
www.zyxel.comZyWALL USG 1000Unified Security GatewayUser’s GuideVersion 2.0010/2007Edition 1DEFAULT LOGINLAN Port P1IP Address http://192.168.1.1User
Contents OverviewZyWALL USG 1000 User’s Guide10Content Filter Screens ...
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide1004.8.2 VPN Express Wizard - Summary This summary of VPN tunnel settings is read-only.Name: Identi
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide101" If you have not already done so, use the myZyXEL.com link and register your ZyWALL with m
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide102Figure 38 VPN Advanced Wizard: Step 2 The following table describes the labels in this screen.T
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide1034.8.5 VPN Advanced Wizard - Remote Gateway The Remote Gateway policy identifies the IPSec devic
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide104Figure 39 VPN Advanced Wizard: Step 3The following table describes the labels in this screen.Ta
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide1054.8.6 VPN Advanced Wizard - Phase 1 Phases: IKE (Internet Key Exchange) negotiation has two pha
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide1064.8.6.1 Phase 2 SettingPhase 2 in an IKE uses the SA that was established in phase 1 to negotiat
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide1074.8.7 VPN Advanced Wizard - Phase 2 Active Protocol: ESP is compatible with NAT, AH is not.Enca
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide108Figure 41 VPN Advanced Wizard: Step 5The following table describes the labels in this screen.4.
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide109Secure Gateway: IP address or domain name of the peer IPSec device.Pre-Shared Key: VPN tunnel pa
Table of ContentsZyWALL USG 1000 User’s Guide11Table of ContentsAbout This User's Guide ...
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide110" If you have not already done so, you can register your ZyWALL with myZyXEL.com and activat
ZyWALL USG 1000 User’s Guide111CHAPTER 5 Configuration BasicsThis section provides information to help you configure the ZyWALL effectively. Some of
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide1125.2 Terminology in the ZyWALLThis section highlights some differences in terminology or
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide113A physical port is the place to which you connect the cable. As shown above, you do not
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide114Figure 43 Interfaces and Zones: Example• The LAN zone contains the ge1 (Gigabit Etherne
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide115Example: This provides a simple example to show you how to configure this feature. The e
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide116Example: See Chapter 6 on page 125.5.4.4 IPSec VPNUse IPSec VPN to provide secure commun
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide117Zones cannot overlap. Each interface and VPN tunnel can be assigned to at most one zone.
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide1182 Click Network > Routing > Policy Route to go to the policy route configuration sc
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide1192 Create an address object for the VoIP server (Object > Address). 3 Click Firewall t
Table of ContentsZyWALL USG 1000 User’s Guide123.1 Web Configurator Requirements ...
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide1205.4.14 Anti-VirusUse anti-virus to detect and take action on viruses. You must subscribe
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide12111 Add a policy that uses the schedule, the filtering profile and the user that you crea
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide1225.4.20 ALGThe ZyWALL’s Application Layer Gateway (ALG) allows VoIP and FTP applications
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide123If you want to force users to log in to the ZyWALL before the ZyWALL routes traffic for
Chapter 5 Configuration BasicsZyWALL USG 1000 User’s Guide1245.6.2 File ManagerUse these screens to upload, download, delete, or run scripts of CLI c
ZyWALL USG 1000 User’s Guide125CHAPTER 6 TutorialsThis chapter provides some examples of using the web configurator to set up features in the ZyWALL.
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide126Figure 44 Network > Interface > Port Grouping, Initial 2 Drag physical port 2 onto repres
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide127Figure 46 Status: Interface Status Summary After Port Grouping6.1.2 Set up Ethernet InterfacesTh
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide128Figure 48 Network > Interface > Ethernet > ge43 Use the default values for the rest of th
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide129Figure 51 Status > Interface Status Summary, After Ethernet Interface Edits6.1.3 WAN TrunkThi
Table of ContentsZyWALL USG 1000 User’s Guide135.2 Terminology in the ZyWALL ...
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide130Figure 54 Network > Interface > Trunk > Edit > Member 4 Use the default values for
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide131Figure 56 Network > Zone > DMZ, Remove ge4 3 Select IFACE/ge4 and click the left arrow to
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1326.2 IPSec VPNThis example is going to show you how to create the VPN tunnel illustrated below.Figur
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide133Figure 60 VPN > IPSec VPN > VPN Gateway > Add6.2.3 Set up the VPN ConnectionThe VPN con
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide134Figure 62 VPN > IPSec VPN > VPN Connection > add6.2.4 Set up the Policy Route for the VP
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide135Figure 64 Network > Routing > Policy Route > AddBecause the new VPN connection has not b
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1366.3 Device HAThis example is going to show you how to set up device HA as illustrated below.Figure
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide137Figure 67 Device HA > VRRP Group > Add: ge13 Click Status, and scroll down to the Interface
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide138Figure 69 Network > Device HA > VRRP Group > Add: ge4" Once you configure an interfa
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1396.3.4 Finish Configuring the MasterFinish configuring the master. The backup router will get these
Table of ContentsZyWALL USG 1000 User’s Guide146.2.2 Set up the VPN Gateway ...
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1406.3.7 Synchronize the Backup1 Connect the backup to the same network as the master.2 Click Device H
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1416.4.1 Set up User AccountsSet up one user account for each user account in the RADIUS server. If i
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1426.4.3 Set up User Authentication Using the RADIUS ServerThis step sets up user authentication using
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide143" The users will have to log in using the web configurator login screen before they can use HT
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide144Figure 81 AppPatrol > http > Edit Default4 Click the Add icon in the policy list. In the new
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide145Figure 83 Object > Schedule > Recurring > add3 Follow the steps in Section 6.4.4 on page
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide146Figure 85 Firewall > LAN > DMZ > Add5 Repeat this process to set up firewall rules for th
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide147Figure 87 Network > Interface > Ethernet > Edit > ge22 Click the Edit icon for ge3, a
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide148The firewall is enabled, so you also need to create a rule to allow traffic in from the WAN zone.Fig
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1496.6.2 NAT 1:1 Virtual ServerThis section sets up a virtual server rule that changes the destinatio
Table of ContentsZyWALL USG 1000 User’s Guide158.1 myZyXEL.com Overview ...
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide150Figure 94 NAT 1:1 Example Policy RouteClick Network > Routing > Policy Route > Add and co
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide151Figure 96 Create a Firewall Rule6.7 NAT LoopbackThe NAT 1:1 example in Section 6.6 on page 147 m
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1526.7.1 NAT Loopback Virtual ServerWhen a LAN user sends SMTP traffic to IP address 1.1.1.1, the traf
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1536.7.2 NAT Loopback Policy RouteWithout a NAT loopback policy route, the LAN user SMTP traffic goes
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide154Figure 102 Create a Policy RouteNow the LAN SMTP server replies to the ZyWALL’s LAN IP address and
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide1556.8 Service Control and the FirewallService control lets you configure rules that control HTTP and
Chapter 6 TutorialsZyWALL USG 1000 User’s Guide156Figure 105 System > WWW > Service Control Rule Edit 4 Click Apply.Figure 106 System >
ZyWALL USG 1000 User’s Guide157CHAPTER 7 StatusThis chapter explains the Status screen, which is the screen you see when you first log in to the ZyW
Chapter 7 StatusZyWALL USG 1000 User’s Guide158The following table describes the labels in this screen. Table 34 StatusLABEL DESCRIPTIONDevice Info
Chapter 7 StatusZyWALL USG 1000 User’s Guide159Signature VersionThis field displays the version number, date, and time of the current set of signatur
Table of ContentsZyWALL USG 1000 User’s Guide1610.6.1 PPPoE/PPTP Overview ...
Chapter 7 StatusZyWALL USG 1000 User’s Guide1607.2 VPN StatusUse this screen to look at the VPN tunnels that are currently established. To access thi
Chapter 7 StatusZyWALL USG 1000 User’s Guide161Figure 108 Status > VPN StatusThe following table describes the labels in this screen. 7.3 DHCP
Chapter 7 StatusZyWALL USG 1000 User’s Guide162Figure 109 Status > DHCP TableThe following table describes the labels in this screen. 7.4 Port S
Chapter 7 StatusZyWALL USG 1000 User’s Guide163Figure 110 Status > Port Statistics The following table describes the labels in this scre
Chapter 7 StatusZyWALL USG 1000 User’s Guide164Figure 111 Status > Current UsersThe following table describes the labels in this screen. Table 38
ZyWALL USG 1000 User’s Guide165CHAPTER 8 RegistrationThis chapter shows you how to register for the ZyWALL’s subscription services.8.1 myZyXEL.com O
Chapter 8 RegistrationZyWALL USG 1000 User’s Guide166• SSL VPN tunnels provide secure network access to remote users. You can purchase and enter a lic
Chapter 8 RegistrationZyWALL USG 1000 User’s Guide167The following table describes the labels in this screen. " If the ZyWALL is registered alr
Chapter 8 RegistrationZyWALL USG 1000 User’s Guide168Figure 113 Licensing > Registration: Registered Device8.3 Service After you activate a tria
Chapter 8 RegistrationZyWALL USG 1000 User’s Guide169Expiration date This field displays the date your service expires.You can continue to use IDP/Ap
Table of ContentsZyWALL USG 1000 User’s Guide1713.3 OSPF Overview ...
Chapter 8 RegistrationZyWALL USG 1000 User’s Guide170
ZyWALL USG 1000 User’s Guide171CHAPTER 9 UpdateThis chapter shows you how to update the ZyWALL’s signature packages.9.1 Updating Anti-virus Signatur
Chapter 9 UpdateZyWALL USG 1000 User’s Guide172Figure 115 Licensing > Update >Anti-Virus The following table describes the labels in this scre
Chapter 9 UpdateZyWALL USG 1000 User’s Guide1739.2 Updating IDP and Application Patrol Signatures The ZyWALL comes with signatures for the IDP and a
Chapter 9 UpdateZyWALL USG 1000 User’s Guide174Figure 117 Downloading IDP SignaturesFigure 118 Successful IDP Signature DownloadAuto Update Select
Chapter 9 UpdateZyWALL USG 1000 User’s Guide1759.3 Updating System Protect Signatures The ZyWALL comes with signatures that the ZyWALL uses to prote
Chapter 9 UpdateZyWALL USG 1000 User’s Guide176Figure 120 Downloading System Protect SignaturesFigure 121 Successful System Protect Signature Down
177PART IINetworkInterface (179)Trunks (219)Policy and Static Routes (225)Routing Protocols (235)Zones (245)DDNS (249)Virtual Servers (255)HTTP
178
ZyWALL USG 1000 User’s Guide179CHAPTER 10 InterfaceSee Section 5.4.2 on page 115 for related information on these screens.10.1 Interface OverviewIn
Table of ContentsZyWALL USG 1000 User’s Guide1818.1 ALG Introduction ...
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide180• Trunks manage load balancing between interfaces.Port groups, trunks, and the auxiliary interface
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide181Figure 122 Example: Entry in the Routing Table Derived from InterfacesFor example, if the ZyWALL
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide18210.1.3 Interface Parameters The ZyWALL restricts the amount of traffic into and out of the ZyWALL
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide183The ZyWALL cannot assign the first address (network address) or the last address (broadcast addres
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide18410.1.6 Relationships Between InterfacesIn the ZyWALL, interfaces are usually created on top of oth
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide185In addition, you use Ethernet interfaces to control which physical ports exchange routing informat
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide186Figure 123 Network > Interface > Interface Summary Each field is described in the foll
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide187Status This field displays the current status of each interface. The possible values depend on wha
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide18810.2.3 Ethernet Summary ScreenThis screen lists every Ethernet interface and virtual interface cre
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide189Each field is described in the following table. 10.2.4 Ethernet Edit The Ethernet Edit screen le
Table of ContentsZyWALL USG 1000 User’s Guide1920.4.2 Additional Topics for IKE SA ...
