USG110

ZyXEL Communications USG110 User manual

  • Hello! I am an AI chatbot trained to assist you with the ZyXEL Communications USG110 User manual. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
Quick Start Guide
www.zyxel.com
ZyWALL/USG Series
ZyWALL 110 / 310 / 1100
USG40 / USG40W / USG60 / USG60W / USG110 / USG210 /
USG310 / USG1100 / USG1900
UTM Security Firewalls
USG20-VPN / USG20W-VPN / USG2200-VPN
VPN Firewalls
Version 4.20
Edition 1, 8/2016
Copyright © 2016 Zyxel Communications Corporation
User’s Guide
Default Login Details
LAN Port IP Address https://192.168.1.1
User Name admin
Password 1234
ZyWALL/USG Series User’s Guide
2
IMPORTANT!
READ CAREFULLY BEFORE USE.
KEEP THIS GUIDE FOR FUTURE REFERENCE.
This is a User’s Guide for a series of products. Not all products support all firmware features.
Screenshots and graphics in this book may differ slightly from your product due to differences in
your product firmware or your computer operating system. Every effort has been made to ensure
that the information in this manual is accurate.
Related Documentation
•Quick Start Guide
The Quick Start Guide shows how to connect the ZyWALL/USG and access the Web Configurator
wizards. (See the wizard real time help for information on configuring each screen.) It also
contains a connection diagram and package contents list.
• CLI Reference Guide
The CLI Reference Guide explains how to use the Command-Line Interface (CLI) to configure the
ZyWALL/USG.
Note: It is recommended you use the Web Configurator to configure the ZyWALL/USG.
• Web Configurator Online Help
Click the help icon in any screen for help in configuring that screen and supplementary
information.
•More Information
Go to support.zyxel.com to find other information on ZyWALL/USG.
ZyWALL/USG Series User’s Guide
3
Part I: User’s Guide .........................................................................................23
Chapter 1
Introduction.........................................................................................................................................25
1.1 Overview ...........................................................................................................................................25
1.1.1 Applications .............................................................................................................................26
1.2 Management Overview .....................................................................................................................28
1.3 Web Configurator ..............................................................................................................................29
1.3.1 Web Configurator Access ........................................................................................................30
1.3.2 Web Configurator Screens Overview ......................................................................................32
1.3.3 Navigation Panel .....................................................................................................................36
1.3.4 Tables and Lists .......................................................................................................................43
Chapter 2
Installation Setup Wizard...................................................................................................................46
2.1 Installation Setup Wizard Screens ...................................................................................................46
2.1.1 Internet Access Setup - WAN Interface ..................................................................................46
2.1.2 Internet Access: Ethernet .......................................................................................................47
2.1.3 Internet Access: PPPoE ..........................................................................................................48
2.1.4 Internet Access: PPTP ...........................................................................................................50
2.1.5 Internet Access: L2TP .............................................................................................................51
2.1.6 Internet Access Setup - Second WAN Interface ......................................................................53
2.1.7 Internet Access Succeed ........................................................................................................53
2.1.8 Wireless Settings: AP Controller ............................................................................................54
2.1.9 Wireless Settings: SSID & Security ........................................................................................54
2.1.10 Internet Access - Device Registration ..................................................................................55
Chapter 3
Hardware, Interfaces and Zones .......................................................................................................57
3.1 Hardware Overview ...........................................................................................................................57
3.1.1 Front Panels ............................................................................................................................57
3.1.2 Rear Panels .............................................................................................................................61
3.2 Mounting ...........................................................................................................................................63
3.2.1 Rack-mounting ........................................................................................................................63
3.2.2 USG2200-VPN Rack Mounting ...............................................................................................64
3.2.3 Wall-mounting ..........................................................................................................................67
3.3 Default Zones, Interfaces, and Ports .................................................................................................68
3.4 Stopping the ZyWALL/USG ..............................................................................................................70
Chapter 4
Easy Mode...........................................................................................................................................71
4.1 Overview ..........................................................................................................................................71
4.1.1 Wizards and Links ...................................................................................................................71
ZyWALL/USG Series User’s Guide
4
4.1.2 Easy Mode Settings .................................................................................................................72
4.1.3 Easy Mode Dashboard ............................................................................................................73
4.2 Initial Setup Wizard Screen 1 - Language and Overview ................................................................75
4.2.1 Initial Setup Wizard Screen 2 - Internet ...............................................................................77
4.2.2 Initial Setup Wizard Screen 2 - Internet Access Errors ........................................................78
4.2.3 Initial Setup Wizard Screen 3 - Date and Time .....................................................................79
4.2.4 Initial Setup Wizard Screen 4 - Wi-Fi ....................................................................................80
4.2.5 Initial Setup Wizard Screen 5 - Register ...............................................................................81
4.2.6 Initial Setup Wizard Screen 6 - Congratulations ...................................................................82
4.3 Initial Setup Wizard Screen 7 - Security Service ...........................................................................83
4.4 Initial Setup Wizard Screen 8 - Port Forwarding .............................................................................85
4.5 Initial Setup Wizard Screen 9 - Guest LAN ....................................................................................86
4.5.1 Connecting AP Scenarios ........................................................................................................87
4.6 Initial Setup Wizard Screen 10 - VPN .............................................................................................88
4.6.1 VPN Setup Wizard: Wizard Type ...........................................................................................89
4.6.2 VPN Express Wizard - Scenario ............................................................................................89
4.6.3 VPN Express Wizard - Configuration ....................................................................................91
4.6.4 VPN Express Wizard - Summary ..........................................................................................92
4.6.5 VPN Express Wizard - Finish ................................................................................................92
4.6.6 VPN Advanced Wizard - Scenario ........................................................................................93
4.6.7 VPN Advanced Wizard - Phase 1 Settings ............................................................................94
4.6.8 VPN Advanced Wizard - Phase 2 ..........................................................................................96
4.6.9 VPN Advanced Wizard - Summary .......................................................................................97
4.6.10 VPN Advanced Wizard - Finish ...........................................................................................98
4.7 VPN Settings for Configuration Provisioning Wizard: Wizard Type ................................................98
4.7.1 Configuration Provisioning Express Wizard - VPN Settings ..................................................99
4.7.2 Configuration Provisioning VPN Express Wizard - Configuration .......................................100
4.7.3 VPN Settings for Configuration Provisioning Express Wizard - Summary ..........................101
4.7.4 VPN Settings for Configuration Provisioning Express Wizard - Finish .................................102
4.7.5 VPN Settings for Configuration Provisioning Advanced Wizard - Scenario ........................103
4.7.6 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 1 Settings ............104
4.7.7 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 2 .........................106
4.7.8 VPN Settings for Configuration Provisioning Advanced Wizard - Summary .......................106
4.7.9 VPN Settings for Configuration Provisioning Advanced Wizard- Finish ..............................108
4.8 VPN Settings for L2TP VPN Settings Wizard ...............................................................................109
4.8.1 L2TP VPN Settings 1 ............................................................................................................. 110
4.8.2 L2TP VPN Settings 2 ............................................................................................................ 111
4.8.3 VPN Settings for L2TP VPN Setting Wizard - Summary ..................................................... 112
4.8.4 VPN Settings for L2TP VPN Setting Wizard Completed ..................................................... 113
4.9 Port Forwarding ............................................................................................................................. 114
4.9.1 Port Forwarding > Add Client .............................................................................................. 115
4.9.2 Port Forwarding > Add Service ............................................................................................ 115
4.9.3 Port Forwarding > UPnP ...................................................................................................... 115
ZyWALL/USG Series User’s Guide
5
4.10 Wi-Fi and Guest Network Wizard ............................................................................................... 117
4.10.1 Guest LAN (Wired Network) .............................................................................................. 118
4.10.2 Connecting AP Scenarios .................................................................................................... 119
4.11 Security Service Wizard ............................................................................................................120
4.11.1 Security Service Wizard 2 - Content Filter Categories .....................................................121
4.11.2 Security Service Wizard 3 - Websites ..............................................................................123
4.11.3 Security Service Wizard 4 - Exemptions ..........................................................................124
4.11.4 Security Service Wizard 5 - IDP/AV .................................................................................125
4.12 MyZyXEL Portal ........................................................................................................................126
4.13 One Security Portal ...................................................................................................................127
Chapter 5
Quick Setup Wizards........................................................................................................................129
5.1 Quick Setup Overview .....................................................................................................................129
5.2 WAN Interface Quick Setup ............................................................................................................130
5.2.1 Choose an Ethernet Interface ................................................................................................130
5.2.2 Select WAN Type ...................................................................................................................131
5.2.3 Configure WAN IP Settings ...................................................................................................131
5.2.4 ISP and WAN and ISP Connection Settings ..........................................................................132
5.2.5 Quick Setup Interface Wizard: Summary ..............................................................................134
5.3 VPN Setup Wizard ..........................................................................................................................135
5.3.1 Welcome ................................................................................................................................136
5.3.2 VPN Setup Wizard: Wizard Type ...........................................................................................137
5.3.3 VPN Express Wizard - Scenario ...........................................................................................137
5.3.4 VPN Express Wizard - Configuration ...................................................................................139
5.3.5 VPN Express Wizard - Summary .........................................................................................139
5.3.6 VPN Express Wizard - Finish ...............................................................................................140
5.3.7 VPN Advanced Wizard - Scenario .......................................................................................141
5.3.8 VPN Advanced Wizard - Phase 1 Settings ...........................................................................143
5.3.9 VPN Advanced Wizard - Phase 2 .........................................................................................144
5.3.10 VPN Advanced Wizard - Summary ....................................................................................145
5.3.11 VPN Advanced Wizard - Finish ...........................................................................................146
5.4 VPN Settings for Configuration Provisioning Wizard: Wizard Type ................................................146
5.4.1 Configuration Provisioning Express Wizard - VPN Settings .................................................147
5.4.2 Configuration Provisioning VPN Express Wizard - Configuration ........................................148
5.4.3 VPN Settings for Configuration Provisioning Express Wizard - Summary ...........................149
5.4.4 VPN Settings for Configuration Provisioning Express Wizard - Finish .................................150
5.4.5 VPN Settings for Configuration Provisioning Advanced Wizard - Scenario .........................151
5.4.6 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 1 Settings ............152
5.4.7 VPN Settings for Configuration Provisioning Advanced Wizard - Phase 2 ..........................154
5.4.8 VPN Settings for Configuration Provisioning Advanced Wizard - Summary ........................154
5.4.9 VPN Settings for Configuration Provisioning Advanced Wizard- Finish ...............................156
5.5 VPN Settings for L2TP VPN Settings Wizard .................................................................................157
ZyWALL/USG Series User’s Guide
6
5.5.1 L2TP VPN Settings ................................................................................................................158
5.5.2 L2TP VPN Settings ................................................................................................................159
5.5.3 VPN Settings for L2TP VPN Setting Wizard - Summary ......................................................160
5.5.4 VPN Settings for L2TP VPN Setting Wizard Completed ......................................................161
Chapter 6
Dashboard.........................................................................................................................................162
6.1 Overview .........................................................................................................................................162
6.1.1 What You Can Do in this Chapter ..........................................................................................162
6.2 Main Dashboard Screen .................................................................................................................162
6.2.1 Device Information Screen ....................................................................................................164
6.2.2 System Status Screen ...........................................................................................................165
6.2.3 VPN Status Screen ................................................................................................................166
6.2.4 DHCP Table Screen ..............................................................................................................168
6.2.5 Number of Login Users Screen .............................................................................................169
6.2.6 System Resources Screen ....................................................................................................169
6.2.7 CPU Usage Screen ...............................................................................................................170
6.2.8 Memory Usage Screen ..........................................................................................................171
6.2.9 Active Session Screen ...........................................................................................................172
6.2.10 Extension Slot Screen .........................................................................................................173
6.2.11 Interface Status Summary Screen .......................................................................................173
6.2.12 Secured Service Status Screen ...........................................................................................175
6.2.13 Content Filter Statistics Screen ...........................................................................................176
6.2.14 Top 5 Viruses Screen ...........................................................................................................176
6.2.15 Top 5 Intrusions Screen .......................................................................................................177
6.2.16 Top 5 IPv4/IPv6 Security Policy Rules that Blocked Traffic Screen .....................................177
6.2.17 The Latest Alert Logs Screen ..............................................................................................178
Part II: Technical Reference..........................................................................179
Chapter 7
Monitor...............................................................................................................................................181
7.1 Overview .........................................................................................................................................181
7.1.1 What You Can Do in this Chapter ..........................................................................................181
7.2 The Port Statistics Screen ..............................................................................................................182
7.2.1 The Port Statistics Graph Screen .........................................................................................184
7.3 Interface Status Screen ...................................................................................................................185
7.4 The Traffic Statistics Screen ............................................................................................................187
7.5 The Session Monitor Screen ..........................................................................................................190
7.6 IGMP Statistics ................................................................................................................................191
7.7 The DDNS Status Screen ...............................................................................................................192
ZyWALL/USG Series User’s Guide
7
7.8 IP/MAC Binding ...............................................................................................................................193
7.9 The Login Users Screen ................................................................................................................193
7.10 The Dynamic Guest Screen .........................................................................................................194
7.11 Cellular Status Screen ...................................................................................................................196
7.11.1 More Information ..................................................................................................................198
7.12 The UPnP Port Status Screen ......................................................................................................199
7.13 USB Storage Screen .....................................................................................................................200
7.14 Ethernet Neighbor Screen ............................................................................................................201
7.15 Wireless .......................................................................................................................................202
7.15.1 Wireless AP Information: AP List .........................................................................................202
7.15.2 AP List More Information ...................................................................................................204
7.15.3 Config AP ...........................................................................................................................206
7.15.4 Wireless AP Information: Radio List ....................................................................................207
7.15.5 Radio List More Information ................................................................................................209
7.15.6 Wireless Station Info ............................................................................................................210
7.15.7 Detected Device ................................................................................................................. 211
7.16 The Printer Status Screen ............................................................................................................212
7.17 The IPSec Monitor Screen ............................................................................................................213
7.17.1 Regular Expressions in Searching IPSec SAs ....................................................................214
7.18 The SSL Screen ............................................................................................................................214
7.19 The L2TP over IPSec Session Monitor Screen .............................................................................215
7.20 The App Patrol Screen ..................................................................................................................215
7.21 The Content Filter Screen .............................................................................................................217
7.22 The IDP Screen .............................................................................................................................218
7.23 The Anti-Virus Screen ...................................................................................................................220
7.24 The Anti-Spam Screens ................................................................................................................222
7.24.1 Anti-Spam Report ................................................................................................................222
7.24.2 The Anti-Spam Status Screen .............................................................................................225
7.25 The SSL Inspection Screens .........................................................................................................226
7.25.1 Certificate Cache List ..........................................................................................................227
7.26 Log Screens ..................................................................................................................................228
7.26.1 View Log ..............................................................................................................................228
7.26.2 View AP Log ........................................................................................................................230
7.26.3 Dynamic Users Log .............................................................................................................233
Chapter 8
Licensing...........................................................................................................................................235
8.1 Registration Overview .....................................................................................................................235
8.1.1 What you Need to Know ........................................................................................................235
8.1.2 Registration Screen ...............................................................................................................236
8.1.3 Service Screen ......................................................................................................................236
8.2 Signature Update ............................................................................................................................237
8.2.1 What you Need to Know ........................................................................................................237
ZyWALL/USG Series User’s Guide
8
8.2.2 The Anti-Virus Update Screen ...............................................................................................237
8.2.3 The IDP/AppPatrol Update Screen ........................................................................................239
Chapter 9
Wireless.............................................................................................................................................241
9.1 Overview .........................................................................................................................................241
9.1.1 What You Can Do in this Chapter ..........................................................................................241
9.2 Controller Screen ...........................................................................................................................241
9.3 AP Management Screens ...............................................................................................................242
9.3.1 Mgnt. AP List ........................................................................................................................242
9.3.2 AP Policy ...............................................................................................................................246
9.3.3 AP Group ...............................................................................................................................247
9.3.4 Firmware ................................................................................................................................251
9.4 MON Mode ......................................................................................................................................253
9.4.1 Add/Edit Rogue/Friendly List .................................................................................................254
9.5 Auto Healing ....................................................................................................................................255
9.6 RTLS Overview ...............................................................................................................................256
9.6.1 What You Can Do in this Chapter ..........................................................................................257
9.6.2 Before You Begin ...................................................................................................................257
9.6.3 Configuring RTLS ..................................................................................................................257
9.7 Technical Reference ........................................................................................................................258
9.7.1 Dynamic Channel Selection ..................................................................................................258
9.7.2 Load Balancing ......................................................................................................................259
Chapter 10
Interfaces...........................................................................................................................................261
10.1 Interface Overview ........................................................................................................................261
10.1.1 What You Can Do in this Chapter ........................................................................................261
10.1.2 What You Need to Know ......................................................................................................262
10.1.3 What You Need to Do First ..................................................................................................266
10.2 Port Role Screen ...........................................................................................................................266
10.3 Ethernet Summary Screen ............................................................................................................267
10.3.1 Ethernet Edit .......................................................................................................................269
10.3.2 Virtual Interfaces .................................................................................................................285
10.3.3 Virtual Interfaces Add/Edit ...................................................................................................285
10.3.4 Object References ...............................................................................................................286
10.3.5 Add/Edit DHCPv6 Request/Release Options ......................................................................287
10.3.6 Add/Edit DHCP Extended Options ......................................................................................287
10.4 PPP Interfaces ..............................................................................................................................289
10.4.1 PPP Interface Summary ......................................................................................................290
10.4.2 PPP Interface Add or Edit ...................................................................................................291
10.5 Cellular Configuration Screen .......................................................................................................296
10.5.1 Cellular Choose Slot ...........................................................................................................299
ZyWALL/USG Series User’s Guide
9
10.5.2 Add / Edit Cellular Configuration .........................................................................................299
10.6 Tunnel Interfaces ..........................................................................................................................305
10.6.1 Configuring a Tunnel ...........................................................................................................307
10.6.2 Tunnel Add or Edit Screen ...................................................................................................308
10.7 VLAN Interfaces ...........................................................................................................................312
10.7.1 VLAN Summary Screen ......................................................................................................313
10.7.2 VLAN Add/Edit ....................................................................................................................315
10.8 Bridge Interfaces ..........................................................................................................................324
10.8.1 Bridge Summary ..................................................................................................................326
10.8.2 Bridge Add/Edit ...................................................................................................................327
10.9 LAG ..............................................................................................................................................336
10.9.1 LAG Summary Screen .........................................................................................................336
10.9.2 LAG Add/Edit ......................................................................................................................338
10.10 VTI ...............................................................................................................................................343
10.10.1 Restrictions for IPsec Virtual Tunnel Interface ...................................................................343
10.10.2 VTI Screen .........................................................................................................................344
10.10.3 VTI Add/Edit ......................................................................................................................344
10.11 Trunk Overview ..........................................................................................................................346
10.11.1 What You Need to Know ....................................................................................................347
10.12 The Trunk Summary Screen .......................................................................................................349
10.12.1 Configuring a User-Defined Trunk .....................................................................................351
10.12.2 Configuring the System Default Trunk ..............................................................................353
10.13 Interface Technical Reference .....................................................................................................354
Chapter 11
Routing ..............................................................................................................................................359
11.1 Policy and Static Routes Overview ................................................................................................359
11.1.1 What You Can Do in this Chapter ........................................................................................359
11.1.2 What You Need to Know .....................................................................................................360
11.2 Policy Route Screen ......................................................................................................................361
11.2.1 Policy Route Edit Screen .....................................................................................................363
11.3 IP Static Route Screen ..................................................................................................................368
11.3.1 Static Route Add/Edit Screen ...............................................................................................368
11.4 Policy Routing Technical Reference ..............................................................................................370
11.5 Routing Protocols Overview .........................................................................................................371
11.5.1 What You Need to Know ......................................................................................................371
11.6 The RIP Screen .............................................................................................................................371
11.7 The OSPF Screen .........................................................................................................................373
11.7.1 Configuring the OSPF Screen .............................................................................................376
11.7.2 OSPF Area Add/Edit Screen ...............................................................................................377
11.7.3 Virtual Link Add/Edit Screen ...............................................................................................379
11.8 Routing Protocol Technical Reference ..........................................................................................380
ZyWALL/USG Series User’s Guide
10
Chapter 12
DDNS................................................................................................................................................382
12.1 DDNS Overview ............................................................................................................................382
12.1.1 What You Can Do in this Chapter ........................................................................................382
12.1.2 What You Need to Know ......................................................................................................382
12.2 The DDNS Screen ........................................................................................................................383
12.2.1 The Dynamic DNS Add/Edit Screen ....................................................................................384
Chapter 13
NAT.....................................................................................................................................................388
13.1 NAT Overview ...............................................................................................................................388
13.1.1 What You Can Do in this Chapter ........................................................................................388
13.1.2 What You Need to Know ......................................................................................................388
13.2 The NAT Screen ............................................................................................................................388
13.2.1 The NAT Add/Edit Screen ....................................................................................................390
13.3 NAT Technical Reference ..............................................................................................................393
Chapter 14
Redirect Service................................................................................................................................395
14.1 Overview .......................................................................................................................................395
14.1.1 HTTP Redirect .....................................................................................................................395
14.1.2 SMTP Redirect ....................................................................................................................395
14.1.3 What You Can Do in this Chapter ........................................................................................396
14.1.4 What You Need to Know ......................................................................................................396
14.2 The Redirect Service Screen ........................................................................................................398
14.2.1 The Redirect Service Edit Screen .......................................................................................399
Chapter 15
ALG ....................................................................................................................................................401
15.1 ALG Overview ...............................................................................................................................401
15.1.1 What You Need to Know ......................................................................................................401
15.1.2 Before You Begin .................................................................................................................404
15.2 The ALG Screen ...........................................................................................................................404
15.3 ALG Technical Reference .............................................................................................................407
Chapter 16
UPnP ..................................................................................................................................................409
16.1 UPnP and NAT-PMP Overview .....................................................................................................409
16.2 What You Need to Know ...............................................................................................................409
16.2.1 NAT Traversal ......................................................................................................................409
16.2.2 Cautions with UPnP and NAT-PMP .....................................................................................410
16.3 UPnP Screen ................................................................................................................................410
16.4 Technical Reference ...................................................................................................................... 411
ZyWALL/USG Series User’s Guide
11
16.4.1 Turning on UPnP in Windows 7 Example ............................................................................ 411
16.4.2 Using UPnP in Windows XP Example .................................................................................413
16.4.3 Web Configurator Easy Access ...........................................................................................415
Chapter 17
IP/MAC Binding.................................................................................................................................418
17.1 IP/MAC Binding Overview .............................................................................................................418
17.1.1 What You Can Do in this Chapter ........................................................................................418
17.1.2 What You Need to Know ......................................................................................................418
17.2 IP/MAC Binding Summary ............................................................................................................419
17.2.1 IP/MAC Binding Edit ............................................................................................................419
17.2.2 Static DHCP Edit .................................................................................................................420
17.3 IP/MAC Binding Exempt List .........................................................................................................421
Chapter 18
Layer 2 Isolation ...............................................................................................................................423
18.1 Overview .......................................................................................................................................423
18.1.1 What You Can Do in this Chapter ........................................................................................423
18.2 Layer-2 Isolation General Screen ................................................................................................424
18.3 White List Screen ..........................................................................................................................424
18.3.1 Add/Edit White List Rule .....................................................................................................425
Chapter 19
DNS Inbound LB ...............................................................................................................................427
19.1 DNS Inbound Load Balancing Overview .......................................................................................427
19.1.1 What You Can Do in this Chapter ........................................................................................427
19.2 The DNS Inbound LB Screen ........................................................................................................428
19.2.1 The DNS Inbound LB Add/Edit Screen ...............................................................................429
19.2.2 The DNS Inbound LB Add/Edit Member Screen .................................................................431
Chapter 20
Web Authentication .........................................................................................................................433
20.1 Web Auth Overview ......................................................................................................................433
20.1.1 What You Can Do in this Chapter ........................................................................................433
20.1.2 What You Need to Know ......................................................................................................434
20.2 Web Authentication General Screen .............................................................................................434
20.2.1 User-aware Access Control Example ..................................................................................439
20.2.2 Authentication Type Screen .................................................................................................445
20.2.3 Custom Web Portal / User Agreement File Screen .............................................................449
20.3 SSO Overview ...............................................................................................................................450
20.4 SSO - ZyWALL/USG Configuration ..............................................................................................452
20.4.1 Configuration Overview .......................................................................................................452
20.4.2 Configure the ZyWALL/USG to Communicate with SSO ....................................................452
ZyWALL/USG Series User’s Guide
12
20.4.3 Enable Web Authentication .................................................................................................453
20.4.4 Create a Security Policy ......................................................................................................454
20.4.5 Configure User Information .................................................................................................455
20.4.6 Configure an Authentication Method ...................................................................................456
20.4.7 Configure Active Directory ...................................................................................................457
20.5 SSO Agent Configuration ..............................................................................................................458
Chapter 21
Hotspot ..............................................................................................................................................462
21.1 Overview .......................................................................................................................................462
21.2 Billing Overview .............................................................................................................................462
21.2.1 What You Need to Know ......................................................................................................462
21.3 The General Screen ......................................................................................................................463
21.4 The Billing Profile Screen ..............................................................................................................466
21.4.1 The Account Generator Screen ...........................................................................................467
21.4.2 The Account Redeem Screen .............................................................................................470
21.4.3 The Billing Profile Add/Edit Screen ......................................................................................472
21.5 The Discount Screen .....................................................................................................................473
21.5.1 The Discount Add/Edit Screen ............................................................................................475
21.6 The Payment Service General Screen ..........................................................................................475
21.6.1 The Payment Service Desktop View / Mobile View Screen .................................................477
Chapter 22
Printer Manager ................................................................................................................................481
22.1 Printer Manager Overview ............................................................................................................481
22.1.1 What You Can Do in this Chapter ........................................................................................481
22.2 The General Setting Screen ..........................................................................................................481
22.2.1 Add Printer Rule ..................................................................................................................484
22.2.2 Edit Printer Rule ..................................................................................................................484
22.2.3 Discover Printer ..................................................................................................................485
22.2.4 Edit Printer Manager (Discover Printer) ..............................................................................486
22.3 The Printout Configuration Screen ................................................................................................487
22.4 Printer Reports Overview ..............................................................................................................488
22.4.1 Key Combinations ...............................................................................................................488
22.4.2 Daily Account Summary ......................................................................................................489
22.4.3 Monthly Account Summary ..................................................................................................489
22.4.4 Account Report Notes .........................................................................................................490
22.4.5 System Status ......................................................................................................................490
Chapter 23
FreeTime............................................................................................................................................492
23.1 Free Time Overview .....................................................................................................................492
23.1.1 What You Can Do in this Chapter ........................................................................................492
ZyWALL/USG Series User’s Guide
13
23.2 The Free Time Screen ..................................................................................................................492
Chapter 24
SMS....................................................................................................................................................496
24.1 SMS Overview ............................................................................................................................496
24.1.1 What You Can Do in this Chapter ........................................................................................496
24.2 The SMS Screen ...........................................................................................................................496
Chapter 25
IPnP....................................................................................................................................................498
25.1 IPnP Overview ..............................................................................................................................498
25.1.1 What You Can Do in this Chapter ........................................................................................498
25.2 IPnP Screen ..................................................................................................................................499
Chapter 26
Walled Garden...................................................................................................................................500
26.1 Walled Garden Overview ..............................................................................................................500
26.2 General Screen .............................................................................................................................500
26.3 URL Base Screen .........................................................................................................................501
26.3.1 Adding/Editing a Walled Garden URL ................................................................................502
26.4 Domain/IP Base Screen ................................................................................................................503
26.4.1 Adding/Editing a Walled Garden Domain or IP ...................................................................504
26.4.2 Walled Garden Login Example ............................................................................................504
Chapter 27
Advertisement Screen......................................................................................................................506
27.1 Advertisement Overview ...............................................................................................................506
27.1.1 Adding/Editing an Advertisement URL ...............................................................................507
Chapter 28
Security Policy..................................................................................................................................508
28.1 Overview .......................................................................................................................................508
28.2 One Security .................................................................................................................................509
28.3 What You Can Do in this Chapter .................................................................................................512
28.3.1 What You Need to Know ......................................................................................................513
28.4 The Security Policy Screen ...........................................................................................................514
28.4.1 Configuring the Security Policy Control Screen ...................................................................515
28.4.2 The Security Policy Control Add/Edit Screen ......................................................................518
28.5 Anomaly Detection and Prevention Overview ...............................................................................520
28.5.1 The Anomaly Detection and Prevention General Screen ....................................................521
28.5.2 Creating New ADP Profiles ................................................................................................522
28.5.3 Traffic Anomaly Profiles ......................................................................................................523
28.5.4 Protocol Anomaly Profiles ...................................................................................................526
ZyWALL/USG Series User’s Guide
14
28.6 The Session Control Screen .........................................................................................................529
28.6.1 The Session Control Add/Edit Screen .................................................................................530
28.7 Security Policy Example Applications ...........................................................................................531
Chapter 29
IPSec VPN..........................................................................................................................................534
29.1 Virtual Private Networks (VPN) Overview .....................................................................................534
29.1.1 What You Can Do in this Chapter ........................................................................................536
29.1.2 What You Need to Know ......................................................................................................537
29.1.3 Before You Begin .................................................................................................................539
29.2 The VPN Connection Screen ........................................................................................................539
29.2.1 The VPN Connection Add/Edit Screen ................................................................................541
29.3 The VPN Gateway Screen ............................................................................................................548
29.3.1 The VPN Gateway Add/Edit Screen ....................................................................................549
29.4 VPN Concentrator ........................................................................................................................556
29.4.1 VPN Concentrator Requirements and Suggestions ............................................................556
29.4.2 VPN Concentrator Screen ...................................................................................................557
29.4.3 The VPN Concentrator Add/Edit Screen .............................................................................557
29.5 ZyWALL/USG IPSec VPN Client Configuration Provisioning .......................................................558
29.6 IPSec VPN Background Information .............................................................................................560
Chapter 30
SSL VPN ............................................................................................................................................570
30.1 Overview .......................................................................................................................................570
30.1.1 What You Can Do in this Chapter ........................................................................................570
30.1.2 What You Need to Know ......................................................................................................570
30.2 The SSL Access Privilege Screen ................................................................................................571
30.2.1 The SSL Access Privilege Policy Add/Edit Screen .............................................................572
30.3 The SSL Global Setting Screen ....................................................................................................575
30.3.1 How to Upload a Custom Logo ............................................................................................576
30.4 ZyWALL/USG SecuExtender ........................................................................................................577
30.4.1 Example: Configure ZyWALL/USG for SecuExtender .........................................................578
Chapter 31
SSL User Screens............................................................................................................................581
31.1 Overview .......................................................................................................................................581
31.1.1 What You Need to Know ......................................................................................................581
31.2 Remote SSL User Login ...............................................................................................................582
31.3 The SSL VPN User Screens .........................................................................................................585
31.4 Bookmarking the ZyWALL/USG ....................................................................................................586
31.5 Logging Out of the SSL VPN User Screens ..................................................................................587
31.6 SSL User Application Screen ........................................................................................................587
31.7 SSL User File Sharing ...................................................................................................................588
ZyWALL/USG Series User’s Guide
15
31.7.1 The Main File Sharing Screen .............................................................................................588
31.7.2 Opening a File or Folder ......................................................................................................589
31.7.3 Downloading a File ..............................................................................................................590
31.7.4 Saving a File ........................................................................................................................590
31.7.5 Creating a New Folder .........................................................................................................591
31.7.6 Renaming a File or Folder ...................................................................................................591
31.7.7 Deleting a File or Folder ......................................................................................................592
31.7.8 Uploading a File ...................................................................................................................592
Chapter 32
ZyWALL/USG SecuExtender (Windows) ........................................................................................594
32.1 The ZyWALL/USG SecuExtender Icon .........................................................................................594
32.2 Status ............................................................................................................................................594
32.3 View Log .......................................................................................................................................595
32.4 Suspend and Resume the Connection .........................................................................................596
32.5 Stop the Connection ......................................................................................................................596
32.6 Uninstalling the ZyWALL/USG SecuExtender ...............................................................................596
Chapter 33
L2TP VPN...........................................................................................................................................598
33.1 Overview .......................................................................................................................................598
33.1.1 What You Can Do in this Chapter ........................................................................................598
33.1.2 What You Need to Know ......................................................................................................598
33.2 L2TP VPN Screen .........................................................................................................................599
33.2.1 Example: L2TP and ZyWALL/USG Behind a NAT Router ...................................................601
Chapter 34
BWM (Bandwidth Management) ...................................................................................................603
34.1 Overview .......................................................................................................................................603
34.1.1 What You Can Do in this Chapter ........................................................................................603
34.1.2 What You Need to Know .....................................................................................................603
34.2 The Bandwidth Management Screen ............................................................................................607
34.2.1 The Bandwidth Management Add/Edit Screen ....................................................................610
Chapter 35
Application Patrol.............................................................................................................................618
35.1 Overview .......................................................................................................................................618
35.1.1 What You Can Do in this Chapter ........................................................................................618
35.1.2 What You Need to Know .....................................................................................................618
35.2 Application Patrol Profile ...............................................................................................................619
35.2.1 The Application Patrol Profile Add/Edit Screen ...................................................................621
35.2.2 The Application Patrol Profile Rule Add Application Screen ...............................................622
ZyWALL/USG Series User’s Guide
16
Chapter 36
Content Filtering...............................................................................................................................624
36.1 Overview .......................................................................................................................................624
36.1.1 What You Can Do in this Chapter ........................................................................................624
36.1.2 What You Need to Know ......................................................................................................624
36.1.3 Before You Begin .................................................................................................................626
36.2 Content Filter Profile Screen .........................................................................................................626
36.3 Content Filter Profile Add or Edit Screen ......................................................................................628
36.3.1 Content Filter Add Profile Category Service ........................................................................628
36.3.2 Content Filter Add Filter Profile Custom Service ................................................................636
36.4 Content Filter Trusted Web Sites Screen .....................................................................................639
36.5 Content Filter Forbidden Web Sites Screen .................................................................................640
36.6 Content Filter Technical Reference ...............................................................................................641
Chapter 37
IDP......................................................................................................................................................643
37.1 Overview .......................................................................................................................................643
37.1.1 What You Can Do in this Chapter ........................................................................................643
37.1.2 What You Need To Know .....................................................................................................643
37.1.3 Before You Begin .................................................................................................................643
37.2 The IDP Profile Screen .................................................................................................................644
37.2.1 Base Profiles .......................................................................................................................645
37.2.2 Adding / Editing Profiles .....................................................................................................646
37.2.3 Profile > Group View Screen ...............................................................................................647
37.2.4 Add Profile > Query View ...................................................................................................650
37.2.5 Query Example ....................................................................................................................654
37.3 IDP Custom Signatures ................................................................................................................655
37.3.1 Add / Edit Custom Signatures ............................................................................................658
37.3.2 Custom Signature Example .................................................................................................662
37.3.3 Applying Custom Signatures ...............................................................................................664
37.3.4 Verifying Custom Signatures ...............................................................................................665
37.4 IDP Technical Reference ...............................................................................................................665
Chapter 38
Anti-Virus...........................................................................................................................................668
38.1 Overview .......................................................................................................................................668
38.1.1 What You Can Do in this Chapter ........................................................................................668
38.1.2 What You Need to Know ......................................................................................................669
38.2 Anti-Virus Profile Screen ...............................................................................................................670
38.2.1 Anti-Virus Profile Add or Edit ...............................................................................................672
38.3 Anti-Virus Black List ......................................................................................................................674
38.3.1 Anti-Virus Black List or White List Add/Edit .........................................................................675
38.3.2 Anti-Virus White List ............................................................................................................676
ZyWALL/USG Series User’s Guide
17
38.4 AV Signature Searching ................................................................................................................677
38.5 Anti-Virus Technical Reference .....................................................................................................678
Chapter 39
Anti-Spam..........................................................................................................................................680
39.1 Overview .......................................................................................................................................680
39.1.1 What You Can Do in this Chapter ........................................................................................680
39.1.2 What You Need to Know ......................................................................................................680
39.2 Before You Begin ..........................................................................................................................681
39.3 The Anti-Spam Profile Screen .......................................................................................................682
39.3.1 The Anti-Spam Profile Add or Edit Screen ..........................................................................683
39.4 The Mail Scan Screen ...................................................................................................................685
39.5 The Anti-Spam Black List Screen ..................................................................................................687
39.5.1 The Anti-Spam Black or White List Add/Edit Screen ...........................................................689
39.5.2 Regular Expressions in Black or White List Entries .............................................................690
39.6 The Anti-Spam White List Screen .................................................................................................690
39.7 The DNSBL Screen .......................................................................................................................692
39.8 Anti-Spam Technical Reference ....................................................................................................694
Chapter 40
SSL Inspection..................................................................................................................................698
40.1 Overview .......................................................................................................................................698
40.1.1 What You Can Do in this Chapter ........................................................................................698
40.1.2 What You Need To Know .....................................................................................................698
40.1.3 Before You Begin .................................................................................................................699
40.2 The SSL Inspection Profile Screen ...............................................................................................699
40.2.1 Add / Edit SSL Inspection Profiles ......................................................................................700
40.3 Exclude List Screen .....................................................................................................................702
40.4 Certificate Update Screen ............................................................................................................704
40.5 Install a CA Certificate in a Browser ..............................................................................................705
Chapter 41
Device HA..........................................................................................................................................707
41.1 Overview .......................................................................................................................................707
41.1.1 What You Can Do in These Screens ...................................................................................707
41.2 Device HA General .......................................................................................................................708
41.2.1 Before You Begin .................................................................................................................708
41.3 Device HA Pro ...............................................................................................................................710
41.3.1 Deploying Device HA Pro .................................................................................................... 711
41.3.2 Configuring Device HA Pro .................................................................................................. 711
41.4 The Active-Passive Mode Screen .................................................................................................713
41.4.1 Configuring Active-Passive Mode Device HA ......................................................................715
41.5 Active-Passive Mode Edit Monitored Interface .............................................................................718
ZyWALL/USG Series User’s Guide
18
41.6 Device HA Technical Reference ....................................................................................................719
Chapter 42
Object.................................................................................................................................................723
42.1 Zones Overview ............................................................................................................................723
42.1.1 What You Need to Know ......................................................................................................723
42.1.2 The Zone Screen .................................................................................................................724
42.2 User/Group Overview ....................................................................................................................725
42.2.1 What You Need To Know .....................................................................................................726
42.2.2 User/Group User Summary Screen .....................................................................................728
42.2.3 User/Group Group Summary Screen ..................................................................................731
42.2.4 User/Group Setting Screen ................................................................................................733
42.2.5 User/Group MAC Address Summary Screen .....................................................................737
42.2.6 User /Group Technical Reference .......................................................................................739
42.3 AP Profile Overview ......................................................................................................................740
42.3.1 Radio Screen .......................................................................................................................741
42.3.2 SSID Screen .......................................................................................................................746
42.4 MON Profile ..................................................................................................................................755
42.4.1 Overview ..............................................................................................................................755
42.4.2 MON Profile .........................................................................................................................755
42.4.3 Technical Reference ............................................................................................................758
42.5 Application .....................................................................................................................................759
42.5.1 Add Application Rule ...........................................................................................................761
42.5.2 Application Group Screen ...................................................................................................764
42.6 Address/Geo IP Overview .............................................................................................................765
42.6.1 What You Need To Know .....................................................................................................766
42.6.2 Address Summary Screen ...................................................................................................766
42.6.3 Address Group Summary Screen ........................................................................................769
42.6.4 Geo IP Summary Screen .....................................................................................................771
42.7 Service Overview ..........................................................................................................................773
42.7.1 What You Need to Know ......................................................................................................774
42.7.2 The Service Summary Screen .............................................................................................775
42.7.3 The Service Group Summary Screen .................................................................................776
42.8 Schedule Overview ......................................................................................................................778
42.8.1 What You Need to Know ......................................................................................................779
42.8.2 The Schedule Screen ..........................................................................................................779
42.8.3 The Schedule Group Screen ...............................................................................................782
42.9 AAA Server Overview .................................................................................................................784
42.9.1 Directory Service (AD/LDAP) ..............................................................................................784
42.9.2 RADIUS Server ...................................................................................................................785
42.9.3 ASAS ...................................................................................................................................785
42.9.4 What You Need To Know ..................................................................................................
