background image

Last Revision Date: 9-30-2010 

 

 

 
 
 
 
 
 
 
 
 
 

BiPAC 7402NX(L) 

 

802.11n 3G/ADSL2+         

(VPN) Firewall Router 

 

User Manual 

 
 
 
 

 

 

 

 

 

 

 

 

 
 

Version released: 

6.24b.dm2 

Summary of Contents for BiPAC 7402NX

Page 1: ...Last Revision Date 9 30 2010 BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router User Manual Version released 6 24b dm2...

Page 2: ...Device LAN IP settings 18 ISP setting in WAN site 18 DHCP server 18 LAN and WAN Port Addresses 18 Information from your ISP 19 Configuring with your Web Browser 20 Chapter 4 Configuration 21 Status 22...

Page 3: ...int to Point Tunneling Protocol 104 IPSec IP Security Protocol 112 L2TP Layer Two Tunneling Protocol 121 QoS Quality of Service 133 Prioritization 133 Outbound IP Throttling LAN to WAN 135 Inbound IP...

Page 4: ...Billion BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Table of Contents APPENDIX A Product Support and Contact Information 161...

Page 5: ...User can use embedded PPTP and L2TP client server IKE and IPSec which are supported by this router to make a VPN connection or users can run the PPTP client in PC and the router already provides IPSe...

Page 6: ...NetMeeting IP phone and others SOHO Firewall Security with DoS and SPI Along with the built in NAT natural firewall feature the router also provides advanced hacker pattern filtering protection It ca...

Page 7: ...port or a range of ports to the specific local computer to handle it For example a user can assign a PC in the LAN acting as a WEB server inside and expose it to the outside network Outside users can...

Page 8: ...Router Important note for using this router Package Contents BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router CD containing the on line manual RJ 11 ADSL telephone cable Ethernet CAT 5 LAN cable T...

Page 9: ...will appear Orange If the speed of transmission hits 10Mbps light will not shine Blinking when data is Transmitted Received 3 USB Lit green when the device is connected to a USB device and ready Flas...

Page 10: ...onsole Console port 3G HSDPA USB modem backup for Internet access 6 RESET To be sure the device is being turned on press RESET button for 1 3 seconds quick reset the device 6 seconds above and power o...

Page 11: ...re using the proper cables Ensure that all other devices connected to the same telephone line as your router e g telephones fax machines analogue modems have a line filter connected between them and t...

Page 12: ...l repeater hub to the router or directly connecting with PCs However to be sure PCs have an Ethernet interface installed properly prior to connecting to the router device You ought to configure your P...

Page 13: ...ecting Your Router 1 Connect this router to a LAN Local Area Network and the ADSL telephone ADSL network 2 Power on the device 3 Make sure the Power is lit steadily and that the LAN LED is lit 4 Conne...

Page 14: ...uring PCs in Windows 7 1 Go to Start Click on Control Panel Then click on Network and Internet 2 When the Network and Sharing Center window pops up select and click on Change adapter settings on the l...

Page 15: ...ocol Version 4 TCP IPv4 then click Properties 5 In the TCP IPv4 properties window select the Obtain an IP address automatically and Obtain DNS Server address automatically radio buttons Then click OK...

Page 16: ...Windows Vista 1 Go to Start Click on Network 2 Then click on Network and Sharing Center at the top bar 3 When the Network and Sharing Center window pops up select and click on Manage network connecti...

Page 17: ...col Version 4 TCP IPv4 then click Properties 6 In the TCP IPv4 properties window select the Obtain an IP address automatically and Obtain DNS Server address automatically radio but tons Then click OK...

Page 18: ...a Connection See Figure 3 1 3 In the LAN Area Connection Status window click Properties See Figure 3 2 4 Select Internet Protocol TCP IP and click Properties See Figure 3 3 5 Select the Obtain an IP a...

Page 19: ...N Connection See Figure 3 5 3 In the LAN Area Connection Status window click Properties See Figure 3 6 4 Select Internet Protocol TCP IP and click Properties See Figure 3 7 5 Select the Obtain an IP a...

Page 20: ...elect TCP IP NE2000 Compatible or the name of any Network Interface Card NIC in your PC See Figure 3 9 3 Click Properties 4 Select the IP Address tab In this page click the Obtain an IP address automa...

Page 21: ...ws NT4 0 1 Go to Start Settings Control Panel In the Control Panel double click Network and choose the Protocols tab 2 Select TCP IP Protocol and click Properties See Figure 3 12 3 Select the Obtain a...

Page 22: ...s 100 LAN and WAN Port Addresses The parameters of LAN and WAN ports are pre set in the factory The default values are shown below LAN Port WAN Port IP address 192 168 1 254 Subnet Mask 255 255 255 0...

Page 23: ...Service Name and Domain Name System DNS IP address it can be automatically assigned by your ISP when you connect or be set manually PPPoA RFC2364 VPI VCI VC LLC based multiplexing Username Password an...

Page 24: ...web browser enter the IP address of your router which by default is 192 168 1 254 and click Go a user name and password window prompt will appear The default username and password are admin and admin...

Page 25: ...rectly to the desired setup page including Status ADSL Status 3G Status EWAN Status IBurst Status ARP Table DHCP Table Routing Table NAT Sessions UPnP Portmap PPTP Status IPSec Status L2TP Status Even...

Page 26: ...C 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 22 Status ADSL Status This section displays the ADSL overall status which shows a number of helpful information such as DSP firm...

Page 27: ...strength Network Name The network name that the device is connected to Card Name The name of the 3G card Card Firmware The current firmware for the 3G card Card IMEI the IMEI International Mobile Equ...

Page 28: ...nfiguration 24 Total Connection Time The cumulative connection time Amount used Show the traffic or hours has been used Billing period The day from which the fee is charged Note Only after you have ch...

Page 29: ...t 1 as a WAN port to be used to connect to Cable Modems and fiber optic lines This alternative yet faster method to connect to the internet will provide users more flexibility to get online Total TX B...

Page 30: ...Card Name The name of the card Signal Strength The signal strength bar indicates the current signal strength Current TX Bytes Packets The statistics of data transmission in bytes packets during a call...

Page 31: ...list of IP addresses of devices on your LAN Local Area Network MAC Address The MAC Media Access Control addresses for each device on your LAN Interface The interface name on the router that this IP A...

Page 32: ...ask The destination Netmask address Gateway Interface The IP address of the gateway or existing interface that this route will use Cost The number of hops counted as the cost of the route RIP Routing...

Page 33: ...This section lists all current NAT sessions between interface of types external WAN and internal LAN UPnP Portmap The section lists all port mapping established using UPnP Universal Plug and Play See...

Page 34: ...l is currently connected Call Connected If the Call for this VPN entry is currently connected Encryption The encryption type used for this VPN connection IPSec Status This shows details of your config...

Page 35: ...particular L2TP connection in your VPN configuration Type The type of connection dial in dial out Enable Whether the connection is currently enabled Active Whether the connection is currently active...

Page 36: ...when you have enabled Intrusion or Blocking Logging in the Configuration Firewall section of the interface Please see the Firewall section of this manual for more details on how to enable Firewall lo...

Page 37: ...l Router Chapter 4 Configuration 33 Error Log Any errors encountered by the router e g invalid names given to entries are logged to this window IDS Log Any records about hacker attacks and intrusion a...

Page 38: ...hapter 4 Configuration 34 Diagnostic It tests the connection to computer s which is connected to LAN ports and also the WAN Internet connection If PING www google com is shown FAIL and the rest is PAS...

Page 39: ...DSL from Connect Mode drop down menu and click Continue 2 If your ADSL line is not ready you need to check your ADSL line has been set or not 3 If your ADSL line is ready the screen appears ADSL Line...

Page 40: ...There are ADSL and 3G Encapsulation Select the encapsulation mode The default mode is PPPoE VPI VCI Enter the VPI and VCI information provided by your ISP Username Enter the username provided by your...

Page 41: ...ce in order to get connected to your network ESSID Broadcast It is function in which transmits its ESSID to the air so that when wireless client searches for a network router can then be discovered an...

Page 42: ...and DHCP Server Bridge Interface You can setup member ports for each VLAN group under Bridge Interface section From the example two VLAN groups need to be created Ethernet P1 and P2 Port 1 2 Ethernet1...

Page 43: ...P Address Specify an IP address on this virtual interface Netmask Specify a subnet mask on this virtual interface Security Interface Specify the firewall setting on this virtual interface Internal The...

Page 44: ...MAC address and information prefix advertised by routers Routers advertise prefixes that identify the subnet s associated with a link while hosts generate an interface identifier that uniquely identi...

Page 45: ...Make sure your PC s MAC is listed Blocked check to prevent unwanted device accessing your LAN by insert the MAC Address in the space provided or click Make sure your PC s MAC is not listed The maximum...

Page 46: ...ault wlan ap to a unique ID name to the AP which is already built in to the router s wireless interface It is case sensitive and must not excess 32 characters Make sure your wireless clients have exac...

Page 47: ...ts according to 4 categories Voice Video Best Efforts and Background Enable Click to activate WMM feature Disable Click to deactivate WMM feature Wireless Distribution System WDS It is a wireless acce...

Page 48: ...SK and WPA2 PSK The WPA PSK adapts the TKIP Temporal Key Integrity Protocol encrypted algorithms which incorporates Message Integrity Code MIC to provide protection against hackers The WPA2 PSK adapts...

Page 49: ...8 You can input the same string in both the AP and Client card settings to generate the same WEP keys Please note that you do not have to enter Key 1 4 as below when the Passphrase is enabled Passphra...

Page 50: ...MAC is listed Blocked To prevent unwanted device accessing the LAN by insert the MAC Address in the space provided or click Make sure your PC s MAC is not listed The maximum client is 16 The MAC addre...

Page 51: ...i Protected Setup feature is a standard protocol created by Wi Fi Alliance This feature greatly simplifies the steps needed to create a Wi Fi network for a residential or an office setting WPS support...

Page 52: ...n the client s Pin e g 16837546 2 Enter the Enrollee s PIN number and then press Start 3 Launch the wireless client s WPS utility eg Ralink Utility Set the Configure Mode as Enrollee press the WPS but...

Page 53: ...lion BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 49 4 The client s SSID and security setting will now be configured to match the SSID and security setting of the regist...

Page 54: ...Start 2 Jot down the WPS PIN e g 25879810 3 Launch the wireless client s WPS utility e g Ralink Utility Set the Config Mode as Registrar Enter the PIN number in the PIN Code column then choose the cor...

Page 55: ...Billion BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 51 setting of the registrar...

Page 56: ...apter 4 Configuration 52 5 Now to make sure that the setup is correctly done cross check to see if the SSID and the security setting of the registrar setting match with the parameters found on both Wi...

Page 57: ...Billion BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 53...

Page 58: ...on 54 PBC Method 1 Press the PBC button of the AP 2 Launch the wireless client s WPS Utility eg Ralink Utility Set the Config Mode as Enrollee Then press the WPS button and choose the correct AP eg wl...

Page 59: ...uter Chapter 4 Configuration 55 3 When the PBC button is pushed a wireless communication will be established between your router and the PC The client s SSID and security setting will now be configure...

Page 60: ...s Vista WCN 1 Jot down the AP PIN from the Web eg 25879810 2 In your Vista operating system access the Control Panel page then select Network and Internet View Network Computers and Devices Double cli...

Page 61: ...1n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 57 4 Enter the passphrase then click Next 5 When you have come to this step you will have completed the Wi Fi network setup using the built in W...

Page 62: ...Billion BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 58...

Page 63: ...devices and you can configure different types to solve compatibility issues The default is Auto which users should keep unless there are specific problems with PCs not being able to access your LAN I...

Page 64: ...u can then configure parameters of the DHCP Server including the IP pool starting IP address and ending IP address to be allocated to PCs on your network lease time for each assigned IP address the pe...

Page 65: ...Here are the items within the WAN section WAN Interface WAN Profile and ADSL Mode WAN Interface The factory default has the Connection Mode as ADSL and the Protocol as PPPoE Main Port Dual WAN In dual...

Page 66: ...on to change to the backup port is determined by Probe Cycle duration multiplied by connection Decision amount e g From the image above it will be 60 seconds multiplied by 5 consecutive fails Failback...

Page 67: ...ervice Name This item is for identification purposes If it is required your ISP provides you the information Maximum input is 15 alphanumeric characters NAT The NAT Network Address Translation feature...

Page 68: ...he optimal MTU size automatically Default is enabled MAC Spoofing This option is required by some service providers You must fill in the MAC address that specify by service provider when it is require...

Page 69: ...anumeric characters NAT The NAT Network Address Translation feature allows multiple users to access the Internet through a single IP account sharing the single IP address If users on your LAN have pub...

Page 70: ...er the optimal MTU size automatically Default is enabled Obtain DNS A Domain Name System DNS contains a mapping table for domain name and IP addresses DNS helps to find the IP address for the specific...

Page 71: ...will attempt to send through the interface IP 0 0 0 0 Auto Your WAN IP address Leave this at 0 0 0 0 to obtain automatically an IP address from your ISP Netmask The default is 0 0 0 0 User can change...

Page 72: ...DNS similar as IPv4 IPv6 Address Check Automatic to obtain IPv6 address automatically If not please type the IP and the prefix length for the IPv6 address from your ISP Gateway Type the gateway to whi...

Page 73: ...excluding media specific headers that IP will attempt to send through the interface IP 0 0 0 0 Auto Your WAN IP address Leave this at 0 0 0 0 to obtain automatically an IP address from your ISP Netma...

Page 74: ...ptable Frame Type Specify which kind of traffic goes through this connection all traffic or only VLAN tagged Filter Type Specify the type of ethernet filtering performed by the named bridge interface...

Page 75: ...Address Translation feature allows multiple users to access the Internet through a single IP account sharing the single IP address If users on your LAN have public IP addresses and can access the Inte...

Page 76: ...to enable RIP function TCP MSS Clamp This option helps to discover the optimal MTU size automatically Default is enabled Obtain DNS A Domain Name System DNS contains a mapping table for domain name a...

Page 77: ...ingle IP address If PCs in LAN should share the WAN IP for WAN access please enable NAT If users on your LAN have public IP addresses and can access the Internet directly the NAT function can be disab...

Page 78: ...s supplied by your ISP NAT The NAT Network Address Translation feature allows multiple users to access the Internet through a single IP account sharing the single IP address If PCs in LAN should share...

Page 79: ...to access the Internet Idle Timeout Auto disconnect the router when there is no activity on the line for a predetermined period of time MTU Maximum Transmission Unit The size of the largest datagram e...

Page 80: ...rimary and Secondary fields Pure Bridge Profile Port Select the profile port as EWAN Protocol Select Pure Bridge Acceptable Frame Type Specify which kind of traffic goes through this connection all tr...

Page 81: ...PA UMTS EDGE GPRS or GSM Internet connection makes downstream rates of to 14 4 Mbps Profile Port Select the profile port as 3G iBurst Enable or Disable the router s iBurst functionality Usage Allowanc...

Page 82: ...rs use the APN internet for their portal The default value of APN is internet Username Enter the username provided by your service provider Password Enter the password provided by your service provide...

Page 83: ...ame time Enabling Connect on Demand will give you an option of Idle Timeout Idle Timeout Auto disconnect the connection when there is no activity on this call for a predetermined period of time The de...

Page 84: ...synchronization problem Profile Type Please keep the factory settings unless ADSL is detected as the symptom of low link rate or unstable problems You may need to change the profile setting to reach t...

Page 85: ...he SNTP server you have specified If you prefer to specify an SNTP server other than those in the list simply enter its IP address as shown above Your ISP may provide an SNTP server for you to use Day...

Page 86: ...ou wish to permanently enable remote access choose a time period of 0 minute Firmware Upgrade Your router s firmware is the software that allows it to operate and provides all its functionality Think...

Page 87: ...making any significant changes to your router s configuration Press Backup to select where on your local PC to save the settings file You may also change the name of the file when saving if you wish...

Page 88: ...er using the factory default settings for example after a firmware upgrade or if you have saved an incorrect configuration select Factory Default Settings to reset to factory default settings You may...

Page 89: ...onfiguration interface Once you have clicked on Edit you are shown the following options You can change the user s password whether their account is active and valid as well as add a comment to each u...

Page 90: ...you create a user account you check Valid to fill in the blank with User Comment Password and Confirm Password Later click Add button to add your new user account For deleting the user account you cho...

Page 91: ...e arisen so that the server can be properly maintained SMTP Server Enter the SMTP server that you would like to use for sending emails Username Enter the username of your email account to be used by t...

Page 92: ...natural firewall This masks LAN users IP addresses which is invisible to outside users on the Internet making it much more difficult for a hacker to target a machine on your network This natural fire...

Page 93: ...are displayed in Port Filters of Packet Filter Select either High Medium or Low security level to enable the Firewall The only difference between these three security levels is the preset port filter...

Page 94: ...tion is only available when the Firewall is enabled and one of these four security levels is chosen All blocked High Medium and Low The preset port filter rules in the Packet Filter must modify accord...

Page 95: ...NO YES NO YES NO YES DNS 53 TCP 6 53 53 NO YES NO YES NO YES FTP 21 TCP 6 21 21 NO YES NO YES NO NO Telnet 23 TCP 6 23 23 NO YES NO YES NO NO SMTP 25 TCP 6 25 25 NO YES NO YES NO YES POP3 110 TCP 6 1...

Page 96: ...d to allow or block traffic to from particular IP address es Selecting the Subnet Mask of the IP address range you wish to allow block the traffic to or form set IP address and Subnet Mask to 0 0 0 0...

Page 97: ...ing Select drop down menu to select existing predefined rules IP version select IPv4 or IPv6 Time Schedule It is self defined time period You may specify a time schedule for your prioritization policy...

Page 98: ...high medium or low security level To setup a web server located on the local network when the firewall is enabled you have to configure the Port Filters setting for HTTP As you can see from the diagr...

Page 99: ...this case for the low security level shown below Note You may click Edit the predefined rule instead of Delete it This is an example to show to how you add a filter on your own 2 Choose the radio butt...

Page 100: ...Predefined Port Filter Source Port 0 65535 I allow all ports to connect with the application Redirect Port 80 80 This is Port defined for HTTP Inbound Outbound Allow 4 The new port filter rule for HTT...

Page 101: ...on This is the duration for blocking Smurf attacks Default value is 600 seconds Scan Attack Block Duration This is the duration for blocking hosts that attempt a possible Scan attack Scan attack types...

Page 102: ...7 Src IP Scan Yes Yes CharGen Scan UDP Dst Port CharGen 19 Src IP Scan Yes Yes X mas Tree Scan TCP Flag X mas Src IP Scan Yes Yes IMAP SYN FIN Scan TCP Flag SYN FIN DstPort IMAP 143 SrcPort 0 or 65535...

Page 103: ...es will be monitoring and checking all hours of the day TimeSlot1 TimeSlot16 It is self defined time period You may specify the time period to check the URL filter rules i e during working hours For s...

Page 104: ...f yes the connection attempt is sent to the remote web server 2 If not check if it is listed in the forbidden list If yes then the connection attempt will be dropped 3 If the packet does not match eit...

Page 105: ...pt for Trusted Domain BUT not its IP address If this is the situation Block surfing by IP address function can be handy and helpful to Andy Now Andy can prevent Bobby from accessing other sites Restri...

Page 106: ...ing The default is set to Disabled Disabled Instant Message blocking is not triggered No action will be performed Always On Action is enabled TimeSlot1 TimeSlot16 This is the self defined time period...

Page 107: ...ll Router Chapter 4 Configuration 103 Firewall Log Firewall Log display log information of any unexpected action with your firewall settings Check the Enable box to activate the logs Log information c...

Page 108: ...Note When the Active checkbox is checked the function of Edit and Delete will not be available Connection Type It informs your PPTP tunnel connection condition Type This refers to your router operate...

Page 109: ...s at different periods to ensure that an intruder has not replaced the client Data Encryption Data sent over the VPN connection can be encrypted by an MPPE algorithm Default is Auto so that this setti...

Page 110: ...nfiguration 106 Example Configuring a Remote Access PPTP VPN Dial out Connection A company s office establishes a PPTP VPN connection with a file server located at a separate location The router is in...

Page 111: ...N_PPTP Given name of PPTP connection 2 Connection Type Remote Access Select Remote Access from Connection Type drop down menu Type Dial out Select Dial out from Type drop down menu 3 IP Address or Dom...

Page 112: ...tication type to use or else manually specify CHAP Challenge Handshake Authentication Protocol or PAP Password Authentication Protocol if you know which type the server is using when acting as a clien...

Page 113: ...PPTP LAN to LAN VPN Connection The branch office establishes a PPTP VPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branc...

Page 114: ...lect LAN to LAN from Connection Type drop down menu Type Dial in Select Dial in from Type drop down menu 3 IP Address 192 168 1 200 IP address assigned to branch office network Peer Network IP 192 168...

Page 115: ...onnection 2 Connection Type LAN to LAN Select LAN to LAN from Connection Type drop down menu Type Dial out Select Dial out from Type drop down menu 3 IP Address or Domain name 69 121 1 33 IP address o...

Page 116: ...ice versa Note When the Active checkbox is checked the function of Edit and Delete will not be available Name This is a given name of the connection Local Subnet Displays IP address and subnet of the...

Page 117: ...et starting from 192 168 1 1 i e 192 168 1 1 through to 192 168 1 254 IP Range The IP address range of the local network For example IP 192 168 1 1 end IP 192 168 1 10 Remote Secure Gateway Address or...

Page 118: ...istant to brute force attacks than MD5 however it is slower e MD5 A one way hashing algorithm that produces a 128 bit hash f SHA1 A one way hashing algorithm that produces a 160 bit hash Encryption Se...

Page 119: ...be noted it must be enabled on the both sites PING to the IP It is able to IP Ping the remote PC with the specified IP address and alert when the connection fails Once alter message is received Route...

Page 120: ...Local Router IP 69 121 1 30 69 121 1 3 Remote Network ID 192 168 1 0 24 192 168 0 0 24 Remote Router IP 69 1 121 3 69 1 121 30 IKE Pre shared Key 12345678 12345678 VPN Connection Type Tunnel mode Tun...

Page 121: ...t from Local Network drop down menu IP Address 192 168 1 0 2 Netmask 255 255 255 0 Head office network 3 Remote Secure Gateway IP or Hostname 69 121 1 30 IP address of the branch office router in WAN...

Page 122: ...ubnet from Local Network drop down menu IP Address 192 168 0 0 2 Netmask 255 255 255 0 Branch office network 3 Remote Secure Gateway IP or Hostname 69 121 1 3 IP address of the head office router in W...

Page 123: ...Billion BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 119 Example Configuring a IPSec Host to LAN VPN Connection...

Page 124: ...t Subnet from Network drop down menu IP Address 192 168 1 0 2 Netmask 255 255 255 0 Head office network 3 Remote Secure Gateway IP or Hostname 69 121 1 30 Remote worker s IP address Remote Network Sin...

Page 125: ...eate a new VPN connection account Active This function activates or deactivates the L2TP connection Check Active checkbox if you want the protocol of tunnel to be activated and vice versa Note When th...

Page 126: ...name Password If you are a Dial Out user client enter the password provided by your Host If you are a Dial In user server enter your own password Authentication Type Default is Auto if you want the ro...

Page 127: ...s it is a tunnel only with no encryption 3DES and AES are more powerful but increase latency DES Stands for Data Encryption Standard it uses 56 bits as an encryption method 3DES Stands for Triple Data...

Page 128: ...mple Configuring a L2TP VPN Remote Access Dial in Connection A remote worker establishes a L2TP VPN connection with the head office using Microsoft s VPN Adapter included with Windows XP 2000 ME etc T...

Page 129: ...ype Remote Access Select Remote Access from Connection Type drop down menu Type Dial in Select Dial in from Type drop down menu 3 IP Address 192 168 1 200 An assigned IP address for the remote worker...

Page 130: ...nfiguration 126 Example Configuring a Remote Access L2TP VPN Dial out Connection A company s office establishes a L2TP VPN connection with a file server located at a separate location The router is in...

Page 131: ...m Connection Type drop down menu Type Dial out Select Dial out from Type drop down menu 3 IP Address or Hostname 69 121 1 33 An Dialed server IP Username username 4 Password 123456 A given username pa...

Page 132: ...wish to connection to k When configuring your router as a server to accept incoming connections enter the Private IP Address Assigned to Dial in User address Peer Network IP Enter Peer network IP add...

Page 133: ...ne way hashing algorithm that produces a 160 bit hash Encryption Select the encryption method from the pull down menu There are four options DES 3DES AES and NULL NULL means it is a tunnel only with n...

Page 134: ...shes a L2TP VPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch office accordingly Both office LAN networks MUST in di...

Page 135: ...N to LAN from Connection Type drop down menu Type Dial in Select Dial in from Type drop down menu 3 IP Address 192 168 1 200 IP address assigned to branch office network Peer Network IP 192 168 0 0 4...

Page 136: ...L2TP connection 2 Connection Type LAN to LAN Select LAN to LAN from drop down menu Type Dial out Select Dial out from drop down menu 3 IP Address or Hostname 69 121 1 33 IP address of the head office...

Page 137: ...To delete the application you can choose Delete option and then click Edit Delete Name User define description to identify this new policy application Time Schedule Scheduling your prioritization poli...

Page 138: ...ng Table Wireless ADSL Router Standard DSCP Disabled None Best Effort Best Effort 000000 Premium Express Forwarding 101110 Gold service L Class 1 Gold 001010 Gold service M Class 1 Silver 001100 Gold...

Page 139: ...ion to identify this new policy name Time Schedule Scheduling your prioritization policy Refer to Time Schedule for more information Protocol The name of supported protocol Rate Limit To limit the spe...

Page 140: ...identify this new policy application Time Schedule Scheduling your prioritization policy Refer to Time Schedule for more information Protocol The name of supported protocol Rate Limit To limit the sp...

Page 141: ...r Chapter 4 Configuration 137 Example QoS for your Network Connection Diagram Information and Settings Upstream 928 kbps Downstream 8 Mbps VoIP User 192 168 1 1 Normal Users 192 168 1 2 192 168 1 5 Re...

Page 142: ...n BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 138 0 100 200 300 400 500 kbps VoIP VPN HIGH Others NORMAL Restricted LOW Throughput VoIP VPN HIGH Others NORMAL Restricte...

Page 143: ...st be sent out smoothly without any dropping Set priority as high level for preventing any other applications to saturate the bandwidth Voice application Voice is latency sensitive application Most Vo...

Page 144: ...ation 140 Restricted Application Some of companies will setup FTP server for customer downloading or home user sharing their files by using FTP With above settings that help to limit utilization of up...

Page 145: ...n the same level Upstream 928kbps 29 32kbps Mission critical Application 192kbps 6 32kbps Voice Application 128kbps 4 32kbps Restricted Application 160kbps 5 32kbps Other Applications 448kbps 14 32kbp...

Page 146: ...and P2P file sharing applications and are using NAT Network Address Translation then you will usually need to configure your router to forward these incoming connection attempts using specific ports t...

Page 147: ...n Users define description to identify this entry or click drop down menu to select existing predefined rules 20 predefined rules are available Application Protocol and External Redirect Ports will be...

Page 148: ...have disabled the NAT option in the WAN ISP section the Virtual Server function will hence be invalid If the DHCP server option is enabled you have to be very careful in assigning the IP addresses of...

Page 149: ...other Virtual Server entries Cautious This Local computer exposing to the Internet may face varies of security risks Go to Configuration Virtual Server Edit DMZ Host o Enabled It activates your DMZ f...

Page 150: ...s given by your ISP If your ISP has provided this information you may insert it here Otherwise use IP Range method IP Range The IP address range of your public WAN IP addresses For example IP 192 168...

Page 151: ...IP Define a public WAN IP address for this Application to use This Global IP address must be defined in the Global IP Address External Port The Port number on the Remote WAN side used when accessing...

Page 152: ...r further information please see IANA s website at http www iana org assignments port numbers For help on determining which private port numbers are used by common applications on this list please see...

Page 153: ...en up remotely by a network message Select Select MAC address of the computer that you want to wake up or turn on remotely Add After selecting click Add then you can perform the Wake up action Edit De...

Page 154: ...gh Sunday to restrict or allowing the usage of the Internet by users or applications This Time Schedule correlates closely with router s time since router does not have a real time clock on board it u...

Page 155: ...s the index of the time slot Name A user define description to identify this time portfolio Day in a week The default is set from Monday through Friday You may specify the days for the schedule to be...

Page 156: ...VLAN Bridge Static Route Go to Configuration Advanced Static Route Destination This is the destination subnet IP address Netmask Subnet mask of the destination IP addresses based on above destination...

Page 157: ...our ISP You will first need to register and establish an account with the Dynamic DNS provider using their website for example http www dyndns org There are more than 5 DDNS services supported Dynamic...

Page 158: ...t Name Give a name for it The Host Name cannot be used with one word only There are two words should be connected with a at least Example Host Name homegateway Incorrect Host Name home gateway or my h...

Page 159: ...the Internet Connection Sharing client from Windows XP in order to support UPnP Windows 2000 does not support UPnP Disable Check to disable the router s UPnP functionality Enable Check to enable the r...

Page 160: ...fine granularity for remote monitoring Traps supported Cold Start Authentication Failure The following MIBs are supported From RFC 1213 MIB II System group Interfaces group Address Translation group I...

Page 161: ...lion BiPAC 7402NX L 802 11n 3G ADSL2 VPN Firewall Router Chapter 4 Configuration 157 From RFC1573 IfMIB ifMIBObjects Group From RFC1695 atmMIB atmMIBObjects From RFC 1907 SNMPv2 only snmpSetSerialNo O...

Page 162: ...protocol is a component if the Internet Protocol version 6 IPv6 suite MLD is used by IPv6 to discover multicast listeners on a directly attached link much as IGMP used in IPv4 The protocol is embedde...

Page 163: ...the member Edit Edit your member ports in selected VLAN group Create VLAN To create another VLAN group Logout To exit the router s web interface choose Logout Please ensure that you have saved the con...

Page 164: ...he router should be on Check that your VPI VCI encapsulation type and type of multiplexing settings are the same as those provided by your ISP Reboot the router GE If you still have problems you may n...

Page 165: ...erring to the Troubleshooting section in the User s Manual If you cannot resolve the problem with the Troubleshooting chapter please contact the dealer where you purchased this product Contact Billion...

Reviews: