EasyManua.ls Logo

ZyXEL Communications USG40 User Manual

ZyXEL Communications USG40
994 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
Quick Start Guide
www.zyxel.com
ZyWALL/USG Series
ZyWALL 110 / 310 / 1100
USG40 / USG40W / USG60 / USG60W / USG110 / USG210 /
USG310 / USG1100 / USG1900
UTM Security Firewalls
USG20-VPN / USG20W-VPN / USG2200-VPN
VPN Firewalls
Version 4.20
Edition 1, 8/2016
Copyright © 2016 Zyxel Communications Corporation
User’s Guide
Default Login Details
LAN Port IP Address https://192.168.1.1
User Name admin
Password 1234

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the ZyXEL Communications USG40 and is the answer not in the manual?

ZyXEL Communications USG40 Specifications

General IconGeneral
BrandZyXEL Communications
ModelUSG40
CategoryFirewall
LanguageEnglish

Summary

Chapter 1 Introduction

1.1 Overview

Provides an overview of the ZyWALL/USG series models and discusses key feature differences.

1.1.1 Applications

Details application scenarios like Security Router, IPv6 Routing, VPN Connectivity, SSL VPN Network Access, User-Aware Access Control, and Load Balancing.

1.3 Web Configurator

Details how to use the Web Configurator, including browser requirements and recommended screen resolution.

1.3.1 Web Configurator Access

Provides step-by-step instructions on how to access the Web Configurator, including login details and initial password change.

Chapter 2 Installation Setup Wizard

2.1 Installation Setup Wizard Screens

Describes the Installation Setup Wizard which helps configure Internet connection settings and activate subscription services.

2.1.1 Internet Access Setup - WAN Interface

Explains how to configure WAN interfaces, encapsulation type, and IP address assignment.

2.1.2 Internet Access: Ethernet

Details the Ethernet encapsulation screen, including IP address, subnet mask, and gateway configuration.

2.1.3 Internet Access: PPPoE

Explains the PPPoE encapsulation screen, including ISP parameters and WAN IP address assignments.

2.1.4 Internet Access: PPTP

Details the PPTP encapsulation screen, including ISP parameters and PPTP configuration.

2.1.5 Internet Access: L2TP

Describes the L2TP encapsulation screen, including ISP parameters and L2TP configuration.

Chapter 3 Hardware, Interfaces and Zones

3.2 Mounting

Explains how to mount the device in a rack or on a wall, covering installation requirements and procedures.

3.2.1 Rack-mounting

Details the steps for rack-mounting the ZyWALL/USG on an EIA standard size rack or in a wiring closet.

3.2.2 USG2200-VPN Rack Mounting

Covers installation requirements and procedures for rack-mounting the USG2200-VPN.

3.2.3 Wall-mounting

Explains how to attach the ZyWALL/USG to a wall, including drilling instructions and screw specifications.

3.4 Stopping the ZyWALL/USG

Explains the proper procedure for shutting down the device to prevent firmware corruption.

Chapter 4 Easy Mode

4.1.1 Wizards and Links

Describes the Easy Mode wizards and links, including Initial Setup Wizard, VPN Wizard, Port Forwarding Wizard, Wi-Fi and Guest Wizard, and Security Service Wizard.

4.1.2 Easy Mode Settings

Explains the Easy Mode settings menu, including Create Recovery Point, Restore Last Recovery Point, Restart, and Shutdown options.

4.1.3 Easy Mode Dashboard

Describes the Easy Mode dashboard, which displays system information, Internet information, VPN tunnel information, and network client status.

4.2.1 Initial Setup Wizard Screen 2 - Internet

Explains the screen for connecting to the Internet, including detecting Internet connectivity and manual entry.

4.2.2 Initial Setup Wizard Screen 2 - Internet Access Errors

Provides solutions for common Internet access error messages like WAN 1 Down, PPPoE Error, DHCP Error, and Ethernet Fixed IP Error.

