background image

ZyXEL MAX-200M1 Series User’s Guide

219

A

P P E N D I X

B

WiMAX Security

Wireless security is vital to protect your wireless communications. Without it, information 
transmitted over the wireless network would be accessible to any networking device within 
range.

User Authentication and Data Encryption

The WiMAX (IEEE 802.16) standard employs user authentication and encryption to ensure 
secured communication at all times.

User authentication is the process of confirming a user’s identity and level of authorization. 
Data encryption is the process of encoding information so that it cannot be read by anyone 
who does not know the code. 

WiMAX uses PKMv2 (Privacy Key Management version 2) for authentication, and CCMP 
(Counter Mode with Cipher Block Chaining Message Authentication Protocol) for data 
encryption. 

WiMAX supports EAP (Extensible Authentication Protocol, RFC 2486) which allows 
additional authentication methods to be deployed with no changes to the base station or the 
mobile or subscriber stations.

PKMv2

PKMv2 is a procedure that allows authentication of a mobile or subscriber station and 
negotiation of a public key to encrypt traffic between the MS/SS and the base station. PKMv2 
uses standard EAP methods such as Transport Layer Security (EAP-TLS) or Tunneled TLS 
(EAP-TTLS) for secure communication. 

In cryptography, a ‘key’ is a piece of information, typically a string of random numbers and 
letters, that can be used to ‘lock’ (encrypt) or ‘unlock’ (decrypt) a message. Public key 
encryption uses key pairs, which consist of a public (freely available) key and a private 
(secret) key. The public key is used for encryption and the private key is used for decryption. 
You can decrypt a message only if you have the private key. Public key certificates (or ‘digital 
IDs’) allow users to verify each other’s identity. 

Summary of Contents for MAX-200M1 Series

Page 1: ...MAX 200M1 Series IEEE 802 16e Simple Indoor CPE User s Guide Version 3 60 04 2007 Edition 1...

Page 2: ......

Page 3: ...by ZyXEL Communications Corporation All rights reserved Disclaimer ZyXEL does not assume any liability arising out of the application or use of any products or software described herein Neither does i...

Page 4: ...erference to radio television reception which can be determined by turning the device off and on the user is encouraged to try to correct the interference by one or more of the following measures 1 Re...

Page 5: ...by the party responsible for compliance could void the user s authority to operate the equipment Viewing Certifications 1 Go to http www zyxel com 2 Select your product from the drop down list box on...

Page 6: ...n appropriate power adaptor or cord for your device Connect the power adaptor or cord to the right supply voltage for example 110V AC in North America or 230V AC in Europe Do NOT allow anything to res...

Page 7: ...ZyXEL MAX 200M1 Series User s Guide Safety Warnings 7 This product is recyclable Dispose of it properly...

Page 8: ...placement as provided under this warranty is the exclusive remedy of the purchaser This warranty is in lieu of all other warranties express or implied including any implied warranty of merchantability...

Page 9: ...a 4 Modrany Cesk Republika info cz zyxel com 420 241 091 359 DENMARK support zyxel dk 45 39 55 07 00 www zyxel dk ZyXEL Communications A S Columbusvej 2860 Soeborg Denmark sales zyxel dk 45 39 55 07 0...

Page 10: ...support zyxel es 34 902 195 420 www zyxel es ZyXEL Communications Arte 21 5 planta 28033 Madrid Spain sales zyxel es 34 913 005 345 SWEDEN support zyxel se 46 31 744 7700 www zyxel se ZyXEL Communicat...

Page 11: ...our ZyXEL Device 29 1 1 1 Wireless Internet Access 29 1 1 2 Make Calls via Internet Telephony Service Provider 30 1 2 ZyXEL Device Hardware 31 1 2 1 LEDs 31 1 2 2 Antenna 32 Chapter 2 Introducing the...

Page 12: ...ction Wizard Setup 49 Chapter 5 VoIP Wizard 55 5 1 Introduction 55 5 2 VOIP Wizard Setup 55 Chapter 6 Status Screens 59 6 1 Status Screen 59 6 2 Site Information 63 6 3 Profile 64 6 4 Any IP Table Win...

Page 13: ...NAT 97 9 1 NAT Overview 97 9 1 1 Port Forwarding Services and Port Numbers 97 9 1 2 Trigger Port Forwarding 98 9 1 2 1 Trigger Port Forwarding Example 98 9 1 2 2 Two Points To Remember About Trigger P...

Page 14: ...0 1 12 Quality of Service QoS 112 10 1 12 1 Type Of Service ToS 112 10 1 12 2 DiffServ 113 10 1 12 3 DSCP and Per Hop Behavior 113 10 1 12 4 VLAN 113 10 2 SIP Screens 114 10 2 1 SIP Settings Screen 11...

Page 15: ...Firewall Screen 135 12 3 2 Firewall Services Screen 136 Chapter 13 Phone Book 139 13 1 Phone Book Overview 139 13 2 Phone Book Screens 139 13 2 1 Incoming Call Policy Screen 139 13 2 2 Speed Dial Scr...

Page 16: ...1 4 UPnP and ZyXEL 164 17 2 UPnP Examples 164 17 2 1 Installing UPnP in Windows Example 164 17 2 1 1 Installing UPnP in Windows Me 164 17 2 1 2 Installing UPnP in Windows XP 166 17 2 2 Using UPnP in W...

Page 17: ...20 2 2 Dynamic DNS Screen 200 20 2 3 Time Setting Screen 202 Chapter 21 Troubleshooting 205 21 1 Problems Starting Up the ZyXEL Device 205 21 2 Problems with the LAN 205 21 3 Problems with the WAN 20...

Page 18: ...ndix D IP Addresses and Subnetting 237 Introduction to IP Addresses 237 Structure 237 Subnet Masks 238 Notation 239 Subnetting 240 Example Four Subnets 241 Example Eight Subnets 242 Subnet Planning 24...

Page 19: ...nnection Wizard Introduction 50 Figure 18 The Connection Wizard System Information 50 Figure 19 The Connection Wizard Internet Configuration 1 51 Figure 20 The Connection Wizard ISP Username and Passw...

Page 20: ...01 Figure 57 Network NAT Port Forwarding Edit 102 Figure 58 Network NAT Trigger Port 103 Figure 59 Network NAT ALG 104 Figure 60 SIP User Agent 107 Figure 61 SIP Proxy Server 107 Figure 62 SIP Redirec...

