background image

 

47

 4.6.4 VPN setting

 

 

 

VPN Settings are settings that are used to create virtual private tunnels to remote VPN gateways. The 

tunnel technology supports data confidentiality, data origin authentication and data integrity of network 

information by utilizing encapsulation protocols, encryption algorithms, and hashing algorithms.   

 VPN enable item 

VPN protects network information from ill network inspectors. But it greatly degrades network throughput. 

Enable it when you really need a security tunnel. It is disabled for default.   

 

Max. number of tunnels item

 

Since VPN greatly degrades network throughput, the allowable maximum number of

 

tunnels is limited. 

Be careful to set the value for allowing the number of tunnels can be created simultaneously. Its value 

ranges from 1 to 5.   

 

Tunnel name

 

Indicate which tunnel that is focused now.   

 

Method

 

IPSec VPN supports two kinds of key-obtained methods: manual key and automatic key exchange. 

Manual key approach indicates that two end VPN gateways setup authenticator and encryption key by 

system managers manually. However, IKE approach will perform automatic Internet key exchange. 

System managers of both end gateways only need set the same pre-shared key.   

Summary of Contents for FBR-1407

Page 1: ...1 LevelOne FBR 1407 ADSL Firewall VPN router w Printer Server User s Manual...

Page 2: ...s manual may cause harmful interference to radio communications Operation of this equipment in a residential area is likely to cause interference in which case the user at his own expense will be requ...

Page 3: ...Your Computer 10 3 2 Install the Software into Your Computers 11 Chapter 4 Configuring ADSL Broadband Router 13 4 1 Start up and Log in 13 4 2 Status 14 4 3 Wizard 15 4 4 Basic Setting 17 4 4 1 Prima...

Page 4: ...ult 70 4 8 5 Reboot 70 4 8 6 Miscellaneous Items 71 Chapter 5 Print Server 72 5 1 Configuring on Windows 95 98 Platforms 72 5 2 Configuring on Windows NT Platforms 75 5 3 Configuring on Windows 2000 a...

Page 5: ...nted packets from outside intruders are blocked to protect your Intranet DHCP server supported All of the networked computers can retrieve TCP IP settings automatically from this product Web based con...

Page 6: ...ress to use for outgoing IP data grams If you have more than one routers and subnets you will need to enable routing table to allow packets to find proper routing path and allow different subnets to c...

Page 7: ...roduct M1 System status 1 Green Blinking This product is functioning properly On The ADSL is linked Show time ADSL status1 Green Blinking This router is trying to connect to your ISP ADSL Act ADSL sta...

Page 8: ...sed and watch the M1 LED when they flash 8 times then release the reset button 2 2 Procedure for Hardware Installation LevelOne FBR 1407 can be positioned at any convenient place in your office or hou...

Page 9: ...Connecting LevelOne FBR 1407 with your printer Use the printer cable to connect your printer to the printer port of this product 4 Power on Connecting the power cord to power inlet and turning the pow...

Page 10: ...otocol you can use the ping command to check if your computer has successfully connected to this product The following example shows the ping procedure for Windows 95 platforms First execute the ping...

Page 11: ...the CD ROM drive The following window will be shown automatically If it isn t please run install exe on the CD ROM Step 2 Click on the INSTALL button Wait until the following Welcome dialog to appear...

Page 12: ...5 Select the item to restart the computer and then click the OK button to reboot your computer Step 6 After rebooting your computer the software installation procedure is finished Now you can configur...

Page 13: ...uct s IP address in the Location for Netscape or Address for IE field and press ENTER For example http 192 168 123 254 After the connection is established you will see the web user interface of this p...

Page 14: ...ck this button to renew or release IP manually B Printer Status The possible kinds of printer status include Ready Not ready Printing and Device error When a job is printing there may appear a Kill Jo...

Page 15: ...oth Annex B and U R2 ADSL line coding schemes The default setting is Annex B If your ISP used U R2 scheme you have to change the line oding scheme to U R2 and then reboot this product to successfully...

Page 16: ...16 Setup Wizard will guide you through a basic configuration procedure step by step Press Next Setup Wizard Select WAN Type For detail settings please refer to 4 4 1 primary setup...

Page 17: ...17 4 4 Basic Setting...

Page 18: ...18 4 4 1 Primary Setup WAN Type Press Change...

Page 19: ...f your ISP You can click Change button to choose a correct one from the following five options A Ethernet Over ATM RFC 1483 Bridged without NAT B Ethernet Over ATM RFC 1483 Bridged with NAT C IP over...

Page 20: ...ubnet Mask WAN Gateway and Primary Secondary DNS These settings are also specified by your ISP VPI VCI Numbers The channel settings provided by your ISP Schedule Type The setting of the ADSL traffic s...

Page 21: ...ddress ISP assigns you a static IP address WAN IP Address Subnet Mask Gateway Primary and Secondary DNS enter the proper setting provided by your ISP You can click the Clone MAC button to copy the MAC...

Page 22: ...s this product to renew your IP address automatically when the lease time is expiring even when the system is idle You can click the Clone MAC button to copy the MAC address of your PC and set it to b...

Page 23: ...ic mode it will try to get a legal IP and WAN settings from ISP s DHCP server If you select static mode you have to set the following WAN setting manually WAN IPAddress WAN Subnet Mask WAN Gateway and...

Page 24: ...Flash memory and the reboot this device 4 3 2 4 Classical IP over ATM RFC 1577 In the Classical IP over ATM Mode NAT is always enabled You have to set the following WAN IP settings WAN IP Mode This pr...

Page 25: ...his device VPI VCI Numbers The channel settings provided by your ISP Schedule Type The setting of the ADSL traffic schedule type This device supports UBR Un specified bit rate and CBR Constant bit rat...

Page 26: ...isable this feature If Auto reconnect is enabled this product will automatically connect to ISP after system is restarted or connection is dropped VPI VCI Numbers The channel settings provided by your...

Page 27: ...s Optional Required by some ISPs Once you finished the required configuration you must click on the Save button to save the configuration into Flash memory and the reboot this device 4 3 2 6 PPP over...

Page 28: ...tem is restarted or connection is dropped VPI VCI Numbers The channel settings provided by your ISP Schedule Type The setting of the ADSL traffic schedule type This device supports UBR Un specified bi...

Page 29: ...f OAM Function Activation De activation loopback and Fault Management individually Then click on the Save button to finish the configuration of the selected session Once you set the appropriate OAM se...

Page 30: ...30 4 4 2 DHCP Server Press More...

Page 31: ...1 DHCP Server Choose Disable or Enable 2 Lease Time this feature allows you to configure IP s lease time DHCP client 3 IP pool starting Address IP pool starting Address Whenever there is a request the...

Page 32: ...32 4 4 3 Change Password You can change Password here We strongly recommend you to change the system password for security reason...

Page 33: ...33 4 5 Forwarding Rules...

Page 34: ...al Server Mapping A virtual server is defined as a Service Port and all requests to this port will be redirected to the computer specified by the Server IP For example if you have an FTP server port 2...

Page 35: ...of Special Applications fails to make an application work try setting your computer as the DMZ host instead 1 Trigger the outbound port number issued by the application 2 Incoming Ports when the trig...

Page 36: ...o be exposed to unrestricted 2 way communication for Internet games Video conferencing Internet telephony and other special applications NOTE This feature should be used only when needed Non standard...

Page 37: ...37 4 6 Security Settings...

Page 38: ...Allow all to pass except those match the specified rules 2 Deny all to pass except those match the specified rules You can specify 8 rules for each direction inbound or outbound For each rule you can...

Page 39: ...sabled individually Inbound Filter To enable Inbound Packet Filter click the check box next to Enable in the Inbound Packet Filter field Suppose you have SMTP Server 25 POP Server 110 Web Server 80 FT...

Page 40: ...read net news port 119 and transfer files via FTP port 21 Others are all allowed After Inbound Packet Filter setting is configured click the save button Outbound Filter To enable Outbound Packet Filt...

Page 41: ...10 and browse Internet port 80 port 53 DNS is necessary to resolve the domain name 192 168 123 10 192 168 123 20 They can do everything block nothing Others are all blocked Example 2 192 168 123 100 1...

Page 42: ...42 Others are allowed After Outbound Packet Filter setting is configured click the save button...

Page 43: ...n when someone accesses the specific URLs Privilege IPAddresses Range Setting a group of hosts and privilege these hosts to access network without restriction Domain Suffix A suffix of URL to be restr...

Page 44: ...record in log file 2 URL include girl com will not be blocked but the action will be record in log file 3 URL include erotica com will be blocked but the action will not be record in log file 4 IP ad...

Page 45: ...tings in this page will take effect only when Enable is checked Connection control Check Connection control to enable the controlling of which wired clients can connect to this device If a client is d...

Page 46: ...ce In this page we provides the following Combobox and button to help you to input the MAC address You can select a specific client in the DHCP clients Combobox and then click on the Copy to button to...

Page 47: ...It is disabled for default Max number of tunnels item Since VPN greatly degrades network throughput the allowable maximum number of tunnels is limited Be careful to set the value for allowing the num...

Page 48: ...e gateway and pre shared key The tunnel name is derived from previous page of VPN setting IKE proposal setup includes the setting of a set of frequent used IKE proposals and the selecting from the set...

Page 49: ...KE proposal Click the button to setup a set of frequent used IKE proposals and select from the set of IKE proposals for the dedicated tunnel proposals for the dedicated tunnel Select IPSec proposal Cl...

Page 50: ...nges from 300 seconds to 172 800 seconds If the value of unit is KB the value of life time represents the maximum allowable amount of transmitted packets through the dedicated VPN tunnel between both...

Page 51: ...c proposal to be focused First char of the name with 0x00 value stands for the proposal is not available DH group There are three groups can be selected group 1 MODP768 group 2 MODP1024 group 5 MODP15...

Page 52: ...480 KBs to 2 147 483 647 KBs Life time unit There are two units can be selected second and KB Proposal ID The identifier of IPSec proposal can be chosen for adding the proposal to the dedicated tunne...

Page 53: ...ddress is 0 0 0 0 any host can connect to this product to perform administration task You can use subnet mask bits nn notation to specified a group of trusted IP addresses For example 10 1 2 0 24 NOTE...

Page 54: ...54 4 7 Advanced Setting...

Page 55: ...tly added to the calculated Target Noise margin It should be ranged between 3dB and 3dB with a granularity of 0 5 dB The default value is set to 0 dB no offset Max Bits per Tone The value of this para...

Page 56: ...llows user to reduce the Tx output power in the upstream direction The value should be ranged between 0 and 10 dBm Rx Output Power Offset This parameter allows user to reduce the Rx output power The v...

Page 57: ...d Time by NTP Protocol Time Server Select a NTP time server to consult UTC time Time Zone Select a time zone where this device locates Set Date and Time manually Selected if you want to Set Date and T...

Page 58: ...mail Alert Enable Check if you want to enable Email alert send syslog via email SMTP Server IP and Port Input the SMTP server IP and port which are concated with If you do not specify port number the...

Page 59: ...our current IP address which changes each time you connect your Internet service provider Before you enable Dynamic DNS you need to register an account on one of these Dynamic DNS servers that we list...

Page 60: ...60 You will get this information when you register an account on a Dynamic DNS server Example After Dynamic DNS setting is configured click the save button...

Page 61: ...values and monitoring network events Enable SNMP You must check either Local or Remote or both to enable SNMP function If Local is checked this device will response request from LAN If Remote is chec...

Page 62: ...device will response to SNMP client which s get community is set as public 2 This device will response to SNMP client which s set community is set as private 3 This device will response request from...

Page 63: ...outing path and allow different subnets to communicate with each other Routing Table settings are settings used to setup the functions of static and dynamic routing RIP Enable Check to enable RIP func...

Page 64: ...168 3 88 it would use the above table to determine that it had to go via 192 168 1 33 a gateway And if it sends Packets to 192 168 5 77 will go via 192 168 1 55 Each rule can be enabled or disabled i...

Page 65: ...decide which service will be turned on or off Select the enable item Press Add New Rule You can write a rule name and set which day and what time to schedule from Start Time to End Time The following...

Page 66: ...66 After configure Rule 1...

Page 67: ...Enable Selected if you want to Enable the Scheduler Edit To edit the schedule rule Delete To delete the schedule rule and the rule of the rules behind the deleted one will decrease one automatically...

Page 68: ...68 4 8 1 View Log You can View system log by clicking the View Log button...

Page 69: ...69 4 8 2 Firmware Upgrade You can upgrade firmware by clicking Firmware Upgrade button...

Page 70: ...bin file Once you want to restore these settings please click Firmware Upgrade button and use the bin file you saved 4 8 4 Reset to default You can also reset this product to factory default by click...

Page 71: ...re the target device must be Wake on LAN enabled and you have to know the MAC address of this device say 00 11 22 33 44 55 Clicking Wake up button will make the router to send the wake up frame to the...

Page 72: ...er you finished the software installation procedure described in Chapter 3 your computer has possessed the network printing facility provided by this product For convenience we call the printer connec...

Page 73: ...73 1 Find out the corresponding icon of your server printer for example the HP LaserJet 6L Click the mouse s right button on that icon and then select the Properties item...

Page 74: ...item Be sure that the Printer Driver item is configured to the correct driver of your server printer 4 Click on the button of Port Settings Type in the IP address of this product and then click the O...

Page 75: ...edure for a Windows NT platform is similar to that of Windows 95 98 except the screen of printer Properties Compared to the procedure in last section the selection of Details is equivalent to the sele...

Page 76: ...and XP Platforms Windows 2000 and XP have built in LPR client users could utilize this feature toPrint You have to install your Printer Driver on LPT1 or other ports before you preceed the following...

Page 77: ...77 2 Select Ports page Click Add Port...

Page 78: ...78 3 Select Standard TCP IP Port and then click New Port 4 Click Next and then provide the following information Type address of server providing LPD that is our NAT device 192 168 123 254...

Page 79: ...79 5 Select Custom then click Settings 6 Select LPR type lp lowercase letter in Queue Name...

Page 80: ...80 And enable LPR Byte Counting Enabled 7 Apply your settings...

Page 81: ...81 5 4 Configuring on Unix based Platforms Please follow the traditional configuration procedure on Unix platforms to setup the print server of this product The printer name is lp...

Page 82: ...y A 1 Install TCP IP Protocol into Your PC 1 Click Start button and choose Settings then click Control Panel 2 Double click Network icon and select Configuration tab in the Network window 3 Click Add...

Page 83: ...ick Network icon Select the TCP IP line that has been associated to your network card in the Configuration tab of the Network window 3 Click Properties button to set the TCP IP protocol for this NAT R...

Page 84: ...84...

Page 85: ...85 b Don t input any value in the Gateway tab c Choose Disable DNS in the DNS Configuration tab...

Page 86: ...P address of this product is 192 168 123 254 So please use 192 168 123 xxx xxx is between 1 and 253 for IP Address field and 255 255 255 0 for Subnet Mask field b In the Gateway tab add the IP address...

Page 87: ...utton Appendix B Main ISP setting for ADSL modem configuration Argentina Argentina Telecom Encapulation RFC 1483 Bridge LLC VPI 0 VCI 33 Handshack protocal Autosense G dmt first Belgium Belgacom Encap...

Page 88: ...VPI 0 VCI 33 Handshack protocal G dmt Helsinki Encapulation RFC 1483 Bridge LLC VPI 0 VCI 100 Handshack protocal Autosense G dmt first France France Telecom Encapulation RFC 2364 PPPoA VC Mux VPI 8 V...

Page 89: ...PI 1 VCI 32 Handshack protocal Autosense G dmt first Israel Israel Encapulation RFC 2364 PPPoA VC Mux VPI 8 VCI 48 Handshack protocal Autosense G dmt first Italy Italy Encapulation RFC 2364 PPPoA VC M...

Page 90: ...35 Handshack protocal Autosense G dmt first New Zealand New Zealand Telecom Encapulation RFC 2364 PPPoA VC Mux VPI 0 VCI 100 Handshack protocal Autosense G dmt first Portugal PT Encapulation RFC 2516...

Page 91: ...C 2364 PPPoA VC Mux VPI 0 VCI 38 Handshack protocal Autosense G dmt first Encapsulation RFC 2364 PPPoA VC Mux RFC 2364 PPPoA LLC RFC 1483 Bridge LLC RFC 1483 Routed LLC RFC 1483 Bridge VC Mux RFC 1483...

Page 92: ...92 VCI 32 65535...

Reviews: