VigorPro 5500 Series Unified Security Firewall User’s Guide
Instructions
Safety Instructions and Approval
Regulatory Information
European Community Declarations
Table of Contents
100
211
171
Trouble Shooting 235
Page
LED Indicators and Connectors
Web Configuration Buttons Explanation
LED
For VigorPro
Wlan
For VigorPro 5500G
Isdn
For VigorPro 5500Gi
Interface Description
Internet
Hardware Installation
VigorPro5500 Series User’s Guide
Changing Password
Configuring Basic Settings
Now, the Main Screen will pop up
Quick Start Wizard
PPPoE
VigorPro5500 Series User’s Guide
Pptp
Static IP
Dhcp
Online Status
Online status for Dhcp
Displays the IP address of the default gateway
Saving Configuration
This page is left blank
Basics of Internet Protocol IP Network
WAN
What are Public IP Address and Private IP Address
Get Your Public IP Address from ISP
Enable
General Setup
Physical Mode
Display Name
Active Mode
Load Balance Mode
Physical Type
Negotiation for determined by the system
Access Mode
Internet Access
Index
Details
Details Page for PPPoE
Details Page for Static or Dynamic IP
Dhcp Client
Settings
Keep WAN
Connection
Address
DNS Server IP
PPP Setup
Pptp Setup
Details Page for Pptp
Assignment
MAC address for the router
Load-Balance Policy
WAN
Protocol
Dest Port End
Binding WAN
Interface Src IP Start
Basics of LAN
LAN
What are Virtual LANs and Rate Control
What is Routing Information Protocol RIP
What is Static Route
Subnet
1st IP Address 1st Subnet Mask For IP Routing Usage
Relay Agent 1st subnet/2nd subnet Specify which subnet that
Configuration
Dhcp Server
DNS Server
Static Route
Add Static Routes to Private and Public Networks
VigorPro5500 Series User’s Guide
Vlan
Bind IP to MAC
Disable
Strict Bind
ARP Table
NAT
Port Redirection
Private IP
Service Name
Public Port
Active
Private Port
True…
DMZ Host
Choose PC
Comment
Open Ports
WAN Interface
Local IP Address
Local Computer
Enable Open Ports
Start Port
End Port
IP Object
Objects Settings
Set to Factory Default Clear all profiles
Interface Choose a proper interface WAN, LAN or Any
Allowed
Address Type
Start IP Address
Selected IP Objects
IP Group
Available IP Objects
Service Type Object
Service Type Group
CSM Profile
Name Available Service Type Objects Selected Service Type
Profile Name
Firewall Facilities
Firewall
Basics for Firewall
Stateful Packet Inspection SPI
IP Filters
Content Filtering
Content Security Management CSM
Denial of Service DoS Defense
Anti-Virus and Anti-Intrusion
Web Filtering
Call Filter
Content Security
Data Filter
Filter
Filter Rule
Filter Setup
Move Up/Down
Next Filter Set
Filter Rule Comments
Check to enable
Direction
Source/Destination IP
Service Type
Example
VigorPro5500 Series User’s Guide
DoS Defense
Block Land
Block IP options
Block Smurf
Block trace router
VigorPro5500 Series User’s Guide
Control
URL Content Filter
White List pass those
Matching keyword
Exe, .com, .scr, .pif, .bas, .bat, .inf, .reg
Zip, rar, .arj, .ace, .cab, .sit
Inside to outside world to protect the local users privacy
Files downloading from web pages. Accordingly, files with
Web Content Filter
Anti-Intrusion
Basic Setup
Service
Advanced Setup
Maintenance Syslog/Mail Alert
Here and enable the SysLog Access Setup from System
Type links
Severity
Action
Anti-Virus
Profile Setting
Syslog/Mail Alert
Enable Virus Scan
Enable Log
Virus List
Detailed View for Anti-Virus
File Pattern List
Enable Syslog/Mail Alert
Default Action
Destroy the file if the file
Name is over length
For Default Action For default action
Message
Service Activation
Anti-Spam
Problem
Timeout or Network
Choose Protocol to Scan
Spam
Bandwidth Management
Cancel
Activating Anti-Spam
Clear
Sessions Limit
Default RX limit
Default TX limit
Bandwidth Limit
Set in that web
RX limit
Quality of Service
TX limit
General Setup for WAN Interface
Reserved Bandwidth Ratio
Enable UDP Bandwidth
Reserved bandwidth to upstream speed and reserved
Bandwidth to downstream speed
Edit the Class Rule for QoS
ManagementQuality of Service
DiffServ CodePoint
Local Address
Remote Address
Edit the Service Type for Class Rule
Port Configuration
Applications
Enable the Function and Add a Dynamic DNS Account
Dynamic DNS
Index WAN Interface
Enable Dynamic
Force Update
Service Provider
Login Name
Set to Factory Default
Disable the Function and Clear all Dynamic DNS Accounts
Schedule
Delete a Dynamic DNS Account
Idle Timeout
Enable Schedule Setup
Start Date yyyy-mm-dd
Start Time hhmm
Server IP Address
Radius
Destination Port
Shared Secret
UPnP
Cant work with Firewall Software
Wake by
Wake On LAN
MAC Address
Wake Up
Remote Access Control
VPN and Remote Access
PPP General Setup
IPSec General Setup
IPSec Security Method
IPSec Peer Identity
107
User
Remote Dial-in User
Specify Remote Node
Enable this account
IPSec Tunnel
Check to enable Callback function -Enables the callback
Medium -Authentication Header AH means data will be
Check to enable callback budget control -By default,
User Name
LAN to LAN
Call Direction
Enable this profile
VPN Connection Through
Enable Ping to Keep Alive is used to handle abnormal
Enable Ping to keep alive
PPP Authentication
Ping to the IP
VPN and Remote Access IPSec Peer Identity
IKE Authentication
Medium AH Authentication Header means data will be
3DES without Authentication -Use triple DES encryption
Provide Isdn Number to Remote- In the case that
Perfect Forward Secret PFS- The IKE Phase 1 key will be
For i models only
Allowed Dial-In Type
Check to enable Callback function-Enables the callback
Profiles set in the VPN and Remote Access IPSec Peer
Specify Clid or Remote
VPN Gateway
From first subnet to remote network, you have to do
Change default route to this VPN tunnel
Refresh Seconds
Connection Management
Dial
Generate
Certificate Management
Local Certificate
View
Import
Trusted CA Certificate
Basic Concept
Certificate Backup
Isdn
General Settings
Dial to Single/Dual ISPs
PPP/MP Setup
Require ISP Callback Cbcp If your ISP supports
Call Control
Method Ipcp
Common Settings
Check Yes and enter the IP address in the field of Fixed IP
Function. Require ISP Callback Cbcp If your ISP
Password Enter the password provided by your ISP
Primary ISP Setup ISP Name Enter your ISP name
Secondary ISP Setup ISP Name Enter the secondary ISP name
Your ISP
Virtual TA
Virtual TA User Profiles
Install a Virtual TA Client
Virtual TA Server
User Profile
Configure a Virtual TA Client/ Server
MSN Configuration
Call Control
Call Control Setup
Basic Setup
Security Overview
Wireless LAN
Basic Concepts
Example
Mixed 11b+11g+SuperG The radio can support
Enable Wireless LAN
Long Preamble
Channel
Hide Ssid
Security
Enable Access Control
Access Control
Clear All
MAC Address Filter
Attribute
14.5 WDS
Choose the mode for WDS setting. Disable mode will not
AP Discovery
Station List
Into Access Control
Station Rate Control
Wired Vlan
Vlan
VLAN0-3
Wireless Vlan
P1 P4
Wvlan
Login ID
How can you wireless client access into Internet?
Vlan Cross Setup
WVLAN0-15
Download Rate
Wireless Rate Control
Upload Rate
System Status
System Maintenance
Default Gateway
Administrator Password
Old Password
New Password
Backup the Configuration
Configuration Backup
Syslog/Mail Alert
Restore Configuration
Return-Path
Authentication
Mail To
Time and Date
Management
Trap Timeout
Reboot System
Manager Host IP
Trap Community
Firmware Upgrade
License
Signature Upgrade
Signature
Authentication/downl
Oad message Upgrade Manually
Automatically
Dial-out Trigger
Diagnostics
Decoded Format
Address, the protocol and length of the package
ARP Cache Table
Routing Table
Leased Time
Dhcp Table
NAT Sessions Table
Wireless Vlan Online Station Table
Ping to
Ping Diagnosis
Ping through
Order by
Data Flow Monitor
TX rate kbps
Traffic Graph
RX rate kbps
Sessions
Trace through
Trace Route
Creating and Activating an Account from VigorPro Website
Registration for the Router
172
173
174
175
176
177
178
179
Registering Your Vigor Router
From System Maintenance Signature Upgrade
181
182
From Anti-SpamProfile Setting
184
For Anti-Virus and Anti-Intrusion Service
Activating Anti-Virus/Anti-Intrusion/Anti-Spam Service
186
187
Back
Rename
Transfer
189
Getting 30 Days of Free Charge
For Anti-Spam Service
191
192
193
Upgrade License for Anti-Spam
195
196
197
Applying a New License for Anti-Intrusion/Anti-Virus
199
200
201
202
Add License
204
Backup and Upgrade Signature for Anti-Intrusion/Anti-Virus
Time for Backup
Switching between DT-DT and DT-KL
Time for Download
Time for Import
207
208
Enabling Anti-Virus/Anti-Intrusion/Anti-Spam
210
Application and Examples
212
213
214
215
216
217
Settings in VPN Router in the enterprise office
219
Settings in the remote host
221
Go to Bandwidth ManagementQuality of Service
QoS Setting Example
223
224
LAN Created by Using NAT
226
Upgrade Firmware for Your Router
228
Request a certificate from a CA server on Windows CA Server
Go to Certificate Management and choose Local Certificate
231
232
233
Time and Date to reset current time of the router first
Checking If the Hardware Status Is OK or Not
Trouble Shooting
For Windows
For MacOs
For MacOs Terminal
Pinging the Router from Your Computer
For PPPoE Users
Checking If the ISP Settings are OK or Not
For Static/Dynamic IP Users
For Pptp Users
Backing to Factory Default Setting If Necessary
Software Reset
Contacting Your Dealer
Hardware Reset