Section |
Page |
ZyWALL USG 2000 |
1 |
About This User's Guide |
3 |
Document Conventions |
6 |
Safety Warnings |
8 |
Contents Overview |
9 |
Table of Contents |
11 |
User’s Guide |
31 |
Introducing the ZyWALL |
33 |
1.1 Overview and Key Default Settings |
33 |
1.2 Rack-mounted Installation |
33 |
1.2.1 Rack-Mounted Installation Procedure |
34 |
1.3 Front Panel |
35 |
1.3.1 Dual Personality Interfaces |
35 |
1.3.2 Maximizing Throughput |
39 |
1.3.3 Front Panel LEDs |
39 |
1.4 Management Overview |
40 |
1.5 Starting and Stopping the ZyWALL |
41 |
Features and Applications |
43 |
2.1 Features |
43 |
2.2 Applications |
45 |
2.2.1 VPN Connectivity |
46 |
2.2.2 SSL VPN Network Access |
46 |
2.2.3 User-Aware Access Control |
48 |
2.2.4 Multiple WAN Interfaces |
48 |
2.2.5 Device HA |
49 |
Web Configurator |
51 |
3.1 Web Configurator Requirements |
51 |
3.2 Web Configurator Access |
51 |
3.3 Web Configurator Screens Overview |
53 |
3.3.1 Title Bar |
54 |
3.3.2 Navigation Panel |
54 |
3.3.3 Main Window |
60 |
3.3.4 Tables and Lists |
63 |
Installation Setup Wizard |
67 |
4.1 Installation Setup Wizard Screens |
67 |
4.1.1 Internet Access Setup - WAN Interface |
68 |
4.1.2 Internet Access: Ethernet |
68 |
4.1.3 Internet Access: PPPoE |
70 |
4.1.4 Internet Access: PPTP |
71 |
4.1.5 ISP Parameters |
71 |
4.1.6 Internet Access Setup - Second WAN Interface |
73 |
4.1.7 Internet Access - Finish |
73 |
4.2 Device Registration |
74 |
Quick Setup |
77 |
5.1 Quick Setup Overview |
77 |
5.2 WAN Interface Quick Setup |
78 |
5.2.1 Choose an Ethernet Interface |
78 |
5.2.2 Select WAN Type |
78 |
5.2.3 Configure WAN Settings |
79 |
5.2.4 WAN and ISP Connection Settings |
80 |
5.2.5 Quick Setup Interface Wizard: Summary |
82 |
5.3 VPN Quick Setup |
83 |
5.4 VPN Setup Wizard: Wizard Type |
84 |
5.5 VPN Express Wizard - Scenario |
85 |
5.5.1 VPN Express Wizard - Configuration |
86 |
5.5.2 VPN Express Wizard - Summary |
87 |
5.5.3 VPN Express Wizard - Finish |
88 |
5.5.4 VPN Advanced Wizard - Scenario |
89 |
5.5.5 VPN Advanced Wizard - Phase 1 Settings |
90 |
5.5.6 VPN Advanced Wizard - Phase 2 |
92 |
5.5.7 VPN Advanced Wizard - Summary |
93 |
5.5.8 VPN Advanced Wizard - Finish |
94 |
Configuration Basics |
95 |
6.1 Object-based Configuration |
95 |
6.2 Zones, Interfaces, and Physical Ports |
96 |
6.2.1 Interface Types |
97 |
6.2.2 Default Interface and Zone Configuration |
98 |
6.3 Terminology in the ZyWALL |
99 |
6.4 Packet Flow |
100 |
6.4.1 ZLD 2.20 Packet Flow Enhancements |
100 |
6.4.2 Routing Table Checking Flow Enhancements |
101 |
6.4.3 NAT Table Checking Flow |
102 |
6.5 Feature Configuration Overview |
103 |
6.5.1 Feature |
104 |
6.5.2 Licensing Registration |
104 |
6.5.3 Licensing Update |
104 |
6.5.4 Interface |
105 |
6.5.5 Trunks |
105 |
6.5.6 Policy Routes |
105 |
6.5.7 Static Routes |
107 |
6.5.8 Zones |
107 |
6.5.9 DDNS |
107 |
6.5.10 NAT |
107 |
6.5.11 HTTP Redirect |
108 |
6.5.12 ALG |
109 |
6.5.13 Auth. Policy |
109 |
6.5.14 Firewall |
109 |
6.5.15 IPSec VPN |
110 |
6.5.16 SSL VPN |
110 |
6.5.17 L2TP VPN |
111 |
6.5.18 Application Patrol |
111 |
6.5.19 Anti-Virus |
112 |
6.5.20 IDP |
112 |
6.5.21 ADP |
112 |
6.5.22 Content Filter |
112 |
6.5.23 Anti-Spam |
113 |
6.5.24 Device HA |
113 |
6.6 Objects |
114 |
6.6.1 User/Group |
114 |
6.7 System |
115 |
6.7.1 DNS, WWW, SSH, TELNET, FTP, SNMP, Dial-in Mgmt, Vantage CNM |
115 |
6.7.2 Logs and Reports |
116 |
6.7.3 File Manager |
116 |
6.7.4 Diagnostics |
116 |
6.7.5 Shutdown |
116 |
Tutorials |
119 |
7.1 How to Configure Interfaces, Port Grouping, and Zones |
119 |
7.1.1 Configure a WAN Ethernet Interface |
120 |
7.1.2 Configure Zones |
120 |
7.1.3 Configure Port Grouping |
121 |
7.2 How to Configure a Cellular Interface |
122 |
7.3 How to Configure Load Balancing |
124 |
7.3.1 Set Up Available Bandwidth on Ethernet Interfaces |
125 |
7.3.2 Configure the WAN Trunk |
126 |
7.4 How to Set Up an IPSec VPN Tunnel |
127 |
7.4.1 Set Up the VPN Gateway |
128 |
7.4.2 Set Up the VPN Connection |
129 |
7.4.3 Configure Security Policies for the VPN Tunnel |
130 |
7.5 How to Configure a Hub-and-spoke IPSec VPN Without a VPN Concentrator |
131 |
7.6 How to Configure User-aware Access Control |
133 |
7.6.1 Set Up User Accounts |
134 |
7.6.2 Set Up User Groups |
134 |
7.6.3 Set Up User Authentication Using the RADIUS Server |
135 |
7.6.4 Web Surfing Policies With Bandwidth Restrictions |
137 |
7.6.5 Set Up MSN Policies |
140 |
7.6.6 Set Up Firewall Rules |
141 |
7.7 How to Use a RADIUS Server to Authenticate User Accounts based on Groups |
142 |
7.8 How to Use Endpoint Security and Authentication Policies |
144 |
7.8.1 Configure the Endpoint Security Objects |
144 |
7.8.2 Configure the Authentication Policy |
146 |
7.9 How to Configure Service Control |
147 |
7.9.1 Allow HTTPS Administrator Access Only From the LAN |
148 |
7.10 How to Allow Incoming H.323 Peer-to-peer Calls |
150 |
7.10.1 Turn On the ALG |
151 |
7.10.2 Set Up a NAT Policy For H.323 |
151 |
7.10.3 Set Up a Firewall Rule For H.323 |
153 |
7.11 How to Allow Public Access to a Web Server |
154 |
7.11.1 Create the Address Objects |
155 |
7.11.2 Configure NAT |
155 |
7.11.3 Set Up a Firewall Rule |
156 |
7.12 How to Use an IPPBX on the DMZ |
157 |
7.12.1 Turn On the ALG |
159 |
7.12.2 Create the Address Objects |
159 |
7.12.3 Setup a NAT Policy for the IPPBX |
160 |
7.12.4 Set Up a WAN to DMZ Firewall Rule for SIP |
161 |
7.12.5 Set Up a DMZ to LAN Firewall Rule for SIP |
162 |
7.13 How to Use Multiple Static Public WAN IP Addresses for LAN to WAN Traffic |
163 |
7.13.1 Create the Public IP Address Range Object |
163 |
7.13.2 Configure the Policy Route |
164 |
7.14 How to Use Active-Passive Device HA |
164 |
7.14.1 Before You Start |
165 |
7.14.2 Configure Device HA on the Master ZyWALL |
166 |
7.14.3 Configure the Backup ZyWALL |
168 |
7.14.4 Deploy the Backup ZyWALL |
170 |
7.14.5 Check Your Device HA Setup |
170 |
L2TP VPN Example |
171 |
8.1 L2TP VPN Example |
171 |
8.2 Configuring the Default L2TP VPN Gateway Example |
171 |
8.3 Configuring the Default L2TP VPN Connection Example |
173 |
8.4 Configuring the L2TP VPN Settings Example |
174 |
8.5 Configuring L2TP VPN in Windows Vista, XP, or 2000 |
