VigorPro 5500 Series Unified Security Firewall User’s Guide
 Instructions
Safety Instructions and Approval
 Regulatory Information
European Community Declarations
 Table of Contents
 100
 211
171
 Trouble Shooting 235
Page
 LED Indicators and Connectors
Web Configuration Buttons Explanation
 LED
For VigorPro
 Wlan
For VigorPro 5500G
 Isdn
 For VigorPro 5500Gi
 Interface Description
 Internet
Hardware Installation
 VigorPro5500 Series User’s Guide
 Changing Password
Configuring Basic Settings
 Now, the Main Screen will pop up
 Quick Start Wizard
 PPPoE
 VigorPro5500 Series User’s Guide
 Pptp
 Static IP
 Dhcp
 Online Status
 Online status for Dhcp
Displays the IP address of the default gateway
 Saving Configuration
 This page is left blank
 Basics of Internet Protocol IP Network
WAN
What are Public IP Address and Private IP Address
Get Your Public IP Address from ISP
 Enable
General Setup
Physical Mode
Display Name
 Active Mode
Load Balance Mode
Physical Type
Negotiation for determined by the system
 Access Mode
Internet Access
Index
Details
 Details Page for PPPoE
 Details Page for Static or Dynamic IP
 Dhcp Client
Settings
Keep WAN
Connection
 Address
DNS Server IP
 PPP Setup
Pptp Setup
Details Page for Pptp
Assignment
 MAC address for the router
Load-Balance Policy
 WAN
Protocol
 Dest Port End
Binding WAN
Interface Src IP Start
 Basics of LAN
LAN
 What are Virtual LANs and Rate Control
What is Routing Information Protocol RIP
What is Static Route
 Subnet
1st IP Address 1st Subnet Mask For IP Routing Usage
 Relay Agent 1st subnet/2nd subnet Specify which subnet that
Configuration
Dhcp Server
 DNS Server
Static Route
 Add Static Routes to Private and Public Networks
 VigorPro5500 Series User’s Guide
 Vlan
 Bind IP to MAC
Disable
Strict Bind
ARP Table
 NAT
 Port Redirection
 Private IP
Service Name
Public Port
 Active
Private Port
 True…
DMZ Host
 Choose PC
 Comment
Open Ports
WAN Interface
Local IP Address
 Local Computer
Enable Open Ports
Start Port
End Port
 IP Object
Objects Settings
Set to Factory Default Clear all profiles
 Interface Choose a proper interface WAN, LAN or Any
Allowed
Address Type
Start IP Address
 Selected IP Objects
IP Group
Available IP Objects
 Service Type Object
 Service Type Group
 CSM Profile
Name Available Service Type Objects Selected Service Type
 Profile Name
 Firewall Facilities
Firewall
Basics for Firewall
 Stateful Packet Inspection SPI
IP Filters
 Content Filtering
Content Security Management CSM
Denial of Service DoS Defense
 Anti-Virus and Anti-Intrusion
Web Filtering
 Call Filter
Content Security
Data Filter
Filter
 Filter Rule
Filter Setup
Move Up/Down
Next Filter Set
 Filter Rule Comments
Check to enable
Direction
Source/Destination IP
 Service Type
 Example
 VigorPro5500 Series User’s Guide
 DoS Defense
 Block Land
Block IP options
Block Smurf
Block trace router
 VigorPro5500 Series User’s Guide
 Control
URL Content Filter
White List pass those
Matching keyword
 Exe, .com, .scr, .pif, .bas, .bat, .inf, .reg
Zip, rar, .arj, .ace, .cab, .sit
Inside to outside world to protect the local users privacy
Files downloading from web pages. Accordingly, files with
 Web Content Filter
 Anti-Intrusion
Basic Setup
Service
 Advanced Setup
 Maintenance Syslog/Mail Alert
Here and enable the SysLog Access Setup from System
Type links
Severity
 Action
 Anti-Virus
Profile Setting
 Syslog/Mail Alert
Enable Virus Scan
Enable Log
 Virus List
 Detailed View for Anti-Virus
File Pattern List
 Enable Syslog/Mail Alert
Default Action
Destroy the file if the file
Name is over length
 For Default Action For default action
 Message
Service Activation
Anti-Spam
 Problem
Timeout or Network
Choose Protocol to Scan
Spam
 Bandwidth Management
Cancel
Activating Anti-Spam
Clear
 Sessions Limit
 Default RX limit
Default TX limit
Bandwidth Limit
Set in that web
 RX limit
Quality of Service
TX limit
 General Setup for WAN Interface
 Reserved Bandwidth Ratio
Enable UDP Bandwidth
Reserved bandwidth to upstream speed and reserved
Bandwidth to downstream speed
 Edit the Class Rule for QoS
ManagementQuality of Service
 DiffServ CodePoint
Local Address
Remote Address
 Edit the Service Type for Class Rule
 Port Configuration
 Applications
Enable the Function and Add a Dynamic DNS Account
Dynamic DNS
Index WAN Interface
 Enable Dynamic
Force Update
Service Provider
Login Name
 Set to Factory Default
Disable the Function and Clear all Dynamic DNS Accounts
Schedule
Delete a Dynamic DNS Account
 Idle Timeout
Enable Schedule Setup
Start Date yyyy-mm-dd
Start Time hhmm
 Server IP Address
Radius
Destination Port
Shared Secret
 UPnP
 Cant work with Firewall Software
 Wake by
Wake On LAN
MAC Address
Wake Up
 Remote Access Control
VPN and Remote Access
 PPP General Setup
 IPSec General Setup
 IPSec Security Method
IPSec Peer Identity
 107
 User
Remote Dial-in User
 Specify Remote Node
Enable this account
IPSec Tunnel
 Check to enable Callback function -Enables the callback
Medium -Authentication Header AH means data will be
Check to enable callback budget control -By default,
User Name
 LAN to LAN
 Call Direction
Enable this profile
VPN Connection Through
 Enable Ping to Keep Alive is used to handle abnormal
Enable Ping to keep alive
PPP Authentication
Ping to the IP
 VPN and Remote Access IPSec Peer Identity
IKE Authentication
Medium AH Authentication Header means data will be
3DES without Authentication -Use triple DES encryption
 Provide Isdn Number to Remote- In the case that
Perfect Forward Secret PFS- The IKE Phase 1 key will be
For i models only
 Allowed Dial-In Type
 Check to enable Callback function-Enables the callback
Profiles set in the VPN and Remote Access IPSec Peer
Specify Clid or Remote
VPN Gateway
 From first subnet to remote network, you have to do
Change default route to this VPN tunnel
 Refresh Seconds
Connection Management
Dial
 Generate
Certificate Management
Local Certificate
 View
Import
 Trusted CA Certificate
 Basic Concept
Certificate Backup
Isdn
 General Settings
 Dial to Single/Dual ISPs
PPP/MP Setup
Require ISP Callback Cbcp If your ISP supports
Call Control
 Method Ipcp
Common Settings
Check Yes and enter the IP address in the field of Fixed IP
Function. Require ISP Callback Cbcp If your ISP
 Password Enter the password provided by your ISP
Primary ISP Setup ISP Name Enter your ISP name
Secondary ISP Setup ISP Name Enter the secondary ISP name
Your ISP
 Virtual TA
 Virtual TA User Profiles
Install a Virtual TA Client
Virtual TA Server
 User Profile
Configure a Virtual TA Client/ Server
MSN Configuration
 Call Control
Call Control Setup
 Basic Setup
 Security Overview
Wireless LAN
Basic Concepts
 Example
 Mixed 11b+11g+SuperG The radio can support
Enable Wireless LAN
 Long Preamble
Channel
Hide Ssid
 Security
 Enable Access Control
Access Control
 Clear All
MAC Address Filter
Attribute
 14.5 WDS
 Choose the mode for WDS setting. Disable mode will not
 AP Discovery
 Station List
Into Access Control
 Station Rate Control
Wired Vlan
Vlan
 VLAN0-3
Wireless Vlan
P1 P4
 Wvlan
Login ID
 How can you wireless client access into Internet?
 Vlan Cross Setup
 WVLAN0-15
 Download Rate
Wireless Rate Control
Upload Rate
 System Status
System Maintenance
 Default Gateway
Administrator Password
Old Password
New Password
 Backup the Configuration
Configuration Backup
 Syslog/Mail Alert
Restore Configuration
 Return-Path
Authentication
Mail To
 Time and Date
 Management
 Trap Timeout
Reboot System
Manager Host IP
Trap Community
 Firmware Upgrade
 License
Signature Upgrade
 Signature
Authentication/downl
Oad message Upgrade Manually
 Automatically
 Dial-out Trigger
Diagnostics
Decoded Format
Address, the protocol and length of the package
 ARP Cache Table
Routing Table
 Leased Time
Dhcp Table
NAT Sessions Table
 Wireless Vlan Online Station Table
 Ping to
Ping Diagnosis
Ping through
 Order by
Data Flow Monitor
 TX rate kbps
Traffic Graph
RX rate kbps
Sessions
 Trace through
Trace Route
 Creating and Activating an Account from VigorPro Website
Registration for the Router
 172
 173
 174
 175
 176
 177
 178
 179
 Registering Your Vigor Router
From System Maintenance Signature Upgrade
 181
 182
 From Anti-SpamProfile Setting
 184
 For Anti-Virus and Anti-Intrusion Service
Activating Anti-Virus/Anti-Intrusion/Anti-Spam Service
 186
 187
 Back
Rename
Transfer
 189
 Getting 30 Days of Free Charge
For Anti-Spam Service
 191
 192
 193
 Upgrade License for Anti-Spam
 195
 196
 197
 Applying a New License for Anti-Intrusion/Anti-Virus
 199
 200
 201
 202
 Add License
 204
 Backup and Upgrade Signature for Anti-Intrusion/Anti-Virus
 Time for Backup
Switching between DT-DT and DT-KL
Time for Download
Time for Import
 207
 208
 Enabling Anti-Virus/Anti-Intrusion/Anti-Spam
 210
 Application and Examples
 212
 213
 214
 215
 216
 217
 Settings in VPN Router in the enterprise office
 219
 Settings in the remote host
 221
 Go to Bandwidth ManagementQuality of Service
QoS Setting Example
 223
 224
 LAN Created by Using NAT
 226
 Upgrade Firmware for Your Router
 228
 Request a certificate from a CA server on Windows CA Server
 Go to Certificate Management and choose Local Certificate
 231
 232
 233
 Time and Date to reset current time of the router first
 Checking If the Hardware Status Is OK or Not
Trouble Shooting
 For Windows
 For MacOs
 For MacOs Terminal
Pinging the Router from Your Computer
 For PPPoE Users
Checking If the ISP Settings are OK or Not
 For Static/Dynamic IP Users
 For Pptp Users
Backing to Factory Default Setting If Necessary
Software Reset
 Contacting Your Dealer
Hardware Reset