Section |
Page |
ZyWALL USG 1000 |
1 |
About This User's Guide |
3 |
Document Conventions |
6 |
Safety Warnings |
8 |
Contents Overview |
9 |
Table of Contents |
11 |
User’s Guide |
31 |
Introducing the ZyWALL |
33 |
1.1 Overview and Key Default Settings |
33 |
1.2 Rack-mounted Installation |
33 |
1.2.1 Rack-Mounted Installation Procedure |
34 |
1.3 Front Panel |
35 |
1.3.1 Front Panel LEDs |
35 |
1.4 Management Overview |
35 |
1.5 Starting and Stopping the ZyWALL |
36 |
Features and Applications |
39 |
2.1 Features |
39 |
2.2 Applications |
41 |
2.2.1 VPN Connectivity |
42 |
2.2.2 SSL VPN Network Access |
42 |
2.2.3 User-Aware Access Control |
44 |
2.2.4 Multiple WAN Interfaces |
44 |
2.2.5 Device HA |
45 |
Web Configurator |
47 |
3.1 Web Configurator Requirements |
47 |
3.2 Web Configurator Access |
47 |
3.3 Web Configurator Screens Overview |
49 |
3.3.1 Title Bar |
50 |
3.3.2 Navigation Panel |
50 |
3.3.3 Main Window |
56 |
3.3.4 Tables and Lists |
59 |
Installation Setup Wizard |
63 |
4.1 Installation Setup Wizard Screens |
63 |
4.1.1 Internet Access Setup - WAN Interface |
64 |
4.1.2 Internet Access: Ethernet |
64 |
4.1.3 Internet Access: PPPoE |
66 |
4.1.4 Internet Access: PPTP |
67 |
4.1.5 ISP Parameters |
67 |
4.1.6 Internet Access Setup - Second WAN Interface |
69 |
4.1.7 Internet Access - Finish |
69 |
4.2 Device Registration |
70 |
Quick Setup |
73 |
5.1 Quick Setup Overview |
73 |
5.2 WAN Interface Quick Setup |
74 |
5.2.1 Choose an Ethernet Interface |
74 |
5.2.2 Select WAN Type |
74 |
5.2.3 Configure WAN Settings |
75 |
5.2.4 WAN and ISP Connection Settings |
76 |
5.2.5 Quick Setup Interface Wizard: Summary |
78 |
5.3 VPN Quick Setup |
79 |
5.4 VPN Setup Wizard: Wizard Type |
80 |
5.5 VPN Express Wizard - Scenario |
81 |
5.5.1 VPN Express Wizard - Configuration |
82 |
5.5.2 VPN Express Wizard - Summary |
83 |
5.5.3 VPN Express Wizard - Finish |
84 |
5.5.4 VPN Advanced Wizard - Scenario |
85 |
5.5.5 VPN Advanced Wizard - Phase 1 Settings |
86 |
5.5.6 VPN Advanced Wizard - Phase 2 |
88 |
5.5.7 VPN Advanced Wizard - Summary |
89 |
5.5.8 VPN Advanced Wizard - Finish |
90 |
Configuration Basics |
91 |
6.1 Object-based Configuration |
91 |
6.2 Zones, Interfaces, and Physical Ports |
92 |
6.2.1 Interface Types |
93 |
6.2.2 Default Interface and Zone Configuration |
94 |
6.3 Terminology in the ZyWALL |
95 |
6.4 Packet Flow |
96 |
6.4.1 ZLD 2.20 Packet Flow Enhancements |
96 |
6.4.2 Routing Table Checking Flow Enhancements |
97 |
6.4.3 NAT Table Checking Flow |
98 |
6.5 Feature Configuration Overview |
99 |
6.5.1 Feature |
100 |
6.5.2 Licensing Registration |
100 |
6.5.3 Licensing Update |
100 |
6.5.4 Interface |
101 |
6.5.5 Trunks |
101 |
6.5.6 Policy Routes |
101 |
6.5.7 Static Routes |
102 |
6.5.8 Zones |
103 |
6.5.9 DDNS |
103 |
6.5.10 NAT |
103 |
6.5.11 HTTP Redirect |
104 |
6.5.12 ALG |
105 |
6.5.13 Auth. Policy |
105 |
6.5.14 Firewall |
105 |
6.5.15 IPSec VPN |
106 |
6.5.16 SSL VPN |
106 |
6.5.17 L2TP VPN |
107 |
6.5.18 Application Patrol |
107 |
6.5.19 Anti-Virus |
108 |
6.5.20 IDP |
108 |
6.5.21 ADP |
108 |
6.5.22 Content Filter |
108 |
6.5.23 Anti-Spam |
109 |
6.5.24 Device HA |
109 |
6.6 Objects |
110 |
6.6.1 User/Group |
110 |
6.7 System |
111 |
6.7.1 DNS, WWW, SSH, TELNET, FTP, SNMP, Dial-in Mgmt, Vantage CNM |
111 |
6.7.2 Logs and Reports |
112 |
6.7.3 File Manager |
112 |
6.7.4 Diagnostics |
112 |
6.7.5 Shutdown |
112 |
Tutorials |
115 |
7.1 How to Configure Interfaces, Port Grouping, and Zones |
115 |
7.1.1 Configure a WAN Ethernet Interface |
116 |
7.1.2 Configure Zones |
116 |
7.1.3 Configure Port Grouping |
117 |
7.2 How to Configure a Cellular Interface |
118 |
7.3 How to Configure Load Balancing |
120 |
7.3.1 Set Up Available Bandwidth on Ethernet Interfaces |
120 |
7.3.2 Configure the WAN Trunk |
121 |
7.4 How to Set Up an IPSec VPN Tunnel |
123 |
7.4.1 Set Up the VPN Gateway |
124 |
7.4.2 Set Up the VPN Connection |
125 |
7.4.3 Configure Security Policies for the VPN Tunnel |
126 |
7.5 How to Configure a Hub-and-spoke IPSec VPN Without a VPN Concentrator |
127 |
7.6 How to Configure User-aware Access Control |
129 |
7.6.1 Set Up User Accounts |
130 |
7.6.2 Set Up User Groups |
130 |
7.6.3 Set Up User Authentication Using the RADIUS Server |
131 |
7.6.4 Web Surfing Policies With Bandwidth Restrictions |
133 |
7.6.5 Set Up MSN Policies |
136 |
7.6.6 Set Up Firewall Rules |
137 |
7.7 How to Use a RADIUS Server to Authenticate User Accounts based on Groups |
138 |
7.8 How to Use Endpoint Security and Authentication Policies |
140 |
7.8.1 Configure the Endpoint Security Objects |
140 |
7.8.2 Configure the Authentication Policy |
142 |
7.9 How to Configure Service Control |
143 |
7.9.1 Allow HTTPS Administrator Access Only From the LAN |
144 |
7.10 How to Allow Incoming H.323 Peer-to-peer Calls |
146 |
7.10.1 Turn On the ALG |
147 |
7.10.2 Set Up a NAT Policy For H.323 |
147 |
7.10.3 Set Up a Firewall Rule For H.323 |
149 |
7.11 How to Allow Public Access to a Web Server |
150 |
7.11.1 Create the Address Objects |
151 |
7.11.2 Configure NAT |
151 |
7.11.3 Set Up a Firewall Rule |
152 |
7.12 How to Use an IPPBX on the DMZ |
153 |
7.12.1 Turn On the ALG |
155 |
7.12.2 Create the Address Objects |
155 |
7.12.3 Setup a NAT Policy for the IPPBX |
156 |
7.12.4 Set Up a WAN to DMZ Firewall Rule for SIP |
157 |
7.12.5 Set Up a DMZ to LAN Firewall Rule for SIP |
158 |
7.13 How to Use Multiple Static Public WAN IP Addresses for LAN to WAN Traffic |
159 |
7.13.1 Create the Public IP Address Range Object |
159 |
7.13.2 Configure the Policy Route |
160 |
7.14 How to Use Active-Passive Device HA |
160 |
7.14.1 Before You Start |
161 |
7.14.2 Configure Device HA on the Master ZyWALL |
162 |
7.14.3 Configure the Backup ZyWALL |
163 |
7.14.4 Deploy the Backup ZyWALL |
164 |
7.14.5 Check Your Device HA Setup |
165 |
L2TP VPN Example |
167 |
8.1 L2TP VPN Example |
167 |
8.2 Configuring the Default L2TP VPN Gateway Example |
167 |
8.3 Configuring the Default L2TP VPN Connection Example |
169 |
8.4 Configuring the L2TP VPN Settings Example |
170 |
8.5 Configuring L2TP VPN in Windows Vista, XP, or 2000 |
171 |
8.5.1 Configuring L2TP in Windows Vista |