Page 21: ...ings 170 Figure 100 Internet Connection Properties Advanced Settings Add 170 Figure 101 System Tray Icon 171 Figure 102 Internet Connection Status 171 Figure 103 Network Connections 172 Figure 104 Net...

Page 22: ...ies 229 Figure 138 Windows XP Advanced TCP IP Properties 230 Figure 139 Windows XP Internet Protocol TCP IP Properties 231 Figure 140 Macintosh OS X Apple Menu 232 Figure 141 Macintosh OS X Network 23...

Page 23: ...ncy 77 Table 17 Example Supported Frequencies GHz 77 Table 18 Network WAN Advanced 79 Table 19 Network WAN Traffic Redirect 80 Table 20 Network LAN IP 88 Table 21 Network LAN DHCP Setup 89 Table 22 Ne...

Page 24: ...Remote Management SNMP 159 Table 55 Management Remote MGMT DNS 160 Table 56 Management Remote MGMT Security 161 Table 57 Management UPnP 175 Table 58 Syslog Logs 178 Table 59 RFC 2408 ISAKMP Payload...

Page 25: ...roubleshooting Accessing Your Device 207 Table 91 Troubleshooting Telephone 213 Table 92 Product Specifications 215 Table 93 Physical Features 216 Table 94 Non Physical Features 216 Table 95 IP Addres...

Page 26: ...ZyXEL MAX 200M1 Series User s Guide 26 List of Tables...

Page 27: ...t news firmware updated documents and other support materials User Guide Feedback Help us help you E mail all User s Guide related comments questions or suggestions for improvement to techwriters zyxe...

Page 28: ...ZyXEL MAX 200M1 Series User s Guide 28 Preface Graphics Icons Key ZyXEL Device Computer Notebook Computer Wireless Signal Wireless Base Station Internet Cloud Router Server...

Page 29: ...ased Graphical User Interface GUI also known as the web configurator provides easy management See Appendix A on page 215 for a complete list of features for your model At the time of writing this User...

Page 30: ...you specify You can define time periods and days during which content filtering is enabled and include or exclude particular computers on your network from content filtering For example you could bloc...

Page 31: ...ce The following table describes your ZyXEL Device s LEDs Table 2 The ZyXEL Device LED STATE DESCRIPTION PWR OFF The ZyXEL Device is not receiving power RED The ZyXEL Device is receiving power but has...

Page 32: ...SIP account is registered GREEN BLINKING A SIP account is registered and the phone attached to the LINE port is in use off the hook ORANGE A SIP account is registered and has a voice message ORANGE B...

Page 33: ...op up windows from your device Web pop up blocking is enabled by default in Windows XP SP Service Pack 2 JavaScripts enabled by default Java permissions enabled by default See the Troubleshooting chap...

Page 34: ...w password retype it to confirm and click Apply alternatively click Ignore to proceed to the main menu if you do not want to change the password now Figure 5 Change Password Screen 6 Click Apply in th...

Page 35: ...For security reasons by default the ZyXEL Device automatically logs you out if you do not use the web configurator for five minutes If this happens log in again Figure 7 Wizard or Advanced Screen 2 1...

Page 36: ...nfigurator 2 2 Web Configurator Main Screen Figure 8 Main Screen As illustrated above the main screen is divided into these parts A title bar B navigation panel C main window D status bar 2 2 1 Title...

Page 37: ...orking settings Traffic Redirect Use this screen to configure your traffic redirect properties LAN IP Use this screen to configure LAN TCP IP settings DHCP Setup Use this screen to configure LAN DHCP...

Page 38: ...sers can use Telnet to manage the ZyXEL Device FTP Use this screen to configure through which interface s and from which IP address es users can use FTP to access the ZyXEL Device SNMP Use this screen...

Page 39: ...s information and configuration fields It is discussed in the rest of this document Right after you log in the Status screen is displayed See Chapter 6 on page 59 for more information about the Status...

Page 40: ...ZyXEL MAX 200M1 Series User s Guide 40 Chapter 2 Introducing the Web Configurator...

Page 41: ...onfigure Internet Access Settings To access the Internet you need information from your Internet Service Provider ISP about your account and the network In this example your user name is User1234 and...

Page 42: ...selected Leave all other fields at their default values 3 Click Apply Your Internet access settings are saved to the ZyXEL Device and are used automatically each time you connect to the Internet 3 1 2...

Page 43: ...his screen will be automatically set to use that frequency For an example of using the WiMAX Frequency screen to configure more frequencies see Section 7 4 2 1 on page 77 4 Look at the LEDs on your Zy...

Page 44: ...P Account Your ZyXEL Device needs to be configured with the details of your SIP account before you can use it to make calls over the Internet In this example your SIP identity is id123 abcvoip com you...

Page 45: ...Click on the Status button in the navigation panel to check that your SIP account is correctly registered Look in the VoIP Status area towards the bottom of the Status screen If the SIP 1 account dis...

Page 46: ...er you must add 555 at its start Note Different VoIP providers implement calls to other networks in different ways Check with your provider for details To configure speed dialling on the ZyXEL Device...

Page 47: ...dial list 1 Ensure that your phone is correctly connected to the ZyXEL Device See the Quick Start Guide for details of hardware connections 2 Lift the phone s receiver and type the speed dial number e...

Page 48: ...ZyXEL MAX 200M1 Series User s Guide 48 Chapter 3 Tutorial...

Page 49: ...he wizard will guide you through configuring your Internet settings 4 2 Internet Connection Wizard Setup 1 After you enter the password to access the web configurator select Go to Wizard setup Otherwi...

Page 50: ...rs this field is case sensitive or numbers The at symbol dash underscore _ and period are also permitted Enter your ISP s IP address in the Domain Name field if your ISP has instructed you to do so or...

Page 51: ...ner EAP fields at their default settings Click Next to continue Figure 20 The Connection Wizard ISP Username and Password 7 A fixed IP address is a static IP that your ISP gives you An automatic dynam...

Page 52: ...they were given to you by your ISP Figure 22 The Connection Wizard WAN IP Address Assignment 9 Every network device has a unique factory assigned Media Access Control MAC address A device s MAC addres...

Page 53: ...lick Apply to move on to the final screen Figure 23 The Connection Wizard WAN MAC Address 10Click Finish to complete and save the Connection Wizard settings Figure 24 The Connection Wizard Congratulat...

Page 54: ...ZyXEL MAX 200M1 Series User s Guide 54 Chapter 4 Internet Setup Wizard...

Page 55: ...password to access the web configurator select Go to Wizard setup Otherwise click the wizard icon in the top right corner of the web configurator to display the wizard main screen Click VOIP SETUP to...

Page 56: ...nter the SIP service domain name in this field the domain name that comes after the symbol in a SIP account like 1234 VoIP provider com You can use up to 127 ASCII Extended set characters User Name Th...

Page 57: ...few seconds and click Register Again If your Internet connection was already working you can click Back and try re entering your SIP account settings Figure 28 VoIP Wizard Fail 5 This screen displays...

Page 58: ...ZyXEL MAX 200M1 Series User s Guide 58 Chapter 5 VoIP Wizard...

Page 59: ...tus of the device system resources interfaces LAN and WAN and SIP accounts You can also register and unregister SIP accounts The Status screen also provides detailed information from Any IP and DHCP a...

Page 60: ...change this in Network WAN If you are using Roadrunner on Ethernet this is controlled by Roadrunner LAN Information IP Address This field displays the current IP address of the ZyXEL Device in the LAN...

Page 61: ...cks whether a base station has traffic waiting Idle the ZyXEL Device is in power saving mode but can connect when a base station alerts it that there is traffic waiting Handover the ZyXEL Device is mo...

Page 62: ...and static routes IVR Usage This field displays what percentage of the ZyXEL Device s IVR memory is currently used IVR Interactive Voice Response refers to the customizable ring tone and on hold musi...

Page 63: ...t it deletes the mapping between your SIP identity and your IP address or domain name The second field displays Registered If the SIP account is not registered with the SIP server Click Register to ha...

Page 64: ...isplays information about the security settings you are using To configure these settings go to the Network WAN Internet Connection screen Table 7 The Site Information Screen LABEL DESCRIPTION Site In...

Page 65: ...version number PKM provides security between the ZyXEL Device and the base station See the WiMAX security appendix for more information Authentication This field displays the user authentication meth...

Page 66: ...tics Also provided are system up time and poll interval s The Poll Interval s field is configurable Table 9 Any IP Table LABEL DESCRIPTION This field is a sequential value It is not associated with a...

Page 67: ...AX network For the LAN interface this field displays Up when the ZyXEL Device is using the interface and Down when the ZyXEL Device is not using the interface TxPkts This field displays the number of...

Page 68: ...lick Details next to VoIP Statistics Table 11 DHCP Table LABEL DESCRIPTION DHCP Table This field is a sequential value It is not associated with a specific entry IP Address This field displays the IP...

Page 69: ...t active You can activate it in VoIP SIP SIP Settings Last Registration This field displays the last time you successfully registered the SIP account It displays N A if you never successfully register...

Page 70: ...aged in a VoIP call through a phone port Duration This field displays how long the current call has lasted Tx Pkts This field displays the number of packets the ZyXEL Device has transmitted in the cur...

Page 71: ...ying interoperability of wireless broadband products In a wireless MAN a wireless equipped computer is known either as a mobile station MS or a subscriber station SS Mobile stations use the IEEE 802 1...

Page 72: ...n and Accounting server to authenticate the mobile or subscriber stations The following figure shows a base station using an AAA server to authenticate mobile station MS allowing it to access the Inte...

Page 73: ...his field displays the Privacy Key Management version number PKM provides security between the ZyXEL Device and the base station At the time of writing the ZyXEL Device supports PKMv2 only See the WiM...

Page 74: ...ssigned IP address in the IP Address field below IP Subnet Mask Enter a subnet mask in dotted decimal notation Refer to the appendices to calculate a subnet mask If you are implementing subnetting Gat...

Page 75: ...h steps In the figure each C is a bandwidth step The arrow D shows the ZyXEL Device searching for a connection Have the ZyXEL Device search only certain frequencies by configuring the downlink frequen...

Page 76: ...ext time the ZyXEL Device searches for a connection it searches only this frequency If you want the ZyXEL Device to search other frequencies enter them in the DL Frequency fields The following table d...

Page 77: ...Device to scan for a connection to a base station Table 16 Network WAN WiMAX Frequency LABEL DESCRIPTION DL Frequency 0 9 These fields show the downlink frequency settings in kilohertz kHz Enter value...

Page 78: ...t of the DL Frequency fields at zero The screen appears as follows Figure 43 Completing the WiMAX Frequency Screen 5 Click Apply The ZyXEL Device stores your settings When the ZyXEL Device searches fo...

Page 79: ...ect None if you do not want to configure DNS servers You must have another DHCP sever on your LAN or else the computers must have their DNS server addresses manually configured If you do not configure...

Page 80: ...o block all NetBIOS packets going from the LAN to the WAN and from the WAN to the LAN Allow Trigger Dial Select this option to allow NetBIOS packets to initiate calls Apply Click this button to save y...

Page 81: ...without getting a response before switching to a WAN backup connection or a different WAN backup connection Period sec The ZyXEL Device tests a WAN connection by periodically sending a ping to either...

Page 82: ...ZyXEL MAX 200M1 Series User s Guide 82 Chapter 7 WAN Setup...

Page 83: ...count and the ISP will assign you a dynamic IP address when the connection is established If this is the case it is recommended that you select a network number from 192 168 0 0 to 192 168 255 0 and y...

Page 84: ...f 192 168 1 1 with subnet mask of 255 255 255 0 24 bits DHCP server enabled with 32 client IP addresses starting from 192 168 1 33 These parameters should work for the majority of installations If you...

Page 85: ...cept all RIP packets received Out Only the ZyXEL Device will send out RIP packets but will not accept any RIP packets received None the ZyXEL Device will not send any RIP packets and will ignore any R...

Page 86: ...Device to be in the same subnet to allow the computer to access the Internet through the ZyXEL Device In cases where your computer is required to use a static IP address in another network you may nee...

Page 87: ...e Internet for the first time through the ZyXEL Device 1 When a computer which is in a different subnet first attempts to access the Internet it sends packets to its default gateway which is not the Z...

Page 88: ...n click Network LAN DHCP Setup Table 20 Network LAN IP LABEL DESCRIPTION IP Address Enter the IP address of the ZyXEL Device on the LAN Note This field is the IP address you use to access the ZyXEL De...

Page 89: ...tic DHCP Pool Size Enter the number of IP addresses to allocate This number must be at least one and is limited by a subnet mask of 255 255 255 0 regardless of the subnet the ZyXEL Device is in For ex...

Page 90: ...k LAN DHCP Setup Use this screen to look at the IP addresses the ZyXEL Device has assigned to DHCP clients on the LAN To access this screen click Network LAN Client List Table 22 Network LAN Static DH...

Page 91: ...try IP Address This field displays the IP address the ZyXEL Device assigned to the computer Host Name This field displays the system name of the computer to which the ZyXEL Device assigned the IP addr...

Page 92: ...on on the subnet Both The ZyXEL Device sends and receives routing information on the subnet In Only The ZyXEL Device only receives routing information on the subnet Out Only The ZyXEL Device only send...

Page 93: ...evice sends and receives routing information on the subnet In Only The ZyXEL Device only receives routing information on the subnet Out Only The ZyXEL Device only sends routing information on the subn...

Page 94: ...rmation RIP 2B The ZyXEL Device broadcasts RIPv2 to exchange routing information RIP 2M The ZyXEL Device multicasts RIPv2 to exchange routing information Multicast You do not have to enable multicasti...

Page 95: ...or UDP packets that enable a computer to connect to and communicate with computers on other networks It may sometimes be necessary to allow NetBIOS packets to pass through the ZyXEL Device in order to...

Page 96: ...ZyXEL MAX 200M1 Series User s Guide 96 Chapter 8 LAN...

Page 97: ...port number identifies a service for example web service is on port 80 and FTP on port 21 In some cases such as for unknown services or where one server can support more than one service for example...

Page 98: ...his problem by allowing computers on the LAN to dynamically take turns using the service The ZyXEL Device records the IP address of a LAN computer that sends traffic to the WAN to request a service wi...

Page 99: ...plication needs a continuous data stream that port range will be tied up so that another computer on the LAN can t trigger it 9 1 3 SIP ALG Some applications such as SIP cannot operate through NAT are...

Page 100: ...If you do not limit the number of NAT sessions a single client can establish this can result in all of the available NAT sessions being used In this case no additional NAT sessions can be established...

Page 101: ...his to enable this rule Clear this to disable this rule Name This field displays the name of the rule It does not have to be unique Start Port This field displays the beginning of the range of port nu...

Page 102: ...Service Name Enter a name to identify this rule You can use 1 31 printable ASCII characters or you can leave this field blank It does not have to be a unique name Start Port End Port Enter the port n...

Page 103: ...ning of the range in the Start Port field enter the port number at the end of the range in the End Port field If you want to delete this rule enter zero in the Start Port and End Port fields Trigger S...

Page 104: ...BEL DESCRIPTION Enable SIP ALG Select this to make sure SIP VoIP works correctly with port forwarding and port triggering rules Enable FTP ALG Select this to make sure FTP file transfer works correctl...

Page 105: ...1 2 Introduction to SIP The Session Initiation Protocol SIP is an application layer control signaling protocol that handles the setting up altering and tearing down of voice and multimedia sessions o...

Page 106: ...hat the telephone is ringing 3 B sends an OK response after the call is answered 4 A then sends an ACK message to acknowledge that B has answered the call 5 Now A and B exchange voice media talk 6 Aft...

Page 107: ...gent client to initiate a call A and B can also both act as a SIP user agent to receive the call Figure 60 SIP User Agent 10 1 5 2 SIP Proxy Server A SIP proxy server receives requests from clients an...

Page 108: ...client device A to call someone who is using client device C 1 Client device A sends a call invitation for C to the SIP redirect server B 2 The SIP redirect server sends the invitation back to A with...

Page 109: ...f you know the NAT router s public IP address and SIP port number you can use the Use NAT feature to manually configure the ZyXEL Device to use a them in the SIP messages This eliminates the need for...

Page 110: ...se G 711 provides excellent sound quality but requires 64kbps of bandwidth G 723 is an Adaptive Differential Pulse Code Modulation ADPCM waveform codec Differential or Delta PCM is similar to PCM but...

Page 111: ...keys on a DTMF telephone corresponds to a different pair of frequencies Pulse dialing sends a series of clicks to the local phone office in order to dial numbers 1 10 1 10 MWI Message Waiting Indicat...

Page 112: ...3 You can continue to add listen to or delete tones or you can hang up the receiver when you are done 10 1 11 3 Deleting Custom Tones Do the following to delete a custom tone 1 Pick up the phone and p...

Page 113: ...s The following figure illustrates the DS field Figure 64 DiffServ Differentiated Service Field DSCP is backward compatible with the three precedence bits in the ToS octet so that non DiffServ complia...

Page 114: ...see in this screen If you change this field the screen automatically refreshes SIP Settings Active SIP Account Select this if you want the ZyXEL Device to use this account Clear it if you do not want...

Page 115: ...port number you entered in the SIP Server Port field SIP Service Domain Enter the SIP service domain name In the full SIP URI this is the part after the symbol You can use up to 127 printable ASCII Ex...

Page 116: ...ZyXEL MAX 200M1 Series User s Guide 116 Chapter 10 SIP Figure 66 VoIP SIP SIP Settings Advanced...

Page 117: ...request to start a SIP session If the request has a shorter time the ZyXEL Device rejects it RTP Port Range Start Port End Port Enter the listening port number s for RTP traffic if your VoIP service...

Page 118: ...r a SIP ALG Server Address Enter the public IP address or domain name of the NAT router Server Port Enter the port number that your SIP sessions use with the public IP address of the NAT router Outbou...

Page 119: ...Device should send fax messages as UDP or TCP IP packets through IP networks This provides better quality but it may have inter operability problems The peer devices must also use T 38 Call Forward Ca...

Page 120: ...iority for RTP voice transmissions The ZyXEL Device creates Type of Service priority tags with this priority to RTP traffic that it transmits Voice VLAN ID Select this if the ZyXEL Device has to be a...

Page 121: ...ansmitting silent packets when you are not speaking When using VAD the ZyXEL Device generates comfort noise when the other party is not speaking The comfort noise lets you know that the line is still...

Page 122: ...s This section describes how to use supplementary phone services with the Europe Type Call Service Mode Commands for supplementary services are listed in the table below After pressing the flash key i...

Page 123: ...first call and answer the second call Either press the flash key and press 1 or just hang up the phone and then answer the phone after it rings Put the first call on hold and answer the second call Pr...

Page 124: ...e but a caller is still on hold there will be a remind ring 11 1 3 3 2 USA Call Waiting This allows you to place a call on hold while you answer another incoming call on the same telephone directory n...

Page 125: ...o drop the connection 5 If you want to separate the activated three way conference into two individual connections one is on line the other is on hold press the flash key wait for the sub command tone...

Page 126: ...rst Incoming Call apply to SIP1 Select this if you want to receive phone calls for the SIP1 account on this phone port If you select more than one source for incoming calls there is no way to distingu...

Page 127: ...echo caused by the sound of your voice reverberating in the telephone receiver while you talk Dialing Interval Select Dialing Interval Select Enter the number of seconds the ZyXEL Device should wait...

Page 128: ...Device is in To access this screen click VoIP Phone Region Table 40 VoIP Phone Common LABEL DESCRIPTION Active Immediate Dial Select this if you want to use the pound key to tell the ZyXEL Device to m...

Page 129: ...for supplementary phone services call hold call waiting call transfer and three way conference calls that your VoIP service provider supports Europe Type use supplementary phone services in European m...

Page 130: ...ZyXEL MAX 200M1 Series User s Guide 130 Chapter 11 Phone...

Page 131: ...irewall itself 12 1 1 Stateful Inspection Firewall Stateful inspection firewalls restrict access by screening data packets against defined access rules They make access control decisions based on IP a...

Page 132: ...ntial security risk A determined hacker might be able to find creative ways to misuse the enabled services to access the firewall or the network 5 For local services that are enabled protect against m...

Page 133: ...forwarded to the LAN by Configuring NAT port forwarding rules Configuring One to One and Many One to One NAT mapping rules in the SMT NAT menus Configuring WAN or LAN WAN access for services in the R...

Page 134: ...ets the connection as the connection has not been acknowledged Figure 74 Triangle Route Problem 12 2 2 Solving the Triangle Route Problem If you have the ZyXEL Device allow triangle route sessions tra...

Page 135: ...es to the ZyXEL Device 4 The ZyXEL Device then sends it to the computer on the LAN in Subnet 1 Figure 75 IP Alias 12 3 Firewall Screens 12 3 1 General Firewall Screen Use this screen to configure the...

Page 136: ...hrough the ZyXEL Device See the appendices for more information about triangle route topology Max NAT Firewall Session Per User Select the maximum number of NAT rules and firewall rules the ZyXEL Devi...

Page 137: ...ervice that is not available in the pre defined Available Services list You must define it using the Type and Port Number fields See Appendix F on page 249 for some examples of services Blocked Servic...

Page 138: ...the week you want the service blocking to be effective Time of Day to Block Select what time each day you want service blocking to be effective Enter times in 24 hour format for example 3 00pm should...

Page 139: ...server In the ZyXEL Device you must set up a speed dial entry in the phone book in order to do this Select Non Proxy Use IP or URL in the Type column and enter the callee s IP address or domain name T...

Page 140: ...number regardless of other rules in the Forward to Number section Specify the phone number in the field on the right Busy Forward to Number Select this if you want the ZyXEL Device to forward incoming...

Page 141: ...the Incoming Call Number You may leave this field blank depending on the Condition Condition Select the situations in which you want to forward incoming calls from the Incoming Call Number or select a...

Page 142: ...one of your SIP accounts to call this phone number Select Non Proxy Use IP or URL if you want to use a different SIP server or if you want to make a peer to peer call In this case enter the IP address...

Page 143: ...ith the Type field in the Speed Dial section Modify Use this field to edit or erase the speed dial entry Click the Edit icon to copy the information for this speed dial entry into the Speed Dial secti...

Page 144: ...ZyXEL MAX 200M1 Series User s Guide 144 Chapter 13 Phone Book...

Page 145: ...ability to block certain web features or specific URL keywords The ZyXEL Device can block web features such as ActiveX controls Java applets cookies and disable web proxies The ZyXEL Device also allow...

Page 146: ...ctiveX controls are downloaded to your browser where they remain in case you visit the site again Java This is used to build downloadable Web components or Internet and intranet business applications...

Page 147: ...isappears after you click Apply Clear All Click this button to remove all of the keywords in the Keyword List Denied Access Message Enter the message that is displayed when the ZyXEL Device s content...

Page 148: ...ZyXEL MAX 200M1 Series User s Guide 148 Chapter 14 Content Filter...

Page 149: ...ough remote node Router 1 However the ZyXEL Device is unable to route a packet to network N3 because it doesn t know that there is a route through the same remote node Router 1 via gateway Router 2 Th...

Page 150: ...rder and it follows only the first one that applies Name This field displays the name that describes the static route Active This field shows whether this static route is active Yes or not No Destinat...

Page 151: ...resses that this static route affects If this static route affects only one IP address enter 255 255 255 255 Gateway IP Address Enter the IP address of the gateway to which the ZyXEL Device should sen...

Page 152: ...ZyXEL MAX 200M1 Series User s Guide 152 Chapter 15 Static Route...

Page 153: ...agement session of lower priority when another remote management session of higher priority starts The priorities for the different types of remote management sessions are as follows 1 Telnet 2 HTTP 1...

Page 154: ...aintenance System General screen 16 2 Remote Management Screens 16 2 1 WWW Screen Use this screen to control HTTP access to your ZyXEL Device To access this screen click Management Remote MGMT WWW Fig...

Page 155: ...en to its default value Table 50 Management Remote MGMT WWW LABEL DESCRIPTION Table 51 Management Remote MGMT Telnet LABEL DESCRIPTION Server Port Enter the port number this service can use to access...

Page 156: ...lustrates an SNMP management operation Note SNMP is only available if TCP IP is configured Table 52 Management Remote MGMT FTP LABEL DESCRIPTION Server Port Enter the port number this service can use...

Page 157: ...tion Base MIB is a collection of managed objects SNMP allows a manager and agents to communicate for the purpose of accessing these objects SNMP itself is a simple request response protocol based on t...

Page 158: ...15 A trap is sent after booting power on 1 warmStart defined in RFC 1215 A trap is sent after booting software reboot 4 authenticationFailure defined in RFC 1215 A trap is sent to the manager when rec...

Page 159: ...s public and allows all requests Trap Destination Enter the IP address of the station to send your SNMP traps to SNMP Port You may change the server port number for a service if needed however you mus...

Page 160: ...anagement Remote MGMT DNS LABEL DESCRIPTION Server Port This field is read only This field displays the port number this service uses to access the ZyXEL Device The computer must use the same port num...

Page 161: ...ond to requests for unauthorized services Select this to prevent outsiders from discovering your ZyXEL Device by sending requests to unsupported port numbers If an outside user attempts to probe an un...

Page 162: ...ZyXEL MAX 200M1 Series User s Guide 162 Chapter 16 Remote MGMT...

Page 163: ...on of a UPnP device will allow you to access the information and properties of that device 17 1 2 NAT Traversal UPnP NAT traversal automates the process of allowing an application to operate through N...

Page 164: ...dows Messenger 4 6 and 4 7 while Windows Messenger 5 0 and Xbox are still being tested The ZyXEL Device only sends UPnP multicasts to the LAN See later sections for examples of installing UPnP in Wind...

Page 165: ...nication 3 In the Communications window select the Universal Plug and Play check box in the Components selection box Figure 93 Add Remove Programs Windows Setup Communication Components 4 Click OK to...

Page 166: ...In the Network Connections window click Advanced in the main menu and select Optional Networking Components Figure 94 Network Connections 4 The Windows Optional Networking Components Wizard window di...

Page 167: ...to use the UPnP feature in Windows XP You must already have UPnP installed in Windows XP and UPnP activated on the ZyXEL Device Make sure the computer is connected to a LAN port of the ZyXEL Device T...

Page 168: ...EL MAX 200M1 Series User s Guide 168 Chapter 17 UPnP Figure 97 Network Connections 3 In the Internet Connection Properties window click Settings to see the port mappings there were automatically creat...

Page 169: ...ZyXEL MAX 200M1 Series User s Guide Chapter 17 UPnP 169 Figure 98 Internet Connection Properties 4 You may edit or delete the port mappings or click Add to manually add port mappings...

Page 170: ...ced Settings Figure 100 Internet Connection Properties Advanced Settings Add 5 When the UPnP enabled device is disconnected from your computer all port mappings will be deleted automatically 6 Select...

Page 171: ...Web Configurator Easy Access With UPnP you can access the web based configurator on the ZyXEL Device without finding out the IP address of the ZyXEL Device first This becomes helpful if you do not kno...

Page 172: ...apter 17 UPnP Figure 103 Network Connections 4 An icon with the description for each UPnP enabled device displays under Local Network 5 Right click on the icon for your ZyXEL Device and select Invoke...

Page 173: ...er s Guide Chapter 17 UPnP 173 Figure 104 Network Connections My Network Places 6 Right click on the icon for your ZyXEL Device and select Properties A properties window displays with basic informatio...

Page 174: ...ries User s Guide 174 Chapter 17 UPnP Figure 105 Network Connections My Network Places Properties Example 17 3 UPnP Screen Use this screen to set up UPnP in your ZyXEL Device To access this screen cli...

Page 175: ...P Select this to allow UPnP enabled applications to automatically configure the ZyXEL Device so that they can communicate through the ZyXEL Device For example using NAT traversal UPnP applications aut...

Page 176: ...ZyXEL MAX 200M1 Series User s Guide 176 Chapter 17 UPnP...

Page 177: ...em Errors consist of both logs and alerts 18 1 2 Syslog Logs There are two types of syslog event logs and traffic logs The device generates an event log when a system event occurs for example when a u...

Page 178: ...t The cat is the same as the category in the router s logs Traffic Log Facility 8 Severity Mon dd hr mm ss hostname src srcIP srcPort dst dstIP dstPort msg Traffic Log note Traffic Log devID mac addre...

Page 179: ...whose log entries you want to view To view all logs select All Logs The list of categories depends on what log categories are selected in the Log Settings page Email Log Now Click this to send the log...

Page 180: ...the following table Table 61 Maintenance Logs Log Settings LABEL DESCRIPTION E mail Log Settings Mail Server Enter the server name or the IP address of the mail server the ZyXEL Device should use to...

Page 181: ...the logs Time for Sending Log This field is only available when you select Daily or Weekly in the Log Schedule field Enter the time of day in 24 hour format for example 23 00 equals 11 00 pm to send t...

Page 182: ...HCP server assigns s The DHCP server assigned an IP address to a client Successful WEB login Someone has logged on to the device s web configurator interface WEB login failed Someone has failed to log...

Page 183: ...n t have a corresponding NAT table entry Router sent blocked web site message TCP The router sent a message to notify a user that the router blocked access to a web site that the user requested Exceed...

Page 184: ...l incomplete connections Maximum Incomplete Low Access block sent TCP RST The router sends a TCP RST packet and generates this log if you turn on the firewall TCP reset mechanism via CI command sys fi...

Page 185: ...d s The PPPoE or dial up call is connected board d line d channel d call d s C02 Call Terminated The PPPoE or dial up call was disconnected Table 69 PPP Logs LOG MESSAGE DESCRIPTION ppp LCP Starting...

Page 186: ...respond within the timeout period DNS resolving failed The ZyXEL Device cannot get the IP address of the external content filtering via DNS query Creating socket failed The ZyXEL Device cannot issue...

Page 187: ...rt scan attack Firewall sent TCP packet in response to DoS attack TCP The firewall sent TCP packet in response to a DoS attack ICMP Source Quench ICMP The firewall detected an ICMP Source Quench attac...

Page 188: ...le 4 A packet that needed fragmentation was dropped because it was set to Don t Fragment DF 5 Source route failed 4 Source Quench 0 A gateway may discard internet datagrams if it does not have the buf...

Page 189: ...SIP register server was not successful SIP UnRegistration Success by SIP SIP Phone Number The listed SIP account s registration was deleted from the SIP register server SIP UnRegistration Fail by SIP...

Page 190: ...A VoIP phone call made from a phone connected to the listed phone port has terminated Table 78 FSM Logs Callee Side LOG MESSAGE DESCRIPTION VoIP Call Start from SIP SIP Port Number A VoIP phone call c...

Page 191: ...Device bin The upload process uses HTTP Hypertext Transfer Protocol and may take up to two minutes After a successful upload the system will reboot Note Only use firmware for your ZyXEL Device s spec...

Page 192: ...lly restarts in this time This causes a temporary network disconnect In some operating systems you may see the following icon on your desktop Table 80 Maintenance Tools Firmware LABEL DESCRIPTION File...

Page 193: ...new browser to log in If the upload is not successful the following screen appears Figure 112 Firmware Upload Error Click Return to go back to the Firmware screen 19 2 3 Configuration Screen Use this...

Page 194: ...onfigured and functioning properly it is highly recommended that you back up your configuration file before making configuration changes The backup configuration file is useful if you need to return t...

Page 195: ...to change the IP address of your computer to be in the same subnet as that of the default management IP address 192 168 5 1 See your Quick Start Guide or the appendices for details on how to set up y...

Page 196: ...117 Maintenance Tools Restart This does not affect the ZyXEL Device s configuration When you click Restart the following screen appears Figure 118 Maintenance Tools Restart In Progress Wait one minut...

Page 197: ...for the Computer name field and enter it as the System Name In Windows XP click Start My Computer View system information and then click the Computer Name tab Note the entry in the Full computer name...

Page 198: ...with a dynamic IP from their ISP or DHCP server that would still like to have a domain name The Dynamic DNS service provider will give you a password or key Enabling the wildcard feature for your host...

Page 199: ...ting Screen 24 hour intervals after starting 20 2 System Screens 20 2 1 General System Screen Use this screen to change the ZyXEL Device s mode set up the ZyXEL Device s system name domain name idle t...

Page 200: ...from the ISP is used Use up to 38 alphanumeric characters Spaces are not allowed but dashes and periods are accepted Administrator Inactivity Timer Enter the number of minutes a management session can...

Page 201: ...rovider Host Name Enter the host name You can specify up to two host names separated by a comma User Name Enter your user name Password Enter the password assigned to you Enable Wildcard Option Select...

Page 202: ...r more NAT routers between the ZyXEL Device and the DDNS server Note The DDNS server may not be able to detect the proper IP address if there is an HTTP proxy server between the ZyXEL Device and the D...

Page 203: ...Server Select this if you want to use a time server to update the current date and time in the ZyXEL Device Time Protocol Select the time service protocol that your time server uses Check with your I...

Page 204: ...e hour to give more daytime light in the evening Start Date Enter which hour on which day of which week of which month daylight savings time starts End Date Enter which hour on the which day of which...

Page 205: ...in to an appropriate power source Make sure that the power source is turned on Remove the power jack then reinsert it If the error persists you may have a hardware problem In this case you should cont...

Page 206: ...you are unsure of the correct settings contact your service provider See Appendix C on page 223 for information on how to set up your IP address The Internet connection disconnects Check your WiMAX l...

Page 207: ...uring from the LAN Refer to for instructions on checking your LAN connection Your computer s and the ZyXEL Device s IP addresses must be on the same subnet for LAN access If you changed the ZyXEL Devi...

Page 208: ...an exception for your device s IP address 21 5 1 1 1 Disable pop up Blockers 1 In Internet Explorer select Tools Pop up Blocker and then select Turn Off Pop up Blocker Figure 122 Pop up Blocker You ca...

Page 209: ...y to save this setting 21 5 1 1 2 Enable pop up Blockers with Exceptions Alternatively if you only want to allow pop up windows from your device see the following steps 1 In Internet Explorer select T...

Page 210: ...g Figure 124 Internet Options 3 Type the IP address of your device the web page that you do not want to have blocked with the prefix http For example http 192 168 1 1 4 Click Add to move the IP addres...

Page 211: ...ay properly in Internet Explorer check that JavaScripts are allowed 1 In Internet Explorer click Tools Internet Options and then the Security tab Figure 126 Internet Options 2 Click the Custom Level b...

Page 212: ...pting 21 5 1 3 Java Permissions 1 From Internet Explorer click Tools Internet Options and then the Security tab 2 Click the Custom Level button 3 Scroll down to Microsoft VM 4 Under Java permissions m...

Page 213: ...phone lacks a dial tone Check the telephone connections and telephone wire Make sure you have the VoIP SIP Settings screen properly configured I can access the Internet but cannot make VoIP calls Make...

Page 214: ...lls and it uses SIP accounts 1 and 2 for incoming calls With this setting you always use SIP account 1 for your outgoing calls and you cannot distinguish which SIP account the calls are coming in thro...

Page 215: ...mperature 0 45 degrees Centigrade Storage Temperature 25 55 degrees Centigrade Operating Humidity 10 90 non condensing Storage Humidity 10 100 Power Supply 18 V DC Power consumption Worst case scenari...

Page 216: ...t is initiated from the LAN The ZyXEL Device s firewall supports TCP UDP inspection DoS detection and prevention real time alerts reports and logs Content Filtering The ZyXEL Device can block access t...

Page 217: ...rk administrator REN A Ringer Equivalence Number REN is used to determine the number of devices like telephones or fax machines that may be connected to the telephone line Your device has a REN of thr...

Page 218: ...ZyXEL MAX 200M1 Series User s Guide 218 Appendix A...

Page 219: ...n WiMAX supports EAP Extensible Authentication Protocol RFC 2486 which allows additional authentication methods to be deployed with no changes to the base station or the mobile or subscriber stations...

Page 220: ...server Types of RADIUS Messages The following types of RADIUS messages are exchanged between the base station and the RADIUS server for user authentication Access Request Sent by an base station requ...

Page 221: ...requests a transport encryption key TEK which the base station generates and encrypts using the authentication key Encrypted traffic The MS SS decrypts the TEK using the authentication key Both statio...

Page 222: ...erver side authentications to establish a secure connection with EAP TLS digital certifications are needed by both the server and the wireless clients for mutual authentication Client authentication i...

Page 223: ...are components you need to install and use TCP IP on your computer Windows 3 1 requires the purchase of a third party TCP IP application package TCP IP should already be installed on computers using W...

Page 224: ...works If you need the adapter 1 In the Network window click Add 2 Select Adapter and then click Add 3 Select the manufacturer and model of your network adapter and then click OK If you need TCP IP 1 I...

Page 225: ...P entry and click Properties 2 Click the IP Address tab If your IP address is dynamic select Obtain an IP address automatically If you have a static IP address select Specify an IP address and type yo...

Page 226: ...e the TCP IP Properties window 6 Click OK to close the Network window Insert the Windows CD if prompted 7 Restart your computer when prompted Verifying Settings 1 Click Start and then Run 2 In the Run...

Page 227: ...C 227 Figure 133 Windows XP Start Menu 2 In the Control Panel double click Network Connections Network and Dial up Connections in Windows 2000 NT Figure 134 Windows XP Control Panel 3 Right click Loc...

Page 228: ...rties 4 Select Internet Protocol TCP IP under the General tab in Win XP and then click Properties Figure 136 Windows XP Local Area Connection Properties 5 The Internet Protocol TCP IP Properties windo...

Page 229: ...IP addresses In the IP Settings tab in IP addresses click Add In TCP IP Address type an IP address in IP address and a subnet mask in Subnet mask and then click Add Repeat the above two steps for eac...

Page 230: ...in Windows XP Click Obtain DNS server address automatically if you do not know your DNS server IP address es If you know your DNS server IP address es click Use the following DNS server addresses and...

Page 231: ...twork Connections window Network and Dial up Connections in Windows 2000 NT 11Restart your computer if prompted Verifying Settings 1 Click Start All Programs Accessories and then Command Prompt 2 In t...

Page 232: ...k the TCP IP tab 3 For dynamically assigned settings select Using DHCP from the Configure list Figure 141 Macintosh OS X Network 4 For statically assigned settings do the following From the Configure...

Page 233: ...nding on your Linux distribution and release version Note Make sure you are logged in as the root administrator Using the K Desktop Environment KDE Follow the steps below to configure your computer IP...

Page 234: ...ave a static IP address click Statically set IP Addresses and fill in the Address Subnet mask and Default Gateway Address fields 3 Click OK to save the changes and close the Ethernet Device General sc...

Page 235: ...ork card on the computer locate the ifconfig eth0 configuration file where eth0 is the name of the Ethernet card Open the configuration file with any plain text editor If you have a dynamic IP address...

Page 236: ...check your TCP IP properties Figure 150 Red Hat 9 0 Checking TCP IP Properties DEVICE eth0 ONBOOT yes BOOTPROTO static IPADDR 192 168 1 10 NETMASK 255 255 255 0 USERCTL no PEERDNS yes TYPE Ethernet na...

Page 237: ...a street share a common street name the hosts on a network share a common network number Similarly as each house has its own house number each host on the network has its own unique identifying numbe...

Page 238: ...f the host ID The following example shows a subnet mask identifying the network number in bold text and host ID of an IP address 192 168 1 2 in decimal By convention subnet masks always consist of a c...

Page 239: ...ontinuous number of zeros for the remainder of the 32 bit mask you can simply specify the number of ones instead of writing the value of each octet This is usually specified by writing a followed by t...

Page 240: ...company network before subnetting Figure 152 Subnetting Example Before Subnetting You can borrow one of the host ID bits to divide the network 192 168 1 0 into two separate sub networks The subnet mas...

Page 241: ...Example Four Subnets The previous example illustrated using a 25 bit subnet mask to divide a 24 bit address into two subnets Similarly to divide a 24 bit address into four subnets you need to borrow t...

Page 242: ...SUBNET MASK NETWORK NUMBER LAST OCTET BIT VALUE IP Address 192 168 1 128 IP Address Binary 11000000 10101000 00000001 10000000 Subnet Mask Binary 11111111 11111111 11111111 11000000 Subnet Address 19...

Page 243: ...BNET MASK NO SUBNETS NO HOSTS PER SUBNET 1 255 255 255 128 25 2 126 2 255 255 255 192 26 4 62 3 255 255 255 224 27 8 30 4 255 255 255 240 28 16 14 5 255 255 255 248 29 32 6 6 255 255 255 252 30 64 2 7...

Page 244: ...You don t need to change the subnet mask computed by the ZyXEL Device unless you are instructed to do otherwise Private IP Addresses Every machine on the Internet must have a unique address If your ne...

Page 245: ...ZyXEL MAX 200M1 Series User s Guide Appendix D 245...

Page 246: ...ZyXEL MAX 200M1 Series User s Guide 246 Appendix D...

Page 247: ...ignaling sessions The SIP UA sends registration packets to the SIP server periodically and keeps the session alive in the ZyXEL Device If the SIP client does not have this mechanism and makes no call...

Page 248: ...ZyXEL MAX 200M1 Series User s Guide 248 Appendix E...

Page 249: ...is used Table 106 Examples of Services NAME PROTOCOL PORT S DESCRIPTION AH IPSEC_TUNNEL User Defined 51 The IPSEC AH Authentication Header tunneling protocol uses this service AIM TCP 5190 AOL s Inte...

Page 250: ...rk Basic Input Output System is used for communication between computers in a LAN NEW ICQ TCP 5190 An Internet chat program NEWS TCP 144 A protocol for news groups NFS UDP 2049 Network File System NFS...

Page 251: ...SQL NET TCP 1521 Structured Query Language is an interface to access data on many different types of database systems including mainframes midrange systems UNIX systems and network servers SSDP UDP 19...

Page 252: ...ZyXEL MAX 200M1 Series User s Guide 252 Appendix F...

Page 253: ...auto discovering UPnP enabled network devices 167 automatic log out 35 auto provisioning 216 B base station see BS BS 71 links 71 BYE request 106 C call hold 122 124 call service mode 122 124 call tr...

Page 254: ...l tone multi frequency see DTMF duplex 215 dynamic DNS 198 217 dynamic host configuration protocol 217 dynamic jitter buffer 217 E EAP 72 echo cancellation 121 217 encoding 219 encrypted traffic 221 e...

Page 255: ...IP PBX 105 ISP 41 ITSP 105 ITU T 121 J jitter buffer 217 K key 65 73 219 key request and reply 221 L language 27 link quality troubleshooting 206 listening port 118 log out 35 M MAC 221 MAN 71 managem...

Page 256: ...proxy server SIP 107 PSTN 111 public certificate 221 public key 65 73 219 Public Switched Telephone Network 111 pulse code modulation 110 pulse dialing 111 Q QoS 112 217 quality of service see QoS Qu...

Page 257: ...IP user agent 107 SNMP 156 manager 157 MIBs 157 sound quality 110 specifications 215 physical and environmental 215 radio 215 speed dial 139 SS 71 standards 215 stateful inspection 131 storage humidit...

Page 258: ...virtual local area network see VLAN VLAN 113 VLAN group 113 VLAN ID 113 VLAN ID tags 113 VLAN tags 113 voice activity detection 121 217 voice coding 110 voice mail 105 voice over IP see VoIP VoIP 27 1...

Reviews: