EasyManua.ls Logo

ZyXEL Communications USG FLEX H Series User Manual

ZyXEL Communications USG FLEX H Series
462 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
Default Login Details
User’s Guide
USG FLEX H Series
Copyright © 2023 Zyxel and/or its affiliates. All rights reserved.
Login IP Address https://192.168.168.1
User Name admin
Password 1234
Version 1.10 Edition 2, 9/2023

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the ZyXEL Communications USG FLEX H Series and is the answer not in the manual?

ZyXEL Communications USG FLEX H Series Specifications

General IconGeneral
TypeFirewall
InterfacesEthernet
Security FeaturesFirewall, IPS, Anti-Virus, Anti-Spam
VPN ProtocolsIPSec, SSL, L2TP, PPTP
ManagementWeb GUI, CLI
High Availability (HA)Yes

Summary

CHAPTER 1 Introduction

1.1 Overview

Provides an overview of the Zyxel Device and its supported models.

1.2 Registration at Nebula Control Center (NCC)

Details the process for registering the Zyxel Device with the Nebula Control Center.

1.3 Management Overview

Outlines the methods available for managing the Zyxel Device.

1.4 Web Configurator

Explains how to access and use the Web Configurator for device management.

CHAPTER 2 Initial Setup Wizard

2.1 Initial Setup Wizard Overview

Describes the purpose and steps of the Initial Setup Wizard.

2.3 Connect to the Internet

Guides through configuring internet connection settings like DHCP or Static IP.

2.5 Device Registration

Explains the process of registering the Zyxel Device for service activation.

2.6 License Activations

Details how security services are activated automatically after device registration.

CHAPTER 3 Hardware, Interfaces and Zones

3.1 Hardware Overview

Describes the front and rear panels and port features of the Zyxel Device models.

3.2 Installation Scenarios

Summarizes installation options: desktop, wall-mounting, and rack-mounting.

3.3 Power Cord Lock

Provides instructions on using the power cord lock for securing the power cord.

3.4 Default Zones, Interfaces, and Ports

Details the default configurations for zones, interfaces, and ports on Zyxel Devices.

CHAPTER 4 Dashboard

4.1 Overview

Introduces the Dashboard screens for checking device status information.

4.2 The System Screen

Displays general device information, system status, and resource usage.

4.3 The Security Screen

Provides an overview of the security status information of the Zyxel Device.

CHAPTER 5 Monitor

5.1 Overview

Explains how to use Monitor screens to check status and statistics information.

5.2 The Port Statistics Screen

Displays packet statistics for each Gigabit Ethernet port.

5.3 The Interface Statistics Screen

Shows packet statistics for each interface, used in system operation.

5.4 The Resource Statistics Screen

Provides details on CPU usage, memory usage, and session usage.

5.5 The App Patrol Screen

Manages the use of various applications on the network with action and log settings.

5.6 The Content Filter Screen

Enables control over access to specific websites or web content.

5.7 The Reputation Filter Screens

Configures settings for IP Reputation, DNS Threat Filter, and URL Threat filtering.

5.8 The IPS Screen

Displays Intrusion Prevention System (IPS) statistics and manages signatures.

5.9 The Anti-Malware Screen

Displays anti-malware statistics and configures detection and actions.

5.10 The SSL Inspection Screens

Decrypts SSL traffic for inspection by security services.

5.11 The Sandbox Screen

Provides a safe environment to analyze unknown or untrusted programs and codes.

5.12 The Interface Screen

Lists all of the Zyxel Device’s interfaces and their information.

5.13 The Session Monitor Screen

Displays established sessions for debugging or statistical analysis.

5.14 The Device Insight Screen

Collects status and basic information of clients connected to Zyxel Device interfaces.

5.15 The Login Users Screen

Shows a list of users currently logged into the Zyxel Device.

5.16 The DHCP Table Screen

Lists interfaces and their DHCP-assigned IP addresses.

5.17 The IPSec VPN Screen

Displays and manages active IPSec SAs and remote access VPN clients.

5.18 The SSL VPN Screen

Tracks SSL VPN clients logged into the Zyxel Device and manages connections.

CHAPTER 6 Licensing

6.1 Licensing Overview

Guides on registering the Zyxel Device and managing service subscriptions.

6.1.2 The Licenses Screen

Displays the status of service registrations and license upgrades.

6.1.3 The Signature Update Screen

Explains how to download the latest signatures for licensed services.

CHAPTER 7 Interfaces

7.1 Interface Overview

Covers configuring Zyxel Device interfaces and creating new ones.

7.2 Interface Screen

Allows viewing Zyxel Device interface settings.

7.3 Internal/External Interface

Guides on configuring external and internal interface settings.

7.4 Bridge Interface

Explains how to combine network segments into a single network using bridges.

7.5 VTI Interface

Details IPSec VPN Tunnel Interface configuration and restrictions.

7.6 Trunk Overview

Explains using trunks for WAN traffic load balancing and reliability.

7.7 The Trunk Summary Screen

Lists configured trunks and their load balancing algorithms.

7.8 Port

Covers configuring port settings, speed, and duplex modes.

CHAPTER 8 Routing

8.1 Policy and Static Routes Overview

Explains overriding default routing behavior using policy and static routes.

8.2 Policy Route Screen

Allows viewing and configuring policy routes and bandwidth management.

8.3 Static Route Screen

Displays and configures static routes for network traffic.

CHAPTER 9 NAT

9.1 NAT Overview

Introduces Network Address Translation (NAT) for managing IP addresses.

9.2 The NAT Screen

Provides a summary of NAT rules and allows creation or modification.

9.2.1 The NAT Add/Edit Screen

Enables creation and editing of NAT rules.

CHAPTER 10 ALG

10.1 ALG Overview

Explains Application Layer Gateway (ALG) for proper FTP operation through NAT.

10.2 The ALG Screen

Allows turning ALGs on/off and configuring port numbers.

CHAPTER 11 IPSec VPN

11.1 Virtual Private Networks (VPN) Overview

Provides an overview of VPNs, focusing on secure communication over the Internet.

11.3 The Site to Site VPN Screen

Lists VPN connections, gateways, and settings; allows activation/deactivation.

11.4 The Remote Access VPN Screen

Configures rules for secure remote access to local networks.

CHAPTER 12 SSL VPN

12.1 Overview

Enables secure remote user login using a web browser without VPN router/client.

12.2 The SSL VPN Screen

Allows creation or editing of SSL access policies.

CHAPTER 13 Security Policy

13.1 Overview

Defines security settings applicable to specific traffic at specific times.

13.3 The Security Policy Screen

Enables/disables policies, asymmetrical routes, and manages policies.

13.4 DoS Prevention Overview

Introduces DoS prevention profiles and applying them to traffic.

13.5 Security Policy Example Applications

Provides examples of blocking LAN users from accessing specific applications.

CHAPTER 14 Object

14.1 Address/Geo IP Overview

Covers address objects, groups, and Geo IP for policy and security settings.

14.2 Service Overview

Defines TCP, UDP, and ICMP service objects and service groups.

14.3 Zone Overview

Explains setting up zones for network security and policy configuration.

14.4 Schedule Overview

Covers setting up one-time and recurring schedules for various policies.

CHAPTER 15 Application Patrol

15.1 Overview

Manages application usage on the network, including protocols and features.

15.2 Application Patrol Profile

Customizes action and log settings for application patrol signatures.

15.3 Example: Block an Application

Demonstrates blocking LAN clients from accessing a specific application like TikTok.

CHAPTER 16 Content Filtering

16.1 Overview

Provides control over access to specific websites or web content.

16.2 Content Filter General Screen

Enables content filtering, manages policies, and sets denial messages.

16.3 Content Filter Allow List Screen

Creates a list of good (allowed) web site addresses.

16.4 Content Filter Block List Screen

Creates a common list of bad (blocked) web site addresses.

16.5 Content Filter Blocked URL Keywords Screen

Creates a list of bad (blocked) URL keywords.

16.6 Test Web Site Category Screen

Checks which category a web page belongs to.

16.7 Example: Block LAN Users From Using a Remote WAN Application

Shows how to block LAN users from remote WAN applications like TeamViewer.

CHAPTER 17 Reputation Filter

17.1 Overview

Configures settings for IP Reputation, DNS Threat Filter, and URL Threat filtering.

17.2 IP Reputation Screen

Enables IP reputation and specifies actions for bad reputation IP addresses.

17.3 DNS Threat Filter Screen

Inspects DNS queries for clients and takes action on bad reputation FQDNs.

17.4 URL Threat Filter Screen

Enables URL Threat filtering and specifies actions for suspicious activities.

CHAPTER 18 Anti-Malware

18.1 Overview

Protects the network from malware by scanning WAN traffic for signatures.

18.2 Anti-Malware Screen

Turns anti-malware on/off and configures block/allow lists for malware patterns.

18.3 The Allow List Screen

Specifies file or hash patterns to allow, avoiding false positives.

18.4 The Block List Screen

Specifies file or hash patterns to block and log.

18.5 Anti-Malware Technical Reference

Provides background information on anti-malware scanner types.

CHAPTER 19 Sandbox

19.1 Overview

Provides a secure environment to analyze unknown or untrusted programs and codes.

19.2 Sandbox Screen

Enables sandbox and specifies actions for malicious or suspicious files.

CHAPTER 20 IPS

20.1 Overview

Introduces Intrusion Prevention System (IPS), custom signatures, and updates.

20.2 The IPS Screen

Displays IPS signature information and registration status.

20.3 The Allow List Screen

Lists signatures exempted from IPS inspection.

20.4 IPS Technical Reference

Provides background information on IPS and Snort equivalents.

CHAPTER 21 IP Exception

21.1 Overview

Allows incoming IP packets to bypass specific security services based on source/destination.

21.2 The IP Exception Screen

Views the IP exception list for specified services.

21.3 Example: Bypass a Website

Demonstrates creating an IP Exception profile to bypass specific security services.

CHAPTER 22 SSL Inspection

22.1 Overview

Decrypts SSL traffic for inspection by security services.

22.2 The SSL Inspection Profile Screen

Provides a template for pre-configured SSL Inspection certificates, actions, and logs.

22.3 Exclude List Screen

Configures an exclusion list to bypass matching sessions to destination servers.

22.4 Certificate Update Screen

Updates the latest certificates of servers using SSL connections.

22.5 Install a CA Certificate in a Browser

Steps to install a certificate in a computer's Windows operating system browser.

CHAPTER 23 User & Authentication

23.1 User/Group Overview

Describes setting up user accounts, groups, and rules for Zyxel Device traffic.

23.2 User Authentication Overview

Explains setting up AAA servers and two-factor authentication.

23.3 AAA Server Overview

Details how to use AAA servers for network access control.

23.4 Two-Factor Authentication Overview

Introduces the mechanism for double-layer security access.

CHAPTER 24 System

24.1 Overview

Covers configuring general Zyxel Device settings.

24.2 Settings

Configures hostname, system time, connection settings, and language.

24.3 SNMP

Explains Simple Network Management Protocol for managing network devices.

24.4 DNS & DDNS

Covers DNS server configuration for domain name resolution and DDNS.

24.5 Notification

Configures mail server settings and alert settings for reports.

24.6 Certificate Overview

Explains how certificates authenticate users based on public-private key pairs.

24.7 My Certificates

Provides a summary list of Zyxel Device's certificates and requests.

24.8 Trusted Certificates

Manages certificates accepted by Zyxel Device as trusted.

