Page 2 - Table of Contents; Chapter 1: Introduction; Introduction to your Router; Features; Chapter 2: Installing the Router; Important note for using this router; The Front LEDs; Chapter 3: Basic Installation; Connecting Your Router; Factory Default Settings; Configuring with your Web Browser; Chapter 4: Configuration; Status
Table of Contents Chapter 1: Introduction ..................................................................... 1 Introduction to your Router .................................................................. 1 Features ...................................................................................
Page 3 - WAN - Wide Area Network
Error Log ........................................................................................... 30Diagnostic ......................................................................................... 30 Quick Start ...................................................................................
Page 4 - VPN - Virtual Private Networks; Edit DMZ Host; Logout; Chapter 5: Troubleshooting
Firewall Log ..................................................................................... 85 VPN - Virtual Private Networks (Only available for BiPAC 7404V(G)OX) 86 PPTP (Point-to-Point Tunneling Protocol) .............................................. 86 IPSec (IP Security Protocol) .........
Page 6 - Express Internet Access; The router complies with ADSL worldwide standards.; Fast Ethernet Switch; and
Chapter 1: Introduction Introduction to your Router Welcome to the 3G/VoIP/ (802.11g) ADSL2+(VPN) Firewall Router. The router is an “all-in-one” ADSL router, combining an ADSL modem, ADSL router and Ethernet network switch functionalities, providing everything you need to get the machines on your ne...
Page 7 - meeting or MSN Messenger seamlessly.; SOHO Firewall Security with DoS and SPI; firewall
Multi-Protocol to Establish a Connection It s upports PPPoA (RFC 2364 - PPP over ATM Adaptation Layer 5), RFC 1483 encapsulatio n overATM (bridged or routed), PPP over Ethernet (RFC 2516), and IPoA (RFC1577) to establish a connection with the ISP. The product also supports VC-based and LLC-based mul...
Page 8 - Rich Packet Filtering; easy static routing table or RIP1/2 routing protocol; Simple Network Management Protocol (SNMP); easy way to remotely manage the router via SNMP.; Web based GUI
Quality of Service (QoS) QoS gives you full control over which types of outgoing data traffic should be given priority by the router, ensuring important data like gaming packets, customer information, or management information move through the router ay lightning speed, even under heavy load. The Qo...
Page 9 - It s
Firmware Upgradeable Device can be upgraded to the latest firmware through the WEB based GUI. Rich Management Interfaces It s upports flexible management interfaces with local console port, LAN port, and WAN port. Users can use terminal applications through the console port to configure and manage t...
Page 10 - Quick Start Guide
Chapter 2: Installing the Router Important note for using this router Package Contents 3G/VoIP/(802.11g) ADSL2+ (VPN) Firewall Router CD-ROM containing the online manual RJ-11 ADSL/telephone Cable Ethernet (CAT-5) Cable Console kitPower adapter A detachable antenna Quick Start Guide 5
Page 12 - The Rear Ports; Connect the USB cable to this port.
The Rear Ports Port Meaning 1 Antenna (Wireless Router only) Connect the detachable antenna to this port. 2 DSL Connect this port to the ADSL/telephone network with the RJ- 11 cable (telephone) provided. 3 Line (Router with LINE port only) Connect this port to the telephone jack on the wall with RJ-...
Page 13 - Cabling; . Make sure that all
Cabling One of the most common causes of problem is bad cabling or ADSL line(s) . Make sure that all connected devices are turned on. On the front panel of your router is a bank of LEDs. Verify that the LAN Link and ADSL line LEDs are lit. If they are not, verify if you are using the proper cables. ...
Page 14 - The router can be configured through your w
Chapter 3: Basic Installation The router can be configured through your w eb browser. A web browser is included as a standard application in the following operating systems: Linux, Mac OS, Windows 98/NT/2000/XP/Me/Vista, etc. The product provides an easy and user-friendly interface for configuration...
Page 15 - Connect this router to a; Make sure the; Power LED; lit steadily and that the; LAN
Connecting Your Router Connect this router to a 1. LAN (Local Area Network) and the ADSL/telephone ( ADSL ) net work. Power on the device. 2. Make sure the 3. Power LED lit steadily and that the LAN LED is lit. Connect your router to the telephone jack on the wall with RJ-11 cable. 4. Connect the US...
Page 16 - Network Configuration; Configuring PC in Windows Vista; When the Network and Sharing
Network Configuration Configuring PC in Windows Vista Go to Start. Click on Network. 1. Then click on Network and Sharing 2. Center at the top bar. When the Network and Sharing 3. Center window pops up, select and click on Manage network connec - tions on the left window column. Select the Local Are...
Page 18 - Configuring PC in Windows XP; In the Local Area Connection Status
Configuring PC in Windows XP Go to Start > Control Panel (in Classic 1. View). In the Control Panel, double-click on Network ConnectionsDouble-click Local Area Connection. 2. In the Local Area Connection Status 3. window, click Properties. Select Internet Protocol (TCP/IP) and 4. click Properties...
Page 19 - Configuring PC in Windows 2000; Click OK to finish the configuration.
Configuring PC in Windows 2000 Go to Start > Settings > Control Panel. 1. In the Control Panel, double-click on Network and Dial-up Connections.Double-click Local Area Connection. 2. In the Local Area Connection Status 3. window click Properties. Select Internet Protocol (TCP/IP) and 4. click ...
Page 21 - Configuring PC in Windows NT4.0; In the Control Panel, double-click on
Configuring PC in Windows NT4.0 Go to Start > Settings > Control Panel. 1. In the Control Panel, double-click on Network and choose the Protocols tab. Select TCP/IP Protocol and click Prop - 2. erties. Select the Obtain an IP address from 3. a DHCP server radio button and click OK. 16
Page 22 - admin
Factory Default Settings Before configuring your router, you need to know the following default settings. Web Interface (Username and Password) Username: admin Password: admin The default username and password are “ admin ” and “ admin ” respectively. Device LAN IP settings IP Address: 192.168.1.254...
Page 23 - Information from your ISP; Domain Name System (DNS) IP address (it can be automatically
Information from your ISP Before configuring this device, you have to check with your ISP (Internet Service Provider) to find out what kind of service is provided such as DHCP (Obtain an IP Address Automatically, Static IP (Fixed IP Address) or PPPoE. Gather the information as illustrated in the fol...
Page 25 - page. The category of each configuration page is listed as below.
Chapter 4: Configuration At the configuration homepage, the left navigation column provides you the link to each configuration page. The category of each configuration page is listed as below. Status ADSL Table3G StatusARP TableDHCP TableRouting TableNAT SessionsUpnP PortmapPPTP StatusIPSec StatusL2...
Page 26 - ADSL Status; as DSP firmware version.; G Status; The current status of the 3G card.
Status ADSL Status This section displays the ADSL overall status, which shows a number of helpful information such as DSP firmware version. 3G Status This section displays the 3G Card’s overall status, which shows you a number of helpful information such as the current signal strength and statistics...
Page 27 - The current firmware for the 3G card.; ARP Table; The MAC (Media Access Control) addresses for each device on your LAN.; yes; ” for static ARP table entries added by the user.; DHCP Table; The fixed host mapping information
Card Name: The name of the 3G card. Card Firmware: The current firmware for the 3G card. Current TX Bytes / Packets: The statistics of transmission, count for this call. Current RX Bytes / Packets: The statistics of receive, count for this call. Total TX Bytes / Packets: The statistics of transmissi...
Page 28 - Leased Table; The IP address that assigned to client.
Leased Table IP Address: The IP address that assigned to client. MAC Address: The MAC address of client. Client Host Name: The Host Name (Computer Name) of client. Expiry: The current lease time of client. 23
Page 29 - Routing Table
Routing Table Routing Table Valid: It indicates a successful routing status. Destination: The IP address of the destination network. Netmask: The destination Netmask address. Gateway/Interface: The IP address of the gateway or existing interface that this route will use. Cost: The number of hops cou...
Page 31 - PPTP Status; This shows details of your configured PPTP VPN Connections.
PPTP Status This shows details of your configured PPTP VPN Connections. Name: The name you assigned to the particular PPTP connection in your VPN configuration. Type: The type of connection (dial- in/dial -out). Enable: Whether th e connection is currently enabled. Active: Whether the connection is ...
Page 33 - Email Status; Advanced section of this manual for details on this function.; VoIP Status
Email Status Details and status for the Email Account you have configured the router to check. Please see the Advanced section of this manual for details on this function. VoIP Status VoIP Call Log 28
Page 34 - Event Log
Event Log This page displays the router’s Event Log entries. Major events are logged to this window, such as when the router’s ADSL connection is disconnected, as well as Firewall events when you have enabled Intrusion or Blocking Logging in the Configuration – Firewall section of the interface. Ple...
Page 35 - It tests the connection to computer(s) which is connected to the
Error Log Any errors encountered by the router (e.g. invalid names given to entries) are logged to this window. Diagnostic It tests the connection to computer(s) which is connected to the LAN ports and also the WAN Internet connection. If PING www.google.com is shown FAIL and the rest is PASS, you o...
Page 36 - Quick Start; or 3G. Select ADSL mode from the drop down menu and click Continue.
Quick Start Click Quick Start. Select the connect mode you want. There are 2 options to choose from: ADSL 1. or 3G. Select ADSL mode from the drop down menu and click Continue. If your ADSL line is not ready, you need to check your ADSL line has been set or not. 2. If your ADSL line is ready, the sc...
Page 38 - ESSID Broadcast
Configure the Wireless LAN setting. 6. WLAN Service: Default setting is set to Enable. If you want to use wireless, both 802.11g and 802.11b device in your network, you can select Enable. ESSID: The ESSID is the unique name of a wireless access point (AP) to be distinguished from another. For securi...
Page 39 - To use VoIP SIP as VoIP call signaling protocol. Default is set to; SIP Service Provider:; space with your username given by your VoIP provider.
SIP: To use VoIP SIP as VoIP call signaling protocol. Default is set to Disable. Region: This selection is a drop-down box, which allows user to select the country for which the VoIP device must work. When a country is selected, the country parameters are automatically loaded. SIP Service Provider: ...
Page 40 - Configuration; configure your ADSL router.
Configuration When you click this item, the column will expand to display the sub-items that will allow you to further configure your ADSL router. LAN, WAN, System, Firewall, VoIP, QoS, Virtual Server, Time Schedule and Advanced The function of each configuration sub-item is described in the followi...
Page 41 - LAN - Local Area Network; DHCP; Bridge Interface; Management Interface:
LAN - Local Area Network Here are the items within the LAN section: Bridge Interface, Ethernet, IP Alias, Ethernet Client Filter, Wireless, Wireless Security, Wireless Client Filter, WPS, Port Setting and DHCP Server. Bridge Interface You can setup member ports for each VLAN group under Bridge Inter...
Page 42 - Ethernet; Primary IP Address; IP Alias; Specify the firewall setting on this virtual interface.
Ethernet Primary IP Address IP Address: The default IP on this router. Subnet Mask: The default subnet mask on this router. RIP: RIP v1, RIP v2, and RIP v2 Multicast. Check to enable RIP function. IP Alias This function creates multiple virtual IP interfaces on this router. It helps to connect two o...
