Please refer to www.zyxel.com for additional support documentation and product certifications. Documentation Feedback Send your comments, questions or suggestions to: techwriters@zyxel.com.tw Thank you! The Technical Writing Team, ZyXEL Communications Corp. Need More Help? More help is available at www.zyxel.com. • Download Library Search for the latest product updates and documentation from this link.
Graphics in this book may differ slightly from the product due to differences in operating systems, operating system versions, or if you installed updated firmware/software for your device. Every effort has been made to ensure that the information in this manual is accurate. AMG1202-T10A User’s Guide...
Syntax Conventions • The AMG1202-T10A may be referred to as the “ZyXEL Device”, the “device”, the “system” or the “product” in this User’s Guide. • Product labels, screen names, field labels and field choices are all in bold font.
Your product is marked with this symbol, which is known as the WEEE mark. WEEE stands for Waste Electronics and Electrical Equipment. It means that used electrical and electronic products should not be mixed with general waste. Used electrical and electronic equipment should be treated separately. AMG1202-T10A User’s Guide...
2.1.1 Accessing the Web Configurator ................27 2.2 The Main Screen ........................29 2.2.1 Title Bar ........................29 2.2.2 Navigation Panel ......................30 2.2.3 Main Window ......................31 2.2.4 Status Bar ........................31 Chapter 3 Status Screens ........................33 3.1 Overview ..........................33 3.2 The Status Screen ........................33 AMG1202-T10A User’s Guide...
Page 12
6.2.1 Advanced Internet Access Setup ................73 6.3 The More Connections Screen ....................74 6.3.1 More Connections Edit ....................76 6.3.2 Configuring More Connections Advanced Setup ............78 6.4 WAN Technical Reference ....................79 6.4.1 Encapsulation ......................79 6.4.2 Multiplexing .........................80 6.4.3 VPI and VCI ........................80 AMG1202-T10A User’s Guide...
Page 13
8.2.4 WPA(2) Authentication ....................103 8.2.5 Wireless LAN Advanced Setup ................104 8.2.6 MAC Filter ......................106 8.3 The More AP Screen ......................107 8.3.1 More AP Edit ......................108 8.4 The WPS Screen .......................108 8.5 The WPS Station Screen ....................110 AMG1202-T10A User’s Guide...
Page 14
10.1.2 What You Need to Know About Firewall ..............139 10.2 The Firewall Screen ......................141 Chapter 11 Filters ............................. 143 11.1 Overview .........................143 11.1.1 What You Can Do in the Filter Screens ..............143 11.1.2 What You Need to Know About Filtering ..............143 AMG1202-T10A User’s Guide...
Page 15
15.1.1 What You Can Do in the DDNS Screen ..............167 15.1.2 What You Need To Know About DDNS ..............167 15.2 The Dynamic DNS Screen ....................168 Chapter 16 Remote Management......................169 16.1 Overview ..........................169 16.1.1 What You Can Do in the Remote Management Screens ........170 AMG1202-T10A User’s Guide...
Page 16
Chapter 20 Tools ............................203 20.1 Overview ..........................203 20.1.1 What You Can Do in the Tool Screens ..............203 20.2 The Firmware Screen .......................203 20.3 The Configuration Screen ....................206 20.4 The Restart Screen ......................208 Chapter 21 Diagnostic ..........................209 AMG1202-T10A User’s Guide...
Page 17
Appendix A Setting up Your Computer’s IP Address ............225 Appendix B IP Addresses and Subnetting................247 Appendix C Pop-up Windows, JavaScripts and Java Permissions ........255 Appendix D Wireless LANs....................265 Appendix E Services......................279 Appendix F Legal Information....................283 Index ............................287 AMG1202-T10A User’s Guide...
Page 18
Table of Contents AMG1202-T10A User’s Guide...
Introduction 1.1 Overview The AMG1202-T10A is an ADSL2+ router. By integrating DSL and NAT, you are provided with ease of installation and high-speed, shared Internet access. The AMG1202-T10A is also a complete security solution with a robust firewall and content filtering.
1.5 Wireless Access The ZyXEL Device is a wireless Access Point (AP) for wireless clients, such as notebook computers or PDAs and iPads. It allows them to connect to the Internet without having to rely on inconvenient Ethernet cables. AMG1202-T10A User’s Guide...
Press the WPS button on another WPS-enabled device within range of the ZyXEL Device. The WPS/ WLAN LED should flash while the ZyXEL Device sets up a WPS connection with the other wireless device. Once the connection is successfully made, the WPS/WLAN LED shines green. AMG1202-T10A User’s Guide...
The ZyXEL Device attempted to make an IP connection but failed. Possible causes are no response from a DHCP server, no PPPoE response, PPPoE authentication failed. The ZyXEL Device does not have an IP connection. Refer to the Quick Start Guide for information on hardware connections. AMG1202-T10A User’s Guide...
To set the device back to the factory default settings, press the RESET button for ten seconds or until the POWER LED begins to blink and then release it. When the POWER LED begins to blink, the defaults have been restored and the device restarts. AMG1202-T10A User’s Guide...
Device, type the admin password (1234 by default) in the password screen and click Login. Click Cancel to revert to the default user password in the password field. If you have changed the password, enter your password and click Login. Figure 4 Password Screen AMG1202-T10A User’s Guide...
Page 28
Go to Advanced setup and click Apply to display the Status screen. Figure 6 Replace Factory Default Certificate Screen Note: For security reasons, the ZyXEL Device automatically logs you out if you do not use the web configurator for five minutes (default). If this happens, log in again. AMG1202-T10A User’s Guide...
Table 2 Web Configurator Icons in the Title Bar ICON DESCRIPTION Wizards: Click this icon to go to the configuration wizards. See Chapter 5 on page for more information. Logout: Click this icon to log out of the web configurator. AMG1202-T10A User’s Guide...
Use this screen to activate 802.1Q/1P, specify the management VLAN group, display the VLAN groups and configure the settings for each VLAN group. Port Setting Use this screen to configure the PVID and assign traffic priority for each port. AMG1202-T10A User’s Guide...
Right after you log in, the Status screen is displayed. See Chapter 3 on page 33 for more information about the Status screen. 2.2.4 Status Bar Check the status bar when you click Apply or OK to verify that the configuration has been updated. AMG1202-T10A User’s Guide...
Page 32
Chapter 2 The Web Configurator AMG1202-T10A User’s Guide...
Figure 8 Status Screen Each field is described in the following table. Table 4 Status Screen LABEL DESCRIPTION Refresh Interval Select how often you want the ZyXEL Device to update this screen. Apply Click this to update this screen immediately. AMG1202-T10A User’s Guide...
Page 34
Status This displays whether WLAN is activated. Security Firewall This displays whether or not the ZyXEL Device’s firewall is activated. Click this to go to the screen where you can change it. System Status AMG1202-T10A User’s Guide...
Page 35
For the LAN interface, this displays the port speed and duplex setting. For the DSL interface, it displays the downstream and upstream transmission rate. For the WLAN interface, it displays the maximum transmission rate when WLAN is enabled or N/A when WLAN is disabled. AMG1202-T10A User’s Guide...
Page 36
Chapter 3 Status Screens AMG1202-T10A User’s Guide...
38) or manual configuration (Section 4.2.3 on page 42). 4.2.1 Configuring the Wireless Network Settings This example uses the following parameters to set up a wireless network. SSID Example Security Mode WPA-PSK Pre-Shared Key DoNotStealMyWirelessNetwork 802.11 Mode 802.11b+g+n AMG1202-T10A User’s Guide...
This section shows you how to set up a wireless network using WPS. It uses the ZyXEL Device as the AP and ZyXEL NWD210N as the wireless client which connects to the notebook. Note: The wireless client must be a WPS-aware device (for example, a WPS USB adapter or PCMCIA card). AMG1202-T10A User’s Guide...
Page 39
The ZyXEL Device sends the proper configuration settings to the wireless client. This may take up to two minutes. The wireless client is then able to communicate with the ZyXEL Device securely. AMG1202-T10A User’s Guide...
When you use the PIN configuration method, you need to use both the ZyXEL Device’s web configurator and the wireless client’s utility. Launch your wireless client’s configuration utility. Go to the WPS settings and select the PIN method to get a PIN number. AMG1202-T10A User’s Guide...
Page 41
The ZyXEL Device authenticates the wireless client and sends the proper configuration settings to the wireless client. This may take up to two minutes. The wireless client is then able to communicate with the ZyXEL Device securely. AMG1202-T10A User’s Guide...
