ZyXEL Communications Network Router USG 2000 Manual de usuario

Busca en linea o descarga Manual de usuario para Routers ZyXEL Communications Network Router USG 2000. ZyXEL Communications Network Router USG 2000 User's Manual Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 108
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 0
www.zyxel.com
www.zyxel.com
ZyWALL USG 2000
Unified Security Gateway
Copyright © 2010
ZyXEL Communications Corporation
Firmware Version 2.12
Edition 1, 3/2010
Default Login Details
LAN Port P1
IP Address https://192.168.1.1
User Name admin
Password 1234
Vista de pagina 0
1 2 3 4 5 6 ... 107 108

Indice de contenidos

Pagina 1 - ZyWALL USG 2000

www.zyxel.comwww.zyxel.comZyWALL USG 2000Unified Security GatewayCopyright © 2010 ZyXEL Communications CorporationFirmware Version 2.12Edition 1, 3/20

Pagina 2

Contents OverviewZyWALL USG 2000 User’s Guide10 Content Filtering ...

Pagina 3 - About This User's Guide

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1006.4 Packet FlowHere is the order in which the ZyWALL applies its features and checks.Fig

Pagina 4 - Customer Support

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1000Notice Information herein is subject to change without notice. Companies, names,

Pagina 5 - Disclaimer

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1001PPP LicenseCopyright (c) 1993 The Australian National University.All rights res

Pagina 6 - Document Conventions

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1002All rights reserved. Redistribution and use in source and binary forms, with or

Pagina 7 - Icons Used in Figures

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1003This Product includes expat-1.95.6 software under the Expat LicenseExpat Licens

Pagina 8 - Safety Warnings

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1004•This license is compatible with The GNU General Public License, Version 2This i

Pagina 9 - Contents Overview

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10052. Redistributions in binary form must reproduce the above copyright notice, th

Pagina 10

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1006be it the RC4, RSA, lhash, DES, etc., code; not just the SSL code. The SSL docum

Pagina 11 - Table of Contents

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1007This Product includes libevent-1.1a and xinetd-2.3.14 software under the a 3-cl

Pagina 12

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1008 * Neither the name of [original copyright holder] nor the names of its

Pagina 13 - Chapter 7

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1009DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING

Pagina 14

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide101• You do not need to set up policy routes for 1:1 NAT entries.• You can create Many 1:1

Pagina 15

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1010Permission to use, copy, modify, and distribute this software for any purpose wi

Pagina 16

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1011"License" shall mean the terms and conditions for use, reproduction,

Pagina 17 - Chapter 15

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1012"Contributor" shall mean Licensor and any individual or Legal Entity o

Pagina 18

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1013attribution notices within Derivative Works that You distribute, alongside or a

Pagina 19

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1014Contributor harmless for any liability incurred by, or claims asserted against,

Pagina 20

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1015USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. This s

Pagina 21

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1016guarantee your freedom to share and change free software--to make sure the softw

Pagina 22 - Chapter 35

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1017Most GNU software, including some libraries, is covered by the ordinary GNU Gen

Pagina 23

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10180. This License Agreement applies to any software library or other program which

Pagina 24

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1019still operates, and performs whatever part of its purpose remains meaningful. (

Pagina 25

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1022 Policy Routes: These are the user-configured policy routes. Configure policy routes to

Pagina 26

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1020"work that uses the Library". Such a work, in isolation, is not a deri

Pagina 27 - Chapter 51

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1021version is interface-compatible with the version that the work was made with. c

Pagina 28

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide102210. Each time you redistribute the Library (or any work based on the Library), t

Pagina 29 - Table of Contents

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1023Library does not specify a license version number, you may choose any version e

Pagina 30

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1024pcmcia-cs-3.2.8, libeeprog, mgetty-1.1.35, gmp-4.1, msmtp-1.4.12 and libqsearch

Pagina 31 - User’s Guide

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1025the software. Also, for each author's protection and ours, we want to make

Pagina 32

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1026b) You must cause any work that you distribute or publish, that in whole or in p

Pagina 33 - CHAPTER 1

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1027source code means all the source code for all modules it contains, plus any ass

Pagina 34

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1028whole is intended to apply in other circumstances. It is not the purpose of this

Pagina 35 - 1.3 Front Panel

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1029DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION

Pagina 36 - 1.3.1.2 Mini-GBIC Slots

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide103ZyWALL stops checking the packets against the NAT table and moves on to bandwidth manage

Pagina 37

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1030means a mechanism generally accepted in the software development community for t

Pagina 38

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10311.11. "Source Code" means the preferred form of the Covered Code for

Pagina 39 - 1.3.3 Front Panel LEDs

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1032Subject to third party intellectual property claims, each Contributor hereby gra

Pagina 40 - 1.4 Management Overview

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1033made available via Electronic Distribution Mechanism, must remain available for

Pagina 41 - Console Port

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1034You must duplicate the notice in Exhibit A in each file of the Source Code. If i

Pagina 42

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1035regulation then You must: (a) comply with the terms of this License to the maxi

Pagina 43 - CHAPTER 2

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1036(not the initial developer or any other contributor) assume the cost of any nece

Pagina 44 - Content Filter

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1037granted by You or any distributor hereunder prior to termination shall survive

Pagina 45 - 2.2 Applications

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1038As between Initial Developer and the Contributors, each party is responsible for

Pagina 46 - 2.2.1 VPN Connectivity

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1039NOTE: The text of this Exhibit A may differ slightly from the text of the notic

Pagina 47 - 2.2.2.2 Full Tunnel Mode

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1046.5.1 FeatureThis provides a brief description. See the appropriate chapter(s) in this U

Pagina 48

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1040USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. This Pr

Pagina 49 - 2.2.5 Device HA

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1041Redistribution and use of this software and associated documentation("Soft

Pagina 50

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1042Copyright 1999-2003 The OpenLDAP Foundation, Redwood City, California, USA. All

Pagina 51 - CHAPTER 3

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1043use of gd. If you have questions, ask. "Derived works" includes all p

Pagina 52 - Figure 19 Login Screen

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1044Copyright (C) 1999, 2000, 2002 Aladdin Enterprises. All rights reserved.This sof

Pagina 53 - Figure 21 Dashboard

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10453. This notice may not be removed or altered from any source distribution.COPYR

Pagina 54 - 3.3.2 Navigation Panel

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1046 * There is no warranty against interference with your enjoyment of the *

Pagina 55 - 3.3.2.2 Monitor Menu

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1047 * Greg Roelofs * Tom Tanner * * libpng versions 0.5, May 1995, through 0

Pagina 56 - 3.3.2.3 Configuration Menu

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1048 * to the following restrictions: * * 1. The origin of this source code must not

Pagina 57 - TAB FUNCTION

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10492. Redistributions in binary form must reproduce the above copyright notice, th

Pagina 58 - Chapter 3 Web Configurator

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide105subscription to update the anti-virus and IDP/application patrol signatures You must hav

Pagina 59

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1050PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTOR

Pagina 60 - 3.3.3 Main Window

ZyWALL USG 2000 User’s Guide1051APPENDIX F Legal InformationCopyrightCopyright © 2010 by ZyXEL Communications Corporation.The contents of this public

Pagina 61 - 3.3.3.3 Object Reference

Appendix F Legal InformationZyWALL USG 2000 User’s Guide1052• This device may not cause harmful interference.• This device must accept any interferenc

Pagina 62 - Table 8 Object References

Appendix F Legal InformationZyWALL USG 2000 User’s Guide1053Notices Changes or modifications not expressly approved by the party responsible for comp

Pagina 63 - 3.3.4 Tables and Lists

Appendix F Legal InformationZyWALL USG 2000 User’s Guide1054To obtain the services of this warranty, contact your vendor. You may also refer to the wa

Pagina 64

IndexZyWALL USG 2000 User’s Guide1055IndexSymbolsNumerics1 to 1 NAT 1021 to 1 SNAT 1033322 Dynamic DNS 3813DES 4713G 1223G see also cellular 299AAAABa

Pagina 65

IndexZyWALL USG 2000 User’s Guide1056and SNMP 827and SSH 818and Telnet 821and VPN connections 444and WWW 803HOST 705RANGE 706SUBNET 706types of 705whe

Pagina 66 - 3.3.4.3 Working with Lists

IndexZyWALL USG 2000 User’s Guide1057real-time alert message 965registration status 552scanner types 561signatures 558statistics 250trial service acti

Pagina 67 - CHAPTER 4

IndexZyWALL USG 2000 User’s Guide1058truncated-options 615truncated-timestamp-header 616TTCP-detected 615types of 574u-encoding 614undersize-len 615un

Pagina 68

IndexZyWALL USG 2000 User’s Guide1059bridge interfaces 278, 319and virtual interfaces of members 319basic characteristics 279effect on routing table 3

Pagina 69

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide106and general NAT on the source address. You have to set up the criteria, next-hops, and NA

Pagina 70 - 4.1.3 Internet Access: PPPoE

IndexZyWALL USG 2000 User’s Guide1060computer names 289, 315, 325, 334, 520computer virus 548infection and prevention 561see also virusconcurrent e-ma

Pagina 71 - 4.1.5 ISP Parameters

IndexZyWALL USG 2000 User’s Guide1061Ddashboard 53, 55, 209Data Encryption Standard, see DESData Terminal Ready, see DTRdate 785daylight savings 786DD

Pagina 72 - 4.1.5.1 PPTP Configuration

IndexZyWALL USG 2000 User’s Guide1062file structure 725directory traversal attack 613directory traversals 613disclaimer 5, 1051Distinguished Name (DN)

Pagina 73

IndexZyWALL USG 2000 User’s Guide1063basic characteristics 279virtual 329Ethernet ports 33, 35default settings 36examples (tutorials) 119exceptional s

Pagina 74 - 4.2 Device Registration

IndexZyWALL USG 2000 User’s Guide1064FTP 821additional signaling port 407ALG 401and address groups 823and address objects 823and certificates 822and z

Pagina 75

IndexZyWALL USG 2000 User’s Guide1065action 573, 608alerts 572and services 712applying custom signatures 592base profiles 564, 568configuration overvi

Pagina 76

IndexZyWALL USG 2000 User’s Guide1066and layer-3 virtualization 278and NAT 391and physical ports 96, 278and policy routes 355and static routes 359and

Pagina 77 - CHAPTER 5

IndexZyWALL USG 2000 User’s Guide1067Perfect Forward Secrecy 450PFS 450phase 2 settings 449policy enforcement 449remote access 448remote IPSec router

Pagina 78 - 5.2.2 Select WAN Type

IndexZyWALL USG 2000 User’s Guide1068remote user configuration 175session monitor 249troubleshooting 879where used 111WINS 520LANinterface 33IP addres

Pagina 79 - 5.2.3 Configure WAN Settings

IndexZyWALL USG 2000 User’s Guide1069main routing table 102main window 60maintenance menu 60malware 629managed web pages 627management accesstroublesh

Pagina 80

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1076.5.7 Static RoutesUse static routes to tell the ZyWALL about networks not directly con

Pagina 81 - Chapter 5 Quick Setup

IndexZyWALL USG 2000 User’s Guide1070NetBIOSBroadcast over IPSec 448Name Server, see NBNS.NetBIOS Name Server, see NBNSNetMeeting 408see also H.323Net

Pagina 82

IndexZyWALL USG 2000 User’s Guide1071offset attack 615request-uri-directory attack 614PP1 33P1~P8 LEDs 40P2P (Peer-to-peer) 574attacks 574see also Pee

Pagina 83 - 5.3 VPN Quick Setup

IndexZyWALL USG 2000 User’s Guide1072port sweep 610port translation, see NATport triggering 360and firewall 356, 876and policy routes 356and service g

Pagina 84

IndexZyWALL USG 2000 User’s Guide1073regular expressions 247reject (IDP)both 573, 608receiver 573, 608sender 573, 608related documentation 3Relative D

Pagina 85

IndexZyWALL USG 2000 User’s Guide1074SCEP (Simple Certificate Enrollment Protocol) 747scheduletroubleshooting 883schedules 717and content filtering 61

Pagina 86

IndexZyWALL USG 2000 User’s Guide1075and firewall 403and RTP 408media inactivity timeout 406signaling inactivity timeout 406signaling port 406troubles

Pagina 87

IndexZyWALL USG 2000 User’s Guide1076access policy 482configuration overview 110full tunnel mode 47, 482network access mode 46prerequisites 110remote

Pagina 88 - Chapter 5 Quick Setup

IndexZyWALL USG 2000 User’s Guide1077port numbers 712portscan 609portsweep 610RST 610SYN (synchronize) 611SYN flood 611window size 588technical refere

Pagina 89

IndexZyWALL USG 2000 User’s Guide1078PPP 872PWR 869RADIUS server 882routing 876schedules 883security settings 871shell scripts 885SIP 876SNAT 876SSL 8

Pagina 90

IndexZyWALL USG 2000 User’s Guide1079user portallinks 765logo 490see SSL user screens 493, 499user sessions, see sessionsuser SSL screens 493, 499acce

Pagina 91

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide108The ZyWALL only checks regular (through-ZyWALL) firewall rules for packets that are redir

Pagina 92

IndexZyWALL USG 2000 User’s Guide1080see also ALG 402VPN 441active protocol 476and NAT 474and the firewall 425basic troubleshooting 877hub-and-spoke,

Pagina 93

IndexZyWALL USG 2000 User’s Guide1081and authentication method objects 802and certificates 801and zones 803see also HTTP, HTTPS 148, 799Zzipped filest

Pagina 94

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1093 Name the entry.4 Select the interface from which you want to redirect incoming HTTP re

Pagina 95 - CHAPTER 6

Table of ContentsZyWALL USG 2000 User’s Guide11Table of ContentsAbout This User's Guide...

Pagina 96

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide110Example: Suppose you have a SIP proxy server connected to the DMZ zone for VoIP calls. Yo

Pagina 97 - 6.2.1 Interface Types

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide111Example: See Chapter 7 on page 119.6.5.17 L2TP VPNUse L2TP VPN to let remote users use

Pagina 98

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide112Note: With this example, Bob would have to log in using his account. If you do not want h

Pagina 99

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1131 Create a user account for Bill if you have not done so already (Configuration > Obj

Pagina 100 - 6.4 Packet Flow

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1146.6 ObjectsObjects store information and are referenced by other features. If you update

Pagina 101

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide115If you want to force users to log in to the ZyWALL before the ZyWALL routes traffic for

Pagina 102

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1162 Create an address object for the administrator’s computer (Configuration > Object &g

Pagina 103

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide117Always use Maintenance > Shutdown > Shutdown or the shutdown command before you tu

Pagina 104 - 6.5.3 Licensing Update

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide118

Pagina 105 - 6.5.6 Policy Routes

ZyWALL USG 2000 User’s Guide119CHAPTER 7 TutorialsHere are examples of using the Web Configurator to set up features in the ZyWALL. See also Chapter

Pagina 106

Table of ContentsZyWALL USG 2000 User’s Guide123.3 Web Configurator Screens Overview ...

Pagina 107 - 6.5.10 NAT

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide120• You want to be able to apply security settings specifically for all VPN tunnels so you create a ne

Pagina 108 - 6.5.11 HTTP Redirect

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1211 Click Configuration > Network > Zone and then the Add icon.2 Enter VPN as the name, select

Pagina 109 - 6.5.14 Firewall

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1222 Drag physical port 5 onto representative interface ge4 and click Apply.Figure 70 Configuration &

Pagina 110 - 6.5.16 SSL VPN

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1233 Click Configuration > Network > Interface > Cellular. Select the 3G device’s entry and c

Pagina 111 - 6.5.18 Application Patrol

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1245 Go to the Dashboard. The Interface Status Summary section should contain a “cellular” entry. When

Pagina 112 - 6.5.22 Content Filter

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide125You do not have to change many of the ZyWALL’s settings from the defaults to set up this trunk. You

Pagina 113 - 6.5.24 Device HA

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1267.3.2 Configure the WAN Trunk 1 Click Configuration > Network > Interface > Trunk. Click t

Pagina 114 - 6.6 Objects

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1273 Select the trunk as the default trunk and click Apply. Figure 78 Configuration > Network >

Pagina 115 - 6.7 System

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide128In this example, the ZyWALL is router X (1.2.3.4), and the remote IPSec router is router Y (2.2.2.2)

Pagina 116 - 6.7.5 Shutdown

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1297.4.2 Set Up the VPN ConnectionThe VPN connection manages the IPSec SA. You have to set up the add

Pagina 117 - MENU ITEM(S)

Table of ContentsZyWALL USG 2000 User’s Guide136.2.1 Interface Types ...

Pagina 118

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1304 Enable the VPN connection and name it (“VPN_CONN_EXAMPLE”). Under VPN Gateway select Site-to-site

Pagina 119 - CHAPTER 7

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1317.5 How to Configure a Hub-and-spoke IPSec VPN Without a VPN ConcentratorA hub-and-spoke IPSec VPN

Pagina 120 - 7.1.2 Configure Zones

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide132• My Address: 10.0.0.1• Peer Gateway Address: 10.0.0.2VPN Connection (VPN Tunnel 1): • Local Policy:

Pagina 121

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide133• To have all Internet access from the spoke routers to go through the VPN tunnel, set the VPN rule

Pagina 122

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1347.6.1 Set Up User AccountsSet up one user account for each user account in the RADIUS server. If it

Pagina 123

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1352 Enter the name of the group that is used in Table 20 on page 133. In this example, it is “Finance

Pagina 124 - ge3: 512 Kbps

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1361 Click Configuration > Object > AAA Server > RADIUS. Double-click the radius entry. Config

Pagina 125

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide137Note: The users will have to log in using the Web Configurator login screen before they can use HTT

Pagina 126

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1381 Click Configuration > AppPatrol. If application patrol and bandwidth management are not enabled

Pagina 127

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1393 Double-click the Default policy.Figure 91 Configuration > AppPatrol > Common > http4 C

Pagina 128 - 7.4.1 Set Up the VPN Gateway

Table of ContentsZyWALL USG 2000 User’s Guide147.1 How to Configure Interfaces, Port Grouping, and Zones ...

Pagina 129

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1405 Click the Add icon in the policy list. In the new policy, select one of the user groups that is al

Pagina 130

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1412 Give the schedule a descriptive name. Set up the days (Monday through Friday) and the times (8:30

Pagina 131 - Headquarters (ZyWALL USG):

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1422 Click the Add icon again and create a rule for one of the user groups that is allowed to access th

Pagina 132 - Branch Office B (ZyWALL USG):

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1431 Click Configuration > Object > AAA Server > RADIUS. Double-click the radius entry. Besid

Pagina 133

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1442 Now you add ext-group-user user objects to identify groups based on the group identifier values. S

Pagina 134 - 7.6.2 Set Up User Groups

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide145• Select Endpoint must have Personal Firewall installed and move the Kaspersky Internet Security en

Pagina 135

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide146Repeat as needed to create endpoint security objects for other Windows operating system versions.7.8

Pagina 136

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1474 Turn on authentication policy and click Apply.Figure 101 Configuration > Auth. Policy T

Pagina 137 - Authentication Policy)

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide148user access (logging into SSL VPN for example). See Chapter 50 on page 783 for more on service contr

Pagina 138 - Chapter 7 Tutorials

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1494 Select the new rule and click the Add icon.Figure 105 Configuration > System > WWW (First

Pagina 139 - Chapter 7 Tutorials

Table of ContentsZyWALL USG 2000 User’s Guide157.14 How to Use Active-Passive Device HA ...

Pagina 140 - 7.6.5 Set Up MSN Policies

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1506 Click Apply.Figure 107 Configuration > System > WWW (Second Example Admin Service Rule Con

Pagina 141 - 7.6.6 Set Up Firewall Rules

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide151for ge2 IP address 10.0.0.8 to a H.323 device located on the LAN and using IP address 192.168.1.56.

Pagina 142 - User Accounts based on Groups

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1521 Use Configuration > Object > Address > Add to create an address object for the public WAN

Pagina 143

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1532 Click Configuration > Network > NAT > Add.Configure a name for the rule (WAN-LAN_H323 he

Pagina 144 - Authentication Policies

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1541 Click Configuration > Firewall > Add.In the From field select WAN.In the To field select LAN

Pagina 145

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1557.11.1 Create the Address ObjectsUse Configuration > Object > Address > Add to create the

Pagina 146

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide156• Keep Enable NAT Loopback selected to allow users connected to other interfaces to access the HTTP

Pagina 147

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1571 Click Configuration > Firewall > Add. Set the From field as WAN and the To field as DMZ. Se

Pagina 148

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide158address 1.1.1.2 that you will use on the ge3 interface and map to the IPPBX’s private IP address of

Pagina 149 - Configured)

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1597.12.1 Turn On the ALGClick Configuration > Network > ALG. Select Enable SIP ALG and Enable

Pagina 150

Table of ContentsZyWALL USG 2000 User’s Guide1610.6 The DDNS Status Screen ...

Pagina 151 - 7.10.1 Turn On the ALG

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1602 Create a host address object named IPPBX-Public for the public WAN IP address 1.1.1.2. Figure 121

Pagina 152

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide161•Click OK. Figure 122 Configuration > Network > NAT > Add 7.12.4 Set Up a WAN to DMZ F

Pagina 153

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1621 Click Configuration > Firewall > Add. Set the From field as WAN and the To field as DMZ. Set

Pagina 154

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1631 Click Configuration > Firewall > Add. Set the From field as DMZ and the To field as LAN. Se

Pagina 155 - 7.11.2 Configure NAT

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1647.13.2 Configure the Policy RouteNow you need to configure a policy route that has the ZyWALL use t

Pagina 156

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide165An Ethernet switch connects both ZyWALLs’ ge1 interfaces to the LAN. Whichever ZyWALL is functionin

Pagina 157

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1667.14.2 Configure Device HA on the Master ZyWALL1 Log into ZyWALL A (the master) and click Configura

Pagina 158

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1673 Set the Device Role to Master. This example focuses on the connection from the LAN (ge1) to the I

Pagina 159 - 7.12.1 Turn On the ALG

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1687.14.3 Configure the Backup ZyWALL1 Connect a computer to ZyWALL B’s ge1 interface and log into its

Pagina 160

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1694 Set the Device Role to Backup. Activate monitoring for the ge1 and ge2 interfaces. Set the Synchr

Pagina 161

Table of ContentsZyWALL USG 2000 User’s Guide1713.2 Port Grouping ...

Pagina 162

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1707.14.4 Deploy the Backup ZyWALLConnect ZyWALL B’s ge1 interface to the LAN network. Connect ZyWALL

Pagina 163

ZyWALL USG 2000 User’s Guide171CHAPTER 8 L2TP VPN ExampleHere is how to create a basic L2TP VPN tunnel.8.1 L2TP VPN ExampleThis example uses the fol

Pagina 164

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide172• Configure the My Address setting. This example uses interface ge2 with static IP address 17

Pagina 165 - 7.14.1 Before You Start

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1738.3 Configuring the Default L2TP VPN Connection Example1 Click Configuration > VPN >

Pagina 166 - ZyWALL Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1743 Select the Default_L2TP_VPN_Connection entry and click Activate and then Apply to turn on t

Pagina 167 - Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide175• The other fields are left to the defaults in this example, click Apply.Figure 140 Config

Pagina 168

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1762 Select Connect to a workplace and click Next.Figure 141 Set up a connection or network: C

Pagina 169

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1774 Enter the domain name or WAN IP address configured as the My Address in the VPN gateway co

Pagina 170

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1786 Click Close. Figure 145 Connect to a workplace: The connection is ready to use7 In the Ne

Pagina 171 - CHAPTER 8

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1798 Click Security, select Advanced (custom settings) and click Settings.Figure 147 Connect

Pagina 172

Table of ContentsZyWALL USG 2000 User’s Guide18Chapter 16Routing Protocols...

Pagina 173 - Connection Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide180inside it. The L2TP tunnel itself does not need encryption since it is inside the encrypted I

Pagina 174

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18113 Select the L2TP VPN connection and click Connect.Figure 152 L2TP to ZyWALL Properties:

Pagina 175

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18215 A window appears while the user name and password are verified and notifies you when the c

Pagina 176 - Chapter 8 L2TP VPN Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18317 After the network location has been set, click Close.Figure 156 Set Network Location Su

Pagina 177

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18419 Click the L2TP connection’s View status link to open a status screen. Figure 158 Network

Pagina 178 - 6 Click Close

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1858.5.2 Configuring L2TP in Windows XPIn Windows XP do the following to establish an L2TP VPN

Pagina 179

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1865 Type L2TP to ZyWALL as the Company Name.Figure 162 New Connection Wizard: Connection Name

Pagina 180

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1877 Enter the domain name or WAN IP address configured as the My Address in the VPN gateway co

Pagina 181 - Chapter 8 L2TP VPN Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18810 Click Security, select Advanced (custom settings) and click Settings.Figure 166 Connect

Pagina 182

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18912 Click IPSec Settings. Figure 168 L2TP to ZyWALL Properties > Security13 Select the U

Pagina 183

Table of ContentsZyWALL USG 2000 User’s Guide1920.2.1 The HTTP Redirect Edit Screen ...

Pagina 184

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide19014 Click Networking. Select L2TP IPSec VPN as the Type of VPN. Click OK.Figure 170 L2TP to

Pagina 185

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide19118 Click Details to see the address that you received is from the L2TP range you specified o

Pagina 186

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1923 Select HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasman\Parameters.Figure 175

Pagina 187 - 172.16.1.2

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1938.5.3.2 Configure the Windows 2000 IPSec PolicyAfter you have created the registry entry an

Pagina 188

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1943 Click Add > IP Security Policy Management >Add > Finish. Click Close > OK.Figur

Pagina 189

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1955 Name the IP security policy L2TP to ZyWALL, and click Next.Figure 182 IP Security Policy

Pagina 190

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1967 Leave the Edit Properties check box selected and click Finish.Figure 184 IP Security Poli

Pagina 191

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1979 Select This rule does not specify a tunnel and click Next.Figure 186 IP Security Policy

Pagina 192 - Figure 176 New DWORD Value

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide19811 Select Use this string to protect the key exchange (preshared key), type password in the t

Pagina 193 - Figure 178 Run mmc

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide19913 Type ZyWALL WAN_IP in the Name field. Clear the Use Add Wizard check box and click Add.Fi

Pagina 195

Table of ContentsZyWALL USG 2000 User’s Guide2025.1 IPSec VPN Overview ...

Pagina 196

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide20015 Configure the following in the Filter Properties window’s Protocol tab. Set the protocol t

Pagina 197

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide20117 Select Require Security and click Next. Then click Finish and Close.Figure 194 IP Secu

Pagina 198 - 12 Click Add

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide2021 Click Start > Settings > Network and Dial-up connections > Make New Connection. In

Pagina 199

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide2034 Select For all users and click Next.Figure 199 New Connection Wizard: Connection Availab

Pagina 200

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide2047 Click Security and select Advanced (custom settings) and click Settings.Figure 202 Connec

Pagina 201

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide2059 Click Networking and select Layer 2 Tunneling Protocol (L2TP) from the drop-down list box.

Pagina 202

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide20612 Click Details and scroll down to see the address that you received is from the L2TP range

Pagina 203 - 6 Click Properties

207PART IITechnical Reference

Pagina 205

ZyWALL USG 2000 User’s Guide209CHAPTER 9 Dashboard9.1 OverviewUse the Dashboard screens to check status information about the ZyWALL.9.1.1 What Yo

Pagina 206

Table of ContentsZyWALL USG 2000 User’s Guide2129.1.1 What You Need to Know ...

Pagina 207 - Technical Reference

Chapter 9 DashboardZyWALL USG 2000 User’s Guide210interface status in widgets that you can re-arrange to suit your needs. You can also collapse, refre

Pagina 208

Chapter 9 DashboardZyWALL USG 2000 User’s Guide211The following front and rear panel labels display when you hover your cursor over a connected inter

Pagina 209 - CHAPTER 9

Chapter 9 DashboardZyWALL USG 2000 User’s Guide212Device This identifies a device installed in one of the ZyWALL’s extension slots, the Security Exten

Pagina 210 - Table 21 Dashboard

Chapter 9 DashboardZyWALL USG 2000 User’s Guide213Status This field displays the current status of each interface. The possible values depend on what

Pagina 211 - LABEL DESCRIPTION

Chapter 9 DashboardZyWALL USG 2000 User’s Guide214Action Use this field to get or to update the IP address for the interface. Click Renew to send a ne

Pagina 212 - Chapter 9 Dashboard

Chapter 9 DashboardZyWALL USG 2000 User’s Guide215Number of Login UsersThis field displays the number of users currently logged in to the ZyWALL. Cli

Pagina 213

Chapter 9 DashboardZyWALL USG 2000 User’s Guide2169.2.1 The CPU Usage ScreenUse this screen to look at a chart of the ZyWALL’s recent CPU usage. To a

Pagina 214

Chapter 9 DashboardZyWALL USG 2000 User’s Guide217The following table describes the labels in this screen. 9.2.2 The Memory Usage ScreenUse this sc

Pagina 215

Chapter 9 DashboardZyWALL USG 2000 User’s Guide2189.2.3 The Session Usage ScreenUse this screen to look at a chart of the ZyWALL’s recent traffic ses

Pagina 216 - 9.2.1 The CPU Usage Screen

Chapter 9 DashboardZyWALL USG 2000 User’s Guide2199.2.4 The VPN Status ScreenUse this screen to look at the VPN tunnels that are currently establish

Pagina 217

Table of ContentsZyWALL USG 2000 User’s Guide2233.1.2 What You Need to Know ...

Pagina 218

Chapter 9 DashboardZyWALL USG 2000 User’s Guide220The following table describes the labels in this screen. 9.2.6 The Number of Login Users ScreenUse

Pagina 219 - 9.2.5 The DHCP Table Screen

Chapter 9 DashboardZyWALL USG 2000 User’s Guide221The following table describes the labels in this screen. Table 27 Dashboard > Number of Login

Pagina 220

Chapter 9 DashboardZyWALL USG 2000 User’s Guide222

Pagina 221

ZyWALL USG 2000 User’s Guide223CHAPTER 10 Monitor10.1 OverviewUse the Monitor screens to check status and statistics information.10.1.1 What You C

Pagina 222

Chapter 10 MonitorZyWALL USG 2000 User’s Guide224•Use the VPN Monitor > L2TP over IPSec screen (see Section 10.13 on page 249) to display and manag

Pagina 223 - CHAPTER 10

Chapter 10 MonitorZyWALL USG 2000 User’s Guide225The following table describes the labels in this screen. Table 28 Monitor > System Status >

Pagina 224

Chapter 10 MonitorZyWALL USG 2000 User’s Guide22610.2.1 The Port Statistics Graph Screen Use this screen to look at a line graph of packet statistics

Pagina 225 - Chapter 10 Monitor

Chapter 10 MonitorZyWALL USG 2000 User’s Guide22710.3 Interface Status ScreenThis screen lists all of the ZyWALL’s interfaces and gives packet stati

Pagina 226

Chapter 10 MonitorZyWALL USG 2000 User’s Guide228Each field is described in the following table. Table 30 Monitor > System Status > Interface

Pagina 227 - 10.3 Interface Status Screen

Chapter 10 MonitorZyWALL USG 2000 User’s Guide229HA Status This field displays the status of the interface in the virtual router.Active - This interf

Pagina 228 - Chapter 10 Monitor

Table of ContentsZyWALL USG 2000 User’s Guide2335.1.4 Before You Begin ...

Pagina 229

Chapter 10 MonitorZyWALL USG 2000 User’s Guide23010.4 The Traffic Statistics ScreenClick Monitor > System Status > Traffic Statistics to displa

Pagina 230

Chapter 10 MonitorZyWALL USG 2000 User’s Guide231You use the Traffic Statistics screen to tell the ZyWALL when to start and when to stop collecting i

Pagina 231

Chapter 10 MonitorZyWALL USG 2000 User’s Guide232Interface Select the interface from which to collect information. You can collect information from Et

Pagina 232

Chapter 10 MonitorZyWALL USG 2000 User’s Guide233The following table displays the maximum number of records shown in the report, the byte count limit

Pagina 233

Chapter 10 MonitorZyWALL USG 2000 User’s Guide234• Number of bytes transmitted (so far)• Duration (so far)You can look at all the active sessions by u

Pagina 234

Chapter 10 MonitorZyWALL USG 2000 User’s Guide235User This field displays when View is set to all sessions. Type the user whose sessions you want to

Pagina 235

Chapter 10 MonitorZyWALL USG 2000 User’s Guide23610.6 The DDNS Status ScreenThe DDNS Status screen shows the status of the ZyWALL’s DDNS domain names

Pagina 236 - 10.7 IP/MAC Binding Monitor

Chapter 10 MonitorZyWALL USG 2000 User’s Guide237session with the ZyWALL. Devices that have never established a session with the ZyWALL do not displa

Pagina 237

Chapter 10 MonitorZyWALL USG 2000 User’s Guide23810.8 The Login Users Screen Use this screen to look at a list of the users currently logged into the

Pagina 238 - 10.8 The Login Users Screen

Chapter 10 MonitorZyWALL USG 2000 User’s Guide23910.9 Cellular Status ScreenThis screen displays your 3G connection status. click Monitor > Syste

Pagina 239 - 10.9 Cellular Status Screen

Table of ContentsZyWALL USG 2000 User’s Guide2438.7 Anti-Spam Technical Reference ...

Pagina 240

Chapter 10 MonitorZyWALL USG 2000 User’s Guide240Status No device - no 3G device is connected to the ZyWALL.Device detected - displays when you connec

Pagina 241

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24110.10 Application Patrol StatisticsThis screen displays a bandwidth usage graph and statistics for

Pagina 242

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24210.10.2 Application Patrol Statistics: Bandwidth StatisticsThe middle of the Monitor > AppPatrol

Pagina 243

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24310.10.3 Application Patrol Statistics: Protocol StatisticsThe bottom of the Monitor > AppPatrol

Pagina 244 - Statistics by Rule

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24410.10.4 Application Patrol Statistics: Individual Protocol Statistics by RuleThe bottom of the Moni

Pagina 245

Chapter 10 MonitorZyWALL USG 2000 User’s Guide245The following table describes the labels in this screen. 10.11 The IPSec Monitor Screen You can us

Pagina 246

Chapter 10 MonitorZyWALL USG 2000 User’s Guide246screen appears. Click a column’s heading cell to sort the table entries by that column’s criteria. Cl

Pagina 247

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24710.11.1 Regular Expressions in Searching IPSec SAsA question mark (?) lets a single character in th

Pagina 248

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24810.12 The SSL Connection Monitor Screen The ZyWALL keeps track of the users who are currently logged

Pagina 249

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24910.13 L2TP over IPSec Session Monitor ScreenClick Monitor > VPN Monitor > L2TP over IPSec to

Pagina 250

Table of ContentsZyWALL USG 2000 User’s Guide2542.1.1 What You Can Do in this Chapter ...

Pagina 251

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25010.14 The Anti-Virus Statistics ScreenClick Monitor > Anti-X Statistics > Anti-Virus to displa

Pagina 252

Chapter 10 MonitorZyWALL USG 2000 User’s Guide251The statistics display as follows when you display the top entries by source.Figure 232 Monitor &g

Pagina 253

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25210.15 The IDP Statistics ScreenClick Monitor > Anti-X Statistics > IDP to display the followin

Pagina 254

Chapter 10 MonitorZyWALL USG 2000 User’s Guide253The statistics display as follows when you display the top entries by source.Figure 235 Monitor &g

Pagina 255

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25410.16 The Content Filter Statistics ScreenClick Monitor > Anti-X Statistics > Content Filter t

Pagina 256

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25510.17 Content Filter Cache ScreenClick Monitor > Anti-X Statistics > Content Filter > Cach

Pagina 257

Chapter 10 MonitorZyWALL USG 2000 User’s Guide256You can remove individual entries from the cache. When you do this, the ZyWALL queries the external c

Pagina 258

Chapter 10 MonitorZyWALL USG 2000 User’s Guide257Category This field shows whether access to the web site’s URL was blocked or allowed.Click the colu

Pagina 259

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25810.18 The Anti-Spam Statistics ScreenClick Monitor > Anti-X Statistics > Anti-Spam to display

Pagina 260

Chapter 10 MonitorZyWALL USG 2000 User’s Guide259Spam Mails This is the number of e-mails that the ZyWALL has determined to be spam.Spam Mails Detect

Pagina 261 - 10.20 Log Screen

Table of ContentsZyWALL USG 2000 User’s Guide2646.1.3 Verifying a Certificate ...

Pagina 262 - Table 50 Monitor > Log

Chapter 10 MonitorZyWALL USG 2000 User’s Guide26010.19 The Anti-Spam Status ScreenClick Monitor > Anti-X Statistics > Anti-Spam > Status to

Pagina 263

Chapter 10 MonitorZyWALL USG 2000 User’s Guide26110.20 Log ScreenLog messages are stored in two separate logs, one for regular log messages and one

Pagina 264

Chapter 10 MonitorZyWALL USG 2000 User’s Guide262The following table describes the labels in this screen. Table 50 Monitor > LogLABEL DESCRIPTIO

Pagina 265 - CHAPTER 11

Chapter 10 MonitorZyWALL USG 2000 User’s Guide263The Web Configurator saves the filter settings if you leave the View Log screen and return to it lat

Pagina 266 - Anti-Virus Engines

Chapter 10 MonitorZyWALL USG 2000 User’s Guide264

Pagina 267 - 11.2 The Registration Screen

ZyWALL USG 2000 User’s Guide265CHAPTER 11 Registration11.1 OverviewUse the Configuration > Licensing > Registration screens to register your Z

Pagina 268 - Chapter 11 Registration

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide266Subscription Services Available on the ZyWALLYou can have the ZyWALL use anti-virus, IDP/AppPatr

Pagina 269 - 11.3 The Service Screen

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide26711.2 The Registration ScreenUse this screen to register your ZyWALL with myZyXEL.com and activ

Pagina 270

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide268Confirm Password Enter the password again for confirmation.E-Mail Address Enter your e-mail addr

Pagina 271 - CHAPTER 12

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide269Note: If the ZyWALL is registered already, this screen is read-only and indicates whether trial

Pagina 272

Table of ContentsZyWALL USG 2000 User’s Guide2750.4 Console Port Speed ...

Pagina 273

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide270The following table describes the labels in this screen. Table 52 Configuration > Licensing

Pagina 274

ZyWALL USG 2000 User’s Guide271CHAPTER 12 Signature Update12.1 OverviewThis chapter shows you how to update the ZyWALL’s signature packages.12.1.1

Pagina 275

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide27212.2 The Antivirus Update ScreenClick Configuration > Licensing > Update > Anti-Vi

Pagina 276 - Chapter 12 Signature Update

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide27312.3 The IDP/AppPatrol Update ScreenClick Configuration > Licensing > Update > ID

Pagina 277 - CHAPTER 13

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide274signatures from myZyXEL.com (see the Registration screens). Use the Update IDP /AppPatrol sc

Pagina 278 - Types of Interfaces

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide27512.4 The System Protect Update Screen Click Configuration > Licensing > Update >

Pagina 279 - Characteristics

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide276The following table describes the fields in this screen. Table 54 Configuration > Licen

Pagina 280 - 13.2 Port Grouping

ZyWALL USG 2000 User’s Guide277CHAPTER 13 Interfaces13.1 Interface OverviewUse the Interface screens to configure the ZyWALL’s interfaces. You can a

Pagina 281 - 13.2.2 Port Grouping Screen

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide27813.1.2 What You Need to Know Interface CharacteristicsInterfaces generally have the following cha

Pagina 282 - 13.3 Ethernet Summary Screen

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide279characteristics. These characteristics are listed in the following table and discussed in more de

Pagina 283 - LABEL DESCRIPTION

Table of ContentsZyWALL USG 2000 User’s Guide2851.1.1 What You Can Do In this Chapter ...

Pagina 284 - 13.3.1 Ethernet Edit

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide280* - You cannot set up a PPP interface, virtual Ethernet interface or virtual VLAN interface if the

Pagina 285

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide28113.2.1 Port Grouping OverviewUse port grouping to create port groups and to assign physical port

Pagina 286 - Chapter 13 Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide282Each section in this screen is described below.13.3 Ethernet Summary ScreenThis screen lists ever

Pagina 287

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide283Figure 249 Configuration > Network > Interface > Ethernet Each field is described

Pagina 288

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide28413.3.1 Ethernet Edit The Ethernet Edit screen lets you configure IP address assignment, interface

Pagina 289

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide285Figure 250 Configuration > Network > Interface > Ethernet > Edit

Pagina 290

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide286This screen’s fields are described in the table below. Table 59 Configuration > Network

Pagina 291 - 13.3.2 Object References

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide287Use Fixed IP AddressThis option appears when Interface Properties is External or General. Select

Pagina 292 - 13.4 PPP Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide288Check Period Enter the number of seconds between connection check attempts.Check Timeout Enter the

Pagina 293 - 13.4.1 PPP Interface Summary

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide289Pool Size Enter the number of IP addresses to allocate. This number must be at least one and is l

Pagina 294

Table of ContentsZyWALL USG 2000 User’s Guide29Chapter 57Product Specifications...

Pagina 295

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide290IP Address Enter the IP address to assign to a device with this entry’s MAC address.MAC Address En

Pagina 296

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide29113.3.2 Object ReferencesWhen a configuration screen includes an Object References icon, select a

Pagina 297

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide292Figure 251 Object References The following table describes labels that can appear in this scr

Pagina 298

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide293Figure 252 Example: PPPoE/PPTP InterfacesPPPoE/PPTP interfaces are similar to other interfaces

Pagina 299

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide294Figure 253 Configuration > Network > Interface > PPP Each field is described in the

Pagina 300

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide29513.4.2 PPP Interface Add or Edit Note: You have to set up an ISP account before you create a PPP

Pagina 301

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide296Figure 254 Configuration > Network > Interface > PPP > Add Each field is explaine

Pagina 302

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide297Enable InterfaceSelect this to enable this interface. Clear this to disable this interface.Interf

Pagina 303

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide298Interface ParametersEgress BandwidthEnter the maximum amount of traffic, in kilobits per second, t

Pagina 304

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide29913.5 Cellular Configuration Screen (3G)3G (Third Generation) is a digital, packet-switched wirel

Pagina 305

About This User's GuideZyWALL USG 2000 User’s Guide3About This User's GuideIntended AudienceThis manual is intended for people who want to

Pagina 306

Table of ContentsZyWALL USG 2000 User’s Guide30

Pagina 307

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide300If the signal strength of a 3G network is too low, the 3G card may switch to an available 2.5G or

Pagina 308 - 13.6 VLAN Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide301Figure 255 Configuration > Network > Interface > Cellular The following table descri

Pagina 309 - VLAN Interfaces Overview

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide302Figure 256 Configuration > Network > Interface > Cellular > Add

Pagina 310 - 13.6.1 VLAN Summary Screen

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide303The following table describes the labels in this screen.Table 65 Configuration > Network >

Pagina 311 - 13.6.2 VLAN Add/Edit

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide304Dial String Enter the dial string if your ISP provides a string, which would include the APN, to i

Pagina 312

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide305Egress BandwidthEnter the maximum amount of traffic, in kilobits per second, the ZyWALL can send

Pagina 313

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide306Get Automatically Select this option If your ISP did not assign you a fixed IP address. This is th

Pagina 314

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide307Data Budget Select this and specify how much downstream and/or upstream data (in Mega bytes) can

Pagina 315

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide30813.6 VLAN Interfaces A Virtual Local Area Network (VLAN) divides a physical network into multiple

Pagina 316

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide309Each VLAN is a separate network with separate IP addresses, subnet masks, and gateways. Each VLAN

Pagina 317

31PART IUser’s Guide

Pagina 318 - 13.7 Bridge Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide310They restrict bandwidth and packet size. They can provide DHCP services, and they can verify the g

Pagina 319 - Bridge Interface Overview

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide31113.6.2 VLAN Add/Edit This screen lets you configure IP address assignment, interface bandwidth p

Pagina 320 - 13.7.1 Bridge Summary

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide312Figure 260 Configuration > Network > Interface > VLAN > Edit

Pagina 321 - 13.7.2 Bridge Add/Edit

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide313Each field is explained in the following table. Table 67 Configuration > Network > Interf

Pagina 322

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide314Metric Enter the priority of the gateway (if any) on this interface. The ZyWALL decides which gate

Pagina 323

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide315DHCP Select what type of DHCP service the ZyWALL provides to the network. Choices are:None - the

Pagina 324

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide316Lease time Specify how long each computer can use the information (especially the IP address) befo

Pagina 325

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide317OSPF Setting See Section 16.3 on page 365 for more information about OSPF.Area Select the area in

Pagina 326

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide31813.7 Bridge Interfaces This section introduces bridges and bridge interfaces and then explains th

Pagina 327 - 13.8 Auxiliary Interface

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide319If computer B responds to computer A, bridge X records the source address 0B:0B:0B:0B:0B:0B and p

Pagina 329 - 13.9 Virtual Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide32013.7.1 Bridge SummaryThis screen lists every bridge interface and virtual interface created on to

Pagina 330

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide32113.7.2 Bridge Add/Edit This screen lets you configure IP address assignment, interface bandwidth

Pagina 331 - IP Address Assignment

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide322Figure 262 Configuration > Network > Interface > Bridge > Add

Pagina 332 - Interface Parameters

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide323Each field is described in the table below.Table 72 Configuration > Network > Interface &

Pagina 333 - DHCP Settings

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide324Gateway This field is enabled if you select Use Fixed IP Address.Enter the IP address of the gatew

Pagina 334

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide325IP Pool Start AddressEnter the IP address from which the ZyWALL begins allocating IP addresses. I

Pagina 335 - PPPoE/PPTP Overview

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide326Add Click this to create a new entry. Edit Select an entry and click this to be able to modify it.

Pagina 336

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide32713.8 Auxiliary Interface This section introduces the auxiliary interface and then explains the s

Pagina 337 - CHAPTER 14

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide328Figure 263 Configuration > Network > Interface > Auxiliary Each field is described in

Pagina 338 - 14.1.2 What You Need to Know

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide32913.9 Virtual Interfaces Use virtual interfaces to tell the ZyWALL where to route packets. Virtua

Pagina 339 - Least Load First

ZyWALL USG 2000 User’s Guide33CHAPTER 1 Introducing the ZyWALLThis chapter gives an overview of the ZyWALL. It explains the front panel ports, LEDs,

Pagina 340 - Spillover

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide330cannot change the MTU. The virtual interface uses the same MTU that the underlying interface uses.

Pagina 341 - Finding Out More

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide33113.10 Interface Technical ReferenceHere is more detailed information about interfaces on the ZyW

Pagina 342

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide332For example, if the ZyWALL gets a packet with a destination address of 100.100.25.25, it routes th

Pagina 343 - 14.3 Configuring a Trunk

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide333• Egress bandwidth sets the amount of traffic the ZyWALL sends out through the interface to the n

Pagina 344 - Chapter 14 Trunks

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide334• IP address - If the DHCP client’s MAC address is in the ZyWALL’s static DHCP table, the interfac

Pagina 345

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide335PPPoE/PPTP OverviewPoint-to-Point Protocol over Ethernet (PPPoE, RFC 2516) and Point-to-Point Tun

Pagina 346

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide336

Pagina 347 - CHAPTER 15

ZyWALL USG 2000 User’s Guide337CHAPTER 14 Trunks14.1 OverviewUse trunks for WAN traffic load balancing to increase overall network throughput and r

Pagina 348 - Static Routes

Chapter 14 TrunksZyWALL USG 2000 User’s Guide33814.1.2 What You Need to Know• Add WAN interfaces to trunks to have multiple connections share the tra

Pagina 349 - DiffServ

Chapter 14 TrunksZyWALL USG 2000 User’s Guide3392 The ZyWALL is using active/active load balancing. So when LAN user A tries to access something on t

Pagina 350 - 15.2 Policy Route Screen

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide34standard EIA rack using a rack-mounting kit. Make sure the rack will safely support the

Pagina 351

Chapter 14 TrunksZyWALL USG 2000 User’s Guide340Since WAN 2 has a smaller load balancing index (meaning that it is less utilized than WAN 1), the ZyWA

Pagina 352

Chapter 14 TrunksZyWALL USG 2000 User’s Guide341interface. This fully utilizes the bandwidth of the first interface to reduce Internet usage fees and

Pagina 353

Chapter 14 TrunksZyWALL USG 2000 User’s Guide34214.2 The Trunk Summary ScreenClick Configuration > Network > Interface > Trunk to open the T

Pagina 354

Chapter 14 TrunksZyWALL USG 2000 User’s Guide34314.3 Configuring a Trunk Click Configuration > Network > Interface > Trunk and then the Add

Pagina 355

Chapter 14 TrunksZyWALL USG 2000 User’s Guide344Each field is described in the table below. Table 80 Configuration > Network > Interface >

Pagina 356

Chapter 14 TrunksZyWALL USG 2000 User’s Guide34514.4 Trunk Technical ReferenceRound Robin Load Balancing AlgorithmRound Robin scheduling services qu

Pagina 357 - 15.3 IP Static Route Screen

Chapter 14 TrunksZyWALL USG 2000 User’s Guide346

Pagina 358

ZyWALL USG 2000 User’s Guide347CHAPTER 15 Policy and Static Routes15.1 Policy and Static Routes OverviewUse policy routes and static routes to overr

Pagina 359 - NAT and SNAT

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide348•Use the Static Route screens (see Section 15.3 on page 357) to list and configure s

Pagina 360 - Port Triggering

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide349Policy Routes Versus Static Routes• Policy routes are more flexible than static rou

Pagina 361 - Maximize Bandwidth Usage

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide353 After attaching both mounting brackets, position the ZyWALL in the rack by lining up

Pagina 362

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide350Finding Out More• See Section 6.5.6 on page 105 for related information on the polic

Pagina 363 - CHAPTER 16

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide351The following table describes the labels in this screen. Table 81 Configuration

Pagina 364 - 16.2 The RIP Screen

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide352DSCP Code This is the DSCP value of incoming packets to which this policy route appl

Pagina 365 - 16.3 The OSPF Screen

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide35315.2.1 Policy Route Edit ScreenClick Configuration > Network > Routing to op

Pagina 366 - OSPF Areas

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide354Incoming Select where the packets are coming from; any, an interface, a tunnel, an S

Pagina 367 - OSPF Routers

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide355VPN Tunnel This field displays when you select VPN Tunnel in the Type field. Select

Pagina 368 - Virtual Links

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide356Source Network Address TranslationSelect none to not use NAT for the route.Select ou

Pagina 369 - OSPF Configuration

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide35715.3 IP Static Route ScreenClick Configuration > Network > Routing > Stat

Pagina 370

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide358The following table describes the labels in this screen. 15.3.1 Static Route Add/Ed

Pagina 371 - Chapter 16 Routing Protocols

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide35915.4 Policy Routing Technical ReferenceHere is more detailed information about som

Pagina 372

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide361.3.1.1 1000Base-T PortsThe 1000Base-T auto-negotiating, auto-crossover Ethernet ports

Pagina 373

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide360following twelve DSCP encodings from AF11 through AF43. The decimal equivalent is li

Pagina 374

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide3613 Computer A and game server 1 are connected to each other until the connection is

Pagina 375 - Authentication Types

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide362

Pagina 376 - Chapter 16 Routing Protocols

ZyWALL USG 2000 User’s Guide363CHAPTER 16 Routing Protocols16.1 Routing Protocols OverviewRouting protocols give the ZyWALL routing information abou

Pagina 377 - CHAPTER 17

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide36416.2 The RIP ScreenRIP (Routing Information Protocol, RFC 1058 and RFC 1389) allows a devi

Pagina 378 - 17.1.2 What You Need to Know

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide365The following table describes the labels in this screen. 16.3 The OSPF ScreenOSPF (Open

Pagina 379 - 17.2 The Zone Screen

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide366System (AS). OSPF offers some advantages over vector-space routing protocols like RIP.• OSP

Pagina 380 - 17.3 Zone Edit

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide367Each type of area is illustrated in the following figure.Figure 279 OSPF: Types of Areas

Pagina 381 - CHAPTER 18

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide368• An Autonomous System Boundary Router (ASBR) exchanges routing information with routers in

Pagina 382 - 18.2 The DDNS Screen

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide369to logically connect the area to the backbone. This is illustrated in the following exampl

Pagina 383 - Chapter 18 DDNS

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide371 Insert the transceiver into the slot with the exposed section of PCB board facing dow

Pagina 384

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide370Click Configuration > Network > Routing > OSPF to open the following screen.Figure

Pagina 385 - DDNS server

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide371Type Select how OSPF calculates the cost associated with routing information from static r

Pagina 386

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide37216.3.2 OSPF Area Add/Edit Screen The OSPF Area Add/Edit screen allows you to create a new

Pagina 387 - CHAPTER 19

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide37316.3.3 Virtual Link Add/Edit Screen The Virtual Link Add/Edit screen allows you to create

Pagina 388 - 19.2 The NAT Screen

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide374372) has the Type set to Normal, a Virtual Link table displays. Click either the Add icon o

Pagina 389 - Chapter 19 NAT

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide375Authentication TypesAuthentication is used to guarantee the integrity, but not the confide

Pagina 390

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide376

Pagina 391

ZyWALL USG 2000 User’s Guide377CHAPTER 17 Zones17.1 Zones OverviewSet up zones to configure network security and network policies in the ZyWALL. A z

Pagina 392 - Chapter 19 NAT

Chapter 17 ZonesZyWALL USG 2000 User’s Guide37817.1.2 What You Need to KnowEffects of Zones on Different Types of TrafficZones effectively divide tra

Pagina 393 - 19.3 NAT Technical Reference

Chapter 17 ZonesZyWALL USG 2000 User’s Guide37917.2 The Zone ScreenThe Zone screen provides a summary of all zones. In addition, this screen allows

Pagina 394

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide381 Press down on the top of the fiber-optic cable where it connects to the transceiver to

Pagina 395

Chapter 17 ZonesZyWALL USG 2000 User’s Guide38017.3 Zone Edit The Zone Edit screen allows you to add or edit a zone. To access this screen, go to the

Pagina 396

ZyWALL USG 2000 User’s Guide381CHAPTER 18 DDNS18.1 DDNS OverviewDynamic DNS (DDNS) services let you use a domain name with a dynamic IP address.18.1

Pagina 397 - CHAPTER 20

Chapter 18 DDNSZyWALL USG 2000 User’s Guide382Note: Record your DDNS account’s user name, password, and domain name to use to configure the ZyWALL.Aft

Pagina 398 - 20.1.2 What You Need to Know

Chapter 18 DDNSZyWALL USG 2000 User’s Guide383Primary Interface/IPThis field displays the interface to use for updating the IP address mapped to the

Pagina 399

Chapter 18 DDNSZyWALL USG 2000 User’s Guide38418.2.1 The Dynamic DNS Add/Edit ScreenThe DDNS Add/Edit screen allows you to add a domain name to the Z

Pagina 400

Chapter 18 DDNSZyWALL USG 2000 User’s Guide385Username Type the user name used when you registered your domain name. You can use up to 31 alphanumeri

Pagina 401 - CHAPTER 21

Chapter 18 DDNSZyWALL USG 2000 User’s Guide386IP Address The options available in this field vary by DDNS provider.Interface -The ZyWALL uses the IP a

Pagina 402 - 21.1.2 What You Need to Know

ZyWALL USG 2000 User’s Guide387CHAPTER 19 NAT19.1 NAT OverviewNAT (Network Address Translation - NAT, RFC 1631) is the translation of the IP address

Pagina 403

Chapter 19 NATZyWALL USG 2000 User’s Guide38819.1.2 What You Need to KnowNAT is also known as virtual server, port forwarding, or port translation.Fi

Pagina 404

Chapter 19 NATZyWALL USG 2000 User’s Guide389Remove To remove an entry, select it and click Remove. The ZyWALL confirms you want to remove it before

Pagina 405 - 21.2 The ALG Screen

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide391.3.2 Maximizing ThroughputThe ZyWALL has one internal bus for ports P1-P7 and another

Pagina 406 - Chapter 21 ALG

Chapter 19 NATZyWALL USG 2000 User’s Guide39019.2.1 The NAT Add/Edit ScreenThe NAT Add/Edit screen lets you create new NAT rules and edit existing on

Pagina 407 - 21.3 ALG Technical Reference

Chapter 19 NATZyWALL USG 2000 User’s Guide391Classification Select what kind of NAT this rule is to perform.Virtual Server - This makes computers on

Pagina 408

Chapter 19 NATZyWALL USG 2000 User’s Guide392Mapped IP Subnet/RangeThis field displays for Many 1:1 NAT. Select to which translated destination IP add

Pagina 409 - CHAPTER 22

Chapter 19 NATZyWALL USG 2000 User’s Guide39319.3 NAT Technical ReferenceHere is more detailed information about NAT on the ZyWALL.NAT LoopbackSuppo

Pagina 410 - 22.2 IP/MAC Binding Summary

Chapter 19 NATZyWALL USG 2000 User’s Guide394For example, a LAN user’s computer at IP address 192.168.1.89 queries a public DNS server to resolve the

Pagina 411 - 22.2.1 IP/MAC Binding Edit

Chapter 19 NATZyWALL USG 2000 User’s Guide395SMTP server replied directly to the LAN user without the traffic going through NAT, the source would not

Pagina 412 - 22.2.2 Static DHCP Edit

Chapter 19 NATZyWALL USG 2000 User’s Guide396

Pagina 413

ZyWALL USG 2000 User’s Guide397CHAPTER 20 HTTP Redirect20.1 OverviewHTTP redirect forwards the client’s HTTP request (except HTTP traffic destined

Pagina 414 - Chapter 22 IP/MAC Binding

Chapter 20 HTTP RedirectZyWALL USG 2000 User’s Guide39820.1.2 What You Need to KnowWeb Proxy ServerA proxy server helps client devices make indirect

Pagina 415 - CHAPTER 23

Chapter 20 HTTP RedirectZyWALL USG 2000 User’s Guide399• a application patrol rule to allow HTTP traffic between ge4 and ge2.• a policy route to forw

Pagina 416 - 23.1.2 What You Need to Know

About This User's GuideZyWALL USG 2000 User’s Guide4• Web Configurator Online HelpClick the help icon in any screen for help in configuring that

Pagina 417

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide401.4 Management OverviewYou can use the following ways to manage the ZyWALL.SYS Off The

Pagina 418

Chapter 20 HTTP RedirectZyWALL USG 2000 User’s Guide40020.2.1 The HTTP Redirect Edit ScreenClick Network > HTTP Redirect to open the HTTP Redirect

Pagina 419

ZyWALL USG 2000 User’s Guide401CHAPTER 21 ALG21.1 ALG OverviewApplication Layer Gateway (ALG) allows the following applications to operate properly

Pagina 420

Chapter 21 ALGZyWALL USG 2000 User’s Guide40221.1.2 What You Need to KnowApplication Layer Gateway (ALG), NAT and FirewallThe ZyWALL can function as

Pagina 421

Chapter 21 ALGZyWALL USG 2000 User’s Guide403• There should be only one SIP server (total) on the ZyWALL’s private networks. Any other SIP servers mu

Pagina 422

Chapter 21 ALGZyWALL USG 2000 User’s Guide404can receive incoming calls from the Internet, LAN IP addresses B and C can still make calls out to the In

Pagina 423 - CHAPTER 24

Chapter 21 ALGZyWALL USG 2000 User’s Guide405• See Section 21.3 on page 407 for ALG background/technical information.21.1.3 Before You BeginYou must

Pagina 424 - 24.1.2 What You Need to Know

Chapter 21 ALGZyWALL USG 2000 User’s Guide406The following table describes the labels in this screen. Table 101 Configuration > Network > AL

Pagina 425 - Firewall and VPN Traffic

Chapter 21 ALGZyWALL USG 2000 User’s Guide40721.3 ALG Technical ReferenceHere is more detailed information about the Application Layer Gateway.ALGSo

Pagina 426 - Session Limits

Chapter 21 ALGZyWALL USG 2000 User’s Guide408connections to the second (passive) interface when the active interface’s connection goes down. When the

Pagina 427 - 2 Any Any Any Any Any Allow

ZyWALL USG 2000 User’s Guide409CHAPTER 22 IP/MAC Binding22.1 IP/MAC Binding OverviewIP address to MAC address binding helps ensure that only the in

Pagina 428

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide41Web ConfiguratorThe Web Configurator allows easy ZyWALL setup and management using an I

Pagina 429

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide41022.1.2 What You Need to KnowDHCPIP/MAC address bindings are based on the ZyWALL’s dynamic and

Pagina 430

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide411The following table describes the labels in this screen. 22.2.1 IP/MAC Binding EditClick Co

Pagina 431 - 24.2 The Firewall Screen

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide412The following table describes the labels in this screen. 22.2.2 Static DHCP EditClick Config

Pagina 432

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide413screen. Use this screen to configure an interface’s IP to MAC address binding settings. Figur

Pagina 433 - Chapter 24 Firewall

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide414The following table describes the labels in this screen. Table 105 Configuration > Netwo

Pagina 434 - Chapter 24 Firewall

ZyWALL USG 2000 User’s Guide415CHAPTER 23 Authentication Policy23.1 Overview Use authentication policies to control who can access the network. You

Pagina 435

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide41623.1.2 What You Need to KnowAuthentication Policy and VPNAuthentication policies are a

Pagina 436

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide417Click Configuration > Auth. Policy to display the screen. Figure 310 Configuratio

Pagina 437

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide418The following table gives an overview of the objects you can configure. Table 106 Co

Pagina 438

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide41923.2.1 Creating/Editing an Authentication PolicyClick Configuration > Auth. Policy

Pagina 439

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide42Always use Maintenance > Shutdown > Shutdown or the shutdown command before you tu

Pagina 440

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide420Figure 312 Configuration > Auth. Policy > Add The following table gives an ove

Pagina 441 - CHAPTER 25

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide421Schedule Select a schedule that defines when the policy applies. Otherwise, select non

Pagina 442 - 25.1.2 What You Need to Know

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide422

Pagina 443 - Application Scenarios

ZyWALL USG 2000 User’s Guide423CHAPTER 24 Firewall24.1 OverviewUse the firewall to block or allow services that use static port numbers. Use applica

Pagina 444 - 25.1.3 Before You Begin

Chapter 24 FirewallZyWALL USG 2000 User’s Guide42424.1.2 What You Need to KnowStateful InspectionThe ZyWALL has a stateful inspection firewall. The Z

Pagina 445

Chapter 24 FirewallZyWALL USG 2000 User’s Guide425• The ZyWALL drops most packets from the DMZ zone to the ZyWALL itself, except for DNS and NetBIOS

Pagina 446

Chapter 24 FirewallZyWALL USG 2000 User’s Guide426traffic blocking to allow or block VPN traffic transmitting between the VPN tunnel and other interfa

Pagina 447 - Chapter 25 IPSec VPN

Chapter 24 FirewallZyWALL USG 2000 User’s Guide427the firewall rule to always be in effect. The following figure shows the results of this rule.Figur

Pagina 448 - Chapter 25 IPSec VPN

Chapter 24 FirewallZyWALL USG 2000 User’s Guide428Now you configure a LAN to WAN firewall rule that allows IRC traffic from the IP address of the CEO’

Pagina 449

Chapter 24 FirewallZyWALL USG 2000 User’s Guide429• The first row allows any LAN computer to access the IRC service on the WAN by logging into the Zy

Pagina 450

ZyWALL USG 2000 User’s Guide43CHAPTER 2 Features and ApplicationsThis chapter introduces the main features and applications of the ZyWALL.2.1 Featur

Pagina 451

Chapter 24 FirewallZyWALL USG 2000 User’s Guide4305 The screen for configuring a service object opens. Configure it as follows and click OK.Figure 318

Pagina 452

Chapter 24 FirewallZyWALL USG 2000 User’s Guide4319 The firewall rule appears in the firewall rule summary.Figure 320 Firewall Example: Doom Rule i

Pagina 453 - Manual Key

Chapter 24 FirewallZyWALL USG 2000 User’s Guide4324 The ZyWALL then sends it to the computer on the LAN in Subnet 1. Figure 321 Using Virtual Interf

Pagina 454 - Key (continued)

Chapter 24 FirewallZyWALL USG 2000 User’s Guide433• The ordering of your rules is very important as rules are applied in sequence.Figure 322 Config

Pagina 455

Chapter 24 FirewallZyWALL USG 2000 User’s Guide434From Zone / To ZoneThis is the direction of travel of packets. Select from which zone the packets co

Pagina 456 - 25.3 The VPN Gateway Screen

Chapter 24 FirewallZyWALL USG 2000 User’s Guide43524.2.2 The Firewall Add/Edit ScreenIn the Firewall screen, click the Edit or Add icon to display t

Pagina 457

Chapter 24 FirewallZyWALL USG 2000 User’s Guide43624.3 The Session Limit ScreenClick Configuration > Firewall > Session Limit to display the Fi

Pagina 458

Chapter 24 FirewallZyWALL USG 2000 User’s Guide437individual limits for specific users, addresses, or both. The individual limit takes priority if yo

Pagina 459

Chapter 24 FirewallZyWALL USG 2000 User’s Guide43824.3.1 The Session Limit Add/Edit ScreenClick Configuration > Firewall > Session Limit and th

Pagina 460

Chapter 24 FirewallZyWALL USG 2000 User’s Guide439User Select a user name or user group to which to apply the rule. The rule is activated only when t

Pagina 461

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide44FirewallThe ZyWALL’s firewall is a stateful inspection firewall. The ZyWALL restricts

Pagina 462

Chapter 24 FirewallZyWALL USG 2000 User’s Guide440

Pagina 463

ZyWALL USG 2000 User’s Guide441CHAPTER 25 IPSec VPN25.1 IPSec VPN OverviewA virtual private network (VPN) provides secure communications between sit

Pagina 464

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide442•Use the VPN Gateway screens (see Section 25.2.1 on page 446) to manage the ZyWALL’s VPN gateways.

Pagina 465 - 25.4 VPN Concentrator

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide443Application ScenariosThe ZyWALL’s application scenarios make it easier to configure your VPN conne

Pagina 466

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide444• See Section 25.5 on page 469 for IPSec VPN background information.• See Section 5.3 on page 83 fo

Pagina 467

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide445SA). Click a column’s heading cell to sort the table entries by that column’s criteria. Click the

Pagina 468

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide44625.2.1 The VPN Connection Add/Edit (IKE) ScreenThe VPN Connection Add/Edit Gateway screen allows y

Pagina 469 - Section 25.2.1 on page 446

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide447Figure 329 Configuration > VPN > IPSec VPN > VPN Connection > Edit (IKE)

Pagina 470 - IKE SA Overview

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide448Each field is described in the following table. Table 118 Configuration > VPN > IPSec VPN

Pagina 471 - Diffie-Hellman key exchange

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide449PolicyLocal Policy Select the address corresponding to the local network. Use Create new Object if

Pagina 472 - Authentication

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide45Anti-Virus ScannerWith the anti-virus packet scanner, your ZyWALL scans files transm

Pagina 473 - Additional Topics for IKE SA

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide450Encryption This field is applicable when the Active Protocol is ESP. Select which key size and encr

Pagina 474 - VPN, NAT, and NAT Traversal

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide451Check Method Select how the ZyWALL checks the connection. The peer must be configured to respond t

Pagina 475 - Certificates

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide452Inbound TrafficSource NAT This translation hides the source address of computers in the remote netw

Pagina 476 - IPSec SA Overview

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide45325.2.2 The VPN Connection Add/Edit Manual Key Screen The VPN Connection Add/Edit Manual Key scree

Pagina 477

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide454Secure Gateway AddressType the IP address of the remote IPSec router in the IPSec SA. SPI Type a un

Pagina 478 - IPSec SA using Manual Keys

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide455Encryption Key This field is applicable when you select an Encryption Algorithm. Enter the encrypt

Pagina 479

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide45625.3 The VPN Gateway ScreenThe VPN Gateway summary screen displays the IPSec VPN gateway policies

Pagina 480

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide45725.3.1 The VPN Gateway Add/Edit ScreenThe VPN Gateway Add/Edit screen allows you to create a new

Pagina 481 - CHAPTER 26

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide458Figure 332 Configuration > VPN > IPSec VPN > VPN Gateway > Edit

Pagina 482 - SSL Access Policy Objects

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide459Each field is described in the following table. Table 121 Configuration > VPN > IPSec VPN

Pagina 483

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide462.2.1 VPN ConnectivitySet up VPN tunnels with other companies, branch offices, telec

Pagina 484

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide460Pre-Shared KeySelect this to have the ZyWALL and remote IPSec router use a pre-shared key (password

Pagina 485 - Chapter 26 SSL VPN

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide461Content This field is read-only if the ZyWALL and remote IPSec router use certificates to identify

Pagina 486 - Chapter 26 SSL VPN

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide462Content This field is disabled if the Peer ID Type is Any. Type the identity of the remote IPSec ro

Pagina 487

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide463Negotiation ModeSelect the negotiation mode to use to negotiate the IKE SA. Choices areMain - this

Pagina 488

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide464NAT Traversal Select this if any of these conditions are satisfied.• This IKE SA might be used to n

Pagina 489

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide46525.4 VPN Concentrator A VPN concentrator combines several IPSec VPN connections into one secure n

Pagina 490

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide466• Branch office A’s ZyWALL uses one VPN rule to access both the headquarters (HQ) network and branc

Pagina 491 - Figure 349 Login Screen

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide467VPN Connection (VPN Tunnel 1): • Local Policy: 192.168.1.0/255.255.255.0• Remote Policy:192.168.11

Pagina 492

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide468• The local IP addresses configured in the VPN rules should not overlap.• The concentrator must hav

Pagina 493 - CHAPTER 27

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide469Concentrator summary screen (see Section 25.4 on page 465), and click either the Add icon or an Ed

Pagina 494 - 27.2 Remote User Login

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide47You do not have to install additional client software on the remote user computers f

Pagina 495 - Figure 354 Login Screen

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide470IKE SA OverviewThe IKE SA provides a secure connection between the ZyWALL and remote IPSec router.I

Pagina 496

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide471The ZyWALL sends one or more proposals to the remote IPSec router. (In some devices, you can only

Pagina 497

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide472the longer it takes to encrypt and decrypt information. For example, DH2 keys (1024 bits) are more

Pagina 498

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide473Router identity consists of ID type and content. The ID type can be domain name, IP address, or e-

Pagina 499 - # DESCRIPTION

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide474Negotiation ModeThere are two negotiation modes--main mode and aggressive mode. Main mode provides

Pagina 500 - 27.4 Bookmarking the ZyWALL

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide475feature, router X and router Y can establish a VPN tunnel as long as the active protocol is ESP. (

Pagina 501

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide476• The local and peer ID type and content come from the certificates.Note: You must set up the certi

Pagina 502 - Chapter 27 SSL User Screens

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide477These modes are illustrated below.In tunnel mode, the ZyWALL uses the active protocol to encapsula

Pagina 503 - CHAPTER 28

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide478Additional Topics for IPSec SAThis section provides more information about IPSec SA in your ZyWALL.

Pagina 504

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide479Each kind of translation is explained below. The following example is used to help explain each on

Pagina 505 - CHAPTER 29

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide482.2.3 User-Aware Access ControlSet up security policies that restrict access to sens

Pagina 506 - Figure 366 File Sharing

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide480• SNAT - the translated source address; a different IP address (range of addresses) to hide the ori

Pagina 507

ZyWALL USG 2000 User’s Guide481CHAPTER 26 SSL VPN26.1 OverviewUse SSL VPN to allow users to use a web browser for secure remote user login (the remo

Pagina 508 - 29.3.1 Downloading a File

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide482You do not have to install additional client software on the remote user computers for access. Figur

Pagina 509 - 29.4 Creating a New Folder

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide483changes through the SSL policies that use the object(s). When you delete an SSL policy, the objects

Pagina 510

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide48426.2 The SSL Access Privilege ScreenClick VPN > SSL VPN to open the Access Privilege screen. This

Pagina 511 - 29.7 Uploading a File

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide485Apply Click Apply to save the settings. Reset Click Reset to discard all changes. Table 127 VPN &g

Pagina 512

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide48626.2.1 The SSL Access Policy Add/Edit Screen To create a new or edit an existing SSL access policy,

Pagina 513 - CHAPTER 30

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide487The following table describes the labels in this screen. Table 128 VPN > SSL VPN > Access Pr

Pagina 514 - 30.2 Statistics

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide48826.3 The SSL Global Setting ScreenClick VPN > SSL VPN and click the Global Setting tab to display

Pagina 515 - 30.3 View Log

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide489on your network for full tunnel mode access, enter access messages or upload a custom logo to be dis

Pagina 516 - 30.5 Stop the Connection

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide492.2.5 Device HASet up an additional ZyWALL as a backup gateway to ensure the defaul

Pagina 517 - CHAPTER 31

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide49026.3.1 How to Upload a Custom LogoFollow the steps below to upload a custom logo to display on the r

Pagina 518 - Policy Route

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide491The following shows an example logo on the remote user screen. Figure 348 Example Logo Graphic Dis

Pagina 519 - 31.2 L2TP VPN Screen

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide4922 SSL VPN connection starts. This may take several minutes depending on your network connection. Once

Pagina 520 - Chapter 31 L2TP VPN

ZyWALL USG 2000 User’s Guide493CHAPTER 27 SSL User Screens27.1 OverviewThis chapter introduces the remote user SSL VPN screens. The following figure

Pagina 521 - CHAPTER 32

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide494System RequirementsHere are the browser and computer system requirements for remote user acc

Pagina 522

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide4951 Open a web browser and enter the web site address or IP address of the ZyWALL. For exampl

Pagina 523 - DiffServ and DSCP Marking

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide4965 Your computer starts establishing a secure connection to the ZyWALL after a successful log

Pagina 524

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide4977 The ZyWALL tries to install the SecuExtender client. You may need to click a pop-up to ge

Pagina 525 - Bandwidth Management Priority

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide49810 If a screen like the following displays, click Continue Anyway to finish installing the S

Pagina 526 - Priority Effect

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide49927.3 The SSL VPN User ScreensThis section describes the main elements in the remote user s

Pagina 527

About This User's GuideZyWALL USG 2000 User’s Guide5See http://www.zyxel.com/web/contact_us.php for contact information. Please have the follow

Pagina 528

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide50

Pagina 529

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide50027.4 Bookmarking the ZyWALLYou can create a bookmark of the ZyWALL by clicking the Add to F

Pagina 530

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide5013 An information screen displays to indicate that the SSL VPN connection is about to termin

Pagina 531

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide502

Pagina 532

ZyWALL USG 2000 User’s Guide503CHAPTER 28 SSL User Application Screens28.1 SSL User Application Screens OverviewUse the Application screen to access

Pagina 533

Chapter 28 SSL User Application ScreensZyWALL USG 2000 User’s Guide504

Pagina 534 - Table 139 Application Edit

ZyWALL USG 2000 User’s Guide505CHAPTER 29 SSL User File Sharing29.1 OverviewThe File Sharing screen lets you access files on a file server through t

Pagina 535

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide50629.2 The Main File Sharing Screen The first File Sharing screen displays the name(s) o

Pagina 536 - Chapter 32 Application Patrol

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide5073 If an access user name and password are required, a screen displays as shown in the

Pagina 537

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide5084 A list of files/folders displays. Click on a file to open it in a separate browser wi

Pagina 538

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide50929.3.2 Saving a FileAfter you have opened a file in a web browser, you can save a cop

Pagina 539

ZyWALL USG 2000 User’s Guide51CHAPTER 3 Web ConfiguratorThe ZyWALL Web Configurator allows easy ZyWALL setup and management using an Internet browser

Pagina 540

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide51029.5 Renaming a File or FolderTo rename a file or folder, click the Rename icon next t

Pagina 541

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide51129.7 Uploading a FileFollow the steps below to upload a file to the file server. 1 Lo

Pagina 542

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide512

Pagina 543

ZyWALL USG 2000 User’s Guide513CHAPTER 30 ZyWALL SecuExtenderThe ZyWALL automatically loads the ZyWALL SecuExtender client program to your computer a

Pagina 544

Chapter 30 ZyWALL SecuExtenderZyWALL USG 2000 User’s Guide51430.2 StatisticsRight-click the ZyWALL SecuExtender icon in the system tray and select St

Pagina 545

Chapter 30 ZyWALL SecuExtenderZyWALL USG 2000 User’s Guide51530.3 View LogIf you have problems with the ZyWALL SecuExtender, customer support may re

Pagina 546

Chapter 30 ZyWALL SecuExtenderZyWALL USG 2000 User’s Guide516connected but not send any traffic through it until you right-click the icon and resume t

Pagina 547 - CHAPTER 33

ZyWALL USG 2000 User’s Guide517CHAPTER 31 L2TP VPN31.1 OverviewL2TP VPN lets remote users use the L2TP and IPSec client software included with their

Pagina 548 - ZyWALL Anti-Virus Scanner

Chapter 31 L2TP VPNZyWALL USG 2000 User’s Guide518• Use transport mode.• Not be a manual key VPN connection. •Use Pre-Shared Key authentication.• Use

Pagina 549

Chapter 31 L2TP VPNZyWALL USG 2000 User’s Guide519Finding Out More• See Section 6.5.17 on page 111 for related information on these screens.• See Cha

Pagina 550 - 33.1.3 Before You Begin

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide522 Open your web browser, and go to http://192.168.1.1. By default, the ZyWALL automatically ro

Pagina 551 - Chapter 33 Anti-Virus

Chapter 31 L2TP VPNZyWALL USG 2000 User’s Guide520VPN Connection Select the IPSec VPN connection the ZyWALL uses for L2TP VPN. All of the configured V

Pagina 552 - Chapter 33 Anti-Virus

ZyWALL USG 2000 User’s Guide521CHAPTER 32 Application Patrol32.1 OverviewApplication patrol provides a convenient way to manage the use of various a

Pagina 553

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide52232.1.2 What You Need to KnowIf you want to use a service, make sure both the firewall an

Pagina 554

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide523numbers for SIP traffic. Likewise, configuring the SIP ALG to use custom port numbers for

Pagina 555 - 33.3 Anti-Virus Black List

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide524• The outbound traffic flows from the connection initiator to the connection responder. •

Pagina 556 - White List) > Add

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide525Bandwidth Management Priority• The ZyWALL gives bandwidth to higher-priority traffic firs

Pagina 557 - 33.5 Anti-Virus White List

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide526Configured Rate EffectIn the following table the configured rates total less than the avai

Pagina 558 - 33.6 Signature Searching

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide527regardless of its priority, server B gets almost no bandwidth with this configuration.

Pagina 559

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide528• FTP traffic from the LAN to the DMZ can use more bandwidth since the interfaces support

Pagina 560

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide529• Enable maximize bandwidth usage so the SIP traffic can borrow unused bandwidth.Figure 3

Pagina 561 - Types of Anti-Virus Scanner

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide535 The screen above appears every time you log in using the default user name and default pass

Pagina 562

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide53032.1.3.5 FTP WAN to DMZ Bandwidth Management Example• ADSL supports more downstream than

Pagina 563 - CHAPTER 34

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide53132.2 Application Patrol General ScreenUse this screen to enable and disable application

Pagina 564 - 34.1.3 Before You Begin

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide53232.3 Application Patrol ApplicationsUse the application patrol Common, Instant Messenger,

Pagina 565 - 34.2 The IDP General Screen

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide533Click Configuration > App Patrol > Common to open the following screen.Figure 391

Pagina 566 - Chapter 34 IDP

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide534Streaming screen and click an application’s Edit icon. The screen displayed here is for th

Pagina 567

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide535# This field is a sequential value, and it is not associated with a specific entry.Note:

Pagina 568 - 34.3.1 Base Profiles

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide536Access This field displays what the ZyWALL does with packets for this application that mat

Pagina 569

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide53732.3.2 The Application Patrol Policy Edit Screen The Application Policy Edit screen allo

Pagina 570 - 34.5 Creating New Profiles

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide538Schedule Select a schedule that defines when the policy applies or select Create Object to

Pagina 571 - Chapter 34 IDP

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide539Action Block For some applications, you can select individual uses of the application tha

Pagina 572

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide543.3.1 Title BarThe title bar provides some icons in the upper right corner.Figure 22 Title

Pagina 573

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide54032.4 The Other Applications ScreenSometimes, the ZyWALL cannot identify the application.

Pagina 574 - 34.6.2 Policy Types

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide541Click AppPatrol > Other to open the Other (applications) screen.Figure 394 AppPatrol

Pagina 575 - 34.6.3 IDP Service Groups

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide542Destination This is the destination address or address group for whom this policy applies.

Pagina 576

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide54332.4.1 The Other Applications Add/Edit ScreenThe Other Configuration Add/Edit screen all

Pagina 577

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide544Schedule Select a schedule that defines when the policy applies or select Create Object to

Pagina 578

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide545Inbound kbpsType how much inbound bandwidth, in kilobits per second, this policy allows t

Pagina 579 - 34.6.5 Query Example

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide546OK Click OK to save your changes back to the ZyWALL.Cancel Click Cancel to exit this scree

Pagina 580 - •Actions: Any

ZyWALL USG 2000 User’s Guide547CHAPTER 33 Anti-Virus33.1 OverviewUse the ZyWALL’s anti-virus feature to protect your connected network from virus/sp

Pagina 581 - 34.7.1 IP Packet Header

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide54833.1.2 What You Need to Know Anti-Virus EnginesSubscribe to signature files for ZyXEL’s anti-viru

Pagina 582

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide5492 If the packets are not session connection setup packets (such as SYN, ACK and FIN), the ZyWALL

Pagina 583

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide55hide the navigation panel menus or drag it to resize them. The following sections introduce t

Pagina 584

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide55033.1.3 Before You Begin• Before using anti-virus, see Chapter 11 on page 265 for how to register

Pagina 585

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide551The following table describes the labels in this screen.Table 143 Configuration > Anti-X >

Pagina 586

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide552Protocol These are the protocols of traffic to scan for viruses.FTP applies to traffic using the T

Pagina 587

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide55333.2.1 Anti-Virus Policy Add or Edit ScreenClick the Add or Edit icon in the Configuration >

Pagina 588

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide554Actions When MatchedDestroy infected fileWhen you select this check box, if a virus pattern is mat

Pagina 589

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide55533.3 Anti-Virus Black ListClick Configuration > Anti-X > Anti-Virus > Black/White List

Pagina 590

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide556The following table describes the labels in this screen.33.4 Anti-Virus Black List or White List

Pagina 591 - 34.8.2.2 Analyze Packets

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide557The following table describes the labels in this screen.33.5 Anti-Virus White ListClick Configur

Pagina 592

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide558column’s heading cell to sort the table entries by that column’s criteria. Click the heading cell

Pagina 593

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide559If Internet Explorer opens a warning screen about a script making Internet Explorer run slowly an

Pagina 594 - 34.9 IDP Technical Reference

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide563.3.2.3 Configuration MenuUse the configuration menu screens to configure the ZyWALL’s featur

Pagina 595 - Snort Signatures

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide560The following table describes the labels in this screen. Table 148 Configuration > Anti-X &g

Pagina 596

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide56133.7 Anti-Virus Technical ReferenceTypes of Computer Viruses The following table describes some

Pagina 597 - CHAPTER 35

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide562A host-based anti-virus (HAV) scanner is often software installed on computers and/or servers in t

Pagina 598 - 35.1.4 Before You Begin

ZyWALL USG 2000 User’s Guide563CHAPTER 34 IDP34.1 OverviewThis chapter introduces packet inspection IDP (Intrusion, Detection and Prevention), IDP

Pagina 599 - 35.2 The ADP General Screen

Chapter 34 IDPZyWALL USG 2000 User’s Guide564IDP ProfilesAn IDP profile is a set of related IDP signatures that you can activate as a set and configur

Pagina 600

Chapter 34 IDPZyWALL USG 2000 User’s Guide56534.2 The IDP General ScreenClick Configuration > Anti-X > IDP > General to open this screen. U

Pagina 601 - 35.3.1 Base Profiles

Chapter 34 IDPZyWALL USG 2000 User’s Guide566Remove Select an entry and click this to delete it. Activate To turn on an entry, select it and click Act

Pagina 602

Chapter 34 IDPZyWALL USG 2000 User’s Guide56734.3 Introducing IDP Profiles An IDP profile is a set of packet inspection signatures. Packet inspecti

Pagina 603 - Chapter 35 ADP

Chapter 34 IDPZyWALL USG 2000 User’s Guide56834.3.1 Base ProfilesThe ZyWALL comes with several base profiles. You use base profiles to create new pro

Pagina 604 - Chapter 35 ADP

Chapter 34 IDPZyWALL USG 2000 User’s Guide56934.4 The Profile Summary ScreenSelect Anti-X > IDP > Profile. Use this screen to:• Add a new prof

Pagina 605

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide57Interface Port Grouping Configure physical port groups.Ethernet Manage Ethernet interfaces an

Pagina 606

Chapter 34 IDPZyWALL USG 2000 User’s Guide57034.5 Creating New Profiles You may want to create a new profile if not all signatures in a base profile

Pagina 607

Chapter 34 IDPZyWALL USG 2000 User’s Guide57134.6 Profiles: Packet Inspection Select Configuration > Anti-X > IDP > Profile and then add a

Pagina 608

Chapter 34 IDPZyWALL USG 2000 User’s Guide572The following table describes the fields in this screen. Table 153 Configuration > Anti-X > IDP

Pagina 609 - 35.4 ADP Technical Reference

Chapter 34 IDPZyWALL USG 2000 User’s Guide573Action To edit what action the ZyWALL takes when a packet matches a signature, select the signature and

Pagina 610 - Filtered Port Scans

Chapter 34 IDPZyWALL USG 2000 User’s Guide57434.6.2 Policy TypesThis section describes IDP policy types, also known as attack types, as categorized i

Pagina 611 - TCP SYN Flood Attack

Chapter 34 IDPZyWALL USG 2000 User’s Guide57534.6.3 IDP Service GroupsAn IDP service group is a set of related packet inspection signatures.Scan A s

Pagina 612 - LAND Attack

Chapter 34 IDPZyWALL USG 2000 User’s Guide576The following figure shows the WEB_PHP service group that contains signatures related to attacks on web s

Pagina 613 - UDP Flood Attack

Chapter 34 IDPZyWALL USG 2000 User’s Guide577signatures by criteria such as name, ID, severity, attack type, vulnerable attack platforms, service cat

Pagina 614

Chapter 34 IDPZyWALL USG 2000 User’s Guide578Severity Search for signatures by severity level(s). Hold down the [Ctrl] key if you want to make multipl

Pagina 615

Chapter 34 IDPZyWALL USG 2000 User’s Guide57934.6.5 Query ExampleThis example shows a search with these criteria:• Severity: severe and high• Attack

Pagina 616

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide58L2TP VPN L2TP VPN Configure L2TP Over IPSec VPN settings.AppPatrol General Enable or disable t

Pagina 617 - CHAPTER 36

Chapter 34 IDPZyWALL USG 2000 User’s Guide580•Actions: AnyFigure 409 Query Example Search CriteriaFigure 410 Query Example Search Results

Pagina 618 - Keyword Blocking URL Checking

Chapter 34 IDPZyWALL USG 2000 User’s Guide58134.7 Introducing IDP Custom Signatures Create custom signatures for new attacks or attacks peculiar to

Pagina 619 - 36.1.3 Before You Begin

Chapter 34 IDPZyWALL USG 2000 User’s Guide58234.8 Configuring Custom SignaturesSelect Configuration > Anti-X > IDP > Custom Signatures. The

Pagina 620

Chapter 34 IDPZyWALL USG 2000 User’s Guide583Note: The ZyWALL checks all signatures and continues searching even after a match is found. If two or mo

Pagina 621 - Chapter 36 Content Filtering

Chapter 34 IDPZyWALL USG 2000 User’s Guide58434.8.1 Creating or Editing a Custom Signature Click the Add icon to create a new signature or click the

Pagina 622 - Chapter 36 Content Filtering

Chapter 34 IDPZyWALL USG 2000 User’s Guide585Try to write signatures that target a vulnerability, for example a certain type of traffic on certain op

Pagina 623

Chapter 34 IDPZyWALL USG 2000 User’s Guide586The following table describes the fields in this screen. Table 159 Configuration > Anti-X > IDP &

Pagina 624

Chapter 34 IDPZyWALL USG 2000 User’s Guide587Fragmentation A fragmentation flag identifies whether the IP datagram should be fragmented, not fragment

Pagina 625

Chapter 34 IDPZyWALL USG 2000 User’s Guide588Flow If selected, the signature only applies to certain directions of the traffic flow and only to client

Pagina 626

Chapter 34 IDPZyWALL USG 2000 User’s Guide589Payload Size This field may be used to check for abnormally sized packets or for detecting buffer overfl

Pagina 627

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide59User/Group User Create and manage users.Group Create and manage groups of users.Setting Manag

Pagina 628

Chapter 34 IDPZyWALL USG 2000 User’s Guide59034.8.2 Custom Signature ExampleBefore creating a custom signature, you must first clearly understand the

Pagina 629

Chapter 34 IDPZyWALL USG 2000 User’s Guide59134.8.2.2 Analyze PacketsUse the packet capture screen (see Section 53.3 on page 860) and a packet analy

Pagina 630

Chapter 34 IDPZyWALL USG 2000 User’s Guide592The final custom signature should look like as shown in the following figure. Figure 415 Example Custom

Pagina 631

Chapter 34 IDPZyWALL USG 2000 User’s Guide593You can activate the signature, configure what action to take when a packet matches it and if it should

Pagina 632

Chapter 34 IDPZyWALL USG 2000 User’s Guide594destination port is the service port (53 for DNS in this case) that the attack tries to exploit.Figure 41

Pagina 633

Chapter 34 IDPZyWALL USG 2000 User’s Guide595Network IntrusionsNetwork-based intrusions have the goal of bringing down a network or networks by attac

Pagina 634

Chapter 34 IDPZyWALL USG 2000 User’s Guide596Note: Not all Snort functionality is supported in the ZyWALL.Same IP sameipTransport ProtocolTransport Pr

Pagina 635

ZyWALL USG 2000 User’s Guide597CHAPTER 35 ADP35.1 OverviewThis chapter introduces ADP (Anomaly Detection and Prevention), anomaly profiles and appl

Pagina 636

Chapter 35 ADPZyWALL USG 2000 User’s Guide598Protocol AnomaliesProtocol anomalies are packets that do not comply with the relevant RFC (Request For Co

Pagina 637

Chapter 35 ADPZyWALL USG 2000 User’s Guide59935.2 The ADP General ScreenClick Configuration > Anti-X > ADP > General. Use this screen to tu

Pagina 638

Document ConventionsZyWALL USG 2000 User’s Guide6Document ConventionsWarnings and NotesThese are how warnings and notes are shown in this User’s Guide

Pagina 639

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide603.3.2.4 Maintenance MenuUse the maintenance menu screens to manage configuration and firmware

Pagina 640

Chapter 35 ADPZyWALL USG 2000 User’s Guide60035.3 The Profile Summary ScreenUse this screen to:• Create a new profile using an existing base profile•

Pagina 641 - CHAPTER 37

Chapter 35 ADPZyWALL USG 2000 User’s Guide60135.3.1 Base ProfilesThe ZyWALL comes with base profiles. You use base profiles to create new profiles.

Pagina 642

Chapter 35 ADPZyWALL USG 2000 User’s Guide602The following table describes the fields in this screen. 35.3.3 Creating New ADP Profiles You may want

Pagina 643

Chapter 35 ADPZyWALL USG 2000 User’s Guide603belonging to this profile, make sure you have clicked OK or Save to save the changes before selecting th

Pagina 644

Chapter 35 ADPZyWALL USG 2000 User’s Guide604The following table describes the fields in this screen. Table 164 Configuration > ADP > Profile

Pagina 645

Chapter 35 ADPZyWALL USG 2000 User’s Guide60535.3.5 Protocol Anomaly Profiles Protocol anomaly is the third screen in an ADP profile. Protocol anoma

Pagina 646

Chapter 35 ADPZyWALL USG 2000 User’s Guide606Figure 422 Profiles: Protocol Anomaly

Pagina 647

Chapter 35 ADPZyWALL USG 2000 User’s Guide607The following table describes the fields in this screen. Table 165 Configuration > ADP > Profil

Pagina 648

Chapter 35 ADPZyWALL USG 2000 User’s Guide608Action To edit what action the ZyWALL takes when a packet matches a signature, select the signature and u

Pagina 649 - CHAPTER 38

Chapter 35 ADPZyWALL USG 2000 User’s Guide60935.4 ADP Technical ReferenceThis section is divided into traffic anomaly background information and pro

Pagina 650 - E-mail Headers

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide613.3.3.1 Warning MessagesWarning messages, such as those resulting from misconfiguration, dis

Pagina 651 - 38.2 Before You Begin

Chapter 35 ADPZyWALL USG 2000 User’s Guide610Decoy Port ScansDecoy port scans are scans where the attacker has spoofed the source address. These are s

Pagina 652

Chapter 35 ADPZyWALL USG 2000 User’s Guide611Flood DetectionFlood attacks saturate a network with useless data, use up all available bandwidth, and t

Pagina 653

Chapter 35 ADPZyWALL USG 2000 User’s Guide612the initiator responds with an ACK (acknowledgment). After this handshake, a connection is established. F

Pagina 654

Chapter 35 ADPZyWALL USG 2000 User’s Guide613UDP Flood AttackUDP is a connection-less protocol and it does not require any connection setup procedure

Pagina 655

Chapter 35 ADPZyWALL USG 2000 User’s Guide614DOUBLE-ENCODING ATTACKThis rule is IIS specific. IIS does two passes through the request URI, doing decod

Pagina 656

Chapter 35 ADPZyWALL USG 2000 User’s Guide615WEBROOT-DIRECTORY-TRAVERSAL ATTACKThis is when a directory traversal traverses past the web server root

Pagina 657

Chapter 35 ADPZyWALL USG 2000 User’s Guide616TRUNCATED-HEADER ATTACKThis is when an ICMP packet is sent which has an ICMP datagram length of less than

Pagina 658

ZyWALL USG 2000 User’s Guide617CHAPTER 36 Content Filtering36.1 OverviewUse the content filtering feature to control access to specific web sites o

Pagina 659

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide618Content Filtering ProfilesA content filtering profile conveniently stores your custom setti

Pagina 660 - 38.6 The DNSBL Screen

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide619Since the ZyWALL checks the URL’s domain name (or IP address) and file path separately, it

Pagina 661 - Chapter 38 Anti-Spam

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide62settings reference the object. The following example shows which configuration settings refere

Pagina 662

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide620your list of content filter policies, create a denial of access message or specify a redire

Pagina 663

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide621Move To change an entry’s position in the numbered list, select it and click Move to displ

Pagina 664

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide62236.3 Content Filter Policy Add or Edit ScreenClick Configuration > Anti-X > Content

Pagina 665

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide623filter policy. A content filter policy defines which content filter profile should be appl

Pagina 666 - Chapter 38 Anti-Spam

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide62436.4 Content Filter Profile Screen Click Configuration > Anti-X > Content Filter >

Pagina 667 - CHAPTER 39

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide625See Chapter 37 on page 641 for how to view content filtering reports. Figure 429 Configu

Pagina 668 - 39.1.3 Before You Begin

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide626The following table describes the labels in this screen. Table 170 Configuration > Ant

Pagina 669 - 39.2 Device HA General

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide627Action for Unsafe Web PagesSelect Pass to allow users to access web pages that match the u

Pagina 670 - Cluster ID

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide628Action When Category Server Is UnavailableSelect Pass to allow users to access any requeste

Pagina 671

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide629Spyware/Malware Sources This category includes pages which distribute spyware and other ma

Pagina 672

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide633.3.3.4 CLI MessagesClick CLI to look at the CLI commands sent by the Web Configurator. Thes

Pagina 673 - Chapter 39 Device HA

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide630Nudity This category includes pages containing nude or seminude depictions of the human bod

Pagina 674 - Chapter 39 Device HA

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide631Arts/Entertainment This category includes pages that promote and provide information about

Pagina 675 - Monitored Interface

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide632Government/Legal This category includes pages sponsored by or which provide information on

Pagina 676

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide633Religion This category includes pages that promote and provide information on conventional

Pagina 677 - 39.5 The Legacy Mode Screen

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide634Sports/Recreation/HobbiesThis category includes pages that promote or provide information a

Pagina 678

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide635Alcohol Sites that promote, offer for sale, glorify, review, or in any way advocate the u

Pagina 679

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide63636.5.1 Content Filter Blocked and Warning MessagesThese are the content filtering warning

Pagina 680

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide63736.6 Content Filter Customization Screen Click Configuration > Anti-X > Content Fil

Pagina 681

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide638Allow Web traffic for trusted web sites onlyWhen this box is selected, the ZyWALL blocks We

Pagina 682

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide63936.7 Content Filter Technical ReferenceThis section provides content filtering background

Pagina 683

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide64• Sort in ascending alphabetical order• Sort in descending (reverse) alphabetical order• Selec

Pagina 684

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide640External Content Filter Server Lookup ProcedureThe content filter lookup process is describ

Pagina 685

ZyWALL USG 2000 User’s Guide641CHAPTER 37 Content Filter Reports37.1 OverviewYou can view content filtering reports after you have activated the cat

Pagina 686 - 192.168.10.112

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6422 Fill in your myZyXEL.com account information and click Login.Figure 433 myZyXEL.co

Pagina 687 - Synchronization

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6433 A welcome screen displays. Click your ZyWALL’s model name and/or MAC address under

Pagina 688

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6444 In the Service Management screen click Content Filter in the Service Name column to

Pagina 689 - CHAPTER 40

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6456 Select items under Global Reports to view the corresponding reports.Figure 437 Co

Pagina 690 - Ext-User Accounts

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6468 A chart and/or list of requested web site categories display in the lower half of th

Pagina 691 - User Awareness

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6479 You can click a category in the Categories report or click URLs in the Report Home

Pagina 692 - 40.2 User Summary Screen

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide648

Pagina 693 - • sync • uucp • zyxel

ZyWALL USG 2000 User’s Guide649CHAPTER 38 Anti-Spam38.1 OverviewThe anti-spam feature can mark or discard spam (unsolicited commercial or junk e-mai

Pagina 694 - Chapter 40 User/Group

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide654 Select a column heading and drag and drop it to change the column order. A green check mark

Pagina 695

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide650Black ListConfigure black list entries to identify spam. The black list entries have the ZyWALL cla

Pagina 696 - 40.3.1 Group Add/Edit Screen

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide651E-mail Header Buffer SizeThe ZyWALL has a 5 K buffer for an individual e-mail header. If an e-mail

Pagina 697 - 40.4 Setting Screen

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide652spam policies. You can also select the action the ZyWALL takes when the mail sessions threshold is

Pagina 698

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65338.3.1 The Anti-Spam Policy Add or Edit ScreenClick the Add or Edit icon in the Configuration >

Pagina 699 - Chapter 40 User/Group

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide654check, which e-mail protocols to scan, the scanning options, and the action to take on spam traffic

Pagina 700

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65538.4 The Anti-Spam Black List ScreenClick Configuration > Anti-X > Anti-Spam > Black /Wh

Pagina 701

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide656specific subject text. Click a column’s heading cell to sort the table entries by that column’s cri

Pagina 702

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65738.4.1 The Anti-Spam Black or White List Add/Edit ScreenIn the anti-spam Black List or White List

Pagina 703

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65838.4.2 Regular Expressions in Black or White List EntriesThe following applies for a black or whit

Pagina 704

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65938.5 The Anti-Spam White List ScreenClick Configuration > Anti-X > Anti-Spam > Black/Whi

Pagina 705 - CHAPTER 41

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide66Here are descriptions for the most common table icons.3.3.4.3 Working with ListsWhen a list o

Pagina 706

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide66038.6 The DNSBL Screen Click Configuration > Anti-X > Anti-Spam > DNSBL to display the ant

Pagina 707

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide661The following table describes the labels in this screen. Table 177 Configuration > Anti-X >

Pagina 708

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide66238.7 Anti-Spam Technical ReferenceHere is more detailed anti-spam information.DNSBL• The ZyWALL ch

Pagina 709

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide663Here is an example of an e-mail classified as spam based on DNSBL replies. Figure 446 DNSBL Spam

Pagina 710 - Chapter 41 Addresses

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide664Here is an example of an e-mail classified as legitimate based on DNSBL replies. Figure 447 DNSBL

Pagina 711 - CHAPTER 42

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide665If the ZyWALL receives conflicting DNSBL replies for an e-mail routing IP address, the ZyWALL clas

Pagina 712

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide666

Pagina 713

ZyWALL USG 2000 User’s Guide667CHAPTER 39 Device HA39.1 OverviewDevice HA lets a backup ZyWALL (B) automatically take over if the master ZyWALL (A)

Pagina 714

Chapter 39 Device HAZyWALL USG 2000 User’s Guide668• Legacy mode allows for more complex relationships between the master and backup ZyWALLs, such as

Pagina 715

Chapter 39 Device HAZyWALL USG 2000 User’s Guide66939.2 Device HA GeneralThe Configuration > Device HA General screen lets you enable or disable

Pagina 716

ZyWALL USG 2000 User’s Guide67CHAPTER 4 Installation Setup Wizard4.1 Installation Setup Wizard Screens If you log into the Web Configurator when the

Pagina 717 - CHAPTER 43

Chapter 39 Device HAZyWALL USG 2000 User’s Guide67039.3 The Active-Passive Mode Screen Virtual RouterThe master and backup ZyWALL form a single ‘virt

Pagina 718

Chapter 39 Device HAZyWALL USG 2000 User’s Guide671B form a virtual router that uses cluster ID 1. ZyWALLs C and D form a virtual router that uses cl

Pagina 719

Chapter 39 Device HAZyWALL USG 2000 User’s Guide672192.168.1.5 and ZyWALL B has its own LAN management IP address of 192.168.1.6. These do not change

Pagina 720 - Chapter 43 Schedules

Chapter 39 Device HAZyWALL USG 2000 User’s Guide673The following table describes the labels in this screen. See Section 39.4 on page 675 for more inf

Pagina 721

Chapter 39 Device HAZyWALL USG 2000 User’s Guide674Monitored Interface SummaryThis table shows the status of the device HA settings and status of the

Pagina 722

Chapter 39 Device HAZyWALL USG 2000 User’s Guide67539.4 Configuring an Active-Passive Mode Monitored InterfaceThe Device HA Active-Passive Mode Moni

Pagina 723 - CHAPTER 44

Chapter 39 Device HAZyWALL USG 2000 User’s Guide676A bridge interface’s device HA settings are not retained if you delete the bridge interface.Figure

Pagina 724 - 44.1.3 ASAS

Chapter 39 Device HAZyWALL USG 2000 User’s Guide67739.5 The Legacy Mode ScreenVirtual Router Redundancy Protocol (VRRP)Legacy mode device HA uses Vi

Pagina 725 - 44.1.5 What You Need To Know

Chapter 39 Device HAZyWALL USG 2000 User’s Guide67839.6 Configuring the Legacy Mode ScreenThe Device HA Legacy Mode screen lets you configure general

Pagina 726 - Bind DN

Chapter 39 Device HAZyWALL USG 2000 User’s Guide679Remove Select an entry and click this to delete it. Activate To turn on an entry, select it and cl

Pagina 727

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide684.1.1 Internet Access Setup - WAN Interface Use this screen to set how many WAN int

Pagina 728

Chapter 39 Device HAZyWALL USG 2000 User’s Guide680Use the VRRP Group Add/Edit screen to add or edit VRRP groups.• You can only use interfaces that ha

Pagina 729 - 44.3 RADIUS Server Summary

Chapter 39 Device HAZyWALL USG 2000 User’s Guide681The following table describes the labels in this screen. Table 182 Configuration > Device H

Pagina 730

Chapter 39 Device HAZyWALL USG 2000 User’s Guide68239.7 Device HA Technical ReferenceActive-Passive Mode Device HA with Bridge InterfacesHere are two

Pagina 731

Chapter 39 Device HAZyWALL USG 2000 User’s Guide6831 Make sure the bridge interfaces of the master ZyWALL (A) and the backup ZyWALL (B) are not conne

Pagina 732 - Chapter 44 AAA Server

Chapter 39 Device HAZyWALL USG 2000 User’s Guide6844 Connect the ZyWALLs.Second Option for Connecting the Bridge Interfaces on Two ZyWALLsAnother opti

Pagina 733 - CHAPTER 45

Chapter 39 Device HAZyWALL USG 2000 User’s Guide6852 Configure a corresponding disabled bridge interface on the backup ZyWALL. Then set the bridge in

Pagina 734

Chapter 39 Device HAZyWALL USG 2000 User’s Guide686Legacy Mode ZyWALL VRRP ApplicationIn VRRP, a virtual router represents a number of ZyWALLs associa

Pagina 735

Chapter 39 Device HAZyWALL USG 2000 User’s Guide687If ZyWALL A becomes available again, ZyWALL A preempts ZyWALL B and becomes the master again (the

Pagina 736

Chapter 39 Device HAZyWALL USG 2000 User’s Guide688

Pagina 737

ZyWALL USG 2000 User’s Guide689CHAPTER 40 User/Group40.1 OverviewThis chapter describes how to set up user accounts, user groups, and user settings

Pagina 738

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide69Note: Enter the Internet access information exactly as given to you by your ISP.Figu

Pagina 739 - CHAPTER 46

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide690Note: The default admin account is always authenticated locally, regardless of the authentication

Pagina 740 - Self-signed Certificates

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide691See Setting up User Attributes in an External Server on page 703 for a list of attributes and how

Pagina 741 - Certificate File Formats

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide69240.2 User Summary ScreenThe User screen provides a summary of all user accounts. To access this s

Pagina 742

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide693•- [dashes]The first character must be alphabetical (A-Z a-z), an underscore (_), or a dash (-).

Pagina 743

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide694The following table describes the labels in this screen. Table 185 Configuration > User/Grou

Pagina 744 - Chapter 46 Certificates

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide69540.3 User Group Summary ScreenUser groups consist of access users and other user groups. You can

Pagina 745 - Chapter 46 Certificates

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide69640.3.1 Group Add/Edit ScreenThe Group Add/Edit screen allows you to create a new user group or ed

Pagina 746 - characters

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide69740.4 Setting Screen The Setting screen controls default settings, login settings, lockout settin

Pagina 747

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide698To access this screen, login to the Web Configurator, and click Configuration > Object > Use

Pagina 748

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide699User Type These are the kinds of user account the ZyWALL supports.• admin - this user can look at

Pagina 749

Document ConventionsZyWALL USG 2000 User’s Guide7Icons Used in FiguresFigures in this User’s Guide may use the following generic icons. The ZyWALL ic

Pagina 750

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide704.1.3 Internet Access: PPPoENote: Enter the Internet access information exactly as g

Pagina 751

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide70040.4.1 Default User Authentication Timeout Settings Edit ScreensThe Default Authentication Timeou

Pagina 752

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide701To access this screen, go to the Configuration > Object > User/Group > Setting screen (s

Pagina 753

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide70240.4.2 User Aware Login ExampleAccess users cannot use the Web Configurator to browse the configu

Pagina 754

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide70340.5 User /Group Technical ReferenceThis section provides some information on users who use an e

Pagina 755

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide704

Pagina 756

ZyWALL USG 2000 User’s Guide705CHAPTER 41 Addresses41.1 OverviewAddress objects can represent a single IP address or a range of IP addresses. Addre

Pagina 757

Chapter 41 AddressesZyWALL USG 2000 User’s Guide706• RANGE - a range address is defined by a Starting IP Address and an Ending IP Address.• SUBNET - a

Pagina 758

Chapter 41 AddressesZyWALL USG 2000 User’s Guide70741.2.1 Address Add/Edit ScreenThe Configuration > Address Add/Edit screen allows you to create

Pagina 759

Chapter 41 AddressesZyWALL USG 2000 User’s Guide70841.3 Address Group Summary ScreenThe Address Group screen provides a summary of all address groups

Pagina 760

Chapter 41 AddressesZyWALL USG 2000 User’s Guide70941.3.1 Address Group Add/Edit ScreenThe Address Group Add/Edit screen allows you to create a new

Pagina 761 - CHAPTER 47

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide714.1.3.2 WAN IP Address Assignments • WAN Interface: This is the name of the interfa

Pagina 762 - 47.2.1 ISP Account Edit

Chapter 41 AddressesZyWALL USG 2000 User’s Guide710

Pagina 763 - Chapter 47 ISP Accounts

ZyWALL USG 2000 User’s Guide711CHAPTER 42 Services42.1 OverviewUse service objects to define TCP applications, UDP applications, and ICMP messages.

Pagina 764 - Chapter 47 ISP Accounts

Chapter 42 ServicesZyWALL USG 2000 User’s Guide712Both TCP and UDP use ports to identify the source and destination. Each port is a 16-bit number. Som

Pagina 765 - CHAPTER 48

Chapter 42 ServicesZyWALL USG 2000 User’s Guide713entries by that column’s criteria. Click the heading cell again to reverse the sort order.Figure 47

Pagina 766 - Weblinks

Chapter 42 ServicesZyWALL USG 2000 User’s Guide71442.2.1 The Service Add/Edit ScreenThe Service Add/Edit screen allows you to create a new service or

Pagina 767

Chapter 42 ServicesZyWALL USG 2000 User’s Guide715To access this screen, log in to the Web Configurator, and click Configuration > Object > Ser

Pagina 768

Chapter 42 ServicesZyWALL USG 2000 User’s Guide71642.3.1 The Service Group Add/Edit ScreenThe Service Group Add/Edit screen allows you to create a ne

Pagina 769 - Chapter 48 SSL Application

ZyWALL USG 2000 User’s Guide717CHAPTER 43 Schedules43.1 OverviewUse schedules to set up one-time and recurring schedules for policy routes, firewall

Pagina 770

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide718Finding Out More• See Section 6.6 on page 114 for related information on these screens.• See Sectio

Pagina 771

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide71943.2.1 The One-Time Schedule Add/Edit ScreenThe One-Time Schedule Add/Edit screen allows you to d

Pagina 772 - Chapter 48 SSL Application

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide72• CHAP/PAP - Your ZyWALL accepts either CHAP or PAP when requested by the remote node

Pagina 773 - CHAPTER 49

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide72043.2.2 The Recurring Schedule Add/Edit ScreenThe Recurring Schedule Add/Edit screen allows you to

Pagina 774 - Requirements

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide721(see Section 43.2 on page 718), and click either the Add icon or an Edit icon in the Recurring sec

Pagina 775

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide722

Pagina 776 - Chapter 49 Endpoint Security

ZyWALL USG 2000 User’s Guide723CHAPTER 44 AAA Server44.1 Overview You can use a AAA (Authentication, Authorization, Accounting) server to provide a

Pagina 777 - Chapter 49 Endpoint Security

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide72444.1.2 RADIUS Server RADIUS (Remote Authentication Dial-In User Service) authentication is a popu

Pagina 778

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide725•Use the Configuration > Object > AAA Server > RADIUS screen (Section 44.3 on page 729)

Pagina 779

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide726organizational boundaries. The following figure shows a basic directory structure branching from c

Pagina 780

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide727• See Section 7.7 on page 142 for an example of how to use a RADIUS server to authenticate user a

Pagina 781

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide728following screen. Use this screen to create a new AD or LDAP entry or edit an existing one. Figure

Pagina 782

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide72944.3 RADIUS Server SummaryUse the RADIUS screen to manage the list of RADIUS servers the ZyWALL

Pagina 783 - CHAPTER 50

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide734.1.6 Internet Access Setup - Second WAN InterfaceIf you selected I have two ISPs,

Pagina 784 - 50.2 Host Name

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide730Click Configuration > Object > AAA Server > RADIUS to display the RADIUS screen. Figure 4

Pagina 785 - 50.3 Date and Time

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide73144.3.1 Adding a RADIUS Server Click Configuration > Object > AAA Server > RADIUS to dis

Pagina 786 - Chapter 50 System

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide732Timeout Specify the timeout period (between 1 and 300 seconds) before the ZyWALL disconnects from

Pagina 787

ZyWALL USG 2000 User’s Guide733CHAPTER 45 Authentication Method45.1 Overview Authentication method objects set how the ZyWALL authenticates HTTP/HTT

Pagina 788

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide7343 Select Server Mode and select an authentication method object from the drop-down list

Pagina 789 - 50.5 DNS Overview

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide73545.2.1 Creating an Authentication Method Object Follow the steps below to create an a

Pagina 790

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide7367 Click OK to save the settings or click Cancel to discard all changes and return to th

Pagina 791 - Chapter 50 System

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide737Add icon Click Add to add a new entry. Click Edit to edit the settings of an entry. Cl

Pagina 792

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide738

Pagina 793 - 50.5.4 PTR Record

ZyWALL USG 2000 User’s Guide739CHAPTER 46 Certificates46.1 OverviewThe ZyWALL can use certificates (also called digital IDs) to authenticate users.

Pagina 794

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide74Note: If you have not already done so, you can register your ZyWALL with myZyXEL.com

Pagina 795 - 50.5.8 MX Record

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide7402 Tim keeps the private key and makes the public key openly available. This means that anyone wh

Pagina 796 - 50.5.9 Adding a MX Record

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide741Factory Default CertificateThe ZyWALL generates its own unique self-signed certificate when you

Pagina 797 - 50.6 WWW Overview

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide7422 Make sure that the certificate has a “.cer” or “.crt” file name extension.Figure 490 Remote

Pagina 798 - 50.6.3 HTTPS

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide74346.2 The My Certificates Screen Click Configuration > Object > Certificate > My Certi

Pagina 799

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide74446.2.1 The My Certificates Add ScreenClick Configuration > Object > Certificate > My C

Pagina 800

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide745ZyWALL create a self-signed certificate, enroll a certificate with a certification authority or

Pagina 801

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide746The following table describes the labels in this screen. Table 210 Configuration > Object &

Pagina 802

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide747Create a certification request and save it locally for later manual enrollmentSelect this to ha

Pagina 803 - 50.6.5 Service Control Rules

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide748If you configured the My Certificate Create screen to have the ZyWALL enroll a certificate and t

Pagina 804

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide74946.2.2 The My Certificates Edit ScreenClick Configuration > Object > Certificate > My

Pagina 805

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide75• Select existing myZyXEL.com account if you already have an account at myZyXEL.com

Pagina 806

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide750The following table describes the labels in this screen. Table 211 Configuration > Object

Pagina 807 - 50.6.7 HTTPS Example

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide751Key Algorithm This field displays the type of algorithm that was used to generate the certifica

Pagina 808

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide75246.2.3 The My Certificates Import Screen Click Configuration > Object > Certificate >

Pagina 809 - 50.6.7.4 Login Screen

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide75346.3 The Trusted Certificates Screen Click Configuration > Object > Certificate > T

Pagina 810

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide75446.3.1 The Trusted Certificates Edit Screen Click Configuration > Object > Certificate &g

Pagina 811

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide755authority’s list of revoked certificates before trusting a certificate issued by the certificat

Pagina 812

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide756The following table describes the labels in this screen. Table 214 Configuration > Object

Pagina 813

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide757Type This field displays general information about the certificate. CA-signed means that a Cert

Pagina 814 - 50.7 SSH

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide75846.3.2 The Trusted Certificates Import Screen Click Configuration > Object > Certificate

Pagina 815 - 50.7.1 How SSH Works

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide759The following table describes the labels in this screen. 46.4 Certificates Technical Reference

Pagina 816 - 50.7.4 Configuring SSH

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide76

Pagina 817

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide760

Pagina 818

ZyWALL USG 2000 User’s Guide761CHAPTER 47 ISP Accounts47.1 OverviewUse ISP accounts to manage Internet Service Provider (ISP) account information fo

Pagina 819 - 50.8 Telnet

Chapter 47 ISP AccountsZyWALL USG 2000 User’s Guide762The following table describes the labels in this screen. See the ISP Account Edit section below

Pagina 820 - 50.8.1 Configuring Telnet

Chapter 47 ISP AccountsZyWALL USG 2000 User’s Guide763The following table describes the labels in this screen. Table 217 Configuration > Object

Pagina 821 - 50.9 FTP

Chapter 47 ISP AccountsZyWALL USG 2000 User’s Guide764Compression Select On button to turn on stac compression, and select Off to turn off stac compre

Pagina 822

ZyWALL USG 2000 User’s Guide765CHAPTER 48 SSL Application48.1 OverviewYou use SSL application objects in SSL VPN. Configure an SSL application objec

Pagina 823 - 50.10 SNMP

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide766Remote Desktop ConnectionsUse SSL VPN to allow remote users to manage LAN computers. Dependin

Pagina 824

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide7672 Click the Add button and select Web Application in the Type field. In the Server Type fiel

Pagina 825 - 50.10.3 Configuring SNMP

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide768The following table describes the labels in this screen. 48.2.1 Creating/Editing a Web-base

Pagina 826

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide769The following table describes the labels in this screen. Table 219 Configuration > Obj

Pagina 827 - 50.11 Dial-in Management

ZyWALL USG 2000 User’s Guide77CHAPTER 5 Quick Setup5.1 Quick Setup OverviewThe Web Configurator's quick setup wizards help you configure Intern

Pagina 828 - Response Strings

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide77048.2.2 Creating/Editing a File Sharing SSL Application ObjectYou can specify the name of a f

Pagina 829 - 50.12 Vantage CNM

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide771The following table describes the labels in this screen. Table 220 Configuration > Obj

Pagina 830

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide772

Pagina 831 - Note: HTTPS is recommended

ZyWALL USG 2000 User’s Guide773CHAPTER 49 Endpoint Security49.1 Overview Use Endpoint Security (EPS), also known as endpoint control, to make sure u

Pagina 832 - 50.13 Language Screen

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide77449.1.1 What You Can Do in this ChapterUse the Configuration > Object > Endpoint Secu

Pagina 833 - CHAPTER 51

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide77549.2 Endpoint Security ScreenThe Endpoint Security screen displays the endpoint security

Pagina 834 - Chapter 51 Log and Report

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide776Apply Click this button to save your changes to the ZyWALL. Reset Click this button to retu

Pagina 835 - 51.3 Log Setting Screens

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide77749.3 Endpoint Security Add/EditClick Configuration > Object > Endpoint Security and

Pagina 836 - 51.3.1 Log Setting Summary

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide778Figure 508 Configuration > Object > Endpoint Security > Add

Pagina 837

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide779The following table gives an overview of the objects you can configure. Table 222 Confi

Pagina 838

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide785.2 WAN Interface Quick SetupClick WAN Interface in the main Quick Setup screen to open the WAN In

Pagina 839 - Chapter 51 Log and Report

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide780Checking Item - Personal FirewallIf you selected Windows as the operating system, you can s

Pagina 840

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide781Checking Item - File InformationIf you selected Windows or Linux as the operating system,

Pagina 841

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide782

Pagina 842

ZyWALL USG 2000 User’s Guide783CHAPTER 50 System50.1 OverviewUse the system screens to configure general ZyWALL settings. 50.1.1 What You Can Do

Pagina 843

Chapter 50 SystemZyWALL USG 2000 User’s Guide784• Connect an external serial modem to the AUX port to provide a management connection in case the ZyWA

Pagina 844

Chapter 50 SystemZyWALL USG 2000 User’s Guide78550.3 Date and Time For effective scheduling and logging, the ZyWALL system time must be accurate. Th

Pagina 845

Chapter 50 SystemZyWALL USG 2000 User’s Guide786Manual Select this radio button to enter the time and date manually. If you configure a new time and d

Pagina 846

Chapter 50 SystemZyWALL USG 2000 User’s Guide78750.3.1 Pre-defined NTP Time Servers ListWhen you turn on the ZyWALL for the first time, the date and

Pagina 847 - CHAPTER 52

Chapter 50 SystemZyWALL USG 2000 User’s Guide78850.3.2 Time Server SynchronizationClick the Synchronize Now button to get the time and date from the

Pagina 848

Chapter 50 SystemZyWALL USG 2000 User’s Guide7895 Under Time and Date Setup, enter a Time Server Address (Table 225 on page 787).6 Click Apply.50.4

Pagina 849

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide79Otherwise, choose PPPoE or PPTP for a dial-up connection according to the information from your IS

Pagina 850

Chapter 50 SystemZyWALL USG 2000 User’s Guide79050.5.1 DNS Server Address AssignmentThe ZyWALL can get the DNS server addresses in the following ways

Pagina 851 - Chapter 52 File Manager

Chapter 50 SystemZyWALL USG 2000 User’s Guide791The following table describes the labels in this screen. Table 227 Configuration > System >

Pagina 852 - Chapter 52 File Manager

Chapter 50 SystemZyWALL USG 2000 User’s Guide792DNS Server This is the IP address of a DNS server. This field displays N/A if you have the ZyWALL get

Pagina 853

Chapter 50 SystemZyWALL USG 2000 User’s Guide79350.5.3 Address Record An address record contains the mapping of a Fully-Qualified Domain Name (FQDN)

Pagina 854

Chapter 50 SystemZyWALL USG 2000 User’s Guide794The following table describes the labels in this screen. 50.5.6 Domain Zone Forwarder A domain zone

Pagina 855

Chapter 50 SystemZyWALL USG 2000 User’s Guide795The following table describes the labels in this screen. 50.5.8 MX Record A MX (Mail eXchange) recor

Pagina 856

Chapter 50 SystemZyWALL USG 2000 User’s Guide79650.5.9 Adding a MX Record Click the Add icon in the MX Record table to add a MX record.Figure 516 C

Pagina 857

Chapter 50 SystemZyWALL USG 2000 User’s Guide797The following table describes the labels in this screen. 50.6 WWW OverviewThe following figure show

Pagina 858

Chapter 50 SystemZyWALL USG 2000 User’s Guide798• See To-ZyWALL Rules on page 424 for more on To-ZyWALL firewall rules.• See Section 7.9 on page 147 f

Pagina 859 - CHAPTER 53

Chapter 50 SystemZyWALL USG 2000 User’s Guide799It relies upon certificates, public keys, and private keys (see Chapter 46 on page 739 for more infor

Pagina 860

Safety WarningsZyWALL USG 2000 User’s Guide8Safety Warnings• Do NOT use this product near water, for example, in a wet basement or near a swimming poo

Pagina 861 - Chapter 53 Diagnostics

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide80• IP Address Assignment: Select Auto If your ISP did not assign you a fixed IP address. Select Stat

Pagina 862

Chapter 50 SystemZyWALL USG 2000 User’s Guide800Note: Admin Service Control deals with management access (to the Web Configurator). User Service Contr

Pagina 863

Chapter 50 SystemZyWALL USG 2000 User’s Guide801Server Port The HTTPS server listens on port 443 by default. If you change the HTTPS server port to a

Pagina 864 - Chapter 53 Diagnostics

Chapter 50 SystemZyWALL USG 2000 User’s Guide802HTTPEnable Select the check box to allow or disallow the computer with the IP address that matches the

Pagina 865 - CHAPTER 54

Chapter 50 SystemZyWALL USG 2000 User’s Guide80350.6.5 Service Control RulesClick Add or Edit in the Service Control table in a WWW, SSH, Telnet, FT

Pagina 866 - Chapter 54 Reboot

Chapter 50 SystemZyWALL USG 2000 User’s Guide804also customize the page that displays after an access user logs into the Web Configurator to access ne

Pagina 867 - CHAPTER 55

Chapter 50 SystemZyWALL USG 2000 User’s Guide805The following figures identify the parts you can customize in the login and access pages.Figure 523

Pagina 868 - Chapter 55 Shutdown

Chapter 50 SystemZyWALL USG 2000 User’s Guide806•Click Color to display a screen of web-safe colors from which to choose.• Enter the name of the desir

Pagina 869 - CHAPTER 56

Chapter 50 SystemZyWALL USG 2000 User’s Guide80750.6.7 HTTPS ExampleIf you haven’t changed the default HTTPS port on the ZyWALL, then in your browse

Pagina 870 - I cannot access the Internet

Chapter 50 SystemZyWALL USG 2000 User’s Guide80850.6.7.2 Netscape Navigator Warning MessagesWhen you attempt to access the ZyWALL HTTPS server, a Web

Pagina 871

Chapter 50 SystemZyWALL USG 2000 User’s Guide809• The issuing certificate authority of the ZyWALL’s HTTPS server certificate is not one of the browse

Pagina 872

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide81Authentication TypeUse the drop-down list box to select an authentication protocol for outgoing ca

Pagina 873

Chapter 50 SystemZyWALL USG 2000 User’s Guide810Apply for a certificate from a Certification Authority (CA) that is trusted by the ZyWALL (see the ZyW

Pagina 874

Chapter 50 SystemZyWALL USG 2000 User’s Guide81150.6.7.5.2 Installing Your Personal Certificate(s)You need a password in advance. The CA may issue t

Pagina 875

Chapter 50 SystemZyWALL USG 2000 User’s Guide8123 Enter the password given to you by the CA.Figure 533 Personal Certificate Import Wizard 34 Have th

Pagina 876

Chapter 50 SystemZyWALL USG 2000 User’s Guide8135 Click Finish to complete the wizard and begin the import process.Figure 535 Personal Certificate

Pagina 877

Chapter 50 SystemZyWALL USG 2000 User’s Guide8142 When Authenticate Client Certificates is selected on the ZyWALL, the following screen asks you to se

Pagina 878

Chapter 50 SystemZyWALL USG 2000 User’s Guide815SSH is a secure communication protocol that combines authentication and data encryption to provide se

Pagina 879

Chapter 50 SystemZyWALL USG 2000 User’s Guide8162 Encryption MethodOnce the identification is verified, both the client and server must agree on the t

Pagina 880

Chapter 50 SystemZyWALL USG 2000 User’s Guide817Note: It is recommended that you disable Telnet and FTP when you configure SSH for secure connections

Pagina 881

Chapter 50 SystemZyWALL USG 2000 User’s Guide81850.7.5 Secure Telnet Using SSH ExamplesThis section shows two examples using a command interface and

Pagina 882

Chapter 50 SystemZyWALL USG 2000 User’s Guide819Enter the password to log in to the ZyWALL. The CLI screen displays next. 50.7.5.2 Example 2: LinuxT

Pagina 883

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide825.2.5 Quick Setup Interface Wizard: SummaryThis screen displays the WAN interface’s settings.Figur

Pagina 884

Chapter 50 SystemZyWALL USG 2000 User’s Guide82050.8.1 Configuring TelnetClick Configuration > System > TELNET to configure your ZyWALL for rem

Pagina 885

Chapter 50 SystemZyWALL USG 2000 User’s Guide82150.9 FTP You can upload and download the ZyWALL’s firmware and configuration files using FTP. To use

Pagina 886 - 56.1 Resetting the ZyWALL

Chapter 50 SystemZyWALL USG 2000 User’s Guide822be used to access the ZyWALL. You can also specify from which IP addresses the access can come.Figure

Pagina 887 - 56.2 Changing a Power Module

Chapter 50 SystemZyWALL USG 2000 User’s Guide82350.10 SNMP Simple Network Management Protocol is a protocol used for exchanging management informati

Pagina 888 - Chapter 56 Troubleshooting

Chapter 50 SystemZyWALL USG 2000 User’s Guide824and version two (SNMPv2c). The next figure illustrates an SNMP management operation. Figure 548 SN

Pagina 889

Chapter 50 SystemZyWALL USG 2000 User’s Guide825• GetNext - Allows the manager to retrieve the next object variable from a table or list within an ag

Pagina 890

Chapter 50 SystemZyWALL USG 2000 User’s Guide826settings, including from which zones SNMP can be used to access the ZyWALL. You can also specify from

Pagina 891 - CHAPTER 57

Chapter 50 SystemZyWALL USG 2000 User’s Guide82750.11 Dial-in ManagementConnect an external serial modem to the AUX port to provide a management con

Pagina 892

Chapter 50 SystemZyWALL USG 2000 User’s Guide828Hang Up check box is selected, the ZyWALL uses this hardware signal to force the WAN device to hang up

Pagina 893

Chapter 50 SystemZyWALL USG 2000 User’s Guide82950.12 Vantage CNM Vantage CNM (Centralized Network Management) is a browser-based global management

Pagina 894

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide835.3 VPN Quick SetupClick VPN Setup in the main Quick Setup screen to open the VPN Setup Wizard We

Pagina 895

Chapter 50 SystemZyWALL USG 2000 User’s Guide83050.12.1 Configuring Vantage CNM Vantage CNM is disabled on the device by default. Click Configuration

Pagina 896

Chapter 50 SystemZyWALL USG 2000 User’s Guide831Transfer ProtocolSelect whether the Vantage CNM sessions should use regular HTTP connections or secur

Pagina 897 - FEATURE STANDARDS REFERENCED

Chapter 50 SystemZyWALL USG 2000 User’s Guide83250.13 Language Screen Click Configuration > System > Language to open the following screen. Use

Pagina 898

ZyWALL USG 2000 User’s Guide833CHAPTER 51 Log and Report51.1 OverviewUse these screens to configure daily reporting and log settings. 51.1.1 What

Pagina 899 - APPENDIX A

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide834Click Configuration > Log & Report > Email Daily Report to display the following scr

Pagina 900 - LOG MESSAGE DESCRIPTION

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide835The following table describes the labels in this screen. 51.3 Log Setting Screens The Log Se

Pagina 901 - Table 262 Anti-Spam Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide836The Log Setting tab also controls what information is saved in each log. For the system log, y

Pagina 902

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide83751.3.2 Edit System Log Settings The Log Settings Edit screen controls the detailed settings

Pagina 903 - Table 263 SSL VPN Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide838Figure 555 Configuration > Log & Report > Log Setting > Edit (System Log)

Pagina 904

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide839The following table describes the labels in this screen. Table 245 Configuration > Log &

Pagina 905 - Appendix A Log Descriptions

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide845.4 VPN Setup Wizard: Wizard TypeA VPN (Virtual Private Network) tunnel is a secure connection to

Pagina 906

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide840E-mail Server 1 Use the E-Mail Server 1 drop-down list to change the settings for e-mailing lo

Pagina 907 - Table 265 ZySH Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide841Active Select this to activate log consolidation. Log consolidation aggregates multiple log m

Pagina 908

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide84251.3.3 Edit Remote Server Log Settings The Log Settings Edit screen controls the detailed set

Pagina 909 - Table 266 ADP Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide843The following table describes the labels in this screen. Table 246 Configuration > Log

Pagina 910 - Table 267 Anti-Virus Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide84451.3.4 Active Log Summary ScreenThe Active Log Summary screen allows you to view and to edit

Pagina 911

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide845The following table describes the fields in this screen. Table 247 Configuration > Log

Pagina 912

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide846System log Select which events you want to log by Log Category. There are three choices:disabl

Pagina 913 - Table 268 User Logs

ZyWALL USG 2000 User’s Guide847CHAPTER 52 File Manager52.1 OverviewConfiguration files define the ZyWALL’s settings. Shell scripts are files of com

Pagina 914 - Table 269 myZyXEL.com Logs

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide848 These files have the same syntax, which is also identical to the way you run CLI commands manua

Pagina 915

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide849Your configuration files or shell scripts can use “exit” or a command line consisting of a sing

Pagina 916

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide855.5 VPN Express Wizard - Scenario Click the Express radio button as shown in Figure 52 on page 84

Pagina 917

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide85052.2 The Configuration File ScreenClick Maintenance > File Manager > Configuration File t

Pagina 918

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide851The following table describes the labels in this screen. Table 249 Maintenance > File Man

Pagina 919 - Table 270 IDP Logs

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide852Copy Use this button to save a duplicate of a configuration file on the ZyWALL. Click a configur

Pagina 920

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide853Apply Use this button to have the ZyWALL use a specific configuration file.Click a configuratio

Pagina 921

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide85452.3 The Firmware Package Screen Click Maintenance > File Manager > Firmware Package to o

Pagina 922

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide855Note: The Web Configurator is the recommended method for uploading firmware. You only need to u

Pagina 923 - MESSAGE EXPLANATION

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide856After you see the Firmware Upload in Process screen, wait two minutes before logging into the Zy

Pagina 924

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide857Note: You should include write commands in your scripts. If you do not use the write command, t

Pagina 925 - Table 272 IKE Logs

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide858Copy Use this button to save a duplicate of a shell script file on the ZyWALL. Click a shell scr

Pagina 926

ZyWALL USG 2000 User’s Guide859CHAPTER 53 Diagnostics53.1 OverviewUse the diagnostics screens for troubleshooting. 53.1.1 What You Can Do in this

Pagina 927

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide865.5.1 VPN Express Wizard - Configuration Figure 54 VPN Express Wizard: Step 3 • Secure Gateway:

Pagina 928 - Table 273 IPSec Logs

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide860The following table describes the labels in this screen. 53.3 The Packet Capture ScreenUse this

Pagina 929 - Table 274 Firewall Logs

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide861The following table describes the labels in this screen. Table 253 Maintenance > Diagnosti

Pagina 930 - Table 276 Policy Route Logs

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide86253.3.1 The Packet Capture Files ScreenClick Maintenance > Diagnostics > Packet Capture >

Pagina 931

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide86353.3.2 Example of Viewing a Packet Capture FileHere is an example of a packet capture file view

Pagina 932

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide864

Pagina 933

ZyWALL USG 2000 User’s Guide865CHAPTER 54 Reboot54.1 OverviewUse this to restart the device (for example, if the device begins behaving erratically)

Pagina 934

Chapter 54 RebootZyWALL USG 2000 User’s Guide866

Pagina 935 - Table 278 System Logs

ZyWALL USG 2000 User’s Guide867CHAPTER 55 Shutdown55.1 OverviewUse this to shutdown the device in preparation for disconnecting the power. See also

Pagina 936

Chapter 55 ShutdownZyWALL USG 2000 User’s Guide868

Pagina 937

ZyWALL USG 2000 User’s Guide869CHAPTER 56 TroubleshootingThis chapter offers some suggestions to solve problems you might encounter. • You can also r

Pagina 938

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide875.5.2 VPN Express Wizard - Summary This screen provides a read-only summary of the VPN tunnel’s c

Pagina 939

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide870• Ping the ZyWALL from a LAN computer. Make sure your computer’s Ethernet card is installed a

Pagina 940

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide871I cannot update the IDP/application patrol signatures.• Make sure your ZyWALL has the IDP/ap

Pagina 941 - Table 280 Device HA Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide872The ZyWALL checks the firewall rules in the order that they are listed. So make sure that you

Pagina 942

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide873The data rates through my cellular connection are no-where near the rates I expected.The act

Pagina 943

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide874The ZyWALL is not applying my application patrol bandwidth management settings.Bandwidth mana

Pagina 944

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide875The ZyWALL’s performance seems slower after configuring IDP.Depending on your network topolo

Pagina 945

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide876The ZyWALL routes and applies SNAT for traffic from some interfaces but not from others.The Z

Pagina 946 - Table 282 NAT Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide877I cannot get the application patrol to manage H.323 traffic.Make sure you have the H.323 ALG

Pagina 947 - Table 283 PKI Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide878• The ZyWALL and remote IPSec router must use the same authentication method to establish the

Pagina 948

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide879of its Trusted Certificates to authenticate the remote IPSec router’s certificate. The trust

Pagina 949 - CODE DESCRIPTION

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide885.5.3 VPN Express Wizard - Finish Now you can use the VPN tunnel.Figure 56 VPN Express Wizard: S

Pagina 950 - Table 284 Interface Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide880I uploaded a logo to show in the SSL VPN user screens but it does not display properly. The l

Pagina 951

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide881decompressed option while you download the firmware package. See Section 33.2.1 on page 553

Pagina 952

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide882• You may need to disable STP (Spanning Tree Protocol).• The master and its backups must all

Pagina 953

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide883I cannot add the admin users to a user group with access users.You cannot put access users a

Pagina 954 - Table 285 Account Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide8842 You must remove any spaces from the certificate’s filename before you can import the certif

Pagina 955 - Table 288 File Manager Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide885I uploaded a logo to use as the screen or window background but it does not display properly

Pagina 956 - Table 289 DHCP Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide886See the CLI Reference Guide for how to determine if you need to recover the firmware and how

Pagina 957

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide8872 Press the RESET button and hold it until the SYS LED begins to blink. (This usually takes

Pagina 958

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide8885 Use the handle to slide out the power module and remove it.Figure 577 Removing the Power

Pagina 959 - APPENDIX B

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide8898 Connect the power cord to the new ZyWALL power module.9 Reconnect the power cord to the po

Pagina 960 - Appendix B Common Services

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide895.5.4 VPN Advanced Wizard - Scenario Click the Advanced radio button as shown in Figure 52 on pag

Pagina 961 - Appendix B Common Services

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide890

Pagina 962

ZyWALL USG 2000 User’s Guide891CHAPTER 57 Product SpecificationsThe following specifications are subject to change without notice. See Chapter 2 on p

Pagina 963 - APPENDIX C

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide892This table gives details about the ZyWALL’s features. AUX port RS-232, DB

Pagina 964 - Windows 2000

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide893Static Routes 10,000 (shared with the policy routes)10,000 (shared with the policy ro

Pagina 965 - Windows 98 SE/Me

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide894Maximum Number of LDAP Groups 32 32 32Maximum Number of LDAP Servers for Each LDAP Gro

Pagina 966

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide895Syslog Servers 4 4 4IDPMaximum Number of IDP Profiles 32 32 32Custom Signatures 512 5

Pagina 967

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide896The following table, which is not exhaustive, lists standards referenced by ZyWALL fea

Pagina 968

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide89757.1 3G PCMCIA Card InstallationOnly insert a compatible 3G card. Slide the connecto

Pagina 969 - APPENDIX D

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide898

Pagina 970

ZyWALL USG 2000 User’s Guide899APPENDIX A Log DescriptionsThis appendix provides descriptions of example log messages for the ZLD-based ZyWALLs. The

Pagina 971

Contents OverviewZyWALL USG 2000 User’s Guide9Contents OverviewUser’s Guide ...

Pagina 972

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide90• Remote Access (Client Role) - Choose this to connect to an IPSec server. This ZyWALL is the clien

Pagina 973

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide900 Table 261 Blocked Web Site LogsLOG MESSAGE DESCRIPTION%s :%s The rating server responded

Pagina 974

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide901%s: Proxy mode is detectedThe system detected a proxy connection and blocked access accordi

Pagina 975

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide902Black List checking has been activated.The anti-spam black list has been turned on.Black Lis

Pagina 976

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide903Table 263 SSL VPN LogsLOG MESSAGE DESCRIPTION%s %s from %s has logged in SSLVPNA user has

Pagina 977

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide904The %s address-object is wrong type for 'network' in SSL Policy %s.The listed addr

Pagina 978

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide905%s %s is accessed. sent=<bytes> rcvd=<bytes>The listed SSL VPN access was used

Pagina 979

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide906Table 264 L2TP Over IPSec LogsLOG MESSAGE DESCRIPTIONThe configuration of L2TP over IPSec

Pagina 980

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide907The ZySH logs deal with internal system errors. Table 265 ZySH LogsLOG MESSAGE DESCRIPTIO

Pagina 981

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide908Can't remove %s 1st:zysh list nameTable OPS%s: cannot retrieve entries from table!1st:z

Pagina 982

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide909Table 266 ADP LogsLOG MESSAGE DESCRIPTIONfrom <zone> to <zone> [type=<type

Pagina 983

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide91that uses a 168-bit key. As a result, 3DES is more secure than DES. It also requires more processi

Pagina 984

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide910Table 267 Anti-Virus LogsLOG MESSAGE DESCRIPTIONInitializing Anti-Virus signature referenc

Pagina 985

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide911AV signature update has failed. Can not update last update time.The anti-virus signatures u

Pagina 986

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide912Anti-Virus rule %d has been modified.The anti-virus rule of the specified number has been ch

Pagina 987

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide913Table 268 User LogsLOG MESSAGE DESCRIPTION%s %s from %s has logged in ZyWALLA user logged

Pagina 988

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide914 Failed login attempt to ZyWALL from %s (login on a lockout address)A login attempt came fro

Pagina 989

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide915Registration has failed. Because of lack must fields.The device received an incomplete resp

Pagina 990 - Konqueror

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide916Do device register. The device started device registration.Do trial service activation.The d

Pagina 991

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide917Device has latest signature file; no need to updateThe device already has the latest versio

Pagina 992

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide918Get server response has failed.The device sent packets to the server, but did not receive a

Pagina 993

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide919Self signed certificate.Verification of a server’s certificate failed because it is self-si

Pagina 994

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide925.5.6 VPN Advanced Wizard - Phase 2 Phase 2 in an IKE uses the SA that was established in phase 1

Pagina 995 - APPENDIX E

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide920Enable IDP engine succeeded.The device turned on the IDP engine.Disable IDP engine succeeded

Pagina 996

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide921Add custom signature error: signature <sid> is over length.An attempt to add a custom

Pagina 997

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide922from <zone> to <zone> [type=<type>] <message> , Action: <action&g

Pagina 998

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide923Duplicate sid <sid> in import file at line <linenum>.The listed signature ID is

Pagina 999

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide924Protocol %s has been enabled.The listed protocol has been turned on in the application patro

Pagina 1000

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide925 Table 272 IKE LogsLOG MESSAGE DESCRIPTIONPeer has not announced DPD capabilityThe remote

Pagina 1001

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide926[SA] : Tunnel [%s] Phase 1 invalid protocol%s is the tunnel name. When negotiating Phase-1,

Pagina 1002

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide927Could not dial manual key tunnel "%s"%s is the tunnel name. The manual key tunnel

Pagina 1003

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide928 VPN gateway %s was enabled%s is the gateway name. An administrator enabled the VPN gateway.

Pagina 1004

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide929 Get outbound transform failWhen outgoing packet need to be transformed, the engine cannot

Pagina 1005

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide93• Nailed-Up: This displays for the site-to-site and remote access client role scenarios. Select th

Pagina 1006

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide930 Firewall %s %s rule %d was %s.1st %s is from zone, 2nd %s is to zone, %d is the index of t

Pagina 1007

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide931 The policy route %d uses empty user group!Use an empty object group.%d: the policy route r

Pagina 1008

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide932HTTPS port has been changed to port %s.An administrator changed the port number for HTTPS.%s

Pagina 1009

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide933Console baud has been reset to %d.An administrator changed the console port baud rate back

Pagina 1010

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide934DNS access control rule %u has been moved to %d.An administrator moved the rule %u to index

Pagina 1011

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide935 Access control rule %u of %s was modified.An access control rule was modified successfully

Pagina 1012

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide936DHCP Server executed with cautious mode disabledDHCP Server executed with cautious mode disa

Pagina 1013

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide937Device is rebooted by administrator!An administrator restarted the device.Insufficient memo

Pagina 1014

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide938Update the profile %s has failed because the feature requested is only available to donators

Pagina 1015

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide939The profile %s has been paused because the HA interface of VRRP status was standby.The prof

Pagina 1016

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide945.5.8 VPN Advanced Wizard - Finish Now you can use the VPN tunnel.Figure 61 VPN Wizard: Step 6:

Pagina 1017

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide940 Table 279 Connectivity Check LogsLOG MESSAGE DESCRIPTIONCan't open link_up2 Cannot r

Pagina 1018

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide941 Can't use MULTICAST IP for destinationThe connectivity check process can't use m

Pagina 1019

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide942%s file not existed, Skip syncing it for %sThere is no file to be synchronized from the Mast

Pagina 1020

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide943Device HA authentication type for VRRP group %s maybe wrong.A VRRP group’s Authentication T

Pagina 1021

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide944 Table 281 Routing Protocol LogsLOG MESSAGE DESCRIPTIONRIP on interface %s has been stoppe

Pagina 1022

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide945RIP md5 authentication id and key have been deleted.RIP md5 authentication id and key have

Pagina 1023

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide946 Invalid OSPF virtual-link %s authentication of area %s.Virtual-link %s authentication has b

Pagina 1024

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide947 Register SIP ALG signal port=%d failed.SIP ALG apply signal port failed.%d: Port numberReg

Pagina 1025

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide948SCEP enrollment "%s" successfully, CA "%s", URL "%s"The device

Pagina 1026

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide949 Export X509 certificate "%s" from "Trusted Certificate" successfullyTh

Pagina 1027

ZyWALL USG 2000 User’s Guide95CHAPTER 6 Configuration BasicsThis information is provided to help you configure the ZyWALL effectively. Some of it is

Pagina 1028

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide950 25 Database method failed due to timeout.26 Database method failed.27 Path was not verified

Pagina 1029

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide951Interface %s is enabled.An administrator enabled an interface. %s: interface name.Interface

Pagina 1030

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide952Interface %s connect failed: MS-CHAP authentication failed.MS-CHAP authentication failed (th

Pagina 1031

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide953"SIM card has been successfully unlocked by PUK code on interface cellular%d.You enter

Pagina 1032

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide954 "Cellular device [%s %s] has been removed from %s.The cellular device (identified by

Pagina 1033

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide955 Table 287 Force Authentication LogsLOG MESSAGE DESCRIPTIONForce User Authentication

Pagina 1034

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide956 Table 289 DHCP LogsLOG MESSAGE DESCRIPTIONCan't find any lease for this client - %

Pagina 1035

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide957Table 291 IP-MAC Binding LogsLOG MESSAGE DESCRIPTIONDrop packet %s-%u.%u.%u.%u-%02X:%02X:

Pagina 1036

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide958

Pagina 1037

ZyWALL USG 2000 User’s Guide959APPENDIX B Common ServicesThe following table lists some commonly-used services and their associated protocols and por

Pagina 1038

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide96objects whenever the interface’s IP address settings change. For example, if you change an

Pagina 1039

Appendix B Common ServicesZyWALL USG 2000 User’s Guide960ESP (IPSEC_TUNNEL)User-Defined 50 The IPSEC ESP (Encapsulation Security Protocol) tunneling p

Pagina 1040

Appendix B Common ServicesZyWALL USG 2000 User’s Guide961PPTP TCP 1723 Point-to-Point Tunneling Protocol enables secure transfer of data over public

Pagina 1041

Appendix B Common ServicesZyWALL USG 2000 User’s Guide962TFTP UDP 69 Trivial File Transfer Protocol is an Internet file transfer protocol similar to F

Pagina 1042

ZyWALL USG 2000 User’s Guide963APPENDIX C Displaying Anti-Virus AlertMessages in WindowsWith the anti-virus packet scan, when a virus is detected, yo

Pagina 1043

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9642 Select the Messenger service and click Start.Figure 581 W

Pagina 1044

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9652 Select the Messenger service and click Start Service.Figur

Pagina 1045

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9661 Right-click on the program task bar and click Properties. F

Pagina 1046

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9674 Right-click in the StartUp pane and click New, Shortcut. F

Pagina 1047

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9686 Specify a name for the shortcut or accept the default and c

Pagina 1048

ZyWALL USG 2000 User’s Guide969APPENDIX D Importing CertificatesThis appendix shows you how to import public key certificates into your web browser.

Pagina 1049

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide976.2.1 Interface Types There are many types of interfaces in the ZyWALL. In addition to b

Pagina 1050

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9701 If your device’s Web Configurator is set to use SSL certification, then the first ti

Pagina 1051 - APPENDIX F

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9714 In the Certificate dialog box, click Install Certificate.Figure 594 Internet Expl

Pagina 1052

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9726 If you want Internet Explorer to Automatically select certificate store based on the

Pagina 1053 - ZyXEL Limited Warranty

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9738 In the Select Certificate Store dialog box, choose a location in which to save the

Pagina 1054 - Registration

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide97410 If you are presented with another Security Warning, click Yes.Figure 600 Internet

Pagina 1055 - Numerics

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide975Installing a Stand-Alone Certificate File in Internet ExplorerRather than browsing to

Pagina 1056 - ZyWALL USG 2000 User’s Guide

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9761 Open Internet Explorer and click Tools > Internet Options.Figure 605 Internet E

Pagina 1057

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9773 In the Certificates dialog box, click the Trusted Root Certificates Authorities tab

Pagina 1058

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9786 The next time you go to the web site that issued the public key certificate you just

Pagina 1059

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9793 The certificate is stored and you can now connect securely to the Web Configurator.

Pagina 1060

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide986.2.2 Default Interface and Zone ConfigurationThis section introduces the ZyWALL’s defaul

Pagina 1061

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9801 Open Firefox and click Tools > Options.Figure 612 Firefox 2: Tools Menu2 In the

Pagina 1062

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9813 In the Certificate Manager dialog box, click Web Sites > Import.Figure 614 Fi

Pagina 1063

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide982Removing a Certificate in FirefoxThis section shows you how to remove a public key cer

Pagina 1064

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9833 In the Certificate Manager dialog box, select the Web Sites tab, select the certifi

Pagina 1065

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9841 If your device’s Web Configurator is set to use SSL certification, then the first ti

Pagina 1066

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide985Installing a Stand-Alone Certificate File in OperaRather than browsing to a ZyXEL Web

Pagina 1067

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9862 In Preferences, click Advanced > Security > Manage certificates.Figure 623 O

Pagina 1068

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9873 In the Certificates Manager, click Authorities > Import.Figure 624 Opera 9: C

Pagina 1069

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9885 In the Install authority certificate dialog box, click Install.Figure 626 Opera 9

Pagina 1070

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9891 Open Opera and click Tools > Preferences.Figure 628 Opera 9: Tools Menu2 In Pr

Pagina 1071

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide99• The DMZ zone contains the ge4, ge5, and ge6 interfaces (physical ports P4, P5, and P6).

Pagina 1072

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9903 In the Certificates manager, select the Authorities tab, select the certificate that

Pagina 1073

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9912 Click Continue.Figure 631 Konqueror 3.5: Server Authentication3 Click Forever whe

Pagina 1074

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide992Installing a Stand-Alone Certificate File in KonquerorRather than browsing to a ZyXEL

Pagina 1075

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9933 The next time you visit the web site, click the padlock in the address bar to open

Pagina 1076

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9944 The next time you go to the web site that issued the public key certificate you just

Pagina 1077

ZyWALL USG 2000 User’s Guide995APPENDIX E Open Software AnnouncementsEnd-User License Agreement for “ZyWALL USG 2000” WARNING: ZyXEL Communications

Pagina 1078

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide996You may not remove any proprietary notice of ZyXEL or any of its licensors from a

Pagina 1079

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide9976.No WarrantyTHE SOFTWARE IS PROVIDED "AS IS." TO THE MAXIMUM EXTENT

Pagina 1080

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide9989.Audit RightsZyXEL SHALL HAVE THE RIGHT, AT ITS OWN EXPENSE, UPON REASONABLE PRI

Pagina 1081

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide999bridge-utils 0.9.5. http://linux-net.osdl.org/index.php/Bridgedhcpcd-1.3.22-pl4

Comentarios a estos manuales

Sin comentarios