...785
42.9.5 Active Directory or LDAP Server Summary .........................................................................787
ZyWALL/USG Series User’s Guide
19
42.9.6 RADIUS Server Summary ...................................................................................................790
42.10 Auth. Method Overview .............................................................................................................792
42.10.1 Before You Begin ...............................................................................................................792
42.10.2 Example: Selecting a VPN Authentication Method ............................................................792
42.10.3 Authentication Method Objects ..........................................................................................793
42.11 Certificate Overview ...................................................................................................................795
42.11.1 What You Need to Know ....................................................................................................795
42.11.2 Verifying a Certificate .........................................................................................................797
42.11.3 The My Certificates Screen ................................................................................................798
42.11.4 The Trusted Certificates Screen .......................................................................................805
42.11.5 Certificates Technical Reference .......................................................................................810
42.12 ISP Account Overview ...............................................................................................................810
42.12.1 ISP Account Summary ...................................................................................................... 811
42.13 SSL Application Overview ..........................................................................................................813
42.13.1 What You Need to Know ....................................................................................................813
42.13.2 The SSL Application Screen ..............................................................................................815
42.14 DHCPv6 Overview ......................................................................................................................818
42.14.1 The DHCPv6 Request Screen ...........................................................................................819
42.14.2 The DHCPv6 Lease Screen ..............................................................................................820
Chapter 43
System...............................................................................................................................................822
43.1 Overview .......................................................................................................................................822
43.1.1 What You Can Do in this Chapter ........................................................................................822
43.2 Host Name ....................................................................................................................................823
43.3 USB Storage .................................................................................................................................823
43.4 Date and Time ...............................................................................................................................824
43.4.1 Pre-defined NTP Time Servers List .....................................................................................827
43.4.2 Time Server Synchronization ...............................................................................................827
43.5 Console Port Speed ......................................................................................................................828
43.6 DNS Overview ...............................................................................................................................829
43.6.1 DNS Server Address Assignment .......................................................................................829
43.6.2 Configuring the DNS Screen ...............................................................................................829
43.6.3 (IPv6) Address Record ........................................................................................................833
43.6.4 PTR Record .........................................................................................................................833
43.6.5 Adding an (IPv6) Address/PTR Record ..............................................................................833
43.6.6 CNAME Record ...................................................................................................................834
43.6.7 Adding a CNAME Record ....................................................................................................834
43.6.8 Domain Zone Forwarder .....................................................................................................835
43.6.9 Adding a Domain Zone Forwarder ......................................................................................835
43.6.10 MX Record ........................................................................................................................836
43.6.11 Adding a MX Record ..........................................................................................................836
43.6.12 Security Option Control .....................................................................................................837
ZyWALL/USG Series User’s Guide
20
43.6.13 Editing a Security Option Control ......................................................................................837
43.6.14 Adding a DNS Service Control Rule ..................................................................................838
43.7 WWW Overview ............................................................................................................................839
43.7.1 Service Access Limitations ..................................................................................................839
43.7.2 System Timeout ...................................................................................................................839
43.7.3 HTTPS .................................................................................................................................840
43.7.4 Configuring WWW Service Control .....................................................................................841
43.7.5 Service Control Rules ..........................................................................................................844
43.7.6 Customizing the WWW Login Page ....................................................................................844
43.7.7 HTTPS Example ..................................................................................................................849
43.8 SSH ............................................................................................................................................856
43.8.1 How SSH Works ..................................................................................................................857
43.8.2 SSH Implementation on the ZyWALL/USG .........................................................................858
43.8.3 Requirements for Using SSH ...............................................................................................858
43.8.4 Configuring SSH ..................................................................................................................858
43.8.5 Secure Telnet Using SSH Examples ...................................................................................859
43.9 Telnet ............................................................................................................................................860
43.9.1 Configuring Telnet ................................................................................................................860
43.10 FTP ............................................................................................................................................862
43.10.1 Configuring FTP ................................................................................................................862
43.11 SNMP .........................................................................................................................................863
43.11.1 SNMPv3 and Security ........................................................................................................864
43.11.2 Supported MIBs .................................................................................................................865
43.11.3 SNMP Traps ......................................................................................................................865
43.11.4 Configuring SNMP .............................................................................................................865
43.11.5 Add SNMPv3 User .............................................................................................................868
43.12 Authentication Server ..................................................................................................................868
43.12.1 Add/Edit Trusted RADIUS Client ......................................................................................870
43.13 CloudCNM Screen ......................................................................................................................870
43.14 Language Screen ........................................................................................................................873
43.15 IPv6 Screen .................................................................................................................................873
43.16 Zyxel One Network (ZON) Utility ................................................................................................874
43.16.1 Zyxel One Network (ZON) System Screen ........................................................................875
Chapter 44
Log and Report .................................................................................................................................877
44.1 Overview .......................................................................................................................................877
44.1.1 What You Can Do In this Chapter ........................................................................................877
44.2 Email Daily Report ........................................................................................................................877
44.3 Log Setting Screens .....................................................................................................................879
44.3.1 Log Setting Summary ..........................................................................................................880
44.3.2 Edit System Log Settings ...................................................................................................881
44.3.3 Edit Log on USB Storage Setting .......................................................................................886
/