Choosing different connection types pops up different settings requests.
Enter appropriate settings that are required by your service provider.
25
Page 27
4.2.1 PPP over ATM (PPPoA) and PPP over Ethernet (PPPoE)
STEP 4: Select the PPP over ATM (PPPoA) or PPP over Ethernet (PPPoE) radio
button and click Next. The following screen appears.
Enable Fullcone NAT
Known as one-to-one NAT, all requests from the same internal IP address and
port are mapped to the same external IP address and port. An external host can
send a packet to the internal host, by sending a packet to the mapped external
address.
PPP Username/PPP Password
The PPP Username and the PPP password requirement are dependent on the
particular requirements of the ISP or the ADSL service provider. The WEB user
interface allows a maximum of 256 characters in the PPP user name and a maximum
of 32 characters in PPP password.
26
Page 28
Disconnect if no activity
The router can be configured to disconnect if there is no activity for a period of time
by selecting the Dial on demand check box. When the checkbox is ticked, you need
to enter the inactivity timeout period. The timeout period ranges from 1 minute to
4320 minutes.
PPP IP Extension
The PPP IP Extension is a special feature deployed by some service providers.
Unless your service provider specially requires this setup, do not select it.
The PPP IP Extension supports the following conditions:
• Allows only one PC on the LAN
• The public IP address assigned by the remote side using the PPP/IPCP protocol
is actually not used on the WAN PPP interface. Instead, it is forwarded to the PC
LAN interface through DHCP. Only one PC on the LAN can be connected to the
remote, since the DHCP server within the ADSL router has a single IP address to
assign to a LAN device.
• NAPT and firewall are disabled when this option is selected.
• The ADSL router becomes the default gateway and DNS server to the PC through
DHCP using the LAN interface IP address.
•The ADSL router extends the IP subnet at the remote service provider to the LAN
PC. That is, the PC becomes a host belonging to the same IP subnet.
•The ADSL router bridges the IP packets between WAN and LAN ports, unless the
packet is addressed to the router’s LAN IP address.
Use Static IP Address
Unless your service provider specially requires this setup, do not select it.
If selected, enter your static IP address.
Retry PPP password on authentication error
Tick the box to select.
Enable PPP Debug Mode
Enable the PPPoE debug mode. The system will put more PPP connection
information in System Log. This is used for debugging purposes.
Bridge PPPoE Frames Between WAN and Local Ports (Default Enabled)
If Enabled, the function can create a local PPPoE connection to the WAN side.
27
Page 29
STEP 5: Click Next to display the following screen.
Enable IGMP Multicast checkbox:
Tick the checkbox to enable IGMP multicast (proxy). IGMP (Internet Group
Membership Protocol) is a protocol used by IP hosts to report their multicast group
memberships to any immediately neighboring multicast routers.
Enable WAN Service checkbox:
Tick this item to enable the ATM service. Untick it to stop the ATM service.
Service Name:
This is user-defined.
28
Page 30
STEP 6: After entering your settings, select Next. The following screen appears.
This screen allows the user to configure the LAN interface IP address, subnet mask
and DHCP server. To assign dynamic IP address, DNS server and default gateway
to other LAN devices, select the button Enable DHCP server on the LAN and enter
the start and end IP addresses and DHCP leased time.
Since the router occupies the first two IP addresses (192.168.1.1 and 192.168.1.2),
the default private address range provided by the ISP server in the router is
192.168.1.3 through 192.168.1.254.
To configure a secondary IP address for the LAN port, click the checkbox, as shown.
29
Page 31
STEP 7: Click Next to continue. To enable the wireless function, select the radio
button (as shown), input a new SSID (if desired) and click Next.
STEP 8: Click Next to display the WAN Setup-Summary screen that presents the
entire configuration summary. Click Save/Reboot if the settings are
correct. Click Back if you wish to modify the settings.
STEP 9: After clicking Save/Reboot, the router will save the configuration to
flash memory and reboot. After the device reboots, the Web UI will
refresh to the Device Info screen. The router is ready for operation when
the LED indicators display correctly, as described in section 1.3.
30
Page 32
4.2.2 M AC Encapsulation Routing (MER)
Step 4: Select the MAC Encapsulation Routing (MER) radio button and click Next.
Enter information provided to you by your ISP to configure the WAN IP settings.
NOTE: DHCP can be enabled for PVC in MER mode if Obtain an IP address
automatically is chosen. Changing the default gateway or the DNS
affects the whole system. Configuring them with static values will disable
the automatic assignment from DHCP or other WAN connection.
If you configure static default gateway over this PVC in MER mode, you
must enter the IP address of the remote gateway in the “Use IP address”
field. Your ISP should provide the values to be entered in these fields.
31
Page 33
Step 5: Click Next to display the following screen.
Enable NAT checkbox: If the LAN is configured with a private IP address, the user
should select this checkbox. The NAT submenu on the left side main panel will be
displayed after reboot. The user can then configure NAT-related features after the
system comes up. If a private IP address is not used on the LAN side, this checkbox
should be de-selected to free up system resources for better performance. When
the system comes back after reboot, the NAT submenu will not be displayed on the
left main panel.
Enable Fullcone NAT: This option becomes available when NAT is enabled.
Known as one-to-one NAT, all requests from the same internal IP address and port
are mapped to the same external IP address and port. An external host can send a
packet to the internal host, by sending a packet to the mapped external address.
Enable Firewall checkbox: If the firewall checkbox is selected, the Security
submenu on the left side main panel will be displayed after system reboot. The
user can then configure firewall features after the system comes up. If firewall is
not used, this checkbox should be de-selected to free up system resources for better
performance. When system comes back after reboot, the Security submenu will
not be displayed on the left main panel.
32
Page 34
Enable IGMP Multicast: Tick the checkbox to enable IGMP multicast (proxy).
IGMP (Internet Group Membership Protocol) is a protocol used by IP hosts to report
their multicast group memberships to any immediately neighboring multicast
routers.
Enable WAN Service: Tick the checkbox to enable the WAN service. If this item
is not selected, you will not be able to use the WAN service.
Service Name: This is a user defined label.
Step 6: Upon completion click Next. The following screen appears.
Consult the following paragraphs for more details about these settings.
33
Page 35
This screen allows the user to configure the LAN interface IP address, subnet mask
and DHCP server. To assign dynamic IP address, DNS server and default gateway
to other LAN devices, select Enable DHCP server and enter the start and end IP
addresses and DHCP leased time.
Since the router occupies the first two IP addresses (192.168.1.1 and 192.168.1.2),
the default private address range provided by the ISP server in the router is
192.168.1.3 through 192.168.1.254.
Select Enable DHCP Server Relay (if available, see note below), and enter the
DHCP Server IP Address. This allows the router to relay the DHCP packets from the
remote DHCP server. The remote DHCP server will provide the IP address.
NOTE: If the NAT function is enabled (default), Enable DHCP Server Relay
won’t be displayed as an option.
To configure a secondary IP address for the LAN port, click the box as shown below.
Step 7: Click Next to continue. To enable the wireless function, select the radio
button (as shown), input a new SSID (if desired).
Click Next to display the final setup screen.
34
Page 36
Step 8: After clicking Save/Reboot, the router will save the configuration to
flash memory and reboot. After the device reboots, the Web UI will
refresh to the Device Info screen. The router is ready for operation when
the LED indicators display correctly, as described in section 1.3.
35
Page 37
4.2.3 IP Over ATM
Step 4: Select the IP over ATM (IPoA) radio button and click Next.
NOTE: DHCP is not supported over IPoA. The user must enter the IP address or
WAN interface for the default gateway setup and the DNS server
addresses provided by their ISP.
Step 5: Click Next. The following screen appears.
Enable NAT checkbox: If the LAN is configured with a private IP address, the user
should select this checkbox. The NAT submenu on the left side main panel will be
displayed after reboot. The user can then configure NAT-related features. If a
private IP address is not used on the LAN side (i.e. the LAN side is using a public IP),
this checkbox should not be selected. When the system comes back after reboot,
the NAT submenu will not be displayed on the left main panel.
36
Page 38
Enable Fullcone NAT: This option becomes available when NAT is enabled.
Known as one-to-one NAT, all requests from the same internal IP address and port
are mapped to the same external IP address and port. An external host can send a
packet to the internal host, by sending a packet to the mapped external address.
Enable Firewall checkbox: If the firewall checkbox is selected, the Security
submenu on the left side main panel will be displayed after system reboot. The
user can then configure firewall features after the system comes up. If firewall is
not used, this checkbox should be de-selected to free up system resources for better
performance. When system comes back after reboot, the Security submenu will
not be displayed on the left main panel.
Enable IGMP Multicast: Tick the checkbox to enable IGMP multicast (proxy).
IGMP (Internet Group Membership Protocol) is a protocol used by IP hosts to report
their multicast group memberships to any immediately neighboring multicast
routers.
Enable WAN Service: Tick the checkbox to enable the WAN service. If this item
is not selected, you will not be able to use the WAN service.
Service Name: This is a user defined label.
37
Page 39
Step 6: Click Next to display the following screen.
This screen allows the user to configure the LAN interface IP address, subnet mask
and DHCP server. To assign dynamic IP address, DNS server and default gateway
to other LAN devices, select the button Enable DHCP server on the LAN and enter
the start and end IP addresses and DHCP leased time.
Since the router occupies the first two IP addresses (192.168.1.1 and 192.168.1.2),
the default private address range provided by the ISP server in the router is
192.168.1.3 through 192.168.1.254.
Select Enable DHCP Server Relay (if available, see note below), and enter the
DHCP Server IP Address. This allows the router to relay the DHCP packets from the
remote DHCP server. The remote DHCP server will provide the IP address.
NOTE: If the NAT function is enabled, Enable DHCP Server Relay won’t be
displayed as an option.
To configure a secondary IP address for the LAN port, click the box as shown below.
38
Page 40
STEP 7: Click Next to continue. To enable the wireless function, select the radio
button (as shown) and input a new SSID (if desired).
Click Next to continue.
Step 8: After clicking Save/Reboot, the router will save the configuration to
flash memory and reboot. After the device reboots, the Web UI will
refresh to the Device Info screen. The router is ready for operation when
the LED indicators display correctly, as described in section 1.3.
39
Page 41
4.2.4 Bridging
Step 4: Select the Bridging radio button and click Next. The following screen
appears. To use the bridge service, tick the checkbox, Enable Bridge
Service, and enter the service name.
Step 5: Click the Next button to continue. Enter the IP address for the LAN
interface. The default IP address is 192.168.1.1. The LAN IP interface
in bridge operating mode is needed for local users to manage the ADSL
router. Notice that there is no IP address for the WAN interface in bridge
mode, and technical support cannot access the ADSL router remotely.
40
Page 42
STEP 6: Click Next to continue. To enable the wireless function, select the radio
button (as shown), input a new SSID (if desired) and click Next.
The following screen will be displayed.
Step 7: After clicking Save/Reboot, the router will save the configuration to
flash memory and reboot. After the device reboots, the Web UI will
refresh to the Device Info screen. The router is ready for operation when
the LED indicators display correctly, as described in section 1.3.
41
Page 43
Chapter 5 Device Info
Select Device Info from the main menu to display Summary information as below.
NOTE: The screen above gives a DSL status summary for ADSL1. For the status
of ADSL2 consult the next selection on the menu: Slave Info.
42
Page 44
Version The software version for the second CPU.
Status The status of the second CPU.
Channel Channel type Interleave or Fast for the second CPU. ADSL
supports two modes of transport called the fast channel and interleaved
channel. The fast channel is meant to transfer latency-critical but error
tolerant data streams like real time video. The interleaved path is a
slower but reliable path, and can be used for data that is intolerant to
errors like file transfer.
Mode Modulation protocol for the second CPU.
Rate (kbps) Current sync rate for the second CPU.
SNR Margin (dB) Signal to Noise Ratio (SNR) margin for the second CPU.
Attenuation (dB) Estimate of average loop attenuation in the downstream
direction for the second CPU.
Super Frames Total number of super frames for the second CPU.
Super Frame
Errors
43
Number of super frames received with errors for the second CPU.
Page 45
5.1 WAN
Select WAN from the Device Info menu to display the status of all configured PVC(s).
Port/VPI/VCI Shows the values of the ATM Port/VPI/VCI
VLAN Mux Shows 802.1Q VLAN ID
Con. ID Shows the connection ID
Category Shows the ATM service classes
Service Shows the name for WAN connection
Interface Shows connection interfaces
Protocol Shows the connection type, such as PPPoE, PPPoA, etc.
IGMP Shows the statue of the IGMP function
State Shows the connection state of the WAN connection
Status Lists the status of DSL link
IP Address Shows IP address for WAN interface
44
Page 46
5.2 Statistics
Selection of the Statistics option provides statistics for the Network Interface of LAN,
WAN, ATM and ADSL. These statistics screens are updated every 15 seconds.
5.2.1 LAN Statistics
The Network Statistics screen shows interface statistics for Ethernet and Wireless
interfaces. (The Network Statistics screen shows interface statistics for LAN of
Ethernet interface. Here provides byte transfer, packet transfer, Error and Drop
statistics for the LAN interface.)
eth0: Communication interface between internal CPUs.
45
Page 47
5.2.2 WAN Statistics
Service Shows the service type
VPI/VCI Shows the values of the ATM VPI/VCI
Protocol Shows the connection type, such as PPPoE,
PPPoA, etc.
Interface Shows connection interfaces
Received/Transmitted - Bytes
- Pkts
- Errs
- Drops
Rx/TX (receive/transmit) packets in bytes
Rx/TX (receive/transmit) packets
Rx/TX (receive/transmit) packets with errors
Rx/TX (receive/transmit) dropped packets
46
Page 48
5.2.3 ATM statistics
ATM Interface Statistics
Field Description
In Octets Number of received octets over the interface
Out Octets Number of transmitted octets over the interface
In Errors Number of cells dropped due to uncorrectable HEC errors
In Unknown Number of received cells discarded during cell header validation,
including cells with unrecognized VPI/VCI values, and cells with
invalid cell header patterns. If cells with undefined PTI values
are discarded, they are also counted here.
In Hec Errors Number of cells received with an ATM Cell Header HEX error
In Invalid Vpi Vci
Errors
In Port Not
Enabled Errors
Number of cells received with an unregistered VCC address.
Number of cells received on a port that has not been enabled.
In PTI Errors Number of cells received with an ATM header Payload Type
Indicator (PTI) error
In Idle Cells Number of idle cells received
In Circuit Type
Errors
47
Number of cells received with an illegal circuit type
Page 49
In Oam RM CRC
Errors
In GFC Errors Number of cells received with a non-zero GFC.
ATM AAL5 Layer Statistics over ADSL interface
Field Description
In Octets Number of received AAL5/AAL0 CPCS PDU octets
Out Octets Number of received AAL5/AAL0 CPCS PDUs octets transmitted
In Ucst Pkts Number of received AAL5/AAL0 CPCS PDUs passed to a
Out Ucast Pkts Number of received AAL5/AAL0 CPCS PDUs received from a
In Errors Number of received AAL5/AAL0 CPCS PDUs received that
Number of OAM and RM cells received with CRC errors
higher-layer for transmission
higher layer for transmissions
contain an error. The types of errors counted include CRC-32
errors.
Out Errors Number of received AAL5/AAL0 CPCS PDUs that could be
transmitted due to errors.
In Discards Number of received AAL5/AAL0 CPCS PDUs discarded due to
an input buffer overflow condition.
Out Discards This field is not currently used
ATM AAL5 Layer Statistics for each VCC over ADSL interface
Field Description
CRC Errors Number of PDUs received with CRC-32 errors
SAR TimeOuts Number of partially re-assembled PDUs which were discarded
because they were not fully re-assembled within the required
period of time. If the re-assembly time is not supported
then, this object contains a zero value.
Over Sized SDUs Number of PDUs discarded because the corresponding SDU
was too large
Short Packets Errors Number of PDUs discarded because the PDU length was less
than the size of the AAL5 trailer
Length Errors Number of PDUs discarded because the PDU length did not
match the length in the AAL5 trailer
48
Page 50
5.2.4 ADSL Statistics
The following graphic shows the ADSL Network Statistics screen. Within the ADSL
Statistics window, a Bit Error Rate (BER) test can be done using the ADSL BER Test
button. The Reset Statistics button refreshes the statistics.
NOTE: This screen displays information for ADSL1. Please refer to Slave Info at
the beginning of this chapter for ADSL2.
Consult the table that follows for descriptions of each field in the table.
49
Page 51
Field Description
Mode Line Coding format
Type Channel type: Interleave or Fast
Line Coding Trellis On/Off
Status Lists the status of the ADSL link
Link Power State Link output power state.
SNR Margin (dB) Signal to Noise Ratio (SNR) margin
Attenuation (dB) Estimate of average loop attenuation in the downstream
direction.
Output Power (dBm) Total upstream output power
Attainable Rate (Kbps) The sync rate you would obtain.
Rate (Kbps) Current sync rate.
K Number of bytes in DMT frame
R Number of check bytes in RS code word
S RS code word size in DMT frame
D The interleaver depth
Delay The delay in milliseconds (msec)
Super Frames Total number of super frames
Super Frame Errors Number of super frames received with errors
RS Words Total number of Reed-Solomon code errors
RS Correctable Errors Total Number of RS with correctable errors
RS Uncorrectable Errors Total Number of RS words with uncorrectable errors
HEC Errors Total Number of Header Error Checksum errors
OCD Errors Total Number of out-of-cell Delineation errors
LCD Errors Total number of Loss of Cell Delineation
Total Cells Total number of ATM cells (including idle and data cells)
Data Cells Total number of ATM data cells
Bit Errors Total number of bit errors
Tot al E S : Tot al N um b e r o f Er r o r ed Se c o n ds
Total SES: Total Number of Severely Errored Seconds
NOTE: Shown below are the menu options for each connection type.
This screenshot is for PPPoE and PPPoA encapsulations.
This screenshot is for MER and IPoA encapsulations.
53
Page 55
This screenshot shows MAC Filtering which is available only with Bridge connections.
/
(
Q
6.1 WAN
Port
VPI/VCI ATM Port
VLAN Mux Shows 802.1Q VLAN ID
Con. ID ID for WAN connection
Category ATM se rvice category, e.g. UBR, CBR…
Service Name of the WAN connection
Interface Name of the interface for WAN
Protocol Shows bridge or router mode
IGMP Shows enable or disable IGMP proxy
oS Shows enable or disable QoS
State Shows enable or disable WAN connection
0-3) / VPI (0-255) / VCI (32-65535)
54
Page 56
6.2 LAN
Configure the ADSL Router IP Address and Subnet Mask for LAN interface. Save
button only saves the LAN configuration data. Save/Reboot button saves the LAN
configuration data and reboots the device to make the new configuration effective.
(Slave) IP Address: Enter the IP address for the LAN port.
(Slave) Subnet Mask: Enter the subnet mask for the LAN port.
Enable IGMP Snooping: Enable /Disable the function that is IGMP Snooping.
Standard Mode: In standard mode, as in all prior releases, multicast traffic will
flood to all bridge ports when there is no client subscribes to any multicast group –
even when IGMP snooping is enabled.
Blocking Mode: In blocking mode, the multicast data traffic will be blocked and not
flood to all bridge ports when there are no client subscriptions to any multicast
group.
To configure a secondary IP address for the LAN port, click the box as shown below.
55
Page 57
6.3 NAT
To display the NAT function, the NAT option must be enabled in WAN Setup.
6.3.1 Virtual Servers
Virtual Server allows you to direct incoming traffic from WAN side (identified by
Protocol and External port) to the Internal server with private IP address on the LAN
side. The Internal port is required only if the external port needs to be converted to
a different port number used by the server on the LAN side. A maximum 32 entries
can be configured.
To add a Virtual Server, simply click the Add button.
The following screen will be displayed.
56
Page 58
Select a Service
or
Custom Server
Server IP Address Enter the IP address for the server.
External Port Start Enter the starting external port number (when you select
External Port End Enter the ending external port number (when you select
Protocol User can select from: TCP, TCP/UDP or UDP.
Internal Port Start Enter the internal port starting number (when you select
Internal Port End Enter the internal port ending number (when you select
User should select the service from the list.
or
User can enter the name of their choice.
Custom Server). When a service is selected the port ranges
are automatically configured.
Custom Server). When a service is selected the port ranges
are automatically configured.
Custom Server). When a service is selected the port ranges
are automatically configured
Custom Server). When a service is selected the port ranges
are automatically configured.
57
Page 59
6.3.2 Port Triggering
Some applications require that specific ports in the router’s firewall be opened for
access by the remote parties. Port Trigger dynamically opens up the ‘Open Ports’ in
the firewall when an application on the LAN initiates a TCP/UDP connection to a
remote party using the ‘Triggering Ports’. The router allows the remote party from
the WAN side to establish new connections back to the application on the LAN side
using the ‘Open Ports’. A maximum 32 entries can be configured.
To add a Trigger Port, simply click the Add button. The following will be displayed.
58
Page 60
Select an Application
User should select the application from the list.
Or Custom Application
Trigger Port Start Enter the starting trigger port number (when you select
Trigger Port End Enter the ending trigger port number (when you select
Trigger Protocol User can select from: TCP, TCP/UDP or UDP.
Open Port Start Enter the starting open port number (when you select
Open Port End Enter the ending open port number (when you select
Open Protocol User can select from: TCP, TCP/UDP or UDP.
Or User can enter the name of their choice.
custom application). When an application is selected the
port ranges are automatically configured.
custom application). When an application is selected the
port ranges are automatically configured.
custom application). When an application is selected the
port ranges are automatically configured.
custom application). When an application is selected the
port ranges are automatically configured.
6.3.3 DMZ Host
The ADSL router will forward IP packets from the WAN that do not belong to any of
the applications configured in the Virtual Servers table to the DMZ host computer.
Enter the computer’s IP address and click Save/Apply to activate the DMZ host.
Clear the IP address field and click Save/Apply to deactivate the DMZ host.
59
Page 61
6.3.4 ALG
SIP ALG is Application layer gateway. If the user has an IP phone (SIP) or VoIP
gateway (SIP) behind the ADSL router, the SIP ALG can help VoIP packet
passthrough the router (NAT enabled).
NOTE: SIP (Session Initiation Protocol, RFC3261) is the protocol of choice for
most VoIP (Voice over IP) phones to initiate communication. This ALG is
only valid for SIP protocol running UDP port 5060.
60
Page 62
6.4 Security
To display the Security function, the firewall option must be enabled in WAN Setup.
6.4.1 MAC Filtering
Each network device has a unique MAC address. You can block or forward the
packets based on the MAC addresses. The MAC Filtering Setup screen allows for
the setup of the MAC filtering policy and rules.
NOTE:This function is only available when in bridge mode. Instead of MAC
filtering, the other connection types use IP Filtering (pg. 62).
The policy FORWARDED means that all MAC layer frames will be FORWARDED
except those matching with any of the specified rules in the following table.
BLOCKED means that all MAC layer frames will be BLOCKED except those
matching with any of the specified rules in the following table. The default is
FORWARDED; this is changed by clicking the Change Policy button.
Choose Add or Remove to configure MAC filtering rules. The following screen
pops up when you click Add. Create a filter to identify the MAC layer frames by
specifying at least one condition below. If multiple conditions are specified, all of
them take effect. Click Save/Apply to save and activate the filter.
61
Page 63
Field Description
Protocol type PPPoE, IPv4, IPv6, AppleTalk, IPX, NetBEUI, IGMP
Destination MAC Address Defines the destination MAC address
Source MAC Address Defines the source MAC address
Frame Direction Select the incoming/outgoing packet interface
62
Page 64
6.4.2 IP Filtering
IP filtering allows you to create a filter rule to identify outgoing/incoming IP traffic
by specifying a new filter name and at least one condition below. All of the specified
conditions in this filter rule must be satisfied for the rule to take effect. Click
‘Save/Apply’ to save and activate the filter.
Outgoing
The default setting for all Outgoing traffic is ACCEPTED.
To add a filtering rule, click the Add button. The following screen will be displayed.
63
Page 65
Filter Name Type a name for the filter rule.
Protocol User can select: TCP, TCP/UDP, UDP or ICMP.
Source IP address Enter source IP address.
Source Subnet Mask Enter source subnet mask.
Source Port (port or port:port) Enter source port number.
Destination IP address Enter destination IP address.
Destination Subnet Mask Enter destination subnet mask.
Destination port (port or port:port) Enter destination port number.
64
Page 66
Incoming
The default setting for all Incoming traffic is Blocked.
To add a filtering rule, click the Add button. The following screen will be displayed.
To configure the parameters, please reference Outgoing table above.
65
Page 67
6.4.3 Parental Control
This allows parents, schools, and libraries to set access times for Internet use.
To add a parental control click the Add button and the following screen will display.
Username Name of the Filter.
MAC Address Displays MAC address of the LAN device on
which the browser is running.
Days of the week (Mon – Sun) Days when the restrictions are applied.
Start/End Blocking Times The times when restrictions start and stop.
66
Page 68
6.5 Quality of Service
NOTE: QoS is not yet supported for bonded routers. However, it is included here
in the event that a future firmware upgrade supports this feature.
6.5.1 Queue Management Configuration
Quality of service: Quality of Service can provide different priority to different
users or data flows, or guarantee a certain level of performance to a data flow in
accordance with requests from Queue Prioritization.
Differentiated Services Code Point (DSCP): You can assign DSCP mark that
specifies the per hop behavior for a given flow of packets in the Internet Protocol (IP)
header.
6.5.2 QoS Queue Configuration
This follows the “Differentiated Services” rule of IP QoS. You can create a new
Queue rule by assigning interface, Enable/Disable and Precedence. This router uses
various queuing strategies to tailor performance to requirements.
67
Page 69
Click Add to display the following screen.
Queue Configuration Status: Make the queue Enable/Disable.
Queue: Assign queue to a specific network interface whose QoS is enabled.
Queue Precedence: Configure precedence for queue. Lower integer values for
precedence imply higher priority for this queue relative to others.
68
Page 70
Click Add to configure network traffic classes.
This screen creates a traffic class rule to classify the upstream traffic, assign
queuing priority and optionally overwrite the IP header TOS byte. A rule consists of
a class name and at least one condition below. All of the specified conditions in this
classification rule must be satisfied for the rule to take effect.
Click Save/Apply to save and activate the rule.
69
Page 71
6.6 Routing
6.6.1 Default Gateway
If the Enable Automatic Assigned Default Gateway checkbox is selected, the
default gateway will be assigned based on a DHCP enabled PVC. If the checkbox is
not selected, enter the static default gateway AND/OR WAN interface.
Click Save/Apply to save it.
NOTE: After enabling the Automatic Assigned Default Gateway, you must
reboot the router to activate it.
70
Page 72
6.6.2 Static Route
This screen lists the configured static routes and allows configuring of static routes.
Choose Add or Remove to configure the static routes.
To add static route, click the Add button to display the following screen. Enter the
destination network address, subnet mask, gateway AND/OR available WAN
interface then click Save/Apply to add the entry to the routing table.
71
Page 73
6.6.3 RIP
To activate RIP for the device, select the Enabled radio button for Global RIP Mode.
To configure an individual interface, select the desired RIP version and operation,
followed by placing a check in the Enabled checkbox for the interface.
Click Save/Apply to start/stop RIP based on the Global RIP mode selected.
NOTE: This screenshot is based on PPPoE encapsulation.
72
Page 74
6.7 DNS
6.7.1 DNS Server
If Enable Automatic Assigned DNS checkbox is selected, this router will accept
the first received DNS assignment from one of the DHCP enabled PVCs during the
connection establishment. If the checkbox is not selected, enter the primary and
optional secondary DNS server IP addresses. Click the Save button to save the new
configuration. You must reboot the router to make the new configuration effective.
6.7.2 Dynamic DNS
The Dynamic DNS service allows you to alias a dynamic IP address to a static
hostname in any of the man y domains, allowing your ADSL router to be mor e easil y
accessed from various locations on the Internet.
73
Page 75
NOTE: The Add and Remove buttons will only be displayed if the CPE has
already been assigned an IP address from the remote server.
To add a dynamic DNS service, click Add and the following screen will be displayed:
D-DNS provider Select a dynamic DNS provider from the list.
Hostname Enter the name for the dynamic DNS server.
Interface Select the interface from the list.
Username Enter the username for the dynamic DNS server.
Password Enter the password for the dynamic DNS server.
74
Page 76
6.8 DSL / Slave DSL
To access the ADSL settings, first click On Advanced Setup and then click on DSL.
This screen shows the settings available for ADSL1. For ADSL2 use Slave DSL.
NOTE: Annex M is enabled by default for this router.
75
Page 77
The Slave DSL settings screen is shown below.
This table describes the DSL settings.
Option Description
G.dmt Enabled Sets G.Dmt if you want the system to use G.Dmt mode.
G.Lite Enabled Sets G.Lite if you want the system to use G.Lite mode.
T1.413 Enabled Sets the T1.413 if you want the system to use only T1.413
mode.
ADSL2 Enabled The device can support the functions of the ADSL2.
AnnexL Enabled The device can support/enhance the long loop test.
ADSL2+ Enabled The device can support the functions of the ADSL2+.
AnnexM Enabled Covers a higher “upstream” data rate version, by making use of
some of the downstream channels.
Inner Pair Reserved only
Outer Pair Reserved only
Bitswap Enable Allows bitswapping function
SRA Enable Allows seamless rate adaptation
76
Page 78
6.9 Print Server
This router is equipped with one high-speed USB2.0 host connection. With
software support, users can connect USB devices such as a printer and hard disc to
the router. For this software release, printer server is supported.
Please refer to Appendix A: Printer Server for detailed installation instructions.
77
Page 79
6.10 Port Mapping
Port Mapping supports multiple port to PVC and bridging groups. Each group will
perform as an independent network. To support this feature, you must create
mapping groups with appropriate LAN and WAN interfaces using the Add button.
The Remove button will remove the grouping and add the ungrouped interfaces to
the Default group.
As shown below, when you tick the Enable virtual ports on checkbox, all of the
LAN interfaces will be grouped together.
To add a port mapping group, click the Add button.
78
Page 80
To create a group from the list, first enter the group name and then select from the
available interfaces on the list.
Automatically Add Clients With the Following DHCP Vendor IDs:
Add support to automatically map LAN interfaces including Wireless and USB to
PVC's using DHCP vendor ID (option 60). The local DHCP server will decline and
send the requests to a remote DHCP server by mapping the appropriate LAN
interface. This will be turned on when PortMapping is enabled.
There are 4 PVCs (0/33, 0/36, 0/37, 0/38). VPI/VCI=0/33 is for PPPoE and the
others are for IP set-top box (video). The LAN interfaces are ENET1, ENET2, ENET3,
ENET4, Wireless and USB.
The Port Mapping configuration is:
1. Default: ENET1, ENET2, ENET3, ENET4, Wireless and USB.
2. Video: nas_0_36, nas_0_37 and nas_0_38. The DHCP vendor ID is "Video".
79
Page 81
The CPE deco server is running on "Default". And ISP's deco server is running on
PVC 0/36. It is for set-top box use only.
On the LAN side, the PC can get IP address from CPE deco server and access the
Internet via PPPoE (0/33).
If the set-top box was connected with interface "ENET1" and send a deco request
with vendor id "Video", the CPE deco server would forward this request to ISP's deco
server. Then the CPE will change the PortMapping configuration automatically.
The Port Mapping configuration will become:
1. Default: ENET2, ENET3, ENET4, Wireless and USB.
2. Video: nas_0_36, nas_0_37, nas_0_38 and ENET1.
6.11 IPSec
You can add, edit or remove IPSec tunnel mode connections from this page.
By clicking Add New Connection, you can add a new IPSec termination rule.
The following screen will display.
80
Page 82
IPSec Connection Name User-defined label
Remote IPSec Gateway Address
(IP or Domain Name)
Tunnel access from local IP
addresses
IP Address for VPN If you choose “single”, please entry the host
Tunnel access from remote IP
addresses
IP Address for VPN If you choose “single”, please entry the host
The IP address of remote tunnel Gateway,
and you can use numeric address and
domain name
It chooses methods that specify the
acceptable host IP on the local side. It has
single and subnet.
IP address for VPN. If you choose “subnet”,
please entry the subnet information for VPN.
It chooses methods that specify the
acceptable host IP on the remote side. It
has single and subnet.
IP address for VPN. If you choose “subnet”,
please entry the subnet information for VPN.
81
Page 83
Key Exchange Method It has two modes. One is auto and the other
is manual.
Authentication Method It has either pre-shared key or x.509.
Pre-Shared Key Input Pre-shared key
Perfect Forward Secrecy Enable/disable the method that is Perfect
Forward Secrecy.
Advanced IKE Settings On IPSec Auto mode, you need to choose
the setting of two phases. Click the button
then choose which modes, Encryption
Algorithm, Integrity Algorithm, Select
Diffie-Hellman Group for Key Exchange, key
time on different phases.
6.12 Certificate
A certificate is a public key, attached with its owner’s information (company name,
server name, personal real name, contact e-mail, postal address, etc) and digital
signatures. There will be one or more digital signatures attached to the certificate,
this indicates that these signatories have verified that the certificate is valid.
6.12.1 Local
82
Page 84
Certificate Name A user-defined name for the certificate.
Common Name Usually, it is the fully qualified domain name for the
machine.
Organization Name The exact legal name of your organization. Do not
abbreviate.
State/Province Name The state or province where your organization is located. It
cannot be abbreviated.
Country/Region Name The two-letter ISO abbreviation for your country.
Click Create Certificate Request to generate a certificate signing request. The
certificate signing request can be submitted to the vendor/ISP/ITSP to apply for a
certificate. Some information must be included in the certificate signing request.
Actually, your vendor/ISP/ITSP will ask you to provide the information they require
and to provide the information in the format they regulate. The explanation for each
column in the following table is only for reference.
Click Apply to generate a private key and a certificate signing request.
This screen is used to paste the certificate content and the private key provided by
83
Page 85
your vendor/ISP/ITSP.
6.12.2 Trusted CA
CA is the abbreviation for Certificate Authority. CA is a part of the X.509 system. It
is itself a certificate, attached with the owner information of this certificate authority.
But its purpose is not to do encryption/decryption. Its purpose is to sign and issue
certificates; in order to prove the owner information of that certificate is correct.
84
Page 86
Click Import Certificate to paste the certificate content of your trusted CA.
Generally speaking, the certificate content will be provided by your vendor/ISP/ITSP
and is used to authenticate the Auto-Configuration Server (ACS) that the CPE will
connect to.
85
Page 87
Chapter 7 Wireless
The Wireless dialog box allows you to enable the wireless capability, hide the access
point, set the wireless network name and restrict the channel set.
7.1 Basic
The Basic option allows you to configure basic features of the wireless LAN interface.
You can enable or disable the wireless LAN interface, hide the network from active
scans, set the wireless network name (also known as SSID) and restrict the channel
set based on country requirements.
Click Save/Apply to configure the basic wireless options.
Consult the table below for descriptions of these options.
Option Description
Enable Wireless A checkbox that enables or disables the wireless LAN interface.
When selected, the Web UI displays Hide Access point, SSID,
and County settings. Wireless is enabled by default.
86
Page 88
Hide Access Point Select Hide Access Point to protect the access point from
)
detection by wireless active scans. If you do not want the
access point to be automatically detected by a wireless station,
this checkbox should be de-selected. The station will not
discover this access point. To connect a station to the
available access points, the station must manually add this
access point name in its wireless configuration. In Windows
XP, go to the Network Æ Programs function to view all of the
available access points. You can also use other software
programs such as NetStumbler to view available access points.
Clients Isolation 1. Prevents clients PC from seeing one another in My Network
Places or Network Neighborhood.
2. Prevents one wireless client communicating with another
wireless client.
Disable WMM
Advertise
Stops the router from ‘advertising’ its Wireless Multimedia
(WMM) functionality, which provides basic quality of service for
time-sensitive applications (e.g. VoIP, Video).
(wireless software version 3.10 and above
SSID Sets the wireless network name. SSID stands for Service Set
Identifier. All stations must be configured with the correct
SSID to access the WLAN. If the SSID does not match, that
user will not be granted access.
The naming conventions are: Minimum is one character and
maximum number of characters: 32 bytes.
BSSID The BSSID is a 48bit identity used to identify a particular BSS
(Basic Service Set) within an area. In Infrastructure BSS
networks, the BSSID is the MAC (Medium Access Control)
address of the AP (Access Point) and in Independent BSS or ad
hoc networks, the BSSID is generated randomly.
Country A drop-down menu that permits worldwide and specific
national settings. Each county listed in the menu enforces
specific regulations limiting channel range:
• US= worldwide
• Japan=1-14
• Jordan= 10-13
• Israel= 1-13
Max Clients The maximum number of clients that can access the router.
87
Page 89
Wireless - Guest /
This router supports multiple SSIDs called Guest SSIDs or
Virtual Access
Points
Virtual Access Points. To enable one or more Guest SSIDs
select the radio buttons under the Enable heading. To hide a
Guest SSID select its radio button under the Hidden heading.
Do the same for Isolate Client and Disable WMM Advertise
functions. For a description of these two functions, see the
entries for “Clients Isolation” and “Disable WMM Advertise” in
this table. Similarly, for Max Clients and BSSID headings,
consult the matching entries in this table.
NOTE: Remote wireless hosts are unable to scan Guest SSIDs.
88
Page 90
7.2 Security
Security options include authentication and encryption services based on the wired
equivalent privacy (WEP) algorithm. WEP is a set of security services used to
protect 802.11 networks from unauthorized access, such as eavesdropping; in this
case, the capture of wireless network traffic. When data encryption is enabled,
secret shared encryption keys are generated and used by the source station and the
destination station to alter frame bits, thus avoiding disclosure to eavesdroppers.
802.11 supports two subtypes of network authentication services: open system and
shared key. Under open system authentication, any wireless station can request
authentication. The system that needs to authenticate with another wireless
station sends an authentication management frame that contains the identity of the
sending station. The receiving station then sends back a frame that indicates
whether it recognizes the identity of the sending station.
Under shared key authentication, each wireless station is assumed to have received
a secret shared key over a secure channel that is independent from 802.11 wireless
network communications channel.
The following screen appears when Security is selected. The Security page allows
you to configure security features of the wireless LAN interface. You can set the
network authentication method, selecting data encryption, specify whether a
network key is required to authenticate to this wireless network and specify the
encryption strength.
Click Apply to configure the wireless security options.
89
Page 91
Option Description
g
Select SSID Sets the wireless network name. SSID stands for Service Set
Network
Authentication
Identifier. All stations must be confi
access the WLAN. If the SSID does not match, that user will not be
granted access.
The naming conventions are: Minimum is one character and
maximum number of characters: 32 bytes.
It specifies the network authentication. When this checkbox is
selected, it specifies that a network key be used for authentication to
the wireless network. If the Network Authentication (Shared mode)
checkbox is not shared (that is, if open system authentication is
used), no authentication is provided. Open system authentication
only performs identity verifications.
Different authentication type pops up different settings requests.
Choosing 802.1X, enter RADIUS Server IP address, RADIUS Port,
and RADIUS key.
ured with the correct SSID to
Also, enable WEP Encryption and the Encryption Strength.
Select the Current Network Key and enter 13 ASCII characters or 26
hexadecimal digits for 128-bit encryption keys and enter 5 ASCII
characters or 10 hexadecimal digits for 64-bit encryption keys.
90
Page 92
Choosing WPA, you must enter WPA Group Rekey Interval.
g
g
Choosing WPA-PSK, you must enter WPA Pre-Shared Key and
Group Rekey Interval.
WEP
Encryption
Encryption
strength
It specifies that a network key is used to encrypt the data is sent over
the network. When this checkbox is selected, it enables data
encryption and prompts the Encryption Strength drop-down menu.
Data Encryption (WEP Enabled) and Network Authentication use the
same key.
A session’s key strength is proportional to the number of binary bits
comprisin
greater number of bits have a greater degree of security, and are
considerably more difficult to forcibly decode. This drop-down
menu sets either a 64 8-bit (5-ASCII character or 10-hexadecimal
character) or 128 8-bit (13-ASCII character or 26-hexadecimal
character) key.
If you set a minimum 128-bit key strength, users attempting to
establish a secure communications channel with your server must
use a browser capable of communicating with a 128-bit session key.
The Encryption Stren
Authentication (shared Mode) check box is selected.
the session key file. This means that session keys with a
th settings do not display unless the network
91
Page 93
7.3 MAC Filter
This MAC Filter page allows access to be restricted or allowed based on a MAC
address. All NICs have a unique 48-bit MAC address burned into the ROM chip on the
card. When MAC address filtering is enabled, you are restricting the NICs that are
allowed to connect to your access point. Therefore, an access point will grant
access to any computer that is using a NIC whose MAC address is on its “allows” list.
WiFi devices and access points that support MAC filtering let you specify a list of MAC
addresses that may connect to the access point, and thus dictate what devices are
authorized to access the wireless network. When a device is using MAC filtering,
any address not explicitly defined will be denied access.
MAC Restrict mode: Off- disables MAC filtering; Allow – permits access for the
specified MAC address; deny; reject access of the specified MAC address, then click
the SET button.
To delete an entry, select the entry at the bottom of the screen and then click the
Remove button, located on the right hand side of the screen.
To add a MAC entry, click Add and enter MAC address
92
Page 94
After clicking the Add button, the following screen appears. Enter the MAC
address and click Apply to add the MAC address to the wireless MAC address filters.
Option Description
MAC
Restrict
Mode
MAC
Address
93
Radio buttons that allow settings of;
Off: MAC filtering function is disabled.
Allow: Permits PCs with listed MAC addresses to connect to access point.
Deny: Prevents PCs with listed MAC from connecting to the access point.
Lists the MAC addresses subject to the Off, Allow, or Deny instruction.
The Add button prompts an entry field that requires you type in a MAC
address in a two-character, 6-byte convention: xx:xx:xx:xx:xx:xx where
xx are hexadecimal numbers. The maximum number of MAC addresses
that can be added is 60.
Page 95
7.4 Wireless Bridge
This page allows you to configure wireless bridge features of the wireless LAN
interface. You can select Wireless Bridge (also known as Wireless Distribution
System) to disable access point functionality. Selecting Access Point enables access
point functionality. Wireless bridge functionality will still be available and wireless
stations will be able to associate to the AP. Select Disabled in Bridge Restrict, which
disables wireless bridge restriction. Any wireless bridge will be granted access.
Selecting Enabled or Enabled (Scan) enables wireless bridge restriction. Only those
bridges selected in Remote Bridges will be granted access.
Feature Options
AP Mode Access Point
Wireless Bridge
Bridge Restrict Enabled
Enabled (Scan)
Disabled
7.5 Advanced
The Advanced page allows you to configure advanced features of the wireless LAN
interface. You can select a particular channel on which to operate, force the
transmission rate to a particular speed, set the fragmentation threshold, set the RTS
threshold, set the wakeup interval for clients in power-save mode, set the beacon
interval for the access point, set XPress mode and set whether short or long
preambles are used.
94
Page 96
Click Apply to configure the advanced wireless options.
g
Option Description
Band The new amendment allows IEEE 802.11g units to fall back to
speeds of 11 Mbps, so IEEE 802.11b and IEEE 802.11
coexist in the same network. The two standards apply to the 2.4
GHz frequency band. IEEE 802.11g creates data-rate parity at 2.4
GHz with the IEEE 802.11a standard, which has a 54 Mbps rate at
5 GHz. (IEEE 802.11a has other differences compared to IEEE
802.11b or g, such as offering more channels.)
Channel Drop-down menu that allows selection of a specific channel.
Auto Channel
Timer (min)
54g Rate Drop-down menu that specifies the following fixed rates: Auto:
Auto channel scan timer in minutes (0 to disable)
Default. Uses the 11 Mbps data rate when possible but drops to
lower rates when necessary. 1 Mbps, 2Mbps, 5.5Mbps, or 11Mbps
devices can
fixed rates. The appropriate setting is dependent on signal
RTS Threshold Request to Send, when set in bytes, specifies the packet size
A threshold, specified in bytes, that determines whether packets
will be fra
that exceed the fra
into, smaller units suitable for the circuit size. Packets smaller
than the specified fragmentation threshold value are not
fragmented.
Enter a value between 256 and 2346.
If you experience a high packet error rate, try to slightly increase
your Fragmentation Threshold. The value should remain at its
default settin
low may result in poor performance.
beyond which the WLAN Card invokes its RTS/CTS mechanism.
Packets that exceed the specified RTS threshold trigger the
RTS/CTS mechanism. The NIC transmits smaller packet without
using RTS/CTS. The default setting of 2347 (maximum length)
disables RTS Threshold.
mented and at what size. On an 802.11 WLAN, packets
mentation threshold are fragmented, i.e., split
of 2346. Setting the Fragmentation Threshold too
DTIM Interval Delivery Traffic Indication Message (DTIM), also known as Beacon
Rate. The entry range is a value between 1 and 65535. A DTIM is
a countdown informing clients of the next window for listening to
broadcast and multicast messages. When the AP has buffered
broadcast or multicast messa
next DTIM with a DTIM Interval value. AP Clients hear the
beacons and awaken to receive the broadcast and multicast
messages. The default is 1.
Beacon Interval The amount of time between beacon transmissions. Each beacon
transmission identifies the presence of an access point. By
default, radio NICs passively scan all RF channels and listen for
beacons coming from access points to find a suitable access point.
Before a station enters power save mode, the station needs the
beacon interval to know when to wake up to receive the beacon
(and learn whether there are buffered frames at the access point).
The entered value is represented in ms. Default is 100.
Acceptable entry range is 1 to 0xffff (65535)
es for associated clients, it sends the
96
Page 98
g
Xpress
TM
Xpress Technology is compliant with draft specifications of two
Tec hn o lo g y
TM
54g
Mode Set the mode to 54g Auto for
planned wireless industry standards.
the widest compatibility. Select the mode to
54g Performance for the fastest performance
among 54g certified equipment. Set
the mode to 54g LRS if you are experiencing
difficulty with legacy 802.11b equipment.
54g Protection In Auto mode the router will use
RTS/CTS to improve 802.11g performance in
mixed 802.11g/802.11b networks. Turn
protection off to maximize 802.11g throughput
under most conditions.
Preamble Type Short preamble is intended for application where maximum
throughput is desired but it doesn’t cooperate with the legacy.
Lon
preamble interoperates with the current 1 and 2 Mbit/s DSSS
specification as described in IEEE Std 802.11-1999
Transmit Power The router will set different power output (by percentage)
according to this selection.
WMM (Wi-Fi
Multimedia)
The technology maintains the priority of audio, video and voice
applications in a Wi-Fi network. It allows multimedia service get
higher priority.
WMM No
Acknowledgem
ent
Refers to the acknowledge policy used at the MAC level. Enabling
no Acknowledgement can result in more efficient throughput but
higher error rates in a noisy Radio Frequency (RF) environment.
WMM APSD This is Automatic Power Save Delivery. It saves power.
97
Page 99
7.6 Station Info
g
This page shows authenticated wireless stations and their status.
MAC Lists the MAC address of all the stations.
Associated Lists all the stations that are associated with the Access
Point, along with the amount of time since packets were transferred
to and from each station. If a station is idle for too lon
from this list.
Authorized Lists those devices with authorized access.
SSID Lists which SSID of the modem that the stations connect to.
Interface Lists which interface of the modem that the stations connect to.
, it is removed
98
Page 100
Chapter 8 Diagnostics
g
The Diagnostics screen provides feedback on the connection status of the router and
the ADSL link. The individual tests are listed below. If a test displays a fail status,
click the Test button, to determine whether the fail status is consistent. If the test
continues to fail, click Help and follow the troubleshooting procedures.
Test Description
Ethernet Connection Pass: indicates that the Ethernet interface from your
computer is connected to the LAN port of your router. A
flashing or solid green LAN LED on the router also signifies
that an Ethernet connection is present and that this test is
successful.
Fail: Indicates that the router does not detect the Ethernet
interface on your computer.
USB Connection Pass: Indicates that the USB interface from your computer is
connected to router properly.
Down: Indicates that the router does not detect the signal
from USB interface.
Wireless Connection Pass: Indicates that the Wireless interface from your
computer is connected to the wireless network.
Down: Indicates that the ADSL router does not detect the
wireless network.
ADSL
Synchronization
Pass: Indicates that the router has detected an ADSL signal
from the telephone company. A solid WAN LED on the router
also indicates the detection of an ADSL signal from the
telephone company.
Fail: Indicates that the router does not detect a si
the telephone company’s DSL network. The WAN LED will
continue to flash green.
nal from
99
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.