User Guide
Page 43
... 3 Web Configurator The ISG50 Web Configurator allows easy ISG50 setup and management using an Internet browser. 3.1 Web Configurator Requirements In order to use the commands to change this setting. The Login screen appears. To protect against brute force, password-guessing attacks, the ISG50 blocks an account's access for 60 minutes after 3 consecutive, failed login attempts. See the Quick Start Guide. 2 Open your ISG50 hardware is recommended to its HTTPS server, and it is properly connected. Figure 17 Login Screen ISG50 User's Guide 43 By default, the ISG50...
... 3 Web Configurator The ISG50 Web Configurator allows easy ISG50 setup and management using an Internet browser. 3.1 Web Configurator Requirements In order to use the commands to change this setting. The Login screen appears. To protect against brute force, password-guessing attacks, the ISG50 blocks an account's access for 60 minutes after 3 consecutive, failed login attempts. See the Quick Start Guide. 2 Open your ISG50 hardware is recommended to its HTTPS server, and it is properly connected. Figure 17 Login Screen ISG50 User's Guide 43 By default, the ISG50...
User Guide
Page 48
... ISG50 User's Guide NAT Set up and manage HTTP redirection rules. IP/MAC Binding Summary Configure IP to MAC address bindings for Automatic Call Distribution (ACD) agents. Log System Log Lists system log entries. Licensing Registration Registration Register the device and activate trial services. Zone Configure zones used to each supported interface. Auth. Service View the licensed service status and upgrade licensed services. PPP Create and manage PPPoE and PPTP interfaces. Cellular Configure a cellular Internet connection for load balancing and link High...
... ISG50 User's Guide NAT Set up and manage HTTP redirection rules. IP/MAC Binding Summary Configure IP to MAC address bindings for Automatic Call Distribution (ACD) agents. Log System Log Lists system log entries. Licensing Registration Registration Register the device and activate trial services. Zone Configure zones used to each supported interface. Auth. Service View the licensed service status and upgrade licensed services. PPP Create and manage PPPoE and PPTP interfaces. Cellular Configure a cellular Internet connection for load balancing and link High...
User Guide
Page 60
... used as your IP address settings. 60 ISG50 User's Guide Chapter 4 Installation Setup Wizard Note: Enter the Internet access information exactly as a regular Ethernet. Otherwise, choose PPP over Ethernet or PPTP for Internet access. • Zone: This is the security zone to which this interface and Internet connection belong. • IP Address Assignment: Select Auto if your ISP. • WAN Interface: This is the interface you are configuring the first WAN interface. • Encapsulation: Choose the Ethernet option when the WAN port...
... used as your IP address settings. 60 ISG50 User's Guide Chapter 4 Installation Setup Wizard Note: Enter the Internet access information exactly as a regular Ethernet. Otherwise, choose PPP over Ethernet or PPTP for Internet access. • Zone: This is the security zone to which this interface and Internet connection belong. • IP Address Assignment: Select Auto if your ISP. • WAN Interface: This is the interface you are configuring the first WAN interface. • Encapsulation: Choose the Ethernet option when the WAN port...
User Guide
Page 92
...; PPP interfaces support Point-to be associated with one Ethernet interface. • Bridge interfaces create a software connection between Ethernet or VLAN interfaces at the layer-2 (data link, MAC address) level. The physical port is a group of interfaces and VPN tunnels) simplify security settings. In configuration, you use physical ports when configuring port groups. Port groups are created when you use the Interface > Port Roles screen to set multiple physical ports to -Point Protocols (PPPoE or PPTP). Use interfaces in the bridge. 92 ISG50 User's Guide You...
...; PPP interfaces support Point-to be associated with one Ethernet interface. • Bridge interfaces create a software connection between Ethernet or VLAN interfaces at the layer-2 (data link, MAC address) level. The physical port is a group of interfaces and VPN tunnels) simplify security settings. In configuration, you use physical ports when configuring port groups. Port groups are created when you use the Interface > Port Roles screen to set multiple physical ports to -Point Protocols (PPPoE or PPTP). Use interfaces in the bridge. 92 ISG50 User's Guide You...
User Guide
Page 99
... FTP traffic. Chapter 6 Configuration Basics PREREQUISITES Criteria: users, user groups, interfaces (incoming), IPSec VPN (incoming), addresses (source, destination), address groups (source, destination), schedules, services, service groups Next-hop: addresses (HOST gateway), IPSec VPN, trunks, interfaces NAT: addresses (translated address), services and service groups (port triggering) Example: You have multiple WAN connections. 9 Select the interface that you are using for your WAN connection (wan1 and wan2 are listed. Note: The ISG50 checks the policy routes in many security settings...
... FTP traffic. Chapter 6 Configuration Basics PREREQUISITES Criteria: users, user groups, interfaces (incoming), IPSec VPN (incoming), addresses (source, destination), address groups (source, destination), schedules, services, service groups Next-hop: addresses (HOST gateway), IPSec VPN, trunks, interfaces NAT: addresses (translated address), services and service groups (port triggering) Example: You have multiple WAN connections. 9 Select the interface that you are using for your WAN connection (wan1 and wan2 are listed. Note: The ISG50 checks the policy routes in many security settings...
User Guide
Page 109
... 75 Configuration > Network > Interface > Cellular 4 Enable the interface and add it to this 3G connection. In this example). Select the 3G device's entry and click Edit. Enter the PIN Code provided by the cellular 3G service provider (0000 in this example you connect the 3G USB card before you set to none has the ISG50 not apply any security settings to Configure a Cellular Interface Use 3G cards for a list of the ISG50's USB ports. 3 Click Configuration > Network > Interface > Cellular. Figure 74 Configuration > Network...
... 75 Configuration > Network > Interface > Cellular 4 Enable the interface and add it to this 3G connection. In this example). Select the 3G device's entry and click Edit. Enter the PIN Code provided by the cellular 3G service provider (0000 in this example you connect the 3G USB card before you set to none has the ISG50 not apply any security settings to Configure a Cellular Interface Use 3G cards for a list of the ISG50's USB ports. 3 Click Configuration > Network > Interface > Cellular. Figure 74 Configuration > Network...
User Guide
Page 113
Figure 81 Configuration > Network > Interface > Trunk 7.4 How to Set Up an IPSec VPN Tunnel This example shows how to use the IPSec VPN configuration screens to create the following VPN tunnel, see Section 5.4 on page 77 for details on the VPN quick setup wizard. ISG50 User's Guide 113 Figure 80 Configuration > Network > Interface > Trunk > Add Chapter 7 General Tutorials 3 Select the trunk as the default trunk and click Apply.
Figure 81 Configuration > Network > Interface > Trunk 7.4 How to Set Up an IPSec VPN Tunnel This example shows how to use the IPSec VPN configuration screens to create the following VPN tunnel, see Section 5.4 on page 77 for details on the VPN quick setup wizard. ISG50 User's Guide 113 Figure 80 Configuration > Network > Interface > Trunk > Add Chapter 7 General Tutorials 3 Select the trunk as the default trunk and click Apply.
User Guide
Page 173
..., replete with which guide them . Wait several seconds, then use the Files tab to save the file to your call center's automated audio menu "map". For example, if the Acme Widget company sells its own set up a customer service line that an agent performs. For example, in Spanish. Agents are fluent in the Acme Widget company's customer support department, some...
..., replete with which guide them . Wait several seconds, then use the Files tab to save the file to your call center's automated audio menu "map". For example, if the Acme Widget company sells its own set up a customer service line that an agent performs. For example, in Spanish. Agents are fluent in the Acme Widget company's customer support department, some...
User Guide
Page 238
... Reset to return the screen to support in dot decimal notation. For example, if you configure IP address assignment, interface parameters, RIP settings, OSPF settings, DHCP settings, connectivity check, and MAC address settings. The ISG50 can modify the entry's settings. To turn off an interface, select it before doing so. The ISG50 supports RIP-1, RIP-2, and both . • Select which settings use subnet broadcasting or multicasting. 238 ISG50 User's Guide See Section 12.3.2 on page 237.) The WAN interface's Edit > Configuration...
... Reset to return the screen to support in dot decimal notation. For example, if you configure IP address assignment, interface parameters, RIP settings, OSPF settings, DHCP settings, connectivity check, and MAC address settings. The ISG50 can modify the entry's settings. To turn off an interface, select it before doing so. The ISG50 supports RIP-1, RIP-2, and both . • Select which settings use subnet broadcasting or multicasting. 238 ISG50 User's Guide See Section 12.3.2 on page 237.) The WAN interface's Edit > Configuration...
User Guide
Page 251
...Table 68 Configuration > Network > Interface > PPP > Add (continued) LABEL MTU Connectivity Check Enable Connectivity Check Check Method DESCRIPTION Maximum Transmission Unit. Bandwidth usage is a failure. Usually, this interface. Type the maximum size of a WAN trunk for a response before the ISG50 stops routing through this value is a digital, packet-switched wireless technology. The ISG50 resumes routing to the ISG50. Check Period Check Timeout Check Fail Tolerance Check Default Gateway Check this interface. This field only displays when you use the default gateway for the...
...Table 68 Configuration > Network > Interface > PPP > Add (continued) LABEL MTU Connectivity Check Enable Connectivity Check Check Method DESCRIPTION Maximum Transmission Unit. Bandwidth usage is a failure. Usually, this interface. Type the maximum size of a WAN trunk for a response before the ISG50 stops routing through this value is a digital, packet-switched wireless technology. The ISG50 resumes routing to the ISG50. Check Period Check Timeout Check Fail Tolerance Check Default Gateway Check this interface. This field only displays when you use the default gateway for the...
User Guide
Page 255
... Configuration > Network > Interface > Cellular > Add LABEL Show Advance Settings / Hide Advance Settings General Settings Enable Interface Interface Properties Interface Name Zone Extension Slot Connected Device Description Connectivity Nailed-Up Idle timeout ISP Settings Profile Selection DESCRIPTION Click this interface. Connections with a GSM or HSDPA 3G card. Spaces are allowed. Your ISG50 accepts CHAP requests only. Clear this screen. CHAP - Enter a description of this button to display a greater or lesser number of your ISP instructed...
... Configuration > Network > Interface > Cellular > Add LABEL Show Advance Settings / Hide Advance Settings General Settings Enable Interface Interface Properties Interface Name Zone Extension Slot Connected Device Description Connectivity Nailed-Up Idle timeout ISP Settings Profile Selection DESCRIPTION Click this interface. Connections with a GSM or HSDPA 3G card. Spaces are allowed. Your ISG50 accepts CHAP requests only. Clear this screen. CHAP - Enter a description of this button to display a greater or lesser number of your ISP instructed...
User Guide
Page 265
... is a failure. In this to specify a domain name or IP address for the connectivity check. ISG50 User's Guide 265 DHCP Relay - Select icmp to have the ISG50 regularly perform a TCP handshake with the gateway you specify to make sure it is still available. Enter the number of DHCP service the ISG50 provides to the network. Enter that the gateway allows. Specify the port number to use the default gateway for the connectivity check. Select what type of...
... is a failure. In this to specify a domain name or IP address for the connectivity check. ISG50 User's Guide 265 DHCP Relay - Select icmp to have the ISG50 regularly perform a TCP handshake with the gateway you specify to make sure it is still available. Enter the number of DHCP service the ISG50 provides to the network. Enter that the gateway allows. Specify the port number to use the default gateway for the connectivity check. Select what type of...
User Guide
Page 299
Chapter 14 Policy and Static Routes Table 89 Configuration > Network > Routing > Static Route > Add (continued) LABEL DESCRIPTION Metric Metric represents the "cost" of the features you can use the pre-defined port triggering setting ISG50 User's Guide 299 NAT and SNAT NAT (Network Address Translation - Use SNAT (Source NAT) to change the source IP address in RFC 2597. The drop precedence determines the probability that approximates the cost for directly connected networks. In practice, 2 or 3 is...
Chapter 14 Policy and Static Routes Table 89 Configuration > Network > Routing > Static Route > Add (continued) LABEL DESCRIPTION Metric Metric represents the "cost" of the features you can use the pre-defined port triggering setting ISG50 User's Guide 299 NAT and SNAT NAT (Network Address Translation - Use SNAT (Source NAT) to change the source IP address in RFC 2597. The drop precedence determines the probability that approximates the cost for directly connected networks. In practice, 2 or 3 is...
User Guide
Page 327
... IP device, the ISG50 uses that is forwarded by the service requesting the connection. Firewall If you configure a NAT rule to forward traffic from the WAN to a LAN server, enabling NAT loopback allows users connected to other firewall rules according to the source IP address and mapped IP address. Ports - Enter the original destination port this NAT rule supports. Original Start Port This field is available if Mapping Type is Ports. Click OK to save your NAT rule settings, click the Firewall link to configure a firewall rule to allow users connected...
... IP device, the ISG50 uses that is forwarded by the service requesting the connection. Firewall If you configure a NAT rule to forward traffic from the WAN to a LAN server, enabling NAT loopback allows users connected to other firewall rules according to the source IP address and mapped IP address. Ports - Enter the original destination port this NAT rule supports. Original Start Port This field is available if Mapping Type is Ports. Click OK to save your NAT rule settings, click the Firewall link to configure a firewall rule to allow users connected...
User Guide
Page 375
... Remote Policy Log Inbound/Outbound traffic NAT Outbound Traffic Source NAT Select tcp to have the ISG50 generate a log every time it is the peer gateway's LAN IP address. Select this to turn on the VPN connection check. Perfect Forward Secrecy (PFS) The ISG50 and the remote IPSec router must use the same DH key group. disable PFS DH1 - Select how the ISG50 checks the connection. Enter that uses the same authentication algorithm. Chapter 24 IPSec VPN Table 123 Configuration > VPN > IPSec VPN > VPN Connection...
... Remote Policy Log Inbound/Outbound traffic NAT Outbound Traffic Source NAT Select tcp to have the ISG50 generate a log every time it is the peer gateway's LAN IP address. Select this to turn on the VPN connection check. Perfect Forward Secrecy (PFS) The ISG50 and the remote IPSec router must use the same DH key group. disable PFS DH1 - Select how the ISG50 checks the connection. Enter that uses the same authentication algorithm. Chapter 24 IPSec VPN Table 123 Configuration > VPN > IPSec VPN > VPN Connection...
User Guide
Page 443
... ISG50 using TAPI connections. License Status License Type Apply New Registration TAPI Driver Download Client TAPI Lines lists the extensions that you install the TAPI driver and utility in the Authority Group > Add screen. This field shows None when the service is activated (Licensed) or not (Not Licensed) or expired (Expired). Make sure your computer is on the ISG50's WAN and you need to activate the TAPI service and create a server...
... ISG50 using TAPI connections. License Status License Type Apply New Registration TAPI Driver Download Client TAPI Lines lists the extensions that you install the TAPI driver and utility in the Authority Group > Add screen. This field shows None when the service is activated (Licensed) or not (Not Licensed) or expired (Expired). Make sure your computer is on the ISG50's WAN and you need to activate the TAPI service and create a server...
User Guide
Page 538
... services. Figure 359 Configuration > PBX > Call Service >Emergency Call 538 ISG50 User's Guide Chapter 34 Call Services The following screen.Use this to save your changes and to apply them and clicking the Left button. To add an extension, select it in this screen. Reset Click this to set every field in the Extension Pool field and click the Right button (to the Enabled Extension list...
... services. Figure 359 Configuration > PBX > Call Service >Emergency Call 538 ISG50 User's Guide Chapter 34 Call Services The following screen.Use this to save your changes and to apply them and clicking the Left button. To add an extension, select it in this screen. Reset Click this to set every field in the Extension Pool field and click the Right button (to the Enabled Extension list...
User Guide
Page 696
... for SSH connections. Table 277 Configuration > System > SSH LABEL DESCRIPTION Enable Select the check box to allow or disallow the computer with the IP address that subsequent entries move the rule to the number that you must have the ISG50 use that opens. Apply Click Apply to save your SSH client program user's guide. 52.8.5.1 Example 1: Microsoft Windows This section describes how to access the ISG50 using a command interface and a graphical interface SSH client program to remotely access the ISG50. Server...
... for SSH connections. Table 277 Configuration > System > SSH LABEL DESCRIPTION Enable Select the check box to allow or disallow the computer with the IP address that subsequent entries move the rule to the number that you must have the ISG50 use that opens. Apply Click Apply to save your SSH client program user's guide. 52.8.5.1 Example 1: Microsoft Windows This section describes how to access the ISG50 using a command interface and a graphical interface SSH client program to remotely access the ISG50. Server...
User Guide
Page 707
... a user name and password to have the ISG50 send the daily e-mail report immediately. Reset Click Reset to return the screen to maintain the detailed settings (such as system errors and attacks. The ISG50 provides a system log and supports e-mail profiles and remote syslog servers. For alerts, the Log Settings tab controls which the outgoing e-mail is available on specified syslog servers. Mail Server Type the name or IP address...
... a user name and password to have the ISG50 send the daily e-mail report immediately. Reset Click Reset to return the screen to maintain the detailed settings (such as system errors and attacks. The ISG50 provides a system log and supports e-mail profiles and remote syslog servers. For alerts, the Log Settings tab controls which the outgoing e-mail is available on specified syslog servers. Mail Server Type the name or IP address...
User Guide
Page 731
... example, "ISG50.bin". Type in the location of the file you upload startup-config.conf, it . to find the .conf file you need to this field or click Browse ... The configuration file must decompress compressed (.zip) files before you try to a valid configuration. Use the Firmware Package screen to check your management session, the changes are applied to use the command line interface if you click Apply or OK. ISG50 User's Guide 731...
... example, "ISG50.bin". Type in the location of the file you upload startup-config.conf, it . to find the .conf file you need to this field or click Browse ... The configuration file must decompress compressed (.zip) files before you try to a valid configuration. Use the Firmware Package screen to check your management session, the changes are applied to use the command line interface if you click Apply or OK. ISG50 User's Guide 731...