Netopia 3300 Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Hardware Netopia 3300 herunter. Netopia 3300 User Manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 334
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1

NNNNeeeettttooooppppiiiiaaaa ®®®® FFFFiiiirrrrmmmmwwwwaaaarrrreeee UUUUsssseeeerrrr GGGGuuuuiiiiddddeeee 3333333300000000----EEEENNNNTT

Seite 2 - Part Number

x Firmware User Guide

Seite 3

4-4 Firmware User GuideExterior addresses are allocated to internal hosts on a demand, or as-needed, basis and then made available when traffic from t

Seite 4

Multiple Network Address Translation 4-5Complex mapsMap lists and server lists are completely independent of each other. A Connection Profile can use

Seite 5

4-6 Firmware User GuideSupport for Yahoo MessengerNetopia Firmware Version 8.7 provides Application Level Gateway (ALG) support for Yahoo Messenger.

Seite 6

Multiple Network Address Translation 4-7The two map lists, Easy-PAT List and Easy-Servers, are created by default and NAT configuration becomes effec

Seite 7

4-8 Firmware User GuideSelect Network Address Translation (NAT) and press Return.The Network Address Translation screen appears.Public Range defines a

Seite 8

Multiple Network Address Translation 4-9NAT rulesThe following rules apply to assigning NAT ranges and server lists:• Static public address ranges m

Seite 9

4-10 Firmware User GuideSelect First Public Address and enter the first exterior IP address in the range you want to assign. Select Last Public Addres

Seite 10 - Firmware User Guide

Multiple Network Address Translation 4-11• Select First and Last Private Address and enter the first and last interior IP addresses you want to assig

Seite 11 - Introduction

4-12 Firmware User Guide• The Add NAT Map screen now displays the range you have assigned.• Select ADD NAT MAP and press Return. Your mapping is adde

Seite 12 - Netopia Telnet Menus

Multiple Network Address Translation 4-13The Show/Change NAT Map List screen appears.• Add Map allows you to add a new map to the map list.• Show/Ch

Seite 13 - Netopia Models

Introduction 1-1 Chapter 1 Introduction This Firmware User Guide covers the advanced features of the Netopia ENT Enterprise-Series Router family.

Seite 14 - Configuring Telnet software

4-14 Firmware User GuideThe Change NAT Map screen appears.Make any modifications you need and then select CHANGE NAT MAP and press Return. Your change

Seite 15

Multiple Network Address Translation 4-15Adding Server ListsServer lists, also known as Exports, are handled similarly to map lists. If you want to

Seite 16 - 1-6 Firmware User Guide

4-16 Firmware User Guide• Select External Service and press Return. A pop-up menu appears listing a selection of commonly exported services.• Choose

Seite 17 - WAN Configuration

Multiple Network Address Translation 4-17• Enter the First and Last Port Number between ports 1 and 65535. Select OK and press Return. You will be r

Seite 18

4-18 Firmware User Guide• Choose the protocol from the pop-up menu: TCP and UDP, TCP only, or UDP only.• Enter the Internal Port Start, if different

Seite 19

Multiple Network Address Translation 4-19The Show/Change NAT Ser ver List screen appears.• Selecting Show/Change Server or Delete Server displays th

Seite 20 - ADSL Line Configuration screen

4-20 Firmware User GuideSelect any server from the list and press Return. The Change NAT Server screen appears.You can make changes to the server’s s

Seite 21 - ATM Circuit Configuration

Multiple Network Address Translation 4-21A pop-up menu lists your configured servers. Select the one you want to delete and press Return. A dialog bo

Seite 22

4-22 Firmware User GuideBinding Map Lists and Server ListsOnce you have created your map lists and server lists, for most Netopia Router models you m

Seite 23

Multiple Network Address Translation 4-23• Select the map list you want to bind to this Connection Profile and press Return. The map list you selecte

Seite 24

1-2 Firmware User Guide Telnet-based Management Telnet-based management is a fast menu-driven interface for the capabilities built into the Netopia

Seite 25

4-24 Firmware User GuideIP Parameters (WAN Default Profile)The Netopia Firmware Version 8.7 using RFC 1483 supports a WAN default profile that permits

Seite 26

Multiple Network Address Translation 4-25• Select the map list you want to bind to the default profile and press Return. The map list you selected wi

Seite 27

4-26 Firmware User GuideNAT AssociationsConfiguration of map and server lists alone is not sufficient to enable NAT for a WAN connection because map an

Seite 28

Multiple Network Address Translation 4-27• Select the list name you want to assign and press Return again. Your selection will then be associated wi

Seite 29 - PPPoE/PPPoA Autodetection

4-28 Firmware User GuideIP PassthroughNetopia Firmware Version 8.7 offers an IP passthrough feature. The IP passthrough feature allows for a single P

Seite 30

Multiple Network Address Translation 4-29The IP Profile Parameters screen, found under the WAN Configuration menu, Add/Change Connection Profile screen

Seite 31 - Advanced Connection Options

4-30 Firmware User GuideToggling IP Passthrough DHCP Enabled to Ye s displays the IP Passthrough DHCP MAC address field. This is an editable field in w

Seite 32 - Scheduled Connections

Multiple Network Address Translation 4-31A restrictionSince both the router and the passthrough host will use same IP address, new sessions that con

Seite 33 - Viewing scheduled connections

4-32 Firmware User GuideMultiNAT Configuration ExampleTo help you understand a typical MultiNAT configuration, this section describes an example of the

Seite 34 - Adding a scheduled connection

Multiple Network Address Translation 4-33Enter your ISP-supplied values as shown below.Select NEXT SCREEN and press Return.Your IP values are shown

Seite 35 - Set Weekly Schedule

Introduction 1-3 • The WAN Configuration menu displays and permits changing your connection profile(s), Virtual Private Networks (VPNs) and default

Seite 36 - Set Once-Only Schedule

4-34 Firmware User GuideSelect Show/Change Public Range, then Easy-PAT Range, and press Return. Enter the value your ISP assigned for your public add

Seite 37 - Backup Configuration

Multiple Network Address Translation 4-35Select ADD NAT PUBLIC RANGE and press Return. You are returned to the Network Address Translation screen.Ne

Seite 38 - Diffserv Options

4-36 Firmware User Guide• First, navigate to the Show/Change Map List screen, select Easy-PAT List and then Show/Change Maps. Choose the Static Map y

Seite 39

Virtual Private Networks (VPNs) 5-1Chapter 5Virtual Private Networks (VPNs)The Netopia Firmware Version 8.7 offers IPsec, PPTP, and ATMP tunneling s

Seite 40

5-2 Firmware User GuideNetopia Firmware Version 8.7 can be used in VPNs either to initiate the connection or to answer it. When used in this way, the

Seite 41 - Priority Queuing (TOS bit)

Virtual Private Networks (VPNs) 5-3leaves the header untouched. The more secure Tunnel mode encrypts both the header and the payload. On the receivi

Seite 42

5-4 Firmware User GuideAbout PPTP TunnelsTo set up a PPTP tunnel, you create a Connection Profile including the IP address and other relevant informat

Seite 43

Virtual Private Networks (VPNs) 5-5When you define a Connection Profile as using PPTP by selecting PPTP as the datalink encapsulation method, and then

Seite 44 - 2-28 Firmware User Guide

5-6 Firmware User GuideNote: Netopia Firmware Version 8.7 supports 128-bit (“strong”) encryption. Unlike MS-CHAP version 1, which supports one-way au

Seite 45

Virtual Private Networks (VPNs) 5-7The IP Profile Parameters screen appears.• Enter the Remote IP Address and Remote IP Mask for the host to which yo

Seite 46 - Filter Sets

1-4 Firmware User Guide Connecting through a Telnet Session Features of Netopia Firmware Version 8.7 can be configured through the Telnet screens.Bef

Seite 47 - Stateful Inspection

5-8 Firmware User GuideAbout L2TP TunnelsL2TP stands for Layer 2 Tunnelling Protocol, an extension to the PPP protocol. L2TP combines features of two

Seite 48 - Add Exposed Address List

Virtual Private Networks (VPNs) 5-9When you define a Connection Profile as using L2TP by selecting L2TP as the datalink encapsulation method, and then

Seite 49 - System Configuration 3-5

5-10 Firmware User Guide• You can specify that this Router will Initiate Connections (acting as a PAC) or only answer them (acting as a PNS).• Tunnel

Seite 50

Virtual Private Networks (VPNs) 5-11About GRE TunnelsGeneric Routing Encapsulation (GRE) protocol is another form of tunneling that Netopia routers

Seite 51

5-12 Firmware User Guide• Enter a GRE Partner IP Address in standard dotted-quad format to specify the address of the other end of the tunnel.• You c

Seite 52 - Exposed Address Associations

Virtual Private Networks (VPNs) 5-13The IP Profile Parameters screen appears.• Enter the Remote IP Address and Remote IP Mask for the host to which y

Seite 53

5-14 Firmware User GuideVPN force-allGRE tunnelling supports “VPN force-all,” which forces all traffic coming from the LAN onto the GRE tunnel. You ac

Seite 54

Virtual Private Networks (VPNs) 5-15About ATMP TunnelsTo set up an ATMP tunnel, you create a Connection Profile including the IP address and other re

Seite 55 - VLAN Configuration

5-16 Firmware User GuideWhen you define a Connection Profile as using ATMP by selecting ATMP as the datalink encapsulation method, and then select Data

Seite 56

Virtual Private Networks (VPNs) 5-17• You can specify that this Router will Initiate Connections, acting as a foreign agent (Ye s), or only answer t

Seite 57 - Adding a RADIUS Profile

Introduction 1-5Navigating through the Telnet ScreensUse your keyboard to navigate the Netopia Firmware Version 8.7’s configuration screens, enter an

Seite 58

5-18 Firmware User GuideMS-CHAP V2 and 128-bit strong encryptionNotes:• Netopia Firmware Version 8.7 supports 128-bit (“strong”) encryption when usin

Seite 59

Virtual Private Networks (VPNs) 5-19• Toggle Answer ATMP/PPTP Connections to Ye s if you want the Router to accept VPN connections or No (the defau

Seite 60 - Adding Port interfaces

5-20 Firmware User GuideVPN QuickViewYou can view the status of your VPN connections in the VPN QuickView screen.From the Main Menu select QuickView

Seite 61

Virtual Private Networks (VPNs) 5-21Dial-Up Networking for VPNMicrosoft Windows Dial-Up Networking software permits a remote standalone workstation

Seite 62 - Changing or Deleting a VLAN

5-22 Firmware User GuideThe Communications window appears.5. In the Communications window, select Dial-Up Networking and click the OK button.This ret

Seite 63 - System Configuration 3-19

Virtual Private Networks (VPNs) 5-23Configuring a Dial-Up Networking profileOnce you have created your Dial-Up Networking profile, you configure it for

Seite 64 - 3-20 Firmware User Guide

5-24 Firmware User Guide4. Click the TCP/IP Settings button. • If your ISP uses dynamic IP addressing (DHCP), select the Server assigned IP address r

Seite 65 - System Configuration 3-21

Virtual Private Networks (VPNs) 5-25Connecting using Dial-Up NetworkingA Dial-Up Networking connection will be automatically launched whenever you r

Seite 66 - Date and time

5-26 Firmware User GuideSelect Display/Change Input Filter.Display/Change Input Filter screenSelect Input Filter 1 and press Return. In the Change In

Seite 67 - Wireless configuration

Virtual Private Networks (VPNs) 5-27In the Display/Change Filter Set screen select Display/Change Output Filter. Display/Change Output Filter screen

Seite 68

1-6 Firmware User Guide

Seite 69 - Wireless Multimedia (WMM)

5-28 Firmware User GuideSelect Output Filter 2 and press Return. In the Change Output Filter 2 screen, set the Protocol Type to allow GRE as shown be

Seite 70 - Enable Privacy

Virtual Private Networks (VPNs) 5-29Select Display/Change Input Filter.Display/Change Input Filter screenSelect Input Filter 1 and press Return. In

Seite 71

5-30 Firmware User GuideIn the Display/Change IP Filter Set screen select Display/Change Output Filter. Display/Change Output Filter screen

Seite 72

Virtual Private Networks (VPNs) 5-31Select Output Filter 1 and press Return. In the Change Output Filter 1 screen, set the Protocol Type and Destina

Seite 73

5-32 Firmware User GuideWindows Networking BroadcastsNetopia firmware provides the ability to forward Windows Networking NetBIOS broadcasts. This is u

Seite 74 - Multiple SSIDs

Virtual Private Networks (VPNs) 5-33Configuration for Router AConfiguration for Router B IP Profile Parameters Rem

Seite 75 - System Configuration 3-31

5-34 Firmware User GuideNote: Microsoft Network browsing is available with or without a Windows Internet Name Service (WINS) server. Shared volumes o

Seite 76

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-1Chapter 6Internet Key Exchange (IKE) IPsec Key Management for VPNsIPsec stands for IP S

Seite 77 - MAC Address Authentication

6-2 Firmware User GuideThe advantage of using IKE is that it automatically negotiates IPsec Security Associations and enables IPsec secure communicat

Seite 78

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-3The Add Connection Profile screen appears.• From the Encapsulation Type pop-up menu sele

Seite 79 - Console Configuration

WAN Configuration 2-1Chapter 2WAN ConfigurationThis chapter describes how to use the Telnet-based management screens to access and configure advanced f

Seite 80 - Upgrade Feature Set

6-4 Firmware User Guide• A pop-up window displays a list of IKE Phase 1 Profiles that you have configured. If you have not previously configured an IKE

Seite 81 - Router/Bridge Set

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-5• The Profile Name field accepts any name of up to 16 characters. Sixteen IKE Phase 1 pro

Seite 82

6-6 Firmware User Guide• If you select Xauth Options the Xauth Options screen appears.Extended Authentication (Xauth), is an extension to the IKE pro

Seite 83

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-7• VPN concentrator – This configures Xauth to expect to receive authentication credentia

Seite 84

6-8 Firmware User GuideNormally it is not necessary to change the settings of the items on the Advanced IKE Phase 1 Options screen. Most of these set

Seite 85

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-9• Traffic based Dead Peer DetectionThe default is No. Toggling this option to Yes allow

Seite 86

6-10 Firmware User GuideSelecting Display/Change IKE Phase 1 Profile or Delete IKE Phase 1 Profile displays an IKE Phase 1 Profile pop-up menu listing t

Seite 87 - Log event dispositions

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-11Key ManagementYou specify your IKE key management on a per-Connection Profile basis. Yo

Seite 88

6-12 Firmware User GuideNote: The Change Connection Profile screen will offer different options, depending on the model of gateway you are using. You

Seite 89

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-13The Key Management pop-up menu at the top of the IPsec Tunnel Options screen allows yo

Seite 90

2-2 Firmware User GuideWAN Ethernet Configuration screenThe WAN Ethernet Configuration screen appears as follows:• Address Translation Enabled allows y

Seite 91

6-14 Firmware User Guide• The ESP Authentication Transform pop-up menu (which is visible only if you have selected ESP or AH+ESP encapsulation) allow

Seite 92 - Install via the Console menu

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-15• Dead Peer Detection toggles whether or not the Router will detect a remote peer bein

Seite 93

6-16 Firmware User GuideNote:• ICMP Dead Peer Detection is not available when using manual re-keying.• ICMP Dead Peer Detection does not initiate a s

Seite 94 - Set up Syslog

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-17This feature allows you to define many local and remote network ranges for a given IPse

Seite 95

6-18 Firmware User Guide• If you choose Subnet, you must enter the Remote Member Address and the subnet mask that is the Remote Member Mask.Enter the

Seite 96 - 3-52 Firmware User Guide

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-19• Scroll down and up with the arrow keys to select the one you want to change, and pre

Seite 97 - Chapter 4

6-20 Firmware User Guide• Specifying IKE key management alters the Advanced IP Profile Options screen as follows:• You can specify a Local Tunnel Endp

Seite 98 - Features

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-21IPsec WAN Configuration ScreensYou can also configure IKE Phase 1 Profiles in the WAN Con

Seite 99 - Dynamic mapping

6-22 Firmware User GuideThe IKE Phase 1 Configuration screen allows configuration of global (non-connection-profile-specific) IPsec parameters. This scre

Seite 100 - LAN Network

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-23Select IPsec Manual Keys and press Return.Depending on your selections of Encapsulatio

Seite 101 - Supported traffic

WAN Configuration 2-3• The WAN Ethernet Speed Setting is configurable via a pop-up menu. Options are: • Auto-Negotiation (the default)• 100 Mbps Full

Seite 102 - MultiNAT Configuration

6-24 Firmware User GuideIf the remote tunnel end point is a hostname (or “0.0.0.0”) 0.0.0.0 is displayed until a Security Association is established.

Seite 103 - System Configuration

Internet Key Exchange (IKE) IPsec Key Management for VPNs 6-25IKE: no matching ph2 proposal Either the local Router rejected the proposals of the re

Seite 104

6-26 Firmware User Guide

Seite 105 - NAT rules

IP Setup 7-1Chapter 7IP SetupNetopia Firmware Version 8.7 uses Internet Protocol (IP) to communicate both locally and with remote networks. This cha

Seite 106 - Add Map

7-2 Firmware User GuideIP SetupThe IP Setup options screen is where you configure the Ethernet side of the Router. The information you enter here cont

Seite 107

IP Setup 7-3The Netopia Firmware Version 8.7 supports multiple IP subnets on the Ethernet interface. You may want to configure multiple IP subnets to

Seite 108 - Modifying map lists

7-4 Firmware User Guide• If you select IP Address Serving you will be taken to the IP Address Serving screen (see “IP Address Serving” on page 7-17).

Seite 109

IP Setup 7-5For example:• To delete a configured subnet, set both the IP address and subnet mask values to 0.0.0.0, either explicitly or by clearing

Seite 110 - 4-14 Firmware User Guide

7-6 Firmware User GuideIf you have configured multiple Ethernet IP subnets, the IP Setup screen changes slightly:The IP address and Subnet mask items

Seite 111 - Adding Server Lists

IP Setup 7-7The Static Routes screen will appear.Viewing static routesTo display a view-only table of static routes, select Display/Change Static Ro

Seite 112

Copyright Copyright© 2006, Netopia, Inc. Netopia, the Netopia logo, Broadband Without Boundaries, and 3-D Reach are registered trademarks belonging t

Seite 113

2-4 Firmware User GuideThe Transmit RIP pop-up menu is hidden if NAT is enabled.Routing Information Protocol (RIP) is needed if there are IP routers

Seite 114 - Modifying server lists

7-8 Firmware User GuideSubnet Mask: The subnet mask associated with the destination network.Next Gateway: The IP address of the gateway that will be

Seite 115

IP Setup 7-9• To make sure that the static route is known only to the Router, select Advertise Route Via RIP and toggle it to No. To allow other RIP

Seite 116 - Deleting a server

7-10 Firmware User GuideRIP OptionsNetopia Firmware Version 8.7 supports RIP-2 MD5 Authentication (RFC2082 Routing Internet Protocol Version 2, Messa

Seite 117

IP Setup 7-11• Select RIP Options. The Ethernet LAN RIP Options screen appears.• Select Receive RIP, and from the pop-up menu choose v2 MD5 Authenti

Seite 118 - IP profile parameters

7-12 Firmware User Guide• You can also select Transmit RIP, and choose v2 MD5 (broadcast) or v2 MD5 (multicast) from the pop-up menu.• RIP v2 Authent

Seite 119

IP Setup 7-13Note:• All of the changes on this menu require a reboot. This is unique to the Ethernet LAN. RIP changes on all other interfaces are im

Seite 120 - IP Parameters

7-14 Firmware User Guide• The key identifier Key ID can be any numeric value from 0 – 255, and must be unique per interface. You can not have two keys

Seite 121

IP Setup 7-15Note: The date and time formats are determined by the system date and time formats. If the current date and time fall within the range

Seite 122 - NAT Associations

7-16 Firmware User GuideConnection Profiles and Default ProfileRIP-2 MD5 authentication may be configured in Connection Profiles, as well. If you are not

Seite 123

IP Setup 7-17• If either Receive RIP or Transmit RIP is set to v2 MD5 Authentication, RIP v2 Authentication Keys is visible. Selecting RIP v2 Authen

Seite 124 - IP Passthrough

WAN Configuration 2-5Usually, the default AutoSense will detect the type and adjust itself accordingly. If you want to set it yourself, and you know

Seite 125

7-18 Firmware User GuideGo to the System Configuration screen. Select IP Address Serving and press Return. The IP Address Serving screen will appear.F

Seite 126 - First Come First Serve Mode

IP Setup 7-19• The DHCP Next-Server field allows you to enter the IP address of the next server in the boot process, which is typically a Trivial Fil

Seite 127 - A restriction

7-20 Firmware User GuideIP Address PoolsThe IP Address Pools screen allows you to configure a separate IP address serving pool for each of up to eight

Seite 128 - MultiNAT Configuration Example

IP Setup 7-21Numerous factors influence the choice of served address. It is difficult to specify the address that will be served to a particular clien

Seite 129

7-22 Firmware User Guide• To serve DHCP clients with the type of NetBIOS used on your network, select Serve NetBIOS Type and toggle it to Yes . • Fro

Seite 130

IP Setup 7-23Select NetBIOS Name Server IP Addr and enter the IP address for the NetBIOS name server.You are now finished setting up DHCP NetBIOS Opt

Seite 131 - Notes on the example

7-24 Firmware User Guide• The ability to view the host name associated with a client to which the gateway has leased an IP address.• The ability for

Seite 132

IP Setup 7-25You can select the entries in the Served IP Addresses screen. Use the up and down arrow keys to move the selection to one of the entrie

Seite 133 - Chapter 5

7-26 Firmware User GuideSelecting Details… displays a pop-up menu that provides additional information associated with the IP address. The pop-up men

Seite 134 - Transit Internetwork

IP Setup 7-27An IP address is marked declined when a client to whom the DHCP server offers the address declines the address. A client declines an ad

Seite 135

2-6 Firmware User Guide7. To add a circuit, select Add Circuit and press Return. The Add Circuit screen appears.• Enter a name for the circuit in the

Seite 136 - About PPTP Tunnels

7-28 Firmware User GuideDHCP Relay AgentThe Netopia Firmware Version 8.7 offers DHCP Relay Agent functionality, as defined in RFC1542. A DHCP relay ag

Seite 137

IP Setup 7-29Select IP Address Serving and press Return. The IP Address Serving screen appears.Select IP Address Serving Mode. The pop-up menu offer

Seite 138

7-30 Firmware User GuideNow you can enter the IP address(es) of your remote DHCP server(s), such as might be located in your company’s corporate head

Seite 139 - About IPsec Tunnels

IP Setup 7-31The Add Connection Profile screen appears.On a Router you can add up to 15 more connection profiles, for a total of 16, although only one

Seite 140 - About L2TP Tunnels

7-32 Firmware User Guide4. Toggle or enter any IP parameters you require and return to the Add Connection Profile screen by pressing Escape. For more

Seite 141

IP Setup 7-33Multicast ForwardingMulticasting is a method for transmitting large amounts of information to many, but not all, computers over an Inte

Seite 142

7-34 Firmware User GuideNavigate to the IP Profile Parameters screen.Typically, you will have a Connection Profile that you created in Easy Setup. You

Seite 143 - About GRE Tunnels

IP Setup 7-35Select Add Virtual Router and press Return.The Add Virtual Router screen appears.• VRID – Enter a VRID value. Each logical IP interface

Seite 144

7-36 Firmware User GuideIf it matches the local IP address of that interface or the subnets, the Virtual Router will be defaulted to have a priority

Seite 145

IP Setup 7-37• Monitor WAN – Toggle this option to Ye s (the default) to enable VRRP routers on the interface to relinquish Master status if the WAN

Seite 146 - VPN force-all

WAN Configuration 2-7Quality of Service (QoS) settingsNote: QoS settings are not available on Ethernet-to-Ethernet WAN models.• Select the QoS (Quali

Seite 147 - About ATMP Tunnels

7-38 Firmware User GuideMultiple logical IP LAN support allows you to create additional IP routed LAN interfaces (ALANs). You can add, edit, or delet

Seite 148

IP Setup 7-39The Add Additional LAN screen appears.Supply the following information:• Name – Enter a descriptive name for the ALAN or accept the ass

Seite 149 - Encryption Support

7-40 Firmware User GuideEditing or Deleting ALANsYou can manage or edit your ALANs at any time. To modify or delete a configured ALAN, return to the I

Seite 150 - ATMP/PPTP Default Profile

Line Backup 8-1Chapter 8Line BackupNetopia Firmware Version 8.7 offers line backup functionality in the event of a line failure on the primary WAN l

Seite 151

8-2 Firmware User Guide• the Backup IP Gateway menu item in the IP Setup screen under the System Configuration menuHere you enter a Backup Gateway IP

Seite 152 - VPN QuickView

Line Backup 8-3Assuming you selected PPP, new fields appear.Underlying Encapsulation and PPP Mode do not usually need to be changed for a PPP connect

Seite 153 - Dial-Up Networking for VPN

8-4 Firmware User GuideThe Datalink (PPP/MP) Options screen appears.• Data Compression should remain set to Standard LZS.• Usually, you use PAP Authe

Seite 154

Line Backup 8-5• Select IP Profile Parameters. The IP Profile Parameters screen appears.• Unless otherwise instructed, accept the defaults, except the

Seite 155

8-6 Firmware User Guide• From the Dial pop-up menu, you can choose whether to Dial Out Only, Dial In Only, or Dial In/Out (default).• Dialing Prefix:

Seite 156

Line Backup 8-7IP SetupHere, you set the IP address of the alternate gateway.Navigate to the IP Setup screen under the System Configuration menu.• Se

Seite 157 - PPTP example

2-8 Firmware User GuideNote: With multiple VCs you must explicitly statically bind the second (and all subsequent) VCs to a profile. The first VC will

Seite 158

8-8 Firmware User GuideWAN ConfigurationTo configure the modem characteristics, from the Main Menu select WAN Configuration and then WAN Setup. The Choo

Seite 159

Line Backup 8-9Choose the interface to configure for backup, MODEM (Wan Module 2) Setup.The Internal Modem Setup screen appears.• Modem Dialing Prefix

Seite 160 - ATMP example

8-10 Firmware User GuideThis screen is used to configure the conditions under which backup will occur, if it will recover, and how the modem is configu

Seite 161

Line Backup 8-11Should this address become unreachable the router will treat this as a loss of connectivity and begin the backup timer. This loss is

Seite 162 - 5-30 Firmware User Guide

8-12 Firmware User Guide• Data Link Encapsulation is Async PPP – if it appears (not on all models) this field is not editable.When you are finished, pr

Seite 163 - GRE as shown below

Line Backup 8-13• Toggle Scheduled Connection Enable to On.• From the How Often pop-up menu, select Weekly and press Return.• From the Schedule Type

Seite 164 - Windows Networking Broadcasts

8-14 Firmware User Guide• Select Use Connection Profile, and press Return. A screen displays all of your Connection Profiles. Select the one you want t

Seite 165

Line Backup 8-15The Backup Configuration screen appears.This screen is used to configure the conditions under which backup will occur, if it will reco

Seite 166

8-16 Firmware User Guide• If you chose Automatic Recovery, select Requires Recovery of. Enter the number of minutes you want the system to wait befor

Seite 167 - Management for VPNs

Line Backup 8-17Backup Management/StatisticsIf backup is enabled, the Statistics & Logs menu offers a Backup Management/Statistics option.To vie

Seite 168

WAN Configuration 2-9Creating a New Connection ProfileConnection profiles are useful for configuring the connection and authentication settings for nego

Seite 169

8-18 Firmware User GuideDuring recovery, the following reasons may appear:• Time Since Detection is a display-only field that is only visible if backu

Seite 170 - Adding an IKE Phase 1 Profile

Monitoring Tools 9-1Chapter 9Monitoring ToolsThis chapter discusses the Router’s device and network monitoring tools. These tools can provide statis

Seite 171

9-2 Firmware User GuideGeneral statusCurrent Date: The current date; this can be set with the Date and Time utility (see “Date and time” on page 3-22

Seite 172

Monitoring Tools 9-3Rate: Shows the line rate for this connection.%Use: Indicates the average percent utilization of the maximum capacity of the cha

Seite 173 - Advanced IKE Phase 1 Options

9-4 Firmware User GuideEvent HistoriesNetopia Firmware Version 8.7 records certain relevant occurrences in event histories. Event histories are usefu

Seite 174

Monitoring Tools 9-5The first event in each call sequence is marked with double arrows (>>).Failures are marked with an asterisk (*).If the eve

Seite 175

9-6 Firmware User GuideIP Routing TableThe IP routing table displays all of the IP routes currently known to the Router.The routing table screen repr

Seite 176

Monitoring Tools 9-7Physical InterfaceThe top left side of the screen lists total packets received and total packets transmitted for the following d

Seite 177 - Key Management

9-8 Firmware User GuideSystem InformationThe System Information screen gives a summary view of the general system level values in the Router.From the

Seite 178

Monitoring Tools 9-9Simple Network Management Protocol (SNMP)Netopia Firmware Version 8.7 includes a Simple Network Management Protocol (SNMP) agent

Seite 179

2-10 Firmware User GuideMultiple Data Link Encapsulation Settings4. Select Encapsulation Options and press Return.• If you selected ATMP, PPTP, L2TP,

Seite 180 - Advanced IPsec Options

9-10 Firmware User GuideFollow these steps to configure the first three items in the screen:1. Select System Name and enter a descriptive name for the

Seite 181 - Enhanced Dead Peer Detection

Monitoring Tools 9-11Setting the Read-Only and Read-Write community strings to the empty string will block all SNMP requests to the gateway. (The ga

Seite 182 - Multiple Network IPsec

9-12 Firmware User GuideSetting the IP trap receivers1. Select Add IP Trap Receiver.2. Select Receiver IP Address or Domain Name. Enter the IP addres

Seite 183

Monitoring Tools 9-134. Toggle Send Heartbeat Trap on (Yes ) or off (No). The heartbeat setting is used to broadcast contact and location informatio

Seite 184

9-14 Firmware User Guide

Seite 185

Security 10-1Chapter 10SecurityNetopia Firmware Version 8.7 provides a number of security features to help protect its configuration screens and your

Seite 186

10-2 Firmware User GuideTelnet Tiered Access – Two Password LevelsNetopia Firmware Version 8.7 offers tiered access control for greater security and

Seite 187

Security 10-3PCs using UPnP can retrieve the Gateway’s WAN IP address, and automatically create NAT port maps. This means that applications that sup

Seite 188 - IPsec Manual Key Entry

10-4 Firmware User GuideLimited user configurationThe Add Access Name/Password and Show/Change Access Name/Passwords screens allow you to select which

Seite 189 - VPN Quickview

Security 10-5You can toggle the default user privileges for each user. The defaults are set to minimize the possibility of an individual user inadve

Seite 190

WAN Configuration 2-11Return to the Add Connection Profile screen by pressing Escape.5. Select IP Profile Parameters and press Return. The IP Profile Pa

Seite 191

10-6 Firmware User GuideAdvanced Security OptionsThe Advanced Security Options screen allows you to configure the global access privileges of users au

Seite 192 - 6-26 Firmware User Guide

Security 10-7RADIUS server authentication• You select your desired mode by using the Security Databases pop-up menu.• Choosing Local Only, the defau

Seite 193 - IP Setup

10-8 Firmware User GuideNote: In the latter two modes that involve both RADIUS and the local database, if the local database includes no username/pas

Seite 194

Security 10-9Configuration is similar to RADIUS server configuration. An additional toggle option TACACS+ Accounting allows you to enable or disable t

Seite 195

10-10 Firmware User GuideAttempting to delete the last username/password pair from the local authentication database when the Security Databases pop-

Seite 196 - IP subnets

Security 10-11• Select RADIUS Access Privileges, and from the pop-up menu, choose which access privilege you want this user to have: All, LAN, WAN,

Seite 197

10-12 Firmware User GuideUser access passwordUsers must be able to change their names and passwords, regardless of other security access restrictions

Seite 198 - Static routes

Security 10-13User menu differencesMenus reflect the security access level of the user. Consequently, configuration menus will display differing optio

Seite 199 - Viewing static routes

10-14 Firmware User GuideBased on access level, the Main Menu displays its configuration options according to the following diagram:WAN Configuration s

Seite 200 - Adding a static route

Security 10-15Connection ProfilesThe Superuser can disallow limited user access to a particular Connection Profile. When adding a Connection Profile in

Seite 201 - Deleting a static route

2-12 Firmware User Guide6. Toggle or enter your IP Parameters.For more information, see:• “IP Setup” on page 7-2• “Network Address Translation (NAT)”

Seite 202 - RIP Options

10-16 Firmware User GuideSystem Configuration menuThe System Configuration menu is always available to all users. Based on access level, the System Con

Seite 203 - IP Setup 7-11

Security 10-17Utilities & Diagnostics menuBased on access level, the Utilities & Diagnostics menu displays its configuration options accordin

Seite 204 - Transmit RIP

10-18 Firmware User Guide Statistics & Logs WAN Event History... Device Event History...

Seite 205 - Adding a key

Security 10-19Quick MenusQuick Menus vary considerably between models, features, and access levels. The following is an example comparison of the Qu

Seite 206 - Changing or deleting a key

10-20 Firmware User GuideThe ATM Circuits Configuration menu screen appears as follows:Note: Multiple ATM circuit configuration is supported on multipl

Seite 207

Security 10-21About Filters and Filter SetsSecurity should be a high priority for anyone administering a network connected to the Internet. Using pa

Seite 208

10-22 Firmware User GuideFilter priorityContinuing the customs inspectors analogy, imagine the inspectors lined up to examine a package. If the packa

Seite 209 - IP Address Serving

Security 10-23• Blocks (discards) the packet• Ignores the packetA filter forwards or blocks a packet only if it finds a match after applying its crite

Seite 210

10-24 Firmware User GuidePort number comparisonsA filter can also use a comparison option to evaluate a packet’s source or destination port number. Th

Seite 211

Security 10-25Putting the parts togetherWhen you display a filter set, its filters are displayed as rows in a table:The table’s columns correspond to

Seite 212 - IP Address Pools

WAN Configuration 2-13• The Receive RIP pop-up menu controls the reception and transmission of Routing Information Protocol (RIP) packets on the WAN

Seite 213 - DHCP NetBIOS Options

10-26 Firmware User GuideFiltering example #1Returning to our filtering rule example from above (see page 10-23), look at how a rule is translated int

Seite 214

Security 10-27This filter blocks any packets coming from a remote network with the IP network address 200.233.14.0. The 0 at the end of the address s

Seite 215 - More Address Serving Options

10-28 Firmware User Guide• That which is not expressly prohibited is permitted.• That which is not expressly permitted is prohibited.It is strongly r

Seite 216

Security 10-29Adding a filter setYou can create up to eight different custom filter sets. Each filter set can contain up to 16 output filters and up to

Seite 217

10-30 Firmware User GuideAdding filters to a filter setThere are two kinds of filters you can add to a filter set: input and output. Input filters check p

Seite 218

Security 10-31Note: There are two groups of items in this screen, one for input filters and one for output filters. In this section, you’ll learn how

Seite 219

10-32 Firmware User Guide3. If you want the filter to forward packets that match its criteria to the destination IP address, select Forward and toggle

Seite 220 - DHCP Relay Agent

Security 10-33Deleting filtersTo delete a filter, select Delete Input Filter or Delete Output Filter in the Display/Change Filter Set screen to displa

Seite 221

10-34 Firmware User GuideBasic Firewall blocks undesirable traffic originating from the WAN (in most cases, the Internet), but forwards all traffic ori

Seite 222 - Connection Profiles

Security 10-35Output filter 1: This filter forwards all outgoing traffic to make sure that no outgoing connections from the LAN are blocked.Basic Firew

Seite 223

Contents iii G Chapter 1 — Introduction...1-1 What’s New in 8.7 ...

Seite 224

2-14 Firmware User Guide9. Select COMMIT and press Return. Your new Connection Profile will be added.If you want to view the Connection Profiles in you

Seite 225 - Multicast Forwarding

10-36 Firmware User GuideFTP sessions. To allow WAN-originated FTP sessions to a LAN-based FTP server with the IP address a.b.c.d (corresponding to a

Seite 226

Security 10-37In addition, the TOS field has been added to the classifier list in a filter. This allows you to filter on TOS field settings in the IP pac

Seite 227

10-38 Firmware User GuideCertain types of IP packets, such as voice or multimedia packets, are sensitive to latency introduced by the network. A dela

Seite 228

Security 10-39Firewall TutorialGeneral firewall termsFilter rule: A filter set is comprised of individual filter rules.Filter set: A grouping of indivi

Seite 229 - Additional LANs

10-40 Firmware User GuideExample TCP/UDP PortsFirewall design rulesThere are two basic rules to firewall design:• “What is not explicitly allowed is d

Seite 230

Security 10-41and a packet goes through these rules destined for FTP, the packet would for ward through the first filter rule (WWW), match the second

Seite 231

10-42 Firmware User GuideEstablished connectionsThe TCP header contains one bit called the ACK bit (or TCP Ack bit). This ACK bit appears only with T

Seite 232 - Editing or Deleting ALANs

Security 10-43Example networkExample filtersExample 1 Incoming packet has the source address of 200.1.1.28Less Than or Equal Any port less than or eq

Seite 233 - Line Backup

10-44 Firmware User Guide This incoming IP packet has a source IP address that matches the network address in the Source IP Address field (00000000)

Seite 234

Security 10-45 Since the Source IP Network Address in the Router is 01100000, and the source IP address after the logical AND is 1011000, this rule

Seite 235 - Line Backup 8-3

WAN Configuration 2-15Advanced Connection OptionsDepending on your model, the Advanced Connection Options screen offers a variety of powerful options

Seite 236

10-46 Firmware User Guide Since the Source IP Network Address in the Router is 01100000, and the source IP address after the logical AND is 01100000

Seite 237

Security 10-47 Select Save Current Configuration as , and press Return. The Save Current Configuration screen appears.Enter a descriptive name for y

Seite 238

10-48 Firmware User Guide A warning screen will ask you to confirm your choice. Factory Default to a saved configuration If you need to Factory Defaul

Seite 239

Security 10-49 Once you make the selection, if you factory Default the Router, it will reboot with the saved configuration you have selected.To remo

Seite 240

10-50 Firmware User Guide

Seite 241 - Backup Configuration screen

Utilities and Diagnostics 11-1 Chapter 11 Utilities and Diagnostics A number of utilities and tests are available for system diagnostic and control

Seite 242

11-2 Firmware User GuidePingThe Netopia Firmware Version 8.7 includes a standard Ping test utility. A Ping test generates IP packets destined for a p

Seite 243

Utilities and Diagnostics 11-3Status: The current status of the Ping test. This item can display the status messages shown in the able below:Packets

Seite 244

11-4 Firmware User GuidePackets Lost: The number of packets unaccounted for, shown in total and as a percentage of total packets sent. This statisti

Seite 245

Utilities and Diagnostics 11-53. Select Timeout (seconds) to set when the trace will timeout for each hop, up to 10 seconds. The default is 3 second

Seite 246 - Backup Default Gateway

2-16 Firmware User GuideWhen you toggle Configuration Changes Reset WAN Connection either to Yes or No using the Tab key and press Return, a pop-up wi

Seite 247

11-6 Firmware User Guide• To end a suspended session, select Terminate Suspended Session. Select a session from the pop-up menu and press Return.Fact

Seite 248 - IP Setup screen

Utilities and Diagnostics 11-7The sections below describe how to update the Router’s firmware and how to download and upload configuration files.Updati

Seite 249 - Backup Management/Statistics

11-8 Firmware User Guide• Select TFTP Server Name and enter the server name or IP address of the TFTP server you will use. The server name or IP addr

Seite 250 - QuickView

Utilities and Diagnostics 11-9You must restar t the system whenever you reconfigure the Router and want the new parameter values to take effect. Unde

Seite 251 - Monitoring Tools

11-10 Firmware User Guide

Seite 252 - Current status

Troubleshooting A-1Appendix ATroubleshootingThis appendix is intended to help you troubleshoot problems you may encounter while setting up and using

Seite 253 - Statistics & Logs

A-2 Firmware User GuideNote: If you are attempting to modify the IP address or subnet mask from a previous, successful configuration attempt, you will

Seite 254 - Event Histories

Troubleshooting A-3How to Reset the Router to Factory DefaultsLose your password? This section shows how to reset the Netopia Router so that you can

Seite 255 - Device Event History

A-4 Firmware User GuideBefore contacting NetopiaLook in this guide for a solution to your problem. You may find a solution in this troubleshooting app

Seite 256 - General Statistics

Index-1IndexAadd static route 7-8Additional LANs 7-4, 7-38ADSL Line Configuration 2-4advanced configurationfeatures 3-1ALANs 7-38ATMP 5-17tunnel optio

Seite 257 - Network Interface

WAN Configuration 2-17Viewing scheduled connectionsTo display a table of scheduled connections, select Display/Change Scheduled Connection in the Sch

Seite 258 - System Information

Index-2navigating 1-5encryption 5-2, 5-7, 5-17, 6-1event historydevice 9-5WAN 9-4Exposed Addresses 3-4Extended Authentication 6-6Ffactory default A-3F

Seite 259 - The SNMP Setup screen

Index-3line backup 8-1backup IP gateway 8-16connection profiles 8-2management and statistics 8-17scheduled connections 8-12WAN configuration 8-8Loggin

Seite 260 - Community strings

Index-4router to serve IP addresses to hosts 7-1routing tablesIP 7-6, 9-6Sscheduled connections 2-16adding 2-18deleting 2-21modifying 2-21once-only 2-

Seite 261 - SNMP traps

Index-5updating Netopia’s firmware 11-7upgrade 1-3uploading configuration files 11-8with TFTP 11-8utilities and diagnostics 11-1VVariable Bit Rate (VB

Seite 263 - Deleting IP trap receivers

2-18 Firmware User Guide• The time of day that the connection will Begin At• The duration of the connection (HH:MM)• Whether it’s a recurring Weekly

Seite 264 - 9-14 Firmware User Guide

WAN Configuration 2-19• Demand-Blocked, meaning that this schedule will prevent a demand call on the line.• Periodic, meaning that the connection is

Seite 265 - Security

2-20 Firmware User Guide• Select Scheduled Window Duration Per Day and enter the maximum duration allowed for this scheduled connection, per call.• R

Seite 266 - UPnP Support

WAN Configuration 2-21You are finished configuring the once-only options. Return to the Add Scheduled Connection screen to continue.• In the Add Schedu

Seite 267 - Superuser configuration

2-22 Firmware User GuideDiffserv OptionsNetopia Firmware Version 8.7 offers Differentiated Services (Diffserv) enhancements. These enhancements allow

Seite 268 - Limited user configuration

WAN Configuration 2-23The Diffserv options are displayed.• Enter a value from 60 to 100 (percent) in the Lo/Hi Ratio field.Differentiated Services use

Seite 269 - Security 10-5

iv Firmware User Guide Adding Port interfaces ... 3-16Changing or Deleting a VLAN...

Seite 270 - Advanced Security Options

2-24 Firmware User GuideThe Diffserv Rule screen appears.• Name – Enter a name in this field to label the rule.• Protocol – Select the protocol from t

Seite 271 - RADIUS server authentication

WAN Configuration 2-25• Inside IP Address/Netmask – For outbound flows, specify an IP address and subnet mask on your LAN. For inbound flows, this sett

Seite 272 - TACACS+ server authentication

2-26 Firmware User GuideThe Router will recognize a delay-sensitive packet as having the low-latency bit set in the TOS field of the IP header.If you

Seite 273 - Warning alerts

WAN Configuration 2-27Toggle Ping Enable to On and press Return. The Ping settings options appear.• The Ping Host Name or IP Address #1 and Ping Host

Seite 275

System Configuration 3-1Chapter 3System ConfigurationThis chapter describes how to use the Telnet-based management screens to access and configure adva

Seite 276 - User access password

3-2 Firmware User GuideThe System Configuration menu screen appears:IP SetupThese screens allow you to configure your network’s use of the IP networkin

Seite 277 - User menu differences

System Configuration 3-3Stateful InspectionStateful inspection is a security feature that prevents unsolicited inbound access when NAT is disabled. S

Seite 278 - WAN Configuration screens

3-4 Firmware User GuideAdd Exposed Address ListYou can specify the IP addresses you want to expose by selecting Add Exposed Address List from the Sta

Seite 279

System Configuration 3-5Select Add Exposed Address Range and press Return. The Exposed Address Range screen appears.Enter the First and Last Exposed

Seite 280 - IP Setup menu

Contents v G Modifying map lists... 4-12Adding Server Lists...

Seite 281 - Statistics & Logs menu

3-6 Firmware User GuideThe pop-up Protocol menu offers the type of protocols to be assigned to this range.• First Exposed Address: Start IP Address o

Seite 282 - 10-18 Firmware User Guide

System Configuration 3-7You can edit or delete exposed address lists by selecting Show/Change Exposed Address List or Delete Exposed Address List. A

Seite 283 - Quick Menus

3-8 Firmware User GuideExposed Address AssociationsEnable and configure stateful inspection on a WAN interface.When you create or modify a Connection

Seite 284 - Telnet Access

System Configuration 3-9Select Stateful Inspection Options and press Return. The Stateful Inspection Parameters screen appears.• Max. TCP Sequence Nu

Seite 285 - About Filters and Filter Sets

3-10 Firmware User GuideOpen ports in default Stateful Inspection installationPort Protocol Description Private Interface Public Interface23 TCP teln

Seite 286 - How individual filters work

System Configuration 3-11VLAN ConfigurationA Virtual Local Area Network (VLAN) is a network of computers that behave as if they are connected to the s

Seite 287 - Port numbers

3-12 Firmware User GuideThe Add VLAN selection appears.Select Add VLAN and press Return.The Add VLAN screen appears.You can create up to 8 VLANs, and

Seite 288 - Other filter attributes

System Configuration 3-13• VLAN Type – Beginning with Firmware Version 8.6.1, LAN or WAN Port(s) can be enabled on the VLAN. See “Adding Port interfa

Seite 289 - Putting the parts together

3-14 Firmware User GuideCaution!If you enable 802.1x for a VLAN that includes a wireless SSID, you must access the Wireless LANConfiguration menu and

Seite 290 - Filtering example #2

System Configuration 3-15The Add Server Profile screen appears.The Add Server Profile screen allows you to specify the RADIUS server and its authentica

Seite 291 - Design guidelines

vi Firmware User Guide PPTP example... 5-25ATMP example ...

Seite 292

3-16 Firmware User GuideAdding Port interfacesOnce you have created a VLAN entry you must associate it with a port interface. This interface may be e

Seite 293 - Adding a filter set

System Configuration 3-17Select Add Port Interface and press Return.The Add Port Interface screen appears. (The Add Port Interface screen varies depe

Seite 294 - Adding filters to a filter set

3-18 Firmware User Guide• TOS-Priority – Use any 802.1p priority bits in the VLAN header to prioritize packets within the Gateway’s internal queues,

Seite 295

System Configuration 3-19If you are deleting a profile, you will be challenged to be sure that you want to delete the profile that you have selected.If

Seite 296 - Modifying filters

3-20 Firmware User GuideConfiguring additional Authentication ServersYou can configure additional (or your first) Authentication Ser ver from the main V

Seite 297 - A sample filter set

System Configuration 3-21The Add Server Profile screen appears.Configure your profile in the same way as described in “Adding a RADIUS Profile” on page 3

Seite 298

3-22 Firmware User GuideDate and timeYou can set the system’s date and time parameters in the Set Date and Time screen. Date and Time parameters gove

Seite 299 - Possible modifications

System Configuration 3-235. Select a System Date Format; the options are MM/DD/YY, DD/MM/YY, and YY/MM/DD, where M is month, D is day, and Y is year.

Seite 300

3-24 Firmware User Guide• Block Wireless Bridging: Toggle this setting to Ye s to block wireless clients from communicating with other wireless clie

Seite 301 - TOS field matching

System Configuration 3-25Note: Enabling Closed System Mode on your wireless Gateway provides another level of security, since your wireless LAN will

Seite 302

Contents vii G Additional LANs ... 7-37 Chapter 8 — Line Backup ...

Seite 303 - Firewall Tutorial

3-26 Firmware User GuideTo enable the Wireless Multimedia custom settings, select diffserv from the pull-down menu.Enable PrivacyBy default, Enable P

Seite 304 - Firewall design rules

System Configuration 3-27The Pre Shared Key field becomes visible to allow you to enter a Pre Shared Key. The key can be between 8 and 63 characters,

Seite 305 - Implied rules

3-28 Firmware User Guide• WPA Version: If you select either WPA-802.1x or WPA-PSK as your privacy setting, the WPA Version pop-up menu allows you to

Seite 306 - Filter basics

System Configuration 3-29You select a single key for encryption of outbound traffic. The WEP-enabled client must have an identical key of the same len

Seite 307 - Example 1

3-30 Firmware User Guideneeds to be done once. Avoid the temptation to enter all the same characters. Default Key (#1 – #4): Specifies which key the R

Seite 308 - Example 3

System Configuration 3-31Toggle Enable Multiple SSIDs to Yes , and enter names or other identifiers for up to three additional SSIDs you want to creat

Seite 309 - Example 5

3-32 Firmware User GuideYou can also specify a WPA Version from the pop-up menu in the same way as the primary SSID.These additional SSIDs are “Close

Seite 310 - Configuration Management

System Configuration 3-33MAC Address AuthenticationEnhanced in Firmware Version 8.5, MAC Address Authentication allows you to specify which client PC

Seite 311

3-34 Firmware User Guide• Allow only specified addresses - limits access to only those addresses that you enter.• Deny only specified addresses - preve

Seite 312

System Configuration 3-35The list is displayed as shown below.You can continue to Add, Change, or Delete addresses to the list by selecting the respe

Seite 313

viii Firmware User Guide Limited user configuration ... 10-4Advanced Security Options ...

Seite 314 - 10-50 Firmware User Guide

3-36 Firmware User GuideFollow these steps to change a parameter’s value:1. Select 57600, 38400, 19200, or 9600.2. Select SET CONFIG NOW to save the

Seite 315 - Utilities and Diagnostics

System Configuration 3-37Router/Bridge SetFor Netopia DSL Routers, this feature allows you to turn off the routing features and use your device as a

Seite 316

3-38 Firmware User GuideIf you chose CONTINUE, the device will reboot and restar t in the selected mode. Routing features will be disabled or changed

Seite 317

System Configuration 3-39IGMP (Internet Group Management Protocol)Multicasting is a method for transmitting large amounts of information to many, but

Seite 318 - Trace Route

3-40 Firmware User Guide• IGMP Snooping – toggling this option to On enables the Netopia Router to “listen in” to IGMP traffic. The Router discovers m

Seite 319 - Telnet Client

System Configuration 3-41The IGMP V2/V3 Settings screen appears.You can configure the following parameters:• Last Member Query Interval (deci-sec) – t

Seite 320 - Factory Defaults

3-42 Firmware User GuideLoggingYou can configure a UNIX-compatible (BSD syslog protocol - RFC 3164) syslog client to report a number of subsets of the

Seite 321 - Downloading configuration files

System Configuration 3-43You will need to install a Syslog client daemon program on your PC and configure it to report the WAN events you specified in

Seite 322 - Restarting the System

3-44 Firmware User Guide2. attempt3. administrative access authenticated and allowed4. administrative access allowed5. dropped - violation of securit

Seite 323

System Configuration 3-45The following syslog messages may be generated by the router if WAN Event Log Options are enabled:1. Device Restarted 2. EN:

Seite 324 - 11-10 Firmware User Guide

Contents ix G Factory Defaults ... 11-6Transferring Configuration and Firmware Files with TFTP.

Seite 325 - Troubleshooting

3-46 Firmware User Guide33. PPPOE: PADS Received 34. PPPOE: PADT Received 35. PPPOE: PADT Sent 36. PPPOE: Discovery state started profile [Profile

Seite 326 - Network problems

System Configuration 3-4766. IKE: phase 1 auth failure sg [IP Address] profile [Name], sg [IP Address] code [code] 67. IKE: phase 1 resend timeout

Seite 327 - Technical Support

3-48 Firmware User GuideProcedure for Default Installation for ICSA firewall certification of Small/Medium Business Category Module (ADSL Routers)Note:

Seite 328 - How to reach us

System Configuration 3-49Setting up an encrypted communication channel: (PPTP with MS-CHAP/MPPE)(See “Virtual Private Networks (VPNs)” on page 5-1 fo

Seite 329

3-50 Firmware User GuideSet up NTP(See “Date and time” on page 3-22 for more information.)1. NTP is enabled by default.2. To change NTP Settings, Go

Seite 330

System Configuration 3-512. Go to WAN Configuration…3. Select Display/Change Connection Profile…4. Select Easy Setup Profile (if available) or the desir

Seite 331

3-52 Firmware User Guide

Seite 332

Multiple Network Address Translation 4-1Chapter 4Multiple Network Address TranslationNetopia Firmware Version 8.7 offers advanced Multiple Network A

Seite 333

4-2 Firmware User GuideFeaturesMultiNAT features can be divided into several categories that can be used simultaneously in different combinations on

Seite 334

Multiple Network Address Translation 4-3Dynamic mappingDynamic mapping, often referred to as many-to-few, offers an extension to the advantages prov

Kommentare zu diesen Handbüchern

Keine Kommentare