ZyXEL Communications Prestige 652H/HW Compact Manual

ZyXEL Communications Prestige 652H/HW Compact Manual

Adsl security/wireless lan router

Advertisement

Quick Links

Prestige 652H/HW
ADSL Security/Wireless LAN Router
Compact Guide
Version 3.40
May 2003

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Prestige 652H/HW and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Summary of Contents for ZyXEL Communications Prestige 652H/HW

  • Page 1 Prestige 652H/HW ADSL Security/Wireless LAN Router Compact Guide Version 3.40 May 2003...
  • Page 2: Table Of Contents

    6 Troubleshooting... 35 1 Introducing the Prestige The Prestige 652H/HW ADSL router is the ideal all-in-one device for small networks connecting to the Internet via ADSL. Key features of the Prestige include firewall, VPN, wireless LAN, NAT, Remote Management and UPnP. See your User’s Guide for more details on all Prestige features.
  • Page 3: Hardware

    Virtual Channel Identifier (VCI): ____________ Multiplexing (VC-based or LLC-based): Encapsulation: RFC 1483 Ethernet Encapsulation Gateway IP Address: ____________________ ENET ENCAP User Name: ____________ PPPoA Service Name: ____________ PPPoE User Name: ____________ 2 Hardware Prestige 652H/HW INTERNET ACCOUNT INFORMATION Password: ____________ Password: ____________...
  • Page 4: Rear Panel Connections

    The PWR LED turns on. The SYS LED blinks while performing system testing and then turns steady on if the testing is successful. A LAN LED turns on if a LAN port is properly connected. Prestige 652H/HW DESCRIPTION turn on the Prestige.
  • Page 5: Inserting A Pcmcia Wireless Lan Card

    With its pin connector facing the slot and the LED side facing upwards, slide the ZyAIR wireless LAN card into the slot. Never force, bend or twist the wireless LAN card into the slot. Step 4. Turn on the Prestige. The WLAN LED should turn on. 2.3 The Front Panel LEDs Prestige 652H/HW DESCRIPTION...
  • Page 6 1/DMZ-4 Blinking Orange Blinking WLAN Green Blinking Prestige 652H/HW Figure 2 Prestige Front Panel Table 2 Front Panel LED Description The Prestige is receiving power. The Prestige is not receiving power. The Prestige is functioning properly. The Prestige is restarting.
  • Page 7: Setting Up Your Computer's Ip Address

    In Windows 2000/NT, click Network and Dial-up Connections. Right-click Local Area Connection and then click Properties. Select Internet Protocol (TCP/IP) (under the General tab in Win XP) and click Properties. Prestige 652H/HW Table 2 Front Panel LED Description The CON/AUX port has a dial-up connection.
  • Page 8: Checking/Updating Your Computer's Ip Address

    In the Command Prompt window, type "ipconfig" and then press ENTER to verify that your computer’s IP address is in the correct range (192.168.1.2 to 192.168.1.254) with subnet mask 255.255.255.0. This is necessary in order to communicate with the Prestige. Prestige 652H/HW...
  • Page 9: Testing The Connection To The Prestige

    Figure 3 Entering Prestige LAN IP Address in Internet Explorer Step 2. An Enter Network Password window displays. Enter the user name (“admin” is the default), password (“1234” is the default) and click OK. Prestige 652H/HW 10ms, Average = Web site address.
  • Page 10 Figure 4 Web Configurator: Password Screen Step 3. You should now see the web configurator SITE MAP screen. Click Wizard Setup to begin a series of screens to configure your Prestige for the first time. Click a link under Advanced Setup to configure advanced Prestige features. Click a link under Maintenance to see Prestige performance statistics, upload firmware and back up, restore or upload a configuration file.
  • Page 11: Common Screen Command Buttons

    The Prestige automatically logs you out if it is left idle for five minutes; 4.2 Common Screen Command Buttons The following table shows common command buttons found on many web configurator screens. Back Click Back to return to the previous screen. Apply Click Apply to save your changes back to the Prestige.
  • Page 12: Figure 8 Internet Connection With Rfc 1483

    Figure 7 Internet Connection with PPPoE From the Network Address Translation drop-down list box, select SUA Only, Full Feature or None. Refer to the Network Address Translation section for more information. Figure 8 Internet Connection with RFC 1483 If your ISP provides the name of your PPPoE service provider, enter it in the Service Name field.
  • Page 13 Figure 9 Internet Connection with ENET ENCAP Figure 10 Internet Connection with PPPoA Step 3. Verify the settings in the screen shown next. To change the LAN information on the Prestige, click Change LAN Configurations. Otherwise click Save Settings to save the configuration and skip to step 5.
  • Page 14 Step 4. If you want to change your Prestige LAN settings, click Change LAN Configuration to display the screen as shown next. Figure 12 Wizard: LAN Configuration Specify the first of the contiguous addresses in the IP address pool in the Client IP Pool Starting Address field. Specify the size or count of the IP address pool in the Size of Client IP Pool field.
  • Page 15: Test Your Internet Connection

    Step 5. The Prestige automatically tests the connection to the computer(s) connected to the LAN ports. To test the connection from the Prestige to the ISP, click Start Diagnose. Otherwise click Return to Main Menu to go back to the Site Map screen. 4.4 Test Your Internet Connection Launch your web browser and navigate to www.zyxel.com.
  • Page 16 The following table describes the fields in this screen. LABEL ESSID (Extended Service Set IDentity) The ESSID is a unique name to identify the Prestige in the wireless LAN. Wireless clients associating to an Access Point (the Prestige) must have the same ESSID.
  • Page 17: Wireless Lan Security Setup

    LABEL RTS/CTS Select this option to enable the RTS (Request To Send)/CTS (Clear To Send) threshold to Threshold minimize collisions. Enter a value between 0 and 2432. The default is 2432. Request To Send is the threshold (number of bytes) for enabling the RTS/CTS handshake. Data with its frame size larger than this value will perform the RTS/CTS handshake.
  • Page 18 Prestige 652H/HW Figure 15 Wireless LAN: MAC Address Filter The following table describes the fields in this screen. Table 4 Wireless LAN: MAC Address Filter LABEL DESCRIPTION Active Select Yes from the drop down list box to enable MAC address filtering.
  • Page 19: Network Address Translation Overview

    Table 4 Wireless LAN: MAC Address Filter LABEL Define the filter action for the list of MAC addresses in the MAC Address table. Select Deny Association to block access to the router, MAC addresses not listed will be allowed Action to access the router Select Allow Association to permit access to the router, MAC addresses not listed will be denied access to the router.
  • Page 20 Step 1. From the main screen click Advanced Setup and then NAT to open the NAT-Mode screen. Select SUA Only. Step 2. Click Edit Details. The following table describes the fields in this screen. Figure 16 NAT: Mode Figure 17 SUA/NAT Server...
  • Page 21: Firewall Overview

    LABEL Start Port Type a port number in this field. To forward only one port, type the port number again in the End Port field. To forward a series of ports, type the start port number here and the end port number in the End Port field.
  • Page 22: Enabling The Firewall

    Prestige 652H/HW Figure 18 Prestige Firewall Application 5.6 Enabling the Firewall From the main screen, click Advanced Setup, Firewall and then Config to open the Configuration screen. Enable (or activate) the firewall by selecting the Enable Firewall check box as seen in the following screen.
  • Page 23: Procedure For Configuring Firewall Rules

    The firewall rules that you configure (summarized below) take priority over the general firewall action settings above. This is your firewall rule number. The ordering of your rules is important as rules are applied in turn. The Move field below allows you to reorder your rules. Prestige 652H/HW Table 6 Summary Screen DESCRIPTION...
  • Page 24 Custom Port. For a comprehensive list of port numbers and services, visit the IANA (Internet Assigned Number Authority) web site. Step 3. Configure the Source Address and Destination Address for the rule. Prestige 652H/HW Table 6 Summary Screen DESCRIPTION...
  • Page 25 Highlight a service from the Available Services box on the left, then click >> to add it to the Selected Services box on the right. To remove a service, highlight it in the Selected Available/ Services box on the right, then click <<. Selected Services Prestige 652H/HW DESCRIPTION...
  • Page 26: Configuring Source And Destination Addresses

    IP addresses (e.g., 192.168.1.10 to 192.169.1.50), a subnet or any IP address? Select an option from the drop down list box Start IP Address Enter the single IP address or the starting IP address in a range here. Prestige 652H/HW DESCRIPTION DESCRIPTION...
  • Page 27: Vpn Overview

    Internet or any insecure network that uses the TCP/IP protocol suite for communication. The following figure provides an example of a VPN application. 5.10 Summary Screen Local and remote IP addresses must be static. Prestige 652H/HW DESCRIPTION Figure 22 VPN Application...
  • Page 28 From the main screen, click Advanced Setup, VPN, and Setup to open the Summary screen. This is a read-only menu of your IPSec rules (tunnels). The following table describes the fields in this screen. LABEL The VPN policy index number Name This field displays the identification name for this VPN policy.
  • Page 29: Configuring Vpn Policies

    LABEL Remote Address This is the IP address(es) of computer(s) on the remote network behind the remote IPSec router. This field displays N/A when the Secure Gateway IP Address field displays 0.0.0.0. In this case only the remote IPSec router can initiate the VPN. The same (static) IP address is displayed twice when the Remote Address Type field in the Configure-IKE (or Manual) screen is configured to Single Address.
  • Page 30 Prestige 652H/HW Figure 24 VPN IKE The following table describes the fields in this screen.
  • Page 31 LABEL Active Select this check box to activate this VPN tunnel. This option determines whether a VPN rule is applied before a packet leaves the firewall. Keep Alive Select either Yes or No from the drop-down list box. Select Yes to have the Prestige automatically re-initiate the SA after the SA lifetime times out, even if there is no traffic.
  • Page 32 LABEL Remote Address Use the drop-down menu to choose Single, Range, or Subnet. Select Single with a Type single IP address. Select Range for a specific range of IP addresses. Select Subnet to specify IP addresses on a network by their subnet mask. IP Address Start When the Address Type field is configured to Single, enter a (static) IP address on the network behind the remote IPSec router.
  • Page 33 LABEL Content When you select IP in the Peer ID Type field, type the IP address of the computer with which you will make the VPN connection or leave the field blank to have the Prestige automatically use the address in the Secure Gateway IP Address field. When you select DNS in the Peer ID Type field, type a domain name (up to 31 characters) by which to identify the remote IPSec router.
  • Page 34: Viewing Sa Monitor

    LABEL Authentication Select SHA1 or MD5 from the drop-down list box. MD5 (Message Digest 5) and SHA1 Algorithm (Secure Hash Algorithm) are hash algorithms used to authenticate packet data. The SHA1 algorithm is generally considered stronger than MD5, but is slower. Select MD5 for minimal security and SHA-1 for maximum security.
  • Page 35 UPnP Allow UPnP to pass through Firewall Prestige 652H/HW Figure 25 UPnP Table 11 UPnP Select this checkbox to activate UPnP. Be aware that anyone could use a UPnP application to open the web configurator's login screen without entering the Prestige's IP address (although you must still enter the password to access the web configurator).
  • Page 36: Troubleshooting

    Make sure you entered the correct user name and password. For wireless clients, check that both the Prestige and wireless client(s) are using the same ESSID, channel and WEP keys (if WEP encryption is activated). Prestige 652H/HW Table 12 Troubleshooting CORRECTIVE ACTION...

Table of Contents