background image

54

Figure 51   

VPN Mode Screen

L2TP Configuration

If you have enabled L2TP over IPSec you must enter the following 
items:

1

In the 

IPSec Configuration 

field, enter 

This Gateway’s ID 

as an 

Internet IP address or name of the Gateway that you are 
configuring. This value is common across all IPSec connections 
but does not apply to PPTP connections. If PPTP only is enabled, 

This Gateway’s ID 

field disappears.

2

In the 

L2TP Configuration 

field, enter:

the 

Domain Name

 as an IP address. A Domain Name locates a 

website on the Internet.

The 

IPSec Shared Key

. This is the key for the connection and 

is a combination of letters, numbers and punctuation and can 
be up to 64 characters in length. 3Com recommends that the 
key and password are not the same. The user will need to 
know the IPSec Shared Key to enable connection.

In the 

Encryption Level 

field, choose either 

Allow DES tunnels 

or 

Allow 3DES tunnels

. 3DES is more secure but may take 

longer to encrypt and decrypt.

3DES is not shipped with the Gateway as standard due to 
international restrictions on encryption. If your country permits its 
use it can be downloaded from the 3Com web site at 

http://www.3com.com/

3

To set up the Gateway for L2TP over IPSec you must allocate IP 
addresses from the Gateway’s LAN for use with L2TP over IPSec. 
The connections made by L2TP over IPSec will appear to come 
from these addresses. The addresses must be in a continuous 
range. 

In the 

Address Pool for PPTP and L2TP clients

 field enter:

The first LAN address you wish to reserve for L2TP over IPSec 
in the 

First Remote IP Address 

field.

The last LAN address you wish to reserve for L2TP over IPSec 
in the 

Last Remote IP Address 

field.

If PPTP mode is selected, then the Address Pool is the same for 
PPTP and L2TP over IPSec clients.

These addresses must be within the Gateway’s LAN subnet and 
must not form part of the DHCP pool..

4

Click 

Apply 

to save your changes.

dua08 569-5aaa02.bo o k  Pag e 54  Thursday , No vem ber 7 , 2002  3:09 PM

Summary of Contents for OFFICE CONNECT CABLE/DSL SECURE GATEWAY...

Page 1: ...dua08 569 5aaa02 bo o k Pag e 1 T hursday No vem ber7 2002 3 09 PM ...

Page 2: ...gend provided on any licensed program or documentation contained in or delivered to you in conjunction with this User Guide Unless otherwise indicated 3Com registered trademarks are registered in the United States and may or may not be registered in other countries 3Com the 3Com logo and OfficeConnect are registered trademarks of 3Com Corporation Intel and Pentium are registered trademarks of Inte...

Page 3: ...Connecting the Cable DSL Secure Gateway 17 Setting Up Your Computers 19 Obtaining an IP Address Automatically 19 Windows 2000 XP 19 Windows 95 98 ME 20 Macintosh OS 8 5 9 x 20 Disabling PPPoE and PPTP Client Software 20 Running the Setup Wizard 23 Accessing the Wizard 23 Setting the Password 24 Setting the Time Zone 25 Auto Configuration Settings 26 Internet Settings 26 Choosing your LAN Settings ...

Page 4: ... 67 Basic Connection Checks 67 Browsing to the Gateway Configuration Screens 67 Connecting to the Internet 68 Forgotten Password 68 Alert LED 69 Recovering from Corrupted Software 69 Frequently Asked Questions 70 Using Discovery 71 Running the Discovery Application 71 Windows Installation 95 98 2000 Me NT 71 IP Addressing 73 The Internet Protocol Suite 73 How does a Device Obtain an IP Address and...

Page 5: ...eise 79 Consignes importantes de sécurité 80 End User Software Licence Agreement 83 3Com Corporation END USER SOFTWARE LICENSE AGREEMENT 83 ISP Information 85 Information Regarding Popular ISPs 85 Glossary 87 Index 93 Regulatory Notices 99 dua08 569 5aaa02 bo o k Pag e 5 T hursday No vem ber7 2002 3 09 PM ...

Page 6: ...6 dua08 569 5aaa02 bo o k Pag e 6 T hursday No vem ber7 2002 3 09 PM ...

Page 7: ...isted Pair Cables are referred to as Twisted Pair Cables throughout this guide Conventions Table 1 and Table 2 list conventions that are used throughout this guide Table 1 Notice Icons Icon Notice Type Description Information note Information that describes important features or instructions Caution Information that alerts you to potential loss of data or potential damage to an application system ...

