User Guide
Page 6
... NOT open the device or unit. Safety Warnings • Do NOT use this product near water, for example, in Europe). • Do NOT allow anything to rest on the power adaptor or cord and do NOT place the product where anyone can expose you wall mount your device, make sure all cables from this device before servicing or disassembling. • Use ONLY an appropriate power adaptor...
... NOT open the device or unit. Safety Warnings • Do NOT use this product near water, for example, in Europe). • Do NOT allow anything to rest on the power adaptor or cord and do NOT place the product where anyone can expose you wall mount your device, make sure all cables from this device before servicing or disassembling. • Use ONLY an appropriate power adaptor...
User Guide
Page 7
... WINDOWS 7 USERS 13 20H 110H CHAPTER4 ACCESSING THE GATEWAY 15 21H 111H 4.1 START-UP AND LOG-IN 15 22H 112H CHAPTER5 BASIC SETTINGS 16 23H 113H 5.1 WAN SETUP ...16 24H 114H 5.1.1 DHCP (automatic IP address assignment 18 25H 115H 5.1.2 Static (Fixed IP address assignment 18 26H 116H 5.1.3 PPPoE (connected by username/password 19 27H 117H 5.1.4 Ethernet WAN MAC Address Clone 20 28H 118H 5.1.5 Mobile WAN (connected by information related to what your ISP needs...
... WINDOWS 7 USERS 13 20H 110H CHAPTER4 ACCESSING THE GATEWAY 15 21H 111H 4.1 START-UP AND LOG-IN 15 22H 112H CHAPTER5 BASIC SETTINGS 16 23H 113H 5.1 WAN SETUP ...16 24H 114H 5.1.1 DHCP (automatic IP address assignment 18 25H 115H 5.1.2 Static (Fixed IP address assignment 18 26H 116H 5.1.3 PPPoE (connected by username/password 19 27H 117H 5.1.4 Ethernet WAN MAC Address Clone 20 28H 118H 5.1.5 Mobile WAN (connected by information related to what your ISP needs...
User Guide
Page 8
... 130H 6.1.5 WPA / WPA2 ...34 41H 131H 6.2 ADVANCED SETUP...35 42H 132H 6.3 WPS - WIFI PROTECTED SETUP 37 43H 133H CHAPTER7 SECURITY SETTINGS 38 44H 134H 7.1 FIREWALL SETUP...38 45H 135H 7.2 ACCESS CONTROL LIST (ACL) SETUP 40 46H 136H 7.2.1 ACL Settings ...40 47H 137H 7.3 MAC ACCESS CONTROL SETUP 43 48H 138H 7.4 OpenDNS SETUP ...45 49H 139H 7.4.1 OpenDNS Settings 45 50H 140H 7.5 WEB FILTERING SETUP 46 51H 141H 7.5.1 Added Web Filtering Rules 47 52H 142H 7.6 VPN / PPTP SETUP...48...
... 130H 6.1.5 WPA / WPA2 ...34 41H 131H 6.2 ADVANCED SETUP...35 42H 132H 6.3 WPS - WIFI PROTECTED SETUP 37 43H 133H CHAPTER7 SECURITY SETTINGS 38 44H 134H 7.1 FIREWALL SETUP...38 45H 135H 7.2 ACCESS CONTROL LIST (ACL) SETUP 40 46H 136H 7.2.1 ACL Settings ...40 47H 137H 7.3 MAC ACCESS CONTROL SETUP 43 48H 138H 7.4 OpenDNS SETUP ...45 49H 139H 7.4.1 OpenDNS Settings 45 50H 140H 7.5 WEB FILTERING SETUP 46 51H 141H 7.5.1 Added Web Filtering Rules 47 52H 142H 7.6 VPN / PPTP SETUP...48...
User Guide
Page 10
.../cable modem and Mobile Cellular USB modem. At the same time, it also is designed for a secure method to access the Local Area Network remotely on Chip) solution, ZyXEL's VFG6005 Series VPN Firewall Gateway provides lower power consumption characteristics which saves not only energy, but also our environment. Session Manager ZyXEL's VFG6005 Series VPN Firewall Gateway supports fast recycling sessions in order to guarantee a stable network connection and to accommodate more users/applications in the network...
.../cable modem and Mobile Cellular USB modem. At the same time, it also is designed for a secure method to access the Local Area Network remotely on Chip) solution, ZyXEL's VFG6005 Series VPN Firewall Gateway provides lower power consumption characteristics which saves not only energy, but also our environment. Session Manager ZyXEL's VFG6005 Series VPN Firewall Gateway supports fast recycling sessions in order to guarantee a stable network connection and to accommodate more users/applications in the network...
User Guide
Page 13
... connected The Ethernet LAN port is connected The Ethernet LAN port is booting up. Wireless connection is enabled Wireless connection is disabled ZyXEL VFG6005 Series VPN Firewall Gateway is disconnected. please contact our customer service team. (contact info at the end of this document) The Ethernet WAN port is connected Data is being transmitted via the WAN port Ethernet/Mobile WAN is faulty; CHAPTER2 HARDWARE INSTALLATION 2.1 PANEL LAYOUT 2.1.1 Front LEDs (left to right) LED Power WLAN WAN LAN(1, 2, 3, 4) Function Power Indication Color Green Wireless Activity Green Red Status...
... connected The Ethernet LAN port is connected The Ethernet LAN port is booting up. Wireless connection is enabled Wireless connection is disabled ZyXEL VFG6005 Series VPN Firewall Gateway is disconnected. please contact our customer service team. (contact info at the end of this document) The Ethernet WAN port is connected Data is being transmitted via the WAN port Ethernet/Mobile WAN is faulty; CHAPTER2 HARDWARE INSTALLATION 2.1 PANEL LAYOUT 2.1.1 Front LEDs (left to right) LED Power WLAN WAN LAN(1, 2, 3, 4) Function Power Indication Color Green Wireless Activity Green Red Status...
User Guide
Page 14
... Reset ZyXEL VFG6005 Series VPN Firewall Gateway will restart automatically and reset the settings to right) Blinking Data is not used. Power Power inlet. 5 USB The port for 3 seconds. Please use USB port 1 as indicated on the top cover. 2.1.2 Rear Panel (left to factory default. USB port 2 is being transmitted via the LAN port Ports Description When the status LED turns green without blinking, please press the Reset button for connecting your DSL or Cable Modem. LAN (yellow) The ports for connecting your computers, printer or other devices...
... Reset ZyXEL VFG6005 Series VPN Firewall Gateway will restart automatically and reset the settings to right) Blinking Data is not used. Power Power inlet. 5 USB The port for 3 seconds. Please use USB port 1 as indicated on the top cover. 2.1.2 Rear Panel (left to factory default. USB port 2 is being transmitted via the LAN port Ports Description When the status LED turns green without blinking, please press the Reset button for connecting your DSL or Cable Modem. LAN (yellow) The ports for connecting your computers, printer or other devices...
User Guide
Page 29
... use to configure The ZyXEL VFG6005 Series VPN Firewall Gateway is the device which has been granted access by your ISP. 5.1.5 Mobile WAN (connected by information related to a fixed MAC address, please select Enable. Configure your ISP only grants access to what your ISP needs) Please enable and enter the APN, PIN code, user name, and password provided by your ISP does not enforce access control, please select Disable. You can also type in the MAC Address which...
... use to configure The ZyXEL VFG6005 Series VPN Firewall Gateway is the device which has been granted access by your ISP. 5.1.5 Mobile WAN (connected by information related to a fixed MAC address, please select Enable. Configure your ISP only grants access to what your ISP needs) Please enable and enter the APN, PIN code, user name, and password provided by your ISP does not enforce access control, please select Disable. You can also type in the MAC Address which...
User Guide
Page 31
... detection. Sets the desired connection mode and speed (HSDPA, UMTS, EDGE, GPRS). Set the max idle time before the mobile WAN is disconnected. (default interval 300 seconds) PPPoE echo will ensure whether the link is 8 bytes). 22 WAN Connection Type Modem Brand Modem Model APN Type Service Provider Access Point Name (APN) Personal Identification Number (PIN) Authentication User Name Password Dial Number Connection Mode PPP Connection Type Max Idle Time PPP Echo Interval PPP Retry Threshold PPPoE MTU Select Enable/Disable to assign...
... detection. Sets the desired connection mode and speed (HSDPA, UMTS, EDGE, GPRS). Set the max idle time before the mobile WAN is disconnected. (default interval 300 seconds) PPPoE echo will ensure whether the link is 8 bytes). 22 WAN Connection Type Modem Brand Modem Model APN Type Service Provider Access Point Name (APN) Personal Identification Number (PIN) Authentication User Name Password Dial Number Connection Mode PPP Connection Type Max Idle Time PPP Echo Interval PPP Retry Threshold PPPoE MTU Select Enable/Disable to assign...
User Guide
Page 37
... configure DDNS on [Setup] - [DDNS] tab. This makes it possible for other internet users to connect to a computer/router which has a dynamic IP address. DDNS is useful when combined with one of the DDNS providers (DynDNS.org, TZO.com or ZoneEdit.com) before you will see the following screen. 28 Click on the ZyXEL VFG6005 Series VPN Firewall Gateway. 2. 5.5 DDNS SETUP DDNS (Dynamic Domain Name Service) allows an...
... configure DDNS on [Setup] - [DDNS] tab. This makes it possible for other internet users to connect to a computer/router which has a dynamic IP address. DDNS is useful when combined with one of the DDNS providers (DynDNS.org, TZO.com or ZoneEdit.com) before you will see the following screen. 28 Click on the ZyXEL VFG6005 Series VPN Firewall Gateway. 2. 5.5 DDNS SETUP DDNS (Dynamic Domain Name Service) allows an...
User Guide
Page 39
... to access the first SSID with the WPA2 PSK (Pre-Shared Key) and secret key, whilst share the second SSID with WEP and the periodically changed key for visitors. Wireless Connection Wireless Mode Transmission Power Wireless Channel Wireless Isolation Between SSIDs Select Enable if you would like to be located to another . CHAPTER6 WIRELESS SETTINGS 6.1 BASIC SETUP Multiple SSIDs allow traffic from one SSID to avoid malicious attacks and prevent certain access for visitors using the second SSID.
... to access the first SSID with the WPA2 PSK (Pre-Shared Key) and secret key, whilst share the second SSID with WEP and the periodically changed key for visitors. Wireless Connection Wireless Mode Transmission Power Wireless Channel Wireless Isolation Between SSIDs Select Enable if you would like to be located to another . CHAPTER6 WIRELESS SETTINGS 6.1 BASIC SETUP Multiple SSIDs allow traffic from one SSID to avoid malicious attacks and prevent certain access for visitors using the second SSID.
User Guide
Page 65
... internal port range should be easily accessed. 56 CHAPTER8 APPLICATIONS SETTINGS 8.1 PORT RANGE FORWARD SETUP By activating the port range forwarding function, remote users can assign a specific external port range to the Internet. Furthermore, users can set up a DMZ host at a particular computer exposed to a local server. Therefore, if users do not wish for destination port to limit the use of the configured external ports, it will dispatch it when the application is not used. When the ZyXEL VFG6005 Series VPN Firewall Gateway receives an external...
... internal port range should be easily accessed. 56 CHAPTER8 APPLICATIONS SETTINGS 8.1 PORT RANGE FORWARD SETUP By activating the port range forwarding function, remote users can assign a specific external port range to the Internet. Furthermore, users can set up a DMZ host at a particular computer exposed to a local server. Therefore, if users do not wish for destination port to limit the use of the configured external ports, it will dispatch it when the application is not used. When the ZyXEL VFG6005 Series VPN Firewall Gateway receives an external...
User Guide
Page 67
Check/Uncheck to be applied. Configure [Add Port Range Forwarding Rule] Settings following the instructions below Port Forwarding Select Enable / Disable to the 1st rule from the top of the list. If a packet fits the conditions setup by the port forwarding rules, the packet will see the following the instructions below Sequence Number Rule Name Rule Enable External Interface Protocol External Port Range Internal IP Internal Port Range This defines the sequences (priorities) of the port forwarding rule. Enter the...
Check/Uncheck to be applied. Configure [Add Port Range Forwarding Rule] Settings following the instructions below Port Forwarding Select Enable / Disable to the 1st rule from the top of the list. If a packet fits the conditions setup by the port forwarding rules, the packet will see the following the instructions below Sequence Number Rule Name Rule Enable External Interface Protocol External Port Range Internal IP Internal Port Range This defines the sequences (priorities) of the port forwarding rule. Enter the...
User Guide
Page 68
... will see the following the instructions below Sequence Number Rule Name Rule Enable This defines the sequences (priorities) of the virtual hosts rule. Configure [Add Port Range Forwarding Rule] Settings following screen. 2. Check/Uncheck to an internal LAN IP address. Click on [Add] tab. 8.2 1-1 NAT 1-1 NAT allows you to map an external Public IP address to enable/disable this port forwarding rule. 59 For example, you can use each of those IP addresses to assign to the 1st rule...
... will see the following the instructions below Sequence Number Rule Name Rule Enable This defines the sequences (priorities) of the virtual hosts rule. Configure [Add Port Range Forwarding Rule] Settings following screen. 2. Check/Uncheck to an internal LAN IP address. Click on [Add] tab. 8.2 1-1 NAT 1-1 NAT allows you to map an external Public IP address to enable/disable this port forwarding rule. 59 For example, you can use each of those IP addresses to assign to the 1st rule...
User Guide
Page 81
... Firmware Upgrade Click Browse and Upgrade to load previous configuration settings. 4. Enter the password again to . (default port is 36 alphanumeric characters (case sensitive) Administrator Password Re-type Password Remote Management Management Port * Please change the settings and interrupt your current configuration settings in the LAN can then have the ability to recover the default system settings. HTTP port which users can access the management interface. Otherwise, a malicious user can connect to confirm. Select Enable to the ZyXEL VFG6005 Series VPN Firewall Gateway...
... Firmware Upgrade Click Browse and Upgrade to load previous configuration settings. 4. Enter the password again to . (default port is 36 alphanumeric characters (case sensitive) Administrator Password Re-type Password Remote Management Management Port * Please change the settings and interrupt your current configuration settings in the LAN can then have the ability to recover the default system settings. HTTP port which users can access the management interface. Otherwise, a malicious user can connect to confirm. Select Enable to the ZyXEL VFG6005 Series VPN Firewall Gateway...
User Guide
Page 87
WAN Ethernet Connection Status MAC Address Connection Type IP Address Subnet Mask Gateway Download Upload Connected / Not Connected MAC Address The current connection type (PPPoE, Static IP, and DHCP) WAN IP Address Number of the gateway Download speed Upload speed 78 The firmware version this device is shown. Router Information Model Name Firmware Version Current Time Running Time Product model name is running . 3. IP address of subnet mask. Current system time The period of time The ZyXEL VFG6005 Series VPN Firewall Gateway has been running . 2.
WAN Ethernet Connection Status MAC Address Connection Type IP Address Subnet Mask Gateway Download Upload Connected / Not Connected MAC Address The current connection type (PPPoE, Static IP, and DHCP) WAN IP Address Number of the gateway Download speed Upload speed 78 The firmware version this device is shown. Router Information Model Name Firmware Version Current Time Running Time Product model name is running . 3. IP address of subnet mask. Current system time The period of time The ZyXEL VFG6005 Series VPN Firewall Gateway has been running . 2.
User Guide
Page 92
... router makes your LAN by using another hub or switch. Hardware Features Dimensions (W x D x H) 159 mm x 107 mm x 25 mm Weight 225 g Power Specification Input: 100~240 V AC, 50~60 Hz Output: 12 V DC 1.5 A Gigabit Ethernet ports Auto-negotiating: 100 Mbps, 1000 Mbps in either crossover or straight-through Ethernet cables. 4 Port Gigabit Switch A combination of a hub when connecting to its factory default settings. Product Specifications The following tables summarize the VFG6005 Series hardware...
... router makes your LAN by using another hub or switch. Hardware Features Dimensions (W x D x H) 159 mm x 107 mm x 25 mm Weight 225 g Power Specification Input: 100~240 V AC, 50~60 Hz Output: 12 V DC 1.5 A Gigabit Ethernet ports Auto-negotiating: 100 Mbps, 1000 Mbps in either crossover or straight-through Ethernet cables. 4 Port Gigabit Switch A combination of a hub when connecting to its factory default settings. Product Specifications The following tables summarize the VFG6005 Series hardware...
User Guide
Page 94
... on your network by default, all incoming traffic from the Internet to your network is blocked unless it is on your network must have a server (mail or web server for your specific model! Port Forwarding If you specify. These dates and times are not allowed, but you can use this feature to have the VFG assign IP addresses, an IP default 85 Firmware Upgrade Download new firmware (when available) from the ZyXEL web site and use the Web Configurator to...
... on your network by default, all incoming traffic from the Internet to your network is blocked unless it is on your network must have a server (mail or web server for your specific model! Port Forwarding If you specify. These dates and times are not allowed, but you can use this feature to have the VFG assign IP addresses, an IP default 85 Firmware Upgrade Download new firmware (when available) from the ZyXEL web site and use the Web Configurator to...
User Guide
Page 132
Figure 160 Macintosh OS X: Network 4 For statically assigned settings, do the following: • From the Configure box, select Manually. • Type your IP address in the IP Address box. • Type your subnet mask in the Subnet mask box. • Type the IP address of your Prestige in the Router address box. 5 Click Apply Now and close the window. 6 Turn on your router and restart your TCP/IP properties in the Network window. 123 Verifying Settings Check your computer (if prompted). 3 For dynamically assigned settings, select Using DHCP from the Configure list.
Figure 160 Macintosh OS X: Network 4 For statically assigned settings, do the following: • From the Configure box, select Manually. • Type your IP address in the IP Address box. • Type your subnet mask in the Subnet mask box. • Type the IP address of your Prestige in the Router address box. 5 Click Apply Now and close the window. 6 Turn on your router and restart your TCP/IP properties in the Network window. 123 Verifying Settings Check your computer (if prompted). 3 For dynamically assigned settings, select Using DHCP from the Configure list.
User Guide
Page 135
... shows an example. Click Yes to save the changes in the Network Configuration screen. Figure 164 Red Hat 9.0: KDE: Network Configuration: Activate 7 After the network card restart process is complete, make sure the Status is Active in all screens. Using Configuration Files Follow the steps below to apply the changes. Figure 165 Red Hat 9.0: Dynamic IP Address Setting in ifconfig-eth0 DEVICE=eth0 ONBOOT=yes BOOTPROTO=dhcp USERCTL=no PEERDNS=yes TYPE=Ethernet •...
... shows an example. Click Yes to save the changes in the Network Configuration screen. Figure 164 Red Hat 9.0: KDE: Network Configuration: Activate 7 After the network card restart process is complete, make sure the Status is Active in all screens. Using Configuration Files Follow the steps below to apply the changes. Figure 165 Red Hat 9.0: Dynamic IP Address Setting in ifconfig-eth0 DEVICE=eth0 ONBOOT=yes BOOTPROTO=dhcp USERCTL=no PEERDNS=yes TYPE=Ethernet •...
User Guide
Page 150
... is the IP port number. • If the Protocol is USER, this is the IP protocol number. • Description: This is a brief explanation of port numbers, ICMP type/code numbers and services, visit the IANA (Internet Assigned Number Authority) web site. • Name: This is a short, descriptive name for the service. For a comprehensive list of the applications that use this is the IP protocol number, not the port number. • Port(s): This value...
... is the IP port number. • If the Protocol is USER, this is the IP protocol number. • Description: This is a brief explanation of port numbers, ICMP type/code numbers and services, visit the IANA (Internet Assigned Number Authority) web site. • Name: This is a short, descriptive name for the service. For a comprehensive list of the applications that use this is the IP protocol number, not the port number. • Port(s): This value...