Zyxel-communications 200 Series Manuale Utente

Navigare online o scaricare Manuale Utente per Hardware Zyxel-communications 200 Series. ZyXEL Communications 200 Series User Manual [en] [ru] [de] [fr] [it] [cs] [pl] [es] Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
Vedere la pagina 0
www.zyxel.com
ZyWALL USG 100/200
Series
Unified Security Gateway
Users Guide
Version 2.10
5/2008
Edition 1
DEFAULT LOGIN
LAN1 Port P4
IP Address http://192.168.1.1
User Name admin
Password 1234
Vedere la pagina 0
1 2 3 4 5 6 ... 901 902

Sommario

Pagina 1 - ZyWALL USG 100/200

www.zyxel.comZyWALL USG 100/200 SeriesUnified Security GatewayUser’s GuideVersion 2.105/2008Edition 1DEFAULT LOGINLAN1 Port P4IP Address http://192.1

Pagina 2

Contents OverviewZyWALL USG 100/200 Series User’s Guide10Anti-X ...

Pagina 3 - About This User's Guide

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide1004.8.4 VPN Advanced WizardClick the Advanced radio button as shown in Figure 34 on page

Pagina 4

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide1014.8.5 VPN Advanced Wizard - Remote Gateway The Remote Gateway policy identifies the I

Pagina 5 - Document Conventions

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide102The following table describes the labels in this screen.4.8.6 VPN Advanced Wizard - Ph

Pagina 6 - Icons Used in Figures

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide103" Multiple SAs connecting through a secure gateway must have the same negotiation

Pagina 7 - Safety Warnings

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide104The following table describes the labels in this screen.Table 20 VPN Advanced Wizard:

Pagina 8

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide1054.8.7 VPN Advanced Wizard - Phase 2 Active Protocol: ESP is compatible with NAT, AH i

Pagina 9 - Contents Overview

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide1064.8.8 VPN Advanced Wizard - Summary This summary of VPN tunnel settings is read-only.N

Pagina 10

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide107Figure 43 VPN Wizard: Step 6: Advanced" If you have not already done so, you ca

Pagina 11 - Table of Contents

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide108

Pagina 12 - Chapter 5

ZyWALL USG 100/200 Series User’s Guide109CHAPTER 5 Configuration BasicsThis section provides information to help you configure the ZyWALL effectively

Pagina 13 - Chapter 6

Table of ContentsZyWALL USG 100/200 Series User’s Guide11Table of ContentsAbout This User's Guide...

Pagina 14 - Chapter 7

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1105.2 Zones, Interfaces, and Physical PortsZones (groups of interfaces and VPN t

Pagina 15

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide111• Bridge interfaces create a software connection between Ethernet or VLAN inte

Pagina 16 - Chapter 12

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide112Table 24 ZyWALL USG 100 Default Port, Interface, and Zone Configuration• The

Pagina 17

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1135.4 Feature Configuration OverviewThis section provides information about co

Pagina 18

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide114" PREQUISITES or WHERE USED does not appear if there are no prerequisites

Pagina 19

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide115Example: See Chapter 6 on page 125.5.4.5 SSL VPNUse SSL VPN to provide secure

Pagina 20

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide116Example: See Chapter 6 on page 125.5.4.9 DDNSDynamic DNS maps a domain name to

Pagina 21 - Chapter 29

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide117" The ZyWALL checks the policy routes in the order that they are listed.

Pagina 22

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1185.4.13 Application PatrolUse application patrol to control which individuals c

Pagina 23 - Chapter 35

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1195.4.16 ADPUse ADP to detect and take action on traffic and protocol anomalies

Pagina 24

Table of ContentsZyWALL USG 100/200 Series User’s Guide123.1 Web Configurator Requirements ...

Pagina 25

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide120The ZyWALL does not check to-ZyWALL firewall rules for packets that are redirec

Pagina 26 - Chapter 43

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1215.5 ObjectsObjects store information and are referenced by other features. If

Pagina 27

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1225.6 System Management and MaintenanceThis section introduces some of the manag

Pagina 28

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide1235.6.3 Licensing RegistrationUse these screens to register your ZyWALL and sub

Pagina 29 - List of Figures

Chapter 5 Configuration BasicsZyWALL USG 100/200 Series User’s Guide124

Pagina 30

ZyWALL USG 100/200 Series User’s Guide125CHAPTER 6 TutorialsThis chapter provides some examples of using the web configurator to set up features in t

Pagina 31

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide126Click Network > Interface > Ethernet and the wan1 interface’s Edit icon. Configure t

Pagina 32

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide127Figure 48 Network > Interface > Ethernet > Edit opt 2 Set DHCP to DHCP Server

Pagina 33

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide128Figure 49 Network > Interface > Ethernet > Edit opt > More Settings 6.1.3 H

Pagina 34

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1296.2 How to Configure a Cellular InterfaceUse 3G cards for cellular WAN (Internet) connec

Pagina 35

Table of ContentsZyWALL USG 100/200 Series User’s Guide135.2 Zones, Interfaces, and Physical Ports ...

Pagina 36

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide130Figure 52 Network > Interface > Cellular > Edit 5 Go to the Status screen. The

Pagina 37

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide131Figure 53 Status The ZyWALL automatically balances the traffic load amongst the availab

Pagina 38

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1321 Click Object > User/Group > User and the Add wlan_user Edit icon.2 Set the User Na

Pagina 39

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide133Figure 55 Network > Interface > WLAN > Add (WPA/WPA2 Security) 3 Turn on the w

Pagina 40

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1346.3.3 How to Set Up the Wireless Clients to Use the WLAN InterfaceThe following sections

Pagina 41

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide135Figure 58 ZyXEL Wireless Client > Profile3 Select WPA2 as the security type and clic

Pagina 42

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide136Figure 60 ZyXEL Wireless Client > Profile: Security Settings5 Confirm your settings a

Pagina 43 - List of Tables

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide137Figure 63 ZyXEL Wireless Client > Profile: ActivateSince the ZyXEL utility does not

Pagina 44

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide138Figure 65 Odyssey Access Client Manager > Profiles > User Info 3 Click the Authent

Pagina 45

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide139Figure 67 Odyssey Access Client Manager > Profiles > Authentication 5 Click Netwo

Pagina 46

Table of ContentsZyWALL USG 100/200 Series User’s Guide146.3 How to Set Up a WLAN Interface ...

Pagina 47

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide140Figure 69 Odyssey Access Client Manager > Networks > Add Use the next section to i

Pagina 48

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1412 Click Import.Figure 71 Internet Explorer: Tools > Internet Options > Content &g

Pagina 49

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide142Figure 73 Internet Explorer Certificate Import Wizard Certificate Store Screen5 If you g

Pagina 50

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide143Figure 75 Internet Explorer: Trusted Root Certification AuthoritiesAs shown here, the M

Pagina 51 - Getting Started

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide144Figure 77 Funk Odyssey Access Wireless Client Login Example 6.4 How to Set Up an IPSec

Pagina 52

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide145Figure 79 VPN > IPSec VPN > VPN Gateway > Add6.4.2 How to Set Up the VPN Conn

Pagina 53 - CHAPTER 1

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide146Figure 81 VPN > IPSec VPN > VPN Connection > Add6.4.3 How to Set Up the Policy

Pagina 54 - 1.3 Management Overview

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide147and destination address objects here. The next-hop is the VPN connection that you created

Pagina 55

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1486.5 How to Configure User-aware Access ControlYou can configure many policies and securit

Pagina 56

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1492 Enter the name of the group that is used in Table 31 on page 148. In this example, it i

Pagina 57 - CHAPTER 2

Table of ContentsZyWALL USG 100/200 Series User’s Guide157.2.4 The VPN Status Screen ...

Pagina 58

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide150Figure 87 Object > Auth. method > Add4 Click System > WWW. In the Authenticatio

Pagina 59 - 2.2 Packet Flow

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1511 Click AppPatrol. If application patrol and bandwidth management are not enabled, enable

Pagina 60 - 2.3 Applications

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide152Figure 93 AppPatrol > Common > http > Edit Default5 Click the Add icon in the p

Pagina 61

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide153Figure 95 Object > Schedule > Add (Recurring)3 Follow the steps in Section 6.5.4

Pagina 62

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide154Figure 97 Firewall > LAN1 to DMZ > Edit3 Click the Add icon at the top of the rule

Pagina 63 - 2.3.5 Device HA

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide155You do not have to change many of the ZyWALL’s settings from the defaults to set up this

Pagina 64

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide156Figure 101 Network > Interface > Trunk > WAN_TRUNK > Edit6.7 How to Configu

Pagina 65 - CHAPTER 3

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide157Figure 102 System > WWW3 In the Zone field select LAN1 and click OK. Figure 103 Sy

Pagina 66 - Figure 10 Login Screen

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide158Figure 104 System > WWW (First Example Admin Service Rule Configured)5 Set the Zone t

Pagina 67 - 3.3.1 Title Bar

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide159Figure 106 System > WWW (Second Example Admin Service Rule Configured)Now administra

Pagina 68 - 3.3.2 Navigation Panel

Table of ContentsZyWALL USG 100/200 Series User’s Guide1610.5.6 Interface Wizard: Summary (Non-WAN) ...

Pagina 69 - Chapter 3 Web Configurator

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1606.8.1 How to Turn On the ALGClick Network > ALG. Select Enable H.323 transformations a

Pagina 70

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide161Figure 110 Network > Virtual Server > Add6.8.3 How to Set Up a Firewall Rule For

Pagina 71

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide162Figure 112 Firewall > Add 4 Configure an address object for the ZyWALL’s 10.0.0.8 WAN

Pagina 72 - 3.3.4 Message Bar

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide163An Ethernet switch connects both ZyWALLs’ lan1 interfaces to LAN1. Whichever ZyWALL is fu

Pagina 73 - Figure 15 CLI Messages

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide1642 Configure 192.168.1.3 as the Management IP and 255.255.255.0 as the Subnet Mask. Click O

Pagina 74

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide165Figure 119 Device HA > General: Master ZyWALL Example6.9.3 How to Configure the Bac

Pagina 75 - CHAPTER 4

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide166Figure 121 Device HA > Active-Passive Mode: Backup ZyWALL Example5 Click the General

Pagina 76

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide167Maintenance > File Manager > Configuration File screen to save copies of the ZyWALL

Pagina 77 - 4.3 Step 1 Internet Access

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide168Figure 125 Creating the Address Object for the wan2 Public IP Address 6.10.2 How to Con

Pagina 78

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide169The firewall allows traffic from the WAN zone to the DMZ zone by default so your configur

Pagina 79

Table of ContentsZyWALL USG 100/200 Series User’s Guide1712.4 Policy Routing Technical Reference ...

Pagina 80

Chapter 6 TutorialsZyWALL USG 100/200 Series User’s Guide170

Pagina 81

ZyWALL USG 100/200 Series User’s Guide171CHAPTER 7 Status7.1 OverviewUse the Status screens to check status information about the ZyWALL.7.1.1 Wha

Pagina 82

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide172Figure 127 Status The following table describes the labels in this screen. Table 32 Stat

Pagina 83

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide173Current Date/TimeThis field displays the current date and time in the ZyWALL. The format is

Pagina 84

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide174Signature VersionThis field displays the version number, date, and time of the current set of

Pagina 85

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide1757.2.1 The CPU Usage ScreenUse this screen to look at a chart of the ZyWALL’s recent CPU usa

Pagina 86

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide176Figure 128 Status > CPU UsageThe following table describes the labels in this screen. 7

Pagina 87

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide177Figure 129 Status > Memory UsageThe following table describes the labels in this screen

Pagina 88

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide178Figure 130 Status > Session UsageThe following table describes the labels in this screen

Pagina 89

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide179Figure 131 Status > VPN StatusThe following table describes the labels in this screen.

Pagina 90

Table of ContentsZyWALL USG 100/200 Series User’s Guide1817.1.2 What You Need to Know About HTTP Redirect ...

Pagina 91 - Device Registration

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide180The following table describes the labels in this screen. 7.2.6 The Port Statistics ScreenUse

Pagina 92

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide181The following table describes the labels in this screen. 7.2.7 The Port Statistics Graph Sc

Pagina 93

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide182Figure 134 Status > Port Statistics > Switch to Graphic View The following table de

Pagina 94 - 4.6 VPN Setup

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide183Figure 135 Status > Current UsersThe following table describes the labels in this scree

Pagina 95 - 4.7 VPN Wizards

Chapter 7 StatusZyWALL USG 100/200 Series User’s Guide184Cellular System This field displays the type of the network to which the ZyWALL is connected.

Pagina 96

ZyWALL USG 100/200 Series User’s Guide185CHAPTER 8 Registration8.1 OverviewUse the Licensing > Registration screens to register your ZyWALL and m

Pagina 97

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide186Subscription Services Available on the ZyWALLYou can have the ZyWALL use anti-virus, ID

Pagina 98

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide187Figure 137 Licensing > RegistrationThe following table describes the labels in th

Pagina 99

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide188" If the ZyWALL is registered already, this screen is read-only and indicates whet

Pagina 100 - 4.8.4 VPN Advanced Wizard

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide1898.3 The Service ScreenUse this screen to display the status of your service registrat

Pagina 101 - Chapter 4 Wizard Setup

Table of ContentsZyWALL USG 100/200 Series User’s Guide1920.4.1 The VPN Concentrator Add/Edit Screen ...

Pagina 102 - Chapter 4 Wizard Setup

Chapter 8 RegistrationZyWALL USG 100/200 Series User’s Guide190

Pagina 103

ZyWALL USG 100/200 Series User’s Guide191CHAPTER 9 Signature Update9.1 OverviewThis chapter shows you how to update the ZyWALL’s signature packages.

Pagina 104

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide192Figure 140 Licensing > Update >Anti-Virus The following table describes the

Pagina 105

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide1939.3 The IDP/AppPatrol Update ScreenClick Licensing > Update > IDP/AppPatrol

Pagina 106

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide194Figure 142 Downloading IDP SignaturesFigure 143 Successful IDP Signature Downlo

Pagina 107

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide195Figure 144 Licensing > Update > System Protect The following table describ

Pagina 108

Chapter 9 Signature UpdateZyWALL USG 100/200 Series User’s Guide196Figure 145 Downloading System Protect SignaturesFigure 146 Successful System Pr

Pagina 109 - CHAPTER 5

197PART IINetworkInterface (199)Trunks (269)Policy and Static Routes (277)Routing Protocols (287)Zones (299)DDNS (303)Virtual Servers (309)HTTP

Pagina 111

ZyWALL USG 100/200 Series User’s Guide199CHAPTER 10 Interface10.1 Interface OverviewUse the Interface screens to configure the ZyWALL’s interfaces.

Pagina 113 - 5.4.1 Feature

Table of ContentsZyWALL USG 100/200 Series User’s Guide20Chapter 25L2TP VPN...

Pagina 114 - 5.4.4 IPSec VPN

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide20010.1.2 What You Need to Know About InterfacesInterface CharacteristicsInterfaces general

Pagina 115 - 5.4.8 Device HA

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide201Trunks and the auxiliary interface have many characteristics that are specific to each t

Pagina 116 - 5.4.10 Policy Routes

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide202* - You cannot set up a PPPoE/PPTP interface, virtual Ethernet interface or virtual VLAN

Pagina 117 - 5.4.12 Firewall

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide203Figure 147 Network > Interface > Status Each field is described in the following

Pagina 118 - 5.4.15 IDP

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide204Status This field displays the current status of each interface. The possible values depe

Pagina 119 - 5.4.18 Anti-Spam

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide20510.3 The Port Role ScreenTo access this screen, click Network > Interface > Port

Pagina 120 - 5.4.21 ALG

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide206Each section in this screen is described below.10.4 The Ethernet Summary ScreenThis scre

Pagina 121 - 5.5 Objects

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide207Figure 149 Network > Interface > EthernetEach field is described in the followin

Pagina 122 - 5.6.2 File Manager

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide208" If you create IP address objects based on an interface’s IP address, subnet, or ga

Pagina 123 - 5.6.6 Diagnostics

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide209Figure 150 Network > Interface > Ethernet > Edit (Opt)

Pagina 124

Table of ContentsZyWALL USG 100/200 Series User’s Guide21Chapter 28Anti-Virus...

Pagina 125 - CHAPTER 6

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide210Each field is described in the table below. The OPT interface’s Edit > Configuration s

Pagina 126 - Chapter 6 Tutorials

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide211Ingress BandwidthThis is reserved for future use.Enter the maximum amount of traffic, in

Pagina 127 - Chapter 6 Tutorials

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide212More Settings/Less SettingsClick this button to display a greater or lesser number of con

Pagina 128

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide213Overwrite Default MAC AddressSelect this option to have the interface use a different MA

Pagina 129

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide21410.5 Interface WizardsYou can use the interface wizard (instead of the regular Ethernet

Pagina 130

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide215Figure 152 Interface Wizard: OPT Interface First Screen The following table descr

Pagina 131 - Figure 53 Status

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide216Figure 154 Interface Wizard: Non-WAN OPT Interface Setup The following table descr

Pagina 132

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide217Figure 155 Interface Wizard: WAN Interface Zone and IP Address Setup The following

Pagina 133

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide218The following table describes the labels in this screen. Table 56 Interface Wizard: WAN

Pagina 134

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide21910.5.6 Interface Wizard: Summary (Non-WAN)Use this screen to review the local interface

Pagina 135

Table of ContentsZyWALL USG 100/200 Series User’s Guide22Chapter 30 ADP ...

Pagina 136 - 6 Click Activate Now

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide220Figure 158 Interface Wizard: Summary WAN (PPTP Shown) The following table describe

Pagina 137

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide22110.6 The PPP Interfaces ScreenUse PPP interfaces (PPPoE/PPTP interfaces) to connect to

Pagina 138

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide22210.6.1 PPP Interface Edit ScreenThis screen lets you configure new or existing PPPoE/PPT

Pagina 139 - 5 Click Networks > Add

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide223Figure 161 Network > Interface > PPP > Edit > ConfigurationEach field is e

Pagina 140

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide224Description Enter a description of this interface. It is not used elsewhere. You can use

Pagina 141 - 2 Click Import

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide225Ingress BandwidthThis is reserved for future use.Enter the maximum amount of traffic, in

Pagina 142

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide22610.7 Cellular Configuration Screen (3G)3G (Third Generation) is a digital, packet-switch

Pagina 143

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide227" Install (or connect) a compatible 3G card to use a cellular connection. See Chapt

Pagina 144 - Figure 78 VPN Example

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide22810.7.1 Cellular Add/Edit ScreenTo change your 3G settings, click Network > Interface

Pagina 145

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide229The following table describes the labels in this screen.Table 63 Interface > Cellul

Pagina 146

Table of ContentsZyWALL USG 100/200 Series User’s Guide2333.2 Before You Begin ...

Pagina 147

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide230PIN Code This field displays with a GSM or HSDPA 3G card. A PIN (Personal Identification

Pagina 148

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide23110.8 Cellular Status ScreenTo check your 3G connection status, click Network > Inter

Pagina 149

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide232The following table describes the labels in this screen.Table 64 Interface > Cellula

Pagina 150

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide23310.9 WLAN Interface General ScreenThe following figure provides an example of a wireles

Pagina 151

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide234Figure 166 Network > Interface > WLAN The following table describes the general w

Pagina 152

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide23510.9.1 WLAN Add/Edit ScreenUse the strongest security that every wireless client in the

Pagina 153

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide236• WPA2-PSK and WPA-PSK do not employ user authentication and are known as the personal ve

Pagina 154 - Figure 99 Trunk Example

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide237Figure 167 Network > Interface > WLAN > Add (No Security)

Pagina 155

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide238The following table describes the general wireless LAN labels in this screen.Table 67 N

Pagina 156

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide239Egress BandwidthEnter the maximum amount of traffic, in kilobits per second, the ZyWALL

Pagina 157 - Figure 102 System > WWW

Table of ContentsZyWALL USG 100/200 Series User’s Guide2435.4.1 Force User Authentication Policy Add/Edit Screen ...

Pagina 158 - 6 Click Apply

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide240Lease time Specify how long each computer can use the information (especially the IP addr

Pagina 159

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide24110.9.2 WLAN Add/Edit Screen: WEP SecurityWEP provides a mechanism for encrypting data u

Pagina 160 - 6.8.1 How to Turn On the ALG

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide242Figure 169 Network > Interface > WLAN > Add (WEP Security) The following table

Pagina 161

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide243The following table describes the WPA-PSK/WPA2-PSK-related wireless LAN security labels

Pagina 162 - 6.9 How to Use Device HA

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide244The following table describes the WPA/WPA2-related wireless LAN security labels. Table 70

Pagina 163 - 6.9.1 Before You Start

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide24510.10 WLAN Interface MAC Filter ScreenThe MAC filter allows you to give specific wirele

Pagina 164

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide246If you set the filter to deny access and add the MAC address of a connected device, the Z

Pagina 165

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide24710.12 VLAN Interface ScreenA Virtual Local Area Network (VLAN) divides a physical netwo

Pagina 166

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide248Figure 176 Example: After VLANEach VLAN is a separate network with separate IP addresse

Pagina 167

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide249" Each VLAN interface is created on top of only one Ethernet interface.Otherwise, V

Pagina 168

Table of ContentsZyWALL USG 100/200 Series User’s Guide2539.3 Active Directory or LDAP Group Summary Screen ...

Pagina 169

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide25010.12.2 Configuring the VLAN Add/Edit ScreenThis screen lets you configure IP address as

Pagina 170

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide251Figure 178 Network > Interface > VLAN > EditEach field is explained in the fo

Pagina 171 - CHAPTER 7

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide252Interface Name This field is read-only if you are editing an existing VLAN interface. Ent

Pagina 172 - Table 32 Status

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide253Connectivity Check The interface can regularly check the connection to the gateway you s

Pagina 173 - Table 32 Status (continued)

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide254IP Pool Start AddressEnter the IP address from which the ZyWALL begins allocating IP addr

Pagina 174

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide25510.13 Bridge Interface ScreenA bridge creates a connection between two or more network

Pagina 175 - 7.2.1 The CPU Usage Screen

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide256Bridge Interface OverviewA bridge interface creates a software bridge between the members

Pagina 176

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide25710.13.2 Configuring the Bridge Add/Edit ScreenThis screen lets you configure IP address

Pagina 177

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide258Figure 182 Network > Interface > Bridge > Add

Pagina 178 - 7.2.4 The VPN Status Screen

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide259Each field is described in the table below.Table 80 Network > Interface > Bridge

Pagina 179 - 7.2.5 The DHCP Table Screen

Table of ContentsZyWALL USG 100/200 Series User’s Guide26Chapter 43 System ...

Pagina 180

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide260Interface ParametersEgress BandwidthEnter the maximum amount of traffic, in kilobits per

Pagina 181

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide26110.14 Auxiliary Interface ScreenUse the auxiliary interface as a backup WAN interface o

Pagina 182

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide262" You must connect an external modem to use the auxiliary port.The ZyWALL uses the a

Pagina 183

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide26310.15 Virtual Interface ScreenUse virtual interfaces to tell the ZyWALL where to route

Pagina 184

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide264Like other interfaces, virtual interfaces have an IP address, subnet mask, and gateway us

Pagina 185 - CHAPTER 8

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide26510.16 Interface Technical ReferenceHere is more detailed information about interfaces o

Pagina 186 - 8.2 The Registration Screen

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide266In the example above, if the ZyWALL gets a packet with a destination address of 5.5.5.5,

Pagina 187 - Chapter 8 Registration

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide267In DHCP, every network has at least one DHCP server. When a computer (a DHCP client) joi

Pagina 188 - Chapter 8 Registration

Chapter 10 InterfaceZyWALL USG 100/200 Series User’s Guide268WINSWINS (Windows Internet Naming Service) is a Windows implementation of NetBIOS Name Se

Pagina 189 - 8.3 The Service Screen

ZyWALL USG 100/200 Series User’s Guide269CHAPTER 11 Trunks11.1 OverviewUse trunks for WAN traffic load balancing to increase overall network through

Pagina 190

Table of ContentsZyWALL USG 100/200 Series User’s Guide2743.12 Vantage CNM ...

Pagina 191 - CHAPTER 9

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide270• If that interface’s connection goes down, the ZyWALL can still send its traffic through an

Pagina 192 - Chapter 9 Signature Update

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide271Least Load First The least load first algorithm uses the current (or recent) outbound bandw

Pagina 193 - Chapter 9 Signature Update

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide272Figure 189 Weighted Round Robin Algorithm ExampleSpilloverThe spillover load balancing alg

Pagina 194

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide273Figure 191 Network > Interface > Trunk The following table describes the items in t

Pagina 195

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide274Figure 192 Network > Interface > Trunk > EditEach field is described in the table

Pagina 196

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide27511.3 Trunk Technical ReferenceRound Robin Load Balancing AlgorithmRound Robin scheduling s

Pagina 197

Chapter 11 TrunksZyWALL USG 100/200 Series User’s Guide276

Pagina 198

ZyWALL USG 100/200 Series User’s Guide277CHAPTER 12 Policy and Static Routes12.1 Policy and Static Routes OverviewUse policy routes and static route

Pagina 199 - CHAPTER 10

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide27812.1.1 What You Can Do in the Policy and Static Route Screens•Use the Pol

Pagina 200 - Chapter 10 Interface

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide279Policy Routes Versus Static Routes• Policy routes are more flexible than

Pagina 201 - Chapter 10 Interface

Table of ContentsZyWALL USG 100/200 Series User’s Guide28Chapter 48Reboot...

Pagina 202

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide280The following table describes the labels in this screen. Table 89 Netwo

Pagina 203

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide28112.2.1 Policy Route Edit ScreenClick Network > Routing to open the Po

Pagina 204

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide282Schedule Select a schedule or select Create Object to configure a new one

Pagina 205 - 10.3 The Port Role Screen

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide28312.3 IP Static Route ScreenClick Network > Routing > Static Route

Pagina 206

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide284Figure 196 Network > Routing > Static RouteThe following table des

Pagina 207

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide28512.4 Policy Routing Technical ReferenceHere is more detailed information

Pagina 208

Chapter 12 Policy and Static RoutesZyWALL USG 100/200 Series User’s Guide286Incoming service: Game (UDP: 1234)Trigger service: Game-1 (UDP: 5670-5678)

Pagina 209

ZyWALL USG 100/200 Series User’s Guide287CHAPTER 13 Routing Protocols13.1 Routing Protocols OverviewRouting protocols give the ZyWALL routing inform

Pagina 210

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide28813.2 The RIP ScreenRIP (Routing Information Protocol, RFC 1058 and RFC 1389) all

Pagina 211

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide28913.3 The OSPF ScreenOSPF (Open Shortest Path First, RFC 2328) is a link-state p

Pagina 212

List of FiguresZyWALL USG 100/200 Series User’s Guide29List of FiguresFigure 1 ZyWALL USG 200 Front Panel ...

Pagina 213

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide290• A normal area is a group of adjacent networks. A normal area has routing inform

Pagina 214 - 10.5 Interface Wizards

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide291• An Area Border Router (ABR) connects two or more areas. It is a member of all

Pagina 215

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide292Figure 202 OSPF: Virtual LinkIn this example, area 100 does not have a direct c

Pagina 216

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide293The following table describes the labels in this screen. See Section 13.3.2 on p

Pagina 217

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide294Figure 204 Network > Routing > OSPF > EditThe following table describe

Pagina 218

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide29513.4 Routing Protocol Technical ReferenceHere is more detailed information abou

Pagina 219

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide296• The packet’s message-digest is the same as the one the ZyWALL calculates using

Pagina 220

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide297

Pagina 221

Chapter 13 Routing ProtocolsZyWALL USG 100/200 Series User’s Guide298

Pagina 222

ZyWALL USG 100/200 Series User’s Guide299CHAPTER 14 Zones14.1 Zones OverviewSet up zones to configure network security and network policies in the

Pagina 223

About This User's GuideZyWALL USG 100/200 Series User’s Guide3About This User's GuideIntended AudienceThis manual is intended for people w

Pagina 224

List of FiguresZyWALL USG 100/200 Series User’s Guide30Figure 39 VPN Advanced Wizard: Step 2 ...

Pagina 225

Chapter 14 ZonesZyWALL USG 100/200 Series User’s Guide30014.1.2 What You Need to Know About ZonesEffects of Zones on Different Types of TrafficZones

Pagina 226

Chapter 14 ZonesZyWALL USG 100/200 Series User’s Guide301Figure 206 Network > Zone The following table describes the labels in this screen.

Pagina 227

Chapter 14 ZonesZyWALL USG 100/200 Series User’s Guide302Member List Available Interface lists the interfaces that do not belong to any zone. The word

Pagina 228

ZyWALL USG 100/200 Series User’s Guide303CHAPTER 15 DDNS15.1 DDNS OverviewDynamic DNS (DDNS) services let you use a domain name with a dynamic IP a

Pagina 229

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide304" Record your DDNS account’s user name, password, and domain name to use to configure the

Pagina 230

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide30515.2.1 The Dynamic DNS Add/Edit ScreenThe DDNS Add/Edit screen allows you to add a domain na

Pagina 231 - 10.8 Cellular Status Screen

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide306The following table describes the labels in this screen. Table 102 Network > DDNS > Ad

Pagina 232

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide30715.3 The DDNS Status ScreenThe DDNS Status screen shows the status of the ZyWALL’s DDNS doma

Pagina 233

Chapter 15 DDNSZyWALL USG 100/200 Series User’s Guide308Figure 210 Network > DDNS > Status The following table describes the labels in

Pagina 234

ZyWALL USG 100/200 Series User’s Guide309CHAPTER 16 Virtual Servers16.1 Virtual Servers OverviewVirtual servers are computers on a private network b

Pagina 235 - 10.9.1 WLAN Add/Edit Screen

List of FiguresZyWALL USG 100/200 Series User’s Guide31Figure 82 Network > Routing > Policy Route ...

Pagina 236

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide310Finding Out More• See Section 5.4.19 on page 119 for related information on these s

Pagina 237

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide31116.2.1 The Virtual Server Add/Edit ScreenThe Virtual Server Add/Edit screen lets

Pagina 238

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide312Original IP Use the drop-down list box to indicate which destination IP address thi

Pagina 239

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide31316.3 NAT 1:1 and NAT Loopback ExamplesThe following sections provide examples of

Pagina 240

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide314NAT 1:1 Address ObjectsFirst create two address objects for the private and public

Pagina 241

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide315Figure 217 NAT 1:1 Example Virtual ServerThe wan2 interface has a different IP a

Pagina 242

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide316Figure 219 NAT 1:1 Example Policy RouteClick Network > Routing > Policy Rou

Pagina 243

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide317Figure 221 Create a Firewall RuleNAT Loopback ExampleThe NAT 1:1 Example on page

Pagina 244

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide318NAT Loopback Virtual ServerWhen a LAN1 user sends SMTP traffic to IP address 1.1.1.

Pagina 245

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide319NAT Loopback Policy RouteWithout a NAT loopback policy route, the LAN1 user SMTP t

Pagina 246

List of FiguresZyWALL USG 100/200 Series User’s Guide32Figure 125 Creating the Address Object for the wan2 Public IP Address ...

Pagina 247 - 10.12 VLAN Interface Screen

Chapter 16 Virtual ServersZyWALL USG 100/200 Series User’s Guide320Figure 227 Create a Policy RouteNow the LAN1 SMTP server replies to the ZyWALL’s

Pagina 248

ZyWALL USG 100/200 Series User’s Guide321CHAPTER 17 HTTP Redirect17.1 OverviewHTTP redirect forwards the client’s HTTP request (except HTTP traffic

Pagina 249

Chapter 17 HTTP RedirectZyWALL USG 100/200 Series User’s Guide32217.1.2 What You Need to Know About HTTP RedirectWeb Proxy ServerA proxy server helps

Pagina 250

Chapter 17 HTTP RedirectZyWALL USG 100/200 Series User’s Guide323" You can configure up to one HTTP redirect rule for each (incoming) interface.

Pagina 251

Chapter 17 HTTP RedirectZyWALL USG 100/200 Series User’s Guide324The following table describes the labels in this screen. Table 107 Network > HTT

Pagina 252

ZyWALL USG 100/200 Series User’s Guide325CHAPTER 18 ALG18.1 ALG OverviewApplication Layer Gateway (ALG) allows the following applications to operate

Pagina 253

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide32618.1.2 What You Need to Know About ALGApplication Layer Gateway (ALG), NAT and FirewallThe ZyW

Pagina 254

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide327• The SIP ALG allows UDP packets with a specified port destination to pass through.• The ZyWAL

Pagina 255 - Figure 180 Bridge Example

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide328For example, you configure firewall and virtual server rules to allow LAN IP address A to recei

Pagina 256

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide329Figure 236 Network > ALG The following table describes the labels in this screen. Table

Pagina 257

List of FiguresZyWALL USG 100/200 Series User’s Guide33Figure 168 Network > Interface > Ethernet > Edit > Edit static DHCP table ...

Pagina 258

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide33018.3 ALG Technical ReferenceHere is more detailed information about the Application Layer Gate

Pagina 259

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide331H.323H.323 is a standard teleconferencing protocol suite that provides audio, data and video c

Pagina 260

Chapter 18 ALGZyWALL USG 100/200 Series User’s Guide332

Pagina 261

333PART IIIFirewallFirewall (335)

Pagina 263 - ATZ is the most

ZyWALL USG 100/200 Series User’s Guide335CHAPTER 19 Firewall19.1 OverviewUse the firewall to block or allow services that use static port numbers.

Pagina 264

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide33619.1.2 What You Need to Know About the FirewallStateful InspectionThe ZyWALL has a statef

Pagina 265

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide337To-ZyWALL Rules Rules with ZyWALL as the To Zone apply to traffic going to the ZyWALL its

Pagina 266

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide338Firewall and VPN TrafficAfter you create a VPN tunnel and add it to a zone, you can set th

Pagina 267

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide339• The second row is the firewall’s default policy that allows all traffic from the LAN to

Pagina 268

List of FiguresZyWALL USG 100/200 Series User’s Guide34Figure 211 Multiple Servers Behind NAT Example ...

Pagina 269 - CHAPTER 11

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide340• The third row is (still) the firewall’s default policy of allowing all traffic from LAN1

Pagina 270 - Figure 187 Link Sticking

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide341Figure 240 Firewall Example: Select the Traveling Direction of Traffic2 Select From WA

Pagina 271 - Chapter 11 Trunks

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide342Figure 243 Firewall Example: Create a Service Object6 Enter the name of the firewall rul

Pagina 272

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide34319.2 The Firewall ScreenAsymmetrical RoutesIf an alternate gateway on LAN1 has an IP add

Pagina 273

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide344• Besides configuring the firewall, you also need to configure virtual servers (NAT port f

Pagina 274

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide345From ZoneTo ZoneThis is the direction of travel of packets. Select from which zone the pa

Pagina 275

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide34619.2.2 The Firewall Edit ScreenIn the Firewall screen, click the Edit or Add icon to disp

Pagina 276

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide347Description Enter a descriptive name of up to 60 printable ASCII characters for the firew

Pagina 277 - CHAPTER 12

Chapter 19 FirewallZyWALL USG 100/200 Series User’s Guide348

Pagina 278

349PART IVVPNIPSec VPN (351)SSL VPN (385)SSL User Screens (395)SSL User Application Screens (401)SSL User File Sharing (403)L2TP VPN (409)L2TP V

Pagina 279 - 12.2 Policy Route Screen

List of FiguresZyWALL USG 100/200 Series User’s Guide35Figure 254 VPN > IPSec VPN > VPN Gateway ...

Pagina 281

ZyWALL USG 100/200 Series User’s Guide351CHAPTER 20 IPSec VPN20.1 IPSec VPN OverviewA virtual private network (VPN) provides secure communications b

Pagina 282

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide352• Use the VPN Concentrator screens (see Section 20.4 on page 369) to combine several IPSe

Pagina 283 - 12.3 IP Static Route Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide353You should set up the following features before you set up the VPN tunnel.• In any VPN c

Pagina 284

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide354Each field is discussed in the following table. See Section 20.2.2 on page 360 and Sectio

Pagina 285 - Port Triggering

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide35520.2.1 The VPN Connection Add/Edit (IKE) ScreenThe VPN Connection Add/Edit Gateway scre

Pagina 286 - Maximize Bandwidth Usage

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide356Figure 252 VPN > IPSec VPN > VPN Connection > Edit (IKE)

Pagina 287 - CHAPTER 13

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide357Each field is described in the following table. Table 116 VPN > IPSec VPN > VPN

Pagina 288 - 13.2 The RIP Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide358SA Life Time Type the maximum number of seconds the IPSec SA can last. Shorter life time

Pagina 289 - 13.3 The OSPF Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide359Related SettingsAdd this VPN connection to IPSec_VPN zone.Select this check box to add t

Pagina 290 - Chapter 13 Routing Protocols

List of FiguresZyWALL USG 100/200 Series User’s Guide36Figure 297 VPN > L2TP VPN ...

Pagina 291 - Chapter 13 Routing Protocols

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide36020.2.2 The VPN Connection Add/Edit Manual Key Screen The VPN Connection Add/Edit Manual

Pagina 292

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide361Figure 253 VPN > IPSec VPN > VPN Connection > Manual Key > EditThis table

Pagina 293

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide362Encapsulation ModeSelect which type of encapsulation the IPSec SA uses. Choices areTunnel

Pagina 294

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide36320.3 The VPN Gateway ScreenThe VPN Gateway summary screen displays the IPSec VPN gatewa

Pagina 295

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide36420.3.1 The VPN Gateway Add/Edit ScreenThe VPN Gateway Add/Edit screen allows you to crea

Pagina 296

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide365Figure 255 VPN > IPSec VPN > VPN Gateway > EditEach field is described in the

Pagina 297

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide366Peer Gateway AddressSelect how the IP address of the remote IPSec router in the IKE SA is

Pagina 298

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide367Peer ID Type Select which type of identification is used to identify the remote IPSec ro

Pagina 299 - CHAPTER 14

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide368Encryption Select which key size and encryption algorithm to use in the IKE SA. Choices a

Pagina 300 - 14.2 The Zone Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide36920.4 The VPN Concentrator ScreenA VPN concentrator combines several IPSec VPN connectio

Pagina 301 - 14.2.1 The Zone Edit Screen

List of FiguresZyWALL USG 100/200 Series User’s Guide37Figure 340 IP Security Policy Properties: IP Filter List ...

Pagina 302 - Chapter 14 Zones

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide370Figure 257 VPN > IPSec VPN > ConcentratorEach field is discussed in the following

Pagina 303 - CHAPTER 15

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide37120.5 The SA Monitor Screen You can use the SA Monitor screen to display and to manage a

Pagina 304 - 15.2 The DDNS Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide372Figure 260 VPN > IPSec VPN > SA MonitorEach field is described in the following t

Pagina 305 - Chapter 15 DDNS

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide37320.6 IPSec VPN Background InformationHere is some more detailed IPSec VPN background in

Pagina 306 - DDNS server

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide374The ZyWALL sends one or more proposals to the remote IPSec router. (In some devices, you

Pagina 307 - 15.3 The DDNS Status Screen

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide375DH public-key cryptography is based on DH key groups. Each key group is a fixed number o

Pagina 308 - Chapter 15 DDNS

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide376Router identity consists of ID type and content. The ID type can be domain name, IP addre

Pagina 309 - CHAPTER 16

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide377Main mode takes six steps to establish an IKE SA.Steps 1 - 2: The ZyWALL sends its propo

Pagina 310 - Chapter 16 Virtual Servers

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide378Extended AuthenticationExtended authentication is often used when multiple IPSec routers

Pagina 311 - It can

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide379IPSec SA OverviewOnce the ZyWALL and remote IPSec router have established the IKE SA, th

Pagina 312

List of FiguresZyWALL USG 100/200 Series User’s Guide38Figure 383 Anti-X > IDP > Profile > Edit > IDP Service Group ...

Pagina 313 - NAT 1:1 Example

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide380These modes are illustrated below.In tunnel mode, the ZyWALL uses the active protocol to

Pagina 314 - NAT 1:1 Virtual Server

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide381IPSec SA using Manual KeysYou might set up an IPSec SA using manual keys when you want t

Pagina 315 - NAT 1:1 Policy Route

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide382Figure 266 VPN Example: NAT for Inbound and Outbound TrafficSource Address in Outbound

Pagina 316 - NAT 1:1 Firewall Rule

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide383You have to specify one or more rules when you set up this kind of NAT. The ZyWALL check

Pagina 317 - NAT Loopback Example

Chapter 20 IPSec VPNZyWALL USG 100/200 Series User’s Guide384

Pagina 318 - NAT Loopback Virtual Server

ZyWALL USG 100/200 Series User’s Guide385CHAPTER 21 SSL VPN21.1 OverviewUse SSL VPN to allow users to use a web browser for secure remote user login

Pagina 319 - NAT Loopback Policy Route

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide386Full Tunnel Mode In full tunnel mode, a virtual connection is created for remote users with

Pagina 320

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide387Finding Out More• See Section 5.4.5 on page 115 for related information on these screens.•

Pagina 321 - CHAPTER 17

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide388Figure 270 VPN > SSL VPN > Access Privilege > Add/Edit The following table desc

Pagina 322 - Chapter 17 HTTP Redirect

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide38921.3 The SSL Connection Monitor Screen The ZyWALL keeps track of the users who are curren

Pagina 323 - Chapter 17 HTTP Redirect

List of FiguresZyWALL USG 100/200 Series User’s Guide39Figure 426 Anti-X > Anti-Spam > Black/White List > White List ...

Pagina 324

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide390• Log out individual users and delete related session information. Once a user logs out, th

Pagina 325 - CHAPTER 18

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide391Figure 272 VPN > SSL VPN > Global Setting The following table describes the labels

Pagina 326 - Chapter 18 ALG

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide39221.4.1 How to Upload a Custom LogoFollow the steps below to upload a custom logo to displa

Pagina 327 - Chapter 18 ALG

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide393Figure 274 SSL VPN Client Portal Screen Example If the user account is not set up for SS

Pagina 328 - 18.2 The ALG Screen

Chapter 21 SSL VPNZyWALL USG 100/200 Series User’s Guide394

Pagina 329 - Table 108 Network > ALG

ZyWALL USG 100/200 Series User’s Guide395CHAPTER 22 SSL User Screens22.1 OverviewThis chapter introduces the remote user SSL VPN screens. The follow

Pagina 330 - 18.3 ALG Technical Reference

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide396• Firefox 1.0 and above• Mozilla 1.7.3 and above• Sun’s Java (Java Runtime Environ

Pagina 331

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide397Figure 277 Login Security Screen 3 A login screen displays. Enter the user na

Pagina 332

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide398Figure 280 SecuExtender Progress 7 The Application screen displays showing the

Pagina 333 - PART III

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide399The following table describes the various parts of a remote user screen. 22.4 Bo

Pagina 334

About This User's GuideZyWALL USG 100/200 Series User’s Guide4Click the help icon in any screen for help in configuring that screen and supplemen

Pagina 335 - CHAPTER 19

List of FiguresZyWALL USG 100/200 Series User’s Guide40Figure 469 Object > AAA Server > RADIUS > Group > Add ...

Pagina 336 - Chapter 19 Firewall

Chapter 22 SSL User ScreensZyWALL USG 100/200 Series User’s Guide400Figure 284 Logout: Connection Termination Progress

Pagina 337 - Chapter 19 Firewall

ZyWALL USG 100/200 Series User’s Guide401CHAPTER 23 SSL User Application Screens23.1 SSL User Application Screens OverviewUse the Application screen

Pagina 338

Chapter 23 SSL User Application ScreensZyWALL USG 100/200 Series User’s Guide402

Pagina 339

ZyWALL USG 100/200 Series User’s Guide403CHAPTER 24 SSL User File Sharing24.1 OverviewThe File Sharing screen lets you access files on a file server

Pagina 340

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide404Figure 286 File Sharing 24.3 Opening a File or FolderYou can open a file i

Pagina 341

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide4054 A list of files/folders displays. Click on a file to open it in a separate

Pagina 342

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide406Figure 289 File Sharing: Save a Word File 24.4 Creating a New FolderTo cr

Pagina 343 - 19.2 The Firewall Screen

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide407Figure 291 File Sharing: Rename A popup window displays. Specify the new n

Pagina 344 - Table 113 Firewall

Chapter 24 SSL User File SharingZyWALL USG 100/200 Series User’s Guide40824.7 Uploading a FileFollow the steps below to upload a file to the file ser

Pagina 345

ZyWALL USG 100/200 Series User’s Guide409CHAPTER 25 L2TP VPN25.1 OverviewL2TP VPN lets remote users use the L2TP and IPSec client software included

Pagina 346

List of FiguresZyWALL USG 100/200 Series User’s Guide41Figure 512 SSL Client Authentication ...

Pagina 347

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide410IPSec Configuration Required for L2TP VPNYou must configure an IPSec VPN connection for L2

Pagina 348

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide411Finding Out More• See Section 5.4.6 on page 115 for related information on these screens.

Pagina 349

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide41225.3 L2TP VPN Session Monitor ScreenClick VPN > L2TP VPN > Session Monitor to open

Pagina 350

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide413Hostname This field displays the name of the computer that has this L2TP VPN connection w

Pagina 351 - CHAPTER 20

Chapter 25 L2TP VPNZyWALL USG 100/200 Series User’s Guide414

Pagina 352 - 20.1.3 Before You Begin

ZyWALL USG 100/200 Series User’s Guide415CHAPTER 26 L2TP VPN ExampleThis chapter shows how to create a basic L2TP VPN tunnel.26.1 L2TP VPN ExampleTh

Pagina 353 - Chapter 20 IPSec VPN

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide416Figure 300 VPN > IPSec VPN > VPN Gateway > Edit • Configure the My Addr

Pagina 354 - Chapter 20 IPSec VPN

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide417Figure 302 VPN > IPSec VPN > VPN Connection > Edit 2 Click the Policy

Pagina 355

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide41826.4 Configuring the L2TP VPN Settings Example1 Click VPN > L2TP VPN to open t

Pagina 356

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide419Figure 305 Routing > Add: L2TP VPN Example2 Configure the following.• Enable

Pagina 357

List of FiguresZyWALL USG 100/200 Series User’s Guide42Figure 555 WLAN Card Installation ...

Pagina 358

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide4202 Click Next in the Welcome screen.3 Select Connect to the network at my workplace

Pagina 359

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide421Figure 308 New Connection Wizard: Connection Name6 Select Do not dial the initi

Pagina 360

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide422Figure 310 New Connection Wizard: VPN Server Selection8 Click Finish.9 The Conne

Pagina 361

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide423Figure 312 Connect L2TP to ZyWALL: Security11 Select Optional encryption (conne

Pagina 362 - 1234567890XYZ for a DES

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide424Figure 314 L2TP to ZyWALL Properties > Security13 Select the Use pre-shared k

Pagina 363 - 20.3 The VPN Gateway Screen

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide425Figure 317 Connect L2TP to ZyWALL16 A window appears while the user name and pa

Pagina 364

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide4261 Click Start > Run. Type regedit and click OK.Figure 320 Starting the Regist

Pagina 365

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide427Figure 323 ProhibitIpSec DWORD Value6 Restart the computer and continue with th

Pagina 366

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide428Figure 326 Add > IP Security Policy Management > Finish4 Right-click IP Se

Pagina 367

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide429Figure 328 IP Security Policy: Name6 Clear the Activate the default response ru

Pagina 368

List of TablesZyWALL USG 100/200 Series User’s Guide43List of TablesTable 1 Front Panel LEDs ...

Pagina 369

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide4308 In the properties dialog box, click Add > Next.Figure 331 IP Security Polic

Pagina 370

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide431Figure 333 IP Security Policy Properties: Network Type11 Select Use this string

Pagina 371 - 20.5 The SA Monitor Screen

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide432Figure 335 IP Security Policy Properties: IP Filter List13 Type ZyWALL WAN_IP in

Pagina 372

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide433Figure 337 Filter Properties: Addressing15 Configure the following in the Filte

Pagina 373 - IKE SA Overview

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide434Figure 339 IP Security Policy Properties: IP Filter List17 Select Require Secur

Pagina 374

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide43526.6.2.3 Configure the Windows 2000 Network ConnectionAfter you have configured

Pagina 375 - Authentication

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide436Figure 344 New Connection Wizard: Destination Address4 Select For all users and

Pagina 376 - Additional Topics for IKE SA

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide4376 Click Properties.Figure 347 Connect L2TP to ZyWALL7 Click Security and select

Pagina 377 - Figure 264 VPN/NAT Example

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide438Figure 349 Connect L2TP to ZyWALL: Security > Advanced9 Click Networking and

Pagina 378

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide439Figure 351 Connect L2TP to ZyWALL11 A ZyWALL-L2TP icon displays in your system

Pagina 379 - IPSec SA Overview

List of TablesZyWALL USG 100/200 Series User’s Guide44Table 39 Status > Port Statistics > Switch to Graphic View ...

Pagina 380

Chapter 26 L2TP VPN ExampleZyWALL USG 100/200 Series User’s Guide440

Pagina 381

441PART VApplication PatrolApplication Patrol (443)

Pagina 383

ZyWALL USG 100/200 Series User’s Guide443CHAPTER 27 Application Patrol27.1 OverviewApplication patrol provides a convenient way to manage the use of

Pagina 384

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide44427.1.2 What You Need to Know About Application Patrol" The ZyWALL checks

Pagina 385 - CHAPTER 21

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide445The application patrol bandwidth management is more flexible and powerful than

Pagina 386 - Table 125 Objects

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide446• Inbound traffic is limited to 500 kbs. The connection initiator is on LAN1 so

Pagina 387 - Chapter 21 SSL VPN

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide447Figure 356 Bandwidth Management BehaviorConfigured Rate EffectIn the followin

Pagina 388

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide448Priority and Over Allotment of Bandwidth EffectServer A has a configured rate th

Pagina 389

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide449Figure 357 Application Patrol Bandwidth Management Example27.1.3.1 Setting t

Pagina 390

List of TablesZyWALL USG 100/200 Series User’s Guide45Table 82 Network > Interface > Bridge > Add ...

Pagina 391

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide450Figure 358 SIP Any to WAN Bandwidth Management Example27.1.3.3 SIP WAN to Any

Pagina 392

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide451Figure 360 FTP WAN to DMZ Bandwidth Management Example27.1.3.6 FTP LAN to DM

Pagina 393

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide452" You must register for the IDP/AppPatrol signature service (at least the t

Pagina 394

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide45327.3 Application Patrol ApplicationsUse the application patrol Common, Instant

Pagina 395 - CHAPTER 22

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide45427.3.1 The Application Patrol Edit ScreenUse this screen to edit the settings f

Pagina 396 - 22.2 Remote User Login

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide455Service Port This is available if the Classification is Service Ports. You can

Pagina 397 - Figure 278 Login Screen

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide45627.3.2 The Application Patrol Policy Edit Screen The Application Policy Edit sc

Pagina 398 - Chapter 22 SSL User Screens

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide457Schedule Select a schedule that defines when the policy applies or select Creat

Pagina 399 - 22.4 Bookmarking the ZyWALL

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide45827.4 The Other Applications ScreenSometimes, the ZyWALL cannot identify the app

Pagina 400

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide459Figure 366 AppPatrol > OtherThe following table describes the labels in th

Pagina 401 - CHAPTER 23

List of TablesZyWALL USG 100/200 Series User’s Guide46Table 125 Objects ...

Pagina 402

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide46027.4.1 The Other Applications Add/Edit ScreenThe Other Configuration Add/Edit s

Pagina 403 - CHAPTER 24

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide461Figure 367 AppPatrol > Other > EditThe following table describes the la

Pagina 404 - Figure 286 File Sharing

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide46227.5 Application Patrol StatisticsThis screen displays a bandwidth usage graph

Pagina 405 - 24.3.2 Saving a File

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide463Figure 368 AppPatrol > Statistics: General SetupThe following table descri

Pagina 406 - 24.4 Creating a New Folder

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide464• Different colors represent different protocols.27.5.3 Application Patrol Sta

Pagina 407

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide465Inbound Kbps This is the incoming bandwidth usage for traffic that matched this

Pagina 408 - 24.7 Uploading a File

Chapter 27 Application PatrolZyWALL USG 100/200 Series User’s Guide466

Pagina 409 - CHAPTER 25

467PART VIAnti-XAnti-Virus (469)IDP (483)ADP (513)Content Filtering (531)Content Filter Reports (551)Anti-Spam (559)

Pagina 411 - 25.2 L2TP VPN Screen

ZyWALL USG 100/200 Series User’s Guide469CHAPTER 28 Anti-Virus28.1 OverviewUse the ZyWALL’s anti-virus feature to protect your connected network fro

Pagina 412

List of TablesZyWALL USG 100/200 Series User’s Guide47Table 168 ADP > Profile > Traffic Anomaly ...

Pagina 413 - Chapter 25 L2TP VPN

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide47028.1.2 What You Need to Know About Anti-VirusAnti-Virus EnginesSubscribe to signature f

Pagina 414

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide471" Since the ZyWALL erases the infected portion of the file before sending it, you

Pagina 415 - CHAPTER 26

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide472Figure 372 Anti-X > Anti-Virus > General The following table describes the label

Pagina 416 - Chapter 26 L2TP VPN Example

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide47328.2.1 Anti-Virus Policy Add or Edit ScreenClick the Add or Edit icon in the Anti-X &g

Pagina 417 - Chapter 26 L2TP VPN Example

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide474Figure 373 Anti-X > Anti-Virus > General > Add The following table describes

Pagina 418

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide47528.3 Anti-Virus Black ListClick Anti-X > Anti-Virus > Black/White List to displa

Pagina 419

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide476Figure 374 Anti-X > Anti-Virus > Black/White List > Black ListThe following t

Pagina 420

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide477Figure 375 Anti-X > Anti-Virus > Black/White List > Black List (or White Lis

Pagina 421

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide478Figure 376 Anti-X > Anti-Virus > Black/White List > White List The following

Pagina 422 - 172.16.1.2

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide479Figure 377 Anti-X > Anti-Virus > Signature: Search by SeverityThe following tab

Pagina 423 - 12 Click IPSec Settings

List of TablesZyWALL USG 100/200 Series User’s Guide48Table 211 Object > AAA Server > Active Directory (or LDAP) > Default ...

Pagina 424 - Click OK

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide48028.7 Anti-Virus Technical ReferenceTypes of Computer Viruses The following table descri

Pagina 425

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide481• HAV scanners are slow in stopping virus threats through real-time traffic (such as fr

Pagina 426 - Figure 322 New DWORD Value

Chapter 28 Anti-VirusZyWALL USG 100/200 Series User’s Guide482

Pagina 427 - Figure 324 Run mmc

ZyWALL USG 100/200 Series User’s Guide483CHAPTER 29 IDP29.1 OverviewThis chapter introduces packet inspection IDP (Intrusion, Detection and Prevent

Pagina 428

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide484" You can only apply one IDP profile to one traffic flow.Base IDP ProfilesBase IDP profile

Pagina 429

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide485Figure 378 Anti-X > IDP > GeneralThe following table describes the screens in this scr

Pagina 430

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide48629.2.1 Configuring IDP PoliciesClick Anti-X > IDP > General and then an Add or Edit icon

Pagina 431 - 12 Click Add

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide487Figure 379 Anti-X > IDP > General > AddThe following table describes the screens in

Pagina 432

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide488Figure 380 Base ProfilesThe following table describes this screen. 29.4 The Profile Summary

Pagina 433

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide489Figure 381 Anti-X > IDP > ProfileThe following table describes the fields in this scre

Pagina 434

List of TablesZyWALL USG 100/200 Series User’s Guide49Table 254 Maintenance > Log > Log Setting ...

Pagina 435

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide4903 Type a new profile name4 Enable or disable individual signatures.5 Edit the default log optio

Pagina 436

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide491Figure 382 Anti-X > IDP > Profile > Edit : Group View

Pagina 437 - 6 Click Properties

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide492The following table describes the fields in this screen. Table 156 Anti-X > IDP > Prof

Pagina 438

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide49329.6.2 Policy TypesThis section describes IDP policy types, also known as attack types, as ca

Pagina 439

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide49429.6.3 IDP Service GroupsAn IDP service group is a set of related packet inspection signatures

Pagina 440

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide495The following figure shows the WEB_PHP service group that contains signatures related to attac

Pagina 441 - Application Patrol

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide496Figure 384 Anti-X > IDP > Profile: Query ViewThe following table describes the fields i

Pagina 442

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide49729.6.5 Query ExampleThis example shows a search with these criteria:• Severity: severe and hi

Pagina 443 - CHAPTER 27

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide498Figure 386 Query Example Search Results29.7 Introducing IDP Custom Signatures Create custom

Pagina 444 - Chapter 27 Application Patrol

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide499Figure 387 IP v4 Packet Headers The header fields are discussed below: Table 160 IP v4 Pa

Pagina 445

Document ConventionsZyWALL USG 100/200 Series User’s Guide5Document ConventionsWarnings and NotesThese are how warnings and notes are shown in this U

Pagina 446

List of TablesZyWALL USG 100/200 Series User’s Guide50Table 297 Device HA Logs ...

Pagina 447

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide50029.8 Configuring Custom SignaturesSelect Anti-X > IDP > Custom Signatures. The first scr

Pagina 448

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide501The following table describes the fields in this screen. 29.8.1 Creating or Editing a Custom

Pagina 449

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide502Figure 389 Anti-X > IDP > Custom Signatures > Add/Edit

Pagina 450

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide503The following table describes the fields in this screen. Table 162 Anti-X > IDP > Cust

Pagina 451

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide504IP Options IP options is a variable-length list of IP options for a datagram that define IP Sec

Pagina 452

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide50529.8.2 Custom Signature ExampleBefore creating a custom signature, you must first clearly und

Pagina 453

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide50629.8.2.2 Analyze PacketsThen use a packet sniffer such as TCPdump or Ethereal to investigate s

Pagina 454 - Table 139 Application Edit

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide507Figure 393 Example Custom Signature

Pagina 455

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide50829.8.3 Applying Custom SignaturesAfter you create your custom signature, it becomes available

Pagina 456

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide509Figure 395 Custom Signature Log29.9 IDP Technical ReferenceThis section contains some backg

Pagina 457

51PART IGetting StartedIntroducing the ZyWALL (53)Features and Applications (57)Web Configurator (65)Configuration Basics (109)Tutorials (125)Sta

Pagina 458

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide510The rule header contains the rule's:• Action•Protocol• Source and destination IP addresses

Pagina 459

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide511" Not all Snort functionality is supported in the ZyWALL.

Pagina 460

Chapter 29 IDPZyWALL USG 100/200 Series User’s Guide512

Pagina 461

ZyWALL USG 100/200 Series User’s Guide513CHAPTER 30 ADP30.1 OverviewThis chapter introduces ADP (Anomaly Detection and Prevention), anomaly profile

Pagina 462

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide514ADP ProfileAn ADP profile is a set of traffic anomaly rules and protocol anomaly rules that you

Pagina 463

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide515The following table describes the screens in this screen. 30.2.1 Configuring ADP PoliciesClic

Pagina 464

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide516The following table describes the screens in this screen. 30.3 The Profile Summary ScreenUse t

Pagina 465

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide517These are the default base profiles at the time of writing. 30.3.2 Configuring The ADP Profil

Pagina 466

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide518ADP profiles consist of traffic anomaly profiles and protocol anomaly profiles. To create a new

Pagina 467

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide519Figure 400 Profiles: Traffic Anomaly

Pagina 469 - CHAPTER 28

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide520The following table describes the fields in this screen. 30.3.5 Protocol Anomaly Profiles Pro

Pagina 470 - Chapter 28 Anti-Virus

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide521Protocol anomaly rules may be updated when you upload new firmware.30.3.6 Protocol Anomaly Co

Pagina 471 - 28.1.3 Before You Begin

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide522Figure 401 Profiles: Protocol Anomaly

Pagina 472

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide523The following table describes the fields in this screen. 30.4 Technical ReferenceThis sectio

Pagina 473 - Chapter 28 Anti-Virus

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide524Many connection attempts to different ports (services) may indicate a port scan. These are some

Pagina 474

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide525Flood DetectionFlood attacks saturate a network with useless data, use up all available bandwi

Pagina 475 - 28.3 Anti-Virus Black List

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide526Figure 403 TCP Three-Way HandshakeA SYN flood attack is when an attacker sends a series of SY

Pagina 476

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide527Protocol Anomaly Background InformationThe following sections may help you configure the proto

Pagina 477 - 28.5 Anti-Virus White List

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide528OVERSIZE-CHUNK-ENCODING ATTACKThis rule is an anomaly detector for abnormally large chunk sizes

Pagina 478 - 28.6 Signature Searching

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide529TRUNCATED-HEADER ATTACKThis is when a UDP packet is sent which has a UDP datagram length of le

Pagina 479

ZyWALL USG 100/200 Series User’s Guide53CHAPTER 1 Introducing the ZyWALLThis chapter gives an overview of the ZyWALL. It explains the front panel por

Pagina 480

Chapter 30 ADPZyWALL USG 100/200 Series User’s Guide530

Pagina 481

ZyWALL USG 100/200 Series User’s Guide531CHAPTER 31 Content Filtering31.1 OverviewUse the content filtering feature to control access to specific we

Pagina 482

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide532The ZyWALL can disable web proxies and block web features such as ActiveX control

Pagina 483 - CHAPTER 29

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide53331.2 Content Filter General ScreenClick Anti-X > Content Filter > General

Pagina 484 - 29.2 The IDP General Screen

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide534Filter Profile This column displays the name of the content filter profile that e

Pagina 485 - Chapter 29 IDP

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide53531.3 Content Filter Policy Add or Edit ScreenClick Anti-X > Content Filter &

Pagina 486 - Chapter 29 IDP

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide53631.4 Content Filter Profile Screen Click Anti-X > Content Filter > Filter

Pagina 487 - 29.3.1 Base Profiles

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide5371 Log into myZyXEL.com and click your device’s link to open it’s Service Managem

Pagina 488 - • Delete an existing profile

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide538Unrated Web Pages Select Block to prevent users from accessing web pages that the

Pagina 489 - 29.5 Creating New Profiles

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide539Alcohol/Tobacco Selecting this category excludes pages that promote or offer the

Pagina 490

Chapter 1 Introducing the ZyWALLZyWALL USG 100/200 Series User’s Guide54Figure 2 ZyWALL USG 100 Front PanelThe following table describes the LEDs.1.

Pagina 491

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide540Alternative Spirituality/OccultSelecting this category excludes pages that promot

Pagina 492

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide541Computers/Internet Selecting this category excludes pages that sponsor or provid

Pagina 493 - 29.6.2 Policy Types

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide542Religion Selecting this category excludes pages that promote and provide informat

Pagina 494 - 29.6.3 IDP Service Groups

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide54331.6 Content Filter Customization Screen Click Anti-X > Content Filter >

Pagina 495

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide544Figure 409 Anti-X > Content Filter > Filter Profile > Customization Th

Pagina 496

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide545Java Java is a programming language and development environment for building dow

Pagina 497 - 29.6.5 Query Example

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide54631.7 Content Filter Cache ScreenClick Anti-X > Content Filter > Cache to d

Pagina 498 - 29.7.1 IP Packet Header

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide547Figure 410 Anti-X > Content Filter > Cache The following table describes

Pagina 499

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide54831.8 Content Filter Technical ReferenceThis section provides content filtering b

Pagina 500

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide5493 Use the Content Filter Cache screen to configure how long a web site address r

Pagina 501

Chapter 1 Introducing the ZyWALLZyWALL USG 100/200 Series User’s Guide55Figure 3 Managing the ZyWALL: Web ConfiguratorCommand-Line Interface (CLI)T

Pagina 502

Chapter 31 Content FilteringZyWALL USG 100/200 Series User’s Guide550

Pagina 503 - number. Select

ZyWALL USG 100/200 Series User’s Guide551CHAPTER 32 Content Filter Reports32.1 OverviewYou can view content filtering reports after you have activat

Pagina 504

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide5523 A welcome screen displays. Click your ZyWALL’s model name and/or MAC addre

Pagina 505

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide5535 Enter your ZyXEL device's MAC address (in lower case) in the Name fi

Pagina 506

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide554Figure 417 Blue Coat: Report Home9 Select a time period in the Date Range

Pagina 507

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide555Figure 418 Global Report Screen Example11 You can click a category in the

Pagina 508

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide556Figure 419 Requested URLs Example32.3 Web Site SubmissionYou may find tha

Pagina 509 - 29.9 IDP Technical Reference

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide557Figure 420 Web Page Review Process Screen3 Type the web site’s URL in the

Pagina 510 - fragoffset

Chapter 32 Content Filter ReportsZyWALL USG 100/200 Series User’s Guide558

Pagina 511

ZyWALL USG 100/200 Series User’s Guide559CHAPTER 33 Anti-Spam33.1 OverviewThe anti-spam feature can mark or discard spam (unsolicited commercial or

Pagina 512

Chapter 1 Introducing the ZyWALLZyWALL USG 100/200 Series User’s Guide56" It is recommended you use the shutdown command before turning off the Z

Pagina 513 - CHAPTER 30

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide560matches a black list entry as spam and immediately takes the configured action for dealin

Pagina 514 - 30.2 The ADP General Screen

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide561Figure 421 DNSBL Example1 The ZyWALL checks the e-mail’s header for sender or relay IP

Pagina 515 - Chapter 30 ADP

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide562Figure 422 Anti-X > Anti-Spam > GeneralThe following table describes the labels i

Pagina 516 - 30.3.1 Base Profiles

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide56333.3.1 The Anti-Spam Policy Add or Edit ScreenClick the Add or Edit icon in the Anti-X

Pagina 517 - Table 166 Base Profiles

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide564The following table describes the labels in this screen.33.4 The Anti-Spam Black List Sc

Pagina 518 - Chapter 30 ADP

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide565Figure 424 Anti-X > Anti-Spam > Black/White List > Black ListThe following ta

Pagina 519

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide566Use this screen to configure an anti-spam black list entry to identify spam e-mail. You c

Pagina 520

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide56733.4.2 Regular Expressions in Black or White List EntriesThe following applies for a bl

Pagina 521

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide56833.6 The DNSBL Screen Click Anti-X > Anti-Spam > DNSBL to display the anti-spam DN

Pagina 522

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide569Figure 427 Anti-X > Anti-Spam > DNSBLThe following table describes the labels in

Pagina 523 - 30.4 Technical Reference

ZyWALL USG 100/200 Series User’s Guide57CHAPTER 2 Features and ApplicationsThis chapter introduces the main features and applications of the ZyWALL.2

Pagina 524

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide57033.6.1 The DNSBL Add/Edit ScreenClick the Add or Edit icon in the Anti-X > Anti-Spam

Pagina 525 - Flood Detection

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide571The following table describes the labels in this screen. 33.7 The Anti-Spam Status Scre

Pagina 526 - Figure 404 SYN Flood

Chapter 33 Anti-SpamZyWALL USG 100/200 Series User’s Guide572Avg. Response Time (sec)This is the average for how long it takes to receive a reply from

Pagina 527 - Section 30.3.5 on page 520)

573PART VIIDevice HADevice HA (575)

Pagina 529

ZyWALL USG 100/200 Series User’s Guide575CHAPTER 34 Device HA34.1 OverviewDevice HA lets a backup ZyWALL (B) automatically take over if a master Zy

Pagina 530

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide576Management AccessYou can configure a separate management IP address for each interface. Y

Pagina 531 - CHAPTER 31

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide577Figure 431 Device HA > GeneralThe following table describes the labels in this scre

Pagina 532 - 31.1.3 Before You Begin

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide57834.3 The Active-Passive Mode Screen Virtual RouterThe master and backup ZyWALL form a si

Pagina 533 - Chapter 31 Content Filtering

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide579Enable monitoring for the same interfaces on the master and backup ZyWALLs. Each monitor

Pagina 534 - Chapter 31 Content Filtering

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide58Intrusion Detection and Prevention (IDP)IDP (Intrusion Detection and Protec

Pagina 535

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide580Figure 435 Device HA > Active-Passive ModeThe following table describes the labels i

Pagina 536

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide581Authentication Select the authentication method the virtual router uses. Every interface

Pagina 537 - _), or dashes (-), but the

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide58234.4 Configuring an Active-Passive Mode Monitored InterfaceThe Device HA Active-Passive

Pagina 538

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide58334.5 The Legacy Mode ScreenVirtual Router Redundancy Protocol (VRRP)Legacy mode device

Pagina 539

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide584Figure 437 Device HA > Legacy ModeThe following table describes the labels in this s

Pagina 540

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide58534.7 The Legacy Mode Add/Edit ScreenUse the VRRP Group Add/Edit screen to add or edit V

Pagina 541

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide586Figure 438 Device HA > Legacy Mode > AddThe following table describes the labels

Pagina 542

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide58734.8 Device HA Technical ReferenceLegacy Mode ZyWALL VRRP ApplicationIn VRRP, a virtual

Pagina 543

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide588Figure 439 Example: VRRP, Normal OperationThe VR ID is not shown. In normal operation,

Pagina 544 - _), or dashes (-), but

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide589• System protect signatures• Certificates (My Certificates, and Trusted Certificates)Syn

Pagina 545

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide59Application PatrolApplication patrol (App. Patrol) manages instant messeng

Pagina 546

Chapter 34 Device HAZyWALL USG 100/200 Series User’s Guide590

Pagina 547

591PART VIIIObjectsUser/Group (593)Addresses (607)Services (613)Schedules (619)AAA Server (625)Authentication Method (635)Certificates (639)SSL

Pagina 549

ZyWALL USG 100/200 Series User’s Guide593CHAPTER 35 User/Group35.1 OverviewThis chapter describes how to set up user accounts, user groups, and user

Pagina 550

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide594" The default admin account is always authenticated locally, regardless of the auth

Pagina 551 - CHAPTER 32

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide595" You cannot put access users and admin users in the same user group." You ca

Pagina 552

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide596Figure 441 Object > User/GroupThe following table describes the labels in this scre

Pagina 553 - Figure 415 Blue Coat: Login

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide597To access this screen, go to the User screen (see Section 35.2 on page 595), and click

Pagina 554

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide59835.3 User Group Summary ScreenUser groups consist of access users and other user groups

Pagina 555

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide599Figure 444 User/Group > Group > AddThe following table describes the labels in

Pagina 556 - 32.3 Web Site Submission

Document ConventionsZyWALL USG 100/200 Series User’s Guide6Icons Used in FiguresFigures in this User’s Guide may use the following generic icons. The

Pagina 557

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide602.2.2 Interface to Interface (To/From ZyWALL)To: Ethernet -> VLAN ->

Pagina 558

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide600Figure 445 Object > User/Group > SettingThe following table describes the labels

Pagina 559 - CHAPTER 33

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide601Maximum number per access accountThis field is effective when Limit ... for access acco

Pagina 560 - Chapter 33 Anti-Spam

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide60235.4.1 Force User Authentication Policy Add/Edit ScreenUse this screen to specify a con

Pagina 561 - 33.2 Before You Begin

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide603The following table describes the labels in this screen. 35.4.2 User Aware Login Exam

Pagina 562

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide604The following table describes the labels in this screen. 35.5 User /Group Technical Re

Pagina 563 - Chapter 33 Anti-Spam

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide605Creating a Large Number of Ext-User AccountsIf you plan to create a large number of Ext

Pagina 564

Chapter 35 User/GroupZyWALL USG 100/200 Series User’s Guide606

Pagina 565

ZyWALL USG 100/200 Series User’s Guide607CHAPTER 36 Addresses36.1 OverviewAddress objects can represent a single IP address or a range of IP addres

Pagina 566

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide608Figure 450 Object > Address > AddressThe following table describes the labels in

Pagina 567

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide609The following table describes the labels in this screen. 36.3 Address Group Summary Scr

Pagina 568 - 33.6 The DNSBL Screen

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide61Figure 4 Applications: VPN Connectivity2.3.2 SSL VPN Network Access You

Pagina 569

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide610The following table describes the labels in this screen. See Section 36.3.1 on page 610 f

Pagina 570

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide611Available This field displays the names of the address and address group objects that ca

Pagina 571

Chapter 36 AddressesZyWALL USG 100/200 Series User’s Guide612

Pagina 572

ZyWALL USG 100/200 Series User’s Guide613CHAPTER 37 Services37.1 OverviewUse service objects to define TCP applications, UDP applications, and ICMP

Pagina 573 - PART VII

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide614Service Objects and Service GroupsUse service objects to define IP protocols.• TCP applica

Pagina 574

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide615The following table describes the labels in this screen. 37.2.1 The Service Add/Edit Sc

Pagina 575 - CHAPTER 34

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide61637.3 The Service Group Summary Screen The Service Group summary screen provides a summary

Pagina 576 - 34.2 Device HA General

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide61737.3.1 The Service Group Add/Edit ScreenThe Service Group Add/Edit screen allows you to

Pagina 577 - Chapter 34 Device HA

Chapter 37 ServicesZyWALL USG 100/200 Series User’s Guide618

Pagina 578 - Figure 432 Virtual Router

ZyWALL USG 100/200 Series User’s Guide619CHAPTER 38 Schedules38.1 OverviewUse schedules to set up one-time and recurring schedules for policy routes

Pagina 579

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide62Figure 6 Network Access Mode: Full Tunnel Mode 2.3.3 User-Aware Access C

Pagina 580

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide62038.2 The Schedule Summary ScreenThe Schedule summary screen provides a summary of all sc

Pagina 581

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide62138.2.1 The One-Time Schedule Add/Edit ScreenThe One-Time Schedule Add/Edit screen allow

Pagina 582

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide62238.2.2 The Recurring Schedule Add/Edit ScreenThe Recurring Schedule Add/Edit screen allo

Pagina 583 - 34.5 The Legacy Mode Screen

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide623Week Days Select each day of the week the recurring schedule is effective.OK Click OK to

Pagina 584

Chapter 38 SchedulesZyWALL USG 100/200 Series User’s Guide624

Pagina 585

ZyWALL USG 100/200 Series User’s Guide625CHAPTER 39 AAA Server39.1 Overview You can use a AAA (Authentication, Authorization, Accounting) server to

Pagina 586

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide626Figure 462 RADIUS Server Network Example39.1.3 ASASASAS (Authenex Strong Authenticati

Pagina 587

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide627RADIUS (Remote Authentication Dial-In User Service) authentication is a popular protoco

Pagina 588 - Synchronization

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide628Bind DN A bind DN is used to authenticate with an LDAP/AD server. For example a bind DN

Pagina 589

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide62939.3 Active Directory or LDAP Group Summary ScreenYou can configure a group of AD or L

Pagina 590

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide63Figure 8 Applications: Multiple WAN Interfaces2.3.5 Device HASet up an

Pagina 591 - PART VIII

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide630Figure 466 Object > AAA Server > Active Directory (or LDAP) > Group > Add

Pagina 592

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide63139.4 Configuring a Default RADIUS ServerTo configure the default external RADIUS serve

Pagina 593 - CHAPTER 35

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide63239.5 Configuring a Group of RADIUS Servers You can configure a group of RADIUS servers

Pagina 594 - Chapter 35 User/Group

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide633The following table describes the labels in this screen. Table 216 Object > AAA Se

Pagina 595 - 35.2 User Summary Screen

Chapter 39 AAA ServerZyWALL USG 100/200 Series User’s Guide634

Pagina 596 - 35.2.1 User Add/Edit Screen

ZyWALL USG 100/200 Series User’s Guide635CHAPTER 40 Authentication Method40.1 Overview Authentication method objects set how the ZyWALL authenticate

Pagina 597

Chapter 40 Authentication MethodZyWALL USG 100/200 Series User’s Guide636Figure 470 Example: Using Authentication Method in VPN 40.2 Viewing Authen

Pagina 598 - 35.3.1 Group Add/Edit Screen

Chapter 40 Authentication MethodZyWALL USG 100/200 Series User’s Guide63740.3 Creating an Authentication Method Object Follow the steps below to cre

Pagina 599 - 35.4 Setting Screen

Chapter 40 Authentication MethodZyWALL USG 100/200 Series User’s Guide638The following table describes the labels in this screen. Table 218 Object

Pagina 600

ZyWALL USG 100/200 Series User’s Guide639CHAPTER 41 Certificates41.1 OverviewThe ZyWALL can use certificates (also called digital IDs) to authentica

Pagina 601 - Chapter 35 User/Group

Chapter 2 Features and ApplicationsZyWALL USG 100/200 Series User’s Guide64

Pagina 602

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide640message, no-one can have altered it (because they cannot re-sign the message with Tim’

Pagina 603

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide641• PEM (Base-64) encoded PKCS#7: This Privacy Enhanced Mail (PEM) format uses lowercas

Pagina 604

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide642Figure 474 Certificate Details 4 Use a secure method to verify that the certificate

Pagina 605

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide64341.2.1 The My Certificates Add ScreenClick Object > Certificate > My Certifica

Pagina 606

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide644Figure 476 Object > Certificate > My Certificates > AddThe following table

Pagina 607 - CHAPTER 36

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide645Organization Identify the company or group to which the certificate owner belongs. Yo

Pagina 608 - Chapter 36 Addresses

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide646If you configured the My Certificate Create screen to have the ZyWALL enroll a certifi

Pagina 609 - Chapter 36 Addresses

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide647Figure 477 Object > Certificate > My Certificates > Edit The following

Pagina 610

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide648Type This field displays general information about the certificate. CA-signed means th

Pagina 611

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide64941.2.3 The My Certificates Import Screen Click Object > Certificate > My Certi

Pagina 612

ZyWALL USG 100/200 Series User’s Guide65CHAPTER 3 Web ConfiguratorThe ZyWALL web configurator allows easy ZyWALL setup and management using an Intern

Pagina 613 - CHAPTER 37

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide650The following table describes the labels in this screen. 41.3 The Trusted Certificat

Pagina 614 - Chapter 37 Services

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide65141.3.1 The Trusted Certificates Edit Screen Click Object > Certificate > Trust

Pagina 615 - Add icon or an Edit icon

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide652Figure 480 Object > Certificate > Trusted Certificates > Edit The following

Pagina 616

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide653Refresh Click Refresh to display the certification path.Enable X.509v3 CRL Distributi

Pagina 617 - Chapter 37 Services

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide65441.3.2 The Trusted Certificates Import Screen Click Object > Certificate > Trus

Pagina 618

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide655Figure 481 Object > Certificate > Trusted Certificates > ImportThe followi

Pagina 619 - CHAPTER 38

Chapter 41 CertificatesZyWALL USG 100/200 Series User’s Guide656

Pagina 620 - Chapter 38 Schedules

ZyWALL USG 100/200 Series User’s Guide657CHAPTER 42 SSL Application42.1 OverviewYou use SSL application objects in SSL VPN. Configure an SSL applica

Pagina 621 - Chapter 38 Schedules

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide6581 Click Object > SSL Application in the navigation panel. 2 Click the Add button

Pagina 622

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide65942.2.1 Creating/Editing a Web-based SSL Application ObjectA web-based application

Pagina 623

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide66Figure 10 Login Screen 3 Type the user name (default: “admin”) and password (defa

Pagina 624

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide66042.2.2 Creating/Editing a File Sharing SSL Application ObjectYou can specify the n

Pagina 625 - CHAPTER 39

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide661" You must then configure the shared folder on the file server for remote acc

Pagina 626 - 39.1.3 ASAS

Chapter 42 SSL ApplicationZyWALL USG 100/200 Series User’s Guide662

Pagina 627

663PART IXSystemSystem (665)

Pagina 629 - Chapter 39 AAA Server

ZyWALL USG 100/200 Series User’s Guide665CHAPTER 43 System43.1 OverviewUse the system screens to configure general ZyWALL settings. 43.1.1 What Y

Pagina 630

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide666• Vantage CNM (Centralized Network Management) is a browser-based global management tool tha

Pagina 631

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide667Figure 487 System > Date and TimeThe following table describes the labels in this scre

Pagina 632 - Chapter 39 AAA Server

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide66843.3.1 Pre-defined NTP Time Servers ListWhen you turn on the ZyWALL for the first time, the

Pagina 633

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide669The ZyWALL continues to use the following pre-defined list of NTP time servers if you do no

Pagina 634

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide67Follow the directions in this screen. If you change the default password, the Login

Pagina 635 - CHAPTER 40

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67043.4 Console Port SpeedThis section shows you how to set the console port speed when you co

Pagina 636

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67143.5.2 Configuring the DNS ScreenClick System > DNS to change your ZyWALL’s DNS setting

Pagina 637

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide672Domain Zone A domain zone is a fully qualified domain name without the host. For example, zy

Pagina 638

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67343.5.3 Address Record An address record contains the mapping of a fully qualified domain n

Pagina 639 - CHAPTER 41

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide674The following table describes the labels in this screen. 43.5.6 Domain Zone Forwarder A do

Pagina 640 - Chapter 41 Certificates

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide675The following table describes the labels in this screen. 43.5.8 MX Record A MX (Mail eXcha

Pagina 641 - Chapter 41 Certificates

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67643.5.10 Adding a DNS Service Control RuleClick the Add icon in the Service Control table to

Pagina 642

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide677Figure 495 Secure and Insecure Service Access From the WAN• See Section 5.6.1 on page 122

Pagina 643

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67843.6.3 HTTPSYou can set the ZyWALL to use HTTP or HTTPS (HTTPS adds security) for web confi

Pagina 644 - characters

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide67943.6.4 Configuring WWW Click System > WWW to open the WWW screen. Use this screen to sp

Pagina 645

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide68The icons provide the following functions.3.3.2 Navigation PanelUse the menu items

Pagina 646

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide680Server Port The HTTPS server listens on port 443 by default. If you change the HTTPS server

Pagina 647

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide68143.6.5 Service Control RulesClick Add or Edit in the Service Control table in a WWW, SSH,

Pagina 648

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide682The following table describes the labels in this screen. 43.6.6 HTTPS ExampleIf you haven’

Pagina 649

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide68343.6.6.2 Netscape Navigator Warning MessagesWhen you attempt to access the ZyWALL HTTPS se

Pagina 650

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide684• For the browser to trust a self-signed certificate, import the self-signed certificate int

Pagina 651

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide68543.6.6.5.1 Installing the CA’s Certificate1 Double click the CA’s trusted certificate to p

Pagina 652

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide686Figure 505 Personal Certificate Import Wizard 12 The file name and path of the certificate

Pagina 653

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide687Figure 507 Personal Certificate Import Wizard 34 Have the wizard determine where the cert

Pagina 654

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide688Figure 509 Personal Certificate Import Wizard 56 You should see the following screen when

Pagina 655

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide689Figure 512 SSL Client Authentication3 You next see the web configurator login screen.Figu

Pagina 656

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide69Interface Status Use this screen to see information about all of the ZyWALL’s inter

Pagina 657 - CHAPTER 42

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide690Figure 514 SSH Communication Over the WAN Example43.7.1 How SSH WorksThe following figure

Pagina 658 - Chapter 42 SSL Application

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69143.7.2 SSH Implementation on the ZyWALLYour ZyWALL supports SSH versions 1 and 2 using RSA

Pagina 659 - Chapter 42 SSL Application

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69243.7.5 Secure Telnet Using SSH ExamplesThis section shows two examples using a command inte

Pagina 660

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69343.7.5.2 Example 2: LinuxThis section describes how to access the ZyWALL using the OpenSSH

Pagina 661

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide694Figure 520 System > TelnetThe following table describes the labels in this screen. 43.

Pagina 662

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69543.9.1 Configuring FTPTo change your ZyWALL’s FTP settings, click System > FTP tab. The

Pagina 663 - System (665)

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69643.10 SNMP Simple Network Management Protocol is a protocol used for exchanging management

Pagina 664

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide697An agent is a management software module that resides in a managed device (the ZyWALL). An

Pagina 665 - CHAPTER 43

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69843.10.3 Configuring SNMP To change your ZyWALL’s SNMP settings, click System > SNMP tab.

Pagina 666 - 43.3 Date and Time

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide69943.11 Dial-in ManagementConnect an external serial modem to the AUX port to provide a mana

Pagina 667 - Chapter 43 System

Safety WarningsZyWALL USG 100/200 Series User’s Guide7Safety Warnings1 For your safety, be sure to read and follow all warning notices and instructio

Pagina 668 - Chapter 43 System

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide70AppPatrol General Use this screen to enable or disable traffic management by applica

Pagina 669

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide700Figure 524 System > Dial-in Mgmt The following table describes the labels in this scre

Pagina 670 - 43.5 DNS Overview

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide701Figure 525 System > Vantage CNMThe following table describes the labels in this screen

Pagina 671 - Table 233 System > DNS

Chapter 43 SystemZyWALL USG 100/200 Series User’s Guide70243.13 Language Screen Click System > Language to open the following screen. Use this scr

Pagina 672

703PART XMaintenance, Troubleshooting, & SpecificationsFile Manager (705)Logs (715)Reports (727)Diagnostics (741)Reboot (743)Troubleshooting

Pagina 674

ZyWALL USG 100/200 Series User’s Guide705CHAPTER 44 File Manager44.1 OverviewConfiguration files define the ZyWALL’s settings. Shell scripts are fi

Pagina 675 - 43.5.9 Adding a MX Record

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide706 These files have the same syntax, which is also identical to the way you run CLI comm

Pagina 676 - 43.6 WWW Overview

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide707" “exit” or “!'” must follow sub commands if it is to make the ZyWALL exit

Pagina 677 - 43.6.2 System Timeout

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide708Once your ZyWALL is configured and functioning properly, it is highly recommended that

Pagina 678 - 43.6.3 HTTPS

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide709The following table describes the labels in this screen. Table 249 Maintenance >

Pagina 679 - 43.6.4 Configuring WWW

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide71User/Group User Use this screen to create and manage users.Group Use this screen to

Pagina 680

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide71044.3 The Firmware Package Screen Click Maintenance > File Manager > Firmware Pa

Pagina 681 - 43.6.5 Service Control Rules

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide711The ZyWALL’s firmware package cannot go through the ZyWALL when you enable the anti-v

Pagina 682 - 43.6.6 HTTPS Example

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide712" The ZyWALL automatically reboots after a successful upload.The ZyWALL automatic

Pagina 683

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide713Each field is described in the following table. Table 251 Maintenance > File Ma

Pagina 684

Chapter 44 File ManagerZyWALL USG 100/200 Series User’s Guide714Browse... Click Browse... to find the .zysh file you want to upload. Upload Click Up

Pagina 685

ZyWALL USG 100/200 Series User’s Guide715CHAPTER 45 Logs45.1 OverviewThis chapter provides general information about the ZyWALL’s log feature. See

Pagina 686

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide716Figure 538 Maintenance > Log > View LogEvents that generate an alert (as well as a log

Pagina 687

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide717The Web configurator saves the filter settings if you leave the View Log screen and return to

Pagina 688

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide718The Log Settings Summary screen provides a summary of all the settings. You can use the Log Se

Pagina 689 - 43.7 SSH

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide71945.4.2 Edit System Log Settings The Log Settings Edit screen controls the detailed settings

Pagina 690 - 43.7.1 How SSH Works

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide723.3.3 Main WindowThe main window shows the screen you select in the menu. It is dis

Pagina 691 - 43.7.4 Configuring SSH

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide720Figure 540 Maintenance > Log > Log Setting > Edit (System Log)

Pagina 692

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide721The following table describes the labels in this screen. Table 255 Maintenance > Log >

Pagina 693 - 43.8 Telnet

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide72245.4.3 Edit Remote Server Log Settings The Log Settings Edit screen controls the detailed set

Pagina 694 - 43.9 FTP

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide723Figure 541 Maintenance > Log > Log Setting > Edit (Remote Server)

Pagina 695 - 43.9.1 Configuring FTP

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide724The following table describes the labels in this screen. 45.4.4 Active Log Summary ScreenThe

Pagina 696 - 43.10 SNMP

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide725Figure 542 Active Log SummaryThis screen provides a different view and a different way of i

Pagina 697 - 43.10.2 SNMP Traps

Chapter 45 LogsZyWALL USG 100/200 Series User’s Guide726Selection Select what information you want to log from each Log Category (except All Logs; see

Pagina 698 - 43.10.3 Configuring SNMP

ZyWALL USG 100/200 Series User’s Guide727CHAPTER 46 Reports46.1 OverviewThis chapter provides information about the report screens. Use the Report

Pagina 699 - 43.11 Dial-in Management

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide728Figure 543 Maintenance > Report > Traffic StatisticsThere is a limit on the number

Pagina 700 - 43.12 Vantage CNM

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide729Flush Data Click this button to discard all of the screen’s statistics and update the repo

Pagina 701 - Note: HTTPS is recommended

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide73Figure 14 Warning Messages Click Refresh Now to update the screen. Close the popu

Pagina 702 - 43.13 Language Screen

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide730The following table displays the maximum number of records shown in the report, the byte co

Pagina 703 - Specifications

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide731Figure 544 Maintenance > Report > SessionThe following table describes the labels

Pagina 704

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide73246.4 The Anti-Virus Report ScreenClick Maintenance > Report > Anti-Virus to display

Pagina 705 - CHAPTER 44

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide733The statistics display as follows when you display the top entries by source.Figure 546

Pagina 706 - Chapter 44 File Manager

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide734Figure 548 Maintenance > Report > IDP: Signature Name The following table describes

Pagina 707 - Chapter 44 File Manager

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide735The statistics display as follows when you display the top entries by source.Figure 549

Pagina 708

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide736Figure 551 Maintenance > Report > Anti-Spam: Sender IP The following table describe

Pagina 709

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide73746.7 The Email Daily Report ScreenClick Maintenance > Report > Email Daily Report t

Pagina 710

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide738Figure 552 Maintenance > Report > Email Daily Report The following table describes

Pagina 711

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide739Password This box is effective when you select the SMTP Authentication check box. Type the

Pagina 712

Chapter 3 Web ConfiguratorZyWALL USG 100/200 Series User’s Guide74Click Refresh Now to update the screen. For example, if you just enabled a particula

Pagina 713

Chapter 46 ReportsZyWALL USG 100/200 Series User’s Guide740

Pagina 714

ZyWALL USG 100/200 Series User’s Guide741CHAPTER 47 Diagnostics47.1 The Diagnostics ScreenThe Diagnostics screen provides an easy way for you to ge

Pagina 715 - CHAPTER 45

Chapter 47 DiagnosticsZyWALL USG 100/200 Series User’s Guide742

Pagina 716 - Chapter 45 Logs

ZyWALL USG 100/200 Series User’s Guide743CHAPTER 48 Reboot48.1 OverviewUse this to restart the device (for example, if the device begins behaving er

Pagina 717 - 45.4 Log Setting Screens

Chapter 48 RebootZyWALL USG 100/200 Series User’s Guide744

Pagina 718 - 45.4.1 Log Setting Summary

ZyWALL USG 100/200 Series User’s Guide745CHAPTER 49 TroubleshootingThis chapter offers some suggestions to solve problems you might encounter. V I ca

Pagina 719 - Chapter 45 Logs

Chapter 49 TroubleshootingZyWALL USG 100/200 Series User’s Guide746• If you have the ZyWALL and remote IPSec router use certificates to authenticate e

Pagina 720

Chapter 49 TroubleshootingZyWALL USG 100/200 Series User’s Guide747V I changed the LAN IP address and can no longer access the Internet.The ZyWALL au

Pagina 721

Chapter 49 TroubleshootingZyWALL USG 100/200 Series User’s Guide74849.1 Resetting the ZyWALLIf you cannot access the ZyWALL by any method, try restar

Pagina 722

ZyWALL USG 100/200 Series User’s Guide749CHAPTER 50 Product Specifications50.1 General SpecificationsThe following specifications are subject to cha

Pagina 723

ZyWALL USG 100/200 Series User’s Guide75CHAPTER 4 Wizard Setup4.1 Wizard Setup OverviewThe web configurator's setup wizards help you configure

Pagina 724

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide7501 It is recommended that you do NOT wall-mount the ZyWALL. A wall-mounting k

Pagina 725

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide751USER PROFILESMaximum Local Users 192 128Maximum Admin Users 5 5Maximum User

Pagina 726

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide752Admin E-mail Addresses 2 2Syslog Servers 4 4IDPMaximum Number of IDP Profile

Pagina 727 - CHAPTER 46

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide753The following table, which is not exhaustive, lists standards referenced by

Pagina 728 - Chapter 46 Reports

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide75450.2 3G or WLAN PCMCIA Card InstallationOnly insert a compatible 802.11b/g-

Pagina 729 - Chapter 46 Reports

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide755POWER CONSUMPTION 20 W MAX. SAFETY STANDARDS UL, CUL (UL 60950-1 FIRST EDIT

Pagina 730 - 46.3 The Session Screen

Chapter 50 Product SpecificationsZyWALL USG 100/200 Series User’s Guide756

Pagina 731

757PART XIAppendices and IndexCommon Services (815)Displaying Anti-Virus Alert Messages in Windows (819)Open Software Announcements (845)Legal Info

Pagina 733 - 46.5 The IDP Report Screen

ZyWALL USG 100/200 Series User’s Guide759APPENDIX A Log DescriptionsThis appendix provides descriptions of example log messages. Table 276 Conte

Pagina 734

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide76Figure 16 Wizard Setup Welcome 4.2 Installation Setup, One ISP The wizard screens

Pagina 735

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide760%s: Service is unavailableContent filter rating service is temporarily unavailable

Pagina 736

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide761Anti-Spam policy %d has been inserted.The anti-spam policy with the specified ind

Pagina 737

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide762DNSBL domain %s has been deleted.The specified DNSBL domain name (%s) has been rem

Pagina 738

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide763The %s address-object is wrong type for '1st-dns' in SSL Policy %s.The

Pagina 739

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide764The SSL VPN policy %s does not configure users or user groups.There are no users o

Pagina 740

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide765Failed login attempt to SSLVPN from %s (reach the max. number of simultaneous log

Pagina 741 - CHAPTER 47

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide766The ZySH logs deal with internal system errors. User %s has been granted an L2TP o

Pagina 742 - Chapter 47 Diagnostics

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide767can't get name for entry %d!1st:zysh entry indexcan't get reference cou

Pagina 743 - CHAPTER 48

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide768Table 283 ADP LogsLOG MESSAGE DESCRIPTIONfrom <zone> to <zone> [type

Pagina 744 - Chapter 48 Reboot

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide769Reloading Anti-Virus signature reference table has failed.The ZyWALL failed to re

Pagina 745 - CHAPTER 49

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide77The following table describes the labels in this screen.4.3 Step 1 Internet Access Enc

Pagina 746 - VPN tunnel

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide770AV signature update has failed.An anti-virus signatures update failed for unknown

Pagina 747 - Chapter 49 Troubleshooting

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide771%s, due to decompress malfunction, %s could not be decompressed. Action on file:

Pagina 748 - 49.1 Resetting the ZyWALL

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide772 Failed login attempt to ZyWALL from %s (reach the max. number of simultaneous log

Pagina 749 - CHAPTER 50

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide773Standard service activation has failed:%s.Standard service activation failed, thi

Pagina 750

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide774Change Anti-Virus engine type has failed. Because of lack must fields.The device f

Pagina 751

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide775IDP signature download has failed.The device still cannot download the IDP signat

Pagina 752

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide776System bootup. Do expiration daily-check.The device processes a service expiration

Pagina 753

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide777Download file size is wrong.The file size downloaded for AS is not identical with

Pagina 754

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide778Custom signature import error: line <line>, sid <sid>, <error_messa

Pagina 755

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide779IDP system-protect signature update from version <version> to version <v

Pagina 756

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide78Figure 18 Ethernet Encapsulation: Auto: FinishYou have set up your ZyWALL to access th

Pagina 757 - Appendices and

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide780IDP system-protect signature update failed. Invalid signature content.An IDP syste

Pagina 758

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide781Table 288 Application PatrolMESSAGE EXPLANATIONService=%s Mode=%s Rule=%s Acces

Pagina 759 - APPENDIX A

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide782 System fatal error: 60011002.The device failed to get the application patrol prot

Pagina 760 - Table 279 Anti-Spam Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide783[SA] : Tunnel [%s] Phase 1 authentication method mismatch%s is the tunnel name. W

Pagina 761 - Appendix A Log Descriptions

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide784Cannot resolve Secure Gateway Addr %s for Tunnel [%s]1st %s is my ip address. 2nd

Pagina 762 - Table 280 SSL VPN Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide785Tunnel [%s] Sending IKE request%s is the tunnel name. The device sent an IKE requ

Pagina 763

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide786 Table 290 IPSec LogsLOG MESSAGE DESCRIPTIONCorrupt packet, Inbound transform o

Pagina 764

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide787 Firewall rule %d has been moved to %d.1st %d is the old global index of rule, 2

Pagina 765

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide788 To send message to policy route daemon failed!Failed to send control message to p

Pagina 766 - Table 282 ZySH Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide789HTTPS port has been changed to default port.An administrator changed the port num

Pagina 767

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide79Figure 19 Ethernet Encapsulation: StaticThe following table describes the labels in t

Pagina 768 - Table 284 Anti-Virus Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide790DHCP Server on Interface %s will be reapplied due to Device HA status is ActiveWhe

Pagina 769

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide791 Interface %s ping check is failed. Zone Forwarder removes DNS servers in records

Pagina 770

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide792%s is dead at %s A daemon (process) is gone (was killed by the operating system).

Pagina 771 - Table 285 User Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide793DHCP request received via interface %s (%s:%s), src_mac: %s with requested IP: %s

Pagina 772 - Table 286 myZyXEL.com Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide794Update the profile %s has failed because of invalid system parameters.Some system

Pagina 773

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide795Update the profile %s has failed because WAN interface was link-down.DDNS profile

Pagina 774

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide796 DDNS Initialization has failed.Initialize DDNS failed,All DDNS profiles are delet

Pagina 775

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide797 Can't get BROADCAST address of %s interfaceThe connectivity check process c

Pagina 776

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide798Master firmware version can not be recognized. Stop syncing from Master.Synchroniz

Pagina 777 - Table 287 IDP Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide799 Device HA authentication string of AH for VRRP group %s maybe wrong.A VRRP group

Pagina 778

Safety WarningsZyWALL USG 100/200 Series User’s Guide8

Pagina 779

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide80" Enter the Internet access information exactly as given to you by your ISP.WAN Int

Pagina 780

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide800Invalid RIP text authentication.RIP text authentication has been set without setti

Pagina 781

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide801RIP v2-broadcast on interface %s has been enabled.RIP v2-broadcast on interface %

Pagina 782 - Table 289 IKE Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide802 Interface %s does not belong to any OSPF area.Interface %s has been set OSPF auth

Pagina 783

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide803 Table 300 PKI LogsLOG MESSAGE DESCRIPTIONGenerate X509certifiate "%s"

Pagina 784

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide804Import PKCS#7 certificate "%s" into "My Certificate" successfu

Pagina 785

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide805 CODE DESCRIPTION1 Algorithm mismatch between the certificate and the search con

Pagina 786 - Table 291 Firewall Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide806AUX Interface disconnecting failed. This AUX interface is not enabled.The AUX inte

Pagina 787 - Table 293 Policy Route Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide807Interface %s links down. Default route will not apply until interface %s links up

Pagina 788

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide808Interface %s connect failed: Connect timeout.A PPPOE connection timed out due to a

Pagina 789

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide809"Incorrect PIN code of interface cellular%d. Please check the PIN code setti

Pagina 790

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide814.3.4 PPPoE: Auto IP Address AssignmentIf you select Auto as the IP Address Assignment

Pagina 791 - Table 295 System Logs

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide810Create interface %s has failed. Wlan device does not exist.The wireless device fai

Pagina 792

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide811 Table 303 Account LogsLOG MESSAGE DESCRIPTIONAccount %s %s has been deleted.

Pagina 793

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide812 Table 306 File Manager LogsLOG MESSAGE DESCRIPTIONERROR:#%s, %s Apply configura

Pagina 794

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide813

Pagina 795

Appendix A Log DescriptionsZyWALL USG 100/200 Series User’s Guide814

Pagina 796

ZyWALL USG 100/200 Series User’s Guide815APPENDIX B Common ServicesThe following table lists some commonly-used services and their associated protoco

Pagina 797 - Table 297 Device HA Logs

Appendix B Common ServicesZyWALL USG 100/200 Series User’s Guide816FTP TCPTCP2021File Transfer Program, a program to enable fast transfer of files, in

Pagina 798

Appendix B Common ServicesZyWALL USG 100/200 Series User’s Guide817RTSP TCP/UDP 554 The Real Time Streaming (media control) Protocol (RTSP) is a remo

Pagina 799

Appendix B Common ServicesZyWALL USG 100/200 Series User’s Guide818

Pagina 800

ZyWALL USG 100/200 Series User’s Guide819APPENDIX C Displaying Anti-Virus AlertMessages in WindowsWith the anti-virus packet scan, when a virus is de

Pagina 801

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide82Figure 22 PPPoE Encapsulation: Auto: FinishYou have set up your ZyWALL to access the I

Pagina 802 - Table 299 NAT Logs

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide820Figure 557 Windows XP: Starting the Messenger Ser

Pagina 803 - Table 300 PKI Logs

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide821Figure 559 Windows 2000: Starting the Messenger

Pagina 804

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide822Figure 562 Windows 98 SE: Task Bar Properties

Pagina 805 - Table 301 Interface Logs

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide823Figure 564 Windows 98 SE: Startup: Create Shortc

Pagina 806

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 100/200 Series User’s Guide824Figure 566 Windows 98 SE: Startup: Shortcut

Pagina 807

ZyWALL USG 100/200 Series User’s Guide825APPENDIX D Importing CertificatesThis appendix shows importing certificates examples using Netscape Navigato

Pagina 808

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide826Figure 568 Login Screen2 Click Install Certificate to open the Install Cer

Pagina 809 - Table 302 WLAN Logs

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide827Figure 570 Certificate Import Wizard 14 Select where you would like to st

Pagina 810

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide828Figure 572 Certificate Import Wizard 36 Click Yes to add the ZyWALL certi

Pagina 811 - Table 303 Account Logs

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide829Figure 574 Certificate General Information after Import

Pagina 812 - Table 306 File Manager Logs

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide83Figure 23 PPPoE Encapsulation: StaticThe following table describes the labels in this

Pagina 813

Appendix D Importing CertificatesZyWALL USG 100/200 Series User’s Guide830

Pagina 814

ZyWALL USG 100/200 Series User’s Guide831APPENDIX E Wireless LANsWireless LAN TopologiesThis section discusses ad-hoc and infrastructure wireless LAN

Pagina 815 - APPENDIX B

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide832Figure 576 Basic Service SetESSAn Extended Service Set (ESS) consists of a series o

Pagina 816 - Appendix B Common Services

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide833Figure 577 Infrastructure WLANChannelA channel is the radio frequency(ies) used by

Pagina 817 - Appendix B Common Services

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide834Figure 578 RTS/CTSWhen station A sends data to the AP, it might not know that the

Pagina 818

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide835If the Fragmentation Threshold value is smaller than the RTS/CTS value (see previous

Pagina 819 - APPENDIX C

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide836Wireless security methods available on the ZyWALL are data encryption, wireless clien

Pagina 820 - Windows 2000

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide837Determines the network services available to authenticated users once they are conne

Pagina 821 - Windows 98 SE/Me

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide838For EAP-TLS authentication type, you must first have a wired connection to the networ

Pagina 822

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide839Dynamic WEP Key ExchangeThe AP maps a unique key that is generated with the RADIUS s

Pagina 823

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide844.3.6 Step 2 Internet Access PPPoE " Enter the Internet access information exactly

Pagina 824

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide840Encryption WPA improves data encryption by using Temporal Key Integrity Protocol (TKI

Pagina 825 - APPENDIX D

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide841Wireless Client WPA SupplicantsA wireless client supplicant is the software that run

Pagina 826 - Figure 568 Login Screen

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide8423 The AP and wireless clients generate a common PMK (Pairwise Master Key). The key it

Pagina 827

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide843Antenna OverviewAn antenna couples RF signals onto air. A transmitter within a wirel

Pagina 828

Appendix E Wireless LANsZyWALL USG 100/200 Series User’s Guide844Positioning AntennasIn general, antennas should be mounted as high as practically pos

Pagina 829

ZyWALL USG 100/200 Series User’s Guide845APPENDIX F Open Software AnnouncementsNotice Information herein is subject to change without notice. Compani

Pagina 830

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide846" This Product includes Netkit Telnet -0.17 software under the Net

Pagina 831 - APPENDIX E

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide847" This Product includes expat-1.95.6 software under the Expat Lic

Pagina 832 - Appendix E Wireless LANs

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide848The above copyright notice and this permission notice shall be included

Pagina 833 - Appendix E Wireless LANs

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide849OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF

Pagina 834 - Fragmentation Threshold

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide85Figure 24 PPPoE Encapsulation: Static: FinishYou have set up your ZyWALL to access th

Pagina 835 - Wireless Security Overview

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide850ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBI

Pagina 836 - IEEE 802.1x

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide851" This Product includes bind-9.2.3 software under the Internet So

Pagina 837 - Types of EAP Authentication

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide852THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRAN

Pagina 838 - PEAP (Protected EAP)

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide853"Work" shall mean the work of authorship, whether in Source

Pagina 839 - WPA and WPA2

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide854(d) If the Work includes a "NOTICE" text file as part of its

Pagina 840 - User Authentication

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide855Version 1.1Copyright (c) 1999-2003 The Apache Software Foundation. All

Pagina 841

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide85659 Temple Place, Suite 330, Boston, MA 02111-1307 USAEveryone is permit

Pagina 842 - Security Parameters Summary

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide857When a program is linked with a library, whether statically or using a

Pagina 843 - Types of Antennas for WLAN

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide858Library is not restricted, and output from such a program is covered on

Pagina 844 - Positioning Antennas

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide8594. You may copy and distribute the Library (or a portion or derivative

Pagina 845 - APPENDIX F

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide86Figure 25 PPTP Encapsulation: AutoThe following table describes the labels in this scr

Pagina 846 - NTP License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide860copy of the library already present on the user's computer system,

Pagina 847 - Expat License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide861simultaneously your obligations under this License and any other perti

Pagina 848 - OpenSSL License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide86216. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITI

Pagina 849 - Original SSLeay License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide863To protect your rights, we need to make restrictions that forbid anyon

Pagina 850

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide864c) If the modified program normally reads commands interactively when r

Pagina 851 - ISC license

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide8654. You may not copy, modify, sublicense, or distribute the Program exc

Pagina 852 - Apache License

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide86610. If you wish to incorporate parts of the Program into other free pro

Pagina 853

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide867Redistributions in binary form must reproduce the above copyright noti

Pagina 854

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide868The Public LicenseVersion 2.8, 17 August 2003Redistribution and use of

Pagina 855

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide869End-User License Agreement for “ZyWALL USG 100 and ZyWALL USG 200”WARN

Pagina 856

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide87The ZyWALL applies the configuration settings. Figure 26 PPTP Encapsulation: Auto: Fi

Pagina 857

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide870You acknowledge that the Software contains proprietary trade secrets of

Pagina 858

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide871ORDERS, OR OTHER RESTRICTIONS. YOU AGREE TO INDEMNIFY ZyXEL AGAINST A

Pagina 859

Appendix F Open Software AnnouncementsZyWALL USG 100/200 Series User’s Guide872

Pagina 860

ZyWALL USG 100/200 Series User’s Guide873APPENDIX G Legal InformationCopyrightCopyright © 2008 by ZyXEL Communications Corporation.The contents of th

Pagina 861

Appendix G Legal InformationZyWALL USG 100/200 Series User’s Guide874If this device does cause harmful interference to radio/television reception, whi

Pagina 862

Appendix G Legal InformationZyWALL USG 100/200 Series User’s Guide875ZyXEL Limited WarrantyZyXEL warrants to the original end user (purchaser) that t

Pagina 863

Appendix G Legal InformationZyWALL USG 100/200 Series User’s Guide876

Pagina 864

ZyWALL USG 100/200 Series User’s Guide877APPENDIX H Customer SupportIn the event of problems that cannot be solved by using this manual, you should c

Pagina 865

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide878• Address: 1005F, ShengGao International Tower, No.137 XianXia Rd., Shanghai• Web:

Pagina 866

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide879Germany• Support E-mail: [email protected]• Sales E-mail: [email protected]• Telephon

Pagina 867 - The MIT License

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide884.3.8 PPTP: Static IP Address AssignmentIf you select Static as the IP Address Assignme

Pagina 868

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide880Malaysia• Support E-mail: [email protected]• Sales E-mail: [email protected]

Pagina 869

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide881Singapore• Support E-mail: [email protected]• Sales E-mail: [email protected]

Pagina 870

Appendix H Customer SupportZyWALL USG 100/200 Series User’s Guide882Turkey• Support E-mail: [email protected]• Telephone: +90 212 222 55 22• Fax: +90-2

Pagina 871

IndexZyWALL USG 100/200 Series User’s Guide883IndexNumerics3DES 3743G 1293G see also cellular 226AAAA server 625AD 626and users 594directory service 6

Pagina 872

IndexZyWALL USG 100/200 Series User’s Guide884alerts 717, 721, 724, 725anti-spam 564anti-virus 475IDP 492ALG 325, 330and firewall 325, 327and NAT 326a

Pagina 873 - APPENDIX G

IndexZyWALL USG 100/200 Series User’s Guide885allowing through the firewall 344vs virtual interfaces 343AT command strings 699authenticationLDAP/AD 62

Pagina 874

IndexZyWALL USG 100/200 Series User’s Guide886and FTP 695and HTTPS 678and IKE SA 378and SSH 691and synchronization (device HA) 589and VPN gateways 353

Pagina 875 - ZyXEL Limited Warranty

IndexZyWALL USG 100/200 Series User’s Guide887copyright 873CPU usage 173, 175CTS (Clear to Send) 834current date/time 173, 666and schedules 619dayligh

Pagina 876 - Appendix G Legal Information

IndexZyWALL USG 100/200 Series User’s Guide888double-encoding 527DTR 699Dynamic Domain Name System. See DDNS.Dynamic Host Configuration Protocol. See

Pagina 877 - APPENDIX H

IndexZyWALL USG 100/200 Series User’s Guide889vs application patrol 335, 337firmwareand restart 710boot module. See boot module.current version 172, 7

Pagina 878 - Appendix H Customer Support

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide894.3.9 Step 2 Internet Access PPTP " Enter the Internet access information exactly

Pagina 879 - Appendix H Customer Support

IndexZyWALL USG 100/200 Series User’s Guide890custom signature example 505custom signatures 498false negatives 489false positives 489inline profile 48

Pagina 880

IndexZyWALL USG 100/200 Series User’s Guide891trunks. See also trunks.types 200virtual. See also virtual interfaces.VLAN. See also VLAN interfaces.whe

Pagina 881

IndexZyWALL USG 100/200 Series User’s Guide892Default_L2TP_VPN_GW example 415DNS 412example 415, 418IPSec configuration 410policy route 410policy rout

Pagina 882

IndexZyWALL USG 100/200 Series User’s Guide893NNAT 285, 3091 to 1 example 313address mapping. See policy routes.ALG. See ALG.and address objects 282an

Pagina 883 - Numerics

IndexZyWALL USG 100/200 Series User’s Guide894Pairwise Master Key (PMK) 840, 842payload option 504payload size 505PCMCIA card installation 754Peanut H

Pagina 884

IndexZyWALL USG 100/200 Series User’s Guide895RRADIUS 625, 626, 836advantages 625and IKE SA 378and PPPoE 268and users 594message types 837messages 837

Pagina 885

IndexZyWALL USG 100/200 Series User’s Guide896and force user authentication policies 603and policy routes 282, 455, 457, 459, 461one-time 619recurring

Pagina 886

IndexZyWALL USG 100/200 Series User’s Guide897spam 559specifications 749device 749feature 750hardware 749spillover (for load balancing) 272SQL slammer

Pagina 887

IndexZyWALL USG 100/200 Series User’s Guide898SYN flood 526synchronization 576and subscription services 576information synchronized 588password 581, 5

Pagina 888

IndexZyWALL USG 100/200 Series User’s Guide899messages 613port numbers 613UDP Decoder 520UDP decoy portscan 524UDP distributed portscan 524UDP flood a

Pagina 889

Contents OverviewZyWALL USG 100/200 Series User’s Guide9Contents OverviewGetting Started ...

Pagina 890

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide904.3.9.3 WAN IP Address Assignments You do not configure this section if you selected Au

Pagina 891

IndexZyWALL USG 100/200 Series User’s Guide900Virtual Private Network. See VPN.virtual router 578Virtual Router ID number (VRID). 584Virtual Router Re

Pagina 892

IndexZyWALL USG 100/200 Series User’s Guide901white listanti-spam 564, 566, 567whitelist 567anti-spam 559Wi-Fi Protected Access 839Windows Internet Na

Pagina 893

IndexZyWALL USG 100/200 Series User’s Guide902

Pagina 894

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide914.4 Device Registration Use this screen to register your ZyWALL with myZXEL.com and

Pagina 895

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide92Figure 30 Registration: Registered Device4.5 Installation Setup, Two Internet Service

Pagina 896

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide93Figure 31 Internet Access: Step 1: First WAN InterfaceAfter you configure the First W

Pagina 897

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide94Figure 33 Internet Access: Finish " You can register your ZyWALL with myZyXEL.com

Pagina 898

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide95Figure 34 VPN Wizard: Wizard TypeThe following table describes the labels in this scr

Pagina 899

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide96Figure 35 VPN Express Wizard: Step 2 The following table describes the labels in this

Pagina 900

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide97Pre-Shared Key: Type the password. Both ends of the VPN tunnel must use the same passwo

Pagina 901

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide98Figure 37 VPN Express Wizard: Step 4 The following table describes the labels in this

Pagina 902

Chapter 4 Wizard SetupZyWALL USG 100/200 Series User’s Guide99Local Policy: IP address and subnet mask of the computers on the network behind your Zy

Modelli collegati 100 Series

Commenti su questo manuale

Nessun commento