Broadband Router User Guide Dec. 2001 Limitation of Liability Information in this document is subject to change without notice and does not represent a commitment on the part. The material contained herein is supplied without representation or warranty of any kind. Therefore assumes no responsibility and shall have no liability of any kind arising from the supply or use of this document or the material contained herein.
Appendix A: Specifications Appendix B: Glossary Appendix C: Warranty, Copyright, FCC Notice Safety Warnings • About This User Guide The Broadband Router is not intended to be serviced by the user. Do not open the case.
The LEDs on the Front Chapter 2 Installing the Broadband Router Installing the Broadband Router Setting Up a Windows PC for Configuring the Broadband Router Connecting more Devices through a Hub to the Broadband Router Chapter 3 Configuring the Broadband Router...
Page 5
Chapter 5 Chapter 6 Appendix A Broadband Router Specifications Appendix B Glossary Appendix C Warranty, Copyrights, FCC Notice Firewall (IP/IPX Filtering) VPN (Virtual Private Network ) Bridging Managing the Broadband Router System Status Connection Log About System System Upgrade Clear Configuration...
ISDN TA or Analog Modem, and even allows a remote user(a tele-commuter or a traveling sales person) to dial in and access your local network. Data comes into the Broadband Router from the local LAN and then is “routed” to the remote network, and vice versa.
FTP server, or a web server), you can configure the Broadband Router to proxy the service from its own address. This means that the remote user can address the router as if it were the special server and the Broadband Router will re- direct this connection to the appropriate computer on the network.
Figure 1-3 Connecting Two Networks with Broadband Router You can set up the Broadband Router to provide Internet access for everyone on your LAN and create your own private wide area network via V.90 Modem or ISDN TA simultaneously.
For the destination side, when a VPN data session creation is requested, the router will base on the originating IP address to search for a matched profile. Once found, the Broadband Router will use the information in the matched profile to authenticate the incoming "call", after which data transfer can begin.
IP addresses automatically (i.e., from the built-in DHCP server in the Broadband Router). It is important for the Web Server on LAN #1 to have the same IP address all the time (so that users can use the same IP address to access it), it also means the Broadband Router should also be assigned a static IP address.
In order for LAN to LAN communication to work in such configurations, the default private network Broadband Routeraddress (192.168.168.0) for one of the above Broadband Router has to be changed (to 192.168.170.0 in the above example). The traffic between these two networks is secure because data are sent across the telephone network via a direct phone call.
Figure 1-7 Broadband Router Connectors The LEDs on the Front There are 20 LEDs on the front of the Broadband Router that show connection and traffic status of Power, PPPoE, COM, EWAN and LAN ports: Figure 1-8 LEDs LED1 LED2...
2Broadband RouterBroadband Router Installing the Broadband Router Now you should be ready to connect your Broadband Router devices on your LAN . Follow these steps to install the Broadband Router: Step 1 Step 2 Step 3 Figure 2-1 Broadband Router Connectors Connect ADSL/Cable modem to the Broadband Router EWAN port using crossover CAT5 UTP LAN cable.
Installed components Any TCP/IP capable workstation can communicate with the Broadband Connect your PC to one of the Broadband Router Switch ports. If you connect to LAN port 1, you should use a straight LAN cable and set the Uplink switch to the Normal position. or use a crossover LAN cable and set the Uplink switch to Uplink.
Page 15
-DNS Configuration Tab: Disable DNS should be selected -IP Address Tab: Obtain IP address automatically should be selected Step 10 When the Broadband Router connected to the LAN (and powered on), reboot the PC. After the PC is re-booted, you should be ready to configure the Broadband Router.
Connecting more Devices through a Hub to the Broadband Router The Broadband Router provides four LAN ports to allow up to four PCs or Workstations to be connected to it directly. If you want to connect more devices, you can connect an external hub or switch to LAN port 1 using a straight LAN cable if the Uplink switch is set to the Uplink position, or using a cross-over LAN cable if the Uplink switch is set to the Normal position.
Setup Wizard The Wizard will lead you step by step to configure the router for your Internet Access by connecting ADSL/Cable modem. You can change your Internet Access configuration by clicking the Setup Wizard item on the top of left side in ARM(Access Router Manager) menu.
Page 18
3. Enter your ISP information There are 4 ways to connect to your ISP, these 4 methods can be found in the “Obtain IP Addresses” section, they include: (1) Static (2) via DHCP (3) via PPP over Ethernet (4) via PPTP Enter the following information: The file name “df_profile”...
Page 19
Obtain IP Address: via DHCP(will automatically get an IP from your ISP for you), (Optional) Host Name(System Name): The Host Name provided by your system. (Optional) Clone MAC: If you want to assign the router a cloned MAC address, please select enable.
Page 20
When this value is reached, the Broadband Router will disconnect the call. You can change the idle timeout value to anything between 0 to 3600 seconds. But if you select 0, the connection will never be timed out.
This is the window where the actual configuration screens appear. Before any selection of the configuration is made, the window shows a picture of the Broadband Router with cables and peripheral devices that can be connected to it. Message Window Whenever appropriate, the Broadband Router will display system status or error messages in this window.
Now select Internet Access as the Access Type , then press Enter, which will cause the following screen to show. There are 4 ways to obtain an IP Address for your router, including via PPP over Ethernet, via DHCP and “Static”, “PPTP”. Please refer to the configuration in Setup Wizard.
Page 23
Step 2 Select the Backup. Step 3 Key in the following information. Remote Phone Number: the telephone number of your ISP. ISP Account Name: the username of your ISP account. ISP Account Password: the password of your ISP account. You can delete the backup profile by clicking Delete. Step 4 Aftern configuration, please click OK, and then click Save, to save you configuration.
Configuring a Basic Internet Access Profile( via Modem) Except ADSL/Cable modem, you also can access Internet via V.90 or ISDN modem. The following screen show you the interface configuration via Modem. Please select Internet Access, and click Next . The following screen will appear.
Internet Service Provider. Watch the Message Window for any messages. If the test is successful, your users will be ready to access the Internet. If not, the Broadband Router will try to give you enough information to let you know why the connection is not successful.
Deleting or Modifying Internet Access Profiles To delete or modify a Connection Profile: Step 1 Step 2 3-10 Configuration - Connection Profiles: Then the following screen will show: You should highlight New in the list, and then click NEXT, which will lead you through the configuration as above.
(the remote router and the local router). Note that the remote site does not have to have a Broadband Router, and may not be configurable by the local administrator. In either case, make sure the configuration of the Broadband Router matches the requirements of the remote site.
Page 28
Profile Name: the name that you will use to identify this profile. Call Direction: If the remote site will be dialing in only, select Incoming. If the Broadband Router will only be dialing out to the remote site, select Outgoing. Select Both if either side can initiate the connection. The default setting is Both.
Note: When you click Save and Test, the Broadband Router attempts to place a call to the remote LAN and log in. Watch the Message Window for any messages. Advanced Options for Remote Office Profiles Step 1 Key in the following information: STAC Compression: allows outgoing data to be compressed to achieve higher throughput, and compressed incoming data to be recognized.
Service Advertising Protocol. Set as IPX Default Route: if this parameter is set to Yes, then the Broadband Router uses this connection if no other route for an IPX packet can be found in the routing table. Remote IPX Network Number: the IPX network number of a network reachable through this connection.
Page 31
Information about each dial-in user who is allowed access is stored in a “connection profile.” When you select Connection Profiles, the Connection Profile Summary screen appears only if you have existing Connection Profiles The following screen appears. Step 2 Highight the New and click the Next. You may see a screen as the following: Step 3 Select Modem as the interface, then select...
Page 32
Enter the following information: Profile Name: a name that you will use to identify this profile. Call Back: sets the call back option. If selected, the Broadband Router disconnects after authenticating the dial-in user, and dials the remote user’ s call back phone number to reconnect.
Page 33
Dialer IP Address: Please key in the private IP address reserved for the dialer. Router IP Address: Please key in a private IP address for the router, not the default IPaddress. e.g. 192.168.168.1. Enable IPX: select YES to allow IPX routing over a connection using this...
Deleting Dial-in User Profiles To delete a Connection Profile: Step 1 Highlight the entry in the list you want to delete, and click DELETE. 3-18 Select Connection Profiles from the ARM menu. Configuration - Connection Profiles The Connection Profile Summary screen appears.
Internet access is allowed. The Broadband Router will not connect to the Internet outside of the configured times. In order for this feature to be effective, the Broadband Router must be configured for the current local time. To do this, see the section, “Setting the System Time”, above.
To install publicly addressed servers on your network (e.g., Web or ftp servers), you need to apply for an IP address for each server plus one for the LAN port of the Broadband Router. All these public IP addresses have to belong to the same IP network.
Page 37
Broadband Router at remote office locations, you need to make sure that each Broadband Router on each LAN is assigned an address in a unique private IP network . Note: If you use a PC (that obtains an IP address automatically) to change the private IP address (e.g., from the default of 192.168.168.230 to 192.168.167.230)
Page 38
IP address for a secondary DNS. DHCP: you can enable or disable the DHCP server feature provided by the Broadband Router. If you want the Broadband Router to act as a DHCP server and assign private IP addresses to requesting DHCP clients, you need to enable the DHCP (this is the default).
Static DHCP assignments In certain LAN environments, it is desirable for some PCs to be assigned the same address each time it requires a DHCP server. Broadband Router is capable of configuring up to 20 PCs for static assinments. Each PC is to be assigned a static address requires an entry to be configured in the DHCP static Assignment Table.
Please click Add button to add a static entry in the following screen. Name: Enter a convenient display name for this reosurce. IP Address: The IP address to be consistently assigned to this device. MAC Address: The hardware address associated with the Ehternet adapter which is permanently assigned to this machine.
The following screen shows an example of the IPX routing table. When an IPX packet arrives in the Broadband Router, IPX tries to determine if the destination IPX Network Number contained in the packet is within the network...
Page 43
“Default IPX Route” is used. This normally is set to a path where another router can be reached that has additional information about other networks not known to the local router. If no match is found and a default IPX route is not defined, the IPX packet is discarded and will go nowhere.
Page 44
Gateway Interface Name: this specifies the interface through which the destination network can be reached. This is either the LAN or a profile name. Gateway MAC Address: identifies the MAC address of the gateway on the LAN through which the Destination Network Number can be reached.
Page 45
The router will search the SAP table for these entries and respond with the necessary information that the workstation can use to communicate with the desired service.
Step 2 Step 3 Virtual Server/DMZ(De-military Zone) NAT feature makes all hosts behind this product are invisable. You can make some of them accessible by enabling the Virtual Server mapping. A virtual server is defined as a service port, and all requests to this port will be redirected to the PC specified by teh server IP.
Page 47
A Packet Filtering Overview The Broadband Router already provides you with many different ways to ensure the security of your data in your local environment. Packet filtering is a security feature that allows you to selectively pass or throw away data traffic between your local LAN and the wide area network (e.g., the Internet).
Page 48
Otherwise, the exception action is taken, i.e., the packet is discarded or forwarded, the opposite of the default action. The Broadband Router maintains separate filtering tables for IP and IPX traffic. These filters are configured separately. Configuration commands allow you to define:...
Page 49
Therefore packet filtering simply defines sets of rules of what to allow or disallow through a set of parameters highlighted below: For IP, For IPX, Examples of packet filtering requirements are: 4-14 Condition Configuration Protocol Parameter Protocol TCP/UDP/ ICMP/IGMP/ Address Single/Range/ Network/Any Port...
Page 50
using any IPX packet type. “I want to disallow people in the manufacturing department to access the Internet“. The corresponding “translated” packet rule is: All access to the Internet is allowed EXCEPT remote devices with the range of IP addresses in the manufacturing department and any port number which are disallowed to communicate with any IP address/port number over my Internet connection using any IP protocol.
Page 51
Step 4 Step 5 4-16 In case of adding a new selection rule, the following screen shows: Enter the following information: Rule No.: a number used for identification purposes. Rule Name: a name by which you will refer to this rule. Interface: the specific WAN interface to which this new selection rule applies.
Page 52
the corresponding entry in the rule table will be removed. TCP/IP Service Type BootP/DHCP Finger HTTP NetBIOS NNTP SMTP SNMP Sun RPC Telnet TFTP Whois Table 4-1 TCP/IP Port Assignments Configuring IPX Packet Rules To add a new IPX packet rule or to edit an existing one, select IPX Filter from the ARM menu: Configuration - Advanced - IPX Filter Step 1...
Page 53
Step 4 Step 5 4-18 in the rule table followed by clicking the Edit button. In case of adding a new selection rule, the following screen shows: Enter the following information: Rule No.: a number used for identification purposes. Rule Name: a name by which you will refer to this rule. Interface: the specific WAN interface this new selection rule will apply IPX Packet Type: The packet type to which the rule applies.
If you highlighted an existing entry (by selecting the Select to Edit button) and clicked Edit instead, a similar screen will display, with all fields already filled out by you previously. Then you can make changes as necessary. If you highlighted an existing entry and clicked Delete instead, the corresponding entry in the rule table will be removed.
Page 55
In order to set up access to and from a remote site, be sure to configure both ends of the VPN tunnel appropriately (the remote router and the local router). Broadband Router supports for the Layer 2 Tunneling Protocol(L2TP), which was the original open standard for Vitual Private Networking.
Page 56
Tunnel Password, if used). Remote Tunnel Name: the name of the remote network that is dialing in. Remote Tunnel Password: the password that your Broadband Router will expect to see from the remote system. If you do not require tunnel authentication, leave this field blank.
Page 57
Call Direction: the direction of the call in the tunnel. If the remote site will be dialing in, select Incoming Only. If the Broadband Router will be dialing out to the remote site, select Outgoing Only. Select Both if either side can initiate the connection.The default setting is Both.
Page 58
Confirm Encryption key: re-enter the DES encryption key to confirm its correct entry. Note: For security reasons, encryption options only appear if you are connected to the Broadband Router over a local LAN and if encryption is enabled on your system. 4-23...
Managing the Broadband Router System Status This section displays statistics and the status of all interfaces. You can click Monitoring - System Status from the ARM Menu. The following status/statistical information is provided for each interface: Device: lists all interfaces, including both the physical interface (i.e., the LAN port, the EWAN port).
Clear: resets the selected statistics values to zero. Connection Log The Broadband Router provides a connection log that you can use to track the connections in establlished both out of or into your Broadband Router. Connect and disconnect messages can be useful in determining connection costs, Trigger messages are useful in determining the particular device and application that triggered the connection.
About System You can check the information of the Broadband Router by clicking About System from the menu. Monitoiring - About System WAN IP: It indicates the WAN IP address of your Boradband Router. Submask: The submask of the WAN IP address.
Page 62
Please refer to the Command Line Interface Manual in the CD for the detail procedure. 2.What if you crash your router’ s firmware, you can download the “Recovery” firmware from your CD to recover your router. Though the CD’ s firmware maybe not updatest, you can get the updatest one from distributor’...
Step 2 Reset System If your router is not operating correctly, upi can choose this option to display the Reset System screen as follows. Step 1 The following screen displays: Step 2 Note: therefore may disrupt current data traffic. Unless you manually save the configuration.
HyperTerminal) to the Broadband Router console port. The default port settings are 19200, 8, None, 1, None. Turn off the Broadband Router, then turn it on again. In the console window, you’ll see the message “Loading firmware...”.
Page 65
Control-C. Step 4 The Broadband Router resets. When this is complete, the Broadband Router will return all settings to the factory default. The password will once again be “password”. Note: Keep in mind that anyone who can physically access the router can...
Messages This chapter lists messages you may see in the ARM message window. System Messages ****** has to be an integer [0123456789] The entered field (******) is not a valid integer. ****** has to be valid IP address The entered field (******) is an invalid IP address format or an invalid IP address value.
Page 67
The IP address obtained from the EWAN Internet connection was in conflict with an IP address subnet already defined for an interface of the router. Either change the IP address subnet for the interface, or contact your ISP for a different address assignment "Call operation in progress.
Page 68
"The confirmed encryption key doesn't match" The encryption key entered in the "Confirm Encryption Key" field is not the same as the key in "Encryption key" field. "Invalid DHCP static IP address" An Invalid static DHCP IP address has been detected. This is not permitted. Please select another address or modify the original entry.
Page 69
The firmware file entered is either missing or invalid. "External logon attempt rejected" Another browser elsewhere in the network has attempted to open the router’ s HTTP page. This attempt was rejected. Only one HTTTP configuration session allowed at a given time.
Page 70
A duplicate filter name has been detected. A filter name must be unique. "General read failure" An error has occurred while communicating with the router. Please use the “Reload” or “Refresh” button to load this page again. "The Internet access time has been configured successfully"...
Page 71
Current DHCP entry can’t be accessed. "Invalid Filter IP Address" This message is displayed when an IP address with a syntax error is entered. An IP address should be a set of four three-digit numbers. Each three-digit number should be between 0 and 255, inclusive. For example, a correct IP address is 192.168.100.2. "Invalid Entry: Private Port"...
Page 72
The IP address entered in the static DHCP configuration form is invalid. Please check all parameters entered. "Remote Tunnel Name is required" Each tunnel configuration requires a remote system name for authentication. If such a name is not provided or is invalid, this message will be displayed. "IP Address is invalid"...
Page 73
The adminstrator is attempting to add a second profile over the EWAN port "Only 8 rules allowed" The maximum number of Filtering rules, system-wide, has been exceeded. To add an additional rule, one must be deleted. Parameter changes applied Changed parameters have been applied to the router configuration.
Page 74
"Phone number or data service type seems to be incorrect" After an "Apply and Test" button is pressed, the router detected a problem with either the remote phone number or the data service type configured. "Phone number up to 15, limit characters to 123456789,;-[]!*#"...
Page 75
A duplicate user name is entered. Dial-In user names must be unique. "Resetting system, please wait..." The message is displayed when the router is in the process of resetting. You can logon to the router after about 30 seconds. "Save configuration failed. Please try again"...
Page 76
The time has been configured successfully. "The Gateway IP Address has been set as the IP Default Route" The Internet access profile has been configured in the router and the configured ISP Gateway IP Addrress is now set as the IP Default Route "This interface has been configured to support a Remote Office...
Page 77
23 to issue a CLI command to do this. If port 23 has been re-assigned, the administrator must re-assign the HTTP port using the CLI through a new Telnet router port (if available), from a LAN-attached device, or through a non- Internet connection.
Page 78
port (if available), from a LAN-attached device, or through a non-Internet connection. Note: Address Translation only applies to Internet connections 6-13...
• • • • • • Features Internet Access, Multimedia Applications and Virtual Server • • • • • • Protocol Support • • • • • • • Management • • • • • • • • • Internet Access via Cable or xDSL Accessing Servers from the Public Network Supporting Inter-office Communication Supporting Dial-In Access to your Network...
Page 80
Monitoring • • • Security • • • • • RAS and WAN Port Redundancy • • • Physical Specification • • • • Hardware Configuration • • • • • • Runtime traffic monitoring Connection log Syslog Natural firewall, private IP addresses not accessible from the Internet IP Packet filtering (IP address/ Protocol/Port number) IPX Packet filtering( Network number/Node number/Socket number) PPP PAP/CHAP/MS-CHAP authentication...
Page 81
Glossary This section provides some common networking terms you may find in this user guide. ARP, ARP Table To send an IP packet to another device on the same LAN, the source device needs to know the MAC address of the destination device first. If such information is already maintained in the ARP (Address Resolution Protocol) table, the corresponding MAC address will be used to transmit the data packet.
The default route is a special IP route in the IP routing table. When a packet is received by the router, if destination network cannot be found in its routing table, the packet will be forwarded over the default route to the next-hop IP router. Such a router often has a more complete routing table, and therefore is “more...
Page 83
DNS IP address, the secondary DNS IP address, the default gateway IP address, WINS Server addresses, NetBIOS Node Type, etc. Edge Router A router that resides at the edge of a network. It is like a gateway that is used to communicate with the outside network. Encryption A method for scrambling data which inhibits unauthorized snooping.
Page 84
Internet Access and ISP Accounts To access the Internet, first you need to have a device (such as a router or a modem) that you can use to connect to the Internet using a dial-up services such as modem or ISDN or a fixed connection service such as a leased line or a frame relay network.
Page 85
When two physically disjoint offices of the same company need to communicate and share data resources with each other, they can use one router on each side and perform LAN to LAN communication - to allow users on one LAN to access resources on the other.
Page 86
Warranty, Copyrights, FCC Notice Warranty Broadband Router Products are provided with a limited one year Warranty. Details of the warranty and return process are explained in the Warranty Policy below. Warranty service is subject to the terms and conditions of company Warranty Policy.
without charge to the customer. If, in the company opinion, it is impractical for any reason to repair or replace the Product, company may at its option refund or pay an amount equal to the lesser of (1) the purchase price paid for the product or (2) the then effective company estimated purchase price for the Product.
Need help?
Do you have a question about the 516204 and is the answer not in the manual?
Questions and answers