background image

ZyWALL 2WE 

 38

LABEL DESCRIPTION 

My IP Address 

Enter the WAN IP address of your ZyWALL. The ZyWALL uses its current WAN IP 
address (static or dynamic) in setting up the VPN tunnel if you leave this field as 

0.0.0.0

.  

The VPN tunnel has to be rebuilt if this IP address changes. 

Local ID Type 

Select 

IP

 to identify this ZyWALL by its IP address.  

Select 

DNS

 to identify this ZyWALL by a domain name. 

Select 

E-mail

 to identify this ZyWALL by an e-mail address.  

Local Content 

When you select 

IP

 in the 

Local ID Type

 field, type the IP address of your computer or 

leave the field blank to have the ZyWALL automatically use its own IP address. 

When you select 

DNS

 in the 

Local ID Type

 field, type a domain name (up to 31 

characters) by which to identify this ZyWALL.  

When you select 

E-mail

 in the 

Local ID Type

 field, type an e-mail address (up to 31 

characters) by which to identify this ZyWALL. 

The domain name or e-mail address that you use in the 

Content

 field is used for 

identification purposes only and does not need to be a real domain name or e-mail 
address.  

Secure Gateway 
Address 

Type the WAN IP address or the URL (up to 31 characters) of the IPSec router with 
which you're making the VPN connection. Set this field to 

0.0.0.0

 if the remote IPSec 

router has a dynamic WAN IP address (the 

IPSec Keying Mode

 field must be set to

 

IKE

). 

Peer ID Type 

Select 

IP

 to identify the remote IPSec router by its IP address. 

Select 

DNS

 to identify the remote IPSec router by a domain name. 

Select 

E-mail

 to identify the remote IPSec router by an e-mail address. 

Peer Content 

When you select 

IP

 in the 

Peer ID Type

 field, type the IP address of the computer with 

which you will make the VPN connection or leave the field blank to have the ZyWALL 
automatically use the address in the 

Secure Gateway field

When you select 

DNS

 in the 

Peer ID Type

 field, type a domain name (up to 31 

characters) by which to identify the remote IPSec router.  

When you select 

E-mail

 in the 

Peer ID Type

 field, type an e-mail address (up to 31 

characters) by which to identify the remote IPSec router.  

The domain name or e-mail address that you use in the 

Content

 field is used for 

identification purposes only and does not need to be a real domain name or e-mail 
address. The domain name also does not have to match the remote router's IP address 
or what you configure in the 

Secure Gateway Addr

 field below. 

Encapsulation 
Mode 

Select 

Tunnel

 mode or 

Transport

 mode from the drop-down list box. 

Содержание ZyXEL ZyWALL 2WE

Страница 1: ...ZyWALL 2WE Internet Security Gateway Compact Guide Version 3 62 April 2004...

Страница 2: ...Configuring SUA Server 15 5 3 Wireless LAN Overview 17 5 4 Configuring Wireless 17 5 5 Configuring IEEE 802 1X Authentication 19 5 6 Local User Database and RADIUS Overview 20 5 7 Firewall Overview 20...

Страница 3: ...Customization 31 5 16 VPN Overview 32 5 17 Summary Screen 32 5 18 Configuring VPN Policies 35 5 18 1 X Auth Extended Authentication 35 5 19 Viewing SA Monitor 39 5 20 UPnP Overview 40 5 21 Configuring...

Страница 4: ...set up and have been given most of the following information Internet Account Information Your device s WAN IP Address if given __________________ DNS Server IP Address if given Primary ______________...

Страница 5: ...nnect this port if you want to configure the ZyWALL using the SMT via console port or set up a backup WAN connection see your User s Guide for details Set this switch to the CON side to use the CON AU...

Страница 6: ...The Front Panel LEDs The PWR LED turns on when you connect the power The SYS LED blinks while performing system testing and then stays on if the testing is successful The CON AUX LAN and WAN LEDs tur...

Страница 7: ...WLAN Green On Off Flashing The Wireless LAN feature is enabled The Wireless LAN link is not ready or has failed The Wireless LAN link is sending receiving packets 3 Setting Up Your Computer s IP Addre...

Страница 8: ...creen 7 Click Obtain DNS server address automatically if you do not know your DNS server IP address es If you know your DNS server IP address es click Use the following DNS server addresses and type t...

Страница 9: ...ia Web Configurator Step 1 Launch your web browser Enter 192 168 1 1 as the web site address Step 2 The default password 1234 is already in the password field in non readable format Click Login to pro...

Страница 10: ...minutes press ENTER to display the Login screen again and then log back in 4 2 Internet Access Using the Wizard Step 1 Click Wizard Setup in the main menu to display the first wizard screen Click WIZA...

Страница 11: ...m the ISP is used Click Next to continue Step 2 The second wizard screen has three variations depending on what encapsulation type you use Use the information in Internet Account Information to fill i...

Страница 12: ...er 0 to prevent the connection from timing out Click Next to continue Choose PPTP if your service provider uses a DSL terminator with PPTP login The ZyWALL must have a static IP address My IP Address...

Страница 13: ...ers WAN MAC Address Select Factory Default to use the factory assigned default MAC address Alternatively select Spoof this Computer s MAC address IP Address and enter the IP address of the computer on...

Страница 14: ...incorrect make changes and click Apply Click Reset to begin configuring this screen afresh 4 5 Common Screen Command Buttons The following table shows common command buttons found on many web configur...

Страница 15: ...maps one local IP address to one global IP address Note that port numbers do not change for One to One NAT mapping type 2 Many to One Many to One mode maps multiple local IP addresses to one global IP...

Страница 16: ...UA server entry Clear this checkbox to disallow forwarding of these ports to an inside server without having to delete the entry Name Enter a name to identify this port forwarding rule Start Port Type...

Страница 17: ...s can be as simple as two computers with wireless network interface cards NICs communicating in a peer to peer network or as complex as a number of computers with wireless NICs communicating through a...

Страница 18: ...ess LAN Wireless Hide ESSID Select this box to hide the ESSID in the outgoing beacon frame so a station cannot obtain the ESSID through passive scanning No default Channel ID Adjacent Access Points AP...

Страница 19: ...5 characters ASCII string or 10 hexadecimal characters 0 9 A F preceded by 0x for each key If you chose 128 bit WEP in the WEP Encryption field then enter 13 characters ASCII string or 26 hexadecimal...

Страница 20: ...h is a password they both know The key is not sent over the network In addition to the shared key password information exchanged is also encrypted to protect the network from unauthorized access By us...

Страница 21: ...LAN to the WAN Deny all sessions originating from the WAN to the LAN LAN to WAN rules are local network to Internet firewall rules The default is to forward all traffic from your local network to the...

Страница 22: ...LL firewall ignore the use of triangle route topology on the network See the User s Guide for more on triangle route topology Firewall Rules Storage Space in Use This read only bar shows how much of t...

Страница 23: ...this firewall rule applies Please note that a blank source or destination address is equivalent to Any Service Type This drop down list box displays the services to which this firewall rule applies P...

Страница 24: ...he new rule to be located Step 2 In the Available Services text box select the services you want Configure customized ports for services not predefined by the ZyWALL by clicking the Add or Edit button...

Страница 25: ...on Active Check the Active check box to have the ZyWALL use this rule Leave it unchecked if you do not want the ZyWALL to use the rule after you apply it Packet Direction Use the drop down list box to...

Страница 26: ...lect everyday or the day s of the week to activate blocking Time of Day to Block 24 Hour Format Select All Day or enter the start and end times in the hour minute format to activate blocking Action fo...

Страница 27: ...Enter the ending IP address in a range here Subnet Mask Enter the subnet mask here if applicable Apply Click Apply to save your customized settings and exit this screen Cancel Click Cancel to exit th...

Страница 28: ...ALL block access to URLs that contain key words that you specify 5 11 4 General Content Filter Configuration Click CONTENT FILTER to open the CONTENT FILTERING screen The General tab displays as shown...

Страница 29: ...for using external database content filtering Step 1 Enable content filtering in the Content Filtering General screen Step 2 In the Content Filtering Categories screen register for external database...

Страница 30: ...ister to go to a web site where you can register for category based content filtering using an external database You can use a trial application or register your iCard s PIN Refer to the web site s on...

Страница 31: ...ot be able to access the web site if you have enabled content filtering in the Content Filter General screen and blocked access to web pages that use Java and or cookies Do not close the Web Configura...

Страница 32: ...te to site lines A secure VPN is a combination of tunneling encryption authentication access control and auditing technologies services used to transport traffic over the Internet or any insecure netw...

Страница 33: ...ick VPN to open the Summary screen This is a read only menu of your IPSec rules tunnels Edit or create an IPSec rule by selecting an index number and then clicking Edit to configure the associated sub...

Страница 34: ...same static IP address is displayed twice when the Remote Address Type field in the Configure IKE or Manual screen is configured to Single Address The beginning and ending static IP addresses in a ran...

Страница 35: ...rule to connect to a single ZyWALL An attacker cannot make a VPN connection without a valid username and password The extended authentication server checks the user names and passwords of the extende...

Страница 36: ...ZyWALL 2WE 36...

Страница 37: ...it is generally recommended Manual is a useful option for troubleshooting Local Address The local IP address must be static and correspond to the remote IPSec router s configured remote IP addresss T...

Страница 38: ...aracters of the IPSec router with which you re making the VPN connection Set this field to 0 0 0 0 if the remote IPSec router has a dynamic WAN IP address the IPSec Keying Mode field must be set to IK...

Страница 39: ...hms for data communications both the sending device and the receiving device must use the same secret key which can be used to encrypt and decrypt the message or to generate and verify a message authe...

Страница 40: ...ve a network smoothly and automatically when it is no longer in use All UPnP enabled devices may communicate freely with each other without additional configuration Disable UPnP if this is not your in...

Страница 41: ...M CORRECTIVE ACTION None of the LEDs turn on when you turn on the ZyWALL Make sure that you have the correct power adaptor connected to the ZyWALL and plugged in to an appropriate power source Check a...

Страница 42: ...f the ISP checks the user ID click WAN and then the ISP tab Check your service type user name and password Check the ZyWALL s connection to the cable DSL device Check whether your cable DSL device req...

Отзывы: