Zyxel-communications Internet Security Gateway ZyWALL 2 Series Instrukcja Użytkownika Strona 1

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Sprzęt komputerowy Zyxel-communications Internet Security Gateway ZyWALL 2 Series. ZyXEL Communications Internet Security Gateway ZyWALL 2 Series User Manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 0
ZyWALL 2 Series
Internet Security Gateway
User’s Guide
Version 3.62
June 2004
Przeglądanie stron 0
1 2 3 4 5 6 ... 613 614

Podsumowanie treści

Strona 1 - ZyWALL 2 Series

ZyWALL 2 Series Internet Security Gateway User’s Guide Version 3.62 June 2004

Strona 2 - Copyright

ZyWALL 2 Series User’s Guide x Table of Contents 14.13 Configuring Advanced IKE Setup ...

Strona 3 - Interference Statement

ZyWALL 2 Series User’s Guide 6-16 WAN Screens Figure 6-9 Traffic Redirect The following table describes the fields in this screen. Table 6-8 Traffi

Strona 4 - Caution

ZyWALL 2 Series User’s Guide WAN Screens 6-17 Table 6-8 Traffic Redirect LABEL DESCRIPTION Check WAN IP Address Configuration of this field is option

Strona 5 - ZyXEL Limited Warranty

ZyWALL 2 Series User’s Guide 6-18 WAN Screens Figure 6-10 Dial Backup Setup

Strona 6 - Customer Support

ZyWALL 2 Series User’s Guide WAN Screens 6-19 The following table describes the labels in this screen. Table 6-9 Dial Backup Setup LABEL DESCRIPTION

Strona 7 - Table of Contents

ZyWALL 2 Series User’s Guide 6-20 WAN Screens Table 6-9 Dial Backup Setup LABEL DESCRIPTION Get IP Address Automatically from Remote Server Type the

Strona 8

ZyWALL 2 Series User’s Guide WAN Screens 6-21 Table 6-9 Dial Backup Setup LABEL DESCRIPTION RIP Version The RIP Version field controls the format and

Strona 9

ZyWALL 2 Series User’s Guide 6-22 WAN Screens Table 6-9 Dial Backup Setup LABEL DESCRIPTION Configure Budget Select this check box to have the dial

Strona 10

ZyWALL 2 Series User’s Guide WAN Screens 6-23 6.11.3 Response Strings The response strings tell the ZyWALL the tags, or labels, immediately preceding

Strona 11

ZyWALL 2 Series User’s Guide 6-24 WAN Screens Figure 6-11 Advanced Setup The following table describes the labels in this screen. Table 6-10 Advanc

Strona 12

ZyWALL 2 Series User’s Guide WAN Screens 6-25 Table 6-10 Advanced Setup LABEL DESCRIPTION EXAMPLE Drop Type the AT Command string to drop a call. &q

Strona 13

ZyWALL 2 Series User’s Guide Table of Contents xi 17.9 Secure Telnet Using SSH Examples ...

Strona 15 - List of Figures

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-1 Chapter 7 Wireless LAN Screens This chapter discusses how to configure Wireless LAN on the Z

Strona 16

ZyWALL 2 Series User’s Guide 7-2 Wireless LAN Screens is they do not know if the channel is currently being used. Therefore, they are considered hid

Strona 17

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-3 A large Fragmentation Threshold is recommended for networks not prone to interference while you

Strona 18

ZyWALL 2 Series User’s Guide 7-4 Wireless LAN Screens 7.4 Configuring Wireless LAN If you are configuring the ZyWALL from a computer connected to t

Strona 19

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-5 Table 7-1 Wireless LABEL DESCRIPTION Enable Wireless LAN The wireless LAN is turned off by def

Strona 20

ZyWALL 2 Series User’s Guide 7-6 Wireless LAN Screens 7.5 Configuring MAC Filter The MAC filter screen allows you to configure the ZyWALL to give ex

Strona 21

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-7 Table 7-2 MAC Address Filter LABEL DESCRIPTION Active Select or clear the check box to enable

Strona 22 - List of Tables

ZyWALL 2 Series User’s Guide 7-8 Wireless LAN Screens • Access-Request Sent by the ZyWALL requesting authentication. • Access-Reject Sent by a RAD

Strona 23

ZyWALL 2 Series User’s Guide Wireless LAN Screens 7-9 Figure 7-5 EAP Authentication The details below provide a general description of how IEEE 802

Strona 24

ZyWALL 2 Series User’s Guide xii Table of Contents 23.3 Configuring Dial Backup in Menu 2...

Strona 25

ZyWALL 2 Series User’s Guide 7-10 Wireless LAN Screens Figure 7-6 802.1X Authentication The following table describes the fields in this screen. Ta

Strona 26 - Preface

NAT and Static Route IV Part IV: NAT and Static Route This part covers Network Address Translation and setting up static routes.

Strona 28

ZyWALL 2 Series User’s Guide NAT 8-1 Chapter 8 Network Address Translation (NAT) This chapter discusses how to configure NAT on the ZyWALL.

Strona 29 - Part I:

ZyWALL 2 Series User’s Guide 8-2 NAT local address before forwarding it to the original inside host. Note that the IP address (either local o

Strona 30

ZyWALL 2 Series User’s Guide NAT 8-3 8.1.4 NAT Application The following figure illustrates a possible NAT application, where three inside LA

Strona 31 - Getting to Know Your ZyWALL

ZyWALL 2 Series User’s Guide 8-4 NAT  Many to One: In Many-to-One mode, the ZyWALL maps multiple local IP addresses to one global IP address

Strona 32 - 1.2.2 Non-Physical Features

ZyWALL 2 Series User’s Guide NAT 8-5 8.2.1 SUA (Single User Account) Versus NAT SUA (Single User Account) is an implementation of a subset o

Strona 33

ZyWALL 2 Series User’s Guide 8-6 NAT Table 8-3 Services and Port Numbers SERVICES PORT NUMBER DNS (Domain Name System) 53 Finger 79 HTTP (Hy

Strona 34

ZyWALL 2 Series User’s Guide NAT 8-7 8.4 Configuring SUA Server If you do not assign a Default Server IP address, the ZyWALL discards all p

Strona 35

ZyWALL 2 Series User’s Guide Table of Contents xiii 30.5 Firewall Versus Filters ...

Strona 36 - Upgrade ZyWALL Firmware

ZyWALL 2 Series User’s Guide 8-8 NAT Table 8-4 SUA Server LABEL DESCRIPTION Default Server In addition to the servers for specified services

Strona 37

ZyWALL 2 Series User’s Guide NAT 8-9 Figure 8-5 Address Mapping The following table describes the fields in this screen. Table 8-5 Address M

Strona 38

ZyWALL 2 Series User’s Guide 8-10 NAT Table 8-5 Address Mapping LABEL DESCRIPTION Type 1. One-to-One mode maps one local IP address to one gl

Strona 39 - Chapter 2

ZyWALL 2 Series User’s Guide NAT 8-11 Table 8-6 Address Mapping Rule LABEL DESCRIPTION Type Choose the port mapping type from one of the fol

Strona 40 - 2.3 Resetting the ZyWALL

ZyWALL 2 Series User’s Guide 8-12 NAT receives a response with a specific port number and protocol ("incoming" port), the ZyWALL fo

Strona 41

ZyWALL 2 Series User’s Guide NAT 8-13 Figure 8-8 Trigger Port The following table describes the fields in this screen. Table 8-7 Trigger Por

Strona 42 - LINK TAB FUNCTION

ZyWALL 2 Series User’s Guide 8-14 NAT Table 8-7 Trigger Port LABEL DESCRIPTION Incoming Incoming is a port (or a range of ports) that a serv

Strona 43

ZyWALL 2 Series User’s Guide Static Route Screens 9-1 Chapter 9 Static Route Screens This chapter shows you how to configure static routes for yo

Strona 44

ZyWALL 2 Series User’s Guide 9-2 Static Route Screens Figure 9-2 Static Route Screen The following table describes the fields in this screen. Table

Strona 45

ZyWALL 2 Series User’s Guide Static Route Screens 9-3 Table 9-1 IP Static Route Summary LABEL DESCRIPTION Gateway This is the IP address of the g

Strona 46

ZyWALL 2 Series User’s Guide xiv Table of Contents Appendix F Types of EAP Authentication ...

Strona 47 - Wizard Setup

ZyWALL 2 Series User’s Guide 9-4 Static Route Screens Table 9-2 Edit IP Static Route LABEL DESCRIPTION Active This field allows you to activate/dea

Strona 48 - 3.3 Internet Access

Firewall and Content Filters V Part V: Firewall and Content Filters This part introduces firewalls in general and the ZyWALL firewall. It also

Strona 50 - 3.3.2 PPPoE Encapsulation

ZyWALL 2 Series User’s Guide Firewalls 10-1 Chapter 10 Firewalls This chapter gives some background information on firewalls and introduces the ZyWAL

Strona 51

ZyWALL 2 Series User’s Guide 10-2 Firewalls i. Information hiding prevents the names of internal systems from being made known via DNS to outside sy

Strona 52 - 3.3.3 PPTP Encapsulation

ZyWALL 2 Series User’s Guide Firewalls 10-3 Figure 10-1 ZyWALL Firewall Application 10.4 Denial of Service Denials of Service (DoS) attacks are a

Strona 53

ZyWALL 2 Series User’s Guide 10-4 Firewalls Table 10-1 Common IP Ports 21 FTP 53 DNS 23 Telnet 80 HTTP 25 SMTP 110 POP3 10.4.2 Types of DoS Attack

Strona 54 - 3.4 WAN and DNS

ZyWALL 2 Series User’s Guide Firewalls 10-5 Figure 10-2 Three-Way Handshake  Under normal circumstances, the application that initiates a session

Strona 55

ZyWALL 2 Series User’s Guide 10-6 Firewalls 2-b In a LAND Attack, hackers flood SYN packets into the network with a spoofed source IP address of the

Strona 56 - 3.4.4 WAN MAC Address

ZyWALL 2 Series User’s Guide Firewalls 10-7  Illegal Commands (NetBIOS and SMTP) The only legal NetBIOS commands are the following - all others are

Strona 57

ZyWALL 2 Series User’s Guide List of Figures xv List of Figures Figure 1-1 Secure Internet Access via Cable, DSL or Wireless Modem...

Strona 58 - 3.5 Basic Setup Complete

ZyWALL 2 Series User’s Guide 10-8 Firewalls all communications to the Internet that originate from the LAN, and blocks all traffic to the LAN that or

Strona 59 - Wizard Setup 3-13

ZyWALL 2 Series User’s Guide Firewalls 10-9 4. Based on the obtained state information, a firewall rule creates a temporary access list entry that i

Strona 60

ZyWALL 2 Series User’s Guide 10-10 Firewalls Below is a brief technical description of how these connections are tracked. Connections may either be d

Strona 61 - Part II:

ZyWALL 2 Series User’s Guide Firewalls 10-11 10.5.5 Upper Layer Protocols Some higher layer protocols (such as FTP and RealAudio) utilize multiple ne

Strona 62

ZyWALL 2 Series User’s Guide 10-12 Firewalls 10.7.1 Packet Filtering:  The router filters packets as they pass through the router’s interface accor

Strona 63 - System Screens

ZyWALL 2 Series User’s Guide Firewalls 10-13 3. To selectively block/allow inbound or outbound traffic between inside host/networks and outside host

Strona 65 - 4.4 Configuring Dynamic DNS

ZyWALL 2 Series User’s Guide Firewall Screens 11-1Chapter 11 Firewall Screens This chapter shows you how to configure your ZyWALL firewall. 11.1 Acc

Strona 66

ZyWALL 2 Series User’s Guide 11-2 Firewall Screens If you configure firewall rules without a good understanding of how they work, you might inadverte

Strona 67 - 4.5 Configuring Password

ZyWALL 2 Series User’s Guide Firewall Screens 11-31. Does this rule stop LAN users from accessing critical resources on the Internet? For example, i

Strona 68

ZyWALL 2 Series User’s Guide xvi List of Figures Figure 8-3 Multiple Servers Behind NAT Example...

Strona 69 - 4.7 Configuring Time Setting

ZyWALL 2 Series User’s Guide 11-4 Firewall Screens policies for managing the ZyWALL through the LAN interface) and policies for LAN-to-LAN (the polic

Strona 70

ZyWALL 2 Series User’s Guide Firewall Screens 11-5 Figure 11-2 WAN to LAN Traffic 11.5 Alerts Alerts are reports on events, such as attacks, that you

Strona 71 - Table 4-5 Time Setting

ZyWALL 2 Series User’s Guide 11-6 Firewall Screens Figure 11-3 Enabling the Firewall The following table describes the fields in this screen. Sele

Strona 72

ZyWALL 2 Series User’s Guide Firewall Screens 11-7Table 11-1 Firewall Rules Summary: First Screen LABEL DESCRIPTION Enable Firewall Select this che

Strona 73 - LAN Screens

ZyWALL 2 Series User’s Guide 11-8 Firewall Screens Table 11-1 Firewall Rules Summary: First Screen LABEL DESCRIPTION Log This field shows you if a l

Strona 74 - 5.5 LAN TCP/IP

ZyWALL 2 Series User’s Guide Firewall Screens 11-9 Figure 11-4 Creating/Editing A Firewall Rule

Strona 75 - 5.6 Configuring IP

ZyWALL 2 Series User’s Guide 11-10 Firewall Screens The following table describes the fields in this screen. Table 11-2 Creating/Editing A Firewall R

Strona 76 - Table 5-1 IP

ZyWALL 2 Series User’s Guide Firewall Screens 11-11Table 11-2 Creating/Editing A Firewall Rule LABEL DESCRIPTION Log This field determines if a log

Strona 77 - LAN 5-5

ZyWALL 2 Series User’s Guide 11-12 Firewall Screens Table 11-3 Adding/Editing Source and Destination Addresses LABEL DESCRIPTION Address Type Do y

Strona 78 - 5.7 Configuring Static DHCP

ZyWALL 2 Series User’s Guide Firewall Screens 11-13Table 11-4 Creating/Editing A Custom Port LABEL DESCRIPTION Service Name Enter a unique name for

Strona 79 - 5.8 Configuring IP Alias

ZyWALL 2 Series User’s Guide List of Figures xvii Figure 14-9 Advanced IKE VPN Rule Setup ...

Strona 80 - 5-8 LAN

ZyWALL 2 Series User’s Guide 11-14 Firewall Screens Figure 11-7 Firewall IP Config Screen Step 4. Select Any in the Destination Address box and the

Strona 81 - Table 5-3 IP Alias

ZyWALL 2 Series User’s Guide Firewall Screens 11-15Step 5. Click DestAdd under the Destination Address box. Step 6. Configure the Firewall Rule Edi

Strona 82

ZyWALL 2 Series User’s Guide 11-16 Firewall Screens Custom ports show up with an “*” before their names in the Services list box and the Rule Summary

Strona 83 - Part III:

ZyWALL 2 Series User’s Guide Firewall Screens 11-17On completing the configuration procedure for this Internet firewall rule, the Rule Summary screen

Strona 84

ZyWALL 2 Series User’s Guide 11-18 Firewall Screens 11.8 Predefined Services The Available Services list box in the Rule Config(uration) screen (see

Strona 85 - WAN Screens

ZyWALL 2 Series User’s Guide Firewall Screens 11-19Table 11-5 Predefined Services SERVICE DESCRIPTION IPSEC_TUNNEL(ESP:0) The IPSEC ESP (Encapsula

Strona 86 - 6.4 Configuring Route

ZyWALL 2 Series User’s Guide 11-20 Firewall Screens Table 11-5 Predefined Services SERVICE DESCRIPTION SMTP(TCP:25) Simple Mail Transfer Protocol

Strona 87 - 6.5 Configuring WAN ISP

ZyWALL 2 Series User’s Guide Firewall Screens 11-2111.9.1 Threshold Values Tune these parameters when something is not working and after you have che

Strona 88

ZyWALL 2 Series User’s Guide 11-22 Firewall Screens Whenever the number of half-open sessions with the same destination host address rises above a th

Strona 89 - 6.5.2 PPPoE Encapsulation

ZyWALL 2 Series User’s Guide Firewall Screens 11-23Table 11-6 Attack Alert LABEL DESCRIPTION DEFAULT VALUES Generate alert when attack detected A d

Strona 90

ZyWALL 2 Series User’s Guide xviii List of Figures Figure 17-21 SNMP Management Model...

Strona 91 - 6.5.3 PPTP Encapsulation

ZyWALL 2 Series User’s Guide 11-24 Firewall Screens Table 11-6 Attack Alert LABEL DESCRIPTION DEFAULT VALUES Maximum Incomplete High This is the num

Strona 92

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-1Chapter 12 Content Filtering Screens This chapter provides a brief overview of content fil

Strona 93 - 6.6 Configuring WAN IP

ZyWALL 2 Series User’s Guide 12-2 Content Filtering Screens Figure 12-1 Content Filter : General The following table describes the labels in thi

Strona 94

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-3Table 12-1 Content Filter : General LABEL DESCRIPTION Enable Content Filter Select this c

Strona 95

ZyWALL 2 Series User’s Guide 12-4 Content Filtering Screens Table 12-1 Content Filter : General LABEL DESCRIPTION Exclude specified address range

Strona 96

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-5Step 1. A computer sends an HTTP request to a web server. Step 2. The ZyWALL looks up th

Strona 97

ZyWALL 2 Series User’s Guide 12-6 Content Filtering Screens Figure 12-3 Content Filter : Categories

Strona 98 - 6.8 Traffic Redirect

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-7The following table describes the labels in this screen. Table 12-2 Content Filter : Categ

Strona 99

ZyWALL 2 Series User’s Guide 12-8 Content Filtering Screens Table 12-2 Content Filter : Categories LABEL DESCRIPTION Select Categories Select All

Strona 100 - Table 6-8 Traffic Redirect

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-9Table 12-2 Content Filter : Categories LABEL DESCRIPTION Gambling Selecting this category

Strona 101

ZyWALL 2 Series User’s Guide List of Figures xix Figure 23-9 Menu 11.5: Dial Backup Remote Node Filter ...

Strona 102

ZyWALL 2 Series User’s Guide 12-10 Content Filtering Screens Table 12-2 Content Filter : Categories LABEL DESCRIPTION Education Selecting this c

Strona 103

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-11Table 12-2 Content Filter : Categories LABEL DESCRIPTION Computers/Internet Selecting th

Strona 104

ZyWALL 2 Series User’s Guide 12-12 Content Filtering Screens Table 12-2 Content Filter : Categories LABEL DESCRIPTION Shopping Selecting this ca

Strona 105

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-13Table 12-2 Content Filter : Categories LABEL DESCRIPTION Software Downloads Selecting th

Strona 106 - 6.11 Advanced Modem Setup

ZyWALL 2 Series User’s Guide 12-14 Content Filtering Screens Table 12-2 Content Filter : Categories LABEL DESCRIPTION Register Click Register to

Strona 107 - 6.11.3 Response Strings

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-15 Figure 12-4 Content Filter : Customization

Strona 108 - Table 6-10 Advanced Setup

ZyWALL 2 Series User’s Guide 12-16 Content Filtering Screens The following table describes the labels in this screen. Table 12-3 Content Filter :

Strona 109

ZyWALL 2 Series User’s Guide Content Filtering Screens 12-17Table 12-3 Content Filter : Customization LABEL DESCRIPTION Delete Select a web site nam

Strona 111 - Wireless LAN Screens

VPN/IPSec VI Part VI: VPN/IPSec This part provides information on how to configure VPN/IPSec.

Strona 112 - 7-2 Wireless LAN Screens

ZyWALL 2 Series User’s Guide ii Copyright Copyright Copyright © 2004 by ZyXEL Communications Corporation. The contents of this publication may not be

Strona 113 - 7.3 Wireless Security

ZyWALL 2 Series User’s Guide xx List of Figures Figure 28-20 Example 4: Menu 15.1.1.1: Address Mapping Rule ...

Strona 115 - Table 7-1 Wireless

ZyWALL 2 Series User’s Guide Introduction to IPSec 13-1 Chapter 13 Introduction to IPSec This chapter introduces the basics of IPSec VPNs. 13.1 VPN

Strona 116 - 7.5 Configuring MAC Filter

ZyWALL 2 Series User’s Guide 13-2 Introduction to IPSec Figure 13-1 Encryption and Decryption  Data Confidentiality The IPSec sender can encrypt

Strona 117 - 7.6 802.1x Overview

ZyWALL 2 Series User’s Guide Introduction to IPSec 13-3 13.2 IPSec Architecture The overall IPSec architecture is shown as follows. Figure 13-2 IP

Strona 118 - 7-8 Wireless LAN Screens

ZyWALL 2 Series User’s Guide 13-4 Introduction to IPSec 13.3 Encapsulation The two modes of operation for IPSec VPNs are Transport mode and Tunnel

Strona 119 - 7.8 Configuring 802.1X

ZyWALL 2 Series User’s Guide Introduction to IPSec 13-5 13.4 IPSec and NAT Read this section if you are running IPSec on a host computer behind th

Strona 121 - Part IV:

ZyWALL 2 Series User’s Guide VPN Screens 14-1 Chapter 14 VPN Screens This chapter introduces the VPN Web configurator. See the Logs chapter for inf

Strona 122

ZyWALL 2 Series User’s Guide 14-2 VPN Screens Table 14-1 AH and ESP ESP AH DES (default) Data Encryption Standard (DES) is a widely used method of d

Strona 123 - Chapter 8

ZyWALL 2 Series User’s Guide VPN Screens 14-3 You can also enter a remote secure gateway’s domain name in the Secure Gateway Address field if the rem

Strona 124 - 8.1.3 How NAT Works

ZyWALL 2 Series User’s Guide List of Figures xxi Figure 33-12 Successful Restoration Confirmation Screen ...

Strona 125 - 8.1.5 NAT Mapping Types

ZyWALL 2 Series User’s Guide 14-4 VPN Screens Figure 14-2 VPN Rules The following table describes the fields in this screen. Table 14-2 VPN Rules L

Strona 126 - 8.2 Using NAT

ZyWALL 2 Series User’s Guide VPN Screens 14-5 Table 14-2 VPN Rules LABEL DESCRIPTION Remote IP Address This is the IP address(es) of computer(s) on t

Strona 127 - 8.3 SUA Server

ZyWALL 2 Series User’s Guide 14-6 VPN Screens When there is outbound traffic with no inbound traffic, the ZyWALL automatically drops the tunnel afte

Strona 128 - IP address

ZyWALL 2 Series User’s Guide VPN Screens 14-7 14.7.2 X-Auth (Extended Authentication) Extended authentication provides added security by allowing you

Strona 129 - 8.4 Configuring SUA Server

ZyWALL 2 Series User’s Guide 14-8 VPN Screens If you do not specify an Intranet DNS server on the remote network, then the VPN host must use IP addr

Strona 130

ZyWALL 2 Series User’s Guide VPN Screens 14-9 Table 14-4 Peer ID Type and Content Fields PEER ID TYPE= CONTENT= IP Type the IP address of the compu

Strona 131

ZyWALL 2 Series User’s Guide 14-10 VPN Screens Table 14-6 Mismatching ID Type and Content Configuration Example ZYWALL A ZYWALL B Peer ID type: E-m

Strona 132 - Configuring Address Mapping

ZyWALL 2 Series User’s Guide VPN Screens 14-11 Figure 14-6 Site-to-Site VPN Example 14.11 Configuring Basic IKE VPN Rule Setup Select one of the VPN

Strona 133

ZyWALL 2 Series User’s Guide 14-12 VPN Screens Figure 14-7 Basic IKE VPN Rule Edit

Strona 134

ZyWALL 2 Series User’s Guide VPN Screens 14-13 The following table describes the fields in this screen. Table 14-7 Basic IKE VPN Rule Edit LABEL DE

Strona 135 - LABEL DESCRIPTION

ZyWALL 2 Series User’s Guide xxii List of Tables List of Tables Table 1-1 Model Specific Features ...

Strona 136 - Table 8-7 Trigger Port

ZyWALL 2 Series User’s Guide 14-14 VPN Screens Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Server Mode Select Server Mode to have this Zy

Strona 137 - Static Route Screens

ZyWALL 2 Series User’s Guide VPN Screens 14-15 Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Local IP Address Enter a static local IP addre

Strona 138

ZyWALL 2 Series User’s Guide 14-16 VPN Screens Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Ending IP Address/ Subnet Mask When the Addres

Strona 139

ZyWALL 2 Series User’s Guide VPN Screens 14-17 Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Local ID Type Select IP to identify this ZyWALL

Strona 140 - 9-4 Static Route Screens

ZyWALL 2 Series User’s Guide 14-18 VPN Screens Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Peer ID Type Select from the following when yo

Strona 141 - Part V:

ZyWALL 2 Series User’s Guide VPN Screens 14-19 Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Content The configuration of the peer content d

Strona 142

ZyWALL 2 Series User’s Guide 14-20 VPN Screens Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION My IP Address Enter the WAN IP address of you

Strona 143 - Firewalls

ZyWALL 2 Series User’s Guide VPN Screens 14-21 Table 14-7 Basic IKE VPN Rule Edit LABEL DESCRIPTION Encryption Algorithm Select DES, 3DES, AES or N

Strona 144

ZyWALL 2 Series User’s Guide 14-22 VPN Screens Figure 14-8 Two Phases to Set Up the IPSec SA In phase 1 you must:  Choose a negotiation mode.  A

Strona 145 - 10.4 Denial of Service

ZyWALL 2 Series User’s Guide VPN Screens 14-23 IPSec SA lifetime period expires. The ZyWALL also automatically renegotiates the IPSec SA if both IPSe

Strona 146 - 10.4.2 Types of DoS Attacks

ZyWALL 2 Series User’s Guide List of Tables xxiii Table 10-2 ICMP Commands That Trigger Alerts ...

Strona 147

ZyWALL 2 Series User’s Guide 14-24 VPN Screens 14.12.5 Perfect Forward Secrecy (PFS) Enabling PFS means that the key is transient. The key is throw

Strona 148 - 18 ADDRESS_MASK_REPLY

ZyWALL 2 Series User’s Guide VPN Screens 14-25 Figure 14-9 Advanced IKE VPN Rule Setup The following table describes the fields in this screen. Tabl

Strona 149 - 10.5 Stateful Inspection

ZyWALL 2 Series User’s Guide 14-26 VPN Screens Table 14-8 Advanced IKE VPN Rule Setup LABEL DESCRIPTION Enable Replay Detection As a VPN setup is p

Strona 150

ZyWALL 2 Series User’s Guide VPN Screens 14-27 Table 14-8 Advanced IKE VPN Rule Setup LABEL DESCRIPTION Authentication Algorithm Select SHA1 or MD5

Strona 151

ZyWALL 2 Series User’s Guide 14-28 VPN Screens Table 14-8 Advanced IKE VPN Rule Setup LABEL DESCRIPTION SA Life Time (seconds) Define the length of

Strona 152 - 10.5.4 UDP/ICMP Security

ZyWALL 2 Series User’s Guide VPN Screens 14-29 Select Manual Key (or Manual) in the Key Management (or IPSec Keying Mode) field to display the manual

Strona 153 - 10.5.5 Upper Layer Protocols

ZyWALL 2 Series User’s Guide 14-30 VPN Screens The following table describes the labels in this screen. Table 14-9 VPN Manual Setup LABEL DESCRIPTIO

Strona 154 - 10.7.2 Firewall

ZyWALL 2 Series User’s Guide VPN Screens 14-31 Table 14-9 VPN Manual Setup LABEL DESCRIPTION Remote: Remote IP addresses must be static and correspo

Strona 155

ZyWALL 2 Series User’s Guide 14-32 VPN Screens Table 14-9 VPN Manual Setup LABEL DESCRIPTION Secure Gateway Addr Type the WAN IP address or the URL

Strona 156

ZyWALL 2 Series User’s Guide VPN Screens 14-33 Table 14-9 VPN Manual Setup LABEL DESCRIPTION Authentication Key Type a unique authentication key to b

Strona 157 - Firewall Screens

ZyWALL 2 Series User’s Guide xxiv List of Tables Table 16-2 RADIUS ...

Strona 158 - 11.3 Rule Logic Overview

ZyWALL 2 Series User’s Guide 14-34 VPN Screens The following table describes the fields in this screen. Table 14-10 VPN SA Monitor LABEL DESCRIPTIO

Strona 159 - Destination Address

ZyWALL 2 Series User’s Guide VPN Screens 14-35 Table 14-11 VPN Global Setting LABEL DESCRIPTION Windows Networking (NetBIOS over TCP/IP) NetBIOS (N

Strona 160 - 11.4.2 WAN to LAN Rules

ZyWALL 2 Series User’s Guide 14-36 VPN Screens Figure 14-13 Telecommuters Sharing One VPN Rule Example Table 14-12 Telecommuters Sharing One VPN Ru

Strona 161 - 11.6 Configuring Firewall

ZyWALL 2 Series User’s Guide VPN Screens 14-37 See the following table and figure for an example where three telecommuters each use a different VPN r

Strona 162

ZyWALL 2 Series User’s Guide 14-38 VPN Screens Table 14-13 Telecommuters Using Unique VPN Rules Example TELECOMMUTERS HEADQUARTERS Local IP Address:

Strona 163 - Firewall Screens 11-7

VPN/IPSec VII Part VII: Certificates This part provides information and configuration instructions for public-key certificates.

Strona 165 - Firewall Screens 11-9

ZyWALL 2 Series User’s Guide Certificates 15-1 Chapter 15 Certificates This chapter gives background information about public-key certificate

Strona 166 - 11-10 Firewall Screens

ZyWALL 2 Series User’s Guide 15-2 Certificates Certification authorities maintain directory servers with databases of valid and revoked certificates.

Strona 167

ZyWALL 2 Series User’s Guide Certificates 15-3 15.4 My Certificates Click CERTIFICATES, My Certificates to open the ZyWALL’s summary list of c

Strona 168 - Address

ZyWALL 2 Series User’s Guide List of Tables xxv Table 26-1 Menu 11.1: Remote Node Profile for Ethernet Encapsulation...

Strona 169

ZyWALL 2 Series User’s Guide 15-4 Certificates Table 15-1 My Certificates LABEL DESCRIPTION PKI Storage Space in Use This bar displays the percentage

Strona 170 - 11-14 Firewall Screens

ZyWALL 2 Series User’s Guide Certificates 15-5 Table 15-1 My Certificates LABEL DESCRIPTION Details Select the radio button next to a certific

Strona 171

ZyWALL 2 Series User’s Guide 15-6 Certificates 15.6 Importing a Certificate Click CERTIFICATES, My Certificates and then Import to open the My Certi

Strona 172

ZyWALL 2 Series User’s Guide Certificates 15-7 Table 15-2 My Certificate Import LABEL DESCRIPTION Apply Click Apply to save the certificate o

Strona 173

ZyWALL 2 Series User’s Guide 15-8 Certificates The following table describes the labels in this screen. Table 15-3 My Certificate Create LABEL DESCRI

Strona 174 - 11.8 Predefined Services

ZyWALL 2 Series User’s Guide Certificates 15-9 Table 15-3 My Certificate Create LABEL DESCRIPTION Create a certification request and enroll fo

Strona 175 - Firewall Screens 11-19

ZyWALL 2 Series User’s Guide 15-10 Certificates After you click Apply in the My Certificate Create screen, you see a screen that tells you the ZyWALL

Strona 176

ZyWALL 2 Series User’s Guide Certificates 15-11 Figure 15-5 My Certificate Details

Strona 177 - 11.9.2 Half-Open Sessions

ZyWALL 2 Series User’s Guide 15-12 Certificates The following table describes the labels in this screen. Table 15-4 My Certificate Details LABEL DESC

Strona 178

ZyWALL 2 Series User’s Guide Certificates 15-13 Table 15-4 My Certificate Details LABEL DESCRIPTION Signature Algorithm This field displays t

Strona 179 - Table 11-6 Attack Alert

ZyWALL 2 Series User’s Guide xxvi Preface Preface About This User's Manual Congratulations on your purchase of the ZyWALL 2 Internet Security Ga

Strona 180

ZyWALL 2 Series User’s Guide 15-14 Certificates Table 15-4 My Certificate Details LABEL DESCRIPTION Certificate in PEM (Base-64) Encoded Format This

Strona 181 - Content Filtering Screens

ZyWALL 2 Series User’s Guide Certificates 15-15 Figure 15-6 Trusted CAs The following table describes the labels in this screen. Table 15-5 T

Strona 182

ZyWALL 2 Series User’s Guide 15-16 Certificates Table 15-5 Trusted CAs LABEL DESCRIPTION Issuer This field displays identifying information about th

Strona 183

ZyWALL 2 Series User’s Guide Certificates 15-17 You must remove any spaces from the certificate’s filename before you can import the certifica

Strona 184

ZyWALL 2 Series User’s Guide 15-18 Certificates Figure 15-8 Trusted CA Details

Strona 185

ZyWALL 2 Series User’s Guide Certificates 15-19 The following table describes the labels in this screen. Table 15-7 Trusted CA Details LABEL D

Strona 186

ZyWALL 2 Series User’s Guide 15-20 Certificates Table 15-7 Trusted CA Details LABEL DESCRIPTION Signature Algorithm This field displays the type of

Strona 187

ZyWALL 2 Series User’s Guide Certificates 15-21 Table 15-7 Trusted CA Details LABEL DESCRIPTION Certificate in PEM (Base-64) Encoded Format Th

Strona 188

ZyWALL 2 Series User’s Guide 15-22 Certificates Figure 15-9 Trusted Remote Hosts The following table describes the labels in this screen. Table 15-8

Strona 189

ZyWALL 2 Series User’s Guide Certificates 15-23 Table 15-8 Trusted Remote Hosts LABEL DESCRIPTION Subject This field displays identifying inf

Strona 190

ZyWALL 2 Series User’s Guide Preface xxvii • The version number on the title page is the latest firmware version that is documented in this User’s

Strona 191

ZyWALL 2 Series User’s Guide 15-24 Certificates Table 15-9 Remote Host Certificates Step 3. Double-click the certificate’s icon to open the Certifi

Strona 192

ZyWALL 2 Series User’s Guide Certificates 15-25 The trusted remote host certificate must be a self-signed certificate; and you must remove any

Strona 193

ZyWALL 2 Series User’s Guide 15-26 Certificates Figure 15-11 Trusted Remote Host Details

Strona 194

ZyWALL 2 Series User’s Guide Certificates 15-27 The following table describes the labels in this screen. Table 15-12 Trusted Remote Host Detai

Strona 195

ZyWALL 2 Series User’s Guide 15-28 Certificates Table 15-12 Trusted Remote Host Details LABEL DESCRIPTION Key Algorithm This field displays the type

Strona 196

ZyWALL 2 Series User’s Guide Certificates 15-29 15.16 Directory Servers Click CERTIFICATES, Directory Servers to open the Directory Servers s

Strona 197

ZyWALL 2 Series User’s Guide 15-30 Certificates Table 15-13 Directory Servers LABEL DESCRIPTION Port This field displays the port number that the di

Strona 198

ZyWALL 2 Series User’s Guide Certificates 15-31 Table 15-14 Directory Server Add LABEL DESCRIPTION Directory Service Setting Name Type up to

Strona 200

Remote Management and UPnP VIII Part VIII: Authentication Server, Remote Management and UPnP This part provides information and configuration ins

Strona 203 - 13.2 IPSec Architecture

ZyWALL 2 Series User’s Guide Authentication Server 16-1 Chapter 16 Authentication Server This chapter discusses how to configure the authentication s

Strona 204 - 13.3 Encapsulation

ZyWALL 2 Series User’s Guide 16-2 Authentication Server Figure 16-1 Local User Database

Strona 205 - 13.4 IPSec and NAT

ZyWALL 2 Series User’s Guide Authentication Server 16-3 The following table describes the fields in this screen. Table 16-1 Local User Database LABE

Strona 206

ZyWALL 2 Series User’s Guide 16-4 Authentication Server Figure 16-2 RADIUS The following table describes the fields in this screen. Table 16-2 RADI

Strona 207 - VPN Screens

ZyWALL 2 Series User’s Guide Authentication Server 16-5 Table 16-2 RADIUS LABEL DESCRIPTION Port Number The default port of the RADIUS server for au

Strona 209 - 14.5 Summary Screen

ZyWALL 2 Series User’s Guide Remote Management Screens 17-1 Chapter 17 Remote Management Screens This chapter provides information on the Remote Mana

Strona 210

ZyWALL 2 Series User’s Guide 17-2 Remote Management Screens 17.1.1 Remote Management Limitations Remote management over LAN or WAN will not work when

Strona 211 - 14.6 Keep Alive

ZyWALL 2 Series User’s Guide Remote Management Screens 17-3 data), authentication (one party can identify the other party) and data integrity (you kn

Strona 212 - 14.7 NAT Traversal

Getting Started I Part I: Getting Started This part helps you get to know your ZyWALL, introduces the web configurator and covers how to config

Strona 213 - 14.7.3 Remote DNS Server

ZyWALL 2 Series User’s Guide 17-4 Remote Management Screens If you disable HTTP Server Access (Disable) in the REMOTE MGMT WWW screen, then the ZyWAL

Strona 214 - 14.8 ID Type and Content

ZyWALL 2 Series User’s Guide Remote Management Screens 17-5 Table 17-1 WWW LABEL DESCRIPTION HTTPS: This feature is not available on the ZyWALL 2WE.

Strona 215

ZyWALL 2 Series User’s Guide 17-6 Remote Management Screens Table 17-1 WWW LABEL DESCRIPTION Reset Click Reset to begin configuring this screen afres

Strona 216 - 14.10 VPN Implementation

ZyWALL 2 Series User’s Guide Remote Management Screens 17-7 17.4.2 Netscape Navigator Warning Messages When you attempt to access the ZyWALL HTTPS se

Strona 217

ZyWALL 2 Series User’s Guide 17-8 Remote Management Screens Figure 17-5 Security Certificate 2 (Netscape) 17.4.3 Avoiding the Browser Warning Messag

Strona 218 - 14-12 VPN Screens

ZyWALL 2 Series User’s Guide Remote Management Screens 17-9 Step 2. Click CERTIFICATES. Find the certificate and check its Subject column. CN stands

Strona 219 - VPN Screens 14-13

ZyWALL 2 Series User’s Guide 17-10 Remote Management Screens Figure 17-6 Login Screen (Internet Explorer)

Strona 220 - 14-14 VPN Screens

ZyWALL 2 Series User’s Guide Remote Management Screens 17-11 Figure 17-7 Login Screen (Netscape) Click Login and you then see the next screen. The f

Strona 221 - VPN Screens 14-15

ZyWALL 2 Series User’s Guide 17-12 Remote Management Screens Figure 17-8 Replace Certificate Click Apply in the Replace Certificate screen to create

Strona 222 - 14-16 VPN Screens

ZyWALL 2 Series User’s Guide Remote Management Screens 17-13 Click Ignore in the Replace Certificate screen to use the common ZyWALL certificate. You

Strona 223 - VPN Screens 14-17

ZyWALL 2 Series User’s Guide FCC iii Federal Communications Commission (FCC) Interference Statement This device complies with Part 15 of FCC rules.

Strona 225 - VPN Screens 14-19

ZyWALL 2 Series User’s Guide 17-14 Remote Management Screens Figure 17-11 SSH Communication Example 17.6 How SSH works The following table summari

Strona 226 - 14-20 VPN Screens

ZyWALL 2 Series User’s Guide Remote Management Screens 17-15 17.7 SSH Implementation on the ZyWALL Your ZyWALL supports SSH version 1.5 using RSA au

Strona 227 - 14.12 IKE Phases

ZyWALL 2 Series User’s Guide 17-16 Remote Management Screens Table 17-2 SSH LABEL DESCRIPTION Server Host Key Select the certificate whose correspon

Strona 228

ZyWALL 2 Series User’s Guide Remote Management Screens 17-17 Step 3. A window displays prompting you to store the host key in you computer. Click Ye

Strona 229 - 14.12.3 Pre-Shared Key

ZyWALL 2 Series User’s Guide 17-18 Remote Management Screens Step 2. Enter “ssh –1 192.168.1.1”. This command forces your computer to connect to the

Strona 230

ZyWALL 2 Series User’s Guide Remote Management Screens 17-19 Step 3. Use the “put” command to upload a new firmware to the ZyWALL. Figure 17-17 Se

Strona 231 - DESCRIPTION

ZyWALL 2 Series User’s Guide 17-20 Remote Management Screens 17.12 Configuring TELNET Click REMOTE MGNT to open the TELNET screen. Figure 17-19 Te

Strona 232

ZyWALL 2 Series User’s Guide Remote Management Screens 17-21 17.13 Configuring FTP You can upload and download the ZyWALL’s firmware and configurati

Strona 233

ZyWALL 2 Series User’s Guide 17-22 Remote Management Screens Table 17-4 FTP LABEL DESCRIPTION Secure Client IP Address A secure client is a “trusted”

Strona 234 - 14.14 Manual Key Setup

ZyWALL 2 Series User’s Guide Remote Management Screens 17-23 Figure 17-21 SNMP Management Model An SNMP managed network consists of two main types o

Strona 235

ZyWALL 2 Series User’s Guide Getting to Know Your ZyWALL 1-1Chapter 1 Getting to Know Your ZyWALL This chapter introduces the main features and ap

Strona 236 - Table 14-9 VPN Manual Setup

ZyWALL 2 Series User’s Guide 17-24 Remote Management Screens • Get - Allows the manager to retrieve an object variable from the agent. • GetNext -

Strona 237 - VPN Screens 14-31

ZyWALL 2 Series User’s Guide Remote Management Screens 17-25 17.14.3 REMOTE MANAGEMENT: SNMP To change your ZyWALL’s SNMP settings, click REMOTE MGN

Strona 238 - 14-32 VPN Screens

ZyWALL 2 Series User’s Guide 17-26 Remote Management Screens Table 17-6 SNMP LABEL DESCRIPTION SNMP Configuration Get Community Enter the Get Communi

Strona 239 - 14.16 SA Monitor

ZyWALL 2 Series User’s Guide Remote Management Screens 17-27 To change your ZyWALL’s DNS settings, click REMOTE MGNT, then the DNS tab. The screen ap

Strona 240 - 14.17 Global Settings

ZyWALL 2 Series User’s Guide 17-28 Remote Management Screens 17.16 Configuring Security To change your ZyWALL’s Security settings, click REMOTE MGNT

Strona 241

ZyWALL 2 Series User’s Guide Remote Management Screens 17-29 Table 17-8 Security LABEL DESCRIPTION Respond to Ping on The ZyWALL will not respond to

Strona 243

ZyWALL 2 Series User’s Guide UPnP 18-1 Chapter 18 UPnP This chapter introduces the Universal Plug and Play feature. 18.1 Universal Plug and Play Ov

Strona 244

ZyWALL 2 Series User’s Guide 18-2 UPnP 18.1.3 Cautions with UPnP The automated nature of NAT traversal applications in establishing their own service

Strona 245 - Part VII:

ZyWALL 2 Series User’s Guide UPnP 18-3 Figure 18-1 Configuring UPnP The following table describes the fields in this screen. Table 18-1 Configuring

Strona 246

ZyWALL 2 Series User’s Guide 1-2 Getting to Know Your ZyWALL 1.2.1 Physical Features 4-Port Switch A combination of switch and router makes your Zy

Strona 247 - Certificates

ZyWALL 2 Series User’s Guide 18-4 UPnP Table 18-1 Configuring UPnP FIELD DESCRIPTION Reset Click Reset to begin configuring this screen afresh 18.

Strona 248 - 15.3 Configuration Summary

ZyWALL 2 Series User’s Guide UPnP 18-5 Table 18-2 UPnP Ports LABEL DESCRIPTION # This is the index number of the UPnP-created NAT mapping rule ent

Strona 249 - 15.4 My Certificates

ZyWALL 2 Series User’s Guide 18-6 UPnP 18.5.1 Installing UPnP in Windows Me Follow the steps below to install UPnP in Windows Me. Click Start and Co

Strona 250 - Table 15-1 My Certificates

ZyWALL 2 Series User’s Guide UPnP 18-7 Step 1. Click Start and Control Panel. Step 2. Double-click Network Connections. Step 3. In the Network Co

Strona 251

ZyWALL 2 Series User’s Guide 18-8 UPnP 18.6 Using UPnP in Windows XP Example This section shows you how to use the UPnP feature in Windows XP. You m

Strona 252

ZyWALL 2 Series User’s Guide UPnP 18-9 Step 4. You may edit or delete the port mappings or click Add to manually add port mappings. When the UPnP-

Strona 253 - 15.7 Creating a Certificate

ZyWALL 2 Series User’s Guide 18-10 UPnP 18.6.2 Web Configurator Easy Access With UPnP, you can access the web-based configurator without first findin

Strona 254 - 15-8 Certificates

Logs IX Part IX: Logs This part provides information and instructions for the logs and reports.

Strona 256 - 15.8 My Certificate Details

ZyWALL 2 Series User’s Guide Log Screens 19-1 Chapter 19 Logs Screens This chapter contains information about configuring general log settings and vi

Strona 257 - Certificates 15-11

ZyWALL 2 Series User’s Guide Getting to Know Your ZyWALL 1-3The ZyWALL supports two simultaneous VPN connections. X-Auth (Extended Authentication)

Strona 258 - 15-12 Certificates

ZyWALL 2 Series User’s Guide 19-2 Log Screens Figure 19-1 View Log The following table describes the labels in this screen. Table 19-1 View Log LABE

Strona 259 - Certificates 15-13

ZyWALL 2 Series User’s Guide Log Screens 19-3 Table 19-1 View Log LABEL DESCRIPTION Note This field displays additional information about the log en

Strona 260 - 15.9 Trusted CAs

ZyWALL 2 Series User’s Guide 19-4 Log Screens Figure 19-2 Log Settings

Strona 261

ZyWALL 2 Series User’s Guide Log Screens 19-5 The following table describes the labels in this screen. Table 19-2 Log Settings LABEL DESCRIPTION Add

Strona 262

ZyWALL 2 Series User’s Guide 19-6 Log Screens Table 19-2 Log Settings LABEL DESCRIPTION Time for Sending Log Enter the time of the day in 24-hour fo

Strona 263

ZyWALL 2 Series User’s Guide Log Screens 19-7 The ZyWALL records web site hits by counting the HTTP GET packets. Many web sites include HTTP GET refe

Strona 264 - 15-18 Certificates

ZyWALL 2 Series User’s Guide 19-8 Log Screens Table 19-3 Reports LABEL DESCRIPTION Refresh Click Refresh to update the report display. The report als

Strona 265 - Certificates 15-19

ZyWALL 2 Series User’s Guide Log Screens 19-9 Table 19-4 Web Site Hits Report LABEL DESCRIPTION Web Site This column lists the domain names of the w

Strona 266 - 15-20 Certificates

ZyWALL 2 Series User’s Guide 19-10 Log Screens Table 19-5 Protocol/ Port Report LABEL DESCRIPTION Protocol/Port This column lists the protocols or s

Strona 267 - 15.12 Trusted Remote Hosts

ZyWALL 2 Series User’s Guide Log Screens 19-11 The following table describes the labels in this screen. Table 19-6 LAN IP Address Report LABEL DESCRI

Strona 268

ZyWALL 2 Series User’s Guide 1-4 Getting to Know Your ZyWALL Universal Plug and Play (UPnP) Using the standard TCP/IP protocol, the ZyWALL and othe

Strona 270

Maintenance X Part X: Maintenance This part covers the maintenance screens.

Strona 272 - 15-26 Certificates

ZyWALL 2 Series User’s Guide Maintenance 20-1 Chapter 20 Maintenance This chapter displays system information such as firmware, port IP addresses an

Strona 273 - Certificates 15-27

ZyWALL 2 Series User’s Guide 20-2 Maintenance The following table describes the labels in this screen. Table 20-1 System Status LABEL DESCRIPTION S

Strona 274 - 15-28 Certificates

ZyWALL 2 Series User’s Guide Maintenance 20-3 Figure 20-2 System Status: Show Statistics The following table describes the labels in this screen. T

Strona 275 - 15.16 Directory Servers

ZyWALL 2 Series User’s Guide 20-4 Maintenance Table 20-2 System Status: Show Statistics LABEL DESCRIPTION Stop Click Stop to stop refreshing statis

Strona 276

ZyWALL 2 Series User’s Guide Maintenance 20-5 Table 20-3 DHCP Table LABEL DESCRIPTION IP Address This field displays the IP address relative to the

Strona 277 - Certificates 15-31

ZyWALL 2 Series User’s Guide 20-6 Maintenance The following table describes the fields in this screen. Figure 20-5 Firmware Upload LABEL DESCRIPTIO

Strona 278

ZyWALL 2 Series User’s Guide Maintenance 20-7 Figure 20-7 Network Temporarily Disconnected After two minutes, log in again and check your new firmw

Strona 279 - Part VIII:

ZyWALL 2 Series User’s Guide Getting to Know Your ZyWALL 1-5Central Network Management Central Network Management (CNM) allows an enterprise or ser

Strona 280

ZyWALL 2 Series User’s Guide 20-8 Maintenance Figure 20-9 Configuration 20.5.1 Backup Configuration Backup Configuration allows you to backup (save

Strona 281 - Authentication Server

ZyWALL 2 Series User’s Guide Maintenance 20-9 20.5.2 Restore Configuration Restore Configuration allows you to restore a previously saved configura

Strona 282 - 16-2 Authentication Server

ZyWALL 2 Series User’s Guide 20-10 Maintenance If you uploaded the default configuration file you may need to change the IP address of your computer

Strona 283 - 16.4 Configuring RADIUS

ZyWALL 2 Series User’s Guide Maintenance 20-11 You can also press the RESET button on the rear panel to reset the factory defaults of your ZyWALL. R

Strona 285 - Table 16-2 RADIUS

SMT General Configuration XI Part XI: SMT General Configuration This part introduces the System Management Terminal and covers the General setup

Strona 287 - Remote Management Screens

ZyWALL 2 Series User’s Guide Introducing the SMT 21-1 Chapter 21 Introducing the SMT This chapter explains how to access the System Management Termin

Strona 288 - 17.2 Introduction to HTTPS

ZyWALL 2 Series User’s Guide 21-2 Introducing the SMT 21.2.2 Entering the Password The login screen appears after you press [ENTER], prompting you to

Strona 289

ZyWALL 2 Series User’s Guide Introducing the SMT 21-3 Table 21-1 Main Menu Commands OPERATION KEYSTROKES DESCRIPTION Entering information Fill in, o

Strona 290 - 17.3 Configuring WWW

ZyWALL 2 Series User’s Guide 1-6 Getting to Know Your ZyWALL Management Terminal) interface. The SMT is a menu-driven interface that you can access

Strona 291 - Table 17-1 WWW

ZyWALL 2 Series User’s Guide 21-4 Introducing the SMT Table 21-2 Main Menu Summary NO. Menu Title FUNCTION 1 General Setup Use this menu to set u

Strona 292 - 17.4 HTTPS Example

ZyWALL 2 Series User’s Guide Introducing the SMT 21-5 Menu 3LAN SetupMenu 4Internet Access SetupMenu 12Static Routing SetupMenu 11Remote Node SetupMe

Strona 293

ZyWALL 2 Series User’s Guide 21-6 Introducing the SMT 21.4 Changing the System Password Change the system password by following the steps shown next

Strona 294

ZyWALL 2 Series User’s Guide SMT Menu 1 – General Setup 22-1 Chapter 22 SMT Menu 1 - General Setup Menu 1 - General Setup contains administrative an

Strona 295 - 17.4.4 Login Screen

ZyWALL 2 Series User’s Guide 22-2 SMT Menu 1 – General Setup Table 22-1 Menu 1: General Setup FIELD DESCRIPTION EXAMPLE Domain Name Enter the do

Strona 296

ZyWALL 2 Series User’s Guide SMT Menu 1 – General Setup 22-3 Figure 22-2 Configure Dynamic DNS Follow the instructions in the next table to

Strona 297

ZyWALL 2 Series User’s Guide 22-4 SMT Menu 1 – General Setup Table 22-2 Configure Dynamic DNS FIELD DESCRIPTION EXAMPLE Offline This field is on

Strona 298

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-1 Chapter 23 WAN and Dial Backup Setup This chapter describes how to configure the WAN us

Strona 299 - 17.5 SSH Overview

ZyWALL 2 Series User’s Guide 23-2 WAN and Dial Backup Setup Table 23-1 MAC Address Cloning in WAN Setup FIELD DESCRIPTION EXAMPLE IP Address This f

Strona 300 - 17.6 How SSH works

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-3 The following table describes the fields in this menu. Table 23-2 Menu 2: Dial Backup Set

Strona 301 - 17.8 Configuring SSH

ZyWALL 2 Series User’s Guide Getting to Know Your ZyWALL 1-71.3.2 Secure Broadband Internet Access and VPN You can connect a cable, DSL or wirele

Strona 302

ZyWALL 2 Series User’s Guide 23-4 WAN and Dial Backup Setup Figure 23-3 Menu 2.1 Advanced WAN Setup The following table describes fields in t

Strona 303 - 17.9.2 Example 2: Linux

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-5 Table 23-4 Advanced WAN Port Setup: Call Control Parameters FIELD DESCRIPTION DEFAULT

Strona 304

ZyWALL 2 Series User’s Guide 23-6 WAN and Dial Backup Setup Figure 23-4 Menu 11.1 Remote Node Profile (Backup ISP) The following table desc

Strona 305 - 17.11 Telnet

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-7 Table 23-5 Menu 11.1 Remote Node Profile (Backup ISP) FIELD DESCRIPTION EXAMPLE Pri Pho

Strona 306 - 17.12 Configuring TELNET

ZyWALL 2 Series User’s Guide 23-8 WAN and Dial Backup Setup Table 23-5 Menu 11.1 Remote Node Profile (Backup ISP) FIELD DESCRIPTION EXAMPLE Idle Ti

Strona 307 - 17.13 Configuring FTP

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-9 23.7 Editing TCP/IP Options Move the cursor to the Edit IP field in menu 11.1, then pres

Strona 308 - 17.14 Configuring SNMP

ZyWALL 2 Series User’s Guide 23-10 WAN and Dial Backup Setup Table 23-6 Menu 11.3: Remote Node Network Layer Options FIELD DESCRIPTION EXAMPLE Netw

Strona 309

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-11 23.8 Editing Login Script For some remote gateways, text login is required before PPP ne

Strona 310 - 17.14.2 SNMP Traps

ZyWALL 2 Series User’s Guide 23-12 WAN and Dial Backup Setup Figure 23-8 Menu 11.4: Remote Node Script The following table describes the fi

Strona 311

ZyWALL 2 Series User’s Guide WAN and Dial Backup Setup 23-13 Figure 23-9 Menu 11.5: Dial Backup Remote Node Filter Menu 11.5 - Remote Node F

Strona 314 - 17.16 Configuring Security

ZyWALL 2 Series User’s Guide LAN Setup 24-1 Chapter 24 LAN Setup This chapter describes how to configure the LAN using Menu 3: LAN Setup. 24.1 In

Strona 315 - Table 17-8 Security

ZyWALL 2 Series User’s Guide 24-2 LAN Setup Figure 24-2 Menu 3.1: LAN Port Filter Setup 24.4 TCP/IP and DHCP Ethernet Setup Menu From the ma

Strona 316

ZyWALL 2 Series User’s Guide LAN Setup 24-3 Figure 24-4 Menu 3.2: TCP/IP and DHCP Ethernet Setup Follow the instructions in the next table

Strona 317 - Chapter 18

ZyWALL 2 Series User’s Guide 24-4 LAN Setup Table 24-2 LAN TCP/IP Setup Menu Fields FIELD DESCRIPTION EXAMPLE TCP/IP Setup: IP Address Enter t

Strona 318 - 18.3 Configuring UPnP

ZyWALL 2 Series User’s Guide LAN Setup 24-5 Figure 24-5 Physical Network Figure 24-6 Partitioned Logical Network You must u

Strona 319 - DESCRIPTION

ZyWALL 2 Series User’s Guide 24-6 LAN Setup Table 24-3 Menu 3.2.1: IP Alias Setup FIELD DESCRIPTION DEFAULT IP Address Enter the IP address of y

Strona 320

ZyWALL 2 Series User’s Guide LAN Setup 24-7 Figure 24-8 Menu 3.5: Wireless LAN Setup The settings of all client stations on the wireless LAN must m

Strona 321

ZyWALL 2 Series User’s Guide 24-8 LAN Setup Table 24-4 Menu 3.5: Wireless LAN Setup FIELD DESCRIPTION EXAMPLE Frag. Threshold The threshold (number

Strona 322

ZyWALL 2 Series User’s Guide LAN Setup 24-9 Step 3. In the Edit MAC Address Filter field, press [SPACE BAR] to select Yes and press [ENTER]. Menu

Strona 323

ZyWALL 2 Series User’s Guide Introducing the Web Configurator 2-1 Chapter 2 Introducing the Web Configurator This chapter describes how to acces

Strona 325

ZyWALL 2 Series User’s Guide Internet Access 25-1 Chapter 25 Internet Access This chapter shows you how to configure your ZyWALL for Internet access.

Strona 326

ZyWALL 2 Series User’s Guide 25-2 Internet Access Table 25-1 Menu 4: Internet Access Setup (Ethernet) FIELD DESCRIPTION Encapsulation Press [SPACE

Strona 327 - Part IX:

ZyWALL 2 Series User’s Guide Internet Access 25-3 25.3 PPTP Encapsulation Point-to-Point Tunneling Protocol (PPTP) is a network protocol that enables

Strona 328

ZyWALL 2 Series User’s Guide 25-4 Internet Access Table 25-2 New Fields in Menu 4 (PPTP) Screen FIELD DESCRIPTION EXAMPLE Encapsulation Press [SPAC

Strona 329 - Logs Screens

ZyWALL 2 Series User’s Guide Internet Access 25-5 Figure 25-3 Internet Access Setup (PPPoE) The following table contains instructions about

Strona 331

SMT Advanced Applications XII Part XII: SMT Advanced Applications This part covers setting up remote nodes, IP static routes and Network Address

Strona 333 - Table 19-2 Log Settings

ZyWALL 2 Series User’s Guide Remote Node Setup 26-1 Chapter 26 Remote Node Setup This chapter shows you how to configure a remote node. 26.1 Intro

Strona 334 - 19.3 Configuring Reports

ZyWALL 2 Series User’s Guide iv Information for Canadian Users Information for Canadian Users The Industry Canada label identifies certified equipm

Strona 335

ZyWALL 2 Series User’s Guide 2-2 Introducing the Web Configurator Step 6. Click Apply in the Replace Certificate screen to create a certificate us

Strona 336 - 19.3.1 Viewing Web Site Hits

ZyWALL 2 Series User’s Guide 26-2 Remote Node Setup Figure 26-1Menu 11.1: Remote Node Profile for Ethernet Encapsulation The following table

Strona 337 - 19.3.2 Viewing Protocol/Port

ZyWALL 2 Series User’s Guide Remote Node Setup 26-3 Table 26-1 Menu 11.1: Remote Node Profile for Ethernet Encapsulation FIELD DESCRIPTION EXAMPL

Strona 338

ZyWALL 2 Series User’s Guide 26-4 Remote Node Setup Encapsulation to PPPoE, then you will see the next screen. Please see the appendix for more info

Strona 339

ZyWALL 2 Series User’s Guide Remote Node Setup 26-5 Do not specify a nailed-up connection unless your telephone company offers flat-rate service or

Strona 340

ZyWALL 2 Series User’s Guide 26-6 Remote Node Setup 26.2.3 PPTP Encapsulation If you change the Encapsulation to PPTP in menu 11.1, then you will se

Strona 341 - Part X:

ZyWALL 2 Series User’s Guide Remote Node Setup 26-7 26.3 Edit IP Move the cursor to the Edit IP field in menu 11.1, then press [SPACE BAR] to sel

Strona 342

ZyWALL 2 Series User’s Guide 26-8 Remote Node Setup Table 26-4 Remote Node Network Layer Options Menu Fields FIELD DESCRIPTION EXAMPLE My WAN Addr

Strona 343 - Maintenance

ZyWALL 2 Series User’s Guide Remote Node Setup 26-9 Table 26-4 Remote Node Network Layer Options Menu Fields FIELD DESCRIPTION EXAMPLE Multicast

Strona 344

ZyWALL 2 Series User’s Guide 26-10 Remote Node Setup Figure 26-6 Menu 11.5: Remote Node Filter (PPPoE or PPTP Encapsulation) 26.5 Traffic Redi

Strona 345

ZyWALL 2 Series User’s Guide Remote Node Setup 26-11 Table 26-5 Menu 11.1: Remote Node Profile (Traffic Redirect Field) FIELD DESCRIPTION EXAMPLE

Strona 346 - 20.3 DHCP Table Screen

ZyWALL 2 Series User’s Guide Introducing the Web Configurator 2-3 2.3.2 Uploading a Configuration File Via Console Port Step 3. Download the defa

Strona 347 - 20.4 F/W Upload Screen

ZyWALL 2 Series User’s Guide 26-12 Remote Node Setup Table 26-6 Menu 11.6: Traffic Redirect Setup FIELD DESCRIPTION EXAMPLE Active Press [SPACE BA

Strona 348

ZyWALL 2 Series User’s Guide Remote Node Setup 26-13 Table 26-6 Menu 11.6: Traffic Redirect Setup FIELD DESCRIPTION EXAMPLE When you have complet

Strona 350 - 20.5.1 Backup Configuration

ZyWALL 2 Series User’s Guide IP Static Route Setup 27-1 Chapter 27 IP Static Route Setup This chapter shows you how to configure static rout

Strona 351

ZyWALL 2 Series User’s Guide 27-2 IP Static Route Setup Figure 27-2 Menu 12. 1: Edit IP Static Route `The following table describes the IP Stat

Strona 352

ZyWALL 2 Series User’s Guide NAT 28-1 Chapter 28 Network Address Translation (NAT) This chapter discusses how to configure NAT on the ZyWALL. 28.

Strona 353 - 20.6 Restart Screen

ZyWALL 2 Series User’s Guide 28-2 NAT Figure 28-1 Menu 4: Applying NAT for Internet Access The following figure shows how you apply NAT to th

Strona 354

ZyWALL 2 Series User’s Guide NAT 28-3 Table 28-1 Applying NAT in Menus 4 & 11.3 FIELD DESCRIPTION OPTIONS When you select this option the

Strona 355 - Part XI:

ZyWALL 2 Series User’s Guide 28-4 NAT Configure LAN IP addresses in NAT menus 15.1 and 15.2. 28.2.1 Address Mapping Sets Enter 1 to bring up Menu 1

Strona 356

ZyWALL 2 Series User’s Guide NAT 28-5 Table 28-2 SUA Address Mapping Rules FIELD DESCRIPTION EXAMPLE Set Name This is the name of the set you s

Strona 357 - Introducing the SMT

ZyWALL 2 Series User’s Guide 2-4 Introducing the Web Configurator Follow the instructions you see in the MAIN MENU screen or click the icon (loca

Strona 358 - 21.2.2 Entering the Password

ZyWALL 2 Series User’s Guide 28-6 NAT Figure 28-6 Menu 15.1.1: First Set The Type, Local and Global Start/End IPs are configured in menu 15.

Strona 359 - 21.3.1 Main Menu

ZyWALL 2 Series User’s Guide NAT 28-7 Table 28-3 Fields in Menu 15.1.1 FIELD DESCRIPTION EXAMPLE Set Name Enter a name for this set of rules. T

Strona 360

ZyWALL 2 Series User’s Guide 28-8 NAT The following table describes the fields in this screen. Table 28-4 Menu 15.1.1.1: Editing/Configuring an Indiv

Strona 361 - Change Console Port Speed

ZyWALL 2 Series User’s Guide NAT 28-9 Step 5. Press [ENTER] at the “Press ENTER to confirm …” prompt to save your configuration after you define

Strona 362

ZyWALL 2 Series User’s Guide 28-10 NAT 28.4.1 Internet Access Only In the following Internet access example, you only need one rule where all your IL

Strona 363 - SMT Menu 1 - General Setup

ZyWALL 2 Series User’s Guide NAT 28-11 28.4.2 Example 2: Internet Access with an Inside Server Figure 28-12 NAT Example 2 In this case, you do ex

Strona 364

ZyWALL 2 Series User’s Guide 28-12 NAT other LAN traffic to the remaining IGA. Map the third IGA to an inside web server and mail server. Four rules

Strona 365

ZyWALL 2 Series User’s Guide NAT 28-13 Step 5. Select Type as One-to-One (direct mapping for packets going both ways), and enter the local Start

Strona 366

ZyWALL 2 Series User’s Guide 28-14 NAT Figure 28-17 Example 3: Final Menu 15.1.1 Now configure the IGA3 to map to our web server and mail se

Strona 367 - WAN and Dial Backup Setup

ZyWALL 2 Series User’s Guide NAT 28-15 28.4.4 Example 4: NAT Unfriendly Application Programs Some applications do not support NAT Mapping using TC

Strona 368 - 23.2 Dial Backup

ZyWALL 2 Series User’s Guide Introducing the Web Configurator 2-5 Table 2-1 Web Configurator Screens Summary LINK TAB FUNCTION General Use this

Strona 369 - 23.4 Advanced WAN Setup

ZyWALL 2 Series User’s Guide 28-16 NAT Figure 28-20 Example 4: Menu 15.1.1.1: Address Mapping Rule After you’ve configured your rule, you shoul

Strona 370

ZyWALL 2 Series User’s Guide NAT 28-17 LAN computer, you have to manually replace the LAN computer's IP address in the forwarding port with a

Strona 371

ZyWALL 2 Series User’s Guide 28-18 NAT 5. Only A can connect to the Real Audio server until the connection is closed or times out. The ZyWALL times o

Strona 372

ZyWALL 2 Series User’s Guide NAT 28-19 Table 28-5 Menu 15.3: Trigger Port Setup FIELD DESCRIPTION EXAMPLE Rule This is the rule index number.

Strona 374 - 23.6 Editing PPP Options

ZyWALL 2 Series User’s Guide Introducing the Firewall 29-1 Chapter 29 Introducing the Firewall This chapter shows you how to get started with the fi

Strona 375 - 23.7 Editing TCP/IP Options

ZyWALL 2 Series User’s Guide 29-2 Introducing the Firewall Figure 29-2 Menu 21.2: Firewall Setup Configure the firewall rules using the we

Strona 376

ZyWALL 2 Series User’s Guide Filter Configuration 30-1 Chapter 30 Filter Configuration This chapter shows you how to create and apply filters. 30.1

Strona 377 - 23.8 Editing Login Script

ZyWALL 2 Series User’s Guide 30-2 Filter Configuration Figure 30-1 Outgoing Packet Filtering Process For incoming packets, your ZyWALL applies data f

Strona 378 - 23.9 Remote Node Filter

ZyWALL 2 Series User’s Guide Filter Configuration 30-3 StartFetch FirstFilter SetFetch FirstFilter RuleActive?ExecuteFilter RuleFetch NextFilter Rul

Strona 379

ZyWALL 2 Series User’s Guide 2-6 Introducing the Web Configurator Table 2-1 Web Configurator Screens Summary LINK TAB FUNCTION General This scre

Strona 380

ZyWALL 2 Series User’s Guide 30-4 Filter Configuration You can apply up to four filter sets to a particular port to block multiple types of packets.

Strona 381 - LAN Setup

ZyWALL 2 Series User’s Guide Filter Configuration 30-5 Step 4. Enter a descriptive name or comment in the Edit Comments field and press [ENTER]. St

Strona 382 - 2. TCP/IP and DHCP Setup

ZyWALL 2 Series User’s Guide 30-6 Filter Configuration Table 30-2 Rule Abbreviations Used ABBREVIATION DESCRIPTION IP Pr Protocol SA Source Address

Strona 383

ZyWALL 2 Series User’s Guide Filter Configuration 30-7 To configure TCP/IP rules, select TCP/IP Filter Rule from the Filter Type field and press [EN

Strona 384 - 24.4.1 IP Alias Setup

ZyWALL 2 Series User’s Guide 30-8 Filter Configuration Table 30-3 TCP/IP Filter Rule Menu Fields FIELD DESCRIPTION OPTIONS Port # Enter the destinat

Strona 385 - IP Alias 1, 2

ZyWALL 2 Series User’s Guide Filter Configuration 30-9 Table 30-3 TCP/IP Filter Rule Menu Fields FIELD DESCRIPTION OPTIONS Log Press [SPACE BAR] an

Strona 386 - 24.5 Wireless LAN Setup

ZyWALL 2 Series User’s Guide 30-10 Filter Configuration Packetinto IP FilterMatchedMatchedYesAction MatchedAction Not MatchedMore?NoFilter Active?Chec

Strona 387

ZyWALL 2 Series User’s Guide Filter Configuration 30-11 30.2.3 Configuring a Generic Filter Rule This section shows you how to configure a generic

Strona 388

ZyWALL 2 Series User’s Guide 30-12 Filter Configuration Table 30-4 Menu 21.1.1.1: Generic Filter Rule FIELD DESCRIPTION OPTIONS Filter Type Use [SPAC

Strona 389

ZyWALL 2 Series User’s Guide Filter Configuration 30-13 30.3 Example Filter Let’s look at an example to block outside users from accessing the ZyWAL

Strona 390

ZyWALL 2 Series User’s Guide Introducing the Web Configurator 2-7 Table 2-1 Web Configurator Screens Summary LINK TAB FUNCTION SNMP Use this scr

Strona 391 - Internet Access

ZyWALL 2 Series User’s Guide 30-14 Filter Configuration Figure 30-9 Example Filter: Menu 21.1.3.1 When you press [ENTER] to confirm, you will see the

Strona 392 - 25-2 Internet Access

ZyWALL 2 Series User’s Guide Filter Configuration 30-15 Figure 30-10 Example Filter Rules Summary: Menu 21.1.3 After you’ve created the

Strona 393 - 25.3 PPTP Encapsulation

ZyWALL 2 Series User’s Guide 30-16 Filter Configuration 30.4 Filter Types and NAT There are two classes of filter rules, Generic Filter (Device) rule

Strona 394 - 25.4 PPPoE Encapsulation

ZyWALL 2 Series User’s Guide Filter Configuration 30-17 30.6 Applying a Filter This section shows you where to apply the filter(s) after you desig

Strona 395 - 25.5 Basic Setup Complete

ZyWALL 2 Series User’s Guide 30-18 Filter Configuration Figure 30-13 Filtering Remote Node Traffic Menu 11.5 – Remote Node Filter Setup Input

Strona 396

ZyWALL 2 Series User’s Guide SNMP Configuration 31-1 Chapter 31 SNMP Configuration This chapter explains SNMP configuration menu 22. 31.1 SNMP Confi

Strona 397 - Part XII:

ZyWALL 2 Series User’s Guide 31-2 SNMP Configuration Table 31-1 Menu 22: SNMP Configuration FIELD DESCRIPTION EXAMPLE Trap Community Type the Trap

Strona 398

SMT System Maintenance XIII Part XIII: SMT System Maintenance This part covers system information and diagnosis, firmware and configuration file

Strona 400

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-1 Chapter 32 System Information & Diagnosis This chapter covers SMT menus 24.1

Strona 402 - Nailed-Up Connection

ZyWALL 2 Series User’s Guide 32-2 System Information and Diagnosis monitor your ZyWALL. Specifically, it gives you information on your system firmwa

Strona 403

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-3 Table 32-1 System Maintenance: Status Menu Fields FIELD DESCRIPTION Status Shows

Strona 404 - 26.2.3 PPTP Encapsulation

ZyWALL 2 Series User’s Guide 32-4 System Information and Diagnosis Step 2. Enter 2 to open Menu 24.2 - System Information and Console Port Speed.

Strona 405 - 26.3 Edit IP

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-5 Table 32-2 Fields in System Maintenance: Information FIELD DESCRIPTION ZyNOS F/W

Strona 406 - 26-8 Remote Node Setup

ZyWALL 2 Series User’s Guide 32-6 System Information and Diagnosis Figure 32-6 Menu 24.3: System Maintenance: Log and Trace 32.4.1 UNIX Syslog The

Strona 407 - 26.4 Remote Node Filter

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-7 Table 32-3 System Maintenance Menu Syslog Parameters PARAMETER DESCRIPTION Log Fa

Strona 408 - 26.5 Traffic Redirect

ZyWALL 2 Series User’s Guide 32-8 System Information and Diagnosis Filter log Message Format SdcmdSyslogSend(SYSLOG_FILLOG, SYSLOG_NOTICE, String

Strona 409

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-9 32.4.2 Call-Triggering Packet Call-Triggering Packet displays information about t

Strona 410 - 26-12 Remote Node Setup

ZyWALL 2 Series User’s Guide 32-10 System Information and Diagnosis Follow the procedure below to get to Menu 24.4 - System Maintenance – Diagnostic

Strona 411 - Remote Node Setup 26-13

ZyWALL 2 Series User’s Guide System Information and Diagnosis 32-11 Figure 32-10 WAN & LAN DHCP The following table describes the diagnostic te

Strona 412

ZyWALL 2 Series User’s Guide Wizard Setup 3-1 Chapter 3 Wizard Setup This chapter provides information on the Wizard Setup screens in the web confi

Strona 414

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-1 Chapter 33 Firmware and Configuration File Maintenance This chapter tells you

Strona 415 - Chapter 28

ZyWALL 2 User’s Guide 33-2 Firmware and Configuration File Maintenance ftp> get rom-0 config.cfg This is a sample FTP session saving the current

Strona 416

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-3 preferred method for backing up your current configuration to your computer si

Strona 417 - 28.2 NAT Setup

ZyWALL 2 User’s Guide 33-4 Firmware and Configuration File Maintenance Step 6. Use “get” to transfer files from the ZyWALL to the computer, for exam

Strona 418 - 28.2.1 Address Mapping Sets

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-5 33.3.5 File Maintenance Over WAN TFTP, FTP and Telnet over the WAN will not wo

Strona 419

ZyWALL 2 User’s Guide 33-6 Firmware and Configuration File Maintenance TFTP client program. For UNIX, use “get” to transfer from the ZyWALL to the co

Strona 420 - Ordering Your Rules

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-7 Step 1. Display menu 24.5 and enter “y” at the following screen. Figure 33-3

Strona 421

ZyWALL 2 User’s Guide 33-8 Firmware and Configuration File Maintenance 33.4 Restore Configuration This section shows you how to restore a previously

Strona 422

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-9 Step 1. Launch the FTP client on your computer. Step 2. Enter “open”, follo

Strona 423 - 28.4 General NAT Examples

ZyWALL 2 Series User’s Guide 3-2 Wizard Setup Figure 3-1 Wizard 1 3.3 Internet Access The ZyWALL offers three choices of encapsulation. They are E

Strona 424 - 28.4.1 Internet Access Only

ZyWALL 2 User’s Guide 33-10 Firmware and Configuration File Maintenance Step 1. Display menu 24.6 and enter “y” at the following screen. Figure 33-9

Strona 425

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-11 33.5 Uploading Firmware and Configuration Files This section shows you how t

Strona 426

ZyWALL 2 User’s Guide 33-12 Firmware and Configuration File Maintenance 33.5.2 Configuration File Upload You see the following screen when you telnet

Strona 427 - 10.132.50.1

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-13 transfers the configuration file on the ZyWALL to your computer and renames i

Strona 428

ZyWALL 2 User’s Guide 33-14 Firmware and Configuration File Maintenance Step 3. Enter the command “sys stdio 0” to disable the console timeout, so t

Strona 429

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-15 33.5.8 Uploading Firmware File Via Console Port Step 1. Select 1 from Menu 2

Strona 430 - 10.132.20.3

ZyWALL 2 User’s Guide 33-16 Firmware and Configuration File Maintenance Figure 33-17 Example Xmodem Upload After the firmware upload process has com

Strona 431

ZyWALL 2 User’s Guide Firmware and Configuration File Maintenance 33-17 Figure 33-18 Menu 24.7.2 As Seen Using the Console Port Step 2. After the &

Strona 432

ZyWALL 2 User’s Guide 33-18 Firmware and Configuration File Maintenance Figure 33-19 Example Xmodem Upload After the configuration upload process has

Strona 433

ZyWALL 2 User’s Guide System Maintenance & Information 34-1 Chapter 34 System Maintenance Menus 8 to 10 This chapter leads you through SMT men

Strona 434

ZyWALL 2 Series User’s Guide Wizard Setup 3-3 Figure 3-2 Wizard 2: Ethernet Encapsulation The following table describes the labels in this screen.

Strona 435 - Introducing the Firewall

ZyWALL 2 User’s Guide 34-2 System Maintenance & Information 34.1.1 Command Syntax The command keywords are in courier new font. Enter the command

Strona 436 - Active: Yes

ZyWALL 2 User’s Guide System Maintenance & Information 34-3 Table 34-1 Valid Commands ether These commands display Ethernet information and con

Strona 437 - Filter Configuration

ZyWALL 2 User’s Guide 34-4 System Maintenance & Information Figure 34-4 Budget Management The total budget is the time limit on the accumul

Strona 438 - Filter Structure

ZyWALL 2 User’s Guide System Maintenance & Information 34-5 Figure 34-5 Call History The following table describes the fields in this sc

Strona 439 - Filter Set

ZyWALL 2 User’s Guide 34-6 System Maintenance & Information Select menu 24 in the main menu to open Menu 24 - System Maintenance, as shown next.

Strona 440 - 1. Filter Setup

ZyWALL 2 User’s Guide System Maintenance & Information 34-7 Table 34-4 Menu 24.10 System Maintenance: Time and Date Setting FIELD DESCRIPTION En

Strona 441

ZyWALL 2 User’s Guide 34-8 System Maintenance & Information ii. When the ZyWALL starts up, if there is a timeserver configured in menu 24.10. ii

Strona 442 - Len Length

ZyWALL 2 User’s Guide Remote Management 35-1 Chapter 35 Remote Management This chapter covers remote management found in SMT menu 24.11. 35.1 Remote

Strona 443

ZyWALL 2 User’s Guide 35-2 Remote Management Figure 35-1 Menu 24.11 – Remote Management Control The following table describes the fields in thi

Strona 444 - 30-8 Filter Configuration

ZyWALL 2 User’s Guide Remote Management 35-3 Table 35-1 Menu 24.11 – Remote Management Control FIELD DESCRIPTION EXAMPLE Once you have filled in th

Strona 445 - Filter Configuration 30-9

ZyWALL 2 Series User’s Guide Warranty v ZyXEL Limited Warranty ZyXEL warrants to the original end user (purchaser) that this product is free from an

Strona 446 - 30-10 Filter Configuration

ZyWALL 2 Series User’s Guide 3-4 Wizard Setup Table 3-1 Ethernet Encapsulation LABEL DESCRIPTION Login Server IP Address Type the authentication ser

Strona 448 - 30-12 Filter Configuration

SMT Advanced Management XIV Part XIV: SMT Advanced Management This part provides information on how to configure call scheduling, and VPN/IPSec

Strona 450

ZyWALL 2 Series User’s Guide Call Scheduling 36-1 Chapter 36 Call Scheduling Call scheduling allows you to dictate when a remote node should

Strona 451

ZyWALL 2 Series User’s Guide 36-2 Call Scheduling To set up a schedule set, select the schedule set you want to setup from menu 26 (1-12) and press

Strona 452 - 30.4 Filter Types and NAT

ZyWALL 2 Series User’s Guide Call Scheduling 36-3 Table 36-1 Schedule Set Setup FIELD DESCRIPTION OPTIONS Day If you selected Weekly in the

Strona 453 - 30.6 Applying a Filter

ZyWALL 2 Series User’s Guide 36-4 Call Scheduling Figure 36-3 Applying Schedule Set(s) to a Remote Node (PPPoE) You can apply up to four sch

Strona 454

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-1 Chapter 37 VPN/IPSec Setup This chapter introduces the VPN SMT menus. 37.1 Introduction T

Strona 455 - SNMP Configuration

ZyWALL 2 Series User’s Guide 37-2 VPN/IPSec Setup Figure 37-2 Menu 27: VPN/IPSec Setup 37.2 IPSec Summary Screen Type 1 in menu 27 and then

Strona 456 - 31.2 SNMP Traps

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-3 Table 37-1 Menu 27.1: IPSec Summary FIELD DESCRIPTION EXAMPLE Name This field displays the

Strona 457 - Part XIII:

ZyWALL 2 Series User’s Guide Wizard Setup 3-5 Figure 3-3 Wizard2: PPPoE Encapsulation The following table describes the labels in this screen. Tab

Strona 458

ZyWALL 2 Series User’s Guide 37-4 VPN/IPSec Setup Table 37-1 Menu 27.1: IPSec Summary FIELD DESCRIPTION EXAMPLE Key Mgt This field displays the SA’s

Strona 459 - Chapter 32

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-5 Table 37-1 Menu 27.1: IPSec Summary FIELD DESCRIPTION EXAMPLE Select Command Press [SPACE B

Strona 460 - FIELD DESCRIPTION

ZyWALL 2 Series User’s Guide 37-6 VPN/IPSec Setup Figure 37-4 Menu 27.1.1: IPSec Setup You must also configure menu 27.1.1.1 or menu 2

Strona 461

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-7 Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE NAT Traversal Select this c

Strona 462 - 32.3.1 System Information

ZyWALL 2 Series User’s Guide 37-8 VPN/IPSec Setup Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE Peer ID type Press [SPACE BAR] to cho

Strona 463 - 32.4 Log and Trace

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-9 Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE Local Local IP addresses mus

Strona 464 - 32.4.1 UNIX Syslog

ZyWALL 2 Series User’s Guide 37-10 VPN/IPSec Setup Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE End Enter a port number in this fie

Strona 465 - PARAMETER DESCRIPTION

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-11 Table 37-2 Menu 27.1.1: IPSec Setup FIELD DESCRIPTION EXAMPLE Port Start 0 is the default

Strona 466

ZyWALL 2 Series User’s Guide 37-12 VPN/IPSec Setup Figure 37-5 Menu 27.1.1.1: IKE Setup Table 37-3 Menu 27.1.1.1: IKE Setup FIELD DES

Strona 467 - 32.4.3 Diagnostic

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-13 Table 37-3 Menu 27.1.1.1: IKE Setup FIELD DESCRIPTION EXAMPLEEncryption Algorithm When DES

Strona 468 - 32.4.4 WAN DHCP

ZyWALL 2 Series User’s Guide 3-6 Wizard Setup Table 3-2 PPPoE Encapsulation LABEL DESCRIPTION Idle Timeout Type the time in seconds that elapses bef

Strona 469

ZyWALL 2 Series User’s Guide 37-14 VPN/IPSec Setup Table 37-3 Menu 27.1.1.1: IKE Setup FIELD DESCRIPTION EXAMPLEEncapsulation Press [SPACE BAR] to ch

Strona 470

ZyWALL 2 Series User’s Guide VPN/IPSec Setup 37-15 To edit this menu, move the cursor to the Edit Manual Setup field in Menu 27.1.1 – IPSec S

Strona 471 - Chapter 33

ZyWALL 2 Series User’s Guide 37-16 VPN/IPSec Setup Table 37-5 Menu 27.1.1.2: Manual Setup FIELD DESCRIPTION EXAMPLE Key3 Enter a unique eight-charac

Strona 472 - 33.3 Backup Configuration

ZyWALL 2 Series User’s Guide SA Monitor 38-1 Chapter 38 SA Monitor This chapter teaches you how to manage your SAs by using the SA Monitor in

Strona 473 - 33.3.1 Backup Configuration

ZyWALL 2 Series User’s Guide 38-2 SA Monitor Table 38-1 Menu 27.2: SA Monitor FIELD DESCRIPTION EXAMPLE # This is the security association index

Strona 474 - 33.3.4 GUI-based FTP Clients

General Appendices XV Part XV: General Appendices This part provides background information about troubleshooting, setting up your computer’s I

Strona 476 - 33.3.7 TFTP Command Example

ZyWALL 2 Series User’s Guide Troubleshooting A-1 Appendix A Troubleshooting This chapter covers potential problems and possible remedies. After each

Strona 477 - Then click Receive

ZyWALL 2 Series User’s Guide Troubleshooting A-2Problems with the LAN Interface Chart 3 Troubleshooting the LAN Interface PROBLEM CORRECTIVE ACTION

Strona 478 - 33.4 Restore Configuration

ZyWALL 2 Series User’s Guide Troubleshooting A-3 Problems with Internet Access Chart 5 Troubleshooting Internet Access PROBLEM CORRECTIVE ACTION Con

Strona 479

ZyWALL 2 Series User’s Guide Wizard Setup 3-7 Figure 3-4 Wizard 2: PPTP Encapsulation The following table describes the labels in this screen. Tab

Strona 481 - 33.5.1 Firmware File Upload

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-1 Appendix B Setting up Your Computer’s IP Address All computers must have a 10

Strona 482

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-2The Network window Configuration tab displays a list of installed components.

Strona 483 - 33.5.5 TFTP File Upload

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-3 1. Click the IP Address tab. -If your IP address is dynamic, select Obtain an

Strona 484

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-43. Click the Gateway tab. -If you do not know your gateway’s IP address, rem

Strona 485

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-5 1. For Windows XP, click Start, Control Panel. In Windows 2000/NT, click Star

Strona 486

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-64. Select Internet Protocol (TCP/IP) (under the General tab in Win XP) and cli

Strona 487

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-7 6. -If you do not know your gateway's IP address, remove any previously

Strona 488 - ZyWALL 2 User’s Guide

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-8 7. In the Internet Protocol TCP/IP Properties window (the General tab in Wind

Strona 489 - Chapter 34

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-9 1. Click the Apple menu, Control Panel and double-click TCP/IP to open the TC

Strona 490 - 34.1.2 Command Usage

ZyWALL 2 Series User’s Guide 3-8 Wizard Setup Table 3-3 PPTP Encapsulation LABEL DESCRIPTION My IP Address Type the (static) IP address assigned to

Strona 491 - 34.2 Call Control Support

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-104. For statically assigned settings, do the following: -From the Configure

Strona 492 - 34.2.2 Call History

ZyWALL 2 Series User’s Guide Setting Up Your Computer’s IP Address B-11 2. Click Network in the icon bar. - Select Automatic from the Location li

Strona 494 - 10. Time and Date Setting

ZyWALL 2 Series User’s Guide Triangle Route C-1 Appendix C Triangle Route The Ideal Setup When the firewall is on, your ZyWALL acts as a secure g

Strona 495 - 34.3.1 Resetting the Time

ZyWALL 2 Series User’s Guide Triangle Route C-2 Diagram 2 “Triangle Route” Problem The “Triangle Route” Solutions This section presents you two solu

Strona 496

ZyWALL 2 Series User’s Guide Triangle Route C-3 Diagram 3 IP Alias Gateways on the WAN Side A second solution to the “triangle route” problem is t

Strona 497 - Remote Management

ZyWALL 2 Series User’s Guide Triangle Route C-4Step 3. Use the following commands to allow/disallow triangle route. sys firewall ignore triangle al

Strona 498

ZyWALL 2 Series User’s Guide Wireless LAN and IEEE 802.11 D-1 Appendix D Wireless LAN and IEEE 802.11 A wireless LAN (WLAN) provides a flexible da

Strona 499 - FIELD DESCRIPTION EXAMPLE

ZyWALL 2 Series User’s Guide D-2 Wireless LAN and IEEE 802.11 Spread Spectrum (DSSS) and Frequency-Hopping Spread Spectrum (FHSS), in the 2.4 to 2.

Strona 500

ZyWALL 2 Series User’s Guide Wireless LAN and IEEE 802.11 D-3 could be any type of network, it is almost invariably an Ethernet LAN. Mobile nodes c

Strona 501 - Part XIV:

ZyWALL 2 Series User’s Guide Wizard Setup 3-9 Regardless of your particular situation, do not create an arbitrary IP address; always follow the gui

Strona 503 - Call Scheduling

ZyWALL 2 Series User’s Guide Wireless LAN with IEEE 802.1x E-1 Appendix E Wireless LAN With IEEE 802.1x As wireless networks become popular for bot

Strona 504

ZyWALL 2 Series User’s Guide Wireless LAN with IEEE 802.1x E-2RADIUS Server Authentication Sequence The following figure depicts a typical wirele

Strona 505

ZyWALL 2 Series User’s Guide Types of EAP Authentication F-1 Appendix F Types of EAP Authentication This appendix discusses three popular EAP auth

Strona 506

ZyWALL 2 Series User’s Guide Types of EAP Authentication F-2TTLS supports EAP methods and legacy authentication methods such as PAP, CHAP, MS-CHAP

Strona 507 - VPN/IPSec Setup

ZyWALL 2 Series User’s Guide PPPoE G-1 Appendix G PPPoE PPPoE in Action An ADSL modem bridges a PPP session over Ethernet (PPP over Ethernet, RFC 25

Strona 508 - 37.2 IPSec Summary Screen

ZyWALL 2 Series User’s Guide G-2 PPPoE The PPPoE driver makes the Ethernet appear as a serial link to the PC and the PC runs PPP over it, while the m

Strona 509 - VPN/IPSec Setup 37-3

ZyWALL 2 Series User’s Guide PPTP H-1 Appendix H PPTP What is PPTP? PPTP (Point-to-Point Tunneling Protocol) is a Microsoft proprietary protocol (R

Strona 510 - 37-4 VPN/IPSec Setup

ZyWALL 2 Series User’s Guide H-2 PPTP PPTP is very similar to L2TP, since L2TP is based on both PPTP and L2F (Cisco’s Layer 2 Forwarding). Conceptual

Strona 511 - 37.3 IPSec Setup

ZyWALL 2 Series User’s Guide PPTP H-3 Diagram H-3 Example Message Exchange between PC and an ANT PPP Data Connection The PPP frames are tunneled b

Strona 512

ZyWALL 2 Series User’s Guide 3-10 Wizard Setup 3.4.4 WAN MAC Address Every Ethernet device has a unique MAC (Media Access Control) address. The MAC a

Strona 514 - 37-8 VPN/IPSec Setup

ZyWALL 2 Series User’s Guide IP Subnetting I-1 Appendix I IP Subnetting IP Addressing Routers “route” based on the network number. The router that d

Strona 515 - VPN/IPSec Setup 37-9

ZyWALL 2 Series User’s Guide I-2 IP Subnetting A class “A” address (24 host bits) can have 224 –2 hosts (approximately 16 million hosts). Since the

Strona 516 - 37-10 VPN/IPSec Setup

ZyWALL 2 Series User’s Guide IP Subnetting I-3 of ones beginning from the left most bit of the mask, followed by a continuous sequence of zeros, for

Strona 517 - 37.4 IKE Setup

ZyWALL 2 Series User’s Guide I-4 IP Subnetting Divide the network 192.168.1.0 into two separate subnets by converting one of the host ID bits of the

Strona 518

ZyWALL 2 Series User’s Guide IP Subnetting I-5 actual host for the first subnet is 192.168.1.1 and the highest is 192.168.1.126. Similarly the host I

Strona 519 - VPN/IPSec Setup 37-13

ZyWALL 2 Series User’s Guide I-6 IP Subnetting Chart I-10 Subnet 4 NETWORK NUMBER LAST OCTET BIT VALUE IP Address 192.168.1. 192 IP Address (Bin

Strona 520 - 37.5 Manual Setup

ZyWALL 2 Series User’s Guide IP Subnetting I-7 4 255.255.255.240 (/28) 16 14 5 255.255.255.248 (/29) 32 6 6 255.255.255.252 (/30) 64 2 7 255.255.2

Strona 521

ZyWALL 2 Series User’s Guide I-8 IP Subnetting Chart I-13 Class B Subnet Planning NO. “BORROWED” HOST BITS SUBNET MASK NO. SUBNETS NO. HOSTS PER S

Strona 522 - 37-16 VPN/IPSec Setup

ZyWALL 2 Series User’s Guide Safety Warnings and Instructions J-1 Appendix J Safety Warnings and Instructions 1. Be sure to read and follow all warn

Strona 523 - SA Monitor

ZyWALL 2 Series User’s Guide Wizard Setup 3-11 Figure 3-5 Wizard 3 The following table describes the labels in this screen. Table 3-6 Wizard 3 LAB

Strona 525 - Part XV:

Command, Log Appendices and Index XVI Part XVI: Command, Log Appendices and Index This part provides information on the command line interface,

Strona 527 - Troubleshooting

ZyWALL 2 Series User’s Guide Command Interpreter K-1 Appendix K Command Interpreter The following describes how to use the command interpreter.

Strona 529

ZyWALL 2 Series User’s Guide Firewall Commands L-1 Appendix L Firewall Commands The following describes the firewall commands. See the Command Int

Strona 530

ZyWALL 2 User’s Guide L-2 Firewall Commands Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION config display firewall e-mail This comm

Strona 531 - Appendix B

ZyWALL 2 Series User’s Guide Firewall Commands L-3 Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION config edit firewall attack block &

Strona 532

ZyWALL 2 User’s Guide L-4 Firewall Commands Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION Config edit firewall set <set #> defau

Strona 533

ZyWALL 2 Series User’s Guide Firewall Commands L-5 Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION Config edit firewall set <se

Strona 534 - Windows 2000/NT/XP

ZyWALL 2 Series User’s Guide 3-12 Wizard Setup Table 3-6 Wizard 3 LABEL DESCRIPTION Remote IP Subnet Mask Enter the gateway IP subnet mask (if your

Strona 535

ZyWALL 2 User’s Guide L-6 Firewall Commands Chart L-1 Firewall Commands FUNCTION COMMAND DESCRIPTION config edit firewall set <set #> r

Strona 536

ZyWALL 2 Series User’s Guide NetBIOS Filter Commands M-1 Appendix M NetBIOS Filter Commands The following describes the NetBIOS packet filter comma

Strona 537

ZyWALL 2 User’s Guide M-2 NetBIOS Filter Commands Chart M-1 NetBIOS Filter Default Settings NAME DESCRIPTION EXAMPLE Between LAN and WAN This field

Strona 538

ZyWALL 2 Series User’s Guide NetBIOS Filter Commands M-3 Command: sys filter netbios config 4 off This command stops NetBIOS commands from initiati

Strona 540

ZyWALL 2 Series User’s Guide Boot Commands N-1 Appendix N Boot Commands The BootModule AT commands execute from within the router’s bootup software

Strona 541

ZyWALL 2 User’s Guide N-2 Boot Commands Diagram N-2 Boot Module Commands AT just answer OK ATHE print h

Strona 542

ZyWALL 2 Series User’s Guide Log Descriptions O-1 Appendix O Log Descriptions Chart O-1 System Error Logs LOG MESSAGE DESCRIPTION %s exceeds the

Strona 543 - Triangle Route

ZyWALL 2 User’s Guide O-2 Log Descriptions Chart O-2 System Maintenance Logs TELNET Login Fail Someone has failed to log on to the router via telnet

Strona 544

ZyWALL 2 Series User’s Guide Log Descriptions O-3 Chart O-5 Attack Logs LOG MESSAGE DESCRIPTION attack IGMP The firewall detected an IGMP attack.

Strona 545

ZyWALL 2 Series User’s Guide Wizard Setup 3-13 Figure 3-6 Internet Access Wizard Setup Complete

Strona 546

ZyWALL 2 User’s Guide O-4 Log Descriptions Chart O-5 Attack Logs LOG MESSAGE DESCRIPTION syn flood TCP The firewall detected a TCP syn flood attack

Strona 547 - Appendix D

ZyWALL 2 Series User’s Guide Log Descriptions O-5 Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Firewall default policy: TCP (set:%d) TCP access m

Strona 548

ZyWALL 2 User’s Guide O-6 Log Descriptions Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Firewall rule match: ESP (set:%d, rule:%d) ESP access matc

Strona 549

ZyWALL 2 Series User’s Guide Log Descriptions O-7 Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Firewall rule NOT match: (set:%d, rule:%d) Access

Strona 550

ZyWALL 2 User’s Guide O-8 Log Descriptions Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Filter match DROP <set %d/rule %d> Access matched th

Strona 551 - Appendix E

ZyWALL 2 Series User’s Guide Log Descriptions O-9 Chart O-6 Access Logs LOG MESSAGE DESCRIPTION Packet without a NAT table entry blocked The route

Strona 552 - Client computer

ZyWALL 2 User’s Guide O-10 Log Descriptions Chart O-8 ICMP Notes TYPE CODE DESCRIPTION 3 Destination Unreachable 0 Net unreachable 1 Host unreac

Strona 553 - Types of EAP Authentication

ZyWALL 2 Series User’s Guide Log Descriptions O-11 Chart O-8 ICMP Notes TYPE CODE DESCRIPTION 14 Timestamp Reply 0 Timestamp reply message 15 I

Strona 554

ZyWALL 2 User’s Guide O-12 Log Descriptions Diagram O-1 Example VPN Initiator IPSec Log VPN Responder IPSec Log The following figure shows a typical

Strona 555 - Appendix G

ZyWALL 2 Series User’s Guide Log Descriptions O-13 A PYLD_MALFORMED packet usually means that the two ends of the VPN tunnel are not using the same

Strona 556

ZyWALL 2 Series User’s Guide vi Customer Support Customer Support When you contact your customer support representative please have the following inf

Strona 558 - Call Connection

ZyWALL 2 User’s Guide O-14 Log Descriptions Chart O-10 Sample IKE Key Exchange Logs LOG MESSAGE DESCRIPTION !! Invalid IP <IP start>/<IP e

Strona 559 - PPP Data Connection

ZyWALL 2 Series User’s Guide Log Descriptions O-15 Chart O-10 Sample IKE Key Exchange Logs LOG MESSAGE DESCRIPTION vs. My Local <IP address>

Strona 560

ZyWALL 2 User’s Guide O-16 Log Descriptions The following table shows RFC-2408 ISAKMP payload types that the log displays. Please refer to the RFC f

Strona 561 - IP Subnetting

ZyWALL 2 Series User’s Guide Log Descriptions O-17 Chart O-13 Log Categories and Available Settings LOG CATEGORIES AVAILABLE PARAMETERS attack 0,

Strona 562

ZyWALL 2 User’s Guide O-18 Log Descriptions ras> sys logs display access # .time source destination

Strona 563

ZyWALL 2 Series User’s Guide Brute-Force Password Guessing Protection P-1 Appendix P Brute-Force Password Guessing Protection The following describ

Strona 565

ZyWALL 2 Series User’s Guide Index Q-1 Appendix Q Index 1 10/100 Mbps Ethernet WAN ... 1-2 4 4-Port Switch ...

Strona 566

ZyWALL 2 Series User’s Guide Q-2 Index Configuration File Upload... 33-16 File Backup ...

Strona 567

ZyWALL 2 Series User’s Guide Index Q-3 Filter... 23-12, 24-1, 26-9, 30-1 Applying ...

Strona 568 - I-8 IP Subnetting

System and LAN II Part II: System and LAN This part covers configuration of the system, and LAN screens.

Strona 569 - Appendix J

ZyWALL 2 Series User’s Guide Q-4 Index Inside Local Address ... 8-1 Internet Access...

Strona 570

ZyWALL 2 Series User’s Guide Index Q-5 N Nailed-up Connection ... 26-4 Nailed-Up Connection ...

Strona 571 - Part XVI:

ZyWALL 2 Series User’s Guide Q-6 Index Replacement ...v Reports...

Strona 572

ZyWALL 2 Series User’s Guide Index Q-7 System Management Terminal ... 21-2 System Name ...

Strona 573 - Command Interpreter

ZyWALL 2 Series User’s Guide Q-8 Index Wireless LAN Setup... 24-6 Wizard Setup ...

Strona 575 - Firewall Commands

ZyWALL 2 Series User’s Guide System 4-1 Chapter 4 System Screens This chapter provides information on the System screens. 4.1 System Overview See the

Strona 576 - Chart L-1 Firewall Commands

ZyWALL 2 Series User’s Guide 4-2 System Table 4-1 System General Setup LABEL DESCRIPTION System Name Choose a descriptive name for identification

Strona 577 - Firewall Commands L-3

ZyWALL 2 Series User’s Guide System 4-3 4.3 Dynamic DNS Dynamic DNS allows you to update your current dynamic IP address with one or many dynamic DNS

Strona 578 - L-4 Firewall Commands

ZyWALL 2 Series User’s Guide 4-4 System Figure 4-2 DDNS The following table describes the fields in this screen. Table 4-2 DDNS LABEL DESCRIPTION

Strona 579 - Firewall Commands L-5

ZyWALL 2 Series User’s Guide System 4-5 Table 4-2 DDNS LABEL DESCRIPTION Host Names 1~3 Enter the host names in the three fields provided. You can s

Strona 580 - L-6 Firewall Commands

ZyWALL 2 Series User’s Guide 4-6 System Figure 4-3 Password The following table describes the fields in this screen. Table 4-3 Password LABEL DESC

Strona 581 - NetBIOS Filter Commands

ZyWALL 2 Series User’s Guide System 4-7 Table 4-4 Default Time Servers ntp1.cs.wisc.edu ntp1.gbg.netnod.se ntp2.cs.wisc.edu tock.usno.navy.mil ntp3.c

Strona 582

ZyWALL 2 Series User’s Guide Table of Contents vii Table of Contents Copyright...

Strona 583 - Command:

ZyWALL 2 Series User’s Guide 4-8 System Figure 4-4 Time Setting The following table describes the fields in this screen. Table 4-5 Time Setting LA

Strona 584

ZyWALL 2 Series User’s Guide System 4-9 Table 4-5 Time Setting LABEL DESCRIPTION Time Server Address Enter the address of your time server. Check wit

Strona 586

ZyWALL 2 Series User’s Guide LAN 5-1 Chapter 5 LAN Screens This chapter describes how to configure LAN settings. 5.1 LAN Overview Local Area Network

Strona 587 - Log Descriptions

ZyWALL 2 Series User’s Guide 5-2 LAN three numbers specify the network number while the last number identifies an individual computer on that networ

Strona 588

ZyWALL 2 Series User’s Guide LAN 5-3 RIP Version controls the format and the broadcasting method of the RIP packets that the ZyWALL sends (it recogni

Strona 589

ZyWALL 2 Series User’s Guide 5-4 LAN Figure 5-1 IP The following table describes the fields in this screen. Table 5-1 IP LABEL DESCRIPTION DHCP Se

Strona 590

ZyWALL 2 Series User’s Guide LAN 5-5 Table 5-1 IP LABEL DESCRIPTION DHCP Server DHCP (Dynamic Host Configuration Protocol, RFC 2131 and RFC 2132) a

Strona 591

ZyWALL 2 Series User’s Guide 5-6 LAN Table 5-1 IP LABEL DESCRIPTION RIP Version The RIP Version field controls the format and the broadcasting meth

Strona 592

ZyWALL 2 Series User’s Guide LAN 5-7 Figure 5-2 Static DHCP The following table describes the fields in this screen. Table 5-2 Static DHCP LABEL DES

Strona 593

ZyWALL 2 Series User’s Guide viii Table of Contents 5.6 Configuring IP ...

Strona 594

ZyWALL 2 Series User’s Guide 5-8 LAN When you use IP alias, you can also configure firewall rules to control access between the LAN's logical n

Strona 595

ZyWALL 2 Series User’s Guide LAN 5-9 The following table describes the fields in this screen. Table 5-3 IP Alias LABEL DESCRIPTION IP Alias 1,2 Sele

Strona 597

WAN and Wireless LAN III Part III: WAN and Wireless LAN This part covers configuration of the WAN and Wireless LAN screens.

Strona 599 - Log Descriptions O-13

ZyWALL 2 Series User’s Guide WAN Screens 6-1 Chapter 6 WAN Screens This chapter describes how to configure WAN settings. 6.1 WAN Overview See the LA

Strona 600

ZyWALL 2 Series User’s Guide 6-2 WAN Screens Table 6-1 Private IP Address Ranges 10.0.0.0 - 10.255.255.255 172.16.0.0 - 172.31.255.255 192.168.0.0 -

Strona 601

ZyWALL 2 Series User’s Guide WAN Screens 6-3 Figure 6-1 WAN Setup: Route The following table describes the fields in this screen. Table 6-3 WAN Setu

Strona 602

ZyWALL 2 Series User’s Guide 6-4 WAN Screens Figure 6-2 Ethernet Encapsulation The following table describes the fields in this screen. Table 6-4 E

Strona 603 - Displaying Logs

ZyWALL 2 Series User’s Guide WAN Screens 6-5 Table 6-4 Ethernet Encapsulation LABEL DESCRIPTION Reset Click Reset to begin configuring this screen af

Strona 604

ZyWALL 2 Series User’s Guide Table of Contents ix 10.3 Introduction to ZyXEL’s Firewall...

Strona 605 - Protection

ZyWALL 2 Series User’s Guide 6-6 WAN Screens Figure 6-3 PPPoE Encapsulation The following table describes the fields in this screen. Table 6-5 PPPo

Strona 606

ZyWALL 2 Series User’s Guide WAN Screens 6-7 Table 6-5 PPPoE Encapsulation LABEL DESCRIPTION Password Type the password associated with the User Nam

Strona 607 - Appendix Q

ZyWALL 2 Series User’s Guide 6-8 WAN Screens Figure 6-4 PPTP Encapsulation The following table describes the fields in this screen. Table 6-6 PPTP

Strona 608

ZyWALL 2 Series User’s Guide WAN Screens 6-9 Table 6-6 PPTP Encapsulation LABEL DESCRIPTION User Name Type the user name given to you by your ISP.

Strona 609

ZyWALL 2 Series User’s Guide 6-10 WAN Screens Figure 6-5 IP Setup The following table describes the fields in this screen. Table 6-7 IP Setup LABEL

Strona 610

ZyWALL 2 Series User’s Guide WAN Screens 6-11 Table 6-7 IP Setup LABEL DESCRIPTION My WAN IP Address (or IP Address) Enter your WAN IP address in th

Strona 611

ZyWALL 2 Series User’s Guide 6-12 WAN Screens Table 6-7 IP Setup LABEL DESCRIPTION Private (PPPoE and PPTP only) This parameter determines if the Z

Strona 612

ZyWALL 2 Series User’s Guide WAN Screens 6-13 Table 6-7 IP Setup LABEL DESCRIPTION Windows Networking (NetBIOS over TCP/IP): Windows Networking (Net

Strona 613

ZyWALL 2 Series User’s Guide 6-14 WAN Screens The MAC address screen allows users to configure the WAN port's MAC Address by either using the f

Strona 614

ZyWALL 2 Series User’s Guide WAN Screens 6-15 Figure 6-8 Traffic Redirect LAN Setup 6.9 Configuring Traffic Redirect To change your ZyWALL’s Traffi

Komentarze do niniejszej Instrukcji

Brak uwag