Zyxel-communications Internet Security Gateway ZyWALL 2 Series Manual de usuario

Busca en linea o descarga Manual de usuario para Hardware Zyxel-communications Internet Security Gateway ZyWALL 2 Series. ZyXEL Communications Internet Security Gateway ZyWALL 2 Series User Manual Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 614
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 0
ZyWALL 2 Series
Internet Security Gateway
User’s Guide
Version 3.62
June 2004
Vista de pagina 0
1 2 3 4 5 6 ... 613 614

Indice de contenidos

Pagina 1 - ZyWALL 2 Series

ZyWALL 2 Series Internet Security Gateway User’s Guide Version 3.62 June 2004

Pagina 2 - Copyright

ZyWALL 2 Series User’s Guide x Table of Contents 14.13 Configuring Advanced IKE Setup ...

Pagina 3 - Interference Statement

ZyWALL 2 Series User’s Guide 6-16 WAN Screens Figure 6-9 Traffic Redirect The following table describes the fields in this screen. Table 6-8 Traffi

Pagina 4 - Caution

ZyWALL 2 Series User’s Guide WAN Screens 6-17 Table 6-8 Traffic Redirect LABEL DESCRIPTION Check WAN IP Address Configuration of this field is option

Pagina 5 - ZyXEL Limited Warranty

ZyWALL 2 Series User’s Guide 6-18 WAN Screens Figure 6-10 Dial Backup Setup

Pagina 6 - Customer Support

ZyWALL 2 Series User’s Guide WAN Screens 6-19 The following table describes the labels in this screen. Table 6-9 Dial Backup Setup LABEL DESCRIPTION

Pagina 7 - Table of Contents

ZyWALL 2 Series User’s Guide 6-20 WAN Screens Table 6-9 Dial Backup Setup LABEL DESCRIPTION Get IP Address Automatically from Remote Server Type the

Pagina 8

ZyWALL 2 Series User’s Guide WAN Screens 6-21 Table 6-9 Dial Backup Setup LABEL DESCRIPTION RIP Version The RIP Version field controls the format and

Pagina 9

ZyWALL 2 Series User’s Guide 6-22 WAN Screens Table 6-9 Dial Backup Setup LABEL DESCRIPTION Configure Budget Select this check box to have the dial

Pagina 10

ZyWALL 2 Series User’s Guide WAN Screens 6-23 6.11.3 Response Strings The response strings tell the ZyWALL the tags, or labels, immediately preceding

Pagina 11

ZyWALL 2 Series User’s Guide 6-24 WAN Screens Figure 6-11 Advanced Setup The following table describes the labels in this screen. Table 6-10 Advanc

Pagina 12

ZyWALL 2 Series User’s Guide WAN Screens 6-25 Table 6-10 Advanced Setup LABEL DESCRIPTION EXAMPLE Drop Type the AT Command string to drop a call. &q

Pagina 13

ZyWALL 2 Series User’s Guide Table of Contents xi 17.9 Secure Telnet Using SSH Examples ...

Pagina 15 - List of Figures

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-1 Chapter 7 Wireless LAN Screens This chapter discusses how to configure Wireless LAN on the Z

Pagina 16

ZyWALL 2 Series User’s Guide 7-2 Wireless LAN Screens is they do not know if the channel is currently being used. Therefore, they are considered hid

Pagina 17

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-3 A large Fragmentation Threshold is recommended for networks not prone to interference while you

Pagina 18

ZyWALL 2 Series User’s Guide 7-4 Wireless LAN Screens 7.4 Configuring Wireless LAN If you are configuring the ZyWALL from a computer connected to t

Pagina 19

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-5 Table 7-1 Wireless LABEL DESCRIPTION Enable Wireless LAN The wireless LAN is turned off by def

Pagina 20

ZyWALL 2 Series User’s Guide 7-6 Wireless LAN Screens 7.5 Configuring MAC Filter The MAC filter screen allows you to configure the ZyWALL to give ex

Pagina 21

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-7 Table 7-2 MAC Address Filter LABEL DESCRIPTION Active Select or clear the check box to enable

Pagina 22 - List of Tables

ZyWALL 2 Series User’s Guide 7-8 Wireless LAN Screens • Access-Request Sent by the ZyWALL requesting authentication. • Access-Reject Sent by a RAD

Pagina 23

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-9 Figure 7-5 EAP Authentication The details below provide a general description of how IEEE 802

Pagina 24

ZyWALL 2 Series User’s Guide xii Table of Contents 23.3 Configuring Dial Backup in Menu 2...

Pagina 25

ZyWALL 2 Series User’s Guide 7-10 Wireless LAN Screens Figure 7-6 802.1X Authentication The following table describes the fields in this screen. Ta

Pagina 26 - Preface

NAT and Static Route IV Part IV: NAT and Static Route This part covers Network Address Translation and setting up static routes.

Pagina 28

ZyWALL 2 Series User’s Guide NAT 8-1 Chapter 8 Network Address Translation (NAT) This chapter discusses how to configure NAT on the ZyWALL.

Pagina 29 - Part I:

ZyWALL 2 Series User’s Guide 8-2 NAT local address before forwarding it to the original inside host. Note that the IP address (either local o

Pagina 30

ZyWALL 2 Series User’s Guide NAT 8-3 8.1.4 NAT Application The following figure illustrates a possible NAT application, where three inside LA

Pagina 31 - Getting to Know Your ZyWALL

ZyWALL 2 Series User’s Guide 8-4 NAT  Many to One: In Many-to-One mode, the ZyWALL maps multiple local IP addresses to one global IP address

Pagina 32 - 1.2.2 Non-Physical Features

ZyWALL 2 Series User’s Guide NAT 8-5 8.2.1 SUA (Single User Account) Versus NAT SUA (Single User Account) is an implementation of a subset o

Pagina 33

ZyWALL 2 Series User’s Guide 8-6 NAT Table 8-3 Services and Port Numbers SERVICES PORT NUMBER DNS (Domain Name System) 53 Finger 79 HTTP (Hy

Pagina 34

ZyWALL 2 Series User’s Guide NAT 8-7 8.4 Configuring SUA Server If you do not assign a Default Server IP address, the ZyWALL discards all p

Pagina 35

ZyWALL 2 Series User’s Guide Table of Contents xiii 30.5 Firewall Versus Filters ...

Pagina 36 - Upgrade ZyWALL Firmware

ZyWALL 2 Series User’s Guide 8-8 NAT Table 8-4 SUA Server LABEL DESCRIPTION Default Server In addition to the servers for specified services

Pagina 37

ZyWALL 2 Series User’s Guide NAT 8-9 Figure 8-5 Address Mapping The following table describes the fields in this screen. Table 8-5 Address M

Pagina 38

ZyWALL 2 Series User’s Guide 8-10 NAT Table 8-5 Address Mapping LABEL DESCRIPTION Type 1. One-to-One mode maps one local IP address to one gl

Pagina 39 - Chapter 2

ZyWALL 2 Series User’s Guide NAT 8-11 Table 8-6 Address Mapping Rule LABEL DESCRIPTION Type Choose the port mapping type from one of the fol

Pagina 40 - 2.3 Resetting the ZyWALL

ZyWALL 2 Series User’s Guide 8-12 NAT receives a response with a specific port number and protocol ("incoming" port), the ZyWALL fo

Pagina 41

ZyWALL 2 Series User’s Guide NAT 8-13 Figure 8-8 Trigger Port The following table describes the fields in this screen. Table 8-7 Trigger Por

Pagina 42 - LINK TAB FUNCTION

ZyWALL 2 Series User’s Guide 8-14 NAT Table 8-7 Trigger Port LABEL DESCRIPTION Incoming Incoming is a port (or a range of ports) that a serv

Pagina 43

ZyWALL 2 Series User’s Guide Static Route Screens 9-1 Chapter 9 Static Route Screens This chapter shows you how to configure static routes for yo

Pagina 44

ZyWALL 2 Series User’s Guide 9-2 Static Route Screens Figure 9-2 Static Route Screen The following table describes the fields in this screen. Table

Pagina 45

ZyWALL 2 Series User’s Guide Static Route Screens 9-3 Table 9-1 IP Static Route Summary LABEL DESCRIPTION Gateway This is the IP address of the g

Pagina 46

ZyWALL 2 Series User’s Guide xiv Table of Contents Appendix F Types of EAP Authentication ...

Pagina 47 - Wizard Setup

ZyWALL 2 Series User’s Guide 9-4 Static Route Screens Table 9-2 Edit IP Static Route LABEL DESCRIPTION Active This field allows you to activate/dea

Pagina 48 - 3.3 Internet Access

Firewall and Content Filters V Part V: Firewall and Content Filters This part introduces firewalls in general and the ZyWALL firewall. It also

Pagina 50 - 3.3.2 PPPoE Encapsulation

ZyWALL 2 Series User’s Guide Firewalls 10-1 Chapter 10 Firewalls This chapter gives some background information on firewalls and introduces the ZyWAL

Pagina 51

ZyWALL 2 Series User’s Guide 10-2 Firewalls i. Information hiding prevents the names of internal systems from being made known via DNS to outside sy

Pagina 52 - 3.3.3 PPTP Encapsulation

ZyWALL 2 Series User’s Guide Firewalls 10-3 Figure 10-1 ZyWALL Firewall Application 10.4 Denial of Service Denials of Service (DoS) attacks are a

Pagina 53

ZyWALL 2 Series User’s Guide 10-4 Firewalls Table 10-1 Common IP Ports 21 FTP 53 DNS 23 Telnet 80 HTTP 25 SMTP 110 POP3 10.4.2 Types of DoS Attack

Pagina 54 - 3.4 WAN and DNS

ZyWALL 2 Series User’s Guide Firewalls 10-5 Figure 10-2 Three-Way Handshake  Under normal circumstances, the application that initiates a session

Pagina 55

ZyWALL 2 Series User’s Guide 10-6 Firewalls 2-b In a LAND Attack, hackers flood SYN packets into the network with a spoofed source IP address of the

Pagina 56 - 3.4.4 WAN MAC Address

ZyWALL 2 Series User’s Guide Firewalls 10-7  Illegal Commands (NetBIOS and SMTP) The only legal NetBIOS commands are the following - all others are

Pagina 57

ZyWALL 2 Series User’s Guide List of Figures xv List of Figures Figure 1-1 Secure Internet Access via Cable, DSL or Wireless Modem...

Pagina 58 - 3.5 Basic Setup Complete

ZyWALL 2 Series User’s Guide 10-8 Firewalls all communications to the Internet that originate from the LAN, and blocks all traffic to the LAN that or

Pagina 59 - Wizard Setup 3-13

ZyWALL 2 Series User’s Guide Firewalls 10-9 4. Based on the obtained state information, a firewall rule creates a temporary access list entry that i

Pagina 60

ZyWALL 2 Series User’s Guide 10-10 Firewalls Below is a brief technical description of how these connections are tracked. Connections may either be d

Pagina 61 - Part II:

ZyWALL 2 Series User’s Guide Firewalls 10-11 10.5.5 Upper Layer Protocols Some higher layer protocols (such as FTP and RealAudio) utilize multiple ne

Pagina 62

ZyWALL 2 Series User’s Guide 10-12 Firewalls 10.7.1 Packet Filtering:  The router filters packets as they pass through the router’s interface accor

Pagina 63 - System Screens

ZyWALL 2 Series User’s Guide Firewalls 10-13 3. To selectively block/allow inbound or outbound traffic between inside host/networks and outside host

Pagina 65 - 4.4 Configuring Dynamic DNS

ZyWALL 2 Series User’s Guide Firewall Screens 11-1Chapter 11 Firewall Screens This chapter shows you how to configure your ZyWALL firewall. 11.1 Acc

Pagina 66

ZyWALL 2 Series User’s Guide 11-2 Firewall Screens If you configure firewall rules without a good understanding of how they work, you might inadverte

Pagina 67 - 4.5 Configuring Password

ZyWALL 2 Series User’s Guide Firewall Screens 11-31. Does this rule stop LAN users from accessing critical resources on the Internet? For example, i

Pagina 68

ZyWALL 2 Series User’s Guide xvi List of Figures Figure 8-3 Multiple Servers Behind NAT Example...

Pagina 69 - 4.7 Configuring Time Setting

ZyWALL 2 Series User’s Guide 11-4 Firewall Screens policies for managing the ZyWALL through the LAN interface) and policies for LAN-to-LAN (the polic

Pagina 70

ZyWALL 2 Series User’s Guide Firewall Screens 11-5 Figure 11-2 WAN to LAN Traffic 11.5 Alerts Alerts are reports on events, such as attacks, that you

Pagina 71 - Table 4-5 Time Setting

ZyWALL 2 Series User’s Guide 11-6 Firewall Screens Figure 11-3 Enabling the Firewall The following table describes the fields in this screen. Sele

Pagina 72

ZyWALL 2 Series User’s Guide Firewall Screens 11-7Table 11-1 Firewall Rules Summary: First Screen LABEL DESCRIPTION Enable Firewall Select this che

Pagina 73 - LAN Screens

ZyWALL 2 Series User’s Guide 11-8 Firewall Screens Table 11-1 Firewall Rules Summary: First Screen LABEL DESCRIPTION Log This field shows you if a l

Pagina 74 - 5.5 LAN TCP/IP

ZyWALL 2 Series User’s Guide Firewall Screens 11-9 Figure 11-4 Creating/Editing A Firewall Rule

Pagina 75 - 5.6 Configuring IP

ZyWALL 2 Series User’s Guide 11-10 Firewall Screens The following table describes the fields in this screen. Table 11-2 Creating/Editing A Firewall R

Pagina 76 - Table 5-1 IP

ZyWALL 2 Series User’s Guide Firewall Screens 11-11Table 11-2 Creating/Editing A Firewall Rule LABEL DESCRIPTION Log This field determines if a log

Pagina 77 - LAN 5-5

ZyWALL 2 Series User’s Guide 11-12 Firewall Screens Table 11-3 Adding/Editing Source and Destination Addresses LABEL DESCRIPTION Address Type Do y

Pagina 78 - 5.7 Configuring Static DHCP

ZyWALL 2 Series User’s Guide Firewall Screens 11-13Table 11-4 Creating/Editing A Custom Port LABEL DESCRIPTION Service Name Enter a unique name for

Pagina 79 - 5.8 Configuring IP Alias

ZyWALL 2 Series User’s Guide List of Figures xvii Figure 14-9 Advanced IKE VPN Rule Setup ...

Pagina 80 - 5-8 LAN

ZyWALL 2 Series User’s Guide 11-14 Firewall Screens Figure 11-7 Firewall IP Config Screen Step 4. Select Any in the Destination Address box and the

Pagina 81 - Table 5-3 IP Alias

ZyWALL 2 Series User’s Guide Firewall Screens 11-15Step 5. Click DestAdd under the Destination Address box. Step 6. Configure the Firewall Rule Edi

Pagina 82

ZyWALL 2 Series User’s Guide 11-16 Firewall Screens Custom ports show up with an “*” before their names in the Services list box and the Rule Summary

Pagina 83 - Part III:

ZyWALL 2 Series User’s Guide Firewall Screens 11-17On completing the configuration procedure for this Internet firewall rule, the Rule Summary screen

Pagina 84

ZyWALL 2 Series User’s Guide 11-18 Firewall Screens 11.8 Predefined Services The Available Services list box in the Rule Config(uration) screen (see

Pagina 85 - WAN Screens

ZyWALL 2 Series User’s Guide Firewall Screens 11-19Table 11-5 Predefined Services SERVICE DESCRIPTION IPSEC_TUNNEL(ESP:0) The IPSEC ESP (Encapsula

Pagina 86 - 6.4 Configuring Route

ZyWALL 2 Series User’s Guide 11-20 Firewall Screens Table 11-5 Predefined Services SERVICE DESCRIPTION SMTP(TCP:25) Simple Mail Transfer Protocol

Pagina 87 - 6.5 Configuring WAN ISP

ZyWALL 2 Series User’s Guide Firewall Screens 11-2111.9.1 Threshold Values Tune these parameters when something is not working and after you have che

Pagina 88

ZyWALL 2 Series User’s Guide 11-22 Firewall Screens Whenever the number of half-open sessions with the same destination host address rises above a th

Pagina 89 - 6.5.2 PPPoE Encapsulation

ZyWALL 2 Series User’s Guide Firewall Screens 11-23Table 11-6 Attack Alert LABEL DESCRIPTION DEFAULT VALUES Generate alert when attack detected A d

Pagina 90

ZyWALL 2 Series User’s Guide xviii List of Figures Figure 17-21 SNMP Management Model...

Pagina 91 - 6.5.3 PPTP Encapsulation

ZyWALL 2 Series User’s Guide 11-24 Firewall Screens Table 11-6 Attack Alert LABEL DESCRIPTION DEFAULT VALUES Maximum Incomplete High This is the num

Pagina 92

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-1Chapter 12 Content Filtering Screens This chapter provides a brief overview of content fil

Pagina 93 - 6.6 Configuring WAN IP

ZyWALL 2 Series User’s Guide 12-2 Content Filtering Screens Figure 12-1 Content Filter : General The following table describes the labels in thi

Pagina 94

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-3Table 12-1 Content Filter : General LABEL DESCRIPTION Enable Content Filter Select this c

Pagina 95

ZyWALL 2 Series User’s Guide 12-4 Content Filtering Screens Table 12-1 Content Filter : General LABEL DESCRIPTION Exclude specified address range

Pagina 96

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-5Step 1. A computer sends an HTTP request to a web server. Step 2. The ZyWALL looks up th

Pagina 97

ZyWALL 2 Series User’s Guide 12-6 Content Filtering Screens Figure 12-3 Content Filter : Categories

Pagina 98 - 6.8 Traffic Redirect

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-7The following table describes the labels in this screen. Table 12-2 Content Filter : Categ

Pagina 99

ZyWALL 2 Series User’s Guide 12-8 Content Filtering Screens Table 12-2 Content Filter : Categories LABEL DESCRIPTION Select Categories Select All

Pagina 100 - Table 6-8 Traffic Redirect

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-9Table 12-2 Content Filter : Categories LABEL DESCRIPTION Gambling Selecting this category

Pagina 101

ZyWALL 2 Series User’s Guide List of Figures xix Figure 23-9 Menu 11.5: Dial Backup Remote Node Filter ...

Pagina 102

ZyWALL 2 Series User’s Guide 12-10 Content Filtering Screens Table 12-2 Content Filter : Categories LABEL DESCRIPTION Education Selecting this c

Pagina 103

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-11Table 12-2 Content Filter : Categories LABEL DESCRIPTION Computers/Internet Selecting th

Pagina 104

ZyWALL 2 Series User’s Guide 12-12 Content Filtering Screens Table 12-2 Content Filter : Categories LABEL DESCRIPTION Shopping Selecting this ca

Pagina 105

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-13Table 12-2 Content Filter : Categories LABEL DESCRIPTION Software Downloads Selecting th

Pagina 106 - 6.11 Advanced Modem Setup

ZyWALL 2 Series User’s Guide 12-14 Content Filtering Screens Table 12-2 Content Filter : Categories LABEL DESCRIPTION Register Click Register to

Pagina 107 - 6.11.3 Response Strings

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-15 Figure 12-4 Content Filter : Customization

Pagina 108 - Table 6-10 Advanced Setup

ZyWALL 2 Series User’s Guide 12-16 Content Filtering Screens The following table describes the labels in this screen. Table 12-3 Content Filter :

Pagina 109

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-17Table 12-3 Content Filter : Customization LABEL DESCRIPTION Delete Select a web site nam

Pagina 111 - Wireless LAN Screens

VPN/IPSec VI Part VI: VPN/IPSec This part provides information on how to configure VPN/IPSec.

Pagina 112 - 7-2 Wireless LAN Screens

ZyWALL 2 Series User’s Guide ii Copyright Copyright Copyright © 2004 by ZyXEL Communications Corporation. The contents of this publication may not be

Pagina 113 - 7.3 Wireless Security

ZyWALL 2 Series User’s Guide xx List of Figures Figure 28-20 Example 4: Menu 15.1.1.1: Address Mapping Rule ...

Pagina 115 - Table 7-1 Wireless

ZyWALL 2 Series User’s Guide Introduction to IPSec 13-1 Chapter 13 Introduction to IPSec This chapter introduces the basics of IPSec VPNs. 13.1 VPN

Pagina 116 - 7.5 Configuring MAC Filter

ZyWALL 2 Series User’s Guide 13-2 Introduction to IPSec Figure 13-1 Encryption and Decryption  Data Confidentiality The IPSec sender can encrypt

Pagina 117 - 7.6 802.1x Overview

ZyWALL 2 Series User’s Guide Introduction to IPSec 13-3 13.2 IPSec Architecture The overall IPSec architecture is shown as follows. Figure 13-2 IP

Pagina 118 - 7-8 Wireless LAN Screens

ZyWALL 2 Series User’s Guide 13-4 Introduction to IPSec 13.3 Encapsulation The two modes of operation for IPSec VPNs are Transport mode and Tunnel

Pagina 119 - 7.8 Configuring 802.1X

ZyWALL 2 Series User’s Guide Introduction to IPSec 13-5 13.4 IPSec and NAT Read this section if you are running IPSec on a host computer behind th

Pagina 121 - Part IV:

ZyWALL 2 Series User’s Guide VPN Screens 14-1 Chapter 14 VPN Screens This chapter introduces the VPN Web configurator. See the Logs chapter for inf

Pagina 122

ZyWALL 2 Series User’s Guide 14-2 VPN Screens Table 14-1 AH and ESP ESP AH DES (default) Data Encryption Standard (DES) is a widely used method of d

Pagina 123 - Chapter 8

ZyWALL 2 Series User’s Guide VPN Screens 14-3 You can also enter a remote secure gateway’s domain name in the Secure Gateway Address field if the rem

Pagina 124 - 8.1.3 How NAT Works

ZyWALL 2 Series User’s Guide List of Figures xxi Figure 33-12 Successful Restoration Confirmation Screen ...

Pagina 125 - 8.1.5 NAT Mapping Types

ZyWALL 2 Series User’s Guide 14-4 VPN Screens Figure 14-2 VPN Rules The following table describes the fields in this screen. Table 14-2 VPN Rules L

Pagina 126 - 8.2 Using NAT

ZyWALL 2 Series User’s Guide VPN Screens 14-5 Table 14-2 VPN Rules LABEL DESCRIPTION Remote IP Address This is the IP address(es) of computer(s) on t

Pagina 127 - 8.3 SUA Server

ZyWALL 2 Series User’s Guide 14-6 VPN Screens When there is outbound traffic with no inbound traffic, the ZyWALL automatically drops the tunnel afte

Pagina 128 - IP address

ZyWALL 2 Series User’s Guide VPN Screens 14-7 14.7.2 X-Auth (Extended Authentication) Extended authentication provides added security by allowing you

Pagina 129 - 8.4 Configuring SUA Server

ZyWALL 2 Series User’s Guide 14-8 VPN Screens If you do not specify an Intranet DNS server on the remote network, then the VPN host must use IP addr

Pagina 130

ZyWALL 2 Series User’s Guide VPN Screens 14-9 Table 14-4 Peer ID Type and Content Fields PEER ID TYPE= CONTENT= IP Type the IP address of the compu

Pagina 131

ZyWALL 2 Series User’s Guide 14-10 VPN Screens Table 14-6 Mismatching ID Type and Content Configuration Example ZYWALL A ZYWALL B Peer ID type: E-m

Pagina 132 - Configuring Address Mapping

ZyWALL 2 Series User’s Guide VPN Screens 14-11 Figure 14-6 Site-to-Site VPN Example 14.11 Configuring Basic IKE VPN Rule Setup Select one of the VPN

Pagina 133

ZyWALL 2 Series User’s Guide 14-12 VPN Screens Figure 14-7 Basic IKE VPN Rule Edit

Pagina 134

ZyWALL 2 Series User’s Guide VPN Screens 14-13 The following table describes the fields in this screen. Table 14-7 Basic IKE VPN Rule Edit LABEL DE

Pagina 135 - LABEL DESCRIPTION

ZyWALL 2 Series User’s Guide xxii List of Tables List of Tables Table 1-1 Model Specific Features ...

Pagina 136 - Table 8-7 Trigger Port

ZyWALL 2 Series User’s Guide 14-14 VPN Screens Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Server Mode Select Server Mode to have this Zy

Pagina 137 - Static Route Screens

ZyWALL 2 Series User’s Guide VPN Screens 14-15 Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Local IP Address Enter a static local IP addre

Pagina 138

ZyWALL 2 Series User’s Guide 14-16 VPN Screens Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Ending IP Address/ Subnet Mask When the Addres

Pagina 139

ZyWALL 2 Series User’s Guide VPN Screens 14-17 Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Local ID Type Select IP to identify this ZyWALL

Pagina 140 - 9-4 Static Route Screens

ZyWALL 2 Series User’s Guide 14-18 VPN Screens Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Peer ID Type Select from the following when yo

Pagina 141 - Part V:

ZyWALL 2 Series User’s Guide VPN Screens 14-19 Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Content The configuration of the peer content d

Pagina 142

ZyWALL 2 Series User’s Guide 14-20 VPN Screens Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION My IP Address Enter the WAN IP address of you

Pagina 143 - Firewalls

ZyWALL 2 Series User’s Guide VPN Screens 14-21 Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Encryption Algorithm Select DES, 3DES, AES or N

Pagina 144

ZyWALL 2 Series User’s Guide 14-22 VPN Screens Figure 14-8 Two Phases to Set Up the IPSec SA In phase 1 you must:  Choose a negotiation mode.  A

Pagina 145 - 10.4 Denial of Service

ZyWALL 2 Series User’s Guide VPN Screens 14-23 IPSec SA lifetime period expires. The ZyWALL also automatically renegotiates the IPSec SA if both IPSe

Pagina 146 - 10.4.2 Types of DoS Attacks

ZyWALL 2 Series User’s Guide List of Tables xxiii Table 10-2 ICMP Commands That Trigger Alerts ...

Pagina 147

ZyWALL 2 Series User’s Guide 14-24 VPN Screens 14.12.5 Perfect Forward Secrecy (PFS) Enabling PFS means that the key is transient. The key is throw

Pagina 148 - 18 ADDRESS_MASK_REPLY

ZyWALL 2 Series User’s Guide VPN Screens 14-25 Figure 14-9 Advanced IKE VPN Rule Setup The following table describes the fields in this screen. Tabl

Pagina 149 - 10.5 Stateful Inspection

ZyWALL 2 Series User’s Guide 14-26 VPN Screens Table 14-8 Advanced IKE VPN Rule Setup LABEL DESCRIPTION Enable Replay Detection As a VPN setup is p

Pagina 150

ZyWALL 2 Series User’s Guide VPN Screens 14-27 Table 14-8 Advanced IKE VPN Rule Setup LABEL DESCRIPTION Authentication Algorithm Select SHA1 or MD5

Pagina 151

ZyWALL 2 Series User’s Guide 14-28 VPN Screens Table 14-8 Advanced IKE VPN Rule Setup LABEL DESCRIPTION SA Life Time (seconds) Define the length of

Pagina 152 - 10.5.4 UDP/ICMP Security

ZyWALL 2 Series User’s Guide VPN Screens 14-29 Select Manual Key (or Manual) in the Key Management (or IPSec Keying Mode) field to display the manual

Pagina 153 - 10.5.5 Upper Layer Protocols

ZyWALL 2 Series User’s Guide 14-30 VPN Screens The following table describes the labels in this screen. Table 14-9 VPN Manual Setup LABEL DESCRIPTIO

Pagina 154 - 10.7.2 Firewall

ZyWALL 2 Series User’s Guide VPN Screens 14-31 Table 14-9 VPN Manual Setup LABEL DESCRIPTION Remote: Remote IP addresses must be static and correspo

Pagina 155

ZyWALL 2 Series User’s Guide 14-32 VPN Screens Table 14-9 VPN Manual Setup LABEL DESCRIPTION Secure Gateway Addr Type the WAN IP address or the URL

Pagina 156

ZyWALL 2 Series User’s Guide VPN Screens 14-33 Table 14-9 VPN Manual Setup LABEL DESCRIPTION Authentication Key Type a unique authentication key to b

Pagina 157 - Firewall Screens

ZyWALL 2 Series User’s Guide xxiv List of Tables Table 16-2 RADIUS ...

Pagina 158 - 11.3 Rule Logic Overview

ZyWALL 2 Series User’s Guide 14-34 VPN Screens The following table describes the fields in this screen. Table 14-10 VPN SA Monitor LABEL DESCRIPTIO

Pagina 159 - Destination Address

ZyWALL 2 Series User’s Guide VPN Screens 14-35 Table 14-11 VPN Global Setting LABEL DESCRIPTION Windows Networking (NetBIOS over TCP/IP) NetBIOS (N

Pagina 160 - 11.4.2 WAN to LAN Rules

ZyWALL 2 Series User’s Guide 14-36 VPN Screens Figure 14-13 Telecommuters Sharing One VPN Rule Example Table 14-12 Telecommuters Sharing One VPN Ru

Pagina 161 - 11.6 Configuring Firewall

ZyWALL 2 Series User’s Guide VPN Screens 14-37 See the following table and figure for an example where three telecommuters each use a different VPN r

Pagina 162

ZyWALL 2 Series User’s Guide 14-38 VPN Screens Table 14-13 Telecommuters Using Unique VPN Rules Example TELECOMMUTERS HEADQUARTERS Local IP Address:

Pagina 163 - Firewall Screens 11-7

VPN/IPSec VII Part VII: Certificates This part provides information and configuration instructions for public-key certificates.

Pagina 165 - Firewall Screens 11-9

ZyWALL 2 Series User’s Guide Certificates 15-1 Chapter 15 Certificates This chapter gives background information about public-key certificate

Pagina 166 - 11-10 Firewall Screens

ZyWALL 2 Series User’s Guide 15-2 Certificates Certification authorities maintain directory servers with databases of valid and revoked certificates.

Pagina 167

ZyWALL 2 Series User’s Guide Certificates 15-3 15.4 My Certificates Click CERTIFICATES, My Certificates to open the ZyWALL’s summary list of c

Pagina 168 - Address

ZyWALL 2 Series User’s Guide List of Tables xxv Table 26-1 Menu 11.1: Remote Node Profile for Ethernet Encapsulation...

Pagina 169

ZyWALL 2 Series User’s Guide 15-4 Certificates Table 15-1 My Certificates LABEL DESCRIPTION PKI Storage Space in Use This bar displays the percentage

Pagina 170 - 11-14 Firewall Screens

ZyWALL 2 Series User’s Guide Certificates 15-5 Table 15-1 My Certificates LABEL DESCRIPTION Details Select the radio button next to a certific

Pagina 171

ZyWALL 2 Series User’s Guide 15-6 Certificates 15.6 Importing a Certificate Click CERTIFICATES, My Certificates and then Import to open the My Certi

Pagina 172

ZyWALL 2 Series User’s Guide Certificates 15-7 Table 15-2 My Certificate Import LABEL DESCRIPTION Apply Click Apply to save the certificate o

Pagina 173

ZyWALL 2 Series User’s Guide 15-8 Certificates The following table describes the labels in this screen. Table 15-3 My Certificate Create LABEL DESCRI

Pagina 174 - 11.8 Predefined Services

ZyWALL 2 Series User’s Guide Certificates 15-9 Table 15-3 My Certificate Create LABEL DESCRIPTION Create a certification request and enroll fo

Pagina 175 - Firewall Screens 11-19

ZyWALL 2 Series User’s Guide 15-10 Certificates After you click Apply in the My Certificate Create screen, you see a screen that tells you the ZyWALL

Pagina 176

ZyWALL 2 Series User’s Guide Certificates 15-11 Figure 15-5 My Certificate Details

Pagina 177 - 11.9.2 Half-Open Sessions

ZyWALL 2 Series User’s Guide 15-12 Certificates The following table describes the labels in this screen. Table 15-4 My Certificate Details LABEL DESC

Pagina 178

ZyWALL 2 Series User’s Guide Certificates 15-13 Table 15-4 My Certificate Details LABEL DESCRIPTION Signature Algorithm This field displays t

Pagina 179 - Table 11-6 Attack Alert

ZyWALL 2 Series User’s Guide xxvi Preface Preface About This User's Manual Congratulations on your purchase of the ZyWALL 2 Internet Security Ga

Pagina 180

ZyWALL 2 Series User’s Guide 15-14 Certificates Table 15-4 My Certificate Details LABEL DESCRIPTION Certificate in PEM (Base-64) Encoded Format This

Pagina 181 - Content Filtering Screens

ZyWALL 2 Series User’s Guide Certificates 15-15 Figure 15-6 Trusted CAs The following table describes the labels in this screen. Table 15-5 T

Pagina 182

ZyWALL 2 Series User’s Guide 15-16 Certificates Table 15-5 Trusted CAs LABEL DESCRIPTION Issuer This field displays identifying information about th

Pagina 183

ZyWALL 2 Series User’s Guide Certificates 15-17 You must remove any spaces from the certificate’s filename before you can import the certifica

Pagina 184

ZyWALL 2 Series User’s Guide 15-18 Certificates Figure 15-8 Trusted CA Details

Pagina 185

ZyWALL 2 Series User’s Guide Certificates 15-19 The following table describes the labels in this screen. Table 15-7 Trusted CA Details LABEL D

Pagina 186

ZyWALL 2 Series User’s Guide 15-20 Certificates Table 15-7 Trusted CA Details LABEL DESCRIPTION Signature Algorithm This field displays the type of

Pagina 187

ZyWALL 2 Series User’s Guide Certificates 15-21 Table 15-7 Trusted CA Details LABEL DESCRIPTION Certificate in PEM (Base-64) Encoded Format Th

Pagina 188

ZyWALL 2 Series User’s Guide 15-22 Certificates Figure 15-9 Trusted Remote Hosts The following table describes the labels in this screen. Table 15-8

Pagina 189

ZyWALL 2 Series User’s Guide Certificates 15-23 Table 15-8 Trusted Remote Hosts LABEL DESCRIPTION Subject This field displays identifying inf

Pagina 190

ZyWALL 2 Series User’s Guide Preface xxvii • The version number on the title page is the latest firmware version that is documented in this User’s

Pagina 191

ZyWALL 2 Series User’s Guide 15-24 Certificates Table 15-9 Remote Host Certificates Step 3. Double-click the certificate’s icon to open the Certifi

Pagina 192

ZyWALL 2 Series User’s Guide Certificates 15-25 The trusted remote host certificate must be a self-signed certificate; and you must remove any

Pagina 193

ZyWALL 2 Series User’s Guide 15-26 Certificates Figure 15-11 Trusted Remote Host Details

Pagina 194

ZyWALL 2 Series User’s Guide Certificates 15-27 The following table describes the labels in this screen. Table 15-12 Trusted Remote Host Detai

Pagina 195

ZyWALL 2 Series User’s Guide 15-28 Certificates Table 15-12 Trusted Remote Host Details LABEL DESCRIPTION Key Algorithm This field displays the type

Pagina 196

ZyWALL 2 Series User’s Guide Certificates 15-29 15.16 Directory Servers Click CERTIFICATES, Directory Servers to open the Directory Servers s

Pagina 197

ZyWALL 2 Series User’s Guide 15-30 Certificates Table 15-13 Directory Servers LABEL DESCRIPTION Port This field displays the port number that the di

Pagina 198

ZyWALL 2 Series User’s Guide Certificates 15-31 Table 15-14 Directory Server Add LABEL DESCRIPTION Directory Service Setting Name Type up to

Pagina 200

Remote Management and UPnP VIII Part VIII: Authentication Server, Remote Management and UPnP This part provides information and configuration ins

Pagina 203 - 13.2 IPSec Architecture

ZyWALL 2 Series User’s Guide Authentication Server 16-1 Chapter 16 Authentication Server This chapter discusses how to configure the authentication s

Pagina 204 - 13.3 Encapsulation

ZyWALL 2 Series User’s Guide 16-2 Authentication Server Figure 16-1 Local User Database

Pagina 205 - 13.4 IPSec and NAT

ZyWALL 2 Series User’s Guide Authentication Server 16-3 The following table describes the fields in this screen. Table 16-1 Local User Database LABE

Pagina 206

ZyWALL 2 Series User’s Guide 16-4 Authentication Server Figure 16-2 RADIUS The following table describes the fields in this screen. Table 16-2 RADI

Pagina 207 - VPN Screens

ZyWALL 2 Series User’s Guide Authentication Server 16-5 Table 16-2 RADIUS LABEL DESCRIPTION Port Number The default port of the RADIUS server for au

Pagina 209 - 14.5 Summary Screen

ZyWALL 2 Series User’s Guide Remote Management Screens 17-1 Chapter 17 Remote Management Screens This chapter provides information on the Remote Mana

Pagina 210

ZyWALL 2 Series User’s Guide 17-2 Remote Management Screens 17.1.1 Remote Management Limitations Remote management over LAN or WAN will not work when

Pagina 211 - 14.6 Keep Alive

ZyWALL 2 Series User’s Guide Remote Management Screens 17-3 data), authentication (one party can identify the other party) and data integrity (you kn

Pagina 212 - 14.7 NAT Traversal

Getting Started I Part I: Getting Started This part helps you get to know your ZyWALL, introduces the web configurator and covers how to config

Pagina 213 - 14.7.3 Remote DNS Server

ZyWALL 2 Series User’s Guide 17-4 Remote Management Screens If you disable HTTP Server Access (Disable) in the REMOTE MGMT WWW screen, then the ZyWAL

Pagina 214 - 14.8 ID Type and Content

ZyWALL 2 Series User’s Guide Remote Management Screens 17-5 Table 17-1 WWW LABEL DESCRIPTION HTTPS: This feature is not available on the ZyWALL 2WE.

Pagina 215

ZyWALL 2 Series User’s Guide 17-6 Remote Management Screens Table 17-1 WWW LABEL DESCRIPTION Reset Click Reset to begin configuring this screen afres

Pagina 216 - 14.10 VPN Implementation

ZyWALL 2 Series User’s Guide Remote Management Screens 17-7 17.4.2 Netscape Navigator Warning Messages When you attempt to access the ZyWALL HTTPS se

Pagina 217

ZyWALL 2 Series User’s Guide 17-8 Remote Management Screens Figure 17-5 Security Certificate 2 (Netscape) 17.4.3 Avoiding the Browser Warning Messag

Pagina 218 - 14-12 VPN Screens

ZyWALL 2 Series User’s Guide Remote Management Screens 17-9 Step 2. Click CERTIFICATES. Find the certificate and check its Subject column. CN stands

Pagina 219 - VPN Screens 14-13

ZyWALL 2 Series User’s Guide 17-10 Remote Management Screens Figure 17-6 Login Screen (Internet Explorer)

Pagina 220 - 14-14 VPN Screens

ZyWALL 2 Series User’s Guide Remote Management Screens 17-11 Figure 17-7 Login Screen (Netscape) Click Login and you then see the next screen. The f

Pagina 221 - VPN Screens 14-15

ZyWALL 2 Series User’s Guide 17-12 Remote Management Screens Figure 17-8 Replace Certificate Click Apply in the Replace Certificate screen to create

Pagina 222 - 14-16 VPN Screens

ZyWALL 2 Series User’s Guide Remote Management Screens 17-13 Click Ignore in the Replace Certificate screen to use the common ZyWALL certificate. You

Pagina 223 - VPN Screens 14-17

ZyWALL 2 Series User’s Guide FCC iii Federal Communications Commission (FCC) Interference Statement This device complies with Part 15 of FCC rules.

Pagina 225 - VPN Screens 14-19

ZyWALL 2 Series User’s Guide 17-14 Remote Management Screens Figure 17-11 SSH Communication Example 17.6 How SSH works The following table summari

Pagina 226 - 14-20 VPN Screens

ZyWALL 2 Series User’s Guide Remote Management Screens 17-15 17.7 SSH Implementation on the ZyWALL Your ZyWALL supports SSH version 1.5 using RSA au

Pagina 227 - 14.12 IKE Phases

ZyWALL 2 Series User’s Guide 17-16 Remote Management Screens Table 17-2 SSH LABEL DESCRIPTION Server Host Key Select the certificate whose correspon

Pagina 228

ZyWALL 2 Series User’s Guide Remote Management Screens 17-17 Step 3. A window displays prompting you to store the host key in you computer. Click Ye

Pagina 229 - 14.12.3 Pre-Shared Key

ZyWALL 2 Series User’s Guide 17-18 Remote Management Screens Step 2. Enter “ssh –1 192.168.1.1”. This command forces your computer to connect to the

Pagina 230

ZyWALL 2 Series User’s Guide Remote Management Screens 17-19 Step 3. Use the “put” command to upload a new firmware to the ZyWALL. Figure 17-17 Se

Pagina 231 - DESCRIPTION

ZyWALL 2 Series User’s Guide 17-20 Remote Management Screens 17.12 Configuring TELNET Click REMOTE MGNT to open the TELNET screen. Figure 17-19 Te

Pagina 232

ZyWALL 2 Series User’s Guide Remote Management Screens 17-21 17.13 Configuring FTP You can upload and download the ZyWALL’s firmware and configurati

Pagina 233

ZyWALL 2 Series User’s Guide 17-22 Remote Management Screens Table 17-4 FTP LABEL DESCRIPTION Secure Client IP Address A secure client is a “trusted”

Pagina 234 - 14.14 Manual Key Setup

ZyWALL 2 Series User’s Guide Remote Management Screens 17-23 Figure 17-21 SNMP Management Model An SNMP managed network consists of two main types o

Pagina 235

ZyWALL 2 Series User’s Guide Getting to Know Your ZyWALL 1-1Chapter 1 Getting to Know Your ZyWALL This chapter introduces the main features and ap

Pagina 236 - Table 14-9 VPN Manual Setup

ZyWALL 2 Series User’s Guide 17-24 Remote Management Screens • Get - Allows the manager to retrieve an object variable from the agent. • GetNext -

Pagina 237 - VPN Screens 14-31

ZyWALL 2 Series User’s Guide Remote Management Screens 17-25 17.14.3 REMOTE MANAGEMENT: SNMP To change your ZyWALL’s SNMP settings, click REMOTE MGN

Pagina 238 - 14-32 VPN Screens

ZyWALL 2 Series User’s Guide 17-26 Remote Management Screens Table 17-6 SNMP LABEL DESCRIPTION SNMP Configuration Get Community Enter the Get Communi

Pagina 239 - 14.16 SA Monitor

ZyWALL 2 Series User’s Guide Remote Management Screens 17-27 To change your ZyWALL’s DNS settings, click REMOTE MGNT, then the DNS tab. The screen ap

Pagina 240 - 14.17 Global Settings

ZyWALL 2 Series User’s Guide 17-28 Remote Management Screens 17.16 Configuring Security To change your ZyWALL’s Security settings, click REMOTE MGNT

Pagina 241

ZyWALL 2 Series User’s Guide Remote Management Screens 17-29 Table 17-8 Security LABEL DESCRIPTION Respond to Ping on The ZyWALL will not respond to

Pagina 243

ZyWALL 2 Series User’s Guide UPnP 18-1 Chapter 18 UPnP This chapter introduces the Universal Plug and Play feature. 18.1 Universal Plug and Play Ov

Pagina 244

ZyWALL 2 Series User’s Guide 18-2 UPnP 18.1.3 Cautions with UPnP The automated nature of NAT traversal applications in establishing their own service

Pagina 245 - Part VII:

ZyWALL 2 Series User’s Guide UPnP 18-3 Figure 18-1 Configuring UPnP The following table describes the fields in this screen. Table 18-1 Configuring

Pagina 246

ZyWALL 2 Series User’s Guide 1-2 Getting to Know Your ZyWALL 1.2.1 Physical Features 4-Port Switch A combination of switch and router makes your Zy

Pagina 247 - Certificates

ZyWALL 2 Series User’s Guide 18-4 UPnP Table 18-1 Configuring UPnP FIELD DESCRIPTION Reset Click Reset to begin configuring this screen afresh 18.

Pagina 248 - 15.3 Configuration Summary

ZyWALL 2 Series User’s Guide UPnP 18-5 Table 18-2 UPnP Ports LABEL DESCRIPTION # This is the index number of the UPnP-created NAT mapping rule ent

Pagina 249 - 15.4 My Certificates

ZyWALL 2 Series User’s Guide 18-6 UPnP 18.5.1 Installing UPnP in Windows Me Follow the steps below to install UPnP in Windows Me. Click Start and Co

Pagina 250 - Table 15-1 My Certificates

ZyWALL 2 Series User’s Guide UPnP 18-7 Step 1. Click Start and Control Panel. Step 2. Double-click Network Connections. Step 3. In the Network Co

Pagina 251

ZyWALL 2 Series User’s Guide 18-8 UPnP 18.6 Using UPnP in Windows XP Example This section shows you how to use the UPnP feature in Windows XP. You m

Pagina 252

ZyWALL 2 Series User’s Guide UPnP 18-9 Step 4. You may edit or delete the port mappings or click Add to manually add port mappings. When the UPnP-

Pagina 253 - 15.7 Creating a Certificate

ZyWALL 2 Series User’s Guide 18-10 UPnP 18.6.2 Web Configurator Easy Access With UPnP, you can access the web-based configurator without first findin

Pagina 254 - 15-8 Certificates

Logs IX Part IX: Logs This part provides information and instructions for the logs and reports.

Pagina 256 - 15.8 My Certificate Details

ZyWALL 2 Series User’s Guide Log Screens 19-1 Chapter 19 Logs Screens This chapter contains information about configuring general log settings and vi

Pagina 257 - Certificates 15-11

ZyWALL 2 Series User’s Guide Getting to Know Your ZyWALL 1-3The ZyWALL supports two simultaneous VPN connections. X-Auth (Extended Authentication)

Pagina 258 - 15-12 Certificates

ZyWALL 2 Series User’s Guide 19-2 Log Screens Figure 19-1 View Log The following table describes the labels in this screen. Table 19-1 View Log LABE

Pagina 259 - Certificates 15-13

ZyWALL 2 Series User’s Guide Log Screens 19-3 Table 19-1 View Log LABEL DESCRIPTION Note This field displays additional information about the log en

Pagina 260 - 15.9 Trusted CAs

ZyWALL 2 Series User’s Guide 19-4 Log Screens Figure 19-2 Log Settings

Pagina 261

ZyWALL 2 Series User’s Guide Log Screens 19-5 The following table describes the labels in this screen. Table 19-2 Log Settings LABEL DESCRIPTION Add

Pagina 262

ZyWALL 2 Series User’s Guide 19-6 Log Screens Table 19-2 Log Settings LABEL DESCRIPTION Time for Sending Log Enter the time of the day in 24-hour fo

Pagina 263

ZyWALL 2 Series User’s Guide Log Screens 19-7 The ZyWALL records web site hits by counting the HTTP GET packets. Many web sites include HTTP GET refe

Pagina 264 - 15-18 Certificates

ZyWALL 2 Series User’s Guide 19-8 Log Screens Table 19-3 Reports LABEL DESCRIPTION Refresh Click Refresh to update the report display. The report als

Pagina 265 - Certificates 15-19

ZyWALL 2 Series User’s Guide Log Screens 19-9 Table 19-4 Web Site Hits Report LABEL DESCRIPTION Web Site This column lists the domain names of the w

Pagina 266 - 15-20 Certificates

ZyWALL 2 Series User’s Guide 19-10 Log Screens Table 19-5 Protocol/ Port Report LABEL DESCRIPTION Protocol/Port This column lists the protocols or s

Pagina 267 - 15.12 Trusted Remote Hosts

ZyWALL 2 Series User’s Guide Log Screens 19-11 The following table describes the labels in this screen. Table 19-6 LAN IP Address Report LABEL DESCRI

Pagina 268

ZyWALL 2 Series User’s Guide 1-4 Getting to Know Your ZyWALL Universal Plug and Play (UPnP) Using the standard TCP/IP protocol, the ZyWALL and othe

Pagina 270

Maintenance X Part X: Maintenance This part covers the maintenance screens.

Pagina 272 - 15-26 Certificates

ZyWALL 2 Series User’s Guide Maintenance 20-1 Chapter 20 Maintenance This chapter displays system information such as firmware, port IP addresses an

Pagina 273 - Certificates 15-27

ZyWALL 2 Series User’s Guide 20-2 Maintenance The following table describes the labels in this screen. Table 20-1 System Status LABEL DESCRIPTION S

Pagina 274 - 15-28 Certificates

ZyWALL 2 Series User’s Guide Maintenance 20-3 Figure 20-2 System Status: Show Statistics The following table describes the labels in this screen. T

Pagina 275 - 15.16 Directory Servers

ZyWALL 2 Series User’s Guide 20-4 Maintenance Table 20-2 System Status: Show Statistics LABEL DESCRIPTION Stop Click Stop to stop refreshing statis

Pagina 276

ZyWALL 2 Series User’s Guide Maintenance 20-5 Table 20-3 DHCP Table LABEL DESCRIPTION IP Address This field displays the IP address relative to the

Pagina 277 - Certificates 15-31

ZyWALL 2 Series User’s Guide 20-6 Maintenance The following table describes the fields in this screen. Figure 20-5 Firmware Upload LABEL DESCRIPTIO

Pagina 278

ZyWALL 2 Series User’s Guide Maintenance 20-7 Figure 20-7 Network Temporarily Disconnected After two minutes, log in again and check your new firmw

Pagina 279 - Part VIII:

ZyWALL 2 Series User’s Guide Getting to Know Your ZyWALL 1-5Central Network Management Central Network Management (CNM) allows an enterprise or ser

Pagina 280

ZyWALL 2 Series User’s Guide 20-8 Maintenance Figure 20-9 Configuration 20.5.1 Backup Configuration Backup Configuration allows you to backup (save

Pagina 281 - Authentication Server

ZyWALL 2 Series User’s Guide Maintenance 20-9 20.5.2 Restore Configuration Restore Configuration allows you to restore a previously saved configura

Pagina 282 - 16-2 Authentication Server

ZyWALL 2 Series User’s Guide 20-10 Maintenance If you uploaded the default configuration file you may need to change the IP address of your computer

Pagina 283 - 16.4 Configuring RADIUS

ZyWALL 2 Series User’s Guide Maintenance 20-11 You can also press the RESET button on the rear panel to reset the factory defaults of your ZyWALL. R

Pagina 285 - Table 16-2 RADIUS

SMT General Configuration XI Part XI: SMT General Configuration This part introduces the System Management Terminal and covers the General setup

Pagina 287 - Remote Management Screens

ZyWALL 2 Series User’s Guide Introducing the SMT 21-1 Chapter 21 Introducing the SMT This chapter explains how to access the System Management Termin

Pagina 288 - 17.2 Introduction to HTTPS

ZyWALL 2 Series User’s Guide 21-2 Introducing the SMT 21.2.2 Entering the Password The login screen appears after you press [ENTER], prompting you to

Pagina 289

ZyWALL 2 Series User’s Guide Introducing the SMT 21-3 Table 21-1 Main Menu Commands OPERATION KEYSTROKES DESCRIPTION Entering information Fill in, o

Pagina 290 - 17.3 Configuring WWW

ZyWALL 2 Series User’s Guide 1-6 Getting to Know Your ZyWALL Management Terminal) interface. The SMT is a menu-driven interface that you can access

Pagina 291 - Table 17-1 WWW

ZyWALL 2 Series User’s Guide 21-4 Introducing the SMT Table 21-2 Main Menu Summary NO. Menu Title FUNCTION 1 General Setup Use this menu to set u

Pagina 292 - 17.4 HTTPS Example

ZyWALL 2 Series User’s Guide Introducing the SMT 21-5 Menu 3LAN SetupMenu 4Internet Access SetupMenu 12Static Routing SetupMenu 11Remote Node SetupMe

Pagina 293

ZyWALL 2 Series User’s Guide 21-6 Introducing the SMT 21.4 Changing the System Password Change the system password by following the steps shown next

Pagina 294

ZyWALL 2 Series User’s Guide SMT Menu 1 – General Setup 22-1 Chapter 22 SMT Menu 1 - General Setup Menu 1 - General Setup contains administrative an

Pagina 295 - 17.4.4 Login Screen

ZyWALL 2 Series User’s Guide 22-2 SMT Menu 1 – General Setup Table 22-1 Menu 1: General Setup FIELD DESCRIPTION EXAMPLE Domain Name Enter the do

Pagina 296

ZyWALL 2 Series User’s Guide SMT Menu 1 – General Setup 22-3 Figure 22-2 Configure Dynamic DNS Follow the instructions in the next table to

Pagina 297

ZyWALL 2 Series User’s Guide 22-4 SMT Menu 1 – General Setup Table 22-2 Configure Dynamic DNS FIELD DESCRIPTION EXAMPLE Offline This field is on

Pagina 298

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-1 Chapter 23 WAN and Dial Backup Setup This chapter describes how to configure the WAN us

Pagina 299 - 17.5 SSH Overview

ZyWALL 2 Series User’s Guide 23-2 WAN and Dial Backup Setup Table 23-1 MAC Address Cloning in WAN Setup FIELD DESCRIPTION EXAMPLE IP Address This f

Pagina 300 - 17.6 How SSH works

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-3 The following table describes the fields in this menu. Table 23-2 Menu 2: Dial Backup Set

Pagina 301 - 17.8 Configuring SSH

ZyWALL 2 Series User’s Guide Getting to Know Your ZyWALL 1-71.3.2 Secure Broadband Internet Access and VPN You can connect a cable, DSL or wirele

Pagina 302

ZyWALL 2 Series User’s Guide 23-4 WAN and Dial Backup Setup Figure 23-3 Menu 2.1 Advanced WAN Setup The following table describes fields in t

Pagina 303 - 17.9.2 Example 2: Linux

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-5 Table 23-4 Advanced WAN Port Setup: Call Control Parameters FIELD DESCRIPTION DEFAULT

Pagina 304

ZyWALL 2 Series User’s Guide 23-6 WAN and Dial Backup Setup Figure 23-4 Menu 11.1 Remote Node Profile (Backup ISP) The following table desc

Pagina 305 - 17.11 Telnet

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-7 Table 23-5 Menu 11.1 Remote Node Profile (Backup ISP) FIELD DESCRIPTION EXAMPLE Pri Pho

Pagina 306 - 17.12 Configuring TELNET

ZyWALL 2 Series User’s Guide 23-8 WAN and Dial Backup Setup Table 23-5 Menu 11.1 Remote Node Profile (Backup ISP) FIELD DESCRIPTION EXAMPLE Idle Ti

Pagina 307 - 17.13 Configuring FTP

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-9 23.7 Editing TCP/IP Options Move the cursor to the Edit IP field in menu 11.1, then pres

Pagina 308 - 17.14 Configuring SNMP

ZyWALL 2 Series User’s Guide 23-10 WAN and Dial Backup Setup Table 23-6 Menu 11.3: Remote Node Network Layer Options FIELD DESCRIPTION EXAMPLE Netw

Pagina 309

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-11 23.8 Editing Login Script For some remote gateways, text login is required before PPP ne

Pagina 310 - 17.14.2 SNMP Traps

ZyWALL 2 Series User’s Guide 23-12 WAN and Dial Backup Setup Figure 23-8 Menu 11.4: Remote Node Script The following table describes the fi

Pagina 311

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-13 Figure 23-9 Menu 11.5: Dial Backup Remote Node Filter Menu 11.5 - Remote Node F

Pagina 314 - 17.16 Configuring Security

ZyWALL 2 Series User’s Guide LAN Setup 24-1 Chapter 24 LAN Setup This chapter describes how to configure the LAN using Menu 3: LAN Setup. 24.1 In

Pagina 315 - Table 17-8 Security

ZyWALL 2 Series User’s Guide 24-2 LAN Setup Figure 24-2 Menu 3.1: LAN Port Filter Setup 24.4 TCP/IP and DHCP Ethernet Setup Menu From the ma

Pagina 316

ZyWALL 2 Series User’s Guide LAN Setup 24-3 Figure 24-4 Menu 3.2: TCP/IP and DHCP Ethernet Setup Follow the instructions in the next table

Pagina 317 - Chapter 18

ZyWALL 2 Series User’s Guide 24-4 LAN Setup Table 24-2 LAN TCP/IP Setup Menu Fields FIELD DESCRIPTION EXAMPLE TCP/IP Setup: IP Address Enter t

Pagina 318 - 18.3 Configuring UPnP

ZyWALL 2 Series User’s Guide LAN Setup 24-5 Figure 24-5 Physical Network Figure 24-6 Partitioned Logical Network You must u

Pagina 319 - DESCRIPTION

ZyWALL 2 Series User’s Guide 24-6 LAN Setup Table 24-3 Menu 3.2.1: IP Alias Setup FIELD DESCRIPTION DEFAULT IP Address Enter the IP address of y

Pagina 320

ZyWALL 2 Series User’s Guide LAN Setup 24-7 Figure 24-8 Menu 3.5: Wireless LAN Setup The settings of all client stations on the wireless LAN must m

Pagina 321

ZyWALL 2 Series User’s Guide 24-8 LAN Setup Table 24-4 Menu 3.5: Wireless LAN Setup FIELD DESCRIPTION EXAMPLE Frag. Threshold The threshold (number

Pagina 322

ZyWALL 2 Series User’s Guide LAN Setup 24-9 Step 3. In the Edit MAC Address Filter field, press [SPACE BAR] to select Yes and press [ENTER]. Menu

Pagina 323

ZyWALL 2 Series User’s Guide Introducing the Web Configurator 2-1 Chapter 2 Introducing the Web Configurator This chapter describes how to acces

Pagina 325

ZyWALL 2 Series User’s Guide Internet Access 25-1 Chapter 25 Internet Access This chapter shows you how to configure your ZyWALL for Internet access.

Pagina 326

ZyWALL 2 Series User’s Guide 25-2 Internet Access Table 25-1 Menu 4: Internet Access Setup (Ethernet) FIELD DESCRIPTION Encapsulation Press [SPACE

Pagina 327 - Part IX:

ZyWALL 2 Series User’s Guide Internet Access 25-3 25.3 PPTP Encapsulation Point-to-Point Tunneling Protocol (PPTP) is a network protocol that enables

Pagina 328

ZyWALL 2 Series User’s Guide 25-4 Internet Access Table 25-2 New Fields in Menu 4 (PPTP) Screen FIELD DESCRIPTION EXAMPLE Encapsulation Press [SPAC

Pagina 329 - Logs Screens

ZyWALL 2 Series User’s Guide Internet Access 25-5 Figure 25-3 Internet Access Setup (PPPoE) The following table contains instructions about

Pagina 331

SMT Advanced Applications XII Part XII: SMT Advanced Applications This part covers setting up remote nodes, IP static routes and Network Address

Pagina 333 - Table 19-2 Log Settings

ZyWALL 2 Series User’s Guide Remote Node Setup 26-1 Chapter 26 Remote Node Setup This chapter shows you how to configure a remote node. 26.1 Intro

Pagina 334 - 19.3 Configuring Reports

ZyWALL 2 Series User’s Guide iv Information for Canadian Users Information for Canadian Users The Industry Canada label identifies certified equipm

Pagina 335

ZyWALL 2 Series User’s Guide 2-2 Introducing the Web Configurator Step 6. Click Apply in the Replace Certificate screen to create a certificate us

Pagina 336 - 19.3.1 Viewing Web Site Hits

ZyWALL 2 Series User’s Guide 26-2 Remote Node Setup Figure 26-1Menu 11.1: Remote Node Profile for Ethernet Encapsulation The following table

Pagina 337 - 19.3.2 Viewing Protocol/Port

ZyWALL 2 Series User’s Guide Remote Node Setup 26-3 Table 26-1 Menu 11.1: Remote Node Profile for Ethernet Encapsulation FIELD DESCRIPTION EXAMPL

Pagina 338

ZyWALL 2 Series User’s Guide 26-4 Remote Node Setup Encapsulation to PPPoE, then you will see the next screen. Please see the appendix for more info

Pagina 339

ZyWALL 2 Series User’s Guide Remote Node Setup 26-5 Do not specify a nailed-up connection unless your telephone company offers flat-rate service or

Pagina 340

ZyWALL 2 Series User’s Guide 26-6 Remote Node Setup 26.2.3 PPTP Encapsulation If you change the Encapsulation to PPTP in menu 11.1, then you will se

Pagina 341 - Part X:

ZyWALL 2 Series User’s Guide Remote Node Setup 26-7 26.3 Edit IP Move the cursor to the Edit IP field in menu 11.1, then press [SPACE BAR] to sel

Pagina 342

ZyWALL 2 Series User’s Guide 26-8 Remote Node Setup Table 26-4 Remote Node Network Layer Options Menu Fields FIELD DESCRIPTION EXAMPLE My WAN Addr

Pagina 343 - Maintenance

ZyWALL 2 Series User’s Guide Remote Node Setup 26-9 Table 26-4 Remote Node Network Layer Options Menu Fields FIELD DESCRIPTION EXAMPLE Multicast

Pagina 344

ZyWALL 2 Series User’s Guide 26-10 Remote Node Setup Figure 26-6 Menu 11.5: Remote Node Filter (PPPoE or PPTP Encapsulation) 26.5 Traffic Redi

Pagina 345

ZyWALL 2 Series User’s Guide Remote Node Setup 26-11 Table 26-5 Menu 11.1: Remote Node Profile (Traffic Redirect Field) FIELD DESCRIPTION EXAMPLE

Pagina 346 - 20.3 DHCP Table Screen

ZyWALL 2 Series User’s Guide Introducing the Web Configurator 2-3 2.3.2 Uploading a Configuration File Via Console Port Step 3. Download the defa

Pagina 347 - 20.4 F/W Upload Screen

ZyWALL 2 Series User’s Guide 26-12 Remote Node Setup Table 26-6 Menu 11.6: Traffic Redirect Setup FIELD DESCRIPTION EXAMPLE Active Press [SPACE BA

Pagina 348

ZyWALL 2 Series User’s Guide Remote Node Setup 26-13 Table 26-6 Menu 11.6: Traffic Redirect Setup FIELD DESCRIPTION EXAMPLE When you have complet

Pagina 350 - 20.5.1 Backup Configuration

ZyWALL 2 Series User’s Guide IP Static Route Setup 27-1 Chapter 27 IP Static Route Setup This chapter shows you how to configure static rout

Pagina 351

ZyWALL 2 Series User’s Guide 27-2 IP Static Route Setup Figure 27-2 Menu 12. 1: Edit IP Static Route `The following table describes the IP Stat

Pagina 352

ZyWALL 2 Series User’s Guide NAT 28-1 Chapter 28 Network Address Translation (NAT) This chapter discusses how to configure NAT on the ZyWALL. 28.

Pagina 353 - 20.6 Restart Screen

ZyWALL 2 Series User’s Guide 28-2 NAT Figure 28-1 Menu 4: Applying NAT for Internet Access The following figure shows how you apply NAT to th

Pagina 354

ZyWALL 2 Series User’s Guide NAT 28-3 Table 28-1 Applying NAT in Menus 4 & 11.3 FIELD DESCRIPTION OPTIONS When you select this option the

Pagina 355 - Part XI:

ZyWALL 2 Series User’s Guide 28-4 NAT Configure LAN IP addresses in NAT menus 15.1 and 15.2. 28.2.1 Address Mapping Sets Enter 1 to bring up Menu 1

Pagina 356

ZyWALL 2 Series User’s Guide NAT 28-5 Table 28-2 SUA Address Mapping Rules FIELD DESCRIPTION EXAMPLE Set Name This is the name of the set you s

Pagina 357 - Introducing the SMT

ZyWALL 2 Series User’s Guide 2-4 Introducing the Web Configurator Follow the instructions you see in the MAIN MENU screen or click the icon (loca

Pagina 358 - 21.2.2 Entering the Password

ZyWALL 2 Series User’s Guide 28-6 NAT Figure 28-6 Menu 15.1.1: First Set The Type, Local and Global Start/End IPs are configured in menu 15.

Pagina 359 - 21.3.1 Main Menu

ZyWALL 2 Series User’s Guide NAT 28-7 Table 28-3 Fields in Menu 15.1.1 FIELD DESCRIPTION EXAMPLE Set Name Enter a name for this set of rules. T

Pagina 360

ZyWALL 2 Series User’s Guide 28-8 NAT The following table describes the fields in this screen. Table 28-4 Menu 15.1.1.1: Editing/Configuring an Indiv

Pagina 361 - Change Console Port Speed

ZyWALL 2 Series User’s Guide NAT 28-9 Step 5. Press [ENTER] at the “Press ENTER to confirm …” prompt to save your configuration after you define

Pagina 362

ZyWALL 2 Series User’s Guide 28-10 NAT 28.4.1 Internet Access Only In the following Internet access example, you only need one rule where all your IL

Pagina 363 - SMT Menu 1 - General Setup

ZyWALL 2 Series User’s Guide NAT 28-11 28.4.2 Example 2: Internet Access with an Inside Server Figure 28-12 NAT Example 2 In this case, you do ex

Pagina 364

ZyWALL 2 Series User’s Guide 28-12 NAT other LAN traffic to the remaining IGA. Map the third IGA to an inside web server and mail server. Four rules

Pagina 365

ZyWALL 2 Series User’s Guide NAT 28-13 Step 5. Select Type as One-to-One (direct mapping for packets going both ways), and enter the local Start

Pagina 366

ZyWALL 2 Series User’s Guide 28-14 NAT Figure 28-17 Example 3: Final Menu 15.1.1 Now configure the IGA3 to map to our web server and mail se

Pagina 367 - WAN and Dial Backup Setup

ZyWALL 2 Series User’s Guide NAT 28-15 28.4.4 Example 4: NAT Unfriendly Application Programs Some applications do not support NAT Mapping using TC

Pagina 368 - 23.2 Dial Backup

ZyWALL 2 Series User’s Guide Introducing the Web Configurator 2-5 Table 2-1 Web Configurator Screens Summary LINK TAB FUNCTION General Use this

Pagina 369 - 23.4 Advanced WAN Setup

ZyWALL 2 Series User’s Guide 28-16 NAT Figure 28-20 Example 4: Menu 15.1.1.1: Address Mapping Rule After you’ve configured your rule, you shoul

Pagina 370

ZyWALL 2 Series User’s Guide NAT 28-17 LAN computer, you have to manually replace the LAN computer's IP address in the forwarding port with a

Pagina 371

ZyWALL 2 Series User’s Guide 28-18 NAT 5. Only A can connect to the Real Audio server until the connection is closed or times out. The ZyWALL times o

Pagina 372

ZyWALL 2 Series User’s Guide NAT 28-19 Table 28-5 Menu 15.3: Trigger Port Setup FIELD DESCRIPTION EXAMPLE Rule This is the rule index number.

Pagina 374 - 23.6 Editing PPP Options

ZyWALL 2 Series User’s Guide Introducing the Firewall 29-1 Chapter 29 Introducing the Firewall This chapter shows you how to get started with the fi

Pagina 375 - 23.7 Editing TCP/IP Options

ZyWALL 2 Series User’s Guide 29-2 Introducing the Firewall Figure 29-2 Menu 21.2: Firewall Setup Configure the firewall rules using the we

Pagina 376

ZyWALL 2 Series User’s Guide Filter Configuration 30-1 Chapter 30 Filter Configuration This chapter shows you how to create and apply filters. 30.1

Pagina 377 - 23.8 Editing Login Script

ZyWALL 2 Series User’s Guide 30-2 Filter Configuration Figure 30-1 Outgoing Packet Filtering Process For incoming packets, your ZyWALL applies data f

Pagina 378 - 23.9 Remote Node Filter

ZyWALL 2 Series User’s Guide Filter Configuration 30-3 StartFetch FirstFilter SetFetch FirstFilter RuleActive?ExecuteFilter RuleFetch NextFilter Rul

Pagina 379

ZyWALL 2 Series User’s Guide 2-6 Introducing the Web Configurator Table 2-1 Web Configurator Screens Summary LINK TAB FUNCTION General This scre

Pagina 380

ZyWALL 2 Series User’s Guide 30-4 Filter Configuration You can apply up to four filter sets to a particular port to block multiple types of packets.

Pagina 381 - LAN Setup

ZyWALL 2 Series User’s Guide Filter Configuration 30-5 Step 4. Enter a descriptive name or comment in the Edit Comments field and press [ENTER]. St

Pagina 382 - 2. TCP/IP and DHCP Setup

ZyWALL 2 Series User’s Guide 30-6 Filter Configuration Table 30-2 Rule Abbreviations Used ABBREVIATION DESCRIPTION IP Pr Protocol SA Source Address

Pagina 383

ZyWALL 2 Series User’s Guide Filter Configuration 30-7 To configure TCP/IP rules, select TCP/IP Filter Rule from the Filter Type field and press [EN

Pagina 384 - 24.4.1 IP Alias Setup

ZyWALL 2 Series User’s Guide 30-8 Filter Configuration Table 30-3 TCP/IP Filter Rule Menu Fields FIELD DESCRIPTION OPTIONS Port # Enter the destinat

Pagina 385 - IP Alias 1, 2

ZyWALL 2 Series User’s Guide Filter Configuration 30-9 Table 30-3 TCP/IP Filter Rule Menu Fields FIELD DESCRIPTION OPTIONS Log Press [SPACE BAR] an

Pagina 386 - 24.5 Wireless LAN Setup

ZyWALL 2 Series User’s Guide 30-10 Filter Configuration Packetinto IP FilterMatchedMatchedYesAction MatchedAction Not MatchedMore?NoFilter Active?Chec

Pagina 387

ZyWALL 2 Series User’s Guide Filter Configuration 30-11 30.2.3 Configuring a Generic Filter Rule This section shows you how to configure a generic

Pagina 388

ZyWALL 2 Series User’s Guide 30-12 Filter Configuration Table 30-4 Menu 21.1.1.1: Generic Filter Rule FIELD DESCRIPTION OPTIONS Filter Type Use [SPAC

Pagina 389

ZyWALL 2 Series User’s Guide Filter Configuration 30-13 30.3 Example Filter Let’s look at an example to block outside users from accessing the ZyWAL

Pagina 390

ZyWALL 2 Series User’s Guide Introducing the Web Configurator 2-7 Table 2-1 Web Configurator Screens Summary LINK TAB FUNCTION SNMP Use this scr

Pagina 391 - Internet Access

ZyWALL 2 Series User’s Guide 30-14 Filter Configuration Figure 30-9 Example Filter: Menu 21.1.3.1 When you press [ENTER] to confirm, you will see the

Pagina 392 - 25-2 Internet Access

ZyWALL 2 Series User’s Guide Filter Configuration 30-15 Figure 30-10 Example Filter Rules Summary: Menu 21.1.3 After you’ve created the

Pagina 393 - 25.3 PPTP Encapsulation

ZyWALL 2 Series User’s Guide 30-16 Filter Configuration 30.4 Filter Types and NAT There are two classes of filter rules, Generic Filter (Device) rule

Pagina 394 - 25.4 PPPoE Encapsulation

ZyWALL 2 Series User’s Guide Filter Configuration 30-17 30.6 Applying a Filter This section shows you where to apply the filter(s) after you desig

Pagina 395 - 25.5 Basic Setup Complete

ZyWALL 2 Series User’s Guide 30-18 Filter Configuration Figure 30-13 Filtering Remote Node Traffic Menu 11.5 – Remote Node Filter Setup Input

Pagina 396

ZyWALL 2 Series User’s Guide SNMP Configuration 31-1 Chapter 31 SNMP Configuration This chapter explains SNMP configuration menu 22. 31.1 SNMP Confi

Pagina 397 - Part XII:

ZyWALL 2 Series User’s Guide 31-2 SNMP Configuration Table 31-1 Menu 22: SNMP Configuration FIELD DESCRIPTION EXAMPLE Trap Community Type the Trap

Pagina 398

SMT System Maintenance XIII Part XIII: SMT System Maintenance This part covers system information and diagnosis, firmware and configuration file

Pagina 400

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-1 Chapter 32 System Information & Diagnosis This chapter covers SMT menus 24.1

Pagina 402 - Nailed-Up Connection

ZyWALL 2 Series User’s Guide 32-2 System Information and Diagnosis monitor your ZyWALL. Specifically, it gives you information on your system firmwa

Pagina 403

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-3 Table 32-1 System Maintenance: Status Menu Fields FIELD DESCRIPTION Status Shows

Pagina 404 - 26.2.3 PPTP Encapsulation

ZyWALL 2 Series User’s Guide 32-4 System Information and Diagnosis Step 2. Enter 2 to open Menu 24.2 - System Information and Console Port Speed.

Pagina 405 - 26.3 Edit IP

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-5 Table 32-2 Fields in System Maintenance: Information FIELD DESCRIPTION ZyNOS F/W

Pagina 406 - 26-8 Remote Node Setup

ZyWALL 2 Series User’s Guide 32-6 System Information and Diagnosis Figure 32-6 Menu 24.3: System Maintenance: Log and Trace 32.4.1 UNIX Syslog The

Pagina 407 - 26.4 Remote Node Filter

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-7 Table 32-3 System Maintenance Menu Syslog Parameters PARAMETER DESCRIPTION Log Fa

Pagina 408 - 26.5 Traffic Redirect

ZyWALL 2 Series User’s Guide 32-8 System Information and Diagnosis Filter log Message Format SdcmdSyslogSend(SYSLOG_FILLOG, SYSLOG_NOTICE, String

Pagina 409

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-9 32.4.2 Call-Triggering Packet Call-Triggering Packet displays information about t

Pagina 410 - 26-12 Remote Node Setup

ZyWALL 2 Series User’s Guide 32-10 System Information and Diagnosis Follow the procedure below to get to Menu 24.4 - System Maintenance – Diagnostic

Pagina 411 - Remote Node Setup 26-13

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-11 Figure 32-10 WAN & LAN DHCP The following table describes the diagnostic te

Pagina 412

ZyWALL 2 Series User’s Guide Wizard Setup 3-1 Chapter 3 Wizard Setup This chapter provides information on the Wizard Setup screens in the web confi

Pagina 414

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-1 Chapter 33 Firmware and Configuration File Maintenance This chapter tells you

Pagina 415 - Chapter 28

ZyWALL 2 User’s Guide 33-2 Firmware and Configuration File Maintenance ftp> get rom-0 config.cfg This is a sample FTP session saving the current

Pagina 416

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-3 preferred method for backing up your current configuration to your computer si

Pagina 417 - 28.2 NAT Setup

ZyWALL 2 User’s Guide 33-4 Firmware and Configuration File Maintenance Step 6. Use “get” to transfer files from the ZyWALL to the computer, for exam

Pagina 418 - 28.2.1 Address Mapping Sets

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-5 33.3.5 File Maintenance Over WAN TFTP, FTP and Telnet over the WAN will not wo

Pagina 419

ZyWALL 2 User’s Guide 33-6 Firmware and Configuration File Maintenance TFTP client program. For UNIX, use “get” to transfer from the ZyWALL to the co

Pagina 420 - Ordering Your Rules

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-7 Step 1. Display menu 24.5 and enter “y” at the following screen. Figure 33-3

Pagina 421

ZyWALL 2 User’s Guide 33-8 Firmware and Configuration File Maintenance 33.4 Restore Configuration This section shows you how to restore a previously

Pagina 422

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-9 Step 1. Launch the FTP client on your computer. Step 2. Enter “open”, follo

Pagina 423 - 28.4 General NAT Examples

ZyWALL 2 Series User’s Guide 3-2 Wizard Setup Figure 3-1 Wizard 1 3.3 Internet Access The ZyWALL offers three choices of encapsulation. They are E

Pagina 424 - 28.4.1 Internet Access Only

ZyWALL 2 User’s Guide 33-10 Firmware and Configuration File Maintenance Step 1. Display menu 24.6 and enter “y” at the following screen. Figure 33-9

Pagina 425

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-11 33.5 Uploading Firmware and Configuration Files This section shows you how t

Pagina 426

ZyWALL 2 User’s Guide 33-12 Firmware and Configuration File Maintenance 33.5.2 Configuration File Upload You see the following screen when you telnet

Pagina 427 - 10.132.50.1

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-13 transfers the configuration file on the ZyWALL to your computer and renames i

Pagina 428

ZyWALL 2 User’s Guide 33-14 Firmware and Configuration File Maintenance Step 3. Enter the command “sys stdio 0” to disable the console timeout, so t

Pagina 429

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-15 33.5.8 Uploading Firmware File Via Console Port Step 1. Select 1 from Menu 2

Pagina 430 - 10.132.20.3

ZyWALL 2 User’s Guide 33-16 Firmware and Configuration File Maintenance Figure 33-17 Example Xmodem Upload After the firmware upload process has com

Pagina 431

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-17 Figure 33-18 Menu 24.7.2 As Seen Using the Console Port Step 2. After the &

Pagina 432

ZyWALL 2 User’s Guide 33-18 Firmware and Configuration File Maintenance Figure 33-19 Example Xmodem Upload After the configuration upload process has

Pagina 433

ZyWALL 2 User’s Guide System Maintenance & Information 34-1 Chapter 34 System Maintenance Menus 8 to 10 This chapter leads you through SMT men

Pagina 434

ZyWALL 2 Series User’s Guide Wizard Setup 3-3 Figure 3-2 Wizard 2: Ethernet Encapsulation The following table describes the labels in this screen.

Pagina 435 - Introducing the Firewall

ZyWALL 2 User’s Guide 34-2 System Maintenance & Information 34.1.1 Command Syntax The command keywords are in courier new font. Enter the command

Pagina 436 - Active: Yes

ZyWALL 2 User’s Guide System Maintenance & Information 34-3 Table 34-1 Valid Commands ether These commands display Ethernet information and con

Pagina 437 - Filter Configuration

ZyWALL 2 User’s Guide 34-4 System Maintenance & Information Figure 34-4 Budget Management The total budget is the time limit on the accumul

Pagina 438 - Filter Structure

ZyWALL 2 User’s Guide System Maintenance & Information 34-5 Figure 34-5 Call History The following table describes the fields in this sc

Pagina 439 - Filter Set

ZyWALL 2 User’s Guide 34-6 System Maintenance & Information Select menu 24 in the main menu to open Menu 24 - System Maintenance, as shown next.

Pagina 440 - 1. Filter Setup

ZyWALL 2 User’s Guide System Maintenance & Information 34-7 Table 34-4 Menu 24.10 System Maintenance: Time and Date Setting FIELD DESCRIPTION En

Pagina 441

ZyWALL 2 User’s Guide 34-8 System Maintenance & Information ii. When the ZyWALL starts up, if there is a timeserver configured in menu 24.10. ii

Pagina 442 - Len Length

ZyWALL 2 User’s Guide Remote Management 35-1 Chapter 35 Remote Management This chapter covers remote management found in SMT menu 24.11. 35.1 Remote

Pagina 443

ZyWALL 2 User’s Guide 35-2 Remote Management Figure 35-1 Menu 24.11 – Remote Management Control The following table describes the fields in thi

Pagina 444 - 30-8 Filter Configuration

ZyWALL 2 User’s Guide Remote Management 35-3 Table 35-1 Menu 24.11 – Remote Management Control FIELD DESCRIPTION EXAMPLE Once you have filled in th

Pagina 445 - Filter Configuration 30-9

ZyWALL 2 Series User’s Guide Warranty v ZyXEL Limited Warranty ZyXEL warrants to the original end user (purchaser) that this product is free from an

Pagina 446 - 30-10 Filter Configuration

ZyWALL 2 Series User’s Guide 3-4 Wizard Setup Table 3-1 Ethernet Encapsulation LABEL DESCRIPTION Login Server IP Address Type the authentication ser

Pagina 448 - 30-12 Filter Configuration

SMT Advanced Management XIV Part XIV: SMT Advanced Management This part provides information on how to configure call scheduling, and VPN/IPSec

Pagina 450

ZyWALL 2 Series User’s Guide Call Scheduling 36-1 Chapter 36 Call Scheduling Call scheduling allows you to dictate when a remote node should

Pagina 451

ZyWALL 2 Series User’s Guide 36-2 Call Scheduling To set up a schedule set, select the schedule set you want to setup from menu 26 (1-12) and press

Pagina 452 - 30.4 Filter Types and NAT

ZyWALL 2 Series User’s Guide Call Scheduling 36-3 Table 36-1 Schedule Set Setup FIELD DESCRIPTION OPTIONS Day If you selected Weekly in the

Pagina 453 - 30.6 Applying a Filter

ZyWALL 2 Series User’s Guide 36-4 Call Scheduling Figure 36-3 Applying Schedule Set(s) to a Remote Node (PPPoE) You can apply up to four sch

Pagina 454

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-1 Chapter 37 VPN/IPSec Setup This chapter introduces the VPN SMT menus. 37.1 Introduction T

Pagina 455 - SNMP Configuration

ZyWALL 2 Series User’s Guide 37-2 VPN/IPSec Setup Figure 37-2 Menu 27: VPN/IPSec Setup 37.2 IPSec Summary Screen Type 1 in menu 27 and then

Pagina 456 - 31.2 SNMP Traps

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-3 Table 37-1 Menu 27.1: IPSec Summary FIELD DESCRIPTION EXAMPLE Name This field displays the

Pagina 457 - Part XIII:

ZyWALL 2 Series User’s Guide Wizard Setup 3-5 Figure 3-3 Wizard2: PPPoE Encapsulation The following table describes the labels in this screen. Tab

Pagina 458

ZyWALL 2 Series User’s Guide 37-4 VPN/IPSec Setup Table 37-1 Menu 27.1: IPSec Summary FIELD DESCRIPTION EXAMPLE Key Mgt This field displays the SA’s

Pagina 459 - Chapter 32

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-5 Table 37-1 Menu 27.1: IPSec Summary FIELD DESCRIPTION EXAMPLE Select Command Press [SPACE B

Pagina 460 - FIELD DESCRIPTION

ZyWALL 2 Series User’s Guide 37-6 VPN/IPSec Setup Figure 37-4 Menu 27.1.1: IPSec Setup You must also configure menu 27.1.1.1 or menu 2

Pagina 461

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-7 Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE NAT Traversal Select this c

Pagina 462 - 32.3.1 System Information

ZyWALL 2 Series User’s Guide 37-8 VPN/IPSec Setup Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE Peer ID type Press [SPACE BAR] to cho

Pagina 463 - 32.4 Log and Trace

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-9 Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE Local Local IP addresses mus

Pagina 464 - 32.4.1 UNIX Syslog

ZyWALL 2 Series User’s Guide 37-10 VPN/IPSec Setup Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE End Enter a port number in this fie

Pagina 465 - PARAMETER DESCRIPTION

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-11 Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE Port Start 0 is the default

Pagina 466

ZyWALL 2 Series User’s Guide 37-12 VPN/IPSec Setup Figure 37-5 Menu 27.1.1.1: IKE Setup Table 37-3 Menu 27.1.1.1: IKE Setup FIELD DES

Pagina 467 - 32.4.3 Diagnostic

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-13 Table 37-3 Menu 27.1.1.1: IKE Setup FIELD DESCRIPTION EXAMPLEEncryption Algorithm When DES

Pagina 468 - 32.4.4 WAN DHCP

ZyWALL 2 Series User’s Guide 3-6 Wizard Setup Table 3-2 PPPoE Encapsulation LABEL DESCRIPTION Idle Timeout Type the time in seconds that elapses bef

Pagina 469

ZyWALL 2 Series User’s Guide 37-14 VPN/IPSec Setup Table 37-3 Menu 27.1.1.1: IKE Setup FIELD DESCRIPTION EXAMPLEEncapsulation Press [SPACE BAR] to ch

Pagina 470

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-15 To edit this menu, move the cursor to the Edit Manual Setup field in Menu 27.1.1 – IPSec S

Pagina 471 - Chapter 33

ZyWALL 2 Series User’s Guide 37-16 VPN/IPSec Setup Table 37-5 Menu 27.1.1.2: Manual Setup FIELD DESCRIPTION EXAMPLE Key3 Enter a unique eight-charac

Pagina 472 - 33.3 Backup Configuration

ZyWALL 2 Series User’s Guide SA Monitor 38-1 Chapter 38 SA Monitor This chapter teaches you how to manage your SAs by using the SA Monitor in

Pagina 473 - 33.3.1 Backup Configuration

ZyWALL 2 Series User’s Guide 38-2 SA Monitor Table 38-1 Menu 27.2: SA Monitor FIELD DESCRIPTION EXAMPLE # This is the security association index

Pagina 474 - 33.3.4 GUI-based FTP Clients

General Appendices XV Part XV: General Appendices This part provides background information about troubleshooting, setting up your computer’s I

Pagina 476 - 33.3.7 TFTP Command Example

ZyWALL 2 Series User’s Guide Troubleshooting A-1 Appendix A Troubleshooting This chapter covers potential problems and possible remedies. After each

Pagina 477 - Then click Receive

ZyWALL 2 Series User’s Guide Troubleshooting A-2Problems with the LAN Interface Chart 3 Troubleshooting the LAN Interface PROBLEM CORRECTIVE ACTION

Pagina 478 - 33.4 Restore Configuration

ZyWALL 2 Series User’s Guide Troubleshooting A-3 Problems with Internet Access Chart 5 Troubleshooting Internet Access PROBLEM CORRECTIVE ACTION Con

Pagina 479

ZyWALL 2 Series User’s Guide Wizard Setup 3-7 Figure 3-4 Wizard 2: PPTP Encapsulation The following table describes the labels in this screen. Tab

Pagina 481 - 33.5.1 Firmware File Upload

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-1 Appendix B Setting up Your Computer’s IP Address All computers must have a 10

Pagina 482

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-2The Network window Configuration tab displays a list of installed components.

Pagina 483 - 33.5.5 TFTP File Upload

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-3 1. Click the IP Address tab. -If your IP address is dynamic, select Obtain an

Pagina 484

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-43. Click the Gateway tab. -If you do not know your gateway’s IP address, rem

Pagina 485

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-5 1. For Windows XP, click Start, Control Panel. In Windows 2000/NT, click Star

Pagina 486

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-64. Select Internet Protocol (TCP/IP) (under the General tab in Win XP) and cli

Pagina 487

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-7 6. -If you do not know your gateway's IP address, remove any previously

Pagina 488 - ZyWALL 2 User’s Guide

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-8 7. In the Internet Protocol TCP/IP Properties window (the General tab in Wind

Pagina 489 - Chapter 34

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-9 1. Click the Apple menu, Control Panel and double-click TCP/IP to open the TC

Pagina 490 - 34.1.2 Command Usage

ZyWALL 2 Series User’s Guide 3-8 Wizard Setup Table 3-3 PPTP Encapsulation LABEL DESCRIPTION My IP Address Type the (static) IP address assigned to

Pagina 491 - 34.2 Call Control Support

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-104. For statically assigned settings, do the following: -From the Configure

Pagina 492 - 34.2.2 Call History

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-11 2. Click Network in the icon bar. - Select Automatic from the Location li

Pagina 494 - 10. Time and Date Setting

ZyWALL 2 Series User’s Guide Triangle Route C-1 Appendix C Triangle Route The Ideal Setup When the firewall is on, your ZyWALL acts as a secure g

Pagina 495 - 34.3.1 Resetting the Time

ZyWALL 2 Series User’s Guide Triangle Route C-2 Diagram 2 “Triangle Route” Problem The “Triangle Route” Solutions This section presents you two solu

Pagina 496

ZyWALL 2 Series User’s Guide Triangle Route C-3 Diagram 3 IP Alias Gateways on the WAN Side A second solution to the “triangle route” problem is t

Pagina 497 - Remote Management

ZyWALL 2 Series User’s Guide Triangle Route C-4Step 3. Use the following commands to allow/disallow triangle route. sys firewall ignore triangle al

Pagina 498

ZyWALL 2 Series User’s Guide Wireless LAN and IEEE 802.11 D-1 Appendix D Wireless LAN and IEEE 802.11 A wireless LAN (WLAN) provides a flexible da

Pagina 499 - FIELD DESCRIPTION EXAMPLE

ZyWALL 2 Series User’s Guide D-2 Wireless LAN and IEEE 802.11 Spread Spectrum (DSSS) and Frequency-Hopping Spread Spectrum (FHSS), in the 2.4 to 2.

Pagina 500

ZyWALL 2 Series User’s Guide Wireless LAN and IEEE 802.11 D-3 could be any type of network, it is almost invariably an Ethernet LAN. Mobile nodes c

Pagina 501 - Part XIV:

ZyWALL 2 Series User’s Guide Wizard Setup 3-9 Regardless of your particular situation, do not create an arbitrary IP address; always follow the gui

Pagina 503 - Call Scheduling

ZyWALL 2 Series User’s Guide Wireless LAN with IEEE 802.1x E-1 Appendix E Wireless LAN With IEEE 802.1x As wireless networks become popular for bot

Pagina 504

ZyWALL 2 Series User’s Guide Wireless LAN with IEEE 802.1x E-2RADIUS Server Authentication Sequence The following figure depicts a typical wirele

Pagina 505

ZyWALL 2 Series User’s Guide Types of EAP Authentication F-1 Appendix F Types of EAP Authentication This appendix discusses three popular EAP auth

Pagina 506

ZyWALL 2 Series User’s Guide Types of EAP Authentication F-2TTLS supports EAP methods and legacy authentication methods such as PAP, CHAP, MS-CHAP

Pagina 507 - VPN/IPSec Setup

ZyWALL 2 Series User’s Guide PPPoE G-1 Appendix G PPPoE PPPoE in Action An ADSL modem bridges a PPP session over Ethernet (PPP over Ethernet, RFC 25

Pagina 508 - 37.2 IPSec Summary Screen

ZyWALL 2 Series User’s Guide G-2 PPPoE The PPPoE driver makes the Ethernet appear as a serial link to the PC and the PC runs PPP over it, while the m

Pagina 509 - VPN/IPSec Setup 37-3

ZyWALL 2 Series User’s Guide PPTP H-1 Appendix H PPTP What is PPTP? PPTP (Point-to-Point Tunneling Protocol) is a Microsoft proprietary protocol (R

Pagina 510 - 37-4 VPN/IPSec Setup

ZyWALL 2 Series User’s Guide H-2 PPTP PPTP is very similar to L2TP, since L2TP is based on both PPTP and L2F (Cisco’s Layer 2 Forwarding). Conceptual

Pagina 511 - 37.3 IPSec Setup

ZyWALL 2 Series User’s Guide PPTP H-3 Diagram H-3 Example Message Exchange between PC and an ANT PPP Data Connection The PPP frames are tunneled b

Pagina 512

ZyWALL 2 Series User’s Guide 3-10 Wizard Setup 3.4.4 WAN MAC Address Every Ethernet device has a unique MAC (Media Access Control) address. The MAC a

Pagina 514 - 37-8 VPN/IPSec Setup

ZyWALL 2 Series User’s Guide IP Subnetting I-1 Appendix I IP Subnetting IP Addressing Routers “route” based on the network number. The router that d

Pagina 515 - VPN/IPSec Setup 37-9

ZyWALL 2 Series User’s Guide I-2 IP Subnetting A class “A” address (24 host bits) can have 224 –2 hosts (approximately 16 million hosts). Since the

Pagina 516 - 37-10 VPN/IPSec Setup

ZyWALL 2 Series User’s Guide IP Subnetting I-3 of ones beginning from the left most bit of the mask, followed by a continuous sequence of zeros, for

Pagina 517 - 37.4 IKE Setup

ZyWALL 2 Series User’s Guide I-4 IP Subnetting Divide the network 192.168.1.0 into two separate subnets by converting one of the host ID bits of the

Pagina 518

ZyWALL 2 Series User’s Guide IP Subnetting I-5 actual host for the first subnet is 192.168.1.1 and the highest is 192.168.1.126. Similarly the host I

Pagina 519 - VPN/IPSec Setup 37-13

ZyWALL 2 Series User’s Guide I-6 IP Subnetting Chart I-10 Subnet 4 NETWORK NUMBER LAST OCTET BIT VALUE IP Address 192.168.1. 192 IP Address (Bin

Pagina 520 - 37.5 Manual Setup

ZyWALL 2 Series User’s Guide IP Subnetting I-7 4 255.255.255.240 (/28) 16 14 5 255.255.255.248 (/29) 32 6 6 255.255.255.252 (/30) 64 2 7 255.255.2

Pagina 521

ZyWALL 2 Series User’s Guide I-8 IP Subnetting Chart I-13 Class B Subnet Planning NO. “BORROWED” HOST BITS SUBNET MASK NO. SUBNETS NO. HOSTS PER S

Pagina 522 - 37-16 VPN/IPSec Setup

ZyWALL 2 Series User’s Guide Safety Warnings and Instructions J-1 Appendix J Safety Warnings and Instructions 1. Be sure to read and follow all warn

Pagina 523 - SA Monitor

ZyWALL 2 Series User’s Guide Wizard Setup 3-11 Figure 3-5 Wizard 3 The following table describes the labels in this screen. Table 3-6 Wizard 3 LAB

Pagina 525 - Part XV:

Command, Log Appendices and Index XVI Part XVI: Command, Log Appendices and Index This part provides information on the command line interface,

Pagina 527 - Troubleshooting

ZyWALL 2 Series User’s Guide Command Interpreter K-1 Appendix K Command Interpreter The following describes how to use the command interpreter.

Pagina 529

ZyWALL 2 Series User’s Guide Firewall Commands L-1 Appendix L Firewall Commands The following describes the firewall commands. See the Command Int

Pagina 530

ZyWALL 2 User’s Guide L-2 Firewall Commands Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION config display firewall e-mail This comm

Pagina 531 - Appendix B

ZyWALL 2 Series User’s Guide Firewall Commands L-3 Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION config edit firewall attack block &

Pagina 532

ZyWALL 2 User’s Guide L-4 Firewall Commands Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION Config edit firewall set <set #> defau

Pagina 533

ZyWALL 2 Series User’s Guide Firewall Commands L-5 Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION Config edit firewall set <se

Pagina 534 - Windows 2000/NT/XP

ZyWALL 2 Series User’s Guide 3-12 Wizard Setup Table 3-6 Wizard 3 LABEL DESCRIPTION Remote IP Subnet Mask Enter the gateway IP subnet mask (if your

Pagina 535

ZyWALL 2 User’s Guide L-6 Firewall Commands Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION config edit firewall set <set #> r

Pagina 536

ZyWALL 2 Series User’s Guide NetBIOS Filter Commands M-1 Appendix M NetBIOS Filter Commands The following describes the NetBIOS packet filter comma

Pagina 537

ZyWALL 2 User’s Guide M-2 NetBIOS Filter Commands Chart M-1 NetBIOS Filter Default Settings NAME DESCRIPTION EXAMPLE Between LAN and WAN This field

Pagina 538

ZyWALL 2 Series User’s Guide NetBIOS Filter Commands M-3 Command: sys filter netbios config 4 off This command stops NetBIOS commands from initiati

Pagina 540

ZyWALL 2 Series User’s Guide Boot Commands N-1 Appendix N Boot Commands The BootModule AT commands execute from within the router’s bootup software

Pagina 541

ZyWALL 2 User’s Guide N-2 Boot Commands Diagram N-2 Boot Module Commands AT just answer OK ATHE print h

Pagina 542

ZyWALL 2 Series User’s Guide Log Descriptions O-1 Appendix O Log Descriptions Chart O-1 System Error Logs LOG MESSAGE DESCRIPTION %s exceeds the

Pagina 543 - Triangle Route

ZyWALL 2 User’s Guide O-2 Log Descriptions Chart O-2 System Maintenance Logs TELNET Login Fail Someone has failed to log on to the router via telnet

Pagina 544

ZyWALL 2 Series User’s Guide Log Descriptions O-3 Chart O-5 Attack Logs LOG MESSAGE DESCRIPTION attack IGMP The firewall detected an IGMP attack.

Pagina 545

ZyWALL 2 Series User’s Guide Wizard Setup 3-13 Figure 3-6 Internet Access Wizard Setup Complete

Pagina 546

ZyWALL 2 User’s Guide O-4 Log Descriptions Chart O-5 Attack Logs LOG MESSAGE DESCRIPTION syn flood TCP The firewall detected a TCP syn flood attack

Pagina 547 - Appendix D

ZyWALL 2 Series User’s Guide Log Descriptions O-5 Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Firewall default policy: TCP (set:%d) TCP access m

Pagina 548

ZyWALL 2 User’s Guide O-6 Log Descriptions Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Firewall rule match: ESP (set:%d, rule:%d) ESP access matc

Pagina 549

ZyWALL 2 Series User’s Guide Log Descriptions O-7 Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Firewall rule NOT match: (set:%d, rule:%d) Access

Pagina 550

ZyWALL 2 User’s Guide O-8 Log Descriptions Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Filter match DROP <set %d/rule %d> Access matched th

Pagina 551 - Appendix E

ZyWALL 2 Series User’s Guide Log Descriptions O-9 Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Packet without a NAT table entry blocked The route

Pagina 552 - Client computer

ZyWALL 2 User’s Guide O-10 Log Descriptions Chart O-8 ICMP Notes TYPE CODE DESCRIPTION 3 Destination Unreachable 0 Net unreachable 1 Host unreac

Pagina 553 - Types of EAP Authentication

ZyWALL 2 Series User’s Guide Log Descriptions O-11 Chart O-8 ICMP Notes TYPE CODE DESCRIPTION 14 Timestamp Reply 0 Timestamp reply message 15 I

Pagina 554

ZyWALL 2 User’s Guide O-12 Log Descriptions Diagram O-1 Example VPN Initiator IPSec Log VPN Responder IPSec Log The following figure shows a typical

Pagina 555 - Appendix G

ZyWALL 2 Series User’s Guide Log Descriptions O-13 A PYLD_MALFORMED packet usually means that the two ends of the VPN tunnel are not using the same

Pagina 556

ZyWALL 2 Series User’s Guide vi Customer Support Customer Support When you contact your customer support representative please have the following inf

Pagina 558 - Call Connection

ZyWALL 2 User’s Guide O-14 Log Descriptions Chart O-10 Sample IKE Key Exchange Logs LOG MESSAGE DESCRIPTION !! Invalid IP <IP start>/<IP e

Pagina 559 - PPP Data Connection

ZyWALL 2 Series User’s Guide Log Descriptions O-15 Chart O-10 Sample IKE Key Exchange Logs LOG MESSAGE DESCRIPTION vs. My Local <IP address>

Pagina 560

ZyWALL 2 User’s Guide O-16 Log Descriptions The following table shows RFC-2408 ISAKMP payload types that the log displays. Please refer to the RFC f

Pagina 561 - IP Subnetting

ZyWALL 2 Series User’s Guide Log Descriptions O-17 Chart O-13 Log Categories and Available Settings LOG CATEGORIES AVAILABLE PARAMETERS attack 0,

Pagina 562

ZyWALL 2 User’s Guide O-18 Log Descriptions ras> sys logs display access # .time source destination

Pagina 563

ZyWALL 2 Series User’s Guide Brute-Force Password Guessing Protection P-1 Appendix P Brute-Force Password Guessing Protection The following describ

Pagina 565

ZyWALL 2 Series User’s Guide Index Q-1 Appendix Q Index 1 10/100 Mbps Ethernet WAN ... 1-2 4 4-Port Switch ...

Pagina 566

ZyWALL 2 Series User’s Guide Q-2 Index Configuration File Upload... 33-16 File Backup ...

Pagina 567

ZyWALL 2 Series User’s Guide Index Q-3 Filter... 23-12, 24-1, 26-9, 30-1 Applying ...

Pagina 568 - I-8 IP Subnetting

System and LAN II Part II: System and LAN This part covers configuration of the system, and LAN screens.

Pagina 569 - Appendix J

ZyWALL 2 Series User’s Guide Q-4 Index Inside Local Address ... 8-1 Internet Access...

Pagina 570

ZyWALL 2 Series User’s Guide Index Q-5 N Nailed-up Connection ... 26-4 Nailed-Up Connection ...

Pagina 571 - Part XVI:

ZyWALL 2 Series User’s Guide Q-6 Index Replacement ...v Reports...

Pagina 572

ZyWALL 2 Series User’s Guide Index Q-7 System Management Terminal ... 21-2 System Name ...

Pagina 573 - Command Interpreter

ZyWALL 2 Series User’s Guide Q-8 Index Wireless LAN Setup... 24-6 Wizard Setup ...

Pagina 575 - Firewall Commands

ZyWALL 2 Series User’s Guide System 4-1 Chapter 4 System Screens This chapter provides information on the System screens. 4.1 System Overview See the

Pagina 576 - Chart L-1 Firewall Commands

ZyWALL 2 Series User’s Guide 4-2 System Table 4-1 System General Setup LABEL DESCRIPTION System Name Choose a descriptive name for identification

Pagina 577 - Firewall Commands L-3

ZyWALL 2 Series User’s Guide System 4-3 4.3 Dynamic DNS Dynamic DNS allows you to update your current dynamic IP address with one or many dynamic DNS

Pagina 578 - L-4 Firewall Commands

ZyWALL 2 Series User’s Guide 4-4 System Figure 4-2 DDNS The following table describes the fields in this screen. Table 4-2 DDNS LABEL DESCRIPTION

Pagina 579 - Firewall Commands L-5

ZyWALL 2 Series User’s Guide System 4-5 Table 4-2 DDNS LABEL DESCRIPTION Host Names 1~3 Enter the host names in the three fields provided. You can s

Pagina 580 - L-6 Firewall Commands

ZyWALL 2 Series User’s Guide 4-6 System Figure 4-3 Password The following table describes the fields in this screen. Table 4-3 Password LABEL DESC

Pagina 581 - NetBIOS Filter Commands

ZyWALL 2 Series User’s Guide System 4-7 Table 4-4 Default Time Servers ntp1.cs.wisc.edu ntp1.gbg.netnod.se ntp2.cs.wisc.edu tock.usno.navy.mil ntp3.c

Pagina 582

ZyWALL 2 Series User’s Guide Table of Contents vii Table of Contents Copyright...

Pagina 583 - Command:

ZyWALL 2 Series User’s Guide 4-8 System Figure 4-4 Time Setting The following table describes the fields in this screen. Table 4-5 Time Setting LA

Pagina 584

ZyWALL 2 Series User’s Guide System 4-9 Table 4-5 Time Setting LABEL DESCRIPTION Time Server Address Enter the address of your time server. Check wit

Pagina 586

ZyWALL 2 Series User’s Guide LAN 5-1 Chapter 5 LAN Screens This chapter describes how to configure LAN settings. 5.1 LAN Overview Local Area Network

Pagina 587 - Log Descriptions

ZyWALL 2 Series User’s Guide 5-2 LAN three numbers specify the network number while the last number identifies an individual computer on that networ

Pagina 588

ZyWALL 2 Series User’s Guide LAN 5-3 RIP Version controls the format and the broadcasting method of the RIP packets that the ZyWALL sends (it recogni

Pagina 589

ZyWALL 2 Series User’s Guide 5-4 LAN Figure 5-1 IP The following table describes the fields in this screen. Table 5-1 IP LABEL DESCRIPTION DHCP Se

Pagina 590

ZyWALL 2 Series User’s Guide LAN 5-5 Table 5-1 IP LABEL DESCRIPTION DHCP Server DHCP (Dynamic Host Configuration Protocol, RFC 2131 and RFC 2132) a

Pagina 591

ZyWALL 2 Series User’s Guide 5-6 LAN Table 5-1 IP LABEL DESCRIPTION RIP Version The RIP Version field controls the format and the broadcasting meth

Pagina 592

ZyWALL 2 Series User’s Guide LAN 5-7 Figure 5-2 Static DHCP The following table describes the fields in this screen. Table 5-2 Static DHCP LABEL DES

Pagina 593

ZyWALL 2 Series User’s Guide viii Table of Contents 5.6 Configuring IP ...

Pagina 594

ZyWALL 2 Series User’s Guide 5-8 LAN When you use IP alias, you can also configure firewall rules to control access between the LAN's logical n

Pagina 595

ZyWALL 2 Series User’s Guide LAN 5-9 The following table describes the fields in this screen. Table 5-3 IP Alias LABEL DESCRIPTION IP Alias 1,2 Sele

Pagina 597

WAN and Wireless LAN III Part III: WAN and Wireless LAN This part covers configuration of the WAN and Wireless LAN screens.

Pagina 599 - Log Descriptions O-13

ZyWALL 2 Series User’s Guide WAN Screens 6-1 Chapter 6 WAN Screens This chapter describes how to configure WAN settings. 6.1 WAN Overview See the LA

Pagina 600

ZyWALL 2 Series User’s Guide 6-2 WAN Screens Table 6-1 Private IP Address Ranges 10.0.0.0 - 10.255.255.255 172.16.0.0 - 172.31.255.255 192.168.0.0 -

Pagina 601

ZyWALL 2 Series User’s Guide WAN Screens 6-3 Figure 6-1 WAN Setup: Route The following table describes the fields in this screen. Table 6-3 WAN Setu

Pagina 602

ZyWALL 2 Series User’s Guide 6-4 WAN Screens Figure 6-2 Ethernet Encapsulation The following table describes the fields in this screen. Table 6-4 E

Pagina 603 - Displaying Logs

ZyWALL 2 Series User’s Guide WAN Screens 6-5 Table 6-4 Ethernet Encapsulation LABEL DESCRIPTION Reset Click Reset to begin configuring this screen af

Pagina 604

ZyWALL 2 Series User’s Guide Table of Contents ix 10.3 Introduction to ZyXEL’s Firewall...

Pagina 605 - Protection

ZyWALL 2 Series User’s Guide 6-6 WAN Screens Figure 6-3 PPPoE Encapsulation The following table describes the fields in this screen. Table 6-5 PPPo

Pagina 606

ZyWALL 2 Series User’s Guide WAN Screens 6-7 Table 6-5 PPPoE Encapsulation LABEL DESCRIPTION Password Type the password associated with the User Nam

Pagina 607 - Appendix Q

ZyWALL 2 Series User’s Guide 6-8 WAN Screens Figure 6-4 PPTP Encapsulation The following table describes the fields in this screen. Table 6-6 PPTP

Pagina 608

ZyWALL 2 Series User’s Guide WAN Screens 6-9 Table 6-6 PPTP Encapsulation LABEL DESCRIPTION User Name Type the user name given to you by your ISP.

Pagina 609

ZyWALL 2 Series User’s Guide 6-10 WAN Screens Figure 6-5 IP Setup The following table describes the fields in this screen. Table 6-7 IP Setup LABEL

Pagina 610

ZyWALL 2 Series User’s Guide WAN Screens 6-11 Table 6-7 IP Setup LABEL DESCRIPTION My WAN IP Address (or IP Address) Enter your WAN IP address in th

Pagina 611

ZyWALL 2 Series User’s Guide 6-12 WAN Screens Table 6-7 IP Setup LABEL DESCRIPTION Private (PPPoE and PPTP only) This parameter determines if the Z

Pagina 612

ZyWALL 2 Series User’s Guide WAN Screens 6-13 Table 6-7 IP Setup LABEL DESCRIPTION Windows Networking (NetBIOS over TCP/IP): Windows Networking (Net

Pagina 613

ZyWALL 2 Series User’s Guide 6-14 WAN Screens The MAC address screen allows users to configure the WAN port's MAC Address by either using the f

Pagina 614

ZyWALL 2 Series User’s Guide WAN Screens 6-15 Figure 6-8 Traffic Redirect LAN Setup 6.9 Configuring Traffic Redirect To change your ZyWALL’s Traffi

Comentarios a estos manuales

Sin comentarios