ZyXEL 793H v2 Guia do Utilizador

Consulte online ou descarregue Guia do Utilizador para Routers ZyXEL 793H v2. ZyXEL Prestige 793H v2 Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir

Resumo do Conteúdo

Página 1 - P-793H v2

P-793H v2 G.SHDSL.bis Bonded Broadband Gateway Support Notes Version 3.70 02/2010

Página 2

P-793H v2 Support Notes 15. What are Device filters and Protocol filters? In ZyNOS, the filters have been separated into two groups. One gr

Página 3

P-793H v2 Support Notes Support Tool 1. LAN/WAN Packet Trace The P-793H v2 packet trace records and analyzes packets running on LAN and WAN

Página 4

P-793H v2 Support Notes (2) Trace WAN packet  Disable the capture of the LAN packet by entering: sys trcp channel enet0 none  Enable to

Página 5 - ZyNOS FAQ

P-793H v2 Support Notes  Offline Trace  Disable the capture of the WAN packet by entering: sys trcp channel mpoa00 none  Enable the cap

Página 6

P-793H v2 Support Notes  Capture the detailed logs by Hyper Terminal Step 1: Initiate a hyper terminal connection from your PC(suppose yo

Página 7

P-793H v2 Support Notes Step 3: So that after you invoke the relevant commands, you could save the logs you‟ve captured. 2. Firmware/Conf

Página 8

P-793H v2 Support Notes  Using TFTP client software  Upload/download ZyNOS via LAN  Upload/download P-793H v2 configurations via LAN (1)

Página 9

P-793H v2 Support Notes Step 5: To upload the P-793H v2configuration, please save the remote file as 'rom-0' in the P-793H v2. An exa

Página 10

P-793H v2 Support Notes 2. Type the CI command 'sys stdio 0' to disable console idle timeout in Command Line Interface (CLI) Exampl

Página 11

P-793H v2 Support Notes Step 5 Use 'put' command to transfer the file to the P-793H v2. Example: Step 1: Connect to the P-793H v2 b

Página 12 - Product FAQ

P-793H v2 Support Notes the remote 'rom-0' file. Step 4: The P-793H v2 reboots automatically after the uploading is finished. Pleas

Página 13

P-793H v2 Support Notes  Allow packets that originate from us Filter rule setup:  Filter Type =TCP/IP Filter Rule  Active =Yes  Destinati

Página 14

P-793H v2 Support Notes CI Command Reference Command Syntax and General User Interface CI has the following command syntax: command <i

Página 15

P-793H v2 Support Notes Reference 1. PPP Numbers POINT-TO-POINT PROTOCOL FIELD ASSIGNMENTS PPP DLL PROTOCOL NUMBERS The Point-to-Point Proto

Página 16

P-793H v2 Support Notes 004d SNA 004f Pv6 Header Compression 0051 KNX Bridging Data [ianp] 0053 Encryption [Meyer] 0055 Individual Link Encr

Página 17

P-793H v2 Support Notes 802b Novell IPX Control Protocol 802d reserved 802f reserved 8031 Bridging NCP 8033 Stream Protocol Control Protocol

Página 18 - DSL FAQ

P-793H v2 Support Notes c021 Link Control Protocol c023 Password Authentication Protocol c025 Link Quality Report c027 Shiva Password Authent

Página 19

P-793H v2 Support Notes 7 Code-Reject 8 * Protocol-Reject 9 * Echo-Request 10 * Echo-Reply 11 * Discard-Request 12 * Identification 13 * T

Página 20

P-793H v2 Support Notes 21 DCE-Identifier [SCHNEIDER] 22 Multi-Link-Plus-Procedure [Smith] 23 Link Discriminator for BACP [RFC2125] 24 LCP-Au

Página 21 - Firewall FAQ

P-793H v2 Support Notes 3 Puddle Jumper [RFC1962] 4-15 unassigned 16 Hewlett-Packard PPC [RFC1962] 17 Stac Electronics LZS [RFC1974] 18 Micr

Página 22

P-793H v2 Support Notes A one octet field is used in the Challenge-Handshake Authentication Protocol (CHAP) to indicate which algorithm is in use

Página 23

P-793H v2 Support Notes The Point-to-Point Protocol (PPP) Link Control Protocol (LCP) Callback Configuration Option contains an 8-bit Operations

Página 24 - Configuration

P-793H v2 Support Notes Product FAQ 1. What is SHDSL, SHDSL.bis? SHDSL stands for Symmetric High-data-rate Digital Subscriber Line. SHDSL ba

Página 25

P-793H v2 Support Notes 4 AT-Compression-Protocol 5 Reserved 6 Server-information 7 Zone-information 8 Default-Router-Address  PPP OSIN

Página 26

P-793H v2 Support Notes 6 MAC-Address 7 Spanning-Tree-Protocol  PPP BRIDGING MAC TYPES The Point-to-Point Protocol (PPP) Bridging Contro

Página 27

P-793H v2 Support Notes 2 IPX-Node-Number [RFC1552] 3 IPX-Compression-Protocol [RFC1552] 4 IPX-Routing-Protocol [RFC1552] 5 IPX-Router-Name [

Página 28

P-793H v2 Support Notes  PPP EAP REQUEST/RESPONSE TYPES A one octet field is used in the Extensible Authentication Protocol (EAP) to indicate

Página 29 - IPSec FAQ

P-793H v2 Support Notes discard 9/tcp sink null discard 9/udp sink null systat 11/tcp systat 11/tcp users daytime 13/tcp daytime 13/udp n

Página 30

P-793H v2 Support Notes sunrpc 111/udp auth 113/tcp authentication sftp 115/tcp path 117/tcp uucp-path 117/tcp nntp 119/tcp usenet # Net

Página 31

P-793H v2 Support Notes monitor 561/udp # experimental garcon 600/tcp maitrd 601/tcp busboy 602/tcp acctmaster 700/udp acctslave

Página 32

P-793H v2 Support Notes rscs6 10006/udp rscs7 10007/udp rscs8 10008/udp rscs9 10009/udp rscsa 10010/udp rscsb 10011

Página 33 - P-793H v2 VPN

P-793H v2 Support Notes 22 XNS-IDP XEROX NS IDP [ETHERNET,XEROX] 23 TRUNK-1 Trunk-1 [BWB6] 24 TRUN

Página 34

P-793H v2 Support Notes 65 KRYPTOLAN Kryptolan [PXL1] 66 RVD MIT Remote Virtual Disk Protocol [MBG] 67 IPPC Internet Pluribus P

Página 35

P-793H v2 Support Notes 6. What do I need before using the SHDSL? 1. You must order the SHDSL service from your telephone company and choose

Página 36

P-793H v2 Support Notes 109 SNP Sitara Networks Protocol [Sridhar] 110 Compaq-Peer Compaq Peer Protocol [Volpe] 111 IPX-in-IP IPX

Página 37

P-793H v2 Support Notes Traffic shaping parameters (PCR, SCR, MBS) can be set in Menu 4 and Menu 11.6 and is valid for both incoming and outgoing

Página 38

P-793H v2 Support Notes P-793H v2 to avoid congestion; traffic shaping takes measures to adapt to unpredictable fluctuations in traffic flows and

Página 39 - Application Notes

P-793H v2 Support Notes www.zyxel.com.tw) for your server (e.g., Web server) from a DDNS server. The outside users can always access the web serv

Página 40

P-793H v2 Support Notes For forwarding the inbound IPSec ESP tunnel, A 'Default' server set is required. You could configure it in Web

Página 41

P-793H v2 Support Notes 24. What is Traffic Redirect ? Traffic redirect forwards WAN traffic to a backup gateway when the Prestige cannot con

Página 42

P-793H v2 Support Notes two-way cable modem transmissions, and while the figure also grows steadily, it will not catch up with telephone lines fo

Página 43 - In WEB Configurator, Network

P-793H v2 Support Notes FAQ ...

Página 44

P-793H v2 Support Notes 6. What are the signaling pins of the DSL connector? The signaling pins on the P-793H v2's DSL connector RJ11 c

Página 45

P-793H v2 Support Notes Triple Play is a VLAN-based policy to forward packets from LAN ports to different PVCs, thus you can configure each PVC s

Página 46

P-793H v2 Support Notes Application-level Firewalls generally are hosts running proxy servers, which permit no traffic directly between networks,

Página 47

P-793H v2 Support Notes 6. What is Denials of Service (DoS) attack? Denial of Service (DoS) attacks are aimed at devices and networks with a co

Página 48

P-793H v2 Support Notes 10. What is LAND attack? In a LAN attack, hackers flood SYN packets to the network with a spoofed source IP address of

Página 49

P-793H v2 Support Notes 2. How do I prevent others from configuring my firewall? There are several ways to protect others from touching the set

