background image

 

 

 

Key Features 

 

Features 

Advantages 

Incredible Data Rate up to 

300Mbps* 

Heavy data payloads such as 

MPEG video streaming 

IEEE 802.11n Compliant and 

backwards compatible with 

802.11b/g 

Fully Interoperable with IEEE  

802.11b / IEEE802.11g 

compliant devices with legacy 

protection 

Four 10/100/1000 Mbps Gigabit 

Switch Ports (Auto-Crossover) 

Scalability, extend your network. 

 

Firewall supports Virtual Server 

Mapping, DMZ, IP Filter, ICMP 

Blocking, SPI 

Avoids the attacks of Hackers or 

Viruses from Internet 

Support 802.1x authenticator, 

802.11i (WPA/WPA2, AES), VPN 

pass-through  

Provide mutual authentication 

(Client and dynamic encryption 

keys to enhance security 

WDS (Wireless Distribution System) 

Make wireless AP and Bridge 

mode simultaneously as a 

wireless repeater 

Sitecom Cloud Security 

Protect your home against 

cybercrime while browsing. 

 

* Theoretical wireless signal rate based on IEEE standard of 802.11a, b, g, n chipset used. Actual 

throughput  may  vary.  Network  conditions  and  environmental  factors  lower  actual  throughput  rate. 

All specifications are subject to change without notice. 

Summary of Contents for N600 X5

Page 1: ...WLR 5001 Wireless Gigabit VPN Router N600 X5 802 11a b g n ...

Page 2: ...QUIREMENTS 11 6 WLR 5001 PLACEMENT 11 7 SETUP LAN WAN 12 8 PC NETWORK ADAPTER SETUP 13 9 BRING UP THE WLR 5001 17 10 INITIAL SETUP WLR 5001 17 11 CONFIGURATION WIZARD 26 11 1 Connecting to an external VPN service 27 12 WIRELESS SETTINGS 32 13 FIREWALL SETTINGS 42 14 ADVANCED SETTINGS 48 15 VPN 57 16 TOOLBOX SETTINGS 106 ...

Page 3: ...ion contained in this manual was correct at the time of publication However as our engineers are always updating and improving the product your device s software may have a slightly different appearance or modified functionality than presented in this manual ...

Page 4: ... WEP WPA or WPA2 encryption With the built in DHCP Server powerful SPI firewall the WLR 5001 protects your computers against intruders and most known Internet attacks and also provides safe VPN pass through With the incredible speed and QoS function of 802 11n the WLR 5001 is ideal for media centric applications like streaming video gaming and VoIP telephony to run multiple media intense data stre...

Page 5: ... SPI Avoids the attacks of Hackers or Viruses from Internet Support 802 1x authenticator 802 11i WPA WPA2 AES VPN pass through Provide mutual authentication Client and dynamic encryption keys to enhance security WDS Wireless Distribution System Make wireless AP and Bridge mode simultaneously as a wireless repeater Sitecom Cloud Security Protect your home against cybercrime while browsing Theoretic...

Page 6: ...listed below are missing Do not discard the packing materials in case of return the unit must be shipped back in its original package 1 The WLR 5001 Router 2 A 100V 240V to 12V 1A Switching Power Adapter 3 A Quick Install Guide 4 A CD with User Manual 5 A Warranty card 6 An UTP cable ...

Page 7: ...ter yourself you might damage the router or endanger yourself 3 4 Disposing of the Router When you dispose of the router be sure to dispose it appropriately Some countries may regulate disposal of an electrical device please consult with your local authority 3 5 Others When using this router please do not let it come into contact with water or other liquids If water is accidentally spilled on the ...

Page 8: ...4 Product Layout Port Description Power connector Connect the 12V DC adapter to this port LAN Yellow Connect your PC s or network devices to this port WAN Blue Connect your ADSL Cable modem to this port ...

Page 9: ...details SSID security code and WPS button functionality Button Description WPS BUTTON Press 0 5 seconds for 2 4 GHz WPS mode Press 5 10 seconds for 5 GHz WPS mode Press 10 seconds to reset the router Press 15 Seconds to reset the router to factory defaults ...

Page 10: ...AN Blue Shows the cable is connected LAN Blue Shows the cable is connected LAN Blue Shows the cable is connected WAN Blue Shows the cable is connected WiFi White Shows 5GHz WiFi activity WiFi Blue Shows 2 4GHz WiFi activity Power Red Shows the device is turned on OPS White Shows OPS activity ...

Page 11: ...t RJ 45 PC with a Web Browser Internet Explorer Safari Firefox Opera Ethernet compatible CAT5e cables 6 WLR 5001 Placement You can place the WLR 5001 on a desk or other flat surface or you can mount it on a wall For optimal performance place your Wireless Broadband Router in the center of your home or your office in a location that is away from any potential source of interference such as a metal ...

Page 12: ...7 Setup LAN WAN WAN connection LAN connection ...

Page 13: ...8 PC Network Adapter setup Windows XP Enter Start Menu select Control panel select Network Select Local Area Connection icon select properties ...

Page 14: ...lect Internet Protocol TCP IP Click Properties Select the General tab The WLR 5001 supports a DHCP function please select both Obtain an IP address automatically and Obtain DNS server address automatically ...

Page 15: ...Windows Vista Seven Enter Start Menu select Control panel select View network status and tasks select Manage network connections Select Local Area Connection icon select properties ...

Page 16: ...nternet Protocol Version 4 TCP IPv4 Click Properties Select the General tab The WLR 5001 supports a DHCP function please select both Obtain an IP address automatically and Obtain DNS server address automatically ...

Page 17: ...g the switch on the back of the device The WLR 5001 automatically enters the self test phase During self test phase the Power LED will be lit continuously to indicate that this product is in normal operation 10 Initial Setup WLR 5001 LOGIN procedure 1 OPEN your browser e g Internet Explorer 2 Type http 192 168 0 1 in the address bar and press Enter ...

Page 18: ...n the back label on the bottom of your router 4 Click OK 5 You will see the home page of the WLR 5001 The System status section allows you to monitor the current status of your router the UP time hardware information serial number as well as firmware version information is displayed here ...

Page 19: ...tion is enabled this router will use the spanning tree protocol to prevent network loops DHCP Server Enabled by default You can enable or disable the DHCP server When DHCP is disabled no ip addresses are assigned to clients and you have to use static ip addresses When DHCP server is enabled your computers will be assigned an ip address automatically until the lease time expires Lease Time Forever ...

Page 20: ...esses to your LAN Clients Note default IP range is 192 168 0 100 192 168 0 200 If you want your PC s to have a static fixed IP address then you ll have to choose an IP address outside this IP address Pool Domain Name You can specify a Domain Name for your LAN Or just keep the default sitecomwlr5001 ...

Page 21: ...Device Status View the Broadband router s current configuration settings Device Status displays the configuration settings you ve configured in the Wizard Basic Settings Wireless Settings section ...

Page 22: ...displays whether the WAN port is connected to a Cable DSL connection It also displays the router s WAN IP address Subnet Mask and ISP Gateway as well as MAC address the Primary DNS Press Renew button to renew your WAN IP address ...

Page 23: ...address and expiration time for each DHCP leased client Use the Refresh button to update the available information You can check Enable Static DHCP IP It is possible to add more static DHCP IPs They are listed in the table Current Static DHCP Table IP can be deleted at will from the table Click the Apply button to save the changed configuration ...

Page 24: ... event occurred after system start up At the bottom of the page the system log can be saved Save to a local file for further processing or the system log can be cleared Clear or it can be refreshed Refresh to get the most updated information When the system is powered down the system log will disappear if not saved to a local file ...

Page 25: ...WLR 5001 Statistics Shows the counters of packets sent and received on WAN LAN WLAN ...

Page 26: ...router Here you can choose your internet connection type Depending on the chosen setting you may need to enter your user name and password MAC address or hostname in the following window After you have entered the correct information click Apply to save the settings ...

Page 27: ...et with either of these two methods you may continue with the set up of the VPN connection Once you are sure the WLR 5001 has Internet connectivity please follow the following steps 1 First of all make sure you are connected to the WLR 5001 It does not matter if you are connected either wirelessly or via a cable connected to one of the LAN ports yellow ports of the device 2 Open your web browser a...

Page 28: ...ress but you may also have PPP over Ethernet established as default 5 At this point you must choose the type of VPN connection you want to set up Depending on the VPN service you want to connect to choose out of 5a Connect to a PPTP service Click on the PPTP option in the menu You should see the following page ...

Page 29: ...regarding 1 IP address This is the IP address that the VPN service has assigned to you 2 Subnet mask If you are configuring your IP address statically your VPN service should have provided you with a subnet mask value along with your IP address 3 Default Gateway If connected statically this value is also provided from your VPN service to route packets properly to the VPN server Fill in the Login i...

Page 30: ...ice provider Click on Apply Now your router will save the new configuration and it will restart with the new configuration trying to connect to the VPN server 5b Connect to a L2TP IPSec service Click on the L2TP IPSec option in the menu You should see the following page Although most of the VPN servers will give you an IP address dynamically some VPN servers must be configured statically If you wa...

Page 31: ...service to route packets properly to the VPN server Fill in the Login information to connect to the VPN service VPN servers use this information for user authentication Please fill in the following information 4 Username Password and Shared Key This information must have been provided from your VPN service provider 5 PPTP Gateway This value corresponds to either the domain name or public IP addres...

Page 32: ...the wireless stations to connect to this router for the 2 4Ghz radio or 5Ghz radio The parameters include Mode ESSID Channel Number and Associated Client Wireless Function Enable or Disable Wireless function here Click Apply and wait for module to be ready loaded ...

Page 33: ...mode to allow 802 11b and 802 11g clients at the same time For the 5GHz mode you can set 802 11a 802 11n or 802 11a n mode ESSID This is the name of the wireless signal which is broadcasted All the devices in the same wireless LAN should have the same ESSID Channel The channel used by the wireless LAN All devices in the same wireless LAN should use the same channel ...

Page 34: ...ou select Shared Key you should also setup a WEP key in the Encryption page After this has been done make sure the wireless clients that you want to connect to the device are also setup with the same encryption key Fragment Threshold Fragment Threshold specifies the maximum size of a packet during the fragmentation of data to be transmitted If you set this value too low it will result in bad perfo...

Page 35: ...ance Broadcast ESSID If you enabled Broadcast ESSID every wireless station located within the coverage of this access point can discover this access point easily If you are building a public wireless network enabling this feature is recommended Disabling Broadcast ESSID can provide better security CTS Protection It is recommended to enable the protection mechanism This mechanism can decrease the r...

Page 36: ...s stations use the same security function and are setup with the same security key Disable When you choose to disable encryption it is very insecure to operate the WLR 5001 Enable 802 1x Auth IEEE 802 1x is an authentication protocol Every user must use a valid account to login to this Access Point before accessing the wireless LAN The authentication is processed by a RADIUS server This mode only ...

Page 37: ...lect ASCII Characters alphanumeric format or Hexadecimal Digits in the A F a f and 0 9 range to be the WEP Key Key1 Key4 The WEP keys are used to encrypt data transmitted in the wireless network Use the following rules to setup a WEP key on the device 64 bit WEP input 10 digits Hex values in the A F a f and 0 9 range or 5 digit ASCII character as the encryption keys 128 bit WEP input 26 digit Hex ...

Page 38: ...ption key frequently So the encryption key is not easy to be cracked by hackers This is the best security available WPA Radius Wi Fi Protected Access WPA is an advanced security standard You can use an external RADIUS server to authenticate wireless stations and provide the session key to encrypt data during communication It uses TKIP or CCMP AES to change the encryption key frequently Press Apply...

Page 39: ...ifficulties filling in the fields just click Clear and both MAC Address and Comment fields will be cleared Remove an address from the list If you want to remove a MAC address from the Current Access Control List select the MAC address that you want to remove in the list and then click Delete Selected If you want to remove all the MAC addresses from the list just click the Delete All button Click R...

Page 40: ...n the wireless client or in the utility of the wireless client to start the WPS mode and switch the wireless router to WPS mode You can simply push the WPS button of the wireless router or click the Start to Process button in the web configuration interface If you want to use the PIN code you have to know the PIN code of the wireless client and switch it to WPS mode then fill in the PIN code of th...

Page 41: ...shows the passphrase key that is randomly generated by the wireless router during the WPS process You may need this information when using a device which doesn t support WPS WPS via Push Button Press the button to start the WPS process The router will wait for the WPS request from the wireless devices within 2 minutes WPS via PIN You can fill in the PIN code of the wireless device and press the bu...

Page 42: ...rs thus limiting the risk of hacker attacks and defending against a wide array of common Internet attacks However for applications that require unrestricted access to the Internet you can configure a specific client server as a Demilitarized Zone DMZ Note To enable the Firewall settings select Enable and click Apply ...

Page 43: ...t the virtual server re directs a particular service Internet application e g FTP websites to a particular LAN client server whereas DMZ re directs all packets regardless of services going to your WAN IP address to a particular LAN client server Enable DMZ Enable disable DMZ Public IP Address The IP address of the WAN port or any other Public IP addresses given to you by your ISP Client PC IP Addr...

Page 44: ...f Death Port Scan and Sync Flood If Internet attacks occur the router can log the events Ping of Death Protections from Ping of Death attack Discard Ping From WAN The router s WAN port will not respond to any Ping requests Port Scan Protects the router from Port Scans Sync Flood Protects the router from Sync Flood attack ...

Page 45: ...low Allow If you select Allow then all clients will be denied to access Internet accept for the PCs in the list below Filter client PCs by IP Fill in IP Filtering Table to filter PC clients by IP Add PC You can click Add PC to add an access control rule for users by IP addresses Remove PC If you want to remove some PCs from the IP Filtering Table select the PC you want to remove in the table and t...

Page 46: ...and the fields will be cleared Remove PC If you want to remove some PC from the MAC Filtering Table select the PC you want to remove in the table and then click Delete Selected If you want to remove all PCs from the table just click the Delete All button If you want to clear the selection and re select again just click Reset Click Apply at the bottom of the screen to save the above configuration ...

Page 47: ... address or the keyword of the web site you want to block Remove URL Keyword If you want to remove some URL keywords from the Current URL Blocking Table select the URL keyword you want to remove in the table and then click Delete Selected If you want remove all URL keywords from the table just click Delete All button If you want to clear the selection and re select again just click Reset Click App...

Page 48: ...you to map Private IP Addresses to Public IP Addresses for key services such as Websites and FTP Select Disable to disable the NAT function Port Forwarding Port Forwarding allows you to re direct a particular range of service port numbers from the Internet WAN Port to a particular LAN IP address It helps you to host servers behind the router NAT firewall Enable Port Forwarding Enable Port Forwardi...

Page 49: ... and Comment of the setting to be added and then click Add Then this Port Forwarding setting will be added into the Current Port Forwarding Table below Remove If you want to remove a Port Forwarding setting from the Current Port Forwarding Table select the Port Forwarding setting that you want to remove in the table and then click Delete Selected If you want to remove all Port Forwarding settings ...

Page 50: ...vice port number Enable Virtual Server Enable Virtual Server Local IP This is the LAN client host IP address that the Public Port number packet will be sent to Local Port This is the port number of the above Private IP host that the below Public Port number will be changed to when the packet enters your LAN to the LAN Server Client IP Type Select the port number protocol type TCP UDP or both If yo...

Page 51: ... Reset If you want to remove Virtual Server settings from the Current Virtual Server Table select the Virtual Server settings you want to remove in the table and then click Delete Selected If you want to remove all Virtual Server settings from the table just click the Delete All button Click Reset will clear your current selections Click Apply at the bottom of the screen to save the above configur...

Page 52: ...ort This is the out going Outbound range of port numbers for this particular application Trigger Type Select whether the outbound port protocol is TCP UDP or both Public Port Enter the In coming Inbound port or port range for this type of application e g 2300 2400 47624 Public Type Select the Inbound port protocol type TCP UDP or both Comment The description of this setting Popular applications Th...

Page 53: ... of the setting to be added and then click Add The Special Application setting will be added into the Current Trigger Port Table below If you happen to make a mistake just click Clear and the fields will be cleared Reset If you want to remove Special Application settings from the Current Trigger Port Table select the Special Application settings you want to remove in the table and then click Delet...

Page 54: ...e or Disable the UPnP feature here After you enable the UPnP feature all client systems that support UPnP like Windows XP can discover this router automatically and access the Internet through this router without having to configure anything The NAT Traversal function provided by UPnP can let applications that support UPnP connect to the internet without having to configure the virtual server sect...

Page 55: ...s rule name Others The rule with a smaller priority number has a higher priority the rule with a larger priority number has a lower priority You can adjust the priority of the rules by moving them up or down Enable Disable QoS You can check Enable QoS to enable QoS functionality for the WAN port Add a QoS rule into the table Click Add then enter a form of the QoS rule Click Apply after filling out...

Page 56: ...enter the detail form of the QoS rule Click Apply after editing the form and the rule will be saved Adjust QoS rule priority You can select the rule and click Move Up to make its priority higher You also can select the rule and click Move Down to make its priority lower ...

Page 57: ... status of VPN connection You can select one of them to connect or disconnect the VPN connection To Connect or Disconnect an existing tunnel Select the tunnel from the list by ticking the corresponding check box and click connect or disconnect Note If the connection type is remote dial in Client to Site or L2TP over IPSec you can t disconnect this session manually WARNING This section explains how...

Page 58: ...N tunnel 1 In the Top Menu on the right side click VPN 2 In the submenu click Wizard to add a VPN profile 3 Click Next to create a VPN profile 4 In the Name field enter a name for the PPTP VPN tunnel This name is for reference purposes Click Next to continue ...

Page 59: ...1 When WLR 5001 is on default settings the LAN IP address is 192 168 0 100 In this case you can select any private IP address other than 192 168 0 x for example 192 168 3 x Remote IP Range Enter an IP range that is on the same subnet as the Server IP address you have entered in the Server IP address field but the range should not include Server IP For example if you specified a Server IP address o...

Page 60: ...8 Enable the VPN policy and then click Apply to save the VPN profile ...

Page 61: ...e Top Menu on the right side click VPN 2 In the submenu click Wizard to add a VPN profile 3 Click Next to create a VPN profile 4 In the Name field enter a name for the L2TP VPN tunnel This name is for reference purposes Click Next to continue 5 Click L2TP and click NEXT to continue ...

Page 62: ...n this case you can select any IP address other than 192 168 0 x Remote IP Range Enter an IP range that is on the same subnet as the Server IP address you have entered in the Server IP address field but the range should not include Server IP For example if you specified a Server IP address of 192 168 2 1 you can define a Remote IP Range of 192 168 2 100 200 Click Next to continue 7 In the Shared K...

Page 63: ...age of the WLR 5001 If the WAN IP address of the WLR 5001 is not a public IP address but a local IP address for example any IP address in the following ranges 10 X X X 172 16 X X or 192 168 X X In this situation your WLR 5001 is placed behind a NAT enabled modem In this case consult your manual to make sure your modem supports VPN pass through and the GRE47 protocol and set it up to allow access t...

Page 64: ... a Microsoft Windows 7 VPN Client Click the Start button and open the Control Panel From the Control Panel select Network and Internet If your control panel view has been set to Icons you can directly go to step 4 ...

Page 65: ...3 From Network and internet select Network and Sharing center 4 Under Network and Sharing Center select Setup a new connection or network ...

Page 66: ...5 Click Connect to a workplace and click Use my internet connection VPN ...

Page 67: ... a name for the VPN client We recommend to select Don t connect now Just set it up so I can connect later Click next to continue 7 Complete the following fields User name Enter the username used to log onto the VPN tunnel Password Enter the password used to log onto the VPN tunnel Click Create to continue ...

Page 68: ...8 When the following screen appears click the Close button to close the VPN connection setting 9 Select Change adapter settings on the left side of the window ...

Page 69: ...nfigure the following settings Under the Type of VPN select the Protocol that has been set in the WLR 5001 Point to point tunneling protocol PPTP or Layer 2 Tunneling Protocol with IPsec L2TP IPSec Check unencrypted password PAP Check Challenge Handshake Authentication Protocol PPTP Check Microsoft CHAP Version 2 MS CHAP v2 ...

Page 70: ...12 Go to Network and Sharing Center on the bottom right of the windows Under VPN Connection click Connect ...

Page 71: ...Configuring a Microsoft Windows XP VPN Client 1 Click the Start button and open the Control Panel 2 From the Control Panel Click on Network Connections ...

Page 72: ...3 Click on Create a network from the left side of the window 4 Click Next to continue to setup the VPN client ...

Page 73: ...5 Select Connect to the network at my workplace and click Next to continue 6 Select Virtual Private network connection and click Next to continue ...

Page 74: ...7 Enter a Company name this name is only for reference purposes 8 Enter the Hostname this should be the WLR 5001 WAN IP address and click Next to continue ...

Page 75: ...9 Click Finish to continue you may choose to add a shortcut for this connection on the Desktop by clicking the checkbox before you click Finish 10 Click on Properties ...

Page 76: ...11 Click on the Security Tab from the top in the window and select Advanced click Settings to continue ...

Page 77: ...f no encryption Check Unencrypted password PAP Check Challenge Handshake Authentication Protocol SPAP Uncheck Microsoft CHAP MS CHAP Check Microsoft CHAP Version 2 MS CHAP v2 Click OK to continue 13 Click Yes to continue If the VPN type you have configured in the WLR 5001 is PPTP you can skip step 14 ...

Page 78: ...Sec You have also entered a Shared key in the WLR 5001 see step 7 of chapter Using the Wizard to Configure the WLR 5001 for L2TP over IPSec for reference Click on IPSec Settings 14b Check Use pre shared key for authentication Key Enter the shared key you have entered in the WLR 5001 ...

Page 79: ...Configuring a MacOS VPN Client 1 Select System Preferences 2 On the System preferences panel Click Network ...

Page 80: ...3 Click on the sign on the bottom left 4 Select the VPN interface ...

Page 81: ...e for this profile this name is for reference purpose only 6 Complete the following fields Server address Enter the WAN IP address of the WLR 5001 Account Name Enter the name used to log onto the VPN tunnel this must be one of the users you have set in the VPN user table of the WLR 5001 Click Authentication Settings to continue ...

Page 82: ...d Key If the VPN Type of the VPN tunnel you have set up in the WLR 5001 is L2TP over IPSec You have also entered a Shared key in the WLR 5001 see step 7 of chapter Using the Wizard to Configure the WLR 5001 for L2TP over IPSec for reference Enter the same key in this field Click OK to continue 8 Click on Advanced in the network panel to continue ...

Page 83: ...9 Select the checkbox Send all traffic over VPN connection Click OK to continue 10 If the VPN tunnel is already connected click Disconnect and Connect again for the changes made in step 9 to take effect ...

Page 84: ...Configuring a VPN client on iOS 1 Click Settings on the Springboard 2 Select General on from the panel of the left side and Click on Network ...

Page 85: ...3 Click on VPN 4 click on Add VPN Configuration ...

Page 86: ... the name used to log onto the VPN tunnel this must be one of the users you have set in the VPN user table of the WLR 5001 Password Enter the Password used to log onto the VPN tunnel Secret L2TP only If the VPN Type of the VPN tunnel you have set up in the WLR 5001 is L2TP over IPSec You have also entered a Shared key in the WLR 5001 see step 7 of chapter Using the Wizard to Configure the WLR 5001...

Page 87: ...4 Set the Switch to ON to connect to the VPN Network ...

Page 88: ...Configuring a VPN client on Android 1 Click on Settings 2 click on More from the Settings menu on the upper left Then Click on VPN ...

Page 89: ...Account Enter the name used to log onto the VPN tunnel this must be one of the users you have set in the VPN user table of the WLR 5001 Password Enter the Password used to log onto the VPN tunnel Secret L2TP only If the VPN Type of the VPN tunnel you have set up in the WLR 5001 is L2TP over IPSec You have also entered a Shared key in the WLR 5001 see step 7 of chapter Using the Wizard to Configure...

Page 90: ...4 Click on the VPN network you have just created to connect ...

Page 91: ... Delete VPN profiles Add click here if you wish to manually add a new VPN profile Edit to edit an existing profile select one from the list by selecting the corresponding radio button and click Edit Click Apply to save the settings and apply the changes ...

Page 92: ...Add Users to an existing Profile Click on Profile Setting Select the Profile for which you wish to modify user settings and click on Edit Then Click on the protocol name you selected to edit ...

Page 93: ...at do not have access to this VPN Tunnel yet The Member box displays users that already have access to this VPN Tunnel To Add or remove users to the VPN Tunnel click the on the username you wish you Add or Remove and press the buttons to the desired box Click Apply Click Apply to save the settings and apply the changes ...

Page 94: ...ack The intended use of this protocol is to provide similar levels of security and remote access as typical VPN products General This page allows you to configure the general VPN settings Name Enter a name for your VPN policy Connection Type Supports IPSec and L2TP over IPSec methods to establish VPN connection PPTP Authentication Select the desired authentication protocol PAP CHAP Auto Select Aut...

Page 95: ... VPN settings Name Enter a name for your VPN policy Connection Type Supports IPSec and L2TP over IPSec methods to establish VPN connection L2TP Authentication Select the desired authentication protocol PAP CHAP Auto Select Auto by default User Name Enter the username for authentication Password Enter the password for authentication Network Server IP Enter the VPN Server IP address Remote IP Range ...

Page 96: ...n a pair of security gateways network to network or between a security gateway and a host network to host General This page allows you to configure the general VPN settings Name Enter a name for your VPN policy Connection Type Supports IPSec and L2TP over IPSec methods to establish VPN connection Authentication Type Supports pre shared key method for authentication Shared Key Enter the Shared Key ...

Page 97: ...e the standard negotiation parameters for IKE Phase 1 of the VPN Tunnel Recommended Setting Aggressive Mode Select this option to configure IKE Phase 1 of the VPN Tunnel to carry out negotiation in a shorter amount of time Not Recommended Less Secure DH Group Select a DH Group from the drop down menu Group 1 Group2 Group5 and Group14 As the DH Group number increases the higher the level of encrypt...

Page 98: ...orward Secrecy Select Enable or Disable to enable or disable PFS Perfect Forward Secrecy PFS is an additional security protocol DH Group Select a PFS DH Group from the drop down menu Group 1 Group2 Group5 Group14 As the DH Group number increases the higher the level of encryption implemented for PFS Life Time Enter the number of seconds for the IPSec Lifetime The period of time to pass before esta...

Page 99: ... traverse through the translation process during NAT The remote VPN endpoint must also support this feature and it must be enabled to function properly over the VPN Dead Peer Detection Enable DPD Dead Peer Detection to delete the VPN tunnel if there is no traffic detected The VPN will re establish once traffic is again sent through the tunnel ...

Page 100: ... your VPN policy Connection Type Supports IPSec and L2TP over IPSec methods to establish VPN connection Authentication Type Supports pre shared key method for authentication Shared Key Enter the Shared Key Confirm Enter your Shared Key again for verification L2TP PPTP Authentication Select the desired authentication protocol PAP CHAP Auto Select Auto by default User Name Enter the username for aut...

Page 101: ... add the user to the current VPN user table Reset This button will clear all values from the input boxes Current VPN user table shows all existing VPN users Delete Selected Select a user from the table and Click Delete Selected to delete this user Delete ALL This deletes all current VPN user from the current table Click Apply to save the settings and apply the changes ...

Page 102: ...configuring IPSec Site to Site architecture In this guide we give an example how to set up a IPSec Site to Site architecture The values in this example are only to give an impression of how to do the configuration ...

Page 103: ...n click Wizard in the submenu Click Next to continue 2 In the Name field enter a name for the IPSec VPN tunnel This name is for reference purposes Click Next to continue 3 Click IPSec and click NEXT to continue 4 Click Site to Site and click NEXT to continue ...

Page 104: ...te Address Enter an IP address that is on the same Subnet as the Local LAN of the remote VPN server In our example the WLR 5001 in location A has a local IP of 192 168 2 1 so we set the Remote address to 192 168 2 0 Remote Netmask Enter the Netmask of the Remote Local LAN In our example the WLR 5001 in Location A has a IP Subnet Mask of 255 255 255 0 click NEXT to continue 6 Enter the Shared Key y...

Page 105: ...pply to save the VPN profile 8 Repeat these steps 1 7 for the other VPN server 9 Once Both VPN routers have been completely set up Click on Status in the submenu of the VPN menu and click Connect to establish the IPSec Site to Site connection ...

Page 106: ...h free Sitecom cloud security subscription After you have set up your Sitecom device for internet access open the webbrowser and enter http www sitecomcloudsecurity com in the address bar If the device has been properly configured the following web page should be shown Here you can select which security features you would like to use The Sitecom Cloud Security service offers the following protecti...

Page 107: ...om product Before you can now activate your subscription you will have to accept the license agreement After this click the activation button You will be shown the status of your Sitecom cloud security and the expiration date of your current subscription ...

Page 108: ...m Cloud Security will always check if a website is safe If it is not safe it will inform you that is not safe to enter If you still wish to visit this webpage click on proceed anyway Alternatively click Back to Safety so that your security will not be breached ...

Page 109: ...w sitecomcloudsecurity com from your web browser You will be asked for a username and password These can be found on the backlabel on the bottom of your Sitecom router or modem If the login succeeded you can click on Settings to change your security options Or click License to renew your subscription ...

Page 110: ...ebpage of your Sitecom product and log in with the supplied credentials these can be found on the back label on the bottom of your Sitecom device Go to Toolbox and select Sitecom Cloud Security Click the Disable radio button and click Apply for the settings to take effect ...

Page 111: ... can contain 0 to 12 alphanumeric characters and are case sensitive Current Password Fill in the current password to allow changing to a new password New Password Enter your new password Confirmed Password Enter your new password again for verification purposes Click Apply at the bottom of the screen to save the above configurations ...

Page 112: ... Address You can set an NTP server address Enable Daylight Savings The router can also take Daylight savings into account If you wish to use this function you must check tick the enable box to enable your daylight saving configuration below Start Daylight Savings Time Select the period in which you wish to start daylight Savings Time End Daylight Savings Time Select the period in which you wish to...

Page 113: ...he host in the Internet that will have management configuration access to the Broadband router from a remote site If the Host Address is left 0 0 0 0 this means anyone can access the router s web based configuration from a remote location providing they know the password Port The port number of the remote management web interface Enabled Select Enabled to enable the remote management function Clic...

Page 114: ...r Broadband router you need to download the firmware file to your local hard disk and enter that file name and path in the appropriate field on this page You can also use the Browse button to find the firmware file on your PC Once you ve selected the new firmware file click Apply at the bottom of the screen to start the upgrade process ...

Page 115: ...actory Defaults selection this will set all configurations to its original default settings e g when you first purchased the router Use the Backup tool to save the Broadband router current configuration to a file named config bin on your PC You can then use the Restore tool to restore the saved configuration to the Broadband router Alternatively you can use the Restore to Factory Defaults tool to ...

Page 116: ...Reset You can reset the router s system should any problem exist The reset function essentially re boots your router s system ...

Page 117: ...common DDNS service providers Enable Disable Enable or disable the DDNS function of this router Provider Select a DDNS service provider Domain name Fill in your static domain name that uses DDNS Account E mail The account that your DDNS service provider assigned to you Password Key The password you set for the DDNS service account above Click Apply at the bottom of the screen to save the above con...

Page 118: ...14 U boot v1 1 3 RaLink SDK 3 1 0 0 15 gcc 3 3 6 RaLink SDK 3 1 0 0 16 Uclibc 0 9 29 RaLink SDK 3 1 0 0 Availability of source code Sitecom Europe BV has made available the full source code of the GPL licensed software including any scripts to control the compilation and installation of the object code on the CD ROM that s shipped with this product No Warranty The free software included in this pr...

Page 119: ...ight law that is to say a work containing the Program or a portion of it either verbatim or with modifications and or translated into another language Hereinafter translation is included without limitation in the term modification Each licensee is addressed as you Activities other than copying distribution and modification are not covered by this License they are outside its scope The act of runni...

Page 120: ...m with the major components compiler kernel and so on of the operating system on which the executable runs unless that component itself accompanies the executable If distribution of executable or object code is made by offering access to copy from a designated place then offering equivalent access to copy the source code from the same place counts as distribution of the source code even though thi...

Page 121: ...ollowing the terms and conditions either of that version or of any later version published by the Free Software Foundation If the Program does not specify a version number of this License you may choose any version ever published by the Free Software Foundation 10 If you wish to incorporate parts of the Program into other free programs whose distribution conditions are different write to the autho...

Page 122: ......

Page 123: ......

Reviews: