Prestige
Disclaimer
Copyright
Trademarks
Federal Communications Commission FCC Interference Statement
Information for Canadian Users
Version
Declaration of Conformity
P312 Broadband Security Gateway CE Doc
ZyXEL Limited Warranty
Information in Menu 24.2.1 -System Information
Customer Support
Table of Contents
LAN Port Filter Setup Chapter
Advanced Management
12-1
13-1
Firewall and Content Filters
17-1
Pptp
21-1
Menu 11.1 Remote Node Profile for Ethernet Encapsulation
List of Figures
List Of Figures Xvii
Xviii
List Of Figures Xix
Menu 21 Filter and Firewall Setup 14-1
List Of Figures Xxi
Page
List Of Tables
Xxiv
List of Tables Xxv
Page
About Your Router
Preface
Structure of this Manual
Syntax Conventions
Related Documentation
Part
Page
Getting to Know Your Prestige
Features of The Prestige
Prestige 312 Broadband Security Gateway
Time and Date Setting
Dhcp Dynamic Host Configuration Protocol
Dynamic DNS Support
IP Multicast
Upgrade Prestige Firmware via LAN
Broadband Internet Access via Cable or xDSL Modem
Applications for Prestige
Logging and Tracing
Secure Internet Access via DSL
Front Panel LEDs and Back Panel Ports
Hardware Installation & Initial Setup
Front Panel LEDs
LED functions
WAN
Prestige 312 Rear Panel and Connections
Additional Installation Requirements
Power Up Your Prestige
Housing
Entering Password
Initial Screen
Navigating the SMT Interface
Main Menu Commands
Operation Keystrokes Description
Enter
System Management Terminal Interface Summary
Main Menu
Prestige 312 Main Menu
Main Menu Summary
Resetting the Prestige
Changing the System Password
Dynamic DNS
General Setup
Dyndns Wildcard
General Setup Menu Field
Configuring Dynamic DNS
Configure Menu 1.1 Configure Dynamic DNS discussed next
Field Description Example
Configure Dynamic DNS Menu Fields
WAN Setup
Yes
Me.ddns.org
WAN Setup Menu Fields
LAN Setup
10 Menu 3 LAN Setup
LAN Port Filter Setup
Factory LAN Defaults
Internet Access
TCP/IP and Dhcp for LAN
IP Address and Subnet Mask
Private IP Addresses
RIP Setup
IP Pool Setup
Dhcp Configuration
IP Multicast
DNS Server Address
IP Alias
TCP/IP and Dhcp Ethernet Setup
Physical Network Partitioned Logical Networks
Menu 3 LAN Setup 10/100 Mbps Ethernet
LAN TCP/IP Setup Menu Fields
LAN Dhcp Setup Menu Fields
Menu 3.2.1 IP Alias Setup
IP Alias Setup
IP Alias Setup Menu Fields
Ethernet Encapsulation
Internet Access Setup
Only/Out Only
RIP-1
Pptp Encapsulation
Internet Access Setup Menu Fields
PPPoE Encapsulation
Configuring the Pptp Client
New Fields in Menu 4 Pptp screen
Prestige automatically disconnects from the Pptp server
Internet Access Setup PPPoE
New Fields in Menu 4 PPPoE screen
Basic Setup Complete
Advanced Applications
Remote Node Profile
Remote Node Setup
Fields in Menu
Nailed-Up Connection
Fields in Menu 11.1 PPPoE Encapsulation Specific
Fields in Menu 11.1 Pptp Encapsulation
Remote Node Network Layer Options Menu Fields
Editing TCP/IP Options with Ethernet Encapsulation
Private
Editing TCP/IP Options with Pptp Encapsulation
Version
2B/RIP-2M and None Multicast
Remote Node Network Layer Options
Editing TCP/IP Options with PPPoE Encapsulation
Remote Node Filter
Yes/No
None/In Only/Out Only and None
Remote Node Filter Ethernet Encapsulation
Example of Static Routing Topology
IP Static Route Setup
Menu 12 IP Static Route Setup
IP Static Route Setup
Field Description
IP Static Route Menu Fields
Page
Introduction
Network Address Translation NAT
NAT Definitions
What NAT Does
NAT Mapping Types
How NAT works
NAT Mapping Types
SUA Single User Account Versus NAT
Type IP Mapping SMT abbreviation
NAT Application
SMT Menus
Applying NAT in the SMT Menus
Applying NAT for Internet Access
Field Options Description Network Full Feature
Configuring NAT
Address Mapping Sets and NAT Server Sets
Applying NAT in Menus 4
Menu 15.1 Address Mapping Sets
Server
Field Description Options/Example
Menu
Ordering Your Rules
Editing an Individual Rule in a Set
Menu 15.1.1.1 configuring an individual rule
Multiple Servers behind NAT
NAT Server Sets
10 Multiple Servers Behind NAT
Configuring a Server behind NAT
Services Port Number
Internet Access Only
Examples
NAT Example
13 Internet Access & NAT Example
Example 3 General Case
Example 2 Internet Access with an Inside Server
16 NAT Example
17 Example 3 Menu
19 Example 3 Final Menu
21 NAT Example
Example 4 -NAT Unfriendly Application Programs
22 Example 4- Menu 15.1.1.1 Address Mapping Rule
Advanced Management
Page
About Filtering
Filter Configuration
Filter Structure of the Prestige
Rule Forward Drop
Filter Rule Process
Menu 21 Filter and Firewall Setup
Configuring a Filter Set
NetBIOSWAN Filter Rules Summary
Abbreviations Used in the Filter Rules Summary Menu
Filter Rules Summary Menu
Abbreviations Description Display
Action Not Matched will be N/A Refers to Action Matched
3 TCP/IP Filter Rule
Configuring a Filter Rule
Abbreviations Used If Filter Type Is IP
Abbreviations Used If Filter Type Is GEN
TCP/IP Filter Rule Menu Fields
Menu 21.1.1.1 TCP/IP Filter Rule
Equal/Not Equal
None/Less/Greater
Yes / No
Action Matched
Following diagram illustrates the logic flow of an IP filter
10 Executing an IP Filter
11 Menu 21.4.1.1 Generic Filter Rule
Generic Filter Rule
Generic Filter Rule Menu Fields
12 Telnet Filter Example
Example Filter
13 Example Filter Menu
14 Example Filter Rules Summary Menu
Filter Types and NAT
Firewall
Applying a Filter and Factory Defaults
LAN traffic
16 Filtering LAN Traffic
Remote Node Filters
Configuring Snmp
Snmp Configuration
About Snmp
Field Description Default
Snmp Configuration Menu Fields
System Information & Diagnosis
Menu 24 System Maintenance
System Status
Menu 24.1 System Maintenance Status
PPPoE Encapsulation
System Maintenance Status Menu Fields
LAN
Dhcp
System Information
System Information and Console Port Speed
Log and Trace
Fields in System Maintenance
Console Port Speed
Unix Syslog
Viewing Error Log
Parameter Description
System Maintenance Menu Syslog Parameters
CDR
CDR
PPP log
Call-Triggering Packet
Diagnostic
WAN Dhcp
10 Menu 24.4 System Maintenance Diagnostic
Internet Setup in Menu 4 Internet Access
System Maintenance Menu Diagnostic
Number Field Description
Filename conventions
Transferring Files
Command
Backup Configuration
Firmware Development
Filename Conventions
Upload Firmware
Restore Configuration
Uploading the Router Firmware
Menu 24.7.1 System Maintenance Upload Router Firmware
Uploading Router Configuration File
Tftp File Transfer
Third Party Tftp Clients -General fields
Example Tftp Command
Telnet into Menu
FTP File Transfer
Telnet into Menu 24.7.2 System Maintenance
Using the FTP command from the DOS Prompt
Third Party FTP Clients -General fields
Page
Command Interpreter Mode
System Maintenance & Information
Valid Commands
Budget Management
Call Control Support
Call Control
Call History
Call History
How often does the Prestige update the time?
Time and Date Setting
Call History Fields
System Maintenance & Information 11-5
Menu 24.11 Remote Management Control
Remote Management Setup
Option to Enter Debug Mode
Boot Commands
Boot Module Commands
About Telnet Configuration
Telnet Configuration and Capabilities
Single Administrator
Telnet Under NAT
Telnet Under the Firewall
System Timeout
Firewall and Content Filters
Types of Firewalls
What is a Firewall
Packet Filtering Firewalls
Application-level Firewalls
Stateful Inspection firewalls
Introduction to ZyXEL’s Firewall
Basics
Denial of Service
Common IP Ports
Types of DoS attacks
SYN Flood
Smurf Attack
Stateful Inspection
Stateful Inspection
Stateful Inspection Process
TCP Security
Stateful Inspection & the Prestige
13.4.4 UDP/ICMP Security
Guidelines For Enhancing Security With Your Firewall
Upper Layer Protocols
Security In General
What Is a Firewall? 13-11
Page
SMT Main Menu
Introducing the Prestige Firewall
Attack Types
View Firewall Log
Land
IP Spoofing
Illegal Commands NetBIOS and Smtp
Icmp Commands That Trigger Alerts
Legal NetBIOS Commands
Legal Smtp Commands
Teardrop
Traceroute
Big Picture Filtering, Firewall and NAT
Packet Filtering
Packet Filtering Vs Firewall
When To Use The Firewall
When To Use Filtering
Firewall
Page
Web Configurator Login and Welcome Screens
Introducing the Prestige Web Configurator
Enabling the Firewall
Prestige Web Configurator Welcome Screen
What are Alerts?
Mail
Mail Screen
What are Logs?
Mail
Smtp Error Messages
Smtp Error Messages
Example E-Mail Log
Mail Log
Attack Alert
Half-Open Sessions
Threshold Values
TCP Maximum Incomplete And Blocking Time
Attack Alert
Existing half-open sessions
Field Description Default Values
Do not set Maximum Incomplete High to
When TCP Maximum Incomplete is
Page
Creating Custom Rules
Rule Checklist
Rules Overview
Rule Logic Overview
Security Ramifications
Key Fields For Configuring Rules
LAN to WAN Rules
Connection Direction
WAN to LAN Rules
WAN to LAN Traffic
Services Supported
Service Description
Services Supported
Firewall Rules Summary First Screen
Rule Summary
Match
Block
Field Description Option
Creating/Editing Firewall Rules
Creating/Editing a Firewall Rule
Source & Destination Addresses
Single Address
Adding/Editing Source & Destination Addresses
Range Address
Subnet Address
Factors Influencing Choices for Timeout Values
Timeout
Timeout Screen
Field Description Default Value
Timeout Menu
Hour
Custom Ports
Custom Ports
Creating/Editing a Custom Port
Creating/Editing a Custom Port
Range
Single
Log Screen
Logs
Log Screen
Command, traceroute, teardrop, or syn
Vulnerability, NetBIOS, smtp illegal
Jan 1
Src IP, dest port, src port and protocol
Logs 18-3
Page
Example Firewall Rules
Activate The Firewall
Example 1 E-Mail Screen
Example 1 Configuring a Rule
Example Firewall Rules 19-5
Example 1 Rule Summary Screen
Example 2 Small Office With Mail, FTP and Web Servers
Send Alerts When Attacked
Configuring a POP Custom Port
Example 2 Local Network Rule 1 Configuration
Example 2 Local Network Rule Summary
10 Example 2 Internet to Local Network Rule Summary
11 Custom Port for Syslog
12 Syslog Rule Configuration
13 Example 3 Rule Summary
Restrict Web Features
Content Filtering
ActiveX
Java
Blocking URLs
Content Filtering Using the Web Configurator
Cookies
Web Proxy
Field Description Restrict Web Features
Content Filtering Fields
Block Web URLs
Troubleshooting, Appendices, Glossary and Index
Page
Problems Starting Up the Prestige
Troubleshooting
Troubleshooting the Start-Up of your Prestige
Problem Corrective Action
Problems with the WAN interface
Problems with the LAN Interface
Troubleshooting the LAN Interface
Troubleshooting the WAN interface
Problems with the Firewall
Problems with Internet Access
Troubleshooting Internet Access
Page
Appendix a PPPoE
Diagram 1 Single-PC per Modem Hardware Configuration
PPPoE in Action
Benefits of PPPoE
How PPPoE Works
Diagram 2 Prestige as a PPPoE Client
Prestige as a PPPoE Client
Appendix B
What is PPTP?
Pptp and the Prestige
Pptp Protocol Overview
Control & PPP connections
Mtbf
Appendix C Hardware Specifications
IRD + OTD +
Appendix D Important Safety Instructions
Function CLI Syntax
Appendix E Firewall CLI Commands
Sets
Function CLI Syntax Description
P312 Broadband Security Gateway
Delete
AC Power Adapter Specifications
Appendix F Power Adapter Specs
P312 Broadband Security Gateway
ARP
Glossary of Terms
CDR Chap
CSU/DSU DCE
Dslam
Dram DSL
DTE
EMI
FCC
FAQ
FTP
Hdlc
IRC ISP
Ipcp PPP IPX
MAC
Ndis
NAT
NIC
PAP
Pots PPP
POP
Pstn
RFC
PVC
RIP
SAP
STP
Spam
SUA TCP
Tftp
VPN
Page
Ddns
Index
Encapsulation
2-11, 2-12, 3-4
13-6
15-1 ZyNOS