Página 50

P-793H v2 Support Notes (1) When the firewall is turned on, all connections from WAN to LAN are blocked by the default ACL rule. To enable WWW/Te

Página 51

P-793H v2 Support Notes (4)A filter set which blocks WWW/Telnet from WAN is applied to WAN node. The default filter rule 3 (Telnet_FTP_WAN) is

Página 52

P-793H v2 Support Notes The P-793H v2 generates the firewall log immediately when the packet matches a firewall rule. The log for Default Firewal

Página 53

P-793H v2 Support Notes 4. When does the P-793H v2 generate the firewall alert? The P-793H v2 generates the alert when an attack is detected by

Página 54

P-793H v2 Support Notes 19. What is DDNS wildcard? Does the P-793H v2support DDNS wildcard? ...

Página 55

P-793H v2 Support Notes Because users typically dial the their local ISP for VPN, thus, long distance phone charge is reduced than making a long

Página 56 - 9. Using Full Feature NAT

P-793H v2 Support Notes There are two protocols provided by IPSec, they are AH (Authentication Header, protocol number 51) and ESP (Encapsulated

Página 57

P-793H v2 Support Notes For IKE VPN, the key and SPIs are negotiated from one VPN gateway to the other. Afterward, two VPN gateways use this nego

Página 58

P-793H v2 Support Notes 15. When should I use FQDN? If your VPN connection is P-793H v2 to P-793H v2, and both of them have static IP address,

Página 59

P-793H v2 Support Notes If your P-793H v2 is capable of VPN, you can find the VPN options in Advanced>VPN tab. For configuring a 'box-t

Página 60

P-793H v2 Support Notes  Netopia VPN  III VPN 7. What VPN software that has been tested with P-793H v2 successfully? We have tested P-793

Página 61

P-793H v2 Support Notes 9. How do I configure P-793H v2 with NAT for internal servers? Generally, without IPSec, to configure an internal ser

Página 62

P-793H v2 Support Notes \ Non-secure host 11. How can I keep a tunnel alive? To keep a tunnel alive, you can check "keep alive" opt

Página 63

P-793H v2 Support Notes function on P-793H v2. To disable it, you can either deactivate each VPN rule or issue a CI command, "ipsec switch o

Página 64

P-793H v2 Support Notes Application Notes General Application Notes 1. Internet Access Using P-793H v2 under Bridge mode  Setup your work

Página 65 - WWW.DYNDNS.ORG

P-793H v2 Support Notes 15. Using Call Scheduling ... 73 16. Using IP Mul

Página 66

P-793H v2 Support Notes Setup your P-793H v2 The following procedure shows you how to configure your P-793H v2 as bridge mode. We will use W

Página 67

P-793H v2 Support Notes Key Settings: Option Description Transfer Mode Select the correct Transfer Mode that your ISP supports. For example,

Página 68

P-793H v2 Support Notes Set up your P-793H v2 under routing mode The following procedure shows you how to configure your P-793H v2 as Routin

Página 69

P-793H v2 Support Notes (2) Configure a LAN IP for the P-793H v2 and the DHCP settings in Web Configurator, Advanced Setup, Network -> LAN.

Página 70

P-793H v2 Support Notes Please set proper parameter for your Internet Access. 4. Back to back scenarios  1 - 1 back to back (1) 4 Wir

Página 71

P-793H v2 Support Notes  1 - 2 back to back Note 1: It is also compatible with G.SHDSL 2.3Mbps application when we connect it with P-

Página 72

P-793H v2 Support Notes Note: When P-793H v2 works as client, options “Enable Rate Adaption” “Transfer Max Rate” “Transfer Min Rate” and “Standar

Página 73

P-793H v2 Support Notes  Setup the P-793H v2 as a DHCP Relay We could set the P-793H v2 as a DHCP Relay via menu 3.2 as below: Or via the

Página 74

P-793H v2 Support Notes Introduction Generally, SUA makes your LAN appear as a single machine to the outside world. LAN users are invisible to

Página 75

P-793H v2 Support Notes ICQ 99a None for Chat. For DCC, please set: ICQ -> preference -> connections -> firewall and set the firewall ti

Página 76

P-793H v2 Support Notes FAQ ZyNOS FAQ 1. What is ZyNOS? ZyNOS is ZyXEL's proprietary Network Operating System. It is the platform on a

Página 77

P-793H v2 Support Notes (VNC) 5800/client IP 5900/client IP AIM (AOL Instant Messenger) None for Chat and IM None for Chat and IM e-Donkey Non

Página 78 - Key Settings:

P-793H v2 Support Notes Configure an Internal Server behind SUA Introduction If you wish, you can make internal servers (e.g., Web, ft

Página 79

P-793H v2 Support Notes Setup, Network -> NAT -> Port Forwarding. The outside users can access the local server using the P-793H v2's

Página 80

P-793H v2 Support Notes Telnet 23 SMTP 25 DNS (Domain Name Server) 53 www-http (Web) 80 Configure a PPTP server behind SUA Introducti

Página 81

P-793H v2 Support Notes PPTP appears as new modem type (Virtual Private Networking Adapter) that can be selected when setting up a connection in

Página 82

P-793H v2 Support Notes  Add an user account for PPTP logged on user  Enable RAS port  Select the network protocols from RAS such as IPX, T

Página 83

P-793H v2 Support Notes Before making a VPN connection from the Win9x client to the NT server, you need to know the exact Internet IP address tha

Página 84

P-793H v2 Support Notes None NAT is disabled when you select this option. SUA Only When you select this option, this remote node will use d

Página 85

P-793H v2 Support Notes -> NAT -> Port Forwarding. The following table explains the fields in this above screen: Field Description Option

Página 86

Service Port Number FTP 21 Telnet 23 SMTP 25 DNS (Domain Name Server) 53 www-http (Web) 80 PPTP (Point-to-Point Tunneling Protocol) 1723 P-793H v2

Página 87 - IPSEC VPN Application Notes

P-793H v2 Support Notes (1) Use the TELNET client program in your PC to login to your P-793H v2, and use Menu 24.8 to enter CI command '

Página 88

P-793H v2 Support Notes (2) Internet Access with an Internal Server In this case, we do exactly as the figure (use the convenient pre-co

Página 89

P-793H v2 Support Notes below: (3) Using Multiple Global IP addresses for clients and servers (One-to-One, Many-to-One, Server Set mapping typ

Página 90

P-793H v2 Support Notes Step 1: In this case, we need to map ILA to more than one IGA, therefore we must choose the Full Feature option from the

Página 91

P-793H v2 Support Notes Rule 4 Setup: Select Server type to map our web server and mail server with ILA3 (192.168.1.20) to IGA3. Menu Networ

Página 92

P-793H v2 Support Notes Some servers providing Internet applications such as some mIRC servers do not allow users to login using the same IP addr

Página 93

P-793H v2 Support Notes With DDNS supported by the P-793H v2, you apply a DNS name (e.g., www.zyxel.com.tw) for your server (e.g., Web server) fr

Página 94

P-793H v2 Support Notes Active Toggle to 'Yes'. Host Name Enter the hostname you subscribe from the above DDNS server. For example, z

Página 95

P-793H v2 Support Notes 5. authentication Failure (defined in RFC-1215) : When receiving any SNMP get or set requirement with wrong community,

Página 96

P-793H v2 Support Notes The SNMP related settings in P-793H v2are configured in Web Configurator, Advanced Setup, Advanced -> Remote MGNT -

Página 97

P-793H v2 Support Notes Trap Destination Enter the IP address of the NMS that you wish to send the traps to. If 0.0.0.0 is entered, the P-793H

Página 98

P-793H v2 Support Notes (2) Press the RESET button for longer than one second and shorter than five seconds and release it. If the POWER LED beg

Página 99

P-793H v2 Support Notes The P-793H v2supports three virtual LAN interfaces via its single physical Ethernet interface. The first network can b

Página 100 - Support Tool

P-793H v2 Support Notes You can edit filter rule to accept or deny LAN packets from/to the IP alias 1/2 go through the P-793H v2 in SMT menu 3.

Página 101

P-793H v2 Support Notes IP Alias 1 Active it and enter the second LAN IP address for the P-793H v2. This will create the second route in the eni

Página 102

P-793H v2 Support Notes Cost Savings- IPPR allows organizations to distribute interactive traffic on high-bandwidth, high-cost path while using l

Página 103

P-793H v2 Support Notes Type of Service= No Change Precedence = No Change This policy example forces the Web packets originated from the clien

Página 104

P-793H v2 Support Notes Start Date Start date of this schedule rule. It can be unmatched with weekday setting. For example, if Start Date is 2000

Página 105

P-793H v2 Support Notes Protocol (RFC-868), and NTP protocol (RFC-1305). You have to assign an IP address of a time server and then, the P-793H v

Página 106

P-793H v2 Support Notes  IP Multicast Setup (1) Enable IGMP in P-793H v2's LAN in Web Configurator, Advanced Setup, Network -> LAN -&

Página 107

P-793H v2 Support Notes Key Settings: Active Check the box to enable BWM on the interface. Note that if you would like to manage traffic fr

Página 108

P-793H v2 Support Notes Key Settings: RuleName Give this rule a name, for example, 'WWW' BW Budget Configure the bandwidth you would

Página 109

P-793H v2 Support Notes The P-793H v2 supports NAT sets on a remote node basis. They are reusable, but only one set is allowed for each remote no

Página 110 - CI Command Reference

P-793H v2 Support Notes Source Port Enter the source port number of the traffic. Protocol ID Enter the protocol number for the traffic. 1 for IC

Página 111 - Reference

P-793H v2 Support Notes For example: 802 groupset 1 1 LAN 1 PVC 1 untagged 802 groupset 2 2 LAN 2 PVC 2 untagged 802 groupset 3 3 LAN 3 PVC 3 unt

Página 112

P-793H v2 Support Notes Fail Tolerance: Type the number of times (2 recommended) that your P-793H v2 may ping the IP addresses configured in the

Página 113

P-793H v2 Support Notes 21. How to deal with Triangle Route and Traffic redirect? Traffic redirect scenario: (1). Triangle route in

Página 114

P-793H v2 Support Notes A traffic route is a path for sending or receiving date packets between two Ethernet devices. Some companies have more th

Página 115

P-793H v2 Support Notes 2) Deploy your second gateway on WAN side Put all of your network gateways on the WAN side as the following figur

Página 116

P-793H v2 Support Notes 22. How to setup Dial Backup? Please refer to “20.How to setup traffic redirect in P-793H v2?” to Configure param

Página 117

P-793H v2 Support Notes remote node. Advanced Setup: Click this button to display the Advanced Setup screen and edit more details of your WAN bac

Página 118

P-793H v2 Support Notes As the figure shown below, the tunnel between Prestige 1 and Prestige 2 ensures the packets flow between PC 1 and PC 2 ar

Página 119

P-793H v2 Support Notes (3) On the SUMMARY menu, select a policy to edit by clicking Edit. On P-793H v2, we can build at most 2 VPN Tunnels.

Página 120

P-793H v2 Support Notes  Many to One: In Many-to-One mode, the P-793H v2 maps multiple ILA to one IGA. This is equivalent to SUA (i.e., PAT, po

Página 121

P-793H v2 Support Notes My IP Address is the WAN IP of Prestige A, 202.132.154.1 in the example. Secure Gateway Address is the remote secure gat

Página 122

P-793H v2 Support Notes Note: If there‟s a NAT router between the two VPN Secure Gateways, we should only choose „ESP‟ VPN Protocol. The minimum

Página 123

P-793H v2 Support Notes Secure Gateway Address is the remote secure gateway, Prestige A‟s WAN IP, 202.132.154.1 in the example. (3) Local ID Ty

Página 124

P-793H v2 Support Notes Prestige> ipsec debug 1 IPSEC debug level 1 Prestige> catcher(): recv pkt numPkt<1> get_hdr nxt_payload<1&

Página 125 - P-793H v2 Support Notes

P-793H v2 Support Notes Most of the cases, static IP addresses are used for VPN tunneling endpoints. But for SOHO users, generally, it is a dyna

Página 126

P-793H v2 Support Notes Solution 1: Step 1: In Prestige A, please register a DDNS account from http://www.dyndns.org or http://dynupdate.no-ip.

Página 127

P-793H v2 Support Notes Generally, without IPSec, to configure an internal server for outside access, we need to configure the server private IP

Página 128

P-793H v2 Support Notes The IP addresses we use in this example are as shown below. Branch_A Headquarter Branch_B WAN:202.3.1.1 LAN:192.168.

Página 129

P-793H v2 Support Notes Remote Address Type is Range Address and IP Address Start is 192.168.1.0, IP Address End is 192.168.2.255. This section c

Página 130

P-793H v2 Support Notes (3) Suppose the pre-shared key is 01234567, we should configure the same key in the corresponding rule in Headquarter VPN

Comentários a estes Manuais

Sem comentários