ZyXEL Communications Network Router USG 2000 Uživatelský manuál Strana 1

Procházejte online nebo si stáhněte Uživatelský manuál pro Směrovače ZyXEL Communications Network Router USG 2000. ZyXEL Communications Network Router USG 2000 User's Manual Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 108
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 0
www.zyxel.com
www.zyxel.com
ZyWALL USG 2000
Unified Security Gateway
Copyright © 2010
ZyXEL Communications Corporation
Firmware Version 2.12
Edition 1, 3/2010
Default Login Details
LAN Port P1
IP Address https://192.168.1.1
User Name admin
Password 1234
Zobrazit stránku 0
1 2 3 4 5 6 ... 107 108

Shrnutí obsahu

Strany 1 - ZyWALL USG 2000

www.zyxel.comwww.zyxel.comZyWALL USG 2000Unified Security GatewayCopyright © 2010 ZyXEL Communications CorporationFirmware Version 2.12Edition 1, 3/20

Strany 2

Contents OverviewZyWALL USG 2000 User’s Guide10 Content Filtering ...

Strany 3 - About This User's Guide

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1006.4 Packet FlowHere is the order in which the ZyWALL applies its features and checks.Fig

Strany 4 - Customer Support

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1000Notice Information herein is subject to change without notice. Companies, names,

Strany 5 - Disclaimer

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1001PPP LicenseCopyright (c) 1993 The Australian National University.All rights res

Strany 6 - Document Conventions

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1002All rights reserved. Redistribution and use in source and binary forms, with or

Strany 7 - Icons Used in Figures

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1003This Product includes expat-1.95.6 software under the Expat LicenseExpat Licens

Strany 8 - Safety Warnings

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1004•This license is compatible with The GNU General Public License, Version 2This i

Strany 9 - Contents Overview

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10052. Redistributions in binary form must reproduce the above copyright notice, th

Strany 10

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1006be it the RC4, RSA, lhash, DES, etc., code; not just the SSL code. The SSL docum

Strany 11 - Table of Contents

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1007This Product includes libevent-1.1a and xinetd-2.3.14 software under the a 3-cl

Strany 12

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1008 * Neither the name of [original copyright holder] nor the names of its

Strany 13 - Chapter 7

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1009DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING

Strany 14

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide101• You do not need to set up policy routes for 1:1 NAT entries.• You can create Many 1:1

Strany 15

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1010Permission to use, copy, modify, and distribute this software for any purpose wi

Strany 16

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1011"License" shall mean the terms and conditions for use, reproduction,

Strany 17 - Chapter 15

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1012"Contributor" shall mean Licensor and any individual or Legal Entity o

Strany 18

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1013attribution notices within Derivative Works that You distribute, alongside or a

Strany 19

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1014Contributor harmless for any liability incurred by, or claims asserted against,

Strany 20

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1015USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. This s

Strany 21

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1016guarantee your freedom to share and change free software--to make sure the softw

Strany 22 - Chapter 35

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1017Most GNU software, including some libraries, is covered by the ordinary GNU Gen

Strany 23

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10180. This License Agreement applies to any software library or other program which

Strany 24

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1019still operates, and performs whatever part of its purpose remains meaningful. (

Strany 25

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1022 Policy Routes: These are the user-configured policy routes. Configure policy routes to

Strany 26

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1020"work that uses the Library". Such a work, in isolation, is not a deri

Strany 27 - Chapter 51

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1021version is interface-compatible with the version that the work was made with. c

Strany 28

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide102210. Each time you redistribute the Library (or any work based on the Library), t

Strany 29 - Table of Contents

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1023Library does not specify a license version number, you may choose any version e

Strany 30

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1024pcmcia-cs-3.2.8, libeeprog, mgetty-1.1.35, gmp-4.1, msmtp-1.4.12 and libqsearch

Strany 31 - User’s Guide

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1025the software. Also, for each author's protection and ours, we want to make

Strany 32

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1026b) You must cause any work that you distribute or publish, that in whole or in p

Strany 33 - CHAPTER 1

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1027source code means all the source code for all modules it contains, plus any ass

Strany 34

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1028whole is intended to apply in other circumstances. It is not the purpose of this

Strany 35 - 1.3 Front Panel

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1029DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION

Strany 36 - 1.3.1.2 Mini-GBIC Slots

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide103ZyWALL stops checking the packets against the NAT table and moves on to bandwidth manage

Strany 37

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1030means a mechanism generally accepted in the software development community for t

Strany 38

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10311.11. "Source Code" means the preferred form of the Covered Code for

Strany 39 - 1.3.3 Front Panel LEDs

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1032Subject to third party intellectual property claims, each Contributor hereby gra

Strany 40 - 1.4 Management Overview

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1033made available via Electronic Distribution Mechanism, must remain available for

Strany 41 - Console Port

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1034You must duplicate the notice in Exhibit A in each file of the Source Code. If i

Strany 42

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1035regulation then You must: (a) comply with the terms of this License to the maxi

Strany 43 - CHAPTER 2

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1036(not the initial developer or any other contributor) assume the cost of any nece

Strany 44 - Content Filter

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1037granted by You or any distributor hereunder prior to termination shall survive

Strany 45 - 2.2 Applications

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1038As between Initial Developer and the Contributors, each party is responsible for

Strany 46 - 2.2.1 VPN Connectivity

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1039NOTE: The text of this Exhibit A may differ slightly from the text of the notic

Strany 47 - 2.2.2.2 Full Tunnel Mode

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1046.5.1 FeatureThis provides a brief description. See the appropriate chapter(s) in this U

Strany 48

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1040USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. This Pr

Strany 49 - 2.2.5 Device HA

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1041Redistribution and use of this software and associated documentation("Soft

Strany 50

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1042Copyright 1999-2003 The OpenLDAP Foundation, Redwood City, California, USA. All

Strany 51 - CHAPTER 3

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1043use of gd. If you have questions, ask. "Derived works" includes all p

Strany 52 - Figure 19 Login Screen

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1044Copyright (C) 1999, 2000, 2002 Aladdin Enterprises. All rights reserved.This sof

Strany 53 - Figure 21 Dashboard

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10453. This notice may not be removed or altered from any source distribution.COPYR

Strany 54 - 3.3.2 Navigation Panel

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1046 * There is no warranty against interference with your enjoyment of the *

Strany 55 - 3.3.2.2 Monitor Menu

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1047 * Greg Roelofs * Tom Tanner * * libpng versions 0.5, May 1995, through 0

Strany 56 - 3.3.2.3 Configuration Menu

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1048 * to the following restrictions: * * 1. The origin of this source code must not

Strany 57 - TAB FUNCTION

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide10492. Redistributions in binary form must reproduce the above copyright notice, th

Strany 58 - Chapter 3 Web Configurator

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide105subscription to update the anti-virus and IDP/application patrol signatures You must hav

Strany 59

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide1050PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTOR

Strany 60 - 3.3.3 Main Window

ZyWALL USG 2000 User’s Guide1051APPENDIX F Legal InformationCopyrightCopyright © 2010 by ZyXEL Communications Corporation.The contents of this public

Strany 61 - 3.3.3.3 Object Reference

Appendix F Legal InformationZyWALL USG 2000 User’s Guide1052• This device may not cause harmful interference.• This device must accept any interferenc

Strany 62 - Table 8 Object References

Appendix F Legal InformationZyWALL USG 2000 User’s Guide1053Notices Changes or modifications not expressly approved by the party responsible for comp

Strany 63 - 3.3.4 Tables and Lists

Appendix F Legal InformationZyWALL USG 2000 User’s Guide1054To obtain the services of this warranty, contact your vendor. You may also refer to the wa

Strany 64

IndexZyWALL USG 2000 User’s Guide1055IndexSymbolsNumerics1 to 1 NAT 1021 to 1 SNAT 1033322 Dynamic DNS 3813DES 4713G 1223G see also cellular 299AAAABa

Strany 65

IndexZyWALL USG 2000 User’s Guide1056and SNMP 827and SSH 818and Telnet 821and VPN connections 444and WWW 803HOST 705RANGE 706SUBNET 706types of 705whe

Strany 66 - 3.3.4.3 Working with Lists

IndexZyWALL USG 2000 User’s Guide1057real-time alert message 965registration status 552scanner types 561signatures 558statistics 250trial service acti

Strany 67 - CHAPTER 4

IndexZyWALL USG 2000 User’s Guide1058truncated-options 615truncated-timestamp-header 616TTCP-detected 615types of 574u-encoding 614undersize-len 615un

Strany 68

IndexZyWALL USG 2000 User’s Guide1059bridge interfaces 278, 319and virtual interfaces of members 319basic characteristics 279effect on routing table 3

Strany 69

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide106and general NAT on the source address. You have to set up the criteria, next-hops, and NA

Strany 70 - 4.1.3 Internet Access: PPPoE

IndexZyWALL USG 2000 User’s Guide1060computer names 289, 315, 325, 334, 520computer virus 548infection and prevention 561see also virusconcurrent e-ma

Strany 71 - 4.1.5 ISP Parameters

IndexZyWALL USG 2000 User’s Guide1061Ddashboard 53, 55, 209Data Encryption Standard, see DESData Terminal Ready, see DTRdate 785daylight savings 786DD

Strany 72 - 4.1.5.1 PPTP Configuration

IndexZyWALL USG 2000 User’s Guide1062file structure 725directory traversal attack 613directory traversals 613disclaimer 5, 1051Distinguished Name (DN)

Strany 73

IndexZyWALL USG 2000 User’s Guide1063basic characteristics 279virtual 329Ethernet ports 33, 35default settings 36examples (tutorials) 119exceptional s

Strany 74 - 4.2 Device Registration

IndexZyWALL USG 2000 User’s Guide1064FTP 821additional signaling port 407ALG 401and address groups 823and address objects 823and certificates 822and z

Strany 75

IndexZyWALL USG 2000 User’s Guide1065action 573, 608alerts 572and services 712applying custom signatures 592base profiles 564, 568configuration overvi

Strany 76

IndexZyWALL USG 2000 User’s Guide1066and layer-3 virtualization 278and NAT 391and physical ports 96, 278and policy routes 355and static routes 359and

Strany 77 - CHAPTER 5

IndexZyWALL USG 2000 User’s Guide1067Perfect Forward Secrecy 450PFS 450phase 2 settings 449policy enforcement 449remote access 448remote IPSec router

Strany 78 - 5.2.2 Select WAN Type

IndexZyWALL USG 2000 User’s Guide1068remote user configuration 175session monitor 249troubleshooting 879where used 111WINS 520LANinterface 33IP addres

Strany 79 - 5.2.3 Configure WAN Settings

IndexZyWALL USG 2000 User’s Guide1069main routing table 102main window 60maintenance menu 60malware 629managed web pages 627management accesstroublesh

Strany 80

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1076.5.7 Static RoutesUse static routes to tell the ZyWALL about networks not directly con

Strany 81 - Chapter 5 Quick Setup

IndexZyWALL USG 2000 User’s Guide1070NetBIOSBroadcast over IPSec 448Name Server, see NBNS.NetBIOS Name Server, see NBNSNetMeeting 408see also H.323Net

Strany 82

IndexZyWALL USG 2000 User’s Guide1071offset attack 615request-uri-directory attack 614PP1 33P1~P8 LEDs 40P2P (Peer-to-peer) 574attacks 574see also Pee

Strany 83 - 5.3 VPN Quick Setup

IndexZyWALL USG 2000 User’s Guide1072port sweep 610port translation, see NATport triggering 360and firewall 356, 876and policy routes 356and service g

Strany 84

IndexZyWALL USG 2000 User’s Guide1073regular expressions 247reject (IDP)both 573, 608receiver 573, 608sender 573, 608related documentation 3Relative D

Strany 85

IndexZyWALL USG 2000 User’s Guide1074SCEP (Simple Certificate Enrollment Protocol) 747scheduletroubleshooting 883schedules 717and content filtering 61

Strany 86

IndexZyWALL USG 2000 User’s Guide1075and firewall 403and RTP 408media inactivity timeout 406signaling inactivity timeout 406signaling port 406troubles

Strany 87

IndexZyWALL USG 2000 User’s Guide1076access policy 482configuration overview 110full tunnel mode 47, 482network access mode 46prerequisites 110remote

Strany 88 - Chapter 5 Quick Setup

IndexZyWALL USG 2000 User’s Guide1077port numbers 712portscan 609portsweep 610RST 610SYN (synchronize) 611SYN flood 611window size 588technical refere

Strany 89

IndexZyWALL USG 2000 User’s Guide1078PPP 872PWR 869RADIUS server 882routing 876schedules 883security settings 871shell scripts 885SIP 876SNAT 876SSL 8

Strany 90

IndexZyWALL USG 2000 User’s Guide1079user portallinks 765logo 490see SSL user screens 493, 499user sessions, see sessionsuser SSL screens 493, 499acce

Strany 91

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide108The ZyWALL only checks regular (through-ZyWALL) firewall rules for packets that are redir

Strany 92

IndexZyWALL USG 2000 User’s Guide1080see also ALG 402VPN 441active protocol 476and NAT 474and the firewall 425basic troubleshooting 877hub-and-spoke,

Strany 93

IndexZyWALL USG 2000 User’s Guide1081and authentication method objects 802and certificates 801and zones 803see also HTTP, HTTPS 148, 799Zzipped filest

Strany 94

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1093 Name the entry.4 Select the interface from which you want to redirect incoming HTTP re

Strany 95 - CHAPTER 6

Table of ContentsZyWALL USG 2000 User’s Guide11Table of ContentsAbout This User's Guide...

Strany 96

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide110Example: Suppose you have a SIP proxy server connected to the DMZ zone for VoIP calls. Yo

Strany 97 - 6.2.1 Interface Types

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide111Example: See Chapter 7 on page 119.6.5.17 L2TP VPNUse L2TP VPN to let remote users use

Strany 98

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide112Note: With this example, Bob would have to log in using his account. If you do not want h

Strany 99

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1131 Create a user account for Bill if you have not done so already (Configuration > Obj

Strany 100 - 6.4 Packet Flow

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1146.6 ObjectsObjects store information and are referenced by other features. If you update

Strany 101

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide115If you want to force users to log in to the ZyWALL before the ZyWALL routes traffic for

Strany 102

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide1162 Create an address object for the administrator’s computer (Configuration > Object &g

Strany 103

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide117Always use Maintenance > Shutdown > Shutdown or the shutdown command before you tu

Strany 104 - 6.5.3 Licensing Update

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide118

Strany 105 - 6.5.6 Policy Routes

ZyWALL USG 2000 User’s Guide119CHAPTER 7 TutorialsHere are examples of using the Web Configurator to set up features in the ZyWALL. See also Chapter

Strany 106

Table of ContentsZyWALL USG 2000 User’s Guide123.3 Web Configurator Screens Overview ...

Strany 107 - 6.5.10 NAT

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide120• You want to be able to apply security settings specifically for all VPN tunnels so you create a ne

Strany 108 - 6.5.11 HTTP Redirect

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1211 Click Configuration > Network > Zone and then the Add icon.2 Enter VPN as the name, select

Strany 109 - 6.5.14 Firewall

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1222 Drag physical port 5 onto representative interface ge4 and click Apply.Figure 70 Configuration &

Strany 110 - 6.5.16 SSL VPN

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1233 Click Configuration > Network > Interface > Cellular. Select the 3G device’s entry and c

Strany 111 - 6.5.18 Application Patrol

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1245 Go to the Dashboard. The Interface Status Summary section should contain a “cellular” entry. When

Strany 112 - 6.5.22 Content Filter

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide125You do not have to change many of the ZyWALL’s settings from the defaults to set up this trunk. You

Strany 113 - 6.5.24 Device HA

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1267.3.2 Configure the WAN Trunk 1 Click Configuration > Network > Interface > Trunk. Click t

Strany 114 - 6.6 Objects

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1273 Select the trunk as the default trunk and click Apply. Figure 78 Configuration > Network >

Strany 115 - 6.7 System

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide128In this example, the ZyWALL is router X (1.2.3.4), and the remote IPSec router is router Y (2.2.2.2)

Strany 116 - 6.7.5 Shutdown

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1297.4.2 Set Up the VPN ConnectionThe VPN connection manages the IPSec SA. You have to set up the add

Strany 117 - MENU ITEM(S)

Table of ContentsZyWALL USG 2000 User’s Guide136.2.1 Interface Types ...

Strany 118

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1304 Enable the VPN connection and name it (“VPN_CONN_EXAMPLE”). Under VPN Gateway select Site-to-site

Strany 119 - CHAPTER 7

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1317.5 How to Configure a Hub-and-spoke IPSec VPN Without a VPN ConcentratorA hub-and-spoke IPSec VPN

Strany 120 - 7.1.2 Configure Zones

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide132• My Address: 10.0.0.1• Peer Gateway Address: 10.0.0.2VPN Connection (VPN Tunnel 1): • Local Policy:

Strany 121

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide133• To have all Internet access from the spoke routers to go through the VPN tunnel, set the VPN rule

Strany 122

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1347.6.1 Set Up User AccountsSet up one user account for each user account in the RADIUS server. If it

Strany 123

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1352 Enter the name of the group that is used in Table 20 on page 133. In this example, it is “Finance

Strany 124 - ge3: 512 Kbps

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1361 Click Configuration > Object > AAA Server > RADIUS. Double-click the radius entry. Config

Strany 125

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide137Note: The users will have to log in using the Web Configurator login screen before they can use HTT

Strany 126

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1381 Click Configuration > AppPatrol. If application patrol and bandwidth management are not enabled

Strany 127

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1393 Double-click the Default policy.Figure 91 Configuration > AppPatrol > Common > http4 C

Strany 128 - 7.4.1 Set Up the VPN Gateway

Table of ContentsZyWALL USG 2000 User’s Guide147.1 How to Configure Interfaces, Port Grouping, and Zones ...

Strany 129

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1405 Click the Add icon in the policy list. In the new policy, select one of the user groups that is al

Strany 130

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1412 Give the schedule a descriptive name. Set up the days (Monday through Friday) and the times (8:30

Strany 131 - Headquarters (ZyWALL USG):

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1422 Click the Add icon again and create a rule for one of the user groups that is allowed to access th

Strany 132 - Branch Office B (ZyWALL USG):

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1431 Click Configuration > Object > AAA Server > RADIUS. Double-click the radius entry. Besid

Strany 133

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1442 Now you add ext-group-user user objects to identify groups based on the group identifier values. S

Strany 134 - 7.6.2 Set Up User Groups

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide145• Select Endpoint must have Personal Firewall installed and move the Kaspersky Internet Security en

Strany 135

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide146Repeat as needed to create endpoint security objects for other Windows operating system versions.7.8

Strany 136

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1474 Turn on authentication policy and click Apply.Figure 101 Configuration > Auth. Policy T

Strany 137 - Authentication Policy)

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide148user access (logging into SSL VPN for example). See Chapter 50 on page 783 for more on service contr

Strany 138 - Chapter 7 Tutorials

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1494 Select the new rule and click the Add icon.Figure 105 Configuration > System > WWW (First

Strany 139 - Chapter 7 Tutorials

Table of ContentsZyWALL USG 2000 User’s Guide157.14 How to Use Active-Passive Device HA ...

Strany 140 - 7.6.5 Set Up MSN Policies

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1506 Click Apply.Figure 107 Configuration > System > WWW (Second Example Admin Service Rule Con

Strany 141 - 7.6.6 Set Up Firewall Rules

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide151for ge2 IP address 10.0.0.8 to a H.323 device located on the LAN and using IP address 192.168.1.56.

Strany 142 - User Accounts based on Groups

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1521 Use Configuration > Object > Address > Add to create an address object for the public WAN

Strany 143

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1532 Click Configuration > Network > NAT > Add.Configure a name for the rule (WAN-LAN_H323 he

Strany 144 - Authentication Policies

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1541 Click Configuration > Firewall > Add.In the From field select WAN.In the To field select LAN

Strany 145

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1557.11.1 Create the Address ObjectsUse Configuration > Object > Address > Add to create the

Strany 146

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide156• Keep Enable NAT Loopback selected to allow users connected to other interfaces to access the HTTP

Strany 147

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1571 Click Configuration > Firewall > Add. Set the From field as WAN and the To field as DMZ. Se

Strany 148

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide158address 1.1.1.2 that you will use on the ge3 interface and map to the IPPBX’s private IP address of

Strany 149 - Configured)

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1597.12.1 Turn On the ALGClick Configuration > Network > ALG. Select Enable SIP ALG and Enable

Strany 150

Table of ContentsZyWALL USG 2000 User’s Guide1610.6 The DDNS Status Screen ...

Strany 151 - 7.10.1 Turn On the ALG

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1602 Create a host address object named IPPBX-Public for the public WAN IP address 1.1.1.2. Figure 121

Strany 152

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide161•Click OK. Figure 122 Configuration > Network > NAT > Add 7.12.4 Set Up a WAN to DMZ F

Strany 153

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1621 Click Configuration > Firewall > Add. Set the From field as WAN and the To field as DMZ. Set

Strany 154

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1631 Click Configuration > Firewall > Add. Set the From field as DMZ and the To field as LAN. Se

Strany 155 - 7.11.2 Configure NAT

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1647.13.2 Configure the Policy RouteNow you need to configure a policy route that has the ZyWALL use t

Strany 156

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide165An Ethernet switch connects both ZyWALLs’ ge1 interfaces to the LAN. Whichever ZyWALL is functionin

Strany 157

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1667.14.2 Configure Device HA on the Master ZyWALL1 Log into ZyWALL A (the master) and click Configura

Strany 158

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1673 Set the Device Role to Master. This example focuses on the connection from the LAN (ge1) to the I

Strany 159 - 7.12.1 Turn On the ALG

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1687.14.3 Configure the Backup ZyWALL1 Connect a computer to ZyWALL B’s ge1 interface and log into its

Strany 160

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1694 Set the Device Role to Backup. Activate monitoring for the ge1 and ge2 interfaces. Set the Synchr

Strany 161

Table of ContentsZyWALL USG 2000 User’s Guide1713.2 Port Grouping ...

Strany 162

Chapter 7 TutorialsZyWALL USG 2000 User’s Guide1707.14.4 Deploy the Backup ZyWALLConnect ZyWALL B’s ge1 interface to the LAN network. Connect ZyWALL

Strany 163

ZyWALL USG 2000 User’s Guide171CHAPTER 8 L2TP VPN ExampleHere is how to create a basic L2TP VPN tunnel.8.1 L2TP VPN ExampleThis example uses the fol

Strany 164

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide172• Configure the My Address setting. This example uses interface ge2 with static IP address 17

Strany 165 - 7.14.1 Before You Start

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1738.3 Configuring the Default L2TP VPN Connection Example1 Click Configuration > VPN >

Strany 166 - ZyWALL Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1743 Select the Default_L2TP_VPN_Connection entry and click Activate and then Apply to turn on t

Strany 167 - Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide175• The other fields are left to the defaults in this example, click Apply.Figure 140 Config

Strany 168

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1762 Select Connect to a workplace and click Next.Figure 141 Set up a connection or network: C

Strany 169

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1774 Enter the domain name or WAN IP address configured as the My Address in the VPN gateway co

Strany 170

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1786 Click Close. Figure 145 Connect to a workplace: The connection is ready to use7 In the Ne

Strany 171 - CHAPTER 8

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1798 Click Security, select Advanced (custom settings) and click Settings.Figure 147 Connect

Strany 172

Table of ContentsZyWALL USG 2000 User’s Guide18Chapter 16Routing Protocols...

Strany 173 - Connection Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide180inside it. The L2TP tunnel itself does not need encryption since it is inside the encrypted I

Strany 174

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18113 Select the L2TP VPN connection and click Connect.Figure 152 L2TP to ZyWALL Properties:

Strany 175

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18215 A window appears while the user name and password are verified and notifies you when the c

Strany 176 - Chapter 8 L2TP VPN Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18317 After the network location has been set, click Close.Figure 156 Set Network Location Su

Strany 177

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18419 Click the L2TP connection’s View status link to open a status screen. Figure 158 Network

Strany 178 - 6 Click Close

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1858.5.2 Configuring L2TP in Windows XPIn Windows XP do the following to establish an L2TP VPN

Strany 179

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1865 Type L2TP to ZyWALL as the Company Name.Figure 162 New Connection Wizard: Connection Name

Strany 180

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1877 Enter the domain name or WAN IP address configured as the My Address in the VPN gateway co

Strany 181 - Chapter 8 L2TP VPN Example

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18810 Click Security, select Advanced (custom settings) and click Settings.Figure 166 Connect

Strany 182

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide18912 Click IPSec Settings. Figure 168 L2TP to ZyWALL Properties > Security13 Select the U

Strany 183

Table of ContentsZyWALL USG 2000 User’s Guide1920.2.1 The HTTP Redirect Edit Screen ...

Strany 184

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide19014 Click Networking. Select L2TP IPSec VPN as the Type of VPN. Click OK.Figure 170 L2TP to

Strany 185

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide19118 Click Details to see the address that you received is from the L2TP range you specified o

Strany 186

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1923 Select HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasman\Parameters.Figure 175

Strany 187 - 172.16.1.2

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1938.5.3.2 Configure the Windows 2000 IPSec PolicyAfter you have created the registry entry an

Strany 188

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1943 Click Add > IP Security Policy Management >Add > Finish. Click Close > OK.Figur

Strany 189

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1955 Name the IP security policy L2TP to ZyWALL, and click Next.Figure 182 IP Security Policy

Strany 190

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1967 Leave the Edit Properties check box selected and click Finish.Figure 184 IP Security Poli

Strany 191

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide1979 Select This rule does not specify a tunnel and click Next.Figure 186 IP Security Policy

Strany 192 - Figure 176 New DWORD Value

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide19811 Select Use this string to protect the key exchange (preshared key), type password in the t

Strany 193 - Figure 178 Run mmc

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide19913 Type ZyWALL WAN_IP in the Name field. Clear the Use Add Wizard check box and click Add.Fi

Strany 195

Table of ContentsZyWALL USG 2000 User’s Guide2025.1 IPSec VPN Overview ...

Strany 196

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide20015 Configure the following in the Filter Properties window’s Protocol tab. Set the protocol t

Strany 197

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide20117 Select Require Security and click Next. Then click Finish and Close.Figure 194 IP Secu

Strany 198 - 12 Click Add

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide2021 Click Start > Settings > Network and Dial-up connections > Make New Connection. In

Strany 199

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide2034 Select For all users and click Next.Figure 199 New Connection Wizard: Connection Availab

Strany 200

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide2047 Click Security and select Advanced (custom settings) and click Settings.Figure 202 Connec

Strany 201

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide2059 Click Networking and select Layer 2 Tunneling Protocol (L2TP) from the drop-down list box.

Strany 202

Chapter 8 L2TP VPN ExampleZyWALL USG 2000 User’s Guide20612 Click Details and scroll down to see the address that you received is from the L2TP range

Strany 203 - 6 Click Properties

207PART IITechnical Reference

Strany 205

ZyWALL USG 2000 User’s Guide209CHAPTER 9 Dashboard9.1 OverviewUse the Dashboard screens to check status information about the ZyWALL.9.1.1 What Yo

Strany 206

Table of ContentsZyWALL USG 2000 User’s Guide2129.1.1 What You Need to Know ...

Strany 207 - Technical Reference

Chapter 9 DashboardZyWALL USG 2000 User’s Guide210interface status in widgets that you can re-arrange to suit your needs. You can also collapse, refre

Strany 208

Chapter 9 DashboardZyWALL USG 2000 User’s Guide211The following front and rear panel labels display when you hover your cursor over a connected inter

Strany 209 - CHAPTER 9

Chapter 9 DashboardZyWALL USG 2000 User’s Guide212Device This identifies a device installed in one of the ZyWALL’s extension slots, the Security Exten

Strany 210 - Table 21 Dashboard

Chapter 9 DashboardZyWALL USG 2000 User’s Guide213Status This field displays the current status of each interface. The possible values depend on what

Strany 211 - LABEL DESCRIPTION

Chapter 9 DashboardZyWALL USG 2000 User’s Guide214Action Use this field to get or to update the IP address for the interface. Click Renew to send a ne

Strany 212 - Chapter 9 Dashboard

Chapter 9 DashboardZyWALL USG 2000 User’s Guide215Number of Login UsersThis field displays the number of users currently logged in to the ZyWALL. Cli

Strany 213

Chapter 9 DashboardZyWALL USG 2000 User’s Guide2169.2.1 The CPU Usage ScreenUse this screen to look at a chart of the ZyWALL’s recent CPU usage. To a

Strany 214

Chapter 9 DashboardZyWALL USG 2000 User’s Guide217The following table describes the labels in this screen. 9.2.2 The Memory Usage ScreenUse this sc

Strany 215

Chapter 9 DashboardZyWALL USG 2000 User’s Guide2189.2.3 The Session Usage ScreenUse this screen to look at a chart of the ZyWALL’s recent traffic ses

Strany 216 - 9.2.1 The CPU Usage Screen

Chapter 9 DashboardZyWALL USG 2000 User’s Guide2199.2.4 The VPN Status ScreenUse this screen to look at the VPN tunnels that are currently establish

Strany 217

Table of ContentsZyWALL USG 2000 User’s Guide2233.1.2 What You Need to Know ...

Strany 218

Chapter 9 DashboardZyWALL USG 2000 User’s Guide220The following table describes the labels in this screen. 9.2.6 The Number of Login Users ScreenUse

Strany 219 - 9.2.5 The DHCP Table Screen

Chapter 9 DashboardZyWALL USG 2000 User’s Guide221The following table describes the labels in this screen. Table 27 Dashboard > Number of Login

Strany 220

Chapter 9 DashboardZyWALL USG 2000 User’s Guide222

Strany 221

ZyWALL USG 2000 User’s Guide223CHAPTER 10 Monitor10.1 OverviewUse the Monitor screens to check status and statistics information.10.1.1 What You C

Strany 222

Chapter 10 MonitorZyWALL USG 2000 User’s Guide224•Use the VPN Monitor > L2TP over IPSec screen (see Section 10.13 on page 249) to display and manag

Strany 223 - CHAPTER 10

Chapter 10 MonitorZyWALL USG 2000 User’s Guide225The following table describes the labels in this screen. Table 28 Monitor > System Status >

Strany 224

Chapter 10 MonitorZyWALL USG 2000 User’s Guide22610.2.1 The Port Statistics Graph Screen Use this screen to look at a line graph of packet statistics

Strany 225 - Chapter 10 Monitor

Chapter 10 MonitorZyWALL USG 2000 User’s Guide22710.3 Interface Status ScreenThis screen lists all of the ZyWALL’s interfaces and gives packet stati

Strany 226

Chapter 10 MonitorZyWALL USG 2000 User’s Guide228Each field is described in the following table. Table 30 Monitor > System Status > Interface

Strany 227 - 10.3 Interface Status Screen

Chapter 10 MonitorZyWALL USG 2000 User’s Guide229HA Status This field displays the status of the interface in the virtual router.Active - This interf

Strany 228 - Chapter 10 Monitor

Table of ContentsZyWALL USG 2000 User’s Guide2335.1.4 Before You Begin ...

Strany 229

Chapter 10 MonitorZyWALL USG 2000 User’s Guide23010.4 The Traffic Statistics ScreenClick Monitor > System Status > Traffic Statistics to displa

Strany 230

Chapter 10 MonitorZyWALL USG 2000 User’s Guide231You use the Traffic Statistics screen to tell the ZyWALL when to start and when to stop collecting i

Strany 231

Chapter 10 MonitorZyWALL USG 2000 User’s Guide232Interface Select the interface from which to collect information. You can collect information from Et

Strany 232

Chapter 10 MonitorZyWALL USG 2000 User’s Guide233The following table displays the maximum number of records shown in the report, the byte count limit

Strany 233

Chapter 10 MonitorZyWALL USG 2000 User’s Guide234• Number of bytes transmitted (so far)• Duration (so far)You can look at all the active sessions by u

Strany 234

Chapter 10 MonitorZyWALL USG 2000 User’s Guide235User This field displays when View is set to all sessions. Type the user whose sessions you want to

Strany 235

Chapter 10 MonitorZyWALL USG 2000 User’s Guide23610.6 The DDNS Status ScreenThe DDNS Status screen shows the status of the ZyWALL’s DDNS domain names

Strany 236 - 10.7 IP/MAC Binding Monitor

Chapter 10 MonitorZyWALL USG 2000 User’s Guide237session with the ZyWALL. Devices that have never established a session with the ZyWALL do not displa

Strany 237

Chapter 10 MonitorZyWALL USG 2000 User’s Guide23810.8 The Login Users Screen Use this screen to look at a list of the users currently logged into the

Strany 238 - 10.8 The Login Users Screen

Chapter 10 MonitorZyWALL USG 2000 User’s Guide23910.9 Cellular Status ScreenThis screen displays your 3G connection status. click Monitor > Syste

Strany 239 - 10.9 Cellular Status Screen

Table of ContentsZyWALL USG 2000 User’s Guide2438.7 Anti-Spam Technical Reference ...

Strany 240

Chapter 10 MonitorZyWALL USG 2000 User’s Guide240Status No device - no 3G device is connected to the ZyWALL.Device detected - displays when you connec

Strany 241

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24110.10 Application Patrol StatisticsThis screen displays a bandwidth usage graph and statistics for

Strany 242

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24210.10.2 Application Patrol Statistics: Bandwidth StatisticsThe middle of the Monitor > AppPatrol

Strany 243

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24310.10.3 Application Patrol Statistics: Protocol StatisticsThe bottom of the Monitor > AppPatrol

Strany 244 - Statistics by Rule

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24410.10.4 Application Patrol Statistics: Individual Protocol Statistics by RuleThe bottom of the Moni

Strany 245

Chapter 10 MonitorZyWALL USG 2000 User’s Guide245The following table describes the labels in this screen. 10.11 The IPSec Monitor Screen You can us

Strany 246

Chapter 10 MonitorZyWALL USG 2000 User’s Guide246screen appears. Click a column’s heading cell to sort the table entries by that column’s criteria. Cl

Strany 247

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24710.11.1 Regular Expressions in Searching IPSec SAsA question mark (?) lets a single character in th

Strany 248

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24810.12 The SSL Connection Monitor Screen The ZyWALL keeps track of the users who are currently logged

Strany 249

Chapter 10 MonitorZyWALL USG 2000 User’s Guide24910.13 L2TP over IPSec Session Monitor ScreenClick Monitor > VPN Monitor > L2TP over IPSec to

Strany 250

Table of ContentsZyWALL USG 2000 User’s Guide2542.1.1 What You Can Do in this Chapter ...

Strany 251

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25010.14 The Anti-Virus Statistics ScreenClick Monitor > Anti-X Statistics > Anti-Virus to displa

Strany 252

Chapter 10 MonitorZyWALL USG 2000 User’s Guide251The statistics display as follows when you display the top entries by source.Figure 232 Monitor &g

Strany 253

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25210.15 The IDP Statistics ScreenClick Monitor > Anti-X Statistics > IDP to display the followin

Strany 254

Chapter 10 MonitorZyWALL USG 2000 User’s Guide253The statistics display as follows when you display the top entries by source.Figure 235 Monitor &g

Strany 255

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25410.16 The Content Filter Statistics ScreenClick Monitor > Anti-X Statistics > Content Filter t

Strany 256

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25510.17 Content Filter Cache ScreenClick Monitor > Anti-X Statistics > Content Filter > Cach

Strany 257

Chapter 10 MonitorZyWALL USG 2000 User’s Guide256You can remove individual entries from the cache. When you do this, the ZyWALL queries the external c

Strany 258

Chapter 10 MonitorZyWALL USG 2000 User’s Guide257Category This field shows whether access to the web site’s URL was blocked or allowed.Click the colu

Strany 259

Chapter 10 MonitorZyWALL USG 2000 User’s Guide25810.18 The Anti-Spam Statistics ScreenClick Monitor > Anti-X Statistics > Anti-Spam to display

Strany 260

Chapter 10 MonitorZyWALL USG 2000 User’s Guide259Spam Mails This is the number of e-mails that the ZyWALL has determined to be spam.Spam Mails Detect

Strany 261 - 10.20 Log Screen

Table of ContentsZyWALL USG 2000 User’s Guide2646.1.3 Verifying a Certificate ...

Strany 262 - Table 50 Monitor > Log

Chapter 10 MonitorZyWALL USG 2000 User’s Guide26010.19 The Anti-Spam Status ScreenClick Monitor > Anti-X Statistics > Anti-Spam > Status to

Strany 263

Chapter 10 MonitorZyWALL USG 2000 User’s Guide26110.20 Log ScreenLog messages are stored in two separate logs, one for regular log messages and one

Strany 264

Chapter 10 MonitorZyWALL USG 2000 User’s Guide262The following table describes the labels in this screen. Table 50 Monitor > LogLABEL DESCRIPTIO

Strany 265 - CHAPTER 11

Chapter 10 MonitorZyWALL USG 2000 User’s Guide263The Web Configurator saves the filter settings if you leave the View Log screen and return to it lat

Strany 266 - Anti-Virus Engines

Chapter 10 MonitorZyWALL USG 2000 User’s Guide264

Strany 267 - 11.2 The Registration Screen

ZyWALL USG 2000 User’s Guide265CHAPTER 11 Registration11.1 OverviewUse the Configuration > Licensing > Registration screens to register your Z

Strany 268 - Chapter 11 Registration

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide266Subscription Services Available on the ZyWALLYou can have the ZyWALL use anti-virus, IDP/AppPatr

Strany 269 - 11.3 The Service Screen

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide26711.2 The Registration ScreenUse this screen to register your ZyWALL with myZyXEL.com and activ

Strany 270

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide268Confirm Password Enter the password again for confirmation.E-Mail Address Enter your e-mail addr

Strany 271 - CHAPTER 12

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide269Note: If the ZyWALL is registered already, this screen is read-only and indicates whether trial

Strany 272

Table of ContentsZyWALL USG 2000 User’s Guide2750.4 Console Port Speed ...

Strany 273

Chapter 11 RegistrationZyWALL USG 2000 User’s Guide270The following table describes the labels in this screen. Table 52 Configuration > Licensing

Strany 274

ZyWALL USG 2000 User’s Guide271CHAPTER 12 Signature Update12.1 OverviewThis chapter shows you how to update the ZyWALL’s signature packages.12.1.1

Strany 275

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide27212.2 The Antivirus Update ScreenClick Configuration > Licensing > Update > Anti-Vi

Strany 276 - Chapter 12 Signature Update

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide27312.3 The IDP/AppPatrol Update ScreenClick Configuration > Licensing > Update > ID

Strany 277 - CHAPTER 13

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide274signatures from myZyXEL.com (see the Registration screens). Use the Update IDP /AppPatrol sc

Strany 278 - Types of Interfaces

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide27512.4 The System Protect Update Screen Click Configuration > Licensing > Update >

Strany 279 - Characteristics

Chapter 12 Signature UpdateZyWALL USG 2000 User’s Guide276The following table describes the fields in this screen. Table 54 Configuration > Licen

Strany 280 - 13.2 Port Grouping

ZyWALL USG 2000 User’s Guide277CHAPTER 13 Interfaces13.1 Interface OverviewUse the Interface screens to configure the ZyWALL’s interfaces. You can a

Strany 281 - 13.2.2 Port Grouping Screen

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide27813.1.2 What You Need to Know Interface CharacteristicsInterfaces generally have the following cha

Strany 282 - 13.3 Ethernet Summary Screen

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide279characteristics. These characteristics are listed in the following table and discussed in more de

Strany 283 - LABEL DESCRIPTION

Table of ContentsZyWALL USG 2000 User’s Guide2851.1.1 What You Can Do In this Chapter ...

Strany 284 - 13.3.1 Ethernet Edit

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide280* - You cannot set up a PPP interface, virtual Ethernet interface or virtual VLAN interface if the

Strany 285

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide28113.2.1 Port Grouping OverviewUse port grouping to create port groups and to assign physical port

Strany 286 - Chapter 13 Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide282Each section in this screen is described below.13.3 Ethernet Summary ScreenThis screen lists ever

Strany 287

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide283Figure 249 Configuration > Network > Interface > Ethernet Each field is described

Strany 288

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide28413.3.1 Ethernet Edit The Ethernet Edit screen lets you configure IP address assignment, interface

Strany 289

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide285Figure 250 Configuration > Network > Interface > Ethernet > Edit

Strany 290

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide286This screen’s fields are described in the table below. Table 59 Configuration > Network

Strany 291 - 13.3.2 Object References

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide287Use Fixed IP AddressThis option appears when Interface Properties is External or General. Select

Strany 292 - 13.4 PPP Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide288Check Period Enter the number of seconds between connection check attempts.Check Timeout Enter the

Strany 293 - 13.4.1 PPP Interface Summary

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide289Pool Size Enter the number of IP addresses to allocate. This number must be at least one and is l

Strany 294

Table of ContentsZyWALL USG 2000 User’s Guide29Chapter 57Product Specifications...

Strany 295

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide290IP Address Enter the IP address to assign to a device with this entry’s MAC address.MAC Address En

Strany 296

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide29113.3.2 Object ReferencesWhen a configuration screen includes an Object References icon, select a

Strany 297

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide292Figure 251 Object References The following table describes labels that can appear in this scr

Strany 298

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide293Figure 252 Example: PPPoE/PPTP InterfacesPPPoE/PPTP interfaces are similar to other interfaces

Strany 299

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide294Figure 253 Configuration > Network > Interface > PPP Each field is described in the

Strany 300

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide29513.4.2 PPP Interface Add or Edit Note: You have to set up an ISP account before you create a PPP

Strany 301

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide296Figure 254 Configuration > Network > Interface > PPP > Add Each field is explaine

Strany 302

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide297Enable InterfaceSelect this to enable this interface. Clear this to disable this interface.Interf

Strany 303

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide298Interface ParametersEgress BandwidthEnter the maximum amount of traffic, in kilobits per second, t

Strany 304

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide29913.5 Cellular Configuration Screen (3G)3G (Third Generation) is a digital, packet-switched wirel

Strany 305

About This User's GuideZyWALL USG 2000 User’s Guide3About This User's GuideIntended AudienceThis manual is intended for people who want to

Strany 306

Table of ContentsZyWALL USG 2000 User’s Guide30

Strany 307

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide300If the signal strength of a 3G network is too low, the 3G card may switch to an available 2.5G or

Strany 308 - 13.6 VLAN Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide301Figure 255 Configuration > Network > Interface > Cellular The following table descri

Strany 309 - VLAN Interfaces Overview

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide302Figure 256 Configuration > Network > Interface > Cellular > Add

Strany 310 - 13.6.1 VLAN Summary Screen

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide303The following table describes the labels in this screen.Table 65 Configuration > Network >

Strany 311 - 13.6.2 VLAN Add/Edit

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide304Dial String Enter the dial string if your ISP provides a string, which would include the APN, to i

Strany 312

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide305Egress BandwidthEnter the maximum amount of traffic, in kilobits per second, the ZyWALL can send

Strany 313

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide306Get Automatically Select this option If your ISP did not assign you a fixed IP address. This is th

Strany 314

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide307Data Budget Select this and specify how much downstream and/or upstream data (in Mega bytes) can

Strany 315

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide30813.6 VLAN Interfaces A Virtual Local Area Network (VLAN) divides a physical network into multiple

Strany 316

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide309Each VLAN is a separate network with separate IP addresses, subnet masks, and gateways. Each VLAN

Strany 317

31PART IUser’s Guide

Strany 318 - 13.7 Bridge Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide310They restrict bandwidth and packet size. They can provide DHCP services, and they can verify the g

Strany 319 - Bridge Interface Overview

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide31113.6.2 VLAN Add/Edit This screen lets you configure IP address assignment, interface bandwidth p

Strany 320 - 13.7.1 Bridge Summary

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide312Figure 260 Configuration > Network > Interface > VLAN > Edit

Strany 321 - 13.7.2 Bridge Add/Edit

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide313Each field is explained in the following table. Table 67 Configuration > Network > Interf

Strany 322

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide314Metric Enter the priority of the gateway (if any) on this interface. The ZyWALL decides which gate

Strany 323

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide315DHCP Select what type of DHCP service the ZyWALL provides to the network. Choices are:None - the

Strany 324

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide316Lease time Specify how long each computer can use the information (especially the IP address) befo

Strany 325

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide317OSPF Setting See Section 16.3 on page 365 for more information about OSPF.Area Select the area in

Strany 326

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide31813.7 Bridge Interfaces This section introduces bridges and bridge interfaces and then explains th

Strany 327 - 13.8 Auxiliary Interface

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide319If computer B responds to computer A, bridge X records the source address 0B:0B:0B:0B:0B:0B and p

Strany 329 - 13.9 Virtual Interfaces

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide32013.7.1 Bridge SummaryThis screen lists every bridge interface and virtual interface created on to

Strany 330

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide32113.7.2 Bridge Add/Edit This screen lets you configure IP address assignment, interface bandwidth

Strany 331 - IP Address Assignment

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide322Figure 262 Configuration > Network > Interface > Bridge > Add

Strany 332 - Interface Parameters

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide323Each field is described in the table below.Table 72 Configuration > Network > Interface &

Strany 333 - DHCP Settings

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide324Gateway This field is enabled if you select Use Fixed IP Address.Enter the IP address of the gatew

Strany 334

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide325IP Pool Start AddressEnter the IP address from which the ZyWALL begins allocating IP addresses. I

Strany 335 - PPPoE/PPTP Overview

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide326Add Click this to create a new entry. Edit Select an entry and click this to be able to modify it.

Strany 336

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide32713.8 Auxiliary Interface This section introduces the auxiliary interface and then explains the s

Strany 337 - CHAPTER 14

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide328Figure 263 Configuration > Network > Interface > Auxiliary Each field is described in

Strany 338 - 14.1.2 What You Need to Know

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide32913.9 Virtual Interfaces Use virtual interfaces to tell the ZyWALL where to route packets. Virtua

Strany 339 - Least Load First

ZyWALL USG 2000 User’s Guide33CHAPTER 1 Introducing the ZyWALLThis chapter gives an overview of the ZyWALL. It explains the front panel ports, LEDs,

Strany 340 - Spillover

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide330cannot change the MTU. The virtual interface uses the same MTU that the underlying interface uses.

Strany 341 - Finding Out More

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide33113.10 Interface Technical ReferenceHere is more detailed information about interfaces on the ZyW

Strany 342

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide332For example, if the ZyWALL gets a packet with a destination address of 100.100.25.25, it routes th

Strany 343 - 14.3 Configuring a Trunk

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide333• Egress bandwidth sets the amount of traffic the ZyWALL sends out through the interface to the n

Strany 344 - Chapter 14 Trunks

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide334• IP address - If the DHCP client’s MAC address is in the ZyWALL’s static DHCP table, the interfac

Strany 345

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide335PPPoE/PPTP OverviewPoint-to-Point Protocol over Ethernet (PPPoE, RFC 2516) and Point-to-Point Tun

Strany 346

Chapter 13 InterfacesZyWALL USG 2000 User’s Guide336

Strany 347 - CHAPTER 15

ZyWALL USG 2000 User’s Guide337CHAPTER 14 Trunks14.1 OverviewUse trunks for WAN traffic load balancing to increase overall network throughput and r

Strany 348 - Static Routes

Chapter 14 TrunksZyWALL USG 2000 User’s Guide33814.1.2 What You Need to Know• Add WAN interfaces to trunks to have multiple connections share the tra

Strany 349 - DiffServ

Chapter 14 TrunksZyWALL USG 2000 User’s Guide3392 The ZyWALL is using active/active load balancing. So when LAN user A tries to access something on t

Strany 350 - 15.2 Policy Route Screen

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide34standard EIA rack using a rack-mounting kit. Make sure the rack will safely support the

Strany 351

Chapter 14 TrunksZyWALL USG 2000 User’s Guide340Since WAN 2 has a smaller load balancing index (meaning that it is less utilized than WAN 1), the ZyWA

Strany 352

Chapter 14 TrunksZyWALL USG 2000 User’s Guide341interface. This fully utilizes the bandwidth of the first interface to reduce Internet usage fees and

Strany 353

Chapter 14 TrunksZyWALL USG 2000 User’s Guide34214.2 The Trunk Summary ScreenClick Configuration > Network > Interface > Trunk to open the T

Strany 354

Chapter 14 TrunksZyWALL USG 2000 User’s Guide34314.3 Configuring a Trunk Click Configuration > Network > Interface > Trunk and then the Add

Strany 355

Chapter 14 TrunksZyWALL USG 2000 User’s Guide344Each field is described in the table below. Table 80 Configuration > Network > Interface >

Strany 356

Chapter 14 TrunksZyWALL USG 2000 User’s Guide34514.4 Trunk Technical ReferenceRound Robin Load Balancing AlgorithmRound Robin scheduling services qu

Strany 357 - 15.3 IP Static Route Screen

Chapter 14 TrunksZyWALL USG 2000 User’s Guide346

Strany 358

ZyWALL USG 2000 User’s Guide347CHAPTER 15 Policy and Static Routes15.1 Policy and Static Routes OverviewUse policy routes and static routes to overr

Strany 359 - NAT and SNAT

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide348•Use the Static Route screens (see Section 15.3 on page 357) to list and configure s

Strany 360 - Port Triggering

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide349Policy Routes Versus Static Routes• Policy routes are more flexible than static rou

Strany 361 - Maximize Bandwidth Usage

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide353 After attaching both mounting brackets, position the ZyWALL in the rack by lining up

Strany 362

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide350Finding Out More• See Section 6.5.6 on page 105 for related information on the polic

Strany 363 - CHAPTER 16

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide351The following table describes the labels in this screen. Table 81 Configuration

Strany 364 - 16.2 The RIP Screen

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide352DSCP Code This is the DSCP value of incoming packets to which this policy route appl

Strany 365 - 16.3 The OSPF Screen

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide35315.2.1 Policy Route Edit ScreenClick Configuration > Network > Routing to op

Strany 366 - OSPF Areas

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide354Incoming Select where the packets are coming from; any, an interface, a tunnel, an S

Strany 367 - OSPF Routers

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide355VPN Tunnel This field displays when you select VPN Tunnel in the Type field. Select

Strany 368 - Virtual Links

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide356Source Network Address TranslationSelect none to not use NAT for the route.Select ou

Strany 369 - OSPF Configuration

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide35715.3 IP Static Route ScreenClick Configuration > Network > Routing > Stat

Strany 370

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide358The following table describes the labels in this screen. 15.3.1 Static Route Add/Ed

Strany 371 - Chapter 16 Routing Protocols

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide35915.4 Policy Routing Technical ReferenceHere is more detailed information about som

Strany 372

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide361.3.1.1 1000Base-T PortsThe 1000Base-T auto-negotiating, auto-crossover Ethernet ports

Strany 373

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide360following twelve DSCP encodings from AF11 through AF43. The decimal equivalent is li

Strany 374

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide3613 Computer A and game server 1 are connected to each other until the connection is

Strany 375 - Authentication Types

Chapter 15 Policy and Static RoutesZyWALL USG 2000 User’s Guide362

Strany 376 - Chapter 16 Routing Protocols

ZyWALL USG 2000 User’s Guide363CHAPTER 16 Routing Protocols16.1 Routing Protocols OverviewRouting protocols give the ZyWALL routing information abou

Strany 377 - CHAPTER 17

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide36416.2 The RIP ScreenRIP (Routing Information Protocol, RFC 1058 and RFC 1389) allows a devi

Strany 378 - 17.1.2 What You Need to Know

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide365The following table describes the labels in this screen. 16.3 The OSPF ScreenOSPF (Open

Strany 379 - 17.2 The Zone Screen

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide366System (AS). OSPF offers some advantages over vector-space routing protocols like RIP.• OSP

Strany 380 - 17.3 Zone Edit

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide367Each type of area is illustrated in the following figure.Figure 279 OSPF: Types of Areas

Strany 381 - CHAPTER 18

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide368• An Autonomous System Boundary Router (ASBR) exchanges routing information with routers in

Strany 382 - 18.2 The DDNS Screen

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide369to logically connect the area to the backbone. This is illustrated in the following exampl

Strany 383 - Chapter 18 DDNS

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide371 Insert the transceiver into the slot with the exposed section of PCB board facing dow

Strany 384

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide370Click Configuration > Network > Routing > OSPF to open the following screen.Figure

Strany 385 - DDNS server

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide371Type Select how OSPF calculates the cost associated with routing information from static r

Strany 386

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide37216.3.2 OSPF Area Add/Edit Screen The OSPF Area Add/Edit screen allows you to create a new

Strany 387 - CHAPTER 19

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide37316.3.3 Virtual Link Add/Edit Screen The Virtual Link Add/Edit screen allows you to create

Strany 388 - 19.2 The NAT Screen

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide374372) has the Type set to Normal, a Virtual Link table displays. Click either the Add icon o

Strany 389 - Chapter 19 NAT

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide375Authentication TypesAuthentication is used to guarantee the integrity, but not the confide

Strany 390

Chapter 16 Routing ProtocolsZyWALL USG 2000 User’s Guide376

Strany 391

ZyWALL USG 2000 User’s Guide377CHAPTER 17 Zones17.1 Zones OverviewSet up zones to configure network security and network policies in the ZyWALL. A z

Strany 392 - Chapter 19 NAT

Chapter 17 ZonesZyWALL USG 2000 User’s Guide37817.1.2 What You Need to KnowEffects of Zones on Different Types of TrafficZones effectively divide tra

Strany 393 - 19.3 NAT Technical Reference

Chapter 17 ZonesZyWALL USG 2000 User’s Guide37917.2 The Zone ScreenThe Zone screen provides a summary of all zones. In addition, this screen allows

Strany 394

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide381 Press down on the top of the fiber-optic cable where it connects to the transceiver to

Strany 395

Chapter 17 ZonesZyWALL USG 2000 User’s Guide38017.3 Zone Edit The Zone Edit screen allows you to add or edit a zone. To access this screen, go to the

Strany 396

ZyWALL USG 2000 User’s Guide381CHAPTER 18 DDNS18.1 DDNS OverviewDynamic DNS (DDNS) services let you use a domain name with a dynamic IP address.18.1

Strany 397 - CHAPTER 20

Chapter 18 DDNSZyWALL USG 2000 User’s Guide382Note: Record your DDNS account’s user name, password, and domain name to use to configure the ZyWALL.Aft

Strany 398 - 20.1.2 What You Need to Know

Chapter 18 DDNSZyWALL USG 2000 User’s Guide383Primary Interface/IPThis field displays the interface to use for updating the IP address mapped to the

Strany 399

Chapter 18 DDNSZyWALL USG 2000 User’s Guide38418.2.1 The Dynamic DNS Add/Edit ScreenThe DDNS Add/Edit screen allows you to add a domain name to the Z

Strany 400

Chapter 18 DDNSZyWALL USG 2000 User’s Guide385Username Type the user name used when you registered your domain name. You can use up to 31 alphanumeri

Strany 401 - CHAPTER 21

Chapter 18 DDNSZyWALL USG 2000 User’s Guide386IP Address The options available in this field vary by DDNS provider.Interface -The ZyWALL uses the IP a

Strany 402 - 21.1.2 What You Need to Know

ZyWALL USG 2000 User’s Guide387CHAPTER 19 NAT19.1 NAT OverviewNAT (Network Address Translation - NAT, RFC 1631) is the translation of the IP address

Strany 403

Chapter 19 NATZyWALL USG 2000 User’s Guide38819.1.2 What You Need to KnowNAT is also known as virtual server, port forwarding, or port translation.Fi

Strany 404

Chapter 19 NATZyWALL USG 2000 User’s Guide389Remove To remove an entry, select it and click Remove. The ZyWALL confirms you want to remove it before

Strany 405 - 21.2 The ALG Screen

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide391.3.2 Maximizing ThroughputThe ZyWALL has one internal bus for ports P1-P7 and another

Strany 406 - Chapter 21 ALG

Chapter 19 NATZyWALL USG 2000 User’s Guide39019.2.1 The NAT Add/Edit ScreenThe NAT Add/Edit screen lets you create new NAT rules and edit existing on

Strany 407 - 21.3 ALG Technical Reference

Chapter 19 NATZyWALL USG 2000 User’s Guide391Classification Select what kind of NAT this rule is to perform.Virtual Server - This makes computers on

Strany 408

Chapter 19 NATZyWALL USG 2000 User’s Guide392Mapped IP Subnet/RangeThis field displays for Many 1:1 NAT. Select to which translated destination IP add

Strany 409 - CHAPTER 22

Chapter 19 NATZyWALL USG 2000 User’s Guide39319.3 NAT Technical ReferenceHere is more detailed information about NAT on the ZyWALL.NAT LoopbackSuppo

Strany 410 - 22.2 IP/MAC Binding Summary

Chapter 19 NATZyWALL USG 2000 User’s Guide394For example, a LAN user’s computer at IP address 192.168.1.89 queries a public DNS server to resolve the

Strany 411 - 22.2.1 IP/MAC Binding Edit

Chapter 19 NATZyWALL USG 2000 User’s Guide395SMTP server replied directly to the LAN user without the traffic going through NAT, the source would not

