click the Advanced Setup button in the General screen.
P-2602H(W)(L)-DxA Series User’s Guide 132 Chapter 9 Wireless LAN Figure 67 Advanced The following table describes the labels in this screen. Table 41 Wireless LAN: Advanced LABEL DESCRIPTION Wireless Advanced Setup RTS/CTS Threshold Enter a value between 0 and 2432.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 133 9.6 OTIST Screen Use this screen to set up and start OTIST on the ZyXEL Device in yo ur wireless network.T o open this screen, click Network > Wir eless LAN > OTIST . Figure 68 Network > Wireless LAN > OTIST The following table describes the labels in this screen.
P-2602H(W)(L)-DxA Series User’s Guide 134 Chapter 9 Wireless LAN Figure 69 Example: Wireless Client OTIST Screen T o start OTIST in the device, click St a r t in this screen. Note: Y ou must click Star t in the ZyXEL Device and in the wireless device(s) within three minutes of each other .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 135 Figure 72 OTIST : In Progres s on the Wireless Device These screens close when the tra nsfer is complete. 9.6.1 Notes on OTIST 1 If you enable OTIST in a wireless device, you see this screen each time you start the utility .
P-2602H(W)(L)-DxA Series User’s Guide 136 Chapter 9 Wireless LAN 9.7 MAC Filter T o change your ZyXEL Device ’ s MAC filter settings, click Network > Wir eless LAN > MAC Filter . The screen appears as shown. Figure 74 MAC Addres s Filter The following table describes the labels in this menu.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 137 9.8 QoS Screen The QoS screen by default allows you to au tomatically give a service a priority level. Click Network > Wi reless LAN > QoS . The following screen displays. Figure 75 Wireless LAN: QoS The following table describes the fields in this screen.
P-2602H(W)(L)-DxA Series User’s Guide 138 Chapter 9 Wireless LAN 9.8.1 Application Pr iority Configuration T o edit a WMM QoS application entry , click the edit icon under Modify .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 9 Wireless LAN 139 See Appendix 31 on page 371 for a list of commonly-used se rv ices and destination ports.
P-2602H(W)(L)-DxA Series User’s Guide 140 Chapter 9 Wireless LAN.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 10 Network Address Translation (NAT) Scr eens 141 C HAPTER 10 Network Address T ranslation (NA T) Screens This chapter discusses how to configure NA T on the ZyXEL Device.
P-2602H(W)(L)-DxA Series User’s Guide 142 Chapter 10 Network Address Translation (NAT) Scree ns 10.1.2 What NA T Does In the simplest form, NA T changes the sour ce IP address in a packet received from a subscriber (the inside local address) to anothe r (the inside global address) before forwarding the packet to the W AN side.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 10 Network Address Translation (NAT) Scr eens 143 10.1.4 NA T Application The following figure illustrates a possible NA T application, wher e three inside LANs (logical LANs using IP Alias) behind the ZyXEL Devi ce can communicate with three distinct W AN networks.
P-2602H(W)(L)-DxA Series User’s Guide 144 Chapter 10 Network Address Translation (NAT) Scree ns Port numbers do NOT change for One-to-One and Many-to-Many No Overload NA T mapping types.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 10 Network Address Translation (NAT) Scr eens 145 Figure 79 NA T General The following table describes the labels in this screen.
P-2602H(W)(L)-DxA Series User’s Guide 146 Chapter 10 Network Address Translation (NAT) Scree ns Y ou may enter a single port number or a range of port numbers to be forwarded, and the local IP address of the desired server . The port number identifies a service; for example, web service is on port 80 and FTP on port 21.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 10 Network Address Translation (NAT) Scr eens 147 10.5 Configuring Port Forwarding Note: If you do not assign a Default Serve r IP address, the ZyXEL Device discards all packet s received for port s that are not specified here o r in the remote management setup.
P-2602H(W)(L)-DxA Series User’s Guide 148 Chapter 10 Network Address Translation (NAT) Scree ns 10.5.1 Port Forwarding Rule Edit T o edit a port forwarding rule, c lick the rule’ s edit icon in the Port Forwarding screen to display the screen shown next.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 10 Network Address Translation (NAT) Scr eens 149 10.5.2 SIP ALG Some NA T routers may include a SIP Application La yer Gateway (ALG). A SIP ALG allows SIP calls to pass through NA T by examining an d translating IP addr esses embe dded in the data stream.
P-2602H(W)(L)-DxA Series User’s Guide 150 Chapter 10 Network Address Translation (NAT) Scree ns.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 151 C HAPTER 11 Vo i c e This chapter provides background informatio n on V oIP and SIP and explains how to configure your device’ s voice settings. 1 1.1 Introduction to V oIP V oIP is the sendin g of voice signals over th e Internet Protocol.
P-2602H(W)(L)-DxA Series User’s Guide 152 Chapter 11 Voice 1 1.2.1.2 SIP Service D omain The SIP service domain of the V oIP service provid er is the domain name in a SIP URI. For example, if the SIP address is 1 122334455@ V oIP-provider .com , then “V oIP-provider .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 153 1 1.2.3.1 SIP User Ag ent A SIP user agent can make and receive V oIP tele phone calls. This means that SIP can be used for peer-to-peer communications even though it is a client-server protocol.
P-2602H(W)(L)-DxA Series User’s Guide 154 Chapter 11 Voice 1 1.2.3.3 SIP Redirect Server A SIP redirect server accepts SIP requests, translates the destination address to an IP address and sends the translated IP address back to th e device that sent the request.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 155 Figure 87 SIP > SIP Settings Each field is described in the following table. Table 53 SIP > SIP Settings LABEL DESCRIPTION SIP Account Select the SIP account you want to see in this screen.
P-2602H(W)(L)-DxA Series User’s Guide 156 Chapter 11 Voice 1 1.3.1 RTP When you make a V oIP call using SIP , the R TP (Real time T ransport Pr otocol) is used to handle voice data transfer .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 157 1 1.6 PSTN Call Setup Signaling Dual-T one MultiFrequency (DTMF) signaling uses pairs of frequencies (one lower frequency and one higher frequency) to set up calls. It is also known as T ouch T one®.
P-2602H(W)(L)-DxA Series User’s Guide 158 Chapter 11 Voice 4 Y ou can continue to add, listen to, or delete tones, or yo u can hang up the receiv er when you are done.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 159 Figure 88 V oIP > SIP Settings > Advanced.
P-2602H(W)(L)-DxA Series User’s Guide 160 Chapter 11 Voice Each field is described in the following table. Table 55 VoIP > SIP Settings > Advanc ed LABEL DESCRIPTION SIP Account This field displays the SIP account you see in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 161 DTMF Mode Control how the ZyXEL Device handles the tones that your telephone makes when you push its buttons. Y ou should use the same mode your V oIP service provider uses. RFC 2833 - send the DTMF tones in RTP packets.
P-2602H(W)(L)-DxA Series User’s Guide 162 Chapter 11 Voice 1 1.10 Quality of Service (QoS) Quality of Service (QoS) refers to both a networ k's ability to deliver data with minimum delay , and the networking methods used to provide ba ndwidth for real-time mu ltimedia applications.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 163 The DSCP value determines the forwardi ng behavior , the PHB (Per -Hop Behavior), that each packet gets across the DiffServ network. Base d on the marking ru le, dif ferent kinds of traf fic can be marked for different priorities of fo rwarding.
P-2602H(W)(L)-DxA Series User’s Guide 164 Chapter 11 Voice 1 1.1 1 Phone Y ou can configure the volume, ec ho cancellation and V AD settings for each individual phone port on the ZyXEL Device. Y ou can also select which SIP account to u se for making outgoing calls.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 165 1 1.13 Analog Phone Screen Use this screen to control which SIP accounts and PSTN line each phone uses. T o access this screen, click V oIP > Phone > Analog Phone . Figure 91 Phone > Analog Phone Each field is described in the following table.
P-2602H(W)(L)-DxA Series User’s Guide 166 Chapter 11 Voice 1 1.14 Advanced Analog Phone Setup Screen Use this screen to edit advanced settings for eac h phone port. T o access this screen, click Advanced Setup in V oIP > Phone > Analog Phone .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 167 1 1.14.1 Common Phone Settings Screen Use this screen to activate and deactivate im mediate dialing. T o acces s this screen, click Vo I P > Phone > Common . Figure 93 Phone > Common Each field is described in the following table.
P-2602H(W)(L)-DxA Series User’s Guide 168 Chapter 11 Voice 1 1.15 Supplement ary Phone Services Overview Supplementary services such as call hold, call waiting, call tran sfer , … are generally available from your V oIP service provider .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 169 1 1.15.2.1 European Call Hold Call hold allows you to put a call ( A ) o n hold by pressing th e flash key . If you have anothe r call, press the flash key an d then “2” to switch back and forth between caller A and B by putting either one on hold.
P-2602H(W)(L)-DxA Series User’s Guide 170 Chapter 11 Voice 2 When you hear the dial tone, dial “* 98#” followed by the number to which you want to transfer the call. to operate the Intercom. 3 After you hear the ring signal or the sec ond party answers it, hang up the phone.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 171 1 1.15.3.2 USA Call W aiting This allows you to place a call on hold while you answer ano t her incoming call on the same telephone (directory) number . If there is a second call to your t elephon e number , you will hear a call waiting tone.
P-2602H(W)(L)-DxA Series User’s Guide 172 Chapter 11 Voice Figure 94 V oIP > Phone > Region Each field is described in the following table. 1 1.17 Speed Dial Speed dial provides shortcuts for dialin g frequently used (V oIP) phone numbers. 1 1.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 173 1 1.18 Speed Dial Screen Y ou have to create speed-dial entries if you want to make peer-to-peer calls or call SIP numbers that use letters. Y ou can also create speed-dial entries for frequently-used SIP phone numbers.
P-2602H(W)(L)-DxA Series User’s Guide 174 Chapter 11 Voice 1 1.19 Incoming Call Policy Screen Use this screen to maintain rules for handlin g inco ming calls. Y ou can block , redirect, or accept them. T o access this screen, click V oIP > Phone Book > Incoming Call Poli cy .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 175 Figure 96 Phone Book > Incoming Call Policy Y ou can create two sets of call-forwarding rules. Each one is stored in a call-forwarding table. Each field is described in the following table.
P-2602H(W)(L)-DxA Series User’s Guide 176 Chapter 11 Voice 1 1.20 PSTN Line Screen (“L” models only) Use this screen to set up the PSTN line you us e to make regular phone calls. T o access this screen, click V oIP > PST N Line > General .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 11 Voice 177 Figure 97 PSTN Line > General Each field is described in the following table. Table 65 PSTN Line > General LABEL DESCRIPTION PSTN Li.
P-2602H(W)(L)-DxA Series User’s Guide 178 Chapter 11 Voice.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 12 Phone Usage 179 C HAPTER 12 Phone Usage This chapter describes how to use a phone conn ected to your ZyXEL Device for basic tasks. 12.1 Dialing a T elephone Number The PHONE LED turns green when your SIP account is registered.
P-2602H(W)(L)-DxA Series User’s Guide 180 Chapter 12 Phone Usage 12.5 Auto Firmware Upgrade During auto-provisioning, the ZyXEL Device checks to see if there is a newer firmware version. If newer firmware is available, the ZyXEL De vice play s a recording w hen you pi ck up your phone’ s handset.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 13 Firewalls 181 C HAPTER 13 Firewalls This chapter gives some back ground information on firewa lls and introduces the ZyXEL Device firewall. 13.1 Firewall Overview Originally , the term fir ewall referred to a construction techni que designed to prevent the spread of fire from one room to another .
P-2602H(W)(L)-DxA Series User’s Guide 182 Chapter 13 Firewalls 13.2.2 Application-level Firewalls Application-level firewalls restrict access by serv ing as proxies for e xternal servers.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 13 Firewalls 183 • The LAN (Local Area Network) port attache s to a network of computers, which ne eds security from the outside world. These computer s will have access to Internet services such as e-mail, FTP , and the W orld W ide W e b.
P-2602H(W)(L)-DxA Series User’s Guide 184 Chapter 13 Firewalls 13.4.2 T ypes of DoS Atta cks There are four types of DoS attacks: 1 Those that exploit bugs in a TCP/IP implementation. 2 Those that exploit weaknesses in the TCP/IP specification. 3 Brute-force attacks that flood a network with useless data.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 13 Firewalls 185 Under normal circumstances, the applica tion that initiates a session sends a SYN (synchronize) packet to the receiving server . The receiver sends back an ACK (acknowledgment) packet and its own SYN, and then the in itiator responds with an ACK (acknowledgment).
P-2602H(W)(L)-DxA Series User’s Guide 186 Chapter 13 Firewalls Figure 101 Smurf Attack 13.4.2.1 ICMP V ulnerability ICMP is an error -reporting protocol that works in concert with IP . The following ICMP types trigger an alert: 13.4.2.2 Illegal Commands (NetBIOS and SMTP) The only legal NetBIOS commands are the following - all others are illegal.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 13 Firewalls 187 13.4.2.3 T raceroute T raceroute is a utility used to determine th e path a packet takes between two endpoints. Sometimes when a packet filter firewall is conf igured incorrectly an at tacker can traceroute the firewall gaining knowledge of the network topology inside the firewall.
P-2602H(W)(L)-DxA Series User’s Guide 188 Chapter 13 Firewalls The previous figure shows the ZyXEL Device’ s default firewall rules in action as well as demonstrates how stateful inspection works. User A can initiate a T elnet session from within the LAN and responses to this request are allowe d.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 13 Firewalls 189 • Allow certain types of traffic from the In ternet to specific hosts on the LAN. • Allow access to a W eb server to everyone but competitors. • Restrict use of certain protocols, such as T elnet, to authoriz ed us ers on the LAN.
P-2602H(W)(L)-DxA Series User’s Guide 190 Chapter 13 Firewalls A similar situation exists for ICMP , except that the ZyXEL Device is even more restrictive.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 13 Firewalls 191 • Encourage your co mpany or organization to develop a comprehen sive security plan. Good network administration takes into ac count what hackers can do and prepares against attacks. The best defense against hack ers and crackers is information.
P-2602H(W)(L)-DxA Series User’s Guide 192 Chapter 13 Firewalls 13.7.1.1 When T o Use Filtering • T o bloc k/allow LAN packet s by their MAC addresses.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 193 C HAPTER 14 Firewall Configuration This chapter shows you how to enable and configure t he ZyXEL Device firewall. 14.1 Access Methods The web configurator is, by far , the most co mprehensive firewall configuration tool your ZyXEL Device has to offer .
P-2602H(W)(L)-DxA Series User’s Guide 194 Chapter 14 Firewall Configuration Note: If you configure firewall rules wit hout a good underst anding of how they work, you might inadvertently introduce securi ty risks to the f irewall and to the protected network.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 195 4 Does a rule that allows Internet users acces s to resources on the LAN create a security vulnerability? For example, if FTP ports (TCP 20, 21) are al lowed from the Internet to t he LAN, Internet users may be able to connect to computers with running FTP servers.
P-2602H(W)(L)-DxA Series User’s Guide 196 Chapter 14 Firewall Configuration 14.4.1 LAN to W AN Rules The default rule for LAN to W AN traffic is that all users on the LAN are allowed non- restricted access to the W AN.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 197 The following table describes the labels in this screen. 14.6 Firewall Rules Summary Note: The ordering of your rule s is very import ant as rules are applie d in turn. Refer to Section 13.
P-2602H(W)(L)-DxA Series User’s Guide 198 Chapter 14 Firewall Configuration Figure 104 Firewall Rules The following table describes the labels in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 199 14.6.1 Configuring Firewall Rules Refer to Section 13.1 on page 181 for more information. In the Rules screen, select an index number and click Add or click a rule’ s Edit icon to display this screen and refe r to the following table for information on the l abels.
P-2602H(W)(L)-DxA Series User’s Guide 200 Chapter 14 Firewall Configuration Figure 105 Firewall: Edit Rule.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 201 The following table describes the labels in this screen. Table 72 Firewall: Edit Rule LABEL DESCRIPTION Active Select this option to ena ble this firewall rule.
P-2602H(W)(L)-DxA Series User’s Guide 202 Chapter 14 Firewall Configuration 14.6.2 Customized Services Configure customized services and port number s not predefined by the ZyXEL Device. For a comprehensive list of port numbers and services, visit the IANA (Internet Assigned Number Authority) website.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 203 Figure 107 Firewall: Configure Customized Services The following table describes the labels in this screen. 14.7 Example Firewall Rule The following Internet firewa ll rule example allows a hypot hetical “MyService” connection from the Internet.
P-2602H(W)(L)-DxA Series User’s Guide 204 Chapter 14 Firewall Configuration Figure 108 Firewall Example: Rules 3 In the Rules screen, select the index number after that you want to add the rule. For example, if you select “6”, your new rule b ecomes number 7 and the previous rule 7 (if there is one) becomes rule 8.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 205 Figure 1 10 Firewall Example: Edit Rule: Destination Address 9 Use the Add >> and Remove buttons between A vailable Services and Selected Services list boxes to configure it as follows.
P-2602H(W)(L)-DxA Series User’s Guide 206 Chapter 14 Firewall Configuration Figure 1 1 1 Firewall Example: Edit Rule: Select Customized Services On completing the configuration procedure for this Internet firewall rule, the Rules screen should look like the following.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 207 Figure 1 12 Firewall Example: Rules: MyService 14.8 DoS Thresholds For DoS attacks, the ZyXEL Device uses threshol ds to determine when to drop sessions that do not become fully established.
P-2602H(W)(L)-DxA Series User’s Guide 208 Chapter 14 Firewall Configuration Y ou should make any chan ges to the threshold values b efore you continue configu ring firewall rules.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 14 Firewall Configurat ion 209 14.8.3 Configuring Firewall Thresholds The ZyXEL Device also sends alerts whenever TCP Maximum Incomplete is exceeded. The global values specified for the threshold an d timeout apply to all TCP connections.
P-2602H(W)(L)-DxA Series User’s Guide 210 Chapter 14 Firewall Configuration Maximum Incomplete Low This is the number of existing half-open sessions that cau ses the firewall to stop deleting half-open sessions.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 15 Content Filtering 211 C HAPTER 15 Content Filtering This chapter covers how to configure content filtering. 15.1 Content Filtering Overview Internet content filtering allows you to create and enforce Internet access policies tailored to your needs.
P-2602H(W)(L)-DxA Series User’s Guide 212 Chapter 15 Content Filtering The following table describes the labels in this screen. 15.3 Configuring the Schedule T o set the days and times for the ZyXEL De vice to perform content filtering, click Security > Content Filter > Schedule .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 15 Content Filtering 213 The following table describes the labels in this screen. 15.4 Configuring T rusted Computers T o exclude a range of users on the LAN fro m content filtering on your ZyXEL Device, click Security > Content Filter > Tr u s t e d .
P-2602H(W)(L)-DxA Series User’s Guide 214 Chapter 15 Content Filtering.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 16 Introduction to IPSec 215 C HAPTER 16 Introduction to IPSec This chapter introduces the basics of IPSec VPNs. 16.1 VPN Overview A VPN (V irtual Private Network) provides sec ure communications between sites without the expense of leased site-to-site lines.
P-2602H(W)(L)-DxA Series User’s Guide 216 Chapter 1 6 Introduction t o IPSec Figure 1 17 Encryption and Decryption 16.1.3.2 Dat a Confidentiality The IPSec sender can encrypt packets befo re transmitting them across a network.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 16 Introduction to IPSec 217 Figure 1 18 IPSec Architecture 16.2.1 IPSec Algorithms The ESP (Encapsulating Security Payload) Protocol (RFC 2406) an d A.
P-2602H(W)(L)-DxA Series User’s Guide 218 Chapter 1 6 Introduction t o IPSec Figure 1 19 T ransport and T unnel Mode IPSec Encapsulation 16.3.1 T ransport Mode Tr a n s p o r t mode is used to pro tect upper layer prot ocols and only af fects the data in the IP packet.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 16 Introduction to IPSec 219 NA T is incompatible with the AH protocol in both Tr a n s p o r t and T unnel mode. An IPSec VPN using the AH protocol digitally sig ns the outbound packet, both data payload and headers, with a hash value appe nded to the pack et.
P-2602H(W)(L)-DxA Series User’s Guide 220 Chapter 1 6 Introduction t o IPSec.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 221 C HAPTER 17 VPN Screens This chapter introduces the VPN screens. See Chapter 24 on page 295 for information on viewing logs and th e appendix for IPSec log descriptions.
P-2602H(W)(L)-DxA Series User’s Guide 222 Chapter 17 VP N Screens 17.3 My IP Address My IP Address is the W AN IP address of th e ZyXEL Device. The ZyXEL Device has to rebuild the VPN tunnel if the My IP Address changes after setup. The following applies if this field is configured as 0.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 223 17.4 Secure Gateway Address Secure Gateway Address is the W AN IP address or domain name of the remote IPSec router (secure gateway). If the remote secure gateway has a static W AN IP address, enter it in the Secure Gateway Address field.
P-2602H(W)(L)-DxA Series User’s Guide 224 Chapter 17 VP N Screens Figure 121 VPN Setup The following table describes the fields in this screen. T able 81 VPN Setup LABEL DESCRIPTION No. This is the VPN policy index number . Click a number to edit VPN policies.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 225 17.6 Keep Alive When you initiate an IPSec tunnel with keep alive enabled, the ZyX EL Device automatically renegotiates the tunnel wh en the IPSec SA lifetime period expires (see Section 17.
P-2602H(W)(L)-DxA Series User’s Guide 226 Chapter 17 VP N Screens 17.7 VPN, NA T , and NA T T raversal NA T is incompatible with the AH protocol in both transport and tunnel mode.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 227 Y* - This is supported in the ZyXEL Device if you enable NA T traversal. 17.8 Remote DNS Server In cases where you want to use domain names to access Intranet servers on a remote network that has a DNS server , you must identify that DNS server .
P-2602H(W)(L)-DxA Series User’s Guide 228 Chapter 17 VP N Screens Regardless of the ID type and content configur ation, the ZyXEL Device does not allow you to save multiple active rules with overlap ping local and remote IP addresses. W ith main mode (see Section 17.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 229 17.9.1 ID T ype and Content Examples T wo IPSec routers must have matching ID type and content configuration in order to set up a VPN tunnel. The two ZyXEL Devices in this example ca n complete negotiation and establish a VPN tunnel.
P-2602H(W)(L)-DxA Series User’s Guide 230 Chapter 17 VP N Screens Figure 124 Edit VPN Policies The following table describes the fields in this screen. T able 87 Edit V PN Policies LABEL DESCRIPTION IPSec Setup Active Select this check box to activate this VPN policy .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 231 NA T T raversal This function is availab le if the VPN protocol is ESP . Select this check box if you want to set up a VPN tunnel when there are NA T routers between the ZyXEL Devi ce and remo te IPSec router .
P-2602H(W)(L)-DxA Series User’s Guide 232 Chapter 17 VP N Screens Remote Remote IP addresses must be static and correspond to the remote IPSec router's configured local IP addresses. The remote fields do not apply when th e Secure Gateway IP Address field is configured to 0.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 233 Peer ID T ype Select IP to identify the remote IPSec router by its IP address. Select DNS to identify the remote IPSec router by a domain name. Select E-mail to identify the remote IPSec router by an e-mail address.
P-2602H(W)(L)-DxA Series User’s Guide 234 Chapter 17 VP N Screens 17.12 IKE Phases There are two phases to every IKE (Internet Key Exchange) ne gotiation – phase 1 (Authentication) and ph ase 2 (Key Exchange). A phase 1 exchange establishes an IKE SA and the second one uses that SA to negotiate SAs for IPSe c.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 235 • Choose an encryption algorithm. • Choose an authentication algorithm. • Choose a Dif fie-Hellman public-key cry ptography key group ( DH1 or DH2 ) . • Set the IKE SA lifetime.
P-2602H(W)(L)-DxA Series User’s Guide 236 Chapter 17 VP N Screens 17.12.2 Diffie-Hellman (DH) Key Groups Diffie-Hellman (DH) is a publi c -key cryptography protocol tha t allows two parties to establish a shared secret over an unsecured communications channel.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 237 Figure 126 Advanced VPN Policies The following table describes the fields in this screen. T able 88 Advanced VPN Policies LABEL DESCRIPTION VPN - IKE Protocol Enter 1 for ICMP , 6 for TCP , 1 7 for UDP , etc.
P-2602H(W)(L)-DxA Series User’s Guide 238 Chapter 17 VP N Screens Negotiati on Mode Select Main or Aggressive from the drop-down list box. Multiple SAs connecting through a secure gateway must have the same negotiation mode . Pre-Shared Key T ype your pre-shared key in this field.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 239 17.14 Manual Key Setup Manual key managemen t is useful if you have problems with IKE key mana gement. 17.14.1 Security Parameter Index (SPI) An SPI is used to distinguish dif ferent SAs te rminating at the same de stination and using the same IPSec protocol.
P-2602H(W)(L)-DxA Series User’s Guide 240 Chapter 17 VP N Screens Figure 127 VPN: Manual Key The following table describes the fields in this screen. Table 89 VPN: Manual Key LABEL DESCRIPTION IPSec Setup Active Select this check box to activate this VPN policy .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 241 DNS Server (for IPSec VPN) If there is a private DNS server that se rvices the VPN, type its IP address here. The ZyXEL Device a ssigns this additional DNS server to the Zy XEL Device 's DHCP clients that have IP addresses in this IPSec rule's range of lo cal addresses.
P-2602H(W)(L)-DxA Series User’s Guide 242 Chapter 17 VP N Screens 17.16 V iewing SA Monitor Click Security , VPN and Monitor to open the SA Mon itor screen as shown. Use this scree n to display and ma nage active VPN co nnections . A Security Association (SA) is the group of se cu rity settings related to a specific VPN tunnel.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 243 When there is outbound traffic b ut no inbound tr affic, the SA times out automatically after two minutes. A tunnel with no outb ound or inbound traf fic is "idle" and does not timeout until the SA lifetime period expires.
P-2602H(W)(L)-DxA Series User’s Guide 244 Chapter 17 VP N Screens 17.17 Configuring Global Setting T o change your ZyXEL Devi ce’ s global settings, click VPN and then Global Setting . The screen appears as shown. Figure 129 VPN: Global Setting The following table describes the fields in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 245 Figure 130 T elecommuters Sharing One VPN Rule Example 17.18.2 T elecommuters Usin g Unique VPN Rules Example In this example the te.
P-2602H(W)(L)-DxA Series User’s Guide 246 Chapter 17 VP N Screens Figure 131 T elecommuters Using Uniq ue VPN Rules Example Table 93 T elecommuters Using Unique VPN Rules Example T ELECOMMUTERS HEADQUARTERS All T ele commuter Rules: All Headquarters Rules: My IP Address 0.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 17 VPN Screens 247 17.19 VPN and Remote Management If a VPN tunnel uses T elnet, FTP , WWW , then you should co nfigure remote management ( Remote Management ) to allow access for that service.
P-2602H(W)(L)-DxA Series User’s Guide 248 Chapter 17 VP N Screens.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 18 Static Rout e 249 C HAPTER 18 S t atic Route This chapter shows you how to configure static routes for your ZyXEL Device. 18.1 S t atic Route Each remote node specifies only the network to which the gateway is di rectly connected, and the ZyXEL Device has no know ledge of the networks beyo nd.
P-2602H(W)(L)-DxA Series User’s Guide 250 Chapter 18 Static Route Figure 133 S tatic Route The following table describes the labels in this screen. 18.2.1 S t atic Route Edit Select a static route index numb er and click Edit . The screen shown next appears.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 18 Static Rout e 251 Figure 134 S tatic Route Edit The following table describes the labels in this screen. T able 95 S tatic Route Edit LABEL DESCRIPTION Active This field allows you to activa te/deactivate this st atic route.
P-2602H(W)(L)-DxA Series User’s Guide 252 Chapter 18 Static Route.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 19 Bandwidth Managemen t 253 C HAPTER 19 Bandwid th Management This chapter contains information about configuri ng bandwidth management, editing rules and viewing the ZyXEL Device’ s bandwidth management logs.
P-2602H(W)(L)-DxA Series User’s Guide 254 Chapter 19 Bandwidth Management The following figure shows LAN subnets. Y ou could configure one ban dwidth class for subnet A and another for subnet B . Figure 135 Subnet-based Ba ndwidt h Management Example 19.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 19 Bandwidth Managemen t 255 19.5.2 Fairness-based Scheduler The ZyXEL Device divides bandwidth equally among bandwidth classes when using the fairness-based scheduler; thus preventing one ba ndwidth class from using all of the interface’ s bandwidth.
P-2602H(W)(L)-DxA Series User’s Guide 256 Chapter 19 Bandwidth Management 19.6.2 Maximize Ba ndwid th Usage Example Here is an example of a ZyXEL Device that has maximize bandwidth usage enabled on an interface. The following table shows each ba nd width class’ s bandwidth budget.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 19 Bandwidth Managemen t 257 • Research requires more bandwidth but only gets its budgeted 2048 kbps because all of the unbudgeted and unu sed bandwidth goes to the higher priority sales and marketing classes.
P-2602H(W)(L)-DxA Series User’s Guide 258 Chapter 19 Bandwidth Management Enable bandwidth manage ment on an interface and set the maximum allo wed bandwidth for that interface. Figure 136 Bandwidth Ma nagement: Summary The following table describes the labels in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 19 Bandwidth Managemen t 259 19.8 Bandwid th Management Rule Setup Y ou must use the Bandwidth Management Summary screen to enable bandwidth management on an interface before yo u can configure rules for that interface.
P-2602H(W)(L)-DxA Series User’s Guide 260 Chapter 19 Bandwidth Management 19.8.1 Rule Configuration Click the Edit icon or User define in the Service field to configure a bandwidth mana gement rule. Use bandwidth rules to allocate specific amounts of bandwidth capacity (bandw idth budgets) to specific applications and/or subnets.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 19 Bandwidth Managemen t 261 See Appendix F on page 3 71 for a list of commonly-used services. The following table describes the labels in this screen.
P-2602H(W)(L)-DxA Series User’s Guide 262 Chapter 19 Bandwidth Management 19.9 Bandwid th Monitor T o view the ZyXEL Device’ s bandwidth usage, click Ad vanced > Bandwidth MGMT > Monitor . The screen appears as shown. Select an interface from the drop-down list box to view the bandwidth usage of its bandwidt h rule s.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 20 Dynamic DNS Setup 263 C HAPTER 20 Dynamic DNS Setup This chapter discusses how to configure your ZyXEL Device to use Dynamic DNS.
P-2602H(W)(L)-DxA Series User’s Guide 264 Chapter 2 0 Dynamic DNS Setup Figure 140 Dynamic DNS The following table describes th e fields in this screen. Table 104 Dynamic DNS LABEL DESCRIPTION Dynamic DNS Setup Active Dynamic DNS Select this check box to use dynamic DNS.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 20 Dynamic DNS Setup 265 Dynamic DNS server auto detect IP Address Select this option only when there are one or more NA T routers betwe en the ZyXEL Device and the DDNS server .
P-2602H(W)(L)-DxA Series User’s Guide 266 Chapter 2 0 Dynamic DNS Setup.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 21 Remote M anagement Configuratio n 267 C HAPTER 21 Remote Management Configuration This chapter provides information on config uring remote management.
P-2602H(W)(L)-DxA Series User’s Guide 268 Chapter 21 Remote Ma nagement Configuration • The IP address in the Secured Client IP field does not match th e client IP address. If it does not match, the ZyXEL Device will disconnect the session immediately .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 21 Remote M anagement Configuratio n 269 The following table describes the labels in this screen. 21.3 T elnet Y ou can configure your ZyXEL Device for remote T elnet access as shown next. The administrator uses T elnet from a compute r on a remote network to access the ZyXEL Device.
P-2602H(W)(L)-DxA Series User’s Guide 270 Chapter 21 Remote Ma nagement Configuration Figure 143 Remote Mana gement: T elnet The following table describes the labels in this screen. 21.5 Configuring FTP Y ou can upload and download the ZyXEL Devi ce’ s firmware and configuration files us ing FTP , please see Section 25.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 21 Remote M anagement Configuratio n 271 Figure 144 Remote Mana gement: FTP The following table describes the labels in this screen. 21.6 SNMP Simple Network Management Protocol (SNM P) i s a protocol u sed for exch anging management information b etween network devices.
P-2602H(W)(L)-DxA Series User’s Guide 272 Chapter 21 Remote Ma nagement Configuration Figure 145 SNMP Managemen t Model An SNMP managed network consis ts of two main types of comp onent: agen ts and a man ager . An agent is a management software module that resi des in a managed device (the ZyXEL Device).
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 21 Remote M anagement Configuratio n 273 21.6.2 SNMP T raps The ZyXEL Device will send traps to the SNMP manager when any on e of the following events occurs: 21.6.3 Configuring SNMP T o chan ge your ZyXEL Device’ s SNMP settings, click Advanced > Remote MGMT > SNMP .
P-2602H(W)(L)-DxA Series User’s Guide 274 Chapter 21 Remote Ma nagement Configuration Figure 146 Remote Mana gement: SNMP The following table describes the labels in this screen.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 21 Remote M anagement Configuratio n 275 21.7 Configuring DNS Use DNS (Domain Name System) to map a domain name to its corresponding IP address and vice versa. Refer to Chapter 8 on page 107 for background information.
P-2602H(W)(L)-DxA Series User’s Guide 276 Chapter 21 Remote Ma nagement Configuration If an outside user attempts to probe an unsupp orted port on your ZyXEL Device, an ICMP response packet is automatically returned. This allows the ou tside user to know the ZyXEL Device exists.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 22 Universa l Plug-and-Play (UPnP) 277 C HAPTER 22 Universal Plug-and-Play (UPnP) This chapter introduces the UPnP feature in the web configura tor .
P-2602H(W)(L)-DxA Series User’s Guide 278 Chapter 22 Univer sal Plug-and-Play (UPnP) 22.1.3 Cautions with UPnP The automated nature of NA T traversal applications in establishing their own services and opening firewall ports ma y present network security issues.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 22 Universa l Plug-and-Play (UPnP) 279 The following table describes th e fields in this screen. 22.3 Inst alling UPnP in Windows Example This section shows ho w to install UPnP in W indows Me and W indows XP .
P-2602H(W)(L)-DxA Series User’s Guide 280 Chapter 22 Univer sal Plug-and-Play (UPnP) Figure 150 Add/Remove Programs: Wind ows Setup: Communication 3 In the Communications window , select the Universal Plug and Play check box in th e Components selection box.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 22 Universa l Plug-and-Play (UPnP) 281 Inst alling UPnP in Windows XP Follow the steps below to install the UPnP in Windows XP . 1 Click St a r t and Control Panel . 2 Double-click Network Connections .
P-2602H(W)(L)-DxA Series User’s Guide 282 Chapter 22 Univer sal Plug-and-Play (UPnP) Figure 154 Networking Services 6 Click OK to go back to the W indows Optional Networking Component Wizard window and click Next . 22.4 Using UPnP in Windows XP Example This section shows yo u how to use the UPnP feature in W indows XP .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 22 Universa l Plug-and-Play (UPnP) 283 Figure 155 Network Connections 3 In the Internet Connection Properties window , click Settings to see the port mappings there were automatically created.
P-2602H(W)(L)-DxA Series User’s Guide 284 Chapter 22 Univer sal Plug-and-Play (UPnP) 4 Y ou may edit or delete the port mappings o r click Add to manually add port mappings.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 22 Universa l Plug-and-Play (UPnP) 285 Figure 159 System T ray Icon 7 Double-click on the icon to display yo ur curr ent Internet co nnection sta tus.
P-2602H(W)(L)-DxA Series User’s Guide 286 Chapter 22 Univer sal Plug-and-Play (UPnP) Figure 161 Network Connections 4 An icon with the description for e ach UPnP-enabled device displays unde r Local Network . 5 Right-click on the icon for your ZyXEL Device an d select Invoke .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 22 Universa l Plug-and-Play (UPnP) 287 Figure 162 Network Connections: My Network Places 6 Right-click on the icon for your ZyXEL Device and select Pr operties . A properties window displays with basic info rmation about the ZyXEL Device.
P-2602H(W)(L)-DxA Series User’s Guide 288 Chapter 22 Univer sal Plug-and-Play (UPnP).
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 23 System 289 C HAPTER 23 System Use this screen to configure the ZyXEL Device’ s time and date settings. 23.1 General Setup and System Name General Setup contains administrative and system-related information.
P-2602H(W)(L)-DxA Series User’s Guide 290 Chapter 23 Syst em Figure 164 System General Setu p The following table describes the labels in this screen. T able 1 13 System General Setup LABEL DESCRIPTION General Setup System Name Choose a descriptive name for identificatio n purposes.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 23 System 291 23.2 T ime Setting T o chan ge your ZyXEL Device’ s time and date, click Maintenance > System > T ime Setting . The screen appears as shown. Use this screen to configure the ZyXEL Device’ s time based on your local time zone.
P-2602H(W)(L)-DxA Series User’s Guide 292 Chapter 23 Syst em New T ime (hh:mm:ss) This field displays the last updated ti me from the time server or t he last time configured manually . When you set Time and Date Setup to Manual , enter the new time in this field and then click Apply .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 23 System 293 End Date Configure the day and time when Dayl ight Saving T ime ends if yo u selected Enable Daylight Saving . The o'clock field uses the 24 hour format. Here are a couple of examples: Daylight Saving Time ends in the United S tates on the last Sunday of October .
P-2602H(W)(L)-DxA Series User’s Guide 294 Chapter 23 Syst em.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 24 Logs 295 C HAPTER 24 Logs This chapter contains inform ation about configuring genera l log settings and viewing the ZyXEL Device’ s logs. Refer to the append ix for example log message explanations.
P-2602H(W)(L)-DxA Series User’s Guide 296 Chapter 24 Logs Figure 166 V iew Log The following table describes the fields in this screen. 24.3 Configuring Log Settings Use the Log Settings screen to c.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 24 Logs 297 Alerts are e-mailed as soon as they happen. Logs may be e-ma iled as soon as the log is full. Selecting many alert and/or log categories (especially Access Control ) may result in many e- mails being sent.
P-2602H(W)(L)-DxA Series User’s Guide 298 Chapter 24 Logs Mail Subject T ype a title that you want to be in the subject line of the log e-mail message that the ZyXEL Device sends. Not all ZyXEL Device models have this field. Send Log to The ZyXEL Device sen ds logs to the e-mail addre ss specified in this field.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 24 Logs 299 24.4 SMTP Error Messages If there are difficulties in sending e-mail the following error message appears. “SMTP action request failed. ret= ??". The “??"are described in the following table.
P-2602H(W)(L)-DxA Series User’s Guide 300 Chapter 24 Logs Figure 168 E-mail Log Example Subject: Firewall Alert From Date: Fri, 07 Apr 2000 10:05:42 From: user@zyxel.com To: user@zyxel.com 1| Apr 7 00 |From:192.168.1.1 To:192.168.1.255 |default poli cy |forward | 09:54:03 |UDP src port:0052 0 dest port:00520 |<1,00> | 2|Apr 7 00 |From:192.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 25 Tools 301 C HAPTER 25 To o l s This chapter explains how to upload new firm ware, manage configuration files and restart your ZyXEL Device. Note: Do not interrupt the file transfer p rocess as this may PERMANENTL Y DAMAGE YOUR ZyXEL Device.
P-2602H(W)(L)-DxA Series User’s Guide 302 Chapter 25 Tools This is a sample FTP session saving the cu rrent configuration to the computer file “ config.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 25 Tools 303 Figure 169 Firmware Upgr ade The following table describes the labels in this screen. Note: Do NOT turn off th e ZyXEL Device while firmware upload is in pro gress! After you see the Firmware Upload in Pr ogr ess screen, wait two minutes before logging into the ZyXEL Device again.
P-2602H(W)(L)-DxA Series User’s Guide 304 Chapter 25 Tools The ZyXEL Device automatically restarts in this time causing a temporary network disconnect.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 25 Tools 305 Figure 173 Configuration 25.5.1 Backup Configuration Backup Configuration allows you to back up (save) the ZyXE L Device’ s current configuration to a file on your co mputer .
P-2602H(W)(L)-DxA Series User’s Guide 306 Chapter 25 Tools After you see a “restore configuration successf ul” scree n, you must then wait one minute before logging into th e ZyXEL Device again. Figure 174 Configuration Upload Successfu l The ZyXEL Device automatically restarts in this time causing a temporary network disconnect.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 25 Tools 307 25.5.3 Reset to Factory Default s Click the Reset button to clear all user-entered conf iguration information and return the ZyXEL Device to its factory defaults . The following warning screen appears.
P-2602H(W)(L)-DxA Series User’s Guide 308 Chapter 25 Tools 25.7 Using FTP or TFTP to Back Up Configuration This section covers how to use FTP or TFTP to save your device’ s config uration file to your computer . 25.7.1 Using the FTP Comman ds to Back Up Configuration 1 Launch the FTP client on your computer .
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 25 Tools 309 25.7.3 Configuration Backup Using GUI-based FTP Client s The following table describes some of the commands that you may see in GUI-based FTP clients.
P-2602H(W)(L)-DxA Series User’s Guide 310 Chapter 25 Tools 25.7.5 TFTP Command Co nfiguration Backup Example The following is an example TFTP command: tftp [-i] host get rom-0 config.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 25 Tools 311 Note: W ARNING! Do not interrupt the file transfer process as this may PERMANENTL Y DAMAGE YOUR device. When the Restore Configuration process is complete, the device will automatically rest art.
P-2602H(W)(L)-DxA Series User’s Guide 312 Chapter 25 Tools 0 config.rom” transfers the configuration file on the device to your computer and renames it “config.rom.” See earlier in this chapter fo r more information on filename conventions. 7 Enter “quit” to exit the ftp prompt.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 25 Tools 313 Note that the telnet connection must be active an d the device in CI mode before and during the TFTP transfer . For details on TFTP commands (see following example), please consult the documentation of your TFTP client program.
P-2602H(W)(L)-DxA Series User’s Guide 314 Chapter 25 Tools.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 26 Diagnostic 315 C HAPTER 26 Diagnostic These read-only screens display information to help you identify problems with the ZyXEL Device. 26.1 General Diagnostic Click Maintenance > Diagnostic to open the screen shown next.
P-2602H(W)(L)-DxA Series User’s Guide 316 Chapter 26 Diagnostic Figure 184 Diagnostic: DSL Line The following table describes th e fields in this screen. Table 124 Diagnostic: DSL Line LABEL DESCRIPTION A TM S tatus Cli ck this button to view your DSL connection’s Asynchronous T ransfer Mode (A TM) statistics.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 26 Diagnostic 317 DSL Line S tatus Cli ck this button to view stat istics about the DSL connections. noise margin downstream is th e signal to noise ratio for the downstre am part of the connection (coming into the ZyXEL Device from the ISP).
P-2602H(W)(L)-DxA Series User’s Guide 318 Chapter 26 Diagnostic.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 27 Troubleshooting 319 C HAPTER 27 T roubleshooting This chapter covers potential proble ms and the corresponding remedies.
P-2602H(W)(L)-DxA Series User’s Guide 320 Chapter 27 Troublesh ooting 27.3 Problems with the W AN Table 127 Troubleshooting the WAN PROBLEM CORRECTIVE ACTION The DSL light is off. Check the telephone wire and connection s between the ZyXEL Device DSL port and the wall jack.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 27 Troubleshooting 321 27.4 Problems Accessi ng the ZyXEL Device 27.4.1 Pop-up Windows, Ja vaScript s and Java Permissions In order to use the web configurator you need to allow: • W eb browser pop-up windows from y our device.
P-2602H(W)(L)-DxA Series User’s Guide 322 Chapter 27 Troublesh ooting • Java permissions (enabled by default). Note: Internet Explorer 6 screens are used here. Screens for o ther Internet Explorer versions may va ry . 27.4.1.1 Internet Explorer Pop-up Blockers Y ou may have to disable pop-up blocking to log into your device.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 27 Troubleshooting 323 Figure 186 Intern et Options 3 Click Apply to save this setting. 27.4.1.1.2 Enable pop-up Blockers with Exceptions Alternatively , if you only want to allow pop-up windows from yo ur device, see the following steps.
P-2602H(W)(L)-DxA Series User’s Guide 324 Chapter 27 Troublesh ooting Figure 187 Internet Options 3 T ype the IP address of your device (the we b page that you do not want to have blocked) with the prefix “http://”. For example, http://192.168.1.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 27 Troubleshooting 325 Figure 188 Pop-up Blocker Settings 5 Click Close to return to the Privacy screen. 6 Click Apply to save this setting. 27.4.1.2 JavaScript s If pages of the web configura tor do not display properly in Intern et Explorer , check that JavaScripts are allowed.
P-2602H(W)(L)-DxA Series User’s Guide 326 Chapter 27 Troublesh ooting Figure 189 Internet Options 2 Click the Custom Level... button. 3 Scroll down to Scripting . 4 Under Active scripting make sure that Enable is selected (the default). 5 Under Scripting of Java applets make sure that Enable is sele cted (the default).
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 27 Troubleshooting 327 Figure 190 Security Settings - Java Scripting 27.4.1.3 Java Permissions 1 From Internet Explorer , click To o l s , Internet Options and then the Security tab. 2 Click the Custom Level.
P-2602H(W)(L)-DxA Series User’s Guide 328 Chapter 27 Troublesh ooting Figure 191 Security Settings - Java 27.4.1.3.1 JA V A (Sun) 1 From Internet Explorer , click To o l s , Internet Options and then the Advanced tab. 2 make sure that Use Java 2 for <applet> u nder Java (Sun) is selected.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 27 Troubleshooting 329 Figure 192 Java (Sun) 27.5 T elephone Problems Table 129 Troubleshooting Telephone PROBLEM CORRECTIVE ACTION The telephone port won’t work or the telephone lacks a dial to ne. Check the telephone con nections and telephone wire.
P-2602H(W)(L)-DxA Series User’s Guide 330 Chapter 27 Troublesh ooting 27.6 Problems With Multiple SIP Account s Y ou can se t up two SIP accounts on yo ur ZyX EL Device and your ZyXEL Device is equipped with two phone ports.
P-2602H(W)(L)-DxA Ser ies User’s Guide Chapter 27 Troubleshooting 331 27.6.2 Incoming Calls The following example shows the default behavior of your ZyXE L Device for incoming calls when two SIP accounts are configured and yo u are using two phones.
P-2602H(W)(L)-DxA Series User’s Guide 332 Chapter 27 Troublesh ooting.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix A Product Specifications 333 A PPENDIX A Product S pecifications See also Chapter 1 on pa ge 37 for a general overview of the key features. S pecification T ables Table 130 Device Specifications Default IP Address 192.
P-2602H(W)(L)-DxA Series User’s Guide 334 Appendix A Product Specifications Table 131 Firmware Specifications ADSL S tandards Support ITU G .992 .1 G .dmt (Annex B, U-R2) EOC specified in ITU-T G .992.1 ADSL2 G . dmt.bis (G .992 .3) ADSL2 G . lite.bis (G .
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix A Product Specifications 335 Wireless (“W” models only) IEEE 802.1 1g Compliance Frequency Range: 2.4 GHz ISM Band Advanced Orthogonal Frequency Divisio n Multiplexing (OFDM) Data Ra tes: 54Mbp s, 1 1Mbp s, 5.
P-2602H(W)(L)-DxA Series User’s Guide 336 Appendix A Product Specifications P-2602HWL Series Power Adaptor S pecifications V oice Fe atures SIP version 2 (Session Initiating Protocol RFC 3261) SDP (Session Description Protocol RFC 2327) RTP (RFC 1889) RTCP (RFC 1890) V oice code cs (coder/decoders) G .
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix A Product Specifications 337 Input Power AC 100~240V olts/50/60Hz/0.5A AC 100~240V olts/50/60Hz/0.6A Output Pow er DC 18V olts/1A DC 18V olts/1A Power.
P-2602H(W)(L)-DxA Series User’s Guide 338 Appendix A Product Specifications.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix B Sp litters and Microf ilters 339 A PPENDIX B S plitters and Microfilters This appendix tells you how to install a POTS splitter or a telephone microfilter . Connecting a POTS S plitter When you use the Full Rate (G .
P-2602H(W)(L)-DxA Series User’s Guide 340 Appendix B Splitters and Microfilters 1 Connect a phone cable from the wall jack to the single jack end of the Y - Connector . 2 Connect a cable from the double jack end of the Y -Connector to th e “wa ll side” of the microfilter .
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix C Setting up Your Computer’s IP Address 341 A PPENDIX C Setting up Y o ur Computer ’ s IP Address All computers must have a 10M or 100M Et hernet adapter card and TCP/IP installed.
P-2602H(W)(L)-DxA Series User’s Guide 342 Appendix C Setting up Your Computer’s IP Address Figure 200 WIndows 95/98 /Me: Network: Co nfiguration Inst alling Component s The Network window Configuration tab displays a list of installed components. Y ou need a network adapter , the TCP/IP protocol and Client for Microso ft Networks.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix C Setting up Your Computer’s IP Address 343 3 Select Microsoft from the list of manufacturers. 4 Select Client for Microsoft Networks from the list of network clients and then click OK . 5 Restart your computer so the changes you made take ef fect.
P-2602H(W)(L)-DxA Series User’s Guide 344 Appendix C Setting up Your Computer’s IP Address Figure 202 Windows 95/98/Me : TCP/IP Pr operties: DNS Configuration 4 Click the Gateway tab. • If you do not know your gateway’ s IP address, remove previously installed gateways.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix C Setting up Your Computer’s IP Address 345 Figure 203 Windows XP: S tart Menu 2 For W indows XP , click Network Connections . For W indows 2000/NT , click Network and Dial-up Connections . Figure 204 Windows XP: Control Panel 3 Right-click Local Area Connection and then click Pr operties .
P-2602H(W)(L)-DxA Series User’s Guide 346 Appendix C Setting up Your Computer’s IP Address Figure 205 Windows XP: Control Panel: Network Connections: Pro perties 4 Select Internet Protocol (TCP/IP) (under the Genera l tab in W in XP) and click Properties .
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix C Setting up Your Computer’s IP Address 347 • If you have a static IP address click Use the following IP Address and fill in the IP addr ess , Subnet mask , and Default gateway fields. Click Advanced .
P-2602H(W)(L)-DxA Series User’s Guide 348 Appendix C Setting up Your Computer’s IP Address 7 In the Internet Protocol TCP/IP Pr operties window (the General tab in W indows XP): • Click Obtain DNS server address automatically if you do not know your DNS server IP addre ss(es).
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix C Setting up Your Computer’s IP Address 349 Macintosh OS 8/9 1 Click the Apple menu, Control Panel and double-click TCP/IP to open the TCP/IP Control Panel . Figure 209 Macintosh OS 8/9: Apple Menu 2 Select Ethernet built-in from the Connect via list.
P-2602H(W)(L)-DxA Series User’s Guide 350 Appendix C Setting up Your Computer’s IP Address Figure 210 Macintosh O S 8/9: TCP/IP 3 For dynamically assigned settings, select Using DHCP Server from the Configur e: list. 4 For statically assigned settings, do the following: •F r o m t h e Configure box, select Manually .
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix C Setting up Your Computer’s IP Address 351 2 Click Network i n the icon bar . • Select Automatic from the Location list. • Select Built-in Ethe rnet from the Show list. • Click the TCP/IP tab.
P-2602H(W)(L)-DxA Series User’s Guide 352 Appendix C Setting up Your Computer’s IP Address.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix D IP Addresses and Subn etting 353 A PPENDIX D IP Addresses and Subnetting This appendix introduces IP addresses, IP address classes and subnet masks. Y ou use subnet masks to subdivid e a network in to smaller logical networks.
P-2602H(W)(L)-DxA Series User’s Guide 354 Appendix D IP Addresses a nd Subnetting The following table shows the network number and host ID arrangement for classes A, B and C. An IP address with host IDs of all zeros is the IP address of the n etwork (192.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix D IP Addresses and Subn etting 355 Subnet Masks A subnet mask is used to dete rmine which bits are part of th e network number , and which bits are part of the host ID (using a logical AND operation). A subnet mask has 32 bits.
P-2602H(W)(L)-DxA Series User’s Guide 356 Appendix D IP Addresses a nd Subnetting The first mask shown is the class “C” natural m ask. Normally if no mask is specified it is understood that the natura l mask is being used. Example: T wo Subnet s As an example, you have a class “C” address 1 92.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix D IP Addresses and Subn etting 357 Host IDs of all zeros represent the subnet itsel f and host IDs of all ones are the broadcast address for that subnet, so the actual number of hosts available on each subnet in the example above is 2 7 – 2 or 126 h osts for each subnet.
P-2602H(W)(L)-DxA Series User’s Guide 358 Appendix D IP Addresses a nd Subnetting Example Eight Subnet s Similarly use a 27-bit mask to create eight subnets (000, 001, 010 , 01 1, 100, 101, 1 10 and 111 ) . Subnet Address: 192.1 68.1.0 Lowest Host ID: 192 .
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix D IP Addresses and Subn etting 359 The following table shows class C IP ad dress last octet values for each subnet. The following table is a summary for class “C” subnet planning. Subnetting With Class A and Class B Networks.
P-2602H(W)(L)-DxA Series User’s Guide 360 Appendix D IP Addresses a nd Subnetting The following table is a summary for class “B” subnet planning. Table 146 Class B Subnet Planning NO. “BORROWED” HOST BIT S SUBNET MASK NO. SUBNETS NO. HOSTS PER SUBNET 1 255.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix E Wir eless LANs 361 A PPENDIX E Wireless LANs Wireless LAN T opologies This section discusses ad-hoc and in frastructure w ireless LAN topologies.
P-2602H(W)(L)-DxA Series User’s Guide 362 Appendix E Wirele ss LANs Figure 214 Basic Service Set ESS An Extended Service Set (ESS) consists of a series of overlappi ng BSSs, each containing an access point, with each access point connected together by a wired network.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix E Wir eless LANs 363 Figure 215 Infrastructure WLAN Channel A channel is the radio frequency(ies) used by IEEE 802.
P-2602H(W)(L)-DxA Series User’s Guide 364 Appendix E Wirele ss LANs Figure 216 RTS/ CTS When station A sends data to the AP , it might no t know that the station B is already using the channel.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix E Wir eless LANs 365 A large Fragmentation Thr eshold is recommended for networks not prone to interference while you should set a smaller thresh old for busy networks or networks tha t are prone to interference.
P-2602H(W)(L)-DxA Series User’s Guide 366 Appendix E Wirele ss LANs IEEE 802.1x In June 2001, the IEEE 802.1x st andard was designed to extend th e features of IEEE 802.1 1 to support extended authentication as well as providing additional accounting and control features.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix E Wir eless LANs 367 • Access-Challenge Sent by a RADIUS server requesting more information in order to allow access. The access point sends a proper response from the user and then sends another Access- Request message.
P-2602H(W)(L)-DxA Series User’s Guide 368 Appendix E Wirele ss LANs EAP-TLS (T ransport Layer Security) W ith EAP-TLS, digital certifications are needed by both the server and the wireless stations for mutual authentication. The server presents a certificate to the client.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix E Wir eless LANs 369 For added security , certificate-based authen tications (EAP-TLS, EAP-TTLS and PEAP) use dynamic keys for data encryption. They are ofte n deployed in corp orate environments, but for public deployment, a simp le user name and p assword pair is more practical.
P-2602H(W)(L)-DxA Series User’s Guide 370 Appendix E Wirele ss LANs The Message Integrity Check (MIC ) is designed to prevent an attacker from capturing data packets, altering them and resending them. The MIC provides a strong mat hematical function in which the receiver and the transmitter each compute and then compare the MIC.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix F Service s 371 A PPENDIX F Services The following table l ists some commonly-used se rvices and their associated protocols and port numbers. • Name : This is a short, descrip tive name for the service.
P-2602H(W)(L)-DxA Series User’s Guide 372 Appendix F Services HTTP TCP 80 Hyper T ext T ransfer Protocol - a clie nt/ server protocol for the world wide web. HTTPS TCP 443 HTTPS is a secured http session often used in e-commerce. ICMP User-Defined 1 Internet Control Message Protocol is often used for diagnostic purposes.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix F Service s 373 RCMD TCP 512 Remote Command Se rvice. REAL_AUDIO TCP 7070 A streaming audio service that enab les real time sound over the we b. REXEC TCP 514 Remote Execution Daemon. RLOGIN TCP 513 Remote Login.
P-2602H(W)(L)-DxA Series User’s Guide 374 Appendix F Services TFTP UDP 69 T rivial File Transfer Protocol is an Internet file transfer protocol similar to FTP , but uses the UDP (User Datagram Protocol) rather than TCP (T ransmission Control Protocol).
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix G Firewall Com mands 375 A PPENDIX G Firewall Commands Sys Firewall Commands The following describes the firewa ll commands. See the Command Interpreter appendix for inform ation on the command structure.
P-2602H(W)(L)-DxA Series User’s Guide 376 Appendix G Firewall Co mmands.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix H Triangle Route 377 A PPENDIX H T riangle Route The Ideal Setup When the firewall is on, your ZyXEL Device acts as a secure gateway between your LAN and the Internet.
P-2602H(W)(L)-DxA Series User’s Guide 378 Appendix H Triangle Route Figure 218 “T riangle Route” Problem The “T riangle Route” Solutions This section presents you two solutions to the “triangle route” problem. IP Aliasing IP alias allows you to partition your network into logical sections over the same Ethernet interface.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix H Triangle Route 379 Gateways on the W AN Side A second solution to the “triangle route” problem is to put all of your network gateways on the W AN side as the following figure shows. This en sures that all incoming network traffic passes through your ZyXEL Device to your LAN.
P-2602H(W)(L)-DxA Series User’s Guide 380 Appendix H Triangle Route.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix I Log Descriptions 381 A PPENDIX I Log Descriptions This appendix provides descrip tions of example log messages. Table 152 System Maintenance Logs LOG MESSAGE DESCRIPTION Time calibration is successful The router has adjusted its time based on information from the time server .
P-2602H(W)(L)-DxA Series User’s Guide 382 Appendix I Log Descriptio ns Successful HTTPS login Someone has logged on to the router's web configurator interface using HTTPS protocol. HTTPS login failed Someone has faile d to log on to the router's web configurator interface using HTTPS protocol.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix I Log Descriptions 383 For type and code details, see T able 165 on page 387 . Table 155 TCP Reset Lo gs LOG MESSAGE DESCRIPTION Under SYN flood attack, sent TCP RST The router sent a TCP reset packet when a host was u nder a SYN flood attack (the TCP incomplete count is per destination h ost.
P-2602H(W)(L)-DxA Series User’s Guide 384 Appendix I Log Descriptio ns Triangle route packet forwarded: ICMP The firewall allow ed a triangle route session to pass through. Packet without a NAT table entry blocked: ICMP The router blocked a packet that didn’t have a corresponding NA T table entry .
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix I Log Descriptions 385 For type and code details, see T able 165 on page 387 . Table 160 UPnP Logs LOG MESSAGE DESCRIPTION UPnP pass through Firewall UPnP packets can p ass through the firewall.
P-2602H(W)(L)-DxA Series User’s Guide 386 Appendix I Log Descriptio ns ip spoofing - no routing entry ICMP (type:%d, code:%d) The firewall classified an ICMP packet with no source routing entry as an IP spoofing attack. vulnerability ICMP (type:%d, code:%d) The firewall detecte d an ICMP vulnerability attack.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix I Log Descriptions 387 No Server to authenticate user. Th ere is no authentication serv er to authenticate a user . Local User Database does not find user`s credential. A user was not authenticated by the local user database because the user is not listed in th e local user database.
P-2602H(W)(L)-DxA Series User’s Guide 388 Appendix I Log Descriptio ns 11 T ime Exceeded 0 T ime to live exceeded in transit 1 Fragment reassembly time exceeded 12 Parameter Problem 0 Pointer indica.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix I Log Descriptions 389 Table 168 RTP Logs LOG MESSAGE DESCRIPTION Error, RTP init fail The initialization of an RTP session failed. Error, Call fail: RTP connect fail A V oIP phone call fail ed because the RTP session could not be established.
P-2602H(W)(L)-DxA Series User’s Guide 390 Appendix I Log Descriptio ns The following table shows RFC-2408 ISAKMP payload types that the log displays. Please refer to RFC 2408 for detail ed information on each type. Log Commands Go to the command interpreter interface ( Appendix J on page 393 explains how to access and use the commands).
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix I Log Descriptions 391 Figure 222 Displaying Log Para meters Example 4 Use sys logs category foll owed by a log category and a parameter to decide what to record.
P-2602H(W)(L)-DxA Series User’s Guide 392 Appendix I Log Descriptio ns Log Command Example This example shows how to set the ZyXEL Devi ce to record the acc ess logs and alerts and then view the results.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix J Com mand Interpreter 393 A PPENDIX J Command Interpreter The following describes how to us e the command interpreter . T eln et to the ZyXEL Device and enter the password to use the co mmands. See the includ ed disk or zyxel.
P-2602H(W)(L)-DxA Series User’s Guide 394 Appendix J Command Interpreter.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 395 A PPENDIX K Internal SPTGEN Internal SPTGEN Overview Internal SP TGEN (System Parame ter T able Generator) is a configuration text file useful for efficient configuration of multiple ZyXEL Devices.
P-2602H(W)(L)-DxA Series User’s Guide 396 Appendix K I nternal SPTGEN Some parameters are dependent on othe rs. For example, if you disable the Configur ed field in menu 1 (see Figure 224 on page 395 ), then you disable every field in this menu .
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 397 Figure 227 Internal SP TGEN FTP Downl oad Example Note: Y ou can rename your “ rom-t ” file when you save it to your computer but it must be named “ rom-t ” when you uplo ad it to your ZyXEL De vice.
P-2602H(W)(L)-DxA Series User’s Guide 398 Appendix K I nternal SPTGEN This section covers ZyXEL De vice Internal SP TGEN screens. The following are the Internal SP TGEN menus.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 399 30100014 = Output device filters Set 2 = 256 30100015 = Output device filters Set 3 = 256 30100016 = Output device filters Set 4 = 256 / Menu 3.
P-2602H(W)(L)-DxA Series User’s Guide 400 Appendix K I nternal SPTGEN 30201006 = IP Alias #1 Incoming protocol filters Set 1 = 256 30201007 = IP Alias #1 Incoming protocol filters Set 2 = 256 302010.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 401 30500002 = Hide ESSID <0(No) | 1(Yes)> = 0 30500003 = Channel ID <1|2|3|4|5|6|7 |8|9|10|11|12| 13> = 1 30500004 = RTS Threshold <0 ~ 2432> = 2432 30500005 = FRAG.
P-2602H(W)(L)-DxA Series User’s Guide 402 Appendix K I nternal SPTGEN 40000000 = Configured <0(No) | 1(Yes)> = 1 40000001 = ISP <0(No) | 1(Yes)> = 1 40000002 = Active <0(No) | 1(Yes)&.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 403 40000031= RIP Direction <0(None) | 1(Both) | 2(In Only) | 3(Out Only)> = 0 40000032= RIP Version <0(Rip-1) | 1(Rip-2B) .
P-2602H(W)(L)-DxA Series User’s Guide 404 Appendix K I nternal SPTGEN 120103005 = IP Static Route set #3, Gat eway = 0.0.0.0 120103006 = IP Static Route set #3, Met ric = 0 120103007 = IP Static Route set #3, Pri vate <0(No) |1(Yes)> = 0 / Menu 12.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 405 120107003 = IP Static Route set #7, Dest ination IP address = 0.0.0.0 120107004 = IP Static Route set #7, Dest ination IP subnetmask = 0 120107005 = IP Static Route set #7, Gate way = 0.
P-2602H(W)(L)-DxA Series User’s Guide 406 Appendix K I nternal SPTGEN 120111001 = IP Static Route set #11, Na me <Str> = 120111002 = IP Static Route set #11, Ac tive <0(No) |1(Yes)> = 0 120111003 = IP Static Route set #11, Destination IP address = 0.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 407 */ Menu 12.1.15 IP Static Route Setu p FIN FN PVA INPUT 120115001 = IP Static Route set #15, Nam e <Str> = 120115002 = IP Static Route set #15, Act ive <0(No) |1(Yes)> = 0 120115003 = IP Static Route set #15, Destinati on IP address = 0.
P-2602H(W)(L)-DxA Series User’s Guide 408 Appendix K I nternal SPTGEN 150000011 = SUA Server #3 Local IP address = 0.0.0.0 150000012 = SUA Server #4 Active <0(No) | 1(Yes)> = 0 150000013 = SUA.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 409 150000045 = SUA Server #10 Port End = 0 150000046 = SUA Server #10 Local IP address = 0.
P-2602H(W)(L)-DxA Series User’s Guide 410 Appendix K I nternal SPTGEN 210101013 = IP Filter Set 1,Rule 1 Act Match <1(check next)|2(forward)| 3(drop)> = 3 210101014 = IP Filter Set 1,Rule 1 Act Not Match <1(check next)|2(forward)| 3(drop)> = 1 / Menu 21.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 411 210103009 = IP Filter Set 1,Rule 3 Src Subnet Mask = 0 210103010 = IP Filter Set 1,Rule 3 Src Port = 0 210103011 = IP Filter Set.
P-2602H(W)(L)-DxA Series User’s Guide 412 Appendix K I nternal SPTGEN 210105006 = IP Filter Set 1,Rule 5 Dest Port = 138 210105007 = IP Filter Set 1,Rule 5 Dest Port Comp <0(none)|1(equal) |2(not equal)|3(less)|4( greater)> = 1 210105008 = IP Filter Set 1,Rule 5 Src IP Address = 0.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 413 Table 180 Menu 21.1 Filer Set #2 , / Menu 21.1 filter set #2, FIN FN PVA INPUT 210200001 = Filter Set 2, Nam <Str> = NetBIOS_WAN / Menu 21.
P-2602H(W)(L)-DxA Series User’s Guide 414 Appendix K I nternal SPTGEN 210202007 = IP Filter Set 2, Rule 2 Dest Port Comp <0(none)|1(equal)|2 (not equal)|3(less)|4(gr eater)> = 1 210202008 = IP Filter Set 2, Rule 2 Src IP address = 0.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 415 210203014 = IP Filter Set 2,Rule 3 Act Not Match <1(check next)|2(forward)|3( drop)> = 1 / Menu 21.
P-2602H(W)(L)-DxA Series User’s Guide 416 Appendix K I nternal SPTGEN 210205007 = IP Filter Set 2, Rule 5 Dest Port Comp <0(none)|1(equal)|2 (not equal)|3(less)|4(gr eater)> = 1 210205008 = IP Filter Set 2, Rule 5 Src IP address = 0.
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 417 210206014 = IP Filter Set 2,Rule 6 Act Not Match <1(check next)|2(forward)|3( drop)> = 2 241100005 = FTP Server Access <0(all)|1(none)|2(L an)|3(Wan)> = 0 241100006 = FTP Server Secured IP address = 0.
P-2602H(W)(L)-DxA Series User’s Guide 418 Appendix K I nternal SPTGEN 230400003 = Idle Timeout (in second) = 999 230400004 = Authentication Databases <0(Local Use r Database Only) |1(RADIUS Only).
P-2602H(W)(L)-DxA Ser ies User’s Guide Appendix K Internal SPTGEN 419 Command Examples The following are example Internal SP TGEN screens associated with the ZyXEL Device’ s command interpreter commands.
P-2602H(W)(L)-DxA Series User’s Guide 420 Appendix K I nternal SPTGEN.
P-2602H(W)(L)-DxA Ser ies User’s Guide Index 421 Index A AAL5 334 AbS 156 ACK Message 152 Address Assignment 109 Address Resolution Protocol (ARP) 11 2 ADSL standards 38 ADSL2 334 AH 217 AH Protoc o.
P-2602H(W)(L)-DxA Series User’s Guide 422 Index CoS 162 CTS (Clear to Send) 364 Custom Ports Creating/Editing 202 Customized Services 202 Customized services 202 D Data Confidentiality 216 Data Inte.
P-2602H(W)(L)-DxA Ser ies User’s Guide Index 423 Custom Ports 202 Enabling 196 Firewall Vs Filters 191 Guidelines For Enhancing Security 190 Introduction 182 LAN to W AN Rules 196 Policies 193 Rule .
P-2602H(W)(L)-DxA Series User’s Guide 424 Index IPSec 215 IPSec Algorithms 217 , 221 IPSec and NA T 218 IPSec Architecture 216 IPSec Passthrough 335 IPSec S tandard 39 IPSec VPN Capability 39 ISDN (Integrated Services Di gital Network) 38 ITSP 44 ITU-T 164 ITU-T G .
P-2602H(W)(L)-DxA Ser ies User’s Guide Index 425 P Packet Filtering 191 Packet filtering When to use 192 Packet Filtering Firewalls 181 Pairwise Master Key (PMK) 369 PCM 156 Peak Cell Rate (PCR) 96 .
P-2602H(W)(L)-DxA Series User’s Guide 426 Index S SA 215 Safety W arnings 5 Saving the S tate 187 Scheduler 254 SDP 336 Seamless Rate Adaptation 334 Secure Gateway Address 223 Security Association 2.
P-2602H(W)(L)-DxA Ser ies User’s Guide Index 427 TFTP and FTP over W AN 302 TFTP Restrictions 267 , 30 2 Three-Way Conference 170 , 171 Three-Way Handshake 184 Threshold V alues 207 TLS 335 To S 162.
Een belangrijk punt na aankoop van elk apparaat ZyXEL Communications P-2602 (of zelfs voordat je het koopt) is om de handleiding te lezen. Dit moeten wij doen vanwege een paar simpele redenen:
Als u nog geen ZyXEL Communications P-2602 heb gekocht dan nu is een goed moment om kennis te maken met de basisgegevens van het product. Eerst kijk dan naar de eerste pagina\'s van de handleiding, die je hierboven vindt. Je moet daar de belangrijkste technische gegevens ZyXEL Communications P-2602 vinden. Op dit manier kan je controleren of het apparaat aan jouw behoeften voldoet. Op de volgende pagina's van de handleiding ZyXEL Communications P-2602 leer je over alle kenmerken van het product en krijg je informatie over de werking. De informatie die je over ZyXEL Communications P-2602 krijgt, zal je zeker helpen om een besluit over de aankoop te nemen.
In een situatie waarin je al een beziter van ZyXEL Communications P-2602 bent, maar toch heb je de instructies niet gelezen, moet je het doen voor de hierboven beschreven redenen. Je zult dan weten of je goed de alle beschikbare functies heb gebruikt, en of je fouten heb gemaakt die het leven van de ZyXEL Communications P-2602 kunnen verkorten.
Maar de belangrijkste taak van de handleiding is om de gebruiker bij het oplossen van problemen te helpen met ZyXEL Communications P-2602 . Bijna altijd, zal je daar het vinden Troubleshooting met de meest voorkomende storingen en defecten #MANUAl# samen met de instructies over hun opplosinge. Zelfs als je zelf niet kan om het probleem op te lossen, zal de instructie je de weg wijzen naar verdere andere procedure, bijv. door contact met de klantenservice of het dichtstbijzijnde servicecentrum.