IMPORTANT!
READ CAREFULLY BEFORE USE.
KEEP THIS GUIDE FOR FUTURE REFERENCE.
This is a User’s Guide for a series of products. Not all products support all firmware features.
Screenshots and graphics in this book may differ slightly from your product due to differences in
your product firmware or your computer operating system. Every effort has been made to ensure
that the information in this manual is accurate.
Related Documentation
•Quick Start Guide
The Quick Start Guide shows how to connect the ZyWALL and access the Web Configurator
wizards. (See the wizard real time help for i n formation on configuring each screen.) It also
contains a connection diagram and package contents list.
• CLI Reference Guide
The CLI Reference Guide explains how to use the Command-Line Interface (CLI) to configure the
ZyWALL.
Note: It is recommended you use the Web Configurator to configure the ZyWALL.
• Web Configurator Online Help
Click the help icon in any screen for help in configuring that screen and supplementary
11.1 Zones Overview ............................................................................................................................211
11.1.1 What You Can Do in this Chapter .. .......................................... ... .... .....................................211
11.1.2 What You Need to Know ......................................................................................................211
11.2 The Zone Screen ...........................................................................................................................212
11.3 Zone Edit .......................................................................................................................................213
23.1 The ZyWALL SecuExtender Icon ..................................................................................................341
23.2 Status ............................................................................................................................................341
44.1 Resetting the ZyWALL ..................................................................................................................535
44.2 Getting More Troubleshooting Help ..............................................................................................536
Appendix A Legal Information..........................................................................................................537
Index ..................................................................................................................................................541
ZyWALL 110/310/1100 Series User’s Guide
15
ZyWALL 110/310/1100 Series User’s Guide16
1.1 Overview
Note: This help covers the fo llowing ZyWALL models and refers to them all as “ZyWALL”.
Features and interface names vary by model. Ke y fe ature d iffe re nces be tw ee n ZyWALL models are
as follows. Other features are common to all models although features may vary slightly by model.
See the specific product’s datasheet for detailed specifications.
Table 1 Model-Specific Features
CHAPTER 1
Introduction
FEATUREZYWALL
Rack-mounting110, 310, 1100
Wall-mounting110
Port Role110
Compact Flash Card Slot110
Here are some ZyWALL application scenarios.
IPv6 Routing
The ZyWALL supports IPv6 Ethernet, PPP, VLAN, and bridge routing. You may also create IPv6
policy routes and IPv6 objects. The ZyWALL can also route IPv6 packets through IPv4 networks
using different tunneling methods.
Figure 1 Applications: IPv6 Routing
VPN Connectivity
Set up VPN tunnels with other companies, branch offices, telecommuters, and business travelers to
provide secure access to your network. You can also purchase the ZyWALL OTPv2 One-Time
Password System for strong two-factor authentication for Web Configurator, Web access, SSL VPN,
and ZyXEL IPSec VPN client user logins.
ZyWALL 110/310/1100 Series User’s Guide17
Chapter 1 Introduction
OTP PIN
SafeWord 2008
Authentication Server
File
Email
Web-based
Server
Server
Application
*****
Web Mail File Share
Web-based Application
https://
Application Server
Non-Web
LAN (192.168.1.X)
Figure 2 Applications: VPN Connectivity
SSL VPN Network Access
SSL VPN lets remote users use their web browsers for a very easy-to-use VPN solution. A user just
browses to the ZyWALL’s web address and enters his user name and password to securely connect
to the ZyWALL’s network. Here full tunnel mode creates a virtual connection for a remote user and
gives him a private IP address in the same subnet as the local network so he can access network
resources in the same way as if he were part of the internal network.
Figure 3 SSL VPN With Full Tunnel Mode
User-Aware Access Control
Set up security policies to restrict access to sensitive information and shared resources based on
the user who is trying to access it. In the following figure user A can access both the Internet and
an internal file server. User B has a lower level of access and can only access the Internet. User C is
not even logged in and cannot access either.
18
ZyWALL 110/310/1100 Series User’s Guide
Chapter 1 Introduction
A
B
C
Figure 4 Applications: User-Aware Access Control
Load Balancing
Set up multiple connections to the Internet on the same port, or different ports, including cellular
interfaces. In either case, you can balance the traffic loads between them.
Figure 5 Applications: Multiple WAN Interfaces
1.2 Management Overview
You can manage the ZyWALL in the following ways.
Web Configurator
The Web Configur ator allows easy ZyWALL setup and management using an Internet browser. This
User’s Guide provides information about the Web Configurator.
Figure 6 Managing the ZyWALL: Web Configurator
ZyWALL 110/310/1100 Series User’s Guide
19
Chapter 1 Introduction
Command-Line Interface (CLI)
The CLI allows you to use text-based commands to configure the ZyWALL. Access it using remote
management (for example, SSH or Telnet) or via the physical or Web Configurator console port.
See the Command Reference Guide for CLI details. The default settings for the console port are:
Table 2 Console Port Default Settings
SETTINGVALUE
Speed115200 bps
Data Bits8
ParityNone
Stop Bit1
Flow ControlOff
1.3 Web Configurator
In order to use the Web Configurator, you must:
• Use one of the following web browser versions or later: Internet Explorer 7, Firefo x 3.5, Chr ome
9.0
• Allow pop-up windows (blocked by default in Windows XP Service Pack 2)
• Enable JavaScripts, Java permissions, and cookies
The recommended screen resolution is 1024 x 768 pixels.
1.3.1 Web Configurator Access
1Make sure your ZyWALL hardware is properly connected. See the Quick Start Guide.
2In your browser go to http://192.168.1.1. By default, the ZyWALL automatically routes this request
to its HTTPS server, and it is recommended to keep this setting. The Login screen appears.
3Type the user name (default: “admin”) and password (default: “1234”).
If you have a OTP (One-Time Password) token generate a number and enter it in the One-Time Password field. The number is only good for one login. You must use the token to generate a new
number the next time you log in.
20
ZyWALL 110/310/1100 Series User’s Guide
Chapter 1 Introduction
A
C
B
4Click Login. If you logged in using the default user name and password, the Update Admin Info
screen appears. Otherwise, the dashboard appears.
5Follow the directions in the Update Admin Info screen. If you change the default password, the
Login screen appears after you click Apply. If you click Ignore, the Installation Setup Wizard
opens if the ZyWALL is using its default configuration; otherwise the dashboard appears.
1.3.2 Web Configurator Screens Overview
The Web Configurator screen is divided into these parts (as illustrated on page 21):
• A - title bar
• B - navigation panel
• C - main window
Title Bar
Figure 7 Title Bar
ZyWALL 110/310/1100 Series User’s Guide
21
Chapter 1 Introduction
The title bar icons in the upper right corner provide the following functions.
Table 3 Title Bar: Web Configurator Icons
LABELDESCRIPTION
LogoutClick this to log out of the Web Configurator.
HelpClick this to open the help page for the current screen.
AboutClick this to display basic information about the ZyWALL.
Site MapClick this to see an overview of links to the Web Configurator screens.
Object Reference Click this to check which configuration items reference an object.
ConsoleClick this to open a Java-based console window from which you can run command line
CLIClick this to open a popup window that displays the CLI commands sent by the Web
About
Click About to display basic information about the ZyWALL.
Figure 8 About
interface (CLI) commands. You will be prompted to enter your user name and password.
See the Command Reference Guide for information about the commands.
Configurator to the ZyWALL.
22
Table 4 About
LABELDESCRIPTION
Boot ModuleThis shows the version number of the software that handles the booting process of the
ZyWALL.
Current VersionThis shows the firmware version of the ZyWALL.
Released DateThis shows the date (yyyy-mm-dd) and time (hh:mm:ss) when the firmware is released.
OKClick this to close the screen.
Site Map
Click Site MAP to see an overview of links to the Web Configurator screens. Click a screen’ s link to
go to that screen.
ZyWALL 110/310/1100 Series User’s Guide
Chapter 1 Introduction
Figure 9 Site Map Object Reference
Click Object Reference to open the Object Reference screen. Select the type of object and the
individual object and click Refresh to show which configuration settings reference the object.
Figure 10 Object Reference
The fields vary with the type of object. This table describes labels that can appear in this screen.
Table 5 Object References
LABELDESCRIPTION
Object Name This identifies the object for which the configuration settings t hat use it are disp layed. Clic k the
#This field is a sequential value, and it is not associated with any entry.
ServiceThis is the type of setting that references the selected object. Click a service’s name to display
PriorityIf it is applicable, this field lists the refe rencing configuration item’s position in its list,
NameThis field identifies the configuration item that references the object.
DescriptionIf the referencing configuration item has a description configured, it displays here.
object’s name to display the object’s configuration screen in the main window.
the service’s configuration screen in the main window.
otherwise N/A displays.
ZyWALL 110/310/1100 Series User’s Guide
23
Chapter 1 Introduction
Table 5 Object References (continued)
LABELDESCRIPTION
RefreshClick this to update the information in this screen.
CancelClick Cancel to close the screen.
Console
Click Console to open a Java-based console window from which you can run CLI commands. You
will be prompted to enter your user name and password. See the Command Reference Guide for
information about the commands.
Figure 11 Console Window
24
CLI Messages
Click CLI to look at the CLI commands sent by the W eb Configurator. Open the pop-up window and
then click some menus in the web configurator to dislay the corresponding commands.
Figure 12 CLI Messages
ZyWALL 110/310/1100 Series User’s Guide
1.3.3 Navigation Panel
Use the navigation panel menu items to open status and configuration screens. Click the arrow in
the middle of the right edge of the navigation panel to hide the panel or drag to resize it. The
following sections introduce the ZyWALL’s navigation panel menus and their screens.
Figure 13 Navigation Panel
Chapter 1 Introduction
Dashboard
The dashboard displays general device information, system status, system resource usage,, and
interface status in widgets that you can re-arr ange to suit your needs. See the W eb Help for details
on the dashboard.
Monitor Menu
The monitor menu screens display status and statistics information.
Table 6 Monitor Menu Screens Summary
FOLDER OR LINK TABFUNCTION
System Status
Port StatisticsDisplays packet statistics for each physical port.
Interface
Status
Traffic
Statistics
Session
Monitor
DDNS StatusDisplays the status of the ZyWALL’s DDNS domain names.
IP/MAC BindingLists the devices that have received an IP address from ZyWALL interfaces
Login UsersLists the users currently logged into the ZyWALL.
Displays general interface information and packet statistics.
Collect and display traffic statistics.
Displays the status of all current sessions.
using IP/MAC binding.
ZyWALL 110/310/1100 Series User’s Guide
25
Chapter 1 Introduction
Table 6 Monitor Menu Screens Summary (continued)
FOLDER OR LINK TABFUNCTION
Cellular StatusDisplays details about the ZyWALL’s 3G connection status.
USB StorageDisplays details about USB device connected to the ZyWALL.
VPN Monitor
IPSecDisplays and manages the active IPSec SAs.
SSLLists users currently logged into the VPN SSL client portal. You can also log
L2TP over
IPSec
LogLists log entries.
Configuration Menu
Use the configuration menu screens to configure the ZyWALL’s features.
Table 7 Configuration Menu Screens Summary
FOLDER OR LINK TABFUNCTION
Quick SetupQuickly configure WAN interfaces or VPN connections.
Network
InterfacePort RoleUse this screen to set the ZyWALL’s flexible ports as LAN1, WLAN,
RoutingPolicy RouteCreate and manage routing policies.
ZoneConfigure zones used to define various policies.
DDNSDDNSDefine and manage the ZyWALL’s DDNS domain names.
NATSet up and manage port forwarding rules.
HTTP RedirectSet up and manage HTTP redirection rules.
ALGConfigure SIP, H.323, and FTP pass-through settings.
IP/MAC
Binding
DNS Inbound LBDNS Load
Auth. PolicyDefine rules to force user authentication.
out individual users and delete related session information.
Displays details about current L2TP sessions.
or DMZ.
EthernetManage Ethernet interfaces and virtual Ethernet interfaces.
PPPCreate and manage PPPoE and PPTP interfaces.
CellularConfigure a cellular Internet connection for an installed 3G card.
TunnelConfigure tunneling between IPv4 and IPv6 networks.
VLANCreate and manage VLAN interfaces and virtual VLAN interfaces.
BridgeCreate and manage bridges and virtual bridge interfaces.
TrunkCreate and manage trunks (groups of interfaces) for load
balancing.
Static RouteCreate and manage IP static routing information.
RIPConfigure device-level RIP settings.
OSPFConfigure device-level OSPF settings, including areas and virtual
links.
SummaryConfigure IP to MAC address bindings for devices connected to
each supported interface.
Exempt ListConfigure ranges of IP addresses to which th e ZyWALL does not
apply IP/MAC binding.
Configure DNS Load Balancing.
Balancing
26
ZyWALL 110/310/1100 Series User’s Guide
Chapter 1 Introduction
Table 7 Configuration Menu Screens Summary (continued)
FOLDER OR LINK TABFUNCTION
FirewallFirewallCreate and manage level-3 traffic rules.
Session ControlLimit the number of concurrent client NAT/firewall sessions.
VPN
IPSec VPNVPN ConnectionConfigure IPSec tunnels.
VPN GatewayConfigure IKE tunnels.
ConcentratorCombine IPSec VPN con nections into a single secure network
Configuration
Provisioning
SSL VPNAccess PrivilegeConfigure SSL VPN access rights for users and groups.
Global SettingConfigure the ZyWALL’s SSL VPN settings that apply to all
L2TP VPNL2TP VPNConfigure L2TP over IPSec tunnels.
BWMBWMEnable and configure bandwidth management rules.
Device HAGeneralConfigure device HA global settings, and see the status of each
Active-Passive
Mode
Object
User/GroupUserCreate and manage users.
GroupCreate and manage groups of users.
SettingManage default settings for all users, general settings for user
AddressAddressCreate and manage host, range, and network (subnet) addresses.
Address GroupCreate and manage groups of addresses.
ServiceServiceCreate and manage TCP and UDP services.
Service GroupCreate and manage groups of services.
ScheduleScheduleCreate one-time and recurring schedules.
AAA ServerActive DirectoryConfigure the Active Directory settings.
LDAPConfigure the LDAP settings.
RADIUSConfigure the RADIUS settings.
Auth. MethodAuthentication
Method
CertificateMy Cer tificatesCreate and manage the ZyWALL’s certificates.
Trusted Certificates Import and manage certificates from trusted sources.
ISP AccountISP AccountCreate and manage ISP account information for PPPoE/PPTP
SSL ApplicationCreate SSL web application objects.
DHCPv6RequestConfigure IPv6 DHCP request type and interface information.
LeaseConfigu r e IPv6 DHCP lease type and interface information.
System
Host NameConfigure the system and domain name for the ZyWALL.
USB StorageSettingsConfigure the settings for the connected USB devices.
Date/TimeConfigure the current date, time, and time zone in the ZyWALL.
Set who can retrieve VPN rule settings from the ZyWALL using the
ZyWALL IPSec VPN Client.
connections.
interface monitored by device HA.
Configure active-passive mode device HA.
sessions, and rules to force user authentication.
Create and manage ways of authenticating users.
interfaces.
ZyWALL 110/310/1100 Series User’s Guide
27
Chapter 1 Introduction
Table 7 Configuration Menu Screens Summary (continued)
FOLDER OR LINK TABFUNCTION
Console SpeedSet the console speed.
DNSConfigure the DNS server and address records for the ZyWALL.
WWWService ControlConfigure HTTP, HTTPS, and general authentication.
SSHConfigure SSH server and SSH service settings.
TELNETConfigure telnet server settings for the ZyWALL.
FTPConfigure FTP server settings.
SNMPConfigure SNMP communities and services.
LanguageSelect the Web Configurator language.
IPv6Enable IPv6 globally on the ZyWALL here.
Log & Report
Email Daily
Report
Log SettingsConfigure the system log, e-mail logs, and remote syslog servers.
Maintenance Menu
Login PageConfigure how the login and access user screens look.
Configure where and how to send daily reports and what reports to
send.
Use the maintenance menu screens to manage configuration and firmware files, run diagnostics,
and reboot or shut down the ZyWALL.
RebootRestart the ZyWALL.
ShutdownTurn off the ZyWALL.
TABFUNCTION
Configuration FileManage and upload configuration files for the ZyWALL.
Firmware Package View the current firmware version and to upload firmware.
Shell ScriptManage and run shell script files for the ZyWALL.
Packet CaptureCapture packets for analysis.
Core DumpConnect a USB device to the ZyWALL and save the ZyWALL operating
System LogConnect a USB device to the ZyWALL and archive the ZyWALL system logs
Routing StatusCheck how the ZyWALL determines where to route a packet.
SNAT StatusView a clear picture on how the ZyWALL converts a packet’s source IP
1.3.4 Tables and Lists
system kernel to it here.
to it here.
address and check the related settings.
28
Web Configurator tables and lists are flexible with several options for how to display their entries.
Click a column heading to sort the table’s entries according to that column’s criteria.
ZyWALL 110/310/1100 Series User’s Guide
Chapter 1 Introduction
Figure 14 Sorting Table Entries by a Column’s Criteria
Click the down arrow next to a column heading for more options about how to display the entries.
The options available vary depending on the type of fields in the column. Here are some examples
of what you can do:
• Sort in ascending or descending (reverse) alphabetical order
• Select which columns to display
• Group entries by field
• Show entries in groups
• Filter by mathematical operators (<, >, or =) or searching for text
Figure 15 Common Table Column Options
Select a column heading cell’s right border and drag to re-size the column.
Figure 16 Resizing a Table Column
Select a column heading and drag and drop it to change the column order. A green check mark
displays next to the column’s title when you drag the column to a valid new location.
ZyWALL 110/310/1100 Series User’s Guide
29
Chapter 1 Introduction
Figure 17 Moving Columns
Use the icons and fields at the bottom of the table to navigate to different pages of entries and
control how many entries display at a time.
Figure 18 Navigating Pages of Table Entries
The tables have icons for working with table entries. You can often use the [Shift] or [Ctrl] key to
select multiple entries to remove, activate, or deactivate.
Figure 19 Common Table Icons
Here are descriptions for the most common table icons.
Table 9 Common Table Icons
LABELDESCRIPTION
AddClick this to create a new entry. For features where the entry’s position in the numbered list is
important (features where the ZyWALL applies the table’s entries in order like the firewall for
example), you can select an entry and click Add to create a new entry after the selected entry.
EditDouble-click an entry or select it and click Edit to open a screen where you can modify the
RemoveTo remove an entry, select it and click Remove. The ZyWALL confirms you want to remove it
ActivateTo turn on an entry, select it and click Activate.
InactivateTo turn off an entry, select it and click Inactivate.
ConnectTo connect an entry, select it and click Connect.
Disconnect To disconnect an entry, select it and click Disconnect.
Object
References
MoveTo change an entry’s position in a numbered list, select it and click Move to display a field to
entry’s settings. In some tables you can just click a table entry and edit it directly in the table.
For those types of tables small red triangles display for table entries with changes that you have
not yet applied.
before doing so.
Select an entry and click Object References to check which settings use the entry.
type a number for where you want to put that entry and press [ENTER] to move the entry to the
number that you typed. For example, if you type 6, the entry you are moving becomes number 6
and the previous entry 6 (if there is one) gets pushed up (or down) one.
30
ZyWALL 110/310/1100 Series User’s Guide
Loading...
+ 532 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.