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide190Figure 125 Network > Interface > Ethernet > Edit
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide191Each field is described in the table below. Table 50 Network > Interface > Ethernet &g
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide192Direction This field is effective when RIP is enabled. Select the RIP direction from the drop-down
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide193Relay Server 2 This field is optional. Enter the IP address of another DHCP server for the network
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide19410.3 Port Grouping This section introduces port groups and then explains the screen for port group
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide195Each physical port is assigned to one Ethernet interface. In port grouping, the Ethernet interface
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide196Figure 129 Network > Interface > Port Grouping Each section in this screen is described
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide197Figure 130 Example: Before VLANIn this example, there are two physical networks and three depart
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide198• Better manageability - You can align network policies more appropriately for users. For example,
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide19910.4.4 VLAN Add/Edit This screen lets you configure IP address assignment, interface bandwidth pa
Table of ContentsZyWALL USG 1000 User’s Guide2024.3.1 Downloading a File ...
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide200Figure 133 Network > Interface > VLAN > Edit
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide201Each field is explained in the following table. Table 53 Network > Interface > VLAN > E
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide202DHCP Select what type of DHCP service the ZyWALL provides to the network. Choices are:None - the Zy
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide20310.5 Bridge Interfaces This section introduces bridges and bridge interfaces and then explains th
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide20410.5.1 Bridge OverviewA bridge creates a connection between two or more network segments at the la
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide20510.5.2 Bridge Interface OverviewA bridge interface creates a software bridge between the members
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide20610.5.4 Bridge Add/Edit This screen lets you configure IP address assignment, interface bandwidth p
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide207Figure 136 Network > Interface > Bridge > Edit
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide208In this example, you are creating a new bridge. If you are editing a bridge, the Interface Name fie
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide209MTU Maximum Transmission Unit. Type the maximum size of each data packet, in bytes, that can move
Table of ContentsZyWALL USG 1000 User’s Guide2127.5.1 Setting the Interface’s Bandwidth ...
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide21010.6 PPPoE/PPTP Interfaces This section introduces PPPoE, PPTP, and PPPoE/PPTP interfaces and then
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide211PPPoE is often used with cable modems and DSL connections. It provides the following advantages:•
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide21210.6.3 PPPoE/PPTP Interface Summary" You have to set up an ISP account before you create a PP
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide21310.6.4 PPPoE/PPTP Interface Add/Edit " You have to set up an ISP account before you create a
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide214Each field is explained in the following table.Table 60 Network > Interface > PPPoE/PPTP &g
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide21510.7 Auxiliary Interface This section introduces the auxiliary interface and then explains the sc
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide216Figure 141 Network > Interface > AuxiliaryEach field is described in the table below. Table
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide21710.8 Virtual Interfaces Use virtual interfaces to tell the ZyWALL where to route packets. Virtual
Chapter 10 InterfaceZyWALL USG 1000 User’s Guide218Figure 142 Network > Interface > AddEach field is described in the table below. Table 62
ZyWALL USG 1000 User’s Guide219CHAPTER 11 TrunksThis chapter shows you how to configure trunks on your ZyWALL. See Section 5.4.3 on page 115 for rela
Table of ContentsZyWALL USG 1000 User’s Guide2229.3 Configuring IDP General ...
Chapter 11 TrunksZyWALL USG 1000 User’s Guide220Maybe you have two connections with different bandwidths. For jitter-sensitive traffic (like video for
Chapter 11 TrunksZyWALL USG 1000 User’s Guide22111.4.2 Weighted Round Robin Round Robin scheduling services queues on a rotating basis and is activa
Chapter 11 TrunksZyWALL USG 1000 User’s Guide222Figure 145 Spillover Algorithm Example11.5 Trunk SummaryClick Network > Interface > Trunk to
Chapter 11 TrunksZyWALL USG 1000 User’s Guide223Figure 147 Network > Interface > Trunk > EditEach field is described in the table below. T
Chapter 11 TrunksZyWALL USG 1000 User’s Guide224Spillover This field displays with the spillover load balancing algorithm. Specify the maximum bandwid
ZyWALL USG 1000 User’s Guide225CHAPTER 12 Policy and Static RoutesThis chapter shows you how to configure policies for IP routing and static routes o
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide226IPPR follows the existing packet filtering facility of RAS in style and in implement
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide227Figure 148 Trigger Port Forwarding Example12.2.3 Maximize Bandwidth UsageThe max
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide228Figure 149 Network > Routing > Policy RouteThe following table describes the
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide22912.4 Policy Route Edit Click Network > Routing to open the Policy Route screen.
Table of ContentsZyWALL USG 1000 User’s Guide23Chapter 31Content Filter Screens...
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide230Figure 150 Network > Routing > Policy Route > EditThe following table des
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide231Type Select Auto to have the ZyWALL use the routing table to find a next-hop and f
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide23212.5 IP Static Routes The ZyWALL has no knowledge of the networks beyond the networ
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide23312.6 Static Route SummaryClick Network > Routing > Static Route to open the
Chapter 12 Policy and Static RoutesZyWALL USG 1000 User’s Guide234The following table describes the labels in this screen. Table 69 Network > Ro
ZyWALL USG 1000 User’s Guide235CHAPTER 13 Routing ProtocolsThis chapter describes how to set up RIP and OSPF routing protocol settings for the ZyWALL
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide236RIP uses UDP port 520.13.1.2 Authentication TypesAuthentication is used to guarantee the i
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide237Figure 154 Network > Routing > RIPThe following table describes the labels in this
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide238• OSPF filters and summarizes routing information, which reduces the size of routing tables
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide239This OSPF AS consists of four areas, areas 0-3. Area 0 is always the backbone. In this exa
Table of ContentsZyWALL USG 1000 User’s Guide2434.1.4 Access Users and the ZyWALL ...
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide240Figure 156 OSPF: Types of RoutersIn order to reduce the amount of traffic between routers
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide2412 Set up the OSPF areas.3 Configure the appropriate interfaces. See Section 10.2.1 on page
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide24213.4.2 OSPF Area Add/Edit The OSPF Area Add/Edit screen allows you to create a new area or
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide243Figure 159 Network > Routing > OSPF > EditThe following table describes the lab
Chapter 13 Routing ProtocolsZyWALL USG 1000 User’s Guide244Text Authentication KeyThis field is available if the Authentication is Text. Type the pass
ZyWALL USG 1000 User’s Guide245CHAPTER 14 ZonesSet up zones to configure network security and network policies in the ZyWALL. See Section 5.4.7 on p
Chapter 14 ZonesZyWALL USG 1000 User’s Guide246Intra-zone traffic is traffic between interfaces or VPN tunnels in the same zone. For example, in Figur
Chapter 14 ZonesZyWALL USG 1000 User’s Guide24714.3 Zone Add/Edit The Zone Add/Edit screen allows you to define a zone or edit an existing one. To a
Chapter 14 ZonesZyWALL USG 1000 User’s Guide248
ZyWALL USG 1000 User’s Guide249CHAPTER 15 DDNSThis chapter describes how to configure dynamic DNS (DDNS) services for the ZyWALL. First, it provides
Table of ContentsZyWALL USG 1000 User’s Guide2538.2 Directory Service (AD/LDAP) Overview ...
Chapter 15 DDNSZyWALL USG 1000 User’s Guide25015.1.2 High Availability (HA)The DDNS server maps a domain name to the IP address of one of the ZyWALL’
Chapter 15 DDNSZyWALL USG 1000 User’s Guide25115.3 DDNS SummaryThe DDNS screen provides a summary of all DDNS domain names and their configuration.
Chapter 15 DDNSZyWALL USG 1000 User’s Guide25215.4 Dynamic DNS Add/Edit The DDNS Add/Edit screen allows you to add a domain name to the ZyWALL or to
Chapter 15 DDNSZyWALL USG 1000 User’s Guide253HA Interface This field is only available when the IP Address Update Policy is Interface. Select the al
Chapter 15 DDNSZyWALL USG 1000 User’s Guide254
ZyWALL USG 1000 User’s Guide255CHAPTER 16 Virtual ServersThis chapter describes how to set up, manage, and remove virtual servers. First, it provides
Chapter 16 Virtual ServersZyWALL USG 1000 User’s Guide256The ZyWALL checks virtual servers before it applies to-ZyWALL firewall rules, so to-ZyWALL fi
Chapter 16 Virtual ServersZyWALL USG 1000 User’s Guide257Figure 166 Network > Virtual ServerThe following table describes the labels in this scr
Chapter 16 Virtual ServersZyWALL USG 1000 User’s Guide25816.4.1 Virtual Server Add/Edit The Virtual Server Add/Edit screen lets you create new virtua
Chapter 16 Virtual ServersZyWALL USG 1000 User’s Guide259User Defined This field is available if Original IP is User Defined. Type the destination IP
Table of ContentsZyWALL USG 1000 User’s Guide26Chapter 42SSL Application ...
Chapter 16 Virtual ServersZyWALL USG 1000 User’s Guide260
ZyWALL USG 1000 User’s Guide261CHAPTER 17 HTTP RedirectThis chapter shows you how to configure HTTP redirection on your ZyWALL. See Section 5.4.19 o
Chapter 17 HTTP RedirectZyWALL USG 1000 User’s Guide262Figure 168 HTTP Redirect ExampleIn the example, proxy server A is connected to ge4 in the DMZ
Chapter 17 HTTP RedirectZyWALL USG 1000 User’s Guide263Figure 169 Network > HTTP RedirectThe following table describes the labels in this screen
Chapter 17 HTTP RedirectZyWALL USG 1000 User’s Guide264Interface Select the interface on which the HTTP request must be received for the ZyWALL to for
ZyWALL USG 1000 User’s Guide265CHAPTER 18 ALGThis chapter covers how to use the ZyWALL’s ALG feature to allow certain applications to pass through th
Chapter 18 ALGZyWALL USG 1000 User’s Guide266You could also have a trunk with one interface set to active and a second interface set to passive. The Z
Chapter 18 ALGZyWALL USG 1000 User’s Guide267Figure 171 H.323 ALG Example 18.1.6 SIPThe Session Initiation Protocol (SIP) is an application-layer
Chapter 18 ALGZyWALL USG 1000 User’s Guide26818.1.6.2 SIP Signaling Session TimeoutMost SIP clients have an “expire” mechanism indicating the lifetim
Chapter 18 ALGZyWALL USG 1000 User’s Guide269For example, you configure firewall and virtual server rules to allow LAN IP address A to receive calls
Table of ContentsZyWALL USG 1000 User’s Guide2744.3 Configuring WWW ...
Chapter 18 ALGZyWALL USG 1000 User’s Guide270The following table describes the labels in this screen. Table 83 Network > ALGLABEL DESCRIPTIONEna
Chapter 18 ALGZyWALL USG 1000 User’s Guide27118.4 WAN to LAN SIP Peer-to-peer Calls ExampleThis example shows how to configure firewall and virtual
Chapter 18 ALGZyWALL USG 1000 User’s Guide272Figure 178 Firewall > WAN to LAN5 Configure the screen as follows. For the Destination, select Creat
Chapter 18 ALGZyWALL USG 1000 User’s Guide273Figure 181 Firewall > WAN > LAN > Add
Chapter 18 ALGZyWALL USG 1000 User’s Guide274
275PART IIIFirewall and VPNFirewall (277)IPSec VPN (291)SSL VPN (323)SSL User Screens (331)SSL User Application Screens (337)SSL User File Sharin
276
ZyWALL USG 1000 User’s Guide277CHAPTER 19 FirewallThis chapter introduces the ZyWALL’s firewall and shows you how to configure your ZyWALL’s firewa
Chapter 19 FirewallZyWALL USG 1000 User’s Guide278Your customized rules take precedence and override the ZyWALL’s default settings. The ZyWALL checks
Chapter 19 FirewallZyWALL USG 1000 User’s Guide279The following table explains the default firewall rules for traffic going through the ZyWALL. See S
Table of ContentsZyWALL USG 1000 User’s Guide2845.2 Configuration File Screen ...
