Thank you for choosing NETGEAR.
After installing your device, locate the serial number on the label of your product and use it to register your product
at https://my.netgear.com. You must register your product before you can use NETGEAR telephone support.
NETGEAR recommends registering your product through the UTM’s Registration screen (see Register the UTM
with NETGEAR on page 65). You can also register your product through the NETGEAR website. For product
updates and web support, visit http://support.netgear.com.
Phone (US & Canada only): 1-888-NETGEAR.
Phone (Other Countries): Check the list of phone numbers at
202-10780-02 2.0May 2012•Updated the main navigatio n menus and configuration
202-10780-02 1.0April 2012•Added new features for all UTM models:
1.0
(continued)
October 2012
(continued)
(continued)
•Added Appendix C, 3G/4G Dongles for the UTM9S and
UTM25S.
•Added many more default values to Appendix H, Default
Settings and Technical Specifications.
menus for many figures in the manual to show consistency
in the presentation of the web management interface
(GUI).
•Updated the outbound rules overview (see Table 27) and
inbound rules overview (Table 28).
•Updated Features That Reduce Traffic and Features That
Increase Traffic.
- Application control (see Configure Application Control)
- Traffic metering for LAN usage (see Create Traffic
Meter Profiles)
- The use of custom user groups in firewall rules (see
Overview of Rules to Block or Allow Specific Kinds of
Traffic and VLAN Rules)
Application control and traffic metering also affect the way
that firewall rules are implemented (see Overview of Rules
to Block or Allow Specific Kinds of Traffic)
•Added support of the following features for all UTM models
(these features were previously supported on the UTM9S
only):
- ReadyNAS integration, quarantine options, and
quarantine logs (see Connect to a ReadyNAS and
Configure Quarantine Settings, Query and Manage the
Quarantine Logs, and Appendix E, ReadyNAS
Integration)
- PPTP server (see Configure the PPTP Server)
- L2TP server (see Configure the L2TP Server)
•Revised the following existing features:
- Firewall scheduling (see Set a Schedule to Block or
Allow Specific Traffic and Overview of Rules to Block or
Allow Specific Kinds of Traffic)
- IPS (see Enable and Configure the Intrusion
Prevention System)
- System status, dashboard, and report functions (see
Chapter 11, Monitor System Access and Performance)
- Diagnostics (see Use Diagnostics Utilities)
•Reorganized the web managem en t in terface (GUI) menus
(for example, the Email Notification configuration menu
link has been moved to the Monitoring main menu; the
Custom Groups configuration menu link has been moved
to the Users main menu)
202-10780-01 1.0September 2011 •Added the UTM9S with the foll owing major new features:
- xDSL module (see Chapter 1, Introduction and Chapter
3, Manually Configure Internet and WAN Settings)
- Wireless module (see Chapter 1, Introduction and
Appendix B, Wireless Network Module for the UTM9S
and UTM25S)
- ReadyNAS integration, quarantine options, and
quarantine logs (see Connect to a ReadyNAS and
Configure Quarantine Settings, Query and Manage the
Quarantine Logs, and Appendix E, ReadyNAS
Integration)
- PPTP server (see Configure the PPTP Server)
- L2TP server (see Configure the L2TP Server)
•Updated the VPN client sections with the new VPN client
(see Chapter 7, Virtual Private Networking
Using IPSec, PPTP, or L2TP Connections)
202-10674-02 1.0March 2011•Added the UTM150.
•Removed the platform-specific chapters and sections
because the UTM5, UTM10, and UTM25 now support the
same web management interface menu layout that was
already supported on the UTM50. The major cha nges for
the UTM5, UTM10, and UTM25 are documented in
Chapter 3, Manually Configure Internet and WAN Settings,
and in the following sections:
- Set Exception Rules for Web and Application Access
- Configure Authentication Domains, Groups, and Users
•Added new features (for all UTM models). The major new
features are documented in the following sections:
- Electronic Licensing
- VLAN Rules
- Create Service Groups
- Create IP Groups
- Manage SSL Certificates for HTTPS Scanning
- Update the Firmware
- View, Schedule, and Generate Reports
202-10674-01 1.0September 2010 •Added the UTM50 and UTM5 0-specific chapters and
sections.
•Revised the DMZ WAN and LAN DMZ default policies.
•Added the Requirements for Entering IP Addresses
section.
•Added a note about the processing of normal email traffic
in the Configure Distributed Spam Analysis section.
•Updated the NTP section.
202-10482-02 1.0January 2010Updated the web management interface screens, made the
manual platform-independent, added a model comparison
table, and removed performance specifications (see marketing
documentation for such specifications).
202-10482-01 1.0September 2009 Initial publication of this reference manual.
4
Contents
Chapter 1Introduction
What Is the ProSecure Unified Threat Management (UTM) Appliance? . .15
Appendix INotification of Compliance (Wired)
Appendix JNotification of Compliance (Wireless)
Index
14
1. Introduction
This chapter provides an overview of the features and capabilities of the NETGEAR ProSecure®
Unified Threat Management (UTM) Appliance. This chapter contains the following sections:
•What Is the ProSecure Unified Threat Management (UTM) Appliance?
•Key Features and Capabilities
•Service Registration Card with License Keys
•Package Contents
•Hardware Features
•Choose a Location for the UTM
Note: For more information about the topics covered in this manual, visit the
Support website at http://support.netgear.com.
1
Note: Firmware updates with new features and bug fixes are made
available from time to time at downloadcenter.netgear.com. Some
products can regularly check the site and download new firmware,
or you can check for and download new firmware manually. If the
features or behavior of your product do not match what is described
in this guide, you might need to update your firmware.
What Is the ProSecure Unified Threat Management (UTM)
Appliance?
The ProSecure Unified Threat Management (UTM) Appliance, hereafter referred to as the
UTM, connects your local area network (LAN) to the Internet through one or two external
broadband access devices such as cable modems, DSL modems, satellite dishes, or
wireless ISP radio antennas, or a combination of those. Dual wide area network (WAN) port s
allow you to increase the effective data rate to the Internet by utilizing both WAN ports to
carry session traffic, or to maintain a backup connection in case of failure of your primary
Internet connection.
As a complete security solution, the UTM combines a powerful, flexib le firewall with a content
scan engine that uses NETGEAR Stream Scanning technology to protect your network from
denial of service (DoS) attacks or distributed DoS (DDoS) attacks, unwanted traffic, traffic
with objectionable content, spam, phishing, and web-borne threats such as spyware, viruses,
and other malware threats.
The UTM provides advanced IPSec and SSL VPN technologies for secure and simple
remote connections. The use of Gigabit Ethernet LAN and WAN ports ensures high data
transfer speeds.
The UTM is a plug-and-play device that can be installed and configured within minutes.
Key Features and Capabilities
•Multiple WAN Port Models for Increased Reliability or Outbound Load Balancing
•Wireless Features
•DSL Features
•Advanced VPN Support for Both IPSec and SSL
•A Powerful, True Firewall
•Stream Scanning for Content Filtering
•Security Features
•Autosensing Ethernet Connections with Auto Uplink
•Extensive Protocol Support
•Easy Installation and Management
•Maintenance and Support
•Model Comparison
The UTM provides the following key features and capabilities:
•For the single WAN port models, a single 10/100/1000 Mbps Gigabit Ethernet WAN port.
For the multiple WAN port models, dual or quad 10/100/1000 Mbps Gigabit Ethernet
WAN ports for load balancing or failover protection of your Internet connection, providing
increased system reliability or increased data rate.
•Built-in four- or six-port 10/100/1000 Mbps Gigabit Ethernet LAN switch for fast data
transfer between local network resources.
•Wireless network module (UTM9S and UTM25S only) for either 2.4-GHz or 5-GHz
wireless modes.
•xDSL network module (UTM9S and UTM25S only) for ADSL and VDSL.
•3G/4G dongle (UTM9S and UTM25S only) for wireless connection to an ISP.
•Depending on the model, bundled with a one-user license of the NETGEAR ProSafe
VPN Client software (VPN01L).
•Advanced stateful packet inspection (SPI) firewall with multi-NAT support.
•Patent-pending S tream Scanning technology that enables scanning of real-t ime protocols
such as HTTP.
•Comprehensive web and email security, covering six major network protocols: HTTP,
HTTPS, FTP, SMTP, POP3, and IMAP.
•Malware database containing hundreds of thousands of signatures of spyware, viruses,
and other malware threats.
•Very frequently updated malware signatures, hourly if necessary. The UTM can
automatically check for new malware signatures as frequently as every 15 minutes.
•Multiple antispam technologies to provide extensive protection against unwanted mail.
•Application control for multiple categories of applications and individual applications to
safeguard data, protect users, and enhance productivity.
•Easy, web-based wizard setup for installation and management.
•SNMP manageable with support for SNMPv1, SNMPv2, and SNMPv3.
