GENERAL APPLICATION NOTES .......................................................................................................................................................... 6
INTERNET CONNECTION ................................................................................................................................................................... 6
Setup the Prestige as a DHCP Relay .................................................................................................................................... 10
Configure an Internal Server Behind SUA ........................................................................................................................... 12
Configure a PPTP server Behind SUA .................................................................................................................................. 14
Using NAT / Multi-NAT ........................................................................................................................................................ 18
About Filter & Filter Examples ............................................................................................................................................ 39
Using the Dynamic DNS (DDNS) ......................................................................................................................................... 62
Network Management Using SNMP................................................................................................................................... 64
Using syslog ........................................................................................................................................................................ 70
Using IP Alias ...................................................................................................................................................................... 74
Using Call Scheduling .......................................................................................................................................................... 76
Using IP Multicast ............................................................................................................................................................... 81
Using Prestige traffic redirect ............................................................................................................................................. 83
Using Universal Plug n Play (UPnP) .................................................................................................................................... 85
Relay to PSTN ..................................................................................................................................................................... 92
How to connect Lifeline and DSL connection ...................................................................................................................... 93
Phone port settings ............................................................................................................................................................ 97
Call Hold setup .................................................................................................................................................................. 110
Three Way Conference setup ............................................................................................................................................ 112
Call Transfer setup ............................................................................................................................................................ 114
Do Not Disturb (DND) ....................................................................................................................................................... 122
Hot Line (Auto Dial) .......................................................................................................................................................... 123
Music on hold ................................................................................................................................................................... 124
Early Media ....................................................................................................................................................................... 126
Country Code .................................................................................................................................................................... 127
What is ZyNOS? ................................................................................................................................................................ 128
How do I access the embedded web configurator? .......................................................................................................... 128
What is the default LAN IP address and Password? Moreover, how do I change it? ....................................................... 128
How do I upload the ZyNOS firmware code via embeded web configurator? .................................................................. 128
How do I upgrade/backup the ZyNOS firmware by using FTP client program via LAN? .................................................. 129
How do I upload or backup ROMFILE via web configurator? ........................................................................................... 129
How do I backup/restore configurations by using FTP client program via LAN? .............................................................. 130
Why can't I make Telnet to Prestige from WAN? ............................................................................................................. 130
What should I do if I forget the system password? .......................................................................................................... 130
What is SUA? When should I use SUA? ............................................................................................................................ 130
What is the difference between NAT and SUA? ............................................................................................................... 131
How many network users can the SUA/NAT support? ..................................................................................................... 131
What are Device filters and Protocol filters? .................................................................................................................... 131
Why can't I configure device filters or protocol filters? .................................................................................................... 131
What is the Prestige Integrated Access Device? ............................................................................................................... 132
Will the Prestige work with my Internet connection? ...................................................................................................... 132
What do I need to use the Prestige? ................................................................................................................................. 132
What is PPPoE? ................................................................................................................................................................. 132
Does the Prestige support PPPoE? .................................................................................................................................... 133
How do I know I am using PPPoE? .................................................................................................................................... 133
Why does my provider use PPPoE? ................................................................................................................................... 133
Which Internet Applications can I use with the Prestige? ................................................................................................. 133
How can I configure the Prestige? .................................................................................................................................... 133
What network interface does the Prestige support? ........................................................................................................ 133
What can we do with Prestige? ........................................................................................................................................ 133
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
4
Does Prestige support dynamic IP addressing? ................................................................................................................ 134
What is the difference between the internal IP and the real IP from my ISP? .................................................................. 134
How does e-mail work through the Prestige? .................................................................................................................. 134
Is it possible to access a server running behind SUA from the outside Internet? If possible, how? .................................. 134
What DHCP capability does the Prestige support? ........................................................................................................... 134
How do I used the reset button, more over what field of parameter will be reset by reset button? ................................ 135
What network interface does the new Prestige series support? ...................................................................................... 135
How does the Prestige support TFTP? .............................................................................................................................. 135
Can the Prestige support TFTP over WAN? ....................................................................................................................... 135
How fast can the data go? ................................................................................................................................................ 135
What is Multi-NAT? .......................................................................................................................................................... 136
When do I need Multi-NAT? .............................................................................................................................................. 136
What IP/Port mapping does Multi-NAT support? ............................................................................................................. 137
What is the difference between SUA and Multi-NAT? ...................................................................................................... 138
What is BOOTP/DHCP? ..................................................................................................................................................... 138
What is DDNS? ................................................................................................................................................................. 139
When do I need DDNS service? ......................................................................................................................................... 139
What DDNS servers does the Prestige support? ............................................................................................................... 139
What is DDNS wildcard? ................................................................................................................................................... 139
Does the Prestige support DDNS wildcard? ...................................................................................................................... 139
Can the Prestige SUA handle IPsec packets sent by the VPN gateway behind Prestige? .................................................. 140
How do I setup my Prestige for routing IPsec packets over SUA? ..................................................................................... 140
What is P2602 and what is the difference between P2602R and P2602RL? .................................................................... 140
What does Lifeline mean? ................................................................................................................................................ 140
Do I need Lifeline? ............................................................................................................................................................ 140
Can I connect more than one phone on the phone port? ................................................................................................. 141
Can I receive incoming PSTN call through P2602RL-
Can I make an outgoing PSTN call through P2602RL –
What is Voice over IP? ...................................................................................................................................................... 141
How does Voice over IP work? .......................................................................................................................................... 141
Why use VoIP? .................................................................................................................................................................. 141
What is the relationship between codec and VoIP? ......................................................................................................... 142
What advantage does Voice over IP can provide? ........................................................................................................... 142
What is the difference between H.323 and SIP? .............................................................................................................. 142
Can H.323 and SIP interoperate with one another? ......................................................................................................... 142
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
5
What is voice quality? ...................................................................................................................................................... 142
How are voice quality normally rated?............................................................................................................................. 142
What is codec? ................................................................................................................................................................. 143
What is the relation of codec and VoIP? .......................................................................................................................... 143
What codec does Prestige support? ................................................................................................................................. 143
Which codec should I choose? .......................................................................................................................................... 143
What do I need in order to use SIP? ................................................................................................................................. 143
Unable to register with the SIP server? ............................................................................................................................ 144
I can register but can not establish a call? ....................................................................................................................... 144
I can make a call but the voice only goes one way not bothway? .................................................................................... 144
I can receive a call but the voice only goes one way not bothway? ................................................................................. 144
If all the about have been tried, but register still fail what should I do? .......................................................................... 145
I suspect there is a hardware problem with my Prestige what should I do? .................................................................... 145
What is a network firewall? ............................................................................................................................................. 145
What makes Prestige firewall secure? ............................................................................................................................. 145
What are the basic types of firewalls? ............................................................................................................................. 146
What kind of firewall is the Prestige? ............................................................................................................................... 146
Why do you need a firewall when your router has packet filtering and NAT built-in? ..................................................... 147
What is Denials of Service (DoS)attack? ........................................................................................................................... 147
What is Ping of Death attack? .......................................................................................................................................... 147
What is Teardrop attack? ................................................................................................................................................. 147
What is SYN Flood attack? ................................................................................................................................................ 147
What is LAND attack? ....................................................................................................................................................... 148
What is Brute-force attack? ............................................................................................................................................. 148
What is IP Spoofing attack?.............................................................................................................................................. 148
What are the default ACL firewall rules in Prestige? ........................................................................................................ 148
How can I protect against IP spoofing attacks? ............................................................................................................... 149
CLI COMMAND LIST ............................................................................................................................................................ 176
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
6
Application Notes
General Application Notes
Internet Connection
A typical Internet access application of the Prestige is shown below. For a small office, there are some
components needs to be checked before accessing the Internet.
Before you begin
Setting up the Windows
Setting up the Prestige router
Troubleshooting
Before you begin
The Prestige is shipped with the following factory default:
2. DHCP server enabled with IP pool starting from 192.168.1.33
3. Default SMT menu password = 1234
Setting up the PC (Windows OS)
1. Ethernet connection
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
7
All PCs must have an Ethernet adapter card installed.
If you only have one PC, connect the PC's Ethernet adapter to the Prestige's LAN port with a
crossover (red one) Ethernet cable.
If you have more than one PC, both the PC's Ethernet adapters and the Prestige's LAN port must
be connected to an external hub with straight Ethernet cable.
2. TCP/IP Installation
You must first install TCP/IP software on each PC before you can use it for Internet access. If you have already
installed TCP/IP, go to the next section to configure it; otherwise, follow these steps to install:
In the Control Panel/Network window, click Add button.
In the Select Network Component Type windows, select Protocol and click Add.
In the Select Network Protocol windows, select Microsoft from the manufacturers, then select
TCP/IP from the Network Protocols and click OK.
3. TCP/IP Configuration
Follow these steps to configure Windows TCP/IP:
In the Control Panel/Network window, click the TCP/IP entry to select it and click Properties
button.
In the TCP/IP Properties window, select obtain an IP address automatically.
Note: Do not assign arbitrary IP address and subnet mask to your PCs, otherwise, you will not be able to access
the Internet.
Click the WINS configuration tab and select Disable WINS Resolution.
Click the Gateway tab. Highlight any installed gateways and click the Remove button until there
are none listed.
Click the DNS Configuration tab and select Disable DNS.
Click OK to save and close the TCP/IP properties window
Click OK to close the Network window. You will be prompted to insert your Windows CD or disk.
When the drivers are updated, you will be asked if you want to restart the PC. Make sure your
Prestige is powered on before answering Yes to the prompt. Repeat the above steps for each
Windows PC on your network.
Setting up the Prestige router
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
8
The following procedure is for the most typical usage of the Prestige where you have a single-user account
(SUA). The Prestige supports embedded web server that allows you to use Web browser to configure it. Before
configuring the router using Browser please be sure there is no Telnet or Console login.
1. Retrieve Prestige Web
Please enter the LAN IP address of the Prestige router in the URL location to retrieve the web screen from the
Prestige. The default LAN IP of the Prestige is 192.168.1.1. See the example below. Note that you can either
use http://192.168.1.1
2. Login first
The default password is the default SMT password, '1234'.
3. Configure Prestige for Internet access by using WIZARD SETUP
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
9
The Web screen shown below takes PPPoE as the example.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
10
Setup the Prestige as a DHCP Relay
What is DHCP Relay?
DHCP stands for Dynamic Host Configuration Protocol. In addition to the DHCP server feature, the P2602
supports the DHCP relay function. When it is configured as DHCP server, it assigns the IP addresses to the
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
11
Menu 3.2 - TCP/IP and DHCP Setup
DHCP Setup
DHCP= Relay
Client IP Pool Starting Address= N/A
Size of Client IP Pool= N/A
Primary DNS Server= N/A
Secondary DNS Server= N/A
Remote DHCP Server= 192.168.1.2
TCP/IP Setup:
IP Address= 192.168.1.1
IP Subnet Mask= 255.255.255.0
RIP Direction= None
Version= N/A
Multicast= None
IP Policies=
LAN clients. When it is configured as DHCP relay, it is reponsable for forwarding the requests and responses
negotiating between the DHCP clients and the server. See figure 1.
Setup the Prestige as a DHCP Client
1. Toggle the DHCP to Relay in menu 3.2 and enter the IP address of the DHCP server in the 'Relay Server
Address' field.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
12
Edit IP Alias= No
Press ENTER to Confirm or ESC to Cancel:
Configure an Internal Server Behind SUA
Introduction
If you wish, you can make internal servers (e.g., Web, ftp or mail server) accessible for outside users, even
though SUA makes your LAN appear as a single machine to the outside world. A service is identified by the
port number. Also, since you need to specify the IP address of a server in the Prestige, a server must have a
fixed IP address and not be a DHCP client whose IP address potentially changes each time it is powered on.
In addition to the servers for specific services, SUA supports a default server. A service request that does not
have a server explicitly designated for it is forwarded to the default server. If the default server is not defined,
the service request is simply discarded.
Configuration
All contents copyright (c) 2007 ZyXEL Communications Corporation.
To make a server visible to the outside world, specify the port number of the service and the inside address of
the server in 'Menu 15.2.1', Multiple Server Configuration. The outside users can access the local server using
the Prestige's
For example (Configuring an internal Web server for outside access) :
WAN IP
address which can be obtained from menu 24.1.
Port numbers for some services
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
14
DNS (Domain Name Server)
53
www-http (Web)
80
Configure a PPTP server Behind SUA
Introduction
PPTP is a tunneling protocol defined by the PPTP forum that allows PPP packets to be encapsulated within
Internet Protocol (IP) packets and forwarded over any IP network, including the Internet itself.
In order to run the Windows 9x PPTP client, you must be able to establish an IP connection with a tunnel server
such as the Windows NT Server 4.0 Remote Access Server.
Windows Dial-Up Networking uses the Internet standard Point-to-Point (PPP) to provide a secure,optimized
multiple-protocol network connection over dial-up telephone lines. All data sent over this connection can be
encrypted and compressed, and multiple network level protocols (TCP/IP, NetBEUI and IPX) can be run
correctly. Windows NT Domain Login level security is preserved even across the Internet.
PPTP appears as new modem type (Virtual Private Networking Adapter) that can be selected when setting up a
connection in the Dial-Up Networking folder. The VPN Adapter type does not appear elsewhere in the system.
Window98 PPTP Client / Internet / NT RAS Server Protocol Stack
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
15
Since PPTP encapsulates its data stream in the PPP protocol, the VPN requires a second dial-up adapter. This
second dial-up adapter for VPN is added during the installation phase of the Upgrade in addition to the first
dial-up adapter that provides PPP support for the analog or ISDN modem.
The PPTP is supported in Windows NT and Windows 98 already. For Windows 95, it needs to be upgraded by
the Dial-Up Networking 1.2 upgrade.
Configuration
This application note explains how to establish a PPTP connection with a remote private network in the Prestige
SUA case. In ZyNOS, all PPTP packets can be forwarded to the internal PPTP Server (WinNT server) behind
SUA. The port number of the PPTP has to be entered in the SMT Menu 15 for Prestige to forward to the
appropriate private IP address of Windows NT server.
Example
The following example shows how to dial to an ISP via the Prestige and then establish a tunnel to a private
network. There will be three items that you need to set up for PPTP application, these are PPTP server (WinNT),
PPTP client (Win9x) and the Prestige.
o PPTP server setup (WinNT)
Add the VPN service from Control Panel>Network
Add an user account for PPTP logged on user
Enable RAS port
Select the network protocols from RAS such as IPX, TCP/IP NetBEUI
Set the Internet gateway to Prestige
All contents copyright (c) 2007 ZyXEL Communications Corporation.
SUA (Single User Account) in previous ZyNOS versions is a NAT set with 2 rules, Many-to-One and Server.
The Prestige now has Full Feature NAT support to map global IP addresses to local IP addresses of clients or
servers. With multiple global IP addresses, multiple severs of the same type (e.g., FTP servers) are allowed on
the LAN for outside access. In previous ZyNOS versions (that supported SUA 'visible' servers had to be of
different types. The Prestige supports NAT sets on a remote node basis. They are reusable, but only one set is
allowed for each remote node. The Prestige 2602RL supports 8 sets since there are 8 remote node. The default
SUA (Read Only) Set in menu 15.1 is a convenient, pre-configured, read only, Many-to-One mapping set,
sufficient for most purposes and helpful to people already familiar with SUA in previous ZyNOS versions.
SMT Menus
1. Applying NAT in the SMT Menus
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
21
Menu 4 - Internet Access Setup
ISP's Name= MyISP
Encapsulation= PPPoE
Multiplexing= LLC-based
VPI #= 0
VCI #= 33
ATM QoS Type= UBR
Peak Cell Rate (PCR)= 0
Sustain Cell Rate (SCR)= 0
Maximum Burst Size (MBS)= 0
My Login= cso@zyxel
My Password= ********
Idle Timeout (sec)= 0
IP Address Assignment= Dynamic
IP Address= N/A
Network Address Translation= Full Feature
Address Mapping Set= 1
Press ENTER to Confirm or ESC to Cancel:
Field
Options
Description
Network Address Translation
Full Feature
When you select this option the SMT will use Address
Mapping Set 1 (Menu 15.1-see later for further
discussion).
None
NAT is disabled when you select this option.
SUA Only
When you select this option the SMT will use Address
Mapping Set 255 (Menu 15.1-see later for further
discussion). This option use basically Many-to-One
You apply NAT via menus 4 and 11.3 as displayed next. The next figure how you apply NAT for Internet
access in menu 4. Enter 4 from the Main Menu to go to Menu 4-Internet Access Setup.
The following table describes the options for Network Address Translation.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
22
Overload mapping. Select Full Feature when you
require other mapping types. It is a convenient,
pre-configured, read only, Many-to-One mapping set,
sufficient for most purposes and helpful to people
already familiar with SUA in previous ZyNOS
versions. Note that there is also a Server type whose
IGA is 0.0.0.0 in this set.
Menu 15 - NAT Setup
1. Address Mapping Sets
2. NAT Server Sets
Table: Applying NAT in Menu 4 and Menu 11.3
2. Configuring NAT
To configure NAT, enter 15 from the Main Menu to bring up the following screen.
3. Address Mapping Sets and NAT Server Sets
Use the Address Mapping Sets menus and submenus to create the mapping table used to assign global addresses
to LAN clients. Each remote node must specify which NAT Address Mapping Set to use. The P2602RL has 8
remote nodes and so allows you to configure 8 NAT Address Mapping Set. You can see nine NAT Address
Mapping sets in Menu 15.1. You can only configure from Set 1 to Set 8. Set 255 is used for SUA. When you
select Full Feature in menu 4 or 11.3. When you select SUA Only, the SMT will use Set 15.2.
The NAT Server Set is a list of LAN side servers mapped to external ports. To use this set (one set for the
Prestige), a server rule must be set up inside the NAT Address Mapping set. Please see NAT Server Sets for
further information on these menus.
Enter 1 to bring up Menu 15.1-Address Mapping Sets
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
23
Menu 15.1 - Address Mapping Sets
1.
2.
3.
4.
5.
6.
7.
8.
255. SUA (read only)
Enter Set Number to Edit:
Menu 15.1.1 - Address Mapping Rules
Set Name= SUA
Idx Local Start IP Local End IP Global Start IP Global End IP Type
The following table explains the fields in this screen. Please note that the fields in this menu are read-only.
Please note that the fields in this menu are read-only. However, the settings of the server set 1 can be modified
in menu 15.1.1.
Now let's look at Option 1 in Menu 15.1.1 Enter 1 to bring up this menu.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
25
9.
10.
Action= Edit , Select Rule= 0
Press ENTER to Confirm or ESC to Cancel:
Field
Description
Option
Set Name
Enter a name for this set of rules. This is a required field. Please note
that if this field is left blank, the entire set will be deleted.
Rule1
Action
They are 4 actions. The default is Edit. Edit means you want to edit a
selected rule (see following field). Insert Before means to insert a new
rule before the rule selected. The rule after the selected rule will then be
moved down by one rule. Delete means to delete the selected rule and
then all the rules after the selected one will be advanced one rule. Save Set means to save the whole set (note when you choose this action the
Select Rule item will be disabled).
Edit
Insert Before
Delete
Save Set
Select Rule
When you choose Edit, Insert Before or Save Set in the previous field
the cursor jumps to this field to allow you to select the rule to apply the
action in question.
1
Menu 15.1.1.1 - - Rule 1
Type: One-to-One
We will just look at the differences from the previous menu. Note that, this screen is not read only, so we have
extra Action and Select Rule fields. Not also that the [?] in the Set Name field means that this is a required field
and you must enter a name for the set. The description of the other fields is as described above. The Type,
Local and Global Start/End IPs are configured in Menu 15.1.1 (described later) and the values are displayed
here.
Note: Save Set in the Action field means to save the whole set. You must do this if you make any changes to
the set-including deleting a rule. No changes to the set take place until this action is taken. Be careful when
ordering your rules as each rule is executed in turn beginning from the first rule.
Selecting Edit in the Action field and then selecting a rule brings up the following menu, Menu
15.1.1.1-Address Mapping Rule in which you can edit an individual rule and configure the Type, Local and
Global Start/End IPs displayed in Menu 15.1.1.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2602RL-D3A Support Notes
26
Local IP:
Start= 0.0.0.0
End = N/A
Global IP:
Start= 0.0.0.0
End = N/A
Press ENTER to Confirm or ESC to Cancel:
Field
Description
Option/Example
Type
Press [SPACEBAR] to toggle through a total of 5 types. These
are the mapping types discussed above plus a server type. Some
examples follow to clarify these a little more.
One-to-One
Many-to-One
Many-to-Many Overload
Many-to-Many No
Overload
Server
Local
IP
Start
This is the starting local IP address (ILA)
0.0.0.0
End
This is the ending local IP address (ILA). If the rule is for all
local IPs, then put the Start IP as 0.0.0.0 and the End IP as
255.255.255.255. This field is N/A for One-to-One type.
255.255.255.255
Global
IP
Start
This is the starting global IP address (IGA). If you have a
dynamic IP, enter 0.0.0.0 as the Global Start IP.
0.0.0.0
End
This is the ending global IP address (IGA). This field is N/A for
One-to-One, Many-to-One and Server types.
200.1.1.64
The following table describes the fields in this screen.
Note: For all Local and Global IPs, the End IP address must begin after the IP Start address, i.e., you cannot
have an End IP address beginning before the Start IP address.
NAT Server Sets
All contents copyright (c) 2007 ZyXEL Communications Corporation.