background image

 

 
 
 
 
 

 
 
 

FriendlyNET

® 

VR2004 Series 

VPN Security Routers 

 
 
 
 

User’s Manual 

Summary of Contents for FriendlyNET VR2004 Series

Page 1: ...FriendlyNET VR2004 Series VPN Security Routers User s Manual ...

Page 2: ...thernet port or 10 100 Fast Ethernet network adapter for each computer sharing the Internet connection Cables 10BaseT or 100BaseTX Fast Ethernet cables to connect computers to the router Client operating system Client must be capable of accept ing an IP address from a DHCP server Supported operat ing systems include Apple Mac OS 9 and higher Microsoft Windows 98 ME 2000 XP Home or Professional Red...

Page 3: ... a working Internet connection using a Ca ble DSL modem First you must collect the TCP IP settings from your computer and your Internet Service Provider ISP This infor mation will be used to configure your new router and any additional computers you wish to add to your new network The following sec tions explain how to collect your TCP IP settings for Macintosh Windows and Linux platforms Mac OS 9...

Page 4: ...ernet card slot where your network card is installed 2 Click the Apply Now button The next screen will show the op tions for your network settings Be sure that the TCP IP tab is selected 3 Before changing your configuration complete the information in the Your Settings portion of the table below and save for fu ture reference Item No TCP IP Control Panel Description Your Setting 1 Configure Manual...

Page 5: ... button choose Run In the dialog box type winipcfg and click OK 2 Choose your computer s Ethernet adapter from the first drop down list Tip The PPP setting is usually for your dial up analog modem Don t choose this selection Item No TCP IP Control Panel Description Your Setting 1 Configure Manually or Using DHCP Server Static IP Address or Dynamic IP Address 2 IP Address WAN IP Address 3 Subnet Ma...

Page 6: ...lick OK 8 Click OK again Windows will begin copying files to your com puter Click Yes to restart your computer with the new settings Repeat steps 1 3 and 5 8 to configure additional PCs on your net work Note Keep your Windows CD handy You may be asked to insert it so that Windows can copy necessary files Windows NT 2000 1 From the Windows Start button choose Run In the dialog box type command and ...

Page 7: ... Properties button 9 Select Obtain an IP Address automatically and Obtain DNS server address automatically 10 Click OK You will be prompted to restart your computer Item No IP Configuration Description Your Setting 1 Host Name Host Name 2 Primary DNS Primary DNS 3 Physical Address MAC Address 4 IP Address WAN IP Address 5 Subnet Mask WAN Subnet Mask 6 Default Gateway WAN Gateway Item No IP Configu...

Page 8: ...ect an Ethernet cable from your Cable DSL modem to the router s WAN port 3 Connect an Ethernet cable from your computer s Ethernet port to one of the LAN ports on the router Repeat the process to connect other computers to the router If you have more com puters to add than you have router ports simply add a hub or switch to one of the router ports This creates additional avail able ports 4 Optiona...

Page 9: ...ick OK 3 Click the Setup Wizard button from the top of the page 4 Step through the configuration screens along the left side of the Setup Wizard page 5 Enter the required values for the WAN type you will use 6 Be sure to save your configuration and restart the router from the Save Restart page in the Setup Wizard The basic configuration of your Asanté router is now complete See Chapters 2 3 and 4 ...

Page 10: ...FriendlyNET VPN Security Router 10 ...

Page 11: ... Configuration 41 Appendix A Warranty Statement and FriendlyCare Support 51 Appendix B FCC Statement 53 Appendix C Troubleshooting 55 Appendix D Renewing Client IP Addresses 59 Appendix E Service Ports 61 Appendix F Hardware and Software Compatibility 63 Appendix G Specifications 65 Appendix H Configuring a System Log Server 69 Appendix I Your 802 11b Wireless Network 73 ...

Page 12: ...FriendlyNET VPN Security Router 12 ...

Page 13: ...4C Router with 4 port 10 100 LAN ports and backup modem port VR2004AC Router with 4 port 10 100 LAN ports and backup modem port plus integrated 802 11b wireless ac cess point 1 1 Features Key features of the router include Cable DSL Modem Support The router is compatible with all major brands of Cable DSL modem Asynchronous Port A dial up modem not included can be attached to the router to automat...

Page 14: ... L2TP pass through function IPSec Security Authentication MD5 SHA 1 DES 3DES Encryption IP Encapsulating Security Payload ESP Internet Security Association and Key Management Protocol Internet IP Security Domain of Interpretation for ISAKMP The NULL Encryption Algorithm and its use with IP Sec 8 IPSec Tunnels IPSec LAN to LAN IPSec Client to LAN PPTP Support Support PPTP Point to Point Tunneling P...

Page 15: ...ents Before installing the router you will have need to have met the fol lowing requirements Microsoft I E 4 0 or later version Netscape Navigator 4 0 or later version or Apple Safari One computer with an built in or installed 10 Mbps 100 Mbps or 10 100 Mbps Ethernet port Optional One Analog Modem or ISDN TA if a dialup con nection is needed One RJ 45 Cable DSL Internet connection TCP IP protocol ...

Page 16: ...ack ets No link has been established on the port Wireless VR2004AC model only Green Blinking Green A wireless connection has been es tablished A wireless connection has not been established COM Green Off A valid link has been established No link has been established Internet Green Off A valid link has been established No link has been established Status Blinking Yellow Off The router is booting up...

Page 17: ...password to your router See page 35 for more details The main menu will appear screens shown are from both models the Wireless Settings page will not appear in screenshots from the VR2004C model Click on the buttons across the top to access the available configuration pages Within each page click on the but tons along the left side to access further pages for configuration see the sections that fo...

Page 18: ... Device IP Settings 2 1 2 Device IP Settings To prevent unauthorized access to the router you should change the device s default IP address on your network This is the internal LAN IP Address and NOT the WAN IP Address from your ISP Click Next to enter the new values and to proceed to ISP Settings 2 1 3 ISP Settings If your ISP requires that you use a static IP Address check the Static IP radio bu...

Page 19: ...dynamic IP Address check the Dynamic IP radio button and click Next to continue to Additional ISP Settings 2 1 4 Additional ISP Settings In this page you can enable the type of WAN connection you are using Your ISP may require you to use any of PPPoE PPTP or AT T like authentication ...

Page 20: ... s MAC Ad dress from Windows 98 Me by running winipcfg or from Windows 2000 NT by running ipconfig all To find a Macintosh s Ethernet MAC address select Get Info from the File menu of either the AppleTalk or TCP IP Control Panel Again do not enter the colons that appear within the MAC address as the fields are already sepa rated within the page Item Description User Name Account name assigned by y...

Page 21: ... multiple access points routers or separate networks If you wish to have one big wireless network leave the SSID and channel settings for each router at the factory default SSID Service Set Identifier An alpha numeric name used for identification the Wireless stations must match the ac cess point s SSID Channel All Wireless stations must use the same channel as the access points If you wish to hav...

Page 22: ...e default key is 1 WEP Security and Apple Airport Wireless Cards The Apple Airport Wireless Card and the router enter and store the WEP Security Key differently From the Airport icon on your com puter s control strip select the router and enter plus the WEP key in the password field Click Next to enter the new data and to proceed to the Modem Set tings page 2 1 6 Modem Settings You can configure t...

Page 23: ...tailed informa tion 2 1 8 Save and Restart After stepping through the Setup Wizard s configuration pages you must save and restart the router through the Save Restart page This process will take a few moments The progress bar across the bottom of the screen shows when the process is 100 complete Also the status LED will blink while the device restarts The router is ready to proceed when it stops b...

Page 24: ...ddress of the router s WAN Ethernet port Firmware Version The current firmware installed 2 3 Device Status This page displays the current connection status of the router and refreshes itself about every 14 seconds Arrows are used to indicate the state of the connections to the router Up and running Not working l l From this page you can view the VPN and DHCP status as well as release and renew IP ...

Page 25: ...ble from the System Tools page Intruder Detection Log Displays security incidents hacker attacks that have occurred Display Routing Table Displays the current routing table whether entries are static or dynamic System Status Displays the router s current configurations and checks router functioning Save Settings Allows the current configuration to be saved to a file Load Settings Allows you to loa...

Page 26: ...FriendlyNET VPN Security Router 26 Upgrade Firmware Allows you to upgrade the router to the latest version of firmware Reset Device Restarts the router ...

Page 27: ...gs URL Filter Settings E mail Alert Note You may be asked to re enter the username admin and pass word before entering the Advanced Settings page the default is no password It is highly recommended that you change this setting to prevent unauthorized access to the router see Chapter 3 6 3 1 DHCP Server Settings The router s DHCP server is enabled by default If you will be connect ing the LAN ports...

Page 28: ...router MAC Address Enter the MAC address of the device or computer IP Address Enter the IP address that you want to reserve 3 2 Virtual Server Settings This feature should only be used by users with an extensive knowledge of TCP IP One of the more powerful features of the router is the Virtual Server feature For a small business with two or more Internet servers the router can balance the workload...

Page 29: ...aced outside the protective firewall to allow unrestricted access to the server and to ensure complete Internet application compatibility even if specified ports are not known To enable the DMZ Demilitarized Zone function enter the IP address of the client into the DMZ IP address field The function is disabled if the IP value is left at zero 0 Important Enabling this option will allow the server o...

Page 30: ...e following Disable Access Control Any user with the correct wire less settings has access to the wireless network Enable Grant Access List Any user who is on the Grant Access list and has the correct wireless settings has ac cess to the wireless network Enable Deny Access List Any user who is on the Deny Access list is denied access to the wireless network If you select Enable Grant Access List o...

Page 31: ... Click Submit to have your changes take effect 3 4 Routing Settings This feature should only be used by users with an extensive knowledge of TCP IP This screen allows you to enter the Static and Dynamic Routing set tings 3 4 1 Static Routing Table Network traffic sent by the router is ordinarily sent to the default gateway configured when the router is set up Occasionally you may need to specify a...

Page 32: ...be used as a gate way to the remote network 3 4 2 Dynamic Routing Settings The router is capable of exchanging routing information with other routers on a LAN It does this by exchanging packets using the Routing Information Protocol RIP If you install the router on a network with other routers your Net work Administrator may want to turn on this feature Unless your Network Administrator asks you t...

Page 33: ...arately By default they are both disabled Both the LAN and the WAN filters have a default policy either to allow all traffic or to block all traffic After configur ing the defaults you can then add rules that make exceptions to the default 3 5 1 LAN Filter Settings Since the router s primary purpose is to allow several computers to share an Internet connection most users will configure a LAN filte...

Page 34: ...left side menu A WAN Filter works similarly to the LAN Filter If for example you need to run a web server from behind your firewall at your home office but you only want people in your main office to be able to connect to it you would want to make the default policy of your WAN Filter Block Your setting would look something like this WAN Side Filter Enabled Enabled Default WAN Side Filter Block Fi...

Page 35: ...m no password default to a password of your choosing and keep it in a safe place Simply enter the new password in the New Password field and retype it for verification Note If you lose or forget your password you can reset the router to its default settings by pressing the small reset button located on the back of the router Use a pen or similar tool to press the reset button for 5 6 seconds All c...

Page 36: ...k the box to ignore ping requests 3 6 3 System Log Because the router s memory cannot hold as many messages as a computer with a hard drive you can have the router send its Sys tem Log messages to another computer or server on the network Check the Enable box to enable the System Log function and enter the log server IP address Note The ability to receive system log messages is most common on Unix...

Page 37: ... who get a dynamic IP address to be able to use a name You need to register with a Dynamic DNS provider see the drop down list in the page shown below and select a name i e your name provider net When the router connects to the Internet it will notify the Dynamic DNS provider of its current IP address Users will be able to find your IP address by providing your name yourname provider net If you ar...

Page 38: ...me will cause the site to be blocked by the router Click the check box to enable the URL Filter function and enter a key word into the Filter String field Press Add After entering all of the desired strings click Submit to enter the data 3 9 E mail Alert The router can be set to periodically E mail you a log of internal se curity events such as denied incoming service requests and admin istrator l...

Page 39: ... select the fre quency for receiving E mail alerts 3 10 Save and Restart Each time you submit or add or change data the Save Restart page will appear To continue configuration select the appropriate option to be taken back to that page When you are finished how ever be sure to click on Save Restart accessed through the Setup Wizard page Do NOT turn off the device until the progress bar completes i...

Page 40: ...FriendlyNET VPN Security Router 40 ...

Page 41: ...c with Up to eight 8 tunnels may be con figured on the router There are two modes for setting up a VPN using the router net work to network and client to network From the Setup Wizard screen click on the VPN Settings button to configure your VPN Enter a connection name for the tunnel and click ADD The tunnel is automatically enabled when you add the name 4 1 Network to Network In a network to netw...

Page 42: ...s Important Each network joined by VPNs must have a different net work address This means that if you leave the LAN address of the first router set to the default value of 192 168 123 254 you should change the LAN address of any other router connecting to the first to another value A good way to do this would be to change the third octet of the IP address to a different value1 Your configurations ...

Page 43: ...lt value is Local Remote IPSec Identifier East Allows you to identify mul tiple tunnels and does not have to match the name used at the other end of the tunnel Maybe left blank The default value is Remote Remote IP Network 192 168 100 254 Remote IP Netmask 255 255 255 0 Remote Gateway IP 10 0 0 123 Network Interface WAN ETHERNET VR2004 B East end Connection Name East West Local IPSec Identifier Ea...

Page 44: ...e network Most users should leave this set to WAN ETHERNET Local IPSEC Identifier Allows you to identify multiple tun nels and does not have to match the name used at the other end of the tunnel This field may remain blank The default value is Local Remote IPSEC Identifier Allows you to identify multiple tunnels and does not have to match the name used at the other end of the tunnel This field may...

Page 45: ...Note If you do not know the Remote Gateway IP of the remote client you can enter 0 0 0 0 However the VPN connection request must then be initiated by the client If you select Manual Mode you must enter the Remote Gateway IP address 4 3 IPSec Keying IKE Mode A VPN tunnel is formed of two separate Secure Associations or SAs One SA is used for traffic in each direction and the router will keep track ...

Page 46: ...ociation SA using the IKE Mode the default mode complete the fields described in the following sections 4 3 1 Perfect Forward Secure This is an optional feature of IKE When enabled the default set ting this feature may impose some additional overhead on the router but can offer added protection against an eavesdropper be ing able to decode the encrypted data Either setting is acceptable but both e...

Page 47: ... device 4 3 4 Key Life The Key Life value sets the amount of time until the router renegoti ates the key thereby decreasing the likelihood of a security breach The default is 3600 seconds one hour 4 3 5 IKE Life Time This value sets the amount of time until the router renegotiates the IKE security association The default is 28800 seconds 8 hours 4 4 Manual Mode Important Asanté recommends that onl...

Page 48: ...g SPI at the other end of the tunnel 4 4 2 Encryption Protocol The router supports two encryption algorithms DES and 3DES Use the drop down menu to select a protocol Selecting NULL disables encryption Note The protocol chosen must match that used by the remote de vice 4 4 3 Encryption Key This string is used as a key to encrypt and decrypt the data trans mitted Use an alpha numeric value of 24 cha...

Page 49: ...mote de vice After configuring all the VPN values that are required click on the Save button This accesses the Save Restart page Click the Save Restart button Do not turn off the router while it is saving To further edit or delete a VPN tunnel access the VPN Settings page from the Setup Wizard Uncheck the Enable box to disable an individual VPN tunnel Click the Edit or Del button to change the VPN...

Page 50: ...FriendlyNET VPN Security Router 50 ...

Page 51: ...age paid In the event of a defect Asanté will repair or replace de fective product or components with new refurbished or equivalent product or components as deemed appropriate by Asanté The foregoing is your sole remedy and Asanté s only obligation with respect to any defect or non conformity Asanté makes no warranty with respect to accessories including but not limited to cables brackets and fast...

Page 52: ...chnical support plan to help you get the most from your FriendlyNET products See Appendix B for information about regis tering your router On line Support These resources are available 24 7 via www asante com support Web including forums support guides and white papers TechInfo Library knowledgebase Downloads manuals drivers and firmware Personalized Support If you have a question about the use or...

Page 53: ...l interference to radio communications However there is no guarantee that interference will not occur in a particular installation If this equipment does cause harmful interference to radio or televi sion reception which can be determined by turning the equipment off and on the user is encouraged to try to correct the interference by one or more of the following measures Reorient or relocate the r...

Page 54: ...FriendlyNET VPN Security Router 54 ...

Page 55: ...ption Suggestions 1 2 3 4 Link Activity Green Off No network connec tion Check network cable connection Wireless VR2004AC only Wireless Status Green Off No wireless con nection OR no traffic detected Check network cable connection COM Dial Up Modem Status Green Off No analog modem detected Verify that the router is configured for dial up Modem see Chapter 2 1 6 Check network cable connection WAN L...

Page 56: ...computer s network adapter port and the corresponding router port to be sure they are on If not check the Ethernet cable s C 2 1 Using Windows Ping To ping an IP address from Windows 1 From the Windows Start button choose Run 2 In the dialog box type ping 192 168 123 254 and click OK 3 You ll see an MS DOS dialog box showing the ping activity If it times out then there is no logical connection fro...

Page 57: ...uter are workstation or straight through cables and are wired to IEEE T568A or T568B speci fications See the diagram below to determine if your cables are workstation cables T568B wiring shown for demonstration purposes To determine if your ca ble is a straight through cable hold both ends of the cable together away from you with the clip portion down Pin 1 should be on your left Verify that the w...

Page 58: ...les Clips or hangers used for telephone wires are available at most hard ware stores 3 Avoid devices that create noise such as florescent light fix tures printers copy machines electric heaters speakers TV sets microwave ovens telephones electric fans and washing machines 4 If you bundle a group of cables together with cable ties zip ties do not tighten them so tightly that you deform the cables 5...

Page 59: ... All button 6 Click the Renew All button 7 Click OK D 2 Windows NT 2000 Perform the following steps to reset the IP address of any Windows NT or 2000 computers 1 Go to the Start button on the lower menu bar From the Start button choose Run 2 Type Command and press Enter 3 At the command line type ipconfig release_all and press En ter 4 Type the command ipconfig renew_all and press Enter 5 Type Exi...

Page 60: ...FriendlyNET VPN Security Router 60 ...

Page 61: ...et Internet BBS 25 SMTP Send mail 53 DNS 67 BOOTP bootstrap protocol 79 finger 80 HTTP worldwide web 110 POP3 receive mail 113 Auth authentication 119 NNTP net news 161 SNMP network management 162 SNMP TRAP network management 443 HTTPS secure worldwide web 517 TALK 518 NTALK 1723 PPTP Microsoft VPN virtual private network 2049 NFS Sun Network File System ...

Page 62: ...FriendlyNET VPN Security Router 62 ...

Page 63: ...latforms compatibility Windows 95 98 NT 2000 Workstation Microsoft Windows NT Server UNIX System Linux OpenBSD SCO UNIX Application Software Compatibility Microsoft Internet Explorer Netscape Navigator Communicator FTP related software ICQ NetMeeting V3 01 Microsoft Outlook Microsoft Outlook Express TCP IP based Internet applications ...

Page 64: ...FriendlyNET VPN Security Router 64 ...

Page 65: ... PPTP user name password Cable host name domain name Device MAC address Wireless VR2004AC SSID channel 64 or 128 bit WEP encryp tion Modem phone number user name password IP baud rate initialization strings and VPN settings Virtual Private Network VPN Connections Select up to 8 simultaneous connections tunnels Identifiers Local IPSec and remote IPSec Remote Network IP Address netmask and gateway N...

Page 66: ...l IPSec debug log Force PPPoE to reconnect Force maximum transmis sion unit MTU size Dynamic DNS Dynamic DNS server host name user name and password Accepts wildcards URL Filtering Blocks access to targeted URLs Email Alert Sends system alerts and logs via email to email server and destination email address Schedule immediately hourly daily at specific time or only when log is full System Tools In...

Page 67: ...k and QuickTime Messaging H 323 AOL Instant Messenger ICQ and MIRC Others RealPlayer Dialpad Quake Half Life and Star Craft Unreal Tournament Standards Compliance Network IEEE 802 3u Fast Ethernet over 2 pairs of UTP Category 5 100BaseTX IEEE 802 3 Ethernet over 2 pairs of UTP Category 3 10BaseT VR2004AC IEEE 802 11b Wireless Ethernet over 2 4GHz VPN Encryption NULL 56 bit Data Encryption Standard...

Page 68: ...g VR2004AC 1 01 pounds 0 46 Kg Environmental Range Operating Temperature 32º to 104º F 0º to 40º C Relative Humidity 10 to 95 non condensing Power 5 VDC 2A Includes external switching power module 100 240 VAC 0 6 A Emissions FCC Class B and CE Support Product Warranty Two year product warranty covers defects in manufacturing and workmanship Technical Support 90 days of free telephone support plus ...

Page 69: ...he syslog daemon to listen on the network Edit etc sysconfig syslog and add the options r x to the line SYS LOGD_OPTIONS Save the file Options to syslogd m 0 disables MARK messages r enables logging from remote machines x disables DNS lookups on messages received with r See syslogd 8 for more details SYSLOGD_OPTIONS r x m 0 2 We also want to configure the system logger to use a specific file for m...

Page 70: ...g messages This is a rea sonable security measure since syslog messages from an un expected source pose a risk of filling the log server s hard drive 5 Now restart ipchains etc init d ipchains restart 6 Enter the IP address of the server in the router s Administration Settings page You should now see messages begin to appear in the selected router log file H 2 Mac OS X Mac OS X runs a syslog daemo...

Page 71: ... configured to use facility local5 Edit etc syslog conf and add a line for the router Router is using local5 local5 var log router log This says that all messages with facility local5 should be logged in var log router log Note that the two portions of the line in syslog must be separated by tabs Don t put any spaces between the two 5 Now restart the system logger root System Library StartupItems ...

Page 72: ...ow you to create more complicated rules for exam ple sunShield found at http homepage mac com opalliere shield_us html H 3 Microsoft Windows Shareware versions of system loggers are available for other operating systems at most of the popular websites e g www tucows com One system log daemon that Asanté recommends is the Kiwi Syslog Daemon for Windows http www kiwisyslog com info_syslog htm They h...

Page 73: ... the user should be able to see the router from the location where the wireless client is placed Keep the wireless router in an open area away from any large objects such as cubicles walls or other obstructions Keep the wireless router away from any electro magnetic emit ting devices that can cause troublesome interference such as computers electrical cables televisions cordless phones mi crowave ...

Page 74: ...r network Asanté s wireless security features protect your network from out side parties The following sections describe steps to take to pre vent unauthorized access to your wireless network Please refer to your Asanté product s documentation for more information Administrator s Password Change the default password of the wireless device as soon as possible to prevent unauthorized access or chang...

Page 75: ...ic pri vacy protection but should be used to make it more difficult for hackers to intercept data or access your network Use the following tips to maximize the benefit of WEP encryption Use the highest level of encryption available Use a shared key Use multiple keys Change the WEP key regularly Enabling encryption can decrease your network performance over all but is necessary for transmitting sen...

Page 76: ...CAL SUPPORT 801 566 8991 Worldwide 801 566 3787 FAX www asante com Copyright 2003 Asanté Technologies Inc Asanté is a registered trademark of As anté Technologies Inc FriendlyNET is a trademark of Asanté Technologies Inc All other names or marks are trademarks or registered trademarks of their respective own ers All features and specifications are subject to change without prior notice 06 00647 00...

Reviews: