ZyXEL Communications USG-50 - V2.21 ED 1 User's Guide

Browse online or download User's Guide for Gateways/controllers ZyXEL Communications USG-50 - V2.21 ED 1. ZyXEL Communications USG-50 - V2.21 ED 1 User`s guide User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 390
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 1 - USG ZyWALL Series

www.zyxel.comUSG ZyWALL SeriesCLI Reference GuideVersion 3.002/2012Edition 2DEFAULT LOGINUser Name adminPassword 1234

Page 2

Table of ContentsZyWALL (ZLD) CLI Reference Guide101.9 Saving Configuration Changes ...

Page 3 - How To Use This Guide

Chapter 7 TrunksZyWALL (ZLD) CLI Reference Guide100The following example creates a spill-over trunk for Ethernet interfaces ge1 and ge3, which will ap

Page 4 - Document Conventions

Chapter 7 TrunksZyWALL (ZLD) CLI Reference Guide1014 File server C finds that the request comes from WAN2’s IP address instead of WAN1’s IP address a

Page 5 - Document Conventions

Chapter 7 TrunksZyWALL (ZLD) CLI Reference Guide102

Page 6

ZyWALL (ZLD) CLI Reference Guide 103CHAPTER 8RouteThis chapter shows you how to configure policies for IP routing and static routes on your ZyWALL.8

Page 7 - Contents Overview

Chapter 8 RouteZyWALL (ZLD) CLI Reference Guide104The following table describes the commands available for policy route. You must use the configure te

Page 8

Chapter 8 RouteZyWALL (ZLD) CLI Reference Guide105[no] dscp {any | <0..63>} Sets a custom DSCP code point (0~63). This is the DSCP value of inc

Page 9

Chapter 8 RouteZyWALL (ZLD) CLI Reference Guide106[no] tunnel tunnel_name Sets the incoming interface to an IPSec VPN tunnel. The no command removes t

Page 10 - Table of Contents

Chapter 8 RouteZyWALL (ZLD) CLI Reference Guide107[no] source {address6_object|any} Sets the source IPv6 IP address that the matched packets must hav

Page 11 - Table of Contents

Chapter 8 RouteZyWALL (ZLD) CLI Reference Guide1088.2.1 Assured Forwarding (AF) PHB for DiffServAssured Forwarding (AF) behavior is defined in RFC 25

Page 12

Chapter 8 RouteZyWALL (ZLD) CLI Reference Guide1098.3 IP Static RouteThe ZyWALL has no knowledge of the networks beyond the network that is directly

Page 13

Table of ContentsZyWALL (ZLD) CLI Reference Guide116.4.1 Virtual Interface Command Examples ...

Page 14

Chapter 8 RouteZyWALL (ZLD) CLI Reference Guide1108.4.1 Static Route Commands ExamplesThe following command sets a static route with IP address 10.10

Page 15

ZyWALL (ZLD) CLI Reference Guide 111CHAPTER 9Routing ProtocolThis chapter describes how to set up RIP and OSPF routing protocols for the ZyWALL.9.1

Page 16

Chapter 9 Routing ProtocolZyWALL (ZLD) CLI Reference Guide1129.2.1 RIP CommandsThis table lists the commands for RIP.9.2.2 General OSPF CommandsThis

Page 17

Chapter 9 Routing ProtocolZyWALL (ZLD) CLI Reference Guide1139.2.3 OSPF Area CommandsThis table lists the commands for OSPF areas.9.2.4 Virtual Lin

Page 18 - Chapter 38

Chapter 9 Routing ProtocolZyWALL (ZLD) CLI Reference Guide1149.2.5 Learned Routing Information CommandsThis table lists the commands to look at learn

Page 19

ZyWALL (ZLD) CLI Reference Guide 115CHAPTER 10ZonesSet up zones to configure network security and network policies in the ZyWALL. 10.1 Zones Overvi

Page 20

Chapter 10 ZonesZyWALL (ZLD) CLI Reference Guide11610.2 Zone Commands SummaryThe following table describes the values required for many zone commands

Page 21 - Introduction

Chapter 10 ZonesZyWALL (ZLD) CLI Reference Guide11710.2.1 Zone Command ExamplesThe following commands add Ethernet interfaces ge1 and ge2 to zone A

Page 22

Chapter 10 ZonesZyWALL (ZLD) CLI Reference Guide118

Page 23 - CHAPTER 1

ZyWALL (ZLD) CLI Reference Guide 119CHAPTER 11DDNSThis chapter describes how to configure dynamic DNS (DDNS) services for the ZyWALL.11.1 DDNS Over

Page 24 - 1.2.1 Console Port

Table of ContentsZyWALL (ZLD) CLI Reference Guide129.1 Routing Protocol Overview ...

Page 25

Chapter 11 DDNSZyWALL (ZLD) CLI Reference Guide12011.2 DDNS Commands SummaryThe following table describes the values required for many DDNS commands.

Page 26 - Router(config)#

Chapter 11 DDNSZyWALL (ZLD) CLI Reference Guide121[no] backup-iface interface_name Sets the backup WAN interface in the specified DDNS profile. The n

Page 27 - 1.2.4 SSH (Secure SHell)

Chapter 11 DDNSZyWALL (ZLD) CLI Reference Guide122

Page 28

ZyWALL (ZLD) CLI Reference Guide 123CHAPTER 12Virtual ServersThis chapter describes how to set up, manage, and remove virtual servers. Virtual serve

Page 29 - 1.5 CLI Modes

Chapter 12 Virtual ServersZyWALL (ZLD) CLI Reference Guide124The following table lists the virtual server commands.Table 60 ip virtual-server Comman

Page 30 - 1.6 Shortcuts and Help

Chapter 12 Virtual ServersZyWALL (ZLD) CLI Reference Guide12512.2.1 Virtual Server Command ExamplesThe following command creates virtual server WAN-

Page 31

Chapter 12 Virtual ServersZyWALL (ZLD) CLI Reference Guide12612.2.2 Tutorial - How to Allow Public Access to a ServerThis is an example of making an

Page 32 - 1.7 Input Values

ZyWALL (ZLD) CLI Reference Guide 127CHAPTER 13HTTP RedirectThis chapter shows you how to configure HTTP redirection on your ZyWALL.13.1 HTTP Redire

Page 33 - TAG # VALUES LEGAL VALUES

Chapter 13 HTTP RedirectZyWALL (ZLD) CLI Reference Guide12813.2 HTTP Redirect CommandsThe following table identifies the values required for many of

Page 34

Chapter 13 HTTP RedirectZyWALL (ZLD) CLI Reference Guide12913.2.1 HTTP Redirect Command ExamplesThe following commands create a HTTP redirect rule,

Page 35 - 1.8 Ethernet Interfaces

Table of ContentsZyWALL (ZLD) CLI Reference Guide1315.1 IP/MAC Binding Overview ...

Page 36 - 1.10 Logging Out

Chapter 13 HTTP RedirectZyWALL (ZLD) CLI Reference Guide130

Page 37 - CHAPTER 2

ZyWALL (ZLD) CLI Reference Guide 131CHAPTER 14ALGThis chapter covers how to use the ZyWALL’s ALG feature to allow certain applications to pass throu

Page 38 - 2.1.1 Debug Commands

Chapter 14 ALGZyWALL (ZLD) CLI Reference Guide13214.2 ALG Commands The following table lists the alg commands. You must use the configure terminal co

Page 39

Chapter 14 ALGZyWALL (ZLD) CLI Reference Guide13314.3 ALG Commands ExampleThe following example turns on pass through for SIP and turns it off for H

Page 40

Chapter 14 ALGZyWALL (ZLD) CLI Reference Guide134

Page 41 - Reference

ZyWALL (ZLD) CLI Reference Guide 135CHAPTER 15IP/MAC Binding15.1 IP/MAC Binding OverviewIP address to MAC address binding helps ensure that only th

Page 42

Chapter 15 IP/MAC BindingZyWALL (ZLD) CLI Reference Guide13615.3 IP/MAC Binding Commands ExampleThe following example enables IP/MAC binding on the L

Page 43 - CHAPTER 3

ZyWALL (ZLD) CLI Reference Guide 137CHAPTER 16FirewallThis chapter introduces the ZyWALL’s firewall and shows you how to configure your ZyWALL’s fir

Page 44

Chapter 16 FirewallZyWALL (ZLD) CLI Reference Guide13816.2 Firewall CommandsThe following table identifies the values required for many of these comm

Page 45 - CHAPTER 4

Chapter 16 FirewallZyWALL (ZLD) CLI Reference Guide139firewall zone_object {zone_object|ZyWALL} delete <1..5000>Removes a direction specific th

Page 46 - Chapter 4 Status

Table of ContentsZyWALL (ZLD) CLI Reference Guide1419.5.3 Configuring the L2TP VPN Settings Example ...

Page 47 - Chapter 4 Status

Chapter 16 FirewallZyWALL (ZLD) CLI Reference Guide140firewall6 zone_object {zone_object|ZyWALL} append Enters the IPv6 firewall sub-command mode to a

Page 48

Chapter 16 FirewallZyWALL (ZLD) CLI Reference Guide14116.2.1 Firewall Sub-CommandsThe following table describes the sub-commands for several firewal

Page 49 - CHAPTER 5

Chapter 16 FirewallZyWALL (ZLD) CLI Reference Guide14216.2.2 Firewall Command ExamplesThese are IPv4 firewall configuration examples. The IPv6 firewa

Page 50 - 5.2 Registration Commands

Chapter 16 FirewallZyWALL (ZLD) CLI Reference Guide143The following command displays the default IPv6 firewall rule that applies to the WAN to ZyWALL

Page 51 - 5.2.1 Command Examples

Chapter 16 FirewallZyWALL (ZLD) CLI Reference Guide144session-limit append Enters the session-limit sub-command mode to add a session-limit rule to th

Page 52 - 5.3 Country Code

ZyWALL (ZLD) CLI Reference Guide 145CHAPTER 17IPSec VPNThis chapter explains how to set up and maintain IPSec VPNs in the ZyWALL. 17.1 IPSec VPN Ov

Page 53

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide146which the ZyWALL and remote IPSec router can send data between computers on the local network a

Page 54

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide147The following sections list the IPSec VPN commands.17.2.1 IKE SA CommandsThis table lists the

Page 55

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide14817.2.2 IPSec SA Commands (except Manual Keys)This table lists the commands for IPSec SAs, excl

Page 56 - Chapter 5 Registration

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide149crypto map rename map_name map_name Renames the specified IPSec SA (first map_name) to the spe

Page 57 - CHAPTER 6

Table of ContentsZyWALL (ZLD) CLI Reference Guide1522.6 IDP Statistics ...

Page 58

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide150[no] nail-up Automatically re-negotiates the SA as needed. The no command does not.[no] replay-

Page 59

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide15117.2.3 IPSec SA Commands (for Manual Keys)This table lists the additional commands for IPSec

Page 60

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide15217.2.5 VPN Configuration Provisioning CommandsThis table lists the commands for VPN configurat

Page 61

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide15317.2.6 SA Monitor CommandsThis table lists the commands for the SA monitor.Table 76 sa Comm

Page 62 - Chapter 6 Interfaces

Chapter 17 IPSec VPNZyWALL (ZLD) CLI Reference Guide154

Page 63 - Chapter 6 Interfaces

ZyWALL (ZLD) CLI Reference Guide 155CHAPTER 18SSL VPNThis chapter shows you how to set up secure SSL VPN access for remote user login.18.1 SSL Acce

Page 64

Chapter 18 SSL VPNZyWALL (ZLD) CLI Reference Guide156The following sections list the SSL VPN commands.18.2.1 SSL VPN CommandsThis table lists the com

Page 65

Chapter 18 SSL VPNZyWALL (ZLD) CLI Reference Guide15718.2.2 Setting an SSL VPN Rule TutorialHere is an example SSL VPN configuration. The SSL VPN ru

Page 66

Chapter 18 SSL VPNZyWALL (ZLD) CLI Reference Guide1581 First of all, configure 10.1.1.254/24 for the IP address of interface ge2 which is an external

Page 67 - 6.2.2 DHCP Setting Commands

Chapter 18 SSL VPNZyWALL (ZLD) CLI Reference Guide1596 Displays the SSL VPN rule settings.Router(config)# show sslvpn policy SSL_VPN_TESTindex: 1 ac

Page 68

Table of ContentsZyWALL (ZLD) CLI Reference Guide16Chapter 26User/Group...

Page 69

Chapter 18 SSL VPNZyWALL (ZLD) CLI Reference Guide160

Page 70

ZyWALL (ZLD) CLI Reference Guide 161CHAPTER 19L2TP VPNThis chapter explains how to set up and maintain L2TP VPNs in the ZyWALL. 19.1 L2TP VPN Overv

Page 71

Chapter 19 L2TP VPNZyWALL (ZLD) CLI Reference Guide16219.2.1 Using the Default L2TP VPN ConnectionDefault_L2TP_VPN_Connection is pre-configured to be

Page 72 - 6.2.5 OSPF Commands

Chapter 19 L2TP VPNZyWALL (ZLD) CLI Reference Guide16319.4 L2TP VPN CommandsThe following table describes the values required for some L2TP VPN comm

Page 73

Chapter 19 L2TP VPNZyWALL (ZLD) CLI Reference Guide16419.5 L2TP VPN ExampleThis example uses the following settings in creating a basic L2TP VPN tunn

Page 74

Chapter 19 L2TP VPNZyWALL (ZLD) CLI Reference Guide165• You configure an IP address pool object named L2TP_POOL to assign the remote users IP address

Page 75

Chapter 19 L2TP VPNZyWALL (ZLD) CLI Reference Guide166• Enable the connection. 19.5.4 Configuring the Policy Route for L2TP ExampleThe following co

Page 76 - 6.3.2 Port Grouping Commands

ZyWALL (ZLD) CLI Reference Guide 167CHAPTER 20Application PatrolThis chapter describes how to set up application patrol for the ZyWALL. 20.1 Applic

Page 77

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide168The following sections list the application patrol commands.20.2.1 Pre-defined Applic

Page 78

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide16920.2.2.1 Rule Sub-commandsThe following table describes the sub-commands for several

Page 79

Table of ContentsZyWALL (ZLD) CLI Reference Guide17Chapter 31Authentication Objects...

Page 80

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide17020.2.3 Exception Commands for Pre-defined ApplicationsThis table lists the commands f

Page 81

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide17120.2.4 Other Application CommandsThis table lists the commands for other application

Page 82 - 6.6.1 Cellular Status

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide17220.2.5.1 Other Rule Sub-commandsThe following table describes the sub-commands for se

Page 83 - STATUS DESCRIPTION

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide173This table lists the general commands for application patrol.Table 90 app Commands:

Page 84

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide17420.2.6.1 General Command ExamplesThe following examples show the information that is

Page 85

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide175Router# configure terminalRouter(config)# show app other configbandwidth-graph: yesRo

Page 86

Chapter 20 Application PatrolZyWALL (ZLD) CLI Reference Guide176

Page 87 - 6.9 WLAN Specific Commands

ZyWALL (ZLD) CLI Reference Guide 177CHAPTER 21Anti-VirusThis chapter introduces and shows you how to configure the anti-virus scanner. 21.1 Anti-Vi

Page 88 - 6.9.1 WLAN General Commands

Chapter 21 Anti-VirusZyWALL (ZLD) CLI Reference Guide17821.2.1 General Anti-virus CommandsThe following table describes general anti-virus commands.

Page 89

Chapter 21 Anti-VirusZyWALL (ZLD) CLI Reference Guide179anti-virus rule <1..32> Enters the anti-virus sub-command mode to edit the specified di

Page 90

Table of ContentsZyWALL (ZLD) CLI Reference Guide1837.1 System Overview ...

Page 91

Chapter 21 Anti-VirusZyWALL (ZLD) CLI Reference Guide18021.2.2.1 Zone to Zone Anti-virus Rule ExampleThis example shows how to configure (and display

Page 92

Chapter 21 Anti-VirusZyWALL (ZLD) CLI Reference Guide18121.2.3.1 White and Black Lists ExampleThis example shows how to enable the white list and co

Page 93

Chapter 21 Anti-VirusZyWALL (ZLD) CLI Reference Guide18221.2.4.1 Signature Search ExampleThis example shows how to search for anti-virus signatures w

Page 94

Chapter 21 Anti-VirusZyWALL (ZLD) CLI Reference Guide18321.3.1 Update Signature ExamplesThese examples show how to enable/disable automatic anti-vir

Page 95

Chapter 21 Anti-VirusZyWALL (ZLD) CLI Reference Guide18421.4.1 Anti-virus Statistics ExampleThis example shows how to collect and display anti-virus

Page 96

ZyWALL (ZLD) CLI Reference Guide 185CHAPTER 22IDP CommandsThis chapter introduces IDP-related commands.22.1 OverviewCommands mostly mirror web conf

Page 97 - CHAPTER 7

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide186This table shows the IDP signature, anomaly, and system-protect activation commands.22.2.1.1

Page 98 - 7.4 Trunk Commands Summary

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide18722.3.1.1 Example of Global Profile CommandsIn this example we rename an IDP signature prof

Page 99 - 7.5 Trunk Command Examples

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide18822.3.2.1 Example of IDP Zone to Zone Rule CommandsThe following example creates IDP zone to

Page 100 - 7.6 Link Sticking

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide189Note: You CANNOT change the base profile later!Table 103 Editing/Creating Anomaly Profile

Page 101

Table of ContentsZyWALL (ZLD) CLI Reference Guide1938.12 Language Commands ...

Page 102 - Chapter 7 Trunks

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide190[no] http-inspection {http-xxx} activate Activates or deactivates http-inspection options wh

Page 103 - CHAPTER 8

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide191show idp anomaly profile scan-detection {tcp-portscan | tcp-decoy-portscan | tcp-portsweep

Page 104

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide19222.3.4.1 Creating an Anomaly Profile ExampleIn this example we create a profile named “test

Page 105 - COMMAND DESCRIPTION

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide193Note: It is recommended you use the web configurator to search for signatures.22.3.6.1 Sea

Page 106 - Chapter 8 Route

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide194example, to search for signatures for Windows NT, Windows XP and Windows 2000 computers, the

Page 107

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide19522.3.6.2 Signature Search ExampleThis example command searches for all signatures in the L

Page 108

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide19622.4.1 Custom Signature ExamplesThese examples show how to create a custom signature, edit

Page 109 - 8.3 IP Static Route

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide197This example shows you how to display custom signature details. Router(config)# show idp si

Page 110

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide198This example shows you how to display custom signature contents. Router(config)# show idp si

Page 111 - CHAPTER 9

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide199This example shows you how to display all details of a custom signature. This example shows

Page 113 - 9.2.4 Virtual Link Commands

Table of ContentsZyWALL (ZLD) CLI Reference Guide2041.2.1 Email Daily Report Example ...

Page 114

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide20022.5.1 Update Signature ExamplesThese examples show how to enable/disable automatic IDP dow

Page 115 - CHAPTER 10

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide20122.6.1 IDP Statistics ExampleThis example shows how to collect and display IDP statistics.

Page 116 - 10.2 Zone Commands Summary

Chapter 22 IDP CommandsZyWALL (ZLD) CLI Reference Guide202

Page 117 - 10.2.1 Zone Command Examples

ZyWALL (ZLD) CLI Reference Guide 203CHAPTER 23Content FilteringThis chapter covers how to use the content filtering feature to control web access. 2

Page 118 - Chapter 10 Zones

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide20423.5 Content Filter Command Input ValuesThe following table explains the values you ca

Page 119 - CHAPTER 11

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide20523.6 General Content Filter CommandsThe following table lists the commands that you c

Page 120 - 11.2 DDNS Commands Summary

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide206mode to be able to use these commands. See Table 111 on page 204 for details about the

Page 121 - Chapter 11 DDNS

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide20723.7 Content Filter Filtering Profile CommandsThe following table lists the commands

Page 122 - Chapter 11 DDNS

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide208content-filter profile filtering_profile custom-list keywordEnters the sub-command for

Page 123 - CHAPTER 12

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide20923.8 Content Filter URL Cache Commands The following table lists the commands that yo

Page 125

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide210Use the configure terminal command to enter the configuration mode to be able to use th

Page 126 - 192.168.3.7

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide21123.9.1 Content Filtering Statistics ExampleThis example shows how to collect and disp

Page 127 - CHAPTER 13

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide2128 Activate the customization.Router# configure terminalRouter(config)# address-object s

Page 128 - 13.2 HTTP Redirect Commands

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide213Use this command to display the settings of the profile.Router(config)# show content-f

Page 129 - Chapter 13 HTTP Redirect

Chapter 23 Content FilteringZyWALL (ZLD) CLI Reference Guide214

Page 130 - Chapter 13 HTTP Redirect

ZyWALL (ZLD) CLI Reference Guide 215CHAPTER 24Anti-SpamThis chapter introduces and shows you how to configure the anti-spam scanner. 24.1 Anti-Spam

Page 131 - CHAPTER 14

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide21624.2.1.1 Activate/Deactivate Anti-Spam ExampleThis example shows how to activate and deactivat

Page 132 - 14.2 ALG Commands

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide217show anti-spam {smtp | pop3} defaultportDisplay the SMTP or POP3 TCP ports the ZyWALL checks f

Page 133 - 14.3 ALG Commands Example

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide21824.2.2.1 Zone to Zone Anti-spam Rule ExampleThis example shows how to configure (and display)

Page 134 - Chapter 14 ALG

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide219Use the white list to identify legitimate e-mail and the black list to identify spam e-mail. T

Page 136 - IP/MAC binding status

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide22024.2.3.1 White and Black Lists ExampleThis example shows how to configure and enable a white l

Page 137 - CHAPTER 16

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide221This table describes the DNSBL commands. Table 122 DNSBL CommandsCOMMAND DESCRIPTION[no] ant

Page 138 - 16.2 Firewall Commands

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide22224.2.4.1 DNSBL ExampleThis example:• Sets the ZyWALL to use “DNSBL-example.com” as a DNSBL.• T

Page 139 - Chapter 16 Firewall

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide22324.3 Anti-Spam StatisticsThe following table describes the commands for collecting and displa

Page 140 - Chapter 16 Firewall

Chapter 24 Anti-SpamZyWALL (ZLD) CLI Reference Guide224

Page 141 - 16.2.1 Firewall Sub-Commands

ZyWALL (ZLD) CLI Reference Guide 225CHAPTER 25Device HAUse device HA to increase network reliability. Device HA lets a backup ZyWALL (B) automatical

Page 142

Chapter 25 Device HAZyWALL (ZLD) CLI Reference Guide226Otherwise you must manually configure the master ZyWALL’s settings on the backup (by editing co

Page 143 - 16.3 Session Limit Commands

Chapter 25 Device HAZyWALL (ZLD) CLI Reference Guide227Virtual Router and Management IP Addresses• If a backup takes over for the master, it uses the

Page 144 - means all IP addresses

Chapter 25 Device HAZyWALL (ZLD) CLI Reference Guide228[no] device-ha ap-mode interface_name manage-ip ip subnet_maskSets the management IP address fo

Page 145 - CHAPTER 17

Chapter 25 Device HAZyWALL (ZLD) CLI Reference Guide22925.4.2 Active-Passive Mode Device HA Command ExampleThis example configures a ZyWALL to be a

Page 146

ZyWALL (ZLD) CLI Reference Guide 23CHAPTER 1Command Line InterfaceThis chapter describes how to access and use the CLI (Command Line Interface).1.1

Page 147 - 17.2.1 IKE SA Commands

Chapter 25 Device HAZyWALL (ZLD) CLI Reference Guide23025.6.1 VRRP Group CommandsThis table lists the commands for VRRP groups.25.6.2 VRRP Synchroni

Page 148

Chapter 25 Device HAZyWALL (ZLD) CLI Reference Guide23125.6.3 Link Monitoring CommandsThis table lists the commands for link monitoring. Link monito

Page 149

Chapter 25 Device HAZyWALL (ZLD) CLI Reference Guide232

Page 150 - Chapter 17 IPSec VPN

ZyWALL (ZLD) CLI Reference Guide 233CHAPTER 26User/GroupThis chapter describes how to set up user accounts, user groups, and user settings for the Z

Page 151

Chapter 26 User/GroupZyWALL (ZLD) CLI Reference Guide23426.2 User/Group Commands SummaryThe following table identifies the values required for many u

Page 152

Chapter 26 User/GroupZyWALL (ZLD) CLI Reference Guide23526.2.2 User Group CommandsThis table lists the commands for groups.26.2.3 User Setting Comm

Page 153 - 17.2.6 SA Monitor Commands

Chapter 26 User/GroupZyWALL (ZLD) CLI Reference Guide23626.2.3.1 User Setting Command ExamplesThe following commands show the current settings for th

Page 154

Chapter 26 User/GroupZyWALL (ZLD) CLI Reference Guide23726.2.4 Force User Authentication CommandsThis table lists the commands for forcing user auth

Page 155 - CHAPTER 18

Chapter 26 User/GroupZyWALL (ZLD) CLI Reference Guide23826.2.4.1 force-auth Sub-commandsThe following table describes the sub-commands for several fo

Page 156 - 18.2.1 SSL VPN Commands

Chapter 26 User/GroupZyWALL (ZLD) CLI Reference Guide239• Description: EPS-on-LAN• Source: use address object “LAN1_SUBNET”• Destination: use address

Page 157

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide241.2.1 Console PortThe default settings for the console port are as follows. When yo

Page 158

Chapter 26 User/GroupZyWALL (ZLD) CLI Reference Guide24026.2.5.1 Additional User Command ExamplesThe following commands display the users that are cu

Page 159 - Chapter 18 SSL VPN

ZyWALL (ZLD) CLI Reference Guide 241CHAPTER 27AddressesThis chapter describes how to set up addresses and address groups for the ZyWALL.27.1 Addres

Page 160 - Chapter 18 SSL VPN

Chapter 27 AddressesZyWALL (ZLD) CLI Reference Guide242The following sections list the address object and address group commands.27.2.1 Address Objec

Page 161 - CHAPTER 19

Chapter 27 AddressesZyWALL (ZLD) CLI Reference Guide24327.2.1.1 Address Object Command ExamplesThe following example creates three IPv4 address obje

Page 162 - 19.3 Policy Route

Chapter 27 AddressesZyWALL (ZLD) CLI Reference Guide244The following example creates host, range, subnet, and link local IPv6 address objects and then

Page 163 - 19.4 L2TP VPN Commands

Chapter 27 AddressesZyWALL (ZLD) CLI Reference Guide24527.2.2.1 Address Group Command ExamplesThe following commands create three address objects A0

Page 164 - 19.5 L2TP VPN Example

Chapter 27 AddressesZyWALL (ZLD) CLI Reference Guide246

Page 165

ZyWALL (ZLD) CLI Reference Guide 247CHAPTER 28ServicesUse service objects to define TCP applications, UDP applications, and ICMP messages. You can a

Page 166

Chapter 28 ServicesZyWALL (ZLD) CLI Reference Guide24828.2.1.1 Service Object Command ExamplesThe following commands create four services, displays t

Page 167 - CHAPTER 20

Chapter 28 ServicesZyWALL (ZLD) CLI Reference Guide24928.2.2.1 Service Group Command ExamplesThe following commands create service ICMP_ECHO, create

Page 168

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide25When you access the CLI using the web console, your computer establishes a SSH (Sec

Page 169 - 20.2.2.1 Rule Sub-commands

Chapter 28 ServicesZyWALL (ZLD) CLI Reference Guide250

Page 170

ZyWALL (ZLD) CLI Reference Guide 251CHAPTER 29SchedulesUse schedules to set up one-time and recurring schedules for policy routes, firewall rules, a

Page 171

Chapter 29 SchedulesZyWALL (ZLD) CLI Reference Guide25229.2.1 Schedule Command ExamplesThe following commands create recurring schedule SCHEDULE1 and

Page 172

ZyWALL (ZLD) CLI Reference Guide 253CHAPTER 30AAA ServerThis chapter introduces and shows you how to configure the ZyWALL to use external authentica

Page 173

Chapter 30 AAA ServerZyWALL (ZLD) CLI Reference Guide25430.2.2 ldap-server Commands The following table lists the ldap-server commands you use to set

Page 174 - Chapter 20 Application Patrol

Chapter 30 AAA ServerZyWALL (ZLD) CLI Reference Guide25530.2.3 radius-server Commands The following table lists the radius-server commands you use t

Page 175

Chapter 30 AAA ServerZyWALL (ZLD) CLI Reference Guide25630.2.6 aaa group server ldap Commands The following table lists the aaa group server ldap com

Page 176

Chapter 30 AAA ServerZyWALL (ZLD) CLI Reference Guide25730.2.7 aaa group server radius Commands The following table lists the aaa group server radiu

Page 177 - CHAPTER 21

Chapter 30 AAA ServerZyWALL (ZLD) CLI Reference Guide25830.2.8 aaa group server Command ExampleThe following example creates a RADIUS server group wi

Page 178

ZyWALL (ZLD) CLI Reference Guide 259CHAPTER 31Authentication ObjectsThis chapter shows you how to select different authentication methods for user a

Page 179 - Chapter 21 Anti-Virus

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide26Note: The default login username is admin. It is case-sensitive.Figure 5 Web Conso

Page 180 - 21.2.3 White and Black Lists

Chapter 31 Authentication ObjectsZyWALL (ZLD) CLI Reference Guide26031.2.1 aaa authentication Command ExampleThe following example creates an authent

Page 181

Chapter 31 Authentication ObjectsZyWALL (ZLD) CLI Reference Guide261• Bind-dn: zyxel\engineerABC• Password: abcdefg• Login-name-attribute: sAMAccount

Page 182

Chapter 31 Authentication ObjectsZyWALL (ZLD) CLI Reference Guide262

Page 183 - 21.4 Anti-virus Statistics

ZyWALL (ZLD) CLI Reference Guide 263CHAPTER 32CertificatesThis chapter explains how to use the Certificates.32.1 Certificates OverviewThe ZyWALL ca

Page 184 - Chapter 21 Anti-Virus

Chapter 32 CertificatesZyWALL (ZLD) CLI Reference Guide26432.4 Certificates Commands SummaryThe following table lists the commands that you can use t

Page 185 - CHAPTER 22

Chapter 32 CertificatesZyWALL (ZLD) CLI Reference Guide265ca validation remote_certificate Enters the sub command mode for validation of certificates

Page 186 - 22.3 IDP Profile Commands

Chapter 32 CertificatesZyWALL (ZLD) CLI Reference Guide266show ca category {local|remote} name certificate_name certpathDisplays the certification pat

Page 187 - old_profile new_profile

Chapter 32 CertificatesZyWALL (ZLD) CLI Reference Guide26732.5 Certificates Commands ExamplesThe following example creates a self-signed X.509 certi

Page 188

ZyWALL (ZLD) CLI Reference Guide 268CHAPTER 33ISP AccountsUse ISP accounts to manage Internet Service Provider (ISP) account information for PPPoE,

Page 189 - Chapter 22 IDP Commands

Chapter 33 ISP AccountsZyWALL (ZLD) CLI Reference Guide26933.1.2 Cellular Account CommandsThe following table lists the cellular ISP account command

Page 190 - Chapter 22 IDP Commands

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide271.2.3 TelnetUse the following steps to Telnet into your ZyWALL.1 If your computer

Page 191

ZyWALL (ZLD) CLI Reference Guide 270CHAPTER 34SSL ApplicationThis chapter describes how to configure SSL application objects for use in SSL VPN.34.1

Page 192 - 22.3.6 Signature Search

Chapter 34 SSL ApplicationZyWALL (ZLD) CLI Reference Guide271server-type file-sharing share-path share-pathSpecifies the IP address, domain name or N

Page 193

Chapter 34 SSL ApplicationZyWALL (ZLD) CLI Reference Guide27234.1.2 SSL Application Command ExamplesThe following commands create and display a serve

Page 194 - If you want to

ZyWALL (ZLD) CLI Reference Guide 273CHAPTER 35Endpoint SecurityThis chapter describes how to configure endpoint security objects for use in authenti

Page 195 - 22.4 IDP Custom Signatures

Chapter 35 Endpoint SecurityZyWALL (ZLD) CLI Reference Guide274RequirementsUser computers must have Sun’s Java (Java Runtime Environment or ‘JRE’) ins

Page 196

Chapter 35 Endpoint SecurityZyWALL (ZLD) CLI Reference Guide275[no] personal-firewall personal_firewall_software_name detect-auto-protection {enable

Page 197

Chapter 35 Endpoint SecurityZyWALL (ZLD) CLI Reference Guide276windows-version {windows-2000 | windows-xp | windows-2003 | windows-2008 | windows-vist

Page 198

Chapter 35 Endpoint SecurityZyWALL (ZLD) CLI Reference Guide27735.1.3 Endpoint Security Object Command ExamplePeter wants to create and display an e

Page 199 - 22.5 Update IDP Signatures

Chapter 35 Endpoint SecurityZyWALL (ZLD) CLI Reference Guide278However, he needs to check the Anti-Virus software name defined on the ZyWALL. The foll

Page 200 - 22.6 IDP Statistics

Chapter 35 Endpoint SecurityZyWALL (ZLD) CLI Reference Guide279Now Peter can create the EPS object profile as the example shown next. Note that he us

Page 201

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide281.4 How Commands Are ExplainedEach chapter explains the commands for one keyword. T

Page 202

ZyWALL (ZLD) CLI Reference Guide 280CHAPTER 36DHCPv6 ObjectsThis chapter describes how to configure and view DHCPv6 request and lease objects. 36.1

Page 203 - CHAPTER 23

Chapter 36 DHCPv6 ObjectsZyWALL (ZLD) CLI Reference Guide28136.1.2 DHCPv6 Object Command ExamplesThis example creates and displays a DHCPv6 lease ob

Page 204 - LABEL DESCRIPTION

Chapter 36 DHCPv6 ObjectsZyWALL (ZLD) CLI Reference Guide282This example creates and displays a DHCPv6 pre-fix delegation lease object named “pfx” for

Page 205

ZyWALL (ZLD) CLI Reference Guide 283CHAPTER 37SystemThis chapter provides information on the commands that correspond to what you can configure in t

Page 206

Chapter 37 SystemZyWALL (ZLD) CLI Reference Guide284Figure 26 Access Page Customization You can specify colors in one of the following ways:• color

Page 207

Chapter 37 SystemZyWALL (ZLD) CLI Reference Guide28537.3 Host Name CommandsThe following table describes the commands available for the hostname and

Page 208

Chapter 37 SystemZyWALL (ZLD) CLI Reference Guide28637.4.1 Date/Time CommandsThe following table describes the commands available for date and time s

Page 209

Chapter 37 SystemZyWALL (ZLD) CLI Reference Guide28737.6 DNS Overview DNS (Domain Name System) is for mapping a domain name to its corresponding IP

Page 210

Chapter 37 SystemZyWALL (ZLD) CLI Reference Guide28837.6.3 DNS Command ExampleThis command sets an A record that specifies the mapping of a fully qua

Page 211 - Chapter 5 on page 49)

ZyWALL (ZLD) CLI Reference Guide 289CHAPTER 38System Remote ManagementThis chapter shows you how to determine which services/protocols can access wh

Page 212 - 8 Activate the customization

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide29•Enter range exactly as it appears, followed by two numbers between 1 and 65535.1.4

Page 213 - Chapter 23 Content Filtering

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide29038.2 Common System Command Input ValuesThe following table identifies the value

Page 214

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide291[no] ip http secure-server cert certificate_name Specifies a certificate used b

Page 215 - CHAPTER 24

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide29238.3.1 HTTP/HTTPS Command ExamplesThis following example adds a service control

Page 216

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide29338.4.3 SSH CommandsThe following table describes the commands available for SS

Page 217 - Chapter 24 Anti-Spam

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide29438.5 Telnet You can configure your ZyWALL for remote Telnet access.38.6 Telnet

Page 218 - 24.2.3 White and Black Lists

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide295This command displays Telnet settings.38.7 Configuring FTP You can upload and

Page 219

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide29638.7.2 FTP Commands ExamplesThis command sets a service control rule that allow

Page 220

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide29738.8.3 SNMP CommandsThe following table describes the commands available for S

Page 221 - Table 122 DNSBL Commands

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide298The following command sets the password (secret) for read-write (rw) access.The

Page 222 - 24.2.4.1 DNSBL Example

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide29938.10.1 AT Command StringsFor regular telephone lines, the default Dial string

Page 223 - 24.3 Anti-Spam Statistics

About This CLI Reference GuideZyWALL (ZLD) CLI Reference Guide3About This CLI Reference GuideIntended AudienceThis manual is intended for people who

Page 224 - Chapter 24 Anti-Spam

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide301.6 Shortcuts and Help1.6.1 List of Available CommandsA list of valid commands can

Page 225 - CHAPTER 25

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide30038.10.4.1 Dial-in Management Command ExamplesThe following commands show you ho

Page 226 - 25.1.1 Before You Begin

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide30138.11.1.1 Vantage CNM Command ExamplesThe following example turns on Vantage C

Page 227

Chapter 38 System Remote ManagementZyWALL (ZLD) CLI Reference Guide30238.13 IPv6 Commands Use the ipv6 commands to enable or disable IPv6 support. Yo

Page 228 - #%^*={}:,.~ characters

ZyWALL (ZLD) CLI Reference Guide 303CHAPTER 39File ManagerThis chapter covers how to work with the ZyWALL’s firmware, certificates, configuration fi

Page 229 - VRRP Group Overview

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide304 These files have the same syntax, which is also identical to the way you run CLI commands m

Page 230 - 25.6.1 VRRP Group Commands

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide305Line 3 in the following example exits sub command mode.Lines 1 and 3 in the following examp

Page 231

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide306• When the ZyWALL reboots, if the startup-config.conf file passes the error check, the ZyWAL

Page 232 - Chapter 25 Device HA

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide30739.4 File Manager Commands SummaryThe following table lists the commands that you can use

Page 233 - CHAPTER 26

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide30839.5 File Manager Command ExamplesThis example saves a back up of the current configuration

Page 234 - 26.2.1 User Commands

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide309The firmware update can take up to five minutes. Do not turn off or reset the ZyWALL while

Page 235 - 26.2.3 User Setting Commands

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide311.6.3 Entering Partial CommandsThe CLI does not accept partial or incomplete comma

Page 236 - Chapter 26 User/Group

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide31039.6.4 Command Line FTP Configuration File Download ExampleThe following example gets a con

Page 237 - Chapter 26 User/Group

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide31139.8 Notification of a Damaged Recovery Image or FirmwareThe ZyWALL’s recovery image and/o

Page 238

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide3124 If “Connect a computer to port 1 and FTP to 192.168.1.1 to upload the new file” displays

Page 239

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide313Note: You only need to use the atuk or atur command if the recovery image is damaged. Figur

Page 240

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide3147 Enter atgo. The ZyWALL starts up. If “Connect a computer to port 1 and FTP to 192.168.1.1

Page 241 - CHAPTER 27

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide3157 Wait for the file transfer to complete.Figure 41 FTP Firmware Transfer Complete8 After

Page 242

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide31610 The username prompt displays after the ZyWALL starts up successfully. The firmware recove

Page 243 - Chapter 27 Addresses

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide317If the default system database file is not valid, the ZyWALL displays a warning message in

Page 244

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide318example, "1.01(XL.0)C0.db". Do the following after you have obtained the default s

Page 245 - ()+/:=?!*#@$_%

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide3197 Hit enter to log in anonymously.8 Set the transfer mode to binary (type bin).9 Transfer t

Page 246 - Chapter 27 Addresses

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide321.7 Input ValuesYou can use the ? or [TAB] to get more information about the next i

Page 247 - CHAPTER 28

Chapter 39 File ManagerZyWALL (ZLD) CLI Reference Guide32012 The username prompt displays after the ZyWALL starts up successfully. The default system

Page 248

ZyWALL (ZLD) CLI Reference Guide 321CHAPTER 40LogsThis chapter provides information about the ZyWALL’s logs. Note: When the system log reaches the m

Page 249

Chapter 40 LogsZyWALL (ZLD) CLI Reference Guide32240.1.1 Log Entries CommandsThis table lists the commands to look at log entries.40.1.2 System Log

Page 250 - Chapter 28 Services

Chapter 40 LogsZyWALL (ZLD) CLI Reference Guide32340.1.2.1 System Log Command ExamplesThe following command displays the current status of the syste

Page 251 - CHAPTER 29

Chapter 40 LogsZyWALL (ZLD) CLI Reference Guide324This table lists the commands for the remote syslog server settings.This table lists the commands fo

Page 252

Chapter 40 LogsZyWALL (ZLD) CLI Reference Guide325[no] logging mail <1..2> address {ip | hostname}Sets the URL or IP address of the mail server

Page 253 - CHAPTER 30

Chapter 40 LogsZyWALL (ZLD) CLI Reference Guide32640.1.4.1 E-mail Profile Command ExamplesThe following commands set up e-mail log 1.40.1.5 Console

Page 254 - 30.2.2 ldap-server Commands

ZyWALL (ZLD) CLI Reference Guide 327CHAPTER 41Reports and RebootThis chapter provides information about the report associated commands and how to re

Page 255

Chapter 41 Reports and RebootZyWALL (ZLD) CLI Reference Guide32841.1.2 Report Command ExamplesThe following commands start collecting data, display t

Page 256

Chapter 41 Reports and RebootZyWALL (ZLD) CLI Reference Guide32941.2 Email Daily Report CommandsThe following table identifies the values used in so

Page 257

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide33domain name Used in content filtering0+ lower-case letters, numbers, or .-Used in i

Page 258

Chapter 41 Reports and RebootZyWALL (ZLD) CLI Reference Guide33041.2.1 Email Daily Report ExampleThis example sets the following about sending a dail

Page 259 - CHAPTER 31

Chapter 41 Reports and RebootZyWALL (ZLD) CLI Reference Guide331• Has the ZyWALL provide username 12345 and password 12345 to the SMTP server for aut

Page 260 - 31.3 test aaa Command

Chapter 41 Reports and RebootZyWALL (ZLD) CLI Reference Guide332This displays the email daily report settings and has the ZyWALL send the report.41.3

Page 261

ZyWALL (ZLD) CLI Reference Guide 333CHAPTER 42Session TimeoutUse these commands to modify and display the session timeout values. You must use the c

Page 262

Chapter 42 Session TimeoutZyWALL (ZLD) CLI Reference Guide334

Page 263 - CHAPTER 32

ZyWALL (ZLD) CLI Reference Guide 335CHAPTER 43 DiagnosticsThis chapter covers how to use the diagnostics feature. 43.1 DiagnosticsThe diagnostics

Page 264 - characters

Chapter 43 DiagnosticsZyWALL (ZLD) CLI Reference Guide336

Page 265 - Chapter 32 Certificates

ZyWALL (ZLD) CLI Reference Guide 337CHAPTER 44Packet Flow ExploreThis chapter covers how to use the packet flow explore feature. 44.1 Packet Flow

Page 266 - Chapter 32 Certificates

Chapter 44 Packet Flow ExploreZyWALL (ZLD) CLI Reference Guide33844.3 Packet Flow Explore Commands ExampleThe following example shows all routing rel

Page 267

Chapter 44 Packet Flow ExploreZyWALL (ZLD) CLI Reference Guide339The following example shows all activated dynamic VPN rules.The following example sh

Page 268 - CHAPTER 33

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide34key length -- 512, 768, 1024, 1536, 2048license key 25 “S-” + 6 upper-case letters o

Page 269

Chapter 44 Packet Flow ExploreZyWALL (ZLD) CLI Reference Guide340The following example shows the default WAN trunk settings.Router> show system sna

Page 270 - CHAPTER 34

ZyWALL (ZLD) CLI Reference Guide 341CHAPTER 45Packet Flow FilterThis chapter covers how to use the packet flow filter feature. 45.1 Packet Flow Fi

Page 271 - Chapter 34 SSL Application

Chapter 45 Packet Flow FilterZyWALL (ZLD) CLI Reference Guide34245.3 Packet Flow Filter Commands ExamplesThe following example configures packet flow

Page 272 - Chapter 34 SSL Application

Chapter 45 Packet Flow FilterZyWALL (ZLD) CLI Reference Guide343This example displays the packet flow filter 1’s settings. This example displays the

Page 273 - CHAPTER 35

Chapter 45 Packet Flow FilterZyWALL (ZLD) CLI Reference Guide344This example activates the packet flow ring buffer feature. Router> configure term

Page 274 - Requirements

ZyWALL (ZLD) CLI Reference Guide 345CHAPTER 46Maintenance ToolsUse the maintenance tool commands to check the conditions of other devices through th

Page 275 - Chapter 35 Endpoint Security

Chapter 46 Maintenance ToolsZyWALL (ZLD) CLI Reference Guide346file-suffix <profile_name> Specifies text to add to the end of the file name (bef

Page 276 - Chapter 35 Endpoint Security

Chapter 46 Maintenance ToolsZyWALL (ZLD) CLI Reference Guide347Here are maintenance tool commands that you can use in configuration mode. 46.1 Maint

Page 277

Chapter 46 Maintenance ToolsZyWALL (ZLD) CLI Reference Guide348Here are maintenance tool commands that you can use in configure mode.The following exa

Page 278

Chapter 46 Maintenance ToolsZyWALL (ZLD) CLI Reference Guide349• IP address: any•Host IP: any• Host port: any (then you do not need to configure this

Page 279

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide351.8 Ethernet InterfacesHow you specify an Ethernet interface depends on the ZyWALL

Page 280 - CHAPTER 36

Chapter 46 Maintenance ToolsZyWALL (ZLD) CLI Reference Guide350

Page 281

ZyWALL (ZLD) CLI Reference Guide 351CHAPTER 47Watchdog TimerThis chapter provides information about the ZyWALL’s watchdog timers. 47.1 Hardware Wat

Page 282

Chapter 47 Watchdog TimerZyWALL (ZLD) CLI Reference Guide35247.3 Application WatchdogThe application watchdog has the system restart a process that f

Page 283 - CHAPTER 37

Chapter 47 Watchdog TimerZyWALL (ZLD) CLI Reference Guide353Application Watch Dog Setting: activate: yes alert: yes console print: always retry c

Page 284

Chapter 47 Watchdog TimerZyWALL (ZLD) CLI Reference Guide354

Page 285 - 37.4 Time and Date

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide355List of Commands (Alphabetical)This section lists the commands and sub-commands in

Page 286 - 37.5 Console Port Speed

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide356[no] ad-server ssl ...

Page 287 - 37.6 DNS Overview

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide357[no] app-watch-dog cpu-threshold min <1..100> max <1..100> ...

Page 288 - 37.6.3 DNS Command Example

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide358{fri|mon|sat|sun|thu|tue|wed} hh:mm offset ...2

Page 289 - CHAPTER 38

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide359[no] description description ...

Page 290 - 38.3 HTTP/HTTPS Commands

Chapter 1 Command Line InterfaceZyWALL (ZLD) CLI Reference Guide361.10 Logging OutEnter the exit or end command in configure mode to go to privilege

Page 291

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide360[no] eps profile profile_name ...

Page 292 - 38.4 SSH

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide361[no] interface {num|interface-name} ...

Page 293 - 38.4.4 SSH Command Examples

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide362[no] ipv6 dhcp6-request-object dhcp6_profile ...

Page 294 - 38.6 Telnet Commands

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide363[no] logging syslog <1..4> {disable | level normal | level all} ...

Page 295 - 38.7 Configuring FTP

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide364[no] out-snat activate ...

Page 296 - 38.8 SNMP

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide365[no] security dot1x acct ip port <1..65535> ...

Page 297 - 38.8.3 SNMP Commands

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide366[no] source {address_object|any} ...

Page 298 - 38.10 Dial-in Management

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide367[no] wan-iface interface_name ...

Page 299 - 38.10.3 Response Strings

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide368anti-spam tag {dnsbl | dnsbl-timeout} [tag] ...

Page 300 - 38.11 Vantage CNM

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide369bandwidth priority <1..7> ...

Page 301 - 38.12 Language Commands

ZyWALL (ZLD) CLI Reference Guide 37CHAPTER 2User and Privilege ModesThis chapter describes how to use these two modes.2.1 User And Privilege Modes

Page 302 - 38.13 IPv6 Commands

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide370content-filter profile filtering_profile url match {block | log | warn | pass} ...

Page 303 - CHAPTER 39

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide371debug system ipv6 ...

Page 304

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide372eps warning-message {windows-auto-update | windows-security-patch | anti-virus | pe

Page 305

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide373force-auth policy flush ...

Page 306

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide374interface dial interface_name ...

Page 307 - Chapter 39 File Manager

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide375ip virtual-server profile_name interface interface_name original-ip {any | ip | ad

Page 308 - 39.6 FTP File Transfer

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide376login-page window-color {color-rgb | color-name | color-number} ...

Page 309

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide377no content-filter profile filtering_profile url offline {log} ...

Page 310 - 3. Firmware

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide378object-group service rename group_name group_name ...

Page 311 - Firmware

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide379renew dhcp interface-name ...

Page 312

Chapter 2 User and Privilege ModesZyWALL (ZLD) CLI Reference Guide38Subsequent chapters in this guide describe the configuration commands. User/privil

Page 313

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide380session-limit delete rule_number ...

Page 314

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide381show anti-spam tag {dnsbl | dnsbl-timeout} ...

Page 315

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide382show comport status ...

Page 316

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide383show firewall ...

Page 317

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide384show idp profiles ...

Page 318

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide385show ipv6 nd ra status config_interface ...

Page 319

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide386show reference object aaa authentication [default | auth_method] ...

Page 320

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide387show sslvpn application [application_object] ...

Page 321 - CHAPTER 40

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide388sslvpn no connection username user_name ...

Page 322 - 40.1.2 System Log Commands

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide389username username user-type ext-user ...

Page 323 - 40.1.3 Debug Log Commands

Chapter 2 User and Privilege ModesZyWALL (ZLD) CLI Reference Guide39is a Linux equivalent, it is displayed in this chapter for your reference. You mu

Page 324

List of Commands (Alphabetical)ZyWALL (ZLD) CLI Reference Guide390

Page 325 - Chapter 40 Logs

Document ConventionsZyWALL (ZLD) CLI Reference Guide4Document ConventionsWarnings and NotesThese are how warnings and notes are shown in this User’s G

Page 326

Chapter 2 User and Privilege ModesZyWALL (ZLD) CLI Reference Guide40debug system ipv6 IPv6 debug commandsdebug [cmdexec|corefile|ip |kernel|mac-id-rew

Page 327 - CHAPTER 41

41PART IIReference

Page 329

ZyWALL (ZLD) CLI Reference Guide 43CHAPTER 3Object ReferenceThis chapter describes how to use object reference commands.3.1 Object Reference Comman

Page 330

Chapter 3 Object ReferenceZyWALL (ZLD) CLI Reference Guide443.1.1 Object Reference Command ExampleThis example shows how to check which configuration

Page 331

ZyWALL (ZLD) CLI Reference Guide 45CHAPTER 4StatusThis chapter explains some commands you can use to display information about the ZyWALL’s current

Page 332 - 41.3 Reboot

Chapter 4 StatusZyWALL (ZLD) CLI Reference Guide46Here are examples of the commands that display the fan speed, MAC address, memory usage, RAM size, a

Page 333 - CHAPTER 42

Chapter 4 StatusZyWALL (ZLD) CLI Reference Guide47Here is an example of the command that displays the open ports. Router(config)# show socket openNo.

Page 334 - Chapter 42 Session Timeout

Chapter 4 StatusZyWALL (ZLD) CLI Reference Guide48Here are examples of the commands that display the system uptime and model, firmware, and build info

Page 335 - CHAPTER 43

ZyWALL (ZLD) CLI Reference Guide 49CHAPTER 5RegistrationThis chapter introduces myzyxel.com and shows you how to register the ZyWALL for IDP/AppPatr

Page 336 - Chapter 43 Diagnostics

Document ConventionsZyWALL (ZLD) CLI Reference Guide5Server Firewall TelephoneSwitch Router

Page 337 - CHAPTER 44

Chapter 5 RegistrationZyWALL (ZLD) CLI Reference Guide50suppose you purchase a one-year Kaspersky engine anti-virus service subscription and use it fo

Page 338

Chapter 5 RegistrationZyWALL (ZLD) CLI Reference Guide515.2.1 Command ExamplesThe following commands allow you to register your device with an exist

Page 339

Chapter 5 RegistrationZyWALL (ZLD) CLI Reference Guide52The following command displays the service registration status and type and how many days rema

Page 340

Chapter 5 RegistrationZyWALL (ZLD) CLI Reference Guide53039 Canada 040 Cape Verde041 Cayman Islands 042 Central African Republic043 Chad 044 Chile045

Page 341 - CHAPTER 45

Chapter 5 RegistrationZyWALL (ZLD) CLI Reference Guide54119 Latvia 120 Lebanon121 Lesotho 122 Liberia123 Liechtenstein 124 Lithuania125 Luxembourg 126

Page 342

Chapter 5 RegistrationZyWALL (ZLD) CLI Reference Guide55197 St Pierre and Miquelon 198 St. Helena199 Suriname 200 Svalbard and Jan Mayen Islands201 S

Page 343

Chapter 5 RegistrationZyWALL (ZLD) CLI Reference Guide56

Page 344 - Chapter 45 Packet Flow Filter

ZyWALL (ZLD) CLI Reference Guide 57CHAPTER 6InterfacesThis chapter shows you how to use interface-related commands.6.1 Interface OverviewIn general

Page 345 - CHAPTER 46

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide58•The auxiliary interface, along with an external modem, provides an interface the ZyWALL can use

Page 346 - Chapter 46 Maintenance Tools

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide59* - Each name consists of 2-4 letters (interface type), followed by a number (x). For most inte

Page 347

Document ConventionsZyWALL (ZLD) CLI Reference Guide6

Page 348

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide606.1.2 Relationships Between InterfacesIn the ZyWALL, interfaces are usually created on top of o

Page 349

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide616.2 Interface General Commands SummaryThe following table identifies the values required for m

Page 350

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide62show interface send statistics interval Displays the interval for how often the ZyWALL refreshes

Page 351 - CHAPTER 47

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide63enable Turns on the IPv6 interface.nd ra accept Sets the IPv6 interface to accept IPv6 neighbor

Page 352 - 47.3 Application Watchdog

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide64nd ra prefix-advertisement dhcp6_profile dhcp6_suffix_64Configures the network prefix to use a d

Page 353 - Chapter 47 Watchdog Timer

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide65nd ra hop-limit Removes the maximum number of hops setting for router advertisements and all IP

Page 354 - Chapter 47 Watchdog Timer

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide666.2.1.1 Basic Interface Properties Command ExamplesThe following commands make Ethernet interfa

Page 355

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide67This example shows how to restart an interface. You can check all interface names on the ZyWALL

Page 356

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide68[no] host ip Specifies the static IP address the ZyWALL should assign. Use this command, along w

Page 357

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide69[no] starting-address ip pool-size <1..65535>Sets the IP start address and maximum pool s

Page 358

Contents OverviewZyWALL (ZLD) CLI Reference Guide7Contents OverviewIntroduction ...

Page 359

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide706.2.2.1 DHCP Setting Command ExamplesThe following example uses these commands to configure DHC

Page 360

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide716.2.3 Interface Parameter Command ExamplesThis table shows an example of each interface type’s

Page 361

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide726.2.4 RIP CommandsThis table lists the commands for RIP settings.6.2.5 OSPF CommandsThis table

Page 362

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide73[no] passive-interface interface_name Sets the OSPF direction of the specified interface to in-

Page 363

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide746.2.6 Connectivity Check (Ping-check) CommandsUse these commands to have an interface regularly

Page 364

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide756.2.6.1 Connectivity Check Command ExampleThe following commands show you how to set the WAN1

Page 365

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide766.3.2 Port Grouping CommandsThis section covers commands that are specific to port grouping.Not

Page 366

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide776.3.2.1 Port Grouping Command ExamplesThe following commands add physical port 5 to representa

Page 367

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide78gateway 4.6.7.8, upstream bandwidth 345, downstream bandwidth 123, and description “I am vir int

Page 368

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide796.5.1 PPPoE/PPTP Interface Command ExamplesThe following commands show you how to configure PP

Page 369

Contents OverviewZyWALL (ZLD) CLI Reference Guide8DHCPv6 Objects ...

Page 370

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide802.2.2.2, MTU 1200, upstream bandwidth 345, downstream bandwidth 123, description “I am ppp0”, an

Page 371

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide81[no] network-selection {auto|home} Home network is the network to which you are originally subs

Page 372

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide826.6.1 Cellular StatusThe following table describes the different kinds of cellular connection s

Page 373

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide83Limited service returned by the service provider in cases where the SIM card is expired, the us

Page 374

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide846.6.2 Cellular Interface Command ExamplesThis example shows the configuration of a cellular int

Page 375

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide856.7 Tunnel Interface Specific CommandsThe ZyWALL uses tunnel interfaces in Generic Routing Enc

Page 376

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide866.7.1 Tunnel Interface Command ExamplesThis example creates a tunnel interface called tunnel0 t

Page 377

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide876.8.1 USB Storage General Commands ExampleThis example shows how to display the status of the

Page 378

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide886.9.1 WLAN General CommandsUse these commands to configure global settings that apply to all of

Page 379

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide896.9.1.1 WLAN General Commands ExampleThis example sets wireless slot 1 to use the IEEE 802.11b

Page 380

Table of ContentsZyWALL (ZLD) CLI Reference Guide9Table of ContentsAbout This CLI Reference Guide...

Page 381

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide90[no] mtu <576..2304> Specifies the Maximum Transmission Unit, which is the maximum number

Page 382

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide916.9.2.1 WLAN Interface Commands ExampleThis example configures WLAN AP interface 2 for slot 1

Page 383 -

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide926.9.3.1 WLAN MAC Filter Commands ExampleThis example creates a MAC filter entry for MAC address

Page 384

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide936.10.1 VLAN Interface Command ExamplesThe following commands show you how to set up VLAN vlan1

Page 385

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide946.11.1 Bridge Interface Command ExamplesThe following commands show you how to set up a bridge

Page 386

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide956.12.1 Auxiliary Interface Command ExamplesThe following commands show you how to set up the a

Page 387

Chapter 6 InterfacesZyWALL (ZLD) CLI Reference Guide96

Page 388

ZyWALL (ZLD) CLI Reference Guide 97CHAPTER 7TrunksThis chapter shows you how to configure trunks on your ZyWALL.7.1 Trunks OverviewYou can group mu

Page 389

Chapter 7 TrunksZyWALL (ZLD) CLI Reference Guide987.3 Trunk Commands Input ValuesThe following table explains the values you can input with the inter

Page 390

Chapter 7 TrunksZyWALL (ZLD) CLI Reference Guide997.5 Trunk Command ExamplesThe following example creates a weighted round robin trunk for Ethernet

Comments to this Manuals

No comments