USG FLEX 700

ZyXEL USG FLEX 700 User guide

  • Hello! I am an AI chatbot trained to assist you with the ZyXEL USG FLEX 700 User guide. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
Default Login Details
User’s Guide
ZyWALL USG FLEX
Series
Copyright © 2021 Zyxel and/ or its affiliates. All rights reserved.
Login IP Address https://(IP assigned by NCC)
or
LAN https://192.168.1.1
User Name admin
Password 1234
Version 5.10 Edition 1, 10/2021
USG FLEX Series User’s Guide
2
IMPORTANT!
READ CAREFULLY BEFORE USE.
KEEP THIS GUIDE FOR FUTURE REFERENCE.
This is a User’s Guide for a series of products. Not all products support all firmware features. Screenshots
and graphics in this book may differ slightly from your product due to differences in product features or
web configurator brand style. Every effort has been made to ensure that the information in this manual
is accurate.
Note: The version number on the cover page refers to the Zyxel Device’s latest firmware
version to which this User’s Guide applies.
Related Documentation
•Quick Start Guide
The Quick Start Guide shows how to connect the Zyxel Device and access the Web Configurator
wizards. (See the wizard real time help for information on configuring each screen.) It also contains a
connection diagram and package contents list.
•CLI Reference Guide
The CLI Reference Guide explains how to use the Command-Line Interface (CLI) to configure the
Zyxel Device.
Note: It is recommended you use the Web Configurator to configure the Zyxel Device.
Web Configurator Online Help
Click the help icon in any screen for help in configuring that screen and supplementary information.
•More Information
Go to support.zyxel.com to find other information on Zyxel Device.
USG FLEX Series User’s Guide
3
Document Conventions
Warnings and Notes
These are how warnings and notes are shown in this guide.
Warnings tell you about things that could harm you or your device.
Note: Notes tell you other important information (for example, other things you may need to
configure or helpful tips) or recommendations.
Syntax Conventions
All models in this series may be referred to as the “Zyxel Device” in this guide.
Product labels, screen names, field labels and field choices are all in bold font.
A right angle bracket ( > ) within a screen name denotes a mouse click. For example, Configuration >
Network > Interface > Ethernet means you first click Configuration in the navigation panel, then
Network, then the Interface sub menu and finally the Ethernet tab to get to that screen.
Icons Used in Figures
Figures in this user guide may use the following generic icons. The Zyxel Device icon is not an exact
representation of your device.
Zyxel Device Generic Router Wireless Router / Access Point
Switch Firewall Server
Internet Network Cloud Smartphone
USB Dongle
Contents Overview
USG FLEX Series User’s Guide
4
Contents Overview
Introduction ........................................................................................................................................... 28
Initial Setup Wizard ............................................................................................................................... 65
Hardware, Interfaces and Zones ........................................................................................................ 92
Quick Setup Wizards ........................................................................................................................... 101
Dashboard .......................................................................................................................................... 147
Monitor ................................................................................................................................................. 158
Licensing .............................................................................................................................................. 244
Wireless ................................................................................................................................................. 249
Interfaces ............................................................................................................................................. 294
Routing ................................................................................................................................................. 404
DDNS ................................................................................................................................................... 431
NAT ....................................................................................................................................................... 437
Redirect Service .................................................................................................................................. 456
ALG ....................................................................................................................................................... 462
UPnP ..................................................................................................................................................... 469
IP/MAC Binding ................................................................................................................................... 484
Layer 2 Isolation .................................................................................................................................. 489
DNS Inbound LB .................................................................................................................................. 493
IPSec VPN ............................................................................................................................................ 499
SSL VPN ................................................................................................................................................ 535
L2TP VPN .............................................................................................................................................. 541
Remote AP VPN .................................................................................................................................. 546
BWM (Bandwidth Management) ..................................................................................................552
Web Authentication .......................................................................................................................... 568
Hotspot ................................................................................................................................................ 601
Printer Manager .................................................................................................................................. 619
Free Time ............................................................................................................................................. 631
IPnP ....................................................................................................................................................... 636
Walled Garden ................................................................................................................................... 639
Advertisement Screen ....................................................................................................................... 645
Security Policy ..................................................................................................................................... 648
Application Patrol ............................................................................................................................... 678
Content Filter ....................................................................................................................................... 687
Anti-Malware ....................................................................................................................................... 729
Reputation Filter .................................................................................................................................. 750
IPS ......................................................................................................................................................... 763
Email Security ...................................................................................................................................... 790
Collaborative Detection & Response .............................................................................................. 809
SSL Inspection ...................................................................................................................................... 823
Contents Overview
USG FLEX Series User’s Guide
5
IP Exception ......................................................................................................................................... 837
Object .................................................................................................................................................. 840
Device HA ........................................................................................................................................... 965
Cloud CNM ........................................................................................................................................ 972
System .................................................................................................................................................. 980
Log and Report ................................................................................................................................. 1041
File Manager ..................................................................................................................................... 1055
Diagnostics ....................................................................................................................................... 1071
Packet Flow Explore ......................................................................................................................... 1093
Shutdown ........................................................................................................................................... 1100
Troubleshooting ................................................................................................................................ 1103
Table of Contents
USG FLEX Series User’s Guide
6
Table of Contents
Document Conventions ......................................................................................................................3
Contents Overview .............................................................................................................................4
Table of Contents.................................................................................................................................6
Part I: User’s Guide..........................................................................................27
Chapter 1
Introduction ........................................................................................................................................28
1.1 Overview ......................................................................................................................................... 28
1.1.1 Model Feature Differences .................................................................................................. 28
1.2 On Premises Mode ......................................................................................................................... 29
1.3 Nebula Mode .................................................................................................................................. 30
1.3.1 NCC Portal ............................................................................................................................. 31
1.3.2 Your Zyxel Device .................................................................................................................. 31
1.3.3 Your Email Account for ZTP .................................................................................................. 32
1.4 Change the Mode ......................................................................................................................... 32
1.4.1 From Nebula Mode to On Premises Mode ........................................................................ 32
1.4.2 From On Premises Mode to Nebula Mode ........................................................................ 33
1.5 Registration at myZyxel .................................................................................................................. 34
1.5.1 Grace Period ......................................................................................................................... 35
1.5.2 Applications ........................................................................................................................... 35
1.6 Management Overview ................................................................................................................ 38
1.7 Web Configurator ........................................................................................................................... 39
1.7.1 Web Configurator Access .................................................................................................... 39
1.7.2 Security Check for Web Interface Overview ..................................................................... 42
1.7.3 The Security Check for Web Interface Screen .................................................................. 45
1.7.4 Remote Access to the Zyxel Device Networks .................................................................. 47
1.7.5 Web Configurator Screens Overview ................................................................................. 47
1.7.6 Navigation Panel .................................................................................................................. 52
1.7.7 Tables and Lists ...................................................................................................................... 61
Chapter 2
Initial Setup Wizard.............................................................................................................................65
2.1 Initial Setup Wizard: Select Management Mode ........................................................................ 65
2.1.1 Welcome Screen .................................................................................................................. 66
2.1.2 Internet Access Setup - WAN Interface .............................................................................. 66
Table of Contents
USG FLEX Series User’s Guide
7
2.1.3 Internet Access: Ethernet .................................................................................................... 67
2.1.4 Internet Access: PPPoE ......................................................................................................... 68
2.1.5 Internet Access: PPTP ........................................................................................................... 70
2.1.6 Internet Access: L2TP ............................................................................................................ 72
2.1.7 Internet Access Setup - Second WAN Interface ............................................................... 74
2.1.8 Internet Access: Congratulations ....................................................................................... 75
2.1.9 Date and Time Settings ........................................................................................................ 76
2.1.10 Register Device ................................................................................................................... 76
2.1.11 Activate Service .................................................................................................................. 78
2.1.12 Service Settings .................................................................................................................... 79
2.1.13 Service Settings: SecuReporter ..........................................................................................80
2.1.14 Wireless Settings: Management Mode ............................................................................. 81
2.1.15 Wireless Settings: AP Controller ......................................................................................... 82
2.1.16 Wireless Settings: SSID & Security ...................................................................................... 82
2.1.17 Remote Management ......................................................................................................83
2.2 Nebula Mode Initial Setup Wizard ................................................................................................ 84
2.2.1 Connect to Internet (WAN) ................................................................................................. 85
2.2.2 Internet Access: Ethernet ..................................................................................................... 86
2.2.3 Internet Access: PPPoE ......................................................................................................... 88
2.2.4 Internet Access: Congratulations ....................................................................................... 89
2.2.5 QR Code ................................................................................................................................ 90
Chapter 3
Hardware, Interfaces and Zones......................................................................................................92
3.1 Hardware Overview ....................................................................................................................... 92
3.1.1 Front Panels ............................................................................................................................ 92
3.1.2 Rear Panels ............................................................................................................................ 94
3.2 Installation Scenarios ..................................................................................................................... 96
3.2.1 Desktop Installation Procedure ...........................................................................................96
3.2.2 Rack-mounting ...................................................................................................................... 97
3.2.3 Wall-mounting ....................................................................................................................... 98
3.3 Default Zones, Interfaces, and Ports ............................................................................................ 99
3.4 Stopping the Zyxel Device .......................................................................................................... 100
Chapter 4
Quick Setup Wizards........................................................................................................................101
4.1 Quick Setup Overview ................................................................................................................. 101
4.2 WAN Interface Quick Setup ........................................................................................................ 102
4.2.1 Choose an Ethernet Interface ........................................................................................... 102
4.2.2 Select WAN Type ................................................................................................................. 103
4.2.3 Configure WAN IP Settings ................................................................................................. 103
4.2.4 ISP and WAN and ISP Connection Settings ...................................................................... 104
4.2.5 Quick Setup Interface Wizard: Summary ......................................................................... 107
Table of Contents
USG FLEX Series User’s Guide
8
4.3 Remote Access VPN Setup-Scenario ......................................................................................... 108
4.3.1 Zyxel VPN Client- VPN Configuration ................................................................................ 109
4.3.2 Zyxel VPN Client- User Authentication .............................................................................. 111
4.3.3 Zyxel VPN Client- Summary ................................................................................................111
4.3.4 L2TP over IPSec Client-VPN Configuration ....................................................................... 112
4.3.5 L2TP over IPSec Client- User Authentication .................................................................... 113
4.3.6 L2TP over IPSec Client- Summary ...................................................................................... 114
4.3.7 L2TP over IPSec Client-Config Provision ............................................................................ 115
4.4 VPN Setup Wizard ......................................................................................................................... 115
4.4.1 Welcome .............................................................................................................................. 116
4.4.2 VPN Setup Wizard: Wizard Type ........................................................................................ 116
4.4.3 VPN Express Wizard - Scenario .......................................................................................... 117
4.4.4 VPN Express Wizard - Configuration ................................................................................. 118
4.4.5 VPN Express Wizard - Summary ......................................................................................... 119
4.4.6 VPN Express Wizard - Finish ................................................................................................ 120
4.4.7 VPN Advanced Wizard - Scenario ................................................................................... 120
4.4.8 VPN Advanced Wizard - Phase 1 Settings ...................................................................... 122
4.4.9 VPN Advanced Wizard - Phase 2 ..................................................................................... 123
4.4.10 VPN Advanced Wizard - Summary ................................................................................ 124
4.4.11 VPN Advanced Wizard - Finish ....................................................................................... 126
4.5 VPN Settings for Configuration Provisioning Wizard: Wizard Type ........................................... 127
4.5.1 Configuration Provisioning Express Wizard - VPN Settings ............................................. 127
4.5.2 Configuration Provisioning VPN Express Wizard - Configuration .................................. 128
4.5.3 VPN Settings for Configuration Provisioning Express Wizard - Summary ...................... 129
4.5.4 VPN Settings for Configuration Provisioning Express Wizard - Finish .............................. 130
4.5.5 VPN Settings for Configuration Provisioning Advanced Wizard - Scenario ................. 131
4.5.6 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 1 Settings .... 132
4.5.7 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 2 .................. 133
4.5.8 VPN Settings for Configuration Provisioning Advanced Wizard - Summary ................ 134
4.5.9 VPN Settings for Configuration Provisioning Advanced Wizard - Finish ....................... 137
4.6 VPN Settings for L2TP VPN Settings Wizard ................................................................................. 137
4.6.1 L2TP VPN Settings ................................................................................................................ 138
4.6.2 L2TP VPN Settings ................................................................................................................ 139
4.6.3 VPN Settings for L2TP VPN Setting Wizard - Summary .................................................... 139
4.6.4 VPN Settings for L2TP VPN Setting Wizard - Completed ................................................ 141
4.7 Wireless Setup Wizard .................................................................................................................. 141
4.7.1 Management Mode ........................................................................................................... 142
4.7.2 SSID ...................................................................................................................................... 142
4.7.3 Radio ................................................................................................................................... 144
4.7.4 Summary ............................................................................................................................. 145
4.7.5 Wizard Completed ............................................................................................................ 146
Chapter 5
Dashboard........................................................................................................................................147
Table of Contents
USG FLEX Series User’s Guide
9
5.1 Overview ....................................................................................................................................... 147
5.1.1 What You Can Do in this Chapter ..................................................................................... 147
5.2 The General Screen ..................................................................................................................... 147
5.2.1 Device Information Screen ................................................................................................149
5.2.2 System Status Screen .......................................................................................................... 150
5.2.3 Tx/Rx Statistics ...................................................................................................................... 150
5.2.4 The Latest Logs Screen ....................................................................................................... 151
5.2.5 System Resources Screen ................................................................................................... 151
5.2.6 DHCP Table Screen ............................................................................................................. 152
5.2.7 Number of Login Users Screen ........................................................................................... 153
5.2.8 Current Login User ............................................................................................................... 154
5.2.9 VPN Status ............................................................................................................................ 154
5.2.10 SSL VPN Status .................................................................................................................... 155
5.3 The Advanced Threat Protection Screen .................................................................................. 155
Part II: Technical Reference.........................................................................157
Chapter 6
Monitor..............................................................................................................................................158
6.1 Overview ....................................................................................................................................... 158
6.1.1 What You Can Do in this Chapter ..................................................................................... 158
6.2 The Port Statistics Screen ............................................................................................................ 160
6.2.1 The Port Statistics Graph Screen ....................................................................................... 161
6.3 Interface Status Screen ................................................................................................................ 162
6.4 The Traffic Statistics Screen .......................................................................................................... 166
6.5 The Session Monitor Screen ........................................................................................................ 169
6.6 The DHCP Table Screen ............................................................................................................... 171
6.7 The Device Insight Screen ........................................................................................................... 172
6.7.1 The Device Insight Edit Screen ...........................................................................................174
6.8 The Login Users Screen ................................................................................................................ 175
6.9 Dynamic Guest ............................................................................................................................ 176
6.10 IGMP Statistics ............................................................................................................................. 178
6.11 The DDNS Status Screen ............................................................................................................. 179
6.12 IP/MAC Binding ........................................................................................................................... 179
6.13 Cellular Status Screen ................................................................................................................ 180
6.13.1 More Information .............................................................................................................. 183
6.14 The UPnP Port Status Screen ..................................................................................................... 184
6.15 USB Storage Screen .................................................................................................................... 185
6.16 Ethernet Neighbor Screen ........................................................................................................ 186
6.17 FQDN Object Screen ................................................................................................................ 187
6.18 Virtual Server Load Balancing .................................................................................................. 189
Table of Contents
USG FLEX Series User’s Guide
10
6.19 AP Information: AP List ............................................................................................................... 190
6.19.1 AP List: More Information ................................................................................................ 194
6.19.2 AP List: Edit AP ................................................................................................................... 197
6.20 AP Information: Radio List .......................................................................................................... 200
6.20.1 Radio List: More Information ............................................................................................202
6.21 AP Information: Built-in AP ........................................................................................................ 203
6.22 AP Information: Top N APs ........................................................................................................ 204
6.23 AP Information: Single AP .......................................................................................................... 206
6.24 ZyMesh ......................................................................................................................................... 207
6.25 SSID Info ....................................................................................................................................... 208
6.26 Station Info: Station List .............................................................................................................. 208
6.27 Station Info: Top N Stations ........................................................................................................ 210
6.28 Station Info: Single Station ......................................................................................................... 211
6.29 Detected Device ....................................................................................................................... 212
6.30 Wireless Health ............................................................................................................................ 214
6.31 The Printer Status Screen ........................................................................................................... 215
6.32 The IPSec Screen ........................................................................................................................ 215
6.32.1 Regular Expressions in Searching IPSec SAs ................................................................... 217
6.33 The SSL Screen ............................................................................................................................. 217
6.34 The L2TP over IPSec Screen ....................................................................................................... 218
6.35 The Remote AP VPN Screen ...................................................................................................... 219
6.36 The App Patrol Screen ............................................................................................................... 220
6.37 The Content Filter Screen .......................................................................................................... 221
6.37.1 Web Content Filter ............................................................................................................ 221
6.37.2 DNS Content Filter ............................................................................................................. 222
6.38 The Anti-Malware Screen .......................................................................................................... 224
6.39 The Reputation Filter Screen ...................................................................................................... 226
6.40 The IPS Screen ............................................................................................................................. 227
6.41 The Email Security Screens ......................................................................................................... 230
6.41.1 Email Security Summary ................................................................................................... 230
6.41.2 The Email Security Status Screen ..................................................................................... 232
6.42 Collaborative Detection & Response (CDR) ........................................................................... 233
6.42.1 CDR History ........................................................................................................................ 234
6.43 The SSL Inspection Screens ........................................................................................................ 235
6.43.1 Certificate Cache List ....................................................................................................... 237
6.44 Log Screens ................................................................................................................................. 238
6.44.1 View Log ............................................................................................................................ 238
6.44.2 View AP Log ....................................................................................................................... 240
6.44.3 Dynamic Users Log ............................................................................................................ 242
Chapter 7
Licensing...........................................................................................................................................244
7.1 Registration Overview .................................................................................................................. 244
Table of Contents
USG FLEX Series User’s Guide
11
7.1.1 What you Need to Know ....................................................................................................244
7.1.2 Registration Screen ............................................................................................................. 244
7.1.3 Service Screen ..................................................................................................................... 245
7.2 Signature Update ......................................................................................................................... 247
7.2.1 What you Need to Know ....................................................................................................247
7.2.2 The Signature Screen .......................................................................................................... 247
7.2.3 Auto Update ........................................................................................................................ 248
Chapter 8
Wireless.............................................................................................................................................249
8.1 Overview ....................................................................................................................................... 249
8.1.1 What You Can Do in this Chapter ..................................................................................... 249
8.2 Built-in AP ...................................................................................................................................... 249
8.2.1 Wireless > Built-in AP > General >Add/Edit SSID ............................................................... 251
8.2.2 Wireless > Built-in AP > Radio .............................................................................................. 254
8.3 Controller Screen ......................................................................................................................... 260
8.3.1 Connecting an AP to the Zyxel Device ............................................................................ 260
8.3.2 Connecting an AP to the Zyxel Device Manually ........................................................... 261
8.3.3 Connecting an AP to the Zyxel Device Using DHCP Option 138 .................................. 261
8.4 AP Management Screens ........................................................................................................... 262
8.4.1 Mgnt. AP List ....................................................................................................................... 262
8.4.2 AP Policy .............................................................................................................................. 276
8.4.3 AP Group ............................................................................................................................. 277
8.4.4 Firmware ............................................................................................................................... 283
8.5 Rogue AP ....................................................................................................................................... 285
8.5.1 Add/Edit Rogue/Friendly List .............................................................................................. 287
8.6 Wireless Health .............................................................................................................................. 288
8.7 Auto Healing ................................................................................................................................. 289
8.8 RTLS Overview ............................................................................................................................... 289
8.8.1 What You Can Do in this Chapter ..................................................................................... 290
8.8.2 Before You Begin ................................................................................................................. 290
8.8.3 Configuring RTLS .................................................................................................................. 291
8.9 Technical Reference .................................................................................................................... 292
8.9.1 Dynamic Channel Selection .............................................................................................. 292
8.9.2 Load Balancing ................................................................................................................... 293
Chapter 9
Interfaces..........................................................................................................................................294
9.1 Interface Overview ...................................................................................................................... 294
9.1.1 What You Can Do in this Chapter ..................................................................................... 294
9.1.2 What You Need to Know ................................................................................................... 295
9.1.3 What You Need to Do First ................................................................................................. 299
9.2 Port Role ......................................................................................................................................... 299
Table of Contents
USG FLEX Series User’s Guide
12
9.3 Port Configuration ........................................................................................................................ 300
9.4 Ethernet Summary Screen ........................................................................................................... 301
9.4.1 Ethernet Edit ........................................................................................................................ 303
9.4.2 Proxy ARP ............................................................................................................................. 319
9.4.3 Virtual Interfaces ................................................................................................................ 320
9.4.4 References ........................................................................................................................... 322
9.4.5 Add/Edit DHCPv6 Request/Release Options ................................................................... 322
9.4.6 Add/Edit DHCP Extended Options ................................................................................... 323
9.5 PPP Interfaces ............................................................................................................................... 325
9.5.1 PPP Interface Summary ...................................................................................................... 325
9.5.2 PPP Interface Add or Edit .................................................................................................. 327
9.6 Cellular Configuration Screen ..................................................................................................... 332
9.6.1 Cellular Choose Slot ........................................................................................................... 335
9.6.2 Add / Edit Cellular Configuration ...................................................................................... 335
9.7 Tunnel Interfaces .......................................................................................................................... 341
9.7.1 Configuring a Tunnel .......................................................................................................... 343
9.7.2 Tunnel Add or Edit Screen .................................................................................................. 344
9.8 VLAN Interfaces ........................................................................................................................... 348
9.8.1 VLAN Summary Screen ....................................................................................................... 349
9.8.2 VLAN Add/Edit ................................................................................................................... 350
9.9 Bridge Interfaces .......................................................................................................................... 362
9.9.1 Bridge Summary .................................................................................................................. 363
9.9.2 Bridge Add/Edit .................................................................................................................. 365
9.10 LAG .............................................................................................................................................. 375
9.10.1 Available Interfaces for LAG ........................................................................................... 376
9.10.2 LAG Summary Screen ....................................................................................................... 376
9.10.3 LAG Add/Edit ................................................................................................................... 377
9.11 VTI ................................................................................................................................................. 387
9.11.1 Restrictions for IPSec Virtual Tunnel Interface ................................................................ 388
9.11.2 VTI Screen .......................................................................................................................... 388
9.11.3 VTI Add/Edit ....................................................................................................................... 389
9.12 Trunk Overview ........................................................................................................................... 392
9.12.1 What You Need to Know ................................................................................................. 392
9.13 The Trunk Summary Screen ........................................................................................................ 395
9.13.1 Configuring a User-Defined Trunk ................................................................................... 396
9.13.2 Configuring the System Default Trunk ............................................................................ 398
9.14 Interface Technical Reference ................................................................................................. 400
Chapter 10
Routing..............................................................................................................................................404
10.1 Policy and Static Routes Overview ........................................................................................... 404
10.1.1 What You Can Do in this Chapter ................................................................................... 404
10.1.2 What You Need to Know ................................................................................................ 405
Table of Contents
USG FLEX Series User’s Guide
13
10.2 Policy Route Screen ................................................................................................................... 406
10.2.1 Policy Route Edit Screen .................................................................................................. 408
10.3 IP Static Route Screen ................................................................................................................ 413
10.3.1 Static Route Add/Edit Screen .......................................................................................... 413
10.4 Policy Routing Technical Reference ........................................................................................415
10.5 Routing Protocols Overview ..................................................................................................... 415
10.5.1 What You Need to Know ................................................................................................. 416
10.6 The RIP Screen ............................................................................................................................. 416
10.7 The OSPF Screen ......................................................................................................................... 418
10.7.1 Configuring the OSPF Screen .......................................................................................... 421
10.7.2 OSPF Area Add/Edit Screen ........................................................................................... 422
10.7.3 Virtual Link Add/Edit Screen ...........................................................................................424
10.8 BGP (Border Gateway Protocol) .............................................................................................. 425
10.8.1 Allow BGP Packets to Enter the Zyxel Device ................................................................ 426
10.8.2 Configuring the BGP Screen ............................................................................................ 426
10.8.3 The BGP Neighbors Screen .............................................................................................. 428
10.8.4 Example Scenario ............................................................................................................. 429
Chapter 11
DDNS ................................................................................................................................................431
11.1 DDNS Overview ........................................................................................................................... 431
11.1.1 What You Can Do in this Chapter ................................................................................... 431
11.1.2 What You Need to Know ................................................................................................. 431
11.2 The DDNS Screen ........................................................................................................................ 432
11.2.1 The Dynamic DNS Add/Edit Screen ................................................................................ 433
Chapter 12
NAT....................................................................................................................................................437
12.1 Overview ..................................................................................................................................... 437
12.2 NAT Overview ............................................................................................................................. 437
12.2.1 What You Can Do in this Chapter ................................................................................... 437
12.2.2 What You Need to Know ................................................................................................. 438
12.3 The NAT Screen ........................................................................................................................... 439
12.3.1 The NAT Add/Edit Screen .................................................................................................440
12.4 NAT Technical Reference .......................................................................................................... 443
12.5 Virtual Server Load Balancing ................................................................................................... 445
12.5.1 Load Balancing Example 1 .............................................................................................. 445
12.5.2 Load Balancing Example 2 .............................................................................................. 446
12.5.3 Virtual Server Load Balancing Process ........................................................................... 447
12.5.4 Load Balancing Rules ....................................................................................................... 448
12.5.5 Virtual Server Load Balancing Algorithms ...................................................................... 449
12.6 The Virtual Server Load Balancer Screen ................................................................................. 450
12.6.1 Adding/Editing a Virtual Server Load Balancing Rule .................................................. 450
Table of Contents
USG FLEX Series User’s Guide
14
Chapter 13
Redirect Service...............................................................................................................................456
13.1 Overview ..................................................................................................................................... 456
13.1.1 HTTP Redirect ..................................................................................................................... 456
13.1.2 SMTP Redirect .................................................................................................................... 456
13.1.3 What You Can Do in this Chapter ................................................................................... 457
13.1.4 What You Need to Know ................................................................................................. 457
13.2 The Redirect Service Screen ..................................................................................................... 459
13.2.1 The Redirect Service Edit Screen ..................................................................................... 460
Chapter 14
ALG....................................................................................................................................................462
14.1 ALG Overview ............................................................................................................................. 462
14.1.1 What You Need to Know ................................................................................................. 462
14.1.2 Before You Begin ............................................................................................................... 465
14.2 The ALG Screen .......................................................................................................................... 465
14.3 ALG Technical Reference ......................................................................................................... 467
Chapter 15
UPnP...................................................................................................................................................469
15.1 UPnP and NAT-PMP Overview ................................................................................................... 469
15.2 What You Need to Know ........................................................................................................... 469
15.2.1 NAT Traversal ..................................................................................................................... 469
15.2.2 Cautions with UPnP and NAT-PMP .................................................................................. 470
15.3 UPnP Screen ................................................................................................................................ 470
15.4 Technical Reference .................................................................................................................. 471
15.4.1 Turning on UPnP in Windows 7 Example ......................................................................... 471
15.4.2 Turn on UPnP in Windows 10 Example ............................................................................ 475
15.4.3 Auto-discover Your UPnP-enabled Network Device .................................................... 477
15.4.4 Web Configurator Easy Access in Windows 7 ............................................................... 480
15.4.5 Web Configurator Easy Access in Windows 10 ............................................................. 482
Chapter 16
IP/MAC Binding................................................................................................................................484
16.1 IP/MAC Binding Overview ......................................................................................................... 484
16.1.1 What You Can Do in this Chapter ................................................................................... 484
16.1.2 What You Need to Know ................................................................................................. 484
16.2 IP/MAC Binding Summary ......................................................................................................... 485
16.2.1 IP/MAC Binding Edit .......................................................................................................... 486
16.2.2 Static DHCP Edit ................................................................................................................ 487
16.3 IP/MAC Binding Exempt List ....................................................................................................... 488
Table of Contents
USG FLEX Series User’s Guide
15
Chapter 17
Layer 2 Isolation...............................................................................................................................489
17.1 Overview ..................................................................................................................................... 489
17.1.1 What You Can Do in this Chapter ................................................................................... 489
17.2 Layer-2 Isolation General Screen ............................................................................................. 489
17.3 Allow List Screen ......................................................................................................................... 490
17.3.1 Add/Edit Allow List Rule ................................................................................................... 491
Chapter 18
DNS Inbound LB................................................................................................................................493
18.1 DNS Inbound Load Balancing Overview ................................................................................. 493
18.1.1 What You Can Do in this Chapter ................................................................................... 493
18.2 The DNS Inbound LB Screen ...................................................................................................... 494
18.2.1 The DNS Inbound LB Add/Edit Screen ............................................................................ 495
18.2.2 The DNS Inbound LB Add/Edit Member Screen ............................................................ 497
Chapter 19
IPSec VPN .........................................................................................................................................499
19.1 Virtual Private Networks (VPN) Overview ................................................................................. 499
19.1.1 What You Can Do in this Chapter ................................................................................... 501
19.1.2 What You Need to Know ................................................................................................. 501
19.1.3 Before You Begin ............................................................................................................... 504
19.2 The VPN Connection Screen ..................................................................................................... 504
19.2.1 The VPN Connection Add/Edit Screen .......................................................................... 506
19.3 The VPN Gateway Screen ......................................................................................................... 513
19.3.1 The VPN Gateway Add/Edit Screen ............................................................................... 515
19.4 VPN Concentrator ..................................................................................................................... 521
19.4.1 VPN Concentrator Requirements and Suggestions ...................................................... 521
19.4.2 VPN Concentrator Screen ............................................................................................... 522
19.4.3 The VPN Concentrator Add/Edit Screen ........................................................................ 522
19.5 Zyxel Device IPSec VPN Client Configuration Provisioning .................................................... 523
19.6 IPSec VPN Background Information ......................................................................................... 526
Chapter 20
SSL VPN..............................................................................................................................................535
20.1 Overview ..................................................................................................................................... 535
20.1.1 What You Can Do in this Chapter ................................................................................... 535
20.1.2 What You Need to Know ................................................................................................. 535
20.2 The SSL Access Privilege Screen ................................................................................................ 536
20.2.1 The SSL Access Privilege Policy Add/Edit Screen ......................................................... 537
20.3 The SSL Global Setting Screen ................................................................................................... 539
Table of Contents
USG FLEX Series User’s Guide
16
Chapter 21
L2TP VPN............................................................................................................................................541
21.1 Overview ..................................................................................................................................... 541
21.1.1 What You Can Do in this Chapter ................................................................................... 541
21.1.2 What You Need to Know ................................................................................................. 541
21.2 L2TP VPN Screen ......................................................................................................................... 542
21.2.1 Example: L2TP and Zyxel Device Behind a NAT Router ................................................ 544
Chapter 22
Remote AP VPN................................................................................................................................546
22.1 Overview ..................................................................................................................................... 546
22.2 Configuring a Remote AP ......................................................................................................... 547
22.3 Remote AP VPN Screen ............................................................................................................. 551
Chapter 23
BWM (Bandwidth Management) .................................................................................................552
23.1 Overview ..................................................................................................................................... 552
23.1.1 What You Can Do in this Chapter ................................................................................... 552
23.1.2 What You Need to Know ................................................................................................ 552
23.2 The Bandwidth Management Configuration .......................................................................... 556
23.2.1 The Bandwidth Management Add/Edit Screen ............................................................ 559
Chapter 24
Web Authentication ........................................................................................................................568
24.1 Web Auth Overview ................................................................................................................... 568
24.1.1 What You Can Do in this Chapter ................................................................................... 568
24.1.2 What You Need to Know ................................................................................................. 569
24.2 Web Authentication General Screen ...................................................................................... 570
24.2.1 User-aware Access Control Example ............................................................................. 575
24.2.2 Authentication Type Screen ............................................................................................ 581
24.2.3 Custom Web Portal / User Agreement File Screen ....................................................... 585
24.2.4 Facebook Wi-Fi Screen ..................................................................................................... 586
24.3 SSO Overview .............................................................................................................................. 590
24.4 SSO - Zyxel Device Configuration ............................................................................................. 591
24.4.1 Configuration Overview ................................................................................................... 592
24.4.2 Configure the Zyxel Device to Communicate with SSO .............................................. 592
24.4.3 Enable Web Authentication ............................................................................................ 593
24.4.4 Create a Security Policy ................................................................................................... 594
24.4.5 Configure User Information ..............................................................................................595
24.4.6 Configure an Authentication Method ........................................................................... 596
24.4.7 Configure Active Directory ..............................................................................................597
24.5 SSO Agent Configuration .......................................................................................................... 598
Table of Contents
USG FLEX Series User’s Guide
17
Chapter 25
Hotspot..............................................................................................................................................601
25.1 Overview ..................................................................................................................................... 601
25.2 Billing Overview ........................................................................................................................... 601
25.2.1 What You Need to Know ................................................................................................. 601
25.3 The Billing > General Screen ...................................................................................................... 602
25.4 The Billing > Billing Profile Screen ............................................................................................... 604
25.4.1 The Account Generator Screen ...................................................................................... 605
25.4.2 The Account Redeem Screen ......................................................................................... 608
25.4.3 The Billing Profile Add/Edit Screen ................................................................................... 610
25.5 The Billing > Discount Screen ..................................................................................................... 611
25.5.1 The Discount Add/Edit Screen ......................................................................................... 613
25.6 The Billing > Payment Service Screen ....................................................................................... 613
25.6.1 The Payment Service > Desktop / Mobile View Screen ............................................... 615
Chapter 26
Printer Manager ...............................................................................................................................619
26.1 Printer Manager Overview ........................................................................................................ 619
26.1.1 What You Can Do in this Chapter ................................................................................... 619
26.2 The Printer Manager > General Screen ................................................................................... 619
26.2.1 Add Printer Rule ................................................................................................................. 622
26.2.2 Edit Printer Rule .................................................................................................................. 622
26.2.3 Discover Printer ................................................................................................................. 623
26.2.4 Edit Printer Manager (Discover Printer) .......................................................................... 625
26.3 The Printout Configuration Screen ............................................................................................ 626
26.4 Printer Reports Overview ........................................................................................................... 627
26.4.1 Key Combinations ............................................................................................................. 627
26.4.2 Daily Account Summary .................................................................................................. 627
26.4.3 Monthly Account Summary ............................................................................................. 628
26.4.4 Account Report Notes ..................................................................................................... 628
26.4.5 System Status ..................................................................................................................... 629
Chapter 27
Free Time...........................................................................................................................................631
27.1 Free Time Overview ................................................................................................................... 631
27.1.1 What You Can Do in this Chapter ................................................................................... 631
27.2 The Free Time Screen ................................................................................................................. 631
Chapter 28
IPnP....................................................................................................................................................636
28.1 IPnP Overview ............................................................................................................................ 636
28.1.1 What You Can Do in this Chapter ................................................................................... 637
28.1.2 IPnP Screen ........................................................................................................................ 637
Table of Contents
USG FLEX Series User’s Guide
18
Chapter 29
Walled Garden.................................................................................................................................639
29.1 Walled Garden Overview ........................................................................................................ 639
29.2 Walled Garden > General Screen ........................................................................................... 639
29.3 Walled Garden > URL Base Screen .......................................................................................... 640
29.3.1 Adding/Editing a Walled Garden URL ........................................................................... 641
29.4 Walled Garden > Domain/IP Base Screen .............................................................................. 642
29.4.1 Adding/Editing a Walled Garden Domain or IP ........................................................... 643
29.4.2 Walled Garden Login Example ....................................................................................... 643
Chapter 30
Advertisement Screen.....................................................................................................................645
30.1 Advertisement Overview ........................................................................................................... 645
30.1.1 Adding/Editing an Advertisement URL .......................................................................... 646
Chapter 31
Security Policy..................................................................................................................................648
31.1 Overview ..................................................................................................................................... 648
31.2 One Security ................................................................................................................................ 649
31.3 What You Can Do in this Chapter ............................................................................................ 652
31.3.1 What You Need to Know ................................................................................................. 652
31.4 The Security Policy Screen ......................................................................................................... 654
31.4.1 Configuring the Security Policy Control Screen ............................................................ 655
31.4.2 The Security Check for Web Interface Screen .............................................................. 658
31.4.3 The Security Policy Control Add/Edit Screen ................................................................. 660
31.5 Anomaly Detection and Prevention Overview ...................................................................... 662
31.5.1 The Anomaly Detection and Prevention General Screen ........................................... 662
31.5.2 Creating New ADP Profiles ..............................................................................................664
31.5.3 Traffic Anomaly Profiles ................................................................................................... 665
31.5.4 Protocol Anomaly Profiles ................................................................................................ 668
31.5.5 The ADP Allow List Screen ................................................................................................ 671
31.5.6 Creating New ADP Allow List Rule ................................................................................... 672
31.6 The Session Control Screen ........................................................................................................ 673
31.6.1 The Session Control Add/Edit Screen .............................................................................. 674
31.7 Security Policy Example Applications ......................................................................................675
Chapter 32
Application Patrol............................................................................................................................678
32.1 Overview ..................................................................................................................................... 678
32.1.1 What You Can Do in this Chapter ................................................................................... 678
32.1.2 What You Need to Know ................................................................................................ 678
32.2 Application Patrol Profile ........................................................................................................... 679
32.2.1 Profile Action: Apply to a Security Policy ....................................................................... 680
Table of Contents
USG FLEX Series User’s Guide
19
32.2.2 Application Patrol Profile > Add/Edit - My Application ............................................... 683
32.2.3 Application Patrol Profile > Add/Edit - Query Result ..................................................... 684
Chapter 33
Content Filter ....................................................................................................................................687
33.1 Overview ..................................................................................................................................... 687
33.1.1 What You Can Do in this Chapter ................................................................................... 687
33.1.2 What You Need to Know ................................................................................................. 687
33.1.3 Before You Begin ............................................................................................................... 689
33.2 Web Content Filter General Screen .........................................................................................690
33.2.1 Apply to a Security Policy ................................................................................................ 691
33.2.2 Web Content Filter Add Category Service .................................................................... 694
33.2.3 Content Filter Add Filter Profile Custom Service ........................................................... 707
33.3 Web Content Filter Trusted Web Sites Screen ........................................................................ 709
33.4 Web Content Filter Forbidden Web Sites Screen ................................................................... 711
33.5 DNS Content Filter General Screen .......................................................................................... 712
33.5.1 DNS Content Filter Add Profile ......................................................................................... 713
33.6 DNS Content Filter Allow List Screen ......................................................................................... 726
33.7 DNS Content Filter Block List Screen ......................................................................................... 727
33.8 Content Filter Technical Reference ......................................................................................... 727
Chapter 34
Anti-Malware....................................................................................................................................729
34.1 Overview ..................................................................................................................................... 729
34.1.1 What You Can Do in this Chapter ................................................................................... 733
34.2 Anti-Malware Screen ................................................................................................................. 734
34.3 The Allow List Screen .................................................................................................................. 737
34.4 The Block List Screen .................................................................................................................. 739
34.5 Anti-Malware Signature Searching ........................................................................................... 740
34.6 Anti-Malware Profile ................................................................................................................... 741
34.6.1 Add or Edit an Anti-Malware Profile ............................................................................... 742
34.6.2 Link a Profile ....................................................................................................................... 744
34.6.3 Anti-Malware Advance Screen ...................................................................................... 745
34.6.4 Remove Profiles ................................................................................................................. 747
34.7 Anti-Malware Technical Reference ......................................................................................... 748
Chapter 35
Reputation Filter ...............................................................................................................................750
35.1 Overview ..................................................................................................................................... 750
35.1.1 What You Need to Know ................................................................................................. 750
35.1.2 What You Can Do in this Chapter ................................................................................... 750
35.2 URL Threat Filter Screen .............................................................................................................. 750
35.2.1 URL Threat Filter Allow List Screen .................................................................................... 753
Table of Contents
USG FLEX Series User’s Guide
20
35.2.2 URL Threat Filter Block List Screen .................................................................................... 753
35.2.3 URL Threat Filter External Block List Screen ..................................................................... 754
35.3 URL Threat Filter Profile ................................................................................................................ 756
35.3.1 Add or Edit a URL Threat Filter Profile .............................................................................. 757
35.3.2 Link a Profile ....................................................................................................................... 759
35.3.3 URL Threat Filter Advance Screen ................................................................................... 760
35.3.4 Remove Profiles ................................................................................................................. 762
Chapter 36
IPS......................................................................................................................................................763
36.1 Overview ..................................................................................................................................... 763
36.1.1 What You Can Do in this Chapter ................................................................................... 763
36.1.2 What You Need To Know ................................................................................................. 763
36.1.3 Before You Begin ............................................................................................................... 764
36.2 The IPS Screen ............................................................................................................................. 764
36.2.1 Query Example .................................................................................................................. 771
36.3 IPS Custom Signatures ............................................................................................................... 772
36.3.1 Add / Edit Custom Signatures ......................................................................................... 773
36.3.2 Custom Signature Example ............................................................................................. 777
36.3.3 Applying Custom Signatures ............................................................................................ 779
36.3.4 Verifying Custom Signatures ............................................................................................ 780
36.4 The Allow List Screen ................................................................................................................. 780
36.5 IPS Profile ...................................................................................................................................... 781
36.5.1 Add or Edit an IPS Profile .................................................................................................. 782
36.5.2 Link a Profile ....................................................................................................................... 784
36.5.3 The IPS Advance Screen ..................................................................................................785
36.5.4 Remove Profiles ................................................................................................................. 786
36.6 IPS Technical Reference ............................................................................................................ 787
Chapter 37
Email Security...................................................................................................................................790
37.1 Overview ..................................................................................................................................... 790
37.1.1 What You Can Do in this Chapter ................................................................................... 790
37.1.2 What You Need to Know ................................................................................................. 790
37.2 Before You Begin ........................................................................................................................ 791
37.3 The Email Security Screen ......................................................................................................... 792
37.4 The Allow List Screen .................................................................................................................. 794
37.5 The Block List Screen .................................................................................................................. 795
37.5.1 The Block or Allow List Add/Edit Screen ......................................................................... 796
37.5.2 Regular Expressions in Block or Allow List Entries ............................................................ 798
37.6 Email Security Profile ................................................................................................................... 798
37.6.1 Add or Edit Email Security Profile ..................................................................................... 799
37.6.2 Link a Profile ....................................................................................................................... 801
/