all | frequencies |
|
exhibits | applications |
---|---|---|---|---|
manual |
app s | submitted / available | |||||||
---|---|---|---|---|---|---|---|---|
1 |
|
User Manual | Users Manual | 1.05 MiB | ||||
1 | Cover Letter(s) | |||||||
1 | Cover Letter(s) | |||||||
1 | External Photos | |||||||
1 | ID Label/Location Info | |||||||
1 | Internal Photos | |||||||
1 | Operational Description | |||||||
1 | RF Exposure Info | |||||||
1 | Test Report | |||||||
1 | Test Setup Photos |
1 | User Manual | Users Manual | 1.05 MiB |
Chapter 1: Introduction This manual contains detail instructions, on how to setup and operate the VPN Internet Gateway. The VPN Internet Gateway provides an easy and cost effective way to communicate securely over a public network, such as the Internet. You can configure to automatically encrypt all data transmitted to a particular site or sites over the Internet. The VPN Internet Gateway can create a secure connection between two or more sites. The VPN Internet Gateway is equipped with:
Internet Gateway the VPN A WAN Ethernet port (connects to any Cable/XDSL modem) 4 LAN Ethernet ports (connect to a PC client or a Hub/switch etc.) One asynchronous port (connects to a dial up modem or a ISDN TA) Connect any Cable/XDSL modem to the VPN Internet Gateway, to establish a high speed Internet connection. Once an Internet connection is made, you can start establishing VPN connections. Those who require a private and secure connection will find this device an easy and cost effective solution to a lease line connection. The asynchronous port can be connected to a dial-up modem or to an ISDN TA and provides you with a backup Internet connection should the Cable/xDSL connection fail. If there is no Cable/xDSL service in your area, the asynchronous port can also serve as your Internet access connection. The VPN Internet Gateway provides a total solution for those SOHO (Small Office and Home Office), SMB (Small and Medium size Businesses) and ROBO
(Remote Office and Branch Office) users, who require a VPN and other sophisticated functions at a cost effective price. 1 Features
Supports Virtual Private Network (VPN) connections (IPSec)
Supports up to 8 IPSec tunnel connections
Supports VPN client software (Safenet and SSH)
Supports DES/3DES Encryption, IP Encapsulating Security Payload
(ESP), Authentication (MD5/SHA-1)
Shared Internet connection via any Cable or xDSL modem
Asynchronous port for backup or dial-up Internet connection
Supports up to 253 users
Provides solid firewall protection for LAN clients/computers
Built-in high speed 4 port 10/100 switch to connect to computers or to additional switches/hubs
Provides centralization of all network address settings (DHCP)
Comprehensive device monitoring system: Device status, Device information, System Tools, Intruder Detection log and more
Easy-to-use, Web-based setup and configuration
Dynamic DNS to have Web and other Servers behind a Dynamic IP address
Acts as a Virtual server to enable remote access to Web, FTP, and other services on your network
DMZ for full 2-way communication between your LAN and the Internet
URL filtering function
Supports the UPnP protocol
E-Mail alert when a network security breach occurs Package Contents Please inspect your package. The following items should be included:
1). One VPN Internet Gateway (the Device) 2). One Power adapter 3). One Users Guide If any of the above items are damaged or missing, please contact your dealer immediately. 2 Minimum System Requirements
Microsoft Internet Explorer 4.0 (or later version) or Netscape Navigator 4.0 (or later version)
One computer with an installed 10Mbps, 100Mbps or 10/100Mbps Ethernet card
One external xDSL or Cable modem with an Ethernet port (RJ-45)
One Modem or ISDN TA (if a dialup connection is needed)
One RJ-45 Cable/XDSL Internet connection
TCP/IP protocol installed in your computer
UTP network Cable with a RJ-45 connector Pre-Installation Checklist Before installing the Internet Gateway, you should:
Have carefully read the entire manual.
Be familiar with the terminology and concepts of browsers. (This guide works under the assumption that you are proficient with the browsers you are using).
Have met all the hardware and software requirements. 3 The Gateways Rear View The diagram below shows the Internet Gateways rear panel and is where all the hardware connections are made. 12VDC Rear View Ports Power (12VDC) WAN Serial Reset Ports 1-4 Description The power port is where you connect the DC power adapter The WAN 10M Ethernet port is where you connect your ADSL/Cable modem. The Serial port is where you connect the 56K modem /
ISDN TA If you want the device to have the factory default settings, press the reset button and hold it for 5 ~ 6 seconds. This will load the factory default settings into the device. Please be careful. Do not press the reset button unless you want to clear the current configurations. There are four LAN ports on the rear panel (supports auto crossover). This is where you connect network devices, such as PCs, switches, hubs, print servers, LAN servers or other network devices. 4 The Gateways Front Panel LED On the routers front panel there are LED lights that inform you of the routers current status. Below is an explanation of each LED and its function. LED LAN (1-4) Link/Act Off LED Status Description Green LED will NOT Light if there is no connection ON Blink Green LED will LIGHT when a connection has been established. Green LED will BLINK if packets are been transmitted or received Serial Off Green LED will NOT Light if there is no connection ON Green LED will LIGHT when a link WAN Off has been established. Green LED will NOT Light when a link has not been established. ON Green LED will LIGHT when a link has been established. 5 LED STATUS POWER LED Status Description Blink Off ON Yellow LED will BLINK when the device is booting up or upgrading a firmware. NO Power Red LED will LIGHT if the Gateway is receiving power. Hardware Installation Setup The diagram below shows how the Internet Gateway is typically setup. 6 When you setup the hardware installation please note the following. 1. Make sure that the power supply outlet voltage is compatible with the power adapters of your PCs, Cable/XDSL modem and the Internet Gateway. 2. For the Internet Gateway, only use the power adapter that comes with it. 3. Connect a network cable from your PCs Ethernet port to one of the LAN ports at the rear panel of the Internet Gateway. Do the same with all of the PCs or switches/hubs you wish to connect to the Internet Gateway. 4. Connect the network cable from your Cable/XDSL modem to the WAN Ethernet port at the rear panel of the Internet Gateway. 7 Chapter 2: Getting Started To setup the Internet Gateway and get connected to the Internet; follow the following step-by-step procedure:
1. Setup your hardware network installation (see Chapter 1 Hardware Installation setup) 2. Configure your network computers (LAN server/client/host) to Obtain an IP address automatically. (See Appendix) Note: By default the Internet Gateways DHCP is enabled - so by setting your computer to Obtain and IP address automatically - you can connect to the Gateway automatically. 3. Launch your web browser and type the routers default IP address
(http:// 192.168.2.1) into the browsers address box and press Enter. Note: If you have setup your computer to use a static IP address:
Please make sure your PCs IP address is in the same network as the routers. In windows 95/98 you can type WINIPCFG and in windows 2000/NT you can type IPCONFIG (see appendix) to find out if you are on the same network. 8 4. The main menu will appear. It displays all the functions that you can use and configure for the Internet Gateway. The User Interface is designed to be extremely user-friendly and is divided into 6 main sections. The 6 sections are listed on the top Tool bar (see screen above) and appear at the top of every browser screen for easy access. For your reference the 6 sections are as follow:
Main Menu Device Information (chapter 3) Device Status (chapter 4) Description The Device information section displays the Internet Gateways network and firmware information. Device status displays the current connection status of the Internet Gateway. 9 Main Menu Setup Wizard (chapter 2) Description to begin using This is the most important section out of the 6 sections. You must configure this section Internet Gateway. The Setup wizard is where you input the information required to connect the Internet Gateway to your Internet Service Provider (ISP). the Advanced Settings (chapter 5) System Tools (chapter 6) The Advanced settings section is where you can configure all the major features and functions of the Internet Gateway. They include: DHCP Server Settings, Virtual Server Settings, Routing Settings, Filter Settings, Administration Settings, Dynamic DNS Settings, URL Filter Settings and E-Mail ALERT The System Tools section detects the status of the Internet Gateway, such as Intruder Detection Log, Display Routing Table, System Diagnostics, Save Settings, Load Settings, Upgrade Firmware and Reset Device A help section for the Internet Gateway Help (chapter 7) 10 5. Click the SETUP WIZARD. A username and password will appear. Leave the password box empty and type admin (the default username) in the username box. Click OK. The setup wizards page will appear as shown below. The Setup wizard will take you through 7 step-by-step (7 steps: buttons on the left) configuration procedures that youll need to do in order to setup the Internet Gateway (e.g. connecting to the Internet / establishing a VPN connection). You can click on one of the 7 buttons on the left to jump to that specific setting. Otherwise by clicking Next, you will proceed to the next step sequentially. (We recommend that you follow the 7 steps sequentially). The 7 steps are as follows:
11
(Step A) Time Zone Settings
(Step B) Device IP Settings
(Step C) ISP Settings
(Step D) ISP Additional Settings
(Step E) Modem Settings
(Step F) VPN Settings
(Step G) Save & Restart 6. (Step A) Time Zone Settings: Please choose a local time zone. Once you have selected a time zone, click the Next button to continue to the next step. 7. (Step B) Device IP Settings In this section, you have to give your Internet Gateway an IP address for the local area network (LAN) side. This is not the IP address given to you by your ISP, but rather the local internal LAN (Private) IP address of your network. The IP address 192.168.2.1 is the default value of your Gateway. 12 The screen shown above is described in the following table:
Parameters Device IP Address Settings Description IP Address IP Subnet Mask Assign an internal LAN IP address for this Internet Gateway or leave it as the default value 192.168.2.1. Enter the subnet mask, you can usually leave entry as 255.255.255.0 default the it Once you have filled in the above information, click the Next button to continue to the next step. 8. (Step C) ISP Settings Different ISPs require different methods of connecting to the Internet. The ISP Settings section is where you input all the information required by your ISP, so that you can connect to the Internet. There are 5 different types of ISP connections in the ISP Settings section. Select the connection required by your ISP from the Select the ISP connection type pull down menu and then proceed to that connection type step. The 5 ISP connection types are as follow:
ISP Connection Type Connect to Cable ISP (Step 8-1) Description Your ISP will automatically give you an IP address Static IP Settings (Step 8-2) PPPoE Settings (Step 8-3) Your ISP has given you an IP address already Your ISP requires you to use a Point-to-Point Protocol over Ethernet (PPPoE) connection. 13 ISP Connection Type PPTP Settings (Step 8-4) Telstra Settings (Step 8-5) Description Your ISP requires you to use a Point-to-Point Tunneling Protocol
(PPTP) connection. The Telstra Settings is a service that applies in Australia only. to connections Step 8-1) Connect to Cable ISP: Select Connect to Cable ISP if you have a cable connection. Please select Connect to Cable ISP and click Next to proceed to the next page. Proceed to step 9
(Step D) ISP Additional Settings of this manual Step 8-2) Static IP Settings: Select Static IP Settings, if your ISP has 14 given you a static IP address. You will have to enter the following information:
Description Parameter IP assigned by your ISP Enter the IP address (provided by your ISP) IP Subnet Mask ISP Gateway Address Enter the IP subnet mask (provided by your ISP) Enter the ISP gateway address (provided by your ISP) Note: Once you have filled in the above information, click Next to proceed to the next step. Proceed to step 9 (Step D) ISP Additional Settings of this manual 15 Step 8-3) PPPoE Settings: Select PPPoE Settings if your ISP requires the PPPoE protocol to establish an Internet connection. You will have to enter the following information:
Parameter User name Password Retype password Description Enter the user name of your ISP account. Enter the password of your ISP account. Enter the password of your ISP account again to re-confirm. Connection Type Select ONE. Dynamic/Fixed:
Always Connect - The VPN Gateway will always connect with your ISP. If this is the case, the Idle Time function is unavailable. Trigger on Demand Once the VPN Gateway detects any packets want to get to Internet, the VPN Gateway will connect with your ISP automatically. Manual You can manually disconnect/connect with your ISP for the WAN port (Cable/xDSL). If this is the case, you have to go to the DEVICE STATUS page and click Connect button to establish the connection or click Disconnect button to disconnect the connection. Select ONE. Dynamic - If your ISP will automatically assign you an IP address Fixed - If your ISP has given you a fixed IP address already, then enter that IP address in the IP assigned by your ISP box. Also enter the subnet mask (provided by ISP) in the IP Netmask box Note: Once you have filled in the above information, click Next to proceed to the next step. Proceed to step 9 (Step D) ISP Additional Settings of this manual 16 Step 8-4) PPTP Settings: Select PPTP Settings, if your ISP requires the PPTP protocol to establish an Internet connection (e.g. Europe). You will have to enter the following information:
Parameter User name Password:
Idle Time PPTP Client IP Description Enter the user name of your ISP account. Enter the password of your ISP account. Optional: You do not have to configure this section. It depends on the users needs. If the Internet connection has been idle for a certain period of time (the Idle Time selected), the Idle Time function will automatically disconnect the Internet connection. Enter the PPTP client IP address (Provided by ISP) 17 Parameter Connection ID Description Input this ID information only if your ISP has given you one. Connection Type Select ONE. Dynamic/Fixed Always Connect - The VPN Gateway will always connect with your ISP. If this is the case, the Idle Time function is unavailable. Trigger on Demand Once the VPN Gateway detects any packets want to get to Internet, the VPN Gateway will connect with your ISP automatically. Manual You can manually disconnect/connect with your ISP for the WAN port (Cable/xDSL). If this is the case, you have to go to the DEVICE STATUS page and click Connect button to establish the connection or click Disconnect button to disconnect the connection. Select ONE. Dynamic - If your ISP will automatically assign you an IP address Fixed - If your ISP has given you a fixed IP address already, then enter that IP address in the IP assigned by your ISP box. Also enter the subnet mask (provided by ISP) in the IP Netmask box Note: Once you have filled in the above information, click Next to proceed to the next step. Proceed to step 9 (Step D) ISP Additional Settings of this manual 18 Step 8-5) Telstra Settings: The Telstra Settings is a service that applies to connections in Australia only. You will have to enter the following:
Parameter User Name Password Retype password Default Domain Description Enter the User Name (Provided by the ISP) Enter the Password (Provided by the ISP) Re-Enter the password of your ISP account again to re-confirm. Input the default domain if your ISP has given you one Note: Once you have filled in the above information, click Next to proceed to the next step. Proceed to step 9 (Step D) ISP Additional Settings of this manual 19 9 (Step D) ISP Additional Settings In this section you can input special settings required by certain ISPs. You do not need to configure the entire section or any part of the section, only the settings needed by your particular ISP (if any). If your ISP does not require any additional settings, then please leave this section blank and proceed to the next step. Parameter Your ISPs require you to manually setup the DNS settings If your ISP requires you to input a DNS setting then you must check this box to enable this function and then enter the DNS address (see DNS below) IP Address Description DNS IP Address Enter the DNS IP address (provided by ISP) 20 Parameter Description Some ISPs use Host Name If your ISP requires you to fill in a Host and Domain Name to authenticate the user Name and Domain Name then you must check this box to enable this function and then enter the Host Name and Domain Name (see Host/Domain Name below) Host Name Domain Name Your ISPs require you to input the LAN cards Mac address Enter the Host Name (provided by your ISP) Enter the domain name (provided by your ISP) If your ISP requires a specific MAC address in order for you to connect to the Internet, then check the box to enable this function and then enter the Mac address (see MAC Address below) NOTE: Some ISPs may only recognize your PCs LAN card MAC address as a legal user. In this case, you will have to copy the LAN card MAC address of that PC and input it in the MAC address field. For WIN 95/98 you can run winipcfg to see the LAN card Mac address For WIN 2000/NT run ipconfig/all to see the LAN card Mac address can you MAC Address Enter the PCs LAN card MAC address that your ISP recognizes as the legal user Note: Once you have filled in the above information, click Next to proceed to the next step. 21 10. (Step E) Modem Settings Description The modem settings screen is where you can setup the asynchronous port as either a backup connection for the Cable/xDSL connection or a dialup Internet access connection. Note: This section is Optional. You may proceed to Step F if you do not wish to use the asynchronous port. Parameter Dialup Modem When Cable/xDSL is not Connected ISP Phone Number User Name Password Click on this box to enable the asynchronous port Enter the ISP phone number (Dial-Up) Enter the User Name for the dial-up Enter the Password for the dial-up 22 Parameter Retype Password Idle Time External IP Modem String settings Description Enter the Password again to re-confirm You can select an idle time threshold
(minutes) for the WAN port. This means if no packets have been sent (no one using the Internet) throughout this specified period, then the router will automatically disconnect with your ISP.
(Optional) If your ISP requires you to input an IP address then please input the IP address here. Otherwise leave it as the default setting (0.0.0.0).
(Optional) Some modems require specific communication strings. This section allows you to specify strings on the router, so that it can communicate with your modem (if required). If you would like to change the baudrate speed, you can do so in the Baudrate Settings field. (Please refer to your modems or ISDN TAs manual for more information) Note: Once you have filled in the above information, click Next to proceed to the next step. 23 11. (Step F) VPN Settings The VPN Settings section is where you can enable and configure the VPN function. Specifically, this device supports the widely used IPSec protocol standard for its VPN connection. VPN allows a secure connection between two parties over a public network, such as the Internet. Note: This section is Optional. You may proceed to Step G if you do not wish to establish a VPN connection. The VPN settings has 3 steps:
11-1) Add a VPN connection: Connection Name 11-2) Configure the VPN Connection 11-3) Secure Association 24 11-1) Add a VPN connection: Connection Name Parameter Connection Name Description To add a VPN connection: Enter a string
(name) into the Connection Name box, and then click the ADD button. Note: Once you have entered the connection name - click on the ADD button to start configuring this VPN connection. The screen below will appear and this is where the VPN configuration is entered. 25 11-2) Configure the VPN Connection Parameter Connection Name Enable UID Local IPSEC Identifier Description This is the Connection Name you entered in the previous screen (Connection Name) Optional - This will enable the Unique Identifier string (UID). Disable UID will disable the UID. The VPN Gateways use the UID for authentication purposes. (see Local/Remote IPSEC Identifier below) Optional - This field allows you to identify multiple tunnels; you dont need to match the name used at the other end of the tunnel. You can enter a proper name in this field; the default value for the Local IPSEC Identifier is, Local 26 Parameter Description Remote IPSEC Identifier Optional - This field allows you to identify multiple tunnels; you dont need to match the name used at the other end of the tunnel. You can enter a proper name in this field; the default value for the Remote IPSEC Identifier is, Remote Enabled Keep Alive Enabled NetBIOS Broadcast Remote Site Remote IP Network Optional - If this function is enabled, it will keep alive
(connected) this VPN connection Optional - This function allows NetBIOS broadcast to be transmitted in this VPN connection Select One:
Single User Select Single User if the remote VPN site is a VPN client, e.g. remote site has no Internet gateway. The remote VPN client must have a VPN client software
(e.g. Safenet or SSH etc.) installed LAN Select LAN if the remote VPN site has an Internet gateway. This is the remote sites NETWORK IP address. (Single User Input the actual IP address of the Remote VPN client. LAN Input the network IP of the remote gateways internal (private) network) 27 Parameter Remote IP Netmask Remote Gateway IP/FQDN Description This is the remote sites subnet mask the remote sites Gateway IP Input address (for Remote Site LAN only) or the Fully Qualified Domain Name (FQDN). is a FQDN consists of a host and domain name, including top-level domain. For example, WWW.VPN.COM fully qualified domain name. WWW is the host, VPN is the second-level domain, and COM is the top-level domain. When you enter the FQDN of the remote site, the VPN gateway will automatically seek the IP address of that FQDN. if In IKE Mode, Note:
the Remote Gateway IP has a dynamic IP address, you must enter 0.0.0.0. in the Remote Gateway IP/FQDN field. In Manual Mode, you must fill in the Remote IP, Remote IP Network and Remote Gateway IP/FQDN field (Remote Gateway IP/FQDN field cannot be 0.0.0.0 for the manual mode). See Appendix - VPN example. Network Interface Select an interface type for the this VPN connection 28 11-3) Secure Association Secure Association is a method of establishing a security policy between two points. There are two methods of creating a Secure Association (SA), Method 1: IKE Mode (By default IKE is selected), Method 2: Aggressive mode and Method 3: Manual mode. 11-3) Method 1: IKE Mode:
IKE is an automated method of establishing a shared security policy and authenticated keys. A preshared key for mutual identification. is used Parameter Perfect Forward Secure Encryption Protocol Description Click either the Enabled or Disabled radio button. This feature provides a better security; it ensures that the encryption keys generated are not relevant to each other. an The VPN Gateway supports two types of encryption algorithms (DES and 3DES). Select encryption algorithm. The encryption algorithm must match the encryption algorithm in the remote device. appropriate 29 Parameter PreShared Key Key Life IKE Life Time Description Enter the PreShared Key name (you can enter a alphanumeric name). This value must match the preshared key value in the remote device. Security is enhanced if the key used to encrypt/decrypt your data is changed periodically. The key life is where you can specify how often you wish the VPN Gateway to renegotiate another key. The value is in seconds, for example, 3600 seconds = 1 hour. The IKE Life Time field allows you to specify a period of time (seconds) that you want the VPN Gateway to renegotiate the IKE security association. For example, 28800 seconds = 8 hours. Note: In IKE Mode, if the Remote Gateway IP is dynamic, you should enter 0.0.0.0 See Appendix - VPN example. 30 11-3) Method 2: Aggressive mode Aggressive is an automated method of establishing a shared security policy and authenticated keys. A preshared key is used for mutual identification. Parameter Perfect Forward Secure Encryption Protocol Key Group Description Click either the Enabled or Disabled radio button. This feature provides a better security; it ensures that the encryption keys generated are not relevant to each other. an The VPN Gateway supports two types of encryption algorithms (DES and 3DES). Select encryption algorithm. The encryption algorithm must match the encryption algorithm in the remote device. appropriate Diffie-Hellman key agreement describes a method whereby two parties, without any prior arrangements, can agree upon a secret key that is known only to them. The VPN Gateway supports two versions of Diffie-Hellman (Group 1 and Group 2). 31 Parameter Description PreShared Key Key Life IKE Life Time Diffie-Hellman Group 1 - IKE use the 768-
bit Diffie-Hellman prime modulus group when performing the new Diffie-Hellman exchange. Diffie-Hellman Group 2 - IKE use the 1,024-bit Diffie-Hellman prime modulus group when performing the new Diffie-
Hellman exchange. Enter the PreShared Key name (you can enter a alphanumeric name). This value must match the preshared key value in the remote device. Security is enhanced if the key used to encrypt/decrypt your data is changed periodically. The key life is where you can specify how often you wish the VPN Gateway to renegotiate another key. The value is in seconds, for example, 3600 seconds = 1 hour. The IKE Life Time field allows you to specify a period of time (seconds) that you want the VPN Gateway to renegotiate the IKE security association. For example, 28800 seconds = 8 hours. Note: In Aggressive Mode, if the Remote Gateway IP is dynamic, you should enter 0.0.0.0 See Appendix - VPN example. 32 11-3) Method 3: Manual mode This is a manual way of establishing a shared security policy and authenticated keys. The Manual mode allows you to pre-define keys. The Manual Mode settings in the remote device must match the configuration set here. To enable the Manual mode function, check the Manual radio box and input the fields shown on the screen below. Parameter Incoming SPI Outgoing SPI Encryption Protocol Description Enter the Incoming SPI that the remote VPN Gateway will use to identify this SA. The incoming SPI value must match the outgoing SPI at the remote site (other end of the VPN tunnel). Enter the Outgoing SPI that the local VPN Gateway will use to identify this SA. The outgoing SPI value must match the incoming SPI at the remote site (other end of the VPN tunnel). The VPN Gateway supports three types of encryption algorithms (Null, DES, and 3DES). Select an appropriate encryption algorithm. The encryption algorithm must match the encryption algorithm in the remote device. 33 Parameter Encryption Key Description Authentication Protocol Authentication Key This string is used as the key to encrypt and decrypt the data transmitted. This value must match the encryption key value in the remote device. supports The VPN Gateway two authentication algorithms (MD5 & SHA-1). Select an appropriate authentication algorithm. The authentication algorithm selected here must be the same as the one in the remote device. is used as This string the key authentication. This value must match the authentication key value in the remote device. Note: In Manual Mode, you must fill in the Remote IP, Remote IP Network and Remote Gateway IP/FQDN (Remote Gateway IP/FQDN field cannot be 0.0.0.0.). See Appendix - VPN example. 34 12. (Step G) Save & Restart This is the final step of the Setup Wizards 7 step-by-step procedure. This step saves the settings you have made in the previous pages to the Internet Gateway. Click Save & Restart to save the settings and to restart the device. After the device has restarted, the device will function according to the saved settings. During the startup process the LED of the device will blink. Please wait until the LED lights have stopped blinking before proceeding. 35 Logout Click Logout if you would like to leave (logout) the routers web based configuration page. Only one user can log onto the Gateways web based configuration at a time. When you logout of the web-based configuration, only then can another computer log onto the device. Click Yes - the screen will close. Click No - the screen will not close. Congratulations!!! You have successfully configured the setup wizard. You may now use the Internet Gateway to access the Internet. If you would like to configure or monitor the many features that this Gateway has to offer, then proceed to the appropriate chapters for more details. Below is a list of the other Main Menus and their corresponding chapters:
Device Information (chapter 3)
Device Status (chapter 4)
Setup Wizard (chapter 2)
Advanced Settings (chapter 5)
System Tools (chapter 6)
Help (chapter 7) 36 Chapter 3: Device Information The Device information section displays the Internet Gateways network and firmware information. Parameters Device Name IP Address Private LAN MAC Address Public WAN (Cable/XDSL) Mac Address Firmware version Description Displays the name of the Internet Gateway Displays the IP address of the Internet Gateway Displays the MAC address of the Internet Gateways LAN port Displays the MAC Address of the Internet Gateways WAN Ethernet port Displays the Internet Gateways current Firmware Version and its release date 37 Chapter 4: Device Status Device status displays the current connection status of the Internet Gateway. Parameter WAN Ethernet the Devices WAN
(shows whether Description Shows information:
Cable/xDSL Internet connection is active or inactive), Connected by DHCP (shows the WAN connection type e.g., DHCP, Static, PPPoE, PPTP or Telstra), ISPs Gateway IP address, devices WAN IP address, devices Netmask and the DNS IP address that the Internet Gateway is using. the 38 Parameter Release (Disconnect) and Renew (Connect) Description Modem Dialup Hang Up and Dial Up Device IP You can manually disconnect/connect with your ISP for the WAN port (Cable/xDSL) Click the Release (Disconnect) button - the Internet Gateway will disconnect with the ISP. Click the Renew (Connect) button - the Internet Gateway will connect with the ISP. The modem (asynchronous port) can be used as a backup Internet connection (dialup) for the Cable/xDSL connection or as an Internet access connection. If the current connection is via the backup modem, it will show Modem: Active, otherwise it will show Not Active. You can manually disconnect/connect with your ISP for the asynchronous port (Dial Up/ISDN TA) If the Modem Dialup shows Modem: Active, clicking on the Hang Up button will DISCONNECT the asynchronous ports Internet connection. If the Modem Dialup shows Not Active, by clicking on the Dial Up button - the Internet Gateway will ESTABLISH an Internet connection for the Gateways asynchronous port. Shows the Devices: LAN IP address, private LAN MAC address and public WAN MAC address. 39 Parameter VPN Status Description This screen displays the current connection status of your VPN connection(s). The VPN connection following information:
shows status the Status - Active/Inactive Connection Name - name of the VPN connection Remote IP, Virtual Network - remote sites Network (private network) IP Interface, Type encryption / authentication State - phase 1 / phase2 TX pkts - transmitted packets Rx pkts - received packets UpTime - how long the connection has been established Drop - click the Drop button to disconnect the VPN connection 40 Parameter DHCP Log VPN Log Description Displays Gateways DHCP server. the DHCP clients logged to the Click the DHCP Log button - the screen will display the DHCP clients information (DHCP clients: IP address, MAC address, IP address lease time). This screen displays the VPN negotiation that occurred between the VPN Gateway and remote devices. Click on Refresh information to update the latest Click on Clear Log to clear the VPN log 41 Parameter Update DDNS Description Click the Update DDNS button to manually update the IP address of your domain name
(dynamic IP address for Gateways WAN port). Note: DO NOT click the Update DDNS button too often. Some ISPs may think this is an attack and may disable your account. 42 Chapter 5: Advanced Settings The Advanced settings section is where you can configure all the major features and functions of the Internet Gateway. They include: DHCP Server Settings, Virtual Server Settings, Routing Settings, Filter Settings, Administration Settings, Dynamic DNS Settings, URL Filter Settings and E-Mail ALERT On the Menu Tool, click Advanced Settings. A username and password will appear. Type admin in the user name box, and then type the password that you have given to the device (by default there is no password) and then Click OK. The Advanced Settings page will appear as shown below. 43 Main Menu DHCP Server Settings Virtual Server Settings Routing Settings Filter Settings Administration Settings Dynamic DNS Settings URL Filter Settings E-Mail ALERT Logout Description Provides centralization of all your LANs network IP addresses Allows remote access to Web, FTP, and other services on your network. The DMZ function allows full 2-way communication between a server on your LAN and the Internet Create a routing table so that the Internet Gateway can route packets to different networks Create LAN or WAN filters to protect your network to configure Allows you the devices administrative settings such as password etc. Allows you to have a Web or other server behind a Dynamic IP address Filter web page request based on the web pages wording Allows you to be alerted of any security infringements Logout or leave the Internet Gateways Web-based configuration 44 DHCP Server Settings You can enable or disable the DHCP server. By enabling the DHCP server the router will automatically give your LAN clients an IP address. If the DHCP is not enabled then youll have to manually set your LAN clients IP addresses. Make sure the LAN Client is on the same subnet as this Internet Gateway if you want this Internet Gateway to be your LAN clients default gateway. Parameter Enable DHCP Server Functions Description By default the Internet Gateways DHCP server is enabled. If you would like to disable the DHCP server, unclick the Enable DHCP Server Functions box (marked red - see screen above) 45 Parameter IP Address Pool Range IP Address Reservation Description The IP address pool contains the range of IP addresses that will be used by the devices DHCP server to automatically assign IP addresses to your network clients. The Default IP address range is:
From 192.168.2.2 to 192.168.2.100 The IP address reservation setting allows you to save for specific computer/network clients. fixed private IP address MAC Address: Enter the MAC address of the PC or server you wish to reserve an IP for. IP Address: Enter the IP address that you want to reserve for the above MAC address. Add an IP address Reservation setting Click the Add button to add the configuration into the IP address reservation table. Delete an IP address Reservation setting Check the IP address reservation tables Del box and click the DEL button to delete a configuration. 46 Virtual Server Settings Use the Virtual Server function when you want different servers/clients in your LAN to handle different service/Internet application type (e.g. Email, FTP, Web server etc.) from the Internet. Computers use numbers called port numbers to recognize a particular service/Internet application type. The Virtual Server allows you to re-direct a particular service port number (from the Internet/WAN Port) to a particular LAN private/internal IP address. The Virtual server settings allow clients on the Internet to access certain services on your LAN via the Internet. Use the Virtual Server function to access a Web, FTP or a Telnet server etc. on your LAN via the Internet. The DMZ function re-directs all packets (regardless of services) going to your WAN IP address to a particular LAN client/server. If you would like to enable the DMZ function, enter an IP address in the DMZ IP field. The value 0 means that the DMZ function is disabled. The difference between the virtual server and the DMZ function is that the virtual server re-directs a particular service/Internet application (e.g. FTP, websites) to a particular LAN client/server, whereas DMZ re-directs all packets
(regardless of services) going to your WAN IP address to a particular LAN client/server. 47 Parameter DMZ Description Enter the IP address that you want to designate as the DMZ server. The value 0 means that the DMZ function is disabled. Virtual Server Settings Internal IP Enter the LAN server/host IP address that the service
(Service Port Range) requests from the Internet will be sent to. Note: You need to give your LAN server/host a fixed/static IP address for the Virtual Server to work properly. Service Port Range Enter the port numbers of the services (requests from the Internet) that will be sent to the Internal IP address
(Specified above). Note: If you only want one service port number e.g. 80
(HTTP) for the specified Internal IP address then enter 80 in both the service port ranges boxes. The Table on the right side of the screen lists the most popular applications and their port numbers. 48 Routing Settings The Static routing settings allow the Internet Gateway to route IP packets to another network (subnet). The routing table stores the routing information so that the Internet Gateway knows where to redirect the IP packets. Parameters Destination IP Address Enter the destination IP address of the remote network to which you want to assign a static route. Description Subnet Mask Gateway IP Address Enter the subnet mask of your network IP address. Enter the IP address of the interface (LAN/WAN port) linked to the remote network (Destination IP address). Add a Static Routing setting Click the Add button to add the configuration into the Static Routing table. 49 Parameters Gateway IP Address Description Delete a Static Routing setting Check the Static Routing tables Del box and click the DEL button to delete a configuration. Dynamic routing settings Allows the Internet Gateway to route IP packets to another network automatically (dynamically). The RIP protocol is used to do the dynamic routing. RIP communicates routing information with other routers periodically. SEND Optional - choose the routing protocol
(routing information) that you wish to transmit to other routers on your network. RECEIVE Optional - choose the routing protocol
(routing information) that you wish to receive from other routers on your network. NOTE: Click the SUBMIT button to input/save the configuration into the Gateway 50 Filter Settings The Filter Settings is divided into LAN Filter Settings and WAN Filter Settings Menu LAN Filter Settings Description The LAN Filter Settings allow the administrator to define whether a local user is permitted to access the Internet. WAN Filter Settings The WAN Filter Settings allow the administrator to define whether a remote/outside user(s) is permitted to access the private local area network. 51 Filter Settings: LAN Filter Settings The LAN Filter Settings allow the administrator to define whether a local user is permitted to access the Internet. To activate this feature, check LAN Side Filter Enabled and then define a filtering policy. To define a filtering policy:
enter the IP address range, enter the network port number and select the transport protocol(s). Parameter LAN Side Filter Enabled Description You must select whether to enable (Yes) or disable (No) the filter function that youve configured in this screen Default LAN Side Filter Filter Entry Select to Block or Pass your regular LAN clients Select to Block or Pass LAN clients specified in this Filter Entry 52 Parameter Protocols Description Select the Transport protocol type (TCP or UDP) for the Destination Port Range (below) that will be filtered Enter the LAN IP address range that you wish to apply this filter rule to. These are the LAN users IP addresses that you wish to apply this filter rule to. If you only want to specify one IP address for this filter rule then enter the same IP address in both the From and the To box. Note: You need to give your LAN PC clients a fixed/static IP address for the filter rule to work properly. Enter the Internet application/service (port number range) for the above IP address range that you wish to apply this filter rule to. If you only want to specify one service port then input the same service port in both the boxes. Add a Filter Entry setting Click the Add button to add the configuration into the LAN Side Filter Table. Delete a Filter Entry setting Check the LAN Side Filter Tables Del box and click the DEL button to delete a configuration. 53 IP Address Range Destination Port Range For example, to prevent local users with IP addresses (ranging from 101 to 200) from accessing websites (HTTP service - port 80), the settings are as follow:
LAN Side Filter Enabled: Enabled Default LAN Side Filter: Pass Filter: Block Protocol: TCP IP Address Range: 101 ~ 200 Destination Port Range: 80 ~ 80 (HTTP) Filter Settings: WAN Filter Settings The WAN Filter Settings allow the administrator to define whether a remote/outside user(s) is permitted to access the private local area network. To activate this feature, check WAN Side Filter Enabled and then define a filtering policy. To define a filtering policy: enter the IP address range, enter the network port number and select the transport protocol(s). 54 Parameter WAN Side Filter Enabled Default WAN Side Filter Filter Entry Protocol IP Address Range Destination Port Range Description You must select whether to enable (Yes) or disable (No) the filter function that youve configured in this screen Select to Block or Pass your regular WAN users Select to Block or Pass WAN clients specified in this Filter Entry Select the Transport protocol type (TCP or UDP) for the Destination Port Range (below) that will be filtered Enter the (Public) IP address range that you wish to apply this filter rule to. These are the external users IP addresses that you wish to apply this filter to. If you only want to specify one external IP address for this filter rule then enter the same IP address in both the From and the To box. Note: WAN clients must have a fixed/static Public IP address for the filter rule to work properly. the Internet application/service
(port Enter number range), for the above IP address range, that you wish to apply this filter rule to. If you only want to specify one service port then input the same service port in both the boxes. Add a Filter Entry setting Click the Add button to add the configuration into the WAN Side Filter Table. Delete a Filter Entry setting Check the WAN Side Filter Tables Del box and click the DEL button to delete a configuration. 55 For example, to prevent remote users with IP addresses (ranging from 211.21.0.1 to 211.29.0.1) from accessing your LANs virtual Web server (port 80), the settings are as follow:
WAN Side Filter Enabled: Enabled Default WAN Side Filter: Pass Filter: Block Protocol: ALL IP Address Range: 211.21.0.1 to 211.29.0.1 Destination Port Range: 80 ~ 80 (HTTP) Administration Settings The Administration Settings section allows you to configure the devices:
Password settings, System Administration, System Log, System Parameters, UPnP and TCP session. 56 Parameter PASSWORD SETTINGS Description You can setup the Internet Gateway so that a password is required, in order to access its web-
based configuration pages. This password will be required the next time you want to configure the Internet Gateway. To setup a password, type your password in the New Password field and type it again in the Retype Password field to reconfirm. Note: It is important to remember your password. If for any reason you lose or forget your password, press the small reset button located on the back of the device for 5~6 seconds. The Reset action will reset the device to the factory default settings. In factory default, the user name is admin and there is NO password SYSTEM ADMINISTRATION This allows remote user(s) to configure and manage the Internet Gateway from a remote site
(through the Internet). IP address of The default value of the HTTP port No is 80. You can select a different port number to do the remote web-based configuration the Remote The default administration host is: 0.0.0.0. (IP address 0.0.0.0 means that any remote PC can access and manage the Internet Gateway from a remote site). Either specify an IP address for the remote administrator or leave it as the default. 57 Parameter SYSTEM ADMIN Description You will have to enable the Allow remote user to configure the device to use the remote web-
based configuration function. Once you have enabled this function, type the devices WAN IP address and the HTTP port No
(e.g. http://202.19.100.1:1023) into the browser of the specified remote administrator. http://<WAN IP Address>: <Port No>
If the HTTP port number, is NOT the default PORT No. 80, then the LAN administrator must also enter the new port number, specified in HTTP port No, in order to access the devices web-based configuration, e.g. Device LAN IP address with HTTP 1023
(http://192.168.2.1:1023) Allow remote user to ping the device: If you enable this function the device will respond to any pings it gets from the Internet. If you disable this function, the device will not respond to any ping requests. port no SYSTEM LOG The System Log function allows the administrator to assign an IP address to a server on which a log server is running. When a particular event occurs, the router will send a notification to the log server. The log server can then present the log to the administrator. [Free log server can be downloaded from Internet, such as Kiwis SysLog Daemon]
58 Parameter Miscellaneous System Parameter UPnP Description Some ISPs require you to force a PPPoE re-connection, when the Internet connection cannot send or receive packets. The System Parameter allows you to set the MTU value (Maximum Transmission Unit) for your Internet connection. If you would like to enable the MTU setting check the box. The default MTU value is 1500 bytes. Some ISPs restrict the packet size for a PPPoE connection. Use the system parameter to change the MTU to cater to your ISPs connection requirement. The Universal Plug and Play (UPnP) function allows Windows XP to automatically configure the router to cater to various Internet applications
(such as games and videoconferencing). NOTE: Click the SUBMIT button to input/save the configuration into the Gateway 59 Dynamic DNS Settings The Dynamic DNS (DDNS) service allows Web or other servers, with a dynamic IP address, to be accessible from the Internet. This means that even if your Internet Gateway has a dynamic WAN IP address, Internet users can still access your web server (domain name) in your LAN. If you would like to use the DDNS function, you will have to register with a DDNS service provider, and enter the following information provided by the DDNS service provider:
Parameter Use a dynamic DNS Click on this box to enable the DNS service function Service Server the DDNS service provider that you have Description Select registered with. Host Name Enter the host name of your DDNS account 60 Parameter User Name Password Use wildcards Description Enter the user name of your DDNS account. Enter the password of your DDNS account. If you use DYNDNS as your DDNS service provider, you can enable the Use wildcards feature. The wildcards feature - any URL request that contain your domain name (e.g. www.router.com), as part of its URL domain name (e.g. http://broad/router.com) request, will be given your dynamic IP address. NOTE: Once you have filled in the above information, click the SUBMIT button to input/save the configuration into the Gateway 61 URL Filter Settings The URL Filter settings prevent users from accessing certain websites on the Internet. The router can block sites based on specific words or letters. Sites will be blocked if any of these words or letters is part of the websites name (URL) or newsgroup name. Parameter Enable URL Filter Functions Description Click on this box to enable the URL filtering function Filter String The Internet Gateway will block any web page requests that have words or letters specified here. NOTE: DO NOT enter http:// into the filter string NOTE: Click the SUBMIT button to input/save the configuration into the Gateway 62 E-Mail ALERT Your router can periodically email you a log of security-related events (such as denied incoming service requests and administrator logins). The router can also email you an immediate alert when it detects a significant security incident, such as: a known attack directed at your IP address, a computer on the Internet scanning your IP address for any open ports and someone on your LAN trying to visit a blocked site. Fill out the settings on the screen below if you would like to have alerts and logs sent to you by e-mail, 63 Parameter Turn E-mail Notification On Description Send Alert And Logs Via E-Mail Your Outgoing Mail Server Send To This E-Mail Address When someone attempts to visit Blocked Sites, router will send logs according to below schedule. None Immediately Hourly Daily When log is full Check this box to enable the E-Mail alert function Enter Your E-Mail accounts Outgoing Mail Server Enter Your E-Mail account that you wish the alert to be sent to. The router will not send any alerts at all The router will send an alert immediately after an incident has occurred to the E-
Mail specified above. The router will send an alert once every hour to the E-Mail specified above. The router will send an alert once a day to the E-Mail specified above. You can specify the exact time from the pull down menu The router will send an alert to the E-Mail specified above only when the log is full. NOTE: Click the SUBMIT button to input/save the configuration into the Gateway 64 Save & Restart Save & Restart lets you save the inputted settings to the Internet Gateway and then restarts (reboots) the device. When you have finished making all the changes on the various pages (above) on chapter 5, please click Save & Restart to save the settings and to restart the device. If you would like to configure the setting(s) again, click on a function
(see screen below), this will link you to that particular functions configuration screen. After the device restarts (reboots), the device will function according to the saved settings. 65 Chapter 6: System Tools The System Tools section displays and detects the status of the Internet Gateway. The System Tools 7 sections are briefly described below:
Main Menu Intruder Detection Log Description Displays any possible Hacker attacks that may have occurred to the Internet Gateway Display Routing Table System Diagnostics Save Settings Load Settings Upgrade Firmware Reset Device Displays configuration the devices current static routing Displays the devices current configuration and Diagnostics information Allows you configuration to a file to save the devices current Allows you to load the factory default settings or files of previously saved configurations into the device. Allows you to upgrade the latest firmware into the device. Allows you to restart/reboot the device. 66 System Tools: Intruder Detection Log The Intruder Detection log displays the possible hacker attacks that may have occurred to the Internet Gateway. Up to 32 hacker attacks may be logged/listed. Below is an explanation of the Intruder Detection log display. Parameter Index Time Protocol Source IP (Port) Description Lists up to 32 Intruder detection logs The attacks protocol type (TCP/UDP) The time in which the attack occurred The source IP address and source Port number of the attack Dest IP (Port) The destination IP address and destination Port number of the attack Event The type of attack 67 System Tools: Display Routing Table The routing table screen below displays the devices current static routing configuration that was configured in the Routing Settings (see chapter 5 -
Routing Settings - for more details). System Tools: System Diagnostics The System diagnostics screen shows the devices configuration information. It also displays the devices current status. Parameter Configuration Description Displays the devices current: firmware version, ISP settings (Internet connection details), Device Settings (Internet Gateways LAN information) Diagnosis Displays connection status and LAN/WAN information. Internet Gateways the current:
68 System Tools: Save Settings 69 The Save Settings screen allows you to save the devices configuration settings to a disk. Click Save File to save your current settings to a file. Then click save to save this configuration file to your disk. You can reload the saved configuration back into the Gateway in the Load Settings (System Tools) section. System Tools: Load Settings The Load Settings screen allows you to load the factory default settings to your 70 device and load settings previously saved configuration files to your device. The Load Settings section consists of 2 sections as described below: Load Default Settings and Load Settings From File Menu Load Default Settings The load default settings screen allows you into load the factory default settings to your device. Description Load Settings From File The load settings from file screen allow you to load a previously saved file into the device again. Upgrade Firmware: Load Default Settings The factory default setting is the configuration when you first purchased the Gateway. Click the START button to start loading the factory default settings. Your previous configurations will be deleted. Note: Load the factory default settings if you have forgotten the Internet Gateways password. The factory default user name is admin and there is NO password. Upgrade Firmware: Load Settings From File 71 The load settings from file screen allows you to load a previously saved file to the device again. Parameter Load Settings File Description To load a previously saved configuration file into the Gateway again, you first need to enter the configuration file name and its path in the box provided. You can also use the Browse button to find the file. Once you have located the files location, click START to start loading the saved configuration into the Internet Gateway System Tools: Upgrade Firmware The upgrade firmware screen allows you to upgrade the latest firmware into your device. 72 Parameter Firmware Upgrade File Description Enter the new firmwares file path into box provided and click START to start upgrading the new firmware into the Internet Gateway. You can also use the Browse button to find the new firmware file. System Tools: Reset Device Reset the Gateway if the Gateway stops responding correctly. Your settings 73 will not be changed. The Reset Device screen allows you to essentially restart/reboot the device. Click on the START button to restart/reboot the device. Chapter 7: Help On the Main Menu Tool bar - click the on the Help Menu if you wish seek further information about a certain function or if you would like to understand certain terminology used in the manual. This section provides a list of frequently asked questions and terminology. Appendix 74 Configuring Your PC to Obtain an IP automatically If you do not want to set a static IP address for your PC, you will need to configure your PC to request an IP address from the Gateway. 1. On your PC, click the Start button, select Settings, then select Control Panel 2. Double-click the Network Icon 3. In the configuration tab, select the TCP/IP protocol line that is associated with your network card/adapter. If there is no TCP/IP line listed, you will need to first install the TCP/IP protocol. 4. Click the Properties button, then choose the IP ADDRESS tab. Select Obtain an IP address automatically. 75 5. Then select the DNS configuration tab to add a DNS IP address. If you do not wish to add a DNS IP address you can select the Disable DNS function. Press OK. You have completed the client settings. 6. After clicking OK, windows might ask you to restart the PC. Click Yes. Viewing Your PCs Network Information There are two tools which are great for finding out a computers IP configuration, 76 MAC address and default gateway.
WINIPCFG (for windows 95/98) Inside the windows 95/98 Start button, select Run and type winipcfg. In the example below this computer has an IP address of 192.168.2.100 and the default gateway is 192.168.2.1. The default gateway should be the network (Router) devices IP address. The MAC address in windows 95/98 is called the Adapter Address. Note: You can also type winipcfg in the DOS command.
IPCONFIG (for Windows 2000/NT) In the DOS command type IPCONFIG and press Enter. Your PC IP information will be displayed as shown below. 77 Virtual Private Network (VPN) Examples There are 2 types of VPN architectural typologies:
Typology 1: LAN - Network-to-Network 78 Internet Gateway LAN 2 VPN Router VPN Internet WAN IP: 211.21.2.1 Netmask: 255.255.255.0 LAN IP: 192.168.2.1 Typology 2: Single User - PC(s) to Network (mode 1 and 2) Typology 1: LAN - Network-to-Network This type of architecture creates a secure VPN tunnel between two networks, for instance, a VPN Internet Gateway (LAN 1) and a VPN Router (LAN 2) see diagram below. LAN 1 Configuration for VPN Internet Gateway (LAN 1) Remote Site: LAN Remote IP Network: 192.168.1.0 Remote IP Netmask: 255.255.255.0 Remote Gateway IP/FQDN: 163.95.1.1 WAN IP: 163.95.1.1 Netmask: 255.255.255.0 LAN IP: 192.168.1.1 Note: In IKE Mode, if the Remote Gateway IP is dynamic, enter 0.0.0.0. in the Remote Gateway IP/FQDN field. In Manual Mode, you have to fill in the Remote IP, Remote IP Network and Remote Gateway IP/FQDN fields. (Remote Gateway IP/FQDN field cannot be 0.0.0.0.) 79 PC A Internet Mode 2 VPN Internet Gateway WAN IP: 163.95.1.1 Netmask: 255.255.255.0 LAN IP: 192.168.1.1 Public IP: 211.21.2.1 Netmask: 255.255.255.0 Virtual LAN IP: 196.168.2.1 Typology 2: Single User - PC(s) to Network (mode 1 and 2) The diagram below is used to describe mode 1 and 2. Mode 1:
PC A must have an IPSec Client software installed (eg. Safenet or SSH etc.). If you do not know PC As IP address, because it has a dynamic public IP, then the VPN Internet Gateways VPN configuration is as follow:
Configuration for VPN Internet Gateway Remote Site: Single User Remote IP Network: 0.0.0.0 Remote IP Netmask: 0.0.0.0 Remote Gateway IP/FQDN: 0.0.0.0 NOTE: If you dont know the IP address (Remote IP Network) for PC A, input 0.0.0.0 in the Remote IP Network field, but the request for the VPN connection has to be initiated by PC A. If you select Manual Mode, you have to fill in the Remote Gateway IP/FQDN. (Remote Gateway IP/FQDN field cannot be 0.0.0.0). Mode 2:
In this example, PC A is given a fixed IP address by its ISP. PC A must have an IPSec Client software installed (e.g. VPNCOM acts as a virtual NIC). The VPN Internet Gateways VPN configuration is as follow:
80 Remote Site: Single User Remote IP Network: 192.168.2.0 Remote IP Netmask: 255.255.255.0 Remote Gateway IP/FQDN: 211.21.2.1 Note: In IKE Mode, if the Remote Gateway IP has a dynamic IP address, you must enter 0.0.0.0. in the Remote Gateway IP/FQDN field. In Manual Mode, you must fill in the Remote IP, Remote IP Network and Remote Gateway IP/FQDN field (Remote Gateway IP/FQDN field cannot be 0.0.0.0 for manual mode). FCC CAUTION 1. The device complies with Part 15 of the FCC rules. Operation is subject to the following two conditions:
(1) This device may not cause harmful interference.
(2) This device must accept any interference received, including interference that may cause undesired operation. 2. FCC RF Radiation Exposure Statement: The equipment complies with FCC RF radiation exposure limits set forth for an uncontrolled environment. This equipment should be installed and operated with a minimum distance of 20 centimeters between the radiator and your body. 3. This Transmitter must not be co-located or operating in conjunction with any other antenna or transmitter. 4. Changes or modifications to this unit not expressly approved by the party responsible for compliance could void the user authority to operate the equipment. 81
frequency | equipment class | purpose | ||
---|---|---|---|---|
1 | 2003-07-17 | 2412 ~ 2462 | DTS - Digital Transmission System | Original Equipment |
app s | Applicant Information | |||||
---|---|---|---|---|---|---|
1 | Effective |
2003-07-17
|
||||
1 | Applicant's complete, legal business name |
Z Com Inc
|
||||
1 | FCC Registration Number (FRN) |
0006796361
|
||||
1 | Physical Address |
5F, No.8 HSIN-ANN RD. HSINCHU SCIENCE PARK
|
||||
1 |
Hsinchu, N/A 300
|
|||||
1 |
Taiwan
|
|||||
app s | TCB Information | |||||
1 | TCB Application Email Address |
k******@emcc.de
|
||||
1 | TCB Scope |
A4: UNII devices & low power transmitters using spread spectrum techniques
|
||||
app s | FCC ID | |||||
1 | Grantee Code |
M4Y
|
||||
1 | Equipment Product Code |
002250
|
||||
app s | Person at the applicant's address to receive grant or for contact | |||||
1 | Name |
J******** j******
|
||||
1 | Title |
R&D DIV Director
|
||||
1 | Telephone Number |
886 3******** Extension:
|
||||
1 | Fax Number |
886 3********
|
||||
1 |
j******@zcom.com.tw
|
|||||
app s | Technical Contact | |||||
n/a | ||||||
app s | Non Technical Contact | |||||
n/a | ||||||
app s | Confidentiality (long or short term) | |||||
1 | Does this application include a request for confidentiality for any portion(s) of the data contained in this application pursuant to 47 CFR § 0.459 of the Commission Rules?: | Yes | ||||
1 | Long-Term Confidentiality Does this application include a request for confidentiality for any portion(s) of the data contained in this application pursuant to 47 CFR § 0.459 of the Commission Rules?: | No | ||||
if no date is supplied, the release date will be set to 45 calendar days past the date of grant. | ||||||
app s | Cognitive Radio & Software Defined Radio, Class, etc | |||||
1 | Is this application for software defined/cognitive radio authorization? | No | ||||
1 | Equipment Class | DTS - Digital Transmission System | ||||
1 | Description of product as it is marketed: (NOTE: This text will appear below the equipment class on the grant) | 802.11b Wireless Router | ||||
1 | Related OET KnowledgeDataBase Inquiry: Is there a KDB inquiry associated with this application? | No | ||||
1 | Modular Equipment Type | Does not apply | ||||
1 | Purpose / Application is for | Original Equipment | ||||
1 | Composite Equipment: Is the equipment in this application a composite device subject to an additional equipment authorization? | No | ||||
1 | Related Equipment: Is the equipment in this application part of a system that operates with, or is marketed with, another device that requires an equipment authorization? | No | ||||
1 | Grant Comments | Power output listed is conducted. The antenna(s) used for this transmitter must be installed to provide a separation distance of at least 20 cm from all persons and must not be co-located or operating in conjunction with any other antenna or transmitter. End-users and installers must be provided with antenna installation instructions and transmitter operating conditions for satisfying RF exposure compliance. | ||||
1 | Is there an equipment authorization waiver associated with this application? | No | ||||
1 | If there is an equipment authorization waiver associated with this application, has the associated waiver been approved and all information uploaded? | No | ||||
app s | Test Firm Name and Contact Information | |||||
1 | Firm Name |
Compliance Certification Services Inc.
|
||||
1 | Name |
P****** L********
|
||||
1 | Telephone Number |
886-3********
|
||||
1 | Fax Number |
886-3********
|
||||
1 |
p******@itri.org.tw
|
|||||
Equipment Specifications | |||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Line | Rule Parts | Grant Notes | Lower Frequency | Upper Frequency | Power Output | Tolerance | Emission Designator | Microprocessor Number | |||||||||||||||||||||||||||||||||
1 | 1 | 15C | CE | 2412.00000000 | 2462.00000000 | 0.0720000 |
some individual PII (Personally Identifiable Information) available on the public forms may be redacted, original source may include additional details
This product uses the FCC Data API but is not endorsed or certified by the FCC