Page 8: ...ty Information sheet Related Documentation In addition to this guide each OfficeConnect Cable DSL Secure Gateway document set includes one Installation Guide This guide contains the instructions you need to install and configure your Cable DSL Secure Gateway Product Registration You can now register your OfficeConnect Cable DSL Secure Gateway on the 3Com web site and receive up to date information...

Page 9: ...re Gateway is designed to provide a cost effective means of sharing a single broadband Internet connection amongst several computers The Gateway also increases your network security by acting as a firewall preventing unauthorised external access to your network and by creating Virtual Private Networks VPNs encrypted links to other private networks The example in Figure 1 shows a network connected ...

Page 10: ... Server redirection to enable remote access to Web FTP and other services on your network Provides firewall protection against Internet hacker attacks Implements Stateful Packet Inspection to block network intrusions Blocks Denial of Service attacks by using pattern detection Supports Virtual Private Networks VPNs Initiates and terminates IPSec connections Terminates PPTP and L2TP over IPSec conne...

Page 11: ...ct your retailer Minimum System and Component Requirements Your OfficeConnect Cable DSL Secure Gateway requires that the computer s and components in your network be configured with at least the following A computer with an operating system that supports TCP IP networking protocols for example Windows 95 98 NT Me 2000 XP Unix Mac OS 8 5 or higher An Ethernet 10 Mbps or 10 100 Mbps NIC for each com...

Page 12: ...The Gateway will then enter the start up sequence and resume normal operation See Recovering from Corrupted Software on page 69 On for 2 seconds and then off The Gateway has detected and prevented a hacker from attacking your network from the Internet Continuously on A fault has been detected with your Gateway during the start up process See Troubleshooting on page 67 The Alert LED will be on for ...

Page 13: ...Panel 5 Power Adapter socket Only use the power adapter that is supplied with this Gateway Do not use any other adapter 6 Ethernet Cable DSL port Use the supplied patch cable to connect the Gateway to the 10 100 port on your cable or DSL modem This port will automatically adjust for the correct speed duplex and cable type You can connect your Cable DSL modem using either straight through or crosso...

Page 14: ...14 dua08 569 5aaa02 bo o k Pag e 14 T hursday No vem ber7 2002 3 09 PM ...

Page 15: ...nsignes importantes de sécurité avant de mettre en route When positioning your Gateway ensure It is out of direct sunlight and away from sources of heat Cabling is away from power lines fluorescent lighting fixtures and sources of electrical noise such as radios transmitters and broadband amplifiers Water or moisture cannot enter the case of the unit Air flow around the unit and through the vents ...

Page 16: ...ress and Host Name for security purposes Static If your ISP allocates fixed or static IP information you need the following information PPPoE User Name PPPoE Password PPPoE Service Name Host Name ____________________ ____________________ ____________________ ____________________ PPTP User Name PPTP Password PPTP Server Address ____________________ ____________________ _____ _____ _____ ____ MAC Ad...

Page 17: ...ateway s Ethernet Cable DSL port to your Cable DSL modem Ensure that your modem is connected to the Internet and switched on 2 Connect your computer to one of the 10 100 LAN ports on the Gateway 3 Connect the power adaptor to the Gateway and wait for the Alert LED to stop flashing Check that the Cable DSL Status LED is illuminated 4 Switch on your computer Once your computer is ready to use check ...

Page 18: ...18 dua08 569 5aaa02 bo o k Pag e 18 T hursday No vem ber7 2002 3 09 PM ...

Page 19: ...ddress Automatically Windows 2000 XP If you are using a Windows 2000 or Windows XP computer use the following procedure to change your TCP IP settings Windows XP specific instructions in brackets 1 From the Windows Start Menu select Settings Control Panel select Control Panel directly from the Start menu in Windows XP 2 Double click on Network and Dial Up Connections Network and Internet Connectio...

Page 20: ...m the desktop select Apple Menu Control Panels and TCP IP 2 In the TCP IP control panel set Connect Via to Ethernet 3 In the TCP IP control panel set Configure to Using DHCP Server 4 Close the TCP IP dialog box and save your changes 5 Restart your computer Disabling PPPoE and PPTP Client Software If you have PPPoE or PPTP client software installed on your computer you will need to disable it To do...

Page 21: ...e with the Gateway Disabling Web Proxy Ensure that you do not have a web proxy enabled on your computer Go to the Control Panel and click on Internet Options Select the Connections tab and click on LAN Settings at the bottom Make sure that the Use Proxy Server option is unchecked dua08 569 5aaa02 bo o k Pag e 21 T hursday No vem ber7 2002 3 09 PM ...

