Prestige
Copyright
Disclaimer
Trademarks
Federal Communications Commission FCC Interference Statement
Information for Canadian Users
Version
Declaration of Conformity
P312 Broadband Security Gateway CE Doc
ZyXEL Limited Warranty
Information in Menu 24.2.1 -System Information
Customer Support
Table of Contents
LAN Port Filter Setup Chapter
Advanced Management
12-1
13-1
Firewall and Content Filters
17-1
Pptp
21-1
Menu 11.1 Remote Node Profile for Ethernet Encapsulation
List of Figures
List Of Figures Xvii
Xviii
List Of Figures Xix
Menu 21 Filter and Firewall Setup 14-1
List Of Figures Xxi
Page
List Of Tables
Xxiv
List of Tables Xxv
Page
Preface
About Your Router
Structure of this Manual
Syntax Conventions
Related Documentation
Part
Page
Features of The Prestige
Getting to Know Your Prestige
Prestige 312 Broadband Security Gateway
Time and Date Setting
Dhcp Dynamic Host Configuration Protocol
Dynamic DNS Support
IP Multicast
Upgrade Prestige Firmware via LAN
Broadband Internet Access via Cable or xDSL Modem
Applications for Prestige
Logging and Tracing
Secure Internet Access via DSL
Front Panel LEDs and Back Panel Ports
Hardware Installation & Initial Setup
Front Panel LEDs
LED functions
WAN
Prestige 312 Rear Panel and Connections
Additional Installation Requirements
Power Up Your Prestige
Housing
Entering Password
Initial Screen
Navigating the SMT Interface
Main Menu Commands
Operation Keystrokes Description
Enter
System Management Terminal Interface Summary
Main Menu
Prestige 312 Main Menu
Main Menu Summary
Resetting the Prestige
Changing the System Password
General Setup
Dynamic DNS
Dyndns Wildcard
General Setup Menu Field
Configuring Dynamic DNS
Configure Menu 1.1 Configure Dynamic DNS discussed next
Field Description Example
Configure Dynamic DNS Menu Fields
WAN Setup
Yes
Me.ddns.org
WAN Setup Menu Fields
LAN Setup
10 Menu 3 LAN Setup
LAN Port Filter Setup
Factory LAN Defaults
Internet Access
TCP/IP and Dhcp for LAN
IP Address and Subnet Mask
Private IP Addresses
RIP Setup
IP Pool Setup
Dhcp Configuration
IP Multicast
DNS Server Address
TCP/IP and Dhcp Ethernet Setup
IP Alias
Physical Network Partitioned Logical Networks
Menu 3 LAN Setup 10/100 Mbps Ethernet
LAN TCP/IP Setup Menu Fields
LAN Dhcp Setup Menu Fields
IP Alias Setup
Menu 3.2.1 IP Alias Setup
IP Alias Setup Menu Fields
Ethernet Encapsulation
Internet Access Setup
Only/Out Only
RIP-1
Pptp Encapsulation
Internet Access Setup Menu Fields
PPPoE Encapsulation
Configuring the Pptp Client
New Fields in Menu 4 Pptp screen
Prestige automatically disconnects from the Pptp server
Internet Access Setup PPPoE
New Fields in Menu 4 PPPoE screen
Basic Setup Complete
Advanced Applications
Remote Node Profile
Remote Node Setup
Fields in Menu
Nailed-Up Connection
Fields in Menu 11.1 PPPoE Encapsulation Specific
Fields in Menu 11.1 Pptp Encapsulation
Remote Node Network Layer Options Menu Fields
Editing TCP/IP Options with Ethernet Encapsulation
Private
Editing TCP/IP Options with Pptp Encapsulation
Version
2B/RIP-2M and None Multicast
Remote Node Network Layer Options
Editing TCP/IP Options with PPPoE Encapsulation
Remote Node Filter
Yes/No
None/In Only/Out Only and None
Remote Node Filter Ethernet Encapsulation
Example of Static Routing Topology
IP Static Route Setup
Menu 12 IP Static Route Setup
IP Static Route Setup
Field Description
IP Static Route Menu Fields
Page
Introduction
Network Address Translation NAT
NAT Definitions
What NAT Does
NAT Mapping Types
How NAT works
SUA Single User Account Versus NAT
NAT Mapping Types
Type IP Mapping SMT abbreviation
SMT Menus
NAT Application
Applying NAT in the SMT Menus
Applying NAT for Internet Access
Field Options Description Network Full Feature
Configuring NAT
Address Mapping Sets and NAT Server Sets
Applying NAT in Menus 4
Menu 15.1 Address Mapping Sets
Server
Field Description Options/Example
Menu
Ordering Your Rules
Editing an Individual Rule in a Set
Menu 15.1.1.1 configuring an individual rule
Multiple Servers behind NAT
NAT Server Sets
10 Multiple Servers Behind NAT
Configuring a Server behind NAT
Internet Access Only
Services Port Number
Examples
NAT Example
13 Internet Access & NAT Example
Example 3 General Case
Example 2 Internet Access with an Inside Server
16 NAT Example
17 Example 3 Menu
19 Example 3 Final Menu
21 NAT Example
Example 4 -NAT Unfriendly Application Programs
22 Example 4- Menu 15.1.1.1 Address Mapping Rule
Advanced Management
Page
About Filtering
Filter Configuration
Filter Structure of the Prestige
Rule Forward Drop
Filter Rule Process
Menu 21 Filter and Firewall Setup
Configuring a Filter Set
NetBIOSWAN Filter Rules Summary
Abbreviations Used in the Filter Rules Summary Menu
Filter Rules Summary Menu
Abbreviations Description Display
Action Not Matched will be N/A Refers to Action Matched
3 TCP/IP Filter Rule
Configuring a Filter Rule
Abbreviations Used If Filter Type Is IP
Abbreviations Used If Filter Type Is GEN
TCP/IP Filter Rule Menu Fields
Menu 21.1.1.1 TCP/IP Filter Rule
Equal/Not Equal
None/Less/Greater
Yes / No
Action Matched
Following diagram illustrates the logic flow of an IP filter
10 Executing an IP Filter
11 Menu 21.4.1.1 Generic Filter Rule
Generic Filter Rule
Generic Filter Rule Menu Fields
12 Telnet Filter Example
Example Filter
13 Example Filter Menu
14 Example Filter Rules Summary Menu
Filter Types and NAT
Applying a Filter and Factory Defaults
Firewall
LAN traffic
16 Filtering LAN Traffic
Remote Node Filters
Snmp Configuration
Configuring Snmp
About Snmp
Field Description Default
Snmp Configuration Menu Fields
System Information & Diagnosis
Menu 24 System Maintenance
System Status
Menu 24.1 System Maintenance Status
PPPoE Encapsulation
System Maintenance Status Menu Fields
LAN
Dhcp
System Information
System Information and Console Port Speed
Fields in System Maintenance
Log and Trace
Console Port Speed
Unix Syslog
Viewing Error Log
System Maintenance Menu Syslog Parameters
Parameter Description
CDR
CDR
PPP log
Call-Triggering Packet
Diagnostic
WAN Dhcp
10 Menu 24.4 System Maintenance Diagnostic
System Maintenance Menu Diagnostic
Internet Setup in Menu 4 Internet Access
Number Field Description
Filename conventions
Transferring Files
Command
Backup Configuration
Firmware Development
Filename Conventions
Restore Configuration
Upload Firmware
Uploading the Router Firmware
Menu 24.7.1 System Maintenance Upload Router Firmware
Uploading Router Configuration File
Tftp File Transfer
Third Party Tftp Clients -General fields
Example Tftp Command
Telnet into Menu
FTP File Transfer
Telnet into Menu 24.7.2 System Maintenance
Using the FTP command from the DOS Prompt
Third Party FTP Clients -General fields
Page
System Maintenance & Information
Command Interpreter Mode
Valid Commands
Call Control Support
Budget Management
Call Control
Call History
Call History
Time and Date Setting
How often does the Prestige update the time?
Call History Fields
System Maintenance & Information 11-5
Menu 24.11 Remote Management Control
Remote Management Setup
Option to Enter Debug Mode
Boot Commands
Boot Module Commands
About Telnet Configuration
Telnet Configuration and Capabilities
Single Administrator
Telnet Under NAT
Telnet Under the Firewall
System Timeout
Firewall and Content Filters
Types of Firewalls
What is a Firewall
Packet Filtering Firewalls
Application-level Firewalls
Stateful Inspection firewalls
Introduction to ZyXEL’s Firewall
Basics
Denial of Service
Common IP Ports
Types of DoS attacks
SYN Flood
Smurf Attack
Stateful Inspection
Stateful Inspection
Stateful Inspection Process
TCP Security
Stateful Inspection & the Prestige
Guidelines For Enhancing Security With Your Firewall
13.4.4 UDP/ICMP Security
Upper Layer Protocols
Security In General
What Is a Firewall? 13-11
Page
SMT Main Menu
Introducing the Prestige Firewall
Attack Types
View Firewall Log
Land
IP Spoofing
Illegal Commands NetBIOS and Smtp
Icmp Commands That Trigger Alerts
Legal NetBIOS Commands
Legal Smtp Commands
Teardrop
Traceroute
Big Picture Filtering, Firewall and NAT
Packet Filtering
Packet Filtering Vs Firewall
When To Use Filtering
When To Use The Firewall
Firewall
Page
Web Configurator Login and Welcome Screens
Introducing the Prestige Web Configurator
Enabling the Firewall
Prestige Web Configurator Welcome Screen
What are Alerts?
Mail
Mail Screen
What are Logs?
Mail
Smtp Error Messages
Smtp Error Messages
Example E-Mail Log
Mail Log
Attack Alert
Threshold Values
Half-Open Sessions
TCP Maximum Incomplete And Blocking Time
Attack Alert
Existing half-open sessions
Field Description Default Values
Do not set Maximum Incomplete High to
When TCP Maximum Incomplete is
Page
Creating Custom Rules
Rule Checklist
Rules Overview
Rule Logic Overview
Security Ramifications
Key Fields For Configuring Rules
Connection Direction
LAN to WAN Rules
WAN to LAN Rules
WAN to LAN Traffic
Services Supported
Service Description
Services Supported
Firewall Rules Summary First Screen
Rule Summary
Match
Block
Field Description Option
Creating/Editing Firewall Rules
Creating/Editing a Firewall Rule
Source & Destination Addresses
Single Address
Adding/Editing Source & Destination Addresses
Range Address
Subnet Address
Factors Influencing Choices for Timeout Values
Timeout
Timeout Screen
Timeout Menu
Field Description Default Value
Hour
Custom Ports
Custom Ports
Creating/Editing a Custom Port
Creating/Editing a Custom Port
Range
Single
Logs
Log Screen
Log Screen
Command, traceroute, teardrop, or syn
Vulnerability, NetBIOS, smtp illegal
Jan 1
Src IP, dest port, src port and protocol
Logs 18-3
Page
Example Firewall Rules
Activate The Firewall
Example 1 E-Mail Screen
Example 1 Configuring a Rule
Example Firewall Rules 19-5
Example 1 Rule Summary Screen
Example 2 Small Office With Mail, FTP and Web Servers
Send Alerts When Attacked
Configuring a POP Custom Port
Example 2 Local Network Rule 1 Configuration
Example 2 Local Network Rule Summary
10 Example 2 Internet to Local Network Rule Summary
11 Custom Port for Syslog
12 Syslog Rule Configuration
13 Example 3 Rule Summary
Restrict Web Features
Content Filtering
ActiveX
Java
Blocking URLs
Content Filtering Using the Web Configurator
Cookies
Web Proxy
Content Filtering Fields
Field Description Restrict Web Features
Block Web URLs
Troubleshooting, Appendices, Glossary and Index
Page
Problems Starting Up the Prestige
Troubleshooting
Troubleshooting the Start-Up of your Prestige
Problem Corrective Action
Problems with the WAN interface
Problems with the LAN Interface
Troubleshooting the LAN Interface
Troubleshooting the WAN interface
Problems with Internet Access
Problems with the Firewall
Troubleshooting Internet Access
Page
Appendix a PPPoE
Diagram 1 Single-PC per Modem Hardware Configuration
PPPoE in Action
Benefits of PPPoE
Diagram 2 Prestige as a PPPoE Client
How PPPoE Works
Prestige as a PPPoE Client
Appendix B
What is PPTP?
Pptp and the Prestige
Pptp Protocol Overview
Control & PPP connections
Appendix C Hardware Specifications
Mtbf
IRD + OTD +
Appendix D Important Safety Instructions
Function CLI Syntax
Appendix E Firewall CLI Commands
Sets
Function CLI Syntax Description
P312 Broadband Security Gateway
Delete
AC Power Adapter Specifications
Appendix F Power Adapter Specs
P312 Broadband Security Gateway
Glossary of Terms
ARP
CDR Chap
CSU/DSU DCE
Dslam
Dram DSL
DTE
EMI
FCC
FAQ
FTP
Hdlc
Ipcp PPP IPX
IRC ISP
MAC
Ndis
NAT
NIC
PAP
POP
Pots PPP
Pstn
RFC
PVC
RIP
SAP
STP
Spam
SUA TCP
Tftp
VPN
Page
Ddns
Index
Encapsulation
2-11, 2-12, 3-4
13-6
15-1 ZyNOS