Benutzeranleitung / Produktwartung Vigor2960F des Produzenten Draytek
Zur Seite of 286
.
Vigor2960 Series User’s Guide ii Vigor2960 Dual-WAN Security Firewall User’s Guide Version: 1.0 Firmware Version: V1.0.5_RC7 (For future update, contact DrayTek) Date: 30/07/2012.
Vigor2960 Series User’s Guide iii Copyright Information Copyright Declarations Copyright 2012 All rights reserved. This pub lication contains information th at is protected by copyright.
Vigor2960 Series User’s Guide iv European Community Declarations Manufacturer: DrayTek Corp. Address: No. 26, Fu Shing Road, HuKou Town ship, HsinChu Industrial Park, Hsin-Chu County, Taiwan 303 Product: Vigor2960 DrayTek Corp.
Vigor2960 Series User’s Guide v T T a a b b l l e e o o f f C C o o n n t t e e n n t t s s Chapter 1: Pref ace ............................................................................................................. 1 1.1 Web Conf iguration Buttons Explanation .
Vigor2960 Series User’s Guide vi 4.5.1 IP Object ............................................................................................................... ..............121 4.5.2 IP Group .......................................................
Vigor2960 Series User’s Guide vii 4.12.5 Time and Date ........................................................................................................... ........ 254 4.12.6 Access Control....................................................
.
Vigor2960 Series User’s Guide 1 C C h h a a p p t t e e r r 1 1 : : P P r r e e f f a a c c e e The Vigor2960 Series integrates a rich suite of functions, including NAT, firewall, VPN, load balance, and bandwidth management cap ability. These products are very suitable for providing multi-integrated solutions to SME markets.
Vigor2960 Series User’s Guide 2 D D e e s s c c r r i i p p t t i i o o n n f f o o r r L L E E D D LED Status Explanation Blinking The router is powered on and running normally.
Vigor2960 Series User’s Guide 3 C C o o n n n n e e c c t t o o r r s s Interface Description Factory Reset Restore the default settings. Usage: Turn on the router (ACT LED is blinking). Press the hole and keep for more than 5 seconds. When you see the ACT LED begins to blink rapidl y than usual, release the button.
Vigor2960 Series User’s Guide 4 1 1 . . 3 3 H H a a r r d d w w a a r r e e I I n n s s t t a a l l l l a a t t i i o o n n 1 1 . . 3 3 . . 1 1 N N e e t t w w o o r r k k C C o o n n n n e e c c t t i i o o n n Before starting to configure the router, you have to connect your devices correctly.
Vigor2960 Series User’s Guide 5 1 1 . . 3 3 . . 2 2 W W a a l l l l - - M M o o u u n n t t e e d d I I n n s s t t a a l l l l a a t t i i o o n n The Vigor2960 Series can be mounted on the wall by using standard brackets shown below. Choose a flat surface (on the wall) which is suitable for placing the router.
Vigor2960 Series User’s Guide 6 This page is left blank..
Vigor2960 Series User’s Guide 7 C C h h a a p p t t e e r r 2 2 : : I I n n i i t t i i a a l l C C o o n n f f i i g g u u r r a a t t i i o o n n For use the router properly, it is necessary for you to change the password of web configuration for security and adjust primary basic settings.
Vigor2960 Series User’s Guide 8 3. Now, the Main Screen will pop up. 4. Go to System Maintenance page and choose Administrator Password . 5. Enter the login password (admin, in default) on the field of Original Password. Type a new one in the field of New Password and retype it on the field of Confirm Password .
Vigor2960 Series User’s Guide 9 2 2 . . 2 2 Q Q u u i i c c k k S S t t a a r r t t W W i i z z a a r r d d Quick Start Wizard is a wizard which is designed for configuring your router accessing Internet with simply steps.
Vigor2960 Series User’s Guide 10 When you finish the above settings, please click Next to go to next page. 2 2 . . 2 2 . . 2 2 S S t t e e p p 2 2 - - C C o o n n f f i i g g u u r r i i n n g g t t.
Vigor2960 Series User’s Guide 11 Gateway IP Address Type a public gateway address for such WAN profile. - click it to remove the IP address if you are not satisfied with it. DNS Server IP Address Add – Click this button to display the IP address field for adding a new IP address.
Vigor2960 Series User’s Guide 12 I I f f D D H H C C P P i i s s s s e e l l e e c c t t e e d d DHCP allows a user to obtain an IP address automatically from a DHCP server on the Internet. If you choose DHCP mode, the DHCP server of your ISP will assign a dynamic IP address for Vigor2960 automatically.
Vigor2960 Series User’s Guide 13 Available parameters are listed as follows: Item Description Username Type in the username provided by ISP in this field. Password Type in the password provided by ISP in this field. Previous Click it to return to previous setting page.
Vigor2960 Series User’s Guide 14 I I f f P P P P T T P P i i s s s s e e l l e e c c t t e e d d This mode lets user get the IP group information by a DSL modem with PPTP service from ISP. Your service provider will give you user name, password, and authentication mode for a PPTP setting.
Vigor2960 Series User’s Guide 15 Server Address Type a remote IP address of PPTP server. Username Type in the username provided by ISP in this field. Password Type in the password provided by ISP in this field. Previous Click it to return to previous setting page.
Vigor2960 Series User’s Guide 16 When you finished the above settings, please click Finish . Later, you can surf the Internet at any time. When the following screen appears, it means you have finished the Quick Start Wizard configuration.
Vigor2960 Series User’s Guide 17 2 2 . . 3 3 R R e e g g i i s s t t e e r r V V i i g g o o r r R R o o u u t t e e r r Please follow the steps below to register the router. 1 Before using such function, please register yo ur router online first. Log into the web configurator of Vigor2960 and click Product Registration .
Vigor2960 Series User’s Guide 18 3 The following page will be displayed after you logging in MyVigor. From this page, please click Add . Note: Below the field of Your Device List , all the Vigor routers that you have registered to MyVigor website will be displayed in sequence.
Vigor2960 Series User’s Guide 19 5 Now, your router information has been added to the database. Click OK to leave this web page and return to My Information web page. 6 Take a look at the page of My Information, the new added Vigor2 960 is listed under Your Device List .
Vigor2960 Series User’s Guide 20 This page is left blank..
Vigor2960 Series User’s Guide 21 C C h h a a p p t t e e r r 3 3 : : A A p p p p l l i i c c a a t t i i o o n n a a n n d d T T u u t t o o r r i i a a l l 3 3 .
Vigor2960 Series User’s Guide 22 3. Open SSL VPN >> SSL Application and click the RDP tab to create a profile named “Win7”. Type IP address, Port number, and Screen Size based on the actual RDP server information, then click Apply to save the settings.
Vigor2960 Series User’s Guide 23 7. A screen like the following figure will appear. Simply click the SSL Applicatio n link. 8. In the following screen, click Connect for connecting to Win7, the RDP server.
Vigor2960 Series User’s Guide 24 9. After that, you can access into Windows 7 via a browser. Note the message below the window. In which, TLS means Transport Layer Security.
Vigor2960 Series User’s Guide 25 Troubleshooting If you have installed Java Runtime Environment edition 6 but still c annot establish the connection, please make sure you have disabled “ Use TLS 1.0 ” in the Java Control Panel as figure shown below.
Vigor2960 Series User’s Guide 26 3 3 . . 2 2 H H o o w w t t o o C C o o n n f f i i g g u u r r e e O O S S P P F F ? ? OSPF (Open Shortest Path First) uses the algorithm of SPF (Shortest Path First) to calculate the route metric. It is suitable for large ne twork and complicated data exchange.
Vigor2960 Series User’s Guide 27 C C o o n n f f i i g g u u r r a a t t i i o o n n f f o o r r V V i i g g o o r r 3 3 9 9 0 0 0 0 A A , , 1. Open LAN >> General Setup to create a LAN (192.168.1.1/24) profile named lan1 with the settings shown below.
