EasyManua.ls Logo

ZyXEL Communications ZYWALL 5 User Manual

ZyXEL Communications ZYWALL 5
668 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
ZyWALL 5
Internet Security Appliance
Users Guide
Version 3.64
3/2005

Table of Contents

Other manuals for ZyXEL Communications ZYWALL 5

Questions and Answers:

ZyXEL Communications ZYWALL 5 Specifications

General IconGeneral
BrandZyXEL Communications
ModelZYWALL 5
CategoryFirewall
LanguageEnglish

Summary

Safety Warnings

Chapter 1 Getting to Know Your ZyWALL

1.1 ZyWALL 5 Internet Security Appliance Overview

Overview of the ZyWALL 5's features and applications, including VPN, firewall, and content filtering.

CHAPTER 2 Introducing the Web Configurator

2.2 Accessing the ZyWALL Web Configurator

Step-by-step guide on how to connect to the ZyWALL's web interface.

2.3 Resetting the ZyWALL

Procedure for restoring factory default configuration or using the reset button.

CHAPTER 3 Wizard Setup

3.2 Internet Access

Configuration of Internet access based on encapsulation type (Ethernet, PPTP, PPPoE).

3.3 VPN Wizard

Screens for configuring VPN rules using pre-shared keys and IKE settings.

Chapter 4 LAN Screens

4.2 DHCP Setup

Configuration of the ZyWALL as a DHCP server or disabling the service.

4.3 LAN TCP/IP

Configuration of LAN parameters including IP address, subnet mask, and RIP.

Chapter 5 Bridge Screens

5.3 Configuring Bridge

Setting the ZyWALL to function as a bridge.

Chapter 6 Wireless LAN

6.2 Wireless Security

Importance of wireless security for protecting communication between stations and access points.

6.5 802.1x Overview

Enhanced security methods for authentication and encryption key management.

6.7 Introduction to WPA

Overview of Wi-Fi Protected Access (WPA) for improved security and data encryption.

6.11 Configuring Wireless LAN

Steps to configure wireless LAN settings like ESSID and WEP.

6.12 Configuring MAC Filter

Configuring the ZyWALL to grant or deny access based on MAC addresses.

CHAPTER 7 WAN Screens

7.4 Configuring WAN Setup

Configuring WAN ISP, IP, and MAC settings.

7.7 Configuring Dial Backup

Configuring Dial Backup settings for an alternate WAN connection.

CHAPTER 8 DMZ Screens

8.2 Configuring DMZ

Configuring DMZ port and associated computers with private or public IP addresses.

CHAPTER 9 Firewalls

9.2 Types of Firewalls

Description of Packet Filtering, Application-level, and Stateful Inspection firewalls.

9.3 Introduction to ZyXEL’s Firewall

Introduction to the ZyWALL's stateful inspection firewall capabilities.

9.4 Denial of Service

Information on Denials of Service (DoS) attacks and ZyWALL's detection methods.

9.5 Stateful Inspection

How stateful inspection works and how the ZyWALL implements it.

Chapter 10 Firewall Screens

10.3 Rule Logic Overview

Study points for configuring firewall rules effectively.

10.6 Configuring Firewall

Steps to enable and configure the firewall.

10.10 DoS Thresholds

Setting thresholds to detect and mitigate Denial of Service (DoS) attacks.

Chapter 11 Content Filtering Screens

11.2 General Content Filter Configuration

Enabling content filtering, configuring schedules, and creating denial messages.

Chapter 12 Content Filtering Registration and Reports

12.3 Registering Your ZyXEL Device

Procedure to log in and register your ZyXEL device.

12.4 Content Filtering Registration

Registering for content filtering service via web configurator.

CHAPTER 13 Introduction to IPSec

13.1 VPN Overview

Secure communication between sites using tunneling, encryption, and authentication.

Chapter 14 VPN Screens

14.2 IPSec Algorithms

Explanation of ESP and AH protocols and their role in IPSec VPNs.

14.4 Remote Gateway Address

Specifying the WAN IP address or domain name of the remote IPSec router.

14.6 NAT Traversal

Setting up a VPN connection when NAT routers are between IPSec routers.

14.8 IKE Phases

Explanation of the two phases of IKE negotiation: Authentication and Key Exchange.

14.12 IKE VPN Rule Summary Screen

Displaying and managing IPSec rules (tunnels) and gateway policies.

CHAPTER 15 Certificates

15.4 My Certificates

Viewing summary list of certificates and certification requests.

15.6 Importing a Certificate

Instructions for saving an existing certificate to the ZyWALL.

15.7 Creating a Certificate

Generating a self-signed certificate, enrolling with CA, or creating a request.

15.10 Importing a Trusted CA’s Certificate

Saving a trusted certification authority’s certificate to the ZyWALL.

15.14 Importing a Trusted Remote Host’s Certificate

Saving a trusted host's certificate to the ZyWALL.

CHAPTER 16 Authentication Server

16.1 Authentication Server Overview

Using local user database or external RADIUS server for VPN authentication.

16.4 Configuring Local User Database

Changing ZyWALL's local user list.

16.5 Configuring RADIUS

Setting up ZyWALL's RADIUS server settings.

CHAPTER 17 Network Address Translation (NAT)

17.1 NAT Overview

Understanding NAT, its definitions, and how it works.

17.2 Using NAT

Applying NAT and understanding SUA versus Full Feature NAT.

17.4 Configuring Address Mapping

Creating and ordering address mapping rules for NAT.

17.5 Port Forwarding

Setting up port forwarding for servers behind NAT.

17.7 Configuring Trigger Port

Configuring trigger port rules for WAN port traffic.

CHAPTER 18 Static Route

18.2 Configuring IP Static Route

Configuring IP static routes in the IP Static Route screen.

CHAPTER 19 Bandwidth Management

19.1 Bandwidth Management Overview

Allocating outgoing capacity to specific traffic types for minimum delay.

19.2 Bandwidth Classes and Filters

Using classes and sub-classes to allocate bandwidth capacity and budgets.

19.8 Maximize Bandwidth Usage

Dividing available bandwidth among classes that require more bandwidth.

19.11 Configuring Class Setup

Setting up bandwidth classes by individual interface.

CHAPTER 20 DNS

20.2 DNS Server Address Assignment

Methods for obtaining DNS server addresses from ISP or manual entry.

20.6 The System Screen

Configuring ZyWALL's DNS address and name server records.

20.10 Dynamic DNS

Updating dynamic IP address with dynamic DNS services for domain name access.

20.11 Configuring Dynamic DNS

Changing ZyWALL's DDNS settings via the DDNS tab.

CHAPTER 21 Remote Management

21.1 Remote Management Overview

Determining which services/protocols can access ZyWALL interfaces from remote computers.

21.4 HTTPS Example

Procedure for accessing ZyWALL via HTTPS, including browser warnings.

21.8 Configuring SSH

Changing ZyWALL's Secure Shell settings.

21.13 Configuring FTP

Uploading and downloading firmware and configuration files using FTP.

21.15 Configuring DNS

Configuring DNS settings for mapping domain names to IP addresses.

CHAPTER 22 UPnP

22.3 Configuring UPnP

Steps to display and configure UPnP settings.

22.6 Using UPnP in Windows XP Example

How to use the UPnP feature in Windows XP.

CHAPTER 23 Logs Screens

23.1 Configuring View Log

Viewing all ZyWALL logs in one location.

23.3 Configuring Log Settings

Configuring log settings for sending logs and alerts via e-mail or syslog.

CHAPTER 24 Maintenance

24.3 Configuring Password

Changing the ZyWALL's password for enhanced security.

24.5 Configuring Time and Date

Configuring ZyWALL's time and date based on local time zone.

24.9 F/W Upload Screen

Procedure for uploading firmware and configuration files via FTP/TFTP.

24.10 Configuration Screen

Information related to factory defaults, backup, and restoring configuration.

CHAPTER 25 Introducing the SMT

25.2 Accessing the SMT via the Console Port

Steps to access SMT menus via console port with communication software.

25.4 Changing the System Password

Procedure for changing the system password.

CHAPTER 26 SMT Menu 1 - General Setup

26.2 Configuring General Setup

Filling in required fields for System Name, Domain Name, and Device Mode.

CHAPTER 27 WAN and Dial Backup Setup

27.3 Dial Backup

Using the Dial Backup port as a reserve connection when WAN fails.

CHAPTER 28 LAN Setup

28.4 TCP/IP and DHCP Ethernet Setup Menu

Configuring TCP/IP and DHCP Ethernet setup.

28.5 Wireless LAN Setup

Setting up ZyWALL as a wireless access point.

CHAPTER 29 Internet Access

29.1 Introduction to Internet Access Setup

Setting up ZyWALL to access the Internet using ISP information.

29.3 Configuring the PPTP Client

Configuring PPTP client with My Login, Password, and PPTP parameters.

CHAPTER 30 DMZ Setup

30.3 TCP/IP Setup

Configuring TCP/IP settings for DMZ, including IP address and RIP.

CHAPTER 34 Introducing the ZyWALL Firewall

CHAPTER 35 Filter Configuration

35.2 Configuring a Filter Set

Grouping related rules into a single set with a descriptive name.

35.6 Applying a Filter

Applying designed filters to ports for traffic control.

CHAPTER 36 SNMP Configuration

36.1 SNMP Configuration

Configuring SNMP settings for network management.

CHAPTER 37 System Information & Diagnosis

37.4 Log and Trace

Information on error logs and trace records stored locally.

37.5 Diagnostic

Diagnostic tests to evaluate system performance.

CHAPTER 38 Firmware and Configuration File Maintenance

38.3 Backup Configuration

Backing up the current ZyWALL configuration to a computer.

38.4 Restore Configuration

Uploading a new or previously saved configuration file.

38.5 Uploading Firmware and Configuration Files

Procedures for uploading firmware and configuration files via FTP/TFTP.

CHAPTER 39 System Maintenance Menus 8 to 10

39.3 Time and Date Setting

Updating ZyWALL's time and date settings based on local time zone.

CHAPTER 40 Remote Management

40.1 Remote Management

Determining services/protocols and interfaces for remote access.

40.8 Configuring SSH

Changing ZyWALL's Secure Shell settings.

40.15 Configuring DNS

Configuring DNS settings for mapping domain names to IP addresses.

CHAPTER 41 Call Scheduling

CHAPTER 42 Troubleshooting

42.1 Problems Starting Up the ZyWALL

Troubleshooting steps for issues when starting up the ZyWALL.

42.2 Problems with the LAN Interface

Troubleshooting steps for issues with LAN connectivity.

42.5 Problems with Internet Access

Steps to resolve issues with accessing the Internet.

42.7 Problems Accessing the ZyWALL

Resolving issues with accessing the ZyWALL via web browser.

APPENDIX C IP Subnetting

Subnetting

Ignoring class arrangement of IP address for subnetting.

APPENDIX D PPPoE

ZyWALL as a PPPoE Client

How ZyWALL as PPPoE client alleviates administrator management of PPPoE clients.

APPENDIX E PPTP

APPENDIX H SIP Passthrough

SIP ALG

SIP Application Layer Gateway (ALG) for VoIP calls passing through NAT.

APPENDIX I VPN Setup

Full Feature NAT Mode

Mapping VPN rule's local policy addresses to a public IP address.

VPN Configuration

Example of VPN rule configuration using the web configurator.

VPN Troubleshooting

Troubleshooting common IPSec tunnel build problems.

APPENDIX L Firewall Commands

Firewall Set-Up

Commands to turn the firewall on or off, retrieve, or save settings.

APPENDIX M NetBIOS Filter Commands

NetBIOS Filter Configuration

Configuring NetBIOS filters for various traffic directions and connections.

APPENDIX N Certificates Commands

my_cert

Commands for creating self-signed, request, or SCEP enrolled certificates.

remote_trusted

Commands to import, export, view, verify, delete, list, and rename trusted remote host certificates.

APPENDIX O Brute-Force Password Guessing Protection

Brute-force password guessing protection commands

Commands for enabling, disabling, and configuring password protection.

APPENDIX Q Log Descriptions

System Error Logs

Descriptions of system error log messages.

Content Filtering Logs

Descriptions of log messages related to content filtering.

Attack Logs

Descriptions of log messages related to detected attacks.

IPSec Logs

Descriptions of log messages related to IPSec tunnel status.

Log Commands

Commands for loading, viewing, and clearing logs.

Related product manuals