Draytek Vigor2912, Vigor2912F, Vigor2912n, Vigor2912Fn User Manual

Page 1
Page 2
Vigor2912 Series User’s Guide
ii
Page 3
Vigor2912 Series User’s Guide
Vigor2912 Series
Dual-WAN Security Router
User’s Guide
Version: 1.7
Firmware Version: V3.8.1.3
(For future update, please visit DrayTek web site)
Date: September 20, 2016
Page 4
Vigor2912 Series User’s Guide
iv
Intellectual Property Rights (IPR) Information
Copyrights
© All rights reserved. This publication contains information that is protected by copyright. No part may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language without written permission from the copyright holders.
Trademarks
The following trademarks are used in this document:
Microsoft is a registered trademark of Microsoft Corp. Windows, Windows 95, 98, Me, NT, 2000, XP, Vista, 7 and Explorer are
trademarks of Microsoft Corp.
Apple and Mac OS are registered trademarks of Apple Inc. Other products may be trademarks or registered trademarks of their respective
manufacturers.
Safety Instructions and Approval
Safety Instructions
Read the installation guide thoroughly before you set up the router. The router is a complicated electronic unit that may be repaired only be
authorized and qualified personnel. Do not try to open or repair the router yourself.
Do not place the router in a damp or humid place, e.g. a bathroom. The router should be used in a sheltered area, within a temperature range of +5 to
+40 Celsius.
Do not expose the router to direct sunlight or other heat sources. The housing and
electronic components may be damaged by direct sunlight or heat sources.
Do not deploy the cable for LAN connection outdoor to prevent electronic shock
hazards.
Keep the package out of reach of children. When you want to dispose of the router, please follow local regulations on
conservation of the environment.
Warranty
We warrant to the original end user (purchaser) that the router will be free from any defects in workmanship or materials for a period of two (2) years from the date of purchase from the dealer. Please keep your purchase receipt in a safe place as it serves as proof of date of purchase. During the warranty period, and upon proof of purchase, should the product have indications of failure due to faulty workmanship and/or materials, we will, at our discretion, repair or replace the defective products or components, without charge for either parts or labor, to whatever extent we deem necessary tore-store the product to proper operating condition. Any replacement will consist of a new or re-manufactured functionally equivalent product of equal value, and will be offered solely at our discretion. This warranty will not apply if the product is modified, misused, tampered with, dam aged by an act of God, or subjected to abnormal working conditions. The warranty does not cover the bundled or licensed software of other vendors. Defects which do not significantly affect the usability of the product will not be covered by the warranty. We reserve the right to revi se the m anual and onli ne documentation and to make changes from time to time in the contents hereof without obligation to notify any person of such revision or changes.
Be a Registered Owner
Web registration is preferred. You can register your Vigor router via http://www.DrayTek.com.
Firmware & Tools Updates
Due to the continuous evolution of DrayTek technology, all routers will be regularly upgraded. Please consult the DrayTek web site for more information on newest firmware, tools and documents.
http://www.DrayTek.com
Page 5
Vigor2912 Series User’s Guide
v
European Community Declarations
Manufacturer: DrayTek Corp. Address: No. 26, Fu Shing Road, Hukou Township, Hsinchu Industrial Park, Hsinchu County, Taiwan 303 Product: Vigor2912 Series Router
DrayTek Corp. declares that Vigor2912 Series of routers are in compliance with the following essential requirements and other relevant provisions of R&TTE 1999/5/EC, ErP 2009/125/EC and RoH S 201 1/65/EU
.
The product conforms to the requirements of Electro-Magnetic Compatibility (EMC) Directive 2004/108/EC by complying with the requirements set forth in EN55022/Class B and EN55024/Class B.
The product conforms to the requirements of Low Voltage (LVD) Directive 2006/95/EC by complying with the requirements set forth in EN60950-1.
This product is designed for 2.4GHz WLAN net work throughout the EC region.
Regulatory Information
Federal Communication Commission Interference Statement This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to Part
15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. This equipment generates, uses and can radiate radio frequency energy and, if not installed and used in accordance with the instructions, may cause harmful interference to radio communications. However, there is no guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to radio or televisio n recept i on , whi ch can be determined by turning the equipment of f and on, the user is encouraged to try to correct the interference by one of the following measures:
Reorient or relocate the receiving antenna. Increase the separation between the equipment and receiver. Connect the equipment into an outlet on a circuit different from that to which the receiver is connected. Consult the dealer or an experienced radio/TV technician for help.
This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions: (1) This device may not cause harmful interference, and (2) This device may accept any interference received, including interference that may cause undesired operation. This equipment complies with RFCC radiation exposure limits set forth for an uncontrolled environment. The antenna/transmitter should be kept at least 20 cm away from human body. Please visit http://www.draytek.com for more detailed information.
Page 6
Vigor2912 Series User’s Guide
vi
Page 7
Vigor2912 Series User’s Guide
vii
TTaabbllee ooff CCoonntteennttss
Introduction...................................................................................................1
1.1 Web Configuration Buttons Explanation................................................................................. 2
1.2 LED Indicators and Connectors.............................................................................................. 3
1.2.1 Vigor2912/Vigor2912F......................................................................................................3
1.2.2 Vigor2912n/Vigor2912Fn.................................................................................................. 5
1.3 Hardware Installation .............................................................................................................. 7
1.4 Printer Installation ................................................................................................................... 8
1.5 Accessing Web User Interface.............................................................................................. 16
1.6 Changing Password.............................................................................................................. 17
1.7 Web Console, Config Backup & Exit..................................................................................... 17
1.7.1 Web Console.................................................................................................................. 18
1.7.2 Config Backup ................................................................................................................ 19
1.7.3 Logout............................................................................................................................. 19
1.8 Online Status......................................................................................................................... 20
1.8.1 Physical Connection.......................................................................................................20
1.8.2 Virtual WAN.................................................................................................................... 22
1.9 Saving Configuration............................................................................................................. 22
Quick Setup.................................................................................................23
2.1 Quick Start Wizard................................................................................................................ 23
2.1.1 For WAN1 (Ethernet/Fiber) and WAN2 (Ethernet)......................................................... 25
2.1.2 For WAN3 (USB)............................................................................................................34
2.2 Service Activation Wizard...................................................................................................... 36
2.3 VPN Client Wizard ................................................................................................................ 39
2.4 VPN Server Wizard............................................................................................................... 45
2.5 Wireless Wizard.................................................................................................................... 50
2.6 Registering Vigor Router....................................................................................................... 53
Tutorials and Applications.........................................................................57
3.1 How to configure settings for IPv6 Service in Vigor2912...................................................... 57
3.2 How can I get the files from USB storage device connecting to Vigor router?..................... 67
3.3 How to Build a LAN-to-LAN VPN Between Remote Office and Headquarter via IPsec Tunnel
(Main Mode)................................................................................................................................ 70
3.4 How to Optimize the Bandwidth through QoS Technology................................................... 74
Page 8
Vigor2912 Series User’s Guide
viii
3.5 QoS Setting Example............................................................................................................ 78
3.6 How to use Landing Page Feature ....................................................................................... 82
3.7 How to Create an Account for MyVigor................................................................................. 86
3.7.1 Create an Account via Vigor Router............................................................................... 86
3.7.2 Create an Account via MyVigor Web Site ...................................................................... 90
3.8 How to Configure Certain Computers Accessing to Internet................................................ 94
3.9 How to Block Facebook Service Accessed by the Users via Web Content Filter / URL
Content Filter............................................................................................................................... 98
Advanced Configuration..........................................................................105
4.1 WAN.................................................................................................................................... 105
4.1.1 Basics of Internet Protocol (IP) Network....................................................................... 105
4.1.2 General Setup............................................................................................................... 107
4.1.3 Internet Access............................................................................................................. 112
4.1.4 Multi-VLAN.................................................................................................................... 140
4.2 LAN ..................................................................................................................................... 144
4.2.1 Basics of LAN ............................................................................................................... 144
4.2.2 General Setup............................................................................................................... 146
4.2.3 Static Route.................................................................................................................. 155
4.2.4 VLAN............................................................................................................................. 160
4.2.5 Bind IP to MAC............................................................................................................. 163
4.2.6 LAN Port Mirror............................................................................................................. 165
4.2.7 Web Portal Setup.......................................................................................................... 166
4.3 Load-Balance /Route Policy................................................................................................ 168
4.3.1 General Setup............................................................................................................... 169
4.3.2 Diagnose....................................................................................................................... 179
4.4 NA T..................................................................................................................................... 181
4.4.1 Port Redirection............................................................................................................ 182
4.4.2 DMZ Host...................................................................................................................... 185
4.4.3 Open Ports.................................................................................................................... 188
4.4.4 Port Triggering.............................................................................................................. 190
4.5 Firewall................................................................................................................................ 193
4.5.1 Basics for Firewall......................................................................................................... 193
4.5.2 General Setup............................................................................................................... 195
4.5.3 Filter Setup ................................................................................................................... 200
4.5.4 DoS Defense ................................................................................................................ 208
4.6 User Management............................................................................................................... 212
4.6.1 General Setup............................................................................................................... 213
4.6.2 User Profile................................................................................................................... 214
4.6.3 User Group................................................................................................................... 218
4.6.4 User Online Status........................................................................................................ 219
4.7 Objects Settings.................................................................................................................. 220
4.7.1 IP Object....................................................................................................................... 221
4.7.2 IP Group ....................................................................................................................... 224
4.7.3 IPv6 Object................................................................................................................... 225
4.7.4 IPv6 Group.................................................................................................................... 227
4.7.5 Service Type Object ..................................................................................................... 228
Page 9
Vigor2912 Series User’s Guide
ix
4.7.6 Service Type Group...................................................................................................... 230
4.7.7 Keyword Object ............................................................................................................231
4.7.8 Keyword Group............................................................................................................. 233
4.7.9 File Extension Object.................................................................................................... 234
4.7.10 SMS/Mail Service Object............................................................................................ 236
4.7.11 Notification Object....................................................................................................... 241
4.8 CSM Profile......................................................................................................................... 243
4.8.1 APP Enforcement Profile.............................................................................................. 244
4.8.2 URL Content Filter Profile............................................................................................. 247
4.8.3 Web Content Filter Profile............................................................................................. 252
4.8.4 DNS Filter Profile.......................................................................................................... 256
4.9 Bandwidth Management ..................................................................................................... 258
4.9.1 Sessions Limit............................................................................................................... 258
4.9.2 Bandwidth Limit ............................................................................................................260
4.9.3 Quality of Service.......................................................................................................... 262
4.10 Applications....................................................................................................................... 270
4.10.1 Dynamic DNS............................................................................................................. 270
4.10.2 LAN DNS.................................................................................................................... 274
4.10.3 Schedule..................................................................................................................... 277
4.10.4 RADIUS...................................................................................................................... 279
4.10.5 Active Directory/ LDAP............................................................................................... 280
4.10.6 UPnP........................................................................................................................... 283
4.10.7 IGMP........................................................................................................................... 284
4.10.8 Wake on LAN.............................................................................................................. 285
4.10.9 SMS / Mail Alert Service............................................................................................. 286
4.10.10 Bonjour ..................................................................................................................... 288
4.11 VPN and Remote A ccess.................................................................................................. 291
4.11.1 Remote Access Control.............................................................................................. 291
4.11.2 PPP General Setup .................................................................................................... 292
4.11.3 IPsec General Setup................................................................................................... 294
4.11.4 IPsec Peer Identity...................................................................................................... 296
4.11.5 Remote Dial-in User ................................................................................................... 298
4.11.6 LAN to LAN................................................................................................................. 301
4.11.7 VPN TRUNK Management......................................................................................... 312
4.11.8 Connection Management ........................................................................................... 316
4.12 Certificate Management.................................................................................................... 317
4.12.1 Local Certificate.......................................................................................................... 318
4.12.2 Trusted CA Certificate ................................................................................................ 321
4.12.3 Certificate Backup....................................................................................................... 322
4.13 Wireless LAN .................................................................................................................... 323
4.13.1 Basic Concepts........................................................................................................... 323
4.13.2 General Setup............................................................................................................. 325
4.13.3 Security....................................................................................................................... 327
4.13.4 Access Control............................................................................................................ 329
4.13.5 WPS............................................................................................................................ 330
4.13.6 WDS............................................................................................................................ 333
4.13.7 Advanced Setting........................................................................................................ 336
4.13.8 Station Control............................................................................................................ 339
4.13.9 AP Discovery.............................................................................................................. 340
4.13.10 Airtime Fairness........................................................................................................ 341
4.13.11 Station List................................................................................................................ 343
4.14 USB Application................................................................................................................ 344
4.14.1 USB General Settings................................................................................................. 344
Page 10
Vigor2912 Series User’s Guide
x
4.14.2 USB User Management.............................................................................................. 346
4.14.3 File Explorer................................................................................................................ 348
4.14.4 USB Device Status..................................................................................................... 349
4.14.5 Modem Support List.................................................................................................... 350
4.14.6 SMB Client Support List.............................................................................................. 350
4.15 System Maintenance......................................................................................................... 351
4.15.1 System Status............................................................................................................. 351
4.15.2 TR-069........................................................................................................................ 353
4.15.3 Administrator Password.............................................................................................. 355
4.15.4 User Password ........................................................................................................... 357
4.15.5 Login Page Greeting................................................................................................... 360
4.15.6 Configuration Backup ................................................................................................. 362
4.15.7 Syslog/Mail Alert......................................................................................................... 365
4.15.8 Time and Date............................................................................................................ 368
4.15.9 SNMP.......................................................................................................................... 370
4.15.10 Management............................................................................................................. 372
4.15.11 Reboot System......................................................................................................... 375
4.15.12 Firmware Upgrade.................................................................................................... 376
4.15.13 Activation.................................................................................................................. 377
4.16 Diagnostics........................................................................................................................ 379
4.16.1 Dial-out Triggering...................................................................................................... 379
4.16.2 Routing Table ............................................................................................................. 380
4.16.3 ARP Cache Table....................................................................................................... 381
4.16.4 IPv6 Neighbour Table................................................................................................. 381
4.16.5 DHCP Table................................................................................................................ 382
4.16.6 NAT Sessions Table................................................................................................... 383
4.16.7 DNS Cache Table....................................................................................................... 384
4.16.8 Ping Diagnosis............................................................................................................ 385
4.16.9 Data Flow Monitor....................................................................................................... 386
4.16.10 Traffic Graph............................................................................................................. 388
4.16.11 Trace Route.............................................................................................................. 389
4.16.12 Syslog Explorer......................................................................................................... 390
4.16.13 IPv6 TSPC Status..................................................................................................... 391
4.16.14 DoS Flood Table....................................................................................................... 392
4.17 External Devices............................................................................................................... 394
Trouble Shooting......................................................................................395
5.1 Checking If the Hardware Status Is OK or Not....................................................................395
5.2 Checking If the Network Connection Settings on Your Computer Is OK or Not ................. 396
5.3 Pinging the Router from Y our Computer............................................................................. 399
5.4 Checking If the ISP Settings are OK or Not........................................................................ 400
5.5 Problems for 3G Network Connection ................................................................................ 400
5.6 Backing to Factory Default Setting If Necessary ................................................................ 401
5.7 Contacting DrayTek............................................................................................................. 403
Appendix I: VLAN Applications on Vigor Router........................................................405
Page 11
Vigor2912 Series User’s Guide
1
IInnttrroodduuccttiioonn
Vigor2912 series is a broadband router which integrates IP layer QoS, NAT session/bandwidth management to help users control works well with large bandwidth.
By adopting hardware-based VPN platform and hardware encryption of AES/DES/3DES, the router increases the performance of VPN greatly, and offers several protocols (such as IPsec/PPTP/L2TP) with up to 16 VPN tunnels.
The object-based design used in SPI (Stateful Packet Inspection) firewall allows users to set firewall policy with ease. CSM (Content Security Management) provides users control and management in IM (Instant Messenger) and P2P (Peer to Peer) more efficiency than before. By the way, DoS/DDoS prevention and URL/Web content filter strengthen the security outside and control inside. Object-based firewall is flexible and allows your network be safe.
In addition, Vigor2912 series supports USB interface for connecting USB printer to share printing function or 3G USB modem for network connection.
Vigor2912 series provides two-level management to simplify the configuration of network connection. The user mode allows user accessing into WEB interface via simple configuration. However, if users want to have advanced configurations, they can access into WEB interface through admin mode.
Page 12
Vigor2912 Series User’s Guide
2
11..11 WWeebb CCoonnffiigguurraattiioonn BBuuttttoonnss EExxppllaannaattiioonn
Several main buttons appeared on the web pages are defined as the following:
Save and apply current settings.
Cancel current settings and recover to the previous saved settings.
Clear all the selections and parameters settings, including selection from
drop-down list. All the values must be reset with factory default settings.
Add new settings for specified item.
Edit the settings for the selected item.
Delete the selected item with the corresponding settings.
Note: For the other buttons shown on the web pages, please refer to Chapter 3, 4 for detailed explanation.
Page 13
Vigor2912 Series User’s Guide
3
11..22 LLEEDD IInnddiiccaattoorrss aanndd CCoonnnneeccttoorrss
Before you use the Vigor router, please get acquainted with the LED indicators and connectors first.
11..22..11 VViiggoorr22991122//VViiggoorr22991122FF
LED Status Explanation
Blinking The router is powered on and running normally. ACT (Activity)
Off The router is powered off.
On The Web Content Filter is active. (It is enabled from
Firewall >> General Setup).
WCF
Off The Web Content Filter is inactive.
QoS
On The QoS function is active.
On The DoS/DDoS function is active. DoS Blinking It will blink while detecting an attack. On The port is connected. Off The port is disconnected.
LAN (P4~P1)
Blinking The data is transmitting. On Internet connection is ready. Off Internet connection is not ready.
WAN(W2~W1)
Blinking The data is transmitting.
VPN On The VPN tunnel is active.
On USB device is connected and ready for use. USB Blinking The data is transmitting.
Page 14
Vigor2912 Series User’s Guide
4
Interface
Description
PWR
Connecter for a power adapter.
ON/OFF
Power Switch.
USB Connecter for a USB device (for 3G/4G USB Modem or printer). W1 (Vigor2912) Connecter an ADSL or cable modem for accessing Internet (WAN). W1 (Vigor2912F) Fiber connection (100Mbps) for accessing the Internet.
W2/P1 Connecter an ADSL or cable modem for accessing Internet (WAN); or
connecter for local network devices (LAN).
This connector is switchable for LAN and WAN connection. P2~P4 Connecters for local network devices (LAN). Factory Reset Restore the default settings. Usage: Turn on the router (ACT LED is
blinking). Press the hole and keep for more than 5 seconds. When you
see the ACT LED begins to blink rapidly than usual, release the button.
Then the router will restart with the factory default configuration.
Page 15
Vigor2912 Series User’s Guide
5
11..22..22 VViiggoorr22991122nn//VViiggoorr22991122FFnn
LED Status Explanation
Blinking The router is powered on and running normally. ACT (Activity)
Off The router is powered off.
On The Web Content Filter is active. (It is enabled from
Firewall >> General Setup).
WCF
Off The Web Content Filter is inactive.
QoS
On The QoS function is active.
On
Wireless access point is ready.
WLAN
Blinking
It will blink slowly while wireless traffic goes through. ACT and WLAN LEDs blink quickly and
simultaneously when WPS is working, and will return to normal condition after two minutes. (You need to setup WPS within 2 minutes.)
On The port is connected. Off The port is disconnected.
LAN (P4~P1)
Blinking The data is transmitting. On Internet connection is ready. Off Internet connection is not ready.
WAN(W2~W1)
Blinking The data is transmitting.
VPN On The VPN tunnel is active.
On USB device is connected and ready for use. USB Blinking The data is transmitting.
Page 16
Vigor2912 Series User’s Guide
6
Interface Description
PWR
Connecter for a power adapter. ON/OFF Power Switch.
USB Connecter for a USB device (for 3G/4G USB Modem or printer). W1 (Vigor2912n) Connecter an ADSL or cable modem for accessing Internet (WAN). W1 (Vigor2912Fn) Fiber connection (100Mbps) for accessing the Internet.
W2/P1 Connecter an ADSL or cable modem for accessing Internet (WAN); or
connecter for local network devices (LAN).
This connector is switchable for LAN and WAN connection. P2~P4 Connecters for local network devices (LAN). Wireless LAN
ON/OFF/WPS
Press "Wireless LAN ON/OFF/WPS" button once to wait for client
device making network connection through WPS.
Press "Wireless LAN ON/OFF/WPS" button twice to enable (WLAN
LED on) or disable (WLAN LED off) wireless connection. Factory Reset Restore the default settings. Usage: Turn on the router (ACT LED is
blinking). Press the hole and keep for more than 5 seconds. When you
see the ACT LED begins to blink rapidly than usual, release the button.
Then the router will restart with the factory default configuration.
Page 17
Vigor2912 Series User’s Guide
7
11..33 HHaarrddwwaarree IInnssttaallllaattiioonn
Before starting to configure the router, you have to connect your devices correctly.
1. Connect the cable Modem/DSL Modem/Media Converter to any WAN port of router
with Ethernet cable (RJ-45).
2. Connect one end of an Ethernet cable (RJ-45) to one of the LAN ports of the router and
the other end of the cable (RJ-45) into the Ethernet port on your computer.
3. Connect one end of the power adapter to the router’s power port on the rear panel, and
the other side into a wall outlet.
4. Power on the device by pressing down the power switch on the rear panel.
5. The system starts to initiate. After completing the system test, the ACT LED will light
up and start blinking.
(For the hardware connection, we take “n” model as an example.)
Page 18
Vigor2912 Series User’s Guide
8
11..44 PPrriinntteerr IInnssttaallllaattiioonn
You can install a printer onto the router for sharing printing. All the PCs connected this router can print documents via the router. The example provided here is made based on Windows XP/2000. For Windows 98/SE/Vista, please visit www.DrayTek.com.
Before using it, please follow the steps below to configure settings for connected computers (or wireless clients).
1. Connect the printer with the router through USB/parallel port.
2. Open All Programs>>Getting Started>>Devices and Printers.
Page 19
Vigor2912 Series User’s Guide
9
3. Click Add a printer.
4. A dialog will appear. Click Add a local printer and click Next.
5. In this dialog, choose Create a new port. In the field of Type of port, use the drop
down list to select Standard TCP/IP Port. Then, click Next.
Page 20
Vigor2912 Series User’s Guide
10
6. In the following dialog, type 192.168.1.1 (router’s LAN IP) in the field of Hostname or
IP Address and type 192.168.1.1 as the Port name. Then, click Next.
7. Click Standard and choose Generic Network Card.
Page 21
Vigor2912 Series User’s Guide
11
8. Now, your system will ask you to choose right name of the printer that you installed onto
the router. Such step can make correct driver loaded onto your PC. When you finish the selection, click Next.
9. Type a name for the chosen printer. Click Next.
Page 22
Vigor2912 Series User’s Guide
12
10. Choose Do not share this printer and click Next.
11. Then, in the following dialog, click Finish.
Page 23
Vigor2912 Series User’s Guide
13
12. The new printer has been added and displayed under Printers and Faxes. Click the new
printer icon and click Printer server properties.
13. Edit the property of the new printer you have added by clicking Configure Port.
Page 24
Vigor2912 Series User’s Guide
14
14. Select "LPR" on Protocol, type p1 (number 1) as Queue Name. Then click OK. Next
please refer to the red rectangle for choosing the correct protocol and LPR name.
The printer can be used for printing now. Most of the printers with different manufacturers are compatible with vigor router.
Page 25
Vigor2912 Series User’s Guide
15
Note 1: Some printers with the fax/scanning or other additional functions are not supported. If you do not know whether your printer is supported or not, please visit www.DrayTek.com to find out the printer list. Open Support > FAQ/Application Notes; find out the link of
Printer Server and click it; then click the What types of printers are compatible with Vigor router? link.
Then, click the What types of printers are compatible with Vigor router? link.
Note 2: Vigor router supports printing request from computers via LAN ports but not WAN port.
Page 26
Vigor2912 Series User’s Guide
16
11..55 AAcccceessssiinngg WWeebb UUsseerr IInntteerrffaaccee
1. Make sure your PC connects to the router correctly.
You may either simply set up your computer to get IP dynamically from the router or set up the IP address of the computer to be the same subnet as the default IP address of Vigor router 192.168.1.1. For the detailed information, please refer to the later section ­Trouble Shooting of the guide.
2. Open a web browser on your PC and type http://192.168.1.1. The following window
will be open to ask for username and password.
3. Please type “admin/admin” as the Username/Password and click Login.
Notice: If you fail to access to the web configuration, please go to “Trouble Shooting” for detecting and solving your problem.
4. Now, the Main Screen will appear.
Note: The home page will be different slightly in accordance with the type of the router you have.
5. The web page can be logged out according to the chosen condition. The default setting is
Auto Logout, which means the web configuration system will logout after 5 minutes without any operation. Change the setting for your necessity.
Page 27
Vigor2912 Series User’s Guide
17
11..66 CChhaannggiinngg PPaasssswwoorrdd
Please change the password for the original security of the router.
1. Open a web browser on your PC and type http://192.168.1.1. A pop-up window will
open to ask for username and password.
2. Please type “admin/admin” as Username/Password for accessing into the web user
interface with admin mode.
3. Go to System Maintenance page and choose Administrator Password/.
4. Enter the login password (the default is “admin”) on the field of Old Password. Type
New Password. Then click OK to continue.
Note: The maximum length of the password you can set is 23 characters.
5. Now, the password has been changed. Next time, use the new password to access the
Web user interface for this router.
Note: Even the password has been changed, the Username for logging to the web user interface is still “admin”.
11..77 WWeebb CCoonnssoollee,, CCoonnffiigg BBaacckkuupp && EExxiitt
Page 28
Vigor2912 Series User’s Guide
18
11..77..11 WWeebb CCoonnssoollee
It is not necessary to use the telnet command via DOS prompt. The changes made by using web console have the same effects as modified through web user interface. The functions/settings modified under Web Console also can be reviewed on the web user interface.
Click the Web Console icon on the top of the main screen to open the following screen.
Page 29
Vigor2912 Series User’s Guide
19
11..77..22 CCoonnffiigg BBaacckkuupp
There is one way to store current used settings quickly by clicking the Config Backup icon. It allows you to backup current settings as a file. Such configuration file can be restored by using System Maintenance>>Configuration Backup.
Simply click the icon on the top of the main screen and a pop up dialog will appear.
Click OK/Save to store the setting.
11..77..33 LLooggoouutt
Click the Logout icon to exit the web user interface.
Page 30
Vigor2912 Series User’s Guide
20
11..88 OOnnlliinnee SSttaattuuss
11..88..11 PPhhyyssiiccaall CCoonnnneeccttiioonn
Such page displays the physical connection status such as LAN connection status, WAN connection status, ADSL information, and so on.
PPhhyyssiiccaall CCoonnnneeccttiioonn ffoorr IIPPvv44 PPrroottooccooll
PPhhyyssiiccaall CCoonnnneeccttiioonn ffoorr IIPPvv66 PPrroottooccooll
Page 31
Vigor2912 Series User’s Guide
21
Detailed explanation (for IPv4) is shown below:
Item Description LAN Status
Primary DNS-Displays the primary DNS server address
for WAN interface. Secondary DNS -Displays the secondary DNS server
address for WAN interface.
IP Address-Displays the IP address of the LAN interface. TX Packets-Displays the total transmitted packets at the
LAN interface. RX Packets-Displays the total received packets at the LAN
interface.
WAN1/WAN2/WAN3 Status
Enable – Yes in red means such interface is available but not enabled. Yes in green means such interface is enabled.
Line – Displays the physical connection (VDSL, ADSL,
Ethernet, or USB) of this interface.
Name – Display the name of the router. Mode - Displays the type of WAN connection (e.g.,
PPPoE).
Up Time - Displays the total uptime of the interface. IP - Displays the IP address of the WAN interface. GW IP - Displays the IP address of the default gateway. TX Packets - Displays the total transmitted packets at the
WAN interface. TX Rate - Displays the speed of transmitted octets at the
WAN interface. RX Packets - Displays the total number of received packets
at the WAN interface. RX Rate - Displays the speed of received octets at the
WAN interface.
Detailed explanation (for IPv6) is shown below:
Item Description LAN Status
IP Address- Displays the IPv6 address of the LAN
interface.. TX Packets-Displays the total transmitted packets at the
LAN interface. RX Packets-Displays the total received packets at the LAN
interface. TX Bytes - Displays the speed of transmitted octets at the
LAN interface. RX Bytes - Displays the speed of received octets at the
LAN interface.
WAN IPv6 Status
Enable – No in red means such interface is available but
not enabled. Yes in green means such interface is enabled. No in red means such interface is not available.
Page 32
Vigor2912 Series User’s Guide
22
Item Description
Mode - Displays the type of WAN connection (e.g., TSPC). Up Time - Displays the total uptime of the interface. IP - Displays the IP address of the WAN interface. Gateway IP - Displays the IP address of the default
gateway.
Note: The words in green mean that the WAN connection of that interface is ready for
accessing Internet; the words in red mean that the WAN connection of that interface is not ready for accessing Internet.
11..88..22 VViirrttuuaall WWAANN
Such page displays the virtual WAN connection information. Virtual WAN are used by TR-069 management, VoIP service and so on. The field of Application will list the purpose of such WAN connection.
11..99 SSaavviinngg CCoonnffiigguurraattiioonn
Each time you click OK on the web page for saving the configuration, you can find messages showing the system interaction with you.
Ready indicates the system is ready for you to input settings. Settings Saved means your settings are saved once you click Finish or OK button.
Page 33
Vigor2912 Series User’s Guide
23
Q
Quuiicckk SSeettuupp
There are several setup wizards offered for you to configure the router simply and quickly.
Quick Start Wizard – used for building network connection, Internet access. Service Activation Wizard – used for activating the web content filter service. VPN Client Wizard – used for establishing VPN tunnel; the router is treated as a VPN
client.
VPN Server Wizard – used for establishing VPN tunnel; the router is treated as a VPN
server.
Wireless Wizard – used for building wireless LAN connection.
22..11 QQuuiicckk SSttaarrtt WWiizzaarrdd
Open Wizards>>Quick Start Wizard. The first screen is entering login password. After typing the password, please click Next.
Page 34
Vigor2912 Series User’s Guide
24
On the next page as shown below, please select the WAN interface that you use. If Ethernet interface is used, please choose WAN1/WAN2; if 3G USB modem is used, please choose WAN3. Then click Next for next step.
WAN1, WAN2 and WAN3 will bring up different configuration page. Refer to the following for detailed information.
Page 35
Vigor2912 Series User’s Guide
25
22..11..11 FFoorr WWAANN11 ((EEtthheerrnneett//FFiibbeerr)) aanndd WWAANN22 ((EEtthheerrnneett)
)
WAN1 is dedicated to physical mode in Ethernet (Vigor2912/Vigor2912n) or Fiber (Vigor2912F/Vigor2912Fn). WAN2 is dedicated to physical mode in Ethernet. If you choose WAN1/WAN2 based on Ethernet, please specify physical type. Then, click Next.
On the next page as shown below, please select the appropriate Internet access type according to the information from your ISP. For example, you should select PPPoE mode if the ISP provides you PPPoE interface. Then click Next for next step.
PPPPPPooEE
1. Choose WAN1/WAN2 as the WAN Interface and click the Next button. The following
page will be open for you to specify Internet Access Type.
Page 36
Vigor2912 Series User’s Guide
26
2. Click PPPoE as the Internet Access Type. Then click Next to continue.
Available settings are explained as follows:
Item Description Service Name
(Optional)
Type the description of the specific network service.
User Name
Assign a specific valid user name provided by the ISP. Note: The maximum length of the user name you can set is
63 characters.
Password
Assign a valid password provided by the ISP. Note: The maximum length of the password you can set is 62
characters.
Confirm Password
Retype the password.
Back
Click it to return to previous setting page.
Next
Click it to get into the next setting page.
Cancel
Click it to give up the quick start wizard.
Page 37
Vigor2912 Series User’s Guide
27
3. Please manually enter the Username/Password provided by your ISP. Click Next for
viewing summary of such connection.
4. Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system
status of this protocol will be shown.
5. Now, you can enjoy surfing on the Internet.
Page 38
Vigor2912 Series User’s Guide
28
PPPPTTPP//LL22TTPP
1. Choose WAN1/WAN2 as the WAN Interface and click the Next button. The following
page will be open for you to specify Internet Access Type.
2. Click PPTP/L2TP as the Internet Access Type. Then click Next to continue.
Available settings are explained as follows:
Item Description User Name
Assign a specific valid user name provided by the ISP. Note: The maximum length of the user name you can set is
63 characters.
Password
Assign a valid password provided by the ISP.
Page 39
Vigor2912 Series User’s Guide
29
Note: The maximum length of the password you can set is 62 characters.
Confirm Password
Retype the password.
WAN IP Configuration
Obtain an IP address automatically – the router will get
an IP address automatically from DHCP server. Specify an IP address – you have to type relational
settings manually.
IP Address - Type the IP address. Subnet Mask –Type the subnet mask.
Gateway – Type the IP address of the gateway. Primary DNS –Type in the primary IP address for the
router. Second DNS –Type in secondary IP address for necessity
in the future.
PPTP Server / L2TP Server
Type the IP address of the server.
Back
Click it to return to previous setting page.
Next
Click it to get into the next setting page.
Cancel
Click it to give up the quick start wizard.
3. Please type in the IP address/mask/gateway information originally provided by your ISP.
Then click Next for viewing summary of such connection.
4. Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system
status of this protocol will be shown.
5. Now, you can enjoy surfing on the Internet.
Page 40
Vigor2912 Series User’s Guide
30
SSttaattiicc IIPP
1. Choose WAN1/WAN2 as the WAN Interface and click the Next button. The following
page will be open for you to specify Internet Access Type.
2. Click Static IP as the Internet Access type. Simply click Next to continue.
Available settings are explained as follows:
Item Description WAN IP
Type the IP address.
Subnet Mask
Type the subnet mask.
Gateway
Type the IP address of gateway.
Primary DNS
Type in the primary IP address for the router.
Secondary DNS
Type in secondary IP address for necessity in the future.
Back
Click it to return to previous setting page.
Next
Click it to get into the next setting page.
Page 41
Vigor2912 Series User’s Guide
31
Cancel
Click it to give up the quick start wizard.
3. Please type in the IP address information originally provided by your ISP. Then click
Next for next step.
4. Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system
status of this protocol will be shown.
5. Now, you can enjoy surfing on the Internet.
Page 42
Vigor2912 Series User’s Guide
32
DDHHCCPP
1. Choose WAN1/WAN2 as WAN Interface and click the Next button. The following page
will be open for you to specify Internet Access Type.
2. Click DHCP as the Internet Access type. Simply click Next to continue.
Available settings are explained as follows:
Item Description Host Name
Type the name of the host. Note: The maximum length of the host name you can set is
39 characters.
MAC
Some Cable service providers specify a specific MAC address for access authentication. In such cases you need to enter the MAC address.
Back
Click it to return to previous setting page.
Next
Click it to get into the next setting page.
Page 43
Vigor2912 Series User’s Guide
33
Cancel
Click it to give up the quick start wizard.
3. After finished the settings above, click Next for viewing summary of such connection.
4. Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system
status of this protocol will be shown.
5. Now, you can enjoy surfing on the Internet.
Page 44
Vigor2912 Series User’s Guide
34
22..11..22 FFoorr WWAANN33 ((UUSSBB))
WAN3 is dedicated to physical mode in USB. If WAN3 is selected, it is not necessary for you to type any information for such connection.
1. Choose WAN3 as WAN Interface.
2. Then, click Next for getting the following page.
Available settings are explained as follows:
Item Description Internet Access
Choose a protocol for accessing the Internet.
3G/4G USB Modem (PPP mode)
SIM Pin code –Type PIN code of the SIM card that will be
used to access Internet. The maximum length of the pin code you can set is 15 characters.
Modem Initial String – Such value is used to initialize USB modem. Please use the default value. If you have any question, please contact to your ISP. The maximum length of the string you can set is 47 characters.
APN Name – APN means Access Point Name which is
Page 45
Vigor2912 Series User’s Guide
35
provided and required by some ISPs. Type the name and click Apply.
4G USB Modem (DHCP mode)
SIM Pin code –Type PIN code of the SIM card that will be
used to access Internet. Network Mode – Force Vigor router to connect Internet
with the mode specified here. If you choose 4G/3G/2G as network mode, the router will choose a suitable one according to the actual wireless signal automatically.
APN Name – APN means Access Point Name which is provided and required by some ISPs.
3. Then, click Next for viewing summary of such connection.
4. Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system
status of this protocol will be shown.
5. Now, you can enjoy surfing on the Internet.
Page 46
Vigor2912 Series User’s Guide
36
22..22 SSeerrvviiccee AAccttiivvaattiioonn WWiizzaarrdd
Service Activation Wizard can guide you to activate WCF service (Web Content Filter) with a quick and easy way. For the Service Activation Wizard is only available for admin
operation, therefore, please type “admin/admin” on Username/Password while Logging into the web user interface.
Service Activation Wizard is a tool which allows you to use trial version of WCF directly without accessing into the server (MyVigor) located on http://myvigor.draytek.com
. For using
Web Content Filter Profile, please refer to later section Web Content Filter Profile for detailed information.
Now, follow the steps listed below to activate WCF feature for your router.
Note: Such function is available only for Admin Mode.
1. Open Wizards>>Service Activation Wizard.
2. The screen of Service Activation Wizard will be shown as follows. Choose the one you
need and click Next. In this case, we choose to activate free trail edition.
Free trial edition: it offers a period of trial for you to get acquainted with WCF function.
Page 47
Vigor2912 Series User’s Guide
37
3. In the following page, you can activate the Web content filter services at the same time
or individually. When you finish the selection, please click Next.
Commtouch is the web content filter based on Commtouch operated in the worldwide. There is a 30-day trial period. After trial, you can purchase DrayTek's prepared Commtouch GlobalView WCF package from retailing outlets.
Commtouch is merged by Cyren, and GlobalView services will be continued to deliver powerful cloud-based information security solutions! Refer to:
http://www.prnewswire.com/news-releases/commtouch-is-now-cyren-239025151.ht ml
BPjM is WCF for German Speaking users. The fragfINN is whitelist for German Speaking users. The BPjM is ideal for your family to provide more Internet security for youngsters.
eb Content Filter (fragFINN) service will not be supported since January 1, 2015.
4. Setting confirmation page will be displayed as follows, please click Next.
Page 48
Vigor2912 Series User’s Guide
38
5. Wait for a moment till the following page appears.
When such page appears, you can enable or disable these services for your necessity. Then, click Finish.
Note: The service will be activated and applied as the default rule configured in Firewall>>General Setup.
6. Now, the web page will display the service that you have activated according to your
selection(s). The valid time for the free trial of these services is one month.
When all the trial editions for various web content filters had been enabled, the configuration page of Service Activation Wizard will be invalid as shown below.
Page 49
Vigor2912 Series User’s Guide
39
22..33 VVPPNN CClliieenntt WWiizzaarrdd
Such wizard is used to configure VPN settings for VPN client. Such wizard will guide to set the LAN-to-LAN profile for VPN dial out connection (from server to client) step by step.
1. Open VPN and Remote Access>>VPN Client Wizard. The following page will appear.
Available settings are explained as follows:
Item Description LAN-to-LAN Client
Mode Selection
Choose the client mode. Route Mode/NAT Mode – If the remote network only
allows you to dial in with single IP, please choose this mode, otherwise please choose Route Mode.
Please choose a LAN-to-LAN Profile
There are 32 VPN profiles for users to set.
Page 50
Vigor2912 Series User’s Guide
40
2. When you finish the mode and profile selection, please click Next to open the following
page.
In this page, you have to select suitable VPN type for the VPN client profile. There are six types provided here. Different type will lead to different configuration page. After making the choices for the client profile, please click Next. You will see different configurations based on the selection(s) you made.
Page 51
Vigor2912 Series User’s Guide
41
Note: The following descriptions for VPN Type are based on the Route Mode specified in LAN-to-LAN Client Mode Selection.
When you choose PPTP (None Encryption) or PPTP (Encryption), you will see the
following graphic:
When you choose IPsec, you will see the following graphic:
When you choose L2TP, you will see the following graphic:
Page 52
Vigor2912 Series User’s Guide
42
When you choose L2TP over IPsec (Nice to Have) or L2TP over IPsec (Must), you
will see the following graphic:
Available settings are explained as follows:
Item Description Profile Name
Type a name for such profile. The length of the file is limited to 10 characters.
Page 53
Vigor2912 Series User’s Guide
43
VPN Dial-Out Through
Use the drop down menu to choose a proper WAN interface for this profile. This setting is useful for dial-out only.
WAN1 First/ WAN2 First/ WAN3 First - While connecting, the router will use WAN1/WAN2/WAN3 as the first channel for VPN connection. If WAN1/WAN2/WAN3 fails, the router will use another WAN interface instead. WAN1 Only /WAN2 Only/WAN 3 Only- While connecting, the router will use WAN1/WAN2/WAN3 as the only channel for VPN connection. WAN1 Only: Only establish VPN if WAN2 down - If WAN2 failed, the router will use WAN1 for VPN connection.
WAN2 Only: Only establish VPN if WAN1 down - If WAN1 failed, the router will use WAN2 for VPN connection.
Always On
Check to enable router always keep VPN connection.
Server IP/Host Name for VPN
Type the IP address of the server or type the host name for such VPN profile.
IKE Authentication Method
IKE Authentication Method usually applies to those are remote dial-in user or node (LAN to LAN) which uses dynamic IP address and IPsec-related VPN connections such as L2TP over IPsec and IPsec tunnel.
Pre-Shared Key - Specify a key for IKE authentication. Confirm Pre-Shared Key -Confirm the pre-shared key.
Digital Signature (X.509)
Click Digital Signature to invoke this function. Peer ID – Choose the peer ID selection from the drop down
list.
Local ID – Choose Alternative Subject Name First or Subject Name First.
Local Certificate – Use the drop down list to choose one of
the certificates for using. You have to configure one certificate at least previously in Certificate Management >> Local Certificate. Otherwise, the setting you choose here will not be effective.
IPsec Security Method
Medium - Authentication Header (AH) means data will be
authenticated, but not be encrypted. By default, this option is active.
High - Encapsulating Security Payload (ESP) means payload (data) will be encrypted and authenticated. You
Page 54
Vigor2912 Series User’s Guide
44
may select encryption algorithm from Data Encryption Standard (DES), Triple DES (3DES), and AES.
User Name
This field is used to authenticate for connection when you select PPTP or L2TP with or without IPsec policy above.
The length of the use name is limited to 11 characters.
Password
This field is used to authenticate for connection when you select PPTP or L2TP with or without IPsec policy above.
The length of the password is limited to 11 characters.
Remote Network IP
Please type one LAN IP address (according to the real location of the remote host) for building VPN connection.
Remote Network Mask
Please type the network mask (according to the real location of the remote host) for building VPN connection.
3. After finishing the configuration, please click Next. The confirmation page will be shown
as follows. If there is no problem, you can click one of the radio buttons listed on the page and click Finish to execute the next action.
Available settings are explained as follows:
Item Description Go to the VPN
Connection Management
Click this radio button to access VPN and Remote Access>>Connection Management for viewing VPN
Connection status.
Do another VPN Server Wizard Setup
Click this radio button to set another profile of VPN Server through VPN Server Wizard.
View more detailed configuration
Click this radio button to access VPN and Remote Access>>LAN to LAN for viewing detailed configuration.
Page 55
Vigor2912 Series User’s Guide
45
22..44 VVPPNN SSeerrvveerr WWiizzaarrdd
Such wizard is used to configure VPN settings for VPN server. Such wizard will guide to set the LAN-to-LAN profile for VPN dial in connection (from client to server) step by step.
1. Open VPN and Remote Access>>VPN Server Wizard. The following page will appear.
Available settings are explained as follows:
Item Description VPN Server Mode
Selection
Choose the direction for the VPN server. Site to Site VPN – To set a LAN-to-LAN profile
automatically, please choose Site to Site VPN. Remote Dial-in User –You can manage remote access by
maintaining a table of remote user profile, so that users can be authenticated to dial-in via VPN connection.
Please choose a LAN-to-LAN Profile
This item is available when you choose Site to Site VPN (LAN-to-LAN) as VPN server mode. There are 32 VPN profiles for users to set.
Page 56
Vigor2912 Series User’s Guide
46
Please choose a Dial-in User Accounts
This item is available when you choose Remote Dial-in User (Teleworker) as VPN server mode. There are 32 VPN tunnels for users to set.
Allowed Dial-in Type
This item is available after you choose any one of dial-in user account profiles. Next, you have to select suitable dial-in type for the VPN server profile. There are several types provided here (similar to VPN Client Wizard).
Different Dial-in Type will lead to different configuration page. In addition, adjustable items for each dial-in type will be changed according to the VPN Server Mode (Site to Site VPN and Remote Dial-in User) selected.
2. After making the choices for the server profile, please click Next. You will see different
configurations based on the selection you made.
Here we take the examples of choosing Site-to-Site VPN as the VPN Server Mode.
Page 57
Vigor2912 Series User’s Guide
47
When you check PPTP, you will see the following graphic:
When you check PPTP & IPsec & L2TP (three types) or PPTP&IPsec (two types) or
L2TP with Policy (Nice to Have/Must), you will see the following graphic:
Page 58
Vigor2912 Series User’s Guide
48
When you check IPsec, you will see the following graphic:
Available settings are explained as follows:
Item Description Profile Name
Type a name for such profile. The length of the file is limited to 10 characters.
User Name
This field is used to authenticate for connection when you select PPTP or L2TP with or without IPsec policy above.
The length of the name is limited to 11 characters.
Password
This field is used to authenticate for connection when you select PPTP or L2TP with or without IPsec policy above.
The length of the name is limited to 11 characters.
Pre-Shared Key
For IPsec/L2TP IPsec authentication, you have to type a pre-shared key.
The length of the name is limited to 64 characters.
Confirm Pre-Shared Key
Type the pre-shared key again for confirmation.
Digital Signature (X.509)
Check the box of Digital Signature to invoke this function. Peer ID – Choose the peer ID selection from the drop down
list.
Local ID – Choose Alternative Subject Name First or Subject Name First.
Peer IP/VPN Client IP
Type the WAN IP address or VPN client IP address for the remote client.
Peer ID
Type the ID name for the remote client. The length of the name is limited to 47 characters.
Page 59
Vigor2912 Series User’s Guide
49
Remote Network IP
Please type one LAN IP address (according to the real location of the remote host) for building VPN connection.
Remote Network Mask
Please type the network mask (according to the real location of the remote host) for building VPN connection.
3. After finishing the configuration, please click Next. The confirmation page will be shown
as follows. If there is no problem, you can click one of the radio buttons listed on the page and click Finish to execute the next action.
Available settings are explained as follows:
Item Description Go to the VPN
Connection Management
Click this radio button to access VPN and Remote Access>>Connection Management for viewing VPN
Connection status.
Do another VPN Server Wizard Setup
Click this radio button to set another profile of VPN Server through VPN Server Wizard.
View more detailed configuration
Click this radio button to access VPN and Remote Access>>LAN to LAN for viewing detailed configuration.
Page 60
Vigor2912 Series User’s Guide
50
22..55 WWiirreelleessss WWiizzaarrdd
The wireless wizard allows you to configure settings specified for a host AP (for home use or internal use for a company) and specified for a guest AP (for any wireless clients accessing into Internet).
Follow the steps listed below:
1. Open Wireless Wizard.
2. The screen of wireless wizard will be shown as follows. This page will be used for internal
users in a company or your home.
Available settings are explained as follows:
Item Description Name
Type the SSID name of this router for wireless 2.4GHz. The default name is defined with DrayTek. Change the name if required.
Mode
At present, the router can connect to 11b Only, 11g Only, 11n Only (2.4GHz), Mixed (11b+11g), Mixed (11g+11n), and Mixed (11b+11g+11n) stations simultaneously. Simply choose Mix (11b+11g+11n) mode.
Channel
Means the channel of frequency of the wireless LAN. The default channel is 6. You may switch channel if the selected channel is under serious interference. If you have no idea of choosing the frequency, please select Auto to let system determine for you.
Security Key
The wireless mode offered by this wizard is WPA2/PSK.
Page 61
Vigor2912 Series User’s Guide
51
The WPA encrypts each frame transmitted from the radio using the key, which either PSK (Pre-Shared Key) entered manually in this field below or automatically negotiated via
802.1x authentication. Either 8~63 ASCII characters, such as 012345678(or 64
Hexadecimal digits leading by 0x, such as “0x321253abcde…”).
Next
Click it to get into the next setting page.
Cancel
Exit the wireless wizard without saving any changes.
3. After typing the required information, click Next. The settings in the page limit the
wireless station (guest) accessing into Internet but not being allowed to share the LAN network and VPN connection.
Available settings are explained as follows:
Item Description Enable/Disable
Click it to enable or disable settings in this page.
SSID
Type the SSID name of this router. (SSID1)
Security Key
The wireless mode offered by this wizard is WPA2/PSK. The WPA encrypts each frame transmitted from the radio
using the key, which either PSK (Pre-Shared Key) entered manually in this field below or automatically negotiated via
802.1x authentication. Either 8~63 ASCII characters, such as 012345678(or 64
Hexadecimal digits leading by 0x, such as "0x321253abcde...").
Rate Control
It controls the data transmission rate through wireless connection.
Upload – Check Enable and type the transmitting rate for data upload. Default value is 30,000 kbps.
Download – Type the transmitting rate for data download. Default value is 30,000 kbps.
Page 62
Vigor2912 Series User’s Guide
52
Next
Click it to get into the next setting page.
Cancel
Exit the wireless wizard without saving any changes.
4. After typing the required information, click Next.
5. The following page will display the configuration summary for wireless setting.
6. Click Finish to complete the wireless settings configuration.
Page 63
Vigor2912 Series User’s Guide
53
22..66 RReeggiisstteerriinngg VViiggoorr RRoouutteerr
You have finished the configuration of Quick Start Wizard and you can surf the Internet at any time. Now it is the time to register your Vigor router to MyVigor website for getting more service. Please follow the steps below to finish the router registration.
1 Please login the web configuration interface of Vigor router by typing “admin/admin
as User Name / Password.
2 Click Support Area>>Production Registration from the home page.
3 A Login page will be shown on the screen. Please type the account and password that
you created previously. And click Login.
Page 64
Vigor2912 Series User’s Guide
54
Notice: If you haven’t an accessing account, please refer to section 3.7 Creating an Account for MyVigor on User’s Guide to create your own one. Please read the articles on the Agreement regarding user rights carefully while creating a user account.
4 The following page will be displayed after you logging in MyVigor. From this page,
please click Add or Product Registration.
5 When the following page appears, please type in Nickname (for the router) and choose
the right registration date from the popup calendar (it appears when you click on the box of Registration Date). After adding the basic information for the router, please click Submit.
Page 65
Vigor2912 Series User’s Guide
55
6 When the following page appears, your router information has been added to the
database.
7 Now, you have finished the product registration. 8 After clicking OK, you will see the following page. Your router has been registered to
myvigor website successfully.
If you have not activated web content filter service by using Service Activation Wizard, you can activate the service from this step. Please click the serial number link.
9 From the Device’s Service section, click the Trial.
Page 66
Vigor2912 Series User’s Guide
56
10 In the following page, check the box of “I have read and accept the above Agreement”.
The system will find out the date for you to activate this version of service. Then, click Next.
11 When this page appears, click Register.
12 Wait for a moment until the following page appears.
13 Click Close.
Page 67
Vigor2912 Series User’s Guide
57
TTuuttoorriiaallss aanndd A
Apppplliiccaattiioonnss
33..11 HHooww ttoo ccoonnffiigguurree sseettttiinnggss ffoorr IIPPvv66 SSeerrvviiccee iinn VViiggoorr22991122
Due to the shortage of IPv4 address, more and more countries use IPv6 to solve the problem. However, to continually use the original rich resources of IPv4, both IPv6 and IPv4 networks shall communicate for each other via intercommunication mechanism to complete the shifting job from IPv4 to IPv6 gradually. At present, there are three common types of intercommunication mechanisms:
Dual Stack
The user can use both IPv4 and IPv6 techniques at the same time. That means adding an IPv6 stack on the origin network layer to let the host own the communication capability of IPv4 and IPv6.
Tunnel
Both IPv6 hosts can communication for each other via existing IPv4 network environment. The IPv6 packets will be encapsulated with the header of IPv4 first. Later, the packets will be transformed and judged by IPv4 router. Once the packets arrive the border between IPv4 and IPv6, the header of IPv4 on the packets will be removed. Then, the packets with IPv6 address will be forwarded to the destination of IPv6 network.
Translation
Such feature is active only for the user who uses IPv4 to communicate with other user using IPv4 service.
Before configuring the settings on Vigor2912, you need to know which connection type that your IPv6 service used.
Note: For the IPv6 service, you have to configure WAN/LAN settings before using the service.
II.. CCoonnffiigguurriinngg tthhee WWAANN SSeettttiinnggss
For the IPv6 WAN settings for Vigor2912, there are five connection types to be chosen: PPP, TSPC, AICCU, DHCPv6 Client and Static IPv6.
1. Access into the web user interface of Viogr2925. Open WAN>> Internet Access.
Choose one of the WAN interfaces as the one supporting IPv6 service. Then, click the IPv6 button of the selected WAN.
Page 68
Vigor2912 Series User’s Guide
58
Note: Only one WAN interface support IPv6 service at one time. In this example, WAN2 is chosen as the one supporting IPv6 service.
2. In the following figure, use the drop down list to choose a proper connection type.
Different connection types will bring out different configuration page. Refer to the following:
PPP – Dual Stack application, IPv4 and IPv6 services can be utilized at the same
time
Choose PPP and type the information for PPPoE of IPv4.
Access into the setting page for IPv6 service, it is not necessary for you to configure anything.
Page 69
Vigor2912 Series User’s Guide
59
Click OK and open Online Status. If the connection is successful, you will get the IP address for IPv4 and IPv6 at the same time.
Page 70
Vigor2912 Series User’s Guide
60
TSPC – Tunnel application, both IPv6 hosts communicate through IPv4 network
Choose TSPC and type the information for TSPC service.
Note: While using such mode, you have to make sure the IPv4 network connection is
normal.
(In the following figure, the TSPC information is obtained from http://gogo6.com/ after applied for the service.)
Click OK and open Online Status. If the connection is successful, the physical connection will be shows as follows:
Page 71
Vigor2912 Series User’s Guide
61
AICCU – Tunnel application
Choose AICCU and type the information for AICCU of IPv6.
Note: While using such mode, you have to make sure the IPv4 network connection is normal.
(In the following figure, the AICCU information is obtained from https://www.sixxs.net/main/
after applied for the service.)
Click OK and open Online Status. If the connection is successful, the physical connection will be shows as follows:
Page 72
Vigor2912 Series User’s Guide
62
DHCPv6 Client
Choose DHCPv6 Client. Click one of the identity associations and type the IAID number.
Click OK and open Online Status. If the connection is successful, the physical connection will be shows as follows:
Page 73
Vigor2912 Series User’s Guide
63
Static IPv6
Choose Static IPv6. Type IPv6 address, Prefix Length and Gateway Address.
Click OK and open Online Status. If the connection is successful, the physical connection will be shows as follows:
Page 74
Vigor2912 Series User’s Guide
64
IIII.. CCoonnffiigguurriinngg tthhee LLAANN SSeettttiinnggss
After finished the WAN settings for IPv6, please configure the LAN settings to make the router’s client getting the IPv6 address.
1. Access into the web user interface of Viogr2925. Open LAN>> General Setup. Click
the IPv6 button.
Note: Only the subnet of LAN1 supports IPv6 feature.
2. In the field of RADVD Configuration, the default setting is Enable. The client’s PC
will ask RADVD service for the Prefix of IPv6 address automatically, and generate an Interface ID by itself to compose a full and unique IPv6 address.
3. In the field of HCPv6 Server Configuration, when DHCPv6 service is enabled, you can
assign available IPv6 address for the client manually.
Note: When both mechanisms are enabled, the client can determine which mechanism to be used (e.g., the default mechanism for Windows7 is RADVD).
Page 75
Vigor2912 Series User’s Guide
65
IIIIII.. CCoonnffiirrmmiinngg IIPPvv66 SSeerrvviiccee RRuunn SSuucccceessssffuullllyy
1. Make sure you have get the correct IPv6 IP address. Get into MS-DOS interface and type
the command of “ipconfig”. Refer to the following figure.
From the above figure we can see IPv6 IP address has been captured by the system.
2. Use the Ping command to ping any IPv6 address indicating an IPv6 website. For
example, www.kame.net
is a website supporting IPv4 IP and IPv6 IP services. Its IPv6
address is seen with a format of 2001:200:dff:fff1:216:3eff:feb1:44d7.
After getting the above message, it means the IPv6 service has been activated successfully.
Page 76
Vigor2912 Series User’s Guide
66
3. Connect to the website for IPv6. Open a web browser and type an URL of IPv6, e.g.,
www.kame.net
. If your computer accesses into the website by using IPv6 address, you
may see a turtle dancing on the screen. If not, only a steady turtle will be seen.
If you can see a turtle dancing on the screen, that means IPv6 service is ready for you to access and utilize.
Page 77
Vigor2912 Series User’s Guide
67
33..22 HHooww ccaann II ggeett tthhee ffiilleess ffrroomm UUSSBB ssttoorraaggee ddeevviiccee ccoonnnneeccttiinngg ttoo VViiggoorr rroouutteerr??
Files on USB storage device can be reviewed by opening USB Applicaiton>>File Explorer. If it is necessary for you to delete, copy files on the device or write, paste files to the devcie, it must be done through SMB server or FTP server.
SMB service is based on the original USB FTP service. You will need to setup USB FTP first. We would like to give brief instructions on USB FTP setup here.
1. Plug the USB device to the USB port on the router. Make sure Disk Connected appears
on the Connection Status as the figure shown below:
2. Then, please open USB Application >> USB General Settings to enable SMB service.
Page 78
Vigor2912 Series User’s Guide
68
3. Setup a user account for the FTP service by using USB Application >>USB User
Management. Click Enable to enable FTP/SMB User account. Here we add a new account "user1" and assign authorities “Read”, “Write” and “List” to it.
4. Click OK to save the configuration.
5. Make sure the FTP service is running properly. Please open a browser and type
ftp://192.168.1.1
. Use the account "user1" to login.
Page 79
Vigor2912 Series User’s Guide
69
6. When the following screen appears, it means the FTP service is running properly.
7. Return to USB Application >> USB Disk Status. The information for FTP server will
be shown as below.
Now, users in LAN of Vigor2912 can access into the USB storage device by typing ftp://192.168.1.1 on any browser. They can add or remove files / directories, depending on the Access Rule for FTP account settings in USB Application >>USB User Management.
Page 80
Vigor2912 Series User’s Guide
70
33..33 HHooww ttoo BBuuiilldd aa LLAANN--ttoo--LLAANN VVPPNN BBeettwweeeenn RReemmoottee OOffffiiccee aanndd HHeeaaddqquuaarrtteerr vviiaa IIPPsseecc TTuunnnneell ((MMaaiinn MMooddee))
CCoonnffiigguurraattiioonn oonn VViiggoorr RRoouutteerr ffoorr HHeeaadd OOffffiiccee
1. Log into the web user interface of Vigor router.
2. Open VPN and Remote Access>>LAN to LAN to create a LAN-to-LAN profile.
3. Click any index number to open the configuration page. Type a name which is easy for
identification for such profile (in this case, type VPN Server), and check the box of Enable This Profile. For Vigor router will be set as a server, the call direction shall be set as Dial-in and set 0 as Idle Timeout.
Page 81
Vigor2912 Series User’s Guide
71
4. Now navigate to the next section, Dial-In Settings to check PPTP, IPsec Tunnel and
L2TP boxes. Check the box of Specify Remote… and type the Peer VPN Server IP (e.g., 218.242.130.19 in this case). Press the IKE Pre-Shared Key button to set the PSK; and select Medium (AH) or High (ESP) as the security method.
5. Continue to navigate to the TCP/IP Network Settings for setting the LAN IP for remote
side.
6. Click OK to save the settings.
Page 82
Vigor2912 Series User’s Guide
72
7. Open VPN and Remote Access>>Connection Management to check the dial-in
connection status (from branch office).
CCoonnffiigguurraattiioonn oonn VViiggoorr RRoouutteerr ffoorr BBrraanncchh OOffffiiccee
1. Log into the web user interface of Vigor router.
2. Open VPN and Remote Access>>LAN to LAN to create a LAN-to-LAN profile. The
following settings are for a permanent VPN connection.
3. Click any index number to open the configuration page. Type a name which is easy for
identification for such profile (in this case, type VPN Client), and check the box of Enable This Profile. For such Vigor router will be set as a client, the call direction shall be set as Dial-out. Check the box of Always on for a permanent VPN connection.
Page 83
Vigor2912 Series User’s Guide
73
4. Now navigate to the next section, Dial-Out Settings to select the IPsec Tunnel service
and type the remote server IP/host name (e.g., 218.242.133.91, in this case). Press the IKE Pre-Shared Key button to set the PSK; and select Medium (AH) or High (ESP) as the security method.
5. Continue to navigate to the TCP/IP Network Settings for setting the LAN IP for the
remote side.
6. Click OK to save the settings.
Page 84
Vigor2912 Series User’s Guide
74
7. Open VPN and Remote Access>>Connection Management to check the dial-in
connection status (from head office).
33..44 HHooww ttoo OOppttiimmiizzee tthhee BBaannddwwiiddtthh tthhrroouugghh QQooSS TTeecchhnnoollooggyy
Have you ever gotten any problems in uploading/downloading files (Voice, video or email/data only) with the narrow/districted bandwidth you may share from the common Internet connection line? The advanced bandwidth management technology-QoS (Quality of Service) helps you to well allocate the bandwidth upon your demand of Voice, Video, or Data transferring. Let's see how to get the optimum bandwidth per your request by using DrayTek Vigor router as below.
Scenario: The Internet connection you got from ISP line is 2MB/512Kb. There are VoIP telephony network, IPTV set top box and data server at your home. Assume you want to allocate 30% of the bandwidth you got to VoIP demand, 50% for IPTV, 15% for mail/data, 5% for others. Let's see how easily it is to do the setting as below:
1.
Open Bandwidth Management>> Quality of Service.
2. You will get the following page. Click the Edit link for Class 1.
3.
In the following page, type a name (e.g., VoIP) for such class and click Add.
Page 85
Vigor2912 Series User’s Guide
75
4. Check the box of ACT. Click Edit to specify the local address.
5. In the pop-up window, choose Range Address as the Address Type and type the start IP
address and end IP address in relational fields. Click OK to save the settings and exit the window.
6. Click OK again to save the settings.
Page 86
Vigor2912 Series User’s Guide
76
7. The class rule for VoIP has been set. Click OK to return to previous page.
8. Do the same steps to add class rules for IPTV and Data/Email with IP addresses as
shown below.
and
Page 87
Vigor2912 Series User’s Guide
77
9. Assuming you get 2MB/512Kb Internet line. You can click the Setup link of WAN1 to
set up the bandwidth for different groups among VoIP, IPTV and Data/Email.
10. In the Setup page, check the box of Enable the QoS Control. Type 30, 50 and 15 in the
boxes for VoIP, IPTV and Data/Email respectively. Check the box of Enable UDP Bandwidth Control.
11. Click OK to save the settings. The class rules for WAN1 are defined as shown below.
Page 88
Vigor2912 Series User’s Guide
78
33..55 QQooSS SSeettttiinngg EExxaammppllee
Assume a teleworker sometimes works at home and takes care of children. When working time, he would use Vigor router at home to connect to the server in the headquarter office downtown via either HTTPS or V PN to check email and access internal database. Meanwhile, children may chat on Skype in the restroom.
1. Go to Bandwidth Management>>Quality of Service.
2. Click Setup link of WAN(1/2/3). Make sure the QoS Control on the left corner is
checked. And select BOTH in Direction.
3. Set Inbound/Outbound bandwidth.
Note: The rate of outbound/inbound must be smaller than the real bandwidth to ensure correct calculation of QoS. It is suggested to set the bandwidth value for inbound/outbound as 80% - 85% of physical network speed provided by ISP to maximize the QoS performance.
Page 89
Vigor2912 Series User’s Guide
79
4. Return to previous page. Enter the Name of Index Class 1 by clicking Edit link. Type the
name “E-mail” for Class 1. Click OK to save the settings.
5. Click the Setup link for WAN2. The user can set reserved bandwidth (e.g., 25%) for
E-mail using protocol POP3 and SMTP. Click OK to save the settings.
6. Return to previous page. Enter the Name of Index Class 2 by clicking Edit link. In this
index, the user will set reserved bandwidth for HTTPS. And click OK.
Page 90
Vigor2912 Series User’s Guide
80
7. Click Setup link for WAN2.
8. Check Enable UDP Bandwidth Control on the bottom to prevent enormous UDP traffic
influent other application. Click OK.
9. If the worker has connected to the headquarter using host to host VPN tunnel. (Please
refer to Chapter 3 VPN for detail instruction), he may set up an index for it. Enter the Class Name of Index 3. In this index, he will set reserved bandwidth for 1 VPN tunnel.
Page 91
Vigor2912 Series User’s Guide
81
10. Click Edit for Class 3 to open a new window. In this index, the user will set reserved
bandwidth for VPN.
11. Click Add to open the following window. Check the ACT box, first.
12. Then click Edit of Local Address to set a worker’s subnet address. Click Edit of
Remote Address to set headquarter’s IP address. Leave other fields and click OK.
Page 92
Vigor2912 Series User’s Guide
82
33..66 HHooww ttoo uussee LLaannddiinngg PPaaggee FFeeaattuurree
Landing Page is a special feature configured under User Management. It can specify the message, content to be seen or specify which website to be accessed into when users try to access into the Internet by passing the authentication. Here, we take Vigor2912 series router as an example.
EExxaammppllee 1
1
UUsseerrss ccaann sseeee tthhee mmeessssaaggee ffoorr llaannddiinngg ppaaggee aafftteerr llooggggiinngg iinnttoo
IInntteerrnneett ssuucccceessssffuullllyy
1. Open the web user interface of Vigor2912.
2. Open User Management -> General Setup to get the following page. In the field of
Landing Page, please type the words of “Login Success”. Please note that the maximum number of characters to be typed here is 255.
3. Now you can enable the Landing Page function. Open User Management -> User
Profile and click one of the index number (e.g., index number 3) links.
Page 93
Vigor2912 Series User’s Guide
83
4. In the following page, check the box of Landing page and click OK to save the settings.
5. Open any browser (e.g., FireFox, Internet Explorer). The logging page will appear and
asks for username and password. Please type the correct username and password.
6. Click Login. If the logging is successful, you will see the message of Login Success
from the browser you use.
Page 94
Vigor2912 Series User’s Guide
84
EExxaammppllee 2
2
TThhee ssyysstteemm wwiillll ccoonnnneecctt ttoo hhttttpp::////wwwwww..ddrraayytteekk..ccoomm
aauuttoommaattiiccaallllyy aafftteerr llooggggiinngg iinnttoo IInntteerrnneett ssuucccceessssffuullllyy
1. In the field of Landing Page, please type the words as below:
“ <body stats=1><script language='javascript'> window.location='http://www.draytek.com'</script></body>”
2. Next, enable the Landing Page function. Open User Management -> User Profile and
click one of the index number (e.g., index number 3) links.
3. In the following page, check the box of Landing page and click OK to save the settings.
Page 95
Vigor2912 Series User’s Guide
85
4. Open any browser (e.g., FireFox, Internet Explorer). The logging page will appear and
asks for username and password. Please type the correct username and password.
5. Click Login. If the logging is successful, you will be directed into the website of
www.draytek.com
.
Page 96
Vigor2912 Series User’s Guide
86
33..77 HHooww ttoo CCrreeaattee aann AAccccoouunntt ffoorr MMyyVViiggoorr
The website of MyVigor (a server located on http://myvigor.draytek.com) provides several useful services (such as Anti-Spam, Web Content Filter, Anti-Intrusion, and etc.) to filtering the web pages for the sake of protecting your system.
To access into MyVigor for getting more information, please create an account for MyVigor.
33..77..11 CCrreeaattee aann AAccccoouunntt vviiaa VViiggoorr RRoouutteerr
1. Click CSM>> Web Content Filter Profile. The following page will appear.
Or Click System Maintenance>>Activation to open the following page.
Page 97
Vigor2912 Series User’s Guide
87
2. Click the Activate link. A login page for MyVigor web site will pop up automatically.
3. Click the link of Create an account now.
4. Check to confirm that you accept the Agreement and click Accept.
Page 98
Vigor2912 Series User’s Guide
88
5. Type your personal information in this page and then click Continue.
6. Choose proper selection for your computer and click Continue.
Page 99
Vigor2912 Series User’s Guide
89
7. Now you have created an account successfully. Click START.
8. Check to see the confirmation email with the title of
New Account Confirmation
Letter from myvigor.draytek.com.
9. Click the Activate my Account link to enable the account that you created. The following
screen will be shown to verify the register process is finished. Please click Login.
Page 100
Vigor2912 Series User’s Guide
90
10. When you see the following page, please type in the account and password (that you just
created) in the fields of UserName and Password.
11. Now, click Login. Your account has been activated. You can access into MyVigor server
to activate the service (e.g., WCF) that you want.
33..77..22 CCrreeaattee aann AAccccoouunntt vviiaa MMyyVViiggoorr WWeebb SSiittee
1. Access into http://myvigor.draytek.com. Find the line of Not registered yet?. Then, click
the link Click here! to access into next page.
Loading...