English Manual Table of Content INTRODUCTION TO YOUR ROUTER .................... 3 FEATURES ............................3 IMPORTANT NOTE FOR USING THIS ROUTER ................6 PACKAGE CONTENTS ........................7 THE FRONT LEDS ..........................8 THE REAR PORTS ..........................9 CABLING ............................10 CONNECTING YOUR ROUTER ....................12 FACTORY DEFAULT SETTINGS ....................
English Manual Chapter 1: Introduction Introduction to your Router Welcome to the 3G/ADSL2+ (802.11g) (VPN) Firewall Router. The router is an “all-in-one” ADSL router, combining an ADSL modem, ADSL router and Ethernet network switch functionalities, providing everything you need to get the machines on your network connected to the Internet over your ADSL broadband connection.
Page 4
English Manual Multi-Protocol to Establish a Connection It supports PPPoA (RFC 2364 - PPP over ATM Adaptation Layer 5), RFC 1483 encapsulation over ATM (bridged or routed), PPP over Ethernet (RFC 2516), and IPoA (RFC1577) to establish a connection with the ISP. The product also supports VC-based and LLC-based multiplexing. Quick Installation Wizard It supports a WEB GUI page to install this device quickly.
Page 5
English Manual Rich Packet Filtering Not only filters the packet based on IP address, but also based on Port numbers. It will filter packets from and to the Internet, and also provides a higher level of security control. Dynamic Host Configuration Protocol (DHCP) Client and Server In the WAN site, the DHCP client can get an IP address from the Internet Service Provider (ISP) automatically.
English Manual The Front LEDs Meaning Lit when power turns ON. Lit in red means the system is failed. To restart Power the device or connect service provider for support. Lit when one of LAN ports connected to an Ethernet device. LAN Port The speed of transmission hits 100Mbps appears Green;...
English Manual The Rear Ports The Ethernet Port # 4 can be used as a console port. You need a special console tool which already includes in the package to connect with LAN port 4 and PC’s RS-232 port (9-pin serial port). Port Meaning Antenna...
English Manual Cabeling One of the most common causes of problems is the bad cabling or ADSL line(s). Make sure that all connected devices are turned on. On the front of the product is a bank of LEDs. Verify that the LAN Link and ADSL line LEDs are lit.
Page 11
English Manual Chapter 3: Basic Installation The router can be configured with your web browser. A web browser is included as a standard application in the following operating systems: Windows 7, Linux, Mac OS, Windows 98/NT/2000/XP/Me, etc. The product provides an easy and user-friendly interface for configuration. Please check your PC’s network components.
English Manual Connecting Your Router 1. Connect this router to a LAN (Local Area Network) and the ADSL/telephone (ADSL) network. 2. Power on the device. 3. Make sure the Power is lit steadily and that the LAN LED is lit. 4.
Page 13
English Manual Configuring PCs in Windows 7 1. Go to Start. Click on Control Panel. Then click on Network and Internet. 2. When the Network and Sharing Center window pops up, select and click on Change adapter settings on the left window panel.
Page 14
English Manual 4. Select Internet Protocol Version 4 (TCP/IPv4) then click Properties. 5. In the TCP/IPv4 properties window, select the Obtain an IP address automatically and Obtain DNS Server address automatically radio buttons. Then click OK to exit the setting. 6.
Page 15
English Manual Configuring PCs in Windows Vista 1. Go to Start. Click on Network. 2. Then click on Network and Sharing Center at the top bar 3. When the Network and Sharing Center window pops up, select and click on Manage network connections on the left window column.
Page 16
English Manual 5. Select Internet Protocol Version 4 (TCP/IPv4) then click Properties. 6. In the TCP/IPv4 properties window, select the Obtain an IP address automatically and Obtain DNS Server address automatically radio buttons. Then click OK to exit the setting. 7.
Page 17
English Manual Configuring PCs in Windows XP Go to Start / Control Panel (in Classic View). In the Control Panel, double-click Network Connections. Double-click Local Area Connection. (See Figure 3.1) Figure 3.1: LAN Area Connection In the LAN Area Connection Status window, click Properties.
Page 18
English Manual Configuring PCs in Windows 2000 Go to Start / Settings / Control Panel. In the Control Panel, double-click Network and Dial-up Connections. Double-click Local Area (“LAN”) Connection. (See Figure 3.5) Figure 3.5: LAN Area Connection In the LAN Area Connection Status window, click Properties.
Page 19
English Manual Configuring PC in Windows 95/98/ME Go to Start / Settings / Control Panel. In the Control Panel, double-click Network and choose the Configuration tab. Select TCP / IP -> NE2000 Compatible, or the name of any Network Interface Card (NIC) in your PC. (See Figure 3.9) Click Properties.
Page 20
English Manual Configuring PC in Windows NT4.0 Go to Start / Settings / Control Panel. In the Control Panel, double-click Network and choose the Protocols tab. Select TCP/IP Protocol and click Properties. (See Figure 3.12) Figure 3.12: TCP / IP Select the Obtain an IP address from a DHCP server radio button and click OK.
English Manual Factory Default Settings Before configuring your, you need to know the following default settings. Web Interface (Username and Password) Username: admin Password: admin The default username and password are “admin” and “admin” respectively. If you ever forget the username/password to login to the router, you may press the RESET button up to 6 seconds to restore the factory default settings.
English Manual Information from your ISP Before configuring this device, you have to check with your ISP (Internet Service Provider) to find out what kind of service is provided such as DHCP (Obtain an IP Address Automatically, Static IP (Fixed IP Address) and PPPoE.
English Manual Configuring with your Web Browser Open your web browser, enter the IP address of your router, which by default is 192.168.1.254, and click “Go”, a user name and password window prompt will appear. The default username and password are “admin” and “admin” respectively. (See Figure 3.14) Figure 3.14: User name &...
Page 24
English Manual Chapter 4: Configuration At the configuration homepage, the left navigation pane where bookmarks are provided links you directly to the desired setup page, including: Status ADSL Status 3G Status EWAN Status iBurst Status ARP Table DHCP Table Routing Table NAT Sessions UPnP Portmap PPTP Status...
English Manual Status ADSL Status This section displays the ADSL overall status, which shows a number of helpful information such as DSP firmware version. Chapter 4: Configuration...
English Manual 3G Status This section displays the 3G Card’s overall status, which shows you a number of helpful information such as the current signal strength and statistics on current and total bytes transferred and received. Status: The current status of the 3G card. Signal Strength: The signal strength bar indicates current 3G signal strength.
English Manual EWAN Status Besides using 3G/ADSL to get connected to the Internet, the router offers its Ethernet port 1 as a WAN port to be used to connect to Cable Modems and fiber optic lines. This alternative, yet faster method to connect to the internet will provide users more flexibility to get online.
English Manual iBurst Status Displays additional information of the 3G status when iBurst function is enabled in the 3G configuration such as its signal strength, card name, connection status and port class Ethernet. Card Name: The name of the card. Signal Strength: The signal strength bar indicates the current signal strength.
English Manual ARP Table This section displays the router’s ARP (Address Resolution Protocol) Table, which shows the mapping of Internet (IP) addresses to Ethernet (MAC) addresses. This is useful as a quick way of determining the MAC address of the network interface of your PCs to use with the router’s Firewall – MAC Address Filter function.
English Manual DHCP Table Leased: The DHCP assigned IP addresses information. Expired: The expired IP addresses information. Permanent: The fixed host mapping information Leased Table IP Address: The IP address that assigned to client. MAC Address: The MAC address of client. Client Host Name: The Host Name (Computer Name) of client.
English Manual Routing Table Routing Table Valid: It indicates a successful routing status. Destination: The IP address of the destination network. Netmask: The destination Netmask address. Gateway/Interface: The IP address of the gateway or existing interface that this route will use. Cost: The number of hops counted as the cost of the route.
English Manual NAT Sessions This section lists all current NAT sessions between interface of types external (WAN) and internal (LAN). UPnP Portmap The section lists all port-mapping established using UPnP (Universal Plug and Play. See Advanced section of this manual for more details on UPnP and the router’s UPnP configuration options. Chapter 4: Configuration...
English Manual PPTP Status This shows details of your configured PPTP VPN Connections. Name: The name you assigned to the particular PPTP connection in your VPN configuration. Type: The type of connection (dial-in/dial-out). Enable: Whether the connection is currently enabled. Active: Whether the connection is currently active.
English Manual Remote Subnet: The Subnet of the remote site. Remote Gateway: The Remote Gateway IP address. SA: The Security Association for this VPN entry. L2TP Status This shows details of your configured L2TP VPN Connections. Name: The name you assigned to the particular L2TP connection in your VPN configuration. Type: The type of connection (dial-in/dial-out).
English Manual Event Log This page displays the router’s Event Log entries. Major events are logged to this window, such as when the router’s ADSL connection is disconnected, as well as Firewall events when you have enabled Intrusion or Blocking Logging in the Configuration – Firewall section of the interface. Please see the Firewall section of this manual for more details on how to enable Firewall logging.
English Manual Diagnostic It tests the connection to computer(s) which is connected to LAN ports and also the WAN Internet connection. If PING www.google.com is shown FAIL and the rest is PASS, you ought to check your PC’s DNS settings is set correctly. Chapter 4: Configuration...
English Manual Quick Start 1. Click Quick Start. Select the connect mode you want. There are three options you can choose, ADSL, EWAN and 3G. Select ADSL from Connect Mode drop-down menu, and click Continue. 2. If your ADSL line is not ready, you need to check your ADSL line has been set or not. 3.
Page 38
English Manual 5. Please enter “Username” and “Password” as supplied by your ISP (Internet Service Provider) and click Apply to continue. Profile Port: Select the connection mode. There are ADSL EWAN and 3G. Protocol: Select the protocol mode. The default mode is PPPoE. VPI/VCI: Enter the VPI and VCI information provided by your ISP.
Page 39
English Manual IP Address: Your WAN IP address. Leave this at 0.0.0.0 to obtain automatically an IP address from your ISP. 6. Configure the Wireless LAN setting. WLAN Service: Default setting is set to Enable. If you want to use wireless, both 802.11g and 802.11b device in your network, you can select Enable.
Page 40
English Manual 8. When ADSL is synchronic, it will appear “check”. Chapter 4: Configuration...
English Manual Configuration When you click this item, you get following sub-items to configure the ADSL router. - LAN, WAN, System, Firewall, VPN, QoS, Virtual Server, Wake on LAN, Time Schedule and Advanced These functions are described below in the following sections. Chapter 4: Configuration...
English Manual LAN - Local Area Network Here are the items within the LAN section: Bridge Interface, Ethernet, IP Alias, Ethernet Client Filter, Wireless, Wireless Security, Wireless Client Filter, WPS, Port Setting DHCP Server. Bridge Interface You can setup member ports for each VLAN group under Bridge Interface section. From the example, two VLAN groups need to be created.
Page 43
English Manual Ethernet Primary IP Address IP Address: The default IP on this router. Subnet Mask: The default subnet mask on this router. RIP: RIP v1, RIP v2, and RIP v2 Multicast. Check to enable RIP function. IP Alias This function creates multiple virtual IP interfaces on this router. It helps to connect two or more local networks to the ISP or remote node.
English Manual Ethernet Client Filter The Ethernet Client Filter supports up to 16 Ethernet network machines that helps you to manage your network control to accept traffic from specific authorized machines or can restrict unwanted machine(s) to access your LAN. There are no pre-define Ethernet MAC address filter rules;...
Page 45
English Manual Active PC in LAN displays a list of individual Ethernet device’s IP Address & MAC Address which connecting to the router. You can easily by checking the box next to the IP address to be blocked or allowed. Then, Add to insert to the Ethernet Client Filter table.
Page 46
English Manual characters. Make sure your wireless clients have exactly the ESSID as the device, in order to get connected to your network. Note: It is case sensitive and must not excess 32 characters. ESSID Broadcast: It is function in which transmits its ESSID to the air so that when wireless client searches for a network, router can then be discovered and recognized.
Page 47
English Manual 4. Peer WDS MAC Address: It is the fourth associated AP’s MAC Address. Note: For MAC Address, Semicolon ( : ) must be included. Chapter 4: Configuration...
English Manual Wireless Security You can disable or enable with WPA or WEP for protecting wireless network. The default mode of wireless security is disabled. WPA-PSK / WPA2-PSK / WEP Security Mode: You can disable or enable with WPA or WEP for protecting wireless network.
Page 49
English Manual WEP Authentication: To prevent unauthorized wireless stations from accessing data transmitted over the network, the router offers secure data encryption, known as WEP. If you require high security for transmissions, there are two options to select from: Open System, Share key.
Page 50
English Manual Wireless Client / MAC Address Filter The MAC Address supports up to 16 wireless network machines and helps you manage your network control to accept traffic from specific authorized machines or to restrict unwanted machine(s) to access your LAN. There are no pre-define MAC Address filter rules;...
Page 51
English Manual WPS feature is follow Wi-Fi Alliance WPS standard and it easily set up security-enabled Wi-Fi networks in the home and small office environment. It is reduced by half the user steps to configure a network and supports two methods that are familiar to most consumers to configure a network and enable security.
Page 52
English Manual Step 4: These are two ways to trigger AP as Enrolee role, you can choose one to do it. Push AP’s WPS button 1 second and release it. In the AP’s WPS configuration page, change Role to “Enrollee” and apply “Start” button.
Page 53
English Manual Step 6: SSID and security will be generated automatically (You can change it) and apply “next” button. Step 7: WPS set up complete. And you have set up security-enabled Wi-Fi networks. Chapter 4: Configuration...
Page 54
English Manual Chapter 4: Configuration...
Page 55
English Manual Set up of security-enabled Wi-Fi network using WCN in Vista Step 1: Note down the AP’s PIN from Web (Ex: 78749887). Step 2: In Vista’s Control Panel, select Network and Internet and choose View network computers and devices. Double click the “ADSL Firewall Router” icon and enter the AP’s PIN code then click “Next”.
Page 56
English Manual Step 4: Enter the Passphrase and apply “Next” button. Step 5: WCN set up complete. And you have set up security-enabled Wi-Fi networks. Chapter 4: Configuration...
Page 57
English Manual Chapter 4: Configuration...
Page 58
English Manual Adding a new WPS device (wireless client) to a network - Use PBC Method Step 1: Push AP’s WPS button more than one second and you will see AP’s WLAN led will flashing per second. Step 2: Open wireless client’s WPS utility, select “Join a wireless network” and apply “next” button. Note: After you push AP’s WPS button, below steps should be completed between 2 minutes.
Page 59
English Manual Chapter 4: Configuration...
Page 60
English Manual Adding a new WPS device (wireless client) to a network - Use PIN Method Step 1: Open wireless client’s WPS utility, select “Join a wireless network” and apply “next” button. Step 2: Note down the wireless client’s PIN (Ex: 41538142) and apply “Start” button for active wireless client WPS PIN method.
Page 61
English Manual Step 4: New WPS device have join into the wireless network. Chapter 4: Configuration...
English Manual Port Setting This section allows you to configure the settings for the router’s Ethernet ports to solve some of the compatibility problems that may be encountered while connecting to the Internet, as well allowing users to tweak the performance of their network. Port # Connection Type: There are Six options to choose from: Auto, disable, 10M half-duplex, 10M full-duplex, 100M half-duplex, 100M full-duplex and Disable.
English Manual DHCP Server You can disable or enable the DHCP (Dynamic Host Configuration Protocol) server or enable the router’s DHCP relay functions. The DHCP protocol allows your router to dynamically assign IP addresses to PCs on your network if they are configured to obtain IP addresses automatically. To disable the router’s DHCP Server, check Disabled and click Next, then click Apply.
English Manual WAN - Wide Area Network WAN refers to your Wide Area Network connection, i.e. your router’s connection to your ISP and the Internet. Here are the items within the WAN section: WAN Interface, WAN Profile ADSL Mode. WAN Interface The factory default has the Connection Mode as ADSL and the Protocol as PPPoE.
Page 65
English Manual WAN1: Select “ADSL” “EWAN” or “3G” mode for WAN1. WAN2: Select the left WAN mode for WAN2 as backup port. eg. If 3G is set for main port, then there can be no option for failover/failback. Time Schedule: A self defined time period. You may specify a time schedule for your prioritization policy.
English Manual WAN Profile ADSL PPPoE Connection PPPoE (PPP over Ethernet) provides access control in a manner which is similar to dial-up services using PPP. Profile Port: Select the profile port as ADSL. Protocol: The ATM protocol will be used in the device. Description: A given name for the connection.
Page 67
English Manual IP (0.0.0.0: Auto): Your WAN IP address. Leave this at 0.0.0.0 to obtain automatically an IP address from your ISP. Auth. Protocol: Default is Auto. Your ISP should advise you on whether to use Chap or Pap. Connection: Always on: If you want the router to establish a PPP session when starting up and to automatically re-establish the PPP session when disconnected by the ISP.
Page 68
English Manual PPPoA Connection Profile Port: Select the profile port as ADSL. Protocol: The ATM protocol will be used in the device. Description: A given name for the connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer. Username: Enter the username provided by your ISP.
Page 69
English Manual Always on: If you want the router to establish a PPP session when starting up and to automatically re-establish the PPP session when disconnected by the ISP. Connect on Demand: If you want to establish a PPP session only when there is a packet requesting access to the Internet (i.e.
Page 70
English Manual MPoA Connection as ADSL. Profile Port: Select the profile port The ATM protocol will be used in the device. Protocol: Description: A given name for the connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer. NAT: The NAT (Network Address Translation) feature allows multiple users to access the Internet through a single IP account, sharing a single IP address.
Page 71
English Manual MAC Spoofing: This option is required by some service providers. You must fill in the MAC address that specify by service provider when it is required. Default is disabled. Obtain DNS: A Domain Name System (DNS) contains a mapping table for domain name and IP addresses.
Page 72
English Manual IPoA Routed Connection as ADSL. Profile Port: Select the profile port Protocol: The ATM protocol will be used in the device. Description: A given name for the connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer. NAT: The NAT (Network Address Translation) feature allows multiple users to access the Internet through a single IP account, sharing a single IP address.
Page 73
English Manual Obtain DNS: A Domain Name System (DNS) contains a mapping table for domain name and IP addresses. DNS helps to find the IP address for the specific domain name. Check the checkbox to obtain DNS automatically. Primary DNS: Enter the primary DNS. Secondary DNS: Enter the secondary DNS.
Page 74
English Manual Pure Bridge as ADSL. Profile Port: Select the profile port The ATM protocol will be used in the device. Protocol: Description: A given name for this connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer. Encap.
Page 75
English Manual Multiple Session with PPPoE pass-through as ADSL. Profile Port: Select the profile port The Multiple Session protocol will be used in the device. Protocol: Description: A given name for this connection. VPI/VCI: Enter the information provided by your ISP. ATM Class: The Quality of Service for ATM layer.
Page 76
English Manual address from your ISP. Auth. Protocol: Default is Auto. Your ISP should advise you on whether to use Chap or Pap. Connection: Always on: If you want the router to establish a PPPoA session when starting up and to automatically re-establish the PPPoA session when disconnected by the ISP.
Page 77
English Manual Configure the detailed information for your second connection like the previous one. Chapter 4: Configuration...
Page 78
English Manual EWAN Obtain an IP Address Automatically When connecting to the ISP, This router also functions as a DHCP client. It can automatically obtain an IP address, netmask, gateway address, and DNS server addresses if the ISP assigns this information via DHCP.
Page 79
English Manual Fixed IP Address Select this option to set static IP information. You will need to enter in the Connection type, IP address, netmask, and gateway address, provided to you by your ISP. Each IP address entered in the fields must be in the appropriate IP form, which is four IP octets separated by a dot (x.x.x.x). The Router will not accept the IP address if it is not in this format.
Page 80
English Manual PPPoE PPPoE (PPP over Ethernet) provides access control in a manner which is similar to dial-up services using PPP. Profile Port: Select the profile port EWAN Username: Enter the username provided by your ISP. You can input up to 128 alphanumeric characters (case sensitive).
Page 81
English Manual Auth. Protocol: Default is Auto. Your ISP advises on using Chap or Pap. MAC Spoofing: Select Enable and enter a MAC address that will temporarily change your router’s MAC address to the one you have specified in this field. Leave it as Disabled if you do not wish to change the MAC address of your router.
Page 82
English Manual Pure Bridge Profile Port: Select the profile port EWAN Protocol: Select Pure Bridge. Acceptable Frame Type: Specify which kind of traffic goes through this connection, all traffic oronly VLAN tagged. Filter Type: Specify the type of ethernet filtering performed by the named bridge interface. Allows all types of ethernet packets through the port.
Page 83
English Manual The router allows you to insert a 3G/HSDPA card to its USB slot, enabling you to use a 3G/HSDPA, UMTS, EDGE, GPRS, or GSM Internet connection, makes downstream rates of to 14.4 Mbps*. Profile Port: Select the profile port iBurst: Enable or Disable the router’s iBurst functionality.
Page 84
English Manual Auth. Protocol: Manually specify CHAP (Challenge Handshake Authentication Protocol) or PAP (Password Authentication Protocol) if you know which authentication type the server is using (when acting as a client), or the authentication type you want the clients to use when tehy are connecting to you (when acting as a server).
English Manual ADSL Mode Connect Mode: This mode will automatically detect your ADSL line code, ADSL2+, ADSL2, AnnexM2 and AnnexM2+, ADSL, All. Please keep the factory setting unless ADSL is detected as the symptom of synchronization problem. Modulation: It will automatically detect capability of your ADSL line mode. Please keep the factory setting unless ADSL is detected as the symptom of synchronization problem.
English Manual System Here are the items within the System section: Time Zone, Remote Access, Firmware Upgrade, Backup/Restore, Restart, User Management Mail Alert. Time Zone The router does not have a real time clock on board; instead, it uses the Simple Network Time Protocol (SNTP) to get the current time from an SNTP server outside your network.
English Manual Remote Access To temporarily permit remote administration of the router (i.e. from outside your LAN), select a time period the router will permit remote access for and click Enable. You may change other configuration options for the web administration interface using Device Management options in the Advanced section of the GUI.
English Manual Firmware Upgrade Your router’s “firmware” is the software that allows it to operate and provides all its functionality. Think of your router as a dedicated computer, and the firmware as the software it runs. Over time this software may be improved and revised, and your router allows you to upgrade the software it runs to take advantage of these changes.
Page 89
English Manual Backup / Restore This function allows you to save a backup of the current configuration of your router to a file on your PC, or to restore a previously saved configuration. This is very useful if you wish to customize the setting of the router, knowing in advance that you can always restore the setting if any mistakes do occur.
English Manual Restart Router Click Restart with option Current Settings to reboot your router (and restore your last saved configuration). If you wish to restart the router using the factory default settings (for example, after a firmware upgrade or if you have saved an incorrect configuration), select Factory Default Settings to reset to factory default settings.
English Manual User Management In order to prevent unauthorized access to your router’s configuration interface, it requires all users to login with a password. You can set up multiple user accounts, each with their own password. You are able to Edit existing users and Add new users who are able to access the device’s configuration interface.
Page 92
English Manual 2. When it is done, click the Add button. To delete a user account: 1. Click on the Delete radio button of the account you want to delete. 2. Then click the Edit/Delete to confirm the deletion. Note: You can delete any user account except for the default admin account. Thus there isno delete radio button available for this account.
English Manual Mail Alert Mail alert is designed to keep system administrator or other relevant personnels alerted of any unexpected events that might have occured to the network computers or server for monitoring efficiency. With this alert system, appropriate solutions may be tackled to fix problems that may have arisen so that the server can be properly maintained.
English Manual Firewall and Access Control Your router includes a full SPI (Stateful Packet Inspection) firewall for controlling Internet access from your LAN, as well as helping to prevent attacks from hackers. Besides, when using NAT, the router acts as a “natural” Internet firewall, as all PCs on your LAN will use private IP addresses that cannot be directly accessed from the Internet.
English Manual Here are the items within the Firewall section: General Settings, Packet Filter, Intrusion Detection, URL Filter, IM/P2P Blocking Firewall Log. General Settings You can choose not to enable Firewall and still able to access to URL Filter and IM/P2P Blocking or enable the Firewall using preset filter rules and modify the port filter rules as required.
Page 96
English Manual (Changed the format only. Any remote user who is attempting to perform this action may result in blocking all the accesses to configure and manage of the device from the Internet. Chapter 4: Configuration...
English Manual Packet Filter This function is only available when the Firewall is enabled and one of these four security levels is chosen (All blocked, High, Medium and Low). The preset port filter rules in the Packet Filter must modify accordingly to the level of Firewall, which is selected. See Table1: Predefined Port Filter for more detail information.
Page 98
English Manual Example: Predefined Port Filters Rules The predefined port filter rules for High, Medium and Low security levels are listed. See Table 1. Note: Firewall – All Blocked/User-defined, you must define and create the port filter rules yourself. No predefined rule is being preconfigured.
Page 99
English Manual YES: Allowed; NO: Blocked; N/A: Not Applicable Packet Filter – Add TCP/UDP Filter Rule Name: Users-define description to identify this entry or click “Select” drop-down menu to select existing predefined rules. The maximum name length is 32 characters. Time Schedule: It is self-defined time period.
Page 100
English Manual Packet Filter – Add Raw IP Filter Go to “Type” drop-down menu, select “Use Protocol Number”. Rule Name Helper: Users-define description to identify this entry or choosing “Select” drop-down menu to select existing predefined rules. Time Schedule: It is self-defined time period. You may specify a time schedule for your prioritization policy.
Page 101
English Manual Example: Configuring your firewall to allow a publicly accessible web server on your LAN The predefined port filter rule for HTTP (TCP port 80) is the same no matter whether the firewall is set to a high, medium or low security level. To setup a web server located on the local network when the firewall is enabled, you have to configure the Port Filters setting for HTTP.
Page 102
English Manual Configuring Packet Filter: Click Packet Filters. You will then be presented with the predefined port filter rules screen (in this case for the low security level), shown below: Note: You may click Edit the predefined rule instead of Delete it. This is an example to show to how you add a filter on your own.
Page 103
English Manual Input the Rule Name, Time Schedule, Source/Destination IP, Type, Source/Destination Port, Inbound and Outbound. Example: Application: Cindy_HTTP Time Schedule: Always On Source / Destination IP Address(es): 0.0.0.0 (I do not wish to active the address-filter, instead I use the port-filter) Type: TCP (Please refer to Table1: Predefined Port Filter) Source Port: 0-65535 (I allow all ports to connect with the application))
English Manual Intrusion Detection The router’s Intrusion Detection System (IDS) is used to detect hacker attacks and intrusion attempts from the Internet. If the IDS function of the firewall is enabled, inbound packets are filtered and blocked depending on whether they are detected as possible hacker attacks, intrusion attempts or other connections that the router determines to be suspicious.
Page 105
English Manual Scan Attack Block Duration: This is the duration for blocking hosts that attempt a possible Scan attack. Scan attack types include X’mas scan, IMAP SYN/FIN scan and similar attempts. Default value is 86400 seconds. DoS Attack Block Duration: This is the duration for blocking hosts that attempt a possible Denial of Service (DoS) attack.
Page 106
English Manual Table 2: Hacker attack types recognized by the IDS Type of Block Intrusion Name Detect Parameter Blacklist Drop Packet Show Log Duration Ascend Kill Ascend Kill data Src IP WinNuke Port 135, 137~139, Src IP Flag: URG ICMP type 8 Victim Smurf Dst IP...
English Manual URL Filter URL (Uniform Resource Locator – e.g. an address in the form of http://www.abcde.com http://www.example.com) filter rules allow you to prevent users on your network from accessing particular websites by their URL. There are no pre-defined URL filter rules; you can add filter rules to meet your requirements.
Page 108
English Manual Domains Filtering: This function checks the whole URL not the IP address, in URLs accessed against your list of domains to block or allow. If it is matched, the URL request will be sent (Trusted) or dropped (Forbidden). For this function to be activated, both check-boxes must be checked. Here is the checking procedure: 1.
Page 109
English Manual Example: Andy wishes to disable all WEB traffic except for ones listed in the trusted domain, which would prevent Bobby from accessing other web sites. Andy selects both functions in the Domain Filtering and thinks that it will stop Bobby. But Bobby knows this function, Domain Filtering, ONLY disables all WEB traffic except for Trusted Domain, BUT not its IP address.
Page 110
English Manual IM / P2P Blocking IM, short for Instant Message, is required to use client program software that allows users to communicate, in exchanging text message, with other IM users in real time over the Internet. A P2P application, known as Peer-to-peer, is group of computer users who share file to specific groups of people across the Internet.
English Manual Firewall Log Firewall Log display log information of any unexpected action with your firewall settings. Check the Enable box to activate the logs. Log information can be seen in the Status – Event Log after enabling. Chapter 4: Configuration...
English Manual VPN - Virtual Private Networks Virtual Private Networks is ways to establish secured communication tunnels to an organization’s network via the Internet. Your router supports three main types of VPN (Virtual Private Network), PPTP, IPSec L2TP. PPTP (Point-to-Point Tunneling Protocol) There are two types of PPTP VPN supported;...
Page 113
English Manual When configuring your router as a Client, enter the remote Server IP Address (or Domain Name) you wish to connect to. When configuring your router as a server, enter the Private IP Address Assigned to Dial in User address. Username: If you are a Dial-Out user (client), enter the username provided by your Host.
Page 114
English Manual Example: Configuring a Remote Access PPTP VPN Dial-out Connection A company’s office establishes a PPTP VPN connection with a file server located at a separate location. The router is installed in the office, connected to a couple of PCs and Servers. Dial-out Chapter 4: Configuration...
Page 115
English Manual Configuring the PPTP VPN in the Office Click Configuration/VPN/PPTP. Choose Remote Access from Connect Type drop-down menu. You can either input the IP address (69.1.121.33 in this case) or hostname to reach the server. Item Function Description Name VPN_PPTP Given name of PPTP connection Select Remote Access from Connection Type...
Page 116
English Manual PPTP Connection - LAN to LAN Click Configuration/VPN/PPTP. Choose LAN to LAN from Connect Type drop-down menu. Name: A given name of the connection. Connection Type: Remote Access or LAN to LAN. Type: Check Dial Out if you want your router to operate as a client (connecting to a remote VPN server, e.g.
Page 117
English Manual Data Encryption: Data sent over the VPN connection can be encrypted by an MPPE algorithm. Default is Auto, so that this setting is negotiated when establishing a connection, or else you can manually Enable or Disable encryption. Key Length: The data can be encrypted by MPPE algorithm with 40 bits or 128 bits. Default is Auto, it is negotiated when establishing a connection.
Page 118
English Manual Example: Configuring a PPTP LAN-to-LAN VPN Connection The branch office establishes a PPTP VPN tunnel with head office to connect two private networks over the Internet. The routers are installed in the head office and branch offices accordingly. Both office LAN networks MUST in different subnet with LAN to LAN application.
Page 119
English Manual Configuring PPTP VPN in the Head Office The IP address 192.168.1.201 will be assigned to the router located in the branch office. Please make sure this IP is not used in the head office LAN. Item Function Description Name HeadOffice Given a name of PPTP connection...
Page 120
English Manual Configuring PPTP VPN in the Branch Office The IP address 69.1.121.30 is the Public IP address of the router located in head office. If you registered the DDNS (please refer to the DDNS section of this manual), you can also use the domain name instead of the IP address to reach the router.
Page 121
English Manual IPSec (IP Security Protocol) Active: This function activates or deactivates the IPSec connection. Check Active checkbox if you want the protocol of tunnel to be activated and vice versa. Note: When the Active checkbox is checked, the function of Edit and Delete will not be available. Name: This is a given name of the connection.
Page 122
English Manual IPSec Proposal: This is selected IPSec security method. IPSec VPN Connection Name: A given name for the connection (e.g. “connection to office”). Local Network: Set the IP address, subnet or address range of the local network. Single Address: The IP address of the local host. Subnet: The subnet of the local network.
Page 123
English Manual IKE (Internet key Exchange) Mode: Select IKE mode to Main mode or Aggressive mode. This IKE provides secured key generation and key management. Hash Function: It is a Message Digest algorithm which coverts any length of a message into a unique set of bits.
Page 124
English Manual Pre-shared Key: This is for the Internet Key Exchange (IKE) protocol, a string from 4 to 128 characters. Both sides should use the same key. IKE is used to establish a shared security policy and authenticated keys for services (such as IPSec) that require a key. Before any IPSec traffic can be passed, each router must be able to verify the identity of its peer.
Page 125
English Manual Ping to the IP Interval (sec) Ping to the IP Action 0.0.0.0 0.0.0.0 2000 xxx.xxx.xxx.xxx (A valid IP Address) xxx.xxx.xxx.xxx(A valid IP Address) 2000 Yes, activate it in every 2000 second. Disconnection Time after no traffic: It is the NO Response time clock. When no traffic stage time is beyond the Disconnection time set, Router will automatically halt the tunnel connection and re- establish it base on the Reconnection Time set.
Page 126
English Manual Example: Configuring a IPSec LAN-to-LAN VPN Connection Table 3: Network Configuration and Security Plan Branch Office Head Office Local Network ID 192.168.0.0/24 192.168.1.0/24 Local Router IP 69.1.121.30 69.1.121.3 Remote Network ID 192.168.1.0/24 192.168.0.0/24 Remote Router IP 69.1.121.3 69.1.121.30 IKE Pre-shared Key 12345678 12345678...
Page 127
English Manual Configuring IPSec VPN in the Head Office Item Function Description Name IPSec_HeadOffice Given a name of IPSec connection Select Subnet from Local Network drop- Local Network Subnet down menu. IP Address 192.168.1.0 Head office network Netmask 255.255.255.0 Remote Secure Gateway IP IP address of the branch office router (in 69.121.1.30 (or Hostname)
Page 128
English Manual Configuring IPSec VPN in the Branch Office Item Function Description IPSec_Branch Name Given a name of IPSec connection Office Select Subnet from Local Network drop- Local Network Subnet down menu. IP Address 192.168.0.0 Branch office network Netmask 255.255.255.0 Remote Secure Gateway IP IP address of the head office router (in WAN 69.121.1.3...
Page 129
English Manual Example: Configuring a IPSec Host-to-LAN VPN Connection Chapter 4: Configuration...
Page 130
English Manual Configuring IPSec VPN in the Office Item Function Description Name IPSec Given a name of IPSec connection Select Subnet from Network drop-down Local Network Subnet menu IP Address 192.168.1.0 Head office network Netmask 255.255.255.0 Remote Secure Gateway IP 69.121.1.30 Remote worker’s IP address (or Hostname)
Page 131
English Manual L2TP (Layer Two Tunneling Protocol) Two types of L2TP VPN are supported Remote Access and LAN-to-LAN (please refer below for more information.). Fill in the blank with information you need and click Add to create a new VPN connection account.
Page 132
English Manual L2TP Connection - Remote Access Connection Type: Remote Access or LAN to LAN. Name: A given name for the connection (e.g. “connection to office”). Active: This function activates or deactivates the L2TP connection. Check Active checkbox if you want the protocol of tunnel to be activated and vice versa.
Page 133
English Manual before sending, and also allows for challenges at different periods to ensure that the client has not been replaced by an intruder. Tunnel Authentication: This enables router to authenticate both the L2TP remote and L2TP host. This is only valid when L2TP remote supports this feature. Secret: The secure password length should be 16 characters which may include numbers and characters.
Page 134
English Manual Click Edit/Delete to save your changes.. Example: Configuring a L2TP VPN - Remote Access Dial-in Connection A remote worker establishes a L2TP VPN connection with the head office using Microsoft's VPN Adapter (included with Windows XP/2000/ME, etc.). The router is installed in the head office, connected to a couple of PCs and Servers.
Page 135
English Manual Configuring L2TP VPN in the Office The input IP address 192.168.1.200 will be assigned to the remote worker. Please make sure this IP is not used in the Office LAN. Item Function Description Name VPN_L2TP Given a name of L2TP connection Select Remote Access from Connection Type Connection Type Remote Access...
Page 136
English Manual Example: Configuring a Remote Access L2TP VPN Dial-out Connection A company’s office establishes a L2TP VPN connection with a file server located at a separate location. The router is installed in the office, connected to a couple of PCs and Servers. Dial-out Chapter 4: Configuration...
Page 137
English Manual Configuring the L2TP VPN in the Office Item Function Description Name VPN_L2TP Given name of L2TP connection Select Remote Access from Connection Type Connection Type Remote Access drop-down menu Type Dial out Select Dial out from Type drop-down menu IP Address (or 69.121.1.33 An Dialed server IP...
Page 138
English Manual Example: Configuring your Router to Dial-in to the Server Currently, Microsoft Windows operation system does not support L2TP incoming service. Additional software may be required to set up your L2TP incoming service. L2TP Connection - LAN to LAN L2TP VPN Connection Name: A given name of the connection.
Page 139
English Manual Netmask: Enter the subnet mask of peer network based on the Peer Network IP setting. Username: If you are a Dial-Out user (client), enter the username provided by your Host. If you are a Dial-In user (server), enter your own username. Password: If you are a Dial-Out user (client), enter the password provided by your Host.
Page 140
English Manual will provide better security, but extends the VPN negotiation time. Diffie-Hellman is a public-key cryptography protocol that allows two parties to establish a shared secret over an unsecured communication channel (i.e. over the Internet). There are three modes, MODP 768-bit, MODP 1024- bit and MODP 1536-bit.
Page 141
English Manual Example: Configuring L2TP LAN-to-LAN VPN Connection The branch office establishes a L2TP VPN tunnel with head office to connect two private networks over the Internet. The routers are installed in the head office and branch office accordingly. Both office LAN networks MUST in different subnet with LAN to LAN application.
Page 142
English Manual Configuring L2TP VPN in the Head Office The IP address 192.168.1.200 will be assigned to the router located in the branch office. Please make sure this IP is not used in the head office LAN. Item Function Description Name HeadOffice Given a name of L2TP connection...
Page 143
English Manual Configuring L2TP VPN in the Branch Office The IP address 69.1.121.30 is the Public IP address of the router located in head office. If you registered the DDNS (please refer to the DDNS section of this manual), you can also use the domain name instead of the IP address to reach the router.
English Manual QoS - Quality of Service QoS function helps you to control your network traffic for each application from LAN (Ethernet and/or Wireless) to WAN (Internet). It facilitates you to control the different quality and speed of through put for each application when the system is running with full loading of upstream.
Page 145
English Manual Destination Port: The destination port of packets to be monitored. DSCP Marking: Differentiated Services Code Point (DSCP), it is the first 6 bits in the ToS byte. DSCP Marking allows users to assign specific application traffic to be executed in priority by the next Router based on the DSCP value.
Page 146
English Manual Outbound IP Throttling (LAN to WAN) IP Throttling allows you to limit the speed of IP traffic. The value entered will limit the speed of the application that you set to the specified value’s multiple of 32kbps. Name: User-define description to identify this new policy/name. Time Schedule: Scheduling your prioritization policy.
Page 147
English Manual Inbound IP Throttling (WAN to LAN) IP Throttling allows you to limit the speed of IP traffic. The value entered will limit the speed of the application that you set to the specified value’s multiple of 32kbps. Name: User-define description to identify this new policy/application. Time Schedule: Scheduling your prioritization policy.
Page 148
English Manual Example: QoS for your Network Connection Diagram VoIP Normal PCs Restricted Information and Settings Upstream: 928 kbps Downstream: 8 Mbps VoIP User: 192.168.1.1 Normal Users: 192.168.1.2~192.168.1.5 Restricted User: 192.168.1.100 Chapter 4: Configuration...
Page 149
English Manual Throughput VoIP/VPN HIGH kbps Others NORMAL Restricted VoIP/VPN Others Restricted HIGH NORMAL Chapter 4: Configuration...
Page 150
English Manual Mission-critical application Mostly the VPN connection is mission-critical application for doing data exchange between head and branch office. The mission-critical application must be sent out smoothly without any dropping. Set priority as high level for preventing any other applications to saturate the bandwidth. Voice application Voice is latency-sensitive application.
Page 151
English Manual Some of companies will setup FTP server for customer downloading or home user sharing their files by using FTP. With above settings that help to limit utilization of upstream of FTP. Time schedule also help you to only limit utilization at daytime. Advanced setting by using IP throttling With IP throttling you can specify more detail for allocating bandwidth;...
Page 152
English Manual Sometime your customers or friends may upload their files to your FTP server and that will saturate your downstream bandwidth. The settings below help you to limit bandwidth for the restricted application. Chapter 4: Configuration...
English Manual Virtual Server (known as Port Forwarding) In TCP/IP and UDP networks a port is a 16-bit number used to identify which application program (usually a server) incoming connections should be delivered to. Some ports have numbers that are pre-assigned to them by the IANA (the Internet Assigned Numbers Authority), and these are referred to as “well-known ports”.
English Manual Add Virtual Server Because NAT can act as a “natural” Internet firewall, your router protects your network from being accessed by outside users when using NAT, as all incoming connection attempts will point to your router unless you specifically create Virtual Server entries to forward those ports to a PC on your network.
Page 155
English Manual Internal IP Address: The private IP in the LAN network, which will be providing the virtual server application. List all existing PCs connecting to the network. You may assign a PC with IP address and MAC from this list. Example: If you like to remote accessing your Router through the Web/HTTP at all time, you would need to enable port number 80 (Web/HTTP) and map to Router’s IP Address.
Page 156
English Manual Edit/Delete: Click it to edit or delete this virtual server application. Using port forwarding does have security implications, as outside users will be able to connect to PCs on your network. For this reason you are advised to use specific Virtual Server entries just for the ports your application requires, instead of using DMZ.
English Manual Edit DMZ Host The DMZ Host is a local computer exposed to the Internet. When setting a particular internal IP address as the DMZ Host, all incoming packets will be checked by the Firewall and NAT algorithms then passed to the DMZ host, when a packet received does not use a port number used by any other Virtual Server entries.
Page 158
English Manual Edit One-to-One NAT (Network Address Translation) One-to-One NAT maps a specific private/local IP address to a global/public IP address. If you have multiple public/WAN IP addresses from you ISP, you are eligible for One-to-One NAT to utilize these IP addresses. Go to Configuration Virtual Server Edit One-to-one NAT NAT Type: Select desired NAT type.
Page 159
English Manual Application: Users-defined description to identify this entry or click drop-down menu to select existing predefined rules. : 20 predefined rules are available. Application, Protocol and External/Redirect Ports will be filled after the selection. Protocol: It is the supported protocol for the virtual server. In addition to specifying the port number to be used, you will also need to specify the protocol used.
Page 160
English Manual Example: List of some well-known and registered port numbers. The Internet Assigned Numbers Authority (IANA) is the central coordinator for the assignment of unique parameter values for Internet protocols. Port numbers range from 0 to 65535, but only ports numbers 0 to 1023 are reserved for privileged services and are designated as “well-known ports”...
English Manual Wake on LAN Wake on LAN (WOL, sometimes WoL) is an Ethernet computer networking standard that allows a computer to be turned on or woken up remotely by a network message. Select: Select MAC address of the computer that you want to wake up or turn on remotely. Add: After selecting, click Add then you can perform the Wake-up action.
English Manual Time Schedule The Time Schedule supports up to 16 time slots which helps you to manage your Internet connection. In each time profile, you may schedule specific day(s) i.e. Monday through Sunday to restrict or allowing the usage of the Internet by users or applications. This Time Schedule correlates closely with router’s time, since router does not have a real time clock on board;...
English Manual Configuration of Time Schedule Edit a Time Slot 1. Choose any Time Slot (ID 1 to ID 16) to edit, click Edit radio button. Note: Watch it carefully, the days you have selected will present in capital letter. Lower case letter shows the day(s) is not selected, and no rule will apply on this day(s).
English Manual Delete a Time Slot Choose Delete radio button, and click Delete button to delete the existing Time profile, i.e. erase the Day and back to default setting of Start Time / End Time. Advanced Configuration options within the Advanced section are for users who wish to take advantage of the more advanced features of the router.
English Manual IP Address: Fill in the IP address of the host computer that is sending the data packet. MAC Address: Fill in the MAC address of the computer that the incoming data packets are to be forwarded. Dynamic DNS The Dynamic DNS function allows you to alias a dynamic IP address to a static hostname, allowing users whose ISP does not assign them a static IP address to use a domain name.
English Manual Enable: Check to enable the Dynamic DNS function. The following fields will be activated and required: Dynamic DNS Server: Select the DDNS service you have established an account with. Domain Name, Username and Password: Enter your registered domain name and your username and password for this service.
English Manual Device Management The Device Management advanced configuration settings allow you to control your router’s security options and device monitoring features. Device Host Name Host Name: Give a name for it. (The Host Name cannot be used with one word only. There are two words should be connected with a '.' at least.
Page 168
English Manual Embedded Web Server ( 2 Management IP Accounts) HTTP Port: This is the port number the router’s embedded web server (for web-based configuration) will use. The default value is the standard HTTP port, 80. Users may specify an alternative if, for example, they are running a web server on a PC within their LAN.
Page 169
English Manual Write Community: Specify a name to be identified as the Write Community, and an IP address. This community string will be checked against the string entered in the configuration file. Once the string name is matched, users from this IP address will be able to view and modify the data. Trap Community: Specify a name to be identified as the Trap Community, and an IP address.
Page 170
English Manual SNMP Version: SNMPv2c and SNMPv3 SNMPv2c is the combination of the enhanced protocol features of SNMPv2 without the SNMPv2 security. The "c" comes from the fact that SNMPv2c uses the SNMPv1 community string paradigm for "security", but is widely accepted as the SNMPv2 standard. SNMPv3 is a strong authentication mechanism, authorization with fine granularity for remote monitoring.
English Manual From RFC 1473 (PPP/IP MIB): PPP IP Group From RFC 1474 (PPP/Bridge MIB): PPP Bridge Group From RFC1573 (IfMIB): ifMIBObjects Group From RFC1695 (atmMIB): atmMIBObjects From RFC 1907 (SNMPv2): only snmpSetSerialNo OID IGMP IGMP, known as Internet Group Management Protocol, is used to management hosts from multicast group.
English Manual Logout To exit the router’s web interface, choose Logout. Please ensure that you have saved the configuration settings before you logout. Be aware that the router is restricted to only one PC accessing the configuration web pages at a time. Once a PC has logged into the web interface, other PCs cannot get access until the current PC has logged out of the web interface.
English Manual Chapter 5: Troubleshooting If the router is not functioning properly, first check this chapter for simple troubleshooting before contacting your service provider for support. Problems starting up the router Problem Corrective Action None of the LEDs are Check the connection between the adapter and the router. If the error on when you turn on persists, you may have a hardware problem.
Page 174
English Manual APPENDIX A: Product Support and Contact Information Most problems can be solved by referring to the Troubleshooting section in the User’s Manual. If you cannot resolve the problem with the Troubleshooting chapter, please contact the dealer where you purchased this product. Chapter 5: Troubleshooting...
Kabeln verwendet werden. LINDY Herstellergarantie LINDY gewährt für dieses Produkt über die gesetzliche Regelung hinaus eine zweijährige Herstellergarantie ab Kaufdatum. Die detaillierten Bedingungen dieser Garantie finden Sie auf der LINDY Website aufgelistet bei den AGBs. WEEE (Waste of Electrical and Electronic Equipment),...
Need help?
Do you have a question about the 52043 and is the answer not in the manual?
Questions and answers