ZyXEL ZyWALL 2WG User Manual

Browse online or download User Manual for Routers ZyXEL ZyWALL 2WG. ZyXEL ZyWALL 2WG User's Manual

  • Download
  • Add to my manuals
  • Print

Summary of Contents

Page 1 - ZyWALL 2WG

ZyWALL 2WG Security Appliance Support Notes Version 4.03 Sep. 2007

Page 2

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 10Utilize 3G and Wireless for the Internet Access Fol

Page 3

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 100Pre-Shared Key must be identical on both entitiesL

Page 4

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 101As the figure shown below, each branch office have

Page 5

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 1022. check Active check box and give a name to

Page 6

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 103 You can setup IKE phase 1 and phase 2 parameters

Page 7

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 104 2. Setup VPN in branch office B Be very careful

Page 8

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 105

Page 9 - Application Notes

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 106Note that since Branch B's LAN is also includ

Page 10 - ZyWALL 2WG Support Notes

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 107

Page 11

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 108 2. The correspondent rule for Branch_B

Page 12

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 109

Page 13

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 11 3). Then the 3G wireless card will be dialed up au

Page 14

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 110 NAT over IPSec on ZyNOS Network Topology The

Page 15

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 111change at least one of the LAN IP addresses in ord

Page 16

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 112 ZyWALL 2 (Remote) STEP 2: Create the Gateway Pol

Page 17

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 113 Gateway Policy on ZyWALL 1 Click “Apply” in orde

Page 18

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 114 Gateway Policy on ZyWALL 2 Gateway Policy on Zy

Page 19

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 115policy. Check the “Active” checkbox in the “Virtu

Page 20

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 116 On ZyWALL 1, the remote network will be changed t

Page 21

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 117 On ZyWALL 2, the Virtual IP Addresses starts fro

Page 22

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 118Click Security > VPN > Connect in order to e

Page 23

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 1191) Ping the local gateway. 2) Ping the IPSec Rem

Page 24 - Internet

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 12 4) If dialed up successfully, you can see the GUI

Page 25

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 120 The VPN high availability is design for securing

Page 26

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 121 3. Give a name for your policy, for example “Dua

Page 27

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 122

Page 28

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 123Access control and security VPN connection (Securi

Page 29

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 124 3. For example, the remote VPN policy is 192.168

Page 30

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 125 4. Click the Insert button to insert a new rule.

Page 31

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 126 6. The service type is Any to block all kind of

Page 32

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 127 7. We can see a new rule had been configured and

Page 33

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 128 How to configure Web filtering rule over VPN –

Page 34

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 129

Page 35

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 13Utilize the embedded wireless card to provide LAN u

Page 36

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 130 ZyWALL vs 3rd Party VPN Gateway SonicWALL with Z

Page 37

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 13111. Go to SECURITY->VPN->Press Add button

Page 38

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 132 16. Select Negotiation Mode to Main mode, Encryp

Page 39

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 133 18. Check Active check box and give a name to th

Page 40

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 13420. On Local Network, choose Subnet Address for yo

Page 41

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 135 23. When you finished doing your settings, you w

Page 42

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 136 2. Click General tab, on Security Policy settin

Page 43

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 137 4. Network IP Address and Subnet Mask are your r

Page 44

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 138 6. When you finished doing your settings, you wi

Page 45

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 139 NetScreen with ZyWALL VPN Tunneling 1. Setup Z

Page 46

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 14 To configure the security and the MAC filter, go t

Page 47

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 140The IP addresses we use in this example are as sho

Page 48

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 141 6. In Authentication Key, enter the key string

Page 49

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 1428. You will see an IKE rule on your VPN page, cli

Page 50

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 143type 192.168.2.0 on Starting IP Address field and

Page 51

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 144 14. When you finished doing your settings, you w

Page 52

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 145 Note: About the settings, you could reference to

Page 53

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 146 6. On Security Level settings, you could set up

Page 54

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 147 8. To edit your IPSec rule, click VPNs -> Au

Page 55

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 148 11. Check VPN Monitor check box, thus you can mo

Page 56

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 149 14. Give a name for your policy, for example “ZyW

Page 57

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 15

Page 58

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 150 17. When you finished doing the settings, you wi

Page 59

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 15118. Move your policy rules to top, thus your devic

Page 60

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 152This page guides us to setup a VPN connection betw

Page 61

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 153 3. Give a name for your policy, for example “ToC

Page 62

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 154 7. Select Negotiation Mode to Main mode, Encrypt

Page 63

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 155 10. On Gateway Policy Information, you should cho

Page 64

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 15613. On IPSec Proposal, select Encapsulation Mode t

Page 65

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 157 1. on your PC, clicking Start->Programmer->

Page 66

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 158 6. On General Properties, the IP Addrrss field i

Page 67 -

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 159 7. On Topology settings, you should see two int

Page 68

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 16

Page 69

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 160 8. Selecting 172.22.2.58 interface, and press Edi

Page 70

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 161 II. Setup Interoperable Device 10. On the main

Page 71

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 162 11. You will see the network objects window, pre

Page 72

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 16312. On General Properties settings, give a name an

Page 73

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 16414. Giving a name for the interface, and assign th

Page 74

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 165 17. Giving a name for the interface, and assign

Page 75

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 166 19. Pressing OK button to save the settings.

Page 76

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 167 III. Setup Networks

Page 77

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 168 20. Selecting Networks object and click the right

Page 78

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 169 22. To add another network policy, and set the ne

Page 79

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 17After you have configured the Security and MAC filt

Page 80

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 170 26. On Center Gateways settings, press Add butto

Page 81

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 17127. If you have already done the previous settings

Page 82

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 17229. If you have already done the previous settings

Page 83

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 17331. On Tunnel Management, leave the settings to de

Page 84

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 174 33. On Shared Secret settings, choose ToZyWALL op

Page 85

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 175 36. Press OK button to save your settings.

Page 86

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 176 37. After you press OK button, you should see a

Page 87

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 177 39. Press Add button to add a rule. 40. On the

Page 88

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 178 42. To use the same way to add another network o

Page 89

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 17944. On the VPN field, click right button of your m

Page 90

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 18Seamless Incorporation into your network Using Tra

Page 91

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 180 47. Clicking OK button to save your settings.

Page 92

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 181 49. On the track field, click right button of yo

Page 93

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 18251. Pressing add button to add another rule which

Page 94

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 183 54. Waiting few seconds for the installation.

Page 95

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 184 55. If you install the policy successfully, your

Page 96

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 185 FortiNet with ZyWALL VPN Tunneling 1. Setup Z

Page 97

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 186 The IP addresses we use in this example are as sh

Page 98

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 187 6. In Authentication Key, enter the key string

Page 99

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 1888. After you press the Apply button, you will see

Page 100

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 189 12. On Remote Network, choose Subnet Address for

Page 101

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 19 Deploying a transparent mode firewall doesn’t req

Page 102

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 19014. After you press the Apply button, you will see

Page 103

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 191 4. On P1 proposal settings, select Encryption to

Page 104

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 192 6. After you press the OK button, you will see a

Page 105

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 193 9. On P2 Proposal settings, select Encryption t

Page 106

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 194 11. After you press the OK button, you will see

Page 107

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 19513. To define the IP source address of the Network

Page 108

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 196 17. On the main page, click Firewall -> Policy

Page 109

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 197 21. After you press the OK button, you will the

Page 110

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 198 Remote Access VPN Scenario The remote access V

Page 111

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 199existing Internet Key Exchange (IKE) Protocol feat

Page 112

ZyWALL 2WG Support Notes 2INDEX Application Notes...

Page 113

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 20User can configure ZyWALL to act as a router mode f

Page 114

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 200 Local User RADIUS When external “RADIUS” is s

Page 115

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 2011. Setup ZyWALL VPN Client 2. Setup ZyWALL Th

Page 116

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 202 Remote Party Identity and Addressing settings:4.

Page 117

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 203 Pre-Share Key Settings: 6. Extend ZyWALL icon, y

Page 118

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 204 Security Policy Settings:9. Click Security Policy

Page 119

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 205 10. Extend Security Policy icon, you will see tw

Page 120 - ZyWALL 2 Plus

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 206

Page 121

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 207 2. Setup ZyWALL VPN 1. Using a web browser, log

Page 122

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 208 You can further adjust IKE Phase 1/Phase 2 parame

Page 123 - IPSec Tunnel

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 209 Content Filter Application To filter non-work rel

Page 124

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 21assign a management IP for ZyWALL. The Gateway IP A

Page 125

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 210 1. Minimize Spyware Attack As mentioned earlier,

Page 126

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 211“Violence/Hate/Racism”, “Gay/Lesbian”, “Gambling”,

Page 127

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 212 2. Proactively Prevent Phishing Phishing – The

Page 128

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 213 2.1.2  Customize the Forbidden web sites which

Page 129

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 214 3. Prevent non-business web surfing Below is an

Page 130

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 215 3.2 Using external database content filte

Page 131

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 216to www.zyxel.com with “(Website Blocking)” message

Page 132

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 217 To manage your ZyWALLs through Vantage CNM, user

Page 133

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 218the following section, we will explain how to regi

Page 134

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 2191. device type 2. device name 3. device&apo

Page 135

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 22Step3. After rebooting, login ZyWALL’s GUI by ac

Page 136

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 220 Step 4. On the device, go to ADVANCED->REMOTE

Page 137

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 221 On Vantage CNM, the device icon will turn green a

Page 138

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 222A02. Will the ZyWALL work with my Internet connect

Page 139

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 223A08. How can I configure the ZyWALL?  Telnet r

Page 140

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 224table. Therefore, to make a local server accessibl

Page 141

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 225A20. My ZyWALL can not get an IP address from the

Page 142

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 226computer to be more easily accessed from various l

Page 143

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 227understand the ESP packet with protocol number 50,

Page 144

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 228B01. What is a network firewall? A firewall is a

Page 145

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 229B04. What kind of firewall is the ZyWALL? 1. Th

Page 146

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 23

Page 147

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 230B07. What is Ping of Death attack? Ping of Death

Page 148

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 231B12. What is IP Spoofing attack? Many DoS attack

Page 149

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 232The above figure indicates the "triangle rout

Page 150

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 233(C) To resolve this conflict, we add an option for

Page 151

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 234• Destination IP Mask =w.x.y.z • Action Matche

Page 152

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 235C06. What kind of iCard should I buy? It depends o

Page 153

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 236In summary, myZyXEL.com delivers a convenient, cen

Page 154

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 237 D05. If I were new to myZyXEL.com, what are the r

Page 155

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 238 D09. Who maintains mySecurityZone & Update Se

Page 156

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 239E04. Can I decide whether to forward or drop the H

Page 157

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 24Internet Connection A typical Internet access appl

Page 158

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 240E10. Who needs ZyXEL Content Filtering? Is ZyXEL C

Page 159

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 241E16. How do I keep database of Content Filtering s

Page 160

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 242BlueCoat uses expert Web content raters to train t

Page 161

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 243· Sex Education · Violence/Hate/Racism · Weapons

Page 162

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 244· Sports/Recreation/Hobbies · Streaming Media/MP3

Page 163

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 245E29. Which User Name & Password should I input

Page 164

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 246policy, Gateway_1. In this case, this will be coun

Page 165

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 247company to carry the data traffic over its Interne

Page 166

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 248In this case, Transport mode only protects the upp

Page 167

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 249 F11. What are Local ID and Peer ID? Local ID a

Page 168

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 25Following picture is an example while PPPoE is sele

Page 169

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 250F14. What VPN protocols are supported by ZyWALL? A

Page 170

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 251172.31.255.255 (these address ranges are reserved

Page 171

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 252 F21. Will ZyXEL support Secure Remote Management?

Page 172

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 253If firewall is turned on in ZyWALL, you must forwa

Page 173

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 254F28. Single, Range, Subnet, which types of IP addr

Page 174

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 255cryptography as asymmetric. Symmetric cryptograph

Page 175

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 256Certificate Policies A Certification Practice St

Page 176

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 257describe the rules governing the different uses of

Page 177

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 258When Bob clicks on the digital signature option on

Page 178

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 259G12. Does ZyXEL provide CA service? No, ZyXEL does

Page 179

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 262. When choosing DHCP setting as a ‘Server’, the

Page 180

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 260configuration to the local computer. Then import t

Page 181

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 261b. Installation Speed and Simplicity: Installing a

Page 182

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 262at 11 Mbps or lower depending on range. The range

Page 183

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 2632. Building Materials: metal door, aluminum studs.

Page 184

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 264see the SSID. H17. What is 802.1x? IEEE 802.1x Po

Page 185

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 27 • How NAT works If we define the local IP address

Page 186

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 285. Server In Server mode, the ZyWALL maps multiple

Page 187

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 29 Step 1. Applying NAT in WAN Interface You can cho

Page 188

ZyWALL 2WG Support Notes 3To filter non-work related and unproductive web surfing to mitigate spyware and phishing threats ...

Page 189

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 30 Key Settings Field Options Description Full Fe

Page 190

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 31Step 3. Using Multiple Global IP addresses for clie

Page 191

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 32Rule 2 Setup: Selecting One-to -One type to map the

Page 192

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 33 Now we configure all other incoming traffic to go

Page 193

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 34 Application for Non NAT Friendly Support Som

Page 194

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 35 Optimize network performance & availabilit

Page 195

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 36 How Bandwidth Management in ZyWALL? ZyWALL achiev

Page 196

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 37Go to ADVANCED->BW MGMT->Summary, activate ba

Page 197

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 38 Key Settings: Class Name Give this class a name, f

Page 198 - ZyWALL 2WG Support Notes

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 39Source IP Address Enter the IP address of source th

Page 199

ZyWALL 2WG Support Notes 4gateway behind ZyWALL? ...226 A28. How do I setup my Z

Page 200

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 40 Step1. Activate Bandwidth Management on the interf

Page 201

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 41 Step3. Add another service and allocate 800kbps fo

Page 202

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 42Step4. Add another service and allocate 800kbps for

Page 203

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 43Secure Connections across the Internet Site-to-Sit

Page 204

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 44 1) Configure the static Public IP address to WAN

Page 205

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 45address is assigned to ZyWALL’s WAN interface, ZyWA

Page 206

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 46 4) Configure the DDNS entry under DNS-> DDNS

Page 207

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 47placed behind the NAT router. For example, the NAT

Page 208

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 48when peer VPN entity also support NAT Traversal fun

Page 209 - Content Filter Application

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 49The configuration goal is to achieve following two:

Page 210 - 1. Minimize Spyware Attack

ZyWALL 2WG Support Notes 5D02. In addition to registration, what can I do with myZyXEL.com?235 D03. Is there anything changed on myZyXEL.com becau

Page 211

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 50 6) Extended Authentication (xAuth) can be enabled

Page 212

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 51 10) Click on the icon to add a new “Network Policy

Page 213

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 52 14) Under “Remote Network”, choose “Single” and in

Page 214

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 53 18) Follow the same procedures as step 10~16 to ad

Page 215

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 54DNS, E-mail, Subject Name and Any. Depending how c

Page 216 - Centralized Management

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 55The factory default self-signed certificates are th

Page 217

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 56 2) Or mark the certificate in PEM (Base-64) Encod

Page 218

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 57 When you configure VPN rule with certificate, s

Page 219

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 58servers, and finally get a certificate for further

Page 220

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 59 Step 2. Create certificate request and enroll cert

Page 221 - A. Product FAQ

ZyWALL 2WG Support Notes 6E15. How many URL keywords does ZyWALL support?...240 E16. How do I keep database of Content Filtering

Page 222

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 60 After pressing the Apply button, ZyWALL would crea

Page 223

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 611. Input a name, for this Certificate so you

Page 224

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 62After pressing the Apply button, ZyWALL would creat

Page 225

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 63 13. You can check detailed settings by clicking Ad

Page 226

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 64 Step 5. Using Certifica e in VPN on ZyWALL B

Page 227 - B. Firewall FAQ

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 65 13. You can check detailed settings by clicking Ad

Page 228

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 66 Offline Enroll Certificates In this guide, we de

Page 229

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 67 LAN 1 ZyWALL A ZyWALL B LAN 210.1.133.0/24 LAN:

Page 230

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 68 2. Input a name, for this Certificate so you can i

Page 231

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 69 5. In My Certificates tab, you can get a new entry

Page 232

ZyWALL 2WG Support Notes 7What do I need to know?...250 F18. Does ZyWALL sup

Page 233

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 70 In this support note, we utilize certificate enrol

Page 234

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 71 3, Select Request a Certificate, then press Next&g

Page 235

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 72 4. Choose Advanced request, the press Next> but

Page 236

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 73 5. Choose "Submit a certificate request using

Page 237

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 74 6. Right click your mouse, then paste the certific

Page 238 - E. Content Filter FAQ

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 75 7. Click "Download CA certification path"

Page 239

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 769. Double click the saved file, Select Certificates

Page 240

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 7711. Choose DER encoded binary X.509(.CER), then pre

Page 241

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 7813. Click Finish. 14. Go to ZyWALL WEB GUI -> V

Page 242

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 79 16. After a while, if you see the gray entry turns

Page 243

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 8G16. Will Self-signed certificate be erased if I res

Page 244

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 80 After import CA's certificate, you will get t

Page 245 - F. IPSec FAQ

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 81 2. Input a name, for this Certificate so you can

Page 246

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 823. Wait for 1-2 minutes until "Request Generat

Page 247

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 83 Step 4. Enroll Certificate Request on ZyWALLB

Page 248

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 84 3, Select Request a Certificate, then press Next&g

Page 249

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 85 4. Choose Advanced request, the press Next> but

Page 250

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 86 5. Choose "Submit a certificate request using

Page 251

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 87 6. Right click your mouse, then paste the certific

Page 252

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 88 7. Click "Download CA certification path"

Page 253

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 899. Double click the saved file, Select Certificates

Page 254 - G. PKI FAQ

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 9Application Notes Mobility Internet Access You may

Page 255

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 90 11. Choose DER encoded binary X.509(.CER), then pr

Page 256

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 91 12. Specify the path to store your exported Certif

Page 257

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 9213. Click Finish. 14. Go to ZyWALL WEB GUI -> V

Page 258

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 93 16. After a while, if you see the gray entry turns

Page 259

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 94 18. After import CA's certificate, you will g

Page 260 - H. Wireless FAQ

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 959. Peer ID type= "ANY". 10. Secure Gatewa

Page 261

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 96 13. You can check detailed settings by clicking Ad

Page 262

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 97 Step 6. Using Certificate in VPN on ZyWALL B

Page 263

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 98 13. You can check detailed settings by clicking Ad

Page 264

ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 99 Using Pre-Shared Key for Device Authentication T

Comments to this Manuals

No comments