background image

                                       

P-660R-Tx v3 Series Support Notes

 

                                                                                     

                                                                                               

44 

All contents copyright © 2008 ZyXEL Communications Corporation. 

 

Please note that a server can support more than one service, e.g., a server 
can provide both FTP and Mail service, while another provides only Web 
service.   

 

The following procedures show how to configure a server behind NAT.   

Step 1: Login Web Configurator, 

Advanced Setup -> NAT -> Virtual Server 

Step 2: Select the service name from the pull-down menu, and fill in the server 
Address on „

Local IP Address‟ 

and then save it. 

 

Step 3: You could click in to modify the Service name, Server IP Address, 
Start/End Port. 
 
The most often used port numbers are shown in the following table. Please 
refer RFC 1700 for further information about port numbers.   
    
 
 
 
 

P-660R-Tx 
v3 

Summary of Contents for P-660R-TX V3

Page 1: ...P 660R Tx v3 Series Support Notes 1 All contents copyright 2008 ZyXEL Communications Corporation P 660R Tx v3 Support Notes Version3 40 Aug 2008 ...

Page 2: ...n 7 6 What is SUA When should I use SUA 7 7 What is the difference between SUA and Full Feature NAT 8 8 Is it possible to access a server running behind SUA from the outside Internet How can I do it 8 9 When do I need select Multiple IP in NAT Full Feature NAT 8 10 What IP Port mapping does Multi NAT support 9 11 How many network users can the SUA NAT support 10 12 How can I protect against IP spo...

Page 3: ... difference between them 13 9 How do I know I am using PPPoE 13 10 Why does my provider use PPPoE 13 11 When do I need to choose dynamic IP 13 12 What is DDNS 15 13 When do I need DDNS service 15 14 What is DDNS wildcard Does the P 660R Tx v3 support DDNS wildcard 15 15 Can the P 660R Tx v3 s SUA Simple IP handle IPSec packets sent by the IPSec gateway 16 16 How do I setup my P 660R Tx v3 for rout...

Page 4: ...han the LLC based multiplexing 22 5 How do I know the details of my ADSL line statistics 23 6 What are the signaling pins of the ADSL connector 23 APPLICATION NOTES 24 GENERAL APPLICATION NOTES 24 1 Internet Access Using P 660R Tx v3 under Bridge mode 24 2 Internet Access Using P 660R Tx v3 under Routing mode 26 3 Make use of Bridge Interface in Routing mode 28 4 Setup the P 660R Tx v3 as a DHCP R...

Page 5: ...right 2008 ZyXEL Communications Corporation 10 Using IP Alias 53 11 Using IP Multicast 55 12 How to configure packet filter on P 660R Tx v3 57 SUPPORT TOOL 62 1 LAN WAN Packet Trace 62 Trace packet by telnet 63 COMMAND SYNTAX AND GENERAL USER INTERFACE 66 ...

Page 6: ...ploading the firmware Please do not power off the router right after the FTP uploading is finished the router will upload the firmware to its flash at this moment 1 Update on web configuration page Advanced Setup Maintenance Firmware You can check your current firmware version and upgrade the firmware of the Router in this page Make sure the firmware you want to use is on the local hard drive of t...

Page 7: ...ill be reset to 192 168 1 1 the password will be reset to 1234 5 How to use the Reset button a Turn your P 660R Tx v3 on Make sure the POWER led is on not blinking b Press the RESET button for ten seconds and then release it If the POWER LED begins to blink the default configuration has been restored and the P 660R Tx v3 restarts 6 What is SUA When should I use SUA SUA Single User Account is a uni...

Page 8: ...No Overload and Server You can make special application when you select Multiple For example With multiple global IP addresses multiple severs using the same port e g FTP servers using port 21 20 are allowed on the LAN for outside access The P 660R Tx v3 supports NAT sets on a remote node basis They are reusable but only one set is allowed for each remote node The P 660R Tx v3 supports 8 sets sinc...

Page 9: ...T supports five types of IP port mapping One to One Many to One Many to Many Overload Many to Many No Overload and Server The details of the mapping between ILA and IGA are described as below Here we define the local IP addresses as the Internal Local Addresses ILA and the global IP addresses as the Inside Global Address IGA One to One In One to One mode the P 660R Tx v3 maps one ILA to one IGA Ma...

Page 10: ...umber of the users but the number of the NAT sessions The P 660R Tx v3 supports 1024 sessions that you can use the ip nat session command in CLI to see You can also use ip nat hashTable wanif0 to view the current active NAT sessions 12 How can I protect against IP spoofing attacks The P 660R Tx v3 s filter sets provide a means to protect against IP spoofing attacks The basic scheme is according to...

Page 11: ... Device Info WAN to check this IP address 4 What is Traffic Shaping Traffic Shaping allocates the bandwidth to WAN dynamically and aims at boosting the efficiency of the bandwidth If there are several VCs in the P 660R Tx v3 but only one VC activated at one time the P 660R Tx v3 allocates all the Bandwidth to the VC and the VC gets full bandwidth If another VCs are activated later the bandwidth is...

Page 12: ...ing the traffic among its virtual channels If you do not need traffic shaping please set SCR 0 MBS 0 and PCR as the maximum value according to the line rate for example 2 3 Mbps line rate will result PCR as 5424 cell sec 7 What do the ATM QoS Types CBR UBR VBR rtVBR nrtVBR mean Constant bit rate CBR An ATM bandwidth allocation service that requires the user to determine a fixed bandwidth requireme...

Page 13: ...n to the provider s server If you need to configure a user name and password on your computer to connect to the ISP you are probably using PPPoE If you are simply connected to the Internet when you turn on your computer you probably are not You can also check your ISP or the information sheet given by the ISP Please choose PPPoE as the encapsulation type in the P 660R Tx v3 if the ISP uses PPPoE 1...

Page 14: ...by PPPOE server So we needn t two PVCs to do multicast NAT Choose to enable or disable NAT function Default Route Choose yes to set the current PVC as a default gateway to internet from your device Note that there must be only one default gateway If you have configured more than one PVC as default gateway the last one would be efficient TCP MTU Option Set TCP MTU value 0 is considered as default v...

Page 15: ...date its IP to DNS entry Once the IP to DNS table in the DDNS server is updated the DNS name for your web server i e www zyxel com tw is still usable 13 When do I need DDNS service When you want your internal server to be accessed by using DNS name rather than using the dynamic IP address we can use the DDNS service The DDNS server allows to alias a dynamic IP address to a static hostname Whenever...

Page 16: ...wed to be changed 16 How do I setup my P 660R Tx v3 for routing IPSec packets over SUA For outgoing IPSec tunnels no extra setting is required For forwarding the inbound IPSec ESP tunnel A Default server set is required You could configure it in Web Configurator Advanced Setup Advanced Setup NAT DMZ Note First we should set Number of IPs as Single for SUA use It is because SUA makes your LAN appea...

Page 17: ...Internet and remote node connections we can route the Web packets to the Internet using one policy and route the FTP packets to the remote LAN using another policy See the figure below Use IPPR to distribute traffic among multiple paths Benefits Source Based Routing Network administrators can use policy based routing to direct traffic from different users through different connections Quality of S...

Page 18: ...tering facility of ZyNOS in style and in implementation The policies are divided into sets where related policies are grouped together A use defines the policies before applying them to an interface or a remote node in the same fashion as the filters There are 12 policy sets with 6 policies in each set 19 What is CWMP P660R Tx V3 supports TR 069 Amendment 1 CPE WAN Management Protocol Release 2 0 ...

Page 19: ... to the ZyXEL Device after a successful login Path This is the part for verification from ACS to ZyXEL Device It can be considered as CPE s URL When ACS initialize a session it will connect with CPE basing on this part Port The default port for access to the ZyXEL Device from the management server is the HTTP port port 80 If you change it make sure it does not conflict with another port on your ne...

Page 20: ...nagement server This user name and password on the management server and the ZyXEL Device must be the same The second group is used to authenticate the management server when making a connection 2 The interval is the duration in seconds for which the ZyXEL Device MUST attempt to connect with the management server to send information and check for configuration updates 21 How to configure ACL You c...

Page 21: ...end SNMP commands select SNMP If you want to allow a user to find the ZyXEL Device on the network for troubleshooting purposes for example select Ping You can allow access for all services select ALL You cannot select a combination of services Interface Select the port through which you can access the device Select Both for access via either port If you configure 0 0 0 0 0 0 0 0 Secure IP Address ...

Page 22: ...able networks are not capable of offering a return channel consequently such networks will need significant upgrading before they can offer high bandwidth services 2 What is the micro filter or splitter used for Generally the voice band uses the lower frequency ranging from 0 to 4KHz while ADSL data transmission uses the higher frequency The micro filter acts as a low pass filter for your telephon...

Page 23: ...dsl perfdata CI wan adsl status CI wan adsl linedata far CI wan adsl linedata near You can also see the detailed information in Web Configurator Status Status Device Info ADSL You may also need some ADSL traffic status Status Statistics Traffic Statistics Interface ADSL 6 What are the signaling pins of the ADSL connector The signaling pins on the P 660R Tx v3 s ADSL connector are pin 3 and pin 4 T...

Page 24: ...omputer to access the Internet Set up your workstation 1 Ethernet connection To connect your computer to the P 660R Tx v3 s LAN port the computer must have an Ethernet adapter card installed For connecting a single computer to the P 660R Tx v3 we use an Ethernet cable 2 TCP IP configuration In most cases the IP address of the computer is assigned by the ISP dynamically so you have to configure the...

Page 25: ... under bridge mode The following procedure shows you how to configure your P 660R Tx v3 as bridge mode We will use Web Configurator to guide you through the related menu 1 Configure P 660R Tx v3 as bridge mode and configure Internet setup parameters in Web Configurator Advanced Setup Interface Setup Internet Encapsulation ...

Page 26: ...Tx v3 in Web Configurator Advanced Setup Interface Setup LAN DHCP We use 192 168 1 1 as the LAN IP for P 660R Tx v3 in this case Step 1 Disable DHCP Server and save it Step 2 Assign an IP to the LAN Interface of P 660R Tx v3 e g 192 168 1 1 2 Internet Access Using P 660R Tx v3 under Routing mode For most Internet users having multiple computers want to share an Internet account for Internet access...

Page 27: ...also provide the DNS to the clients via DHCP if it is available For this setup in Windows we check the option Obtain an IP address automatically in its TCP IP setup Please see the example shown below Set up your P 660R Tx v3 under routing mode The following procedure shows you how to configure your P 660R Tx v3 as Routing mode for routing traffic We will use Web Configurator to guide you through t...

Page 28: ...ttings in Web Configurator Advanced Setup Interface Setup LAN DHCP 3 Make use of Bridge Interface in Routing mode Using Bridge Interface in routing mode allows you to connect to internet with both Routing and Bridging A route channel for your device and a bridge channel for your pc but they use the same PVC so we needn t two PVCs to do multicast you also need not to set a new VLAN on the DSLAM One...

Page 29: ... PPPoA PPPoE while your computer can also get a public IP through PPPoE 4 Setup the P 660R Tx v3 as a DHCP Relay What is DHCP Relay DHCP stands for Dynamic Host Configuration Protocol In addition to the DHCP server feature the P 660R Tx v3 supports the DHCP relay function When it is configured as DHCP server it assigns the IP addresses to the LAN clients When it is configured as DHCP relay it is r...

Page 30: ...tup the P 660R Tx v3 as a DHCP Relay We could set the P 660R Tx v3 as a DHCP Relay by the following command in CLI Ip dhcp enif0 mode relay Ip dhcp enif0 relay server Server IP Address You can also set it in web configuration page Interface Setup LAN DHCP Click to choose Relay input the Relay Agent IP and save the configuration ...

Page 31: ...to connect to the local user behind the P 660R Tx v3 In such case a SUA server must be configured to forward the incoming packets to the true destination behind SUA After the required server are configured in Web Configurator Advanced Setup Advanced Setup NAT Virtual Server the internal server or client applications can be accessed by using the P 660R Tx v3 s WAN IP Address SUA Supporting Table Th...

Page 32: ...ming Connection FTP None 21 client IP SSH None 22 client IP TELNET None 23 client IP and active Telnet service from WAN SMTP None 25 client IP HTTP Server None 80 client IP POP3 None 110 client IP HTTPs None 443 client IP T 120 None 1503 client IP H 232 None 1720 client IP PPTP None 1723 client IP pcAnywhere None 5631 client IP VNC None 5900 client IP CUSeeMe None 7648 client IP ...

Page 33: ...e White Pine Cu SeeMe uses dedicate ports port 7648 port 24032 to transmit and receive data therefore only one local Cu SeeMe is allowed within the same LAN Configurations For example if the workstation operating Cu SeeMe has an IP of 192 168 1 33 then the default SUA server must be set to 192 168 1 33 The peer Cu SeeMe user can reach this workstation by using P 660R Tx v3 s WAN IP address which c...

Page 34: ...Internal Server behind SUA Introduction If you wish you can make internal servers e g Web ftp or mail server accessible for outside users even though SUA makes your LAN appear as a single machine to the outside world A service is identified by the port number Also since you need to specify the IP address of a server behind the P 660R Tx v3 ...

Page 35: ...eb Configurator Advanced Setup Advance Setup NAT DMZ The outside users can access the local server using the P 660R Tx v3 s WAN IP address which can be obtained from Web Configurator Status Device Info For example Configuring an internal Web server for outside access suppose the Server IP Address is 192 168 1 33 Enable DMZ and fill in the DMZ Host IP Address press button Save Note that there are s...

Page 36: ...at allows PPP packets to be encapsulated within Internet Protocol IP packets and forwarded over any IP network including the Internet itself In order to run the Windows 9x PPTP client you must be able to establish an IP connection with a tunnel server such as the Windows NT Server 4 0 Remote Access Server Windows Dial Up Networking uses the Internet standard Point to Point PPP to provide a secure ...

Page 37: ...appear elsewhere in the system Since PPTP encapsulates its data stream in the PPP protocol the VPN requires a second dial up adapter This second dial up adapter for VPN is added during the installation phase of the Upgrade in addition to the first dial up adapter that provides PPP support for the analog or ISDN modem The PPTP is supported in Windows NT and Windows 98 already For Windows 95 it need...

Page 38: ...lect the network protocols from RAS such as IPX TCP IP NetBEUI Set the Internet gateway to P 660R Tx v3 2 PPTP client setup Win9x Add one VPN connection from Dial Up Networking by entering the correct username password and the IP address of the P 660R Tx v3 s Internet IP address for logging to NT RAS server Set the Internet gateway to the router that is connecting to ISP 3 P 660R Tx v3 setup Befor...

Page 39: ...onnection Therefore the output below shows the default gateway of the Win9x client after the dial up connection has been established Before making a VPN connection from the Win9x client to the NT server you need to know the exact Internet IP address that the ISP assigns to P 660R Tx v3 router in SUA mode and enter this IP address in the VPN dial up dialog box You can check this Internet IP address...

Page 40: ... for reaching the PPTP server After the VPN link is established you can start the network protocol application such as IP IPX and NetBEUI 6 Using Full Feature NAT When P 660R Tx v3 is in Routing mode you can select NAT Option as Multiple IPs equal to Full Feature in Advanced Setup NAT Number of IPs ...

Page 41: ... P 660R Tx v3 has 8 remote nodes and so allows you to configure 8 NAT Address Mapping Sets You must specify which NAT Address Mapping Set 1 8 to use in the remote node when you select Multiple IPs You can edit 8 rules for each Address Mapping Set The NAT Server Set is a list of LAN side servers mapped to external ports We can configure it in Web Configurator Advanced Setup Advanced Setup NAT IP Ad...

Page 42: ...Corporation This menu is for Address Mapping Set 1 you can edit 8 Address Mapping Rules for Set 1 You can edit or delete a rule by clicking the two buttons below the rule table Click to select the rule number you want to set in the pull down menu and then the rule type and Start End IPs ...

Page 43: ... 0 0 0 as the Global Start IP 0 0 0 0 Public End IP This is the ending global IP address IGA This field is N A for One to One Many to One and Server types 200 1 1 64 Note For all Local and Public End IP address must begin after the IP Start address i e you can not have an End IP address beginning before the Start IP address NAT Server Sets The NAT Server Set is a list of LAN side servers mapped to...

Page 44: ...ocedures show how to configure a server behind NAT Step 1 Login Web Configurator Advanced Setup NAT Virtual Server Step 2 Select the service name from the pull down menu and fill in the server Address on Local IP Address and then save it Step 3 You could click in to modify the Service name Server IP Address Start End Port The most often used port numbers are shown in the following table Please ref...

Page 45: ... Access with an Internal Server Using Multiple Global IP addresses for clients and servers Support Non NAT Friendly Applications 1 Internet Access Only In our Internet Access example we only need one rule where all our ILAs map to one IGA assigned by the ISP You can just use the default Single NAT or you could select Multiple NAT and select an Address Mapping Set with a Many to One Rule See the fo...

Page 46: ...yXEL Communications Corporation In this case we do exactly as the figure use the convenient pre configured SUA Only set and also go to Web Configurator Advanced Setup Advanced Setup NAT Virtual Server to specify the Internet Server behind the NAT as below P 660R Tx v3 ...

Page 47: ...any to One type to map the other clients to IGA3 200 0 0 3 Rule 4 Server type to map a web server and mail server with ILA3 192 168 1 20 to IGA3 Type Server allows us to specify multiple servers of different types to other machines behind NAT on the LAN Step 1 In this case we need to map ILA to more than one IGAs therefore we must choose the Multiple IPs option from the NAT field in currently acti...

Page 48: ...configure all other incoming traffic to go to our web server and mail server from Web Configurator 4 Support Non NAT Friendly Applications Some servers providing Internet applications such as some mIRC servers do not allow users to login using the same IP address In this case it is better to use Many to Many No Overload or One to One NAT mapping types thus each user login to the server using a uni...

Page 49: ...P 660R Tx v3 When the ISP assigns the P 660R Tx v3 a new IP the P 660R Tx v3 must inform the DDNS server the change of this IP so that the server can update its IP to DNS entry Once the IP to DNS table in the DDNS server is updated the DNS name for your web server i e www zyxel com tw is still usable The DDNS server the P 660R Tx v3 supports currently is WWW DYNDNS ORG where you apply the DNS from...

Page 50: ...ncludes SNMP support in some P 660R Tx v3 routers It is implemented based on the SNMPv1 so it will be able to communicate with SNMPv1 NMSs Further users can also add ZyXEL s private MIB in the NMS to monitor and control additional system variables The ZyXEL s private MIB tree is shown in figure 3 For SNMPv1 operation ZyXEL permits one community string so that the router can belong to only one comm...

Page 51: ...t requirement with wrong community this trap is sent to the manager 6 whyReboot defined in ZYXEL MIB When the system is going to restart warmstart the trap will be sent with the reason of restart before rebooting 1 For intentional reboot In some cases download new files CI command sys reboot reboot is done intentionally And traps with the message System reboot by user will be sent 2 For fatal erro...

Page 52: ...SNMP Key Settings Get Community Select to set the password for the incoming Get and Get Next requests from the management station Set Community Select to set the password for incoming Set requests from the management station 9 Using system log Our ADSL Router keeps a running log of events and activities occurring on the Router If the device is rebooted the logs are automatically cleared You can ch...

Page 53: ...gle physical Ethernet interface The first network can be configured in Web Configurator Advanced Setup Interface Setup LAN DHCP The second and third networks can be configured in telnet CLI There are three internal virtual LAN interfaces for the P 660R Tx v3 to route the packets from to the three networks correctly They are enif0 for the major network enif0 0 for the IP alias 1 and enif0 1 for the...

Page 54: ... filter rule to accept or deny LAN packets from to the IP alias 1 2 go through the P 660R Tx v3 by command in CLI lan index index number Usage index number 1 main LAN 2 IP Alias 1 3 IP Alias 2 lan filter incoming outgoing tcpip generic set Usage set the corresponding filter set number you ve configured lan save ...

Page 55: ...ients can be any of the three networks 2 The second and third networks can be configured in CLI with the commands mentioned above 11 Using IP Multicast What is IP Multicast Traditionally IP packets are transmitted in two ways unicast or broadcast Multicast is a third way to deliver IP packets to a group of hosts Host groups are identified by class D IP addresses i e those with 1110 as their higher...

Page 56: ...lticast routers can decide if a multicast packet needs to be forwarded At start up the P 660R Tx v3 queries all directly connected networks to gather group membership After that the P 660R Tx v3 updates the information by periodic queries The P 660R Tx v3 implementation of IGMP is also compatible with version 1 The multicast setting can be turned on or off on Ethernet and remote nodes IP Multicast...

Page 57: ...ion 1 IGMP v2 for IGMP version 2 IGMP v3 for IGMP version 3 12 How to configure packet filter on P 660R Tx v3 The P 660R Tx v3 allows you to configure up to three types IP MAC filter Application filter URL filter You can set in the web configuration page Access Management Filter For each type there are different filter rules for you to define ...

Page 58: ...P 660R Tx v3 Series Support Notes 58 All contents copyright 2008 ZyXEL Communications Corporation Filter by IP MAC ...

Page 59: ...ule Type You can choose to filter by IP or MAC If you choose filter by IP you will need to set source and destination IP as well as port number of those packets you want to filter address according to your need if choose MAC as filter condition you may need to set their MAC Addresses from to where the packets come go Protocol You can choose one of the protocols TCP UDP or ICMP those to be filtered...

Page 60: ... can set 16 rules here in all Here are some recommendations for you when use filter feature 1 By factory default ZyXEL has preconfigured many filter sets for your reference you can check them in web configuration page as mentioned above This could satisfy mostly requirement You could select any of them to apply to the WAN node or LAN Interface on demand 2 If you are very advanced user you could ed...

Page 61: ...Disable application filter sys filter set app msn oscar real ymsg allow deny Allow or deny msn oscar real ymsg sys filter set url enable Enable URL filter sys filter set url disable Disable URL filter sys filter set add index URL Set a URL filter rule Index is from 0 15 sys filter set url del index Delete a URL filter rule Index is from 0 15 sys filter set save Save the latest settings of filter ...

Page 62: ... details of the packet flow on LAN or WAN end of P 660R Tx v3 It is also very helpful for diagnostics if you have compatibility problems with your ISP or if you want to know the details of a packet for configuring a filter rule The format of the display is as following Packet index timer second channel receive transmit length protocol sourceIP port destIP port There are two ways to dump the trace ...

Page 63: ...ght 2008 ZyXEL Communications Corporation Trace packet by telnet Step 1 Initiate a hyper terminal connection from your PC suppose you connected to the LAN port of P 660R Tx v3 Step 2 Click the properties to configure parameters to telnet to the P 660R Tx v3 ...

Page 64: ...P 660R Tx v3 Series Support Notes 64 All contents copyright 2008 ZyXEL Communications Corporation ...

Page 65: ...P 660R Tx v3 Series Support Notes 65 All contents copyright 2008 ZyXEL Communications Corporation Step 3 So that after you invoke the relevant commands you could save the logs you ve captured ...

Page 66: ...nd param command help command subcommand help General user interface 1 Shows the following commands and all major sub commands 2 exit Exit Subcommand To get the latest CI Command list The latest CI Command list is available in release note of every ZyXEL firmware release Please go to ZyXEL public WEB site http www zyxel com support download_index php to download firmware package zip you should unz...

Reviews: