background image

 

 

 

 

 

P-2602HWNLI 

 

 

 

 

 

Support Notes 

Version 3.40 

March. 2006 

 

 

 

 

 

 

 

 

 

 

 

 

 

Summary of Contents for P-2602HWNLI

Page 1: ...P 2602HWNLI Support Notes Version 3 40 March 2006...

Page 2: ...ling 79 Using IP Multicast 84 Using Prestige traffic redirect 85 Using Universal Plug n Play UPnP 88 Wireless Application Notes 94 Infrastructure mode 94 Wireless MAC address filtering 99 WEP configur...

Page 3: ...ackup restore configurations by using FTP client program via LAN 157 Why can t I make Telnet to Prestige from WAN 157 What should I do if I forget the system password 158 What is SUA When should I use...

Page 4: ...n the data go 163 What is Multi NAT 164 When do I need Multi NAT 164 What IP Port mapping does Multi NAT support 165 What is the difference between SUA and Multi NAT 166 What is BOOTP DHCP 166 What is...

Page 5: ...t the voice only goes one way not both way 172 I can receive a call but the voice only goes one way not both way 172 If all the about have been tried but register still fail what should I do 173 I sus...

Page 6: ...encryption does Prestige VPN support 183 What types of authentication does Prestige VPN support 183 I am planning my Prestige to Prestige VPN configuration What do I need to know 183 Does Prestige sup...

Page 7: ...ere with Bluetooth devices 191 Can radio signals pass through walls 191 What are potential factors that may causes interference among WLAN products 192 What s the difference between a WLAN and a WWAN...

Page 8: ...Wireless Snifter 195 What is the difference between Open System and Shared Key of Authentication Type 195 What is 802 1x 196 What is the difference between No authentication required No access allowed...

Page 9: ...eeds to be checked before accessing the Internet Before you begin Setting up the Windows Setting up the Prestige router Troubleshooting Before you begin The Prestige is shipped with the following fact...

Page 10: ...from the Network Protocols and click OK 3 TCP IP Configuration Follow these steps to configure Windows TCP IP In the Control Panel Network window click the TCP IP entry to select it and click Properti...

Page 11: ...it Before configuring the router using Browser please be sure there is no Telnet or Console login 1 Retrieve Prestige Web Please enter the LAN IP address of the Prestige router in the URL location to...

Page 12: ...P 2602HWNLI Support Notes All contents copyright c 2006 ZyXEL Communications Corporation 12 The Web screen shown below takes PPPoE as the example...

Page 13: ...Corporation 13 Setup the Prestige as a DHCP Relay What is DHCP Relay DHCP stands for Dynamic Host Configuration Protocol In addition to the DHCP server feature the P2602 supports the DHCP relay funct...

Page 14: ...menu 3 2 and enter the IP address of the DHCP server in the Relay Server Address field Menu 3 2 TCP IP and DHCP Setup DHCP Relay TCP IP Setup Client IP Pool Starting Address N A IP Address 192 168 1 1...

Page 15: ...nt whose IP address potentially changes each time it is powered on In addition to the servers for specific services SUA supports a default server A service request that does not have a server explicit...

Page 16: ...ddress 1 Default Default 0 0 0 0 2 80 80 192 168 1 10 3 0 0 0 0 0 0 4 0 0 0 0 0 0 5 0 0 0 0 0 0 6 0 0 0 0 0 0 7 0 0 0 0 0 0 8 0 0 0 0 0 0 9 0 0 0 0 0 0 10 0 0 0 0 0 0 11 0 0 0 0 0 0 12 0 0 0 0 0 0 Pre...

Page 17: ...twork connection over dial up telephone lines All data sent over this connection can be encrypted and compressed and multiple network level protocols TCP IP NetBEUI and IPX can be run correctly Window...

Page 18: ...the appropriate private IP address of Windows NT server Example The following example shows how to dial to an ISP via the Prestige and then establish a tunnel to a private network There will be three...

Page 19: ...NAT Server Setup Rule Start Port No End Port No IP Address 1 Default Default 0 0 0 0 2 80 80 192 168 1 10 3 0 0 0 0 0 0 4 0 0 0 0 0 0 5 0 0 0 0 0 0 6 0 0 0 0 0 0 7 0 0 0 0 0 0 8 0 0 0 0 0 0 9 0 0 0 0...

Page 20: ...now the exact Internet IP address that the ISP assigns to Prestige router in SUA mode and enter this IP address in the VPN dial up dialog box You can check this Internet IP address from PNC Monitor or...

Page 21: ...Prestige thus preventing intruders from probing your network The SUA feature that the Prestige supports previously operates by mapping the private IP addresses to a global IP address It is only one s...

Page 22: ...ingle User Account feature that previous ZyNOS routers supported the SUA only option in today s routers 4 Many to Many Overload In Many to Many Overload mode the Prestige maps the multiple ILA to shar...

Page 23: ...ver The Prestige now has Full Feature NAT support to map global IP addresses to local IP addresses of clients or servers With multiple global IP addresses multiple severs of the same type e g FTP serv...

Page 24: ...My Login cso zyxel net My Password Idle Timeout sec 0 IP Address Assignment Dynamic IP Address N A Network Address Translation Full Feature Address Mapping Set 1 Press ENTER to Confirm or ESC to Canc...

Page 25: ...ng Sets and NAT Server Sets Use the Address Mapping Sets menus and submenus to create the mapping table used to assign global addresses to LAN clients Each remote node must specify which NAT Address M...

Page 26: ...first look at Option 255 Option 255 is equivalent to SUA in previous ZyXEL routers The fields in this menu cannot be changed Entering 255 brings up this screen Menu 15 1 1 Address Mapping Rules Set N...

Page 27: ...rting local IP address ILA If the rule is for all local IPs then the Start IP is 0 0 0 0 and the End IP is 255 255 255 255 255 255 255 255 Global Start IP This is the starting global IP address IGA If...

Page 28: ...new rule before the rule selected The rule after the selected rule will then be moved down by one rule Delete means to delete the selected rule and then all the rules after the selected one will be a...

Page 29: ...No Overload Server Start This is the starting local IP address ILA 0 0 0 0 Local IP End This is the ending local IP address ILA If the rule is for all local IPs then put the Start IP as 0 0 0 0 and t...

Page 30: ...or port 80 Web the server at IP address 192 168 1 36 and for port 21 FTP another at IP address 192 168 1 33 Please note that a server can support more than one service e g a server can provide both FT...

Page 31: ...to Confirm or ESC to Cancel The most often used port numbers are shown in the following table Please refer RFC 1700 for further information about port numbers Service Port Number FTP 21 Telnet 23 SMTP...

Page 32: ...Encapsulation PPPoE Multiplexing LLC based VPI 0 VCI 33 ATM QoS Type UBR Peak Cell Rate PCR 0 Sustain Cell Rate SCR 0 Maximum Burst Size MBS 0 My Login cso zyxel My Password Idle Timeout sec 0 IP Add...

Page 33: ...configured to handle this case 2 Internet Access with an Internal Server In this case we do exactly as above use the convenient pre configured SUA Only set and also go to Menu 15 2 NAT Server Setup U...

Page 34: ...ernal FTP servers and also an internal general server for the web and mail In this case we want to assign the 3 IGAs by the following way using 4 NAT rules 5 Rule 1 One to One type to map the FTP Serv...

Page 35: ...BR Peak Cell Rate PCR 0 Sustain Cell Rate SCR 0 Maximum Burst Size MBS 0 My Login cso zyxel My Password Idle Timeout sec 0 IP Address Assignment Static IP Address IGA 3 Network Address Translation Ful...

Page 36: ...Cancel Rule 2 Setup Selecting One to One type to map the FTP Server 2 with ILA2 192 168 1 11 to IGA2 Menu 15 1 1 2 Rule 2 Type One to One Local IP Start 192 168 1 11 End N A Global IP Start Enter IGA...

Page 37: ...8 1 20 to IGA3 Menu 15 1 1 4 Rule 4 Type Server Local IP Start N A End N A Global IP Start Enter IGA3 End N A Press ENTER to Confirm or ESC to Cancel When we have configured all four rules Menu 15 1 1...

Page 38: ...from Menu 15 2 NAT Server Setup not Set 1 Set 1 is used for SUA Only case Menu 15 2 NAT Server Setup Rule Start Port No End Port No IP Address 1 Default Default 0 0 0 0 2 80 80 192 168 1 20 3 25 25 1...

Page 39: ...mapping types thus each user login to the server using a unique global IP address The following figure illustrates this One rule configured for using Many to Many No Overload mapping type is shown bel...

Page 40: ...lobal IP Start Enter IGA1 End N A Press ENTER to Confirm or ESC to Cancel Menu 15 1 1 2 Rule 2 Type One to One Local IP Start 192 168 1 11 End N A Global IP Start Enter IGA2 End N A Press ENTER to Con...

Page 41: ...iple type of NAT mapping rules SUA One to One Many to One Many to Many overload Many One to One Server The following table summarizes these types NAT Type IP Mapping One to One ILA1 IGA1 Many to One S...

Page 42: ...The Prestige allows you to configure up to twelve filter sets with six rules in each set for a total of 72 filter rules in the system You can apply up to four filter sets to a particular port to bloc...

Page 43: ...Filter Types and SUA Conceptually there are two categories of filter rules device and protocol The Generic filter rules belong to the device category they act on the raw data from to LAN and WAN The...

Page 44: ...and output filter sets If SUA is enabled SUA converts the source IP address from 192 168 1 33 to 203 205 115 6 and port number from 1023 to 4034 WAN device output and call filter sets The sequence of...

Page 45: ...ric Filter Rule Filter 1 1 Filter Type Generic Filter Rule Active Yes Offset 0 Length 0 Mask N A Value N A More No Log None Action Matched Check Next Rule Action Not Matched Check Next Rule Menu 21 1...

Page 46: ...us Menu 11 5 and Menu 13 1 have been added as well as some changes made to the Menu 3 1 Menu 11 1 and Menu 13 The new fields are shown below Menu 3 1 Menu 3 1 General Ethernet Setup Input Filter Sets...

Page 47: ...event you from entering a protocol filter set configured in Menu 21 to the device filters field in Menu 3 1 11 5 or entering a device filter set to the protocol filters field Even though SMT will prev...

Page 48: ...se you have to enter an IP Address for the workstation you want to block See the procedure for configuring this filter below o Create a filter set in Menu 21 e g set 1 o Create three filter rules in M...

Page 49: ...TCP IP Filter Rule Filter 1 1 Filter Type TCP IP Filter Rule Active Yes IP Protocol 6 IP Source Route No Destination IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port 80 Port Comp Equal Source IP Addr 0 0 0 0 IP M...

Page 50: ...ask 0 0 0 0 Port Port Comp None TCP Estab No More No Log None Action Matched Drop Action Not Matched Check Next Rule Press ENTER to Confirm or ESC to Cancel 4 Rule 3 for c DNS packet UDP 17 Port numbe...

Page 51: ...lter Rules M m n 1 Y IP Pr 6 SA 0 0 0 0 DA 0 0 0 0 DP 80 N D N 2 Y IP Pr 6 SA 0 0 0 0 DA 0 0 0 0 DP 53 N D N 3 Y IP Pr 17 SA 0 0 0 0 DA 0 0 0 0 DP 53 N D F 6 Apply the filter set to the Output Protoco...

Page 52: ...CP IP Filter Rule Filter 1 1 Filter Type TCP IP Filter Rule Active Yes IP Protocol 0 IP Source Route No Destination IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port Port Comp None Source IP Addr 192 168 1 5 IP Ma...

Page 53: ...tige you can identify the uninteresting MAC address from the Prestige s LAN packet trace Please have a look at the following example to know the trace of the LAN packets ras sys trcp channel enet0 bot...

Page 54: ...conds hops IP protocol type ICMP 0x01 Checksum 0xE3EA IP address 202 132 155 93 Source IP address 202 132 155 99 Destination IP address No option Internet Control Message Protocol Type 8 Echo Request...

Page 55: ...8 69 2 We are now ready to configure the Generic Filter Rule as below Menu 21 1 1 Generic Filter Rule Filter 1 1 Filter Type Generic Filter Rule Active Yes Offset 6 Length 6 Mask ffffffffffff Value 00...

Page 56: ...t matches the Value In this case we will drop it Action Not Matched Enter the action you want if the masked packet does not match the Value In this case we will forward it If you want to configure mor...

Page 57: ...ied to menu 3 1 and menu 4 1 for activating the NetBIOS services The details of the filter settings are described as follows Configuration The packets need to be blocked are as follows Please configur...

Page 58: ...s Set Comments 1 NetBIOS_WAN 7 _______________ 2 NetBIOS_LAN 8 _______________ 3 _______________ 9 _______________ 4 _______________ 10 _______________ 5 _______________ 11 _______________ 6 _________...

Page 59: ...to Confirm or ESC to Cancel Rule 2 Destination port number 137 with protocol number 17 UDP Menu 21 1 2 TCP IP Filter Rule Filter 1 2 Filter Type TCP IP Filter Rule Active Yes IP Protocol 17 IP Source...

Page 60: ...No Destination IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port 138 Port Comp Equal Source IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port 0 Port Comp None TCP Estab No More No Log None Action Matched Drop Action Not Match...

Page 61: ...le Press ENTER to Confirm or ESC to Cancel Rule 5 Destination port number 139 with protocol number 6 TCP Menu 21 1 5 TCP IP Filter Rule Filter 1 5 Filter Type TCP IP Filter Rule Active Yes IP Protocol...

Page 62: ...Source Route No Destination IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port 139 Port Comp Equal Source IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port 0 Port Comp None TCP Estab N A More No Log None Action Matched Drop Ac...

Page 63: ...t Protocol Filter in the remote node setup Configure the second filter set NetBIOS_LAN by selecting the Filter Set number 2 Rule 1 Source port number 137 Destination port number 53 with protocol numbe...

Page 64: ...ination IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port 53 Port Comp Equal Source IP Addr 0 0 0 0 IP Mask 0 0 0 0 Port 137 Port Comp Equal TCP Estab N A More No Log None Action Matched Drop Action Not Matched Fo...

Page 65: ...nal server It is inconvenient for the users if this IP is dynamic With DDNS supported by the Prestige you apply a DNS name e g www zyxel com tw for your server e g Web server from a DDNS server The ou...

Page 66: ...DNS option to Yes and press ENTER for configuring the settings of the DDNS in menu 1 1 Menu 1 General Setup System Name P2602WNLI 67A Location Contact Person s Name Domain Name First System DNS Serve...

Page 67: ...me you subscribe from the above DDNS server For example zyxel com tw EMAIL Enter the email address you give to the DDNS server User Enter the user name that Password Enter the password that the DDNS s...

Page 68: ...iables are defined using the OSI Abstract Syntax Notation One ASN 1 ASN 1 specifies how a variable is encoded in a transmitted data frame it is very powerful because the encoded data is self defining...

Page 69: ...e operations to determine which variables a managed device supports and to sequentially gather information from variable tables such as IP routing table in managed devices 9 Traps The managed devices...

Page 70: ...e NMS of some events The SNMPv1 messages contains two part The first part contains a version and a community name The second part contains the actual SNMP protocol data unit PDU specifying the operati...

Page 71: ...rmstarts the trap will be sent after booting linkDown defined in RFC 1215 If any link of IDSL or WAN is down the trap will be sent with the port number The port number is its interface index under the...

Page 72: ...nd traps with the message of the fatal code will be sent 4 Configure the Prestige for SNMP The SNMP related settings in Prestige are configured in menu 22 SNMP Configuration The following steps descri...

Page 73: ...d from the NMS The default is public Trusted Host Enter the IP address of the NMS The Prestige will only respond to SNMP messages coming from this IP address If 0 0 0 0 is entered the Prestige will re...

Page 74: ...tc syslog conf by adding the following line at the end of the etc syslog conf file local1 var log zyxel log Where var log zyxel log is the full path of the log file 3 Restart syslogd CDR log call mess...

Page 75: ...aracters to the server Example Jul 19 11 28 39 192 168 102 2 ZyXEL Communications Corp Packet Trigger Protocol 1 Data 4500003c100100001f010004c0a86614ca849a7b08004a5c020001006162636465666768696a6b6c6d...

Page 76: ...PAP IPCP IPXCP Example Jul 19 11 43 25 192 168 1 1 ZyXEL Communications Corp ppp LCP Starting Jul 19 11 43 29 192 168 1 1 ZyXEL Communications Corp ppp IPCP Starting Jul 19 11 43 34 192 168 1 1 ZyXEL...

Page 77: ...k can be configured in menu 3 2 as usual The second and third networks that we call IP Alias 1 and IP Alias 2 can be configured in menu 3 2 1 IP Alias Setup There are three internal virtual LAN interf...

Page 78: ...u 3 2 TCP IP and DHCP Setup DHCP Setup DHCP Server Client IP Pool Starting Address 192 168 1 33 Size of Client IP Pool 32 Primary DNS Server 0 0 0 0 Secondary DNS Server 0 0 0 0 Remote DHCP Server N A...

Page 79: ...ection None Version RIP 1 Incoming protocol filters Outgoing protocol filters IP Alias 2 Yes IP Address 192 168 3 1 IP Subnet Mask 255 255 255 0 RIP Direction None Version RIP 1 Incoming protocol filt...

Page 80: ...n Forced Down Enable Dial On Demand or Disable Dial On Demand on specified date and time SMT Menu for Call Scheduling 1 Edit the Schedule sets in menu 26 Copyright c 1994 2006 ZyXEL Communications Cor...

Page 81: ...Enter Schedule Set Number to Configure 1 Edit Name ZyXEL Press ENTER to Confirm or ESC to Cancel 3 The Menu 26 1 Schedule Set Setup is as follows Menu 26 1 Schedule Set Setup Active Yes Start Date yy...

Page 82: ...d Enable Dial On Demand The remote node accepts Dial on demand during this period Disable Dial On Demand The remote node denies any demand dial during the period For the existing connected nodes it wi...

Page 83: ...e from external server in boot time Time service is implemented by the Daytime protocol RFC 867 Time protocol RFC 868 and NTP protocol RFC 1305 You have to assign an IP address of a time server and th...

Page 84: ...rt multicast groups The latest version is version 2 see RFC2236 IP hosts use IGMP to report their multicast group membership to any immediate neighbor multicast routers so the multicast routers can de...

Page 85: ...1 3 Menu 11 3 Remote Node Network Layer Options IP Options Bridge Options IP Address Assignment Dynamic Ethernet Addr Timeout min N A Rem IP Addr 0 0 0 0 Rem Subnet Mask 0 0 0 0 My WAN Addr N A NAT SU...

Page 86: ...n Prestige will try to forward outgoing traffic to backup gateway that users specify in traffic redirect configuration menu How to deploy backup gateway You can deploy the backup gateway on LAN of Pre...

Page 87: ...e is no response Fail Tolerance Type the number of times 2 recommended that your Prestige may ping the IP addresses configured in the Check WAN IP Address fields without getting a response before swit...

Page 88: ...Prestige s Internet connection terminates Back Click Back to return to the previous screen Apply Click Apply to save the changes Cancel Click Cancel to begin configuring this screen afresh Using Unive...

Page 89: ...4 each devices should have DHCP client when the device gets connected to the network it will discover DHCP server on network to get an IP address If not then Auto IP mechanism should be supported so t...

Page 90: ...re in UPnP in this application note In the diagram suppose PC1 and PC2 both sign in MSN server and they would like to establish a video conference PC1 is behind PPPoE dial up router which supports UPn...

Page 91: ...ication to change configuration in this device For instance if you enable this item then user s MSN application can assign dynamic port mapping to the router So that network administrator don t need t...

Page 92: ...pport Notes All contents copyright c 2006 ZyXEL Communications Corporation 92 3 Start a Video conversation with one online user 4 On the opposite side your partner selects Accept to accept your conver...

Page 93: ...P 2602HWNLI Support Notes All contents copyright c 2006 ZyXEL Communications Corporation 93 5 Finally your video conversation is achieved...

Page 94: ...ucture mode What is Infrastructure mode Infrastructure mode sometimes referred to as Access Point mode is an operating mode of an 802 11b Wi Fi client unit In infrastructure mode the client unit can a...

Page 95: ...Prestige wireless VoIP IAD please follow the steps below 1 From the SMT main menu enter 3 to display Menu 3 LAN Setup 2 Enter 5 to display Menu 3 5 Wireless LAN Setup Menu 3 5 Wireless LAN Setup ESSID...

Page 96: ...ireless Access Point to Infrastructure mode using Web configurator To configure Infrastructure mode of your Prestige wireless VoIP IAD please follow the steps below 1 From the web configurator main me...

Page 97: ...card please follow the following steps 1 Double click on the utility icon in your windows task bar the utility will pop up on your windows screen 2 Select configuration tab 3 Select Infrastructure fr...

Page 98: ...P 2602HWNLI Support Notes All contents copyright c 2006 ZyXEL Communications Corporation 98 5 Double click on the AP you want to associated with...

Page 99: ...ontrol layer in that only stations with registered MAC addresses can connect This approach requires that the list of MAC addresses be configured 2 ZyXEL MAC Filter Implementation ZyXEL s MAC Filter Im...

Page 100: ...00 00 00 4 00 00 00 00 00 00 16 00 00 00 00 00 00 28 00 00 00 00 00 00 5 00 00 00 00 00 00 17 00 00 00 00 00 00 29 00 00 00 00 00 00 6 00 00 00 00 00 00 18 00 00 00 00 00 00 30 00 00 00 00 00 00 7 00...

Page 101: ...login AP by giving the LAN IP address of AP in URL field Default LAN IP is 192 168 1 1 default password to login web configurator is 1234 2 Click Network and click Wireless LAN tab on the left 3 Click...

Page 102: ...integrity check is used to ensure that packages are not modified during the transition The standard does not discuss how the shared key is established In practice most installations use a single key t...

Page 103: ...WEP keys simultaneously You need to specify one of the 4 keys as default Key for data encryption To set up the Access Point you will need to set the one of the following parameters o 64 bit WEP key se...

Page 104: ...sed to encrypt wireless data transmission For example 3 5 Wireless LAN Setup ESSID Wireless Hide ESSID No Channel ID CH07 2442MHz RTS Threshold 2432 Frag Threshold 2432 WEP 64 bit WEP Default Key 3 Ke...

Page 105: ...xample if access point use Key 3 to encrypt data then station will use Key 3 to decrypt data So the Key 3 of station has to equal to the Key 3 of access point Though access point use Key 3 as default...

Page 106: ...ngs Enter exactly 5 13 or 29 characters to match the security strength 40 64bit 128 bit 256 nit respectively Setting up the Station 1 Double click on the utility icon in your windows task bar or right...

Page 107: ...doesn t exist in your task bar click Start Programs IEEE802 11b WLAN Card IEEE802 11b WLAN Card 2 Select the Encryption tab Select encryption type correspond with access point Set up 4 Keys which cor...

Page 108: ...P 2602HWNLI Support Notes All contents copyright c 2006 ZyXEL Communications Corporation 108...

Page 109: ...456789ABCD Configuring 802 1x IEEE 802 1x Introduction IEEE 802 1x port based authentication is desired to prevent unauthorized devices clients from gaining access to the network As LANs extend to ho...

Page 110: ...controls the physical access to the network based on the authentication status of the client The authenticator acts as an intermediary proxy between the client and the authentication server i e RADIU...

Page 111: ...trol The port state determines whether or not the supplicant Wireless Client is granted access to the network behind Wireless AP There are two authentication port state on the AP authorized state and...

Page 112: ...the identity of the client and begins relaying authentication messages between supplicant and the authentication server Each supplicant attempting to access the network is uniquely identified by the a...

Page 113: ...an EAP request identity frame to the 802 1x client to request its identity typically the authenticator sends an initial identity request frame followed by one or more requests for authentication infor...

Page 114: ...EL Communications Corporation 114 The EAPOL packet contains the following fields protocol version packet type packet body length and packet body Most of the fields are obvious The packet type can have...

Page 115: ...sion EAPOL Key This is used for TLS authentication method The Wireless AP uses this packet to send the calculated WEP key to the supplicant after TLS negotiation has completed between the supplicant a...

Page 116: ...Timeout in second N A Key Management Protocol N A Dynamic WEP Key Exchange N A PSK N A WPA Mixed Mode N A Data Privacy for Broadcast Multicast packets N A WPA Broadcast Multicast Key Update Timer N A...

Page 117: ...rs to login to the Wireless AP simultaneously When you use internal authentication server ZyXEL wireless AP is acted as Authenticator and Authentication Server By storing wireless 802 1x client profil...

Page 118: ...Type a number and press Enter to edit the wireless 802 1x client profile Menu 14 1 Edit Dial in User User Name ZyXEL Active Yes Password Press ENTER to Confirm or ESC to Cancel Key settings Option Des...

Page 119: ...decapsulating the Extensible Authentication Protocol EAP frames and interacting with the authentication server When the authenticator receives EAPOL frames and relays them to the authentication server...

Page 120: ...The specific exchange of EAP frames depends on the authentication method being used The figure below shows a message exchange initiated by the client using the MD5 Challenge authentication method with...

Page 121: ...ication is 1812 You need not change this value unless your network administrator instructs you to do so Shared Secret Specify a password up to 31 characters as the key to be shared between external RA...

Page 122: ...degree of attenuation This will cause the RF coverage pattern be irregular and hard to predict Site survey can help us overcome these problem and even provide us a map of RF coverage of the facility...

Page 123: ...m with all information you gathered in the preparation phase Now you are ready to make the survey 2 Install an access point at the preliminary location 3 User a notebook with wireless client installed...

Page 124: ...access point installation spot if wireless service is required from corner of the room 6 Repeat step 1 5 and now you should be able to mark an RF coverage area as illustrated in above picture 7 You ma...

Page 125: ...more information please refer to roaming at PSTN Lifeline Application Notes Usage of PSTN Lifeline By using the PSTN lifeline function you can make and receive regular PSTN phone calls in coexistence...

Page 126: ...ou how to configure lifeline under P2602WNLI 67A WEB GUI Lifeline configuration To configure lifeline in P2602WNLI click on VoIP PSTN Line to display the following screen You can specify a prefix numb...

Page 127: ...re your local emergency services such as Police Dept Fire Dept and Emergency Medical services phone number in this field Thus in any cases these unit can be reach in case of emergency by dialing their...

Page 128: ...2WNLI includes a DSL cable and a RJ 11 cable Connect the DSL cable to the DSL port and connect RJ 11 to Lifeline port 2 Connect the RJ11 to the splitter phone jack or a telephone wall jack 3 Connect t...

Page 129: ...4 Connect the DSL cable to the other output jacket on the Y connector 5 Connect the Y connector input port with a phone cable to the wall Jack or line from ISP ISDN Lifeline Application Notes Usage o...

Page 130: ...ou how to configure lifeline under P2602WNLI 67A WEB GUI Lifeline configuration To configure lifeline in P2602WNLI click on VoIP ISDN Line to display the following screen You can specify a prefix numb...

Page 131: ...e your local emergency services such as Police Dept Fire Dept and Emergency Medical services phone number in this field Thus in any cases these unit can be reach in case of emergency by dialing their...

Page 132: ...WNLI includes a DSL cable and a RJ 45 cable Connect the DSL cable to the DSL port and connect RJ 45 to Lifeline port 2 Connect the RJ45 to the splitter phone jack or a telephone wall jack 3 Connect th...

Page 133: ...egular phone shop 3 Connect the RJ 45 to one of the output jack on the Y connector 4 Connect the DSL cable to the other output jacket on the Y connector 5 Connect the Y connector input port with a pho...

Page 134: ...ional circuit switched telephone networks The Prestige can hold up to two SIP account simultaneously please follow the below instruction to configure the SIP account properly Note You should have a vo...

Page 135: ...figure the 2nd SIP account please select SIP2 by using the SIP account selector than follow step 1 to 8 to complete the 2nd account setup Each field s detail description on this page is listed below L...

Page 136: ...domain name that comes after the symbol in a full SIP URI Enter the SIP service domain name in this field You can use up to 127 ASCII Extended set characters User Name This is the user name for regis...

Page 137: ...user s networking topology 2 Setup device s WAN connection 3 Configuring SIP VoIP related settings in device A and B There are two ways to make IP to IP call 1 Make you can call by speed dial like 01...

Page 138: ...P 2602HWNLI Support Notes All contents copyright c 2006 ZyXEL Communications Corporation 138 Setup Configuring SIP VoIP related settings in device A...

Page 139: ...6 ZyXEL Communications Corporation 139 1 Setup WEB GUI VoIP enter device A s number in the SIP number column 2 Fill in device B s IP into SIP server address Register server address as example 3 Setup...

Page 140: ...P 2602HWNLI Support Notes All contents copyright c 2006 ZyXEL Communications Corporation 140 Setup Configuring SIP VoIP related settings in device B...

Page 141: ...3 Setup speed dial put device A s information into the column After completing the setting you can dial 01 from the phone under device A then the phone under device B will ring Phone Port Settings P 2...

Page 142: ...ll apply to Here user can define which type s of incoming call will apply to this analog phone for example if user tick SIP1 then once somebody calls the SIP one number this analog phone will ring P 2...

Page 143: ...ige uses for the speech signal that it sends to the peer device 1 is the quietest and 1 is the loudest Listening Volume Use this field to set the loudness that the Prestige uses for the speech signal...

Page 144: ...rom ISDN phone Advanced voice settings configuration Click VoIP in the navigation panel and then SIP to open the SIP Settings Select a SIP account and then click Advanced Settings to display the follo...

Page 145: ...ration Duration This field sets how long an entry remains registered with the SIP register server After this time period expires the SIP register server deletes the Prestige s entry from the database...

Page 146: ...de sets how the Prestige handles the tones that your telephone makes when you push its buttons It is recommended that you use the same mode that your VoIP service provider uses Select RFC 2833 to send...

Page 147: ...ferent call forwarding table for each SIP account or use the same call forwarding table for both Back Click Back to return to the previous screen without saving configuration changes Apply Click Apply...

Page 148: ...e phone book Each field s detail description of the page is listed below Label Description Speed Dial Select a speed dial key combination from the drop down list box SIP Number Enter the SIP number of...

Page 149: ...accounts This field displays the SIP server s or the party s IP address or domain name if calls to this party do not use one of your SIP accounts Delete Click this button to remove an entry from the...

Page 150: ...teway must also be set up to use VLAN tags Some switches also give priority to voice traffic based on its VLAN tag Type the VLAN ID VID from 1 to 4095 for the Prestige to add to voice Ethernet frames...

Page 151: ...s to the number that you configure Busy Forward to Number Enable this feature to have the Prestige forward incoming calls to the number that you configure when your SIP account has a call connected No...

Page 152: ...hone s connected to the phone port s is busy Busy Forward to Number Enable this feature to have the Prestige forward incoming calls to the number that you configure when the phone s connected to the p...

Page 153: ...number specified in the Incoming Call Number field to the number in the Forward to Number field when your SIP account has a call connected Select No Answer to have the Prestige forward any calls from...

Page 154: ...Dial Use these fields to specify phone numbers to which the Prestige will always send calls through the regular phone service without the need of dialing a prefix number These numbers must be for pho...

Page 155: ...Network Operating System It is the platform on all Prestige routers that delivers network services and applications It is designed in a modular fashion so it is easy for developers to add new features...

Page 156: ...eft menu c Press F W Upload tab d Press browse button and point to the directory where the firmware you want to upload is kept and press Upload button e It will prompt you the firmware is upload succe...

Page 157: ...l ask you where to store the back up romfile e Press Save file and browse to where you want the file be save f Press Save button How do I backup restore configurations by using FTP client program via...

Page 158: ...ket to the Internet as if it is originated from Prestige using the IP address assigned by ISP When reply packets from the external Internet are received by Prestige the original IP source address and...

Page 159: ...evice filter group TCP IP and IPX filters belong to the protocol filter group Why can t I configure device filters or protocol filters In ZyNOS you can not mix different filter groups in the same filt...

Page 160: ...t to Point Protocol over Ethernet that is an IETF draft standard specifying how a computer interacts with a broadband modem i e xDSL cable wireless etc to achieve access to the high speed data network...

Page 161: ...interface does the Prestige support The Prestige supports 10 100M Ethernet to connect to the LAN computer or hub switch and 10 100M ADSL interface to the ISP What can we do with Prestige Browse the Wo...

Page 162: ...n assigned the proper access right Is it possible to access a server running behind SUA from the outside Internet If possible how Yes it is possible because Prestige delivers the packet to the local s...

Page 163: ...work then how big a pipe there is at the head end to the rest of the Internet Different models of PCs and Macs are able to handle IP traffic at varying speeds Very few can handle it at 30 Mbps Etherne...

Page 164: ...server and a telnet server on your local network and make them accessible to the outside world If you do not define any servers NAT offers the additional benefit of firewall protection In such case a...

Page 165: ...A to one IGA This is equivalent to SUA i e PAT port address translation ZyXEL s Single User Account feature that previous ZyNOS routers supported the SUA only option in today s routers 3 Many to Many...

Page 166: ...15 1 is a convenient pre configured read only Many to One mapping set sufficient for most purposes and helpful to people already familiar with SUA in previous ZyNOS versions What is BOOTP DHCP BOOTP s...

Page 167: ...pply the DNS from and update the WAN IP to What is DDNS wildcard Some DDNS servers support the wildcard feature which allows the hostname yourhost dyndns org to be aliased to the same IP address as yo...

Page 168: ...LI P2602HWNLI is a SIP based VoIP analog telephone adapter It allows you to send voice signals over the Internet or VoIP of IP via SIP protocol which is an internationally recognized standard for VoIP...

Page 169: ...asically VoIP is a technique to send voice information in digital form in discrete packets over digital network rather than by using traditional circuit switch PSTN To do so we will need an analog to...

Page 170: ...tive of view Where as H 323 emerged around 1996 and as an International Telecommunication Union standard it was designed from a telecommunications perspective Both standards have the same objective to...

Page 171: ...er What codec does Prestige support Prestige supports the following commonly used codec G 729 voice codec G 711u law voice codec G 711a law voice codec Note G 711 u law or G 711 a law is country speci...

Page 172: ...pter such as Prestige ATA series I can register but can not establish a call If you can register to server but can not make a call very likely there is NAT router or firewall before it which is blocki...

Page 173: ...c tips in the user s guide Please contact your ZyXEL local vendor to send the device in for RMA service Firewall FAQ What is a network firewall A firewall is a system or group of systems that enforces...

Page 174: ...ession data to assure the integrity of the connection and to adapt to dynamic protocols The flexible nature of Stateful Inspection firewalls generally provides the best speed and transparency however...

Page 175: ...Death and Teardrop 2 Those that exploits weaknesses in the TCP IP specification such as SYN Flood and LAND Attacks 3 Brute force attacks that flood a network with useless data such as Smurf attack 4 I...

Page 176: ...network the router will broadcast the ICMP echo request packet to all hosts on the network If there are numerous hosts this will create a large amount of ICMP echo request packet the resulting ICMP t...

Page 177: ...acks The basic scheme is as follows For the input data filter Deny packets from the outside that claim to be from the inside Allow everything that is not spoofing us Filter rule setup Filter type TCP...

Page 178: ...blocking period of time is supported currently on ZyXEL appliance Can I override block or allow certain URLs by wording Yes you can use key word blocking to achieve this How many URL keywords does Pr...

Page 179: ...to the remote office 2 Reducing number of access lines Many companies pay monthly charges for two types access lines 1 high speed links for their Internet access and 2 frame relay ISDN Primary Rate I...

Page 180: ...te sites to be encrypted and verified You can create encrypted tunnels VPNs or just do encryption between computers Since you have so many options IPSec is truly the most extensible and complete netwo...

Page 181: ...n IKE and manual key VPN The only difference between IKE and manual key is how the encryption keys and SPIs are determined For IKE VPN the key and SPIs are negotiated from one VPN gateway to the other...

Page 182: ...t s not neccessary to follow the format exactly By default Prestige takes IP as phase 1 ID type for itself and it s remote peer But if it s remote peer is using DNS or E mail you have to ajust the set...

Page 183: ...upport Prestige supports 56 bit DES and 168 bit 3DES and AES What types of authentication does Prestige VPN support VPN vendors support a number of different authentication methods Prestige VPN suppor...

Page 184: ...in the range 172 16 0 0 172 31 255 255 these address ranges are reserved by internet standard for private LAN numberings behind NAT devices It is usually a static IP so that we can pre configure it i...

Page 185: ...ng on it currently Does Prestige VPN support NetBIOS broadcast The current 3 50 firmware release does not support it But it is in our wish list Is the host behind NAT allowed to use IPSec NAT Conditio...

Page 186: ...se 1 ID in Prestige Phase 1 ID can be configured in VPN setup menu as following Note that you can make such configuration in either web configurator or SMT menu If I have NAT router between two VPN ga...

Page 187: ...on whenever phase 2 SA lifetime is due IKE negotiation procedure will be invoked automatically even without traffic to make the connection stay But to reduce the consumption of system resource if VPN...

Page 188: ...IPSec passthrough you have to disable the VPN function on Prestige To disable it you can either deactivate each VPN rule or issue a CI command ipsec switch off from SMT menu 24 8 You can get into SMT...

Page 189: ...peer to peer networks suitable for a small number of users to full infrastructure networks of thousands of users that enable roaming over a broad area What are the disadvantages of Wireless LANs The s...

Page 190: ...second Mbps However depending on signal quality and how many other people are using the wireless ethernet through a particular Access Point usable speed will be much less on the order of 4 or 5 Mbps...

Page 191: ...pread spectrum radio communication applications use the 2 4 GHz band This includes WLAN systems not necessarily of the type IEEE 802 11b cordless phones wireless medical telemetry equipment and Blueto...

Page 192: ...s the difference between a WLAN and a WWAN WLANs are generally privately owned wireless systems that are deployed in a corporation warehouse hospital or educational campus setting Data rates are high...

Page 193: ...which hops through a predefined sequence of several frequencies at a specific rate This avoids problems with fixed channel narrowband noise and simple jamming Both transmitter and receiver must have...

Page 194: ...acy WEP is a security mechanism defined within the 802 11 standard and designed to make the security of the wireless medium equal to that of a cable wire WEP data encryption was designed to prevent ac...

Page 195: ...g off the broadcast of SSID in the beacon message a common practice does not prevent getting the SSID since the SSID is sent in the clear in the probe message when a client associates to an AP a snift...

Page 196: ...its and receives normal traffic without 802 1X based authentication of the client No access allowed causes the port to remain in the unauthorized state ignoring all attempts by the client to authentic...

Page 197: ...Because WPA PSK only requires a single password to be entered on wireless AP gateway and wireless client As long as the passwords match a client will be granted access to the WLAN Trouble Shooting For...

Page 198: ...nel enet0 bothway 1 3 Enable the trace log by entering sys trcp sw on sys trcl sw on 1 4 Display the brief trace online by entering sys trcd brief or 1 5 Display the detailed trace online by entering...

Page 199: ...12089 790 sec Frame Type TCP 192 168 1 2 1116 192 31 7 130 80 Ethernet Header Destination MAC Addr 00A0C5921311 Source MAC Addr 0080C84CEA63 Network Type 0x0800 TCP IP IP Header IP Version 4 Header L...

Page 200: ...00 70 02 P p 0030 20 00 BE C3 00 00 02 04 05 B4 01 01 04 02 0001 LAN Frame ENET0 XMIT Size 58 58 Time 12090 020 sec Frame Type TCP 192 31 7 130 80 192 168 1 2 1116 Ethernet Header Destination MAC Addr...

Page 201: ...63 00 A0 C5 92 13 11 08 00 45 00 L c E 0010 00 2C 57 F3 40 00 ED 06 AC 8C C0 1F 07 82 C0 A8 W 0020 01 02 00 50 04 5C 4A D1 B5 7F 00 BD 15 A8 60 12 P J 0030 FA F0 F8 77 00 00 02 04 05 B4 w 0002 LAN Fr...

Page 202: ...ngth 6 Captured 6 0000 20 20 20 20 20 20 RAW DATA 0000 00 A0 C5 92 13 11 00 80 C8 4C EA 63 08 00 45 00 L c E 0010 00 28 35 0B 40 00 80 06 3C 79 C0 A8 01 02 C0 1F 5 y 0020 07 82 04 5C 00 50 00 BD 15 A8...

Page 203: ...TCP 202 132 155 97 10261 192 31 7 130 80 5 12374 940 ENET1 T 0438 TCP 202 132 155 97 10261 192 31 7 130 80 6 12375 320 ENET1 R 0064 TCP 192 31 7 130 80 202 132 155 97 10261 7 12375 360 ENET1 R 0090 U...

Page 204: ...7 98 8F 3F A9 09 E4 0F 26 14 9C 58 3E 95 3E E7 X 0020 FC 2A 4C 2F FB BE 2F FE EF D0 L RAW DATA 0000 00 A0 C5 92 13 12 00 A0 C5 01 23 45 08 00 45 00 E E 0010 04 8B B1 39 40 00 EE 06 A9 AB C0 1F 07 82 C...

Page 205: ...Source Port 0x281E 10270 Destination Port 0x0050 80 Sequence Number 0x00C18F63 12685155 Ack Number 0xD3E95DE9 3555286505 Header Length 20 Flags 0x10 A Window Size 0x1DD5 7637 Checksum 0x7A12 31250 Urg...

Page 206: ...hecksum 0x533C 21308 Source IP 0xCA849B61 202 132 155 97 Destination IP 0xC01F0782 192 31 7 130 TCP Header Source Port 0x281E 10270 Destination Port 0x0050 80 Sequence Number 0x00C18F63 12685155 Ack N...

Page 207: ...f 1 6 Display the trace briefly by entering sys trcp brief 1 7 Display specific packets by using sys trcp parse from_index to_index Exmaple Prestige sys trcp channel enet1 none Prestige sys trcp chann...

Page 208: ...n MAC Addr 0080C84CEA63 Source MAC Addr 00A0C5921311 Network Type 0x0800 TCP IP IP Header IP Version 4 Header Length 20 Type of Service 0x00 0 Total Length 0x002C 44 Idetification 0x7F02 32514 Flags 0...

Page 209: ...ntering sys trcp channel enet1 bothway 1 3 Enable the trace log by entering sys trcp sw on sys trcl sw on 1 4 Wait for packet passing through Prestige over WAN 1 5 Disable the trace log by entering sy...

Page 210: ...202 132 155 97 10278 Ethernet Header Destination MAC Addr 00A0C5921312 Source MAC Addr 00A0C5591284 Network Type 0x0800 TCP IP IP Header IP Version 4 Header Length 20 Type of Service 0x00 0 Total Leng...

Page 211: ...50 28 26 4D 71 3D 8A 00 C8 C0 15 50 18 a P Mq P 0030 22 38 AB 57 00 00 48 54 54 50 2F 31 2E 31 20 33 8 W HTTP 1 1 3 0040 30 34 20 4E 6F 74 20 4D 6F 64 69 66 69 65 64 0D 04 Not Modified 0050 0A 44 61...

Page 212: ...0000 47 45 54 20 2F 70 69 63 74 75 72 65 73 2F 6D 61 GET pictures ma 0010 67 61 7A 69 6E 65 5F 6C 6F 67 6F 2F 62 65 73 74 gazine_logo best 0020 6F 66 74 69 6D 65 73 2E 67 69 oftimes gi RAW DATA 0000 0...

Page 213: ...dial 1 dial remote node 1 5 After all if the Prestige crashes and you can do nothing please send the above log back to us 6 If the Prestige crashes and you are able to enter commands please type atds...

Page 214: ...ice name telstra service name bpa service name iprimus service name pacificinternet service name integrationisp service name bpa dev service name bpa sif service name telstrarna service name gpmsystem...

Page 215: ...40 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ed 2b b f j n e5bdc050 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ed 2b b f j n e5bdc060 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ed 2b b f j n e5bdc070 00...

Page 216: ...or WAN end of Prestige It is also very helpful for diagnostics if you have compatibility problems with your ISP or if you want to know the details of a packet for configuring a filter rule The format...

Page 217: ...80 1 11883 100 ENET0 R 0062 TCP 192 168 1 2 1108 192 31 7 130 80 2 11883 330 ENET0 T 0058 TCP 192 31 7 130 80 192 168 1 2 1108 3 11883 340 ENET0 R 0060 TCP 192 168 1 2 1108 192 31 7 130 80 4 11883 340...

Page 218: ...F0782 192 31 7 130 TCP Header Source Port 0x045C 1116 Destination Port 0x0050 80 Sequence Number 0x00BD15A7 12391847 Ack Number 0x00000000 0 Header Length 28 Flags 0x02 S Window Size 0x2004 8192 Check...

Page 219: ...ce 0x00 0 Total Length 0x002C 44 Idetification 0x57F3 22515 Flags 0x02 Fragment Offset 0x00 Time to Live 0xED 237 Protocol 0x06 TCP Header Checksum 0xAC8C 44172 Source IP 0xC01F0782 192 31 7 130 Desti...

Page 220: ...2 31 7 130 80 Ethernet Header Destination MAC Addr 00A0C5921311 Source MAC Addr 0080C84CEA63 Network Type 0x0800 TCP IP IP Header IP Version 4 Header Length 20 Type of Service 0x00 0 Total Length 0x00...

Page 221: ...able to capture the WAN packet by entering sys trcp channel mpoa00 bothway 1 3 Enable the trace log by entering sys trcp sw on sys trcl sw on 1 4 Display the brief trace online by entering sys trcd br...

Page 222: ...ource IP 0xC01F0782 192 31 7 130 Destination IP 0xCA849B61 202 132 155 97 TCP Header Source Port 0x0050 80 Destination Port 0x281E 10270 Sequence Number 0xD3E95985 3555285381 Ack Number 0x00C18F63 126...

Page 223: ...Enable the trace log by entering sys trcp sw on sys trcl sw on 1 4 Wait for packet passing through the Prestige over LAN 1 5 Disable the trace log by entering sys trcp sw off sys trcl sw off 1 6 Displ...

Page 224: ...n 224 CLI Command List The latest CI command list is available in release notes of every ZyXEL firmware release Please go to ZyXEL public WEB site http www zyxel com support download php to download f...

Reviews: