ZyXEL P-660HN-T1A Support Guide

ZyXEL P-660HN-T1A Manual

ZyXEL P-660HN-T1A manual content summary:

  • ZyXEL P-660HN-T1A | Support Guide - Page 1
    P-660HN Series Support Notes P-660HN-T1A 802.11n 1x1 Wireless ADSL2+ 4-port Gateway Support Notes Version3.40 Apr. 2010 1 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 2
    the default password for Web Configurator 12 3. What's the difference between 'Common User Account' and 'Administrator Account 12 4. How do I know the P-660HN-T1A's WAN IP address assigned by the ISP?...12 5. What is the micro filter or splitter used for 13 6. The P-660HN-T1A supports Bridge and
  • ZyXEL P-660HN-T1A | Support Guide - Page 3
    the default ACL firewall rules in P-660HN-T1A? . 23 Configuration 23 1. How do I configure the firewall 23 2. How do I prevent others from configuring my firewall? ......... 23 3. Why can't I configure my P-660HN-T1A using Web Configurator/Telnet over WAN 24 4. Why can't I upload the firmware and
  • ZyXEL P-660HN-T1A | Support Guide - Page 4
    mode does P-660HN-T1A support? ...31 15. What Wireless standard does P-660HN-T1A support? . 31 16. Does P-660HN-T1A support MAC filtering 31 17. Does P-660HN-T1A support auto rate adaption 31 Advanced FAQ 32 1. What is Ad Hoc mode 32 2. What is Infrastructure mode 32 3. How many Access Points
  • ZyXEL P-660HN-T1A | Support Guide - Page 5
    packet filter on P-660HN-T1A 81 16. Change WAN MTU via WEB-GUI 84 Wireless Application Notes 86 1. Configure a Wireless Client to Ad hoc mode 86 2. MAC Filter 92 3. Setup WEP (Wired Equivalent Privacy 94 4. Site Survey 98 5. Configure 802.1x and WPA 102 6. The WPS/WLAN Button 106 Support
  • ZyXEL P-660HN-T1A | Support Guide - Page 6
    and it could be accessed via telnet session. Note: It is protected by super password, '1234' by factory default. 3. How do I update the firmware and configuration file? You can do this if you access the P-660HN-T1A as Administrator. You can upload the firmware and configuration file to Prestige from
  • ZyXEL P-660HN-T1A | Support Guide - Page 7
    the current configuration and restore factory defaults this way: Use the RESET button on the rear panel of P-660HN-T1A to reset the router. After the router is reset, the LAN IP address will be reset to '192.168.1.1', the common user password will be reset to 'user', the Administrator password will
  • ZyXEL P-660HN-T1A | Support Guide - Page 8
    P-660HN-T1A delivers the packet to the local server by looking up to a SUA server table. Therefore, to make a local server accessible to the outside users, the port number and the inside IP address of the server must be configured. (You can configure it in Web Configurator, Advanced Setup, Network
  • ZyXEL P-660HN-T1A | Support Guide - Page 9
    global IP addresses as the Inside Global Address (IGA),  One to One: In One-to-One mode, the P-660HN-T1A maps one ILA to one IGA.  Many to One: In Many-to-One mode, the P-660HN-T1A maps multiple ILA to one IGA. This is equivalent to SUA (i.e., PAT, port address translation), ZyXEL's Single User
  • ZyXEL P-660HN-T1A | Support Guide - Page 10
    of the users but the number of the sessions. The P-660HN-T1A supports 4k sessions that you can use the 'ip nat session' command in CLI to see. You can also use „ip nat hashTable wanif0‟ to view the current active NAT sessions. 14. What are Device filters and Protocol filters? The filters have been
  • ZyXEL P-660HN-T1A | Support Guide - Page 11
    P-660HN Series Support Notes  Action Not Matched =Forward Where a.b.c.d is an IP address on your local network and w.x.y.z is your netmask: For the output data filters:  Deny bounce back packet  Allow packets that originate from us Filter rule setup:  Filter Type =TCP/IP Filter Rule  Active =
  • ZyXEL P-660HN-T1A | Support Guide - Page 12
    1. How can I manage P-660HN-T1A?  Multilingual Embedded Web GUI for Local and Remote management  CLI (Command-line interface)  Telnet support (Administrator Password Protected ) for remote configuration change and status monitoring  FTP/ TFTP sever, firmware upgrade and configuration backup and
  • ZyXEL P-660HN-T1A | Support Guide - Page 13
    the broadband connections. Besides, PPPoE supports a broad range of existing applications and service including authentication, accounting, secure access and configuration management. 9. What is DDNS? The Dynamic DNS service allows you to alias a dynamic IP address to a static hostname, allowing
  • ZyXEL P-660HN-T1A | Support Guide - Page 14
    server to be accessed by using DNS name rather than using the dynamic IP address we can use the DDNS service. The DDNS server allows to alias a dynamic IP address to a static hostname. Whenever the ISP assigns you a new IP, the P-660HN-T1A sends this IP to the DDNS server for its updates. 11. What
  • ZyXEL P-660HN-T1A | Support Guide - Page 15
    -T1A? The P-660HN-T1A must manage traffic fairly and provide bandwidth allocation for different sorts of applications, such as voice, video, and data. All applications have their own natural bit rate. Large data transactions have a fluctuating natural bit rate. The P-660HN-T1A is able to support
  • ZyXEL P-660HN-T1A | Support Guide - Page 16
    P-660HN-T1A performs content filtering. You can also specify trusted IP Addresses on LAN for which the P-660HN-T1A will not perform content filtering. You can configure the details about it in Web Configurator, Advanced setup, Security -> Filter. 16 All contents copyright © 2010 ZyXEL Communications
  • ZyXEL P-660HN-T1A | Support Guide - Page 17
    to the user's manual. 4. How do I know the ADSL line is up? You can see the DSL LED Green on the P-660HN-T1A's front panel is on when the ADSL physical layer is up. 5. How does the P-660HN-T1A work on a noisy ADSL? Depending on the line quality, the P-660HN-T1A uses "Fall Back" and "Fall Forward" to
  • ZyXEL P-660HN-T1A | Support Guide - Page 18
    CI> wan adsl linedata near  You can also do it in Web Configurator, Advanced Setup, Maintenance -> Diagnostic -> DSL Line -> DSL Status: 8. What are the signaling pins of the ADSL connector? The signaling pins on the P-660HN-T1A's ADSL connector are pin 3 and pin 4. The middle two pins for a RJ11
  • ZyXEL P-660HN-T1A | Support Guide - Page 19
    is internet access such as ftp etc ... Triple Play is a port-based policy to forward packets from different LAN port to different PVCs, thus you can configure each PVC separately to assign different QoS to different application. 19 All contents copyright © 2010 ZyXEL Communications Corporation
  • ZyXEL P-660HN-T1A | Support Guide - Page 20
    -configured to automatically detect and thwart Denial of Service (DoS) attacks such as Ping of Death, SYN Flood, LAND attack, IP Spoofing, etc. It also uses stateful packet inspection to determine if an inbound connection is allowed through the firewall to the private LAN. The P-660HN-T1A supports
  • ZyXEL P-660HN-T1A | Support Guide - Page 21
    660HN Series Support Notes Stateful Inspection Firewalls restrict access by screening data packets against defined access rules. They make access control decisions based on IP address and protocol. They also 'inspect' the session data to assure the integrity of the connection and to adapt to dynamic
  • ZyXEL P-660HN-T1A | Support Guide - Page 22
    , the system will ignore all incoming SYN requests, making the system unavailable for legitimate users. 10. What is LAND attack? In a LAN attack, hackers flood SYN packets to the network with a spoofed source IP address of the targeted system. This makes it appear as if the host computer sent the
  • ZyXEL P-660HN-T1A | Support Guide - Page 23
    ? You can use the Web Configurator to configure the firewall for P-660HN-T1A. By factory default, if you connect your PC to the LAN Interface of P-660HN-T1A, you can access Web Configurator via „http://192.168.1.1‟. Note: Don't forget to type in the Administrator Password. 2. How do I prevent others
  • ZyXEL P-660HN-T1A | Support Guide - Page 24
    P-660HN Series Support Notes 1. Change the default Administrator password since it is required when setting up the firewall. 2. Limit who can access to your P-660HN-T1A‟s Web Configurator or CLI. You can enter the IP address of the secured LAN host in Web Configurator, Advanced Setup, Advanced ->
  • ZyXEL P-660HN-T1A | Support Guide - Page 25
    P-660HN Series Support Notes (2)You have disabled WWW/Telnet service in Web Configurator, Advanced setup, Advanced -> Remote MGNT: (3) WWW/Telnet service is enabled but your host IP is not the secured host entered in Web Configurator, Advanced setup, Advanced -> Remote MGNT: (4)A filter set which
  • ZyXEL P-660HN-T1A | Support Guide - Page 26
    P-660HN Series Support Notes (2) You have disabled FTP service in Web Configurator, Advanced setup, Advanced -> Remote MGNT. (3) FTP service is enabled but your host IP is not the secured host entered in Web Configurator, Advanced setup, Advanced -> Remote MGNT. (4) A filter set which blocks FTP
  • ZyXEL P-660HN-T1A | Support Guide - Page 27
    When does the P-660HN-T1A generate the firewall alert? The P-660HN-T1A generates the alert when an attack is detected by the firewall and sends it via Email. So, to send the alert, you must configure the mail server and Email address using Web Configurator, Advanced Setup, Maintenance -> Logs -> Log
  • ZyXEL P-660HN-T1A | Support Guide - Page 28
    the centre of the wireless client population. 2. What are the advantages of Wireless LAN? Mobility: Wireless LAN systems can provide LAN users with access to real-time information anywhere in their organization. This mobility supports productivity and service opportunities not possible with wired
  • ZyXEL P-660HN-T1A | Support Guide - Page 29
    with their laptops. 5. What is an Access Point? The AP (access point also known as a base station) is the wireless server that with an antenna and a wired Ethernet connection that broadcasts information using radio signals. AP typically acts as a bridge for the clients. It can pass information to
  • ZyXEL P-660HN-T1A | Support Guide - Page 30
    P-660HN Series Support Notes 802.11b), cordless phones, wireless medical telemetry equipment and Bluetooth™ short-range wireless applications, which include connecting printers to computers and . (4) Add additional APs if necessary. 30 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 31
    modes supported on P-660HN-T1A are: Static WEP, WPA-PSK, WPA, WPA2-PSK, and WPAPSKMixed. 15. What Wireless standard does P-660HN-T1A support? It supports IEEE 802.11b/g/draft n standard. 16. Does P-660HN-T1A support MAC filtering? Yes, it supports up to 32 MAC Address filtering. 17. Does P-660HN-T1A
  • ZyXEL P-660HN-T1A | Support Guide - Page 32
    infrastructure. If such connectivity is required the Access Points must be used to connect to the wired LAN backbone. Wireless clients have their configurations set for "infrastructure mode" in order to utilise access points relaying. 3. How many Access Points are required in a given area? This
  • ZyXEL P-660HN-T1A | Support Guide - Page 33
    across the P-660HN-T1A Access Point's radio link? To secure the date across the P-660HN-T1A Access Point‟s radio link, we could select any one of the security mode: Static 64/128 bit WEP, WPA-PSK, WPA, WPA2-PSK, WPA2. 2. What is WEP? 33 All contents copyright © 2010 ZyXEL Communications Corporation
  • ZyXEL P-660HN-T1A | Support Guide - Page 34
    Pre-Shared Key) can be used if user do not have a Radius server but still want to benefit from it. Because WPA-PSK only requires a single password to be entered on wireless AP/gateway and wireless client. As long as the passwords match, a client will be granted access to the WLAN. 4. What is the
  • ZyXEL P-660HN-T1A | Support Guide - Page 35
    660HN Series Support Notes packets.The SSID is in the beacon and probe management messages and SSID goes over the air in clear text. This makes obtaining the SSID easy by sniffing 802.11n wireless traffic. 8. By turning off the broadcast of SSID, can someone still sniff the SSID? Many APs by default
  • ZyXEL P-660HN-T1A | Support Guide - Page 36
    -T1A under Bridge mode  Setup your workstation  Setup your P-660HN-T1A under bridge mode If the ISP limits some specific computers to access Internet, that means only the traffic to/from these computers will be forwarded and the other will be filtered. In this case, we use P-660HN-T1A which works
  • ZyXEL P-660HN-T1A | Support Guide - Page 37
    660HN Series Support Notes Setup your P-660HN-T1A under bridge mode The following procedure shows you how to configure your P-660HN-T1A as bridge mode. We will use Web Configurator to guide you through the related menu. 1. Retrieve Prestige Web Please enter the LAN IP address of the Prestige router
  • ZyXEL P-660HN-T1A | Support Guide - Page 38
    P-660HN Series Support Notes 2. Login first The default username and password is the default SMT password '1234'. (1) Configure P-660HN-T1A as bridge mode and configure Internet setup parameters in Web Configurator, Advanced Setup, Network -> WAN -> Internet Connection. Key Settings: Option
  • ZyXEL P-660HN-T1A | Support Guide - Page 39
    as default, so you need only to configure the workstations as the DHCP clients in the networking settings. In this case, the IP address of the computer is assigned by the P-660HN-T1A. The P-660HN-T1A can also provide the DNS to the clients via DHCP if it is available. For this setup in Windows
  • ZyXEL P-660HN-T1A | Support Guide - Page 40
    Support Notes Set up your P-660HN-T1A under routing mode The following procedure shows you how to configure your P-660HN-T1A as Routing mode for routing traffic. We will use Web Configurator to guide you through the related menu. (1) Configure P-660HN-T1A as routing mode and configure Internet setup
  • ZyXEL P-660HN-T1A | Support Guide - Page 41
    that your ISP supports. For example, LLC. Specify a VPI (Virtual Path Identifier) and a VCI (Virtual Channel Identifier) given to you by your ISP. Set to Dynamic if the ISP provides the IP for the P-660HN-T1A dynamically. Otherwise, set to Static and enter the IP in the IP Address field. 41 All
  • ZyXEL P-660HN-T1A | Support Guide - Page 42
    stands for Dynamic Host Configuration Protocol. In addition to the DHCP server feature, the P-660HN-T1A supports the DHCP relay function. When it is configured as DHCP server, it assigns the IP addresses to the LAN clients. When it is configured as DHCP relay, it is responsible for forwarding the
  • ZyXEL P-660HN-T1A | Support Guide - Page 43
    the P-660HN-T1A's WAN IP Address. SUA Supporting Table The following are the required Web Configurator, Advanced Setup, Network -> NAT -> Port Forwarding for the various applications running SUA mode. ZyXEL SUA Supporting Table1 Application Required Settings in Port Forwarding Port/IP Outgoing
  • ZyXEL P-660HN-T1A | Support Guide - Page 44
    /client IP Default/client IP Default/client IP 1720/client IP 1503/client IP . . . Default/client IP Default/client IP . . . 5631/client IP 5632/client IP 22/client IP IPsec (ESP tunneling mode) None (one client only) Default/Client Microsoft Messenger Service 3.0 6901/client IP 6901/client IP
  • ZyXEL P-660HN-T1A | Support Guide - Page 45
    has an IP of 192.168.1.34, then the default SUA server must be set to 192.168.1.34. The peer Cu-SeeMe user can reach this workstation by using P-660HN-T1A's WAN IP address which can be obtained from Web Configurator, Status -> WAN Information. 45 All contents copyright © 2010 ZyXEL Communications
  • ZyXEL P-660HN-T1A | Support Guide - Page 46
    must have a fixed IP address and not be a DHCP client whose IP address potentially changes each time P-660HN-T1A is powered on. In addition to the servers for specific services, SUA supports a default server. A service request that does not have a server explicitly designated for is forwarded to the
  • ZyXEL P-660HN-T1A | Support Guide - Page 47
    P-660HN Series Support Notes To make a server visible to the outside world, specify the port number of the service and the inside address of the server in Web Configurator, Advanced Setup, Network -> NAT -> Port Forwarding. The outside users can access the local server using the P-660HN-T1A's WAN IP
  • ZyXEL P-660HN-T1A | Support Guide - Page 48
    P-660HN Series Support Notes Service FTP Telnet SMTP DNS (Domain Name Server) www-http (Web) Port Number 21 23 25 53 80 Configure a PPTP server behind SUA Introduction PPTP is a tunneling protocol defined by the PPTP forum that allows PPP packets to be encapsulated within Internet Protocol (IP)
  • ZyXEL P-660HN-T1A | Support Guide - Page 49
    (WinNT server) behind SUA. The port number of the PPTP has to be entered in the Web Configurator, Advanced Setup, Network -> NAT -> Port Forwarding on P-660HN-T1A to forward to the appropriate private IP address of Windows NT server. 49 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 50
    on user  Enable RAS port  Select the network protocols from RAS such as IPX, TCP/IP NetBEUI  Set the Internet gateway to P-660HN-T1A (2) PPTP client setup (Win9x)  Add one VPN connection from Dial-Up Networking by entering the correct username & password and the IP address of the P-660HN-T1A
  • ZyXEL P-660HN-T1A | Support Guide - Page 51
    ISP assigns to P-660HN-T1A router in SUA mode and enter this IP address in the VPN dial-up dialog box. You can check this Internet IP address from PNC Monitor or S Web Configurator, Status -> WAN Information. If the Internet IP address is a fixed IP address provided by ISP in SUA mode, then you can
  • ZyXEL P-660HN-T1A | Support Guide - Page 52
    660HN Series Support Notes 5. Using Full Feature NAT When P-660HN-T1A is in Routing mode, you can select NAT Option as Full Feature in Network -> NAT -> General: Key Settings: Field Network Address Translation Options Description Full Feature When you select this option you can select Address
  • ZyXEL P-660HN-T1A | Support Guide - Page 53
    Setup, Network -> NAT -> Port Forwarding. To use the NAT server sets you‟ve configured, a Server rule must be set up inside the NAT Address Mapping set. Please see NAT Server Sets for further information on how to apply it. When you select SUA Only, the P-660HN-T1A will use a default SUA Address
  • ZyXEL P-660HN-T1A | Support Guide - Page 54
    P-660HN Series Support Notes IP. Global End This is the ending global IP address (IGA). IP Type This is the NAT mapping types. N/A Many-to-One and Server Here we‟ll guide you to configure Address Mapping Sets from Web Configurator and CLI. (Since in Web Configurator we can only edit the rules
  • ZyXEL P-660HN-T1A | Support Guide - Page 55
    Local and Global IPs, the End IP address must begin after the IP Start address, i.e., you cannot have an End IP address beginning before the Start IP address.  Configure Address Mapping Sets in CLI Setp 1: Telnet to the P-660HN-T1A. (We suppose the LAN IP Address of P-660HN-T1A is 192.168.1.1) Step
  • ZyXEL P-660HN-T1A | Support Guide - Page 56
    P-660HN Series Support Notes Setp 3: Set NAT address mapping rule for the Address Mapping Set you just configured (Set 2 in this example) by command „ip nat addrmap rule [rule#] [insert | edit] [type] [local start IP] [local end IP] [global start IP] [global end IP] [server set #]‟. Suppose we set a
  • ZyXEL P-660HN-T1A | Support Guide - Page 57
    edit [rule#] svrport ip nat server edit [rule#] remotehost Configure the IP address range of remote host (Leave it to be default value if you don‟t need this command) ip nat server edit [rule
  • ZyXEL P-660HN-T1A | Support Guide - Page 58
    port numbers. Service FTP Telnet SMTP DNS (Domain Name Server) www-http (Web) PPTP (Point-to-Point Tunneling Protocol)  Examples Port Number 21 23 25 53 80 1723  Internet Access Only  Internet Access with an Internal Server  Using Multiple Global IP addresses for clients and servers  Support
  • ZyXEL P-660HN-T1A | Support Guide - Page 59
    an Address Mapping Set with a Many-to-One Rule. See the following figure. (2) Internet Access with an Internal Server In this case, we do exactly as the figure (use the convenient pre-configured SUA Only set) and also go to Web Configurator, Advanced Setup, Network -> NAT -> Port Forwarding to
  • ZyXEL P-660HN-T1A | Support Guide - Page 60
    below: P-660HN Series Support Notes (3) Using Multiple Global IP addresses for clients and servers (One-to-One, Many (192.168.1.11) to IGA2 (200.0.0.2).  Rule 3 (Many-to-One type) to map the other clients to IGA3 (200.0.0.3).  Rule 4 (Server type) to map a web server and mail server with ILA3
  • ZyXEL P-660HN-T1A | Support Guide - Page 61
    P-660HN Series Support Notes Step 1: In this case, we need to map ILA to more than one IGA, therefore we must choose the Full Feature option from the NAT field in currently active remote node, and assign IGA3 to P-660HN-T1A‟s WAN IP Address. Step 2: Go to Web Configurator, Advanced Setup, Network ->
  • ZyXEL P-660HN-T1A | Support Guide - Page 62
    P-660HN Series Support Notes Rule 3 Setup: Select Many-to-One type to map the other clients to IGA3 (200.0.0.3). Rule 4 Setup: Select Server type to map our web server and mail server with ILA3 (192.168.1.20) to IGA3. Menu Network -> NAT -> Address Mapping should look as follows now: 62 All contents
  • ZyXEL P-660HN-T1A | Support Guide - Page 63
    web server and mail server from Web Configurator, Advanced Setup, Network -> NAT -> Port Forwarding: (4) Support Non NAT Friendly Applications Some servers providing Internet applications such as some mIRC servers do not allow users to login using the same IP address. In this case it is better to
  • ZyXEL P-660HN-T1A | Support Guide - Page 64
    the problems if your DNS server uses an IP associated with dynamic IPs. Without DDNS, we always tell the users to use the WAN IP of the P-660HN-T1A to access the internal server. It is inconvenient for the users if this IP is dynamic. With DDNS supported by the P-660HN-T1A, you apply a DNS name
  • ZyXEL P-660HN-T1A | Support Guide - Page 65
    in the P-660HN-T1A, you must register an account from the DDNS server such as WWW.DYNDNS.ORG first. After the registration, you have a hostname for your internal server and a password using to update the IP to the DDNS server. 2. Login Web Configurator, Advanced Setup, Advanced -> Dynamic DNS Select
  • ZyXEL P-660HN-T1A | Support Guide - Page 66
    P-660HN Series Support Notes 7. QoS(802.1Q) The QoS General Screen Click Advanced > QoS to open the screen as shown next.Use this screen to enable or disable QoS, and select to have the ZyXEL Device automatically assign priority to traffic according to the IEEE 802.1p priority level, IP precedence
  • ZyXEL P-660HN-T1A | Support Guide - Page 67
    8. Network Management Using SNMP  ZyXEL SNMP Implementation ZyXEL currently includes SNMP support in some P-660HN-T1A routers. It is implemented based on the SNMPv1, so it will be able to communicate with SNMPv1 NMSs. Further, users can also add ZyXEL's private MIB in the NMS to monitor and control
  • ZyXEL P-660HN-T1A | Support Guide - Page 68
    community, this trap is sent to the manager. 6. whyReboot (defined in ZYXEL-MIB) : When the system is going to restart (warmstart), the trap will be sent with the reason of restart before rebooting. (1) For intentional reboot : In some cases (download new files, CI command "sys reboot", ...), reboot
  • ZyXEL P-660HN-T1A | Support Guide - Page 69
    P-660HN Series Support Notes  Downloading ZyXEL's private MIB  Configure the P-660HN-T1A for SNMP The SNMP related settings in P-660HN-T1A are configured in Web Configurator, Advanced Setup, Advanced -> Remote MGNT -> SNMP The following steps describe a simple setup procedure for configuring all
  • ZyXEL P-660HN-T1A | Support Guide - Page 70
    P-660HN Series Support Notes You can configure it in Web Configurator, Advanced Setup, Maintenance -> Logs -> System Log. 10. Using IP Alias  What is IP Alias ? In a typical environment, a LAN router is required to connect two local networks. The P-660HN-T1A can connect three local networks to the
  • ZyXEL P-660HN-T1A | Support Guide - Page 71
    #= the corresponding filter set number you‟ve configured lan save  IP Alias Setup (1) Edit the first network in Web Configurator, Advanced Setup, Network -> LAN -> IP/DHCP Setup by configuring the P-660HN-T1A's first LAN IP address. 71 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 72
    P-660HN Series Support Notes Key Settings: DHCP Setup TCP/IP Setup If the P-660HN-T1A's DHCP server is enabled, the IP pool for the clients can be any of the three networks. Enter the first LAN IP address for the P-660HN-T1A. This will create the first route in the enif0 interface. (2) Edit the
  • ZyXEL P-660HN-T1A | Support Guide - Page 73
    P-660HN Series Support Notes Use IPPR to distribute traffic among multiple paths  Benefits Source-Based Routing - Network administrators can use policy-based routing to direct traffic from different users through different connections. Quality of Service (QoS)- Organizations can differentiate
  • ZyXEL P-660HN-T1A | Support Guide - Page 74
    end= N/A Destination: addr start= 0.0.0.0 end= N/A port start= 80 end= 80 Action= Matched Gateway addr = 192.168.1.254 Log= No Type of Service= No Change Precedence = No Change This policy example forces the Web packets originated from the clients with IP addresses from 192.168.1.2 to 192
  • ZyXEL P-660HN-T1A | Support Guide - Page 75
    Support Notes ip policyrouting set criteria packetlength 0 (Set the packet length as 0 for the rule) ip policyrouting set criteria srcip 192.168.1.2 192.168.1.20 (Set the source IP address for the rule: Start=192.168.1.2, end=192.168.1.20) ip policyrouting set criteria srcport 0 (Set the source port
  • ZyXEL P-660HN-T1A | Support Guide - Page 76
    660HN Series Support Notes just like the scheduler ina video recorder which records the program according to the specified time. Users can apply at most 4 schedule sets in Remote Node. The remote node configured to configure a Call Scheduling? You can configure to configure call schedule it works on
  • ZyXEL P-660HN-T1A | Support Guide - Page 77
    P-660HN Series Support Notes (Set 660HN-T1A There is no RTC (Real-Time Clock) chip so the P-660HN-T1A should launch a mechanism to get current time and date from external server in boot time. Time service is implemented by the Daytime protocol(RFC-867), Time 77 All contents copyright © 2010 ZyXEL
  • ZyXEL P-660HN-T1A | Support Guide - Page 78
    P-660HN Series Support Notes protocol(RFC-868), and NTP protocol(RFC-1305). You have to assign an IP address of a time server and then, the P-660HN-T1A will get the date, time, and time-zone information from this server. You can configure it in Web Configurator, Advanced Setup, Maintenance -> System
  • ZyXEL P-660HN-T1A | Support Guide - Page 79
    P-660HN Series Support Notes P-660HN-T1A supports IGMP v1 ,v2 and IGMP v3 without source filtering.  IP Multicast Setup (1) Enable IGMP in P-660HN-T1A's LAN in Web Configurator, Advanced Setup, Network -> LAN -> IP -> Advanced Setup. (2) Enable IGMP in P-660HN-T1A's remote node in Web Configurator,
  • ZyXEL P-660HN-T1A | Support Guide - Page 80
    configure itself if the hunting result is successfully. This feature has two constraints: 1. It supports the ISP provides one kind of service (PPPoE/PPPoA, etc.) only, otherwise the hunting will get confusing and failed. 2. VC auto-hunting only supports dynamic WAN IP address. If the router
  • ZyXEL P-660HN-T1A | Support Guide - Page 81
    node> 15. How to configure packet filter on P-660HN-T1A? The P-660HN-T1A allows you to configure up to twelve filter sets with six rules in each set, for a total of 72 filter rules in the system. You can apply up to four filter sets to a particular port to block multiple types of packets
  • ZyXEL P-660HN-T1A | Support Guide - Page 82
    P-660HN Series Support Notes The packet filter function on P-660HN-T1A is the same as before, just that you could only configure the filter set and apply them by command in CLI. It‟s very complex for common users to do it. So here‟s the recommendation: (1) Usually if you want to block special
  • ZyXEL P-660HN-T1A | Support Guide - Page 83
    begin to configure the filter rules Set the name of filter set Set the type of filter rule Enable the rule Disable the rule Set the protocol ID of the rule Set the sourceroute yes/no Set the destination IP address and subnet mask of 83 All contents copyright © 2010 ZyXEL Communications Corporation
  • ZyXEL P-660HN-T1A | Support Guide - Page 84
    P-660HN Series Support Notes mask] the rule Set the destination port and compare type (compare sys filter set destport [port#] [compare type could be 0(none)|1(equal)|2(not type = none|equal|notequal|less|greater] equal)|3(less)|4(greater) ) sys filter set srcip [address] [subnet mask] Set the
  • ZyXEL P-660HN-T1A | Support Guide - Page 85
    P-660HN Series Support Notes 85 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 86
    P-660HN Series Support Notes Wireless Application Notes 1. Configure a Wireless Client to Ad hoc mode Ad hoc Introduction What is Ad Hoc mode? Ad hoc mode is a wireless network consists of a number of stations without access points. Without using an access point or any connection to a wired network,
  • ZyXEL P-660HN-T1A | Support Guide - Page 87
    Support Notes Step 3: Select Ad hoc from the operation mode pull down menu, fill you an SSID and select a channel you want to use than press OK to apply. Step 4: Since there is no DHCP server to give the host IP you must first designate a static IP for your station. From Windows Start select Control
  • ZyXEL P-660HN-T1A | Support Guide - Page 88
    P-660HN Series Support Notes Step 5: From general tab select TCP/IP and click property 88 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 89
    P-660HN Series Support Notes Step 6: Fill in your network IP address and subnet mask and click OK to finish. Configuration for Wireless Station B To configure Ad hoc mode on your ZyAIR B-100/B-200/B-300 wireless NIC card please follow the following step. Step1: Double click on the utility icon in
  • ZyXEL P-660HN-T1A | Support Guide - Page 90
    Support Notes Step 3: Select Ad hoc from the operation mode pull down menu, fill you an SSID and select a channel you want to use than press OK to apply. Step 4: Since there is no DHCP server to give the host IP you must first designate a static IP for your station. From Windows Start select Control
  • ZyXEL P-660HN-T1A | Support Guide - Page 91
    P-660HN Series Support Notes Step 5: From general tab select TCP/IP and click property 91 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 92
    P-660HN Series Support Notes Step 6: Fill in your network IP address and subnet mask and click OK to finish. Step 7: Station A now are able to connect to Station B. 2. MAC Filter MAC Filter Overview Users can use MAC Filter as a method to restrict unauthorized stations from accessing the APs. ZyXEL
  • ZyXEL P-660HN-T1A | Support Guide - Page 93
    . Users can choose either way to configure their filter rule. Configure the WLAN MAC Filter The MAC Filter related settings in ZyXEL APs are configured in Web Configurator, Advanced Setup, Network -> Wireless LAN ->MAC Filter. Before you configure the MAC filter, you need to know the MAC address of
  • ZyXEL P-660HN-T1A | Support Guide - Page 94
    P-660HN Series Support Notes hosts with MAC addresses configured in this list will be blocked. MAC Address This field specifies those MAC Addresses that you want to add in the list. 3. Setup WEP (Wired Equivalent Privacy) Introduction The 802.11 standard describes the communication that occurs in
  • ZyXEL P-660HN-T1A | Support Guide - Page 95
    P-660HN Series Support Notes Step 2: Set up WEP Key in the Web Configurator. You need to set the one of the following parameters: WEP key (secret key) with 58 hexadecimal digits There are two ways you can configure the WEP Key. (1) You can put in a special WEP key in the „WEP Key‟ menu directly
  • ZyXEL P-660HN-T1A | Support Guide - Page 96
    P-660HN Series Support Notes (2) You can also put in an arbitrary sequence of characters in the „Passphrase‟ and then press button „Generate‟ to let the P-660HN-T1A generate WEP Key for you:  Setting up the Station Step 1: Double click on the utility icon in your windows task bar or right click the
  • ZyXEL P-660HN-T1A | Support Guide - Page 97
    P-660HN Series Support Notes Note: If the utility icon doesn't exist in your task bar, click Start -> Programs -> ...... to start the utility. Step 2: Select the 'Configuration' tab. Select „Set Security‟ to configure encryption type and parameters correspond with access point. 97 All contents
  • ZyXEL P-660HN-T1A | Support Guide - Page 98
    660HN Series Support Notes Note: You should select Key 1 as default Transmit Key, since the P-660HN-T1A is supposed to use Key 1 by default. Key settings The WEP Encryption type of station has to equal to the access point to predict. 98 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 99
    user's area, when doing so ask a question where is wireless coverage needed and where does not, and note and take note on the diagram this is information is needed to determine the number of AP required. 4. Determine the preliminary access point location on the facility diagram base on the service
  • ZyXEL P-660HN-T1A | Support Guide - Page 100
    P-660HN Series Support Notes Step 4: It's always a good idea to start with putting the access point at the corner of the room and walk away from the access point in a systematic manner. Record down the changes at point where transfer rate drop and the link quality and signal strength information on
  • ZyXEL P-660HN-T1A | Support Guide - Page 101
    P-660HN Series Support Notes Step 5: When you reach the farthest point of connection mark the spot. Now you move the access point to this new spot as have already determine the farthest point of the access point installation spot if wireless service is required from corner of the room. Step 6:
  • ZyXEL P-660HN-T1A | Support Guide - Page 102
    P-660HN Series Support Notes Note: If there are more than one access point is needed be sure to make the adjacent access point service area over lap one another. So the wireless station is able to roam. For more information please refer to roaming at 5. Configure 802.1x and WPA  What is the WPA
  • ZyXEL P-660HN-T1A | Support Guide - Page 103
    key management. Authentication can be done using local user database internal to the P-660HN-T1A (authenticate up to 32 users) or an external RADIUS server for an unlimited number of users. Step 1: To change your P-660HN-T1A's authentication settings, login Web Configurator, Advanced Setup, Network
  • ZyXEL P-660HN-T1A | Support Guide - Page 104
    P-660HN Series Support Notes  Configuration for your PC Step 1: Double click on your wireless utility icon in your windows task bar, the utility will pop up on your windows screen. Step 2: Select the configuration tab, type in the SSID (Service Set Identifier), select the operating Mode as
  • ZyXEL P-660HN-T1A | Support Guide - Page 105
    P-660HN Series Support Notes Step 4: Click OK for finish, and begin to Site survey. Connect to the AP as you have configured. 105 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 106
    WPS WLAN ON/OFF button for 1 to 5 seconds and release it. The WPS/WLAN LED should change from on to off or vice versa. 2. Activate WPS (1) Make sure the POWER LED is on (not blinking). (2) Press the WPS WLAN ON/OFF button for 5 to 10 seconds and release it. 106 All contents copyright © 2010 ZyXEL
  • ZyXEL P-660HN-T1A | Support Guide - Page 107
    configuring a filter rule. The format of the display is as following: Packet: [index] [timer/second][channel-receive/transmit][length] [protocol] [sourceIP/port] [destIP/port , you need to telnet to the P-660HN-T1A firstly. The password is Administrator passwords, „admin‟ by default.  Online Trace
  • ZyXEL P-660HN-T1A | Support Guide - Page 108
    P-660HN Series Support Notes (2) Trace WAN packet  Disable the capture of the LAN packet by entering: sys trcp channel enet0 none  Enable to : sys trcd brief  Display the detailed trace online by entering: sys trcd parse Example: 108 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 109
    P-660HN Series Support Notes  Offline Trace  Disable the capture of the WAN packet by entering: sys trcp channel mpoa00 none  Enable : sys trcp brief  Display specific packets by using: sys trcp parse 109 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 110
    P-660HN Series Support Notes  Capture the detailed logs by Hyper Terminal Step 1: Initiate a hyper terminal connection from your PC(suppose you connected to the LAN port of P-660HN-T1A) Step 2: Click the „properties‟ to configure parameters to telnet to the P-660HN-T1A. 110 All contents copyright ©
  • ZyXEL P-660HN-T1A | Support Guide - Page 111
    P-660HN Series Support Notes Step 3: So that after you invoke the relevant commands, you could save the logs you‟ve captured. 111 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 112
    P-660HN Series Support Notes 2. Firmware/Configurations Uploading and Downloading using TFTP  Using TFTP client software  Upload/download firmware/confituration via LAN  Upload/download Prestige configurations via LAN (1) Using TFTP to upload/download firmware/configuration via LAN Step 1: TELNET
  • ZyXEL P-660HN-T1A | Support Guide - Page 113
    TFTP client software Step 4: To download the P-660HN-T1A configuration, please get the remote file 'rom-0' from the Prestige. Step 5: To upload the P-660HN-T1A configuration, please save the remote file as 'rom-0' in the Prestige. An example: 113 All contents copyright © 2010 ZyXEL Communications
  • ZyXEL P-660HN-T1A | Support Guide - Page 114
    P-660HN Series Support Notes  The 192.168.1.1 is the IP address of the Prestige.  The local file is the source file of your configuration file that is available in your hard disk.  The remote file is the file name that will be saved in Prestige.  Check the port number 69 and 512-Octet blocks for
  • ZyXEL P-660HN-T1A | Support Guide - Page 115
    configuration file is 'rom-0'. Step 1 Use FTP client entering the IP from your workstation to address of the Prestige. connect to the Prestige by Press 'Enter' key to ignore the username, because the Prestige does Step2 not check the username. Step 3 Enter the 'admin'. CLI password
  • ZyXEL P-660HN-T1A | Support Guide - Page 116
    'Binary'. P-660HN Series Support Notes Step 2: Press 'OK' to ignore the 'Username' prompt. Step 3: To upload the firmware file, we transfer the local 'ras' file to overwrite the remote 'ras' file. To upload the configuration file, we transfer the local 'rom-0' to overwrite the remote 'rom-0' file.
  • ZyXEL P-660HN-T1A | Support Guide - Page 117
    P-660HN Series Support Notes Step 4: The Prestige reboots automatically after the uploading is finished. Please do not power off the router at this moment. 117 All contents copyright © 2010 ZyXEL Communications Corporation.
  • ZyXEL P-660HN-T1A | Support Guide - Page 118
    exit Exit Subcommand To get the latest CI Command list The latest CI Command list is available in release note of every ZyXEL firmware release. Please goto ZyXEL public WEB site http://www.zyxel.com/support/download_index.php to download firmware package (*.zip), you should unzip the package to get
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

P-660HN Series Support Notes
1
All contents copyright © 2010 ZyXEL Communications Corporation.
P-660HN-T1A
802.11n 1x1 Wireless ADSL2+ 4-port Gateway
Support Notes
Version3.40
Apr. 2010