Zyxel-communications 200 Series Manuel d'utilisateur

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Matériel Zyxel-communications 200 Series. ZyXEL Communications 200 Series User Manual [en] [ru] [de] [fr] [it] [cs] [pl] [es] Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 902
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 0
www.zyxel.com
ZyWALL USG 100/200
Series
Unified Security Gateway
Users Guide
Version 2.10
5/2008
Edition 1
DEFAULT LOGIN
LAN1 Port P4
IP Address http://192.168.1.1
User Name admin
Password 1234
Vue de la page 0
1 2 3 4 5 6 ... 901 902

Résumé du contenu

Page 1 - ZyWALL USG 100/200

www.zyxel.comZyWALL USG 100/200 SeriesUnified Security GatewayUser’s GuideVersion 2.105/2008Edition 1DEFAULT LOGINLAN1 Port P4IP Address http://192.1

Page 2

Contents OverviewZyWALL USG 100/200 Series User’s Guide10Anti-X ...

Page 3 - About This User's Guide

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide1004.8.4 VPN Advanced WizardClick the Advanced radio button as shown in Figure 34 on page

Page 4

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide1014.8.5 VPN Advanced Wizard - Remote Gateway The Remote Gateway policy identifies the I

Page 5 - Document Conventions

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide102The following table describes the labels in this screen.4.8.6 VPN Advanced Wizard - Ph

Page 6 - Icons Used in Figures

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide103" Multiple SAs connecting through a secure gateway must have the same negotiation

Page 7 - Safety Warnings

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide104The following table describes the labels in this screen.Table 20 VPN Advanced Wizard:

Page 8

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide1054.8.7 VPN Advanced Wizard - Phase 2 Active Protocol: ESP is compatible with NAT, AH i

Page 9 - Contents Overview

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide1064.8.8 VPN Advanced Wizard - Summary This summary of VPN tunnel settings is read-only.N

Page 10

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide107Figure 43 VPN Wizard: Step 6: Advanced" If you have not already done so, you ca

Page 11 - Table of Contents

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide108

Page 12 - Chapter 5

ZyWALL USG 100/200 Series User’s Guide109CHAPTER 5 Configuration BasicsThis section provides information to help you configure the ZyWALL effectively

Page 13 - Chapter 6

Table of ContentsZyWALL USG 100/200 Series User’s Guide11Table of ContentsAbout This User's Guide...

Page 14 - Chapter 7

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1105.2 Zones, Interfaces, and Physical PortsZones (groups of interfaces and VPN t

Page 15

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide111• Bridge interfaces create a software connection between Ethernet or VLAN inte

Page 16 - Chapter 12

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide112Table 24 ZyWALL USG 100 Default Port, Interface, and Zone Configuration• The

Page 17

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1135.4 Feature Configuration OverviewThis section provides information about co

Page 18

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide114" PREQUISITES or WHERE USED does not appear if there are no prerequisites

Page 19

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide115Example: See Chapter 6 on page 125.5.4.5 SSL VPNUse SSL VPN to provide secure

Page 20

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide116Example: See Chapter 6 on page 125.5.4.9 DDNSDynamic DNS maps a domain name to

Page 21 - Chapter 29

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide117" The ZyWALL checks the policy routes in the order that they are listed.

Page 22

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1185.4.13 Application PatrolUse application patrol to control which individuals c

Page 23 - Chapter 35

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1195.4.16 ADPUse ADP to detect and take action on traffic and protocol anomalies

Page 24

Table of ContentsZyWALL USG 100/200 Series User’s Guide123.1 Web Configurator Requirements ...

Page 25

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide120The ZyWALL does not check to-ZyWALL firewall rules for packets that are redirec

Page 26 - Chapter 43

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1215.5 ObjectsObjects store information and are referenced by other features. If

Page 27

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1225.6 System Management and MaintenanceThis section introduces some of the manag

Page 28

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1235.6.3 Licensing RegistrationUse these screens to register your ZyWALL and sub

Page 29 - List of Figures

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide124

Page 30

ZyWALL USG 100/200 Series User’s Guide125CHAPTER 6 TutorialsThis chapter provides some examples of using the web configurator to set up features in t

Page 31

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide126Click Network > Interface > Ethernet and the wan1 interface’s Edit icon. Configure t

Page 32

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide127Figure 48 Network > Interface > Ethernet > Edit opt 2 Set DHCP to DHCP Server

Page 33

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide128Figure 49 Network > Interface > Ethernet > Edit opt > More Settings 6.1.3 H

Page 34

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1296.2 How to Configure a Cellular InterfaceUse 3G cards for cellular WAN (Internet) connec

Page 35

Table of ContentsZyWALL USG 100/200 Series User’s Guide135.2 Zones, Interfaces, and Physical Ports ...

Page 36

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide130Figure 52 Network > Interface > Cellular > Edit 5 Go to the Status screen. The

Page 37

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide131Figure 53 Status The ZyWALL automatically balances the traffic load amongst the availab

Page 38

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1321 Click Object > User/Group > User and the Add wlan_user Edit icon.2 Set the User Na

Page 39

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide133Figure 55 Network > Interface > WLAN > Add (WPA/WPA2 Security) 3 Turn on the w

Page 40

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1346.3.3 How to Set Up the Wireless Clients to Use the WLAN InterfaceThe following sections

Page 41

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide135Figure 58 ZyXEL Wireless Client > Profile3 Select WPA2 as the security type and clic

Page 42

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide136Figure 60 ZyXEL Wireless Client > Profile: Security Settings5 Confirm your settings a

Page 43 - List of Tables

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide137Figure 63 ZyXEL Wireless Client > Profile: ActivateSince the ZyXEL utility does not

Page 44

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide138Figure 65 Odyssey Access Client Manager > Profiles > User Info 3 Click the Authent

Page 45

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide139Figure 67 Odyssey Access Client Manager > Profiles > Authentication 5 Click Netwo

Page 46

Table of ContentsZyWALL USG 100/200 Series User’s Guide146.3 How to Set Up a WLAN Interface ...

Page 47

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide140Figure 69 Odyssey Access Client Manager > Networks > Add Use the next section to i

Page 48

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1412 Click Import.Figure 71 Internet Explorer: Tools > Internet Options > Content &g

Page 49

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide142Figure 73 Internet Explorer Certificate Import Wizard Certificate Store Screen5 If you g

Page 50

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide143Figure 75 Internet Explorer: Trusted Root Certification AuthoritiesAs shown here, the M

Page 51 - Getting Started

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide144Figure 77 Funk Odyssey Access Wireless Client Login Example 6.4 How to Set Up an IPSec

Page 52

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide145Figure 79 VPN > IPSec VPN > VPN Gateway > Add6.4.2 How to Set Up the VPN Conn

Page 53 - CHAPTER 1

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide146Figure 81 VPN > IPSec VPN > VPN Connection > Add6.4.3 How to Set Up the Policy

Page 54 - 1.3 Management Overview

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide147and destination address objects here. The next-hop is the VPN connection that you created

Page 55

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1486.5 How to Configure User-aware Access ControlYou can configure many policies and securit

Page 56

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1492 Enter the name of the group that is used in Table 31 on page 148. In this example, it i

Page 57 - CHAPTER 2

Table of ContentsZyWALL USG 100/200 Series User’s Guide157.2.4 The VPN Status Screen ...

Page 58

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide150Figure 87 Object > Auth. method > Add4 Click System > WWW. In the Authenticatio

Page 59 - 2.2 Packet Flow

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1511 Click AppPatrol. If application patrol and bandwidth management are not enabled, enable

Page 60 - 2.3 Applications

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide152Figure 93 AppPatrol > Common > http > Edit Default5 Click the Add icon in the p

Page 61

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide153Figure 95 Object > Schedule > Add (Recurring)3 Follow the steps in Section 6.5.4

Page 62

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide154Figure 97 Firewall > LAN1 to DMZ > Edit3 Click the Add icon at the top of the rule

Page 63 - 2.3.5 Device HA

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide155You do not have to change many of the ZyWALL’s settings from the defaults to set up this

Page 64

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide156Figure 101 Network > Interface > Trunk > WAN_TRUNK > Edit6.7 How to Configu

Page 65 - CHAPTER 3

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide157Figure 102 System > WWW3 In the Zone field select LAN1 and click OK. Figure 103 Sy

Page 66 - Figure 10 Login Screen

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide158Figure 104 System > WWW (First Example Admin Service Rule Configured)5 Set the Zone t

Page 67 - 3.3.1 Title Bar

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide159Figure 106 System > WWW (Second Example Admin Service Rule Configured)Now administra

Page 68 - 3.3.2 Navigation Panel

Table of ContentsZyWALL USG 100/200 Series User’s Guide1610.5.6 Interface Wizard: Summary (Non-WAN) ...

Page 69 - Chapter 3 Web Configurator

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1606.8.1 How to Turn On the ALGClick Network > ALG. Select Enable H.323 transformations a

Page 70

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide161Figure 110 Network > Virtual Server > Add6.8.3 How to Set Up a Firewall Rule For

Page 71

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide162Figure 112 Firewall > Add 4 Configure an address object for the ZyWALL’s 10.0.0.8 WAN

Page 72 - 3.3.4 Message Bar

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide163An Ethernet switch connects both ZyWALLs’ lan1 interfaces to LAN1. Whichever ZyWALL is fu

Page 73 - Figure 15 CLI Messages

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1642 Configure 192.168.1.3 as the Management IP and 255.255.255.0 as the Subnet Mask. Click O

Page 74

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide165Figure 119 Device HA > General: Master ZyWALL Example6.9.3 How to Configure the Bac

Page 75 - CHAPTER 4

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide166Figure 121 Device HA > Active-Passive Mode: Backup ZyWALL Example5 Click the General

Page 76

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide167Maintenance > File Manager > Configuration File screen to save copies of the ZyWALL

Page 77 - 4.3 Step 1 Internet Access

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide168Figure 125 Creating the Address Object for the wan2 Public IP Address 6.10.2 How to Con

Page 78

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide169The firewall allows traffic from the WAN zone to the DMZ zone by default so your configur

Page 79

Table of ContentsZyWALL USG 100/200 Series User’s Guide1712.4 Policy Routing Technical Reference ...

Page 80

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide170

Page 81

ZyWALL USG 100/200 Series User’s Guide171CHAPTER 7 Status7.1 OverviewUse the Status screens to check status information about the ZyWALL.7.1.1 Wha

Page 82

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide172Figure 127 Status The following table describes the labels in this screen. Table 32 Stat

Page 83

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide173Current Date/TimeThis field displays the current date and time in the ZyWALL. The format is

Page 84

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide174Signature VersionThis field displays the version number, date, and time of the current set of

Page 85

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide1757.2.1 The CPU Usage ScreenUse this screen to look at a chart of the ZyWALL’s recent CPU usa

Page 86

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide176Figure 128 Status > CPU UsageThe following table describes the labels in this screen. 7

Page 87

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide177Figure 129 Status > Memory UsageThe following table describes the labels in this screen

Page 88

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide178Figure 130 Status > Session UsageThe following table describes the labels in this screen

Page 89

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide179Figure 131 Status > VPN StatusThe following table describes the labels in this screen.

Page 90

Table of ContentsZyWALL USG 100/200 Series User’s Guide1817.1.2 What You Need to Know About HTTP Redirect ...

Page 91 - Device Registration

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide180The following table describes the labels in this screen. 7.2.6 The Port Statistics ScreenUse

Page 92

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide181The following table describes the labels in this screen. 7.2.7 The Port Statistics Graph Sc

Page 93

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide182Figure 134 Status > Port Statistics > Switch to Graphic View The following table de

Page 94 - 4.6 VPN Setup

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide183Figure 135 Status > Current UsersThe following table describes the labels in this scree

Page 95 - 4.7 VPN Wizards

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide184Cellular System This field displays the type of the network to which the ZyWALL is connected.

Page 96

ZyWALL USG 100/200 Series User’s Guide185CHAPTER 8 Registration8.1 OverviewUse the Licensing > Registration screens to register your ZyWALL and m

Page 97

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide186Subscription Services Available on the ZyWALLYou can have the ZyWALL use anti-virus, ID

Page 98

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide187Figure 137 Licensing > RegistrationThe following table describes the labels in th

Page 99

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide188" If the ZyWALL is registered already, this screen is read-only and indicates whet

Page 100 - 4.8.4 VPN Advanced Wizard

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide1898.3 The Service ScreenUse this screen to display the status of your service registrat

Page 101 - Chapter 4 Wizard Setup

Table of ContentsZyWALL USG 100/200 Series User’s Guide1920.4.1 The VPN Concentrator Add/Edit Screen ...

Page 102 - Chapter 4 Wizard Setup

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide190

Page 103

ZyWALL USG 100/200 Series User’s Guide191CHAPTER 9 Signature Update9.1 OverviewThis chapter shows you how to update the ZyWALL’s signature packages.

Page 104

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide192Figure 140 Licensing > Update >Anti-Virus The following table describes the

Page 105

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide1939.3 The IDP/AppPatrol Update ScreenClick Licensing > Update > IDP/AppPatrol

Page 106

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide194Figure 142 Downloading IDP SignaturesFigure 143 Successful IDP Signature Downlo

Page 107

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide195Figure 144 Licensing > Update > System Protect The following table describ

Page 108

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide196Figure 145 Downloading System Protect SignaturesFigure 146 Successful System Pr

Page 109 - CHAPTER 5

197PART IINetworkInterface (199)Trunks (269)Policy and Static Routes (277)Routing Protocols (287)Zones (299)DDNS (303)Virtual Servers (309)HTTP

Page 111

ZyWALL USG 100/200 Series User’s Guide199CHAPTER 10 Interface10.1 Interface OverviewUse the Interface screens to configure the ZyWALL’s interfaces.

