background image

 

 

 

 

 

 

Summary of Contents for VIGOR VIGOR2750

Page 1: ......

Page 2: ...Vigor2750 Series User s Guide ii Vigor2750 Series High Speed VDSL2 Router User s Guide Version 1 0 Firmware Version V1 4 0 Date 26 10 2010 ...

Page 3: ...ions on conservation of the environment Warranty We warrant to the original end user purchaser that the router will be free from any defects in workmanship or materials for a period of two 2 years from the date of purchase from the dealer Please keep your purchase receipt in a safe place as it serves as proof of date of purchase During the warranty period and upon proof of purchase should the prod...

Page 4: ...diate radio frequency energy and if not installed and used in accordance with the instructions may cause harmful interference to radio communications However there is no guarantee that interference will not occur in a particular installation If this equipment does cause harmful interference to radio or television reception which can be determined by turning the equipment off and on the use is enco...

Page 5: ... Web Page 15 2 3 Changing Password 16 2 4 Quick Start Wizard 18 2 4 1 Setting up the Password 19 2 4 2 Setting up the Time Zone 19 2 4 3 Setting up the Internet Connection 20 2 4 4 Setting up the Wireless Connection 24 2 4 5 Saving the Wizard Configuration 29 2 5 Online Status 29 2 6 Saving Configuration 30 3 UserModeOperation 31 3 1 VDSL 31 3 1 1 VDSL Status 32 3 1 2 VDSL Setup 32 3 2 WAN 33 3 2 ...

Page 6: ...cess Control 84 3 7 4 Station List 85 3 7 5 Access Point Discovery 86 3 7 6 WMM Configuration 86 3 7 7 WDS 88 3 8 USB Application 90 3 8 1 USB General Settings 90 3 8 2 FTP User Management 91 3 8 3 Disk Status 92 3 8 4 Disk Shares 92 3 9 IPv6 94 3 9 1 IPv6 WAN Setup 94 3 9 2 IPv6 LAN Setup 97 3 9 3 IPv6 Firewall Setup 99 3 9 4 IPv6 Routing 101 3 9 5 IPv6 Neighbour 102 3 9 6 IPv6 TSPC Status 102 3 ...

Page 7: ...e 147 4 5 2 Ports Configuration 148 4 5 3 Access Control List 150 4 6 Bandwidth Management 162 4 6 1 Session Limit 162 4 6 2 Bandwidth Limit 163 4 6 3 Port Rate Control 165 4 6 4 QoS Control List 165 4 6 5 Ports Priority 170 4 6 6 QoS Statistics 171 4 7 Applications 174 4 7 1 Dynamic DNS 174 4 7 2 Schedule 175 4 7 3 IGMP 177 4 7 4 IGMP Status 177 4 7 5 UPnP Configuration 178 4 7 6 Wake On LAN 180 ...

Page 8: ...4 13 System Maintenance 221 4 13 1 System Status 221 4 13 2 TR 069 223 4 13 3 System Password 224 4 13 4 User Password 225 4 13 5 Configuration Backup 225 4 13 6 Syslog Mail Alert 227 4 13 7 Time and Date 229 4 13 8 Management 230 4 13 9 Reboot System 231 4 13 10 Firmware Upgrade 231 4 14 Diagnostics 232 4 14 1 Ping 232 4 14 2 Routing Table 233 4 14 3 System Log 234 4 14 4 Traffic Overview 234 4 1...

Page 9: ...K or Not 250 6 3 Pinging the Router from Your Computer 252 6 4 Checking If the ISP Settings are OK or Not 253 6 5 Forcing Vigor Router into TFTP Mode for Performing the Firmware Upgrade 254 6 6 Backing to Factory Default Setting If Necessary 257 6 7 Contacting Your Dealer 258 Appendix Basic Commands 259 ...

Page 10: ......

Page 11: ...rformance and secured broadband connectivity provided by Vigor 2750 series you can simultaneously engage these bandwidth intensive applications such as high definition video streaming online gaming and Internet telephony access 1 1 1 1 W We eb b C Co on nf fi ig gu ur ra at ti io on n B Bu ut tt to on ns s E Ex xp pl la an na at ti io on n Several main buttons appeared on the web pages are defined...

Page 12: ...are NAT is disabled On The DSL port is connected Blinking Slowly The router is ready DSL Blinking Quickly The connection is training On Green The port is connected with 1000Mbps Blinking Green The data is transmitting On Orange The port is connected with 100Mbps LAN1 2 3 4 Blinking Orange The data is transmitting USB1 2 On A USB device is connected and active VPN On The VPN tunnel is active QoS On...

Page 13: ...ngs Usage Turn on the router ACT LED is blinking Press the hole and keep for more than 5 seconds When you see the ACT LED begins to blink rapidly than usual release the button Then the router will restart with the factory default configuration PWR Connector for a power adapter I O Power Switch ...

Page 14: ...e port is connected with 100Mbps LAN1 2 3 4 Blinking Orange The data is transmitting USB1 2 On A USB device is connected and active VPN On The VPN tunnel is active QoS On The QoS function is active WLAN On Wireless access point is ready On Press this button for 2 seconds to wait for client device making network connection through WPS When the LED lights up the WPS connection will be on WPS Button ...

Page 15: ...ngs Usage Turn on the router ACT LED is blinking Press the hole and keep for more than 5 seconds When you see the ACT LED begins to blink rapidly than usual release the button Then the router will restart with the factory default configuration PWR Connector for a power adapter I O Power Switch ...

Page 16: ...N1 2 3 4 Blinking Orange The data is transmitting USB1 2 On A USB device is connected and active On The phone connected to this port is off hook Off The phone connected to this port is on hook Phone1 Phone2 Blinking A phone call comes WLAN On Wireless access point is ready On Press this button for 2 seconds to wait for client device making network connection through WPS When the LED lights up the ...

Page 17: ...eset Restore the default settings Usage Turn on the router ACT LED is blinking Press the hole and keep for more than 5 seconds When you see the ACT LED begins to blink rapidly than usual release the button Then the router will restart with the factory default configuration PWR Connector for a power adapter ON OFF Power Switch ...

Page 18: ...Connect Phone port to a conventional analog telephone 4 Connect detachable antennas to the router for Vigor2750 series n model 5 Connect one end of the power cord to the power port of this device Connect the other end to the wall outlet of electricity 6 Power on the router 7 Check the ACT and DSL LAN LEDs to assure network connection For the detailed information of LED status please refer to secti...

Page 19: ...ta an nd d I In ns st ta al ll la at ti io on n The Vigor2750 must be placed erectly Therefore you have to install a stand onto the router to make it standing firmly Please follow the figures listed below to finish the installation c d e f ...

Page 20: ...ia the router The example provided here is made based on Windows XP 2000 For Windows 98 SE Vista please visit www draytek com Before using it please follow the steps below to configure settings for connected computers or wireless clients 1 Connect the printer with the router through USB parallel port 2 Open Start Settings Printer and Faxes 3 Open File Add a New Computer A welcome dialog will appea...

Page 21: ... Series User s Guide 11 4 Click Local printer attached to this computer and click Next 5 In this dialog choose Create a new port Type of port and use the drop down list to select Standard TCP IP Port Click Next ...

Page 22: ... following dialog type 192 168 1 1 router s LAN IP in the field of Printer Name or IP Address and type IP_192 168 1 1 as the port name Then click Next 7 Click Standard and choose Generic Network Card 8 Then in the following dialog click Finish ...

Page 23: ...orrect driver loaded onto your PC When you finish the selection click Next 10 For the final stage you need to go back to Control Panel Printers and edit the property of the new printer you have added 11 Select LPR on Protocol type p1 number 1 as Queue Name Then click OK Next please refer to the red rectangle for choosing the correct protocol and UPR name ...

Page 24: ... or other additional functions are not supported If you do not know whether your printer is supported or not please visit www draytek com to find out the printer list Open Support FAQ find out the link of Printer Server and click it then click the What types of printers are compatible with Vigor router link Note 2 Vigor router supports printing request from computers via LAN ports but not WAN port...

Page 25: ...iguration 2 2 2 2 A Ac cc ce es ss si in ng g W We eb b P Pa ag ge e 1 Make sure your PC connects to the router correctly You may either simply set up your computer to get IP dynamically from the router or set up the IP address of the computer to be the same subnet as the default IP address of Vigor router 192 168 1 1 For the detailed information please refer to the later section Trouble Shooting ...

Page 26: ...rd d No matter user mode operation or admin mode operation please change the password for the original security of the router 1 Open a web browser on your PC and type http 192 168 1 1 A pop up window will open to ask for username and password 2 Please type admin admin on Username Password for admin mode Otherwise do not type any word both username and password are Null for user mode on the window ...

Page 27: ...e configuration Note The home page will change slightly in accordance with the type of the router you have 4 Go to System Maintenance page and choose System Password User Password Or 5 Type New Password in New Password and Confirm New Password fields Then click OK to continue ...

Page 28: ...Q Qu ui ic ck k S St ta ar rt t W Wi iz za ar rd d Notice Quick Start Wizard for user mode operation is the same as for admin mode operation If your router can be under an environment with high speed NAT the configuration provide here can help you to deploy and use the router quickly The first screen of Quick Start Wizard is welcome page please click Next ...

Page 29: ...password After typing the password please click Next 2 2 4 4 2 2 S Se et tt ti in ng g u up p t th he e T Ti im me e Z Zo on ne e On the next page as shown below please select the Time Zone for the router installed and specify the NTP server s If the NTP Server you want is not listed on this page please click NTP Server to add a new one Then click Next for next step ...

Page 30: ...h connection type will bring out different web page S St ta at ti ic c I IP P You will receive a fixed public IP address or a public subnet namely multiple public IP addresses from your DSL or Cable ISP service providers In most cases a Cable service provider will offer a fixed public IP while a DSL service provider will offer a public subnet If you have a public subnet you could assign an IP addr...

Page 31: ...e PC Address The result will be displayed in the field of MAC Address After finishing the settings here please click Next D DH HC CP P It is not necessary for you to type any IP address manually Simply choose this type and the system will obtain the IP address automatically from DHCP server Enable The router will detect the MAC address automatically Or check the box to enable MAC address cloning C...

Page 32: ...select PPPoE for this router The following page will be shown User Name Assign a specific valid user name provided by the ISP Password Assign a valid password provided by the ISP Confirm Password Type the password again for confirmation Redial Policy If you want to connect to Internet all the time you can choose Always On Otherwise choose Connect on Demand Idle Time Out Set the timeout for breakin...

Page 33: ... server WAN IP Network Settings You can choose Static IP or DHCP as WAN IP network setting IP Address Type the IP address if you choose Static IP as the WAN IP network setting Subnet Mask Type the subnet mask if you chose Static IP as the WAN IP Redial Policy If you want to connect to Internet all the time you can choose Always On Otherwise choose Connect on Demand Idle Time Out Set the timeout fo...

Page 34: ...For the user of Vigor2750 please skip this step Enable Wireless LAN Check the box to enable the wireless function SSID Broadcast Choose Show to make the SSID being seen by wireless clients Choose Hide to prevent from wireless sniffing and make it harder for unauthorized clients or STAs to join your wireless LAN SSID It means the identification of the wireless LAN SSID can be any text numbers or va...

Page 35: ...tication simply consists of two communications The first is an authentication request by the client that contains the station ID typically the MAC address This is followed by an authentication response from the AP router containing a success or failure message An example of when a failure may occur is if the client s MAC address is explicitly excluded in the AP router configuration Shared Shared k...

Page 36: ...PA encrypts each frame transmitted from the radio using the key which either PSK Pre Shared Key entered manually in this field below or automatically negotiated via 802 1x authentication Select WPA WPA2 or Auto as WPA mode WPA Algorithm Choose the WPA algorithm TKIP AES or Auto WPA Pre shared Key The keys can be entered in ASCII or Hexadecimal Check the key you wish to use ...

Page 37: ... choose WPA RADIUS as the security configuration you have to specify WPA mode algorithm Radius server Radius server port and Radius server secret respectively Type The WPA encrypts each frame transmitted from the radio using the key which either PSK Pre Shared Key entered manually in this field below or automatically negotiated via 802 1x authentication Select WPA WPA2 or Auto as WPA mode WPA Algo...

Page 38: ... Button style WPS setup procedure The router will wait for WPS requests from wireless clients about two minutes The WPS LED on the router will blink fast when WPS is in progress It will return to normal condition after two minutes You need to setup WPS within two minutes Configure via Client PinCode Type the PIN code specified in wireless client you wish to connect and click Start PIN button The W...

Page 39: ...Finish and then restart the router 2 2 5 5 O On nl li in ne e S St ta at tu us s The online status shows the system status WAN status and other status related to this router within one page If you select PPPoE as the protocol you will find out a link of Dial PPPoE or Drop PPPoE in the Online Status web page Detailed explanation is shown below LAN Status IP Address Displays the IP address of the LA...

Page 40: ...eceived packets at the WAN interface TX Bytes Display the total transmitted bytes at the WAN interface RX Bytes Display the total received packets at the WAN interface Profile Display current VDSL profile used State Display the state of VDSL line Up Speed Display the maximum up speed of VDSL line Down Speed Display the maximum down speed of VDSL line SNR Upstream Display the signal to noise ratio ...

Page 41: ... PC and type http 192 168 1 1 The window will ask for typing username and password 2 Do not type any word both username and password are Null for user operation on the window and click Login on the window Now the Main Screen will appear Be aware that User mode will be displayed on the bottom left side 3 3 1 1 V VD DS SL L This menu allows you to check VDSL status and configure VDSL settings for yo...

Page 42: ...wnstream and so on 3 3 1 1 2 2 V VD DS SL L S Se et tu up p This page allows you to set VDSL2 profile and G h Carrier Set VDSL2 Profile Check the profiles that the router will support Each profile can be used in different VDSL deployment architectures The working profile will be decided by CO side G hs Carrier Set Choose one of the items as the G hs Carrier Set Each set will have different frequen...

Page 43: ...ork Address Translation NAT function of the router will dedicate to translate public private addresses and the packets will be delivered to the correct host PC in the local area network Thus all the host PCs can share a common Internet connection G Ge et t Y Yo ou ur r P Pu ub bl li ic c I IP P A Ad dd dr re es ss s f fr ro om m I IS SP P In DSL deployment the PPP Point to Point style authenticati...

Page 44: ... when DSL WAN is not available the router will use 3 5G for supporting automatically The supported 3G USB Modem will be listed on DrayTek web site Please visit www draytek com for more detailed information Below shows the menu items for WAN 3 3 2 2 1 1 I In nt te er rn ne et t A Ac cc ce es ss s This page allows you to set WAN configuration with different modes Use the Connection Type drop down li...

Page 45: ...ny IP address to the WAN interface To use Static as the accessing protocol of the internet please choose Static mode from Connection Type drop down menu The following web page will be shown IP Address Type the IP address Subnet Mask Type the subnet mask Gateway IP Address Type the gateway IP address Primary DNS Server Type in the primary IP address for the router if you want to use Static IP mode ...

Page 46: ...the DHCP server of your ISP will assign a dynamic IP address for your router automatically It is not necessary for you to assign any setting Router Name Type in a name for the router It must be the same as the name used in Syslog Domain Name Type the domain name e g draytek to fit the request of some ISPs Mode Such function allows you to verify whether network connection is alive or not through AR...

Page 47: ...he password again for confirmation Redial Policy If you want to connect to Internet all the time you can choose Always On Otherwise choose Connect on Demand Idle Time Out Set the timeout for breaking down the Internet after passing through the time without any action When you choose Connect on Demand you have to type value here MTU Size It means Max Transmit Unit for packet The default setting is ...

Page 48: ...d Click Clone MAC Address The result will be displayed in the field of MAC Address After finishing all the settings here please click OK to activate them P PP PT TP P L L2 2T TP P To use PPTP L2TP as the accessing protocol of the internet please choose PPTP L2TP from Connection Type drop down menu The following web page will be displayed Username Type in the username provided by ISP in this field ...

Page 49: ... not provide it the router will apply a default secondary DNS Server automatically Redial Policy If you want to connect to Internet all the time you can choose Always On Otherwise choose Connect on Demand and Idle Time Out Set the timeout for breaking down the Internet after passing through the time without any action When you choose Connect on Demand you have to type value here MTU Size It means ...

Page 50: ...me which is provided and required by some ISPs Modem Dial String Such value is used to dial through USB mode Please use the default value If you have any question please contact to your ISP PPP Username Type the PPP username optional PPP Password Type the PPP password optional Clone MAC Address It is available when the box of Enable is checked Click Clone MAC Address The result will be displayed i...

Page 51: ... transmission can be done via 4 VLAN groups Enable Multi VLAN Setup Check the box to enable Multi VLAN configuration WAN VLAN ID Data sent out through the WAN port will be tagged with VLAN ID number specified here The range of ID number you can type is from 2 4096 Enable VoIP WAN Setup Check the box to enable VoIP WAN configuration Such feature is available only for v model VoIP WAN VLAN ID Voice ...

Page 52: ... usage of VoIP The settings will be changed based on the connection type selected When Static IP is selected as connection type you need to configure the following settings IP Address Type the IP address obtained from ISP for the usage of VoIP Subnet Mask Type the Subnet mask obtained from ISP for the usage of VoIP Gateway IP Address Type the gateway IP address obtained from ISP for the usage of V...

Page 53: ...Type the password obtained from the ISP Confirm Password Type the password again for confirmation MTU Size Type the largest size in bytes of a packet After finishing all the settings here please click OK to activate them 3 3 2 2 3 3 3 3G G B Ba ac ck ku up p This page is used to setup 3G backup function If you enable 3G backup make sure your WAN connection type is not in 3G mode When the WAN conne...

Page 54: ...L LA AN N Local Area Network LAN is a group of subnets regulated and ruled by router The design of network structure is related to what type of public IP addresses coming from your ISP B Ba as si ic cs s o of f L LA AN N The most generic function of Vigor router is NAT It creates a private subnet of your own As mentioned previously the router will talk to other public hosts on the Internet by usin...

Page 55: ...e with other public hosts or servers outside Therefore the router should be set as the gateway for public hosts W Wh ha at t i is s R Ro ou ut ti in ng g I In nf fo or rm ma at ti io on n P Pr ro ot to oc co ol l R RI IP P Vigor router will exchange routing information with neighboring routers using the RIP to accomplish IP routing This allows users to change the information of the router such as ...

Page 56: ...de 46 You can group local hosts by physical ports and create up to 4 virtual LANs To manage the communication between different groups please set up rules in Virtual LAN VLAN function and the rate of each Below shows the LAN menu ...

Page 57: ...the box to enable DHCP server setting Start IPAddress Enter a value of the IP address pool for the DHCP server to start with when issuing IP addresses If the 2nd IP address of your router is 220 135 240 1 the starting IP address must be 220 135 240 2 or greater but smaller than 220 135 240 254 IP Pool Counts Enter the number of IP addresses in the pool The maximum is 10 For example if you type 3 a...

Page 58: ...he router will resolve the domain name immediately Otherwise the router forwards the DNS query packet to the external DNS server by establishing a WAN connection After finishing all the settings here please click OK to activate them 3 3 3 3 2 2 P Po or rt ts s Ports page is used to change the setting for LAN ports You can set or reset the following items All of them are described in detail below P...

Page 59: ...AC drops frames after an excessive collision has occurred If yes a frame is dropped after excessive collision This is IEEE Standard 802 3 half duplex flow control operation Restart It determines whether the MAC retransmits frames after an excessive collision has occurred If set a frame is not dropped after excessive collisions but the backoff sequence is restarted This is a violation of IEEE Stand...

Page 60: ...fault Aging Time is 300 seconds MAC Table Learning List the port members which apply dynamic learning mechanism or not Auto Enable this port MAC address dynamic learning mechanism Disable Disable this port MAC address dynamic learning mechanism only support static MAC address setting Secure Disable this port MAC address dynamic learning mechanism and copy the dynamic learning packets to CPU Static...

Page 61: ...AN N Virtual LAN function provides you a very convenient way to manage hosts by grouping them based on the physical port You can also manage the in out rate of each port Go to LAN page and select VLAN The following page will appear VLAN function is enabled in default Note For the VALN feature in LAN is port based the available numbers for PVLAN ID can be 1 4 Add New Private VLAN Click this button ...

Page 62: ...t t It is used to monitor the traffic of the network For example we assume that LAN1 and LAN2 are Monitor Port and Monitor ingress Port respectively thus the traffic received by LAN2 will be copied to LAN1 for monitoring Enable Monitor Port Check to enable this function Monitor Port Click the one of the LAN ports to specify it for monitoring Monitor ingress port Check to set up the port s for bein...

Page 63: ...d P Pu ub bl li ic c N Ne et tw wo or rk ks s Here is an example of setting Static Route in Main Router so that user A and B locating in different subnet can talk to each other via the router Assuming the Internet access has been configured and the router works properly z use the Main Router to surf the Internet z create a private subnet 192 168 10 0 using an internal Router A 192 168 1 2 z create...

Page 64: ... which regulates all packets destined to 211 100 88 0 will be forwarded to 192 168 1 3 3 Verify current routing table 3 3 3 3 7 7 B Bi in nd d I IP P t to o M MA AC C This function is used to bind the IP and MAC address in LAN to have a strengthening control in network When this function is enabled all the assigned IP and MAC address binding together cannot be changed If you modified the binding I...

Page 65: ...C address listed in ARP table can be selected and added to IP Bind List by clicking Add below Add and Edit IP Address Type the IP address that will be used for the specified MAC address Mac Address Type the MAC address that is used to bind with the assigned IP address Refresh It is used to refresh the ARP table When there is one new PC added to the LAN you can click this link to obtain the newly A...

Page 66: ...the inversion based on its table Therefore the internal host can communicate with external host smoothly The benefit of the NAT includes z Save cost on applying public IP address and apply efficient usage of IP address NAT allows the internal IP addresses of local hosts to be translated into one public IP address thus you can have only one IP address on behalf of the entire internal hosts z Enhanc...

Page 67: ...u keep the application involved up to date to avoid falling victim to any security exploits To add a new open port click Add new entry Name Specify the name for the defined network service Protocol Specify the transport layer protocol It could be TCP UDP and TCP UDP Start Port Specify the starting port number of the service offered by the local host End Port optional Specify the ending port number...

Page 68: ...r clients will continue to work without inappropriate interruption DMZ Host allows a defined internal user to be totally exposed to the Internet which usually helps some special applications such as Netmeeting or Internet Games etc Note The security properties of NAT are somewhat bypassed if you set up DMZ host We suggest you to add additional filter rules or a secondary firewall Click DMZ Host to...

Page 69: ...will occupy over resources which might result in important accesses impacted To solve the problem you can use limit session to limit the session procession for specified Hosts In the Bandwidth Management menu click Sessions Limit to open the web page To activate the function of limit session simply click Enable and set the default session limit Disable Click this button to close the function of li...

Page 70: ...e Remove the selected settings existing on the limitation list When you finish adding a new session limit simply click OK 3 3 5 5 2 2 B Ba an nd dw wi id dt th h L Li im mi it t The downstream or upstream from FTP HTTP or some P2P applications will occupy large of bandwidth and affect the applications for other programs Please use Limit Bandwidth to make the bandwidth usage more efficient In the B...

Page 71: ...fluenced by the bandwidth limitation set here Please define the start IP address for the specific limitation End IP Define the end IP address for the specific limitation TX Limit Define the limitation for the speed of the upstream to be applied as specific limitation If you do not set the limit in this field the system will use the default speed for the specific limitation you set for each index R...

Page 72: ... st t Deploying QoS Quality of Service management to guarantee that all applications receive the service levels required and sufficient bandwidth to meet performance expectations is indeed one important aspect of modern enterprise network One reason for QoS is that numerous TCP based applications tend to continually increase their transmission rate and consume all available bandwidth which is call...

Page 73: ...omain owners to define the service level provided toward traffic from different domains Then each DS node in these domains will perform the priority treatment This is called per hop behavior PHB The definition of PHB includes Expedited Forwarding EF Assured Forwarding AF and Best Effort BE AF defines the four classes of delivery or forwarding classes and three levels of drop precedence in each cla...

Page 74: ...mission for the QCE QoS Control List allows users to set up to five groups of QCL Each QCL group can contain 12 QCE settings A Ad dd di in ng g a a N Ne ew w Q QC CE E Click to add a new QCE onto this page Different QCE type will bring out different web settings z If you choose Ethernet Type as QCE Type you have to type value for it and specify traffic class from Low Normal Medium and High ...

Page 75: ... traffic class from Low Normal Medium and High z If you choose TCP UDP Port as QCE Type you have to type the port number for it and specify traffic class from Low Normal Medium and High TCP UDP Port Click Single or Range If you select Range you have to type in the starting port number and the end porting number on the boxes below TCP UDP Port Range Type in the starting port number and the end port...

Page 76: ...ype value for it and specify traffic class from Low Normal Medium and High z If you choose ToS as QCE Type you have to specify priority class from Low Normal Medium and High z If you choose Tag Priority as QCE Type you have to specify priority class from Low Normal Medium and High ...

Page 77: ...ch port The classification is controlled by a QCL Quality Control List that is assigned to each port A QCL consists of an ordered list of up to 12 QCEs Quality Control Entry Each QCE can be used to classify certain frames to a specific QoS class This classification can be based on parameters such as VLAN ID UDP TCP port IPv4 IPv6 DSCP or Tag Priority Frames not matching any of the QCEs are classif...

Page 78: ... Use the drop down list to choose 1 2 4 or 8 as the queue weighted number 3 3 5 5 6 6 Q Qo oS S S St ta at ti is st ti ic cs s This page displays statistics for QoS setting Click WAN LAN link to check detailed information for each interface Click WAN LAN link to check detailed information for each interface ...

Page 79: ... frames in good and bad packets received RX 65 127 Bytes Display the number of 65 127 byte frames in good and bad packets received RX 128 255 Bytes Display the number of 128 255 byte frames in good and bad packets received RX 256 511 Bytes Display the number of 256 511 byte frames in good and bad packets received RX 512 1023 Bytes Display the number of 512 1023 byte frames in good and bad packets ...

Page 80: ...icast Display the show the counting number of the transmitted unicast packet Tx Multicast Display the show the counting number of the transmitted multicast packet Tx Broadcast Display the counting number of the transmitted broadcast packet Tx Pause Show the counting number of the transmitted pause packet Tx 64 Bytes Display the number of 64 byte frames in good and bad packets transmitted Tx 65 127...

Page 81: ...the router to update its online WAN IP address mappings on the specified Dynamic DNS server Once the router is online you will be able to use the registered domain name to access the router or internal virtual servers from the Internet It is particularly helpful if you host a web server FTP server or other server behind the router Before you use the Dynamic DNS feature you have to apply for free D...

Page 82: ...p to the Internet at a specified time but also restrict Internet access to certain hours so that users can connect to the Internet only during certain hours say business hours The schedule is also applicable to other functions You have to set your time before set schedule In System Maintenance Time and Date menu press Inquire Time button to set the Vigor router s clock to current time of your PC T...

Page 83: ...WN VPN connection will be activated inactivated based on the time schedule configured here Acts Specify how often the schedule will be applied Once The schedule will be applied just once Routine Specify which days in one week should perform the schedule Weekday If you choose Routine as Acts please specify the weekday s to perform the schedule ...

Page 84: ...roxy can act as a multicast proxy for hosts on LAN sides If you enable such function you can access any multicast group whenever you want Snooping Enabled Check the box to enable this function Unregistered IPMC Check the box to enable unregistered IPMC traffic flooding Fast Leave Check the box to Fast Leave on the LAN port 3 3 6 6 4 4 I IG GM MP P S St ta at tu us s This page display current IGMP ...

Page 85: ...e the firewall to automatically open the ports that they need to pass through a router It is more reliable than requiring a router to work out by itself which ports need to be opened Further the user does not have to manually set up port mappings or a DMZ UPnP is available on Windows XP and the router provide the associated support for MSN Messenger to allow full use of the voice video and messagi...

Page 86: ... some security threats You should consider carefully these risks before activating the UPnP function Some Microsoft operating systems have found out the UPnP weaknesses and hence you need to ensure that you have applied the latest service packs and patches Non privileged users can control some router functions including removing and adding port mappings The UPnP function dynamically adds port mapp...

Page 87: ...mmunications has enjoyed tremendous growth Wireless technology now reaches or is capable of reaching virtually every location on the surface of the earth Hundreds of millions of people exchange information every day via wireless communication products The Vigor n model a k a Vigor wireless router is designed for maximum flexibility and efficiency of a small office home Any authorized staff can bri...

Page 88: ...d Equivalent Privacy is a legacy method to encrypt each frame transmitted via radio using either a 64 bit or 128 bit key Usually access point will preset a set of four keys and it will communicate with each station using only one out of the four keys WPA Wi Fi Protected Access the most dominating security mechanism in industry is separated into two categories WPA personal or called WPA Pre Share K...

Page 89: ...ow Hide Choose Show to make the SSID being seen by wireless clients Choose Hide to prevent from wireless sniffing and make it harder for unauthorized clients or STAs to join your wireless LAN SSID It means the identification of the wireless LAN SSID can be any text numbers or various special characters The default SSID is DrayTek We suggest you to change it Isolate Member Check this box to make th...

Page 90: ...to extend the bandwidth for wireless connection Such value can be modified manual However do not set the same value with Channel Tx Power Set the power percentage for transmission signal of access point The greater the value is the higher intensity of the signal will be Enable Green AP Such function is used to reduce the power consumption Green AP for the access point When there is no station conn...

Page 91: ...e format of WEP Key is restricted to 5 ASCII characters or 10 hexadecimal values in 64 bit encryption level or restricted to 13 ASCII characters or 26 hexadecimal values in 128 bit encryption level The allowed content is the ASCII characters from 33 to 126 except and Authentication Mode Choose OPEN or SHARED as the authentication mode OPEN Set wireless to authentication open mode SHARED Set wirele...

Page 92: ... and the RADIUS server in performing mutual authentication It enables centralized remote access authentication for network management Type The WPA encrypts each frame transmitted from the radio using the key which either PSK Pre Shared Key entered manually in this field below or automatically negotiated via 802 1x authentication Select WPA WPA2 or Auto as WPA mode WPA Algorithm Choose the WPA algo...

Page 93: ...he PIN code specified in wireless client you wish to connect and click Start PIN button The WLAN LED on the router will blink fast when WPS is in progress It will return to normal condition after two minutes You need to setup WPS within two minutes It is the simplest way to build connection between wireless network clients and vigor router Users do not need to select any encryption mode and type a...

Page 94: ...onal security of wireless access the Access Control facility allows you to restrict the network access right by controlling the wireless LAN MAC address of client Only the valid MAC address that has been configured can access the wireless LAN interface By clicking the Access Control a new web page will appear as depicted below so that you could edit the clients MAC addresses to control their acces...

Page 95: ...uration 3 3 7 7 4 4 S St ta at ti io on n L Li is st t Station List provides the knowledge of connecting wireless clients now along with its status code Index Display the number of the connecting client IP Address Display the WAN IP address for the connecting client MAC Address Display the MAC Address for the connecting client Connected Time Display the connection time for the connecting client SS...

Page 96: ...ignal of the scanned AP Scan It is used to discover all the connected AP The results will be shown on the box above this button If you want the found AP applying the WDS settings please type in the AP s MAC address on the bottom of the page and click Bridge or Repeater Next click Add to Later the MAC address of the AP will be added on WDS settings page 3 3 7 7 6 6 W WM MM M C Co on nf fi ig gu ur ...

Page 97: ...cify the value ranging from 1 to 15 Be aware that CWMax value must be greater than CWMin or equals to CWMin value Both values will influence the time delay for WMM accessing categories The difference between AC_VI and AC_VO categories must be smaller however the difference between AC_BE and AC_BK categories must be greater Txop It means transmission opportunity For WMM categories of AC_VI and AC_V...

Page 98: ...ill have better performance with lower reliability 3 3 7 7 7 7 W WD DS S WDS means Wireless Distribution System It is a protocol for connecting two access points AP wirelessly Usually it can be used for the following application y Provide bridge traffic between two LANs through the air y Extend the coverage range of a WLAN To meet the above requirement two WDS modes are implemented in Vigor router...

Page 99: ...e In Repeater mode the router will connect to up to four Vigor2750 which use the same mode and all wired Ethernet clients of every Vigor2750 will be connected together You can use this mode to connect a network to other networks which is physically isolated When you use this mode this access point is still able to accept wireless clients Click WDS from Wireless LAN menu The following page will be ...

Page 100: ...h clients local and remote must use the same Phy Mode to have the same transmission rate OK Click this button to save the configuration 3 3 8 8 U US SB B A Ap pp pl li ic ca at ti io on n USB diskette can be regarded as an FTP server By way of Vigor router users on LAN WAN can access write and read data stored in USB diskette After setting the configuration in USB Application you can type the IP a...

Page 101: ...fore modifying settings in this page please insert a USB diskette and configure settings in User User Configuration first Otherwise an error message will appear to warn you Click the name link under User Name to open the setting web page User Name It displays the username that user uses to login to the FTP server Volume Select the proper volume for the connected USB diskette Home Folder It determi...

Page 102: ...first And then remove the USB diskette later Safely Remove Disk Check this box and then you can remove the USB diskette safely Manufacturer Display the manufacturer of the disk Model Display the type of the disk Size Display the storage space of the diskette s Free Capacity Display the free disk space of the diskette s Status Display current usage status of the diskette s Update Click this button ...

Page 103: ...ew folder in the USB diskette In addition if the user types here he she can access into all of the disk folders and files in USB diskette Note When write protect status for the USB diskette is ON you cannot type any new folder name in this field Only can be used in such case Visible Check this box to make the shared folder to be seen in Network Neighborhood on Windows of clients in local network A...

Page 104: ...ntain Link Local only Static IPv6 DHCPv6 and TSPC Each type requires different parameter settings L Li in nk k L Lo oc ca al l O On nl ly y Link Local address is used for communicating with neighbouring nodes on the same link It is defined by the address prefix fe80 10 You don t need to setup Link Local address manually for it is generated automatically according to your MAC Address ...

Page 105: ...fix Length Type your IPv6 address prefix length here Gateway IPv6 Server Type your IPv6 gateway address here Primary DNS Server Type your IPv6 primary DNS Server address here Secondary DNS Server Type your IPv6 secondary DNS Server address here D DH HC CP Pv v6 6 C Cl li ie en nt t I IA A_ _N NA A DHCPv6 client mode would use IA_NA option of DHCPv6 protocol to obtain IPv6 address from server Prima...

Page 106: ...ns inside the configuration file It gets a public IPv6 IP address and an IPv6 prefix from the tunnel broker and then monitors the state of the tunnel in background After getting the IPv6 prefix and starting router advertisement daemon RADVD the PC behind this router can directly connect to IPv6 the Internet Username Type the name obtained from the broker vigor2750 is a default username applied fro...

Page 107: ...palive_interval Type the time for the interval between two keepalive messages transferring from the client to the broker Prefixlen Type the required prefix length for the client network If_prefix Display LAN interface name The name of the OS interface that will be configured with the first 64 of the received prefix from the broker and the router advertisement daemon is started to advertise that pr...

Page 108: ...t End IPv6 address configuration IPv6 Start Address IPv6 End Address Type the start and end address for IPv6 server RADVD The router advertisement daemon radvd sends Router Advertisement messages specified by RFC 2461 to a local Ethernet LAN periodically and when requested by a node sending a Router Solicitation message These messages are required for IPv6 stateless autoconfiguration Advertisement...

Page 109: ...s configured for IPv4 packets only Name Display the name of the rule Protocol Display the protocol TCP UDP ICMPv6 the rule uses Source IP Display the source IP address of such rule Destination IP Display the destination IP address of such rule Source Port Display the source port number of such rule Destination Port Display the destination port number of such rule Action Display the status accept o...

Page 110: ... for the rule Protocol Specify a protocol for this rule Source IP Type Determine the IP type as the source Source IP Type the IP address here if you choose Single as Source IP Type Source Subnet Type the subnet mask here if you choose Subnet as Source IP Type Destination IP Type Determine the IP type as the destination Destination IP Type the IP address here if you choose Single as Destination IP ...

Page 111: ... the packets through the protocol of IPv6 Accept If the IPv6 packets fit the condition listed in this page the router will let it pass through Drop If the IPv6 packets fit the condition listed in this page the router will block it 3 3 9 9 4 4 I IP Pv v6 6 R Ro ou ut ti in ng g This page displays the routing table for the protocol of IPv6 Device Display the interface name eth0 eth1 fp etc that used...

Page 112: ...or s may be unreachable but not verified until a packet is sent delay neighbor may be unreachable and a packet was sent probe neighbor may be unreachable and probes are sent to verify the reachability Auto refresh Check this box to enable an automatic refresh of the page at regular intervals 3 3 9 9 6 6 I IP Pv v6 6 T TS SP PC C S St ta at tu us s IPv6 TSPC status web page could help you to diagno...

Page 113: ...addresses remote endpoint address TSPC Prfix TSPC Prefixlen prefix length tunnel broker and so on Tunnel Status Disconnected The remote client doesn t connect to the tunnel server Connecting The remote client is connecting to the tunnel server Connected The remote client has been connected to the tunnel server Activity Sent sent to the tunnel RX bytes Received received from the tunnel RX bytes Whe...

Page 114: ... s Guide 104 When your PC obtains the IPv6 address please connect to http www ipv6 org If your PC access Internet via IPv6 connection your IPv6 address will be shown on the web page immediately Refer to the following figure ...

Page 115: ...TTPs SSH FTP and TELNET by using IPv6 protocol Check the box and type the port number respectively to enable the remote management of services Enable HTTP HTTPS SSH ICMP Ping FTP TELNET Enable the checkbox to allow system administrators to login from the Internet There are several servers provided by the system to allow you managing the router from Internet Check the box es to specify ...

Page 116: ...me for this user Full Name Type full name for this user Password Type the password for this user Password again Type the password again for confirmation Allow Disk Sharing Check this box to enable Samba file sharing Allow IPSEC L2TP Check this box to let the user connect via IPSEC L2TP Allow PPTP Check this box to let the user connect via PPTP Allow FTP Check this box to let the user connect to FT...

Page 117: ...na an nc ce e For the system setup there are several items that you have to know the way of configuration Status TR 069 User Password Configuration Backup Syslog Mail Alert Time and Date Management Reboot System and Firmware Upgrade Below shows the menu items for System Maintenance 3 3 1 11 1 1 1 S Sy ys st te em m S St ta at tu us s The System Status provides basic network settings of Vigor route...

Page 118: ...AN Interface IP Address Display the IP address of the LAN interface IP Mask Display the subnet mask address of the LAN interface IPv6 Address Global Display the global IPv6 address of the LAN interface IPv6 Address Link Display the link local IPv6 address of the LAN interface DHCP Server Display if the DHCP server is active or not WAN Connection Mode Display current connection type used Link Statu...

Page 119: ...ching with VigorACS server Such page provides VigorACS and CPE settings under TR 069 protocol All the settings configured here is for CPE to be controlled and managed with VigorACS server Users need to type URL username and password for the VigorACS server that such device will be connected However URL username and password under CPE client are fixed that users cannot change it The default CPE use...

Page 120: ...olve such problem you might change port number for CPE Periodic Inform Settings Uncheck Enable The system will not send inform message to ACS server Check Enable The system will send inform message to ACS server periodically with the time set in the box of interval time The default setting is Enable Please set interval time or schedule time for the router to send notification to CPE Or click Disab...

Page 121: ...em Maintenance Configuration Backup The following windows will be popped up as shown below 2 Type a key arbitrarily for encrypting the file Keep the key in mind You will need it whenever you want to restore such file Click Backup button to get into the following dialog Click Save button to open another dialog for saving configuration as a file 3 In Save As dialog the default filename is config cfg...

Page 122: ...able R Re es st to or re e C Co on nf fi ig gu ur ra at ti io on n 1 Go to System Maintenance Configuration Backup The following windows will be popped up as shown below 2 Click Browse button to choose the correct configuration file for uploading to the router Click Restore button and wait for few seconds the following picture will tell you that the restoration procedure is successful Note If the ...

Page 123: ...oose the severity level for the system log entry User access log Check this box to record the user MAC address the access IP address and the access port Enable Mail Alert Check the box to activate function of mail alert Send a test e mail Make a simple test for the e mail address specified in this page Please assign the mail address first and click this button to execute a test for verify the mail...

Page 124: ...e following 1 Just set your monitor PC s IP address in the field of Server IP Address 2 Install the Router Tools in the Utility within provided CD After installation click on the Router Tools Syslog from program menu 3 From the Syslog screen select the router you want to monitor Be reminded that in Network Information select the network adapter used to connect to the router Otherwise you won t suc...

Page 125: ...where the time of the router should be inquired from Current System Time Click Inquire Time to get the current time Time Zone Select the time zone where the router is located Add NTP server Click the button to add a new NTP server Delete Click this button to remove an NTP server Click OK to save these settings ...

Page 126: ...ckbox to allow system administrators to login from the Internet There are several servers provided by the system to allow you managing the router from Internet Check the box es to specify Enable SNMP Check it to enable such service Manager Host IP Set one host as the manager to execute SNMP function Type the IP address to specify the certain host Access List You could specify that the system admin...

Page 127: ... in the future 3 3 1 11 1 9 9 F Fi ir rm mw wa ar re e U Up pg gr ra ad de e Before upgrading your router firmware you need to install the Router Tools The Firmware Upgrade Utility is included in the tools The following web page will guide you to upgrade firmware by using an example Note that this example is running over Windows OS Operating System Download the newest firmware from DrayTek s web s...

Page 128: ...Vigor2750 Series User s Guide 118 This page is left blank ...

Page 129: ...1 Open a web browser on your PC and type http 192 168 1 1 The window will ask for typing username and password 2 Please type admin admin on Username Password for administration operation Now the Main Screen will appear Be aware that Admin mode will be displayed on the bottom left side 4 4 1 1 V VD DS SL L This menu allows you to check VDSL status and configure VDSL settings for you request ...

Page 130: ...wnstream and so on 4 4 1 1 2 2 V VD DS SL L S Se et tu up p This page allows you to set VDSL2 profile and G hs Carrier Set VDSL2 Profile Check the profiles that the router will support Each profile can be used in different VDSL deployment architectures The working profile will be decided by CO side G hs Carrier Set Choose one of the items as the G hs Carrier Set Each set will have different freque...

Page 131: ...h the Network Address Translation NAT function of the router will dedicate to translate public private addresses and the packets will be delivered to the correct host PC in the local area network Thus all the host PCs can share a common Internet connection G Ge et t Y Yo ou ur r P Pu ub bl li ic c I IP P A Ad dd dr re es ss s f fr ro om m I IS SP P In DSL deployment the PPP Point to Point style au...

Page 132: ... for supporting automatically The supported 3G USB Modem will be listed on DrayTek web site Please visit www draytek com for more detailed information Below shows the menu items for WAN 4 4 2 2 1 1 I In nt te er rn ne et t A Ac cc ce es ss s This page allows you to set WAN configuration with different modes Use the Connection Type drop down list to choose one of the WAN modes The corresponding pag...

Page 133: ...tatic mode from Connection Type drop down menu The following web page will be shown IP Address Type the IP address Subnet Mask Type the subnet mask Gateway IP Address Type the gateway IP address Primary DNS Server You must specify a DNS server IP address here because your ISP should provide you with usually more than one DNS Server If your ISP does not provide it the router will automatically appl...

Page 134: ...em D DH HC CP P DHCP allows a user to obtain an IP address automatically from a DHCP server on the Internet If you choose DHCP mode the DHCP server of your ISP will assign a dynamic IP address for your router automatically It is not necessary for you to assign any setting Router Name Type in a name for the router e g Vigor2750 It must be the same as the name used in Syslog Domain Name Type the dom...

Page 135: ...e following web page will be shown Username Type in the username provided by ISP in this field Password Type in the password provided by ISP in this field Confirm Password Type the password again for confirmation Redial Policy If you want to connect to Internet all the time you can choose Always On Otherwise choose Connect on Demand Idle Time Out Set the timeout for breaking down the Internet afte...

Page 136: ... all the settings that you adjusted in this page will be invalid Clone MAC Address It is available when the box of Enable is checked Click Clone MAC Address The result will be displayed in the field of MAC Address After finishing all the settings here please click OK to activate them P PP PT TP P L L2 2T TP P To use PPTP L2TP as the accessing protocol of the internet please choose PPTP L2TP from C...

Page 137: ...ddress here because your ISP often provides you more than one DNS Server If your ISP does not provide it the router will automatically apply default secondary DNS Server IP address 194 98 0 1 to this field Redial Policy If you want to connect to Internet all the time you can choose Always On Otherwise choose Connect on Demand and Idle Time Out Set the timeout for breaking down the Internet after p...

Page 138: ...fault value If you have any question please contact to your ISP APN Name APN means Access Point Name which is provided and required by some ISPs Modem Dial String Such value is used to dial through USB mode Please use the default value If you have any question please contact to your ISP PPP Username Type the PPP username optional PPP Password Type the PPP password optional Clone MAC Address It is ...

Page 139: ...s Enable Multi VLAN Setup Check the box to enable Multi VLAN configuration WAN VLAN ID Data sent out through the WAN port will be tagged with VLAN ID number specified here The range of ID number you can type is from 2 4096 Enable VoIP WAN Setup Check the box to enable VoIP WAN configuration VoIP WAN VLAN ID Voice sent out through the WAN port will be tagged with VLAN ID number specified here The r...

Page 140: ... you need to configure the following settings IP Address Type the IP address obtained from ISP for the usage of VoIP Subnet Mask Type the Subnet mask obtained from ISP for the usage of VoIP Gateway IP Address Type the gateway IP address obtained from ISP for the usage of VoIP Primary DNS Server Type the IP address of primary DNS server obtained from ISP for the usage of VoIP Secondary DNS Server T...

Page 141: ...ion MTU Size It means Max Transmit Unit for packet The default setting is 1442 After finishing all the settings here please click OK to activate them 4 4 2 2 3 3 3 3G G B Ba ac ck ku up p This page is used to setup 3G backup function If you enable 3G backup make sure your WAN connection type is not in 3G mode When the WAN connection is broken router will try to keep the connection with 3G mode Aft...

Page 142: ...in the field of MAC Address 4 4 3 3 L LA AN N Local Area Network LAN is a group of subnets regulated and ruled by router The design of network structure is related to what type of public IP addresses coming from your ISP B Ba as si ic cs s o of f L LA AN N The most generic function of Vigor router is NAT It creates a private subnet of your own As mentioned previously the router will talk to other ...

Page 143: ...ing to help hosts in the public subnet to communicate with other public hosts or servers outside Therefore the router should be set as the gateway for public hosts W Wh ha at t i is s R Ro ou ut ti in ng g I In nf fo or rm ma at ti io on n P Pr ro ot to oc co ol l R RI IP P Vigor router will exchange routing information with neighboring routers using the RIP to accomplish IP routing This allows us...

Page 144: ... W Wh ha at t a ar re e V Vi ir rt tu ua al l L LA AN Ns s a an nd d R Ra at te e C Co on nt tr ro ol l You can group local hosts by physical ports and create up to 4 virtual LANs To manage the communication between different groups please set up rules in Virtual LAN VLAN function and the rate of each 4 4 3 3 1 1 G Ge en ne er ra al l S Se et tu up p This page provides you the general settings for...

Page 145: ... 240 11 Lease Time It allows you to set the leased time for the specified PC Force DNS manual setting Force router to use DNS servers in this page instead of DNS servers given by the Internet Access server PPPoE PPTP L2TP or DHCP server Primary IPAddress You must specify a DNS server IP address here because your ISP should provide you with usually more than one DNS Server If your ISP does not prov...

Page 146: ...for the router If you have no idea in configuring speed simple use the default setting Auto Flow Control If flow control is enabled by checking Configured box both parties can send PAUSE frame to the transmitting device s if the receiving port is too busy to handle If not there will be no flow control in the port It drops the packet if too much to handle Current Rx indicates whether pause frames o...

Page 147: ...ive collisions but the backoff sequence is restarted This is a violation of IEEE Standard 802 3 but is useful in non dropping half duplex flow control operation Power Control The Configured column allows for changing the power savings mode parameters per port Disabled All power savings mechanisms disabled ActiPHY Link down power savings enabled PerfectReach Link up power savings enabled Enabled Bo...

Page 148: ...anism or not Auto Enable this port MAC address dynamic learning mechanism Disable Disable this port MAC address dynamic learning mechanism only support static MAC address setting Secure Disable this port MAC address dynamic learning mechanism and copy the dynamic learning packets to CPU Static MAC Table Config Specify static MAC address with VLAN ID to apply aging configuration Delete Click the bu...

Page 149: ...age will appear VLAN function is enabled in default Note For the VALN feature in LAN is port based the available numbers for PVLAN ID can be 1 4 Add New Private VLAN Click this button to add a new private VLAN The router allows you to add up to 4 VLAN To add or remove a VLAN please refer to the following example 1 VLAN 1 is consisted of hosts linked to P1 P4 2 After checking the box to enable VLAN...

Page 150: ...le Monitor Port Check to enable this function Monitor Port Click the one of the LAN ports to specify it for monitoring Monitor ingress port Check to set up the port s for being monitored It only monitors the packets received by the port you set up Monitor egress port Check to set up the port s for being monitored It only monitors the packets transmitted by the port you set up 4 4 3 3 6 6 S St ta a...

Page 151: ...ernet access has been configured and the router works properly z use the Main Router to surf the Internet z create a private subnet 192 168 10 0 using an internal Router A 192 168 1 2 z create a public subnet 211 100 88 0 via an internal Router B 192 168 1 3 z have set Main Router 192 168 1 1 as the default gateway for the Router A 192 168 1 2 Before setting Static Route user A cannot talk to user...

Page 152: ...ent routing table 4 4 3 3 7 7 B Bi in nd d I IP P t to o M MA AC C This function is used to bind the IP and MAC address in LAN to have a strengthening control in network When this function is enabled all the assigned IP and MAC address binding together cannot be changed If you modified the binding IP or MAC address it might cause you not access into the Internet Click LAN and click Bind IP to MAC ...

Page 153: ...List Simply click and select the one and click Remove The selected item will be removed from the IP Bind List Note Before you select Strict Bind you have to bind one set of IP MAC address for one PC If not no one of the PCs can access into Internet And the web configurator of the router might not be accessed 4 4 4 4 N NA AT T Usually the router serves as an NAT Network Address Translation router N...

Page 154: ...the menu items for NAT 4 4 4 4 1 1 H Ha ar rd dw wa ar re e N NA AT T Hardware base Acceleration Engine also named Protocol Processing Engine API is the function that Draytek provides to extremely speed up the NAT performance While the hardware acceleration mechanism is activated most of the bandwidth usage will be concentrated on the specific sessions which increase transmission speed to get ulti...

Page 155: ...UDP and TCP UDP Start Port Specify the starting port number of the service offered by the local host End Port optional Specify the ending port number of the service offered by the local host Local Host Enter the private IP address of the local host Local Port optional If it is configured the forwarded traffic is mapped to this port on the local host ...

Page 156: ...n the LAN Regular web surfing and other such Internet activities from other clients will continue to work without inappropriate interruption DMZ Host allows a defined internal user to be totally exposed to the Internet which usually helps some special applications such as Netmeeting or Internet Games etc The security properties of NAT are somewhat bypassed if you set up DMZ host We suggest you to ...

Page 157: ...he system by offending the vulnerabilities of the protocol or operation system The DoS Defense function enables the Vigor router to inspect every incoming packet based on the attack signature database Any malicious packet that might duplicate itself to paralyze the host in the secure LAN will be strictly blocked and a Syslog message will be sent as warning if you set up Syslog server Also the Vigo...

Page 158: ...o configure the ACL Access Control List parameters for each port These parameters will affect data packets received on a port unless the data packets match a specific ACE Access Control Entry Port There is one DSL port and 4 LAN ports in Vigor2750 Here each port will be configured with different ID action rate limiter ID port copy and etc Action Select whether forwarding is permitted Allow or deni...

Page 159: ... L Li im mi it te er r I ID D Configure the rate limiter for the ACL Access Control List of the router Please click Rate Limiter ID link to access into the following page Rate Limiter ID Rate limiter ID will be applied to DSL port and LAN port Please specify a rate number for each ID The default setting is 1 packet per second Rate Define the rate by choosing from the following drop down list ...

Page 160: ... di in ng g a a N Ne ew w A Ac cc ce es ss s C Co on nt tr ro ol l P Pr ro of fi il le e Click to add a new specific session limitation onto the list Define which port the packet from ACE Configuration Ingress Port define which port the packet coming from The policy IDs are defined in Firewall Port Configuration Each Policy ID might have more than one port grouped Frame Type Such option differs ac...

Page 161: ... ta ai il le ed d E Ex xp pl la an na at ti io on n f fo or r F Fr ra am me e T Ty yp pe e Frame Type selection will lead different options for configuration z Choose Ethernet Type as the Frame Type you will get Ethernet Type Parameters option as the following Ethernet Type Filter Choose Any to set the parameter with any value set by the router automatically or choose Specific to specify certain v...

Page 162: ...ned in Sender IP Address and Sender IP Mask fields Sender IP Address Type the Sender IP Address here This option is available when you choose Host or Network as Sender IP Filter Sender IP Mask Type the Sender IP Mask here This option is available only when you choose Network as Sender IP Filter Target IP Filter Specify the target IP filter for this specific ACE Choose Any to filter all of the pack...

Page 163: ...et hardware address field THA settings 0 means target hardware address is not equal to the SMAC address 1 means s target hardware address is equal to the SMAC address Any means any value is allowed IP Ethernet Length Specify whether frames packets can meet the action according to the ARP RARP hardware address length HLN and protocol address length PLN settings 0 means ARP RARP frames packets where...

Page 164: ...alue is allowed z Choose IPv4 as the Frame Type You will see IP Parameters on the bottom of the page If you choose ICMP as IP Protocol Filter you will get the page as the following Source IP Specify the Source IP filter for this ACE Any No source IP filter is specified Host Source IP filter is set to Host Specify the source IP address in the Source IP Address field that appears Network Source IP f...

Page 165: ...you want to filter a specific ICMP filter with this ACE you can enter a specific ICMP value A field for entering an ICMP value appears ICMP Type Value If you choose Specific as ICMP Type Filter you have to type the ICMP Type Value manually The allowed range is 0 to 255 A frame meeting this ACE matches this ICMP value ICMP Code Filter Specify the ICMP code filter for this ACE Any No ICMP code filte...

Page 166: ...y when you choose Network as Source IP Dest IP Specify the destination IP filter for this ACE Any No destination IP filter is specified Host Destination IP filter is set to Host Specify the destination IP address in the destination IP Address field that appears Network Destination IP filter is set to Network Specify the destination IP address and destination IP mask in the destination IP Address a...

Page 167: ...ame meeting this ACE matches this UDP source value Dest Port Filter Specify the UDP port destination filter for this ACE Any No UDP destination filter is specified Specific If you want to filter a specific UDP destination filter with this ACE you can enter a specific UDP destination value A field for entering a UDP destination value appears Range If you want to filter a specific UDP destination ra...

Page 168: ...en you choose Host or Network as source IP filter Source IP Mask Type the SIP Mask here This option is available only when you choose Network as source IP filter Dest IP Filter Specify the destination IP filter for this ACE Any No destination IP filter is specified Host Destination IP filter is set to Host Specify the destination IP address in the destination IP Address field that appears Network ...

Page 169: ...cify the TCP port destination filter for this ACE Any No TCP destination filter is specified Specific If you want to filter a specific TCP destination filter with this ACE you can enter a specific TCP destination value A field for entering a TCP destination value appears Range If you want to filter a specific TCP destination range filter with this ACE you can enter a specific TCP destination range...

Page 170: ...entry Any Any value is allowed TCP PSH Specify the TCP Push Function PSH value for this ACE 0 TCP frames where the PSH field is set must not be able to match this entry 1 TCP frames where the PSH field is set must be able to match this entry Any Any value is allowed TCP ACK Specify the TCP Acknowledgment field significant ACK value for this ACE 0 TCP frames where the ACK field is set must not be a...

Page 171: ...er is set to Host Specify the source IP address in the source IP Address field that appears Network Source IP filter is set to Network Specify the source IP address and source IP mask in the source IP Address and source IP Mask fields that appear Source IP Address Type the source IP Address here This option is available when you choose Host or Network as source IP Filter Source IP Mask Type the so...

Page 172: ... si io on n L Li im mi it t A PC with private IP address can access to the Internet via NAT router The router will generate the records of NAT sessions for such connection The P2P Peer to Peer applications e g BitTorrent always need many sessions for procession and also they will occupy over resources which might result in important accesses impacted To solve the problem you can use limit session ...

Page 173: ... the system will use the default session limit for the specific limitation you set for each index Add Adds the specific session limitation onto the list above Edit Allows you to edit the settings for the selected limitation Delete Remove the selected settings existing on the limitation list When you finish adding a new session limit simply click OK The following page will appear for you to check 4...

Page 174: ... you set on this web page Start IP Bandwidth limit can be applied on certain IP range That s only the PCs within the range will be influenced by the bandwidth limitation set here Please define the start IP address for the specific limitation End IP Define the end IP address for the specific limitation TX Limit Define the limitation for the speed of the upstream to be applied as specific limitation...

Page 175: ...i is st t Deploying QoS Quality of Service management to guarantee that all applications receive the service levels required and sufficient bandwidth to meet performance expectations is indeed one important aspect of modern enterprise network One reason for QoS is that numerous TCP based applications tend to continually increase their transmission rate and consume all available bandwidth which is ...

Page 176: ...domain owners to define the service level provided toward traffic from different domains Then each DS node in these domains will perform the priority treatment This is called per hop behavior PHB The definition of PHB includes Expedited Forwarding EF Assured Forwarding AF and Best Effort BE AF defines the four classes of delivery or forwarding classes and three levels of drop precedence in each cl...

Page 177: ...r the QCE QoS Control List QCL allows users to set up to five groups of QCL Each QCL group can contain 12 QCE settings A Ad dd di in ng g a a N Ne ew w Q QC CE E Click to add a new QoS Control Entry QCE onto this page Different QCE type will bring out different web settings z If you choose Ethernet Type as QCE Type you have to type value for it and specify traffic class from Low Normal Medium and ...

Page 178: ...y traffic class from Low Normal Medium and High z If you choose TCP UDP Port as QCE Type you have to type the port number for it and specify traffic class from Low Normal Medium and High TCP UDP Port Click Single or Range If you select Range you have to type in the starting port number and the end porting number on the boxes below TCP UDP Port Range Type in the starting port number and the end por...

Page 179: ...ype value for it and specify traffic class from Low Normal Medium and High z If you choose ToS as QCE Type you have to specify priority class from Low Normal Medium and High z If you choose Tag Priority as QCE Type you have to specify priority class from Low Normal Medium and High ...

Page 180: ...igure QoS settings for each port The classification is controlled by a QCL Quality Control List that is assigned to each port A QCL consists of an ordered list of up to 12 QCEs Quality Control Entry Each QCE can be used to classify certain frames to a specific QoS class This classification can be based on parameters such as VLAN ID UDP TCP port IPv4 IPv6 DSCP or Tag Priority Frames not matching an...

Page 181: ...edium class 2 packets from Normal class and 1 packet from Low class at the same time Strict Priority mode means Vigor will always process the packets from High Class at first then the packets from Medium class then the normal class Queue Weighted Use the drop down list to choose 1 2 4 or 8 as the queue weighted number 4 4 6 6 6 6 Q Qo oS S S St ta at ti is st ti ic cs s This page displays statisti...

Page 182: ...e frames in good and bad packets received RX 65 127 Bytes Display the number of 65 127 byte frames in good and bad packets received RX 128 255 Bytes Display the number of 128 255 byte frames in good and bad packets received RX 256 511 Bytes Display the number of 256 511 byte frames in good and bad packets received RX 512 1023 Bytes Display the number of 512 1023 byte frames in good and bad packets...

Page 183: ... Unicast Display the show the counting number of the transmitted unicast packet Tx Multicast Display the show the counting number of the transmitted multicast packet Tx Broadcast Display the counting number of the transmitted broadcast packet Tx Pause Show the counting number of the transmitted pause packet Tx 64 Bytes Display the number of 64 byte frames in good and bad packets transmitted Tx 65 ...

Page 184: ...ver Once the router is online you will be able to use the registered domain name to access the router or internal virtual servers from the Internet It is particularly helpful if you host a web server FTP server or other server behind the router Before you use the Dynamic DNS feature you have to apply for free DDNS service to the DDNS service providers The router provides up to three accounts from ...

Page 185: ...so that users can connect to the Internet only during certain hours say business hours The schedule is also applicable to other functions You have to set your time before set schedule In System Maintenance Time and Date menu press Inquire Time button to set the Vigor router s clock to current time of your PC The clock will reset once if you power down or reset the router There is another way to se...

Page 186: ...ss Wi Fi connection will be activated inactivated based on the time schedule configured here VPN UP DOWN VPN connection will be activated inactivated based on the time schedule configured here Acts Specify how often the schedule will be applied Once The schedule will be applied just once Routine Specify which days in one week should perform the schedule ...

Page 187: ...GMP proxy can act as a multicast proxy for hosts on LAN sides If you enable such function you can access any multicast group whenever you want Snooping Enabled Check the box to enable this function Unregistered IPMC Check the box to enable unregistered IPMC traffic flooding Fast Leave Check the box to Fast Leave on the LAN port 4 4 7 7 4 4 I IG GM MP P S St ta at tu us s This page display current ...

Page 188: ...router to work out by itself which ports need to be opened Further the user does not have to manually set up port mappings or a DMZ UPnP is available on Windows XP and the router provide the associated support for MSN Messenger to allow full use of the voice video and messaging features Enable UPnP Enable UPnP function You have to type the download and upload speed Download Speed Enter the maximum...

Page 189: ...an t work with Firewall Software Enabling firewall applications on your PC may cause the UPnP function not working properly This is because these applications will block the accessing ability of some network ports Security Considerations Activating the UPnP function on your network may incur some security threats You should consider carefully these risks before activating the UPnP function Some Mi...

Page 190: ...led a network card supporting WOL function By the way WOL function must be set as Enable on the BIOS setting Wake by Two types provide for you to wake up the binded IP If you choose Wake by MAC Address you have to type the correct MAC address of the host in MAC Address boxes If you choose Wake by IP Address you have to choose the correct IP address IP Address The IP addresses that have been config...

Page 191: ...N Service If this checkbox is checked the system firewall will allow VPN IPSec remote access from WAN side to the router Enable IPSec VPN Pass through Server inside your LAN If this checkbox is checked the system firewall will allow VPN IPSec remote access from WAN side to a VPN device on the LAN Type the IP address of the VPN device in the field next to the checkbox Enable PPTP VPN Service If thi...

Page 192: ... users For more detailed information about user profile settings please refer to section 4 13 4 4 8 8 3 3 I IP PS Se ec c R Re em mo ot te e D Di ia al l i in n This page allows you to configure IPSec Site to Client settings Mobile VPN Type This usually applies to those are remote dial in user or node LAN to LAN which uses dynamic IP address and IPSec related VPN connections such as L2TP over IPSe...

Page 193: ...ll use the given secret Advanced Settings Phase 1 IKE Negotiation of IKE parameters including encryption hash Diffie Hellman parameter values and lifetime to protect the following IKE exchange authentication of both peers using either a Pre Shared Key or Digital Signature x 509 The peer that starts the negotiation proposes all its policies to the remote peer and then remote peer tries to find a hi...

Page 194: ... ESP Status Display the status of the phase 2 IPSec ESP key exchange ESP Alg Display the encryption and authentication algorithm used during phase 2 of the VPN connection Establishment This algorithm is used for transporting data and the choice will affect the performance of the VPN tunnel User Name Display the dial in user account Interface Display the connection name assigned by the router Remot...

Page 195: ...cate the name of the LAN to LAN profile Endpoint Display the IP address of the VPN client IKE Alg Display the encryption and authentication algorithm used during phase 1 of the VPN connection Establishment The algorithm is used during exchange of key exchange ESP Alg Display the encryption and authentication algorithm used during phase 2 of the VPN connection Establishment This algorithm is used f...

Page 196: ... at the other end of the VPN tunnel IKE phase 1 mode Select from Main mode and Aggressive mode The ultimate outcome is to exchange security proposals to create a protected secure channel Main mode is more secure than Aggressive mode since more exchanges are done in a secure channel to set up the IPSec session However the Aggressive mode is faster The default value in Vigor router is Main mode Pre ...

Page 197: ...t specified in Remote Network Mask will travel through the VPN tunnel Remote Network Mask Add a static route to direct all traffic destined to this Remote Network IP Address Remote Network Mask through the VPN connection For IPSec this is the destination clients IDs of phase 2 quick mode IKE Phase 1 proposal Propose the local available authentication schemes and encryption algorithms to the VPN pe...

Page 198: ...t with the standard IEEE 802 11n draft 2 protocol To boost its performance further the Vigor Router is also loaded with advanced wireless technology to lift up data rate up to 300 Mbps Hence you can finally smoothly enjoy stream music and video Note The actual data throughput will vary according to the network conditions and environmental factors including volume of network traffic network overhea...

Page 199: ... a pre defined key is used for encryption during data transmission WPA applies Temporal Key Integrity Protocol TKIP for data encryption while WPA2 applies AES The WPA Enterprise combines not only encryption but also authentication Since WEP has been proved vulnerable you may consider using WPA for the most secure connection You should select the appropriate security mechanism according to your nee...

Page 200: ...AN SSID It means the identification of the wireless LAN SSID can be any text numbers or various special characters The default SSID is DrayTek We suggest you to change it Isolate Member Check this box to make the wireless clients stations with the same SSID not accessing for each other Wireless Mode Choose the wireless mode for this router At present only 802 11B B N mix is available Channel It me...

Page 201: ... for the access point When there is no station connected the power consumption of access point will be reduced Encryption Select an appropriate encryption mode to improve the security and privacy of your wireless data packets Each encryption mode will bring out different web page and ask you to offer additional configuration W Wi ir re el le es ss s S Se ec cu ur ri it ty y C Co on nf fi ig gu ur ...

Page 202: ...lues in 128 bit encryption level The allowed content is the ASCII characters from 33 to 126 except and Authentication Mode Choose OPEN or SHARED as the authentication mode OPEN Set wireless to authentication open mode SHARED Set wireless to authentication shared mode z WPA PSK Accepts only WPA clients and the encryption key should be entered in PSK The WPA encrypts each frame transmitted from the ...

Page 203: ... key which either PSK Pre Shared Key entered manually in this field below or automatically negotiated via 802 1x authentication Select WPA WPA2 or Auto as WPA mode WPA Algorithm Choose the WPA algorithm TKIP AES or Auto Server IP Address Enter the IP address of RADIUS server Destination Port The UDP port number that the RADIUS server is using The default value is 1812 based on RFC 2138 Shared Secr...

Page 204: ...condition after two minutes You need to setup WPS within two minutes It is the simplest way to build connection between wireless network clients and vigor router Users do not need to select any encryption mode and type any long encryption passphrase to setup a wireless client every time He she only needs to press a button on wireless client and WPS will connect for client and router automatically ...

Page 205: ...on with network card installed press Start PBC button of network card If you want to use PIN code you have to know the PIN code specified in wireless client Then provide the PIN code of the wireless client you wish to connect to the vigor router ...

Page 206: ...control their access rights deny or allow Filter Type Choose the rule for the MAC addresses displayed in this page Allow List all the MAC address of wireless clients listed here are allowed to do wireless connection Deny List all the MAC address of wireless clients listed here will be blocked Add a New Entry Add a new MAC address into the list Delete Delete the selected MAC address in the list Thi...

Page 207: ...t can be used to facilitate finding an AP for a WDS link This page is used to scan the existence of the APs on the wireless LAN Please click Scan to discover all the connected APs Note During the scanning process about 5 seconds no client is allowed to connect to Vigor CH Display the channel for the scanned AP SSID Display the SSID of the scanned AP BSSID Display the MAC address of the scanned AP ...

Page 208: ...ault setting is Disable Aifsn It controls how long the client waits for each data transmission Please specify the value ranging from 1 to 15 Such parameter will influence the time delay for WMM accessing categories For the service of voice or video image please set small value for AC_VI and AC_VO categories For the service of e mail or web browsing please set large value for AC_BE and AC_BK catego...

Page 209: ... transmitting WMM packets through wireless connection It can assure that the peer must receive the WMM packets Check the box means the AP router will not answer any response request for the transmitting packets It will have better performance with lower reliability 4 4 9 9 7 7 W WD DS S WDS means Wireless Distribution System It is a protocol for connecting two access points AP wirelessly Usually i...

Page 210: ...a network to other networks which is physically isolated Please note that when you set to this mode Vigor2750 will not accept regular wireless clients anymore In Repeater mode the router will connect to up to four Vigor2750 which use the same mode and all wired Ethernet clients of every Vigor2750 will be connected together You can use this mode to connect a network to other networks which is physi...

Page 211: ... Address field valid or not Choose one of the types for the router Please disable the unused link to get better performance Key Type 8 63 ASCII characters or 64 hexadecimal digits leading by 0x Peer Mac Address Four peer MAC addresses are allowed to be entered in this page at one time Phy Mode There are three types of transmission rates developed by different techniques for Phy Mode Data will be t...

Page 212: ...ype as the Phy Mode HTMIX If 802 11b g n wireless mode is used please choose such type as the Phy Mode Both clients local and remote must use the same Phy Mode to have the same transmission rate OK Click this button to save the configuration ...

Page 213: ...B diskette into the Vigor router please make sure the memory format for the USB diskette is FAT16 or FAT32 It is recommended for you to use FAT32 for viewing the filename completely FAT16 cannot support long filename Enable FTP Check this box to enable FTP connection Enable Disk Sharing Check this box to share the information on USB disk Workgroup Name Type the name for FTP users for accessing int...

Page 214: ... folder name in this field Only can be used in such case Access Rule Select the access right for the USB diskette When you finish the settings simply click OK to save the configuration 4 4 1 10 0 3 3 D Di is sk k S St ta at tu us s This page can display current using status of the USB diskette If you want to remove the diskette from USB port in router please check the box of Safely Remove Disk fir...

Page 215: ...computers Volume Select the proper volume for the connected USB diskette Path It determines the range for the client to access into The user can enter a directory name in this field Then after clicking OK the router will create the specific new folder in the USB diskette In addition if the user types here he she can access into all of the disk folders and files in USB diskette Note When write prot...

Page 216: ... access to the share disk Specific Users Only specific user s can access into the share disk 4 4 1 11 1 I IP Pv v6 6 4 4 1 11 1 1 1 I IP Pv v6 6 W WA AN N S Se et tu up p This page defines the IPv6 connection types for WAN interface Possible types contain Link Local only Static IPv6 DHCPv6 and TSPC Each type requires different parameter settings ...

Page 217: ...gnificant 64 bits are usually chosen as the interface hardware address constructed in modified EUI 64 format Prefix Length Display the fixed value 64 for prefix length S St ta at ti ic c I IP Pv v6 6 This type allows you to setup static IPv6 address for WAN IPv6 Address Type your IPv6 static IP here Prefix Length Type your IPv6 address prefix length here Gateway IPv6 Server Type your IPv6 gateway ...

Page 218: ...nel setup protocol client TSPC is an application which could help you to connect to IPv6 network easily Please make sure your IPv4 WAN connection is OK and apply one free account from hexage http go6 net 4105 register asp before you try to use TSPC for network connection TSPC would connect to tunnel broker and requests a tunnel according to the specifications inside the configuration file It gets ...

Page 219: ... the broker choose the tunnel mode appropriate for the client IPv6 in IPv4 Native Request an IPv6 in IPv4 tunnel IPv6 in IPv4 NAT Traversal Request an IPv6 in UDP of IPv4 tunnel for clients behind a NAT Auto reconnect Delay After passing the time set here the client will retry to connect in case of failure or keepalive timeout 0 means not retry Keepalive Yes Keep the connection between TSPC and tu...

Page 220: ...ngs IPv6 Address Type static IPv6 address for LAN IPv6 Link_local Address It is used for communicating with neighbouring nodes on the same link It is defined by the address prefix fe80 10 You don t need to setup Link Local address manually for it is generated automatically according to your MAC Address Enable Autoconfiguration Check this box to enable the auto configuration function for IPv6 conne...

Page 221: ... lifetime of 0 indicates that the router is not a default router and should not appear on the default router list 4 4 1 11 1 3 3 I IP Pv v6 6 F Fi ir re ew wa al ll l S Se et tu up p This page allows users to set firewall rules for IPv6 packets Note Section 4 4 Firewall is configured for IPv4 packets only Name Display the name of the rule Protocol Display the protocol TCP UDP ICMPv6 the rule uses ...

Page 222: ... for the rule Protocol Specify a protocol for this rule Source IP Type Determine the IP type as the source Source IP Type the IP address here if you choose Single as Source IP Type Source Subnet Type the subnet mask here if you choose Subnet as Source IP Type Destination IP Type Determine the IP type as the destination Destination IP Type the IP address here if you choose Single as Destination IP ...

Page 223: ...as the protocol Action Set the action that the router will perform for the packets through the protocol of IPv6 Accept If the IPv6 packets fit the condition listed in this page the router will let it pass through Drop If the IPv6 packets fit the condition listed in this page the router will block it E Ex xa am mp pl le e Refer to the following example 1 Use TSPC mode to connect to IPv6 network PC ...

Page 224: ...e for the protocol of IPv6 Device Display the interface name eth0 eth1 fp etc that used to transfer packets with addresses matching the prefix Prefix The IPv6 address prefix Metric Display the distance to the target usually counted in hops It is not used by recent kernels but may be needed by routing daemons Expires Display the lifetime of the route MTU Display the largest size in bytes of a packe...

Page 225: ...sible states include incomplete address resolution is in progress reachable neighbor is reachable stale neighbor s may be unreachable but not verified until a packet is sent delay neighbor may be unreachable and a packet was sent probe neighbor may be unreachable and probes are sent to verify the reachability Auto refresh Check this box to enable an automatic refresh of the page at regular interva...

Page 226: ...ring out different pages to represent IPv6 disconnection connecting and connected Tunnel Information Display interface name used to send TSPC prefix tunnel mode local endpoint addresses remote endpoint address TSPC Prfix TSPC Prefixlen prefix length tunnel broker and so on Tunnel Status Disconnected The remote client doesn t connect to the tunnel server Connecting The remote client is connecting t...

Page 227: ...n LAN Next the PC will generate one set of IPv6 public IP see the figure below Users can use such IP for connecting to IPv6 network When your PC obtains the IPv6 address please connect to http www ipv6 org If your PC access Internet via IPv6 connection your IPv6 address will be shown on the web page immediately Refer to the following figure ...

Page 228: ... HTTPs SSH FTP and TELNET by using IPv6 protocol Check the box and type the port number respectively to enable the remote management of services Enable HTTP HTTPS SSH ICMP Ping FTP TELNET Enable the checkbox to allow system administrators to login from the Internet There are several servers provided by the system to allow you managing the router from Internet Check the box es to specify ...

Page 229: ...rd Type the password for this user Confirm Password Type the password again for confirmation Allow Disk Sharing Check this box to have the remote user share the disk information Allow IPSEC L2TP Check this box to let the remote user connecting to this device through IPSEC L2TP Allow PPTP Check this box to let the remote user connecting to this device through PPTP Allow FTP Check this box to let th...

Page 230: ...ted and displayed on the page E Ed di it ti in ng g D De el le et ti in ng g U Us se er r S Se et tt ti in ng gs s To edit a user click the name link under Username to open the following page Modify the settings except Username and then click OK to save and exit it If you want to remove such user settings simply click Delete User ...

Page 231: ... S Sy ys st te em m S St ta at tu us s The System Status provides basic network settings of Vigor router It includes LAN and WAN interface information Also you could get the current running firmware version or firmware related information from this presentation Model Name Display the model name of the router Firmware Version Display the firmware version of the router Build Date Time Display the da...

Page 232: ...connection status MAC Address Display the MAC address of the WAN Interface IP Address Display the IP address of the WAN interface IP Mask Display the subnet mask address of the WAN interface IPv6 Address Link Display the IPv6 address of the WAN interface Default Gateway Display the gateway address of the WAN interface Primary DNS Display the specified primary DNS setting Secondary DNS Display the ...

Page 233: ...you configure VigorACS server ACS Settings Such data must be typed according to the ACS Auto Configuration Server you want to link Please refer to VigorACS user s manual for detailed information URL Type the URL for VigorACS server If the connected CPE needs to be authenticated please set URL as the following and type username and password for VigorACS server http IP address of VigorACS 8080 ACSSe...

Page 234: ...ically with the time set in the box of interval time The default setting is Enable Please set interval time or schedule time for the router to send notification to CPE Or click Disable to close the mechanism of notification 4 4 1 13 3 3 3 S Sy ys st te em m P Pa as ss sw wo or rd d This page allows you to set new password for admin operation Old Password Type in the old password The factory defaul...

Page 235: ...ssword to access into the web configurator again 4 4 1 13 3 5 5 C Co on nf fi ig gu ur ra at ti io on n B Ba ac ck ku up p B Ba ac ck ku up p t th he e C Co on nf fi ig gu ur ra at ti io on n Follow the steps below to backup your configuration 1 Go to System Maintenance Configuration Backup The following windows will be popped up as shown below 2 Type a key arbitrarily for encrypting the file Keep...

Page 236: ...e example is using Windows platform for demonstrating examples The Mac or Linux platform will appear different windows but the backup function is still available Note Backup for Certification must be done independently The Configuration Backup does not include information of Certificate R Re es st to or re e C Co on nf fi ig gu ur ra at ti io on n 1 Go to System Maintenance Configuration Backup Th...

Page 237: ...ted you will be asked to type the encrypted key before clicking Restore 4 4 1 13 3 6 6 S Sy ys sl lo og g M Ma ai il l A Al le er rt t SysLog function is provided for users to monitor router There is no bother to directly get into the Web Configurator of the router or borrow debug equipments Enable Syslog Access Check Enable to activate function of syslog Router Name Assign a name of this device S...

Page 238: ...he password for authentication Enable E mail Alert Check the box of User Login to send alert message to the e mail box while the router detecting the item s you specify here Click OK to save these settings For viewing the Syslog please do the following 1 Just set your monitor PC s IP address in the field of Server IP Address 2 Install the Router Tools in the Utility within provided CD After instal...

Page 239: ...where the time of the router should be inquired from Current System Time Click Inquire Time to get the current time Time Zone Select the time zone where the router is located Add NTP server Click the button to add a new NTP server Delete Click this button to remove an NTP server Click OK to save these settings ...

Page 240: ...ckbox to allow system administrators to login from the Internet There are several servers provided by the system to allow you managing the router from Internet Check the box es to specify Enable SNMP Check it to enable such service Manager Host IP Set one host as the manager to execute SNMP function Type the IP address to specify the certain host Access List You could specify that the system admin...

Page 241: ...n the future 4 4 1 13 3 1 10 0 F Fi ir rm mw wa ar re e U Up pg gr ra ad de e Before upgrading your router firmware you need to install the Router Tools The Firmware Upgrade Utility is included in the tools The following web page will guide you to upgrade firmware by using an example Note that this example is running over Windows OS Operating System Download the newest firmware from DrayTek s web ...

Page 242: ...agnostics 4 4 1 14 4 1 1 P Pi in ng g Click Diagnostics and click Ping to open the web page It is used to troubleshoot IP connection for your router IP Address Type in the IP address of the Host IP that you want to ping Ping Size Type in the payload size of the ICMP packet Values range from 8 bytes to 1400 bytes Start Click this button to start the ping work The result will be displayed on the scr...

Page 243: ... represent different routing status U route is up H target is a host G use gateway R reinstate route for dynamic routing D dynamically installed by daemon or redirect M modified from routing daemon or redirect A installed by addrconf C cache entry reject route Metric Display the distance to the target usually counted in hops Ref Display number of references to this route Not used in the Linux kern...

Page 244: ...em of the system log entry Message Display a short description of the system log entry Auto refresh Check it to enable auto refresh function Reverse Check it to have newest log entries presented first Refresh Click it to reload the page Export Click it to export the log as a text file Clear Click it to remove all of the records 4 4 1 14 4 4 4 T Tr ra af ff fi ic c O Ov ve er rv vi ie ew w This pag...

Page 245: ...ing Drops Display the number of the data lost in receiving and sending Filtered Display the number of received frames filtered by the forwarding process Auto refresh Check it to enable auto refresh function Refresh Click it to reload the page Clear Click it to clear the counters for all ports 4 4 1 14 4 5 5 D De et ta ai il le ed d S St ta at ti is st ti ic cs s This page display detailed statisti...

Page 246: ...he packet received Rx Normal Display the normal queue counter of the packet received Rx Medium Display the medium queue counter of the packet received Rx High Display the high queue counter of the packet received Rx Drops Display the number of frames dropped due to the lack of receiving buffer Rx CRC Alignment Display the number of Alignment errors packets received Rx Undersize Display the number ...

Page 247: ...l Display the number of Frames late collision or excessive collision Error which switch transmitted Auto refresh Check it to enable auto refresh function Refresh Click it to reload the page Clear Click it to clear the counters for all ports 4 4 1 14 4 6 6 M MA AC C A Ad dd dr re es ss s T Ta ab bl le e The MAC Address Table contains up to 8192 entries and is sorted first by VLAN ID then by MAC add...

Page 248: ...or dynamic entry VLAN Display the VLAN ID of that entry MAC Address Display the MAC address of that entry Port Members Display the port of that entry Auto refresh Check it to enable auto refresh function Refresh Click it to reload the page Clear Click it to clear the whole table ...

Page 249: ... DHCP Table to open the web page Computer Name It displays the name of the computer accepted the assigned IP address by this router IP Address It displays the IP address assigned by this router for specified PC MAC Address It displays the MAC address for the specified PC that DHCP assigned IP address for it Expire Time It displays the leased time of the specified PC Auto refresh Check it to enable...

Page 250: ... IP Address TX rate RX rate or Session link for arranging the data display Auto refresh Check it to enable auto refresh function Refresh Click this link to refresh this page manually Index Display the number of the data flow IP Address Display the IP address of the monitored device TX rate kbps Display the transmission speed of the monitored device RX rate kbps Display the receiving speed of the m...

Page 251: ...ere are for LAN ports and one DSL port in your router Through this page you can know which port is using and you can get the detailed statistics for each port by moving and clicking the mouse on the connected one Auto refresh Check it to enable auto refresh function Refresh Click it to reload the page if you change the LAN port connection Or you can check Auto refresh to reload the page by the sys...

Page 252: ...Vigor2750 Series User s Guide 242 This page is left blank ...

Page 253: ...by Vigor router a user can easily access into Internet for data transmission dialing a VoIP phone call out watching IPTV via IP STB and so on Below shows an example of multi VLAN application Please follow the steps below to configure multi VLAN settings 1 Go to LAN page and select VLAN The following page will appear VLAN function is enabled in default 2 Click Add New Private VLAN and type 2 as VLA...

Page 254: ...Vigor2750 Series User s Guide 244 3 Go to WAN page and select Multi VLAN Configure the settings as the following figure ...

Page 255: ...ll be categorized to the default class default is Normal 1 The first step to enable QoS is to set the correct WAN TX RX Rate in Port Rate Control page Policer Enabled option means to enable QoS for the RX Incoming direction Shaper Enabled option means to enable QoS for the TX Outgoing direction 2 Then configure the ports or protocols with specific traffic class value Open Bandwidth Management QoS ...

Page 256: ...DP port 6881 for BT with medium priority in non working hours 4 The last step is to select the QoS profile and configure the Queuing Weighted mode and rate Weighted mode means Vigor will process the packets from different classes according to the setting rate For example process 8 packets from High class 4 packets from Medium class 2 packets from Normal class and 1 packet from Low class at the sam...

Page 257: ...Vigor2750 Series User s Guide 247 5 After setting up above configurations we can see the packet counters in QoS Statistics page ...

Page 258: ...Vigor2750 Series User s Guide 248 This page is left blank ...

Page 259: ... Backing to factory default setting if necessary If all above stages are done and the router still cannot run normally it is the time for you to contact your dealer for advanced help 6 6 1 1 C Ch he ec ck ki in ng g I If f t th he e H Ha ar rd dw wa ar re e S St ta at tu us s I Is s O OK K o or r N No ot t Follow the steps below to verify the hardware status 1 Check the power line and WLAN LAN con...

Page 260: ...ter trying the above section if the link is stilled failed please do the steps listed below to make sure the network connection settings is OK F Fo or r W Wi in nd do ow ws s The example is based on Windows XP As to the examples for other operation systems please refer to the similar steps or find support notes in www draytek com 1 Go to Control Panel and then double click on Network Connections 2...

Page 261: ...atically and Obtain DNS server address automatically F Fo or r M Ma ac c O OS S 1 Double click on the current used Mac OS on the desktop 2 Open the Application folder and get into Network 3 On the Network screen select Using DHCP from the drop down list of Configure IPv4 ...

Page 262: ...uter correctly F Fo or r W Wi in nd do ow ws s 1 Open the Command Prompt window from Start menu Run 2 Type command for Windows 95 98 ME or cmd for Windows NT 2000 XP Vista The DOS command dialog will appear 3 Type ping 192 168 1 1 and press Enter If the link is OK the line of Reply from 192 168 1 1 bytes 32 time 1ms TTL 255 will appear 4 If the line does not appear please check the IP address sett...

Page 263: ... Se et tt ti in ng gs s a ar re e O OK K o or r N No ot t Open WAN Internet Access page and then check whether the ISP settings are set correctly Use the Connection Type drop down list to choose Static IP DHCP PPPoE PPTP L2TP 3G USB Modem for reviewing the settings that you configured previously ...

Page 264: ...neously 3 Change your PC IP address to 192 168 1 10 4 Open Firmware Upgrade Utility and key in Router IP 192 168 1 1 manually 5 Install Router Tools on one computer that connects to Vigor Router s LAN port 6 Make sure the computer can ping Vigor s LAN IP Default IP is 192 168 1 1 7 Run Router Tools Firmware Upgrade Utility 8 Input Vigor s LAN IP manually or use the button to select 9 Indicate the ...

Page 265: ...ow will pop up If the message of Request Timeout Transfer Abort appears please check if the connection between the computer and the Vigor is active or not And if the message of Incorrect No file name Transfer Abort appears please check if the firmware you download is correct for your Vigor router ...

Page 266: ...r2750 Series User s Guide 256 Note Please turn off the Firewall protection while upgrading the firmware with Windows Vista The Firewall function can be turned off via Control Panel Security Center Firewall ...

Page 267: ...et t You can reset the router to factory default via Web page Go to System Maintenance and choose Reboot System on the web page The following screen will appear Choose Using factory default configuration and click OK After few seconds the router will return all the settings to the factory settings H Ha ar rd dw wa ar re e R Re es se et t While the router is running ACT LED blinking press the Facto...

Page 268: ... nt ta ac ct ti in ng g Y Yo ou ur r D De ea al le er r If the router still cannot work correctly after trying many efforts please contact your dealer for further help right away For any questions please feel free to send e mail to support draytek com ...

Page 269: ... that meet desired criteria free Display memory usage grep Search file s for lines that match a given pattern help Display help for a built in command ifconfig Configure a network interface ifup Start a network interface up ifdown Stop a network interface kill Stop a process from running ls List information about file s mount Mount a file system top List processes running on the system ps Process ...

Page 270: ...Vigor2750 Series User s Guide 260 ...

Reviews: