VPN100

ZyXEL VPN100, VPN300, VPN50 User guide

  • Hello! I am an AI chatbot trained to assist you with the ZyXEL VPN100 User guide. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
Default Login Details
User’s Guide
ZyWALL USG/VPN
Series
Copyright © 2020 Zyxel Communications Corporation
LAN Port IP Address https://192.168.1.1
User Name admin
Password 1234
Version 4.35 Edition 3, 6/2020
ZyWALL USG/VPN Series User’s Guide
2
IMPORTANT!
READ CAREFULLY BEFORE USE.
KEEP THIS GUIDE FOR FUTURE REFERENCE.
This is a User’s Guide for a series of products. Not all products support all firmware features. Screenshots
and graphics in this book may differ slightly from your product due to differences in product features or
web configurator brand style. Most screen shots in this guide come from the USG110 and USG60W.
Screen shots for other models may vary. Every effort has been made to ensure that the information in
this manual is accurate.
Note: The version number on the cover page refers to the latest firmware version supported
by the Zyxel Device. This guide applies to ZLD versions 4.10, 4.11, 4.13, 4.15, 4.16, 4.20,
4.25, 4.30, 4.31, 4.32, 4.33, and 4.35 at the time of writing.
Related Documentation
•Quick Start Guide
The Quick Start Guide shows how to connect the Zyxel Device and access the Web Configurator
wizards. (See the wizard real time help for information on configuring each screen.) It also contains a
connection diagram and package contents list.
•CLI Reference Guide
The CLI Reference Guide explains how to use the Command-Line Interface (CLI) to configure the
Zyxel Device.
Note: It is recommended you use the Web Configurator to configure the Zyxel Device.
Web Configurator Online Help
Click the help icon in any screen for help in configuring that screen and supplementary information.
•More Information
Go to https://businessforum.zyxel.com for product discussions.
•Go to support.zyxel.com to find other information on the Zyxel Device
.
ZyWALL USG/VPN Series User’s Guide
3
Document Conventions
Warnings and Notes
These are how warnings and notes are shown in this guide.
Warnings tell you about things that could harm you or your device.
Note: Notes tell you other important information (for example, other things you may need to
configure or helpful tips) or recommendations.
Syntax Conventions
All models in this series may be referred to as the “Zyxel Device” in this guide.
Product labels, screen names, field labels and field choices are all in bold font.
A right angle bracket ( > ) within a screen name denotes a mouse click. For example, Configuration >
Network > Interface > Ethernet means you first click Configuration in the navigation panel, then
Network, then the Interface sub menu and finally the Ethernet tab to get to that screen.
Icons Used in Figures
Figures in this user guide may use the following generic icons. The Zyxel Device icon is not an exact
representation of your device.
Zyxel Device Generic Router Wireless Router / Access Point
Switch Firewall Server
Internet Network Cloud Smartphone
USB Dongle
Contents Overview
ZyWALL USG/VPN Series User’s Guide
4
Contents Overview
Introduction ........................................................................................................................................... 28
Initial Setup Wizard ............................................................................................................................... 58
Hardware, Interfaces and Zones ........................................................................................................ 73
Easy Mode ............................................................................................................................................. 90
Quick Setup Wizards ........................................................................................................................... 157
Dashboard .......................................................................................................................................... 190
Monitor ................................................................................................................................................. 205
Licensing .............................................................................................................................................. 275
Wireless ................................................................................................................................................. 282
Interfaces ............................................................................................................................................. 305
Routing ................................................................................................................................................. 415
DDNS ................................................................................................................................................... 442
NAT ....................................................................................................................................................... 448
Redirect Service .................................................................................................................................. 456
ALG ....................................................................................................................................................... 462
UPnP ..................................................................................................................................................... 469
IP/MAC Binding ................................................................................................................................... 484
Layer 2 Isolation .................................................................................................................................. 489
DNS Inbound LB .................................................................................................................................. 493
Web Authentication .......................................................................................................................... 499
Hotspot ................................................................................................................................................ 531
Printer Manager .................................................................................................................................. 549
Free Time ............................................................................................................................................. 561
IPnP ....................................................................................................................................................... 566
Walled Garden ................................................................................................................................... 569
Advertisement Screen ....................................................................................................................... 575
Security Policy ..................................................................................................................................... 578
Cloud CNM ........................................................................................................................................ 604
Amazon VPC ...................................................................................................................................... 612
IPSec VPN ............................................................................................................................................ 614
SSL VPN ................................................................................................................................................ 650
SSL User Screens ................................................................................................................................. 661
Zyxel Device SecuExtender (Windows) ............................................................................................674
L2TP VPN .............................................................................................................................................. 678
BWM (Bandwidth Management) ..................................................................................................683
Application Patrol ............................................................................................................................... 698
Content Filtering ................................................................................................................................. 704
IDP ........................................................................................................................................................ 723
Anti-Virus .............................................................................................................................................. 748
Contents Overview
ZyWALL USG/VPN Series User’s Guide
5
Anti-Spam ............................................................................................................................................ 760
SSL Inspection ...................................................................................................................................... 778
Device HA ........................................................................................................................................... 787
Object .................................................................................................................................................. 803
System .................................................................................................................................................. 915
Log and Report ................................................................................................................................... 973
File Manager ....................................................................................................................................... 991
Diagnostics ....................................................................................................................................... 1005
Packet Flow Explore ........................................................................................................................ 1026
Shutdown ........................................................................................................................................... 1034
Troubleshooting ................................................................................................................................ 1036
Table of Contents
ZyWALL USG/VPN Series User’s Guide
6
Table of Contents
Document Conventions ......................................................................................................................3
Contents Overview .............................................................................................................................4
Table of Contents.................................................................................................................................6
Part I: User’s Guide..........................................................................................27
Chapter 1
Introduction ........................................................................................................................................28
1.1 Overview ......................................................................................................................................... 28
1.2 SD-WAN Mode ................................................................................................................................ 30
1.2.1 Switching to SD-WAN mode ................................................................................................ 31
1.3 Registration at myZyxel .................................................................................................................. 34
1.3.1 Grace Period ......................................................................................................................... 35
1.4 Applications .................................................................................................................................... 35
1.5 Management Overview ................................................................................................................ 38
1.6 Web Configurator ........................................................................................................................... 40
1.6.1 Web Configurator Access .................................................................................................... 40
1.6.2 Web Configurator Screens Overview ................................................................................. 43
1.6.3 Navigation Panel .................................................................................................................. 46
1.6.4 Tables and Lists ...................................................................................................................... 55
Chapter 2
Initial Setup Wizard.............................................................................................................................58
2.1 Initial Setup Wizard Screens .......................................................................................................... 58
2.1.1 Internet Access Setup - WAN Interface ............................................................................. 59
2.1.2 Internet Access: Ethernet .................................................................................................... 59
2.1.3 Internet Access: PPPoE ......................................................................................................... 61
2.1.4 Internet Access: PPTP ........................................................................................................... 62
2.1.5 Internet Access: L2TP ............................................................................................................ 64
2.1.6 Internet Access Setup - Second WAN Interface ............................................................... 65
2.1.7 Internet Access: Congratulations ....................................................................................... 66
2.1.8 Date and Time Settings ........................................................................................................ 66
2.1.9 Register Device ..................................................................................................................... 67
2.1.10 Activate Service .................................................................................................................. 68
2.1.11 Wireless Settings: AP Controller ......................................................................................... 69
2.1.12 Wireless Settings: SSID & Security ...................................................................................... 70
Table of Contents
ZyWALL USG/VPN Series User’s Guide
7
2.1.13 Remote Management ......................................................................................................71
Chapter 3
Hardware, Interfaces and Zones......................................................................................................73
3.1 Hardware Overview ....................................................................................................................... 73
3.1.1 Front Panels ............................................................................................................................ 73
3.1.2 Rear Panels ............................................................................................................................ 78
3.2 Installation Scenarios ...................................................................................................................... 80
3.2.1 Desk-mounting ...................................................................................................................... 80
3.2.2 Rack-mounting ...................................................................................................................... 81
3.2.3 USG2200-VPN/USG2200 Rack Mounting ............................................................................ 82
3.2.4 Wall-mounting ....................................................................................................................... 85
3.3 Default Zones, Interfaces, and Ports ............................................................................................ 87
3.4 Stopping the Zyxel Device ............................................................................................................ 89
Chapter 4
Easy Mode..........................................................................................................................................90
4.1 Overview ........................................................................................................................................ 90
4.1.1 Objects and Rules ................................................................................................................. 90
4.1.2 Wizards and Links .................................................................................................................. 91
4.1.3 Easy Mode Settings ............................................................................................................... 92
4.1.4 Easy Mode Dashboard ......................................................................................................... 93
4.2 Initial Setup Wizard - Language and Overview ........................................................................ 95
4.2.1 Initial Setup Wizard - Internet ........................................................................................... 97
4.2.2 Initial Setup Wizard - Internet Access Errors ..................................................................... 98
4.2.3 Initial Setup Wizard - Date and Time ................................................................................ 99
4.2.4 Initial Setup Wizard - Register Device ............................................................................ 100
4.2.5 Initial Setup Wizard - Activate Services .......................................................................... 102
4.2.6 Initial Setup Wizard - Wi-Fi ................................................................................................ 104
4.2.7 Initial Setup Wizard - Remote Management ................................................................ 104
4.2.8 Initial Setup Wizard - Congratulations ............................................................................ 106
4.3 Initial Setup Wizard - Security Service ..................................................................................... 107
4.4 Initial Setup Wizard - Port Forwarding ....................................................................................... 109
4.5 Initial Setup Wizard - Guest LAN ............................................................................................... 110
4.5.1 Connecting AP Scenarios ..................................................................................................112
4.6 Initial Setup Wizard - VPN ........................................................................................................... 114
4.6.1 VPN Setup Wizard: Wizard Type ...................................................................................... 115
4.6.2 VPN Express Wizard - Scenario ......................................................................................... 115
4.6.3 VPN Express Wizard - Configuration ................................................................................ 118
4.6.4 VPN Express Wizard - Summary ........................................................................................ 118
4.6.5 VPN Express Wizard - Finish ............................................................................................... 119
4.6.6 VPN Advanced Wizard - Scenario .................................................................................. 120
4.6.7 VPN Advanced Wizard - Phase 1 Settings ..................................................................... 121
Table of Contents
ZyWALL USG/VPN Series User’s Guide
8
4.6.8 VPN Advanced Wizard - Phase 2 .................................................................................... 122
4.6.9 VPN Advanced Wizard - Summary ................................................................................. 123
4.6.10 VPN Advanced Wizard - Finish ...................................................................................... 124
4.7 VPN Settings for Configuration Provisioning Wizard: Wizard Type ......................................... 125
4.7.1 Configuration Provisioning Express Wizard - VPN Settings ............................................ 126
4.7.2 Configuration Provisioning VPN Express Wizard - Configuration ................................. 127
4.7.3 VPN Settings for Configuration Provisioning Express Wizard - Summary ..................... 128
4.7.4 VPN Settings for Configuration Provisioning Express Wizard - Finish .............................. 129
4.7.5 VPN Settings for Configuration Provisioning Advanced Wizard - Scenario ................ 130
4.7.6 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 1 Settings .... 131
4.7.7 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 2 ................. 132
4.7.8 VPN Settings for Configuration Provisioning Advanced Wizard - Summary ............... 133
4.7.9 VPN Settings for Configuration Provisioning Advanced Wizard- Finish ....................... 136
4.8 VPN Settings for L2TP VPN Settings Wizard ............................................................................... 137
4.8.1 L2TP VPN Settings 1 ............................................................................................................. 137
4.8.2 L2TP VPN Settings 2 ............................................................................................................ 138
4.8.3 VPN Settings for L2TP VPN Setting Wizard - Summary ................................................... 139
4.8.4 VPN Settings for L2TP VPN Setting Wizard Completed .................................................. 140
4.9 Port Forwarding ........................................................................................................................... 141
4.9.1 Port Forwarding > Add Client .......................................................................................... 142
4.9.2 Port Forwarding > Add Service ........................................................................................ 142
4.9.3 Port Forwarding > UPnP .................................................................................................... 142
4.10 Wi-Fi and Guest Network Wizard ........................................................................................... 143
4.10.1 Guest LAN (Wired Network) ........................................................................................... 144
4.10.2 Connecting AP Scenarios ................................................................................................ 146
4.11 Security Service Wizard .......................................................................................................... 147
4.11.1 Security Service Wizard 2 - Content Filter Categories ............................................... 149
4.11.2 Security Service Wizard 3 - Websites ........................................................................... 151
4.11.3 Security Service Wizard 4 - Exemptions ...................................................................... 152
4.11.4 Security Service Wizard 5 - IDP/AV .............................................................................. 153
4.12 MyZyxel Portal ......................................................................................................................... 154
4.13 One Security Portal ................................................................................................................. 155
Chapter 5
Quick Setup Wizards........................................................................................................................157
5.1 Quick Setup Overview ................................................................................................................. 157
5.2 WAN Interface Quick Setup ........................................................................................................ 158
5.2.1 Choose an Ethernet Interface ........................................................................................... 158
5.2.2 Select WAN Type ................................................................................................................. 159
5.2.3 Configure WAN IP Settings ................................................................................................. 160
5.2.4 ISP and WAN and ISP Connection Settings ...................................................................... 161
5.2.5 Quick Setup Interface Wizard: Summary ......................................................................... 163
5.3 VPN Setup Wizard ......................................................................................................................... 164
Table of Contents
ZyWALL USG/VPN Series User’s Guide
9
5.3.1 Welcome .............................................................................................................................. 165
5.3.2 VPN Setup Wizard: Wizard Type ........................................................................................ 165
5.3.3 VPN Express Wizard - Scenario .......................................................................................... 166
5.3.4 VPN Express Wizard - Configuration ................................................................................. 167
5.3.5 VPN Express Wizard - Summary ......................................................................................... 168
5.3.6 VPN Express Wizard - Finish ................................................................................................ 169
5.3.7 VPN Advanced Wizard - Scenario ................................................................................... 169
5.3.8 VPN Advanced Wizard - Phase 1 Settings ...................................................................... 171
5.3.9 VPN Advanced Wizard - Phase 2 ..................................................................................... 172
5.3.10 VPN Advanced Wizard - Summary ................................................................................ 173
5.3.11 VPN Advanced Wizard - Finish ....................................................................................... 174
5.4 VPN Settings for Configuration Provisioning Wizard: Wizard Type ........................................... 175
5.4.1 Configuration Provisioning Express Wizard - VPN Settings ............................................. 175
5.4.2 Configuration Provisioning VPN Express Wizard - Configuration .................................. 176
5.4.3 VPN Settings for Configuration Provisioning Express Wizard - Summary ...................... 177
5.4.4 VPN Settings for Configuration Provisioning Express Wizard - Finish .............................. 178
5.4.5 VPN Settings for Configuration Provisioning Advanced Wizard - Scenario ................. 179
5.4.6 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 1 Settings .... 180
5.4.7 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 2 .................. 181
5.4.8 VPN Settings for Configuration Provisioning Advanced Wizard - Summary ................ 182
5.4.9 VPN Settings for Configuration Provisioning Advanced Wizard- Finish ........................ 184
5.5 VPN Settings for L2TP VPN Settings Wizard ................................................................................. 185
5.5.1 L2TP VPN Settings ................................................................................................................ 186
5.5.2 L2TP VPN Settings ................................................................................................................ 187
5.5.3 VPN Settings for L2TP VPN Setting Wizard - Summary .................................................... 188
5.5.4 VPN Settings for L2TP VPN Setting Wizard Completed ................................................... 189
Chapter 6
Dashboard........................................................................................................................................190
6.1 Overview ....................................................................................................................................... 190
6.1.1 What You Can Do in this Chapter ..................................................................................... 190
6.2 Main Dashboard Screen .............................................................................................................. 190
6.2.1 Device Information Screen ................................................................................................192
6.2.2 System Status Screen .......................................................................................................... 193
6.2.3 DHCP Table Screen ............................................................................................................. 194
6.2.4 Number of Login Users Screen ........................................................................................... 195
6.2.5 System Resources Screen ................................................................................................... 196
6.2.6 Extension Slot Screen .......................................................................................................... 197
6.2.7 Interface Status Summary Screen ..................................................................................... 198
6.2.8 Secured Service Status Screen .......................................................................................... 199
6.2.9 Content Filter Statistics Screen ........................................................................................... 200
6.2.10 Top 5 Viruses Screen ......................................................................................................... 200
6.2.11 Top 5 Intrusions Screen ..................................................................................................... 201
Table of Contents
ZyWALL USG/VPN Series User’s Guide
10
6.2.12 Top 5 IPv4/IPv6 Security Policy Rules that Blocked Traffic Screen ............................... 201
6.2.13 The Latest Alert Logs Screen ............................................................................................202
6.3 VPN Screen .................................................................................................................................... 202
Part II: Technical Reference.........................................................................204
Chapter 7
Monitor..............................................................................................................................................205
7.1 Overview ....................................................................................................................................... 205
7.1.1 What You Can Do in this Chapter ..................................................................................... 205
7.2 The Port Statistics Screen ............................................................................................................ 207
7.2.1 The Port Statistics Graph Screen ....................................................................................... 208
7.3 Interface Status Screen ................................................................................................................ 209
7.4 The Traffic Statistics Screen .......................................................................................................... 213
7.5 The Session Monitor Screen ........................................................................................................ 216
7.6 IGMP Statistics ............................................................................................................................... 218
7.7 The DDNS Status Screen ............................................................................................................... 219
7.8 IP/MAC Binding ............................................................................................................................. 219
7.9 The Login Users Screen ................................................................................................................ 220
7.10 The Dynamic Guest Screen ...................................................................................................... 221
7.11 Cellular Status Screen ................................................................................................................ 223
7.11.1 More Information .............................................................................................................. 225
7.12 The UPnP Port Status Screen ..................................................................................................... 226
7.13 USB Storage Screen .................................................................................................................... 227
7.14 Ethernet Neighbor Screen ........................................................................................................ 228
7.15 FQDN Object Screen ................................................................................................................ 229
7.16 AP Information: AP List ............................................................................................................... 231
7.16.1 AP List: More Information ................................................................................................ 233
7.16.2 AP List: Config AP ............................................................................................................. 236
7.17 AP Information: Radio List .......................................................................................................... 237
7.17.1 Radio List: More Information ............................................................................................239
7.18 AP Information: Top N APs ........................................................................................................ 240
7.19 AP Information: Single AP .......................................................................................................... 242
7.20 ZyMesh ......................................................................................................................................... 243
7.21 SSID Info ....................................................................................................................................... 243
7.22 Station Info: Station List .............................................................................................................. 244
7.23 Station Info: Top N Stations ........................................................................................................ 245
7.24 Station Info: Single Station ......................................................................................................... 246
7.25 Detected Device ....................................................................................................................... 247
7.26 The Printer Status Screen ........................................................................................................... 248
7.27 The SecuDeployer Monitor Screen ...........................................................................................248
Table of Contents
ZyWALL USG/VPN Series User’s Guide
11
7.27.1 Device Information (for Zyxel Device Server) ............................................................... 249
7.27.2 Device Information (for Zyxel Device Client) ................................................................ 251
7.28 The IPSec Screen ........................................................................................................................ 253
7.29 The SSL Screen ............................................................................................................................. 254
7.30 The L2TP over IPSec Screen ....................................................................................................... 255
7.31 The App Patrol Screen ............................................................................................................... 256
7.32 The Content Filter Screen .......................................................................................................... 257
7.33 The IDP Screen ............................................................................................................................ 259
7.34 The Anti-Virus Screen .................................................................................................................. 261
7.35 The Anti-Spam Screens .............................................................................................................. 263
7.35.1 Anti-Spam Summary ......................................................................................................... 263
7.35.2 The Anti-Spam Status Screen ........................................................................................... 265
7.36 The SSL Inspection Screens ........................................................................................................ 267
7.36.1 Certificate Cache List ....................................................................................................... 268
7.37 Log Screens ................................................................................................................................. 269
7.37.1 View Log ............................................................................................................................ 269
7.37.2 View AP Log ....................................................................................................................... 271
7.37.3 Dynamic Users Log ............................................................................................................ 273
Chapter 8
Licensing...........................................................................................................................................275
8.1 Registration Overview .................................................................................................................. 275
8.1.1 What you Need to Know ....................................................................................................275
8.1.2 Registration Screen ............................................................................................................. 275
8.1.3 Service Screen ..................................................................................................................... 276
8.2 Signature Update ......................................................................................................................... 278
8.2.1 What you Need to Know ....................................................................................................278
8.2.2 The Anti-Virus Update Screen ............................................................................................ 278
8.2.3 The IDP/AppPatrol Update Screen ................................................................................... 279
Chapter 9
Wireless.............................................................................................................................................282
9.1 Overview ....................................................................................................................................... 282
9.1.1 What You Can Do in this Chapter ..................................................................................... 282
9.2 Controller Screen ......................................................................................................................... 282
9.3 AP Management Screens ........................................................................................................... 283
9.3.1 Mgnt. AP List ....................................................................................................................... 283
9.3.2 AP Policy .............................................................................................................................. 287
9.3.3 AP Group ............................................................................................................................. 288
9.3.4 Firmware ............................................................................................................................... 295
9.4 Rogue AP ....................................................................................................................................... 297
9.4.1 Add/Edit Rogue/Friendly List .............................................................................................. 299
9.5 Auto Healing ................................................................................................................................. 300
Table of Contents
ZyWALL USG/VPN Series User’s Guide
12
9.6 RTLS Overview ............................................................................................................................... 301
9.6.1 What You Can Do in this Chapter ..................................................................................... 301
9.6.2 Before You Begin ................................................................................................................. 301
9.6.3 Configuring RTLS .................................................................................................................. 302
9.7 Technical Reference .................................................................................................................... 303
9.7.1 Dynamic Channel Selection .............................................................................................. 303
9.7.2 Load Balancing ................................................................................................................... 304
Chapter 10
Interfaces..........................................................................................................................................305
10.1 Interface Overview .................................................................................................................... 305
10.1.1 What You Can Do in this Chapter ................................................................................... 305
10.1.2 What You Need to Know ................................................................................................. 306
10.1.3 What You Need to Do First ...............................................................................................310
10.2 Port Role ....................................................................................................................................... 310
10.3 Port Configuration ...................................................................................................................... 311
10.4 Port Group ................................................................................................................................... 312
10.5 Ethernet Summary Screen ......................................................................................................... 313
10.5.1 Ethernet Edit ...................................................................................................................... 315
10.5.2 Proxy ARP ........................................................................................................................... 334
10.5.3 Virtual Interfaces .............................................................................................................. 336
10.5.4 References ......................................................................................................................... 337
10.5.5 Add/Edit DHCPv6 Request/Release Options ................................................................. 338
10.5.6 Add/Edit DHCP Extended Options ................................................................................. 338
10.6 PPP Interfaces ............................................................................................................................. 340
10.6.1 PPP Interface Summary .................................................................................................... 340
10.6.2 PPP Interface Add or Edit ................................................................................................ 342
10.7 Cellular Configuration Screen ................................................................................................... 347
10.7.1 Cellular Choose Slot ......................................................................................................... 350
10.7.2 Add / Edit Cellular Configuration .................................................................................... 350
10.8 Tunnel Interfaces ........................................................................................................................ 356
10.8.1 Configuring a Tunnel ........................................................................................................ 358
10.8.2 Tunnel Add or Edit Screen ................................................................................................ 359
10.9 VLAN Interfaces ......................................................................................................................... 362
10.9.1 VLAN Summary Screen .....................................................................................................364
10.9.2 VLAN Add/Edit ................................................................................................................. 365
10.10 Bridge Interfaces ...................................................................................................................... 377
10.10.1 Bridge Summary .............................................................................................................. 379
10.10.2 Bridge Add/Edit .............................................................................................................. 380
10.11 LAG ............................................................................................................................................ 391
10.11.1 LAG Summary Screen .....................................................................................................391
10.11.2 LAG Add/Edit ................................................................................................................. 393
10.12 VTI ............................................................................................................................................... 398
Table of Contents
ZyWALL USG/VPN Series User’s Guide
13
10.12.1 Restrictions for IPSec Virtual Tunnel Interface .............................................................. 398
10.12.2 VTI Screen ........................................................................................................................ 398
10.12.3 VTI Add/Edit ..................................................................................................................... 399
10.13 Trunk Overview ......................................................................................................................... 403
10.13.1 What You Need to Know ............................................................................................... 403
10.14 The Trunk Summary Screen ...................................................................................................... 406
10.14.1 Configuring a User-Defined Trunk ................................................................................. 407
10.14.2 Configuring the System Default Trunk .......................................................................... 409
10.15 Interface Technical Reference ............................................................................................... 410
Chapter 11
Routing..............................................................................................................................................415
11.1 Policy and Static Routes Overview ........................................................................................... 415
11.1.1 What You Can Do in this Chapter ................................................................................... 415
11.1.2 What You Need to Know ................................................................................................ 416
11.2 Policy Route Screen ................................................................................................................... 417
11.2.1 Policy Route Edit Screen .................................................................................................. 420
11.3 IP Static Route Screen ................................................................................................................ 424
11.3.1 Static Route Add/Edit Screen .......................................................................................... 424
11.4 Policy Routing Technical Reference ........................................................................................426
11.5 Routing Protocols Overview ..................................................................................................... 426
11.5.1 What You Need to Know ................................................................................................. 427
11.6 The RIP Screen ............................................................................................................................. 427
11.7 The OSPF Screen ......................................................................................................................... 429
11.7.1 Configuring the OSPF Screen .......................................................................................... 432
11.7.2 OSPF Area Add/Edit Screen ........................................................................................... 433
11.7.3 Virtual Link Add/Edit Screen ...........................................................................................435
11.8 BGP (Border Gateway Protocol) .............................................................................................. 436
11.8.1 Allow BGP Packets to Enter the Zyxel Device ................................................................ 437
11.8.2 Configuring the BGP Screen ............................................................................................ 437
11.8.3 The BGP Neighbors Screen .............................................................................................. 439
11.8.4 Example Scenario ............................................................................................................. 440
Chapter 12
DDNS ................................................................................................................................................442
12.1 DDNS Overview ........................................................................................................................... 442
12.1.1 What You Can Do in this Chapter ................................................................................... 442
12.1.2 What You Need to Know ................................................................................................. 442
12.2 The DDNS Screen ........................................................................................................................ 443
12.2.1 The Dynamic DNS Add/Edit Screen ................................................................................ 444
Chapter 13
NAT....................................................................................................................................................448
Table of Contents
ZyWALL USG/VPN Series User’s Guide
14
13.1 NAT Overview ............................................................................................................................. 448
13.1.1 What You Can Do in this Chapter ................................................................................... 448
13.1.2 What You Need to Know ................................................................................................. 448
13.2 The NAT Screen ........................................................................................................................... 449
13.2.1 The NAT Add/Edit Screen .................................................................................................451
13.3 NAT Technical Reference .......................................................................................................... 454
Chapter 14
Redirect Service...............................................................................................................................456
14.1 Overview ..................................................................................................................................... 456
14.1.1 HTTP Redirect ..................................................................................................................... 456
14.1.2 SMTP Redirect .................................................................................................................... 456
14.1.3 What You Can Do in this Chapter ................................................................................... 457
14.1.4 What You Need to Know ................................................................................................. 457
14.2 The Redirect Service Screen ..................................................................................................... 459
14.2.1 The Redirect Service Edit Screen ..................................................................................... 460
Chapter 15
ALG....................................................................................................................................................462
15.1 ALG Overview ............................................................................................................................. 462
15.1.1 What You Need to Know ................................................................................................. 462
15.1.2 Before You Begin ............................................................................................................... 465
15.2 The ALG Screen .......................................................................................................................... 465
15.3 ALG Technical Reference ......................................................................................................... 467
Chapter 16
UPnP...................................................................................................................................................469
16.1 UPnP and NAT-PMP Overview ................................................................................................... 469
16.2 What You Need to Know ........................................................................................................... 469
16.2.1 NAT Traversal ..................................................................................................................... 469
16.2.2 Cautions with UPnP and NAT-PMP .................................................................................. 470
16.3 UPnP Screen ................................................................................................................................ 470
16.4 Technical Reference .................................................................................................................. 471
16.4.1 Turning on UPnP in Windows 7 Example ......................................................................... 471
16.4.2 Turn on UPnP in Windows 10 Example ............................................................................ 475
16.4.3 Auto-discover Your UPnP-enabled Network Device .................................................... 477
16.4.4 Web Configurator Easy Access in Windows 7 ............................................................... 480
16.4.5 Web Configurator Easy Access in Windows 10 ............................................................. 482
Chapter 17
IP/MAC Binding................................................................................................................................484
17.1 IP/MAC Binding Overview ......................................................................................................... 484
17.1.1 What You Can Do in this Chapter ................................................................................... 484
Table of Contents
ZyWALL USG/VPN Series User’s Guide
15
17.1.2 What You Need to Know ................................................................................................. 484
17.2 IP/MAC Binding Summary ......................................................................................................... 485
17.2.1 IP/MAC Binding Edit .......................................................................................................... 485
17.2.2 Static DHCP Edit ................................................................................................................ 486
17.3 IP/MAC Binding Exempt List ....................................................................................................... 487
Chapter 18
Layer 2 Isolation...............................................................................................................................489
18.1 Overview ..................................................................................................................................... 489
18.1.1 What You Can Do in this Chapter ................................................................................... 489
18.2 Layer-2 Isolation General Screen ............................................................................................. 489
18.3 White List Screen ......................................................................................................................... 490
18.3.1 Add/Edit White List Rule ................................................................................................... 491
Chapter 19
DNS Inbound LB................................................................................................................................493
19.1 DNS Inbound Load Balancing Overview ................................................................................. 493
19.1.1 What You Can Do in this Chapter ................................................................................... 493
19.2 The DNS Inbound LB Screen ...................................................................................................... 494
19.2.1 The DNS Inbound LB Add/Edit Screen ............................................................................ 495
19.2.2 The DNS Inbound LB Add/Edit Member Screen ............................................................ 497
Chapter 20
Web Authentication ........................................................................................................................499
20.1 Web Auth Overview ................................................................................................................... 499
20.1.1 What You Can Do in this Chapter ................................................................................... 499
20.1.2 What You Need to Know ................................................................................................. 500
20.2 Web Authentication General Screen ...................................................................................... 500
20.2.1 User-aware Access Control Example ............................................................................. 505
20.2.2 Authentication Type Screen ............................................................................................ 511
20.2.3 Custom Web Portal / User Agreement File Screen ....................................................... 515
20.2.4 Facebook Wi-Fi Screen ..................................................................................................... 516
20.3 SSO Overview .............................................................................................................................. 520
20.4 SSO - Zyxel Device Configuration ............................................................................................. 521
20.4.1 Configuration Overview ................................................................................................... 522
20.4.2 Configure the Zyxel Device to Communicate with SSO .............................................. 522
20.4.3 Enable Web Authentication ............................................................................................ 523
20.4.4 Create a Security Policy ................................................................................................... 524
20.4.5 Configure User Information ..............................................................................................525
20.4.6 Configure an Authentication Method ........................................................................... 526
20.4.7 Configure Active Directory ..............................................................................................526
20.5 SSO Agent Configuration .......................................................................................................... 527
Table of Contents
ZyWALL USG/VPN Series User’s Guide
16
Chapter 21
Hotspot..............................................................................................................................................531
21.1 Overview ..................................................................................................................................... 531
21.2 Billing Overview ........................................................................................................................... 531
21.2.1 What You Need to Know ................................................................................................. 531
21.3 The Billing > General Screen ...................................................................................................... 532
21.4 The Billing > Billing Profile Screen ............................................................................................... 534
21.4.1 The Account Generator Screen ...................................................................................... 535
21.4.2 The Account Redeem Screen ......................................................................................... 538
21.4.3 The Billing Profile Add/Edit Screen ................................................................................... 540
21.5 The Billing > Discount Screen ..................................................................................................... 541
21.5.1 The Discount Add/Edit Screen ......................................................................................... 543
21.6 The Billing > Payment Service Screen ....................................................................................... 543
21.6.1 The Payment Service > Desktop / Mobile View Screen ............................................... 545
Chapter 22
Printer Manager ...............................................................................................................................549
22.1 Printer Manager Overview ........................................................................................................ 549
22.1.1 What You Can Do in this Chapter ................................................................................... 549
22.2 The Printer Manager > General Screen ................................................................................... 549
22.2.1 Add Printer Rule ................................................................................................................. 552
22.2.2 Edit Printer Rule .................................................................................................................. 552
22.2.3 Discover Printer ................................................................................................................. 553
22.2.4 Edit Printer Manager (Discover Printer) .......................................................................... 555
22.3 The Printout Configuration Screen ............................................................................................ 556
22.4 Printer Reports Overview ........................................................................................................... 557
22.4.1 Key Combinations ............................................................................................................. 557
22.4.2 Daily Account Summary .................................................................................................. 557
22.4.3 Monthly Account Summary ............................................................................................. 558
22.4.4 Account Report Notes ..................................................................................................... 558
22.4.5 System Status ..................................................................................................................... 559
Chapter 23
Free Time...........................................................................................................................................561
23.1 Free Time Overview .................................................................................................................... 561
23.1.1 What You Can Do in this Chapter ................................................................................... 561
23.2 The Free Time Screen ................................................................................................................. 561
Chapter 24
IPnP....................................................................................................................................................566
24.1 IPnP Overview ............................................................................................................................ 566
24.1.1 What You Can Do in this Chapter ................................................................................... 567
24.1.2 IPnP Screen ........................................................................................................................ 567
Table of Contents
ZyWALL USG/VPN Series User’s Guide
17
Chapter 25
Walled Garden.................................................................................................................................569
25.1 Walled Garden Overview ........................................................................................................ 569
25.2 Walled Garden > General Screen ........................................................................................... 569
25.3 Walled Garden > URL Base Screen .......................................................................................... 570
25.3.1 Adding/Editing a Walled Garden URL ........................................................................... 571
25.4 Walled Garden > Domain/IP Base Screen .............................................................................. 572
25.4.1 Adding/Editing a Walled Garden Domain or IP ........................................................... 573
25.4.2 Walled Garden Login Example ....................................................................................... 573
Chapter 26
Advertisement Screen.....................................................................................................................575
26.1 Advertisement Overview ........................................................................................................... 575
26.1.1 Adding/Editing an Advertisement URL .......................................................................... 576
Chapter 27
Security Policy..................................................................................................................................578
27.1 Overview ..................................................................................................................................... 578
27.2 One Security ................................................................................................................................ 579
27.3 What You Can Do in this Chapter ............................................................................................ 582
27.3.1 What You Need to Know ................................................................................................. 583
27.4 The Security Policy Screen ......................................................................................................... 584
27.4.1 Configuring the Security Policy Control Screen ............................................................ 585
27.4.2 The Security Policy Control Add/Edit Screen ................................................................. 588
27.5 Anomaly Detection and Prevention Overview ...................................................................... 590
27.5.1 The Anomaly Detection and Prevention General Screen ........................................... 591
27.5.2 Creating New ADP Profiles ..............................................................................................592
27.5.3 Traffic Anomaly Profiles ................................................................................................... 593
27.5.4 Protocol Anomaly Profiles ................................................................................................ 596
27.6 The Session Control Screen ........................................................................................................ 599
27.6.1 The Session Control Add/Edit Screen .............................................................................. 600
27.7 Security Policy Example Applications ......................................................................................601
Chapter 28
Cloud CNM......................................................................................................................................604
28.1 Cloud CNM Overview ................................................................................................................ 604
28.1.1 What You Can Do in this Chapter ................................................................................... 604
28.2 Cloud CNM SecuManager ....................................................................................................... 604
28.3 Cloud CNM SecuReporter ......................................................................................................... 607
Chapter 29
Amazon VPC ...................................................................................................................................612
29.1 Overview ..................................................................................................................................... 612
Table of Contents
ZyWALL USG/VPN Series User’s Guide
18
29.2 Amazon VPC Configuration Process ........................................................................................ 612
Chapter 30
IPSec VPN .........................................................................................................................................614
30.1 Virtual Private Networks (VPN) Overview ................................................................................. 614
30.1.1 What You Can Do in this Chapter ................................................................................... 616
30.1.2 What You Need to Know ................................................................................................. 616
30.1.3 Before You Begin ............................................................................................................... 619
30.2 The VPN Connection Screen ..................................................................................................... 619
30.2.1 The VPN Connection Add/Edit Screen .......................................................................... 621
30.3 The VPN Gateway Screen ......................................................................................................... 628
30.3.1 The VPN Gateway Add/Edit Screen ............................................................................... 629
30.4 VPN Concentrator ..................................................................................................................... 636
30.4.1 VPN Concentrator Requirements and Suggestions ...................................................... 636
30.4.2 VPN Concentrator Screen ............................................................................................... 637
30.4.3 The VPN Concentrator Add/Edit Screen ........................................................................ 637
30.5 Zyxel Device IPSec VPN Client Configuration Provisioning .................................................... 638
30.6 IPSec VPN Background Information ......................................................................................... 640
Chapter 31
SSL VPN..............................................................................................................................................650
31.1 Overview ..................................................................................................................................... 650
31.1.1 What You Can Do in this Chapter ................................................................................... 650
31.1.2 What You Need to Know ................................................................................................. 650
31.2 The SSL Access Privilege Screen ................................................................................................ 651
31.2.1 The SSL Access Privilege Policy Add/Edit Screen ......................................................... 652
31.3 The SSL Global Setting Screen ................................................................................................... 655
31.3.1 How to Upload a Custom Logo ...................................................................................... 656
31.4 Zyxel Device SecuExtender ....................................................................................................... 657
31.4.1 Example: Configure Zyxel Device for SecuExtender ..................................................... 658
Chapter 32
SSL User Screens..............................................................................................................................661
32.1 Overview ..................................................................................................................................... 661
32.1.1 What You Need to Know ................................................................................................. 661
32.2 Remote SSL User Login ............................................................................................................... 662
32.3 The SSL VPN User Screens ........................................................................................................... 664
32.4 Bookmarking the Zyxel Device .................................................................................................. 664
32.5 Logging Out of the SSL VPN User Screens ................................................................................ 665
32.6 SSL User Application Screen ...................................................................................................... 665
32.7 SSL User File Sharing .................................................................................................................... 666
32.7.1 The Main File Sharing Screen ........................................................................................... 666
32.7.2 Opening a File or Folder ................................................................................................... 667
Table of Contents
ZyWALL USG/VPN Series User’s Guide
19
32.7.3 Downloading a File ........................................................................................................... 668
32.7.4 Saving a File ....................................................................................................................... 668
32.7.5 Creating a New Folder ..................................................................................................... 669
32.7.6 Renaming a File or Folder ................................................................................................ 669
32.7.7 Deleting a File or Folder .................................................................................................... 670
32.7.8 Uploading a File ................................................................................................................ 670
32.8 SecuExtender Screen ................................................................................................................ 671
32.8.1 Installing the SecuExtender Client ................................................................................... 671
Chapter 33
Zyxel Device SecuExtender (Windows).........................................................................................674
33.1 The Zyxel Device SecuExtender Icon ....................................................................................... 674
33.2 Status ............................................................................................................................................ 674
33.3 View Log ...................................................................................................................................... 675
33.4 Suspend and Resume the Connection ................................................................................... 676
33.5 Stop the Connection ................................................................................................................. 676
33.6 Uninstalling the Zyxel Device SecuExtender ............................................................................ 676
Chapter 34
L2TP VPN............................................................................................................................................678
34.1 Overview ..................................................................................................................................... 678
34.1.1 What You Can Do in this Chapter ................................................................................... 678
34.1.2 What You Need to Know ................................................................................................. 678
34.2 L2TP VPN Screen ......................................................................................................................... 679
34.2.1 Example: L2TP and Zyxel Device Behind a NAT Router ................................................ 681
Chapter 35
BWM (Bandwidth Management) .................................................................................................683
35.1 Overview ..................................................................................................................................... 683
35.1.1 What You Can Do in this Chapter ................................................................................... 683
35.1.2 What You Need to Know ................................................................................................ 683
35.2 The Bandwidth Management Configuration .......................................................................... 687
35.2.1 The Bandwidth Management Add/Edit Screen ............................................................ 690
Chapter 36
Application Patrol............................................................................................................................698
36.1 Overview ..................................................................................................................................... 698
36.1.1 What You Can Do in this Chapter ................................................................................... 698
36.1.2 What You Need to Know ................................................................................................ 698
36.2 Application Patrol Profile ........................................................................................................... 699
36.2.1 The Application Patrol Profile Add/Edit Screen ............................................................. 701
36.2.2 The Application Patrol Profile Rule Add Application Screen ....................................... 702
Table of Contents
ZyWALL USG/VPN Series User’s Guide
20
Chapter 37
Content Filtering...............................................................................................................................704
37.1 Overview ..................................................................................................................................... 704
37.1.1 What You Can Do in this Chapter ................................................................................... 704
37.1.2 What You Need to Know ................................................................................................. 704
37.1.3 Before You Begin ............................................................................................................... 706
37.2 Content Filter Profile Screen ...................................................................................................... 706
37.2.1 Content Filter Add Profile Category Service .................................................................. 708
37.2.2 Content Filter Add Filter Profile Custom Service ........................................................... 716
37.3 Content Filter Trusted Web Sites Screen ................................................................................. 719
37.4 Content Filter Forbidden Web Sites Screen ............................................................................ 720
37.5 Content Filter Technical Reference ......................................................................................... 721
Chapter 38
IDP .....................................................................................................................................................723
38.1 Overview ..................................................................................................................................... 723
38.1.1 What You Can Do in this Chapter ................................................................................... 723
38.1.2 What You Need To Know ................................................................................................. 723
38.1.3 Before You Begin ............................................................................................................... 723
38.2 The IDP Profile Screen ................................................................................................................. 724
38.2.1 Base Profiles ....................................................................................................................... 725
38.2.2 Adding / Editing Profiles .................................................................................................. 726
38.2.3 Profile > Group View Screen ............................................................................................ 727
38.2.4 Add Profile > Query View ................................................................................................ 730
38.2.5 Query Example .................................................................................................................. 734
38.3 IDP Custom Signatures .............................................................................................................. 735
38.3.1 Add / Edit Custom Signatures ......................................................................................... 738
38.3.2 Custom Signature Example ............................................................................................. 742
38.3.3 Applying Custom Signatures ............................................................................................ 744
38.3.4 Verifying Custom Signatures ............................................................................................ 744
38.4 IDP Technical Reference ........................................................................................................... 745
Chapter 39
Anti-Virus...........................................................................................................................................748
39.1 Overview ..................................................................................................................................... 748
39.1.1 What You Can Do in this Chapter ................................................................................... 750
39.2 Anti-Virus Profile Screen ............................................................................................................. 750
39.2.1 Anti-Virus Profile Add or Edit ............................................................................................. 752
39.3 Anti-Virus Black List ...................................................................................................................... 754
39.3.1 Anti-Virus Black List or White List Add/Edit ...................................................................... 755
39.3.2 Anti-Virus Black/White List ................................................................................................. 756
39.4 AV Signature Searching ............................................................................................................. 757
39.5 Anti-Virus Technical Reference ................................................................................................. 758
/