background image

Broadband Security Router User Guide

 

 

- 62 - 

SPI 

SPI is an acronym for Stateful Packet Inspection. The SPI engine examines not just the 
headers of the packet, but also the packet contents, it can then determine more about the 
packet than just its source and destination information. Moreover, stateful inspection 
firewalls also close off ports until a connection to the specific port is requested. 

TCP/IP 

Short for Transmission Control Protocol and Internet Protocol, the suite of 
communications protocols that enable hosts on the Internet to connect and exchange 
streams of data. 

VPN 

VPN is an acronym for Virtual Private Network. Via access control and encryption, 
VPN brings the same security to data transmission through the Internet as if it being 
transmitted through a private network. It not only takes advantage of economies of 
scale but also ensures high level security while the packet is sent over the large public 
network. 

Wide Area Network (WAN) 

A system of LANs being connected by telephone lines and radio waves. Although 
someWANs may be privately owned, they are usually considered a means of public 
access. 

WEP 

An acronym for 

Wired Equivalent Privacy

. It is an encryption mechanism used to 

protect your wireless data communications. WEP uses a combination of 64-bit/128-bit 
keys to encrypt data that is transmitted between all points in a wireless network to 
insure data security. It is described in the IEEE 802.11 standard.

 

Summary of Contents for WR214C

Page 1: ...H Hi ig gh h P Pe er rf fo or rm ma an nc ce e W Wi ir re el le es ss s R Ro ou ut te er r User s Manual 2003 06 10 ...

Page 2: ...Declaration of Conformity This equipment complies with the specifications relating to electromagnetic compatibility EN 55022 A1 Class B and EN 50082 1 This meets the reasonable protection requirements set out in the European Council Directive on the approximation of the laws of the member states relating to Electromagnetic Compatibility Directive 89 336 EEC Manufacturer s Disclaimer State The info...

Page 3: ...sic Configuration Setup 16 Wireless 16 WAN Connection Type 18 Chapter 4 Advanced Applications 23 DHCP Configuration 23 Access Control 24 Virtual Server Settings 27 Special Applications 35 DMZ Host 30 Dynamic Routing 32 Static Routing 33 DDNS 35 Chapter 5 Management 41 Device Administration Settings 41 Status Monitor 43 Log 44 Backup Restore 46 Upgrade Firmware 46 Diagnostic Ping 47 Chapter 6 Macin...

Page 4: ...Broadband Security Router User Guide iv Chapter 7 Trouble Shooting 51 Hardware 51 Client Side Computers 52 Appendix A Technical Specifications 55 Appendix B Glossary 57 ...

Page 5: ...evice not only provides natural firewall protecting your network from access by outside users but also extends your LAN connection Users on the LAN can share a single account of Internet access by having this device connect to a DSL Cable modem This Wireless Router allows up to 253 users on the Ethernet LAN simultaneously but makes IP configuration simple and easy Configured as a DHCP server the H...

Page 6: ...anagement Applications This chapter describes how to configure Management functions for administration Chapter 6 Macintosh Setup This chapter provides instructions on how to set up your Macintosh computers in your network Chapter 7 Trouble Shooting This chapter describes any potential problems you may encounter and the suggested remedies Conventions The following explains the conventions used thro...

Page 7: ...thernet or 1000Mbps Gigabit Ethernet With a switched Ethernet each sender and receiver has the full bandwidth Fast Ethernet is defined by the as the IEEE 802 3u standard a high speed version of Ethernet with 100Mbps transmission rate Wireless LAN Wireless Local Area Network systems WLANs transmit and receive data through the air by using radio frequency RF This offers some advantages like mobility...

Page 8: ...ses NAT to allow all of your network s PCs to connect to the Internet using only one purchased IP address Supports PPPoE that enable user to seamlessly connect to ISPs with the familiar dial up connection interface Built in web based user interface for easy configuration and management through common web browsers such as Netscape Communicator 6 0 or later and Internet Explorer 5 0 or later Built i...

Page 9: ...ty Router User Guide 5 Package Contents After carefully unpacking the shipping carton check the contents listed below Router Power Adapter User s Manual The High Performance Wireless Router Power Adapter User s Manual ...

Page 10: ...Broadband Security Router User Guide 6 ...

Page 11: ...er to the model on your hand to find proper description LED Status Description Power Green Steady on when the power is on Diag Red Lights up during system checking connections and internal operation when the power is first switched on If the device works properly the light should switch off automatically WLAN Link Act Green Steady on when the wireless AP is enabled When the wireless AP is disabled...

Page 12: ...r longer than 3 seconds Note If you are Macintosh users please refer to Chapter 6 Macintosh Setup for more detailed information about configuring TCP IP hardware installation and so on System Requirements To connect to the Internet an external ADSL or Cable modem and an Internet access account from an ISP is required In order to operate with the High Performance Wireless Router each PC that is to ...

Page 13: ...your PCs 1 Click the Start button Choose Settings then Control Panel Double click the Network icon Your Network window should appear as follows 2 Select the Configuration tab Important For Windows 2000 Windows XP Setting you will find that they differs with Windows 98 ME NT slightly See the following for reference Click the Local Area Connection icon on the lower right hand side of your desktop sc...

Page 14: ...al in the Network window 3 Check whether the TCP IP Protocol has already been installed onto your computer s Ethernet card Note that TCP IP Protocol can be installed for a computer s Dial Up Adapter as well as for the Ethernet card If yes go to step 7 If no click the Add button 4 Double click Protocol in the Select Network Component Type or highlight Protocol then click Add ...

Page 15: ...stall TCP IP 6 After a few seconds you will be returned to the Network window The TCP IP Protocol should now be on the list of installed network components see 3 above 7 Click the Properties button The TCP IP Properties window consists of several tabs Choose the IPAddress tab 8 Select Obtain an IP address automatically Click OK Restart your PC to complete the TCP IP installation ...

Page 16: ...users To set up computers with fixed IP Addresses go to the IPAddress tab of the TCP IP Properties window as shown above Select Specify an IP address and enter 192 168 1 xxx in the IPAddress location where xxx is a number between 2 and 254 used by the High Performance Wireless Router to identify each computer and the default Subnet Mask 255 255 255 0 Note that no two computers on the same LAN can ...

Page 17: ...elect Enable DNS Enter the DNS IP Address obtained from your ISP in the Server Search Order location Then click the Add button Click on the Gateway tab and enter the High Performance Wireless Router s default gateway value 192 168 1 1 in the New gateway field then click Add Button ...

Page 18: ...Broadband Security Router User Guide 14 Click OK Restart your PC to complete the TCP IP installation ...

Page 19: ... by your ISP Provided by some ISPs Host Name Domain Name IP address given by ISP Obtain IP Address automatically Static IP IP Address ____ ____ ____ ____ Subnet Mask ____ ____ ____ ____ Default Gateway ____ ____ ____ ____ DNS Server Primary ____ ____ ____ ____ DNS Server Secondary ____ ____ ____ ____ DNS Server Third ____ ____ ____ ____ PPP authentication PPPoE PPTP Login Name Password ___________...

Page 20: ...st Name This entry is required by certain ISPs Domain Name This entry is required by certain ISPs Time Zone Select the time zone of your location from the drop down list Private IPAddress The Device IP Address and Subnet Mask of the router are used for the internal LAN The default values are 192 168 1 1 for the IP Address and 255 255 255 0 for the Subnet Mask Wireless Check Enable or Disable to ma...

Page 21: ... to insure data security To code decode the data transmission all points must use the identical key To make the WEP encryption active or inactive select Mandatory or Disable WEP Key Setting As the WEP is active click the button of WEP Key Setting to go to the setting page Select 64Bit or 128Bit encryption algorithm from the drop down list There are two ways to generate WEP key Passphrase Enter a a...

Page 22: ... ISP s assignment If you are unsure which connection type you currently use contact your ISP to obtain the correct information Obtain IP automatically It is the default option for the router If your ISP automatically assigns an IP address and other values to the High Performance Wireless Router leave them there without making any changes Static IP The WAN IP Address and Subnet Mask of the router e...

Page 23: ...e password your ISP provides you Connect on demand It is a utility used to trigger the PPPoE session when there is a packet being sent through the WAN port while it is on disconnected situation Check the radio button to make this function active and then you must enter the number of minutes you wish the network to remain idle before disconnection occurs in the Max Idle Time location Keep Alive Thi...

Page 24: ...t is on disconnected situation Check the radio button to make this function active and then you must enter the number of minutes you wish the network to remain idle before disconnection occurs in the Max Idle Time location Keep Alive This function keeps your RAS connection enable even if it remains idle However in some situation RAS session cannot be established immediately after disconnection Thi...

Page 25: ...your ISP provides you an Alcatel Speed TouchTM modem it is suggested that you enter the 10 0 0 138 in this column User Name Enter the user name provided by your ISP Password Enter the password provided by your ISP Connect on demand It is a utility used to trigger the PPTP session when there is packet being sent through the WAN port while it is on disconnected situation Check the radio button to ma...

Page 26: ...d situation Check the radio button to make this function active and then you must enter the number of minutes you wish the network to remain idle before disconnection occurs in the Max Idle Time location Keep Alive This function keeps your HBS connection enable even if it remains idle However in some situation HBS session cannot be established immediately after disconnection This is because the sy...

Page 27: ...IP Addresses to each computer in your network Unless you already have one in you LAN it is highly recommended that you set your router to act as a DHCP server Dynamic IPAddress Select Enable to use the DHCP server option of the router If you already have a DHCP server in your network set the router s DHCP option to Disable Starting IPAddress Enter a numerical value from 2 to 254 for the DHCP serve...

Page 28: ...rt is TCP IP For example through WINS the two PCs that belong to different subnet can locate each other by name Enter the IP address of WINS server and it will be assigned to DHCP clients DHCP Clients Table Click the DHCP Clients Table button to show current DHCP client information Apply Click this button after making any changes for activating the settings Undo Click this button if you are not sa...

Page 29: ...rt numbers which are used by the applications you wish to be blocked Here is an example for the IP Access Setting Enter the range of 51 80 in the Filter Group column and 20 80 in the Block port Range column then click Apply button As the result the user s computers which have IP Addresses in the range of 192 168 1 51 to 192 168 1 80 will not be able to use the applications which use port numbers f...

Page 30: ...tions Show URL Log URL Log allows network administrators to check the URL access records Click the button of Show URL Log to go to the URL Filter Log table This table lists the users computers by their IP Addresses the access status and their URL Access destinations Private MAC Filter This function allows network administrators to use the MAC addresses of PCs to restrict users computers from acces...

Page 31: ...this application it is recommended you use a fixed Public IP Address from your ISP Note that your High Performance Wireless Router supports only one server of any particular type This router also supports UPnP Forwarding You can use either Virtual Server Settings or UPnP Forwarding by clicking the button to change setting page Please note that do not set the same function server to different IP Ad...

Page 32: ...onnection port number The client side should select passive mode and use the same port number entered here Server IPAddress Enter the appropriate IP Addresses of the service computers Apply Click this button after making any changes for activating the settings Undo Click this button if you are not satisfied with the settings in this page before clicking Apply Example If the service port number 80 ...

Page 33: ...for interoperability Currently this function supported by this device allows you to set virtual server from Windows OS that supports UPnP such as Windows XP UPnP Function Check Enable will allow LAN side PCs that support UPnP to set virtual server Before you enable the UPnP Forwarding you have to set up individual network computers to act as servers and configure each with a fixed IP Address In th...

Page 34: ...ter the appropriate IP Addresses of the service computers in the Redirect IPAddress locations Enable Check to make this forwarding setting active Apply Click this button after making any changes for activating the settings Undo Click this button if you are not satisfied with the settings in this page before clicking Apply Example If the service port number 80 80 representing an HTTP web address is...

Page 35: ...p a LAN PC to act as a DMZ Host you should configure it using a fixed IP Address Note In the One Page Setup screen ensure the Private IP Address is set to the High Performance Wireless Router s default setting of 192 168 1 1 In the Public IP Address area select Specify an IP Address and then enter the IP Address and other necessary information provided by your ISP Click the DMZ Host option in the ...

Page 36: ... RIP 2 to enable the TX transmit function RIP 1 is the protocol used by older routers Newer routers should use RIP 2 RIP 1 Compatible servers to broadcast RIP 1 and multicast RIP 2 RX From the drop down list select one of the routing information types RIP 1 or RIP 2 to enable the RX receive function Show Routing Table Click this button after clicking Apply to see current routing information Apply ...

Page 37: ...reless Router through another router destination LAN Up to 20 route entries may be input into the High Performance Wireless Router The diagram below gives an example of the physical connections required to use Static Routing In the above diagram PC2 in LAN 2 is connected to the High Performance Wireless Router via another router while PC1 in LAN 1 is connected to the High Performance Wireless Rout...

Page 38: ...example enter 192 168 1 2 in the Default Gateway field Hop Count Enter the number of hops required between the LANs to be connected The Hop Count represents the cost of the routing transmission The default value is 1 Interface Choose LAN if the Destination LAN is on your Router s LAN side and choose WAN if the Destination LAN is on the Router s WAN side Show Routing Table Click this button after c...

Page 39: ...tbound The Outgoing Control Port Numbers act as the trigger When the High Performance Wireless Router detects the outgoing packets with these port numbers it will allow the inbound packets with the Incoming Port Numbers that you set in the next column to pass through the High Performance Wireless Router Incoming Port Range Enter the port number or range numbers the inbound packets carry Apply Clic...

Page 40: ...to provide synchronization among the stations in wireless LAN RTS Threshold RTS packet is use to account for potential hidden stations This feature allows you to set the size of RTS packet Fragmentation Threshold If the length of data frame needing transmission exceeds the fragmentation threshold you set in the column the data frame will be fragmented If there is significant interference or high u...

Page 41: ... key with Wireless Router When the MAC Filter function is disabled the background color is gray You can add the MAC addresses showing in this table to the Wireless MAC Filter List table by checking the box beside these MAC addresses If the MAC Filter function is enabled Green Background When the wireless client MAC addresses showing in this table have been entered into the Wireless MAC Filter List...

Page 42: ...nternet actually runs on IP Addresses which are numerical order for example 66 37 215 53 These IP Address identify the location of each device connected to Internet However the human brain does not easily remember this numbering system so a system that allocate domain name such as www dyndns org provides an easier method If you type 66 37 215 53 or www dyndns org in the web browser s address bar t...

Page 43: ...ed to apply to DynDNS org to be able to use the service Please visit www dyndns org for further information DDNS Service Check the Enable option if you wish to activate this function Username After you have applied for the DDNS service from DynDNS org you will be issued with a Username Enter this username in the Username field Password DynDNS org will also issue you with a password Enter the detai...

Page 44: ...Broadband Security Router User Guide 40 settings Update After clicking Apply to invoke the DDNS settings you have to click this button to refresh the settings ...

Page 45: ...his feature allows the administrator to manage the High Performance Wireless Router by setting certain parameters For security reasons it is strongly recommended that you set Passwords and so that only authorized persons are able to magage this High Performance Wireless Router If the Password is left blank all users on your network can access this router simply by entering the unit s IP Address in...

Page 46: ...ers change their access equipment External Admin Check Enable to allow you to configure the High Performance Wireless Router from the WAN side To access the setting page from the external side enter http WAN IPAddress 8080 into the web browser address bar and press the Enter key MTU Check Enable if you want to set a maximum limitation for incoming and outgoing packet size Enter the maximum packet ...

Page 47: ...t is absolutely necessary Apply Click this button after making any changes for activating the settings Undo Click this button if you are not satisfied with the settings in this page before clicking Apply Status Monitor This screen shows the router s current status All of the information provided is read only Product Name This field shows the name of this router Firmware Version This field shows th...

Page 48: ... you selected Static IP in One Page Setup Public IP Address the information will be the same as your input DHCP Release Click this button to eliminate the IP address obtained from DHCP server DHCP Renew Click this button to refresh the IP address from DHCP server Note that the DHCP Release and DHCP Renew button only show up when you select Get IP Address Automatically in the OnePage Setup Intranet...

Page 49: ...ail server You may find this information when you apply for e mail service from your ISP E mail Alert to Enter the e mail address you wish to send to Return Address Enter the e mail address you wish to send to if the alert e mail cannot be sent to the address above Log Schedule Select from the drop down list that when you wish the alert e mail will be send When Log is Full The alert e mail will be...

Page 50: ...ting back Backup Click Backup button save the current configuration as a backup file in your hard disk Restore Enter path of the configuration file you saved on the PC You can click Browse to view the folders and select the file Click Restore to retrieve it Upgrade Firmware This setting page allows you to upgrade the latest version firmware to keep your router up to date Before you upgrade the fir...

Page 51: ...pgrade to proceed firmware upgrade process Please note that don t power off the router during the firmware upgrading Diagnostic Ping This function allows you to test the connection between router and LAN or between router and Internet Ping This page allows you to set configuration for diagnostic ping After filling in the parameters for your requirement click Start to begin the connection testing S...

Page 52: ...ime between two packets Time out Enter the number of time regarding as no response after starting to ping the destination device Start Click this button to begin the ping test Ping Result The result will show the numbers of sending packet numbers of packet receiving and the average return time Tracert To trace the route between the router and a certain device you can type in the IP address of that...

Page 53: ...gh Performance Wireless Router s DHCP server Dynamic IP Addressing using DHCP Server 1 From the Apple menu select Control Panel and click on TCP IP 2 In the TCP IP A New Name For Your Configuration window select Ethernet in the Connect via location from the drop down list 3 In the Setup area select Using DHCP Server in the Configure location from the drop down list No other data needs to be entere...

Page 54: ...ve to be configured to connect to the Internet via the High Performance Wireless Router 1 From the Apple menu select Control Panel and click on TCP IP 2 From the File menu select Configurations and select your existing network configuration Click Duplicate 3 Rename your existing configuration Click OK and Make Active 4 In the Setup area select Manually in the Configure location from the drop down ...

Page 55: ...68 1 254 and is therefore compatible with the High Performance Wireless Router s default IP address of 192 168 1 1 3 3 Check also the Subnet Mask is set to 255 255 255 0 Q The DIAG LED stays lit The DIAG LED should light up when the device is first powered up to indicate it is checking for proper operation After a few seconds the LED should go off If it stays lit the device is experiencing a probl...

Page 56: ... page why Some ISPs such as Home require that their host name be specifically configured into your computer before you can surf their local web pages If you are unable to access your ISP s home page enter your ISP s Domain Name into the OnePage Setup to enable all computers in your LAN access to it If you only want to allow computers to access these home pages open the TCP IP Properties window on ...

Page 57: ...ss and supports only the TCP IP Protocol If your Novell or Apple system is configured with TCP IP the High Performance Wireless Router can support them Q Does the High Performance Wireless Router support 100Mb Ethernet A Yes the High Performance Wireless Router supports both 10Mb 100Mb Ethernet on the LAN side Q What is NAT and what is it used for A The Network Address Translation NAT Protocol tra...

Page 58: ...only see the IP of the High Performance Wireless Router but cannot access LAN computers The LAN computers are well protected with the High Performance Wireless Router s natural firewall Q When should I use DMZ host A Enable DMZ host when you want to have unrestricted communication between your PC and the Internet for example playing Internet games i e Ages of Empire or having multimedia conference...

Page 59: ...0Mbps auto sensing Ethernet RJ 45 One Wireless Access Point Management Web based UI Management LED Display Power DIAG WLAN Enable Activity WAN and LAN port s Link Activity Environment Operation Temperature 0 40 degrees C 32 104 degrees F Storage Temperature 20 60 degrees C 4 140 degrees F Humidity Operating 10 85 non condensing Storage 5 to 90 Non Condensing Dimension 87 L x 150 W x 30 H mm 3 4 x ...

Page 60: ...Broadband Security Router User Guide 56 Mounting Desktop Wall mounting ...

Page 61: ...other network resources Adapter A device that makes the connection to a network segment such as Ethernet modem cards and adapters ADSL Asymmetric Digital Subscriber Line ADSL as it s name indicates is an asymmetrical data trasmission technology with higher traffic rate downstream and lower traffic rate upstream ADSL technology satisfies the bandwidth requirements of applications which demand asymm...

Page 62: ...me that identifies one or more IP Addresses For example the domain name microsoft com represents about a dozen IP Addresses Domain names are used in URLs to identify particular Web pages For example in the URL http www pcwebopedia com index html the domain name is pcwebopedia com DoS DoS is the abbreviation for Denial of Service This occurs when a computer or network is overwhelmed to the point th...

Page 63: ...cess control policy between an organisation s networks and the Internet IEEE Short for Institute of Electrical and Electronics Engineers an organization best known for developing standards for the computer and electronics industry Internet A global network connecting millions of computers for the exchange of data news and opinions Intranet A network based on the TCP IP Protocol an internet belongi...

Page 64: ...l Local Area Network LAN A computer network that spans a relatively small area Most LANs are confined to a single building or group of buildings However one LAN can be connected to other LANs over any distance via telephone lines and radio waves A system of LANs connected in this way is called a wide area network WAN MAC Address Short for Media Access Control Address and in a hardware address that...

Page 65: ...ds Ethernet and the Point to Point Protocol It s a communications protocol for transmitting information between devices from different manufacturers over an Ethernet PPTP Short for Point to Point Tunneling Protocol PPTP encapsulates the packet for transmission over the Internet It is similar to creating a private tunnel over a large public network and has almost equal security to a private network...

Page 66: ...te Network Via access control and encryption VPN brings the same security to data transmission through the Internet as if it being transmitted through a private network It not only takes advantage of economies of scale but also ensures high level security while the packet is sent over the large public network Wide Area Network WAN A system of LANs being connected by telephone lines and radio waves...

Page 67: ... Statement The equipment complies with FCC RF radiation exposure limits set forth for an uncontrolled environment This equipment should be installed and operated with a minimum distance of 20 centimeters between the radiator and your body 3 This Transmitter must not be co located or operating in conjunction with any other antenna or transmitter 4 Changes or modifications to this unit not expressly...

Reviews: