Draytek Vigor2920 Series User Manual

Draytek Vigor2920 Series User Manual

Dual-wan security router
Hide thumbs Also See for Vigor2920 Series:
Table of Contents

Advertisement

Advertisement

Table of Contents
loading

Summary of Contents for Draytek Vigor2920 Series

  • Page 2 Vigor2920 Series Dual-WAN Security Router User’s Guide Version: 2.1 Firmware Version: V3.3.7 Date: 31/10/2011 Vigor2920 Series User’s Guide...
  • Page 3: Copyright Information

    Web registration is preferred. You can register your Vigor router via Be a Registered http://www.DrayTek.com. Owner Due to the continuous evolution of DrayTek technology, all routers will be regularly Firmware & Tools upgraded. Please consult the DrayTek web site for more information on newest Updates firmware, tools and documents.
  • Page 4: European Community Declarations

    Product: Vigor2920 Series Router DrayTek Corp. declares that Vigor2920 Series of routers are in compliance with the following essential requirements and other relevant provisions of R&TTE Directive 1999/5/EEC. The product conforms to the requirements of Electro-Magnetic Compatibility (EMC) Directive 2004/108/EC by complying with the requirements set forth in EN55022/Class B and EN55024/Class B.
  • Page 5: Table Of Contents

    Tutorials and Applications .................33 3.1 How to configure Multi-Subnet for Vigor Router ..............33 3.2 How to use SmartMonitor with Vigor2920 series ..............40 3.3 Create a LAN-to-LAN Connection Between Remote Office and Headquarter ..... 41 3.4 Create a Remote Dial-in User Connection Between the Teleworker and Headquarter..49 3.5 QoS Setting Example......................
  • Page 6 4.7.2 URL Content Filter Profile..................... 155 4.7.3 Web Content Filter Profile..................... 160 4.8 Bandwidth Management ..................... 163 4.8.1 Sessions Limit....................... 163 4.8.2 Bandwidth Limit ......................165 4.8.3 Quality of Service......................167 4.9 Applications ......................... 174 4.9.1 Dynamic DNS ....................... 174 Vigor2920 Series User’s Guide...
  • Page 7 4.15.4 Administrator Password....................278 4.15.5 User Password ......................279 4.15.6 Configuration Backup ....................281 4.15.7 Syslog/Mail Alert ......................283 4.15.8 Time and Date ......................285 4.15.9 Management....................... 286 4.15.10 Reboot System ......................287 4.15.11 Firmware Upgrade ....................289 Vigor2920 Series User’s Guide...
  • Page 8 5.4 Checking If the ISP Settings are OK or Not ................ 307 5.5 Problems for 3G Network Connection ................307 5.6 Backing to Factory Default Setting If Necessary ..............308 5.7 Contacting Your Dealer ....................... 309 viii Vigor2920 Series User’s Guide...
  • Page 9: Preface

    Vigor2920 series is a broadband router. It integrates IP layer QoS, NAT session/bandwidth management to help users control works well with large bandwidth. By adopting hardware-based VPN platform and hardware encryption of AES/DES/3DS, the router increases the performance of VPN greatly, and offers several protocols (such as IPSec/PPTP/L2TP) with up to 2 VPN tunnels.
  • Page 10: Led Indicators And Connectors

    The port is connected. GigaLAN (Green) The port is disconnected. 1/2/3/4 Blinking The data is transmitting. Right LED The port is connected with 1000Mbps. (Green) The port is connected with 10/100Mbps when left LED is on. Vigor2920 Series User’s Guide...
  • Page 11 Then the router will restart with the factory default configuration. GigaLAN (1-4) Connecters for local networked devices. WAN1/WAN2(Giga) Connecters for remote networked devices. Connecter for 3G Modem or printer. Connecter for a power adapter. Power Switch. ON/OFF Vigor2920 Series User’s Guide...
  • Page 12: For Vigor2920N

    The port is connected. GigaLAN (Green) The port is disconnected. 1/2/3/4 Blinking The data is transmitting. Right LED The port is connected with 1000Mbps. (Green) The port is connected with 10/100Mbps when left LED is on. Vigor2920 Series User’s Guide...
  • Page 13 Then the router will restart with the factory default configuration. GigaLAN (1-4) Connecters for local networked devices. WAN1/WAN2(Giga) Connecters for remote networked devices. Connecter for 3G Modem or printer. Connecter for a power adapter. Power Switch. ON/OFF Vigor2920 Series User’s Guide...
  • Page 14: For Vigor2920Vn

    The port is connected. GigaLAN (Green) The port is disconnected. 1/2/3/4 Blinking The data is transmitting. Right LED The port is connected with 1000Mbps. (Green) The port is connected with 10/100Mbps when left LED is on. Vigor2920 Series User’s Guide...
  • Page 15 Connecter for analog phone(s). Line Connector for PSTN life line. GigaLAN (1-4) Connecters for local networked devices. WAN1/WAN2(Giga) Connecters for remote networked devices. Connecter for Mobile HDD, 3G Modem or printer. Connecter for a power adapter. Power Switch. ON/OFF Vigor2920 Series User’s Guide...
  • Page 16: Hardware Installation

    Power on the device by pressing down the power switch on the rear panel. The system starts to initiate. After completing the system test, the ACT LED will light up and start blinking. (For the detailed information of LED status, please refer to section 1.1.) Vigor2920 Series User’s Guide...
  • Page 17: Printer Installation

    You can install a printer onto the router for sharing printing. All the PCs connected this router can print documents via the router. The example provided here is made based on Windows XP/2000. For Windows 98/SE/Vista, please visit www.DrayTek.com. Before using it, please follow the steps below to configure settings for connected computers (or wireless clients).
  • Page 18 Click Local printer attached to this computer and click Next. In this dialog, choose Create a new port Type of port and use the drop down list to select Standard TCP/IP Port. Click Next. Vigor2920 Series User’s Guide...
  • Page 19 In the following dialog, type 192.168.1.1 (router’s LAN IP) in the field of Printer Name or IP Address and type IP_192.168.1.1 as the port name. Then, click Next. Click Standard and choose Generic Network Card. Then, in the following dialog, click Finish. Vigor2920 Series User’s Guide...
  • Page 20 11. Select "LPR" on Protocol, type p1 (number 1) as Queue Name. Then click OK. Next please refer to the red rectangle for choosing the correct protocol and LPR name. Vigor2920 Series User’s Guide...
  • Page 21 If you do not know whether your printer is supported or not, please visit www.DrayTek.com to find out the printer list. Open Support >FAQ; find out the link of Printer Server and click it; then click the What types of printers are compatible with Vigor router? link.
  • Page 22 This page is left blank. Vigor2920 Series User’s Guide...
  • Page 23: Basic Settings

    The web page can be logged out according to the chosen condition. The default setting is Auto Logout, which means the web configuration system will logout after 5 minutes without any operation. Change the setting for your necessity. Vigor2920 Series User’s Guide...
  • Page 24: Changing Password

    Go to System Maintenance page and choose Administrator Password. Enter the login password on the field of Old Password. Type a new password in New Password and Confirm New Password fields. Then click OK to continue. Vigor2920 Series User’s Guide...
  • Page 25: Quick Start Wizard

    If your router can be under an environment with high speed NAT, the configuration provide here can help you to deploy and use the router quickly. The first screen of Quick Start Wizard is entering login password. After typing the password, please click Next. Vigor2920 Series User’s Guide...
  • Page 26: For Wan1/Wan2

    Choose WAN1/WAN2 and click Next to display the following page. Please select the appropriate Internet access type according to the information from your ISP. For example, you should select PPPoE mode if the ISP provides you PPPoE interface. Then click Next for next step. Vigor2920 Series User’s Guide...
  • Page 27 Assign a specific valid user name provided by the ISP. User Name Assign a valid password provided by the ISP. Password Retype the password. Confirm Password Click Next for viewing summary of such connection. Vigor2920 Series User’s Guide...
  • Page 28 Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system status of this protocol will be shown. Click PPTP/L2TP as the protocol. Type in all the information that your ISP provides for this protocol. Click Next for viewing summary of such connection. Vigor2920 Series User’s Guide...
  • Page 29 Click Static IP as the protocol. Type in all the information that your ISP provides for this protocol. After finishing the settings in this page, click Next to see the following page. Vigor2920 Series User’s Guide...
  • Page 30 Click DHCP as the protocol. Type in all the information that your ISP provides for this protocol. After finishing the settings in this page, click Next to see the following page. Vigor2920 Series User’s Guide...
  • Page 31: For Wan3

    Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system status of this protocol will be shown. To use 3G USB modem for network connection, please choose WAN3. Then, click Next to continue. Vigor2920 Series User’s Guide...
  • Page 32: Service Activation Wizard

    Service Activation Wizard is a tool which allows you to use trial version or update the license of WCF directly without accessing into the server (MyVigor) located on http://myvigor.draytek.com. For using Web Content Filter Profile, please refer to later section Web Content Filter Profile for detailed information.
  • Page 33 When you finish the selection, please click Next. Commtouch is the web content filter based on Commtouch operated in the worldwide. There is a 30-day trial period. After trial, you can purchase DrayTek's prepared Commtouch GlobalView WCF package from retailing outlets.
  • Page 34 Note: The service will be activated and applied as the default rule configured in Firewall>>General Setup. Now, the web page will display the service that you have activated according to your selection(s). The valid time for the free trial of these services is 30-day. Vigor2920 Series User’s Guide...
  • Page 35 Later, if you need to extend the license valid time for the same service, you can also use the Service Activation Wizard again to reach your goal by clicking the radio button of Formal edition with license key and clicking Next. Vigor2920 Series User’s Guide...
  • Page 36: Online Status

    - Displays the total transmitted packets at the LAN interface. RX Packets - Displays the total number of received packets at the LAN interface. WAN 1 Status ~ WAN 3 Line Status - Displays the physical connection of this interface. Vigor2920 Series User’s Guide...
  • Page 37: Virtual Wan

    Internet; the words in red mean that the WAN connection of that interface is not ready for accessing Internet. Such page displays the virtual WAN connection information. Virtual WAN are used by TR-069 management, VoIP service and so on. The Application field will list the purpose of such WAN connection. Vigor2920 Series User’s Guide...
  • Page 38: Saving Configuration

    Please follow the steps below to finish the router registration. Please login the web configuration interface of Vigor router by typing “admin/admin” as User Name / Password. Click Support Area>>Production Registration from the home page. Vigor2920 Series User’s Guide...
  • Page 39 A Login page will be shown on the screen. Please type the account and password that you created previously. And click Login. The following page will be displayed after you logging in MyVigor. From this page, please click Add or Product Registration. Vigor2920 Series User’s Guide...
  • Page 40 (it appears when you click on the box of Registration Date). After adding the basic information for the router, please click Submit. When the following page appears, your router information has been added to the database. Now, you have finished the product registration. Vigor2920 Series User’s Guide...
  • Page 41: Tutorials And Applications

    VLAN Configuration. For VLAN0 setting, check P1 and set LAN1 as the Subnet. For VLAN1 setting, check P2 and set LAN2 as the Subnet. For VLAN2 setting, check P3 and P4, and set LAN3 as the Subnet. Vigor2920 Series User’s Guide...
  • Page 42 The equipment connecting to Vigor2920 LAN Port 3 and Port 4 (LAN3) can get the IP address of 192.168.3.0/24 For the detailed settings of the network segment, open LAN>>General Setup and click Details Page. Adjust the settings for your request. Refer to the following figure. Vigor2920 Series User’s Guide...
  • Page 43 To make any two of VLAN groups linked with each other, just check the boxes of the ones in the field of Inter-LAN Routing in the page of LAN >> General Setup. Refer to the following figure. LAN2 and LAN3 are linked. Vigor2920 Series User’s Guide...
  • Page 44 (8) for VID setting. Then check P4 and set LAN2 as the Subnet. To activate the function of VLAN Tag for VLAN2 setting, check the box of Enable and type the value (9) for VID setting. Then check P4 and set LAN3 as the Subnet. Vigor2920 Series User’s Guide...
  • Page 45 In the page of LAN >> General Setup, check the Status box of LAN2, LAN3 and LAN4 and enable the function of DHCP. For the detailed settings of the network segment, open LAN>>General Setup and click Details Page. Adjust the settings for your request. Refer to the following figure. Vigor2920 Series User’s Guide...
  • Page 46 Port 23 is set with Trunk in this example and will transfer the packets with VLAN Tag information. That is, packets with VID 7, 8, 9 and 10 will be transferred to Vigor2920 by Port 23 and VID information will be retained. Vigor2920 Series User’s Guide...
  • Page 47 To make any two of VLAN groups of Tag Based VLAN linked with each other, just check the boxes of the ones in the field of Inter-LAN Routing in the page of LAN >> General Setup. Refer to the following figure. LAN2 and LAN3 are linked. Vigor2920 Series User’s Guide...
  • Page 48: How To Use Smartmonitor With Vigor2920 Series

    SmartMonitor to the monitor port of Vigor router, then all the traffic in other LAN port will forward to the monitor port. But, there is no hardware monitor port for Vigor2920 series. Therefore we need to configure mirror port setting in the web configurator of Vigor2920 for using SmartMonitor.
  • Page 49: Create A Lan-To-Lan Connection Between Remote Office And Headquarter

    For using PPP based services, such as PPTP, L2TP, you have to set general settings in PPP General Setup. For using IPSec-based service, such as IPSec or L2TP with IPSec Policy, you have to set general settings in IPSec General Setup, such as the pre-shared key that both parties have known. Vigor2920 Series User’s Guide...
  • Page 50 Go to LAN-to-LAN. Click on one index number to edit a profile. Set Common Settings as shown below. You should enable both of VPN connections because any one of the parties may start the VPN connection. Vigor2920 Series User’s Guide...
  • Page 51 Address, IKE Authentication Method and IPSec Security Method for this Dial-Out connection. If a PPP-based service is selected, you should further specify the remote peer IP Address, Username, Password, PPP Authentication and VJ Compression for this Dial-Out connection. Vigor2920 Series User’s Guide...
  • Page 52 Otherwise, it will apply the settings defined in IPSec General Setup above. If a PPP-based service is selected, you should further specify the remote peer IP Address, Username, Password, and VJ Compression for this Dial-In connection. Vigor2920 Series User’s Guide...
  • Page 53 PPP General Setup. For using IPSec-based service, such as IPSec or L2TP with IPSec Policy, you have to set general settings in IPSec General Setup, such as the pre-shared key that both parties have known. Vigor2920 Series User’s Guide...
  • Page 54 Set Dial-Out Settings as shown below to dial to connect to Router A aggressively with the selected Dial-Out method. If an IPSec-based service is selected, you should further specify the remote peer IP Address, IKE Authentication Method and IPSec Security Method for this Dial-Out connection. Vigor2920 Series User’s Guide...
  • Page 55 If an IPSec-based service is selected, you may further specify the remote peer IP Address, IKE Authentication Method and IPSec Security Method for this Dial-In connection. Otherwise, it will apply the settings defined in IPSec General Setup above. Vigor2920 Series User’s Guide...
  • Page 56 Username, Password, and VJ Compression for this Dial-In connection. At last, set the remote network IP/subnet in TCP/IP Network Settings so that Router B can direct the packets destined to the remote network to Router A via the VPN connection. Vigor2920 Series User’s Guide...
  • Page 57: Create A Remote Dial-In User Connection Between The Teleworker And Headquarter

    PPP General Setup. For using IPSec-based service, such as IPSec or L2TP with IPSec Policy, you have to set general settings in IKE/IPSec General Setup, such as the pre-shared key that both parties have known. Vigor2920 Series User’s Guide...
  • Page 58 If an IPSec-based service is selected, you may further specify the remote peer IP Address, IKE Authentication Method and IPSec Security Method for this Dial-In connection. Otherwise, it will apply the settings defined in IPSec General Setup above. Vigor2920 Series User’s Guide...
  • Page 59 For Win2000/XP, please use "Network and Dial-up connections" or “Smart VPN Client”, complimentary software to help you create PPTP, L2TP, and L2TP over IPSec tunnel. You can find it in CD-ROM in the package or go to www.DrayTek.com download center. Install as instructed.
  • Page 60 VPN router. To use default gateway on remote network means that all the packets of remote host will be directed to VPN server then forwarded to Internet. This will make the remote host seem to be working in the enterprise network. Vigor2920 Series User’s Guide...
  • Page 61: Qos Setting Example

    Vigor router at home to connect to the server in the headquarter office downtown via either HTTPS or VPN to check email and access internal database. Meanwhile, children may chat on Skype in the restroom. Go to Bandwidth Management>>Quality of Service. Vigor2920 Series User’s Guide...
  • Page 62 80% - 85% of physical network speed provided by ISP to maximize the QoS performance. Return to previous page. Enter the Name of Index Class 1 by clicking Edit link. Type the name “E-mail” for Class 1. Vigor2920 Series User’s Guide...
  • Page 63 POP3 and SMTP. Return to previous page. Enter the Name of Index Class 2 by clicking Edit link. In this index, the user will set reserved bandwidth for HTTPS. And click OK. Click Setup link for WAN. Vigor2920 Series User’s Guide...
  • Page 64 Class Name of Index 3. In this index, he will set reserved bandwidth for 1 VPN tunnel. 10. Click Edit to open a new window. 11. Click Edit to open the following window. Check the ACT box, first. Vigor2920 Series User’s Guide...
  • Page 65: Request A Certificate From A Ca Server On Windows Ca Server

    12. Then click Edit of Local Address to set a worker’s subnet address. Click Edit of Remote Address to set headquarter’s IP address. Leave other fields and click OK. Go to Certificate Management and choose Local Certificate. Vigor2920 Series User’s Guide...
  • Page 66 Copy and save the X509 Local Certificate Requet as a text file and save it for later use. Connect to CA server via web browser. Follow the instruction to submit the request. Below we take a Windows 2000 CA server for example. Select Request a Certificate. Vigor2920 Series User’s Guide...
  • Page 67 64 encoded certificate and Download CA certificate. Now you should get a certificate (.cer file) and save it. Back to Vigor router, go to Local Certificate. Click IMPORT button and browse the file to import the certificate (.cer file) into Vigor router. When finished, click refresh and Vigor2920 Series User’s Guide...
  • Page 68 “------BEGINE CERTIFICATE------..” You may review the detail information of the certificate by clicking View button. Vigor2920 Series User’s Guide...
  • Page 69: Request A Ca Certificate And Set As Trusted On Windows Ca Server

    Use web browser connecting to the CA server that you would like to retrieve its CA certificate. Click Retrive the CA certificate or certificate recoring list. Vigor2920 Series User’s Guide...
  • Page 70 You may review the detail information of the certificate by clicking View button. Note: Before setting certificate configuration, please go to System Maintenance >> Time and Date to reset current time of the router first. Vigor2920 Series User’s Guide...
  • Page 71: Creating An Account For Myvigor

    The website of MyVigor (a server located on http://myvigor.draytek.com) provides several useful services (such as Web Content Filter) to filtering the web pages for the sake of protecting your system. In general, Service Activation Wizard can activate WCF service for the router by using simple steps.
  • Page 72 2. Click the Activate link. A login page for MyVigor web site will pop up automatically. 3. Click the link of Create an account now. 4. Check to confirm that you accept the Agreement and click Accept. Vigor2920 Series User’s Guide...
  • Page 73 5. Type your personal information in this page and then click Continue. 6. Choose proper selection for your computer and click Continue. Vigor2920 Series User’s Guide...
  • Page 74 New Account Confirmation Letter from myvigor.draytek.com. 9. Click the Activate my Account link to enable the account that you created. The following screen will be shown to verify the register process is finished. Please click Login. Vigor2920 Series User’s Guide...
  • Page 75: Creating An Account Via Myvigor Web Site

    11. Now, click Login. Your account has been activated. You can access into MyVigor server to activate the service (e.g., WCF) that you want. 1. Access into http://myvigor.draytek.com. Find the line of Not registered yet?. Then, click the link Click here! to access into next page.
  • Page 76 2. Check to confirm that you accept the Agreement and click Accept. 3. Type your personal information in this page and then click Continue. 4. Choose proper selection for your computer and click Continue. Vigor2920 Series User’s Guide...
  • Page 77 New Account Confirmation Letter from myvigor.draytek.com. 7. Click the Activate my Account link to enable the account that you created. The following screen will be shown to verify the register process is finished. Please click Login. Vigor2920 Series User’s Guide...
  • Page 78 UserName and Password. Then type the code in the box of Auth Code according to the value displayed on the right side of it. Now, click Login. Your account has been activated. You can access into MyVigor server to activate the service (e.g., WCF) that you want. Vigor2920 Series User’s Guide...
  • Page 79: Web Configuration

    Hence, the NIC has reserved certain addresses that will never be registered publicly. These are known as private IP addresses, and are listed in the following ranges: Vigor2920 Series User’s Guide...
  • Page 80 After connecting into the router, 3G USB Modem will be regarded as the third WAN port. However, the original Ethernet WAN1/WAN2 still can be used and Load-Balance can be done in the router. Besides, 3G USB Modem in WAN3 also can be used as backup device. Vigor2920 Series User’s Guide...
  • Page 81: General Setup

    Therefore, when WAN1/WAN2 is not available, the router will use 3.5G for supporting automatically. The supported 3G USB Modem will be listed on Draytek web site. Please visit www.draytek.com for more detailed information. Below shows the menu items for WAN.
  • Page 82 Type the description for such WAN interface. Display Name Display the physical mode of such WAN interface. Physical Mode You can change the physical type for WAN2 or choose Auto Physical Type negotiation for determined by the system. Vigor2920 Series User’s Guide...
  • Page 83 WAN. When any WAN disconnect – Such backup WAN will be activated when any master WAN interface disconnects. When all WAN disconnect – Such backup WAN will be activated only when all master WAN interfaces disconnect. Vigor2920 Series User’s Guide...
  • Page 84 If you choose Always On as Active Mode, such interface will be used for access into Internet all the time. If you choose Backup as the Active Mode, you have to specify which WAN interface will be selected to backup multiple Vigor2920 Series User’s Guide...
  • Page 85: Internet Access

    (Ethernet) /WAN3 (3G USB Modem) according to the real network connection. Use the drop down list to choose a proper access mode. The Access Mode details page of that mode will be popped up. If not, click Vigor2920 Series User’s Guide...
  • Page 86 Password – Type in the password provided by ISP in this field. Index (1-15) in Schedule Setup - You can type in four sets of time schedule for your request. All the schedules can be set previously in Application – Schedule web page and you can Vigor2920 Series User’s Guide...
  • Page 87 WAN IP Alias - If you have multiple public IP addresses and would like to utilize them on the WAN interface, please use WAN IP Alias. You can set up to 8 public IP addresses other than the current one you are using. Vigor2920 Series User’s Guide...
  • Page 88 IP address to the WAN interface. To use Static or Dynamic IP as the accessing protocol of the internet, please choose Static or Dynamic IP mode from Internet Access menu. The following web page will be shown. Vigor2920 Series User’s Guide...
  • Page 89 IP address in this field for pinging. TTL (Time to Live) – Displays value for your reference. TTL value is set by telnet command. It means Max Transmit Unit for packet. The default setting is 1442. Vigor2920 Series User’s Guide...
  • Page 90 Specify a MAC Address: Some Cable service providers specify a specific MAC address for access authentication. In such cases you need to click the Specify a MAC Address and enter the MAC address in the MAC Address field. Vigor2920 Series User’s Guide...
  • Page 91 Password -Type in the password provided by ISP in this field. Index (1-15) in Schedule Setup - You can type in four sets of time schedule for your request. All the schedules can be set previously in Application – Schedule web page and you can Vigor2920 Series User’s Guide...
  • Page 92 Click Yes to use this function and type in a fixed IP address in the box. Fixed IP Address -Type a fixed IP address. Obtain an IP address automatically – Click this button to WAN IP Network Vigor2920 Series User’s Guide...
  • Page 93 Type PIN code of the SIM card that will be used to access SIM PIN code Internet. Such value is used to initialize USB modem. Please use the Modem Initial String default value. If you have any question, please contact to your ISP. Vigor2920 Series User’s Guide...
  • Page 94: Load-Balance Policy

    The user can assign traffic category and force it to go to dedicate network interface based on the following web page setup. Twenty policies of load-balance are supported by this router. Note: Load-Balance Policy is running only when more than one WAN interface is activated. Vigor2920 Series User’s Guide...
  • Page 95 Displays the IP address for the start of the destination port. Dest Port Start Displays the IP address for the end of the destination port. Dest Port End Use Up or Down link to move the order of the policy. Move UP/Move Down Vigor2920 Series User’s Guide...
  • Page 96 Type the destination port end for the destination IP. If this field Dest Port End is blank, it means that all the destination ports will be passed through the WAN interface. After finishing all the settings here, please click OK to save the configuration. Vigor2920 Series User’s Guide...
  • Page 97: Multi-Vlan

    And type the number for VLAN ID (number). To add the packet priority number for such VLAN. The range Priority is from 0 to 7. After finishing all the settings here, please click OK to save the configuration. Vigor2920 Series User’s Guide...
  • Page 98 IPTV - Packets from IGMP proxy will be sent out from such WAN interface. Therefore, the setting for IGMP shall be configured with PVC in the page of Application>>IGMP. For other settings, refer to Details Page for PPPoE in WAN1. Vigor2920 Series User’s Guide...
  • Page 99 LAN port for channel 3 to 8. Click Clear to remove all the configurations in this page if you do not satisfy it. When you finish the configuration, please click OK to save and exit this page. Vigor2920 Series User’s Guide...
  • Page 100: Lan

    IP address. As a part of the public subnet, the Vigor router will serve for IP routing to help hosts in the public subnet to communicate with other public hosts or servers outside. Therefore, the router should be set as the gateway for public hosts. Vigor2920 Series User’s Guide...
  • Page 101 You can group local hosts by physical ports and create up to 4 virtual LANs. To manage the communication between different groups, please set up rules in Virtual LAN (VLAN) function and the rate of each. Vigor2920 Series User’s Guide...
  • Page 102: General Setup

    LAN configuration page. Each LAN must be configured in different subnet. Check the box to link two or more different subnets (LAN and Inter-LAN Routing LAN). After finishing all the settings here, please click OK to save the configuration. Vigor2920 Series User’s Guide...
  • Page 103 IP address of your router is 192.168.1.1, the starting IP address must be 192.168.1.2 or greater, but smaller than 192.168.1.254. IP Pool Counts - Enter the maximum number of PCs that you want the DHCP server to assign IP addresses to. The default is Vigor2920 Series User’s Guide...
  • Page 104 There are two common scenarios of LAN settings that stated in Chapter 3. For the configuration examples, please refer to that chapter to get more information for your necessity. Details Page for LAN2 to LAN4 will be available only when VLAN settings for LAN2 to LAN4 are configured and activated. Vigor2920 Series User’s Guide...
  • Page 105 DHCP server. The value is usually as same as the 1st IP address of the router, which means the router is the default gateway. After finishing all the settings here, please click OK to save the configuration. Vigor2920 Series User’s Guide...
  • Page 106: Static Route

    Main Router 192.168.1.1 as the default gateway for the Router A 192.168.1.2. Before setting Static Route, user A cannot talk to user B for Router A can only forward recognized packets to its default gateway Main Router. Vigor2920 Series User’s Guide...
  • Page 107 192.168.10.0 will be forwarded to 192.168.1.2. Click OK. Return to Static Route Setup page. Click on another Index Number to add another static route as show below, which regulates all packets destined to 211.100.88.0 will be forwarded to 192.168.1.3. Vigor2920 Series User’s Guide...
  • Page 108 Go to Diagnostics and choose Routing Table to verify current routing table. Vigor2920 Series User’s Guide...
  • Page 109: Vlan

    Choose one of them to make the selected VLAN mapping to Subnet the specified subnet only. For example, LAN1 is specified for VLAN0. It means that PCs grouped under VLAN0 can get the IP address (es) that specified by the subnet. Vigor2920 Series User’s Guide...
  • Page 110: Bind Ip To Mac

    Click this radio button to disable this function. All the settings Disable on this page will be invalid. Click this radio button to block the connection of the IP/MAC Strict Bind which is not listed in IP Bind List. Vigor2920 Series User’s Guide...
  • Page 111: Lan Port Mirror

    VLAN at the same time. Third, it can transfer all data traffics to be mirrored to one analyzer connect to the mirroring port. Last, it is more convenient and easy to configure in user’s interface. Vigor2920 Series User’s Guide...
  • Page 112: Nat

    192.168.1.0/24 subnet for the router. As stated before, the NAT facility can map one or more IP addresses and/or service ports into different specified services. In other words, the NAT function can be achieved by using port mapping methods. Below shows the menu items for NAT. Vigor2920 Series User’s Guide...
  • Page 113: Port Redirection

    The port redirection can only apply to incoming traffic. To use this function, please go to NAT page and choose Port Redirection web page. The Port Redirection Table provides 20 port-mapping entries for the internal hosts. Vigor2920 Series User’s Guide...
  • Page 114 Private IP service. Display if the profile is enabled (v) or not (x). Status Press any number under Index to access into next page for configuring port redirection. Available settings are explained as follows: Item Description Vigor2920 Series User’s Guide...
  • Page 115 80 to avoid conflict, such as 8080. This can be set in the System Maintenance >>Management Setup. You then will access the admin screen of by suffixing the IP address with 8080, e.g., http://192.168.1.1:8080 instead of port 80. Vigor2920 Series User’s Guide...
  • Page 116: Dmz Host

