Motorola Netopia 3300 Podręcznik Użytkownika

Przeglądaj online lub pobierz Podręcznik Użytkownika dla Networking Motorola Netopia 3300. Motorola Netopia 3300 User guide [en] Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 327
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów

Podsumowanie treści

Strona 1 - Software User Guide

Netopia® Software User GuideMarch 2005Netopia® 3300 Series GatewaysVersion 7.5

Strona 2 - Copyright

Table of Contents 10 -----E----- . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 291-----F----- . . . . . . .

Strona 3

100Delete User ProfileWhen you click the Delete User Profile link, the Confirm Deletion of User screen appears.

Strona 4 - Expert Mode

101ConfigureLink: UPnPUniversal Plug and Play (UPnP™) is a set of protocols that allows a PC to automatically dis-cover other UPnP devices (anything f

Strona 5

102Link: LAN ManagementTR-064 is a LAN-side DSL Gateway configuration specification. It is an extension of UPnP. It defines more services to locally mana

Strona 6

103ConfigureLink: Advanced -> Ethernet BridgeThe Netopia Gateway can be used as a bridge, rather than a router. A bridge is a device that joins two

Strona 7

104Configuring for Bridge Mode1. Browse into the Netopia Gateway’s web interface.2. Click on the Configure button in the upper Menu bar.3. Click on the

Strona 8 - Command Line Interface

105ConfigureThe Ethernet Bridge page appears.The appearance of this page varies, depending on your Gateway’s inter-faces.7. If available:a. Check the

Strona 9 - Glossary

10611. If you are satisfied with the changes you have made, click Save and Restart in the Save Database box to Apply changes and restart Gateway. You h

Strona 10 - . . . . . 303

107ConfigureLink: SystemThe System Name defaults to your Gateway's factory identifier combined with its serial number. Some cable-oriented Service

Strona 11 - Table of Contents

108• Syslog: Enable syslog logging in the system.• Syslog Host Name/IP Address: Enter the name or the IP Address of the host that should receive syslo

Strona 12

109ConfigureLog Event MessagesAdministration Related Log Messages1. administrative access attempted:This log-message is generated whenever the user at

Strona 13 - CHAPTER 1 Introduction

11 Table of Contents Canada . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307Declaration for Canadian users

Strona 14 - Intended Audience

110DSL Log Messages (most common):1. WAN: Data link activated at <Rate> Kbps (rx/tx)This log message is generated when the DSL link comes up.2.W

Strona 15 - Documentation Conventions

111Configure6. dropped - frag-mented packet:This log-message is generated whenever a packet, traversing the router, is dropped because it is fragmente

Strona 16

112Link: Internal ServersYour Gateway ships with an embedded Web server and support for a Telnet session, to allow ease of use for configuration and ma

Strona 17 - A Word About Example Screens

113ConfigureTo select the games or software that you want to host for a specific PC, highlight the name(s) in the box on the left side of the screen. C

Strona 18

114Buddy Phone Calista IP Phone CART Precision Racing, v 1.0Citrix Metaframe/ICA Client Close Combat for Windows 1.0 Close Combat: A Bridge Too Far, v

Strona 19 - CHAPTER 2 Basic Mode Setup

115ConfigureRename a User(PC)If a PC on your LAN has no assigned host name, you can assign one by clicking the Rename a User(PC) link.To rename a serv

Strona 20 - ☛ CAUTION:

116☛ NOTE:The new name given to a server is only known to Software Hosting. It is not used as an identifier in other network functions, such as DNS or

Strona 21 - Set up the Netopia Gateway

117ConfigureLink: Time ZoneWhen you click the Time Zone link, the Time Zone page appears.You can set your local time zone by selecting the number of h

Strona 22 - Then go to Step 2

118An example of multiple VLANs is shown below:To create a VLAN, click the Add button.The VLAN Entry page appears.You can create up to 32 VLANs, and y

Strona 23

119Configure• VLAN id – This must be a unique identifying number between 1 and 4095.• VLAN Name – A descriptive name for the VLAN.• VLAN Protocol – Th

Strona 24

Table of Contents 12

Strona 25 - Configure the Netopia Gateway

120For Netopia VGx technology models, separate Ethernet switch ports are displayed and may be configured.To enable any of them on this VLAN, select one

Strona 26 - Connect to the Internet

121ConfigureYou can Add, Edit, or Delete your VLAN entries by returning to the VLANs page, and selecting the appropriate entry from the displayed list

Strona 27 - Configure the Netopia Gateway

122SecurityButton: SecurityThe Security features are available by clicking on the Security toolbar button. Some items of this category do not appear w

Strona 28

123SecurityLink: PasswordsAccess to your Gateway may be controlled through two optional user accounts, Admin and User. When you first power up your Gat

Strona 29 - Home Page - Basic Mode

124To display the Passwords window, click the Security toolbar button on the Home page.Use the following procedure to change existing passwords or add

Strona 30

125SecurityPassword changes are automatically saved, and take effect immediately.Link: FirewallUse a Netopia FirewallBreakWater Basic Firewall. BreakW

Strona 31 - Link: Manage My Account

1263. Click Firewall.4. Click on the radio button to select the protection level you want. Click Submit. Changing the BreakWater setting does not requ

Strona 32 - Link: Status Details

127SecurityTIPS for making your BreakWater Basic Firewall Selection Basic Firewall BackgroundAs a device on the Internet, a Netopia Gateway requires a

Strona 33 - Enable Rmt Mgmt

128This table shows how inbound traffic is treated. Inbound means the traffic is coming from the WAN into the WAN side of the Gateway. This table shows

Strona 34 - Link: Update Firmware

129Security☛ NOTE:The Gateway’s WAN DHCP client port in SilentRunning mode is enabled. This feature allows end users to continue using DHCP-served IP

Strona 35 - Continue

13 What’s New in 7.5 CHAPTER 1 Introduction What’s New in 7.5 New in Netopia Firmware Version 7.5 are the following features: Web-based User Interfac

Strona 36

130Link: IPSecWhen you click on the IPSec link, the IPSec configuration screen appears.Your Gateway can support two mechanisms for IPSec tunnels:• IPSe

Strona 37 - Link: Access Control Login

131SecuritySafeHarbour IPSec VPNSafeHarbour VPN IPSec Tunnel provides a single, encrypted tunnel to be terminated on the Gateway, making a secure tunn

Strona 38

132A typical SafeHarbour configuration is shown below:Configuring a SafeHarbour VPNUse the following procedure to configure your SafeHarbour tunnel.1. Ob

Strona 39 - CHAPTER 3 Expert Mode

133SecurityTable 1: IPSec Tunnel Details Parameter Setup WorksheetParameter Netopia Gateway Peer GatewayNamePeer Internal NetworkPeer Internal Netmask

Strona 40

1343. Be sure that you have SafeHarbour VPN enabled.SafeHarbour is a keyed feature. See “Install Keys” on page 184. for information con-cerning instal

Strona 41 - Home Page - Information

135Security10.Make the Tunnel Details entries.Enter or select the required set-tings.Refer to your “IPSec Tunnel Details Parameter Setup Work-sheet” o

Strona 42

136Parameter DescriptionsThe following tables describe SafeHarbour’s parameters that are used for an IPSec VPN tunnel configuration:Table 2: IPSec Conf

Strona 43 - Link: Breadcrumb Trail

137SecurityPAT Address If NAT is enabled, this field appears. You can specify a Port Address Trans-lation (PAT) address or leave the default all-zeroes

Strona 44 - Button: Restart

138SA Hash Type SA Hash Type refers to the Authentication Hash algorithm used during SA negotiation. Values supported include MD5 and SHA1. N/A will

Strona 45 - Link: Alert Symbol

139SecurityXauth Enable Extended Authentication (XAuth), an extension to the Internet Key Exchange (IKE) protocol. The Xauth extension provides dual a

Strona 46 - Button: Help

14 About Netopia Documentation ☛ NOTE: This guide describes the wide variety of features and functionality of the Neto-pia Gateway, when used in Ro

Strona 47 - Link: Quickstart

140Link: Stateful InspectionAll computer operating systems are vulnerable to attack from outside sources, typically at the operating system or Interne

Strona 48

141Security• UDP no-activity time-out: The time in seconds after which a UDP session will be ter-minated, if there is no traffic on the session.• TCP n

Strona 49 - Link: LAN

142Add, Edit, or delete exposed addresses options are active only if NAT is disabled on a WAN interface. The hosts specified in exposed addresses will

Strona 50

143SecurityClick the Add button to add a new range of exposed addresses.You can edit a previously configured range by clicking the Edit button, or dele

Strona 51

144Stateful Inspection OptionsStateful Inspection Parameters are active on a WAN interface only if you enable them on your Gateway.• Stateful Inspecti

Strona 52 - Wireless

145SecurityOpen Ports in Default Stateful Inspection Installation Port Protocol DescriptionLAN (Private) InterfaceWAN (Public) Interface23 TCP telnet

Strona 53

146Link: Packet FilterWhen you click the Packet Filter link the Filter Sets screen appears.Security should be a high priority for anyone administering

Strona 54

147Securityadmit or refuse TCP/IP connections from certain remote networks and specific hosts. You will also use filters to screen particular types of c

Strona 55 - Advanced

148A filter inspects data packets like a customs inspector scrutinizing packages.Filter priorityContinuing the customs inspectors analogy, imagine the

Strona 56

149Securitychance to forward or reject it, and so on. Because of this hierarchical structure, each filter is said to have a priority. The first filter ha

Strona 57

15 Documentation Conventions Documentation Conventions General This manual uses the following conventions to present information: Internal Web Interf

Strona 58

150Here is what this rule looks like when implemented as a filter in Netopia Firmware Version 7.5: To understand this particular fil-ter, look at the pa

Strona 59 - Wireless MAC Authorization

151SecurityPort number comparisonsA filter can also use a comparison option to evaluate a packet’s source or destination port number. The comparison op

Strona 60

152Other filter attributesThere are three other attributes to each filter:• The filter’s order (i.e., priority) in the filter set• Whether the filter is cu

Strona 61

153Security• Src Port: The source port to match. This is the port on the sending host that originated the packet.• Dst Port: The destination port to m

Strona 62

154• Destination Port = 23• The filter should be enabled and instructed to block the Telnet packets containing the source address shown in step 2:• For

Strona 63 - RADIUS Server

155SecurityFiltering example #2Suppose a filter is configured to block all incoming IP packets with the source IP address of 200.233.14.0, regardless of

Strona 64 - Link: WAN

156Design guidelinesCareful thought must go into designing a new filter set. You should consider the following guidelines: • Be sure the filter set’s ov

Strona 65 - ATM Traffic Shaping

157Working with IP Filters and Filter SetsWorking with IP Filters and Filter SetsTo work with filters and filter sets, begin by accessing the filter set

Strona 66

158Enter new name for the filter set, for example Filter Set 1.To save the filter set, click the Submit button. The saved filter set is empty (contains n

Strona 67

159Working with IP Filters and Filter SetsPackets in Netopia Firmware Version 7.5 pass through an input filter if they originate from the WAN and throu

Strona 68 - Link: Advanced

16curly ({ }) brackets, with values sep-arated with vertical bars (|).Alternative values for an argument are pre-sented in curly ({ }) brackets, with

Strona 69 - Link: IP Static ARP

160The Filter Set page appears.☛ Note:There are two Add buttons in this page, one for input filters and one for out-put filters. In this section, you’l

Strona 70 - Application 1

161Working with IP Filters and Filter Sets2. If you want the filter to forward packets that match its criteria to the desti-nation IP address, check th

Strona 71 - Application 3

162If Protocol Type is set to TCP or UDP, the settings for port comparison will appear. These settings only take effect if the Protocol Type is TCP or

Strona 72

163Working with IP Filters and Filter SetsModifying filtersTo modify a filter, select a filter from the table and click the Edit button. The Rule Entry p

Strona 73

164Associating a Filter Set with an InterfaceOnce you have created a filter set, you must associate it with an interface in order for it to be effectiv

Strona 74 - Add or Edit more Pinholes

165Firewall TutorialYou can repeat this process for both the WAN and LAN interfaces, to associate your filter sets.When you return to the Filter Sets p

Strona 75

166Host: A workstation on the network.Packet: Unit of communication on the Internet.Packet filter: Packet filters allow or deny packets based on source

Strona 76

167Firewall TutorialExample TCP/UDP PortsFirewall design rulesThere are two basic rules to firewall design:• “What is not explicitly allowed is denied.

Strona 77

168and a packet goes through these rules destined for FTP, the packet would forward through the first rule (WWW), go through the second rule (FTP), and

Strona 78 - NAT/PAT Table

169Firewall TutorialExample filter set pageThis is an example of the Netopia filter set page:

Strona 79 - Link: Default Server

17OrganizationOrganizationThis guide consists of eight chapters, including a glossary, and an index. It is organized as follows:• Chapter 1, “Introduc

Strona 80

170Filter basicsIn the source or destination IP address fields, the IP address that is entered must be the network address of the subnet. A host addres

Strona 81

171 Firewall Tutorial Example filters Example 1 Incoming packet has the source address of 200.1.1.28This incoming IP packet has a source IP address t

Strona 82

172 Example 4 Incoming packet has the source address of 200.1.1.104.This rule does match and this packet will not be forwarded. Example 5 Incomin

Strona 83 - Link: Differentiated Services

173 Policy-based Routing using Filtersets Policy-based Routing using Filtersets Netopia Firmware Version 7.5 offers the ability to route IP packets u

Strona 84

174 If you check the Idle Reset checkbox, a match on this rule will keep the WAN connection alive by resetting the idle-timeout status.The Idle Res

Strona 85

175 Policy-based Routing using Filtersets subsequent filter is required to match and forward all other packets. Management IP traffic If the Force Rout

Strona 86 - Link: DHCP Server

176 Link: Security Log Security Monitoring is a keyed feature. See page 184 for information concerning installing Netopia Software Feature Keys.Secur

Strona 87

177Policy-based Routing using FiltersetsThe capacity of the security log is 100 security alert messages. When the log reaches capacity, subsequent mes

Strona 88 - Link: SNMP

178To reset this log, select Reset from the Security Monitor tool bar.The following message is displayed.When the Security Log contains no entries, th

Strona 89

179InstallInstallButton: InstallFrom the Install toolbar button you can Install new Operating System Software and Feature Keys as updates become avail

Strona 91

180Link: Install Software(This link is not available on the 3342/3352 models, since firmware updates must be upgraded via the USB host driver.)This pag

Strona 92

181InstallBackgroundFirmware upgrade image files are posted periodically on the Netopia website. You can download the latest operating system software

Strona 93 - Add User

182a. Click the Browse button, select the file you want, and click Open. -or-b. Enter the name and path of the software image you want to install in

Strona 94 - Edit Profile

183InstallVerify the Netopia Firmware ReleaseTo verify that the Netopia firmware image has loaded successfully, use the following steps:1. Open a web c

Strona 95 - Web Filter Profile

184Link: Install KeysYou can obtain advanced product functionality by employing a software Feature Key. Soft-ware feature keys are specific to a Gatewa

Strona 96 - Chat Filter Profile

185Install4. Click the Install Key button.5. Click the Restart toolbar button.The Confirmation screen appears.

Strona 97

1866. Click the Restart the Gateway link to confirm.To check your installed features:7. Click the Install toolbar button.8. Click the list of features

Strona 98 - Email Filter Profile

187InstallThe System Status page appears with the information from the features link displayed below. You can check that the feature you just installe

Strona 100 - Delete User Profile

189CHAPTER 4 Basic TroubleshootingThis section gives some simple suggestions for troubleshooting problems with your Gate-way’s initial configuration.Be

Strona 101 - Link: UPnP

19CHAPTER 2 Basic Mode SetupMost users will find that the basic Quickstart configuration is all that they ever need to use. This section may be all that

Strona 102 - Link: LAN Management

190Status Indicator LightsThe first step in troubleshooting is to check the status indicator lights (LEDs) in the order outlined below.Netopia Gateway

Strona 103 - ☛ NOTE:

191Status Indicator LightsNetopia Gateway 3341, 3351 status indicator lightsEthernet LinkEthernet TrafficDSL TrafficDSL SyncUSB ActivePowerPower:USB A

Strona 104 - Configuring for Bridge Mode

192Netopia Gateway 3342, 3352 status indicator lights☛ Special patterns:• Both LEDs are off during boot (power on boot or warm reboot). • When the 33

Strona 105 - Enable System Bridge

193Status Indicator LightsNetopia Gateway 3346, 3356 status indicator lightsLAN 1LAN 2LAN 3LAN 4DSL SYNCPowerPower:DSL Sync:Solid green when trained w

Strona 106 - Save and

194Netopia Gateway 3347W, 3347WG status indicator lightsLED Function Summary MatrixPowerUSB ActiveDSL SyncDSL TrafficEthernet TrafficEthernet LinkUnlit

Strona 107 - Link: Syslog Parameters

195Status Indicator LightsIf a status indicator light does not look correct, look for these possible problems: LED State Possible problemsPower Unlit1

Strona 108

196EN TrafficUnlit1. Make sure you have Ethernet drivers installed on the PC.2. Make sure the PC’s TCP/IP Properties for the Ethernet Network Control P

Strona 109 - Log Event Messages

197Factory Reset SwitchFactory Reset Switch(optional on some models; 3342/3352 models do not have a reset switch)Lose your password? This section show

Strona 110 - Access-related Log Messages

1982. Carefully insert the point of a pen or an unwound paperclip into the open-ing.•If you press the factory default button for less than 1/2 a secon

Strona 111

199CHAPTER 5 Advanced TroubleshootingAdvanced Troubleshooting can be accessed from the Gateway’s Web UI. Point your browser to http://192.168.1.254. T

Strona 112 - Link: Software Hosting

2 Copyright Copyright © 2005 Netopia, Inc. Netopia and the Netopia logo are registered trademarks belonging to Netopia, Inc., registered U.S. Patent

Strona 113 - Age of Wonders

20Important Safety InstructionsPOWER SUPPLY INSTALLATIONConnect the power supply cord to the power jack on the Netopia Gateway. Plug the power supply

Strona 114

200Home PageThe home page displays basic information about the Gateway. This includes the ISP User-name, Connection Status, Device Address, Remote Gat

Strona 115 - Rename a User(PC)

201ISP Username This should be the valid PPPoE username. If not, go to Expert Mode and change to the correct username.Device Address This is the negot

Strona 116

202Button: TroubleshootExpert ModeExpert Mode has advanced troubleshooting tools that are used to pinpoint the exact source of a problem. Clicking the

Strona 117 - Link: VLAN

203Link: Ports: EthernetThe Ethernet port selection shows the traffic sent and received on the Ethernet interface. There should be frames and bytes on

Strona 118

204Link: Ports: DSLThe DSL port selection shows the state of the DSL line, whether it is up or down and how many times the Gateway attempted to train.

Strona 119 - Configure

205Link: DSL: Circuit ConfigurationThe DSL Circuit Configuration screen shows the traffic sent and received over the DSL line as well as the trained rate

Strona 120 - ☛ Note:

206Link: System Log: EntireThe system log shows the state of the WAN connection as well as the PPPoE session. Ver-ify that the PPPoE session has been

Strona 121

207Link: DiagnosticsThe diagnostics section tests a number of different things at the same time, including the DSL line, the Ethernet inter face and t

Strona 122 - Button: Security

208Link: Network ToolsThree test tools are available from this page.• NSLookup - converts a domain name to its IP address and vice versa.• Ping - test

Strona 123 - Link: Passwords

209PING: The network tools section sends a PING from the Gateway to either the LAN or WAN to verify connectivity. A PING could be either an IP address

Strona 124

21Set up the Netopia GatewaySet up the Netopia GatewayRefer to your Quickstart Guide for instructions on how to connect your Netopia gateway to your p

Strona 125

210Below are some specific tests:3. To use the TraceRoute capability, type a destination address (domain name or IP address) in the text box and click

Strona 126 - Firewall

211Example: Show the path to the grosso.com site.Result: It took 20 hops to get to the grosso.com web site.

Strona 128

213CHAPTER 6 Command Line InterfaceThe Netopia Gateway operating software includes a command line interface (CLI) that lets you access your Netopia Ga

Strona 129

214OverviewThe CLI has two major command modes: SHELL and CONFIG. Summary tables that list the commands are provided below. Details of the entire comm

Strona 130 - Link: IPSec

215OverviewCONFIG CommandsCommand Verbs Status and/or Descriptiondelete Delete configuration list datahelp Help command optionsave Save configuration da

Strona 131 - SafeHarbour IPSec VPN

216Starting and Ending a CLI SessionOpen a telnet connection from a workstation on your network.You initiate a telnet connection by issuing the follow

Strona 132

217Using the CLI Help FacilitySaving SettingsIn CONFIG mode, the save command saves the working copy of the settings to the Gate-way. The Gateway auto

Strona 133 - Security

218The only commands you cannot truncate are restart and clear. To prevent accidental interruption of communications, you must enter the restart and c

Strona 134

219SHELL Commandsthe diagnostic utility indents its entry in the console window. For example, the diagnostic utility indents the Check IP connect to E

Strona 135 - Save and Restart

22Then go to Step 2.Step 2. Select Obtain an IP address automatically.Step 3. Select Obtain DNS server address automatically, if available.Step 4. Rem

Strona 136

220If you include the optional keyword confirm, you will not be prompted to confirm whether or not you want to perform the operation.license [key]This

Strona 137

221SHELL Commandsnetstat -i Displays the IP interfaces for your Netopia Gateway.netstat -r Displays the IP routes stored in your Netopia Gateway.nsloo

Strona 138

222reset arp Clears the Address Resolution Protocol (ARP) cache on your unit.reset atmResets the Asynchronous Transfer Mode (ATM) statistics.reset cra

Strona 139

223SHELL Commandsreset security-logClears the security monitoring log to make room to capture new entries. reset wan-users [all | ip-address]This func

Strona 140

224show bridge interfacesDisplays bridge interfaces maintained by the Netopia Gateway.show bridge tableDisplays the bridging table maintained by the N

Strona 141 - Exposed Addresses

225SHELL Commandsshow ip lan-discoveryDisplays the LAN Host Discovery Table of hosts on the wired or wireless LAN, and whether or not they are current

Strona 142 - Add more Exposed Addresses

226show wireless [all]Shows wireless status and statistics.show wireless clients [ MAC_address ]Displays details on connected clients, or more details

Strona 143

227SHELL CommandsWAN Commandsatmping vccn [ segment | end-to-end ]Lets you check the ATM connection reachability and network connectivity. This comman

Strona 144

228show configDumps the Netopia Gateway’s configuration script just as the script command does in config mode.show dslDisplays DSL port statistics, such

Strona 145 - WAN (Public)

229About CONFIG CommandsSome CLI commands are not available until certain conditions are met. For example, you must enable IP for an interface before

Strona 146 - ☛ WARNING:

23Set up the Netopia GatewayMacintosh MacOS 8 or higher or Mac OS X: Step 1. Access the TCP/IP or Network control panel. a. MacOS follows a path like

Strona 147 - How filter sets work

230Entering Commands in CONFIG ModeCONFIG commands consist of keywords and arguments. Keywords in a CONFIG command specify the action you want to take

Strona 148 - APPROVED

231About CONFIG CommandsGuidelines: CONFIG CommandsThe following table provides guidelines for entering and formatting CONFIG commands.If a command is

Strona 149 - How individual filters work

232Step Mode: A CLI Configuration TechniqueThe Netopia Gateway command line interface includes a step mode to automate the pro-cess of entering configur

Strona 150

233CONFIG CommandsDogzilla (top)>> validateError: Subnet mask is incorrectGlobal Validation did not passinspection!You can use the validate comm

Strona 151

234• cbr: One parameter is required for CBR VCs. Enter the Peak Cell Rate that applies to the VC. This value should be between 1 and the line rate. Yo

Strona 152

235CONFIG Commandsset atm [vccn] encap { ppp-vcmux | ppp-llc | ether-llc | ip-llc | ppoe-vcmux | pppoe-llc }Sel

Strona 153

236☛ NOTE:For bridging in the 3341 (or any model with a USB port), you cannot set the bridge option off, or bridge ethernet option off; these are on

Strona 154 - • Forward = unchecked

237CONFIG CommandsDHCP SettingsAs a Dynamic Host Control Protocol (DHCP) server, your Netopia Gateway can assign IP addresses and provide configuration

Strona 155

238DMT Settings DSL Commandsset dmt type [ lite | dmt | ansi | multi ] Selects the type of Discrete Multitone (DMT) asynchronous digital subscriber li

Strona 156 - Design guidelines

239CONFIG CommandsCommon Commandsset dns domain-name domain-name Specifies the default domain name for your network. When an application needs to resol

Strona 157

24Then go to Step 2.Step 2. Select Built-in Ethernet Step 3. Select Configure Using DHCPStep 4. Close and Save, if prompted.Proceed to “Configure the Ne

Strona 158

240Because different dynamic DNS vendors use different proprietary protocols, currently only www.dyndns.org is supported.IP SettingsYou can use the co

Strona 159

241CONFIG Commandsset ip dsl vccn broadcast broadcast_addressSpecifies the broadcast address for the TCP/IP network connected to the virtual circuit. I

Strona 160

242an extension of RIP-2 that increases security by requiring an authentication key when routes are advertised.Depending on your network needs, you ca

Strona 161

243CONFIG CommandsThe broadcast address for most networks is the network number followed by 255. For example, the broadcast address for the 192.168.1.

Strona 162 - 9. From the

244set ip ethernet A rip-receive { off | v1 | v2 | v1-compat | v2-MD5 }Specifies whether the Netopia Gateway should use Routing Information Protocol (R

Strona 163 - Deleting a filter set

245CONFIG Commandsset ip ip-ppp [vccn] address ip_addressAssigns an IP address to the virtual PPP interface. If you specify an IP address other than 0

Strona 164 - Ethernet 100BT

246set ip ip-ppp [vccn] rip-send { off | v1 | v2 | v1-compat | v2-MD5 }Specifies whether the Netopia Gateway unit should use Routing Information Protoc

Strona 165

247CONFIG CommandsStatic ARP SettingsYour Netopia Gateway maintains a dynamic Address Resolution Protocol (ARP) table to map IP addresses to Ethernet

Strona 166 - Basic protocol types

248IP Prioritizationset ip prioritize [ off | on ]Allows you to support traffic that has the TOS bit set. This defaults to off.Differentiated Services

Strona 167 - Firewall design rules

249CONFIG Commandsset diffserv custom-flows name name protocol [ TCP | UDP | ICMP | other ] direction [ outbound | inbound | both ]

Strona 168

25Configure the Netopia GatewayConfigure the Netopia Gateway1. Run your Web browser application, such as Netscape Navigator or Microsoft Internet Explo

Strona 169 - Example filter set page

250SIP Passthroughset ip sip-passthrough [ on | off ]Turns Session Initiation Protocol application layer gateway client passthrough on or off. The def

Strona 170 - Input Packet

251CONFIG Commandsset ip static-routes destination-network net_address gateway-address gate_addressSpecifies the IP address of the Gateway for the

Strona 171 - Example filters

252set ip-maps name <name> external-ip <ip address>Specifies the name and static ip address of the WAN device to be mapped.Up to 8 mapped s

Strona 172

253CONFIG CommandsNetwork Address Translation (NAT) Pinhole SettingsNAT pinholes let you pass specific types of network traffic through the NAT interfac

Strona 173 - TOS field matching

254set pinhole name name internal-ip internal-ipSpecifies the IP address of the internal host to which traffic of the specified type should be transferre

Strona 174

255CONFIG Commandsset ppp module [vccn] magic-number { on | off }Enables or disables LCP magic number negotiation.set ppp module [vccn] protocol-compr

Strona 175

256set ppp module [vccn] terminate-max integerSpecifies the maximum number of unacknowledged termination requests that your Netopia Gateway will send b

Strona 176 - Security Log

257CONFIG Commands option [ off | on | pap-only | chap-only ]Specifying on turns both PAP and CHAP on, or you can select PAP or CHAP. Specify t

Strona 177

258set preference more linesSpecifies how many lines of information you want the command line interface to display at one time. The lines argument spec

Strona 178

259CONFIG CommandsPort Renumbering SettingsIf you use NAT pinholes to forward HTTP or telnet traffic through your Netopia Gateway to an internal host,

Strona 179 - Button: Install

26The browser then displays the Welcome page.The browser then displays the Quickstart web page.2. Enter the username and password supplied by your Int

Strona 180 - Link: Install Software

260Security SettingsSecurity settings include the Firewall and IPSec parameters. All of the security functionality is keyed.Firewall Settings (for Bre

Strona 181 - Install Software

261CONFIG Commandsset security ipsec tunnels name "123" tun-enable (on) {on | off}This enables this particular tunnel. Currently, one

Strona 182

262set security ipsec tunnels name "123" IKE-mode pre-shared-key ("") {hex string}See page 130 for details about SafeHarbour

Strona 183

263CONFIG Commandsset security ipsec tunnels name "123" IKE-mode PFS-enable { off | on }See page 130 for details about SafeHarbour IPse

Strona 184 - Link: Install Keys

264set security ipsec tunnels name "123" local-id id_valueSpecifies the NAT local ID value as specified in the local-id-type for the specified

Strona 185 - Install Key

265CONFIG CommandsInternet Key Exchange (IKE) SettingsThe following four IPsec parameters configure the rekeying event.set security ipsec tunnels name

Strona 186 - Restart the Gateway

266Stateful InspectionStateful inspection options are accessed by the security state-insp tag.set security state-insp [ ip-ppp | dsl ] vccn option [ o

Strona 187

267CONFIG Commandsset security state-insp udp-timeout [ 30 - 65535 ]Sets the stateful inspection UDP timeout interval, in seconds.set security state-i

Strona 188

268set security state-insp xposed-addr exposed-address# "n" start-port [ 1 - 65535 ]set security state-insp xposed-addr exposed

Strona 189 - • read the Quickstart Guide;

269CONFIG Commandsset security pkt-filter filterset filterset-name in index frc-rte [ on | off ]Turns forced routing on or off for the specified filter rul

Strona 190 - Status Indicator Lights

27Configure the Netopia GatewayOnce a connection is established, your browser is redirected to your service provider’s home page or a registration pag

Strona 191

270set security pkt-filter filterset filterset-name in index protocol valueSpecifies the protocol value to match packets, the type of higher-layer Interne

Strona 192 - ☛ Special patterns:

271CONFIG Commandsset security pkt-filter filterset filterset-name in index src-port valueSpecifies the source IP port to match packets (the port on the s

Strona 193 - LAN 1, 2, 3, 4:

272set snmp sysgroup contact contact_infoIdentifies the system contact, such as the name, phone number, beeper number, or email address of the person r

Strona 194

273CONFIG Commandsassigned a name to your Netopia Gateway, you can enter that name in the Address text field of your browser to open a connection to yo

Strona 195

274set system idle-timeout { telnet [ 1...120 ] | http [ 1... 120 ] }Specifies a timeout period of inactivity for telnet or HTTP access to the Gateway,

Strona 196

275CONFIG Commands location ("string"):The heartbeat setting is used in conjunction with the configuration server to broadcast con-tact

Strona 197 - Factory Reset Switch

276set system ntp option [ off | on ]:server-address (204.152.184.72)alt-server-address (""):time-zone [ -12 - 12 ] update-period (60) [ 1 -

Strona 198

277CONFIG CommandsSyslogset system syslog option [ off | on ]Enables or disables system syslog feature. If syslog option is on, the following commands

Strona 199

278 set security state-insp eth B option on• Type the command to enable the router to drop fragmented packets set security state-insp eth B deny-fr

Strona 200 - Home Page

279CONFIG CommandsWireless Settings (supported models)set wireless option ( on | off )Administratively enables or disables the wireless interface.set

Strona 201 - Expert Mode

28Netopia Gateway Status Indicator LightsColored LEDs on your Netopia Gateway indicate the status of various port activity. Different Gateway models h

Strona 202 - Link: System Status

280set wireless privacy option { off | WEP | WPA-PSK | WPA-802.1x }Specifies the type of privacy enabled on the wireless LAN. off = no privacy; WEP = W

Strona 203 - Link: Ports: Ethernet

281CONFIG CommandsFor simplicity, it is easiest to have both the Gateway and the client transmit with the same key. The default is 1.

Strona 204 - Link: Ports: DSL

282set wireless privacy encryption-key1-length {40/64bit, 128bit, 256bit}set wireless privacy encryption-key2-length {40/64bit, 128bit, 256b

Strona 205

283CONFIG CommandsWireless MAC Address Authorization Settingsset wireless mac-auth option { on | off }Enabling this feature limits the MAC addresses t

Strona 206 - Link: System Log: Entire

284set radius radius-port port_numberSpecifies the port on which the RADIUS server is listening. The default value is 1812.VLAN SettingsThese settings

Strona 207 - Link: Diagnostics

285CONFIG Commandsenabled Netopia Gateway, will not need application layer gateway support on the Netopia Gateway to work through NAT. The default is

Strona 208 - Link: Network Tools

286TR-069. DSL Forum CPE WAN Management Protocol (TR-069) provides services similar to UPnP and TR-064. The communication between the Netopia Gateway

Strona 209 - button

287CHAPTER 7 Glossary10Base-T. IEEE 802.3 specification for Ethernet that uses unshielded twisted pair (UTP) wiring with RJ-45 eight-conductor plugs at

Strona 210 - TraceRoute

288ADSL. Asymmetric Digital Subscriber Line. Modems attached to twisted pair copper wiring that transmit 1.5-9 Mbps downstream (to the subscriber) and

Strona 211

289BRI. Basic Rate Interface. ISDN standard for provision of low-speed ISDN services (two B channels (64 kbps each) and one D channel (16 kbps)) over

Strona 212

29Home Page - Basic ModeHome Page - Basic ModeAfter you have performed the basic Quickstart configuration, any time you log in to your Netopia Gateway

Strona 213

290crossover cable. Cable that lets you connect a port on one Ethernet hub to a port on another Ethernet hub. You can order an Ethernet crossover cabl

Strona 214 - Overview

291Diffie-Hellman. A group of key-agreement algorithms that let two computers compute a key independently without exchanging the actual key. It can gen

Strona 215 - Keywords

292encapsulation. Technique used to enclose information formatted for one protocol, such as AppleTalk, within a packet formatted for a different proto

Strona 216 - Ending a CLI Session

293FTP. File Transfer Protocol. Application protocol that lets one IP node trans-fer files to and from another node.FTP server. Host on network from wh

Strona 217 - About SHELL Commands

294-----I-----IKE. Internet Key Exchange protocol provides automated key management and is a preferred alternative to manual key management as it prov

Strona 218 - SHELL Commands

295-----K-----Key Management . The Key Management algorithm manages the exchange of security keys in the IPSec protocol architecture. SafeHarbour supp

Strona 219 - CODE Description

296at the other end of the connection converts the analog signal back to a digi-tal signal. MRU. Maximum Receive Unit. The maximum packet size, in byt

Strona 220

297PAP. Password Authentication Protocol. Security protocol within the PPP pro-tocol suite that prevents unauthorized access to network services. See

Strona 221

298protocol. Formal set of rules and conventions that specify how information can be exchanged over a network. PSTN. Public Switched Telephone Network

Strona 222

299• The authentication algorithm for AH and ESP• The encryption algorithm for ESP• The encryption and authentication keys• Lifetime of encryption key

Strona 223

3 Table of Contents Table of Contents Copyright . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 CHAPTER 1 Int

Strona 224

30The Home Page displays the following information in the center section: The links in the left-hand column on this page allow you to manage or configu

Strona 225

300conversation, rather than just individual packets. It verifies that packets are sent from and received by the proper IP addresses along the proper c

Strona 226

301-----V-----VJ. Van Jacobson. Abbreviation for a compression standard documented in RFC 1144. VLAN. Virtual Local Area Network. A network of compute

Strona 228 - About CONFIG Commands

303DescriptionCHAPTER 8 Technical Specifications and Safety InformationDescriptionDimensions: Smart Modems: 13.5 cm (w) x 13.5 cm (d) x 3.5 cm (h); 5.

Strona 229

304Software and protocolsSoftware media: Software preloaded on internal flash memory; field upgrades done via download to internal flash memory via TFTP

Strona 230

305Agency approvalsAgency approvalsNorth AmericaSafety Approvals: United States – UL 60950, Third Edition Canada – CSA: CAN/CSA-C22.2 No. 60950-00EM

Strona 231 - Guidelines: CONFIG Commands

306The Netopia Firmware Version 7.4.2 complies with the following EU directives: Low Voltage, 73/23/EEC EMC Compatibility, 89/336/EEC, conforming to

Strona 232

307Manufacturer’s Declaration of Conformance☛ ImportantThis product was tested for FCC compliance under conditions that included the use of shielded

Strona 233

308Important Safety InstructionsAustralian Safety InformationThe following safety information is provided in conformance with Australian safety requir

Strona 234

30947 CFR Part 68 Information47 CFR Part 68 InformationFCC Requirements1. The Federal Communications Commission (FCC) has established Rules which perm

Strona 235

31Home Page - Basic ModeLink: Manage My AccountYou can change your ISP account information for the Netopia Gateway. You can also man-age other aspects

Strona 236

310d) The REN is used to determine the number of devices that may be connected to a telephone line. Excessive RENs on a telephone line may result in t

Strona 237

311CHAPTER 9 Overview of Major CapabilitiesThe Netopia Gateway offers simplified setup and management features as well as advanced broadband router cap

Strona 238

312Wide Area Network TerminationPPPoE/PPPoA (Point-to-Point Protocol over Ethernet/ATM)The PPPoE specification, incorporating the PPP and Ethernet stan

Strona 239 - Dynamic DNS Settings

313Simplified Local Area Network Setup• Your network may change address with each connection making it more difficult to attack.When you configure Insta

Strona 240

314☛ NOTE:The Netopia DNS Proxy only proxies UDP DNS queries, not TCP DNS queries.ManagementEmbedded Web ServerThere is no specialized software to in

Strona 241

315SecurityTraceRoute - displays the path to a destination by showing the number of hops and the router addresses of these hops.The system log also pr

Strona 242 - Ethernet LAN Settings

316from routers on networks connected to its WAN interface. In other words, the end com-puter stations on your LAN are invisible from the Internet.Onl

Strona 243

317Security☛ NOTE:1. The default setting for NAT is ON.2. Netopia uses Port Address Translation (PAT) to implement the NAT facility.3. NAT Pinhole tr

Strona 244

318Common TCP/IP protocols and ports are:See page 70 for How To instructions.Default ServerThis feature allows you to:• Direct your Gateway to forward

Strona 245

319SecurityIP-PassthroughNetopia OS now offers an IP passthrough feature. The IP passthrough feature allows a sin-gle PC on the LAN to have the Gatewa

Strona 246

32Link: Status DetailsIf you need to diagnose any problems with your Netopia Gateway or its connection to the Internet, you can run a sophisticated di

Strona 247 - MAC_address

320☛ NOTE:Typically, no special configuration is necessary to use the IPSec pass through feature.In the diagram, VPN PC clients are shown behind the N

Strona 248

321IndexSymbols!! command 218AAccess Controls 91Access the GUI 39Address resolution table 224Administrativerestrictions 245Administrator password 39,1

Strona 249 -

322(DNS) 238DSL Forum settings 285EEcho request 255echo-period 255Embedded Web Server 314Ethernet address 235Ethernet statistics 222FFeature KeysObtai

Strona 250 - Static Route Settings

323Local Area Network 313Location, SNMP 271, 272Log 225Logging in 216lost echoes 255MMagic number 255Maturity Level 92Memory 225Metric 251Multiple Wir

Strona 251

324SSecondary nameserver 238securityfilters 146–??Security log 177Set bncp command 233,234, 235Set bridge commands 236Set dns commands 239Set ip stati

Strona 252

325Telnet command 226Telnet traffic 259TFTP 252TFTP server 219Toolbar 43TOS bit 150, 173TraceRoute 208, 315Trap 271Trivial File TransferProtocol 219Tr

Strona 254

Netopia 3300 series by NetopiaNetopia, Inc.6001 Shellmound StreetEmeryville, CA 94608April 21, 2005

Strona 255

33Home Page - Basic ModeLink: Enable Remote ManagementThis link allows you to authorize a remotely-located person, such as a support technician, to di

Strona 256

34Link: Expert ModeMost users will find that the basic Quickstart configuration is all that they ever need to use. Some users, however, may want to do m

Strona 257

35Home Page - Basic ModeClick the Update Firmware link. The Firmware Update Confirmation page appears.If you click the Continue button, the Gateway wil

Strona 258

36Link: Factory ResetIn some cases, you may need to clear all the configuration settings and start over again to program the Netopia Gateway. You can p

Strona 259

37Home Page - Basic ModeLink: Access Control LoginIf you have configured Access Controls (see “Access Control” on page 91) an additional link Access Co

Strona 261

39Access the Expert Web InterfaceCHAPTER 3 Expert ModeUsing the Expert Mode Web-based user interface for the Netopia 3300-series Gateway you can config

Strona 262

Table of Contents 4 Update Firmware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34Factory Reset . . . . . . .

Strona 263

403. Click on the Expert Mode link in the left-hand column of links.You are challenged to confirm your choice.Click OK.The Home Page opens in Expert Mo

Strona 264

41Access the Expert Web InterfaceHome Page - Expert ModeThe Home Page is the summary page for your Netopia Gateway. The toolbar at the top pro-vides l

Strona 265

42Product ID Refers to internal circuit board series; useful in determining which software upgrade applies to your hardware type.Date & Time This

Strona 266 - Stateful Inspection

43ToolbarToolbarThe toolbar is the dark blue bar at the top of the page containing the major navigation but-tons. These buttons are available from alm

Strona 267 - Example:

44RestartButton: RestartThe Restart button on the toolbar allows you to restart the Gateway at any time. You will be prompted to confirm the restart be

Strona 268

45RestartLink: Alert SymbolThe Alert symbol appears in the upper right corner if you make a database change; one in which a change is made to the Gate

Strona 269

46HelpButton: HelpContext-sensitive Help is provided in your Gateway. The page shown here is displayed when you are on the Home page or other transiti

Strona 270 - Operator Action

47ConfigureConfigureButton: ConfigureThe Configuration options are presented in the order of likelihood you will need to use them. Quickstart is typicall

Strona 271

481. Enter your ISP Username and ISP Password.2. Click Connect to the Internet.A brief message is displayed while the Gateway attempts to establish a

Strona 272 - SNMP Notify Type Settings

49ConfigureLink: LAN* Enable Interface: Enables all LAN-connected computers to share resources and to con-nect to the WAN. The Interface should always

Strona 273

5 Table of Contents Can I use IPMaps with my PPPoE or PPPoA connection? . . . . . 77Will IPMaps allow IP addresses from different subnets to be assi

Strona 274

50• Advanced: Clicking on the Advanced link displays the Advanced LAN IP Interface page.• IGMP Forwarding: The default setting is Disabled. If you che

Strona 275 - "):

51Configure• DHCP Server: Your Gateway can provide network configuration information to computers on your LAN, using the Dynamic Host Configuration Prot

Strona 276

52WirelessIf your Gateway is a wireless model (such as a 3347W) you can enable or disable the wire-less LAN (WLAN) by clicking the Wireless link. Wire

Strona 277

53ConfigurePrivacy• Off - No Privacy provides no encryption on your wireless LAN data.• WPA-802.1x provides RADIUS server authentication support.• WPA

Strona 278 - • Type save

54The Pre Shared Key is a passphrase shared between the Router and the clients and is used to generate dynamically changing keys. The passphrase can b

Strona 279

55ConfigureAdvancedIf you click the Advanced link, the advanced 802.11 Wireless Settings page appears.Note: This page displays different options depen

Strona 280

56You can then configure:Enable Multiple Wireless IDs: This feature allows you to add additional network identifi-ers (SSIDs or Network Names) for your

Strona 281

57Configurethe same channel, the Netopia Gateway will initiate a three- to four-minute scan of the channels, locate a better one, and switch. Once it

Strona 282

58☛ NOTE: While clients may also have a passphrase feature, these are vendor-specific and may not necessarily create the same keys. You can passphrase

Strona 283 - RADIUS Server Settings

59ConfigureEncryption Key Size #1 – #4: Selects the length of each encryption key. The longer the key, the stronger the encryption and the more difficu

Strona 284

Table of Contents 6 Configuring a SafeHarbour VPN . . . . . . . . . . . . . . . . . . . . . . . . 132Parameter Descriptions. . . . . . . . . . . .

Strona 285 - DSL Forum settings

60The screen expands as follows:Click the Add button. The Authorized Wireless MAC Address Entry screen appears.Enter the MAC (hardware) address of the

Strona 286 - 123.45.678.910

61ConfigureYour entry will be added to a list of up to 64 authorized addresses as shown:You can continue to Add, Edit, or Delete addresses to the list

Strona 287 - Glossary

62• RADIUS Server Addr/Name: The default RADIUS server name or IP address that you want to use.• RADIUS Server Secret: The RADIUS secret key used by t

Strona 288 - -----B

63ConfigureThe Advanced Network Configuration page appears.You access the RADIUS Server configuration screen from the Advanced Network Configura-tion web

Strona 289 - -----C

64Link: WANWAN IP InterfacesYour IP interfaces are listed. Click on an interface to configure it.IP GatewayEnable Gateway: You can configure the Gateway

Strona 290 - -----D

65ConfigureATM Circuits: You can configure the ATM circuits and the number of Sessions. The IP Interface(s) should be reconfigured after making changes

Strona 291 - -----E

66You can choose UBR (Unspecified Bit Rate), CBR (Constant Bit Rate), or VBR (Variable Bit Rate) from the pull-down menu and set the Peak Cell Rate (PC

Strona 292 - -----F

67Configure☛ Note:The difference between VBR-rt and VBR-nrt is the tolerated Cell Delay Varia-tion range and the provisioned Maximum Burst Size. Clas

Strona 293 - -----H

68Link: AdvancedSelected Advanced options are discussed in the pages that follow. Many are self-explana-tory or are dictated by your service provider.

Strona 294 - -----I

69ConfigureLink: IP Static RoutesA static route identifies a manually configured pathway to a remote network. Unlike dynamic routes, which are acquired

Strona 295 - Internet Key Exchange (IKE)

7 Table of Contents Example 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171Example 2 . . . . . . . . . . .

Strona 296 - -----P

70Link: PinholesPinholes allow you to transparently route selected types of network traffic, such as FTP requests or HTTP (Web) connections, to a speci

Strona 297

71Configurevisible IP address on your network is the Gateway’s WAN IP (supplied by your Service Pro-vider). All traffic intended for that LAN Web serve

Strona 298 - MD5 SHA1

72A diagram of this LAN example is:You can also use the LAN-side address of the Gateway, 192.168.1.x:8100 to access the web and 192.168.1.x:23 to acce

Strona 299 - 1 and 1,000,000 MB

73ConfigurePinhole Configuration Procedure. Use the following steps:1. From the Configure toolbar button -> Advanced link, select the Internal Server

Strona 300 - -----U

745. Click Add. Type your specific data into the Pinhole Entries table of this page. Click Submit. 6. Click on the Add or Edit more Pinholes link. Clic

Strona 301 - -----X

75Configure7. Click on the Add or Edit more Pinholes link. Click the Add button. Add the next Pinhole. Type the specific data for the third Pinhole.☛

Strona 302

7610. Select the Save and Restart link to complete the entire Pinhole creation task and ensure that the parameters are properly saved.☛ NOTE:REMEMBER

Strona 303 - ■ 1.0 amps

77ConfigureConfigure the IPMaps FeatureFAQs for the IPMaps FeatureBefore configuring an example of an IPMaps-enabled network, review these frequently as

Strona 304

78IPMaps Block DiagramThe following diagram shows the IPMaps principle in conjunction with existing Netopia NAT operations:NAT/PAT Table143.137.50.371

Strona 305 - Agency approvals

79ConfigureLink: Default ServerThis feature allows you to:• Direct your Gateway to forward all externally initiated IP traffic (TCP and UDP protocols o

Strona 306 - ☛ Warnings:

Table of Contents 8 CHAPTER 6 Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . 213 Overview . . . . . . . . . . . . . . . . .

Strona 307 - ☛ Important

80Typical Network Diagram. A typical network using the NAT Default Server looks like this:You can also use the LAN-side address of the Gateway, 192.16

Strona 308 - Important Safety Instructions

81ConfigureWith this topology, you configure the embedded administration ports as a first task, fol-lowed by the Pinholes and, finally, the NAT Default S

Strona 309 - 47 CFR Part 68 Information

82The Host Hardware Address field displays. Here you enter the MAC address of the desig-nated IP-Passthrough computer.• If this MAC address is not all

Strona 310 - Electrical Safety Advisory

83ConfigureLink: Differentiated ServicesWhen you click the Differentiated Services link, the Differentiated Services configura-tion screen appears.Neto

Strona 311 - • “Security” on page 315

84You can then define Custom Flows. If your applications do not provide Quality of Service (QoS) control, Custom Flows allows you to define streams for

Strona 312 - Wide Area Network Termination

85ConfigureQoS Setting TOS Bit Value BehaviorOff TOS=000 This custom flow is disabled. You can activate it by selecting one of the two settings below.

Strona 313 - DNS Proxy

86Link: DNSYour Service Provider may maintain a Domain Name server. If you have the information for the DNS servers, enter it on the DNS page. If your

Strona 314

87ConfigureYour Service Provider may, for certain services, want to provide configuration from its DHCP servers to the computers on your LANs. In this

Strona 315

88Link: SNMPWhen you click the SNMP link, the SNMP configuration page appears.The Simple Network Management Protocol (SNMP) lets a network administrato

Strona 316 - Netopia Gateway

89Configure☛ WARNING:SNMP presents you with a security issue. The community facility of SNMP behaves somewhat like a password. The community “public”

Strona 317

9 Table of Contents Static ARP Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 247IGMP Forwarding . . . . . . . . . . .

Strona 318

90The IP Trap Entry screen appears.Enter an IP Trap Entry IP address. This is the destination for SNMP trap messages, the IP address of the host actin

Strona 319

91ConfigureLink: Access ControlBasic Access Controls prevent designated users from accessing certain types of undesir-able Internet content. You can d

Strona 320

92Click the Setup link in Access Control Options. The Manage Users screen appears.Click the here link. The Add New User screen appears. You can create

Strona 321

93ConfigureHere you can specify the time of day, day(s) of the week, and whether this user will be per-mitted or blocked from accessing the Internet a

Strona 322

94After you have added your users and configured their access control settings, you can return to the Access Control pages at any time to add more user

Strona 323

95Configure• Delete User Profile – allows you to delete this user.Web Filter ProfileWhen you click the Web Filter Profile link, the Block/Allow Websites

Strona 324

96Chat Filter ProfileWhen you click the Chat Filter Profile link, the Chat Filtering screen appears.Chat Filtering allows you to choose whether or not t

Strona 325

97Configure• Messaging Services – If a chat service is permitted, choose which one(s): AOL, Yahoo!, MSN, or ICQ. You can choose more than one, but you

Strona 326

98Email Filter ProfileWhen you click the Email Filter Profile link, the Email Filtering screen appears.Email Filtering allows you to choose whether or n

Strona 327 - April 21, 2005

99ConfigureFor example, if you want to limit a child to exchanging email only with other family mem-bers, you can allow the email server(s), but restr

Komentarze do niniejszej Instrukcji

Brak uwag