171 |
8.5.2 Configuring L2TP in Windows XP |
181 |
8.5.3 Configuring L2TP in Windows 2000 |
187 |
Technical Reference |
203 |
Dashboard |
205 |
9.1 Overview |
205 |
9.1.1 What You Can Do in this Chapter |
205 |
9.2 The Dashboard Screen |
205 |
9.2.1 The CPU Usage Screen |
212 |
9.2.2 The Memory Usage Screen |
213 |
9.2.3 The Session Usage Screen |
214 |
9.2.4 The VPN Status Screen |
215 |
9.2.5 The DHCP Table Screen |
215 |
9.2.6 The Number of Login Users Screen |
216 |
Monitor |
219 |
10.1 Overview |
219 |
10.1.1 What You Can Do in this Chapter |
219 |
10.2 The Port Statistics Screen |
220 |
10.2.1 The Port Statistics Graph Screen |
222 |
10.3 Interface Status Screen |
223 |
10.4 The Traffic Statistics Screen |
226 |
10.5 The Session Monitor Screen |
229 |
10.6 The DDNS Status Screen |
231 |
10.7 IP/MAC Binding Monitor |
232 |
10.8 The Login Users Screen |
233 |
10.9 Cellular Status Screen |
234 |
10.10 Application Patrol Statistics |
236 |
10.10.1 Application Patrol Statistics: General Setup |
236 |
10.10.2 Application Patrol Statistics: Bandwidth Statistics |
237 |
10.10.3 Application Patrol Statistics: Protocol Statistics |
238 |
10.10.4 Application Patrol Statistics: Individual Protocol Statistics by Rule |
239 |
10.11 The IPSec Monitor Screen |
240 |
10.11.1 Regular Expressions in Searching IPSec SAs |
242 |
10.12 The SSL Connection Monitor Screen |
243 |
10.13 L2TP over IPSec Session Monitor Screen |
244 |
10.14 The Anti-Virus Statistics Screen |
245 |
10.15 The IDP Statistics Screen |
247 |
10.16 The Content Filter Statistics Screen |
249 |
10.17 Content Filter Cache Screen |
250 |
10.18 The Anti-Spam Statistics Screen |
253 |
10.19 The Anti-Spam Status Screen |
255 |
10.20 Log Screen |
256 |
Registration |
259 |
11.1 Overview |
259 |
11.1.1 What You Can Do in this Chapter |
259 |
11.1.2 What you Need to Know |
259 |
11.2 The Registration Screen |
261 |
11.3 The Service Screen |
263 |
Signature Update |
265 |
12.1 Overview |
265 |
12.1.1 What You Can Do in this Chapter |
265 |
12.1.2 What you Need to Know |
265 |
12.2 The Antivirus Update Screen |
266 |
12.3 The IDP/AppPatrol Update Screen |
267 |
12.4 The System Protect Update Screen |
269 |
Interfaces |
271 |
13.1 Interface Overview |
271 |
13.1.1 What You Can Do in this Chapter |
271 |
13.1.2 What You Need to Know |
272 |
13.2 Port Grouping |
274 |
13.2.1 Port Grouping Overview |
275 |
13.2.2 Port Grouping Screen |
275 |
13.3 Ethernet Summary Screen |
276 |
13.3.1 Ethernet Edit |
278 |
13.3.2 Object References |
285 |
13.4 PPP Interfaces |
286 |
13.4.1 PPP Interface Summary |
287 |
13.4.2 PPP Interface Add or Edit |
289 |
13.5 Cellular Configuration Screen (3G) |
293 |
13.5.1 Cellular Add/Edit Screen |
295 |
13.6 VLAN Interfaces |
302 |
13.6.1 VLAN Summary Screen |
304 |
13.6.2 VLAN Add/Edit |
305 |
13.7 Bridge Interfaces |
312 |
13.7.1 Bridge Summary |
314 |
13.7.2 Bridge Add/Edit |
315 |
13.8 Auxiliary Interface |
321 |
13.8.1 Auxiliary Interface Overview |
321 |
13.8.2 Auxiliary |
321 |
13.9 Virtual Interfaces |
323 |
13.9.1 Virtual Interfaces Add/Edit |
324 |
13.10 Interface Technical Reference |
325 |
Trunks |
331 |
14.1 Overview |
331 |
14.1.1 What You Can Do in this Chapter |
331 |
14.1.2 What You Need to Know |
332 |
14.2 The Trunk Summary Screen |
336 |
14.3 Configuring a Trunk |
337 |
14.4 Trunk Technical Reference |
339 |
Policy and Static Routes |
341 |
15.1 Policy and Static Routes Overview |
341 |
15.1.1 What You Can Do in this Chapter |
341 |
15.1.2 What You Need to Know |
342 |
15.2 Policy Route Screen |
344 |
15.2.1 Policy Route Edit Screen |
347 |
15.3 IP Static Route Screen |
351 |
15.3.1 Static Route Add/Edit Screen |
352 |
15.4 Policy Routing Technical Reference |
353 |
Routing Protocols |
357 |
16.1 Routing Protocols Overview |
357 |
16.1.1 What You Can Do in this Chapter |
357 |
16.1.2 What You Need to Know |
357 |
16.2 The RIP Screen |
358 |
16.3 The OSPF Screen |
359 |
16.3.1 Configuring the OSPF Screen |
363 |
16.3.2 OSPF Area Add/Edit Screen |
366 |
16.3.3 Virtual Link Add/Edit Screen |
367 |
16.4 Routing Protocol Technical Reference |
368 |
Zones |
371 |
17.1 Zones Overview |
371 |
17.1.1 What You Can Do in this Chapter |
371 |
17.1.2 What You Need to Know |
372 |
17.2 The Zone Screen |
373 |
17.3 Zone Edit |
374 |
DDNS |
375 |
18.1 DDNS Overview |
375 |
18.1.1 What You Can Do in this Chapter |
375 |
18.1.2 What You Need to Know |
375 |
18.2 The DDNS Screen |
376 |
18.2.1 The Dynamic DNS Add/Edit Screen |
378 |
NAT |
381 |
19.1 NAT Overview |
381 |
19.1.1 What You Can Do in this Chapter |
381 |
19.1.2 What You Need to Know |
382 |
19.2 The NAT Screen |
382 |
19.2.1 The NAT Add/Edit Screen |
384 |
19.3 NAT Technical Reference |
387 |
HTTP Redirect |
391 |
20.1 Overview |
391 |
20.1.1 What You Can Do in this Chapter |
391 |
20.1.2 What You Need to Know |
392 |
20.2 The HTTP Redirect Screen |
393 |
20.2.1 The HTTP Redirect Edit Screen |
394 |
ALG |
395 |
21.1 ALG Overview |
395 |
21.1.1 What You Can Do in this Chapter |
395 |
21.1.2 What You Need to Know |
396 |
21.1.3 Before You Begin |
399 |
21.2 The ALG Screen |
399 |
21.3 ALG Technical Reference |
401 |
IP/MAC Binding |
403 |
22.1 IP/MAC Binding Overview |
403 |
22.1.1 What You Can Do in this Chapter |
403 |
22.1.2 What You Need to Know |
404 |
22.2 IP/MAC Binding Summary |
404 |
22.2.1 IP/MAC Binding Edit |
405 |
22.2.2 Static DHCP Edit |
406 |
22.3 IP/MAC Binding Exempt List |
407 |
Authentication Policy |
409 |
23.1 Overview |
409 |
23.1.1 What You Can Do in this Chapter |
409 |
23.1.2 What You Need to Know |
410 |
23.2 Authentication Policy Screen |
410 |
23.2.1 Creating/Editing an Authentication Policy |
413 |
Firewall |
417 |
24.1 Overview |
417 |
24.1.1 What You Can Do in this Chapter |
417 |
24.1.2 What You Need to Know |
418 |
24.1.3 Firewall Rule Example Applications |
420 |
24.1.4 Firewall Rule Configuration Example |
423 |
24.2 The Firewall Screen |
425 |
24.2.1 Configuring the Firewall Screen |
426 |
24.2.2 The Firewall Add/Edit Screen |
429 |
24.3 The Session Limit Screen |
430 |
24.3.1 The Session Limit Add/Edit Screen |
432 |
IPSec VPN |
435 |
25.1 IPSec VPN Overview |
435 |
25.1.1 What You Can Do in this Chapter |
435 |
25.1.2 What You Need to Know |
436 |
25.1.3 Before You Begin |
438 |
25.2 The VPN Connection Screen |
438 |
25.2.1 The VPN Connection Add/Edit (IKE) Screen |
440 |
25.2.2 The VPN Connection Add/Edit Manual Key Screen |
447 |
25.3 The VPN Gateway Screen |
450 |
25.3.1 The VPN Gateway Add/Edit Screen |
451 |
25.4 VPN Concentrator |
459 |
25.4.1 IPSec VPN Concentrator Example |
459 |
25.4.2 VPN Concentrator Screen |
462 |
25.4.3 The VPN Concentrator Add/Edit Screen |
462 |
25.5 IPSec VPN Background Information |
463 |
SSL VPN |
475 |
26.1 Overview |
475 |
26.1.1 What You Can Do in this Chapter |
475 |
26.1.2 What You Need to Know |
475 |
26.2 The SSL Access Privilege Screen |
478 |
26.2.1 The SSL Access Policy Add/Edit Screen |
480 |
26.3 The SSL Global Setting Screen |
482 |
26.3.1 How to Upload a Custom Logo |
484 |
26.4 Establishing an SSL VPN Connection |
485 |
SSL User Screens |
487 |
27.1 Overview |
487 |
27.1.1 What You Need to Know |
487 |
27.2 Remote User Login |
488 |
27.3 The SSL VPN User Screens |
493 |
27.4 Bookmarking the ZyWALL |
494 |
27.5 Logging Out of the SSL VPN User Screens |
494 |
SSL User Application Screens |
497 |
28.1 SSL User Application Screens Overview |
497 |
28.2 The Application Screen |
497 |
SSL User File Sharing |
499 |
29.1 Overview |
499 |
29.1.1 What You Need to Know |
499 |
29.2 The Main File Sharing Screen |
500 |
29.3 Opening a File or Folder |
500 |
29.3.1 Downloading a File |
502 |
29.3.2 Saving a File |
503 |
29.4 Creating a New Folder |
503 |
29.5 Renaming a File or Folder |
504 |
29.6 Deleting a File or Folder |
504 |
29.7 Uploading a File |
505 |
ZyWALL SecuExtender |
507 |
30.1 The ZyWALL SecuExtender Icon |
507 |
30.2 Statistics |
508 |
30.3 View Log |
509 |
30.4 Suspend and Resume the Connection |
509 |
30.5 Stop the Connection |
510 |
30.6 Uninstalling the ZyWALL SecuExtender |
510 |
L2TP VPN |
511 |
31.1 Overview |
511 |
31.1.1 What You Can Do in this Chapter |
511 |
31.1.2 What You Need to Know |
511 |
31.2 L2TP VPN Screen |
513 |
Application Patrol |
515 |
32.1 Overview |
515 |
32.1.1 What You Can Do in this Chapter |
515 |
32.1.2 What You Need to Know |
516 |
32.1.3 Application Patrol Bandwidth Management Examples |
521 |
32.2 Application Patrol General Screen |
525 |
32.3 Application Patrol Applications |
526 |
32.3.1 The Application Patrol Edit Screen |
527 |
32.3.2 The Application Patrol Policy Edit Screen |
531 |
32.4 The Other Applications Screen |
534 |
32.4.1 The Other Applications Add/Edit Screen |
537 |
Anti-Virus |
541 |
33.1 Overview |
541 |
33.1.1 What You Can Do in this Chapter |
541 |
33.1.2 What You Need to Know |
542 |
33.1.3 Before You Begin |
544 |
33.2 Anti-Virus Summary Screen |
544 |
33.2.1 Anti-Virus Policy Add or Edit Screen |
547 |
33.3 Anti-Virus Black List |
549 |
33.4 Anti-Virus Black List or White List Add/Edit |
550 |
33.5 Anti-Virus White List |
551 |
33.6 Signature Searching |
552 |
33.7 Anti-Virus Technical Reference |
555 |
IDP |
557 |
34.1 Overview |
557 |
34.1.1 What You Can Do in this Chapter |
557 |
34.1.2 What You Need To Know |
557 |
34.1.3 Before You Begin |
558 |
34.2 The IDP General Screen |
559 |
34.3 Introducing IDP Profiles |
561 |
34.3.1 Base Profiles |
562 |
34.4 The Profile Summary Screen |
563 |
34.5 Creating New Profiles |
564 |
34.5.1 Procedure To Create a New Profile |
564 |
34.6 Profiles: Packet Inspection |
565 |
34.6.1 Profile > Group View Screen |
565 |
34.6.2 Policy Types |
568 |
34.6.3 IDP Service Groups |
569 |
34.6.4 Profile > Query View Screen |
570 |
34.6.5 Query Example |
573 |
34.7 Introducing IDP Custom Signatures |
575 |
34.7.1 IP Packet Header |
575 |
34.8 Configuring Custom Signatures |
576 |
34.8.1 Creating or Editing a Custom Signature |
578 |
34.8.2 Custom Signature Example |
584 |
34.8.3 Applying Custom Signatures |
586 |
34.8.4 Verifying Custom Signatures |
587 |
34.9 IDP Technical Reference |
588 |
ADP |
591 |
35.1 Overview |
591 |
35.1.1 ADP and IDP Comparison |
591 |
35.1.2 What You Can Do in this Chapter |
591 |
35.1.3 What You Need To Know |
591 |
35.1.4 Before You Begin |
592 |
35.2 The ADP General Screen |
593 |
35.3 The Profile Summary Screen |
594 |
35.3.1 Base Profiles |
595 |
35.3.2 Configuring The ADP Profile Summary Screen |
595 |
35.3.3 Creating New ADP Profiles |
596 |
35.3.4 Traffic Anomaly Profiles |
596 |
35.3.5 Protocol Anomaly Profiles |
599 |
35.3.6 Protocol Anomaly Configuration |
599 |
35.4 ADP Technical Reference |
603 |
Content Filtering |
613 |
36.1 Overview |
613 |
36.1.1 What You Can Do in this Chapter |
613 |
36.1.2 What You Need to Know |
613 |
36.1.3 Before You Begin |
615 |
36.2 Content Filter General Screen |
615 |
36.3 Content Filter Policy Add or Edit Screen |
618 |
36.4 Content Filter Profile Screen |
620 |
36.5 Content Filter Categories Screen |
620 |
36.5.1 Content Filter Blocked and Warning Messages |
632 |
36.6 Content Filter Customization Screen |
633 |
36.7 Content Filter Technical Reference |
635 |
Content Filter Reports |
637 |
37.1 Overview |
637 |
37.2 Viewing Content Filter Reports |
637 |
Anti-Spam |
645 |
38.1 Overview |
645 |
38.1.1 What You Can Do in this Chapter |
645 |
38.1.2 What You Need to Know |
645 |
38.2 Before You Begin |
647 |
38.3 The Anti-Spam General Screen |
647 |
38.3.1 The Anti-Spam Policy Add or Edit Screen |
649 |
38.4 The Anti-Spam Black List Screen |
651 |
38.4.1 The Anti-Spam Black or White List Add/Edit Screen |
653 |
38.4.2 Regular Expressions in Black or White List Entries |
654 |
38.5 The Anti-Spam White List Screen |
655 |
38.6 The DNSBL Screen |
656 |
38.7 Anti-Spam Technical Reference |
658 |
Device HA |
663 |
39.1 Overview |
663 |
39.1.1 What You Can Do in this Chapter |
663 |
39.1.2 What You Need to Know |
663 |
39.1.3 Before You Begin |
664 |
39.2 Device HA General |
665 |
39.3 The Active-Passive Mode Screen |
666 |
39.3.1 Configuring Active-Passive Mode Device HA |
668 |
39.4 Configuring an Active-Passive Mode Monitored Interface |
671 |
39.5 The Legacy Mode Screen |
673 |
39.6 Configuring the Legacy Mode Screen |
674 |
39.7 Device HA Technical Reference |
678 |
User/Group |
685 |
40.1 Overview |
685 |
40.1.1 What You Can Do in this Chapter |
685 |
40.1.2 What You Need To Know |
685 |
40.2 User Summary Screen |
688 |
40.2.1 User Add/Edit Screen |
688 |
40.3 User Group Summary Screen |
691 |
40.3.1 Group Add/Edit Screen |
692 |
40.4 Setting Screen |
693 |
40.4.1 Default User Authentication Timeout Settings Edit Screens |
696 |
40.4.2 User Aware Login Example |
698 |
40.5 User /Group Technical Reference |
699 |
Addresses |
701 |
41.1 Overview |
701 |
41.1.1 What You Can Do in this Chapter |
701 |
41.1.2 What You Need To Know |
701 |
41.2 Address Summary Screen |
701 |
41.2.1 Address Add/Edit Screen |
703 |
41.3 Address Group Summary Screen |
704 |
41.3.1 Address Group Add/Edit Screen |
705 |
Services |
707 |
42.1 Overview |
707 |
42.1.1 What You Can Do in this Chapter |
707 |
42.1.2 What You Need to Know |
707 |
42.2 The Service Summary Screen |
708 |
42.2.1 The Service Add/Edit Screen |
710 |
42.3 The Service Group Summary Screen |
710 |
42.3.1 The Service Group Add/Edit Screen |
712 |
Schedules |
713 |
43.1 Overview |
713 |
43.1.1 What You Can Do in this Chapter |
713 |
43.1.2 What You Need to Know |
713 |
43.2 The Schedule Summary Screen |
714 |
43.2.1 The One-Time Schedule Add/Edit Screen |
715 |
43.2.2 The Recurring Schedule Add/Edit Screen |
716 |
AAA Server |
719 |
44.1 Overview |
719 |
44.1.1 Directory Service (AD/LDAP) |
719 |
44.1.2 RADIUS Server |
720 |
44.1.3 ASAS |
720 |
44.1.4 What You Can Do in this Chapter |
720 |
44.1.5 What You Need To Know |
721 |
44.2 Active Directory or LDAP Server Summary |
723 |
44.2.1 Adding an Active Directory or LDAP Server |
723 |
44.3 RADIUS Server Summary |
725 |
44.3.1 Adding a RADIUS Server |
727 |
Authentication Method |
729 |
45.1 Overview |
729 |
45.1.1 What You Can Do in this Chapter |
729 |
45.1.2 Before You Begin |
729 |
45.1.3 Example: Selecting a VPN Authentication Method |
729 |
45.2 Authentication Method Objects |
730 |
45.2.1 Creating an Authentication Method Object |
731 |
Certificates |
735 |
46.1 Overview |
735 |
46.1.1 What You Can Do in this Chapter |
735 |
46.1.2 What You Need to Know |
735 |
46.1.3 Verifying a Certificate |
737 |
46.2 The My Certificates Screen |
739 |
46.2.1 The My Certificates Add Screen |
740 |
46.2.2 The My Certificates Edit Screen |
745 |
46.2.3 The My Certificates Import Screen |
748 |
46.3 The Trusted Certificates Screen |
749 |
46.3.1 The Trusted Certificates Edit Screen |
750 |
46.3.2 The Trusted Certificates Import Screen |
754 |
46.4 Certificates Technical Reference |
755 |
ISP Accounts |
757 |
47.1 Overview |
757 |
47.1.1 What You Can Do in this Chapter |
757 |
47.2 ISP Account Summary |
757 |
47.2.1 ISP Account Edit |
758 |
SSL Application |
761 |
48.1 Overview |
761 |
48.1.1 What You Can Do in this Chapter |
761 |
48.1.2 What You Need to Know |
761 |
48.1.3 Example: Specifying a Web Site for Access |
762 |
48.2 The SSL Application Screen |
763 |
48.2.1 Creating/Editing a Web-based SSL Application Object |
764 |
48.2.2 Creating/Editing a File Sharing SSL Application Object |
766 |
Endpoint Security |
769 |
49.1 Overview |
769 |
49.1.1 What You Can Do in this Chapter |
770 |
49.1.2 What You Need to Know |
770 |
49.2 Endpoint Security Screen |
771 |
49.3 Endpoint Security Add/Edit |
773 |
System |
779 |
50.1 Overview |
779 |
50.1.1 What You Can Do in this Chapter |
779 |
50.2 Host Name |
780 |
50.3 Date and Time |
781 |
50.3.1 Pre-defined NTP Time Servers List |
783 |
50.3.2 Time Server Synchronization |
784 |
50.4 Console Port Speed |
785 |
50.5 DNS Overview |
785 |
50.5.1 DNS Server Address Assignment |
786 |
50.5.2 Configuring the DNS Screen |
786 |
50.5.3 Address Record |
789 |
50.5.4 PTR Record |
789 |
50.5.5 Adding an Address/PTR Record |
789 |
50.5.6 Domain Zone Forwarder |
790 |
50.5.7 Adding a Domain Zone Forwarder |
790 |
50.5.8 MX Record |
791 |
50.5.9 Adding a MX Record |
792 |
50.5.10 Adding a DNS Service Control Rule |
792 |
50.6 WWW Overview |
793 |
50.6.1 Service Access Limitations |
794 |
50.6.2 System Timeout |
794 |
50.6.3 HTTPS |
794 |
50.6.4 Configuring WWW Service Control |
795 |
50.6.5 Service Control Rules |
799 |
50.6.6 Customizing the WWW Login Page |
799 |
50.6.7 HTTPS Example |
803 |
50.7 SSH |
810 |
50.7.1 How SSH Works |
811 |
50.7.2 SSH Implementation on the ZyWALL |
812 |
50.7.3 Requirements for Using SSH |
812 |
50.7.4 Configuring SSH |
812 |
50.7.5 Secure Telnet Using SSH Examples |
814 |
50.8 Telnet |
815 |
50.8.1 Configuring Telnet |
816 |
50.9 FTP |
817 |
50.9.1 Configuring FTP |
817 |
50.10 SNMP |
819 |
50.10.1 Supported MIBs |
821 |
50.10.2 SNMP Traps |
821 |
50.10.3 Configuring SNMP |
821 |
50.11 Dial-in Management |
823 |
50.11.1 Configuring Dial-in Mgmt |
824 |
50.12 Vantage CNM |
825 |
50.12.1 Configuring Vantage CNM |
826 |
50.13 Language Screen |
828 |
Log and Report |
829 |
51.1 Overview |
829 |
51.1.1 What You Can Do In this Chapter |
829 |
51.2 Email Daily Report |
829 |
51.3 Log Setting Screens |
831 |
51.3.1 Log Setting Summary |
832 |
51.3.2 Edit System Log Settings |
833 |
51.3.3 Edit Remote Server Log Settings |
838 |
51.3.4 Active Log Summary Screen |
840 |
File Manager |
843 |
52.1 Overview |
843 |
52.1.1 What You Can Do in this Chapter |
843 |
52.1.2 What you Need to Know |
843 |
52.2 The Configuration File Screen |
846 |
52.3 The Firmware Package Screen |
850 |
52.4 The Shell Script Screen |
852 |
Diagnostics |
855 |
53.1 Overview |
855 |
53.1.1 What You Can Do in this Chapter |
855 |
53.2 The Diagnostic Screen |
855 |
53.3 The Packet Capture Screen |
856 |
53.3.1 The Packet Capture Files Screen |
858 |
53.3.2 Example of Viewing a Packet Capture File |
859 |
Reboot |
861 |
54.1 Overview |
861 |
54.1.1 What You Need To Know |
861 |
54.2 The Reboot Screen |
861 |
Shutdown |
863 |
55.1 Overview |
863 |
55.1.1 What You Need To Know |
863 |
55.2 The Shutdown Screen |
863 |
Troubleshooting |
865 |
56.1 Resetting the ZyWALL |
882 |
56.2 Getting More Troubleshooting Help |
883 |
Product Specifications |
885 |
57.1 3G PCMCIA Card Installation |
891 |
Log Descriptions |
893 |
Common Services |
953 |
Displaying Anti-Virus Alert Messages in Windows |
957 |
Importing Certificates |
963 |
Open Software Announcements |
989 |
Legal Information |
1045 |