Page 113 - 5.4.1 Feature

Table of ContentsZyWALL USG 100/200 Series User’s Guide20Chapter 25L2TP VPN...

Page 114 - 5.4.4 IPSec VPN

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide20010.1.2 What You Need to Know About InterfacesInterface CharacteristicsInterfaces general

Page 115 - 5.4.8 Device HA

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide201Trunks and the auxiliary interface have many characteristics that are specific to each t

Page 116 - 5.4.10 Policy Routes

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide202* - You cannot set up a PPPoE/PPTP interface, virtual Ethernet interface or virtual VLAN

Page 117 - 5.4.12 Firewall

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide203Figure 147 Network > Interface > Status Each field is described in the following

Page 118 - 5.4.15 IDP

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide204Status This field displays the current status of each interface. The possible values depe

Page 119 - 5.4.18 Anti-Spam

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide20510.3 The Port Role ScreenTo access this screen, click Network > Interface > Port

Page 120 - 5.4.21 ALG

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide206Each section in this screen is described below.10.4 The Ethernet Summary ScreenThis scre

Page 121 - 5.5 Objects

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide207Figure 149 Network > Interface > EthernetEach field is described in the followin

Page 122 - 5.6.2 File Manager

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide208" If you create IP address objects based on an interface’s IP address, subnet, or ga

Page 123 - 5.6.6 Diagnostics

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide209Figure 150 Network > Interface > Ethernet > Edit (Opt)

Page 124

Table of ContentsZyWALL USG 100/200 Series User’s Guide21Chapter 28Anti-Virus...

Page 125 - CHAPTER 6

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide210Each field is described in the table below. The OPT interface’s Edit > Configuration s

Page 126 - Chapter 6 Tutorials

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide211Ingress BandwidthThis is reserved for future use.Enter the maximum amount of traffic, in

Page 127 - Chapter 6 Tutorials

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide212More Settings/Less SettingsClick this button to display a greater or lesser number of con

Page 128

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide213Overwrite Default MAC AddressSelect this option to have the interface use a different MA

Page 129

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide21410.5 Interface WizardsYou can use the interface wizard (instead of the regular Ethernet

Page 130

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide215Figure 152 Interface Wizard: OPT Interface First Screen The following table descr

Page 131 - Figure 53 Status

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide216Figure 154 Interface Wizard: Non-WAN OPT Interface Setup The following table descr

Page 132

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide217Figure 155 Interface Wizard: WAN Interface Zone and IP Address Setup The following

Page 133

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide218The following table describes the labels in this screen. Table 56 Interface Wizard: WAN

Page 134

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide21910.5.6 Interface Wizard: Summary (Non-WAN)Use this screen to review the local interface

Page 135

Table of ContentsZyWALL USG 100/200 Series User’s Guide22Chapter 30 ADP ...

Page 136 - 6 Click Activate Now

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide220Figure 158 Interface Wizard: Summary WAN (PPTP Shown) The following table describe

Page 137

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide22110.6 The PPP Interfaces ScreenUse PPP interfaces (PPPoE/PPTP interfaces) to connect to

Page 138

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide22210.6.1 PPP Interface Edit ScreenThis screen lets you configure new or existing PPPoE/PPT

Page 139 - 5 Click Networks > Add

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide223Figure 161 Network > Interface > PPP > Edit > ConfigurationEach field is e

Page 140

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide224Description Enter a description of this interface. It is not used elsewhere. You can use

Page 141 - 2 Click Import

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide225Ingress BandwidthThis is reserved for future use.Enter the maximum amount of traffic, in

Page 142

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide22610.7 Cellular Configuration Screen (3G)3G (Third Generation) is a digital, packet-switch

Page 143

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide227" Install (or connect) a compatible 3G card to use a cellular connection. See Chapt

Page 144 - Figure 78 VPN Example

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide22810.7.1 Cellular Add/Edit ScreenTo change your 3G settings, click Network > Interface

Page 145

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide229The following table describes the labels in this screen.Table 63 Interface > Cellul

Page 146

Table of ContentsZyWALL USG 100/200 Series User’s Guide2333.2 Before You Begin ...

Page 147

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide230PIN Code This field displays with a GSM or HSDPA 3G card. A PIN (Personal Identification

Page 148

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide23110.8 Cellular Status ScreenTo check your 3G connection status, click Network > Inter

Page 149

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide232The following table describes the labels in this screen.Table 64 Interface > Cellula

Page 150

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide23310.9 WLAN Interface General ScreenThe following figure provides an example of a wireles

Page 151

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide234Figure 166 Network > Interface > WLAN The following table describes the general w

Page 152

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide23510.9.1 WLAN Add/Edit ScreenUse the strongest security that every wireless client in the

Page 153

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide236• WPA2-PSK and WPA-PSK do not employ user authentication and are known as the personal ve

Page 154 - Figure 99 Trunk Example

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide237Figure 167 Network > Interface > WLAN > Add (No Security)

Page 155

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide238The following table describes the general wireless LAN labels in this screen.Table 67 N

Page 156

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide239Egress BandwidthEnter the maximum amount of traffic, in kilobits per second, the ZyWALL

Page 157 - Figure 102 System > WWW

Table of ContentsZyWALL USG 100/200 Series User’s Guide2435.4.1 Force User Authentication Policy Add/Edit Screen ...

Page 158 - 6 Click Apply

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide240Lease time Specify how long each computer can use the information (especially the IP addr

Page 159

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide24110.9.2 WLAN Add/Edit Screen: WEP SecurityWEP provides a mechanism for encrypting data u

Page 160 - 6.8.1 How to Turn On the ALG

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide242Figure 169 Network > Interface > WLAN > Add (WEP Security) The following table

Page 161

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide243The following table describes the WPA-PSK/WPA2-PSK-related wireless LAN security labels

Page 162 - 6.9 How to Use Device HA

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide244The following table describes the WPA/WPA2-related wireless LAN security labels. Table 70

Page 163 - 6.9.1 Before You Start

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide24510.10 WLAN Interface MAC Filter ScreenThe MAC filter allows you to give specific wirele

Page 164

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide246If you set the filter to deny access and add the MAC address of a connected device, the Z

Page 165

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide24710.12 VLAN Interface ScreenA Virtual Local Area Network (VLAN) divides a physical netwo

Page 166

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide248Figure 176 Example: After VLANEach VLAN is a separate network with separate IP addresse

Page 167

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide249" Each VLAN interface is created on top of only one Ethernet interface.Otherwise, V

Page 168

Table of ContentsZyWALL USG 100/200 Series User’s Guide2539.3 Active Directory or LDAP Group Summary Screen ...

Page 169

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide25010.12.2 Configuring the VLAN Add/Edit ScreenThis screen lets you configure IP address as

Page 170

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide251Figure 178 Network > Interface > VLAN > EditEach field is explained in the fo

Page 171 - CHAPTER 7

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide252Interface Name This field is read-only if you are editing an existing VLAN interface. Ent

Page 172 - Table 32 Status

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide253Connectivity Check The interface can regularly check the connection to the gateway you s

Page 173 - Table 32 Status (continued)

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide254IP Pool Start AddressEnter the IP address from which the ZyWALL begins allocating IP addr

Page 174

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide25510.13 Bridge Interface ScreenA bridge creates a connection between two or more network

Page 175 - 7.2.1 The CPU Usage Screen

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide256Bridge Interface OverviewA bridge interface creates a software bridge between the members

Page 176

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide25710.13.2 Configuring the Bridge Add/Edit ScreenThis screen lets you configure IP address

Page 177

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide258Figure 182 Network > Interface > Bridge > Add

Page 178 - 7.2.4 The VPN Status Screen

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide259Each field is described in the table below.Table 80 Network > Interface > Bridge

Page 179 - 7.2.5 The DHCP Table Screen

Table of ContentsZyWALL USG 100/200 Series User’s Guide26Chapter 43 System ...

Page 180

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide260Interface ParametersEgress BandwidthEnter the maximum amount of traffic, in kilobits per

Page 181

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide26110.14 Auxiliary Interface ScreenUse the auxiliary interface as a backup WAN interface o

Page 182

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide262" You must connect an external modem to use the auxiliary port.The ZyWALL uses the a

Page 183

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide26310.15 Virtual Interface ScreenUse virtual interfaces to tell the ZyWALL where to route

Page 184

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide264Like other interfaces, virtual interfaces have an IP address, subnet mask, and gateway us

Page 185 - CHAPTER 8

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide26510.16 Interface Technical ReferenceHere is more detailed information about interfaces o

Page 186 - 8.2 The Registration Screen

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide266In the example above, if the ZyWALL gets a packet with a destination address of 5.5.5.5,

Page 187 - Chapter 8 Registration

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide267In DHCP, every network has at least one DHCP server. When a computer (a DHCP client) joi

Page 188 - Chapter 8 Registration

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide268WINSWINS (Windows Internet Naming Service) is a Windows implementation of NetBIOS Name Se

Page 189 - 8.3 The Service Screen

ZyWALL USG 100/200 Series User’s Guide269CHAPTER 11 Trunks11.1 OverviewUse trunks for WAN traffic load balancing to increase overall network through

Page 190

Table of ContentsZyWALL USG 100/200 Series User’s Guide2743.12 Vantage CNM ...

Page 191 - CHAPTER 9

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide270• If that interface’s connection goes down, the ZyWALL can still send its traffic through an

Page 192 - Chapter 9 Signature Update

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide271Least Load First The least load first algorithm uses the current (or recent) outbound bandw

Page 193 - Chapter 9 Signature Update

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide272Figure 189 Weighted Round Robin Algorithm ExampleSpilloverThe spillover load balancing alg

Page 194

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide273Figure 191 Network > Interface > Trunk The following table describes the items in t

Page 195

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide274Figure 192 Network > Interface > Trunk > EditEach field is described in the table

Page 196

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide27511.3 Trunk Technical ReferenceRound Robin Load Balancing AlgorithmRound Robin scheduling s

Page 197

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide276

Page 198

ZyWALL USG 100/200 Series User’s Guide277CHAPTER 12 Policy and Static Routes12.1 Policy and Static Routes OverviewUse policy routes and static route

Page 199 - CHAPTER 10

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide27812.1.1 What You Can Do in the Policy and Static Route Screens•Use the Pol

Page 200 - Chapter 10 Interface

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide279Policy Routes Versus Static Routes• Policy routes are more flexible than

Page 201 - Chapter 10 Interface

Table of ContentsZyWALL USG 100/200 Series User’s Guide28Chapter 48Reboot...

Page 202

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide280The following table describes the labels in this screen. Table 89 Netwo

Page 203

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide28112.2.1 Policy Route Edit ScreenClick Network > Routing to open the Po

Page 204

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide282Schedule Select a schedule or select Create Object to configure a new one

Page 205 - 10.3 The Port Role Screen

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide28312.3 IP Static Route ScreenClick Network > Routing > Static Route

Page 206

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide284Figure 196 Network > Routing > Static RouteThe following table des

Page 207

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide28512.4 Policy Routing Technical ReferenceHere is more detailed information

Page 208

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide286Incoming service: Game (UDP: 1234)Trigger service: Game-1 (UDP: 5670-5678)

Page 209

ZyWALL USG 100/200 Series User’s Guide287CHAPTER 13 Routing Protocols13.1 Routing Protocols OverviewRouting protocols give the ZyWALL routing inform

Page 210

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide28813.2 The RIP ScreenRIP (Routing Information Protocol, RFC 1058 and RFC 1389) all

Page 211

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide28913.3 The OSPF ScreenOSPF (Open Shortest Path First, RFC 2328) is a link-state p

Page 212

List of FiguresZyWALL USG 100/200 Series User’s Guide29List of FiguresFigure 1 ZyWALL USG 200 Front Panel ...

Page 213

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide290• A normal area is a group of adjacent networks. A normal area has routing inform

Page 214 - 10.5 Interface Wizards

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide291• An Area Border Router (ABR) connects two or more areas. It is a member of all

Page 215

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide292Figure 202 OSPF: Virtual LinkIn this example, area 100 does not have a direct c

Page 216

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide293The following table describes the labels in this screen. See Section 13.3.2 on p

Page 217

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide294Figure 204 Network > Routing > OSPF > EditThe following table describe

Page 218

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide29513.4 Routing Protocol Technical ReferenceHere is more detailed information abou

Page 219

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide296• The packet’s message-digest is the same as the one the ZyWALL calculates using

Page 220

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide297

Page 221

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide298

Page 222

ZyWALL USG 100/200 Series User’s Guide299CHAPTER 14 Zones14.1 Zones OverviewSet up zones to configure network security and network policies in the

Page 223

About This User's GuideZyWALL USG 100/200 Series User’s Guide3About This User's GuideIntended AudienceThis manual is intended for people w

Page 224

List of FiguresZyWALL USG 100/200 Series User’s Guide30Figure 39 VPN Advanced Wizard: Step 2 ...

Page 225

Chapter 14 ZonesZyWALL USG 100/200 Series User’s Guide30014.1.2 What You Need to Know About ZonesEffects of Zones on Different Types of TrafficZones

Page 226

Chapter 14 ZonesZyWALL USG 100/200 Series User’s Guide301Figure 206 Network > Zone The following table describes the labels in this screen.

Page 227

Chapter 14 ZonesZyWALL USG 100/200 Series User’s Guide302Member List Available Interface lists the interfaces that do not belong to any zone. The word

Page 228

ZyWALL USG 100/200 Series User’s Guide303CHAPTER 15 DDNS15.1 DDNS OverviewDynamic DNS (DDNS) services let you use a domain name with a dynamic IP a

Page 229

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide304" Record your DDNS account’s user name, password, and domain name to use to configure the

Page 230

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide30515.2.1 The Dynamic DNS Add/Edit ScreenThe DDNS Add/Edit screen allows you to add a domain na

Page 231 - 10.8 Cellular Status Screen

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide306The following table describes the labels in this screen. Table 102 Network > DDNS > Ad

Page 232

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide30715.3 The DDNS Status ScreenThe DDNS Status screen shows the status of the ZyWALL’s DDNS doma

Page 233

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide308Figure 210 Network > DDNS > Status The following table describes the labels in

Page 234

ZyWALL USG 100/200 Series User’s Guide309CHAPTER 16 Virtual Servers16.1 Virtual Servers OverviewVirtual servers are computers on a private network b

Page 235 - 10.9.1 WLAN Add/Edit Screen

List of FiguresZyWALL USG 100/200 Series User’s Guide31Figure 82 Network > Routing > Policy Route ...

Page 236

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide310Finding Out More• See Section 5.4.19 on page 119 for related information on these s

Page 237

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide31116.2.1 The Virtual Server Add/Edit ScreenThe Virtual Server Add/Edit screen lets

Page 238

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide312Original IP Use the drop-down list box to indicate which destination IP address thi

Page 239

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide31316.3 NAT 1:1 and NAT Loopback ExamplesThe following sections provide examples of

Page 240

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide314NAT 1:1 Address ObjectsFirst create two address objects for the private and public

Page 241

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide315Figure 217 NAT 1:1 Example Virtual ServerThe wan2 interface has a different IP a

Page 242

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide316Figure 219 NAT 1:1 Example Policy RouteClick Network > Routing > Policy Rou

Page 243

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide317Figure 221 Create a Firewall RuleNAT Loopback ExampleThe NAT 1:1 Example on page

Page 244

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide318NAT Loopback Virtual ServerWhen a LAN1 user sends SMTP traffic to IP address 1.1.1.

Page 245

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide319NAT Loopback Policy RouteWithout a NAT loopback policy route, the LAN1 user SMTP t

Page 246

List of FiguresZyWALL USG 100/200 Series User’s Guide32Figure 125 Creating the Address Object for the wan2 Public IP Address ...

Page 247 - 10.12 VLAN Interface Screen

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide320Figure 227 Create a Policy RouteNow the LAN1 SMTP server replies to the ZyWALL’s

Page 248

ZyWALL USG 100/200 Series User’s Guide321CHAPTER 17 HTTP Redirect17.1 OverviewHTTP redirect forwards the client’s HTTP request (except HTTP traffic

Page 249

Chapter 17 HTTP RedirectZyWALL USG 100/200 Series User’s Guide32217.1.2 What You Need to Know About HTTP RedirectWeb Proxy ServerA proxy server helps

Page 250

Chapter 17 HTTP RedirectZyWALL USG 100/200 Series User’s Guide323" You can configure up to one HTTP redirect rule for each (incoming) interface.

Page 251

Chapter 17 HTTP RedirectZyWALL USG 100/200 Series User’s Guide324The following table describes the labels in this screen. Table 107 Network > HTT

Page 252

ZyWALL USG 100/200 Series User’s Guide325CHAPTER 18 ALG18.1 ALG OverviewApplication Layer Gateway (ALG) allows the following applications to operate

Page 253

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide32618.1.2 What You Need to Know About ALGApplication Layer Gateway (ALG), NAT and FirewallThe ZyW

Page 254

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide327• The SIP ALG allows UDP packets with a specified port destination to pass through.• The ZyWAL

Page 255 - Figure 180 Bridge Example

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide328For example, you configure firewall and virtual server rules to allow LAN IP address A to recei

Page 256

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide329Figure 236 Network > ALG The following table describes the labels in this screen. Table

Page 257

List of FiguresZyWALL USG 100/200 Series User’s Guide33Figure 168 Network > Interface > Ethernet > Edit > Edit static DHCP table ...

Page 258

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide33018.3 ALG Technical ReferenceHere is more detailed information about the Application Layer Gate

Page 259

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide331H.323H.323 is a standard teleconferencing protocol suite that provides audio, data and video c

Page 260

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide332

Page 261

333PART IIIFirewallFirewall (335)

Page 263 - ATZ is the most

ZyWALL USG 100/200 Series User’s Guide335CHAPTER 19 Firewall19.1 OverviewUse the firewall to block or allow services that use static port numbers.

Page 264

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide33619.1.2 What You Need to Know About the FirewallStateful InspectionThe ZyWALL has a statef

Page 265

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide337To-ZyWALL Rules Rules with ZyWALL as the To Zone apply to traffic going to the ZyWALL its

Page 266

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide338Firewall and VPN TrafficAfter you create a VPN tunnel and add it to a zone, you can set th

Page 267

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide339• The second row is the firewall’s default policy that allows all traffic from the LAN to

Page 268

List of FiguresZyWALL USG 100/200 Series User’s Guide34Figure 211 Multiple Servers Behind NAT Example ...

Page 269 - CHAPTER 11

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide340• The third row is (still) the firewall’s default policy of allowing all traffic from LAN1

Page 270 - Figure 187 Link Sticking

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide341Figure 240 Firewall Example: Select the Traveling Direction of Traffic2 Select From WA

Page 271 - Chapter 11 Trunks

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide342Figure 243 Firewall Example: Create a Service Object6 Enter the name of the firewall rul

Page 272

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide34319.2 The Firewall ScreenAsymmetrical RoutesIf an alternate gateway on LAN1 has an IP add

Page 273

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide344• Besides configuring the firewall, you also need to configure virtual servers (NAT port f

Page 274

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide345From ZoneTo ZoneThis is the direction of travel of packets. Select from which zone the pa

Page 275

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide34619.2.2 The Firewall Edit ScreenIn the Firewall screen, click the Edit or Add icon to disp

Page 276

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide347Description Enter a descriptive name of up to 60 printable ASCII characters for the firew

Page 277 - CHAPTER 12

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide348

Page 278

349PART IVVPNIPSec VPN (351)SSL VPN (385)SSL User Screens (395)SSL User Application Screens (401)SSL User File Sharing (403)L2TP VPN (409)L2TP V

Page 279 - 12.2 Policy Route Screen

List of FiguresZyWALL USG 100/200 Series User’s Guide35Figure 254 VPN > IPSec VPN > VPN Gateway ...

Page 281

ZyWALL USG 100/200 Series User’s Guide351CHAPTER 20 IPSec VPN20.1 IPSec VPN OverviewA virtual private network (VPN) provides secure communications b

Page 282

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide352• Use the VPN Concentrator screens (see Section 20.4 on page 369) to combine several IPSe

Page 283 - 12.3 IP Static Route Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide353You should set up the following features before you set up the VPN tunnel.• In any VPN c

Page 284

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide354Each field is discussed in the following table. See Section 20.2.2 on page 360 and Sectio

Page 285 - Port Triggering

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide35520.2.1 The VPN Connection Add/Edit (IKE) ScreenThe VPN Connection Add/Edit Gateway scre

Page 286 - Maximize Bandwidth Usage

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide356Figure 252 VPN > IPSec VPN > VPN Connection > Edit (IKE)

Page 287 - CHAPTER 13

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide357Each field is described in the following table. Table 116 VPN > IPSec VPN > VPN

Page 288 - 13.2 The RIP Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide358SA Life Time Type the maximum number of seconds the IPSec SA can last. Shorter life time

Page 289 - 13.3 The OSPF Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide359Related SettingsAdd this VPN connection to IPSec_VPN zone.Select this check box to add t

Page 290 - Chapter 13 Routing Protocols

List of FiguresZyWALL USG 100/200 Series User’s Guide36Figure 297 VPN > L2TP VPN ...

Page 291 - Chapter 13 Routing Protocols

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide36020.2.2 The VPN Connection Add/Edit Manual Key Screen The VPN Connection Add/Edit Manual

Page 292

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide361Figure 253 VPN > IPSec VPN > VPN Connection > Manual Key > EditThis table

Page 293

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide362Encapsulation ModeSelect which type of encapsulation the IPSec SA uses. Choices areTunnel

Page 294

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide36320.3 The VPN Gateway ScreenThe VPN Gateway summary screen displays the IPSec VPN gatewa

Page 295

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide36420.3.1 The VPN Gateway Add/Edit ScreenThe VPN Gateway Add/Edit screen allows you to crea

Page 296

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide365Figure 255 VPN > IPSec VPN > VPN Gateway > EditEach field is described in the

Page 297

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide366Peer Gateway AddressSelect how the IP address of the remote IPSec router in the IKE SA is

Page 298

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide367Peer ID Type Select which type of identification is used to identify the remote IPSec ro

Page 299 - CHAPTER 14

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide368Encryption Select which key size and encryption algorithm to use in the IKE SA. Choices a

Page 300 - 14.2 The Zone Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide36920.4 The VPN Concentrator ScreenA VPN concentrator combines several IPSec VPN connectio

Page 301 - 14.2.1 The Zone Edit Screen

List of FiguresZyWALL USG 100/200 Series User’s Guide37Figure 340 IP Security Policy Properties: IP Filter List ...

Page 302 - Chapter 14 Zones

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide370Figure 257 VPN > IPSec VPN > ConcentratorEach field is discussed in the following

Page 303 - CHAPTER 15

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide37120.5 The SA Monitor Screen You can use the SA Monitor screen to display and to manage a

Page 304 - 15.2 The DDNS Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide372Figure 260 VPN > IPSec VPN > SA MonitorEach field is described in the following t

Page 305 - Chapter 15 DDNS

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide37320.6 IPSec VPN Background InformationHere is some more detailed IPSec VPN background in

Page 306 - DDNS server

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide374The ZyWALL sends one or more proposals to the remote IPSec router. (In some devices, you

Page 307 - 15.3 The DDNS Status Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide375DH public-key cryptography is based on DH key groups. Each key group is a fixed number o

Page 308 - Chapter 15 DDNS

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide376Router identity consists of ID type and content. The ID type can be domain name, IP addre

Page 309 - CHAPTER 16

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide377Main mode takes six steps to establish an IKE SA.Steps 1 - 2: The ZyWALL sends its propo

Page 310 - Chapter 16 Virtual Servers

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide378Extended AuthenticationExtended authentication is often used when multiple IPSec routers

Page 311 - It can

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide379IPSec SA OverviewOnce the ZyWALL and remote IPSec router have established the IKE SA, th

Page 312

List of FiguresZyWALL USG 100/200 Series User’s Guide38Figure 383 Anti-X > IDP > Profile > Edit > IDP Service Group ...

Page 313 - NAT 1:1 Example

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide380These modes are illustrated below.In tunnel mode, the ZyWALL uses the active protocol to

Page 314 - NAT 1:1 Virtual Server

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide381IPSec SA using Manual KeysYou might set up an IPSec SA using manual keys when you want t

Page 315 - NAT 1:1 Policy Route

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide382Figure 266 VPN Example: NAT for Inbound and Outbound TrafficSource Address in Outbound

Page 316 - NAT 1:1 Firewall Rule

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide383You have to specify one or more rules when you set up this kind of NAT. The ZyWALL check

Page 317 - NAT Loopback Example

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide384

Page 318 - NAT Loopback Virtual Server

ZyWALL USG 100/200 Series User’s Guide385CHAPTER 21 SSL VPN21.1 OverviewUse SSL VPN to allow users to use a web browser for secure remote user login

Page 319 - NAT Loopback Policy Route

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide386Full Tunnel Mode In full tunnel mode, a virtual connection is created for remote users with

Page 320

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide387Finding Out More• See Section 5.4.5 on page 115 for related information on these screens.•

Page 321 - CHAPTER 17

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide388Figure 270 VPN > SSL VPN > Access Privilege > Add/Edit The following table desc

Page 322 - Chapter 17 HTTP Redirect

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide38921.3 The SSL Connection Monitor Screen The ZyWALL keeps track of the users who are curren

Page 323 - Chapter 17 HTTP Redirect

List of FiguresZyWALL USG 100/200 Series User’s Guide39Figure 426 Anti-X > Anti-Spam > Black/White List > White List ...

Page 324

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide390• Log out individual users and delete related session information. Once a user logs out, th

Page 325 - CHAPTER 18

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide391Figure 272 VPN > SSL VPN > Global Setting The following table describes the labels

Page 326 - Chapter 18 ALG

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide39221.4.1 How to Upload a Custom LogoFollow the steps below to upload a custom logo to displa

Page 327 - Chapter 18 ALG

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide393Figure 274 SSL VPN Client Portal Screen Example If the user account is not set up for SS

Page 328 - 18.2 The ALG Screen

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide394

Page 329 - Table 108 Network > ALG

ZyWALL USG 100/200 Series User’s Guide395CHAPTER 22 SSL User Screens22.1 OverviewThis chapter introduces the remote user SSL VPN screens. The follow

Page 330 - 18.3 ALG Technical Reference

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide396• Firefox 1.0 and above• Mozilla 1.7.3 and above• Sun’s Java (Java Runtime Environ

Page 331

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide397Figure 277 Login Security Screen 3 A login screen displays. Enter the user na

Page 332

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide398Figure 280 SecuExtender Progress 7 The Application screen displays showing the

Page 333 - PART III

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide399The following table describes the various parts of a remote user screen. 22.4 Bo

Page 334

About This User's GuideZyWALL USG 100/200 Series User’s Guide4Click the help icon in any screen for help in configuring that screen and supplemen

Page 335 - CHAPTER 19

List of FiguresZyWALL USG 100/200 Series User’s Guide40Figure 469 Object > AAA Server > RADIUS > Group > Add ...

Page 336 - Chapter 19 Firewall

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide400Figure 284 Logout: Connection Termination Progress

Page 337 - Chapter 19 Firewall

ZyWALL USG 100/200 Series User’s Guide401CHAPTER 23 SSL User Application Screens23.1 SSL User Application Screens OverviewUse the Application screen

Page 338

Chapter 23 SSL User Application ScreensZyWALL USG 100/200 Series User’s Guide402

Page 339

ZyWALL USG 100/200 Series User’s Guide403CHAPTER 24 SSL User File Sharing24.1 OverviewThe File Sharing screen lets you access files on a file server

Page 340

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide404Figure 286 File Sharing 24.3 Opening a File or FolderYou can open a file i

Page 341

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide4054 A list of files/folders displays. Click on a file to open it in a separate

Page 342

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide406Figure 289 File Sharing: Save a Word File 24.4 Creating a New FolderTo cr

Page 343 - 19.2 The Firewall Screen

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide407Figure 291 File Sharing: Rename A popup window displays. Specify the new n

Page 344 - Table 113 Firewall

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide40824.7 Uploading a FileFollow the steps below to upload a file to the file ser

Page 345

ZyWALL USG 100/200 Series User’s Guide409CHAPTER 25 L2TP VPN25.1 OverviewL2TP VPN lets remote users use the L2TP and IPSec client software included

Page 346

List of FiguresZyWALL USG 100/200 Series User’s Guide41Figure 512 SSL Client Authentication ...

Page 347

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide410IPSec Configuration Required for L2TP VPNYou must configure an IPSec VPN connection for L2

Page 348

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide411Finding Out More• See Section 5.4.6 on page 115 for related information on these screens.

Page 349

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide41225.3 L2TP VPN Session Monitor ScreenClick VPN > L2TP VPN > Session Monitor to open

Page 350

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide413Hostname This field displays the name of the computer that has this L2TP VPN connection w

Page 351 - CHAPTER 20

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide414

Page 352 - 20.1.3 Before You Begin

ZyWALL USG 100/200 Series User’s Guide415CHAPTER 26 L2TP VPN ExampleThis chapter shows how to create a basic L2TP VPN tunnel.26.1 L2TP VPN ExampleTh

Page 353 - Chapter 20 IPSec VPN

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide416Figure 300 VPN > IPSec VPN > VPN Gateway > Edit • Configure the My Addr

Page 354 - Chapter 20 IPSec VPN

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide417Figure 302 VPN > IPSec VPN > VPN Connection > Edit 2 Click the Policy

Page 355

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide41826.4 Configuring the L2TP VPN Settings Example1 Click VPN > L2TP VPN to open t

Page 356

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide419Figure 305 Routing > Add: L2TP VPN Example2 Configure the following.• Enable

Page 357

List of FiguresZyWALL USG 100/200 Series User’s Guide42Figure 555 WLAN Card Installation ...

Page 358

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide4202 Click Next in the Welcome screen.3 Select Connect to the network at my workplace

Page 359

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide421Figure 308 New Connection Wizard: Connection Name6 Select Do not dial the initi

Page 360

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide422Figure 310 New Connection Wizard: VPN Server Selection8 Click Finish.9 The Conne

Page 361

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide423Figure 312 Connect L2TP to ZyWALL: Security11 Select Optional encryption (conne

Page 362 - 1234567890XYZ for a DES

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide424Figure 314 L2TP to ZyWALL Properties > Security13 Select the Use pre-shared k

Page 363 - 20.3 The VPN Gateway Screen

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide425Figure 317 Connect L2TP to ZyWALL16 A window appears while the user name and pa

Page 364

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide4261 Click Start > Run. Type regedit and click OK.Figure 320 Starting the Regist

Page 365

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide427Figure 323 ProhibitIpSec DWORD Value6 Restart the computer and continue with th

Page 366

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide428Figure 326 Add > IP Security Policy Management > Finish4 Right-click IP Se

Page 367

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide429Figure 328 IP Security Policy: Name6 Clear the Activate the default response ru

Page 368

List of TablesZyWALL USG 100/200 Series User’s Guide43List of TablesTable 1 Front Panel LEDs ...

Page 369

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide4308 In the properties dialog box, click Add > Next.Figure 331 IP Security Polic

Page 370

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide431Figure 333 IP Security Policy Properties: Network Type11 Select Use this string

Page 371 - 20.5 The SA Monitor Screen

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide432Figure 335 IP Security Policy Properties: IP Filter List13 Type ZyWALL WAN_IP in

Page 372

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide433Figure 337 Filter Properties: Addressing15 Configure the following in the Filte

Page 373 - IKE SA Overview

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide434Figure 339 IP Security Policy Properties: IP Filter List17 Select Require Secur

Page 374

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide43526.6.2.3 Configure the Windows 2000 Network ConnectionAfter you have configured

Page 375 - Authentication

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide436Figure 344 New Connection Wizard: Destination Address4 Select For all users and

Page 376 - Additional Topics for IKE SA

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide4376 Click Properties.Figure 347 Connect L2TP to ZyWALL7 Click Security and select

Page 377 - Figure 264 VPN/NAT Example

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide438Figure 349 Connect L2TP to ZyWALL: Security > Advanced9 Click Networking and

Page 378

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide439Figure 351 Connect L2TP to ZyWALL11 A ZyWALL-L2TP icon displays in your system

Page 379 - IPSec SA Overview

List of TablesZyWALL USG 100/200 Series User’s Guide44Table 39 Status > Port Statistics > Switch to Graphic View ...

Page 380

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide440

Page 381

441PART VApplication PatrolApplication Patrol (443)

Page 383

ZyWALL USG 100/200 Series User’s Guide443CHAPTER 27 Application Patrol27.1 OverviewApplication patrol provides a convenient way to manage the use of

Page 384

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide44427.1.2 What You Need to Know About Application Patrol" The ZyWALL checks

Page 385 - CHAPTER 21

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide445The application patrol bandwidth management is more flexible and powerful than

Page 386 - Table 125 Objects

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide446• Inbound traffic is limited to 500 kbs. The connection initiator is on LAN1 so

Page 387 - Chapter 21 SSL VPN

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide447Figure 356 Bandwidth Management BehaviorConfigured Rate EffectIn the followin

Page 388

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide448Priority and Over Allotment of Bandwidth EffectServer A has a configured rate th

Page 389

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide449Figure 357 Application Patrol Bandwidth Management Example27.1.3.1 Setting t

Page 390

List of TablesZyWALL USG 100/200 Series User’s Guide45Table 82 Network > Interface > Bridge > Add ...

Page 391

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide450Figure 358 SIP Any to WAN Bandwidth Management Example27.1.3.3 SIP WAN to Any

Page 392

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide451Figure 360 FTP WAN to DMZ Bandwidth Management Example27.1.3.6 FTP LAN to DM

Page 393

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide452" You must register for the IDP/AppPatrol signature service (at least the t

Page 394

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide45327.3 Application Patrol ApplicationsUse the application patrol Common, Instant

Page 395 - CHAPTER 22

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide45427.3.1 The Application Patrol Edit ScreenUse this screen to edit the settings f

Page 396 - 22.2 Remote User Login

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide455Service Port This is available if the Classification is Service Ports. You can

Page 397 - Figure 278 Login Screen

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide45627.3.2 The Application Patrol Policy Edit Screen The Application Policy Edit sc

Page 398 - Chapter 22 SSL User Screens

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide457Schedule Select a schedule that defines when the policy applies or select Creat

Page 399 - 22.4 Bookmarking the ZyWALL

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide45827.4 The Other Applications ScreenSometimes, the ZyWALL cannot identify the app

Page 400

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide459Figure 366 AppPatrol > OtherThe following table describes the labels in th

Page 401 - CHAPTER 23

List of TablesZyWALL USG 100/200 Series User’s Guide46Table 125 Objects ...

Page 402

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide46027.4.1 The Other Applications Add/Edit ScreenThe Other Configuration Add/Edit s

Page 403 - CHAPTER 24

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide461Figure 367 AppPatrol > Other > EditThe following table describes the la

Page 404 - Figure 286 File Sharing

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide46227.5 Application Patrol StatisticsThis screen displays a bandwidth usage graph

Page 405 - 24.3.2 Saving a File

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide463Figure 368 AppPatrol > Statistics: General SetupThe following table descri

Page 406 - 24.4 Creating a New Folder

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide464• Different colors represent different protocols.27.5.3 Application Patrol Sta

Page 407

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide465Inbound Kbps This is the incoming bandwidth usage for traffic that matched this

Page 408 - 24.7 Uploading a File

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide466

Page 409 - CHAPTER 25

467PART VIAnti-XAnti-Virus (469)IDP (483)ADP (513)Content Filtering (531)Content Filter Reports (551)Anti-Spam (559)

Page 411 - 25.2 L2TP VPN Screen

ZyWALL USG 100/200 Series User’s Guide469CHAPTER 28 Anti-Virus28.1 OverviewUse the ZyWALL’s anti-virus feature to protect your connected network fro

Page 412

List of TablesZyWALL USG 100/200 Series User’s Guide47Table 168 ADP > Profile > Traffic Anomaly ...

Page 413 - Chapter 25 L2TP VPN

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide47028.1.2 What You Need to Know About Anti-VirusAnti-Virus EnginesSubscribe to signature f

Page 414

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide471" Since the ZyWALL erases the infected portion of the file before sending it, you

Page 415 - CHAPTER 26

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide472Figure 372 Anti-X > Anti-Virus > General The following table describes the label

Page 416 - Chapter 26 L2TP VPN Example

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide47328.2.1 Anti-Virus Policy Add or Edit ScreenClick the Add or Edit icon in the Anti-X &g

Page 417 - Chapter 26 L2TP VPN Example

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide474Figure 373 Anti-X > Anti-Virus > General > Add The following table describes

Page 418

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide47528.3 Anti-Virus Black ListClick Anti-X > Anti-Virus > Black/White List to displa

Page 419

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide476Figure 374 Anti-X > Anti-Virus > Black/White List > Black ListThe following t

Page 420

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide477Figure 375 Anti-X > Anti-Virus > Black/White List > Black List (or White Lis

Page 421

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide478Figure 376 Anti-X > Anti-Virus > Black/White List > White List The following

Page 422 - 172.16.1.2

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide479Figure 377 Anti-X > Anti-Virus > Signature: Search by SeverityThe following tab

Page 423 - 12 Click IPSec Settings

List of TablesZyWALL USG 100/200 Series User’s Guide48Table 211 Object > AAA Server > Active Directory (or LDAP) > Default ...

Page 424 - Click OK

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide48028.7 Anti-Virus Technical ReferenceTypes of Computer Viruses The following table descri

Page 425

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide481• HAV scanners are slow in stopping virus threats through real-time traffic (such as fr

Page 426 - Figure 322 New DWORD Value

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide482

Page 427 - Figure 324 Run mmc

ZyWALL USG 100/200 Series User’s Guide483CHAPTER 29 IDP29.1 OverviewThis chapter introduces packet inspection IDP (Intrusion, Detection and Prevent

Page 428

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide484" You can only apply one IDP profile to one traffic flow.Base IDP ProfilesBase IDP profile

Page 429

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide485Figure 378 Anti-X > IDP > GeneralThe following table describes the screens in this scr

Page 430

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide48629.2.1 Configuring IDP PoliciesClick Anti-X > IDP > General and then an Add or Edit icon

Page 431 - 12 Click Add

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide487Figure 379 Anti-X > IDP > General > AddThe following table describes the screens in

Page 432

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide488Figure 380 Base ProfilesThe following table describes this screen. 29.4 The Profile Summary

Page 433

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide489Figure 381 Anti-X > IDP > ProfileThe following table describes the fields in this scre

Page 434

List of TablesZyWALL USG 100/200 Series User’s Guide49Table 254 Maintenance > Log > Log Setting ...

Page 435

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide4903 Type a new profile name4 Enable or disable individual signatures.5 Edit the default log optio

Page 436

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide491Figure 382 Anti-X > IDP > Profile > Edit : Group View

Page 437 - 6 Click Properties

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide492The following table describes the fields in this screen. Table 156 Anti-X > IDP > Prof

Page 438

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide49329.6.2 Policy TypesThis section describes IDP policy types, also known as attack types, as ca

Page 439

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide49429.6.3 IDP Service GroupsAn IDP service group is a set of related packet inspection signatures

Page 440

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide495The following figure shows the WEB_PHP service group that contains signatures related to attac

Page 441 - Application Patrol

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide496Figure 384 Anti-X > IDP > Profile: Query ViewThe following table describes the fields i

Page 442

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide49729.6.5 Query ExampleThis example shows a search with these criteria:• Severity: severe and hi

Page 443 - CHAPTER 27

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide498Figure 386 Query Example Search Results29.7 Introducing IDP Custom Signatures Create custom

Page 444 - Chapter 27 Application Patrol

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide499Figure 387 IP v4 Packet Headers The header fields are discussed below: Table 160 IP v4 Pa

Page 445

Document ConventionsZyWALL USG 100/200 Series User’s Guide5Document ConventionsWarnings and NotesThese are how warnings and notes are shown in this U

Page 446

List of TablesZyWALL USG 100/200 Series User’s Guide50Table 297 Device HA Logs ...

Page 447

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide50029.8 Configuring Custom SignaturesSelect Anti-X > IDP > Custom Signatures. The first scr

Page 448

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide501The following table describes the fields in this screen. 29.8.1 Creating or Editing a Custom

Page 449

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide502Figure 389 Anti-X > IDP > Custom Signatures > Add/Edit

Page 450

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide503The following table describes the fields in this screen. Table 162 Anti-X > IDP > Cust

Page 451

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide504IP Options IP options is a variable-length list of IP options for a datagram that define IP Sec

Page 452

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide50529.8.2 Custom Signature ExampleBefore creating a custom signature, you must first clearly und

Page 453

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide50629.8.2.2 Analyze PacketsThen use a packet sniffer such as TCPdump or Ethereal to investigate s

Page 454 - Table 139 Application Edit

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide507Figure 393 Example Custom Signature

Page 455

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide50829.8.3 Applying Custom SignaturesAfter you create your custom signature, it becomes available

Page 456

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide509Figure 395 Custom Signature Log29.9 IDP Technical ReferenceThis section contains some backg

Page 457

51PART IGetting StartedIntroducing the ZyWALL (53)Features and Applications (57)Web Configurator (65)Configuration Basics (109)Tutorials (125)Sta

Page 458

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide510The rule header contains the rule's:• Action•Protocol• Source and destination IP addresses

Page 459

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide511" Not all Snort functionality is supported in the ZyWALL.

Page 460

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide512

Page 461

ZyWALL USG 100/200 Series User’s Guide513CHAPTER 30 ADP30.1 OverviewThis chapter introduces ADP (Anomaly Detection and Prevention), anomaly profile

Page 462

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide514ADP ProfileAn ADP profile is a set of traffic anomaly rules and protocol anomaly rules that you

Page 463

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide515The following table describes the screens in this screen. 30.2.1 Configuring ADP PoliciesClic

Page 464

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide516The following table describes the screens in this screen. 30.3 The Profile Summary ScreenUse t

Page 465

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide517These are the default base profiles at the time of writing. 30.3.2 Configuring The ADP Profil

Page 466

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide518ADP profiles consist of traffic anomaly profiles and protocol anomaly profiles. To create a new

Page 467

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide519Figure 400 Profiles: Traffic Anomaly

Page 469 - CHAPTER 28

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide520The following table describes the fields in this screen. 30.3.5 Protocol Anomaly Profiles Pro

Page 470 - Chapter 28 Anti-Virus

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide521Protocol anomaly rules may be updated when you upload new firmware.30.3.6 Protocol Anomaly Co

Page 471 - 28.1.3 Before You Begin

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide522Figure 401 Profiles: Protocol Anomaly

Page 472

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide523The following table describes the fields in this screen. 30.4 Technical ReferenceThis sectio

Page 473 - Chapter 28 Anti-Virus

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide524Many connection attempts to different ports (services) may indicate a port scan. These are some

Page 474

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide525Flood DetectionFlood attacks saturate a network with useless data, use up all available bandwi

Page 475 - 28.3 Anti-Virus Black List

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide526Figure 403 TCP Three-Way HandshakeA SYN flood attack is when an attacker sends a series of SY

Page 476

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide527Protocol Anomaly Background InformationThe following sections may help you configure the proto

Page 477 - 28.5 Anti-Virus White List

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide528OVERSIZE-CHUNK-ENCODING ATTACKThis rule is an anomaly detector for abnormally large chunk sizes

Page 478 - 28.6 Signature Searching

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide529TRUNCATED-HEADER ATTACKThis is when a UDP packet is sent which has a UDP datagram length of le

Page 479

ZyWALL USG 100/200 Series User’s Guide53CHAPTER 1 Introducing the ZyWALLThis chapter gives an overview of the ZyWALL. It explains the front panel por

Page 480

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide530

Page 481

ZyWALL USG 100/200 Series User’s Guide531CHAPTER 31 Content Filtering31.1 OverviewUse the content filtering feature to control access to specific we

Page 482

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide532The ZyWALL can disable web proxies and block web features such as ActiveX control

Page 483 - CHAPTER 29

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide53331.2 Content Filter General ScreenClick Anti-X > Content Filter > General

Page 484 - 29.2 The IDP General Screen

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide534Filter Profile This column displays the name of the content filter profile that e

Page 485 - Chapter 29 IDP

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide53531.3 Content Filter Policy Add or Edit ScreenClick Anti-X > Content Filter &

Page 486 - Chapter 29 IDP

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide53631.4 Content Filter Profile Screen Click Anti-X > Content Filter > Filter

Page 487 - 29.3.1 Base Profiles

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide5371 Log into myZyXEL.com and click your device’s link to open it’s Service Managem

Page 488 - • Delete an existing profile

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide538Unrated Web Pages Select Block to prevent users from accessing web pages that the

Page 489 - 29.5 Creating New Profiles

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide539Alcohol/Tobacco Selecting this category excludes pages that promote or offer the

Page 490

Chapter 1 Introducing the ZyWALLZyWALL USG 100/200 Series User’s Guide54Figure 2 ZyWALL USG 100 Front PanelThe following table describes the LEDs.1.

Page 491

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide540Alternative Spirituality/OccultSelecting this category excludes pages that promot

Page 492

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide541Computers/Internet Selecting this category excludes pages that sponsor or provid

Page 493 - 29.6.2 Policy Types

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide542Religion Selecting this category excludes pages that promote and provide informat

Page 494 - 29.6.3 IDP Service Groups

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide54331.6 Content Filter Customization Screen Click Anti-X > Content Filter >

Page 495

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide544Figure 409 Anti-X > Content Filter > Filter Profile > Customization Th

Page 496

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide545Java Java is a programming language and development environment for building dow

Page 497 - 29.6.5 Query Example

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide54631.7 Content Filter Cache ScreenClick Anti-X > Content Filter > Cache to d

Page 498 - 29.7.1 IP Packet Header

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide547Figure 410 Anti-X > Content Filter > Cache The following table describes

Page 499

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide54831.8 Content Filter Technical ReferenceThis section provides content filtering b

Page 500

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide5493 Use the Content Filter Cache screen to configure how long a web site address r

Page 501

Chapter 1 Introducing the ZyWALLZyWALL USG 100/200 Series User’s Guide55Figure 3 Managing the ZyWALL: Web ConfiguratorCommand-Line Interface (CLI)T

Page 502

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide550

Page 503 - number. Select

ZyWALL USG 100/200 Series User’s Guide551CHAPTER 32 Content Filter Reports32.1 OverviewYou can view content filtering reports after you have activat

Page 504

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide5523 A welcome screen displays. Click your ZyWALL’s model name and/or MAC addre

Page 505

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide5535 Enter your ZyXEL device's MAC address (in lower case) in the Name fi

Page 506

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide554Figure 417 Blue Coat: Report Home9 Select a time period in the Date Range

Page 507

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide555Figure 418 Global Report Screen Example11 You can click a category in the

Page 508

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide556Figure 419 Requested URLs Example32.3 Web Site SubmissionYou may find tha

Page 509 - 29.9 IDP Technical Reference

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide557Figure 420 Web Page Review Process Screen3 Type the web site’s URL in the

Page 510 - fragoffset

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide558

Page 511

ZyWALL USG 100/200 Series User’s Guide559CHAPTER 33 Anti-Spam33.1 OverviewThe anti-spam feature can mark or discard spam (unsolicited commercial or

Page 512

Chapter 1 Introducing the ZyWALLZyWALL USG 100/200 Series User’s Guide56" It is recommended you use the shutdown command before turning off the Z

Page 513 - CHAPTER 30

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide560matches a black list entry as spam and immediately takes the configured action for dealin

Page 514 - 30.2 The ADP General Screen

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide561Figure 421 DNSBL Example1 The ZyWALL checks the e-mail’s header for sender or relay IP

Page 515 - Chapter 30 ADP

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide562Figure 422 Anti-X > Anti-Spam > GeneralThe following table describes the labels i

Page 516 - 30.3.1 Base Profiles

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide56333.3.1 The Anti-Spam Policy Add or Edit ScreenClick the Add or Edit icon in the Anti-X

Page 517 - Table 166 Base Profiles

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide564The following table describes the labels in this screen.33.4 The Anti-Spam Black List Sc

Page 518 - Chapter 30 ADP

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide565Figure 424 Anti-X > Anti-Spam > Black/White List > Black ListThe following ta

Page 519

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide566Use this screen to configure an anti-spam black list entry to identify spam e-mail. You c

Page 520

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide56733.4.2 Regular Expressions in Black or White List EntriesThe following applies for a bl

Page 521

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide56833.6 The DNSBL Screen Click Anti-X > Anti-Spam > DNSBL to display the anti-spam DN

Page 522

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide569Figure 427 Anti-X > Anti-Spam > DNSBLThe following table describes the labels in

Page 523 - 30.4 Technical Reference

ZyWALL USG 100/200 Series User’s Guide57CHAPTER 2 Features and ApplicationsThis chapter introduces the main features and applications of the ZyWALL.2

Page 524

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide57033.6.1 The DNSBL Add/Edit ScreenClick the Add or Edit icon in the Anti-X > Anti-Spam

Page 525 - Flood Detection

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide571The following table describes the labels in this screen. 33.7 The Anti-Spam Status Scre

Page 526 - Figure 404 SYN Flood

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide572Avg. Response Time (sec)This is the average for how long it takes to receive a reply from

Page 527 - Section 30.3.5 on page 520)

573PART VIIDevice HADevice HA (575)

Page 529

ZyWALL USG 100/200 Series User’s Guide575CHAPTER 34 Device HA34.1 OverviewDevice HA lets a backup ZyWALL (B) automatically take over if a master Zy

Page 530

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide576Management AccessYou can configure a separate management IP address for each interface. Y

Page 531 - CHAPTER 31

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide577Figure 431 Device HA > GeneralThe following table describes the labels in this scre

Page 532 - 31.1.3 Before You Begin

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide57834.3 The Active-Passive Mode Screen Virtual RouterThe master and backup ZyWALL form a si

Page 533 - Chapter 31 Content Filtering

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide579Enable monitoring for the same interfaces on the master and backup ZyWALLs. Each monitor

Page 534 - Chapter 31 Content Filtering

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide58Intrusion Detection and Prevention (IDP)IDP (Intrusion Detection and Protec

Page 535

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide580Figure 435 Device HA > Active-Passive ModeThe following table describes the labels i

Page 536

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide581Authentication Select the authentication method the virtual router uses. Every interface

Page 537 - _), or dashes (-), but the

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide58234.4 Configuring an Active-Passive Mode Monitored InterfaceThe Device HA Active-Passive

Page 538

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide58334.5 The Legacy Mode ScreenVirtual Router Redundancy Protocol (VRRP)Legacy mode device

Page 539

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide584Figure 437 Device HA > Legacy ModeThe following table describes the labels in this s

Page 540

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide58534.7 The Legacy Mode Add/Edit ScreenUse the VRRP Group Add/Edit screen to add or edit V

Page 541

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide586Figure 438 Device HA > Legacy Mode > AddThe following table describes the labels

Page 542

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide58734.8 Device HA Technical ReferenceLegacy Mode ZyWALL VRRP ApplicationIn VRRP, a virtual

Page 543

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide588Figure 439 Example: VRRP, Normal OperationThe VR ID is not shown. In normal operation,

Page 544 - _), or dashes (-), but

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide589• System protect signatures• Certificates (My Certificates, and Trusted Certificates)Syn

Page 545

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide59Application PatrolApplication patrol (App. Patrol) manages instant messeng

Page 546

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide590

Page 547

591PART VIIIObjectsUser/Group (593)Addresses (607)Services (613)Schedules (619)AAA Server (625)Authentication Method (635)Certificates (639)SSL

Page 549

ZyWALL USG 100/200 Series User’s Guide593CHAPTER 35 User/Group35.1 OverviewThis chapter describes how to set up user accounts, user groups, and user

Page 550

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide594" The default admin account is always authenticated locally, regardless of the auth

Page 551 - CHAPTER 32

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide595" You cannot put access users and admin users in the same user group." You ca

Page 552

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide596Figure 441 Object > User/GroupThe following table describes the labels in this scre

Page 553 - Figure 415 Blue Coat: Login

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide597To access this screen, go to the User screen (see Section 35.2 on page 595), and click

Page 554

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide59835.3 User Group Summary ScreenUser groups consist of access users and other user groups

Page 555

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide599Figure 444 User/Group > Group > AddThe following table describes the labels in

Page 556 - 32.3 Web Site Submission

Document ConventionsZyWALL USG 100/200 Series User’s Guide6Icons Used in FiguresFigures in this User’s Guide may use the following generic icons. The

Page 557

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide602.2.2 Interface to Interface (To/From ZyWALL)To: Ethernet -> VLAN ->

Page 558

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide600Figure 445 Object > User/Group > SettingThe following table describes the labels

Page 559 - CHAPTER 33

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide601Maximum number per access accountThis field is effective when Limit ... for access acco

Page 560 - Chapter 33 Anti-Spam

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide60235.4.1 Force User Authentication Policy Add/Edit ScreenUse this screen to specify a con

Page 561 - 33.2 Before You Begin

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide603The following table describes the labels in this screen. 35.4.2 User Aware Login Exam

Page 562

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide604The following table describes the labels in this screen. 35.5 User /Group Technical Re

Page 563 - Chapter 33 Anti-Spam

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide605Creating a Large Number of Ext-User AccountsIf you plan to create a large number of Ext

Page 564

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide606

Page 565

ZyWALL USG 100/200 Series User’s Guide607CHAPTER 36 Addresses36.1 OverviewAddress objects can represent a single IP address or a range of IP addres

Page 566

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide608Figure 450 Object > Address > AddressThe following table describes the labels in

Page 567

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide609The following table describes the labels in this screen. 36.3 Address Group Summary Scr

Page 568 - 33.6 The DNSBL Screen

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide61Figure 4 Applications: VPN Connectivity2.3.2 SSL VPN Network Access You

Page 569

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide610The following table describes the labels in this screen. See Section 36.3.1 on page 610 f

Page 570

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide611Available This field displays the names of the address and address group objects that ca

Page 571

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide612

Page 572

ZyWALL USG 100/200 Series User’s Guide613CHAPTER 37 Services37.1 OverviewUse service objects to define TCP applications, UDP applications, and ICMP

Page 573 - PART VII

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide614Service Objects and Service GroupsUse service objects to define IP protocols.• TCP applica

Page 574

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide615The following table describes the labels in this screen. 37.2.1 The Service Add/Edit Sc

Page 575 - CHAPTER 34

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide61637.3 The Service Group Summary Screen The Service Group summary screen provides a summary

Page 576 - 34.2 Device HA General

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide61737.3.1 The Service Group Add/Edit ScreenThe Service Group Add/Edit screen allows you to

Page 577 - Chapter 34 Device HA

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide618

Page 578 - Figure 432 Virtual Router

ZyWALL USG 100/200 Series User’s Guide619CHAPTER 38 Schedules38.1 OverviewUse schedules to set up one-time and recurring schedules for policy routes

Page 579

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide62Figure 6 Network Access Mode: Full Tunnel Mode 2.3.3 User-Aware Access C

Page 580

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide62038.2 The Schedule Summary ScreenThe Schedule summary screen provides a summary of all sc

Page 581

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide62138.2.1 The One-Time Schedule Add/Edit ScreenThe One-Time Schedule Add/Edit screen allow

Page 582

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide62238.2.2 The Recurring Schedule Add/Edit ScreenThe Recurring Schedule Add/Edit screen allo

Page 583 - 34.5 The Legacy Mode Screen

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide623Week Days Select each day of the week the recurring schedule is effective.OK Click OK to

Page 584

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide624

Page 585

ZyWALL USG 100/200 Series User’s Guide625CHAPTER 39 AAA Server39.1 Overview You can use a AAA (Authentication, Authorization, Accounting) server to

Page 586

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide626Figure 462 RADIUS Server Network Example39.1.3 ASASASAS (Authenex Strong Authenticati

Page 587

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide627RADIUS (Remote Authentication Dial-In User Service) authentication is a popular protoco

Page 588 - Synchronization

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide628Bind DN A bind DN is used to authenticate with an LDAP/AD server. For example a bind DN

Page 589

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide62939.3 Active Directory or LDAP Group Summary ScreenYou can configure a group of AD or L

Page 590

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide63Figure 8 Applications: Multiple WAN Interfaces2.3.5 Device HASet up an

Page 591 - PART VIII

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide630Figure 466 Object > AAA Server > Active Directory (or LDAP) > Group > Add

Page 592

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide63139.4 Configuring a Default RADIUS ServerTo configure the default external RADIUS serve

Page 593 - CHAPTER 35

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide63239.5 Configuring a Group of RADIUS Servers You can configure a group of RADIUS servers

Page 594 - Chapter 35 User/Group

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide633The following table describes the labels in this screen. Table 216 Object > AAA Se

Page 595 - 35.2 User Summary Screen

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide634

Page 596 - 35.2.1 User Add/Edit Screen

ZyWALL USG 100/200 Series User’s Guide635CHAPTER 40 Authentication Method40.1 Overview Authentication method objects set how the ZyWALL authenticate

Page 597

Chapter 40 Authentication MethodZyWALL USG 100/200 Series User’s Guide636Figure 470 Example: Using Authentication Method in VPN 40.2 Viewing Authen

Page 598 - 35.3.1 Group Add/Edit Screen

Chapter 40 Authentication MethodZyWALL USG 100/200 Series User’s Guide63740.3 Creating an Authentication Method Object Follow the steps below to cre

Page 599 - 35.4 Setting Screen

Chapter 40 Authentication MethodZyWALL USG 100/200 Series User’s Guide638The following table describes the labels in this screen. Table 218 Object

Page 600

ZyWALL USG 100/200 Series User’s Guide639CHAPTER 41 Certificates41.1 OverviewThe ZyWALL can use certificates (also called digital IDs) to authentica

Page 601 - Chapter 35 User/Group

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide64

Page 602

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide640message, no-one can have altered it (because they cannot re-sign the message with Tim’

Page 603

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide641• PEM (Base-64) encoded PKCS#7: This Privacy Enhanced Mail (PEM) format uses lowercas

Page 604

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide642Figure 474 Certificate Details 4 Use a secure method to verify that the certificate

Page 605

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide64341.2.1 The My Certificates Add ScreenClick Object > Certificate > My Certifica

Page 606

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide644Figure 476 Object > Certificate > My Certificates > AddThe following table

Page 607 - CHAPTER 36

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide645Organization Identify the company or group to which the certificate owner belongs. Yo

Page 608 - Chapter 36 Addresses

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide646If you configured the My Certificate Create screen to have the ZyWALL enroll a certifi

Page 609 - Chapter 36 Addresses

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide647Figure 477 Object > Certificate > My Certificates > Edit The following

Page 610

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide648Type This field displays general information about the certificate. CA-signed means th

Page 611

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide64941.2.3 The My Certificates Import Screen Click Object > Certificate > My Certi

Page 612

ZyWALL USG 100/200 Series User’s Guide65CHAPTER 3 Web ConfiguratorThe ZyWALL web configurator allows easy ZyWALL setup and management using an Intern

Page 613 - CHAPTER 37

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide650The following table describes the labels in this screen. 41.3 The Trusted Certificat

Page 614 - Chapter 37 Services

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide65141.3.1 The Trusted Certificates Edit Screen Click Object > Certificate > Trust

Page 615 - Add icon or an Edit icon

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide652Figure 480 Object > Certificate > Trusted Certificates > Edit The following

Page 616

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide653Refresh Click Refresh to display the certification path.Enable X.509v3 CRL Distributi

Page 617 - Chapter 37 Services

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide65441.3.2 The Trusted Certificates Import Screen Click Object > Certificate > Trus

Page 618

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide655Figure 481 Object > Certificate > Trusted Certificates > ImportThe followi

Page 619 - CHAPTER 38

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide656

Page 620 - Chapter 38 Schedules

ZyWALL USG 100/200 Series User’s Guide657CHAPTER 42 SSL Application42.1 OverviewYou use SSL application objects in SSL VPN. Configure an SSL applica

Page 621 - Chapter 38 Schedules

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide6581 Click Object > SSL Application in the navigation panel. 2 Click the Add button

Page 622

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide65942.2.1 Creating/Editing a Web-based SSL Application ObjectA web-based application

Page 623

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide66Figure 10 Login Screen 3 Type the user name (default: “admin”) and password (defa

Page 624

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide66042.2.2 Creating/Editing a File Sharing SSL Application ObjectYou can specify the n

Page 625 - CHAPTER 39

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide661" You must then configure the shared folder on the file server for remote acc

Page 626 - 39.1.3 ASAS

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide662

Page 627

663PART IXSystemSystem (665)

Page 629 - Chapter 39 AAA Server

ZyWALL USG 100/200 Series User’s Guide665CHAPTER 43 System43.1 OverviewUse the system screens to configure general ZyWALL settings. 43.1.1 What Y

Page 630

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide666• Vantage CNM (Centralized Network Management) is a browser-based global management tool tha

Page 631

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide667Figure 487 System > Date and TimeThe following table describes the labels in this scre

Page 632 - Chapter 39 AAA Server

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide66843.3.1 Pre-defined NTP Time Servers ListWhen you turn on the ZyWALL for the first time, the

Page 633

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide669The ZyWALL continues to use the following pre-defined list of NTP time servers if you do no

Page 634

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide67Follow the directions in this screen. If you change the default password, the Login

Page 635 - CHAPTER 40

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67043.4 Console Port SpeedThis section shows you how to set the console port speed when you co

Page 636

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67143.5.2 Configuring the DNS ScreenClick System > DNS to change your ZyWALL’s DNS setting

Page 637

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide672Domain Zone A domain zone is a fully qualified domain name without the host. For example, zy

Page 638

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67343.5.3 Address Record An address record contains the mapping of a fully qualified domain n

Page 639 - CHAPTER 41

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide674The following table describes the labels in this screen. 43.5.6 Domain Zone Forwarder A do

Page 640 - Chapter 41 Certificates

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide675The following table describes the labels in this screen. 43.5.8 MX Record A MX (Mail eXcha

Page 641 - Chapter 41 Certificates

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67643.5.10 Adding a DNS Service Control RuleClick the Add icon in the Service Control table to

Page 642

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide677Figure 495 Secure and Insecure Service Access From the WAN• See Section 5.6.1 on page 122

Page 643

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67843.6.3 HTTPSYou can set the ZyWALL to use HTTP or HTTPS (HTTPS adds security) for web confi

Page 644 - characters

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67943.6.4 Configuring WWW Click System > WWW to open the WWW screen. Use this screen to sp

Page 645

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide68The icons provide the following functions.3.3.2 Navigation PanelUse the menu items

Page 646

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide680Server Port The HTTPS server listens on port 443 by default. If you change the HTTPS server

Page 647

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide68143.6.5 Service Control RulesClick Add or Edit in the Service Control table in a WWW, SSH,

Page 648

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide682The following table describes the labels in this screen. 43.6.6 HTTPS ExampleIf you haven’

Page 649

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide68343.6.6.2 Netscape Navigator Warning MessagesWhen you attempt to access the ZyWALL HTTPS se

Page 650

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide684• For the browser to trust a self-signed certificate, import the self-signed certificate int

Page 651

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide68543.6.6.5.1 Installing the CA’s Certificate1 Double click the CA’s trusted certificate to p

Page 652

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide686Figure 505 Personal Certificate Import Wizard 12 The file name and path of the certificate

Page 653

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide687Figure 507 Personal Certificate Import Wizard 34 Have the wizard determine where the cert

Page 654

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide688Figure 509 Personal Certificate Import Wizard 56 You should see the following screen when

Page 655

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide689Figure 512 SSL Client Authentication3 You next see the web configurator login screen.Figu

Page 656

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide69Interface Status Use this screen to see information about all of the ZyWALL’s inter

Page 657 - CHAPTER 42

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide690Figure 514 SSH Communication Over the WAN Example43.7.1 How SSH WorksThe following figure

Page 658 - Chapter 42 SSL Application

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69143.7.2 SSH Implementation on the ZyWALLYour ZyWALL supports SSH versions 1 and 2 using RSA

Page 659 - Chapter 42 SSL Application

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69243.7.5 Secure Telnet Using SSH ExamplesThis section shows two examples using a command inte

Page 660

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69343.7.5.2 Example 2: LinuxThis section describes how to access the ZyWALL using the OpenSSH

Page 661

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide694Figure 520 System > TelnetThe following table describes the labels in this screen. 43.

Page 662

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69543.9.1 Configuring FTPTo change your ZyWALL’s FTP settings, click System > FTP tab. The

Page 663 - System (665)

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69643.10 SNMP Simple Network Management Protocol is a protocol used for exchanging management

Page 664

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide697An agent is a management software module that resides in a managed device (the ZyWALL). An

Page 665 - CHAPTER 43

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69843.10.3 Configuring SNMP To change your ZyWALL’s SNMP settings, click System > SNMP tab.

Page 666 - 43.3 Date and Time

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69943.11 Dial-in ManagementConnect an external serial modem to the AUX port to provide a mana

Page 667 - Chapter 43 System

Safety WarningsZyWALL USG 100/200 Series User’s Guide7Safety Warnings1 For your safety, be sure to read and follow all warning notices and instructio

Page 668 - Chapter 43 System

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide70AppPatrol General Use this screen to enable or disable traffic management by applica

Page 669

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide700Figure 524 System > Dial-in Mgmt The following table describes the labels in this scre

Page 670 - 43.5 DNS Overview

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide701Figure 525 System > Vantage CNMThe following table describes the labels in this screen

Page 671 - Table 233 System > DNS

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide70243.13 Language Screen Click System > Language to open the following screen. Use this scr

Page 672

703PART XMaintenance, Troubleshooting, & SpecificationsFile Manager (705)Logs (715)Reports (727)Diagnostics (741)Reboot (743)Troubleshooting

Page 674

ZyWALL USG 100/200 Series User’s Guide705CHAPTER 44 File Manager44.1 OverviewConfiguration files define the ZyWALL’s settings. Shell scripts are fi

Page 675 - 43.5.9 Adding a MX Record

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide706 These files have the same syntax, which is also identical to the way you run CLI comm

Page 676 - 43.6 WWW Overview

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide707" “exit” or “!'” must follow sub commands if it is to make the ZyWALL exit

Page 677 - 43.6.2 System Timeout

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide708Once your ZyWALL is configured and functioning properly, it is highly recommended that

Page 678 - 43.6.3 HTTPS

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide709The following table describes the labels in this screen. Table 249 Maintenance >

Page 679 - 43.6.4 Configuring WWW

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide71User/Group User Use this screen to create and manage users.Group Use this screen to

Page 680

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide71044.3 The Firmware Package Screen Click Maintenance > File Manager > Firmware Pa

Page 681 - 43.6.5 Service Control Rules

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide711The ZyWALL’s firmware package cannot go through the ZyWALL when you enable the anti-v

Page 682 - 43.6.6 HTTPS Example

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide712" The ZyWALL automatically reboots after a successful upload.The ZyWALL automatic

Page 683

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide713Each field is described in the following table. Table 251 Maintenance > File Ma

Page 684

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide714Browse... Click Browse... to find the .zysh file you want to upload. Upload Click Up

Page 685

ZyWALL USG 100/200 Series User’s Guide715CHAPTER 45 Logs45.1 OverviewThis chapter provides general information about the ZyWALL’s log feature. See

Page 686

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide716Figure 538 Maintenance > Log > View LogEvents that generate an alert (as well as a log

Page 687

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide717The Web configurator saves the filter settings if you leave the View Log screen and return to

Page 688

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide718The Log Settings Summary screen provides a summary of all the settings. You can use the Log Se

Page 689 - 43.7 SSH

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide71945.4.2 Edit System Log Settings The Log Settings Edit screen controls the detailed settings

Page 690 - 43.7.1 How SSH Works

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide723.3.3 Main WindowThe main window shows the screen you select in the menu. It is dis

Page 691 - 43.7.4 Configuring SSH

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide720Figure 540 Maintenance > Log > Log Setting > Edit (System Log)

Page 692

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide721The following table describes the labels in this screen. Table 255 Maintenance > Log >

Page 693 - 43.8 Telnet

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide72245.4.3 Edit Remote Server Log Settings The Log Settings Edit screen controls the detailed set

Page 694 - 43.9 FTP

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide723Figure 541 Maintenance > Log > Log Setting > Edit (Remote Server)

Page 695 - 43.9.1 Configuring FTP

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide724The following table describes the labels in this screen. 45.4.4 Active Log Summary ScreenThe

Page 696 - 43.10 SNMP

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide725Figure 542 Active Log SummaryThis screen provides a different view and a different way of i

Page 697 - 43.10.2 SNMP Traps

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide726Selection Select what information you want to log from each Log Category (except All Logs; see

Page 698 - 43.10.3 Configuring SNMP

ZyWALL USG 100/200 Series User’s Guide727CHAPTER 46 Reports46.1 OverviewThis chapter provides information about the report screens. Use the Report

Page 699 - 43.11 Dial-in Management

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide728Figure 543 Maintenance > Report > Traffic StatisticsThere is a limit on the number

Page 700 - 43.12 Vantage CNM

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide729Flush Data Click this button to discard all of the screen’s statistics and update the repo

Page 701 - Note: HTTPS is recommended

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide73Figure 14 Warning Messages Click Refresh Now to update the screen. Close the popu

Page 702 - 43.13 Language Screen

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide730The following table displays the maximum number of records shown in the report, the byte co

Page 703 - Specifications

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide731Figure 544 Maintenance > Report > SessionThe following table describes the labels

Page 704

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide73246.4 The Anti-Virus Report ScreenClick Maintenance > Report > Anti-Virus to display

Page 705 - CHAPTER 44

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide733The statistics display as follows when you display the top entries by source.Figure 546

Page 706 - Chapter 44 File Manager

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide734Figure 548 Maintenance > Report > IDP: Signature Name The following table describes

Page 707 - Chapter 44 File Manager

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide735The statistics display as follows when you display the top entries by source.Figure 549

Page 708

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide736Figure 551 Maintenance > Report > Anti-Spam: Sender IP The following table describe

Page 709

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide73746.7 The Email Daily Report ScreenClick Maintenance > Report > Email Daily Report t

Page 710

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide738Figure 552 Maintenance > Report > Email Daily Report The following table describes

Page 711

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide739Password This box is effective when you select the SMTP Authentication check box. Type the

Page 712

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide74Click Refresh Now to update the screen. For example, if you just enabled a particula

Page 713

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide740

Page 714

ZyWALL USG 100/200 Series User’s Guide741CHAPTER 47 Diagnostics47.1 The Diagnostics ScreenThe Diagnostics screen provides an easy way for you to ge

Page 715 - CHAPTER 45

Chapter 47 DiagnosticsZyWALL USG 100/200 Series User’s Guide742

Page 716 - Chapter 45 Logs

ZyWALL USG 100/200 Series User’s Guide743CHAPTER 48 Reboot48.1 OverviewUse this to restart the device (for example, if the device begins behaving er

Page 717 - 45.4 Log Setting Screens

Chapter 48 RebootZyWALL USG 100/200 Series User’s Guide744

Page 718 - 45.4.1 Log Setting Summary

ZyWALL USG 100/200 Series User’s Guide745CHAPTER 49 TroubleshootingThis chapter offers some suggestions to solve problems you might encounter. V I ca

Page 719 - Chapter 45 Logs

Chapter 49 TroubleshootingZyWALL USG 100/200 Series User’s Guide746• If you have the ZyWALL and remote IPSec router use certificates to authenticate e

Page 720

Chapter 49 TroubleshootingZyWALL USG 100/200 Series User’s Guide747V I changed the LAN IP address and can no longer access the Internet.The ZyWALL au

Page 721

Chapter 49 TroubleshootingZyWALL USG 100/200 Series User’s Guide74849.1 Resetting the ZyWALLIf you cannot access the ZyWALL by any method, try restar

Page 722

ZyWALL USG 100/200 Series User’s Guide749CHAPTER 50 Product Specifications50.1 General SpecificationsThe following specifications are subject to cha

Page 723

ZyWALL USG 100/200 Series User’s Guide75CHAPTER 4 Wizard Setup4.1 Wizard Setup OverviewThe web configurator's setup wizards help you configure

Page 724

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide7501 It is recommended that you do NOT wall-mount the ZyWALL. A wall-mounting k

Page 725

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide751USER PROFILESMaximum Local Users 192 128Maximum Admin Users 5 5Maximum User

Page 726

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide752Admin E-mail Addresses 2 2Syslog Servers 4 4IDPMaximum Number of IDP Profile

Page 727 - CHAPTER 46

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide753The following table, which is not exhaustive, lists standards referenced by

Page 728 - Chapter 46 Reports

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide75450.2 3G or WLAN PCMCIA Card InstallationOnly insert a compatible 802.11b/g-

Page 729 - Chapter 46 Reports

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide755POWER CONSUMPTION 20 W MAX. SAFETY STANDARDS UL, CUL (UL 60950-1 FIRST EDIT

Page 730 - 46.3 The Session Screen

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide756

Page 731

757PART XIAppendices and IndexCommon Services (815)Displaying Anti-Virus Alert Messages in Windows (819)Open Software Announcements (845)Legal Info

Page 733 - 46.5 The IDP Report Screen

ZyWALL USG 100/200 Series User’s Guide759APPENDIX A Log DescriptionsThis appendix provides descriptions of example log messages. Table 276 Conte

Page 734

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide76Figure 16 Wizard Setup Welcome 4.2 Installation Setup, One ISP The wizard screens

Page 735

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide760%s: Service is unavailableContent filter rating service is temporarily unavailable

Page 736

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide761Anti-Spam policy %d has been inserted.The anti-spam policy with the specified ind

Page 737

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide762DNSBL domain %s has been deleted.The specified DNSBL domain name (%s) has been rem

Page 738

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide763The %s address-object is wrong type for '1st-dns' in SSL Policy %s.The

Page 739

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide764The SSL VPN policy %s does not configure users or user groups.There are no users o

Page 740

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide765Failed login attempt to SSLVPN from %s (reach the max. number of simultaneous log

Page 741 - CHAPTER 47

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide766The ZySH logs deal with internal system errors. User %s has been granted an L2TP o

Page 742 - Chapter 47 Diagnostics

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide767can't get name for entry %d!1st:zysh entry indexcan't get reference cou

Page 743 - CHAPTER 48

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide768Table 283 ADP LogsLOG MESSAGE DESCRIPTIONfrom <zone> to <zone> [type

Page 744 - Chapter 48 Reboot

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide769Reloading Anti-Virus signature reference table has failed.The ZyWALL failed to re

Page 745 - CHAPTER 49

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide77The following table describes the labels in this screen.4.3 Step 1 Internet Access Enc

Page 746 - VPN tunnel

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide770AV signature update has failed.An anti-virus signatures update failed for unknown

Page 747 - Chapter 49 Troubleshooting

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide771%s, due to decompress malfunction, %s could not be decompressed. Action on file:

Page 748 - 49.1 Resetting the ZyWALL

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide772 Failed login attempt to ZyWALL from %s (reach the max. number of simultaneous log

Page 749 - CHAPTER 50

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide773Standard service activation has failed:%s.Standard service activation failed, thi

Page 750

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide774Change Anti-Virus engine type has failed. Because of lack must fields.The device f

Page 751

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide775IDP signature download has failed.The device still cannot download the IDP signat

Page 752

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide776System bootup. Do expiration daily-check.The device processes a service expiration

Page 753

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide777Download file size is wrong.The file size downloaded for AS is not identical with

Page 754

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide778Custom signature import error: line <line>, sid <sid>, <error_messa

Page 755

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide779IDP system-protect signature update from version <version> to version <v

Page 756

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide78Figure 18 Ethernet Encapsulation: Auto: FinishYou have set up your ZyWALL to access th

Page 757 - Appendices and

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide780IDP system-protect signature update failed. Invalid signature content.An IDP syste

Page 758

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide781Table 288 Application PatrolMESSAGE EXPLANATIONService=%s Mode=%s Rule=%s Acces

Page 759 - APPENDIX A

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide782 System fatal error: 60011002.The device failed to get the application patrol prot

Page 760 - Table 279 Anti-Spam Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide783[SA] : Tunnel [%s] Phase 1 authentication method mismatch%s is the tunnel name. W

Page 761 - Appendix A Log Descriptions

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide784Cannot resolve Secure Gateway Addr %s for Tunnel [%s]1st %s is my ip address. 2nd

Page 762 - Table 280 SSL VPN Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide785Tunnel [%s] Sending IKE request%s is the tunnel name. The device sent an IKE requ

Page 763

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide786 Table 290 IPSec LogsLOG MESSAGE DESCRIPTIONCorrupt packet, Inbound transform o

Page 764

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide787 Firewall rule %d has been moved to %d.1st %d is the old global index of rule, 2

Page 765

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide788 To send message to policy route daemon failed!Failed to send control message to p

Page 766 - Table 282 ZySH Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide789HTTPS port has been changed to default port.An administrator changed the port num

Page 767

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide79Figure 19 Ethernet Encapsulation: StaticThe following table describes the labels in t

Page 768 - Table 284 Anti-Virus Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide790DHCP Server on Interface %s will be reapplied due to Device HA status is ActiveWhe

Page 769

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide791 Interface %s ping check is failed. Zone Forwarder removes DNS servers in records

Page 770

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide792%s is dead at %s A daemon (process) is gone (was killed by the operating system).

Page 771 - Table 285 User Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide793DHCP request received via interface %s (%s:%s), src_mac: %s with requested IP: %s

Page 772 - Table 286 myZyXEL.com Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide794Update the profile %s has failed because of invalid system parameters.Some system

Page 773

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide795Update the profile %s has failed because WAN interface was link-down.DDNS profile

Page 774

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide796 DDNS Initialization has failed.Initialize DDNS failed,All DDNS profiles are delet

Page 775

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide797 Can't get BROADCAST address of %s interfaceThe connectivity check process c

Page 776

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide798Master firmware version can not be recognized. Stop syncing from Master.Synchroniz

Page 777 - Table 287 IDP Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide799 Device HA authentication string of AH for VRRP group %s maybe wrong.A VRRP group

Page 778

Safety WarningsZyWALL USG 100/200 Series User’s Guide8

Page 779

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide80" Enter the Internet access information exactly as given to you by your ISP.WAN Int

Page 780

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide800Invalid RIP text authentication.RIP text authentication has been set without setti

Page 781

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide801RIP v2-broadcast on interface %s has been enabled.RIP v2-broadcast on interface %

Page 782 - Table 289 IKE Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide802 Interface %s does not belong to any OSPF area.Interface %s has been set OSPF auth

Page 783

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide803 Table 300 PKI LogsLOG MESSAGE DESCRIPTIONGenerate X509certifiate "%s"

Page 784

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide804Import PKCS#7 certificate "%s" into "My Certificate" successfu

Page 785

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide805 CODE DESCRIPTION1 Algorithm mismatch between the certificate and the search con

Page 786 - Table 291 Firewall Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide806AUX Interface disconnecting failed. This AUX interface is not enabled.The AUX inte

Page 787 - Table 293 Policy Route Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide807Interface %s links down. Default route will not apply until interface %s links up

Page 788

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide808Interface %s connect failed: Connect timeout.A PPPOE connection timed out due to a

Page 789

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide809"Incorrect PIN code of interface cellular%d. Please check the PIN code setti

Page 790

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide814.3.4 PPPoE: Auto IP Address AssignmentIf you select Auto as the IP Address Assignment

Page 791 - Table 295 System Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide810Create interface %s has failed. Wlan device does not exist.The wireless device fai

Page 792

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide811 Table 303 Account LogsLOG MESSAGE DESCRIPTIONAccount %s %s has been deleted.

Page 793

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide812 Table 306 File Manager LogsLOG MESSAGE DESCRIPTIONERROR:#%s, %s Apply configura

Page 794

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide813

Page 795

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide814

Page 796

ZyWALL USG 100/200 Series User’s Guide815APPENDIX B Common ServicesThe following table lists some commonly-used services and their associated protoco

Page 797 - Table 297 Device HA Logs

Appendix B Common ServicesZyWALL USG 100/200 Series User’s Guide816FTP TCPTCP2021File Transfer Program, a program to enable fast transfer of files, in

Page 798

Appendix B Common ServicesZyWALL USG 100/200 Series User’s Guide817RTSP TCP/UDP 554 The Real Time Streaming (media control) Protocol (RTSP) is a remo

Page 799

Appendix B Common ServicesZyWALL USG 100/200 Series User’s Guide818

Page 800

ZyWALL USG 100/200 Series User’s Guide819APPENDIX C Displaying Anti-Virus AlertMessages in WindowsWith the anti-virus packet scan, when a virus is de

Page 801

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide82Figure 22 PPPoE Encapsulation: Auto: FinishYou have set up your ZyWALL to access the I

Page 802 - Table 299 NAT Logs

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide820Figure 557 Windows XP: Starting the Messenger Ser

Page 803 - Table 300 PKI Logs

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide821Figure 559 Windows 2000: Starting the Messenger

Page 804

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide822Figure 562 Windows 98 SE: Task Bar Properties

Page 805 - Table 301 Interface Logs

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide823Figure 564 Windows 98 SE: Startup: Create Shortc

Page 806

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide824Figure 566 Windows 98 SE: Startup: Shortcut

Page 807

ZyWALL USG 100/200 Series User’s Guide825APPENDIX D Importing CertificatesThis appendix shows importing certificates examples using Netscape Navigato

Page 808

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide826Figure 568 Login Screen2 Click Install Certificate to open the Install Cer

Page 809 - Table 302 WLAN Logs

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide827Figure 570 Certificate Import Wizard 14 Select where you would like to st

Page 810

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide828Figure 572 Certificate Import Wizard 36 Click Yes to add the ZyWALL certi

Page 811 - Table 303 Account Logs

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide829Figure 574 Certificate General Information after Import

Page 812 - Table 306 File Manager Logs

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide83Figure 23 PPPoE Encapsulation: StaticThe following table describes the labels in this

Page 813

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide830

Page 814

ZyWALL USG 100/200 Series User’s Guide831APPENDIX E Wireless LANsWireless LAN TopologiesThis section discusses ad-hoc and infrastructure wireless LAN

Page 815 - APPENDIX B

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide832Figure 576 Basic Service SetESSAn Extended Service Set (ESS) consists of a series o

Page 816 - Appendix B Common Services

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide833Figure 577 Infrastructure WLANChannelA channel is the radio frequency(ies) used by

Page 817 - Appendix B Common Services

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide834Figure 578 RTS/CTSWhen station A sends data to the AP, it might not know that the

Page 818

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide835If the Fragmentation Threshold value is smaller than the RTS/CTS value (see previous

Page 819 - APPENDIX C

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide836Wireless security methods available on the ZyWALL are data encryption, wireless clien

Page 820 - Windows 2000

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide837Determines the network services available to authenticated users once they are conne

Page 821 - Windows 98 SE/Me

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide838For EAP-TLS authentication type, you must first have a wired connection to the networ

Page 822

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide839Dynamic WEP Key ExchangeThe AP maps a unique key that is generated with the RADIUS s

Page 823

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide844.3.6 Step 2 Internet Access PPPoE " Enter the Internet access information exactly

Page 824

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide840Encryption WPA improves data encryption by using Temporal Key Integrity Protocol (TKI

Page 825 - APPENDIX D

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide841Wireless Client WPA SupplicantsA wireless client supplicant is the software that run

Page 826 - Figure 568 Login Screen

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide8423 The AP and wireless clients generate a common PMK (Pairwise Master Key). The key it

Page 827

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide843Antenna OverviewAn antenna couples RF signals onto air. A transmitter within a wirel

Page 828

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide844Positioning AntennasIn general, antennas should be mounted as high as practically pos

Page 829

ZyWALL USG 100/200 Series User’s Guide845APPENDIX F Open Software AnnouncementsNotice Information herein is subject to change without notice. Compani

Page 830

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide846" This Product includes Netkit Telnet -0.17 software under the Net

Page 831 - APPENDIX E

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide847" This Product includes expat-1.95.6 software under the Expat Lic

Page 832 - Appendix E Wireless LANs

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide848The above copyright notice and this permission notice shall be included

Page 833 - Appendix E Wireless LANs

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide849OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF

Page 834 - Fragmentation Threshold

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide85Figure 24 PPPoE Encapsulation: Static: FinishYou have set up your ZyWALL to access th

Page 835 - Wireless Security Overview

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide850ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBI

Page 836 - IEEE 802.1x

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide851" This Product includes bind-9.2.3 software under the Internet So

Page 837 - Types of EAP Authentication

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide852THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRAN

Page 838 - PEAP (Protected EAP)

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide853"Work" shall mean the work of authorship, whether in Source

Page 839 - WPA and WPA2

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide854(d) If the Work includes a "NOTICE" text file as part of its

Page 840 - User Authentication

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide855Version 1.1Copyright (c) 1999-2003 The Apache Software Foundation. All

Page 841

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide85659 Temple Place, Suite 330, Boston, MA 02111-1307 USAEveryone is permit

Page 842 - Security Parameters Summary

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide857When a program is linked with a library, whether statically or using a

Page 843 - Types of Antennas for WLAN

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide858Library is not restricted, and output from such a program is covered on

Page 844 - Positioning Antennas

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide8594. You may copy and distribute the Library (or a portion or derivative

Page 845 - APPENDIX F

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide86Figure 25 PPTP Encapsulation: AutoThe following table describes the labels in this scr

Page 846 - NTP License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide860copy of the library already present on the user's computer system,

Page 847 - Expat License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide861simultaneously your obligations under this License and any other perti

Page 848 - OpenSSL License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide86216. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITI

Page 849 - Original SSLeay License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide863To protect your rights, we need to make restrictions that forbid anyon

Page 850

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide864c) If the modified program normally reads commands interactively when r

Page 851 - ISC license

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide8654. You may not copy, modify, sublicense, or distribute the Program exc

Page 852 - Apache License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide86610. If you wish to incorporate parts of the Program into other free pro

Page 853

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide867Redistributions in binary form must reproduce the above copyright noti

Page 854

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide868The Public LicenseVersion 2.8, 17 August 2003Redistribution and use of

Page 855

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide869End-User License Agreement for “ZyWALL USG 100 and ZyWALL USG 200”WARN

Page 856

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide87The ZyWALL applies the configuration settings. Figure 26 PPTP Encapsulation: Auto: Fi

Page 857

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide870You acknowledge that the Software contains proprietary trade secrets of

Page 858

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide871ORDERS, OR OTHER RESTRICTIONS. YOU AGREE TO INDEMNIFY ZyXEL AGAINST A

Page 859

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide872

Page 860

ZyWALL USG 100/200 Series User’s Guide873APPENDIX G Legal InformationCopyrightCopyright © 2008 by ZyXEL Communications Corporation.The contents of th

Page 861

Appendix G Legal InformationZyWALL USG 100/200 Series User’s Guide874If this device does cause harmful interference to radio/television reception, whi

Page 862

Appendix G Legal InformationZyWALL USG 100/200 Series User’s Guide875ZyXEL Limited WarrantyZyXEL warrants to the original end user (purchaser) that t

Page 863

Appendix G Legal InformationZyWALL USG 100/200 Series User’s Guide876

Page 864

ZyWALL USG 100/200 Series User’s Guide877APPENDIX H Customer SupportIn the event of problems that cannot be solved by using this manual, you should c

Page 865

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide878• Address: 1005F, ShengGao International Tower, No.137 XianXia Rd., Shanghai• Web:

Page 866

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide879Germany• Support E-mail: [email protected]• Sales E-mail: [email protected]• Telephon

Page 867 - The MIT License

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide884.3.8 PPTP: Static IP Address AssignmentIf you select Static as the IP Address Assignme

Page 868

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide880Malaysia• Support E-mail: [email protected]• Sales E-mail: [email protected]

Page 869

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide881Singapore• Support E-mail: [email protected]• Sales E-mail: [email protected]

Page 870

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide882Turkey• Support E-mail: [email protected]• Telephone: +90 212 222 55 22• Fax: +90-2

Page 871

IndexZyWALL USG 100/200 Series User’s Guide883IndexNumerics3DES 3743G 1293G see also cellular 226AAAA server 625AD 626and users 594directory service 6

Page 872

IndexZyWALL USG 100/200 Series User’s Guide884alerts 717, 721, 724, 725anti-spam 564anti-virus 475IDP 492ALG 325, 330and firewall 325, 327and NAT 326a

Page 873 - APPENDIX G

IndexZyWALL USG 100/200 Series User’s Guide885allowing through the firewall 344vs virtual interfaces 343AT command strings 699authenticationLDAP/AD 62

Page 874

IndexZyWALL USG 100/200 Series User’s Guide886and FTP 695and HTTPS 678and IKE SA 378and SSH 691and synchronization (device HA) 589and VPN gateways 353

Page 875 - ZyXEL Limited Warranty

IndexZyWALL USG 100/200 Series User’s Guide887copyright 873CPU usage 173, 175CTS (Clear to Send) 834current date/time 173, 666and schedules 619dayligh

Page 876 - Appendix G Legal Information

IndexZyWALL USG 100/200 Series User’s Guide888double-encoding 527DTR 699Dynamic Domain Name System. See DDNS.Dynamic Host Configuration Protocol. See

Page 877 - APPENDIX H

IndexZyWALL USG 100/200 Series User’s Guide889vs application patrol 335, 337firmwareand restart 710boot module. See boot module.current version 172, 7

Page 878 - Appendix H Customer Support

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide894.3.9 Step 2 Internet Access PPTP " Enter the Internet access information exactly

Page 879 - Appendix H Customer Support

IndexZyWALL USG 100/200 Series User’s Guide890custom signature example 505custom signatures 498false negatives 489false positives 489inline profile 48

Page 880

IndexZyWALL USG 100/200 Series User’s Guide891trunks. See also trunks.types 200virtual. See also virtual interfaces.VLAN. See also VLAN interfaces.whe

Page 881

IndexZyWALL USG 100/200 Series User’s Guide892Default_L2TP_VPN_GW example 415DNS 412example 415, 418IPSec configuration 410policy route 410policy rout

Page 882

IndexZyWALL USG 100/200 Series User’s Guide893NNAT 285, 3091 to 1 example 313address mapping. See policy routes.ALG. See ALG.and address objects 282an

Page 883 - Numerics

IndexZyWALL USG 100/200 Series User’s Guide894Pairwise Master Key (PMK) 840, 842payload option 504payload size 505PCMCIA card installation 754Peanut H

Page 884

IndexZyWALL USG 100/200 Series User’s Guide895RRADIUS 625, 626, 836advantages 625and IKE SA 378and PPPoE 268and users 594message types 837messages 837

Page 885

IndexZyWALL USG 100/200 Series User’s Guide896and force user authentication policies 603and policy routes 282, 455, 457, 459, 461one-time 619recurring

Page 886

IndexZyWALL USG 100/200 Series User’s Guide897spam 559specifications 749device 749feature 750hardware 749spillover (for load balancing) 272SQL slammer

Page 887

IndexZyWALL USG 100/200 Series User’s Guide898SYN flood 526synchronization 576and subscription services 576information synchronized 588password 581, 5

Page 888

IndexZyWALL USG 100/200 Series User’s Guide899messages 613port numbers 613UDP Decoder 520UDP decoy portscan 524UDP distributed portscan 524UDP flood a

Page 889

Contents OverviewZyWALL USG 100/200 Series User’s Guide9Contents OverviewGetting Started ...

Page 890

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide904.3.9.3 WAN IP Address Assignments You do not configure this section if you selected Au

Page 891

IndexZyWALL USG 100/200 Series User’s Guide900Virtual Private Network. See VPN.virtual router 578Virtual Router ID number (VRID). 584Virtual Router Re

Page 892

IndexZyWALL USG 100/200 Series User’s Guide901white listanti-spam 564, 566, 567whitelist 567anti-spam 559Wi-Fi Protected Access 839Windows Internet Na

Page 893

IndexZyWALL USG 100/200 Series User’s Guide902

Page 894

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide914.4 Device Registration Use this screen to register your ZyWALL with myZXEL.com and

Page 895

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide92Figure 30 Registration: Registered Device4.5 Installation Setup, Two Internet Service

Page 896

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide93Figure 31 Internet Access: Step 1: First WAN InterfaceAfter you configure the First W

Page 897

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide94Figure 33 Internet Access: Finish " You can register your ZyWALL with myZyXEL.com

Page 898

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide95Figure 34 VPN Wizard: Wizard TypeThe following table describes the labels in this scr

Page 899

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide96Figure 35 VPN Express Wizard: Step 2 The following table describes the labels in this

Page 900

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide97Pre-Shared Key: Type the password. Both ends of the VPN tunnel must use the same passwo

Page 901

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide98Figure 37 VPN Express Wizard: Step 4 The following table describes the labels in this

Page 902

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide99Local Policy: IP address and subnet mask of the computers on the network behind your Zy

Modèles reliés 100 Series

Commentaires sur ces manuels

Pas de commentaire