    Netmeeting or Internet Games etc. The security properties of NAT are somewhat bypassed if you set up DMZ host. We suggest you to add additional filter rules or a secondary firewall. Click DMZ Host to open the following page: Vigor2920 Series User’s Guide...
  • Page 117 WAN2 interface, you will find them in Aux. WAN IP for your selection. Available settings are explained as follows: Item Description Check to enable the DMZ Host function. Enable Enter the private IP address of the DMZ host, or click Choose Private IP PC to select one. Vigor2920 Series User’s Guide...
  • Page 118: Open Ports

    WinMX, eMule and others), Internet Camera etc. Ensure that you keep the application involved up-to-date to avoid falling victim to any security exploits. Click Open Ports to open the following page: Each item is explained as follows: Vigor2920 Series User’s Guide...
  • Page 119 Specify the transport layer protocol. It could be TCP, UDP, or Protocol ----- (none) for selection. Specify the starting port number of the service offered by the Start Port local host. Vigor2920 Series User’s Guide...
  • Page 120: Address Mapping

    Display the private IP set for this address mapping, e.g., Private IP 192.168.1.10. Display the subnet mask selected for this address mapping. Mask Display the status for the entry, enable or disable. Status Click the index number link to open the configuration page. Vigor2920 Series User’s Guide...
  • Page 121 Private IP compared with the Public IP address for incoming packets. Select a value of subnet mask for private IP address. Subnet Mask After finishing all the settings here, please click OK to save the configuration. Vigor2920 Series User’s Guide...
  • Page 122: Firewall

    It will check packets according to the filter rules. If legal, the packet will pass the router. The following illustrations are flow charts explaining how router will treat incoming traffic and outgoing traffic respectively. Vigor2920 Series User’s Guide...
  • Page 123 4. Port Scan attack 12. Tear drop attack 5. IP options 13. Ping of Death attack 6. Land attack 14. ICMP fragment 7. Smurf attack 15. Unknown protocol 8. Trace route Below shows the menu items for Firewall. Vigor2920 Series User’s Guide...
  • Page 124: General Setup

    If the firewall system does not have any response (pass or block) for these packets, such as no response coming from web content filter, then the router’s firewall will block the packets directly. Vigor2920 Series User’s Guide...
  • Page 125 The default setting is 60000. Choose one of the QoS rules to be applied as firewall rule. For Quality of Service detailed information of setting QoS, please refer to the related section later. Vigor2920 Series User’s Guide...
  • Page 126 Select one of the Web Content Filter profile settings (created Web Content Filter in CSM>> Web Content Filter) for applying with this router. Please set at least one profile for anti-virus in CSM>> Web Content Filter web page first. Or choose [Create New] from Vigor2920 Series User’s Guide...
  • Page 127 However, if the network is not stable, small value will be proper. Session timeout – Setting timeout for sessions can make the best utilization of network resources. After finishing all the settings here, please click OK to save the configuration. Vigor2920 Series User’s Guide...
  • Page 128: Filter Setup

    Set the link to the next filter set to be executed after the current Next Filter Set filter run. Do not make a loop with many filter sets. To edit Filter Rule, click the Filter Rule index button to enter the Filter Rule setup page. Vigor2920 Series User’s Guide...
  • Page 129 ON Set the direction of packet flow. It is for Data Filter only. For Direction the Call Filter, this setting is not available since Call Filter is only applied to outgoing traffic. Vigor2920 Series User’s Guide...
  • Page 130 From the IP Group drop down list, choose the one that you want to apply. Or use the IP Object drop down list to choose the object that you want. Click Edit to access into the following dialog to choose a Service Type suitable service type. Vigor2920 Series User’s Guide...
  • Page 131 Too Short - Apply the rule only to packets that are too short to contain a complete header. Specifies the action to be taken when packets match the rule. Filter Block Immediately - Packets matching the rule will be dropped immediately. Vigor2920 Series User’s Guide...
  • Page 132 [Create New] from the drop down list in this page to create a new profile. All the hosts in LAN must follow the standard configured in the APP Enforcement profile selected here. For detailed information, refer to the section of Vigor2920 Series User’s Guide...
  • Page 133 Please use the drop-down list to choose a codepage. If you do not have any idea of choosing suitable codepage, please open Syslog. From Codepage Information of Setup dialog, you will see the recommended codepage listed on the dialog box. Vigor2920 Series User’s Guide...
  • Page 134 TCP protocol only; session timeout is configured for the data flow which matched with the firewall rule. DrayTek Banner – Please uncheck this box and the following screen will not be shown for the unreachable web page. The default setting is Enabled.
  • Page 135 Each filter set is composed by 7 filter rules, which can be further defined. After that, in General Setup you may specify one set for call filter and one set for data filter to execute first. Vigor2920 Series User’s Guide...
  • Page 136: Dos Defense

    UDP packets for a period defined in Timeout. The default setting for threshold and timeout are 150 packets per second and 10 seconds, respectively. Check the box to activate the ICMP flood defense function. Enable ICMP flood Vigor2920 Series User’s Guide...
  • Page 137 Check the box to activate the Block Tear Drop function. Many Block Tear Drop machines may crash when receiving ICMP datagrams (packets) that exceed the maximum length. To avoid this type of attack, the Vigor router is designed to be capable of discarding any Vigor2920 Series User’s Guide...
  • Page 138 All the warning messages related to DoS Defense will be sent to user and user can review it through Syslog daemon. Look for the keyword DoS in the message, followed by a name to indicate what kind of attacks is detected. Vigor2920 Series User’s Guide...
  • Page 139: User Management

    Note: If Transparency Mode is selected in Firewall>>General Setup, User Management cannot be used any more. Please uncheck Transparency Mode first if you want to utilize user management to handle users in LAN, WAN or WLAN. Vigor2920 Series User’s Guide...
  • Page 140: General Setup

    User-Based - If you choose such mode, the router will apply the filter rules configured in User Management>>User Profile to the users. Rule-Based –If you choose such mode, the router will apply the filter rules configured in Firewall>>General Setup and Filter Rule to the users. Vigor2920 Series User’s Guide...
  • Page 141: User Profile

    To set the user profile, please click any index number link to open the following page. Notice that profile 1 (admin) and profile 2 (System Reservation) are factory default settings. Profile 2 is reserved for future use. Click any index number to open the following configuration page: Vigor2920 Series User’s Guide...
  • Page 142 Firewall can be adopted for such user profile. Create New Policy – If you choose such item, the following page will be popped up for you to define another filter rule as a new policy. Vigor2920 Series User’s Guide...
  • Page 143 User Management >> General Setup) will be displayed. After authentication, the destination URL (if requested by the user) will be guided automatically by the router. Alert Tool – If it is selected, the user can open Alert Tool and Vigor2920 Series User’s Guide...
  • Page 144: User Group

    When a user tries to access into the web configurator of Landing Page Vigor2920 series with the user name and password specified in this profile, he/she will be lead into the web page configured in Landing Page field in User Management>>General Setup.
  • Page 145: User Online Status

    This page displays the user(s) connected to the router and refreshes the connection status in an interval of several seconds. Available settings are explained as follows: Vigor2920 Series User’s Guide...
  • Page 146 Display the idle timeout setting for such profile. Idle Time Block - can prevent specified user accessing into Internet. Action Unblock – the user will be blocked. Logout – the user will be logged out forcefully. Vigor2920 Series User’s Guide...
  • Page 147: Objects Settings

    You can set up to 192 sets of IP Objects with different conditions. Available settings are explained as follows: Item Description Display a name for this profile. Name Clear all profiles. Set to Factory Default Click the number under Index column for settings in detail. Vigor2920 Series User’s Guide...
  • Page 148 Select Subnet Address if this object contains one subnet for IP address. Select Any Address if this object contains any IP address. Select Mac Address if this object contains Mac address. Type the MAC address of the network card which will be MAC Address controlled. Vigor2920 Series User’s Guide...
  • Page 149: Ip Group

    This page allows you to bind several IP objects into one IP group. Available settings are explained as follows: Item Description Display a name for this IP group profile. Name Clear all profiles. Set to Factory Default Vigor2920 Series User’s Guide...
  • Page 150 All the available IP objects with the specified interface chosen Available IP Objects above will be shown in this box. Click >> button to add the selected IP objects in this box. Selected IP Objects Vigor2920 Series User’s Guide...
  • Page 151: Service Type Object

    Set to Factory Default Click the number under Index column for settings in detail. Available settings are explained as follows: Item Description Type a name for this profile. Name Specify the protocol(s) which this profile will apply to. Protocol Vigor2920 Series User’s Guide...
  • Page 152 (>) – the port number greater than this value is available. (<) – the port number less than this value is available for this profile. Below is an example of service type objects settings. Vigor2920 Series User’s Guide...
  • Page 153: Service Type Group

    This page allows you to bind several service types into one group. Available settings are explained as follows: Item Description Display a name for this profile. Name Clear all profiles. Set to Factory Default Vigor2920 Series User’s Guide...
  • Page 154: Keyword Object

    Click >> button to add the selected IP objects in this box. Selected Service Type Objects You can set 200 keyword object profiles for choosing as black /white list in CSM >>URL Web Content Filter Profile. Vigor2920 Series User’s Guide...
  • Page 155 Type the content for such profile. For example, type gambling Contents as Contents. When you browse the webpage, the page with gambling information will be watched out and be passed/blocked based on the configuration on Firewall settings. Vigor2920 Series User’s Guide...
  • Page 156: Keyword Group

    Display a name for this profile. Name Clear all profiles. Set to Factory Default Click the number under Index column for setting in detail. Available settings are explained as follows: Item Description Type a name for this group. Name Vigor2920 Series User’s Guide...
  • Page 157: File Extension Object

    Vigor router. Available settings are explained as follows: Item Description Display a name for this profile. Name Clear all profiles. Set to Factory Default Vigor2920 Series User’s Guide...
  • Page 158 Type a name for this profile. Profile Name Type a name for such profile and check all the items of file extension that will be processed in the router. Finally, click OK to save this profile. Vigor2920 Series User’s Guide...
  • Page 159: Csm Profile

    Please note that this action will not introduce any delay in your Web surfing because each of multiple load balanced database servers can handle millions of requests for categorization. Note: The priority of URL Content Filter is higher than Web Content Filter. Vigor2920 Series User’s Guide...
  • Page 160: App Enforcement Profile

    There are four tabs IM, P2P, Protocol and Misc displayed on this page. Each tab will bring out different items that you can choose to disallow people using. Below shows the items which are categorized under IM. Vigor2920 Series User’s Guide...
  • Page 161 Click it to choose all of the items in this page. Select All Uncheck all the selected boxes. Clear All The profiles configured here can be applied in the Firewall>>General Setup and Firewall>>Filter Setup pages as the standard for the host(s) to follow. Vigor2920 Series User’s Guide...
  • Page 162 The items categorized under P2P ----- The items categorized under Protocol. Vigor2920 Series User’s Guide...
  • Page 163: Url Content Filter Profile

    For example, an ActiveX control object is usually used for providing interactive web feature. If malicious code hides inside, it may occupy user’s system. Vigor2920 Series User’s Guide...
  • Page 164 Each item is explained as follows: Item Description Clear all profiles. Set to Factory Default Display the number of the profile which allows you to click to Profile set different policy. Display the name of the URL Content Filter Profile. Name Vigor2920 Series User’s Guide...
  • Page 165 Control and Web Feature below, such function can determine the priority for the actions executed. For this one, the router will process the packages with the conditions set below for web feature first, then URL second. Vigor2920 Series User’s Guide...
  • Page 166 In addition, the maximal length of each frame is 32-character long. After specifying keywords, the Vigor router will decline the connection request to the website whose URL string matched to any user-defined keyword. It should be Vigor2920 Series User’s Guide...
  • Page 167 File Extension Profile – Choose one of the profiles that you configured in Object Setting>> File Extension Objects previously for passing or blocking the file downloading. Vigor2920 Series User’s Guide...
  • Page 168: Web Content Filter Profile

    Please refer to section of creating MyVigor account. WCF adopts the mechanism developed and offered by certain service provider (e.g., DrayTek). No matter activating WCF feature or getting a new license for web content filter, you have to click Activate to satisfy your request.
  • Page 169 It is recommended for you to use the default setting, Setup Test Server auto-selected. Such server is powered by Commtouch. Click it to open http://myvigor.draytek.com for searching Find more another qualified and suitable server. Click this link to retrieve the factory settings.
  • Page 170 Block - restrict accessing into the corresponding webpage with the characters listed on Group/Object Selections. If the web pages do not match with the specified feature set here, they will be processed with the categories listed on the box below. Vigor2920 Series User’s Guide...
  • Page 171: Bandwidth Management

    To solve the problem, you can use limit session to limit the session procession for specified Hosts. In the Bandwidth Management menu, click Sessions Limit to open the web page. Vigor2920 Series User’s Guide...
  • Page 172 Adds the specific session limitation onto the list above. Allows you to edit the settings for the selected limitation. Edit Vigor2920 Series User’s Guide...
  • Page 173: Bandwidth Limit

    In the Bandwidth Management menu, click Bandwidth Limit to open the web page. To activate the function of limit bandwidth, simply click Enable and set the default upstream and downstream limit. Vigor2920 Series User’s Guide...
  • Page 174 You can type in four sets of time schedule for your request. All Index (1-15) in Schedule the schedules can be set previously in Application >> Setup Schedule web page and you can use the number that you have set in that web page. Vigor2920 Series User’s Guide...
  • Page 175: Quality Of Service

    The core routers in the backbone will do the same checking before executing treatments in order to ensure service-level consistency throughout the whole QoS-enabled network. Vigor2920 Series User’s Guide...
  • Page 176 You can configure general setup for the WAN interface, edit the Class Rule, and edit the Service Type for the Class Rule for your request. Display an online statistics for quality of service for your reference. This feature is available only when the Quality of Service for WAN interface is enabled. Vigor2920 Series User’s Guide...
  • Page 177 Note: The rate of outbound/inbound must be smaller than the real bandwidth to ensure correct calculation of QoS. It is suggested to set the bandwidth value for inbound/outbound as 80% - 85% of physical network speed provided by ISP to maximize the QoS performance. Vigor2920 Series User’s Guide...
  • Page 178 Edit link of that one. After you click the Edit link, you will see the following page. Now you can define the name for that Class. In this case, “Test” is used as the name of Class Index #1. Vigor2920 Series User’s Guide...
  • Page 179 QoS control. It can also be edited. You can choose the predefined service type from the Service Type drop down list. Those types are predefined in factory. Simply choose the one that you want for using by current QoS. Vigor2920 Series User’s Guide...
  • Page 180 Edit to open the rule edit page for modification. To add a new service type, edit or delete an existed service type, please click the Edit link under Service Type field. After you click the Edit link, you will see the following page. Vigor2920 Series User’s Guide...
  • Page 181 Range as the type. By the way, you can set up to 10 service types. If you want to edit/delete an existed service type, please select the radio button of that one and click Edit/Edit for modification. Vigor2920 Series User’s Guide...
  • Page 182: Applications

    In the DDNS setup menu, check Enable Dynamic DNS Setup. Available settings are explained as follows: Item Description Clear all profiles and recover to factory settings. Set to Factory Default Check this box to enable DDNS function. Enable Dynamic DNS Setup Vigor2920 Series User’s Guide...
  • Page 183 WAN1/WAN2/WAN3 as the first channel for such account. If WAN1/WAN2/WAN3 fails, the router will use another WAN interface instead. WAN1/WAN2/WAN3 Only - While connecting, the router will use WAN1/WAN2/WAN3 as the only channel for such account. Vigor2920 Series User’s Guide...
  • Page 184: Schedule

    The clock will reset once if you power down or reset the router. There is another way to set up time. You can inquiry an NTP server (a time server) on the Internet to synchronize the router’s clock. This method can only be applied when the WAN connection has been built up. Vigor2920 Series User’s Guide...
  • Page 185 To add a schedule, please click any index, say Index No. 1. The detailed settings of the call schedule with index 1 are shown below. Available settings are explained as follows: Item Description Check to enable the schedule. Enable Schedule Setup Specify the starting date of the schedule. Start Date (yyyy-mm-dd) Vigor2920 Series User’s Guide...
  • Page 186 Assign these two profiles to the PPPoE Internet access profile. Now, the PPPoE Internet connection will follow the schedule order to perform Force On or Force Down action according to the time plan that has been pre-defined in the schedule profiles. Vigor2920 Series User’s Guide...
  • Page 187: Radius

    The RADIUS server and client share a secret that is used to Shared Secret authenticate the messages sent between them. Both sides must be configured to use the same shared secret. Re-type the Shared Secret for confirmation. Confirm Shared Secret Vigor2920 Series User’s Guide...
  • Page 188: Upnp

    The NAT Traversal of UPnP enables the multimedia features of your applications to operate. This has to manually set up port mappings or use other similar methods. The screenshots below show examples of this facility. Vigor2920 Series User’s Guide...
  • Page 189 Non-privileged users can control some router functions, including removing and adding port mappings. The UPnP function dynamically adds port mappings on behalf of some UPnP-aware applications. When the applications terminate abnormally, these mappings may not be removed. Vigor2920 Series User’s Guide...
  • Page 190: Igmp

    This field displays the ID port for the multicast group. The Group ID available range for IGMP starts from 224.0.0.0 to 239.255.255.254. It indicates the LAN port used for the multicast group. P1 to P4 Click this link to renew the working multicast group status. Refresh Vigor2920 Series User’s Guide...
  • Page 191: Wake On Lan

    Type any one of the MAC address of the bound PCs. MAC Address Click this button to wake up the selected IP. See the following Wake Up figure. The result will be shown on the box. Vigor2920 Series User’s Guide...
  • Page 192: Vpn And Remote Access

    Item Description Choose the client mode. LAN-to-LAN Client Route Mode/NAT Mode – If the remote network only allows Mode Selection you to dial in with single IP, please choose this mode, otherwise please choose Route Mode. Vigor2920 Series User’s Guide...
  • Page 193 Item Description There are 32 VPN profiles for users to set. Please choose a LAN-to-LAN Profile When you finish the mode and profile selection, please click Next to open the following page. Vigor2920 Series User’s Guide...
  • Page 194 Next. You will see different configurations based on the selection(s) you made. When you choose PPTP (None Encryption) or PPTP (Encryption), you will see the following graphic: When you choose IPSec, you will see the following graphic: Vigor2920 Series User’s Guide...
  • Page 195 When you choose L2TP over IPSec (Nice to Have) or L2TP over IPSec (Must), you will see the following graphic: Available settings are explained as follows: Item Description Type a name for such profile. The length of the file is limited Profile Name to 10 characters. Vigor2920 Series User’s Guide...
  • Page 196 High - Encapsulating Security Payload (ESP) means payload (data) will be encrypted and authenticated. You may select encryption algorithm from Data Encryption Standard (DES), Triple DES (3DES), and AES. This field is used to authenticate for connection when you User Name Vigor2920 Series User’s Guide...
  • Page 197 Click this radio button to set another profile of VPN Server Do another VPN Server through VPN Server Wizard. Wizard Setup Click this radio button to access VPN and Remote View more detailed Access>>LAN to LAN for viewing detailed configuration. configuration Vigor2920 Series User’s Guide...
  • Page 198: Vpn Server Wizard

    VPN connection. This item is available when you choose Site to Site VPN Please choose a (LAN-to-LAN) as VPN server mode. There are 32 VPN LAN-to-LAN Profile profiles for users to set. Vigor2920 Series User’s Guide...
  • Page 199 After making the choices for the server profile, please click Next. You will see different configurations based on the selection you made. Here we take the examples of choosing Remote-Dial-in User as the VPN Server Mode. Vigor2920 Series User’s Guide...
  • Page 200 When you check PPTP, you will see the following graphic: When you check PPTP/IPSec/L2TP (three types) or PPTP/IPSec (two types) or L2TP with Policy (Nice to Have/Must), you will see the following graphic: Vigor2920 Series User’s Guide...
  • Page 201 After finishing the configuration, please click Next. The confirmation page will be shown as follows. If there is no problem, you can click one of the radio buttons listed on the page and click Finish to execute the next action. Vigor2920 Series User’s Guide...
  • Page 202: Remote Access Control

    Enable the necessary VPN service as you need. If you intend to run a VPN server inside your LAN, you should disable the VPN service of Vigor Router to allow VPN tunnel pass through, as well as the appropriate NAT settings, such as DMZ or open port. Vigor2920 Series User’s Guide...
  • Page 203: Ppp General Setup

    MPPE encryption scheme with maximum bits (128-bit) to encrypt the data. The Mutual Authentication function is mainly used to Mutual Authentication communicate with other routers or clients who need (PAP) bi-directional authentication in order to provide stronger Vigor2920 Series User’s Guide...
  • Page 204: Ipsec General Setup

    AH it receives. Encapsulating Security Payload (ESP) is a security protocol that provides data confidentiality and protection with optional authentication and replay detection service. Vigor2920 Series User’s Guide...
  • Page 205 By default, this option is active. High - Encapsulating Security Payload (ESP) means payload (data) will be encrypted and authenticated. You may select encryption algorithm from Data Encryption Standard (DES), Triple DES (3DES), and AES. Vigor2920 Series User’s Guide...
  • Page 206: Ipsec Peer Identity

    Click each index to edit one peer digital certificate. There are three security levels of digital signature authentication: Fill each necessary field to authenticate the remote peer. The following explanation will guide you to fill all the necessary fields. Vigor2920 Series User’s Guide...
  • Page 207 Click to check the specific fields of digital signature to accept Accept Subject Name the peer with matching value. The field includes Country (C), State (ST), Location (L), Organization (O), Organization Unit (OU), Common Name (CN), and Email (E). Vigor2920 Series User’s Guide...
  • Page 208: Remote Dial-In User

    Click each index to edit one remote user profile. Each Dial-In Type requires you to fill the different corresponding fields on the right. If the fields gray out, it means you may leave it untouched. The following explanation will guide you to fill all the necessary fields. Vigor2920 Series User’s Guide...
  • Page 209 Nice to Have - Apply the IPSec policy first, if it is applicable during negotiation. Otherwise, the dial-in VPN connection becomes one pure L2TP connection. Must -Specify the IPSec policy to be definitely applied on the L2TP connection. Vigor2920 Series User’s Guide...
  • Page 210 IPSec Policy when you specify the IP address of the Method remote node. The only exception is Digital Signature (X.509) can be set when you select IPSec tunnel either with or without specify the IP address of the remote node. Vigor2920 Series User’s Guide...
  • Page 211: Lan To Lan

    ID, connection type (VPN connection - including PPTP, IPSec Tunnel, and L2TP by itself or over IPSec) and corresponding security methods, etc. The router supports up to 32 VPN tunnels simultaneously. The following figure shows the summary table. Each item will be explained as follows: Vigor2920 Series User’s Guide...
  • Page 212 For the web page is too long, we divide the page into several sections for explanation. Available settings are explained as follows: Item Description Specify a name for the profile of the LAN-to-LAN connection. Profile Name Check here to activate this profile. Enable this profile Vigor2920 Series User’s Guide...
  • Page 213 This function is to help the router to determine the status of Enable PING to keep IPSec VPN connection, especially useful in the case of alive Vigor2920 Series User’s Guide...
  • Page 214 This group of fields is applicable for IPSec Tunnels and L2TP IKE Authentication with IPSec Policy. Method Pre-Shared Key - Input 1-63 characters as pre-shared key. Digital Signature (X.509) - Select one predefined Profiles set Vigor2920 Series User’s Guide...
  • Page 215 IKE phase 2 proposal-To propose the local available algorithms to the VPN peers, and get its feedback to find a match. Three combinations are available for both modes. We suggest you select the combination that covers the most Vigor2920 Series User’s Guide...
  • Page 216 Local ID-In Aggressive mode, Local ID is on behalf of the IP address while identity authenticating with remote VPN server. The length of the ID is limited to 47 characters. Available settings are explained as follows: Item Description Vigor2920 Series User’s Guide...
  • Page 217 Profiles set in the VPN and Remote Access >>IPSec Peer Identity. Local ID – Specify which one will be inspected first. Alternative Subject Name First – The alternative subject name (configured in Certificate Management>>Local Certificate) will be inspected Vigor2920 Series User’s Guide...
  • Page 218 PPTP or L2TP. Remote Network IP/ Remote Network Mask - Add a static route to direct all traffic destined to this Remote Network IP Address/Remote Network Mask through the VPN connection. Vigor2920 Series User’s Guide...
  • Page 219 Change default route to this VPN tunnel - Check this box to change the default route with this VPN tunnel. Note that this setting is available only for one WAN interface is enabled. It is not available when both WAN interfaces are enabled. Vigor2920 Series User’s Guide...
  • Page 220: Vpn Trunk Management

    Before setting VPN TRUNK backup profile, please configure at least two sets of LAN to LAN profiles (with fully configured dial-out settings) first, otherwise you will not have selections for grouping Member1 and Member2. Available settings are explained as follows: Vigor2920 Series User’s Guide...
  • Page 221 LAN-to-LAN) for you to choose for grouping under certain VPN TRUNK-VPN Backup/Load Balance mechanism profile. No - Index number of LAN-to-LAN dial-out profile. Name - Profile name of LAN-to-LAN dial-out profile. Connection Type - Connection type of LAN-to-LAN dial-out profile. Vigor2920 Series User’s Guide...
  • Page 222 Enable radio button; type a name for such profile (e.g., 071023); choose one of the LAN-to-LAN profiles from Member1 drop down list; choose one of the LAN-to-LAN profiles from Member2 drop down list; and click Add at last. Vigor2920 Series User’s Guide...
  • Page 223 Peer GRE IP. See the following graphic for an example. Later, on peer side (as VPN Client): please type 192.168.50.100 in the field of My GRE IP and type IP address of the server (192.168.50.200) in the field of Peer GRE IP. Vigor2920 Series User’s Guide...
  • Page 224 Resume – when VPN connection breaks down or disconnects, Member 1 will be the top priority for the system to do VPN connection. This field will display detailed information for Environment Detail Information Recovers Detection. Vigor2920 Series User’s Guide...
  • Page 225: Connection Management

    VPN backup function. Backup Mode - This filed displays the profile name saved in VPN TRUNK Management (with Index number and VPN Server IP address). The VPN connection built by Backup Mode supports VPN backup function. Vigor2920 Series User’s Guide...
  • Page 226 Tx Rate – Display the transmission rate for data through such VPN tunnel. Rx Pkts – Display the receiving packets passing through such VPN channel. Rx Rate – Display the receiving rate for data through such VPN tunnel. Vigor2920 Series User’s Guide...
  • Page 227: Certificate Management

    Remember to adjust the time of Vigor router before using the certificate so that you can get the correct valid period of certificate. Below shows the menu items for Certificate Management. Available settings are explained as follows: Item Description Click this button to open Generate Certificate Request Generate window. Vigor2920 Series User’s Guide...
  • Page 228 Click this button to refresh the information listed below. Refresh Click this button to view the detailed settings for certificate View request. After clicking Generate, the generated information will be displayed on the window below: Vigor2920 Series User’s Guide...
  • Page 229: Trusted Ca Certificate

    For viewing each trusted CA certificate, click View to open the certificate detail information window. If you want to delete a CA certificate, choose the one and click Delete to remove all the certificate information. Vigor2920 Series User’s Guide...
  • Page 230: Certificate Backup

    The more bandwidth a codec uses the better the voice quality, however the codec used must be appropriate for your Internet bandwidth. Usually there will be two types of calling scenario, as illustrated below: Vigor2920 Series User’s Guide...
  • Page 231 QoS Assurance assists to assign high priority to voice traffic via Internet. You will always have the required inbound and outbound bandwidth that is prioritized exclusively for Voice traffic over Internet but you just get your data a little slower and it is tolerable for data traffic. Vigor2920 Series User’s Guide...
  • Page 232: Dialplan

    Note: If the incoming or outgoing calls do not match any entry on the phonebook, the router will try to make the call "being protected". But, if the call ends up "unprotected"(e.g. peer side does not support ZRTP+SRTP), the router will not play out a warning message. Vigor2920 Series User’s Guide...
  • Page 233 The speed-dial number of this index. This can be any number Phone Number you choose, using digits 0-9 and * . The name entered here is to remind the user whose number it Display Name Enter your friend’s SIP Address. SIP URL Vigor2920 Series User’s Guide...
  • Page 234 "being protected". But, if the call ends up "unprotected"(e.g. peer side does not support ZRTP+SRTP), the router will not play out a warning message. Vigor2920 Series User’s Guide...
  • Page 235 VoIP interface. Take the above picture (Prefix Table Setup web page) as an example, the prefix number of 03 will be replaced by 8863. For example: dial number of “031111111” will be changed to “88631111111” and sent to SIP server. Vigor2920 Series User’s Guide...
  • Page 236 Click the link to move the selected entry up or down. Move UP /Move Down Call barring is used to block phone calls coming from the one that is not welcomed. Each item is explained as follows: Vigor2920 Series User’s Guide...
  • Page 237 Determine the direction for the phone call, IN – incoming call, Call Direction OUT-outgoing call, IN & OUT – both incoming and outgoing calls. Determine the type of the VoIP phone call, URI/URL or Barring Type number. Vigor2920 Series User’s Guide...
  • Page 238 SIP accounts. Such control also can be done based on preconfigured schedules. For Block IP Address – this function can block incoming calls (through Phone port) coming from IP address. Such control also can be done based on preconfigured schedules. Vigor2920 Series User’s Guide...
  • Page 239 Please dial number typed in this field to call back to that one. Dial the number typed in this field to call the previous Last Call Return [Out] outgoing phone call again. Vigor2920 Series User’s Guide...
  • Page 240 IP address. Dial the number typed in this field to release this function. Block IP Calls [Deact] Dial the number typed in this field to block the last incoming Block Last Calls [Act] phone call. Vigor2920 Series User’s Guide...
  • Page 241: Sip Accounts

