User Guide
Page 13
... ...81 5.8 Configuring WAN Backup 82 Chapter 6 LAN Setup...85 6.1 LAN Overview ...85 6.1.1 LANs, WANs and the ZyXEL Device 85 6.1.2 DHCP Setup ...86 6.1.3 DNS Server Address 86 6.2 LAN TCP/IP ...86 6.2.1 IP Address and Subnet...NAT 100 7.3 SIP ALG ...100 7.4 NAT General Setup ...101 7.5 Port Forwarding ...102 7.5.1 Default Server IP Address 102 7.5.2 Port Forwarding: Services and Port Numbers 102 7.5.3 Configuring Servers Behind Port Forwarding (Example 103 7.6 Configuring Port Forwarding 103 7.6.1 Port Forwarding Rule Edit 104 7.7 Address Mapping ...105 7.7.1 Address Mapping Rule Edit ...
... ...81 5.8 Configuring WAN Backup 82 Chapter 6 LAN Setup...85 6.1 LAN Overview ...85 6.1.1 LANs, WANs and the ZyXEL Device 85 6.1.2 DHCP Setup ...86 6.1.3 DNS Server Address 86 6.2 LAN TCP/IP ...86 6.2.1 IP Address and Subnet...NAT 100 7.3 SIP ALG ...100 7.4 NAT General Setup ...101 7.5 Port Forwarding ...102 7.5.1 Default Server IP Address 102 7.5.2 Port Forwarding: Services and Port Numbers 102 7.5.3 Configuring Servers Behind Port Forwarding (Example 103 7.6 Configuring Port Forwarding 103 7.6.1 Port Forwarding Rule Edit 104 7.7 Address Mapping ...105 7.7.1 Address Mapping Rule Edit ...
User Guide
Page 20
... Figure 52 NAT General ...101 Figure 53 Multiple Servers Behind NAT Example 103 Figure 54 NAT Port Forwarding ...104 Figure 55 Port Forwarding Rule Setup 105 Figure 56 Address Mapping Rules ...106 Figure 57 Edit Address Mapping Rule 107 Figure... 132 Figure 67 Firewall: Configure Customized Services 133 Figure 68 Firewall Example: Rules ...134 Figure 69 Edit Custom Port Example 134 Figure 70 Firewall Example: Edit Rule: Destination Address 135 Figure 71 Firewall Example: Edit Rule: Select... Edit ...153 Figure 81 Subnet-based Bandwidth Management Example 156 20 P-660H-Tx v2 User's Guide
... Figure 52 NAT General ...101 Figure 53 Multiple Servers Behind NAT Example 103 Figure 54 NAT Port Forwarding ...104 Figure 55 Port Forwarding Rule Setup 105 Figure 56 Address Mapping Rules ...106 Figure 57 Edit Address Mapping Rule 107 Figure... 132 Figure 67 Firewall: Configure Customized Services 133 Figure 68 Firewall Example: Rules ...134 Figure 69 Edit Custom Port Example 134 Figure 70 Firewall Example: Edit Rule: Destination Address 135 Figure 71 Firewall Example: Edit Rule: Select... Edit ...153 Figure 81 Subnet-based Bandwidth Management Example 156 20 P-660H-Tx v2 User's Guide
User Guide
Page 25
...Table 27 NAT Mapping Types ...100 Table 28 NAT General ...101 Table 29 Services and Port Numbers 102 Table 30 NAT Port Forwarding ...104 Table 31 Port Forwarding Rule Setup 105 Table 32 Address Mapping Rules ...106 Table 33 Edit Address Mapping Rule 108... Table 34 Common IP Ports ...113 Table 35 ICMP Commands That Trigger Alerts 116 Table 36 Legal NetBIOS Commands ...116 Table 37 Legal SMTP Commands ...116 Table 38 Firewall: General ...127 P-660H-Tx v2...
...Table 27 NAT Mapping Types ...100 Table 28 NAT General ...101 Table 29 Services and Port Numbers 102 Table 30 NAT Port Forwarding ...104 Table 31 Port Forwarding Rule Setup 105 Table 32 Address Mapping Rules ...106 Table 33 Edit Address Mapping Rule 108... Table 34 Common IP Ports ...113 Table 35 ICMP Commands That Trigger Alerts 116 Table 36 Legal NetBIOS Commands ...116 Table 37 Legal SMTP Commands ...116 Table 38 Firewall: General ...127 P-660H-Tx v2...
User Guide
Page 42
... to which to apply the rule. Trusted Use this screen to set up dynamic DNS. 42 P-660H-Tx v2 User's Guide IP Alias Use this screen to configure LAN DHCP settings. Port Forwarding Use this screen to define a bandwidth rule. Schedule Use this screen to exclude a range of ...the direction of the firewall rules, and allows you to edit/add a firewall rule. Address Mapping Use this screen to view the ZyXEL Device's bandwidth usage and allotments. Monitor Use this screen to configure network address translation mapping rules. Advanced Static Route Use this screen ...
... to which to apply the rule. Trusted Use this screen to set up dynamic DNS. 42 P-660H-Tx v2 User's Guide IP Alias Use this screen to configure LAN DHCP settings. Port Forwarding Use this screen to define a bandwidth rule. Schedule Use this screen to exclude a range of ...the direction of the firewall rules, and allows you to edit/add a firewall rule. Address Mapping Use this screen to view the ZyXEL Device's bandwidth usage and allotments. Monitor Use this screen to configure network address translation mapping rules. Advanced Static Route Use this screen ...
User Guide
Page 79
...to edit a server mapping set of your PPPoE service here. Select SUA Only if you have one set . Click Edit to go to the Port Forwarding screen to disable NAT. Chapter 5 WAN Setup Table 18 More Connections Edit (continued) LABEL DESCRIPTION User Name (PPPoA and PPPoE encapsulation only) ...will not timeout. VCI The valid range for example, the source address of ATM traffic). P-660H-Tx v2 User's Guide 79 For LLC-based multiplexing or PPP encapsulation, one each protocol. The ZyXEL Device will try to 255. Max Idle Timeout Specify an idle time-out in the Max Idle...
...to edit a server mapping set of your PPPoE service here. Select SUA Only if you have one set . Click Edit to go to the Port Forwarding screen to disable NAT. Chapter 5 WAN Setup Table 18 More Connections Edit (continued) LABEL DESCRIPTION User Name (PPPoA and PPPoE encapsulation only) ...will not timeout. VCI The valid range for example, the source address of ATM traffic). P-660H-Tx v2 User's Guide 79 For LLC-based multiplexing or PPP encapsulation, one each protocol. The ZyXEL Device will try to 255. Max Idle Timeout Specify an idle time-out in the Max Idle...
User Guide
Page 98
...NAT changes the source IP address in each packet and then forwards it to the original inside global address) before forwarding the packet to the Internet. The global IP addresses for ... source port numbers for example, a web server and a telnet server, on the WAN. Figure 50 How NAT Works 7.1.4 NAT Application The following figure illustrates this chapter. 98 P-660H-Tx v2 User's... is the destination address on the LAN, and the IGA is the destination address on your ZyXEL Device filters out all incoming inquiries, thus preventing intruders from a subscriber (the inside local address...
...NAT changes the source IP address in each packet and then forwards it to the original inside global address) before forwarding the packet to the Internet. The global IP addresses for ... source port numbers for example, a web server and a telnet server, on the WAN. Figure 50 How NAT Works 7.1.4 NAT Application The following figure illustrates this chapter. 98 P-660H-Tx v2 User's... is the destination address on the LAN, and the IGA is the destination address on your ZyXEL Device filters out all incoming inquiries, thus preventing intruders from a subscriber (the inside local address...
User Guide
Page 101
...client is not degraded by the number of NAT sessions they need to the ZyXEL Device. SUA Only Select this check box to make sure SIP (VoIP) works correctly with port-forwarding and porttriggering rules. If your ZyXEL Device. Not all fields are available on all models. Each NAT session establishes.... If you have multiple public WAN IP addresses for your network has a large number of users using all of the available NAT sessions. P-660H-Tx v2 User's Guide 101 Chapter 7 Network Address Translation (NAT) Screens 7.4 NAT General Setup You must create a firewall rule in all of the...
...client is not degraded by the number of NAT sessions they need to the ZyXEL Device. SUA Only Select this check box to make sure SIP (VoIP) works correctly with port-forwarding and porttriggering rules. If your ZyXEL Device. Not all fields are available on all models. Each NAT session establishes.... If you have multiple public WAN IP addresses for your network has a large number of users using all of the available NAT sessions. P-660H-Tx v2 User's Guide 101 Chapter 7 Network Address Translation (NAT) Screens 7.4 NAT General Setup You must create a firewall rule in all of the...
User Guide
Page 102
... SNMP (Simple Network Management Protocol) 161 102 P-660H-Tx v2 User's Guide In some cases, such as a Web or FTP server) from ports that are shown in this screen. If you can make visible to a port or a range of inside (behind NAT on...Port Forwarding screen to forward incoming service requests to the server(s) on your ISP. 7.5.1 Default Server IP Address In addition to specify a range of the desired server. The most often used port numbers are not specified in the following table. Many residential broadband ISP accounts do not assign a Default Server IP address, the ZyXEL...
... SNMP (Simple Network Management Protocol) 161 102 P-660H-Tx v2 User's Guide In some cases, such as a Web or FTP server) from ports that are shown in this screen. If you can make visible to a port or a range of inside (behind NAT on...Port Forwarding screen to forward incoming service requests to the server(s) on your ISP. 7.5.1 Default Server IP Address In addition to specify a range of the desired server. The most often used port numbers are not specified in the following table. Many residential broadband ISP accounts do not assign a Default Server IP address, the ZyXEL...
User Guide
Page 103
P-660H-Tx v2 User's Guide 103 Figure 53 Multiple Servers Behind NAT Example 7.6 Configuring Port Forwarding " The Port Forwarding screen is available only when you do not assign a Default Server IP address, the ZyXEL Device discards all packets received for particular services. Click Network > NAT > Port Forwarding to a third (C in the example). " If you select SUA Only in the NAT...
P-660H-Tx v2 User's Guide 103 Figure 53 Multiple Servers Behind NAT Example 7.6 Configuring Port Forwarding " The Port Forwarding screen is available only when you do not assign a Default Server IP address, the ZyXEL Device discards all packets received for particular services. Click Network > NAT > Port Forwarding to a third (C in the example). " If you select SUA Only in the NAT...
User Guide
Page 104
... is the rule index number (read-only). Start Port This is the last port number that identifies a service. Note that are not specified here or in the Port Forwarding screen 104 P-660H-Tx v2 User's Guide If you can edit the port forwarding rule. Active Click this action. Apply Click Apply ...to save your changes to the screen where you do not assign a Default Server IP address, the ZyXEL Device discards all packets ...
... is the rule index number (read-only). Start Port This is the last port number that identifies a service. Note that are not specified here or in the Port Forwarding screen 104 P-660H-Tx v2 User's Guide If you can edit the port forwarding rule. Active Click this action. Apply Click Apply ...to save your changes to the screen where you do not assign a Default Server IP address, the ZyXEL Device discards all packets ...
User Guide
Page 105
Apply Click Apply to the ZyXEL Device. To forward only one port, enter the port number again in this field. If there are ignored. To forward a series of empty P-660H-Tx v2 User's Guide 105 Back Click Back to return to identify this port-forwarding rule. To forward only one port, enter the port number again in the NAT > General screen. Chapter 7 Network...
Apply Click Apply to the ZyXEL Device. To forward only one port, enter the port number again in this field. If there are ignored. To forward a series of empty P-660H-Tx v2 User's Guide 105 Back Click Back to return to identify this port-forwarding rule. To forward only one port, enter the port number again in the NAT > General screen. Chapter 7 Network...
User Guide
Page 108
...set . Enter 0.0.0.0 here if you have selected in this screen. Set Select a number from your ISP. Edit Details Click this screen afresh. 108 P-660H-Tx v2 User's Guide This is the starting local IP address (ILA). Local End IP This is N/A for One-to-one NAT mapping type. • ...to one global IP address. Global End IP This is N/A for Server port mapping. Cancel Click Cancel to begin configuring this link to go to the Port Forwarding screen to edit a server mapping set that you to the ZyXEL Device. If your changes to specify inside servers of the following table ...
...set . Enter 0.0.0.0 here if you have selected in this screen. Set Select a number from your ISP. Edit Details Click this screen afresh. 108 P-660H-Tx v2 User's Guide This is the starting local IP address (ILA). Local End IP This is N/A for One-to-one NAT mapping type. • ...to one global IP address. Global End IP This is N/A for Server port mapping. Cancel Click Cancel to begin configuring this link to go to the Port Forwarding screen to edit a server mapping set that you to the ZyXEL Device. If your changes to specify inside servers of the following table ...
User Guide
Page 152
...the name that you want to the screen where you can set up a static route on the ZyXEL Device. Modify Click the Edit icon to go to delete the route. 11.2.1 Static Route Edit... This is always based on the same network segment as the device's LAN or WAN port. Destination This parameter specifies the IP network address of an individual static route. The gateway...DESCRIPTION # This is a router or switch on network number. The gateway helps forward packets to remove a static route from the ZyXEL Device. Click the Delete icon to their destinations. Use this screen to activate...
...the name that you want to the screen where you can set up a static route on the ZyXEL Device. Modify Click the Edit icon to go to delete the route. 11.2.1 Static Route Edit... This is always based on the same network segment as the device's LAN or WAN port. Destination This parameter specifies the IP network address of an individual static route. The gateway...DESCRIPTION # This is a router or switch on network number. The gateway helps forward packets to remove a static route from the ZyXEL Device. Click the Delete icon to their destinations. Use this screen to activate...
User Guide
Page 153
... identical to the host ID. The gateway is always based on the same network segment as the device's LAN or WAN port. The gateway helps forward packets to the ZyXEL Device. P-660H-Tx v2 User's Guide 153 If you to activate/deactivate this screen afresh. Cancel Click Cancel to a single host, use a subnet mask of...
... identical to the host ID. The gateway is always based on the same network segment as the device's LAN or WAN port. The gateway helps forward packets to the ZyXEL Device. P-660H-Tx v2 User's Guide 153 If you to activate/deactivate this screen afresh. Cancel Click Cancel to a single host, use a subnet mask of...
User Guide
Page 182
...660H-Tx v2 User's Guide See the following table describes the fields in order to communicate with each other without entering the ZyXEL Device's IP address (although you must have IIS (Internet Information Services) enabled on the Windows web server for UPnP to manually configure port forwarding... for examples of installing and using NAT traversal, UPnP applications automatically reserve a NAT forwarding port in this eliminates the need to work. 15.2 UPnP and ZyXEL ZyXEL has achieved UPnP certification from the Universal ...
...660H-Tx v2 User's Guide See the following table describes the fields in order to communicate with each other without entering the ZyXEL Device's IP address (although you must have IIS (Internet Information Services) enabled on the Windows web server for UPnP to manually configure port forwarding... for examples of installing and using NAT traversal, UPnP applications automatically reserve a NAT forwarding port in this eliminates the need to work. 15.2 UPnP and ZyXEL ZyXEL has achieved UPnP certification from the Universal ...
User Guide
Page 213
... Subject: Firewall Alert From xxxxx Date: Fri, 07 Apr 2000 10:05:42 From: user@zyxel.com To: user@zyxel.com 1|Apr 7 00 |From:192.168.1.1 To:192.168.1.255 |default policy |forward | 09:54:03 |UDP src port:00520 dest port:00520 | | 2|Apr 7 00 |From:192.168.1.131 To:192.168.1.255 |default policy..., PPPoE, PPTP or dial-up server. Table 79 System Maintenance Logs LOG MESSAGE DESCRIPTION Time calibration is Full! The maximum number of example log messages. P-660H-Tx v2 User's Guide 213
... Subject: Firewall Alert From xxxxx Date: Fri, 07 Apr 2000 10:05:42 From: user@zyxel.com To: user@zyxel.com 1|Apr 7 00 |From:192.168.1.1 To:192.168.1.255 |default policy |forward | 09:54:03 |UDP src port:00520 dest port:00520 | | 2|Apr 7 00 |From:192.168.1.131 To:192.168.1.255 |default policy..., PPPoE, PPTP or dial-up server. Table 79 System Maintenance Logs LOG MESSAGE DESCRIPTION Time calibration is Full! The maximum number of example log messages. P-660H-Tx v2 User's Guide 213
User Guide
Page 217
Creating socket failed The ZyXEL Device cannot issue a query because TCP/IP socket creation failed, port:port number. P-660H-Tx v2 User's Guide 217 Waiting content filter The external content filtering server did not return the category type. %s:%s The content filter server responded that...period. Connecting to content The connection to the time schedule or you didn't select the "Block Matched Web Site" check box, the system forwards the web content. filter server fail License key is invalid The external content filtering license key is not on according to the external content ...
Creating socket failed The ZyXEL Device cannot issue a query because TCP/IP socket creation failed, port:port number. P-660H-Tx v2 User's Guide 217 Waiting content filter The external content filtering server did not return the category type. %s:%s The content filter server responded that...period. Connecting to content The connection to the time schedule or you didn't select the "Block Matched Web Site" check box, the system forwards the web content. filter server fail License key is invalid The external content filtering license key is not on according to the external content ...
User Guide
Page 234
... ADSL Standards Other Protocol Support Management Firewall NAT/SUA Content Filtering Multi-Mode standard (ANSI T1.413,Issue 2; Transparent bridging for FLASH memory, ADSL circuitry, RAM and LAN port MAP - Prevents Denial of Service attacks such as Ping of Death, SYN Flood, LAND...tutorial and automatic configurator) TR-069 Stateful Packet Inspection. Port Forwarding 2048 NAT sessions Multimedia application PPTP under NAT/SUA IPSec passthrough SIP ALG passthrough VPN passthrough Web page blocking by URL keyword. 234 P-660H-Tx v2 User's Guide DHCP Server/Client/Relay RIP I .610...
... ADSL Standards Other Protocol Support Management Firewall NAT/SUA Content Filtering Multi-Mode standard (ANSI T1.413,Issue 2; Transparent bridging for FLASH memory, ADSL circuitry, RAM and LAN port MAP - Prevents Denial of Service attacks such as Ping of Death, SYN Flood, LAND...tutorial and automatic configurator) TR-069 Stateful Packet Inspection. Port Forwarding 2048 NAT sessions Multimedia application PPTP under NAT/SUA IPSec passthrough SIP ALG passthrough VPN passthrough Web page blocking by URL keyword. 234 P-660H-Tx v2 User's Guide DHCP Server/Client/Relay RIP I .610...
User Guide
Page 235
...to subdivide a physical network into logical networks over the same Ethernet interface with a Dynamic DNS service provider. You must have the ZyXEL Device assign IP addresses, an IP default gateway and DNS servers to an earlier configuration. IP alias allows you to let people ...access it back on the ZyXEL Device later if you turn on your ZyXEL Device. These dates and times are then used to have its own unique IP address. P-660H-Tx v2 User's Guide 235 Configuration Backup & Restoration Network Address Translation (NAT) Port Forwarding DHCP (Dynamic Host Configuration Protocol...
...to subdivide a physical network into logical networks over the same Ethernet interface with a Dynamic DNS service provider. You must have the ZyXEL Device assign IP addresses, an IP default gateway and DNS servers to an earlier configuration. IP alias allows you to let people ...access it back on the ZyXEL Device later if you turn on your ZyXEL Device. These dates and times are then used to have its own unique IP address. P-660H-Tx v2 User's Guide 235 Configuration Backup & Restoration Network Address Translation (NAT) Port Forwarding DHCP (Dynamic Host Configuration Protocol...
User Guide
Page 251
...Rule 2 Src IP address IP Filter Set 1,Rule 2 Src Subnet Mask IP Filter Set 1,Rule 2 Src Port IP Filter Set 1,Rule 2 Src Port Comp 210102013 = IP Filter Set 1,Rule 2 Act Match 210102014 = IP Filter Set 1,Rule 2 Act Not ...Match = 0 = 0 PVA INPUT = 2 = 1 = 6 = 0.0.0.0 = 0 = 138 = 0.0.0.0 = 0 = 0 Table 109 Menu 21.1 Filer Set #2, / Menu 21.1 filter set #2, FIN FN 210200001 = Filter Set 2, Nam / Menu 21.1.2.1 Filter set #2, rule #1 PVA INPUT = NetBIOS_WAN P-660H-Tx v2...
...Rule 2 Src IP address IP Filter Set 1,Rule 2 Src Subnet Mask IP Filter Set 1,Rule 2 Src Port IP Filter Set 1,Rule 2 Src Port Comp 210102013 = IP Filter Set 1,Rule 2 Act Match 210102014 = IP Filter Set 1,Rule 2 Act Not ...Match = 0 = 0 PVA INPUT = 2 = 1 = 6 = 0.0.0.0 = 0 = 138 = 0.0.0.0 = 0 = 0 Table 109 Menu 21.1 Filer Set #2, / Menu 21.1 filter set #2, FIN FN 210200001 = Filter Set 2, Nam / Menu 21.1.2.1 Filter set #2, rule #1 PVA INPUT = NetBIOS_WAN P-660H-Tx v2...