... 8 VERVIEW ... 8 ROCEDURE 1. Configuring the Router for your LAN ... 8 2. Installing the Router in your LAN ... 12 3. Configuring the Router for Internet Access ... 13 4. Enable Dedicated DMZ Port ... 15 5.
High-Performance multi ADSL Modem Support The Multi-WAN VPN Router has four (4) WAN ports, allowing the connection of up to four (4) Broadband modems at the same time. This can provide a greater increase in bandwidth than is allowed by a single modem.
Page 5
IP address allocated by your ISP, a separate "DMZ" PC can be specified. So if your ISP has given you multiple IP addresses, you can have multiple “DMZ” PCs. With the Multi-WAN VPN Router, each “DMZ” PC has unrestricted 2-way Internet access, providing the ability to run programs that are otherwise normally incompatible with NAT routers.
DHCP Server Support Dynamic Host Configuration Protocol provides a dynamic IP address to PCs and other devices upon request. The Multi-WAN VPN Router can act as a DHCP Server for devices on your local LAN. Multi Segment LAN Support LANs comprising of one or more segments or additional IPs are supported via the Multi-WAN VPN Router's built-in static routing table.
Package Contents The following items are included in the Multi-WAN VPN Router package: Multi-WAN VPN Router Unit Power Cord Quick Installation Guide CD with Manual If any of the above items are damaged or missing, please contact your dealer immediately.
Page 8
LAN cable to connect to a normal port on another hub. Reset Button When pressed and released, the Multi-WAN VPN Router will reboot (restart) within 1 second. It will reset to default when pushed and held for more than 3 seconds.
100 ~ 240VAC Connects to AC100~240V / 50~60Hz with supplied AC power cord. Default Settings When the Multi-WAN VPN Router has finished booting, all configuration settings will be set to the factory defaults, including: IP Address set to its default value of 192.168.1.1, with a Network Mask of 255.255.255.0 ...
Page 10
Enter the name of the firmware upgrade file located on your PC, or click the "Browse" button to locate the file. Enter the LAN IP address of the Multi-WAN VPN Router in the "Server IP" field. Click "Upgrade Firmware" to send the file to the Multi-WAN VPN Router.
Overview Basic Setup of your Multi-WAN VPN Router involves the following steps: 1. Attach the Multi-WAN VPN Router to a PC using any LAN port (5 to14) and configure it for your LAN. 2. Install your Multi-WAN VPN Router in your LAN and connect the Broadband Modem(s).
Page 12
7. Enter admin for the "User Name" and leave the "Password" field blank. The "User Name" is always set as admin For security, it is highly recommended that you set a password. You may do this using the Admin Setup screen.
Page 13
10. If your LAN already has a DHCP Server and you wish to continue using it, the following configuration is required: The DHCP Server function in the Multi-WAN VPN Router must be disabled. You will find this setting in the LAN & DHCP screen.
Page 14
12. Save your data, then go to Step 2, Installing the Multi-WAN VPN Router in your LAN. IP Address – IP address for the Multi-WAN VPN Router, as seen from the Local LAN. Use the default value unless the address is already in use or your LAN is using a different IP Address range.
Use the cable supplied with your DSL/Cable modem. If no cable was supplied, use a standard cable. 3. Use standard LAN cables to connect PCs to the LAN ports on the Multi-WAN VPN Router. Both 10BaseT and 100BaseT connections can be used simultaneously.
3. Configuring the Router for Internet Access Select Primary Setup from the menu. You will see a screen like in the example below. Configure each WAN one by one through the Interface column pull-down menu. For any of the following situations, refer to Chapter 3: Advanced Port Setup, for any further configuration which may be required: ...
Page 17
Settings – Primary Setup Interface – A pull down menu for each WAN port that you are going to Connection Mode connect to the Internet. Connect Mode – Enable – Select this if you have connected a broadband modem to this port.
Select DMZ Setting from the Basic Configuration menu. You will see a screen like in the example below. Set Port15 or Port16 as dedicated DMZ port by select corresponding WAN Ports Note: Select LAN for Port15 and Port16, these ports will be the same as other LAN ports on the Router Page 15...
If using fixed IP addresses on your LAN, or if you wish to check your TCP/IP settings, refer to Appendix B – Windows TCP/IP Setup. Internet Access To configure your PCs to use the Multi-WAN VPN Router for Internet access, follow this procedure: For Windows 9x/2000 1. Select Start Menu - Settings - Control Panel - Internet Options.
Page 20
Setup is now completed. Accessing AOL To access AOL (America On Line) through the Multi-WAN VPN Router, the AOL for Windows software must be configured to use TCP/IP network access rather than a dial-up connection. The configuration process is as follows: ...
Ensure your DNS settings are correct. Linux Clients To access the Internet via the Multi-WAN VPN Router using Linux, it is only necessary to set the Multi-WAN VPN Router as the "Gateway" and ensure your Name Server settings are correct.
3: Advanced Port Overview Port Options contains some options which can be set on any WAN port. For most situations, the default values are satisfactory. Load Balance is only functional if you are using multiple WAN ports. It allows you to determine the proportion of WAN traffic sent through each port.
Page 23
60 seconds. Alive Indicator – This is the IP address used to check if the WAN connection is operating. The Multi-WAN VPN Router will contact this system to check if the WAN connection is working or not. You may change this address if you wish.
Load Balance This screen is only operational if using Internet connections on multiple WAN ports Figure 3-2: Load Balance Only functional when using two (2) or more WAN ports - these settings determine the proportion of traffic sent over each port. Page 21...
Page 25
Settings – Load Balance Enable – This enables your Load Balance setting options and must be Load Balance Configuration checked for other settings on this screen to be effective. Balance Type – You can select the Balance types based on: ...
Advanced PPPoE The Advanced PPPoE screen is required in order to use multiple PPPoE sessions on the same WAN port. It can also be used to manually connect or disconnect a PPPoE session. Figure 3-3: Advanced PPPoE Page 23...
Page 27
Settings – Advanced PPPoE WAN Port – Selected WAN port only using PPPoE connection Select WAN Port & Session PPPoE Session – ISPs can usually provide multiple floating real IPs for PPPoE. Each WAN port can have up to eight (8) PPPoE sessions, each with a different IP address if your WAN port is using PPPoE connectivity.
Advanced PPTP This Advanced PPTP screen is only useful if using the PPTP connection method. Figure 3-4: Advanced PPTP Page 25...
Page 29
Settings – Advanced PPTP WAN Port Select the desired WAN port (click desired WAN on Connection Status). The data of the selected port will then be displayed in the WAN IP Account section. PPTP MTU – Maximum transfer unit for PPTP. The default value is 1460 ...
4: Advanced Setup Overview The following features are provided in Advanced Setup: Host IP Routing Virtual Server Special Application Dynamic DNS Multi DMZ UPnP Setup NAT Setup Advanced Feature This chapter contains details on the configuration and use of each of these features. Page 27...
Host IP This feature is used in the following situations: You have Multi-Session PPPoE and wish to bind each session to a particular PC on your LAN. You wish to use the Access Filter feature. This requires that each PC is identified by using the Host IP screen.
Page 32
Update – After making the desired changes, use this to update the selected entry Reset – Reverse any changes you have made since loading the data from the Multi-WAN VPN Router. Host & Group This table shows the current bindings. List...
Routing This section is only relevant if your LAN has other Routers or Gateways. If you don't have other Routers or Gateways on your LAN, you can ignore the Static Routing page completely. If your LAN has other Gateways and Routers, you must configure the Static Routing screen as described below.
Configuring Other Routers on your LAN All traffic for devices not on the local LAN must be forwarded to the Multi-WAN VPN Router so that it can be forwarded to the Internet. This is done by configuring other Routers to use the Multi-WAN VPN Router as the Default Route or Default Gateway, as illustrated by the example below.
Page 35
For the Multi-WAN VPN Router Gateway's Routing Table For the LAN shown above, with 2 routers and 3 LAN segments - the Multi-WAN VPN Router requires 2 entries as follows: Entry 1 (Segment 1) Destination IP Address Network Mask Gateway IP Address...
Note that, in this illustration, both Internet users are connecting to the same IP Address but using different protocols. Connecting to the Virtual Server Once configured, anyone on the Internet can connect to your Virtual Servers. They must use the Multi-WAN VPN Router's Internet IP Address (the IP Address allocated by your ISP). e.g. http://205.20.45.34 ftp://205.20.45.34 ...
Page 37
http://my_domain_name.dyndns.org ftp://my_domain_name.dyndns.org This screen allows you to define your own Server types. Figure 4-5: Virtual Server Page 34...
Page 38
Settings – Virtual Server Enable – The enable checkbox is to Enable or Disable each Virtual Virtual Server Configuration server as required. Server Name – Enter a suitable name for this server. (By default, 12 well-known virtual servers have been listed on the Custom Virtual Server List) ...
Multi-WAN VPN Router. In this case, you can define the application as a "Special Application" in order to make it work. Note that the terms "Incoming" and "Outgoing" on this screen refer to traffic from the client (PC) viewpoint Settings –...
Page 40
Add – Create a new Special Application entry. Buttons Delete – Delete the selected entry. Update – Save any changes you have made to the current entry. Cancel – Cancel any changes you have made since the last saved operation.
This also solves the problem of having a dynamic IP address. With a dynamic IP address, your IP address may change each time you connect to your ISP, making it difficult to connect to you. You must register for the Dynamic DNS service. The Multi-WAN VPN Router supports 3 types of service providers: ...
Page 42
Settings – Dynamic DNS Dynamic DNS This pull-down menu can Enable/Disable the Dynamic DNS feature and select Service the required service provider. Disable – Dynamic DNS is not used. TZO – Select this to use the TZO service (www.tzo.com). You must configure the TZO section of this screen.
Multi DMZ This feature allows each WAN port IP address to be associated with one (1) computer on your LAN. All outgoing traffic from that PC will be associated with that WAN port IP address. Any traffic sent to that IP address will be forwarded to the specified PC, allowing unrestricted 2-way communication between the "DMZ PC"...
UPnP Setup With the UPnP (Universal Plug & Play) function, you can easily setup and configure an entire network as well as enable detection and control of networked devices and services. Settings – UPnP Setup If set to Enable UPnP, this device will register on the local network. You will UPnP Option find that there is an icon showing on the My Network Places in Window XP.
NAT Setup NAT (Network Address Translation) is the technology which allows one (1) WAN (Internet) IP address to be used by multiple LAN users. Figure 4-10: NAT Setup Page 42...
Page 46
NAT Routing – You can enable or disable NAT through the check box. If Configuration you disable the NAT checkbox, it will act as a bridge or Static Router. Most features will be unavailable. TCP Timeout – Enter the desired value to use on each WAN port. The default is 300 ...
Advanced Feature External Filters Configuration – These settings determine whether the Multi-WAN VPN Router should respond to ICMP (ping) requests received from the WAN port or not. Interface Binding – Use these settings to ensure that certain traffic is sent by a particular WAN port and thereby a particular ISP account.
Page 48
Settings – Advanced Feature Block Selected ICMP Types – These settings determine whether or not External Filters Configuration this device should respond to ICMP requests received from the WAN port. If checked, the selected packet types are blocked. Otherwise, the packets are accepted.
Page 49
Protocol & Port Protocol and Port Binding Binding Use these settings if you wish to ensure that particular traffic is sent by a specific WAN port, and thereby a particular ISP account. Enable - Enable or disable each item as required. ...
5: Security Management Overview Block URL – Ability to block a specific website by configuring IP address, URL or Keywords. Access Filter – Ability to block all Internet access, a known port or user defined ports by group access.
Page 51
Settings – Block URL Access Group This allows you to have different blocking rules for different Groups of PCs. All PCs (users) are in the Default Group unless moved to another specified group on the Host IP screen. If you want the same restrictions to apply to everyone, select Default for the Group.
Access Filter The network Administrator can use the Access Filter to gain fine control over the Internet access and applications available to LAN users. Five (5) user groups are available and each group can have different access rights assigned to them.
Page 53
Settings – Access Filter Access Group This allows you have different access rights for different Groups of PCs. Filter Setting Select the desired option for this Group: ICMP Filters If you enable ICMP Filter that means it will block ICMP request packet types specified by users from local host to remote side.
Session Limit This new feature allows to drop the new sessions from both WAN and LAN side, if the number of new sessions exceeds the maximum value set by you in the Sampling Time field. Settings – Session Limit Sampling Time The time interval specified by you for new sessions.
SysFilter Exception System Filter Exception - This will reject every packet with an unrecognized port to block port scan programs from hackers. This, however, also incurs problems in some situations where servers (e.g. SMTP server port 113) or WAN clients need to send a response packet to verify the activity of their communication peers.
We call this by creating a “tunnel”. A VPN tunnel connects the two PCs or networks Note: The VPN Router uses industry standard IPSec encryption. However, due to the variations in how manufactures interpret these standards, many VPN products are not interoperable.
Page 57
Settings – IKE Global Setup Global List (Phase 1) The list will only show the approximate information of all Global Settings on each WAN port. You can modify it by clicking on a selected row. Global Parameters ...
Page 58
Planning the VPN When planning your VPN, you must make the following choices first: 1. If the remote site is a LAN network, the two end-point networks must have different LAN IP address ranges. If the remote end-point is a single PC running a VPN client, its destination address must be a single IP address with subnet mask of 255.255.255.255 2.
IPSec Policy Setup The VPN Policy Setup is to define the VPN phase 2 policy including the encryption and authentication method. Once you have finished the configuration, you can press the “Connect” button to make the VPN connection. You can also press the “Set Options” button for advanced setting details of VPN policy.
Page 60
Session – If you are using a multi-session PPPoE connection, you can select which PPPoE session will create a VPN tunnel between two sites. Local Identity Type – You can select how the router will identify itself to the destination VPN site. There are three options to select from: ...
Page 61
SPI and no two tunnels share the same SPI. Note that the Inbound SPI must match the other router‟s outbound SPI. AutoKey (IKE) – There are two types of operation modes which can be used in Phase 1 Negotiation: Main mode –...
Page 62
Security Association The list will display the details of all Policy Setup configuration data List that you have entered. Modification can be made by clicking on a selected row. Action Connect – Manually trigger the tunnel negotiation with selected IKE/IPSec proposals Disconnect –Manually shut down the established tunnel and clear all the SA in use, inform peer by sending Delete payload.
Page 63
Settings – IPSec Policy Options Dead Peer Detection Feature Figure 6-3: IPSec Policy Options Dead Peer Detection (DPD) – If set to Enable, a device will periodically send HELLO/ACK messages to check if the tunnel is alive when both peers of a VPN tunnel provide DPD mechanism. Once a dead peer is detected, a device will end the connection so it can be re-established.
Page 64
UDP Checksum – All UDP packets contain a UDP checksum, a calculated value that ensures UDP packets are free of transmission errors. The device (Multi-WAN router) does not require use of UDP checksum for NAT-T. Therefore, the checkbox keep it always “Disable”.
Page 65
Options NetBIOS Broadcast – This option is used to forward NetBIOS packets across the Internet from remote side to local side and vice versa. When enabled, the remote side computer can be reached by a host name.
Mesh Group Setup The Multi-WAN VPN Link Balancer not only provides VPN failover and backup but is also capable of offering VPN load balance. If you have setup IPSec policy on the “IPSec Policy Setup” web page, then you don‟t have to enter IPSec policy setup again here.
Page 67
Settings –Mesh Group Configuration Aggregation Group This will display all the VPN connections that are using for VPN load balancing. You should enable the check box before you make a VPN load balance connection. Delete Button – This button can delete one or all IPSec Policies. ...
VPN Log You can monitor the VPN status through the VPN Logs web page. The log level (priority) can be chosen from the VPN IKE Global Settings web page. Data – VPN Logs Message Status Undefined Messages ...
7: QoS Configuration Overview The Multi-WAN VPN Router incorporates a QoS (Quality of Service) utility to provide high quality network support service. Because it classifies outgoing packets based on policies defined by users, real-time applications should respond or perform better.
Policy Configuration Setting the QoS policy can allocate Inbound/Outbound bandwidth (based on your configuration) to pass through this device. You can define some policies which classify received packets based on Local/Remote IP, MAC, port and protocol type. This feature is useful when the WAN link is very busy or congested or when using special applications that need real time services such as Internet phone, video conference...etc.
Page 71
Setup Bandwidth Control QoS Example The following is teaching you how to setup bandwidth control QoS. ( A) 51200 k bit/Sec is the maximum bandwidth that device CPU can handle. 1. First, you have to “Enable” QoS, once you have enabled it. It will start QoS mechanisms. 2.
Page 72
1. Policy Name: Give a name of your bandwidth control policy. 2. Local Address: It is you LAN side IP address. ( by default 0.0.0.0 To 0.0.0.0 mean all local LAN IP address) If you choose MAC ( address. 3. Protocol type and local/remote port: Port and Protocol Type define all packets for special applications.
8: Management Assistant Overview The following advanced features are Admin. Setup Email Alert SNMP Syslog Upgrade Firmware This chapter contains details of the configuration and use of each of these features. provided: Page 70...
Admin. Setup Remote Access Configuration – This feature allows you to manage the Multi-WAN VPN Router via the Internet. You can restrict access to a specified IP address or address range. Administrator Password – This feature allows you to assign a password for remote upgrade and access to the Multi-WAN VPN Router.
Page 75
3. In the "Address" bar, enter "HTTP://" followed by the Internet IP Address of the Multi-WAN VPN Router. If the port number is not 80, then the port number is also required. (After the IP Address, enter ":" followed by the port number.) e.g.
Email Alert This feature will send a warning Email to the system administrator when any WAN port is disconnected, has received excessive ping flooding, exceeded session limitation, etc. Settings – Email Alert Link Down – If set to Enable, it will send a warning email to alert the Global Setting: administrator when any WAN port is disconnected.
SNMP This section is only useful if you have SNMP (Simple Network Management Protocol) software on your PC. If you have SNMP software, you can use a standard MIB II file with the Multi-WAN VPN Router. Settings – SNMP ...
Syslog This feature can send the real time system information to a web page or to specified PCs. Syslog Configuration – Syslog Configuration allows you to select whether to send the system information to another machine or not. Up to three machines can be chosen to send the system log to. Message Status –...
Page 79
Settings – Syslog Sending Out – Set to “Enable”, if you want to send system log messages Syslog Delivery to other machines (PCs). Keep Sent Message – If set to Enable, it means you want to keep sent messages;...
Upgrade Firmware The Upgrade Firmware Screen allows you to upgrade the firmware or backup the system configuration. You can backup your system configuration by pressing the Save System Configuration “Save” button. This will save the system configuration for future use. ...
9: Network Info Operation Once the Multi-WAN VPN Router and the PCs are configured, operation is automatic. However, there are some situations where additional Internet configuration may be required. Refer to Chapter 4 - Advanced Setup for further details. System Status Use the System Status link on the main menu to view this screen.
Page 82
WAN IP address is allocated to you. Connect/Disconnect – Used for dial-up/connection of PPPoE or PPTP. IP Address – The IP address of the Multi-WAN VPN Router, as seen from the Internet. This IP Address is allocated by the ISP (Internet Service Provider). ...
The DCHP server function will be enabled. These changes may mean that the current connection is invalid and you will have to re-connect to the Multi-WAN VPN Router using its default IP address (192.168.1.1). Figure 9-2: Restore Factory Defaults Page 80...
WAN Status Use the WAN Status link on the main menu to view this screen. Data – WAN Status This section displays data for each WAN port. Statistics Status – This will display either Connected or Disconnected. Default Loading Share - The default traffic loading on each WAN port. ...
If using the default Multi-WAN VPN Router settings and the default Windows 95/98/ME/2000 TCP/IP settings, no changes need to be made. By default, the Multi-WAN VPN Router will act as a DHCP Server, automatically providing a suitable IP Address (and related information) to each PC when the PC boots. ...
Page 87
DNS address or addresses provided by your ISP, then click OK. On the Gateway tab, enter the Multi-WAN VPN Router's IP address in the New gateway field and click Add, as shown below. (Your LAN administrator can advise you of the IP Address assigned to the Multi-WAN VPN Router.)
On the DNS Configuration tab, ensure Enable DNS is selected. If the DNS Server Search Order list is empty, enter the DNS address provided by your ISP in the field beside the Add button, then click Add. Checking TCP/IP Settings - Windows 2000: 1.
If your PC is already configured, check with your network administrator before making the following changes: Enter the Multi-WAN VPN Router's IP address in the Default gateway field and click OK. (Your LAN administrator can advise you of the IP Address assigned to the Multi-WAN VPN Router.) ...
Page 90
Figure B-7: Network Configuration (Windows XP) 3. Select the TCP/IP protocol for your network card. 4. Click on the Properties button. You should then see a screen like the following: Figure B-8: TCP/IP Properties (Windows XP) Page 87...
Page 91
If your PC is already configured, check with your network administrator before making the following changes. Enter the Multi-WAN VPN Router's IP address in the Default gateway field and click OK. (Your LAN administrator can advise you of the IP Address assigned to the Multi-WAN VPN Router.) ...
This chapter covers some common problems that may be encountered while using the Multi-WAN VPN Router and some possible solutions to them. If you follow the suggested steps and the Multi- WAN VPN Router still does not function properly, contact your dealer for further advice.
If the PCs are configured correctly, but still not working, check the Multi-WAN VPN Router. Ensure that it is connected and ON. Connect to it and check its settings. (If you can't connect to it, check the LAN and power connections.) ...
FCC Statement This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions: This device may not cause harmful interference. This device must accept any interference received, including interference that may cause undesired operation. Tested to comply with FCC Standards for Home or Office use.
Need help?
Do you have a question about the FBR-4000 and is the answer not in the manual?
Questions and answers