    As Vigor VoIP Router is turned on, it will first register with Registrar using AuthorizationUser@Domain/Realm. After that, your call will be bypassed by SIP Proxy to the destination using AccountName@Domain/Realm as identity. Note: Selection items for Ring Port will differ according to the router you have. Vigor2920 Series User’s Guide...
  • Page 242 By the way, ISDN-S0 can be used by mapping with MSN numbers. Show the status for the corresponding SIP account. R means Status such account is registered on SIP server successfully. – means the account is failed to register on SIP server. Vigor2920 Series User’s Guide...
  • Page 243 Item Description Assign a name for this profile for identifying. You can type Profile Name similar name with the domain. For example, if the domain name is draytel.org, then you might set draytel-1 in this field. Vigor2920 Series User’s Guide...
  • Page 244 The password provided to you when you registered with a SIP Password service. The time duration that your SIP Registrar server keeps your Expiry Time registration record. Before the time expires, the router will send another register request to SIP Registrar again. Vigor2920 Series User’s Guide...
  • Page 245 If your upstream speed is only 64Kbps, do not use G.711 codec. It is better for you to have at least 256Kbps upstream if you would like to use G.711. Single Codec – If the box is checked, only the selected Codec will be applied. Vigor2920 Series User’s Guide...
  • Page 246: Phone Settings

    Tone - Display the tone settings that configured in the advanced settings page of Phone Index. Gain - Display the volume gain settings for Mic/Speaker that configured in the advanced settings page of Phone Index. Vigor2920 Series User’s Guide...
  • Page 247 Dynamic RTP Port End - Specifies the end port for RTP stream. The default value is 15000. RTP TOS – It decides the level of VoIP package. Use the drop down list to choose any one of them. Vigor2920 Series User’s Guide...
  • Page 248 Check the box to enable T.38 fax function. T.38 Fax Function Error Correction Mode – choose a mode for error correction. Vigor2920 Series User’s Guide...
  • Page 249 Wrong tone settings might cause inconvenience for users. To set the sound pattern of the phone set, simply choose a proper region to let the system find out the preset tone settings and caller ID type automatically. Or you can adjust tone settings Vigor2920 Series User’s Guide...
  • Page 250 Congestion tone will be shown automatically on the page. If you cannot find out a suitable one, please choose User Defined and fill out the corresponding values for dial tone, ringing tone, busy tone, congestion tone by yourself for VoIP phone. Vigor2920 Series User’s Guide...
  • Page 251 DTMF tone and transfer it into SIP form. Then it will be sent to the remote end with SIP message. Payload Type (rfc2833) - Choose a number from 96 to 127, the default value was 101. This setting is available for the OutBand (RFC2833) mode. Vigor2920 Series User’s Guide...
  • Page 252: Status

    WAIT_ANS - Indicates that a connection is launched and waiting for remote user’s answer. ALERTING - Indicates that a call is coming. ACTIVE-Indicates that the VoIP connection is launched. Indicates the voice codec employed by present channel. Codec Vigor2920 Series User’s Guide...
  • Page 253: Wireless Lan

    Point (AP) connecting to lots of wireless clients or Stations (STA). All the STAs will share the same Internet connection via Vigor wireless router. The General Settings will set up the information of this wireless network, including its SSID as identification, located channel etc. Vigor2920 Series User’s Guide...
  • Page 254 LAN from wired LAN for either quarantine or limit access reasons. To isolate means neither of the parties can access each other. To elaborate an example for business use, you may set up a wireless LAN for visitors only so they can connect to Internet without hassle of Vigor2920 Series User’s Guide...
  • Page 255: General Setup

    Below shows the menu items for Wireless LAN. By clicking the General Settings, a new web page will appear so that you could configure the SSID and the wireless channel. Please refer to the following figure for more information. Vigor2920 Series User’s Guide...
  • Page 256 Means the identification of the wireless LAN. SSID can be any SSID text numbers or various special characters. The default SSID is "DrayTek”. We suggest you to change it. VPN – Check this box to make the wireless clients (stations) Isolate with different VPN not accessing for each other.
  • Page 257 Therefore, you can use and install it into your PC for matching with Packet-OVERDRIVE (refer to the following picture of Vigor N61 wireless utility window, choose Enable for TxBURST on the tab of Option). Note: * means the real transmission rate depends on the Vigor2920 Series User’s Guide...
  • Page 258 It controls the data transmission rate through wireless Rate Control connection. Upload – Check Enable and type the transmitting rate for data upload. Default value is 30,000 kbps. Download – Type the transmitting rate for data download. Default value is 30,000 kbps. Vigor2920 Series User’s Guide...
  • Page 259: Security

    Internet through such router, please input the default PSK value for connection. By clicking the Security Settings, a new web page will appear so that you could configure the settings of WEP and WPA. Available settings are explained as follows: Item Description Vigor2920 Series User’s Guide...
  • Page 260 012345678(or 64 Hexadecimal digits leading by 0x, such as "0x321253abcde..."). Type - Select from Mixed (WPA+WPA2) or WPA2 only. Pre-Shared Key (PSK) - Either 8~63 ASCII characters, such as 012345678..(or 64 Hexadecimal digits leading by 0x, such as "0x321253abcde..."). Vigor2920 Series User’s Guide...
  • Page 261: Access Control

    Item Description Select to enable the MAC Address filter for wireless LAN Enable Mac Address identified with SSID 1 to 4 respectively. All the clients Filter (expressed by MAC addresses) listed in the box can be Vigor2920 Series User’s Guide...
  • Page 262 Delete Edit the selected MAC address in the list. Edit Give up the access control set up. Cancel Click it to save the access control list. Clean all entries in the MAC address list. Clear All Vigor2920 Series User’s Guide...
  • Page 263: Wps

    On the side of Vigor 2920 series which served as an AP, press WPS button once on the front panel of the router or click Start PBC on web configuration interface. On the side of a station with network card installed, press Start PBC button of network card. Vigor2920 Series User’s Guide...
  • Page 264 Please click OK and go back Wireless LAN>>Security to choose WPA-PSK or WPA2-PSK mode and access WPS again. Below shows Wireless LAN>>WPS web page. Available settings are explained as follows: Item Description Check this box to enable WPS setting. Enable WPS Vigor2920 Series User’s Guide...
  • Page 265 Start PIN button. The WPS LED on the PinCode router will blink fast when WPS is in progress. It will return to normal condition after two minutes. (You need to setup WPS within two minutes) Vigor2920 Series User’s Guide...
  • Page 266: Wds

    To meet the above requirement, two WDS modes are implemented in Vigor router. One is Bridge, the other is Repeater. Below shows the function of WDS-bridge interface: The application for the WDS-Repeater mode is depicted as below: Vigor2920 Series User’s Guide...
  • Page 267 Bridge 2 through WDS links. However, hosts connected to Bridge 1 CANNOT communicate with hosts connected to Bridge 3 through Bridge 2. Click WDS from Wireless LAN menu. The following page will be shown. Vigor2920 Series User’s Guide...
  • Page 268 Type – There are some types for you to choose. WPA and Pre-shared Key WPA2 are used for WDS devices (e.g.2920n wireless router, you can set the encryption mode as WPA or WPA2 to establish your WDS system between AP and the router. Vigor2920 Series User’s Guide...
  • Page 269 Click Enable to make this router serving as an access point; Access Point Function click Disable to cancel this function. It allows user to send “hello” message to peers. Yet, it is valid Status only when the peer also supports this function. Vigor2920 Series User’s Guide...
  • Page 270: Advanced Setting

    (increasing the wireless performance) or long guard interval for data transmit based on the station capability. combine frames with different Aggregation MSDU can Aggregation MSDU sizes. It is used for improving MAC layer’s performance for some brand’s clients. The default setting is Enable. Vigor2920 Series User’s Guide...
  • Page 271: Wmm Configuration

    1 to 15. Be aware that CWMax value must be greater than CWMin or equals to CWMin value. Both values will influence the time delay for WMM accessing categories. The difference between AC_VI and AC_VO categories must be Vigor2920 Series User’s Guide...
  • Page 272: Ap Discovery

    This page is used to scan the existence of the APs on the wireless LAN. Yet, only the AP which is in the same channel of this router can be found. Please click Scan to discover all the connected APs. Vigor2920 Series User’s Guide...
  • Page 273 AP’s MAC address on the bottom of the page and click Bridge or Repeater. Next, click Add to. Later, the MAC address of the AP will be added to Bridge or Repeater field of WDS settings page. Vigor2920 Series User’s Guide...
  • Page 274: Station List

    Vigor router and username/password created in USB Application>>USB User Management on the client software. Then, the client can use the FTP site (USB storage disk) or share the Samba service through Vigor router. Vigor2920 Series User’s Guide...
  • Page 275: Usb General Settings

    Samba Service Settings LAN Only – Users coming from internet cannot connect to Access Mode the samba server of the router. LAN And WAN - Both LAN and WAN users can access samba server of the router. Vigor2920 Series User’s Guide...
  • Page 276: Usb User Management

    Display the number link of the profile. Index Display the name that FTP/Samba users will use for accessing Username into FTP/Samba server. Display the home folder of this entry. Home Folder Click it to clear all profiles settings. Set to Factory Default Vigor2920 Series User’s Guide...
  • Page 277 USB storage disk. Note: When write protect status for the USB storage disk is ON, you cannot type any new folder name in this field. Only “/” can be used in such case. Vigor2920 Series User’s Guide...
  • Page 278: File Explorer

    File Explorer offers an easy way for users to view and manage the content of USB storage disk connected on Vigor router. Available settings are explained as follows: Item Description Click this icon to refresh files list. Refresh Vigor2920 Series User’s Guide...
  • Page 279: Usb Disk Status

    FTP server. Display the username that user uses to login to the FTP server. Username When you insert USB storage disk into the Vigor router, the system will start to find out such device within several seconds. Vigor2920 Series User’s Guide...
  • Page 280: Syslog Explorer

    Always record the new event – only the newest events will be recorded by the system. Display the time of the event occurred. Time Display the information for each event. Message Vigor2920 Series User’s Guide...
  • Page 281 This page displays the syslog recorded on the USB storage disk. Each item is explained as follows: Item Description Display the time of the event occurred. Time Display the type of the record. Log Type Display the information for each event. Message Vigor2920 Series User’s Guide...
  • Page 282: System Maintenance

    WAN interface information. Also, you could get the current running firmware version or firmware related information from this presentation. Each item is explained as follows: Item Description Display the model name of the router. Model Name Display the firmware version of the router. Firmware Version Vigor2920 Series User’s Guide...
  • Page 283 - Display the IP address of the WAN interface. Default Gateway - Display the assigned IP address of the default gateway. VoIP Profile - Display the VoIP profile for the phone port. In/Out - Display the number of incoming /outgoing phone call. Vigor2920 Series User’s Guide...
  • Page 284: Https Encryption Setup

    Available parameters are explained as follows: Item Description Choose this option to have high security. High If you have no idea of this setting, simply use the default Default setting as HTTPS encryption mode. Choose this option to have high performance. Vigor2920 Series User’s Guide...
  • Page 285: 277

    Disable to close the mechanism of notification. The default is Disable. If you click Enable, please type the STUN Settings relational settings listed below: Server IP – Type the IP address of the STUN server. Vigor2920 Series User’s Guide...
  • Page 286: Administrator Password

    Type in new password in this field. New Password Type in the new password again. Confirm Password When you click OK, the login window will appear. Please use the new password to access into the web configurator again. Vigor2920 Series User’s Guide...
  • Page 287: User Password

    Below shows an example for accessing into User Operation with User Password. 1. Open System Maintenance>>User Password. 2. Check the box of Enable User Mode for simple web configuration to enable user mode operation. Type a new password in the field of New Password and click OK. Vigor2920 Series User’s Guide...
  • Page 288 5. The following window will be open to ask for username and password. Type the new user password in the filed of Password and click Login. 6. The main screen with User Mode will be shown as follows. Vigor2920 Series User’s Guide...
  • Page 289: Configuration Backup

    Setting in User Mode can be configured as same as in Admin Mode. Follow the steps below to backup your configuration. Go to System Maintenance >> Configuration Backup. The following windows will be popped-up, as shown below. Vigor2920 Series User’s Guide...
  • Page 290 The above example is using Windows platform for demonstrating examples. The Mac or Linux platform will appear different windows, but the backup function is still available. Note: Backup for Certification must be done independently. The Configuration Backup does not include information of Certificate. Vigor2920 Series User’s Guide...
  • Page 291: Syslog/Mail Alert

    Web Configurator of the router or borrow debug equipments. Available parameters are explained as follows: Item Description Enable - Check Enable to activate function of syslog. SysLog Access Setup Syslog Save to – Check Syslog Server to save the log to Vigor2920 Series User’s Guide...
  • Page 292 For viewing the Syslog, please do the following: Just set your monitor PC’s IP address in the field of Server IP Address Install the Router Tools in the Utility within provided CD. After installation, click on the Router Tools>>Syslog from program menu. Vigor2920 Series User’s Guide...
  • Page 293: Time And Date

    Select this option to use the browser time from the remote Use Browser Time administrator PC host as router’s system time. Select to inquire time information from Time Server on the Use Internet Time Internet using assigned protocol. Select a time protocol. Time Protocol Vigor2920 Series User’s Guide...
  • Page 294: Management

    Internet. Check the box(es) to specify. Check the checkbox to reject all PING packets from the Disable PING from the Internet. For security issue, this function is enabled by default. Internet Vigor2920 Series User’s Guide...
  • Page 295: Reboot System

    Set the IP address of the host that will receive the trap Notification Host IP community. The default setting is 10 seconds. Trap Timeout The Web Configurator may be used to restart your router. Click Reboot System from System Maintenance to open the following page. Vigor2920 Series User’s Guide...
  • Page 296 Note: When the system pops up Reboot System web page after you configure web settings, please click Reboot Now to reboot your router for ensuring normal operation and preventing unexpected errors of the router in the future. Vigor2920 Series User’s Guide...
  • Page 297: Firmware Upgrade

    You have to visit DrayTek website periodically to check if there is any new released firmware offered for your Vigor router to have newest features. If yes, download the file into your computer first. Next, access into web interface of this router and open System Maintenance>> Firmware Upgrade.
  • Page 298: Activation

    The Activate link brings you accessing into Activate www.vigorpro.com to finish the activation of the account and the router. As for authentication information of web filter, the process Authentication Message of authenticating will be displayed on this field for your reference. Vigor2920 Series User’s Guide...
  • Page 299: Diagnostics

    Below shows the successful activation of Web Content Filter: Diagnostic Tools provide a useful way to view or diagnose the status of your Vigor router. Below shows the menu items for Diagnostics. Vigor2920 Series User’s Guide...
  • Page 300: Dial-Out Triggering

    Click it to reload the page. Refresh Click Diagnostics and click Routing Table to open the web page. Each item is explained as follows: Item Description Click it to reload the page. Refresh Vigor2920 Series User’s Guide...
  • Page 301: Arp Cache Table

    The facility provides information on IP address assignments. This information is helpful in diagnosing network problems, such as IP address conflicts, etc. Click Diagnostics and click DHCP Table to open the web page. Each item is explained as follows: Item Description Display the connection item number. Index Vigor2920 Series User’s Guide...
  • Page 302: Nat Sessions Table

    It indicates the temporary port of the router used for NAT. #Pseudo Port It indicates the destination IP address and port of remote host. Peer IP:Port It displays the representing number for different interface. Interface Click it to reload the page. Refresh Vigor2920 Series User’s Guide...
  • Page 303: Data Flow Monitor

    Description Check this box to enable this function. Enable Data Flow Monitor Use the drop down list to choose the time interval of Refresh Seconds refreshing data flow that will be done by the system automatically. Vigor2920 Series User’s Guide...
  • Page 304 Peak means the highest peak value detected by the router in data transmission. Speed means line speed specified in WAN>>General Setup. If you do not specify any rate at that page, here will display Auto for instead. Vigor2920 Series User’s Guide...
  • Page 305: Traffic Graph

    WAN1/WAN2/WAN3 Bandwidth chart, the numbers displayed on vertical axis represent the numbers of the transmitted and received packets in the past. For Sessions chart, the numbers displayed on vertical axis represent the numbers of the NAT sessions during the past. Vigor2920 Series User’s Guide...
  • Page 306: Ping Diagnosis

    Type in the IP address of the Host/IP that you want to ping. IP Address Click this button to start the ping work. The result will be displayed on the screen. Click this link to remove the result on the window. Clear Vigor2920 Series User’s Guide...
  • Page 307: Trace Route

    Use the drop down list to choose the protocol that you want to Protocol ping through. It indicates the IP address of the host. Host/IP Address Click this button to start route tracing work. Click this link to remove the result on the window. Clear Vigor2920 Series User’s Guide...
  • Page 308: Syslog Explorer

    Always record the new event – only the newest events will be recorded by the system. Display the time of the event occurred. Time Display the information for each event. Message Vigor2920 Series User’s Guide...
  • Page 309: External Devices

    You can change the device name if required or remove the information for off-line device whenever you want. When you finished the configuration, click OK to save it. Note: Only DrayTek products can be detected by this function. Vigor2920 Series User’s Guide...
  • Page 310 This page is left blank. Vigor2920 Series User’s Guide...
  • Page 311: Trouble Shooting

    Turn on the router. Make sure the ACT LED blink once per second and the correspondent LAN LED is bright. If not, it means that there is something wrong with the hardware status. Simply back to “1.3 Hardware Installation” to execute the hardware installation again. And then, try again. Vigor2920 Series User’s Guide...
  • Page 312: Checking If The Network Connection Settings On Your Computer Is Ok Or Not

    Go to Control Panel and then double-click on Network Connections. Right-click on Local Area Connection and click on Properties. Select Internet Protocol (TCP/IP) and then click Properties. Vigor2920 Series User’s Guide...
  • Page 313 Select Obtain an IP address automatically and Obtain DNS server address automatically. Double click on the current used Mac OS on the desktop. Open the Application folder and get into Network. On the Network screen, select Using DHCP from the drop down list of Configure IPv4. Vigor2920 Series User’s Guide...
  • Page 314: Pinging The Router From Your Computer

    Open the Application folder and get into Utilities. Double click Terminal. The Terminal window will appear. Type ping 192.168.1.1 and press [Enter]. If the link is OK, the line of “64 bytes from 192.168.1.1: icmp_seq=0 ttl=255 time=xxxx ms” will appear. Vigor2920 Series User’s Guide...
  • Page 315: Checking If The Isp Settings Are Ok Or Not

    PIN code and try again. If it still fails, it might be the compliance problem of system. Please open DrayTek Syslog Tool to capture the connection information (WAN Log) and send the page (similar to the following graphic) to the service center of DrayTek.
  • Page 316: Backing To Factory Default Setting If Necessary

    Go to System Maintenance and choose Reboot System on the web page. The following screen will appear. Choose Using factory default configuration and click OK. After few seconds, the router will return all the settings to the factory settings. Vigor2920 Series User’s Guide...
  • Page 317: Contacting Your Dealer

    After restore the factory default setting, you can configure the settings for the router again to fit your personal request. If the router still cannot work correctly after trying many efforts, please contact your dealer for further help right away. For any questions, please feel free to send e-mail to support@DrayTek.com. Vigor2920 Series User’s Guide...

This manual is also suitable for:

Vigor2920nVigor2920vn

Table of Contents