ZyXEL Communications P-334WT Support Notes page 20

Hide thumbs Also See for P-334WT:
Table of Contents

Advertisement

packets which are used for key managements. Because the remote gateway checks this source port
during connections, the port thus is not allowed to be changed.
18. How do I setup my Prestige for routing IPsec packets over SUA?
For outgoing IPsec tunnels, no extra setting is required. For forwarding the inbound IPsec ESP tunnel, A
'Default' server set in menu 15 is required. It is because SUA makes your LAN appear as a single
machine to the outside world. LAN users are invisible to outside users. So, to make an internal server for
outside access, we must specify the service port and the LAN IP of this server in Menu 15. Thus SUA is
able to forward the incoming packets to the requested service behind SUA and the outside users access
the server using the Prestige's WAN IP address. So, we have to configure the internal IPsec as a default
server (unspecified service port) in menu 15 when it acts a server gateway.
19. Why can't I use video conferencing with MSN 4.6?
This is because MSN 4.6 require support of UPnP (Universal plug n' play). To be able to use MSN
through Prestige, you have to enable the UPnP feature under Advanced-> UPNP and Check the enable
UPnP check box and press "Apply button" to make it active.
20. How can I access internal server via public IP address assigned on WAN?
You should be able to access your internal server via it's internal IP address when SUA is on, to access
your internal server via the public IP address assigned on WAN, you can enter CI command "ip nat
loopback on" in SMT Menu 24.8, To make the configuration permanently, you need to add this
command to the system boot file (autoexec.net). You can refer to Product Support Note section on
www.
zyxel.com
for configuration details.
21. Should I create any firewall rule by myself to allow incoming traffic when NAT is used ?
Built-in firewall function is supported in P-334WT. When a session is initiated from a user located in P-
334WT's LAN network, incoming traffic will be allowed by Stateful Inspection mechanism. However, if
the session is initiated from WAN side and there is no related access rule for the incoming traffic, the
traffic will be blocked by P-334WT. To help users get rid of the problem and configuration tasks, P-
334WT will create firewall policy automatically to allow incoming traffic if NAT is enabled in the P-
334WTs. Following NAT types ,including: Port Mapping, One-to-one, Many one-to-one, Server Type
are supported with automatic ACL rule creation function for incoming traffic. Therefore, users don't
have to configure any access rule by themselves to support FTP, WEB, TELNET ...etc services.
All contents copyright © 2004 ZyXEL Communications Corporation.

Advertisement

Table of Contents
loading

Table of Contents