Copyright Copyright (C) 2005 PLANET Technology Corp. All rights reserved. The products and programs described in this User’s Manual are licensed products of PLANET Technology, This User’s Manual contains proprietary information protected by copyright, and this User’s Manual and all accompanying hardware, software, and documentation are copyrighted.
Router and plug your PC to the LAN port and you're ready to share files and access the Internet. The VRT-401G is embedded with an IEEE 802.11g/b access point that allows you to build up a wireless LAN. The 54M Wireless VPN Firewall Router provides a total solution for the Small and Medium-sized Business (SMB) and the Small Office/Home Office (SOHO) markets, giving you an instant network today, and the flexibility to handle tomorrow's expansion and speed.
Get to know the Wireless VPN Firewall Router Back Panel The diagram (fig1.0) below shows the VRT-401G’s back panel. The router’s back panel is divided into three sections, LAN, WAN and Reset: 1) Local Area Network (LAN) The VRT-401G’s 4 LAN ports are where you connect your LAN’s PCs, printer servers, hubs and switches etc.
10/100M (Port 1-4) LNK/ACT (Port 1-4) Flashing WLAN Flashing Setup Diagram Figure 1.2 below shows a typical setup for a Local Area Network (LAN). Getting started This is a step-by-step instruction on how to start using the router and get connected to the Internet.
Page 8
Configure your PC to obtain an IP address automatically By default the VRT-401G’s DHCP is on, this means that you can obtain an IP address automatically once you’ve configured your PC to obtain an IP address automatically. This section will show you how to configure your PC’s so that it can obtain an IP address automatically for either Windows 95/98/Me, 2000 or NT operating systems.
Page 9
8: Reboot the PC. Your PC will now obtain an IP address automatically you’re your Broadband Router’s DHCP server. Note: Please make sure that the Broadband router’s DHCP server is the only DHCP server available on your LAN. Once you’ve configured your PC to obtain an IP address automatically, please proceed to Step 3 2b) Windows XP 1: Click the Start button and select Settings, then click Network Connections.
Page 10
5: Click OK to confirm the setting. Your PC will now obtain an IP address automatically from your Broadband Router’s DHCP server. Note: Please make sure that the Broadband router’s DHCP server is the only DHCP server available on your LAN. Once you’ve configured your PC to obtain an IP address automatically, please proceed to Step 3.
Page 11
6: Click OK to confirm the setting. Your PC will now obtain an IP address automatically from your Broadband Router’s DHCP server. Note: Please make sure that the Broadband router’s DHCP server is the only DHCP server available on your LAN. Once you’ve configured your PC to obtain an IP address automatically, please proceed to Step 3.
Page 12
Note: Please make sure that the VRT-401G’s DHCP server is the only DHCP server available on your LAN. If there is another DHCP on your network, then you’ll need to switch one of the DHCP servers off. (To disable the VRT-401G’s DHCP server see chapter 2 LAN Port)
Page 13
Quick Setup Wizard, General Setup, Status Information and Tools. Quick Setup Wizard (Chapter 1) If you only want to start using the VRT-401G as an Internet Access device then you ONLY need to configure the screens in the Quick Setup Wizard section.
Page 14
Mapping, Virtual Server, Access Control, Hacker Attack Prevention, DMZ, Special applications other functions requirements. In this section you can see the VRT-401G's system information, Internet Connection, Device Status, System Log, Security Log and DHCP client information. This section contains the VRT-401G’s Tools - Tools include Configuration tools, Firmware upgrade and Reset.
Page 15
7) Click on Quick Setup Wizard (see chapter 1) to start configuring settings required by your ISP so that you can start accessing the Internet. The other sections (General Setup, Status Information and Tools) do not need to be configured unless you wish to implement/monitor more advance features/information.
Chapter 1 Quick Setup The Quick Setup section is designed to get you using the VRT-401G as quickly as possible. In the Quick Setup you are required to fill in only the information necessary to access the Internet. Once you click on the Quick Setup Wizard in the HOME page, you should see the screen below.
In this section you have to select one of four types of connections that you will be using to connect your VRT-401G’s WAN port to your ISP (see screen below). Note: Different ISP’s require different methods of connecting to the Internet, please check with your ISP as to the type of connection it requires.
PC’s MAC address see Appendix A. (see Glossary for an explanation on MAC address) This is optional. Some ISP will check the TTL response to build up the connection. When you select Enabled, VRT-401G will respond the TTL time plus 1.
This is the ISP’s DNS server IP address This is the ISP’s IP address gateway This is optional. Some ISP will check the TTL response to build up the connection. When you select Enabled, VRT-401G will respond the TTL time plus 1.
Page 20
Parameter User Name Password Service Name Connection Type Idle Time Description Enter the User Name provided by your ISP for the PPPoE connection Enter the Password provided by your ISP for the PPPoE connection This is optional. Enter the Service name should your ISP requires it, otherwise leave it blank.
ISP charge you by time used. This is optional. Some ISP will check the TTL response to build up the connection. When you select Enabled, VRT-401G will respond the TTL time plus 1...
Page 22
Parameter Obtain an IP address automatically MAC Address Use the following IP address IP Address Subnet Mask Gateway User ID Password PPTP Gateway Connection ID BEZEQ-ISRAEL Connection Type Description The ISP requires you to obtain an IP address by DHCP before connecting to the PPTP server.
Idle Time Click <OK> when you have finished the configuration above. Congratulations! You have completed the configuration for the PPTP connection. You can start using the router now, if you wish to use some of the advance features supported by this router see chapter 2, 3, 4. 1.5 L2TP Select L2TP if your ISP requires the L2TP protocol to connect you to the Internet.
Page 24
Parameter Obtain an IP address automatically MAC Address Use the following IP address IP Address Subnet Mask Gateway User ID Password L2TP Gateway Connection Type Description The ISP requires you to obtain an IP address by DHCP before connecting to the L2TP server. Your ISP may require a particular MAC address in order for you to connect to the Internet.
Idle Time Out Click <OK> when you have finished the configuration above. Congratulations! You have completed the configuration for the L2TP connection. You can start using the router now, if you wish to use some of the advance features supported by this router see chapter 2, 3, 4. 1.6 Telstra Big Pond Select Telstra Big Pond if your ISP requires the Telstra Big Pond protocol to connect you to the Internet.
Page 26
Click <OK> when you have finished the configuration above. Congratulations! You have completed the configuration for the Telstra Big Pond connection. You can start using the router now, if you wish to use some of the advance features supported by this router see chapter 2, 3, 4.
2.7 Firewall 2.8 VPN Description This section allows you to set the VRT-401G’s system Time Zone, Password and Remote Management Administrator. This section allows you to select the connection method in order to establish a connection with your ISP (same as the Quick Setup Wizard section) You can specify the LAN segment’s IP address, Subnet Mask,...
Select one of the above five General Setup selections and proceed to the manual’s relevant sub- section 2.1 System The system screen allows you to specify a time zone, to change the system password and to specify a remote management user for the VRT-401G Parameters System Settings 2.1.1 Time Zone 2.1.2 Password Settings...
(with the advance settings in place) 2.1.2 Password Settings You can change the password required to log into the VRT-401G's system web-based management. By default, the password is admin. So please assign a password to the Administrator as soon as possible, and store it in a safe place.
(with the advance settings in place) 2.1.3 Remote Management The remote management function allows you to designate a host in the Internet the ability to configure the VRT-401G from a remote site. Enter the designated host IP Address in the Host IP Address field. Parameters...
Host Address This is the IP address of the management/configuration access to the VRT-401G from a remote site. This means if you are at home and your home IP address has been designated the Remote Management host IP address for this router (located in your company office), then you are able to configure this router from your home.
Parameters 2.2.1 Dynamic IP address 2.2.2 Static IP address 2.2.3 PPPoE 2.2.4 PPTP 2.2.5 L2TP 2.2.6 Telstra Big Pond 2.2.7 DNS 2.2.8 DDNS Once you have made a selection, click <More Configuration> at the bottom of the screen, and proceed to the manual’s relevant sub-section 2.2.1 Dynamic IP Choose the Dynamic IP selection if your ISP will automatically give you an IP address.
2.2.5 L2TP Select L2TP if your ISP requires the L2TP protocol to connect you to the Internet. Your ISP should provide all the information required in this section. (See chapter 1 “L2TP” for more detail) 2.2.6 Telstra Big Pond Select Telstra Big Pond if your ISP requires the Telstra Big Pond protocol to connect you to the Internet.
2.2.8 DDNS DDNS allows you to map the static domain name to a dynamic IP address. You must get an account, password and your static domain name from the DDNS service providers. This router supports DynDNS, TZO and other common DDNS service providers. Parameters Default Enable/Disable...
Page 35
LAN client’s IP addresses; make sure the LAN Client is in the same subnet as VRT-401G, if you want the router to be your LAN client’s default gateway. The DHCP when enabled will temporarily give your LAN clients an IP address.
Domain Name Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) 2.4 Wireless Wireless Access Point builds a wireless LAN and can let all PCs equipped with IEEE 802.11b or 801.11g wireless network adaptor connect to your Intranet.
Page 37
AP Mode setting Page: Station-Ad Hoc mode setting page:...
Page 38
Station-Infrastructure mode setting page: AP Bridge-Point to Point mode setting page:...
Page 39
AP Bridge-Point to Multi-Point mode setting page: AP Bridge-WDS mode setting page:...
Page 40
Parameters Default Mode Band ESSID default Channel Number Associated Clients WLAN MAC Clone MAC MAC address Set Security Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) Description It allows you to set the AP to AP, Station, Bridge or WDS mode.
2.4.2 Advanced Settings You can set advanced wireless LAN parameters of this router. The parameters include Authentication Type, Fragment Threshold, RTS Threshold, Beacon Interval, Preamble Type …… You should not change these parameters unless you know what effect the changes will have on this router.
Data Rate Preamble Type Broadcast ESSID IAPP 802.11g Protection Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router. 2.4.3 Security This Access Point provides complete wireless LAN security functions, include WEP, IEEE 802.11x, IEEE 802.11x with WEP, WPA with pre-shared key and WPA with RADIUS.
Page 43
Parameters Default Key Length 64-bit Key Format Default Key Key 1 - Key 4 Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) Description You can select the WEP key length for encryption, 64-bit or 128-bit.
2.4.3.2 802.1x only IEEE 802.1x is an authentication protocol. Every user must use a valid account to login to this Access Point before accessing the wireless LAN. The authentication is processed by a RADIUS server. This mode only authenticates user by IEEE 802.1x, but it does not encryption the data during communication.
For the WEP settings, please refer to section 2.4.3.1 “WEP only”. For the 802.1x settings, please refer to section 2.4.3.2 “802.1x only”. 2.4.3.4 WPA Pre-shared key Wi-Fi Protected Access (WPA) is an advanced security standard. You can use a pre-shared key to authenticate wireless stations and encrypt data during communication.
WPA2(AES) WPA2 Mixed Pre-shared Key Format Pre-shared Key Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) 2.4.3.5 WPA Radius Wi-Fi Protected Access (WPA) is an advanced security standard.
WPA2(AES) WPA2 Mixed RADIUS Server IP address RADIUS Server Port RADIUS Server Password Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) 2.4.4 Access Control This wireless router provides MAC Address Control, which prevents the unauthorized MAC Addresses from accessing your wireless network.
Remove MAC address from the list Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) 2.5 QoS The QoS can let you classify Internet application traffic by source/destination IP address and port number.
Page 49
Add a QoS rule into the table Remove QoS rules from the table Edit a QoS rule Adjust QoS rule priority Edit QoS Rule: You can assign packet classification criteria by its local IP range, remote IP range, traffic type, protocol, local port range and remote port range parameters.
Bandwidth You can assign the download or upload bandwidth by the unit of Kbps (1024 bit per second). You can limit the maximum bandwidth consumed by this rule by selecting “Maximum”. You also can reserve enough bandwidth for this rule by selecting “Guarantee”. Local IP Address Enter the local IP address range of the packets that this rule will apply to.
Page 51
Parameter 2.6.1 Port Forwarding 2.6.2 Virtual Server 2.6.3 Special Applications 2.6.4 UPnP Setting 2.6.5 ALG Setting 2.6.6 Static Routing Click on one of the three NAT selections and proceed to the manual's relevant sub-section. Description You can have different services (e.g. email, FTP, Web etc.) going to different service servers/clients in your LAN.
2.6.1 Port Forwarding The Port Forwarding allows you to re-direct a particular range of service port numbers (from the Internet/WAN Ports) to a particular LAN IP address. It helps you to host some servers behind the router NAT firewall. Parameter Enable Port Forwarding Private IP Type...
Page 53
Computers use numbers called port numbers to recognize a particular service/Internet application type. The Virtual Server allows you to re-direct a particular service port number (from the Internet/WAN Port) to a particular LAN private IP address and its service port number. (See Glossary for an explanation on Port number) Parameters Enable Virtual Server...
Page 54
Remove Virtual Server Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) Example: Virtual Server The diagram below demonstrates one of the ways you can use the Virtual Server function. Use the Virtual Server when you want the web server located in your private LAN to be accessible to Internet users.
2.6.3 Special Applications Some applications require multiple connections, such as Internet games, video conferencing, Internet telephony and others. In this section you can configure the router to support multiple connections for these types of applications. Parameters Enable Trigger Port Trigger Port Trigger Type Public Port Public Type...
Add Special Application Remove Special Application Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) Example: Special Applications If you need to run applications that require multiple connections, then specify the port (outbound) normally associated with that application in the "Trigger Port"...
Parameters Default UPnP Feature Disable Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) 2.6.5 ALG Settings You can select applications that need “Application Layer Gateway” to support. Description You can Enable or Disable UPnP feature here.
Parameters Default Enable Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) 2.6.6 Static Routing This router provides Static Routing function when NAT is disabled. With Static Routing, the router can forward packets according to your routing rules.
Page 59
Parameter Enable Static Routing Destination LAN IP Subnet Mask Default Gateway Hop Count Interface Add a Rule Remove a Rule Description Static Routing function is default disabled. You have to enable the Static Routing function before your routing rules take effect. The network address of destination LAN.
(with the advance settings in place) 2.7 Firewall The VRT-401G provides extensive firewall protection by restricting connection parameters, thus limiting the risk of hacker attack, and defending against a wide array of common Internet attacks.
Page 61
users to define the traffic type permitted in your LAN. You can control which PC client can have access to these services. Parameters Deny Allow Filter client PC by MAC address Add PC Remove PC Filter client PCs by IP Add PC Remove PC Description...
Page 62
You can now configure other advance sections or start using the router (with the advance settings in place) Add PC Parameters Client PC Description Client PC IP Addresses Client PC Service and then click "Delete Selected". If you want remove all PCs from the table, just click "Delete All"...
Protocol Port Range Apply Changes Reset Click <Apply Changes> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) Example: Access Control In the example below, LAN client A can only access websites that use Port 80.
You can now configure other advance sections or start using the router (with the advance settings in place) 2.7.3 DoS (Denial of Service) The VRT-401G's firewall can block common hacker attacks, including Denial of Service, Ping of Death, Port Scan and Sync Flood. If Internet attacks occur the router can log the events. Description Enable/disable URL Blocking Fill in “URL/Keyword”...
Page 65
Parameters Denial of Service Feature Ping of Death Discard Ping From WAN Port Scan Sync Flood Click <Apply> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) Note: You can press Advance Settings to configure more detail settings per each DoS feature if necessary.
2.7.4 DMZ If you have a local client PC that cannot run an Internet application (e.g. Games) properly from behind the NAT firewall, then you can open the client up to unrestricted two-way Internet access by defining a DMZ Host. The DMZ function allows you to re-direct all packets going to your WAN port IP address to a particular IP address in your LAN.
2.8 VPN Virtual Private Network (VPN) provides a secure, private communication tunnel between two or more devices across the Internet. These VPN devices can be either a computer running VPN software or a special device like a VPN enabled router. It allows your home computer to be connected to your office network or can allow two home computers in different locations to connect to each over the Internet.
Page 68
Parameters Enable IPSEC VPN Enable NAT Traversal Generate RSA Key Show RSA Public Key Current VPN Connection Table WAN IP Edit a VPN Connection Description Enable the IPSec VPN Server. Enable the NAT Traversal function allows the clients behind NAT to connect to this VPN server. Automatically generate the RSA Public Key.
Click <Apply Changes> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) Edit Connection Parameters Enable Tunnel # Connection Name Local Site Remote Site Network Management...
Page 70
Connection Type Local/Remote ID Auth Method Click <Apply Changes> at the bottom of the screen to save the above configurations. You can now configure other advance sections or start using the router (with the advance settings in place) Advanced VPN Setting Parameters Encryption Hash/Authentication...
Diffie Hellman Key Life Time Click <OK> at the bottom of the screen to save the above configurations. 2.8.2 L2TP Server Layer Two Tunneling Protocol (L2TP) is an extension of the Point-to-Point Tunneling Protocol (PPTP). By enable this server, we can enable the operation of a virtual private network (VPN) over the Internet.
L2TP Settings Parameters Enable L2TP Server Server IP Address Client IP Pool Authentication VPN Users Click <Apply> at the bottom of the screen to save the above configurations. Note: L2TP client IP address must be public IP. 2.8.3 PPTP Server PPTP is a protocol from Microsoft that is used to create a virtual private network (VPN) over the Internet.
PPTP Settings Parameters Enable PPTP Server Server IP Address Client IP Pool Authentication Encryption VPN Users Click <Apply> at the bottom of the screen to save the above configurations. Description By enable this server, we can enable the operation of a virtual private network (VPN) over the Internet.
The Status section allows you to monitor the current status of your router. You can use the Status page to monitor: the connection status of the VRT-401G's WAN/LAN interfaces, the current firmware and hardware version numbers, any illegal attempts to access your network, and information on all DHCP client PCs currently connected to your network.
Parameters Information 3.2 Internet Connection View the VRT-401G’s current Internet connection status and other related information Parameters Internet Connection Description You can see the router’s system information such as the router’s: LAN MAC Address, WAN MAC Address, Hardware version, Serial Number, Boot code Version, Runtime code Version...
3.3 Device Status View the VRT-401G’s current configuration settings. The Device Status displays the settings you’ve configured in the Quick Setup Wizard/General Setup section. Parameters Device Status 3.4 System Log View the operation log of the system. Description This page shows the VRT-401G’s current device settings. This page displays the VRT-401G LAN port’s current LAN IP...
View any attempts that have been made to illegally gain access to your network. Parameters Description This page shows the current system log of the VRT-401G. It displays any event occurred after system start up. At the bottom of the page, the system log can be saved <Save>...
Security Log 3.6 Active DHCP Client View your LAN client's information that is currently linked to the VRT-401G's DHCP server arameters Active DHCP Client 3.7 Statistics View the statistics of packets sent and received on WAN, LAN and Wireless LAN.
Page 79
Parameters Statistics Description Shows the counters of packets sent and received on WAN, LAN and Wireless LAN.
Chapter 4 Tool This page includes the basic configuration tools, such as Configuration Tools (save or restore configuration settings), Firmware Parameters 4.1 Configuration Tools 4.2 Firmware Upgrade This page allows you to upgrade the router’s firmware 4.3 Reset Select one of the above three Tools Settings selection and proceed to the manual’s relevant sub-section 4.1 Configuration Tools The Configuration Tools screen allows you to save (Backup) the router’s current configuration...
This page allows you to upgrade the router’s firmware Parameters Firmware Upgrade This tool allows you to upgrade the VRT-401G’s system firmware. Description Use the "Backup" tool to save the VRT-401G current configuration to a file named "config.bin" on your PC. You can then use the "Restore"...
Once you’ve selected the new firmware file, click <Apply> at the bottom of the screen to start the upgrade process. (You may have to wait a few minutes for the upgrade to complete). Once the upgrade is complete you can start using the router. 4.3 Reset You can reset the router’s system should any problem exist.
Appendix A How to Manually find your PC’s IP and MAC address 1) In Window’s open the Command Prompt program 2) Type Ipconfig /all and <enter> • Your PC’s IP address is the one entitled IP address (192.168.1.77) • The router’s IP address is the one entitled Default Gateway (192.168.1.254) •...
Glossary Default Gateway (Router): Every non-router IP device needs to configure a default gateway’s IP address. When the device sends out an IP packet, if the destination is not on the same network, the device has to send the packet to its default gateway, which will then send it out towards the destination.
Page 85
ISP: Internet Service Provider. An ISP is a business that provides connectivity to the Internet for individuals and other businesses or organizations. LAN: Local Area Network. A LAN is a group of computers and devices connected together in a relatively small area (such as a house or an office). Your home network is considered a LAN. MAC Address: MAC stands for Media Access Control.
Page 86
create IP address numbers used only within a particular network (as opposed to valid IP address numbers recognized by the Internet, which must be assigned by InterNIC). TCP/IP, UDP: Transmission Control Protocol/Internet Protocol (TCP/IP) and Unreliable Datagram Protocol (UDP). TCP/IP is the standard protocol for data transmission over the Internet. Both TCP and UDP are transport layer protocol.
Need help?
Do you have a question about the VRT-401G and is the answer not in the manual?
Questions and answers