Strany 412 - 22.2.2 Static DHCP Edit

Chapter 19 NATZyWALL USG 2000 User’s Guide396

Strany 413

ZyWALL USG 2000 User’s Guide397CHAPTER 20 HTTP Redirect20.1 OverviewHTTP redirect forwards the client’s HTTP request (except HTTP traffic destined

Strany 414 - Chapter 22 IP/MAC Binding

Chapter 20 HTTP RedirectZyWALL USG 2000 User’s Guide39820.1.2 What You Need to KnowWeb Proxy ServerA proxy server helps client devices make indirect

Strany 415 - CHAPTER 23

Chapter 20 HTTP RedirectZyWALL USG 2000 User’s Guide399• a application patrol rule to allow HTTP traffic between ge4 and ge2.• a policy route to forw

Strany 416 - 23.1.2 What You Need to Know

About This User's GuideZyWALL USG 2000 User’s Guide4• Web Configurator Online HelpClick the help icon in any screen for help in configuring that

Strany 417

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide401.4 Management OverviewYou can use the following ways to manage the ZyWALL.SYS Off The

Strany 418

Chapter 20 HTTP RedirectZyWALL USG 2000 User’s Guide40020.2.1 The HTTP Redirect Edit ScreenClick Network > HTTP Redirect to open the HTTP Redirect

Strany 419

ZyWALL USG 2000 User’s Guide401CHAPTER 21 ALG21.1 ALG OverviewApplication Layer Gateway (ALG) allows the following applications to operate properly

Strany 420

Chapter 21 ALGZyWALL USG 2000 User’s Guide40221.1.2 What You Need to KnowApplication Layer Gateway (ALG), NAT and FirewallThe ZyWALL can function as

Strany 421

Chapter 21 ALGZyWALL USG 2000 User’s Guide403• There should be only one SIP server (total) on the ZyWALL’s private networks. Any other SIP servers mu

Strany 422

Chapter 21 ALGZyWALL USG 2000 User’s Guide404can receive incoming calls from the Internet, LAN IP addresses B and C can still make calls out to the In

Strany 423 - CHAPTER 24

Chapter 21 ALGZyWALL USG 2000 User’s Guide405• See Section 21.3 on page 407 for ALG background/technical information.21.1.3 Before You BeginYou must

Strany 424 - 24.1.2 What You Need to Know

Chapter 21 ALGZyWALL USG 2000 User’s Guide406The following table describes the labels in this screen. Table 101 Configuration > Network > AL

Strany 425 - Firewall and VPN Traffic

Chapter 21 ALGZyWALL USG 2000 User’s Guide40721.3 ALG Technical ReferenceHere is more detailed information about the Application Layer Gateway.ALGSo

Strany 426 - Session Limits

Chapter 21 ALGZyWALL USG 2000 User’s Guide408connections to the second (passive) interface when the active interface’s connection goes down. When the

Strany 427 - 2 Any Any Any Any Any Allow

ZyWALL USG 2000 User’s Guide409CHAPTER 22 IP/MAC Binding22.1 IP/MAC Binding OverviewIP address to MAC address binding helps ensure that only the in

Strany 428

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide41Web ConfiguratorThe Web Configurator allows easy ZyWALL setup and management using an I

Strany 429

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide41022.1.2 What You Need to KnowDHCPIP/MAC address bindings are based on the ZyWALL’s dynamic and

Strany 430

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide411The following table describes the labels in this screen. 22.2.1 IP/MAC Binding EditClick Co

Strany 431 - 24.2 The Firewall Screen

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide412The following table describes the labels in this screen. 22.2.2 Static DHCP EditClick Config

Strany 432

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide413screen. Use this screen to configure an interface’s IP to MAC address binding settings. Figur

Strany 433 - Chapter 24 Firewall

Chapter 22 IP/MAC BindingZyWALL USG 2000 User’s Guide414The following table describes the labels in this screen. Table 105 Configuration > Netwo

Strany 434 - Chapter 24 Firewall

ZyWALL USG 2000 User’s Guide415CHAPTER 23 Authentication Policy23.1 Overview Use authentication policies to control who can access the network. You

Strany 435

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide41623.1.2 What You Need to KnowAuthentication Policy and VPNAuthentication policies are a

Strany 436

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide417Click Configuration > Auth. Policy to display the screen. Figure 310 Configuratio

Strany 437

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide418The following table gives an overview of the objects you can configure. Table 106 Co

Strany 438

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide41923.2.1 Creating/Editing an Authentication PolicyClick Configuration > Auth. Policy

Strany 439

Chapter 1 Introducing the ZyWALLZyWALL USG 2000 User’s Guide42Always use Maintenance > Shutdown > Shutdown or the shutdown command before you tu

Strany 440

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide420Figure 312 Configuration > Auth. Policy > Add The following table gives an ove

Strany 441 - CHAPTER 25

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide421Schedule Select a schedule that defines when the policy applies. Otherwise, select non

Strany 442 - 25.1.2 What You Need to Know

Chapter 23 Authentication PolicyZyWALL USG 2000 User’s Guide422

Strany 443 - Application Scenarios

ZyWALL USG 2000 User’s Guide423CHAPTER 24 Firewall24.1 OverviewUse the firewall to block or allow services that use static port numbers. Use applica

Strany 444 - 25.1.3 Before You Begin

Chapter 24 FirewallZyWALL USG 2000 User’s Guide42424.1.2 What You Need to KnowStateful InspectionThe ZyWALL has a stateful inspection firewall. The Z

Strany 445

Chapter 24 FirewallZyWALL USG 2000 User’s Guide425• The ZyWALL drops most packets from the DMZ zone to the ZyWALL itself, except for DNS and NetBIOS

Strany 446

Chapter 24 FirewallZyWALL USG 2000 User’s Guide426traffic blocking to allow or block VPN traffic transmitting between the VPN tunnel and other interfa

Strany 447 - Chapter 25 IPSec VPN

Chapter 24 FirewallZyWALL USG 2000 User’s Guide427the firewall rule to always be in effect. The following figure shows the results of this rule.Figur

Strany 448 - Chapter 25 IPSec VPN

Chapter 24 FirewallZyWALL USG 2000 User’s Guide428Now you configure a LAN to WAN firewall rule that allows IRC traffic from the IP address of the CEO’

Strany 449

Chapter 24 FirewallZyWALL USG 2000 User’s Guide429• The first row allows any LAN computer to access the IRC service on the WAN by logging into the Zy

Strany 450

ZyWALL USG 2000 User’s Guide43CHAPTER 2 Features and ApplicationsThis chapter introduces the main features and applications of the ZyWALL.2.1 Featur

Strany 451

Chapter 24 FirewallZyWALL USG 2000 User’s Guide4305 The screen for configuring a service object opens. Configure it as follows and click OK.Figure 318

Strany 452

Chapter 24 FirewallZyWALL USG 2000 User’s Guide4319 The firewall rule appears in the firewall rule summary.Figure 320 Firewall Example: Doom Rule i

Strany 453 - Manual Key

Chapter 24 FirewallZyWALL USG 2000 User’s Guide4324 The ZyWALL then sends it to the computer on the LAN in Subnet 1. Figure 321 Using Virtual Interf

Strany 454 - Key (continued)

Chapter 24 FirewallZyWALL USG 2000 User’s Guide433• The ordering of your rules is very important as rules are applied in sequence.Figure 322 Config

Strany 455

Chapter 24 FirewallZyWALL USG 2000 User’s Guide434From Zone / To ZoneThis is the direction of travel of packets. Select from which zone the packets co

Strany 456 - 25.3 The VPN Gateway Screen

Chapter 24 FirewallZyWALL USG 2000 User’s Guide43524.2.2 The Firewall Add/Edit ScreenIn the Firewall screen, click the Edit or Add icon to display t

Strany 457

Chapter 24 FirewallZyWALL USG 2000 User’s Guide43624.3 The Session Limit ScreenClick Configuration > Firewall > Session Limit to display the Fi

Strany 458

Chapter 24 FirewallZyWALL USG 2000 User’s Guide437individual limits for specific users, addresses, or both. The individual limit takes priority if yo

Strany 459

Chapter 24 FirewallZyWALL USG 2000 User’s Guide43824.3.1 The Session Limit Add/Edit ScreenClick Configuration > Firewall > Session Limit and th

Strany 460

Chapter 24 FirewallZyWALL USG 2000 User’s Guide439User Select a user name or user group to which to apply the rule. The rule is activated only when t

Strany 461

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide44FirewallThe ZyWALL’s firewall is a stateful inspection firewall. The ZyWALL restricts

Strany 462

Chapter 24 FirewallZyWALL USG 2000 User’s Guide440

Strany 463

ZyWALL USG 2000 User’s Guide441CHAPTER 25 IPSec VPN25.1 IPSec VPN OverviewA virtual private network (VPN) provides secure communications between sit

Strany 464

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide442•Use the VPN Gateway screens (see Section 25.2.1 on page 446) to manage the ZyWALL’s VPN gateways.

Strany 465 - 25.4 VPN Concentrator

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide443Application ScenariosThe ZyWALL’s application scenarios make it easier to configure your VPN conne

Strany 466

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide444• See Section 25.5 on page 469 for IPSec VPN background information.• See Section 5.3 on page 83 fo

Strany 467

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide445SA). Click a column’s heading cell to sort the table entries by that column’s criteria. Click the

Strany 468

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide44625.2.1 The VPN Connection Add/Edit (IKE) ScreenThe VPN Connection Add/Edit Gateway screen allows y

Strany 469 - Section 25.2.1 on page 446

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide447Figure 329 Configuration > VPN > IPSec VPN > VPN Connection > Edit (IKE)

Strany 470 - IKE SA Overview

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide448Each field is described in the following table. Table 118 Configuration > VPN > IPSec VPN

Strany 471 - Diffie-Hellman key exchange

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide449PolicyLocal Policy Select the address corresponding to the local network. Use Create new Object if

Strany 472 - Authentication

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide45Anti-Virus ScannerWith the anti-virus packet scanner, your ZyWALL scans files transm

Strany 473 - Additional Topics for IKE SA

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide450Encryption This field is applicable when the Active Protocol is ESP. Select which key size and encr

Strany 474 - VPN, NAT, and NAT Traversal

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide451Check Method Select how the ZyWALL checks the connection. The peer must be configured to respond t

Strany 475 - Certificates

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide452Inbound TrafficSource NAT This translation hides the source address of computers in the remote netw

Strany 476 - IPSec SA Overview

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide45325.2.2 The VPN Connection Add/Edit Manual Key Screen The VPN Connection Add/Edit Manual Key scree

Strany 477

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide454Secure Gateway AddressType the IP address of the remote IPSec router in the IPSec SA. SPI Type a un

Strany 478 - IPSec SA using Manual Keys

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide455Encryption Key This field is applicable when you select an Encryption Algorithm. Enter the encrypt

Strany 479

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide45625.3 The VPN Gateway ScreenThe VPN Gateway summary screen displays the IPSec VPN gateway policies

Strany 480

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide45725.3.1 The VPN Gateway Add/Edit ScreenThe VPN Gateway Add/Edit screen allows you to create a new

Strany 481 - CHAPTER 26

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide458Figure 332 Configuration > VPN > IPSec VPN > VPN Gateway > Edit

Strany 482 - SSL Access Policy Objects

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide459Each field is described in the following table. Table 121 Configuration > VPN > IPSec VPN

Strany 483

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide462.2.1 VPN ConnectivitySet up VPN tunnels with other companies, branch offices, telec

Strany 484

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide460Pre-Shared KeySelect this to have the ZyWALL and remote IPSec router use a pre-shared key (password

Strany 485 - Chapter 26 SSL VPN

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide461Content This field is read-only if the ZyWALL and remote IPSec router use certificates to identify

Strany 486 - Chapter 26 SSL VPN

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide462Content This field is disabled if the Peer ID Type is Any. Type the identity of the remote IPSec ro

Strany 487

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide463Negotiation ModeSelect the negotiation mode to use to negotiate the IKE SA. Choices areMain - this

Strany 488

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide464NAT Traversal Select this if any of these conditions are satisfied.• This IKE SA might be used to n

Strany 489

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide46525.4 VPN Concentrator A VPN concentrator combines several IPSec VPN connections into one secure n

Strany 490

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide466• Branch office A’s ZyWALL uses one VPN rule to access both the headquarters (HQ) network and branc

Strany 491 - Figure 349 Login Screen

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide467VPN Connection (VPN Tunnel 1): • Local Policy: 192.168.1.0/255.255.255.0• Remote Policy:192.168.11

Strany 492

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide468• The local IP addresses configured in the VPN rules should not overlap.• The concentrator must hav

Strany 493 - CHAPTER 27

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide469Concentrator summary screen (see Section 25.4 on page 465), and click either the Add icon or an Ed

Strany 494 - 27.2 Remote User Login

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide47You do not have to install additional client software on the remote user computers f

Strany 495 - Figure 354 Login Screen

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide470IKE SA OverviewThe IKE SA provides a secure connection between the ZyWALL and remote IPSec router.I

Strany 496

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide471The ZyWALL sends one or more proposals to the remote IPSec router. (In some devices, you can only

Strany 497

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide472the longer it takes to encrypt and decrypt information. For example, DH2 keys (1024 bits) are more

Strany 498

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide473Router identity consists of ID type and content. The ID type can be domain name, IP address, or e-

Strany 499 - # DESCRIPTION

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide474Negotiation ModeThere are two negotiation modes--main mode and aggressive mode. Main mode provides

Strany 500 - 27.4 Bookmarking the ZyWALL

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide475feature, router X and router Y can establish a VPN tunnel as long as the active protocol is ESP. (

Strany 501

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide476• The local and peer ID type and content come from the certificates.Note: You must set up the certi

Strany 502 - Chapter 27 SSL User Screens

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide477These modes are illustrated below.In tunnel mode, the ZyWALL uses the active protocol to encapsula

Strany 503 - CHAPTER 28

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide478Additional Topics for IPSec SAThis section provides more information about IPSec SA in your ZyWALL.

Strany 504

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide479Each kind of translation is explained below. The following example is used to help explain each on

Strany 505 - CHAPTER 29

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide482.2.3 User-Aware Access ControlSet up security policies that restrict access to sens

Strany 506 - Figure 366 File Sharing

Chapter 25 IPSec VPNZyWALL USG 2000 User’s Guide480• SNAT - the translated source address; a different IP address (range of addresses) to hide the ori

Strany 507

ZyWALL USG 2000 User’s Guide481CHAPTER 26 SSL VPN26.1 OverviewUse SSL VPN to allow users to use a web browser for secure remote user login (the remo

Strany 508 - 29.3.1 Downloading a File

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide482You do not have to install additional client software on the remote user computers for access. Figur

Strany 509 - 29.4 Creating a New Folder

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide483changes through the SSL policies that use the object(s). When you delete an SSL policy, the objects

Strany 510

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide48426.2 The SSL Access Privilege ScreenClick VPN > SSL VPN to open the Access Privilege screen. This

Strany 511 - 29.7 Uploading a File

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide485Apply Click Apply to save the settings. Reset Click Reset to discard all changes. Table 127 VPN &g

Strany 512

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide48626.2.1 The SSL Access Policy Add/Edit Screen To create a new or edit an existing SSL access policy,

Strany 513 - CHAPTER 30

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide487The following table describes the labels in this screen. Table 128 VPN > SSL VPN > Access Pr

Strany 514 - 30.2 Statistics

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide48826.3 The SSL Global Setting ScreenClick VPN > SSL VPN and click the Global Setting tab to display

Strany 515 - 30.3 View Log

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide489on your network for full tunnel mode access, enter access messages or upload a custom logo to be dis

Strany 516 - 30.5 Stop the Connection

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide492.2.5 Device HASet up an additional ZyWALL as a backup gateway to ensure the defaul

Strany 517 - CHAPTER 31

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide49026.3.1 How to Upload a Custom LogoFollow the steps below to upload a custom logo to display on the r

Strany 518 - Policy Route

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide491The following shows an example logo on the remote user screen. Figure 348 Example Logo Graphic Dis

Strany 519 - 31.2 L2TP VPN Screen

Chapter 26 SSL VPNZyWALL USG 2000 User’s Guide4922 SSL VPN connection starts. This may take several minutes depending on your network connection. Once

Strany 520 - Chapter 31 L2TP VPN

ZyWALL USG 2000 User’s Guide493CHAPTER 27 SSL User Screens27.1 OverviewThis chapter introduces the remote user SSL VPN screens. The following figure

Strany 521 - CHAPTER 32

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide494System RequirementsHere are the browser and computer system requirements for remote user acc

Strany 522

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide4951 Open a web browser and enter the web site address or IP address of the ZyWALL. For exampl

Strany 523 - DiffServ and DSCP Marking

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide4965 Your computer starts establishing a secure connection to the ZyWALL after a successful log

Strany 524

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide4977 The ZyWALL tries to install the SecuExtender client. You may need to click a pop-up to ge

Strany 525 - Bandwidth Management Priority

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide49810 If a screen like the following displays, click Continue Anyway to finish installing the S

Strany 526 - Priority Effect

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide49927.3 The SSL VPN User ScreensThis section describes the main elements in the remote user s

Strany 527

About This User's GuideZyWALL USG 2000 User’s Guide5See http://www.zyxel.com/web/contact_us.php for contact information. Please have the follow

Strany 528

Chapter 2 Features and ApplicationsZyWALL USG 2000 User’s Guide50

Strany 529

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide50027.4 Bookmarking the ZyWALLYou can create a bookmark of the ZyWALL by clicking the Add to F

Strany 530

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide5013 An information screen displays to indicate that the SSL VPN connection is about to termin

Strany 531

Chapter 27 SSL User ScreensZyWALL USG 2000 User’s Guide502

Strany 532

ZyWALL USG 2000 User’s Guide503CHAPTER 28 SSL User Application Screens28.1 SSL User Application Screens OverviewUse the Application screen to access

Strany 533

Chapter 28 SSL User Application ScreensZyWALL USG 2000 User’s Guide504

Strany 534 - Table 139 Application Edit

ZyWALL USG 2000 User’s Guide505CHAPTER 29 SSL User File Sharing29.1 OverviewThe File Sharing screen lets you access files on a file server through t

Strany 535

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide50629.2 The Main File Sharing Screen The first File Sharing screen displays the name(s) o

Strany 536 - Chapter 32 Application Patrol

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide5073 If an access user name and password are required, a screen displays as shown in the

Strany 537

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide5084 A list of files/folders displays. Click on a file to open it in a separate browser wi

Strany 538

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide50929.3.2 Saving a FileAfter you have opened a file in a web browser, you can save a cop

Strany 539

ZyWALL USG 2000 User’s Guide51CHAPTER 3 Web ConfiguratorThe ZyWALL Web Configurator allows easy ZyWALL setup and management using an Internet browser

Strany 540

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide51029.5 Renaming a File or FolderTo rename a file or folder, click the Rename icon next t

Strany 541

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide51129.7 Uploading a FileFollow the steps below to upload a file to the file server. 1 Lo

Strany 542

Chapter 29 SSL User File SharingZyWALL USG 2000 User’s Guide512

Strany 543

ZyWALL USG 2000 User’s Guide513CHAPTER 30 ZyWALL SecuExtenderThe ZyWALL automatically loads the ZyWALL SecuExtender client program to your computer a

Strany 544

Chapter 30 ZyWALL SecuExtenderZyWALL USG 2000 User’s Guide51430.2 StatisticsRight-click the ZyWALL SecuExtender icon in the system tray and select St

Strany 545

Chapter 30 ZyWALL SecuExtenderZyWALL USG 2000 User’s Guide51530.3 View LogIf you have problems with the ZyWALL SecuExtender, customer support may re

Strany 546

Chapter 30 ZyWALL SecuExtenderZyWALL USG 2000 User’s Guide516connected but not send any traffic through it until you right-click the icon and resume t

Strany 547 - CHAPTER 33

ZyWALL USG 2000 User’s Guide517CHAPTER 31 L2TP VPN31.1 OverviewL2TP VPN lets remote users use the L2TP and IPSec client software included with their

Strany 548 - ZyWALL Anti-Virus Scanner

Chapter 31 L2TP VPNZyWALL USG 2000 User’s Guide518• Use transport mode.• Not be a manual key VPN connection. •Use Pre-Shared Key authentication.• Use

Strany 549

Chapter 31 L2TP VPNZyWALL USG 2000 User’s Guide519Finding Out More• See Section 6.5.17 on page 111 for related information on these screens.• See Cha

Strany 550 - 33.1.3 Before You Begin

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide522 Open your web browser, and go to http://192.168.1.1. By default, the ZyWALL automatically ro

Strany 551 - Chapter 33 Anti-Virus

Chapter 31 L2TP VPNZyWALL USG 2000 User’s Guide520VPN Connection Select the IPSec VPN connection the ZyWALL uses for L2TP VPN. All of the configured V

Strany 552 - Chapter 33 Anti-Virus

ZyWALL USG 2000 User’s Guide521CHAPTER 32 Application Patrol32.1 OverviewApplication patrol provides a convenient way to manage the use of various a

Strany 553

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide52232.1.2 What You Need to KnowIf you want to use a service, make sure both the firewall an

Strany 554

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide523numbers for SIP traffic. Likewise, configuring the SIP ALG to use custom port numbers for

Strany 555 - 33.3 Anti-Virus Black List

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide524• The outbound traffic flows from the connection initiator to the connection responder. •

Strany 556 - White List) > Add

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide525Bandwidth Management Priority• The ZyWALL gives bandwidth to higher-priority traffic firs

Strany 557 - 33.5 Anti-Virus White List

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide526Configured Rate EffectIn the following table the configured rates total less than the avai

Strany 558 - 33.6 Signature Searching

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide527regardless of its priority, server B gets almost no bandwidth with this configuration.

Strany 559

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide528• FTP traffic from the LAN to the DMZ can use more bandwidth since the interfaces support

Strany 560

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide529• Enable maximize bandwidth usage so the SIP traffic can borrow unused bandwidth.Figure 3

Strany 561 - Types of Anti-Virus Scanner

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide535 The screen above appears every time you log in using the default user name and default pass

Strany 562

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide53032.1.3.5 FTP WAN to DMZ Bandwidth Management Example• ADSL supports more downstream than

Strany 563 - CHAPTER 34

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide53132.2 Application Patrol General ScreenUse this screen to enable and disable application

Strany 564 - 34.1.3 Before You Begin

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide53232.3 Application Patrol ApplicationsUse the application patrol Common, Instant Messenger,

Strany 565 - 34.2 The IDP General Screen

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide533Click Configuration > App Patrol > Common to open the following screen.Figure 391

Strany 566 - Chapter 34 IDP

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide534Streaming screen and click an application’s Edit icon. The screen displayed here is for th

Strany 567

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide535# This field is a sequential value, and it is not associated with a specific entry.Note:

Strany 568 - 34.3.1 Base Profiles

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide536Access This field displays what the ZyWALL does with packets for this application that mat

Strany 569

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide53732.3.2 The Application Patrol Policy Edit Screen The Application Policy Edit screen allo

Strany 570 - 34.5 Creating New Profiles

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide538Schedule Select a schedule that defines when the policy applies or select Create Object to

Strany 571 - Chapter 34 IDP

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide539Action Block For some applications, you can select individual uses of the application tha

Strany 572

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide543.3.1 Title BarThe title bar provides some icons in the upper right corner.Figure 22 Title

Strany 573

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide54032.4 The Other Applications ScreenSometimes, the ZyWALL cannot identify the application.

Strany 574 - 34.6.2 Policy Types

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide541Click AppPatrol > Other to open the Other (applications) screen.Figure 394 AppPatrol

Strany 575 - 34.6.3 IDP Service Groups

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide542Destination This is the destination address or address group for whom this policy applies.

Strany 576

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide54332.4.1 The Other Applications Add/Edit ScreenThe Other Configuration Add/Edit screen all

Strany 577

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide544Schedule Select a schedule that defines when the policy applies or select Create Object to

Strany 578

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide545Inbound kbpsType how much inbound bandwidth, in kilobits per second, this policy allows t

Strany 579 - 34.6.5 Query Example

Chapter 32 Application PatrolZyWALL USG 2000 User’s Guide546OK Click OK to save your changes back to the ZyWALL.Cancel Click Cancel to exit this scree

Strany 580 - •Actions: Any

ZyWALL USG 2000 User’s Guide547CHAPTER 33 Anti-Virus33.1 OverviewUse the ZyWALL’s anti-virus feature to protect your connected network from virus/sp

Strany 581 - 34.7.1 IP Packet Header

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide54833.1.2 What You Need to Know Anti-Virus EnginesSubscribe to signature files for ZyXEL’s anti-viru

Strany 582

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide5492 If the packets are not session connection setup packets (such as SYN, ACK and FIN), the ZyWALL

Strany 583

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide55hide the navigation panel menus or drag it to resize them. The following sections introduce t

Strany 584

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide55033.1.3 Before You Begin• Before using anti-virus, see Chapter 11 on page 265 for how to register

Strany 585

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide551The following table describes the labels in this screen.Table 143 Configuration > Anti-X >

Strany 586

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide552Protocol These are the protocols of traffic to scan for viruses.FTP applies to traffic using the T

Strany 587

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide55333.2.1 Anti-Virus Policy Add or Edit ScreenClick the Add or Edit icon in the Configuration >

Strany 588

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide554Actions When MatchedDestroy infected fileWhen you select this check box, if a virus pattern is mat

Strany 589

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide55533.3 Anti-Virus Black ListClick Configuration > Anti-X > Anti-Virus > Black/White List

Strany 590

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide556The following table describes the labels in this screen.33.4 Anti-Virus Black List or White List

Strany 591 - 34.8.2.2 Analyze Packets

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide557The following table describes the labels in this screen.33.5 Anti-Virus White ListClick Configur

Strany 592

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide558column’s heading cell to sort the table entries by that column’s criteria. Click the heading cell

Strany 593

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide559If Internet Explorer opens a warning screen about a script making Internet Explorer run slowly an

Strany 594 - 34.9 IDP Technical Reference

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide563.3.2.3 Configuration MenuUse the configuration menu screens to configure the ZyWALL’s featur

Strany 595 - Snort Signatures

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide560The following table describes the labels in this screen. Table 148 Configuration > Anti-X &g

Strany 596

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide56133.7 Anti-Virus Technical ReferenceTypes of Computer Viruses The following table describes some

Strany 597 - CHAPTER 35

Chapter 33 Anti-VirusZyWALL USG 2000 User’s Guide562A host-based anti-virus (HAV) scanner is often software installed on computers and/or servers in t

Strany 598 - 35.1.4 Before You Begin

ZyWALL USG 2000 User’s Guide563CHAPTER 34 IDP34.1 OverviewThis chapter introduces packet inspection IDP (Intrusion, Detection and Prevention), IDP

Strany 599 - 35.2 The ADP General Screen

Chapter 34 IDPZyWALL USG 2000 User’s Guide564IDP ProfilesAn IDP profile is a set of related IDP signatures that you can activate as a set and configur

Strany 600

Chapter 34 IDPZyWALL USG 2000 User’s Guide56534.2 The IDP General ScreenClick Configuration > Anti-X > IDP > General to open this screen. U

Strany 601 - 35.3.1 Base Profiles

Chapter 34 IDPZyWALL USG 2000 User’s Guide566Remove Select an entry and click this to delete it. Activate To turn on an entry, select it and click Act

Strany 602

Chapter 34 IDPZyWALL USG 2000 User’s Guide56734.3 Introducing IDP Profiles An IDP profile is a set of packet inspection signatures. Packet inspecti

Strany 603 - Chapter 35 ADP

Chapter 34 IDPZyWALL USG 2000 User’s Guide56834.3.1 Base ProfilesThe ZyWALL comes with several base profiles. You use base profiles to create new pro

Strany 604 - Chapter 35 ADP

Chapter 34 IDPZyWALL USG 2000 User’s Guide56934.4 The Profile Summary ScreenSelect Anti-X > IDP > Profile. Use this screen to:• Add a new prof

Strany 605

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide57Interface Port Grouping Configure physical port groups.Ethernet Manage Ethernet interfaces an

Strany 606

Chapter 34 IDPZyWALL USG 2000 User’s Guide57034.5 Creating New Profiles You may want to create a new profile if not all signatures in a base profile

Strany 607

Chapter 34 IDPZyWALL USG 2000 User’s Guide57134.6 Profiles: Packet Inspection Select Configuration > Anti-X > IDP > Profile and then add a

Strany 608

Chapter 34 IDPZyWALL USG 2000 User’s Guide572The following table describes the fields in this screen. Table 153 Configuration > Anti-X > IDP

Strany 609 - 35.4 ADP Technical Reference

Chapter 34 IDPZyWALL USG 2000 User’s Guide573Action To edit what action the ZyWALL takes when a packet matches a signature, select the signature and

Strany 610 - Filtered Port Scans

Chapter 34 IDPZyWALL USG 2000 User’s Guide57434.6.2 Policy TypesThis section describes IDP policy types, also known as attack types, as categorized i

Strany 611 - TCP SYN Flood Attack

Chapter 34 IDPZyWALL USG 2000 User’s Guide57534.6.3 IDP Service GroupsAn IDP service group is a set of related packet inspection signatures.Scan A s

Strany 612 - LAND Attack

Chapter 34 IDPZyWALL USG 2000 User’s Guide576The following figure shows the WEB_PHP service group that contains signatures related to attacks on web s

Strany 613 - UDP Flood Attack

Chapter 34 IDPZyWALL USG 2000 User’s Guide577signatures by criteria such as name, ID, severity, attack type, vulnerable attack platforms, service cat

Strany 614

Chapter 34 IDPZyWALL USG 2000 User’s Guide578Severity Search for signatures by severity level(s). Hold down the [Ctrl] key if you want to make multipl

Strany 615

Chapter 34 IDPZyWALL USG 2000 User’s Guide57934.6.5 Query ExampleThis example shows a search with these criteria:• Severity: severe and high• Attack

Strany 616

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide58L2TP VPN L2TP VPN Configure L2TP Over IPSec VPN settings.AppPatrol General Enable or disable t

Strany 617 - CHAPTER 36

Chapter 34 IDPZyWALL USG 2000 User’s Guide580•Actions: AnyFigure 409 Query Example Search CriteriaFigure 410 Query Example Search Results

Strany 618 - Keyword Blocking URL Checking

Chapter 34 IDPZyWALL USG 2000 User’s Guide58134.7 Introducing IDP Custom Signatures Create custom signatures for new attacks or attacks peculiar to

Strany 619 - 36.1.3 Before You Begin

Chapter 34 IDPZyWALL USG 2000 User’s Guide58234.8 Configuring Custom SignaturesSelect Configuration > Anti-X > IDP > Custom Signatures. The

Strany 620

Chapter 34 IDPZyWALL USG 2000 User’s Guide583Note: The ZyWALL checks all signatures and continues searching even after a match is found. If two or mo

Strany 621 - Chapter 36 Content Filtering

Chapter 34 IDPZyWALL USG 2000 User’s Guide58434.8.1 Creating or Editing a Custom Signature Click the Add icon to create a new signature or click the

Strany 622 - Chapter 36 Content Filtering

Chapter 34 IDPZyWALL USG 2000 User’s Guide585Try to write signatures that target a vulnerability, for example a certain type of traffic on certain op

Strany 623

Chapter 34 IDPZyWALL USG 2000 User’s Guide586The following table describes the fields in this screen. Table 159 Configuration > Anti-X > IDP &

Strany 624

Chapter 34 IDPZyWALL USG 2000 User’s Guide587Fragmentation A fragmentation flag identifies whether the IP datagram should be fragmented, not fragment

Strany 625

Chapter 34 IDPZyWALL USG 2000 User’s Guide588Flow If selected, the signature only applies to certain directions of the traffic flow and only to client

Strany 626

Chapter 34 IDPZyWALL USG 2000 User’s Guide589Payload Size This field may be used to check for abnormally sized packets or for detecting buffer overfl

Strany 627

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide59User/Group User Create and manage users.Group Create and manage groups of users.Setting Manag

Strany 628

Chapter 34 IDPZyWALL USG 2000 User’s Guide59034.8.2 Custom Signature ExampleBefore creating a custom signature, you must first clearly understand the

Strany 629

Chapter 34 IDPZyWALL USG 2000 User’s Guide59134.8.2.2 Analyze PacketsUse the packet capture screen (see Section 53.3 on page 860) and a packet analy

Strany 630

Chapter 34 IDPZyWALL USG 2000 User’s Guide592The final custom signature should look like as shown in the following figure. Figure 415 Example Custom

Strany 631

Chapter 34 IDPZyWALL USG 2000 User’s Guide593You can activate the signature, configure what action to take when a packet matches it and if it should

Strany 632

Chapter 34 IDPZyWALL USG 2000 User’s Guide594destination port is the service port (53 for DNS in this case) that the attack tries to exploit.Figure 41

Strany 633

Chapter 34 IDPZyWALL USG 2000 User’s Guide595Network IntrusionsNetwork-based intrusions have the goal of bringing down a network or networks by attac

Strany 634

Chapter 34 IDPZyWALL USG 2000 User’s Guide596Note: Not all Snort functionality is supported in the ZyWALL.Same IP sameipTransport ProtocolTransport Pr

Strany 635

ZyWALL USG 2000 User’s Guide597CHAPTER 35 ADP35.1 OverviewThis chapter introduces ADP (Anomaly Detection and Prevention), anomaly profiles and appl

Strany 636

Chapter 35 ADPZyWALL USG 2000 User’s Guide598Protocol AnomaliesProtocol anomalies are packets that do not comply with the relevant RFC (Request For Co

Strany 637

Chapter 35 ADPZyWALL USG 2000 User’s Guide59935.2 The ADP General ScreenClick Configuration > Anti-X > ADP > General. Use this screen to tu

Strany 638

Document ConventionsZyWALL USG 2000 User’s Guide6Document ConventionsWarnings and NotesThese are how warnings and notes are shown in this User’s Guide

Strany 639

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide603.3.2.4 Maintenance MenuUse the maintenance menu screens to manage configuration and firmware

Strany 640

Chapter 35 ADPZyWALL USG 2000 User’s Guide60035.3 The Profile Summary ScreenUse this screen to:• Create a new profile using an existing base profile•

Strany 641 - CHAPTER 37

Chapter 35 ADPZyWALL USG 2000 User’s Guide60135.3.1 Base ProfilesThe ZyWALL comes with base profiles. You use base profiles to create new profiles.

Strany 642

Chapter 35 ADPZyWALL USG 2000 User’s Guide602The following table describes the fields in this screen. 35.3.3 Creating New ADP Profiles You may want

Strany 643

Chapter 35 ADPZyWALL USG 2000 User’s Guide603belonging to this profile, make sure you have clicked OK or Save to save the changes before selecting th

Strany 644

Chapter 35 ADPZyWALL USG 2000 User’s Guide604The following table describes the fields in this screen. Table 164 Configuration > ADP > Profile

Strany 645

Chapter 35 ADPZyWALL USG 2000 User’s Guide60535.3.5 Protocol Anomaly Profiles Protocol anomaly is the third screen in an ADP profile. Protocol anoma

Strany 646

Chapter 35 ADPZyWALL USG 2000 User’s Guide606Figure 422 Profiles: Protocol Anomaly

Strany 647

Chapter 35 ADPZyWALL USG 2000 User’s Guide607The following table describes the fields in this screen. Table 165 Configuration > ADP > Profil

Strany 648

Chapter 35 ADPZyWALL USG 2000 User’s Guide608Action To edit what action the ZyWALL takes when a packet matches a signature, select the signature and u

Strany 649 - CHAPTER 38

Chapter 35 ADPZyWALL USG 2000 User’s Guide60935.4 ADP Technical ReferenceThis section is divided into traffic anomaly background information and pro

Strany 650 - E-mail Headers

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide613.3.3.1 Warning MessagesWarning messages, such as those resulting from misconfiguration, dis

Strany 651 - 38.2 Before You Begin

Chapter 35 ADPZyWALL USG 2000 User’s Guide610Decoy Port ScansDecoy port scans are scans where the attacker has spoofed the source address. These are s

Strany 652

Chapter 35 ADPZyWALL USG 2000 User’s Guide611Flood DetectionFlood attacks saturate a network with useless data, use up all available bandwidth, and t

Strany 653

Chapter 35 ADPZyWALL USG 2000 User’s Guide612the initiator responds with an ACK (acknowledgment). After this handshake, a connection is established. F

Strany 654

Chapter 35 ADPZyWALL USG 2000 User’s Guide613UDP Flood AttackUDP is a connection-less protocol and it does not require any connection setup procedure

Strany 655

Chapter 35 ADPZyWALL USG 2000 User’s Guide614DOUBLE-ENCODING ATTACKThis rule is IIS specific. IIS does two passes through the request URI, doing decod

Strany 656

Chapter 35 ADPZyWALL USG 2000 User’s Guide615WEBROOT-DIRECTORY-TRAVERSAL ATTACKThis is when a directory traversal traverses past the web server root

Strany 657

Chapter 35 ADPZyWALL USG 2000 User’s Guide616TRUNCATED-HEADER ATTACKThis is when an ICMP packet is sent which has an ICMP datagram length of less than

Strany 658

ZyWALL USG 2000 User’s Guide617CHAPTER 36 Content Filtering36.1 OverviewUse the content filtering feature to control access to specific web sites o

Strany 659

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide618Content Filtering ProfilesA content filtering profile conveniently stores your custom setti

Strany 660 - 38.6 The DNSBL Screen

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide619Since the ZyWALL checks the URL’s domain name (or IP address) and file path separately, it

Strany 661 - Chapter 38 Anti-Spam

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide62settings reference the object. The following example shows which configuration settings refere

Strany 662

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide620your list of content filter policies, create a denial of access message or specify a redire

Strany 663

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide621Move To change an entry’s position in the numbered list, select it and click Move to displ

Strany 664

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide62236.3 Content Filter Policy Add or Edit ScreenClick Configuration > Anti-X > Content

Strany 665

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide623filter policy. A content filter policy defines which content filter profile should be appl

Strany 666 - Chapter 38 Anti-Spam

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide62436.4 Content Filter Profile Screen Click Configuration > Anti-X > Content Filter >

Strany 667 - CHAPTER 39

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide625See Chapter 37 on page 641 for how to view content filtering reports. Figure 429 Configu

Strany 668 - 39.1.3 Before You Begin

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide626The following table describes the labels in this screen. Table 170 Configuration > Ant

Strany 669 - 39.2 Device HA General

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide627Action for Unsafe Web PagesSelect Pass to allow users to access web pages that match the u

Strany 670 - Cluster ID

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide628Action When Category Server Is UnavailableSelect Pass to allow users to access any requeste

Strany 671

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide629Spyware/Malware Sources This category includes pages which distribute spyware and other ma

Strany 672

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide633.3.3.4 CLI MessagesClick CLI to look at the CLI commands sent by the Web Configurator. Thes

Strany 673 - Chapter 39 Device HA

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide630Nudity This category includes pages containing nude or seminude depictions of the human bod

Strany 674 - Chapter 39 Device HA

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide631Arts/Entertainment This category includes pages that promote and provide information about

Strany 675 - Monitored Interface

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide632Government/Legal This category includes pages sponsored by or which provide information on

Strany 676

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide633Religion This category includes pages that promote and provide information on conventional

Strany 677 - 39.5 The Legacy Mode Screen

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide634Sports/Recreation/HobbiesThis category includes pages that promote or provide information a

Strany 678

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide635Alcohol Sites that promote, offer for sale, glorify, review, or in any way advocate the u

Strany 679

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide63636.5.1 Content Filter Blocked and Warning MessagesThese are the content filtering warning

Strany 680

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide63736.6 Content Filter Customization Screen Click Configuration > Anti-X > Content Fil

Strany 681

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide638Allow Web traffic for trusted web sites onlyWhen this box is selected, the ZyWALL blocks We

Strany 682

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide63936.7 Content Filter Technical ReferenceThis section provides content filtering background

Strany 683

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide64• Sort in ascending alphabetical order• Sort in descending (reverse) alphabetical order• Selec

Strany 684

Chapter 36 Content FilteringZyWALL USG 2000 User’s Guide640External Content Filter Server Lookup ProcedureThe content filter lookup process is describ

Strany 685

ZyWALL USG 2000 User’s Guide641CHAPTER 37 Content Filter Reports37.1 OverviewYou can view content filtering reports after you have activated the cat

Strany 686 - 192.168.10.112

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6422 Fill in your myZyXEL.com account information and click Login.Figure 433 myZyXEL.co

Strany 687 - Synchronization

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6433 A welcome screen displays. Click your ZyWALL’s model name and/or MAC address under

Strany 688

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6444 In the Service Management screen click Content Filter in the Service Name column to

Strany 689 - CHAPTER 40

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6456 Select items under Global Reports to view the corresponding reports.Figure 437 Co

Strany 690 - Ext-User Accounts

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6468 A chart and/or list of requested web site categories display in the lower half of th

Strany 691 - User Awareness

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide6479 You can click a category in the Categories report or click URLs in the Report Home

Strany 692 - 40.2 User Summary Screen

Chapter 37 Content Filter ReportsZyWALL USG 2000 User’s Guide648

Strany 693 - • sync • uucp • zyxel

ZyWALL USG 2000 User’s Guide649CHAPTER 38 Anti-Spam38.1 OverviewThe anti-spam feature can mark or discard spam (unsolicited commercial or junk e-mai

Strany 694 - Chapter 40 User/Group

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide654 Select a column heading and drag and drop it to change the column order. A green check mark

Strany 695

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide650Black ListConfigure black list entries to identify spam. The black list entries have the ZyWALL cla

Strany 696 - 40.3.1 Group Add/Edit Screen

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide651E-mail Header Buffer SizeThe ZyWALL has a 5 K buffer for an individual e-mail header. If an e-mail

Strany 697 - 40.4 Setting Screen

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide652spam policies. You can also select the action the ZyWALL takes when the mail sessions threshold is

Strany 698

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65338.3.1 The Anti-Spam Policy Add or Edit ScreenClick the Add or Edit icon in the Configuration >

Strany 699 - Chapter 40 User/Group

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide654check, which e-mail protocols to scan, the scanning options, and the action to take on spam traffic

Strany 700

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65538.4 The Anti-Spam Black List ScreenClick Configuration > Anti-X > Anti-Spam > Black /Wh

Strany 701

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide656specific subject text. Click a column’s heading cell to sort the table entries by that column’s cri

Strany 702

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65738.4.1 The Anti-Spam Black or White List Add/Edit ScreenIn the anti-spam Black List or White List

Strany 703

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65838.4.2 Regular Expressions in Black or White List EntriesThe following applies for a black or whit

Strany 704

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide65938.5 The Anti-Spam White List ScreenClick Configuration > Anti-X > Anti-Spam > Black/Whi

Strany 705 - CHAPTER 41

Chapter 3 Web ConfiguratorZyWALL USG 2000 User’s Guide66Here are descriptions for the most common table icons.3.3.4.3 Working with ListsWhen a list o

Strany 706

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide66038.6 The DNSBL Screen Click Configuration > Anti-X > Anti-Spam > DNSBL to display the ant

Strany 707

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide661The following table describes the labels in this screen. Table 177 Configuration > Anti-X >

Strany 708

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide66238.7 Anti-Spam Technical ReferenceHere is more detailed anti-spam information.DNSBL• The ZyWALL ch

Strany 709

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide663Here is an example of an e-mail classified as spam based on DNSBL replies. Figure 446 DNSBL Spam

Strany 710 - Chapter 41 Addresses

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide664Here is an example of an e-mail classified as legitimate based on DNSBL replies. Figure 447 DNSBL

Strany 711 - CHAPTER 42

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide665If the ZyWALL receives conflicting DNSBL replies for an e-mail routing IP address, the ZyWALL clas

Strany 712

Chapter 38 Anti-SpamZyWALL USG 2000 User’s Guide666

Strany 713

ZyWALL USG 2000 User’s Guide667CHAPTER 39 Device HA39.1 OverviewDevice HA lets a backup ZyWALL (B) automatically take over if the master ZyWALL (A)

Strany 714

Chapter 39 Device HAZyWALL USG 2000 User’s Guide668• Legacy mode allows for more complex relationships between the master and backup ZyWALLs, such as

Strany 715

Chapter 39 Device HAZyWALL USG 2000 User’s Guide66939.2 Device HA GeneralThe Configuration > Device HA General screen lets you enable or disable

Strany 716

ZyWALL USG 2000 User’s Guide67CHAPTER 4 Installation Setup Wizard4.1 Installation Setup Wizard Screens If you log into the Web Configurator when the

Strany 717 - CHAPTER 43

Chapter 39 Device HAZyWALL USG 2000 User’s Guide67039.3 The Active-Passive Mode Screen Virtual RouterThe master and backup ZyWALL form a single ‘virt

Strany 718

Chapter 39 Device HAZyWALL USG 2000 User’s Guide671B form a virtual router that uses cluster ID 1. ZyWALLs C and D form a virtual router that uses cl

Strany 719

Chapter 39 Device HAZyWALL USG 2000 User’s Guide672192.168.1.5 and ZyWALL B has its own LAN management IP address of 192.168.1.6. These do not change

Strany 720 - Chapter 43 Schedules

Chapter 39 Device HAZyWALL USG 2000 User’s Guide673The following table describes the labels in this screen. See Section 39.4 on page 675 for more inf

Strany 721

Chapter 39 Device HAZyWALL USG 2000 User’s Guide674Monitored Interface SummaryThis table shows the status of the device HA settings and status of the

Strany 722

Chapter 39 Device HAZyWALL USG 2000 User’s Guide67539.4 Configuring an Active-Passive Mode Monitored InterfaceThe Device HA Active-Passive Mode Moni

Strany 723 - CHAPTER 44

Chapter 39 Device HAZyWALL USG 2000 User’s Guide676A bridge interface’s device HA settings are not retained if you delete the bridge interface.Figure

Strany 724 - 44.1.3 ASAS

Chapter 39 Device HAZyWALL USG 2000 User’s Guide67739.5 The Legacy Mode ScreenVirtual Router Redundancy Protocol (VRRP)Legacy mode device HA uses Vi

Strany 725 - 44.1.5 What You Need To Know

Chapter 39 Device HAZyWALL USG 2000 User’s Guide67839.6 Configuring the Legacy Mode ScreenThe Device HA Legacy Mode screen lets you configure general

Strany 726 - Bind DN

Chapter 39 Device HAZyWALL USG 2000 User’s Guide679Remove Select an entry and click this to delete it. Activate To turn on an entry, select it and cl

Strany 727

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide684.1.1 Internet Access Setup - WAN Interface Use this screen to set how many WAN int

Strany 728

Chapter 39 Device HAZyWALL USG 2000 User’s Guide680Use the VRRP Group Add/Edit screen to add or edit VRRP groups.• You can only use interfaces that ha

Strany 729 - 44.3 RADIUS Server Summary

Chapter 39 Device HAZyWALL USG 2000 User’s Guide681The following table describes the labels in this screen. Table 182 Configuration > Device H

Strany 730

Chapter 39 Device HAZyWALL USG 2000 User’s Guide68239.7 Device HA Technical ReferenceActive-Passive Mode Device HA with Bridge InterfacesHere are two

Strany 731

Chapter 39 Device HAZyWALL USG 2000 User’s Guide6831 Make sure the bridge interfaces of the master ZyWALL (A) and the backup ZyWALL (B) are not conne

Strany 732 - Chapter 44 AAA Server

Chapter 39 Device HAZyWALL USG 2000 User’s Guide6844 Connect the ZyWALLs.Second Option for Connecting the Bridge Interfaces on Two ZyWALLsAnother opti

Strany 733 - CHAPTER 45

Chapter 39 Device HAZyWALL USG 2000 User’s Guide6852 Configure a corresponding disabled bridge interface on the backup ZyWALL. Then set the bridge in

Strany 734

Chapter 39 Device HAZyWALL USG 2000 User’s Guide686Legacy Mode ZyWALL VRRP ApplicationIn VRRP, a virtual router represents a number of ZyWALLs associa

Strany 735

Chapter 39 Device HAZyWALL USG 2000 User’s Guide687If ZyWALL A becomes available again, ZyWALL A preempts ZyWALL B and becomes the master again (the

Strany 736

Chapter 39 Device HAZyWALL USG 2000 User’s Guide688

Strany 737

ZyWALL USG 2000 User’s Guide689CHAPTER 40 User/Group40.1 OverviewThis chapter describes how to set up user accounts, user groups, and user settings

Strany 738

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide69Note: Enter the Internet access information exactly as given to you by your ISP.Figu

Strany 739 - CHAPTER 46

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide690Note: The default admin account is always authenticated locally, regardless of the authentication

Strany 740 - Self-signed Certificates

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide691See Setting up User Attributes in an External Server on page 703 for a list of attributes and how

Strany 741 - Certificate File Formats

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide69240.2 User Summary ScreenThe User screen provides a summary of all user accounts. To access this s

Strany 742

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide693•- [dashes]The first character must be alphabetical (A-Z a-z), an underscore (_), or a dash (-).

Strany 743

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide694The following table describes the labels in this screen. Table 185 Configuration > User/Grou

Strany 744 - Chapter 46 Certificates

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide69540.3 User Group Summary ScreenUser groups consist of access users and other user groups. You can

Strany 745 - Chapter 46 Certificates

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide69640.3.1 Group Add/Edit ScreenThe Group Add/Edit screen allows you to create a new user group or ed

Strany 746 - characters

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide69740.4 Setting Screen The Setting screen controls default settings, login settings, lockout settin

Strany 747

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide698To access this screen, login to the Web Configurator, and click Configuration > Object > Use

Strany 748

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide699User Type These are the kinds of user account the ZyWALL supports.• admin - this user can look at

Strany 749

Document ConventionsZyWALL USG 2000 User’s Guide7Icons Used in FiguresFigures in this User’s Guide may use the following generic icons. The ZyWALL ic

Strany 750

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide704.1.3 Internet Access: PPPoENote: Enter the Internet access information exactly as g

Strany 751

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide70040.4.1 Default User Authentication Timeout Settings Edit ScreensThe Default Authentication Timeou

Strany 752

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide701To access this screen, go to the Configuration > Object > User/Group > Setting screen (s

Strany 753

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide70240.4.2 User Aware Login ExampleAccess users cannot use the Web Configurator to browse the configu

Strany 754

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide70340.5 User /Group Technical ReferenceThis section provides some information on users who use an e

Strany 755

Chapter 40 User/GroupZyWALL USG 2000 User’s Guide704

Strany 756

ZyWALL USG 2000 User’s Guide705CHAPTER 41 Addresses41.1 OverviewAddress objects can represent a single IP address or a range of IP addresses. Addre

Strany 757

Chapter 41 AddressesZyWALL USG 2000 User’s Guide706• RANGE - a range address is defined by a Starting IP Address and an Ending IP Address.• SUBNET - a

Strany 758

Chapter 41 AddressesZyWALL USG 2000 User’s Guide70741.2.1 Address Add/Edit ScreenThe Configuration > Address Add/Edit screen allows you to create

Strany 759

Chapter 41 AddressesZyWALL USG 2000 User’s Guide70841.3 Address Group Summary ScreenThe Address Group screen provides a summary of all address groups

Strany 760

Chapter 41 AddressesZyWALL USG 2000 User’s Guide70941.3.1 Address Group Add/Edit ScreenThe Address Group Add/Edit screen allows you to create a new

Strany 761 - CHAPTER 47

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide714.1.3.2 WAN IP Address Assignments • WAN Interface: This is the name of the interfa

Strany 762 - 47.2.1 ISP Account Edit

Chapter 41 AddressesZyWALL USG 2000 User’s Guide710

Strany 763 - Chapter 47 ISP Accounts

ZyWALL USG 2000 User’s Guide711CHAPTER 42 Services42.1 OverviewUse service objects to define TCP applications, UDP applications, and ICMP messages.

Strany 764 - Chapter 47 ISP Accounts

Chapter 42 ServicesZyWALL USG 2000 User’s Guide712Both TCP and UDP use ports to identify the source and destination. Each port is a 16-bit number. Som

Strany 765 - CHAPTER 48

Chapter 42 ServicesZyWALL USG 2000 User’s Guide713entries by that column’s criteria. Click the heading cell again to reverse the sort order.Figure 47

Strany 766 - Weblinks

Chapter 42 ServicesZyWALL USG 2000 User’s Guide71442.2.1 The Service Add/Edit ScreenThe Service Add/Edit screen allows you to create a new service or

Strany 767

Chapter 42 ServicesZyWALL USG 2000 User’s Guide715To access this screen, log in to the Web Configurator, and click Configuration > Object > Ser

Strany 768

Chapter 42 ServicesZyWALL USG 2000 User’s Guide71642.3.1 The Service Group Add/Edit ScreenThe Service Group Add/Edit screen allows you to create a ne

Strany 769 - Chapter 48 SSL Application

ZyWALL USG 2000 User’s Guide717CHAPTER 43 Schedules43.1 OverviewUse schedules to set up one-time and recurring schedules for policy routes, firewall

Strany 770

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide718Finding Out More• See Section 6.6 on page 114 for related information on these screens.• See Sectio

Strany 771

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide71943.2.1 The One-Time Schedule Add/Edit ScreenThe One-Time Schedule Add/Edit screen allows you to d

Strany 772 - Chapter 48 SSL Application

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide72• CHAP/PAP - Your ZyWALL accepts either CHAP or PAP when requested by the remote node

Strany 773 - CHAPTER 49

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide72043.2.2 The Recurring Schedule Add/Edit ScreenThe Recurring Schedule Add/Edit screen allows you to

Strany 774 - Requirements

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide721(see Section 43.2 on page 718), and click either the Add icon or an Edit icon in the Recurring sec

Strany 775

Chapter 43 SchedulesZyWALL USG 2000 User’s Guide722

Strany 776 - Chapter 49 Endpoint Security

ZyWALL USG 2000 User’s Guide723CHAPTER 44 AAA Server44.1 Overview You can use a AAA (Authentication, Authorization, Accounting) server to provide a

Strany 777 - Chapter 49 Endpoint Security

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide72444.1.2 RADIUS Server RADIUS (Remote Authentication Dial-In User Service) authentication is a popu

Strany 778

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide725•Use the Configuration > Object > AAA Server > RADIUS screen (Section 44.3 on page 729)

Strany 779

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide726organizational boundaries. The following figure shows a basic directory structure branching from c

Strany 780

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide727• See Section 7.7 on page 142 for an example of how to use a RADIUS server to authenticate user a

Strany 781

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide728following screen. Use this screen to create a new AD or LDAP entry or edit an existing one. Figure

Strany 782

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide72944.3 RADIUS Server SummaryUse the RADIUS screen to manage the list of RADIUS servers the ZyWALL

Strany 783 - CHAPTER 50

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide734.1.6 Internet Access Setup - Second WAN InterfaceIf you selected I have two ISPs,

Strany 784 - 50.2 Host Name

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide730Click Configuration > Object > AAA Server > RADIUS to display the RADIUS screen. Figure 4

Strany 785 - 50.3 Date and Time

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide73144.3.1 Adding a RADIUS Server Click Configuration > Object > AAA Server > RADIUS to dis

Strany 786 - Chapter 50 System

Chapter 44 AAA ServerZyWALL USG 2000 User’s Guide732Timeout Specify the timeout period (between 1 and 300 seconds) before the ZyWALL disconnects from

Strany 787

ZyWALL USG 2000 User’s Guide733CHAPTER 45 Authentication Method45.1 Overview Authentication method objects set how the ZyWALL authenticates HTTP/HTT

Strany 788

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide7343 Select Server Mode and select an authentication method object from the drop-down list

Strany 789 - 50.5 DNS Overview

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide73545.2.1 Creating an Authentication Method Object Follow the steps below to create an a

Strany 790

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide7367 Click OK to save the settings or click Cancel to discard all changes and return to th

Strany 791 - Chapter 50 System

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide737Add icon Click Add to add a new entry. Click Edit to edit the settings of an entry. Cl

Strany 792

Chapter 45 Authentication MethodZyWALL USG 2000 User’s Guide738

Strany 793 - 50.5.4 PTR Record

ZyWALL USG 2000 User’s Guide739CHAPTER 46 Certificates46.1 OverviewThe ZyWALL can use certificates (also called digital IDs) to authenticate users.

Strany 794

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide74Note: If you have not already done so, you can register your ZyWALL with myZyXEL.com

Strany 795 - 50.5.8 MX Record

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide7402 Tim keeps the private key and makes the public key openly available. This means that anyone wh

Strany 796 - 50.5.9 Adding a MX Record

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide741Factory Default CertificateThe ZyWALL generates its own unique self-signed certificate when you

Strany 797 - 50.6 WWW Overview

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide7422 Make sure that the certificate has a “.cer” or “.crt” file name extension.Figure 490 Remote

Strany 798 - 50.6.3 HTTPS

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide74346.2 The My Certificates Screen Click Configuration > Object > Certificate > My Certi

Strany 799

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide74446.2.1 The My Certificates Add ScreenClick Configuration > Object > Certificate > My C

Strany 800

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide745ZyWALL create a self-signed certificate, enroll a certificate with a certification authority or

Strany 801

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide746The following table describes the labels in this screen. Table 210 Configuration > Object &

Strany 802

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide747Create a certification request and save it locally for later manual enrollmentSelect this to ha

Strany 803 - 50.6.5 Service Control Rules

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide748If you configured the My Certificate Create screen to have the ZyWALL enroll a certificate and t

Strany 804

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide74946.2.2 The My Certificates Edit ScreenClick Configuration > Object > Certificate > My

Strany 805

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide75• Select existing myZyXEL.com account if you already have an account at myZyXEL.com

Strany 806

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide750The following table describes the labels in this screen. Table 211 Configuration > Object

Strany 807 - 50.6.7 HTTPS Example

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide751Key Algorithm This field displays the type of algorithm that was used to generate the certifica

Strany 808

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide75246.2.3 The My Certificates Import Screen Click Configuration > Object > Certificate >

Strany 809 - 50.6.7.4 Login Screen

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide75346.3 The Trusted Certificates Screen Click Configuration > Object > Certificate > T

Strany 810

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide75446.3.1 The Trusted Certificates Edit Screen Click Configuration > Object > Certificate &g

Strany 811

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide755authority’s list of revoked certificates before trusting a certificate issued by the certificat

Strany 812

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide756The following table describes the labels in this screen. Table 214 Configuration > Object

Strany 813

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide757Type This field displays general information about the certificate. CA-signed means that a Cert

Strany 814 - 50.7 SSH

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide75846.3.2 The Trusted Certificates Import Screen Click Configuration > Object > Certificate

Strany 815 - 50.7.1 How SSH Works

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide759The following table describes the labels in this screen. 46.4 Certificates Technical Reference

Strany 816 - 50.7.4 Configuring SSH

Chapter 4 Installation Setup WizardZyWALL USG 2000 User’s Guide76

Strany 817

Chapter 46 CertificatesZyWALL USG 2000 User’s Guide760

Strany 818

ZyWALL USG 2000 User’s Guide761CHAPTER 47 ISP Accounts47.1 OverviewUse ISP accounts to manage Internet Service Provider (ISP) account information fo

Strany 819 - 50.8 Telnet

Chapter 47 ISP AccountsZyWALL USG 2000 User’s Guide762The following table describes the labels in this screen. See the ISP Account Edit section below

Strany 820 - 50.8.1 Configuring Telnet

Chapter 47 ISP AccountsZyWALL USG 2000 User’s Guide763The following table describes the labels in this screen. Table 217 Configuration > Object

Strany 821 - 50.9 FTP

Chapter 47 ISP AccountsZyWALL USG 2000 User’s Guide764Compression Select On button to turn on stac compression, and select Off to turn off stac compre

Strany 822

ZyWALL USG 2000 User’s Guide765CHAPTER 48 SSL Application48.1 OverviewYou use SSL application objects in SSL VPN. Configure an SSL application objec

Strany 823 - 50.10 SNMP

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide766Remote Desktop ConnectionsUse SSL VPN to allow remote users to manage LAN computers. Dependin

Strany 824

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide7672 Click the Add button and select Web Application in the Type field. In the Server Type fiel

Strany 825 - 50.10.3 Configuring SNMP

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide768The following table describes the labels in this screen. 48.2.1 Creating/Editing a Web-base

Strany 826

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide769The following table describes the labels in this screen. Table 219 Configuration > Obj

Strany 827 - 50.11 Dial-in Management

ZyWALL USG 2000 User’s Guide77CHAPTER 5 Quick Setup5.1 Quick Setup OverviewThe Web Configurator's quick setup wizards help you configure Intern

Strany 828 - Response Strings

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide77048.2.2 Creating/Editing a File Sharing SSL Application ObjectYou can specify the name of a f

Strany 829 - 50.12 Vantage CNM

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide771The following table describes the labels in this screen. Table 220 Configuration > Obj

Strany 830

Chapter 48 SSL ApplicationZyWALL USG 2000 User’s Guide772

Strany 831 - Note: HTTPS is recommended

ZyWALL USG 2000 User’s Guide773CHAPTER 49 Endpoint Security49.1 Overview Use Endpoint Security (EPS), also known as endpoint control, to make sure u

Strany 832 - 50.13 Language Screen

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide77449.1.1 What You Can Do in this ChapterUse the Configuration > Object > Endpoint Secu

Strany 833 - CHAPTER 51

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide77549.2 Endpoint Security ScreenThe Endpoint Security screen displays the endpoint security

Strany 834 - Chapter 51 Log and Report

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide776Apply Click this button to save your changes to the ZyWALL. Reset Click this button to retu

Strany 835 - 51.3 Log Setting Screens

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide77749.3 Endpoint Security Add/EditClick Configuration > Object > Endpoint Security and

Strany 836 - 51.3.1 Log Setting Summary

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide778Figure 508 Configuration > Object > Endpoint Security > Add

Strany 837

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide779The following table gives an overview of the objects you can configure. Table 222 Confi

Strany 838

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide785.2 WAN Interface Quick SetupClick WAN Interface in the main Quick Setup screen to open the WAN In

Strany 839 - Chapter 51 Log and Report

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide780Checking Item - Personal FirewallIf you selected Windows as the operating system, you can s

Strany 840

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide781Checking Item - File InformationIf you selected Windows or Linux as the operating system,

Strany 841

Chapter 49 Endpoint SecurityZyWALL USG 2000 User’s Guide782

Strany 842

ZyWALL USG 2000 User’s Guide783CHAPTER 50 System50.1 OverviewUse the system screens to configure general ZyWALL settings. 50.1.1 What You Can Do

Strany 843

Chapter 50 SystemZyWALL USG 2000 User’s Guide784• Connect an external serial modem to the AUX port to provide a management connection in case the ZyWA

Strany 844

Chapter 50 SystemZyWALL USG 2000 User’s Guide78550.3 Date and Time For effective scheduling and logging, the ZyWALL system time must be accurate. Th

Strany 845

Chapter 50 SystemZyWALL USG 2000 User’s Guide786Manual Select this radio button to enter the time and date manually. If you configure a new time and d

Strany 846

Chapter 50 SystemZyWALL USG 2000 User’s Guide78750.3.1 Pre-defined NTP Time Servers ListWhen you turn on the ZyWALL for the first time, the date and

Strany 847 - CHAPTER 52

Chapter 50 SystemZyWALL USG 2000 User’s Guide78850.3.2 Time Server SynchronizationClick the Synchronize Now button to get the time and date from the

Strany 848

Chapter 50 SystemZyWALL USG 2000 User’s Guide7895 Under Time and Date Setup, enter a Time Server Address (Table 225 on page 787).6 Click Apply.50.4

Strany 849

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide79Otherwise, choose PPPoE or PPTP for a dial-up connection according to the information from your IS

Strany 850

Chapter 50 SystemZyWALL USG 2000 User’s Guide79050.5.1 DNS Server Address AssignmentThe ZyWALL can get the DNS server addresses in the following ways

Strany 851 - Chapter 52 File Manager

Chapter 50 SystemZyWALL USG 2000 User’s Guide791The following table describes the labels in this screen. Table 227 Configuration > System >

Strany 852 - Chapter 52 File Manager

Chapter 50 SystemZyWALL USG 2000 User’s Guide792DNS Server This is the IP address of a DNS server. This field displays N/A if you have the ZyWALL get

Strany 853

Chapter 50 SystemZyWALL USG 2000 User’s Guide79350.5.3 Address Record An address record contains the mapping of a Fully-Qualified Domain Name (FQDN)

Strany 854

Chapter 50 SystemZyWALL USG 2000 User’s Guide794The following table describes the labels in this screen. 50.5.6 Domain Zone Forwarder A domain zone

Strany 855

Chapter 50 SystemZyWALL USG 2000 User’s Guide795The following table describes the labels in this screen. 50.5.8 MX Record A MX (Mail eXchange) recor

Strany 856

Chapter 50 SystemZyWALL USG 2000 User’s Guide79650.5.9 Adding a MX Record Click the Add icon in the MX Record table to add a MX record.Figure 516 C

Strany 857

Chapter 50 SystemZyWALL USG 2000 User’s Guide797The following table describes the labels in this screen. 50.6 WWW OverviewThe following figure show

Strany 858

Chapter 50 SystemZyWALL USG 2000 User’s Guide798• See To-ZyWALL Rules on page 424 for more on To-ZyWALL firewall rules.• See Section 7.9 on page 147 f

Strany 859 - CHAPTER 53

Chapter 50 SystemZyWALL USG 2000 User’s Guide799It relies upon certificates, public keys, and private keys (see Chapter 46 on page 739 for more infor

Strany 860

Safety WarningsZyWALL USG 2000 User’s Guide8Safety Warnings• Do NOT use this product near water, for example, in a wet basement or near a swimming poo

Strany 861 - Chapter 53 Diagnostics

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide80• IP Address Assignment: Select Auto If your ISP did not assign you a fixed IP address. Select Stat

Strany 862

Chapter 50 SystemZyWALL USG 2000 User’s Guide800Note: Admin Service Control deals with management access (to the Web Configurator). User Service Contr

Strany 863

Chapter 50 SystemZyWALL USG 2000 User’s Guide801Server Port The HTTPS server listens on port 443 by default. If you change the HTTPS server port to a

Strany 864 - Chapter 53 Diagnostics

Chapter 50 SystemZyWALL USG 2000 User’s Guide802HTTPEnable Select the check box to allow or disallow the computer with the IP address that matches the

Strany 865 - CHAPTER 54

Chapter 50 SystemZyWALL USG 2000 User’s Guide80350.6.5 Service Control RulesClick Add or Edit in the Service Control table in a WWW, SSH, Telnet, FT

Strany 866 - Chapter 54 Reboot

Chapter 50 SystemZyWALL USG 2000 User’s Guide804also customize the page that displays after an access user logs into the Web Configurator to access ne

Strany 867 - CHAPTER 55

Chapter 50 SystemZyWALL USG 2000 User’s Guide805The following figures identify the parts you can customize in the login and access pages.Figure 523

Strany 868 - Chapter 55 Shutdown

Chapter 50 SystemZyWALL USG 2000 User’s Guide806•Click Color to display a screen of web-safe colors from which to choose.• Enter the name of the desir

Strany 869 - CHAPTER 56

Chapter 50 SystemZyWALL USG 2000 User’s Guide80750.6.7 HTTPS ExampleIf you haven’t changed the default HTTPS port on the ZyWALL, then in your browse

Strany 870 - I cannot access the Internet

Chapter 50 SystemZyWALL USG 2000 User’s Guide80850.6.7.2 Netscape Navigator Warning MessagesWhen you attempt to access the ZyWALL HTTPS server, a Web

Strany 871

Chapter 50 SystemZyWALL USG 2000 User’s Guide809• The issuing certificate authority of the ZyWALL’s HTTPS server certificate is not one of the browse

Strany 872

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide81Authentication TypeUse the drop-down list box to select an authentication protocol for outgoing ca

Strany 873

Chapter 50 SystemZyWALL USG 2000 User’s Guide810Apply for a certificate from a Certification Authority (CA) that is trusted by the ZyWALL (see the ZyW

Strany 874

Chapter 50 SystemZyWALL USG 2000 User’s Guide81150.6.7.5.2 Installing Your Personal Certificate(s)You need a password in advance. The CA may issue t

Strany 875

Chapter 50 SystemZyWALL USG 2000 User’s Guide8123 Enter the password given to you by the CA.Figure 533 Personal Certificate Import Wizard 34 Have th

Strany 876

Chapter 50 SystemZyWALL USG 2000 User’s Guide8135 Click Finish to complete the wizard and begin the import process.Figure 535 Personal Certificate

Strany 877

Chapter 50 SystemZyWALL USG 2000 User’s Guide8142 When Authenticate Client Certificates is selected on the ZyWALL, the following screen asks you to se

Strany 878

Chapter 50 SystemZyWALL USG 2000 User’s Guide815SSH is a secure communication protocol that combines authentication and data encryption to provide se

Strany 879

Chapter 50 SystemZyWALL USG 2000 User’s Guide8162 Encryption MethodOnce the identification is verified, both the client and server must agree on the t

Strany 880

Chapter 50 SystemZyWALL USG 2000 User’s Guide817Note: It is recommended that you disable Telnet and FTP when you configure SSH for secure connections

Strany 881

Chapter 50 SystemZyWALL USG 2000 User’s Guide81850.7.5 Secure Telnet Using SSH ExamplesThis section shows two examples using a command interface and

Strany 882

Chapter 50 SystemZyWALL USG 2000 User’s Guide819Enter the password to log in to the ZyWALL. The CLI screen displays next. 50.7.5.2 Example 2: LinuxT

Strany 883

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide825.2.5 Quick Setup Interface Wizard: SummaryThis screen displays the WAN interface’s settings.Figur

Strany 884

Chapter 50 SystemZyWALL USG 2000 User’s Guide82050.8.1 Configuring TelnetClick Configuration > System > TELNET to configure your ZyWALL for rem

Strany 885

Chapter 50 SystemZyWALL USG 2000 User’s Guide82150.9 FTP You can upload and download the ZyWALL’s firmware and configuration files using FTP. To use

Strany 886 - 56.1 Resetting the ZyWALL

Chapter 50 SystemZyWALL USG 2000 User’s Guide822be used to access the ZyWALL. You can also specify from which IP addresses the access can come.Figure

Strany 887 - 56.2 Changing a Power Module

Chapter 50 SystemZyWALL USG 2000 User’s Guide82350.10 SNMP Simple Network Management Protocol is a protocol used for exchanging management informati

Strany 888 - Chapter 56 Troubleshooting

Chapter 50 SystemZyWALL USG 2000 User’s Guide824and version two (SNMPv2c). The next figure illustrates an SNMP management operation. Figure 548 SN

Strany 889

Chapter 50 SystemZyWALL USG 2000 User’s Guide825• GetNext - Allows the manager to retrieve the next object variable from a table or list within an ag

Strany 890

Chapter 50 SystemZyWALL USG 2000 User’s Guide826settings, including from which zones SNMP can be used to access the ZyWALL. You can also specify from

Strany 891 - CHAPTER 57

Chapter 50 SystemZyWALL USG 2000 User’s Guide82750.11 Dial-in ManagementConnect an external serial modem to the AUX port to provide a management con

Strany 892

Chapter 50 SystemZyWALL USG 2000 User’s Guide828Hang Up check box is selected, the ZyWALL uses this hardware signal to force the WAN device to hang up

Strany 893

Chapter 50 SystemZyWALL USG 2000 User’s Guide82950.12 Vantage CNM Vantage CNM (Centralized Network Management) is a browser-based global management

Strany 894

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide835.3 VPN Quick SetupClick VPN Setup in the main Quick Setup screen to open the VPN Setup Wizard We

Strany 895

Chapter 50 SystemZyWALL USG 2000 User’s Guide83050.12.1 Configuring Vantage CNM Vantage CNM is disabled on the device by default. Click Configuration

Strany 896

Chapter 50 SystemZyWALL USG 2000 User’s Guide831Transfer ProtocolSelect whether the Vantage CNM sessions should use regular HTTP connections or secur

Strany 897 - FEATURE STANDARDS REFERENCED

Chapter 50 SystemZyWALL USG 2000 User’s Guide83250.13 Language Screen Click Configuration > System > Language to open the following screen. Use

Strany 898

ZyWALL USG 2000 User’s Guide833CHAPTER 51 Log and Report51.1 OverviewUse these screens to configure daily reporting and log settings. 51.1.1 What

Strany 899 - APPENDIX A

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide834Click Configuration > Log & Report > Email Daily Report to display the following scr

Strany 900 - LOG MESSAGE DESCRIPTION

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide835The following table describes the labels in this screen. 51.3 Log Setting Screens The Log Se

Strany 901 - Table 262 Anti-Spam Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide836The Log Setting tab also controls what information is saved in each log. For the system log, y

Strany 902

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide83751.3.2 Edit System Log Settings The Log Settings Edit screen controls the detailed settings

Strany 903 - Table 263 SSL VPN Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide838Figure 555 Configuration > Log & Report > Log Setting > Edit (System Log)

Strany 904

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide839The following table describes the labels in this screen. Table 245 Configuration > Log &

Strany 905 - Appendix A Log Descriptions

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide845.4 VPN Setup Wizard: Wizard TypeA VPN (Virtual Private Network) tunnel is a secure connection to

Strany 906

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide840E-mail Server 1 Use the E-Mail Server 1 drop-down list to change the settings for e-mailing lo

Strany 907 - Table 265 ZySH Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide841Active Select this to activate log consolidation. Log consolidation aggregates multiple log m

Strany 908

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide84251.3.3 Edit Remote Server Log Settings The Log Settings Edit screen controls the detailed set

Strany 909 - Table 266 ADP Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide843The following table describes the labels in this screen. Table 246 Configuration > Log

Strany 910 - Table 267 Anti-Virus Logs

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide84451.3.4 Active Log Summary ScreenThe Active Log Summary screen allows you to view and to edit

Strany 911

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide845The following table describes the fields in this screen. Table 247 Configuration > Log

Strany 912

Chapter 51 Log and ReportZyWALL USG 2000 User’s Guide846System log Select which events you want to log by Log Category. There are three choices:disabl

Strany 913 - Table 268 User Logs

ZyWALL USG 2000 User’s Guide847CHAPTER 52 File Manager52.1 OverviewConfiguration files define the ZyWALL’s settings. Shell scripts are files of com

Strany 914 - Table 269 myZyXEL.com Logs

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide848 These files have the same syntax, which is also identical to the way you run CLI commands manua

Strany 915

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide849Your configuration files or shell scripts can use “exit” or a command line consisting of a sing

Strany 916

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide855.5 VPN Express Wizard - Scenario Click the Express radio button as shown in Figure 52 on page 84

Strany 917

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide85052.2 The Configuration File ScreenClick Maintenance > File Manager > Configuration File t

Strany 918

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide851The following table describes the labels in this screen. Table 249 Maintenance > File Man

Strany 919 - Table 270 IDP Logs

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide852Copy Use this button to save a duplicate of a configuration file on the ZyWALL. Click a configur

Strany 920

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide853Apply Use this button to have the ZyWALL use a specific configuration file.Click a configuratio

Strany 921

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide85452.3 The Firmware Package Screen Click Maintenance > File Manager > Firmware Package to o

Strany 922

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide855Note: The Web Configurator is the recommended method for uploading firmware. You only need to u

Strany 923 - MESSAGE EXPLANATION

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide856After you see the Firmware Upload in Process screen, wait two minutes before logging into the Zy

Strany 924

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide857Note: You should include write commands in your scripts. If you do not use the write command, t

Strany 925 - Table 272 IKE Logs

Chapter 52 File ManagerZyWALL USG 2000 User’s Guide858Copy Use this button to save a duplicate of a shell script file on the ZyWALL. Click a shell scr

Strany 926

ZyWALL USG 2000 User’s Guide859CHAPTER 53 Diagnostics53.1 OverviewUse the diagnostics screens for troubleshooting. 53.1.1 What You Can Do in this

Strany 927

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide865.5.1 VPN Express Wizard - Configuration Figure 54 VPN Express Wizard: Step 3 • Secure Gateway:

Strany 928 - Table 273 IPSec Logs

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide860The following table describes the labels in this screen. 53.3 The Packet Capture ScreenUse this

Strany 929 - Table 274 Firewall Logs

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide861The following table describes the labels in this screen. Table 253 Maintenance > Diagnosti

Strany 930 - Table 276 Policy Route Logs

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide86253.3.1 The Packet Capture Files ScreenClick Maintenance > Diagnostics > Packet Capture >

Strany 931

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide86353.3.2 Example of Viewing a Packet Capture FileHere is an example of a packet capture file view

Strany 932

Chapter 53 DiagnosticsZyWALL USG 2000 User’s Guide864

Strany 933

ZyWALL USG 2000 User’s Guide865CHAPTER 54 Reboot54.1 OverviewUse this to restart the device (for example, if the device begins behaving erratically)

Strany 934

Chapter 54 RebootZyWALL USG 2000 User’s Guide866

Strany 935 - Table 278 System Logs

ZyWALL USG 2000 User’s Guide867CHAPTER 55 Shutdown55.1 OverviewUse this to shutdown the device in preparation for disconnecting the power. See also

Strany 936

Chapter 55 ShutdownZyWALL USG 2000 User’s Guide868

Strany 937

ZyWALL USG 2000 User’s Guide869CHAPTER 56 TroubleshootingThis chapter offers some suggestions to solve problems you might encounter. • You can also r

Strany 938

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide875.5.2 VPN Express Wizard - Summary This screen provides a read-only summary of the VPN tunnel’s c

Strany 939

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide870• Ping the ZyWALL from a LAN computer. Make sure your computer’s Ethernet card is installed a

Strany 940

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide871I cannot update the IDP/application patrol signatures.• Make sure your ZyWALL has the IDP/ap

Strany 941 - Table 280 Device HA Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide872The ZyWALL checks the firewall rules in the order that they are listed. So make sure that you

Strany 942

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide873The data rates through my cellular connection are no-where near the rates I expected.The act

Strany 943

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide874The ZyWALL is not applying my application patrol bandwidth management settings.Bandwidth mana

Strany 944

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide875The ZyWALL’s performance seems slower after configuring IDP.Depending on your network topolo

Strany 945

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide876The ZyWALL routes and applies SNAT for traffic from some interfaces but not from others.The Z

Strany 946 - Table 282 NAT Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide877I cannot get the application patrol to manage H.323 traffic.Make sure you have the H.323 ALG

Strany 947 - Table 283 PKI Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide878• The ZyWALL and remote IPSec router must use the same authentication method to establish the

Strany 948

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide879of its Trusted Certificates to authenticate the remote IPSec router’s certificate. The trust

Strany 949 - CODE DESCRIPTION

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide885.5.3 VPN Express Wizard - Finish Now you can use the VPN tunnel.Figure 56 VPN Express Wizard: S

Strany 950 - Table 284 Interface Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide880I uploaded a logo to show in the SSL VPN user screens but it does not display properly. The l

Strany 951

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide881decompressed option while you download the firmware package. See Section 33.2.1 on page 553

Strany 952

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide882• You may need to disable STP (Spanning Tree Protocol).• The master and its backups must all

Strany 953

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide883I cannot add the admin users to a user group with access users.You cannot put access users a

Strany 954 - Table 285 Account Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide8842 You must remove any spaces from the certificate’s filename before you can import the certif

Strany 955 - Table 288 File Manager Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide885I uploaded a logo to use as the screen or window background but it does not display properly

Strany 956 - Table 289 DHCP Logs

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide886See the CLI Reference Guide for how to determine if you need to recover the firmware and how

Strany 957

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide8872 Press the RESET button and hold it until the SYS LED begins to blink. (This usually takes

Strany 958

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide8885 Use the handle to slide out the power module and remove it.Figure 577 Removing the Power

Strany 959 - APPENDIX B

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide8898 Connect the power cord to the new ZyWALL power module.9 Reconnect the power cord to the po

Strany 960 - Appendix B Common Services

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide895.5.4 VPN Advanced Wizard - Scenario Click the Advanced radio button as shown in Figure 52 on pag

Strany 961 - Appendix B Common Services

Chapter 56 TroubleshootingZyWALL USG 2000 User’s Guide890

Strany 962

ZyWALL USG 2000 User’s Guide891CHAPTER 57 Product SpecificationsThe following specifications are subject to change without notice. See Chapter 2 on p

Strany 963 - APPENDIX C

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide892This table gives details about the ZyWALL’s features. AUX port RS-232, DB

Strany 964 - Windows 2000

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide893Static Routes 10,000 (shared with the policy routes)10,000 (shared with the policy ro

Strany 965 - Windows 98 SE/Me

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide894Maximum Number of LDAP Groups 32 32 32Maximum Number of LDAP Servers for Each LDAP Gro

Strany 966

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide895Syslog Servers 4 4 4IDPMaximum Number of IDP Profiles 32 32 32Custom Signatures 512 5

Strany 967

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide896The following table, which is not exhaustive, lists standards referenced by ZyWALL fea

Strany 968

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide89757.1 3G PCMCIA Card InstallationOnly insert a compatible 3G card. Slide the connecto

Strany 969 - APPENDIX D

Chapter 57 Product SpecificationsZyWALL USG 2000 User’s Guide898

Strany 970

ZyWALL USG 2000 User’s Guide899APPENDIX A Log DescriptionsThis appendix provides descriptions of example log messages for the ZLD-based ZyWALLs. The

Strany 971

Contents OverviewZyWALL USG 2000 User’s Guide9Contents OverviewUser’s Guide ...

Strany 972

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide90• Remote Access (Client Role) - Choose this to connect to an IPSec server. This ZyWALL is the clien

Strany 973

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide900 Table 261 Blocked Web Site LogsLOG MESSAGE DESCRIPTION%s :%s The rating server responded

Strany 974

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide901%s: Proxy mode is detectedThe system detected a proxy connection and blocked access accordi

Strany 975

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide902Black List checking has been activated.The anti-spam black list has been turned on.Black Lis

Strany 976

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide903Table 263 SSL VPN LogsLOG MESSAGE DESCRIPTION%s %s from %s has logged in SSLVPNA user has

Strany 977

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide904The %s address-object is wrong type for 'network' in SSL Policy %s.The listed addr

Strany 978

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide905%s %s is accessed. sent=<bytes> rcvd=<bytes>The listed SSL VPN access was used

Strany 979

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide906Table 264 L2TP Over IPSec LogsLOG MESSAGE DESCRIPTIONThe configuration of L2TP over IPSec

Strany 980

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide907The ZySH logs deal with internal system errors. Table 265 ZySH LogsLOG MESSAGE DESCRIPTIO

Strany 981

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide908Can't remove %s 1st:zysh list nameTable OPS%s: cannot retrieve entries from table!1st:z

Strany 982

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide909Table 266 ADP LogsLOG MESSAGE DESCRIPTIONfrom <zone> to <zone> [type=<type

Strany 983

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide91that uses a 168-bit key. As a result, 3DES is more secure than DES. It also requires more processi

Strany 984

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide910Table 267 Anti-Virus LogsLOG MESSAGE DESCRIPTIONInitializing Anti-Virus signature referenc

Strany 985

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide911AV signature update has failed. Can not update last update time.The anti-virus signatures u

Strany 986

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide912Anti-Virus rule %d has been modified.The anti-virus rule of the specified number has been ch

Strany 987

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide913Table 268 User LogsLOG MESSAGE DESCRIPTION%s %s from %s has logged in ZyWALLA user logged

Strany 988

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide914 Failed login attempt to ZyWALL from %s (login on a lockout address)A login attempt came fro

Strany 989

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide915Registration has failed. Because of lack must fields.The device received an incomplete resp

Strany 990 - Konqueror

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide916Do device register. The device started device registration.Do trial service activation.The d

Strany 991

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide917Device has latest signature file; no need to updateThe device already has the latest versio

Strany 992

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide918Get server response has failed.The device sent packets to the server, but did not receive a

Strany 993

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide919Self signed certificate.Verification of a server’s certificate failed because it is self-si

Strany 994

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide925.5.6 VPN Advanced Wizard - Phase 2 Phase 2 in an IKE uses the SA that was established in phase 1

Strany 995 - APPENDIX E

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide920Enable IDP engine succeeded.The device turned on the IDP engine.Disable IDP engine succeeded

Strany 996

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide921Add custom signature error: signature <sid> is over length.An attempt to add a custom

Strany 997

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide922from <zone> to <zone> [type=<type>] <message> , Action: <action&g

Strany 998

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide923Duplicate sid <sid> in import file at line <linenum>.The listed signature ID is

Strany 999

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide924Protocol %s has been enabled.The listed protocol has been turned on in the application patro

Strany 1000

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide925 Table 272 IKE LogsLOG MESSAGE DESCRIPTIONPeer has not announced DPD capabilityThe remote

Strany 1001

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide926[SA] : Tunnel [%s] Phase 1 invalid protocol%s is the tunnel name. When negotiating Phase-1,

Strany 1002

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide927Could not dial manual key tunnel "%s"%s is the tunnel name. The manual key tunnel

Strany 1003

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide928 VPN gateway %s was enabled%s is the gateway name. An administrator enabled the VPN gateway.

Strany 1004

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide929 Get outbound transform failWhen outgoing packet need to be transformed, the engine cannot

Strany 1005

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide93• Nailed-Up: This displays for the site-to-site and remote access client role scenarios. Select th

Strany 1006

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide930 Firewall %s %s rule %d was %s.1st %s is from zone, 2nd %s is to zone, %d is the index of t

Strany 1007

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide931 The policy route %d uses empty user group!Use an empty object group.%d: the policy route r

Strany 1008

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide932HTTPS port has been changed to port %s.An administrator changed the port number for HTTPS.%s

Strany 1009

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide933Console baud has been reset to %d.An administrator changed the console port baud rate back

Strany 1010

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide934DNS access control rule %u has been moved to %d.An administrator moved the rule %u to index

Strany 1011

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide935 Access control rule %u of %s was modified.An access control rule was modified successfully

Strany 1012

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide936DHCP Server executed with cautious mode disabledDHCP Server executed with cautious mode disa

Strany 1013

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide937Device is rebooted by administrator!An administrator restarted the device.Insufficient memo

Strany 1014

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide938Update the profile %s has failed because the feature requested is only available to donators

Strany 1015

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide939The profile %s has been paused because the HA interface of VRRP status was standby.The prof

Strany 1016

Chapter 5 Quick SetupZyWALL USG 2000 User’s Guide945.5.8 VPN Advanced Wizard - Finish Now you can use the VPN tunnel.Figure 61 VPN Wizard: Step 6:

Strany 1017

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide940 Table 279 Connectivity Check LogsLOG MESSAGE DESCRIPTIONCan't open link_up2 Cannot r

Strany 1018

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide941 Can't use MULTICAST IP for destinationThe connectivity check process can't use m

Strany 1019

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide942%s file not existed, Skip syncing it for %sThere is no file to be synchronized from the Mast

Strany 1020

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide943Device HA authentication type for VRRP group %s maybe wrong.A VRRP group’s Authentication T

Strany 1021

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide944 Table 281 Routing Protocol LogsLOG MESSAGE DESCRIPTIONRIP on interface %s has been stoppe

Strany 1022

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide945RIP md5 authentication id and key have been deleted.RIP md5 authentication id and key have

Strany 1023

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide946 Invalid OSPF virtual-link %s authentication of area %s.Virtual-link %s authentication has b

Strany 1024

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide947 Register SIP ALG signal port=%d failed.SIP ALG apply signal port failed.%d: Port numberReg

Strany 1025

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide948SCEP enrollment "%s" successfully, CA "%s", URL "%s"The device

Strany 1026

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide949 Export X509 certificate "%s" from "Trusted Certificate" successfullyTh

Strany 1027

ZyWALL USG 2000 User’s Guide95CHAPTER 6 Configuration BasicsThis information is provided to help you configure the ZyWALL effectively. Some of it is

Strany 1028

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide950 25 Database method failed due to timeout.26 Database method failed.27 Path was not verified

Strany 1029

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide951Interface %s is enabled.An administrator enabled an interface. %s: interface name.Interface

Strany 1030

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide952Interface %s connect failed: MS-CHAP authentication failed.MS-CHAP authentication failed (th

Strany 1031

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide953"SIM card has been successfully unlocked by PUK code on interface cellular%d.You enter

Strany 1032

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide954 "Cellular device [%s %s] has been removed from %s.The cellular device (identified by

Strany 1033

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide955 Table 287 Force Authentication LogsLOG MESSAGE DESCRIPTIONForce User Authentication

Strany 1034

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide956 Table 289 DHCP LogsLOG MESSAGE DESCRIPTIONCan't find any lease for this client - %

Strany 1035

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide957Table 291 IP-MAC Binding LogsLOG MESSAGE DESCRIPTIONDrop packet %s-%u.%u.%u.%u-%02X:%02X:

Strany 1036

Appendix A Log DescriptionsZyWALL USG 2000 User’s Guide958

Strany 1037

ZyWALL USG 2000 User’s Guide959APPENDIX B Common ServicesThe following table lists some commonly-used services and their associated protocols and por

Strany 1038

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide96objects whenever the interface’s IP address settings change. For example, if you change an

Strany 1039

Appendix B Common ServicesZyWALL USG 2000 User’s Guide960ESP (IPSEC_TUNNEL)User-Defined 50 The IPSEC ESP (Encapsulation Security Protocol) tunneling p

Strany 1040

Appendix B Common ServicesZyWALL USG 2000 User’s Guide961PPTP TCP 1723 Point-to-Point Tunneling Protocol enables secure transfer of data over public

Strany 1041

Appendix B Common ServicesZyWALL USG 2000 User’s Guide962TFTP UDP 69 Trivial File Transfer Protocol is an Internet file transfer protocol similar to F

Strany 1042

ZyWALL USG 2000 User’s Guide963APPENDIX C Displaying Anti-Virus AlertMessages in WindowsWith the anti-virus packet scan, when a virus is detected, yo

Strany 1043

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9642 Select the Messenger service and click Start.Figure 581 W

Strany 1044

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9652 Select the Messenger service and click Start Service.Figur

Strany 1045

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9661 Right-click on the program task bar and click Properties. F

Strany 1046

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9674 Right-click in the StartUp pane and click New, Shortcut. F

Strany 1047

Appendix C Displaying Anti-Virus Alert Messages in WindowsZyWALL USG 2000 User’s Guide9686 Specify a name for the shortcut or accept the default and c

Strany 1048

ZyWALL USG 2000 User’s Guide969APPENDIX D Importing CertificatesThis appendix shows you how to import public key certificates into your web browser.

Strany 1049

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide976.2.1 Interface Types There are many types of interfaces in the ZyWALL. In addition to b

Strany 1050

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9701 If your device’s Web Configurator is set to use SSL certification, then the first ti

Strany 1051 - APPENDIX F

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9714 In the Certificate dialog box, click Install Certificate.Figure 594 Internet Expl

Strany 1052

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9726 If you want Internet Explorer to Automatically select certificate store based on the

Strany 1053 - ZyXEL Limited Warranty

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9738 In the Select Certificate Store dialog box, choose a location in which to save the

Strany 1054 - Registration

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide97410 If you are presented with another Security Warning, click Yes.Figure 600 Internet

Strany 1055 - Numerics

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide975Installing a Stand-Alone Certificate File in Internet ExplorerRather than browsing to

Strany 1056 - ZyWALL USG 2000 User’s Guide

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9761 Open Internet Explorer and click Tools > Internet Options.Figure 605 Internet E

Strany 1057

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9773 In the Certificates dialog box, click the Trusted Root Certificates Authorities tab

Strany 1058

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9786 The next time you go to the web site that issued the public key certificate you just

Strany 1059

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9793 The certificate is stored and you can now connect securely to the Web Configurator.

Strany 1060

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide986.2.2 Default Interface and Zone ConfigurationThis section introduces the ZyWALL’s defaul

Strany 1061

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9801 Open Firefox and click Tools > Options.Figure 612 Firefox 2: Tools Menu2 In the

Strany 1062

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9813 In the Certificate Manager dialog box, click Web Sites > Import.Figure 614 Fi

Strany 1063

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide982Removing a Certificate in FirefoxThis section shows you how to remove a public key cer

Strany 1064

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9833 In the Certificate Manager dialog box, select the Web Sites tab, select the certifi

Strany 1065

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9841 If your device’s Web Configurator is set to use SSL certification, then the first ti

Strany 1066

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide985Installing a Stand-Alone Certificate File in OperaRather than browsing to a ZyXEL Web

Strany 1067

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9862 In Preferences, click Advanced > Security > Manage certificates.Figure 623 O

Strany 1068

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9873 In the Certificates Manager, click Authorities > Import.Figure 624 Opera 9: C

Strany 1069

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9885 In the Install authority certificate dialog box, click Install.Figure 626 Opera 9

Strany 1070

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9891 Open Opera and click Tools > Preferences.Figure 628 Opera 9: Tools Menu2 In Pr

Strany 1071

Chapter 6 Configuration BasicsZyWALL USG 2000 User’s Guide99• The DMZ zone contains the ge4, ge5, and ge6 interfaces (physical ports P4, P5, and P6).

Strany 1072

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9903 In the Certificates manager, select the Authorities tab, select the certificate that

Strany 1073

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9912 Click Continue.Figure 631 Konqueror 3.5: Server Authentication3 Click Forever whe

Strany 1074

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide992Installing a Stand-Alone Certificate File in KonquerorRather than browsing to a ZyXEL

Strany 1075

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9933 The next time you visit the web site, click the padlock in the address bar to open

Strany 1076

Appendix D Importing CertificatesZyWALL USG 2000 User’s Guide9944 The next time you go to the web site that issued the public key certificate you just

Strany 1077

ZyWALL USG 2000 User’s Guide995APPENDIX E Open Software AnnouncementsEnd-User License Agreement for “ZyWALL USG 2000” WARNING: ZyXEL Communications

Strany 1078

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide996You may not remove any proprietary notice of ZyXEL or any of its licensors from a

Strany 1079

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide9976.No WarrantyTHE SOFTWARE IS PROVIDED "AS IS." TO THE MAXIMUM EXTENT

Strany 1080

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide9989.Audit RightsZyXEL SHALL HAVE THE RIGHT, AT ITS OWN EXPENSE, UPON REASONABLE PRI

Strany 1081

Appendix E Open Software AnnouncementsZyWALL USG 2000 User’s Guide999bridge-utils 0.9.5. http://linux-net.osdl.org/index.php/Bridgedhcpcd-1.3.22-pl4

Komentáře k této Příručce

Žádné komentáře