Page 2 - ZyWALL 2WG Support Notes; INDEX; Access control and security VPN connection (Security policy
ZyWALL 2WG Support Notes 2 INDEX Application Notes ...................................................................................................... 9 Mobility Internet Access ........................................................................................9 Utilize 3G and Wireless for t...
Page 6 - E24. How does the ZyXEL content filtering handle dynamically
ZyWALL 2WG Support Notes 6 E15. How many URL keywords does ZyWALL support?.................... 240 E16. How do I keep database of Content Filtering service updated? . 241 E17. What is BlueCoat Filter list? .......................................................... 241 E18. How many ratings does the ...
Page 8 - G16. Will Self-signed certificate be erased if I reset to default
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 8 G16. Will Self-signed certificate be erased if I reset to default configuration file? .................................................................................... 259 G17. Will certificates stored in...
Page 9 - Application Notes; Mobility Internet Access; provide wireless access for your LAN users.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 9 Application Notes Mobility Internet Access You may have the experienced a need of Internet access in a location where wired connection is difficult to deploy, e.g. in countryside or mountain. Or you are just...
Page 10 - Utilize 3G and Wireless for the Internet Access; Following we will show you how to configure it step-by-step.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 10 Utilize 3G and Wireless for the Internet Access Following we will show you how to configure it step-by-step. Utilize 3G card to get Internet access 1). Plug the 3G card to ZyWALL 2WG's card slot before powe...
Page 13 - Utilize the embedded wireless card to provide LAN users access
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 13 Utilize the embedded wireless card to provide LAN users access 1). Go to GUI menu Network > WIRELESS CARD, enable it and configure the other parameters like 802.11 mode (four modes available: 802.11b onl...
Page 14 - further configure it.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 14 To configure the security and the MAC filter, go to Wireless Card > Security or Wireless Card > MAC Filter to further configure it. For example, we would like to provide the wireless access clients wi...
Page 17 - of wireless card setting as shown
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 17 After you have configured the Security and MAC filter profiles, you can choose them in the main page of wireless card setting as shown
Page 18 - Seamless Incorporation into your network; Using Transparent (Bridge Mode) Firewall
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 18 Seamless Incorporation into your network Using Transparent (Bridge Mode) Firewall If user wants to insert a firewall into current network, IP setting of hosts and servers may need to change. Following examp...
Page 21 - ZyWALL will restart after applying the change.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 21 assign a management IP for ZyWALL. The Gateway IP Address is used as next-hop of default route. ZyWALL will restart after applying the change. (Note: Here we suggest admin to dedicate an IP address to ZyWAL...
Page 22 - Go to
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 22 Step3. After rebooting, login ZyWALL’s GUI by accessing ZyWALL’s management IP address. (Accessing ZyWALL by the PC with a static IP address configured in the same subnet or with an IP from DHCP server (ref...
Page 24 - Internet Connection; configure ZyWALL to gain the Internet access.; ZyWALL; menu and click; LAN; Internet
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 24 Internet Connection A typical Internet access application of the ZyWALL is shown below. This section guides you how to configure ZyWALL to gain the Internet access. ZyWALL Step1. First of all, Select Home m...
Page 25 - Following picture is an example while PPPoE is selected.; Finish; ” button to apply the setting
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 25 Following picture is an example while PPPoE is selected. Once the required information is correctly configured, click on the “ Finish ” button to apply the setting and then you have finished configuring Int...
Page 26 - gateway and DNS to the associated clients.; inside; network and the other is the; outside; preventing intruders from probing your network.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 26 2. When choosing DHCP setting as a ‘Server’, the LAN will automatically assign IP, subnet, gateway and DNS to the associated clients. 3. When choosing DHCP setting as a ‘Relay’, the LAN will forward the DHC...
Page 27 - How NAT works; One to One; In Many One to One, the ZyWALL maps each ILA to unique IGA.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 27 • How NAT works If we define the local IP addresses as the Internal Local Addresses (ILA) and the global IP addresses as the Inside Global Address (IGA), see the following figure. The term 'inside' refers t...
Page 28 - Server; each server to one unique IGA please use the One-to-One mode.; NAT Type; Overload
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 28 5. Server In Server mode, the ZyWALL maps multiple inside servers to one global IP address. This allows us to specify multiple servers of different types behind the NAT for outside access. Note, if you want...
Page 29 - Step 1. Applying NAT in WAN Interface
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 29 Step 1. Applying NAT in WAN Interface You can choose the NAT mapping types to either SUA Only or Full Feature in WAN setup. NETWORK -> WAN or ADVANCED -> NAT -> NAT Overview
Page 30 - Key Settings; Step 2. Configuring NAT Address Mapping
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 30 Key Settings Field Options Description Full Feature Set to 'Full Feature' if there are multiple IP addresses given by ISP and can assigned to your clients. Routing Set to 'Routring' if you clients use Inter...
Page 31 - the following way using 4 NAT rules.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 31 Step 3. Using Multiple Global IP addresses for clients and servers (One-to-One, Many-to-One, Server Set mapping types) In this case we have 3 IGAs (IGA1, IGA2 and IGA3) from the ISP. We have two very busy i...
Page 32 - When we have configured all four rules in the rule summary page.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 32 Rule 2 Setup: Selecting One-to -One type to map the FTP Server 2 with ILA2 (192.168.1.11) to IGA2 (200.1.1.2). Rule 3 Setup: Select Many-to-One type to map the other clients to IGA3. Rule 4 Setup: Select Se...
Page 34 - Application for Non NAT Friendly Support
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 34 Application for Non NAT Friendly Support Some servers providing Internet applications such as some mIRC servers do not allow users to login using the same IP address. In this case it is better to use Many O...
Page 35 - Optimize network performance & availability; Using Bandwidth Management
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 35 Optimize network performance & availability Using Bandwidth Management Why Bandwidth Management (BWM)? Nowadays, we have many different traffic types for Internet applications. Some traffic may consume ...