CHAPTER 25 Log and Report

25.1 Overview

Covers configuring daily reporting and log settings.

25.2 Log/Events Screen

Displays Zyxel Device log messages and allows filtering.

25.3 Log Settings Screen

Controls log messages, alerts, and storage on USB or syslog servers.

25.4 SecuReporter

Security analytics portal for log analysis, anomaly detection, and threat reporting.

25.5 Email Daily Report

Configures daily traffic reports and statistics via email.

CHAPTER 26 File Manager

26.1 Overview

Defines configuration files and covers storing, naming, and editing them.

26.2 The Configuration File Screen

Stores, runs, and names configuration files; allows download/upload.

26.3 Firmware Management

Checks current firmware version and uploads new firmware.

CHAPTER 27 Diagnostics

27.1 Overview

Provides an overview of diagnostic screens for troubleshooting.

27.2 The Diagnostics Screens

Generates configuration and diagnostic information files for customer support.

27.3 The Packet Capture Screen

Captures network traffic files for analysis using a packet analyzer.

27.4 The CPU / Memory Status Screen

Views CPU and memory performance of applications.

27.5 The System Log Screen

Lists diagnostic information files stored on the Zyxel Device or USB.

27.6 The Network Tool Screen

Performs network tests like ping and traceroute.

CHAPTER 28 Reboot

28.1 Overview

Instructions for rebooting the Zyxel Device.

28.2 The Reboot Screen

Provides options to reboot or shutdown the Zyxel Device.

CHAPTER 29 Troubleshooting

None of the LEDs turn on.

Troubleshooting steps for when device LEDs do not illuminate.

Cannot access the Zyxel Device from the LAN.

Steps to resolve issues accessing the Zyxel Device from the local network.

I cannot access the Internet.

Troubleshooting steps for when internet access is unavailable.

I cannot update the IPS/application patrol/IP reputation signatures.

Checks license and internet connection for signature update issues.

The content filter category service is not working.

Verifies internet connection for content filter service functionality.

I configured security settings but the Zyxel Device is not applying them for certain interfaces.

Ensures interfaces are assigned to zones for security settings to apply.

The Zyxel Device is not applying the custom policy route I configured.

Verifies custom policy route order for correct traffic application.

My rules and settings that apply to a particular interface no longer work.

Addresses issues where interface IP address changes affect rules.

I cannot set up a PPP interface.

Requires ISP account setup before creating PPPoE or PPTP interfaces.

The Zyxel Device’s performance slowed down after I configured many new application patrol entries.

Suggests optimizing application patrol entry order for performance.

The Zyxel Device destroyed/dropped a file/email without notifying me.

Ensures security features have logs enabled for notifications.

I cannot get Dynamic DNS to work.

Troubleshooting steps for Dynamic DNS connectivity issues.

I cannot get the application patrol to manage FTP traffic.

Verifies if the FTP ALG is enabled for application patrol.

The Zyxel Device keeps resetting the connection.

Addresses issues related to asymmetrical or triangle routes.

I cannot set up an IPSec VPN tunnel to another device.

Troubleshooting steps for IPSec VPN tunnel configuration errors.

APPENDIX A Customer Support

Required Information

Lists essential details needed when contacting customer support.

Corporate Headquarters (Worldwide)

Provides contact information for Zyxel's worldwide headquarters.

APPENDIX B Product Features

APPENDIX C Legal Information

Copyright

States the copyright information for the publication.

Disclaimer

Disclaims liability for product application or use issues.

Regulatory Notice and Statement (Class B)

Provides regulatory information for Class B digital devices.

FCC Statement

Details FCC compliance rules for device operation in the USA.

Environment Statement

Covers ecodesign requirements for energy-related products.

Disposal and Recycling Information

Provides guidelines for proper disposal and recycling of the product.

List of National Codes

Lists ISO 3166 2-letter country codes.

Safety Warnings

Lists important safety precautions for device usage and handling.

Related product manuals