Manuel d'utilisation / d'entretien du produit 650 Series du fabricant ZyXEL Communications
Aller à la page of 513
Pr estige 650 Series ADSL Router User's Guide Version 3. 4 0 February 2004.
Prestige 650 Series User’s Guide ii Copyright Copyright Copyright © 2 003 by ZyXEL Com munications Corporation. The contents of this publi cation may not be reproduced i n any part or as a whole, t.
Prestige 650 Series User’s Guide FCC Statement i ii Federal Communications Commission (FCC) Interference S t atement This device complies with Part 15 of FCC rules. Operation is subject to the following two cond itions: • This device m ay not cause harmful interference.
Prestige 650 Series User’s Guide iv ZyXEL Warranty ZyXEL Limited W arranty ZyXEL warrants to the original end us er (purchaser) that this product is free from any defects in materials or workm anship for a period of up to tw o years from the date of purchase .
Prestige 650 Series User’s Guide Customer Support v Customer Support Please have th e following i nformation re ady when you cont act customer support. • Product model and serial num ber. • Warranty Information. • Date that you received your device.
Prestige 650 Series User’s Guide vi Table of Contents T able of Content s Copyright...................................................................................................................... ................................... ii Federal Communications Commission (FCC) Interfer en ce S tatemen t .
Prestige 650 Series User’s Guide Table of Contents vii 4.3 DNS Se rver Address Assignm ent ..............................................................................................4-2 4.4 LAN TCP/IP .............................................
Prestige 650 Series User’s Guide viii Table of Contents 10.5 Stateful In spec tion ............................................................................................................ ....... 10-7 10.6 Guidelines for Enhanci ng Secur ity with Your Firewall .
Prestige 650 Series User’s Guide Table of Contents ix 16.8 Pre-Share d Key ................................................................................................................. .......16-7 16.9 Editing VPN Policie s .....................
Prestige 650 Series User’s Guide x Table of Contents Chapter 21 Maintenance ......................................................................................................... .................. 21-1 21.1 Maintenance Overview .................
Prestige 650 Series User’s Guide Table of Contents xi 28.2 Configuring an IP static route ................................................................................................. .28- 2 Chapter 29 Brid ging Setup ...........................
Prestige 650 Series User’s Guide xii Table of Contents 36.3 Restore Conf igura tion .......................................................................................................... .... 36-7 36.4 Uploading Firm ware and Co nfiguration F iles .
Prestige 650 Series User’s Guide Table of Contents xiii A.4 Web Config urator............................................................................................................... ....... A-3 A.5 Login Userna me and Password ...............
Prestige 650 Series User’s Guide xiv List of Figures List of Figures Figure 1-1 Prestige Intern et Access Ap plication ................................................................................ ............. 1-8 Figure 1-2 Prestige LAN- to-LA N Application .
Prestige 650 Series User’s Guide List of Figures xv Figure 10-5 Stat eful I nspection ................................................................................................ .................... 10-8 Figure 1 1-1 Enab ling the Fi rewall....
Prestige 650 Series User’s Guide xvi List of Figures Figure 19-2 V iew Logs .......................................................................................................... ....................... 19-4 Figure 19-3 E-m ail Log Exam ple ....
Prestige 650 Series User’s Guide List of Figures xvii Figure 25-2 Menu 3.5.1 WL AN MAC Addre ss Filtering ............................................................................ 25 -4 Figure 26-1 Phys ical Network ..............................
Prestige 650 Series User’s Guide xviii List of Figures Figure 30-1 1 NA T Exam ple 1 ..................................................................................................... ................ 30-12 Figure 30-12 Menu 4 Intern et Access & NA T E xample .
Prestige 650 Series User’s Guide List of Figures xix Figure 35-1 Menu 24 System Main tenance ......................................................................................... ........ 35-1 Figure 35-2 Menu 24.1 System Maintena nc e : Status.
Prestige 650 Series User’s Guide xx List of Figures Figure 39-7 IP Rou ting Policy Example ....................................................................................................... 39-8 Figure 39-8 IP Rou ting Policy Example ..........
Prestige 650 Series User’s Guide List of Tables xxi List of T ables T able 1-1 Model Sp ecific Features.............................................................................................. ................... 1-2 T able 2-1 Password .......
Prestige 650 Series User’s Guide xxii List of Tables T able 14-2 Content Filter: Sc hedule ............................................................................................................. 14-4 T able 14-3 Content Filter: T rusted ......
Prestige 650 Series User’s Guide List of Tables xxiii T able 21-9 Restor e C onfiguration ............................................................................................... ............... 21-16 T able 22-1 Main Menu C ommands..........
Prestige 650 Series User’s Guide xxiv List of Tables T able 37-1 Menu 24.9.1 Budget Mana gement ....................................................................................... ....... 37-3 T able 37-2 Menu 24.10 System Mainte nance: T im e and Date Settin g .
Prestige 650 Series User’s Guide List of Tables xxv List of Chart s Chart A-1 T roubles hooting Powe r LE D .........................................................................................................A-1 Chart A-2 T roubles hooting LAN LE D .
Prestige 650 Series User’s Guide xxvi Preface Preface Congratulations on your purchase from the Prestige 650 AD SL Router series. Your Prestige i s easy to instal l and configure . Use the we b configurat or, System Management Terminal (SMT) or command interpreter interf ace to configure your Pres tige.
Prestige 650 Series User’s Guide Preface xxvii • Mouse action s equences are denoted usi ng a comm a. For exam ple, “click t he Apple ico n, Contr ol Panels and then Modem ” means first click the Apple icon, then point your mouse pointer to Control Panels and then click Modem .
Prestige 650 Series User’s Guide xxviii What is DSL? Introduction to DSL DSL (Digital Subscriber Line) technology enh ances the data capacity of the ex isting twisted-pair wire that runs between t he local tele phone com pany switchin g of fices and m ost homes and offices.
Getting Started I Part I: Getting Started This part is structured as a step-by-step guide to help you acce ss your P restige. I t covers key features and applications, accessi ng the web config urator , password setup and configuring the wizard screens for initial setup.
.
Prestige 650 Series User’s Guide Getting To Know Your Prestige 1-1 Chapter 1 Getting To Know Your Prestige This chapter describes the key features and applications of your Prestige .
Prestige 650 Series User’s Guide 1-2 Getting To Know Your Prestige 1.2 Features of the Prestige The following secti ons describe the features of the Prestige series. Feature s vary by Prestige m odel. This table lists the key features of t he Prestige series.
Prestige 650 Series User’s Guide Getting To Know Your Prestige 1-3 Four-Port Switch A combination of switch and router makes your Prestige a cost-effectiv e and viable network so lution. You can connect up to four computers to the LAN ports on you Prestige without the co st of a hub.
Prestige 650 Series User’s Guide 1-4 Getting To Know Your Prestige LAN. The Prestige firewall supports TCP/UDP inspectio n, DoS detection and prevention, real time alerts, reports and logs .
Prestige 650 Series User’s Guide Getting To Know Your Prestige 1-5 ♦ Supports OAM F4/F5 loo p-back, AIS a nd RDI O AM cells. ♦ ATM Forum UNI 3.1/4. 0 PVC. ♦ Supports up to 8 PVCs (UBR, CBR, VBR). ♦ Multiple Pro tocols over AAL5 (RFC 1483 ). ♦ PPP over AAL5 (RFC 2364).
Prestige 650 Series User’s Guide 1-6 Getting To Know Your Prestige ♦ PPPoE feature o PPPoE idle time out o PPPoE dial on dem and Networking Comp atibility Your Prestige is compatible with major ADSL DS LAM (Digital Subscriber Lin e Access Multiplexer) providers.
Prestige 650 Series User’s Guide Getting To Know Your Prestige 1-7 • ADSL circuitry • RAM • LAN port Filters The Prestige's packet filtering functions allows added network security and management. Ease of Inst allation Your Prestige is designed for quick, intuitiv e and easy installation.
Prestige 650 Series User’s Guide 1-8 Getting To Know Your Prestige Figure 1-1 Prestige Internet Access Application 1.3.2 LAN to LAN Application You can use the Prestige to connect two geogr aphical ly dispersed net works ove r the ADSL line. A typica l LAN-to-LAN application for your Prestige is shown as follows.
Prestige 650 Series User’s Guide Introducing the Web Configurato r 2-1 Chapter 2 Introducing the Web Configurator This chapter describes how to access and navigate the web configurator.
Prestige 650 Series User’s Guide 2-2 Introducing the Web Configurato r Step 6. You should now see the Site Map screen. The Prestige automatically times out after fiv e minutes of inactivity . Simply log back into the Prestige if this happen s to you.
Prestige 650 Series User’s Guide Introducing the Web Configurato r 2-3 Click the HELP icon (located in the top right corner of most scre ens) to vie w embedded help. 2.4 Configuring Password It is highly recommended tha t you change the password for accessing the Prestige.
Prestige 650 Series User’s Guide 2-4 Introducing the Web Configurato r 2.5 Resetting the Prestige If you forget your password or ca nnot access the Prestige, you will nee d to reload the factory-default configuration file or use the RESET butto n on the back of the Prestige.
Prestige 650 Series User’s Guide Introducing the Web Configurato r 2-5 Figure 2-4 Example Xmodem Upload Step 6. After successful firm ware upload, en ter "atgo" to restart the router. Type the configuration file’s location, or click Browse to search for it.
.
Prestige 650 Series User’s Guide Wizard Setup 3-1 Chapter 3 Wizard Setup This chapter provides information on the Wiza rd Setup screens in the web configurator.
Prestige 650 Series User’s Guide 3-2 Wizard Setup 3.2.4 RFC 1483 RFC 1483 describes two method s for Multiprotocol Encapsu lation over ATM Adaptation Layer 5 (AAL5).
Prestige 650 Series User’s Guide Wizard Setup 3-3 Figure 3-1 Wizard Screen 1 The following table describes the labels in this screen. Table 3-1 Wizard Screen 1 LA BE L DESCRIPTION Mode From the Mode drop-down list box, sel ect Routing (default) if your ISP allows multiple computers to share an Internet account.
Prestige 650 Series User’s Guide 3-4 Wizard Setup Table 3-1 Wizard Screen 1 LA BE L DESCRIPTION Next Click this button to go to the next wizard screen. The next wizard screen yo u see depends on what protocol you chose ab ove. Click on the protocol link to see the next wizard screen for that protocol.
Prestige 650 Series User’s Guide Wizard Setup 3-5 3.7.1 IP Assignment with PPPoA or PPPoE Encap sulation If you have a dynamic IP, t hen the IP Address and ENE T ENCAP Gate way fields a re not appl icable (N/A). If you have a st atic IP, the n you only need to fill in the IP Address field and not the EN ET ENCAP G ateway field.
Prestige 650 Series User’s Guide 3-6 Wizard Setup 3.8 Nailed-Up Connection (PPP) A nailed-up connection is a dial-up line where the connec tion is always up rega rdless of traffic demand. The Prestige does two things when you specify a nailed-up c onnection.
Prestige 650 Series User’s Guide Wizard Setup 3-7 Figure 3-2 Internet Connection with PPPoA The following table describes the labels in this screen. Table 3-2 Internet Connection with PPPoA LA BE L DESCRIPTION User Name Enter the user name exactly as your ISP assigned.
Prestige 650 Series User’s Guide 3-8 Wizard Setup Table 3-2 Internet Connection with PPPoA LA BE L DESCRIPTION IP Address This option is available if you select Routing in the Mode field.
Prestige 650 Series User’s Guide Wizard Setup 3-9 3.10.2 RFC 1483 Select RFC 1483 from the Encapsulati on drop-down list box in the first wizard screen to display the screen as shown. Figure 3-3 Internet Connection w ith RFC 1483 The following table describes the labels in this screen.
Prestige 650 Series User’s Guide 3-10 Wizard Setup Figure 3-4 Internet Connection w ith ENET ENCAP The following table describes the labels in this screen. Table 3-4 Internet Connection with ENET ENCAP LA BE L DESCRIPTION IP Address A static IP address is a fixed IP that your ISP gives you.
Prestige 650 Series User’s Guide Wizard Setup 3-11 Table 3-4 Internet Connection with ENET ENCAP LA BE L DESCRIPTION Network Address Translation Select None , SUA Only or Full Fea ture from the drop-sown list box. Refer to the NAT chapter for more details.
Prestige 650 Series User’s Guide 3-12 Wizard Setup Table 3-5 Internet Connection with PPPoE LA BE L DESCRIPTION Service Name Type the name of your PPPoE service here. User Name Confi gure User Name and Password fields for PPPoA and PPPoE encapsulation only.
Prestige 650 Series User’s Guide Wizard Setup 3-13 DHCP service off, you m ust have anot her DHCP ser ver on your LAN , or else the c omputer m ust be manually configur ed. 3.11.1 IP Pool Setup The Prestige i s pre-configure d with a p ool of 32 IP addresses st arting fro m 192.
Prestige 650 Series User’s Guide 3-14 Wizard Setup Figure 3-7 Wizard : LAN Configuration The following table describes the labels in this screen. Table 3-6 Wizard : LAN Configuration LA BE L DESCRIPTION LAN IP Address Enter the IP address of your Prestige in dotted decim al notation, for example, 192.
Prestige 650 Series User’s Guide Wizard Setup 3-15 Table 3-6 Wizard : LAN Configuration LA BE L DESCRIPTION Client IP Pool Starting Address This field specifies the first of the contiguous addresses in the IP address pool. Size of Client IP Pool This field speci fie s the size or count of the IP address pool.
Prestige 650 Series User’s Guide 3-16 Wizard Setup 3.14 T est Y our Internet Connection Launch your web browser and navigate to www. zyxel.com . Internet access is just th e beginning. Refer to the rest of this User’s Guide for more detailed information on the comp lete range of Prestige features.
LAN, Wireless LAN and WAN II Part II: LAN, Wireless LAN and WAN This part covers the LAN (Local Area Network), wireless LAN and W AN setup..
.
Prestige 650 Series User’s Guide LAN Setup 4-1 Chapter 4 LAN Setup This chapter describes how to configure LAN settings. 4.1 LAN Overview A Local Area Network (LAN) is a sh ared communication system to whic h m any computers are attached.
Prestige 650 Series User’s Guide 4-2 LAN Setup There are two ways that an ISP disseminates the DNS se rver addresses. The first is for an ISP to tell a customer the DNS server addresses, us ually in the form of an information sheet, when s/he signs up.
Prestige 650 Series User’s Guide LAN Setup 4-3 These param eters should wor k for the m ajority of in stallations. If y our ISP gives you explicit DNS server address(es), read the em bedded we b confi gurator help regarding w hat fields need to be config ured.
Prestige 650 Series User’s Guide 4-4 LAN Setup 4.5 Configuring LAN Click LAN to open t he followin g screen. Figure 4-2 LAN The following table describes the labels in this screen.
Prestige 650 Series User’s Guide LAN Setup 4-5 Table 4-1 LAN LA BE L DESCRIPTION DHCP If set to Server , your Prestige can assign IP addresses, an IP default gateway and DNS servers to Windows 95, Windo ws NT and other systems that support the DHCP client.
.
Prestige 650 Series User’s Guide Wireless LAN Setup 5-1 Chapter 5 Wireless LAN Setup This chapter discusses how to configure Wireless LAN on the Prestige. This chapter is only applicable to the Prestige 650H and Prestige 650HW. 5.1 Wireless LAN Overview This section introduces the wireless LAN and some basi c configurations.
Prestige 650 Series User’s Guide 5-2 Wireless LAN Setup 5.1.4 RTS/CTS A hidden node occurs when two stati ons are within range of the sam e acce ss point, but are not withi n range of each other.
Prestige 650 Series User’s Guide Wireless LAN Setup 5-3 Enabling the RTS Threshold causes redundant ne twork overhead that could negatively affect the throughput p erformance instead of providing a remedy .
Prestige 650 Series User’s Guide 5-4 Wireless LAN Setup 5.3 Dat a Encryption with WEP WEP encryption scrambles the data tran smitted between the wireless stations and the access points to keep network com munications private. It e ncrypts unicast and multicast communications in a network.
Prestige 650 Series User’s Guide Wireless LAN Setup 5-5 Figure 5-3 Wireless The following table describes the labels in this screen. Table 5-1 Wireless LA BE L DESCRIPTION ESSID The ESSID (Extended Service Set Ident ification) is a unique name to ide ntify the Prestige in the wireless LAN.
Prestige 650 Series User’s Guide 5-6 Wireless LAN Setup Table 5-1 Wireless LA BE L DESCRIPTION Hide ESSID Select Yes to hide the ESSID in so a station cannot obtain the ESSI D through passive scanning. Select No to make the ESSID visible so a stat ion can obtain the ESSI D through passive scanning.
Prestige 650 Series User’s Guide Wireless LAN Setup 5-7 5.6 Configuring MAC Filter The MAC filter screen allows you to confi gure the Prestige to gi ve ex clusive access to up to 32 devices (Allow Association) or exclude up to 32 devices from accessing the Prestige (Deny Association).
Prestige 650 Series User’s Guide 5-8 Wireless LAN Setup Figure 5-4 MAC Address Filter The following table describes the labels in this menu..
Prestige 650 Series User’s Guide Wireless LAN Setup 5-9 Table 5-2 MAC Address Filter LA BE L DESCRIPTION Active Select Yes from the drop down list bo x to enable MAC address filtering. Action Define the filter action for the list of MAC addresses in the M AC address filter table.
Prestige 650 Series User’s Guide 5-10 Wireless LAN Setup • Access-Request Sent by an acc ess point reque sting authent ication. • Access-Reject Sent by a RADIUS server rejecting access . • Access-Accept Sent by a RADIUS server allowing access.
Prestige 650 Series User’s Guide Wireless LAN Setup 5-11 Figure 5-5 EAP Authentication The details below provide a gener al description of how IEEE 802.1x EAP auth entication works. For an example list of EAP-MD5 authentication st eps, see the IE EE 802.
Prestige 650 Series User’s Guide 5-12 Wireless LAN Setup Table 5-3 802.1x LA BE L DESCRIPTION Wireless Port Control To control wireless stations access to the wired net work, select a control method from the drop-down list box. Cho ose from No A uthentication R equired , Authentication Required and No Access Allowed .
Prestige 650 Series User’s Guide Wireless LAN Setup 5-13 Table 5-3 802.1x LA BE L DESCRIPTION Authentication Databases This field is activated only when you select Authentication Required in the Wireless Port Control field. The authentication databas e contains wireless station login information.
Prestige 650 Series User’s Guide 5-14 Wireless LAN Setup Figure 5-7 Local User Database.
Prestige 650 Series User’s Guide Wireless LAN Setup 5-15 The following table describes the labels in this screen. Table 5-4 Local User Database LABEL DESCRIPTION # This is the index number of a local user accou nt. Active Select this check box to enable the user pr ofile.
Prestige 650 Series User’s Guide 5-16 Wireless LAN Setup Figure 5-8 RADIUS The following table describes the labels in this screen. Table 5-5 RADIUS LABEL DESCRIPTION Authentication Server Active Select Yes from the drop-down list box to e nab le user authentic ation through an external authenticati on server.
Prestige 650 Series User’s Guide Wireless LAN Setup 5-17 Table 5-5 RADIUS LABEL DESCRIPTION Shared Secret Enter a password (up to 31 alpha numeric characters) as the key to be shared between the external authentication serv er and the access points.
.
Prestige 650 Series User’s Guide WAN Setup 6-1 Chapter 6 WAN Setup This chapter describes how to configure WAN settings. 6.1 W AN Overview A WAN (Wi de Area Networ k) is an out side connecti on to anot her network or the Inter net. See the Wizard Setup chapter for more infor mation on the fields in t he WAN screens.
Prestige 650 Series User’s Guide 6-2 WAN Setup 6.4 T r affic Shaping Traffic Shaping is an agreem ent between the carrier an d the subscriber to regulate the average rate and fluctuations of data transmission over an ATM networ k.
Prestige 650 Series User’s Guide WAN Setup 6-3 6.5 Configuring W AN Setup To change your Prestige’s WAN remote node settings , click WAN . The screen differs by the encapsulation.
Prestige 650 Series User’s Guide 6-4 WAN Setup The following table describes the labels in this screen. Table 6-1 Internet Access Setup LABEL DESCRIPTION Name Enter the name of your Internet Service Prov ider, e.g., MyISP. This information is for identification purposes only.
Prestige 650 Series User’s Guide WAN Setup 6-5 Table 6-1 Internet Access Setup LABEL DESCRIPTION Maximum Burst Size Maximum Burst Size (MBS) refe rs to the maximum number of cells that can be sent at the peak rate. Type the MBS, which is less than 65535.
Prestige 650 Series User’s Guide 6-6 WAN Setup Table 6-1 Internet Access Setup LABEL DESCRIPTION Subnet Mask (ENET ENCAP encapsulation only) Enter a subnet mask in dotted decimal notatio n. Refer to the Subnetting appendix in the to cal culate a subnet mask If you are implementing subn etting.
NAT, Dynamic DNS and Time Zone III Part III: NAT, Dynamic DNS and Time Zone This part covers NA T (Network Address T ran slation), dynamic DNS (Domain Na me Sever) and T ime Zone setup.
.
Prestige 650 Series User’s Guide NAT 7-1 Chapter 7 Network Address Translation (NAT) This chapter discusses how to configure NAT on the Prestige . 7.
Prestige 650 Series User’s Guide 7-2 NAT local address before forwarding it to the origin al inside host. Note that the IP address (either local or global ) of an outside host is neve r changed. The global IP a ddresses for the i nside hosts can be either stati c or dynami cally assigned by t he ISP.
Prestige 650 Series User’s Guide NAT 7-3 Figure 7-2 NAT Application With IP Alias 7.1.5 NA T Mapping T ypes NAT support s five types of IP/port mapping. They are: 1. One to One : In One -to-One m ode, the Prest ige maps one l ocal IP address t o one global IP address.
Prestige 650 Series User’s Guide 7-4 NAT 5. Server : This type allows you to specify inside serv ers of different services b ehind the NAT to be accessible to the outside world. Port numbers do not change for One-to-One and Many-to-Many No Overload NA T mapping types.
Prestige 650 Series User’s Guide NAT 7-5 1. Choose SUA Only if you have just one public W AN IP address for y our Prestige. 2. Choose Full Feature if you have multiple public W AN IP addresses for y our Prestige.
Prestige 650 Series User’s Guide 7-6 NAT Many residential broadband ISP account s do not allo w you to run any serv er processes (such as a W eb or FTP server) from y our location. Y our ISP may periodically check for servers and may suspend your account if it discov ers any active services at your location.
Prestige 650 Series User’s Guide NAT 7-7 Figure 7-3 Multiple Servers Behind NAT Example 7.4 Selecting the NA T Mode Click NAT to open the follo wing screen.
Prestige 650 Series User’s Guide 7-8 NAT Table 7-4 NAT Mode LABEL DESCRIPTION None Select this radio button to disabl e NAT. SUA Only Select this radio button if you have just one p ublic WAN IP address for your Prestige. The Prestige uses Address Mapping Set 1 in the N AT - Edit SUA /NAT Server Set screen.
Prestige 650 Series User’s Guide NAT 7-9 Figure 7-5 Edit SUA/NAT Server Set The following table describes the labels in this screen. Table 7-5 Edit SUA/NAT Server Set LABEL DESCRIPTION Start Port No. Enter a port number in this field. To forward only one port, enter the port num ber again in the End Port No.
Prestige 650 Series User’s Guide 7-10 NAT Table 7-5 Edit SUA/NAT Server Set LABEL DESCRIPTION End Port No. Enter a port number in this field. To forward only one port, enter the port num ber again in the Start Port No. field above and then enter it again in this field.
Prestige 650 Series User’s Guide NAT 7-11 Figure 7-6 Address Mapping Rules The following table describes the labels in this screen. Table 7-6 Address Mapping Rules LABEL DESCRIPTION Local Start IP This is the starting Inside Local IP A ddress (ILA).
Prestige 650 Series User’s Guide 7-12 NAT Table 7-6 Address Mapping Rules LABEL DESCRIPTION Type 1-1 : One-to-one mode maps one local IP address to one globa l IP address. Note that port numbers do not change for t he One-to-one NAT mappi ng type. M-1 : Many-to-One mode maps multiple local IP addresses to one gl obal IP address.
Prestige 650 Series User’s Guide NAT 7-13 The following table describes the labels in this screen. Table 7-7 Address Mapping Rule Edit LABEL DESCRIPTION Type Choose the port mapping type from one of the follo wing. 1. One-to-One : One-to-One mode maps one local IP address to one glob al IP address.
.
Prestige 650 Series User’s Guide Dynamic DNS Setup 8-1 Chapter 8 Dynamic DNS Setup This chapter discusses how to configure your Prestige to use Dynamic DNS. 8.1 Dynamic DNS Dynamic DNS allows you to update your curr ent dynamic IP address with one or many dynamic DNS services so that anyone can c ontact you (in NetMee ting, CU-SeeMe, etc.
Prestige 650 Series User’s Guide 8-2 Dynamic DNS Setup Figure 8-1 DDNS The following table describes the labels in this screen. Table 8-1 DDNS LABEL DESCRIPTION Active Select this che ck box to use dynamic DNS. Service Provider Select the name of your Dynamic DNS service provider.
Prestige 650 Series User’s Guide Time and Date Setup 9-1 Chapter 9 Time and Date Setup Use this screen to configure the Prestige’s time and date settings. This chapter is not available on all models. 9.1 Configuring T ime Zone To change your Prestig e’s time and date, click Time Zone (or Time And Date ).
Prestige 650 Series User’s Guide 9-2 Time and Date Setup The following table describes the labels in this screen. Table 9-1 Time and Date LABEL DESCRIPTION Time Server Use Time Server when Bootup (or Use Protocol when Bootup) Select the time service protocol that y our time server sends when you turn on the Prestige.
Prestige 650 Series User’s Guide Time and Date Setup 9-3 Table 9-1 Time and Date LABEL DESCRIPTION New Date (yyyy-mm-dd) This field displays the last updated date from the time server. When you select None in the Use Time Serv er when Bootup field, enter the new date in this field and then click Apply .
Firewall and Content Filter IV Part IV: Firewall and Content Filter This part introduces fire walls in general and the Prestige firewall. It also explains customized services and logs and gives example firewall ru les and an overvie w of content filtering.
Prestige 650 series User’s Guide Firewalls 10-1 Chapter 10 Firewalls This chapter gives som e background inform ation on firewalls and introdu ces the Prestige firewall.
Prestige 650 series User’s Guide 10-2 Firewalls i. Inform ation hiding prevents the names of int ernal system s from being m ade known vi a DNS to outside system s, since the app lication gate way is the only host whose name must be m ade known to outside systems.
Prestige 650 series User’s Guide Firewalls 10-3 Figure 10-1 Prestige Firewall Application 10.4 Denial of Service Denials of Service (DoS) attacks are aim ed at devices an d networks wi th a connection to the Internet. Their goal is not to steal information, but to disable a devi ce or network so users no longer have access to network resources.
Prestige 650 series User’s Guide 10-4 Firewalls Table 10-1 Common IP Ports 21 FTP 53 DNS 23 Telnet 80 HTTP 25 SMTP 110 POP3 10.4.2 T ypes of DoS Att acks There are four types of DoS a ttacks: 1. Those that e xploit bu gs in a T CP/IP im plementat ion.
Prestige 650 series User’s Guide Firewalls 10-5 Figure 10-2 Three-Way Handshake Under normal circumstances, the application that initiate s a session sends a SYN (synchronize) packet to the receiving server. The receiver sends back an ACK (ack nowledgment) packet and its own SYN, and then the initiator responds with an ACK (acknowledgment).
Prestige 650 series User’s Guide 10-6 Firewalls 2-b In a LAND Atta ck , hackers flood S YN packets i nto th e network with a spoofed source IP address of the targeted system. Th is makes it appear as if the host computer sent t he packets to itself, making the system unavailable while the target system tries to respond to itself.
Prestige 650 series User’s Guide Firewalls 10-7 The only legal NetBIOS commands are the fo llowing - all others are illegal. Table 10-3 Legal NetBIOS Command s MESSAGE: REQUEST: POSITIVE: NEGATIVE: RETARGET: KEEPALIVE: All SMTP commands are illegal excep t for th ose displayed in the following tables.
Prestige 650 series User’s Guide 10-8 Firewalls Allows all sessio ns originating from the LA N (local network) to the WAN (Internet). Denies all session s originatin g from the WAN to the LAN.
Prestige 650 series User’s Guide Firewalls 10-9 4. Based on the obtained state in form ation, a firewall rule crea tes a temporary access list entry that is inserted at the beginni ng of the WAN interfa ce's inbound extended access list.
Prestige 650 series User’s Guide 10-10 Fire walls Below is a brief technical description of how these connections a re tracked. C onnections m ay either be defined by t he upper pr otocols (for i nstance, TCP), or by the Presti ge itself (as wi th the " virtual connect ions" created for UDP and ICMP).
Prestige 650 series User’s Guide Firewalls 10-11 10.5.5 Upper Layer Protocols Some higher layer protocols (such as FTP and RealAudio) utilize multiple network connections simultaneously .
Prestige 650 series User’s Guide 10-12 Fire walls 1. Encourag e your company or or ganization to dev elop a comprehen sive security plan . Good network administrat ion takes into acc ount what hac kers can do an d prepares agai nst attacks. The best defense against hackers and cracke rs is information.
Prestige 650 series User’s Guide Firewalls 10-13 Packet filtering only ch ecks the header portion of an IP packet. When T o Use Filtering 1. To block/allow LAN pac kets by their MAC addresses. 2. To block/allow special IP packets which are neit her TCP nor UDP, nor ICM P packets.
Prestige 650 series User’s Guide 10-14 Fire walls 6. The firewall can bloc k specific URL traffic that m ight occur in the fu ture. The URL can be save d in an Access Control List (ACL) database.
Prestige 650 series User’s Guide Firewall Configuration 11-1 Chapter 11 Firewall Configuration This chapter show s you how to enable and co nfigure the Prestige firewall.
Prestige 650 series User’s Guide 11-2 Firewall Configuration 11.3 Configuring E-mail Alerts To change your Prestige’s E-mail log settings, click Advanced Setup , Fi rewall , and then E-mail . The screen appe ars as show n. This screen is not av ailable on all models.
Prestige 650 series User’s Guide Firewall Configuration 11-3 Table 11-1 E-mail LABEL DESCRIPTION E-mail Alerts To Alerts are sent to the e-mail address specified in this field. If this field is left blank, alerts will not be sent via e-mail. Return Address Type an E-mail address to id entify the Presti ge as the sender of the e-mail messages i.
Prestige 650 series User’s Guide 11-4 Firewall Configuration 11.4.1 Alert s Alerts are reports on ev ents, such as attacks, that you may wan t to know about right away.
Prestige 650 series User’s Guide Firewall Configuration 11-5 delete half-open sessions as necessary, until the rate of new connection attempts drops below another threshold ( one-minute low ). The rate is the number of new attempts detected in the last one-minute sample period.
Prestige 650 series User’s Guide 11-6 Firewall Configuration Figure 11-3 Alert The following table describes the labels in this screen. Table 11-2 Alert LABEL DESCRIPTION Generate alert when attack detected Select this check box to generate an alert whenever an attack is detected.
Prestige 650 series User’s Guide Firewall Configuration 11-7 Table 11-2 Alert LABEL DESCRIPTION One Minute High This is the rate of ne w half-open se ssions that causes the firewall to start deleting half-open sessions. The defau lt is "100".
.
Prestige 650 series User’s Guide Creating Custom Rules 12-1 Chapter 12 Creating Custom Rules This chapter contains in structions for defining both Local Netwo rk and Internet rules. Thi s chapter applies to the Prestige 650H/HW and the Prestig e 650H-E.
Prestige 650 series User’s Guide 12-2 Creating Custom Rules 2. Is the intent of the rule to forward or b lock traffic? 3. What is the direction c onnection: fr om the LAN to the Internet, or from the Internet to the LAN ? 4. What IP services will be affected? 5.
Prestige 650 series User’s Guide Creating Custom Rules 12-3 Source Address What is the connection’s source addres s; is it on the LAN or WAN? Is it a single IP, a range of IPs or a subnet? Destination Address What is the connection’s destination add ress; is it on the LAN or WAN? Is it a single IP, a range of IPs or a subnet? 12.
Prestige 650 series User’s Guide 12-4 Creating Custom Rules 12.3.2 W AN to LAN Rules The default rule for WAN to LAN traffic blocks all in coming conn ections (WAN to LAN). If you wish to allow certain WAN users to have access to your LAN, you will need to create custom rules to allow it.
Prestige 650 series User’s Guide Creating Custom Rules 12-5 Figure 12-3 Fire wall Logs The following table describes the labels in this screen. Table 12-1 Firewall Logs LABEL DESCRIPTION EXAMPLE No. This is the index number of the fire wall log. 128 entries are available numbered from 0 to 127.
Prestige 650 series User’s Guide 12-6 Creating Custom Rules Table 12-1 Firewall Logs LABEL DESCRIPTION EXAMPLE Reason T his field states the reason for the log; i.e., was the rule matched, not matched, or was there an attack. The set and rule coordinates (<X, Y> where X=1,2; Y=00~10) follow with a simple explanation.
Prestige 650 series User’s Guide Creating Custom Rules 12-7 Click on Firewall , then Rule Sum mary to bring up the follo wing screen. This screen is a summary of the existing rules. Note the order in which the rules are listed. The ordering of your rules is very import ant as rules are applied in turn.
Prestige 650 series User’s Guide 12-8 Creating Custom Rules Table 12-2 Firewall Rules Summary: First Scre en LABEL DESCRIPTION The default action for packets not matching following rules Use the drop-down list box to select whether to Block (silently discard) or Forward (allow the passage of) packets that do not match the follo wing rules.
Prestige 650 series User’s Guide Creating Custom Rules 12-9 defines the servi ce. (Note that there may be more than one IP protocol t ype. For exam ple, look at t he default configuration labeled “( DNS )”. (UDP/TCP:53) means UDP port 53 and TCP port 53.
Prestige 650 series User’s Guide 12-10 Creating Custom Rules Table 12-3 Predefined Services SERVICE DESCRIPTION NEWS(TCP:144) A protocol for news groups. NFS(UDP:2049) Network File System - NFS is a client/server distribut ed file service that provides transparent file-sharing for net work environments.
Prestige 650 series User’s Guide Creating Custom Rules 12-11 Table 12-3 Predefined Services SERVICE DESCRIPTION SSDP(UDP:1900) Simple Service Discovery Protocol (SSDP) is a discovery service searching for Universal Plug and Pla y devices on your hom e network or upstream Internet gateways using UDP port 1900.
Prestige 650 series User’s Guide 12-12 Creating Custom Rules Figure 12-5 Creating/Editing A Fire wall Rule The following table describes the labels in this screen. Table 12-4 Creating/Editing A Fire wall Rule LABEL DESCRIPTION Source Address Click SrcAdd to add a new address, SrcEdit to edit an existing one or SrcDelete to delete one.
Prestige 650 series User’s Guide Creating Custom Rules 12-13 Table 12-4 Creating/Editing A Fire wall Rule LABEL DESCRIPTION Destination Address Click DestAdd to add a ne w address, DestEdit to edit an existing one or DestDelete to delete one. Services Select a service in the Available Services box on the left, then click >> to select.
Prestige 650 series User’s Guide 12-14 Creating Custom Rules Figure 12-6 Adding/Editing Source a nd Destination Addresses The following table describes the labels in this screen.
Prestige 650 series User’s Guide Creating Custom Rules 12-15 12.8.1 Factors Influencing Choices for T imeout V alues The factors infl uencing choic es for time out values ar e the s ame as the factors influencing choices for threshold value s – see section 11.
Prestige 650 series User’s Guide 12-16 Creating Custom Rules Table 12-6 Timeout LABEL DESCRIPTION Back Click Back to return to the previous screen. Apply Click Apply to save your customized settings and exit this screen. Cancel Click Cancel to return to the previous config uration.
Prestige 650 series User’s Guide Customized Services 13-1 Chapter 13 Customized Services This chapter covers creating, viewing and editi ng custom services.
Prestige 650 series User’s Guide 13-2 Customized Services Table 13-1 Customized Services LABEL DESCRIPTION Customized Services No. This is the number of your cust omized po rt. Click a rule’s number of a service to go to the Firewall Customized Services Config screen to configure or edit a customized service.
Prestige 650 series User’s Guide Customized Services 13-3 Table 13-2 Creating/Editing A Custo mized Service LABEL DESCRIPTION Service Name Type a unique name for your custom port. Service Type Choose the IP port ( TCP , UDP or TCP/UDP ) that defines your customized port from the drop down list box.
Prestige 650 series User’s Guide 13-4 Customized Services Step 1. Click ScrAdd to open th e Rule IP Config screen. Configure it as follows and click Apply .
Prestige 650 series User’s Guide Customized Services 13-5 Step 4. Follow the procedures outlined earlier in this ch apter to configure all your rules. Conf igure the rule configuration screen lik e the one below and apply it. Figure 13-6 Syslog Rule Con figuration Example This is your My Service custom port.
Prestige 650 series User’s Guide 13-6 Customized Services Step 6. On completing the configuration pro cedure for these Internet firewall rules, the Rule Summary screen should look lik e the following. Don ’t forget to click Apply whe n you ha ve finis hed configuring your rule(s) to sav e your settings back to the Prestige.
Prestige 650 series User’s Guide Content Filtering 14-1 Chapter 14 Content Filtering This chapter cove rs how to configure content filtering . This cha pter applies to the Prestige 650H/HW. 14.1 Content Filtering Overview Internet content filtering allows you to c reate and enforce Internet access policie s tailored to your needs.
Prestige 650 series User’s Guide 14-2 Content Filtering Figure 14-1 Content Filte r: Key word The following table describes the labels in this screen. Table 14-1 Content Filter: Key word LABEL DESCRIPTION Enable Keyword Blocking Select this check box to enable this feature.
Prestige 650 series User’s Guide Content Filtering 14-3 Table 14-1 Content Filter: Key word LABEL DESCRIPTION Add Keyword Click Add Keyword after y ou have typed a keyword. Repeat this procedure to add other ke ywords. Up to 127 keywords are allo wed.
Prestige 650 series User’s Guide 14-4 Content Filtering Table 14-2 Content Filter: Schedule LA BE L DESCRIPTION Days to Block: Select a check box to configur e which days of the week (or everyday) you want the content filtering to be active.
Prestige 650 series User’s Guide Content Filtering 14-5 Table 14-3 Content Filter: Trusted LABEL DESCRIPTION To Type the ending IP address of a specif ic ran ge of users on your LAN that you want to exclude from content filtering. Leave this field blank if you want to exclude an individu al computer.
Prestige 650 series User’s Guide 14-6 Content Filtering The following table describes the labels in this screen. Table 14-4 Content Filter Logs LABEL DESCRIPTION Page Choose a page of logs from the drop-down list box to dis play. No. This is the index number of the content filter log.
VPN/IPSec V Part V: VPN/IPSec This part provides informati on about conf iguring VPN/IPSec for secure communications..
.
Prestige 650 Series User ’ s Guide Introduction to IPSec 15-1 Chapter 15 Introduction to IPSec This chapter introduces the basics of IPSec VPNs. This chapter applies to the Prestige 650H/HW. 15.1 VPN Overview A VPN (Virt ual Private Net work) provi des secure com munications between site s without t he expense of leased site-to-site lines.
Prestige 650 Series User ’ s Guide 15-2 Introduction to IPSec Figure 15-1 Encryption and Dec ryption Data Confidentiality The IPSec sender can enc rypt packets befo re transm itting them across a network.
Prestige 650 Series User ’ s Guide Introduction to IPSec 15-3 Figure 15-2 VPN Application 15.2 IPSec Architecture The overall IPSec architect ure is shown as follows.
Prestige 650 Series User ’ s Guide 15-4 Introduction to IPSec Figure 15-3 IPSec Architecture 15.2.1 IPSec Algorithms The ESP (Encapsulat ing Securit y Payload) Protocol (R FC 2406) an d AH (Aut hent.
Prestige 650 Series User ’ s Guide Introduction to IPSec 15-5 15.3 Encap sulation The two modes of ope ration for IPSec VPNs are Tr ansport m ode and Tunnel m ode.
Prestige 650 Series User ’ s Guide 15-6 Introduction to IPSec A NAT device in between the IPSec endpoints will rewrite either the source or des tination address with one of its own choosing.
Prestige 650 Series User ’ s Guide VPN Screens 16-1 Chapter 16 VPN Screens This chapter introduces the VPN screens. See the L ogs chapter for information on viewing logs and the Reference Guide for IPSec log descriptions. This chapter applies to the Prestige 650H/HW.
Prestige 650 Series User ’ s Guide 16-2 VPN Screens Table 16-1 AH and ESP ESP AH DES (default) Data Encryption Standard (D ES) is a widely used method of data encryption using a pr ivate (secret) key. DES applies a 56-bit key to each 64-bit block of dat a.
Prestige 650 Series User ’ s Guide VPN Screens 16-3 The Secure Gateway IP Address may be configured as 0.0.0.0 only when using IKE key management and not Manual key management. 16.5 VPN Summary Screen The following figure helps explain the main fields in th e web configurator.
Prestige 650 Series User ’ s Guide 16-4 VPN Screens Figure 16-2 VPN Summary The following table describes the labels in this screen. Table 16-2 VPN Summary LA BE L DESCRIPTION No. This is the VPN policy i ndex number. Click a number to edit VPN polic ies.
Prestige 650 Series User ’ s Guide VPN Screens 16-5 Table 16-2 VPN Summary LA BE L DESCRIPTION IPSec Algorithm This field displays the security protocols us ed for an SA. Both AH and ESP increase Prestige processing req uirements and communi cations latency (delay).
Prestige 650 Series User ’ s Guide 16-6 VPN Screens Wi th mai n mo d e (s ee section 16.10.1 ), the ID type and content are encr ypted to provide identity protectio n. In this case the Prestige can only d istinguish between up to eight different incoming SAs that connect from remote IPSec r outers that ha ve dynami c WAN IP ad dresses.
Prestige 650 Series User ’ s Guide VPN Screens 16-7 Table 16-5 Matching ID Ty pe and Content Configuration Exam ple PRESTIGE A PRESTIGE B Local ID type: E-mail Local ID type: IP Local ID content: tom@yourcompany.com Local ID content: 1.1.1.2 Peer ID type: IP Peer ID type: E-mail Peer ID content: 1.
Prestige 650 Series User ’ s Guide 16-8 VPN Screens Figure 16-3 VPN IKE.
Prestige 650 Series User ’ s Guide VPN Screens 16-9 The following table describes the labels in this screen. Table 16-7 VPN IKE LABEL DESCRIPTION IPSec Setup Active Select this check box to activate this VPN policy. Keep Alive Select either Yes or No from the drop-down list box.
Prestige 650 Series User ’ s Guide 16-10 VPN Screens Table 16-7 VPN IKE LABEL DESCRIPTION Local Address Type Use the drop-do wn menu to choose Single , Range , or Subnet . Select Single for a single IP address. Select Range for a specific range of IP address es.
Prestige 650 Series User ’ s Guide VPN Screens 16-1 1 Table 16-7 VPN IKE LABEL DESCRIPTION End / Subnet Mask When the Remote Address Type field is configured to Single , enter the IP address in the IP Address Start field again here.
Prestige 650 Series User ’ s Guide 16-12 VPN Screens Table 16-7 VPN IKE LABEL DESCRIPTION Content When you select IP in the Peer ID Type field, type the IP address of the computer with which you will mak e the VPN connection or leave the fiel d blank to have the Prestige automatically use the address in the Secure Gatew ay Address field.
Prestige 650 Series User ’ s Guide VPN Screens 16-13 Table 16-7 VPN IKE LABEL DESCRIPTION Authentication Algorithm Select SHA1 or MD5 from the drop-down list box. MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm) are hash al gorithms used to authenticate packet data.
Prestige 650 Series User ’ s Guide 16-14 VPN Screens Choose a D iffie-Hellman public-key cryp tography key group ( DH1 or DH2 ) . Set the IKE SA lifetime. This field allows you to determine how long an IKE SA should stay up before it tim es out.
Prestige 650 Series User ’ s Guide VPN Screens 16-15 16.10.3 Perfect Forward Secrecy (PFS) Enabling PFS means that th e key is transient. The key is thrown away and replaced by a brand new key using a new Diffie -Hellma n exchange for eac h new IPSec SA setup.
Prestige 650 Series User ’ s Guide 16-16 VPN Screens Figure 16-5 VPN IKE: Adv anced The following table describes the labels in this screen. Table 16-8 VPN IKE: Advanced LABEL DESCRIPTION VPN - IKE Protocol Enter 1 for ICMP, 6 for TCP, 17 fo r UDP, etc.
Prestige 650 Series User ’ s Guide VPN Screens 16-17 Table 16-8 VPN IKE: Advanced LABEL DESCRIPTION Enable Replay Protection As a VPN setup is processing intensive, the system is vulnerable to De nial of Service (DoS) attacks The IPSec receiver can detect and reject old or dupl icate packets to protect against replay attacks.
Prestige 650 Series User ’ s Guide 16-18 VPN Screens Table 16-8 VPN IKE: Advanced LABEL DESCRIPTION Encryption Algorithm Select DES or 3DES from the drop-do wn list box.
Prestige 650 Series User ’ s Guide VPN Screens 16-19 Table 16-8 VPN IKE: Advanced LABEL DESCRIPTION Authentication Algorithm Select SH A1 or MD5 from the drop-down list box. MD5 (Message Digest 5) and SHA1 (Secure Hash Algorithm) are hash al gorithms used to authenticate packet data.
Prestige 650 Series User ’ s Guide 16-20 VPN Screens Current ZyXEL implement ation assumes identical outgoing and incoming SPIs. 16.13 Configuring Manual Key You only configu re VPN Manual Key when you select Manual in the Key Management field on the VPN IKE screen.
Prestige 650 Series User ’ s Guide VPN Screens 16-21 The following table describes the labels in this screen. Table 16-9 VPN Manual Key LABEL DESCRIPTION IPSec Setup Active Select this check box to activate this VPN policy. Name Type up to 32 characters to identify this VPN polic y.
Prestige 650 Series User ’ s Guide 16-22 VPN Screens Table 16-9 VPN Manual Key LABEL DESCRIPTION IP Address Start When the Local A ddress Type field is configured to Single , enter a (static) IP address on the LAN behind your Prestige.
Prestige 650 Series User ’ s Guide VPN Screens 16-23 Table 16-9 VPN Manual Key LABEL DESCRIPTION My IP Address Enter the WAN IP address of your Prestige. T he Prestige uses its current WAN IP address (static or dynamic) in setting up th e VPN tunnel if you leave this field as 0.
Prestige 650 Series User ’ s Guide 16-24 VPN Screens Table 16-9 VPN Manual Key LABEL DESCRIPTION Apply Click Apply to save your changes back to the Prestige. Cancel Click Cancel to begin configu ring this screen afresh. Delete Click Delete to remove the current rule.
Prestige 650 Series User ’ s Guide VPN Screens 16-25 Figure 16-7 SA Monitor The following table describes the labels in this screen. Table 16-10 SA Monitor LABEL DESCRIPTION No This is the securit y association index number. Name This field displays the identi fication name for this VPN policy.
Prestige 650 Series User ’ s Guide 16-26 VPN Screens Table 16-10 SA Monitor LABEL DESCRIPTION Back Click Back to return to the previous screen. Apply Click Apply to save your changes back to the Prestige. Refresh Click Refresh to disp lay the current active VPN connection (s).
Prestige 650 Series User ’ s Guide VPN Screens 16-27 16.16 Configuring IPSec Logs To view IPSec logs in t his screen, click Advanced Setup , VPN , and then Logs to open the screen shown next. Figure 16-9 VPN Logs The following table describes the labels in this screen.
Prestige 650 Series User ’ s Guide 16-28 VPN Screens Double exclamation marks (!!) d enote an error or warning message. The following table sh ows sample log messages during IKE ke y exchange.
Prestige 650 Series User ’ s Guide VPN Screens 16-29 Table 16-13 Sample IKE Key Exchange Logs LOG MESSAGE DESCRIPTION !! Local / remote IPs of incoming request conflict with rule <#d> If the security gateway is “0.0.0.0”, the Prestige will use the peer’s “Local Addr” as its “Remote Addr”.
Prestige 650 Series User ’ s Guide 16-30 VPN Screens Table 16-14 Sample IPSec Logs During Packet Tra nsmission LOG MESSAGE DESCRIPTION !! Inbound packet authentication failed The authentication configur ation settings are incorrect. Please check them.
Prestige 650 Series User ’ s Guide VPN Screens 16-31 16.17 T elecommuter VPN/IPSec Examples The following examples show how multiple telecommuters can make VPN connections to a single Prestige at headquarters. The telecommu ters use IPSec routers with dynamic WAN IP addresses.
Prestige 650 Series User ’ s Guide 16-32 VPN Screens 16.17.2 T elecommuters Using Unique VPN Rules Example In this example the telecommuters (A, B and C in the figure) use IPSec routers with domain names that are mapped to thei r dynam ic WAN IP addresses (use Dynami c DNS to do this ).
Prestige 650 Series User ’ s Guide VPN Screens 16-33 Table 16-17 Telecommuters Using Unique VPN Rules Example HEADQUARTERS TELECOMMUTERS Local ID Content: bob@bigcompan yhq.com Peer ID T ype: E-mail Peer ID Content: bob@bigcompan yhq.com Headquarters Prestige Rule 1 : Telecommuter A (telecommute ra.
Remote Management, UPnP and Logs VI Part VI: Remote Management, UPnP and Logs This part cont ains information on ho w to configur e the Prestige for remote management, setting up Universal Plug and Play (UPnP) and the logs.
Prestige 650 Series User’s Guide Remote Management Conf iguration 17-1 Chapter 17 Remote Management Configuration This chapter provides information on configuring remote management.
Prestige 650 Series User’s Guide 17-2 Remote Management Conf iguration 17.1.2 Remote Management and NA T When NAT is enabled: Use the Prestige’s WAN IP address wh e n configu ring from the WAN. Use the Prestige’s LAN IP address when configuring from the LAN.
Prestige 650 Series User’s Guide Remote Management Conf iguration 17-3 17.4 Web You can use the Prestige’s em bedded web co nfigurator for c onfiguration a nd file m anagement. See t he online hel p for details. 17.5 Configuring Remote Management Click Remote Management t o open the followi ng screen.
Prestige 650 Series User’s Guide 17-4 Remote Management Conf iguration Table 17-1 Remote Management LA BE L DESCRIPTION Apply Click Apply to save your settings back to the Prestige.
Prestige 650 Series User’s Guide UPnP 18-1 Chapter 18 Universal Plug-and-Play (UPnP) This chapter introduces the UPnP feature in the web configurator. 18.1 Universal Plug and Play Overview Universal Plug and Play (UPnP) is a di stributed, open networki ng standard t hat uses TCP/IP for simple p eer- to-peer networ k connectivity between devi ces.
Prestige 650 Series User’s Guide 18-2 UPnP All UPnP-enabled devices may communicate freely with ea ch other without add itional configur ation. Disable UPnP if this is not your intention. 18.2 UPnP and ZyXEL ZyXEL has achieved UPnP c ertification fro m th e Universal Plug and Pl ay Forum Creates UPnP™ Implem enters Corp.
Prestige 650 Series User’s Guide UPnP 18-3 Allow users to make configuration changes through UPnP Select this check box to allow UPnP-e nabl ed applications to automaticall y configure the Prestige .
Prestige 650 Series User’s Guide 18-4 UPnP Step 3. In the Communications window, select the Universal Plug and Play chec k box in the Components selection box. Step 4. Click OK to go back to the Add/Remove Programs Properties window and click Next .
Prestige 650 Series User’s Guide UPnP 18-5 Step 5. In the Networ king Services window, select the Universal Plu g and Play check box. Step 6. Click OK to go back to the Windows Optional Ne tworking C omponent Wizard window and click Next . 18.4 Using UPnP in Windows XP Example This section sh ows you how t o use the UP nP feature in Windows XP.
Prestige 650 Series User’s Guide 18-6 UPnP Step 3. In the Internet Connection P roperties window, click Settings to see the port mappings there were a utomatically created. Step 4. You may edit or delete the port mappings or cli ck Add to manually add port m appings.
Prestige 650 Series User’s Guide UPnP 18-7 Step 6. Double-click on the icon to display your current Internet connection status. 18.4.2 W eb Configurator Easy Access With UPnP, you can access the web-base d configurator on the Prestige without finding out the IP address of the Prestige first.
Prestige 650 Series User’s Guide 18-8 UPnP Step 4. An icon with the description for each UPnP-enabl ed device displa ys under Local Network . Step 5. Right-click on the icon for your Prestige and select Invoke . The web configurator login screen displ ays.
Prestige 650 Series User’s Guide Logs Screens 19-1 Chapter 19 Logs Screens This chapter contains informa tion about configuring general log s ettings and viewing the Prestige’s logs. This chapter is only applicable to P650H-E. Refer to the appendices for example log message explanations.
Prestige 650 Series User’s Guide 19-2 Logs Screens Figure 19-1 Log Settings The following table describes the labels in this screen..
Prestige 650 Series User’s Guide Logs Screens 19-3 Table 19-1 Log Settings LABEL DESCRIPTION Address Info Mail Server Enter the server name or the IP addr ess of the mail server for the e-mail address es specified below. If this field is left blank, logs and alert messages will not be sent via e-mail.
Prestige 650 Series User’s Guide 19-4 Logs Screens Table 19-1 Log Settings LABEL DESCRIPTION Log Select the categories of logs that y ou want to record. Logs include alerts. Send Immediate Alert Select the categories of alerts for which you want the Prestige to instantly e-mail alerts to the e-mail address specified in th e Send A lerts To field.
Prestige 650 Series User’s Guide Logs Screens 19-5 Table 19-2 View Logs LABEL DESCRIPTION Display The categories that you select in the Log Settings screen (see section 19.
Prestige 650 Series User’s Guide 19-6 Logs Screens Table 19-3 SMTP Error Messages -6 means RCPT TO fail -7 means DATA fail -8 means mail data send fail 19.4.1 Example E-mail Log An "End of Log" message dis plays for each mail in whic h a complete log has been sent.
Bandwidth Management VII Part VII: Bandwidth Management This part prov ides information on the functi ons and configuratio n of Bandwidth M anagement..
.
Prestige 650 Series User’s Guide Bandwidth Management 20-1 Chapter 20 Bandwidth Management This chapter describes the functions and configur ation of bandwidth management.
Prestige 650 Series User’s Guide 20-2 Bandwidth Management The total of the configured ba ndwidth budgets for child-classes cannot e xceed the configure d bandwidth budget speed of the parent class.
Prestige 650 Series User’s Guide Bandwidth Management 20-3 Figure 20-2 Subnet-based Band width Management Example 20.4.3 Application and Subnet-based Bandwid th Management Example The following example uses bandwidth classes based on LAN subnets and a pplications (specific applications in each subnet are allotted bandwidt h).
Prestige 650 Series User’s Guide 20-4 Bandwidth Management Figure 20-3 Application and Subnet-based Bandwidth Management Example 20.5 Scheduler The schedule r divides up an interface’s bandwidth am ong the ban dwidth classes. T he Prestige has two types of scheduler: fairness-based and priority-based .
Prestige 650 Series User’s Guide Bandwidth Management 20-5 and on their priority levels. When only one class requires m ore ba n dwidth, the Prest ige gives extra bandwidth to that class.
Prestige 650 Series User’s Guide 20-6 Bandwidth Management The following fig ure shows the bandwidth usage with the maxim ize bandwidth usage option enabled. The Prestige divide s up the unb udgeted 2 Mbps a mong the class es that require m ore bandwidth.
Prestige 650 Series User’s Guide Bandwidth Management 20-7 20.7 Bandwid th Borrowing Bandwidth borrowing allows a child-class to borrow unused band width from its parent cl ass, whereas maximize bandwidth usag e allows bandwidth classes to borrow an y unused or unbudgeted bandw idth on the whole interface.
Prestige 650 Series User’s Guide 20-8 Bandwidth Management Figure 20-6 Bandwidth Borrowing Example The Bill class can borrow unused bandwidth from the Sales USA class because the Bill class has bandwidth borro wing enabled.
Prestige 650 Series User’s Guide Bandwidth Management 20-9 The Bill class cannot borrow unused bandwidth from the Root class b ecause the Sales class has bandwidth b orrowing disa bled. The Amy class cannot borrow u nused bandw idth fr om the Sales USA class because t he Amy class has bandwidt h borrowin g disabled.
Prestige 650 Series User’s Guide 20-10 Bandwidth Management Figure 20-7 Bandwidth Manager: Summary The following table describes the labels in this screen. Table 20-2 Bandwidth Manager: Summary LABEL DESCRIPTION LAN WLAN WAN These read-only labels repres ent the physical interfaces.
Prestige 650 Series User’s Guide Bandwidth Management 20-11 Table 20-2 Bandwidth Manager: Summary LABEL DESCRIPTION Scheduler Select either Priority-Based or Fairness-Based from the drop-do wn menu to control the traffic flow. Select Priority-Based to give preferenc e to bandwidth classes with higher priorities.
Prestige 650 Series User’s Guide 20-12 Bandwidth Management Figure 20-8 Band width Manager: Class Setup The following table describes the labels in this screen. Table 20-3 Bandwidth Manager: Class Setup LABEL DESCRIPTION Interface Select an interface from the drop-d own li st box for which you wish to set up classes.
Prestige 650 Series User’s Guide Bandwidth Management 20-13 20.9.1 Bandwid th Manager Class Configuration Configure a bandwidt h managem ent class in the Class Configuration screen. You m ust use the Bandwidth Manager - Summary screen to enable bandwidth m anagement on an int erface before y ou can configure classes for that interface.
Prestige 650 Series User’s Guide 20-14 Bandwidth Management Table 20-4 Bandwidth Manager: Class Configuration LABEL DESCRIPTION Class Name Use the aut o-generated name or enter a des criptive name of up to 20 alphanumeric characters, inclu ding spaces.
Prestige 650 Series User’s Guide Bandwidth Management 20-15 Table 20-4 Bandwidth Manager: Class Configuration LABEL DESCRIPTION Destination Port Enter the port number of t he destination. A blank destination port means any destination port. Source IP Address Enter the sourc e IP address.
Prestige 650 Series User’s Guide 20-16 Bandwidth Management 20.9.2 Bandwid th Management St atistics Use the Bandwidth Management Statistics screen t o view networ k perform ance informat ion. Click t he Statistics button in the Class Setup screen to open t he Statistics screen.
Prestige 650 Series User’s Guide Bandwidth Management 20-17 Table 20-6 Bandwidth Management Statistics LABEL DESCRIPTION Set Interval Click Set Interval to apply the new update period you ent ered in the Update Period field above. Stop Update Click Stop Update to stop the browser from refreshing bandwidth management statistics.
Prestige 650 Series User’s Guide 20-18 Bandwidth Management Table 20-7 Bandwidth Manager Monitor LABEL DESCRIPTION Back Click Back to go to the main BW Manager screen.
Maintenance VIII Part VIII: Maintenance This part covers the m aintenance screens..
.
Prestige 650 Series User’s Guide Maintenance 21-1 Chapter 21 Maintenance This chapter displays system information such as ZyNOS firmware, port IP addresses and port traffic statistics. 21.1 Maintenance Overview Use the maintenance screens to view system informa tion, upload new firmware, m anage configuratio n and restart your Prestige.
Prestige 650 Series User’s Guide 21-2 Maintenance Figure 21-1 System Status The following table describes the labels in this screen..
Prestige 650 Series User’s Guide Maintenance 21-3 Table 21-1 System Status LA BE L DESCRIPTION System Status Syst em Na me This is the name of your Prestige. It is for identification purp oses. ZyNOS F/W Version This is the ZyNOS firmware version and the date created.
Prestige 650 Series User’s Guide 21-4 Maintenance Table 21-1 System Status LA BE L DESCRIPTION Show Statistics Click Show Statistics to see router performance statistics such as number of packets sent and number of packets received for each port. 21.
Prestige 650 Series User’s Guide Maintenance 21-5 The following table describes the labels in this screen. Table 21-2 System Status: Sho w Statistics LA BE L DESCRIPTION System up Time T his is the elap sed time the system has been up. CPU Load This field specifies the per centage of CPU utilization.
Prestige 650 Series User’s Guide 21-6 Maintenance Table 21-2 System Status: Sho w Statistics LA BE L DESCRIPTION Collisions This is the number of coll isions on this port. Poll Interval(s) Type the time interval for the bro wser to refresh system statistics.
Prestige 650 Series User’s Guide Maintenance 21-7 Table 21-3 DHCP Table LA BE L DESCRIPTION Host Name This is the name of the host computer. IP Address This field displays the IP address relative to the Host Name field. MAC Address This field displays the MAC (Media Access Contro l) addr ess of the comput er with the displayed host name.
Prestige 650 Series User’s Guide 21-8 Maintenance Table 21-4 Association List LA BE L DESCRIPTION # This is the index number of an associate d wireless client. MAC Address This field displays the MAC (Media Access Contro l) address of an associated wireless station.
Prestige 650 Series User’s Guide Maintenance 21-9 The following table describes the labels in this screen. Table 21-5 Channel Usage Table LA BE L DESCRIPTION Channel This is the inde x number of the channel. IP Address This field displays Yes if another AP or Ad-h oc network is using the channel within the Prestige’s transmission range.
Prestige 650 Series User’s Guide 21-10 Maintenance Figure 21-7 Diagnostic General The following table describes the labels in this screen. Table 21-6 Diagnostic General LA BE L DESCRIPTION TCP/ IP Address Type the IP address of a computer that you wa nt to ping in order to test a connection.
Prestige 650 Series User’s Guide Maintenance 21-11 Table 21-6 Diagnostic General LA BE L DESCRIPTION Back Click this button to go back to the main Diagnostic screen. 21.5.2 Diagnostic DSL Line Screen Click Diagnostic and then DSL Line to open the screen sh own next.
Prestige 650 Series User’s Guide 21-12 Maintenance Table 21-7 Diagnostic DSL Line LA BE L DESCRIPTION Reset ADSL Line Click this button to reinitialize the ADSL line. The large text bo x above then displays the progress and results of this operation, for e xample: "Start to reset ADSL Loading ADSL modem F/W.
Prestige 650 Series User’s Guide Maintenance 21-13 Figure 21-9 Firm ware Upgrade The following table describes the labels in this screen. Table 21-8 Firmware Upgrade LA BE L DESCRIPTION File Path Type in the location of the file you want to upload i n this field or click Browse .
Prestige 650 Series User’s Guide 21-14 Maintenance Figure 21-10 Net work Temporarily Disconnected After two m inutes, log in again an d check you r new firm ware version in the System Status sc reen. If the upload was not successful, the fo llowing screen will appear.
Prestige 650 Series User’s Guide Maintenance 21-15 Figure 21-12 Backup Configura tion 21.7.2 Restore Configuration Restore confi guration replace s your Pr estige 's current configuration (firew all settings, etc.) with a previou sly saved config uration.
Prestige 650 Series User’s Guide 21-16 Maintenance Table 21-9 Restore Confi guration LA BE L DESCRIPTION File Path Type in the location of the file you want to upload i n this field or click Browse ... to find it. Browse... Click Browse... to find the file yo u want to upload.
Prestige 650 Series User’s Guide Maintenance 21-17 If you uploaded the d efault configuration file you may need to change t he IP addre ss of you r computer to be in the same subnet as that o f the defaul t Prestige IP ad dress (192.168 .1.1). See the a ppendix for details on how to set u p your com puter’s IP ad dress.
Prestige 650 Series User’s Guide 21-18 Maintenance The following warning screen will appear. Figure 21-18 Reset Warni ng Message You can also press the RESET button on the side panel to reset the fact ory defaults of your Prestige. Refer to the Resetting the Prestige section for more inf ormation on the RE SET but ton.
SMT General Configuration IX Part IX: SMT General Configuration This part covers System Manag ement T erminal configuration for general setup, LAN setup, wireless LAN setup, Internet acce ss, remote nodes, remote node TCP/IP , static routing an d NA T .
.
Prestige 650 Series User’s Guide Introducing the SMT 22-1 Chapter 22 Introducing the SMT This chapter explains how to access and navigate the System Management Terminal and gives an overview of its menus.
Prestige 650 Series User’s Guide 22-2 Introducing the SMT Please note that if there is no activity for longer than five minutes after you log in, your Prestige will automatically log you out. Figure 22-1 Login Screen 22.1.4 Prestige SM T Menu Overview We use the Pre stige 650H/H W-31 SMT m enus in this guide as an e xample.
Prestige 650 Series User’s Guide Introducing the SMT 22-3 Menu 3 LAN Set up Menu 4 Internet Acces s Setu p Menu 1 2 S tatic Routi ng Setup Menu 1 1 .5 Remote Node Filter Menu 1 1 Remote Node Setup Menu 1 1.3 Re mote N ode N etwo r k Layer Option s Menu 3.
Prestige 650 Series User’s Guide 22-4 Introducing the SMT 22.2 Navigating the SMT Interface The SMT (System Management Terminal) is the inte rface that you use t o co nfigure your Pr estige. Several operations that you should be familiar with before you attempt to modify the configuration are listed in the table below.
Prestige 650 Series User’s Guide Introducing the SMT 22-5 Figure 22-3 SMT Main Menu for P650H/HW-31 22.2.1 System Management T erminal Interface Summar y Table 22-2 Main Menu Summary for P650 H/HW-31 # MENU TITLE DESCRIPTION 1 Genera l Setup Use this menu to set up your general information.
Prestige 650 Series User’s Guide 22-6 Introducing the SMT Table 22-2 Main Menu Summary for P650 H/HW-31 # MENU TITLE DESCRIPTION 25 IP Routing P olicy Setup Use this menu to configur e your IP routing policy. 26 Sched ule Setup Use this menu to schedule outgoing cal ls.
Prestige 650 Series User’s Guide General Setup 23-1 Chapter 23 General Setup Menu 1 - General Setup contains administrative and system-related information. 23.1 General Setup Menu 1 — General Se tup contains a dministrat ive and system -related in formation ( shown next ).
Prestige 650 Series User’s Guide 23-2 General Setup Figure 23-1 Menu 1 General Setup Fill in the required fields. Refer to the table shown next for more information about these fields. Table 23-1 Menu 1 General Setup FIELD DESCRIPTION EX AMPLE System Name Enter a descriptive name for identificatio n purposes.
Prestige 650 Series User’s Guide General Setup 23-3 23.2.1 Configuring Dynamic DNS If you have a private W AN IP address , then you cannot use Dynamic DNS. To configure Dynamic DNS , go to Menu 1 — Ge neral Setup and select Yes in the Edit Dynamic DNS field.
.
Prestige 650 Series User’s Guide LAN Setup 24-1 Chapter 24 LAN Setup This chapter covers how to configure your wired Local Area Network (LAN) settings. 24.1 LAN Setup This section describes how to configure the Ethern et using Menu 3 — LAN Setup .
Prestige 650 Series User’s Guide 24-2 LAN Setup 24.2 Protocol Dependent Ethernet Setup Depending on the protoc ols for your a pplications, you need to con figure the res pective Ethernet Set up, as outlined b elow. For TCP/IP Ethernet setup refer to the Internet Access Application chapter.
Prestige 650 Series User’s Guide LAN Setup 24-3 Table 24-1 DHCP Ethernet Setup Menu Fields FIELD DESCRIPTION EX AMPLE DHCP Setup DHCP If set to Server , your Prestige can assign IP addresses, an IP default gateway and DNS servers to Windo ws 95, Windows NT and other systems that support the DHCP client.
Prestige 650 Series User’s Guide 24-4 LAN Setup Table 24-2 TCP/IP Ethernet Setup Me nu Fields FIELD DESCRIPTION EXAMPLE Multicast IGMP (Internet Group Multicast Pr otocol) is a network-layer protocol used to establish membership in a Multic ast group.
Prestige 650 Series User’s Guide Wireless LAN Setup 25-1 Chapter 25 Wireless LAN Setup This chapter covers how to configure wireless LAN settings in SMT menu 3.
Prestige 650 Series User’s Guide 25-2 Wireless LAN Setup Figure 25-1 Menu 3.5 - Wireless LAN Setup The following table describes the fields in this menu. Table 25-1 Wireless LAN Setup Field Description FIELD DESCRIPTION EXAMPLE ESSID The ESSID (Extended Service Set IDentifie r) identifies the service set the wireless station is to connect to.
Prestige 650 Series User’s Guide Wireless LAN Setup 25-3 Table 25-1 Wireless LAN Setup Field Description FIELD DESCRIPTION EXAMPLE WEP WEP (Wired Equivalent Privac y) provides data encryption to prevent wireless stations from accessing data transmitted over the wireless network.
Prestige 650 Series User’s Guide 25-4 Wireless LAN Setup Figure 25-2 Menu 3.5.1 WLAN M AC Address Filtering The following table describes the fields in this menu. Table 25-2 Menu 3.5.1 WLAN M AC Address Filtering FIELD DESCRIPTION Active To enable MAC address filter ing, press [SPACE BAR] to select Yes and press [ENTER].
Prestige 650 Series User’s Guide Internet Access 26-1 Chapter 26 Internet Access This chapter show s you how to configure the LA N an d WAN of your Prestige for Internet access .
Prestige 650 Series User’s Guide 26-2 Internet Access Figure 26-1 Ph ysical Network Figure 26-2 Partitioned Logical Networks Use menu 3. 2.1 to confi gure IP Alia s on your Prest ige. 26.4 IP Alias Setup Use menu 3. 2 to confi gure the first networ k.
Prestige 650 Series User’s Guide Internet Access 26-3 Figure 26-3 Menu 3.2 TCP/IP and DHCP Setup Pressing [ ENTER ] displays Menu 3.2.1 — IP Alias Setup , as shown next. Figure 26-4 Menu 3.2.1 IP Alias Setup Follow the instructions in the following table to configu re IP Alias parameters.
Prestige 650 Series User’s Guide 26-4 Internet Access Table 26-1 Menu 3.2.1 IP Alias Setup FIELD DESCRIPTION EXAMPLE IP Alias Choose Yes to configure the LAN net work for the Prestige. Yes IP Address Enter the IP address of your Prestige in dotted decimal not ation 192.
Prestige 650 Series User’s Guide Internet Access 26-5 26.6 Internet Access Configuration Menu 4 allows you to enter the In ternet Access information in one screen. Menu 4 is actually a simplified setup for one of the remote nodes that you ca n access in menu 11.
Prestige 650 Series User’s Guide 26-6 Internet Access Table 26-2 Menu 4 Internet Ac cess Setup FIELD DESCRIPTION EXAMPLE Multiplexing Press [ SPACE BAR ] to select the method of multiplexing used by your ISP. Choices are VC-based or LLC-based . LLC-based VPI # Enter the Virtual Path Identi fier (VPI) assign ed to you.
Prestige 650 Series User’s Guide Internet Access 26-7 Table 26-2 Menu 4 Internet Ac cess Setup FIELD DESCRIPTION EXAMPLE Network Address Translation Press [ SPACE BAR ] to select None , SUA Only or Ful l Feature . Please see the NAT Chapter for more details on the SUA (Single User Account) feature.
.
Prestige 650 Series User’s Guide Remote Node Configuration 27-1 Chapter 27 Remote Node Configuration This chapter covers remote node configuration. 27.1 Remote Node Setup Overview This section describes the protocol-i ndependent parame ters for a rem ote node.
Prestige 650 Series User’s Guide 27-2 Remote Node Configuration Figure 27-1 Menu 11 Remote No de Setup 27.2.2 Encap sulation and Multiplexing Scenarios For Internet access you sho uld use the encapsulation and multiplex ing methods used by your ISP.
Prestige 650 Series User’s Guide Remote Node Configuration 27-3 Figure 27-2 Menu 11.1 Remote Node Profile In Menu 11.1 – Rem ote Node Profile , fill in the fields as described in the following table.
Prestige 650 Series User’s Guide 27-4 Remote Node Configuration Table 27-1 Menu 11.1 Remote Node Profile FIELD DESCRIPTION EXAMPLE Rem Login Type the login name that this remote node will use to call yo ur Prestige. The login name and the Rem Password will be used to authenticate this node.
Prestige 650 Series User’s Guide Remote Node Configuration 27-5 Table 27-1 Menu 11.1 Remote Node Profile FIELD DESCRIPTION EXAMPLE Schedule Sets T his field is only applicable for PPPoE and PPPoA encapsulation. You can apply up to four schedule sets here.
Prestige 650 Series User’s Guide 27-6 Remote Node Configuration minimum of "1" for directl y connected net works. The number m ust be between "1" and "15"; a n umber greater than "15" means the link is down. The smaller the number, the lower the "cost".
Prestige 650 Series User’s Guide Remote Node Configuration 27-7 Figure 27-3 Menu 11.3 Remote Node Net work Layer Options The next table explain s fields in Menu 11.
Prestige 650 Series User’s Guide 27-8 Remote Node Configuration Table 27-2 Menu 11.3 Remote Node Network Layer Options FIELD DESCRIPTION EXAMPLE Address Mapping Set When Full Feature is selected in the NA T field, configure address mapping sets in menu 15.
Prestige 650 Series User’s Guide Remote Node Configuration 27-9 Figure 27-4 Sample IP Addresses for a TCP/IP LAN-to-LAN Connection 27.5 Remote Node Filter Move the cur sor to the Edit Filter Sets fiel d in m enu 11.1, the n press [SPACE BAR] to select Yes .
Prestige 650 Series User’s Guide 27-10 Remote Node Configurati on Figure 27-5 Menu 11.5 Remote Node Filter (RFC 1 483 or ENET Encapsulation) Figure 27-6 Menu 11.5 Remote Node Filter (PPPoA or PPPoE Encapsulati on) 27.5.1 W eb Configurator Intern et Security Filter Rules In the web configu rator, open th e Security screen as shown next.
Prestige 650 Series User’s Guide Remote Node Configuration 27-11 Figure 27-7 Internet Security Once you apply the filter rules in the web configurator, filter sets 11 and 12 are automatically applied in the protocol filter s field unde r Input Filter Sets in SMT m enu 11.
Prestige 650 Series User’s Guide 27-12 Remote Node Configurati on Figure 27-8 Menu 21- Filer Set Co nfiguration (P650R an d P650R-E) The following figures display the filter rules in filter sets 11 and 12. Figure 27-9 Menu 21.11- WebSe t 11 Figure 27-10 Menu 21.
Prestige 650 Series User’s Guide Remote Node Configuration 27-13 Do not edit filter set s 1 1 and 12. They are used exc lusively by the web configurator . Any rules you configured in sets 1 1 and 12 will be erased and replaced when you apply the web configurator-generated filter rules.
Prestige 650 Series User’s Guide 27-14 Remote Node Configurati on Figure 27-12 Menu 11.6 for LLC-based Multiplexing or PPP Encapsulation In this case, only one set of VPI and VC I num bers need be specifi ed for all pr otocols.
Prestige 650 Series User’s Guide Remote Node Configuration 27-15 The followin g network t opology all ows you t o avoi d triangl e route security issues when the backup gateway is connected to the LAN. Use IP alias to conf igure the LAN into two or three logical networks with the Prestige itself as the gateway for each LAN net work.
Prestige 650 Series User’s Guide 27-16 Remote Node Configurati on Figure 27-15 Menu 11.1 – Remote No de Profile To configure traffic redi rect properties, press [SPACE BAR] to select Yes in the Edit Traffic Redirec t field an d then pr ess [ENTER].
Prestige 650 Series User’s Guide Remote Node Configuration 27-17 Figure 27-16 Menu 11.7 Traffic Redire ct Setup The following table describes the fields in this menu. Table 27-4 Menu 11.7 Traffic Redirect Setup FIELD DESCRIPTION Active Press [SPACE BAR] and sele ct Yes (to enable) or No (to disable) traffic redirect setup.
.
Prestige 650 Series User’s Guide Static Route Setup 28-1 Chapter 28 Static Route Setup This chapter shows how to setup IP static routes. 28.1 IP S t atic Route Overview Static routes tell the Prestige routing information th at it cannot learn au tomati cally through other m eans.
Prestige 650 Series User’s Guide 28-2 Static Route Setup 28.2 Configuring an IP st atic route Step 1. To configure an IP static route, use Menu 12 – Static Route Setup (show n next). Figure 28-2 Menu 12 Static Route Setup Step 2. From m enu 12, select 1 t o open Menu 12.
Prestige 650 Series User’s Guide Static Route Setup 28-3 Figure 28-4 Menu12.1.1 Edit IP Static Route The following table describes the fields for Menu 12.1.1 – Edit IP Stat ic Route Setup . Table 28-1 Menu12.1.1 Edit IP Static Route FIELD DESCRIPTION Route # This is the index number of the static route that y ou ch ose in menu 12.
Prestige 650 Series User’s Guide 28-4 Static Route Setup Table 28-1 Menu12.1.1 Edit IP Static Route FIELD DESCRIPTION Private T his parameter determine s if the Prestige will include the route to this remote node in its RIP broadcasts. If set to Yes , this route is kept private and is not included in RIP broadcasts.
Prestige 650 Series User’s Guide Bridging Setup 29-1 Chapter 29 Bridging Setup This chapter shows you how to configure th e bridging parameters of your Prestige. 29.1 Bridging Overview Bridging ba ses the forwa rding decisi on on the MAC (M edia Access C ontrol), or hardware a ddress, while routing does it on the net work layer ( IP) address.
Prestige 650 Series User’s Guide 29-2 Bridging Setup Figure 29-1 Menu 11.1 Remote Node Profile Step 2. Move the cur sor to the Edit IP/Bridge field, then press [ SPACE BAR ] to set the value to Yes and press [ENTER] to edit Menu 11.3 – Remote Node Network Layer Options .
Prestige 650 Series User’s Guide Bridging Setup 29-3 Table 29-1 Menu 11.3 Remote Node Network Layer Options : Bridge Field s FIELD DESCRIPTION Bridge (menu 11.1) Make sure this field is set to Yes . Edit IP/Bridge (menu 11.1) Press [SPACE BAR] to select Yes and press [ENTER] to display menu 1 1.
Prestige 650 Series User’s Guide 29-4 Bridging Setup The following table describes the Edit Bridg e Static Route menu. Table 29-2 Menu 12.3.1 Edit Bridge Static Ro ute FIELD DESCRIPTION Route # This is the route inde x number you typed in Menu 12.3 – Brid ge Static Route Setup .
Prestige 650 Series User’s Guide NAT 30-1 Chapter 30 Network Address Translation (NAT) This chapter discusses h ow to configure NAT on the Prestige. 30.1 NA T Overview 30.1.1 SUA (Single User Account) V ersus NA T SUA (Single User Account) is a ZyNOS implementati on of a su bset of NAT that supports two types of mapping, Many-to-One and Serv er .
Prestige 650 Series User’s Guide 30-2 NAT Figure 30-1 Menu 4 Apply ing NAT for Internet Access The following fi gure shows how you appl y NAT to the rem ote node in menu 11.1 . Step 1. Enter 11 from the main menu. Step 2. When menu 11 appears, as shown in the following figure, t ype the num ber of the rem ote node that you want to conf igure.
Prestige 650 Series User’s Guide NAT 30-3 Figure 30-2 Menu 11.3 Apply ing NAT to the Remote Node The following table describes the op tions for Network Address Translation.
Prestige 650 Series User’s Guide 30-4 NAT The server set is a list of LA N servers mapped to external ports. T o use this set, a server rule must be set up inside the NAT address m apping set. Please see the secti on on po rt forwardi ng in the c hapter on N AT web configurator screens for further in formati on on these m enus.
Prestige 650 Series User’s Guide NAT 30-5 Figure 30-5 Menu 15.1.255 SUA Addr ess Mapping Rules The following table explains the fields in this menu. Menu 15.1.255 is read-only . Table 30-2 SUA Address Mapping Rules FIELD DESCRIPTION EXAMPLE Set Name This is the name of the set you selected in menu 15.
Prestige 650 Series User’s Guide 30-6 NAT Table 30-2 SUA Address Mapping Rules FIELD DESCRIPTION EXAMPLE When you have compl eted this menu, press [ENTER] at the prompt “Press ENTER to confirm or ESC to cancel” to save your configuration or press [E SC] to cancel and go back to the prev ious screen.
Prestige 650 Series User’s Guide NAT 30-7 up by that number of empty rules. For example, if you have already conf igured rules 1 to 6 in your curr ent set and now you configure rule number 9. In the set su mmary screen, the new rule will be rule 7, not 9.
Prestige 650 Series User’s Guide 30-8 NAT Figure 30-7 Menu 15.1.1.1 Editing/Co nfiguring an Individual Rule in a Set The following table explains the fields in this menu.
Prestige 650 Series User’s Guide NAT 30-9 Table 30-4 Menu 15.1.1.1 Editing/Conf iguring an Individual Rule in a Set FIELD DESCRIPTION EXAMPLE Server Mapping Set Only available when Type is set to Server . Ty pe a number from 1 to 10 to choose a server set from menu 15.
Prestige 650 Series User’s Guide 30-10 NAT Figure 30-9 Menu 15.2.1 NAT Serv er Setup Step 4. Enter a port number in an unused Start Port No field. To forwar d only one port, en ter it again in the End Port No field. To specify a range of ports, e nte r the last port to be forwarded in the End Port No field.
Prestige 650 Series User’s Guide NAT 30-11 Figure 30-10 Multiple Servers Behind NAT Ex ample 30.5 General NA T Examples The following are some exampl es of NAT configurati on.
Prestige 650 Series User’s Guide 30-12 NAT Figure 30-11 NAT Example 1 Figure 30-12 Menu 4 Internet Access & NAT Example From m enu 4, choose t he SUA Onl y option from the Network Address Translation field. This is the Many-to-O ne mapping discussed i n section 30.
Prestige 650 Series User’s Guide NAT 30-13 30.5.2 Example 2: Internet A ccess w ith an Inside Server Figure 30-13 NAT Example 2 In this case, you do exactly as above (use the conve nient pre-configured S UA Only set) and also go to menu 15.2 to specify t he Inside Se rver behind the NAT as sho wn in the next figure.
Prestige 650 Series User’s Guide 30-14 NAT 30.5.3 Example 3: Multip le Public IP Addresses With Inside Servers In this exam ple, there ar e 3 IGAs from our ISP. T here are many department s but two ha ve their ow n FTP server. All departments share the same router.
Prestige 650 Series User’s Guide NAT 30-15 Step 5. Select Type as One-to-One (di rect mapping fo r packets going bot h ways) , and enter the local Start IP as 192.168.1.10 (th e IP address of FTP Server 1), th e global Start I P as 10.132.50.1 (our first IGA).
Prestige 650 Series User’s Guide 30-16 NAT Figure 30-18 Example 3: Final Menu 15.1.1 Now conf igure th e IGA3 to map to our web serv er and ma il serv er on the LA N. Step 8. Enter 15 from the main menu. Step 9. Enter 2 in Menu 15 - NAT Setup . Step 10.
Prestige 650 Series User’s Guide NAT 30-17 30.5.4 Example 4: NA T Unfr iendly Application Programs Some applications do not supp ort NAT Mapping using TC P or UDP port address translation.
Prestige 650 Series User’s Guide 30-18 NAT Figure 30-20 Example 4: Menu 15.1.1.1 Address M apping Rule After you’ve configured your rule, you should b e able to check the settings in menu 15.1.1 as shown next. Figure 30-21 Example 4: Menu 15.1.1 Address Ma pping Rules Menu 15.
SMT Advanced Management X Part X: SMT Advanced Management This part discusse s filtering se tup, SNMP , system security , sy stem information and diagnosis, firmware and configuration file maintenance, sy stem maintenan ce, remote management, IP policy routing and call scheduling.
.
Prestige 650 Series User’s Guide Filter Configuration 31-1 Chapter 31 Filter Configuration This chapter shows you how to create and apply filters. 31.1 About Filtering Your Prestige uses filters to decide whether or not to allow passage of a data packet and/or to make a call.
Prestige 650 Series User’s Guide 31-2 Filter Configuration Figure 31-1 Outgoing Packet Filtering Process Two sets of factory filter rules have been configured in menu 21 to prevent NetBIOS traffic from triggering calls. A summary of their filter rules is shown in the figures that follow.
Prestige 650 Series User’s Guide Filter Configuration 31-3 Start Fetch First Filter Set Fetch First Filter Rule Active? Execute Filter Rule Fetch Next Filter Rule Next filter Rule Available? Fetch N.
Prestige 650 Series User’s Guide 31-4 Filter Configuration For incoming packets, your Prestige ap plies data filters only. Packets are p rocessed depending on whether a match is found. The following section s describe how to configure filter sets. The Filter Structur e of the Prestige A filter set consists of one or more filter rules.
Prestige 650 Series User’s Guide Filter Configuration 31-5 Step 5. Press [ENTER] at the message “ Press ENTER to confirm …” to display Menu 21.
Prestige 650 Series User’s Guide 31-6 Filter Configuration 31.3 Configuring a Filter Set for the Prestige 650R and the Prestige 650R-E To configure a filter set, follow the steps sh own next. Step 1. Enter 21 in the main menu to disp lay Menu 21 – Filter S et Configuration .
Prestige 650 Series User’s Guide Filter Configuration 31-7 Figure 31-8 TELNET_WAN Filter Rules Summary Figure 31-9 PPPoE Filter Rules Summary Figure 31-10 FTP_WAN Filter Rules Summary Menu 21.
Prestige 650 Series User’s Guide 31-8 Filter Configuration 31.3.1 Filter Rules Summary Menus The following tables briefly describe the abbreviations used in menu 21.1.x. Table 31-1 Abbreviations Used in the Filter Rules Summary Menu FIELD DESCRIPTION # The filter rule number: 1 to 6.
Prestige 650 Series User’s Guide Filter Configuration 31-9 Table 31-2 Rule Abbreviations Used FILTER TYPE DESCRIPTION Off Offset Len Length 31.4 Configuring a Filter Rule To configure a filter rule, type its number in Menu 21.1.x – F ilter Rules Summary and press [ENTER] to open me nu 21.
Prestige 650 Series User’s Guide 31-10 Filter Configuration Figure 31-11 Menu 21.1.x.1 TCP/IP Filter Rule The following table describes how to con figure your TCP/IP filter rule.
Prestige 650 Series User’s Guide Filter Configuration 31-11 Table 31-3 Menu 21.1.x.1 TCP/IP Filter Rule FIELD DESCRIPTION EXAMPLE IP Addr Type the destination IP address of the packet you want to filter. This field is igno red if it is 0.0.0.0. IP address IP Mask Type the IP mask to apply to the Destination: IP Addr field.
Prestige 650 Series User’s Guide 31-12 Filter Configuration Table 31-3 Menu 21.1.x.1 TCP/IP Filter Rule FIELD DESCRIPTION EXAMPLE Log Select the logging option from the follo wing: None – No packets will be logged. Action Matched – Only packets that match the rule parameters will be logged.
Prestige 650 Series User’s Guide Filter Configuration 31-13 Packet into IP Filter Matched Matched Yes Action Matched Action Not Matched More? No Filter Active? Check IP Protocol Drop Drop Packet Acc.
Prestige 650 Series User’s Guide 31-14 Filter Configuration 31.4.2 Generic Filter Rule This section shows you how to co nfigure a generic filte r rule. The purpose of generic rules is to allow you to filter non-IP packets. For IP, it is generally easier to use the IP rules directly.
Prestige 650 Series User’s Guide Filter Configuration 31-15 Table 31-4 Menu 21.1.6.1 Generic Filter Rule FIELD DESCRIPTION EXAMPLE Filter # This is the filter se t, filter rule coordinates, for instance, 2, 3 refers to the second filter set and the third rule of that set.
Prestige 650 Series User’s Guide 31-16 Filter Configuration 31.5 Filter T ypes and NA T There are two classe s of filter rules, Generic Filter Device rules and Protocol Filter ( TCP/IP ) rules. Generic Filter rules act on the raw data from/to LAN and WAN.
Prestige 650 Series User’s Guide Filter Configuration 31-17 Figure 31-15 Sample Telnet Filter Step 1. Enter 1 i n menu 21 to displ ay Menu 21.1 — Filter Set Configuration . Step 2. Enter the index number of the filter set you want to configure (in this case 6) .
Prestige 650 Series User’s Guide 31-18 Filter Configuration Step 4. Press [ENTER] at the message “ Press [ENTER] to confirm or [ESC] to cancel” to open Menu 21.6 — Filter Rules Summary . Step 5. Type 1 to configure the first filter rule. Make the entries in this menu as shown next.
Prestige 650 Series User’s Guide Filter Configuration 31-19 Figure 31-17 Menu 21.1.6 Sample Filter Rules Summary After you have created the filter set, you must apply it. Step 1. Enter 11 in the main menu to display menu 11 and typ e the remote node number to edit.
Prestige 650 Series User’s Guide 31-20 Filter Configuration Table 31-5 Filter Sets Table FILTER SETS DESCRIPTION Input Filter Sets: Apply filters for incoming traffic. You may apply protocol or devic e filter rules. See earlier in this chapter for information on filters.
Prestige 650 Series User’s Guide Filter Configuration 31-21 Figure 31-19 Filtering Remote Node T raffic Note that call filter sets are visible when you select PPPoA or PPPoE encapsulation.
.
Prestige 650 Series User’s Guide Enabling the Firewall 32-1 Chapter 32 Enabling the Firewall This chapter show s you how to get started with the Prestige firewall. Firewall a pplies to the Prestige 650H/HW. 32.1 Remote Management and the Firewall When SMT menu 24.
Prestige 650 Series User’s Guide 32-2 Enabling the Firewall Figure 32-1 Menu 21.2 Fire wall Setup Use the web configurator or the com mand interpreter to configure the fire wall rules. 32.4 V iewing Firewall Log In menu 21, enter 3 to view the firewall log.
Prestige 650 Series User’s Guide Enabling the Firewall 32-3 Table 32-1 Firewall Logs LABEL DESCRIPTION EXA MPLE # This is the index number of the firewall log. 128 entries are available numbered from 0 to 127. Once they are all us ed, the log will wrap around an d the old logs will be lost.
.
Prestige 650 Series User’s Guide SNMP Configuration 33-1 Chapter 33 SNMP Configuration This chapter explains SNMP Configuration menu 22. 33.1 SNMP Overview Simple Netw ork Managem ent Protoc ol is a prot ocol used for exchan ging managem ent inform ation betw een network de vices.
Prestige 650 Series User’s Guide 33-2 SNMP Configuration An agent is a managem ent software m odule that resides i n a managed device (the Pres tige). An agent translates the local management information from the managed device into a form compatible with SNMP.
Prestige 650 Series User’s Guide SNMP Configuration 33-3 Figure 33-2 Menu 22 SNMP Configuration The following table d escribes the SNMP configu ration parameters.
Prestige 650 Series User’s Guide 33-4 SNMP Configuration 33.4 SNMP T r ap s The Prestige will send traps to the SNMP manager when any on e of the following events occurs: Table 33-2 SNMP Traps TRAP # TRAP NAME DESCRIPTION 1 coldStart ( defined in RFC-121 5 ) A trap is sent after booting (power on).
Prestige 650 Series User’s Guide System Security 34-1 Chapter 34 System Security This chapter describes how to configure the system security on the Prestige. This chapter is only applicable to the Prestige 650H and the Prestige 650HW. 34.1 System Security Overview You can confi gure the syste m password , an external R ADIUS server a nd IEEE802.
Prestige 650 Series User’s Guide 34-2 System Security Figure 34-3 Menu 23.2 Sy stem Security : RADIUS Server The following table describes the fields in this menu.
Prestige 650 Series User’s Guide System Security 34-3 Table 34-1 Menu 23.2 Sy stem Security : RADIUS Serv er FIELD DESCRIPTION EX AMPLE Port # The default port of the RADIUS server for accounting is 1813 . You need not change this value unl ess your network administrator instructs you to do so with additional information.
Prestige 650 Series User’s Guide 34-4 System Security Figure 34-5 Menu 23.4 Sy stem Security : IEEE802.1x The following table describes the fields in this menu. Table 34-2 Menu 23.4 Sy stem Security : IEEE802.1x FIELD DESCRIPTION Wireless Port Control Press [SPACE BAR] and select a security mode for the wireless LAN access.
Prestige 650 Series User’s Guide System Security 34-5 Table 34-2 Menu 23.4 Sy stem Security : IEEE802.1x FIELD DESCRIPTION Authentication Databases This field is activated only when you se lect Authentication Required in the Wireless Port Control field.
Prestige 650 Series User’s Guide 34-6 System Security Figure 34-6 Menu 14 Dial-in User Setup Step 3. Type a number and pres s [ENTER] to edit the user profile. Figure 34-7 Menu 14.1 Edit Dial-in Us er The following table describes the fields in this menu.
Prestige 650 Series User’s Guide System Information and Diagnosis 35-1 Chapter 35 System Information and Diagnosis This chapter covers the information and diag nostic tools in SMT menus 24.
Prestige 650 Series User’s Guide 35-2 System Information and Diagnosis Figure 35-2 Menu 24.1 Sy stem Maintenance : Status The following ta ble describe s the fields present in Menu 24.1 — System Maintenance — Status which are read-only and meant fo r diagnostic purposes.
Prestige 650 Series User’s Guide System Information and Diagnosis 35-3 Table 35-1 Menu 24.1 Sy stem Maintenance : Status FIELD DESCRIPTION Ethernet This shows statistics for the LAN. Status T his shows the current status of the LAN. Tx Pkts T his is the number of transmitted packets to the LAN.
Prestige 650 Series User’s Guide 35-4 System Information and Diagnosis Figure 35-4 Menu 24.2.1 Sy stem Maintenance : Information The following table describes the fields in this menu. Table 35-2 Menu 24.2.1 Sy stem Maintenance : Information FIELD DESCRIPTION Name T his displays the system name of your Prestige.
Prestige 650 Series User’s Guide System Information and Diagnosis 35-5 35.3.2 Console Port Speed You can set up differe nt port speeds for the console port throu gh Menu 24.2.2 – System Mainte nance – Console Port Speed . Your Prestige suppo rts 9600 (defau lt), 19200, 38400, 57600 an d 115200 bps.
Prestige 650 Series User’s Guide 35-6 System Information and Diagnosis After the Prestige finishes displaying the error log, you will have the option to clear it. Samples of typical error and information messages are presented in t he next fi gure. Figure 35-7 Sample Error and Information Mes sages 35.
Prestige 650 Series User’s Guide System Information and Diagnosis 35-7 Table 35-3 Menu 24.3.2 Sy stem Maintenance : Sy slog and Accounting PARAMETER DESCRIPTION UNIX Syslog: Active Use [SPACE BAR] and then [ENTER] to turn syslog on or off. Syslog IP Address Type the IP address of your s yslog server.
Prestige 650 Series User’s Guide 35-8 System Information and Diagnosis SdcmdSyslogSend (SYSLOG_PKTTRI, SYSLOG_NOTICE, String); String = Packet trigger: Protocol=xx Data=xxxxxxxxxx…..x Protocol: (1:IP 2:IPX 3:IPXHC 4:BPDU 5:ATALK 6:IPNG) Data: We will send forty-eight Hex characters to the server Jul 19 11:28:39 192.
Prestige 650 Series User’s Guide System Information and Diagnosis 35-9 Figure 35-9 Menu 24.4 Sy stem Maintenance : Diagnostic The following table describes the diagn ostic tests available in menu 24.
.
Prestige 650 Series User’s Guide Firmware and Configuration File Maintenance 36-1 Chapter 36 Firmware and Configuration File Maintenance This chapter tells you how to backup and restor e your configuration file as well as upload n ew firmware and configuration files.
Prestige 650 Series User’s Guide 36-2 Firmware and Configuration File Maintenance Table 36-1 Filename Conventions FILE TYPE INTERNA L NAME EXTERN AL NA ME DESCRIPTION Configuration File Rom-0 This is the configurat ion filename on the Prestige.
Prestige 650 Series User’s Guide Firmware and Configuration File Maintenance 36-3 36.2.1 Backup Configuration Follow the instructions as shown in the next screen. Figure 36-1 Telnet in Menu 24.5 36.2.2 Using the FTP Command from the Command Line Step 1.
Prestige 650 Series User’s Guide 36-4 Firmware and Configuration File Maintenance Figure 36-2 FTP Session Example 36.2.4 GUI-based FTP Client s The followin g table describes some of t he commands t hat you m ay see in GUI-based F TP clients.
Prestige 650 Series User’s Guide Firmware and Configuration File Maintenance 36-5 3. The IP addres s in the Secur ed Client IP fie ld in me nu 24.11 does not match t he client I P. If it doe s not match, the Prestige will disconnect the Telnet session immediately.
Prestige 650 Series User’s Guide 36-6 Firmware and Configuration File Maintenance 36.2.8 GUI-based TFTP Client s The followin g table describes some of t he fields that you may see in GU I-based TFTP cli ents. Table 36-3 General Commands for GUI-based TFTP Clients COMMAND DESCRIPTION Host Enter the IP address of the Prestige.
Prestige 650 Series User’s Guide Firmware and Configuration File Maintenance 36-7 Step 3. Run the Hype rTerm inal program by clic king Transfer , then Receive File as shown in the following screen. Figure 36-5 Backup Configuration Example Step 4. After a successful backup you will see the following scr een.
Prestige 650 Series User’s Guide 36-8 Firmware and Configuration File Maintenance WA R N I N G ! DO NOT INTERRUPT THE FILE TR ANSFER PROCESS AS THIS MA Y PERMANENTL Y DAMAGE YOUR PRESTIGE. 36.3.1 Restore Using FTP For details about backup using (T)FTP please refer to ea rlier sections on FTP and TFTP file upload in this chapter.
Prestige 650 Series User’s Guide Firmware and Configuration File Maintenance 36-9 36.3.2 Restore Using FTP Session Example Figure 36-8 Restore Usi ng FTP Session Example Refer to section 36 .2.5 to read about configurations that disallow TFTP and FTP over WAN.
Prestige 650 Series User’s Guide 36-10 Firmware and Configuration File Maintenance Figure 36-11 Restore Configuration Example Step 4. After a successful restoration you will see the fo llowing screen. Press any key to restart the Prestige and return to the SMT menu.
Prestige 650 Series User’s Guide Firmware and Configuration File Maintenance 36-11 Figure 36-13 Telnet Into Menu 24.7.1 Upload Sy stem Firm w are 36.4.2 Configuration File Upload You see the following screen when you telnet into menu 24.7 .2. Figure 36-14 Telnet Into Menu 24.
Prestige 650 Series User’s Guide 36-12 Firmware and Configuration File Maintenance Step 2. Enter “open”, followed by a space and the IP addres s of your Prestige. Step 3. Press [ENTER] when prom pted for a use rname. Step 4. Enter your pas sword as re quested (the default is “1234”).
Prestige 650 Series User’s Guide Firmware and Configuration File Maintenance 36-13 Step 1. Use telnet from your comput er to connect to the Prestige and log in. Because T FTP does not have any security checks, the Prestige records the IP addres s of the telnet client and accepts TFTP requests only from this address.
Prestige 650 Series User’s Guide 36-14 Firmware and Configuration File Maintenance 36.4.8 Uploading Firmware File Via Console Port (only for the Prestige 650H/HW) Step 1. Select 1 from Menu 24.7 – System Mainte nance – Upload Firmware to disp lay Menu 24.
Prestige 650 Series User’s Guide Firmware and Configuration File Maintenance 36-15 After the co nfiguration upload pr ocess has c ompleted, resta rt the Prestige by enteri ng “atgo”. 36.4.10 Uploading Configuration File Via Console Port Step 1. Select 2 from Menu 24.
Prestige 650 Series User’s Guide 36-16 Firmware and Configuration File Maintenance Figure 36-19 Example Xmodem Upload After the co nfiguration upload pr ocess has c ompleted, resta rt the Prestige by enteri ng “atgo”. Type the configuration file’s location, or click Browse to search for it.
Prestige 650 Series User’s Guide System Maintenance 37-1 Chapter 37 System Maintenance This chapter leads yo u through SMT menus 24.8 to 24.10. 37.1 Command Interpreter Mode Overview The Command I nterpreter (CI) is a part o f the main system firmware.
Prestige 650 Series User’s Guide 37-2 System Maintenance Figure 37-2 Valid Commands 37.2 Call Control Support Call Control Suppo rt is only applicable when Encapsulation is set to PPPoE in menu 4 or me nu 11.1. The budget management function allows you to set a limit on the total outgo ing call time of the Prestige within certain times.
Prestige 650 Series User’s Guide System Maintenance 37-3 Figure 37-4 Menu 24.9.1 Budget Man agement The total budget is the time limit on the accum ulated time for outgoing calls to a rem ote node. When this limit is reached, the call will be dropped a nd further out going calls to that remote node will be bloc ked.
Prestige 650 Series User’s Guide 37-4 System Maintenance 37.3 T ime and Date Setting The Prestige keeps trac k of the time and date . There is also a software m echanism to set the time manually or get the current time and dat e from an external serv er when you turn on your Prestige.
Prestige 650 Series User’s Guide System Maintenance 37-5 Table 37-2 Menu 24.10 System Main tenance: Time and Date Setting FIELD DESCRIPTION Enter the time service protocol that your time server sends when you turn on the Prestige.
.
Prestige 650 Series User’s Guide Remote Management 38-1 Chapter 38 Remote Management This chapter cove rs remote management (SMT m enu 24.11). Remote managem ent is not available on all models.
Prestige 650 Series User’s Guide 38-2 Remote Management Figure 38-1 Menu 24.11 Remote Managemen t Control The following table describes the fields in this menu.
Prestige 650 Series User’s Guide Remote Management 38-3 1. A filter in menu 3.1 (LAN) or in menu 11.5 (WAN) is applied to block a Telnet, FTP or Web service. 2. You ha ve disabled t hat service i n menu 24.1 1. 3. The IP addres s in the Secur ed Client IP fie ld (menu 24.
.
Prestige 650 Series User’s Guide IP Policy Routing 39-1 Chapter 39 IP Policy Routing This chapter covers setting and applying policies used for IP routing. 39.1 IP Policy Routing Overview Traditionally, routing is based on the destin ation ad dress only and the IAD takes the shortest path to forward a pac ket.
Prestige 650 Series User’s Guide 39-2 IP Policy Routing IPPR follows the existing pack et filtering facility of RAS in style and in implementation. The po licies are divided into sets, where related policies are grouped to geth er.
Prestige 650 Series User’s Guide IP Policy Routing 39-3 Figure 39-2 Menu 25.1 IP Routing Policy Setup Table 39-1 Menu 25.1 IP Routing Policy Setup AB B RE V I AT I O N M E ANI NG Criterion SA Source.
Prestige 650 Series User’s Guide 39-4 IP Policy Routing Type a num ber from 1 to 6 to display Menu 25.1.1 – IP Routing Policy (see the next figure). This menu allows you to configure a policy rule. Figure 39-3 Menu 25.1.1 IP Routing Policy The following table describes the fields in this menu.
Prestige 650 Series User’s Guide IP Policy Routing 39-5 Table 39-2 Menu 25.1.1 IP Routing Policy FIELD DESCRIPTION Len Comp Press [SPACE BAR] and then [ENTER] to choose from Equal , Not Equal , Less , Greater , Less or Equal or Greater or Equal . Source: addr start / end Source IP address range from start to end.
Prestige 650 Series User’s Guide 39-6 IP Policy Routing Figure 39-4 Menu 3.2 TCP/IP and DHCP Ethernet Setup Go to menu 11.3 (sho wn next) a nd type the number(s) of the IP R outing Polic y set(s) as appr opriate. You can cascade up t o four policy sets by typing t heir num bers separated by commas.
Prestige 650 Series User’s Guide IP Policy Routing 39-7 39.6 IP Policy Routing Example If a network has both In ternet and remote node conn ections, you can rout e Web packets to the Internet using one pol icy and r oute FTP packets t o a remot e network usi ng another policy.
Prestige 650 Series User’s Guide 39-8 IP Policy Routing Step 1. Create a routing policy set in menu 25. Step 2. Create a rule for this set in Menu 25.1.1 — IP Routing Policy as s hown next. Figure 39-7 IP Routing Policy Example Step 3. Check Menu 25.
Prestige 650 Series User’s Guide IP Policy Routing 39-9 Figure 39-8 IP Routing Policy Example Step 6. Check Menu 25.1 — IP Routing Policy Setup to see if the rule is added correctly. Step 7. Apply both policy set s in menu 3. 2 as shown ne xt. Figure 39-9 Apply ing IP Policies Example Menu 3.
.
Prestige 650 Series User’s Guide Call Scheduling 40-1 Chapter 40 Call Scheduling Call scheduling (applicable for PPPoA or PPPoE encaps ulation only) allows you to dictate when a remote node should be call ed and for how long.
Prestige 650 Series User’s Guide 40-2 Call Scheduling T o delete a schedule set, enter the set number and press [SP ACE BAR] and then [ENTER] (or delete) in the Edit Name field. To setup a schedule set, select the schedule set you want to setup from men u 26 (1-12) and pr ess [ENTER] to see Menu 26.
Prestige 650 Series User’s Guide Call Scheduling 40-3 Table 40-1 Menu 26.1 Schedule Set Setup FIELD DESCRIPTION EX AMPLE How Often Should this schedule set recur weekly or be used just once only? Press the [SPACE BAR] and then [ENTER] to select Once or Weekly .
Prestige 650 Series User’s Guide 40-4 Call Scheduling Figure 40-3 Applying Schedule Set( s) to a Remote Node (PPPoE) You can ap ply up to f our schedule sets, separat ed by comm as, for one remote node. Change t he schedule set numbers to your pref erence(s).
SMT VPN/IPSec and Internal SPTGEN XI Part XI: SMT VPN/IPSec and Internal SP TGEN This part provides informati on about configuring VPN/IPSec for secure communications an d Internal SPTGEN for configuration of multiple Prestiges.
.
Prestige 650 Series User ’ s Guide VPN/IPSec Setup 41-1 Chapter 41 VPN/IPSec Setup This chapter introduces the VPN SMT menus. 41.1 VPN/IPSec Overview The VPN/IPSe c main SMT me nu has these main submenus: 1.
Prestige 650 Series User ’ s Guide 41-2 VPN/IPSec Setup Figure 41-2 Menu 27 VPN/IPSec Setup 41.2 IPSec Summary Screen Type 1 in m enu 27 and t hen press [ENTE R] to display Menu 27.1 IPSec Summary . Thi s is a summary read-only m enu of your IPSec rule s (tunnels).
Prestige 650 Series User ’ s Guide VPN/IPSec Setup 41-3 Table 41-1 Menu 27.1 IPSec Summary FIELD DESCRIPTION EX AMPLE Name This field displ ays the unique iden tification na me for this VPN rule. The name may be up to 32 characters long but onl y 10 characters will be displayed her e.
Prestige 650 Series User ’ s Guide 41-4 VPN/IPSec Setup Table 41-1 Menu 27.1 IPSec Summary FIELD DESCRIPTION EX AMPLE Key Mgt This field displa ys the SA’s type of key management, ( IKE or Manual ). IKE Remote Addr Start When the Addr Type field in Menu 27.
Prestige 650 Series User ’ s Guide VPN/IPSec Setup 41-5 Table 41-1 Menu 27.1 IPSec Summary FIELD DESCRIPTION EX AMPLE Select Command Press [SPACE BAR] to choose from None , Edit , Delete , Go To Rule , Next Page or Previous Page and then press [ENTER].
Prestige 650 Series User ’ s Guide 41-6 VPN/IPSec Setup Figure 41-4 Menu 27.1.1 IPSec Setup The following table describes the fields in this menu. Table 41-2 Menu 27.1.1 IPSec Setup FIELD DESCRIPTION EXAMPLE Index T his is the VPN rule index n umber you selec ted in the previous menu.
Prestige 650 Series User ’ s Guide VPN/IPSec Setup 41-7 Table 41-2 Menu 27.1.1 IPSec Setup FIELD DESCRIPTION EXAMPLE Content When you select IP in the Local ID Type field, type the IP address of your computer or leave the field blank to have the Prestige a utomatically use it s own IP address.
Prestige 650 Series User ’ s Guide 41-8 VPN/IPSec Setup Table 41-2 Menu 27.1.1 IPSec Setup FIELD DESCRIPTION EXAMPLE Secure Gateway Address Type the IP address or the domain name (up to 31 characters) of the IPSec router with which you’re making the VPN connection.
Prestige 650 Series User ’ s Guide VPN/IPSec Setup 41-9 Table 41-2 Menu 27.1.1 IPSec Setup FIELD DESCRIPTION EXAMPLE End/Subnet Mask When the Addr Type field is configured to Single , this field is N/A . When the Addr Type field is configured to Range , enter the end (static) IP address, in a range of computers on the LAN behi nd your Prestige.
Prestige 650 Series User ’ s Guide 41-10 VPN/IPSec Setup Table 41-2 Menu 27.1.1 IPSec Setup FIELD DESCRIPTION EXAMPLE End/Subnet Mask When the Addr Type field is configured to Single , this field is N/A .
Prestige 650 Series User ’ s Guide VPN/IPSec Setup 41-1 1 41.4 IKE Setup To edit this menu, the Key Management fie ld in Menu 27.1.1 – IPSec Setu p must be set to IKE . Move the cursor to the Edit Key Management Setup field in Menu 27.1.1 – IPSec Setup ; press [SPACE BAR] to select Yes and then press [ENTER] to display Menu 27 .
Prestige 650 Series User ’ s Guide 41-12 VPN/IPSec Setup Table 41-3 Menu 27.1.1.1 IKE Setup FIELD DESCRIPTION EXAMPLE Encryption Algorithm When DES is used for data communications, both sender and receiver mus t know the same secret key, which can be used to encrypt and decrypt the message or to generate and verif y a message authentication code.
Prestige 650 Series User ’ s Guide VPN/IPSec Setup 41-13 Table 41-3 Menu 27.1.1.1 IKE Setup FIELD DESCRIPTION EXAMPLE Perfect Forward Secrecy (PFS) Perfect Forward Secrecy (PFS) is disabled ( None ) by default in phase 2 IPSec SA setup. This allows faster IPSe c setup, but is not so secure.
Prestige 650 Series User ’ s Guide 41-14 VPN/IPSec Setup Figure 41-6 Menu 27.1.1.2 Manual Setup The following table describes the fields in this menu. Table 41-5 Menu 27.1.1.2 Manual Setup FIELD DESCRIPTION EXAMPLE Active Protocol Press [SPACE BAR] to choose from ESP Tunnel , ESP Transport , AH Tunnel or AH Transport and then press [ENTER].
Prestige 650 Series User ’ s Guide VPN/IPSec Setup 41-15 Table 41-5 Menu 27.1.1.2 Manual Setup FIELD DESCRIPTION EXAMPLE Authentication Algorithm Press [SPACE BAR] to choose from MD5 or SHA1 and then press [ENTER]. MD5 Key Enter the authentication key t o be used by IPSec if applicable.
.
Prestige 650 Series User ’ s Guide SA Monitor 42-1 Chapter 42 SA Monitor This chapter teaches you how to manage your SA s by using the SA Monitor in SMT menu 27.2. 42.1 SA Monitor Overview A Security Association (SA) is the group of security settings related to a specific VPN tunnel.
Prestige 650 Series User ’ s Guide 42-2 SA Monitor Table 42-1 Menu 27.2 SA Monitor FIELD DESCRIPTION EXAMPLE # T his is the security association inde x number. Name This field displays th e identification name for this VPN polic y. This name is unique for each connection where the secure gateway IP address is a public static IP address.
Prestige 650 Series User ’ s Guide SA Monitor 42-3 42.3 V iewing IPSec Log To view the IPSec and IKE connection log, type 3 in menu 27 and pr ess [ENTE R] to display the IPSec lo g as shown next. The following figure shows a typical log from the initiato r of a VPN connection.
.
Prestige 650 Series User ’ s Guide Internal SPTGEN 43-1 Chapter 43 Internal SPTGEN 43.1 Internal SPTGEN Overview Internal SPTGEN (Sy stem Parameter Table Gene rator) is a configuration text file useful for efficient configuration of multiple Prestiges.
Prestige 650 Series User ’ s Guide 43-2 Internal SPTGEN Figure 43-1 Configuration Text File Format: Column Descriptions DO NOT alter or delete any field except p arameters in the Input column. For more text file examples, refer to the Exampl e Internal SPTGEN Scree ns Appendix .
Prestige 650 Series User ’ s Guide Internal SPTGEN 43-3 Figure 43-2 Invalid Parameter Entered: Comman d Line Example The Prestige will display the following if you enter parameter(s) that are valid. Figure 43-3 Valid Parameter Entered: Command Line Example 43.
Prestige 650 Series User ’ s Guide 43-4 Internal SPTGEN Y ou can rename your “rom-t” file when you save it to your computer but it must be named “rom-t” when you upload it to y our Prestige. 43.4 Internal SPTGEN FTP Upload Example Figure 43-5 Internal SPTGEN FTP Upload Example c:ftp 192.
Appendices and Index XII Part XII: Appendices and Index This part cont ains troubleshooting, ad ditional background information and an index of key terms.
.
Prestige 650 Series User’s Guide Troubleshooting A-1 Appendix A Troubleshooting This chapter covers potential problems and the corresponding remedies. A.1 Using LEDs to Diagnose Problems The LEDs are useful aides f or finding possible probl em causes.
Prestige 650 Series User’s Guide A-2 Troubleshooting A.1.3 DSL LED The DSL LED on the front panel does not light up . Chart A-3 Troubleshooti ng DSL LED STEPS CORRECTIVE ACTION 1 Check the telepho ne wire and connections bet ween the Prestige DSL por t and the wall jack.
Prestige 650 Series User’s Guide Troubleshooting A-3 Chart A-5 Troubleshooti ng Telnet STEPS CORRECTIVE ACTION 2 Make sure you are using the correct IP addre ss of the Prestige. Check the IP address of the Prestige. 3 Ping the Prestige from your c omputer.
Prestige 650 Series User’s Guide A-4 Troubleshooting The web configur ator does not display properly. Chart A-7 Troubleshooti ng Internet Bro wser Display STEPS CORRECTIVE ACTION 1 Make sure yo u are using Internet Explorer 5.0 and l ater versions. 2 Delete the temporar y web files and log in ag ain.
Prestige 650 Series User’s Guide Troubleshooting A-5 Chart A-9 Troubleshooti ng LAN Interface STEPS CORRECTIVE ACTION 2 Make sure that the IP address and the subnet ma sk of the Prestige and yo ur computer(s) are on the same subnet. A.7 W AN Interface Initialization of the ADSL conn ection failed.
Prestige 650 Series User’s Guide A-6 Troubleshooting Chart A-12 Troubleshooti ng Internet Access STEPS CORRECTIVE ACTION 2 If the DSL LED is off, refer to Section A.1.3 . 3 Verify your WAN settings. Ref er to the WAN Setup chapter (web configurator) or the Internet Access chapter (SMT).
Prestige 650 Series User’s Guide Troubleshooting A-7 A.10 Remote Node Connection I cannot con nect to a rem ote node or I SP. Chart A-15 Troubleshooti ng Connecting to a Remote Node or ISP STEPS CORRECTIVE ACTION 1 Check menu 4 or W AN screen to verify that t he username and pass word are entered properl y.
.
Prestige 650 Series User’s Guide IP Subnetting B-1 Appendix B IP Subnetting IP Addres sing Routers “route” base d on the network num ber. The rout er that delivers the data packet to the correct destination hos t uses the host ID.
Prestige 650 Series User’s Guide B-2 IP Subnetting A class “A” address (24 host bits) can have 2 24 –2 h osts (app roxima tely 16 mi llion hosts ). Since the first octet of a class “A” IP addre ss must c ontain a “0”, the first octet of a class “A” ad dress can have a value of 0 to 12 7.
Prestige 650 Series User’s Guide IP Subnetting B-3 of ones beginning from the left most bit of the mask, followed by a continuou s sequence of zeros, for a total number of 32 bi ts.
Prestige 650 Series User’s Guide B-4 IP Subnetting Divide the network 19 2.168.1.0 i nto two se parate subnets by convert ing one o f the host ID bits of the IP address to a networ k number bit. The “borrow ed” host ID bit can be either “0” or “1” thus giving two subnets; 192.
Prestige 650 Series User’s Guide IP Subnetting B-5 actual host for the first subn et is 192.168.1.1 and the highest is 192.168.1 .126. Similarly the host ID range for the second subnet is 192.
Prestige 650 Series User’s Guide B-6 IP Subnetting Chart B-10 Subnet 4 NETWORK NUMBER LAST OCTET BIT VA LUE IP Address 192.168.1. 192 IP Address (Binary) 11000000.1 0101000.000000 01. 11 000000 Subnet Mask (Binary) 11111111.11111111.1 1111111. 11 0 00000 Subnet Address: 192.
Prestige 650 Series User’s Guide IP Subnetting B-7 Chart B-12 Class C Subnet Planning NO. “BORROWED” HOST BITS SUBNET MASK NO. SUBNETS NO. HOSTS PER SUBNET 5 255.255.255.248 (/29) 32 6 6 255.255.255.252 (/30) 64 2 7 255.255.255.254 (/31) 128 1 Subnetting With Class A and Class B Net works.
Prestige 650 Series User’s Guide B-8 IP Subnetting Chart B-13 Class B Subnet Planning NO. “BORROWED” HOST BITS SUBNET MA SK NO. SUBNETS NO. HOSTS PER SUBNET 12 255.255.255.240 (/28) 4096 14 13 255.255.255.248 (/29) 8192 6 14 255.255.255.252 (/30) 16384 2 15 255.
Prestige 650 Series User’s Guide Wireless LAN and IEEE 802.11 C-1 Appendix C Wireless LAN and IEEE 802.11 A wireless LAN (WLA N) provides a flexi ble data commun ications system that y ou can use to access various services (navigating the Internet, email, printer se rvices, etc.
Prestige 650 Series User’s Guide C-2 Wireless LAN and IEEE 802.11 Ad-hoc Wireless LAN Configuration The simplest WL AN config uration is an i ndependent (A d-hoc) WLAN that connects a set of compute rs with wireless nodes or stations (STA), w hich is cal led a Basic Service Set (BSS).
Prestige 650 Series User’s Guide Wireless LAN and IEEE 802.11 C-3 Diagram C-2 ESS Provides Campus-Wide Coverage.
.
Prestige 650 Series User’s Guide PPPoE D-1 Appendix D PPPoE PPPoE in Action An ADSL m odem bridges a PPP session o ver Ethernet (PPP over Et hernet, R FC 2516) f rom your PC t o an ATM PVC (Permanent Virt ual Circuit) which c onnect s to a xDSL Access Concentrator where the PPP session terminates (see the ne xt figure).
Prestige 650 Series User’s Guide D-2 PPPoE How PPPoE Works The PPPoE driver m akes the Ethernet appear as a serial link to the PC and the PC runs PPP over it, while the modem bridges the Et hernet frames to the Access Conce ntr ator (AC).
Prestige 650 Series User’s Guide Virtual Circuit Topology E-1 Appendix E Virtual Circuit Topology ATM is a connection-oriented techno logy, meaning that it sets up virtual circuits over which end systems communicate.
.
Prestige 650 Series User’s Guide Setting up Your Computer’s IP Address F-1 Appendix F Setting up Your Computer’s IP Address All computers must have a 1 0M or 100M Et he rnet adapter card and TC P/IP installed.
Prestige 650 Series User’s Guide F-2 Setting up Your Computer’s IP Address Installing Components The Network window Configuration ta b displa ys a list of i nstalled com ponents. Y ou need a network adapter, the T CP/IP prot ocol and C lient for Microsoft Networks.
Prestige 650 Series User’s Guide Setting up Your Computer’s IP Address F-3 2. Click the IP Address tab. -If your IP address is dynamic, select Obtain an IP address automatically . -If you have a static IP address, select Specify an IP address and type your informatio n into the IP Address and Subne t Mask fields.
Prestige 650 Series User’s Guide F-4 Setting up Your Computer’s IP Address 4. Click the Gateway tab. -If you do not know your gateway’s IP address, remove previously installed gate ways. -If you have a gateway IP address, type it in the Ne w ga te way f ie l d and click Add .
Prestige 650 Series User’s Guide Setting up Your Computer’s IP Address F-5 Windows 2000/NT/XP 1. For Windo ws XP, click start , Control Panel . In Windows 2000/NT, click Start , Settings , Control Panel . 2. For Windo ws XP, click Network Connections .
Prestige 650 Series User’s Guide F-6 Setting up Your Computer’s IP Address 4. Select Internet Protocol (TCP/IP) (under the General tab in Win XP) and click Properties . 5. T he Internet Protocol TCP/IP Properties window opens (the General tab in Windows XP).
Prestige 650 Series User’s Guide Setting up Your Computer’s IP Address F-7 6. -If you do not kno w your gateway's IP address, remove any previously installed gate ways in the IP Settin gs tab and click OK .
Prestige 650 Series User’s Guide F-8 Setting up Your Computer’s IP Address 7. In the Internet Protocol TCP/IP Properties window (the Gene ral t ab in Windows XP): -Click Obtain DNS server address automatically if you do not know your DNS server IP address(es).
Prestige 650 Series User’s Guide Setting up Your Computer’s IP Address F-9 Macintosh OS 8/9 1. Click the Apple menu, Control Panel and double-click TCP/IP to open the TCP/IP Control Panel .
Prestige 650 Series User’s Guide F-10 Setting up Your Computer’s IP Address 3. For d ynamically assigned settings, select Using DHCP Server from the Configure: list. 4. For staticall y assigned settings, do the following: -From the Configure box, select Manually .
Prestige 650 Series User’s Guide Setting up Your Computer’s IP Address F-11 2. Click Network in the icon bar. - Select Automatic from the Location list. - Select Built-in Ethernet from the Show list. - Click the TCP/IP tab. 3. For dynamically assigned settings, select Using DHCP from the Configure list.
.
Prestige 650 Series User’s Guide Splitters and Microfilters G-1 Appendix G Splitters and Microfilters This appendix tells you how to install a POTS splitter or a telephone microfilter.
Prestige 650 Series User’s Guide G-2 Splitters and Microfilters Step 2. Connect a cable from the double jack end of the Y-Connector to the “wall side” of the microfilter. Step 3. Connect another cable from the double jack end of the Y-C onnect or to the Prestige.
Prestige 650 Series User’s Guide Log Descriptions H-1 Appendix H Log Descriptions This appen dix provides desc riptions of e xample log m essages 1 . Chart H-1 System Mainte nance Logs LOG MESSAGE DESCRIPTION Time calibration is successful The router has adjusted its time based on information from the time server.
Prestige 650 Series User’s Guide H-2 Log Descriptions Chart H-2 UPnP Logs LOG MESSAGE DESCRIPTION UPnP pass through Firewall UPnP packets can pass through the firewall. The attack logs may include the protocol (Protocol) of the packet (fo r exam ple TCP or UDP) that triggered the log.
Prestige 650 Series User’s Guide Log Descriptions H-3 (Protocol) is the prot ocol of th e packet (for exam ple TCP or U DP) that triggere d the log. (Direction) is the direction in which the packet was traveling (for exam ple LAN to WAN or WAN to LAN) (Rule) is the number of the firewall rule which caused th e log.
Prestige 650 Series User’s Guide H-4 Log Descriptions Chart H-4 Access Logs LOG MESSAGE DESCRIPTION ICMP Destination Unreachable The Prestige sent or received an ICMP Desti nation Unreachable packet when a packet was dropped bec ause the target port was not open.
Prestige 650 Series User’s Guide Log Descriptions H-5 Chart H-6 ICMP Notes TYPE CODE DESCRIPTION 0 Net unreachable 1 Host unrea chable 2 Protocol unreachable 3 Port unreachable 4 A packet that neede.
Prestige 650 Series User’s Guide H-6 Log Descriptions Chart H-6 ICMP Notes TYPE CODE DESCRIPTION 0 Timestamp reply message 15 Information Request 0 Information request message 16 Information Reply 0.
Prestige 650 Series User’s Guide Power Adaptor Specifications I-1 Appendix I Power Adaptor Specifications I.1 Prestige 650R-E1/-E3/-E7 ADSL Router NORTH AMERICA PLUG STANDARDS AC Power Adapter model DV-121AACS Input power AC120Volts/60Hz/23W max. Output power AC12Volts/1.
Prestige 650 Series User’s Guide I-2 Power Adaptor Specifications Power consumption 8 W Safety standards CCEE (GB8898) EUROPEAN PLUG STANDARDS AC Power Adapter model DV-121AACCP-5716 Input power AC230Volts/50Hz/100mA Output power AC12Volts/1.
Prestige 650 Series User’s Guide Power Adaptor Specifications I-3 CHINESE PLUG STANDARDS AC Power Adapter model DV-121AACCP-5720 Input power AC220Volts/50Hz/18W Output power AC12Volts/1.
Prestige 650 Series User’s Guide I-4 Power Adaptor Specifications Input power AC220Volts/50Hz/18W Output power AC12Volts/1.0A Power consumption 12 W Safety standards CCEE (GB8898) EUROPEAN PLUG STANDARDS AC Power Adapter model AA-121ABN Input power AC230Volts/50Hz/140mA Output power AC12Volts/1.
Prestige 650 Series User’s Guide Power Adaptor Specifications I-5 Power consumption 8 W Safety standards CCEE (GB8898) EUROPEAN PLUG STANDARDS AC Power Adapter model AA-121ABN Input power AC230Volts/50Hz/140mA Output power AC12Volts/1.
Prestige 650 Series User’s Guide I-6 Power Adaptor Specifications Safety standards UL, CUL, CSA (UL 1310, CSA C22.2 No.223) NORTH AMERICA PLUG STANDARDS AC Power Adapter model AA-121A25 Input power AC120Volts/60Hz/19W Output power AC 12Volts/ 1.25A Power consumption 12 W Safety standards UL, CUL (UL 1310, CSA C22.
Prestige 650 Series User’s Guide Power Adaptor Specifications I-7 EUROPEAN PLUG STANDARDS AC Power Adapter model AA-121A3BN Input power AC230Volts/50Hz/140mA Output power AC12Volts/1.3A Power consumption 13 W Safety standards ITS-GS, CE (EN 60950) I.
Prestige 650 Series User’s Guide I-8 Power Adaptor Specifications AC Power Adapter model AA-121A3D Input power AC230Volts/50Hz/140mA Output power AC12Volts/1.
Prestige 650 Series User’s Guide Power Adaptor Specifications I-9 Output power AC12Volts/1.0A Power consumption 10 W Safety standards CCEE (GB8898) EUROPEAN PLUG STANDARDS AC Power Adapter model DV-121AACUP-5716 Input power AC230Volts/50Hz/100mA Output power AC12Volts/1.
.
Prestige 650 Series User’s Guide Index J-1 Appendix J Index A Action for Matche d Pack ets ................................. 12-13 Address Assi gnment ................................................. 4-2 Ad-hoc Config uration.......................
Prestige 650 Series User’s Guide J-2 Index D Data encryption......................................................... 5-4 Data Filte ri ng .......................................................... 31-1 Default Polic y Log...........................
Prestige 650 Series User’s Guide Index J-3 Firewall Vs Filters ................................... 10-12 Guidelines For Enhancing Se curity ......... 10-11 Introduction ............................................... 10-2 LAN to WAN Rules ..........
Prestige 650 Series User’s Guide J-4 Index IP Protoc ol .............................................................. 39-4 IP Routing Poli cy (IPP R) ........................................ 39-1 Benefits............................................
Prestige 650 Series User’s Guide Index J-5 Packet Filterin g Firewalls ....................................... 10-1 Packet Trig gered .................................................... 35-7 Packets .................................................
Prestige 650 Series User’s Guide J-6 Index Server .. 7-4 , 9-2, 30-4, 30-5, 30-8, 30-9, 30-10, 30-13, 30-14, 37-5 Service ............................................................... iv, 12-2 Service Type .........................................
Prestige 650 Series User’s Guide Index J-7 Telnet .......................................................... A-3 Web Configurator ....................................... A-3 Type of Service ........................... 39- 1, 39-3, 39-4, 39-5 U UDP/ICMP Secu rit y .
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté ZyXEL Communications 650 Series c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du ZyXEL Communications 650 Series - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation ZyXEL Communications 650 Series, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le ZyXEL Communications 650 Series va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le ZyXEL Communications 650 Series, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du ZyXEL Communications 650 Series.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le ZyXEL Communications 650 Series. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei ZyXEL Communications 650 Series ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.