2. What is the default password for Web Configurator?...10 3. What’s the difference between ‘Common User Account’ and ‘Administrator Account’? ...10 4. How do I know the P-660H-Tx v2's WAN IP address assigned by the ISP?...11 5. What is the micro filter or splitter used for?...11 6.
Page 3
3. What is the microfilter used for? ...16 4. How do I know the ADSL line is up?...17 5. How does the P-660H-Tx v2 work on a noisy ADSL?...17 6. Does the VC-based multiplexing perform better than the LLC-based multiplexing?...17 7.
Page 4
General Application Notes ...27 1. Internet Access Using P-660H-Tx v2 under Bridge mode ...27 2. Internet Access Using P-660H-Tx v2 under Routing mode ..29 3. Setup the P-660H-Tx v2 as a DHCP Relay ...31 4. SUA Notes...32 5. Using Full Feature NAT ...41 6.
Note: It is protected by super password, ‘1234’ by factory default. 4. How do I update the firmware and configuration file? You can do this if you access the P-660H-Tx v2 as Administrator. You can upload the firmware and configuration file to Prestige from Web Condigurator, or using FTP or TFTP client software.
In case you forget the system password, you can erase the current configuration and restore factory defaults this way: Use the RESET button on the rear panel of P-660H-Tx v2 to reset the router. After the router is reset, the LAN IP address will be reset to '192.168.1.1', the common user password will be reset to 'user', the Administrator password will be reset to ‘1234’.
LAN for outside access. The P-660H-Tx v2 supports NAT sets on a remote node basis. They are reusable, but only one set is allowed for each remote node. The P-660H-Tx v2 supports 8 sets since there are 8 remote nodes.
IP addresses as the Internal Local Addresses (ILA) and the global IP addresses as the Inside Global Address (IGA), • One to One: In One-to-One mode, the P-660H-Tx v2 maps one ILA to one IGA. • Many to One: In Many-to-One mode, the P-660H-Tx v2 maps multiple ILA to one IGA.
The Prestige does not limit the number of the users but the number of the sessions. The P-660H-Tx v2 supports 2048 sessions that you can use the 'ip nat session' command in CLI to see. You can also use ‘ip nat hashTable wanif0’...
16. How can I protect against IP spoofing attacks? The P-660H-Tx v2's filter sets provide a means to protect against IP spoofing attacks. The basic scheme is as follows: For the input data filter: • Deny packets from the outside that claim to be from the inside •...
P-660H-Tx v2 and check the current system status. For Administrator Account, besides accessing the status monitor of P-660H-Tx v2, it can also access Winzard setup/ Advanced setup of P-660H-Tx v2: Moreover, only with Administrator Password, you could manage the P-660H-Tx v2 via FTP/TFTP or Telnet.
P-660H-Tx v2 Support Notes 4. How do I know the P-660H-Tx v2's WAN IP address assigned by the ISP? You can view "My WAN IP <from ISP> : x.x.x.x" shown in Web Configurator ‘Status->Device Information ->WAN Information’ to check this IP address.
IP address we can use the DDNS service. The DDNS server allows to alias a dynamic IP address to a static hostname. Whenever the ISP assigns you a new IP, the P-660H-Tx v2 sends this IP to the DDNS server for its updates.
Because the remote gateway checks this source port during connections, the port thus is not allowed to be changed. 13. How do I setup my P-660H-Tx v2 for routing IPSec packets over SUA? For outgoing IPSec tunnels, no extra setting is required.
All applications have their own natural bit rate. Large data transactions have a fluctuating natural bit rate. The P-660H-Tx v2 is able to support variable traffic among different virtual connections. Certain traffic may be discarded if the virtual connection experiences congestion.
(that you specify) in the URL. You can set a schedule for when the P-660H-Tx v2 performs content filtering. You can also specify trusted IP Addresses on LAN for which the P-660H-Tx v2 will not perform content filtering. You can configure the details about it in Web Configurator, Advanced setup, Security ->...
4. How do I know the ADSL line is up? You can see the DSL LED Green on the P-660H-Tx v2's front panel is on when the ADSL physical layer is up. 5. How does the P-660H-Tx v2 work on a noisy ADSL? Depending on the line quality, the P-660H-Tx v2 uses "Fall Back"...
8. What are the signaling pins of the ADSL connector? The signaling pins on the P-660H-Tx v2's ADSL connector are pin 3 and pin 4. The middle two pins for a RJ11 cable. 9. What is triple play? More and more Telco/ISPs are providing three kinds of services (VoIP, Video and Internet) over one existing ADSL connection.
Service (DoS) attacks such as Ping of Death, SYN Flood, LAND attack, IP Spoofing, etc. It also uses stateful packet inspection to determine if an inbound connection is allowed through the firewall to the private LAN. The P-660H-Tx v2 supports Network Address Translation (NAT), which translates the private local addresses to one or multiple public addresses.
4. The P-660H-Tx v2's firewall is fast. It uses a hashing function to search the matched session cache instead of going through every individual rule for a packet.
1. How do I configure the firewall? You can use the Web Configurator to configure the firewall for P-660H-Tx v2. By factory default, if you connect your PC to the LAN Interface of P-660H-Tx v2, you can access Web Configurator via ‘http://192.168.1.1’.
1. Change the default Administrator password since it is required when setting up the firewall. 2. Limit who can access to your P-660H-Tx v2’s Web Configurator or CLI. You can enter the IP address of the secured LAN host in Web Configurator, Advanced Setup, Advanced ->...
3. How do I view the firewall log? All logs generated in P-660H-Tx v2, including firewall logs, IPSec logs, system logs are migrated to centralized logs. So you can view firewall logs in Centralized logs: Web Configurator, Advanced setup, Maintenance -> Logs ->View Log.
5. What is the difference between the log and alert? A log entry is just added to the log inside the P-660H-Tx v2 and e-mailed together with all other log entries at the scheduled time as configured. An alert is e-mailed immediately after an attacked is detected.
In this case, we use P-660H-Tx v2 which works as an ADSL bridge modem to connect to the ISP. The ISP will generally give one Internet account and limit only one computer to access the Internet.
Page 29
P-660H-Tx v2 Support Notes Setup your P-660H-Tx v2 under bridge mode The following procedure shows you how to configure your P-660H-Tx v2 as bridge mode. We will use Web Configurator to guide you through the related menu. (1) Configure P-660H-Tx v2 as bridge mode and configure Internet setup parameters in Web Configurator, Advanced Setup, Network ->...
Identifier) given to you by your ISP. (2) Turn off DHCP Server and configure a LAN IP for the P-660H-Tx v2 in Web Configurator, Advanced Setup, Network -> LAN. We use 192.168.1.1 as the LAN IP for P-660H-Tx v2 in this case: Step 1: Disactive DHCP Server and apply it: Step 2: Assign an IP to the LAN Interface of P-660H-Tx v2, e.g.: 192.168.1.1:...
Page 31
Ethernet cable. (2) TCP/IP configuration Since the P-660H-Tx v2 is set to DHCP server as default, so you need only to configure the workstations as the DHCP clients in the networking settings. In this case, the IP address of the computer is assigned by the P-660H-Tx v2.
Otherwise, set to Static and enter the IP in the IP Assignment Address field. (2) Configure a LAN IP for the P-660H-Tx v2 and the DHCP settings in Web Configurator, Advanced Setup, Network -> LAN. 3. Setup the P-660H-Tx v2 as a DHCP Relay •...
Cu-SeeMe, and ICQ will need to connect to the local user behind the P-660H-Tx v2. In such case, a SUA server must be configured to forward the incoming packets to the true destination behind SUA. After the required server are configured in Web Configurator, Advanced Setup, Network ->...
Page 35
Certain Quake servers do not allow multiple users to login using the same unique IP, so only one Quake user will be allowed in this case. Moreover, when a Quake server is configured behind SUA, P-660H-Tx v2 will not be able to provide information of that server on the internet.
Page 36
Also, since you need to specify the IP address of a server behind the P-660H-Tx v2, a server must have a fixed IP address and not be a DHCP client whose IP address potentially changes each time P-660H-Tx v2 is powered on.
Page 37
Setup, Network -> NAT -> Port Forwarding. The outside users can access the local server using the P-660H-Tx v2's WAN IP address which can be obtained from Web Configurator, Status -> WAN Information. For example: Configuring an internal Web server for outside access (suppose the Server IP Address is 192.168.1.10 ) :...
Page 39
Configuration This application note explains how to establish a PPTP connection with a remote private network in the P-660H-Tx v2 SUA case. In ZyNOS, all PPTP packets can be forwarded to the internal PPTP Server (WinNT server) behind SUA. The port number of the PPTP has to be entered in the Web Configurator, Advanced Setup, Network ->...
Page 40
Example The following example shows how to dial to an ISP via the P-660H-Tx v2 and then establish a tunnel to a private network. There will be three items that you need to set up for PPTP application, these are PPTP server (WinNT), PPTP client (Win9x) and the P-660H-Tx v2.
Page 41
Before making a VPN connection from the Win9x client to the NT server, you need to know the exact Internet IP address that the ISP assigns to P-660H-Tx v2 router in SUA mode and enter this IP address in the VPN dial-up dialog box.
Page 43
The P-660H-Tx v2 has 8 remote nodes and so allows you to configure 8 NAT Address Mapping Sets, You must specify which NAT Address Mapping Set (1~8) to use in the remote node when you select Full Feature NAT. You can edit 10 rules for each Address Mapping Set. You can edit the rules for Address Mapping Sets #1 in Web Configurator.
Page 45
Start IP address. • Configure Address Mapping Sets in CLI Setp 1: Telnet to the P-660H-Tx v2. (We suppose the LAN IP Address of P-660H-Tx v2 is 192.168.1.1) Step 2: Select one Address Mapping Set (#1~#8) by command ‘ip nat addrmap map [map #] [set name]’...
Page 51
Step 1: In this case, we need to map ILA to more than one IGA, therefore we must choose the Full Feature option from the NAT field in currently active remote node, and assign IGA3 to P-660H-Tx v2’s WAN IP Address. Step 2: Go to Web Configurator, Advanced Setup, Network -> NAT ->...
This solves the problems if your DNS server uses an IP associated with dynamic IPs. Without DDNS, we always tell the users to use the WAN IP of the P-660H-Tx v2 to access the internal server. It is inconvenient for the users if this IP is dynamic.
Page 55
When the ISP assigns the P-660H-Tx v2 a new IP, the P-660H-Tx v2 must inform the DDNS server the change of this IP so that the server can update its IP-to-DNS entry. Once the IP-to-DNS table in the DDNS server is updated, the DNS name for your web server (i.e., www.zyxel.com.tw) is still usable.
7. Network Management Using SNMP • ZyXEL SNMP Implementation ZyXEL currently includes SNMP support in some P-660H-Tx v2 routers. It is implemented based on the SNMPv1, so it will be able to communicate with SNMPv1 NMSs. Further, users can also add ZyXEL's private MIB in the NMS to monitor and control additional system variables.
Page 58
Enter the correct Set Community. This Set Community must match the Community 'Set-community requested from the NMS. The default is 'public'. Enter the IP address of the NMS. The P-660H-Tx v2HW-DX will only Trusted respond to SNMP messages coming from this IP address. If 0.0.0.0 is Host entered, the P-660H-Tx v2HW-DX will respond to all NMS managers.
In a typical environment, a LAN router is required to connect two local networks. The P-660H-Tx v2 can connect three local networks to the ISP or a remote node, we call this function as 'IP Alias'. In this case, an internal router is not required.
Page 60
IP alias 1 and enif0:1 for the IP alias 2. Therefore, three routes are created in the P-660H-Tx v2 as shown below when the three networks are configured. If the P-660H-Tx v2's DHCP is also enabled, the IP pool for the clients can be any of the three networks.
Active it and enter the second LAN IP address for the P-660H-Tx v2. This IP Alias 1 will create the second route in the enif0:0 interface. Active it and enter the third LAN IP address for the P-660H-Tx v2. This will IP Alias 2 create the third route in the enif0:1 interface.
• What is Call Scheduling? Call scheduling enables the mechanism for the P-660H-Tx v2 to run the remote node connection according to the pre-defined schedule. This feature is just like the scheduler ina video recorder which records the program according to the specified time.
Time service is implemented by the Daytime protocol(RFC-867), Time protocol(RFC-868), and NTP protocol(RFC-1305). You have to assign an IP address of a time server and then, the P-660H-Tx v2 will get the date, time, and time-zone information from this server. You can configure it in Web Configurator, Advanced Setup, Maintenance ->...
At start up, the P-660H-Tx v2 queries all directly connected networks to gather group membership. After that, the P-660H-Tx v2 updates the information by periodic queries. The P-660H-Tx v2 implementation of IGMP is also compatible with version 1. The multicast setting can be turned on or off on Ethernet and remote nodes.
16. How to configure packet filter on P-660H-Tx v2? The P-660H-Tx v2 allows you to configure up to twelve filter sets with six rules in each set, for a total of 72 filter rules in the system. You can apply up to four filter sets to a particular port to block multiple types of packets.
Page 75
P-660H-Tx v2 Support Notes The packet filter function on P-660H-Tx v2 is the same as before, just that you could only configure the filter set and apply them by command in CLI. It’s very complex for common users to do it. So here’s the recommendation: (1) Usually if you want to block special packets, you could edit a firewall rule in Web Configurator.
Offline Trace--capture the trace first and display later The details for capturing the trace in CLI as follows: First of all, you need to telnet to the P-660H-Tx v2 firstly. The password is Administrator passwords, ‘admin’ by default. • Online Trace (1) Trace LAN packet •...
• Capture the detailed logs by Hyper Terminal Step 1: Initiate a hyper terminal connection from your PC(suppose you connected to the LAN port of P-660H-Tx v2) Step 2: Click the ‘properties’ to configure parameters to telnet to the P-660H-Tx v2.
Step 2: Type the CI command 'sys stdio 0' to disable console idle timeout in Command Line Interface (CLI). Step 3: Download ZyNOS via LAN : Step 4: Upload P-660H-Tx v2 configurations via LAN: [localfile] rom-0 Step 5: Download P-660H-Tx v2 configurations via LAN: rom-0 [localfile] •...