ZyXEL Communications FSG1100HN User Manual

Wireless active fiber router
Hide thumbs Also See for FSG1100HN:
Table of Contents

Advertisement

Quick Links

FSG1100HN

Wireless Active Fiber Router
IP Address
http://192.168.1.1
User Name
admin
Password
1234
Firmware Version: 1.0
Edition1, 3/2010
www.zyxel.com

Advertisement

Table of Contents
loading

Summary of Contents for ZyXEL Communications FSG1100HN

  • Page 1: Fsg1100Hn

    FSG1100HN Wireless Active Fiber Router IP Address http://192.168.1.1 User Name admin Password 1234 Firmware Version: 1.0 Edition1, 3/2010 www.zyxel.com...
  • Page 3: About This User's Guide

    User’s Guide PDF. Related Documentation • Quick Start Guide The Quick Start Guide is designed to help you get your FSG1100HN up and running right away. It contains information on setting up your network and configuring for Internet access.
  • Page 4 If you have a specific question about your product, the answer may be here. This is a collection of answers to previously asked questions about ZyXEL products. • Forum This contains discussions on ZyXEL products. Learn from others who use ZyXEL products and share your experiences as well.’ FSG1100HN User’s Guide...
  • Page 5 Should problems arise that cannot be solved by the methods listed above, you should contact your vendor. If you cannot contact your vendor, then contact a ZyXEL office for the region in which you bought the device. See http://www.zyxel.com/web/contact_us.php for contact information. Please have the following information ready when you contact an office.
  • Page 6: Document Conventions

    Syntax Conventions • The FSG1100HN may be referred to as the “FSG1100HN”, the “device”, the “product” or the “system” in this User’s Guide. • Product labels, screen names, field labels and field choices are all in bold font.
  • Page 7 Document Conventions Icons Used in Figures Figures in this User’s Guide may use the following generic icons. The ZyXEL icon is not an exact representation of your device. FSG1100HN User’s Guide...
  • Page 8: Safety Warnings

    Your product is marked with this symbol, which is known as the WEEE mark. WEEE stands for Waste Electronics and Electrical Equipment. It means that used electrical and electronic products should not be mixed with general waste. Used electrical and electronic equipment should be treated separately. FSG1100HN User’s Guide...
  • Page 9 SAFETY WARNINGS FSG1100HN User’s Guide...
  • Page 10: Table Of Contents

    Introduction ......................13 Overview ..............................15 Applications ............................... 15 Ways to Manage the FSG1100HN ....................16 Good Habits for Managing the FSG1100HN ................16 The WPS Button ............................. 19 LEDs................................16 Introducing the Web Configurator ....................... 21 Overview ..............................19 Overview ..............................
  • Page 11 Firewall ................................71 Security ........................69 What You Can Do ............................ 72 8.2.1 About the FSG1100HN Firewall....................72 What You Need To Know ........................72 Firewall Filter Screen ..........................73 Firewall Filter Add Screen ........................74 Firewall Denial of Service Screen ....................75 Firewall Content Filter Screen ......................
  • Page 13: Introduction

    Introduction Getting to Know Your FSG-100HN (15) The WPS Button (19) Introducing the Web Configurator (21) Setting the Device Mode (24) FSG1100HN User’s Guide...
  • Page 15: Getting To Know Your Fsg1100Hn

    You can create the following networks using the FSG1100HN: • Wired. You can connect network devices via the Ethernet ports of the FSG1100HN so that they can communicate with each other and access the Internet. • Wireless. Wireless clients can connect to the FSG1100HN to access network resources.
  • Page 16: Ways To Manage The Fsg1100Hn

    FSG1100HN using a (supported) web browser. Good Habits for Managing the FSG1100HN Do the following things regularly to make the FSG1100HN more secure and to manage the FSG1100HN more effectively. • Change the password. Use a password that’s not easy to guess and that consists of different types of characters, such as numbers and letters.
  • Page 17 LAN. Blinking The FSG1100HN is sending/receiving data through the wireless LAN. The FSG1100HN is negotiating a WPS connection with a wireless client. The FSG1100HN is not ready or has failed. Orange Blinking The FSG1100HN’s WPS connection is being configured. Internet Green The FSG1100HN’s IP is connected (the...
  • Page 18 Chapter 2 The WPS Button The FSG1100HN’s power is off, it is in bridged mode, or a connection not present. The FSG1100HN’s attempt to achieve an IP connection failed (no DHCP response, no PPPoE response, PPPoE authentication failed, no IP address from IPCP, etc.).
  • Page 19: The Wps Button

    Number that allows one device to authenticate the other) in each of the two devices. When WPS is activated on a device, it has two minutes to find another device that also has WPS activated. Then, the two devices connect and set up a secure network by themselves. FSG1100HN User’s Guide...
  • Page 21: Introducing The Web Configurator

    Internet Explorer. Accessing the Web Configurator 1. Make sure your FSG1100HN hardware is properly connected and prepare your computer or computer network to connect to the FSG1100HN (refer to the Quick Start Guide). 2. Launch your web browser.
  • Page 22: Procedure To Use The Reset Button

    1 Make sure the power LED is on. 2 Press the RESET button for longer than 1 second to restart/reboot the FSG1100HN. 3 Press the RESET button for longer than five seconds to set the FSG1100HN back to its factory-default configurations. FSG1100HN User’s Guide...
  • Page 23: Navigating The Web Configurator

    Firmware Version This is the firmware version. System Up Time This is the total time the FSG1100HN has been on. Current Date/Time This is the FSG1100HN’s present date and time. Device Mode This is the current FSG1100HN mode. The device can function as a Router, Bridge, or Mixed.
  • Page 24: Wlan Information: Multiple Ap Table

    SSID This is a descriptive name used to identify the FSG1100HN on the wireless LAN. Mode This is the level of wireless security the FSG1100HN is currently using. Band This is the manually selected operating frequency currently being used on the wireless LAN.
  • Page 25: Summary: Active Session Table

    The Active Session Table displays all current active sessions. Click System Information > Active Session to open the Active Session Table screen. System Information > Active Session The following table describes the active session labels in this screen. FSG1100HN User’s Guide...
  • Page 26: Setting The Device Mode

    LAN1-LAN4 Select LAN1 to LAN4 for router, bridge, or a mix of each. WLAN Select WLAN for router or bridge. Click Apply to save your changes back to the FSG1100HN. Apply Click Refresh to begin configuring this screen afresh. Refresh...
  • Page 28: Network

    Network Wireless LAN (30) WAN (48) LAN (56) Network Address Translation (NAT) (63) FSG1100HN User’s Guide...
  • Page 29 FSG1100HN User’s Guide...
  • Page 30: Wireless Lan

    Wireless LAN Overview This chapter discusses how to configure the wireless network settings in your FSG1100HN. See the appendices for more detailed information about wireless networks. The following figure provides an example of a wireless network. Example of a Wireless Network The wireless network is the part in the blue circle.
  • Page 31: What You Can Do

    • Every wireless client in the same wireless network must use security compatible with the AP. Security stops unauthorized devices from using the wireless network. It can also protect the information that is sent in the wireless network. FSG1100HN User’s Guide...
  • Page 32: Wireless Basic Settings Screen

    Enter a descriptive name for the Service Set Identity (SSID) associated with the wireless station. All wireless stations associating with the access point built-in to the FSG1100HN must have the same SSID. Select the channel width. Select 20MHz if no 802.11n wireless clients...
  • Page 33: Multiple Ap Table

    Refresh 4.4.1 Multiple AP Table The FSG1100HN allows up to four APs to be enabled and configured on the Multiple AP window. Click Wireless > Basic Settings > Multiple AP to open the Multiple AP screen. Wireless > Basic Settings > Multiple AP The following table describes the multiple AP labels in this screen.
  • Page 34: Active Wireless Client Table

    Auto. Broadcast SSID Enable or disable the broadcasting of the FSG1100HN’s SSID. If this is disabled, the SSID in the outgoing beacon frame will be hidden. This prevents a station from obtaining the SSID through scanning using a site survey tool.
  • Page 35: Wireless Advanced Settings Screen

    Type affects the timing in the wireless network. There are two preamble types: long and short. If a wireless device uses a different preamble type than the FSG1100HN, then it cannot communicate with the FSG1100HN. IAPP Enable or disable Inter-Access Point Protocol (IAPP). This protocol...
  • Page 36 Output Select the transmit power of the antennas. The default is 100%. Power Click Apply to save your changes back to the FSG1100HN. Apply Click Refresh to begin configuring this screen afresh. Refresh...
  • Page 37: Wep

    Both the wireless stations and the access points must use the same WEP key. The FSG1100HN allows configuration of up to four 64-bit or 128-bit WEP keys but only one key can be enabled at any one time.
  • Page 38 0 to 9 and the letters A to F. Encryption Keys are used to encrypt data. Both the FSG1100HN and the Key 1 wireless stations must use the same WEP key for data to 4 transmission.
  • Page 39: Wpa

    Wireless > Security > WPA Wireless Security Setup window for WPA (Personal (Pre-Shared Key)) Wireless Security Setup window for WPA (Enterprise (RADIUS)) The following table describes the wireless security for WPA labels in these screens. Wireless > Security > WPA FSG1100HN User’s Guide...
  • Page 40 1812 is the default port. RADIUS Enter the security key for the RADIUS server. Server Password Click Apply to save your changes back to the FSG1100HN. Apply Reset Click Reset to reset the settings on this screen. FSG1100HN User’s Guide...
  • Page 41: Wpa2

    Wireless > Security > WPA2 Wireless Security Setup window for WPA2 (Personal (Pre-Shared Key)) Wireless Security Setup window for WPA2 (Enterprise (RADIUS)) The following table describes the wireless security for WPA2 labels in these screens. Wireless > Security > WPA2 FSG1100HN User’s Guide...
  • Page 42: Wpa-Mixed

    Server Port is the default port. RADIUS Enter the security key for the RADIUS server. Server Password Click Apply to save your changes back to the FSG1100HN. Apply Click Reset to reset the settings on this screen. Reset 4.6.4 WPA-Mixed Click Wireless >...
  • Page 43 1812 is the default port. RADIUS Server Enter the security key for the RADIUS server. Password Click Apply to save your changes back to the FSG1100HN. Apply Reset Click Reset to reset the settings on this screen. FSG1100HN User’s Guide...
  • Page 44: Wireless Access Control Screen

    MAC Address Enter a MAC address. Comment Enter a user-specified comment to help identify this access control rule. Click Apply to save your changes back to the FSG1100HN. Apply Click Refresh to begin configuring this screen afresh. Refresh Delete Click button to delete the table entry.
  • Page 45 This displays No if WPS is disabled and there are no wireless or wireless security changes on the FSG1100HN or if the user clicks the Reset to Unconfigured button to remove the configured wireless and wireless security settings.
  • Page 46 Push Button Configuration (PBC) allows users to click the Configure via PBC button to set up WPS. Once the button is clicked on this window, users have 2 minutes to press a similar virtual or actual button on the new wireless client device. FSG1100HN User’s Guide...
  • Page 47 Chapter 4 Wireless LAN FSG1100HN User’s Guide...
  • Page 48: Overview

    Chapter 5 WAN Overview This chapter discusses the FSG1100HN’s WAN screens. Use these screens to configure your FSG1100HN for Internet access. A WAN (Wide Area Network) connection is an outside connection to another network or the Internet. It connects your private networks (such as a LAN (Local Area Network) and other networks, so that a computer in one location can communicate with computers in other locations.
  • Page 49: Wan For Dhcp Client Screen

    Dynamic Host Configuration Protocol (DHCP), based on RFC 2131 and RFC 2132, allows individual clients to obtain TCP/IP configuration at start-up from a server. Users can configure the FSG1100HN’s LAN as a DHCP server or disable it. When configured as a server, the FSG1100HN provides the TCP/IP configuration for the clients.
  • Page 50 Virtual Private Network (VPN). It relies on an encryption protocol that it passes within the tunnel to provide privacy. Apply Click Apply to save your changes back to the FSG1100HN. Refresh Click Refresh to begin configuring this screen afresh. FSG1100HN User’s Guide...
  • Page 51: Wan For Static Ip Screen

    WAN Access Type IP Address The WAN IP address is an IP address for the FSG1100HN, which makes it accessible from an outside network. It is used to communicate with other devices on other networks. If this static WAN IP address has been assigned by the ISP, it should also assign the subnet mask and DNS server IP address(es).
  • Page 52 Virtual Private Network (VPN). It relies on an encryption Connection protocol that it passes within the tunnel to provide privacy. Click Apply to save your changes back to the FSG1100HN. Apply Click Refresh to begin configuring this screen afresh.
  • Page 53: Wan For Pppoe Screen

    ISP to use their existing network configuration with newer broadband technologies such as ADSL. The PPPoE driver on the FSG1100HN is transparent to the computers on the LAN, which see only Ethernet and are not aware of PPPoE thus saving users the need to manage PPPoE clients on individual computers.
  • Page 54 - it is not used to carry user data. The FSG1100HN supports both IGMP version 1 and IGMP version 2. At start up, the FSG1100HN queries all directly connected networks to gather group membership. After that, it periodically updates this information.
  • Page 55 Chapter 5 WAN FSG1100HN User’s Guide...
  • Page 56: Overview

    LAN DHCP server, manage IP addresses, and partition your physical network into logical networks. LAN Setup What You Can Do • Use the LAN General screen (58) to change your basic LAN settings. • Use the VLAN screen (61) to configure VLAN settings. FSG1100HN User’s Guide...
  • Page 57: Ip Pool Setup

    WAN network as shown next. LAN and WAN IP Addresses The LAN parameters of the FSG1100HN are preset in the factory with the following values: • IP address of 192.168.1.254 with subnet mask of 255.255.255.0 (24 bits) •...
  • Page 58: Lan General Screen

    LABEL DESCRIPTION LAN Settings IP Address Enter the (LAN) IP address of the FSG1100HN in dotted decimal notation 192.168.1.254 (factory default). Subnet Mask The subnet mask specifies the network number portion of an IP address. The FSG1100HN will automatically calculate the subnet mask based on the IP address assigned by the user.
  • Page 59: Active Dhcp Client Table

    IP Alias Choose Enable to configure the LAN network for the FSG1100HN. IP Address Enter the IP address of the FSG1100HN in dotted decimal notation. Subnet Mask The FSG1100HN will automatically calculate the subnet mask based on the IP address assigned by the user.
  • Page 60: Static Dhcp

    6.4.2 Static DHCP The Static DHCP window allows users to set up static DHCP on the FSG1100HN. Select an index between 1 and 20, enter an IP address, a MAC Address, and an optional identifying comment. A Static DHCP List at the bottom of the window displays the current static DHCP entries.
  • Page 61: Vlan Screen

    Tick the Canonical Format Indicator (CFI). This is used to determine whether a network is Ethernet or Token Ring. Apply Click Apply to save your changes back to the FSG1100HN. Click Refresh to begin configuring this screen afresh. Refresh FSG1100HN User’s Guide...
  • Page 62 Chapter 6 LAN FSG1100HN User’s Guide...
  • Page 63: Nat

    • Use the NAT General screen (64) to enable NAT, NAT loopback, SIP ALG, and RTSP ALG. • Use the NAT DMZ screen (66) to change your FSG1100HN’s DMZ settings. • Use the NAT Port Forwarding screen (67) change your FSG1100HN’s port forwarding settings.
  • Page 64: Nat General Screen

    It replaces the original IP source address in each packet and then forwards it to the Internet. The FSG1100HN keeps track of the original addresses and port numbers so incoming reply packets can have their original values restored.
  • Page 65 Chapter 7 NAT Apply Click Apply to save your changes back to the FSG1100HN. Refresh Click Refresh to begin configuring this screen afresh. FSG1100HN User’s Guide...
  • Page 66: Nat Dmz Screen

    Active Enable of Disable DMZ. Host IP Address Enter an IP address that will be open to the Internet. Click Apply to save your changes back to the FSG1100HN. Apply Refresh Click Refresh to begin configuring this screen afresh. FSG1100HN User’s Guide...
  • Page 67: Nat Port Forwarding Screen

    Port Range above. Comment This is a user-selected name or other information about a specific port forwarding entry in the Forward Table. Click Apply to save your changes back to the FSG1100HN. Apply Refresh Click Refresh to begin configuring this screen afresh.
  • Page 68 Chapter 7 NAT FSG1100HN User’s Guide...
  • Page 69: Security

    Security Firewall (71) FSG1100HN User’s Guide...
  • Page 70 FSG1100HN User’s Guide...
  • Page 71: Firewall

    Overview Use these screens to enable and configure the firewall that protects your FSG1100HN and your LAN from unwanted or malicious traffic. Enable the firewall to protect your LAN computers from attacks by hackers on the Internet and control access between the LAN and WAN. By default the firewall: •...
  • Page 72: What You Can Do

    • Use the Firewall Filter screen (73) to enable or disable the FSG1100HN’s firewall. • Use the Firewall Filter Add screen (74) to add a filter to the FSG1100HN firewall. • Use the Firewall Denial of Service screen (75) to enable and configure Denial of Service Prevention.
  • Page 73: Firewall Filter Screen

    Chapter 8 Firewall Firewall Filter Screen The Filter window allows users to view existing filters on the FSG1100HN. To set up a new filter, click the Add button. Click Firewall > Filter to open the Filter screen. Firewall > Filter The following table describes the filter labels in this screen.
  • Page 74: Firewall Filter Add Screen

    -- IP Address/Subnet Mask Source Enter the range of ports to be filtered between 1 and 65535. -- Port Range Destination Enter the destination IP address and subnet mask of the device to be filtered. -- IP Address/Subnet Mask FSG1100HN User’s Guide...
  • Page 75: Firewall Denial Of Service Screen

    Click Firewall > Denial of Service to open the Denial of Service screen. Firewall > Denial of Service The following table describes the denial of service labels in this screen. Firewall > Denial of Service LABEL DESCRIPTION Denial of Service Enable DoS Enable Denial of Service Prevention. Prevention FSG1100HN User’s Guide...
  • Page 76 Click to select all of the DoS types on this screen. Clear All Click to deselect all the DoS types ticked on this screen. Click Apply to save your changes back to the FSG1100HN. Apply Click Refresh to begin configuring this screen afresh.
  • Page 77: Firewall Content Filter Screen

    URL www.zyxel.com.tw/news/pressroom.php, the file path news/pressroom.php Since the FSG1100HN checks the URL’s domain name (or IP address) and file path separately, it will not find items that go across the two. For example, with the URL www.zyxel.com.tw/news/pressroom.php, the FSG1100HN would find “tw” in the domain name (www.zyxel.com.tw).
  • Page 78 Index An index number for the Keyword List Table entry (row). Active This column indicates if this entry is active or not. Keyword The keyword for this table entry. Delete Click button to delete the table entry. FSG1100HN User’s Guide...
  • Page 79 Chapter 8 Firewall FSG1100HN User’s Guide...
  • Page 80: Management

    Management Bandwidth Maintenance (82) TR-069 (85) Auto Provision (88) FSG1100HN User’s Guide...
  • Page 81 FSG1100HN User’s Guide...
  • Page 82: Media Bandwidth Management

    Manual Uplink Speed Enter the uplink speed in Kbps. Automatic Downlink Enable or Disable automatic downlink speed. Speed Manual Downlink Speed Enter the downlink speed in Kbps. Media Bandwidth Management Rules Address Type Choose IP or MAC. FSG1100HN User’s Guide...
  • Page 83 Enter the downlink bandwidth in Kbps. Comment This is a user-selected name or other information about this rule. Click Add to add the settings configured in the current session back to the FSG1100HN. Refresh Click Refresh to begin configuring this screen afresh. Index index...
  • Page 84 Chapter 9 Media Bandwidth Management FSG1100HN User’s Guide...
  • Page 85: General Screen

    Enter a user name. Password Enter a password. Action Enable or Disable auto execution. If enabled, when Auto Execution the device reboots, TR-069 will be automatically enabled. Apply Click Apply to save your changes back to the FSG1100HN. FSG1100HN User’s Guide...
  • Page 86 Chapter 10 TR-069 Refresh Click Refresh to begin configuring this screen afresh. FSG1100HN User’s Guide...
  • Page 87 Chapter 10 TR-069 FSG1100HN User’s Guide...
  • Page 88: Auto Provision

    Select the number of retry attempts allowed. The range is from 0 to 5 Time attempts. Timeout Enter an age-out value, in seconds, between 30 and 604800. Delay Enter a delay time, in seconds, between 30 and 604800. Time Apply Click Apply to save your changes back to the FSG1100HN. FSG1100HN User’s Guide...
  • Page 89 Chapter 11 Auto Provision Refresh Click Refresh to begin configuring this screen afresh. FSG1100HN User’s Guide...
  • Page 90 Chapter 11 Auto Provision FSG1100HN User’s Guide...
  • Page 91: Maintenance And Troubleshooting

    Maintenance Troubleshooting System Settings (93) Log (98) Tools (100) FSG1100HN User’s Guide...
  • Page 92 FSG1100HN User’s Guide...
  • Page 93: System Settings

    12.1 System Settings General Screen The System Settings screen’s General tab allows users to enter a name to identify the FSG1100HN on the network, configure the administrator inactivity timer, and set the system password. Click Maintenance > System Settings > General to open the System Settings General screen.
  • Page 94: 12.2 System Settings Dynamic Dns Screen

    Retype to Type the new password again in this field. Confirm Apply Click Apply to save your changes back to the FSG1100HN. Click Refresh to begin configuring this screen afresh. Refresh 12.2 System Settings Dynamic DNS Screen Dynamic Domain Name System (DDNS) allows the use of a domain name with a dynamic IP address.
  • Page 95: 12.3 System Settings Time Screen

    12.3 System Settings Time Screen The System Settings’ Time tab allows time, date, and time zone configuration, including use of an NTP Server and setting up DST on the FSG1100HN. Click Maintenance > System Settings > Time to open the System Settings Time screen.
  • Page 96 Germany for instance, you would type 2 because Germany's time zone is one hour ahead of GMT or UTC (GMT+1). Apply Click Apply to save your changes back to the FSG1100HN. Click Refresh to begin configuring this screen afresh. Refresh...
  • Page 97 Chapter 12 System Settings FSG1100HN User’s Guide...
  • Page 98: Log

    Enter a valid IP address in the field provided and tick the Address Enable Remote Log check box to use the remote log feature. Apply Click Apply to save your changes back to the FSG1100HN. Click Refresh to renew the log screen. Refresh Click Clear to delete all the logs.
  • Page 99 Chapter 13 Log FSG1100HN User’s Guide...
  • Page 100: Tools

    Upload Click to restore the selected configuration file. 14.2 Tools Configuration Screen This tab allows users to backup configuration, restore configuration, and restore factory default configuration. Click Maintenance > Tools > Configuration to open the Configuration screen. FSG1100HN User’s Guide...
  • Page 101: 14.3 Tools Restart Screen

    DESCRIPTION Backup Configuration - Allows you to back up (save) the FSG1100HN’s current configuration to a file on your computer. Once your FSG1100HN is configured and functioning properly, it is highly recommended that you back up your configuration file before making configuration changes. The backup configuration file will be useful in case you need to return to your previous settings.
  • Page 102 Click Restart to reboot the FSG1100HN. The following table describes the tools restart label in this screen. Maintenance > Tools > Restart LABEL DESCRIPTION Restart Restart Click to have the FSG1100HN reboot. This does not effect the FSG1100HN’s configuration. FSG1100HN User’s Guide...
  • Page 103 Chapter 14 Tools FSG1100HN User’s Guide...
  • Page 104: Appendices

    Appendices Pop-up Windows, JavaScripts and Java Permissions (106) IP Addresses and Subnetting (114) Setting up Your Computer’s IP Address (124) Wireless LANs (142) Services (154) Legal Information (158) FSG1100HN User’s Guide...
  • Page 105 FSG1100HN User’s Guide...
  • Page 106: Pop-Up Windows, Javascripts And Java Permissions

    Disable pop-up Blockers 1 In Internet Explorer, select Tools, Pop-up Blocker and then select Turn Off Pop-up Blocker. Pop-up Blocker You can also check if pop-up blocking is disabled in the Pop-up Blocker section in the Privacy tab. FSG1100HN User’s Guide...
  • Page 107 4 Click Apply to save this setting. Enable pop-up Blockers with Exceptions Alternatively, if you only want to allow pop-up windows from your device, see the following steps. 1 In Internet Explorer, select Tools, Internet Options and then the Privacy tab. FSG1100HN User’s Guide...
  • Page 108 2 Select Settings…to open the Pop-up Blocker Settings screen. Internet Options: Privacy 3 Type the IP address of your device (the web page that you do not want to have blocked) with the prefix “http://”. For example, http://192.168.167.1. FSG1100HN User’s Guide...
  • Page 109 Pop-up Blocker Settings 5 Click Close to return to the Privacy screen. 6 Click Apply to save this setting. JavaScripts If pages of the Web Configurator do not display properly in Internet Explorer, check that JavaScripts are allowed. FSG1100HN User’s Guide...
  • Page 110 2 Click the Custom Level... button. 3 Scroll down to Scripting. 4 Under Active scripting make sure that Enable is selected (the default). 5 Under Scripting of Java applets make sure that Enable is selected (the default). FSG1100HN User’s Guide...
  • Page 111: Java Permissions

    1 From Internet Explorer, click Tools, Internet Options and then the Security tab. 2 Click the Custom Level... button. 3 Scroll down to Microsoft VM. 4 Under Java permissions make sure that a safety level is selected. FSG1100HN User’s Guide...
  • Page 112 5 Click OK to close the window. Security Settings – Java JAVA (Sun) 1 From Internet Explorer, click Tools, Internet Options and then the Advanced tab. 2 Make sure that Use Java 2 for <applet> under Java (Sun) is selected. FSG1100HN User’s Guide...
  • Page 113 Appendix A Pop-up Windows, JavaScripts, and Java Permissions 3 Click OK to close the window. Java (Sun) FSG1100HN User’s Guide...
  • Page 114: Ip Addresses And Subnetting

    192.168.1.1). Each of these four parts is known as an octet. An octet is an eight-digit binary number (for example 11000000, which is 192 in decimal notation). Therefore, each octet has a possible range of 00000000 to 11111111 in binary, or 0 to 255 in decimal. FSG1100HN User’s Guide...
  • Page 115: Subnet Masks

    ID of an IP address (192.168.1.2 in decimal). Subnet Mask - Identifying Network Number OCTET: OCTET: OCTET: OCTET: (192) (168) IP Address (Binary) 11000000 10101000 00000001 00000010 Subnet Mask (Binary) 11111111 11111111 11111111 00000000 FSG1100HN User’s Guide...
  • Page 116 An IP address with host IDs of all zeros is the IP address of the network (192.168.1.0 with a 24-bit subnet mask, for example). An IP address with host IDs of all ones is the broadcast address for that network (192.168.1.255 with a 24-bit subnet mask, for example). FSG1100HN User’s Guide...
  • Page 117 The following table shows some possible subnet masks using both notations. Alternative Subnet Mask Notation SUBNET MASK ALTERNATIVE LAST OCTET LAST OCTET NOTATION (BINARY) (DECIMAL) 255.255.255.0 0000 0000 255.255.255.128 1000 0000 255.255.255.192 1100 0000 255.255.255.224 1110 0000 255.255.255.240 1111 0000 255.255.255.248 1111 1000 255.255.255.252 1111 1100 FSG1100HN User’s Guide...
  • Page 118 You can “borrow” one of the host ID bits to divide the network 192.168.1.0 into two separate sub-networks. The subnet mask is now 25 bits (255.255.255.128 or /25). The “borrowed” host ID bit can have a value of either 0 or 1, allowing two subnets; 192.168.1.0 /25 and 192.168.1.128 /25. FSG1100HN User’s Guide...
  • Page 119 Similarly, to divide a 24-bit address into four subnets, you need to “borrow” two host ID bits to give four possible combinations (00, 01, 10 and 11). The subnet mask is 26 bits (11111111.11111111.11111111.11000000) or 255.255.255.192. FSG1100HN User’s Guide...
  • Page 120 Subnet 4 IP/SUBNET MASK NETWORK NUMBER LAST OCTET BIT VALUE IP Address) 192.168.1. IP Address (Binary) 11000000.10101000.00000001. 11000000 Subnet Mask (Binary) 11111111.11111111.11111111. 11000000 Subnet Address: Lowest Host ID: 192.168.1.193 192.168.1.192 Broadcast Address: Highest Host ID: 192.168.1.254 192.168.1.255 FSG1100HN User’s Guide...
  • Page 121 The following table is a summary for subnet planning on a network with a 24-bit network number. 24-bit Network Number Subnet Planning NO. “BORROWED” SUBNET MASK NO. SUBNETS NO. HOSTS HOST BITS PER SUBNET 255.255.255.128 (/25) 255.255.255.128 (/26) 255.255.255.128 (/27) 255.255.255.128 (/28) 255.255.255.128 (/29) 255.255.255.128 (/30) 255.255.255.128 (/31) FSG1100HN User’s Guide...
  • Page 122 FSG1100HN. Once you have decided on the network number, pick an IP address for your FSG1100HN that is easy to remember (for instance, 192.168.1.254) but make sure that no other device on your network is using that IP address. The subnet mask specifies the network number portion of an IP address. Your FSG1100HN will compute the subnet mask automatically based on the IP FSG1100HN User’s Guide...
  • Page 123: Private Ip Addresses

    Appendix B IP Addresses and Subnetting address that you entered. You don't need to change the subnet mask computed by the FSG1100HN unless you are instructed to do otherwise. Private IP Addresses Every machine on the Internet must have a unique address. If your networks are isolated from the Internet (running only between two branch offices, for example) you can assign any IP addresses to the hosts without problems.
  • Page 124: Setting Up Your Computer's Ip Address

    "communicate" with your network. If you manually assign IP information instead of using dynamic assignment, make sure that your computers have IP addresses that place them in the same subnet as the FSG1100HN’s LAN port. FSG1100HN User’s Guide...
  • Page 125 2 Select Adapter and then click Add. 3 Select the manufacturer and model of your network adapter and then click OK. If you need TCP/IP: 1 In the Network window, click Add. 2 Select Protocol and then click Add. FSG1100HN User’s Guide...
  • Page 126 • If your IP address is dynamic, select Obtain an IP address automatically. • If you have a static IP address, select Specify an IP address and type your information into the IP Address and Subnet Mask fields. Windows 95/98/Me: TCP/IP Properties: IP Address FSG1100HN User’s Guide...
  • Page 127: Verifying Settings

    6 Click OK to close the Network window. Insert the Windows CD if prompted. 7 Turn on your Prestige and restart your computer when prompted. Verifying Settings 1 Click Start and then Run. 2 In the Run window, type "winipcfg" and then click OK to open the IP Configuration window. FSG1100HN User’s Guide...
  • Page 128 3 Select your network adapter. You should see your computer's IP address, subnet mask and default gateway. Windows 2000/NT/XP The following example figures use the default Windows XP GUI theme. 1 Click start (Start in Windows 2000/NT), Settings, Control Panel. Windows XP: Start Menu FSG1100HN User’s Guide...
  • Page 129 Appendix C Setting up Your Computer’s IP Address 2 In the Control Panel, double-click Network Connections (Network and Dialup Connections in Windows 2000/NT). Windows XP: Control Panel 3 Right-click Local Area Connection and then click Properties. Windows XP: Control Panel: Network Connections: Properties FSG1100HN User’s Guide...
  • Page 130 • If you have a dynamic IP address click Obtain an IP address automatically. • If you have a static IP address click Use the following IP Address and fill in the IP address, Subnet mask, and Default gateway fields. • Click Advanced. FSG1100HN User’s Guide...
  • Page 131 Gateway. To manually configure a default metric (the number of transmission hops), clear the Automatic metric check box and type a metric in Metric. • Click Add. • Repeat the previous three steps for each default gateway you want to add. FSG1100HN User’s Guide...
  • Page 132 • Click Obtain DNS server address automatically if you do not know your DNS server IP address(es). • If you know your DNS server IP address(es), click Use the following DNS server addresses, and type them in the Preferred DNS server and Alternate DNS server fields. FSG1100HN User’s Guide...
  • Page 133 1 Click Start, All Programs, Accessories and then Command Prompt. 2 In the Command Prompt window, type "ipconfig" and then press [ENTER]. You can also open Network Connections, right-click a network connection, click Status and then click the Support tab. FSG1100HN User’s Guide...
  • Page 134 Appendix C Setting up Your Computer’s IP Address Macintosh OS 8/9 1 Click the Apple menu, Control Panel and double-click TCP/IP to open the TCP/IP Control Panel. Macintosh OS 8/9: Apple Menu FSG1100HN User’s Guide...
  • Page 135 5 Close the TCP/IP Control Panel. 6 Click Save if prompted, to save changes to your configuration. 7 Turn on your Prestige and restart your computer (if prompted). Verifying Settings Check your TCP/IP properties in the TCP/IP Control Panel window. FSG1100HN User’s Guide...
  • Page 136: Macintosh Os X

    2 Click Network in the icon bar. • Select Automatic from the Location list. • Select Built-in Ethernet from the Show list. • Click the TCP/IP tab. 3 For dynamically assigned settings, select Using DHCP from the Configure list. Macintosh OS X: Network FSG1100HN User’s Guide...
  • Page 137 Follow the steps below to configure your computer IP address using the KDE. 1 Click the Red Hat button (located on the bottom left corner), select System Setting and click Network. Red Hat 9.0: KDE: Network Configuration: Devices FSG1100HN User’s Guide...
  • Page 138 3 Click OK to save the changes and close the Ethernet Device General screen. 4 If you know your DNS server IP address(es), click the DNS tab in the Network Configuration screen. Enter the DNS server information in the fields provided. Red Hat 9.0: KDE: Network Configuration: DNS FSG1100HN User’s Guide...
  • Page 139 Open the configuration file with any plain text editor. • If you have a dynamic IP address, enter dhcp in the = field. BOOTPROTO The following figure shows an example. Red Hat 9.0: Dynamic IP Address Setting in ifconfig-eth0 DEVICE=eth0 ONBOOT=yes BOOTPROTO=dhcp USERCTL=no PEERDNS=yes TYPE=Ethernet FSG1100HN User’s Guide...
  • Page 140 Red Hat 9.0: Restart Ethernet Card [root@localhost init.d]# network restart Shutting down interface eth0: [OK] Shutting down loopback interface: [OK] Setting network parameters: [OK] Bringing up loopback interface: [OK] Bringing up interface eth0: [OK] FSG1100HN User’s Guide...
  • Page 141 Link encap:Ethernet HWaddr 00:50:BA:72:5B:44 inet addr:172.23.19.129 Bcast:172.23.19.255 Mask:255.255.255.0 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:717 errors:0 dropped:0 overruns:0 frame:0 TX packets:13 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:100 RX bytes:730412 (713.2 Kb) TX bytes:1570 (1.5 Kb) Interrupt:10 Base address:0x1000 [root@localhost]# FSG1100HN User’s Guide...
  • Page 142: Wireless Lans

    (AP). Intra-BSS traffic is traffic between wireless stations in the BSS. When Intra- BSS is enabled, wireless station A and B can access the wired network and FSG1100HN User’s Guide...
  • Page 143 This wired connection between APs is called a Distribution System (DS). This type of wireless LAN topology is called an Infrastructure WLAN. The Access Points not only provide communication with the wired network but also mediate wireless network traffic in the immediate neighborhood. FSG1100HN User’s Guide...
  • Page 144 A hidden node occurs when two stations are within range of the same access point, but are not within range of each other. The following figure illustrates a hidden node. Both stations (STA) are within range of the access point (AP) or FSG1100HN User’s Guide...
  • Page 145 (see next), then the RTS (Request To Send)/CTS (Clear to Send) handshake will never occur as data frames will be fragmented before they reach RTS/CTS size. Note: Enabling the RTS Threshold causes redundant network overhead that could negatively affect the throughput performance instead of providing a remedy. FSG1100HN User’s Guide...
  • Page 146: Fragmentation Threshold

    IEEE 802.11g is fully compatible with the IEEE 802.11b standard. This means an IEEE 802.11b adapter can interface directly with an IEEE 802.11g access point (and vice versa) at 11 Mbps or lower depending on range. IEEE 802.11g FSG1100HN User’s Guide...
  • Page 147 • Accounting Keeps track of the client’s network activity. RADIUS is a simple package exchange in which your AP acts as a message relay between the wireless station and the network RADIUS server. FSG1100HN User’s Guide...
  • Page 148: Types Of Radius Messages

    The wireless station ‘proves’ that it knows the password by encrypting the password with the challenge and sends back the information. Password is not sent in plain text. FSG1100HN User’s Guide...
  • Page 149: Dynamic Wep Key Exchange

    The AP maps a unique key that is generated with the RADIUS server. This key expires when the wireless connection times out, disconnects or reauthentication times out. A new WEP key is generated each time reauthentication is performed. FSG1100HN User’s Guide...
  • Page 150 Temporal Key Integrity Protocol (TKIP) uses 128-bit keys that are dynamically generated and distributed by the authentication server. It includes a per-packet key mixing function, a Message Integrity Check (MIC) named Michael, an extended initialization vector (IV) with sequencing rules, and a re-keying mechanism. FSG1100HN User’s Guide...
  • Page 151: User Authentication

    If the AP or the wireless clients do not support WPA2, just use WPA or WPA- PSK depending on whether you have an external RADIUS server or not. Select WEP only when the AP and/or wireless clients do not support WPA or WPA2. WEP is less secure than WPA or WPA2. FSG1100HN User’s Guide...
  • Page 152: Wpa With Radius Application Example

    AP and the wireless clients. FSG1100HN User’s Guide...
  • Page 153: Security Parameters Summary

    Enable without Dynamic WEP Key Open Enable with Dynamic WEP Key Enable without Dynamic WEP Key Disable Shared Enable with Dynamic WEP Key Enable without Dynamic WEP Key Disable TKIP Enable WPA-PSK TKIP Enable WPA2 Enable WPA2-PSK Enable FSG1100HN User’s Guide...
  • Page 154: Services

    A popular videoconferencing solution from White Pines Software. TCP/UDP 24032 TCP/UDP Domain Name Server, a service that matches web names (e.g. www.zyxel.com) to IP numbers. User-Defined The IPSEC ESP (Encapsulation Security Protocol) tunneling protocol (IPSEC_TUNNEL) uses this service. FINGER Finger is a UNIX or Internet related command that can be used to find out if a user is logged on.
  • Page 155 Network News Transport Protocol is the delivery mechanism for the USENET newsgroup service. PING User-Defined Packet Internet Groper is a protocol that sends out ICMP echo requests to test whether or not a remote host is reachable. FSG1100HN User’s Guide...
  • Page 156 SNMP-TRAPS TCP/UDP Traps for use with the SNMP (RFC: 1215). SQL-NET 1521 Structured Query Language is an interface to access data on many different types of database systems, including mainframes, midrange systems, UNIX systems, and network servers. FSG1100HN User’s Guide...
  • Page 157 Trivial File Transfer Protocol is an Internet file transfer protocol similar to FTP, but uses the UDP (User Datagram Protocol) rather than TCP (Transmission Control Protocol). VDOLIVE 7000 A videoconferencing solution. The UDP port number is specified in the application. User-Defined FSG1100HN User’s Guide...
  • Page 158: Legal Information

    Published by ZyXEL Communications Corporation. All rights reserved. Disclaimer ZyXEL does not assume any liability arising out of the application or use of any products, or software described herein. Neither does it convey any license under its patent rights nor the patent rights of others. ZyXEL further reserves the right to make changes in any products described herein without notice.
  • Page 159: Zyxel Limited Warranty

    EC region and Switzerland, with restrictions in France. Viewing Certifications 1 Go to http://www.zyxel.com. 2 Select your product on the ZyXEL home page to go to that product's page. 3 Select the certification you wish to view from this page. ZyXEL Limited Warranty...
  • Page 160 Software as long as this License Agreement remains in full force and effect. Ownership of the Software, Documentation and all intellectual property rights therein shall remain at all times with ZyXEL. Any other use of the Software by any other entity is strictly forbidden and is a violation of this License Agreement.
  • Page 161 Appendix E Services any proprietary notice of ZyXEL or any of its licensors from any copy of the Software or Documentation. 4. Restrictions You may not publish, display, disclose, sell, rent, lease, modify, store, loan, distribute, or create derivative works of the Software, or any part thereof. You may not assign, sublicense, convey or otherwise transfer, pledge as security or otherwise encumber the rights and licenses granted hereunder with respect to the Software.
  • Page 162 Appendix E Services DAYS FROM THE DATE OF PURCHASE OF THE SOFTWARE, AND NO WARRANTIES SHALL APPLY AFTER THAT PERIOD. 7. Limitation of Liability IN NO EVENT WILL ZyXEL BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY INCIDENTAL CONSEQUENTIAL DAMAGES...
  • Page 163 Appendix E Services NOTE: Some components of this product incorporate source code covered under the open source code licenses. To obtain the source code covered under those Licenses, please check ZyXEL Technical Support (support@zyxel.com.tw) to get it. FSG1100HN User’s Guide...
  • Page 164 2.12.1 http://dnrd.sourceforge.net/ Goahead 2.1.1 http://www.goahead.com Web Server igmpproxy http://igmpproxy.sourceforge.net/ iproute2 2.6.19 http://linux-net.osdl.org/index.php/Iproute2 iptables 1.3.8 http://www.netfilter.org ntpclient 2000_34 http://doolittle.icarus.com/ntpclient/ pppd 2.4.2 http://ppp.samba.org/ pptp 1.3.1 http://pptpclient.sourceforge.net/ tftpd 0.42 ftp://ftp.kernel.org/pub/software/network/tftp/ udhcpd 0.9.9 http://freshmeat.net/projects/udhcp/ updatedd http://freshmeat.net/projects/updatedd/ iwpriv wireless_ http://www.hpl.hp.com/personal/Jean_Tourrilhes/ tools.25 Linux/Tools.html FSG1100HN User’s Guide...
  • Page 165 No part may be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, except the express written permission of ZyXEL Communications Corporation. This Product includes MIPS Linux Kernel 2.6.20, bridge-utils 0.9.5, busybox 1.8.2, Dnrd 2.12.1, iproute2 2.6.19, iptables 1.3.8, ntpclient 2000_345, pptp1.3.1, iwpriv...
  • Page 166 Subsection b above.) The source code for a work means the preferred form of the work for making FSG1100HN User’s Guide...
  • Page 167 9. The Free Software Foundation may publish revised and/or new versions of the General Public License from time to time. Such new versions will be similar in spirit to the present version, but may differ in detail to address new problems or concerns. FSG1100HN User’s Guide...
  • Page 168 Please see the INSTALL and INSTALL.tftp files for compilation and installation instructions. ===> IMPORTANT: IF YOU ARE UPGRADING FROM ANOTHER TFTP SERVER, OR FROM ===> A VERSION OF TFTP-HPA OLDER THAN 0.17 SEE THE FILE ===> "README.security" FOR IMPORTANT SECURITY MODEL CHANGES! FSG1100HN User’s Guide...
  • Page 169 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY FSG1100HN User’s Guide...
  • Page 170 .\" ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE .\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL .\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS .\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) FSG1100HN User’s Guide...
  • Page 171 *The Regents of the University of California. All rights reserved. * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * 1. Redistributions of source code must retain the above copyright FSG1100HN User’s Guide...
  • Page 172 *This product includes software developed by the University of *California, Berkeley and its contributors. * 4. Neither the name of the University nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. FSG1100HN User’s Guide...
  • Page 173 .\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE .\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE .\" ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE .\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL FSG1100HN User’s Guide...
  • Page 174 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF * SUCH DAMAGE. FSG1100HN User’s Guide...
  • Page 175 *The Regents of the University of California. All rights reserved. * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * 1. Redistributions of source code must retain the above copyright FSG1100HN User’s Guide...
  • Page 176 Point-to-Point Protocol (PPP) to provide Internet connections over serial lines. Copyrights: *********** All of the code can be freely used and redistributed. The individual source files each have their own copyright and permission notice. FSG1100HN User’s Guide...
  • Page 177 4. Redistributions of any form whatsoever must retain the following acknowledgments: "This product includes software developed by Computing Services at Carnegie Mellon University (http://www.cmu.edu/computing/)." "This product includes software developed by Paul Mackerras <paulus@samba.org>". "This product includes software developed by Pedro Roque Marques <pedro_m@yahoo.com>". FSG1100HN User’s Guide...
  • Page 178 3.9-beta3 - COPYRIGHT 1989 by The Board of Trustees of Leland Stanford Junior University. - Original license can be found in the Stanford.txt file. This Product includes Goahead Web Server 2.1.1 software under below license. License Agreement FSG1100HN User’s Guide...
  • Page 179 You hereby grant in both source code and binary code to GoAhead a world-wide, royalty-free, non-exclusive license to copy, modify, display, use and sublicense any Modifications You make that are distributed or planned for distribution. Within 30 FSG1100HN User’s Guide...
  • Page 180 Original Code by displaying the GoAhead WebServer mark in marketing and promotional materials such as the home page of your web site or web pages promoting the product. 4.3 Placement of Copyright Notice by You. FSG1100HN User’s Guide...
  • Page 181 DAMAGES RESULTING FROM THE USE OF THE ORIGINAL CODE, THE INABILITY TO USE THE ORIGINAL CODE, OR ANY DEFECT IN THE ORIGINAL CODE, INCLUDING ANY LOST PROFITS, EVEN IF THEY HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. FSG1100HN User’s Guide...
  • Page 182 Washington, without regard to its rules governing the conflict of laws. If any provision of this Agreement is held illegal or unenforceable by a court or tribunal of competent jurisdiction, the remaining provisions of this Agreement shall remain in effect and the FSG1100HN User’s Guide...
  • Page 183 SET FORTH IN THIS AGREEMENT. IF YOU DO NOT WISH TO ACCEPT THIS LICENSE OR YOU DO NOT QUALIFY FOR A LICENSE BASED ON THE TERMS SET FORTH ABOVE, YOU MUST NOT CLICK THE "Register" BUTTON. Exhibit A GoAhead Trademarks, Logos, and Product Designation Information 01/28/00 FSG1100HN User’s Guide...

Table of Contents