
www.zyxel.comZyWALL USG 300Unified Security GatewayUser’s GuideVersion 2.009/2007Edition 2DEFAULT LOGINLAN Port 1IP Address http://192.168.1.1User Na
Contents OverviewZyWALL USG 300 User’s Guide10Content Filter Screens ...
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide1004.8.2 VPN Express Wizard - Summary This summary of VPN tunnel settings is read-only.Name: Identif
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide101" If you have not already done so, use the myZyXEL.com link and register your ZyWALL with my
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide102Figure 38 VPN Advanced Wizard: Step 2 The following table describes the labels in this screen.Ta
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide1034.8.5 VPN Advanced Wizard - Remote Gateway The Remote Gateway policy identifies the IPSec device
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide104Figure 39 VPN Advanced Wizard: Step 3The following table describes the labels in this screen.Tab
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide1054.8.6 VPN Advanced Wizard - Phase 1 Phases: IKE (Internet Key Exchange) negotiation has two phas
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide1064.8.6.1 Phase 2 SettingPhase 2 in an IKE uses the SA that was established in phase 1 to negotiate
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide1074.8.7 VPN Advanced Wizard - Phase 2 Active Protocol: ESP is compatible with NAT, AH is not.Encap
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide108Figure 41 VPN Advanced Wizard: Step 5The following table describes the labels in this screen.4.8
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide109Secure Gateway: IP address or domain name of the peer IPSec device.Pre-Shared Key: VPN tunnel pas
Table of ContentsZyWALL USG 300 User’s Guide11Table of ContentsAbout This User's Guide...
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide110" If you have not already done so, you can register your ZyWALL with myZyXEL.com and activate
ZyWALL USG 300 User’s Guide111CHAPTER 5 Configuration BasicsThis section provides information to help you configure the ZyWALL effectively. Some of
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide1125.2 Terminology in the ZyWALLThis section highlights some differences in terminology or o
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide113A physical port is the place to which you connect the cable. As shown above, you do not u
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide114Figure 43 Interfaces and Zones: Example• The LAN zone contains the ge1 (Gigabit Ethernet
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide115Example: This provides a simple example to show you how to configure this feature. The ex
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide116Example: See Chapter 6 on page 125.5.4.4 IPSec VPNUse IPSec VPN to provide secure communi
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide117Zones cannot overlap. Each interface and VPN tunnel can be assigned to at most one zone.
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide1182 Click Network > Routing > Policy Route to go to the policy route configuration scr
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide1192 Create an address object for the VoIP server (Object > Address). 3 Click Firewall to
Table of ContentsZyWALL USG 300 User’s Guide122.3.5 Device HA ...
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide1205.4.14 Anti-VirusUse anti-virus to detect and take action on viruses. You must subscribe
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide12111 Add a policy that uses the schedule, the filtering profile and the user that you creat
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide1225.4.20 ALGThe ZyWALL’s Application Layer Gateway (ALG) allows VoIP and FTP applications t
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide123If you want to force users to log in to the ZyWALL before the ZyWALL routes traffic for t
Chapter 5 Configuration BasicsZyWALL USG 300 User’s Guide1245.6.2 File ManagerUse these screens to upload, download, delete, or run scripts of CLI co
ZyWALL USG 300 User’s Guide125CHAPTER 6 TutorialsThis chapter provides some examples of using the web configurator to set up features in the ZyWALL.
Chapter 6 TutorialsZyWALL USG 300 User’s Guide126Figure 44 Network > Interface > Port Grouping, Initial 2 Drag physical port 2 onto represe
Chapter 6 TutorialsZyWALL USG 300 User’s Guide127Figure 46 Status: Interface Status Summary After Port Grouping6.1.2 Set up Ethernet InterfacesThi
Chapter 6 TutorialsZyWALL USG 300 User’s Guide128Figure 48 Network > Interface > Ethernet > ge43 Use the default values for the rest of the
Chapter 6 TutorialsZyWALL USG 300 User’s Guide129Figure 51 Status > Interface Status Summary, After Ethernet Interface Edits6.1.3 WAN TrunkThis
Table of ContentsZyWALL USG 300 User’s Guide13Chapter 5 Configuration Basics...
Chapter 6 TutorialsZyWALL USG 300 User’s Guide130Figure 54 Network > Interface > Trunk > Edit > Member 4 Use the default values fo
Chapter 6 TutorialsZyWALL USG 300 User’s Guide131Figure 56 Network > Zone > DMZ, Remove ge4 3 Select IFACE/ge4 and click the left arrow to
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1326.2 IPSec VPNThis example is going to show you how to create the VPN tunnel illustrated below.Figure
Chapter 6 TutorialsZyWALL USG 300 User’s Guide133Figure 60 VPN > IPSec VPN > VPN Gateway > Add6.2.3 Set up the VPN ConnectionThe VPN conn
Chapter 6 TutorialsZyWALL USG 300 User’s Guide134Figure 62 VPN > IPSec VPN > VPN Connection > add6.2.4 Set up the Policy Route for the VPN
Chapter 6 TutorialsZyWALL USG 300 User’s Guide135Figure 64 Network > Routing > Policy Route > AddBecause the new VPN connection has not be
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1366.3 Device HAThis example is going to show you how to set up device HA as illustrated below.Figure 6
Chapter 6 TutorialsZyWALL USG 300 User’s Guide137Figure 67 Device HA > VRRP Group > Add: ge13 Click Status, and scroll down to the Interface
Chapter 6 TutorialsZyWALL USG 300 User’s Guide138Figure 69 Network > Device HA > VRRP Group > Add: ge4" Once you configure an interfac
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1396.3.4 Finish Configuring the MasterFinish configuring the master. The backup router will get these
Table of ContentsZyWALL USG 300 User’s Guide146.1.4 Zones ...
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1406.3.7 Synchronize the Backup1 Connect the backup to the same network as the master.2 Click Device HA
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1416.4.1 Set up User AccountsSet up one user account for each user account in the RADIUS server. If it
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1426.4.3 Set up User Authentication Using the RADIUS ServerThis step sets up user authentication using
Chapter 6 TutorialsZyWALL USG 300 User’s Guide143" The users will have to log in using the web configurator login screen before they can use HTT
Chapter 6 TutorialsZyWALL USG 300 User’s Guide144Figure 81 AppPatrol > http > Edit Default4 Click the Add icon in the policy list. In the new
Chapter 6 TutorialsZyWALL USG 300 User’s Guide145Figure 83 Object > Schedule > Recurring > add3 Follow the steps in Section 6.4.4 on page
Chapter 6 TutorialsZyWALL USG 300 User’s Guide146Figure 85 Firewall > LAN > DMZ > Add5 Repeat this process to set up firewall rules for the
Chapter 6 TutorialsZyWALL USG 300 User’s Guide147Figure 87 Network > Interface > Ethernet > Edit > ge22 Click the Edit icon for ge3, an
Chapter 6 TutorialsZyWALL USG 300 User’s Guide148The firewall is enabled, so you also need to create a rule to allow traffic in from the WAN zone.Figu
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1496.6.2 NAT 1:1 Virtual ServerThis section sets up a virtual server rule that changes the destination
Table of ContentsZyWALL USG 300 User’s Guide15Chapter 8Registration...
Chapter 6 TutorialsZyWALL USG 300 User’s Guide150Figure 94 NAT 1:1 Example Policy RouteClick Network > Routing > Policy Route > Add and con
Chapter 6 TutorialsZyWALL USG 300 User’s Guide151Figure 96 Create a Firewall Rule6.7 NAT LoopbackThe NAT 1:1 example in Section 6.6 on page 147 ma
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1526.7.1 NAT Loopback Virtual ServerWhen a LAN user sends SMTP traffic to IP address 1.1.1.1, the traff
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1536.7.2 NAT Loopback Policy RouteWithout a NAT loopback policy route, the LAN user SMTP traffic goes
Chapter 6 TutorialsZyWALL USG 300 User’s Guide154Figure 102 Create a Policy RouteNow the LAN SMTP server replies to the ZyWALL’s LAN IP address and
Chapter 6 TutorialsZyWALL USG 300 User’s Guide1556.8 Service Control and the FirewallService control lets you configure rules that control HTTP and
Chapter 6 TutorialsZyWALL USG 300 User’s Guide156Figure 105 System > WWW > Service Control Rule Edit 4 Click Apply.Figure 106 System >
ZyWALL USG 300 User’s Guide157CHAPTER 7 StatusThis chapter explains the Status screen, which is the screen you see when you first log in to the ZyWA
Chapter 7 StatusZyWALL USG 300 User’s Guide158The following table describes the labels in this screen. Table 34 StatusLABEL DESCRIPTIONDevice Infor
Chapter 7 StatusZyWALL USG 300 User’s Guide159Signature VersionThis field displays the version number, date, and time of the current set of signature
Table of ContentsZyWALL USG 300 User’s Guide1610.5.4 Bridge Add/Edit ...
Chapter 7 StatusZyWALL USG 300 User’s Guide1607.2 VPN StatusUse this screen to look at the VPN tunnels that are currently established. To access this
Chapter 7 StatusZyWALL USG 300 User’s Guide161Figure 108 Status > VPN StatusThe following table describes the labels in this screen. 7.3 DHCP
Chapter 7 StatusZyWALL USG 300 User’s Guide162Figure 109 Status > DHCP TableThe following table describes the labels in this screen. 7.4 Port St
Chapter 7 StatusZyWALL USG 300 User’s Guide163Figure 110 Status > Port Statistics The following table describes the labels in this screen. 7.5
Chapter 7 StatusZyWALL USG 300 User’s Guide164Figure 111 Status > Current UsersThe following table describes the labels in this screen. Table 38
ZyWALL USG 300 User’s Guide165CHAPTER 8 RegistrationThis chapter shows you how to register for the ZyWALL’s subscription services.8.1 myZyXEL.com Ov
Chapter 8 RegistrationZyWALL USG 300 User’s Guide166• SSL VPN tunnels provide secure network access to remote users. You can purchase and enter a lice
Chapter 8 RegistrationZyWALL USG 300 User’s Guide167The following table describes the labels in this screen. " If the ZyWALL is registered alre
Chapter 8 RegistrationZyWALL USG 300 User’s Guide168Figure 113 Licensing > Registration: Registered Device8.3 Service After you activate a trial
Chapter 8 RegistrationZyWALL USG 300 User’s Guide169Expiration date This field displays the date your service expires.You can continue to use IDP/App
Table of ContentsZyWALL USG 300 User’s Guide1713.1.2 Authentication Types ...
Chapter 8 RegistrationZyWALL USG 300 User’s Guide170
ZyWALL USG 300 User’s Guide171CHAPTER 9 UpdateThis chapter shows you how to update the ZyWALL’s signature packages.9.1 Updating Anti-virus Signature
Chapter 9 UpdateZyWALL USG 300 User’s Guide172Figure 115 Licensing > Update >Anti-Virus The following table describes the labels in this scree
Chapter 9 UpdateZyWALL USG 300 User’s Guide1739.2 Updating IDP and Application Patrol Signatures The ZyWALL comes with signatures for the IDP and ap
Chapter 9 UpdateZyWALL USG 300 User’s Guide174Figure 117 Downloading IDP SignaturesFigure 118 Successful IDP Signature DownloadAuto Update Select
Chapter 9 UpdateZyWALL USG 300 User’s Guide1759.3 Updating System Protect Signatures The ZyWALL comes with signatures that the ZyWALL uses to protec
Chapter 9 UpdateZyWALL USG 300 User’s Guide176Figure 120 Downloading System Protect SignaturesFigure 121 Successful System Protect Signature Downl
177PART IINetworkInterface (179)Trunks (219)Policy and Static Routes (225)Routing Protocols (235)Zones (245)DDNS (249)Virtual Servers (255)HTTP
178
ZyWALL USG 300 User’s Guide179CHAPTER 10 InterfaceSee Section 5.4.2 on page 115 for related information on these screens.10.1 Interface OverviewIn g
Table of ContentsZyWALL USG 300 User’s Guide18Chapter 18ALG ...
Chapter 10 InterfaceZyWALL USG 300 User’s Guide180• Trunks manage load balancing between interfaces.Port groups, trunks, and the auxiliary interface h
Chapter 10 InterfaceZyWALL USG 300 User’s Guide181Figure 122 Example: Entry in the Routing Table Derived from InterfacesFor example, if the ZyWALL
Chapter 10 InterfaceZyWALL USG 300 User’s Guide18210.1.3 Interface Parameters The ZyWALL restricts the amount of traffic into and out of the ZyWALL t
Chapter 10 InterfaceZyWALL USG 300 User’s Guide183The ZyWALL cannot assign the first address (network address) or the last address (broadcast address
Chapter 10 InterfaceZyWALL USG 300 User’s Guide18410.1.6 Relationships Between InterfacesIn the ZyWALL, interfaces are usually created on top of othe
Chapter 10 InterfaceZyWALL USG 300 User’s Guide185In addition, you use Ethernet interfaces to control which physical ports exchange routing informati
Chapter 10 InterfaceZyWALL USG 300 User’s Guide186Figure 123 Network > Interface > Interface Summary Each field is described in the foll
Chapter 10 InterfaceZyWALL USG 300 User’s Guide187Status This field displays the current status of each interface. The possible values depend on what
Chapter 10 InterfaceZyWALL USG 300 User’s Guide18810.2.3 Ethernet Summary ScreenThis screen lists every Ethernet interface and virtual interface crea
Chapter 10 InterfaceZyWALL USG 300 User’s Guide189Each field is described in the following table. 10.2.4 Ethernet Edit The Ethernet Edit screen let
Table of ContentsZyWALL USG 300 User’s Guide1920.4 VPN Gateway Screens ...
Chapter 10 InterfaceZyWALL USG 300 User’s Guide190Figure 125 Network > Interface > Ethernet > Edit
Chapter 10 InterfaceZyWALL USG 300 User’s Guide191Each field is described in the table below. Table 50 Network > Interface > Ethernet >
Chapter 10 InterfaceZyWALL USG 300 User’s Guide192Direction This field is effective when RIP is enabled. Select the RIP direction from the drop-down l
Chapter 10 InterfaceZyWALL USG 300 User’s Guide193Relay Server 2 This field is optional. Enter the IP address of another DHCP server for the network.
Chapter 10 InterfaceZyWALL USG 300 User’s Guide19410.3 Port Grouping This section introduces port groups and then explains the screen for port groups
Chapter 10 InterfaceZyWALL USG 300 User’s Guide195Each physical port is assigned to one Ethernet interface. In port grouping, the Ethernet interfaces
Chapter 10 InterfaceZyWALL USG 300 User’s Guide196Figure 129 Network > Interface > Port Grouping Each section in this screen is described
Chapter 10 InterfaceZyWALL USG 300 User’s Guide197Figure 130 Example: Before VLANIn this example, there are two physical networks and three departm
Chapter 10 InterfaceZyWALL USG 300 User’s Guide198• Better manageability - You can align network policies more appropriately for users. For example, y
Chapter 10 InterfaceZyWALL USG 300 User’s Guide19910.4.4 VLAN Add/Edit This screen lets you configure IP address assignment, interface bandwidth par
Table of ContentsZyWALL USG 300 User’s Guide2024.2 Main File Sharing Screen ...
Chapter 10 InterfaceZyWALL USG 300 User’s Guide200Figure 133 Network > Interface > VLAN > Edit
Chapter 10 InterfaceZyWALL USG 300 User’s Guide201Each field is explained in the following table. Table 53 Network > Interface > VLAN > Ed
Chapter 10 InterfaceZyWALL USG 300 User’s Guide202DHCP Select what type of DHCP service the ZyWALL provides to the network. Choices are:None - the ZyW
Chapter 10 InterfaceZyWALL USG 300 User’s Guide20310.5 Bridge Interfaces This section introduces bridges and bridge interfaces and then explains the
Chapter 10 InterfaceZyWALL USG 300 User’s Guide20410.5.1 Bridge OverviewA bridge creates a connection between two or more network segments at the lay
Chapter 10 InterfaceZyWALL USG 300 User’s Guide20510.5.2 Bridge Interface OverviewA bridge interface creates a software bridge between the members o
Chapter 10 InterfaceZyWALL USG 300 User’s Guide20610.5.4 Bridge Add/Edit This screen lets you configure IP address assignment, interface bandwidth pa
Chapter 10 InterfaceZyWALL USG 300 User’s Guide207Figure 136 Network > Interface > Bridge > Edit In this example, you are creating
Chapter 10 InterfaceZyWALL USG 300 User’s Guide208Available This field displays Ethernet interfaces and VLAN interfaces that can become part of the br
Chapter 10 InterfaceZyWALL USG 300 User’s Guide209These fields appear if the ZyWALL is a DHCP Relay.Relay Server 1 Enter the IP address of a DHCP ser
Table of ContentsZyWALL USG 300 User’s Guide2127.4.5 Bandwidth Management Behavior ...
Chapter 10 InterfaceZyWALL USG 300 User’s Guide21010.6 PPPoE/PPTP Interfaces This section introduces PPPoE, PPTP, and PPPoE/PPTP interfaces and then
Chapter 10 InterfaceZyWALL USG 300 User’s Guide211PPPoE is often used with cable modems and DSL connections. It provides the following advantages:• T
Chapter 10 InterfaceZyWALL USG 300 User’s Guide21210.6.3 PPPoE/PPTP Interface Summary" You have to set up an ISP account before you create a PPP
Chapter 10 InterfaceZyWALL USG 300 User’s Guide21310.6.4 PPPoE/PPTP Interface Add/Edit " You have to set up an ISP account before you create a
Chapter 10 InterfaceZyWALL USG 300 User’s Guide214Each field is explained in the following table.Table 60 Network > Interface > PPPoE/PPTP >
Chapter 10 InterfaceZyWALL USG 300 User’s Guide21510.7 Auxiliary Interface This section introduces the auxiliary interface and then explains the scr
Chapter 10 InterfaceZyWALL USG 300 User’s Guide216Figure 141 Network > Interface > AuxiliaryEach field is described in the table below. Table
Chapter 10 InterfaceZyWALL USG 300 User’s Guide21710.8 Virtual Interfaces Use virtual interfaces to tell the ZyWALL where to route packets. Virtual
Chapter 10 InterfaceZyWALL USG 300 User’s Guide218Figure 142 Network > Interface > AddEach field is described in the table below. Table 62 N
ZyWALL USG 300 User’s Guide219CHAPTER 11 TrunksThis chapter shows you how to configure trunks on your ZyWALL. See Section 5.4.3 on page 115 for relat
Table of ContentsZyWALL USG 300 User’s Guide2229.1.4 Signatures ...
Chapter 11 TrunksZyWALL USG 300 User’s Guide220Maybe you have two connections with different bandwidths. For jitter-sensitive traffic (like video for
Chapter 11 TrunksZyWALL USG 300 User’s Guide22111.4.2 Weighted Round Robin Round Robin scheduling services queues on a rotating basis and is activat
Chapter 11 TrunksZyWALL USG 300 User’s Guide222Figure 145 Spillover Algorithm Example11.5 Trunk SummaryClick Network > Interface > Trunk to o
Chapter 11 TrunksZyWALL USG 300 User’s Guide223Figure 147 Network > Interface > Trunk > EditEach field is described in the table below. Ta
Chapter 11 TrunksZyWALL USG 300 User’s Guide224Spillover This field displays with the spillover load balancing algorithm. Specify the maximum bandwidt
ZyWALL USG 300 User’s Guide225CHAPTER 12 Policy and Static RoutesThis chapter shows you how to configure policies for IP routing and static routes on
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide226IPPR follows the existing packet filtering facility of RAS in style and in implementa
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide227Figure 148 Trigger Port Forwarding Example12.2.3 Maximize Bandwidth UsageThe maxi
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide228Figure 149 Network > Routing > Policy RouteThe following table describes the
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide22912.4 Policy Route Edit Click Network > Routing to open the Policy Route screen.
Table of ContentsZyWALL USG 300 User’s Guide2330.9.1 HTTP Inspection and TCP/UDP/ICMP Decoders ... 45
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide230Figure 150 Network > Routing > Policy Route > EditThe following table desc
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide231Type Select Auto to have the ZyWALL use the routing table to find a next-hop and fo
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide23212.5 IP Static Routes The ZyWALL has no knowledge of the networks beyond the network
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide23312.6 Static Route SummaryClick Network > Routing > Static Route to open the S
Chapter 12 Policy and Static RoutesZyWALL USG 300 User’s Guide234The following table describes the labels in this screen. Table 69 Network > Rou
ZyWALL USG 300 User’s Guide235CHAPTER 13 Routing ProtocolsThis chapter describes how to set up RIP and OSPF routing protocol settings for the ZyWALL.
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide236RIP uses UDP port 520.13.1.2 Authentication TypesAuthentication is used to guarantee the in
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide237Figure 154 Network > Routing > RIPThe following table describes the labels in this
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide238• OSPF filters and summarizes routing information, which reduces the size of routing tables
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide239This OSPF AS consists of four areas, areas 0-3. Area 0 is always the backbone. In this exam
Table of ContentsZyWALL USG 300 User’s Guide2434.1.1 User Types ...
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide240Figure 156 OSPF: Types of RoutersIn order to reduce the amount of traffic between routers,
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide2412 Set up the OSPF areas.3 Configure the appropriate interfaces. See Section 10.2.1 on page
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide24213.4.2 OSPF Area Add/Edit The OSPF Area Add/Edit screen allows you to create a new area or
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide243Figure 159 Network > Routing > OSPF > EditThe following table describes the labe
Chapter 13 Routing ProtocolsZyWALL USG 300 User’s Guide244Text Authentication KeyThis field is available if the Authentication is Text. Type the passw
ZyWALL USG 300 User’s Guide245CHAPTER 14 ZonesSet up zones to configure network security and network policies in the ZyWALL.See Section 5.4.7 on pag
Chapter 14 ZonesZyWALL USG 300 User’s Guide246Intra-zone traffic is traffic between interfaces or VPN tunnels in the same zone. For example, in Figure
Chapter 14 ZonesZyWALL USG 300 User’s Guide24714.3 Zone Add/Edit The Zone Add/Edit screen allows you to define a zone or edit an existing one. To ac
Chapter 14 ZonesZyWALL USG 300 User’s Guide248
ZyWALL USG 300 User’s Guide249CHAPTER 15 DDNSThis chapter describes how to configure dynamic DNS (DDNS) services for the ZyWALL. First, it provides a
Table of ContentsZyWALL USG 300 User’s Guide2538.1 AAA Server Overview ...
Chapter 15 DDNSZyWALL USG 300 User’s Guide25015.1.2 High Availability (HA)The DDNS server maps a domain name to the IP address of one of the ZyWALL’s
Chapter 15 DDNSZyWALL USG 300 User’s Guide25115.3 DDNS SummaryThe DDNS screen provides a summary of all DDNS domain names and their configuration. I
Chapter 15 DDNSZyWALL USG 300 User’s Guide25215.4 Dynamic DNS Add/Edit The DDNS Add/Edit screen allows you to add a domain name to the ZyWALL or to e
Chapter 15 DDNSZyWALL USG 300 User’s Guide253HA Interface This field is only available when the IP Address Update Policy is Interface. Select the alt
Chapter 15 DDNSZyWALL USG 300 User’s Guide254
ZyWALL USG 300 User’s Guide255CHAPTER 16 Virtual ServersThis chapter describes how to set up, manage, and remove virtual servers. First, it provides
Chapter 16 Virtual ServersZyWALL USG 300 User’s Guide256The ZyWALL checks virtual servers before it applies to-ZyWALL firewall rules, so to-ZyWALL fir
Chapter 16 Virtual ServersZyWALL USG 300 User’s Guide257Figure 166 Network > Virtual ServerThe following table describes the labels in this scre
Chapter 16 Virtual ServersZyWALL USG 300 User’s Guide25816.4.1 Virtual Server Add/Edit The Virtual Server Add/Edit screen lets you create new virtual
Chapter 16 Virtual ServersZyWALL USG 300 User’s Guide259User Defined This field is available if Original IP is User Defined. Type the destination IP
Table of ContentsZyWALL USG 300 User’s Guide2641.2 ISP Account Summary ...
Chapter 16 Virtual ServersZyWALL USG 300 User’s Guide260
ZyWALL USG 300 User’s Guide261CHAPTER 17 HTTP RedirectThis chapter shows you how to configure HTTP redirection on your ZyWALL.See Section 5.4.19 on
Chapter 17 HTTP RedirectZyWALL USG 300 User’s Guide262Figure 168 HTTP Redirect ExampleIn the example, proxy server A is connected to ge4 in the DMZ
Chapter 17 HTTP RedirectZyWALL USG 300 User’s Guide263Figure 169 Network > HTTP RedirectThe following table describes the labels in this screen.
Chapter 17 HTTP RedirectZyWALL USG 300 User’s Guide264Interface Select the interface on which the HTTP request must be received for the ZyWALL to forw
ZyWALL USG 300 User’s Guide265CHAPTER 18 ALGThis chapter covers how to use the ZyWALL’s ALG feature to allow certain applications to pass through the
Chapter 18 ALGZyWALL USG 300 User’s Guide266You could also have a trunk with one interface set to active and a second interface set to passive. The Zy
Chapter 18 ALGZyWALL USG 300 User’s Guide267Figure 171 H.323 ALG Example 18.1.6 SIPThe Session Initiation Protocol (SIP) is an application-layer c
Chapter 18 ALGZyWALL USG 300 User’s Guide26818.1.6.2 SIP Signaling Session TimeoutMost SIP clients have an “expire” mechanism indicating the lifetime
Chapter 18 ALGZyWALL USG 300 User’s Guide269For example, you configure firewall and virtual server rules to allow LAN IP address A to receive calls t
Table of ContentsZyWALL USG 300 User’s Guide2744.1.1 Service Access Limitations ...
Chapter 18 ALGZyWALL USG 300 User’s Guide270The following table describes the labels in this screen. Table 83 Network > ALGLABEL DESCRIPTIONEnab
Chapter 18 ALGZyWALL USG 300 User’s Guide27118.4 WAN to LAN SIP Peer-to-peer Calls ExampleThis example shows how to configure firewall and virtual s
Chapter 18 ALGZyWALL USG 300 User’s Guide272Figure 178 Firewall > WAN to LAN5 Configure the screen as follows. For the Destination, select Create
Chapter 18 ALGZyWALL USG 300 User’s Guide273Figure 181 Firewall > WAN > LAN > Add
Chapter 18 ALGZyWALL USG 300 User’s Guide274
275PART IIIFirewall and VPNFirewall (277)IPSec VPN (291)SSL VPN (323)SSL User Screens (331)SSL User Application Screens (337)SSL User File Sharin
276
ZyWALL USG 300 User’s Guide277CHAPTER 19 FirewallThis chapter introduces the ZyWALL’s firewall and shows you how to configure your ZyWALL’s firewal
Chapter 19 FirewallZyWALL USG 300 User’s Guide278Your customized rules take precedence and override the ZyWALL’s default settings. The ZyWALL checks t
Chapter 19 FirewallZyWALL USG 300 User’s Guide279The following table explains the default firewall rules for traffic going through the ZyWALL. See Se
Table of ContentsZyWALL USG 300 User’s Guide2845.1.2 Errors in Configuration Files or Shell Scripts ...
Chapter 19 FirewallZyWALL USG 300 User’s Guide28019.2.1.2 To-ZyWALL Rules Rules with ZyWALL as the To Zone apply to traffic going to the ZyWALL itsel
Chapter 19 FirewallZyWALL USG 300 User’s Guide281Figure 183 Blocking All LAN to WAN IRC Traffic Example Your firewall would have the following conf
Chapter 19 FirewallZyWALL USG 300 User’s Guide282Figure 184 Limited LAN to WAN IRC Traffic ExampleYour firewall would have the following configurati
Chapter 19 FirewallZyWALL USG 300 User’s Guide28319.4 AlertsYou can choose to generate an alert or log when a rule is matched and have the ZyWALL se
Chapter 19 FirewallZyWALL USG 300 User’s Guide28419.6 Configuring the FirewallClick Firewall to open the Firewall screen. This screen varies dependin
Chapter 19 FirewallZyWALL USG 300 User’s Guide285Allow Asymmetrical RouteIf an alternate gateway on the LAN has an IP address in the same subnet as t
Chapter 19 FirewallZyWALL USG 300 User’s Guide28619.6.1 Edit a Firewall Rule In the Firewall screen, click the Edit or Add icon to display the Firewa
Chapter 19 FirewallZyWALL USG 300 User’s Guide287The following table describes the labels in this screen. 19.7 Firewall Rule Configuration Exampl
Chapter 19 FirewallZyWALL USG 300 User’s Guide288selected entry. Remember the sequence (priority) of the rules is important since they are applied in
Chapter 19 FirewallZyWALL USG 300 User’s Guide289Figure 190 Firewall Example: Create an Address Object4 Select Create Object in the Service drop-do
Table of ContentsZyWALL USG 300 User’s Guide29Appendix E Importing Certificates ...
Chapter 19 FirewallZyWALL USG 300 User’s Guide290Figure 193 Firewall Example: MyService Example Rule in Summary
ZyWALL USG 300 User’s Guide291CHAPTER 20 IPSec VPNThis chapter explains how to set up and maintain IPSec VPNs in the ZyWALL. See Section 5.4.4 on pag
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide292Figure 195 VPN: IKE SA and IPSec SA In this example, a computer in network A is exchanging data wi
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide293Usually, you should select ESP. AH does not support encryption, and ESP is more suitable with NAT.2
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide294If you enable PFS, the ZyWALL and remote IPSec router perform a DH key exchange every time an IPSec
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide295• Source address in outbound packets - this translation is necessary if you want the ZyWALL to rout
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide296• Destination - the original destination address; the local network (A).• SNAT - the translated sour
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide297• Make sure the to-ZyWALL firewall rules allow IPSec VPN traffic to the ZyWALL. IKE uses UDP port 5
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide298Each field is discussed in the following table. See Section 20.3.3 on page 302 and Section 20.3.2 on
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide299Figure 199 VPN > IPSec VPN > VPN Connection > Edit (IKE) Each field is described in the
About This User's GuideZyWALL USG 300 User’s Guide3About This User's GuideThis manual is designed to guide you through the configuration o
Table of ContentsZyWALL USG 300 User’s Guide30
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide300Active Protocol Select which protocol you want to use in the IPSec SA. Choices are:AH (RFC 2402) - p
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide301Policy EnforcementSelect this if you want the ZyWALL to drop traffic whose source and destination I
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide30220.3.3 VPN Connection Add/Edit Manual Key The VPN Connection Add/Edit Manual Key screen allows you
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide303Figure 200 VPN > IPSec VPN > VPN Connection > Manual Key > EditThe following table de
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide304Encapsulation ModeSelect which type of encapsulation the IPSec SA uses. Choices areTunnel - this mod
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide305Authentication KeyEnter the authentication key, which depends on the authentication algorithm.MD5 -
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide30620.4 VPN Gateway Screens You use the VPN Gateway summary screen to look at the VPN gateways you hav
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide307It takes several steps to establish an IKE SA. The negotiation mode determines how many. There are
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide308" Both routers must use the same encryption algorithm, authentication algorithm, and DH key gro
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide309In main mode, the ZyWALL and remote IPSec router authenticate each other in steps 5 and 6, as illus
List of FiguresZyWALL USG 300 User’s Guide31List of FiguresFigure 1 ZyWALL USG 300 Front Panel ...
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide310For example, in Table 93 on page 310, the ZyWALL and the remote IPSec router authenticate each other
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide31120.4.2.2 VPN, NAT, and NAT TraversalIn the following example, there is another router (A) between
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide312• Instead of using the pre-shared key, the ZyWALL and remote IPSec router check the signatures on ea
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide31320.4.4 VPN Gateway Add/Edit The VPN Gateway Add/Edit screen allows you to create a new VPN gateway
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide314Figure 206 VPN > IPSec VPN > VPN Gateway > EditEach field is described in the following t
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide315Proposal# This field is a sequential value, and it is not associated with a specific proposal. The
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide316Secure Gateway AddressType the IP address or the domain name of the remote IPSec router. Set this fi
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide317Peer ID Type Select which type of identification is used to identify the remote IPSec router during
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide31820.5 VPN Concentrator A VPN concentrator combines several VPN connections into one secure network.
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide31920.5.1 VPN Concentrator SummaryYou use the VPN Concentrator summary screen to look at the VPN conc
List of FiguresZyWALL USG 300 User’s Guide32Figure 39 VPN Advanced Wizard: Step 3 ...
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide320Each field is described in the following table. 20.6 SA Monitor Screen You can use the SA Monitor
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide321Figure 211 VPN > IPSec VPN > SA MonitorEach field is described in the following table. Tabl
Chapter 20 IPSec VPNZyWALL USG 300 User’s Guide32220.6.1 Regular Expressions in Searching IPSec SAs by Name or PolicyA question mark (?) lets a singl
ZyWALL USG 300 User’s Guide323CHAPTER 21 SSL VPNThis chapter shows you how to set up secure SSL VPN access for remote user login. See Section 5.4.5 o
Chapter 21 SSL VPNZyWALL USG 300 User’s Guide32421.1.2 SSL Access Policy LimitationsYou cannot delete an object that is used by an SSL access policy.
Chapter 21 SSL VPNZyWALL USG 300 User’s Guide32521.3 Creating/Editing an SSL Access Policy To create a new or edit an existing SSL access policy, cl
Chapter 21 SSL VPNZyWALL USG 300 User’s Guide32621.4 SSL Connection Monitor The ZyWALL keeps track of the users who are currently logged into the VPN
Chapter 21 SSL VPNZyWALL USG 300 User’s Guide327• log out a user and delete related session information. Once a user logs out, the corresponding entr
Chapter 21 SSL VPNZyWALL USG 300 User’s Guide328Figure 215 VPN > SSL VPN > Global Setting The following table describes the labels in this scr
Chapter 21 SSL VPNZyWALL USG 300 User’s Guide32921.5.1 Uploading a Custom LogoFollow the steps below to upload a custom logo on the ZyWALL. 1 Click
List of FiguresZyWALL USG 300 User’s Guide33Figure 82 AppPatrol > http > Edit Default ...
Chapter 21 SSL VPNZyWALL USG 300 User’s Guide330Figure 217 SSL VPN Client Portal Screen Example If the user account is not set up for SSL VPN access
ZyWALL USG 300 User’s Guide331CHAPTER 22 SSL User ScreensThis chapter introduces secure network access and gives an overview of the remote user scree
Chapter 22 SSL User ScreensZyWALL USG 300 User’s Guide332• Windows 2000 and Windows XP• Internet Explorer 5.5 and above (for IE7, JRE 1.6 must be enab
Chapter 22 SSL User ScreensZyWALL USG 300 User’s Guide333Figure 220 Login Security Screen 3 A login screen displays. Enter the user name and pass
Chapter 22 SSL User ScreensZyWALL USG 300 User’s Guide334" Available resource links vary depending on the configuration your network administrato
Chapter 22 SSL User ScreensZyWALL USG 300 User’s Guide33522.4 BookmarkYou can create a bookmark of the ZyWALL by clicking the Add to Favorite icon.
Chapter 22 SSL User ScreensZyWALL USG 300 User’s Guide336
ZyWALL USG 300 User’s Guide337CHAPTER 23 SSL User Application ScreensThis chapter describes the Application screens you use to access an application
Chapter 23 SSL User Application ScreensZyWALL USG 300 User’s Guide338
ZyWALL USG 300 User’s Guide339CHAPTER 24 SSL User File Sharing ScreensThis chapter describes the File Sharing screen you use to access files on a fil
List of FiguresZyWALL USG 300 User’s Guide34Figure 125 Network > Interface > Ethernet > Edit ...
Chapter 24 SSL User File Sharing ScreensZyWALL USG 300 User’s Guide340Figure 228 File Sharing 24.3 Opening a File or FolderYou can open a file if t
Chapter 24 SSL User File Sharing ScreensZyWALL USG 300 User’s Guide3414 A list of files/folders displays. Click on a file to open it in a separate br
Chapter 24 SSL User File Sharing ScreensZyWALL USG 300 User’s Guide342Figure 231 File Sharing: Save a Word File 24.4 Creating a New FolderTo creat
Chapter 24 SSL User File Sharing ScreensZyWALL USG 300 User’s Guide343Figure 233 File Sharing: Rename A popup window displays. Specify the new name
Chapter 24 SSL User File Sharing ScreensZyWALL USG 300 User’s Guide34424.7 Uploading a FileFollow the steps below to upload a file to the file server
ZyWALL USG 300 User’s Guide345CHAPTER 25 L2TP VPNThis chapter explains how to set up and maintain L2TP VPNs in the ZyWALL. See Section 5.4.6 on page
Chapter 25 L2TP VPNZyWALL USG 300 User’s Guide346• Use transport mode.• Not be a manual key VPN connection. •Use Pre-Shared Key authentication.• Use a
Chapter 25 L2TP VPNZyWALL USG 300 User’s Guide34725.4 L2TP VPN ConfigurationClick VPN > L2TP VPN to open the following screen. Use this screen to
Chapter 25 L2TP VPNZyWALL USG 300 User’s Guide34825.5 L2TP VPN Session MonitorClick VPN > L2TP VPN > Session Monitor to open the following scre
Chapter 25 L2TP VPNZyWALL USG 300 User’s Guide349Disconnect Click the Disconnect icon next to an L2TP VPN connection to disconnect it.Refresh Click R
List of FiguresZyWALL USG 300 User’s Guide35Figure 168 HTTP Redirect Example ...
Chapter 25 L2TP VPNZyWALL USG 300 User’s Guide350
ZyWALL USG 300 User’s Guide351CHAPTER 26 L2TP VPN ExampleThis chapter shows how to create a basic L2TP VPN tunnel.26.1 L2TP VPN ExampleThis chapter
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide352Figure 242 VPN > IPSec VPN > VPN Gateway > Edit • Configure the My Address setting
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide35326.3 Configuring the Default L2TP VPN Connection Example1 Click VPN > Network > IPSec
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide354Figure 245 VPN > IPSec VPN > VPN Connection (Enable) 26.4 Configuring the L2TP VPN S
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide355Figure 247 Routing > Add: L2TP VPN Example2 Configure the following.• Enable the policy
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide35626.6.1 Configuring L2TP in Windows XPIn Windows XP do the following to establish an L2TP VPN
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide357Figure 250 New Connection Wizard: Connection Name6 Select Do not dial the initial connecti
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide358Figure 252 New Connection Wizard: VPN Server Selection8 Click Finish.9 The Connect L2TP to
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide359Figure 254 Connect L2TP to ZyWALL: Security11 Select Optional encryption (connect even if
List of FiguresZyWALL USG 300 User’s Guide36Figure 211 VPN > IPSec VPN > SA Monitor ...
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide360Figure 256 L2TP to ZyWALL Properties > Security13 Select the Use pre-shared key for auth
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide361Figure 259 Connect L2TP to ZyWALL16 A window appears while the user name and password are
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide3621 Click Start > Run. Type regedit and click OK.Figure 262 Starting the Registry Editor2
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide363Figure 265 ProhibitIpSec DWORD Value6 Restart the computer and continue with the next sect
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide364Figure 268 Add > IP Security Policy Management > Finish4 Right-click IP Security Poli
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide365Figure 270 IP Security Policy: Name6 Clear the Activate the default response rule check bo
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide3668 In the properties dialog box, click Add > Next.Figure 273 IP Security Policy Propertie
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide367Figure 275 IP Security Policy Properties: Network Type11 Select Use this string to protect
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide368Figure 277 IP Security Policy Properties: IP Filter List13 Type ZyWALL WAN_IP in the Name f
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide369Figure 279 Filter Properties: Addressing15 Configure the following in the Filter Propertie
List of FiguresZyWALL USG 300 User’s Guide37Figure 254 Connect L2TP to ZyWALL: Security ...
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide370Figure 281 IP Security Policy Properties: IP Filter List17 Select Require Security and cli
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide37126.6.2.3 Configure the Windows 2000 Network ConnectionAfter you have configured the IPSec p
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide372Figure 286 New Connection Wizard: Destination Address4 Select For all users and click Next.
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide3736 Click Properties.Figure 289 Connect L2TP to ZyWALL7 Click Security and select Advanced (
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide374Figure 291 Connect L2TP to ZyWALL: Security > Advanced9 Click Networking and select Laye
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide375Figure 293 Connect L2TP to ZyWALL11 A ZyWALL-L2TP icon displays in your system tray. Doubl
Chapter 26 L2TP VPN ExampleZyWALL USG 300 User’s Guide376
377PART IVApplication Patrol & Anti-XApplication Patrol (379)Anti-Virus (403)IDP (417)ADP (445)Content Filter Screens (463)Content Filter Rep
378
ZyWALL USG 300 User’s Guide379CHAPTER 27 Application PatrolThis chapter describes how to use application patrol for the ZyWALL. It provides an overvi
List of FiguresZyWALL USG 300 User’s Guide38Figure 297 LAN to WAN, Outbound 200 kbps, Inbound 500 kbps ...
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide380" The ZyWALL allows the first eight packets to go through the firewall, regardless of
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide38127.4.1 Connection and Packet Directions Application patrol looks at the connection direct
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide382Figure 297 LAN to WAN, Outbound 200 kbps, Inbound 500 kbps 27.4.3 Bandwidth Management P
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide383Figure 298 Bandwidth Management Behavior27.4.5.1 Configured Rate EffectIn the following
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide38427.4.5.4 Priority and Over Allotment of Bandwidth EffectServer A has a configured rate tha
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide385Figure 299 Application Patrol Bandwidth Management Example27.5.1 Setting the Interface’
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide386Figure 300 SIP Any to WAN Bandwidth Management Example27.5.3 SIP WAN to Any Bandwidth Ma
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide387• Third highest priority (3).• Disable maximize bandwidth usage since you do not want to g
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide38827.6 Other ApplicationsSometimes, the ZyWALL cannot identify the application. For example,
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide389Figure 304 AppPatrol > GeneralThe following table describes the labels in this screen
List of FiguresZyWALL USG 300 User’s Guide39Figure 340 Base Profiles ...
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide39027.9 Application Patrol ApplicationsUse the application patrol Common, Instant Messenger,
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide39127.9.1 Application Patrol Edit Use this screen to edit the settings for an application. T
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide392# This field is a sequential value, and it is not associated with a specific condition.Note
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide39327.9.2 Application Patrol Policy Edit The Application Policy Edit screen allows you to ed
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide394Schedule Select a schedule that defines when the policy applies or select Create Object to
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide39527.10 Other Protocol Screen The Other Protocol screen controls the default policy for TCP
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide396The following table describes the labels in this screen. See Section 27.10.1 on page 397 fo
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide39727.10.1 Other Configuration Add/Edit The Other Configuration Add/Edit screen allows you t
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide398Schedule Select a schedule that defines when the policy applies or select Create Object to
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide39927.11 Application Patrol StatisticsThis screen displays a bandwidth usage graph and stati
About This User's GuideZyWALL USG 300 User’s Guide4" It is recommended you use the web configurator to configure the ZyWALL.• Web Configurat
List of FiguresZyWALL USG 300 User’s Guide40Figure 383 Object > Service > Service > Edit ...
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide400The following table describes the labels in this screen. 27.11.2 Application Patrol Stati
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide401Figure 312 AppPatrol > Statistics: Protocol StatisticsThe following table describes t
Chapter 27 Application PatrolZyWALL USG 300 User’s Guide402Forwarded Data (KB) This is how much of the application’s traffic the ZyWALL has sent (in k
ZyWALL USG 300 User’s Guide403CHAPTER 28 Anti-VirusThis chapter introduces and shows you how to configure the anti-virus scanner.See Section 5.4.14 o
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide4044 Once the virus is spread through the network, the number of infected networked computers can grow
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide405Figure 313 ZyWALL Anti-virus Example The following describes the virus scanning process on the
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide406• Encrypted traffic. This could be password-protected files or VPN traffic where the ZyWALL is not
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide407The following table describes the labels in this screen.Table 121 Anti-X > Anti-Virus > Ge
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide40828.3.1 Anti-Virus Policy EditClick the Add or Edit icon in the Anti-X > Anti-Virus > General
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide409Protocols to Scan Select which protocols of traffic to scan for viruses.FTP applies to traffic usi
List of FiguresZyWALL USG 300 User’s Guide41Figure 426 Secure and Insecure Service Access From the WAN ...
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide41028.4 Anti-Virus SettingClick Anti-X > Anti-Virus > Setting screen to display the configurati
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide411The following table describes the labels in this screen.Table 123 Anti-X > Anti-Virus > Se
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide41228.5 Anti-Virus White List Add/EditFrom the Anti-X > Anti-Virus > Setting screen, click a wh
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide41328.6 Anti-Virus Black List Add/EditFrom the Anti-X > Anti-Virus > Setting screen, click a b
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide414Figure 319 Anti-X > Anti-Virus > Signature: Search by SeverityThe following table describes
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide415Severity This is the severity level of the anti-virus signature. Click the severity column header
Chapter 28 Anti-VirusZyWALL USG 300 User’s Guide416
ZyWALL USG 300 User’s Guide417CHAPTER 29 IDPThis chapter introduces IDP (Intrusion, Detection and Prevention), IDP profiles, binding an IDP profile
Chapter 29 IDPZyWALL USG 300 User’s Guide41829.1.4 SignaturesIf a packet matches a signature, the action specified by the signature is taken. You can
Chapter 29 IDPZyWALL USG 300 User’s Guide419Figure 320 Anti-X > IDP > GeneralThe following table describes the screens in this screen. Table
List of FiguresZyWALL USG 300 User’s Guide42Figure 469 Maintenance > Log > Log Setting ...
Chapter 29 IDPZyWALL USG 300 User’s Guide42029.4 Configuring IDP BindingsClick Anti-X > IDP > General and then an Add or Edit icon to display t
Chapter 29 IDPZyWALL USG 300 User’s Guide421Figure 321 Anti-X > IDP > General > AddThe following table describes the screens in this scree
Chapter 29 IDPZyWALL USG 300 User’s Guide422Figure 322 Base ProfilesThe following table describes this screen. 29.6 Profile Summary ScreenSelect An
Chapter 29 IDPZyWALL USG 300 User’s Guide423Figure 323 Anti-X > IDP > ProfileThe following table describes the fields in this screen. 29.7
Chapter 29 IDPZyWALL USG 300 User’s Guide424" If Internet Explorer opens a warning screen about a script making Internet Explorer run slowly and
Chapter 29 IDPZyWALL USG 300 User’s Guide425Figure 324 Anti-X > IDP > Profile > Edit : Group View
Chapter 29 IDPZyWALL USG 300 User’s Guide426The following table describes the fields in this screen. Table 131 Anti-X > IDP > Profile > Gr
Chapter 29 IDPZyWALL USG 300 User’s Guide42729.8.2 Policy TypesThis section describes IDP policy types, also known as attack types, as categorized i
Chapter 29 IDPZyWALL USG 300 User’s Guide42829.8.3 IDP Service GroupsAn IDP service group is a set of related packet inspection signatures.DoS/DDoS T
Chapter 29 IDPZyWALL USG 300 User’s Guide429The following figure shows the WEB_PHP service group that contains signatures related to attacks on web s
List of TablesZyWALL USG 300 User’s Guide43List of TablesTable 1 Front Panel LEDs ...
Chapter 29 IDPZyWALL USG 300 User’s Guide430Figure 326 Anti-X > IDP > Profile: Query ViewThe following table describes the fields in this scre
Chapter 29 IDPZyWALL USG 300 User’s Guide43129.8.5 Query ExampleThis example shows a search with these criteria:• Severity: severe and high• Attack
Chapter 29 IDPZyWALL USG 300 User’s Guide432Figure 328 Query Example Search Results29.9 Introducing IDP Custom Signatures Create custom signatures
Chapter 29 IDPZyWALL USG 300 User’s Guide433Figure 329 IP v4 Packet Headers The header fields are discussed below: Table 135 IP v4 Packet Header
Chapter 29 IDPZyWALL USG 300 User’s Guide43429.10 Configuring Custom SignaturesSelect Anti-X > IDP > Custom Signatures. The first screen shows
Chapter 29 IDPZyWALL USG 300 User’s Guide435The following table describes the fields in this screen. 29.10.1 Creating or Editing a Custom Signature
Chapter 29 IDPZyWALL USG 300 User’s Guide436Figure 331 Anti-X > IDP > Custom Signatures > Add/Edit
Chapter 29 IDPZyWALL USG 300 User’s Guide437The following table describes the fields in this screen. Table 137 Anti-X > IDP > Custom Signatur
Chapter 29 IDPZyWALL USG 300 User’s Guide438IP Options IP options is a variable-length list of IP options for a datagram that define IP Security Optio
Chapter 29 IDPZyWALL USG 300 User’s Guide43929.10.2 Custom Signature ExampleBefore creating a custom signature, you must first clearly understand th
List of TablesZyWALL USG 300 User’s Guide44Table 39 Licensing > Registration ...
Chapter 29 IDPZyWALL USG 300 User’s Guide44029.10.2.2 Analyze PacketsThen use a packet sniffer such as TCPdump or Ethereal to investigate some more.F
Chapter 29 IDPZyWALL USG 300 User’s Guide441Figure 335 Example Custom Signature
Chapter 29 IDPZyWALL USG 300 User’s Guide44229.10.3 Applying Custom SignaturesAfter you create your custom signature, it becomes available in the IDP
Chapter 29 IDPZyWALL USG 300 User’s Guide443Figure 337 Custom Signature Log29.10.5 Snort SignaturesYou may want to refer to open source Snort sign
Chapter 29 IDPZyWALL USG 300 User’s Guide444" Not all Snort functionality is supported in the ZyWALL.Flow flowFlags flagsSequence Number seqAck N
ZyWALL USG 300 User’s Guide445CHAPTER 30 ADPThis chapter introduces ADP (Anomaly Detection and Prevention), anomaly profiles and binding an ADP prof
Chapter 30 ADPZyWALL USG 300 User’s Guide44630.1.3 ADP on the ZyWALLADP on the ZyWALL protects against network-based intrusions. See Section 30.8 on
Chapter 30 ADPZyWALL USG 300 User’s Guide447The following table describes the screens in this screen. 30.4 Configuring Anomaly Profile BindingsClick
Chapter 30 ADPZyWALL USG 300 User’s Guide448Figure 339 Anti-X > ADP > General > AddThe following table describes the screens in this screen
Chapter 30 ADPZyWALL USG 300 User’s Guide449Figure 340 Base ProfilesThese are the default base profiles at the time of writing. 30.6 Profile Summa
List of TablesZyWALL USG 300 User’s Guide45Table 82 Network > HTTP Redirect > Edit ...
Chapter 30 ADPZyWALL USG 300 User’s Guide45030.7 Creating New Profiles You may want to create a new profile if not all rules in a base profile are ap
Chapter 30 ADPZyWALL USG 300 User’s Guide45130.8.1 Port ScanningAn attacker scans device(s) to determine what types of network protocols or services
Chapter 30 ADPZyWALL USG 300 User’s Guide45230.8.1.4 Filtered Port ScansA filtered port scan may indicate that there were no network errors (ICMP unr
Chapter 30 ADPZyWALL USG 300 User’s Guide45330.8.2.3 TCP SYN Flood AttackUsually a client starts a session by sending a SYN (synchronize) packet to
Chapter 30 ADPZyWALL USG 300 User’s Guide45430.8.2.5 UDP Flood AttackUDP is a connection-less protocol and it does not require any connection setup p
Chapter 30 ADPZyWALL USG 300 User’s Guide45530.8.3 Profile > Traffic Anomaly ScreenFigure 345 Profiles: Traffic Anomaly
Chapter 30 ADPZyWALL USG 300 User’s Guide456The following table describes the fields in this screen. 30.9 Profiles: Protocol Anomaly Protocol anomal
Chapter 30 ADPZyWALL USG 300 User’s Guide457Protocol anomaly detection includes HTTP Inspection, TCP Decoder, UDP Decoder and ICMP Decoder where each
Chapter 30 ADPZyWALL USG 300 User’s Guide458NON-RFC-HTTP-DELIMITER ATTACKThis is when a newline “\n” character is detected as a delimiter. This is non
Chapter 30 ADPZyWALL USG 300 User’s Guide45930.9.2 Protocol Anomaly ConfigurationIn the Anti-X > ADP > Profile screen, click the Edit icon or
List of TablesZyWALL USG 300 User’s Guide46Table 125 Anti-X > Anti-Virus > Setting > Black List Add ...
Chapter 30 ADPZyWALL USG 300 User’s Guide460Figure 346 Profiles: Protocol Anomaly
Chapter 30 ADPZyWALL USG 300 User’s Guide461The following table describes the fields in this screen. Table 145 ADP > Profile > Protocol Anom
Chapter 30 ADPZyWALL USG 300 User’s Guide462
ZyWALL USG 300 User’s Guide463CHAPTER 31 Content Filter ScreensThis chapter covers how to use the content filter feature to control web access. See S
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide46431.1.3 Content Filter Configuration GuidelinesYou must configure an address object, a
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide465Block web access when no policy is appliedSelect this check box to stop users from acc
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide46631.3 Content Filter Policy Screen Click Anti-X > Content Filter > General > A
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide467The following table describes the labels in this screen. 31.4 Content Filter Profile
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide46831.5 External Web Filtering Service When you register for and enable the external web
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide46931.6 Content Filter Categories Screen Click Anti-X > Content Filter > Filter Pr
List of TablesZyWALL USG 300 User’s Guide47Table 168 Object > Address > Address Group > Add ...
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide470Figure 351 Anti-X > Content Filter > Filter Profile > Add The following tabl
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide471Matched Web Pages Select Block to prevent users from accessing web pages that match th
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide472Nudity Selecting this category excludes pages containing nude or seminude depictions of
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide473Business/Economy Selecting this category excludes pages devoted to business firms, bus
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide474Health Selecting this category excludes pages that provide advice and information on ge
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide475Email Selecting this category excludes pages offering web-based email services, such a
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide476Sports/Recreation/Hobbies Selecting this category excludes pages that promote or provid
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide47731.7 Content Filter Customization Screen Click Anti-X > Content Filter > Filter
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide478The following table describes the labels in this screen. Table 150 Anti-X > Conte
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide47931.8 Keyword Blocking URL CheckingThe ZyWALL checks the URL’s domain name (or IP addr
List of TablesZyWALL USG 300 User’s Guide48Table 211 SNMP Traps ...
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide48031.9 Content Filter Cache Screen Click Anti-X > Content Filter > Cache to displa
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide481Refresh Click this button to reload the list of content filter cache entries.Total cac
Chapter 31 Content Filter ScreensZyWALL USG 300 User’s Guide482
ZyWALL USG 300 User’s Guide483CHAPTER 32 Content Filter ReportsThis chapter describes how to view content filtering reports after you have activated
Chapter 32 Content Filter ReportsZyWALL USG 300 User’s Guide484ZyWALL using the Rename button in the Service Management screen (see Figure 356 on page
Chapter 32 Content Filter ReportsZyWALL USG 300 User’s Guide4856 Click Submit.Figure 357 Blue Coat: Login7 In the Web Filter Home screen, click the
Chapter 32 Content Filter ReportsZyWALL USG 300 User’s Guide486Figure 359 Blue Coat: Report Home9 Select a time period in the Date Range field, eith
Chapter 32 Content Filter ReportsZyWALL USG 300 User’s Guide487Figure 360 Global Report Screen Example11 You can click a category in the Categories
Chapter 32 Content Filter ReportsZyWALL USG 300 User’s Guide488Figure 361 Requested URLs Example32.2 Web Site SubmissionYou may find that a web sit
Chapter 32 Content Filter ReportsZyWALL USG 300 User’s Guide489Figure 362 Web Page Review Process Screen3 Type the web site’s URL in the field and
List of TablesZyWALL USG 300 User’s Guide49Table 254 Interface Logs ...
Chapter 32 Content Filter ReportsZyWALL USG 300 User’s Guide490
491PART VDevice HA & ObjectsDevice HA (493)User/Group (503)Addresses (515)Services (521)Schedules (527)AAA Server (531)Authentication Object
ZyWALL USG 300 User’s Guide493CHAPTER 33 Device HAUse device HA and Virtual Router Redundancy Protocol (VRRP) to increase network reliability. See S
Chapter 33 Device HAZyWALL USG 300 User’s Guide494" Every router in a virtual router must use the same advertisement interval.If Router A becomes
Chapter 33 Device HAZyWALL USG 300 User’s Guide49533.1.1 Additional VRRP Notes• It is possible to set up two virtual routers so that they back up ea
Chapter 33 Device HAZyWALL USG 300 User’s Guide49633.2.1 Link Monitoring and Service ControlWith link monitoring enabled, a backup ZyWALL that takes
Chapter 33 Device HAZyWALL USG 300 User’s Guide497Figure 366 Device HA > VRRP GroupThe following table describes the labels in this screen. See
Chapter 33 Device HAZyWALL USG 300 User’s Guide49833.5 VRRP Group Add/Edit The VRRP Group Add/Edit screen allows you to add VRRP groups to the ZyWALL
Chapter 33 Device HAZyWALL USG 300 User’s Guide499VRID Type the virtual router ID number.Description Type the description of the VRRP group. This fie
Document ConventionsZyWALL USG 300 User’s Guide5Document ConventionsWarnings and NotesThese are how warnings and notes are shown in this User’s Guide
List of TablesZyWALL USG 300 User’s Guide50
Chapter 33 Device HAZyWALL USG 300 User’s Guide50033.6 Synchronization Overview In a virtual router, backup routers do not automatically get configur
Chapter 33 Device HAZyWALL USG 300 User’s Guide501" You must subscribe to services on the backup ZyWALL before synchronizing it with the master
Chapter 33 Device HAZyWALL USG 300 User’s Guide502Sync. Now Click this button to get updated certificates, AV signatures, IDP and application patrol s
ZyWALL USG 300 User’s Guide503CHAPTER 34 User/GroupThis chapter describes how to set up user accounts, user groups, and user settings for the ZyWALL
Chapter 34 User/GroupZyWALL USG 300 User’s Guide50434.1.2 Ext-User AccountsSet up an Ext-User account if the user is authenticated by an external ser
Chapter 34 User/GroupZyWALL USG 300 User’s Guide50534.1.2.2 Creating a Large Number of Ext-User AccountsIf you plan to create a large number of Ext-
Chapter 34 User/GroupZyWALL USG 300 User’s Guide506" This works with HTTP traffic only. The ZyWALL does not force users to log in before it route
Chapter 34 User/GroupZyWALL USG 300 User’s Guide507Figure 372 User/Group > User > EditThe following table describes the labels in this screen
Chapter 34 User/GroupZyWALL USG 300 User’s Guide508The user name can only contain the following characters:• Alphanumeric A-z 0-9 (there is no unicode
Chapter 34 User/GroupZyWALL USG 300 User’s Guide50934.3.1 Group Add/Edit The Group Add/Edit screen allows you to create a new user group or edit an
51PART IIntroductionIntroducing the ZyWALL (53)Features and Applications (57)Web Configurator (65)Configuration Basics (111)Tutorials (125)Status
Chapter 34 User/GroupZyWALL USG 300 User’s Guide51034.4 Setting Screen The Setting screen controls default settings, login settings, lockout settings
Chapter 34 User/GroupZyWALL USG 300 User’s Guide511The following table describes the labels in this screen. Table 162 User/Group > SettingLABEL
Chapter 34 User/GroupZyWALL USG 300 User’s Guide51234.4.1 Force User Authentication Policy Add/Edit Use this screen to specify a condition when users
Chapter 34 User/GroupZyWALL USG 300 User’s Guide513Figure 376 User/Group > Setting > Force User Authentication Policy > Add/EditThe follow
Chapter 34 User/GroupZyWALL USG 300 User’s Guide514Figure 377 Web Configurator for Non-Admin UsersThe following table describes the labels in this s
ZyWALL USG 300 User’s Guide515CHAPTER 35 AddressesThis chapter describes how to set up addresses and address groups for the ZyWALL. See Section 5.5
Chapter 35 AddressesZyWALL USG 300 User’s Guide516Figure 378 Object > Address > AddressThe following table describes the labels in this screen
Chapter 35 AddressesZyWALL USG 300 User’s Guide517The following table describes the labels in this screen. 35.3 Address Group Screens Use the Addres
Chapter 35 AddressesZyWALL USG 300 User’s Guide518The following table describes the labels in this screen. See Section 35.3.2 on page 518 for more inf
Chapter 35 AddressesZyWALL USG 300 User’s Guide519Available This field displays the names of the address and address group objects that can be added
52
Chapter 35 AddressesZyWALL USG 300 User’s Guide520
ZyWALL USG 300 User’s Guide521CHAPTER 36 ServicesUse service objects to define TCP applications, UDP applications, and ICMP messages. You can also cr
Chapter 36 ServicesZyWALL USG 300 User’s Guide522• UDP applications• ICMP messages• user-defined services (for other types of IP protocols)These objec
Chapter 36 ServicesZyWALL USG 300 User’s Guide52336.2.1 Service Add/Edit The Service Add/Edit screen allows you to create a new service or edit an e
Chapter 36 ServicesZyWALL USG 300 User’s Guide52436.3 Service Group Summary Screen The Service Group summary screen provides a summary of all service
Chapter 36 ServicesZyWALL USG 300 User’s Guide525Figure 385 Object > Service > Service Group > EditThe following table describes the label
Chapter 36 ServicesZyWALL USG 300 User’s Guide526
ZyWALL USG 300 User’s Guide527CHAPTER 37 SchedulesUse schedules to set up one-time and recurring schedules for policy routes, firewall rules, applica
Chapter 37 SchedulesZyWALL USG 300 User’s Guide528Figure 386 Object > ScheduleThe following table describes the labels in this screen. See Sectio
Chapter 37 SchedulesZyWALL USG 300 User’s Guide529Figure 387 Object > Schedule > Edit (One Time)The following table describes the labels in t
ZyWALL USG 300 User’s Guide53CHAPTER 1 Introducing the ZyWALLThis chapter gives an overview of the ZyWALL. It explains the front panel ports, LEDs, i
Chapter 37 SchedulesZyWALL USG 300 User’s Guide530Figure 388 Object > Schedule > Edit (Recurring)The Yea r, Month, and Day columns are not use
ZyWALL USG 300 User’s Guide531CHAPTER 38 AAA ServerThis chapter introduces and shows you how to configure the ZyWALL to use external authentication
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide5325 Configure the ASAS as a RADIUS server in the ZyWALL’s Object > AAA Server screens.6 Give the O
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide533Figure 390 Basic Directory Structure 38.2.2 Distinguished Name (DN) A DN uniquely identifies an
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide534Figure 391 Object > AAA Server > Active Directory (or LDAP) > Default The following tabl
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide5351 Click Object > AAA Server > Active Directory (or LDAP) > Group to display the screen. F
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide536The following table describes the labels in this screen. 38.4 RADIUS Server RADIUS (Remote Authen
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide537Figure 394 RADIUS Server Network Example38.5 Configuring a Default RADIUS ServerTo configure th
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide53838.6 Configuring a Group of RADIUS Servers You can configure a group of RADIUS servers in the RADI
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide539The following table describes the labels in this screen. Table 181 Object > AAA Server > R
Chapter 1 Introducing the ZyWALLZyWALL USG 300 User’s Guide54The following table describes the LEDs.1.3 Management OverviewYou can use the following
Chapter 38 AAA ServerZyWALL USG 300 User’s Guide540
ZyWALL USG 300 User’s Guide541CHAPTER 39 Authentication ObjectsThis chapter shows you how to select different authentication methods for user authen
Chapter 39 Authentication ObjectsZyWALL USG 300 User’s Guide54239.3 Creating an Authentication Object Follow the steps below to create an authenticat
Chapter 39 Authentication ObjectsZyWALL USG 300 User’s Guide543The following table describes the labels in this screen. 39.3.1 Example: Selecting a
Chapter 39 Authentication ObjectsZyWALL USG 300 User’s Guide544Figure 400 Example: Using Authentication Method in VPN
ZyWALL USG 300 User’s Guide545CHAPTER 40 CertificatesThis chapter gives background information about public-key certificates and explains how to use
Chapter 40 CertificatesZyWALL USG 300 User’s Guide546Certification authorities maintain directory servers with databases of valid and revoked certific
Chapter 40 CertificatesZyWALL USG 300 User’s Guide547" Be careful to not convert a binary file to text during the transfer process. It is easy f
Chapter 40 CertificatesZyWALL USG 300 User’s Guide548Figure 402 Certificate Details 4 Use a secure method to verify that the certificate owner has t
Chapter 40 CertificatesZyWALL USG 300 User’s Guide549The following table describes the labels in this screen. 40.6.1 My Certificates Add Screen Cl
Chapter 1 Introducing the ZyWALLZyWALL USG 300 User’s Guide551.3.2 Command-Line Interface (CLI)The CLI allows you to use text-based commands to conf
Chapter 40 CertificatesZyWALL USG 300 User’s Guide550Figure 404 Object > Certificate > My Certificates > AddThe following table describes t
Chapter 40 CertificatesZyWALL USG 300 User’s Guide551Organization Identify the company or group to which the certificate owner belongs. You can use u
Chapter 40 CertificatesZyWALL USG 300 User’s Guide552If you configured the My Certificate Create screen to have the ZyWALL enroll a certificate and th
Chapter 40 CertificatesZyWALL USG 300 User’s Guide553Figure 405 Object > Certificate > My Certificates > Edit The following table desc
Chapter 40 CertificatesZyWALL USG 300 User’s Guide554Type This field displays general information about the certificate. CA-signed means that a Certif
Chapter 40 CertificatesZyWALL USG 300 User’s Guide55540.6.3 My Certificate Import Screen Click Object > Certificate > My Certificates > Imp
Chapter 40 CertificatesZyWALL USG 300 User’s Guide556The following table describes the labels in this screen. 40.7 Trusted Certificates Screen Cli
Chapter 40 CertificatesZyWALL USG 300 User’s Guide55740.8 Trusted Certificates Edit Screen Click Object > Certificate > Trusted Certificates a
Chapter 40 CertificatesZyWALL USG 300 User’s Guide558Figure 408 Object > Certificate > Trusted Certificates > Edit The following table desc
Chapter 40 CertificatesZyWALL USG 300 User’s Guide559Refresh Click Refresh to display the certification path.Enable X.509v3 CRL Distribution Points a
Chapter 1 Introducing the ZyWALLZyWALL USG 300 User’s Guide56" It is recommended you use the shutdown command before turning off the ZyWALL.When
Chapter 40 CertificatesZyWALL USG 300 User’s Guide56040.9 Trusted Certificates Import Screen Click Object > Certificate > Trusted Certificates
Chapter 40 CertificatesZyWALL USG 300 User’s Guide561Figure 409 Object > Certificate > Trusted Certificates > ImportThe following table de
Chapter 40 CertificatesZyWALL USG 300 User’s Guide562
ZyWALL USG 300 User’s Guide563CHAPTER 41 ISP AccountsUse ISP accounts to manage Internet Service Provider (ISP) account information for PPPoE/PPTP in
Chapter 41 ISP AccountsZyWALL USG 300 User’s Guide56441.3 ISP Account Edit The ISP Account Edit screen lets you add information about new accounts an
Chapter 41 ISP AccountsZyWALL USG 300 User’s Guide565Encryption MethodThis field is available if this ISP account uses the PPTP protocol. Use the dro
Chapter 41 ISP AccountsZyWALL USG 300 User’s Guide566
ZyWALL USG 300 User’s Guide567CHAPTER 42 SSL ApplicationThis chapter describes how to configure SSL application objects for use in SSL VPN.42.1 SSL
Chapter 42 SSL ApplicationZyWALL USG 300 User’s Guide568The following table describes the labels in this screen. 42.3 Creating/Editing an SSL Applic
Chapter 42 SSL ApplicationZyWALL USG 300 User’s Guide569The following table describes the labels in this screen. 42.3.2 Example: Specifying a Web S
ZyWALL USG 300 User’s Guide57CHAPTER 2 Features and ApplicationsThis chapter introduces the main features and applications of the ZyWALL.2.1 Feature
Chapter 42 SSL ApplicationZyWALL USG 300 User’s Guide5707 Click Apply to save the settings. The configuration screen should look similar to the follow
Chapter 42 SSL ApplicationZyWALL USG 300 User’s Guide571" You must then configure the shared folder on the file server for remote access. Refer
Chapter 42 SSL ApplicationZyWALL USG 300 User’s Guide572
573PART VISystemSystem (575)Service Control (587)
ZyWALL USG 300 User’s Guide575CHAPTER 43 SystemThis chapter provides information on the general system screens. See Chapter 44 on page 587 for detai
Chapter 43 SystemZyWALL USG 300 User’s Guide57643.3 Time and Date This section shows you how:1 To manually set the ZyWALL date and time.2 To get the
Chapter 43 SystemZyWALL USG 300 User’s Guide577Manual Select this radio button to enter the time and date manually. If you configure a new time and d
Chapter 43 SystemZyWALL USG 300 User’s Guide57843.3.1 Pre-defined NTP Time Servers ListWhen you turn on the ZyWALL for the first time, the date and t
Chapter 43 SystemZyWALL USG 300 User’s Guide579Figure 418 Synchronization in ProcessThe Current Time and Current Date fields will display the appro
Chapter 2 Features and ApplicationsZyWALL USG 300 User’s Guide58Intrusion Detection and Prevention (IDP)IDP (Intrusion Detection and Protection) can d
Chapter 43 SystemZyWALL USG 300 User’s Guide580Figure 419 System > Console Port SpeedThe following table describes the labels in this screen. 43.
Chapter 43 SystemZyWALL USG 300 User’s Guide581Figure 420 System > DNSThe following table describes the labels in this screen. Table 200 Syst
Chapter 43 SystemZyWALL USG 300 User’s Guide582DNS Server This is the IP address of a DNS server. This field displays N/A if you have the ZyWALL get a
Chapter 43 SystemZyWALL USG 300 User’s Guide58343.5.4 Address Record An address record contains the mapping of a fully qualified domain name (FQDN)
Chapter 43 SystemZyWALL USG 300 User’s Guide58443.5.7 Domain Zone Forwarder A domain zone forwarder contains a DNS server’s IP address. The ZyWALL ca
Chapter 43 SystemZyWALL USG 300 User’s Guide58543.5.9 MX Record A MX (Mail eXchange) record indicates which host is responsible for the mail for a p
Chapter 43 SystemZyWALL USG 300 User’s Guide586The following table describes the labels in this screen. 43.6 Language Screen Click System > Langu
ZyWALL USG 300 User’s Guide587CHAPTER 44 Service ControlThis chapter covers controlling access to the ZyWALL.44.1 Service Control OverviewUse this
Chapter 44 Service ControlZyWALL USG 300 User’s Guide58844.1.1 Service Access LimitationsA service cannot be used to access the ZyWALL when:1 You hav
Chapter 44 Service ControlZyWALL USG 300 User’s Guide589Figure 427 HTTP/HTTPS Implementation" If you disable HTTP in the WWW screen, then the
Chapter 2 Features and ApplicationsZyWALL USG 300 User’s Guide592.2.1 Interface to Interface (Through ZyWALL)Ethernet -> VLAN -> Encap -> A
Chapter 44 Service ControlZyWALL USG 300 User’s Guide590Figure 428 System > WWWThe following table describes the labels in this screen. Table 20
Chapter 44 Service ControlZyWALL USG 300 User’s Guide591Admin/User Service ControlAdmin Service Control specifies from which zones an administrator c
Chapter 44 Service ControlZyWALL USG 300 User’s Guide59244.4 Service Control Rules Click Add or Edit in the Service Control table in a WWW, SSH, Teln
Chapter 44 Service ControlZyWALL USG 300 User’s Guide59344.5.1 Internet Explorer Warning MessagesWhen you attempt to access the ZyWALL HTTPS server,
Chapter 44 Service ControlZyWALL USG 300 User’s Guide594Figure 431 Security Certificate 1 (Netscape)Figure 432 Security Certificate 2 (Netscape)44
Chapter 44 Service ControlZyWALL USG 300 User’s Guide59544.5.4 Login ScreenAfter you accept the certificate, the ZyWALL login screen appears. The lo
Chapter 44 Service ControlZyWALL USG 300 User’s Guide596Figure 435 CA Certificate Example2 Click Install Certificate and follow the wizard as shown
Chapter 44 Service ControlZyWALL USG 300 User’s Guide5972 The file name and path of the certificate you double-clicked should automatically appear in
Chapter 44 Service ControlZyWALL USG 300 User’s Guide598Figure 439 Personal Certificate Import Wizard 45 Click Finish to complete the wizard and beg
Chapter 44 Service ControlZyWALL USG 300 User’s Guide59944.5.6 Using a Certificate When Accessing the ZyWALL ExampleUse the following procedure to a
Document ConventionsZyWALL USG 300 User’s Guide6Icons Used in FiguresFigures in this User’s Guide may use the following generic icons. The ZyWALL icon
Chapter 2 Features and ApplicationsZyWALL USG 300 User’s Guide60Ethernet -> VLAN -> Encap -> ALG -> AC -> DNAT-> Routing -> FW -&
Chapter 44 Service ControlZyWALL USG 300 User’s Guide60044.6 SSH You can use SSH (Secure SHell) to securely access the ZyWALL’s command line interf
Chapter 44 Service ControlZyWALL USG 300 User’s Guide601The SSH client sends a connection request to the SSH server. The server identifies itself wit
Chapter 44 Service ControlZyWALL USG 300 User’s Guide602Figure 447 System > SSHThe following table describes the labels in this screen. Table 20
Chapter 44 Service ControlZyWALL USG 300 User’s Guide60344.7 Secure Telnet Using SSH ExamplesThis section shows two examples using a command interfa
Chapter 44 Service ControlZyWALL USG 300 User’s Guide6042 Enter “ssh –1 192.168.1.1”. This command forces your computer to connect to the ZyWALL using
Chapter 44 Service ControlZyWALL USG 300 User’s Guide605The following table describes the labels in this screen. 44.9 Configuring FTP You can uploa
Chapter 44 Service ControlZyWALL USG 300 User’s Guide606Figure 452 System > FTPThe following table describes the labels in this screen. Table 21
Chapter 44 Service ControlZyWALL USG 300 User’s Guide60744.10 SNMP Simple Network Management Protocol is a protocol used for exchanging management i
Chapter 44 Service ControlZyWALL USG 300 User’s Guide608• Set - Allows the manager to set values for object variables within an agent. • Trap - Used b
Chapter 44 Service ControlZyWALL USG 300 User’s Guide609The following table describes the labels in this screen. 44.11 Dial-in ManagementConnect an
Chapter 2 Features and ApplicationsZyWALL USG 300 User’s Guide61With reverse proxy mode, remote users can easily access any web-based applications on
Chapter 44 Service ControlZyWALL USG 300 User’s Guide61044.11.1 a managementAT Command StringsFor regular telephone lines, the default Dial string te
Chapter 44 Service ControlZyWALL USG 300 User’s Guide61144.13 Vantage CNM Vantage CNM (Centralized Network Management) is a browser-based global man
Chapter 44 Service ControlZyWALL USG 300 User’s Guide612The following table describes the labels in this screen. Table 214 System > Vantage CNMLA
613PART VIIMaintenance & TroubleshootingFile Manager (615)Logs (625)Reports (637)Diagnostics (647)Reboot (649)Troubleshooting (651)
ZyWALL USG 300 User’s Guide615CHAPTER 45 File ManagerThis chapter covers how to use the ZyWALL’s File Manager screens to handle the ZyWALL’s configur
Chapter 45 File ManagerZyWALL USG 300 User’s Guide616While configuration files and shell scripts have the same syntax, the ZyWALL applies configuratio
Chapter 45 File ManagerZyWALL USG 300 User’s Guide617Lines 1 and 2 are comments. Line 5 exits sub command mode. 45.1.2 Errors in Configuration Files
Chapter 45 File ManagerZyWALL USG 300 User’s Guide618You can change the way the startup-config.conf file is applied. Include the setenv-startup stop-o
Chapter 45 File ManagerZyWALL USG 300 User’s Guide619The following table describes the labels in this screen. Table 216 Maintenance > File Mana
Chapter 2 Features and ApplicationsZyWALL USG 300 User’s Guide62Figure 6 Applications: User-Aware Access Control2.3.4 Multiple WAN InterfacesSet up
Chapter 45 File ManagerZyWALL USG 300 User’s Guide62045.3 Firmware Package Screen Click Maintenance > File Manager > Firmware Package to open t
Chapter 45 File ManagerZyWALL USG 300 User’s Guide621The ZyWALL’s firmware package cannot go through the ZyWALL when you enable the anti-virus Destro
Chapter 45 File ManagerZyWALL USG 300 User’s Guide622Figure 462 Firmware Upload In ProcessThe ZyWALL automatically restarts in this time causing a t
Chapter 45 File ManagerZyWALL USG 300 User’s Guide623Figure 465 Maintenance > File Manager > Shell Script Each field is described in the foll
Chapter 45 File ManagerZyWALL USG 300 User’s Guide624Rename Use this button to change the label of a shell script file on the ZyWALL. You cannot renam
ZyWALL USG 300 User’s Guide625CHAPTER 46 LogsThis chapter provides general information about the ZyWALL’s log feature. See Appendix B on page 661 fo
Chapter 46 LogsZyWALL USG 300 User’s Guide626Figure 468 Maintenance > Log > View LogIf an event generates log messages and alerts, it is displ
Chapter 46 LogsZyWALL USG 300 User’s Guide627The Web configurator saves the filter settings if you leave the View Log screen and return to it later.4
Chapter 46 LogsZyWALL USG 300 User’s Guide628For alerts, the Log Settings tab controls which events generate alerts and where alerts are e-mailed.The
Chapter 46 LogsZyWALL USG 300 User’s Guide62946.3.1 Log Settings Edit E-mail The Log Settings Edit screen controls the detailed settings for each lo
Chapter 2 Features and ApplicationsZyWALL USG 300 User’s Guide63Figure 8 Applications: Device HA
Chapter 46 LogsZyWALL USG 300 User’s Guide630Figure 470 Maintenance > Log > Log Setting > E-mail > Edit
Chapter 46 LogsZyWALL USG 300 User’s Guide631The following table describes the labels in this screen. Table 222 Maintenance > Log > Log Setti
Chapter 46 LogsZyWALL USG 300 User’s Guide63246.3.2 Log Settings Edit syslog The Log Settings Edit screen controls the detailed settings for each log
Chapter 46 LogsZyWALL USG 300 User’s Guide633Figure 471 Maintenance > Log > Log Setting > Remote Server > Edit
Chapter 46 LogsZyWALL USG 300 User’s Guide634The following table describes the labels in this screen. 46.3.3 Active Log Summary The Active Log Summa
Chapter 46 LogsZyWALL USG 300 User’s Guide635Figure 472 Active Log SummaryThis screen provides a different view and a different way of indicating w
Chapter 46 LogsZyWALL USG 300 User’s Guide636Selection Select what information you want to log from each Log Category (except All Logs; see below). Ch
ZyWALL USG 300 User’s Guide637CHAPTER 47 ReportsThis chapter provides information about the report screens.47.1 Traffic ScreenClick Maintenance >
Chapter 47 ReportsZyWALL USG 300 User’s Guide638Figure 473 Maintenance > Report > TrafficThere is a limit on the number of records shown in th
Chapter 47 ReportsZyWALL USG 300 User’s Guide639Traffic Type Select the type of report to display. Choices are:Host IP Address/User - displays the IP
Chapter 2 Features and ApplicationsZyWALL USG 300 User’s Guide64
Chapter 47 ReportsZyWALL USG 300 User’s Guide640The following table displays the maximum number of records shown in the report, the byte count limit,
Chapter 47 ReportsZyWALL USG 300 User’s Guide641Figure 474 Maintenance > Report > SessionThe following table describes the labels in this scr
Chapter 47 ReportsZyWALL USG 300 User’s Guide64247.3 Anti-Virus Report ScreenClick Maintenance > Report > Anti-Virus to display the following s
Chapter 47 ReportsZyWALL USG 300 User’s Guide643The statistics display as follows when you display the top entries by source.Figure 476 Maintenance
Chapter 47 ReportsZyWALL USG 300 User’s Guide644Figure 478 Maintenance > Report > IDP: Signature Name The following table describes the labels
Chapter 47 ReportsZyWALL USG 300 User’s Guide645The statistics display as follows when you display the top entries by source.Figure 479 Maintenance
Chapter 47 ReportsZyWALL USG 300 User’s Guide646
ZyWALL USG 300 User’s Guide647CHAPTER 48 DiagnosticsThis chapter covers how to use the Diagnostics screen. 48.1 DiagnosticsThe Diagnostics screen
Chapter 48 DiagnosticsZyWALL USG 300 User’s Guide648
ZyWALL USG 300 User’s Guide649CHAPTER 49 RebootUse this to restart the device (for example, if the device begins behaving erratically). See also Sect
ZyWALL USG 300 User’s Guide65CHAPTER 3 Web ConfiguratorThe ZyWALL web configurator allows easy ZyWALL setup and management using an Internet browser.
Chapter 49 RebootZyWALL USG 300 User’s Guide650
ZyWALL USG 300 User’s Guide651CHAPTER 50 TroubleshootingThis chapter offers some suggestions to solve problems you might encounter. V I cannot set up
Chapter 50 TroubleshootingZyWALL USG 300 User’s Guide652The ZyWALL’s firmware package cannot go through the ZyWALL when you enable the anti-virus Dest
653PART VIIIAppendices and IndexProduct Specifications (655)Common Services (701)Displaying Anti-Virus Alert Messages in Windows (705)Open Software
ZyWALL USG 300 User’s Guide655APPENDIX A Product SpecificationsThe following specifications are subject to change without notice. See Chapter 2 on pa
Appendix A Product SpecificationsZyWALL USG 300 User’s Guide656Table 233 Feature Specifications VERSION #FEATUREV2.00# of MAC
Appendix A Product SpecificationsZyWALL USG 300 User’s Guide657Service Groups 200Schedule Objects 128ISP Accounts 16Maximum Number of LDAP Groups 8Ma
Appendix A Product SpecificationsZyWALL USG 300 User’s Guide658The following table, which is not exhaustive, lists standards referenced by ZyWALL feat
Appendix A Product SpecificationsZyWALL USG 300 User’s Guide659Built-in service, SNMP agent RFCs 1067, 1213, 2576, 2578, 2579, 2580, 2741, 2667, 2981
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide66Figure 9 Login Screen 3 Type the user name (default: “admin”) and password (default: “1234”)
Appendix A Product SpecificationsZyWALL USG 300 User’s Guide660
ZyWALL USG 300 User’s Guide661APPENDIX B Log DescriptionsThis appendix provides descriptions of example log messages. Table 235 Content Filter L
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide662%s: Service is unavailableContent filter rating service is temporarily unavailable and access
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide663 Table 238 User LogsLOG MESSAGE DESCRIPTION%s %s has logged in from %sThe specified user s
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide664 Table 239 myZyXEL.com LogsLOG MESSAGE DESCRIPTIONSend registration message to MyZyXEL.com
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide665Service expiration check has succeeded.The service expiration day check was successful.Servi
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide666Update server is busy now. File download after %d seconds.The update server was busy so the d
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide667Do expiration daily-check has failed. Because of lack must fields.The device received an inc
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide668 Certification verification failed: Depth: %d, Error Number(%d):%s.Verification of a server’s
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide669IDP service standard license is expired. Update signature failed.IDP service standard licen
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide67Follow the directions in this screen. If you change the default password, the Login screen (Fi
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide670IDP off-line update failed. File damaged.IDP signature off-line update failed. Signature file
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide671 IDP signature update failed. Invalid signature content.IDP signature update failed. Sigquer
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide672System fatal error: 60018009.Error when do ioctl L7_ACTION_IOCTL_ADDR_USAGE.System fatal erro
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide673 App Patrol Name=%s Type=%s %s=%d Protocol=%s Action=%sPackets logging. 1st %s: Protocol Nam
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide674[SA] : Tunnel [%s] Phase 1 authentication algorithm mismatch%s is the tunnel name. When negot
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide675Cannot resolve My IP Addr %s for Tunnel [%s]1st %s is my ip address. 2nd %s is the tunnel na
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide676The cookie pair is : 0x%08x%08x / 0x%08x%08xIndicates the initiator/responder cookie pair.The
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide677 Tunnel [%s:%s] Sending IKE requestThe variables represent the phase 1 name and tunnel name
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide678 Table 244 Firewall LogsLOG MESSAGE DESCRIPTIONpriority:%lu, from %s to %s, service %s, %
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide679Cannot get handle from UAM, user-aware PR is disabledUser-aware policy routing is disabled d
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide68The icons provide the following functions.3.3.2 Navigation PanelUse the menu items on the navi
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide680 Table 247 Built-in Services LogsLOG MESSAGE DESCRIPTIONUser on %u.%u.%u.%u has been denied
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide681Console baud has been changed to %s.An administrator changed the console port baud rate.%s i
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide682The default record of Zone Forwarder have reached the maximum number of 128 DNS servers.The d
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide683 Access control rule %d of %s was moved to %d.An access control rule was moved successfully.
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide684Receive an ARP response from an unknown clientThe device received an ARP response from an unk
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide685Update the profile %s has failed because the FQDN %s is not under your control.The owner of
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide686Update the profile %s has failed because Custom IP was empty.The DDNS profile's IP selec
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide687 DDNS has been enabled by Device-HA.DDNS is enabled by Device-HA, because one of VRRP groups
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide688 Can't get remote address of %s interfaceThe connectivity check process can't get r
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide689Master configuration is the same with Backup. Skip updating it.The System Startup configurat
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide69Routing Policy Route Use this screen to create and manage routing policies.Static Route Use th
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide690Device HA authentication type for VRRP group %s maybe wrong.A VRRP group’s Authentication Typ
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide691 Table 251 Routing Protocol LogsLOG MESSAGE DESCRIPTIONRIP on interface %s has been stoppe
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide692RIP md5 authentication id and key have been deleted.RIP md5 authentication id and key have be
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide693 Invalid OSPF virtual-link %s authentication of area %s.Virtual-link %s authentication has b
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide694 Register H.323 ALG extra port=%d failed.H323 ALG apply additional signal port failed.%d: Por
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide695Import X509 certificate "%s" into My Certificate successfullyThe device imported a
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide696 Export X509 certificate "%s" from "My Certificate" failedThe device was
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide697 27 Path was not verified.28 Maximum path length reached.Table 254 Interface LogsLOG MESSA
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide698%s MTU > (%s MTU - 8), %s may not work correctly.An administrator configured a PPP interfa
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide699 Interface %s is disconnected.A PPP or AUX interface disconnected successfully. %s: interfa
Safety WarningsZyWALL USG 300 User’s Guide7Safety Warnings1 For your safety, be sure to read and follow all warning notices and instructions.• Do NOT
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide70IDP General Use this screen to look at and manage IDP bindings.Profile Use this screen to creat
Appendix B Log DescriptionsZyWALL USG 300 User’s Guide700 Table 257 Force Authentication LogsLOG MESSAGE DESCRIPTIONForce User Authentication will
ZyWALL USG 300 User’s Guide701APPENDIX C Common ServicesThe following table lists some commonly-used services and their associated protocols and port
Appendix C Common ServicesZyWALL USG 300 User’s Guide702FTP TCPTCP2021File Transfer Program, a program to enable fast transfer of files, including lar
Appendix C Common ServicesZyWALL USG 300 User’s Guide703RTSP TCP/UDP 554 The Real Time Streaming (media control) Protocol (RTSP) is a remote control
Appendix C Common ServicesZyWALL USG 300 User’s Guide704
ZyWALL USG 300 User’s Guide705APPENDIX D Displaying Anti-Virus AlertMessages in WindowsWith the anti-virus packet scan, when a virus is detected, you
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 300 User’s Guide706Figure 484 Windows XP: Starting the Messenger Service 3 Clos
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 300 User’s Guide707Figure 486 Windows 2000: Starting the Messenger Service 3 C
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 300 User’s Guide708Figure 489 Windows 98 SE: Task Bar Properties 3 Double-c
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 300 User’s Guide709Figure 491 Windows 98 SE: Startup: Create Shortcut 6 Spec
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide713.3.3 Main WindowThe main window shows the screen you select in the menu. It is discussed in
Appendix D Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 300 User’s Guide710Figure 493 Windows 98 SE: Startup: Shortcut " The
ZyWALL USG 300 User’s Guide711APPENDIX E Importing CertificatesThis appendix shows importing certificates examples using Netscape Navigator and Inter
Appendix E Importing CertificatesZyWALL USG 300 User’s Guide712Figure 495 Login Screen2 Click Install Certificate to open the Install Certificate wi
Appendix E Importing CertificatesZyWALL USG 300 User’s Guide713Figure 497 Certificate Import Wizard 14 Select where you would like to store the cer
Appendix E Importing CertificatesZyWALL USG 300 User’s Guide714Figure 499 Certificate Import Wizard 36 Click Yes to add the ZyWALL certificate to t
Appendix E Importing CertificatesZyWALL USG 300 User’s Guide715Figure 501 Certificate General Information after Import
Appendix E Importing CertificatesZyWALL USG 300 User’s Guide716
ZyWALL USG 300 User’s Guide717APPENDIX F Open Software AnnouncementsNotice Information herein is subject to change without notice. Companies, names,
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide718" This Product includes Netkit Telnet -0.17 software under the Netkit Telnet
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide719" This Product includes expat-1.95.6 software under the Expat LicenseExpat L
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide723.3.4 Message BarCheck the message bar when you click Apply or OK to verify that the configura
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide720" This Product includes openssl-0.9.8d-ocf software under the OpenSSL License
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide721OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide722" This Product includes libevent-1.1a and xinetd-2.3.14 software under the a
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide723The ISC license for bind is:Copyright (c) 1993-1999 by Internet Software Consorti
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide724Apache LicenseVersion 2.0, January 2004http://www.apache.org/licenses/TERMS AND CO
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide7252. Grant of Copyright License. Subject to the terms and conditions of this Licens
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide7266. Trademarks. This License does not grant permission to use the trade names, trad
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide727Products derived from this software may not be called "Apache", nor may
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide728This license, the Lesser General Public License, applies to some specially designa
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide729For example, on rare occasions, there may be a special need to encourage the wide
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide73Figure 14 CLI MessagesClick Change Display Style to show or hide the index numbers for the c
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide7302. You may modify your copy or copies of the Library or any portion of it, thus fo
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide731However, linking a "work that uses the Library" with the Library create
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide732It may happen that this requirement contradicts the license restrictions of other
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide73312. If the distribution and/or use of the Library is restricted in certain countr
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide734" This Product includes bridge-utils, dhcpcd-1.3.22-pl4, rp-pppoe-3.5, vlan-1
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide735TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION0. This License ap
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide736right to control the distribution of derivative or collective works based on the P
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide7377. If, as a consequence of a court judgment or allegation of patent infringement
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide738FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANC
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide739AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (I
Chapter 3 Web ConfiguratorZyWALL USG 300 User’s Guide74
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide740THIS SOFTWARE IS PROVIDED BY THE OPENLDAP FOUNDATION AND ITS CONTRIBUTORS ``AS IS&
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide7412.1 GUBUSOFT hereby grants Customer the following non-exclusive, non-transferable
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide742Defensive Suspension. If Customer commences or participates in any legal proceedin
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide743" This Product includes overLIB software under the overLIB License (Artistic
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide744make other distribution arrangements with the Copyright Holder. You may distribute
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide745BY EXERCISING ANY RIGHTS TO THE WORK PROVIDED HERE, YOU ACCEPT AND AGREE TO BE BO
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide746ii.Mechanical Rights and Statutory Royalties. Licensor waives the exclusive right
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide7475. Representations, Warranties and DisclaimerUNLESS OTHERWISE MUTUALLY AGREED TO
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide748e.This License constitutes the entire agreement between the parties with respect t
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide749You have no ownership rights in the Software. Rather, you have a license to use
ZyWALL USG 300 User’s Guide75CHAPTER 4 Wizard SetupThis chapter provides information on configuring the Wizard setup screens in the web configurator.
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide750THE WAIVER OR EXCLUSION OF IMPLIED WARRANTIES SO THEY MAY NOT APPLY TO YOU. IF TH
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide751This License Agreement is effective until it is terminated. You may terminate th
Appendix F Open Software AnnouncementsZyWALL USG 300 User’s Guide752
ZyWALL USG 300 User’s Guide753APPENDIX G Legal InformationCopyrightCopyright © 2007 by ZyXEL Communications Corporation.The contents of this publicat
Appendix G Legal InformationZyWALL USG 300 User’s Guide754FCC WarningThis device has been tested and found to comply with the limits for a Class A dig
Appendix G Legal InformationZyWALL USG 300 User’s Guide755NoteRepair or replacement, as provided under this warranty, is the exclusive remedy of the
Appendix G Legal InformationZyWALL USG 300 User’s Guide756
ZyWALL USG 300 User’s Guide757APPENDIX H Customer SupportRequired Information• Product model and serial number.• Warranty Information.• Date that you
Appendix H Customer SupportZyWALL USG 300 User’s Guide758Denmark• Support E-mail: [email protected]• Sales E-mail: [email protected]• Telephone: +45-39-55
Appendix H Customer SupportZyWALL USG 300 User’s Guide759• Telephone: +91-11-30888144 to +91-11-30888153• Fax: +91-11-30888149, +91-11-26810715• Web:
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide76Use VPN SETUP to configure a VPN connection. See Section 4.6 on page 95.Figure 15 Wizard Setup We
Appendix H Customer SupportZyWALL USG 300 User’s Guide760Norway• Support E-mail: [email protected] • Sales E-mail: [email protected]• Telephone: +47-22-80
Appendix H Customer SupportZyWALL USG 300 User’s Guide761• Telephone: +46-31-744-7700• Fax: +46-31-744-7701• Web: www.zyxel.se• Regular Mail: ZyXEL C
Appendix H Customer SupportZyWALL USG 300 User’s Guide762
IndexZyWALL USG 300 User’s Guide763IndexNumerics3DES 308AAAA servers 531and authentication methods 541and users 504LDAP Default 533LDAP Group 534LDAP
IndexZyWALL USG 300 User’s Guide764and virtual servers 268FTP 265H.323 265, 266peer-to-peer calls 268RTP 266See also VoIP pass through. 265SIP 265, 26
IndexZyWALL USG 300 User’s Guide765and policy routes 232behavior 382configured rate effect 383examples 384in application patrol 380interface, outbound
IndexZyWALL USG 300 User’s Guide766SSL 326console port 55speed 579content (pattern) 439content filtering 463, 464and address groups 463, 464, 467and a
IndexZyWALL USG 300 User’s Guide767and interfaces 183Domain Name System. See DNS.double-encoding 457DTR 610Dynamic Domain Name System. See DDNS.Dynami
IndexZyWALL USG 300 User’s Guide768and address objects 513and schedules 513prerequisites 123fragmentation flag 437fragmentation offset 437FTP 605addit
IndexZyWALL USG 300 User’s Guide769IDP 418Snort signatures 443statistics 643traffic directions 418updating signatures 173verifying custom signatures 4
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide77Figure 16 Internet Access: Step 1 The following table describes the labels in this screen.4
IndexZyWALL USG 300 User’s Guide770IP static routes. See static routes.IP stream identifier 434IP v4 packet headers 433IPSec 291basic troubleshooting
IndexZyWALL USG 300 User’s Guide771types of 625log options 409log options (IDP) 426logged in users 163logindefault settings 655SSL user 332logo 328log
IndexZyWALL USG 300 User’s Guide772and RIP 239and static routes 239and to-ZyWALL firewall 238area 0 239areas. See OSPF areas.authentication method 185
IndexZyWALL USG 300 User’s Guide773as VPN 211product registration 755profilesADP 448packet inspection 424protocolusage statistics 400protocol anomaly
IndexZyWALL USG 300 User’s Guide774Ssafety warnings 7same IP 438scanner types 404schedules 527and content filtering 463, 464, 467and current date/time
IndexZyWALL USG 300 User’s Guide775and address groups 602and address objects 602and certificates 602and zones 602client requirements 601encryption met
IndexZyWALL USG 300 User’s Guide776TT/TCP 458task bar properties 708TCP 521ACK (acknowledgment) 453ACK number 438connections 521port numbers 521SYN (s
IndexZyWALL USG 300 User’s Guide777and firewall 287and policy routes 230, 392, 394, 396, 398configuration overview 122user namesrules 507user portalSe
IndexZyWALL USG 300 User’s Guide778advantages 318and IPSec SA policy enforcement 320disadvantages 318VPN connectionsand address objects 296and policy
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide78IP Address Assignment: Select Auto If your ISP did not assign you a fixed IP address. Select Static
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide79Figure 18 Ethernet Encapsulation: StaticThe following table describes the labels in this screen.
Safety WarningsZyWALL USG 300 User’s Guide8
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide804.3.3 Step 2 Internet Access Ethernet You do not configure this screen if you selected Auto as the
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide81You can click Next and use the following screen to perform a basic registration (see Section 4.4 o
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide82The ZyWALL applies the configuration settings. Figure 21 PPPoE Encapsulation: Auto: FinishYou hav
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide83Figure 22 PPPoE Encapsulation: StaticThe following table describes the labels in this screen.Tab
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide844.3.6 Step 2 Internet Access PPPoE " Enter the Internet access information exactly as given t
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide85Figure 23 PPPoE Encapsulation: Static: FinishYou have set up your ZyWALL to access the Internet.
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide86Figure 24 PPTP Encapsulation: AutoThe following table describes the labels in this screen.Table 1
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide87The ZyWALL applies the configuration settings. Figure 25 PPTP Encapsulation: Auto: FinishYou hav
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide88" If you have not already done so, you can register your ZyWALL with myZyXEL.com and activate
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide894.3.9 Step 2 Internet Access PPTP " Enter the Internet access information exactly as given t
Contents OverviewZyWALL USG 300 User’s Guide9Contents OverviewIntroduction ...
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide90Type the Password associated with the user name. Select Nailed-Up if you do not want the connection
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide914.3.10 Step 4 Internet Access - Finish You have set up your ZyWALL to access the Internet. "
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide92Figure 28 RegistrationThe following table describes the labels in this screen. Table 13 Registr
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide93Figure 29 Registration: Registered Device4.5 Installation Setup, Two Internet Service Providers
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide94Figure 30 Internet Access: Step 1: First WAN InterfaceAfter you configure the First WAN Interface
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide95Figure 32 Internet Access: Finish " You can register your ZyWALL with myZyXEL.com and activ
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide96Click VPN SETUP in the Wizard Setup Welcome screen (Figure 15 on page 76) to open the following scr
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide974.7.1 VPN Express WizardClick the Express radio button as shown in Figure 33 on page 96 to displa
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide98Name: Type the name used to identify this VPN connection (and VPN gateway). You may use 1-31 alphan
Chapter 4 Wizard SetupZyWALL USG 300 User’s Guide994.8.1 VPN Express Wizard - Policy Setting The Policy Setting specifies which devices can use the
Comentários a estes Manuais