ZyXEL P-663HN-51 User Guide - Page 63

Advanced Setup > WAN > Add 3: PPPoA continued, Table 15 - firewall

Page 63 highlights

Chapter 5 WAN Setup Table 15 Advanced Setup > WAN > Add (3: PPPoA) (continued) LABEL DESCRIPTION Authentication Method The ZyXEL Device supports PAP (Password Authentication Protocol) and CHAP (Challenge Handshake Authentication Protocol). CHAP is more secure than PAP; however, PAP is readily available on more platforms. Use the drop-down list box to select an authentication protocol for outgoing calls. Options are: AUTO - Your ZyXEL Device accepts either CHAP, PAP, or MSCHAP when requested by this remote node. CHAP - Your ZyXEL Device accepts CHAP only. PAP - Your ZyXEL Device accepts PAP only. Enable NAT Enable Fullcone NAT MSCHAP - Your ZyXEL Device accepts MSCHAP (Microsoft CHAP) only. Turn on NAT to translate IP addresses between two different networks (so you can have a private LAN with IP addresses that are different from the public IP addresses on the WAN. See Chapter 7 on page 83 for more details. This field displays when you enable NAT. In full cone NAT, all requests from the same private IP address and port are mapped to the same public source IP address and port. Someone on the Internet only needs to know the mapping scheme in order to send packets to a device behind the ZyXEL Device. Enable Firewall Dial on demand The ZyXEL Device uses restricted cone NAT when you disable full cone NAT. Select this to turn on the ZyXEL Device's Stateful Packet Inspection (SPI) firewall. By default the firewall blocks traffic originating from the WAN from going to the LAN. See Chapter 8 on page 93 for how to configure firewall rules. Select Dial on demand when you don't want the connection up all the time and specify an idle time-out (in seconds) in the Inactivity Timeout field. PPP IP extension Clear the Dial on demand option to keep the connection up all the time. The ZyXEL Device will try to bring up the connection automatically if it is disconnected. Only select this option if your service provider requires it. The following conditions apply to a connection using PPP IP extension. • Only one computer can be connected on the LAN. • The ISP only assigns a single public IP address and the LAN computer uses it on its LAN interface. • The firewall and NAT features are disabled. • The ZyXEL Device uses DHCP to tell the LAN computer that the ZyXEL Device is its default gateway and DNS server. • The ZyXEL Device extends the ISP's IP subnet to the LAN computer. • The ZyXEL Device bridges packets between the DSL and LAN interface, except for packets destined for the ZyXEL Device's LAN IP address. P-663HN-51 User's Guide 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300

Chapter 5 WAN Setup
P-663HN-51 User’s Guide
63
Authentication
Method
The ZyXEL Device supports PAP (Password Authentication Protocol)
and CHAP (Challenge Handshake Authentication Protocol). CHAP is
more secure than PAP; however, PAP is readily available on more
platforms.
Use the drop-down list box to select an authentication protocol for
outgoing calls. Options are:
AUTO
- Your ZyXEL Device accepts either CHAP, PAP, or MSCHAP
when requested by this remote node.
CHAP
- Your ZyXEL Device accepts CHAP only.
PAP
- Your ZyXEL Device accepts PAP only.
MSCHAP
- Your ZyXEL Device accepts MSCHAP (Microsoft CHAP)
only.
Enable NAT
Turn on NAT to translate IP addresses between two different networks
(so you can have a private LAN with IP addresses that are different
from the public IP addresses on the WAN. See
Chapter 7 on page 83
for more details.
Enable Fullcone
NAT
This field displays when you enable NAT. In full cone NAT, all requests
from the same private IP address and port are mapped to the same
public source IP address and port. Someone on the Internet only
needs to know the mapping scheme in order to send packets to a
device behind the ZyXEL Device.
The ZyXEL Device uses restricted cone NAT when you disable full cone
NAT.
Enable Firewall
Select this to turn on the ZyXEL Device’s Stateful Packet Inspection
(SPI) firewall. By default the firewall blocks traffic originating from the
WAN from going to the LAN. See
Chapter 8 on page 93
for how to
configure firewall rules.
Dial on demand
Select
Dial on demand
when you don't want the connection up all
the time and specify an idle time-out (in seconds) in the
Inactivity
Timeout
field.
Clear the
Dial on demand
option
to keep the connection up all the
time. The ZyXEL Device will try to bring up the connection
automatically if it is disconnected.
PPP IP extension
Only select this option if your service provider requires it. The
following conditions apply to a connection using PPP IP extension.
Only one computer can be connected on the LAN.
The ISP only assigns a single public IP address and the LAN
computer uses it on its LAN interface.
The firewall and NAT features are disabled.
The ZyXEL Device uses DHCP to tell the LAN computer that the
ZyXEL Device is its default gateway and DNS server.
The ZyXEL Device extends the ISP’s IP subnet to the LAN
computer.
The ZyXEL Device bridges packets between the DSL and LAN
interface, except for packets destined for the ZyXEL Device's LAN
IP address.
Table 15
Advanced Setup > WAN > Add (3: PPPoA) (continued)
LABEL
DESCRIPTION