•Support for the NETGEAR Network Management System NMS200.
•Front panel LEDs for easy monitoring of status and activity.
•Flash memory for firmware upgrade.
•Internal universal switching power supply.
Multiple WAN Port Models for Increased Reliability or
Outbound Load Balancing
The UTM product line offers models with two broadband WAN ports. The second WAN port
allows you to connect a second broadband Internet line that can be configured on a mutually
exclusive basis to:
•Provide backup and rollover if one line is inoperable, ensuring that you are never
disconnected.
•Load balance, or use both Internet lines simultaneously for outgoing traffic. A UTM with
dual WAN port s balances users between the two line s f or maximum bandwidth efficiency.
See Appendix D, Network Planning for Dual WAN Port s (Multiple W AN Port Models Only) for
the planning factors to consider when implementing the following capabilities with dual WAN
port gateways:
Wireless client connections are supported on the UTM9S and UTM25S with an NMWLSN
wireless network module installed. The UTM9S and UTM25S support the following wireless
features:
•2.4-GHz radio and 5-GHz radio. Either 2.4-GHz band support with 802.11b/g/n/ wireless
modes or 5-GHz band support with 802.11a/n wireless modes.
•Wireless security profiles. Support for up to four wireless security profiles, each with it s
own SSID.
•WMM QoS priority. Wi-Fi Multimedia (WMM) Quality of Service (QoS) priority settings to
map one of four queues to each Differentiated Services Code Point (DSCP) value.
•Wireless Distribution System (WDS). WDS enables expansion of a wireless network
through two or more access points that are interconnected.
•Access control. The Media Access Control (MAC) address filtering feature can ensure
that only trusted wireless stations can use the UTM to gain access to your LAN.
•Hidden mode. The SSID is not broadcast, assuring that only clients configured with the
correct SSID can connect.
•Secure and economical operation. Adjustable power output allows more secure or
economical operation.
•3G/4G dongle. Mobile broadband USB adapter for a wireless connection to an ISP.
DSL Features
DSL is supported on the UTM9S and UTM25S with an NMVDSLA or NMVDSLB DSL
network module installed. The UTM9S and UTM25S support the following types of DSL
connections:
•ADSL, ADSL2, and ADSL2+
•VDSL and VDSL2
Annex A, Annex B, and Annex M are supported to accommodate PPPoE, PPPoA, and IPoA
ISP connections.
Advanced VPN Support for Both IPSec and SSL
The UTM supports IPSec and SSL virtual private network (VPN) connections.
•IPSec VPN delivers full network access between a central office and branch offices, or
between a central office and telecommuters. Remote access by telecommuters requires
the installation of VPN client software on the remote computer.
-IPSec VPN with broad protocol support for secure connection to other IPSec
gateways and clients.
-Depending on the model, bundled with a one-user license of the NETGEAR ProSafe
•SSL VPN provides remote access for mobile users to selected corporate resources
without requiring a preinstalled VPN client on their computers.
-Uses the familiar Secure Sockets Layer (SSL) protocol, commonly used for
e-commerce transactions, to provide client-free access with customizable user
portals and support for a wide variety of user repositories.
-Allows browser-based, platform-independent remote access through a number of
popular browsers, such as Microsoft Internet Explorer, Mozilla Firefox, and Apple
Safari.
-Provides granular access to corporate resources based on user type or group
membership.
A Powerful, True Firewall
Unlike simple NA T routers, the UTM is a true firewall, using st ateful packet inspection (SPI) to
defend against hacker attacks. Its firewall features have the following capabilities:
•DoS protection. Automatically detects and thwarts (distributed) denial of service (DoS)
attacks such as Ping of Death and SYN flood.
•Secure firewall. Blocks unwanted traffic from the Internet to your LAN.
•Schedule policies. Permits scheduling of firewall policies by day and time.
•Logs security incidents. Logs security events such as blocked incoming traffic, port
scans, attacks, and administrator logins. You can configure the firewall to email the log to
you at specified intervals. You can also configure the firewall to send immediate alert
messages to your email address or email pager whenever a significant event occurs.
Stream Scanning for Content Filtering
Stream Scanning is based on the simple observation that network traffic travels in streams.
The UTM scan engine starts receiving and analyzing traf fic as the stream enters the network.
As soon as a number of bytes are available, scanning starts. The scan engine continues to
scan more bytes as they become available, while at the same time another thread starts to
deliver the bytes that have been scanned.
This multithreaded approach, in which the receiving, scanning, and delivering processes
occur concurrently, ensures that network performance remains unimpeded. The result is that
file scanning is up to five times faster than with traditional antivirus solutions—a performance
advantage that you really notice.
Stream Scanning also enables organizations to withstand massive spikes in traffic, as in the
event of a malware outbreak. The scan engine has the following capabilities:
•Real-time protection. The patent-pending Stream Scanning technology enables
scanning of previously undefended real-time protocols, such as HTTP. Network activities
susceptible to latency (for example, web browsing) are no longer brought to a standstill.
•Comprehensive protection. Provides both web and email security, covering six major
network protocols: HTTP, HTTPS, FTP, SMTP, POP3, and IMAP. The UTM uses
enterprise-class scan engines employing both signature-based and distributed spam
analysis to stop both known and unknown threats. The malware database contains
hundreds of thousands of signatures of spyware, viruses, and other malware.
•Objectionable traffic protection. The UTM prevents objectionable content from
reaching your computers. You can control access to the Internet content by screening for
web services, web addresses, and keywords within web addresses. You can log and
report attempts to access objectionable Internet sites.
•Application control. The UTM provides application control for entire categories of
applications, individual applications, or a combination of both. You can either globally
allow or block applications or configure custom application control profiles for groups of
users, individual users, or a combination of both. The UTM supports multiple applications.
•Automatic signature updates. Malware signatures are updated as frequently as every
hour, and the UTM can check automatically for new signatures as frequently as every 15
minutes.
Security Features
The UTM is equipped with several features designed to maintain security:
•Computers hidden by NAT. NAT opens a temporary path to the Internet for requests
originating from the local network. Requests originating from outside the LAN are
discarded, preventing users outside the LAN from finding and directly accessing the
computers on the LAN.
•Port forwarding with NAT. Although NAT prevents Internet locations from directly
accessing the computers on the LAN, the UTM allows you to direct incoming traffic to
specific computers based on the service port number of the incoming request. You can
specify forwarding of single ports or ranges of ports.
•DMZ port. Incoming traffic from the Internet is usually discarded by the UTM unless the
traffic is a response to one of your local computers or a service for which you have
configured an inbound rule. Instead of discarding this traffic, you can use the dedicated
demilitarized zone (DMZ) port to forward the traffic to one computer on your network.
Autosensing Ethernet Connections with Auto Uplink
With its internal four- or six-port 10/100/1000 Mbps switch and single or dual
(model-dependant) 10/100/1000 WAN ports, the UTM can connect to either a 10-Mbps
standard Ethernet network, a 100-Mbps Fast Ethernet network, or a 1000-Mbps Gigabit
Ethernet network. The four LAN and one or two WAN interface s are autosensing and capable
of full-duplex or half-duplex operation.
TM
The UTM incorporates Auto Uplink
whether the Ethernet cable plugged into the port should have a normal connection such as to
a computer or an uplink connection such as to a switch or hub. Tha t port then configures it self
correctly. This feature eliminates the need for you to think about crossover cables, as Auto
Uplink accommodates either type of cable to make the right connection.
technology. Each Ethernet port automatically senses
The UTM supports the T ransmission Control Protocol/Internet Proto col (TCP/IP) and Routing
Information Protocol (RIP). For further information about TCP/IP, see Internet Configuration
Requirements on page 624. The UTM provides the following protocol support:
•IP address sharing by NAT. The UTM allows many networked computers to share an
Internet account using only a single IP address, which might be statically or dynamically
assigned by your Internet service provider (ISP). This technique, known as Network
Address Translation (NAT), allows the use of an inexpensive single-user ISP account.
•Automatic configuration of attached computers by DHCP. The UTM dynamically
assigns network configuration information, including IP, gateway, and Domain Name
Server (DNS) addresses, to attached computers on the LAN using the Dynamic Host
Configuration Protocol (DHCP). This feature greatly simplifies configuration of computers
on your local network.
•DNS proxy. When DHCP is enabled and no DNS addresses are specified, the firewall
provides its own address as a DNS server to the attached computers. The firewall obt ains
actual DNS addresses from the ISP during connection setup and forwards DNS request s
from the LAN.
•PPP over Ethernet (PPPoE). PPPoE is a protocol for connecting remote hosts to the
Internet over a DSL connection by simulating a dial-up connection.
•Quality of Service (QoS). The UTM supports QoS, including traffic prioritization and
traffic classification with Type of Service (ToS) and Differentiated Services Code Point
(DSCP) marking.
Easy Installation and Management
You can install, configure, and operate the UTM within minutes after connecting it to the
network. The following features simplify installation and management tasks:
•Browser-based management. Browser-based configuration allows you to easily
configure the UTM from almost any type of operating system, such as Windows,
Macintosh, or Linux. A user-friendly Setup Wizard is provided, and online help
documentation is built into the browser-based web management interface.
•Autodetection of ISP. The UTM automatically senses the type of Internet connection,
asking you only for the information required for your type of ISP account.
•IPSec VPN Wizard. The UTM includes the NETGEAR IPSec VPN Wizard so you can
easily configure IPSec VPN tunnels according to the recommendations of the Virtual
Private Network Consortium (VPNC). This ensures that the IPSec VPN tunnels are
interoperable with other VPNC-compliant VPN routers and clients.
•SSL VPN Wizard. The UTM includes the NETGEAR SSL VPN Wizard so you can easily
configure SSL connections over VPN according to the recommendations of the VPNC.
This ensures that the SSL connections are interoperable with other VPNC-compliant
VPN routers and clients.
•SNMP. The UTM supports the Simple Network Management Protocol (SNMP) to let you
monitor and manage log resources from an SNMP-compliant system manager. The
SNMP system configuration lets you change the system variables for MIB2.
•Diagnostic functions. The UTM incorporates built-in diagnostic functions such as ping,
traceroute, DNS lookup, and remote reboot.
•Remote management. The UTM allows you to log in to the web management interface
from a remote location on the Internet. For security, you can limit remote management
access to a specified remote IP address or range of addresses.
•Visual monitoring. The UTM’s front panel LEDs provide an easy way to monitor its
status and activity.
Maintenance and Support
NETGEAR offers the following features to help you maximize your use of the UTM:
•Flash memory for firmware upgrades.
•Technical support seven days a week, 24 hours a day. Information about support is
available on the NETGEAR ProSecure website at
http://prosecure.netgear.com/support/index.php.
Model Comparison
The following table compares the UTM models to show the differences. For performance
specifications and sizing guidelines, see NETGEAR’s marketing documentation at
FeatureUTM5UTM9SUTM10UTM25UTM25S UTM50UTM150
Network Modules and Broadband Adapters
xDSL network module with RJ11 port
Wireless network module
3G/4G USB dongle
Deployment
VLAN support
Dual WAN auto-rollover mode
Dual WAN load balancing mode
Single WAN mode
Service Registration Card with License Keys
Be sure to store the license key card that came with your UTM (see a sample card in the
following figure) in a secure location. If you do not use electronic licensing (see Electronic
Licensing on page 67), you need these service license keys to activate your product during
the initial setup. The service license keys are assigned to the serial number of your product.
Note: When you reset the UTM to the original factory default settings after
you have entered the license keys to activate the UTM (se e Register
the UTM with NETGEAR on page 65), the license keys are erased.
The license keys and the different types of licenses that are
available for the UTM are no longer displayed on the Registration
screen. However, af ter you have reconfigured the UTM to connect to
the Internet and to the NETGEAR registration server, the UTM
retrieves and restores all registration information based on its MAC
address and hardware serial number . You do not need to reenter the
license keys and reactivate the UTM.
Package Contents
The UTM product package contains the following items:
-ProSafe VPN Client software (VPN01L) (depends on the UTM model)
•Service Registration Card with license keys
If any of the parts are incorrect, missing, or damaged, contact your NETGEAR dealer. Keep
the carton, including the original packing materials, in case you need to return the product for
repair.
Hardware Features
•Front Panel UTM5 and UTM10
•Front Panel UTM25
•Front Panel UTM50
•Front Panel UTM150
•Front Panel UTM9S and UTM25S and Network Modules
•LED Descriptions, UTM5, UTM10, UTM25, UTM50, and UTM150
•LED Descriptions, UTM9S, UTM25S, and their Network Modules
The front panels contain ports an d LEDs; the rear panels contain port s, connectors, and other
components; and the bottom panels contain product labels.
Front Panel UTM5 and UTM10
Viewed from left to right, the UTM5 and UTM10 front panel contains the following ports:
•One nonfunctioning USB port. This port is included for future management
enhancements. The port is currently not operable on the UTM.
•LAN Ethernet ports. Four switched N-way automatic speed negotiating, Auto MDI/MDIX,
Gigabit Ethernet ports with RJ-45 connectors.
•WAN Ethernet port. One independent N-way automatic speed negotiating, Auto
MDI/MDIX, Gigabit Ethernet ports with RJ-45 connectors.
The front panel also contains three groups of status indicator light-emitting diodes (LEDs),
including Power and Test LEDs, LAN LEDs, and WAN LEDs, all of which are explained in
detail in Table 2 on page 30. In addition, the front panel provides some LED explanation to
the left of the LAN ports.
Viewed from left to right, the UTM25 front panel contains the following ports:
•One nonfunctioning USB port. This port is included for future management
enhancements. The port is currently not operable on the UTM.
•LAN Ethernet ports. Four switched N-way automatic speed negotiating, Auto MDI/MDIX,
Gigabit Ethernet ports with RJ-45 connectors.
•WAN Ethernet ports. Two independent N-way automatic speed negotiating, Auto
MDI/MDIX, Gigabit Ethernet ports with RJ-45 connectors.
The front panel also contains three groups of st atus indicator LEDs, including Powe r and Test
LEDs, LAN LEDs, and WAN LEDs, all of which are explained in detail in Table 2 on page 30.
In addition, the front panel provides some LED explanation to the left of the LAN ports.
Figure 3. Front panel UTM25
Front Panel UTM50
Viewed from left to right, the UTM50 front panel contains the following ports:
•One nonfunctioning USB port. This port is included for future management
enhancements. The port is currently not operable on the UTM.
•LAN Ethernet ports. Six switched N-way automatic speed negotiating, Auto MDI/MDIX,
Gigabit Ethernet ports with RJ-45 connectors.
•WAN Ethernet ports. Two independent N-way automatic speed negotiating, Auto
MDI/MDIX, Gigabit Ethernet ports with RJ-45 connectors.
The front panel also contains three groups of st atus indicator LEDs, including Powe r and Test
LEDs, LAN LEDs, and WAN LEDs, all of which are explained in detail in Table 2 on page 30.
In addition, the front panel provides some LED explanation to the right of the WAN ports.
Viewed from left to right, the UTM150 front panel contains the following ports:
•One nonfunctioning USB port. This port is included for future management
enhancements. The port is currently not operable on the UTM.
•LAN Ethernet ports. Four switched N-way automatic speed negotiating, Auto MDI/MDIX,
Gigabit Ethernet ports with RJ-45 connectors.
•WAN Ethernet ports. Four independent N-way automatic speed negotiating, Auto
MDI/MDIX, Gigabit Ethernet ports with RJ-45 connectors.
The front panel also contains three group s of status indicator LEDs, including Power and Test
LEDs, LAN LEDs, and WAN LEDs, all of which are explained in d et a il in Table 2 on page 30.
In addition, the front panel provides some LED explanation to the right of the WAN ports.
Viewed from left to right, the UTM9S and UTM25S front panel contains the following ports
and slots:
•One USB port that can accept a 3G/4G dongle for wireless connectivity to an ISP. The
port is currently operable on the UTM9S and UTM25S only.
•LAN Ethernet ports. Four switched N-way automatic speed negotiating, Auto MDI/MDIX,
Gigabit Ethernet ports with RJ-45 connectors.
•WAN Ethernet ports. Two independent N-way automatic speed negotiating, Auto
MDI/MDIX, Gigabit Ethernet ports with RJ-45 connectors.
The front panel also contains three groups of st atus indicator LEDs, including Powe r and Test
LEDs, LAN LEDs, and WAN LEDs, all of which are explained in detail in Table 3 on page 32.
Some LED explanation is provided on the front panel below the LAN and WAN ports.
The following xDSL network modules are available for insertion in one of the UTM9S or
UTM25S slots:
•NMSDSLA. VDSL/ADSL2+ network module, Annex A.
•NMSDSLB. VDSL/ADSL2+ network module, Annex B.
Note: In previous releases for the UTM9S, these network modules were
referred to as the UTM9SDSLA and UTM9SDSLB. The UTM9SDSLA
is identical to the NMSDSLA, and the UTM9SDSLB is identical to the
NMSDSLB.
The xDSL network module provides one RJ-11 port for connection to a telephone line. The
two LEDs are explained in Table 3 on page 32.
Figure 7. xDSL network module
Wireless Network Modules
The wireless network module (NMSWLSN) can be inserted in one of the UTM9S and
UTM25S slots. The wireless network module does not provide any ports. The antennas are
detachable. The two LEDs are explained in Table 3 on page 32.
Note: In previous releases for the UTM9S, this network module was referred to
as the UTM9SWLSN. The UTM9SWLSN is identical to the NMSWLSN.