WITHIN 2 MINUTES Authentication by PIN SECURITY INFO COMMUNICATION 4.2.3 Without WPS Use the wireless adapter’s utility installed on the notebook to search for the “Example” SSID. Then enter the “DoNotStealMyWirelessNetwork” pre-shared key to establish an wireless Internet connection. AMG1202-T10A User’s Guide...
Thomas mostly uses his notebook to access the Internet on weekends; occasionally he uses it at night on weekdays. Here is how Thomas can set up a schedule to turn on the wireless network at specific time and days. Click Network > Wireless Network > Scheduling to open the following screen. AMG1202-T10A User’s Guide...
He decided to prevent Josephine from accessing the Internet so that she can concentrate on preparing for her final exams. Josephine’s computer connects wirelessly to the Internet through the ZyXEL Device. Thomas can deny access to the wireless network using the MAC address of Josephine’s computer. Thomas Josephine AMG1202-T10A User’s Guide...
Page 45
Click Network > LAN > Client List to open the following screen. Look for the MAC address of Josephine’s computer. Click Network > Wireless LAN to open the AP screen. Click the Edit button in the MAC Filter field. AMG1202-T10A User’s Guide...
In the following figure, router R is connected to the ZyXEL Device’s LAN. R connects to two networks, N1 (192.168.1.x/24) and N2 (192.168.10.x/24). If you want to send traffic from AMG1202-T10A User’s Guide...
Page 47
B. This tutorial uses the following example IP settings: Table 5 IP Settings in this Tutorial DEVICE / COMPUTER IP ADDRESS The ZyXEL Device’s WAN 172.16.1.1 The ZyXEL Device’s LAN 192.168.1.1 192.168.1.34 R’s N1 192.168.1.253 AMG1202-T10A User’s Guide...
Page 48
Type 192.168.1.253 (R’s N1 address) in the Gateway IP Address field. Click Apply. Now B should be able to receive traffic from A. You may need to additionally configure B’s firewall settings to allow specific traffic to pass through. AMG1202-T10A User’s Guide...
Use this setting if your applications can use random public IP addresses and the applications are initiated from the Intranet computers (A and B). For example, VoIP application. See Section 4.5.2 on page 51 if it is not. IP-1 AMG1202-T10A User’s Guide...
Page 50
Click the Address Mapping tab, and then click the Edit icon on a new rule. Configure the rule using the following settings: • Type: Many-to-Many No Overload • Local IP addresses: 192.168.1.2 ~ 192.168.1.3 • Global IP addresses: 172.16.1.253 ~ 172.16.1.254 Then click Apply. AMG1202-T10A User’s Guide...
• Rule 1 (This maps the public IP address 172.16.1.253 to the private IP address 192.168.1.2) Type: One-to-One Local Start IP: 192.168.1.2 Global Start IP: 172.16.1.253 • Rule 2 (This maps the public IP address 172.16.1.254 to the private IP address 192.168.1.3) Type: One-to-One Local Start IP: 192.168.1.3 AMG1202-T10A User’s Guide...
• The connection with VPI/VCI, 0/33, is dedicated for Media-On-Demand (MOD) service. • The connection with VPI/VCI, 0/34, is dedicated for VoIP service. • The connection with VPI/VCI, 0/35, is dedicated for general data transmission. Figure 9 Example for Multiple WAN Connections AMG1202-T10A User’s Guide...
After you enter the password to access the web configurator, select Go to Wizard setup and click Apply. Otherwise, click the wizard icon ( ) in the top right corner of the web configurator to go to the wizards. Figure 10 Select a Mode AMG1202-T10A User’s Guide...
Page 56
ISP. See Section 5.2.1 on page 58 for more details. If you would like to skip your Internet setup and configure the wireless LAN settings, leave Yes selected and click Next. Figure 12 Auto Detection: No DSL Connection AMG1202-T10A User’s Guide...
Page 57
The following screen appears if the ZyXEL device detects a connection but not the connection type. Click Next and refer to Section 5.2.1 on page 58 on how to manually configure the ZyXEL Device for Internet access. Figure 14 Auto Detection: Failed AMG1202-T10A User’s Guide...
VC-based or LLC-based. Virtual Circuit VPI (Virtual Path Identifier) and VCI (Virtual Channel Identifier) define a virtual circuit. Refer to the appendix for more information. Enter the VPI assigned to you. This field may already be configured. AMG1202-T10A User’s Guide...
Page 59
The next wizard screen varies depending on what mode and encapsulation type you use. All screens shown are with routing mode. Configure the fields and click Next to continue. See Section 5.3 on page 63 for wireless connection wizard setup Figure 16 Internet Connection with PPPoE AMG1202-T10A User’s Guide...
Page 60
Type the name of your PPPoE service here. Back Click this to return to the previous screen without saving. Apply Click this to save your changes. Exit Click this to close the wizard screen without saving. Internet Connection with RFC 1483 Figure 17 AMG1202-T10A User’s Guide...
Page 61
Click this to return to the previous screen without saving. Next Click this to continue to the next wizard screen. Exit Click this to close the wizard screen without saving. Figure 18 Internet Connection with ENET ENCAP AMG1202-T10A User’s Guide...
Page 62
Table 11 Internet Connection with PPPoA LABEL DESCRIPTION User Name Enter the login name that your ISP gives you. Password Enter the password associated with the user name above. Back Click this to return to the previous screen without saving. AMG1202-T10A User’s Guide...
• If the following screen displays, check if your account is activated or click Restart the Internet/ Wireless Setup Wizard to verify your Internet access settings. Figure 21 Connection Test Failed-2. 5.3 Wireless Connection Wizard Setup After you configure the Internet access information, use the following screens to set up your wireless LAN. AMG1202-T10A User’s Guide...
Page 64
Select the check box to turn on the wireless LAN. Back Click this to return to the previous screen without saving. Next Click this to continue to the next wizard screen. Exit Click this to close the wizard screen without saving. AMG1202-T10A User’s Guide...
Page 65
WEP encryption key (if WEP is enabled), WPA-PSK (if WPA-PSK is enabled) for wireless communication. This screen varies depending on the security mode you selected in the previous screen. Fill in the field (if available) and click Next. AMG1202-T10A User’s Guide...
Click this to continue to the next wizard screen. Exit Click this to close the wizard screen without saving. 5.3.2 Manually Assign a WEP Key Choose Manually assign a WEP key to setup WEP Encryption parameters. Figure 26 Manually Assign a WEP key AMG1202-T10A User’s Guide...
Page 67
Click Apply to save your wireless LAN settings. Figure 27 Wireless LAN Setup 3 Use the read-only summary table to check whether what you have configured is correct. Click Finish to complete and save the wizard setup. AMG1202-T10A User’s Guide...
Page 68
Refer to the rest of this guide for more detailed information on the complete range of ZyXEL Device features. If you cannot access the Internet, open the web configurator again to confirm that the Internet settings you configured in the wizard setup are correct. AMG1202-T10A User’s Guide...
WAN IP Address The WAN IP address is an IP address for the ZyXEL Device, which makes it accessible from an outside network. It is used by the ZyXEL Device to communicate with other devices in other AMG1202-T10A User’s Guide...
Finding Out More Section 6.4 on page 79 for technical background information on WAN. 6.1.3 Before You Begin You need to know your Internet access settings such as encapsulation and WAN IP address. Get this information from your ISP. AMG1202-T10A User’s Guide...
Other options are ADSL2+, ADSL2, G.DMT, T1.413 and G.lite. ADSL Type Select the type supported by your ISP. Available options are ANNEX A, ANNEX A/L, ANNEX M and ANNEX A/L/M. General AMG1202-T10A User’s Guide...
Page 72
Max Idle Timeout Specify an idle time-out in the Max Idle Timeout field when you select Connect on Demand. The default setting is 0, which means the Internet session will not timeout. Apply Click this to save your changes. AMG1202-T10A User’s Guide...
Select the RIP direction from None, Both, In Only and Out Only. RIP Version This field is not configurable if you select None in the RIP Direction field. Select the RIP version from RIP-1, RIP-2B and RIP-2M. AMG1202-T10A User’s Guide...
Click this to restore your previously saved settings. 6.3 The More Connections Screen The ZyXEL Device allows you to configure more than one Internet access connection. To configure additional Internet access connections click Network > WAN > More Connections. The screen AMG1202-T10A User’s Guide...
Page 75
Internet access setup. Click the Remove icon to delete the Internet access setup from your connection list. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
Select Routing from the drop-down list box if your ISP allows multiple computers to share an Internet account. If you select Bridge, the ZyXEL Device will forward any packet that it does not route to this remote node; otherwise, the packets are discarded. AMG1202-T10A User’s Guide...
Page 77
Select SUA Only if you have one public IP address and want to use NAT. Click Edit Detail to go to the Port Forwarding screen to edit a server mapping set. Otherwise, select None to disable NAT. AMG1202-T10A User’s Guide...
Type the SCR, which must be less than the PCR. Note that system default is 0 cells/sec. Maximum Burst Size Maximum Burst Size (MBS) refers to the maximum number of cells that can be sent at the peak rate. Type the MBS, which is less than 65535. AMG1202-T10A User’s Guide...
This enables the service provider to easily create and offer new IP services for individuals. Operationally, PPPoE saves significant effort for both you and the ISP or carrier, as it requires no specific configuration of the broadband modem at the customer site. AMG1202-T10A User’s Guide...
The Single User Account feature can be enabled or disabled if you have either a dynamic or static IP. However the encapsulation method assigned influences your choices for IP address and ENET ENCAP gateway. AMG1202-T10A User’s Guide...
Sustained Cell Rate (SCR) is the mean cell rate of each bursty traffic source. It specifies the maximum average rate at which cells can be sent over the virtual connection. SCR may not be greater than the PCR. AMG1202-T10A User’s Guide...
It is commonly used for "bursty" traffic typical on LANs. PCR and MBS define the burst levels, SCR defines the minimum level. An example of an VBR-nRT connection would be non-time sensitive data file transfers. AMG1202-T10A User’s Guide...
Page 83
Unspecified Bit Rate (UBR) The Unspecified Bit Rate (UBR) ATM traffic class is for bursty data transfers. However, UBR doesn't guarantee any bandwidth and only delivers traffic when the network has spare bandwidth. An example application is background file transfer. AMG1202-T10A User’s Guide...
Page 84
Chapter 6 WAN Setup AMG1202-T10A User’s Guide...
7.1.2 What You Need To Know About LAN IP Address IP addresses identify individual devices on a network. Every networking device (including computers, servers, routers, printers, etc.) needs an IP address to communicate across the network. These networking devices are also known as hosts. AMG1202-T10A User’s Guide...
7.2 The LAN IP Screen Use this screen to set the Local Area Network IP address and subnet mask of your ZyXEL Device. Click Network > LAN to open the IP screen. Follow these steps to configure your LAN settings. AMG1202-T10A User’s Guide...
Use this screen to edit your ZyXEL Device's RIP, multicast and Windows Networking settings. Click the Advanced Setup button in the LAN IP screen. The screen appears as shown. Figure 37 Network > LAN > IP: Advanced Setup AMG1202-T10A User’s Guide...
Use this screen to configure the DNS server information that the ZyXEL Device sends to the DHCP client devices on the LAN. Click Network > DHCP Setup to open this screen. Figure 38 Network > LAN > DHCP Setup AMG1202-T10A User’s Guide...
This table allows you to assign IP addresses on the LAN to specific individual computers based on their MAC Addresses. Every Ethernet device has a unique MAC (Media Access Control) address. The MAC address is assigned at the factory and consists of six pairs of hexadecimal characters, for example, 00:A0:C5:00:00:02. AMG1202-T10A User’s Guide...
IP alias allows you to partition a physical network into different logical networks over the same Ethernet interface. The ZyXEL Device supports three logical LAN interfaces via its single physical Ethernet interface with the ZyXEL Device itself as the gateway for each LAN network. AMG1202-T10A User’s Guide...
Alternatively, click the right mouse button to copy and/or paste the IP address. IP Subnet Mask Your ZyXEL Device will automatically calculate the subnet mask based on the IP address that you assign. Unless you are implementing subnetting, use the subnet mask computed by the ZyXEL Device. AMG1202-T10A User’s Guide...
The actual physical connection determines whether the ZyXEL Device ports are LAN or WAN ports. There are two separate IP networks, one inside the LAN network and the other outside the WAN network as shown next. Figure 42 LAN and WAN IP Addresses AMG1202-T10A User’s Guide...
If the ISP did not explicitly give you an IP network number, then most likely you have a single user account and the ISP will assign you a dynamic IP address when the connection is established. If this is the case, it is recommended that you select a network number from 192.168.0.0 to AMG1202-T10A User’s Guide...
• Out Only - the ZyXEL Device will send out RIP packets but will not accept any RIP packets received. • None - the ZyXEL Device will not send any RIP packets and will ignore any RIP packets received. AMG1202-T10A User’s Guide...
After that, the ZyXEL Device periodically updates this information. IP multicasting can be enabled/disabled on the ZyXEL Device LAN and/or WAN interfaces in the web configurator (LAN; WAN). Select None to disable IP multicasting on these interfaces. AMG1202-T10A User’s Guide...
Page 96
Chapter 7 LAN Setup AMG1202-T10A User’s Guide...
You don’t necessarily need to use all these screens to set up your wireless connection. For example, you may just want to set up a network name, a wireless radio channel and security in the AP screen. AMG1202-T10A User’s Guide...
• What advanced options do you want to configure, if any? If you want to configure advanced options such as Quality of Service, ensure that you know precisely what you want to do. If you do not want to configure advanced options, leave them as they are. AMG1202-T10A User’s Guide...
Security Mode See the following sections for more details about this field. MAC Filter This shows whether the wireless devices with the MAC addresses listed are allowed or denied to access the ZyXEL Device using this SSID. AMG1202-T10A User’s Guide...
Choose No Security from the drop-down list box. 8.2.2 WEP Encryption Use this screen to configure and enable WEP encryption. Click Network > Wireless LAN to display the AP screen. Select Static WEP from the Security Mode list. AMG1202-T10A User’s Guide...
Page 101
WEP key for data transmission. If you want to manually set the WEP key, enter any 5 or 13 characters (ASCII string) or 10 or 26 hexadecimal characters ("0-9", "A-F") for a 64-bit or 128-bit WEP key respectively. AMG1202-T10A User’s Guide...
PSK key management) or RADIUS server (if using WPA(2) key management) sends a new group key out to all clients. The re-keying process is the WPA(2) equivalent of automatically changing the WEP key for an AP and all stations in a WLAN on a periodic basis. AMG1202-T10A User’s Guide...
Idle Timeout The ZyXEL Device automatically disconnects a wireless station from the wired network after a period of inactivity. The wireless station needs to enter the username and password again before access to the wired network is allowed. AMG1202-T10A User’s Guide...
Set the output power of the ZyXEL Device. If there is a high density of APs in an area, decrease the output power to reduce interference with other APs. Select one of the following: 100%, 75%, 50% or 25%. AMG1202-T10A User’s Guide...
Page 105
Back Click this to return to the previous screen without saving. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
12:34:56:78:9a:bc. Back Click this to return to the previous screen without saving. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
Click the Remove icon to hide the SSID in the outgoing beacon frame so a station cannot obtain the SSID through scanning using a site survey tool. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
Click this to return to the previous screen without saving. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. 8.4 The WPS Screen Use this screen to configure WiFi Protected Setup (WPS) on your ZyXEL Device. AMG1202-T10A User’s Guide...
Page 109
This button is available when the WPS status is Configured. Click this button to remove all configured wireless and wireless security settings for WPS connections on the ZyXEL Device. Apply Click this to save your changes. Refresh Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
Use this screen to set up your WDS (Wireless Distribution System) links between the ZyXEL Device and other wireless APs. You need to know the MAC address of the peer device. Once the security settings of peer sides match one another, the connection between devices is made. AMG1202-T10A User’s Guide...
Page 111
12:34:56:78:9a:bc). Enter a Pre-Shared Key (PSK) from 8 to 63 case-sensitive ASCII characters (including spaces and symbols). Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
Apply Click this to save your changes. Reset Click this to restore your previously saved settings. 8.8 Wireless LAN Technical Reference This section discusses wireless LANs in depth. For more information, see the appendix. AMG1202-T10A User’s Guide...
ZyXEL Device is the AP. Every wireless network must follow these basic guidelines. • Every device in the same wireless network must use the same SSID. The SSID is the name of the wireless network. It stands for Service Set IDentifier. AMG1202-T10A User’s Guide...
(malicious software) intended to compromise the network. For these reasons, a variety of security systems have been developed to ensure that only authorized people can use a wireless data network, or understand the data carried on it. AMG1202-T10A User’s Guide...