Chapter 19 FirewallZyWALL USG 1000 User’s Guide280" The ZyWALL checks the firewall rules before the service control rules for traffic destined fo
Chapter 19 FirewallZyWALL USG 1000 User’s Guide281Your firewall would have the following configuration. • The first row blocks LAN access to the IRC
Chapter 19 FirewallZyWALL USG 1000 User’s Guide282Your firewall would have the following configuration. • The first row allows the LAN computer at IP
Chapter 19 FirewallZyWALL USG 1000 User’s Guide283You can have the ZyWALL permit the use of asymmetrical route topology on the network (not reset the
Chapter 19 FirewallZyWALL USG 1000 User’s Guide284Figure 186 Firewall The following table describes the labels in this screen. Table 88 FirewallL
Chapter 19 FirewallZyWALL USG 1000 User’s Guide285Maximum session per hostUse this field to set the highest number of sessions that the ZyWALL will p
Chapter 19 FirewallZyWALL USG 1000 User’s Guide28619.6.1 Edit a Firewall Rule In the Firewall screen, click the Edit or Add icon to display the Firew
Chapter 19 FirewallZyWALL USG 1000 User’s Guide28719.7 Firewall Rule Configuration ExampleThe following Internet firewall rule example allows a hypo
Chapter 19 FirewallZyWALL USG 1000 User’s Guide288Figure 188 Firewall Example: Select the Traveling Direction of Traffic2 Select From WAN and To LA
Chapter 19 FirewallZyWALL USG 1000 User’s Guide289Figure 190 Firewall Example: Create an Address Object4 Select Create Object in the Service drop-d
Table of ContentsZyWALL USG 1000 User’s Guide29Appendix F Open Software Announcements ...
Chapter 19 FirewallZyWALL USG 1000 User’s Guide290Figure 193 Firewall Example: MyService Example Rule in Summary
ZyWALL USG 1000 User’s Guide291CHAPTER 20 IPSec VPNThis chapter explains how to set up and maintain IPSec VPNs in the ZyWALL. See Section 5.4.4 on pa
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide292Figure 195 VPN: IKE SA and IPSec SA In this example, a computer in network A is exchanging data w
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide293Usually, you should select ESP. AH does not support encryption, and ESP is more suitable with NAT.
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide294If you enable PFS, the ZyWALL and remote IPSec router perform a DH key exchange every time an IPSec
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide295• Source address in outbound packets - this translation is necessary if you want the ZyWALL to rou
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide296• Destination - the original destination address; the local network (A).• SNAT - the translated sou
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide297• Make sure the to-ZyWALL firewall rules allow IPSec VPN traffic to the ZyWALL. IKE uses UDP port
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide298Each field is discussed in the following table. See Section 20.3.3 on page 302 and Section 20.3.2 o
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide299Figure 199 VPN > IPSec VPN > VPN Connection > Edit (IKE) Each field is described in the
About This User's GuideZyWALL USG 1000 User’s Guide3About This User's GuideThis manual is designed to guide you through the configuration
Table of ContentsZyWALL USG 1000 User’s Guide30
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide300Active Protocol Select which protocol you want to use in the IPSec SA. Choices are:AH (RFC 2402) -
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide301Policy EnforcementSelect this if you want the ZyWALL to drop traffic whose source and destination
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide30220.3.3 VPN Connection Add/Edit Manual Key The VPN Connection Add/Edit Manual Key screen allows you
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide303Figure 200 VPN > IPSec VPN > VPN Connection > Manual Key > EditThe following table d
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide304Encapsulation ModeSelect which type of encapsulation the IPSec SA uses. Choices areTunnel - this mo
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide305Authentication KeyEnter the authentication key, which depends on the authentication algorithm.MD5
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide30620.4 VPN Gateway Screens You use the VPN Gateway summary screen to look at the VPN gateways you ha
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide307It takes several steps to establish an IKE SA. The negotiation mode determines how many. There are
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide308" Both routers must use the same encryption algorithm, authentication algorithm, and DH key gr
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide309In main mode, the ZyWALL and remote IPSec router authenticate each other in steps 5 and 6, as illu
List of FiguresZyWALL USG 1000 User’s Guide31List of FiguresFigure 1 ZyWALL USG 1000 Front Panel ...
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide310For example, in Table 93 on page 310, the ZyWALL and the remote IPSec router authenticate each othe
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide31120.4.2.2 VPN, NAT, and NAT TraversalIn the following example, there is another router (A) between
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide312• Instead of using the pre-shared key, the ZyWALL and remote IPSec router check the signatures on e
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide31320.4.4 VPN Gateway Add/Edit The VPN Gateway Add/Edit screen allows you to create a new VPN gatewa
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide314Figure 206 VPN > IPSec VPN > VPN Gateway > EditEach field is described in the following
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide315Proposal# This field is a sequential value, and it is not associated with a specific proposal. The
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide316Secure Gateway AddressType the IP address or the domain name of the remote IPSec router. Set this f
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide317Peer ID Type Select which type of identification is used to identify the remote IPSec router durin
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide31820.5 VPN Concentrator A VPN concentrator combines several VPN connections into one secure network.
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide31920.5.1 VPN Concentrator SummaryYou use the VPN Concentrator summary screen to look at the VPN co
List of FiguresZyWALL USG 1000 User’s Guide32Figure 39 VPN Advanced Wizard: Step 3 ...
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide320Each field is described in the following table. 20.6 SA Monitor Screen You can use the SA Monitor
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide321Figure 211 VPN > IPSec VPN > SA MonitorEach field is described in the following table. Tab
Chapter 20 IPSec VPNZyWALL USG 1000 User’s Guide32220.6.1 Regular Expressions in Searching IPSec SAs by Name or PolicyA question mark (?) lets a sing
ZyWALL USG 1000 User’s Guide323CHAPTER 21 SSL VPNThis chapter shows you how to set up secure SSL VPN access for remote user login. See Section 5.4.5
Chapter 21 SSL VPNZyWALL USG 1000 User’s Guide32421.1.2 SSL Access Policy LimitationsYou cannot delete an object that is used by an SSL access policy
Chapter 21 SSL VPNZyWALL USG 1000 User’s Guide32521.3 Creating/Editing an SSL Access Policy To create a new or edit an existing SSL access policy, c
Chapter 21 SSL VPNZyWALL USG 1000 User’s Guide32621.4 SSL Connection Monitor The ZyWALL keeps track of the users who are currently logged into the VP
Chapter 21 SSL VPNZyWALL USG 1000 User’s Guide327• log out a user and delete related session information. Once a user logs out, the corresponding ent
Chapter 21 SSL VPNZyWALL USG 1000 User’s Guide328Figure 215 VPN > SSL VPN > Global Setting The following table describes the labels in this sc
Chapter 21 SSL VPNZyWALL USG 1000 User’s Guide32921.5.1 Uploading a Custom LogoFollow the steps below to upload a custom logo on the ZyWALL. 1 Click
List of FiguresZyWALL USG 1000 User’s Guide33Figure 82 AppPatrol > http > Edit Default ...
Chapter 21 SSL VPNZyWALL USG 1000 User’s Guide330Figure 217 SSL VPN Client Portal Screen Example If the user account is not set up for SSL VPN acces
ZyWALL USG 1000 User’s Guide331CHAPTER 22 SSL User ScreensThis chapter introduces secure network access and gives an overview of the remote user scre
Chapter 22 SSL User ScreensZyWALL USG 1000 User’s Guide332• Internet Explorer 5.5 and above (for IE7, JRE 1.6 must be enabled)• Netscape 7.2 and above
Chapter 22 SSL User ScreensZyWALL USG 1000 User’s Guide333Figure 220 Login Security Screen 3 A login screen displays. Enter the user name and pas
Chapter 22 SSL User ScreensZyWALL USG 1000 User’s Guide334" Available resource links vary depending on the configuration your network administrat
Chapter 22 SSL User ScreensZyWALL USG 1000 User’s Guide33522.4 BookmarkYou can create a bookmark of the ZyWALL by clicking the Add to Favorite icon.
Chapter 22 SSL User ScreensZyWALL USG 1000 User’s Guide336
ZyWALL USG 1000 User’s Guide337CHAPTER 23 SSL User Application ScreensThis chapter describes the Application screens you use to access an application
Chapter 23 SSL User Application ScreensZyWALL USG 1000 User’s Guide338
ZyWALL USG 1000 User’s Guide339CHAPTER 24 SSL User File Sharing ScreensThis chapter describes the File Sharing screen you use to access files on a fi
List of FiguresZyWALL USG 1000 User’s Guide34Figure 125 Network > Interface > Ethernet > Edit ...
Chapter 24 SSL User File Sharing ScreensZyWALL USG 1000 User’s Guide340Figure 228 File Sharing 24.3 Opening a File or FolderYou can open a file if
Chapter 24 SSL User File Sharing ScreensZyWALL USG 1000 User’s Guide3414 A list of files/folders displays. Click on a file to open it in a separate b
Chapter 24 SSL User File Sharing ScreensZyWALL USG 1000 User’s Guide342Figure 231 File Sharing: Save a Word File 24.4 Creating a New FolderTo crea
Chapter 24 SSL User File Sharing ScreensZyWALL USG 1000 User’s Guide343Figure 233 File Sharing: Rename A popup window displays. Specify the new nam
Chapter 24 SSL User File Sharing ScreensZyWALL USG 1000 User’s Guide34424.7 Uploading a FileFollow the steps below to upload a file to the file serve
ZyWALL USG 1000 User’s Guide345CHAPTER 25 L2TP VPNThis chapter explains how to set up and maintain L2TP VPNs in the ZyWALL. See Section 5.4.6 on page
Chapter 25 L2TP VPNZyWALL USG 1000 User’s Guide346• Use transport mode.• Not be a manual key VPN connection. •Use Pre-Shared Key authentication.• Use
Chapter 25 L2TP VPNZyWALL USG 1000 User’s Guide34725.4 L2TP VPN ConfigurationClick VPN > L2TP VPN to open the following screen. Use this screen t
Chapter 25 L2TP VPNZyWALL USG 1000 User’s Guide34825.5 L2TP VPN Session MonitorClick VPN > L2TP VPN > Session Monitor to open the following scr
Chapter 25 L2TP VPNZyWALL USG 1000 User’s Guide349Disconnect Click the Disconnect icon next to an L2TP VPN connection to disconnect it.Refresh Click
List of FiguresZyWALL USG 1000 User’s Guide35Figure 168 HTTP Redirect Example ...
Chapter 25 L2TP VPNZyWALL USG 1000 User’s Guide350
ZyWALL USG 1000 User’s Guide351CHAPTER 26 L2TP VPN ExampleThis chapter shows how to create a basic L2TP VPN tunnel.26.1 L2TP VPN ExampleThis chapter
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide352Figure 242 VPN > IPSec VPN > VPN Gateway > Edit • Configure the My Address settin
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide35326.3 Configuring the Default L2TP VPN Connection Example1 Click VPN > Network > IPSe
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide354Figure 245 VPN > IPSec VPN > VPN Connection (Enable) 26.4 Configuring the L2TP VPN
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide355Figure 247 Routing > Add: L2TP VPN Example2 Configure the following.• Enable the polic
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide35626.6.1 Configuring L2TP in Windows XPIn Windows XP do the following to establish an L2TP VP
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide357Figure 250 New Connection Wizard: Connection Name6 Select Do not dial the initial connect
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide358Figure 252 New Connection Wizard: VPN Server Selection8 Click Finish.9 The Connect L2TP to
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide359Figure 254 Connect L2TP to ZyWALL: Security11 Select Optional encryption (connect even if
List of FiguresZyWALL USG 1000 User’s Guide36Figure 211 VPN > IPSec VPN > SA Monitor ...
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide360Figure 256 L2TP to ZyWALL Properties > Security13 Select the Use pre-shared key for aut
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide361Figure 259 Connect L2TP to ZyWALL16 A window appears while the user name and password are
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide3621 Click Start > Run. Type regedit and click OK.Figure 262 Starting the Registry Editor2
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide363Figure 265 ProhibitIpSec DWORD Value6 Restart the computer and continue with the next sec
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide364Figure 268 Add > IP Security Policy Management > Finish4 Right-click IP Security Pol
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide365Figure 270 IP Security Policy: Name6 Clear the Activate the default response rule check b
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide3668 In the properties dialog box, click Add > Next.Figure 273 IP Security Policy Properti
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide367Figure 275 IP Security Policy Properties: Network Type11 Select Use this string to protec
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide368Figure 277 IP Security Policy Properties: IP Filter List13 Type ZyWALL WAN_IP in the Name
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide369Figure 279 Filter Properties: Addressing15 Configure the following in the Filter Properti
List of FiguresZyWALL USG 1000 User’s Guide37Figure 254 Connect L2TP to ZyWALL: Security ...
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide370Figure 281 IP Security Policy Properties: IP Filter List17 Select Require Security and cl
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide37126.6.2.3 Configure the Windows 2000 Network ConnectionAfter you have configured the IPSec
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide372Figure 286 New Connection Wizard: Destination Address4 Select For all users and click Next
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide3736 Click Properties.Figure 289 Connect L2TP to ZyWALL7 Click Security and select Advanced
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide374Figure 291 Connect L2TP to ZyWALL: Security > Advanced9 Click Networking and select Lay
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide375Figure 293 Connect L2TP to ZyWALL11 A ZyWALL-L2TP icon displays in your system tray. Doub
Chapter 26 L2TP VPN ExampleZyWALL USG 1000 User’s Guide376
377PART IVApplication Patrol & Anti-XApplication Patrol (379)Anti-Virus (403)IDP (417)ADP (445)Content Filter Screens (463)Content Filter Rep
378
ZyWALL USG 1000 User’s Guide379CHAPTER 27 Application PatrolThis chapter describes how to use application patrol for the ZyWALL. It provides an overv
List of FiguresZyWALL USG 1000 User’s Guide38Figure 297 LAN to WAN, Outbound 200 kbps, Inbound 500 kbps ...
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide380" The ZyWALL allows the first eight packets to go through the firewall, regardless of
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide38127.4.1 Connection and Packet Directions Application patrol looks at the connection direc
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide382Figure 297 LAN to WAN, Outbound 200 kbps, Inbound 500 kbps 27.4.3 Bandwidth Management
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide383Figure 298 Bandwidth Management Behavior27.4.5.1 Configured Rate EffectIn the followin
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide38427.4.5.4 Priority and Over Allotment of Bandwidth EffectServer A has a configured rate th
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide385Figure 299 Application Patrol Bandwidth Management Example27.5.1 Setting the Interface
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide386Figure 300 SIP Any to WAN Bandwidth Management Example27.5.3 SIP WAN to Any Bandwidth M
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide387• Third highest priority (3).• Disable maximize bandwidth usage since you do not want to
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide38827.6 Other ApplicationsSometimes, the ZyWALL cannot identify the application. For example
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide389Figure 304 AppPatrol > GeneralThe following table describes the labels in this scree
List of FiguresZyWALL USG 1000 User’s Guide39Figure 340 Base Profiles ...
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide39027.9 Application Patrol ApplicationsUse the application patrol Common, Instant Messenger,
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide39127.9.1 Application Patrol Edit Use this screen to edit the settings for an application.
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide392# This field is a sequential value, and it is not associated with a specific condition.Not
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide39327.9.2 Application Patrol Policy Edit The Application Policy Edit screen allows you to e
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide394Schedule Select a schedule that defines when the policy applies or select Create Object to
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide39527.10 Other Protocol Screen The Other Protocol screen controls the default policy for TC
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide396The following table describes the labels in this screen. See Section 27.10.1 on page 397 f
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide39727.10.1 Other Configuration Add/Edit The Other Configuration Add/Edit screen allows you
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide398Schedule Select a schedule that defines when the policy applies or select Create Object to
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide39927.11 Application Patrol StatisticsThis screen displays a bandwidth usage graph and stat
About This User's GuideZyWALL USG 1000 User’s Guide4" It is recommended you use the web configurator to configure the ZyWALL.• Web Configura
List of FiguresZyWALL USG 1000 User’s Guide40Figure 383 Object > Service > Service > Edit ...
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide400The following table describes the labels in this screen. 27.11.2 Application Patrol Stat
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide401Figure 312 AppPatrol > Statistics: Protocol StatisticsThe following table describes
Chapter 27 Application PatrolZyWALL USG 1000 User’s Guide402Forwarded Data (KB) This is how much of the application’s traffic the ZyWALL has sent (in
ZyWALL USG 1000 User’s Guide403CHAPTER 28 Anti-VirusThis chapter introduces and shows you how to configure the anti-virus scanner. See Section 5.4.14
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide4044 Once the virus is spread through the network, the number of infected networked computers can gro
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide405Figure 313 ZyWALL Anti-virus Example The following describes the virus scanning process on th
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide406• Encrypted traffic. This could be password-protected files or VPN traffic where the ZyWALL is not
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide407The following table describes the labels in this screen.Table 121 Anti-X > Anti-Virus > G
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide40828.3.1 Anti-Virus Policy EditClick the Add or Edit icon in the Anti-X > Anti-Virus > Genera
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide409Protocols to Scan Select which protocols of traffic to scan for viruses.FTP applies to traffic us
List of FiguresZyWALL USG 1000 User’s Guide41Figure 426 Secure and Insecure Service Access From the WAN ...
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide41028.4 Anti-Virus SettingClick Anti-X > Anti-Virus > Setting screen to display the configurat
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide411The following table describes the labels in this screen.Table 123 Anti-X > Anti-Virus > S
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide41228.5 Anti-Virus White List Add/EditFrom the Anti-X > Anti-Virus > Setting screen, click a w
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide41328.6 Anti-Virus Black List Add/EditFrom the Anti-X > Anti-Virus > Setting screen, click a
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide414Figure 319 Anti-X > Anti-Virus > Signature: Search by SeverityThe following table describe
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide415Severity This is the severity level of the anti-virus signature. Click the severity column header
Chapter 28 Anti-VirusZyWALL USG 1000 User’s Guide416
ZyWALL USG 1000 User’s Guide417CHAPTER 29 IDPThis chapter introduces IDP (Intrusion, Detection and Prevention), IDP profiles, binding an IDP profile
Chapter 29 IDPZyWALL USG 1000 User’s Guide41829.1.4 SignaturesIf a packet matches a signature, the action specified by the signature is taken. You ca
Chapter 29 IDPZyWALL USG 1000 User’s Guide419Figure 320 Anti-X > IDP > GeneralThe following table describes the screens in this screen. Table
List of FiguresZyWALL USG 1000 User’s Guide42Figure 469 Maintenance > Log > Log Setting ...
Chapter 29 IDPZyWALL USG 1000 User’s Guide42029.4 Configuring IDP BindingsClick Anti-X > IDP > General and then an Add or Edit icon to display
Chapter 29 IDPZyWALL USG 1000 User’s Guide421Figure 321 Anti-X > IDP > General > AddThe following table describes the screens in this scre
Chapter 29 IDPZyWALL USG 1000 User’s Guide422Figure 322 Base ProfilesThe following table describes this screen. 29.6 Profile Summary ScreenSelect A
Chapter 29 IDPZyWALL USG 1000 User’s Guide423Figure 323 Anti-X > IDP > ProfileThe following table describes the fields in this screen. 29.7
Chapter 29 IDPZyWALL USG 1000 User’s Guide424" If Internet Explorer opens a warning screen about a script making Internet Explorer run slowly and
Chapter 29 IDPZyWALL USG 1000 User’s Guide425Figure 324 Anti-X > IDP > Profile > Edit : Group View
Chapter 29 IDPZyWALL USG 1000 User’s Guide426The following table describes the fields in this screen. Table 131 Anti-X > IDP > Profile > G
Chapter 29 IDPZyWALL USG 1000 User’s Guide42729.8.2 Policy TypesThis section describes IDP policy types, also known as attack types, as categorized
Chapter 29 IDPZyWALL USG 1000 User’s Guide42829.8.3 IDP Service GroupsAn IDP service group is a set of related packet inspection signatures.DoS/DDoS
Chapter 29 IDPZyWALL USG 1000 User’s Guide429The following figure shows the WEB_PHP service group that contains signatures related to attacks on web
List of TablesZyWALL USG 1000 User’s Guide43List of TablesTable 1 Front Panel LEDs ...
Chapter 29 IDPZyWALL USG 1000 User’s Guide430Figure 326 Anti-X > IDP > Profile: Query ViewThe following table describes the fields in this scr
Chapter 29 IDPZyWALL USG 1000 User’s Guide43129.8.5 Query ExampleThis example shows a search with these criteria:• Severity: severe and high• Attack
Chapter 29 IDPZyWALL USG 1000 User’s Guide432Figure 328 Query Example Search Results29.9 Introducing IDP Custom Signatures Create custom signatures
Chapter 29 IDPZyWALL USG 1000 User’s Guide433Figure 329 IP v4 Packet Headers The header fields are discussed below: Table 135 IP v4 Packet Heade
Chapter 29 IDPZyWALL USG 1000 User’s Guide43429.10 Configuring Custom SignaturesSelect Anti-X > IDP > Custom Signatures. The first screen shows
Chapter 29 IDPZyWALL USG 1000 User’s Guide435The following table describes the fields in this screen. 29.10.1 Creating or Editing a Custom Signatur
Chapter 29 IDPZyWALL USG 1000 User’s Guide436Figure 331 Anti-X > IDP > Custom Signatures > Add/Edit
Chapter 29 IDPZyWALL USG 1000 User’s Guide437The following table describes the fields in this screen. Table 137 Anti-X > IDP > Custom Signatu
Chapter 29 IDPZyWALL USG 1000 User’s Guide438IP Options IP options is a variable-length list of IP options for a datagram that define IP Security Opti
Chapter 29 IDPZyWALL USG 1000 User’s Guide43929.10.2 Custom Signature ExampleBefore creating a custom signature, you must first clearly understand t
List of TablesZyWALL USG 1000 User’s Guide44Table 39 Licensing > Registration ...
Chapter 29 IDPZyWALL USG 1000 User’s Guide44029.10.2.2 Analyze PacketsThen use a packet sniffer such as TCPdump or Ethereal to investigate some more.
Chapter 29 IDPZyWALL USG 1000 User’s Guide441Figure 335 Example Custom Signature
Chapter 29 IDPZyWALL USG 1000 User’s Guide44229.10.3 Applying Custom SignaturesAfter you create your custom signature, it becomes available in the ID
Chapter 29 IDPZyWALL USG 1000 User’s Guide443Figure 337 Custom Signature Log29.10.5 Snort SignaturesYou may want to refer to open source Snort sig
Chapter 29 IDPZyWALL USG 1000 User’s Guide444" Not all Snort functionality is supported in the ZyWALL.Flow flowFlags flagsSequence Number seqAck
ZyWALL USG 1000 User’s Guide445CHAPTER 30 ADPThis chapter introduces ADP (Anomaly Detection and Prevention), anomaly profiles and binding an ADP pro
Chapter 30 ADPZyWALL USG 1000 User’s Guide44630.1.3 ADP on the ZyWALLADP on the ZyWALL protects against network-based intrusions. See Section 30.8 on
Chapter 30 ADPZyWALL USG 1000 User’s Guide447The following table describes the screens in this screen. 30.4 Configuring Anomaly Profile BindingsClic
Chapter 30 ADPZyWALL USG 1000 User’s Guide448Figure 339 Anti-X > ADP > General > AddThe following table describes the screens in this scree
Chapter 30 ADPZyWALL USG 1000 User’s Guide449Figure 340 Base ProfilesThese are the default base profiles at the time of writing. 30.6 Profile Summ
List of TablesZyWALL USG 1000 User’s Guide45Table 82 Network > HTTP Redirect > Edit ...
Chapter 30 ADPZyWALL USG 1000 User’s Guide45030.7 Creating New Profiles You may want to create a new profile if not all rules in a base profile are a
Chapter 30 ADPZyWALL USG 1000 User’s Guide45130.8.1 Port ScanningAn attacker scans device(s) to determine what types of network protocols or service
Chapter 30 ADPZyWALL USG 1000 User’s Guide45230.8.1.4 Filtered Port ScansA filtered port scan may indicate that there were no network errors (ICMP un
Chapter 30 ADPZyWALL USG 1000 User’s Guide45330.8.2.3 TCP SYN Flood AttackUsually a client starts a session by sending a SYN (synchronize) packet to
Chapter 30 ADPZyWALL USG 1000 User’s Guide45430.8.2.5 UDP Flood AttackUDP is a connection-less protocol and it does not require any connection setup
Chapter 30 ADPZyWALL USG 1000 User’s Guide45530.8.3 Profile > Traffic Anomaly ScreenFigure 345 Profiles: Traffic Anomaly
Chapter 30 ADPZyWALL USG 1000 User’s Guide456The following table describes the fields in this screen. 30.9 Profiles: Protocol Anomaly Protocol anoma
Chapter 30 ADPZyWALL USG 1000 User’s Guide457Protocol anomaly detection includes HTTP Inspection, TCP Decoder, UDP Decoder and ICMP Decoder where eac
Chapter 30 ADPZyWALL USG 1000 User’s Guide458OVERSIZE-CHUNK-ENCODING ATTACKThis rule is an anomaly detector for abnormally large chunk sizes. This pic
Chapter 30 ADPZyWALL USG 1000 User’s Guide45930.9.2 Protocol Anomaly ConfigurationIn the Anti-X > ADP > Profile screen, click the Edit icon or
List of TablesZyWALL USG 1000 User’s Guide46Table 125 Anti-X > Anti-Virus > Setting > Black List Add ...
Chapter 30 ADPZyWALL USG 1000 User’s Guide460Figure 346 Profiles: Protocol Anomaly
Chapter 30 ADPZyWALL USG 1000 User’s Guide461The following table describes the fields in this screen. Table 145 ADP > Profile > Protocol Ano
Chapter 30 ADPZyWALL USG 1000 User’s Guide462
ZyWALL USG 1000 User’s Guide463CHAPTER 31 Content Filter ScreensThis chapter covers how to use the content filter feature to control web access. See
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide46431.1.3 Content Filter Configuration GuidelinesYou must configure an address object, a
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide465Block web access when no policy is appliedSelect this check box to stop users from ac
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide46631.3 Content Filter Policy Screen Click Anti-X > Content Filter > General >
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide467The following table describes the labels in this screen. 31.4 Content Filter Profil
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide46831.5 External Web Filtering Service When you register for and enable the external web
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide46931.6 Content Filter Categories Screen Click Anti-X > Content Filter > Filter P
List of TablesZyWALL USG 1000 User’s Guide47Table 168 Object > Address > Address Group > Add ...
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide470Figure 351 Anti-X > Content Filter > Filter Profile > Add The following tab
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide471Enable External Web Filter ServiceEnable external database content filtering to have
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide472Intimate Apparel/Swimsuit Selecting this category excludes pages that contain images o
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide473Arts/Entertainment Selecting this category excludes pages that promote and provide in
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide474Political/Activist Groups Selecting this category excludes pages sponsored by or which
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide475Open Image/Media Search Selecting this category excludes pages with image or video s
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide476Sexuality/Alternative Lifestyles Selecting this category excludes pages that provide i
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide47731.7 Content Filter Customization Screen Click Anti-X > Content Filter > Filte
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide478Figure 352 Anti-X > Content Filter > Filter Profile > Customization The fol
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide479Allow Web traffic for trusted web sites onlyWhen this box is selected, the ZyWALL blo
List of TablesZyWALL USG 1000 User’s Guide48Table 211 SNMP Traps ...
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide48031.8 Keyword Blocking URL CheckingThe ZyWALL checks the URL’s domain name (or IP addr
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide481Please see Section 32.2 on page 488 for how to submit a web site that has been incorr
Chapter 31 Content Filter ScreensZyWALL USG 1000 User’s Guide482Page x of x This is the number of the page of entries currently displayed and the tota
ZyWALL USG 1000 User’s Guide483CHAPTER 32 Content Filter ReportsThis chapter describes how to view content filtering reports after you have activated
Chapter 32 Content Filter ReportsZyWALL USG 1000 User’s Guide484ZyWALL using the Rename button in the Service Management screen (see Figure 356 on pag
Chapter 32 Content Filter ReportsZyWALL USG 1000 User’s Guide4856 Click Submit.Figure 357 Blue Coat: Login7 In the Web Filter Home screen, click th
Chapter 32 Content Filter ReportsZyWALL USG 1000 User’s Guide486Figure 359 Blue Coat: Report Home9 Select a time period in the Date Range field, eit
Chapter 32 Content Filter ReportsZyWALL USG 1000 User’s Guide487Figure 360 Global Report Screen Example11 You can click a category in the Categorie
Chapter 32 Content Filter ReportsZyWALL USG 1000 User’s Guide488Figure 361 Requested URLs Example32.2 Web Site SubmissionYou may find that a web si
Chapter 32 Content Filter ReportsZyWALL USG 1000 User’s Guide489Figure 362 Web Page Review Process Screen3 Type the web site’s URL in the field and
List of TablesZyWALL USG 1000 User’s Guide49Table 254 Interface Logs ...
Chapter 32 Content Filter ReportsZyWALL USG 1000 User’s Guide490
491PART VDevice HA & ObjectsDevice HA (493)User/Group (503)Addresses (515)Services (521)Schedules (527)AAA Server (531)Authentication Object
ZyWALL USG 1000 User’s Guide493CHAPTER 33 Device HAUse device HA and Virtual Router Redundancy Protocol (VRRP) to increase network reliability. See
Chapter 33 Device HAZyWALL USG 1000 User’s Guide494" Every router in a virtual router must use the same advertisement interval.If Router A become
Chapter 33 Device HAZyWALL USG 1000 User’s Guide49533.1.1 Additional VRRP Notes• It is possible to set up two virtual routers so that they back up e
Chapter 33 Device HAZyWALL USG 1000 User’s Guide49633.2.1 Link Monitoring and Remote ManagementWith link monitoring enabled, a backup ZyWALL that tak
Chapter 33 Device HAZyWALL USG 1000 User’s Guide497Figure 366 Device HA > VRRP GroupThe following table describes the labels in this screen. See
Chapter 33 Device HAZyWALL USG 1000 User’s Guide49833.5 VRRP Group Add/Edit The VRRP Group Add/Edit screen allows you to add VRRP groups to the ZyWAL
Chapter 33 Device HAZyWALL USG 1000 User’s Guide499VRID Type the virtual router ID number.Description Type the description of the VRRP group. This fi
Document ConventionsZyWALL USG 1000 User’s Guide5Document ConventionsWarnings and NotesThese are how warnings and notes are shown in this User’s Guid
List of TablesZyWALL USG 1000 User’s Guide50
Chapter 33 Device HAZyWALL USG 1000 User’s Guide50033.6 Synchronization Overview In a virtual router, backup routers do not automatically get configu
Chapter 33 Device HAZyWALL USG 1000 User’s Guide501" You must subscribe to services on the backup ZyWALL before synchronizing it with the master
Chapter 33 Device HAZyWALL USG 1000 User’s Guide502Sync. Now Click this button to get updated certificates, AV signatures, IDP and application patrol
ZyWALL USG 1000 User’s Guide503CHAPTER 34 User/GroupThis chapter describes how to set up user accounts, user groups, and user settings for the ZyWAL
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide50434.1.2 Ext-User AccountsSet up an Ext-User account if the user is authenticated by an external se
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide50534.1.2.2 Creating a Large Number of Ext-User AccountsIf you plan to create a large number of Ext
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide506" This works with HTTP traffic only. The ZyWALL does not force users to log in before it rout
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide507Figure 372 User/Group > User > EditThe following table describes the labels in this scree
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide50834.2.1.1 Rules for User NamesEnter a user name from 1 to 31 characters.The user name can only con
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide50934.3.1 Group Add/Edit The Group Add/Edit screen allows you to create a new user group or edit an
51PART IIntroductionIntroducing the ZyWALL (53)Features and Applications (57)Web Configurator (65)Configuration Basics (111)Tutorials (125)Status
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide51034.4 Setting Screen The Setting screen controls default settings, login settings, lockout setting
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide511User Logon SettingLimit ... for administration accountSelect this check box if you want to set a
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide51234.4.1 Force User Authentication Policy Add/Edit Use this screen to specify a condition when user
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide513The following table describes the labels in this screen. 34.5 Web Configurator for Non-Admin Us
Chapter 34 User/GroupZyWALL USG 1000 User’s Guide514The following table describes the labels in this screen. Table 164 Web Configurator for Non-Adm
ZyWALL USG 1000 User’s Guide515CHAPTER 35 AddressesThis chapter describes how to set up addresses and address groups for the ZyWALL. See Section 5.5
Chapter 35 AddressesZyWALL USG 1000 User’s Guide516Figure 378 Object > Address > AddressThe following table describes the labels in this scree
Chapter 35 AddressesZyWALL USG 1000 User’s Guide517The following table describes the labels in this screen. 35.3 Address Group Screens Use the Addre
Chapter 35 AddressesZyWALL USG 1000 User’s Guide518The following table describes the labels in this screen. See Section 35.3.2 on page 518 for more in
Chapter 35 AddressesZyWALL USG 1000 User’s Guide519Available This field displays the names of the address and address group objects that can be added
52
Chapter 35 AddressesZyWALL USG 1000 User’s Guide520
ZyWALL USG 1000 User’s Guide521CHAPTER 36 ServicesUse service objects to define TCP applications, UDP applications, and ICMP messages. You can also c
Chapter 36 ServicesZyWALL USG 1000 User’s Guide522• UDP applications• ICMP messages• user-defined services (for other types of IP protocols)These obje
Chapter 36 ServicesZyWALL USG 1000 User’s Guide52336.2.1 Service Add/Edit The Service Add/Edit screen allows you to create a new service or edit an
Chapter 36 ServicesZyWALL USG 1000 User’s Guide52436.3 Service Group Summary Screen The Service Group summary screen provides a summary of all servic
Chapter 36 ServicesZyWALL USG 1000 User’s Guide525Figure 385 Object > Service > Service Group > EditThe following table describes the labe
Chapter 36 ServicesZyWALL USG 1000 User’s Guide526
ZyWALL USG 1000 User’s Guide527CHAPTER 37 SchedulesUse schedules to set up one-time and recurring schedules for policy routes, firewall rules, applic
Chapter 37 SchedulesZyWALL USG 1000 User’s Guide528Figure 386 Object > ScheduleThe following table describes the labels in this screen. See Secti
Chapter 37 SchedulesZyWALL USG 1000 User’s Guide529Figure 387 Object > Schedule > Edit (One Time)The following table describes the labels in
ZyWALL USG 1000 User’s Guide53CHAPTER 1 Introducing the ZyWALLThis chapter gives an overview of the ZyWALL. It explains the front panel ports, LEDs,
Chapter 37 SchedulesZyWALL USG 1000 User’s Guide530Figure 388 Object > Schedule > Edit (Recurring)The Yea r, Month, and Day columns are not us
ZyWALL USG 1000 User’s Guide531CHAPTER 38 AAA ServerThis chapter introduces and shows you how to configure the ZyWALL to use external authentication
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide5325 Configure the ASAS as a RADIUS server in the ZyWALL’s Object > AAA Server screens.6 Give the
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide533Figure 390 Basic Directory Structure 38.2.2 Distinguished Name (DN) A DN uniquely identifies a
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide534Figure 391 Object > AAA Server > Active Directory (or LDAP) > Default The following tab
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide5351 Click Object > AAA Server > Active Directory (or LDAP) > Group to display the screen.
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide536The following table describes the labels in this screen. 38.4 RADIUS Server RADIUS (Remote Authe
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide537Figure 394 RADIUS Server Network Example38.5 Configuring a Default RADIUS ServerTo configure t
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide53838.6 Configuring a Group of RADIUS Servers You can configure a group of RADIUS servers in the RAD
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide539The following table describes the labels in this screen. Table 181 Object > AAA Server >
Chapter 1 Introducing the ZyWALLZyWALL USG 1000 User’s Guide54The following table describes the LEDs.1.3 Management OverviewYou can use the following
Chapter 38 AAA ServerZyWALL USG 1000 User’s Guide540
ZyWALL USG 1000 User’s Guide541CHAPTER 39 Authentication ObjectsThis chapter shows you how to select different authentication methods for user authe
Chapter 39 Authentication ObjectsZyWALL USG 1000 User’s Guide54239.3 Creating an Authentication Object Follow the steps below to create an authentica
Chapter 39 Authentication ObjectsZyWALL USG 1000 User’s Guide543The following table describes the labels in this screen. 39.3.1 Example: Selecting
Chapter 39 Authentication ObjectsZyWALL USG 1000 User’s Guide544Figure 400 Example: Using Authentication Method in VPN
ZyWALL USG 1000 User’s Guide545CHAPTER 40 CertificatesThis chapter gives background information about public-key certificates and explains how to use
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide546Certification authorities maintain directory servers with databases of valid and revoked certifi
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide547" Be careful to not convert a binary file to text during the transfer process. It is easy
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide548Figure 402 Certificate Details 4 Use a secure method to verify that the certificate owner has
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide549The following table describes the labels in this screen. 40.6.1 My Certificates Add Screen C
Chapter 1 Introducing the ZyWALLZyWALL USG 1000 User’s Guide55Command-Line Interface (CLI)The CLI allows you to use text-based commands to configure
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide550Figure 404 Object > Certificate > My Certificates > AddThe following table describes
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide551Organization Identify the company or group to which the certificate owner belongs. You can use
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide552If you configured the My Certificate Create screen to have the ZyWALL enroll a certificate and t
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide553Figure 405 Object > Certificate > My Certificates > Edit The following table des
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide554Type This field displays general information about the certificate. CA-signed means that a Certi
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide55540.6.3 My Certificate Import Screen Click Object > Certificate > My Certificates > Im
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide556The following table describes the labels in this screen. 40.7 Trusted Certificates Screen Cl
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide55740.8 Trusted Certificates Edit Screen Click Object > Certificate > Trusted Certificates
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide558Figure 408 Object > Certificate > Trusted Certificates > Edit The following table des
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide559Refresh Click Refresh to display the certification path.Enable X.509v3 CRL Distribution Points
Chapter 1 Introducing the ZyWALLZyWALL USG 1000 User’s Guide56" It is recommended you use the shutdown command before turning off the ZyWALL.When
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide56040.9 Trusted Certificates Import Screen Click Object > Certificate > Trusted Certificates
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide561Figure 409 Object > Certificate > Trusted Certificates > ImportThe following table d
Chapter 40 CertificatesZyWALL USG 1000 User’s Guide562
ZyWALL USG 1000 User’s Guide563CHAPTER 41 ISP AccountsUse ISP accounts to manage Internet Service Provider (ISP) account information for PPPoE/PPTP i
Chapter 41 ISP AccountsZyWALL USG 1000 User’s Guide56441.3 ISP Account Edit The ISP Account Edit screen lets you add information about new accounts a
Chapter 41 ISP AccountsZyWALL USG 1000 User’s Guide565Encryption MethodThis field is available if this ISP account uses the PPTP protocol. Use the dr
Chapter 41 ISP AccountsZyWALL USG 1000 User’s Guide566
ZyWALL USG 1000 User’s Guide567CHAPTER 42 SSL ApplicationThis chapter describes how to configure SSL application objects for use in SSL VPN.42.1 SSL
Chapter 42 SSL ApplicationZyWALL USG 1000 User’s Guide568The following table describes the labels in this screen. 42.3 Creating/Editing an SSL Appli
Chapter 42 SSL ApplicationZyWALL USG 1000 User’s Guide569The following table describes the labels in this screen. 42.3.2 Example: Specifying a Web
ZyWALL USG 1000 User’s Guide57CHAPTER 2 Features and ApplicationsThis chapter introduces the main features and applications of the ZyWALL.2.1 Featur
Chapter 42 SSL ApplicationZyWALL USG 1000 User’s Guide5707 Click Apply to save the settings. The configuration screen should look similar to the follo
Chapter 42 SSL ApplicationZyWALL USG 1000 User’s Guide571" You must then configure the shared folder on the file server for remote access. Refer
Chapter 42 SSL ApplicationZyWALL USG 1000 User’s Guide572
573PART VISystemSystem (575)Service Control (587)
ZyWALL USG 1000 User’s Guide575CHAPTER 43 SystemThis chapter provides information on the general system screens. See Chapter 44 on page 587 for det
Chapter 43 SystemZyWALL USG 1000 User’s Guide57643.3 Time and Date This section shows you how:1 To manually set the ZyWALL date and time.2 To get the
Chapter 43 SystemZyWALL USG 1000 User’s Guide577Manual Select this radio button to enter the time and date manually. If you configure a new time and
Chapter 43 SystemZyWALL USG 1000 User’s Guide57843.3.1 Pre-defined NTP Time Servers ListWhen you turn on the ZyWALL for the first time, the date and
Chapter 43 SystemZyWALL USG 1000 User’s Guide579Figure 418 Synchronization in ProcessThe Current Time and Current Date fields will display the appr
Chapter 2 Features and ApplicationsZyWALL USG 1000 User’s Guide58Intrusion Detection and Prevention (IDP)IDP (Intrusion Detection and Protection) can
Chapter 43 SystemZyWALL USG 1000 User’s Guide580Figure 419 System > Console Port SpeedThe following table describes the labels in this screen. 43
Chapter 43 SystemZyWALL USG 1000 User’s Guide581Figure 420 System > DNSThe following table describes the labels in this screen. Table 200 Sys
Chapter 43 SystemZyWALL USG 1000 User’s Guide582From This displays whether the DNS server IP address is assigned by the ISP dynamically through a spec
Chapter 43 SystemZyWALL USG 1000 User’s Guide58343.5.4 Address Record An address record contains the mapping of a fully qualified domain name (FQDN)
Chapter 43 SystemZyWALL USG 1000 User’s Guide58443.5.7 Domain Zone Forwarder A domain zone forwarder contains a DNS server’s IP address. The ZyWALL c
Chapter 43 SystemZyWALL USG 1000 User’s Guide58543.5.9 MX Record A MX (Mail eXchange) record indicates which host is responsible for the mail for a
Chapter 43 SystemZyWALL USG 1000 User’s Guide586The following table describes the labels in this screen. 43.6 Language Screen Click System > Lang
ZyWALL USG 1000 User’s Guide587CHAPTER 44 Service ControlThis chapter covers controlling access to the ZyWALL. See Chapter 43 on page 575 for the ge
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide58844.1.1 Service Access LimitationsA service cannot be used to access the ZyWALL when:1 You ha
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide589Figure 427 HTTP/HTTPS Implementation" If you disable HTTP in the WWW screen, then the
Chapter 2 Features and ApplicationsZyWALL USG 1000 User’s Guide592.2.1 Interface to Interface (Through ZyWALL)Ethernet -> VLAN -> Encap ->
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide590Figure 428 System > WWWThe following table describes the labels in this screen. Table 2
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide591Admin/User Service ControlAdmin Service Control specifies from which zones an administrator
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide59244.4 Service Control Rules Click Add or Edit in the Service Control table in a WWW, SSH, Tel
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide59344.5.1 Internet Explorer Warning MessagesWhen you attempt to access the ZyWALL HTTPS server
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide594Figure 431 Security Certificate 1 (Netscape)Figure 432 Security Certificate 2 (Netscape)4
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide59544.5.4 Login ScreenAfter you accept the certificate, the ZyWALL login screen appears. The l
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide596Figure 435 CA Certificate Example2 Click Install Certificate and follow the wizard as shown
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide5972 The file name and path of the certificate you double-clicked should automatically appear i
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide598Figure 439 Personal Certificate Import Wizard 45 Click Finish to complete the wizard and be
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide59944.5.6 Using a Certificate When Accessing the ZyWALL ExampleUse the following procedure to
Document ConventionsZyWALL USG 1000 User’s Guide6Icons Used in FiguresFigures in this User’s Guide may use the following generic icons. The ZyWALL ico
Chapter 2 Features and ApplicationsZyWALL USG 1000 User’s Guide60Ethernet -> VLAN -> Encap -> ALG -> AC -> DNAT-> Routing -> FW -
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide60044.6 SSH You can use SSH (Secure SHell) to securely access the ZyWALL’s command line inter
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide601The client automatically saves any new server public keys. In subsequent connections, the se
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide602The following table describes the labels in this screen. 44.7 Secure Telnet Using SSH Examp
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide603Figure 448 SSH Example 1: Store Host KeyEnter the password to log in to the ZyWALL. The CL
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide6043 The CLI screen displays next. 44.8 Telnet You can use Telnet to access the ZyWALL’s comman
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide60544.9 Configuring FTP You can upload and download the ZyWALL’s firmware and configuration fi
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide60644.10 SNMP Simple Network Management Protocol is a protocol used for exchanging management i
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide607An agent is a management software module that resides in a managed device (the ZyWALL). An a
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide60844.10.3 Configuring SNMP To change your ZyWALL’s SNMP settings, click System > SNMP tab.
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide60944.11 Dial-in ManagementConnect an external serial modem to the AUXport to provide a manage
Chapter 2 Features and ApplicationsZyWALL USG 1000 User’s Guide61With reverse proxy mode, remote users can easily access any web-based applications o
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide610Figure 455 System > Dial-in Mgmt The following table describes the labels in this scree
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide61144.14 Configuring Vantage CNM Vantage CNM is disabled on the device by default. Click Syste
Chapter 44 Service ControlZyWALL USG 1000 User’s Guide612HTTPS Authentication When you are using HTTPs, select this option to have the ZyWALL authenti
613PART VIIMaintenance & TroubleshootingFile Manager (615)Logs (625)Reports (637)Diagnostics (647)Reboot (649)Troubleshooting (651)
ZyWALL USG 1000 User’s Guide615CHAPTER 45 File ManagerThis chapter covers how to use the ZyWALL’s File Manager screens to handle the ZyWALL’s configu
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide616While configuration files and shell scripts have the same syntax, the ZyWALL applies configurati
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide617Lines 1 and 2 are comments. Line 5 exits sub command mode. 45.1.2 Errors in Configuration File
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide618You can change the way the startup-config.conf file is applied. Include the setenv-startup stop-
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide619The following table describes the labels in this screen. Table 216 Maintenance > File Man
Chapter 2 Features and ApplicationsZyWALL USG 1000 User’s Guide62Figure 6 Applications: User-Aware Access Control2.3.4 Multiple WAN InterfacesSet u
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide62045.3 Firmware Package Screen Click Maintenance > File Manager > Firmware Package to open
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide621The ZyWALL’s firmware package cannot go through the ZyWALL when you enable the anti-virus Destr
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide622Figure 462 Firmware Upload In ProcessThe ZyWALL automatically restarts in this time causing a
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide623Figure 465 Maintenance > File Manager > Shell Script Each field is described in the fol
Chapter 45 File ManagerZyWALL USG 1000 User’s Guide624Rename Use this button to change the label of a shell script file on the ZyWALL. You cannot rena
ZyWALL USG 1000 User’s Guide625CHAPTER 46 LogsThis chapter provides general information about the ZyWALL’s log feature. See Appendix B on page 663 f
Chapter 46 LogsZyWALL USG 1000 User’s Guide626Figure 468 Maintenance > Log > View LogIf an event generates log messages and alerts, it is disp
Chapter 46 LogsZyWALL USG 1000 User’s Guide627The Web configurator saves the filter settings if you leave the View Log screen and return to it later.
Chapter 46 LogsZyWALL USG 1000 User’s Guide628For alerts, the Log Settings tab controls which events generate alerts and where alerts are e-mailed.The
Chapter 46 LogsZyWALL USG 1000 User’s Guide62946.3.1 Log Settings Edit E-mail The Log Settings Edit screen controls the detailed settings for each l
Chapter 2 Features and ApplicationsZyWALL USG 1000 User’s Guide63Figure 8 Applications: Device HA
Chapter 46 LogsZyWALL USG 1000 User’s Guide630Figure 470 Maintenance > Log > Log Setting > E-mail > Edit
Chapter 46 LogsZyWALL USG 1000 User’s Guide631The following table describes the labels in this screen. Table 222 Maintenance > Log > Log Sett
Chapter 46 LogsZyWALL USG 1000 User’s Guide63246.3.2 Log Settings Edit syslog The Log Settings Edit screen controls the detailed settings for each lo
Chapter 46 LogsZyWALL USG 1000 User’s Guide633Figure 471 Maintenance > Log > Log Setting > Remote Server > Edit
Chapter 46 LogsZyWALL USG 1000 User’s Guide634The following table describes the labels in this screen. 46.3.3 Active Log Summary The Active Log Summ
Chapter 46 LogsZyWALL USG 1000 User’s Guide635Figure 472 Active Log SummaryThis screen provides a different view and a different way of indicating
Chapter 46 LogsZyWALL USG 1000 User’s Guide636Selection Select what information you want to log from each Log Category (except All Logs; see below). C
ZyWALL USG 1000 User’s Guide637CHAPTER 47 ReportsThis chapter provides information about the report screens.47.1 Traffic ScreenClick Maintenance &g
Chapter 47 ReportsZyWALL USG 1000 User’s Guide638Figure 473 Maintenance > Report > TrafficThere is a limit on the number of records shown in t
Chapter 47 ReportsZyWALL USG 1000 User’s Guide639Traffic Type Select the type of report to display. Choices are:Host IP Address/User - displays the I
Chapter 2 Features and ApplicationsZyWALL USG 1000 User’s Guide64
Chapter 47 ReportsZyWALL USG 1000 User’s Guide640The following table displays the maximum number of records shown in the report, the byte count limit,
Chapter 47 ReportsZyWALL USG 1000 User’s Guide641Figure 474 Maintenance > Report > SessionThe following table describes the labels in this sc
Chapter 47 ReportsZyWALL USG 1000 User’s Guide64247.3 Anti-Virus Report ScreenClick Maintenance > Report > Anti-Virus to display the following
Chapter 47 ReportsZyWALL USG 1000 User’s Guide643The statistics display as follows when you display the top entries by source.Figure 476 Maintenanc
Chapter 47 ReportsZyWALL USG 1000 User’s Guide644Figure 478 Maintenance > Report > IDP: Signature Name The following table describes the label
Chapter 47 ReportsZyWALL USG 1000 User’s Guide645The statistics display as follows when you display the top entries by source.Figure 479 Maintenanc
Chapter 47 ReportsZyWALL USG 1000 User’s Guide646
ZyWALL USG 1000 User’s Guide647CHAPTER 48 DiagnosticsThis chapter covers how to use the Diagnostics screen. 48.1 DiagnosticsThe Diagnostics screen
Chapter 48 DiagnosticsZyWALL USG 1000 User’s Guide648
ZyWALL USG 1000 User’s Guide649CHAPTER 49 RebootUse this to restart the device (for example, if the device begins behaving erratically). See also Sec
ZyWALL USG 1000 User’s Guide65CHAPTER 3 Web ConfiguratorThe ZyWALL web configurator allows easy ZyWALL setup and management using an Internet browser
Chapter 49 RebootZyWALL USG 1000 User’s Guide650
ZyWALL USG 1000 User’s Guide651CHAPTER 50 TroubleshootingThis chapter offers some suggestions to solve problems you might encounter. V I cannot set u
Chapter 50 TroubleshootingZyWALL USG 1000 User’s Guide652Routing policies define how the ZyWALL forwards packets to their destinations. You must creat
Chapter 50 TroubleshootingZyWALL USG 1000 User’s Guide653If you want to reboot the device without changing the current configuration, see Chapter 49
Chapter 50 TroubleshootingZyWALL USG 1000 User’s Guide654
655PART VIIIAppendices and IndexProduct Specifications (657)Common Services (703)Displaying Anti-Virus Alert Messages in Windows (707)Open Software
656
ZyWALL USG 1000 User’s Guide657APPENDIX A Product SpecificationsThe following specifications are subject to change without notice. See Chapter 2 on p
Appendix A Product SpecificationsZyWALL USG 1000 User’s Guide658Table 233 Feature Specifications VERSION #FEATUREV2.00# of MAC
Appendix A Product SpecificationsZyWALL USG 1000 User’s Guide659Service Groups 1000Schedule Objects 512ISP Accounts 128Maximum Number of LDAP Groups
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide66Figure 9 Login Screen 3 Type the user name (default: “admin”) and password (default: “1234
Appendix A Product SpecificationsZyWALL USG 1000 User’s Guide660The following table, which is not exhaustive, lists standards referenced by ZyWALL fea
Appendix A Product SpecificationsZyWALL USG 1000 User’s Guide661Built-in service, SNMP agent RFCs 1067, 1213, 2576, 2578, 2579, 2580, 2741, 2667, 298
Appendix A Product SpecificationsZyWALL USG 1000 User’s Guide662
ZyWALL USG 1000 User’s Guide663APPENDIX B Log DescriptionsThis appendix provides descriptions of example log messages. Table 235 Content Filter
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide664%s: Service is unavailableContent filter rating service is temporarily unavailable and acces
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide665 Table 238 User LogsLOG MESSAGE DESCRIPTION%s %s has logged in from %sThe specified user
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide666 Table 239 myZyXEL.com LogsLOG MESSAGE DESCRIPTIONSend registration message to MyZyXEL.com
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide667Service expiration check has succeeded.The service expiration day check was successful.Serv
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide668Update server is busy now. File download after %d seconds.The update server was busy so the
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide669Do expiration daily-check has failed. Because of lack must fields.The device received an in
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide675 The screen above appears every time you log in using the default user name and default pass
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide670 Certification verification failed: Depth: %d, Error Number(%d):%s.Verification of a server’
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide671IDP service standard license is expired. Update signature failed.IDP service standard lice
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide672IDP off-line update failed. File damaged.IDP signature off-line update failed. Signature fil
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide673 IDP signature update failed. Invalid signature content.IDP signature update failed. Sigque
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide674System fatal error: 60018009.Error when do ioctl L7_ACTION_IOCTL_ADDR_USAGE.System fatal err
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide675 App Patrol Name=%s Type=%s %s=%d Protocol=%s Action=%sPackets logging. 1st %s: Protocol Na
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide676[SA] : Tunnel [%s] Phase 1 authentication algorithm mismatch%s is the tunnel name. When nego
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide677Cannot resolve My IP Addr %s for Tunnel [%s]1st %s is my ip address. 2nd %s is the tunnel n
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide678The cookie pair is : 0x%08x%08x / 0x%08x%08xIndicates the initiator/responder cookie pair.Th
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide679 Tunnel [%s:%s] Sending IKE requestThe variables represent the phase 1 name and tunnel nam
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide68The icons provide the following functions.3.3.2 Navigation PanelUse the menu items on the nav
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide680 Table 244 Firewall LogsLOG MESSAGE DESCRIPTIONpriority:%lu, from %s to %s, service %s,
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide681Cannot get handle from UAM, user-aware PR is disabledUser-aware policy routing is disabled
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide682 Table 247 Built-in Services LogsLOG MESSAGE DESCRIPTIONUser on %u.%u.%u.%u has been denie
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide683Console baud has been changed to %s.An administrator changed the console port baud rate.%s
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide684The default record of Zone Forwarder have reached the maximum number of 128 DNS servers.The
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide685 Access control rule %d of %s was moved to %d.An access control rule was moved successfully
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide686Receive an ARP response from an unknown clientThe device received an ARP response from an un
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide687Update the profile %s has failed because the FQDN %s is not under your control.The owner of
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide688Update the profile %s has failed because Custom IP was empty.The DDNS profile's IP sele
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide689 DDNS has been enabled by Device-HA.DDNS is enabled by Device-HA, because one of VRRP group
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide69Routing Policy Route Use this screen to create and manage routing policies.Static Route Use t
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide690 Can't get remote address of %s interfaceThe connectivity check process can't get
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide691Master configuration is the same with Backup. Skip updating it.The System Startup configura
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide692Device HA authentication type for VRRP group %s maybe wrong.A VRRP group’s Authentication Ty
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide693 Table 251 Routing Protocol LogsLOG MESSAGE DESCRIPTIONRIP on interface %s has been stopp
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide694RIP md5 authentication id and key have been deleted.RIP md5 authentication id and key have b
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide695 Invalid OSPF virtual-link %s authentication of area %s.Virtual-link %s authentication has
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide696 Register H.323 ALG extra port=%d failed.H323 ALG apply additional signal port failed.%d: Po
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide697Import X509 certificate "%s" into My Certificate successfullyThe device imported
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide698 Export X509 certificate "%s" from "My Certificate" failedThe device was
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide699 27 Path was not verified.28 Maximum path length reached.Table 254 Interface LogsLOG MESS
Safety WarningsZyWALL USG 1000 User’s Guide7Safety Warnings1 For your safety, be sure to read and follow all warning notices and instructions.• Do NO
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide70IDP General Use this screen to look at and manage IDP bindings.Profile Use this screen to crea
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide700%s MTU > (%s MTU - 8), %s may not work correctly.An administrator configured a PPP interf
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide701 Interface %s is disconnected.A PPP or AUX interface disconnected successfully. %s: interf
Appendix B Log DescriptionsZyWALL USG 1000 User’s Guide702 Table 257 Force Authentication LogsLOG MESSAGE DESCRIPTIONForce User Authentication will
ZyWALL USG 1000 User’s Guide703APPENDIX C Common ServicesThe following table lists some commonly-used services and their associated protocols and por
Appendix C Common ServicesZyWALL USG 1000 User’s Guide704FTP TCPTCP2021File Transfer Program, a program to enable fast transfer of files, including la
