This is a User’s Guide for a series of products. Not all products support all firmware features. Screenshots
and graphics in this book may differ slightly from your product due to differences in your product
firmware or your computer operating system. Every effort has been made to ensure that the information
in this manual is accurate.
Related Documentation
•Quick Start Guide
The Quick Start Guide shows how to connect the VPN2S and access the Web Configurator wizards. It
contains information on setting up your network and configuring for Internet access.
•More Information
Go to support.zyxel.com to find other information on the
VPN2S.
VPN2S User’s Guide
2
Document Conventions
VPN2S
Warnings and Notes
These are how warnings and notes are shown in this guide.
Warnings tell you about things that could harm you or your device.
Note: Notes tell you other important information (for example, other things you may need to
configure or helpful tips) or recommendations.
Syntax Conventions
• All models in this series may be referred to as the “VPN2S” in this guide.
• Product labels, screen names, field labels and field choices are all in bold font.
• A right angle bracket ( > ) within a screen name denotes a mouse click. For example, Configuration > Log / Report > Log Settings means you first click Configuration in the navigation panel, then the Log
sub menu and finally the Log Settings tab to get to that screen.
Icons Used in Figures
Figures in this user guide may use the following generic icons. The VPN2S icon is not an exact
representation of your device.
LAN ......................................................................................................................................................... 78
Security Service ................................................................................................................................... 152
System .................................................................................................................................................. 217
Service / License ................................................................................................................................. 229
Device Name ...................................................................................................................................... 231
Host Name List ..................................................................................................................................... 233
Date / Time .......................................................................................................................................... 235
User Account ...................................................................................................................................... 238
USB Storage ......................................................................................................................................... 241
Language ............................................................................................................................................ 255
LAN ......................................................................................................................................................78
Appendix A Customer Support ..................................................................................................... 265
Appendix B Legal Information ....................................................................................................... 271
Index .................................................................................................................................................275
VPN2S User’s Guide
12
PART I
User’s Guide
13
1.1 Overview
The VPN2S is a VPN firewall with Gigabit Ethernet (GbE) gateway. It has two USB ports that can be used
for file sharing or using a 3G/4G dongle for cellular WAN (Internet) backup connections.
Features
• Four GbE Ports for LAN Connection
• Firewall with Secure Network Management
• Secure Access via VPN (IPsec, PPTP, L2TP)
Only use firmware for your VPN2S’s specific model. Refer to the label on
the bottom of your VPN2S.
CHAPTER 1
Introducing the VPN2S
1.2 Registration at myZyxel
myZyxelis Zyxel’s online services center where you can register your VPN2S and manage subscription
services available for your VPN2S (see Maintenance > Service / License for services available for your
VPN2S).
Note: You need to create a myZyxel account at http://portal.myZyxel.com before you can
register your device and activate the services at myZyxel.
You may need your VPN2S’s serial number and LAN MAC address to register it at
myZyxel. See the label at the back of the VPN2S’s for details.
VPN2S User’s Guide
14
Chapter 1 Introducing the VPN2S
Figure 1 myZyxel Login
1.3 Ways to Manage the VPN2S
Use any of the following methods to manage the VPN2S.
Web Configurator
The Web Configurator allows easy VPN2S setup and management using an Internet browser. This User’s
Guide provides information about the Web Configurator.
Figure 2 Managing the VPN2S: Web Configurator
FTP
Use File Transfer Protocol for firmware upgrades and configuration backup/restore.
VPN2S User’s Guide
15
Chapter 1 Introducing the VPN2S
SNMP
The device can be monitored and/or managed by an SNMP manager.
1.4 Good Habits for Managing the VPN2S
Do the following things regularly to make the VPN2S more secure and to manage the VPN2S more
effectively.
• Change the password. Use a password that’s not easy to guess and that consists of different types of
characters, such as numbers and letters. The password must have 6-64 printable characters [0-9][a-z]
[A-Z][!@#$%*].
• Write down the password and put it in a safe place.
• Back up the configuration (and make sure you know how to restore it). Restoring an earlier working
configuration may be useful if the device becomes unstable or even crashes. If you forget your
password, you will have to reset the VPN2S to its factory default settings. If you backed up an earlier
configuration file, you would not have to totally re-configure the VPN2S. You could simply restore your
last configuration.
1.5 Applications for the VPN2S
Here are some example uses for which the VPN2S is well suited.
1.5.1 Internet Access
As a VPN firewall your VPN2S has multiple WAN interfaces, including, 3G/4G and Gigabit Ethernet to
share the network traffic load. You can configure multiple WAN load balance and failover rules to
distribute traffic amongst the different interfaces.
If you prefer you can also use a 3G/4G dongle for cellular backup WAN (Internet) connections.
Note: If you connect all WAN ports the priority order will be Ethernet WAN port, and USB port.
VPN2S User’s Guide
16
Chapter 1 Introducing the VPN2S
VPN2S
VPN2S
Computers can connect to the VPN2S’s LAN ports.
Figure 3 VPN2S’s Internet Access Application
Figure 4 VPN2S’s Internet Access Application: 3G/4G WAN Backup
You can also configure IP filtering on the VPN2S for secure Internet access. When the IP filter is on, all
incoming traffic from the Internet to your network is blocked by default unless it is initiated from your
network. This means that probes from the outside to your network are not allowed, but you can safely
browse the Internet and download files.
1.5.2 VPN2S’s USB Support
Use the USB port for file sharing or insert a 3G/4G dongle for cellular backup WAN (Internet) connections.
VPN2S User’s Guide
17
Chapter 1 Introducing the VPN2S
VPN2S
File Sharing
Use the USB port (built-in USB 2.0) to share files on USB memory sticks or USB hard drives (B). Use FTP to
access the files on the USB device.
Figure 5 USB File Sharing Application
1.5.3 IPv6 Routing
The VPN2S supports IPv6 Ethernet and PPP. You may also create IPv6 policy routes.
Figure 6 Applications: IPv6 Routing
1.5.4 VPN Connectivity
Set up VPN tunnels with other companies, branch offices, telecommuters, and business travelers to
provide secure access to your network. AS is an Authentication Server in the below figure.
VPN2S User’s Guide
18
Figure 7 Applications: VPN Connectivity
1.5.5 Load Balancing
Set up multiple connections to the Internet on the same port, or different ports. In either case, you can
balance the traffic loads between them.
Figure 8 Applications: Multiple WAN Interfaces
Chapter 1 Introducing the VPN2S
1.6 LEDs (Lights)
This section describes the LEDs on the VPN2S.
The following figure shows the front and rear panels of the VPN2S.
VPN2S User’s Guide
19
Chapter 1 Introducing the VPN2S
Figure 9 VPN2S Front and Rear Panels
None of the LEDs are on if the VPN2S is not receiving power. The location of the LEDs are highlighted in
the figures above.
Table 1 LED Descriptions
LEDCOLORSTATUSDESCRIPTION
POWERGreenOnThe VPN2S is receiving power and ready for use.
BlinkingThe VPN2S is self-testing.
RedOnThe VPN2S detected an error while self-testing, or there is a device
OffThe VPN2S is not receiving power.
LANGreenOnThe VPN2S has a successful Ethernet connection with a device on the Local
BlinkingThe VPN2S is sending or receiving data to/from the LAN.
OffThe VPN2S does not have an Ethernet connection with the LAN.
WANGreenOnThe VPN2S has a successful Ethernet connection on the WAN.
BlinkingThe VPN2S is sending or receiving data to/from the WAN.
OffThere is no Ethernet connection on the WAN.
INTERNETGreenOnThe VPN2S has an IP connection but no traffic.
RedOnThe Ethernet WAN port is connected to an Ethernet port but the VPN2S
OffThere is no Internet connection or the gateway is in bridged mode.
MOBILEGreenOnThe VPN2S recognizes a 3G/4G dongle connection in USB port 1/2.
OffThe VPN2S does not detect a 3G/4G dongle connection in USB port 1/2.
USB GreenOnThe VPN2S recognizes a USB connection in USB port 1/2.
OffThe VPN2S does not detect a USB connection in USB port 1/2.
malfunction.
Area Network (LAN).
Your device has a WAN IP address (either static or assigned by a DHCP
server), PPP negotiation was successfully completed (if used).
cannot access the Internet. There is an Internet connection problem.
VPN2S User’s Guide
20
Table 1 LED Descriptions (continued)
LEDCOLORSTATUSDESCRIPTION
ETHERNET
LAN 1-4 (On
Connector)
Green
(Left LED)
1GM
Amber
(Right LED)
10-100M
OnThe VPN2S has a successful Ethernet connection with a device on the Local
Blinking The VPN2S is sending or receiving data to/from the LAN.
OffThe VPN2S does not have an Ethernet connection with the LAN.
OnThe VPN2S has a successful Ethernet connection with a device on the Local
Blinking The VPN2S is sending or receiving data to/from the LAN.
OffThe VPN2S does not have an Ethernet connection with the LAN.
1.7 The RESET Button
If you forget your password or cannot access the web configurator, you will need to use the RESET
button at the back of the device to reload the factory-default configuration file. This means that you will
lose all configurations that you had previously and the password will be reset to “1234”.
Chapter 1 Introducing the VPN2S
Area Network (LAN).
Area Network (LAN).
1Make sure the POWER LED is on (not blinking).
2To set the device back to the factory default settings, press the RESET button for five seconds or until the
POWER LED begins to blink and then release it. When the POWER LED begins to blink, the defaults have
been restored and the device restarts.
VPN2S User’s Guide
21
The Web Configurator
2.1 Overview
The web configurator is an HTML-based management interface that allows easy device setup and
management via Internet browser. Use Internet Explorer 10.0 and later versions, Mozilla Firefox 45 and
later versions, Google Chrome 45 and later versions, and Safari 9.0 and later versions. The
recommended screen resolution is 1024 by 768 pixels.
In order to use the web configurator you need to allow:
• Allow pop-up windows from your device (blocked by default in some Internet browsers).
• JavaScript (enabled by default).
• Java permissions (enabled by default).
2.1.1 Accessing the Web Configurator
CHAPTER 2
1Make sure your VPN2S hardware is properly connected (refer to the Quick Start Guide).
2Launch your web browser. If the VPN2S does not automatically re-direct you to the login screen, go to
http://192.168.1.1.
3A password screen displays. To access the administrative web configurator and manage the VPN2S,
type the default username admin and password 1234 in the password screen and click Login. If
advanced account security is enabled (see Section 20.3 on page 238) the number of dots that appears
when you type the password changes randomly to prevent anyone watching the password field from
knowing the length of your password. If you have changed the password, enter your password and click
Login.
Figure 10 Password Screen
VPN2S User’s Guide
22
Chapter 2 The Web Configurator
4The following screen displays if you have not yet changed your password from the default. Enter a new
password, retype it to confirm and click Apply. After changing the password your VPN2S will log out
automatically. so you can log in with your new password.
Figure 11 Change Password Screen
5The Privacy Statement screen appears automatically after login. Click on the check box to agree to all
the terms and click Acknowledge.
Figure 12 Privacy Statement Screen
6The Register screen appears after the Privacy Statement screen. Click OK in the Register screen to
register the VPN2S at myzyxel.com.
VPN2S User’s Guide
23
Chapter 2 The Web Configurator
B
A
C
Figure 13 Register Screen
7The Wizard appears after the Register screen. Use the Wizard to configure VPN2S’s basic settings. See
Chapter 3 on page 29 for more information.
8The Dashboard page appears after the Wizard set up, here you can view the VPN2S’s interface and
system information.
2.2 Web Configurator Layout
Figure 14 Screen Layout
As illustrated above, the main screen is divided into these parts:
• A - title bar
• B - navigation panel
• C - main window
VPN2S User’s Guide
24
2.2.1 Title Bar
The title bar provides some icons in the upper right corner.
The icons provide the following functions.
Table 2 Web Configurator Icons in the Title Bar
ICON DESCRIPTION
2.2.2 Navigation Panel
Chapter 2 The Web Configurator
Help: Click this icon to view a description of the screen you are currently using.
Logout: Click this icon to log out of the web configurator.
Click a color from the palette to change the color of your web configurator.
Use the menu items on the navigation panel to open screens to configure VPN2S features. The following
tables describe each menu item.
Table 3 Navigation Panel Summary
LINKTABFUNCTION
DashboardClick this to go to the main Web Configurator screen.
WizardUse this screen to configure the VPN2S’s basic settings. For more
information see Chapter 3 on page 29.
Configuration
Configuration
Site Map
WAN / Internet
WAN StatusUse this screen to view the WAN ports’ status.
WAN SetupUse this screen to view and configure ISP parameters, WAN IP address
Mobile Use this screen to configure the mobile 3G/4G connection.
Port SettingUse this screen to set flexible ports as part of LAN or WAN interfaces.
Multi-WANUse this screen to configure the multiple WAN load balance and failover
Dynamic
DNS
LAN / Home Network
Click this to view a summary of all the available screens in the
Configuration menu.
assignment, and other advanced properties. You can also add new WAN
connections.
rules to distribute traffic among different interfaces.
Use this screen to allow a static hostname alias for a dynamic IP address.
VPN2S User’s Guide
25
Chapter 2 The Web Configurator
Table 3 Navigation Panel Summary (continued)
LINKTABFUNCTION
LAN StatusLAN StatusUse this screen to view the status of all network traffic going through the
LAN ports of the VPN2S.
DHCP ClientUse this screen to view the status of all devices connected to the VPN2S.
You can also set screen refresh time to see updates on new devices.
ARP TableUse this screen to view the ARP table. It displays the IP and MAC address
Multicast Status Use this screen to look at IGMP/MLD group status and traffic statistics.
LAN SetupUse this screen to configure LAN TCP/IP settings, and other advanced
Static DHCPUse this screen to assign specific IP addresses to individual MAC
Additional
Subnet
Wake on LANUse this screen to remotely wake up a hibernating device on the local
VLAN /
Interface
Group
DNS EntryUse this screen to view and configure a domain name and DNS routes on
DNS
Forwarder
Routing
Routing
Status
Policy RouteUse this screen to view and set up policy routes on the VPN2S.
Static RouteUse this screen to view and set up static routes on the VPN2S.
RIPUse this screen to set up RIP (Routing Information Protocol) settings on the
NAT
Port
Forwarding
Port
Triggering
Address
Mapping
Default
Server
ALGUse this screen to enable or disable NAT ALG and SIP ALG.
Firewall / Security
Firewall
Overview
DoSUse this screen to activate protection against Denial of Service (DoS)
Firewall RulesUse this screen to add and view existing firewall rules to the VPN2S.
Device
Service
Zone ControlUse this screen to set the firewall’s default actions based on the direction
of each DHCP connection.
properties.
addresses.
Use this screen to configure IP alias.
network.
Use this screen to create a new interface group, which is a new LAN
bridge interface (subnet).
the VPN2S.
Use this screen to view and configure domain zone forwarder on the
VPN2S.
Use this screen to view the IPv4 and IPv6 routing flow.
VPN2S.
Use this screen to make your local servers visible to the outside world.
Use this screen to change your VPN2S’s port triggering settings.
Use this screen to change your VPN2S’s address mapping settings.
Use this screen to configure a default server which receives packets from
ports that are not specified in the Port Forwarding screen.
Use this screen to enable the firewall.
attacks.
Use this screen to manage the services (such as HTTP and SSH) in the
VPN2S.
of travel of packets.
VPN2S User’s Guide
26
Chapter 2 The Web Configurator
Table 3 Navigation Panel Summary (continued)
LINKTABFUNCTION
ServiceUse this screen to add Internet services.
MAC FilterUse this screen to block or allow traffic from devices of certain MAC
addresses to the VPN2S.
CertificateUse this screen to view a summary list of certificates and manage
certificates and certification requests.
AAA ServerUse this screen to manage the list of LDAP and RADIUS servers the VPN2S
Security Service
Content FilterUse this screen to control access to specific websites or web content.
VPN
VPN StatusUse this screen to look at the status of VPN tunnels that are currently
IPsec VPNUse this screen to display and manage IPsec VPN gateways and
PPTP VPNUse this screen to configure the PPTP VPN settings in the VPN2S.
L2TP VPNUse this screen to configure L2TP over IPsec tunnels.
L2TP Client
Status
GRE VPNUse this screen to configure the GRE VPN settings in the VPN2S.
Bandwidth Management
GeneralUse this screen to enable QoS and traffic prioritizing. You can also
Queue SetupUse this screen to configure QoS queues.
Classification
Setup
Policer SetupUse these screens to configure QoS policers.
Shaper SetupUse this screen to limit outgoing traffic transmission rate on the selected
Network Management
SNMPUse this screen to configure SNMP communities and services.
System
Scheduler
Rule
Log/Report
Log ViewerUse this screen to view the system logs on the VPN2S.
Log SettingsUse this screen to change specify settings to recording your logs on the
Maintenance
Maintenance
Site Map
Service / LicenseUse this screen to view the status of your licenses and update any license
Device NameUse this screen to give your VPN2S a name.
Host Name ListUse this screen to add connected devices to the VPN2S.
Date / TimeUse this screen to change your VPN2S’s time and date.
can use in authenticating users.
established.
connections.
Use this screen to view details about the L2TP clients.
configure the QoS rules and actions.
Use this screen to define a classifier.
interface.
Use this screen to configure the days and times when a configured
restriction (such as User Access control) is enforced.
VPN2S.
Click this to view a summary of all the available screens in the
Maintenance menu.
information.
VPN2S User’s Guide
27
Table 3 Navigation Panel Summary (continued)
LINKTABFUNCTION
User AccountUse this screen to manage user accounts, which includes configuring the
USB StorageUse this screen to enable USB storage sharing.
DiagnosticNetwork ToolsUse this screen to ping an IP address or trace the route packets take to a
Firmware Upgrade
Firmware Use this screen to upload firmware to your device.
Mobile ProfileUse this screen to update the mobile profile on the VPN2S.
Backup / RestoreUse this screen to backup and restore your device’s configuration
LanguageUse this screen to change the VPN2S web configurator’s language,
Restart /
Shutdown
2.2.3 Main Window
Chapter 2 The Web Configurator
username, password, retry times, file sharing, captive portal, and
customizing the login message.
host
Packet CaptureUse this screen to capture packets going through the VPN2S.
(settings) or reset the factory default settings.
Use this screen to reboot the VPN2S without turning the power off.
The main window displays information and configuration fields. It is discussed in the rest of this
document.
If you click Dashboard a graphic shows the connection status of the VPN2S’s ports. The connected
interfaces are in color and disconnected interfaces are gray.
Figure 15 Dashboard Screen
VPN2S User’s Guide
28
3.1 Overview
The Web Configurator's quick setup Wizard helps you configure Internet and VPN connection settings.
This chapter provides information on configuring the Wizard screens in the Web Configurator. See the
feature-specific chapters in this User’s Guide for background information.
Before you begin configuring your VPN2S register your device at myZyxel portal and check your current
license status.
The Wizard consists of the following setups:
• Wizard Basic Setup - Use Basic Setup to set up a WAN (Internet) connection. This Wizard creates
matching ISP account settings in the VPN2S if you use PPPoE. See Section 3.2 on page 30.
• Wizard IPsec VPN Setup - Use IPsec VPN Setup to configure an IPsec VPN (Virtual Private Network) rule
for a secure connection to another computer or network. See Section 3.3 on page 35.
• Wizard IPv6 Setup - Use IPv6 Setup to configure the IPv6 settings on your VPN2S. See Section 3.4 on
page 43.
Figure 16 Wizard Setup
CHAPTER 3
Wizard
Note: See the technical reference chapters (starting on page 47) for background information
on the features in this chapter.
VPN2S User’s Guide
29
3.2 Wizard Basic Setup
The Wizard appears automatically after you log in the first time. Or you can go to the Wizard tab in the
navigation panel. Click the Welcome to Basic Setup down arrow to configure an interface to connect
to the Internet. Click Next to continue the Wizard, Back to return to the previous screen.
Figure 17 Wizard Basic Setup
Chapter 3 Wizard
1Enter your Internet connection information in this screen. The screen and fields to enter may vary
depending on your current connection type and the Encapsulation you choose. You can also use this
screen to enable the VLAN tag in the VPN2S. Assign it a priority level (802.1p) and a VLAN ID for traffic
through this connection. Click Next.
VPN2S User’s Guide
30
Loading...
+ 249 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.