Some wireless devices, such as scanners, can detect wireless networks but cannot use wireless networks. These kinds of wireless devices might not have MAC addresses. Hexadecimal characters are 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, A, B, C, D, E, and F. AMG1202-T10A User’s Guide...
When you select WPA2 or WPA2-PSK in your ZyXEL Device, you can also select an option (WPA compatible) to support WPA as well. In this case, if some of the devices support WPA and some AMG1202-T10A User’s Guide...
A and B can access the wired network and communicate with each other. When Intra-BSS traffic blocking is enabled, wireless station A and B can still access the wired network but cannot communicate with each other. Figure 57 Basic Service set AMG1202-T10A User’s Guide...
WPS (check each device’s documentation to make sure). Depending on the devices you have, you can either press a button (on the device itself, or in its configuration utility) or enter a PIN (a unique Personal Identification Number that allows one device AMG1202-T10A User’s Guide...
(referred to here as the AP) and a client device using the PIN method. Ensure WPS is enabled on both devices. Access the WPS section of the AP’s configuration interface. See the device’s User’s Guide for how to do this. AMG1202-T10A User’s Guide...
Page 120
On a computer connected to the wireless client, try to connect to the Internet. If you can connect, WPS was successful. If you cannot connect, check the list of associated wireless clients in the AP’s configuration utility. If you see the wireless client in the list, WPS was successful. AMG1202-T10A User’s Guide...
Page 121
WPA-PSK or WPA2-PSK pre-shared key to the enrollee. Whether WPA-PSK or WPA2-PSK is used depends on the standards supported by the devices. If the registrar is already part of a network, it sends the existing information. If not, it generates the SSID and WPA(2)-PSK randomly. AMG1202-T10A User’s Guide...
Page 122
This section shows how security settings are distributed in an example WPS setup. The following figure shows an example network. In step 1, both AP1 and Client 1 are unconfigured. When WPS is activated on both, they perform the handshake. In this example, AP1 AMG1202-T10A User’s Guide...
Page 123
(it already has security information for the network). AP1 supplies the existing security information to Client 2. Figure 62 WPS: Example Network Step 2 REGISTRAR EXISTING CONNECTION CLIENT 1 ENROLLEE CLIENT 2 AMG1202-T10A User’s Guide...
Page 124
(if the device supports this feature). Then, you can enter the key into the non-WPS device and join the network as normal (the non-WPS device must also support WPA-PSK or WPA2-PSK). AMG1202-T10A User’s Guide...
Page 125
Check the MAC addresses of your wireless clients (usually printed on a label on the bottom of the device). If there is an unknown MAC address you can remove it or reset the AP. AMG1202-T10A User’s Guide...
Page 126
Chapter 8 Wireless LAN AMG1202-T10A User’s Guide...
(the inside local address) to another (the inside global address) before forwarding the packet to the WAN side. When the response comes back, NAT translates the destination address (the inside global address) back to the inside local address before forwarding it to the original inside host. AMG1202-T10A User’s Guide...
Table 41 Network > NAT > General LABEL DESCRIPTION Active Network Select this check box to enable NAT. Address Translation SUA Only Select this radio button if you have just one public WAN IP address for your ZyXEL Device. AMG1202-T10A User’s Guide...
Note: If you do not assign a Default Server IP address, the ZyXEL Device discards all packets received for ports that are not specified here or in the remote management setup. AMG1202-T10A User’s Guide...
If you do not assign a Default Server IP address, the ZyXEL Device discards all packets received for ports that are not specified here or in the remote management setup. Port Forwarding AMG1202-T10A User’s Guide...
9.3.2 The Port Forwarding Rule Edit Screen Use this screen to edit a port forwarding rule. Click the rule’s edit icon in the Port Forwarding screen to display the screen shown next. Figure 67 Network > NAT > Port Forwarding: Edit AMG1202-T10A User’s Guide...
7, not 9. Now if you delete rule 4, rules 5 to 7 will be pushed up by 1 rule, so old rules 5, 6 and 7 become new rules 4, 5 and 6. AMG1202-T10A User’s Guide...
Page 133
Click the edit icon to go to the screen where you can edit the address mapping rule. Click the delete icon to delete an existing address mapping rule. Note that subsequent address mapping rules move up by one when you take this action. AMG1202-T10A User’s Guide...
This is the ending global IP address (IGA). This field is N/A for One-to-One, Many-to-One and Server mapping types. Server Mapping Click this link to go to the Port Forwarding screen to edit a port forwarding set that you have selected in the Server Mapping Set field. Edit Details AMG1202-T10A User’s Guide...
9.6.1 NAT Definitions Inside/outside denotes where a host is located relative to the ZyXEL Device, for example, the computers of your subscribers are the inside hosts, while the web servers on the Internet are the outside hosts. AMG1202-T10A User’s Guide...
IP addresses to globally unique ones required for communication with hosts on other networks. It replaces the original IP source address (and TCP or UDP source port numbers for Many-to-One and Many-to-Many Overload NAT mapping) in each packet and then forwards it to the Internet. The AMG1202-T10A User’s Guide...
The following figure illustrates a possible NAT application, where three inside LANs (logical LANs using IP alias) behind the ZyXEL Device can communicate with three distinct WAN networks. Figure 72 NAT Application With IP Alias 9.6.5 NAT Mapping Types NAT supports five types of IP/port mapping. They are: AMG1202-T10A User’s Guide...
Page 138
ILA2 IGA1 … Many-to-Many Overload ILA1 IGA1 ILA2 IGA2 ILA3 IGA1 ILA4 IGA2 … Many-to-Many No Overload ILA1 IGA1 ILA2 IGA2 ILA3 IGA3 … Server Server 1 IP IGA1 Server 2 IP IGA1 Server 3 IP IGA1 AMG1202-T10A User’s Guide...
The ZyXEL Device is pre-configured to automatically detect and thwart all known DoS attacks. DDoS A DDoS attack is one in which multiple compromised systems attack a single target, thereby causing denial of service for users of the targeted system. AMG1202-T10A User’s Guide...
Stateful Packet Inspection (SPI) tracks each connection crossing the firewall and makes sure it is valid. Filtering decisions are based not only on rules but also context. For example, traffic from the WAN may only be allowed to cross the firewall in response to a request from the LAN. AMG1202-T10A User’s Guide...
The following table describes the labels in this screen. Table 49 Advanced > Firewall LABEL DESCRIPTION Firewall Use this field to enable or disable firewall on your ZyXEL Device. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
An IP/MAC filter set consists of one or more filter rules. The ZyXEL Device allows you to configure up to twelve filter sets with six rules in each set, for a total of 72 filter rules in the system. AMG1202-T10A User’s Guide...
This is the index number of the filter rule. This is the URL you have configured the ZyXEL Device to block. Apply Click this to save your changes. Delete Click this to remove the filter rule. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
Use this field to allow or deny Yahoo Messenger traffic Real Audio/Video Use this field to allow or deny transferring RealPlayer format files. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
IP/MAC Filter Set Editing IP/MAC Filter Set Index Select the index number of the filter set. Interface Select the PVC to which to apply the filter. Direction Apply the filter to Both, Incoming or Outgoing traffic direction. AMG1202-T10A User’s Guide...
Page 147
When a packet doesn’t match the rule, this is the action the ZyXEL Device takes on the packet. Save Click this to save your changes. Delete Click this to remove the filter rule. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
(R1). You create one static route to connect to services offered by your ISP behind router R2. You create another static route to communicate with a separate network behind a router R3 connected to the LAN. Figure 77 Example of Static Routing Topology AMG1202-T10A User’s Guide...
Click the Edit icon to go to the screen where you can set up a static route on the ZyXEL Device. Click the Remove icon to remove a static route from the ZyXEL Device. A window displays asking you to confirm that you want to delete the route. AMG1202-T10A User’s Guide...
You can also select a specific WAN PVC as the gateway. See Section 6.3.1 on page to configure additional WAN connections. Back Click this to return to the previous screen without saving. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
- they are not confined to the device on which they were created. The VLAN ID associates a frame with a specific VLAN and provides the information that devices need to process the frame across the network. AMG1202-T10A User’s Guide...
VID of a frame, then the frame is transmitted as a tagged frame; otherwise, it is transmitted as an untagged frame. 13.2 The 802.1Q/1P Group Setting Screen Use this screen to activate 802.1Q/1P and display the VLAN groups. Click Advanced > 802.1Q/1P to display the following screen. AMG1202-T10A User’s Guide...
Page 155
Click the Edit button to configure the ports in the VLAN group. Click the Remove button to delete the VLAN group. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
Select Tx Tagging if you want the port to tag all outgoing traffic transmitted through this VLAN. You select this if you want to create VLANs across different devices and not just the ZyXEL Device. Back Click this to return to the previous screen without saving. AMG1202-T10A User’s Guide...
Assign a VLAN ID for the port. The valid VID range is between 1 and 4094. The ZyXEL Device assigns the PVID to untagged frames or priority-tagged frames received on this port. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
Figure 84 QoS Example VoIP: Queue 6 50 Mbps Boss: Queue 5 IP=192.168.1.23 14.1.1 What You Can Do in the QoS Screens • Use the QoS screen (Section 14.2 on page 160) to configure QoS settings on the ZyXEL Device. AMG1202-T10A User’s Guide...
QoS. 14.2 The QoS Screen Use this screen to enable or disable QoS and have the ZyXEL Device assign priority levels to traffic according to the port range, IEEE 802.1p priority level and/or IP precedence. AMG1202-T10A User’s Guide...
Page 161
Summary Click this to open a summary table showing the QoS settings. See Section 14.2.1 on page 163 for more details. Rule Rule Index Select the rule’s index number from the drop-down list box. AMG1202-T10A User’s Guide...
Page 162
Maximize reliability and Minimize monetary cost. DSCP Specify a DSCP number between 0 and 63 to re-assign the priority level to Remarking matched traffic. 802.1p Select a priority level (0 to 7) to re-assign the priority level to matched traffic. Remarking AMG1202-T10A User’s Guide...
This is the VLAN ID associated with the rule. IPP/TOS (DSCP) This shows the IPP/TOS or DSCP settings. 802.1p This is the 802.1p priority level. Actions IPP/TOS (DSCP) The ZyXEL Device re-assigns the priority values specified in this field to Remarking matched traffic. AMG1202-T10A User’s Guide...
14.3.3 Automatic Priority Queue Assignment If you enable QoS on the ZyXEL Device, the ZyXEL Device can automatically base on the IEEE 802.1p priority level, IP precedence and/or packet length to assign priority to traffic which does not match a class. AMG1202-T10A User’s Guide...
IP address as yourhost.dyndns.org. This feature is useful if you want to be able to use, for example, www.yourhost.dyndns.org and still reach your hostname. If you have a private WAN IP address, then you cannot use Dynamic DNS. AMG1202-T10A User’s Guide...
Type your user name. Password Type the password assigned to you. Enable Wildcard Select the check box to enable DynDNS Wildcard. Option Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
You may only have one remote management session running at a time. The ZyXEL Device automatically disconnects a remote management session of lower priority when another remote management session of higher priority starts. The priorities for the different types of remote management sessions are as follows. Telnet HTTP AMG1202-T10A User’s Guide...
There is a default system management idle timeout of five minutes (three hundred seconds). The ZyXEL Device automatically logs you out if the management session remains idle for longer than this timeout period. The management session does not time out when a statistics screen is polling. AMG1202-T10A User’s Guide...
Click this to restore your previously saved settings. 16.3 The Telnet Screen You can use Telnet to access the ZyXEL Device’s command line interface. Specify which interfaces allow Telnet access and from which IP address the access can come. AMG1202-T10A User’s Guide...
You can use FTP (File Transfer Protocol) to upload and download the ZyXEL Device’s firmware and configuration files. Please see the User’s Guide chapter on firmware and configuration file maintenance for details. To use this feature, your computer must have an FTP client. AMG1202-T10A User’s Guide...
Simple Network Management Protocol is a protocol used for exchanging management information between network devices. Your ZyXEL Device supports SNMP agent functionality, which allows a manager station to manage and monitor the ZyXEL Device through the network. The ZyXEL Device AMG1202-T10A User’s Guide...
Page 174
Get operation, followed by a series of GetNext operations. • Set - Allows the manager to set values for object variables within an agent. • Trap - Used by the agent to inform the manager of some events. AMG1202-T10A User’s Guide...
Type the trap community, which is the password sent with each trap to the SNMP manager. The default is public and allows all requests. Trap Destination Type the IP address of the station to send your SNMP traps to. AMG1202-T10A User’s Guide...
Choose Selected to just allow the computer with the IP address that you specify to send DNS queries to the ZyXEL Device. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
WAN Ping requests. Otherwise select LAN & WAN to reply to both incoming LAN and WAN Ping requests. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
The automated nature of NAT traversal applications in establishing their own services and opening firewall ports may present network security issues. Network information and configuration may also be obtained and modified by users in some network environments. AMG1202-T10A User’s Guide...
ZyXEL Device, for example by using NAT traversal, UPnP applications automatically reserve a NAT forwarding port in order to communicate with another UPnP enabled device; this eliminates the need to manually configure port forwarding for the UPnP enabled application. AMG1202-T10A User’s Guide...
Follow the steps below to install the UPnP in Windows Me. Click Start and Control Panel. Double-click Add/Remove Programs. Click on the Windows Setup tab and select Communication in the Components selection box. Click Details. Add/Remove Programs: Windows Setup: Communication AMG1202-T10A User’s Guide...
Page 181
Click OK to go back to the Add/Remove Programs Properties window and click Next. Restart the computer when prompted. Installing UPnP in Windows XP Follow the steps below to install the UPnP in Windows XP. Click Start and Control Panel. Double-click Network Connections. AMG1202-T10A User’s Guide...
Page 182
In the Network Connections window, click Advanced in the main menu and select Optional Networking Components …. Network Connections The Windows Optional Networking Components Wizard window displays. Select Networking Service in the Components selection box and click Details. Windows Optional Networking Components Wizard AMG1202-T10A User’s Guide...
Make sure the computer is connected to a LAN port of the ZyXEL Device. Turn on your computer and the ZyXEL Device. Auto-discover Your UPnP-enabled Network Device Click Start and Control Panel. Double-click Network Connections. An icon displays under Internet Gateway. AMG1202-T10A User’s Guide...
Page 184
Chapter 17 Universal Plug-and-Play (UPnP) Right-click the icon and select Properties. Network Connections In the Internet Connection Properties window, click Settings to see the port mappings there were automatically created. Internet Connection Properties AMG1202-T10A User’s Guide...
Page 185
You may edit or delete the port mappings or click Add to manually add port mappings. Internet Connection Properties: Advanced Settings Internet Connection Properties: Advanced Settings: Add When the UPnP-enabled device is disconnected from your computer, all port mappings will be deleted automatically. AMG1202-T10A User’s Guide...
Page 186
IP address of the ZyXEL Device first. This comes helpful if you do not know the IP address of the ZyXEL Device. Follow the steps below to access the web configurator. Click Start and then Control Panel. Double-click Network Connections. AMG1202-T10A User’s Guide...
Page 187
Chapter 17 Universal Plug-and-Play (UPnP) Select My Network Places under Other Places. Network Connections An icon with the description for each UPnP-enabled device displays under Local Network. AMG1202-T10A User’s Guide...
Page 188
Right-click on the icon for your ZyXEL Device and select Invoke. The web configurator login screen displays. Network Connections: My Network Places Right-click on the icon for your ZyXEL Device and select Properties. A properties window displays with basic information about the ZyXEL Device. Network Connections: My Network Places: Properties: Example AMG1202-T10A User’s Guide...
Type your new system password (up to 30 characters). Note that as you type a Password password, the screen displays a (*) for each character you type. After you change the password, use the new password to access the ZyXEL Device. AMG1202-T10A User’s Guide...
Each time you reload this page, the ZyXEL Device synchronizes the time with the time server. Current Date This field displays the date of your ZyXEL Device. Each time you reload this page, the ZyXEL Device synchronizes the date with the time server. Time and Date Setup AMG1202-T10A User’s Guide...
Page 191
Last, Sunday, October. The time you type in the o'clock field depends on your time zone. In Germany for instance, you would type 2 because Germany's time zone is one hour ahead of GMT or UTC (GMT+1). AMG1202-T10A User’s Guide...
Page 192
Chapter 18 System Settings Table 71 Maintenance > System > Time and Date (continued) LABEL DESCRIPTION Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. AMG1202-T10A User’s Guide...
19.2 The System Log Screen Use the System Log screen to configure and view the logs you wish to display. To change your ZyXEL Device’s log settings, click Maintenance > Logs > Log Settings. The screen appears as shown. AMG1202-T10A User’s Guide...
The router failed to get information from the time server. Time calibration failed A WAN interface got a new IP address from the DHCP, WAN interface gets IP: %s PPPoE, or dial-up server. AMG1202-T10A User’s Guide...
Page 195
This attempt to create a NAT session exceeds the maximum %s exceeds the max. number of NAT session table entries allowed to be created per number of session per host. host! The router failed to allocate memory for the NetBIOS filter setNetBIOSFilter: calloc settings. error AMG1202-T10A User’s Guide...
Page 196
The router sent a TCP reset packet when a dynamic firewall Firewall session time session timed out.Default timeout values:ICMP idle timeout (s): out, sent TCP RST 60UDP idle timeout (s): 60TCP connection (three way handshaking) timeout (s): 30TCP FIN-wait timeout (s): 60TCP idle (established) timeout (s): 3600 AMG1202-T10A User’s Guide...
Page 197
(3 is for dial-up, 6 is for PPPoE, 10 is for PPTP) dev=%x ch=%x %s "channel" or “ch” is the call channel ID. For example,"board 0 line 0 channel 0, call 3, C01 Outgoing Call dev=6 ch=0 "Means the router has dialed to the PPPoE server 3 times. AMG1202-T10A User’s Guide...
Page 198
The firewall detected an ICMP attack. attack ICMP (type:%d, code:%d) The firewall detected a TCP/UDP/IGMP/ESP/GRE/OSPF land land [ TCP | UDP | IGMP | attack. ESP | GRE | OSPF ] The firewall detected an ICMP land attack. land ICMP (type:%d, code:%d) AMG1202-T10A User’s Guide...
Page 199
User logout because of idle expired. timeout expired. A user logged out. User logout because of user request. There is no response message from the RADIUS server, No response from RADIUS. Pls please check the RADIUS server. check RADIUS Server. AMG1202-T10A User’s Guide...
Page 200
Redirect datagrams for the Host Redirect datagrams for the Type of Service and Network Redirect datagrams for the Type of Service and Host Echo Echo message Time Exceeded Time to live exceeded in transit Fragment reassembly time exceeded Parameter Problem AMG1202-T10A User’s Guide...
Page 201
RFC 2408 for detailed information on each type. Table 88 RFC-2408 ISAKMP Payload Types LOG DISPLAY PAYLOAD TYPE Security Association Proposal PROP Transform TRANS Key Exchange Identification Certificate Certificate Request CER_REQ Hash HASH Signature Nonce NONCE Notification NOTFY Delete Vendor ID AMG1202-T10A User’s Guide...
Click Maintenance > Tools to open the Firmware screen. Follow the instructions in this screen to upload firmware to your ZyXEL Device. The upload process uses HTTP (Hypertext Transfer Protocol) and may take up to two minutes. After a successful upload, the system will reboot. AMG1202-T10A User’s Guide...
Page 204
Click this to begin the upload process. This process may take up to two minutes. After you see the Firmware Upload in Progress screen, wait two minutes before logging into the ZyXEL Device again. Figure 101 Firmware Upload In Progress AMG1202-T10A User’s Guide...
Page 205
After two minutes, log in again and check your new firmware version in the Status screen. If the upload was not successful, the following screen will appear. Click Return to go back to the Firmware screen. Figure 103 Error Message AMG1202-T10A User’s Guide...
Restore Configuration allows you to upload a new or previously saved configuration file from your computer to your ZyXEL Device. Table 90 Restore Configuration LABEL DESCRIPTION File Path Type in the location of the file you want to upload in this field or click Browse ... to find it. AMG1202-T10A User’s Guide...
Page 207
Appendix A on page 225 for details on how to set up your computer’s IP address. If the upload was not successful, the following screen will appear. Click Return to go back to the Configuration screen. Figure 107 Configuration Upload Error AMG1202-T10A User’s Guide...
ZyXEL Device hangs, for example. Click Maintenance > Tools > Restart. Click Restart to have the ZyXEL Device reboot. This does not affect the ZyXEL Device's configuration. Figure 110 Maintenance > Tools >Restart AMG1202-T10A User’s Guide...
210) to view the DSL line statistics and reset the ADSL line. 21.2 The General Screen Use this screen to ping an IP address. Click Maintenance > Diagnostic to open the screen shown next. Figure 111 Maintenance > Diagnostic > General AMG1202-T10A User’s Guide...
21.3 The DSL Line Screen Use this screen to view the DSL line statistics and reset the ADSL line. Click Maintenance > Diagnostic > DSL Line to open the screen shown next. Figure 112 Maintenance > Diagnostic > DSL Line AMG1202-T10A User’s Guide...
Page 211
PVC with proper VPIs/VCIs before you begin this test. The ZyXEL Device sends an OAM F5 packet to the DSLAM/ATM switch and then returns it (loops it back) to the ZyXEL Device. The ATM loopback test is useful for troubleshooting problems with the DSLAM and ATM network. AMG1202-T10A User’s Guide...
Page 212
Reset ADSL Line Successfully!" Capture All Logs Click this to display information and statistics about your ZyXEL Device’s ATM statistics, DSL connection statistics, DHCP settings, firmware version, WAN and gateway IP address, VPI/VCI and LAN IP address. AMG1202-T10A User’s Guide...
Make sure you understand the normal behavior of the LED. See Section 1.6 on page Check the hardware connections. Inspect your cables for damage. Contact the vendor to replace any damaged cables. Turn the ZyXEL Device off and on. If the problem continues, contact the vendor. AMG1202-T10A User’s Guide...
Reset the device to its factory defaults, and try to access the ZyXEL Device with the default IP address. See Section 1.7 on page If the problem continues, contact the network administrator or vendor, or try one of the advanced suggestions. Advanced Suggestions AMG1202-T10A User’s Guide...
Check the hardware connections, and make sure the LEDs are behaving as expected. See the Quick Start Guide and Section 1.6 on page Make sure you entered your ISP account information correctly in the wizard. These fields are case- sensitive, so make sure [Caps Lock] is not on. AMG1202-T10A User’s Guide...
Page 216
If the problem continues, contact the network administrator or vendor, or try one of the advanced suggestions. Advanced Suggestions • Check the settings for QoS. If it is disabled, you might consider activating it. If it is enabled, you might consider raising or lowering the priority for some applications. AMG1202-T10A User’s Guide...
Default Admin Password 1234 DHCP Server IP Pool 192.168.1.32 to 192.168.1.64 Static DHCP Addresses URL Filtering URL web page blocking Static Routes Device Management Use the web configurator to easily configure the rich range of features on the ZyXEL Device. AMG1202-T10A User’s Guide...
Page 218
LAN, which see only Ethernet and are not aware of PPPoE thus saving you from having to manage PPPoE clients on individual computers. Other PPPoE Features PPPoE idle time out PPPoE dial on demand AMG1202-T10A User’s Guide...
Page 219
ADSL physical connection ATM AAL5 (ATM Adaptation Layer type 5) Support multi-protocol over AAL5 (RFC2684/1483) Support PPP over ATM AAL5 (RFC2364) PPP over Ethernet support for DSL connection (RFC 2516) Support VC-based and LLC-based multiplexing Support up to 8 PVCs I.610 F4/F5 OAM TR-067/TR-100 supported AMG1202-T10A User’s Guide...
Wi-Fi Protected Access (WPA) is a subset of the IEEE 802.11i security standard. Key differences between WPA and WEP are user authentication and improved data encryption. WPA2 WPA 2 is a wireless security standard that defines stronger encryption, authentication and key management than WPA. AMG1202-T10A User’s Guide...
Page 221
Network Address Translation - Protocol IEEE 802.11 Also known by the brand Wi-Fi, denotes a set of Wireless LAN/WLAN standards developed by working group 11 of the IEEE LAN/MAN Standards Committee (IEEE 802). IEEE 802.11b Uses the 2.4 gigahertz (GHz) band AMG1202-T10A User’s Guide...
Power Consumption 7.7 Watt max Safety Standards ANSI/UL 60950-1, CSA 60950-1 EUROPEAN PLUG STANDARDS AC Power Adapter Model Input Power AC 230Volts/50Hz Output Power DC 12Volts/1.0A Power Consumption 8.3 Watt max Safety Standards CE, GS or TUV, EN60950-1 AMG1202-T10A User’s Guide...
IP addresses that place them in the same subnet as the ZyXEL Device’s LAN port. Windows 95/98/Me Click Start, Settings, Control Panel and double-click the Network icon to open the Network window. Figure 113 WIndows 95/98/Me: Network: Configuration AMG1202-T10A User’s Guide...
Restart your computer so the changes you made take effect. Configuring In the Network window Configuration tab, select your network adapter's TCP/IP entry and click Properties Click the IP Address tab. • If your IP address is dynamic, select Obtain an IP address automatically. AMG1202-T10A User’s Guide...
Page 227
• If you do not know your DNS information, select Disable DNS. • If you know your DNS information, select Enable DNS and type the information in the fields below (you may not need to fill them all in). Figure 115 Windows 95/98/Me: TCP/IP Properties: DNS Configuration AMG1202-T10A User’s Guide...
Select your network adapter. You should see your computer's IP address, subnet mask and default gateway. Windows 2000/NT/XP The following example figures use the default Windows XP GUI theme. Click start (Start in Windows 2000/NT), Settings, Control Panel. Figure 116 Windows XP: Start Menu AMG1202-T10A User’s Guide...
Page 229
In the Control Panel, double-click Network Connections (Network and Dial-up Connections in Windows 2000/NT). Figure 117 Windows XP: Control Panel Right-click Local Area Connection and then click Properties. Figure 118 Windows XP: Control Panel: Network Connections: Properties AMG1202-T10A User’s Guide...
Page 230
• If you have a dynamic IP address click Obtain an IP address automatically. • If you have a static IP address click Use the following IP Address and fill in the IP address, Subnet mask, and Default gateway fields. AMG1202-T10A User’s Guide...
Page 231
(the number of transmission hops), clear the Automatic metric check box and type a metric in Metric. • Click Add. • Repeat the previous three steps for each default gateway you want to add. AMG1202-T10A User’s Guide...
Page 232
• Click Obtain DNS server address automatically if you do not know your DNS server IP address(es). • If you know your DNS server IP address(es), click Use the following DNS server addresses, and type them in the Preferred DNS server and Alternate DNS server fields. AMG1202-T10A User’s Guide...
In the Command Prompt window, type "ipconfig" and then press [ENTER]. You can also open Network Connections, right-click a network connection, click Status and then click the Support tab. Windows Vista This section shows screens from Windows Vista Enterprise Version 6.0. AMG1202-T10A User’s Guide...
Page 234
Click the Start icon, Control Panel. Figure 123 Windows Vista: Start Menu In the Control Panel, double-click Network and Internet. Figure 124 Windows Vista: Control Panel Click Network and Sharing Center. Figure 125 Windows Vista: Network And Internet AMG1202-T10A User’s Guide...
Page 235
Figure 126 Windows Vista: Network and Sharing Center Right-click Local Area Connection and then click Properties. Note: During this procedure, click Continue whenever Windows displays a screen saying that it needs your permission to continue. Figure 127 Windows Vista: Network and Sharing Center AMG1202-T10A User’s Guide...
Page 236
• If you have a dynamic IP address click Obtain an IP address automatically. • If you have a static IP address click Use the following IP address and fill in the IP address, Subnet mask, and Default gateway fields. AMG1202-T10A User’s Guide...
Page 237
(the number of transmission hops), clear the Automatic metric check box and type a metric in Metric. • Click Add. • Repeat the previous three steps for each default gateway you want to add. AMG1202-T10A User’s Guide...
Page 238
• Click Obtain DNS server address automatically if you do not know your DNS server IP address(es). • If you know your DNS server IP address(es), click Use the following DNS server addresses, and type them in the Preferred DNS server and Alternate DNS server fields. AMG1202-T10A User’s Guide...
Page 239
Click Start, All Programs, Accessories and then Command Prompt. In the Command Prompt window, type "ipconfig" and then press [ENTER]. You can also open Network Connections, right-click a network connection, click Status and then click the Support tab. AMG1202-T10A User’s Guide...
Page 240
Appendix A Setting up Your Computer’s IP Address Macintosh OS 8/9 Click the Apple menu, Control Panel and double-click TCP/IP to open the TCP/IP Control Panel. Figure 132 Macintosh OS 8/9: Apple Menu AMG1202-T10A User’s Guide...
Macintosh OS X Click the Apple menu, and click System Preferences to open the System Preferences window. Figure 134 Macintosh OS X: Apple Menu Click Network in the icon bar. • Select Automatic from the Location list. AMG1202-T10A User’s Guide...
Page 242
• Type the IP address of your ZyXEL Device in the Router address box. Click Apply Now and close the window. Turn on your ZyXEL Device and restart your computer (if prompted). Verifying Settings Check your TCP/IP properties in the Network window. AMG1202-T10A User’s Guide...
Page 243
Follow the steps below to configure your computer IP address using the KDE. Click the Red Hat button (located on the bottom left corner), select System Setting and click Network. Figure 136 Red Hat 9.0: KDE: Network Configuration: Devices AMG1202-T10A User’s Guide...
Page 244
If you know your DNS server IP address(es), click the DNS tab in the Network Configuration screen. Enter the DNS server information in the fields provided. Figure 138 Red Hat 9.0: KDE: Network Configuration: DNS Click the Devices tab. AMG1202-T10A User’s Guide...
The following example shows an example where the static IP address is 192.168.1.10 and the subnet mask is 255.255.255.0. Figure 141 Red Hat 9.0: Static IP Address Setting in ifconfig-eth0 DEVICE=eth0 ONBOOT=yes BOOTPROTO=static IPADDR=192.168.1.10 NETMASK=255.255.255.0 USERCTL=no PEERDNS=yes TYPE=Ethernet AMG1202-T10A User’s Guide...
192.168.1.1). Each of these four parts is known as an octet. An octet is an eight-digit binary number (for example 11000000, which is 192 in decimal notation). Therefore, each octet has a possible range of 00000000 to 11111111 in binary, or 0 to 255 in decimal. AMG1202-T10A User’s Guide...
Host ID 00000010 By convention, subnet masks always consist of a continuous sequence of ones beginning from the leftmost bit of the mask, followed by a continuous sequence of zeros, for a total number of 32 bits. AMG1202-T10A User’s Guide...
Page 249
This is usually specified by writing a “/” followed by the number of bits in the mask after the address. For example, 192.1.1.0 /25 is equivalent to saying 192.1.1.0 with subnet mask 255.255.255.128. AMG1202-T10A User’s Guide...
Page 250
You can “borrow” one of the host ID bits to divide the network 192.168.1.0 into two separate sub- networks. The subnet mask is now 25 bits (255.255.255.128 or /25). The “borrowed” host ID bit can have a value of either 0 or 1, allowing two subnets; 192.168.1.0 /25 and 192.168.1.128 /25. AMG1202-T10A User’s Guide...
Page 251
Table 102 Subnet 1 LAST OCTET BIT IP/SUBNET MASK NETWORK NUMBER VALUE IP Address (Decimal) 192.168.1. IP Address (Binary) 11000000.10101000.00000001. 00000000 Subnet Mask (Binary) 11111111.11111111.11111111. 11000000 AMG1202-T10A User’s Guide...
Page 252
Similarly, use a 27-bit mask to create eight subnets (000, 001, 010, 011, 100, 101, 110 and 111). The following table shows IP address last octet values for each subnet. Table 106 Eight Subnets SUBNET LAST BROADCAST SUBNET FIRST ADDRESS ADDRESS ADDRESS ADDRESS AMG1202-T10A User’s Guide...
Regardless of your particular situation, do not create an arbitrary IP address; always follow the guidelines above. For more information on address assignment, please refer to RFC 1597, Address Allocation for Private Internets and RFC 1466, Guidelines for Management of IP Address Space. AMG1202-T10A User’s Guide...
In Internet Explorer, select Tools, Pop-up Blocker and then select Turn Off Pop-up Blocker. Figure 148 Pop-up Blocker You can also check if pop-up blocking is disabled in the Pop-up Blocker section in the Privacy tab. In Internet Explorer, select Tools, Internet Options, Privacy. AMG1202-T10A User’s Guide...
Page 256
Click Apply to save this setting. Enable Pop-up Blockers with Exceptions Alternatively, if you only want to allow pop-up windows from your device, see the following steps. In Internet Explorer, select Tools, Internet Options and then the Privacy tab. AMG1202-T10A User’s Guide...
Page 257
Select Settings…to open the Pop-up Blocker Settings screen. Figure 150 Internet Options: Privacy Type the IP address of your device (the web page that you do not want to have blocked) with the prefix “http://”. For example, http://192.168.167.1. AMG1202-T10A User’s Guide...
Page 258
Figure 151 Pop-up Blocker Settings Click Close to return to the Privacy screen. Click Apply to save this setting. JavaScripts If pages of the web configurator do not display properly in Internet Explorer, check that JavaScripts are allowed. AMG1202-T10A User’s Guide...
Page 259
Figure 152 Internet Options: Security Click the Custom Level... button. Scroll down to Scripting. Under Active scripting make sure that Enable is selected (the default). Under Scripting of Java applets make sure that Enable is selected (the default). AMG1202-T10A User’s Guide...
Figure 153 Security Settings - Java Scripting Java Permissions From Internet Explorer, click Tools, Internet Options and then the Security tab. Click the Custom Level... button. Scroll down to Microsoft VM. Under Java permissions make sure that a safety level is selected. AMG1202-T10A User’s Guide...
Page 261
Click OK to close the window. Figure 154 Security Settings - Java JAVA (Sun) From Internet Explorer, click Tools, Internet Options and then the Advanced tab. Make sure that Use Java 2 for <applet> under Java (Sun) is selected. AMG1202-T10A User’s Guide...
Page 262
Mozilla Firefox 2.0 screens are used here. Screens for other versions may vary. You can enable Java, Javascripts and pop-ups in one screen. Click Tools, then click Options in the screen that appears. Figure 156 Mozilla Firefox: Tools > Options AMG1202-T10A User’s Guide...
Page 263
Appendix C Pop-up Windows, JavaScripts and Java Permissions Click Content.to show the screen below. Select the check boxes as shown in the following screen. Figure 157 Mozilla Firefox Content Security AMG1202-T10A User’s Guide...
Page 264
Appendix C Pop-up Windows, JavaScripts and Java Permissions AMG1202-T10A User’s Guide...
(AP). Intra-BSS traffic is traffic between wireless clients in the BSS. When Intra-BSS is enabled, wireless client A and B can access the wired network and communicate with each other. When Intra-BSS is AMG1202-T10A User’s Guide...
Page 266
APs is called a Distribution System (DS). This type of wireless LAN topology is called an Infrastructure WLAN. The Access Points not only provide communication with the wired network but also mediate wireless network traffic in the immediate neighborhood. AMG1202-T10A User’s Guide...
Page 267
A hidden node occurs when two stations are within range of the same access point, but are not within range of each other. The following figure illustrates a hidden node. Both stations (STA) are within range of the access point (AP) or wireless gateway, but out-of-range of each other, so they AMG1202-T10A User’s Guide...
AP will fragment the packet into smaller data frames. A large Fragmentation Threshold is recommended for networks not prone to interference while you should set a smaller threshold for busy networks or networks that are prone to interference. AMG1202-T10A User’s Guide...
Wireless security is vital to your network to protect wireless communication between wireless clients, access points and the wired network. Wireless security methods available on the ZyXEL Device are data encryption, wireless client authentication, restricting access by device MAC address and hiding the ZyXEL Device identity. AMG1202-T10A User’s Guide...
Page 270
• Authentication Determines the identity of the users. • Authorization Determines the network services available to authenticated users once they are connected to the network. • Accounting Keeps track of the client’s network activity. AMG1202-T10A User’s Guide...
For EAP-TLS authentication type, you must first have a wired connection to the network and obtain the certificate(s) from a certificate authority (CA). A certificate (also called digital IDs) can be used to authenticate users and a CA issues certificates and guarantees the identity of each certificate owner. AMG1202-T10A User’s Guide...
The AP maps a unique key that is generated with the RADIUS server. This key expires when the wireless connection times out, disconnects or reauthentication times out. A new WEP key is generated each time reauthentication is performed. AMG1202-T10A User’s Guide...
Page 273
Cipher block chaining Message authentication code Protocol (CCMP). TKIP uses 128-bit keys that are dynamically generated and distributed by the authentication server. AES (Advanced Encryption Standard) is a block cipher that uses a 256-bit mathematical algorithm AMG1202-T10A User’s Guide...
WPA. At the time of writing, the most widely available supplicant is the WPA patch for Windows XP, Funk Software's Odyssey client. The Windows XP patch is a free download that adds WPA capability to Windows XP's built-in "Zero Configuration" wireless client. However, you must run Windows XP to use it. AMG1202-T10A User’s Guide...
The AP checks each wireless client's password and allows it to join the network only if the password matches. The AP and wireless clients generate a common PMK (Pairwise Master Key). The key itself is not sent over the network, but is derived from the PSK and the SSID. AMG1202-T10A User’s Guide...
An antenna couples RF signals onto air. A transmitter within a wireless device sends an RF signal to the antenna, which propagates the signal through the air. The antenna also operates in reverse by capturing RF signals from the air. Positioning the antennas properly increases the range and coverage area of a wireless LAN. AMG1202-T10A User’s Guide...
For a single AP application, place omni-directional antennas as close to the center of the coverage area as possible. For directional antennas, point the antenna in the direction of the desired coverage area. AMG1202-T10A User’s Guide...
Page 278
Appendix D Wireless LANs AMG1202-T10A User’s Guide...
• If the Protocol is TCP, UDP, or TCP/UDP, this is the IP port number. • If the Protocol is USER, this is the IP protocol number. • Description: This is a brief explanation of the applications that use this service or the situations in which this service is used. AMG1202-T10A User’s Guide...
Page 280
6667 This is another popular Internet chat program. MSN Messenger 1863 Microsoft Networks’ messenger service uses this protocol. NetBIOS TCP/UDP The Network Basic Input/Output System is used for communication between TCP/UDP computers in a LAN. TCP/UDP TCP/UDP AMG1202-T10A User’s Guide...
Page 281
Internet. SMTP enables you to move messages from one e-mail server to another. SMTPS This is a more secure version of SMTP that runs over SSL. SNMP TCP/UDP Simple Network Management Program. SNMP-TRAPS TCP/UDP Traps for use with the SNMP (RFC:1215). AMG1202-T10A User’s Guide...
Page 282
UNIX environments. It operates over TCP/ IP networks. Its primary function is to allow users to log into remote host systems. VDOLIVE 7000 A videoconferencing solution. The UDP port number is specified in the application. user- defined AMG1202-T10A User’s Guide...
This publication is subject to change without notice. Trademarks ZyNOS (ZyXEL Network Operating System) is a registered trademark of ZyXEL Communications, Inc. Other trademarks mentioned in this publication are used for identification purposes only and may be properties of their respective owners.
This device has been designed for the WLAN 2.4 GHz network throughout the EC region and Switzerland, with restrictions in France. This Class B digital apparatus complies with Canadian ICES-003. Cet appareil numérique de la classe B est conforme à la norme NMB-003 du Canada. AMG1202-T10A User’s Guide...
Registration Register your product online to receive e-mail notices of firmware upgrades and information at www.zyxel.com for global products, or at www.us.zyxel.com for North American products. AMG1202-T10A User’s Guide...
Page 286
Appendix F Legal Information AMG1202-T10A User’s Guide...
133, 134, 137 notices administrator password 28, 189 viewing alerts channel alternative subnet mask notation interference antenna channel, wireless LAN directional gain client list omni-directional Command Line Interface, see CLI AP (access point) compatibility, WDS application filter AMG1202-T10A User’s Guide...
Page 288
LAND attack DSL connections, status Ping of Death status dynamic DNS SYN attack activation wildcard firmware activation version Dynamic Host Configuration Protocol, see DHCP forwarding ports 128, 129 activation dynamic WEP key exchange configuration DYNDNS wildcard example activation AMG1202-T10A User’s Guide...
Page 289
162, 164 Maximum Burst Size, see MBS configuration Maximum Transmission Unit, see MTU IP/MAC filter 74, 78, 82 structure MBSSID 74, 79 multicast 70, 74, 86, 88, 95 IGMPInternet Group Multicast Protocol, see IGMP Multiple BSS, see MBSSID AMG1202-T10A User’s Guide...
Page 290
Quality of Service, see QoS Network Address Translation, see NAT RADIUS message types messages Pairwise Master Key (PMK) 274, 275 shared secret key passwords 27, 28 RADIUS server administrator reauthentication, WPA registration 74, 78, 81 product Peak Cell Rate, see PCR AMG1202-T10A User’s Guide...
Page 291
IP filter system IP precedenceQoS firmware IP precedence version logs port forwarding passwords 27, 28 static route administrator reset wireless LAN status 30, 33 wizard firewalls shaping traffic 81, 82 Simple Network Management Protocol, see SNMP AMG1202-T10A User’s Guide...
Page 292
Wide Area Network, see WAN VBR-RT 74, 78, 82 Wi-Fi Protected Access 72, 77, 80 WiFi Protected Setup, see WPS Virtual Channel Identifier, see VCI wireless client WPA supplicants Virtual Local Area Network, see VLAN Wireless Distribution System, see WDS AMG1202-T10A User’s Guide...