Page 2
Re la te d Do c um e nta tio n • Quick Start Guide The Quick Start Guide shows how to connect the managed device • More Information Go to to find other information on the XMG suppo rt.zyxe l.c o m XMG3512-B10A User’s Guide...
3.2 Quick Start Setup ..........................30 C ha pte r 4 T uto ria ls ...............................33 4.1 Overview ............................33 4.2 Setting Up an ADSL PPPoE Connection ..................33 4.3 Setting Up a Secure Wireless Network ..................36 XMG3512-B10A User’s Guide...
Page 6
C ha pte r 7 Wire le ss ...............................83 7.1 Overview ............................83 7.1.1 What You Can Do in this Chapter ..................83 7.1.2 What You Need to Know ..................... 83 7.2 The General Screen ........................84 XMG3512-B10A User’s Guide...
Page 7
8.9.1 LANs, WANs and the XMG ....................122 8.9.2 DHCP Setup ......................... 123 8.9.3 DNS Server Addresses ......................123 C ha pte r 9 Ro uting ..............................124 9.1 Overview ............................124 9.2 The Routing Screen ........................124 XMG3512-B10A User’s Guide...
Page 8
11.6 The ALG Screen .......................... 158 11.7 The Address Mapping Screen ....................158 11.7.1 Add/Edit Address Mapping Rule ..................159 11.8 The Sessions Screen ........................160 11.9 Technical Reference ........................161 11.9.1 NAT Definitions ........................161 11.9.2 What NAT Does ......................... 161 XMG3512-B10A User’s Guide...
Page 9
15.3 The Media Server Screen ......................179 C ha pte r 16 Fire wa ll..............................181 16.1 Overview ............................. 181 16.1.1 What You Can Do in this Chapter ................... 181 16.1.2 What You Need to Know ....................182 16.2 The Firewall Screen ........................182 XMG3512-B10A User’s Guide...
Page 10
L o g ..............................203 21.1 Overview ............................. 203 21.1.1 What You Can Do in this Chapter ................... 203 21.1.2 What You Need To Know ....................203 21.2 The System Log Screen ......................204 21.3 The Security Log Screen ......................204 XMG3512-B10A User’s Guide...
Page 11
28.1 Overview ............................ 218 28.2 The User Account Screen ......................218 28.2.1 The User Account Add/Edit Screen ................218 C ha pte r 29 Re m o te Ma na g e m e nt........................220 29.1 Overview ............................. 220 XMG3512-B10A User’s Guide...
Page 12
C ha pte r 36 Dia g no stic ............................237 36.1 Overview ............................. 237 36.1.1 What You Can Do in this Chapter ................... 237 36.2 What You Need to Know ......................237 36.3 Ping & TraceRoute & NsLookup ....................238 XMG3512-B10A User’s Guide...
Page 13
37.6 UPnP ............................. 247 Pa rt III: Appe ndic e s ..................248 Appendix A Customer Support ..................... 249 Appendix B Wireless LANs....................... 255 Appendix C Services........................268 Appendix D Legal Information ...................... 272 Inde x ..............................281 XMG3512-B10A User’s Guide...
XMG. You could simply restore your last configuration. 1.4 Applic a tio ns fo r the XMG Here are some example uses for which the XMG is well suited. XMG3512-B10A User’s Guide...
LAN port to the broadband modem or router. This way, > Ethe rne t WAN you can access the Internet via an Ethernet connection and still use the QoS, Firewall and parental control functions on the XMG. XMG3512-B10A User’s Guide...
Use the built-in USB 2.0 port to share files on a USB memory stick or a USB hard drive ( ). You can connect one USB hard drive to the XMG at a time. Use FTP to access the files on the USB device. XMG3512-B10A User’s Guide...
) connected to the XMG’s USB port (without having to copy them to another computer). USB Media Server Application Fig ure 5 1.5 L EDs (L ig hts) The following graphic displays the labels of the LEDs. XMG3512-B10A User’s Guide...
Page 19
The DSL line is down. Green The XMG has a successful connection on the WAN. Blinking The XMG is sending or receiving data to/from the WAN. The XMG does not detect a SFP connection to the WAN. XMG3512-B10A User’s Guide...
This means that you will lose all configurations that you had previously and the password will be reset to “1234”. Make sure the LED is on (not blinking). PO WER XMG3512-B10A User’s Guide...
Press the WPS button on another WPS-enabled device within range of the XMG. The LED flashes WiFi orange while the XMG sets up a WPS connection with the other wireless device. Once the connection is successfully made, the LED shines green. LED turns off when the wireless network is off. XMG3512-B10A User’s Guide...
Make sure the screws are fastened well enough to hold the weight of the XMG with the connection cables. Align the holes on the back of the XMG with the screws on the wall. Hang the XMG on the screws. Wall Mounting Example Fig ure 8 XMG3512-B10A User’s Guide...
L o g in Fig ure 9 The following screen displays if you have not yet changed your password. Enter a new password, retype it to confirm and click Apply XMG3512-B10A User’s Guide...
Q uic k Sta rt Wiza rd Ne two rk Ma p Fig ure 11 Click to display the screen, where you can view the XMG’s interface and system Sta tus Sta tus information. XMG3512-B10A User’s Guide...
The title bar provides some icons in the upper right corner. The icons provide the following functions. Table 3 Web Configurator Icons in the Title Bar IC O N DESC RIPT IO N : Select the language you prefer. L a ng ua g e XMG3512-B10A User’s Guide...
STB devices when they request IP addresses. Wake on LAN Use this screen to remotely turn on a device on the local network. TFTP Server Name Configure a TFTP server name which is sent to clients using DHCP option XMG3512-B10A User’s Guide...
Page 27
(such as parental control) is enforced. Certificates Local Certificates Use this screen to view a summary list of certificates and manage certificates and certification requests. Trusted CA Use this screen to view and manage the list of the trusted CAs. XMG3512-B10A User’s Guide...
Page 28
Use this screen to configure up to two mail servers and sender addresses Notification Notification on the XMG. Log Setting Log Setting Use this screen to change your XMG’s log settings. Firmware Firmware Use this screen to upload firmware to your XMG. Upgrade Upgrade XMG3512-B10A User’s Guide...
Page 29
Use this screen to configure CFM (Connectivity Fault Management) MD (maintenance domain) and MA (maintenance association), perform connectivity tests and view test reports. OAM Ping Use this screen to view information to help you identify problems with the DSL connection. XMG3512-B10A User’s Guide...
Select the time zone of your location. Click Ne xt Quick Start - Welcome Fig ure 13 Enter your Internet connection information in this screen. The screen and fields to enter may vary depending on your current connection type. Click Ne xt XMG3512-B10A User’s Guide...
XMG. Click Sa ve Quick Start - Wireless Setting Fig ure 15 Your XMG saves your settings and attempts to connect to the Internet. Click to complete the C lo se setup. XMG3512-B10A User’s Guide...
Ne two rk Se tting > Bro a db a nd Add Ne w WAN Inte rfa c e In this example, the DSL connection has the following information. G e ne ra l Name MyDSLConnection Type ADSL over ATM Connection Mode Routing Encapsulation PPPoE XMG3512-B10A User’s Guide...
Then select DNS as and enter the DNS server addresses provided to you, such as Sta tic 192.168.5.2 (DNS server1)/ (DNS server2). 192.168.5.1 Leave the rest of the fields to the default settings. Click to save your settings. Apply XMG3512-B10A User’s Guide...
Page 35
Bro a db a nd Try to connect to a website to see if you have correctly set up your Internet connection. Be sure to contact your service provider for any information you need to configure the WAN screens. XMG3512-B10A User’s Guide...
Ne two rk Se tting Wire le ss G e ne ra l Mo re Se c ure as the security mode. Configure the screen using the provided parameters (see WPA2- PSK page 36). Click Apply XMG3512-B10A User’s Guide...
Page 37
Thomas can now use the WPS feature to establish a wireless connection between his notebook and the XMG (see Section 4.3.2 on page 38). He can also use the notebook’s wireless client to search for the XMG (see Section 4.3.3 on page 41). XMG3512-B10A User’s Guide...
Both buttons have exactly the same function: you can use one or the other. Note: It doesn’t matter which button is pressed first. You must press the second button within two minutes of pressing the first one. XMG3512-B10A User’s Guide...
Page 39
Launch your wireless client’s configuration utility. Go to the WPS settings and select the PIN method to get a PIN number. Log into XMG’s web configurator and go to the screen. Enable the Ne two rk Se tting > Wire le ss > WPS WPS function and click Apply XMG3512-B10A User’s Guide...
Page 40
This may take up to two minutes. The wireless client is then able to communicate with the XMG securely. The following figure shows you how to set up a wireless network and its security on a XMG and a wireless client by using PIN method. XMG3512-B10A User’s Guide...
Use the wireless adapter’s utility installed on the notebook to search for the “Example” SSID. Then enter the “DoNotStealMyWirelessNetwork” pre-shared key to establish an wireless Internet connection. Note: The XMG supports IEEE 802.11b and IEEE 802.11g wireless clients. Make sure that your notebook or computer’s wireless adapter supports one of these standards. XMG3512-B10A User’s Guide...
Use this screen to set up the company’s Ne two rk Se tting > Wire le ss G e ne ra l general wireless network group. Configure the screen using the provided parameters and click Apply XMG3512-B10A User’s Guide...
Page 43
Click the icon to Ne two rk Se tting > Wire le ss > G ue st/ Mo re AP Edit configure the second wireless network group. Configure the screen using the provided parameters and click XMG3512-B10A User’s Guide...
Page 44
Chapter 4 Tutorials In the screen, click the icon to configure the third wireless network group.Configure G ue st Mo re AP Edit the screen using the provided parameters and click Apply XMG3512-B10A User’s Guide...
In order to extend your Intranet and control traffic flowing directions, you may connect a router to the XMG’s LAN. The router may be used to separate two department networks. This tutorial shows how to configure a static routing rule for two network routings. XMG3512-B10A User’s Guide...
Page 46
This tutorial uses the following example IP settings: Table 5 IP Settings in this Tutorial DEVIC E / C O MPUT ER IP ADDRESS The XMG’s WAN 172.16.1.1 The XMG’s LAN 192.168.1.1 IP Type IPv4 Use Interface VDSL/ppp1.1 192.168.1.34 ’s N1 192.168.1.253 XMG3512-B10A User’s Guide...
4.6 C o nfig uring Q o S Q ue ue a nd C la ss Se tup This section contains tutorials on how you can configure the QoS screen. XMG3512-B10A User’s Guide...
Page 48
In the screen that opens, check Q ue ue Se tup Add ne w Q ue ue Ac tive and enter or select the following values: • : E-mail Na m e • Inte rfa c e XMG3512-B10A User’s Guide...
Page 49
Click > to create a new class. Check and follow the C la ssific a tio n Se tup Add ne w C la ssific a tio n Ac tive settings as shown in the screen below. XMG3512-B10A User’s Guide...
Page 50
This maps e-mail traffic coming from port 25 to the highest priority, which you have created in the previous screen (see the field). This also maps your computer’s IP address and MAC address IP Pro to c o l to the queue (see the fields). E- m a il So urc e XMG3512-B10A User’s Guide...
Then you will need to configure the same account and host name on the XMG later. 4.7.2 C o nfig uring DDNS o n Yo ur XMG Configure the following settings in the screen. Ne two rk Se tting > DNS > Dyna m ic DNS XMG3512-B10A User’s Guide...
Josephine’s computer connects wirelessly to the Internet through the XMG. Thomas decides to use the screen to grant wireless network access to his computer but not to Josephine’s Se c urity > MAC Filte r computer. XMG3512-B10A User’s Guide...
4.9 Ac c e ss Yo ur Sha re d File s Fro m a C o m pute r Here is how to use an FTP program to access a file storage device connected to the XMG’s USB port. XMG3512-B10A User’s Guide...
Page 54
21 and click . A screen asking for password authentication appears. Q uic kc o nne c t File Sharing via Windows Explorer Once you log in the USB device displays in the folder. XMG3512-B10A User’s Guide...
5.2 T he Ne two rk Ma p Sc re e n Use this screen to view the network connection status of the device and its clients. A warning message appears if there is a connection problem. XMG3512-B10A User’s Guide...
If you prefer to view the status in a list, click in the selection box. You can L ist Vie w Vie wing m o de configure how often you want the XMG to update this screen in Re fre sh inte rva l Fig ure 18 XMG3512-B10A User’s Guide...
This field displays the current subnet mask in the WAN. MAC Address This shows the WAN Ethernet adapter MAC (Media Access Control) Address of your XMG. Primary DNS This field displays the first DNS server address assigned by the ISP. server XMG3512-B10A User’s Guide...
Page 59
If memory usage does get close to 100%, the XMG is probably becoming unstable, and you should restart the device. See Section 35.2 on page 234, or turn off the device (unplug the power) for a few seconds. XMG3512-B10A User’s Guide...
Page 60
For the Ethernet WAN and LAN interfaces, this displays the port speed and duplex setting. For the DSL interface, it displays the downstream and upstream transmission rate. For the WLAN interface, it displays the maximum transmission rate or with WLAN N/ A disabled. XMG3512-B10A User’s Guide...
C O NNEC T IO N SET T ING S ADSL/VDSL over Routing PPPoE PPP information, IPv4/IPv6 IP address, routing feature, DNS server, VLAN, and MTU IPoE IPv4/IPv6 IP address, routing feature, DNS server, VLAN, and MTU Bridge VLAN XMG3512-B10A User’s Guide...
IPv6 address size to 128 bits (from the 32-bit IPv4 address) allows up to 3.4 x 10 IP addresses. The XMG can use IPv4/IPv6 dual stack to connect to IPv4 and IPv6 networks, and supports IPv6 rapid deployment (6RD). XMG3512-B10A User’s Guide...
Page 63
Border Relay router (BR in the figure) to connect to the native IPv6 Internet. The local network can also use IPv4 services. The XMG uses it’s configured IPv4 WAN IP to route IPv4 traffic to the IPv4 Internet. XMG3512-B10A User’s Guide...
I Pv4 in I Pv6 AFTR I Pv4 I nt ernet 6.1.3 Be fo re Yo u Be g in You need to know your Internet access settings such as encapsulation and WAN IP address. Get this information from your ISP. XMG3512-B10A User’s Guide...
WAN interface Add Ne w WAN Inte rfa c e Bro a db a nd Edit to configure a WAN connection. The screen varies depending on the interface type, mode, encapsulation, and IPv6/IPv4 mode you select. XMG3512-B10A User’s Guide...
Page 66
The following table describes the labels in this screen. Table 9 Network Setting > Broadband > Add New WAN Interface/Edit (Routing Mode) L ABEL DESC RIPT IO N General Name Specify a descriptive name for this connection. XMG3512-B10A User’s Guide...
Page 67
(IAD) you want the XMG to add in the DHCP Discovery packets that go to the DHCP server. DHCP This field displays when editing an existing WAN interface. Type the DHCP Unique Identifier (DUID) option 61 you want the XMG to add in the DHCP Discovery packets that go to the DHCP server. DUID XMG3512-B10A User’s Guide...
Page 68
This is available only when you select in the field. Select to let IPv6 O nly IPv4/ IPv6 Mo de Ena b le local computers use IPv4 through an ISP’s IPv6 network. DS-Lite Relay Specify the transition router’s IPv6 address. Server IP XMG3512-B10A User’s Guide...
Page 69
XMG to get subscription information and maintain a joined member list for each multicast group. It can reduce multicast traffic significantly. Apply as Default Select this option to have the XMG use the WAN interface of this connection as the system Gateway default gateway. XMG3512-B10A User’s Guide...
Page 70
If you select as the interface type, the following screen appears. ADSL / VDSL o ve r PT M Ethe rne t Network Setting > Broadband > Add New WAN Interface/Edit (ADSL/VDSL over PTM -Bridge Fig ure 25 Mode) XMG3512-B10A User’s Guide...
Page 71
The following table describes the fields in this screen. Table 11 Network Setting > Broadband > Add New WAN Interface/Edit (ADSL over ATM-Bridge Mode) L ABEL DESC RIPT IO N General Name Enter a service name of the connection. XMG3512-B10A User’s Guide...
Rate Adaptation) functions. The XMG supports the PhyR retransmission scheme. PhyR is a retransmission scheme designed to provide protection against noise on the DSL line. It improves voice, video and data transmission resilience by utilizing a retransmission buffer. XMG3512-B10A User’s Guide...
Page 73
4096 4.3125 14.5 3479 8.625 14.5 Click > > to display the following screen. Ne two rk Se tting Bro a db a nd Adva nc e d Network Setting > Broadband > Advanced Fig ure 27 XMG3512-B10A User’s Guide...
Page 74
ADSL2+. It has a long reach performance, and unlike VDSL systems it is not limited to short local loops. VDSL Profile VDSL2 profiles differ in the width of the frequency band used to transmit the broadband signal. Profiles that use a wider frequency band can deliver higher maximum speeds. XMG3512-B10A User’s Guide...