Page 43 - Ethernet Client Filter; Ethernet Client Filter:; Default setting is set; Disable; Click the Candidate button to access the; Active PC in LAN
Ethernet Client Filter The Ethernet Client Filter supports up to 16 Ethernet network machines that helps you to manage your network control to accept traffic from specific authorized machines or can restrict unwanted machine(s) to access your LAN. There are no pre-define Ethernet MAC address filter ...
Page 44 - MAC Address which connecting to the router.
MAC Address which connecting to the router. You can easily by checking the box next to the IP address to be blocked or allowed. Then, Add to insert to the Ethernet Client Filter table. The maximum Ethernet client is 16. 39
Page 45 - Wireless; Parameters; unique name of a wireless access point (AP) to be
Wireless Parameters WLAN Service: Default setting is set to Enable. If you do not have any wireless, both 802.11g and 802.11b, device in your network, select Disable. Mode: The default setting is 802.11b+g (Mixed mode). If you do not know or have both 11g and 11b devices in your network, then keep t...
Page 46 - and choose the most suitable level for your network.
Note: Wireless performance may degrade if select ID channel is already being occupied by other AP(s). TX PowerLevel: It is a function that enhances the wireless transmitting signal strength. User may adjust this power level from minimum 1 up to maximum 127. Note: The Power Level maybe different in e...
Page 47 - Wireless Security; The default mode of wireless security is disabled.
Wireless Security You can disable or enable with WPA or WEP for protecting wireless network. The default mode of wireless security is disabled. 42
Page 48 - PSK adapts the TKIP (Temporal Key Integrity Protocol); Share key; WEP
WPA-PSK / WPA2-PSK Security Mode: You can disable or enable with WPA or WEP for protecting wireless network. The default mode of wireless security is Disable . WPA Algorithms: There are two types of the WPA-PSK, WPA-PSK and WPA2-PSK. The WPA- PSK adapts the TKIP (Temporal Key Integrity Protocol) enc...
Page 49 - Default Used WEP Key:; Select the encryption key ID please refer to
Passphrase: This is used to generate WEP keys automatically based upon the input string and a pre-defined algorithm in WEP64 or WEP128. Default Used WEP Key: Select the encryption key ID; please refer to Key (1~4) below. Key (1-4): Enter the key to encrypt wireless data. To allow encrypted data tran...
Page 50 - Wireless Client / MAC Address Filter; traffic from specific authorized machines or; Wireless Client Filter:; The MAC; Associated Wireless Client; ’s MAC Address that currently
Wireless Client / MAC Address Filter The MAC Address supports up to 16 wireless network machines and helps you manage your network control to accept traffic from specific authorized machines or to restrict unwanted machine(s) to access your LAN. There are no pre-define MAC Address filter rules; you ...
Page 51 - WPS; WPS feature is follow Wi-Fi Alliance WPS standard and it
connects to the router. You can easily by checking the box next to the MAC address to be blocked or allowed. Then, Add to insert to the Wireless Client (MAC Address) Filter table. The maximum Wireless client is 16. WPS WPS feature is follow Wi-Fi Alliance WPS standard and it easily set up security-e...
Page 52 - Port Setting; allows you to configure; router’s Ethernet switch will check the 2; octet of each IP packet. If the value in the TOS field
Port Setting This section allows you to configure the settings for the router’s Ethernet ports to solve some of the compatibility problems that may be encountered while connecting to the Internet, as well allowing users to tweak the performance of their network. Port # Connection Type: There are Six...
Page 53 - DHCP Server; only if advised to do so by your network administrator or ISP.
DHCP Server You can disable or enable the DHCP (Dynamic Host Configuration Protocol) server or enable the router’s DHCP relay functions. The DHCP protocol allows your router to dynamically assign IP addresses to PCs on your network if they are configured to obtain IP addresses automatically. To disa...
Page 54 - the Internet. Here are the items within the; WAN Interface, WAN Profile; ADSL; WAN Interface; WAN Connection-ADSL Mode; User can select either ADSL or 3G mode.; Connectivity Decision:; Set how many times of probing failed to switch backup port.; Failover Probe Cycle:; port) once the main connection is communicating again.
WAN - Wide Area Network WAN refers to your Wide Area Network connection, i.e. your router’s connection to your ISP and the Internet. Here are the items within the WAN section: WAN Interface, WAN Profile and ADSL Mode. WAN Interface WAN Connection-ADSL Mode The default setting for Connection Mode is ...
Page 55 - The host must be an IP address.; WAN Connection-3G Mode; Mode is unavailable.
Rule 1. ADSL Down Rule 2. Ping Fail No Ping: It will not send any ping packet to determine the connection. It means to disable the ping fail detection. Ping Gateway: It will send ping packet to gateway and wait response from gateway in every “Probe Cycle”. Ping Host: It will send ping packet to spec...
Page 56 - WAN Profile; PPPoE Connection; Select the profile port as ADSL.
WAN Profile PPPoE Connection PPPoE (PPP over Ethernet) provides access control in a manner which is similar to dial-up services using PPP. Profile Port: Select the profile port as ADSL. Protocol: The ATM protocol will be used in the device. Description: A given name for the connection. VPI/VCI: Ente...
Page 58 - PPPoA Connection
PPPoA Connection Profile Port: Select the profile port as ADSL. Protocol: The ATM protocol will be used in the device.. Description: A given name for the connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer. Username: Enter the username pro...
Page 60 - MPoA Connection; device and modify data.
MPoA Connection Profile Port: Select the profile port as ADSL. Protocol: The ATM protocol will be used in the device. Description: A given name for the connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer. NAT: The NAT (Network Address Tran...
Page 62 - IPoA Routed Connection; Profile Port; The ATM protocol will be used in the device.; Gateway; MTU size automatically. Default is
IPoA Routed Connection Profile Port : Select the profile port as ADSL. Protocol: The ATM protocol will be used in the device. Description: A given name for the connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer. NAT: The NAT (Network Addr...
Page 63 - Pure Bridge; Acceptable Frame Type:; Allows only IP/ARP types of ethernet packets through the port.; Pppoe
Pure Bridge Profile Port: Select the profile port as ADSL. Protocol: The ATM protocol will be used in the device. Description: A given name for this connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer. Encap. mode: Choose whether you want ...
Page 64 - Authentication Type:; Default is None. Manually specify CHAP (Challenge Handshake
3G TEL No.: The dial string to make a GPRS / 3G user internetworking call. It may provide by your mobile service provider. APN: An APN is similar to a URL on the WWW, it is what the unit makes a GPRS / UMTS call. The service provider is able to attach anything to an APN to create a data connection, ...
Page 65 - Obtain DNS Automatically:; Select this check box to use DNS.
Connection: Always On: The router will make UMTS/GPRS call when starting up. Enabling Always On, will give you an option of Keep Alive. Keep Alive: Set Enable to allow the router automatically reconnects the connection when ISP disconnects it. Connect to Demand: If you want to make UMTS/GPRS call on...
Page 66 - ADSL Mode; the symptom of synchronization problem.
ADSL Mode Connect Mode: This mode will automatically detect your ADSL line code, ADSL2+, ADSL2, AnnexM2 and AnnexM2+, ADSL, All. Please keep the factory setting unless ADSL is detected as the symptom of synchronization problem. Modulation: It will automatically detect capability of your ADSL line mo...
Page 67 - System; Here are the items within the System section:; Time Zone; Your ISP may provide an SNTP server for you to use.
System Here are the items within the System section: Time Zone, Remote Access, Firmware Upgrade, Backup/Restore, Restart and User Management. Time Zone The router does not have a real time clock on board; instead, it uses the Simple Network Time Protocol (SNTP) to get the current time from an SNTP s...
Page 68 - runs to take advantage of these changes.
Remote Access To temporarily permit remote administration of the router (i.e. from outside your LAN), select a time period the router will permit remote access for and click Enable. You may change other configuration options for the web administration interface using Device Management options in the...
Page 69 - name of the file when saving if you wish to keep multiple backups.
Backup / Restore These functions allow you to save and backup your router’s current settings to a file on your PC, or to restore a previously saved backup. This is useful if you wish to experiment with different settings, knowing that you have a backup handy in the case of any mistakes. It is advisa...
Page 70 - Restart Router; factory default settings.
Restart Router Click Restart with option Current Settings to reboot your router (and restore your last saved configuration). If you wish to restart the router using the factory default settings (for example, after a firmware upgrade or if you have saved an incorrect configuration), select Factory De...
Page 71 - User Management; You are able to Edit existing users and Add
User Management In order to prevent unauthorized access to your router’s configuration interface, it requires all users to login with a password. You can set up multiple user accounts, each with their own password. You are able to Edit existing users and Add new users who are able to access the devi...
Page 73 - Firewall and Access Control; NAT natural firewall:; firewall is turned on when NAT function is enabled.
Firewall and Access Control Your router includes a full SPI (Stateful Packet Inspection) firewall for controlling Internet access from your LAN, as well as helping to prevent attacks from hackers. Besides, when using NAT, the router acts as a “natural” Internet firewall, as all PCs on your LAN will ...
Page 74 - General Settings; the predefined port filter rules for High, Medium and Low
Listed are the items under the Firewall section: General Settings, Packet Filter, Intrusion Detection, URL Filter, IM/P2P Blocking and Firewall Log. General Settings You can choose not to enable Firewall and still able to access to URL Filter and IM/P2P Blocking or enable the Firewall using preset f...
Page 75 - Packet Filter; preset
disable. Mostly it is for preventing any scan tools from WAN site by hacker. Packet Filter This function is only available when the Firewall is enabled and one of these four security levels is chosen (All blocked, High, Medium and Low). The preset port filter rules in the Packet Filter must modify a...
Page 76 - Predefined; Start End Inbound Outbound Inbound Outbound Inbound Outbound
Example: Predefined Port Filters Rules The predefined port filter rules for High, Medium and Low security levels are listed. See Table 1. Note: Firewall – All Blocked/User-defined, you must define and create the port filter rules yourself. No predefined rule is being preconfigured. Table 1: Predefin...
Page 77 - Blocked; Packet Filter – Add TCP/UDP Filter; Users-define description to identify this entry or click “
Inbound: Internet to LAN Outbound: LAN to Internet YES: Allowed NO: Blocked N/A: Not Applicable Packet Filter – Add TCP/UDP Filter Rule Name Helper: Users-define description to identify this entry or click “ Select ” drop-down menu to select existing predefined rules. The maximum name length is 32 c...
Page 78 - Packet Filter – Add Raw IP Filter; Users-define description to identify this entry or
Packet Filter – Add Raw IP Filter Go to “ Type ” drop-down menu, select “ Use Protocol Number ” . Rule Name Helper: Users-define description to identify this entry or choosing “ Select ” drop-down menu to select existing predefined rules. Time Schedule: It is self-defined time period. You may specif...
Page 79 - HTTP to your router is not allowed.
As you can see from the diagram below, when the firewall is enabled with one of the three presets (Low/Medium/High), inbound HTTP access is not allowed which means remote access through HTTP to your router is not allowed. Note: Inbound indicates accessing from Internet to LAN and Outbound is from LA...
Page 80 - Configuring Packet Filter:; to how you add a filter on your own.
Configuring Packet Filter: Click Packet Filters. You will then be presented with the predefined port filter rules screen (in 1. this case for the low security level), shown below: Note: You may click Edit the predefined rule instead of Delete it. This is an example to show to how you add a filter on...
Page 83 - Intrusion Detection; ICMP flood
Intrusion Detection The router’s Intrusion Detection System (IDS) is used to detect hacker attacks and intrusion attempts from the Internet. If the IDS function of the firewall is enabled, inbound packets are filtered and blocked depending on whether they are detected as possible hacker attacks, int...
Page 84 - Back Orifice Scan; Max TCP Open
cannot protect against such attacks. Table 2: Hacker attack types recognized by the IDS Intrusion Name Detect Parameter Blacklist Type of Block Duration Drop Packet Show Log Ascend Kill Ascend Kill data Src IP DoS Yes Yes WinNuke TCP Port 135, 137~139, Flag: URG Src IP DoS Yes Yes Smurf ICMP type 8 ...
Page 86 - URL Filter; To enable or disable URL Filter feature.; Time; For example, if the URL is
URL Filter URL (Uniform Resource Locator – e.g. an address in the form of http://www.abcde.com or http:// www.example.com) filter rules allow you to prevent users on your network from accessing particular websites by their URL. There are no pre-defined URL filter rules; you can add filter rules to m...
Page 88 - from accessing other sites.; Restrict URL Features:; This function enhances the restriction to your URL rules.; Block surfing by IP address:; Preventing someone who uses the IP address as URL for skip-
Example: Andy wishes to disable all WEB traffic except for ones listed in the trusted domain, which would prevent Bobby from accessing other web sites. Andy selects both functions in the Domain Filtering and thinks that it will stop Bobby. But Bobby knows this function, Domain Filtering, ONLY disabl...
Page 89 - Instant Message Blocking; Peer to Peer Blocking:
IM / P2P Blocking IM, short for Instant Message, is required to use client program software that allows users to communicate , in exchanging text message, with other IM users in real time over the Internet. A P2P application, known as Peer-to-peer, is group of computer users who share file to specif...
Page 90 - Firewall Log
Firewall Log Firewall Log display log information of any unexpected action with your firewall settings. Check the Enable box to activate the logs. Log information can be seen in the Status – Event Log after enabling. 85
Page 91 - want the protocol of tunnel to be activated and vice versa.; PPTP Connection - Remote Access; Remote Access or LAN to LAN.
VPN - Virtual Private Networks (Only available for BiPAC 7404V(G)OX) Virtual Private Networks is ways to establish secured communication tunnels to an organization’s network via the Internet. Your router supports three main types of VPN (Virtual Private Network): PPTP, IPSec and L2TP . PPTP (Point-t...
Page 92 - not replaced the client.; Active as default route:
Username: If you are a Dial-Out user (client), enter the username provided by your Host. If you are a Dial-In user (server), enter your own username. Password: If you are a Dial-Out user (client), enter the password provided by your Host. If you are a Dial-In user (server), enter your own password. ...
Page 93 - Example: Configuring a Remote Access PPTP VPN Dial-out Connection
Example: Configuring a Remote Access PPTP VPN Dial-out Connection A company’s office establishes a PPTP VPN connection with a file server located at a separate location. The router is installed in the office, connected to a couple of PCs and Servers. 88
Page 94 - Keep as default value in most of the cases, PPTP server &
Configuring the PPTP VPN in the Office Click Configuration/VPN/PPTP. Choose Remote Access from Connect Type drop-down menu. You can either input the IP address (69.1.121.33 in this case) or hostname to reach the server. Function Description Name VPN_PPTP Given name of PPTP connection Connection Type...
Page 95 - PPTP Connection - LAN to LAN
PPTP Connection - LAN to LAN Click Configuration/VPN/PPTP. Choose LAN to LAN from Connect Type drop-down menu. Name: A given name for the connection (e.g. “connection to office”). Connection Type: Remote Access or LAN to LAN. Type: Check Dial Out if you want your router to operate as a client (conne...
Page 101 - IPSec VPN Connection; Set the IP address, subnet or address range of the local network.
IPSec VPN Connection Name: A given name for the connection (e.g. “connection to office”). Local Network: Set the IP address, subnet or address range of the local network. Single Address: The IP address of the local host. Subnet: The subnet of the local network. For example, IP: 192.168.1.0 with netm...
Page 102 - Perfect Forward Secrecy:
Remote ID: Identifier: Input remote ID’s information, like domain name www.ipsectest.com Hash Function: It is a Message Digest algorithm which coverts any length of a message into a unique set of bits. It is widely used MD5 (Message Digest) and SHA-1 (Secure Hash Algorithm) algorithms. SHA1 is more ...
Page 103 - Ping to the IP; Yes, activate it in every 2000; Disconnection Time after no traffic:; It is the NO Response time clock. When no traffic stage
unsecured communication channel (i.e. over the Internet). There are three modes, MODP 768-bit, MODP 1024-bit and MODP 1536-bit. MODP stands for Modular Exponentiation Groups. SA Lifetime: Specify the number of minutes that a Security Association (SA) will stay active before new encryption and authen...
Page 104 - Example: Configuring an IPSec LAN to LAN VPN Connection; Table 3: Network Configuration and Security Plan; Branch Office; Tunnel mode
Example: Configuring an IPSec LAN to LAN VPN Connection Table 3: Network Configuration and Security Plan Branch Office Head Office Local Network ID 192.168.0.0/24 192.168.1.0/24 Local Router IP 69.1.121.30 69.1.121.3 Remote Network ID 192.168.1.0/24 192.168.0.0/24 Remote Router IP 69.1.121.3 69.1.12...
Page 105 - Head office network
Configuring IPSec VPN in the Head Office Function Description Name IPSec_HeadOffice Give a name of IPSec Connection Local Network Subnet Select Subnet from Local Network drop-down menu. IP Address 192.168.1.0 Head office network Netmask 255.255.255.0 Remote Secure Gateway IP (or Hostname) 69.121.1.3...
Page 106 - Branch office network
Configuring IPSec VPN in the Branch Office Function Description Name IPSec_BranchOffice Give a name of IPSec Connection Local Network Subnet Select Subnet from Local Network drop-down menu. IP Address 192.168.0.0 Branch office network Netmask 255.255.255.0 Remote Secure Gateway IP (or Hostname) 69.1...
Page 107 - Example: Configuring an IPSec Host to LAN VPN Connection
Example: Configuring an IPSec Host to LAN VPN Connection 102
Page 109 - L2TP Connection-Remote Access
L2TP (Layer Two Tunneling Protocol) Two types of L2TP VPN are supported Remote Access and LAN-to-LAN (please refer below for more information.). Fill in the blank with information you need and click Add to create a new VPN connection account. Active: This function activates or deactivates the PPTP c...
Page 110 - Connection Type: Remote Access or LAN to LAN; Tunnel Authentication:; This is only valid when L2TP remote supports this feature.; Enter hostname of remote VPN device. It is a tunnel identifier; Local Host; a VPN tunnel. As default, Router’s default Hostname is
Connection Type: Remote Access or LAN to LAN Name: A given name for the connection (e.g. “connection to office”). Connection Type: Remote Access or LAN to LAN. Type: Check Dial Out if you want your router to operate as a client (connecting to a remote VPN server, e.g. your office server), check Dial...
Page 111 - Choose whether to enable PFS using Diffie-Hellman public-key
SHA1: A one-way hashing algorithm that produces a 160−bit hash. Encryption: Select the encryption method from the pull-down menu. There are four options, DES, 3DES, AES and NULL. NULL means it is a tunnel only with no encryption. 3DES and AES are more powerful but increase latency. DES: Stands for D...
Page 112 - Example: Configuring a L2TP VPN - Remote Access Dial-in Connection; connected to a couple of PCs and Servers.
Example: Configuring a L2TP VPN - Remote Access Dial-in Connection A remote worker establishes a L2TP VPN connection with the head office using Microsoft's VPN Adapter (included with Windows XP/2000/ME, etc.). The router is installed in the head office, connected to a couple of PCs and Servers. 107
Page 113 - Configuring L2TP VPN in the Office; IP is not used in the Office LAN.; Function; Keep this as the default value for most cases
Configuring L2TP VPN in the Office The input IP address 192.168.1.200 will be assigned to the remote worker. Please make sure this IP is not used in the Office LAN. Function Description Name VPN_L2TP Give a name of L2TP Connection Connection Type Remote Access Select Remote Access from the Connectio...
Page 114 - Example: Configuring a Remote Access L2TP VPN Dial-out Connection
Example: Configuring a Remote Access L2TP VPN Dial-out Connection A company’s office establishes a L2TP VPN connection with a file server located at a separate location. The router is installed in the office, connected to a couple of PCs and Servers. 109
Page 115 - Example: Configuring your Router to Dial-in to the Server
Configuring L2TP VPN in the Office The input IP address 192.168.1.200 will be assigned to the remote worker. Please make sure this IP is not used in the Office LAN. Function Description Name VPN_L2TP Give a name of L2TP Connection Connection Type Remote Access Select Remote Access from the Connectio...
Page 116 - L2TP Connection - LAN to LAN; L2TP VPN Connection
L2TP Connection - LAN to LAN L2TP VPN Connection Name: A given name for the connection Connection Type: Remote Access or LAN to LAN. Type: Check Dial Out if you want your router to operate as a client (connecting to a remote VPN server, e.g. your office server), check Dial In to have it operate as a...
Page 121 - VoIP - Voice over Internet Protocol; Here are the items within the VoIP section:
116 VoIP - Voice over Internet Protocol VoIP enables telephone calls through existing Internet connection instead of going through the PSTN (Public Switched Telephone Network). It is not only cost-effective, especially for a long distance telephone charges, but also toll-quality voice calls over the...
Page 122 - different SIP Service Provider.; SIP Device Parameters; phone while you talk. Default is set to Enable.
117 SIP Device Parameters This section provides easy setup for your VoIP service. Phone port 1 and 2 can be registered to different SIP Service Provider. SIP Device Parameters SIP: To use VoIP SIP as VoIP call signaling protocol. Default is set to Disable. Silence Suppression (VAD): Voice Activation...
Page 123 - Advanced – Parameters; VoIP through IP Interface:; Whenever VoIP S; Edit; Advanced – PSTN Environment Adjustment
118 Advanced – Parameters VoIP through IP Interface: IP Interface decides where to send/receive the voip traffic; it includes: ipwan and iplan. Easy way to select the interface is to check the location of the SIP server. If it locates some where in the Internet then select ipwan. If the VoIP SIP ser...
Page 125 - SIP Accounts; ser-defined name is for identifying the Profile.; Outbound Proxy Address:
120 SIP Accounts This section reflects and contains basic settings for the VoIP module from selected provider in the Wizard section. Fail to provide correct information will halt making calls out to the Internet. Profile Name: U ser-defined name is for identifying the Profile. Registrar Address (or ...
Page 126 - Phone Port; It allows you to change the phone port setting for specify FXS port.
121 Phone Port This section displays status and allows you to edit the account information of your Phones. Click Edit to update your phone information. Port: It allows you to change the phone port setting for specify FXS port. *69 (Return Call): Dial *69 to return the last missed call. It is only av...
Page 127 - Codec Preference; compression Priority 1 owns the top priority.; Volume Control
122 without waiting. Note: Refer to Special Dial Code section in this Manual for more details. Codec Preference Codec is known as Coder-Decoder used for data signal conversion. Set the priority of voice compression; Priority 1 owns the top priority. G.729: It is used to encoder and decoder voice inf...
Page 128 - PSTN Dial Plan (Router with LINE port only); The dialed number; Dial at Timeout no Prefix:; The dialed number will be sent call through the PSTN
123 PSTN Dial Plan (Router with LINE port only) This section enables you to configure “VoIP with PSTN switching” on your system. You can define a range of dial plans to make regular call from VoIP switching to PSTN line. Prefix numbers is essential key to make a distinguishing between VoIP and Regul...
Page 130 - PSTN Dial Plan Examples:; Dial with Prefix
125 PSTN Dial Plan Examples: Dial with Prefix 1. If you dial 01223 707070, number 01223707070 will be dialed out via FXO to make a regular phone call. Dial without Prefix 2. If you dial 9102, the number 102 will only be dialed out via FXO port to make a regular phone call. Dial at Timeout 3. If you ...
Page 132 - VoIP Dial Plan; Dial Plan Rules; Prepend xxx unconditionally:; number when making a call.
127 VoIP Dial Plan This section helps you to make a telephony number dialed as making a regular call via VoIP. You no longer need to memorize a long dial string of number for making a VoIP call. Go to Configuration > VoIP > VoIP Dial Plan. Dial Plan Rules Click the Add button to create and def...
Page 133 - Description; Any digit number between 0 and 9 in variable length. Maximum; Special Dial Plan; in variable length. Maximum length is 16.
128 Main Digit Sequence: The call(s) can be called out via SIP or PSTN or ENUM. x: Any numeric number between 0 and 9. . ( period ): Repeat numeric number(s) between 0 and 9. * (asterisk sign): It is normal character ‘* ’ on phone key pad. Please check if special service(s) is provided by your VoIP ...
Page 135 - Call Feature; feature, anonymous call feature and incoming no answer timer.; Speed Dial; automatically call out to number listed on entry 9.
130 Call Feature VoIP has all the basic features of a traditional phone. Besides the provided basic features, VoIP also comes with several enhanced features that allows you to further customize their settings to suit your personal needs such as call forwarding setting, call waiting time length, conf...
Page 137 - Tone Parameters; recommended that this option be configured by advance; Apply; to apply the settings.
132 Tone Parameters You may need to check with your local telephone service provider for such information. Also, it is recommended that this option be configured by advance d user unless you are instructed to do so. Click Apply to apply the settings.
Page 138 - QoS - Quality of Service; Here are the items within the QoS section:; Prioritization, Outbound IP Throttling & Inbound IP; Prioritization; There are three priority settings to be provided in the Router:
133 QoS - Quality of Service QoS function helps you to control your network traffic for each application from LAN (Ethernet and/or Wireless) to WAN (Internet). It facilitates you to control the different quality and speed of through put for each application when the system is running with full loadi...
Page 139 - DSCP Mapping Table; checking the DSCP through-out the QoS network.; Best Effort
134 Destination IP address Range : The destination IP address or range of packets to be monitored. Destination Port : The destination port of packets to be monitored. DSCP Marking : Differentiated Services Code Point (DSCP), it is the first 6 bits in the ToS byte. DSCP Marking allows users to assign...
Page 140 - : To limit the speed of outbound traffic; Source IP Address Range; : The source IP address or range of packets to be monitored.; Destination IP Address Range; : The destination IP address or range of packets to be monitored.
135 information. Protocol : The name of supported protocol. Rate Limit : To limit the speed of outbound traffic Source IP Address Range : The source IP address or range of packets to be monitored. Source Port(s) : The source port of packets to be monitored. Destination IP Address Range : The destina...
Page 142 - QoS for your Network; Connection Diagram; Restricted PC
137 Example: QoS for your Network Connection Diagram Restricted PC Normal PCs VoIP
Page 143 - Information and Settings
138 Information and Settings Upstream: 928 kbps Downstream: 8 Mbps VoIP User : 192.168.1.1 Normal Users : 192.168.1.2~192.168.1.5 Restricted User: 192.168.1.100
Page 144 - packets as high priority.; Restricted Application
139 Mission-critical application Mostly the VPN connection is mission-critical application for doing data exchange between head and branch office. The mission-critical application must be sent out smoothly without any dropping. Set priority as high level for preventing any other applications to satu...
Page 145 - only limit utilization at daytime.; Advanced setting by using IP throttling; located in the same level.
140 With above settings that help to limit utilization of upstream of FTP. Time schedule also help you to only limit utilization at daytime. Advanced setting by using IP throttling With IP throttling you can specify more detail for allocating bandwidth; even the applications are located in the same ...
Page 146 - restricted application.
141 Sometime your customers or friends may upload their files to your FTP server and that will saturate your downstream bandwidth. The settings below help you to limit bandwidth for the restricted application.
Page 147 - Virtual Server (known as Port Forwarding); if you want to host an online game server.
142 Virtual Server (known as Port Forwarding) In TCP/IP and UDP networks a port is a 16-bit number used to identify which application program (usually a server) incoming connections should be delivered to. Some ports have numbers that are pre-assigned to them by the IANA (the Internet Assigned Numbe...
Page 148 - Add Virtual Server; Application; to select an existing predefined rules.; Protocol; User; Time Schedule; section; Internal IP Address:; address and MAC from this list.
143 Add Virtual Server Because NAT can act as a “natural” Internet firewall, your router protects your network from being accessed by outside users when using NAT, as all incoming connection attempts will point to your router unless you specifically create Virtual Server entries to forward those por...
Page 150 - used by any other Virtual Server entries.; radio button is
145 Edit DMZ Host The DMZ Host is a local computer exposed to the Internet. When setting a particular internal IP address as the DMZ Host, all incoming packets will be checked by the Firewall and NAT algorithms then passed to the DMZ host, when a packet received does not use a port number used by an...
Page 151 - button to apply your changes.
146 Edit One-to-One NAT (Network Address Translation) One-to-One NAT maps a specific private/local IP address to a global/public IP address. If you have multiple public/WAN IP addresses from you ISP, you are eligible for One-to-One NAT to utilize these IP addresses. Go to Configuration > Virtual ...
Page 153 - For further information, please see IANA’s website at; numbers; please see the FAQs (Frequently Asked Questions) at; Port Number; World Wide Web HTTP
148 Example: List of some well-known and registered port numbers. The Internet Assigned Numbers Authority (IANA) is the central coordinator for the assignment of unique parameter values for Internet protocols. Port numbers range from 0 to 65535, but only ports numbers 0 to 1023 are reserved for priv...
Page 155 - Configuration of Time Schedule; Edit a Time Slot; A detailed setting of this Time Slot will be shown.
150 Configuration of Time Schedule Edit a Time Slot Choose any Time Slot (ID 1 to ID 16) to edit, click Edit radio button. 1. Note: Watch it carefully, the days you have selected will present in capital letter. Lower case letter shows the day(s) is not selected, and no rule will apply on this day(s)...
Page 156 - Delete a Time Slot; Delete button
151 Delete a Time Slot Select the Delete radio button of the selected Time Slot under the Time Slot section, and click the Edit/ Delete button to confirm the deletion of the selected Time profile, i.e. erase the Day and back to default setting of Start Time / End Time.
Page 157 - Advanced; Device Management, IGMP; Static Route
152 Advanced Configuration options within the Advanced section are for users who wish to take advantage of the more advanced features of the router. Users who do not understand the features should not attempt to reconfigure their router, unless advised to do so by support staff. Here are the items w...
Page 158 - Dynamic DNS
153 Dynamic DNS The Dynamic DNS function allows you to alias a dynamic IP address to a static hostname, allowing users whose ISP does not assign them a static IP address to use a domain name. This is especially useful for hosting servers via your ADSL connection, so that anyone wishing to connect to...
Page 159 - Check Email; section of this manual for more information.
154 Check Email This function allows you to have the router check your POP3 mailbox for new Email messages. The Mail LED on your router will light when it detects new messages waiting for download. You may also view the status of this function using the Status – Email Checking section of the web int...
Page 160 - Device Management; security options and device monitoring features.; Device Host Name; Assign it a name; Embedded Web Server ( 2 Management IP Accounts); You may specify an IP address allowed to logon and access the
155 Device Management The Device Management advanced configuration settings allow you to control your router’s security options and device monitoring features. Device Host Name Host Name: Assign it a name . (The Host Name cannot be used with one word only. There are two words should be connected wit...
Page 161 - function) – Simple Network Management Protocol.; SNMP Version: SNMPv2c and SNMPv3
156 For Example: User A changes HTTP port number to 100 , specifies their own IP address of 192.168.1.55 , and sets the logout time to be 100 seconds. The router will only allow User A access from the IP address 192.168.1.55 to logon to the Web GUI by typing: http://192.168.1.254:100 in their web br...
Page 162 - ICMP Group
157 for “security”, but is widely accepted as the SNMPv2 standard. SNMPv3 is a strong authentication mechanism, authorization with fine granularity for remote monitoring. Traps supported: Cold Start, Authentication Failure. The following MIBs are supported: From RFC 1213 (MIB-II) System group System...
Page 163 - IGMP; Accepting multicast packet. Default is set to Enable.; VLAN Bridge; Edit your member ports in selected VLAN group.
158 IGMP IGMP, known as Internet Group Management Protocol, is used to management hosts from multicast group. IGMP Forwarding: Accepting multicast packet. Default is set to Enable. IGMP Snooping: Allowing switched Ethernet to check and make correct forwarding decisions. Default is set to Disable. VL...
Page 164 - logging out of the system.
159 Logout To exit the router web interface, choose Logout. Please save your configuration setting before logging out of the system. Be aware that the router configuration interface can only be accessed by one PC at a time. Therefore when a PC has logged into the system interface, the other users ca...
Page 165 - Problems with the router
160 Chapter 5: Troubleshooting If your router is not functioning properly, please refer to the suggested solutions provided in this chapter. If your problems persist or the suggested solutions do not meet your needs, please kindly contact your service provider or Billion for support. Problems with t...
Page 166 - Check the Ethernet LEDs on the front panel. The LED
161 Problem with LAN interface Problem Suggested Action Cannot PING any PC on LAN Check the Ethernet LEDs on the front panel. The LED should be on for the port that has a PC connected. If it does not lit, check to see if the cable between your router and the PC is properly connected. Make sure you h...
Page 167 - purchased your product.; Contact Billion
162 Appendix: Product Support & Contact Following the suggestions listed in the Troubleshooting section of the user manual can help you solve most of your problems. However if your problems persist or you come across other technical issues that are not listed in the Troubleshooting section, plea...