Page 36 - How Bandwidth Management in ZyWALL?; Bandwidth Borrowing; from the interface.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 36 How Bandwidth Management in ZyWALL? ZyWALL achieves BWM by classifying packets, and control when to send out the classified packets. Bandwidth Management of ZyXEL appliances operates on the IP layer. The ma...
Page 39 - Scenario
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 39 Source IP Address Enter the IP address of source that meats this class. Note that for traffic from 'LAN to WAN' , since BWM is before NAT, you should use the IP address before NAT processing. Source Subnet ...
Page 40 - then click on “Add Sub-Class” to create and add a new class under root.; Service; as FTP
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 40 Step1. Activate Bandwidth Management on the interface on which you want to control. In this example, it is LAN. Assign 2048Kbps to LAN interface. Step2. Go to “Class Setup” and select LAN from the drop-down...
Page 42 - Select the; address as Destination IP Address.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 42 Step4. Add another service and allocate 800kbps for IPTV user and destined to Media traffic to IPTV user. Select the Service as Custom from drop-down list and set Protocol IP as 17 (UDP). Input IPTV user’s ...
Page 43 - Secure Connections across the Internet; locations with encryption technology.; Configure ZyWALLs with Static WAN IP Address
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 43 Secure Connections across the Internet Site-to-Site VPN (Intranet) Scenario A site-to-site VPN protects the network resources on your protected networks from unauthorized use by users on an unprotected netw...
Page 44 - Remote Gateway Address
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 44 1) Configure the static Public IP address to WAN interface through Network-> WAN-> WAN IP Address Assignment 2) Enter the WAN IP address as My Address in Gateway Policy 3) On peer VPN gateway, use the...
Page 46 - My Domain
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 46 4) Configure the DDNS entry under DNS-> DDNS and bind it to a WAN interface. 5) Under Gateway Policy menu, select the DDNS entry from drop-down list and use it as My Domain Name. 6) Configure the DDNS en...
Page 47 - ZyWALL behind NAT router.; NAT Traversal; ” no matter if the front NAT router supports NAT Traversal
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 47 placed behind the NAT router. For example, the NAT router has a different interface (e.g. leased line, ISDN) which are not supported by IPSec gateway. This example gives some guideline for configuring ZyWAL...
Page 48 - private IP address
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 48 when peer VPN entity also support NAT Traversal function. If yes, the IPSec traffic will be encapsulated in UDP packet to avoid traversal problem on NAT routers. 4) Under VPN->Gateway Policy-> Gateway...
Page 49 - WAN
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 49 The configuration goal is to achieve following two: 1) Setup VPN rule to allow PC1 to access Dept.1 through the tunnel between GW1 & GW2 2) Setup VPN rule to allow PC2 to access Dept.2 through the tunne...
Page 50 - Click on “Apply” to save profile
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 50 6) Extended Authentication (xAuth) can be enabled or not depending on your application. For detailed info, you can refer to XXX. 7) Under “IKE Proposal”, select the Encryption and Authentication Algorithm. ...
Page 51 - the event of SA Lifetime expires, failure on the link.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 51 10) Click on the icon to add a new “Network Policy” over the configured Gateway Policy. 11) Activate the profile and name this policy as “PC1-to-Dept1” in this example. Enable “Nailed-Up” option if you need...
Page 53 - Follow the same procedures as step 10~16 to add 2; Using Certificate for Device Authentication; Digital Signatures
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 53 18) Follow the same procedures as step 10~16 to add 2 nd Network Policy, PC2-to-Dept2. Finish Using Certificate for Device Authentication IKE must authenticate the identities of the systems using the Diffie...
Page 54 - Online Enroll Certificates; Using Self-signed Certificates; be exchanged and imported into; Trusted Remote Hosts; before making a VPN connection.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 54 DNS, E-mail, Subject Name and Any . Depending how certificates are generated, it can be classified into three methods: 1) Using Self-signed Certificates (both entities must be ZyXEL IPSec gateway) 2) Online...
Page 55 - you login to ZyWALL.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 55 The factory default self-signed certificates are the same on all ZyWALL models. It is not secure to use the default self-signed certificate. To make the self-signed certificate unique for this device, you s...
Page 56 - Or mark the certificate in
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 56 2) Or mark the certificate in PEM (Base-64) Encoded Format and then copy to a test editor (e.g. Notepad) and then save to you local computer in PEM (Base-64) Encoded Format. Then import the certificate to t...
Page 57 - Therefore, configure Peer ID Type and content on peer ZyWALL.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 57 When you configure VPN rule with certificate, select Certificate under VPN-> Gateway Policy. Select My Certificate from the drop-down list. When (My) certificate is selected, ZyWALL will show what is the...
Page 58 - enroll certificates.; ZyWALL A; Step 1. Download CA server's Certificate
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 58 servers, and finally get a certificate for further usage. ZyWALL supports both SCEP and CMP protocols as methods of online enrollment. Both SCEP and CMP online enrollment protocols provide secure mechanisms...
Page 59 - either enter them or not.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 59 Step 2. Create certificate request and enroll certificate request on ZyWALL A 1. Input a name, for this Certificate so you can identify this Certificate later. 2. In Subject Information, give this certifica...
Page 62 - Step 4. Using Certifica e in VPN on ZyWALL A; Activate the rule
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 62 After pressing the Apply button, ZyWALL would create the certification request and send it to the CA server for enrollment. After CA server agrees to issue the corresponding certificate, ZyWALL will receive...
Page 63 - You can check detailed settings by clicking Advanced button.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 63 13. You can check detailed settings by clicking Advanced button.
Page 64 - Step 5. Using Certifica e in VPN on ZyWALL B
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 64 Step 5. Using Certifica e in VPN on ZyWALL B t 1. Activate the rule 2. Give this VPN rule a name "toZyWALL_A" 3. Select Key Management to "IKE" 4. Select Negotiation Mode to "Main" 5...
Page 66 - Offline Enroll Certificates; Windows 2000 server in this example. The whole procedure includes
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 66 Offline Enroll Certificates In this guide, we describe how ZyWALL devices, both ZyWALL A and ZyWALL B as IPSec/VPN tunnel end points, authenticate each other through PKI. We use CA (Certificate Authority) s...
Page 67 - Step 1. Create Certificate Reques on ZyWALL A; Go to VPN->My Certificates -> Click Create button.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 67 LAN 1 ZyWALL A ZyWALL B LAN 2 10.1.133.0/24 LAN: 10.1.133.1 WAN: 192.168.1.35 LAN: 192.168.2.1 WAN: 192.168.1.36 192.168.2.0/24 t Step 1. Create Certificate Reques on ZyWALL A 1. Go to VPN->My Certificat...
Page 69 - Click Details to export the request.; Step 2. Enroll Certificate Request; mouse, and select Copy. Keep your copy in clipboard for later paste.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 69 5. In My Certificates tab, you can get a new entry in grey color. This is the Certificate Request you just created. Click Details to export the request. Step 2. Enroll Certificate Request 1. Copy the conten...
Page 77 - Specify the path to store your exported Certificate.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 77 11. Choose DER encoded binary X.509(.CER), then press Nxet>, 12. Specify the path to store your exported Certificate.
Page 79 - certificate is successful.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 79 16. After a while, if you see the gray entry turns to a black one, then it means the import of ZyWALL's certificate is successful. 17. Repeat the same procedure from 9 to 13, to export CA's certificate. Not...
Page 80 - Step 3. Create Certificate Reques on ZyWALL_B
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 80 After import CA's certificate, you will get this display. t Step 3. Create Certificate Reques on ZyWALL_B 1. Go to VPN->My Certificates -> Click Create button.
Page 83 - Step 4. Enroll Certificate Request on ZyWALLB
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 83 Step 4. Enroll Certificate Request on ZyWALLB 1. Copy the content of Certificate in PEM Encoded Format, by selecting all of the content, then right click your mouse, and select Copy. Keep your copy in clipb...
Page 94 - Step 5. Using Certifica e in VPN on ZyWALL A
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 94 18. After import CA's certificate, you will get this display. Step 5. Using Certifica e in VPN on ZyWALL A t 1. Activate the rule 2. Give this VPN rule a name "toZyWALL_B" 3. Select Key Management t...
Page 97 - Step 6. Using Certificate in VPN
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 97 Step 6. Using Certificate in VPN on ZyWALL B 1. Activate the rule 2. Give this VPN rule a name "toZyWALL_A" 3. Select Key Management to "IKE" 4. Select Negotiation Mode to "Main" 5. ...
Page 99 - Using Pre-Shared Key for Device Authentication
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 99 Using Pre-Shared Key for Device Authentication The IKE protocol also provides primary authentication - verifying the identity of the remote system before negotiating the encryption algorithm and keys. Two k...
Page 100 - If “; ID Type; If “; Setup VPN in Branch Office A
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 100 Pre-Shared Key must be identical on both entities Local ID Type & Content on Local ZyWALL must be identical as Peer ID Type & Content on Peer VPN gateway Configuration on Peer VPN gateway Configura...
Page 101 - The IP addresses we use in this example are as shown below.; Setup VPN in branch office A
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 101 As the figure shown below, each branch office have a VPN tunnel to headquarter, thus PCs in branch offices can access systems in headquarter via the tunnel. Through VPN routing, ZyWALL series now provide y...
Page 102 - check Active check box and give a name to this policy.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 102 2. check Active check box and give a name to this policy. 3. Give this VPN rule a name, Branch_A. 4. Select Key Management to IKE and Negotiation Mode to Main. 5. In Local section, select Address Type to R...
Page 104 - Setup VPN in branch office B
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 104 2. Setup VPN in branch office B Be very careful about the remote IP address in branch office B, because for systems behind branch office B want to systems behind branch office A and headquarter, we have to...
Page 106 - , so that local management traffic from; Setup VPN in Headquar er; The correspondent rule for Branch_A in headquarter
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 106 Note that since Branch B's LAN is also included in remote polic y, please go to ZyWALL's SMT menu 24.8 CI command mode, and issue this command, "ipsec swSkipOverlapIp on" , so that local management...
Page 108 - The correspondent rule for Branch_B
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 108 2. The correspondent rule for Branch_B
Page 110 - NAT over IPSec on ZyNOS
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 110 NAT over IPSec on ZyNOS Network Topology The above is an IPSec VPN application running in tunnel mode. In the network topology shown, both the local area networks (LAN) are assigned with the same network I...
Page 112 - STEP 2: Create the Gateway Policy (Phase 1) on the ZyWALL 1 and ZyWALL 2
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 112 ZyWALL 2 (Remote) STEP 2: Create the Gateway Policy (Phase 1) on the ZyWALL 1 and ZyWALL 2 Click Security > VPN > Add Gateway Policy in order to add a new IPSec VPN Gateway Policy. Assign “My Address...
Page 113 - Gateway Policy on ZyWALL 1
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 113 Gateway Policy on ZyWALL 1 Click “Apply” in order to complete the settings. Repeat the steps for ZyWALL 2.
Page 114 - Gateway Policy on ZyWALL 2
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 114 Gateway Policy on ZyWALL 2 Gateway Policy on ZyWALL 2 STEP 3: Create the Network Policy (Phase 2) on the ZyWALL 1 and ZyWALL 2 After completing the settings for the “Gateway Policy”, click “Add Network Pol...
Page 116 - Click “Apply” in order to complete the setting.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 116 On ZyWALL 1, the remote network will be changed to 172.16.3.0. Click “Apply” in order to complete the setting. Repeat the steps for ZyWALL 2 in order to configure Network Policy.
Page 117 - STEP 4: Establish the IPSec VPN Tunnel Connection
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 117 On ZyWALL 2, the Virtual IP Addresses starts from 172.16.3.1 to 172.16.3.254. STEP 4: Establish the IPSec VPN Tunnel Connection
Page 118 - click “Return” to back to VPN page.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 118 Click Security > VPN > Connect in order to establish the IPSec VPN Tunnel connection. Once the IPSec works correctly, you will see the message as it appears in the following screenshot, and click “Re...
Page 119 - Ping the local gateway.; Never lost your VPN connection (IPSec High Availability); Setup ZyWALL VPN with high availability
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 119 1) Ping the local gateway. 2) Ping the IPSec Remote Gateway 3) Ping the remote host with virtual IP address that’s located on the remote network. Never lost your VPN connection (IPSec High Availability) 1....
Page 120 - administrator to configure the network setting.; Add; button
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 120 The VPN high availability is design for securing VPN connection. Normally we will deploy the ZyWALL2 Plus as branch office or SOHO gateway and build up the VPN tunnel to central office. The design for IPSe...
Page 123 - Setup ZyWALL VPN with access control - Firewall; IPSec Tunnel; IPSec Local Gateway; How to configure access control rule over VPN; default is
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 123 Access control and security VPN connection (Security policy enforcement IPSec) Setup ZyWALL VPN with access control - Firewall Setup ZyWALL VPN with web filtering rule – Content Filter Normally, the traffi...
Page 125 - Click the Insert button to insert a new rule.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 125 4. Click the Insert button to insert a new rule. 5. Edit the source and destination address as 192.168.2.33 and 192.168.1.0/255.255.255.0
Page 126 - The service type is; Any; to block all kind of traffic from 192.168.2.33 to access LAN subnet; Action for Matched Packets; is; Drop; and then click apply to save and activate the
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 126 6. The service type is Any to block all kind of traffic from 192.168.2.33 to access LAN subnet and Action for Matched Packets is Drop and then click apply to save and activate the configuration.
Page 128 - How to configure Web filtering rule over VPN – Content Filter
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 128 How to configure Web filtering rule over VPN – Content Filter 1. The switch to enable the content filtering over VPN traffic is available in Content Filter general configuration page. The content filtering...
Page 130 - ZyWALL vs 3rd Party VPN Gateway; SonicWALL with ZyWALL VPN Tunneling; Setup ZyWALL VPN; the tunneling endpoints are ZyWALL router and SonicWALL router.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 130 ZyWALL vs 3rd Party VPN Gateway SonicWALL with ZyWALL VPN Tunneling 1. Setup ZyWALL VPN 2. Setup SonicWALL VPN This page guides us to setup a VPN connection between the ZyWALL and SonicWALL router. As the ...
Page 133 - Check; Active; check box and give a name to this policy.; ToSonicWALL; IKE policy for your IPSec
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 133 18. Check Active check box and give a name to this policy. 19. On Gateway Policy Information, you should choose ToSonicWALL IKE policy for your IPSec rule.
Page 135 - Setup SonicWALL VPN; Enable VPN; check box, and then press; button, it will bring up a page which; VPN Policy Wizard; to set up your VPN rules as
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 135 23. When you finished doing your settings, you will see the following page. 2. Setup SonicWALL VPN (We choose SonicWALL TZ150 device in this example.) 1. Using a web browser, login SonicWALL by giving the ...
Page 138 - When your VPN tunnel is up, you will see the following page.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 138 6. When you finished doing your settings, you will see the following page. 7. When your VPN tunnel is up, you will see the following page.
Page 139 - NetScreen with ZyWALL VPN Tunneling; the tunneling endpoints are ZyWALL router and NetScreen router.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 139 NetScreen with ZyWALL VPN Tunneling 1. Setup ZyWALL VPN 2. Setup NetScreen VPN This page guides us to setup a VPN connection between the ZyWALL and NetScreen router. As the figure shown below, the tunnel b...
Page 140 - PC 1
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 140 The IP addresses we use in this example are as shown below. PC 1 ZyWALL Netscreen PC2 192.168.2.33 WAN: 172.22.3.89 LAN: 192.168.2.1 WAN: 172.22.1.251 LAN: 192.168.1.1 192.168.1.36 1. Setup ZyWALL VPN 24. ...
Page 144 - Setup NetScreen VPN; Check your WAN/LAN IP address; Click; Network; used for
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 144 14. When you finished doing your settings, you will see the following page. 2. Setup NetScreen VPN (We choose NetScreen-5GT device in this example.) 3. Using a web browser, login NetScreen by giving the LA...
Page 146 - DES; for; Encryption Algorithm; and; Authentication Algorithm
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 146 6. On Security Level settings, you could set up phase 1 IKE rules. In this example, select User Defined, and choose pre-g1-des-md5 rule. The pre-g1-des-md5 means Pre-Share Key, group1, DES for Encryption A...
Page 151 - Check Point with ZyWALL VPN Tunneling
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 151 18. Move your policy rules to top, thus your device will check the rule at first. 19. Click VPNs -> Monitor Status, this page displays a table that lists all the VPN groups configured on the NetScreen d...
Page 152 - shown in the following figure,; the tunneling endpoints are ZyWALL router and a PC which uses
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 152 This page guides us to setup a VPN connection between the ZyWALL and a PC which uses Check Point software. As the figure shown below, the tunnel between PC1 and PC2 ensures the packet flows between them ar...
Page 156 - Setup CheckPoint VPN
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 156 13. On IPSec Proposal, select Encapsulation Mode to Tunnel, Active Protocol to ESP, Encryption Algorithm to DES and Authentication Algorithm to SHA1 , and then press Apply button on this page. 14. After yo...
Page 157 - check point object is; Check Point Gateway; not a; Convert To Gateway; to change its settings.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 157 1. on your PC, clicking Start->Programmer->Check Point SmartConsole R60 -> SmartDashboard 2. Enter your user name and password, then press OK button to use your Check Point. 3. On Network Objects,...
Page 158 - General Properties; field is the; WAN IP of your PC; type; Check Point Products; check box
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 158 6. On General Properties , the IP Addrrss field is the WAN IP of your PC . In this example, you should type 172.22.2.58 IP address on the text box. On Check Point Products settings, check VPN check box her...
Page 159 - On; Topology
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 159 7. On Topology settings, you should see two interfaces of IP settings here if your PC has two network cards.
Page 161 - II. Setup Interoperable Device
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 161 II. Setup Interoperable Device 10. On the main menu, click Manage -> Network Objects .
Page 162 - You will see the network objects window, press; new; button and select; Interoperable Device
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 162 11. You will see the network objects window, press new button and select Interoperable Device .
Page 163 - example, the IP address is ZyWALL’s WAN IP address.; button to add a new interface.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 163 12. On General Properties settings, give a name and an IP address for the Interoperable Device. In this example, the IP address is ZyWALL’s WAN IP address. 13. On Topology settings, pressing Add button to ...
Page 164 - example, you should assign ZyWALL’s WAN port settings.; press OK button to save the settings.; button to add another interface.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 164 14. Giving a name for the interface, and assign the IP address/ subnet mask for the interface. In this example, you should assign ZyWALL’s WAN port settings. 15. Clicking Topology screen, and choose Extern...
Page 165 - example, you should assign ZyWALL’s LAN port settings.; Network defined by; for the interface, then press; OK; button to save the settings.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 165 17. Giving a name for the interface, and assign the IP address/ subnet mask for the interface. In this example, you should assign ZyWALL’s LAN port settings. 18. Clicking Topology screen, choose Internal (...
Page 166 - Pressing OK button to save the settings.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 166 19. Pressing OK button to save the settings.
Page 168 - Networks; object and click the right button of your mouse, and choose; New Network
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 168 20. Selecting Networks object and click the right button of your mouse, and choose New Network . 21. Give a name for your network policy, and set the network IP address to 192.168.1.0/24 . Then, press OK b...
Page 169 - To add another network policy, and set the network IP address; IV. Setup VPN Communities; Click VPN communities tab to do the settings.; New
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 169 22. To add another network policy, and set the network IP address 192.168.2.0/24 . Then, press OK button to save the settings. IV. Setup VPN Communities 23. Click VPN communities tab to do the settings. 24...
Page 170 - Center Gateways; button to add a center gateway.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 170 26. On Center Gateways settings, press Add button to add a center gateway.
Page 171 - gateway, and then press; button to add a remote gateway.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 171 27. If you have already done the previous settings, you should see a central gateway here. Select the gateway, and then press OK button. 28. On Satellite Gateways settings, press Add button to add a remote...
Page 173 - Tunnel Management; , leave the settings to default settings.; To center, or through the center to other satellites, to internet
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 173 31. On Tunnel Management , leave the settings to default settings. 32. On VPN routing settings, choose To center, or through the center to other satellites, to internet and other VPN targets option.
Page 174 - Enter the secret key in the text box, and then press; On Advanced VPN Properties settings, choose; Group 1
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 174 33. On Shared Secret settings, choose ToZyWALL option, and press Edit button 34. Enter the secret key in the text box, and then press OK button. 35. On Advanced VPN Properties settings, choose Group 1 for ...
Page 175 - button to save your settings.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 175 36. Press OK button to save your settings.
Page 176 - After you press OK button, you should see a new object here.; Security; tab on the right side to do the security settings.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 176 37. After you press OK button, you should see a new object here. IV. Setup Security 38. Click Security tab on the right side to do the security settings.
Page 177 - Add...; option to add your network objects.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 177 39. Press Add button to add a rule. 40. On the default rule, select the source field, and click right button of your mouse, and then choose Add… option to add your network objects. 41. Choosing Net_192.168...
Page 178 - To use the same way to add another network object (
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 178 42. To use the same way to add another network object ( Net_192.168.2.0 ) on the source field. 43. On the destination field, please use the same way to add your network objects: Net_192.168.1.0 and Net_192...
Page 179 - On the VPN field, click right button of your mouse, and choose; Edit Cell...; option to add your VPN; Only connections encrypted in specific VPN Communities; button to add community to your rule.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 179 44. On the VPN field, click right button of your mouse, and choose Edit Cell… option to add your VPN communities. 45. On VPN Match Conditions, choose Only connections encrypted in specific VPN Communities ...
Page 180 - accept; option for your rule.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 180 47. Clicking OK button to save your settings. 48. On action field, click right button of your mouse, and choose accept option for your rule.
Page 181 - On the track field, click right button of your mouse, and choose; Log
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 181 49. On the track field, click right button of your mouse, and choose Log option for your rule. 50. If you finished the settings, you should see a rule as below.
Page 182 - Selecting your policy rule, and press; button to install the policy.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 182 51. Pressing add button to add another rule which could drop packets if it doesn’t match your VPN rule. V. Install Policy 52. On your main menu, click Policy -> Install.. option to Install your policy. ...
Page 183 - Waiting few seconds for the installation.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 183 54. Waiting few seconds for the installation.
Page 185 - FortiNet with ZyWALL VPN Tunneling; the tunneling endpoints are ZyWALL router and FortiNet router.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 185 FortiNet with ZyWALL VPN Tunneling 1. Setup ZyWALL VPN 2. Setup FortiNet VPN This page guides us to setup a VPN connection between the ZyWALL and FortiNet router. As the figure shown below, the tunnel betw...
Page 190 - Setup FortiNet VPN
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 190 14. After you press the Apply button, you will see the following page. 2. Setup FortiNet VPN (We choose FortiGate-60 device in this example.) 1. Using a web browser, login FortiNet by giving the LAN IP add...
Page 191 - Encryption; to
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 191 4. On P1 proposal settings, select Encryption to DES , Authentication to MD5, and DH Group to Group1 . Then, press “-” button to delete the second P1 proposal rules. 5. To uncheck the Nat-traversal check b...
Page 193 - P2 Proposal; button to save
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 193 9. On P2 Proposal settings, select Encryption to DES , and Authentication to SHA1 , and also press “-” button to delete the second P2 proposal rules. 10. To uncheck the Enable perfect forward secrecy(PFS) ...
Page 194 - On the main page, click; Create New; button to edit your address
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 194 11. After you press the OK button, you will see your IPSec rule(Phase2) on this page. 12. On the main page, click Firewall -> Address , and then press Create New button to edit your address rules.
Page 195 - Fortinet network
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 195 13. To define the IP source address of the Network behind FortiNet. Giving a name for your address rule, for example “ Fortinet network ”, and enter the IP Range/Subnet in the text box. In this example, yo...
Page 197 - After you press the; button, you will the policy rule on this page.; VPN
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 197 21. After you press the OK button, you will the policy rule on this page. 22. Click VPN -> IPSec -> Monitor , this page displays a table that lists all the VPN rules configured on the FortiNet device...
Page 198 - network over a public networking infrastructure.; of; domain name; ” is used as; Remote
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 198 Remote Access VPN Scenario The remote access VPN scenario is to provide a remote users secure connections to access corporate network over a public networking infrastructure. VPN has become the logical sol...
Page 199 - authenticated during normal IKE authentication.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 199 existing Internet Key Exchange (IKE) Protocol feature. Xauth allows authentication methods to perform user authentication in a separate phase after the IKE authentication phase 1 exchange. The Xauth featur...
Page 200 - Local User; ZyXEL VPN Client to ZyWALL Tunneling
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 200 Local User RADIUS When external “RADIUS” is selected, please input the Service IP address of the external RADIUS server and the shared Key which must be configured on the RADIUS. The default (UDP) port num...
Page 201 - Setup ZyWALL VPN Client; Open ZyWALL VPN Client Security Policy Editor
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 201 1. Setup ZyWALL VPN Client 2. Setup ZyWALL This page guides us to setup a VPN connection between the VPN software and ZyWALL router. There will be several devices we need to setup for this case. They are V...
Page 202 - Remote Party Identity and Addressing settings:
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 202 Remote Party Identity and Addressing settings: 4. In ID Type option, please choose IP Address option, and enter the IP address of the remote PC (PC 2 in this case). 5. Check Connect using Secure Gateway Tu...
Page 204 - Security Policy Settings:
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 204 Security Policy Settings: 9. Click Security Policy option to choose Main Mode as Phase 1 Negotiation Mode
Page 205 - they should match whatever you enter in ZyWALL.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 205 10. Extend Security Policy icon, you will see two icons, Authentication (Phase 1) and Key Exchange (Phase 2). 11. The settings shown in the following two figures for both Phases are our examples. You can c...
Page 207 - See the VPN rule screen shot
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 207 2. Setup ZyWALL VPN 1. Using a web browser, login ZyWALL by giving the LAN IP address of ZyWALL in URL field. Default LAN IP is 192.168.1.1 , default password to login web configurator is 1234 . 2. Go to S...
Page 209 - Content Filter Application
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 209 Content Filter Application To filter non-work related and unproductive web surfing to mitigate spyware and phishing threats Web browsing is one of the most common activity people do on daily bases. However...
Page 210 - Minimize Spyware Attack; CF License Activation; In; Registration; do is, first select “; Existing myZyXEL.com account; ” and enter your username password, and; Enable external database content filtering in the; Sex Educatio
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 210 1. Minimize Spyware Attack As mentioned earlier, pornography websites are known to contain Spyware and Trojans, thus it is recommended to use ZyWALL 2 Plus to prevent users from access these types of websi...
Page 211 - Gambling; most spyware comes from such kind of websites; Demonstrate Content Filtering by an example:
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 211 “ Violence/Hate/Racism ”, “ Gay/Lesbian ”, “ Gambling ”, “ Illegal/Questionable ”, “ Illegal Drugs ”, and “ Cult/Occult ” categories( most spyware comes from such kind of websites ) to be filtered while ac...
Page 212 - Proactively Prevent Phishing
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 212 2. Proactively Prevent Phishing Phishing – The act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private informa...
Page 213 - as our own. Just as the settings in the; Enable Web site; check box. Enter the distrusted web site in the; Forbidden Web Site; Demonstrate “Customization” Content filtering by an example:
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 213 2.1.2
Customize the Forbidden web sites which are known phishing web sites In addition to use external content filter server to do filtering policies, we can customize the filter policies as our own. Jus...
Page 215 - Using external database content filtering; CONTENT; ” and “; Financial Services; Demonstrate Content Filtering by an example:; Using a browser to browse the sports website, for example,
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 215 3.2 Using external database content filtering If you have registered the CF service, you can enable external database content filtering in the CONTENT FILTER -> Categories page, with selecting the categ...
Page 216 - Centralized Management; Using Vantage CNM for Management; manage and monitor ZyWALL devices from any location.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 216 to www.zyxel.com with “ (Website Blocking) ” message displayed at the moment. Centralized Management Using Vantage CNM for Management Vantage CNM is a centralized network management solution that allows us...
Page 217 - please refer to; Vantage CNM Support Note
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 217 To manage your ZyWALLs through Vantage CNM, user needs to prepare Vantage CNM server and 3rd party FTP/Syslog/Telnet servers. For the detailed installation & registration process (to myZyXEL.com), plea...
Page 218 - for detailed
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 218 the following section, we will explain how to register device manually. Devices can be also added (imported) to Vantage CNM through XML files. For detailed operation, please refer to Vantage CNM Support No...
Page 220 - , enable Vantage CNM and
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 220 Step 4. On the device, go to ADVANCED->REMOTE MGMT->CNM , enable Vantage CNM and configure Vantage CNM Server Address in the filed. If Encryption Algorithm is enabled, you must select the same algori...
Page 221 - IP of the device will be shown on the content screen.; FAQ; A01. What is the ZyWALL Internet Access Sharing Router?; simultaneously provide a high quality networking environment.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 221 On Vantage CNM, the device icon will turn green and the device status will change to “On” and the WAN IP of the device will be shown on the content screen. FAQ A. Product FAQ A01. What is the ZyWALL Intern...
Page 222 - A02. Will the ZyWALL work with my Internet connection?; PPPoE had been supported in the ZyWALL.; A03. What do I need to use the ZyWALL?; configuration management.; A07. Why does my Internet Service Provider use PPPoE?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 222 A02. Will the ZyWALL work with my Internet connection? The ZyWALL is designed to be compatible with most network environment (cable or xDSL modems). Most external Cable and xDSL modems use an Ethernet port...
Page 223 - Telnet remote management- CLI command line; A10. Does ZyWALL support dynamic IP addressing?; The ZyWALL supports both static and dynamic IP address from ISP.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 223 A08. How can I configure the ZyWALL? Telnet remote management- CLI command line Web browser- web server embedded for easy configurations A09. What can we do with ZyWALL? Browse the World Wide Web (WWW)...
Page 224 - address of the server must be configured in NAT menu.; A14. What DHCP capability does the ZyWALL support?; able to receive downstream packets via ZyWALL.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 224 table. Therefore, to make a local server accessible to the outsider, the port number and the internal IP address of the server must be configured in NAT menu. A14. What DHCP capability does the ZyWALL supp...
Page 225 - troubleshoot the problem as described below.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 225 A20. My ZyWALL can not get an IP address from the ISP to connect to the Internet, what can I do? Currently, there are various ways that ISPs control their users. That is, the WAN IP is provided only when t...
Page 226 - first apply an account from several free Web servers such as; A24. What DDNS servers does the ZyWALL support?; The DDNS servers the ZyWALL supports currently is; A26. Does the ZyWALL support DDNS wildcard?; Yes, the ZyWALL supports DDNS wildcard that
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 226 computer to be more easily accessed from various locations on the Internet. To use the service, you must first apply an account from several free Web servers such as WWW.DYNDNS.ORG . Without DDNS, we alway...
Page 227 - not allowed to be changed.; A28. How do I setup my ZyWALL for routing IPSec packets over NAT?; service port) in menu 15 when it acts a server gateway.; A30. What is the flow ZyWALL handles inbound and outgoing traffic?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 227 understand the ESP packet with protocol number 50, replace the source IP address of the IPSec gateway to the router's WAN IP address. However, NAT should not change the source port of the UDP packets which...
Page 228 - B03. What are the basic types of firewalls?; Conceptually, there are three types of firewalls:
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 228 B01. What is a network firewall? A firewall is a system or group of systems that enforces an access-control policy between two networks. It may also be defined as a mechanism used to protect a trusted netw...
Page 229 - B04. What kind of firewall is the ZyWALL?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 229 B04. What kind of firewall is the ZyWALL? 1. The ZyWALL's firewall inspects packets contents and IP headers. It is applicable to all protocols, that understands data in the packet is intended for other lay...
Page 230 - unavailable while the target system tries to respond to itself.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 230 B07. What is Ping of Death attack? Ping of Death uses a 'PING' utility to create an IP packet that exceeds the maximum 65535 bytes of data allowed by the IP specification. The oversize packet is then sent ...
Page 231 - be allowed through the router or firewall.; B13. What are the default ACL firewall rules in ZyWALL?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 231 B12. What is IP Spoofing attack? Many DoS attacks also use IP Spoofing as part of their attack. IP Spoofing may be used to break into systems, to hide the hacker's identity, or to magnify the effect of the...
Page 232 - triangle route
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 232 The above figure indicates the " triangle route " topology. It works fine if you turn off firewall function on ZyWALL box. However, if you turn on firewall, your connection will be blocked by firew...
Page 233 - Triangle Route
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 233 (C) To resolve this conflict, we add an option for users to allow/disallow such Triangle Route topology in both CI command and Web configurator. You can issue this command, " sys firewall ignore triang...
Page 234 - C. Security Service licenses FAQ; C02. Where can I buy the iCard and how much does it cost?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 234 • Destination IP Mask =w.x.y.z • Action Matched =Drop • Action No Matched =Forward Where a.b.c.d is an IP address on your local network and w.x.y.z is your net mask. C. Security Service licenses FAQ C01. W...
Page 235 - AS; ZyWALL 2Plus; ZyWALL 5; The activation will fail.; Content Filtering service?; Yes, you can try the Content Filtering service for free.; D. Security Service Activation and UpdateFAQ; Access firmware and security service updates.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 235 C06. What kind of iCard should I buy? It depends on the ZyWALL model you have, the security service you desire and the license period you need. See the following table for those mappings. (Here we highligh...
Page 236 - Which ZyWALL models can be registered via myZyXEL.com?; following table for model mappings.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 236 In summary, myZyXEL.com delivers a convenient, centralized way to register all your ZyWALL security appliances and security services. It eliminates the hassle of registering individual ZyWALL appliances an...
Page 238 - D10. What’s the URL for these service portals?; mySecurityZone; E. Content Filter FAQ
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 238 D09. Who maintains mySecurityZone & Update Server? It’s maintained by ZyXEL Security Response Team (ZSRT) who manages backend support from the beginning of outbreak happen to attack sample collection, ...
Page 239 - data center is timed out?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 239 E04. Can I decide whether to forward or drop the HTTP response if the query to BlueCoat data center is timed out? Yes, you can set the policy, drop or forward, when query is timed out. The default policy i...
Page 240 - or for large corporations?; - 68% of all Internet porn traffic occurs during the 9 to 5 workday.; E15. How many URL keywords does ZyWALL support?; 4 keywords are supported.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 240 E10. Who needs ZyXEL Content Filtering? Is ZyXEL Content Filtering for small companies or for large corporations? All businesses can benefit from using the ZyXEL Content Filtering solution ZyXEL Content Fi...
Page 241 - E16. How do I keep database of Content Filtering service updated?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 241 E16. How do I keep database of Content Filtering service updated? From the current design, there is no local Content Filtering signature database stored on the ZyWALL devices. As a result, you don’t have t...
Page 242 - Site Submissions; E23. How many and what categories do you provide?; Potential Liable & Objectionable Content Categories
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 242 BlueCoat uses expert Web content raters to train the ratings technology. Initially, category experts create a list of URLs that represent good content for each category. The ratings technology then uses th...
Page 243 - Potential Non-Productive Categories
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 243 · Sex Education · Violence/Hate/Racism · Weapons Potential Non-Productive Categories · Abortion · Arts/Entertainment · Auctions · Brokerage/Trading · Business & Economy · Chat/Instant Messaging · Compu...
Page 244 - geographically load balanced?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 244 · Sports/Recreation/Hobbies · Streaming Media/MP3 · Travel · Vehicles · Web Advertisements · Web Communications · Web Hosting E24. How does the ZyXEL content filtering handle dynamically generated sites? W...
Page 245 - bottom of the device as below,; F01. How to count my VPN tunnels on ZyWALL?; ZyWALL counts the Network policies as VPN tunnels.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 245 E29. Which User Name & Password should I input for Content Filtering report? The User Name is the smallest Ethernet MAC address of your device. To identify check the sticker in the bottom of the device...
Page 247 - F04. What are most common VPN protocols?; What secure protocols does IPSec support?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 247 company to carry the data traffic over its Internet access lines, thus reducing the need for some installed lines. F04. What are most common VPN protocols? There are currently three major tunneling protoco...
Page 249 - F12. Is my ZyWALL ready for IPSec VPN?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 249 F11. What are Local ID and Peer ID? Local ID and Peer ID are used in IKE phase 1 negotiation. It’s in FQDN(Fully Qualified Domain Name) format, IKE standard takes it as one type of Phase 1 ID. Phase 1 ID i...
Page 250 - F14. What VPN protocols are supported by ZyWALL?; authentication/integrity with or without confidentiality.; Source IP/Destination IP; indistinguishable, and VPN will not work.; Secure Gateway IP Address
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 250 F14. What VPN protocols are supported by ZyWALL? All ZyWALL series support ESP (protocol number 50) and AH (protocol number 51). F15. What types of encryption does ZyWALL VPN support? ZyWALL supports 56-bi...
Page 251 - F18. Does ZyWALL support dynamic secure gateway IP?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 251 172.31.255.255 (these address ranges are reserved by internet standard for private LAN numberings behind NAT devices). It is usually a static IP so that we can pre-configure it in ZyWALL for making VPN con...
Page 252 - F21. Will ZyXEL support Secure Remote Management?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 252 F21. Will ZyXEL support Secure Remote Management? Yes, we will support it and we are working on it currently. F22. Does ZyWALL VPN support NetBIOS broadcast? Yes, the ZyWALL does support NetBIOS broadcast ...
Page 253 - IKE
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 253 If firewall is turned on in ZyWALL, you must forward IKE port in Internet interface. If NAT are also enabled in ZyWALL, NAT server is required for non-secure connections, NAT server is not required for sec...
Page 254 - WAN to LAN; symmetric
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 254 F28. Single, Range, Subnet, which types of IP address does ZyWALL support in VPN/IPSec? All ZyWALL series support single, range, and subnet configuration for VPN IPSec. In other words, you can specify a si...
Page 255 - G03. What are the security services PKI provides?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 255 cryptography as asymmetric. Symmetric cryptography, such as DES, 3DES, AES, is normally used for data transmission, since it requires less computation power than asymmetric cryptography. The task of privat...
Page 257 - G09. How does a PKI ensure data confidentiality?; recipient's private key can decrypt the message.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 257 describe the rules governing the different uses of these certificates. G09. How does a PKI ensure data confidentiality? Users' public keys are published in an accessible directory. A person wishing to send...
Page 258 - before applying the hash function to the message.)
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 258 When Bob clicks on the digital signature option on his e-mail application, special software applies a mathematical formula known as a hash function to the message, converting it to a fixed-length string of...
Page 259 - party) in order to use PKI functionality on ZyWALL.; G14. How can I have Self-signed certificate for ZyXEL appliance?; You can check content of Self-signed certificate in WEB GUI.; G18. What can I do prior to reset appliance's configuration?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 259 G12. Does ZyXEL provide CA service? No, ZyXEL doesn't maintain CA service for customers, customers need to find CA server (trusted 3rd party) in order to use PKI functionality on ZyWALL. G13. What if custo...
Page 260 - the certificates by importing them afterward.; H01. What are the capability of wireless feature of ZyWALL?; authentication and WEP/WPA/WPA2 for security access control.; H02. What is the coverage range of Wireless in ZyWALL?; centre of the wireless client population.; H04. What are the advantages of Wireless LANs?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 260 configuration to the local computer. Then import them back to ZyXEL appliance. G19. If I export My Certificates from ZyXEL appliance, save them locally, and then import them back after resetting the config...
Page 261 - Wireless technology allows the network to go where wire cannot go.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 261 b. Installation Speed and Simplicity: Installing a wireless LAN system can be fast and easy and can eliminate the need to pull cable through walls and ceilings. c. Installation Flexibility: Wireless techno...
Page 262 - will solve this problem.; H11. Can wireless signals pass through walls?
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 262 at 11 Mbps or lower depending on range. The range at 54 Mbps is less than for 802.11b operating at 11 Mbps. H08. What is 802.11a? 802.11a the second revision of 802.11 that operates in the unlicensed 5 GHz...
Page 263 - Minimizing the number of walls and ceilings
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 263 2. Building Materials: metal door, aluminum studs. 3. Electrical devices: microwaves, monitors, electric motors. Solution : 1.Minimizing the number of walls and ceilings 2.Antenna is positioned for best re...
Page 264 - digital certificate.
ZyWALL 2WG Support Notes All contents copyright (c) 2006 ZyXEL Communications Corporation. 264 see the SSID. H17. What is 802.1x? IEEE 802.1x Port-Based Network Access Control is an IEEE (Institute of Electrical and Electronics Engineers) standard, which specifies a standard mechanism for authentica...