background image

Table of Contents

AMG1202-T10A User’s Guide

12

Chapter   4
Tutorials................................................................................................................................... 37

4.1 Overview  ..............................................................................................................................37
4.2 Setting Up a Secure Wireless Network  ................................................................................37

4.2.1 Configuring the Wireless Network Settings ................................................................37
4.2.2 Using WPS  .................................................................................................................38
4.2.3 Without WPS  ..............................................................................................................42
4.2.4 Setting Up Wireless Network Scheduling  ...................................................................43

4.3 Configuring the MAC Address Filter .....................................................................................44
4.4 Configuring Static Route for Routing to Another Network  ....................................................46
4.5 Multiple Public and Private IP Address Mappings ................................................................49

4.5.1 Full Feature NAT + Many-to-Many No Overload Mapping  .........................................49
4.5.2 Full Feature NAT + One-to-One Mapping ...................................................................51

4.6 Multiple WAN Connections Example ...................................................................................52

Part II: Technical Reference...................................................................53

Chapter   5
Internet and Wireless Setup Wizard...................................................................................... 55

5.1 Overview  ..............................................................................................................................55
5.2 Internet Access Wizard Setup ..............................................................................................55

5.2.1 Manual Configuration  .................................................................................................58

5.3 Wireless Connection Wizard Setup ......................................................................................63

5.3.1 Manually Assign a WPA-PSK key ...............................................................................66
5.3.2 Manually Assign a WEP Key  ......................................................................................66

Chapter   6
WAN Setup .............................................................................................................................. 69

6.1 Overview  ..............................................................................................................................69

6.1.1 What You Can Do in the WAN Screens ......................................................................69
6.1.2 What You Need to Know About WAN .........................................................................69
6.1.3 Before You Begin ........................................................................................................70

6.2 The Internet Access Setup Screen  ......................................................................................71

6.2.1 Advanced Internet Access Setup  ...............................................................................73

6.3 The More Connections Screen  ............................................................................................74

6.3.1 More Connections Edit  ...............................................................................................76
6.3.2 Configuring More Connections Advanced Setup ........................................................78

6.4 WAN Technical Reference  ...................................................................................................79

6.4.1 Encapsulation  .............................................................................................................79
6.4.2 Multiplexing .................................................................................................................80
6.4.3 VPI and VCI ................................................................................................................80

Summary of Contents for AMG1202-T10A

Page 1: ...zyxel com AMG1202 T10A Wireless N lite ADSL2 4 port Ethernet Gateway Copyright 2011 ZyXEL Communications Corporation Firmware Version 1 00 Edition 1 6 2011 Default Login Details IP Address http 192 168 1 1 Password 1234 ...

Page 2: ......

Page 3: ...rnet access Support Disc Refer to the included CD for support documents ZyXEL Web Site Please refer to www zyxel com for additional support documentation and product certifications Documentation Feedback Send your comments questions or suggestions to techwriters zyxel com tw Thank you The Technical Writing Team ZyXEL Communications Corp Need More Help More help is available at www zyxel com Downlo...

Page 4: ...annot contact your vendor then contact a ZyXEL office for the region in which you bought the device See http www zyxel com web contact_us php for contact information Please have the following information ready when you contact an office Product model and serial number Warranty Information Date that you received your device Brief description of the problem and the steps you took to solve it Disclai...

Page 5: ...r or return key on your keyboard Enter means for you to type one or more characters and then press the ENTER key Select or choose means for you to use one of the predefined choices A right angle bracket within a screen name denotes a mouse click For example Maintenance Log Log Setting means you first click Maintenance in the navigation panel then the Log sub menu and finally the Log Setting tab to...

Page 6: ...Document Conventions AMG1202 T10A User s Guide 6 Server Firewall Telephone Router Switch ...

Page 7: ...n Europe Do NOT allow anything to rest on the power adaptor or cord and do NOT place the product where anyone can walk on the power adaptor or cord Do NOT use the device if the power adaptor or cord is damaged as it might cause electrocution If the power adaptor or cord is damaged remove it from the device and the power source Do NOT attempt to repair the power adaptor or cord Contact your local v...

Page 8: ...Safety Warnings AMG1202 T10A User s Guide 8 ...

Page 9: ...Internet and Wireless Setup Wizard 55 WAN Setup 69 LAN Setup 85 Wireless LAN 97 Network Address Translation NAT 127 Firewall 139 Filters 143 Static Route 149 802 1Q 1P 153 Quality of Service QoS 159 Dynamic DNS Setup 167 Remote Management 169 Universal Plug and Play UPnP 178 System Settings 189 Logs 193 Tools 203 Diagnostic 209 Troubleshooting 213 Product Specifications 217 ...

Page 10: ...Contents Overview AMG1202 T10A User s Guide 10 ...

Page 11: ...r Managing the ZyXEL Device 21 1 4 Applications for the ZyXEL Device 22 1 4 1 Internet Access 22 1 5 Wireless Access 22 1 5 1 Using the WPS WLAN Button 23 1 6 LEDs Lights 24 1 7 The RESET Button 25 1 7 1 Using the Reset Button 25 Chapter 2 The Web Configurator 27 2 1 Overview 27 2 1 1 Accessing the Web Configurator 27 2 2 The Main Screen 29 2 2 1 Title Bar 29 2 2 2 Navigation Panel 30 2 2 3 Main W...

Page 12: ...WAN Connections Example 52 Part II Technical Reference 53 Chapter 5 Internet and Wireless Setup Wizard 55 5 1 Overview 55 5 2 Internet Access Wizard Setup 55 5 2 1 Manual Configuration 58 5 3 Wireless Connection Wizard Setup 63 5 3 1 Manually Assign a WPA PSK key 66 5 3 2 Manually Assign a WEP Key 66 Chapter 6 WAN Setup 69 6 1 Overview 69 6 1 1 What You Can Do in the WAN Screens 69 6 1 2 What You ...

Page 13: ...n 90 7 5 1 Configuring the LAN IP Alias Screen 91 7 6 LAN Technical Reference 92 7 6 1 LANs WANs and the ZyXEL Device 92 7 6 2 DHCP Setup 93 7 6 3 DNS Server Addresses 93 7 6 4 LAN TCP IP 93 7 6 5 RIP Setup 94 7 6 6 Multicast 95 Chapter 8 Wireless LAN 97 8 1 Overview 97 8 1 1 What You Can Do in the Wireless LAN Screens 97 8 1 2 What You Need to Know About Wireless 98 8 1 3 Before You Start 98 8 2 ...

Page 14: ...2 The NAT General Setup Screen 128 9 3 The Port Forwarding Screen 129 9 3 1 Configuring the Port Forwarding Screen 130 9 3 2 The Port Forwarding Rule Edit Screen 131 9 4 The Address Mapping Screen 132 9 4 1 The Address Mapping Rule Edit Screen 134 9 5 The ALG Screen 135 9 6 NAT Technical Reference 135 9 6 1 NAT Definitions 135 9 6 2 What NAT Does 136 9 6 3 How NAT Works 136 9 6 4 NAT Application 1...

Page 15: ...2 1 Editing 802 1Q 1P Group Setting 156 13 3 The 802 1Q 1P Port Setting Screen 157 Chapter 14 Quality of Service QoS 159 14 1 Overview 159 14 1 1 What You Can Do in the QoS Screens 159 14 1 2 What You Need to Know About QoS 160 14 2 The QoS Screen 160 14 2 1 The QoS Settings Summary Screen 163 14 3 QoS Technical Reference 164 14 3 1 IEEE 802 1p 164 14 3 2 IP Precedence 164 14 3 3 Automatic Priorit...

Page 16: ...ed to Know About UPnP 178 17 2 The UPnP Screen 179 17 3 Installing UPnP in Windows Example 180 17 4 Using UPnP in Windows XP Example 183 Chapter 18 System Settings 189 18 1 Overview 189 18 1 1 What You Can Do in the System Settings Screens 189 18 2 The General Screen 189 18 3 The Time and Date Screen 190 Chapter 19 Logs 193 19 1 Overview 193 19 1 1 What You Need To Know About Logs 193 19 2 The Sys...

Page 17: ... Access and Login 214 22 3 Internet Access 215 Chapter 23 Product Specifications 217 23 1 Hardware Specifications 217 23 2 Firmware Specifications 217 23 3 Wireless Features 220 23 4 Power Adaptor Specifications 222 Appendix A Setting up Your Computer s IP Address 225 Appendix B IP Addresses and Subnetting 247 Appendix C Pop up Windows JavaScripts and Java Permissions 255 Appendix D Wireless LANs ...

Page 18: ...Table of Contents AMG1202 T10A User s Guide 18 ...

Page 19: ...19 PART I User s Guide ...

Page 20: ...20 ...

Page 21: ...ne commands are mostly used for troubleshooting by service engineers FTP for firmware upgrades and configuration backup restore TR 069 This is an auto configuration server used to remotely configure your device 1 3 Good Habits for Managing the ZyXEL Device Do the following things regularly to make the ZyXEL Device more secure and to manage the ZyXEL Device more effectively Change the password Use ...

Page 22: ... means that probes from the outside to your network are not allowed but you can safely browse the Internet and download files Use the filtering feature to block access to specific web sites or Internet applications such as MSN or Yahoo Messenger You can also configure IP MAC filtering rules for incoming or outgoing traffic Use QoS to efficiently manage traffic on your network by giving priority to...

Page 23: ...en the wireless network is active You can also use the WPS WLAN button to quickly set up a secure wireless connection between the ZyXEL Device and a WPS compatible client by adding one device at a time To activate WPS 1 Make sure the POWER LED is on and not blinking 2 Press the WPS WLAN button for five to ten seconds and release it 3 Press the WPS button on another WPS enabled device within range ...

Page 24: ... to from the LAN Off The ZyXEL Device does not have an Ethernet connection with the LAN WPS WLAN Green On The wireless network is activated Blinking The ZyXEL Device is communicating with other wireless clients Orange Blinking The ZyXEL Device is setting up a WPS connection Off The wireless network is not activated DSL Green On The DSL line is up Blinking The ZyXEL Device is initializing the DSL l...

Page 25: ...ation file This means that you will lose all configurations that you had previously and the password will be reset to 1234 1 7 1 Using the Reset Button 1 Make sure the POWER LED is on not blinking 2 To set the device back to the factory default settings press the RESET button for ten seconds or until the POWER LED begins to blink and then release it When the POWER LED begins to blink the defaults ...

Page 26: ...Chapter 1 Introduction AMG1202 T10A User s Guide 26 ...

Page 27: ...k 2 JavaScripts enabled by default Java permissions enabled by default See Appendix C on page 255 if you need to make sure these functions are allowed in Internet Explorer 2 1 1 Accessing the Web Configurator 1 Make sure your ZyXEL Device hardware is properly connected refer to the Quick Start Guide 2 Launch your web browser 3 Type 192 168 1 1 as the URL 4 A password screen displays To access the ...

Page 28: ...o proceed to the main menu if you do not want to change the password now Figure 5 Change Password Screen 6 Select Go to Wizard setup and click Apply to display the wizard main screen Otherwise select Go to Advanced setup and click Apply to display the Status screen Figure 6 Replace Factory Default Certificate Screen Note For security reasons the ZyXEL Device automatically logs you out if you do no...

Page 29: ...on panel C main window D status bar 2 2 1 Title Bar The title bar provides some icons in the upper right corner The icons provide the following functions B C D A Table 2 Web Configurator Icons in the Title Bar ICON DESCRIPTION Wizards Click this icon to go to the configuration wizards See Chapter 5 on page 55 for more information Logout Click this icon to log out of the web configurator ...

Page 30: ...ttings More AP Use this screen to configure multiple BSSs on the ZyXEL Device WPS Use this screen to configure and view your WPS Wi Fi Protected Setup settings WPS Station Use this screen to set up a WPS wireless network WDS Use this screen to set up Wireless Distribution System links to other access points Scheduling Use this screen to configure the dates times to enable or disable the wireless L...

Page 31: ... to access the ZyXEL Device SNMP Use this screen to configure through which interface s and from which IP address es users can access the SNMP agent on the ZyXEL Device DNS Use this screen to configure through which interface s and from which IP address es users can send DNS queries to the ZyXEL Device ICMP Use this screen to set whether or not your device will respond to pings and probes for serv...

Page 32: ...Chapter 2 The Web Configurator AMG1202 T10A User s Guide 32 ...

Page 33: ...ormation from DHCP and statistics from bandwidth management and traffic 3 2 The Status Screen Use this screen to view the status of the ZyXEL Device Click Status to open this screen Figure 8 Status Screen Each field is described in the following table Table 4 Status Screen LABEL DESCRIPTION Refresh Interval Select how often you want the ZyXEL Device to update this screen Apply Click this to update...

Page 34: ...the current IP address of the ZyXEL Device in the LAN Click this to go to the screen where you can change it IP Subnet Mask This is the current subnet mask in the LAN DHCP This field displays what DHCP services the ZyXEL Device is providing to the LAN Choices are Server The ZyXEL Device is a DHCP server in the LAN It assigns IP addresses to other computers in the LAN Relay The ZyXEL Device acts as...

Page 35: ...uch If memory usage does get close to 100 the ZyXEL Device is probably becoming unstable and you should restart the device See Section 20 4 on page 208 or turn off the device unplug the power for a few seconds Interface Status Interface This column displays each interface the ZyXEL Device has Status This field indicates whether or not the ZyXEL Device is using the interface For the DSL interface t...

Page 36: ...Chapter 3 Status Screens AMG1202 T10A User s Guide 36 ...

Page 37: ...up a wireless network so that he can use his notebook to access the Internet In this wireless network the ZyXEL Device serves as an access point AP and the notebook is the wireless client The wireless client can access the Internet through the AP Thomas has to configure the wireless network settings on the ZyXEL Device Then he can set up a wireless network using WPS Section 4 2 2 on page 38 or man...

Page 38: ...ure to establish a wireless connection between his notebook and the ZyXEL Device see Section 4 2 2 on page 38 He can also use the notebook s wireless client to search for the ZyXEL Device see Section 4 2 3 on page 42 4 2 2 Using WPS This section shows you how to set up a wireless network using WPS It uses the ZyXEL Device as the AP and ZyXEL NWD210N as the wireless client which connects to the not...

Page 39: ... wireless client utility go to the WPS setting page Enable WPS and press the WPS button Start or WPS button 4 Push and hold the WPS button located on the ZyXEL Device s rear panel for more than 5 seconds Alternatively you may log into ZyXEL Device s web configurator and click the Push Button in the Network Wireless LAN WPS Station screen Note Your ZyXEL Device has a WPS button located on its rear ...

Page 40: ...Example WPS Process PBC Method PIN Configuration When you use the PIN configuration method you need to use both the ZyXEL Device s web configurator and the wireless client s utility 1 Launch your wireless client s configuration utility Go to the WPS settings and select the PIN method to get a PIN number Wireless Client ZyXEL Device SECURITY INFO COMMUNICATION WITHIN 2 MINUTES Press and hold for 5 ...

Page 41: ...buttons or the button next to the PIN field on both the wireless client utility screen and the ZyXEL Device s WPS Station screen within two minutes The ZyXEL Device authenticates the wireless client and sends the proper configuration settings to the wireless client This may take up to two minutes The wireless client is then able to communicate with the ZyXEL Device securely ...

Page 42: ...lient by using PIN method Example WPS Process PIN Method 4 2 3 Without WPS Use the wireless adapter s utility installed on the notebook to search for the Example SSID Then enter the DoNotStealMyWirelessNetwork pre shared key to establish an wireless Internet connection Authentication by PIN SECURITY INFO WITHIN 2 MINUTES Wireless Client ZyXEL Device COMMUNICATION ...

Page 43: ...eless adapter supports one of these standards 4 2 4 Setting Up Wireless Network Scheduling Thomas mostly uses his notebook to access the Internet on weekends occasionally he uses it at night on weekdays Here is how Thomas can set up a schedule to turn on the wireless network at specific time and days 1 Click Network Wireless Network Scheduling to open the following screen ...

Page 44: ...ing the MAC Address Filter Thomas noticed that his daughter Josephine spends too much time surfing the web and downloading media files He decided to prevent Josephine from accessing the Internet so that she can concentrate on preparing for her final exams Josephine s computer connects wirelessly to the Internet through the ZyXEL Device Thomas can deny access to the wireless network using the MAC a...

Page 45: ... T10A User s Guide 45 1 Click Network LAN Client List to open the following screen Look for the MAC address of Josephine s computer 2 Click Network Wireless LAN to open the AP screen Click the Edit button in the MAC Filter field ...

Page 46: ...Route for Routing to Another Network In order to extend your Intranet and control traffic flowing directions you may connect a router to the ZyXEL Device s LAN The router may be used to separate two department networks This tutorial shows how to configure a static routing rule for two network routings In the following figure router R is connected to the ZyXEL Device s LAN R connects to two network...

Page 47: ... static routing rule on the ZyXEL Device to specify R as the router in charge of forwarding traffic to N2 In this case the ZyXEL Device routes traffic from A to R and then R routes the traffic to B This tutorial uses the following example IP settings Table 5 IP Settings in this Tutorial DEVICE COMPUTER IP ADDRESS The ZyXEL Device s WAN 172 16 1 1 The ZyXEL Device s LAN 192 168 1 1 A 192 168 1 34 R...

Page 48: ...e the Static Route Setup screen using the following settings 4a Type 192 168 10 0 and subnet mask 255 255 255 0 for the destination N2 4b Type 192 168 1 253 R s N1 address in the Gateway IP Address field 4a Click Apply Now B should be able to receive traffic from A You may need to additionally configure B s firewall settings to allow specific traffic to pass through R s N2 192 168 10 2 B 192 168 1...

Page 49: ...r of the following settings Full Feature NAT with many to many no overload mapping Full Feature NAT with one to one mapping 4 5 1 Full Feature NAT Many to Many No Overload Mapping Use this setting if your applications can use random public IP addresses and the applications are initiated from the Intranet computers A and B For example VoIP application See Section 4 5 2 on page 51 if it is not Table...

Page 50: ...nslation NAT and Full Feature in the General screen Click Apply 3 Click the Address Mapping tab and then click the Edit icon on a new rule 4 Configure the rule using the following settings Type Many to Many No Overload Local IP addresses 192 168 1 2 192 168 1 3 Global IP addresses 172 16 1 253 172 16 1 254 Then click Apply ...

Page 51: ...ck Network NAT 2 Select Active Network Address Translation NAT and Full Feature in the General screen Click Apply 3 Click the Address Mapping tab click the Edit icon on a new rule 4 Configure two rules for the one to one mappings Rule 1 This maps the public IP address 172 16 1 253 to the private IP address 192 168 1 2 Type One to One Local Start IP 192 168 1 2 Global Start IP 172 16 1 253 Rule 2 T...

Page 52: ...more than one WAN connection on the ZyXEL Device to record traffic statistics or calculate service charges In Figure 9 three WAN connections are configured over the ADSL line The connection with VPI VCI 0 33 is dedicated for Media On Demand MOD service The connection with VPI VCI 0 34 is dedicated for VoIP service The connection with VPI VCI 0 35 is dedicated for general data transmission Figure 9...

Page 53: ...53 PART II Technical Reference ...

Page 54: ...54 ...

Page 55: ...ormation given to you by your ISP Note See the advanced menu chapters for background information on these fields 5 2 Internet Access Wizard Setup 1 After you enter the password to access the web configurator select Go to Wizard setup and click Apply Otherwise click the wizard icon in the top right corner of the web configurator to go to the wizards Figure 10 Select a Mode ...

Page 56: ...s not detected Check your hardware connections and click Restart the INTERNET WIRELESS SETUP Wizard to return to the wizard welcome screen If you still cannot connect click Manually configure your Internet connection Follow the directions in the wizard and enter your Internet setup information as provided to you by your ISP See Section 5 2 1 on page 58 for more details If you would like to skip yo...

Page 57: ...d or service name exactly as provided by your ISP Then click Next and see Section 5 3 on page 63 for wireless connection wizard setup Figure 13 Auto Detection PPPoE 3c The following screen appears if the ZyXEL device detects a connection but not the connection type Click Next and refer to Section 5 2 1 on page 58 on how to manually configure the ZyXEL Device for Internet access Figure 14 Auto Dete...

Page 58: ...ount Select Bridge when your ISP provides you more than one IP address and you want the connected computers to get individual IP address from ISP s DHCP server directly If you select Bridge you cannot use Firewall DHCP server and NAT on the ZyXEL Device Encapsulation Select the encapsulation type your ISP uses from the Encapsulation drop down list box Choices vary depending on what you select in t...

Page 59: ...e 63 for wireless connection wizard setup Figure 16 Internet Connection with PPPoE VCI Enter the VCI assigned to you This field may already be configured Back Click this to return to the previous screen without saving Next Click this to continue to the next wizard screen The next wizard screen you see depends on what protocol you chose above Exit Click this to close the wizard screen without savin...

Page 60: ... the user name exactly as your ISP assigned If assigned a name in the form user domain where domain identifies a service name then enter both components exactly as given Password Enter the password associated with the user name above Service Name Type the name of your PPPoE service here Back Click this to return to the previous screen without saving Apply Click this to save your changes Exit Click...

Page 61: ...NET ENCAP Table 9 Internet Connection with RFC 1483 LABEL DESCRIPTION IP Address This field is available if you select Routing in the Mode field Type your ISP assigned IP address in this field Back Click this to return to the previous screen without saving Next Click this to continue to the next wizard screen Exit Click this to close the wizard screen without saving ...

Page 62: ... IP address Subnet Mask Enter a subnet mask in dotted decimal notation Refer to the appendix to calculate a subnet mask If you are implementing subnetting Gateway IP address You must specify a gateway IP address supplied by your ISP when you use ENET ENCAP in the Encapsulation field in the previous screen First DNS Server Enter the IP addresses of the DNS servers The DNS servers are passed to the ...

Page 63: ...Test Failed 1 If the following screen displays check if your account is activated or click Restart the Internet Wireless Setup Wizard to verify your Internet access settings Figure 21 Connection Test Failed 2 5 3 Wireless Connection Wizard Setup After you configure the Internet access information use the following screens to set up your wireless LAN Apply Click this to save your changes Exit Click...

Page 64: ... activate the wireless LAN Click Next to continue Figure 23 Wireless LAN Setup Wizard 1 The following table describes the labels in this screen Table 12 Wireless LAN Setup Wizard 1 LABEL DESCRIPTION Active Select the check box to turn on the wireless LAN Back Click this to return to the previous screen without saving Next Click this to continue to the next wizard screen Exit Click this to close th...

Page 65: ...he ZyXEL Device make sure all wireless stations use the same SSID in order to access the network Channel Selection The range of radio frequencies used by IEEE 802 11b g wireless devices is called a channel Select a channel ID that is not already in use by a neighboring device Security Select Manually assign a WPA PSK key to configure a Pre Shared Key WPA PSK Choose this option only if your wireles...

Page 66: ...ually assign a WEP key to setup WEP Encryption parameters Figure 26 Manually Assign a WEP key Table 14 Manually Assign a WPA PSK key LABEL DESCRIPTION Pre Shared Key Type from 8 to 63 case sensitive ASCII characters You can set up the most secure wireless connection by configuring WPA in the wireless LAN screens You need to configure an authentication server to do this Back Click this to return to...

Page 67: ...ete and save the wizard setup Table 15 Manually Assign a WEP key LABEL DESCRIPTION Key The WEP keys are used to encrypt data Both the ZyXEL Device and the wireless stations must use the same WEP key for data transmission Enter any 5 or 13 ASCII characters or 10 or 26 hexadecimal characters 0 9 A F for a 64 bit or 128 bit WEP key respectively Back Click this to return to the previous screen without...

Page 68: ...ess and WLAN Wizard Setup Complete 7 Launch your web browser and navigate to www zyxel com Internet access is just the beginning Refer to the rest of this guide for more detailed information on the complete range of ZyXEL Device features If you cannot access the Internet open the web configurator again to confirm that the Internet settings you configured in the wizard setup are correct ...

Page 69: ...ttings on the ZyXEL Device for Internet access Use the More Connections screen Section 6 3 on page 74 to set up additional Internet access connections 6 1 2 What You Need to Know About WAN Encapsulation Method Encapsulation is used to include data from an upper layer protocol into a lower layer protocol To set up a WAN connection to the Internet you need to use the same encapsulation method used b...

Page 70: ... 1 recipient or Broadcast 1 sender everybody on the network Multicast delivers IP packets to a group of hosts on the network not everybody and not just one IGMP IGMP Internet Group Multicast Protocol is a network layer protocol used to establish membership in a Multicast group it is not used to carry user data There are three versions of IGMP IGMP version 2 and 3 are improvements over version 1 bu...

Page 71: ...able describes the labels in this screen Table 16 Network WAN Internet Access Setup LABEL DESCRIPTION Line ADSL Mode Select the mode supported by your ISP Use Auto Sync Up if you are not sure which mode to choose from The ZyXEL Device dynamically diagnoses the mode supported by the ISP and selects the best compatible one for your connection Other options are ADSL2 ADSL2 G DMT T1 413 and G lite ADS...

Page 72: ...dix for more information These fields are not available if you set the WAN type to Ethernet VPI The valid range for the VPI is 0 to 255 Enter the VPI assigned to you VCI The valid range for the VCI is 32 to 65535 0 to 31 is reserved for local management of ATM traffic Enter the VCI assigned to you IP Address This option is available if you select Routing in the Mode field A static IP address is a ...

Page 73: ...re details of your WAN setup Table 16 Network WAN Internet Access Setup continued LABEL DESCRIPTION Table 17 Network WAN Internet Access Setup Advanced Setup LABEL DESCRIPTION RIP Multicast Setup This section is not available when you configure the ZyXEL Device to be in bridge mode RIP Direction RIP Routing Information Protocol allows a router to exchange routing information with other routers Use...

Page 74: ...ay and delay variation Select nrtVBR non real time Variable Bit Rate type for connections that do not require closely controlled delay and delay variation Peak Cell Rate Divide the DSL line rate bps by 424 the size of an ATM cell to find the Peak Cell Rate PCR This is the maximum rate at which the sender can send cells Type the PCR here Sustain Cell Rate The Sustain Cell Rate SCR sets the average ...

Page 75: ...on Select the check box to enable it Name This is the name you gave to the Internet connection VPI VCI This field displays the Virtual Path Identifier VPI and Virtual Channel Identifier VCI numbers configured for this WAN connection Encapsulation This field indicates the encapsulation method of the Internet connection Modify The first ISP connection is read only in this screen Use the WAN Internet...

Page 76: ...Table 19 Network WAN More Connections Edit LABEL DESCRIPTION General Active Select the check box to activate or clear the check box to deactivate this connection Name Enter a unique descriptive name of up to 13 ASCII characters for this connection Mode Select Routing from the drop down list box if your ISP allows multiple computers to share an Internet account If you select Bridge the ZyXEL Device...

Page 77: ... each time you connect to the Internet If you use the encapsulation type except RFC 1483 select Obtain an IP Address Automatically when you have a dynamic IP address otherwise select Static IP Address and type your ISP assigned IP address in the IP Address field below If you use RFC 1483 enter the IP address given by your ISP in the IP Address field Subnet Mask This option is available if you sele...

Page 78: ...k WAN More Connections Edit Advanced Setup LABEL DESCRIPTION ATM QoS ATM QoS Type Select CBR Continuous Bit Rate to specify fixed always on bandwidth for voice or data traffic Select UBR Unspecified Bit Rate for applications that are non time sensitive such as e mail Select nrtVBR Variable Bit Rate non Real Time or rtVBR Variable Bit Rate Real Time for bursty traffic and bandwidth sharing with oth...

Page 79: ...nal computer PC interacts with a broadband modem DSL cable wireless etc connection The PPPoE option is for a dial up connection using PPPoE For the service provider PPPoE offers an access and authentication method that works with existing access control systems for example RADIUS One of the benefits of PPPoE is the ability to let you access one of multiple network services a function known as dyna...

Page 80: ...dentify what protocols the virtual circuit VC is carrying Be sure to use the multiplexing method required by your ISP VC based Multiplexing In this case by prior mutual agreement each protocol is assigned to a specific virtual circuit for example VC1 carries IP etc VC based multiplexing may be dominant in environments where dynamic creation of large numbers of ATM VCs is fast and economical LLC ba...

Page 81: ... turned on and whenever the connection is down A nailed up connection can be very expensive for obvious reasons Do not specify a nailed up connection unless your telephone company offers flat rate service or you need a constant connection and the cost is of no concern 6 4 6 NAT NAT Network Address Translation NAT RFC 1631 is the translation of the IP address of a host in a packet for example the s...

Page 82: ...raffic exceeds this rate cells may be dropped Examples of connections that need CBR would be high resolution video and voice Variable Bit Rate VBR The Variable Bit Rate VBR ATM traffic class is used with bursty connections Connections that use the Variable Bit Rate VBR traffic class can be grouped into real time VBR RT or non real time VBR nRT connections The VBR RT real time Variable Bit Rate typ...

Page 83: ...ecified Bit Rate UBR The Unspecified Bit Rate UBR ATM traffic class is for bursty data transfers However UBR doesn t guarantee any bandwidth and only delivers traffic when the network has spare bandwidth An example application is background file transfer ...

Page 84: ...Chapter 6 WAN Setup AMG1202 T10A User s Guide 84 ...

Page 85: ...your ZyXEL Device s RIP multicast and Windows Networking settings from this screen Use the DHCP Setup screen Section 7 3 on page 88 to configure the ZyXEL Device s DHCP settings Use the Client List screen Section 7 4 on page 89 to assign IP addresses on the LAN to specific individual computers based on their MAC Addresses Use the IP Alias screen Section 7 5 on page 90 to change your ZyXEL Device s...

Page 86: ...MP Internet Group Multicast Protocol is a network layer protocol used to establish membership in a Multicast group it is not used to carry user data There are three versions of IGMP IGMP version 2 and 3 are improvements over version 1 but IGMP version 1 is still in wide use DNS DNS Domain Name System is for mapping a domain name to its corresponding IP address and vice versa The DNS server is extr...

Page 87: ...cast and Windows Networking settings Click the Advanced Setup button in the LAN IP screen The screen appears as shown Figure 37 Network LAN IP Advanced Setup Table 21 Network LAN IP LABEL DESCRIPTION IP Address Enter the LAN IP address you want to assign to your ZyXEL Device in dotted decimal notation for example 192 168 1 1 factory default IP Subnet Mask Type the subnet mask of your network in do...

Page 88: ...vanced Setup LABEL DESCRIPTION RIP Multicast Setup RIP Direction Select the RIP direction from None Both In Only and Out Only RIP Version Select the RIP version from RIP 1 RIP 2B and RIP 2M Multicast IGMP Internet Group Multicast Protocol is a network layer protocol used to establish membership in a multicast group The ZyXEL Device supports IGMP v1 IGMP v2 and IGMP v3 Select None to disable it Bac...

Page 89: ...te DHCP server in the Remote DHCP Server field in this case When DHCP is used the following items need to be set IP Pool Starting Address This field specifies the first of the contiguous addresses in the IP address pool Pool Size This field specifies the size or count of the IP address pool Remote DHCP Server If Relay is selected in the DHCP field above then enter the IP address of the actual remo...

Page 90: ...entry row Status This field displays whether the client is connected to the ZyXEL Device Host Name This field displays the computer host name IP Address This field displays the IP address relative to the field listed above MAC Address The MAC Media Access Control or Ethernet address on a LAN Local Area Network is unique to your computer six pairs of hexadecimal notation A network interface card su...

Page 91: ...he following screen Figure 41 Network LAN IP Alias The following table describes the labels in this screen Ethernet Interface A 192 168 1 1 192 168 1 24 B 192 168 2 1 192 168 2 24 C 192 168 3 1 192 168 3 24 Table 25 Network LAN IP Alias LABEL DESCRIPTION IP Alias 1 Select the check box to configure another LAN network for the ZyXEL Device IP Address Enter the IP address of your ZyXEL Device in dot...

Page 92: ...formation that it receives when set to None it will not send any RIP packets and will ignore any RIP packets received RIP Version The RIP Version field controls the format and the broadcasting method of the RIP packets that the ZyXEL Device sends it recognizes both formats when receiving RIP 1 is universally supported but RIP 2 carries more information RIP 1 is probably adequate for most networks ...

Page 93: ...ter them in the DNS Server fields in the DHCP Setup screen Some ISPs choose to disseminate the DNS server addresses using the DNS server extensions of IPCP IP Control Protocol after the connection is up If your ISP did not give you explicit DNS servers chances are the DNS servers are conveyed through IPCP negotiation The ZyXEL Device supports the IPCP DNS server extensions through the DNS proxy fe...

Page 94: ...out problems However the Internet Assigned Numbers Authority IANA has reserved the following three blocks of IP addresses specifically for private networks 10 0 0 0 10 255 255 255 172 16 0 0 172 31 255 255 192 168 0 0 192 168 255 255 You can obtain your IP address from the IANA from an ISP or it can be assigned from a private network If you belong to a small organization and your Internet access i...

Page 95: ...s still in wide use IGMP version 3 supports source filtering reporting or ignoring traffic from specific source address to a particular host on the network If you would like to read more detailed information about interoperability between IGMP version 2 and version 1 please see sections 4 and 5 of RFC 2236 The class D IP address is used to identify host groups and can be in the range 224 0 0 0 to ...

Page 96: ...Chapter 7 LAN Setup AMG1202 T10A User s Guide 96 ...

Page 97: ...page 99 to turn the wireless connection on or off set up wireless security configure the MAC filter and make other basic configuration changes Use the More AP screen see Section 8 3 on page 107 to set up multiple wireless networks on your ZyXEL Device Use the WPS screen see Section 8 4 on page 108 to enable or disable WPS generate a security PIN Personal Identification Number and see information a...

Page 98: ...l characters 0 9 and A to F and it is usually written in the following format 0A A0 00 BB CC DD The MAC address filter controls access to the wireless network You can use the MAC address of each wireless client to allow or deny access to the wireless network Finding Out More See Section 8 8 on page 112 for advanced technical information on wireless networks 8 1 3 Before You Start Before you start ...

Page 99: ...associated Wireless devices associating to the access point AP must have the same SSID Enter a descriptive name up to 32 printable 7 bit ASCII characters for the wireless LAN Note If you are configuring the ZyXEL Device from a computer connected to the wireless LAN and you change the ZyXEL Device s SSID or WEP settings you will lose your wireless connection when you press Apply to confirm You must...

Page 100: ...to configure and enable WEP encryption Click Network Wireless LAN to display the AP screen Select Static WEP from the Security Mode list Edit Click this to go to the MAC Filter screen to configure MAC filter settings See Section 8 2 6 on page 106 for more details QoS Select this check box to activate Quality of Service QoS Apply Click this to save your changes Cancel Click this to restore your pre...

Page 101: ... than WEP use the highest encryption level available Figure 45 Network Wireless LAN AP Static WEP The following table describes the wireless LAN security labels in this screen Table 28 Network Wireless LAN AP Static WEP LABEL DESCRIPTION Security Mode Choose Static WEP from the drop down list box Passphrase Enter a passphrase up to 32 printable characters and click Generate The ZyXEL Device automa...

Page 102: ...ireless clients can all use AES Select TKIP AES to allow the wireless clients to use either TKIP or AES Enable Key Autogeneration Click the check box to have the ZyXEL Device generate the Pre Shared Key Pre Shared Key The encryption mechanisms used for WPA 2 and WPA 2 PSK are the same The only difference between the two is that WPA 2 PSK uses a simple common password instead of user specific crede...

Page 103: ... Select TKIP AES to allow the wireless clients to use either TKIP or AES WPA Compatible This check box is available only when you select WPA2 PSK or WPA2 in the Security Mode field Select the check box to have both WPA PSK and WPA wireless clients be able to communicate with the ZyXEL Device even when the ZyXEL Device is using WPA2 PSK or WPA2 ReAuthentication Timer Specify how often wireless stat...

Page 104: ...the external authentication server in dotted decimal notation Port Number Enter the port number of the external authentication server You need not change this value unless your network administrator instructs you to do so with additional information Shared Secret Enter a password up to 31 alphanumeric characters as the key to be shared between the external authentication server and the ZyXEL Devic...

Page 105: ...Select 802 11b g n to allow IEEE 802 11b IEEE 802 11g or IEEE802 11n compliant WLAN devices to associate with the ZyXEL Device The transmission rate of your ZyXEL Device might be reduced Channel Bandwidth Select whether the ZyXEL Device uses a wireless channel width of 20MHz or 20 40MHz A standard 20MHz channel offers transfer speeds of up to 150Mbps whereas a 40MHz channel uses two standard chann...

Page 106: ...the MAC Address table Select Deny to block access to the ZyXEL Device MAC addresses not listed will be allowed to access the ZyXEL Device Select Allow to permit access to the ZyXEL Device MAC addresses not listed will be denied access to the ZyXEL Device Set This is the index number of the MAC address MAC Address Enter the MAC addresses of the wireless devices that are allowed or denied access to ...

Page 107: ...of parameters relating to one of the ZyXEL Device s BSSs The SSID Service Set IDentifier identifies the Service Set with which a wireless device is associated This field displays the name of the wireless profile on the network When a wireless client scans for an AP to associate with this is the name that is broadcast and seen in the wireless client utility Security This field indicates the securit...

Page 108: ...d you change the ZyXEL Device s SSID or security settings you will lose your wireless connection when you press Apply to confirm You must then change the wireless settings of your computer to match the ZyXEL Device s new settings Hide SSID Select this check box to hide the SSID in the outgoing beacon frame so a station cannot obtain the SSID through scanning using a site survey tool Security Mode ...

Page 109: ...to using WPS The PIN is not necessary when you use WPS push button method Generate Click this to have the ZyXEL Device create a new PIN WPS Status This displays Configured when the ZyXEL Device has connected to a wireless network using WPS or Enable WPS is selected and wireless or wireless security settings have been changed The current wireless and wireless security settings also appear in the sc...

Page 110: ... You need to know the MAC address of the peer device Once the security settings of peer sides match one another the connection between devices is made Table 36 Network Wireless LAN WPS Station LABEL DESCRIPTION Push Button Click this to add another WPS enabled wireless device within wireless range of the ZyXEL Device to your wireless network This button may either be a physical button on the outsi...

Page 111: ... key for data transmission The option is available only when you set the security mode to WPA 2 or WPA 2 PSK in the Wireless LAN AP screen TKIP Select this to use TKIP Temporal Key Integrity Protocol encryption AES Select this to use AES Advanced Encryption Standard encryption This is the index number of the individual WDS link Active Select this to activate the link between the ZyXEL Device and t...

Page 112: ... For more information see the appendix Table 38 Network Wireless LAN QoS LABEL DESCRIPTION Enable Wireless LAN Scheduling Select this box to activate wireless LAN scheduling on your ZyXEL Device Action Select On or Off to enable or disable the wireless LAN Day Check the day s you want to turn the wireless LAN on or off Except for the following times Specify a time frame during which the schedule w...

Page 113: ...s one or more access points and one or more wireless clients The wireless clients connect to the access points An ad hoc type of network is one in which there is no access point Wireless clients connect to one another in order to exchange information The following figure provides an example of a wireless network Figure 56 Example of a Wireless Network The wireless network is the part in the blue c...

Page 114: ...s but also join the network Once an unauthorized person has access to the network he or she can steal information or introduce malware malicious software intended to compromise the network For these reasons a variety of security systems have been developed to ensure that only authorized people can use a wireless data network or understand the data carried on it Table 39 Additional Wireless Terms T...

Page 115: ...lude real words For example if your mother owns a 1970 Dodge Challenger and her favorite movie is Vanishing Point which you know was made in 1971 you could use 70dodchal71vanpoi as your security key The following sections introduce different types of wireless security you can set up in the wireless network 8 8 3 1 SSID Normally the ZyXEL Device acts like a beacon and regularly broadcasts the SSID ...

Page 116: ...t in the wireless network Encryption is like a secret code If you do not know the secret code you cannot understand the message The types of encryption you can choose depend on the type of authentication See Section 8 8 3 3 on page 116 for information about this For example if the wireless network has a RADIUS server you can choose WPA or WPA2 If users do not log in to the wireless network you can...

Page 117: ...upt the data signal Interference may come from other radio transmissions such as military or air traffic control communications or from machines that are coincidental emitters such as electric motors or microwaves Problems with absorption occur when physical objects such as thick walls are between the two radios muffling the signal 8 8 5 BSS A Basic Service Set BSS exists when all communications b...

Page 118: ...ses of the APs you want to link to Once the security settings of peer sides match one another the connection between devices is made At the time of writing WDS security is compatible with other ZyXEL access points only Refer to your other access point s documentation for details The following figure illustrates how WDS link works between APs Notebook computer A is a wireless client connecting to a...

Page 119: ... key through an secure connection to the enrollee If you need to make sure that WPS worked check the list of associated wireless clients in the AP s configuration utility If you see the wireless client in the list WPS was successful 8 8 8 2 PIN Configuration Each WPS enabled device has its own PIN Personal Identification Number This may either be static it cannot be changed or dynamic in some devi...

Page 120: ...uration interface has an area for entering another device s PIN you can either enter the client s PIN in the AP or enter the AP s PIN in the client it does not matter which 6 Start WPS on both devices within two minutes 7 Use the configuration utility to activate WPS not the push button on the device itself 8 On a computer connected to the wireless client try to connect to the Internet If you can ...

Page 121: ...evice acts as the enrollee the device that receives network and security settings The registrar creates a secure EAP Extensible Authentication Protocol tunnel and sends the network name SSID and the WPA PSK or WPA2 PSK pre shared key to the enrollee Whether WPA PSK or WPA2 PSK is used depends on the standards supported by the devices If the registrar is already part of a network it sends the exist...

Page 122: ...that it is not part of an existing network and can act as either enrollee or registrar if it supports both functions If the registrar is unconfigured the security settings it transmits to the enrollee are randomly generated Once a WPS enabled device has connected to another device using WPS it becomes configured A configured wireless client can still act as enrollee or registrar in subsequent WPS ...

Page 123: ...rk You know that Client 1 supports registrar mode but it is better to use AP1 for the WPS handshake with the new client since you must connect to the access point anyway in order to use the network In this case AP1 must be the registrar since it is configured it already has security information for the network AP1 supplies the existing security information to Client 2 Figure 62 WPS Example Network...

Page 124: ...wo enrollees and one registrar you must set up the first enrollee by pressing the WPS button on the registrar and the first enrollee for example then check that it successfully enrolled then set up the second device in the same way WPS works only with other WPS enabled devices However you can still add non WPS devices to a network you already set up using WPS WPS works by automatically issuing a r...

Page 125: ... if this has happened WPS works between only two devices simultaneously so if another device has enrolled your device will be unable to enroll and will not have access to the network If this happens open the access point s configuration interface and look at the list of associated clients usually displayed by MAC address It does not matter if the access point is the WPS registrar the enrollee or w...

Page 126: ...Chapter 8 Wireless LAN AMG1202 T10A User s Guide 126 ...

Page 127: ...o enable and disable the SIP VoIP ALG in the ZyXEL Device 9 1 2 What You Need To Know About NAT Inside Outside Inside outside denotes where a host is located relative to the ZyXEL Device for example the computers of your subscribers are the inside hosts while the web servers on the Internet are the outside hosts Global Local Global local denotes the IP address of a host in a packet as the packet t...

Page 128: ...es as outlined in Table 48 on page 138 Choose SUA Only if you have just one public WAN IP address for your ZyXEL Device Choose Full Feature if you have multiple public WAN IP addresses for your ZyXEL Device Finding Out More See Section 9 6 on page 135 for advanced technical information on NAT 9 2 The NAT General Setup Screen Use this screen to activate NAT Click Network NAT to open the following s...

Page 129: ...ports a default server IP address A default server receives packets from ports that are not specified in this screen Note If you do not assign a Default Server IP address the ZyXEL Device discards all packets received for ports that are not specified here or in the remote management setup Full Feature Select this radio button if you have multiple public WAN IP addresses for your ZyXEL Device Max N...

Page 130: ...NAT Port Forwarding to open the following screen See Appendix E on page 279 for port numbers commonly used for particular services Figure 66 Network NAT Port Forwarding The following table describes the fields in this screen A 192 168 1 33 D 192 168 1 36 C 192 168 1 35 B 192 168 1 34 WAN LAN 192 168 1 1 IP Address assigned by ISP Table 42 Network NAT Port Forwarding LABEL DESCRIPTION Default Serve...

Page 131: ...r not Clear the check box to disable the rule Select the check box to enable it Service Name This is a service s name Start Port This is the first port number that identifies a service End Port This is the last port number that identifies a service Port Translation Start End Port This is the start end port number that the device translates Server IP Address This is the server s IP address Modify C...

Page 132: ...ctive Click this check box to enable the rule Service Name Enter a name to identify this port forwarding rule Start Port Enter a port number in this field To forward only one port enter the port number again in the End Port field To forward a series of ports enter the start port number here and the end port number in the End Port field End Port Enter a port number in this field To forward only one...

Page 133: ...ny to One and Server mapping types Global End IP This is the ending Inside Global IP Address IGA This field is N A for One to one Many to One and Server mapping types Type 1 1 One to one mode maps one local IP address to one global IP address Note that port numbers do not change for the One to one NAT mapping type M 1 Many to One mode maps multiple local IP addresses to one global IP address This ...

Page 134: ...ad mode maps multiple local IP addresses to shared global IP addresses Many to Many No Overload Many to Many No Overload mode maps each local IP address to unique global IP addresses Server This type allows you to specify inside servers of different services behind the NAT to be accessible to the outside world Local Start IP This is the starting local IP address ILA Local IP addresses are N A for ...

Page 135: ...0 Network NAT ALG The following table describes the fields in this screen 9 6 NAT Technical Reference This chapter contains more information regarding NAT 9 6 1 NAT Definitions Inside outside denotes where a host is located relative to the ZyXEL Device for example the computers of your subscribers are the inside hosts while the web servers on the Internet are the outside hosts Back Click this to r...

Page 136: ... hosts can be either static or dynamically assigned by the ISP In addition you can designate servers for example a web server and a telnet server on your local network and make them accessible to the outside world If you do not define any servers for Many to One and Many to Many Overload mapping see Table 48 on page 138 NAT offers the additional benefit of firewall protection With no servers defin...

Page 137: ...ible NAT application where three inside LANs logical LANs using IP alias behind the ZyXEL Device can communicate with three distinct WAN networks Figure 72 NAT Application With IP Alias 9 6 5 NAT Mapping Types NAT supports five types of IP port mapping They are 192 168 1 13 192 168 1 10 192 168 1 11 192 168 1 12 SA 192 168 1 10 SA IGA1 Inside Local IP Address 192 168 1 10 192 168 1 11 192 168 1 12...

Page 138: ...local IP addresses to shared global IP addresses Many to Many No Overload In Many to Many No Overload mode the ZyXEL Device maps each local IP address to a unique global IP address Server This type allows you to specify inside servers of different services behind the NAT to be accessible to the outside world Port numbers do NOT change for One to One and Many to Many No Overload NAT mapping types T...

Page 139: ...ack floods a targeted system with a series of SYN packets Each packet causes the targeted system to issue a SYN ACK response While the targeted system waits for the ACK that follows the SYN ACK it queues up all outstanding SYN ACK responses on a backlog queue SYN ACKs are moved off the queue only when an ACK comes back or when an internal timer terminates the three way handshake Once the queue is ...

Page 140: ...to respond to itself Ping of Death Ping of Death uses a ping utility to create and send an IP packet that exceeds the maximum 65 536 bytes of data allowed by the IP specification This may cause systems to crash hang or reboot SPI Stateful Packet Inspection SPI tracks each connection crossing the firewall and makes sure it is valid Filtering decisions are based not only on rules but also context Fo...

Page 141: ...rewall to display the following screen Figure 73 Advanced Setup Firewall The following table describes the labels in this screen Table 49 Advanced Firewall LABEL DESCRIPTION Firewall Use this field to enable or disable firewall on your ZyXEL Device Apply Click this to save your changes Cancel Click this to restore your previously saved settings ...

Page 142: ...Chapter 10 Firewall AMG1202 T10A User s Guide 142 ...

Page 143: ...to allow or deny traffic from certain types of applications Use the IP MAC Filter screen Section 11 4 on page 146 to create IP MAC filter rules 11 1 2 What You Need to Know About Filtering URL The URL Uniform Resource Locator identifies and helps locates resources on a network On the Internet the URL is the web address that you type in the address bar of your Internet browser for example http www ...

Page 144: ...Management Filter URL LABEL DESCRIPTION URL Filter Editing Active Use this field to enable or disable the URL filter URL Index Select the index number of the filter URL Enter the URL for the ZyXEL Device to block URL Filter Listing Index This is the index number of the filter rule URL This is the URL you have configured the ZyXEL Device to block Apply Click this to save your changes Delete Click t...

Page 145: ... Filter The following table describes the labels in this screen Table 51 Access Management Filter Application LABEL DESCRIPTION Application Filter Editing Application Filter Use this field to enable or disable the application filter ICQ Use this field to allow or deny ICQ traffic MSN Use this field to allow or deny MSN traffic YMSG Use this field to allow or deny Yahoo Messenger traffic Real Audio...

Page 146: ... describes the labels in this screen Table 52 Access Management Filter IP MAC LABEL DESCRIPTION IP Filter Select IP Filter Select Select IP White Filter to configure traffic to allow Select IP Black Filter to configure traffic to block IP MAC Filter Set Editing IP MAC Filter Set Index Select the index number of the filter set Interface Select the PVC to which to apply the filter Direction Apply th...

Page 147: ... filter The range of this field is 0 to 65535 This field is ignored if it is 0 Protocol Select ICMP TCP or UDP for the upper layer protocol Rule Unmatched Select the action for a packet not matching the rule Select Forward to forward traffic immediately and skip checking the remaining rules Select Next to check the next rule IP Filter Listing IP Filter Set Index Select the index number of the filt...

Page 148: ...Chapter 11 Filters AMG1202 T10A User s Guide 148 ...

Page 149: ...e static routes For example the next figure shows a computer A connected to the ZyXEL Device s LAN interface The ZyXEL Device routes most traffic from A to the Internet through the ZyXEL Device s default gateway R1 You create one static route to connect to services offered by your ISP behind router R2 You create another static route to communicate with a separate network behind a router R3 connect...

Page 150: ...is the number of an individual static route Destination This parameter specifies the IP network address of the final destination Routing is always based on network number Netmask This parameter specifies the IP network subnet mask of the final destination Gateway This is the IP address of the gateway The gateway is a router or switch on the same network segment as the device s LAN or WAN port The ...

Page 151: ... the IP network address of the final destination Routing is always based on network number If you need to specify a route to a single host use a subnet mask of 255 255 255 255 in the subnet mask field to force the network number to be identical to the host ID IP Subnet Mask Enter the IP subnet mask here Gateway IP Address Enter the IP address of the gateway The gateway is a router or switch on the...

Page 152: ...Chapter 12 Static Route AMG1202 T10A User s Guide 152 ...

Page 153: ...e 154 to activate 802 1Q 1P specify the management VLAN group display the VLAN groups and configure the settings for each VLAN group Use the Port Setting screen Section 13 3 on page 157 to configure the PVID for each port 13 1 2 What You Need to Know About 802 1Q 1P IEEE 802 1P Priority IEEE 802 1P specifies the user priority field and defines up to eight separate traffic types by inserting a tag ...

Page 154: ...VLAN tag To forward a frame from an 802 1Q VLAN unaware device to an 802 1Q VLAN aware switch the ZyXEL Device first decides where to forward the frame and then inserts a VLAN tag reflecting the ingress port s default VID The default PVID is VLAN 1 for all ports but this can be changed Whether to tag an outgoing frame depends on the setting of the egress port on a per VLAN per port basis recall th...

Page 155: ...P 1Q feature Summary This field displays the index number of the VLAN group Active This field displays whether 802 1P 1Q is active for the VLAN group VID This field displays the ID number of the VLAN group Port Number These columns display the VLAN s settings for each port A tagged port is marked as T an untagged port is marked as U and ports not participating in a VLAN are marked as Modify Click ...

Page 156: ...he group setting VLAN ID Assign a VLAN ID for the VLAN group The valid VID range is between 1 and 4094 Default Gateway Select the default gateway for the VLAN group Ports This field displays the types of ports available to join the VLAN group Control Select Fixed for the port to be a permanent member of the VLAN group Select Forbidden if you want to prohibit the port from joining the VLAN group Tx...

Page 157: ...ncel Click this to restore your previously saved settings Table 56 Advanced 802 1Q 1P Group Setting Edit continued LABEL DESCRIPTION Table 57 Advanced 802 1Q 1P Port Setting LABEL DESCRIPTION Ports This field displays the types of ports available to join the VLAN group 802 1Q PVID Assign a VLAN ID for the port The valid VID range is between 1 and 4094 The ZyXEL Device assigns the PVID to untagged ...

Page 158: ...Chapter 13 802 1Q 1P AMG1202 T10A User s Guide 158 ...

Page 159: ...ongestion allowing time sensitive applications to flow more smoothly Time sensitive applications include both those that require a low level of latency delay and a low level of jitter variations in delay such as Voice over IP VoIP or Internet gaming and those for which jitter alone is a problem such as Internet radio or streaming video In the following figure your Internet connection has an upstre...

Page 160: ...ou can use 802 1p to give different priorities to different packet types Tagging and Marking In a QoS class you can configure whether to add or change the DiffServ Code Point DSCP value IEEE 802 1p priority level and VLAN ID number in a matched packet When the packet passes through a compatible network the networking device such as a backbone switch can provide specific treatment or service based ...

Page 161: ...to improve your network performance You can give priority to traffic that the ZyXEL Device forwards out through the WAN interface Give high priority to voice and video to make them run more smoothly Similarly give low priority to many large file downloads so that they do not reduce the quality of other applications Summary Click this to open a summary table showing the QoS settings See Section 14 ...

Page 162: ...s any source port number See Appendix E on page 279 for some common services and port numbers Protocol ID Select an IP protocol type from the drop down list box Vlan ID Range Enter the source VLAN ID in this field IPP DS Field Select IPP TOS to specify an IP precedence range and type of services Select DSCP to specify a DiffServ Code Point DSCP range IP Precedence Range Enter a range from 0 to 7 f...

Page 163: ... CANCEL Click this to restore previously saved settings Table 58 Advanced Setup QoS LABEL DESCRIPTION Table 59 Advanced Setup QoS QoS Settings Summary LABEL DESCRIPTION Rules This is the rule s index number Active This shows whether the rule is enabled or disabled Physical Ports This is the physical port associated with the rule Destination MAC and IP Mask Port Ranges This is the port range for de...

Page 164: ...o traffic which does not match a class 802 1p Remarking The ZyXEL Device re assigns the priority levels specified in this field to matched traffic Queue The ZyXEL Device assigns the queue level specified in this field to matched traffic Table 59 Advanced Setup QoS QoS Settings Summary continued LABEL DESCRIPTION Table 60 IEEE 802 1p Priority Level and Traffic Type PRIORITY LEVEL TRAFFIC TYPE Level...

Page 165: ...fic in lower index queues is dropped if the network is congested Table 61 Internal Layer2 and Layer3 QoS Mapping PRIORITY QUEUE LAYER 2 LAYER 3 IEEE 802 1P USER PRIORITY ETHERNET PRIORITY TOS IP PRECEDENCE DSCP IP PACKET LENGTH BYTE 0 1 0 000000 1 2 2 0 0 000000 1100 3 3 1 001110 001100 001010 001000 250 1100 4 4 2 010110 010100 010010 010000 5 5 3 011110 011100 011010 011000 250 6 6 4 100110 1001...

Page 166: ...Chapter 14 Quality of Service QoS AMG1202 T10A User s Guide 166 ...

Page 167: ...f all you need to have registered a dynamic DNS account with www dyndns org This is for people with a dynamic IP from their ISP or DHCP server that would still like to have a domain name The Dynamic DNS service provider will give you a password or key 15 1 1 What You Can Do in the DDNS Screen Use the Dynamic DNS screen Section 15 2 on page 168 to enable DDNS and configure the DDNS settings on the ...

Page 168: ...dynamic DNS Service Provider This is the name of your Dynamic DNS service provider Dynamic DNS Type Select the type of service that you are registered for from your Dynamic DNS service provider Host Name Type the domain name assigned to your ZyXEL Device by your Dynamic DNS provider You can specify up to two host names in the field separated by a comma User Name Type your user name Password Type t...

Page 169: ...N you still need to configure a firewall rule to allow access You may manage your ZyXEL Device from a remote location via Internet WAN only LAN only LAN and WAN None Disable To disable remote management of a service select Disable in the corresponding Service Access field You may only have one remote management session running at a time The ZyXEL Device automatically disconnects a remote managemen...

Page 170: ...n 16 7 on page 177 to set whether or not your ZyXEL Device will respond to pings and probes for services that you have not made available 16 1 2 What You Need to Know About Remote Management Remote Management Limitations Remote management does not work when You have not enabled that service on the interface in the corresponding remote management screen You have disabled that service in one of the ...

Page 171: ...cess and from which IP address the access can come Table 63 Advanced Remote Management WWW LABEL DESCRIPTION Server Port You may change the server port number for a service if needed However you must use the same port number in order to use that service for remote management Server Access Select the interface s through which a computer may access the ZyXEL Device using this service Secured Client ...

Page 172: ...nt Telnet LABEL DESCRIPTION Server Port You may change the server port number for a service if needed however you must use the same port number in order to use that service for remote management Server Access Select the interface s through which a computer may access the ZyXEL Device using this service Secured Client IP Address A secured client is a trusted computer that is allowed to communicate ...

Page 173: ... Device through the network The ZyXEL Device Table 65 Advanced Remote MGMT FTP LABEL DESCRIPTION Server Port You may change the server port number for a service if needed However you must use the same port number in order to use that service for remote management Server Access Select the interface s through which a computer may access the ZyXEL Device using this service Secured Client IP Address A...

Page 174: ...piece of information to be collected about a device Examples of variables include such as number of packets received node port status etc A Management Information Base MIB is a collection of managed objects SNMP allows a manager and agents to communicate for the purpose of accessing these objects SNMP itself is a simple request response protocol based on the manager agent model The manager issues ...

Page 175: ...ng this service Secured Client IP Address A secured client is a trusted computer that is allowed to access the SNMP agent on the ZyXEL Device Select All to allow any computer to access the SNMP agent Choose Selected to just allow the computer with the IP address that you specify to access the SNMP agent SNMP Configuration Get Community Enter the Get Community which is the password for the incoming...

Page 176: ...n Apply Click Apply to save your changes back to the ZyXEL Device Cancel Click Cancel to begin configuring this screen afresh Table 66 Advanced Remote MGMT SNMP continued LABEL DESCRIPTION Table 67 Advanced Remote Management DNS LABEL DESCRIPTION Server Port The DNS service port number is 53 and cannot be changed here Server Access Select the interface s through which a computer may send DNS queri...

Page 177: ...onfigure the firewall anti probing settings to match Figure 95 Advanced Remote Management ICMP The following table describes the labels in this screen Table 68 Advanced Remote Management ICMP LABEL DESCRIPTION ICMP Internet Control Message Protocol is a message control and error reporting protocol between a host server and a gateway to the Internet ICMP uses Internet Protocol IP datagrams but the ...

Page 178: ... UPnP compatible device installed on your network will appear as a separate icon Selecting the icon of a UPnP device will allow you to access the information and properties of that device NAT Traversal UPnP NAT traversal automates the process of allowing an application to operate through NAT UPnP network devices can automatically configure network addressing announce their presence in the network ...

Page 179: ... screen shown next See Section 17 1 on page 178 for more information Figure 96 Advanced UPnP General The following table describes the fields in this screen Table 69 Advanced UPnP General LABEL DESCRIPTION Active the Universal Plug and Play UPnP Feature Select this check box to activate UPnP Be aware that anyone could use a UPnP application to open the web configurator s login screen without enter...

Page 180: ...w the steps below to install the UPnP in Windows Me 1 Click Start and Control Panel Double click Add Remove Programs 2 Click on the Windows Setup tab and select Communication in the Components selection box Click Details Add Remove Programs Windows Setup Communication Apply Click this to save your changes Cancel Click this to restore your previously saved settings Table 69 Advanced UPnP General LA...

Page 181: ...omponents selection box Add Remove Programs Windows Setup Communication Components 4 Click OK to go back to the Add Remove Programs Properties window and click Next 5 Restart the computer when prompted Installing UPnP in Windows XP Follow the steps below to install the UPnP in Windows XP 1 Click Start and Control Panel 2 Double click Network Connections ...

Page 182: ...ions window click Advanced in the main menu and select Optional Networking Components Network Connections 4 The Windows Optional Networking Components Wizard window displays Select Networking Service in the Components selection box and click Details Windows Optional Networking Components Wizard ...

Page 183: ... Next 17 4 Using UPnP in Windows XP Example This section shows you how to use the UPnP feature in Windows XP You must already have UPnP installed in Windows XP and UPnP activated on the ZyXEL Device Make sure the computer is connected to a LAN port of the ZyXEL Device Turn on your computer and the ZyXEL Device Auto discover Your UPnP enabled Network Device 1 Click Start and Control Panel Double cl...

Page 184: ...G1202 T10A User s Guide 184 2 Right click the icon and select Properties Network Connections 3 In the Internet Connection Properties window click Settings to see the port mappings there were automatically created Internet Connection Properties ...

Page 185: ...or delete the port mappings or click Add to manually add port mappings Internet Connection Properties Advanced Settings Internet Connection Properties Advanced Settings Add 5 When the UPnP enabled device is disconnected from your computer all port mappings will be deleted automatically ...