Page 22: ...22 dua08 569 5aaa02 bo o k Pag e 22 T hursday No vem ber7 2002 3 09 PM ...

Page 23: ...your Gateway in to the location or address box of your browser Figure 9 The default URL for the gateway is http 192 168 1 1 If you have changed the IP address of the unit you should substitute this for the default address within the URL Figure 9 Web Browser Location Field Factory Default The Login screen as shown in Figure 10 should appear in your browser If it does not refer to Troubleshooting on...

Page 24: ...to continue You will now be guided through the setup of your Gateway Setting the Password When the Change Administration Password screen Figure 13 appears type the Old Password then a new password in both the New Password and Confirm Password fields The default password for the Gateway is admin It is case sensitive and must be entered as the Old Password the first time you configure the Gateway 3C...

Page 25: ...r local time 1 Select your time zone from the drop down menu 2 Check the Enable Daylight Saving box to automatically adjust the time seasonally 3 Click Next to continue To set the Gateway to World Time UTC 1 Select GMT Greenwich Mean Time from the drop down menu 2 Ensure that the Enable Daylight Saving box is cleared 3 Click Next to continue Figure 14 Time Zone Screen The Daylight Savings option a...

Page 26: ... settings manually continue at Internet Settings below If you chose one of the automatic configuration options continue at Choosing your LAN Settings on page 29 Internet Settings The Internet Settings window allows you to set up the Gateway for the type of Internet connection you have Before setting up your Internet connection mode have the modem configuration supplied by your ISP to hand Figure 1...

Page 27: ...e box blank 6 Click Next to continue Dynamic IP Address Mode To setup the Gateway for use with a dynamic IP address connection Figure 18 Hostname Screen 1 If your ISP requires the addresses of a Primary and Secondary DNS Server then enter them in the fields labelled Primary DNS Address and Secondary DNS Address If your ISP does not require one of the fields to be filled in then leave it blank This...

Page 28: ...L modem Otherwise click No 5 Click Next to continue Continue at Choosing your LAN Settings on page 30 PPPoE Mode To setup the gateway for use with a PPP over Ethernet PPPoE connection use the following procedure Figure 20 PPPoE Screen 1 Enter your PPP over Ethernet user name in the PPPoE User Name text box 2 Enter your PPP over Ethernet password in the PPPoE Password text box If your ISP does not ...

Page 29: ...User Name text box 3 Enter your PPTP password in the PPTP Password text box 4 Enter your primary DNS address in the Primary DNS Address text box 5 If your ISP provides a secondary DNS address enter it in the Secondary DNS Address text box otherwise leave the box blank 6 Check all your settings and then click Next Figure 22 displays 7 Click Next to continue Figure 22 PPTP IP Settings 8 IP settings ...

Page 30: ...eld This should be large enough to contain all your computers and other network devices The default 255 255 255 0 allows for 254 devices including the Gateway 3 If you are going to set up an IPSec VPN with another Gateway you must set your subnet mask to 255 255 255 0 See Configuring VPNs on page 53 Activating DHCP The Gateway contains a Dynamic Host Configuration DHCP server that can automaticall...

Page 31: ...will vary depending on the LAN settings entered in the LAN IP Address screen To disable DHCP select Do not enable the DHCP server Click Next when you have finished Viewing the Summary When you complete the Setup Wizard a configuration summary will display See Figure 25 below Verify the configuration information of the Gateway and click Finish to save your settings and restart the Gateway Figure 25...

Page 32: ...the settings you want to change and follow the instructions from that point Your Gateway is now configured You can start using your Gateway straight away or further configure your Gateway see Gateway Configuration on page 33 dua08 569 5aaa02 bo o k Pag e 32 T hursday No vem ber7 2002 3 09 PM ...

Page 33: ...bnet mask information set up DHCP server parameters and display the DHCP client list Internet Settings sets up Internet addressing modes such as PPPoE connection dynamic IP address allocation Network Address Translation NAT and static IP address settings Firewall allows configuration of the Gateway s firewall features Virtual Servers Special Applications PC Privileges and other general security op...

Page 34: ...l or if the LAN and Internet addresses or subnets conflicted Figure 27 Notice Board Screen Changing the Administration Password You should change the password to prevent unauthorized access to the Administration System Figure 28 Password Screen To change the password 1 Enter the current password in the Old Password field 2 Enter the new password in the New Password field 3 Enter the new password a...

Page 35: ...ngs DHCP client settings LAN IP Settings The Unit Configuration screen allows you to change the TCP IP settings of your Gateway and its DHCP server Figure 30 Unit Configuration Screen Changing the LAN Settings These settings will have been entered during the set up wizard when the device is first used You only need to change these if you reconfigure your network If you make any changes click Apply...

Page 36: ...o use the Gateway to control the permissions of individual machines on your network then you must use the Gateway s DHCP server to allocate addresses or use static addressing If you use another DHCP server you may get unexpected results See PC Privileges on page 47 To enable the DHCP Server ensure that the Enable check box is ticked To disable the DHCP Server ensure that the Enable check box is cl...

Page 37: ...resses in the DHCP Pool and you know of computers that are unlikely to connect to your network soon you can release the IP address allowing it to be reallocated to another machine If you have spare or expired IP addresses in the pool you will not need to release addresses The IP Address Host Name and MAC Address indicate the address that has been allocated They identify the machine by name and by ...

Page 38: ...ateway DNS address es 2 Dynamic IP Address DSL or Cable Dynamic IP addressing or DHCP automatically assigns the Gateway IP information This method is popular with Cable providers This method is also used if your modem has a built in DHCP server 3 PPPoE DSL only If the installation instructions that accompany your modem ask you to install a PPPoE client on your PC then select this option To configu...

Page 39: ...ill refresh with options relevant to that choice If you select Static IP address to be specified manually see Configuring a Static IP Address on page 40 If you select Dynamic IP address automatically allocated see Configuring a Dynamic IP Address on page 41 If you select PPPoE PPP over Ethernet see Configuring a PPPoE connection on page 42 If you select PPTP used by some European providers see Con...

Page 40: ...If you have been allocated a range of IP addresses by your ISP enter the first IP address in the range Subnet Mask The subnet mask supplied by your ISP for this connection ISP Gateway Address The Gateway address from your ISP to the Internet Primary DNS Address The address of your ISP s Domain Name Service server Secondary DNS Address The address of your ISP s secondary Domain Name Service server ...

Page 41: ...ay Address The gateway address from your ISP to the Internet is automatically configured but is not displayed Primary DNS Address The address of your ISP s Domain Name Service server is automatically configured and cannot be edited Secondary DNS Address The address of your ISP s secondary Domain Name Service server The second server is optionally provided by an ISP in case of failure of the primar...

Page 42: ...cify a service name for your connection Primary DNS Address The address of your ISP s Domain Name Service server is automatically configured and is not editable Secondary DNS Address The address of your ISP s secondary Domain Name Service server The second server is optionally provided by an ISP in case of failure of the primary server Host Name The Host Name of your computer may be required by yo...

Page 43: ...ry DNS Address The address of your ISP s secondary Domain Name Service server The second server is optionally provided by an ISP in case of failure of the primary server Maximum Idle Time The amount of time without activity before the Gateway terminates the Internet connection Initial IP Address and Initial Subnet Mask IP settings must be used when establishing a PPTP connection Alternatively if t...

Page 44: ...p all the addresses on your LAN to the Internet address of your Gateway To set up One to Many NAT 1 Select One to Many NAT from the NAT Mode drop down box 2 Click Apply to save your changes 192 168 1 100 172 16 57 52 192 168 1 101 172 16 57 53 192 168 1 102 172 16 57 54 192 168 1 100 192 168 1 101 172 16 57 52 192 168 1 102 One to Many NAT One to One NAT dua08 569 5aaa02 bo o k Pag e 44 T hursday ...

Page 45: ...in the First IP Address in ISP Pool field 3 Enter the first address in your LAN range of addresses to which you want to map this range in the First IP Address in LAN Pool field 3Com recommends that you set your DHCP pool to the same as the range of LAN addresses used as your LAN pool 4 Enter the number of addresses in the range into the Pool Size field 5 Click Apply to save your changes Configurin...

Page 46: ...ing a virtual server allows one or more of the computers on your network to function as an Internet service host For example one of your computers could be configured as an FTP host allowing others outside of your office network to download files of your choosing Or if you have created a Web site you can configure one of your computers as a Web server so that others can view your Web site If you a...

Page 47: ...the PC Privileges setup screen This is shown in Figure 44 below The Gateway s DHCP server has been enhanced to support PC Privileges If you want to use DHCP and control access to the Internet on a user by user basis then you must either use the Gateway s DHCP server or static addressing Figure 44 PC Privileges Screen Access from the local network to the Internet can be controlled on a PC by PC bas...

Page 48: ...llow in the except specify ports box and set the drop down box to Allow Enter the services that you wish to deny in the except specify ports box and set the drop down box to Deny Enter multiple ports as either a comma separated list e g 101 105 107 or as a range e g 101 107 5 Click Apply to save the settings To assign different access rights for different computers 1 Click the Control PC Access to...

Page 49: ...checked and that other check boxes are left cleared Set the Block or Allow other services drop down box to Block other services For the purposes of this example your users also need to access a test web server on port 8080 To allow this Enter the number 8080 in the except specify ports box Click Apply to save your changes and close the PC Privileges window VPN connections to other networks are una...

Page 50: ...e are two buttons outside the table Help displays the online help page for this screen New creates a new special application See Adding and Editing Special Applications below Adding and Editing Special Applications 1 Click on the New button to create a new special application or on the name of a special application to edit the settings for that application Figure 48 Special Application Settings Sc...

Page 51: ...ovider can provide you with this information CAUTION Selecting Multiple Hosts Allowed weakens the security that your Gateway s firewall is able to provide and should only be used if the special application requires it Timeout Enter the number of seconds the Gateway should wait for the first reply from the special application server before it abandons the connection The default Timeout is three sec...

Page 52: ... devices to ensure that everything is working correctly By default the Gateway has PING disabled so that it does not respond to PING requests This makes the device more diffi cult to find on the Internet and less prone to attack This feature is enabled by clicking on the check box so that a tick can be seen and then selecting Apply 3Com recommends that you leave Allow PING from the Internet disabl...

Page 53: ...e IPSec It is not as secure as IPSec but is easy to administrate PPTP does not support Gateway to Gateway connections and is only suitable for connecting remote users Enabling IPSec VPN will disable pass through to IPSec and L2TP IPSec Virtual Servers on the LAN Enabling L2TP over IPSec will disable pass through to IPSec and L2TP IPSec Virtual Servers on the LAN Enabling the PPTP server will disab...

Page 54: ...w 3DES tunnels 3DES is more secure but may take longer to encrypt and decrypt 3DES is not shipped with the Gateway as standard due to international restrictions on encryption If your country permits its use it can be downloaded from the 3Com web site at http www 3com com 3 To set up the Gateway for L2TP over IPSec you must allocate IP addresses from the Gateway s LAN for use with L2TP over IPSec T...

Page 55: ...r PPTP and L2TP over IPSec clients These addresses must be within the Gateway s LAN subnet and must not form part of the DHCP pool Click Apply to save your changes Viewing VPN Connections The VPN Connections Screen shows information about the IPSec L2TP over IPSec and PPTP connections made by the Gateway It also allows you to add delete edit and temporarily disable these connections Figure 52 VPN ...

Page 56: ...tion cannot therefore be activated until both ends of the tunnel have been configured Connection Name User Name the ID of the remote gateway the value entered in This Gateway s ID on the remote gateway or the remote user s login name This can be a name containing numbers and letters but no punctuation or an IP address but cannot be a domain name If the Connection Name is set using numeric IP addre...

Page 57: ...If your country permits its use it can be downloaded from the 3Com web site at http www 3com com Exchange keys using choose the encryption method used to exchange shared keys Diffie Hellman Group 2 is more secure but less common than Diffie Hellman Group 1 Use Perfect Forward Secrecy Choose whether to use perfect forward secrecy Using perfect forward secrecy will change the encryption keys during ...

Page 58: ... on encryption If your country permits its use it can be downloaded from the 3Com web site at http www 3com com Hash Algorithm choose either SHA 1 or MD5 from the drop down list Both ends of the connection must use the same value Exchange keys using choose the encryption method used to exchange shared keys Diffie Hellman Group 2 is more secure but less common than Diffie Hellman Group 1 Use Perfec...

Page 59: ...erver Address field a Enter 174 27 34 202 on Gateway One b Enter 172 19 201 162 on Gateway Two 8 Enter the IP address of the other LAN subnet in the Remote Network address field a Enter 192 168 2 0 on Gateway One b Enter 192 168 1 0 on Gateway Two 9 The Remote Subnet Mask is a default setting of 255 255 255 0 10 Enter a password in the Tunnel Shared Key field in both Gateways The example uses TYP0...

Page 60: ...me fields Click Apply to save your changes or Close to return without saving Editing IPSec Routes This screen allows you to add and replace networks in the existing IPSec Route See Figure 57 To do this 1 Select edit to display the Edit Route screen Figure 58 2 Click in the table and add a new Network and Subnet Mask entry 3 Click Apply to save your changes or Close to return without saving The gat...

Page 61: ...ure 59 Restart Pressing the Restart the Gateway button has the same effect as power cycling the unit No configuration information will be lost but the log files will be erased This function may be of use if you are experiencing problems and you wish to re establish your Internet connection Figure 59 Restart Screen dua08 569 5aaa02 bo o k Pag e 61 T hursday No vem ber7 2002 3 09 PM ...

Page 62: ... savings box and then click Apply Figure 60 Figure 60 Time Zone Screen The Gateway reads the correct time from NTP servers on the Internet and sets its system clock accordingly The Daylight Savings option automatically adjusts the clock to daylight savings time as appropriate to your time zone Loading and Saving the Gateway Configuration Figure 61 Configuration Screen Select the Configuration tab ...

Page 63: ...ay make available 3DES encryption is not shipped with the Gateway as standard due to international restrictions on encryption If your country permits its use it can be downloaded from the 3Com web site at http www 3com com Figure 62 Upgrade Screen Once you have downloaded the software use the Browse button to locate the file on your computer and then click on Apply You may need to change the file ...

Page 64: ...onnection Status to display the current unit status including a summary of the configuration See Figure 63 Log Settings to choose whether to store the log on the Gateway or to send to the remote user or both See Figure 64 If you choose the option to store the log on the Gateway the log file will be overwritten when it is full If you choose the option to send logs to a remote server then you will n...

Page 65: ...lecting Support Feedback on the main menu generates both The support links screen which contains a list of Internet links that provide information and support concerning the Gateway Figure 65 Figure 65 Support Screen dua08 569 5aaa02 bo o k Pag e 65 T hursday No vem ber7 2002 3 09 PM ...

Page 66: ... links screen which contains an Internet link to the 3Com website so that you can provide feedback on the product Figure 66 Figure 66 Feedback Screen dua08 569 5aaa02 bo o k Pag e 66 T hursday No vem ber7 2002 3 09 PM ...

Page 67: ...am may be available that can give you this information Refer to the documentation supplied with your NIC for details Ensure that you have configured your computer as described in Setting Up Your Computers on page 19 Restart your computer while it is connected to the Gateway to ensure that your computer receives an IP address When entering the address of the Gateway into your web browser ensure tha...

Page 68: ...k PC Privileges to see if you have allowed your PCs to connect to the Internet See PC Privileges on page 47 Forgotten Password If you can browse to the Gateway configuration screen but cannot log on because you do not know or have forgotten the password follow the steps below to reset the Gateway to it s factory default configuration Warning all your configuration changes will be lost and you will...

Page 69: ...y has detected a hacker attack from the Internet and has prevented it from harming your network You need take no specific action on this unless you decide that these attacks are happening frequently in which case you may wish to discuss this with your ISP The Gateway logs such attacks and this information is available through the configuration screens Recovering from Corrupted Software If the Aler...

Page 70: ...and switches connected to the Gateway 3Com OfficeConnect hubs and switches provide a simple reliable means of expanding your network contact your supplier for more information or visit http www 3com com Does the Gateway support virtual private networks VPNs The Gateway fully supports VPNs It is capable of Initiating and terminating IPSec connections Terminating L2TP over IPSec and PPTP connections...

Page 71: ...your computer A menu will appear select Gateway Discovery Discovery will find the Gateway even if it is unconfigured or misconfigured Figure 67 Discovery Welcome Screen 2 When the Welcome screen is displayed click on Next and wait until the application discovers the Gateways connected to your LAN Figure 68 Discovered Gateway In Figure 68 the serial number of the unit has been replaced with xxxxxx ...

Page 72: ...Highlight the Cable DSL Secure Gateway by clicking on it and press Next Figure 69 Discovery Finish Screen 4 Click on Finish to launch a web browser and display the login page for the Gateway dua08 569 5aaa02 bo o k Pag e 7 2 T hursday No vem ber7 2002 3 09 PM ...

Page 73: ...ks and a subnet mask is a number that enables a device to identify the sub network to which it is connected For your network to work correctly all devices on the network must have The same sub network address The same subnet mask The only value that will be different is the specific host device number This value must always be unique An example IP address is 192 168 100 8 However the size of the n...

Page 74: ...ch allows computers on your network to obtain an IP address and subnet mask automatically DHCP assigns a temporary IP address and subnet mask which gets reallocated once you disconnect from the network DHCP will work on any client Operating System such as Windows 95 Windows 98 or Windows NT 4 0 Also using DHCP means that the same IP address and subnet mask will never be duplicated for devices on t...

Page 75: ...Automatic IP addressing support was introduced by Microsoft in the Windows 98 operating system and is also supported in Windows 2000 Private IP Addresses The following address ranges have been reserved by the Internet Engineering Task Force IETF for private use 10 0 0 0 10 255 255 255 172 16 0 0 172 31 255 255 192 168 0 0 192 168 255 255 The Gateway has a default subnet of 192 168 1 0 192 168 1 25...

Page 76: ...76 dua08 569 5aaa02 bo o k Pag e 7 6 T hursday No vem ber7 2002 3 09 PM ...

Page 77: ...6 mm 1 4 in Weight Approximately 537 g 1 18 lbs Standards Functional ISO 8802 3 IEEE 802 3 Safety UL 60950 EN 60950 CSA 22 2 60950 IEC 60950 EMC EN 55022 Class B EN 55024 AS NZS 3548 B FCC Part 15 Class B ICES 003 Class B VCCI Class B CNS 13438 Class A Environmental EN 60068 IEC 68 Category 5 screened cables must be used to ensure compliance with the Class B requirements of this standard The use o...

Page 78: ...ay complies to the IEEE 802 3i u and x specifications Cable Specifications The Cable DSL Secure Gateway supports the following cable types and maximum lengths Category 3 Ethernet or Category 5 Fast Ethernet or Dual Speed Ethernet Twisted Pair shielded and unshielded cable types Maximum cable length of 100m 327 86 ft Category 5 cables are required for a 100BASE TX connection dua08 569 5aaa02 bo o k...

Page 79: ...ions WARNING There are no user replaceable fuses or user serviceable parts inside the Gateway If you have a physical problem with the unit that cannot be solved with problem solving actions in this guide contact your supplier WARNING Disconnect the power adapter before moving the unit WARNING RJ 45 ports These are shielded RJ 45 data sockets They cannot be used as telephone sockets Only connect RJ...

Page 80: ...ürfen nur RJ 45 Datenstecker angeschlossen werden Consignes importantes de sécurité AVERTISSEMENT Les avertissements présentent des consignes que vous devez respecter pour garantir votre sécurité personnelle Vous devez respecter attentivement toutes les consignes Nous vous demandons de lire attentivement les consignes suivantes de sécurité avant d installer ou de retirer l appareil AVERTISSEMENT F...

Page 81: ...t pas être résolu avec les actions de la résolution des problèmes dans ce guide contacter votre fournisseur AVERTISSEMENT Débranchez l adaptateur électrique avant de retirer cet appareil AVERTISSEMENT Ports RJ 45 Il s agit de prises femelles blindées de données RJ 45 Vous ne pouvez pas les utiliser comme prise de téléphone Branchez uniquement des connecteurs de données RJ 45 sur ces prises femelle...

Page 82: ...82 dua08 569 5aaa02 bo o k Pag e 8 2 T hursday No vem ber7 2002 3 09 PM ...

Page 83: ...ept as set forth above you may not assign or transfer your rights under this Agreement Modification reverse engineering reverse compiling or disassembly of the Software is expressly prohibited However if you are a European Union EU resident information necessary to achieve interoperability of the Software with other programs within the meaning of the EU Directive on the Legal Protection of Compute...

Page 84: ... illegal or unenforceable the validity legality and enforceability of any of the remaining provisions shall not in any way be affected or impaired and a valid legal and enforceable provision of similar intent and economic impact shall be substituted therefor ENTIRE AGREEMENT This Agreement sets forth the entire understanding and agreement between you and 3Com and supersedes all prior agreements wh...

Page 85: ...service name blank unless your ISP requires it Bell Century Tel Citizens Primus Prodigy Snet Sprint FC Verizon First World Brightnet Earthlink Ameritech Covad Mindspring Sympatico DSL USwest Qwest SNet Internet Connection Types Characteristics Popular ISPs PPTP Cable or DSL always on Some European ISPs require a PPTP tunnel to authenticate their network KPN Netherlands Austria Telecom Static DSL D...

Page 86: ...86 dua08 569 5aaa02 bo o k Pag e 8 6 T hursday No vem ber7 2002 3 09 PM ...

Page 87: ...ps the bandwidth of Fast Ethernet is 100 Mbps Category 3 Cables One of five grades of Twisted Pair TP cabling defined by the EIA TIA 586 standard Category 3 is voice grade cable and can only be used in Ethernet networks 10BASE T to transmit data at speeds of up to 10 Mbps Category 5 Cables One of five grades of Twisted Pair TP cabling defined by the EIA TIA 586 standard Category 5 can be used in E...

Page 88: ...ps over a variety of cables Ethernet Address See MAC address Fast Ethernet An Ethernet system that is designed to operate at 100 Mbps Firewall Electronic protection that prevents anyone outside of your network from seeing your files or damaging your computers Full Duplex A system that allows packets to be transmitted and received at the same time and in effect doubles the potential throughput of a...

Page 89: ...et Service Provider An ISP is a business that provides connectivity to the Internet for individuals and other businesses or organizations LAN Local Area Network A network of end stations such as PCs printers servers and network devices hubs and switches that cover a relatively small geographic area usually not larger than a floor or building LANs are characterized by high transmission speeds over ...

Page 90: ... jack Server A computer in a network that is shared by multiple end stations Servers provide end stations with access to shared network services such as computer files and printer queues Subnet Address An extension of the IP addressing scheme that allows a site to use a single IP network address for multiple physical networks Subnet mask A subnet mask which may be a part of the TCP IP information ...

Page 91: ...vement of data packets on a network VPN Virtual Private Network A VPN is a private network where the data is passed across a public network infrastructure such as the Internet The data is kept private by using encryption WAN Wide Area Network A network that connects computers located in geographically separate areas for example different buildings cities or countries The Internet is an example of ...

Page 92: ...92 dua08 569 5aaa02 bo o k Pag e 92 T hursday No vem ber7 2002 3 09 PM ...

Page 93: ...7 cable DSL status LED 13 category 3 cables 87 category 5 cables 87 changing the admin password 34 client 87 configuring computers 19 configuring the Gateway 33 configuring VPN 53 connecting the cable DSL modem 17 connecting to the Internet 38 Consignes importantes de sécurité 80 creating a virtual server 46 CSA statement 99 D data encryption standard 87 daylight saving 62 DES 87 DHCP 87 recording...

Page 94: ... statement 99 feedback 8 finding the Gateway 71 firewall 9 defined 88 disabling 52 settings 45 firmware upgrading 63 front panel diagram 12 full duplex 88 G Gateway changing the password 34 connecting the cable DSL modem 17 defined 88 firewall 9 installation information 15 positioning 15 powering up 17 restarting 61 Gateway configuration 33 Gateway to Gateway connection 58 getting help 33 giving f...

Page 95: ...atus 13 LAN status 12 power 12 loading Gateway configuration 62 local area network 89 login screen 23 logs viewing 64 M MAC address 89 Macintosh OS 8 5 9 x setting up 20 main menu accessing 33 media access control 89 multiple hosts 51 N NAT configuring 43 defined 89 network address remote 57 network address translation 43 89 network defined 90 network interface card defined 90 NIC defined 90 notic...

Page 96: ...leges setting 47 product registration 8 protocol defined 90 R rear panel diagram 13 recording DHCP settings 16 recording PPPoE settings 16 recording PPTP settings 16 recording static address settings 16 registration 8 remote network address 57 restarting the Gateway 61 restoring Gateway configuration 62 RJ 45 defined 90 S safety information 79 sample network diagram 9 saving Gateway configuration ...

Page 97: ...7 58 59 U upgrading firmware 63 UTC world time 25 V VCCI statement 99 viewing status and logs 64 virtual DMZ 46 virtual private network 91 virtual servers 45 creating 46 VPN configuring 53 defined 91 example 58 VPN mode 53 W WAN See wide area network web proxies disabling 21 Wichtige Sicherheitshinweise 79 wide area network 91 Windows 2000 XP setting up 19 Windows 95 98 ME setting up 20 wizard aut...

Page 98: ...98 dua08 569 5aaa02 bo o k Pag e 98 T hursday No vem ber7 2002 3 09 PM ...

Page 99: ...Relocate the equipment with respect to the receiver Move the equipment away from the receiver Plug the equipment into a different outlet so that equipment and receiver are on different branch circuits Consult the dealer or an experienced radio television technician for help The user may find the following booklet prepared by the Federal Communications Commission helpful How to Identify and Resolve...

Page 100: ...100 dua08 569 5aaa02 bo o k Pag e 100 T hursday No vem ber7 2002 3 09 PM ...

Page 101: ...dua08 569 5aaa02 bo o k Pag e 101 T hursday No vem ber7 2002 3 09 PM ...

Page 102: ...DUA08569 5AAA02 Published November 2002 dua08 569 5aaa02 bo o k Pag e 102 T hursday No vem ber7 2002 3 09 PM ...

Reviews: