Page 2 - Broadband Security Gateway; Copyright; Disclaimer
P312 Broadband Security Gateway ii Copyright Prestige 312 Broadband Security Gateway Copyright Copyright © 2000 by ZyXEL Communications Corporation. The contents of this publication may not be reproduced in any part or as a whole, transcribed, stored in aretrieval system, translated into any languag...
Page 3 - Federal Communications Commission (FCC) Interference Statement; Notice 1
P312 Broadband Security Gateway FCC Statement iii Federal Communications Commission (FCC) Interference Statement This device complies with Part 15 of FCC rules. Operation is subject to the following two conditions: This device may not cause harmful interference. This device must accept any interfere...
Page 4 - Information for Canadian Users; Caution
P312 Broadband Security Gateway iv Canadian Users Information for Canadian Users The Industry Canada label identifies certified equipment. This certification means that the equipment meetscertain telecommunications network protective, operation, and safety requirements. The Industry Canadadoes not g...
Page 5 - Declaration of Conformity; ZyXEL Communications Corp; is in conformity with; Standard; Standard Item; Version
P312 Broadband Security Gateway Warranty v Declaration of Conformity We, the Manufacturer/Importer, ZyXEL Communications Corp . No. 6, Innovation Rd. II, Science-Based Industrial Park, Hsinchu, Taiwan, 300 R.O.C declare that the product Prestige 312 is in conformity with (reference to the specificat...
Page 7 - ZyXEL Limited Warranty; Note; Please register your Prestige (fast, easy online registration at
P312 Broadband Security Gateway Warranty vii ZyXEL Limited Warranty ZyXEL warrants to the original end user (purchaser) that this product is free from any defects in materials orworkmanship for a period of up to two years from the date of purchase. During the warranty period, and uponproof of purcha...
Page 8 - Customer Support; Prestige Model and serial number.
P312 Broadband Security Gateway viii Customer Support Customer Support When you contact your customer support representative please have the following information ready: ♦ Prestige Model and serial number. ♦ Information in Menu 24.2.1 –System Information . ♦ Warranty Information. ♦ Date you received...
Page 9 - Table of Contents; Chapter 1
P312 Broadband Security Gateway Table Of Contents ix Table of Contents Table of Contents ........................................................................................................................... ix List of Figures .......................................................................
Page 16 - List of Figures
P312 Broadband Security Gateway xvi List Of Figures List of Figures Figure 1-1 Secure Internet Access via Cable ............................................................................................ 1-3 Figure 1-2 Secure Internet Access via DSL.....................................................
Page 23 - List Of Tables
P312 Broadband Security Gateway List of Tables xxiii List Of Tables Table 2-1 LED functions ........................................................................................................................ 2-1 Table 2-2 Main Menu Commands .........................................................
Page 27 - Preface; About Your Router; Multiple office/department connections via access devices.; About This User's Manual; such as Remote Node Setup IP Static routes and NAT.
P312 Broadband Security Gateway Preface xxvii Preface About Your Router Congratulations on your purchase of the Prestige 312 Broadband Security Gateway. Don’t forget to register your Prestige (fast, easy online registration at www.zyxel.com ) for free future product updates and information. The Pres...
Page 28 - Related Documentation; The SMT menu titles and labels are in; Bold Times; font. The choices of a menu item are in; Bold Arial; ENTER
P312 Broadband Security Gateway xxviii Preface Regardless of your particular application, it is important that you follow the steps outlined in Chapters 1-2 to connect your Prestige to your LAN. You can then refer to the appropriate chapters of the manual, dependingon your applications. Related Docu...
Page 29 - Getting Started; Prestige
Getting Started I Part I: Getting Started Chapters 1-3 are structured as a step-by-step guide to help you connect, install and setup your Prestige to operate on your network and access the Internet.
Page 31 - The Prestige 312 Broadband Security Gateway; The following are the essential features of the Prestige 312.; Firewall
P312 Broadband Security Gateway Getting to Know Your Prestige 1-1 Chapter 1 Getting to Know Your Prestige This chapter introduces the main features and applications of the Prestige. 1.1 The Prestige 312 Broadband Security Gateway The Prestige 312 is a dual Ethernet Broadband Security Gateway integra...
Page 33 - Logging and Tracing; The Prestige has the following features:; Upgrade Prestige Firmware via LAN; The firmware of the Prestige 312 can be upgraded via the LAN.; Embedded FTP and TFTP Servers; Applications for Prestige 312; Broadband Internet Access via Cable or xDSL Modem; Secure Internet Access via Cable
P312 Broadband Security Gateway Getting to Know Your Prestige 1-3 not choose a time service protocol that your timeserver will send when the Prestige powers up you can enterthe time manually but each time the system is booted, the time & date will be reset to 1/1/1970 0:0:0 . Logging and Tracing...
Page 34 - Secure Internet Access via DSL
P312 Broadband Security Gateway 1-4 Getting to Know Your Prestige Figure 1-2 Secure Internet Access via DSL You can also use your xDSL modem in the bridge mode for always-on Internet access and high speed datatransfer.
Page 35 - Chapter 2; Front Panel LEDs and Back Panel Ports; Front Panel; The following table describes the LED functions:; LED functions; LEDs
P312 Broadband Security Gateway Hardware Installation & Initial Setup 2-1 Chapter 2 Hardware Installation & Initial Setup This chapter shows you how to connect the hardware and perform the initial setup. 2.1 Front Panel LEDs and Back Panel Ports 2.1.1 Front Panel LEDs The LEDs on the front p...
Page 36 - Prestige 312 Rear Panel and Connections
P312 Broadband Security Gateway 2-2 Hardware Installation & Initial Setup LEDs Function Indicator Status Active Description Flashing The 100M LAN is sending/receiving packets. Off The WAN Link is not ready, or has failed. On The WAN Link is ok. WAN WAN Green Flashing The 10M WAN link is sending/...
Page 37 - OR; Connect the power adapter to the port labeled; Installation; A computer with an Ethernet NIC (Network Interface Card) installed.
P312 Broadband Security Gateway Hardware Installation & Initial Setup 2-3 connector on the back of the cable modem. Connect an xDSL Modem to the xDSL Wall Jack. Please also see Appendix C for important safety instructions on making connections to the Prestige. Step 1. Connecting the Console Port...
Page 38 - Power Up Your Prestige; Enter; Initial Screen; The login screen appears after you press [
P312 Broadband Security Gateway 2-4 Hardware Installation & Initial Setup ♦ 9600 Baud. ♦ No parity, 8 Data bits, 1 Stop bit, Flow Control set to None. 3. A cable/xDSL modem and an ISP account. After the Prestige is properly set up, you can make future changes to the configuration through telnetc...
Page 39 - Password Screen; Navigating the SMT Interface; Main Menu Commands; Operation
P312 Broadband Security Gateway Hardware Installation & Initial Setup 2-5 Figure 2-4 Password Screen 2.6 Navigating the SMT Interface The SMT (System Management Terminal) is the interface that you use to configure your Prestige.Several operations that you should be familiar with before you attem...
Page 40 - Menu; After you enter the password, the SMT displays the; System Management Terminal Interface Summary; Main Menu Summary; Menu Title
P312 Broadband Security Gateway 2-6 Hardware Installation & Initial Setup 2.6.1 Main Menu After you enter the password, the SMT displays the Prestige 312 Main Menu , as shown below. Figure 2-5 Prestige 312 Main Menu 2.6.2 System Management Terminal Interface Summary Table 2-3 Main Menu Summary #...
Page 41 - Changing the System Password; Enter 23 in the Main Menu to open; Enter your existing password and press
P312 Broadband Security Gateway Hardware Installation & Initial Setup 2-7 99 Exit To exit from SMT and return to a blank screen. 2.7 Changing the System Password The first thing your should do before anything else is to change the default system password by followingthe steps below. Step 1. Ente...
Page 42 - Setup; DNS; NetMeeting; DYNDNS Wildcard; Menu 1 – General Setup
P312 Broadband Security Gateway 2-8 Hardware Installation & Initial Setup 2.8 General Setup Menu 1 - General Setup contains administrative and system-related information. The fields for General Setup are as shown next. System Name is for identification purposes. However, because some ISPs check ...
Page 43 - General Setup Menu Field; To configure Dynamic DNS, go to; and press select; Yes; in the; Edit Dynamic; Pressing; Menu 1.1– Configure Dynamic DNS
P312 Broadband Security Gateway Hardware Installation & Initial Setup 2-9 Table 2-4 General Setup Menu Field Field Description Example System Name Choose a descriptive name for identification purposes. It isrecommended you enter your computer’s “Computer name” in thisfield. This name can be up t...
Page 44 - Configure Dynamic DNS Menu Fields; This section describes how to configure the WAN using
P312 Broadband Security Gateway 2-10 Hardware Installation & Initial Setup Table 2-5 Configure Dynamic DNS Menu Fields Field Description Example ServiceProvider Enter the name of your Dynamic DNS client. www.ddns.org Active Press [SPACE BAR] to toggle between Yes or No . Yes Host Enter the domai...
Page 45 - Menu 2 – WAN Setup; or upload a different rom file.; WAN Setup Menu Fields; This section describes how to configure the LAN using
P312 Broadband Security Gateway Hardware Installation & Initial Setup 2-11 Figure 2-9 Menu 2 – WAN Setup The MAC address field allows users to configure the WAN port's MAC Address by either using the factorydefault or cloning the MAC address from a workstation on your LAN. Once it is successfull...
Page 46 - Menu 3.1 – LAN Port Filter Setup
P312 Broadband Security Gateway 2-12 Hardware Installation & Initial Setup Figure 2-10 Menu 3 - LAN Setup 2.10.1 LAN Port Filter Setup This menu allows you to specify the filter sets that you wish to apply to the LAN traffic. You seldom needto filter the LAN traffic, however, the filter sets may...
Page 47 - Chapter 3; LAN; not
P312 Broadband Security Gateway Internet Access 3-1 Chapter 3 Internet Access This chapter shows you how to configure the LAN as well as the WAN of your Prestige for Internet access. 3.1 TCP/IP and DHCP for LAN The Prestige has built-in DHCP server capability that assigns IP addresses and DNS server...
Page 48 - IP
P312 Broadband Security Gateway 3-2 Internet Access The subnet mask specifies the network number portion of an IP address. Your Prestige will compute thesubnet mask automatically based on the IP address that you entered. You don’t need to change the subnetmask computed by the Prestige unless you are...
Page 49 - Configuration; You can configure the Prestige as; None; LAN, or else the workstation must be manually configured.; IP Pool Setup; fields in; Example of network properties for LAN servers with fixed IP#:; Multicast; a group
P312 Broadband Security Gateway Internet Access 3-3 3.1.5 DHCP Configuration DHCP (Dynamic Host Configuration Protocol, RFC 2131 and RFC 2132) allows the individual clients(workstations) to obtain the TCP/IP configuration at start-up from a server . You can configure the Prestige as a DHCP server or...
Page 50 - to disable IP Multicasting on these; Alias; Physical Network; From the Main Menu, enter 3
P312 Broadband Security Gateway 3-4 Internet Access The address 224.0.0.1 is used for query messages and is assigned to the permanent group of all IP hosts(including gateways). All hosts must join the 224.0.0.1 group in order to participate in IGMP. The address224.0.0.2 is assigned to the multicast ...
Page 52 - LAN DHCP Setup Menu Fields
P312 Broadband Security Gateway 3-6 Internet Access Follow the instructions in the following table on how to configure the DHCP fields. Table 3-1 LAN DHCP Setup Menu Fields Field Description Example DHCP= This field enables/disables the DHCP server. If it is set to Server , your Prestige will act as...
Page 53 - Edit IP Alias
P312 Broadband Security Gateway Internet Access 3-7 Field Description Example Edit IP Alias The Prestige supports three logical LAN interfaces via its single physical Ethernet interface with the Prestige itself as the gateway foreach LAN network. Press the space bar to toggle No to Yes, thenpress [E...
Page 54 - Access; PPPoE; Encapsulation; You must choose the; is for a dial-up connection using PPPoE. If you choose; Ethernet; in; Menu 4 – Internet Access Setup (Ethernet)
P312 Broadband Security Gateway 3-8 Internet Access RIP Direction Press the space bar to select the RIP direction from None, Both/In Only/Out Only. None Version Press the space bar to select the RIP version from RIP-1/RIP- 2B/RIP-2M. RIP-1 IncomingProtocol Filters Enter the filter set(s) you wish to...
Page 55 - Internet Access Setup Menu Fields
P312 Broadband Security Gateway Internet Access 3-9 The following table describes this screen. Table 3-4 Internet Access Setup Menu Fields Field Description ISP’s Name Enter the name of your Internet Service Provider, e.g., myISP. Thisinformation is for identification purposes only. Encapsulation Pr...
Page 56 - PPTP
P312 Broadband Security Gateway 3-10 Internet Access 3.3.3 Configuring the PPTP Client To configure a PPTP client, you must configure the My Login and Password fields for a PPP connection and the PPTP parameters for a PPTP connection. After configuring the User Name and Password for PPP connection, ...
Page 58 - Basic Setup Complete; to operate on your network; See
P312 Broadband Security Gateway 3-12 Internet Access Table 3-6 New Fields in Menu 4 (PPPoE) screen Field Description Examples Encapsulation Press the [SPACE BAR] and then press [ENTER] to choose PPPoE . The encapsulation method influences your choices for IP Address. PPPoE Service Name Enter the PPP...
Page 59 - Advanced Applications
Advanced Applications II Part II: Advanced Applications Advanced Applications (Chapters 4-6) describe the advanced applications of your Prestige, such as Remote Node Setup IP Static routes and NAT.
Page 60 - Chapter 4; This chapter shows you how to configure a remote node.; Remote Node Profile, Menu 11.3 - Remote Node Network Layer Options; Remote Node Profile
P312 Broadband Security Gateway Remote Node Setup 4-1 Chapter 4 Remote Node Setup This chapter shows you how to configure a remote node. A remote node is required for placing calls to a remote gateway. A remote node represents both the remotegateway and the network behind it across a WAN connection....
Page 62 - to; Menu 11.1 Remote Node Profile for PPPoE Encapsulation
P312 Broadband Security Gateway Remote Node Setup 4-3 4.1.2 PPPoE Encapsulation The Prestige supports PPPoE (Point-to-Point Protocol over Ethernet). You can only use PPPoEencapsulation when you’re using the Prestige with an xDSL modem as the WAN device. If you change the Encapsulation to PPPoE, then...
Page 63 - Allocated Budget; Idle Timeout; If you change the
P312 Broadband Security Gateway 4-4 Remote Node Setup Table 4-2 Fields in Menu 11.1 (PPPoE Encapsulation Specific) Field Description Examples Authen This field sets the authentication protocol used foroutgoing calls. Options for this field are: CHAP/PAP - Your Prestige will accept either CHAP orPAP ...
Page 64 - Remote Node Profile for PPTP Encapsulation
P312 Broadband Security Gateway Remote Node Setup 4-5 Figure 4-3 Remote Node Profile for PPTP Encapsulation The next table shows how to configure fields in Menu 11.1 not previously discussed above. Table 4-3 Fields in Menu 11.1 (PPTP Encapsulation) Field Description Examples Encapsulation Toggle the...
Page 65 - Edit IP; field in; to open; Remote Node Network Layer Options
P312 Broadband Security Gateway 4-6 Remote Node Setup 4.2 Editing TCP/IP Options (with Ethernet Encapsulation) Move the cursor to the Edit IP field in Menu 11.1 , then press the [SPACE BAR] to toggle and set the value to Yes . Press [Enter] to open Menu 11.3 - Network Layer Options . Figure 4-4 Remo...
Page 68 - Remote Node Filter
P312 Broadband Security Gateway Remote Node Setup 4-9 between 1 and 15. In practice, 2 or 3 is usually a good number. Private This parameter determines if the Prestige will include the route to thisremote node in its RIP broadcasts. If set to Yes , this route is kept private and not included in RIP ...
Page 69 - Remote Node Filter (Ethernet Encapsulation)
P312 Broadband Security Gateway 4-10 Remote Node Setup Figure 4-6 Remote Node Filter (Ethernet Encapsulation) Figure 4-7 Remote Node Filter (PPPoE or PPTP Encapsulation) Menu 11.5 - Remote Node Filter Input Filter Sets: protocol filters= 3 device filters= Output Filter Sets: protocol filters= 1 devi...
Page 70 - Chapter 5; Example of Static Routing Topology
P312 Broadband Security Gateway IP Static Route Setup 5-1 Chapter 5 IP Static Route Setup This chapter shows you how to configure static routes with your Prestige. Static routes tell the Prestige routing information that it cannot learn automatically through other means.This can arise in cases where...
Page 71 - IP Static Route Setup; You configure IP static routes in; `The following table describes the IP Static Route Menu fields.
P312 Broadband Security Gateway 5-2 IP Static Route Setup 5.1 IP Static Route Setup You configure IP static routes in Menu 12. 1 , by selecting one of the IP static routes as shown below. Enter 12 from the Main Menu. Figure 5-2 Menu 12 - IP Static Route Setup Now, enter the index number of one of th...
Page 72 - IP Static Route Menu Fields; Field
P312 Broadband Security Gateway IP Static Route Setup 5-3 Table 5-1 IP Static Route Menu Fields Field Description Route # This is the index number of the static route that you chose in Menu 12. Route Name Enter a descriptive name for this route. This is for identification purposes only. Active This ...
Page 74 - Chapter 6; This chapter discusses how to configure NAT on the Prestige.; Definitions; Inside; Table 6-1 NAT Definitions; Term
P312 Broadband Security Gateway NAT 6-1 Chapter 6 Network Address Translation (NAT) This chapter discusses how to configure NAT on the Prestige. 6.1 Introduction NAT (Network Address Translation - NAT, RFC 1631) is the translation of the IP address of a host in apacket, e.g., the source address of a...
Page 75 - How NAT Works
P312 Broadband Security Gateway 6-2 NAT them accessible to the outside world. If you do not define any servers (for Many-to-One and Many-to-ManyOverload mapping – see below), NAT offers the additional benefit of firewall protection. If no server isdefined in these cases, all incoming inquiries will ...
Page 76 - The following table summarizes these types.; Table 6-2 NAT Mapping Types; Type; and; Server; for a detailed description of the NAT set for SUA.; Full Feature; NAT support to map global IP addresses to local IP addresses of
P312 Broadband Security Gateway NAT 6-3 2. Many to One: In Many-to-One mode, the Prestige maps multiple local IP addresses to one global IPaddress. This is equivalent to SUA (i.e., PAT, port address translation), ZyXEL’s Single User Accountfeature that previous ZyXEL routers supported (the SUA Only ...
Page 77 - SUA Only; see section; NAT Application; Menus
P312 Broadband Security Gateway 6-4 NAT remote node basis. They are reusable, but only one set is allowed for each remote node. The Prestigesupports 2 sets since there is only one remote node. The second set ( SUA Only option in Menu 15.1) is a convenient, pre-configured, read only Many-to-1 port ma...
Page 78 - Applying NAT for Internet Access; This figure shows how you apply NAT to the remote node in Menu 11.1.
P312 Broadband Security Gateway NAT 6-5 Figure 6-3 Applying NAT for Internet Access This figure shows how you apply NAT to the remote node in Menu 11.1. Step 1. Enter 11 from the Main Menu. Step 2. Move the cursor to the Edit IP field, press the [SPACEBAR] to toggle the default No to Yes , then pres...
Page 79 - NAT; Menu 15 NAT Setup; in menu 4 or 11.3, the SMT will use Set 1, which supports all; for; Menu 15.1 – Address Mapping Sets
P312 Broadband Security Gateway 6-6 NAT Table 6-3 Applying NAT in Menus 4 & 11.3 Field Options Description Full Feature When you select this option the SMT will useAddress Mapping Set 1 (Menu 15.1 – see section 6.2.3 for further discussion). You can configure any of the 5 mapping types described...
Page 80 - Menu 15.1 Address Mapping Sets; SUA Address Mapping Rules; The following table explains the fields in this screen.
P312 Broadband Security Gateway NAT 6-7 Figure 6-6 Menu 15.1 Address Mapping Sets Let’s look first at Option 255. Option 255 is equivalent to SUA in previous ZyXEL routers ( see section 6.1.4) . The fields in this menu cannot be changed. Entering 255 brings up this screen. Figure 6-7 SUA Address Map...
Page 81 - Action; Select Rule; field means that this is a required field and you must enter a
P312 Broadband Security Gateway 6-8 NAT Table 6-4 SUA Address Mapping Rules Field Description Options/Example Set Name This is the name of the set you selected in Menu15.1 or enter the name of a new set you want tocreate. SUA Idx This is the index or rule number. 1 Local Start IP Local End IP Local ...
Page 82 - Ordering Your Rules
P312 Broadband Security Gateway NAT 6-9 Figure 6-8 First Set in Menu 15.1.1 The Type, Local and Global Start/End IPs are configured in Menu 15.1.1.1 (described later) and the values are displayed here. Ordering Your Rules Ordering your rules is important because the Prestige applies the rules in the...
Page 83 - Selecting; Edit; field and then selecting a rule brings up the following menu,; Address Mapping Rule; The following table describes the fields in this screen.
P312 Broadband Security Gateway 6-10 NAT moved down by one rule. Delete means to delete the selected rule and then all the rules after the selectedone will be advanced one rule. Save Set means to save the whole set (note when you choose this action,the Select Rule item will be disabled). Select Rule...
Page 84 - Menu 15.2 – NAT Server Sets; is used to configure these servers. If you’re using; with either; Service Type
P312 Broadband Security Gateway NAT 6-11 Field Description Option/Example examples. and Server Local IP Only local IP fields are N/A for server; Global IP fields MUST be set for Server . Start This is the starting local IP address (ILA). 0.0.0.0 End This is the ending local IP address (ILA). Ifthe r...
Page 85 - Multiple Servers Behind NAT
P312 Broadband Security Gateway 6-12 NAT Figure 6-10 Multiple Servers Behind NAT 6.3.2 Configuring a Server behind NAT Follow the steps below to configure a server behind NAT: Step 1. Enter 15 in the main menu to go to Menu 15 – NAT Setup. Step 2. Enter 2 to go to Menu 15.2 - NAT Server Setup . Step...
Page 86 - Menu 15.2 – NAT Server Setup; Services
P312 Broadband Security Gateway NAT 6-13 Figure 6-11 Menu 15.2 – NAT Server Setup Table 6-7 Services & Port numbers Services Port Number FTP (File Transfer Protocol) 21 Telnet 23 SMTP (Simple Mail Transfer Protocol) 25 DNS(Domain Name System) 53 HTTP (Hyper Text Transfer protocol or WWW, Web) 80...
Page 87 - NAT Example 1; From Menu 4 shown above, simply choose the; option from the; The; read only option from; Network Address Translation
P312 Broadband Security Gateway 6-14 NAT Figure 6-12 NAT Example 1 Figure 6-13 Internet Access & NAT Example From Menu 4 shown above, simply choose the SUA Only option from the Network Address Translation field. This is the Many-to-One mapping discussed in section 6.1.4. The SUA Only read only o...
Page 88 - Example 2 – Internet Access with an Inside Server; NAT Example 2
P312 Broadband Security Gateway NAT 6-15 6.4.2 Example 2 – Internet Access with an Inside Server Figure 6-14 NAT Example 2 In this case, we do exactly as above (use the convenient pre-configured SUA Only set) and also go to Menu 15.2 to specify the Inside Server behind the NAT as shown in the next f...
Page 90 - Start IP
P312 Broadband Security Gateway NAT 6-17 Step 5. Select Type= as One-to-One (direct mapping for packets going both ways) , and enter the local Start IP as 192.168.1.10 (the IP address of FTP Server 1), the global Start IP as 10.132.50.1 (our first IGA). ( See Figure 6-18) Step 6. Repeat the previous...
Page 92 - Example 4 –NAT Unfriendly Application Programs; mapping as port numbers do; No Overload
P312 Broadband Security Gateway NAT 6-19 6.4.4 Example 4 –NAT Unfriendly Application Programs Some applications do not support NAT Mapping using TCP or UDP port address translation. In this case itis better to use Many-to-Many No Overload mapping as port numbers do not change for Many-to-Many No Ove...
Page 94 - Advanced Management; Transferring Files and Telnet.
Advanced Management III Part III: Advanced Management Chapters 7 - 12 provide information on Prestige filtering, System Information and Diagnosis, Transferring Files and Telnet.
Page 96 - Chapter 7; Filtering; the following figure.; Outgoing Packet Filtering Process
P312 Broadband Security Gateway Filters 7-1 Chapter 7 Filter Configuration This chapter shows you how to create and apply filter(s). 7.1 About Filtering Your Prestige uses filters to decide whether to allow passage of a data packet and/or to make a call. Thereare two types of filter applications: da...
Page 97 - The Filter Structure of the Prestige; for the
P312 Broadband Security Gateway 7-2 Filters 7.1.1 The Filter Structure of the Prestige A filter set consists of one or more filter rules. Usually, you would group related rules, e.g., all the rules forNetBIOS, into a single set and give it a descriptive name. The Prestige allows you to configure up ...
Page 98 - Execute; Filter Set; Filter Rule Process
P312 Broadband Security Gateway Filters 7-3 Start Fetch First Filter Set Fetch First Filter Rule Active? Execute Filter Rule Fetch Next Filter Rule Next filter Rule Available? Fetch Next Filter Set Next Filter Set Available? Accept Packet Drop Packet Yes No Yes No Yes Packet into filter Filter Set F...
Page 99 - Configuring a Filter Set; Filter Set Configuration; Summary
P312 Broadband Security Gateway 7-4 Filters 7.2 Configuring a Filter Set To configure a filter set, follow the procedure below. For more information on Menus 21.2 and 21.3, please see Part 4. Step 1. Select option 21. Filter Set Configuration from the Main Menu to open Menu 21 . Figure 7-4 Menu 21 –...
Page 100 - NetBIOS_WAN Filter Rules Summary
P312 Broadband Security Gateway Filters 7-5 Figure 7-6 NetBIOS_WAN Filter Rules Summary Figure 7-7 NetBIOS _LAN Filter Rules Summary Figure 7-8 TEL_FTP_WEB_WAN Filter Rules Summary Menu 21.1.1 - Filter Rules Summary # A Type Filter Rules M m n - - ---- -------------------------------------------- --...
Page 101 - Abbreviations Used in the Filter Rules Summary Menu
P312 Broadband Security Gateway 7-6 Filters 7.2.1 Filter Rules Summary Menu This screen shows the summary of the existing rules in the filter set. The following tables contain a briefdescription of the abbreviations used in the previous menus. Table 7-1 Abbreviations Used in the Filter Rules Summary...
Page 102 - Abbreviations Used If Filter Type Is IP; Abbreviations Used If Filter Type Is GEN; Abbreviation
P312 Broadband Security Gateway Filters 7-7 The protocol dependent filter rules abbreviation are listed as follows: ! If the filter type is IP, the following abbreviations listed in the following table will be used. Table 7-2 Abbreviations Used If Filter Type Is IP Abbreviation Description Pr Protoc...
Page 103 - TCP/IP Filter Rule Menu Fields
P312 Broadband Security Gateway 7-8 Filters Figure 7-9 Menu 21.1.1.1 - TCP/IP Filter Rule The following table describes how to configure your TCP/IP filter rule. Table 7-4 TCP/IP Filter Rule Menu Fields Field Description Option Active This field activates/deactivates the filter rule. Yes/No IP Proto...
Page 105 - The following diagram illustrates the logic flow of an IP filter.
P312 Broadband Security Gateway 7-10 Filters Field Description Option Once you have completed filling in Menu 21.1.1.1 - TCP/IP Filter Rule , press [Enter] at the message [Press Enter to Confirm] to save your configuration, or press [Esc] to cancel. This data will now bedisplayed on Menu 21.1.1 - Fi...
Page 106 - Executing an IP Filter
P312 Broadband Security Gateway Filters 7-11 Packet into IP Filter Matched Matched Yes Action Matched Action Not Matched More? No Filter Active? Check IP Protocol Drop Drop Packet Accept Packet Drop Forward Check Next Rule Check Next Rule Check Next Rule Forward Not Matched Yes No Check Src IP Addr ...
Page 108 - Generic Filter Rule Menu Fields
P312 Broadband Security Gateway Filters 7-13 The following table describes the fields in the Generic Filter Rule Menu. Table 7-5 Generic Filter Rule Menu Fields Field Description Option Filter # This is the filter set, filter rule co-ordinates, i.e., 2,3 refers to the secondfilter set and the third ...
Page 109 - Filter; see Figure; Telnet Filter Example
P312 Broadband Security Gateway 7-14 Filters Drop Once you have completed filling in Menu 21.4.1.1 - Generic Filter Rule , press [Enter] at the message [Press Enter to Confirm] to save your configuration, or press [Esc] to cancel. This data will now bedisplayed on Menu 21.1.1 - Filter Rules Summary ...
Page 111 - Example Filter Rules Summary – Menu 21.1.3; Filter Types and NAT; Generic Filter
P312 Broadband Security Gateway 7-16 Filters Figure 7-14 Example Filter Rules Summary – Menu 21.1.3 After you’ve created the filter set, you must apply it. Step 1. Enter 11 from the main menu to go to Menu 11. Step 2. Go to the Edit Filter Sets field, press the [SPACEBAR] to toggle Yes to No and pre...
Page 112 - Protocol and Device Filter Sets; Firewall configuration is discussed in; Applying a Filter and Factory Defaults; traffic; protocol; field under; Input Filter Sets
P312 Broadband Security Gateway Filters 7-17 packets and after NAT for incoming packets. On the other hand, the generic, or device filters are applied tothe raw packets that appear on the wire. They are applied at the point when the Prestige is receiving andsending the packets; i.e. the interface. T...
Page 113 - Filtering LAN Traffic; protocol filters; Output; Call
P312 Broadband Security Gateway 7-18 Filters Figure 7-16 Filtering LAN Traffic 7.6.2 Remote Node Filters Go to Menu 11.5 (shown below – note that call filter sets are only present for PPPoE encapsulation) andenter the number(s) of the filter set(s) as appropriate. You can cascade up to four filter s...
Page 114 - Chapter 8; SNMP; from the Main Menu to open
P312 Broadband Security Gateway SNMP 8-1 Chapter 8 SNMP Configuration This chapter discusses SNMP (Simple Network Management Protocol) for network management and monitoring. 8.1 About SNMP Your Prestige supports SNMP agent functionality, which allows a manager station to manage and monitorthe Presti...
Page 115 - SNMP Configuration Menu Fields
P312 Broadband Security Gateway 8-2 SNMP The following table describes the SNMP configuration parameters. Table 8-1 SNMP Configuration Menu Fields Field Description Default GetCommunity Enter the get community, which is the password for the incomingGet- and GetNext- requests from the management stat...
Page 116 - Chapter 9
P312 Broadband Security Gateway System Information & Diagnosis 9-1 Chapter 9 System Information & Diagnosis This chapter talks you through SMT Menus 24.1 to 24 .4. This chapter covers the diagnostic tools that help you to maintain your Prestige. These tools include updateson system status, p...
Page 117 - Status; System Maintenance - Status
P312 Broadband Security Gateway 9-2 System Information & Diagnosis 9.1 System Status The first selection, System Status, gives you information on the version of your system firmware and thestatus and statistics of the ports, as shown in the figure below. System Status is a tool that can be used ...
Page 118 - System Maintenance - Status Menu Fields
P312 Broadband Security Gateway System Information & Diagnosis 9-3 The following table describes the fields present in Menu 24.1 - System Maintenance - Status . Table 9-1 System Maintenance - Status Menu Fields Field Description Port The WAN or LAN port. Status Shows the port speed and duplex se...
Page 119 - System Information and Console Port Speed; Menu 24 – System Maintenance; Menu 24.2 - System Information and Console Port Speed; From this Menu you have two choices as shown in the next figure:; Menu 24.2 – System Information and Console Port Speed; Information
P312 Broadband Security Gateway 9-4 System Information & Diagnosis 9.2 System Information and Console Port Speed This section describes your system and allows you to choose different console port speeds. To get to theSystem Information and Console Port Speed: Step 1. Enter 24 to go to Menu 24 – ...
Page 120 - Fields in System Maintenance; Menu 24.2.2 – System Maintenance – Change
P312 Broadband Security Gateway System Information & Diagnosis 9-5 Table 9-2 Fields in System Maintenance Field Description Name This is the Prestige's system name + domain name assigned in Menu1. E.G., System Name= xxx; Domain Name= baboo.mickey.com Name= xxx.baboo.mickey.com Routing Refers to ...
Page 121 - From Menu 24, select option 3 to open; Examples of Error and Information Messages; Syslog; and Accounting
P312 Broadband Security Gateway 9-6 System Information & Diagnosis 9.3.1 Viewing Error Log The first place you should look for clues when something goes wrong is the error/trace log. Follow theprocedure below to view the local error/trace log: Step 1. Select option 24 from the Main Menu to open ...
Page 122 - System Maintenance Menu Syslog Parameters
P312 Broadband Security Gateway System Information & Diagnosis 9-7 Figure 9-8 Menu 24.3.2 - System Maintenance – UNIX Syslog You need to configure the UNIX syslog parameters described in the following table to activate syslog thenchoose what you want to log. Table 9-3 System Maintenance Menu Sys...
Page 123 - Packet triggered
P312 Broadband Security Gateway 9-8 System Information & Diagnosis 1. CDR CDR Message Format SdcmdSyslogSend( SYSLOG_CDR, SYSLOG_INFO, String );String = board xx line xx channel xx, call xx, strboard = the hardware board IDline = the WAN ID in a boardChannel = channel ID within the WANcall = the...
Page 125 - Packet; in hex format. An example is shown; Call-Triggering Packet Example
P312 Broadband Security Gateway 9-10 System Information & Diagnosis 9.3.3 Call-Triggering Packet Call-Triggering Packet displays information about the packet that triggered a dial-out call in an easyreadable format. Equivalent information is available in Menu 24.1 in hex format. An example is sh...
Page 126 - DHCP; IP Address Assignment
P312 Broadband Security Gateway System Information & Diagnosis 9-11 Figure 9-10 Menu 24.4 - System Maintenance - Diagnostic Follow the procedure below to get to Menu 24.4 - System Maintenance – Diagnostic. Step 1. From the Main Menu, select option 24 to open Menu 24 - System Maintenance . Step 2...
Page 127 - System Maintenance Menu Diagnostic; Number
P312 Broadband Security Gateway 9-12 System Information & Diagnosis Figure 9-11 WAN & LAN DHCP The following table describes the diagnostic tests available in Menu 24.4 for your Prestige and the connections. Table 9-4 System Maintenance Menu Diagnostic Number Field Description 1 Ping Host En...
Page 128 - Transferring Files; firmware and a new configuration file.; Filename conventions
P312 Broadband Security Gateway Transferring Files 10-1 Chapter 10 Transferring Files This chapter tells you how to back up and restore your configuration file as well as upload new firmware and a new configuration file. 10.1 Filename conventions The configuration file (often called the romfile or r...
Page 129 - Filename Conventions; Backup Configuration; Option 5 from; allows you to backup the current Prestige configuration to
P312 Broadband Security Gateway 10-2 Transferring Files Table 10-1 Filename Conventions File Type Internal Name External Name Description AT Command ConfigurationFile Rom-0 *.rom This is the router configuration filenameon the Prestige. Uploading the rom-0 filereplaces the entire ROM file system,inc...
Page 130 - Restore Configuration; - Restore Configuration; atur
P312 Broadband Security Gateway Transferring Files 10-3 10.3 Restore Configuration Menu 24.6 -- System Maintenance - Restore Configuration allows you to restore the configuration via the console port.FTP and TFTP are the preferred methods for restoring your current workstation configuration to yourP...
Page 131 - Uploading Router Configuration File; atlc
P312 Broadband Security Gateway 10-4 Transferring Files Step 4. After successful firmware upload, enter atgo to restart the Prestige. Figure 10-4 Menu 24.7.1 - System Maintenance - Upload Router Firmware 10.4.2 Uploading Router Configuration File The configuration data, system-related data, the erro...
Page 132 - TFTP File Transfer; Menu 24 – System; sys stdio 0
P312 Broadband Security Gateway Transferring Files 10-5 Figure 10-5 Menu 24.7.2 - System Maintenance - Upload Router Configuration File 10.5 TFTP File Transfer In addition to the direct console port connection, the Prestige supports the up/downloading of the firmwareand the configuration file using ...
Page 133 - Third Party TFTP Clients –General fields; Host; Binary; Abort; You have disabled Telnet service in Menu 24.11.
P312 Broadband Security Gateway 10-6 Transferring Files Note: If you upload the firmware to the Prestige, it will reboot automatically when the file transfer is completed (the SYS LED will flash). Note that the telnet connection must be active and the SMT in CI mode before and during the TFTPtransfe...
Page 134 - FTP File Transfer; You see the following screen when you telnet into Menu 24.7.2.
P312 Broadband Security Gateway Transferring Files 10-7 10.6 FTP File Transfer In addition to uploading the firmware and configuration via the console port and TFTP client, you can alsoupload the Prestige firmware and configuration files using FTP. To use this feature, your workstation musthave an F...
Page 135 - Using the FTP command from the DOS Prompt; open
P312 Broadband Security Gateway 10-8 Transferring Files Figure 10-7 Telnet into Menu 24.7.2 - System Maintenance To transfer the firmware and the configuration file, follow these examples: 10.6.1 Using the FTP command from the DOS Prompt Step 1. Launch the FTP client on your workstation. Step 2. Typ...
Page 136 - FTP Session Example; Third Party FTP Clients –General fields
P312 Broadband Security Gateway Transferring Files 10-9 Figure 10-8 FTP Session Example The system reboots after a successful upload. The following table describes some of the fields that you may see in third party FTP clients. Table 10-3 Third Party FTP Clients –General fields Host Address Enter th...
Page 138 - System Maintenance & Information; Command Interpreter Mode; from; System Maintenance; prompt. Type “exit” to return to the SMT main menu when finished.; Command Mode in Menu 24
P312 Broadband Security Gateway System Maintenance & Information 11-1 Chapter 11 System Maintenance & Information This chapter leads you through SMT menus 24.8 to 24.11. 11.1 Command Interpreter Mode The Command Interpreter (CI) is a part of the main router firmware. The CI provides much of ...
Page 139 - Call Control Support; Management; Maintenance - Call Control
P312 Broadband Security Gateway 11-2 System Maintenance & Information 11.2 Call Control Support The Prestige provides two call control functions: budget management and call history. Please note that thismenu is only applicable when Encapsulation is set to PPPoE or PPTP in Menu 4 or Menu 11.1. Th...
Page 140 - Budget Management; This is the second option in; Call History
P312 Broadband Security Gateway System Maintenance & Information 11-3 The total budget is the time limit on the accumulated time for outgoing calls to a remote node. When thislimit is reached, the call will be dropped and further outgoing calls to that remote node will be blocked.After each peri...
Page 141 - Call History Fields; Time and Date Setting
P312 Broadband Security Gateway 11-4 System Maintenance & Information Table 11-2 Call History Fields Field Description Phone Number The PPPoE service names are shown here. Dir This shows whether the call was incoming or outgoing. Rate This is the transfer rate of the call. #call This is the numb...
Page 142 - System Maintenance – Time and Date Setting
P312 Broadband Security Gateway System Maintenance & Information 11-5 Figure 11-6 System Maintenance – Time and Date Setting Table 11-3 Time and Date Setting Fields Field Description Use Time Server whenBootup= Enter the time service protocol that your timeserver will send when thePrestige power...
Page 143 - Remote Management Setup
P312 Broadband Security Gateway 11-6 System Maintenance & Information zone and Greenwich mean Time (GMT). Be aware if/when daylightsavings time alters this time difference for your time zone. Once you have filled in the new time and date, press [Enter] to save the setting and press [Esc] toretur...
Page 144 - Option to Enter Debug Mode
P312 Broadband Security Gateway System Maintenance & Information 11-7 Table 11-4 Menu 24.11 - Remote Management Control Field Description Option FTP service active Press the [SPACE BAR] to toggle Yes to No and press [Enter] to disable all FTP activity (both LAN and WAN). Yes No Telnet service ac...
Page 145 - Boot Module Commands
P312 Broadband Security Gateway 11-8 System Maintenance & Information Figure 11-9 Boot Module Commands ======= Debug Command Listing ======= AT just answer OKATHE print helpATBAx change baudrate. 1:38.4k, 2:19.2k, 3:9.6k 4:57.6k 5:115.2kATENx,(y) set BootExtension Debug Flag (y=password)ATSE sho...
Page 146 - Telnet Configuration and Capabilities; About Telnet Configuration; Telnet Configuration on a TCP/IP Network; Telnet Under NAT
P312 Broadband Security Gateway Telnet 12-1 Chapter 12 Telnet Configuration and Capabilities This chapter covers the Telnet Configuration and Capabilities of the Prestige. 12.1 About Telnet Configuration Before the Prestige is properly setup for TCP/IP, the only option for configuring it is through ...
Page 147 - Telnet Under the Firewall
P312 Broadband Security Gateway 12-2 Telnet 12.3.2 System Timeout There is a system timeout of 5 minutes (300 seconds) for either the console port or telnet. Your Prestigewill automatically log you out if you do nothing in this timeout period, except when it is continuouslyupdating the status in Men...
Page 148 - Firewall and Content Filters
Firewall and Content Filters IV Part IV: Firewall and Content Filters Chapters 13 – 20 describe types of firewalls, how to configure your Prestige firewall using the Prestige Web Configurator, as well as types of Denial of Services (DoS) attacks and Content Filtering.
Page 149 - P312 Broadband Security Gateway; What is a Firewall; This chapter gives some background information on firewalls.; Types of Firewalls
P312 Broadband Security Gateway What Is a Firewall? 13-1 Chapter 13 What is a Firewall This chapter gives some background information on firewalls. Originally, the term firewall referred to a construction technique designed to prevent the spread of fire from one room to another. The network term fir...
Page 150 - Introduction to ZyXEL’s Firewall
P312 Broadband Security Gateway 13-2 What Is a Firewall? needed to filter application traffic and direct it to a number of specific systems. The router need onlyallow application traffic destined for the application gateway and reject the rest. 13.1.3 Stateful Inspection firewalls Stateful Inspectio...
Page 151 - Prestige Firewall Application; Denial of Service
P312 Broadband Security Gateway What Is a Firewall? 13-3 Figure 13-1 Prestige Firewall Application 13.3 Denial of Service Denials of Service (DoS) attacks are aimed at devices and networks with a connection to the Internet. Theirgoal is not to steal information, but to disable a device or network so...
Page 152 - Common IP Ports; There are four types of DoS attacks:
P312 Broadband Security Gateway 13-4 What Is a Firewall? Table 13-1 Common IP Ports 21 FTP 53 DNS 23 Telnet 80 HTTP 25 SMTP 110 POP3 13.3.2 Types of DoS attacks There are four types of DoS attacks: 1. Those that exploit bugs in a TCP/IP implementation. 2. Those that exploit weaknesses in the TCP/IP ...
Page 153 - SYN Flood
P312 Broadband Security Gateway What Is a Firewall? 13-5 Under normal circumstances, the application that initiates a session sends a SYN (synchronize) packet to thereceiving server. The receiver sends back an ACK (acknowledgment) packet and its own SYN, and then theinitiator responds with an ACK (a...
Page 154 - Smurf Attack; Stateful Inspection; saving the
P312 Broadband Security Gateway 13-6 What Is a Firewall? Figure 13-4 Smurf Attack 4. Often, many DoS attacks also employ a technique known as "IP Spoofing" as part of their attack. IPSpoofing may be used to break into systems, to hide the hacker's identity, or to magnify the effect of theDoS...
Page 155 - Stateful Inspection; The packet travels from the firewall's LAN to the WAN.
P312 Broadband Security Gateway What Is a Firewall? 13-7 Figure 13-5 Stateful Inspection Figure 13-5 shows the Prestige’s default firewall rules in action as well as demonstrates how statefulinspection works. User A can initiate a Telnet session from within the LAN and responses to this request area...
Page 157 - Guidelines For Enhancing Security With Your Firewall; Change the default password on the SMT and Web Configurator.
P312 Broadband Security Gateway What Is a Firewall? 13-9 When any subsequent packet hits the box (from the Internet or from the LAN), its connection information isextracted and checked against the cache. A packet is only allowed to pass through if it corresponds to a validconnection (that is, if it ...
Page 161 - Introducing the Prestige Firewall; some background information on firewalls.; Menu 21 - Filter Set and Firewall Configuration.
P312 Broadband Security Gateway Introducing the Prestige Firewall 14-1 Chapter 14 Introducing the Prestige Firewall This chapter shows you how to get started with the Prestige Firewall. Please see Chapter 13 for some background information on firewalls. 14.1 SMT Menus From the Main Menu (see below) ...
Page 162 - Menu 21.2 – Firewall Setup; Maintenance - UNIX Syslog
P312 Broadband Security Gateway 14-2 Introducing the Prestige Firewall Figure 14-3 Menu 21.2 – Firewall Setup Please note that you can only configure the firewall rules using the Prestige Web Configurator or CLI commands. 14.1.1 View Firewall Log Enter 3 from menu 21 to view the firewall log. Firewa...
Page 163 - ICMP Echo; MESSAGE; Legal SMTP Commands
P312 Broadband Security Gateway Introducing the Prestige Firewall 14-3 ICMP Echo A brute-force attack, such as a "Smurf" attack, targets a feature in the IP specification known as directed orsubnet broadcasting, to quickly flood the target network with useless data. A Smurf hacker floods a r...
Page 164 - Traceroute
P312 Broadband Security Gateway 14-4 Introducing the Prestige Firewall Traceroute Traceroute is a utility used to determine the path a packet takes between two endpoints. Sometimes when a packet filter firewall is configured incorrectly an attacker can traceroute the firewall gaining knowledge ofthe...
Page 165 - View Firewall Log; The Big Picture – Filtering, Firewall and NAT
P312 Broadband Security Gateway Introducing the Prestige Firewall 14-5 Table 14-4 View Firewall Log Field Description # This is the index number of the firewall log. 128 entries are available numbered from 0 to127. Once they are all used, the log will wrap around and the old logs will be lost. mm:dd...
Page 166 - Big Picture - Filtering, Firewall and NAT; Packet Filtering Vs Firewall
P312 Broadband Security Gateway 14-6 Introducing the Prestige Firewall Figure 14-5 Big Picture - Filtering, Firewall and NAT 14.3 Packet Filtering Vs Firewall Below are some comparisons between the Prestige’s filtering and firewall functions. 14.3.1 Packet Filtering: ! The router filters packets as ...
Page 167 - When To Use Filtering; To block/allow LAN packets by their MAC address.; When To Use The Firewall; To prevent DoS attacks and prevent hackers cracking your network.
P312 Broadband Security Gateway Introducing the Prestige Firewall 14-7 When To Use Filtering 1. To block/allow LAN packets by their MAC address. 2. To block/allow special IP packets which are neither TCP, UDP, nor ICMP packets. 3. To block/allow both inbound (WAN to LAN) and outbound (LAN to WAN) tr...
Page 169 - Introducing the Prestige Web Configurator; Web Configurator Login and Welcome Screens; Login screen as seen in Netscape; You have an SMT console session running.
P312 Broadband Security Gateway Introducing the Prestige Web Configurator 15-1 Chapter 15 Introducing the Prestige Web Configurator This chapter shows you how to configure your firewall with the Web Configurator. 15.1 Web Configurator Login and Welcome Screens Launch your web browser and enter 192.1...
Page 170 - Prestige Web Configurator Welcome Screen; Enabling the Firewall
P312 Broadband Security Gateway 15-2 Introducing the Prestige Web Configurator Figure 15-2 Prestige Web Configurator Welcome Screen 15.2 Enabling the Firewall Click Firewall, then Configuration, then the Rule Config tab to enable the firewall as seen in the followingscreen.
Page 171 - Enabling the Firewall; screen
P312 Broadband Security Gateway Introducing the Prestige Web Configurator 15-3 Figure 15-3 Enabling the Firewall 15.3 E-Mail This screen allows you to specify your mail server, where e-mail alerts should be sent as well as when andhow often they should be sent. 15.3.1 What are Alerts? Alerts are rep...
Page 172 - To; field and schedule times for sending alerts in the; Alert Timer; . You can also choose not to create a log for a rule in
P312 Broadband Security Gateway 15-4 Introducing the Prestige Web Configurator To field and schedule times for sending alerts in the Alert Timer fields in the E-Mail screen (following screen). 15.3.2 What are Logs? A log is a detailed record that you create for packets that either match a rule, don’...
Page 174 - SMTP Error Messages
P312 Broadband Security Gateway 15-6 Introducing the Prestige Web Configurator 15.3.3 SMTP Error Messages If there are difficulties in sending e-mail the following error messages appear. Please see the Support Noteson the accompanying CD for information on other types of error messages.E-mail error ...
Page 176 - TCP Maximum Incomplete And Blocking Time
P312 Broadband Security Gateway 15-8 Introducing the Prestige Web Configurator You can use the default threshold values, or you can change them to values more suitable to your securityrequirements. 15.4.1 Threshold Values: You really just need to tune these parameters when something is not working a...
Page 177 - Blocking Time
P312 Broadband Security Gateway Introducing the Prestige Web Configurator 15-9 The Prestige deletes the oldest existing half-open session for the host for every new connection request to thehost. This ensures that the number of half-open sessions to a given host will never exceed the threshold.2. If...
Page 178 - Attack Alert
P312 Broadband Security Gateway 15-10 Introducing the Prestige Web Configurator Table 15-3 Attack Alert Field Description Default Values Generate alert whenattack detected A detected attack automatically generatesa log entry. Check this box to generate analert (as well as a log) whenever an attackis...
Page 181 - Creating Custom Rules; Allow access to a Web server to everyone but competitors.; Rule Logic Overview; Is the intent of the rule to forward or block traffic?
P312 Broadband Security Gateway Creating Custom Rules 16-1 Chapter 16 Creating Custom Rules 16.1 Rules Overview Firewall rules are subdivided into “Local Network” and “Internet”. By default, the Prestige’s stateful packetinspection allows all communications to the Internet that originate from the lo...
Page 183 - Connection Direction; LAN to WAN Traffic
P312 Broadband Security Gateway Creating Custom Rules 16-3 16.3 Connection Direction This section talks about configuring firewall rules for connections going from LAN to WAN and WAN toLAN in your firewall. 16.3.1 LAN to WAN Rules The default rule for LAN to WAN traffic is that all users on the LAN ...
Page 184 - WAN to LAN Traffic; Services Supported; Rule Config
P312 Broadband Security Gateway 16-4 Creating Custom Rules Figure 16-2 WAN to LAN Traffic 16.4 Services Supported The list box in the Rule Config (uration) screen ( see Figure 16-4 ) displays all services that the Prestige supports. Custom services may also be configured using the Custom Ports funct...
Page 185 - Services Supported
P312 Broadband Security Gateway Creating Custom Rules 16-5 Table 16-1 Services Supported SERVICE DESCRIPTION BGP(TCP:179) Border Gateway Protocol BOOTP_CLIENT(UDP:68) DHCP Client BOOTP_SERVER(UDP:67) DHCP Server CU-SEEME(TCP/UDP:7648, 24032) A popular videoconferencing solution from White Pines Soft...
Page 186 - Click on; to bring up the following screen. This screen is a summary of the; Firewall Rules Summary – First Screen
P312 Broadband Security Gateway 16-6 Creating Custom Rules 16.5 Rule Summary The fields in the Rule Summary screens are the same for Local Network and Internet , so the discussion below refers to both. Click on Firewall , then Local Network to bring up the following screen. This screen is a summary ...
Page 188 - button from the screen above to display the
P312 Broadband Security Gateway 16-8 Creating Custom Rules Field Description Option section 16.5.1 for more details. Delete Press this button to delete an existing firewall rule.Note that subsequent firewall rules move up by onewhen you take this action. Move Rule You may reorder your rules using th...
Page 189 - Creating/Editing A Firewall Rule
P312 Broadband Security Gateway Creating Custom Rules 16-9 Figure 16-4 Creating/Editing A Firewall Rule Table 16-3 Creating/Editing A Firewall Rule Field Description Option Source Address Press SrcAdd to add a new address, SrcEdit to edit an existing one or SrcDelete to delete one. Please see the ne...
Page 190 - SrcAdd
P312 Broadband Security Gateway 16-10 Creating Custom Rules Field Description Option from the Available Services box on the left, then press >> to select it. The selected service shows up on the Selected Services box on the right. To remove a service, clickon it in the Selected Services box on...
Page 191 - Adding/Editing Source & Destination Addresses
P312 Broadband Security Gateway Creating Custom Rules 16-11 Figure 16-5 Adding/Editing Source & Destination Addresses Table 16-4 Adding/Editing Source & Destination Addresses Field Description Option Address Type Do you want your rule to apply to packets with a particular(single) IP, a range...
Page 192 - Apply; Cancel; Help; Click on either
P312 Broadband Security Gateway 16-12 Creating Custom Rules When you have finished, click Apply to save your customized settings and exit this screen, Cancel to exit this screen without saving, or Help for online HTML help on fields in this screen. 16.6 Timeout The fields in the Timeout screens are ...
Page 193 - Timeout Screen
P312 Broadband Security Gateway Creating Custom Rules 16-13 Figure 16-6 Timeout Screen
Page 194 - Timeout Menu
P312 Broadband Security Gateway 16-14 Creating Custom Rules Table 16-5 Timeout Menu Field Description Default Value TCP Timeout Values Connection Timeout This is the length of time the Prestige waits for a TCPsession to reach the established state before droppingthe session. 30 seconds FIN-Wait Time...
Page 195 - . For further information on these services, please read; Custom Ports; to bring up the following screen.; Custom Ports; The next table describes the fields in this screen.
P312 Broadband Security Gateway Custom Ports 17-1 Chapter 17 Custom Ports 17.1 Introduction You will need to configure customized ports for services not included in the services provided in thescrolling list box in the screen shown in Figure 16-4 . For further information on these services, please r...
Page 197 - Creating/Editing A Custom Port
P312 Broadband Security Gateway Custom Ports 17-3 Figure 17-2 Creating/Editing A Custom Port The next table describes the fields in this screen.
Page 199 - Logs; to bring up the next screen. Firewall logs may also be viewed in; and the old logs are lost.; Log Screen
P312 Broadband Security Gateway Logs 18-1 Chapter 18 Logs 18.1 Log Screen When you configure a new rule you also have the option to log events that match, don’t match (or both) thisrule ( see Figure 16-4 ). Click on the Logs to bring up the next screen. Firewall logs may also be viewed in SMT Menu 2...
Page 203 - Example Firewall Rules; for a; tab, then check the; Firewall Enabled; see the Appendix
P312 Broadband Security Gateway Example Firewall Rules 19-1 Chapter 19 Example Firewall Rules 19.1 Examples Please note that whenever you open a hole in the firewall to forward a service from the Internet to the localnetwork, and NAT is also enabled, you may have to also configure a server behind NA...
Page 204 - Activate The Firewall; Now we configure our
P312 Broadband Security Gateway 19-2 Examples Firewall Rules Figure 19-1 Activate The Firewall Step 2. Now we configure our E-mail screen as follows. Click the E-Mail tab to bring up the next screen. Check here to activate the firewall.You may also activate the firewall inSMT menu 21.2.
Page 205 - Example 1 – E-Mail Screen; Figure
P312 Broadband Security Gateway Example Firewall Rules 19-3 Figure 19-2 Example 1 – E-Mail Screen Step 3. Now we configure our firewall rule as shown in the following screen. The default firewallblocks all Internet traffic entering our local network, but we want to create a hole for webservice from ...
Page 206 - Example 1 – Configuring A Rule; Click; DestAdd
P312 Broadband Security Gateway 19-4 Examples Firewall Rules Figure 19-3 Example 1 – Configuring A Rule This is an Internet toLocal Network rule. Click DestAdd to configure the destinationaddress as the IP of ourserver on the LAN. Seethe next screen. Click this button when youhave finished editing s...
Page 208 - Example 1 - Rule Summary Screen; Example 2 – Small Office With Mail, FTP and Web Servers
P312 Broadband Security Gateway 19-6 Examples Firewall Rules Figure 19-5 Example 1 - Rule Summary Screen 19.1.2 Example 2 – Small Office With Mail, FTP and Web Servers Our small office has:i. A mail server with an IP of 192.168.10.2. ii. Two FTP servers. We want FTP server One (IP of 192.168.10.3) t...
Page 209 - Configure the E-Mail screen as shown in example 1; and configure the screen as follows.
P312 Broadband Security Gateway Example Firewall Rules 19-7 Step 1. First we want to send alerts when there is an attack. Go to the Attack Alert screen (click Configuration , then the Attack Alert tab) shown next. Figure 19-6 Send Alerts When Attacked Step 2. Configure the E-Mail screen as shown in ...
Page 210 - Configuring A POP Custom Port; Source Address; Single
P312 Broadband Security Gateway 19-8 Examples Firewall Rules Figure 19-7 Configuring A POP Custom Port Step 4. Now, we will create rules to block all outgoing traffic (from the local network to the Internet)except for traffic originating from the HTTP proxy server and our mail server. Click Internet...
Page 211 - Example 2 - Local Network Rule 1 Configuration
P312 Broadband Security Gateway Example Firewall Rules 19-9 Figure 19-8 Example 2 - Local Network Rule 1 Configuration Step 6. Similarly configure another local network to Internet rule allowing traffic from our web (HTTP)proxy server. Step 7. The Rule Summary screen should look like Figure 19-9 . D...
Page 212 - Example 2 - Local Network Rule Summary; Destination Address
P312 Broadband Security Gateway 19-10 Examples Firewall Rules Figure 19-9 Example 2 - Local Network Rule Summary Step 8. Now we want an FTP server (IP of 192.168.10.3) to be accessible from the Internet. Rememberthe default Internet to Local Network ACL set blocks all traffic from the Internet, so w...
Page 213 - Example 2 - Internet to Local Network Rule Summary
P312 Broadband Security Gateway Example Firewall Rules 19-11 Figure 19-10 Example 2 - Internet to Local Network Rule Summary 19.1.3 Example 3: DHCP Negotiation and Syslog Connection from theInternet The following are some Internet firewall rules examples to:1. Allow DHCP negotiation between the ISP ...
Page 214 - Custom Port for Syslog
P312 Broadband Security Gateway 19-12 Examples Firewall Rules Figure 19-11 Custom Port for Syslog Step 2. Follow the procedures outlined in the previous examples to configure all your rules. Whenfinished, your rule summary screen should look like the following. Custom ports show up with an“*” before...
Page 215 - Syslog Rule Configuration
P312 Broadband Security Gateway Example Firewall Rules 19-13 Figure 19-12 Syslog Rule Configuration This is ourSyslogcustom port. Click Apply when finished. This is the address rangeof the syslog servers.
Page 216 - Example 3 Rule Summary; to save your
P312 Broadband Security Gateway 19-14 Examples Firewall Rules Figure 19-13 Example 3 Rule Summary Rule 1: Allow DHCP negotiation between the ISP and the P312.Rule 2: Allow a syslog connection from the WAN. Click Apply to save your settings back to the Prestige.
Page 217 - Content Filtering; Restrict Web Features
P312 Broadband Security Gateway Content Filtering 20-1 Chapter 20 Content Filtering The Prestige can block web features such as ActiveX controls, Java applets, cookies as well as disable webproxies. The Prestige can also block specific URLs by using the keyword feature. Please note that content filt...
Page 218 - Domain Name; field. The Prestige looks at the; Content Filtering Using the Web Configurator; Main Menu
P312 Broadband Security Gateway 20-2 Content Filtering 20.1.3 Cookies Cookies are used by Web servers to track usage. Cookies provide service based on ID. Unfortunately,cookies can be programmed not only to identify the visitor to the site, but also to track that visitor's activities.Because they re...
Page 219 - Figure 20-1 Content Filtering Screen
P312 Broadband Security Gateway Content Filtering 20-3 Figure 20-1 Content Filtering Screen Table 20-1 Content Filtering Fields Field Description Restrict Web Features Check the box(es) to restrict that feature. When you download a pagecontaining a restricted feature, that part of the web page will ...
Page 220 - Troubleshooting, Appendices, Glossary and Index; a Glossary of Terms and an Index.
Troubleshooting, Appendices, Glossary and Index V Part V: Troubleshooting, Appendices, Glossary and Index Chapter 21 provides information about solving common problems, followed by some Appendices, a Glossary of Terms and an Index.
Page 222 - Troubleshooting; problem. Please see our supporting disk for further information.; Problems Starting Up the Prestige; Troubleshooting the Start-Up of your Prestige; Problem
P312 Broadband Security Gateway Troubleshooting 21-1 Chapter 21 Troubleshooting This chapter covers the potential problems you may run into and the possible remedies. After each problem description, some instructions are provided to help you to diagnose and to solve the problem. Please see our suppo...
Page 223 - Problems with the LAN Interface; Troubleshooting the LAN Interface; Problems with the WAN interface; Troubleshooting the WAN interface
P312 Broadband Security Gateway 21-2 Troubleshooting 21.2 Problems with the LAN Interface Table 21-2 Troubleshooting the LAN Interface Problem Corrective Action Check the 10M/100M LEDs on the front panel. One of these LEDsshould be on. If they are both off, check the cables between yourPrestige and ...
Page 224 - Problems with Internet Access; Troubleshooting Internet Access; Problems with the Firewall
P312 Broadband Security Gateway Troubleshooting 21-3 21.4 Problems with Internet Access Table 21-4 Troubleshooting Internet Access Problem Corrective Action Connect your Cable/xDSL modem with the Prestige usingappropriate cable. Check with the manufacturer of your Cable/xDSL modem about thecable req...
Page 226 - Appendix A; PPPoE in Action; PPPoE offers the following benefits:; Traditional Dial-up Scenario
P312 Broadband Security Gateway PPPoE E Appendix A PPPoE PPPoE in Action An ADSL modem bridges a PPP session over Ethernet (PPP over Ethernet, RFC 2516) from your PC to anATM PVC (Permanent Virtual Circuit) which connects to a xDSL Access Concentrator where the PPPsession terminates (see the next fi...
Page 227 - How PPPoE Works
P312 Broadband Security Gateway PPPoE F How PPPoE Works The PPPoE driver makes the Ethernet appear as a serial link to the PC and the PC runs PPP over it, while themodem bridges the Ethernet frames to the Access Concentrator (AC). Between the AC and an ISP, the AC isacting as a L2TP (Layer 2 Tunneli...
Page 228 - Appendix B; PPTP and the Prestige; . In the case above as; PPTP Protocol Overview
P312 Broadband Security Gateway PPTP G Appendix B PPTP What is PPTP? PPTP (Point-to-Point Tunneling Protocol) is a Microsoft proprietary protocol (RFC 2637 for PPTP isinformational only) to tunnel PPP frames. How can we transport PPP frames from a PC to a broadband modem over Ethernet? A solution is...
Page 229 - Control & PPP connections; Call ID
P312 Broadband Security Gateway PPTP H PNS and the PAC must have IP connectivity; however, the PAC must in addition have dial-up capability.The phone call is between the user and the PAC and the PAC tunnels the PPP frames to the PNS. The PPTPuser is unaware of the tunnel between the PAC and the PNS....
Page 230 - Appendix C
P312 Broadband Security Gateway Hardware Specifications I Appendix C Hardware Specifications Power Specification I/P AC 120V / 60Hz ; O/P DC 12V 1200 mA MTBF 100000 hrs Operation Temperature 0º C ~ 40º C Ethernet Specification forWAN 10Mbit Half Duplex Ethernet Specification forLAN 10/100 Mbit Half ...
Page 231 - Appendix D; Be sure to read and follow all warning notices and instructions.
P312 Broadband Security Gateway J Safety Instructions Appendix D Important Safety Instructions The following safety instructions apply to the Prestige:1. Be sure to read and follow all warning notices and instructions. 2. The maximum recommended ambient temperature for the Prestige is 40º(104º). Car...
Page 232 - Appendix E; Command Interpreter Mode; from the Main Menu to go into CLI
P312 Broadband Security Gateway CLI Commands K Appendix E Firewall CLI Commands The following table describes the syntax used to configure your firewall using Command Line Interface(CLI) commands. Select option 24.8 Command Interpreter Mode from the Main Menu to go into CLI mode. For details on othe...
Page 237 - Appendix F; AC Power Adapter Specifications
P312 Broadband Security Gateway P Power Adapter Specifications Appendix F Power Adapter Specs AC Power Adapter Specifications North AmericaAC Power Adapter model MW48-1201200Input power: AC120Volts/60HzOutput power: DC12Volts/1.2APower consumption: 9 WPlug: North American standardsSafety standards: ...
Page 239 - Glossary of Terms
P312 Broadband Security Gateway R Glossary Glossary of Terms 10BaseT The 10-Mbps baseband Ethernet specification that uses two pairs of twisted-paircabling (Category 3 or 5): one pair for transmitting data and the other for receivingdata. ARP Address Resolution Protocol is a protocol for mapping an ...
Page 250 - Index
P312 Broadband Security Gateway Index CC Index A Action for Matched Packets .......................... 16-10Activate The Firewall ...................................... 19-2ActiveX ........................................................... 20-1Add Keyword ..............................................