ZyXEL 35 SERIES User Manual

Browse online or download User Manual for Networking ZyXEL 35 SERIES. ZyXEL 35 Series User's Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 807
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
ZyWALL 5/35/70 Series
Internet Security Appliance
Users Guide
Version 4.00
12/2005
Page view 0
1 2 ... 807

Summary of Contents

Page 1 - ZyWALL 5/35/70 Series

ZyWALL 5/35/70 SeriesInternet Security ApplianceUser’s GuideVersion 4.0012/2005

Page 2 - Copyright

ZyWALL 5/35/70 Series User’s Guide Table of Contents 10Table of ContentsCopyright ...

Page 3 - Statement

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 100Figure 30 VPN Wizard: VPN StatusThe following table describes the labels in this screen.

Page 4

ZyWALL 5/35/70 Series User’s Guide101 Chapter 3 Wizard SetupName This is the name of this VPN network policy.Network Policy SettingLocal NetworkStart

Page 5 - Safety Warnings

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 1023.8 VPN Wizard Setup CompleteCongratulations! You have successfully set up the VPN rule a

Page 6 - ZyXEL Limited Warranty

ZyWALL 5/35/70 Series User’s Guide103 Chapter 3 Wizard Setup

Page 7 - Customer Support

ZyWALL 5/35/70 Series User’s GuideChapter 4 Registration 104CHAPTER 4Registration4.1 myZyXEL.com overviewmyZyXEL.com is ZyXEL’s online services cente

Page 8 - Customer Support 8

ZyWALL 5/35/70 Series User’s Guide105 Chapter 4 RegistrationYou will get automatic e-mail notification of new signature releases from mySecurityZone

Page 9 - 9 Customer Support

ZyWALL 5/35/70 Series User’s GuideChapter 4 Registration 106The following table describes the labels in this screen. Note: If the ZyWALL is registered

Page 10 - Table of Contents

ZyWALL 5/35/70 Series User’s Guide107 Chapter 4 RegistrationFigure 33 Registration: Registered Device4.3 ServiceAfter you activate a trial, you ca

Page 11

ZyWALL 5/35/70 Series User’s GuideChapter 4 Registration 108The following table describes the labels in this screen. Table 21 ServiceLABEL DESCRIPTI

Page 12 - Chapter 7

ZyWALL 5/35/70 Series User’s Guide109 Chapter 4 Registration

Page 13 - Chapter 9

ZyWALL 5/35/70 Series User’s Guide11 Table of Contents2.4.5 Show Statistics: Line Chart...

Page 14 - Chapter 11

ZyWALL 5/35/70 Series User’s GuideChapter 5 LAN Screens 110CHAPTER 5LAN ScreensThis chapter describes how to configure LAN settings. This chapter is o

Page 15 - Chapter 13

ZyWALL 5/35/70 Series User’s Guide111 Chapter 5 LAN ScreensThese parameters should work for the majority of installations. If your ISP gives you expl

Page 16 - Chapter 15

ZyWALL 5/35/70 Series User’s GuideChapter 5 LAN Screens 112Both RIP-2B and RIP-2M send routing data in RIP-2 format; the difference being that RIP-2B

Page 17

ZyWALL 5/35/70 Series User’s Guide113 Chapter 5 LAN ScreensFigure 35 LANThe following table describes the labels in this screen.Table 22 LAN LAB

Page 18 - Chapter 20

ZyWALL 5/35/70 Series User’s GuideChapter 5 LAN Screens 114Multicast Select IGMP V-1 or IGMP V-2 or None. IGMP (Internet Group Multicast Protocol) is

Page 19 - Chapter 22

ZyWALL 5/35/70 Series User’s Guide115 Chapter 5 LAN Screens5.6 LAN Static DHCPThis table allows you to assign IP addresses on the LAN to specific in

Page 20

ZyWALL 5/35/70 Series User’s GuideChapter 5 LAN Screens 1165.7 LAN IP AliasIP alias allows you to partition a physical network into different logical

Page 21 - Chapter 27

ZyWALL 5/35/70 Series User’s Guide117 Chapter 5 LAN ScreensFigure 38 LAN IP AliasThe following table describes the labels in this screen.Table 24

Page 22 - Chapter 29

ZyWALL 5/35/70 Series User’s GuideChapter 5 LAN Screens 1185.8 LAN Port RolesUse the Port Roles screen to set ports as LAN, DMZ or WLAN interfaces. T

Page 23

ZyWALL 5/35/70 Series User’s Guide119 Chapter 5 LAN ScreensTo change your ZyWALL’s port role settings, click NETWORK, LAN and then the Port Roles tab

Page 24

ZyWALL 5/35/70 Series User’s Guide Table of Contents 12Chapter 6Bridge Screens...

Page 25

ZyWALL 5/35/70 Series User’s GuideChapter 5 LAN Screens 120After you change the LAN/DMZ/WLAN port roles and click Apply, please wait for few seconds u

Page 26

ZyWALL 5/35/70 Series User’s Guide121 Chapter 5 LAN Screens

Page 27 - Chapter 47

ZyWALL 5/35/70 Series User’s GuideChapter 6 Bridge Screens 122CHAPTER 6Bridge ScreensThis chapter describes how to configure bridge settings. This cha

Page 28

ZyWALL 5/35/70 Series User’s Guide123 Chapter 6 Bridge Screens6.2.1 Rapid STPThe ZyWALL uses IEEE 802.1w RSTP (Rapid Spanning Tree Protocol) that al

Page 29 - 29 Table of Contents

ZyWALL 5/35/70 Series User’s GuideChapter 6 Bridge Screens 124Once a stable network topology has been established, all bridges listen for Hello BPDUs

Page 30 - Appendix S

ZyWALL 5/35/70 Series User’s Guide125 Chapter 6 Bridge ScreensFigure 43 BridgeThe following table describes the labels in this screen.Table 28 Br

Page 31 - 31 Table of Contents

ZyWALL 5/35/70 Series User’s GuideChapter 6 Bridge Screens 1266.4 Bridge Port Roles Use the Port Roles screen to set ports as LAN, DMZ or WLAN interf

Page 32 - List of Figures

ZyWALL 5/35/70 Series User’s Guide127 Chapter 6 Bridge ScreensFigure 44 WLAN Port Role Example To change your ZyWALL’s port role settings, click NE

Page 33

ZyWALL 5/35/70 Series User’s GuideChapter 6 Bridge Screens 128After you change the LAN/DMZ/WLAN port roles and click Apply, please wait for few second

Page 34

ZyWALL 5/35/70 Series User’s Guide129 Chapter 6 Bridge Screens

Page 35

ZyWALL 5/35/70 Series User’s Guide13 Table of Contents7.17 Configuring Advanced Modem Setup ...

Page 36

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 130CHAPTER 7WAN ScreensThis chapter describes how to configure WAN settings. Multiple WAN and

Page 37

ZyWALL 5/35/70 Series User’s Guide131 Chapter 7 WAN ScreensYou can select through which WAN port you want to send out traffic from UPnP-enabled appli

Page 38

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 1327.4.1.1 Example 1The following figure depicts an example where both the WAN ports on the Z

Page 39

ZyWALL 5/35/70 Series User’s Guide133 Chapter 7 WAN Screens7.4.2 Weighted Round Robin Similar to the Round Robin (RR) algorithm, the Weighted Round

Page 40

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 134Figure 49 Spillover Algorithm Example7.5 TCP/IP Priority (Metric)The metric represents t

Page 41

ZyWALL 5/35/70 Series User’s Guide135 Chapter 7 WAN ScreensFigure 50 WAN General

Page 42

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 136The following table describes the labels in this screen.Table 32 WAN General LABEL DESCRI

Page 43

ZyWALL 5/35/70 Series User’s Guide137 Chapter 7 WAN Screens7.7 Configuring Load Balancing To configure load balancing on the ZyWALL, click NETWORK,

Page 44 - List of Tables

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 1387.7.1 Least Load FirstTo configure Least Load First, select Least Load First in the Load B

Page 45

ZyWALL 5/35/70 Series User’s Guide139 Chapter 7 WAN Screens7.7.2 Weighted Round RobinTo load balance using the weighted round robin method, select W

Page 46

ZyWALL 5/35/70 Series User’s Guide Table of Contents 149.16.4 IEEE 802.1x + Dynamic WEP ...

Page 47

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 140Figure 53 Load Balancing: SpilloverThe following table describes the related fields in th

Page 48

ZyWALL 5/35/70 Series User’s Guide141 Chapter 7 WAN ScreensFigure 54 WAN RouteThe following table describes the labels in this screen.Table 36 WA

Page 49

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 1427.9 WAN IP Address Assignment Every computer on the Internet must have a unique IP address

Page 50

ZyWALL 5/35/70 Series User’s Guide143 Chapter 7 WAN Screens1 The ISP tells you the DNS server addresses, usually in the form of an information sheet,

Page 51 - 51 List of Tables

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 144Figure 55 WAN: Ethernet EncapsulationThe following table describes the labels in this scr

Page 52 - User Guide Feedback

ZyWALL 5/35/70 Series User’s Guide145 Chapter 7 WAN ScreensRetype to Confirm Type your password again to make sure that you have entered is correctly

Page 53 - Graphics Icons Key

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 1467.12.2 PPPoE EncapsulationThe ZyWALL supports PPPoE (Point-to-Point Protocol over Ethernet

Page 54 - CHAPTER 1

ZyWALL 5/35/70 Series User’s Guide147 Chapter 7 WAN ScreensOperationally, PPPoE saves significant effort for both you and the ISP or carrier, as it r

Page 55 - 1.2.1 Physical Features

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 148The following table describes the labels in this screen.Table 40 WAN: PPPoE Encapsulation

Page 56 - 1.2.2 Non-Physical Features

ZyWALL 5/35/70 Series User’s Guide149 Chapter 7 WAN ScreensRIP Direction RIP (Routing Information Protocol) allows a router to exchange routing infor

Page 57

ZyWALL 5/35/70 Series User’s Guide15 Table of Contents11.3.3.2 Service ...

Page 58

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 1507.12.3 PPTP EncapsulationPoint-to-Point Tunneling Protocol (PPTP) is a network protocol th

Page 59

ZyWALL 5/35/70 Series User’s Guide151 Chapter 7 WAN ScreensThe following table describes the labels in this screen.Table 41 WAN: PPTP Encapsulation

Page 60

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 152Enable NAT (Network Address Translation)Network Address Translation (NAT) allows the transl

Page 61

ZyWALL 5/35/70 Series User’s Guide153 Chapter 7 WAN Screens7.13 Traffic RedirectTraffic redirect forwards WAN traffic to a backup gateway when the Z

Page 62 - 1.3.2 VPN Application

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 154Figure 59 Traffic Redirect LAN Setup7.14 Configuring Traffic RedirectTo change your ZyWA

Page 63 - 1.3.3 Front Panel LEDs

ZyWALL 5/35/70 Series User’s Guide155 Chapter 7 WAN Screens7.15 Configuring Dial BackupClick NETWORK, WAN and then the Dial Backup tab to display t

Page 64 - Table 2 Front Panel LEDs

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 156Figure 61 Dial Backup

Page 65

ZyWALL 5/35/70 Series User’s Guide157 Chapter 7 WAN ScreensThe following table describes the labels in this screen.Table 43 Dial Backup LABEL DESCR

Page 66 - CHAPTER 2

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 158Enable RIP Select this check box to turn on RIP (Routing Information Protocol), which allow

Page 67 - 2.3 Resetting the ZyWALL

ZyWALL 5/35/70 Series User’s Guide159 Chapter 7 WAN Screens7.16 Advanced Modem Setup7.16.1 AT Command StringsFor regular telephone lines, the defau

Page 68 - Then click Send

ZyWALL 5/35/70 Series User’s Guide Table of Contents 1613.3.3 Signature Actions ...

Page 69 - 2.4.1 Router Mode

ZyWALL 5/35/70 Series User’s GuideChapter 7 WAN Screens 160Figure 62 Advanced SetupThe following table describes the labels in this screen. Table 44

Page 70

ZyWALL 5/35/70 Series User’s Guide161 Chapter 7 WAN ScreensDial Timeout (sec) Type a number of seconds for the ZyWALL to try to set up an outgoing ca

Page 71 - 2.4.2 Bridge Mode

ZyWALL 5/35/70 Series User’s GuideChapter 8 DMZ Screens 162CHAPTER 8DMZ ScreensThis chapter describes how to configure the ZyWALL’s DMZ.8.1 DMZThe De

Page 72

ZyWALL 5/35/70 Series User’s Guide163 Chapter 8 DMZ ScreensFigure 63 DMZThe following table describes the labels in this screen. Table 45 DMZ LAB

Page 73

ZyWALL 5/35/70 Series User’s GuideChapter 8 DMZ Screens 164RIP Version The RIP Version field controls the format and the broadcasting method of the RI

Page 74 - 2.4.3 Navigation Panel

ZyWALL 5/35/70 Series User’s Guide165 Chapter 8 DMZ Screens8.3 DMZ Static DHCPThis table allows you to assign IP addresses on the DMZ to specific in

Page 75 - Table 6 Screens Summary

ZyWALL 5/35/70 Series User’s GuideChapter 8 DMZ Screens 166Figure 64 DMZ Static DHCPThe following table describes the labels in this screen.Table 46

Page 76

ZyWALL 5/35/70 Series User’s Guide167 Chapter 8 DMZ Screens8.4 DMZ IP AliasIP alias allows you to partition a physical network into different logica

Page 77

ZyWALL 5/35/70 Series User’s GuideChapter 8 DMZ Screens 1688.5 DMZ Public IP Address ExampleThe following figure shows a simple network setup with pu

Page 78

ZyWALL 5/35/70 Series User’s Guide169 Chapter 8 DMZ ScreensFigure 66 DMZ Public Address Example8.6 DMZ Private and Public IP Address ExampleThe fo

Page 79 - 2.4.4 System Statistics

ZyWALL 5/35/70 Series User’s Guide17 Table of ContentsChapter 16Content Filtering Screens ...

Page 80

ZyWALL 5/35/70 Series User’s GuideChapter 8 DMZ Screens 170Figure 67 DMZ Private and Public Address Example8.7 DMZ Port RolesUse the Port Roles scr

Page 81 - 2.4.6 DHCP Table Screen

ZyWALL 5/35/70 Series User’s Guide171 Chapter 8 DMZ ScreensFigure 68 WLAN Port Role Example Note: Do the following if you are configuring from a co

Page 82 - 2.4.7 VPN Status

ZyWALL 5/35/70 Series User’s GuideChapter 8 DMZ Screens 172Figure 69 DMZ: Port RolesThe following table describes the labels in this screen. Table 4

Page 83 - Table 10 Home : VPN Status

ZyWALL 5/35/70 Series User’s Guide173 Chapter 8 DMZ Screens

Page 84 - CHAPTER 3

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 174CHAPTER 9Wireless LAN This chapter discusses how to configure wireless LAN on the ZyWALL.9

Page 85 - 85 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide175 Chapter 9 Wireless LANFigure 70 WLANThe following table describes the labels in this screen.Table 49 WLAN

Page 86 - 3.2.1.2 PPPoE Encapsulation

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 176RIP Version The RIP Version field controls the format and the broadcasting method of the R

Page 87 - 3.2.1.3 PPTP Encapsulation

ZyWALL 5/35/70 Series User’s Guide177 Chapter 9 Wireless LAN9.3 WLAN Static DHCPThis table allows you to assign IP addresses on the WLAN to specific

Page 88 - Chapter 3 Wizard Setup 88

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 178Figure 71 WLAN Static DHCPThe following table describes the labels in this screen.9.4 W

Page 89 - 89 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide179 Chapter 9 Wireless LANWhen you use IP alias, you can also configure firewall rules to control access between th

Page 90 - Chapter 3 Wizard Setup 90

ZyWALL 5/35/70 Series User’s Guide Table of Contents 18Chapter 19VPN Screens...

Page 91 - 91 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 1809.5 WLAN Port RolesUse the Port Roles screen to set ports as LAN, DMZ or WLAN interfaces.

Page 92 - Chapter 3 Wizard Setup 92

ZyWALL 5/35/70 Series User’s Guide181 Chapter 9 Wireless LANNote: Do the following if you are configuring from a computer connected to a LAN, DMZ or

Page 93 - 93 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 182After you change the LAN/DMZ/WLAN port roles and click Apply, please wait for few seconds

Page 94 - Chapter 3 Wizard Setup 94

ZyWALL 5/35/70 Series User’s Guide183 Chapter 9 Wireless LANFigure 76 ZyWALL Wireless Security LevelsIf you do not enable any wireless security on

Page 95 - 95 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 1849.6.3 Restricted AccessThe MAC Filter screen allows you to configure the AP to give exclu

Page 96 - Chapter 3 Wizard Setup 96

ZyWALL 5/35/70 Series User’s Guide185 Chapter 9 Wireless LAN9.9 802.1x OverviewThe IEEE 802.1x standard outlines enhanced security methods for both

Page 97 - 97 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 186Sent by the RADIUS server to indicate that it has started or stopped accounting. In order

Page 98 - Chapter 3 Wizard Setup 98

ZyWALL 5/35/70 Series User’s Guide187 Chapter 9 Wireless LANIf this feature is enabled, it is not necessary to configure a default encryption key in

Page 99 - 99 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 188TKIP regularly changes and rotates the encryption keys so that the same encryption key is

Page 100 - Chapter 3 Wizard Setup 100

ZyWALL 5/35/70 Series User’s Guide189 Chapter 9 Wireless LANFigure 78 WPA-PSK Authentication9.13 Introduction to RADIUSThe ZyWALL can use an exter

Page 101 - 101 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide19 Table of Contents20.5.1 Certificate File Formats ...

Page 102 - Chapter 3 Wizard Setup 102

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 190Figure 79 WPA with RADIUS Application Example9.15 Wireless Client WPA SupplicantsA wire

Page 103 - 103 Chapter 3 Wizard Setup

ZyWALL 5/35/70 Series User’s Guide191 Chapter 9 Wireless LANFigure 80 Wireless Card: No SecurityThe following table describes the labels in this sc

Page 104 - CHAPTER 4

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 1929.16.1 Static WEPStatic WEP provides a mechanism for encrypting data using encryption key

Page 105 - 4.2 Registration

ZyWALL 5/35/70 Series User’s Guide193 Chapter 9 Wireless LANFigure 81 Wireless Card: Static WEPThe following table describes the wireless LAN secur

Page 106 - Chapter 4 Registration 106

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 194Figure 82 Wireless Card: WPA-PSKThe following wireless LAN security fields become availa

Page 107 - 4.3 Service

ZyWALL 5/35/70 Series User’s Guide195 Chapter 9 Wireless LAN9.16.3 WPAClick the NETWORK and WIRELESS CARD to display the Wireless Card screen. Selec

Page 108 - Table 21 Service

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 1969.16.4 IEEE 802.1x + Dynamic WEPClick the NETWORK and WIRELESS CARD to display the Wirele

Page 109 - 109 Chapter 4 Registration

ZyWALL 5/35/70 Series User’s Guide197 Chapter 9 Wireless LAN9.16.5 IEEE 802.1x + Static WEPClick the NETWORK and WIRELESS CARD to display the Wirele

Page 110 - CHAPTER 5

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 1989.16.6 IEEE 802.1x + No WEPClick the NETWORK and WIRELESS CARD to display the Wireless Ca

Page 111 - 5.3.3 RIP Setup

ZyWALL 5/35/70 Series User’s Guide199 Chapter 9 Wireless LANThe following wireless LAN security fields become available when you select 802.1x + No W

Page 112 - 5.5 LAN

ZyWALL 5/35/70 Series User’s Guide Copyright 2CopyrightCopyright © 2005 by ZyXEL Communications Corporation.The contents of this publication may not b

Page 113 - Table 22 LAN

ZyWALL 5/35/70 Series User’s Guide Table of Contents 2022.7 Port Triggering ...

Page 114 - Table 22 LAN (continued)

ZyWALL 5/35/70 Series User’s GuideChapter 9 Wireless LAN 200The following wireless LAN security fields become available when you select No Access 802.

Page 115 - 5.6 LAN Static DHCP

ZyWALL 5/35/70 Series User’s Guide201 Chapter 9 Wireless LANFigure 88 Wireless Card: MAC Address FilterThe following table describes the labels in

Page 116 - 5.7 LAN IP Alias

ZyWALL 5/35/70 Series User’s GuideChapter 10 Firewalls 202CHAPTER 10FirewallsThis chapter gives some background information on firewalls and introduce

Page 117 - Table 24 LAN IP Alias

ZyWALL 5/35/70 Series User’s Guide203 Chapter 10 Firewalls1 Information hiding prevents the names of internal systems from being made known via DNS t

Page 118 - 5.8 LAN Port Roles

ZyWALL 5/35/70 Series User’s GuideChapter 10 Firewalls 204Figure 89 ZyWALL Firewall Application10.4 Denial of ServiceDenials of Service (DoS) attac

Page 119 - Table 25 LAN Port Roles

ZyWALL 5/35/70 Series User’s Guide205 Chapter 10 Firewalls10.4.2 Types of DoS AttacksThere are four types of DoS attacks: 1 Those that exploit bugs

Page 120 - Chapter 5 LAN Screens 120

ZyWALL 5/35/70 Series User’s GuideChapter 10 Firewalls 206response. While the targeted system waits for the ACK that follows the SYN-ACK, it queues up

Page 121 - 121 Chapter 5 LAN Screens

ZyWALL 5/35/70 Series User’s Guide207 Chapter 10 FirewallsFigure 92 Smurf Attack10.4.2.1 ICMP Vulnerability ICMP is an error-reporting protocol th

Page 122 - CHAPTER 6

ZyWALL 5/35/70 Series User’s GuideChapter 10 Firewalls 208All SMTP commands are illegal except for those displayed in the following tables.10.4.2.3 T

Page 123 - 6.2.3 How STP Works

ZyWALL 5/35/70 Series User’s Guide209 Chapter 10 FirewallsFigure 93 Stateful InspectionThe previous figure shows the ZyWALL’s default firewall rule

Page 124 - 6.3 Bridge

ZyWALL 5/35/70 Series User’s Guide21 Table of ContentsChapter 26DNS...

Page 125 - Table 28 Bridge

ZyWALL 5/35/70 Series User’s GuideChapter 10 Firewalls 210temporary entries might be modified, in order to permit only packets that are valid for the

Page 126 - 6.4 Bridge Port Roles

ZyWALL 5/35/70 Series User’s Guide211 Chapter 10 FirewallsIf an initiation packet originates on the LAN, this means that someone is trying to make a

Page 127 - Table 29 Bridge Port Roles

ZyWALL 5/35/70 Series User’s GuideChapter 10 Firewalls 212Any protocol that operates in this way must be supported on a case-by-case basis. You can us

Page 128 - Chapter 6 Bridge Screens 128

ZyWALL 5/35/70 Series User’s Guide213 Chapter 10 Firewalls10.7.2 Firewall• The firewall inspects packet contents as well as their source and destina

Page 129 - 129 Chapter 6 Bridge Screens

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 214CHAPTER 11Firewall ScreensThis chapter shows you how to configure your ZyWALL firewal

Page 130 - CHAPTER 7

ZyWALL 5/35/70 Series User’s Guide215 Chapter 11 Firewall Screens• WLAN to WANBy default, the ZyWALL’s stateful packet inspection drops packets trave

Page 131 - 7.4.1 Least Load First

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 21611.3 Rule Logic OverviewNote: Study these points carefully before configuring rules.

Page 132 - 7.4.1.2 Example 2

ZyWALL 5/35/70 Series User’s Guide217 Chapter 11 Firewall Screens11.3.3.2 ServiceSelect the service from the Service scrolling list box. If the serv

Page 133 - 7.4.3 Spillover

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 218Figure 94 LAN to WAN Traffic11.4.2 WAN To LAN RulesThe default rule for WAN to LAN

Page 134 - 7.6 WAN General

ZyWALL 5/35/70 Series User’s Guide219 Chapter 11 Firewall Screens11.6 Firewall Default Rule (Router Mode)Click SECURITY, FIREWALL to open the Defaul

Page 135 - Figure 50 WAN General

ZyWALL 5/35/70 Series User’s Guide Table of Contents 2227.13 FTP ...

Page 136 - Table 32 WAN General

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 22011.7 Firewall Default Rule (Bridge Mode) Click SECURITY, FIREWALL to open the Defau

Page 137 - Algorithm field

ZyWALL 5/35/70 Series User’s Guide221 Chapter 11 Firewall ScreensFigure 97 Default Rule (Bridge Mode)The following table describes the labels in th

Page 138 - 7.7.1 Least Load First

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 22211.8 Firewall Rule Summary Click SECURITY, FIREWALL, then the Rule Summary tab to op

Page 139 - 7.7.3 Spillover

ZyWALL 5/35/70 Series User’s Guide223 Chapter 11 Firewall Screens11.8.1 Firewall Edit Rule Follow these directions to create a new rule.1 In the

Page 140 - 7.8 WAN Route

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 224Figure 99 Firewall Edit Rule

Page 141 - Table 36 WAN Route

ZyWALL 5/35/70 Series User’s Guide225 Chapter 11 Firewall ScreensThe following table describes the labels in this screen. Table 70 Firewall Edit

Page 142 - Chapter 7 WAN Screens 142

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 22611.9 Anti-Probing If an outside user attempts to probe an unsupported port on you

Page 143 - 7.12 WAN

ZyWALL 5/35/70 Series User’s Guide227 Chapter 11 Firewall Screens11.10 Firewall Threshold In the Threshold screen, shown later, you may choose to

Page 144 - Chapter 7 WAN Screens 144

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 228When the rate of new connection attempts rises above a threshold (one-minute high), t

Page 145 - 145 Chapter 7 WAN Screens

ZyWALL 5/35/70 Series User’s Guide229 Chapter 11 Firewall ScreensFigure 101 Firewall ThresholdThe following table describes the labels in this scre

Page 146 - 7.12.2 PPPoE Encapsulation

ZyWALL 5/35/70 Series User’s Guide23 Table of ContentsChapter 30Logs Screens...

Page 147 - 147 Chapter 7 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 23011.11 Service Click SECURITY, FIREWALL, then the Service tab to open the screen as s

Page 148 - Chapter 7 WAN Screens 148

ZyWALL 5/35/70 Series User’s Guide231 Chapter 11 Firewall ScreensFigure 102 Firewall ServiceThe following table describes the labels in this screen

Page 149 - 149 Chapter 7 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 23211.11.1 Firewall Edit Custom Service Configure customized ports for services not pre

Page 150 - 7.12.3 PPTP Encapsulation

ZyWALL 5/35/70 Series User’s Guide233 Chapter 11 Firewall Screens11.11.2 Predefined ServicesThe Predefined Services table in the Service screen disp

Page 151 - 151 Chapter 7 WAN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 234IMAP(TCP/UDP:143) Internet Message Access Protocol (IMAP) is used to access mail stor

Page 152 - Chapter 7 WAN Screens 152

ZyWALL 5/35/70 Series User’s Guide235 Chapter 11 Firewall Screens11.12 Example Firewall Rule The following Internet firewall rule example allows a h

Page 153 - 7.13 Traffic Redirect

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 236Figure 104 Service2 Configure it as follows and click Apply.Figure 105 Edit Custo

Page 154 - Table 42 Traffic Redirect

ZyWALL 5/35/70 Series User’s Guide237 Chapter 11 Firewall ScreensFigure 106 Rule Summary6 Enter the name of the firewall rule.7 Select Any in the D

Page 155 - 7.15 Configuring Dial Backup

ZyWALL 5/35/70 Series User’s GuideChapter 11 Firewall Screens 238Note: Custom services show up with an * before their names in the Services list box a

Page 156 - Figure 61 Dial Backup

ZyWALL 5/35/70 Series User’s Guide239 Chapter 11 Firewall ScreensFigure 109 My Service Example Rule Summary Rule 1: Allows a My Service connection

Page 157 - Table 43 Dial Backup

ZyWALL 5/35/70 Series User’s Guide Table of Contents 2432.4 Changing the System Password ...

Page 158 - Chapter 7 WAN Screens 158

ZyWALL 5/35/70 Series User’s GuideChapter 12 Intrusion Detection and Prevention (IDP) 240CHAPTER 12Intrusion Detection and Prevention (IDP) This chapt

Page 159 - 7.16 Advanced Modem Setup

ZyWALL 5/35/70 Series User’s Guide241 Chapter 12 Intrusion Detection and Prevention (IDP)Firewalls are usually deployed at the network edge. However,

Page 160 - Table 44 Advanced Setup

ZyWALL 5/35/70 Series User’s GuideChapter 12 Intrusion Detection and Prevention (IDP) 24212.1.5 Example IntrusionsThe following are some examples of

Page 161 - 161 Chapter 7 WAN Screens

ZyWALL 5/35/70 Series User’s Guide243 Chapter 12 Intrusion Detection and Prevention (IDP)12.1.5.4 MyDoomMyDoom W32.Mydoom.A@mm (also known as W32.No

Page 162 - CHAPTER 8

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 244CHAPTER 13Configuring IDPThis chapter shows you how to configure IDP on the ZyWALL. 13

Page 163 - DMZ are on separate subnets

ZyWALL 5/35/70 Series User’s Guide245 Chapter 13 Configuring IDPFigure 111 Applying IDP to Interfaces13.2 General SetupUse this screen to enable I

Page 164 - Table 45 DMZ (continued)

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 246Figure 112 IDP: GeneralThe following table describes the labels in this screen.13.3

Page 165 - 8.3 DMZ Static DHCP

ZyWALL 5/35/70 Series User’s Guide247 Chapter 13 Configuring IDPTo see signatures listed by intrusion type supported by the ZyWALL, select that type

Page 166 - Table 46 DMZ Static DHCP

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 24813.3.2 Intrusion SeverityIntrusions are assigned a severity level based on the follow

Page 167 - 8.4 DMZ IP Alias

ZyWALL 5/35/70 Series User’s Guide249 Chapter 13 Configuring IDPFigure 114 Signature Actions The following table describes signature actions. 13.3.

Page 168 - Chapter 8 DMZ Screens 168

ZyWALL 5/35/70 Series User’s Guide25 Table of Contents37.3 TCP/IP Setup ...

Page 169 - 169 Chapter 8 DMZ Screens

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 250Figure 115 IDP: SignaturesThe following table describes the labels in this screen.Ta

Page 170 - 8.7 DMZ Port Roles

ZyWALL 5/35/70 Series User’s Guide251 Chapter 13 Configuring IDP13.3.5 Query View Click IDP in the navigation panel and then click the Signatures ta

Page 171 - 171 Chapter 8 DMZ Screens

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 252Note: A partial name may be searched but a complete ID number must be entered before a

Page 172 - Table 48 DMZ: Port Roles

ZyWALL 5/35/70 Series User’s Guide253 Chapter 13 Configuring IDPFigure 117 Signature Query by Complete ID13.3.5.2 Query Example 21 From the “group

Page 173 - 173 Chapter 8 DMZ Screens

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 254Figure 118 Signature Query by Attribute. 13.4 Update The ZyWALL comes with built-in

Page 174 - CHAPTER 9

ZyWALL 5/35/70 Series User’s Guide255 Chapter 13 Configuring IDP13.4.2 Configuring IDP UpdateWhen scheduling signature updates, you should choose a

Page 175

ZyWALL 5/35/70 Series User’s GuideChapter 13 Configuring IDP 256The following table describes the labels in this screen.Table 81 Signatures Update L

Page 176 - Table 49 WLAN (continued)

ZyWALL 5/35/70 Series User’s Guide257 Chapter 13 Configuring IDP13.5 Backup and RestoreYou can change the pre-defined Active, Log, Alert and/or Acti

Page 177 - 9.3 WLAN Static DHCP

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 258CHAPTER 14Anti-Virus This chapter introduces and shows you how to configure the anti-virus

Page 178 - 9.4 WLAN IP Alias

ZyWALL 5/35/70 Series User’s Guide259 Chapter 14 Anti-Virus2 The virus spreads to other files and programs on the computer. 3 The infected files are

Page 179 - Table 51 WLAN IP Alias

ZyWALL 5/35/70 Series User’s Guide Table of Contents 2642.2 NAT Setup ...

Page 180 - 9.5 WLAN Port Roles

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 26014.2.1 How the ZyWALL Anti-Virus Scanner WorksThe ZyWALL checks traffic going to the inte

Page 181 - Table 52 WLAN Port Roles

ZyWALL 5/35/70 Series User’s Guide261 Chapter 14 Anti-Virus1 The ZyWALL anti-virus scanner cannot detect polymorphic viruses. 2 The ZyWALL does not

Page 182 - 9.6 Wireless Security

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 262The following table describes the labels in this screen.14.4 Signature Update The ZyWALL

Page 183 - 9.6.2 Authentication

ZyWALL 5/35/70 Series User’s Guide263 Chapter 14 Anti-VirusNote: You should have already registered the ZyWALL at myZyXEL.com (http://www.myzyxel.com

Page 184 - 9.8 WEP Encryption

ZyWALL 5/35/70 Series User’s GuideChapter 14 Anti-Virus 264Figure 123 Anti-Virus: UpdateThe following table describes the labels in this screen. Ta

Page 185 - 9.9 802.1x Overview

ZyWALL 5/35/70 Series User’s Guide265 Chapter 14 Anti-VirusUpdate Now Click this button to begin downloading signatures from the Update Server immedi

Page 186 - Chapter 9 Wireless LAN 186

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 266CHAPTER 15Anti-SpamThis chapter covers how to use the ZyWALL’s anti-spam feature to deal wit

Page 187 - 9.11 Introduction to WPA

ZyWALL 5/35/70 Series User’s Guide267 Chapter 15 Anti-Spam15.1.1.1 SpamBulk EngineThe e-mail fingerprint ID that the ZyWALL generates and sends to t

Page 188 - Chapter 9 Wireless LAN 188

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 26815.1.1.4 SpamTricks EngineThe SpamTricks engine checks for the tactics that spammers use to

Page 189 - 9.13 Introduction to RADIUS

ZyWALL 5/35/70 Series User’s Guide269 Chapter 15 Anti-SpamThe anti-spam external database checks for spoofing of e-mail attributes (like the IP addre

Page 190 - 9.16 Wireless Card

ZyWALL 5/35/70 Series User’s Guide27 Table of Contents46.2 System Status ...

Page 191 - 191 Chapter 9 Wireless LAN

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 27015.1.7 MIME HeadersMIME (Multipurpose Internet Mail Extensions) allows varied media types t

Page 192 - 9.16.1 Static WEP

ZyWALL 5/35/70 Series User’s Guide271 Chapter 15 Anti-SpamThe following table describes the labels in this screen. 15.3 Anti-Spam External DB Screen

Page 193 - 9.16.2 WPA-PSK

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 272Figure 126 Anti-Spam: External DBThe following table describes the labels in this screen.

Page 194 - Chapter 9 Wireless LAN 194

ZyWALL 5/35/70 Series User’s Guide273 Chapter 15 Anti-Spam15.4 Anti-Spam Lists Screen Click SECURITY, ANTI-SPAM, Lists to display the Anti-Spam Lis

Page 195 - 9.16.3 WPA

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 274Figure 127 Anti-Spam: ListsThe following table describes the labels in this screen. Table

Page 196 - Chapter 9 Wireless LAN 196

ZyWALL 5/35/70 Series User’s Guide275 Chapter 15 Anti-Spam15.5 Anti-Spam Rule Edit Screen Click SECURITY, ANTI-SPAM, Lists to display the Anti-Spa

Page 197 - 197 Chapter 9 Wireless LAN

ZyWALL 5/35/70 Series User’s GuideChapter 15 Anti-Spam 276The following table describes the labels in this screen. Table 88 Anti-Spam Rule EditLAB

Page 198 - 9.16.6 IEEE 802.1x + No WEP

ZyWALL 5/35/70 Series User’s Guide277 Chapter 15 Anti-SpamApply Click Apply to save your settings and exit this screen.Cancel Click Cancel to exit th

Page 199 - 199 Chapter 9 Wireless LAN

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 278CHAPTER 16Content Filtering ScreensThis chapter provides an overview of cont

Page 200 - 9.17 MAC Filter

ZyWALL 5/35/70 Series User’s Guide279 Chapter 16 Content Filtering ScreensFigure 129 Content Filter : GeneralThe following table describes the labe

Page 201 - 201 Chapter 9 Wireless LAN

ZyWALL 5/35/70 Series User’s Guide Table of Contents 28Chapter 48System Maintenance Menus 8 to 10...

Page 202 - CHAPTER 10

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 28016.3 Content Filtering with an External DatabaseWhen you register for and e

Page 203 - 203 Chapter 10 Firewalls

ZyWALL 5/35/70 Series User’s Guide281 Chapter 16 Content Filtering ScreensFigure 130 Content Filtering Lookup Procedure1 A computer behind the ZyWA

Page 204 - 10.4 Denial of Service

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 282Figure 131 Content Filter : CategoriesThe following table describes the la

Page 205 - 10.4.2 Types of DoS Attacks

ZyWALL 5/35/70 Series User’s Guide283 Chapter 16 Content Filtering ScreensUnrated Web Pages Select Block to prevent users from accessing web pages th

Page 206 - Figure 91 SYN Flood

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 284Alcohol/Tobacco Selecting this category excludes pages that promote or offer

Page 207 - 10.4.2.1 ICMP Vulnerability

ZyWALL 5/35/70 Series User’s Guide285 Chapter 16 Content Filtering ScreensEducation Selecting this category excludes pages that offer educational inf

Page 208 - 10.5 Stateful Inspection

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 286News/Media Selecting this category excludes pages that primarily report info

Page 209 - 209 Chapter 10 Firewalls

ZyWALL 5/35/70 Series User’s Guide287 Chapter 16 Content Filtering ScreensHumor/Jokes Selecting this category excludes pages that primarily focus on

Page 210 - 10.5.3 TCP Security

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 28816.5 Content Filter Customization Click SECURITY, CONTENT FILTER, then th

Page 211 - 10.5.5 Upper Layer Protocols

ZyWALL 5/35/70 Series User’s Guide289 Chapter 16 Content Filtering ScreensThe following table describes the labels in this screen. Table 91 Content

Page 212 - 10.7.1 Packet Filtering:

ZyWALL 5/35/70 Series User’s Guide29 Table of ContentsHardware Installation...

Page 213 - 10.7.2 Firewall

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 29016.6 Customizing Keyword Blocking URL CheckingYou can use commands to set h

Page 214 - CHAPTER 11

ZyWALL 5/35/70 Series User’s Guide291 Chapter 16 Content Filtering ScreensUse the ip urlfilter customize actionFlags 8 [disable | enable] command to

Page 215

ZyWALL 5/35/70 Series User’s GuideChapter 16 Content Filtering Screens 292The following table describes the labels in this screen.Table 92 Content F

Page 216 - 11.3 Rule Logic Overview

ZyWALL 5/35/70 Series User’s Guide293 Chapter 16 Content Filtering Screens

Page 217 - 11.4.1 LAN To WAN Rules

ZyWALL 5/35/70 Series User’s GuideChapter 17 Content Filtering Reports 294CHAPTER 17Content Filtering ReportsThis chapter describes how to view conten

Page 218 - 11.5 Alerts

ZyWALL 5/35/70 Series User’s Guide295 Chapter 17 Content Filtering ReportsFigure 134 myZyXEL.com: Login3 A welcome screen displays. Click your ZyWA

Page 219

ZyWALL 5/35/70 Series User’s GuideChapter 17 Content Filtering Reports 296Figure 136 myZyXEL.com: Service Management5 Enter your ZyXEL device's

Page 220

ZyWALL 5/35/70 Series User’s Guide297 Chapter 17 Content Filtering ReportsFigure 138 Content Filtering Reports Main Screen8 Select items under Glob

Page 221

ZyWALL 5/35/70 Series User’s GuideChapter 17 Content Filtering Reports 298Figure 140 Global Report Screen Example11You can click a category in the C

Page 222 - 11.8 Firewall Rule Summary

ZyWALL 5/35/70 Series User’s Guide299 Chapter 17 Content Filtering ReportsFigure 141 Requested URLs Example17.3 Web Site SubmissionYou may find th

Page 223 - Table 69 Rule Summary

ZyWALL 5/35/70 Series User’s Guide3 Federal Communications Commission (FCC) Interference StatementFederal Communications Commission (FCC) Interferen

Page 224

ZyWALL 5/35/70 Series User’s Guide Table of Contents 30Appendix SLog Descriptions...

Page 225 - Table 70 Firewall Edit Rule

ZyWALL 5/35/70 Series User’s GuideChapter 17 Content Filtering Reports 300Figure 142 Web Page Review Process Screen3 Type the web site’s URL in the

Page 226 - 11.9 Anti-Probing

ZyWALL 5/35/70 Series User’s Guide301 Chapter 17 Content Filtering Reports

Page 227 - 11.10 Firewall Threshold

ZyWALL 5/35/70 Series User’s GuideChapter 18 Introduction to IPSec 302CHAPTER 18Introduction to IPSecThis chapter introduces the basics of IPSec VPNs.

Page 228

ZyWALL 5/35/70 Series User’s Guide303 Chapter 18 Introduction to IPSecFigure 143 Encryption and Decryption18.1.3.2 Data ConfidentialityThe IPSec s

Page 229

ZyWALL 5/35/70 Series User’s GuideChapter 18 Introduction to IPSec 30418.2 IPSec ArchitectureThe overall IPSec architecture is shown as follows.Figur

Page 230 - 11.11 Service

ZyWALL 5/35/70 Series User’s Guide305 Chapter 18 Introduction to IPSecFigure 145 Transport and Tunnel Mode IPSec Encapsulation18.3.1 Transport Mod

Page 231 - Table 73 Firewall Service

ZyWALL 5/35/70 Series User’s GuideChapter 18 Introduction to IPSec 306NAT is incompatible with the AH protocol in both Transport and Tunnel mode. An I

Page 232

ZyWALL 5/35/70 Series User’s Guide307 Chapter 18 Introduction to IPSec

Page 233 - 11.11.2 Predefined Services

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 308CHAPTER 19VPN ScreensThis chapter introduces the VPN Web Configurator. See Chapter 30 on p

Page 234

ZyWALL 5/35/70 Series User’s Guide309 Chapter 19 VPN Screens19.3 My ZyWALLMy ZyWALL identifies the WAN IP address or domain name of the ZyWALL (if i

Page 235 - 11.12 Example Firewall Rule

ZyWALL 5/35/70 Series User’s Guide31 Table of Contents

Page 236 - Figure 104 Service

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 310If the remote secure gateway has a static WAN IP address, enter it in the Remote Gateway A

Page 237 - Figure 106 Rule Summary

ZyWALL 5/35/70 Series User’s Guide311 Chapter 19 VPN ScreensFigure 146 NAT Router Between IPSec RoutersNormally you cannot set up a VPN connection

Page 238

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 312between three encryption algorithms (DES, 3DES and AES), two authentication algorithms (MD

Page 239 - 10.0.0.15 on the LAN

ZyWALL 5/35/70 Series User’s Guide313 Chapter 19 VPN ScreensThe two ZyWALLs in this example cannot complete their negotiation because ZyWALL B’s Loca

Page 240 - CHAPTER 12

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 314• Choose an authentication algorithm.• Choose a Diffie-Hellman public-key cryptography key

Page 241 - 12.1.4 Network IDP

ZyWALL 5/35/70 Series User’s Guide315 Chapter 19 VPN Screens19.8.3 Diffie-Hellman (DH) Key GroupsDiffie-Hellman (DH) is a public-key cryptography pr

Page 242 - 12.1.5 Example Intrusions

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 31619.10 VPN Rules (IKE) Click VPN to display the VPN Rules (IKE) screen. This is a read-on

Page 243 - 12.1.6 ZyWALL IDP

ZyWALL 5/35/70 Series User’s Guide317 Chapter 19 VPN ScreensFigure 149 Gateway and Network Policies This figure helps explain the main fields in th

Page 244 - CHAPTER 13

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 318Note: The Recycle Bin gateway policy is a virtual placeholder for any network policy(ies)

Page 245 - 13.2 General Setup

ZyWALL 5/35/70 Series User’s Guide319 Chapter 19 VPN ScreensFigure 151 VPN Rules (IKE): Gateway Policy: Edit

Page 246 - 13.3 IDP Signatures

ZyWALL 5/35/70 Series User’s Guide List of Figures 32List of FiguresFigure 1 Secure Internet Access via Cable, DSL or Wireless Modem ...

Page 247 - Attack Type list box

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 320The following table describes the labels in this screen. Table 101 VPN Rules (IKE): Gate

Page 248 - 13.3.3 Signature Actions

ZyWALL 5/35/70 Series User’s Guide321 Chapter 19 VPN ScreensRemote Gateway AddressType the WAN IP address or the domain name (up to 31 characters) of

Page 249 - Table 79 Signature Actions

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 322Peer ID Type Select from the following when you set Authentication Key to Pre-shared Key.•

Page 250 - Figure 115 IDP: Signatures

ZyWALL 5/35/70 Series User’s Guide323 Chapter 19 VPN ScreensServer Mode Select Server Mode to have this ZyWALL authenticate extended authentication c

Page 251 - 13.3.5 Query View

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 32419.12 VPN Rules (IKE): Network Policy Edit Click VPN and the add network policy ( ) ic

Page 252

ZyWALL 5/35/70 Series User’s Guide325 Chapter 19 VPN ScreensFigure 152 VPN Rules (IKE): Network Policy Edit

Page 253 - 13.3.5.2 Query Example 2

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 326The following table describes the labels in this screen. Table 102 VPN Rules (IKE): Netw

Page 254 - 13.4 Update

ZyWALL 5/35/70 Series User’s Guide327 Chapter 19 VPN ScreensStarting IP Address When the Address Type field is configured to Single Address, enter a

Page 255

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 32819.13 VPN Rules (IKE): Network Policy Move Click the move ( ) icon in the VPN Rules (IK

Page 256 - Table 81 Signatures Update

ZyWALL 5/35/70 Series User’s Guide329 Chapter 19 VPN ScreensFigure 153 VPN Rules (IKE): Network Policy Move The following table describes the label

Page 257 - 13.5 Backup and Restore

ZyWALL 5/35/70 Series User’s Guide33 List of FiguresFigure 39 WLAN Port Role Example ...

Page 258 - CHAPTER 14

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 330You may want to configure a VPN rule that uses manual key management if you are having pro

Page 259 - 259 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s Guide331 Chapter 19 VPN Screens19.15 VPN Rules (Manual): Edit Manual key management is useful if you have problems wi

Page 260 - Chapter 14 Anti-Virus 260

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 332Figure 155 VPN Rules (Manual): Edit The following table describes the labels in this scr

Page 261 - 261 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s Guide333 Chapter 19 VPN ScreensLocal Network Local IP addresses must be static and correspond to the remote IPSec router

Page 262 - 14.4 Signature Update

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 334My ZyWALL When the ZyWALL is in router mode, enter the WAN IP address or the domain name o

Page 263 - 14.4.1 mySecurity Zone

ZyWALL 5/35/70 Series User’s Guide335 Chapter 19 VPN Screens19.16 VPN SA Monitor In the web configurator, click VPN and the SA Monitor tab. Use thi

Page 264 - Chapter 14 Anti-Virus 264

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 33619.17 VPN Global Setting Click VPN, then the Global Setting tab to open the VPN Global Se

Page 265 - 265 Chapter 14 Anti-Virus

ZyWALL 5/35/70 Series User’s Guide337 Chapter 19 VPN Screens19.18 Telecommuter VPN/IPSec ExamplesThe following examples show how multiple telecommut

Page 266 - CHAPTER 15

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 338Figure 158 Telecommuters Sharing One VPN Rule Example19.18.2 Telecommuters Using Unique

Page 267 - 15.1.1.3 SpamContent Engine

ZyWALL 5/35/70 Series User’s Guide339 Chapter 19 VPN ScreensFigure 159 Telecommuters Using Unique VPN Rules ExampleTable 109 Telecommuters Using

Page 268 - 15.1.3 Phishing

ZyWALL 5/35/70 Series User’s Guide List of Figures 34Figure 82 Wireless Card: WPA-PSK ...

Page 269 - 15.1.6 SMTP and POP3

ZyWALL 5/35/70 Series User’s GuideChapter 19 VPN Screens 34019.19 VPN and Remote ManagementIf a VPN tunnel uses Telnet, FTP, WWW, SNMP, DNS or ICMP,

Page 270 - 15.1.7 MIME Headers

ZyWALL 5/35/70 Series User’s Guide341 Chapter 19 VPN Screens

Page 271 - Table 85 Anti-Spam: General

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 342CHAPTER 20CertificatesThis chapter gives background information about public-key certific

Page 272 - Chapter 15 Anti-Spam 272

ZyWALL 5/35/70 Series User’s Guide343 Chapter 20 CertificatesCertification authorities maintain directory servers with databases of valid and revoked

Page 273 - 273 Chapter 15 Anti-Spam

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 34420.4 My Certificates Click SECURITY, CERTIFICATES, My Certificates to open the My Certif

Page 274 - Table 87 Anti-Spam: Lists

ZyWALL 5/35/70 Series User’s Guide345 Chapter 20 CertificatesType This field displays what kind of certificate this is. REQ represents a certificatio

Page 275 - 275 Chapter 15 Anti-Spam

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 34620.5 My Certificate Import Click SECURITY, CERTIFICATES, My Certificates and then Impor

Page 276 - Chapter 15 Anti-Spam 276

ZyWALL 5/35/70 Series User’s Guide347 Chapter 20 CertificatesFigure 162 My Certificate ImportThe following table describes the labels in this scree

Page 277 - 277 Chapter 15 Anti-Spam

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 348Figure 163 My Certificate CreateThe following table describes the labels in this screen

Page 278 - CHAPTER 16

ZyWALL 5/35/70 Series User’s Guide349 Chapter 20 CertificatesCountry Type up to 127 characters to identify the nation where the certificate owner is

Page 279

ZyWALL 5/35/70 Series User’s Guide35 List of FiguresFigure 125 Anti-Spam: General ...

Page 280

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 350After you click Apply in the My Certificate Create screen, you see a screen that tells yo

Page 281

ZyWALL 5/35/70 Series User’s Guide351 Chapter 20 CertificatesFigure 164 My Certificate Details

Page 282

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 352The following table describes the labels in this screen. Table 113 My Certificate Deta

Page 283

ZyWALL 5/35/70 Series User’s Guide353 Chapter 20 Certificates20.8 Trusted CAs Click SECURITY, CERTIFICATES, Trusted CAs to open the Trusted CAs sc

Page 284

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 354Figure 165 Trusted CAsThe following table describes the labels in this screen. Table 11

Page 285

ZyWALL 5/35/70 Series User’s Guide355 Chapter 20 Certificates20.9 Trusted CA Import Click SECURITY, CERTIFICATES, Trusted CAs to open the Trusted

Page 286

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 356The following table describes the labels in this screen.20.10 Trusted CA Details Click

Page 287

ZyWALL 5/35/70 Series User’s Guide357 Chapter 20 CertificatesFigure 167 Trusted CA DetailsThe following table describes the labels in this screen.

Page 288

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 358Certification Path Click the Refresh button to have this read-only text box display the e

Page 289

ZyWALL 5/35/70 Series User’s Guide359 Chapter 20 Certificates20.11 Trusted Remote Hosts Click SECURITY, CERTIFICATES, Trusted Remote Hosts to open

Page 290

ZyWALL 5/35/70 Series User’s Guide List of Figures 36Figure 168 Trusted Remote Hosts ...

Page 291 - 16.7 Content Filtering Cache

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 360Figure 168 Trusted Remote HostsThe following table describes the labels in this screen.

Page 292

ZyWALL 5/35/70 Series User’s Guide361 Chapter 20 Certificates20.12 Verifying a Trusted Remote Host’s CertificateCertificates issued by certification

Page 293

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 362Figure 170 Certificate Details Verify (over the phone for example) that the remote host

Page 294 - CHAPTER 17

ZyWALL 5/35/70 Series User’s Guide363 Chapter 20 CertificatesFigure 171 Trusted Remote Host ImportThe following table describes the labels in this

Page 295

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 364Figure 172 Trusted Remote Host DetailsThe following table describes the labels in this

Page 296 - Figure 137 Blue Coat: Login

ZyWALL 5/35/70 Series User’s Guide365 Chapter 20 CertificatesCertificate Information These read-only fields display detailed information about the ce

Page 297

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 36620.15 Directory Servers Click SECURITY, CERTIFICATES, Directory Servers to open the Dir

Page 298

ZyWALL 5/35/70 Series User’s Guide367 Chapter 20 CertificatesThe following table describes the labels in this screen. 20.16 Directory Server Add or

Page 299 - 17.3 Web Site Submission

ZyWALL 5/35/70 Series User’s GuideChapter 20 Certificates 368The following table describes the labels in this screen. Table 121 Directory Server Add

Page 300

ZyWALL 5/35/70 Series User’s Guide369 Chapter 20 Certificates

Page 301

ZyWALL 5/35/70 Series User’s Guide37 List of FiguresFigure 211 Login Screen (Internet Explorer) ...

Page 302 - CHAPTER 18

ZyWALL 5/35/70 Series User’s GuideChapter 21 Authentication Server 370CHAPTER 21Authentication ServerThis chapter discusses how to configure the ZyWAL

Page 303 - 18.1.4 VPN Applications

ZyWALL 5/35/70 Series User’s Guide371 Chapter 21 Authentication ServerFigure 175 Local User Database

Page 304 - 18.3 Encapsulation

ZyWALL 5/35/70 Series User’s GuideChapter 21 Authentication Server 372The following table describes the labels in this screen. 21.3 RADIUS Use RA

Page 305 - 18.4 IPSec and NAT

ZyWALL 5/35/70 Series User’s Guide373 Chapter 21 Authentication ServerThe following table describes the labels in this screen. Table 123 RADIUSLAB

Page 306 - Table 93 VPN and NAT

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 374CHAPTER 22Network Address Translation (NAT) This chapter discusses h

Page 307

ZyWALL 5/35/70 Series User’s Guide375 Chapter 22 Network Address Translation (NAT)22.1.2 What NAT DoesIn the simplest form, NAT changes the source I

Page 308 - CHAPTER 19

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 376Figure 177 How NAT Works 22.1.4 NAT ApplicationThe following figu

Page 309 - 19.4 Remote Gateway Address

ZyWALL 5/35/70 Series User’s Guide377 Chapter 22 Network Address Translation (NAT)22.1.5 Port Restricted Cone NATAt the time of writing ZyWALL ZyNOS

Page 310 - 19.6 NAT Traversal

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 378• Server: This type allows you to specify inside servers of differen

Page 311 - 19.7 ID Type and Content

ZyWALL 5/35/70 Series User’s Guide379 Chapter 22 Network Address Translation (NAT)22.3 NAT Overview Click ADVANCED, NAT to open the NAT Overview s

Page 312 - Chapter 19 VPN Screens 312

ZyWALL 5/35/70 Series User’s Guide List of Figures 38Figure 254 Firmware Upload In Process ...

Page 313 - 19.8 IKE Phases

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 38022.4 NAT Address Mapping Ordering your rules is important because

Page 314 - 19.8.2 Pre-Shared Key

ZyWALL 5/35/70 Series User’s Guide381 Chapter 22 Network Address Translation (NAT)Figure 181 NAT Address MappingThe following table describes the l

Page 315 - 19.9.1 Authentication Server

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 38222.4.1 NAT Address Mapping Edit Click the Edit button to display t

Page 316 - 19.10 VPN Rules (IKE)

ZyWALL 5/35/70 Series User’s Guide383 Chapter 22 Network Address Translation (NAT)The following table describes the labels in this screen. 22.5 Por

Page 317 - 317 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 38422.5.1 Default Server IP AddressIn addition to the servers for spec

Page 318 - Chapter 19 VPN Screens 318

ZyWALL 5/35/70 Series User’s Guide385 Chapter 22 Network Address Translation (NAT)Figure 183 Multiple Servers Behind NAT Example22.5.4 NAT and Mul

Page 319 - 319 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 386Figure 184 Port Translation Example22.6 Port Forwarding Note: If

Page 320 - Chapter 19 VPN Screens 320

ZyWALL 5/35/70 Series User’s Guide387 Chapter 22 Network Address Translation (NAT)Figure 185 Port ForwardingThe following table describes the label

Page 321 - 321 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 38822.7 Port Triggering Some services use a dedicated range of ports

Page 322 - Chapter 19 VPN Screens 322

ZyWALL 5/35/70 Series User’s Guide389 Chapter 22 Network Address Translation (NAT)4 The ZyWALL forwards the traffic to Jane’s computer IP address. 5

Page 323 - 323 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s Guide39 List of FiguresFigure 297 Menu 6.3: Route Failover ...

Page 324 - Chapter 19 VPN Screens 324

ZyWALL 5/35/70 Series User’s GuideChapter 22 Network Address Translation (NAT) 390Trigger The trigger port is a port (or a range of ports) that causes

Page 325 - 325 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s Guide391 Chapter 22 Network Address Translation (NAT)

Page 326 - Chapter 19 VPN Screens 326

ZyWALL 5/35/70 Series User’s GuideChapter 23 Static Route 392CHAPTER 23Static RouteThis chapter shows you how to configure static routes for your ZyWA

Page 327 - 327 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s Guide393 Chapter 23 Static RouteNote: The default route is disabled after you change the static WAN IP address to a dyna

Page 328 - Chapter 19 VPN Screens 328

ZyWALL 5/35/70 Series User’s GuideChapter 23 Static Route 39423.2.1 IP Static Route Edit Select a static route index number and click Edit. The scr

Page 329 - 19.14 VPN Rules (Manual)

ZyWALL 5/35/70 Series User’s Guide395 Chapter 23 Static RouteGateway IP AddressEnter the IP address of the gateway. The gateway is a router or switch

Page 330 - Chapter 19 VPN Screens 330

ZyWALL 5/35/70 Series User’s GuideChapter 24 Policy Route 396CHAPTER 24Policy RouteThis chapter covers setting and applying policies used for IP routi

Page 331 - 331 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s Guide397 Chapter 24 Policy RouteIPPR follows the existing packet filtering facility of RAS in style and in implementatio

Page 332 - Chapter 19 VPN Screens 332

ZyWALL 5/35/70 Series User’s GuideChapter 24 Policy Route 398The following table describes the labels in this screen. 24.5 Policy Route Edit Click PO

Page 333 - 333 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s Guide399 Chapter 24 Policy RouteFigure 192 Edit IP Policy RouteThe following table describes the labels in this screen

Page 334 - Chapter 19 VPN Screens 334

ZyWALL 5/35/70 Series User’s Guide Federal Communications Commission (FCC) Interference Statement 4

Page 335 - 19.16 VPN SA Monitor

ZyWALL 5/35/70 Series User’s Guide List of Figures 40Figure 339 Menu 21.2: Firewall Setup ...

Page 336 - 19.17 VPN Global Setting

ZyWALL 5/35/70 Series User’s GuideChapter 24 Policy Route 400Packet Length Type a length of packet (in bytes). The operators in the Len Compare field

Page 337 - 337 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s Guide401 Chapter 24 Policy Route

Page 338 - Chapter 19 VPN Screens 338

ZyWALL 5/35/70 Series User’s GuideChapter 25 Bandwidth Management 402CHAPTER 25Bandwidth ManagementThis chapter describes the functions and configurat

Page 339 - 339 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s Guide403 Chapter 25 Bandwidth Management25.3 Proportional Bandwidth AllocationBandwidth management allows you to define

Page 340 - Chapter 19 VPN Screens 340

ZyWALL 5/35/70 Series User’s GuideChapter 25 Bandwidth Management 40425.6 Application and Subnet-based Bandwidth ManagementYou could also create band

Page 341 - 341 Chapter 19 VPN Screens

ZyWALL 5/35/70 Series User’s Guide405 Chapter 25 Bandwidth ManagementWhen you enable maximize bandwidth usage, the ZyWALL first makes sure that each

Page 342 - CHAPTER 20

ZyWALL 5/35/70 Series User’s GuideChapter 25 Bandwidth Management 40625.7.5.1 Priority-based Allotment of Unused and Unbudgeted BandwidthThe followin

Page 343 - 20.3 Configuration Summary

ZyWALL 5/35/70 Series User’s Guide407 Chapter 25 Bandwidth Management25.8 Bandwidth BorrowingBandwidth borrowing allows a sub-class to borrow unused

Page 344 - 20.4 My Certificates

ZyWALL 5/35/70 Series User’s GuideChapter 25 Bandwidth Management 408• The Bill class cannot borrow unused bandwidth from the Root class because the S

Page 345 - 345 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s Guide409 Chapter 25 Bandwidth ManagementFigure 194 Bandwidth Management: SummaryThe following table describes the labe

Page 346 - 20.5 My Certificate Import

ZyWALL 5/35/70 Series User’s Guide41 List of FiguresFigure 382 Example Xmodem Upload ...

Page 347 - 20.6 My Certificate Create

ZyWALL 5/35/70 Series User’s GuideChapter 25 Bandwidth Management 41025.11 Configuring Class Setup The Class Setup screen displays the configured ba

Page 348 - Chapter 20 Certificates 348

ZyWALL 5/35/70 Series User’s Guide411 Chapter 25 Bandwidth Management25.11.1 Bandwidth Manager Class Configuration Configure a bandwidth management

Page 349 - 349 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s GuideChapter 25 Bandwidth Management 412Figure 196 Bandwidth Management: Edit ClassThe following table describes the la

Page 350 - Chapter 20 Certificates 350

ZyWALL 5/35/70 Series User’s Guide413 Chapter 25 Bandwidth ManagementEnable Bandwidth Filter Select Enable Bandwidth Filter to have the ZyWALL use th

Page 351 - 351 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s GuideChapter 25 Bandwidth Management 41425.11.2 Bandwidth Management Statistics Use the Bandwidth Management Statis

Page 352 - Chapter 20 Certificates 352

ZyWALL 5/35/70 Series User’s Guide415 Chapter 25 Bandwidth ManagementFigure 197 Bandwidth Management: Statistics The following table describes the

Page 353 - 20.8 Trusted CAs

ZyWALL 5/35/70 Series User’s GuideChapter 25 Bandwidth Management 416Figure 198 Bandwidth Management: Monitor The following table describes the labe

Page 354 - Table 114 Trusted CAs

ZyWALL 5/35/70 Series User’s Guide417 Chapter 25 Bandwidth Management

Page 355 - 20.9 Trusted CA Import

ZyWALL 5/35/70 Series User’s GuideChapter 26 DNS 418CHAPTER 26DNSThis chapter shows you how to configure the DNS screens.26.1 DNS Overview DNS (Doma

Page 356 - 20.10 Trusted CA Details

ZyWALL 5/35/70 Series User’s Guide419 Chapter 26 DNS26.4 Address RecordAn address record contains the mapping of a fully qualified domain name (FQDN

Page 357 - 357 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s Guide List of Figures 42Figure 425 Windows XP: Advanced TCP/IP Properties ...

Page 358 - Chapter 20 Certificates 358

ZyWALL 5/35/70 Series User’s GuideChapter 26 DNS 420Figure 199 Private DNS Server ExampleNote: If you do not specify an Intranet DNS server on the r

Page 359 - 359 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s Guide421 Chapter 26 DNSFigure 200 System DNSThe following table describes the labels in this screen.Table 147 System

Page 360 - Chapter 20 Certificates 360

ZyWALL 5/35/70 Series User’s GuideChapter 26 DNS 42226.6.1 Adding an Address Record Click Add in the System screen to add an address record.Figure 2

Page 361 - 361 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s Guide423 Chapter 26 DNSThe following table describes the labels in this screen. 26.6.2 Inserting a Name Server record

Page 362 - Chapter 20 Certificates 362

ZyWALL 5/35/70 Series User’s GuideChapter 26 DNS 424The following table describes the labels in this screen.26.7 DNS Cache DNS cache is the temporar

Page 363 - 363 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s Guide425 Chapter 26 DNS26.8 Configure DNS CacheTo configure your ZyWALL’s DNS caching, click ADVANCED, DNS, then the Ca

Page 364 - Chapter 20 Certificates 364

ZyWALL 5/35/70 Series User’s GuideChapter 26 DNS 42626.9 Configuring DNS DHCP Click ADVANCED, DNS and then the DHCP tab to open the DNS DHCP screen

Page 365 - 365 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s Guide427 Chapter 26 DNSFigure 204 DNS DHCPThe following table describes the labels in this screen.Table 151 DNS DHCP

Page 366 - 20.15 Directory Servers

ZyWALL 5/35/70 Series User’s GuideChapter 26 DNS 42826.10 Dynamic DNS Dynamic DNS allows you to update your current dynamic IP address with one or m

Page 367 - Table 120 Directory Servers

ZyWALL 5/35/70 Series User’s Guide429 Chapter 26 DNSFigure 205 DDNSThe following table describes the labels in this screen.Table 152 DDNSLABEL DE

Page 368 - Chapter 20 Certificates 368

ZyWALL 5/35/70 Series User’s Guide43 List of FiguresFigure 468 Headquarters Network Policy Edit ...

Page 369 - 369 Chapter 20 Certificates

ZyWALL 5/35/70 Series User’s GuideChapter 26 DNS 430WAN Interface Select the WAN port to use for updating the IP address of the domain name.IP Address

Page 370 - CHAPTER 21

ZyWALL 5/35/70 Series User’s Guide431 Chapter 26 DNS

Page 371

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 432CHAPTER 27Remote ManagementThis chapter provides information on the Remote Managemen

Page 372 - 21.3 RADIUS

ZyWALL 5/35/70 Series User’s Guide433 Chapter 27 Remote Management1 A filter in SMT menu 3.1 (LAN) or in menu 11.5 (WAN) is applied to block a Telnet

Page 373 - Table 123 RADIUS

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 434Figure 206 HTTPS ImplementationNote: If you disable HTTP Server Access (Disable) i

Page 374 - CHAPTER 22

ZyWALL 5/35/70 Series User’s Guide435 Chapter 27 Remote ManagementFigure 207 WWWThe following table describes the labels in this screen. Table 153

Page 375 - 22.1.3 How NAT Works

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 43627.4 HTTPS ExampleIf you haven’t changed the default HTTPS port on the ZyWALL, then

Page 376 - 22.1.4 NAT Application

ZyWALL 5/35/70 Series User’s Guide437 Chapter 27 Remote Management27.4.2 Netscape Navigator Warning MessagesWhen you attempt to access the ZyWALL HT

Page 377 - 22.1.6 NAT Mapping Types

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 43827.4.3 Avoiding the Browser Warning MessagesThe following describes the main reason

Page 378 - 22.2 Using NAT

ZyWALL 5/35/70 Series User’s Guide439 Chapter 27 Remote ManagementFigure 211 Login Screen (Internet Explorer)Figure 212 Login Screen (Netscape)Cl

Page 379 - 22.3 NAT Overview

ZyWALL 5/35/70 Series User’s Guide List of Tables 44List of TablesTable 1 Model Specific Features ...

Page 380 - 22.4 NAT Address Mapping

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 440Figure 213 Replace CertificateClick Apply in the Replace Certificate screen to cre

Page 381

ZyWALL 5/35/70 Series User’s Guide441 Chapter 27 Remote ManagementFigure 215 Common ZyWALL Certificate27.5 SSH Unlike Telnet or FTP, which trans

Page 382

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 442Figure 217 How SSH Works1 Host IdentificationThe SSH client sends a connection req

Page 383 - 22.5 Port Forwarding

ZyWALL 5/35/70 Series User’s Guide443 Chapter 27 Remote Management27.7.1 Requirements for Using SSHYou must install an SSH client program on a clien

Page 384

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 44427.9 Secure Telnet Using SSH ExamplesThis section shows two examples using a comman

Page 385 - 22.5.5 Port Translation

ZyWALL 5/35/70 Series User’s Guide445 Chapter 27 Remote ManagementFigure 220 SSH Example 2: Test 2 Enter “ssh –1 192.168.1.1”. This command forces

Page 386 - 22.6 Port Forwarding

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 446Figure 222 Secure FTP: Firmware Upload Example27.11 Telnet You can configure you

Page 387 - Table 130 Port Forwarding

ZyWALL 5/35/70 Series User’s Guide447 Chapter 27 Remote ManagementFigure 224 Teln e tThe following table describes the labels in this screen. 27.13

Page 388 - 22.7 Port Triggering

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 448Figure 225 FTPThe following table describes the labels in this screen. 27.14 SNMP

Page 389 - Table 131 Port Triggering

ZyWALL 5/35/70 Series User’s Guide449 Chapter 27 Remote ManagementFigure 226 SNMP Management ModelAn SNMP managed network consists of two main type

Page 390

ZyWALL 5/35/70 Series User’s Guide45 List of TablesTable 39 WAN: Ethernet Encapsulation ...

Page 391

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 45027.14.1 Supported MIBsThe ZyWALL supports MIB II that is defined in RFC-1213 and R

Page 392 - CHAPTER 23

ZyWALL 5/35/70 Series User’s Guide451 Chapter 27 Remote ManagementFigure 227 SNMPThe following table describes the labels in this screen. Table 158

Page 393 - Table 132 IP Static Route

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 45227.15 DNS Use DNS (Domain Name System) to map a domain name to its corresponding I

Page 394 - Chapter 23 Static Route 394

ZyWALL 5/35/70 Series User’s Guide453 Chapter 27 Remote ManagementIf you allow your ZyWALL to be managed by the Vantage CNM server, then you should n

Page 395 - 395 Chapter 23 Static Route

ZyWALL 5/35/70 Series User’s GuideChapter 27 Remote Management 454Last Registration Time This field displays the last date (year-month-date) and time

Page 396 - CHAPTER 24

ZyWALL 5/35/70 Series User’s Guide455 Chapter 27 Remote Management

Page 397 - 24.4 IP Routing Policy Setup

ZyWALL 5/35/70 Series User’s GuideChapter 28 UPnP 456CHAPTER 28UPnPThis chapter introduces the Universal Plug and Play feature. This chapter is only a

Page 398 - 24.5 Policy Route Edit

ZyWALL 5/35/70 Series User’s Guide457 Chapter 28 UPnPAll UPnP-enabled devices may communicate freely with each other without additional configuration

Page 399 - 399 Chapter 24 Policy Route

ZyWALL 5/35/70 Series User’s GuideChapter 28 UPnP 45828.3 Displaying UPnP Port Mapping Click UPnP and then Ports to display the UPnP Ports screen.

Page 400 - Chapter 24 Policy Route 400

ZyWALL 5/35/70 Series User’s Guide459 Chapter 28 UPnPThe following table describes the labels in this screen. 28.4 Installing UPnP in Windows Examp

Page 401 - 401 Chapter 24 Policy Route

ZyWALL 5/35/70 Series User’s Guide List of Tables 46Table 82 Common Computer Virus Types ...

Page 402 - CHAPTER 25

ZyWALL 5/35/70 Series User’s GuideChapter 28 UPnP 46028.4.1 Installing UPnP in Windows MeFollow the steps below to install UPnP in Windows Me. 1 Clic

Page 403

ZyWALL 5/35/70 Series User’s Guide461 Chapter 28 UPnP28.4.2 Installing UPnP in Windows XPFollow the steps below to install UPnP in Windows XP.28.5

Page 404 - 25.7 Scheduler

ZyWALL 5/35/70 Series User’s GuideChapter 28 UPnP 46228.5.1 Auto-discover Your UPnP-enabled Network Device1 Click Start and Control Panel. Double-cli

Page 405 - Research: 2048 kbps

ZyWALL 5/35/70 Series User’s Guide463 Chapter 28 UPnPNote: When the UPnP-enabled device is disconnected from your computer, all port mappings will be

Page 406

ZyWALL 5/35/70 Series User’s GuideChapter 28 UPnP 464Follow the steps below to access the web configurator.1 Click Start and then Control Panel. 2 Dou

Page 407 - 25.8 Bandwidth Borrowing

ZyWALL 5/35/70 Series User’s Guide465 Chapter 28 UPnP6 Right-click the icon for your ZyXEL device and select Properties. A properties window displays

Page 408 - 25.10 Configuring Summary

ZyWALL 5/35/70 Series User’s GuideChapter 29 ALG Screen 466CHAPTER 29ALG ScreenThis chapter covers how to use the ZyWALL’s ALG feature to allow certai

Page 409

ZyWALL 5/35/70 Series User’s Guide467 Chapter 29 ALG ScreenIf the primary WAN connection fails, the client needs to re-initialize the connection thro

Page 410

ZyWALL 5/35/70 Series User’s GuideChapter 29 ALG Screen 468Figure 232 H.323 ALG Example • With multiple WAN IP addresses on the ZyWALL, you can conf

Page 411

ZyWALL 5/35/70 Series User’s Guide469 Chapter 29 ALG ScreenFigure 234 H.323 Calls from the WAN with Multiple Outgoing Calls• The H.323 ALG operates

Page 412

ZyWALL 5/35/70 Series User’s Guide47 List of TablesTable 125 NAT Mapping Types ...

Page 413

ZyWALL 5/35/70 Series User’s GuideChapter 29 ALG Screen 470The following example shows SIP signaling and audio sessions between SIP clients A and B an

Page 414

ZyWALL 5/35/70 Series User’s Guide471 Chapter 29 ALG ScreenFigure 236 ALG The following table describes the labels in this screen. Table 163 ALG

Page 415 - 25.12 Configuring Monitor

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 472CHAPTER 30Logs ScreensThis chapter contains information about configuring general log set

Page 416

ZyWALL 5/35/70 Series User’s Guide473 Chapter 30 Logs ScreensThe following table describes the labels in this screen. 30.2 Log Description Exampl

Page 417

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 47430.2.1 Certificate Not Trusted Log NotemyZyXEL.com and the update server use certificate

Page 418 - CHAPTER 26

ZyWALL 5/35/70 Series User’s Guide475 Chapter 30 Logs ScreensFigure 239 myZyXEL.com: Certificate Download30.3 Configuring Log Settings To change y

Page 419 - 26.5 Name Server Record

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 476Figure 240 Log Settings

Page 420 - 26.6 System Screen

ZyWALL 5/35/70 Series User’s Guide477 Chapter 30 Logs ScreensThe following table describes the labels in this screen.Table 166 Log Settings LABEL D

Page 421 - Table 147 System DNS

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 47830.4 Configuring Reports The Reports page displays which computers on the LAN send and r

Page 422 - Chapter 26 DNS 422

ZyWALL 5/35/70 Series User’s Guide479 Chapter 30 Logs ScreensFigure 241 ReportsNote: Enabling the ZyWALL’s reporting function decreases the overall

Page 423 - 423 Chapter 26 DNS

ZyWALL 5/35/70 Series User’s Guide List of Tables 48Table 168 Web Site Hits Report ...

Page 424 - 26.7 DNS Cache

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 48030.4.1 Viewing Web Site HitsIn the Reports screen, select Web Site Hits from the Report

Page 425 - 26.8 Configure DNS Cache

ZyWALL 5/35/70 Series User’s Guide481 Chapter 30 Logs ScreensFigure 243 Protocol/Port Report ExampleThe following table describes the labels in thi

Page 426 - 26.9 Configuring DNS DHCP

ZyWALL 5/35/70 Series User’s GuideChapter 30 Logs Screens 48230.4.3 Viewing Host IP AddressIn the Reports screen, select Host IP Address from the Rep

Page 427 - Table 151 DNS DHCP

ZyWALL 5/35/70 Series User’s Guide483 Chapter 30 Logs Screens30.4.4 Reports SpecificationsThe following table lists detailed specifications on the r

Page 428 - 26.10 Dynamic DNS

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 484CHAPTER 31MaintenanceThis chapter displays information on the maintenance screens.31.1 Ma

Page 429 - Table 152 DDNS

ZyWALL 5/35/70 Series User’s Guide485 Chapter 31 MaintenanceFigure 245 General SetupThe following table describes the labels in this screen. 31.3

Page 430 - Chapter 26 DNS 430

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 486Figure 246 Password SetupThe following table describes the labels in this screen.31.4 T

Page 431 - 431 Chapter 26 DNS

ZyWALL 5/35/70 Series User’s Guide487 Chapter 31 MaintenanceFigure 247 Time and DateThe following table describes the labels in this screen. Table

Page 432 - CHAPTER 27

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 488Get from Time ServerSelect this radio button to have the ZyWALL get the time and date from

Page 433 - 27.2 Introduction to HTTPS

ZyWALL 5/35/70 Series User’s Guide489 Chapter 31 Maintenance31.5 Pre-defined NTP Time Servers ListWhen you turn on the ZyWALL for the first time, th

Page 434 - 27.3 WWW

ZyWALL 5/35/70 Series User’s Guide49 List of TablesTable 211 Remote Node Network Layer Options Menu Fields ...

Page 435 - Table 153 WWW

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 490When the System Time and Date Synchronization in Process screen appears, wait up to one mi

Page 436 - 27.4 HTTPS Example

ZyWALL 5/35/70 Series User’s Guide491 Chapter 31 Maintenance31.6 Introduction To Transparent Bridging A transparent bridge is invisible to the opera

Page 437

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 4923 As a transparent bridge does not modify the frames it forwards, it is effectively “steal

Page 438 - 27.4.4 Login Screen

ZyWALL 5/35/70 Series User’s Guide493 Chapter 31 Maintenance31.9 Configuring Device Mode (Bridge) To configure and have your ZyWALL work as a router

Page 439

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 49431.10 F/W Upload Screen Find firmware at www.zyxel.com in a file that (usually) uses the

Page 440

ZyWALL 5/35/70 Series User’s Guide495 Chapter 31 MaintenanceFigure 253 Firmware UploadThe following table describes the labels in this screen.Note:

Page 441 - 27.6 How SSH works

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 496Figure 255 Network Temporarily DisconnectedAfter two minutes, log in again and check you

Page 442 - Figure 217 How SSH Works

ZyWALL 5/35/70 Series User’s Guide497 Chapter 31 MaintenanceFigure 257 Backup and Restore31.11.1 Backup Configuration Backup Configuration allows

Page 443 - 27.8 Configuring SSH

ZyWALL 5/35/70 Series User’s GuideChapter 31 Maintenance 498Note: Do not turn off the ZyWALL while configuration file upload is in progress.After you

Page 444 - 27.9.2 Example 2: Linux

ZyWALL 5/35/70 Series User’s Guide499 Chapter 31 Maintenance31.11.3 Back to Factory Defaults Pressing the Reset button in this section clears all u

Page 445

ZyWALL 5/35/70 Series User’s Guide5 Safety WarningsSafety WarningsFor your safety, be sure to read and follow all warning notices and instructions.•

Page 446 - 27.12 Configuring TELNET

ZyWALL 5/35/70 Series User’s Guide List of Tables 50Table 254 Classes of IP Addresses ...

Page 447 - 27.13 FTP

ZyWALL 5/35/70 Series User’s GuideChapter 32 Introducing the SMT 500CHAPTER 32Introducing the SMTThis chapter explains how to access the System Manage

Page 448 - 27.14 SNMP

ZyWALL 5/35/70 Series User’s Guide501 Chapter 32 Introducing the SMTFigure 263 Initial Screen32.2.2 Entering the PasswordThe login screen appears

Page 449

ZyWALL 5/35/70 Series User’s GuideChapter 32 Introducing the SMT 50232.3.1 Main MenuAfter you enter the password, the SMT displays the ZyWALL Main Me

Page 450 - 27.14.2 SNMP Traps

ZyWALL 5/35/70 Series User’s Guide503 Chapter 32 Introducing the SMTFigure 265 Main Menu (Router Mode)Figure 266 Main Menu (Bridge Mode)The follo

Page 451 - Table 158 SNMP

ZyWALL 5/35/70 Series User’s GuideChapter 32 Introducing the SMT 50432.3.2 SMT Menus OverviewThe following table gives you an overview of your ZyWALL

Page 452 - 27.15 DNS

ZyWALL 5/35/70 Series User’s Guide505 Chapter 32 Introducing the SMT6 Route Setup (for the ZyWALL 35 and the ZyWALL 70)6.1 Route Assessment6.2 Traffi

Page 453 - 27.17 Configuring CNM

ZyWALL 5/35/70 Series User’s GuideChapter 32 Introducing the SMT 50632.4 Changing the System PasswordChange the system password by following the step

Page 454 - Table 160 CNM (continued)

ZyWALL 5/35/70 Series User’s Guide507 Chapter 32 Introducing the SMTFigure 267 Menu 23: System Password2 Type your existing password and press [ENT

Page 455

ZyWALL 5/35/70 Series User’s GuideChapter 33 SMT Menu 1 - General Setup 508CHAPTER 33SMT Menu 1 - General SetupMenu 1 - General Setup contains adminis

Page 456 - CHAPTER 28

ZyWALL 5/35/70 Series User’s Guide509 Chapter 33 SMT Menu 1 - General SetupFigure 269 Menu 1: General Setup (Bridge Mode)The following table descri

Page 457 - 28.2 Configuring UPnP

ZyWALL 5/35/70 Series User’s Guide51 List of TablesTable 297 AS Logs ...

Page 458 - Table 161 UPnP

ZyWALL 5/35/70 Series User’s GuideChapter 33 SMT Menu 1 - General Setup 51033.2.1 Configuring Dynamic DNSTo configure Dynamic DNS, set the ZyWALL to

Page 459 - Table 162 UPnP Ports

ZyWALL 5/35/70 Series User’s Guide511 Chapter 33 SMT Menu 1 - General SetupFigure 271 Menu 1.1.1: DDNS Host SummaryThe following table describes th

Page 460 - Chapter 28 UPnP 460

ZyWALL 5/35/70 Series User’s GuideChapter 33 SMT Menu 1 - General Setup 512Figure 272 Menu 1.1.1: DDNS Edit HostThe following table describes the fi

Page 461 - 461 Chapter 28 UPnP

ZyWALL 5/35/70 Series User’s Guide513 Chapter 33 SMT Menu 1 - General SetupThe IP address updates when you reconfigure menu 1 or perform DHCP client

Page 462 - Chapter 28 UPnP 462

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 514CHAPTER 34WAN and Dial Backup SetupThis chapter describes how to configure t

Page 463 - 463 Chapter 28 UPnP

ZyWALL 5/35/70 Series User’s Guide515 Chapter 34 WAN and Dial Backup SetupThe following table describes the fields in this screen.34.3 Dial BackupTh

Page 464 - Chapter 28 UPnP 464

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 516Figure 274 Menu 2: Dial Backup Setup The following table describes the fi

Page 465 - 465 Chapter 28 UPnP

ZyWALL 5/35/70 Series User’s Guide517 Chapter 34 WAN and Dial Backup SetupTo edit the advanced setup for the Dial Backup port, move the cursor to the

Page 466 - CHAPTER 29

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 51834.6 Remote Node Profile (Backup ISP)On a ZyWALL with multiple WAN ports, e

Page 467 - 29.4 RTP

ZyWALL 5/35/70 Series User’s Guide519 Chapter 34 WAN and Dial Backup SetupFigure 276 Menu 11.3: Remote Node Profile (Backup ISP)The following tabl

Page 468 - Chapter 29 ALG Screen 468

ZyWALL 5/35/70 Series User’s Guide Preface 52PrefaceCongratulations on your purchase of the ZyWALL. Note: Register your product online to receive e-ma

Page 469 - 29.5 SIP

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 52034.7 Editing PPP OptionsThe ZyWALL’s dial back-up feature uses PPP. To edit

Page 470 - 29.6 ALG Screen

ZyWALL 5/35/70 Series User’s Guide521 Chapter 34 WAN and Dial Backup SetupFigure 277 Menu 11.3.1: Remote Node PPP OptionsThis table describes the R

Page 471 - Table 163 ALG

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 522Figure 278 Menu 11.3.2: Remote Node Network Layer OptionsThe following tab

Page 472 - CHAPTER 30

ZyWALL 5/35/70 Series User’s Guide523 Chapter 34 WAN and Dial Backup Setup34.9 Editing Login ScriptFor some remote gateways, text login is required

Page 473 - 30.2 Log Description Example

ZyWALL 5/35/70 Series User’s GuideChapter 34 WAN and Dial Backup Setup 524You can use two variables, $USERNAME and $PASSWORD (all UPPER case), to repr

Page 474 - Chapter 30 Logs Screens 474

ZyWALL 5/35/70 Series User’s Guide525 Chapter 34 WAN and Dial Backup SetupThe following table describes the fields in this menu.34.10 Remote Node Fi

Page 475 - 475 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s GuideChapter 35 LAN Setup 526CHAPTER 35LAN SetupThis chapter describes how to configure the LAN using Menu 3 - LAN Setup.

Page 476 - Figure 240 Log Settings

ZyWALL 5/35/70 Series User’s Guide527 Chapter 35 LAN SetupFigure 282 Menu 3.1: LAN Port Filter Setup 35.4 TCP/IP and DHCP Ethernet Setup MenuFrom

Page 477 - Table 166 Log Settings

ZyWALL 5/35/70 Series User’s GuideChapter 35 LAN Setup 528Figure 284 Menu 3.2: TCP/IP and DHCP Ethernet SetupFollow the instructions in the next tab

Page 478 - 30.4 Configuring Reports

ZyWALL 5/35/70 Series User’s Guide529 Chapter 35 LAN SetupUse the instructions in the following table to configure TCP/IP parameters for the LAN port

Page 479 - Table 167 Reports

ZyWALL 5/35/70 Series User’s Guide53 PrefaceSyntax Conventions• “Enter” means for you to type one or more characters. “Select” or “Choose” means for

Page 480 - 30.4.2 Viewing Protocol/Port

ZyWALL 5/35/70 Series User’s GuideChapter 35 LAN Setup 53035.4.1 IP Alias SetupIP alias allows you to partition a physical network into different log

Page 481 - 481 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s Guide531 Chapter 35 LAN SetupOutgoing Protocol FiltersEnter the filter set(s) you wish to apply to the outgoing traffic

Page 482 - Chapter 30 Logs Screens 482

ZyWALL 5/35/70 Series User’s GuideChapter 36 Internet Access 532CHAPTER 36Internet AccessThis chapter shows you how to configure your ZyWALL for Inter

Page 483 - 483 Chapter 30 Logs Screens

ZyWALL 5/35/70 Series User’s Guide533 Chapter 36 Internet AccessThe following table describes the fields in this menu.Table 200 Menu 4: Internet Ac

Page 484 - CHAPTER 31

ZyWALL 5/35/70 Series User’s GuideChapter 36 Internet Access 53436.3 Configuring the PPTP ClientNote: The ZyWALL supports only one PPTP server connec

Page 485 - 31.3 Configuring Password

ZyWALL 5/35/70 Series User’s Guide535 Chapter 36 Internet AccessFigure 288 Internet Access Setup (PPPoE)The following table contains instructions a

Page 486 - 31.4 Time and Date

ZyWALL 5/35/70 Series User’s GuideChapter 37 DMZ Setup 536CHAPTER 37DMZ SetupThis chapter describes how to configure the ZyWALL’s DMZ using Menu 5 - D

Page 487 - Table 174 Time and Date

ZyWALL 5/35/70 Series User’s Guide537 Chapter 37 DMZ Setup37.3.1 IP AddressFrom the main menu, enter 5 to open Menu 5 - DMZ Setup to configure TCP/I

Page 488 - Chapter 31 Maintenance 488

ZyWALL 5/35/70 Series User’s GuideChapter 37 DMZ Setup 53837.3.2 IP Alias SetupYou must use menu 5.2 to configure the first network. Move the cursor

Page 489 - 31.5.1 Resetting the Time

ZyWALL 5/35/70 Series User’s Guide539 Chapter 37 DMZ Setup

Page 490 - Chapter 31 Maintenance 490

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 54CHAPTER 1 Getting to Know Your ZyWALLThis chapter introduces the main featur

Page 491 - 31.7 Transparent Firewalls

ZyWALL 5/35/70 Series User’s GuideChapter 38 Route Setup 540CHAPTER 38Route SetupThis chapter describes how to configure the ZyWALL's traffic red

Page 492 - Chapter 31 Maintenance 492

ZyWALL 5/35/70 Series User’s Guide541 Chapter 38 Route SetupThe following table describes the fields in this menu.38.3 Traffic RedirectTo configure

Page 493 - 493 Chapter 31 Maintenance

ZyWALL 5/35/70 Series User’s GuideChapter 38 Route Setup 54238.4 Route FailoverThis menu allows you to configure how the ZyWALL uses the route assess

Page 494 - 31.10 F/W Upload Screen

ZyWALL 5/35/70 Series User’s Guide543 Chapter 38 Route Setup

Page 495 - Table 179 Firmware Upload

ZyWALL 5/35/70 Series User’s GuideChapter 39 Wireless Setup 544CHAPTER 39Wireless SetupUse menu 7 to set up your ZyWALL as the wireless access point.3

Page 496 - 31.11 Backup and Restore

ZyWALL 5/35/70 Series User’s Guide545 Chapter 39 Wireless SetupFollow the instructions in the next table on how to configure the wireless LAN paramet

Page 497 - 497 Chapter 31 Maintenance

ZyWALL 5/35/70 Series User’s GuideChapter 39 Wireless Setup 54639.1.1 MAC Address Filter SetupYour ZyWALL checks the MAC address of the wireless stat

Page 498 - Chapter 31 Maintenance 498

ZyWALL 5/35/70 Series User’s Guide547 Chapter 39 Wireless Setup39.2 TCP/IP SetupFor more detailed information about RIP setup, IP Multicast and IP a

Page 499 - 31.12 Restart Screen

ZyWALL 5/35/70 Series User’s GuideChapter 39 Wireless Setup 548Figure 301 Menu 7.2: TCP/IP and DHCP Ethernet SetupThe DHCP and TCP/IP setup fields a

Page 500 - CHAPTER 32

ZyWALL 5/35/70 Series User’s Guide549 Chapter 39 Wireless SetupFigure 302 Menu 7.2.1: IP Alias SetupRefer to Table 199 on page 530 for instructions

Page 501 - 32.2.2 Entering the Password

ZyWALL 5/35/70 Series User’s Guide55 Chapter 1 Getting to Know Your ZyWALLTable Key: An O in a mode’s column shows that the device mode has the speci

Page 502 - 32.3.1 Main Menu

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 550CHAPTER 40Remote Node SetupThis chapter shows you how to configure a remote node.40.

Page 503 - Table 182 Main Menu Summary

ZyWALL 5/35/70 Series User’s Guide551 Chapter 40 Remote Node SetupFigure 303 Menu 11: Remote Node Setup40.3 Remote Node Profile SetupThe following

Page 504 - 32.3.2 SMT Menus Overview

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 552The following table describes the fields in this menu.Table 208 Menu 11.1: Remote

Page 505

ZyWALL 5/35/70 Series User’s Guide553 Chapter 40 Remote Node Setup40.3.2 PPPoE EncapsulationThe ZyWALL supports PPPoE (Point-to-Point Protocol over

Page 506

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 55440.3.2.3 MetricSee Section 7.5 on page 134 for details on the Metric field.40.3.3

Page 507 - 32.5 Resetting the ZyWALL

ZyWALL 5/35/70 Series User’s Guide555 Chapter 40 Remote Node SetupFigure 306 Menu 11.1: Remote Node Profile for PPTP EncapsulationThe next table sh

Page 508 - CHAPTER 33

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 556Figure 307 Menu 11.1.2: Remote Node Network Layer Options for Ethernet Encapsulati

Page 509

ZyWALL 5/35/70 Series User’s Guide557 Chapter 40 Remote Node Setup40.5 Remote Node FilterMove the cursor to the field Edit Filter Sets in menu 11.1,

Page 510 - 33.2.1.1 Editing DDNS Host

ZyWALL 5/35/70 Series User’s GuideChapter 40 Remote Node Setup 558Figure 308 Menu 11.1.4: Remote Node Filter (Ethernet Encapsulation)Figure 309 Me

Page 511

ZyWALL 5/35/70 Series User’s Guide559 Chapter 40 Remote Node SetupFigure 310 Menu 11.1.5: Traffic Redirect SetupThe following table describes the f

Page 512

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 56Time and DateThe ZyWALL allows you to get the current time and date from an

Page 513

ZyWALL 5/35/70 Series User’s GuideChapter 41 IP Static Route Setup 560CHAPTER 41IP Static Route SetupThis chapter shows you how to configure static ro

Page 514 - Edit Advanced Setup= No

ZyWALL 5/35/70 Series User’s Guide561 Chapter 41 IP Static Route SetupFigure 312 Menu 12. 1: Edit IP Static Route`The following table describes the

Page 515 - 34.3 Dial Backup

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 562CHAPTER 42Network Address Translation (NAT)This chapter discusses ho

Page 516 - Edit Advanced Setup= Yes

ZyWALL 5/35/70 Series User’s Guide563 Chapter 42 Network Address Translation (NAT)Figure 313 Menu 4: Applying NAT for Internet AccessThe following

Page 517 - [ENTER]

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 564The following table describes the fields in this menu.42.2 NAT Setu

Page 518

ZyWALL 5/35/70 Series User’s Guide565 Chapter 42 Network Address Translation (NAT)42.2.1 Address Mapping Sets Enter 1 to bring up Menu 15.1 - Addres

Page 519

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 566Note: Menu 15.1.255 is read-only. 42.2.1.2 User-Defined Address Map

Page 520 - 34.7 Editing PPP Options

ZyWALL 5/35/70 Series User’s Guide567 Chapter 42 Network Address Translation (NAT)Figure 318 Menu 15.1.1: First SetNote: The Type, Local and Global

Page 521 - 34.8 Editing TCP/IP Options

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 568Note: You must press [ENTER] at the bottom of the screen to save the

Page 522

ZyWALL 5/35/70 Series User’s Guide569 Chapter 42 Network Address Translation (NAT)42.3 Configuring a Server behind NATNote: If you do not assign a D

Page 523 - 34.9 Editing Login Script

ZyWALL 5/35/70 Series User’s Guide57 Chapter 1 Getting to Know Your ZyWALLBandwidth ManagementBandwidth management allows you to allocate network res

Page 524

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 570Figure 321 Menu 15.2.1: NAT Server Sets4 Select Edit Rule in the S

Page 525 - 34.10 Remote Node Filter

ZyWALL 5/35/70 Series User’s Guide571 Chapter 42 Network Address Translation (NAT)Figure 322 15.2.1.2: NAT Server ConfigurationThe following table

Page 526 - CHAPTER 35

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 572Figure 323 Menu 15.2.1: NAT Server Setup You assign the private ne

Page 527 - 527 Chapter 35 LAN Setup

ZyWALL 5/35/70 Series User’s Guide573 Chapter 42 Network Address Translation (NAT)Figure 325 NAT Example 1Figure 326 Menu 4: Internet Access &

Page 528 - Chapter 35 LAN Setup 528

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 57442.4.2 Example 2: Internet Access with an Default Server Figure 327

Page 529 - 529 Chapter 35 LAN Setup

ZyWALL 5/35/70 Series User’s Guide575 Chapter 42 Network Address Translation (NAT)1 Map the first IGA to the first inside FTP server for FTP traffic

Page 530 - 35.4.1 IP Alias Setup

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 576Figure 330 Example 3: Menu 11.1.2The following figure shows how to

Page 531 - 531 Chapter 35 LAN Setup

ZyWALL 5/35/70 Series User’s Guide577 Chapter 42 Network Address Translation (NAT)Figure 332 Example 3: Final Menu 15.1.1Now configure the IGA3 to

Page 532 - CHAPTER 36

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 57842.4.4 Example 4: NAT Unfriendly Application ProgramsSome applicati

Page 533

ZyWALL 5/35/70 Series User’s Guide579 Chapter 42 Network Address Translation (NAT)Figure 336 Example 4: Menu 15.1.1: Address Mapping Rules42.5 Tri

Page 534

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 58Content FilteringThe ZyWALL can block web features such as ActiveX controls,

Page 535 - 36.5 Basic Setup Complete

ZyWALL 5/35/70 Series User’s GuideChapter 42 Network Address Translation (NAT) 580Note: Only one LAN computer can use a trigger port (range) at a time

Page 536 - CHAPTER 37

ZyWALL 5/35/70 Series User’s Guide581 Chapter 42 Network Address Translation (NAT)

Page 537 - 37.3.1 IP Address

ZyWALL 5/35/70 Series User’s GuideChapter 43 Introducing the ZyWALL Firewall 582CHAPTER 43Introducing the ZyWALL FirewallThis chapter shows you how to

Page 538 - 37.3.2 IP Alias Setup

ZyWALL 5/35/70 Series User’s Guide583 Chapter 43 Introducing the ZyWALL FirewallFigure 339 Menu 21.2: Firewall SetupNote: Configure the firewall rul

Page 539 - 539 Chapter 37 DMZ Setup

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 584CHAPTER 44Filter ConfigurationThis chapter shows you how to create and apply filt

Page 540 - CHAPTER 38

ZyWALL 5/35/70 Series User’s Guide585 Chapter 44 Filter Configuration44.1.1 The Filter Structure of the ZyWALLA filter set consists of one or more f

Page 541 - 38.3 Traffic Redirect

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 586Figure 341 Filter Rule Process You can apply up to four filter sets to a partic

Page 542 - 38.4 Route Failover

ZyWALL 5/35/70 Series User’s Guide587 Chapter 44 Filter Configuration44.2 Configuring a Filter SetThe ZyWALL includes filtering for NetBIOS over TCP

Page 543 - 543 Chapter 38 Route Setup

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 588The protocol dependent filter rules abbreviation are listed as follows:Refer to t

Page 544 - CHAPTER 39

ZyWALL 5/35/70 Series User’s Guide589 Chapter 44 Filter ConfigurationTo speed up filtering, all rules in a filter set must be of the same class, i.e.

Page 545

ZyWALL 5/35/70 Series User’s Guide59 Chapter 1 Getting to Know Your ZyWALLIEEE 802.1x for Network SecurityThe ZyWALL supports the IEEE 802.1x standar

Page 546 - Chapter 39 Wireless Setup 546

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 590The following figure illustrates the logic flow of an IP filter.DestinationIP Add

Page 547 - 39.2 TCP/IP Setup

ZyWALL 5/35/70 Series User’s Guide591 Chapter 44 Filter ConfigurationFigure 345 Executing an IP Filter44.2.3 Configuring a Generic Filter Rule Thi

Page 548 - 39.2.2 IP Alias Setup

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 592to allow you to filter non-IP packets. For IP, it is generally easier to use the

Page 549

ZyWALL 5/35/70 Series User’s Guide593 Chapter 44 Filter Configuration44.3 Example FilterLet’s look at an example to block outside users from accessi

Page 550 - CHAPTER 40

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 594Figure 348 Example Filter: Menu 21.1.3.1The port number for the telnet service

Page 551

ZyWALL 5/35/70 Series User’s Guide595 Chapter 44 Filter ConfigurationM = N means an action can be taken immediately. The action is to drop the packet

Page 552

ZyWALL 5/35/70 Series User’s GuideChapter 44 Filter Configuration 59644.6 Applying a Filter This section shows you where to apply the filter(s) after

Page 553 - 40.3.2 PPPoE Encapsulation

ZyWALL 5/35/70 Series User’s Guide597 Chapter 44 Filter ConfigurationFigure 352 Filtering DMZ Traffic44.6.3 Applying Remote Node FiltersGo to menu

Page 554 - 40.3.3 PPTP Encapsulation

ZyWALL 5/35/70 Series User’s GuideChapter 45 SNMP Configuration 598CHAPTER 45SNMP ConfigurationThis chapter explains SNMP configuration menu 22.45.1

Page 555 - 40.4 Edit IP

ZyWALL 5/35/70 Series User’s Guide599 Chapter 45 SNMP Configuration45.2 SNMP Traps The ZyWALL will send traps to the SNMP manager when any one of th

Page 556

ZyWALL 5/35/70 Series User’s Guide ZyXEL Limited Warranty 6ZyXEL Limited WarrantyZyXEL warrants to the original end user (purchaser) that this product

Page 557 - 40.5 Remote Node Filter

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 60Dynamic DNS SupportWith Dynamic DNS (Domain Name System) support, you can ha

Page 558 - 40.6 Traffic Redirect

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 600CHAPTER 46System Information & DiagnosisThis chapter covers SMT

Page 559

ZyWALL 5/35/70 Series User’s Guide601 Chapter 46 System Information & Diagnosis3 There are three commands in Menu 24.1 - System Maintenance - Sta

Page 560 - CHAPTER 41

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 60246.3 System Information and Console Port SpeedThis section describ

Page 561

ZyWALL 5/35/70 Series User’s Guide603 Chapter 46 System Information & DiagnosisFigure 358 Menu 24.2.1: System Maintenance: Information The fol

Page 562 - CHAPTER 42

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 604Figure 359 Menu 24.2.2: System Maintenance: Change Console Port S

Page 563

ZyWALL 5/35/70 Series User’s Guide605 Chapter 46 System Information & DiagnosisFigure 361 Examples of Error and Information Messages46.4.2 Sys

Page 564 - 42.2 NAT Setup

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 606Your ZyWALL sends five types of syslog messages. Some examples (not

Page 565 - 42.2.1 Address Mapping Sets

ZyWALL 5/35/70 Series User’s Guide607 Chapter 46 System Information & Diagnosis4 PPP log 5 Firewall logFilter log Message FormatSdcmdSyslogSend(S

Page 566

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 60846.4.3 Call-Triggering PacketCall-Triggering Packet displays infor

Page 567 - 42.2.1.3 Ordering Your Rules

ZyWALL 5/35/70 Series User’s Guide609 Chapter 46 System Information & Diagnosis1 From the main menu, select option 24 to open Menu 24 - System Ma

Page 568

ZyWALL 5/35/70 Series User’s Guide61 Chapter 1 Getting to Know Your ZyWALLTraffic RedirectTraffic Redirect forwards WAN traffic to a backup gateway o

Page 569

ZyWALL 5/35/70 Series User’s GuideChapter 46 System Information & Diagnosis 610Table 229 System Maintenance Menu DiagnosticFIELD DESCRIPTIONPing

Page 570

ZyWALL 5/35/70 Series User’s Guide611 Chapter 46 System Information & Diagnosis

Page 571

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 612CHAPTER 47Firmware and Configuration File MaintenanceThis

Page 572 - 42.4 General NAT Examples

ZyWALL 5/35/70 Series User’s Guide613 Chapter 47 Firmware and Configuration File MaintenanceThe following table is a summary. Please note that the in

Page 573 - Section 42.4 on page 572

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 614Figure 366 Telnet into Menu 24.547.3.2 Using the FTP Co

Page 574 - Figure 327 NAT Example 2

ZyWALL 5/35/70 Series User’s Guide615 Chapter 47 Firmware and Configuration File Maintenance47.3.3 Example of FTP Commands from the Command Line Fig

Page 575 - Figure 329 NAT Example 3

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 6164 The IP you entered in the Secured Client IP field in men

Page 576

ZyWALL 5/35/70 Series User’s Guide617 Chapter 47 Firmware and Configuration File Maintenance47.3.8 GUI-based TFTP ClientsThe following table describ

Page 577

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 618Figure 370 Backup Configuration ExampleType a location f

Page 578 - Figure 334 NAT Example 4

ZyWALL 5/35/70 Series User’s Guide619 Chapter 47 Firmware and Configuration File MaintenanceFigure 372 Telnet into Menu 24.61 Launch the FTP client

Page 579 - 42.5 Trigger Port Forwarding

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 621.3 Applications for the ZyWALL Here are some examples of what you can do w

Page 580

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 62047.4.2 Restore Using FTP Session ExampleFigure 373 Rest

Page 581

ZyWALL 5/35/70 Series User’s Guide621 Chapter 47 Firmware and Configuration File Maintenance4 After a successful restoration you will see the followi

Page 582 - CHAPTER 43

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 622Figure 378 Telnet Into Menu 24.7.1: Upload System Firmwa

Page 583

ZyWALL 5/35/70 Series User’s Guide623 Chapter 47 Firmware and Configuration File Maintenance47.5.3 FTP File Upload Command from the DOS Prompt Examp

Page 584 - CHAPTER 44

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 6241 Use telnet from your computer to connect to the ZyWALL a

Page 585

ZyWALL 5/35/70 Series User’s Guide625 Chapter 47 Firmware and Configuration File MaintenanceFigure 381 Menu 24.7.1 As Seen Using the Console Port2

Page 586

ZyWALL 5/35/70 Series User’s GuideChapter 47 Firmware and Configuration File Maintenance 626Figure 383 Menu 24.7.2 As Seen Using the Console Port 2

Page 587

ZyWALL 5/35/70 Series User’s Guide627 Chapter 47 Firmware and Configuration File Maintenance

Page 588 - Len Length

ZyWALL 5/35/70 Series User’s GuideChapter 48 System Maintenance Menus 8 to 10 628CHAPTER 48System Maintenance Menus 8 to 10This chapter leads you thro

Page 589

ZyWALL 5/35/70 Series User’s Guide629 Chapter 48 System Maintenance Menus 8 to 10The required fields in a command are enclosed in angle brackets <

Page 590

ZyWALL 5/35/70 Series User’s Guide63 Chapter 1 Getting to Know Your ZyWALLFigure 2 VPN Application1.3.3 Front Panel LEDsFigure 3 ZyWALL 70 Front

Page 591

ZyWALL 5/35/70 Series User’s GuideChapter 48 System Maintenance Menus 8 to 10 63048.2 Call Control SupportThe ZyWALL provides two call control functi

Page 592 - Length= 0

ZyWALL 5/35/70 Series User’s Guide631 Chapter 48 System Maintenance Menus 8 to 10Figure 388 Budget ManagementThe total budget is the time limit on

Page 593 - 44.3 Example Filter

ZyWALL 5/35/70 Series User’s GuideChapter 48 System Maintenance Menus 8 to 10 632Figure 389 Call HistoryThe following table describes the fields in

Page 594

ZyWALL 5/35/70 Series User’s Guide633 Chapter 48 System Maintenance Menus 8 to 10Figure 390 Menu 24: System MaintenanceEnter 10 to go to Menu 24.10

Page 595 - 44.5 Firewall Versus Filters

ZyWALL 5/35/70 Series User’s GuideChapter 48 System Maintenance Menus 8 to 10 634Table 236 Menu 24.10 System Maintenance: Time and Date SettingFIELD

Page 596 - 44.6 Applying a Filter

ZyWALL 5/35/70 Series User’s Guide635 Chapter 48 System Maintenance Menus 8 to 10End Date (mm-nth-week-hr)Configure the day and time when Daylight Sa

Page 597 - HTTP connections

ZyWALL 5/35/70 Series User’s GuideChapter 49 Remote Management 636CHAPTER 49Remote ManagementThis chapter covers remote management found in SMT menu 2

Page 598 - CHAPTER 45

ZyWALL 5/35/70 Series User’s Guide637 Chapter 49 Remote ManagementFigure 392 Menu 24.11 – Remote Management ControlThe following table describes th

Page 599 - 45.2 SNMP Traps

ZyWALL 5/35/70 Series User’s GuideChapter 49 Remote Management 63849.1.1 Remote Management LimitationsRemote management over LAN or WAN will not work

Page 600 - CHAPTER 46

ZyWALL 5/35/70 Series User’s Guide639 Chapter 49 Remote Management

Page 601

ZyWALL 5/35/70 Series User’s GuideChapter 1 Getting to Know Your ZyWALL 64The following table describes the LEDs.Table 2 Front Panel LEDs LED COLOR

Page 602 - 46.3.1 System Information

ZyWALL 5/35/70 Series User’s GuideChapter 50 IP Policy Routing 640CHAPTER 50IP Policy Routing This chapter covers setting and applying policies used f

Page 603 - 46.3.2 Console Port Speed

ZyWALL 5/35/70 Series User’s Guide641 Chapter 50 IP Policy Routing50.2 IP Routing Policy SetupTo setup a routing policy, perform the following proce

Page 604 - 46.4 Log and Trace

ZyWALL 5/35/70 Series User’s GuideChapter 50 IP Policy Routing 6421 Type 25 in the main menu to open Menu 25 - IP Routing Policy Summary.2 Select Edit

Page 605 - 46.4.2 Syslog Logging

ZyWALL 5/35/70 Series User’s Guide643 Chapter 50 IP Policy Routing50.2.1 Applying Policy to PacketsTo apply the policy to packets received on the se

Page 606 - 3 Filter log

ZyWALL 5/35/70 Series User’s GuideChapter 50 IP Policy Routing 644Figure 395 Menu 25.1.1: IP Routing Policy SetupThe following table describes the f

Page 607 - 5 Firewall log

ZyWALL 5/35/70 Series User’s Guide645 Chapter 50 IP Policy RoutingFigure 396 Example of IP Policy Routing To force Web packets coming from clients

Page 608 - 46.5 Diagnostic

ZyWALL 5/35/70 Series User’s GuideChapter 50 IP Policy Routing 6464 Create another rule in menu 25.1 for this rule to route packets from any host (IP=

Page 609 - 46.5.1 WAN DHCP

ZyWALL 5/35/70 Series User’s Guide647 Chapter 50 IP Policy Routing

Page 610

ZyWALL 5/35/70 Series User’s GuideChapter 51 Call Scheduling 648CHAPTER 51Call SchedulingCall scheduling allows you to dictate when a remote node shou

Page 611

ZyWALL 5/35/70 Series User’s Guide649 Chapter 51 Call SchedulingFigure 400 Schedule Set SetupIf a connection has been already established, your ZyW

Page 612 - CHAPTER 47

ZyWALL 5/35/70 Series User’s Guide65 Chapter 1 Getting to Know Your ZyWALL

Page 613 - 47.3 Backup Configuration

ZyWALL 5/35/70 Series User’s GuideChapter 51 Call Scheduling 650Once your schedule sets are configured, you must then apply them to the desired remote

Page 614

ZyWALL 5/35/70 Series User’s Guide651 Chapter 51 Call SchedulingFigure 402 Applying Schedule Set(s) to a Remote Node (PPTP) Menu 11.1 -

Page 615 - 47.3.4 GUI-based FTP Clients

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 652CHAPTER 52TroubleshootingThis chapter covers potential problems and possible remedies.

Page 616 - 47.3.7 TFTP Command Example

ZyWALL 5/35/70 Series User’s Guide653 Chapter 52 Troubleshooting52.3 Problems with the DMZ Interface52.4 Problems with the WAN InterfaceTable 245

Page 617

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 65452.5 Problems Accessing the ZyWALL52.5.1 Pop-up Windows, JavaScripts and Java Permis

Page 618 - 47.4 Restore Configuration

ZyWALL 5/35/70 Series User’s Guide655 Chapter 52 Troubleshooting• Web browser pop-up windows from your device.• JavaScripts (enabled by default).• Ja

Page 619

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 656Figure 404 Internet Options: Privacy3 Click Apply to save this setting.52.5.1.1.2 E

Page 620

ZyWALL 5/35/70 Series User’s Guide657 Chapter 52 TroubleshootingFigure 405 Internet Options: Privacy3 Type the IP address of your device (the web p

Page 621 - 47.5.1 Firmware File Upload

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 658Figure 406 Pop-up Blocker Settings5 Click Close to return to the Privacy screen. 6 C

Page 622

ZyWALL 5/35/70 Series User’s Guide659 Chapter 52 TroubleshootingFigure 407 Internet Options: Security 2 Click the Custom Level... button. 3 Scroll

Page 623 - 47.5.5 TFTP File Upload

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 66CHAPTER 2Introducing the Web ConfiguratorThis chapter describes how to

Page 624

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 660Figure 408 Security Settings - Java Scripting52.5.1.3 Java Permissions1 From Intern

Page 625

ZyWALL 5/35/70 Series User’s Guide661 Chapter 52 TroubleshootingFigure 409 Security Settings - Java 52.5.1.3.1 JAVA (Sun)1 From Internet Explorer,

Page 626

ZyWALL 5/35/70 Series User’s GuideChapter 52 Troubleshooting 662Figure 410 Java (Sun)52.6 Packet FlowThe following is the packet check flow on the

Page 627

ZyWALL 5/35/70 Series User’s Guide663 Chapter 52 Troubleshooting

Page 628 - CHAPTER 48

ZyWALL 5/35/70 Series User’s GuideAppendix A Product Specifications 664APPENDIX AProduct SpecificationsSee also the Introduction chapter for a general

Page 629 - 48.1.2 Command Usage

ZyWALL 5/35/70 Series User’s Guide665 Appendix A Product SpecificationsOperation Humidity 20% ~ 95% RH (non-condensing)Storage Humidity 20% ~ 95% RH

Page 630 - 48.2 Call Control Support

ZyWALL 5/35/70 Series User’s GuideAppendix A Product Specifications 666Anti-Spam Spam, Phishing detectionConfigurable white and black listsSMTP, POP3

Page 631 - 48.2.2 Call History

ZyWALL 5/35/70 Series User’s Guide667 Appendix A Product Specifications Other Protocol Support PPP (Point-to-Point Protocol) link layer protocol.Tran

Page 632 - 48.3 Time and Date Setting

ZyWALL 5/35/70 Series User’s GuideAppendix A Product Specifications 668Compatible ZyXEL WLAN CardsThe following table lists the ZyXEL WLAN cards that

Page 633

ZyWALL 5/35/70 Series User’s Guide669 Appendix A Product SpecificationsFigure 411 WLAN Card InstallationCable Pin AssignmentsIn a serial communicat

Page 634

ZyWALL 5/35/70 Series User’s Guide67 Chapter 2 Introducing the Web ConfiguratorFigure 6 Change Password Screen6 Click Apply in the Replace Certific

Page 635

ZyWALL 5/35/70 Series User’s GuideAppendix A Product Specifications 670 Figure 413 Ethernet Cable Pin AssignmentsTable 253 Console/Dial Backup Por

Page 636 - CHAPTER 49

ZyWALL 5/35/70 Series User’s Guide671 Appendix A Product Specifications

Page 637

ZyWALL 5/35/70 Series User’s GuideAppendix B Hardware Installation 672APPENDIX BHardware InstallationThe ZyWALL can be placed on a desktop or rack-mou

Page 638

ZyWALL 5/35/70 Series User’s Guide673 Appendix B Hardware InstallationFigure 414 Attaching Rubber Feet Note: Do not block the ventilation holes

Page 639

ZyWALL 5/35/70 Series User’s GuideAppendix B Hardware Installation 674Figure 415 Attaching Mounting Brackets and Screws3 After attaching both mounti

Page 640 - CHAPTER 50

ZyWALL 5/35/70 Series User’s Guide675 Appendix B Hardware Installation

Page 641 - 50.2 IP Routing Policy Setup

ZyWALL 5/35/70 Series User’s GuideAppendix C Removing and Installing a Fuse 676APPENDIX CRemoving and Installing a Fuse This appendix shows you how to

Page 642

ZyWALL 5/35/70 Series User’s Guide677 Appendix C Removing and Installing a Fuse

Page 643 - (shown next)

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 678APPENDIX DSetting up Your Computer’s IP AddressAll computers mus

Page 644

ZyWALL 5/35/70 Series User’s Guide679 Appendix D Setting up Your Computer’s IP AddressFigure 417 WIndows 95/98/Me: Network: ConfigurationInstalling

Page 645

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 682.3.1 Procedure To Use The Reset ButtonMake sure the SYS LED is on (no

Page 646

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 6803 Select Microsoft from the list of manufacturers.4 Select Clien

Page 647

ZyWALL 5/35/70 Series User’s Guide681 Appendix D Setting up Your Computer’s IP AddressFigure 419 Windows 95/98/Me: TCP/IP Properties: DNS Configura

Page 648 - CHAPTER 51

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 682Figure 420 Windows XP: Start Menu2 In the Control Panel, doubl

Page 649

ZyWALL 5/35/70 Series User’s Guide683 Appendix D Setting up Your Computer’s IP AddressFigure 422 Windows XP: Control Panel: Network Connections: Pr

Page 650

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 684• If you have a static IP address click Use the following IP Add

Page 651

ZyWALL 5/35/70 Series User’s Guide685 Appendix D Setting up Your Computer’s IP AddressFigure 425 Windows XP: Advanced TCP/IP Properties7 In the Int

Page 652 - CHAPTER 52

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 686Figure 426 Windows XP: Internet Protocol (TCP/IP) Properties8

Page 653

ZyWALL 5/35/70 Series User’s Guide687 Appendix D Setting up Your Computer’s IP AddressFigure 427 Macintosh OS 8/9: Apple Menu2 Select Ethernet buil

Page 654

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 6884 For statically assigned settings, do the following:•From the C

Page 655 - Figure 403 Pop-up Blocker

ZyWALL 5/35/70 Series User’s Guide689 Appendix D Setting up Your Computer’s IP AddressFigure 430 Macintosh OS X: Network4 For statically assigned s

Page 656

ZyWALL 5/35/70 Series User’s Guide69 Chapter 2 Introducing the Web ConfiguratorNote: Follow the instructions you see in the HOME screen or click the

Page 657

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 690Note: Make sure you are logged in as the root administrator. Usi

Page 658 - 52.5.1.2 JavaScripts

ZyWALL 5/35/70 Series User’s Guide691 Appendix D Setting up Your Computer’s IP Address• If you have a dynamic IP address, click Automatically obtain

Page 659 - 3 Scroll down to Scripting

ZyWALL 5/35/70 Series User’s GuideAppendix D Setting up Your Computer’s IP Address 6921 Assuming that you have only one network card on the computer,

Page 660 - 52.5.1.3 Java Permissions

ZyWALL 5/35/70 Series User’s Guide693 Appendix D Setting up Your Computer’s IP AddressFigure 438 Red Hat 9.0: Restart Ethernet Card Verifying Sett

Page 661 - 52.5.1.3.1 JAVA (Sun)

ZyWALL 5/35/70 Series User’s GuideAppendix E IP Subnetting 694APPENDIX EIP SubnettingIP Addressing Routers “route” based on the network number. The ro

Page 662 - 52.6 Packet Flow

ZyWALL 5/35/70 Series User’s Guide695 Appendix E IP SubnettingSince the first octet of a class “A” IP address must contain a “0”, the first octet of

Page 663

ZyWALL 5/35/70 Series User’s GuideAppendix E IP Subnetting 696Since the mask is always a continuous number of ones beginning from the left, followed b

Page 664 - APPENDIX A

ZyWALL 5/35/70 Series User’s Guide697 Appendix E IP SubnettingNote: In the following charts, shaded/bolded last octet bit values indicate host ID bit

Page 665 - Table 249 Performance

ZyWALL 5/35/70 Series User’s GuideAppendix E IP Subnetting 698Example: Four Subnets The above example illustrated using a 25-bit subnet mask to divide

Page 666

ZyWALL 5/35/70 Series User’s Guide699 Appendix E IP SubnettingExample Eight SubnetsSimilarly use a 27-bit mask to create 8 subnets (001, 010, 011, 10

Page 667

ZyWALL 5/35/70 Series User’s Guide7 Customer SupportCustomer SupportPlease have the following information ready when you contact customer support.•

Page 668 - Compatible ZyXEL WLAN Cards

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 70The following table describes the labels in this screen.Table 3 Web C

Page 669 - Cable Pin Assignments

ZyWALL 5/35/70 Series User’s GuideAppendix E IP Subnetting 700Subnetting With Class A and Class B Networks. For class “A” and class “B” addresses the

Page 670

ZyWALL 5/35/70 Series User’s Guide701 Appendix E IP Subnetting

Page 671

ZyWALL 5/35/70 Series User’s GuideAppendix F PPPoE 702APPENDIX FPPPoEPPPoE in ActionAn ADSL modem bridges a PPP session over Ethernet (PPP over Ethern

Page 672 - APPENDIX B

ZyWALL 5/35/70 Series User’s Guide703 Appendix F PPPoEFigure 440 Single-Computer per Router Hardware ConfigurationHow PPPoE WorksThe PPPoE driver m

Page 673 - Rack-Mounted Installation

ZyWALL 5/35/70 Series User’s GuideAppendix G PPTP 704APPENDIX GPPTPWhat is PPTP?PPTP (Point-to-Point Tunneling Protocol) is a Microsoft proprietary pr

Page 674 - Figure 416 Rack Mounting

ZyWALL 5/35/70 Series User’s Guide705 Appendix G PPTPPPTP Protocol OverviewPPTP is very similar to L2TP, since L2TP is based on both PPTP and L2F (Ci

Page 675

ZyWALL 5/35/70 Series User’s GuideAppendix G PPTP 706Figure 444 Example Message Exchange between Computer and an ANTPPP Data ConnectionThe PPP frame

Page 676 - APPENDIX C

ZyWALL 5/35/70 Series User’s Guide707 Appendix G PPTP

Page 677

ZyWALL 5/35/70 Series User’s GuideAppendix H Wireless LANs 708APPENDIX HWireless LANsWireless LAN TopologiesThis section discusses ad-hoc and infrastr

Page 678 - APPENDIX D

ZyWALL 5/35/70 Series User’s Guide709 Appendix H Wireless LANsFigure 446 Basic Service SetESSAn Extended Service Set (ESS) consists of a series of

Page 679 - Installing Components

ZyWALL 5/35/70 Series User’s Guide71 Chapter 2 Introducing the Web Configurator2.4.2 Bridge ModeThe following screen displays when the ZyWALL is set

Page 680 - Configuring

ZyWALL 5/35/70 Series User’s GuideAppendix H Wireless LANs 710Figure 447 Infrastructure WLANChannelA channel is the radio frequency(ies) used by IEE

Page 681 - Windows 2000/NT/XP

ZyWALL 5/35/70 Series User’s Guide711 Appendix H Wireless LANsFigure 448 RTS/CTSWhen station A sends data to the AP, it might not know that the sta

Page 682

ZyWALL 5/35/70 Series User’s GuideAppendix H Wireless LANs 712A large Fragmentation Threshold is recommended for networks not prone to interference wh

Page 683

ZyWALL 5/35/70 Series User’s Guide713 Appendix H Wireless LANsIEEE 802.1xIn June 2001, the IEEE 802.1x standard was designed to extend the features o

Page 684

ZyWALL 5/35/70 Series User’s GuideAppendix H Wireless LANs 714• Access-ChallengeSent by a RADIUS server requesting more information in order to allow

Page 685

ZyWALL 5/35/70 Series User’s Guide715 Appendix H Wireless LANs3 The wireless station replies with identity information, including username and passwo

Page 686 - Macintosh OS 8/9

ZyWALL 5/35/70 Series User’s GuideAppendix H Wireless LANs 716PEAP (Protected EAP) Like EAP-TTLS, server-side certificate authentication is used to

Page 687

ZyWALL 5/35/70 Series User’s Guide717 Appendix H Wireless LANsFigure 450 WEP Authentication StepsOpen system authentication involves an unencrypted

Page 688 - Macintosh OS X

ZyWALL 5/35/70 Series User’s GuideAppendix H Wireless LANs 718Note: EAP-MD5 cannot be used with Dynamic WEP Key ExchangeFor added security, certificat

Page 689 - Verifying Settings

ZyWALL 5/35/70 Series User’s Guide719 Appendix H Wireless LANsThe Message Integrity Check (MIC) is designed to prevent an attacker from capturing dat

Page 690

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 72Figure 10 Web Configurator HOME Screen in Bridge ModeThe following ta

Page 691 - Using Configuration Files

ZyWALL 5/35/70 Series User’s GuideAppendix H Wireless LANs 720In a network environment with multiple access points, wireless stations are able to swit

Page 692

ZyWALL 5/35/70 Series User’s Guide721 Appendix H Wireless LANsRequirements for RoamingThe following requirements must be met in order for wireless st

Page 693

ZyWALL 5/35/70 Series User’s GuideAppendix I Triangle Route 722APPENDIX ITriangle RouteThe Ideal Setup When the firewall is on, your ZyWALL acts as a

Page 694 - APPENDIX E

ZyWALL 5/35/70 Series User’s Guide723 Appendix I Triangle RouteFigure 453 “Triangle Route” ProblemThe “Triangle Route” SolutionsThis section presen

Page 695 - Subnetting

ZyWALL 5/35/70 Series User’s GuideAppendix I Triangle Route 724Figure 454 IP AliasGateways on the WAN SideA second solution to the “triangle route”

Page 696 - Example: Two Subnets

ZyWALL 5/35/70 Series User’s Guide725 Appendix I Triangle Route

Page 697 - Table 260 Subnet 2

ZyWALL 5/35/70 Series User’s GuideAppendix J Windows 98 SE/Me Requirements for Anti-Virus Message Display 726APPENDIX JWindows 98 SE/Me Requirements f

Page 698 - Example: Four Subnets

ZyWALL 5/35/70 Series User’s Guide727 Appendix J Windows 98 SE/Me Requirements for Anti-Virus Message DisplayFigure 457 WIndows 98 SE: Program Task

Page 699 - Example Eight Subnets

ZyWALL 5/35/70 Series User’s GuideAppendix J Windows 98 SE/Me Requirements for Anti-Virus Message Display 728Figure 459 Windows 98 SE: StartUp 5 A

Page 700 - Appendix E IP Subnetting 700

ZyWALL 5/35/70 Series User’s Guide729 Appendix J Windows 98 SE/Me Requirements for Anti-Virus Message DisplayFigure 461 Windows 98 SE: Startup: Sel

Page 701 - 701 Appendix E IP Subnetting

ZyWALL 5/35/70 Series User’s Guide73 Chapter 2 Introducing the Web ConfiguratorFirmware Version This is the ZyNOS Firmware version and the date creat

Page 702 - APPENDIX F

ZyWALL 5/35/70 Series User’s GuideAppendix K VPN Setup 730APPENDIX KVPN Setup This appendix will help you to quickly create a IPSec/VPN connection bet

Page 703 - ZyWALL as a PPPoE Client

ZyWALL 5/35/70 Series User’s Guide731 Appendix K VPN SetupThe following pages show a typical configuration that builds a tunnel between two private n

Page 704 - APPENDIX G

ZyWALL 5/35/70 Series User’s GuideAppendix K VPN Setup 732Figure 464 Headquarters Gateway Policy EditThe IP address of the branch office IPSec route

Page 705 - Control & PPP Connections

ZyWALL 5/35/70 Series User’s Guide733 Appendix K VPN SetupFigure 465 Branch Office Gateway Policy Edit3 Click the add network policy ( ) icon next

Page 706 - PPP Data Connection

ZyWALL 5/35/70 Series User’s GuideAppendix K VPN Setup 734Figure 466 Headquarters VPN RuleFigure 467 Branch Office VPN Rule4 Configure the screens

Page 707 - 707 Appendix G PPTP

ZyWALL 5/35/70 Series User’s Guide735 Appendix K VPN SetupFigure 468 Headquarters Network Policy EditIP addresses on different subnets.Activate the

Page 708 - APPENDIX H

ZyWALL 5/35/70 Series User’s GuideAppendix K VPN Setup 736Figure 469 Branch Office Network Policy EditDialing the VPN Tunnel via Web ConfiguratorTo

Page 709 - 709 Appendix H Wireless LANs

ZyWALL 5/35/70 Series User’s Guide737 Appendix K VPN SetupFigure 470 VPN Rule ConfiguredThe following screen displays.Figure 471 VPN DialThis scr

Page 710 - Appendix H Wireless LANs 710

ZyWALL 5/35/70 Series User’s GuideAppendix K VPN Setup 738VPN TroubleshootingIf the IPSec tunnel does not build properly, the problem is likely a conf

Page 711 - Fragmentation Threshold

ZyWALL 5/35/70 Series User’s Guide739 Appendix K VPN SetupFigure 473 VPN Log Example ras> sys log disp ike ipsec# .time source

Page 712 - Preamble Type

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 742.4.3 Navigation PanelAfter you enter the password, use the sub-menus

Page 713 - IEEE 802.1x

ZyWALL 5/35/70 Series User’s GuideAppendix K VPN Setup 740IPSec DebugIf you are having difficulty building an IPSec tunnel to a non-ZyXEL IPSec router

Page 714 - EAP Authentication

ZyWALL 5/35/70 Series User’s Guide741 Appendix K VPN SetupUse a VPN TunnelA VPN tunnel gives you a secure connection to another computer or network.

Page 715 - Types of Authentication

ZyWALL 5/35/70 Series User’s GuideAppendix L Importing Certificates 742APPENDIX L Importing CertificatesThis appendix shows importing certificates exa

Page 716 - WEP Authentication Steps

ZyWALL 5/35/70 Series User’s Guide743 Appendix L Importing CertificatesFigure 476 Login Screen2 Click Install Certificate to open the Install Certi

Page 717 - Dynamic WEP Key Exchange

ZyWALL 5/35/70 Series User’s GuideAppendix L Importing Certificates 744Figure 478 Certificate Import Wizard 14 Select where you would like to store

Page 718 - Encryption

ZyWALL 5/35/70 Series User’s Guide745 Appendix L Importing CertificatesFigure 480 Certificate Import Wizard 36 Click Yes to add the ZyWALL certifi

Page 719 - Security Parameters Summary

ZyWALL 5/35/70 Series User’s GuideAppendix L Importing Certificates 746Figure 482 Certificate General Information after ImportEnrolling and Importin

Page 720 - Figure 451 Roaming Example

ZyWALL 5/35/70 Series User’s Guide747 Appendix L Importing CertificatesFigure 483 ZyWALL Trusted CA ScreenThe CA sends you a package containing the

Page 721 - Requirements for Roaming

ZyWALL 5/35/70 Series User’s GuideAppendix L Importing Certificates 748Figure 484 CA Certificate Example2 Click Install Certificate and follow the w

Page 722 - APPENDIX I

ZyWALL 5/35/70 Series User’s Guide749 Appendix L Importing CertificatesFigure 485 Personal Certificate Import Wizard 12 The file name and path of t

Page 723 - IP Aliasing

ZyWALL 5/35/70 Series User’s Guide75 Chapter 2 Introducing the Web ConfiguratorTable Key: An O in a mode’s column shows that the device mode has the

Page 724 - Gateways on the WAN Side

ZyWALL 5/35/70 Series User’s GuideAppendix L Importing Certificates 750Figure 487 Personal Certificate Import Wizard 34 Have the wizard determine wh

Page 725

ZyWALL 5/35/70 Series User’s Guide751 Appendix L Importing CertificatesFigure 489 Personal Certificate Import Wizard 56 You should see the followin

Page 726 - APPENDIX J

ZyWALL 5/35/70 Series User’s GuideAppendix L Importing Certificates 752Figure 492 SSL Client Authentication3 You next see the ZyWALL login screen.Fi

Page 727

ZyWALL 5/35/70 Series User’s Guide753 Appendix L Importing Certificates

Page 728

ZyWALL 5/35/70 Series User’s GuideAppendix M Command Interpreter 754APPENDIX MCommand InterpreterThe following describes how to use the command interp

Page 729 - Figure 456 on page 726)

ZyWALL 5/35/70 Series User’s Guide755 Appendix M Command Interpreter

Page 730 - APPENDIX K

ZyWALL 5/35/70 Series User’s GuideAppendix N Firewall Commands 756APPENDIX NFirewall Commands The following describes the firewall commands. See Appen

Page 731 - VPN Configuration

ZyWALL 5/35/70 Series User’s Guide757 Appendix N Firewall CommandsE-mail config edit firewall e-mail mail-server <ip address of mail server>Th

Page 732 - Appendix K VPN Setup 732

ZyWALL 5/35/70 Series User’s GuideAppendix N Firewall Commands 758config edit firewall attack minute-high <0-255>This command sets the threshold

Page 733 - 733 Appendix K VPN Setup

ZyWALL 5/35/70 Series User’s Guide759 Appendix N Firewall CommandsConfig edit firewall set <set #> tcp-idle-timeout <seconds>This command

Page 734 - Appendix K VPN Setup 734

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 76WAN General This screen allows you to configure load balancing, route p

Page 735 - 735 Appendix K VPN Setup

ZyWALL 5/35/70 Series User’s GuideAppendix N Firewall Commands 760config edit firewall set <set #> rule <rule #> destaddr-subnet <ip ad

Page 736 - Appendix K VPN Setup 736

ZyWALL 5/35/70 Series User’s Guide761 Appendix N Firewall Commands

Page 737 - Figure 471 VPN Dial

ZyWALL 5/35/70 Series User’s GuideAppendix O NetBIOS Filter Commands 762APPENDIX ONetBIOS Filter CommandsThe following describes the NetBIOS packet fi

Page 738 - VPN Troubleshooting

ZyWALL 5/35/70 Series User’s Guide763 Appendix O NetBIOS Filter CommandsThe filter types and their default settings are as follows.NetBIOS Filter Con

Page 739 - Figure 473 VPN Log Example

ZyWALL 5/35/70 Series User’s GuideAppendix O NetBIOS Filter Commands 764sys filter netbios config 3 onThis command blocks IPSec NetBIOS packets.sys fi

Page 740 - IPSec Debug

ZyWALL 5/35/70 Series User’s Guide765 Appendix O NetBIOS Filter Commands

Page 741 - Use a VPN Tunnel

ZyWALL 5/35/70 Series User’s GuideAppendix P Certificates Commands 766APPENDIX PCertificates Commands The following describes the certificate commands

Page 742 - APPENDIX L

ZyWALL 5/35/70 Series User’s Guide767 Appendix P Certificates Commandscreate cmp_enroll <name> <CA addr> <CA cert> <auth key>

Page 743 - Figure 476 Login Screen

ZyWALL 5/35/70 Series User’s GuideAppendix P Certificates Commands 768replace_factoryCreate a certificate using your device MAC address that will be s

Page 744

ZyWALL 5/35/70 Series User’s Guide769 Appendix P Certificates Commands delete <name> Delete the specified trusted remote host certificate. <

Page 745

ZyWALL 5/35/70 Series User’s Guide77 Chapter 2 Introducing the Web ConfiguratorIDP General Use this screen to enable IDP on the ZyWALL and choose wha

Page 746

ZyWALL 5/35/70 Series User’s GuideAppendix Q Brute-Force Password Guessing Protection 770APPENDIX QBrute-Force Password Guessing ProtectionBrute-force

Page 747

ZyWALL 5/35/70 Series User’s Guide771 Appendix Q Brute-Force Password Guessing Protection

Page 748

ZyWALL 5/35/70 Series User’s GuideAppendix R Boot Commands 772APPENDIX RBoot CommandsThe BootModule AT commands execute from within the router’s bootu

Page 749

ZyWALL 5/35/70 Series User’s Guide773 Appendix R Boot CommandsFigure 495 Boot Module CommandsAT just answer OKATHE print helpAT

Page 750

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 774APPENDIX SLog DescriptionsThis appendix provides descriptions of example log messages

Page 751

ZyWALL 5/35/70 Series User’s Guide775 Appendix S Log DescriptionsConfiguration Change: PC = 0x%x, Task ID = 0x%xThe router is saving configuration ch

Page 752

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 776 WAN connection is down. A WAN connection is down. You cannot access the network thro

Page 753

ZyWALL 5/35/70 Series User’s Guide777 Appendix S Log Descriptions Table 278 TCP Reset Logs LOG MESSAGE DESCRIPTIONUnder SYN flood attack, sent TCP

Page 754 - APPENDIX M

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 778 For type and code details, see Ta b l e 294 on page 789. Table 280 ICMP Logs LOG

Page 755

ZyWALL 5/35/70 Series User’s Guide779 Appendix S Log Descriptions ppp:LCP Closing The PPP connection’s Link Control Protocol stage is closing.ppp:I

Page 756 - APPENDIX N

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 78NAT NAT Overview Use this screen to enable NAT.Address MappingUse this

Page 757

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 780 For type and code details, see Table 294 on page 789.Connecting to content filter se

Page 758

ZyWALL 5/35/70 Series User’s Guide781 Appendix S Log DescriptionsFirewall sent TCP packet in response to DoS attack TCPThe firewall sent TCP packet i

Page 759

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 782 Table 287 Wireless LogsLOG MESSAGE DESCRIPTIONWLAN MAC Filter Fail The MAC filter

Page 760

ZyWALL 5/35/70 Series User’s Guide783 Appendix S Log Descriptions Table 289 IKE Logs LOG MESSAGE DESCRIPTIONActive connection allowed exceededThe I

Page 761

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 784Remote IP <Remote IP> / <Remote IP> conflictsThe security gateway is set

Page 762 - APPENDIX O

ZyWALL 5/35/70 Series User’s Guide785 Appendix S Log DescriptionsRule [%d] Phase 2 authentication algorithm mismatchThe listed rule’s IKE phase 2 aut

Page 763 - NetBIOS Filter Configuration

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 786 Table 290 PKI Logs LOG MESSAGE DESCRIPTIONEnrollment successful The SCEP online ce

Page 764

ZyWALL 5/35/70 Series User’s Guide787 Appendix S Log Descriptions Table 291 Certificate Path Verification Failure Reason Codes CODE DESCRIPTION1 A

Page 765

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 788Local User Database does not find user`s credential.A user was not authenticated by t

Page 766 - APPENDIX P

ZyWALL 5/35/70 Series User’s Guide789 Appendix S Log Descriptions (L to L/ZW) LAN to LAN/ZyWALLACL set for packets traveling from the LAN to the LAN

Page 767

ZyWALL 5/35/70 Series User’s Guide79 Chapter 2 Introducing the Web Configurator2.4.4 System StatisticsClick Show Statistics in the HOME screen. Read

Page 768

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 790 11 Time Exceeded0 Time to live exceeded in transit1 Fragment reassembly time exceede

Page 769

ZyWALL 5/35/70 Series User’s Guide791 Appendix S Log Descriptions Signature update OK - New signature version: <Signature version> Release Date

Page 770 - APPENDIX Q

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 792 The turbo card is not ready , please insert the card and reboot!The turbo card is no

Page 771

ZyWALL 5/35/70 Series User’s Guide793 Appendix S Log DescriptionsRemove rating server [%Rating Server IP Address%] from server list!The listed server

Page 772 - APPENDIX R

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 794Syslog LogsThere are two types of syslog: event logs and traffic logs. The device gen

Page 773 - 773 Appendix R Boot Commands

ZyWALL 5/35/70 Series User’s Guide795 Appendix S Log DescriptionsThe following table shows RFC-2408 ISAKMP payload types that the log displays. Pleas

Page 774 - APPENDIX S

ZyWALL 5/35/70 Series User’s GuideAppendix S Log Descriptions 796Log CommandsGo to the command interpreter interface. Appendix M on page 754 explains

Page 775

ZyWALL 5/35/70 Series User’s Guide797 Appendix S Log Descriptions• Use the sys logs clear command to erase all of the ZyWALL’s logs.Log Command Examp

Page 776

ZyWALL 5/35/70 Series User’s Guide Index 798IndexNumerics10/100 Mbps Ethernet WAN 55110V AC 5230V AC 5AAbnormal Working Conditions 6AC 5Access control

Page 777 - Table 278 TCP Reset Logs

ZyWALL 5/35/70 Series User’s Guide799 IndexCCA 715Cable Modem 203Cables, Connecting 5Call Back Delay 518Call Control 630Call History 631, 632Call Sc

Page 778 - Table 282 PPP Logs

ZyWALL 5/35/70 Series User’s Guide Customer Support [email protected] +48-22-5286603 www.pl.zyxel.com ZyXEL Communications ul.Emilli Plater 53

Page 779 - Table 283 UPnP Logs

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 802.4.5 Show Statistics: Line ChartClick the icon in the Show Statistics

Page 780 - Table 285 Attack Logs

ZyWALL 5/35/70 Series User’s Guide Index 800DNS 452DNS ServerFor VPN Host 419Domain Name 142, 276, 384, 484, 603DoSBasics 204Types 205DoS (Denial of S

Page 781

ZyWALL 5/35/70 Series User’s Guide801 IndexFirmware FileMaintenance 612Fitness 6Flow Control 500Fragmentation Threshold 711Fragmentation threshold 7

Page 782 - Table 288 IPSec Logs

ZyWALL 5/35/70 Series User’s Guide Index 802IP Addressing 694IP Alias 60, 530IP Alias Setup 530IP Classes 694IP Multicast 60Internet Group Management

Page 783 - Table 289 IKE Logs

ZyWALL 5/35/70 Series User’s Guide803 IndexMIME 273MIME Header 276MIME Headers 270MIME Value 276Modifications 3MSDU 545Multicast 112, 114, 176, 523,

Page 784

ZyWALL 5/35/70 Series User’s Guide Index 804Levels 248Policy-based Routing 396Polyphormic virus 258Pool 5POP2 269POP3 204, 269, 271, 273, 384Port Forw

Page 785

ZyWALL 5/35/70 Series User’s Guide805 IndexReturn Material Authorization (RMA) Number 6Returned Products 6Returns 6RFC 1889 467RFC 3489 469Rights 2R

Page 786 - Table 290 PKI Logs

ZyWALL 5/35/70 Series User’s Guide Index 806SSH 57, 441SSH Implementation 442startup 728Stateful Inspection 57, 202, 203, 208, 209Process 209ZyWALL 21

Page 787 - Table 292 802.1X Logs

ZyWALL 5/35/70 Series User’s Guide807 IndexUnsolicited Commercial E-mail 266Upload Firmware 621UPnP 58, 456UPnP Examples 459UPnP Port Mapping 458Upp

Page 788

ZyWALL 5/35/70 Series User’s Guide81 Chapter 2 Introducing the Web ConfiguratorThe following table describes the labels in this screen.2.4.6 DHCP Ta

Page 789 - Table 294 ICMP Notes

ZyWALL 5/35/70 Series User’s GuideChapter 2 Introducing the Web Configurator 82The following table describes the labels in this screen.2.4.7 VPN Stat

Page 790 - Table 295 IDP Logs

ZyWALL 5/35/70 Series User’s Guide83 Chapter 2 Introducing the Web ConfiguratorFigure 14 Home : VPN StatusThe following table describes the labels

Page 791 - Table 296 AV Logs

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 84CHAPTER 3Wizard SetupThis chapter provides information on the Wizard Setup screens in the w

Page 792 - Table 297 AS Logs

ZyWALL 5/35/70 Series User’s Guide85 Chapter 3 Wizard SetupFigure 15 ISP Parameters : Ethernet EncapsulationThe following table describes the label

Page 793

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 863.2.1.2 PPPoE EncapsulationPoint-to-Point Protocol over Ethernet (PPPoE) functions as a di

Page 794 - Syslog Logs

ZyWALL 5/35/70 Series User’s Guide87 Chapter 3 Wizard Setup3.2.1.3 PPTP EncapsulationPoint-to-Point Tunneling Protocol (PPTP) is a network protocol

Page 795

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 88Figure 17 ISP Parameters: PPTP EncapsulationThe following table describes the labels in t

Page 796 - Log Commands

ZyWALL 5/35/70 Series User’s Guide89 Chapter 3 Wizard Setup3.2.2 Internet Access Wizard: Second ScreenClick Next to go to the screen where you can r

Page 797 - Log Command Example

ZyWALL 5/35/70 Series User’s Guide9 Customer Support

Page 798 - Numerics

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 90Figure 19 Internet Access Setup Complete3.2.3 Internet Access Wizard: RegistrationIf you

Page 799 - 799 Index

ZyWALL 5/35/70 Series User’s Guide91 Chapter 3 Wizard SetupThe following table describes the labels in this screen. After you fill in the fields and

Page 800 - Index 800

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 92Figure 22 Internet Access Wizard: StatusThe following screen appears if the registration

Page 801 - 801 Index

ZyWALL 5/35/70 Series User’s Guide93 Chapter 3 Wizard SetupFigure 25 Internet Access Wizard: Activated Services3.3 VPN Wizard Gateway SettingUse t

Page 802 - Index 802

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 94The following table describes the labels in this screen.3.4 VPN Wizard Network SettingTwo

Page 803 - 803 Index

ZyWALL 5/35/70 Series User’s Guide95 Chapter 3 Wizard SetupFigure 27 VPN Wizard: Network SettingThe following table describes the labels in this sc

Page 804 - Index 804

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 963.5 VPN Wizard IKE Tunnel Setting (IKE Phase 1)Figure 28 VPN Wizard: IKE Tunnel SettingR

Page 805 - 805 Index

ZyWALL 5/35/70 Series User’s Guide97 Chapter 3 Wizard SetupThe following table describes the labels in this screen.Table 17 VPN Wizard: IKE Tunnel

Page 806 - Index 806

ZyWALL 5/35/70 Series User’s GuideChapter 3 Wizard Setup 983.6 VPN Wizard IPSec Setting (IKE Phase 2)Figure 29 VPN Wizard: IPSec SettingThe followi

Page 807 - 807 Index

ZyWALL 5/35/70 Series User’s Guide99 Chapter 3 Wizard Setup3.7 VPN Wizard Status SummaryThis read-only screen shows the status of the current VPN se

Comments to this Manuals

No comments