Page 186: ...play your current Internet connection status Internet Connection Status Web Configurator Easy Access With UPnP you can access the web based configurator on the ZyXEL Device without finding out the IP address of the ZyXEL Device first This comes helpful if you do not know the IP address of the ZyXEL Device Follow the steps below to access the web configurator 1 Click Start and then Control Panel 2 ...

Page 187: ...Universal Plug and Play UPnP AMG1202 T10A User s Guide 187 3 Select My Network Places under Other Places Network Connections 4 An icon with the description for each UPnP enabled device displays under Local Network ...

Page 188: ...EL Device and select Invoke The web configurator login screen displays Network Connections My Network Places 6 Right click on the icon for your ZyXEL Device and select Properties A properties window displays with basic information about the ZyXEL Device Network Connections My Network Places Properties Example ...

Page 189: ... 18 2 The General Screen Use this screen to configure system admin password Click Maintenance System to open the General screen Figure 97 Maintenance System General The following table describes the labels in this screen Table 70 Maintenance System General LABEL DESCRIPTION Password Admin Password Old Password Type the default password or the existing password you use to access the system in this ...

Page 190: ...e the new password again for confirmation Apply Click this to save your changes Cancel Click this to restore your previously saved settings Table 70 Maintenance System General LABEL DESCRIPTION Table 71 Maintenance System Time and Date LABEL DESCRIPTION Current Time and Date Current Time This field displays the time of your ZyXEL Device Each time you reload this page the ZyXEL Device synchronizes ...

Page 191: ... if you selected Enable Daylight Saving The o clock field uses the 24 hour format Here are a couple of examples Daylight Saving Time starts in most parts of the United States on the second Sunday of March Each time zone in the United States starts using Daylight Saving Time at 2 A M local time So in the United States you would select Second Sunday March and type 2 in the o clock field Daylight Sav...

Page 192: ...System Settings AMG1202 T10A User s Guide 192 Apply Click this to save your changes Cancel Click this to restore your previously saved settings Table 71 Maintenance System Time and Date continued LABEL DESCRIPTION ...

Page 193: ...ted access to blocked web sites Some categories such as System Errors consist of both logs and alerts You may differentiate them by their color in the View Log screen Alerts display in red and logs display in black Logs A log is a message about an event that occurred on your ZyXEL Device For example when someone logs in to the ZyXEL Device you can set a schedule for how often logs should be enable...

Page 194: ...able 72 Maintenance Logs Log Settings LABEL DESCRIPTION System Log Log Type Select the types of logs that you want to display and record Then click Submit to display the details Clear Log Click this to delete all the logs Save Log Click this to save the logs in a text file Table 73 System Maintenance Logs LOG MESSAGE DESCRIPTION Time calibration is successful The router has adjusted its time based...

Page 195: ...outer got the time and date from the NTP server Connect to Daytime server fail The router was not able to connect to the Daytime server Connect to Time server fail The router was not able to connect to the Time server Connect to NTP server fail The router was not able to connect to the NTP server Too large ICMP packet has been dropped The router dropped an ICMP packet that was too large Configurat...

Page 196: ...NAT table entry Router sent blocked web site message TCP The router sent a message to notify a user that the router blocked access to a web site that the user requested Table 76 TCP Reset Logs LOG MESSAGE DESCRIPTION Under SYN flood attack sent TCP RST The router sent a TCP reset packet when a host was under a SYN flood attack the TCP incomplete count is per destination host Exceed TCP MAX incompl...

Page 197: ...ket Direction type d code d ICMP access matched the default policy and was blocked or forwarded according to the user s setting Firewall rule NOT match ICMP Packet Direction rule d type d code d ICMP access matched or didn t match a firewall rule denoted by its number and was blocked or forwarded according to the rule Triangle route packet forwarded ICMP The firewall allowed a triangle route sessi...

Page 198: ...ction s Internet Protocol Control Protocol stage is opening ppp LCP Closing The PPP connection s Link Control Protocol stage is closing ppp IPCP Closing The PPP connection s Internet Protocol Control Protocol stage is closing Table 81 UPnP Logs LOG MESSAGE DESCRIPTION UPnP pass through Firewall UPnP packets can pass through the firewall Table 82 Content Filtering Logs LOG MESSAGE DESCRIPTION s blo...

Page 199: ...ll classified an ICMP packet with no source routing entry as an IP spoofing attack vulnerability ICMP type d code d The firewall detected an ICMP vulnerability attack traceroute ICMP type d code d The firewall detected an ICMP traceroute attack Table 84 802 1X Logs LOG MESSAGE DESCRIPTION RADIUS accepts user A user was authenticated by the RADIUS Server RADIUS rejects user Pls check RADIUS Server ...

Page 200: ...ce Table 86 ICMP Notes TYPE CODE DESCRIPTION 0 Echo Reply 0 Echo reply message 3 Destination Unreachable 0 Net unreachable 1 Host unreachable 2 Protocol unreachable 3 Port unreachable 4 A packet that needed fragmentation was dropped because it was set to Don t Fragment DF 5 Source route failed 4 Source Quench 0 A gateway may discard internet datagrams if it does not have the buffer space needed to...

Page 201: ...s message is sent by the system RAS displays as the system name if you haven t configured one when the router generates a syslog The facility is defined in the web MAIN MENU LOGS Log Settings page The severity is the log s syslog class The definition of messages and notes are defined in the various log charts throughout this appendix The devID is the last three characters of the MAC address of the...

Page 202: ...Chapter 19 Logs AMG1202 T10A User s Guide 202 ...

Page 203: ...download new firmware releases from your nearest ZyXEL FTP site or www zyxel com to use to upgrade your device s performance Only use firmware for your device s specific model Refer to the label on the bottom of your ZyXEL Device 20 1 1 What You Can Do in the Tool Screens Use the Firmware Upgrade screen Section 20 2 on page 203 to upload firmware to your device Use the Configuration screen Section...

Page 204: ...vice again Figure 101 Firmware Upload In Progress Table 89 Maintenance Tools Firmware LABEL DESCRIPTION Current Firmware Version This is the present Firmware version and the date created File Path Type in the location of the file you want to upload in this field or click Browse to find it Browse Click this to find the bin file you want to upload Remember that you must decompress compressed zip fil...

Page 205: ...n some operating systems you may see the following icon on your desktop Figure 102 Network Temporarily Disconnected After two minutes log in again and check your new firmware version in the Status screen If the upload was not successful the following screen will appear Click Return to go back to the Firmware screen Figure 103 Error Message ...

Page 206: ...ZyXEL Device is configured and functioning properly it is highly recommended that you back up your configuration file before making configuration changes The backup configuration file will be useful in case you need to return to your previous settings Click Backup to save the ZyXEL Device s current configuration to your computer Restore Configuration Restore Configuration allows you to upload a ne...

Page 207: ...work Temporarily Disconnected If you uploaded the default configuration file you may need to change the IP address of your computer to be in the same subnet as that of the default device IP address 192 168 1 1 See Appendix A on page 225 for details on how to set up your computer s IP address If the upload was not successful the following screen will appear Click Return to go back to the Configurat...

Page 208: ...also press the RESET button on the rear panel to reset the factory defaults of your ZyXEL Device Refer to Section 1 7 on page 25 for more information on the RESET button 20 4 The Restart Screen System restart allows you to reboot the ZyXEL Device remotely without turning the power off You may need to do this if the ZyXEL Device hangs for example Click Maintenance Tools Restart Click Restart to hav...

Page 209: ... You Can Do in the Diagnostic Screens Use the General screen Section 21 2 on page 209 to ping an IP address Use the DSL Line screen Section 21 3 on page 210 to view the DSL line statistics and reset the ADSL line 21 2 The General Screen Use this screen to ping an IP address Click Maintenance Diagnostic to open the screen shown next Figure 111 Maintenance Diagnostic General ...

Page 210: ... line statistics and reset the ADSL line Click Maintenance Diagnostic DSL Line to open the screen shown next Figure 112 Maintenance Diagnostic DSL Line Table 91 Maintenance Diagnostic General LABEL DESCRIPTION TCP IP Address Type the IP address of a computer that you want to ping in order to test a connection Ping Click this to ping the IP address that you entered ...

Page 211: ... the number of ATM cells sent that were rejected inF4Pkts is the number of ATM Operations Administration and Management OAM F4 cells that have been received See ITU recommendation I 610 for more on OAM for ATM outF4Pkts is the number of ATM OAM F4 cells that have been sent inF5Pkts is the number of ATM OAM F5 cells that have been received outF5Pkts is the number of ATM OAM F5 cells that have been ...

Page 212: ...ne the quality of the connection whether a given sub carrier loop has sufficient margins to support certain ADSL transmission rates and possibly to determine whether particular specific types of interference or line attenuation exist Refer to the ITU T G 992 1 recommendation for more information on DMT The better or shorter the line the higher the number of bits transmitted for a DMT tone The maxi...

Page 213: ... you are using the power adaptor or cord included with the ZyXEL Device 3 Make sure the power adaptor or cord is connected to the ZyXEL Device and plugged in to an appropriate power source Make sure the power source is turned on 4 Turn the ZyXEL Device off and on 5 If the problem continues contact the vendor One of the LEDs does not behave as expected 1 Make sure you understand the normal behavior...

Page 214: ...f this does not work you have to reset the device to its factory defaults See Section 1 7 on page 25 I cannot see or access the Login screen in the web configurator 1 Make sure you are using the correct IP address The default IP address is 192 168 1 1 If you changed the IP address Section 7 2 on page 86 use the new IP address If you changed the IP address and have forgotten it see the troubleshoot...

Page 215: ...ther session or ask the person who is logged in to log out 3 Turn the ZyXEL Device off and on 4 If this does not work you have to reset the device to its factory defaults See Section 22 1 on page 213 I cannot Telnet to the ZyXEL Device See the troubleshooting suggestions for I cannot see or access the Login screen in the web configurator Ignore the suggestions about your browser I cannot use FTP t...

Page 216: ... Turn the ZyXEL Device off and on 3 If the problem continues contact your ISP The Internet connection is slow or intermittent 1 There might be a lot of traffic on the network Look at the LEDs and check Section 1 6 on page 24 If the ZyXEL Device is sending or receiving a lot of information try closing some programs that use the Internet especially peer to peer applications 2 Check the signal streng...

Page 217: ...tton Restores factory defaults Antenna 1 internal antenna 3dBi WPS Button 1 second turn on or off WLAN 5 seconds enable WPS Wi Fi Protected Setup Operation Temperature 0º C 40º C Storage Temperature 20º 60º C Operation Humidity 20 90 RH Storage Humidity 20 90 RH Table 94 Firmware Specifications Default IP Address 192 168 1 1 Default Subnet Mask 255 255 255 0 24 bits Default Admin Password 1234 DHC...

Page 218: ...ports versions 1 and 2 of IGMP Internet Group Management Protocol used to join multicast groups see RFC 2236 Time and Date Get the current time and date from an external server when you turn on your ZyXEL Device You can also set the time manually These dates and times are then used in logs Logs Use logs for troubleshooting You can send logs from the ZyXEL Device to an external syslog server Univer...

Page 219: ... filtering function allows added network security and management ADSL Standards Support Multi Mode standard ANSI T1 413 Issue 2 G dmt G 992 1 G lite G992 2 EOC specified in ITU T G 992 1 ADSL2 G dmt bis G 992 3 ADSL2 G lite bis G 992 4 ADSL2 G 992 5 Reach Extended ADSL RE ADSL SRA Seamless Rate Adaptation Auto negotiating rate adaptation ADSL physical connection ATM AAL5 ATM Adaptation Layer type ...

Page 220: ...le 95 Wireless Features Internal Antenna The ZyXEL Device is equipped with one internal antenna to provide a clear radio signal between the wireless stations and the access points Wireless LAN MAC Address Filtering Your device can check the MAC addresses of wireless stations against a list of allowed or denied MAC addresses WEP Encryption WEP Wired Equivalent Privacy encrypts data frames before tr...

Page 221: ...ported STANDARD DESCRIPTION RFC 867 Daytime Protocol RFC 868 Time Protocol RFC 1058 RIP 1 Routing Information Protocol RFC 1112 IGMP v1 RFC 1305 Network Time Protocol NTP version 3 RFC 1483 Multiprotocol Encapsulation over ATM Adaptation Layer 5 RFC 1631 IP Network Address Translator NAT RFC 1661 The Point to Point Protocol PPP RFC 1723 RIP 2 Routing Information Protocol RFC 2236 Internet Group Ma...

Page 222: ... ITU G 992 4 G lite bis ITU standard also referred to as ADSL2 that extends the capability of basic ADSL in data rates ITU G 992 5 ADSL2 ITU standard also referred to as ADSL2 that extends the capability of basic ADSL by doubling the number of downstream bits Microsoft PPTP MS PPTP Microsoft s implementation of Point to Point Tunneling Protocol MBM v2 Media Bandwidth Management v2 RFC 2383 ST2 ove...

Page 223: ...Chapter 23 Product Specifications AMG1202 T10A User s Guide 223 ...

Page 224: ...Chapter 23 Product Specifications AMG1202 T10A User s Guide 224 ...

Page 225: ...application package TCP IP should already be installed on computers using Windows NT 2000 XP Macintosh OS 7 and later operating systems After the appropriate TCP IP components are installed configure the TCP IP settings in order to communicate with your network If you manually assign IP information instead of using dynamic assignment make sure that your computers have IP addresses that place them ...

Page 226: ...w click Add 2 Select Protocol and then click Add 3 Select Microsoft from the list of manufacturers 4 Select TCP IP from the list of network protocols and then click OK If you need Client for Microsoft Networks 1 Click Add 2 Select Client and then click Add 3 Select Microsoft from the list of manufacturers 4 Select Client for Microsoft Networks from the list of network clients and then click OK 5 R...

Page 227: ... Address and Subnet Mask fields Figure 114 Windows 95 98 Me TCP IP Properties IP Address 3 Click the DNS Configuration tab If you do not know your DNS information select Disable DNS If you know your DNS information select Enable DNS and type the information in the fields below you may not need to fill them all in Figure 115 Windows 95 98 Me TCP IP Properties DNS Configuration ...

Page 228: ...se the Network window Insert the Windows CD if prompted 7 Turn on your ZyXEL Device and restart your computer when prompted Verifying Settings 1 Click Start and then Run 2 In the Run window type winipcfg and then click OK to open the IP Configuration window 3 Select your network adapter You should see your computer s IP address subnet mask and default gateway Windows 2000 NT XP The following examp...

Page 229: ... 229 2 In the Control Panel double click Network Connections Network and Dial up Connections in Windows 2000 NT Figure 117 Windows XP Control Panel 3 Right click Local Area Connection and then click Properties Figure 118 Windows XP Control Panel Network Connections Properties ...

Page 230: ...k Properties Figure 119 Windows XP Local Area Connection Properties 5 The Internet Protocol TCP IP Properties window opens the General tab in Windows XP If you have a dynamic IP address click Obtain an IP address automatically If you have a static IP address click Use the following IP Address and fill in the IP address Subnet mask and Default gateway fields ...

Page 231: ...IP addresses click Add In TCP IP Address type an IP address in IP address and a subnet mask in Subnet mask and then click Add Repeat the above two steps for each IP address you want to add Configure additional default gateways in the IP Settings tab by clicking Add in Default gateways In TCP IP Gateway Address type the IP address of the default gateway in Gateway To manually configure a default me...

Page 232: ...perties 7 In the Internet Protocol TCP IP Properties window the General tab in Windows XP Click Obtain DNS server address automatically if you do not know your DNS server IP address es If you know your DNS server IP address es click Use the following DNS server addresses and type them in the Preferred DNS server and Alternate DNS server fields ...

Page 233: ...the Local Area Connection Properties window 10 Close the Network Connections window Network and Dial up Connections in Windows 2000 NT 11 Turn on your ZyXEL Device and restart your computer if prompted Verifying Settings 1 Click Start All Programs Accessories and then Command Prompt 2 In the Command Prompt window type ipconfig and then press ENTER You can also open Network Connections right click ...

Page 234: ...ser s Guide 234 1 Click the Start icon Control Panel Figure 123 Windows Vista Start Menu 2 In the Control Panel double click Network and Internet Figure 124 Windows Vista Control Panel 3 Click Network and Sharing Center Figure 125 Windows Vista Network And Internet ...

Page 235: ...connections Figure 126 Windows Vista Network and Sharing Center 5 Right click Local Area Connection and then click Properties Note During this procedure click Continue whenever Windows displays a screen saying that it needs your permission to continue Figure 127 Windows Vista Network and Sharing Center ...

Page 236: ...Figure 128 Windows Vista Local Area Connection Properties 7 The Internet Protocol Version 4 TCP IPv4 Properties window opens the General tab If you have a dynamic IP address click Obtain an IP address automatically If you have a static IP address click Use the following IP address and fill in the IP address Subnet mask and Default gateway fields ...

Page 237: ... tab in IP addresses click Add In TCP IP Address type an IP address in IP address and a subnet mask in Subnet mask and then click Add Repeat the above two steps for each IP address you want to add Configure additional default gateways in the IP Settings tab by clicking Add in Default gateways In TCP IP Gateway Address type the IP address of the default gateway in Gateway To manually configure a de...

Page 238: ...roperties 9 In the Internet Protocol Version 4 TCP IPv4 Properties window the General tab Click Obtain DNS server address automatically if you do not know your DNS server IP address es If you know your DNS server IP address es click Use the following DNS server addresses and type them in the Preferred DNS server and Alternate DNS server fields ...

Page 239: ...Protocol Version 4 TCP IPv4 Properties window 11 Click Close to close the Local Area Connection Properties window 12 Close the Network Connections window 13 Turn on your ZyXEL Device and restart your computer if prompted Verifying Settings 1 Click Start All Programs Accessories and then Command Prompt 2 In the Command Prompt window type ipconfig and then press ENTER You can also open Network Conne...

Page 240: ...tting up Your Computer s IP Address AMG1202 T10A User s Guide 240 Macintosh OS 8 9 1 Click the Apple menu Control Panel and double click TCP IP to open the TCP IP Control Panel Figure 132 Macintosh OS 8 9 Apple Menu ...

Page 241: ...ress box Type your subnet mask in the Subnet mask box Type the IP address of your ZyXEL Device in the Router address box 5 Close the TCP IP Control Panel 6 Click Save if prompted to save changes to your configuration 7 Turn on your ZyXEL Device and restart your computer if prompted Verifying Settings Check your TCP IP properties in the TCP IP Control Panel window Macintosh OS X 1 Click the Apple m...

Page 242: ...ntosh OS X Network 4 For statically assigned settings do the following From the Configure box select Manually Type your IP address in the IP Address box Type your subnet mask in the Subnet mask box Type the IP address of your ZyXEL Device in the Router address box 5 Click Apply Now and close the window 6 Turn on your ZyXEL Device and restart your computer if prompted Verifying Settings Check your ...

Page 243: ...e location may vary depending on your Linux distribution and release version Note Make sure you are logged in as the root administrator Using the K Desktop Environment KDE Follow the steps below to configure your computer IP address using the KDE 1 Click the Red Hat button located on the bottom left corner select System Setting and click Network Figure 136 Red Hat 9 0 KDE Network Configuration Dev...

Page 244: ...ain IP address settings with and select dhcp from the drop down list If you have a static IP address click Statically set IP Addresses and fill in the Address Subnet mask and Default Gateway Address fields 3 Click OK to save the changes and close the Ethernet Device General screen 4 If you know your DNS server IP address es click the DNS tab in the Network Configuration screen Enter the DNS server...

Page 245: ...0 is the name of the Ethernet card Open the configuration file with any plain text editor If you have a dynamic IP address enter dhcp in the BOOTPROTO field The following figure shows an example Figure 140 Red Hat 9 0 Dynamic IP Address Setting in ifconfig eth0 If you have a static IP address enter static in the BOOTPROTO field Type IPADDR followed by the IP address in dotted decimal notation and ...

Page 246: ...s Enter ifconfig in a terminal screen to check your TCP IP properties Figure 144 Red Hat 9 0 Checking TCP IP Properties nameserver 172 23 5 1 nameserver 172 23 5 2 root localhost init d network restart Shutting down interface eth0 OK Shutting down loopback interface OK Setting network parameters OK Bringing up loopback interface OK Bringing up interface eth0 OK root localhost ifconfig eth0 Link en...

Page 247: ...er and the other part is the host ID In the same way that houses on a street share a common street name the hosts on a network share a common network number Similarly as each house has its own house number each host on the network has its own unique identifying number the host ID Routers use the network number to send packets to the correct network while the host ID determines to which host on the...

Page 248: ... 32 bits If a bit in the subnet mask is a 1 then the corresponding bit in the IP address is part of the network number If a bit in the subnet mask is 0 then the corresponding bit in the IP address is part of the host ID The following example shows a subnet mask identifying the network number in bold text and host ID of an IP address 192 168 1 2 in decimal By convention subnet masks always consist ...

Page 249: ...le As these two IP addresses cannot be used for individual hosts calculate the maximum number of possible hosts in a network as follows Notation Since the mask is always a continuous number of ones beginning from the left followed by a continuous number of zeros for the remainder of the 32 bit mask you can simply specify the number of ones instead of writing the value of each octet This is usually...

Page 250: ... a maximum of 28 2 or 254 possible hosts The following figure shows the company network before subnetting Figure 146 Subnetting Example Before Subnetting You can borrow one of the host ID bits to divide the network 192 168 1 0 into two separate sub networks The subnet mask is now 25 bits 255 255 255 128 or 25 The borrowed host ID bit can have a value of either 0 or 1 allowing two subnets 192 168 1...

Page 251: ...2 168 1 1 and the highest is 192 168 1 126 Similarly the host ID range for subnet B is 192 168 1 129 to 192 168 1 254 Example Four Subnets The previous example illustrated using a 25 bit subnet mask to divide a 24 bit address into two subnets Similarly to divide a 24 bit address into four subnets you need to borrow two host ID bits to give four possible combinations 00 01 10 and 11 The subnet mask...

Page 252: ...ost ID 192 168 1 126 Table 104 Subnet 3 IP SUBNET MASK NETWORK NUMBER LAST OCTET BIT VALUE IP Address 192 168 1 128 IP Address Binary 11000000 10101000 00000001 10000000 Subnet Mask Binary 11111111 11111111 11111111 11000000 Subnet Address 192 168 1 128 Lowest Host ID 192 168 1 129 Broadcast Address 192 168 1 191 Highest Host ID 192 168 1 190 Table 105 Subnet 4 IP SUBNET MASK NETWORK NUMBER LAST O...

Page 253: ...MASK NO SUBNETS NO HOSTS PER SUBNET 1 255 255 255 128 25 2 126 2 255 255 255 192 26 4 62 3 255 255 255 224 27 8 30 4 255 255 255 240 28 16 14 5 255 255 255 248 29 32 6 6 255 255 255 252 30 64 2 7 255 255 255 254 31 128 1 Table 108 16 bit Network Number Subnet Planning NO BORROWED HOST BITS SUBNET MASK NO SUBNETS NO HOSTS PER SUBNET 1 255 255 128 0 17 2 32766 2 255 255 192 0 18 4 16382 3 255 255 22...

Page 254: ...our ZyXEL Device will compute the subnet mask automatically based on the IP address that you entered You don t need to change the subnet mask computed by the ZyXEL Device unless you are instructed to do otherwise Private IP Addresses Every machine on the Internet must have a unique address If your networks are isolated from the Internet running only between two branch offices for example you can a...

Page 255: ...Internet Explorer Pop up Blockers You may have to disable pop up blocking to log into your device Either disable pop up blocking enabled by default in Windows XP SP Service Pack 2 or allow pop up blocking and create an exception for your device s IP address Disable Pop up Blockers 1 In Internet Explorer select Tools Pop up Blocker and then select Turn Off Pop up Blocker Figure 148 Pop up Blocker Y...

Page 256: ...of the screen This disables any web pop up blockers you may have enabled Figure 149 Internet Options Privacy 3 Click Apply to save this setting Enable Pop up Blockers with Exceptions Alternatively if you only want to allow pop up windows from your device see the following steps 1 In Internet Explorer select Tools Internet Options and then the Privacy tab ...

Page 257: ...G1202 T10A User s Guide 257 2 Select Settings to open the Pop up Blocker Settings screen Figure 150 Internet Options Privacy 3 Type the IP address of your device the web page that you do not want to have blocked with the prefix http For example http 192 168 167 1 ...

Page 258: ... Add to move the IP address to the list of Allowed sites Figure 151 Pop up Blocker Settings 5 Click Close to return to the Privacy screen 6 Click Apply to save this setting JavaScripts If pages of the web configurator do not display properly in Internet Explorer check that JavaScripts are allowed ...

Page 259: ...lorer click Tools Internet Options and then the Security tab Figure 152 Internet Options Security 2 Click the Custom Level button 3 Scroll down to Scripting 4 Under Active scripting make sure that Enable is selected the default 5 Under Scripting of Java applets make sure that Enable is selected the default ...

Page 260: ...ck OK to close the window Figure 153 Security Settings Java Scripting Java Permissions 1 From Internet Explorer click Tools Internet Options and then the Security tab 2 Click the Custom Level button 3 Scroll down to Microsoft VM 4 Under Java permissions make sure that a safety level is selected ...

Page 261: ...sions AMG1202 T10A User s Guide 261 5 Click OK to close the window Figure 154 Security Settings Java JAVA Sun 1 From Internet Explorer click Tools Internet Options and then the Advanced tab 2 Make sure that Use Java 2 for applet under Java Sun is selected ...

Page 262: ...ck OK to close the window Figure 155 Java Sun Mozilla Firefox Mozilla Firefox 2 0 screens are used here Screens for other versions may vary You can enable Java Javascripts and pop ups in one screen Click Tools then click Options in the screen that appears Figure 156 Mozilla Firefox Tools Options ...

Page 263: ...p up Windows JavaScripts and Java Permissions AMG1202 T10A User s Guide 263 Click Content to show the screen below Select the check boxes as shown in the following screen Figure 157 Mozilla Firefox Content Security ...

Page 264: ...Appendix C Pop up Windows JavaScripts and Java Permissions AMG1202 T10A User s Guide 264 ...

Page 265: ...h is commonly referred to as an ad hoc network or Independent Basic Service Set IBSS The following diagram shows an example of notebook computers using wireless adapters to form an ad hoc wireless LAN Figure 158 Peer to Peer Communication in an Ad hoc Network BSS A Basic Service Set BSS exists when all communications between wireless clients or between a wireless client and a wired network client ...

Page 266: ... ESS consists of a series of overlapping BSSs each containing an access point with each access point connected together by a wired network This wired connection between APs is called a Distribution System DS This type of wireless LAN topology is called an Infrastructure WLAN The Access Points not only provide communication with the wired network but also mediate wireless network traffic in the imm...

Page 267: ...duce interference Interference occurs when radio signals from different access points overlap causing interference and degrading performance Adjacent channels partially overlap however To avoid interference due to overlap your AP should be on a channel at least five channels away from a channel that an adjacent AP is using For example if your region has 11 channels and an adjacent AP is using chan...

Page 268: ...ves and confirms with the requesting station the time frame for the requested transmission Stations can send frames smaller than the specified RTS CTS directly to the AP without the RTS Request To Send CTS Clear to Send handshake You should only configure RTS CTS if the possibility of hidden nodes exists on your network and the cost of resending large frames is more than the extra network overhead...

Page 269: ...e short preamble when all wireless devices on the network support it otherwise the ZyXEL Device uses long preamble Note The wireless devices MUST use the same preamble mode in order to communicate IEEE 802 11g Wireless LAN IEEE 802 11g is fully compatible with the IEEE 802 11b standard This means an IEEE 802 11b adapter can interface directly with an IEEE 802 11g access point and vice versa at 11 ...

Page 270: ... user profile and accounting management on a network RADIUS server Support for EAP Extensible Authentication Protocol RFC 2486 that allows additional authentication methods to be deployed with no changes to the access point or the wireless clients RADIUS RADIUS is based on a client server model that supports authentication authorization and accounting The access point is the client and the server ...

Page 271: ...network security the access point and the RADIUS server use a shared secret key which is a password they both know The key is not sent over the network In addition to the shared key password information exchanged is also encrypted to protect the network from unauthorized access Types of EAP Authentication This section discusses some popular authentication types EAP MD5 EAP TLS EAP TTLS PEAP and LE...

Page 272: ... makes user identity vulnerable to passive attacks A digital certificate is an electronic ID card that authenticates the sender s identity However to implement EAP TLS you need a Certificate Authority CA to handle certificates which imposes a management overhead EAP TTLS Tunneled Transport Layer Service EAP TTLS is an extension of the EAP TLS authentication that uses certificates for only the serv...

Page 273: ...ires a single identical password entered into each access point wireless gateway and wireless client As long as the passwords match a wireless client will be granted access to a WLAN If the AP or the wireless clients do not support WPA2 just use WPA or WPA PSK depending on whether you have an external RADIUS server or not Select WEP only when the AP and or wireless clients do not support WPA or WP...

Page 274: ...common password approach makes WPA 2 PSK susceptible to brute force password guessing attacks but it s still an improvement over WEP as it employs a consistent single alphanumeric password to derive a PMK which is used to generate unique temporal encryption keys This prevent all wireless devices sharing the same encryption keys a weakness of WEP User Authentication WPA and WPA2 apply IEEE 802 1x a...

Page 275: ...RADIUS server distributes the PMK to the AP The AP then sets up a key hierarchy and management system using the PMK to dynamically generate unique data encryption keys The keys are used to encrypt every data packet that is wirelessly communicated between the AP and the wireless clients Figure 162 WPA 2 with RADIUS Application Example WPA 2 PSK Application Example A WPA 2 PSK application looks as f...

Page 276: ...a couples RF signals onto air A transmitter within a wireless device sends an RF signal to the antenna which propagates the signal through the air The antenna also operates in reverse by capturing RF signals from the air Positioning the antennas properly increases the range and coverage area of a wireless LAN Table 112 Wireless Security Relational Matrix AUTHENTICATION METHOD KEY MANAGEMENT PROTOC...

Page 277: ...are two types of antennas used for wireless LAN applications Omni directional antennas send the RF signal out in all directions on a horizontal plane The coverage area is torus shaped like a donut which makes these antennas ideal for a room environment With a wide coverage area it is possible to make circular overlapping coverage areas with multiple access points Directional antennas concentrate t...

Page 278: ...Appendix D Wireless LANs AMG1202 T10A User s Guide 278 ...

Page 279: ...pe of IP protocol used by the service If this is TCP UDP then the service uses the same port number with TCP and UDP If this is USER DEFINED the Port s is the IP protocol number not the port number Port s This value depends on the Protocol If the Protocol is TCP UDP or TCP UDP this is the IP port number If the Protocol is USER this is the IP protocol number Description This is a brief explanation ...

Page 280: ...l a program to enable fast transfer of files including large files that may not be possible by e mail H 323 TCP 1720 NetMeeting uses this protocol HTTP TCP 80 Hyper Text Transfer Protocol a client server protocol for the world wide web HTTPS TCP 443 HTTPS is a secured http session often used in e commerce ICMP User Defined 1 Internet Control Message Protocol is often used for diagnostic purposes I...

Page 281: ...GRE User Defined 47 PPTP Point to Point Tunneling Protocol enables secure transfer of data over public networks This is the data channel RCMD TCP 512 Remote Command Service REAL_AUDIO TCP 7070 A streaming audio service that enables real time sound over the web REXEC TCP 514 Remote Execution Daemon RLOGIN TCP 513 Remote Login ROADRUNNER TCP UDP 1026 This is an ISP that provides services mainly for ...

Page 282: ...1558 Stream Works Protocol SYSLOG UDP 514 Syslog allows you to send system logs to a UNIX server TACACS UDP 49 Login Host Protocol used for Terminal Access Controller Access Control System TELNET TCP 23 Telnet is the login and terminal emulation protocol common on the Internet and in UNIX environments It operates over TCP IP networks Its primary function is to allow users to log into remote host s...

Page 283: ...tice Trademarks ZyNOS ZyXEL Network Operating System is a registered trademark of ZyXEL Communications Inc Other trademarks mentioned in this publication are used for identification purposes only and may be properties of their respective owners Certifications Federal Communications Commission FCC Interference Statement The device complies with Part 15 of FCC rules Operation is subject to the follo...

Page 284: ...or 802 11g operation of this product in the U S A is firmware limited to channels 1 through 11 To comply with FCC RF exposure compliance requirements a separation distance of at least 20 cm must be maintained between the antenna of this device and all persons 注意 依據 低功率電波輻射性電機管理辦法 第十二條 經型式認證合格之低功率射頻電機 非經許可 公司 商號或使用 者均不得擅自變更頻率 加大功率或變更原設計之特性及功能 第十四條 低功率射頻電機之使用不得影響飛航安全及干擾合法通信 經發現 有干擾現象時 應立即停用 並改善至無干擾時...

Page 285: ... with damaged by an act of God or subjected to abnormal working conditions Note Repair or replacement as provided under this warranty is the exclusive remedy of the purchaser This warranty is in lieu of all other warranties express or implied including any implied warranty of merchantability or fitness for a particular use or purpose ZyXEL shall in no event be held liable for indirect or consequen...

Page 286: ...Appendix F Legal Information AMG1202 T10A User s Guide 286 ...

Page 287: ...ord 28 189 alerts 193 alternative subnet mask notation 250 antenna directional 277 gain 277 omni directional 277 AP access point 267 application filter 145 applications NAT 137 Asynchronous Transfer Mode see ATM ATM 211 MBS 74 78 PCR 74 78 QoS 74 78 82 SCR 74 78 status 211 authentication 114 116 RADIUS server 116 WPA 104 B backup configuration 206 Basic Service Set See BSS 265 Basic Service Set se...

Page 288: ...c DNS 167 activation 168 wildcard 167 activation 168 Dynamic Host Configuration Protocol see DHCP dynamic WEP key exchange 272 DYNDNS wildcard 167 activation 168 E EAP Authentication 271 encapsulation 69 72 77 ENET ENCAP 79 PPPoA 80 PPPoE 79 RFC 1483 80 encryption 99 116 273 WEP 100 key 101 WPA 103 authentication 104 reauthentication 103 WPA PSK 102 pre shared key 102 ENET ENCAP 72 77 79 ESS 266 E...

Page 289: ...IP precedence 162 164 configuration 162 IP MAC filter 146 structure 143 L LAN 85 client list 89 DHCP 86 89 93 DNS 86 89 93 IGMP 86 95 IP address 85 86 93 IP alias 90 configuration 91 MAC address 90 multicast 86 88 95 RIP 86 88 92 94 status 34 subnet mask 86 87 93 LAND attack 140 LEDs 24 limitations wireless LAN 117 WPS 124 Local Area Network see LAN login 27 passwords 27 28 logs 193 alerts 193 set...

Page 290: ... NAT P P2P 129 Pairwise Master Key PMK 274 275 passwords 27 28 administrator 189 PBC 119 PCR 74 78 81 Peak Cell Rate see PCR PIN WPS 109 110 119 example 121 Ping of Death 140 port forwarding 128 129 activation 132 configuration 130 example 130 rules 131 PPPoA 72 77 80 PPPoE 72 77 79 preamble 105 114 preamble mode 269 pre shared key 102 private IP address 94 product registration 285 PSK 274 push bu...

Page 291: ...cedence 162 logs 193 port forwarding 130 static route 151 WAN 71 wireless LAN 99 wizard 58 shaping traffic 81 82 Simple Network Management Protocol see SNMP Single User Account see SUA SIP ALG 135 activation 135 SNMP 173 174 agents 174 Get 174 GetNext 174 Manager 174 managers 174 MIB 174 network components 174 Set 174 Trap 174 versions 173 SPI 140 SSID 98 99 108 115 activation 107 MBSSID 118 stati...

Page 292: ... Area Network see VLAN Virtual Path Identifier see VPI VLAN 153 802 1P priority 153 activation 154 group settings 156 port settings 157 PVC 154 PVID 157 tagging frames 153 154 156 VPI 72 77 80 W WAN 69 ATM QoS 74 78 82 encapsulation 69 72 77 IGMP 70 IP address 69 72 77 80 mode 72 76 MTU 74 79 multicast 70 74 multiplexing 72 77 80 nailed up connection 72 77 81 NAT 77 RIP 73 setup 71 status 34 traff...

Page 293: ... 110 example 122 limitations 124 PIN 109 110 119 push button 23 110 119 status 109 wireless security 269 Wireless tutorial 38 wizard 55 configuration 58 wireless LAN 63 WLAN interference 267 security parameters 276 WPA 103 116 273 authentication 104 key caching 274 pre authentication 274 reauthentication 103 user authentication 274 vs WPA PSK 274 wireless client supplicant 274 with RADIUS applicat...

Page 294: ...Index AMG1202 T10A User s Guide 294 ...

Page 295: ...Index AMG1202 T10A User s Guide 295 ...

Page 296: ...Index AMG1202 T10A User s Guide 296 ...

Reviews: