Zyxel-communications 5 Series User Manual

Browse online or download User Manual for Hardware Zyxel-communications 5 Series. ZyXEL Communications 5 Series User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 835
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
ZyWALL 5/35/70 Series
Internet Security Appliance
Users Guide
Version 4.01
7/2006
Edition 1
Page view 0
1 2 3 4 5 6 ... 834 835

Summary of Contents

Page 1 - ZyWALL 5/35/70 Series

ZyWALL 5/35/70 SeriesInternet Security ApplianceUser’s GuideVersion 4.017/2006Edition 1

Page 2

ZyWALL 5/35/70 Series User’s Guide10 Customer Support

Page 3 - Copyright

ZyWALL 5/35/70 Series User’s Guide100 Chapter 3 Wizard SetupClick VPN Setup in the Wizard Setup Welcome screen (Figure 17 on page 90) to open the VPN

Page 4 - Certifications

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 1013.4 VPN Wizard Network SettingUse this screen to name the VPN network policy (IPSec SA) a

Page 5 - Safety Warnings

ZyWALL 5/35/70 Series User’s Guide102 Chapter 3 Wizard SetupFigure 30 VPN Wizard: Network SettingThe following table describes the labels in this sc

Page 6 - 6 Safety Warnings

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 1033.5 VPN Wizard IKE Tunnel Setting (IKE Phase 1)Use this screen to specify the authenticat

Page 7 - ZyXEL Limited Warranty

ZyWALL 5/35/70 Series User’s Guide104 Chapter 3 Wizard SetupThe following table describes the labels in this screen.3.6 VPN Wizard IPSec Setting (IKE

Page 8 - Customer Support

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 105Figure 32 VPN Wizard: IPSec SettingThe following table describes the labels in this scre

Page 9 - Customer Support 9

ZyWALL 5/35/70 Series User’s Guide106 Chapter 3 Wizard Setup3.7 VPN Wizard Status SummaryThis read-only screen shows the status of the current VPN se

Page 10 - 10 Customer Support

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 107Figure 33 VPN Wizard: VPN StatusThe following table describes the labels in this screen.

Page 11 - Table of Contents

ZyWALL 5/35/70 Series User’s Guide108 Chapter 3 Wizard SetupName This is the name of this VPN network policy.Network Policy SettingLocal NetworkStarti

Page 12

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 1093.8 VPN Wizard Setup CompleteCongratulations! You have successfully set up the VPN rule f

Page 13

ZyWALL 5/35/70 Series User’s GuideTable of Contents 11Table of ContentsCopyright ...

Page 14 - Chapter 10

ZyWALL 5/35/70 Series User’s Guide110 Chapter 3 Wizard Setup

Page 15 - Chapter 11

ZyWALL 5/35/70 Series User’s GuideChapter 4 Tutorial 111CHAPTER 4TutorialThis chapter describes how to apply security settings to VPN traffic.4.1 Sec

Page 16

ZyWALL 5/35/70 Series User’s Guide112 Chapter 4 TutorialFigure 35 IDP for From VPN Traffic Here is how you would configure this example. 1 Click SEC

Page 17 - Chapter 16

ZyWALL 5/35/70 Series User’s GuideChapter 4 Tutorial 1134.1.2 IDP for To VPN Traffic ExampleYou can also apply security settings to the To VPN packet

Page 18 - Chapter 18

ZyWALL 5/35/70 Series User’s Guide114 Chapter 4 TutorialFigure 38 IDP Configuration for To VPN Traffic4.2 Firewall Rule for VPN ExampleThe firewall

Page 19

ZyWALL 5/35/70 Series User’s GuideChapter 4 Tutorial 115Figure 39 Firewall Rule for VPN4.2.1 Configuring the VPN RuleThis section shows how to conf

Page 20

ZyWALL 5/35/70 Series User’s Guide116 Chapter 4 TutorialFigure 41 SECURITY > VPN > VPN Rules (IKE)> Add Gateway Policy 3 Click the Add N

Page 21 - Chapter 26

ZyWALL 5/35/70 Series User’s GuideChapter 4 Tutorial 117Figure 42 SECURITY > VPN > VPN Rules (IKE): With Gateway Policy Example 4 Use this sc

Page 22 - Chapter 28

ZyWALL 5/35/70 Series User’s Guide118 Chapter 4 TutorialFigure 43 SECURITY > VPN > VPN Rules (IKE)> Add Network Policy 4.2.2 Configuring

Page 23

ZyWALL 5/35/70 Series User’s GuideChapter 4 Tutorial 1194.2.2.1 Firewall Rule to Allow Access ExampleConfigure a firewall rule that allows FTP access

Page 24

ZyWALL 5/35/70 Series User’s Guide12 Table of Contents2.4.5 Navigation Panel ...

Page 25

ZyWALL 5/35/70 Series User’s Guide120 Chapter 4 TutorialFigure 45 SECURITY > FIREWALL > Rule Summary > Edit: Allow 4 The rule displays in t

Page 26

ZyWALL 5/35/70 Series User’s GuideChapter 4 Tutorial 121Figure 46 SECURITY > FIREWALL > Rule Summary: Allow4.2.2.2 Default Firewall Rule to B

Page 27

ZyWALL 5/35/70 Series User’s Guide122 Chapter 4 Tutorial

Page 28

ZyWALL 5/35/70 Series User’s GuideChapter 5 Registration 123CHAPTER 5Registration5.1 myZyXEL.com overviewmyZyXEL.com is ZyXEL’s online services cente

Page 29

ZyWALL 5/35/70 Series User’s Guide124 Chapter 5 RegistrationYou will get automatic e-mail notification of new signature releases from mySecurityZone a

Page 30 - 30 Table of Contents

ZyWALL 5/35/70 Series User’s GuideChapter 5 Registration 125The following table describes the labels in this screen. Note: If the ZyWALL is registered

Page 31 - List of Figures

ZyWALL 5/35/70 Series User’s Guide126 Chapter 5 RegistrationFigure 49 REGISTRATION: Registered Device5.3 ServiceAfter you activate a trial, you can

Page 32

ZyWALL 5/35/70 Series User’s GuideChapter 5 Registration 127The following table describes the labels in this screen. Table 22 REGISTRATION > Serv

Page 33

ZyWALL 5/35/70 Series User’s Guide128 Chapter 5 Registration

Page 34

ZyWALL 5/35/70 Series User’s GuideChapter 6 LAN Screens 129CHAPTER 6LAN ScreensThis chapter describes how to configure LAN settings. This chapter is o

Page 35

ZyWALL 5/35/70 Series User’s GuideTable of Contents 13Chapter 6LAN Screens...

Page 36

ZyWALL 5/35/70 Series User’s Guide130 Chapter 6 LAN ScreensWhere you obtain your network number depends on your particular situation. If the ISP or yo

Page 37

ZyWALL 5/35/70 Series User’s GuideChapter 6 LAN Screens 1316.3 DHCP The ZyWALL can use DHCP (Dynamic Host Configuration Protocol, RFC 2131 and RFC 21

Page 38

ZyWALL 5/35/70 Series User’s Guide132 Chapter 6 LAN ScreensIGMP (Internet Group Multicast Protocol) is a network-layer protocol used to establish memb

Page 39

ZyWALL 5/35/70 Series User’s GuideChapter 6 LAN Screens 133Figure 52 NETWORK > LANThe following table describes the labels in this screen.Table 2

Page 40

ZyWALL 5/35/70 Series User’s Guide134 Chapter 6 LAN ScreensRIP Version The RIP Version field controls the format and the broadcasting method of the RI

Page 41

ZyWALL 5/35/70 Series User’s GuideChapter 6 LAN Screens 1356.8 LAN Static DHCPThis table allows you to assign IP addresses on the LAN to specific ind

Page 42

ZyWALL 5/35/70 Series User’s Guide136 Chapter 6 LAN ScreensFigure 53 NETWORK > LAN > Static DHCPThe following table describes the labels in th

Page 43

ZyWALL 5/35/70 Series User’s GuideChapter 6 LAN Screens 137The ZyWALL has a single LAN interface. Even though more than one of ports 1~4 may be in the

Page 44 - 44 List of Figures

ZyWALL 5/35/70 Series User’s Guide138 Chapter 6 LAN ScreensFigure 55 NETWORK > LAN > IP AliasThe following table describes the labels in this

Page 45 - List of Tables

ZyWALL 5/35/70 Series User’s GuideChapter 6 LAN Screens 1396.10 LAN Port RolesUse the Port Roles screen to set ports as part of the LAN, DMZ and/or W

Page 46

ZyWALL 5/35/70 Series User’s Guide14 Table of Contents8.8 WAN Route ...

Page 47

ZyWALL 5/35/70 Series User’s Guide140 Chapter 6 LAN ScreensFigure 56 NETWORK > LAN > Port RolesThe following table describes the labels in thi

Page 48

ZyWALL 5/35/70 Series User’s GuideChapter 7 Bridge Screens 141CHAPTER 7Bridge ScreensThis chapter describes how to configure bridge settings. This cha

Page 49

ZyWALL 5/35/70 Series User’s Guide142 Chapter 7 Bridge Screens7.2 Spanning Tree Protocol (STP)STP detects and breaks network loops and provides backu

Page 50

ZyWALL 5/35/70 Series User’s GuideChapter 7 Bridge Screens 143STP-aware bridges exchange Bridge Protocol Data Units (BPDUs) periodically. When the bri

Page 51

ZyWALL 5/35/70 Series User’s Guide144 Chapter 7 Bridge ScreensFigure 59 NETWORK > BridgeThe following table describes the labels in this screen.T

Page 52 - 52 List of Tables

ZyWALL 5/35/70 Series User’s GuideChapter 7 Bridge Screens 1457.4 Bridge Port Roles Use the Port Roles screen to set ports as part of the LAN, DMZ an

Page 53 - User Guide Feedback

ZyWALL 5/35/70 Series User’s Guide146 Chapter 7 Bridge ScreensFigure 60 NETWORK > Bridge > Port RolesThe following table describes the labels

Page 54 - Graphics Icons Key

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 147CHAPTER 8WAN ScreensThis chapter describes how to configure WAN settings. Multiple WAN and

Page 55 - CHAPTER 1

ZyWALL 5/35/70 Series User’s Guide148 Chapter 8 WAN ScreensYou can select through which WAN port you want to send out traffic from UPnP-enabled applic

Page 56 - 1.2.1 Physical Features

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 1498.4.1.1 Example 1The following figure depicts an example where both the WAN ports on the Z

Page 57 - 1.2.2 Non-Physical Features

ZyWALL 5/35/70 Series User’s GuideTable of Contents 1510.9.1 Introduction to RADIUS ...

Page 58

ZyWALL 5/35/70 Series User’s Guide150 Chapter 8 WAN Screens8.4.2 Weighted Round Robin Similar to the Round Robin (RR) algorithm, the Weighted Round R

Page 59

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 151Figure 64 Spillover Algorithm Example8.5 TCP/IP Priority (Metric)The metric represents t

Page 60

ZyWALL 5/35/70 Series User’s Guide152 Chapter 8 WAN ScreensFigure 65 NETWORK > WAN (General)

Page 61

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 153The following table describes the labels in this screen.Table 33 NETWORK > WAN (Genera

Page 62

ZyWALL 5/35/70 Series User’s Guide154 Chapter 8 WAN ScreensCheck WAN1/2 ConnectivitySelect the check box to have the ZyWALL periodically test the resp

Page 63 - 1.3.2 VPN Application

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 1558.7 Configuring Load Balancing To configure load balancing on the ZyWALL, click NETWORK &g

Page 64 - 1.3.3 Front Panel Lights

ZyWALL 5/35/70 Series User’s Guide156 Chapter 8 WAN Screens8.7.2 Weighted Round RobinTo load balance using the weighted round robin method, select We

Page 65

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 1578.7.3 SpilloverTo load balance using the spillover method, select Spillover in the Load Ba

Page 66

ZyWALL 5/35/70 Series User’s Guide158 Chapter 8 WAN ScreensFigure 69 NETWORK > WAN (Route)The following table describes the labels in this screen

Page 67 - CHAPTER 2

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 1598.9 WAN IP Address Assignment Every computer on the Internet must have a unique IP address

Page 68 - 2.3 Resetting the ZyWALL

ZyWALL 5/35/70 Series User’s Guide16 Table of Contents11.13.1 Firewall Edit Custom Service ...

Page 69 - Then click Send

ZyWALL 5/35/70 Series User’s Guide160 Chapter 8 WAN Screens1 The ISP tells you the DNS server addresses, usually in the form of an information sheet,

Page 70 - 2.4.1 Title Bar

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 161Figure 70 NETWORK > WAN > WAN (Ethernet Encapsulation) The following table descri

Page 71 - 2.4.2 Main Window

ZyWALL 5/35/70 Series User’s Guide162 Chapter 8 WAN ScreensRetype to Confirm Type your password again to make sure that you have entered is correctly.

Page 72

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 1638.12.2 PPPoE EncapsulationThe ZyWALL supports PPPoE (Point-to-Point Protocol over Ethernet

Page 73

ZyWALL 5/35/70 Series User’s Guide164 Chapter 8 WAN ScreensOperationally, PPPoE saves significant effort for both you and the ISP or carrier, as it re

Page 74

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 165The following table describes the labels in this screen.Table 41 NETWORK > WAN > WA

Page 75

ZyWALL 5/35/70 Series User’s Guide166 Chapter 8 WAN Screens8.12.3 PPTP EncapsulationPoint-to-Point Tunneling Protocol (PPTP) is a network protocol th

Page 76

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 167PPTP supports on-demand, multi-protocol and virtual private networking over public networks

Page 77

ZyWALL 5/35/70 Series User’s Guide168 Chapter 8 WAN ScreensThe following table describes the labels in this screen.Table 42 NETWORK > WAN > WA

Page 78 - 2.4.5 Navigation Panel

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 169Enable NAT (Network Address Translation)Network Address Translation (NAT) allows the transl

Page 79 - Table 7 Screens Summary

ZyWALL 5/35/70 Series User’s GuideTable of Contents 1714.2.2 Notes About the ZyWALL Anti-Virus ...27

Page 80

ZyWALL 5/35/70 Series User’s Guide170 Chapter 8 WAN Screens8.13 Traffic Redirect Traffic redirect forwards WAN traffic to a backup gateway when t

Page 81

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 171Figure 75 NETWORK > WAN > Traffic RedirectThe following table describes the labels

Page 82

ZyWALL 5/35/70 Series User’s Guide172 Chapter 8 WAN ScreensFigure 76 NETWORK > WAN > Dial Backup

Page 83 - 2.4.6 Port Statistics

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 173The following table describes the labels in this screen.Table 44 NETWORK > WAN > Di

Page 84

ZyWALL 5/35/70 Series User’s Guide174 Chapter 8 WAN ScreensEnable RIP Select this check box to turn on RIP (Routing Information Protocol), which allow

Page 85 - 2.4.8 DHCP Table Screen

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 1758.16 Advanced Modem Setup 8.16.1 AT Command StringsFor regular telephone lines, the defa

Page 86 - 2.4.9 VPN Status

ZyWALL 5/35/70 Series User’s Guide176 Chapter 8 WAN ScreensFigure 77 NETWORK > WAN > Dial Backup > Edit The following table describes the

Page 87 - 2.4.10 Bandwidth Monitor

ZyWALL 5/35/70 Series User’s GuideChapter 8 WAN Screens 177Dial Timeout (sec) Type a number of seconds for the ZyWALL to try to set up an outgoing cal

Page 88

ZyWALL 5/35/70 Series User’s Guide178 Chapter 8 WAN Screens

Page 89 - CHAPTER 3

ZyWALL 5/35/70 Series User’s GuideChapter 9 DMZ Screens 179CHAPTER 9DMZ ScreensThis chapter describes how to configure the ZyWALL’s DMZ.9.1 DMZ The

Page 90 - 3.2 Internet Access

ZyWALL 5/35/70 Series User’s Guide18 Table of ContentsChapter 17Content Filtering Reports...

Page 91 - Chapter 3 Wizard Setup 91

ZyWALL 5/35/70 Series User’s Guide180 Chapter 9 DMZ ScreensFigure 78 NETWORK > DMZ The following table describes the labels in this screen. Table

Page 92 - 3.2.1.2 PPPoE Encapsulation

ZyWALL 5/35/70 Series User’s GuideChapter 9 DMZ Screens 181RIP Version The RIP Version field controls the format and the broadcasting method of the RI

Page 93 - 3.2.1.3 PPTP Encapsulation

ZyWALL 5/35/70 Series User’s Guide182 Chapter 9 DMZ Screens9.3 DMZ Static DHCP This table allows you to assign IP addresses on the DMZ to specific i

Page 94 - 94 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 9 DMZ Screens 183Figure 79 NETWORK > DMZ > Static DHCP The following table describes the labels in

Page 95 - Chapter 3 Wizard Setup 95

ZyWALL 5/35/70 Series User’s Guide184 Chapter 9 DMZ ScreensThe ZyWALL has a single DMZ interface. Even though more than one of ports 1~4 may be in the

Page 96 - 96 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 9 DMZ Screens 1859.5 DMZ Public IP Address ExampleThe following figure shows a simple network setup with pu

Page 97 - Chapter 3 Wizard Setup 97

ZyWALL 5/35/70 Series User’s Guide186 Chapter 9 DMZ ScreensFigure 81 DMZ Public Address Example9.6 DMZ Private and Public IP Address ExampleThe fol

Page 98 - 98 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 9 DMZ Screens 187Figure 82 DMZ Private and Public Address Example9.7 DMZ Port Roles Use the Port Roles s

Page 99 - Chapter 3 Wizard Setup 99

ZyWALL 5/35/70 Series User’s Guide188 Chapter 9 DMZ ScreensFigure 83 NETWORK > DMZ > Port Roles The following table describes the labels in th

Page 100 - 100 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 189CHAPTER 10Wireless LANThis chapter discusses how to configure wireless LAN on the ZyWALL.

Page 101 - Chapter 3 Wizard Setup 101

ZyWALL 5/35/70 Series User’s GuideTable of Contents 1918.16.1 Hub-and-spoke VPN Example ...35

Page 102 - 102 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide190 Chapter 10 Wireless LANClick NETWORK, > WLAN to open the WLAN screen to configure the IP address for ZyWALL’s

Page 103 - Chapter 3 Wizard Setup 103

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 191RIP Version The RIP Version field controls the format and the broadcasting method of the

Page 104 - 104 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide192 Chapter 10 Wireless LAN10.3 WLAN Static DHCP This table allows you to assign IP addresses on the WLAN to speci

Page 105 - Chapter 3 Wizard Setup 105

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 193Figure 85 NETWORK > WLAN > Static DHCP The following table describes the labels i

Page 106 - 106 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide194 Chapter 10 Wireless LANThe ZyWALL has a single WLAN interface. Even though more than one of ports 1~4 may be in

Page 107 - Chapter 3 Wizard Setup 107

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 19510.5 WLAN Port Roles Use the Port Roles screen to set ports as part of the LAN, DMZ and

Page 108 - 108 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide196 Chapter 10 Wireless LANFigure 87 WLAN Port Role Example Note: Do the following if you are configuring from a c

Page 109 - Chapter 3 Wizard Setup 109

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 197The following table describes the labels in this screen. After you change the LAN/DMZ/WLA

Page 110 - 110 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide198 Chapter 10 Wireless LANFigure 90 ZyWALL Wireless Security LevelsIf you do not enable any wireless security on

Page 111 - CHAPTER 4

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 19910.6.3 Restricted AccessThe MAC Filter screen allows you to configure the AP to give exc

Page 113 - Chapter 4 Tutorial 113

ZyWALL 5/35/70 Series User’s Guide20 Table of Contents21.1.5 Port Restricted Cone NAT ...

Page 114 - 114 Chapter 4 Tutorial

ZyWALL 5/35/70 Series User’s Guide200 Chapter 10 Wireless LAN10.9 802.1x OverviewThe IEEE 802.1x standard outlines enhanced security methods for both

Page 115 - Chapter 4 Tutorial 115

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 201Sent by the access point requesting accounting.• Accounting-ResponseSent by the RADIUS se

Page 116 - 116 Chapter 4 Tutorial

ZyWALL 5/35/70 Series User’s Guide202 Chapter 10 Wireless LAN10.10 Dynamic WEP Key ExchangeThe AP maps a unique key that is generated with the RADIUS

Page 117 - Chapter 4 Tutorial 117

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 203Temporal Key Integrity Protocol (TKIP) uses 128-bit keys that are dynamically generated a

Page 118 - 118 Chapter 4 Tutorial

ZyWALL 5/35/70 Series User’s Guide204 Chapter 10 Wireless LANFigure 92 WPA-PSK Authentication10.13 Introduction to RADIUSThe ZyWALL can use an exte

Page 119 - Chapter 4 Tutorial 119

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 205Figure 93 WPA with RADIUS Application Example10.15 Wireless Client WPA SupplicantsA wi

Page 120 - 120 Chapter 4 Tutorial

ZyWALL 5/35/70 Series User’s Guide206 Chapter 10 Wireless LANFigure 94 NETWORK > WIRELESS CARD: No SecurityThe following table describes the labe

Page 121 - Chapter 4 Tutorial 121

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 20710.16.1 Static WEPStatic WEP provides a mechanism for encrypting data using encryption k

Page 122 - 122 Chapter 4 Tutorial

ZyWALL 5/35/70 Series User’s Guide208 Chapter 10 Wireless LANFigure 95 NETWORK > WIRELESS CARD: Static WEPThe following table describes the wirel

Page 123 - CHAPTER 5

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 209Figure 96 NETWORK > WIRELESS CARD: WPA-PSKThe following wireless LAN security fields

Page 124 - 5.2 Registration

ZyWALL 5/35/70 Series User’s GuideTable of Contents 2124.7.5 Maximize Bandwidth Usage Example ...42624.

Page 125 - Table 21 REGISTRATION

ZyWALL 5/35/70 Series User’s Guide210 Chapter 10 Wireless LAN10.16.3 WPAClick NETWORK > WIRELESS CARD to display the Wireless Card screen. Select

Page 126 - 5.3 Service

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 21110.16.4 IEEE 802.1x + Dynamic WEPClick NETWORK > WIRELESS CARD to display the Wireles

Page 127 - Chapter 5 Registration 127

ZyWALL 5/35/70 Series User’s Guide212 Chapter 10 Wireless LANThe following wireless LAN security fields become available when you select 802.1x + Dyna

Page 128 - 128 Chapter 5 Registration

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 213Figure 99 NETWORK > WIRELESS CARD: 802.1x + Static WEPThe following wireless LAN sec

Page 129 - CHAPTER 6

ZyWALL 5/35/70 Series User’s Guide214 Chapter 10 Wireless LAN10.16.6 IEEE 802.1x + No WEPClick the NETWORK > WIRELESS CARD to display the Wireless

Page 130 - 6.2.1 Private IP Addresses

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 215The following wireless LAN security fields become available when you select 802.1x + No W

Page 131 - 6.5 Multicast

ZyWALL 5/35/70 Series User’s Guide216 Chapter 10 Wireless LANFigure 101 NETWORK > WIRELESS CARD: No Access 802.1x + Static WEPThe following wirel

Page 132 - 6.7 LAN

ZyWALL 5/35/70 Series User’s GuideChapter 10 Wireless LAN 21710.17 MAC Filter The MAC filter screen allows you to configure the ZyWALL to give exclus

Page 133 - Table 23 NETWORK > LAN

ZyWALL 5/35/70 Series User’s Guide218 Chapter 10 Wireless LANUser Name Enter a descriptive name for the MAC address.MAC AddressEnter the MAC addresses

Page 134 - 134 Chapter 6 LAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 219CHAPTER 11FirewallThis chapter shows you how to configure your ZyWALL’s firewall.11.1 Firewa

Page 135 - 6.8 LAN Static DHCP

ZyWALL 5/35/70 Series User’s Guide22 Table of Contents26.4.2 Netscape Navigator Warning Messages ...45626.

Page 136 - 6.9 LAN IP Alias

ZyWALL 5/35/70 Series User’s Guide220 Chapter 11 FirewallYour customized rules take precedence and override the ZyWALL’s default settings. The ZyWALL

Page 137 - Chapter 6 LAN Screens 137

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 221To set the ZyWALL to by default silently block traffic from WAN 1 from going to the DMZ inter

Page 138 - 138 Chapter 6 LAN Screens

ZyWALL 5/35/70 Series User’s Guide222 Chapter 11 FirewallBy default, the ZyWALL drops packets traveling in the following directions.See Chapter 4 on p

Page 139 - 6.10 LAN Port Roles

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 223Figure 106 From LAN to VPN Example In order to do this, you would configure the SECURITY &g

Page 140 - 140 Chapter 6 LAN Screens

ZyWALL 5/35/70 Series User’s Guide224 Chapter 11 Firewall11.3.2 From VPN Packet Direction You can also apply firewall rules to traffic that comes in

Page 141 - CHAPTER 7

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 225Figure 109 Block VPN to LAN Traffic by Default Example 11.3.3 From VPN To VPN Packet Di

Page 142 - 7.2.3 How STP Works

ZyWALL 5/35/70 Series User’s Guide226 Chapter 11 FirewallFigure 110 From VPN to VPN Example You would configure the SECURITY > FIREWALL > Defa

Page 143 - 7.3 Bridge

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 227Consider these security ramifications before creating a rule:1 Does this rule stop LAN users

Page 144 - 144 Chapter 7 Bridge Screens

ZyWALL 5/35/70 Series User’s Guide228 Chapter 11 Firewall• The second row is the firewall’s default policy that allows all traffic from the LAN to go

Page 145 - 7.4 Bridge Port Roles

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 229• The third row is (still) the firewall’s default policy of allowing all traffic from the LAN

Page 146 - 146 Chapter 7 Bridge Screens

ZyWALL 5/35/70 Series User’s GuideTable of Contents 2328.1.2 ALG and the Firewall ...

Page 147 - CHAPTER 8

ZyWALL 5/35/70 Series User’s Guide230 Chapter 11 FirewallFigure 114 Using IP Alias to Solve the Triangle Route Problem11.7 Firewall Default Rule (R

Page 148 - 8.4.1 Least Load First

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 231The following table describes the labels in this screen. Table 66 SECURITY > FIREWALL &g

Page 149 - 8.4.1.2 Example 2

ZyWALL 5/35/70 Series User’s Guide232 Chapter 11 Firewall11.8 Firewall Default Rule (Bridge Mode) Click SECURITY > FIREWALL to open the Default R

Page 150 - 8.4.3 Spillover

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 233The following table describes the labels in this screen. Table 67 SECURITY > FIREWALL

Page 151 - 8.6 WAN General

ZyWALL 5/35/70 Series User’s Guide234 Chapter 11 Firewall11.9 Firewall Rule Summary Click SECURITY > FIREWALL > Rule Summary to open the screen

Page 152 - 152 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 23511.9.1 Firewall Edit Rule Follow these directions to create a new rule.1 In the Rule Sum

Page 153 - Chapter 8 WAN Screens 153

ZyWALL 5/35/70 Series User’s Guide236 Chapter 11 FirewallFigure 118 SECURITY > FIREWALL > Rule Summary > Edit

Page 154 - 154 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 237The following table describes the labels in this screen. Table 69 SECURITY > FIREWALL

Page 155 - 8.7.1 Least Load First

ZyWALL 5/35/70 Series User’s Guide238 Chapter 11 Firewall11.10 Anti-Probing Click SECURITY > FIREWALL > Anti-Probing to open the following s

Page 156 - 8.7.2 Weighted Round Robin

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 239The following table describes the labels in this screen. 11.11 Firewall Thresholds For Do

Page 157 - 8.8 WAN Route

ZyWALL 5/35/70 Series User’s Guide24 Table of Contents31.5.2 Time Server Synchronization ...

Page 158 - 158 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s Guide240 Chapter 11 Firewall11.11.1 Threshold ValuesIf everything is working properly, you probably do not need to chang

Page 159 - Chapter 8 WAN Screens 159

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 241The following table describes the labels in this screen. Table 71 SECURITY > FIREWALL &g

Page 160 - 8.12 WAN

ZyWALL 5/35/70 Series User’s Guide242 Chapter 11 Firewall11.13 Service Click SECURITY > FIREWALL > Service to open the screen as shown next. Us

Page 161 - Chapter 8 WAN Screens 161

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 243Figure 122 SECURITY > FIREWALL > ServiceThe following table describes the labels in t

Page 162 - 162 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s Guide244 Chapter 11 Firewall11.13.1 Firewall Edit Custom Service Click SECURITY > FIREWALL > Service > Add to d

Page 163 - 8.12.2 PPPoE Encapsulation

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 24511.14 My Service Firewall Rule ExampleThe following Internet firewall rule example allows a

Page 164 - 164 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s Guide246 Chapter 11 FirewallFigure 125 My Service Firewall Rule Example: Edit Custom Service 3 Click Rule Summary. Sele

Page 165 - Chapter 8 WAN Screens 165

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 247Figure 127 My Service Firewall Rule Example: Rule Edit 9 In the Edit Rule screen, use the a

Page 166 - 8.12.3 PPTP Encapsulation

ZyWALL 5/35/70 Series User’s Guide248 Chapter 11 FirewallFigure 128 My Service Firewall Rule Example: Rule ConfigurationRule 1 allows a My Service c

Page 167 - Chapter 8 WAN Screens 167

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall 249Figure 129 My Service Firewall Rule Example: Rule Summary

Page 168 - 168 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s GuideTable of Contents 25Chapter 35LAN Setup...

Page 169 - Chapter 8 WAN Screens 169

ZyWALL 5/35/70 Series User’s Guide250 Chapter 11 Firewall

Page 170 - 8.13 Traffic Redirect

ZyWALL 5/35/70 Series User’s GuideChapter 12 Intrusion Detection and Prevention (IDP) 251CHAPTER 12Intrusion Detection andPrevention (IDP)This chapter

Page 171 - 8.15 Configuring Dial Backup

ZyWALL 5/35/70 Series User’s Guide252 Chapter 12 Intrusion Detection and Prevention (IDP)Firewalls are usually deployed at the network edge. However,

Page 172 - 172 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 12 Intrusion Detection and Prevention (IDP) 25312.1.5 Example IntrusionsThe following are some examples of

Page 173 - Chapter 8 WAN Screens 173

ZyWALL 5/35/70 Series User’s Guide254 Chapter 12 Intrusion Detection and Prevention (IDP)12.1.5.4 MyDoomMyDoom W32.Mydoom.A@mm (also known as W32.Nov

Page 174 - 174 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 255CHAPTER 13Configuring IDPThis chapter shows you how to configure IDP on the ZyWALL. 13

Page 175 - 8.16 Advanced Modem Setup

ZyWALL 5/35/70 Series User’s Guide256 Chapter 13 Configuring IDP13.2 General SetupUse this screen to enable IDP on the ZyWALL and choose what traffic

Page 176 - 176 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 25713.3 IDP SignaturesThe rules that define how to identify and respond to intrusions ar

Page 177 - Chapter 8 WAN Screens 177

ZyWALL 5/35/70 Series User’s Guide258 Chapter 13 Configuring IDPTo see signatures listed by intrusion type supported by the ZyWALL, select that type f

Page 178 - 178 Chapter 8 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 25913.3.2 Intrusion SeverityIntrusions are assigned a severity level based on the follow

Page 179 - CHAPTER 9

ZyWALL 5/35/70 Series User’s Guide26 Table of Contents40.3 Remote Node Profile Setup ...

Page 180 - DMZ are on separate subnets

ZyWALL 5/35/70 Series User’s Guide260 Chapter 13 Configuring IDPFigure 134 SECURITY > IDP > Signature: Actions The following table describes s

Page 181 - Chapter 9 DMZ Screens 181

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 261Figure 135 SECURITY > IDP > Signature: Group ViewThe following table describes

Page 182 - 9.3 DMZ Static DHCP

ZyWALL 5/35/70 Series User’s Guide262 Chapter 13 Configuring IDP13.3.5 Query View Click IDP > Signature to see the ZyWALL’s “group view” signature

Page 183 - 9.4 DMZ IP Alias

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 263Figure 136 SECURITY > IDP > Signature: Query ViewThe following table describes

Page 184 - 184 Chapter 9 DMZ Screens

ZyWALL 5/35/70 Series User’s Guide264 Chapter 13 Configuring IDPSearch Click this button to begin the search. The results display at the bottom of the

Page 185 - Chapter 9 DMZ Screens 185

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 26513.3.5.1 Query Example 11 From the “group view” signature screen, click the Switch to

Page 186 - 186 Chapter 9 DMZ Screens

ZyWALL 5/35/70 Series User’s Guide266 Chapter 13 Configuring IDPFigure 138 SECURITY > IDP > Signature: Query by Complete ID13.3.5.2 Query Exa

Page 187 - 9.7 DMZ Port Roles

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 267Figure 139 Signature Query by Attribute. 13.4 Update The ZyWALL comes with built-in

Page 188 - 188 Chapter 9 DMZ Screens

ZyWALL 5/35/70 Series User’s Guide268 Chapter 13 Configuring IDP13.4.2 Configuring IDP UpdateWhen scheduling signature updates, you should choose a d

Page 189 - CHAPTER 10

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 26913.5 Backup and RestoreYou can change the pre-defined Active, Log, Alert and/or Actio

Page 190

ZyWALL 5/35/70 Series User’s GuideTable of Contents 2744.2 Configuring a Filter Set ...

Page 191 - Chapter 10 Wireless LAN 191

ZyWALL 5/35/70 Series User’s Guide270 Chapter 13 Configuring IDPFigure 141 SECURITY > IDP > Backup & RestoreUse the Backup & Restore s

Page 192 - 10.3 WLAN Static DHCP

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 271CHAPTER 14Anti-VirusThis chapter introduces and shows you how to configure the anti-virus s

Page 193 - 10.4 WLAN IP Alias

ZyWALL 5/35/70 Series User’s Guide272 Chapter 14 Anti-Virus2 The virus spreads to other files and programs on the computer. 3 The infected files are u

Page 194 - 194 Chapter 10 Wireless LAN

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 27314.2.1 How the ZyWALL Anti-Virus Scanner WorksThe ZyWALL checks traffic going in the dire

Page 195 - 10.5 WLAN Port Roles

ZyWALL 5/35/70 Series User’s Guide274 Chapter 14 Anti-VirusNote: Turn the ZyWALL off before you install or remove the ZyWALL Turbo card. Note: The Zy

Page 196 - 196 Chapter 10 Wireless LAN

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 275Figure 143 SECURITY > ANTI-VIRUS > General The following table describes the labels

Page 197 - 10.6 Wireless Security

ZyWALL 5/35/70 Series User’s Guide276 Chapter 14 Anti-Virus14.4 Signature SearchingClick SECURITY > ANTI-VIRUS > Signature to display this scre

Page 198 - 10.6.2 Authentication

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 277Figure 144 SECURITY > ANTI-VIRUS > Signature: Query ViewThe following table describ

Page 199 - 10.8 WEP Encryption

ZyWALL 5/35/70 Series User’s Guide278 Chapter 14 Anti-Virus14.4.1 Signature Search ExampleThis example shows a search for signatures that are enabled

Page 200 - 10.9 802.1x Overview

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 279Figure 145 Query Example Search Criteria

Page 201 - Chapter 10 Wireless LAN 201

ZyWALL 5/35/70 Series User’s Guide28 Table of Contents47.3.4 GUI-based FTP Clients ...

Page 202 - 10.11 Introduction to WPA

ZyWALL 5/35/70 Series User’s Guide280 Chapter 14 Anti-VirusFigure 146 Query Example Search Results

Page 203 - Chapter 10 Wireless LAN 203

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 28114.5 Signature Update The ZyWALL comes with built-in signatures created by the ZyXEL Secu

Page 204 - 10.13 Introduction to RADIUS

ZyWALL 5/35/70 Series User’s Guide282 Chapter 14 Anti-VirusFigure 147 SECURITY > ANTI-VIRUS > UpdateThe following table describes the labels i

Page 205 - 10.16 Wireless Card

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 28314.6 Backup and Restore Click ANTI-VIRUS > Backup & Restore. The screen displays a

Page 206 - 206 Chapter 10 Wireless LAN

ZyWALL 5/35/70 Series User’s Guide284 Chapter 14 Anti-VirusUse the Backup & Restore screen to:• Back up anti-virus signatures with your custom con

Page 207 - 10.16.1 Static WEP

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 285CHAPTER 15Anti-SpamThis chapter covers how to use the ZyWALL’s anti-spam feature to deal wit

Page 208 - 10.16.2 WPA-PSK

ZyWALL 5/35/70 Series User’s Guide286 Chapter 15 Anti-Spam15.1.1.1 SpamBulk EngineThe e-mail fingerprint ID that the ZyWALL generates and sends to th

Page 209 - Chapter 10 Wireless LAN 209

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 28715.1.1.4 SpamTricks EngineThe SpamTricks engine checks for the tactics that spammers use to

Page 210 - 10.16.3 WPA

ZyWALL 5/35/70 Series User’s Guide288 Chapter 15 Anti-SpamThe anti-spam external database checks for spoofing of e-mail attributes (like the IP addres

Page 211 - Chapter 10 Wireless LAN 211

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 28915.1.7 MIME HeadersMIME (Multipurpose Internet Mail Extensions) allows varied media types t

Page 212 - 212 Chapter 10 Wireless LAN

ZyWALL 5/35/70 Series User’s GuideTable of Contents 2950.3 IP Policy Routing Example ...

Page 213 - Chapter 10 Wireless LAN 213

ZyWALL 5/35/70 Series User’s Guide290 Chapter 15 Anti-SpamFigure 150 SECURITY > ANTI-SPAM > GeneralThe following table describes the labels in

Page 214 - 10.16.6 IEEE 802.1x + No WEP

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 291From, To Select the directions of travel of packets that you want to check. Select or clear

Page 215 - Chapter 10 Wireless LAN 215

ZyWALL 5/35/70 Series User’s Guide292 Chapter 15 Anti-Spam15.3 Anti-Spam External DB Screen Click SECURITY > ANTI-SPAM > External DB to dis

Page 216 - 216 Chapter 10 Wireless LAN

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 293The following table describes the labels in this screen. Table 85 SECURITY > ANTI-SPAM

Page 217 - 10.17 MAC Filter

ZyWALL 5/35/70 Series User’s Guide294 Chapter 15 Anti-Spam15.4 Anti-Spam Lists Screen Click SECURITY > ANTI-SPAM > Lists to display the Anti-S

Page 218 - 218 Chapter 10 Wireless LAN

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 295Figure 152 SECURITY > ANTI-SPAM > ListsThe following table describes the labels in t

Page 219 - CHAPTER 11

ZyWALL 5/35/70 Series User’s Guide296 Chapter 15 Anti-Spam15.5 Anti-Spam Lists Edit Screen Click SECURITY > ANTI-SPAM > Lists to display the

Page 220 - 11.2 Packet Direction Matrix

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 297Figure 153 SECURITY > ANTI-SPAM > Lists > Edit The following table describes the

Page 221 - Chapter 11 Firewall 221

ZyWALL 5/35/70 Series User’s Guide298 Chapter 15 Anti-SpamE-Mail Address This field displays when you select the E-Mail type. Enter an e-mail address

Page 222 - 222 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 299CHAPTER 16Content Filtering ScreensThis chapter provides an overview of cont

Page 223 - Chapter 11 Firewall 223

ZyWALL 5/35/70 Series User’s GuideCopyright 3CopyrightCopyright © 2006 by ZyXEL Communications Corporation.The contents of this publication may not be

Page 224 - 224 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s Guide30 Table of ContentsImporting Certificates...

Page 225 - Chapter 11 Firewall 225

ZyWALL 5/35/70 Series User’s Guide300 Chapter 16 Content Filtering ScreensFigure 154 SECURITY > CONTENT FILTER > GeneralThe following table de

Page 226 - 11.4 Security Considerations

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 301Restrict Web Features Select the check box(es) to restrict a feature. When

Page 227 - 11.5 Firewall Rules Example

ZyWALL 5/35/70 Series User’s Guide302 Chapter 16 Content Filtering Screens16.3 Content Filtering with an External DatabaseWhen you register for and e

Page 228 - 228 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 3035 The external content filtering server sends the category information back

Page 229 - 11.6 Asymmetrical Routes

ZyWALL 5/35/70 Series User’s Guide304 Chapter 16 Content Filtering ScreensFigure 156 SECURITY > CONTENT FILTER > CategoriesThe following table

Page 230 - 230 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 305Unrated Web Pages Select Block to prevent users from accessing web pages tha

Page 231 - Chapter 11 Firewall 231

ZyWALL 5/35/70 Series User’s Guide306 Chapter 16 Content Filtering ScreensNudity Selecting this category excludes pages containing nude or seminude de

Page 232 - 232 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 307Illegal Drugs Selecting this category excludes pages that promote, offer, se

Page 233 - (VPN pass-through traffic)

ZyWALL 5/35/70 Series User’s Guide308 Chapter 16 Content Filtering ScreensWeb Communications Selecting this category excludes pages that allow or offe

Page 234 - 11.9 Firewall Rule Summary

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 309Vehicles Selecting this category excludes pages that provide information on

Page 235 - Chapter 11 Firewall 235

ZyWALL 5/35/70 Series User’s GuideList of Figures 31List of FiguresFigure 1 Secure Internet Access via Cable, DSL or Wireless Modem ...

Page 236 - 236 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s Guide310 Chapter 16 Content Filtering Screens16.5 Content Filter Customization Click SECURITY > CONTENT FILTER >

Page 237 - Chapter 11 Firewall 237

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 311The following table describes the labels in this screen. Table 90 SECURITY

Page 238 - 11.10 Anti-Probing

ZyWALL 5/35/70 Series User’s Guide312 Chapter 16 Content Filtering Screens16.6 Customizing Keyword Blocking URL CheckingYou can use commands to set h

Page 239 - 11.11 Firewall Thresholds

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 313Use the ip urlfilter customize actionFlags 8 [disable | enable] command to e

Page 240 - 11.12 Threshold Screen

ZyWALL 5/35/70 Series User’s Guide314 Chapter 16 Content Filtering ScreensThe following table describes the labels in this screen. Table 91 SECURI

Page 241 - Chapter 11 Firewall 241

ZyWALL 5/35/70 Series User’s GuideChapter 17 Content Filtering Reports 315CHAPTER 17Content Filtering ReportsThis chapter describes how to view conten

Page 242 - 11.13 Service

ZyWALL 5/35/70 Series User’s Guide316 Chapter 17 Content Filtering ReportsFigure 159 myZyXEL.com: Login3 A welcome screen displays. Click your ZyWAL

Page 243 - Chapter 11 Firewall 243

ZyWALL 5/35/70 Series User’s GuideChapter 17 Content Filtering Reports 317Figure 161 myZyXEL.com: Service Management5 Enter your ZyXEL device's

Page 244 - 244 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s Guide318 Chapter 17 Content Filtering ReportsFigure 163 Content Filtering Reports Main Screen8 Select items under Globa

Page 245 - Chapter 11 Firewall 245

ZyWALL 5/35/70 Series User’s GuideChapter 17 Content Filtering Reports 319Figure 165 Global Report Screen Example11You can click a category in the C

Page 246 - 246 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s Guide32 List of FiguresFigure 39 Firewall Rule for VPN ...

Page 247 - Chapter 11 Firewall 247

ZyWALL 5/35/70 Series User’s Guide320 Chapter 17 Content Filtering ReportsFigure 166 Requested URLs Example17.3 Web Site SubmissionYou may find tha

Page 248 - 10.0.0.15 on the LAN

ZyWALL 5/35/70 Series User’s GuideChapter 17 Content Filtering Reports 321Figure 167 Web Page Review Process Screen3 Type the web site’s URL in the

Page 249 - Chapter 11 Firewall 249

ZyWALL 5/35/70 Series User’s Guide322 Chapter 17 Content Filtering Reports

Page 250 - 250 Chapter 11 Firewall

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 323CHAPTER 18IPSec VPNThis chapter explains how to set up and maintain IPSec VPNs in the ZyWALL

Page 251 - CHAPTER 12

ZyWALL 5/35/70 Series User’s Guide324 Chapter 18 IPSec VPNA VPN tunnel is usually established in two phases. Each phase establishes a security associa

Page 252 - 12.1.4 Network IDP

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 325You can usually provide a static IP address or a domain name for the ZyWALL. Sometimes, your

Page 253 - 12.1.5 Example Intrusions

ZyWALL 5/35/70 Series User’s Guide326 Chapter 18 IPSec VPNFigure 172 SECURITY > VPN > VPN Rules (IKE) The following table describes the label

Page 254 - 12.1.6 ZyWALL IDP

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 32718.3 IKE SA Setup This section provides more details about IKE SAs.18.3.1 IKE SA Proposa

Page 255 - CHAPTER 13

ZyWALL 5/35/70 Series User’s Guide328 Chapter 18 IPSec VPNSee the field descriptions for information about specific encryption algorithms, authenticat

Page 256 - 13.2 General Setup

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 329Router identity consists of ID type and ID content. The ID type can be IP address, domain na

Page 257 - 13.3 IDP Signatures

ZyWALL 5/35/70 Series User’s GuideList of Figures 33Figure 82 DMZ Private and Public Address Example ...

Page 258 - Attack Type list box

ZyWALL 5/35/70 Series User’s Guide330 Chapter 18 IPSec VPN• The local ID type and ID content come from the certificate. On the ZyWALL, you simply sele

Page 259 - 13.3.3 Signature Actions

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 331Step 2: The remote IPSec router selects an acceptable proposal and sends it back to the ZyWA

Page 260

ZyWALL 5/35/70 Series User’s Guide332 Chapter 18 IPSec VPN18.4 Additional IPSec VPN TopicsThis section discusses other IPSec VPN topics that apply to

Page 261

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 333Figure 177 IPSec High AvailabilityWhen setting up a IPSec high availability VPN tunnel, th

Page 262 - 13.3.5 Query View

ZyWALL 5/35/70 Series User’s Guide334 Chapter 18 IPSec VPN18.5 VPN Rules (IKE) Gateway Policy Edit In the VPN Rule (IKE) screen, click the add gatew

Page 263

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 335Figure 178 SECURITY > VPN > VPN Rules (IKE) > Edit Gateway Policy

Page 264

ZyWALL 5/35/70 Series User’s Guide336 Chapter 18 IPSec VPNThe following table describes the labels in this screen. Table 95 SECURITY > VPN > V

Page 265 - 13.3.5.1 Query Example 1

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 337Fall back to Primary Remote Gateway when possibleSelect this to have the ZyWALL change back

Page 266 - 13.3.5.2 Query Example 2

ZyWALL 5/35/70 Series User’s Guide338 Chapter 18 IPSec VPNPeer ID Type Select from the following when you set Authentication Key to Pre-shared Key.Sel

Page 267 - 13.4 Update

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 339Server Mode Select Server Mode to have this ZyWALL authenticate extended authentication clie

Page 268

ZyWALL 5/35/70 Series User’s Guide34 List of FiguresFigure 125 My Service Firewall Rule Example: Edit Custom Service ...

Page 269 - 13.5 Backup and Restore

ZyWALL 5/35/70 Series User’s Guide340 Chapter 18 IPSec VPN18.6 IPSec SA Overview Once the ZyWALL and remote IPSec router have established the IKE

Page 270

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 341Usually, you should select ESP. AH does not support encryption, and ESP is more suitable wit

Page 271 - CHAPTER 14

ZyWALL 5/35/70 Series User’s Guide342 Chapter 18 IPSec VPNIf you enable PFS, the ZyWALL and remote IPSec router perform a DH key exchange every time a

Page 272 - 272 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 343Figure 180 SECURITY > VPN > VPN Rules (IKE) > Edit Network Policy

Page 273 - Chapter 14 Anti-Virus 273

ZyWALL 5/35/70 Series User’s Guide344 Chapter 18 IPSec VPNThe following table describes the labels in this screen. Table 96 SECURITY > VPN > V

Page 274 - 274 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 345Starting IP Address When the Address Type field is configured to Single Address, enter a (st

Page 275 - Chapter 14 Anti-Virus 275

ZyWALL 5/35/70 Series User’s Guide346 Chapter 18 IPSec VPN18.8 VPN Rules (IKE): Network Policy Move Click the move ( ) icon in the VPN Rules (IKE)

Page 276 - 14.4 Signature Searching

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 347• The gateway policy contains the IKE SA settings. It identifies the IPSec routers at either

Page 277 - Chapter 14 Anti-Virus 277

ZyWALL 5/35/70 Series User’s Guide348 Chapter 18 IPSec VPN18.9 IPSec SA Using Manual Keys You might set up an IPSec SA using manual keys when you

Page 278 - 278 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 349Figure 182 SECURITY > VPN > VPN Rules (Manual) The following table describes the lab

Page 279 - Chapter 14 Anti-Virus 279

ZyWALL 5/35/70 Series User’s GuideList of Figures 35Figure 168 VPN: Example ...

Page 280 - 280 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s Guide350 Chapter 18 IPSec VPN18.11 VPN Rules (Manual): Edit Click the edit icon on the VPN Rules (Manual) screen to op

Page 281 - 14.5 Signature Update

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 351The following table describes the labels in this screen. Table 99 SECURITY > VPN > V

Page 282 - 282 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s Guide352 Chapter 18 IPSec VPNEnding IP Address/Subnet MaskWhen the Address Type field is configured to Single Address, th

Page 283 - 14.6 Backup and Restore

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 35318.12 VPN SA Monitor In the web configurator, click SECURITY > VPN > SA Monitor. Use

Page 284 - 284 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s Guide354 Chapter 18 IPSec VPN18.13 VPN Global Setting Click SECURITY > VPN > Global Setting to open the VPN Global

Page 285 - CHAPTER 15

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 35518.14 Telecommuter VPN/IPSec ExamplesThe following examples show how multiple telecommuters

Page 286 - 15.1.1.3 SpamContent Engine

ZyWALL 5/35/70 Series User’s Guide356 Chapter 18 IPSec VPNFigure 186 Telecommuters Sharing One VPN Rule Example18.14.2 Telecommuters Using Unique V

Page 287 - 15.1.3 Phishing

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 357The ZyWALL at headquarters can also initiate VPN connections to the telecommuters since it c

Page 288 - 15.1.6 SMTP and POP3

ZyWALL 5/35/70 Series User’s Guide358 Chapter 18 IPSec VPN18.15 VPN and Remote ManagementYou can allow someone to use a service (like Telnet or HTTP)

Page 289 - 15.1.7 MIME Headers

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 359Figure 189 VPN TopologiesHub-and-spoke VPN reduces the number of VPN connections that you

Page 290 - 290 Chapter 15 Anti-Spam

ZyWALL 5/35/70 Series User’s Guide36 List of FiguresFigure 211 NAT Application With IP Alias ...

Page 291 - Chapter 15 Anti-Spam 291

ZyWALL 5/35/70 Series User’s Guide360 Chapter 18 IPSec VPNFigure 190 Hub-and-spoke VPN Example18.16.2 Hub-and-spoke Example VPN Rule AddressesThe V

Page 292 - 292 Chapter 15 Anti-Spam

ZyWALL 5/35/70 Series User’s GuideChapter 18 IPSec VPN 36118.16.3 Hub-and-spoke VPN Requirements and SuggestionsConsider the following when implement

Page 293 - Chapter 15 Anti-Spam 293

ZyWALL 5/35/70 Series User’s Guide362 Chapter 18 IPSec VPN

Page 294 - 294 Chapter 15 Anti-Spam

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 363CHAPTER 19CertificatesThis chapter gives background information about public-key certific

Page 295 - Chapter 15 Anti-Spam 295

ZyWALL 5/35/70 Series User’s Guide364 Chapter 19 CertificatesCertification authorities maintain directory servers with databases of valid and revoked

Page 296 - 296 Chapter 15 Anti-Spam

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 365Figure 192 Certificate Details 4 Use a secure method to verify that the certificate own

Page 297 - Chapter 15 Anti-Spam 297

ZyWALL 5/35/70 Series User’s Guide366 Chapter 19 CertificatesUse the Directory Servers screen to configure a list of addresses of directory servers (t

Page 298 - 298 Chapter 15 Anti-Spam

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 367Type This field displays what kind of certificate this is. REQ represents a certification

Page 299 - CHAPTER 16

ZyWALL 5/35/70 Series User’s Guide368 Chapter 19 Certificates19.6 My Certificate Details Click SECURITY > CERTIFICATES > My Certificates to op

Page 300

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 369The following table describes the labels in this screen. Table 105 SECURITY > CERTI

Page 301

ZyWALL 5/35/70 Series User’s GuideList of Figures 37Figure 254 Secure FTP: Firmware Upload Example ...

Page 302

ZyWALL 5/35/70 Series User’s Guide370 Chapter 19 Certificates19.7 My Certificate Export Click SECURITY > CERTIFICATES > My Certificates and th

Page 303

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 371Figure 196 SECURITY > CERTIFICATES > My Certificates > ExportThe following tab

Page 304

ZyWALL 5/35/70 Series User’s Guide372 Chapter 19 CertificatesNote: You can only import a certificate that matches a corresponding certification reques

Page 305

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 373Figure 197 SECURITY > CERTIFICATES > My Certificates > ImportThe following tab

Page 306

ZyWALL 5/35/70 Series User’s Guide374 Chapter 19 CertificatesThe following table describes the labels in this screen. 19.9 My Certificate Create Cli

Page 307

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 375The following table describes the labels in this screen. Table 109 SECURITY > CERTIF

Page 308

ZyWALL 5/35/70 Series User’s Guide376 Chapter 19 CertificatesAfter you click Apply in the My Certificate Create screen, you see a screen that tells yo

Page 309

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 377Figure 200 SECURITY > CERTIFICATES > Trusted CAsThe following table describes the

Page 310 - FILTER Customization screen

ZyWALL 5/35/70 Series User’s Guide378 Chapter 19 Certificates19.11 Trusted CA Details Click SECURITY > CERTIFICATES > Trusted CAs to open the

Page 311

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 379Figure 201 SECURITY > CERTIFICATES > Trusted CAs > DetailsThe following table

Page 312

ZyWALL 5/35/70 Series User’s Guide38 List of FiguresFigure 297 Firmware Upload Error ...

Page 313

ZyWALL 5/35/70 Series User’s Guide380 Chapter 19 CertificatesCertification Path Click the Refresh button to have this read-only text box display the e

Page 314

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 38119.12 Trusted CA Import Click SECURITY > CERTIFICATES > Trusted CAs to open the

Page 315 - CHAPTER 17

ZyWALL 5/35/70 Series User’s Guide382 Chapter 19 CertificatesFigure 202 SECURITY > CERTIFICATES > Trusted CAs > ImportThe following table d

Page 316

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 383Figure 203 SECURITY > CERTIFICATES > Trusted Remote HostsThe following table desc

Page 317 - 6 Click Submit

ZyWALL 5/35/70 Series User’s Guide384 Chapter 19 Certificates19.14 Trusted Remote Hosts Import Click SECURITY > CERTIFICATES > Trusted Remote

Page 318

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 385The following table describes the labels in this screen. 19.15 Trusted Remote Host Certi

Page 319

ZyWALL 5/35/70 Series User’s Guide386 Chapter 19 CertificatesFigure 205 SECURITY > CERTIFICATES > Trusted Remote Hosts > DetailsThe followi

Page 320 - 17.3 Web Site Submission

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 387Type This field displays general information about the certificate. With trusted remote h

Page 321

ZyWALL 5/35/70 Series User’s Guide388 Chapter 19 Certificates19.16 Directory Servers Click SECURITY > CERTIFICATES > Directory Servers to open

Page 322

ZyWALL 5/35/70 Series User’s GuideChapter 19 Certificates 389The following table describes the labels in this screen. 19.17 Directory Server Add or

Page 323 - CHAPTER 18

ZyWALL 5/35/70 Series User’s GuideList of Figures 39Figure 340 Menu 7.1.1: WLAN MAC Address Filter ...

Page 324 - 18.1.1 IKE SA Overview

ZyWALL 5/35/70 Series User’s Guide390 Chapter 19 CertificatesThe following table describes the labels in this screen. Table 117 SECURITY > CERTIF

Page 325 - 18.2 VPN Rules (IKE)

ZyWALL 5/35/70 Series User’s GuideChapter 20 Authentication Server 391CHAPTER 20Authentication ServerThis chapter discusses how to configure the ZyWAL

Page 326 - 326 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s Guide392 Chapter 20 Authentication ServerFigure 208 SECURITY > AUTH SERVER > Local User Database

Page 327 - 18.3 IKE SA Setup

ZyWALL 5/35/70 Series User’s GuideChapter 20 Authentication Server 393The following table describes the labels in this screen. 20.3 RADIUS Click

Page 328 - 18.3.1.2 Authentication

ZyWALL 5/35/70 Series User’s Guide394 Chapter 20 Authentication ServerThe following table describes the labels in this screen. Table 119 SECURITY &

Page 329 - Chapter 18 IPSec VPN 329

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 395CHAPTER 21Network Address Translation(NAT)This chapter discusses how

Page 330 - 18.3.1.4 Negotiation Mode

ZyWALL 5/35/70 Series User’s Guide396 Chapter 21 Network Address Translation (NAT)21.1.2 What NAT DoesIn the simplest form, NAT changes the source IP

Page 331 - Figure 176 VPN/NAT Example

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 39721.1.4 NAT ApplicationThe following figure illustrates a possible N

Page 332 - 18.4.1 SA Life Time

ZyWALL 5/35/70 Series User’s Guide398 Chapter 21 Network Address Translation (NAT)21.1.5 Port Restricted Cone NATZyWALL ZyNOS version 4.00 and later

Page 333 - Chapter 18 IPSec VPN 333

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 399• Server: This type allows you to specify inside servers of differen

Page 334 - 334 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s Guide4 CertificationsCertificationsFederal Communications Commission (FCC) Interference StatementThe device complies with

Page 335 - Chapter 18 IPSec VPN 335

ZyWALL 5/35/70 Series User’s Guide40 List of FiguresFigure 382 Filter Rule Process ...

Page 336 - 336 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s Guide400 Chapter 21 Network Address Translation (NAT)21.3 NAT Overview Screen Click ADVANCED > NAT to open the NAT O

Page 337 - Chapter 18 IPSec VPN 337

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 40121.4 NAT Address Mapping Click ADVANCED > NAT > Address Map

Page 338 - 338 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s Guide402 Chapter 21 Network Address Translation (NAT)Figure 214 ADVANCED > NAT > Address MappingThe following tab

Page 339 - Chapter 18 IPSec VPN 339

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 40321.4.1 NAT Address Mapping Edit Click the Edit button to display t

Page 340 - 18.6 IPSec SA Overview

ZyWALL 5/35/70 Series User’s Guide404 Chapter 21 Network Address Translation (NAT)The following table describes the labels in this screen. 21.5 Port

Page 341 - 18.6.0.3 Encapsulation

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 40521.5.1 Default Server IP AddressIn addition to the servers for spec

Page 342 - 342 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s Guide406 Chapter 21 Network Address Translation (NAT)Figure 216 Multiple Servers Behind NAT Example21.5.4 NAT and Mult

Page 343 - Chapter 18 IPSec VPN 343

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 407Figure 217 Port Translation Example21.6 Port Forwarding Screen Cl

Page 344 - 344 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s Guide408 Chapter 21 Network Address Translation (NAT)Figure 218 ADVANCED > NAT > Port ForwardingThe following tab

Page 345 - Chapter 18 IPSec VPN 345

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 40921.7 Port Triggering Some services use a dedicated range of ports

Page 346 - Network Policy Move screen

ZyWALL 5/35/70 Series User’s GuideList of Figures 41Figure 425 Example Xmodem Upload ...

Page 347 - Chapter 18 IPSec VPN 347

ZyWALL 5/35/70 Series User’s Guide410 Chapter 21 Network Address Translation (NAT)4 The ZyWALL forwards the traffic to Jane’s computer IP address. 5 O

Page 348 - 18.10 VPN Rules (Manual)

ZyWALL 5/35/70 Series User’s GuideChapter 21 Network Address Translation (NAT) 411End Port Type a port number or the ending port number in a range of

Page 349 - Chapter 18 IPSec VPN 349

ZyWALL 5/35/70 Series User’s Guide412 Chapter 21 Network Address Translation (NAT)

Page 350 - 350 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s GuideChapter 22 Static Route 413CHAPTER 22Static RouteThis chapter shows you how to configure static routes for your ZyWA

Page 351 - Chapter 18 IPSec VPN 351

ZyWALL 5/35/70 Series User’s Guide414 Chapter 22 Static RouteFigure 222 ADVANCED > STATIC ROUTE > IP Static RouteThe following table describes

Page 352 - 352 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s GuideChapter 22 Static Route 41522.2.1 IP Static Route Edit Select a static route index number and click Edit. The scr

Page 353 - 18.12 VPN SA Monitor

ZyWALL 5/35/70 Series User’s Guide416 Chapter 22 Static RouteMetric Metric represents the “cost” of transmission for routing purposes. IP routing uses

Page 354 - 18.13 VPN Global Setting

ZyWALL 5/35/70 Series User’s GuideChapter 23 Policy Route 417CHAPTER 23Policy RouteThis chapter covers setting and applying policies used for IP routi

Page 355 - Chapter 18 IPSec VPN 355

ZyWALL 5/35/70 Series User’s Guide418 Chapter 23 Policy RouteIPPR follows the existing packet filtering facility of RAS in style and in implementation

Page 356 - 356 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s GuideChapter 23 Policy Route 419The following table describes the labels in this screen. 23.5 Policy Route Edit Click AD

Page 357 - Chapter 18 IPSec VPN 357

ZyWALL 5/35/70 Series User’s Guide42 List of FiguresFigure 468 Macintosh OS 8/9: Apple Menu ...

Page 358 - 18.16 Hub-and-spoke VPN

ZyWALL 5/35/70 Series User’s Guide420 Chapter 23 Policy RouteFigure 225 Edit IP Policy RouteThe following table describes the labels in this screen.

Page 359 - Figure 189 VPN Topologies

ZyWALL 5/35/70 Series User’s GuideChapter 23 Policy Route 421Packet Length Type a length of packet (in bytes). The operators in the Len Compare field

Page 360 - 360 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s Guide422 Chapter 23 Policy Route

Page 361 - Chapter 18 IPSec VPN 361

ZyWALL 5/35/70 Series User’s GuideChapter 24 Bandwidth Management 423CHAPTER 24Bandwidth ManagementThis chapter describes the functions and configurat

Page 362 - 362 Chapter 18 IPSec VPN

ZyWALL 5/35/70 Series User’s Guide424 Chapter 24 Bandwidth Management24.3 Proportional Bandwidth AllocationBandwidth management allows you to define

Page 363 - CHAPTER 19

ZyWALL 5/35/70 Series User’s GuideChapter 24 Bandwidth Management 42524.6 Application and Subnet-based Bandwidth ManagementYou could also create band

Page 364 - 19.3 Verifying a Certificate

ZyWALL 5/35/70 Series User’s Guide426 Chapter 24 Bandwidth ManagementWhen you enable maximize bandwidth usage, the ZyWALL first makes sure that each b

Page 365 - 19.4 Configuration Summary

ZyWALL 5/35/70 Series User’s GuideChapter 24 Bandwidth Management 42724.7.5.1 Priority-based Allotment of Unused and Unbudgeted BandwidthThe followin

Page 366 - 19.5 My Certificates

ZyWALL 5/35/70 Series User’s Guide428 Chapter 24 Bandwidth Management24.8 Bandwidth BorrowingBandwidth borrowing allows a sub-class to borrow unused

Page 367 - Chapter 19 Certificates 367

ZyWALL 5/35/70 Series User’s GuideChapter 24 Bandwidth Management 429• The Bill class cannot borrow unused bandwidth from the Root class because the S

Page 368 - 368 Chapter 19 Certificates

ZyWALL 5/35/70 Series User’s GuideList of Figures 43Figure 511 Certificate Import Wizard 2 ...

Page 369 - Chapter 19 Certificates 369

ZyWALL 5/35/70 Series User’s Guide430 Chapter 24 Bandwidth ManagementIf you use VoIP and NetMeeting at the same time, the device allocates up to 500 K

Page 370 - 19.7 My Certificate Export

ZyWALL 5/35/70 Series User’s GuideChapter 24 Bandwidth Management 43124.12 Configuring Class Setup The Class Setup screen displays the configured ba

Page 371 - 19.8 My Certificate Import

ZyWALL 5/35/70 Series User’s Guide432 Chapter 24 Bandwidth ManagementFigure 228 ADVANCED > BW MGMT > Class SetupThe following table describes

Page 372 - 372 Chapter 19 Certificates

ZyWALL 5/35/70 Series User’s GuideChapter 24 Bandwidth Management 43324.12.1 Bandwidth Manager Class Configuration Configure a bandwidth management

Page 373 - Chapter 19 Certificates 373

ZyWALL 5/35/70 Series User’s Guide434 Chapter 24 Bandwidth ManagementFigure 229 ADVANCED > BW MGMT > Class Setup > Add Sub-ClassThe followi

Page 374 - 19.9 My Certificate Create

ZyWALL 5/35/70 Series User’s GuideChapter 24 Bandwidth Management 435Enable Bandwidth Filter Select Enable Bandwidth Filter to have the ZyWALL use thi

Page 375 - Chapter 19 Certificates 375

ZyWALL 5/35/70 Series User’s Guide436 Chapter 24 Bandwidth Management24.12.2 Bandwidth Management Statistics Click ADVANCED > BW MGMT > Cl

Page 376 - 19.10 Trusted CAs

ZyWALL 5/35/70 Series User’s GuideChapter 24 Bandwidth Management 437Figure 230 ADVANCED > BW MGMT > Class Setup > Statistics The following

Page 377 - Chapter 19 Certificates 377

ZyWALL 5/35/70 Series User’s Guide438 Chapter 24 Bandwidth ManagementFigure 231 ADVANCED > BW MGMT > Monitor The following table describes the

Page 378 - 19.11 Trusted CA Details

ZyWALL 5/35/70 Series User’s GuideChapter 25 DNS 439CHAPTER 25DNSThis chapter shows you how to configure the DNS screens.25.1 DNS Overview DNS (Doma

Page 379 - Chapter 19 Certificates 379

ZyWALL 5/35/70 Series User’s Guide44 List of Figures

Page 380 - 380 Chapter 19 Certificates

ZyWALL 5/35/70 Series User’s Guide440 Chapter 25 DNS25.4 Address RecordAn address record contains the mapping of a fully qualified domain name (FQDN)

Page 381 - 19.12 Trusted CA Import

ZyWALL 5/35/70 Series User’s GuideChapter 25 DNS 441Figure 232 Private DNS Server ExampleNote: If you do not specify an Intranet DNS server on the r

Page 382 - 382 Chapter 19 Certificates

ZyWALL 5/35/70 Series User’s Guide442 Chapter 25 DNSThe following table describes the labels in this screen.25.6.1 Adding an Address Record Click Ad

Page 383 - Chapter 19 Certificates 383

ZyWALL 5/35/70 Series User’s GuideChapter 25 DNS 443An address record contains the mapping of a fully qualified domain name (FQDN) to an IP address. C

Page 384 - 384 Chapter 19 Certificates

ZyWALL 5/35/70 Series User’s Guide444 Chapter 25 DNSFigure 235 ADVANCED > DNS > Insert (Name Server Record)The following table describes the l

Page 385 - Chapter 19 Certificates 385

ZyWALL 5/35/70 Series User’s GuideChapter 25 DNS 44525.7 DNS Cache DNS cache is the temporary storage area where a router stores responses from DNS

Page 386 - 386 Chapter 19 Certificates

ZyWALL 5/35/70 Series User’s Guide446 Chapter 25 DNSThe following table describes the labels in this screen.25.9 Configuring DNS DHCP Click ADVANCED

Page 387 - Chapter 19 Certificates 387

ZyWALL 5/35/70 Series User’s GuideChapter 25 DNS 447Figure 237 ADVANCED > DNS > DHCPThe following table describes the labels in this screen.LA

Page 388 - 19.16 Directory Servers

ZyWALL 5/35/70 Series User’s Guide448 Chapter 25 DNS25.10 Dynamic DNS Dynamic DNS allows you to update your current dynamic IP address with one or m

Page 389 - Chapter 19 Certificates 389

ZyWALL 5/35/70 Series User’s GuideChapter 25 DNS 449Figure 238 ADVANCED > DNS > DDNSThe following table describes the labels in this screen.LA

Page 390 - 390 Chapter 19 Certificates

ZyWALL 5/35/70 Series User’s GuideList of Tables 45List of TablesTable 1 ZyWALL Model Specific Features ...

Page 391 - CHAPTER 20

ZyWALL 5/35/70 Series User’s Guide450 Chapter 25 DNSIP Address Update PolicySelect Use WAN IP Address to have the ZyWALL update the domain name with t

Page 392

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 451CHAPTER 26Remote ManagementThis chapter provides information on the Remote Managemen

Page 393 - 20.3 RADIUS

ZyWALL 5/35/70 Series User’s Guide452 Chapter 26 Remote Management2 The IP address in the Secure Client IP Address field does not match the client IP

Page 394

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 453Figure 239 HTTPS ImplementationNote: If you disable the HTTP service in the REMOTE

Page 395 - CHAPTER 21

ZyWALL 5/35/70 Series User’s Guide454 Chapter 26 Remote ManagementFigure 240 ADVANCED > REMOTE MGMT > WWWThe following table describes the lab

Page 396 - 21.1.3 How NAT Works

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 45526.4 HTTPS ExampleIf you haven’t changed the default HTTPS port on the ZyWALL, then

Page 397 - 21.1.4 NAT Application

ZyWALL 5/35/70 Series User’s Guide456 Chapter 26 Remote Management26.4.2 Netscape Navigator Warning MessagesWhen you attempt to access the ZyWALL HTT

Page 398 - 21.1.6 NAT Mapping Types

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 45726.4.3 Avoiding the Browser Warning MessagesThe following describes the main reason

Page 399 - 21.2 Using NAT

ZyWALL 5/35/70 Series User’s Guide458 Chapter 26 Remote ManagementFigure 244 Example: Lock Denoting a Secure ConnectionClick Login and you then see

Page 400 - 21.3 NAT Overview Screen

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 459Figure 246 Device-specific CertificateClick Ignore in the Replace Certificate scre

Page 401 - 21.4 NAT Address Mapping

ZyWALL 5/35/70 Series User’s Guide46 List of TablesTable 39 Example of Network Properties for LAN Servers with Fixed IP Addresses ... 160Table

Page 402

ZyWALL 5/35/70 Series User’s Guide460 Chapter 26 Remote ManagementFigure 248 SSH Communication Example26.6 How SSH Works The following table summa

Page 403

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 461After the identification is verified and data encryption activated, a secure tunnel

Page 404 - 21.5 Port Forwarding

ZyWALL 5/35/70 Series User’s Guide462 Chapter 26 Remote ManagementFigure 250 ADVANCED > REMOTE MGMT > SSHThe following table describes the lab

Page 405

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 4632 Configure the SSH client to accept connection using SSH version 1. 3 A window disp

Page 406 - 21.5.5 Port Translation

ZyWALL 5/35/70 Series User’s Guide464 Chapter 26 Remote ManagementFigure 253 SSH Example 2: Log in3 The SMT main menu displays next. 26.10 Secure F

Page 407 - 21.6 Port Forwarding Screen

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 465Figure 254 Secure FTP: Firmware Upload Example26.11 Telnet You can configure you

Page 408

ZyWALL 5/35/70 Series User’s Guide466 Chapter 26 Remote ManagementFigure 256 ADVANCED > REMOTE MGMT > TelnetThe following table describes the

Page 409 - 21.7 Port Triggering

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 467Figure 257 ADVANCED > REMOTE MGMT > FTPThe following table describes the lab

Page 410

ZyWALL 5/35/70 Series User’s Guide468 Chapter 26 Remote ManagementFigure 258 SNMP Management ModelAn SNMP managed network consists of two main types

Page 411

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 46926.14.1 Supported MIBsThe ZyWALL supports MIB II that is defined in RFC-1213 and R

Page 412

ZyWALL 5/35/70 Series User’s GuideList of Tables 47Table 82 SECURITY > ANTI-VIRUS > General ...

Page 413 - CHAPTER 22

ZyWALL 5/35/70 Series User’s Guide470 Chapter 26 Remote ManagementFigure 259 ADVANCED > REMOTE MGMT > SNMPThe following table describes the la

Page 414 - 414 Chapter 22 Static Route

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 47126.15 DNS Use DNS (Domain Name System) to map a domain name to its corresponding I

Page 415 - Chapter 22 Static Route 415

ZyWALL 5/35/70 Series User’s Guide472 Chapter 26 Remote ManagementIf you allow your ZyWALL to be managed by the Vantage CNM server, then you should no

Page 416 - 416 Chapter 22 Static Route

ZyWALL 5/35/70 Series User’s GuideChapter 26 Remote Management 473Last Registration Time This field displays the last date (year-month-date) and time

Page 417 - CHAPTER 23

ZyWALL 5/35/70 Series User’s Guide474 Chapter 26 Remote Management

Page 418 - 23.4 IP Routing Policy Setup

ZyWALL 5/35/70 Series User’s GuideChapter 27 UPnP 475CHAPTER 27UPnPThis chapter introduces the Universal Plug and Play feature. This chapter is only a

Page 419 - 23.5 Policy Route Edit

ZyWALL 5/35/70 Series User’s Guide476 Chapter 27 UPnPWhen a UPnP device joins a network, it announces its presence with a multicast message. For secur

Page 420 - 420 Chapter 23 Policy Route

ZyWALL 5/35/70 Series User’s GuideChapter 27 UPnP 47727.3 Displaying UPnP Port Mapping Click ADVANCED > UPnP > Ports to display the UPnP Port

Page 421 - Chapter 23 Policy Route 421

ZyWALL 5/35/70 Series User’s Guide478 Chapter 27 UPnPThe following table describes the labels in this screen. 27.4 Installing UPnP in Windows Exampl

Page 422 - 422 Chapter 23 Policy Route

ZyWALL 5/35/70 Series User’s GuideChapter 27 UPnP 47927.4.1 Installing UPnP in Windows MeFollow the steps below to install UPnP in Windows Me. 1 Clic

Page 423 - CHAPTER 24

ZyWALL 5/35/70 Series User’s Guide48 List of TablesTable 125 Services and Port Numbers ...

Page 424

ZyWALL 5/35/70 Series User’s Guide480 Chapter 27 UPnP27.4.2 Installing UPnP in Windows XPFollow the steps below to install UPnP in Windows XP.27.5 U

Page 425 - 24.7 Scheduler

ZyWALL 5/35/70 Series User’s GuideChapter 27 UPnP 48127.5.1 Auto-discover Your UPnP-enabled Network Device1 Click Start and Control Panel. Double-cli

Page 426 - Research: 2048 kbps

ZyWALL 5/35/70 Series User’s Guide482 Chapter 27 UPnPNote: When the UPnP-enabled device is disconnected from your computer, all port mappings will be

Page 427

ZyWALL 5/35/70 Series User’s GuideChapter 27 UPnP 483Follow the steps below to access the web configurator.1 Click Start and then Control Panel. 2 Dou

Page 428 - 24.8 Bandwidth Borrowing

ZyWALL 5/35/70 Series User’s Guide484 Chapter 27 UPnP6 Right-click the icon for your ZyXEL device and select Properties. A properties window displays

Page 429

ZyWALL 5/35/70 Series User’s GuideChapter 28 ALG Screen 485CHAPTER 28ALG ScreenThis chapter covers how to use the ZyWALL’s ALG feature to allow certai

Page 430 - 24.11 Configuring Summary

ZyWALL 5/35/70 Series User’s Guide486 Chapter 28 ALG ScreenIf the primary WAN connection fails, the client needs to re-initialize the connection throu

Page 431

ZyWALL 5/35/70 Series User’s GuideChapter 28 ALG Screen 487Figure 264 H.323 ALG Example • With multiple WAN IP addresses on the ZyWALL, you can conf

Page 432

ZyWALL 5/35/70 Series User’s Guide488 Chapter 28 ALG ScreenFigure 266 H.323 Calls from the WAN with Multiple Outgoing Calls• The H.323 ALG operates

Page 433

ZyWALL 5/35/70 Series User’s GuideChapter 28 ALG Screen 489The following example shows SIP signaling (1) and audio (2) sessions between SIP clients A

Page 434

ZyWALL 5/35/70 Series User’s GuideList of Tables 49Table 168 TCP Reset Logs ...

Page 435

ZyWALL 5/35/70 Series User’s Guide490 Chapter 28 ALG ScreenFigure 268 ADVANCED > ALG The following table describes the labels in this screen. Ta

Page 436

ZyWALL 5/35/70 Series User’s GuideChapter 29 Reports 491CHAPTER 29ReportsThis chapter contains information about the ZyWALL’s system and threat report

Page 437 - Bandwidth Manager Monitor

ZyWALL 5/35/70 Series User’s Guide492 Chapter 29 ReportsFigure 269 REPORTS > SYSTEM REPORTSNote: Enabling the ZyWALL’s reporting function decreas

Page 438

ZyWALL 5/35/70 Series User’s GuideChapter 29 Reports 49329.2.1 Viewing Web Site HitsIn the Reports screen, select Web Site Hits from the Report Type

Page 439 - CHAPTER 25

ZyWALL 5/35/70 Series User’s Guide494 Chapter 29 Reports29.2.2 Viewing Host IP AddressIn the Reports screen, select Host IP Address from the Report T

Page 440 - 25.5 Name Server Record

ZyWALL 5/35/70 Series User’s GuideChapter 29 Reports 49529.2.3 Viewing Protocol/PortIn the Reports screen, select Protocol/Port from the Report Type

Page 441 - 25.6 System Screen

ZyWALL 5/35/70 Series User’s Guide496 Chapter 29 Reports29.2.4 System Reports SpecificationsThe following table lists detailed specifications on the

Page 442 - 442 Chapter 25 DNS

ZyWALL 5/35/70 Series User’s GuideChapter 29 Reports 497The following table describes the labels in this screen. The statistics display as follows whe

Page 443 - Chapter 25 DNS 443

ZyWALL 5/35/70 Series User’s Guide498 Chapter 29 ReportsFigure 274 REPORTS > THREAT REPORTS > IDP > Source The statistics display as follow

Page 444 - 444 Chapter 25 DNS

ZyWALL 5/35/70 Series User’s GuideChapter 29 Reports 499The following table describes the labels in this screen. The statistics display as follows wh

Page 445 - 25.8 Configure DNS Cache

ZyWALL 5/35/70 Series User’s GuideSafety Warnings 5Safety WarningsFor your safety, be sure to read and follow all warning notices and instructions.• D

Page 446 - 25.9 Configuring DNS DHCP

ZyWALL 5/35/70 Series User’s Guide50 List of TablesTable 211 Menu 11.3.2: Remote Node Network Layer Options ...

Page 447 - Chapter 25 DNS 447

ZyWALL 5/35/70 Series User’s Guide500 Chapter 29 ReportsFigure 278 REPORTS > THREAT REPORTS > Anti-Virus > Destination 29.5 Anti-Spam Thre

Page 448 - 25.10 Dynamic DNS

ZyWALL 5/35/70 Series User’s GuideChapter 29 Reports 501The statistics display as follows when you display the top entries by source.Spam Mail Detecte

Page 449 - Chapter 25 DNS 449

ZyWALL 5/35/70 Series User’s Guide502 Chapter 29 ReportsFigure 280 REPORTS > THREAT REPORTS > Anti-Spam > Source The statistics display as

Page 450 - 450 Chapter 25 DNS

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 503CHAPTER 30Logs ScreensThis chapter contains information about configuring general log set

Page 451 - CHAPTER 26

ZyWALL 5/35/70 Series User’s Guide504 Chapter 30 Logs ScreensThe following table describes the labels in this screen. 30.2 Log Description Example

Page 452 - 26.2 WWW (HTTP and HTTPS)

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 50530.2.1 About the Certificate Not Trusted LogmyZyXEL.com and the update server use certif

Page 453 - 26.3 WWW

ZyWALL 5/35/70 Series User’s Guide506 Chapter 30 Logs ScreensFigure 284 myZyXEL.com: Certificate Download30.3 Configuring Log Settings To change yo

Page 454

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 507Figure 285 LOGS > Log Settings

Page 455 - 26.4 HTTPS Example

ZyWALL 5/35/70 Series User’s Guide508 Chapter 30 Logs ScreensThe following table describes the labels in this screen. Table 164 LOGS > Log Sett

Page 456

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 50930.3.1 Log DescriptionsThis section provides descriptions of example log messages. Log S

Page 457 - 26.4.4 Login Screen

ZyWALL 5/35/70 Series User’s GuideList of Tables 51Table 254 Menu 25: Sample IP Routing Policy Summary ...

Page 458

ZyWALL 5/35/70 Series User’s Guide510 Chapter 30 Logs ScreensTime initialized by Time serverThe router got the time and date from the time server.Time

Page 459 - 26.5 SSH

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 511 Table 166 System Error LogsLOG MESSAGE DESCRIPTION%s exceeds the max. number of sessio

Page 460 - 26.6 How SSH Works

ZyWALL 5/35/70 Series User’s Guide512 Chapter 30 Logs Screens Exceed maximum sessions per host (%d).The device blocked a session because the host&apos

Page 461 - 26.8 Configuring SSH

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 513 For type and code details, see Table 183 on page 524. Table 169 Packet Filter LogsLOG

Page 462

ZyWALL 5/35/70 Series User’s Guide514 Chapter 30 Logs Screens Table 172 PPP LogsLOG MESSAGE DESCRIPTIONppp:LCP Starting The PPP connection’s Link

Page 463 - 26.9.2 Example 2: Linux

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 515 For type and code details, see Table 183 on page 524.%s When the content filter is not o

Page 464

ZyWALL 5/35/70 Series User’s Guide516 Chapter 30 Logs Screensip spoofing - no routing entry ICMP (type:%d, code:%d)The firewall classified an ICMP pac

Page 465 - 26.12 Configuring TELNET

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 517 Remote Management: SNMP denied Attempted use of SNMP service was blocked according to re

Page 466 - 26.13 FTP

ZyWALL 5/35/70 Series User’s Guide518 Chapter 30 Logs Screens Table 179 IKE LogsLOG MESSAGE DESCRIPTIONActive connection allowed exceededThe IKE pro

Page 467 - 26.14 SNMP

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 519Remote IP <Remote IP> / <Remote IP> conflictsThe security gateway is set to “

Page 468

ZyWALL 5/35/70 Series User’s Guide52 List of Tables

Page 469 - 26.14.2 SNMP Traps

ZyWALL 5/35/70 Series User’s Guide520 Chapter 30 Logs ScreensRule [%d] Phase 2 authentication algorithm mismatchThe listed rule’s IKE phase 2 authenti

Page 470

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 521 Table 180 PKI LogsLOG MESSAGE DESCRIPTIONEnrollment successful The SCEP online certifi

Page 471 - 26.15 DNS

ZyWALL 5/35/70 Series User’s Guide522 Chapter 30 Logs Screens CODE DESCRIPTION1 Algorithm mismatch between the certificate and the search constraints

Page 472 - 26.17 Configuring CNM

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 523Local User Database does not find user`s credential.A user was not authenticated by the l

Page 473

ZyWALL 5/35/70 Series User’s Guide524 Chapter 30 Logs Screens (L to L/ZW) LAN to LAN/ZyWALLACL set for packets traveling from the LAN to the LAN or th

Page 474

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 525 11 Time Exceeded0 Time to live exceeded in transit1 Fragment reassembly time exceeded12

Page 475 - CHAPTER 27

ZyWALL 5/35/70 Series User’s Guide526 Chapter 30 Logs Screens Signature update OK - New signature version: <Signature version> Release Date: <

Page 476 - 27.2 Configuring UPnP

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 527 The turbo card is not ready , please insert the card and reboot!The turbo card is not in

Page 477 - Chapter 27 UPnP 477

ZyWALL 5/35/70 Series User’s Guide528 Chapter 30 Logs ScreensRemove rating server [%Rating Server IP Address%] from server list!The listed server IP a

Page 478 - 478 Chapter 27 UPnP

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 52930.4 Syslog LogsThere are two types of syslog: event logs and traffic logs. The device g

Page 479 - Chapter 27 UPnP 479

ZyWALL 5/35/70 Series User’s GuidePreface 53PrefaceCongratulations on your purchase of the ZyWALL. Note: Register your product online to receive e-mai

Page 480 - 480 Chapter 27 UPnP

ZyWALL 5/35/70 Series User’s Guide530 Chapter 30 Logs ScreensThe following table shows RFC-2408 ISAKMP payload types that the log displays. Please ref

Page 481 - Chapter 27 UPnP 481

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 531CHAPTER 31MaintenanceThis chapter displays information on the maintenance screens.31.1 Ma

Page 482 - 482 Chapter 27 UPnP

ZyWALL 5/35/70 Series User’s Guide532 Chapter 31 MaintenanceFigure 286 MAINTENANCE > General SetupThe following table describes the labels in thi

Page 483 - Chapter 27 UPnP 483

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 533Figure 287 MAINTENANCE > Password The following table describes the labels in this sc

Page 484 - 484 Chapter 27 UPnP

ZyWALL 5/35/70 Series User’s Guide534 Chapter 31 MaintenanceFigure 288 MAINTENANCE > Time and DateThe following table describes the labels in thi

Page 485 - CHAPTER 28

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 535Get from Time ServerSelect this radio button to have the ZyWALL get the time and date from

Page 486 - 28.4 RTP

ZyWALL 5/35/70 Series User’s Guide536 Chapter 31 Maintenance31.5 Pre-defined NTP Time Server PoolsWhen you turn on the ZyWALL for the first time, the

Page 487 - Chapter 28 ALG Screen 487

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 537Click the Return button to go back to the Time and Date screen after the time and date is

Page 488 - 28.5 SIP

ZyWALL 5/35/70 Series User’s Guide538 Chapter 31 MaintenanceFor example, if a bridge receives a frame via port 1 from host A (MAC address 00a0c5123478

Page 489 - 28.6 ALG Screen

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 53931.8 Configuring Device Mode (Router) Click MAINTENANCE > Device Mode to open the fol

Page 490 - Table 153 ADVANCED > ALG

ZyWALL 5/35/70 Series User’s Guide54 PrefaceSyntax Conventions• “Enter” means for you to type one or more characters. “Select” or “Choose” means for y

Page 491 - CHAPTER 29

ZyWALL 5/35/70 Series User’s Guide540 Chapter 31 Maintenance31.9 Configuring Device Mode (Bridge) Click MAINTENANCE > Device Mode to open the fol

Page 492 - 492 Chapter 29 Reports

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 541Figure 293 MAINTENANCE > Device Mode (Bridge Mode)The following table describes the l

Page 493 - 29.2.1 Viewing Web Site Hits

ZyWALL 5/35/70 Series User’s Guide542 Chapter 31 Maintenance31.10 F/W Upload Screen Find firmware at www.zyxel.com in a file that (usually) uses the

Page 494 - 494 Chapter 29 Reports

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 543After you see the Firmware Upload in Process screen, wait two minutes before logging into

Page 495 - 29.2.3 Viewing Protocol/Port

ZyWALL 5/35/70 Series User’s Guide544 Chapter 31 Maintenance31.11 Backup and Restore See Section 47.5 on page 672 for transferring configuration fil

Page 496 - 496 Chapter 29 Reports

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 54531.11.2 Restore Configuration Load a configuration file from your computer to your ZyWALL

Page 497 - Chapter 29 Reports 497

ZyWALL 5/35/70 Series User’s Guide546 Chapter 31 MaintenanceFigure 301 Configuration Upload Error31.11.3 Back to Factory Defaults Click the Reset

Page 498 - 498 Chapter 29 Reports

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 547Figure 303 MAINTENANCE > Restart

Page 499 - Chapter 29 Reports 499

ZyWALL 5/35/70 Series User’s Guide548 Chapter 31 Maintenance

Page 500 - 500 Chapter 29 Reports

ZyWALL 5/35/70 Series User’s GuideChapter 32 Introducing the SMT 549CHAPTER 32Introducing the SMTThis chapter explains how to access the System Manage

Page 501 - Chapter 29 Reports 501

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 55CHAPTER 1Getting to Know Your ZyWALLThis chapter introduces the main feature

Page 502 - 502 Chapter 29 Reports

ZyWALL 5/35/70 Series User’s Guide550 Chapter 32 Introducing the SMTFigure 304 Initial Screen32.2.2 Entering the PasswordThe login screen appears a

Page 503 - CHAPTER 30

ZyWALL 5/35/70 Series User’s GuideChapter 32 Introducing the SMT 55132.3.1 Main MenuAfter you enter the password, the SMT displays the ZyWALL Main Me

Page 504 - 30.2 Log Description Example

ZyWALL 5/35/70 Series User’s Guide552 Chapter 32 Introducing the SMTFigure 306 Main Menu (Router Mode)Figure 307 Main Menu (Bridge Mode)The follow

Page 505 - Chapter 30 Logs Screens 505

ZyWALL 5/35/70 Series User’s GuideChapter 32 Introducing the SMT 55332.3.2 SMT Menus OverviewThe following table gives you an overview of your ZyWALL

Page 506 - 506 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s Guide554 Chapter 32 Introducing the SMT6 Route Setup (for the ZyWALL 35 and the ZyWALL 70)6.1 Route Assessment6.2 Traffic

Page 507 - Chapter 30 Logs Screens 507

ZyWALL 5/35/70 Series User’s GuideChapter 32 Introducing the SMT 55532.4 Changing the System PasswordChange the system password by following the step

Page 508 - 508 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s Guide556 Chapter 32 Introducing the SMTFigure 308 Menu 23: System Password2 Type your existing password and press [ENTE

Page 509 - 30.3.1 Log Descriptions

ZyWALL 5/35/70 Series User’s GuideChapter 33 SMT Menu 1 - General Setup 557CHAPTER 33SMT Menu 1 - General SetupMenu 1 - General Setup contains adminis

Page 510 - 510 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s Guide558 Chapter 33 SMT Menu 1 - General SetupFigure 310 Menu 1: General Setup (Bridge Mode)The following table describ

Page 511 - Table 166 System Error Logs

ZyWALL 5/35/70 Series User’s GuideChapter 33 SMT Menu 1 - General Setup 55933.2.1 Configuring Dynamic DNSTo configure Dynamic DNS, set the ZyWALL to

Page 512 - Table 168 TCP Reset Logs

ZyWALL 5/35/70 Series User’s Guide56 Chapter 1 Getting to Know Your ZyWALLTable Key: An O in a mode’s column shows that the device mode has the specif

Page 513 - Table 171 CDR Logs

ZyWALL 5/35/70 Series User’s Guide560 Chapter 33 SMT Menu 1 - General SetupFigure 312 Menu 1.1.1: DDNS Host SummaryThe following table describes the

Page 514 - Table 173 UPnP Logs

ZyWALL 5/35/70 Series User’s GuideChapter 33 SMT Menu 1 - General Setup 561Figure 313 Menu 1.1.1: DDNS Edit HostThe following table describes the fi

Page 515 - Table 175 Attack Logs

ZyWALL 5/35/70 Series User’s Guide562 Chapter 33 SMT Menu 1 - General SetupThe IP address updates when you reconfigure menu 1 or perform DHCP client r

Page 516 - 516 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 563CHAPTER 34WAN and Dial Backup SetupThis chapter describes how to configure t

Page 517 - Table 178 IPSec Logs

ZyWALL 5/35/70 Series User’s Guide564 Chapter 34 WAN and Dial Backup SetupThe following table describes the fields in this screen.34.3 Dial BackupThe

Page 518 - Table 179 IKE Logs

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 565Figure 315 Menu 2: Dial Backup Setup The following table describes the fi

Page 519 - Chapter 30 Logs Screens 519

ZyWALL 5/35/70 Series User’s Guide566 Chapter 34 WAN and Dial Backup SetupTo edit the advanced setup for the Dial Backup port, move the cursor to the

Page 520 - 520 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 56734.6 Remote Node Profile (Backup ISP)On a ZyWALL with multiple WAN ports, e

Page 521 - Table 180 PKI Logs

ZyWALL 5/35/70 Series User’s Guide568 Chapter 34 WAN and Dial Backup SetupFigure 317 Menu 11.3: Remote Node Profile (Backup ISP)The following table

Page 522 - Table 181 802.1X Logs

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 56934.7 Editing PPP OptionsThe ZyWALL’s dial back-up feature uses PPP. To edit

Page 523 - Table 182 ACL Setting Notes

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 57The 10/100 Mbps auto-negotiating Ethernet ports allow the ZyWALL to detect t

Page 524 - Table 183 ICMP Notes

ZyWALL 5/35/70 Series User’s Guide570 Chapter 34 WAN and Dial Backup SetupFigure 318 Menu 11.3.1: Remote Node PPP OptionsThis table describes the Re

Page 525 - Table 184 IDP Logs

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 571Figure 319 Menu 11.3.2: Remote Node Network Layer OptionsThe following tab

Page 526 - Table 185 AV Logs

ZyWALL 5/35/70 Series User’s Guide572 Chapter 34 WAN and Dial Backup Setup34.9 Editing Login ScriptFor some remote gateways, text login is required b

Page 527 - Table 186 AS Logs

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 573You can use two variables, $USERNAME and $PASSWORD (all UPPER case), to repr

Page 528 - 528 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s Guide574 Chapter 34 WAN and Dial Backup SetupThe following table describes the fields in this menu.34.10 Remote Node Fil

Page 529 - 30.4 Syslog Logs

ZyWALL 5/35/70 Series User’s GuideChapter 35 LAN Setup 575CHAPTER 35LAN SetupThis chapter describes how to configure the LAN using Menu 3 - LAN Setup.

Page 530 - 530 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s Guide576 Chapter 35 LAN SetupFigure 323 Menu 3.1: LAN Port Filter Setup 35.4 TCP/IP and DHCP Ethernet Setup MenuFrom t

Page 531 - CHAPTER 31

ZyWALL 5/35/70 Series User’s GuideChapter 35 LAN Setup 577Figure 325 Menu 3.2: TCP/IP and DHCP Ethernet SetupFollow the instructions in the next tab

Page 532 - 31.3 Configuring Password

ZyWALL 5/35/70 Series User’s Guide578 Chapter 35 LAN SetupUse the instructions in the following table to configure TCP/IP parameters for the LAN port.

Page 533 - 31.4 Time and Date

ZyWALL 5/35/70 Series User’s GuideChapter 35 LAN Setup 57935.4.1 IP Alias SetupIP alias allows you to partition a physical network into different log

Page 534 - 534 Chapter 31 Maintenance

ZyWALL 5/35/70 Series User’s Guide58 Chapter 1 Getting to Know Your ZyWALLSIP PassthroughThe ZyWALL includes a SIP Application Layer Gateway (ALG). It

Page 535 - Chapter 31 Maintenance 535

ZyWALL 5/35/70 Series User’s Guide580 Chapter 35 LAN SetupOutgoing Protocol FiltersEnter the filter set(s) you wish to apply to the outgoing traffic b

Page 536 - 31.5.1 Resetting the Time

ZyWALL 5/35/70 Series User’s GuideChapter 36 Internet Access 581CHAPTER 36Internet AccessThis chapter shows you how to configure your ZyWALL for Inter

Page 537 - Chapter 31 Maintenance 537

ZyWALL 5/35/70 Series User’s Guide582 Chapter 36 Internet AccessThe following table describes the fields in this menu.Table 216 Menu 4: Internet Acc

Page 538 - 31.7 Transparent Firewalls

ZyWALL 5/35/70 Series User’s GuideChapter 36 Internet Access 58336.3 Configuring the PPTP ClientNote: The ZyWALL supports only one PPTP server connec

Page 539 - Chapter 31 Maintenance 539

ZyWALL 5/35/70 Series User’s Guide584 Chapter 36 Internet AccessFigure 329 Internet Access Setup (PPPoE)The following table contains instructions ab

Page 540 - 540 Chapter 31 Maintenance

ZyWALL 5/35/70 Series User’s GuideChapter 37 DMZ Setup 585CHAPTER 37DMZ SetupThis chapter describes how to configure the ZyWALL’s DMZ using Menu 5 - D

Page 541 - Chapter 31 Maintenance 541

ZyWALL 5/35/70 Series User’s Guide586 Chapter 37 DMZ Setup37.3.1 IP AddressFrom the main menu, enter 5 to open Menu 5 - DMZ Setup to configure TCP/IP

Page 542 - 31.10 F/W Upload Screen

ZyWALL 5/35/70 Series User’s GuideChapter 37 DMZ Setup 58737.3.2 IP Alias SetupUse menu 5.2 to configure the first network. Move the cursor to the Ed

Page 543 - Chapter 31 Maintenance 543

ZyWALL 5/35/70 Series User’s Guide588 Chapter 37 DMZ Setup

Page 544 - 31.11 Backup and Restore

ZyWALL 5/35/70 Series User’s GuideChapter 38 Route Setup 589CHAPTER 38Route SetupThis chapter describes how to configure the ZyWALL's traffic red

Page 545 - Chapter 31 Maintenance 545

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 59FirewallThe ZyWALL is a stateful inspection firewall with DoS (Denial of Ser

Page 546 - 31.12 Restart Screen

ZyWALL 5/35/70 Series User’s Guide590 Chapter 38 Route SetupThe following table describes the fields in this menu.38.3 Traffic RedirectTo configure t

Page 547 - Chapter 31 Maintenance 547

ZyWALL 5/35/70 Series User’s GuideChapter 38 Route Setup 59138.4 Route FailoverThis menu allows you to configure how the ZyWALL uses the route assess

Page 548 - 548 Chapter 31 Maintenance

ZyWALL 5/35/70 Series User’s Guide592 Chapter 38 Route Setup

Page 549 - CHAPTER 32

ZyWALL 5/35/70 Series User’s GuideChapter 39 Wireless Setup 593CHAPTER 39Wireless SetupUse menu 7 to set up your ZyWALL as the wireless access point.3

Page 550 - 32.2.2 Entering the Password

ZyWALL 5/35/70 Series User’s Guide594 Chapter 39 Wireless SetupFollow the instructions in the next table on how to configure the wireless LAN paramete

Page 551 - 32.3.1 Main Menu

ZyWALL 5/35/70 Series User’s GuideChapter 39 Wireless Setup 59539.1.1 MAC Address Filter SetupYour ZyWALL checks the MAC address of the wireless stat

Page 552 - Table 198 Main Menu Summary

ZyWALL 5/35/70 Series User’s Guide596 Chapter 39 Wireless Setup39.2 TCP/IP SetupFor more detailed information about RIP setup, IP Multicast and IP al

Page 553 - 32.3.2 SMT Menus Overview

ZyWALL 5/35/70 Series User’s GuideChapter 39 Wireless Setup 597Figure 342 Menu 7.2: TCP/IP and DHCP Ethernet SetupThe DHCP and TCP/IP setup fields a

Page 554

ZyWALL 5/35/70 Series User’s Guide598 Chapter 39 Wireless SetupFigure 343 Menu 7.2.1: IP Alias SetupRefer to Table 215 on page 579 for instructions

Page 555

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 599CHAPTER 40Remote Node SetupThis chapter shows you how to configure a remote node.40.

Page 556 - 32.5 Resetting the ZyWALL

ZyWALL 5/35/70 Series User’s Guide6 Safety WarningsThis product is recyclable. Dispose of it properly.

Page 557 - CHAPTER 33

ZyWALL 5/35/70 Series User’s Guide60 Chapter 1 Getting to Know Your ZyWALLRADIUS (RFC2138, 2139)The ZyWALL can work with a RADIUS (Remote Authenticati

Page 558

ZyWALL 5/35/70 Series User’s Guide600 Chapter 40 Remote Node SetupFigure 344 Menu 11: Remote Node Setup40.3 Remote Node Profile SetupThe following

Page 559 - 33.2.1.1 Editing DDNS Host

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 601The following table describes the fields in this menu.Table 224 Menu 11.1: Remote

Page 560

ZyWALL 5/35/70 Series User’s Guide602 Chapter 40 Remote Node Setup40.3.2 PPPoE EncapsulationThe ZyWALL supports PPPoE (Point-to-Point Protocol over E

Page 561

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 60340.3.2.3 MetricSee Section 8.5 on page 151 for details on the Metric field.40.3.3

Page 562

ZyWALL 5/35/70 Series User’s Guide604 Chapter 40 Remote Node SetupFigure 347 Menu 11.1: Remote Node Profile for PPTP EncapsulationThe next table sho

Page 563 - Edit Advanced Setup= No

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 605Figure 348 Menu 11.1.2: Remote Node Network Layer Options for Ethernet Encapsulati

Page 564 - 34.3 Dial Backup

ZyWALL 5/35/70 Series User’s Guide606 Chapter 40 Remote Node Setup40.5 Remote Node FilterMove the cursor to the field Edit Filter Sets in menu 11.1,

Page 565 - Edit Advanced Setup= Yes

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 607Figure 349 Menu 11.1.4: Remote Node Filter (Ethernet Encapsulation)Figure 350 Me

Page 566 - [ENTER]

ZyWALL 5/35/70 Series User’s Guide608 Chapter 40 Remote Node SetupFigure 351 Menu 11.1.5: Traffic Redirect SetupThe following table describes the fi

Page 567

ZyWALL 5/35/70 Series User’s GuideChapter 41 IP Static Route Setup 609CHAPTER 41IP Static Route SetupThis chapter shows you how to configure static ro

Page 568

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 61PPTP supports on-demand, multi-protocol and virtual private networking over

Page 569 - 34.7 Editing PPP Options

ZyWALL 5/35/70 Series User’s Guide610 Chapter 41 IP Static Route SetupFigure 353 Menu 12. 1: Edit IP Static Route`The following table describes the

Page 570 - 34.8 Editing TCP/IP Options

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 611CHAPTER 42Network Address Translation(NAT)This chapter discusses how

Page 571

ZyWALL 5/35/70 Series User’s Guide612 Chapter 42 Network Address Translation (NAT)Figure 354 Menu 4: Applying NAT for Internet AccessThe following f

Page 572 - 34.9 Editing Login Script

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 613The following table describes the fields in this menu.42.2 NAT Setu

Page 573

ZyWALL 5/35/70 Series User’s Guide614 Chapter 42 Network Address Translation (NAT)42.2.1 Address Mapping Sets Enter 1 to bring up Menu 15.1 - Address

Page 574 - 34.10 Remote Node Filter

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 615Note: Menu 15.1.255 is read-only. 42.2.1.2 User-Defined Address Map

Page 575 - CHAPTER 35

ZyWALL 5/35/70 Series User’s Guide616 Chapter 42 Network Address Translation (NAT)Figure 359 Menu 15.1.1: First SetNote: The Type, Local and Global

Page 576 - 576 Chapter 35 LAN Setup

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 617Note: You must press [ENTER] at the bottom of the screen to save the

Page 577 - Chapter 35 LAN Setup 577

ZyWALL 5/35/70 Series User’s Guide618 Chapter 42 Network Address Translation (NAT)42.3 Configuring a Server behind NATNote: If you do not assign a De

Page 578 - 578 Chapter 35 LAN Setup

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 619Figure 362 Menu 15.2.1: NAT Server Sets4 Select Edit Rule in the S

Page 579 - 35.4.1 IP Alias Setup

ZyWALL 5/35/70 Series User’s Guide62 Chapter 1 Getting to Know Your ZyWALLNetwork Address Translation (NATNetwork Address Translation (NAT) allows the

Page 580 - 580 Chapter 35 LAN Setup

ZyWALL 5/35/70 Series User’s Guide620 Chapter 42 Network Address Translation (NAT)Figure 363 15.2.1.2: NAT Server ConfigurationThe following table d

Page 581 - CHAPTER 36

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 621Figure 364 Menu 15.2.1: NAT Server Setup You assign the private ne

Page 582

ZyWALL 5/35/70 Series User’s Guide622 Chapter 42 Network Address Translation (NAT)Figure 366 NAT Example 1Figure 367 Menu 4: Internet Access &

Page 583

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 62342.4.2 Example 2: Internet Access with a Default Server Figure 368

Page 584 - 36.5 Basic Setup Complete

ZyWALL 5/35/70 Series User’s Guide624 Chapter 42 Network Address Translation (NAT)1 Map the first IGA to the first inside FTP server for FTP traffic i

Page 585 - CHAPTER 37

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 625Figure 371 Example 3: Menu 11.1.2The following figure shows how to

Page 586 - 37.3.1 IP Address

ZyWALL 5/35/70 Series User’s Guide626 Chapter 42 Network Address Translation (NAT)Figure 373 Example 3: Final Menu 15.1.1Now configure the IGA3 to m

Page 587 - 37.3.2 IP Alias Setup

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 62742.4.4 Example 4: NAT Unfriendly Application ProgramsSome applicati

Page 588 - 588 Chapter 37 DMZ Setup

ZyWALL 5/35/70 Series User’s Guide628 Chapter 42 Network Address Translation (NAT)Figure 377 Example 4: Menu 15.1.1: Address Mapping Rules42.5 Trig

Page 589 - CHAPTER 38

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 629Note: Only one LAN computer can use a trigger port (range) at a time

Page 590 - 38.3 Traffic Redirect

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 63Upgrade ZyWALL Firmware via LANThe firmware of the ZyWALL can be upgraded vi

Page 591 - 38.4 Route Failover

ZyWALL 5/35/70 Series User’s Guide630 Chapter 42 Network Address Translation (NAT)

Page 592 - 592 Chapter 38 Route Setup

ZyWALL 5/35/70 Series User’s GuideChapter 43 Introducing the ZyWALL Firewall 631CHAPTER 43Introducing the ZyWALL FirewallThis chapter shows you how to

Page 593 - CHAPTER 39

ZyWALL 5/35/70 Series User’s Guide632 Chapter 43 Introducing the ZyWALL FirewallFigure 380 Menu 21.2: Firewall SetupNote: Configure the firewall rul

Page 594 - 594 Chapter 39 Wireless Setup

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 633CHAPTER 44Filter ConfigurationThis chapter shows you how to create and apply filt

Page 595 - Chapter 39 Wireless Setup 595

ZyWALL 5/35/70 Series User’s Guide634 Chapter 44 Filter Configuration44.1.1 The Filter Structure of the ZyWALLA filter set consists of one or more fi

Page 596 - 39.2 TCP/IP Setup

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 635Figure 382 Filter Rule Process You can apply up to four filter sets to a partic

Page 597 - 39.2.2 IP Alias Setup

ZyWALL 5/35/70 Series User’s Guide636 Chapter 44 Filter Configuration44.2 Configuring a Filter SetThe ZyWALL includes filtering for NetBIOS over TCP/

Page 598 - 598 Chapter 39 Wireless Setup

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 637The protocol dependent filter rules abbreviation are listed as follows:Refer to t

Page 599 - CHAPTER 40

ZyWALL 5/35/70 Series User’s Guide638 Chapter 44 Filter ConfigurationTo speed up filtering, all rules in a filter set must be of the same class, i.e.,

Page 600

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 639The following figure illustrates the logic flow of an IP filter.DestinationIP Add

Page 601

ZyWALL 5/35/70 Series User’s Guide64 Chapter 1 Getting to Know Your ZyWALLFigure 2 VPN Application1.3.3 Front Panel LightsFigure 3 ZyWALL 70 Fron

Page 602 - 40.3.2 PPPoE Encapsulation

ZyWALL 5/35/70 Series User’s Guide640 Chapter 44 Filter ConfigurationFigure 386 Executing an IP Filter44.2.3 Configuring a Generic Filter Rule This

Page 603 - 40.3.3 PPTP Encapsulation

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 641to allow you to filter non-IP packets. For IP, it is generally easier to use the

Page 604 - 40.4 Edit IP

ZyWALL 5/35/70 Series User’s Guide642 Chapter 44 Filter Configuration44.3 Example FilterLet’s look at an example to block outside users from accessin

Page 605

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 6436 Enter 1 to configure the first filter rule (the only filter rule of this set).

Page 606 - 40.5 Remote Node Filter

ZyWALL 5/35/70 Series User’s Guide644 Chapter 44 Filter ConfigurationM = N means an action can be taken immediately. The action is to drop the packet

Page 607 - 40.6 Traffic Redirect

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 64544.5.1 Packet Filtering:• The router filters packets as they pass through the ro

Page 608

ZyWALL 5/35/70 Series User’s Guide646 Chapter 44 Filter Configuration6 The firewall can block specific URL traffic that might occur in the future. The

Page 609 - CHAPTER 41

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 647Figure 393 Filtering DMZ Traffic44.6.3 Applying Remote Node FiltersGo to menu

Page 610

ZyWALL 5/35/70 Series User’s Guide648 Chapter 44 Filter Configuration

Page 611 - CHAPTER 42

ZyWALL 5/35/70 Series User’s GuideChapter 45 SNMP Configuration 649CHAPTER 45SNMP ConfigurationThis chapter explains SNMP configuration menu 22.45.1

Page 612

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 65CARD Green Off The wireless LAN is not ready, or has failed.On The wireless

Page 613 - 42.2 NAT Setup

ZyWALL 5/35/70 Series User’s Guide650 Chapter 45 SNMP Configuration45.2 SNMP Traps The ZyWALL will send traps to the SNMP manager when any one of the

Page 614 - 42.2.1 Address Mapping Sets

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 651CHAPTER 46System Information & DiagnosisThis chapter covers SMT

Page 615

ZyWALL 5/35/70 Series User’s Guide652 Chapter 46 System Information & Diagnosis3 There are three commands in Menu 24.1 - System Maintenance - Stat

Page 616 - 42.2.1.3 Ordering Your Rules

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 65346.3 System Information and Console Port SpeedThis section describ

Page 617

ZyWALL 5/35/70 Series User’s Guide654 Chapter 46 System Information & DiagnosisFigure 399 Menu 24.2.1: System Maintenance: Information The foll

Page 618

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 655Figure 400 Menu 24.2.2: System Maintenance: Change Console Port S

Page 619

ZyWALL 5/35/70 Series User’s Guide656 Chapter 46 System Information & DiagnosisFigure 402 Examples of Error and Information Messages46.4.2 Sysl

Page 620

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 657Your ZyWALL sends five types of syslog messages. Some examples (not

Page 621 - 42.4 General NAT Examples

ZyWALL 5/35/70 Series User’s Guide658 Chapter 46 System Information & Diagnosis4 PPP log 5 Firewall logFilter log Message FormatSdcmdSyslogSend(SY

Page 622 - Figure 366 NAT Example 1

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 65946.4.3 Call-Triggering PacketCall-Triggering Packet displays infor

Page 623 - Figure 368 NAT Example 2

ZyWALL 5/35/70 Series User’s Guide66 Chapter 1 Getting to Know Your ZyWALL

Page 624 - Figure 370 NAT Example 3

ZyWALL 5/35/70 Series User’s Guide660 Chapter 46 System Information & Diagnosis1 From the main menu, select option 24 to open Menu 24 - System Mai

Page 625

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 661Table 245 System Maintenance Menu DiagnosticFIELD DESCRIPTIONPing

Page 626 - 2 Enter 2 to go to menu 15.2

ZyWALL 5/35/70 Series User’s Guide662 Chapter 46 System Information & Diagnosis

Page 627 - Figure 375 NAT Example 4

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 663CHAPTER 47Firmware and Configuration FileMaintenanceThis c

Page 628 - 42.5 Trigger Port Forwarding

ZyWALL 5/35/70 Series User’s Guide664 Chapter 47 Firmware and Configuration File MaintenanceThe following table is a summary. Please note that the int

Page 629

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 665Figure 407 Telnet into Menu 24.547.3.2 Using the FTP Co

Page 630

ZyWALL 5/35/70 Series User’s Guide666 Chapter 47 Firmware and Configuration File Maintenance47.3.3 Example of FTP Commands from the Command Line Figu

Page 631 - CHAPTER 43

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 6674 The IP you entered in the Secured Client IP field in men

Page 632

ZyWALL 5/35/70 Series User’s Guide668 Chapter 47 Firmware and Configuration File Maintenance47.3.8 GUI-based TFTP ClientsThe following table describe

Page 633 - CHAPTER 44

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 669Figure 411 Backup Configuration ExampleType a location f

Page 634

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 67CHAPTER 2Introducing the WebConfiguratorThis chapter describes how to a

Page 635

ZyWALL 5/35/70 Series User’s Guide670 Chapter 47 Firmware and Configuration File MaintenanceFigure 413 Telnet into Menu 24.61 Launch the FTP client

Page 636

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 67147.4.2 Restore Using FTP Session ExampleFigure 414 Rest

Page 637 - Len Length

ZyWALL 5/35/70 Series User’s Guide672 Chapter 47 Firmware and Configuration File Maintenance4 After a successful restoration you will see the followin

Page 638

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 673Figure 419 Telnet Into Menu 24.7.1: Upload System Firmwa

Page 639

ZyWALL 5/35/70 Series User’s Guide674 Chapter 47 Firmware and Configuration File Maintenance47.5.3 FTP File Upload Command from the DOS Prompt Exampl

Page 640

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 6751 Use telnet from your computer to connect to the ZyWALL a

Page 641 - Length= 0

ZyWALL 5/35/70 Series User’s Guide676 Chapter 47 Firmware and Configuration File MaintenanceFigure 422 Menu 24.7.1 As Seen Using the Console Port2 A

Page 642

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 677Figure 424 Menu 24.7.2 As Seen Using the Console Port 2

Page 643

ZyWALL 5/35/70 Series User’s Guide678 Chapter 47 Firmware and Configuration File Maintenance

Page 644 - 44.5 Firewall Versus Filters

ZyWALL 5/35/70 Series User’s GuideChapter 48 System Maintenance Menus 8 to 10 679CHAPTER 48System Maintenance Menus 8 to10This chapter leads you throu

Page 645 - 44.5.2 Firewall

ZyWALL 5/35/70 Series User’s Guide68 Chapter 2 Introducing the Web ConfiguratorFigure 6 Change Password Screen6 Click Apply in the Replace Certifica

Page 646 - 44.6 Applying a Filter

ZyWALL 5/35/70 Series User’s Guide680 Chapter 48 System Maintenance Menus 8 to 10The required fields in a command are enclosed in angle brackets <&

Page 647 - HTTP connections

ZyWALL 5/35/70 Series User’s GuideChapter 48 System Maintenance Menus 8 to 10 68148.2 Call Control SupportThe ZyWALL provides two call control functi

Page 648

ZyWALL 5/35/70 Series User’s Guide682 Chapter 48 System Maintenance Menus 8 to 10Figure 429 Budget ManagementThe total budget is the time limit on t

Page 649 - CHAPTER 45

ZyWALL 5/35/70 Series User’s GuideChapter 48 System Maintenance Menus 8 to 10 683Figure 430 Call HistoryThe following table describes the fields in

Page 650 - 45.2 SNMP Traps

ZyWALL 5/35/70 Series User’s Guide684 Chapter 48 System Maintenance Menus 8 to 10Figure 431 Menu 24: System MaintenanceEnter 10 to go to Menu 24.10

Page 651 - CHAPTER 46

ZyWALL 5/35/70 Series User’s GuideChapter 48 System Maintenance Menus 8 to 10 685Table 252 Menu 24.10 System Maintenance: Time and Date SettingFIELD

Page 652

ZyWALL 5/35/70 Series User’s Guide686 Chapter 48 System Maintenance Menus 8 to 10End Date (mm-nth-week-hr)Configure the day and time when Daylight Sav

Page 653 - 46.3.1 System Information

ZyWALL 5/35/70 Series User’s GuideChapter 49 Remote Management 687CHAPTER 49Remote ManagementThis chapter covers remote management found in SMT menu 2

Page 654 - 46.3.2 Console Port Speed

ZyWALL 5/35/70 Series User’s Guide688 Chapter 49 Remote ManagementFigure 433 Menu 24.11 – Remote Management ControlThe following table describes the

Page 655 - 46.4 Log and Trace

ZyWALL 5/35/70 Series User’s GuideChapter 49 Remote Management 68949.1.1 Remote Management LimitationsRemote management over LAN or WAN will not work

Page 656 - 46.4.2 Syslog Logging

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 691 Press the RESET button for ten seconds, and then release it. If the S

Page 657 - 3 Filter log

ZyWALL 5/35/70 Series User’s Guide690 Chapter 49 Remote Management

Page 658 - 5 Firewall log

ZyWALL 5/35/70 Series User’s GuideChapter 50 IP Policy Routing 691CHAPTER 50IP Policy RoutingThis chapter covers setting and applying policies used fo

Page 659 - 46.5 Diagnostic

ZyWALL 5/35/70 Series User’s Guide692 Chapter 50 IP Policy Routing50.2 IP Routing Policy SetupTo setup a routing policy, perform the following proced

Page 660 - 46.5.1 WAN DHCP

ZyWALL 5/35/70 Series User’s GuideChapter 50 IP Policy Routing 6931 Type 25 in the main menu to open Menu 25 - IP Routing Policy Summary.2 Select Edit

Page 661

ZyWALL 5/35/70 Series User’s Guide694 Chapter 50 IP Policy Routing50.2.1 Applying Policy to PacketsTo apply the policy to packets received on the sel

Page 662

ZyWALL 5/35/70 Series User’s GuideChapter 50 IP Policy Routing 695Figure 436 Menu 25.1.1: IP Routing Policy SetupThe following table describes the f

Page 663 - CHAPTER 47

ZyWALL 5/35/70 Series User’s Guide696 Chapter 50 IP Policy RoutingFigure 437 Example of IP Policy Routing To force Web packets coming from clients w

Page 664 - 47.3 Backup Configuration

ZyWALL 5/35/70 Series User’s GuideChapter 50 IP Policy Routing 697Figure 438 IP Routing Policy Example 12 Select Yes in the LAN field in menu 25.1.1

Page 665

ZyWALL 5/35/70 Series User’s Guide698 Chapter 50 IP Policy RoutingFigure 439 IP Routing Policy Example 25 Select Yes in the LAN field in menu 25.1.1

Page 666 - 47.3.4 GUI-based FTP Clients

ZyWALL 5/35/70 Series User’s GuideChapter 51 Call Scheduling 699CHAPTER 51Call SchedulingCall scheduling allows you to dictate when a remote node shou

Page 667 - 47.3.7 TFTP Command Example

ZyWALL 5/35/70 Series User’s GuideZyXEL Limited Warranty 7ZyXEL Limited WarrantyZyXEL warrants to the original end user (purchaser) that this product

Page 668

ZyWALL 5/35/70 Series User’s Guide70 Chapter 2 Introducing the Web ConfiguratorFigure 9 HOME ScreenAs illustrated above, the main screen is divided

Page 669 - 47.4 Restore Configuration

ZyWALL 5/35/70 Series User’s Guide700 Chapter 51 Call SchedulingFigure 441 Schedule Set SetupIf a connection has been already established, your ZyWA

Page 670

ZyWALL 5/35/70 Series User’s GuideChapter 51 Call Scheduling 701Once your schedule sets are configured, you must then apply them to the desired remote

Page 671

ZyWALL 5/35/70 Series User’s Guide702 Chapter 51 Call SchedulingFigure 443 Applying Schedule Set(s) to a Remote Node (PPTP) Menu 11.1 -

Page 672 - 47.5.1 Firmware File Upload

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 703CHAPTER 52TroubleshootingThis chapter covers potential problems and possible remedies.

Page 673

ZyWALL 5/35/70 Series User’s Guide704 Chapter 52 Troubleshooting52.3 Problems with the DMZ Interface52.4 Problems with the WAN InterfaceTable 261

Page 674 - 47.5.5 TFTP File Upload

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 70552.5 Problems Accessing the ZyWALL52.5.1 Pop-up Windows, JavaScripts and Java Permis

Page 675

ZyWALL 5/35/70 Series User’s Guide706 Chapter 52 Troubleshooting• Web browser pop-up windows from your device.• JavaScripts (enabled by default).• Jav

Page 676

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 707Figure 445 Internet Options: Privacy3 Click Apply to save this setting.52.5.1.1.2 E

Page 677

ZyWALL 5/35/70 Series User’s Guide708 Chapter 52 TroubleshootingFigure 446 Internet Options: Privacy3 Type the IP address of your device (the web pa

Page 678

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 709Figure 447 Pop-up Blocker Settings5 Click Close to return to the Privacy screen. 6 C

Page 679 - CHAPTER 48

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 712.4.2 Main WindowThe main window shows the screen you select in the na

Page 680 - 48.1.2 Command Usage

ZyWALL 5/35/70 Series User’s Guide710 Chapter 52 TroubleshootingFigure 448 Internet Options: Security 2 Click the Custom Level... button. 3 Scroll d

Page 681 - 48.2 Call Control Support

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 711Figure 449 Security Settings - Java Scripting52.5.1.3 Java Permissions1 From Intern

Page 682 - 48.2.2 Call History

ZyWALL 5/35/70 Series User’s Guide712 Chapter 52 TroubleshootingFigure 450 Security Settings - Java 52.5.1.3.1 JAVA (Sun)1 From Internet Explorer,

Page 683 - 48.3 Time and Date Setting

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 713Figure 451 Java (Sun)52.6 Packet FlowThe following is the packet check flow on the

Page 684

ZyWALL 5/35/70 Series User’s Guide714 Chapter 52 Troubleshooting

Page 685

ZyWALL 5/35/70 Series User’s GuideAppendix A Product Specifications 715APPENDIX AProduct SpecificationsSee also the Introduction chapter for a general

Page 686

ZyWALL 5/35/70 Series User’s Guide716 Appendix A Product SpecificationsOperation Humidity 20% ~ 95% RH (non-condensing)Storage Humidity 20% ~ 95% RH (

Page 687 - CHAPTER 49

ZyWALL 5/35/70 Series User’s GuideAppendix A Product Specifications 717Anti-Virus/IDP (Intrusion Detection and Prevention)Accelerated by a ZyWALL Turb

Page 688

ZyWALL 5/35/70 Series User’s Guide718 Appendix A Product Specifications Other Protocol Support PPP (Point-to-Point Protocol) link layer protocol.Trans

Page 689

ZyWALL 5/35/70 Series User’s GuideAppendix A Product Specifications 719Compatible ZyXEL WLAN CardsThe following table lists the ZyXEL WLAN cards that

Page 690

ZyWALL 5/35/70 Series User’s Guide72 Chapter 2 Introducing the Web ConfiguratorSystem Name This is the System Name you enter in the MAINTENANCE > G

Page 691 - CHAPTER 50

ZyWALL 5/35/70 Series User’s Guide720 Appendix A Product SpecificationsNote: Only certain ZyXEL wireless LAN cards are compatible with the ZyWALL.Do n

Page 692 - 50.2 IP Routing Policy Setup

ZyWALL 5/35/70 Series User’s GuideAppendix A Product Specifications 721 Figure 454 Ethernet Cable Pin AssignmentsTable 269 Console/Dial Backup Por

Page 693

ZyWALL 5/35/70 Series User’s Guide722 Appendix A Product Specifications

Page 694 - (shown next)

ZyWALL 5/35/70 Series User’s GuideAppendix B Hardware Installation 723APPENDIX BHardware InstallationThe ZyWALL can be placed on a desktop or rack-mou

Page 695

ZyWALL 5/35/70 Series User’s Guide724 Appendix B Hardware InstallationFigure 455 Attaching Rubber Feet Note: Do not block the ventilation holes.

Page 696

ZyWALL 5/35/70 Series User’s GuideAppendix B Hardware Installation 725Figure 456 Attaching Mounting Brackets and Screws3 After attaching both mounti

Page 697

ZyWALL 5/35/70 Series User’s Guide726 Appendix B Hardware Installation

Page 698 - LAN port

ZyWALL 5/35/70 Series User’s GuideAppendix C Removing and Installing a Fuse 727APPENDIX CRemoving and Installing a FuseThis appendix shows you how to

Page 699 - CHAPTER 51

ZyWALL 5/35/70 Series User’s Guide728 Appendix C Removing and Installing a Fuse

Page 700

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 729APPENDIX DSetting up Your Computer’s IP AddressAll computers mus

Page 701

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 73Status For the LAN, DMZ and WLAN ports, this displays the port speed an

Page 702

ZyWALL 5/35/70 Series User’s Guide730 Appendix D Setting up Your Computer’s IP AddressFigure 458 WIndows 95/98/Me: Network: ConfigurationInstalling

Page 703 - CHAPTER 52

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 7314 Select Client for Microsoft Networks from the list of network

Page 704

ZyWALL 5/35/70 Series User’s Guide732 Appendix D Setting up Your Computer’s IP AddressFigure 460 Windows 95/98/Me: TCP/IP Properties: DNS Configurat

Page 705

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 733Figure 461 Windows XP: Start Menu2 In the Control Panel, doubl

Page 706 - Figure 444 Pop-up Blocker

ZyWALL 5/35/70 Series User’s Guide734 Appendix D Setting up Your Computer’s IP AddressFigure 463 Windows XP: Control Panel: Network Connections: Pro

Page 707

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 735• Click Advanced.Figure 465 Windows XP: Internet Protocol (TCP

Page 708

ZyWALL 5/35/70 Series User’s Guide736 Appendix D Setting up Your Computer’s IP AddressFigure 466 Windows XP: Advanced TCP/IP Properties7 In the Inte

Page 709 - 52.5.1.2 JavaScripts

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 737Figure 467 Windows XP: Internet Protocol (TCP/IP) Properties8

Page 710 - 3 Scroll down to Scripting

ZyWALL 5/35/70 Series User’s Guide738 Appendix D Setting up Your Computer’s IP AddressFigure 468 Macintosh OS 8/9: Apple Menu2 Select Ethernet built

Page 711 - 52.5.1.3 Java Permissions

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 739•From the Configure box, select Manually.• Type your IP address

Page 712 - 52.5.1.3.1 JAVA (Sun)

ZyWALL 5/35/70 Series User’s Guide74 Chapter 2 Introducing the Web Configurator2.4.4 HOME Screen: Bridge Mode The following screen displays when t

Page 713 - 52.6 Packet Flow

ZyWALL 5/35/70 Series User’s Guide740 Appendix D Setting up Your Computer’s IP AddressFigure 471 Macintosh OS X: Network4 For statically assigned se

Page 714

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 741Note: Make sure you are logged in as the root administrator. Usi

Page 715 - APPENDIX A

ZyWALL 5/35/70 Series User’s Guide742 Appendix D Setting up Your Computer’s IP Address• If you have a static IP address, click Statically set IP Addre

Page 716 - Table 265 Performance

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 743• If you have a dynamic IP address, enter dhcp in the BOOTPROTO=

Page 717

ZyWALL 5/35/70 Series User’s Guide744 Appendix D Setting up Your Computer’s IP AddressFigure 479 Red Hat 9.0: Restart Ethernet Card Verifying Setti

Page 718

ZyWALL 5/35/70 Series User’s GuideAppendix E IP Addresses and Subnetting 745APPENDIX EIP Addresses and SubnettingThis appendix introduces IP addresses

Page 719 - Compatible ZyXEL WLAN Cards

ZyWALL 5/35/70 Series User’s Guide746 Appendix E IP Addresses and SubnettingThe following table shows the network number and host ID arrangement for c

Page 720 - Cable Pin Assignments

ZyWALL 5/35/70 Series User’s GuideAppendix E IP Addresses and Subnetting 747Subnet MasksA subnet mask is used to determine which bits are part of the

Page 721

ZyWALL 5/35/70 Series User’s Guide748 Appendix E IP Addresses and SubnettingThe first mask shown is the class “C” natural mask. Normally if no mask is

Page 722

ZyWALL 5/35/70 Series User’s GuideAppendix E IP Addresses and Subnetting 749Host IDs of all zeros represent the subnet itself and host IDs of all ones

Page 723 - APPENDIX B

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 75You can use the firewall and VPN in bridge mode.Figure 11 Web Configu

Page 724 - Rack-Mounted Installation

ZyWALL 5/35/70 Series User’s Guide750 Appendix E IP Addresses and SubnettingExample Eight SubnetsSimilarly use a 27-bit mask to create eight subnets (

Page 725 - Figure 457 Rack Mounting

ZyWALL 5/35/70 Series User’s GuideAppendix E IP Addresses and Subnetting 751The following table shows class C IP address last octet values for each su

Page 726

ZyWALL 5/35/70 Series User’s Guide752 Appendix E IP Addresses and SubnettingThe following table is a summary for class “B” subnet planning. Table 283

Page 727 - APPENDIX C

ZyWALL 5/35/70 Series User’s GuideAppendix F Common Services 753Appendix F Common ServicesThe following table lists some commonly-used services and th

Page 728

ZyWALL 5/35/70 Series User’s Guide754 Appendix F Common ServicesHTTP TCP 80 Hyper Text Transfer Protocol - a client/server protocol for the world wide

Page 729 - APPENDIX D

ZyWALL 5/35/70 Series User’s GuideAppendix F Common Services 755SFTP TCP 115 Simple File Transfer Protocol.SMTP TCP 25 Simple Mail Transfer Protocol i

Page 730 - Installing Components

ZyWALL 5/35/70 Series User’s Guide756 Appendix F Common Services

Page 731 - Configuring

ZyWALL 5/35/70 Series User’s GuideAppendix G Wireless LANs 757APPENDIX GWireless LANsWireless LAN TopologiesThis section discusses ad-hoc and infrastr

Page 732 - Windows 2000/NT/XP

ZyWALL 5/35/70 Series User’s Guide758 Appendix G Wireless LANsFigure 482 Basic Service SetESSAn Extended Service Set (ESS) consists of a series of o

Page 733

ZyWALL 5/35/70 Series User’s GuideAppendix G Wireless LANs 759Figure 483 Infrastructure WLANChannelA channel is the radio frequency(ies) used by IEE

Page 734

ZyWALL 5/35/70 Series User’s Guide76 Chapter 2 Introducing the Web ConfiguratorSystem Time This field displays your ZyWALL’s present date (in yyyy-mm-

Page 735

ZyWALL 5/35/70 Series User’s Guide760 Appendix G Wireless LANsFigure 484 RTS/CTSWhen station A sends data to the AP, it might not know that the stat

Page 736

ZyWALL 5/35/70 Series User’s GuideAppendix G Wireless LANs 761A large Fragmentation Threshold is recommended for networks not prone to interference wh

Page 737 - Macintosh OS 8/9

ZyWALL 5/35/70 Series User’s Guide762 Appendix G Wireless LANsIEEE 802.1xIn June 2001, the IEEE 802.1x standard was designed to extend the features of

Page 738

ZyWALL 5/35/70 Series User’s GuideAppendix G Wireless LANs 763• Access-ChallengeSent by a RADIUS server requesting more information in order to allow

Page 739 - Macintosh OS X

ZyWALL 5/35/70 Series User’s Guide764 Appendix G Wireless LANs3 The wireless station replies with identity information, including username and passwor

Page 740 - Verifying Settings

ZyWALL 5/35/70 Series User’s GuideAppendix G Wireless LANs 765PEAP (Protected EAP) Like EAP-TTLS, server-side certificate authentication is used to

Page 741

ZyWALL 5/35/70 Series User’s Guide766 Appendix G Wireless LANsFigure 486 WEP Authentication StepsOpen system authentication involves an unencrypted

Page 742 - Using Configuration Files

ZyWALL 5/35/70 Series User’s GuideAppendix G Wireless LANs 767If this feature is enabled, it is not necessary to configure a default encryption key in

Page 743

ZyWALL 5/35/70 Series User’s Guide768 Appendix G Wireless LANsThe RADIUS server distributes a Pairwise Master Key (PMK) key to the AP that then sets u

Page 744

ZyWALL 5/35/70 Series User’s GuideAppendix G Wireless LANs 769RoamingA wireless station is a device with an IEEE 802.11 mode compliant wireless adapte

Page 745 - APPENDIX E

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 77Port Status For the WAN, LAN, DMZ, and WLAN Interfaces, this displays t

Page 746

ZyWALL 5/35/70 Series User’s Guide770 Appendix G Wireless LANs3 Access point P2 acknowledges the presence of wireless station Y and relays this inform

Page 747 - Subnetting

ZyWALL 5/35/70 Series User’s GuideAppendix H Windows 98 SE/Me Requirements for Anti-Virus Message Display 771APPENDIX HWindows 98 SE/Me Requirements f

Page 748 - Example: Two Subnets

ZyWALL 5/35/70 Series User’s Guide772 Appendix H Windows 98 SE/Me Requirements for Anti-Virus Message DisplayFigure 490 Windows 98 SE: Task Bar Prop

Page 749 - Example: Four Subnets

ZyWALL 5/35/70 Series User’s GuideAppendix H Windows 98 SE/Me Requirements for Anti-Virus Message Display 773Figure 492 Windows 98 SE: Startup: Crea

Page 750 - Example Eight Subnets

ZyWALL 5/35/70 Series User’s Guide774 Appendix H Windows 98 SE/Me Requirements for Anti-Virus Message DisplayFigure 494 Windows 98 SE: Startup: Shor

Page 751 - Table 281 Eight Subnets

ZyWALL 5/35/70 Series User’s GuideAppendix I VPN Setup 775APPENDIX IVPN SetupThis appendix will help you to quickly create a IPSec/VPN connection betw

Page 752

ZyWALL 5/35/70 Series User’s Guide776 Appendix I VPN SetupThe following pages show a typical configuration that builds a tunnel between two private ne

Page 753 - Common Services

ZyWALL 5/35/70 Series User’s GuideAppendix I VPN Setup 777Figure 496 Headquarters Gateway Policy EditThe IP address of the branch office IPSec route

Page 754

ZyWALL 5/35/70 Series User’s Guide778 Appendix I VPN SetupFigure 497 Branch Office Gateway Policy Edit3 Click the add network policy ( ) icon next t

Page 755

ZyWALL 5/35/70 Series User’s GuideAppendix I VPN Setup 779Figure 498 Headquarters VPN RuleFigure 499 Branch Office VPN Rule4 Configure the screens

Page 756

ZyWALL 5/35/70 Series User’s Guide78 Chapter 2 Introducing the Web Configurator2.4.5 Navigation PanelAfter you enter the password, use the sub-menus

Page 757 - APPENDIX G

ZyWALL 5/35/70 Series User’s Guide780 Appendix I VPN SetupFigure 500 Headquarters Network Policy EditIP addresses on different subnets.Activate the

Page 758 - 758 Appendix G Wireless LANs

ZyWALL 5/35/70 Series User’s GuideAppendix I VPN Setup 781Figure 501 Branch Office Network Policy EditDialing the VPN Tunnel via Web ConfiguratorTo

Page 759 - Appendix G Wireless LANs 759

ZyWALL 5/35/70 Series User’s Guide782 Appendix I VPN SetupFigure 502 VPN Rule ConfiguredThe following screen displays.Figure 503 VPN DialThis scre

Page 760 - Fragmentation Threshold

ZyWALL 5/35/70 Series User’s GuideAppendix I VPN Setup 783VPN TroubleshootingIf the IPSec tunnel does not build properly, the problem is likely a conf

Page 761 - Preamble Type

ZyWALL 5/35/70 Series User’s Guide784 Appendix I VPN SetupFigure 505 VPN Log Example ras> sys log disp ike ipsec# .time source

Page 762 - IEEE 802.1x

ZyWALL 5/35/70 Series User’s GuideAppendix I VPN Setup 785IPSec DebugIf you are having difficulty building an IPSec tunnel to a non-ZyXEL IPSec router

Page 763 - EAP Authentication

ZyWALL 5/35/70 Series User’s Guide786 Appendix I VPN SetupUse a VPN TunnelA VPN tunnel gives you a secure connection to another computer or network. T

Page 764 - Types of Authentication

ZyWALL 5/35/70 Series User’s GuideAppendix J Importing Certificates 787APPENDIX JImporting CertificatesThis appendix shows importing certificates exam

Page 765 - WEP Authentication Steps

ZyWALL 5/35/70 Series User’s Guide788 Appendix J Importing CertificatesFigure 508 Login Screen2 Click Install Certificate to open the Install Certif

Page 766 - Dynamic WEP Key Exchange

ZyWALL 5/35/70 Series User’s GuideAppendix J Importing Certificates 789Figure 510 Certificate Import Wizard 14 Select where you would like to store

Page 767 - Encryption

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 79Table Key: An O in a mode’s column shows that the device mode has the s

Page 768 - Security Parameters Summary

ZyWALL 5/35/70 Series User’s Guide790 Appendix J Importing CertificatesFigure 512 Certificate Import Wizard 36 Click Yes to add the ZyWALL certific

Page 769 - Figure 487 Roaming Example

ZyWALL 5/35/70 Series User’s GuideAppendix J Importing Certificates 791Figure 514 Certificate General Information after ImportEnrolling and Importin

Page 770 - Requirements for Roaming

ZyWALL 5/35/70 Series User’s Guide792 Appendix J Importing CertificatesFigure 515 ZyWALL Trusted CA ScreenThe CA sends you a package containing the

Page 771 - APPENDIX H

ZyWALL 5/35/70 Series User’s GuideAppendix J Importing Certificates 793Figure 516 CA Certificate Example2 Click Install Certificate and follow the w

Page 772

ZyWALL 5/35/70 Series User’s Guide794 Appendix J Importing CertificatesFigure 517 Personal Certificate Import Wizard 12 The file name and path of th

Page 773

ZyWALL 5/35/70 Series User’s GuideAppendix J Importing Certificates 795Figure 519 Personal Certificate Import Wizard 34 Have the wizard determine wh

Page 774

ZyWALL 5/35/70 Series User’s Guide796 Appendix J Importing CertificatesFigure 521 Personal Certificate Import Wizard 56 You should see the following

Page 775 - APPENDIX I

ZyWALL 5/35/70 Series User’s GuideAppendix J Importing Certificates 797Figure 524 SSL Client Authentication3 You next see the ZyWALL login screen.Fi

Page 776 - VPN Configuration

ZyWALL 5/35/70 Series User’s Guide798 Appendix J Importing Certificates

Page 777 - Appendix I VPN Setup 777

ZyWALL 5/35/70 Series User’s GuideAppendix K Command Interpreter 799APPENDIX KCommand InterpreterThe following describes how to use the command interp

Page 778 - 778 Appendix I VPN Setup

ZyWALL 5/35/70 Series User’s Guide8 Customer SupportCustomer SupportPlease have the following information ready when you contact customer support.• Pr

Page 779 - Appendix I VPN Setup 779

ZyWALL 5/35/70 Series User’s Guide80 Chapter 2 Introducing the Web ConfiguratorWAN General This screen allows you to configure load balancing, route p

Page 780 - 780 Appendix I VPN Setup

ZyWALL 5/35/70 Series User’s Guide800 Appendix K Command InterpreterFigure 526 Displaying Log Categories Example3 Use sys logs category followed by

Page 781 - Appendix I VPN Setup 781

ZyWALL 5/35/70 Series User’s GuideAppendix K Command Interpreter 801Log Command ExampleThis example shows how to set the ZyWALL to record the access l

Page 782 - Figure 503 VPN Dial

ZyWALL 5/35/70 Series User’s Guide802 Appendix K Command InterpreterFigure 528 Routing Command ExampleARP Behavior and the ARP ackGratuitous Command

Page 783 - VPN Troubleshooting

ZyWALL 5/35/70 Series User’s GuideAppendix K Command Interpreter 803A backup gateway (as in the following graphic) is an example of when you might wan

Page 784 - Figure 505 VPN Log Example

ZyWALL 5/35/70 Series User’s Guide804 Appendix K Command InterpreterFigure 530 Managing the Bandwidth of an IPSec SAUse on with this command to set

Page 785 - IPSec Debug

ZyWALL 5/35/70 Series User’s GuideAppendix K Command Interpreter 805Setting the Key Length for Phase 2 IPSec AES Encryption By default the ZyWALL us

Page 786 - Use a VPN Tunnel

ZyWALL 5/35/70 Series User’s Guide806 Appendix K Command Interpreter

Page 787 - APPENDIX J

ZyWALL 5/35/70 Series User’s GuideAppendix L Firewall Commands 807APPENDIX LFirewall CommandsThe following describes the firewall commands. See Append

Page 788 - Figure 508 Login Screen

ZyWALL 5/35/70 Series User’s Guide808 Appendix L Firewall CommandsE-mail config edit firewall e-mail mail-server <ip address of mail server>Thi

Page 789

ZyWALL 5/35/70 Series User’s GuideAppendix L Firewall Commands 809config edit firewall attack minute-high <0-255>This command sets the threshold

Page 790

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 81IDP General Use this screen to enable IDP on the ZyWALL and choose what

Page 791

ZyWALL 5/35/70 Series User’s Guide810 Appendix L Firewall CommandsConfig edit firewall set <set #> tcp-idle-timeout <seconds>This command

Page 792

ZyWALL 5/35/70 Series User’s GuideAppendix L Firewall Commands 811config edit firewall set <set #> rule <rule #> destaddr-subnet <ip ad

Page 793

ZyWALL 5/35/70 Series User’s Guide812 Appendix L Firewall Commands

Page 794

ZyWALL 5/35/70 Series User’s GuideAppendix M NetBIOS Filter Commands 813APPENDIX MNetBIOS Filter CommandsThe following describes the NetBIOS packet fi

Page 795

ZyWALL 5/35/70 Series User’s Guide814 Appendix M NetBIOS Filter CommandsThe filter types and their default settings are as follows.NetBIOS Filter Conf

Page 796

ZyWALL 5/35/70 Series User’s GuideAppendix M NetBIOS Filter Commands 815sys filter netbios config 3 onThis command blocks IPSec NetBIOS packets.sys fi

Page 797

ZyWALL 5/35/70 Series User’s Guide816 Appendix M NetBIOS Filter Commands

Page 798

ZyWALL 5/35/70 Series User’s GuideAppendix N Certificates Commands 817APPENDIX NCertificates CommandsThe following describes the certificate commands.

Page 799 - APPENDIX K

ZyWALL 5/35/70 Series User’s Guide818 Appendix N Certificates Commandscreate cmp_enroll <name> <CA addr> <CA cert> <auth key>

Page 800 - Displaying Logs

ZyWALL 5/35/70 Series User’s GuideAppendix N Certificates Commands 819replace_factoryCreate a certificate using your device MAC address that will be s

Page 801 - Routing Command

ZyWALL 5/35/70 Series User’s Guide82 Chapter 2 Introducing the Web ConfiguratorAUTH SERVER Local User DatabaseUse this screen to configure the local u

Page 802

ZyWALL 5/35/70 Series User’s Guide820 Appendix N Certificates Commands delete <name> Delete the specified trusted remote host certificate. <n

Page 803 - Figure 529 Backup Gateway

ZyWALL 5/35/70 Series User’s GuideAppendix O Brute-Force Password Guessing Protection 821APPENDIX OBrute-Force Password GuessingProtectionBrute-force

Page 804

ZyWALL 5/35/70 Series User’s Guide822 Appendix O Brute-Force Password Guessing Protection

Page 805

ZyWALL 5/35/70 Series User’s GuideAppendix P Boot Commands 823APPENDIX PBoot CommandsThe BootModule AT commands execute from within the router’s bootu

Page 806

ZyWALL 5/35/70 Series User’s Guide824 Appendix P Boot CommandsFigure 534 Boot Module CommandsAT just answer OKATHE print helpATB

Page 807 - APPENDIX L

ZyWALL 5/35/70 Series User’s GuideIndex 825IndexNumerics10/100 Mbps DMZ 5610/100 Mbps LAN 5610/100 Mbps WAN 579600 baud 549Aaccess control 258Access P

Page 808

ZyWALL 5/35/70 Series User’s Guide826 Indexblacklist 288, 296boldArial font 54Times New Roman font 54boot sector virus 271BPDU 143bridge firewall 57,

Page 809

ZyWALL 5/35/70 Series User’s GuideIndex 827use server detected IP 562wildcard 561default configuration 68default server IP address 405default settings

Page 810

ZyWALL 5/35/70 Series User’s Guide828 Indexfilter 574, 585, 606, 633and NAT 644applying 646configuration 633configuring 636DMZ 646example 642filter ru

Page 811

ZyWALL 5/35/70 Series User’s GuideIndex 829and certificates 329and RADIUS 330authentication algorithms 327, 333Diffie-Hellman key group 328encryption

Page 812

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 832.4.6 Port Statistics Click Port Statistics in the HOME screen. Read-

Page 813 - APPENDIX M

ZyWALL 5/35/70 Series User’s Guide830 IndexMAC Service Data Unit. See MSDU.macro virus 271mail sessions threshold 292main menu commands 550maintenance

Page 814 - NetBIOS Filter Configuration

ZyWALL 5/35/70 Series User’s GuideIndex 831PMK 768Point-to-Point Protocol over Ethernet. See PPPoEPoint-to-Point Tunneling Protocol. See PPTP.policy a

Page 815

ZyWALL 5/35/70 Series User’s Guide832 Indexrequired fields 551reset button 57, 68resetting the time 536resetting the ZyWALL 68restore configuration 54

Page 816

ZyWALL 5/35/70 Series User’s GuideIndex 833GetNext 468manager 468MIB 468, 469password 649Set 468Trap 468trusted host 649SNMP service 405source address

Page 817 - APPENDIX N

ZyWALL 5/35/70 Series User’s Guide834 IndexUunicast 131Universal Plug and Play. See UPnP.unsolicited commercial e-mail 285upgrading firmware 542upload

Page 818

ZyWALL 5/35/70 Series User’s GuideIndex 835ZZyNOS 654, 664ZyWALL registration 124ZyXEL’s Network Operating System. See ZyNOS.

Page 819

ZyWALL 5/35/70 Series User’s Guide84 Chapter 2 Introducing the Web ConfiguratorThe following table describes the labels in this screen.2.4.7 Show Sta

Page 820

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 85Figure 13 HOME > Show Statistics > Line ChartThe following tabl

Page 821 - APPENDIX O

ZyWALL 5/35/70 Series User’s Guide86 Chapter 2 Introducing the Web ConfiguratorFigure 14 HOME > DHCP TableThe following table describes the label

Page 822

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 87Figure 15 HOME > VPN StatusThe following table describes the label

Page 823 - APPENDIX P

ZyWALL 5/35/70 Series User’s Guide88 Chapter 2 Introducing the Web ConfiguratorFigure 16 Home > Bandwidth MonitorThe following table describes th

Page 824 - 824 Appendix P Boot Commands

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 89CHAPTER 3Wizard SetupThis chapter provides information on the Wizard Setup screens in the w

Page 825 - Numerics

ZyWALL 5/35/70 Series User’s GuideCustomer Support 9+” is the (prefix) number you enter to make an international telephone [email protected]

Page 826 - 826 Index

ZyWALL 5/35/70 Series User’s Guide90 Chapter 3 Wizard SetupFigure 17 Wizard Setup Welcome3.2 Internet Access The Internet access wizard screen has

Page 827 - Index 827

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 91Figure 18 ISP Parameters: Ethernet EncapsulationThe following table describes the labels

Page 828 - 828 Index

ZyWALL 5/35/70 Series User’s Guide92 Chapter 3 Wizard Setup3.2.1.2 PPPoE Encapsulation Point-to-Point Protocol over Ethernet (PPPoE) functions as a d

Page 829 - Index 829

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 933.2.1.3 PPTP EncapsulationPoint-to-Point Tunneling Protocol (PPTP) is a network protocol t

Page 830 - 830 Index

ZyWALL 5/35/70 Series User’s Guide94 Chapter 3 Wizard SetupNote: The ZyWALL supports one PPTP server connection at any given time.Figure 20 ISP Para

Page 831 - Index 831

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 953.2.2 Internet Access Wizard: Second ScreenClick Next to go to the screen where you can re

Page 832 - 832 Index

ZyWALL 5/35/70 Series User’s Guide96 Chapter 3 Wizard SetupFigure 21 Internet Access Wizard: Second ScreenFigure 22 Internet Access Setup Complete

Page 833 - Index 833

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 97Figure 23 Internet Access Wizard: RegistrationThe following table describes the labels in

Page 834 - 834 Index

ZyWALL 5/35/70 Series User’s Guide98 Chapter 3 Wizard SetupFigure 24 Internet Access Wizard: Registration in ProgressClick Close to leave the wizard

Page 835 - Index 835

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 99Figure 26 Internet Access Wizard: Registration FailedIf the ZyWALL has been registered, t

Comments to this Manuals

No comments