ZyXEL Communications 792H manual Local Network, 10-7, 30-6

Page 425

Header

HyperTerminal program

31-6, 31-9

IANA

3-8

ICMP echo

8-6

Idle Timeout

21-6

IGMP

4-3, 4-4

IGMP support

24-7

Install UPnP

16-3

Windows Me

16-4

Windows XP

16-5

Installation

 

Ease

1-4

Interactive Applications

33-1

Internal SPTGEN

38-1

FTP Download Example

38-3

FTP Upload Example

38-4

Points to Remember

38-2

Text File

38-1

Internet Access.... 1-1, 1-2, 20-4, 21-1, 22-1, 23-1,

23-2

 

Internet Access Application

1-5

Internet Access Setup

27-1

Internet Assigned Numbers Authority ..

See IANA

Internet Control Message Protocol (ICMP) ..... 8-6

IP address

21-6, 21-8

IP Address3-6, 4-3, 6-5, 6-8, 17-6, 22-5, 25-3, 26-

3, 28-11, 30-4, 30-9, 33-3

 

Remote

21-8

IP Address Assignment

3-7

ENET ENCAP

3-8

PPPoA or PPPoE

3-7

RFC 1483

3-8

IP Alias Setup

22-2

IP Filter

 

Logic Flow

28-12

IP mask

28-11

IP Multicast

1-2

Internet Group Management Protocol (IGMP)

.................................................................

1-2

IP Packet

28-14

IP Policies

33-5

IP Policy Routing

1-2

IP Policy Routing (IPPR)

 

Applying an IP Policy

33-5

Ethernet IP Policies

 

33-5

Gateway

 

33-5

IP Pool Setup

 

3-16

IP Ports

 

36-9, 36-10

IP Protocol

 

33-4

IP Routing Policy (IPPR)

33-1

Benefits

 

33-1

Cost Savings

 

33-1

Criteria

 

33-1

Load Sharing

 

33-1

Setup

 

33-2

IP Routing Policy Setup

.................................

33-3

IP Spoofing

 

8-4, 8-7

IP Static Route

 

25-1

IP Static Route Setup

 

25-2

IP Subnet Mask

 

21-8

Remote

 

21-8

IPSec standard

 

1-2

IPSec VPN Capability

 

1-2

Key Fields For Configuring Rules

10-2

LAN

 

30-2, 30-3

LAN Setup

 

4-1, 5-1

LAN TCP/IP

 

4-2

LAN to WAN Rules

 

10-3

LAND

 

8-4, 8-6

Link type

 

30-2

LLC-based Multiplexing

24-10

Local Network

 

 

 

Rule Summary

 

10-7

Log and Trace

 

30-6

Log Facility

 

30-7

Logging Option

28-12, 28-15

Login

 

24-3

MAC address

 

26-3

Main Menu

 

19-4

Management Information Base (MIB)

...........29-2

Max-incomplete High

 

9-4

Max-incomplete Low

 

9-4

MBS

See Maximum Burst Size

Media Access Control

 

26-1

Message Logging

 

30-5

x

Index

Image 425
Contents Prestige 792H Page Trademarks DisclaimerPage Certifications Page Information for Canadian Users Page Safety Warnings ZyXEL Limited WarrantyPage Customer Support Page Table of Contents WAN Setup LAN SetupDynamic DNS Setup Customized Services 11-1 Firewall ConfigurationContent Filtering 12-1 Creating Custom Rules 10-115-1 14-1General Setup 19-1 Maintenance 17-1WAN Setup 20-4 Dial Backup 21-123-1 22-124-1 25-1Snmp Configuration 29-1 Filter Configuration 28-1System Maintenance 30-1 Firmware and Configuration File Maintenance 31-1IP Policy Routing 33-1 System Maintenance and Information 32-1Call Scheduling 34-1 Remote Management 35-1Troubleshooting 39-1 VPN/IPSec Setup 36-1SA Monitor 37-1 Internal Sptgen 38-1List of Figures Xviii List of Figures List of Figures Xix Diagnostic General 17-8 List of Figures Xxi Xxii List of Figures List of Figures Xxiii Xxiv List of Figures List of Figures Xxv Page List of Tables List of Tables Xxvii Xxviii List of Tables 28-15 Xxx List of Tables Page Syntax Conventions Related DocumentationXxxii Preface Introduction to G.SHDSL Introduction to DSLPart Page Symmetrical High Speed Internet Access Features of the PrestigeGetting to Know Your G.SHDSL Router ScalabilityFirewall IPSec VPN CapabilityTraffic Redirect Snmp Simple Network Management Protocol versions 1IP Alias SUA for Single-IP Address Internet AccessIP Policy Routing 10/100MB Auto-negotiation Ethernet/Fast Ethernet InterfaceEase of Installation Upgrade Firmware via LANUniversal Plug and Play UPnP Full Network ManagementLAN-to-LAN Application Internet AccessApplication Scenarios for the Prestige Accessing the Prestige Web Configurator Introducing the Web ConfiguratorWeb Configurator Overview Password Screen Navigating the Prestige Web ConfiguratorConfiguring Password Label Description Resetting the PrestigeUploading a Configuration File Via Console Port Using The Reset ButtonPage Wizard Setup Introduction Wizard SetupWAN Setup Service TypeEncapsulation Standard ModeTransfer Rates PPP over EthernetPPPoA Multiplexing4 RFC VC-based MultiplexingVPI and VCI Wizard Setup Configuration First ScreenRate and the same Transfer Min Rate Server see Service TypePPPoE IP Address and Subnet MaskVPI VCIIP Assignment with PPPoA or PPPoE Encapsulation IP Address AssignmentPrivate IP Addresses IP Assignment with RFC 1483 EncapsulationIP Assignment with Enet Encap Encapsulation 10 NAT Wizard Setup Configuration ISP ParametersNailed-Up Connection PPP Internet Connection with PPPoA Internet Internet Connection with RFC 11.2 RFCEnet Encap Internet Connection with Enet EncapInternet Connection with PPPoE PPPoEDhcp Setup IP Pool Setup Wizard Setup Configuration LAN ConfigurationWizard LAN Configuration Wizard Screen LAN COnfigurationWizard Setup Configuration Connection Tests Wizard Screen Connection Tests Test Your Internet ConnectionPage LAN Overview LAN SetupDNS Server Address LANs, WANs and the PrestigeLAN TCP/IP DNS Server Address AssignmentRIP Setup Factory LAN DefaultsIP Address and Subnet Mask MulticastLAN Configuring LANTCP/IP LAN Metric WAN SetupWAN Overview PPPoE Encapsulation Traffic Shaping Example of Traffic Shaping Configuring WAN SetupWAN Setup ATM traffic. Enter the VCI assigned to you Subnet as the remote node For remote node setup, enter the IP address in the sameEncap in the Encapsulation field Traffic RedirectTraffic Redirect LAN Setup Configuring WAN BackupWAN Backup Cost 38400 , 57600 , 115200 or 230400 bps Outgoing Authentication ProtocolWAN , Traffic Redirect , Dial Backup Configuring Advanced WAN Backup Advanced WAN Backup 57600 , 115200 or 230400 bps Choose Both, In Only or Out Only Choose RIP-1,RIP-2B or RIP-2MConnection settings AT Command StringsResponse Strings DTR SignalConfiguring Advanced Modem Setup Advanced Modem Setup Nmbr ClidPart Page NAT Overview Network Address Translation NATNAT Definitions What NAT DoesNAT Application How NAT WorksNAT Application With IP Alias NAT Mapping TypesMapping types SUA Single User Account Versus NATNAT Mapping Types Type IP Mapping SMT AbbreviationSUA Server Port Forwarding Services and Port NumbersServices and Port Numbers Configuring Servers Behind SUA ExampleServices Port Number EchoMultiple Servers Behind NAT Example Selecting the NAT ModeConfiguring SUA Server Edit SUA/NAT Server Set Configuring Address Mapping Many-to-One and Server mapping types Address Mapping RulesAddress Mapping Rule Edit Editing an Address Mapping RuleAddress Mapping Rules screen Page Configuring Dynamic DNS Dynamic DNS SetupDynamic DNS Dyndns WildcardDdns Firewall and Content Filter Page Firewall Overview FirewallsTypes of Firewalls Packet Filtering FirewallsStateful Inspection Firewalls Introduction to ZyXEL’s FirewallBasics Denial of ServiceCommon IP Ports Types of DoS AttacksThree-Way Handshake Icmp Commands That Trigger Alerts Legal Smtp Commands Legal NetBIOS CommandsStateful Inspection Message Request Positive Negative Retarget KeepaliveStateful Inspection Stateful Inspection ProcessStateful Inspection and the Prestige 4 UDP/ICMP Security TCP SecuritySecurity In General Guidelines for Enhancing Security with Your FirewallUpper Layer Protocols Packet Filtering Packet Filtering Vs FirewallFirewall When To Use FilteringPrestige 792H G.SHDSL Router Enabling the Firewall Firewall ConfigurationRemote Management and the Firewall E-mail Configuring E-mail AlertsAttack Alert Daily Weekly Hourly When Log is Full NoneHalf-Open Sessions AlertsThreshold Values TCP Maximum Incomplete and Blocking Time Following table describes the labels in this screen Alert256 Page Study these points carefully before configuring rules Rule ChecklistCreating Custom Rules Rules OverviewBlock means the firewall silently discards the packet Key Fields For Configuring RulesSecurity Ramifications LAN to WAN Rules Connection DirectionWAN to LAN Rules LogsLabel Description Example Firewall LogsBlock, Forward or None Rule SummaryFirewall Rules Summary First Screen Predefined Services Service Description Predefined ServicesNEWSTCP144 RLOGINTCP513NNTPTCP119 PINGICMP0Creating/Editing Firewall Rules Creating/Editing a Firewall Rule Source and Destination Addresses Range Address , Subnet Address and Any Address TimeoutTimeout Factors Influencing Choices for Timeout Values10-16 Creating Custom Rules Introduction to Customized Services Customized ServicesCreating/Editing a Customized Service Creating/Editing a Customized ServiceClick Rule Summary under Internet to Local Network Set Example Custom Service Firewall RuleConfigure Source IP Example Syslog Rule Configuration Example Rule Summary Example Configuring Keyword Blocking Content FilteringContent Filtering Overview Content Filter Keyword Content Filter Schedule Configuring the ScheduleContent Filter Trusted Configuring Trusted ComputersContent Filter Logs Configuring LogsBlockcybernot BLOCKUNTRUSTDOMAIN, BLOCKKEYWORD, BlockactivexBLOCKJAVAAPPLET, BLOCKCOOKIE, Blockproxy VPN/IPSec Page VPN Overview Introduction to IPSecIPSec Security AssociationData Integrity Data Origin AuthenticationVPN Applications VPN Application IPSec ArchitectureKey Management IPSec AlgorithmsIPSec and NAT Transport ModeTunnel Mode ESP Security Protocol Mode NATVPN and NAT VPN Screens AH Authentication Header Protocol14.1 VPN/IPSec Overview IPSec AlgorithmsSecure Gateway Address My IP AddressDynamic Secure Gateway Address AH and ESPIPSec Summary Fields VPN Summary ScreenVPN Summary Keep Alive ID Type and ContentLocal ID Type and Content Fields ID Type and Content ExamplesPeer ID Type and Content Fields Local ID TYPE= CONTENT=Mismatching ID Type and Content Configuration Example Matching ID Type and Content Configuration ExamplePre-Shared Key Editing VPN PoliciesVPN IKE VPN Screens 14-9 14-10 VPN Screens VPN Screens 14-11 IKE Authentication Algorithm fields described nextTwo Phases to Set Up the IPSec SA IKE PhasesDiffie-Hellman DH Key Groups Negotiation ModePerfect Forward Secrecy PFS 14.11Configuring Advanced IKE SettingsLabel Description VPN IKE VPN IKE AdvancedVPN Screens 14-17 14-18 VPN Screens Security Parameter Index SPI 14.12Manual Key SetupVPN Manual Key 14.13Configuring Manual KeySPI 14-22 VPN Screens VPN Screens 14-23 14.14Viewing SA Monitor 10 SA Monitor SA Monitor11 Global Setting 14.15Configuring Global Setting12 VPN Logs 14.16Configuring IPSec LogsLOG Message Description 13 Sample IKE Key Exchange LogsRequest conflict with rule #d 14 Sample IPSec Logs During Packet TransmissionLOG Display Payload Type 15 RFC-2408 Isakmp Payload TypesHeadquarters Telecommuters 14.17Telecommuter VPN/IPSec ExamplesTelecommuters Sharing One VPN Rule Example All Headquarters Rules All Telecommuter Rules Telecommuters Using Unique VPN Rules Example14.18VPN and Remote Management Remote Management and UPnP Remote Management Overview Remote Management ConfigurationRemote Management Limitations Remote Management and NATTelnet System Timeout15.3 FTP 15.4 WebRemote Management Configuring Remote ManagementUniversal Plug-and-Play UPnP How do I know if Im using UPnP?Universal Plug and Play Overview NAT TransversalUPnP and ZyXEL Accessing the Prestige Web Configurator to Configure UPnPConfiguring UPnP Field Description Installing UPnP in Windows ExampleInstalling UPnP in Windows Me Optional Networking Component Installing UPnP in Windows XPDouble-clickNetwork Connections Auto-discover Your UPnP-enabled Network Device Using UPnP in Windows XP ExampleInternet Connection Properties Connections Select My Network Places under Other Places Web Configurator Easy Access ExampleClick start and then Control Panel UPnP 16-9 Maintenance Page System Status Screen MaintenanceMaintenance Overview System Status VPI/VCI System Status Show Statistics System StatisticsMaintenance 17-5 Dhcp Table Dhcp Table ScreenMAC Diagnostic ScreensDiagnostic General Screen Diagnostic General Prestige 792H G.SHDSL Router Diagnostic DSL Line ScreenFirmware Screen Firmware UpgradeNetwork Temporarily Disconnected SMT General Configuration Procedure for SMT Configuration via Telnet Procedure for SMT Configuration via Console PortEntering Password Introducing the SMTPrestige SMT Menu Overview Login ScreenPrestige Menu Overview Navigating the SMT Interface Main Menu CommandsOperation Keystroke Description ? or ChangeMeMenu Title Description System Management Terminal Interface SummaryMain Menu Summary Menu 23 System Password Changing the System PasswordConfiguring Menu General SetupGeneral Setup Yes Configure Menu 1.1 Configure Dynamic DNS discussed nextField Description Example User Configuring Dynamic DNSPage From the main menu, enter 2 to open menu WAN Setup Screen20-5 Configuring Dial Backup in Menu Dial BackupDial Backup Overview Enter to go to Menu 2.1 Advanced Setup Advanced WAN Setup115200 9600, 19200, 38400, 57600, 115200 or 230400 bpsNmbr = Field Description DefaultConnect Remote Node Profile Backup ISPAdvanced WAN Port Setup Call Control Parameters CHAP/PAP Remote Node Profile Backup ISPPress Enter to go to Menu 11.3 Remote Node Network Otherwise select Standard PPP Editing PPP OptionsEditing TCP/IP Options NAT Enter to open Menu 11.3 Network Layer OptionsBoth Editing Filter SetsBoth/ None /In Only /Out Only and None RIP-1Menu 11.5 Remote Node Filter Ethernet LAN Port Filter Setup Ethernet SetupTCP/IP and Dhcp Setup IP Alias SetupRIP-2B or RIP-2M Route IP SetupBoth , In Only or Out Only General Setup 22.1.4 TCP/IP Ethernet Setup and DhcpRIP-1,RIP-2B or RIP-2M Both Both, In Only, Out Only or NoneRIP-1 22-6 Internet Access Setup Internet AccessInternet Access Overview Or Enet Encap Enet EncapLLC-based UBRSUA Only DynamicAdvanced Applications Remote Node Overview Remote Node ConfigurationRemote Node Setup Encapsulation and Multiplexing Scenarios Remote Node SetupBased or LLC-based Then the Rem Login, Rem Password, My Login, MyTo display Menu 11.3 Remote Node Network Layer Options ChapTo display Menu 11.6 Remote Node ATM Layer Options Allocated Budget is 10 minutes and the Period hrRemote Remote Node Network Layer OptionsStatic Options are Both, In Only, Out Only or None My WAN Addr Sample IP AddressesSample IP Addresses for a TCP/IP LAN-to-LAN Connection Remote Node FilterPress Enter to open Menu 11.6 Remote Node ATM Layer Options Editing ATM Layer OptionsVC-based Multiplexing non-PPP Encapsulation Menu 11.6 for LLC-based Multiplexing or PPP Encapsulation LLC-based Multiplexing or PPP EncapsulationStatic Route Overview Static Route SetupStatic Route Setup Edit IP Static Route Page Bridge Ethernet Setup Bridging SetupRemote Node Bridging Setup Bridging OverviewRemote Node Bridging Options Bridge Static Route SetupBridge Static Route Setup 26-4 Bridging Setup Applying NAT Applying NAT for Internet Access Full Feature NAT SetupAddress Mapping Sets Enter 1 to bring up Menu 15.1 Address Mapping SetsAddress Mapping Rules SUA Address Mapping SetsUser-Defined Address Mapping Sets Natset Field Desription ExampleSelect Rule item Global Start/End IPsEdit To-One,Many-to-One and Server types One-to-OneFor Server NAT Server Sets NAT Server Setup General NAT Examples Example 1 Internet Access Only11 NAT Example 13 NAT Example Example 2 Internet Access with an Inside Server14 NAT Example 2 Menu Example 3 Multiple Public IP Addresses With Inside Servers15 NAT Example 17 Example 3 Menu Enter 2 in Menu 15 NAT Setup 19 Example 3- Menu Example 4 NAT Unfriendly Application Programs21 Example 4 Menu 22 Example 4 Menu Advanced Management Page About Filtering Filter ConfigurationOutgoing Packet Filtering Process Filter Rule Process Execute Filter RuleFilter Structure of the Prestige Filter Set ConfigurationNetBios WAN Filter Rules Summary TelnetWAN Filter Rules Summary Ftpwan Filter Rules Summary Abbreviations Used in the Filter Rules Summary Menu Filter Rules Summary MenusRule Abbreviations Used Filter Rule ConfigurationFilter Type Description GENChoices are TCP/IP Filter Rule or Generic Filter Rule 28.3.1 TCP/IP Filter RuleTCP/IP Filter Rule If More is Yes , then Action Matched and Action Not TCP/IP Filter RuleChoices are None , Less , Greater , Equal or Not Equal Choices are Check Next Rule, Forward or Drop Check Next RuleCheck Next Rule, Forward or Drop 12 Executing an IP Filter 13 Generic Filter Rule Generic Filter RuleGeneric Filter Rule Menu Fields Example Filter Filter Types and NAT15 Sample Telnet Filter 16 Sample Filter Rules Summary Menu 17 Sample Filter Rules Summary Menu Ethernet Traffic Applying Filters and Factory DefaultsFilter Sets Table Filter Sets Description19 Filtering Ethernet Traffic Remote Node FiltersPage Snmp Overview Snmp ConfigurationSnmp is only available if TCP/IP is configured Supported MIBs Snmp ConfigurationSnmp Traps Snmp TrapsSnmp Trap # Trap Name Description29-4 Snmp Configuration System Status System MaintenanceSystem Maintenance Overview System Maintenance Status WAN System InformationSystem Information LAN Menu 1 General SetupConsole Port Speed Viewing Error LogLog and Trace Syslog Sample Error and Information MessagesCDR System Maintenance Menu Syslog ParametersParameter Description System Maintenance Diagnostic DiagnosticSystem Maintenance Menu Diagnostic Page Filename Conventions Firmware and Configuration File MaintenanceFile Type Internal External Name Description Backup ConfigurationFilename Conventions Example of FTP Commands from the Command Line Backup ConfigurationUsing the FTP Command from the Command Line Command Description General Commands for GUI-based FTP ClientsGUI-based FTP Clients Tftp and FTP over WAN Will Not Work WhenGUI-based Tftp Clients Backup Configuration Using TftpTftp Command Example General Commands for GUI-based Tftp Clients Backup Via Console PortBackup Configuration Example Restore ConfigurationSystem Maintenance Restore Configuration Restore Using FTPRestore Via Console Port Restore Using FTP Session ExampleFirmware File Upload Uploading Firmware and Configuration Files13 System Maintenance Upload System Firmware Configuration File UploadTftp File Upload FTP File Upload Command from the DOS Prompt ExampleFTP Session Example of Firmware File Upload Uploading Via Console Port Tftp Upload Command ExampleUploading Firmware File Via Console Port Example Xmodem Firmware Upload Using HyperTerminalExample Xmodem Configuration Upload Using HyperTerminal Uploading Configuration File Via Console Port19 Example Xmodem Upload Command Interpreter Mode System Maintenance and InformationBudget Management Call Control SupportBudget Management System Maintenance Time and Date Setting Time and Date SettingNTP RFC-1305 is similar to Time RFC-868 Resetting the TimeTime and Date Setting Fields Page IP Policy Routing Overview IP Policy RoutingIP Policy Routing Benefits Routing PolicyIP Routing Policy Setup IP Routing Policy SetupAbbreviation Meaning ServiceCriterion ActionG t Delay, Max Thruput, Min Cost or Max ReliableEthernet IP Policies Applying an IP PolicyLess, Greater, Less or Equal or Greater or Equal Matched33-6 IP Policy Routing Example of IP Policy Routing IP Policy Routing ExampleIP Routing Policy Example Applying IP Policies Page Call Scheduling Overview Schedule SetupCall Scheduling Schedule Set Setup Forced On OnceApplying Schedule Sets to a Remote Node PPPoE Remote Management Remote Management and Telnet ServicesRemote Management and FTP Services Remote Management and Web Services Remote Management SetupDisabling Remote Management Remote Management ControlRemote Management and NAT System TimeoutSMT VPN/IPSec and Internal Sptgen 36.1 VPN/IPSec Overview VPN/IPSec SetupIPSec Summary Screen Menu 27 VPN/IPSec SetupESP DES MD5 Tunnel36-4 VPN/IPSec Setup IPSec Setup IPSec Summary Menu 27.1.1 IPSec SetupGateway Address field below Single Address field set toSubnet Manual Setup 3Menu 27.1.1.1 IKE Setup IKE SetupField Description ExampleMD5 DESDH1 Mode Security Protocol Manual SetupActive Protocol Active Protocol Encapsulation and Security ProtocolESP Tunnel Menu 27.1.1.2 Manual SetupVPN/IPSec Setup 36-15 Page SA Monitor Overview Using SA MonitorSA Monitor Refresh TaiwanESP DES VPN Responder IPSec Log Diagram 37-1 Example VPN Responder IPSec LogViewing IPSec Log Page Internal Sptgen Overview Configuration Text File FormatInternal Sptgen 38-2 Internal Sptgen Internal Sptgen FTP Download Example Invalid Parameter Entered Command Line ExampleInternal Sptgen FTP Upload Example Internal Sptgen FTP Upload ExampleAppendices and Index Page Problems Starting Up the Prestige TroubleshootingProblems with the LAN Interface Troubleshooting the Start-Up of Your PrestigeProblems with Internet Access Problems with the WAN InterfaceTroubleshooting the WAN Interface Troubleshooting Internet AccessProblems with Telnet Problems with the PasswordTroubleshooting the Password Troubleshooting TelnetPage PPPoE in Action Appendix a PPPoEBenefits of PPPoE Traditional Dial-up ScenarioPrestige as a PPPoE Client Diagram 2 Prestige as a PPPoE ClientAppendix B Virtual Circuit Topology Diagram 3 Virtual Circuit TopologyAppendix C Power Adapter SpecificationsNorth American Plug Standards United Kingdom Plug StandardsChina Standards European Plug StandardsAA-121ABN Power Consumption Safety Standards Ccee GB8898 Index 17-10 28-430-6 Local Network10-7 24-1,24-2 24-230-5 RIPTraceroute TCP/IP
Related manuals
Manual 2 pages 9.52 Kb