Related Documentation • Quick Start Guide The Quick Start Guide shows how to connect the PMG2006-T20A and get up and running right away. • More Information Go to support.zyxel.com to find other information on the PMG2006-T20A...
Table of Contents 4.4 Access the PMG2006-T20A Using DDNS ..................30 4.4.1 Registering a DDNS Account on www.dyndns.org ............30 4.4.2 Configuring DDNS on Your PMG2006-T20A ................ 31 4.4.3 Testing the DDNS Setting ...................... 31 4.5 Configuring the MAC Address Filter ..................... 31 Part II: Technical Reference................
Page 6
10.1.1 What You Can Do in this Chapter ..................87 10.1.2 What You Need To Know ....................87 10.2 The DNS Entry Screen ........................88 10.2.1 Add/Edit DNS Entry ......................88 10.3 The Dynamic DNS Screen ......................89 PMG2006-T20A User’s Guide...
Page 7
15.2.1 Add/Edit a Schedule ......................109 Chapter 16 Certificates ............................111 16.1 Overview ............................. 111 16.1.1 What You Can Do in this Chapter ................... 111 16.2 What You Need to Know ......................111 16.3 The Local Certificates Screen ....................111 PMG2006-T20A User’s Guide...
Page 8
20.2 The Routing Table Screen ......................126 Chapter 21 System...............................128 21.1 Overview ............................. 128 21.2 The System Screen ........................128 Chapter 22 User Account............................129 22.1 Overview ............................ 129 22.2 The User Account Screen ......................129 22.2.1 The User Account Add/Edit Screen ................130 PMG2006-T20A User’s Guide...
If you forget your password, you will have to reset the PMG2006-T20A to its factory default settings. If you backed up an earlier configuration file, you would not have to totally re-configure the PMG2006-T20A. You could simply restore your last configuration.
Chapter 1 Introduction Figure 1 PMG2006-T20A Applications 1.5 Hardware 1.5.1 Front Panel The following graphic displays the front panel of the PMG2006-T20A. Figure 2 PMG2006-T20A Front Panel 1.5.2 LEDs (Lights) The following graphic displays the labels of the LEDs. PMG2006-T20A User’s Guide...
Chapter 1 Introduction Figure 3 LEDs (PMG2006-T20A) None of the LEDs are on if the PMG2006-T20A is not receiving power. Table 1 LED Descriptions COLOR STATUS DESCRIPTION Green The PMG2006-T20A is receiving power and ready for use. Blinking The PMG2006-T20A is self-testing.
0.5 cm. If not using screw anchors, use a screwdriver to insert the screws into the wall. Do not insert the screws all the way in - leave a gap of about 0.5 cm. PMG2006-T20A User’s Guide...
Page 16
Make sure the screws are fastened well enough to hold the weight of the PMG2006-T20A with the connection cables. Align the holes on the back of the PMG2006-T20A with the screws on the wall. Hang the PMG2006-T20A on the screws.
Safari 2.0 and later versions. The recommended screen resolution is 1024 by 768 pixels. In order to use the web configurator you need to allow: • Web browser pop-up windows from your PMG2006-T20A. Web pop-up blocking is enabled by default in Windows XP SP (Service Pack) 2. • JavaScript (enabled by default).
Page 18
After you finished or closed the Quick Start Wizard screen, the Network Map page appears. Figure 8 Network Map Click Status to display the Status screen, where you can view the PMG2006-T20A’s interface and system information. PMG2006-T20A User’s Guide...
ICON DESCRIPTION Language: Select the language you prefer. Quick Start: Click this icon to open screens where you can configure the PMG2006-T20A’s time zone Internet access, and wireless settings. Logout: Click this icon to log out of the web configurator.
Chapter 2 The Web Configurator 2.2.2 Navigation Panel Use the menu items on the navigation panel to open screens to configure PMG2006-T20A features. The following tables describe each menu item. Table 5 Navigation Panel Summary LINK FUNCTION Connection Status This screen shows the network status of the PMG2006-T20A and computers/devices connected to it.
Page 21
Use this screen to view the ARP table. It displays the IP and MAC address of each DHCP connection. Routing Table Routing Table Use this screen to view the routing table on the PMG2006-T20A. Maintenance System System Use this screen to set Device name and Domain name.
Page 22
Use this screen to backup and restore your PMG2006-T20A’s configuration (settings) or reset the factory default settings. Reboot Reboot Use this screen to reboot the PMG2006-T20A without turning the power off. Diagnostic Ping & Use this screen to identify problems with the DSL connection. You can Traceroute &...
H A P T E R Quick Start 3.1 Overview Use the Quick Start screens to configure the PMG2006-T20A’s time zone, basic Internet access, and wireless settings. Note: See the technical reference chapters (starting on Chapter 4 on page 25) for background information on the features in this chapter.
Page 24
Chapter 3 Quick Start Figure 11 Quick Start - Internet Connection Your PMG2006-T20A saves your settings and attempts to connect to the Internet. Click Close to complete the setup. Figure 12 Quick Start - Result Summary PMG2006-T20A User’s Guide...
If you connect to the Internet through a GPON connection, use the information from your Internet Service Provider (ISP) to configure the PMG2006-T20A. Be sure to contact your service provider for any information you need to configure the Broadband screens.
Page 26
Then select DNS as Static and enter the DNS server addresses provided to you, such as 192.168.5.2 (DNS server1)/192.168.5.1 (DNS server2). Leave the rest of the fields to the default settings. Click Apply to save your settings. PMG2006-T20A User’s Guide...
Page 27
You should see a summary of your new GPON connection setup in the Broadband screen as follows. Try to connect to a website to see if you have correctly set up your Internet connection. Be sure to contact your service provider for any information you need to configure the WAN screens. PMG2006-T20A User’s Guide...
In this case, B will never receive the traffic. You need to specify a static routing rule on the PMG2006-T20A to specify R as the router in charge of forwarding traffic to N2. In this case, the PMG2006-T20A routes traffic from A to R and then R routes the traffic to B.
Page 29
192.168.10.2 192.168.10.33 To configure a static route to route traffic from N1 to N2: Log into the PMG2006-T20A’s Web Configurator in advanced mode. Click Network Setting > Routing. Click Add new Static Route in the Static Route screen. Configure the Static Route Setup screen using the following settings: Select Enable in Active field.
• Hostname: zyxelrouter.dyndns.org • Service Type: Host with IP address • IP Address: Enter the WAN IP address that your PMG2006-T20A is currently using. You can find the IP address on the PMG2006-T20A’s Web Configurator Status page. Then you will need to configure the same account and host name on the PMG2006-T20A later.
Click Apply. 4.4.3 Testing the DDNS Setting Now you should be able to access the PMG2006-T20A from the Internet. To test this: Open a web browser on the computer (using the IP address a.b.c.d) that is connected to the Internet.
Page 32
Thomas can also grant access to the computers of other members of his family and friends. However, Josephine and others not listed in this screen will no longer be able to access the Internet through the PMG2006-T20A. PMG2006-T20A User’s Guide...
After you log into the Web Configurator, the Network Map screen appears. This shows the network connection status of the PMG2006-T20A and clients connected to it. You can use the Status screen to look at the current status of the PMG2006-T20A, system resources, and interfaces (LAN, WAN, and WLAN).
PMG2006-T20A to update this screen in Refresh interval. Figure 14 Network Map: List View Mode 5.3 The Status Screen Use this screen to view the status of the PMG2006-T20A. Click Status to open this screen. PMG2006-T20A User’s Guide...
Page 36
WAN Information (These fields display when you have a WAN connection.) Encapsulation This field displays the current encapsulation method. IP Address This field displays the current IP address of the PMG2006-T20A in the WAN. IP Subnet Mask This field displays the current subnet mask in the WAN. MAC Address This shows the WAN Ethernet adapter MAC (Media Access Control) Address of your PMG2006-T20A.
Page 37
This field displays what DHCP services the PMG2006-T20A is providing to the LAN. The possible values are: Server - The PMG2006-T20A is a DHCP server in the LAN. It assigns IP addresses to other computers in the LAN. Relay - The PMG2006-T20A acts as a surrogate DHCP server and relays DHCP requests and responses between the remote server and the clients.
Page 38
This displays the optical transceiver’s optical receiving power in dBm. Tx Power (dbm) This displays the optical transceiver’s optical transmitting power in dBm. Temperature (C) This displays the optical transceiver’s temperature in Celsius. The normal range is 0-55 degrees. PMG2006-T20A User’s Guide...
The following terms and concepts may help as you read this chapter. WAN IP Address The WAN IP address is an IP address for the PMG2006-T20A, which makes it accessible from an outside network. It is used by the PMG2006-T20A to communicate with other devices in other networks. It can be static (fixed) or dynamically assigned by the ISP each time the PMG2006-T20A tries to access the Internet.
Page 40
ISP’s Border Relay router (BR in the figure) to connect to the native IPv6 Internet. The local network can also use IPv4 services. The PMG2006-T20A uses it’s configured IPv4 WAN IP to route IPv4 traffic to the IPv4 Internet.
Page 41
Use Dual Stack Lite when local network computers use IPv4 and the ISP has an IPv6 network. When the PMG2006-T20A has an IPv6 WAN address and you set IPv4/IPv6 Mode to IPv6 Only, you can enable Dual Stack Lite to use IPv4 computers and services.
This shows whether the PMG2006-T20A act as an IGMP proxy on this connection. This shows whether NAT is activated or not for this connection. Default This shows whether the PMG2006-T20A use the WAN interface of this connection as the system Gateway default gateway.
The following example screen displays when you select Routing mode, and PPPoE encapsulation. The screen varies when you select other interface type, encapsulation, and IPv4/IPv6 mode. Figure 20 Network Setting > Broadband > Add New WAN Interface/Edit (Routing Mode) PMG2006-T20A User’s Guide...
Page 44
Select IPv4 Only if you want the PMG2006-T20A to run IPv4 only. Select IPv4 IPv6 DualStack to allow the PMG2006-T20A to run IPv4 and IPv6 at the same time. Select IPv6 Only if you want the PMG2006-T20A to run IPv6 only.
Page 45
Select this option to enable full cone NAT on this connection. This field is available only when you Enable activate NAT. In full cone NAT, the PMG2006-T20A maps all outgoing packets from an internal IP address and port to a single IP address and port on the external network. The PMG2006-T20A also maps packets coming to that external IP address and port to the internal IP address and port.
Page 46
DHCPC Options (This is available only when you select IPv4 Only or IPv4 IPv6 DualStack in the IPv4/IPv6 Mode field.) Request Options Select Option 42 to have the PMG2006-T20A get the NTP server which is available to the client. Select Option 43 to have the PMG2006-T20A automatically add vendor specific information in the DHCP packets to request the vendor specific options from the DHCP server.
Secondary DNS Enter the second IPv6 DNS server address assigned by the ISP. Server Apply Click Apply to save your changes back to the PMG2006-T20A. Cancel Click Cancel to exit this screen without saving. 6.2.1.2 Bridge Mode Click the Add new WAN Interface in the Network Setting > Broadband screen or the Edit icon next to the connection you want to configure.
Page 48
Table 10 Network Setting > Broadband > Add New WAN Interface/Edit (Bridge Mode) (continued) LABEL DESCRIPTION 802.1q Type the VLAN ID number (from 0 to 4094) for traffic through this connection. Click OK to save your changes. Cancel Click Cancel to exit this screen without saving. PMG2006-T20A User’s Guide...
• Use the Static DHCP screen to assign IP addresses on the LAN to specific individual computers based on their MAC Addresses (Section 7.3 on page 55). • Use the UPnP screen to enable UPnP and UPnP NAT traversal on the PMG2006-T20A (Section 7.4 on page 56).
Page 50
Chapter 7 Home Networking DHCP A DHCP (Dynamic Host Configuration Protocol) server can assign your PMG2006-T20A an IP address, subnet mask, DNS and other routing information when it's turned on. DNS (Domain Name System) is for mapping a domain name to its corresponding IP address and vice versa.
7.2 The LAN Setup Screen Use this screen to set the Local Area Network IP address and subnet mask of your PMG2006-T20A. Click Network Setting > Home Networking to open the LAN Setup screen. Follow these steps to configure your LAN settings.
Page 52
Chapter 7 Home Networking Click Apply to save your settings. Figure 22 Network Setting > Home Networking > LAN Setup PMG2006-T20A User’s Guide...
Page 53
Select Enable to have the PMG2006-T20A record DHCP IP addresses with the MAC addresses the for the same IP addresses are assigned to. The PMG2006-T20A assigns the same IP address to the same MAC host address when the host requests an IP address again through DHCP.
Page 54
Select this to manually enter an interface ID for the LAN interface’s link-local address. LAN Global Identifier Type EUI64 Select this to have the PMG2006-T20A generate an interface ID using the EUI-64 format for its global address. Manual Select this to manually enter an interface ID for the LAN interface’s global IPv6 address.
Knowing the LAN clients’ MAC addresses on your network beforehand can help you set up quickly. Use this screen to change your PMG2006-T20A’s static DHCP settings. Click Network Setting > Home Networking > Static DHCP to open the following screen.
Table 13 Static DHCP: Static DHCP Configuration/Edit LABEL DESCRIPTION Active Select this to activate the connection between the client and the PMG2006-T20A. Group Name Select the interface group name for which you want to configure static DHCP settings. See Chapter 11 on page 91 for how to create a new interface group.
This section shows you how to use the UPnP feature in Windows 7. UPnP server is installed in Windows 7. Activate UPnP on the PMG2006-T20A. Make sure the computer is connected to a LAN port of the PMG2006-T20A. Turn on your computer and the PMG2006-T20A.
Page 58
Select Turn on network discovery and click Save Changes. Network discovery allows your computer to find other computers and devices on the network and other computers on the network to find your computer. This makes it easier to share files and printers. PMG2006-T20A User’s Guide...
The PMG2006-T20A supports multiple logical LAN interfaces via its physical Ethernet interface with the PMG2006-T20A itself as the gateway for the LAN network. When you use IP alias, you can also configure firewall rules to control access to the LAN's logical network (subnet).
Use the TFTP Server Name screen to set the TFTP server address which is passed to the clients using DHCP option 66. The DHCP clients in the PMG2006-T20A local network, such as STB devices that support the TFTP booting mechanism, can then use the TFTP server address or domain name for initial system settings download.
DHCP (Dynamic Host Configuration Protocol, RFC 2131 and RFC 2132) allows individual clients to obtain TCP/IP configuration at start-up from a server. You can configure the PMG2006-T20A as a DHCP server or disable it. When configured as a server, the PMG2006-T20A provides the TCP/IP configuration for the clients.
Once you have decided on the network number, pick an IP address that is easy to remember, for instance, 192.168.1.1, for your PMG2006-T20A, but make sure that no other device on your network is using that IP address.
Figure 29 Example of Routing Topology 8.2 The Routing Screen Use this screen to view and configure the static route rules on the PMG2006-T20A to save time and bandwidth. Click Network Setting > Routing > Static Route to open the following screen.
Modify Click the Edit icon to edit the static route on the PMG2006-T20A. Click the Delete icon to remove a static route from the PMG2006-T20A. A window displays asking you to confirm that you want to delete the route. 8.2.1 Add/Edit Static Route Use this screen to add or edit a static route.
Click Cancel to exit this screen without saving. 8.3 The DNS Route Screen Use this screen to view and configure DNS routes on the PMG2006-T20A. Click Network Setting > Routing > DNS Route to open the following screen. Figure 32 Network Setting > Routing > DNS Route The following table describes the labels in this screen.
Click the Delete icon to delete the DNS route. 8.3.1 The DNS Route Add Screen You can manually add the PMG2006-T20A’s DNS route entry. Click Add New DNS Route in the Network Setting > Routing > DNS Route screen. The screen shown next appears.
Page 67
Chapter 8 Routing The Policy Route screen let you view and configure routing policies on the PMG2006-T20A. Click Network Setting > Routing > Policy Route to open the following screen. Figure 34 Network Setting > Routing > Policy Route The following table describes the labels in this screen.
Broadband screens. Click OK to save your changes. Cancel Click Cancel to exit this screen without saving. 8.5 RIP Routing Information Protocol (RIP, RFC 1058 and RFC 1389) allows a device to exchange routing information with other routers. PMG2006-T20A User’s Guide...
Operation Select Passive to have the PMG2006-T20A update the routing table based on the RIP packets received from neighbors but not advertise its route information to other routers in this interface.
76). • Use the DMZ screen to configure a default server (Section 9.5 on page 78). • Use the ALG screen to enable and disable the NAT and SIP (VoIP) ALG in the PMG2006-T20A (Section 9.6 on page 79). • Use the Address Mapping screen to configure the PMG2006-T20A's address mapping settings (Section 9.7 on page...
(B in the example) and assign a default server IP address of 192.168.1.35 to a third (C in the example). You assign the LAN IP addresses and the ISP assigns the WAN IP address. The NAT network appears as a single host on the Internet. PMG2006-T20A User’s Guide...
Page 72
Port Protocol This shows the IP protocol supported by this virtual server, whether it is TCP, UDP, or TCP/UDP. Modify Click the Edit icon to edit this rule. Click the Delete icon to delete an existing rule. PMG2006-T20A User’s Guide...
Start Port field above. Translation Start This shows the port number to which you want the PMG2006-T20A to translate the incoming port. Port For a range of ports, enter the first number of the range to which you want the incoming ports translated.
Click this to add a new NAT application rule. Application This is the index number of the entry. Application This field shows the type of application that the service forwards. Forwarded WAN Interface This field shows the WAN interface through which the service is forwarded. PMG2006-T20A User’s Guide...
Select the category of the application from the drop-down list box. Category Application Select a service from the drop-down list box and the PMG2006-T20A automatically configures Forwarded the protocol, start, end, and map port number that define the service. View Rules Click this to display the configuration of the service that you have chosen in Application Fowarded.
Trigger port forwarding solves this problem by allowing computers on the LAN to dynamically take turns using the service. The PMG2006-T20A records the IP address of a LAN computer that sends traffic to the WAN to request a service with a specific port number and protocol (a "trigger" port). When the PMG2006-T20A's WAN port receives a response with a specific port number and protocol ("open"...
This field shows the WAN interface through which the service is forwarded. Trigger Start Port The trigger port is a port (or a range of ports) that causes (or triggers) the PMG2006-T20A to record the IP address of the LAN computer that sent the traffic to a server on the WAN.
Select a WAN interface for which you want to configure port triggering rules. Trigger Start Port The trigger port is a port (or a range of ports) that causes (or triggers) the PMG2006-T20A to record the IP address of the LAN computer that sent the traffic to a server on the WAN.
SIP data stream to a public IP address. You do not need to use STUN or an outbound proxy if your PMG2006-T20A is behind a SIP ALG. Use this screen to enable and disable the ALGs in the PMG2006-T20A. To access this screen, click Network Setting > NAT > ALG.
NAT. The Real Time Streaming (media control) Protocol (RTSP) is a remote control for multimedia on the Internet. PPTP ALG Enable this to turn on the PPTP ALG on the PMG2006-T20A to detect PPTP traffic and help build PPTP sessions through the PMG2006-T20A’s NAT. IPSEC ALG Enable this to turn on the IPsec ALG on the PMG2006-T20A to detect IPsec traffic and help build IPsec sessions through the PMG2006-T20A’s NAT.
One-to-one NAT mapping type. Many-to-One: This mode maps multiple local IP addresses to one global IP address. This is equivalent to SUA (i.e., PAT, port address translation), the PMG2006-T20A's Single User Account feature that previous routers supported only.
NAT sessions. Apply Click this to save your changes on this screen and activate this feature. Cancel Click this to exit this screen without saving any changes. 9.9 Technical Reference This part contains more information regarding NAT. PMG2006-T20A User’s Guide...
Chapter 9 Network Address Translation (NAT) 9.9.1 NAT Definitions Inside/outside denotes where a host is located relative to the PMG2006-T20A, for example, the computers of your subscribers are the inside hosts, while the web servers on the Internet are the outside hosts.
(and TCP or UDP source port numbers for Many-to-One and Many-to-Many Overload NAT mapping) in each packet and then forwards it to the Internet. The PMG2006-T20A keeps track of the original addresses and port numbers so incoming reply packets can have their original values restored.
Page 85
(B in the example) and assign a default server IP address of 192.168.1.35 to a third (C in the example). You assign the LAN IP addresses and the ISP assigns the WAN IP address. The NAT network appears as a single host on the Internet. PMG2006-T20A User’s Guide...
(in the order you specify in the Broadband screen) to resolve domain names that do not match any DNS routing entry. After the PMG2006-T20A receives a DNS reply from a DNS server, it creates a new entry for the resolved IP address in the routing table.
If you have a private WAN IP address, then you cannot use Dynamic DNS. 10.2 The DNS Entry Screen Use this screen to view and configure DNS routes on the PMG2006-T20A. Click Network Setting > DNS to open the DNS Entry screen.
Click Cancel to exit this screen without saving. 10.3 The Dynamic DNS Screen Use this screen to change your PMG2006-T20A’s DDNS. Click Network Setting > DNS > Dynamic DNS. The screen appears as shown. Figure 55 Network Setting > DNS > Dynamic DNS The following table describes the fields in this screen.
Page 90
Table 39 Network Setting > DNS > > Dynamic DNS (continued) LABEL DESCRIPTION Current Dynamic This shows the IP address your Dynamic DNS provider has currently associated with the hostname. Apply Click Apply to save your changes. Cancel Click Cancel to exit this screen without saving. PMG2006-T20A User’s Guide...
Interface Grouping 11.1 Overview By default, all LAN and WAN interfaces on the PMG2006-T20A are in the same group and can communicate with each other. Create interface groups to have the PMG2006-T20A assign the IP addresses in different domains to different groups. Each group acts as an independent network on the PMG2006-T20A.
Click the Add New Interface Group button in the Interface Grouping screen to open the following screen. Use this screen to create a new interface group. Note: An interface can belong to only one group at a time. PMG2006-T20A User’s Guide...
Page 93
This shows the filtering criteria. The LAN interface on which the matched traffic is received will belong to this group automatically. WildCard This shows if wildcard on DHCP option 60 is enabled. Support Modify Click the Modify icon to edit this rule from the PMG2006-T20A. PMG2006-T20A User’s Guide...
Chapter 11 Interface Grouping Table 41 Interface Group Configuration (continued) LABEL DESCRIPTION Click OK to save your changes back to the PMG2006-T20A. Cancel Click Cancel to exit this screen without saving. 11.2.2 Interface Grouping Criteria Click the Add button in the Interface Grouping Configuration screen to open the following screen.
12.1 Overview This chapter shows you how to enable and configure the PMG2006-T20A’s security settings. Use the firewall to protect your PMG2006-T20A and network from attacks by hackers on the Internet and control access to it. By default the firewall: •...
LAN. 12.2 The Firewall Screen Use this screen to set the security level of the firewall on the PMG2006-T20A, and block unauthorized access to your network. Firewall rules are grouped based on the direction of travel of packets to which they apply.
LABEL DESCRIPTION Firewall Select Enable to activate the firewall feature on the PMG2006-T20A. Select Low to allow LAN to WAN and WAN to LAN packet directions. Medium Select Medium to allow LAN to WAN but deny WAN to LAN packet directions.
Type a single port number or the range of port numbers that define your customized service. Protocol This field is displayed if you select Other as the protocol. Number Enter the protocol number of your customized port. PMG2006-T20A User’s Guide...
Click the Move To icon to change the order of the rule. Enter the number in the # field. 12.4.1 Add/Edit an ACL Rule Click Add new ACL rule or the Edit icon next to an existing ACL rule in the Access Control screen. The following screen displays. PMG2006-T20A User’s Guide...
Page 100
Enter a single port number or the range of port numbers of the source. Custom This field is displayed only when you select Specific Protocol in Select Protocol. Destination Port Enter a single port number or the range of port numbers of the destination. PMG2006-T20A User’s Guide...
The following table describes the labels in this screen. Table 48 Security > Firewall > DoS LABEL DESCRIPTION DoS Protection Select Enable to enable protection against DoS attacks. Blocking Apply Click Apply to save your changes. Cancel Click Cancel to exit this screen without saving. PMG2006-T20A User’s Guide...
13.2 The MAC Filter Screen Use this screen to allow wireless and LAN clients access to the PMG2006-T20A. Click Security > MAC Filter. The screen appears as shown. Figure 67 Security > MAC Filter...
Page 103
Select Enable to activate the MAC filter function. MAC Restrict Mode Select Allow to only permit the listed MAC addresses access to the PMG2006-T20A. Select Deny to permit anyone access to the PMG2006-T20A except the listed MAC addresses. This is the index number of the MAC address.
14.1 Overview Parental control allows you to block web sites with the specific URL. You can also define time periods and days during which the PMG2006-T20A performs parental control on a specific user. 14.2 The Parental Control Screen Use this screen to enable parental control, view the parental control rules and schedules.
Use this screen to configure a restricted access schedule and/or URL filtering settings to block the users on your network from accessing certain web sites. Figure 69 Parental Control Rule: Add/Edit Rule PMG2006-T20A User’s Guide...
Page 106
Web Site sites with the URLs listed below. If you select Allow the Web URLs, the PMG2006-T20A blocks access to all URLs except ones listed below. Click Add to show a screen to enter the URL of web site or URL keyword to which the PMG2006- T20A blocks or allows access.
Page 107
Select the transport layer protocol used for the service. Choices are TCP, UDP, or TCP & UDP. Port Enter the port of the service. If you have chosen a pre-defined service in the Service Name field, this field will not be configurable. PMG2006-T20A User’s Guide...
Page 108
Table 53 Parental Control Rule: Add/Edit > Add Keyword LABEL DESCRIPTION Site/URL Enter a keyword and click OK to have the PMG2006-T20A block access to the website URLs that Keyword contain the keyword. Click OK to save your changes. Cancel Click Cancel to exit this screen without saving.
Scheduler Rule 15.1 Overview You can define time periods and days during which the PMG2006-T20A performs scheduled rules of certain features (such as Firewall Access Control) in the Scheduler Rule screen. Note that the scheduler rules need to work with other configurations.
Page 110
Enter a name (up to 31 printable English keyboard characters, not including spaces) for this schedule. Select check boxes for the days that you want the PMG2006-T20A to perform this scheduler rule. Time of Day Enter the time period of each day, in 24-hour format, during which the rule will be enforced.
• Use the Local Certificates screen to generate certification requests and import the PMG2006-T20A's CA-signed certificates (Section 16.4 on page 114). • Use the Trusted CA screen to save the certificates of trusted CAs to the PMG2006-T20A (Section 16.4 on page 114).
Click this button to save the certificate that you have enrolled from a certification authority from your computer to the PMG2006-T20A. Create Certificate Click this button to go to the screen where you can have the PMG2006-T20A generate a Request certification request.
Page 113
Type up to 63 ASCII characters (not including spaces) to identify this certificate. Name Common Name Select Auto to have the PMG2006-T20A configure this field automatically. Or select Customize to enter it manually. Type the IP address (in dotted decimal notation), domain name or e-mail address in the field provided.
Certificate This is the name of the signed certificate. Name Certificate Copy and paste the signed certificate into the text box to store it on the PMG2006-T20A. Apply Click Apply to save your changes. Cancel Click Cancel to exit this screen without saving.
Import Click this button to open a screen where you can save the certificate of a certification authority Certificate that you trust to the PMG2006-T20A. This is the index number of the entry. Name This field displays the name used to identify this certificate.
Type in the location of the certificate you want to upload in this field or click Choose File to find Path Apply Click Apply to save your changes. Cancel Click Cancel to exit this screen without saving. PMG2006-T20A User’s Guide...
17.1 Overview The web configurator allows you to choose which categories of events and/or alerts to have the PMG2006-T20A log and then display the logs or have the PMG2006-T20A send them to an administrator (as e-mail) or to a syslog server.
DESCRIPTION Level Select a severity level from the drop-down list box. This filters search results according to the severity level you have selected. When you select a severity, the PMG2006-T20A searches through all logs of that severity or higher. Category Select the type of logs to display.
Page 119
DESCRIPTION Level Select a severity level from the drop-down list box. This filters search results according to the severity level you have selected. When you select a severity, the PMG2006-T20A searches through all logs of that severity or higher. Category Select the type of logs to display.
• Use the LAN screen to view the LAN traffic statistics (Section 18.3 on page 121). • Use the NAT screen to view the NAT status of the PMG2006-T20A’s client(s) (Section 18.4 on page 122) 18.2 The WAN Status Screen Click System Monitor >...
Click System Monitor > Traffic Status > LAN to open the following screen. The figure in this screen shows the number of bytes received and sent on the PMG2006-T20A from each LAN port. Figure 85 System Monitor > Traffic Status > LAN The following table describes the fields in this screen.
Click System Monitor > Traffic Status > NAT to open the following screen. The figure in this screen shows the NAT session statistics for hosts currently connected on the PMG2006-T20A. A higher Number of Open Sessions indicates busier Internet activities.
ARP updates the ARP Table for future reference and then sends the packet to the MAC address that replied. 19.2 ARP Table Screen Use the ARP table to view IP-to-MAC address mapping(s). To open this screen, click System Monitor > ARP Table. Figure 87 System Monitor > ARP Table PMG2006-T20A User’s Guide...
Page 124
This is the learned IPv4 or IPv6 IP address of a device connected to a port. Address MAC Address This is the MAC address of the device with the listed IP address. Device This is the type of interface used by the device. PMG2006-T20A User’s Guide...
H A P T E R Routing Table 20.1 Overview Routing is based on the destination address only and the PMG2006-T20A takes the shortest path to forward a packet. 20.2 The Routing Table Screen Click System Monitor > Routing Table to open the following screen.
WAN interface using PPPoE. pon indicates a PON interface through which all packets are transmitted. omci indicates an OMCI interface where OMCI data is transmitted between the PMG2006-T20A and the OLT. oam indicates that PLOAM messages are transmitted on the PON interface.
H A P T E R System 21.1 Overview In the System screen, you can name your PMG2006-T20A (Host) and give it an associated domain name for identification purposes. 21.2 The System Screen Click Maintenance > System to open the following screen.
Clear the check box to disable the user account. Select the check box to enable it. User Name This field displays the name of the account used to log into the PMG2006-T20A web configurator. Retry Times This field displays the number of times consecutive wrong passwords can be entered for this account.
Enter the number of times consecutive wrong passwords can be entered for this account. 0 means there is no limit. Idle Timeout Enter the length of inactive time before the PMG2006-T20A will automatically log the user out of the web configurator. Lock Period Enter the length of time a user must wait before attempting to log in again after a number of consecutive wrong passwords have been entered as defined in Retry Times.
Page 130
Chapter 22 User Account Table 72 Maintenance > User Account > Add/Edit (continued) (continued) LABEL DESCRIPTION Click OK to save your changes. Cancel Click Cancel to exit this screen without saving. PMG2006-T20A User’s Guide...
Use this screen to configure through which interface(s), which services can access the PMG2006-T20A. You can also specify the port numbers the services must use to connect to the PMG2006-T20A. Click Maintenance > Remote Management > MGMT Services to open the following screen.
Click Cancel to restore your previously saved settings. 23.3 The Trust Domain Screen Use this screen to view a list of public IP addresses which are allowed to access the PMG2006-T20A through the services configured in the Maintenance > Remote Management screen. Click Maintenance >...
Page 133
Table 75 Maintenance > Remote Management > Trust Domain > Add Trust Domain LABEL DESCRIPTION IP Address Enter a public IPv4 IP address which is allowed to access the service on the PMG2006-T20A from the WAN. Click OK to save your changes back to the PMG2006-T20A. Cancel Click Cancel to exit this screen without saving.
An SNMP managed network consists of two main types of component: agents and a manager. An agent is a management software module that resides in a managed device (the PMG2006-T20A). An agent translates the local management information from the managed device into a form compatible with SNMP.
Page 135
• Set - Allows the manager to set values for object variables within an agent. • Trap - Used by the agent to inform the manager of some events. Click Maintenance > SNMP to open the following screen. Use this screen to configure the PMG2006-T20A SNMP settings.
25.2 The Time Screen To change your PMG2006-T20A’s time and date, click Maintenance > Time. The screen appears as shown. Use this screen to configure the PMG2006-T20A’s time based on your local time zone.
LABEL DESCRIPTION Current Date This field displays the date of your PMG2006-T20A. Each time you reload this page, the PMG2006-T20A synchronizes the date with the time server. Time and Date Setup First ~ Fifth Time Select an NTP time server from the drop-down list box.
A mail server is an application or a computer that runs such an application to receive, forward and deliver e-mail messages. To have the PMG2006-T20A send reports, logs or notifications via e-mail, you must specify an e-mail server and the e-mail addresses of the sender and receiver.
Enter the e-mail address that you want to be in the from/sender line of the e-mail notification Address that the PMG2006-T20A sends. If you activate SSL/TLS authentication, the e-mail address must be able to be authenticated by the mail server as well.
H A P T E R Log Setting 27.1 Overview You can configure where the PMG2006-T20A sends logs and which logs and/or immediate alerts the PMG2006-T20A records in the Logs Setting screen. 27.2 The Log Settings Screen To change your PMG2006-T20A’s log settings, click Maintenance > Logs Setting. The screen appears as shown.
LABEL DESCRIPTION Syslog Setting Syslog Logging The PMG2006-T20A sends a log to an external syslog server. Select Enable to enable syslog logging. Mode Select the syslog destination from the drop-down list box. If you select Remote, the log(s) will be sent to a remote syslog server. If you select Local File, the log(s) will be saved in a local file.
Mail Subject PMG2006-T20A sends. Send Log to The PMG2006-T20A sends logs to the e-mail address specified in this field. If this field is left blank, the PMG2006-T20A does not send logs via E-mail. Send Alarm to Alerts are real-time notifications that are sent as soon as an event, such as a DoS attack, system error, or forbidden web access attempt occurs.
Page 143
|<1,02> 127|Apr 7 00 |From:192.168.1.131 To:192.168.1.255 |match |forward | 10:05:17 |UDP src port:00520 dest port:00520 |<1,02> 128|Apr 7 00 |From:192.168.1.1 To:192.168.1.255 |match |forward | 10:05:30 |UDP src port:00520 dest port:00520 |<1,02> End of Firewall Log PMG2006-T20A User’s Guide...
H A P T E R Firmware Upgrade 28.1 Overview This chapter explains how to upload new firmware to your PMG2006-T20A. You can download new firmware releases from your nearest Zyxel FTP site (or www.zyxel.com) to use to upgrade your device’s performance.
Page 145
Click this to begin the upload process. This process may take up to two minutes. Figure 103 Firmware Uploading The PMG2006-T20A automatically restarts in this time causing a temporary network disconnect. In some operating systems, you may see the following icon on your desktop.
Figure 105 Maintenance > Backup/Restore Backup Configuration Backup Configuration allows you to back up (save) the PMG2006-T20A’s current configuration to a file on your computer. Once your PMG2006-T20A is configured and functioning properly, it is highly recommended that you back up your configuration file before making configuration changes. The backup configuration file will be useful in case you need to return to your previous settings.
After the PMG2006-T20A configuration has been restored successfully, the login screen appears. Login again to restart the PMG2006-T20A. The PMG2006-T20A automatically restarts in this time causing a temporary network disconnect. In some operating systems, you may see the following icon on your desktop.
RESET button. 29.3 The Reboot Screen System restart allows you to reboot the PMG2006-T20A remotely without turning the power off. You may need to do this if the PMG2006-T20A hangs, for example. It will take a few minutes before you can log into the PMG2006-T20A again after rebooting.
Diagnostic 30.1 Overview The Diagnostic screens display information to help you identify problems with the PMG2006-T20A. A connectivity fault point generally takes time to discover and impacts subscriber’s network access. In order to eliminate the management and maintenance efforts, IEEE 802.1ag is a Connectivity Fault Management (CFM) specification which allows network administrators to identify and manage connection faults.
Ping 6 Click this to ping the IPv6 address that you entered. Trace Route Click this to display the route path and transmission delays between the PMG2006-T20A to the IPv4 address that you entered. Trace Route 6 Click this to display the route path and transmission delays between the PMG2006-T20A to the IPv6 address that you entered.
Make sure you are using the power adaptor or cord included with the PMG2006-T20A. Make sure the power adaptor or cord is connected to the PMG2006-T20A and plugged in to an appropriate power source. Make sure the power source is turned on.
The default LAN IP address is 192.168.1.1. If you changed the IP address and have forgotten it, you might get the IP address of the PMG2006-T20A by looking up the IP address of the default gateway for your computer. To do this in most Windows computers, click Start >...
You cannot log in to the web configurator while someone is using Telnet to access the PMG2006-T20A. Log out of the PMG2006-T20A in the other session, or ask the person who is logged in to log out. Turn the PMG2006-T20A off and on.
If you are trying to access the Internet wirelessly, make sure that you enabled the wireless LAN in the PMG2006-T20A and your wireless client and that the wireless settings in the wireless client are the same as the settings in the PMG2006-T20A.
• Brief description of the problem and the steps you took to solve it. Corporate Headquarters (Worldwide) Taiwan • Zyxel Communications Corporation • http://www.zyxel.com Asia China • Zyxel Communications (Shanghai) Corp. Zyxel Communications (Beijing) Corp. Zyxel Communications (Tianjin) Corp. • http://www.zyxel.cn India • Zyxel Technology India Pvt Ltd • http://www.zyxel.in Kazakhstan •...
Page 158
Appendix A Customer Support Belgium • Zyxel Communications B.V. • http://www.zyxel.com/be/nl/ • http://www.zyxel.com/be/fr/ Bulgaria • Zyxel България • http://www.zyxel.com/bg/bg/ Czech Republic • Zyxel Communications Czech s.r.o • http://www.zyxel.cz Denmark • Zyxel Communications A/S • http://www.zyxel.dk Estonia • Zyxel Estonia • http://www.zyxel.com/ee/et/ Finland •...
Page 159
• Zyxel Communications Poland • http://www.zyxel.pl Romania • Zyxel Romania • http://www.zyxel.com/ro/ro Russia • Zyxel Russia • http://www.zyxel.ru Slovakia • Zyxel Communications Czech s.r.o. organizacna zlozka • http://www.zyxel.sk Spain • Zyxel Communications ES Ltd • http://www.zyxel.es Sweden • Zyxel Communications • http://www.zyxel.se Switzerland •...
Page 160
Appendix A Customer Support • http://www.zyxel.ch/ Turkey • Zyxel Turkey A.S. • http://www.zyxel.com.tr • Zyxel Communications UK Ltd. • http://www.zyxel.co.uk Ukraine • Zyxel Ukraine • http://www.ua.zyxel.com Latin America Argentina • Zyxel Communication Corporation • http://www.zyxel.com/ec/es/ Brazil • Zyxel Communications Brasil Ltda.
Appendix A Customer Support North America • Zyxel Communications, Inc. - North America Headquarters • http://www.zyxel.com/us/en/ Oceania Australia • Zyxel Communications Corporation • http://www.zyxel.com/au/en/ Africa South Africa • Nology (Pty) Ltd. • http://www.zyxel.co.za PMG2006-T20A User’s Guide...
10 bits 54 bits 64 bits Global Address A global address uniquely identifies a device on the Internet. It is similar to a “public IP address” in IPv4. A global unicast address starts with a 2 or 3. PMG2006-T20A User’s Guide...
The following table describes the multicast addresses which are reserved and can not be assigned to a multicast group. Table 86 Reserved Multicast Address MULTICAST ADDRESS FF00:0:0:0:0:0:0:0 FF01:0:0:0:0:0:0:0 FF02:0:0:0:0:0:0:0 FF03:0:0:0:0:0:0:0 FF04:0:0:0:0:0:0:0 FF05:0:0:0:0:0:0:0 FF06:0:0:0:0:0:0:0 FF07:0:0:0:0:0:0:0 FF08:0:0:0:0:0:0:0 FF09:0:0:0:0:0:0:0 FF0A:0:0:0:0:0:0:0 FF0B:0:0:0:0:0:0:0 FF0C:0:0:0:0:0:0:0 FF0D:0:0:0:0:0:0:0 PMG2006-T20A User’s Guide...
IA_NA before the lifetimes expire. After T1, the client sends the server (S1) (from which the addresses in the IA_NA were obtained) a Renew message. If the time T2 is reached and the server PMG2006-T20A User’s Guide...
LAN. The PMG2006-T20A uses the received IPv6 prefix (for example, 2001:db2::/48) to generate its LAN IP address. Through sending Router Advertisements (RAs) regularly by multicast, the PMG2006-T20A passes the IPv6 prefix information to its LAN hosts. The hosts then can use the prefix to generate their IPv6 addresses.
When the PMG2006-T20A needs to send a packet, it first consults the destination cache to determine the next hop. If there is no matching entry in the destination cache, the PMG2006-T20A uses the prefix list to determine whether the destination address is on-link and can be reached directly without passing through a router.
Page 167
Install Dibbler and select the DHCPv6 client option on your computer. After the installation is complete, select Start > All Programs > Dibbler-DHCPv6 > Client Install as service. Select Start > Control Panel > Administrative Tools > Services. Double click Dibbler - a DHCPv6 client. PMG2006-T20A User’s Guide...
Page 168
Windows 7 supports IPv6 by default. DHCPv6 is also enabled when you enable IPv6 on a Windows 7 computer. To enable IPv6 in Windows 7: Select Control Panel > Network and Sharing Center > Local Area Connection. Select the Internet Protocol Version 6 (TCP/IPv6) checkbox to enable it. Click OK to save the change. PMG2006-T20A User’s Guide...
• If the Protocol is TCP, UDP, or TCP/UDP, this is the IP port number. • If the Protocol is USER, this is the IP protocol number. • Description: This is a brief explanation of the applications that use this service or the situations in which this service is used. PMG2006-T20A User’s Guide...
Page 171
Microsoft Networks’ messenger service uses this protocol. NetBIOS TCP/UDP The Network Basic Input/Output System is used for communication between computers in a LAN. TCP/UDP TCP/UDP TCP/UDP NEW-ICQ 5190 An Internet chat program. NEWS A protocol for news groups. PMG2006-T20A User’s Guide...
Page 172
SSDP 1900 The Simple Service Discovery Protocol supports Universal Plug-and-Play (UPnP). TCP/UDP Secure Shell Remote Login Program. STRM WORKS 1558 Stream Works Protocol. SYSLOG Syslog allows you to send system logs to a UNIX server. PMG2006-T20A User’s Guide...
Page 173
Internet and in UNIX environments. It operates over TCP/IP networks. Its primary function is to allow users to log into remote host systems. VDOLIVE 7000 A videoconferencing solution. The UDP port number is specified in the application. user- defined PMG2006-T20A User’s Guide...
The contents of this publication may not be reproduced in any part or as a whole, transcribed, stored in a retrieval system, translated into any language, or transmitted in any form or by any means, electronic, mechanical, magnetic, optical, chemical, photocopying, manual, or otherwise, without the prior written permission of Zyxel Communications Corporation. Published by Zyxel Communications Corporation. All rights reserved.
(Energy-related Products directive) as well as ecodesign requirement laid down in applicable implementing measures, power consumption has satisfied regulation requirements which are: • Network standby power consumption < 8W, and/or • Off mode power consumption < 0.5W, and/or PMG2006-T20A User’s Guide...
Page 176
Various symbols are used in this product to ensure correct usage, to prevent danger to the user and others, and to prevent property damage. The meaning of these symbols are described below. It is important that you read these descriptions thoroughly and fully understand the contents. PMG2006-T20A User’s Guide...
North American products. Trademarks ZyNOS (Zyxel Network Operating System) and ZON (Zyxel One Network) are registered trademarks of Zyxel Communications, Inc. Other trademarks mentioned in this publication are used for identification purposes only and may be properties of their respective owners.
50, 61 Domain Name creating Domain Name System, see DNS public key replacing dynamic DNS storage space wildcard Certification Authority Dynamic Host Configuration Protocol, see DHCP Certification Authority. see CA DYNDNS wildcard certifications viewing PMG2006-T20A User’s Guide...
Page 179
Loop Back Response, see LBR Inside Local Address, see ILA loopback interface group Internet wizard setup Internet access wizard setup Internet Protocol version 6 Internet Protocol version 6, see IPv6 IP address 49, 62 MAC address ping Mac filter private PMG2006-T20A User’s Guide...
Page 180
SIP ALG NNTP activation SMTP SNMP 85, 135, 136 agents passwords GetNext Manager Ping of Death managers Point-to-Point Tunneling Protocol, see PPTP POP3 network components port forwarding ports Trap PPTP versions prefix delegation SNMP trap private IP address PMG2006-T20A User’s Guide...
Page 181
SYN attack syslog ZyXEL Family Safety page protocol severity levels system firmware version passwords status time time trademarks Universal Plug and Play, see UPnP upgrading firmware UPnP cautions NAT traversal status Wide Area Network, see WAN warranty PMG2006-T20A User’s Guide...
Need help?
Do you have a question about the PMG2006-T20A and is the answer not in the manual?
Questions and answers