175 |
8.5.1 Configuring L2TP in Windows Vista |
175 |
8.5.2 Configuring L2TP in Windows XP |
185 |
8.5.3 Configuring L2TP in Windows 2000 |
191 |
Technical Reference |
207 |
Dashboard |
209 |
9.1 Overview |
209 |
9.1.1 What You Can Do in this Chapter |
209 |
9.2 The Dashboard Screen |
209 |
9.2.1 The CPU Usage Screen |
216 |
9.2.2 The Memory Usage Screen |
217 |
9.2.3 The Session Usage Screen |
218 |
9.2.4 The VPN Status Screen |
219 |
9.2.5 The DHCP Table Screen |
219 |
9.2.6 The Number of Login Users Screen |
220 |
Monitor |
223 |
10.1 Overview |
223 |
10.1.1 What You Can Do in this Chapter |
223 |
10.2 The Port Statistics Screen |
224 |
10.2.1 The Port Statistics Graph Screen |
226 |
10.3 Interface Status Screen |
227 |
10.4 The Traffic Statistics Screen |
230 |
10.5 The Session Monitor Screen |
233 |
10.6 The DDNS Status Screen |
236 |
10.7 IP/MAC Binding Monitor |
236 |
10.8 The Login Users Screen |
238 |
10.9 Cellular Status Screen |
239 |
10.10 Application Patrol Statistics |
241 |
10.10.1 Application Patrol Statistics: General Setup |
241 |
10.10.2 Application Patrol Statistics: Bandwidth Statistics |
242 |
10.10.3 Application Patrol Statistics: Protocol Statistics |
243 |
10.10.4 Application Patrol Statistics: Individual Protocol Statistics by Rule |
244 |
10.11 The IPSec Monitor Screen |
245 |
10.11.1 Regular Expressions in Searching IPSec SAs |
247 |
10.12 The SSL Connection Monitor Screen |
248 |
10.13 L2TP over IPSec Session Monitor Screen |
249 |
10.14 The Anti-Virus Statistics Screen |
250 |
10.15 The IDP Statistics Screen |
252 |
10.16 The Content Filter Statistics Screen |
254 |
10.17 Content Filter Cache Screen |
255 |
10.18 The Anti-Spam Statistics Screen |
258 |
10.19 The Anti-Spam Status Screen |
260 |
10.20 Log Screen |
261 |
Registration |
265 |
11.1 Overview |
265 |
11.1.1 What You Can Do in this Chapter |
265 |
11.1.2 What you Need to Know |
265 |
11.2 The Registration Screen |
267 |
11.3 The Service Screen |
269 |
Signature Update |
271 |
12.1 Overview |
271 |
12.1.1 What You Can Do in this Chapter |
271 |
12.1.2 What you Need to Know |
271 |
12.2 The Antivirus Update Screen |
272 |
12.3 The IDP/AppPatrol Update Screen |
273 |
12.4 The System Protect Update Screen |
275 |
Interfaces |
277 |
13.1 Interface Overview |
277 |
13.1.1 What You Can Do in this Chapter |
277 |
13.1.2 What You Need to Know |
278 |
13.2 Port Grouping |
280 |
13.2.1 Port Grouping Overview |
281 |
13.2.2 Port Grouping Screen |
281 |
13.3 Ethernet Summary Screen |
282 |
13.3.1 Ethernet Edit |
284 |
13.3.2 Object References |
291 |
13.4 PPP Interfaces |
292 |
13.4.1 PPP Interface Summary |
293 |
13.4.2 PPP Interface Add or Edit |
295 |
13.5 Cellular Configuration Screen (3G) |
299 |
13.5.1 Cellular Add/Edit Screen |
301 |
13.6 VLAN Interfaces |
308 |
13.6.1 VLAN Summary Screen |
310 |
13.6.2 VLAN Add/Edit |
311 |
13.7 Bridge Interfaces |
318 |
13.7.1 Bridge Summary |
320 |
13.7.2 Bridge Add/Edit |
321 |
13.8 Auxiliary Interface |
327 |
13.8.1 Auxiliary Interface Overview |
327 |
13.8.2 Auxiliary |
327 |
13.9 Virtual Interfaces |
329 |
13.9.1 Virtual Interfaces Add/Edit |
330 |
13.10 Interface Technical Reference |
331 |
Trunks |
337 |
14.1 Overview |
337 |
14.1.1 What You Can Do in this Chapter |
337 |
14.1.2 What You Need to Know |
338 |
14.2 The Trunk Summary Screen |
342 |
14.3 Configuring a Trunk |
343 |
14.4 Trunk Technical Reference |
345 |
Policy and Static Routes |
347 |
15.1 Policy and Static Routes Overview |
347 |
15.1.1 What You Can Do in this Chapter |
347 |
15.1.2 What You Need to Know |
348 |
15.2 Policy Route Screen |
350 |
15.2.1 Policy Route Edit Screen |
353 |
15.3 IP Static Route Screen |
357 |
15.3.1 Static Route Add/Edit Screen |
358 |
15.4 Policy Routing Technical Reference |
359 |
Routing Protocols |
363 |
16.1 Routing Protocols Overview |
363 |
16.1.1 What You Can Do in this Chapter |
363 |
16.1.2 What You Need to Know |
363 |
16.2 The RIP Screen |
364 |
16.3 The OSPF Screen |
365 |
16.3.1 Configuring the OSPF Screen |
369 |
16.3.2 OSPF Area Add/Edit Screen |
372 |
16.3.3 Virtual Link Add/Edit Screen |
373 |
16.4 Routing Protocol Technical Reference |
374 |
Zones |
377 |
17.1 Zones Overview |
377 |
17.1.1 What You Can Do in this Chapter |
377 |
17.1.2 What You Need to Know |
378 |
17.2 The Zone Screen |
379 |
17.3 Zone Edit |
380 |
DDNS |
381 |
18.1 DDNS Overview |
381 |
18.1.1 What You Can Do in this Chapter |
381 |
18.1.2 What You Need to Know |
381 |
18.2 The DDNS Screen |
382 |
18.2.1 The Dynamic DNS Add/Edit Screen |
384 |
NAT |
387 |
19.1 NAT Overview |
387 |
19.1.1 What You Can Do in this Chapter |
387 |
19.1.2 What You Need to Know |
388 |
19.2 The NAT Screen |
388 |
19.2.1 The NAT Add/Edit Screen |
390 |
19.3 NAT Technical Reference |
393 |
HTTP Redirect |
397 |
20.1 Overview |
397 |
20.1.1 What You Can Do in this Chapter |
397 |
20.1.2 What You Need to Know |
398 |
20.2 The HTTP Redirect Screen |
399 |
20.2.1 The HTTP Redirect Edit Screen |
400 |
ALG |
401 |
21.1 ALG Overview |
401 |
21.1.1 What You Can Do in this Chapter |
401 |
21.1.2 What You Need to Know |
402 |
21.1.3 Before You Begin |
405 |
21.2 The ALG Screen |
405 |
21.3 ALG Technical Reference |
407 |
IP/MAC Binding |
409 |
22.1 IP/MAC Binding Overview |
409 |
22.1.1 What You Can Do in this Chapter |
409 |
22.1.2 What You Need to Know |
410 |
22.2 IP/MAC Binding Summary |
410 |
22.2.1 IP/MAC Binding Edit |
411 |
22.2.2 Static DHCP Edit |
412 |
22.3 IP/MAC Binding Exempt List |
413 |
Authentication Policy |
415 |
23.1 Overview |
415 |
23.1.1 What You Can Do in this Chapter |
415 |
23.1.2 What You Need to Know |
416 |
23.2 Authentication Policy Screen |
416 |
23.2.1 Creating/Editing an Authentication Policy |
419 |
Firewall |
423 |
24.1 Overview |
423 |
24.1.1 What You Can Do in this Chapter |
423 |
24.1.2 What You Need to Know |
424 |
24.1.3 Firewall Rule Example Applications |
426 |
24.1.4 Firewall Rule Configuration Example |
429 |
24.2 The Firewall Screen |
431 |
24.2.1 Configuring the Firewall Screen |
432 |
24.2.2 The Firewall Add/Edit Screen |
435 |
24.3 The Session Limit Screen |
436 |
24.3.1 The Session Limit Add/Edit Screen |
438 |
IPSec VPN |
441 |
25.1 IPSec VPN Overview |
441 |
25.1.1 What You Can Do in this Chapter |
441 |
25.1.2 What You Need to Know |
442 |
25.1.3 Before You Begin |
444 |
25.2 The VPN Connection Screen |
444 |
25.2.1 The VPN Connection Add/Edit (IKE) Screen |
446 |
25.2.2 The VPN Connection Add/Edit Manual Key Screen |
453 |
25.3 The VPN Gateway Screen |
456 |
25.3.1 The VPN Gateway Add/Edit Screen |
457 |
25.4 VPN Concentrator |
465 |
25.4.1 IPSec VPN Concentrator Example |
465 |
25.4.2 VPN Concentrator Screen |
468 |
25.4.3 The VPN Concentrator Add/Edit Screen |
468 |
25.5 IPSec VPN Background Information |
469 |
SSL VPN |
481 |
26.1 Overview |
481 |
26.1.1 What You Can Do in this Chapter |
481 |
26.1.2 What You Need to Know |
481 |
26.2 The SSL Access Privilege Screen |
484 |
26.2.1 The SSL Access Policy Add/Edit Screen |
486 |
26.3 The SSL Global Setting Screen |
488 |
26.3.1 How to Upload a Custom Logo |
490 |
26.4 Establishing an SSL VPN Connection |
491 |
SSL User Screens |
493 |
27.1 Overview |
493 |
27.1.1 What You Need to Know |
493 |
27.2 Remote User Login |
494 |
27.3 The SSL VPN User Screens |
499 |
27.4 Bookmarking the ZyWALL |
500 |
27.5 Logging Out of the SSL VPN User Screens |
500 |
SSL User Application Screens |
503 |
28.1 SSL User Application Screens Overview |
503 |
28.2 The Application Screen |
503 |
SSL User File Sharing |
505 |
29.1 Overview |
505 |
29.1.1 What You Need to Know |
505 |
29.2 The Main File Sharing Screen |
506 |
29.3 Opening a File or Folder |
506 |
29.3.1 Downloading a File |
508 |
29.3.2 Saving a File |
509 |
29.4 Creating a New Folder |
509 |
29.5 Renaming a File or Folder |
510 |
29.6 Deleting a File or Folder |
510 |
29.7 Uploading a File |
511 |
ZyWALL SecuExtender |
513 |
30.1 The ZyWALL SecuExtender Icon |
513 |
30.2 Statistics |
514 |
30.3 View Log |
515 |
30.4 Suspend and Resume the Connection |
515 |
30.5 Stop the Connection |
516 |
30.6 Uninstalling the ZyWALL SecuExtender |
516 |
L2TP VPN |
517 |
31.1 Overview |
517 |
31.1.1 What You Can Do in this Chapter |
517 |
31.1.2 What You Need to Know |
517 |
31.2 L2TP VPN Screen |
519 |
Application Patrol |
521 |
32.1 Overview |
521 |
32.1.1 What You Can Do in this Chapter |
521 |
32.1.2 What You Need to Know |
522 |
32.1.3 Application Patrol Bandwidth Management Examples |
527 |
32.2 Application Patrol General Screen |
531 |
32.3 Application Patrol Applications |
532 |
32.3.1 The Application Patrol Edit Screen |
533 |
32.3.2 The Application Patrol Policy Edit Screen |
537 |
32.4 The Other Applications Screen |
540 |
32.4.1 The Other Applications Add/Edit Screen |
543 |
Anti-Virus |
547 |
33.1 Overview |
547 |
33.1.1 What You Can Do in this Chapter |
547 |
33.1.2 What You Need to Know |
548 |
33.1.3 Before You Begin |
550 |
33.2 Anti-Virus Summary Screen |
550 |
33.2.1 Anti-Virus Policy Add or Edit Screen |
553 |
33.3 Anti-Virus Black List |
555 |
33.4 Anti-Virus Black List or White List Add/Edit |
556 |
33.5 Anti-Virus White List |
557 |
33.6 Signature Searching |
558 |
33.7 Anti-Virus Technical Reference |
561 |
IDP |
563 |
34.1 Overview |
563 |
34.1.1 What You Can Do in this Chapter |
563 |
34.1.2 What You Need To Know |
563 |
34.1.3 Before You Begin |
564 |
34.2 The IDP General Screen |
565 |
34.3 Introducing IDP Profiles |
567 |
34.3.1 Base Profiles |
568 |
34.4 The Profile Summary Screen |
569 |
34.5 Creating New Profiles |
570 |
34.5.1 Procedure To Create a New Profile |
570 |
34.6 Profiles: Packet Inspection |
571 |
34.6.1 Profile > Group View Screen |
571 |
34.6.2 Policy Types |
574 |
34.6.3 IDP Service Groups |
575 |
34.6.4 Profile > Query View Screen |
576 |
34.6.5 Query Example |
579 |
34.7 Introducing IDP Custom Signatures |
581 |
34.7.1 IP Packet Header |
581 |
34.8 Configuring Custom Signatures |
582 |
34.8.1 Creating or Editing a Custom Signature |
584 |
34.8.2 Custom Signature Example |
590 |
34.8.3 Applying Custom Signatures |
592 |
34.8.4 Verifying Custom Signatures |
593 |
34.9 IDP Technical Reference |
594 |
ADP |
597 |
35.1 Overview |
597 |
35.1.1 ADP and IDP Comparison |
597 |
35.1.2 What You Can Do in this Chapter |
597 |
35.1.3 What You Need To Know |
597 |
35.1.4 Before You Begin |
598 |
35.2 The ADP General Screen |
599 |
35.3 The Profile Summary Screen |
600 |
35.3.1 Base Profiles |
601 |
35.3.2 Configuring The ADP Profile Summary Screen |
601 |
35.3.3 Creating New ADP Profiles |
602 |
35.3.4 Traffic Anomaly Profiles |
602 |
35.3.5 Protocol Anomaly Profiles |
605 |
35.3.6 Protocol Anomaly Configuration |
605 |
35.4 ADP Technical Reference |
609 |
Content Filtering |
617 |
36.1 Overview |
617 |
36.1.1 What You Can Do in this Chapter |
617 |
36.1.2 What You Need to Know |
617 |
36.1.3 Before You Begin |
619 |
36.2 Content Filter General Screen |
619 |
36.3 Content Filter Policy Add or Edit Screen |
622 |
36.4 Content Filter Profile Screen |
624 |
36.5 Content Filter Categories Screen |
624 |
36.5.1 Content Filter Blocked and Warning Messages |
636 |
36.6 Content Filter Customization Screen |
637 |
36.7 Content Filter Technical Reference |
639 |
Content Filter Reports |
641 |
37.1 Overview |
641 |
37.2 Viewing Content Filter Reports |
641 |
Anti-Spam |
649 |
38.1 Overview |
649 |
38.1.1 What You Can Do in this Chapter |
649 |
38.1.2 What You Need to Know |
649 |
38.2 Before You Begin |
651 |
38.3 The Anti-Spam General Screen |
651 |
38.3.1 The Anti-Spam Policy Add or Edit Screen |
653 |
38.4 The Anti-Spam Black List Screen |
655 |
38.4.1 The Anti-Spam Black or White List Add/Edit Screen |
657 |
38.4.2 Regular Expressions in Black or White List Entries |
658 |
38.5 The Anti-Spam White List Screen |
659 |
38.6 The DNSBL Screen |
660 |
38.7 Anti-Spam Technical Reference |
662 |
Device HA |
667 |
39.1 Overview |
667 |
39.1.1 What You Can Do in this Chapter |
667 |
39.1.2 What You Need to Know |
667 |
39.1.3 Before You Begin |
668 |
39.2 Device HA General |
669 |
39.3 The Active-Passive Mode Screen |
670 |
39.3.1 Configuring Active-Passive Mode Device HA |
672 |
39.4 Configuring an Active-Passive Mode Monitored Interface |
675 |
39.5 The Legacy Mode Screen |
677 |
39.6 Configuring the Legacy Mode Screen |
678 |
39.7 Device HA Technical Reference |
682 |
User/Group |
689 |
40.1 Overview |
689 |
40.1.1 What You Can Do in this Chapter |
689 |
40.1.2 What You Need To Know |
689 |
40.2 User Summary Screen |
692 |
40.2.1 User Add/Edit Screen |
692 |
40.3 User Group Summary Screen |
695 |
40.3.1 Group Add/Edit Screen |
696 |
40.4 Setting Screen |
697 |
40.4.1 Default User Authentication Timeout Settings Edit Screens |
700 |
40.4.2 User Aware Login Example |
702 |
40.5 User /Group Technical Reference |
703 |
Addresses |
705 |
41.1 Overview |
705 |
41.1.1 What You Can Do in this Chapter |
705 |
41.1.2 What You Need To Know |
705 |
41.2 Address Summary Screen |
705 |
41.2.1 Address Add/Edit Screen |
707 |
41.3 Address Group Summary Screen |
708 |
41.3.1 Address Group Add/Edit Screen |
709 |
Services |
711 |
42.1 Overview |
711 |
42.1.1 What You Can Do in this Chapter |
711 |
42.1.2 What You Need to Know |
711 |
42.2 The Service Summary Screen |
712 |
42.2.1 The Service Add/Edit Screen |
714 |
42.3 The Service Group Summary Screen |
714 |
42.3.1 The Service Group Add/Edit Screen |
716 |
Schedules |
717 |
43.1 Overview |
717 |
43.1.1 What You Can Do in this Chapter |
717 |
43.1.2 What You Need to Know |
717 |
43.2 The Schedule Summary Screen |
718 |
43.2.1 The One-Time Schedule Add/Edit Screen |
719 |
43.2.2 The Recurring Schedule Add/Edit Screen |
720 |
AAA Server |
723 |
44.1 Overview |
723 |
44.1.1 Directory Service (AD/LDAP) |
723 |
44.1.2 RADIUS Server |
724 |
44.1.3 ASAS |
724 |
44.1.4 What You Can Do in this Chapter |
724 |
44.1.5 What You Need To Know |
725 |
44.2 Active Directory or LDAP Server Summary |
727 |
44.2.1 Adding an Active Directory or LDAP Server |
727 |
44.3 RADIUS Server Summary |
729 |
44.3.1 Adding a RADIUS Server |
731 |
Authentication Method |
733 |
45.1 Overview |
733 |
45.1.1 What You Can Do in this Chapter |
733 |
45.1.2 Before You Begin |
733 |
45.1.3 Example: Selecting a VPN Authentication Method |
733 |
45.2 Authentication Method Objects |
734 |
45.2.1 Creating an Authentication Method Object |
735 |
Certificates |
739 |
46.1 Overview |
739 |
46.1.1 What You Can Do in this Chapter |
739 |
46.1.2 What You Need to Know |
739 |
46.1.3 Verifying a Certificate |
741 |
46.2 The My Certificates Screen |
743 |
46.2.1 The My Certificates Add Screen |
744 |
46.2.2 The My Certificates Edit Screen |
749 |
46.2.3 The My Certificates Import Screen |
752 |
46.3 The Trusted Certificates Screen |
753 |
46.3.1 The Trusted Certificates Edit Screen |
754 |
46.3.2 The Trusted Certificates Import Screen |
758 |
46.4 Certificates Technical Reference |
759 |
ISP Accounts |
761 |
47.1 Overview |
761 |
47.1.1 What You Can Do in this Chapter |
761 |
47.2 ISP Account Summary |
761 |
47.2.1 ISP Account Edit |
762 |
SSL Application |
765 |
48.1 Overview |
765 |
48.1.1 What You Can Do in this Chapter |
765 |
48.1.2 What You Need to Know |
765 |
48.1.3 Example: Specifying a Web Site for Access |
766 |
48.2 The SSL Application Screen |
767 |
48.2.1 Creating/Editing a Web-based SSL Application Object |
768 |
48.2.2 Creating/Editing a File Sharing SSL Application Object |
770 |
Endpoint Security |
773 |
49.1 Overview |
773 |
49.1.1 What You Can Do in this Chapter |
774 |
49.1.2 What You Need to Know |
774 |
49.2 Endpoint Security Screen |
775 |
49.3 Endpoint Security Add/Edit |
777 |
System |
783 |
50.1 Overview |
783 |
50.1.1 What You Can Do in this Chapter |
783 |
50.2 Host Name |
784 |
50.3 Date and Time |
785 |
50.3.1 Pre-defined NTP Time Servers List |
787 |
50.3.2 Time Server Synchronization |
788 |
50.4 Console Port Speed |
789 |
50.5 DNS Overview |
789 |
50.5.1 DNS Server Address Assignment |
790 |
50.5.2 Configuring the DNS Screen |
790 |
50.5.3 Address Record |
793 |
50.5.4 PTR Record |
793 |
50.5.5 Adding an Address/PTR Record |
793 |
50.5.6 Domain Zone Forwarder |
794 |
50.5.7 Adding a Domain Zone Forwarder |
794 |
50.5.8 MX Record |
795 |
50.5.9 Adding a MX Record |
796 |
50.5.10 Adding a DNS Service Control Rule |
796 |
50.6 WWW Overview |
797 |
50.6.1 Service Access Limitations |
798 |
50.6.2 System Timeout |
798 |
50.6.3 HTTPS |
798 |
50.6.4 Configuring WWW Service Control |
799 |
50.6.5 Service Control Rules |
803 |
50.6.6 Customizing the WWW Login Page |
803 |
50.6.7 HTTPS Example |
807 |
50.7 SSH |
814 |
50.7.1 How SSH Works |
815 |
50.7.2 SSH Implementation on the ZyWALL |
816 |
50.7.3 Requirements for Using SSH |
816 |
50.7.4 Configuring SSH |
816 |
50.7.5 Secure Telnet Using SSH Examples |
818 |
50.8 Telnet |
819 |
50.8.1 Configuring Telnet |
820 |
50.9 FTP |
821 |
50.9.1 Configuring FTP |
821 |
50.10 SNMP |
823 |
50.10.1 Supported MIBs |
825 |
50.10.2 SNMP Traps |
825 |
50.10.3 Configuring SNMP |
825 |
50.11 Dial-in Management |
827 |
50.11.1 Configuring Dial-in Mgmt |
828 |
50.12 Vantage CNM |
829 |
50.12.1 Configuring Vantage CNM |
830 |
50.13 Language Screen |
832 |
Log and Report |
833 |
51.1 Overview |
833 |
51.1.1 What You Can Do In this Chapter |
833 |
51.2 Email Daily Report |
833 |
51.3 Log Setting Screens |
835 |
51.3.1 Log Setting Summary |
836 |
51.3.2 Edit System Log Settings |
837 |
51.3.3 Edit Remote Server Log Settings |
842 |
51.3.4 Active Log Summary Screen |
844 |
File Manager |
847 |
52.1 Overview |
847 |
52.1.1 What You Can Do in this Chapter |
847 |
52.1.2 What you Need to Know |
847 |
52.2 The Configuration File Screen |
850 |
52.3 The Firmware Package Screen |
854 |
52.4 The Shell Script Screen |
856 |
Diagnostics |
859 |
53.1 Overview |
859 |
53.1.1 What You Can Do in this Chapter |
859 |
53.2 The Diagnostic Screen |
859 |
53.3 The Packet Capture Screen |
860 |
53.3.1 The Packet Capture Files Screen |
862 |
53.3.2 Example of Viewing a Packet Capture File |
863 |
Reboot |
865 |
54.1 Overview |
865 |
54.1.1 What You Need To Know |
865 |
54.2 The Reboot Screen |
865 |
Shutdown |
867 |
55.1 Overview |
867 |
55.1.1 What You Need To Know |
867 |
55.2 The Shutdown Screen |
867 |
Troubleshooting |
869 |
56.1 Resetting the ZyWALL |
886 |
56.2 Changing a Power Module |
887 |
56.3 Getting More Troubleshooting Help |
889 |
Product Specifications |
891 |
57.1 3G PCMCIA Card Installation |
897 |
Log Descriptions |
899 |
Common Services |
959 |
Displaying Anti-Virus Alert Messages in Windows |
963 |
Importing Certificates |
969 |
Open Software Announcements |
995 |
Legal Information |
1051 |