4.2.4 Initial Setup Wizard Screen 4 - Wi-Fi

Explains how to configure Wi-Fi network name (SSID), password, and enable Guest Wi-Fi Network.

4.2.5 Initial Setup Wizard Screen 5 - Register

Shows registration status and license status for services like Content Filtering, IDP, and Anti-Virus.

4.3 Initial Setup Wizard Screen 7 - Security Service

Allows configuration of licensed services like Content Filter, IDP, and Anti-Virus, emphasizing activation at myZyXEL.com.

4.4 Initial Setup Wizard Screen 8 - Port Forwarding

Explains NAT port forwarding to direct incoming traffic from the Internet to the correct virtual server in the network.

4.5 Initial Setup Wizard Screen 9 - Guest LAN

Details how to convert the OPT or P6 port to a guest port, isolating it from LAN/DMZ ports for Internet access only.

4.6 Initial Setup Wizard Screen 10 - VPN

Guides through creating a VPN tunnel by selecting the VPN wizard type and launching the respective wizard.

4.6.1 VPN Setup Wizard: Wizard Type

Allows selection between Express and Advanced wizards for VPN rule creation, with Express using default settings and Advanced allowing custom changes.

4.6.2 VPN Express Wizard - Scenario

Guides the user to select the VPN scenario that best describes the intended VPN connection, illustrating options like Site-to-site.

4.6.3 VPN Express Wizard - Configuration

Details the configuration steps for VPN Express Wizard, including Secure Gateway, Pre-Shared Key, Local Policy, and Remote Policy.

4.6.6 VPN Advanced Wizard - Scenario

Guides the user to select the VPN scenario for the Advanced Wizard, similar to the Express Wizard.

4.6.7 VPN Advanced Wizard - Phase 1 Settings

Details Phase 1 settings for IKE negotiation, including Secure Gateway, Negotiation Mode, Encryption Algorithm, and Authentication Algorithm.

4.6.8 VPN Advanced Wizard - Phase 2

Explains Phase 2 settings for IKE, including Active Protocol, Encapsulation, Encryption Algorithm, and Authentication Algorithm.

4.7 VPN Settings for Configuration Provisioning Wizard: Wizard Type

Explains setting up a VPN rule that can be retrieved with the ZyWALL/USG IPSec VPN Client, including restrictions.

4.7.2 Configuration Provisioning VPN Express Wizard - Configuration

Details the configuration steps for the VPN Express Wizard, including Secure Gateway and Pre-Shared Key.

4.7.5 VPN Settings for Configuration Provisioning Advanced Wizard - Scenario

Guides the user to select the VPN scenario for the Advanced Wizard, similar to the Express Wizard.

4.7.6 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 1 Settings

Details Phase 1 settings for IKE negotiation, including Secure Gateway, Negotiation Mode, Encryption Algorithm, and Authentication Algorithm.

4.7.7 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 2

Explains Phase 2 settings for IKE, including Active Protocol, Encapsulation, Encryption Algorithm, and Authentication Algorithm.

4.8 VPN Settings for L2TP VPN Settings Wizard

Guides the user to set up an L2TP VPN rule, including selecting VPN settings and the L2TP VPN wizard.

4.8.1 L2TP VPN Settings 1

Details the first L2TP VPN settings screen, including Rule Name, My Address (interface), and Authentication Method.

4.8.2 L2TP VPN Settings 2

Explains the second L2TP VPN settings screen, including IP Address Pool, Starting IP Address, End IP Address, and DNS Servers.

4.9 Port Forwarding

Explains NAT port forwarding to direct incoming traffic from the Internet to the correct virtual server.

4.9.1 Port Forwarding > Add Client

Details how to add a new client to the port forwarding list by entering Name, IP Address, and MAC Address.

4.9.2 Port Forwarding > Add Service

Explains how to add a new service to the port forwarding list by entering Service Name and Port Range.

4.10 Wi-Fi and Guest Network Wizard

Guides through enabling Wi-Fi Network and Guest Wi-Fi Network, configuring name, password, and duration.

4.11 Security Service Wizard

Guides through registering the ZyWALL/USG and activating licenses for required services like Content Filtering, IDP, and Anti-Virus.

4.11.1 Security Service Wizard 2 - Content Filter Categories

Details how to configure Content Filter to block websites by category, such as Chat, Dating & Personals, Gambling, Games, Hacking, etc.

4.11.2 Security Service Wizard 3 - Websites

Explains how to create lists of trusted (allowed) and forbidden (blocked) web site addresses.

4.11.4 Security Service Wizard 5 - IDP/AV

Details how to configure Intrusion Detection and Prevention (IDP) and Anti-Virus (AV) features.

Chapter 5 Quick Setup Wizards

5.2 WAN Interface Quick Setup

Guides through configuring an interface to connect to the Internet, covering Ethernet, PPPoE, and PPTP.

5.2.2 Select WAN Type

Explains how to select the type of encapsulation for the connection: Ethernet, PPPoE, or PPTP.

5.2.4 ISP and WAN and ISP Connection Settings

Guides through configuring ISP and WAN interface settings, including static and dynamic IP assignments.

5.3 VPN Setup Wizard

Guides through creating Virtual Private Network (VPN) rules, including IPSec VPN, SSL VPN, and L2TP VPN.

5.3.2 VPN Setup Wizard: Wizard Type

Allows selection between Express and Advanced wizards for VPN rule creation.

5.3.3 VPN Express Wizard - Scenario

Guides the user to select the VPN scenario that best describes the intended VPN connection.

5.3.4 VPN Express Wizard - Configuration

Details the configuration steps for VPN Express Wizard, including Secure Gateway and Pre-Shared Key.

5.3.7 VPN Advanced Wizard - Scenario

Guides the user to select the VPN scenario for the Advanced Wizard.

5.3.8 VPN Advanced Wizard - Phase 1 Settings

Details Phase 1 settings for IKE negotiation, including Secure Gateway and Negotiation Mode.

5.3.9 VPN Advanced Wizard - Phase 2

Explains Phase 2 settings for IKE, including Active Protocol and Encapsulation.

5.4 VPN Settings for Configuration Provisioning Wizard: Wizard Type

Explains setting up a VPN rule that can be retrieved with the ZyWALL/USG IPSec VPN Client.

5.4.2 Configuration Provisioning VPN Express Wizard - Configuration

Details the configuration steps for the VPN Express Wizard, including Secure Gateway.

5.4.5 VPN Settings for Configuration Provisioning Advanced Wizard - Scenario

Guides the user to select the VPN scenario for the Advanced Wizard.

5.4.6 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 1 Settings

Details Phase 1 settings for IKE negotiation, including Secure Gateway and Negotiation Mode.

5.4.7 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 2

Explains Phase 2 settings for IKE, including Active Protocol and Encapsulation.

5.5 VPN Settings for L2TP VPN Settings Wizard

Guides the user to set up an L2TP VPN rule, including selecting VPN settings and the L2TP VPN wizard.

5.5.1 L2TP VPN Settings 1

Details the first L2TP VPN settings screen, including Rule Name and My Address (interface).

5.5.2 L2TP VPN Settings 2

Explains the second L2TP VPN settings screen, including IP Address Pool, Starting IP Address, and End IP Address.

5.6 VPN Settings for L2TP VPN Settings Wizard

Guides the user to set up an L2TP VPN rule, including selecting VPN settings and the L2TP VPN wizard.

Chapter 6 Dashboard

6.1.1 What You Can Do in this Chapter

Explains how to use the main Dashboard screen to view system information, status, resource usage, and interface status.

6.2.1 Device Information Screen

Displays ZyWALL/USG's system and model name, serial number, MAC address, and firmware version.

6.2.2 System Status Screen

Shows system uptime, current date/time, VPN status, DHCP table, login users, system resources, CPU usage, memory usage, and boot status.

6.2.3 VPN Status Screen

Provides information on currently established VPN tunnels and links to the Zyxel VPN Client product page.

6.2.6 System Resources Screen

Displays CPU Usage, Memory Usage, Flash Usage, USB Storage Usage, and Active Sessions.

6.2.12 Secured Service Status Screen

Shows Unified Threat Management (UTM) services that are available and enabled, including License Status and Type.

6.2.13 Content Filter Statistics Screen

Displays content filter statistics, including Total Web Pages Inspected, Blocked, Warned, and Passed.

Chapter 7 Monitor

7.1.1 What You Can Do in this Chapter

Explains how to use the Monitor screens for Port Statistics, Interface Status, Traffic Statistics, Session Monitor, IGMP Statistics, DDNS Status, IP/MAC Binding, Login Users, Dynamic Guest, Cellular Status, UPnP Port Status, USB Storage, and Ethernet Neighbor.

7.2 The Port Statistics Screen

Allows viewing packet statistics for each Gigabit Ethernet port.

7.3 Interface Status Screen

Lists all ZyWALL/USG interfaces and gives packet statistics for them.

7.4 The Traffic Statistics Screen

Provides basic information about traffic, such as most-visited websites, most-used protocols, and LAN IP with heaviest traffic.

7.5 The Session Monitor Screen

Displays all established sessions for debugging or statistical analysis, showing user, protocol, source/destination address, and duration.

7.8 IP/MAC Binding

Helps ensure that only intended devices use privileged IP addresses by binding IP to MAC addresses.

7.10 The Dynamic Guest Screen

Shows dynamic guest user accounts, which are created automatically and allowed to access services for a certain period.

7.15.1 Wireless AP Information: AP List

Shows the AP Information menu, containing AP List and Radio List screens.

7.15.3 Config AP

Allows configuring AP settings, including MAC address, model, radio settings, and description.

7.17 The IPSec Monitor Screen

Allows displaying and managing active IPSec SAs, including Name, Policy, IKE Name, Cookies, My Address, Secure Gateway, and Up Time.

7.18 The SSL Screen

Tracks users currently logged into the VPN SSL client and allows logging out users and deleting session information.

7.19 The L2TP over IPSec Session Monitor Screen

Displays and manages the ZyWALL/USG’s connected L2TP VPN sessions.

7.20 The App Patrol Screen

Manages the use of various applications on the network, including protocols and instant messenger.

7.21 The Content Filter Screen

Displays content filter statistics, including Total Web Pages Inspected, Blocked, Warned, and Passed.

7.22 The IDP Screen

Displays IDP (Intrusion Detection and Prevention) statistics.

7.23 The Anti-Virus Screen

Displays anti-virus statistics, including Total Viruses Detected and Infected Files Detected.

7.24 The Anti-Spam Screens

Manages anti-spam features, including Report and Status screens.

7.25 The SSL Inspection Screens

Decrypts SSL traffic, sends it to UTM engines for inspection, then encrypts and forwards it.

7.26 Log Screens

Stores log messages for viewing or e-mailing, and sets alerts for events requiring more attention.

7.26.1 View Log

Allows viewing all log messages or selecting specific categories, and viewing the Debug Log.

Chapter 8 Licensing

8.1 Registration Overview

Explains how to register your ZyWALL/USG and manage its service subscriptions.

8.1.2 Registration Screen

Guides the user to register their ZyWALL/USG at myZyXEL.com and activate services.

8.1.3 Service Screen

Displays the status of service registrations and licenses, and allows activation or extension of subscriptions.

8.2 Signature Update

Shows how to update the ZyWALL/USG’s signature packages for Anti-Virus, IDP, and AppPatrol.

8.2.2 The Anti-Virus Update Screen

Details how to update anti-virus signatures, including current version, released date, and update options.

8.2.3 The IDP/AppPatrol Update Screen

Guides on updating IDP and AppPatrol signatures, requiring an account at myZyXEL.com and IDP service subscription.

Chapter 9 Wireless

9.1.1 What You Can Do in this Chapter

Explains how to use Controller, AP Management, MON Mode, Auto Healing, and RTLS screens for wireless management.

9.3 AP Management Screens

Provides tools to manage all connected APs, including AP List, AP Policy, AP Group, and Firmware screens.

9.3.1 Mgnt. AP List

Displays the Managed AP List and Radio List screens.

9.3.2 AP Policy

Allows configuration of the AP controller’s IP address and actions managed APs take if the controller fails.

9.3.3 AP Group

Enables configuration of AP groups, defining radio, port, VLAN and load balancing settings for all APs in the group.

9.3.4 Firmware

Allows checking for and downloading new AP firmware when available on the firmware server.

9.4.1 Add/Edit Rogue/Friendly List

Explains how to add or edit rogue/friendly AP entries, including MAC address, description, and role.

9.6.3 Configuring RTLS

Guides on how to turn RTLS on or off and specify the IP address and server port of the Ekahau RTLS Controller.

9.7.2 Load Balancing

Discusses load balancing techniques for wireless bandwidth, such as station number and traffic level.

Chapter 10 Interfaces

10.1.1 What You Can Do in this Chapter

Details how to use Port Role, Ethernet, Virtual Interface, PPP, Cellular, Tunnel, VLAN, Bridge, Trunk, and LAG screens.

10.2 Port Role Screen

Allows setting the ZyWALL/USG’s flexible ports as part of LAN, WAN, or DMZ interfaces.

10.3.1 Ethernet Edit

Lets you configure IP address assignment, interface parameters, RIP, OSPF, DHCP, connectivity check, and MAC address settings.

10.4 PPP Interfaces

Explains how to use PPPoE/PPTP/L2TP interfaces to connect to your ISP.

10.4.2 PPP Interface Add or Edit

Allows configuration of a PPPoE or PPTP or L2TP interface, including ISP account setup.

10.5.2 Add / Edit Cellular Configuration

Allows configuration of mobile broadband settings, including APN, Dial String, and Authentication Type.

10.6 Tunnel Interfaces

Explains the use of tunnel interfaces in GRE, IPv6 in IPv4, and 6to4 tunnels.

10.6.2 Tunnel Add or Edit Screen

Allows configuration of a tunnel interface, including Name, Zone, Tunnel Mode, and IP Address Assignment.

10.8.2 Bridge Add/Edit

Allows configuration of IP address assignment, interface bandwidth parameters, DHCP settings, and connectivity check for each bridge interface.

10.9.2 LAG Add/Edit

Allows configuration of Interface and LAG parameters for each LAG interface.

10.10 VTI

Explains Virtual Tunnel Interface (VTI) which encrypts or decrypts IPv4 traffic from or to the interface.

10.10.3 VTI Add/Edit

Lets you configure IP address assignment and interface parameters for virtual interfaces.

10.11.1 What You Need to Know

Provides information on adding WAN interfaces to trunks and using policy routes for traffic management.

10.12.1 Configuring a User-Defined Trunk

Guides on creating or editing a WAN trunk entry.

Chapter 11 Routing

11.1.2 What You Need to Know

Covers Policy Routing concepts like Source-Based Routing, Bandwidth Shaping, Cost Savings, Load Sharing, and NAT.

11.2 Policy Route Screen

Allows viewing configured policy routes and turning policy routing based bandwidth management on or off.

11.2.1 Policy Route Edit Screen

Guides on configuring or editing a policy route, covering IPv4 and IPv6 settings.

11.3 IP Static Route Screen

Displays configured static routes and explains how to use RIP or OSPF to propagate routing information.

11.3.1 Static Route Add/Edit Screen

Allows creating or editing a static route, configuring required information like destination, subnet mask, and next-hop.

11.6 The RIP Screen

Guides on configuring ZyWALL/USG to use RIP for receiving and/or sending routing information.

11.7 The OSPF Screen

Details OSPF configuration, including general settings, areas, and virtual links.

11.7.2 OSPF Area Add/Edit Screen

Allows creating or editing OSPF areas, including Area ID, Type, and Authentication.

Chapter 12 DDNS

12.1.1 What You Can Do in this Chapter

Guides on using DDNS screens to view configured DDNS domain names and their details, and add/edit domain names.

12.2 The DDNS Screen

Provides a summary of all DDNS domain names and their configuration.

12.2.1 The Dynamic DNS Add/Edit Screen

Allows adding a domain name or editing an existing one.

Chapter 13 NAT

13.2 The NAT Screen

Provides a summary of all NAT rules and their configuration, allowing creation, editing, and deletion of rules.

13.2.1 The NAT Add/Edit Screen

Allows creating new NAT rules or editing existing ones.

Chapter 14 Redirect Service

14.1.1 HTTP Redirect

Describes how HTTP redirect forwards client HTTP requests to a web proxy server.

14.1.2 SMTP Redirect

Explains how SMTP redirect forwards authenticated client's SMTP messages to a SMTP server.

14.2 The Redirect Service Screen

Allows configuration of HTTP or SMTP request redirection.

14.2.1 The Redirect Service Edit Screen

Allows creating or editing a redirect rule for HTTP or SMTP requests.

Chapter 15 ALG

15.1.1 What You Need to Know

Discusses Application Layer Gateway (ALG), NAT, and Security Policy, and how ZyWALL/USG supports NAT mapping types.

15.2 The ALG Screen

Allows turning ALGs off or on, configuring port numbers, and configuring SIP ALG time outs.

Chapter 16 UPnP

16.1.1 What You Need to Know

Describes UPnP hardware identification and NAT Traversal capabilities.

16.3 UPnP Screen

Allows enabling UPnP and NAT-PMP on the ZyWALL/USG.

Chapter 17 IP/MAC Binding

17.1.1 What You Can Do in this Chapter

Guides on using Summary and Edit screens to bind IP addresses to MAC addresses, and Exempt List to configure IP ranges.

17.2.1 IP/MAC Binding Edit

Allows configuring an interface’s IP to MAC address binding settings.

17.3 IP/MAC Binding Exempt List

Allows configuring ranges of IP addresses to which IP/MAC binding is not applied.

Chapter 18 Layer 2 Isolation

18.1.1 What You Can Do in this Chapter

Guides on using General screen to enable layer-2 isolation and White List screen to enable and configure the white list.

18.2 Layer-2 Isolation General Screen

Allows enabling Layer-2 isolation on the ZyWALL/USG and specific internal interface(s).

18.3 White List Screen

Lists IP addresses not in the white list that are blocked from communicating with other devices, except for broadcast packets.

18.3.1 Add/Edit White List Rule

Allows creating a new rule in the white list or editing an existing one.

Chapter 19 DNS Inbound LB

19.2 The DNS Inbound LB Screen

Provides a summary of DNS load balancing rules and details, allowing adding, editing, or removing rules.

19.2.1 The DNS Inbound LB Add/Edit Member Screen

Allows adding a member interface for the DNS load balancing rule.

Chapter 20 Web Authentication

20.1.1 What You Can Do in this Chapter

Guides on using Web Authentication screens to create and manage policies, and configuring SSO communication.

20.2 Web Authentication General Screen

Displays general web portal settings and authentication policies, enabling web authentication.

20.2.1 User-aware Access Control Example

Shows how to configure policies and security settings for specific users or groups, authenticated locally or by an external server.

20.2.2 Authentication Type Screen

Allows viewing, creating, and managing authentication type profiles for user authentication.

20.4 SSO - ZyWALL/USG Configuration

Shows the steps required on the ZyWALL/USG to use SSO.

20.4.2 Configure the ZyWALL/USG to Communicate with SSO

Guides on configuring Web Authentication > SSO to set up communication with the SSO agent.

20.4.3 Enable Web Authentication

Explains how to enable Web Authentication and add a web authentication policy.

20.4.4 Create a Security Policy

Guides on configuring a Security Policy for SSO traffic to prevent blocking.

20.4.6 Configure an Authentication Method

Details how to configure Active Directory (AD) for authentication with SSO.

20.4.7 Configure Active Directory

Explains how to configure an Active Directory (AD) server in AAA Setup to match the AD configured on the SSO agent.

Chapter 21 Hotspot

21.2 Billing Overview

Guides on using General, Billing Profile, Discount, and Payment Service screens for billing settings.

21.3 The General Screen

Allows configuration of general billing settings, accounting method, currency unit, and SSID profiles.

21.4 The Billing Profile Screen

Defines billing profiles for web-based account generator and statement printer buttons.

21.4.1 The Account Generator Screen

Allows automatic creation of dynamic guest accounts.

21.4.3 The Billing Profile Add/Edit Screen

Allows creation or editing of billing profiles, defining Internet access time and charge per time unit.

Chapter 22 Printer Manager

Chapter 25 IPnP

Chapter 26 Walled Garden

26.3.1 Adding/Editing a Walled Garden URL

Allows creating or editing a walled garden web site URL entry.

26.4.1 Adding/Editing a Walled Garden Domain or IP

Allows creating or editing a walled garden domain or IP address entry.

Chapter 28 Security Policy

28.4.1 Configuring the Security Policy Control Screen

Guides on enabling/disabling Security Policy and asymmetrical routes, setting session limits, and displaying policies.

28.4.2 The Security Policy Control Add/Edit Screen

Allows creating or editing a Security Policy rule.

Chapter 29 IPSec VPN

29.5 ZyWALL/USG IPSec VPN Client Configuration Provisioning

Allows setting who can retrieve VPN rule settings using the ZyWALL/USG IPSec VPN Client.

Chapter 30 SSL VPN

30.2.1 The SSL Access Privilege Policy Add/Edit Screen

Allows creating or editing an SSL access policy.

Chapter 33 L2TP VPN

33.2 L2TP VPN Screen

Allows configuration of ZyWALL/USG’s L2TP VPN settings.

Chapter 34 BWM (Bandwidth Management)

34.2 The Bandwidth Management Screen

Controls bandwidth allocation for TCP and UDP traffic, allowing enabling/disabling and adding/editing policies.

34.2.1 The Bandwidth Management Add/Edit Screen

Allows creation or editing of bandwidth management conditions, including 802.1P Marking.

Chapter 35 Application Patrol

35.2.1 The Application Patrol Profile Add/Edit Screen

Guides on configuring profile settings, including Name, Description, and Profile Management.

Chapter 36 Content Filtering

36.2 Content Filter Profile Screen

Allows enabling content filtering, viewing/ordering policies, creating denial messages, and checking external web filtering service registration.

36.3 Content Filter Profile Add or Edit Screen

Guides on creating or editing a filter profile, configuring Category Service and Custom Service tabs.

Chapter 37 IDP

37.2 The IDP Profile Screen

Allows viewing registration and signature information, and binding IDP profiles to traffic.

37.2.2 Adding / Editing Profiles

Guides on creating new IDP profiles or editing existing ones.

37.2.4 Add Profile > Query View

Allows searching for signatures by criteria such as Name, ID, Severity, Policy Type, Platform, Service, Actions.

Chapter 38 Anti-Virus

38.2 Anti-Virus Profile Screen

Allows turning anti-virus on or off, setting policies, checking license status, and updating signatures.

38.2.1 Anti-Virus Profile Add or Edit

Guides on adding or editing an anti-virus profile.

38.3.1 Anti-Virus Black List or White List Add/Edit

Allows creating or editing black or white list entries for file patterns.

Chapter 39 Anti-Spam

39.3 The Anti-Spam Profile Screen

Allows turning anti-spam on or off and managing anti-spam policies.

39.3.1 The Anti-Spam Profile Add or Edit Screen

Guides on configuring anti-spam policies for traffic direction, protocols, scanning options, and actions.

39.5.1 The Anti-Spam Black or White List Add/Edit Screen

Allows creating or editing black or white list entries based on subject text, sender IP, or header fields.

Chapter 40 SSL Inspection

40.2 The SSL Inspection Profile Screen

Allows creating or editing SSL Inspection profiles.

40.2.1 Add / Edit SSL Inspection Profiles

Guides on creating or editing SSL Inspection profiles.

Chapter 41 Device HA

41.3 Device HA Pro

Explains the requirements and benefits of Device HA Pro, including easier deployment and faster failover.

41.4.1 Configuring Active-Passive Mode Device HA

Guides on configuring general active-passive mode Device HA settings, viewing monitored interfaces, and synchronizing backups.

Chapter 42 Object

42.3.2.2 Add/Edit SSID Profile

Guides on creating or editing an SSID profile.

42.6.2.1 IPv4 Address Add/Edit Screen

Allows creating or editing an IPv4 address object.

42.6.2.2 IPv6 Address Add/Edit Screen

Allows creating or editing an IPv6 address object.

42.7.2.1 The Service Add/Edit Screen

Allows creating a new service or editing an existing one.

42.8.2.1 The One-Time Schedule Add/Edit Screen

Allows defining or editing a one-time schedule.

42.9.5.1 Adding an Active Directory or LDAP Server

Guides on creating or editing an AD or LDAP server entry.

42.9.6.1 Adding a RADIUS Server

Guides on creating or editing a RADIUS server entry.

42.10.3 Authentication Method Objects

Allows creating and managing authentication method objects.

42.11.4.1 The Trusted Certificates Edit Screen

Allows viewing certificate information, changing name, and setting revocation checking.

42.13.2.1 Creating/Editing an SSL Application Object

Guides on creating web-based applications or file sharing applications.

42.14.1.1 DHCPv6 Request Add/Edit Screen

Allows creating or editing a DHCPv6 request object.

42.14.2.1 DHCPv6 Lease Add/Edit Screen

Allows creating or editing a DHCPv6 lease object.

Chapter 43 System

43.6.12 Security Option Control

Configures security options for DNS, including Query Recursion and Additional Info from Cache.

43.7.5 Service Control Rules

Allows adding or editing a service control rule for WWW, SSH, Telnet, FTP, or SNMP.

43.12.1 Add/Edit Trusted RADIUS Client

Allows creating or editing a trusted RADIUS client.

Chapter 44 Log and Report

44.2 Email Daily Report

Allows starting or stopping data collection and viewing traffic statistics.

44.3 Log Setting Screens

Controls log messages and alerts, supporting viewing, regular e-mailing, and storing on USB.

Chapter 45 File Manager

45.2 The Configuration File Screen

Allows storing, running, and naming configuration files, and downloading/uploading them.

Chapter 46 Diagnostics

46.2 The Diagnostic Screen

Allows generating a file with configuration and diagnostic information for customer support.

46.3 The Packet Capture Screen

Allows capturing network traffic for identifying network problems.

Chapter 47 Packet Flow Explore

Chapter 49 Troubleshooting

49.1 Resetting the ZyWALL/USG

Explains how to reset the ZyWALL/USG to factory default settings.

Appendix B Legal Information

Safety Warnings

Provides important safety warnings for product usage.

ZyXEL Limited Warranty

Details the product warranty terms and conditions.

Related product manuals