All contents copyright (c) 2007 ZyXEL Communications Corporation.
8
Prestige 2802HW(L)-Ix Support Notes
Application Notes
General Application Notes
Internet Connection
A typical Internet access application of the Prestige is shown below. For a small office, there are some
components needs to be checked before accessing the Internet.
• Before you begin
• Setting up the Windows
• Setting up the Prestige router
• Troubleshooting
• Before you begin
The Prestige is shipped with the following factory default:
2. DHCP server enabled with IP pool starting from 192.168.1.33
3. Default SMT menu password = 1234
• Setting up the PC (Windows OS)
1. Ethernet connection
All PCs must have an Ethernet adapter card installed.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
9
Prestige 2802HW(L)-Ix Support Notes
• If you only have one PC, connect the PC's Ethernet adapter to the Prestige's LAN port with a
crossover (red one) Ethernet cable.
• If you have more than one PC, both the PC's Ethernet adapters and the Prestige's LAN port must
be connected to an external hub with straight Ethernet cable.
2. TCP/IP Installation
You must first install TCP/IP software on each PC before you can use it for Internet access. If you have already
installed TCP/IP, go to the next section to configure it; otherwise, follow these steps to install:
• In the Control Panel/Network window, click Add button.
• In the Select Network Component Type windows, select Protocol and click Add.
• In the Select Network Protocol windows, select Microsoft from the manufacturers, then select
TCP/IP from the Network Protocols and click OK.
3. TCP/IP Configuration
Follow these steps to configure Windows TCP/IP:
• In the Control Panel/Network window, click the TCP/IP entry to select it and click Properties
button.
• In the TCP/IP Properties window, select obtain an IP address automatically.
Note: Do not assign arbitrary IP address and subnet mask to your PCs, otherwise, you will not be able to access
the Internet.
• Click the WINS configuration tab and select Disable WINS Resolution.
• Click the Gateway tab. Highlight any installed gateways and click the Remove button until there
are none listed.
• Click the DNS Configuration tab and select Disable DNS.
• Click OK to save and close the TCP/IP properties window
• Click OK to close the Network window. You will be prompted to insert your Windows CD or disk.
When the drivers are updated, you will be asked if you want to restart the PC. Make sure your
Prestige is powered on before answering Yes to the prompt. Repeat the above steps for each
Windows PC on your network.
• Setting up the Prestige router
All contents copyright (c) 2007 ZyXEL Communications Corporation.
10
Prestige 2802HW(L)-Ix Support Notes
The following procedure is for the most typical usage of the Prestige where you have a single-user account
(SUA). The Prestige supports embedded web server that allows you to use Web browser to configure it. Before
configuring the router using Browser please be sure there is no Telnet or Console login.
1. Retrieve Prestige Web
Please enter the LAN IP address of the Prestige router in the URL location to retrieve the web screen from the
Prestige. The default LAN IP of the Prestige is 192.168.1.1. See the example below. Note that you can either
use http://192.168.1.1
2. Login first
The default password is the default WEB GUI password, '1234'.
3. Configure Prestige for Internet access by using WIZARD SETUP
All contents copyright (c) 2007 ZyXEL Communications Corporation.
11
Prestige 2802HW(L)-Ix Support Notes
The Web screen shown below takes PPPoE as the example.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
12
Prestige 2802HW(L)-Ix Support Notes
Setup the Prestige as a DHCP Relay
• What is DHCP Relay?
DHCP stands for Dynamic Host Configuration Protocol. In addition to the DHCP server feature, the P2802
supports the DHCP relay function. When it is configured as DHCP server, it assigns the IP addresses to the
LAN clients. When it is configured as DHCP relay, it is reponsable for forwarding the requests and responses
negotiating between the DHCP clients and the server. See figure 1.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
13
Prestige 2802HW(L)-Ix Support Notes
• Setup the Prestige as a DHCP Client
1. Toggle the DHCP to Relay in Network>LAN>DHCP Setup and enter the IP address of the DHCP server in
the 'Remote DHCP Server' field.
14
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
Configure an Internal Server Behind SUA
• Introduction
If you wish, you can make internal servers (e.g., Web, ftp or mail server) accessible for outside users, even
though SUA makes your LAN appear as a single machine to the outside world. A service is identified by the
port number. Also, since you need to specify the IP address of a server in the Prestige, a server must have a
fixed IP address and not be a DHCP client whose IP address potentially changes each time it is powered on.
In addition to the servers for specific services, SUA supports a default server. A service request that does not
have a server explicitly designated for it is forwarded to the default server. If the default server is not defined,
the service request is simply discarded.
• Configuration
To make a server visible to the outside world, specify the port number of the service and the inside address of
the server in 'Network>NAT>Port Forwarding', Port Forwarding Configuration. The outside users can access
the local server using the Prestige's
WAN IP
address.
• For example (Configuring an internal Web server for outside access) :
All contents copyright (c) 2007 ZyXEL Communications Corporation.
15
Prestige 2802HW(L)-Ix Support Notes
• Port numbers for some services
ServicePort Number
FTP 21
Telnet 23
SMTP 25
DNS (Domain Name Server) 53
www-http (Web) 80
Configure a PPTP server Behind SUA
• Introduction
PPTP is a tunneling protocol defined by the PPTP forum that allows PPP packets to be encapsulated within
Internet Protocol (IP) packets and forwarded over any IP network, including the Internet itself.
In order to run the Windows 9x PPTP client, you must be able to establish an IP connection with a tunnel server
such as the Windows NT Server 4.0 Remote Access Server.
16
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
Windows Dial-Up Networking uses the Internet standard Point-to-Point (PPP) to provide a secure,optimized
multiple-protocol network connection over dial-up telephone lines. All data sent over this connection can be
encrypted and compressed, and multiple network level protocols (TCP/IP, NetBEUI and IPX) can be run
correctly. Windows NT Domain Login level security is preserved even across the Internet.
Window98 PPTP Client / Internet / NT RAS Server Protocol Stack
PPTP appears as new modem type (Virtual Private Networking Adapter) that can be selected when setting up a
connection in the Dial-Up Networking folder. The VPN Adapter type does not appear elsewhere in the system.
Since PPTP encapsulates its data stream in the PPP protocol, the VPN requires a second dial-up adapter. This
second dial-up adapter for VPN is added during the installation phase of the Upgrade in addition to the first
dial-up adapter that provides PPP support for the analog or ISDN modem.
The PPTP is supported in Windows NT and Windows 98 already. For Windows 95, it needs to be upgraded by
the Dial-Up Networking 1.2 upgrade.
• Configuration
This application note explains how to establish a PPTP connection with a remote private network in the Prestige
SUA case. In ZyNOS, all PPTP packets can be forwarded to the internal PPTP Server (WinNT server) behind
SUA. The port number of the PPTP has to be Configure in the WEB GUI Network > NAT > Port
Forwarding
for Prestige to forward to the appropriate private IP address of Windows NT server.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
17
• Example
Prestige 2802HW(L)-Ix Support Notes
The following example shows how to dial to an ISP via the Prestige and then establish a tunnel to a private
network. There will be three items that you need to set up for PPTP application, these are PPTP server (WinNT),
PPTP client (Win9x) and the Prestige.
o PPTP server setup (WinNT)
Add the VPN service from Control Panel>Network
Add an user account for PPTP logged on user
Enable RAS port
Select the network protocols from RAS such as IPX, TCP/IP NetBEUI
Set the Internet gateway to Prestige
o PPTP client setup (Win9x)
Add one VPN connection from Dial-Up Networking by entering the correct
username & password and the IP address of the Prestige's Internet IP address for
logging to NT RAS server.
Set the Internet gateway to the router that is connecting to ISP
o Prestige router setup
• Before making a VPN connection from Win9x to WinNT server, you need to connect Prestige
router to your ISP first.
• Go to WEB GUI “Network>NAT>Port Forwarding”. Enter the IP address of the PPTP server
(WinNT server) and specify the Service Name for PPTP as shown below.
18
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
When you have finished the above settings, you can ping to the remote Win9x client from
WinNT. This ping command is used to demonstrate that remote the Win9x can be reached across the
Internet. If the Internet connection between two LANs is achieve, you can place a VPN call from the
remote Win9x client.
For example:
C:\ping 203.66.113.2
When a dial-up connection to ISP is established, a default gateway is assigned to the router traffic
through that connection. Therefore, the output below shows the default gateway of the Win9x client
after the dial-up connection has been established.
Before making a VPN connection from the Win9x client to the NT server, you need to know the exact
Internet IP address that the ISP assigns to Prestige router in SUA mode and enter this IP address in the
VPN dial-up dialog box. You can check this Internet IP address from PNC Monitor or WEB GUI Status
page. If the Internet IP address is a fixed IP address provided by ISP in SUA mode, then you can
always use this IP address for reaching the VPN server.
In the following example, the IP address '140.113.1.225' is dynamically assigned by ISP. You must
enter this IP address in the 'VPN Server' dialog box for reaching the PPTP server. After the VPN link is
established, you can start the network protocol application such as IP, IPX and NetBEUI.
19
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
Using NAT / Multi-NAT
• What is Multi-NAT?
NAT (Network Address Translation-NAT RFC 1631) is the translation of an Internet Protocol address used
within one network to a different IP address known within another network. One network is designated the
inside
network and the other is the
outside
. Typically, a company maps its local inside network addresses to one
or more global outside IP addresses and "unmaps" the global IP addresses on incoming packets back into local
IP addresses. The IP addresses for the NAT can be either fixed or dynamically assigned by the ISP. In addition,
you can designate servers, e.g., a web server and a telnet server, on your local network and make them
accessible to the outside world. If you do not define any servers, NAT offers the additional benefit of firewall
protection. In such case, all incoming connections to your network will be filtered out by the Prestige, thus
preventing intruders from probing your network.
The SUA feature that the Prestige supports previously operates by mapping the private IP addresses to a global
IP address. It is only one subset of the NAT. The Prestige with ZyNOS V3.40 supports the most of the features
of the NAT based on RFC 1631, and we call this feature as 'Multi-NAT'. For more information on IP address
translation, please refer to RFC 1631,
• How NAT works
All contents copyright (c) 2007 ZyXEL Communications Corporation.
The IP Network Address Translator (NAT)
.
20
Prestige 2802HW(L)-Ix Support Notes
If we define the local IP addresses as the Internal Local Addresses (ILA) and the global IP addresses as the
Inside Global Address (IGA), see the following figure. The term 'inside' refers to the set of networks that are
subject to translation. NAT operates by mapping the ILA to the IGA required for communication with hosts on
other networks. It replaces the original IP source address (and TCP or UDP source port numbers) and then
forwards each packet to the Internet ISP, thus making them appear as if they had come from the NAT system
itself (e.g., the Prestige router). The Prestige keeps track of the original addresses and port numbers so incoming
reply packets can have their original values restored.
1. NAT Mapping Types
NAT supports five types of IP/port mapping. They are:
2. One to One
In One-to-One mode, the Prestige maps one ILA to one IGA.
3. Many to One
In Many-to-One mode, the Prestige maps multiple ILA to one IGA. This is equivalent to SUA (i.e., PAT, port
address translation), ZyXEL's Single User Account feature that previous ZyNOS routers supported (the SUA
only option in today's routers).
4. Many to Many Overload
In Many-to-Many Overload mode, the Prestige maps the multiple ILA to shared IGA.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
21
Prestige 2802HW(L)-Ix Support Notes
5. Many to Many No Overload
In Many-to-Many No Overload mode, the Prestige maps each ILA to unique IGA.
• Server
In Server mode, the Prestige maps multiple inside servers to one global IP address. This allows us to specify
multiple servers of different types behind the NAT for outside access. Note, if you want to map each server to
one unique IGA please use the One-to-One mode.
The following table summarizes these types.
NA T Type IP Mapping
Mapping
Direction
One-to-One ILA1<--->IGA1 Both
ILA1---->IGA1
Many-to-One (SUA/PAT)
ILA2---->IGA1
Outgoing
...
ILA1---->IGA1
ILA2---->IGA2
Many-to-Many Overload
ILA3---->IGA1
Outgoing
ILA4---->IGA2
...
ILA1---->IGA1
Many-to-Many No
Overload
(Allocate by Connections)
ILA2---->IGA3
ILA3---->IGA2
ILA4---->IGA4
Outgoing
...
Server
Incoming
Server 2 IP<----IGA1
Server 1 IP<----IGA1
• SUA Versus NAT
SUA (Single User Account) in previous ZyNOS versions is a NAT set with 2 rules, Many-to-One and Server.
The Prestige now has Full Feature NAT support to map global IP addresses to local IP addresses of clients or
servers. With multiple global IP addresses, multiple severs of the same type (e.g., FTP servers) are allowed on
the LAN for outside access. In previous ZyNOS versions (that supported SUA 'visible' servers had to be of
22
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
different types. The Prestige supports NAT sets on a remote node basis. They are reusable, but only one set is
allowed for each remote node. The Prestige 2802HWL supports 8 sets since there are 8 remote node. The
default SUA (Read Only) Set is a convenient, pre-configured, read only, Many-to-One mapping set, sufficient
for most purposes and helpful to people already familiar with SUA in previous ZyNOS versions.
• WEB GUI Menus
1. Applying NAT in the WEB GUI
You apply NAT via WEB GUI “Network>NAT>General" as displayed next. The next figure that you could
apply NAT for Internet access –Full Feature.
The following table describes the options for Network Address Translation.
FieldOptionsDescription
When you select this option the SMT will use Address
Full Feature
Mapping Set 1 (Menu 15.1-see later for further
discussion).
None
Network Address Translation
NAT is disabled when you select this option.
When you select this option the SMT will use Address
Mapping Set 255 (Menu 15.1-see later for further
SUA Only
discussion). This option use basically Many-to-One
Overload mapping. Select Full Feature when you
require other mapping types. It is a convenient,
All contents copyright (c) 2007 ZyXEL Communications Corporation.
23
Prestige 2802HW(L)-Ix Support Notes
pre-configured, read only, Many-to-One mapping set,
sufficient for most purposes and helpful to people
already familiar with SUA in previous ZyNOS
versions. Note that there is also a Server type whose
IGA is 0.0.0.0 in this set.
2. Address Mapping Sets and NAT Server Sets
Use the Address Mapping Sets menus and submenus to create the mapping table used to assign global addresses
to LAN clients. Each remote node must specify which NAT Address Mapping Set to use. The P2802HWL has
8 remote nodes and so allows you to configure 8 NAT Address Mapping Set. You can see nine NAT Address
Mapping sets in WEB GUI Network > NAT > Address Mapping. You can only configure from Set 1 to
Set 10 when you select Full Feature in WEB GUI NAT configuration. When you select SUA Only, thePort
Forwarding
will auto configure as to Many to one and Server as default in system.
The NAT Server Set is a list of LAN side servers mapped to external ports. To use this set (one set for the
Prestige), a server rule must be set up inside the NAT Address Mapping set. Please see NAT Server Sets for
further information on these menus.
Enter WEB GUI Network > NAT > Address Mapping to bring up Address Mapping Sets Menu.
Now let's look at WEB GUI MenuNetwork > NAT > Address Mapping.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
24
Prestige 2802HW(L)-Ix Support Notes
FieldDescriptionOption/Example
# This is the rule index number.
Local Start IP This is the starting local IP address (ILA).
0.0.0.0 for the
Many-to-One type.
This is the starting local IP address (ILA). If the rule is for all
Local End IP
local IPs, then the Start IP is 0.0.0.0 and the End IP is
255.255.255.255
255.255.255.255.
Global Start
This is the starting global IP address (IGA). If you have a
0.0.0.0
IP
dynamic IP, enter 0.0.0.0 as the Global Start IP.
Global End IP This is the ending global IP address (IGA). N/A
Type This is the NAT mapping types. Many-to-One and Server
Click the edit icon to go to the screen where you can edit the
address mapping rule.
Modify
Click the delete icon to delete an existing address mapping
N/A
rule. Note that subsequent address mapping rules move up by
one when you take this action.
To edit an address mapping rule, click the rule's edit icon in the Address Mapping screen to display the screen
show next.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
25
Prestige 2802HW(L)-Ix Support Notes
The following table describes the fields in this screen.
FieldDescriptionOption/Example
One-to-One
Press [CHOOSE BAR] to toggle through a total of 5 types.
Many-to-One
Many-to-Many Overload
Type
These are the mapping types discussed above plus a server type.
Many-to-Many No
Some examples follow to clarify these a little more.
Overload
Server
Start This is the starting local IP address (ILA) 0.0.0.0
Local
IP
End
This is the ending local IP address (ILA). If the rule is for all
local IPs, then put the Start IP as 0.0.0.0 and the End IP as
255.255.255.255
255.255.255.255. This field is N/A for One-to-One type.
This is the starting global IP address (IGA). If you have a
Global
IP
Start
dynamic IP, enter 0.0.0.0 as the Global Start IP.
This is the ending global IP address (IGA). This field is N/A for
End
0.0.0.0
200.1.1.64
One-to-One, Many-to-One and Server types.
Note: For all Local and Global IPs, the End IP address must begin after the IP Start address, i.e., you cannot
have an End IP address beginning before the Start IP address.
• NAT Server Sets
The NAT Server Set is a list of LAN side servers mapped to external ports (similar to the old SUA menu of
before). If you wish, you can make inside servers for different services, e.g., Web or FTP, visible to the outside
users, even though NAT makes your network appears as a single machine to the outside world. A server is
identified by the port number, e.g., Web service is on port 80 and FTP on port 21.
As an example (see the following figure), if you have a Web server at 192.168.1.36 and a FTP server at
192.168.1.33, then you need to specify for port 80 (Web) the server at IP address 192.168.1.36 and for port 21
(FTP) another at IP address 192.168.1.33.
26
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
Please note that a server can support more than one service, e.g., a server can provide both FTP and Mail
service, while another provides only Web service.
The following procedures show how to configure a server behind NAT.
Step 1. EnterNetwork > NAT > Address Mapping in the WEB GUI to go to Address Mapping Setup.
Step 2. Enter Edit Details of Server Mapping Setto go to NAT Server Setup.
Step 3. Selet the service type in Service Name field and the inside IP address of the server in the Server IP
Address field.
Step 4. Press Add icon to add your configuration after you define all the servers, press Apply icon to save the
settings.
27
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
The most often used port numbers are shown in the following table. Please refer RFC 1700 for further
information about port numbers.
ServicePort Number
FTP 20,21
Telnet 23
SMTP 25
DNS (Domain Name Server) 53
www-http (Web) 80
PPTP (Point-to-Point Tunneling
1723
Protocol)
1. Internet Access Only
In our Internet Access example, we only need one rule where all our ILAs map to one IGA assigned by the ISP.
See the following figure.
28
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
From WEB GUINetwork > NAT > General shown above simply choose the SUA Only option in the NAT
Setup. This is the Many-to-One mapping discussed earlier.
2. Internet Access with an Internal Server
29
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Prestige 2802HW(L)-Ix Support Notes
In this case, we do exactly as above (use the convenient pre-configured SUA Only set) and also go to Menu
Network > NAT > Port Forwarding
as shown below.
to specify the Internet Server behind the NAT as shown in the NAT
3. Using Multiple Global IP addresses for clients and servers (One-to-One, Many-to-One, Server Set mapping
types are used)
30
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Loading...
+ 157 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.