background image

Configuration | Gateway 400

 

User Guide

35

Enable IPv6 SPI

: Use this option to enable the stateful packet inspection (SPI) firewall for IPv6 con-

nections.

Enable Firewall Logging

: Use this option for logging firewall attacks. Go to 

System

 | 

Diagnostics

 | 

System Messages

 to open the firewall log (

Chapter 5.8.12.1, System Messages, on 

page 46

).

5.7.1.2

Schedule Rule

Click 

New

 to create a new schedule. If required, you can also create multiple schedules. Any existing 

schedules are displayed in an overview. To edit a schedule, click on the pencil icon at the end of the 
overview. .

Name

Here you can enter a name for your schedule. 

Activate Time Period

: Here you can specify the desired time period. For each day of the week, you 

can specify the 

Start Time (hh:mm)

 and the 

End Time (hh:mm)

. For contiguous pe-

riods extending over several days, each intervening day must be specified as a full 
day  with the Start Time 00:00 and the End Time 23:59. 

5.7.1.3

Firewall Rules

Click 

New

 to create a new firewall rule. The existing firewall rules are displayed in an overview. To 

edit a firewall rule, 
click on the pencil icon at the end of the overview. 

.

You can define IP-based client rules and assign pre-defined services to them or create your own cri-
teria. The following fields are available for this: 

Automatically refresh provider prefix

: (only valid for IPv6) If the computers on your local network 

have IPv6 addresses, these consist of a local part and a provider prefix. This prefix is 
assigned to you and can be updated automatically by the Gateway 400.

Client PC Description

: Enter a name for the rule.

Address Type

:  Select the format of the IP address to create either an IPv4 or IPv6 address.

Client PC Address

: Enter the IP address of the network device to which the rule should be applied. 

Use the format of the previously selected 

Address Type

. For IPv4, the rule can be ap-

plied to all devices in the home network with the address 192.168.100.0.

Scheduling Rule (Ref. Schedule Rule Page)

: If you created a schedule under 

“Schedule Rule” on 

page 35

, you can select it here.

Status

Here you can select whether the rule is enabled or disabled.



Client PC Service

Select the respective service name option (

WWW

Sending email

SMTP

News Forums

Receiving 

email

SecureHTTP

File Transfer

Telnet Service

NetMeeting

DNS

SNMP

VPN PPTP

VPN L2TP

TCP

UDP

) to specify which services are to be blocked.

If you block 

User-defined Services

, the following section is enabled, in which you can individually 

configure the 

TCP

 or 

UDP

 protocol and the 

Port Range

5.7.1.4

IP Stack Settings

The device can detect and block conventional hacker attacks (such as IP Spoofing, Land Attack, Ping 
of Death, IP with zero length, Smurf Attack, UDP port loopback, Snork Attack, TCP null scan and TCP 
SYN flooding).

Attention

If you select 

Enable IPv6 SPI

, all devices in your local network are directly accessible from 

the Internet. Use this option only if you are familiar with the possible consequences! 

Содержание 400

Страница 1: ...User Guide Gateway 400 ...

Страница 2: ......

Страница 3: ... PPPoE DHCP SIPconnect 1 1 interoperability Brief Description Voice over IP is increasingly replacing analog and ISDN based transmission technology This creates the need to integrate existing ISDN private branch exchanges PBX in the new IP environment and to also provide the ISDN service in an all IP network The ISDN SIP Gateway 400 provides 4 S0 interfaces on the subscriber side in its basic conf...

Страница 4: ...nd tips Notational Conventions Example Bold font is used denote fields and titles of screen dialogs connec tions at the Gateway 400 as well as LEDs and buttons Save Cancel Setup Assistant LAN3 WPS Paths folder names and file names C Program Files Downloads config bin Blue font is used to indicate addresses to be entered in the browser as well as links and references within this manual http sphairo...

Страница 5: ... Gateway 400 to the Factory Default Settings 15 3 Installation 16 3 1 Installation diagram for S0 bus 18 4 Setup 20 4 1 Computer Settings 20 4 2 Carrier Detection 20 5 Configuration 21 5 1 Screen Dialog Layout 21 5 2 Overview 22 5 3 DSL 23 5 3 1 Monitoring Index 23 5 3 2 Spectrum 23 5 4 Internet 23 5 4 1 Access Setup 23 5 4 1 1 Internet Access 23 5 4 2 Dynamic DNS 24 5 4 3 DNS Relay 25 5 4 4 Stati...

Страница 6: ...on 42 5 8 3 System Time 42 5 8 4 Languages 42 5 8 5 Save Configuration 42 5 8 6 Reset Device 43 5 8 7 Firmware Update 44 5 8 8 Remote Management 44 5 8 9 SSH 44 5 8 10 CWMP 45 5 8 10 1ACS Configuration 45 5 8 10 2Client Configuration 45 5 8 11 SNMP 45 5 8 12 Diagnostics 46 5 8 12 1System Messages 46 5 8 12 2Packet Tracer 46 5 8 12 3LED Test 46 5 8 13 QoS 46 5 8 13 1Settings 46 5 8 13 2Class Creati...

Страница 7: ...7 11 Index 65 ...

Страница 8: ...8 ...

Страница 9: ...nd making phone calls you need an ADSL VDSL2 connection unlocked by your ISP To connect the Gateway 400 to the network device e g switch computer NAS server the net work device must be equipped with an Ethernet port no less than 10 100 Mbps 1 Gbps for op timum speed For the configuration you need a computer with a current web browser 1 2 Package Contents 1 Gateway 400 1 power cord 1 DSL cable RJ45...

Страница 10: ...nt of a mixup the devices will not operate as intended The device is designed for use as a desktop unit However it can also be mounted in a rack Please refer to the installation instructions USB devices must only be connected with cables of no more than 3 meters approx 9 feet Cables to SELV interfaces must not exit the building Clock lines should only be connected at the remote end as described in...

Страница 11: ...r operating system e g by pressing the Windows key and the F1 function key A screen dialog appears Enter TCP IP settings in the Search field 1 4 2 Fixed IP Address If you want to assign static IP addresses even though the DHCP server is enabled you should use IP addresses from the following ranges For network devices connected to the LAN 1 socket 192 168 100 2 through 192 168 100 49 192 168 100 81...

Страница 12: ... flashing Software is being updated SIP green on off SIP account is successfully registered not registered flashing slowly SIP account is being registered flashing quickly 4 Hz Active ongoing call red flashing At least one SIP account registration has failed BCK Currently without function RJ45 sockets or clamps for connect ing a telephone system or ISDN telephones RJ45 sockets for network devices ...

Страница 13: ...n off 100 MB network connection is active No network device connected flashing Data traffic via the WAN LAN interface yellow on off 1 GB network connection is active No network device connected LAN 1 2 green on off 100 MB network connection is active No network device connected flashing Data traffic on the LAN interface yellow on off 1 GB network connection is active No network device connected S0...

Страница 14: ...15 5 s 15 s Restore factory defaults see Resetting the Gateway 400 to the Factory Default Settings on page 15 15 s Additional reset actions only if requested by customer support Meaning of the LEDs Name Color Status Meaning Master green on Gateway 400 is in the master mode Slave yellow on Gateway 400 is in the slave mode Note To avoid damaging the device press the reset switch lightly i e without ...

Страница 15: ... seconds until the Power LED turns red and flashes 2 Then release the reset switch The Power LED lights up red for about 30 seconds It then turns green again After about 2 minutes the Gateway 400 will be operational again 3 As described in Chapter 4 Setup on page 20 you must now set up and reconfigure the Gate way 400 or load the previously saved configuration Chapter 5 8 5 Save Configuration on p...

Страница 16: ... into the LAN socket on the modem and the other RJ45 connector into the ETH socket on the Gateway 400 Step 3 Network device connection Take the yellow cable network cable and plug the RJ45 connector of the yellow cable into the LAN 1 or LAN 2 socket on the Gateway 400 Plug the other RJ45 connector into the corresponding socket on the network device to be connected Wait until the LAN LED begins to ...

Страница 17: ...tions Connect your telephone system or telephones to the sockets S01 to S04 or the clamps 1 to 4 a1b a2b See Installation diagram for S0 bus on page 18 Figure 1 Installation diagram for a point to point connection Note The ISDN interfaces of the Gateway 400 support the Restricted Power Mode This may reduce the functionality of ISDN telephones e g no permanent display or cause some telephones to no...

Страница 18: ... Figure 3 Installation diagram for S0 bus Note In the Gateway 400 the terminating resistors are already integrated PABX GATEWAY 400 Option 1 Option 2 ISDN Phones 1 2 3 4 5 6 7 8 RJ45 connector cable side Pin 3 RX 2a Pin 4 TX 1a Pin 5 TX 1b Pin 6 RX 2b 1a 1b 2a 2b IAE socket 1a 1b 2a 2b IAE socket a1b a2b resistors 100Ω 100Ω Gateway 400 S0 bus Terminating 1a 1b 2a 2b IAE socket ...

Страница 19: ... bus Distance between terminal device and Gateway 400 max 1000 meters Only one terminal device can be connected point to point connection Used in point to point or point to multipoint mode in special cases with only one terminal default This setting is also used for the extended passive bus The extended pas sive bus is at least 100 meters and no more than 500 meters long The ter minal devices may ...

Страница 20: ...ource Carrier detection can also be started manually In this case you can use any computer with a current web browser 1 Connect the computer to the LAN 1 socket on the Gateway 400 2 Start your web browser and enter http sphairon box in the address line You can also enter http 192 168 100 1 for a network connection via the LAN 1 socket or http 192 168 200 1 for a network connection via the LAN 2 so...

Страница 21: ...ich allow you to change the Gateway 400 settings The menu items are grouped by function and may be subdivided into submenus Chapter 5 Configuration on page 21 de scribes each menu item of the Gateway 400 in detail Screen Dialog with Settings Clicking on a menu item opens the corresponding screen dialog Each screen offers various dia log boxes with settings for configuring the Gateway 400 Clicking ...

Страница 22: ...0 CONNECTION Status of the DSL or WANoE line INTERNET Status of the Internet connection NETWORK Status of the LAN connections USB Connected USB network devices SECURITY Enabled security settings TELEPHONY Configured telephony settings SYSTEM Hardware and firmware version numbers Security Log Logging of logins configuration changes etc The icon indicates that a specific setting has not been configu...

Страница 23: ...figuration it can also be adapted manually at any time see Protocol Stack on page 39 Access data For the Access data overview item you will need to specify the access ID provided by your ISP Under Provider you can choose between several pre configured Internet providers If your own pro vider is not listed select Other provider Specify your access data Access name and Password for the Internet Re e...

Страница 24: ...r or router is configured to use another ISP for Internet access Daily Auto Disconnect Daily Auto Disconnect disconnects the Gateway 400 from the Internet daily ata specified time This setting preempts the forced disconnect initiated by the ISP after 24 hour Internet connections and thus prevents unnecessary interruptions of ongoing calls Forced disconnects are technically re quired in order to re...

Страница 25: ...uerying the DNS again Activate User Defined DNS Server This setting is only required if you do not want to use the default settings of your Internet service provider If required enter the IP address of the DNS server The DNS Server 1 and DNS Server 2 replace the Primary DNS and the Secondary DNS from the Internet settings respectively 5 4 4 Static Routing Here you can enter static routes for netwo...

Страница 26: ...78 which tries to accelerate connection setup by attempting to dial partially entered incomplete numbers while digits are being entered If the option Overlap Dialing is enabled the additional option Enable fallback to normal dialing will be available This option can be used to temporarily enable en bloc dialing if the connection setup fails using overlap dialing Configuration of incoming VoIP call...

Страница 27: ...y Enter the data provided by your VoIP provider e g sipgate de port 5060 RTP port range Enter the data provided by your VoIP provider e g 10000 19000 T 38 Support Only required for fax If the VoIP providersupports T 38 for transmission of fax data you can select this option DTMF Mode Select one of the following options from the drop down list Inband DTMF dial tones are audibly transmitted together...

Страница 28: ... you enter the DID number for the intercept position central attendant e g 0 Activate Select this check box if you want to use this call number Use Registrar Select this check box if you want to use the registrar server of the VoIP provider Some VoIP providers do not require a registrar in such cases this function must be disabled Enter the required VoIP account data and click Save Registering the...

Страница 29: ...us An extended pas sive bus is used if the point to multipoint connection covers a distance of more than 200meters At distances of more than 500 meters no more than one terminal device may be connected See Installation diagram for S0 bus on page 18 Interface In this drop down list you can select the ISDN interface of the Gateway 400 Group membership The group membership enables multiple ISDN lines...

Страница 30: ...nge of values from 0 to 255 IP addresses are divided into two parts a network part and a host part Computers can only communicate directly with each other if the network partof their IP address is the same In the same network no host address may be assigned twice The division into network part and ad dress part is determined by the subnet mask e g 255 255 255 0 In CIDR notation this is written as ...

Страница 31: ...e DHCP Server active IP Address 192 168 200 1 Subnet Mask 255 255 255 0 Host Name sphairon box DHCP Server activated DHCP Gateway 192 168 200 1 IP Start Address 192 168 200 50 IP End Address 192 168 200 80 Allocation period 2 weeks Domain Name localdomain Note With these factory network settings all computers connected to the Gateway 400 are part of the same subnet only if they are connected via t...

Страница 32: ... LAN has been configured the Pro vider prefix supplied by your ISP will be automatically distributed in your network If you do not want the Provider prefix to be distributed in the local network you must ensure that the option Router Advertisements is disabled 5 6 1 2 Static Routing Here you can enter static routes for networks which can be accessed via the LAN interfaces Con nections to the WAN i...

Страница 33: ...vailable in your network 5 6 2 2 FTP Server Here you can share your USB device on the network via an FTP server In this way the files that are located on the attached USB mass storage device will be accessible on your local network or the In ternet First setup individual user profiles and select the directories and folders whose contents you want to share For each user profile you can set differen...

Страница 34: ...st be activated separately before they can be used 5 7 Security This screen dialog shows status information for the current security settings The security settings can be edited via the following menu items 5 7 1 Firewall 5 7 1 1 Settings Firewall The Gateway 400 features a built inFirewall to protect yourhome network and your Internetaccess against unauthorized use This firewall offers a comprehe...

Страница 35: ...network have IPv6 addresses these consist of a local part and a provider prefix This prefix is assigned to you and can be updated automatically by the Gateway 400 Client PC Description Enter a name for the rule Address Type Select the format of the IP address to create either an IPv4 or IPv6 address Client PC Address Enter the IP address of the network device to which the rule should be applied Us...

Страница 36: ...lic IP address of the Gateway 400 This is required for example if the network device has a private IP and you want to communicate with servers on the Internet This feature is only available for IPv4 connections ICMPv4 Enable ICMPv4 Filter ICMP is used to exchange error and information messages Since this feature can also be used for malicious attacks in the network you are given the option to acti...

Страница 37: ... rule applies to all connected network devices Verify that the IP address entered here is specified as a static IP address at the ap propriate computer Protocol Select the transmission protocol from the Protocol drop down menu With the TCP protocol requests are constantly sent during data transmission to ensure that the transmitted data information has been received successfully Information that i...

Страница 38: ... the Copy button If the specified port range differs from the required port range you can change it For information on the TCP and UDP transmission protocols refer to the previous chapter 5 7 3 IPSec IPsec Internet Protocol Security enables secure communication over potentially insecure IP net works such as the Internet for example Data packets that are forwarded from one computer to an otheronthe...

Страница 39: ... the device and a firewall configuration also be created If changes are made to the protocol stack editor then any previously made settings at the fire wall will be disabled In addition it should be checked whether any configured services of the device are affected by the changes Physical In this column you specify the physical interface Select DSL WANoE UMTS or LAN from the drop down menu More in...

Страница 40: ...hether ADSL or VDSL is involved In addition you will need to specify which an nex is to be used Click Save Layer 2 Settings Configure Layer 2 depending on the data transmission method selected under Physical Layer 2 is the second layer data link layer of the OSI layer model There is where the physical addressing with error control error correction and data flow control occurs Select the required L...

Страница 41: ... can be obtained from Internet service pro vider Bridge Configuration No configuration is required here Layer 2 configuration for the Physical setting WANoE For the physical interface WANoE you can define whether the specified port is to be used as a VLAN or a bridge To edit the settings click on the pencil icon IP Settings Set the parameters for PPPoE and StaticIP PPPoE This sets up a point to po...

Страница 42: ...te automatic time synchronization If you want to set the Date and Time manually clear the check mark You can then edit the values in the other fields Update interval Select the desired value from the drop down list NTP interface Select the interface over which the connection to the time server can be made from the drop down list Time Server ConfigurationDefault de pool ntp org You can enter two ti...

Страница 43: ...he factory settings click the Reset button The message Resetting your device to the facto ry default state appears while the device is being reset After the reset has completed the Login screen dialog is displayed Enter the factory set login credentials Access name admin and Pass word admin You will now need to set up the Chapter 4 Setup on page 20Chapter 5 Configuration on page 21 again as descri...

Страница 44: ...ay 400 is configured as a bridge you must enable the WAN side ac cess for remote management This re quires the protocol stack to be configured To do this navigate to this screen dialog via the menu item Internet Access Setup Protocol Stack b Click on the pencil icon for Bridge X c In the new screen dialog click on the pencil icon for ATM X YZ d In the new screen dialog select the Allow Local Acces...

Страница 45: ...Dynamic CNR Port specify the whitelisted and blacklisted CNR ports 5 8 11 SNMP The SNMP Network Management Protocol allows you to monitor and control the individual net work components from a central management station The network components are referred to as the Agents and the management station is referred to as the Manager To communicate with each other the Agents and the Manager must be locat...

Страница 46: ...s The On Off mode with the options Off and On The Flash mode with the options 2 Hz flashing slowly and 4 Hz flashing fast The Timer mode is currently not supported After selecting the desired options from the drop down menus click Execute 5 8 13 QoS The Quality of Service QoS indicates the quality of a communication service Here you can activate the QoS settings for your device QoS must be enabled...

Страница 47: ...ore to allow this value to be exceeded if needed Click Activate to enable the selected DSCP class Click Save to save your settings and return to the QoS Overview For the configured DSCP classes to take effect select the option Enable QoS and click Save 5 8 13 3 Rule Creation In this screen you can define classification rules to group outbound data packets into DSCP classes Click New to create a ne...

Страница 48: ...rk devices such as network printers etc The network activity of the connected devices is indicated via the LAN1 and LAN2 LED displays on the Gateway 400 Please note that separate networks are involved Question 3 I cannot access the user interface of the Gateway 400 Please check if the connection between your computer and the Gateway 400 is OK One of the LAN LEDs LAN1 or LAN2 or the WLAN LED should...

Страница 49: ... the new screen dialog double click the icon LAN Connection and then click on the Properties button This opens the Local Area Connection Properties screen dialog Select Internet Protocol Version 4 TCP IPv4 Click on the Properties button This opens the screen dialog Properties of Internet Protocol Ver sion 4 TCP IPv4 Select the option Use the following IP address Then enter the following IP address...

Страница 50: ...ions of the GPL as needed to protect the freedom of users Finally every program is threatened constantly by software patents States should not allow patents to restrict development and use of software on general purpose computers but in those that do we wish to avoid the special danger that patents applied to a free program could make it effectively proprietary To prevent this the GPL assures that...

Страница 51: ...o charge c Convey individual copies of the object code with a copy of the written offer to provide the Corresponding Source This alternative is allowed only occasionally and noncommercially and only if you received the object code with such an offer in accord with subsection 6b d Convey the object code by offering access from a designated place gratis or for a charge and offer equivalent access to...

Страница 52: ...nd propagate the contents of its contribu tor version In the following three paragraphs a patent license is any express agreement or commitment however denominated not to enforce a patent such as an express permission to practice a patent or covenant not to sue for patent infringement To grant such a patent license to a party means to make such an agreement or com mitment not to enforce a patent a...

Страница 53: ...y one can redistribute and change under these terms To do so attach the following notices to the program It is safest to attach them to the start of each source file to most effectively state the exclusion of warranty and each file should have at least the copyright line and a pointer to where the full notice is found one line to give the program s name and a brief idea of what it does Copyright C...

Страница 54: ...Gateway 400 User Guide Legal Notices 54 ...

Страница 55: ... RFC 3261 V2 0 Manage up to 10 Internet SIP accounts Up to 8 simultaneous connections provider dependent Support for service features CLIP CLIR CFx CW CH 3PTY 64k Clear Channel Voice Activity Detection Comfort Noise Generation Echo compensation G 168 compatible DTMF In band Out band SIP Info Codec and voice compression G 711 a law μ law G 726 G 729 T 38 Support Adaptive fixed jitter buffer max 180...

Страница 56: ...ondary IP NAT DNS Integrated SPI Firewall PAP CHAP Authentication SSH SSL client for management support QoS Voice priority IEEE 802 1p IEEE 802 1Q 4096 VLANs tag insertion deletion General Data Dimensions H x W x D 45 x 245 x 165 mm Integrated power supply Nominal voltage 230 V AC Power consumption 200 mA maximum Nominal frequency 50 Hz ...

Страница 57: ... protection Factory default credentials Access name admin Password admin Page 20 and Page 42 Access Protection Access Name Password Note Note My Internet access credentials Page 23 Internet Access User name Password Note My password s for USB devices Read only Page 33 FTP Server Note My password s for USB devices Full Access Page 33 FTP Server Attention Please protect this information carefully ag...

Страница 58: ...Gateway 400 User Guide Passwords 58 Note More Notes ...

Страница 59: ...Web browsers typically support not only the display of HTML pages but also other services on the Internet such as file transfers using FTP chat e mail or news groups C Connected USB mass storage To make a mass storage device connected to the USB port available on your computer set up a network drive in Windows Explorer under Tools Enter the IP address ofthe Gateway 400followed by an ftp e g 192 16...

Страница 60: ...ve to remember the numerical code For example when you enter the do main name www zyxel com with the http protocol and the Internet service an IP address is actually accessed via the DNS DSL Digital Subscriber Line In 1998 the German Telekom introduced new access technology in telephone networks under the term T DSL The so called xDSL techniques use conventional copper lines as a broadband medium ...

Страница 61: ...the TCP IP protocol each computer is identified by a unique numeric address Each IP address can occur once i e must be unique within a network The Gateway 400 allows you to use network addresses in one of two possible formats the proven 32 bit legacy format Internet Protocol Version 4 IPv4 or the new 128 bit format Internet Protocol Version 6 IPv6 Further details can be found in the section LAN on...

Страница 62: ...an inactive connection Online Online identifies an active connection P Password protection configuration You can change the password for the user interface of the Gateway 400 in the System Password menu Make sure that you always do this after you first connect the Gateway 400 in order to prevent unauthorized access to the Gateway 400 If you have forgotten your password you can revert to the fac to...

Страница 63: ... SELV interfaces are connected with one another SELV devices are not protect ed against voltage spikes which can lead to technical defects or hazards for users In the event of a mixup the devices will notoperate as intended Cables to SELV interfaces must not exit the building SIP The Session Initiation Protocol SIP is a network protocol for setting up con trolling and terminating a VoIP connection...

Страница 64: ...detected automatically User Guide This User Guide provides you with detailed information The latest edition of this User Guide can be found on the Internet at www zyxel com in the Service Area V VoIP Voice over Internet Protocol With Internet telephony VoIP the information required for telephony i e to control the connection setup and voice can be transmitted over a network that is also used for d...

Страница 65: ...lossary 59 GNU 50 I indicators 12 installation 16 Internet access setup 23 IP Protocol Stack 41 IP address 31 L LAN settings 30 network settings 11 language 42 layer 2 protocol stack 40 Legal Notices 50 License Terms and Conditions 50 login data Gateway 400 42 M monitoring index 23 N network settings 31 P package contents 9 password set modify delete 42 Physical Protocol Stack 40 ping test 46 port...

Страница 66: ...y 400 User Guide Index 66 system messages 46 system time 42 T technical data 55 telephony set up 26 trigger ports 38 U USB 33 User Administration 42 V VoIP accounts 27 VoIP provider 27 Z zone configuration 36 ...

Страница 67: ......

Страница 68: ... ZyXEL Communications Corp www zyxel com Subject to errors and technical alterations Gateway 400 Edition 1 2 07 14 ...

Отзывы: