Manuel d'utilisation / d'entretien du produit 2900 du fabricant Draytek
Aller à la page of 173
Vigor2900 Series Security Router User’s Guide Version: 2.0 Date: 2006/1/16 Copyright 2005 All rights reserve d. This publication contains information th at is protected by copyright.
Vigor2900 Series User’s Guide ii.
Vigor2900 Series User’s Guide iii T T a a b b l l e e o o f f C C o o n n t t e e n n t t s s 1 Pref ace ............................................................................................................... 1 1.1 LED Indicators and Connectors .
Vigor2900 Series User’s Guide iv 3.1 Dynamic DNS Setup .......................................................................................................... ... 53 3.2 Call Control and PPP/MP Setup ..............................................
Vigor2900 Series User’s Guide v 4.7.2 Triggered Dial- out Packet Header ................................................................................ 132 4.7.3 Viewing R outing Table ...............................................................
.
Vigor2900 Series User’s Guide 1 1 P P r r e e f f a a c c e e Targeting requirement for residential, SOHO (Small Office and Home Office) and business users, the Vigor2900 series provides ex ceptional bandwidth for Internet access.
Vigor2900 Series User’s Guide 2 1 1 . . 1 1 . . 1 1 F F r r o o n n t t a a n n d d R R e e a a r r V V i i e e w w f f o o r r V V i i g g o o r r 2 2 9 9 0 0 0 0 ACT DMZ QoS Attack VPN Printer W AN P1 P2 P3 P4 LAN LED Status Explanation ACT (Activity) Blinking The router is powered on and running properly.
Vigor2900 Series User’s Guide 3 1 1 . . 1 1 . . 2 2 F F r r o o n n t t a a n n d d R R e e a a r r V V i i e e w w f f o o r r V V i i g g o o r r 2 2 9 9 0 0 0 0 G G ACT QoS WLAN Attack VP N Printer WAN P1 P2 P3 P4 LAN LED Status Explanation ACT (Activity) Blinking The router is powered on and running properly.
Vigor2900 Series User’s Guide 4 1 1 . . 1 1 . . 3 3 F F r r o o n n t t a a n n d d R R e e a a r r V V i i e e w w f f o o r r V V i i g g o o r r 2 2 9 9 0 0 0 0 G G i i ACT ISDN WLAN Attack VPN Printer WAN P1 P2 P3 P4 LAN LED Status Explanation ACT (Activity) Blinking The router is powered on and running properly.
Vigor2900 Series User’s Guide 5 1 1 . . 1 1 . . 4 4 F F r r o o n n t t a a n n d d R R e e a a r r V V i i e e w w f f o o r r V V i i g g o o r r 2 2 9 9 0 0 0 0 i i ACT ISDN QoS Attack VPN Printer W AN P1 P2 P3 P4 LAN LED Status Explanation ACT (Activity) Blinking The router is powered on and running properly.
Vigor2900 Series User’s Guide 6 1 1 . . 1 1 . . 5 5 F F r r o o n n t t a a n n d d R R e e a a r r V V i i e e w w f f o o r r V V i i g g o o r r 2 2 9 9 0 0 0 0 V V LED Status Explanation ACT (Activity) Blinking The router is powered on and running properly.
Vigor2900 Series User’s Guide 7 1 1 . . 1 1 . . 6 6 F F r r o o n n t t a a n n d d R R e e a a r r V V i i e e w w f f o o r r V V i i g g o o r r 2 2 9 9 0 0 0 0 V V G G LED Status Explanation ACT (Activity) Blinking The router is powered on and running properly.
Vigor2900 Series User’s Guide 8 1 1 . . 1 1 . . 7 7 F F r r o o n n t t a a n n d d R R e e a a r r V V i i e e w w f f o o r r V V i i g g o o r r 2 2 9 9 0 0 0 0 V V G G i i LED Status Explanation ACT (Activity) Blinking The router is powered on and running properly.
Vigor2900 Series User’s Guide 9 1 1 . . 1 1 . . 8 8 F F r r o o n n t t a a n n d d R R e e a a r r V V i i e e w w f f o o r r V V i i g g o o r r 2 2 9 9 0 0 0 0 V V i i LED Status Explanation ACT (Activity) Blinking The router is powered on and running properly.
Vigor2900 Series User’s Guide 10 1 1 . . 2 2 H H a a r r d d w w a a r r e e I I n n s s t t a a l l l l a a t t i i o o n n Before starting to configure the router, you have to connect your devices correctly. 1. Connect this device to a router with an Ethernet cable.
Vigor2900 Series User’s Guide 11 2 C C o o n n f f i i g g u u r r i i n n g g B B a a s s i i c c S S e e t t t t i i n n g g s s For use the router properly, it is necessary for you to change the password of web configuration for security and adjust primary basic settings.
Vigor2900 Series User’s Guide 12 Notice: Some of the settings might not appear as above, because the hom e page will change slightly according to the featur es that your router has. 4. Click Administrator Password Setup from the Basic Setup group. 5.
Vigor2900 Series User’s Guide 13 2 2 . . 2 2 Q Q u u i i c c k k S S t t a a r r t t W W i i z z a a r r d d If your router can be under an environment with high speed NAT, the configuration provide here can help you to deploy and use the router quickl y.
Vigor2900 Series User’s Guide 14 Please select the appropriate time zone for the router. Then, click Next . 2 2 . . 2 2 . . 1 1 S S e e l l e e c c t t i i n n g g P P r r o o t t o o c c o o l l In.
Vigor2900 Series User’s Guide 15 PPPoE is used for most of DSL modem users. All local users can share one PPPoE connection for accessing the Internet. Your service provider will provide you information about user name, password, and authentication mode.
Vigor2900 Series User’s Guide 16 2 2 . . 2 2 . . 3 3 P P P P T T P P For PPTP connection, please click PPTP as the protocol. Click Next to see the following page. User Name Assign a specific valid user name provided by the ISP. Password Assign a valid password provided by the ISP.
Vigor2900 Series User’s Guide 17 PPTP Server IP Specify the IP address of the PPTP Server. After finishing the settings in this page, click Next to see the following page.
Vigor2900 Series User’s Guide 18 2 2 . . 2 2 . . 4 4 L L 2 2 T T P P Note: This setting is available only for Vigor 2900, Vigor 2900G, Vigor 2900Gi and Vigor 2900i . Click L2TP as the protocol. Click Next to see the following page. User Name Assign a specific valid user name provided by the ISP.
Vigor2900 Series User’s Guide 19 Subnet Mask Type the subnet mask. PPTP Server IP Specify the IP address of the PPTP Server. After finishing the settings in this page, click Next to see the following page. Click Finish to save current settings and restart the router.
Vigor2900 Series User’s Guide 20 Click Next to see the following page. WAN IP Type the WAN IP address that obtained from ISP. Subnet Mask Type the subnet mask obtained from ISP. Gateway Type the gateway address obtained from ISP. Primary DNS Type the IP address as the primary DNS obtained from ISP.
Vigor2900 Series User’s Guide 21 2 2 . . 2 2 . . 6 6 D D H H C C P P Click DHCP as the protocol. Click Next to see the following page. Host Name Specify the host name for the router. MAC This is an optional setting. The router will detect the MAC address automatically.
Vigor2900 Series User’s Guide 22 Click Finish to save current settings and restart the router. 2 2 . . 3 3 L L A A N N T T C C P P / / I I P P a a n n d d D D H H C C P P S S e e r r v v e e r r B B a a s s i i c c s s o o f f L L A A N N The most generic function of V igor router is NA T .
Vigor2900 Series User’s Guide 23 will serve for IP routing to help hosts in th e public subnet to communicate with other public hosts or servers outside.
Vigor2900 Series User’s Guide 24 W W h h a a t t a a r r e e V V i i r r t t u u a a l l L L A A N N s s Y ou can group local hosts by physical ports and create up to 4 virtual LANs. T o manage the communication between different groups, please set up rules in V irtual LAN (VLAN) function and the rate of each.
Vigor2900 Series User’s Guide 25 2 nd DHCP Se rver Y ou can configure the router to serve as a DHCP server for the 2nd subnet. S tart IP Address: Enter a value of the IP address pool for the DHCP server to start with when issuing IP addresses. If the 2nd IP address of your router is 220.
Vigor2900 Series User’s Guide 26 DHCP server for your network. If you want to use another DHCP server in the network other than the V igor Router ’ s, you can let Relay Agent help you to redirect the DHCP request to the specified location. Enable Server - Let the router assign IP address to every host in the LAN.
Vigor2900 Series User’s Guide 27 2 2 . . 4 4 I I S S D D N N S S e e t t u u p p ISDN stands for Integrated Services Digital Netw ork. It is an international communications standard for sending voice, video, and data over digit al telephone lines or normal telephone wires.
Vigor2900 Series User’s Guide 28 which can simulate a real ISDN terminal adapter installed on your computer. You can install the CAPI-compliant software for dial-up netw orking, fax or voice applications de pending on the functionality of the CAPI software you installed.
Vigor2900 Series User’s Guide 29 S S e e c c u u r r i i t t y y O O v v e e r r v v i i e e w w Real-time Hardware Encryption: Vigor Router is equipped with a hardware AES encryptio n engine so it can apply the highest prote ction to your data without influencing user experience.
Vigor2900 Series User’s Guide 30 Example 3 Separate the Wireless and the Wired LAN- WLAN Isolation enables you to isolate your wireless LAN from wired LAN for either quaran tine or limit access reasons. To isolate means neither of the parties can access each other.
Vigor2900 Series User’s Guide 31 2 2 . . 5 5 . . 2 2 G G e e n n e e r r a a l l S S e e t t t t i i n n g g s s By clicking the General Settings , a new web page will appear so that you could configure the SSID and the wireless channel. Please refer to the following figure for more information.
Vigor2900 Series User’s Guide 32 LAN. SSID can be any text numbers or various special characters. Channel The channel of frequency of the wireless LAN. The default channel is 6. You may switch channel if the selected channel is under serious interference.
Vigor2900 Series User’s Guide 33 2 2 . . 5 5 . . 3 3 S S e e c c u u r r i i t t y y By clicking the Security Settings , a new web page will appear so that you could configure the settings of WEP and WPA. Mode There are several modes provided for you to choose.
Vigor2900 Series User’s Guide 34 applicable if you select WPA/PSK. WEP/802.1x or WPA/802.1x - Accept WEP or WPA clients with 802.1x authentication. Only Mixed(WPA+WPA2) is applicable if you select WPA/PSK. Since the key will be auto-negotiated during authentication, the field of key setting below will be not available for input.
Vigor2900 Series User’s Guide 35 All wireless devices must support the same WEP encryption bit size and have the same key . Four keys can be entered here, but only one key can be selected at a time. The keys can be entered in ASCII or Hexadeci mal. Check the key you wish to use.
Vigor2900 Series User’s Guide 36 Client’s MAC Address - Manually enter the MAC address of wireless client. Attribute v - select to apply VPN to the connection of the wireless client of the MAC address. s - select to isolate the wireless connection of the wireless client of the MAC address from LAN.
Vigor2900 Series User’s Guide 37 2 2 . . 6 6 I I n n t t e e r r n n e e t t A A c c c c e e s s s s S S e e t t u u p p Quick Start Wizard offers user an easy method to quick setup the connection mode for the router.
Vigor2900 Series User’s Guide 38 If your router supports ISDN function, you w ill get the following page with ISDN dial-up Internet Access. The following sections will introd uce the Internet Access Modes.
Vigor2900 Series User’s Guide 39 PPPoE Link Click Enable for activating this function. If you click Disable , thi s function will be closed and all the settings that you adjusted in this page will be invalid. ISP Name Type in the ISP Name provided by ISP in this field.
Vigor2900 Series User’s Guide 40 By checking the checkbox Join NAT IP Pool , data from NAT hosts will be round-robin forwarded on a session basis. If you do not check Join NAT IP Pool , you can stil.
Vigor2900 Series User’s Guide 41 IP addresses for other purpose, su ch as DMZ host, Open Ports. WAN physical type Check and choose a proper type used for duplex between this device and other router that you want to comm unicate. Both sides should use the same physical type; otherwise, the connection might be failed due to inconsistent type.
Vigor2900 Series User’s Guide 42 Access Control Click Enable for activating this function. If you click Disable , thi s function will be closed and all the settings that you adjusted in this page will be invalid. ISDN Dial Backup Setup This setting is available for the routers supporting ISDN function only.
Vigor2900 Series User’s Guide 43 PING Interval - Enter the interval for the system to execute the PING operation. WAN physical type Check and choose a proper type used for duplex between this device and other router that you want to communicate.
Vigor2900 Series User’s Guide 44 Specify an IP address – Click this radio button to specify some data if you want to use Static IP m ode. IP Address – Type the IP address. Subnet Mask – Type the subnet mask. Gateway IP Address – Type the gateway IP address.
Vigor2900 Series User’s Guide 45 PPTP Setup PPTP Link - Click Enable to enable a PPTP client to establish a tunnel to a DSL modem on the WAN interface. PPTP Server - Specify the IP address of the PPTP server. ISP Access Setup ISP Name - Type in the ISP Name provided by ISP in this field.
Vigor2900 Series User’s Guide 46 Idle Timeout - Set the timeout for breaking down the Internet after passing through the time without any action. IP Address Assignment Method(IPCP) Fixed IP - Usually ISP dynamically assigns IP address to you each time you connect to it and request.
Vigor2900 Series User’s Guide 47 L2TP Setup L2TP Link - Click Enable to enable a L2TP client to establish a tunnel to a DSL modem on the WAN interface. L2TP Server - Specify the IP address of the L2TP server. ISP Access Setup ISP Name - Type in the ISP Name provided by ISP in this field.
Vigor2900 Series User’s Guide 48 use the same physical type; otherwise, the connection might be failed due to inconsistent type. It is recommended for you to set Auto negotiation as the physical type.
Vigor2900 Series User’s Guide 49 Idle Timeout Idle timeout means the ro uter will be disconnect after being idle for a preset amount of time. The default is 180 seconds. If you set the time to 0, the ISDN connection to the ISP will always remain on.
Vigor2900 Series User’s Guide 50 z The V irtual T A client onl y supports the CAPI 2.0 protocol and has no built-in F AX engine. z One ISDN BRI interface has two B channels. The maximum number of active clients is also two. z Before you configure the V irtual T A, you must set the correct country code.
Vigor2900 Series User’s Guide 51 V irtual T A S erver Enable: Select it to activate the server . Disable: Select it to deactivate the server . All V irtual T A applications will be terminated. Username Enter the username of a specific client. Password Enter the password of a specific client.
Vigor2900 Series User’s Guide 52 On the client - Right-click the mouse on the VT icon. The following pop-up menu will be shown. Click the V irtual T A Login tab to launch the login box. Enter the Username/Password and then click OK . Aft er a short time, the VT icon text will turn green.
Vigor2900 Series User’s Guide 53 3 A A d d v v a a n n c c e e d d W W e e b b C C o o n n f f i i g g u u r r a a t t i i o o n n After finished basic configuration of the router, you can access Internet with ease.
Vigor2900 Series User’s Guide 54 Active Display if this account is active or inactive. View Log It opens another dialog and shows log for DDNS information. Force Update Click this button to get the newest DDNS inform ation. 3. Select Index number 1 to add an account for the router.
Vigor2900 Series User’s Guide 55 3 3 . . 2 2 C C a a l l l l C C o o n n t t r r o o l l a a n n d d P P P P P P / / M M P P S S e e t t u u p p Some applications require that the router (only for the i m odels) be remotely activated, or be able to dial up to the ISP via the ISDN inte rface.
Vigor2900 Series User’s Guide 56 PPP Authentication It specifies the PPP authentication method for PPP/MP connections. Normally you can set it to PA P / C H A P f or better compatibility . TCP Header Compression VJ Compr es sion - It is used for TCP/IP protocol header compression.
Vigor2900 Series User’s Guide 57 Index Click the num ber below Index to access into the setting page of schedule. Status Display if this schedule setting is active or inactive. You can set up to 15 schedules. Then you can apply them to your Internet Acce ss or VPN and Remote Access >> LAN-to-LAN settings.
Vigor2900 Series User’s Guide 58 Disable Dial-On-Demand - Specify the connection to be up when it has traffic on the line. Once there is no traffic over idle timeout, the connection will be down and never up again durin g the schedule. Idle Timeout Specify the duration (or period) for the schedule.
Vigor2900 Series User’s Guide 59 On NAT page, you will see the private IP address defined in RFC-1918. Usually we use the 192.168.1.0/24 subnet for the router. As stated before, the NAT facility can map one or more IP addresses and/or servi ce por ts into different specified services.
Vigor2900 Series User’s Guide 60 Service Name Enter the description of the specific network service. Protocol Select the transport layer protocol (TCP or UDP). Public Port Specify which port can be redirected to the specified Private IP and Port of the internal host.
Vigor2900 Series User’s Guide 61 3 3 . . 4 4 . . 2 2 D D M M Z Z H H o o s s t t S S e e t t u u p p As mentioned above, Port Redirection can redirect incoming TCP/UDP or othe r traffic on particular ports to the specific private IP address/port of host in the LAN.
Vigor2900 Series User’s Guide 62 Enable Check to enable the DMZ Host function. Private IP Enter the private IP address of the DMZ host, or click Choose PC to select one. Choose PC Click this button and then a window will autom atically pop up, as depicted below.
Vigor2900 Series User’s Guide 63 Index Indicate the relative number for the particular entry that you want to offer service in a local host. You should click the appropriate index number to edit or clear the corresponding entry. Comment Specify the name for the defined network service.
Vigor2900 Series User’s Guide 64 However, if you previously have set up WAN Alias in Internet Access>>PPPoE, you will find that WAN IP appeared for your selection. Enable Open Ports Check to enable this entry. Comment Make a name for the defined network application/service.
Vigor2900 Series User’s Guide 65 3 3 . . 4 4 . . 4 4 V V i i e e w w W W e e l l l l - - K K n n o o w w n n P P o o r r t t s s L L i i s s t t There is a list providing some well-known port numbers of certain services/applications for your reference.
Vigor2900 Series User’s Guide 66 When you press the WAN IP Alias button, a window will show up for you to in put other public IP addresses. The Join NAT IP Pool check box indicates that the local users can use this IP to connect to the Internet. If you do not ch ick this check box, this IP addre ss will not be available to the local users.
Vigor2900 Series User’s Guide 67 3 3 . . 5 5 R R A A D D I I U U S S S S e e t t u u p p Remote Authentication Dial-In User Servi ce (RADIUS) is a security authentication client/server protocol that supports authenti cation, authorization and accounting, which is widely used by Internet service providers.
Vigor2900 Series User’s Guide 68 Shared Secret The RADIUS server and client share a secret that is used to authenticate the messages sent be tween them. Both sides must be configured to use the same shared secret. Re-type Shared Secret Re-type the Shared Secret for confirmation.
Vigor2900 Series User’s Guide 69 is that those hosts on the intern al private subnets (ex. 192.168.10.0/24) can access the Internet via the router , and continuously exchange of IP routing information with dif ferent subnets. 2. Click Index Number 1 from the S tatic Route Configuration page.
Vigor2900 Series User’s Guide 70 D D e e l l e e t t e e S S t t a a t t i i c c R R o o u u t t e e 1. Click the Index Number that you want to delete from the S tatic Route Configuration page. 2. Select Empty/Clear from the drop-down menu, and then click the OK button to delete the route.
Vigor2900 Series User’s Guide 71 D D e e a a c c t t i i v v a a t t e e S S t t a a t t i i c c R R o o u u t t e e 1. Click the Index Number that you want to disable from the S tatic Route Configuration page. 2. Select Inactive/Disable from the drop-down menu, and then click the OK button to delete the route.
Vigor2900 Series User’s Guide 72 3 3 . . 7 7 I I P P F F i i l l t t e e r r / / F F i i r r e e w w a a l l l l S S e e t t u u p p 3 3 . . 7 7 . . 1 1 B B a a s s i i c c s s f f o o r r F F i i r.
Vigor2900 Series User’s Guide 73 z Data Filter - When there is an existing Internet connection, Data Filter is applied to incoming and outgoing traffic. It will check pack ets according to t he filter rules. If legal, the packet will pass the router.
Vigor2900 Series User’s Guide 74 D D e e n n i i a a l l o o f f S S e e r r v v i i c c e e ( ( D D o o S S ) ) D D e e f f e e n n s s e e The DoS Defense functionality helps you to detect and mitigate the DoS attack. The attacks are usually categorized into two types, the fl ooding-type attacks and the vulnerability attacks.
Vigor2900 Series User’s Guide 75 W W e e b b C C o o n n t t e e n n t t F F i i l l t t e e r r ( ( f f o o r r V V m m o o d d e e l l s s o o n n l l y y ) ) We all know that the content on the Internet just like other types of media may be inappropriate sometimes.
Vigor2900 Series User’s Guide 76 Filter Rule Click a button numbered (1 ~ 7) to ed it the filter rule. Click the button will open Edit Filter Rule web page. For the detailed information, refer to the following page. Active Enable or disable the filter rule.
Vigor2900 Series User’s Guide 77 Pass or Block Specifies the action to be taken when packets match the rule. Block Immediately - Packets matching the rule will be dropped immediately. Pass Immediately - Packets matching the rule will be passed immediately.
Vigor2900 Series User’s Guide 78 Don’t care - No action will be taken towards fragmented packets. Unfragmented - Apply the rule to unfragmented packets. Fragmented - Apply the rule to fragmented packets. Too Short - Apply the rule only to packets that are too short to contain a complete header.
Vigor2900 Series User’s Guide 79 E E x x a a m m p p l l e e o o f f R R e e s s t t r r i i c c t t i i n n g g U U n n a a u u t t h h o o r r i i z z e e d d I I n n t t e e r r n n e e t t S S e.
Vigor2900 Series User’s Guide 80 Call Filter Check Enable to activate the Call Filter function. Assign a start filter set for the Call Filter. Data Filter Check Enable to activate the Data Filter function. Assign a start filter set for the Data Filter.
Vigor2900 Series User’s Guide 81 Active Check this box to invoke th is setting. MAC Address Type in the MAC Address of the device that the router connects to. Pass Scheduler (1..15) Let the device with the specific MAC address to be passed within certain time interval only.
Vigor2900 Series User’s Guide 82 Enable Dos Defense Check the box to activate the DoS Defense Functionality. Enable SYN flood defense Check the box to activate the SYN flood defense function.
Vigor2900 Series User’s Guide 83 header. The reason for limitation is IP option appears to be a vulnerability of the security for the LAN because it will carry significant information, such as security, TCC (closed user group) parameters, a series of Internet addresses, routing messages.
Vigor2900 Series User’s Guide 84 the protocol types greater than 100 are reserved and undefined at this time. Therefore, the router should have ability to detect and reject this kind of packets. Warning Messages We provide Syslog function for user to retrieve message from Vigor router.
Vigor2900 Series User’s Guide 85 Enable URL Access Control Check the box to activate URL Access Control. Block websites with matching keywords Click this button to restrict accessing into the corresponding webpage with the keywords listed on the box below.
Vigor2900 Series User’s Guide 86 Prevent web access from IP address Check the box to deny any web surfing activity using IP address, such as http://202.
Vigor2900 Series User’s Guide 87 3 3 . . 7 7 . . 6 6 W W e e b b C C o o n n t t e e n n t t F F i i l l t t e e r r ( ( f f o o r r V V m m o o d d e e l l s s o o n n l l y y ) ) Choose IP Filter/Firewall Setup on the Advanced Setup group and click the Web Content Filter link.
Vigor2900 Series User’s Guide 88 3 3 . . 7 7 . . 7 7 I I M M B B l l o o c c k k i i n n g g IM Blocking means instant messenger blocki ng. You will see a list of common IM (such as MSN, Yahoo, ICQ/AQL) applications. Check Enable IM Blocking and select the one(s) that you want to block.
Vigor2900 Series User’s Guide 89 Action Specify the action for each protocol. Allow – Allow the client to access into th e application through the specified protocol. Disallow – Forbid the client to access into the application through the specified protocol.
Vigor2900 Series User’s Guide 90 3 3 . . 8 8 V V P P N N a a n n d d R R e e m m o o t t e e A A c c c c e e s s s s S S e e t t u u p p A Virtual Private Network (VPN) is the extension of a private network that encompasses links across shared or public networks like the Intern et.
Vigor2900 Series User’s Guide 91 Dial-In PPP Authentication PAP Only - Select this option to force the router to authenticate dial-in users with the PAP protocol. PAP or CHAP - Selecting this option means the router will attempt to authenticate dial-in users with the CHAP protocol first.
Vigor2900 Series User’s Guide 92 3 3 . . 8 8 . . 3 3 V V P P N N I I K K E E / / I I P P S S e e c c G G e e n n e e r r a a l l S S e e t t u u p p In IPSec General Setup, there are two major parts of configuration.
Vigor2900 Series User’s Guide 93 (data) will be encrypted and authenticated. You may select encryption algorithm from Data Encryption Standard (DES), Triple DES (3DES), and AES.
Vigor2900 Series User’s Guide 94 Enable this account Check the box to enable this function. Idle Timeout- If the dial-in user is idle over the limitation of the timer, the router will drop this connection. By default, the Idle Timeout is set to 300 seconds.
Vigor2900 Series User’s Guide 95 IKE Pre-Shared Key Check the box of Pre-Shared Key to invoke this function and type in the required characters (1-63) as the pre-shared key. IPSec Security Method This group of fields is a must for IPSec Tunnels and L2TP with IPSec Policy when you specify the remote node.
Vigor2900 Series User’s Guide 96 Click to clear all indexes. Name Indicate the name of the LAN-to-LAN profile. The symbol ??? represents that the profile is empty Status Indicate the status of individual profiles. The symbol V and X represent the profile to be active and inactive, respectively.
Vigor2900 Series User’s Guide 97 Profile Name Specify a name for the profile of the LAN-to-LAN connection. Enable this profile Check here to activate this profile. Call Direction Specify the allowed call direction of this LAN-to-LAN profile. Both :-initiator/responder Dial-Out - initiator only Dial-In- responder only.
Vigor2900 Series User’s Guide 98 User Name This field is applicable when you select PPTP or L2TP w/ or w/out IPSec policy above. Password This field is applicable when you select PPTP or L2TP w/ or w/out IPSec policy above. PPP Authentication This field is applicable when you select PPTP or L2TP w/ or w/out IPSec policy above.
Vigor2900 Series User’s Guide 99 Main mode. IKE phase 1 proposal- To propose the local available authentication schemes and encryption algorithms to the VPN peers, and get its feedback to find a match. Two combinations are available for Aggressive mode and nine for Main mode.
Vigor2900 Series User’s Guide 100 Allowed Dial-In Type Determine the dial-in connection with different types. ISDN Allow the remote ISDN dial-in connection. You can further set up Callback function below. You should set the User Name and Password of remote dial-in user below.
Vigor2900 Series User’s Guide 101 methods on the right side. If you uncheck the checkbox , the connection type you select above will apply the authentication methods and security methods in the general settings. User Name This field is applicable when you select PPTP or L2TP w/ or w/out IPSec policy above.
Vigor2900 Series User’s Guide 102 phase. If the PPP IP address is fixed by remote side, specify the fixed IP address here. Remote Network IP/ Remote Network Mask Add a static router to direct all traffic destined to this Remote Network IP Address/ Remote Network Mask through the VPN connection.
Vigor2900 Series User’s Guide 103 your applications to operate. This has to manually set up port mappings or use other similar methods. The screenshots below show examples of this facility . The UPnP facility on the router enables UPnP aware applications such as MSN Messenger to discover what are behind a NA T router .
Vigor2900 Series User’s Guide 104 ¾ Some Microsoft operating systems ha ve found out the UPnP weaknesses and hence you need to ensure that you have applied the latest service packs and patches. ¾ Non-privileged users can control some router functions, including removing and adding port mappings.
Vigor2900 Series User’s Guide 105 The major benefit of this mode is that you don ’t have to memorize your friend’s IP address, which might change very frequently if it’s dynamic. Instead of that, you will only have to using dial plan or directly dial your friend’s account name if you are with the same SIP Registrar.
Vigor2900 Series User’s Guide 106 3 3 . . 1 1 0 0 . . 1 1 D D i i a a l l P P l l a a n n S S e e t t u u p p In this section, you can set your VoIP contacts in the “phonebook” we called DialPlan - help you to make calls quickly and easily by using “speed-dial” Phone Number .
Vigor2900 Series User’s Guide 107 3 3 . . 1 1 0 0 . . 2 2 S S I I P P R R e e l l a a t t e e d d F F u u n n c c t t i i o o n n s s S S e e t t u u p p In this section, you set up your own SIP setti ngs. When you apply for an account, your SIP service provider will give you an Account Name or user name, SIP Registrar, Proxy, and Domain name .
Vigor2900 Series User’s Guide 108 choose None and check the box to achieve the goal. Some SIP server allows user to use VoIP function without registering. For such server, please check the box of make call without register . Choosing Auto is recommended.
Vigor2900 Series User’s Guide 109 3 3 . . 1 1 0 0 . . 3 3 C C O O D D E E C C / / R R T T P P / / D D T T M M F F S S e e t t u u p p The codec used for each call can be negotiated with the peer party before each session. Mic/Speaker Gain Adjust the volume of micropho ne and speaker by entering number from 1- 10.
Vigor2900 Series User’s Guide 110 will contains 20 ms voice information. The more data contains in a single packet the less overhead it creates but may increase. Voice Active Detector Choose On to enable this function to de tect if the user is talking or not.
Vigor2900 Series User’s Guide 111 Dial Tone Power Level This setting is used to adjust th e loudness of the dial tone. The smaller the number is, the louder the dial tone is. It is recommended for you to use the default setting. Ring Frequency This setting is used to drive the frequency of the ring tone.
Vigor2900 Series User’s Guide 112 supports, please use the default setting. 3 3 . . 1 1 0 0 . . 5 5 V V o o i i c c e e C C a a l l l l S S t t a a t t u u s s On VoIP call status, you can find codec, connection and other important call status for both VoIP 1 and 2 ports.
Vigor2900 Series User’s Guide 113 Rx Pkts Total number of received voice packets during this connection session. Rx Losts Total number of lost packets during this connection session. Rx Jitter The jitter of received voice packets. In Calls The accumulating in-call times.
Vigor2900 Series User’s Guide 114 Enable Check this box to enable this function (for VLAN Configuration). P1 – P4 Check the box to make the com puter connecting to the port being grouped in specified VLAN. Be aware that each port can be grouped in different VLAN at the same time only if you check the box.
Vigor2900 Series User’s Guide 115 3. T o remove VLAN, uncheck the needed box and click OK to save the results. 3 3 . . 1 1 2 2 Q Q o o S S C C o o n n t t r r o o l l S S e e t t u u p p Deploying Q.
Vigor2900 Series User’s Guide 116 Vigor routers as edge routers of DS domain shall check the marked DSCP value in the IP header of bypassing traffic, thus to allocate certain amount of resource execute appropriate policing, classification or scheduling.
Vigor2900 Series User’s Guide 117 Reserved Bandwidth Ratio It is reserved for the group index in the form of ratio of reserved bandwidth to upstream speed and reserve d bandwidth to downstream speed . Setup There are two-level of settings: Basic - setup Reserved Bandwidth Ratio according to the traffic service type.
Vigor2900 Series User’s Guide 118 level type by the system. Please assign one of the levels of the data for processing with QoS control. Service Type – It determines the service type of the data for processing with QoS control. It can also be edited.
Vigor2900 Series User’s Guide 119 Please type in the service name, select Service typ e (TCP/UDP and both). Next choose either one of the port confi guration type (Single or Range) and type in the range for the Port Number . Enable UDP Bandwidth Control Check this and set the limited bandwidth ratio on the right field.
Vigor2900 Series User’s Guide 120 This page is left blank..
Vigor2900 Series User’s Guide 121 4 S S y y s s t t e e m m M M a a n n a a g g e e m m e e n n t t 4 4 . . 1 1 O O n n l l i i n n e e S S t t a a t t u u s s The Online Status provides basic network settings of Vigor router. It includes LAN and WAN interface information.
Vigor2900 Series User’s Guide 122 VPN Displays the VPN connection name. Type Displays the VPN connection type. Remote IP Displays the remote IP of VPN connection. Virtual Network Displays the IP address and subnet mask of virtual network. Tx Pkts Displays the total transmitted packets.
Vigor2900 Series User’s Guide 123 2. Click Backup button to get into the following dialog. 3. Click Save button to open another dialog for saving configuration as a file. In Save As dialog, the default filename is config.cfg . You could gi ve it another name by yourself.
Vigor2900 Series User’s Guide 124 4. Click Save button, the configuration will download a utomatically to your computer as a file named config.cfg . The above example is using W indows platform for demonstrating examples. The Mac or Linux platform will appear dif ferent windows, but the backup function is still available.
Vigor2900 Series User’s Guide 125 R R e e s s t t o o r r e e C C o o n n f f i i g g u u r r a a t t i i o o n n 1. Click Configuration Backup/Restoration on the System Management group. The following window will be popped-up. 2. Click Browse button to choose the correct configura tion file for uploading to the r outer.
Vigor2900 Series User’s Guide 126 4 4 . . 4 4 S S y y s s L L o o g g / / M M a a i i l l A A l l e e r r t t S S e e t t u u p p SysLog is a popular utility in Unix world. To monitor router activity, you can run a SysLog Daemon to capture all activities from the router.
Vigor2900 Series User’s Guide 127 3. From the Syslog screen, select the router you want to monitor. Be reminded that in Network Information , select the network adapter used to connect to the router. Otherwise, you won’t succeed in retrieving information from the router.
Vigor2900 Series User’s Guide 128 The Vigor router will send many types of SysLog messages. Some examples of the SysLog messages with their individual formats are shown below.
Vigor2900 Series User’s Guide 129 4 4 . . 5 5 T T i i m m e e S S e e t t u u p p It allows you to specify where the time of the router should be inquired from.
Vigor2900 Series User’s Guide 130 4 4 . . 6 6 M M a a n n a a g g e e m m e e n n t t S S e e t t u u p p The port number used to send/receive SIP messag e for building a session. The default value is 5060 and this must match with the peer Registrar when making VoIP calls.
Vigor2900 Series User’s Guide 131 Trap Community Set trap comm unity by typing a proper name. The default setting is public. Notification Host IP Set the IP address of the host that will receive the trap community. Trap Timeout The default setting is 10 seconds.
Vigor2900 Series User’s Guide 132 Dial ISDN Clicking here causes the router to dial to the preset ISP. Click Internet Access Setup > Dial to a Single ISP to configure dial-up settings. Activity Display the connection name for each B channel. If the B channel is idle, it will show Idle .
Vigor2900 Series User’s Guide 133 Click it to reload the page. In the left of each routing rule, you will see a key. These keys are defined as follows. C --- Directly connected. S --- Static route. R --- RIP. * --- Default route. ~ --- Routes for private routing domain.
Vigor2900 Series User’s Guide 134 Click it to clear the whole table. 4 4 . . 7 7 . . 5 5 V V i i e e w w i i n n g g D D H H C C P P A A s s s s i i g g n n e e d d I I P P A A d d d d r r e e s s s s e e s s The facility provides information on IP address as signments.
Vigor2900 Series User’s Guide 135 Click it to reload the page. Each line across the screen indicat es an active session. The following information is displayed: Private IP:Port The internal user’s (PC’s) IP address and port number. #Pseudo Port The public port number.
Vigor2900 Series User’s Guide 136 4 4 . . 9 9 F F i i r r m m w w a a r r e e U U p p g g r r a a d d e e ( ( T T F F T T P P S S e e r r v v e e r r ) ) Before upgrading your router firmware, you need to i n stall the Router Tools. The Firmware Upgrade Utility is included in the tools.
Vigor2900 Series User’s Guide 137 5 A A p p p p l l i i c c a a t t i i o o n n a a n n d d E E x x a a m m p p l l e e s s 5 5 . . 1 1 C C r r e e a a t t e e a a L L A A N N - - t t o o - - L L A .
Vigor2900 Series User’s Guide 138 4. For using PPP based services, such as PPTP, L2TP, you have to set general settings in PPP General Setup . For using IPSec -based service, such as IPSec or L2TP with IPSec Policy, you have to set general settings in IPSec General Setup , such as the pre-shared key that both parties have known.
Vigor2900 Series User’s Guide 139 6. Set Common Settings as shown below. You should enable this pr ofile. 7. Set Dial-Out Settings as shown below to dial to connect to Router B aggressively with the selected Dial-Out method.
Vigor2900 Series User’s Guide 140 8. Set Dial-In settings as shown below to allow Router B dial-in to build VPN connection. If an IPSec-based service i s sele cted, y ou may further specify the remote peer IP Address, IKE Authentication Method and I PSec Security Method for this Dial-In connection.
Vigor2900 Series User’s Guide 141 Settings in Router B in the remote office: 1. Choose VPN and Remote Acce ss Setup on the Advanced Setup group . 2. Select R emot e Access Control Setup . The following page will appear. Enable the necessary VPN service and click OK .
Vigor2900 Series User’s Guide 142 5. Return to VPN and Remote Access Set u p page and choose LAN-to-LAN Profile Setup. Click on one index number to edit a profile. 6. Set Common Settings as shown below. You should enable both of VPN connections because any one of the parties may start the VPN connection.
Vigor2900 Series User’s Guide 143 If a PPP-based service is selected, y ou should further specify the remote peer IP Address, Username, Password, PPP Authentication and VJ Compression for this Dial-Out connection. 8. Set Dial-In settings as shown below to allow Router A dial-in to build VPN connection.
Vigor2900 Series User’s Guide 144 If a PPP-based service is selected, y ou should further specify the remote peer IP Address, Username, Password, and VJ Compression for this Dial-In connection.
Vigor2900 Series User’s Guide 145 5 5 . . 2 2 C C r r e e a a t t e e a a R R e e m m o o t t e e D D i i a a l l - - i i n n U U s s e e r r C C o o n n n n e e c c t t i i o o n n B B e e t t w w .
Vigor2900 Series User’s Guide 146 For using IPSec-based service, such as IPSec or L2TP with IPSec Policy, you have to set general settings in IKE/IPSec General Setup , such as the pre-shar ed key that both parties have known. 5. Return to VPN and Remote Access Set u p page and choose Remote User Profile Setup (Teleworker).
Vigor2900 Series User’s Guide 147 connection. Otherwise, it will apply the settings defined in IPSec General Setup above. If a PPP-based service is selected, y ou should further specify the remote peer IP Address, Username, Password, and VJ Compression for this Dial-In connection.
Vigor2900 Series User’s Guide 148 3. In Step 2. Connect to VPN Server , click Insert button to add a new entry. If an IPSec-based service is selected as shown below, You may further specify the method you use to get IP, the security method, and authentication method.
Vigor2900 Series User’s Guide 149 If a PPP-based service is selected, you should fu rther specify the remote VPN server IP address, Username, Password, and encryption method. The User Name and Password should be consistent with the one set up in the VPN router.
Vigor2900 Series User’s Guide 150 5 5 . . 3 3 Q Q o o S S S S e e t t t t i i n n g g E E x x a a m m p p l l e e Assume a teleworker someti mes works at hom e and takes care of children.
Vigor2900 Series User’s Guide 151 7. If the worker has connected to the headqua ter using host to host VPN tunnel. (Please refer to Chapter 3 VPN for detail instruction), he m ay set up an index for it. Enter the Class Name of Index 3. In this index, he will set reserve bandwidth for 1 VPN tunnel.
Vigor2900 Series User’s Guide 152 Y ou can just set the settings wrapped inside the red rectangles to fit the request of NA T usage. T o use another DHCP server in the network rather than the built-in one of V igor Router , you have to change the settings as show below .
Vigor2900 Series User’s Guide 153 Y ou can just set the settings wrapped inside the red rectangles to fit the request of NA T usage..
Vigor2900 Series User’s Guide 154 5 5 . . 5 5 C C a a l l l l i i n n g g S S c c e e n n a a r r i i o o f f o o r r V V o o I I P P f f u u n n c c t t i i o o n n 5 5 . . 5 5 . . 1 1 C C a a l l l l i i n n g g v v i i a a S S I I P P S S e e v v e e r r Example 1: Both John and David have SIP Addresses from different servi ce providers.
Vigor2900 Series User’s Guide 155 Example 2: Both John and David have SIP Addresses from the same servi ce provider. John’s SIP URL: 1234@draytel.org , David ’s SIP URL: 4321@draytel.org Settings for John DialPlan index 1 Phone Number: 1111 Display Name: David SIP URL: 4321@draytel.
Vigor2900 Series User’s Guide 156 5 5 . . 5 5 . . 2 2 P P e e e e r r - - t t o o - - P P e e e e r r C C a a l l l l i i n n g g Example 3: Both Arnor and Paulin have Vigor routers respectively, they can call each other without SIP Registrar. First they must have each other’s IP address and assign an Account Name for the port used for calling.
Vigor2900 Series User’s Guide 157 5 5 . . 6 6 U U p p g g r r a a d d e e F F i i r r m m w w a a r r e e f f o o r r Y Y o o u u r r R R o o u u t t e e r r Before upgrading your router firmware, you need to i n stall the Router Tools. The Firmware Upgrade Utility is included in the tools.
Vigor2900 Series User’s Guide 158 9. Double click on the icon of router tool. The setup wizard will appear. 10. Follow the onscreen instructions to install the tool. Finally, click Finish to end the installation. 11. From the Start menu, open Programs and choose Router Tools XXX >> Firmware Upgrade Utility .
Vigor2900 Series User’s Guide 159 14. Click Send . 15. Now the firmware update is finished..
Vigor2900 Series User’s Guide 160 This page is left blank..
Vigor2900 Series User’s Guide 161 6 T T r r o o u u b b l l e e S S h h o o o o t t i i n n g g This section will guide you to solve abnormal s ituations if you cannot access into the Internet after installing the router and finishing the we b configuration.
Vigor2900 Series User’s Guide 162 F F o o r r W W i i n n d d o o w w s s The example is based on Windows XP. As to the examples for other operation systems, please refer to the si milar steps or find support notes in www.draytek.com . 1. Go to Control Panel and then double-click on Network Connection s.
Vigor2900 Series User’s Guide 163 4. Select Obtain an IP address automatically and Obtain DNS server address automatically. F F o o r r M M a a c c O O s s 1. Double click on the current used MacOs on the desktop. 2. Open the Application folder and get into Network .
Vigor2900 Series User’s Guide 164 6 6 . . 3 3 P P i i n n g g i i n n g g t t h h e e R R o o u u t t e e r r f f r r o o m m Y Y o o u u r r C C o o m m p p u u t t e e r r The default gateway IP address of the router is 192.168.1.1. For some reason, you might need to use “ping” command to check the link status of the router.
Vigor2900 Series User’s Guide 165.
Vigor2900 Series User’s Guide 166 6 6 . . 4 4 C C h h e e c c k k i i n n g g I I f f t t h h e e I I S S P P S S e e t t t t i i n n g g s s a a r r e e O O K K o o r r N N o o t t Click Internet Access group and then check whether the ISP settings are set correctly.
Vigor2900 Series User’s Guide 167 H H a a r r d d w w a a r r e e R R e e s s e e t t While the router is running (ACT LED blinking), press the Factory Reset button and hold for more than 5 seconds. When you see the ACT LED blinks rapidly, please release the button.
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté Draytek 2900 c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du Draytek 2900 - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation Draytek 2900, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le Draytek 2900 va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le Draytek 2900, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du Draytek 2900.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le Draytek 2900. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei Draytek 2900 ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.