11. What is DDNS wildcard? Does the AMG1202-T10B/AMG1302-T10B support DDNS wildcard? ....12 12. What is Traffic Shaping? ..............12 13. Why do we perform traffic shaping in the AMG1202-T10B /AMG1302-T10B? .................. 13 14. What do the parameters (PCR, SCR, MBS) mean? ...... 13 15.
Page 3
AMG1202-T10B/AMG1302-T10B Support Notes 5. How does the AMG1302-T10B /AMG1202-T10B work on a noisy ADSL? ....................16 6. Does the VC-based multiplexing perform better than the LLC-based multiplexing? ..............16 7. How do I know the details of my ADSL line statistics? ....16 8.
Page 4
9. What is an ESSID? ............... 33 Security FAQ..................... 34 1. How do I secure the data across the AMG1302-T10B /AMG1202-T10B Access Point's radio link? ......34 2. What is WEP? ..............34 3. What is WPA-PSK? .............. 34 4. What is the difference between 40-bit and 64-bit WEP? ..34 5.
Page 5
1. Internet Access Using AMG1302-T10B/AMG1202-T10B under Bridge mode ................37 2. Internet Access Using AMG1302-T10B/AMG1202-T10B under Routing mode ................40 3. Setup the AMG1302-T10B/AMG1202-T10B as a DHCP Relay ....................43 4. SUA Notes ................43 5. Using the Dynamic DNS (DDNS) ......... 53 6.
Note: It is protected by super password, ‘1234’ by factory default. 2. How do I update the firmware and configuration file? You can do this via accessing web GUI of AMG1202-T10B/AMG1302-T10B as Administrator. Firmware update function is under Maintanance -> Firmware Upgrade.
AMG1202-T10B/AMG1302-T10B Support Notes Use the RESET button on the rear panel of AMG1202-T10B/AMG1302-T10B to reset the router. After the router is reset, the LAN IP address will be reset to '192.168.1.1', the common user password will be reset to '1234', and the Administrator password will be reset to ‘1234’.
AMG1202-T10B/AMG1302-T10B maps one ILA to one IGA. Many to One: In Many-to-One mode, the AMG1202-T10B/AMG1302-T10B maps multiple ILA to one IGA. This is equivalent to SUA (i.e., PAT, port address translation), ZyXEL's Single User Account feature (the SUA is optional in today's Prestige routers).
'protocol filter group'. You can configure the filter rule in CLI. 10. How can I protect against IP spoofing attacks? The AMG1202-T10B/AMG1302-T10B’s filter sets provide a means to protect against IP spoofing attacks. The basic scheme is as follows: For the input data filter: ...
Moreover, only with Administrator Password, you could manage the AMG1202-T10B/AMG1302-T10B via FTP/TFTP or Telnet. 4. How do I know the AMG1202-T10B/AMG1302-T10B’s WAN IP address assigned by the ISP? You can view "My WAN IP <from ISP> : x.x.x.x" shown in Web Configurator ‘Status->Device Information ->WAN Information’...
You can also check your ISP or the information sheet given by the ISP. Please choose PPPoE as the encapsulation type in the AMG1202-T10B/AMG1302-T10B if the ISP uses PPPoE. 8. Why does my provider use PPPoE? PPPoE emulates a familiar Dial-Up connection.
IP address, we can use the DDNS service. The DDNS server allows to alias a dynamic IP address to a static hostname. Whenever the ISP assigns you a new IP, the AMG1202-T10B/AMG1302-T10B sends this IP to the DDNS server for its updates.
Support Notes the VC gets full bandwidth. If another VCs are activated later, the bandwidth is yield to other VCs afterward. 13. Why do we perform traffic shaping in the AMG1202-T10B /AMG1302-T10B? The AMG1202-T10B/AMG1302-T10B must manage traffic fairly and provide bandwidth allocation for different sorts of applications, such as voice, video, and data.
AMG1302-T10B /AMG1202-T10B performs content filtering. You can also specify trusted IP Addresses on LAN for which the AMG1302-T10B /AMG1202-T10B will not perform content filtering. You can configure the details about it in Web Configurator, Advanced setup, Security -> Filter.
4. How do I know the ADSL line is up? You can see the DSL LED Green on the AMG1302-T10B /AMG1202-T10B’s front panel is on when the ADSL physical layer is up.
AMG1202-T10B/AMG1302-T10B Support Notes 5. How does the AMG1302-T10B /AMG1202-T10B work on a noisy ADSL? Depending on the line quality, the AMG1302-T10B /AMG1202-T10B uses "Fall Back" and "Fall Forward" to automatically adjust the date rate. 6. Does the VC-based multiplexing perform better than the...
LAND attack, IP Spoofing, etc. It also uses stateful packet inspection to determine if an inbound connection is allowed through the firewall to the private LAN. The AMG1302-T10B /AMG1202-T10B supports Network Address Translation (NAT), which translates the private local addresses to one or multiple public addresses.
4. The AMG1302-T10B/AMG1202-T10B’s firewall is fast. It uses a hashing function to search the matched session cache instead of going through every individual rule for a packet.
1. How do I configure the firewall? You can use the Web Configurator to configure the firewall for AMG1302-T10B /AMG1202-T10B. By factory default, if you connect your PC to the LAN Interface of AMG1302-T10B/AMG1202-T10B, you can access Web Configurator via ‘http://192.168.1.1’.
Web Configurator, Advanced setup, Maintenance -> RemoteMGNT. (4) A filter set which blocks FTP from WAN is applied to WAN node. Log and Alert 1. When does the AMG1302-T10B/AMG1202-T10B generate the firewall log? The AMG1302-T10B/AMG1202-T10B generates the firewall log immediately when the packet matches a firewall rule.
4. When does the AMG1302-T10B/AMG1202-T10B generate the firewall alert? The AMG1302-T10B/AMG1202-T10B generates the alert when an attack is detected by the firewall and sends it via Email. So, to send the alert, you must configure the mail server and Email address using Web Configurator, Advanced Setup, Maintenance ->...
Support Notes 5. What is the difference between the log and alert? A log entry is just added to the log inside the AMG1302-T10B/AMG1202-T10B and e-mailed together with all other log entries at the scheduled time as configured. An alert is e-mailed immediately after an attacked is detected.
17. Does AMG1302-T10B/AMG1202-T10B support auto rate adaption? Yes, it means that the AP on AMG1302-T10B/AMG1202-T10B will automatically decelerate when devices move beyond the optimal range, or other interference is present. If the device moves back within the range of a higher-speed transmission, the connection will automatically speed up again.
1. How do I secure the data across the AMG1302-T10B /AMG1202-T10B Access Point's radio link? To secure the date across the AMG1302-T10B/AMG1202-T10B. Access Point’s radio link, we could select any one of the security mode: Static 64/128 bit WEP, WPA-PSK, WPA, WPA2-PSK, WPA2.
If the ISP limits some specific computers to access Internet, that means only the traffic to/from these computers will be forwarded and the other will be filtered. In this case, we use AMG1302-T10B/AMG1202-T10B which works as an ADSL bridge modem to connect to the ISP. The ISP will generally give one Internet account and limit only one computer to access the Internet.
Page 38
Support Notes Setup your AMG1302-T10B/AMG1202-T10B under bridge mode The following procedure shows you how to configure your AMG1302-T10B /AMG1202-T10B as bridge mode. We will use Web Configurator to guide you through the related menu. 1. Retrieve Prestige Web Please enter the LAN IP address of the Prestige router in the URL location to retrieve the web screen from the Prestige.
Page 39
Support Notes http://192.168.1.1 2. Login first The default username and password is the default SMT password '1234'. (1) Configure AMG1302-T10B/AMG1202-T10B as bridge mode and configure Internet setup parameters in Web Configurator, Advanced Setup, Network Setting-> Broadband -> Internet Connection. Key Settings:...
In this case, the IP address of the computer is assigned by the AMG1302-T10B/AMG1202-T10B. The AMG1302-T10B /AMG1202-T10B can also provide the DNS to the clients via DHCP if it is available. For this setup in Windows, we check the option 'Obtain an IP address automatically' in its TCP/IP setup.
DHCP clients and the server. See figure 1. Setup the AMG1302-T10B/AMG1202-T10B as a DHCP Relay We could set the AMG1302-T10B/AMG1202-T10B as a DHCP Relay by the following command in CLI: dhcrelay [Server IP Address] 4.
Page 44
LAN users are invisible to outside users. However, some applications such as Cu-SeeMe and ICQ will need to connect to the local user behind the AMG1302-T10B/AMG1202-T10B. In such case, a SUA server must be configured to forward the incoming packets to the true destination behind SUA.
Page 46
IP, so only one Quake user will be allowed in this case. Moreover, when a Quake server is configured behind SUA, AMG1302-T10B/AMG1202-T10B will not be able to provide information of that server on the internet. Quake II has the same limitations as that of Quake I.
Page 47
A service is identified by the port number. Also, since you need to specify the IP address of a server behind the AMG1302-T10B/AMG1202-T10B, a server must have a fixed IP address and not be a DHCP client whose IP address potentially changes each time AMG1302-T10B/AMG1202-T10B is powered on.
Page 48
Web Configurator, Advanced Setup, Network Setting-> NAT -> Port Forwarding. The outside users can access the local server using the AMG1302-T10B/AMG1202-T10B’s WAN IP address which can be obtained from Web Configurator, Status -> WAN Information.
Page 50
Configuration This application note explains how to establish a PPTP connection with a remote private network in the AMG1302-T10B/AMG1202-T10B SUA case. All PPTP packets can be forwarded to the internal PPTP Server (WinNT server) behind SUA. The port number of the PPTP has to be entered in the Web Configurator, Advanced Setup, and Network ->...
Page 51
The following example shows how to dial to an ISP via the AMG1302-T10B /AMG1202-T10B and then establish a tunnel to a private network. There will be three items that you need to set up for PPTP application, these are PPTP server (WinNT), and PPTP client (Win9x) and the AMG1302-T10B /AMG1202-T10B.
Page 52
Before making a VPN connection from the Win9x client to the NT server, you need to know the exact Internet IP address that the ISP assigns to AMG1302-T10B/AMG1202-T10B router in SUA mode and enter this IP address in the VPN dial-up dialog box. You can check this Internet IP address from PNC Monitor or S Web Configurator, Status ->...
The outside users can always access the web server using the www.zyxel.com.tw regardless of the WAN IP of the P-120/P-1302. When the ISP assigns the AMG1302-T10B/AMG1202-T10B a new IP, the AMG1302-T10B/AMG1202-T10B must inform the DDNS server the change of this IP so that the server can update its IP-to-DNS entry. Once the IP-to-DNS table in the DDNS server is updated, the DNS name for your web server (i.e.,...
Setup the DDNS 1. Before configuring the DDNS settings in the AMG1302-T10B /AMG1202-T10B, you must register an account from the DDNS server such as WWW.DYNDNS.ORG first. After the registration, you have a hostname for your internal server and a password using to update the IP to the DDNS server.
ZyXEL SNMP Implementation ZyXEL currently includes SNMP support in some AMG1302-T10B /AMG1202-T10B routers. It is implemented based on the SNMPv1, so it will be able to communicate with SNMPv1 NMSs. Further, users can also add ZyXEL's private MIB in the NMS to monitor and control additional system variables.
Page 57
Downloading ZyXEL's private MIB Configure the AMG1302-T10B/AMG1202-T10B for SNMP The SNMP related settings in AMG1302-T10B/AMG1202-T10B are configured in Web Configurator, Advanced Setup, Maintenance -> Remote MGNT -> SNMP The following steps describe a simple setup procedure for configuring all SNMP settings.
Page 59
AMG1302-T10B/AMG1202-T10B as shown below when the two networks are configured. If the AMG1302-T10B /AMG1202-T10B’s DHCP is also enabled, the IP pool for the clients can be any of the two networks. IP Alias Setup (1) Edit the first network in Web Configurator, Advanced Setup, Network Setting ->...
IGMP to report their multicast group membership to any immediate-neighbor multicast routers so the multicast routers can decide if a multicast packet needs to be forwarded. At start up, the AMG1302-T10B/AMG1202-T10B queries all directly connected networks to gather group membership.
Page 62
IP Multicast Setup v (1) Enable IGMP in AMG1302-T10B/AMG1202-T10B’s LAN in Web Configurator, Advanced Setup, And Network Setting->Home Networking ->LAN Setup. (2) Enable IGMP in AMG1302-T10B/AMG1202-T10B’s remote node in Web Configurator, Advanced Setup, And Network Setting->Home Networking ->LAN Setup. Key Settings: IGMP-v1 for IGMP version 1, IGMP-v2 for IGMP version 2.
Extensible Authentication Protocol (EAP) to authenticate wireless clients using an external RADIUS database. You cannot use the AMG1302-T10B/ AMG1202-T10B’s local user database for WPA authentication purpose since the local user database uses MD5 EAP which can not to generate keys.
Page 75
Authentication can be done using local user database internal to the AMG1302-T10B/AMG1202-T10B (authenticate up to 32 users) or an external RADIUS server for an unlimited number of users. Step 1: To change your AMG1302-T10B/AMG1202-T10B’s authentication settings, login Web Configurator, Advanced Setup, Network Setting->...
Need help?
Do you have a question about the AMG1202-T10B and is the answer not in the manual?
Questions and answers