Appendix C Common ServicesZyWALL USG 1000 User’s Guide705RTSP TCP/UDP 554 The Real Time Streaming (media control) Protocol (RTSP) is a remote control
Appendix C Common ServicesZyWALL USG 1000 User’s Guide706
ZyWALL USG 1000 User’s Guide707APPENDIX D Displaying Anti-Virus AlertMessages in WindowsWith the anti-virus packet scan, when a virus is detected, yo
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 1000 User’s Guide708Figure 484 Windows XP: Starting the Messenger Service 3 Clo
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 1000 User’s Guide709Figure 486 Windows 2000: Starting the Messenger Service 3
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide713.3.3 Main WindowThe main window shows the screen you select in the menu. It is discussed in
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 1000 User’s Guide710Figure 489 Windows 98 SE: Task Bar Properties 3 Double-
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 1000 User’s Guide711Figure 491 Windows 98 SE: Startup: Create Shortcut 6 Spe
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 1000 User’s Guide712Figure 493 Windows 98 SE: Startup: Shortcut " The
ZyWALL USG 1000 User’s Guide713APPENDIX E Importing CertificatesThis appendix shows importing certificates examples using Netscape Navigator and Inte
Appendix E Importing CertificatesZyWALL USG 1000 User’s Guide714Figure 495 Login Screen2 Click Install Certificate to open the Install Certificate w
Appendix E Importing CertificatesZyWALL USG 1000 User’s Guide715Figure 497 Certificate Import Wizard 14 Select where you would like to store the ce
Appendix E Importing CertificatesZyWALL USG 1000 User’s Guide716Figure 499 Certificate Import Wizard 36 Click Yes to add the ZyWALL certificate to
Appendix E Importing CertificatesZyWALL USG 1000 User’s Guide717Figure 501 Certificate General Information after Import
Appendix E Importing CertificatesZyWALL USG 1000 User’s Guide718
ZyWALL USG 1000 User’s Guide719APPENDIX F Open Software AnnouncementsNotice Information herein is subject to change without notice. Companies, names,
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide723.3.4 Message BarCheck the message bar when you click Apply or OK to verify that the configur
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide720" This Product includes Netkit Telnet -0.17 software under the Netkit Telnet
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide721" This Product includes expat-1.95.6 software under the Expat LicenseExpat
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide722" This Product includes openssl-0.9.8d-ocf software under the OpenSSL Licens
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide723OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED O
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide724" This Product includes libevent-1.1a and xinetd-2.3.14 software under the a
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide725The ISC license for bind is:Copyright (c) 1993-1999 by Internet Software Consort
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide726Apache LicenseVersion 2.0, January 2004http://www.apache.org/licenses/TERMS AND C
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide7272. Grant of Copyright License. Subject to the terms and conditions of this Licen
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide7286. Trademarks. This License does not grant permission to use the trade names, tra
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide729Products derived from this software may not be called "Apache", nor ma
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide73Figure 14 CLI MessagesClick Change Display Style to show or hide the index numbers for the
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide730This license, the Lesser General Public License, applies to some specially design
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide731For example, on rare occasions, there may be a special need to encourage the wid
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide7322. You may modify your copy or copies of the Library or any portion of it, thus f
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide733However, linking a "work that uses the Library" with the Library creat
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide734It may happen that this requirement contradicts the license restrictions of other
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide73512. If the distribution and/or use of the Library is restricted in certain count
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide736" This Product includes bridge-utils, dhcpcd-1.3.22-pl4, rp-pppoe-3.5, vlan-
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide737TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION0. This License a
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide738right to control the distribution of derivative or collective works based on the
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide7397. If, as a consequence of a court judgment or allegation of patent infringement
Chapter 3 Web ConfiguratorZyWALL USG 1000 User’s Guide74
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide740FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMAN
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide741AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide742THIS SOFTWARE IS PROVIDED BY THE OPENLDAP FOUNDATION AND ITS CONTRIBUTORS ``AS IS
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide7432.1 GUBUSOFT hereby grants Customer the following non-exclusive, non-transferabl
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide744Defensive Suspension. If Customer commences or participates in any legal proceedi
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide745" This Product includes overLIB software under the overLIB License (Artisti
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide746make other distribution arrangements with the Copyright Holder. You may distribut
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide747BY EXERCISING ANY RIGHTS TO THE WORK PROVIDED HERE, YOU ACCEPT AND AGREE TO BE B
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide748ii.Mechanical Rights and Statutory Royalties. Licensor waives the exclusive right
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide7495. Representations, Warranties and DisclaimerUNLESS OTHERWISE MUTUALLY AGREED TO
ZyWALL USG 1000 User’s Guide75CHAPTER 4 Wizard SetupThis chapter provides information on configuring the Wizard setup screens in the web configurator
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide750e.This License constitutes the entire agreement between the parties with respect
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide751You have no ownership rights in the Software. Rather, you have a license to use
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide752THE WAIVER OR EXCLUSION OF IMPLIED WARRANTIES SO THEY MAY NOT APPLY TO YOU. IF T
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide753This License Agreement is effective until it is terminated. You may terminate t
Appendix F Open Software AnnouncementsZyWALL USG 1000 User’s Guide754
ZyWALL USG 1000 User’s Guide755APPENDIX G Legal InformationCopyrightCopyright © 2007 by ZyXEL Communications Corporation.The contents of this publica
Appendix G Legal InformationZyWALL USG 1000 User’s Guide756FCC WarningThis device has been tested and found to comply with the limits for a Class A di
Appendix G Legal InformationZyWALL USG 1000 User’s Guide757NoteRepair or replacement, as provided under this warranty, is the exclusive remedy of the
Appendix G Legal InformationZyWALL USG 1000 User’s Guide758
ZyWALL USG 1000 User’s Guide759APPENDIX H Customer SupportPlease have the following information ready when you contact customer support.Required Info
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide76Use VPN SETUP to configure a VPN connection. See Section 4.6 on page 95.Figure 15 Wizard Setup W
Appendix H Customer SupportZyWALL USG 1000 User’s Guide760• Regular Mail: ZyXEL Communications, Czech s.r.o., Modranská 621, 143 01 Praha 4 - Modrany,
Appendix H Customer SupportZyWALL USG 1000 User’s Guide761India• Support E-mail: [email protected]• Sales E-mail: [email protected]• Telephone: +91-11-30
Appendix H Customer SupportZyWALL USG 1000 User’s Guide762• Regular Mail: ZyXEL Communications Inc., 1130 N. Miller St., Anaheim, CA 92806-2001, U.S.A
Appendix H Customer SupportZyWALL USG 1000 User’s Guide763Sweden• Support E-mail: [email protected]• Sales E-mail: [email protected]• Telephone: +46-31-7
Appendix H Customer SupportZyWALL USG 1000 User’s Guide764
IndexZyWALL USG 1000 User’s Guide765IndexNumerics3DES 308AAAA servers 531and authentication methods 541and users 504LDAP Default 533LDAP Group 534LDAP
IndexZyWALL USG 1000 User’s Guide766and virtual servers 268FTP 265H.323 265, 266peer-to-peer calls 268RTP 266See also VoIP pass through. 265SIP 265, 2
IndexZyWALL USG 1000 User’s Guide767and policy routes 232behavior 382configured rate effect 383examples 384in application patrol 380interface, outboun
IndexZyWALL USG 1000 User’s Guide768SSL 326console port 55speed 579content (pattern) 439content filtering 463, 464and address groups 463, 464, 467and
IndexZyWALL USG 1000 User’s Guide769and interfaces 183Domain Name System. See DNS.double-encoding 457DTR 609Dynamic Domain Name System. See DDNS.Dynam
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide77Figure 16 Internet Access: Step 1 The following table describes the labels in this screen.
IndexZyWALL USG 1000 User’s Guide770and address objects 513and schedules 513prerequisites 123fragmentation flag 437fragmentation offset 437FTP 605addi
IndexZyWALL USG 1000 User’s Guide771IDP 418Snort signatures 443statistics 643traffic directions 418updating signatures 173verifying custom signatures
IndexZyWALL USG 1000 User’s Guide772IP static routes. See static routes.IP stream identifier 434IP v4 packet headers 433IPSec 291basic troubleshooting
IndexZyWALL USG 1000 User’s Guide773types of 625log options 409log options (IDP) 426logged in users 163logindefault settings 657SSL user 332logo 328lo
IndexZyWALL USG 1000 User’s Guide774and RIP 239and static routes 239and to-ZyWALL firewall 238area 0 239areas. See OSPF areas.authentication method 18
IndexZyWALL USG 1000 User’s Guide775as VPN 211product registration 757profilesADP 448packet inspection 424protocolusage statistics 400protocol anomaly
IndexZyWALL USG 1000 User’s Guide776and authentication algorithms 236and Ethernet interfaces 185RTP 266See also ALG. 266Ssafety warnings 7same IP 438s
IndexZyWALL USG 1000 User’s Guide777SSH 600and address groups 602and address objects 602and certificates 602and zones 602client requirements 601encryp
IndexZyWALL USG 1000 User’s Guide778TT/TCP 458task bar properties 710TCP 521ACK (acknowledgment) 453ACK number 438connections 521port numbers 521SYN (
IndexZyWALL USG 1000 User’s Guide779and content filtering 463and firewall 287and policy routes 230, 392, 394, 396, 398configuration overview 122user n
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide78IP Address Assignment: Select Auto If your ISP did not assign you a fixed IP address. Select Stati
IndexZyWALL USG 1000 User’s Guide780advantages 318and IPSec SA policy enforcement 320disadvantages 318VPN connectionsand address objects 296and policy
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide79Figure 18 Ethernet Encapsulation: StaticThe following table describes the labels in this screen
Safety WarningsZyWALL USG 1000 User’s Guide8
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide804.3.3 Step 2 Internet Access Ethernet You do not configure this screen if you selected Auto as th
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide81You can click Next and use the following screen to perform a basic registration (see Section 4.4
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide82The ZyWALL applies the configuration settings. Figure 21 PPPoE Encapsulation: Auto: FinishYou ha
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide83Figure 22 PPPoE Encapsulation: StaticThe following table describes the labels in this screen.Ta
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide844.3.6 Step 2 Internet Access PPPoE " Enter the Internet access information exactly as given
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide85Figure 23 PPPoE Encapsulation: Static: FinishYou have set up your ZyWALL to access the Internet
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide86Figure 24 PPTP Encapsulation: AutoThe following table describes the labels in this screen.Table
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide87The ZyWALL applies the configuration settings. Figure 25 PPTP Encapsulation: Auto: FinishYou ha
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide88" If you have not already done so, you can register your ZyWALL with myZyXEL.com and activate
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide894.3.9 Step 2 Internet Access PPTP " Enter the Internet access information exactly as given
Contents OverviewZyWALL USG 1000 User’s Guide9Contents OverviewIntroduction ...
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide90Type the Password associated with the user name. Select Nailed-Up if you do not want the connectio
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide914.3.10 Step 4 Internet Access - Finish You have set up your ZyWALL to access the Internet. "
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide92Figure 28 RegistrationThe following table describes the labels in this screen. Table 13 Regist
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide93Figure 29 Registration: Registered Device4.5 Installation Setup, Two Internet Service Provider
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide94Figure 30 Internet Access: Step 1: First WAN InterfaceAfter you configure the First WAN Interfac
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide95Figure 32 Internet Access: Finish " You can register your ZyWALL with myZyXEL.com and acti
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide96Click VPN SETUP in the Wizard Setup Welcome screen (Figure 15 on page 76) to open the following sc
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide974.7.1 VPN Express WizardClick the Express radio button as shown in Figure 33 on page 96 to displ
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide98Name: Type the name used to identify this VPN connection (and VPN gateway). You may use 1-31 alpha
Chapter 4 Wizard SetupZyWALL USG 1000 User’s Guide994.8.1 VPN Express Wizard - Policy Setting The Policy Setting specifies which devices can use the
Comentários a estes Manuais