Ethernet LAN port to the Ethernet WAN port. Otherwise, Ena b le select Disa b le Apply Click to save your changes back to the XMG. Apply Cancel Click to return to the previous configuration. C a nc e l XMG3512-B10A User’s Guide...
N/ A certificate assigned. Trusted CA This shows the Trusted CA used for this authentication. This displays when there is no Trusted N/ A CA assigned. Modify Click this icon to edit an item. XMG3512-B10A User’s Guide...
Enc a psula tio n Be sure to use the encapsulation method required by your ISP. The XMG can work in bridge mode or routing mode. When the XMG is in routing mode, it supports the following methods. XMG3512-B10A User’s Guide...
Page 78
In this case, by prior mutual agreement, each protocol is assigned to a specific virtual circuit; for example, VC1 carries IP, etc. VC-based multiplexing may be dominant in environments where dynamic creation of large numbers of ATM VCs is fast and economical. XMG3512-B10A User’s Guide...
Page 79
These are the basic ATM traffic classes defined by the ATM Forum Traffic Management 4.0 Specification. Constant Bit Rate (CBR) Constant Bit Rate (CBR) provides fixed bandwidth that is always available even if no data is being sent. CBR traffic is generally time-sensitive (doesn't tolerate delay). CBR is used for connections that XMG3512-B10A User’s Guide...
Page 80
VLAN also increases network performance by limiting broadcasts to a smaller and more manageable logical broadcast domain. In traditional switched environments, all broadcast packets go to each and every individual port. With VLAN, all broadcasts are confined to a specific broadcast domain. XMG3512-B10A User’s Guide...
Page 81
The XMG can get the DNS server addresses in the following ways. The ISP tells you the DNS server addresses, usually in the form of an information sheet, when you sign up. If your ISP gives you DNS server addresses, manually enter them in the DNS server fields. XMG3512-B10A User’s Guide...
Page 82
(start from the left) in the address compose the network address. The prefix length is written as “/x” where x is a number. For example, 2001:db8:1a2b:15::1a2f:0/32 means that the first 32 bits (2001:db8) is the subnet prefix. XMG3512-B10A User’s Guide...
XMG’s new settings. Click > to open the screen. Ne two rk Se tting Wire le ss G e ne ra l Network Setting > Wireless > General Fig ure 32 XMG3512-B10A User’s Guide...
Page 85
No Se c urity encryption or authentication. See the following sections for more details about this field. Apply Click to save your changes. Apply Cancel Click to restore your previously saved settings. C a nc e l XMG3512-B10A User’s Guide...
5G Hz In order to configure and enable WEP encryption, click > to display the Ne two rk Se tting Wire le ss G e ne ra l screen, then select as the security level. Ba sic XMG3512-B10A User’s Guide...
WPA2-PSK. The WPA2-PSK security mode is a newer, more robust version of the WPA encryption standard. It offers slightly better security, although the use of PSK makes it less robust than it could be. Note: is not available if you enable WPS before you configure them. WPA- PSK XMG3512-B10A User’s Guide...
This screen allows you to enable and configure multiple Basic Service Sets (BSSs) on the XMG. Click > . The following screen displays. Ne two rk Se tting > Wire le ss G ue st/ Mo re AP XMG3512-B10A User’s Guide...
7.3.1 Edit G ue st/ Mo re AP Use this screen to edit an SSID profile. Click the icon next to an SSID in the screen. The Edit G ue st/ Mo re AP following screen displays. XMG3512-B10A User’s Guide...
Page 90
, clients connecting to the same SSID can communicate with each Ho m e G ue st other directly. If you select , clients are blocked from connecting to each other directly. Exte rna l G ue st XMG3512-B10A User’s Guide...
MAC (Media Access Control) address. The MAC address is assigned at the factory and consists of six pairs of hexadecimal characters, for example, 00:A0:C5:00:00:02. You need to know the MAC addresses of the devices to configure this screen. XMG3512-B10A User’s Guide...
WPS allows you to quickly set up a wireless network with strong security, without having to configure security settings manually. Set up each WPS connection between two devices. Both devices must support WPS. See Section 7.9.8.3 on page 105 for more information about WPS. XMG3512-B10A User’s Guide...
Page 93
Method 3 Use this section to set up a WPS wireless network by entering the PIN of the XMG into the client. Select and click to activate WPS method 3 on the XMG. Ena b le Apply XMG3512-B10A User’s Guide...
Note: This works only if the wireless device to which the XMG is connected also supports this feature. Apply Click to save your changes. Apply Cancel Click to restore your previously saved settings. C a nc e l XMG3512-B10A User’s Guide...
Delivery Traffic Indication Message (DTIM) is the time period after which broadcast and multicast packets are transmitted to mobile clients in the Power Saving mode. A high DTIM value can cause clients to lose connectivity with the network. This value can be set from 1 to 255. XMG3512-B10A User’s Guide...
You can go to the screen, click the link, and G e ne ra l m o re Ne two rk Se tting > Wire le ss > then change the channel width setting in the field. Ba ndwidth XMG3512-B10A User’s Guide...
• An “infrastructure” type of network has one or more access points and one or more wireless clients. The wireless clients connect to the access points. • An “ad-hoc” type of network is one in which there is no access point. Wireless clients connect to one another in order to exchange information. XMG3512-B10A User’s Guide...
Page 98
When you create a network, you must select a channel to use. Since the available unlicensed spectrum varies from one country to another, the number of available channels also varies. XMG3512-B10A User’s Guide...
For example, if your mother owns a 1970 Dodge Challenger and her favorite movie is XMG3512-B10A User’s Guide...
Page 100
Some wireless devices, such as scanners, can detect wireless networks but cannot use wireless networks. These kinds of wireless devices might not have MAC addresses. Hexadecimal characters are 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, A, B, C, D, E, and F. XMG3512-B10A User’s Guide...
Problems with absorption occur when physical objects (such as thick walls) are between the two radios, muffling the signal. XMG3512-B10A User’s Guide...
• You must use different keys for different BSSs. If two wireless devices have different BSSIDs (they are in different BSSs), but have the same keys, they may hear each other’s communications (but not communicate with each other). • MBSSID should not replace but rather be used in conjunction with 802.1x security. XMG3512-B10A User’s Guide...
(see the device’s User’s Guide for how to do this - for the XMG, see Section 7.6 on page 94). Press the button on one of the devices (it doesn’t matter which). For the XMG you must press the WPS button for more than five seconds. XMG3512-B10A User’s Guide...
Page 104
If you cannot connect, check the list of associated wireless clients in the AP’s configuration utility. If you see the wireless client in the list, WPS was successful. The following figure shows a WPS-enabled wireless client (installed in a notebook computer) connecting to the WPS-enabled AP via the PIN method. XMG3512-B10A User’s Guide...
Page 105
If the registrar is already part of a network, it sends the existing information. If not, it generates the SSID and WPA(2)-PSK randomly. The following figure shows a WPS-enabled client (installed in a notebook computer) connecting to a WPS-enabled access point. XMG3512-B10A User’s Guide...
Page 106
When WPS is activated on both, they perform the handshake. In this example, is the registrar, and is the enrollee. The registrar randomly generates the security information to set up the network, C lie nt 1 since it is unconfigured and has no existing information. XMG3512-B10A User’s Guide...
Page 107
, so you cannot for the WPS handshake with the new access point. However, you know that supports C lie nt 2 the registrar function, so you use it to perform the WPS handshake instead. XMG3512-B10A User’s Guide...
Page 108
If this happens, open the access point’s configuration interface and look at the list of associated clients (usually displayed by MAC address). It does not matter if the access XMG3512-B10A User’s Guide...
Page 109
Check the MAC addresses of your wireless clients (usually printed on a label on the bottom of the device). If there is an unknown MAC address you can remove it or reset the AP. XMG3512-B10A User’s Guide...
Wa ke o n L AN • Use the screen to set a TFTP server address which is passed to the clients using DHCP T FT P Se rve r Na m e option 66. (Section 8.8 on page 122). XMG3512-B10A User’s Guide...
UPnP devices and enable exchange of simple product and service descriptions. NAT traversal allows the following: • Dynamic port mapping • Learning public IP addresses XMG3512-B10A User’s Guide...
Enter the IP subnet mask into the field. Unless instructed otherwise it is best to leave this Sub ne t Ma sk alone, the configurator will automatically compute a subnet mask based upon the IP address you entered. XMG3512-B10A User’s Guide...
Page 113
Chapter 8 Home Networking Click to save your settings. Apply Network Setting > Home Networking > LAN Setup Fig ure 50 XMG3512-B10A User’s Guide...
Page 114
Sta tic DNS Server 1/2 This field is only available when you select in the field. Enter the first and second DNS Sta tic (Domain Name System) server IP addresses the XMG passes to the DHCP clients. XMG3512-B10A User’s Guide...
Page 115
IPv6 address of a DNS server. Enter the DNS server IPv6 Use r- De fine d addresses the XMG passes to the DHCP clients. Select if you do not want to configure IPv6 DNS servers. No ne XMG3512-B10A User’s Guide...
IP address field editable and change it. Edit Click the icon to delete a static DHCP entry. A window displays asking you to confirm De le te that you want to delete the selected entry. XMG3512-B10A User’s Guide...
IP address, convey its capabilities and learn about other devices on the network. In turn, a device can leave a network smoothly and automatically when it is no longer in use. page 111 for more information on UPnP. XMG3512-B10A User’s Guide...
Make sure the computer is connected to a LAN port of the XMG. Turn on your computer and the XMG. Click the start icon, and then the C o ntro l Pa ne l Ne two rk a nd Sha ring C e nte r. XMG3512-B10A User’s Guide...
Page 119
T urn o n ne two rk disc o ve ry Sa ve C ha ng e s find other computers and devices on the network and other computers on the network to find your computer. This makes it easier to share files and printers. XMG3512-B10A User’s Guide...
Enter the public IPv4 subnet mask provided by your ISP. Offer Public IP Select to enable the XMG to provide public IP addresses by DHCP server. Ena b le by DHCP Enable ARP Select to enable the ARP (Address Resolution Protocol) proxy. Ena b le Proxy XMG3512-B10A User’s Guide...
Click > > to open this screen. Ne two rk Se tting Ho m e Ne two rking Wa ke o n L AN Network Setting > Home Networking > Wake on LAN Fig ure 56 XMG3512-B10A User’s Guide...
L ANs, WANs a nd the XMG The actual physical connection determines whether the XMG ports are LAN or WAN ports. There are two separate IP networks, one inside the LAN network and the other outside the WAN network as shown next. XMG3512-B10A User’s Guide...
DNS servers out of the DHCP setup under all circumstances. If your ISP gives you explicit DNS servers, make sure that you enter their IP addresses in the screen. DHC P Se tup XMG3512-B10A User’s Guide...
Use this screen to view and configure the static route rules on the XMG. Click Ne two rk Se tting > Ro uting to open the following screen. > Sta tic Ro ute Network Setting > Routing > Static Route Fig ure 60 XMG3512-B10A User’s Guide...
Use this screen to add or edit a static route. Click in the screen or the Add ne w sta tic ro ute Ro uting Edit icon next to the static route you want to edit. The screen shown next appears. Routing: Add/Edit Fig ure 61 XMG3512-B10A User’s Guide...
A gray bulb signifies that this DNS route is not active. Domain Name This is the host name or domain name of the DNS route entry. WAN Interface This is the WAN connection through which the XMG forwards DNS requests for this domain name. XMG3512-B10A User’s Guide...
Policy-based routing is applied to outgoing packets, prior to the normal routing. You can use source-based policy forwarding to direct traffic from different users through different connections or distribute traffic among multiple paths for load sharing. XMG3512-B10A User’s Guide...
Page 128
This is the WAN interface through which the traffic is routed. Modify Click the icon to edit this policy. Edit Click the icon to remove a policy from the XMG. A window displays asking you to confirm De le te that you want to delete the policy. XMG3512-B10A User’s Guide...
Cancel Click to exit this screen without saving. C a nc e l 9.5 RIP Routing Information Protocol (RIP, RFC 1058 and RFC 1389) allows a device to exchange routing information with other routers. XMG3512-B10A User’s Guide...
Select the check box to set the XMG to not send the route information to the default gateway. Gateway Apply Click to save your changes back to the XMG. Apply Cancel Click to restore your previously saved settings. C a nc e l XMG3512-B10A User’s Guide...
Sha pe r Se tup (Section 10.6 on page 141). • Use the screen to control incoming traffic transmission rate and bursts (Section 10.7 on Po lic e r Se tup page 142). XMG3512-B10A User’s Guide...
(or queues). Your XMG uses the Token Bucket algorithm to allow a certain amount of large bursts while keeping a limit at the average rate. Traffic Rat e Traffic Rat e Tim e Tim e ( Before Traffic Shaping) ( Aft er Traffic Shaping) XMG3512-B10A User’s Guide...
Ne two rk Se tting > Q o S > G e ne ra l Use this screen to enable or disable QoS and set the upstream bandwidth. See Section 10.1 on page 131 for more information. Network Settings > QoS > General Fig ure 67 XMG3512-B10A User’s Guide...
10.4 T he Q ue ue Se tup Sc re e n Click to open the screen as shown next. Ne two rk Se tting > Q o S > Q ue ue Se tup Use this screen to configure QoS queue assignment. XMG3512-B10A User’s Guide...
Page 135
This shows the maximum transmission rate allowed for traffic on this queue. Modify Click the icon to edit the queue. Edit Click the icon to delete an existing queue. Note that subsequent rules move up by one De le te when you take this action. XMG3512-B10A User’s Guide...
Rate Limit Specify the maximum transmission rate (in Kbps) allowed for traffic on this queue. Click to save your changes. Cancel Click to exit this screen without saving. C a nc e l XMG3512-B10A User’s Guide...
10.5.1 Add/ Edit Q o S C la ss Click in the screen or the icon next to a classifier to open Add Ne w C la ssific a tio n C la ssific a tio n Se tup Edit the following screen. XMG3512-B10A User’s Guide...
Page 138
Chapter 10 Quality of Service (QoS) Classification Setup: Add/Edit Fig ure 71 XMG3512-B10A User’s Guide...
Page 139
For example, if you set the MAC address to 00:13:49:00:00:00 and the mask to ff:ff:ff:00:00:00, a packet with a MAC address of 00:13:49:12:34:56 matches this criteria. Exclude Select this option to exclude the packets that match the specified criteria from this classifier. Others XMG3512-B10A User’s Guide...
Page 140
Re m o ve If you select , the XMG treat all matched traffic untagged and add a second VLAN ID. If you select , the XMG keep the VLAN ID in the packets. Unc ha ng e XMG3512-B10A User’s Guide...
Rate Limit (kbps) This shows the average rate limit of traffic bursts for this shaper. Modify Click the icon to edit the shaper. Edit Click the icon to delete an existing shaper. Note that subsequent rules move up by one De le te when you take this action. XMG3512-B10A User’s Guide...
The following table describes the labels in this screen. Table 51 Network Setting > QoS > Policer Setup L ABEL DESC RIPT IO N Add new Policer Click this to create a new entry. This is the index number of the entry. XMG3512-B10A User’s Guide...
Fig ure 75 The following table describes the labels in this screen. Table 52 Policer Setup: Add/Edit L ABEL DESC RIPT IO N Active Select to enable or disable this policer. Name Enter the descriptive name of this policer. XMG3512-B10A User’s Guide...
A VLAN tag includes the 12-bit VLAN ID and 3-bit user priority. The VLAN ID associates a frame with a specific VLAN and provides the information that devices need to process the frame across the network. XMG3512-B10A User’s Guide...
Page 145
The DSCP value determines the forwarding behavior, the PHB (Per-Hop Behavior), that each packet gets across the DiffServ network. Based on the marking rule, different kinds of traffic can be marked for different kinds of forwarding. Resources can then be allocated according to the DSCP values and the configured policies. XMG3512-B10A User’s Guide...
Page 147
• A packet arrives. The packet is marked green and can be transmitted if the number of tokens in the CBS bucket is equal to or greater than the size of the packet (in bytes). • After a packet is transmitted, a number of tokens corresponding to the packet size is removed from the CBS bucket. XMG3512-B10A User’s Guide...
Page 148
• If the PBS bucket has enough tokens, the XMG checks the CBS bucket. The packet is marked green and can be transmitted if the number of tokens in the CBS bucket is equal to or greater than the size of the packet (in bytes). Otherwise, the packet is marked yellow. XMG3512-B10A User’s Guide...
IP address of a host when the packet is in the local network, while the global address refers to the IP address of the host when the same packet is traveling in the WAN side. XMG3512-B10A User’s Guide...
IP address of 192.168.1.35 to a third ( in the example). You assign the LAN IP addresses and the ISP assigns the WAN IP address. The NAT network appears as a single host on the Internet. XMG3512-B10A User’s Guide...
Page 151
This shows the IP protocol supported by this virtual server, whether it is , or T C P T C P/ UDP Modify Click the icon to edit this rule. Edit Click the icon to delete an existing rule. De le te XMG3512-B10A User’s Guide...
To forward only one port, enter the port number again in the field. End Po rt To forward a series of ports, enter the start port number here and the end port number in the field. Po rt XMG3512-B10A User’s Guide...
Click this to add a new NAT application rule. Application This is the index number of the entry. Application This field shows the type of application that the service forwards. Forwarded WAN Interface This field shows the WAN interface through which the service is forwarded. XMG3512-B10A User’s Guide...
Some services use a dedicated range of ports on the client side and a dedicated range of ports on the server side. With regular port forwarding you set a forwarding port in NAT to forward a service (coming in XMG3512-B10A User’s Guide...
Page 155
Use this screen to view your Ne two rk Se tting > NAT > Po rt T rig g e ring XMG’s trigger port settings. Network Setting > NAT > Port Triggering Fig ure 82 XMG3512-B10A User’s Guide...
This screen lets you create new port triggering rules. Click in the screen or Add ne w rule Po rt T rig g e ring click a rule’s icon to open the following screen. Edit Port Triggering: Add/Edit Fig ure 83 XMG3512-B10A User’s Guide...
De fa ult Se rve r Addre ss received for ports that are not specified in the screen. NAT Po rt Fo rwa rding Apply Click to save your changes. Apply Cancel Click to restore your previously saved settings. C a nc e l XMG3512-B10A User’s Guide...
XMG takes the corresponding action and the remaining rules are ignored. Click to display the following screen. Ne two rk Se tting > NAT > Addre ss Ma pping Network Setting > NAT > Address Mapping Fig ure 86 XMG3512-B10A User’s Guide...
To add or edit an address mapping rule, click or the rule’s edit icon in the Add ne w rule Addre ss screen to display the screen shown next. Ma pping Address Mapping: Add/Edit Fig ure 87 XMG3512-B10A User’s Guide...
With heavy peer-to-peer application use, lower this number to ensure no single client uses too many of the available NAT sessions. Apply Click this to save your changes on this screen. Cancel Click this to exit this screen without saving any changes. XMG3512-B10A User’s Guide...
With no servers defined, your XMG filters out all incoming inquiries, thus preventing intruders from probing your network. For more information on IP address translation, refer to RFC 1631 , T he IP Ne two rk Addre ss T ra nsla to r (NAT ) . XMG3512-B10A User’s Guide...
Address (IGA) 192.168.1.11 192.168.1.10 11.9.4 NAT Applic a tio n The following figure illustrates a possible NAT application, where three inside LANs (logical LANs using IP alias) behind the XMG can communicate with three distinct WAN networks. XMG3512-B10A User’s Guide...
Page 163
Let's say you want to assign ports 21-25 to one FTP, Telnet and SMTP server ( in the example), port 80 to another ( in the example) and assign a default server IP address of 192.168.1.35 to a third ( in the XMG3512-B10A User’s Guide...
Page 164
You assign the LAN IP addresses and the ISP assigns the WAN IP address. The NAT network appears as a single host on the Internet. Multiple Servers Behind NAT Example Fig ure 91 A=192.168.1.33 192.168.1.1 B=192.168.1.34 IP address assigned by ISP C=192.168.1.35 D=192.168.1.36 XMG3512-B10A User’s Guide...
Enabling the wildcard feature for your host causes *.yourhost.dyndns.org to be aliased to the same IP address as yourhost.dyndns.org. This feature is useful if you want to be able to use, for example, www.yourhost.dyndns.org and still reach your hostname. XMG3512-B10A User’s Guide...
You can manually add or edit the XMG’s DNS name and IP address entry. Click Add Ne w DNS Entry screen or the icon next to the entry you want to edit. The screen shown next appears. DNS Entry Edit DNS Entry: Add/Edit Fig ure 93 XMG3512-B10A User’s Guide...
Last Updated Time This shows the last time the IP address the Dynamic DNS provider has associated with the hostname was updated. Current Dynamic This shows the IP address your Dynamic DNS provider has currently associated with the hostname. XMG3512-B10A User’s Guide...
Page 168
Table 70 Network Setting > DNS > > Dynamic DNS (continued) L ABEL DESC RIPT IO N Apply Click to save your changes. Apply Cancel Click to exit this screen without saving. C a nc e l XMG3512-B10A User’s Guide...
The following table describes the fields in this screen. Table 71 Network Setting > Vlan Group L ABEL DESC RIPT IO N Add New Vlan Click this button to create a new VLAN group. Group This is the index number of the VLAN group. XMG3512-B10A User’s Guide...
LAN port with the number T x T a g g ing VL AN ID entered above. Click to save your changes back to the XMG. Cancel Click to exit this screen without saving. C a nc e l XMG3512-B10A User’s Guide...
(meaning it is a Windows 2000 DHCP client) is assigned the IP address 192.168.2.2 and uses the WAN VDSL_PoE/ppp0.1 interface. Interface Grouping Application Fig ure 98 Default: ETH 2~4 192.168.1.x/24 eth10.0 VDSL_PoE/ppp0.1 192.168.2.x/24 DHCP Vendor ID option: MSFT 5.0 XMG3512-B10A User’s Guide...
Add Ne w Inte rfa c e G ro up Inte rfa c e G ro uping screen. Use this screen to create a new interface group. Note: An interface can belong to only one group at a time. XMG3512-B10A User’s Guide...
Page 173
Inte rfa c e s interfaces to this group. Available LAN Interfaces To remove a LAN or wireless LAN interface from the interface list on the left, use the right-facing arrow. XMG3512-B10A User’s Guide...
Select this option to be able to use wildcards in the Vendor Class Identifier configured for DHCP wildcard option 60. DHCP Option 61 Select this and enter the device identity of the matched traffic. DHCP Option Select this and enter vendor specific information of the matched traffic. XMG3512-B10A User’s Guide...
Page 175
Select this and the VLAN group of the matched traffic from the drop-down list box. Click to save your changes back to the XMG. Cancel Click to exit this screen without saving. C a nc e l XMG3512-B10A User’s Guide...
(Section 15.3 on page Me dia Se rve r 179). 15.1.2 Wha t Yo u Ne e d T o Kno w The following terms and concepts may help as you read this chapter. XMG3512-B10A User’s Guide...
Use this screen to set up file sharing through the XMG. The XMG’s LAN users can access the shared folder (or share) from the USB device inserted in the XMG. To access this screen, click Ne two rk Se tting > USB Se rvic e > File Sha ring XMG3512-B10A User’s Guide...
Use this screen to create a user account that can access the secured shares on the USB device. To access this screen, click the button in the Add Ne w Use r Ne two rk Se tting > USB Se rvic e > File Sha ring screen. XMG3512-B10A User’s Guide...
To change your XMG’s media server settings, click . The Ne two rk Se tting > USB Se rvic e > Me dia Se rve r screen appears as shown. XMG3512-B10A User’s Guide...
Page 180
Enter the path clients use to access the media files on a USB storage device connected to the Path XMG. Apply Click to save your changes. Apply Cancel Click to restore your previously saved settings. C a nc e l XMG3512-B10A User’s Guide...
(Section 16.4 Ac c e ss C o ntro l on page 185). • Use the screen to activate protection against Denial of Service (DoS) attacks (.Section 16.5 on Do S page 187). XMG3512-B10A User’s Guide...
Use this screen to set the security level of the firewall on the XMG. Firewall rules are grouped based on the direction of travel of packets to which they apply. Click to display the screen. Se c urity > Fire wa ll G e ne ra l XMG3512-B10A User’s Guide...
IANA (Internet Assigned Number Authority) website. See Appendix C on page 268 for some examples. Click to display the following screen. Se c urity > Fire wa ll > Pro to c o l Security > Firewall > Protocol Fig ure 108 XMG3512-B10A User’s Guide...
Type a single port number or the range of port numbers that define your customized service. Protocol This field is displayed if you select as the protocol. O the r Number Enter the protocol number of your customized port. XMG3512-B10A User’s Guide...
16.4.1 Add/ Edit a n AC L Rule Click or the icon next to an existing ACL rule in the screen. The Add ne w AC L rule Edit Ac c e ss C o ntro l following screen displays. XMG3512-B10A User’s Guide...
Page 186
Se le c t Pro to c o l Choose the IP port ( , or ) that defines your customized port from T C P/ UDP T C P IC MP IC MPv6 the drop-down list box. XMG3512-B10A User’s Guide...
DESC RIPT IO N DoS Protection Select to enable protection against DoS attacks. Ena b le Blocking Apply Click to save your changes. Apply Cancel Click to exit this screen without saving. C a nc e l XMG3512-B10A User’s Guide...
17.2 T he MAC Filte r Sc re e n Use this screen to allow wireless and LAN clients access to the XMG. Click > . The Se c urity MAC Filte r screen appears as shown. Security > MAC Filter Fig ure 113 XMG3512-B10A User’s Guide...
Enter the MAC addresses in a valid MAC address format, that is, six hexadecimal character pairs, for example, 12:34:56:78:9a:bc. Apply Click to save your changes. Apply Cancel Click to restore your previously saved settings. C a nc e l XMG3512-B10A User’s Guide...
This shows the day(s) and time on which parental control is enabled. Schedule Network Service This shows whether the network service is configured. If not, will be shown. No ne Website This shows whether the website block is configured. If not, will be shown. No ne Blocked XMG3512-B10A User’s Guide...
Use this screen to configure a restricted access schedule and/or URL filtering settings to block the users on your network from accessing certain web sites. Parental Control Rule: Add/Edit Rule Fig ure 115 XMG3512-B10A User’s Guide...
Page 192
This shows the URL of web site or URL keyword to which the XMG blocks or allows access. Modify Click the icon to go to the screen where you can edit the rule. Edit Click the icon to delete an existing rule. De le te XMG3512-B10A User’s Guide...
Page 193
Select the transport layer protocol used for the service. Choices are TCP, UDP, or TCP & UDP. Port Enter the port of the service. If you have chosen a pre-defined service in the Service Name field, this field will not be configurable. XMG3512-B10A User’s Guide...
Page 194
Enter a keyword and click to have the XMG to block access to the website URLs that contain the keyword Click to save your changes. Cancel Click to exit this screen without saving. C a nc e l XMG3512-B10A User’s Guide...
Add Ne w Rule Sc he dule r Rule Edit to open the following screen. Use this screen to configure a restricted access schedule. XMG3512-B10A User’s Guide...
Enter the time period of each day, in 24-hour format, during which the rule will be enforced. Range Description Enter a description for this scheduler rule. Click to save your changes. Cancel Click to exit this screen without saving. C a nc e l XMG3512-B10A User’s Guide...
This is the XMG’s summary list of Se c urity > C e rtific a te s L o c a l C e rtific a te s certificates and certification requests. Security > Certificates > Local Certificates Fig ure 121 XMG3512-B10A User’s Guide...
L o c a l C e rtific a te s C re a te C e rtific a te Re q ue st following screen. Use this screen to have the XMG generate a certification request. Create Certificate Request Fig ure 122 XMG3512-B10A User’s Guide...
After you create a certificate request and have it signed by a Certificate Authority, in the L o c a l screen click the certificate request’s icon to import the signed certificate into C e rtific a te s L o a d Sig ne d the XMG. XMG3512-B10A User’s Guide...