Page 2
This manual and any associated artwork, software and product designs are copyrighted with all rights reserved. Under the copyright laws such materials may not be copied, in whole or part, without the prior written consent of Netopia, Inc. Under the law, copying includes translation to another language or format.
C C C C o o o o n n n n t t t t e e e e n n n n t t t t s s s s Welcome to the Netopia R2121 User’s Reference Guide . This guide is designed to be your single source for information about your Netopia R2121 Dual Analog Router.
Page 4
User’s Reference Guide Configuring TCP/IP on Windows 95, 98, or NT computers ... 3-9 Configuring TCP/IP on Macintosh computers ... 3-13 Chapter 4 — Monitoring with SmartView ...4-1 SmartView overview ... 4-1 Navigating SmartView ... 4-2 General Machine Information page ... 4-2 Connection Profiles page ...
Page 5
Easy Setup Security... 7-6 Chapter 8 — WAN and System Configuration ...8-1 Creating a new Connection Profile ... 8-2 Viewing or editing connection profiles ... 8-6 Deleting connection profiles ... 8-7 System Configuration screens ... 8-8 Navigating through the System Configuration screens... 8-8 System Configuration features ...
Page 9
ISP’s Point of presence ... B-2 Endorsements ... B-2 Deciding on an ISP account ... B-2 Setting up a Netopia R2121 account ... B-2 Obtaining an IP host address ... B-2 SmartIP™ ... B-3 Obtaining information from the ISP... B-3 Local LAN IP address information to obtain (NAT enabled) ...
Page 10
Tips and rules for distributing IP addresses... C-9 Nested IP subnets ... C-11 Broadcasts... C-13 Packet header types... C-13 Appendix D — Understanding Netopia NAT Behavior...D-1 Network Configuration ... D-1 Background ... D-1 Exported services ... D-5 Important notes ... D-6 Configuration ...
Page 11
Contents Index ...Index-1 Limited Warranty and Limitation of Remedies ...1...
Configuration options for your Netopia R2121 Dual Analog The Netopia R2121 can be used in different ways depending on your needs. In general, you will probably want to use it in one or more of the following ways: (Click on one of these links) “1.
For Small Office connections to the Internet, using a single dynamic IP address with Network Address Translation (NAT) enabled, you should use the following configuration option: the SmartStart™ Wizard, included on your Netopia R2121 CD. This is the fastest and simplest way to get you up and running with the minimum difficulty.
Page 15
2. Small Office connection to the Internet For Small Office connections to the Internet, using a block of IP addresses (Network Address Translation disabled), you should use the following configuration tool: Easy Setup configuration using console-based management. This option allows maximum flexibility for experienced users and administrators.
For direct connections to a Corporate Office, you can use either one of two configuration options: If you will be using Network Address Translation, use the SmartStart™ Wizard, included on your Netopia R2121 CD. For instructions on this option, see on page 3-3.
4. Configured to accept incoming dial-up connections To configure the Netopia R2121 to accept incoming dial-up connections, you should use the following configuration method: To create one or more dial-in Connection Profiles for each dial-in user, see new Connection Profile” on page You do this using console-based management.
5. Configured for two onboard and one external modem on the Auxiliary port To configure the Netopia R2121 to use the two onboard modems and a third external modem on the Auxiliary serial port, you should use the following configuration options. This might be done to allow three separate simultaneous dial-in/dial-out connections or one or two aggregated dial-in/dial-out calls using Multilink PPP.
Page 19
P P P P a a a a r r r r t t t t I I I I : : : : G G G G e e e e t t t t t t t t i i i i n n n n g g g g S S S S t t t t a a a a r r r r t t t t e e e e d d d d...
The Netopia R2121 Dual Analog Router is a full-featured, stand-alone, multiprotocol router for connecting diverse local area networks (LANs) to the Internet and other remote networks. The Netopia R2121 Dual Analog Router uses two 56Kbps modems communicating over standard analog telephone lines to provide your whole network with a high-speed connection to the outside world.
How to use this guide This guide is designed to be your single source for information about your Netopia R2121 Dual Analog Router. It is intended to be viewed on-line, using the powerful features of the Adobe Acrobat Reader. The information display has been deliberately designed to present the maximum information in the minimum space on your screen.
Cable length and network size limitations when expanding networks For small networks, install the Netopia R2121 near one of the LANs. For large networks, you can install the Netopia R2121 in a wiring closet or a central network administration site.
Windows and Macintosh, ZTerm terminal emulator software and NCSA Telnet 2.6 for Macintosh You will need: A Windows 95-based PC or a Macintosh with Ethernet connectivity for configuring the Netopia R2121. This may be built-in Ethernet or an add-on card, with TCP/IP installed and configured. See SmartStart”...
Page 25
Netopia R2121 are powered ON. the computer running SmartStart and the Netopia R2121 to be configured must be on the same Ether- net segment; there can be no intervening routers. Repeaters, such as 10Base-T hubs, are acceptable.
2-4 User’s Reference Guide Netopia R2121 Dual Analog Router Back Panel Ports The figure below displays the back of the Netopia R2121 with Dual Analog. Netopia R2121 with Dual Analog back panel Ethernet Crossover switch 8 port Ethernet hub Telco or line ports...
Page 27
The following table describes all the Netopia R2121 Dual Analog Router back panel ports. Port Power port a mini-DIN8 power adapter cable connection. Telco 1 port a red RJ-11 telephone jack labelled “Telco 1". Console port a DE-9 Console port for a direct serial connection to the console screens. You may use this if you are an experienced user and choose not to use SmartStart.
2-6 User’s Reference Guide Netopia R2121 Dual Analog Router Status Lights The figure below represents the Netopia R2121 status light (LED) panel. Netopia R2121 LED front panel 2 3 4 5 Modem 1 The following table summarizes the meaning of the various LED states and colors: When this happens...
Page 29
Making the Physical Connections 2-7 When this happens... the LEDs... when link is detected 14 though 21 are solid green. when data is received on their respective ports 14 though 21 flash green...
Once you’ve connected your router to your computer and your telecommunications line and installed a web browser, you’re ready to run the Netopia SmartStart™ Wizard. The SmartStart Wizard will help you set up the router and share the connection. The SmartStart Wizard walks you through a series of questions and based on your responses automatically configures the router for connecting your LAN to the Internet or to your remote...
Page 32
SmartStart, in case you do not want to use the dynamic addressing features built in to the Netopia Router and need to restore the fixed IP address.
The SmartStart Wizard presents a series of screens to guide you through the preliminary configuration of a Netopia R2121. It will then create a connection profile using the information you supply to it. Welcome screen. The first screen welcomes you to the SmartStart Wizard configuration utility.
Check your cable connections. Be sure you have connected the router and the computer properly, using the correct cables. Refer to the Step 1 “Connect the Router” sheet in your Netopia R2121 documentation folio. Make sure the router is turned on and that there is an Ethernet connection between your computer and the router.
Page 35
ISP Automation or Manual Entry. Options are explained below. Make your selection and click Next. If you select ISP Automation, SmartStart offers you the option of choosing one of several Netopia ISP partners that support the Netopia R2121. You then see the page 3-5.
Page 36
3-6 User’s Reference Guide with: Your dial-up number, sometimes referred to as an ISP POP number Your Login name and Password. (These are case-sensitive.) Note: Your ISP may provide you with additional values such as “Remote IP Gateway” or “Subnet Mask.” These entries are not required for the SmartStart Wizard to configure your router.
Page 37
Connection Profile Test screen. SmartStart tests your connection profile by attempting to connect to your ISP. To test the connection profile with your ISP, click Next. While the test is running, SmartStart reports its progress in a brief succession of dialog boxes as described below. Available Line Test Progress screen.
3-8 User’s Reference Guide Advanced option Router IP Address screen. If you selected the Advanced option in the “Easy or Advanced options screen” on page 3-4, SmartStart asks you to choose between entering the router’s current IP address and assigning an IP address to the router.
Remember, the serial number is on the bottom of the router. It is also found in your documentation folio. Note: Forcing a new IP address may turn off the Netopia R2121’s IP address serving capabilities, if you assign an IP address and subnet mask outside the router’s current...
Page 40
3-10 User’s Reference Guide Dynamic configuration (recommended) If you configure your Netopia R2121 using SmartStart, you can accept the dynamic IP address assigned by your router. The Dynamic Host Configuration Protocol (DHCP) server, which enables dynamic addressing, is enabled by default in the router. If your PC is not set for dynamic addressing, SmartStart will offer to do this for you when you launch it.
Page 41
Static configuration (optional) If you are manually configuring for a fixed or static IP address, perform the following: Go to Start Menu/Settings/Control Panels and double click the Network icon. From the Network components list, select the Configuration tab. Select TCP/IP-->Your Network Card. Then select Properties. In the TCP/IP Properties screen (shown below), select the IP Address tab.
Page 42
Click on the Gateway tab (shown below). Under “New gateway,” enter 192.168.1.1. Click Add. This is the Netopia R2121’s pre-assigned IP address. Click OK in this window, and the next window. When prompted, reboot the computer. Note: You can also use these instructions to configure other computers on your network with manual or static IP addresses.
Macintosh. Dynamic configuration (recommended) If you configure your Netopia R2121 using SmartStart, you can accept the dynamic IP address assigned by your router. The Dynamic Host Configuration Protocol (DHCP), which enables dynamic addressing, is enabled by default in the router. To configure your Macintosh computer for dynamic addressing do the following: Go to the Apple menu.
Page 44
3-14 User’s Reference Guide Static configuration (optional) If you are manually configuring for a fixed or static IP address, perform the following: Go to the Apple menu. Select Control Panels and then TCP/IP or MacTCP. With the TCP/IP window open, go to the Edit menu and select User Mode.
Page 45
If you want to use MacIP to dynamically assign IP addresses to the Macintosh computers on your network you must install the optional AppleTalk feature set kit. Note: You cannot use MacIP dynamic configuration to configure your Netopia R2121 Dual Analog Router because you must first configure the router in order to enable AppleTalk.
Page 46
These are the only fields you need to modify in these screens. Note: More information about configuring your Macintosh computer for TCP/IP connectivity through a Netopia R2121 can be found in Technote NIR_026, “Open Transport and Netopia Routers,” located on the Netopia Web site.
M M M M o o o o n n n n i i i i t t t t o o o o r r r r i i i i n n n n g g g g w w w w i i i i t t t t h h h h S S S S m m m m a a a a r r r r t t t t V V V V i i i i e e e e w w w w This chapter discusses SmartView, the Netopia R2121’s device and network web-based monitoring tool. This tool can provide statistical information, report on current network status, record events, and help in diagnosing and locating problems.
In addition to the static machine information about your router, such as model and firmware version, SmartView displays a real-time visual representation of the Netopia R2121’s status lights (LEDs). This is particularly useful if the router is located out of visual range, such as in a wiring closet.
You can view two different event histories: one for the router’s system and one for the WAN. The Netopia R2121’s built-in battery backup prevents loss of event history from a shut down or reset.
Page 50
4-4 User’s Reference Guide Device Event History page WAN Event History page...
To view Event Histories, click the Statistics icon. To go to SmartView, if your browser is Java-enabled, click the SmartView icon. For information on other advanced monitoring tools built into your Netopia R2121 Dual Analog Router, see “Monitoring Tools” on page 13-1.
Before connecting the Netopia R2121 to any AppleTalk LANs that contain other AppleTalk routers, you should read “Routers and seeding” on page 12-3. See the sections later in this chapter for details on how to connect the Netopia R2121 to different types of networks. Readying computers on your local network PC and Macintosh computers must have certain components installed before they can communicate through the Netopia R2121.
Page 54
TCP/IP stack: This is the software that lets your PC or Macintosh communicate using Internet protocols. TCP/IP stacks must be configured with some of the same information you used to configure the Netopia R2121. There are a number of TCP/IP stacks available for PC computers. Windows 95 includes a built-in TCP/IP stack. See “Configuring TCP/IP on Windows 95, 98, or NT computers”...
The Netopia R2121 supports Ethernet connections through its eight Ethernet ports. The Router automatically detects which Ethernet port is in use. You can connect either 10Base-T or EtherWave Ethernet networks to the Netopia R2121. The following table displays some important attributes of these types of Ethernet.
Ethernet The Netopia R2121 in a 10Base-T network To connect your 10Base-T network to the Netopia R2121 through an Ethernet port, use a 10Base-T cable with RJ-45 connectors. If you have more than eight devices to connect, you can attach additional devices using either a 10Base-T hub or an EtherWave™...
If you add devices connected through a hub, connect the hub to Ethernet port number 1 on the Netopia R2121 and set the Normal/Uplink switch to Uplink. When there are no more free ports on the 10Base-T hub, the network can be extended using EtherWave, a daisy-chainable Ethernet solution from Farallon.
HD-15 (female) Connect the male HD-15 end of the LocalTalk cable to the Auxiliary port on your Netopia R2121. Connect the other end of the cable to your LocalTalk network. You can use only one connection on the Auxiliary port. You cannot use both the PhoneNET connector and an external modem.
Wiring guidelines for PhoneNET cabling Topology daisy chain backbone 4-branch passive star* LocalTalk StarController 12-branch active star * distance is per branch Note: Make sure you do not connect your LocalTalk network to a Telco port or a POTS (Phone 1 and 2) port. For detailed configuration instructions see Connecting Your Local Area Network 5-7 22 gauge...
Page 61
P P P P a a a a r r r r t t t t I I I I I I I I : : : : A A A A d d d d v v v v a a a a n n n n c c c c e e e e d d d d C C C C o o o o n n n n f f f f i i i i g g g g u u u u r r r r a a a a t t t t i i i i o o o o n n n n...
C C C C o o o o n n n n s s s s o o o o l l l l e e e e - - - - b b b b a a a a s s s s e e e e d d d d M M M M a a a a n n n n a a a a g g g g e e e e m m m m e e e e n n n n t t t t Console-based management is a menu-driven interface for the capabilities built in to the Netopia R2121.
“Quick View status overview” on page 13-1 Connecting through a Telnet session Features of the Netopia R2121 may be configured through the console screens. Before you can access the console screens through Telnet, you must have: a network connection locally to the router or IP access to the router through the WAN port. This could be the same connection as the one you used with SmartStart.
ZTerm, included on the Netopia CD, for the Macintosh. The Netopia R2121 back panel has a connector labeled “Console” for attaching the Router to either a PC or Macintosh computer via the serial port on the computer. (On a Macintosh, the serial port is called the Modem port or the Printer port.) This connection lets you use the computer to configure and monitor the Netopia R2121...
The new baud rate is displayed at the bottom of the screen. Navigating through the console screens Use your keyboard to navigate the Netopia R2121’s configuration screens, enter and edit information, and make choices. The following table lists the keys to use to navigate through the console screens.
E E E E a a a a s s s s y y y y S S S S e e e e t t t t u u u u p p p p This chapter describes how to use the Easy Setup console screens on your Netopia R2121 Dual Analog Router.
Page 68
If you do not see the Main Menu, verify that: the computer used to view the console screen has its serial port connected to the Netopia R2121’s “Console” port or an Ethernet connection to one of its Ethernet ports. See console cable to your router”...
ISP or a corporate site. On a Netopia R2121 Dual Analog Router you can add up to 15 more connection profiles, for a total of 16. See “Creating a new Connection Profile” on page Select Number to Dial and enter the telephone number you received from your ISP.
However, you may enter another address if you want to use static addressing. When using numbered interfaces, the Netopia Router will use its local WAN IP address and subnet mask to send packets to the remote router. Both routers have WAN IP addresses and subnet masks associated with the connection.
Page 71
Select Primary Domain Name Server and enter the IP address your ISP has given you. The Default IP Gateway defaults to the remote IP address you entered in the Easy Setup connection profile. If the Netopia Router does not recognize the destination of any IP traffic, it forwards that traffic to this gateway.
PREVIOUS SCREEN Configure a Configuration Access Name and Password here. The final step in configuring the Easy Setup console screens is to restart the Netopia R2121, so the configuration settings take effect. Select RESTART DEVICE. A prompt asks you to confirm your choice.
This chapter describes how to use the console-based management screens to access and configure advanced features of your Netopia R2121 Dual Analog Router. You can customize these features for your individual setup. These menus provide a powerful method for experienced users to set up their router’s connection profiles and system configuration.
Configure a new Conn. Profile. Finished? On a Netopia R2121 Dual Analog Router you can add up to 15 more connection profiles, for a total of 16. Select Profile Name and enter a name for this connection profile. It can be any name you wish. For example: the name of your ISP.
Page 75
Address Translation Enabled: Local WAN IP Address: Remote IP Address: Remote IP Mask: Filter Set... Remove Filter Set Receive RIP: Toggle to Yes if this is a single IP address ISP account. Configure IP requirements for a remote network connection here. Toggle or enter any IP Parameters you require and return to the Add Connection Profile screen by pressing Escape.
Page 76
8-4 User’s Reference Guide Select Datalink Options and press Return. The Datalink Options screen appears. Data Compression... Send Authentication... Send User Name: Send Password: Receive User Name: Receive Password: Channel Usage... Bandwidth Allocation... Maximum Packet Size: In this Screen you will configure the PPP/MP specific connection params. You can accept the defaults, or change them if you wish.
Page 77
The Channel Usage pop-up menu allows you to choose how many lines your connections may use, and whether or not they are preemptable. Supported options are: Option Dynamic 1-Channel 2-Channels 2-Channel Preemptable 3-Channels 3-Channel Preemptable Note: The Bandwidth Allocation pop-up options are: Off, Auto, BAP or MP+. BAP is the default. You should only choose one of the other options if you are specifically advised to do so by your ISP or administrator.
8-6 User’s Reference Guide add an alternate number to use if the first number fails to connect change any of the default parameter settings When you are finished with these entries, press Escape to return to the Add Connection Profile screen. Select ADD PROFILE NOW and press Return.
Select the connection profile you want to view or edit and press Return. The profile is displayed, and you can change any of the parameters. Changes take effect immediately without rebooting the router. Profile Name: Profile Enabled: IP Enabled: IP Profile Parameters... IPX Enabled: Data Link Encapsulation is Data Link Options...
6-3) You can also retrieve the Netopia R2121’s configuration information and remotely set its parameters using the Simple Network Management Protocol (see Open a Telnet connection to the IP address you set in the router with SmartStart, for example “192.168.1.1.”...
To go back in this sequence of screens, use the Escape key. System Configuration features SmartStart may be all you need to configure your Netopia R2121. Some users, however, require advanced settings or prefer manual control over the default selections that SmartStart automatically chooses. For these users, the Netopia R2121 provides System Configuration options.
Page 82
8-10 User’s Reference Guide Layer Category Datalink Layer PPP/MP Parameters Physical Layer Telco Parameters To access the System Configuration screens, select System Configuration in the Main Menu, then press Return. The System Configuration Menu screen appears: Return/Enter to configure Networking Protocols (such as TCP/IP). Use this screen if you want options beyond Easy Setup.
Network Protocols Setup These screens allow you to configure your network’s use of the standard networking protocols: IP: details are given in “IP Setup, SmartIP and Network Address Translation” on page IPX: details are given in “IPX Setup” on page 11-1. AppleTalk: details are given in Note: AppleTalk requires the optional AppleTalk feature expansion kit.
8-12 User’s Reference Guide Select Current Date and enter the date in the appropriate format. Use one- or two-digit numbers for the month and day, and the last two digits of the current year. The date’s numbers must be separated by forward slashes (/).
You can upgrade your Netopia R2121 by adding new feature sets through the Upgrade Feature Set utility. See the release notes that came with your router or feature set upgrade or visit the Netopia web site at www.netopia.com for information on new feature sets, how to obtain them, and how to install them on your Netopia R2121.
You can specify the UNIX syslog Facility to use by selecting the Facility pop-up. Installing the Syslog client The Goodies folder on the Netopia CD contains a Syslog client daemon program that can be configured to report the WAN events you specified in the Logging Configuration screen.
Page 87
The following screen shows a sample syslog dump of WAN events: 5 10:14:06 tsnext.farallon.com 5 10:14:06 tsnext.farallon.com >>Issued Speech Setup Request from our DN: 5108645534 5 10:14:06 tsnext.farallon.com 5 10:14:06 tsnext.farallon.com 5 10:14:06 tsnext.farallon.com 5 10:14:06 tsnext.farallon.com >>Issued Speech Setup Request from our DN: 5108645534 5 10:14:06 tsnext.farallon.com 5 10:14:06 tsnext.farallon.com 5 10:14:06 tsnext.farallon.com...
Page 89
It is also useful for once-only connections that you want to schedule in advance. The Netopia R2121 Dual Analog Router can answer calls as well as initiate them. To answer calls, the Netopia R2121 uses a Default Answer Profile. The Default Answer Profile controls how incoming calls are set up, authenticated, filtered, and more.
9-2 User’s Reference Guide Specifying telephone connections You can configure telephone connections in the WAN Configuration screen under the Main Menu. Select WAN (Wide Area Network) Setup. Return/Enter for WAN line configuration. From here you will configure yours and the remote sites' WAN information. The Internal Modem Configuration screen appears.
Page 91
Allows carrier tones to be heard, as well. You can specify how to use the auxiliary serial port on the Netopia R2121’s back panel. By default, this port is enabled for an external asynchronous modem. If you have installed the optional AppleTalk feature set, then this port defaults to a LocalTalk connection.
Default Answer Profile for Dial-in Connections The Netopia R2121 Dual Analog Router can answer calls as well as initiate them. To answer calls, the Netopia R2121 uses a Default Answer Profile. The Default Answer Profile controls how incoming calls are set up, authenticated, filtered, and more.
Page 93
Required: Authentication is attempted if the calling number is available. If authentication fails, or the calling number is not available, the Netopia Router disconnects the caller. Use this setting if you require all calls to be CNA-authenticated. Calling Number Authentication (CNA), is an application of CallerID. It is a method of verifying that an incoming call is originating from an expected site.
Page 94
If a remote network has a non-standard mask (that is, it uses subnetting), the only way for it to successfully connect to the Netopia Router is by matching a connection profile. In other words, you will have to set up a connection profile for that network.If Must Match a Defined Profile is set to No, you can also set the...
Call acceptance scenarios The following are a few common call acceptance scenarios and information on how to configure the Netopia R2121 for those purposes. To accept all calls, regardless of whether they match a connection profile: Toggle Must Match a Defined Profile to No.
Page 96
9-8 User’s Reference Guide Navigate from here to add/modify/change/delete Scheduled Connections. Viewing scheduled connections To display a table of view-only scheduled connections, select Display/Change Scheduled Connection in the Scheduled Connections screen. Each scheduled connection occupies one row of the table. +-Days----Begin At---HH:MM---When----Conn.
Page 97
The other columns show: The time of day that the connection will Begin At The duration of the connection (HH:MM) Whether it’s a recurring Weekly connection or used Once Only Which connection profile (Conn. Prof.) is used to connect Whether the scheduled connection is currently Enabled The router checks the date and time set in scheduled connections against the system date and time.
Page 98
9-10 User’s Reference Guide Only from the pop-up menu. The Schedule Type item directly below How Often allows you to set the type of schedule. Options are:. Selection: Forced Up Forced Down Demand-Allowed Demand-Blocked Periodic If How Often is set to Weekly, the item directly below Schedule Type reads Set Weekly Schedule. If How Often is set to Once Only, the item directly below How Often reads Set Once-Only Schedule.
Page 99
1:3 (or 1:03) would be accepted as 3 minutes after one o’clock. The entry 7:0 (or 7:00) would be accepted as seven o’clock, exactly. The entries 44, :5, and 2: would be rejected. Select AM or PM and choose AM or PM from the pop-up menu. Select Scheduled Window Duration Per Day and enter the maximum duration allowed for this scheduled connection, per call.
Escape key. Cost control feature -- call accounting The Netopia R2121 offers system-wide and per connection profile call accounting to track first minutes and additional minutes, for initiated data and voice calls. Main Menu To go to the Call Accounting screen, select Call Accounting Configuration in the WAN Configuration screen.
Page 101
Enable Call Accounting: Day for auto-reset of timers: Maximum Aggregate connect time: To enable call accounting, follow these steps: Select Enable Call Accounting and toggle it to On. Select Day for auto-reset of timers and enter the day of the month for the Router to reset the Call Account- ing Statistics.
9-14 User’s Reference Guide Once you have enabled Call Accounting, you can specify per-connection profile limits in the Telco Options for each profile. Go to: Main Menu Configuration Dial... Dialing Prefix: Number to Dial: Alternate Site to Dial: Dial on Demand: Idle Timeout (seconds): CNA Validation Number: Callback:...
Page 103
The Call Accounting Statistics screen appears. If you select Aggregate Statistics, the following screen appears. Total First Minutes: Total Additional Time (HH:MM): Remaining Time (HH:MM): Trigger Date(MDY): Hit Return or Enter to reset Total First/Additional Time. Total First Minutes displays the total number of first minutes of outbound calls placed during the recording interval.
Page 104
9-16 User’s Reference Guide enabled, the message will read, Aggregate Not Enforced. Trigger Date (MDY) displays the date, in month, day, year format, when the call accounting begins. You can reset the counters by selecting RESET AGGREGATE MINUTE COUNTERS. A dialog box will ask you to confirm the reset.
I I I I P P P P S S S S e e e e t t t t u u u u p p p p , , , , S S S S m m m m a a a a r r r r t t t t I I I I P P P P a a a a n n n n d d d d N N N N e e e e t t t t w w w w o o o o r r r r k k k k A A A A d d d d d d d d r r r r e e e e s s s s s s s s T T T T r r r r a a a a n n n n s s s s l l l l a a a a t t t t i i i i o o o o n n n n The Netopia R2121 uses Internet Protocol (IP) to communicate both locally and with remote networks. This chapter shows you how to configure the Router to route IP traffic.
Page 106
Connection Profiles simultaneously to connect to two or more networks. Each profile may have Network Address Translation enabled. When Network Address Translation is enabled, the Netopia R2121 can either use a statically assigned IP address, or one dynamically assigned each time the router connects to the ISP. While a dynamically assigned IP address offers the ISP more flexibility, it does have an important limitation.
Pick a network number for your local network (referred to as the internal network). This can be any IP address range you want. The Netopia R2121 Dual Analog Router has a default IP address of 192.168.1.1. You may choose to change this address to match a pre-existing addressing scheme. For this example, we will use 10.0.0.0.
Page 108
ISP assigns an address each time you connect. However, if you want to use static addressing you may enter a specific address. When your Netopia R2121 connects to the ISP, the remote router assigns your Netopia R2121 an IP address that external users use to communicate with your network.
Telnet uses port number 23 SNMP uses port number 161 To help direct incoming IP traffic to the appropriate server, the Netopia R2121 lets you associate these and other port numbers to distinct IP addresses on your internal LAN using Exported Services. See page 10-6 for details.
Main Menu The IP Setup options screen is where you configure the Ethernet side of the Netopia R2121. The information you enter here controls how the Router routes IP traffic. Consult your network administrator or Internet Service Provider to obtain the IP setup information (such as the Ethernet IP Address, Ethernet Subnet Mask, Default IP Gateway and DNS Server IP Address) you will need before changing any of the settings in this screen.
Page 111
Select Default IP Gateway and enter the IP address for a default gateway. This can be the address of any major router accessible to the Netopia R2121. A default gateway should be able to successfully route packets when the Netopia R2121 cannot recognize the intended recipient’s IP address. A typical example of a default gateway is the ISP’s router.
Page 112
Select any of the services/ports and press Return to associate it with the address of a server on your local area network. For example, if we select www-http 80, press Return, and type 10.0.0.2. The Netopia R2121 will then redirect any incoming traffic destined for a Web server to address 10.0.0.2.
Page 113
Routing Information Protocol (RIP) is needed if there are IP routers on other segments of your Ethernet network that the Netopia R2121 needs to recognize. If this is the case select Receive RIP and select v1, v2, or Both from the popup menu. With Receive RIP set to “v1,” the Netopia R2121’s Ethernet port will accept routing information provided by RIP packets from other routers that use the same subnet mask.
fields to indicate that you can edit the values in this row to configure an additional subnet. All eight row labels are always visible, regardless of the number of subnets configured. To add an IP subnet, enter the Netopia R2121’s IP address on the subnet in the IP Address field in a IP Subnets...
Page 115
particular row and the subnet mask for the subnet in the Subnet Mask field in that row. For example: IP Address ---------------- 192.128.117.162 192.128.152.162 0.0.0.0 To delete a configured subnet, set both the IP address and subnet mask values to 0.0.0.0, either explicitly or by clearing each field and pressing Return or Enter to commit the change.
Static routes are IP routes that are maintained manually. Each static route acts as a pointer that tells the Netopia R2121 how to reach a particular network. However, static routes are used only if they appear in the IP routing table, which contains all of the routes used by the Netopia R2121 (see Static routes are helpful in situations where a route to a network must be used and other means of finding the...
Page 117
Configure/View/Delete Static Routes from this and the following Screens. Viewing static routes To display a view-only table of static routes, select Display/Change Static Route in the Static Routes screen. +-Dest. Network---Subnet Mask-----Next Gateway----Priority-Enabled-+ +------------------------------------------------------------------+ | 0.0.0.0 +------------------------------------------------------------------+ Select a Static Route to modify. The table has the following columns: Dest.
Page 118
Select Destination Network Subnet Mask and enter the subnet mask used by the destination network. Select Next Gateway IP Address and enter the IP address for the router that the Netopia R2121 will use to reach the destination network. This router does not necessarily have to be part of the destination network, but it must at least know where to forward packets destined for that network.
Page 119
Rules of static route installation The Netopia R2121 applies certain rules before installing enabled static routes in the IP routing table. An enabled static route will not be installed in the IP routing table if any of the following conditions are true: The static route’s Next Gateway IP Address matches the IP address used by a connection profile or the...
Menu Configuration In addition to being a router, the Netopia R2121 is also an IP address server. There are four protocols it can use to distribute IP addresses. The first, called Dynamic Host Configuration Protocol (DHCP), is widely supported on PC networks, as well as Apple Macintosh computers using Open Transport and computers using the UNIX operating system.
Page 121
DHCP, BOOTP, Dynamic WAN, and/or MacIP. Example: Your ISP has given your Netopia R2121 the IP address 192.168.6.137, with a subnet mask of 255.255.255.248. The subnet mask allocated will give you six IP addresses to use when connecting to the ISP over the Internet (for more information on understanding IP addressing refer to “Understanding IP...
10-18 User’s Reference Guide DHCP NetBIOS Options If your network uses NetBIOS, you can enable the Netopia R2121 to use DHCP to distribute NetBIOS information. NetBIOS stands for Network Basic Input/Output System. It is a layer of software originally developed by IBM and Sytek to link a network operating system with specific hardware.
Page 123
Note: Addresses assigned through BOOTP are permanently allocated from the IP Address Serving pool until you release them. To view all of the IP addresses currently being served by the Netopia R2121, from the Statistics & Logs menu select Served IP Addresses.
Page 124
10-20 User’s Reference Guide The Served IP Addresses screen appears. -IP Address-------Type----Expires--Client Identifier-------------------------- ----------------------------------SCROLL UP----------------------------------- 192.168.1.100 192.168.1.101 192.168.1.102 192.168.1.103 192.168.1.104 192.168.1.105 192.168.1.106 192.168.1.107 192.168.1.108 192.168.1.109 192.168.1.110 192.168.1.111 192.168.1.112 192.168.1.113 ---------------------------------SCROLL DOWN---------------------------------- Lease Management... EN = Ethernet Address; AT = AppleTalk Address; CP = Profile Name; HX = hex To release these addresses, select Lease Management.
Select MacIP/KIP Static Options and press Return. The MacIP (KIP) Forwarding Setup screen tells the Netopia R2121 how many static addresses to allocate for MacIP/KIP clients. The addresses must fall within the address pool from the previous screen. You will need to enter the number of static MacIP addresses to reserve in this screen.
Internetwork Packet Exchange (IPX) is the network protocol used by Novell NetWare networks. This chapter shows you how to configure the Netopia R2121 for routing data using IPX. You also learn how to configure the router to serve IPX network addresses.
11-2 User’s Reference Guide IPX address An IPX address consists of a network number, a node number, and a socket number. An IPX network number is composed of eight hexadecimal digits. The network number must be the same for all nodes on a particular physical network segment.
IPX Spoofing The Netopia R2121 has several IPX features designed to restrict the traffic on the dial-up link when the unit is not sending or receiving IPX data. When the link is idle and a user is logged into a Novell server, the server will send “keep alive”...
Page 130
IPX network to only those required by remote users connecting to the Netopia R2121. An Ethernet SAP filter must be used with networks that have so many servers advertised that the Netopia R2121 would otherwise exhaust its internal memory storing server entries.
Select Default Gateway Address, and enter the network address of the IPX network to which all packets of unknown destination address should be routed. Note: The Default Gateway Address is usually set up to match the IPX Address in your network Connection Profile.
Page 132
11-6 User’s Reference Guide To configure IPX routing in the answer profile, select IPX Parameters and go to the IPX Parameters (Default Answer Profile) screen. The items in this screen are similar to the IPX Profile Parameters items of the same name (see page 11-5).
IPX routing tables Main Menu IPX routing tables provide information on current IPX routes and services. To go to the IPX Routing Table screen, select IPX Routing Table in the Routing Tables screen. This table shows detailed information about current IPX network routes. Net Addr-Hops-Ticks-Type--Status-Interface--------------via Router------------ -----------------------------------SCROLL UP---------------------------------- 00000020...
This chapter discusses the concept of AppleTalk routing and how to configure AppleTalk Setup for a Netopia R2121 with the AppleTalk kit installed. AppleTalk support is available as a separate kit for the Netopia R2121 Dual Analog Router. Skip this chapter if you do not have the AppleTalk kit.
Page 136
AppleTalk tells them apart according to an additional part of their addresses: the network number. The Netopia R2121 assigns a unique network number to each member network. In terms of the city street metaphor, the network number is similar to the name of the street. Putting a network number together with a node number fully specifies the address of a node on an internet.
When two networks using AppleTalk communicate with each other through a network based on the Internet Protocol, they are said to be tunneling through the IP network. The Netopia R2121 uses AURP to allow your AppleTalk network to tunnel to designated AppleTalk partner networks, as well as to accept connections from remote AppleTalk networks tunneling to your AppleTalk LAN.
You should set the Netopia R2121’s seeding action to work best in your particular network environment. These scenarios may guide you in deciding how to set the router’s seeding: If the Netopia R2121 is the only router on your network, you must set it to either hard seeding or soft seeding. The default is soft seeding.
Page 139
Main Menu The Netopia Feature Set Upgrade screen appears. You may be able to extend the features of your Netopia by purchasing a 'Software Upgrade'. notes that came with your Netopia or visit the Netopia Communications web site at www.netopia.com.
Otherwise, your EtherTalk network may experience routing conflicts. The Netopia R2121 supports creating up to 32 zone names. As an alternative, you can set EtherTalk seeding to soft seeding and let the Netopia R2121 receive the zone name and network number from the other router.
Note: Your LocalTalk network may already have a zone and network number in place. For the Netopia R2121’s LocalTalk port to be part of your LocalTalk network, it must have a network number and zone name that matches the values in use on the LocalTalk network.
12-8 User’s Reference Guide As an alternative, you can set LocalTalk seeding to soft seeding and let the Netopia R2121 receive the zone name and network number from the other router. Select LocalTalk Network Number and enter the desired network number.
Page 143
Site A has an AURP tunnel to site B. Both sides have multiple zones defined on the EtherTalk port and a unique zone on their LocalTalk ports. If side A has indicated one of its EtherTalk zones is the Free Trade Zone and has opted to use the Free Trade Zone option for its tunnel to B, then only this Free Trade Zone will show up on side B and only those machines or services in the Free Trade Zone will be accessible to side B.
Page 144
The AURP tickle timer is a parameter that you can set anywhere between 0 and 100 hours. This parameter tells the AURP partners when to send out an AURP tickle packet. If this value is set to 0, the Netopia R2121 will never send out a tickle packet.
Page 145
Update Interval every time there's such a change in the network topology. This will cause the Netopia's WAN link to be brought up. You can opt to minimize what may be unnecessary calls by changing the Update Interval value to some larger value. At the end of this time window if there has been a local AppleTalk network change the Netopia R2121 will call any remote AURP partner and forward the new network information.
“SNMP” on page 13-13 Quick View status overview You can get a useful, overall status report from the Netopia R2121 in the Quick View screen. To go to the Quick View screen, select Quick View in the Main Menu. The Quick View screen has three status sections:...
IPX Address: The Netopia R2121’s IPX address, entered in the IPX Setup screen. EtherTalk Address: The Netopia R2121’s AppleTalk address on its EtherTalk Phase II interface, entered in the EtherTalk Phase II Setup screen (only if the optional AppleTalk feature set is installed).
ISDN caller identification (if available). Status lights This section shows the current real-time status of the Netopia R2121’s status lights (LEDs). It is useful for remotely monitoring the router’s status. The Quick View screen’s arrangement of LEDs corresponds to the physical arrangement of LEDs on the router.
Main Menu When you are troubleshooting your Netopia R2121, the Statistics screens provide insight into the recent event activities of the Router. From the Main Menu go to Statistics & Logs and select one of the options described in the sections below.
You can view two different event histories: one for the router’s system and one for the WAN. The Netopia R2121’s built-in battery backup prevents loss of event history from a shut down or reset.
Page 152
13-6 User’s Reference Guide WAN Event History The WAN Event History screen lists a total of 128 events on the WAN. The most recent events appear at the top. To go to the WAN Event History screen, select WAN Event History in the Statistics & Logs screen. -Date-----Time-----Event------------------------------------------------------ ----------------------------------SCROLL UP----------------------------------- 11/22/98 01:56:49...
Page 153
Date: Date of the event. Event: A brief description of the event. Ch.: The channel involved in the event. Dir. Number: The directory number (number dialed) involved in the event. The first event in each call sequence is marked with double arrows (>>). Failures are marked with an asterisk (*).
Return. Routing Tables You can view all of the IP, IPX and AppleTalk routes in the Netopia R2121’s IP, IPX and AppleTalk routing tables, respectively. To go to a Routing Table screen, select the Routing Table you are interested in from the Statistics & Logs screen.
Page 155
IPX Sap Bindery table The IPX Sap Bindery table displays all of the IPX Sap Bindery routes currently known to the Netopia R2121. To display the IPX SAP Bindery Table screen, select IPX Sap Bindery Table in the Statistics & Logs screen and press Return.
Page 156
AppleTalk network (e.g.: LocalTalk or EtherTalk Phase II). An IP address is displayed if the Netopia R2121 is connected to the router shown using AURP. IP address means a connection transports over AURP (AppleTalk encapsulated IP).
Pkts Fwded: The number of packets sent to the router shown. Served IP Addresses You can view all of the IP addresses currently being served by the Netopia R2121 Dual Analog Router from the Served IP Addresses screen. From the Statistics & Logs menu, select Served IP Addresses.
Page 158
13-12 User’s Reference Guide The IP Address Lease Management screen appears. Reset All Leases Release BootP Leases Reclaim Declined Addresses Hit RETURN/ENTER, you will return to the previous screen. By selecting each of these options you can: Reset all current IP addresses leased through DHCP without waiting for the default one hour lease period to elapse Release BootP leases that may be in place, and which may no longer be required Reclaim served leases that have been declined, for example by devices which may no longer be on the...
AppleTalk MIB-I (RFC 1243) Netopia MIB These MIBs are on the Netopia R2121 CD included with the Netopia R2121. You should load these MIBs into your SNMP management software in the order they are listed here. Follow the instructions included with your SNMP manager on how to load MIBs.
Select System Contact and enter the name of the person responsible for maintaining the router. System Name, System Location, and System Contact set the values returned by the Netopia R2121 SNMP agent for the SysName, SysLocation, and SysContact objects, respectively, in the MIB-II system group. Although optional, the information you enter in these items can help a system administrator manage the network more efficiently.
SNMP traps An SNMP trap is an informational message sent from an SNMP agent (in this case, the Netopia R2121) to a manager. When a manager receives a trap, it may log the trap as well as generate an alert message of its own.
Page 162
13-16 User’s Reference Guide Return/Enter to modify an existing Trap Receiver. Navigate from here to view, add, modify and delete IP Trap Receivers. Setting the IP trap receivers Select Add IP Trap Receiver. Select Receiver IP Address or Domain Name. Enter the IP address or domain name of the SNMP manager you want to receive the trap.
S S S S e e e e c c c c u u u u r r r r i i i i t t t t y y y y The Netopia R2121 provides a number of security features to help protect its configuration screens and your local network from unauthorized access.
14-2 User’s Reference Guide User accounts When you first set up and configure the Netopia R2121, no passwords are required to access the configuration screens. Anyone could tamper with the router’s configuration by simply connecting it to a console. However, by adding user accounts, you can protect the most sensitive screens from unauthorized access. User accounts are composed of name/password combinations that can be given to authorized users.
Remote modem terminal emulator setups can dial in to either internal modem line and establish a remote console session, even though they are not using PPP. This allows Netopia Inc.'s “Up and Running, Guaranteed!” department or other administrator with the appropriate security to remotely configure your router for you. If you used SmartStart to configure your router, this option will be set to “No”.
SmartStart. To prevent access to these features toggle this option to “No”. Telnet access Telnet is a TCP/IP service that allows remote terminals to access hosts on an IP network. The Netopia R2121 supports Telnet access to its configuration screens. Caution! You should consider password-protecting or restricting Telnet access to the Netopia R2121 if you suspect there is a chance of tampering.
Security 14-5 How filter sets work A filter set acts like a team of customs inspectors. Each filter is an inspector through which incoming and outgoing packages must pass. The inspectors work as a team, but each inspects every package individually. Each inspector has a specific task.
Page 168
14-6 User’s Reference Guide If the package does not match the first inspector’s criteria, it goes to the second inspector, and so on. You can see that the order of the inspectors in the line is very important. For example, let’s say the first inspector’s orders are to send along all packages that come from Rome, and the second inspector’s orders are to reject all packages that come from France.
This rule applies to Telnet packets that come from a host with the IP address 199.211.211.17. If a match occurs, the packet is blocked. Here is what this rule looks like when implemented as a filter on the Netopia R2121: +-#--Source IP Addr--Dest IP Addr-----Proto-Src.Port-D.Port--On?-Fwd-+ +--------------------------------------------------------------------+ 199.211.211.17...
Page 170
14-8 User’s Reference Guide Port numbers A filter can also match a packet’s port number attributes, but only if the filter’s protocol type is set to TCP or UDP, since only those protocols use port numbers. The filter can be configured to match the following: The source port number (the port on the sending host that originated the packet) The destination port number (the port on the receiving host that the packet is destined for) By matching on a port number, a filter can be applied to selected TCP or UDP services, such as Telnet, FTP, and...
Page 171
Greater Than or Equal: For the filter to match, the packet’s port number must be greater than or equal to the port number specified in the filter. Other filter attributes There are three other attributes to each filter: The filter’s order (i.e., priority) in the filter set Whether the filter is currently active Whether the filter is set to pass (forward) packets or to block (discard) packets Putting the parts together...
Page 172
14-10 User’s Reference Guide Protocol Src. Port: The source port to match. This is the port on the sending host that originated the packet. D. Port: The destination port to match. This is the port on the receiving host for which the packet is intended. On?: Displays Yes when the filter is in effect or No when it is not.
This four-step process is how we produced the following filter from the original rule: +-#---Source IP Addr---Dest IP Addr-----Proto-Src.Port-D.Port--On?-Fwd-+ +----------------------------------------------------------------------+ 192.211.211.17 +----------------------------------------------------------------------+ Filtering example #2 Suppose a filter is configured to block all incoming IP packets with the source IP address of 200.233.14.0, regardless of the type of connection or its destination.
14-12 User’s Reference Guide Disadvantages of filters Although using filter sets can greatly enhance network security, there are disadvantages: Filters are complex. Combining them in filter sets introduces subtle interactions, increasing the likelihood of implementation errors. Enabling a large number of filters can have a negative impact on performance. Processing of packets will take longer if they have to go through many checkpoints.
Return/Enter to configure and add a new Filter Set Set Up IP Filter Sets (Firewalls) from this and the following Menus. The procedure for creating and maintaining filter sets is as follows: Add a new filter set. Create the filters for the new filter set. View, change, or delete individual filters and filter sets.
Page 176
14-14 User’s Reference Guide Filter Set Name: Display/Change Input Filter... Add Input Filter... Delete Input Filter... Display/Change Output Filter... Add Output Filter... Delete Output Filter... ADD FILTER SET Configure the Filter Set name and its associated Filters. Naming a new filter set All new filter sets have a default name.
Page 177
The Netopia R-series Router Packets in the Netopia R2121 pass through an input filter if they originate in the WAN and through an output filter if they’re being sent out to the WAN. The process for adding input and output filters is exactly the same. The main difference between the two involves their reference to source and destination.
Page 178
14-16 User’s Reference Guide Enter the IP specific information for this filter. To make the filter active in the filter set, select Enabled and toggle it to Yes. If Enabled is toggled to No, the filter can still exist in the filter set, but it will have no effect. If you want the filter to forward packets that match its criteria to the destination IP address, select Forward and toggle it to Yes.
10. When you are finished configuring the filter, select ADD THIS FILTER NOW to save the filter in the filter set. Select CANCEL to discard the filter. Viewing filters To display a view-only table of input (output) filters, select Display/Change Input Filters (Display/Change Output Filters) in the Add IP Filter Set screen.
filter set. A sample IP filter set This section contains the settings for a filter set, called Basic Firewall, which is part of the Netopia R2121’s factory configuration. Basic Firewall blocks undesirable traffic originating from the WAN (in most cases, the Internet), but passes all traffic originating from the LAN.
Page 181
The five input filters and one output filter that make up Basic Firewall are shown in the table below. Setting Input filter 1 Enabled Forward Source IP 0.0.0.0 address Source IP 0.0.0.0 address mask Dest. IP 0.0.0.0 address Dest. IP 0.0.0.0 address mask Protocol type...
Page 182
14-20 User’s Reference Guide Basic Firewall is suitable for a LAN containing only client hosts that wish to access servers on the WAN, not for a LAN containing servers providing services to clients on the WAN. Basic Firewall’s general strategy is to explicitly pass WAN-originated TCP and UDP traffic to ports greater than 1023.
Page 183
AURP tunnel. To allow an AURP tunnel between a remote AURP router with the IP address a.b.c.d (corresponding to a numbered IP address such as 163.176.8.243) and a local AURP router (including the Netopia R2121 itself), insert the following input filter ahead of the current input filter 1: Enabled: Yes Forward: Yes Source IP Address: a.b.c.d...
14-22 User’s Reference Guide IPX filters Main Menu IPX packet filters work very similarly to IP packet filters. They filter data traffic coming from or going to remote IPX networks. IPX filters can be set up to pass or discard IPX packets based on a number of user-defined criteria.
The items in the IPX Filters and Filter Sets screen are grouped into four areas: IPX packet filters IPX packet filter sets IPX SAP filters IPX SAP filter sets The following sections explain the items in each of these areas. IPX packet filters For each IPX packet filter, you can configure a set of parameters to match on the source or destination attributes of IPX data packets coming from or going to the WAN.
14-24 User’s Reference Guide Select Filter Name and enter a descriptive name for the filter. To specify a source network for the filter to match on, select Source Network and enter an IPX network address. To specify a source node for the filter to match on, select Source Node Address and enter an IPX node address.
Page 187
Add Packet Filter Set Filter Set Name: Show Filters/Change Action on Match... Append Filter... Remove Filter... ADD FILTER SET NOW Configure an IPX Filter Set here. You must ADD FILTER SET NOW to save. Follow these steps to configure the new packet filter set: Select Filter Set Name and enter a descriptive name for the filter set.
14-26 User’s Reference Guide To add a filter to the filter set, select Append Filter to display a table of filters. Select a filter from the table and press Return to add it to the filter set. The default action of newly added filters is to not forward packets that match their criteria.
Page 189
(no characters), and ? to match any single character in the server’s name. For example, the filter could match on the server name “NETOPIA” with “NETO*”, “NETO?IA”, and “NETOPIA*”. To specify a socket for the filter to match on, select Socket and enter an IPX socket number.
14-28 User’s Reference Guide Deleting a SAP filter To delete a SAP filter, select Delete IPX SAP filter in the IPX Filters and Filter Sets screen to display a table of filters. Select a filter from the table and press Return to delete it. Press the Escape key to exit the table without deleting the filter.
Page 191
Set whether filters forward or drop matching packets here. Select a filter and toggle the entry forwarding action to Yes (pass) or No (discard). To add a filter to the filter set, select Append Filter to display a table of filters. Select a filter from the table and press Return to add it to the filter set.
14-30 User’s Reference Guide Firewall tutorial General Firewall Terms Firewall: a component or set of components that restrict access between a protected network and the Internet, or between two networks. Host: A workstation on the Network. Packet: Unit of communication on the Internet. Packet Filter: Packet filters allow or deny packets based on source or destination IP addresses, TCP or UDP ports, or the TCP ACK bit.
Example TCP/UDP Ports TCP Port 20/21 Firewall design rules There are two basic rules to firewall design: “What is not explicitly allowed is denied...” “What is not explicitly denied is allowed...” The first rule is far more secure, and is the best approach to firewall design. It is far easier (and more secure) to allow in or out only certain services and deny anything else.
Page 194
14-32 User’s Reference Guide and a packet goes through these rules destined for FTP, the packet would pass through the first filter rule (WWW), match the second rule (FTP) and the packet is allowed through. Even though the next rule is to deny all FTP traffic, the FTP packet will never make it to this rule.
In the source or destination IP address fields, the IP address that is entered MUST be the NETWORK address of the subnet. A HOST address can be entered, but the applied subnet mask must be 32 bits (255.255.255.255). The Netopia R2121 has the ability to compare source and destination TCP or UDP ports. These options are as follows:...
Any port less than or equal to the port defined Matches only the port defined Matches the port or any port greater Matches anything greater than the port defined. Incoming Packet Filter Netopia 200.1.1.0 (Source IP Network Address) 255.255.255.128 (Source IP Mask) Forward = No...
Page 197
This incoming IP packet (10000000) has a source IP address that does not match the network address in the Source IP Address field (00000000) in the Netopia R2121. This rule WILL forward this packet because the packet does not match.
Page 198
14-36 User’s Reference Guide Since the Source IP Network Address in the Netopia R2121 is 01100000, and the source IP address after the logical AND is 1011000, this rule does NOT match and this packet will be passed. Example 4 Filter Rule: Incoming packet has the source address of 200.1.1.104...
Security 14-37 Since the Source IP Network Address in the Netopia R2121 is 01100000, and the source IP address after the logical AND is 01100000, this rule DOES match and this packet will NOT be passed. This rule masks off a SINGLE IP address.
Note: The Netopia R2121 currently only supports Ascend routers as ACMs. An external Netopia R2121 calling into a designated server. For example, a telecommuter dialing into a remote site from a Netopia R2121 interested in accessing personal email or file sharing services.
CACHE-TOKEN. Your network administrator or the remote network administrator will tell you which method to select. If you select PAP-TOKEN, select Send User Name and enter a name for your Netopia R2121. You will not need to enter a Send Password for PAP-TOKEN. Press Return.
Page 202
14-40 User’s Reference Guide Select Secure Authentication Monitor and press Return. The Secure Authentication Monitor screen appears. Wait for the call to initiate. Profile Name---State---%Use---Remote Address---Est.---More Info--- Status --- Passcode Required For Connection Profile: 0-Challenge: Enter PASSCODE: Passcode: From the fields that appear, select Enter PASSCODE and press Return. Enter your PIN and the code displayed on your security authentication token card LED.
Page 203
Note: When using CACHE-TOKEN, your passcode is valid for a time interval determined by the network administrator. When this time interval expires, you must provide a new passcode for the call negotiation. When using PAP-TOKEN, your passcode is valid for one call negotiation. For a second call negotiation, you must enter the next passcode provided by the security authentication token card every 60 seconds.
C C C C h h h h a a a a p p p p t t t t e e e e r r r r 1 1 1 1 5 5 5 5 U U U U t t t t i i i i l l l l i i i i t t t t i i i i e e e e s s s s a a a a n n n n d d d d D D D D i i i i a a a a g g g g n n n n o o o o s s s s t t t t i i i i c c c c s s s s A number of utilities and tests are available for system diagnostic and control purposes: “Ping”...
(Ping-capable) IP host. Each time the target host receives a Ping packet, it returns a packet to the original sender. Ping allows you to see whether a particular IP destination is reachable from the Netopia R2121. You can also ascertain the quality and reliability of the connection to the desired destination by studying the Ping test’s statistics.
Page 207
Ping packets. Note that the second return Ping packet is considered to be late because it is not received by the Netopia R2121 before the third Ping packet is sent. The first and third return Ping packets are on time.
The time-to-live (TTL) value for each Ping packet sent by the Netopia R2121 is 255, the maximum allowed. The TTL value defines the number of IP routers that the packet can traverse. Ping packets that reach their TTL value are dropped, and a “destination unreachable”...
Select Timeout per probe (1..10 sec) to set when the trace will timeout for each hop, up to 10 seconds. The default is 3 seconds. Select Use Reverse DNS to learn the names of the routers between the Netopia Router and the destination router. The default is Yes.
15-6 User’s Reference Guide The Telnet client screen appears. Host Name or IP Address: Control Character to Suspend: Enter the IP Address/Domain Name of a host. Enter the host name or the IP address in dotted decimal format of the machine you want to telnet into and press Return.
If you select Continue, you will immediately terminate your session. Factory defaults You can reset the Netopia R2121 to its factory default settings. Select the Revert to Factory Defaults item in the Statistics & Diagnostics screen and press Return. Select CONTINUE in the dialog box and press Return.
firmware governs how the modems communicate with the remote site. Modem firmware, for example to support the ITU V.90 standard, is included on your Netopia CD for XMODEM transfer and later updates will be available on the Netopia website. Router firmware updates are also periodically posted on the Netopia website.
Some models do not support all firmware versions. Loading an incorrect firmware version can permanently damage the unit. Do not manually power down or reset the Netopia R2121 while it is automatically resetting or it could be damaged. If you choose to download the firmware, the TFTP Transfer State item will change from Idle to Reading Firmware.
Using TFTP, you can send a file containing a snapshot of the Router’s current configuration to a TFTP server. The file can then be downloaded by a different Netopia R2121 unit to configure its parameters (see configuration files” on page 15-9).
Send Firmware to Netopia Internal modem... Modem Firmware Status: Updating firmware Firmware updates may be available periodically from Netopia or from a site maintained by your organization’s network administration. The procedure below applies whether you are using the console or the built-in modems.
The system will reset at the end of a successful file transfer to put the new firmware into effect. While the system resets, the LEDs will blink on and off. Caution! Do not manually power down or reset the Netopia R2121 while it is automatically resetting or it could be damaged. Downloading configuration files The Netopia R2121 can be configured by downloading a configuration file.
You can restart the system by selecting the Restart System item in the Utilities & Diagnostics screen. You must restart the system whenever you reconfigure the Netopia R2121 and want the new parameter values to take effect. Under certain circumstances, restarting the system may also clear up system or network malfunctions.
Page 219
P P P P a a a a r r r r t t t t I I I I I I I I I I I I : : : : A A A A p p p p p p p p e e e e n n n n d d d d i i i i x x x x e e e e s s s s...
Note: If you are attempting to modify the IP address or subnet mask from a previous, successful configuration attempt, you will need to clear the IP address or reset your Netopia R2121 to the factory default before reinitiating the configuration process. For further information on resetting your Netopia R2121 to factory default, see “Factory defaults”...
Problems communicating with remote IP hosts Verify the accuracy of the default gateway’s IP address (entered in the IP Setup or Easy Setup screen). Use the Netopia R2121’s ping utility, in the Statistics, Tests, Utilities screen, and try to ping local and remote hosts. See “Ping”...
Power outages If you suspect that power was restored after a power outage, and the Netopia R2121 is connected to a remote site, you may need to switch the Netopia R2121 off and then back on again. After temporary power outages, a connection that still seems to be up may actually be disconnected.
Page 224
Netopia World Wide Web server via http://www.netopia.com Internet via anonymous FTP to ftp.netopia.com/pub FAX-Back This service provides technical notes which answer the most commonly asked questions, and offer solutions for many common problems encountered with Netopia products. FAX-Back: +1 510-814-5040...
During the setup session, the SmartStart setup application will provide you with a list of service providers who support the Netopia R2121 with Dual Analog. You can register with one of these ISPs as part of setting up your router.
Setting up a Netopia R2121 account Check whether your ISP has the Netopia R2121 on a list of supported products that have been tested with a particular configuration. If the ISP does not have the Netopia R2121 on such a list, describe the Netopia R2121 in as much detail as needed, so your ISP account can be optimized.
The Netopia R2121 with Dual Analog supports the SmartIP™ feature which includes Network Address Translation. Network Address Translation provides Internet access to the network connected to the Netopia R2121 using only a single IP address. These routers translate between the internal or local area network (LAN) addresses and a single external IP address and route accordingly.
Page 228
The Ethernet IP address for your Netopia R2121 The Ethernet IP subnet mask address for your Netopia R2121 The Default Gateway IP Address (same as Remote IP Address in most cases) Primary and Secondary Domain Name Server IP Addresses Domain Name (usually the same as the ISP’s domain name unless you have registered for your own...
U U U U n n n n d d d d e e e e r r r r s s s s t t t t a a a a n n n n d d d d i i i i n n n n g g g g I I I I P P P P A A A A d d d d d d d d r r r r e e e e s s s s s s s s i i i i n n n n g g g g This appendix is a brief general introduction to IP addressing. A basic understanding of IP will help you in configuring the Netopia R2121 and using some of its powerful features, such as static routes and packet filtering.
C-2 User’s Reference Guide IP addresses indicate both the identity of the network and the identity of the individual host on the network. The number of bits used for the network number and the number of bits used for the host number can vary, as long as certain rules are followed.
When setting up IP routing with a Class A Address, or even multiple Class C Addresses, subnetting is fairly straightforward. Subnetting a single Class C address between two networks, however, is more complex. This section describes the general procedures for subnetting a single Class C network between two Netopia routers so that each can have Internet access.
Page 232
Below is a diagram of a simple network configuration. The ISP is providing a Class C address to the customer site, and both networks A and B want to gain Internet access through this address. Netopia R2121 B connects to Netopia R2121 A and is provided Internet access through Routers A and B.
ISP's equipment. The most important item in this configuration is the Static Route defined on Router B. This tells Router B what path to take to get to the network defined by Netopia R2121 B. Without this information, Customer Site B will be able to access Customer Site A, but not the Internet.
These two methods are not mutually exclusive; you can manually issue some of the addresses while the rest are distributed by the Netopia R2121. Using the Router in this way allows it to function as an address server. One reason to use the Netopia R2121 as an address server is that it takes less time than manually distributing the addresses.
DHCP address lease for one hour. The number of devices a Netopia R2121 can serve DHCP to is 512. This is imposed by global limits on the size of the address serving database, which is shared by all address serving functions active in the router.
Clients (IPCP), is used to fulfill WAN client requirements The Netopia R2121 can use both DHCP and MacIP. Whether you use one or both will depend on your particular networking environment. If that environment includes both PCs and Macintosh computers that do not use Open Transport, you will need to use both DHCP and MacIP to distribute IP addresses to all of your computers.
In any situation where a device is dialing into a Netopia router, the router may need to be configured to serve IP via the WAN interface. This is only a requirement if the calling device has not been configured locally to know what its address(es) are.
Page 238
(199.1.1.49, 199.1.1.50, and 199.1.1.51). Distributed to the (Ethernet IP address) Pool of Addresses Distributed Netopia R2121 Manually distributed (static) by MacIP and DHCP...
The figure at left shows a possible network configuration following this scheme. The main network is set up with the Class C address a.b.c.0, and contains Router A (which could be a Netopia R2121), a Netopia R2121, and a number of other hosts. Router A maintains a link to the Internet, and may be used as the default gateway.
Page 240
Router C a.b.c.248 The Netopia R2121’s connection profiles for Routers B and C create entries in its IP routing table. One entry points to the subnet a.b.c.128, while a second entry points to the subnet a.b.c.248. The IP routing table might...
These two protocols specify two different ways to organize the very first signals in the sequence of electrical signals that make up an IP packet travelling over Ethernet. By default, the Netopia R2121 uses Ethernet packet headers for IP traffic. If your network requires 802.3 IP framing, you must configure this through SNMP.
R2121 uses a one-to-many IP address mapping scheme, that is against a single IP address the Netopia R2121 acquires on its WAN interface the Netopia R2121 can proxy 14, 30, or an unlimited number of IP hosts on the LAN interface.
Page 244
192.168.5.1 and the address of the Router at the ISP is 200.1.1.1. Assuming that the addresses negotiated by the routers are valid and unique for the Internet, the Netopia R2121 and the hosts on its LAN would be able to access the Internet.
Page 245
Dst Port:: 5001 As you can see, the IP packet from Workstation A is sent to the Netopia R2121 and the source IP address is substituted with 200.1.1.40 and the source port is substituted with 5001, then the IP packet checksum is recalculated.
Page 246
5001 and the source port for Workstation B has been changed to 5002. If you were to look at the internal port mapping table that is maintained by the Netopia R2121, it would look similar to the following: Netopia Router LAN: 192.168.5.1...
Exported Services are essentially user defined pointers for a particular type of incoming TCP or UDP service from the WAN interface to a host on the local LAN interface. This is necessary since the Netopia R2121 and thus the attached local LAN has only one IP presence on the WAN interface and Internet. Exported Services allows the user to redirect one type of service, for example Port 21 (FTP), to a single host on the local LAN interface.
Device Event History. When using NAT it is most likely that the Netopia R2121 will be receiving an IP address from a “pool” of dynamic IP addresses at the ISP. This means that the Netopia R2121's IP presence on the Internet will change with each connection.
Page 249
Toggling Address Translation Enabled to Yes enables the Netopia R2121 to send out an all-zeros IPCP address that requests an IP to be assigned to the Netopia R2121’s WAN interface. Note that the remote IP address is 127.0.0.2, which should also be the Default Gateway under IP Setup in System Configuration. This is done for profile matching purposes and because the IP address of the router the Netopia R2121 is dialing is not always...
Summary NAT is a powerful feature of the Netopia R2121 and when used and set up properly can yield a secure network while only using one IP address on the WAN interface. Note that the addresses listed in this appendix are for demonstration purposes only.
A A A A p p p p p p p p e e e e n n n n d d d d i i i i x x x x E E E E B B B B i i i i n n n n a a a a r r r r y y y y C C C C o o o o n n n n v v v v e e e e r r r r s s s s i i i i o o o o n n n n T T T T a a a a b b b b l l l l e e e e This table is provided to help you choose subnet numbers and host numbers for IP and MacIP networks that use subnetting for IP addresses.
Further Reading F-1 A A A A p p p p p p p p e e e e n n n n d d d d i i i i x x x x F F F F F F F F u u u u r r r r t t t t h h h h e e e e r r r r R R R R e e e e a a a a d d d d i i i i n n n n g g g g Angell, David.
Page 254
F-2 User’s Reference Guide Hares, S. "Components of OSI: Inter-Domain Routing Protocol (IDRP)." ConneXions: The Interoperability Report, Vol. 6, No. 5: May 1992. Jones, N.E.H. and D. Kosiur. Macworld Networking Handbook . San Mateo, California: IDG Books Worldwide, Inc.; 1992. Joyce, S.T.
Page 255
Further Reading F-3 Rose, M.T. The Open Book: A Practical Perspective on OSI . Englewood Cliffs, New Jersey: Prentice Hall; 1990. Rose, M.T. The Simple Book: An Introduction to Management of TCP/IP-based Internets . Englewood Cliffs, New Jersey: Prentice Hall; 1991. Ross, F.E.
A A A A p p p p p p p p e e e e n n n n d d d d i i i i x x x x G G G G T T T T e e e e c c c c h h h h n n n n i i i i c c c c a a a a l l l l S S S S p p p p e e e e c c c c i i i i f f f f i i i i c c c c a a a a t t t t i i i i o o o o n n n n s s s s a a a a n n n n d d d d S S S S a a a a f f f f e e e e t t t t y y y y I I I I n n n n f f f f o o o o r r r r m m m m a a a a t t t t i i i i o o o o n n n n Pinouts for Auxiliary Port Modem Cable Shield HD-15...
9.4” (w) x 7.9” (d) x 2.1” (h) Communications interfaces: The Netopia R2121 Dual Analog Router has two RJ-45 jacks for modem connections; an 8 port 10Base-T Ethernet hub for your LAN connection; a DE-9 Console port; and an HD-15 Auxiliary port that can be used as either a serial or LocalTalk port.
Diagnostics: PING, event logging, routing table displays, traceroute, statistics counters, Call Accounting Agency approvals The Netopia R2121 Dual Analog Router has met the safety standards (per CSA-950) of the Canadian Standards Association for Canada. The Netopia R2121 Dual Analog Router has met the safety standards (per UL-1950) of the Underwriters Laboratories for United States.
Page 260
It is the responsibility of users requiring service to report the need for service to our Company or to one of our authorized agents. Service can be obtained at Netopia, Inc., 2470 Mariner Square Loop, Alameda, California, 94501. Important This product was tested for FCC compliance under conditions that included the use of shielded cables and connectors between system components.
Do not use the telephone to report a gas leak in the vicinity of the leak. Battery The Netopia R2121’s lithium battery is designed to last for the life of the product. The battery is not user-ser- viceable. Caution! Danger of explosion if battery is incorrectly replaced.
A A A A b b b b o o o o u u u u t t t t 5 5 5 5 6 6 6 6 K K K K L L L L i i i i n n n n e e e e A A A A c c c c c c c c e e e e s s s s s s s s The Netopia R2121 with Dual Analog is capable of 56Kbps per line connections. This means that if you use both onboard modems, you can achieve inbound data transfer rates of up to 112Kbps.
Page 264
Internet Service Provider, but simply a fact of life in trying to extend the limitations of noisy analog telephone lines. The Netopia R2121 with Dual Analog ships with the unified ITU V.90 standard firmware, also known as V.PCM, which merges the K56flex standard with the competing x2 standard. K56flex firmware can be found on the Netopia CD for XMODEM transfer to the onboard modems, if your ISP supports that technology.
Glossary 1 G G G G l l l l o o o o s s s s s s s s a a a a r r r r y y y y Access Line: A telephone line reaching from the telephone company central office to a point usually on your premises.
Page 266
CNA (Calling Number Authentication): A security feature that will reject an incoming call if it does not match the Calling Number field in one of the Netopia ISDN Router’s Connection Profiles. CND (Calling Number Delivery): Also known as caller ID, a feature that allows the Called Customer Premises Equipment (CPE) to receive a calling party’s directory number during the call establishment phase.
Page 267
LocalTalk networks are compatible with Phase II but are not extended because a single LocalTalk network cannot have multiple network numbers or multiple zone names. firmware: System software stored in a device’s memory that controls the device. The Netopia ISDN Router’s firmware can be updated.
Page 268
4 User’s Reference Guide internet: A set of networks connected together by routers. This is a general term, not to be confused with the large, multi-organizational collection of IP networks known as the Internet. An internet is sometimes also known as an internetwork.
Page 269
Glossary 5 NAT (Network Address Translation): A feature that allows communication between the LAN connected to the Netopia ISDN Router and the Internet using a single IP address, instead of having a separate IP address for each computer on the network.
Page 270
A physical or logical connection between a router and a network. Where a network only allows the use of one protocol, each physical connection corresponds to one logical router port. An example is the Netopia ISDN Router’s LocalTalk port. Where a network allows the use of several protocols, each physical connection may correspond to several logical router ports—one for each protocol used.
Page 271
WANs can span a state, a country, or even the world. WAN IP: In addition to being a router, the Netopia ISDN Router is also an IP address server. There are four protocols it can use to distribute IP addresses over the WAN which include: DHCP, BOOTP, IPCP and MacIP. WAN IP is a feature for both the Small Office and Corporate Netopia ISDN Router models.
Page 273
I I I I n n n n d d d d e e e e x x x x Numerics 10Base-T 5-4 10Base-T, connecting 5-4 Add Static Route 10-14 Adding a filter set 14-13 advanced configuration features 8-9 answer profile call acceptance scenarios 9-7 defined 9-4 answering calls 9-4...
Page 274
connection profiles defined 7-3 scheduling 9-1 console configuring 8-12 screens, connecting to 8-8 Console Configuration 8-12 Console connection problems A-2 console-based management configuring with 6-1 D. Port 14-10 date and time setting 8-11 deciding on an ISP account B-2 default terminal emulation software settings 6- Delete Static Route 10-15 Deleting a packet filter 14-24 Deleting filters 14-17...
Page 275
Navigating through the configuration screens 8- NCSA Telnet 6-3 Nested IP subnets C-11 NetBIOS 10-18 10-9 NetBIOS Scope 10-19 Netopia answering calls 9-4 connecting to Ethernet, rules 5-3 connecting to LocalTalk 5-6 connection profile 7-3 distributing IP addresses 10-16 IP setup 7-4 IPX setup 7-4 LocalTalk configuration 12-7...
Page 276
monitoring 13-1 security 14-1 system utilities and tests 15-1 Network Address Translation see NAT 10-1 Network problems A-2 network status overview 13-1 Next 13-10 Next Router Address 13-10 non-seeding 12-3 Output filter 1 14-19 overview 1-1 packet header C-13 and answer profile 9-6 Parts of a filter 14-7 password to protect security screen 14-2...
Page 277
Trusted subnet 14-20 tunneling 12-3 unproxied addresses 10-1 updating firmware with TFTP 15-8 with XMODEM 15-11 Updating Netopia’s firmware 15-8 Uploading a configuration file 15-10 uploading configuration files with TFTP 15-10 with XMODEM 15-12 user accounts 14-2 using filters 14-12 Utilities and Tests 15-1 Viewing and modifying packet filters 14-24...
Page 278
WAN configuration 9-2 10-3 WAN event history 13-6 WAN statistics 13-4 13-5 Windows 95 SmartStart 3-3 XMODEM 15-10 XMODEM file transfers downloading configuration files 15-12 updating firmware 15-11 uploading configuration files 15-12 Zone Name 13-10...
Page 279
L L L L i i i i m m m m i i i i t t t t e e e e d d d d W W W W a a a a r r r r r r r r a a a a n n n n t t t t y y y y a a a a n n n n d d d d L L L L i i i i m m m m i i i i t t t t a a a a t t t t i i i i o o o o n n n n o o o o f f f f R R R R e e e e m m m m e e e e d d d d i i i i e e e e s s s s Netopia warrants to you, the end user, that the Netopia™ Router with Dual Analog (the “Product”) will be free from defects in materials and workmanship under normal use for a period of one (1) year from date of purchase.
Need help?
Do you have a question about the R2121 and is the answer not in the manual?
Questions and answers