Vigor2960 Series User’s Guide 28 4. Open LAN >> OSPF Configuration to enable this profile. Click Ad d to make the LAN Profiles lan2 area setting as 11 and lan1 area as 11. (As shown in the topology diagram .) C C o o n n f f i i g g u u r r a a t t i i o o n n f f o o r r V V i i g g o o r r 3 3 9 9 0 0 0 0 B B , , 1.
Vigor2960 Series User’s Guide 29 3. Open LAN >> Static Route Setup and click the Inter-LAN Route tab to enable this profile. 4. Open LAN >> OSPF Configuration to enable this profile. Click Ad d to make the LAN Profiles lan2 area setting as 11 and lan1 area as 11.
Vigor2960 Series User’s Guide 30 2. Next, continue to create a LAN (192.168.3.3/ 24) profile name d lan2 with the settings shown below. 3. Open LAN >> Static Route Setup and click the Inter-LAN Route tab to enable this profile. 4. Open LAN >> OSPF Configuration to enable this profile.
Vigor2960 Series User’s Guide 31 5. After setting, check the routing information (m arked with red line) which is created by OSPF. R R o o u u t t i i n n g g i i n n f f o o r r m m a a t t i i o o.
Vigor2960 Series User’s Guide 32 3 3 . . 3 3 H H o o w w t t o o C C o o n n f f i i g g u u r r e e L L A A N N t t o o L L A A N N I I P P S S e e c c T T u u n n n n e e l l b b e e t t w w e e e.
Vigor2960 Series User’s Guide 33 C C o o n n f f i i g g u u r r i i n n g g V V i i g g o o r r 2 2 7 7 1 1 0 0 1. In Vigor2710, it is necessary to build two VPN connections (for two WANs) to connect with Vigor2960. Please open the web configurator of Vigor2710 and open VPN and Remote Access >> LAN t o LAN .
Vigor2960 Series User’s Guide 34 3. For the role of Vigor2710 is dialing-out , please skip Dial-In setting. Type the Remote Network IP and Remote Network Mask of Vigor2960 to complete configuration. 4. Please check if the VPN connection is built successfully in both devices respecti vely.
Vigor2960 Series User’s Guide 35 C C h h a a p p t t e e r r 4 4 : : A A d d v v a a n n c c e e d d C C o o n n f f i i g g u u r r a a t t i i o o n n After finished basic configuration of the router, you can access Internet with ease.
Vigor2960 Series User’s Guide 36 via PAP or CHAP with RADIUS authentication system. And your IP address, DNS server, and other related information will usually be assigned by your ISP.
Vigor2960 Series User’s Guide 37 means enabled. Description Display a brief explanation for such profile. VLAN ID Display the VLAN ID of the profile. VLAN Tag If the data transmitted with tag, Enable will be displayed in this field. Otherwise, Disable will be shown instead.
Vigor2960 Series User’s Guide 38 Port Display the physical WAN interface for such profile. Default MAC Address Enable – Click it to enable the default MAC address for such profile. Disable – Click it to type the MAC address manually for such profile.
Vigor2960 Series User’s Guide 39 Different IPv4 and IPv6 protocol types speci fied will bring up diffe rent configuration web page. z If you choose Static as IPv4 protocol type, click the Static tab to open the following page: Available parameters are listed as follows: Item Description IP Address Type the IP address specified for such profile.
Vigor2960 Series User’s Guide 40 – Click the icon to remove the selected entry. IP Alias Type other IP addresses to be bound to this interface. This setting is optional. If you have typed addresses here, you can see and choose it in later web page settings (e.
Vigor2960 Series User’s Guide 41 – click the icon to remove the selected entry. Connection Detection Interval Assign an interval period of time for each detecting. Connection Detection Retry Assign detecting times to ensure the connection of the WAN interface.
Vigor2960 Series User’s Guide 42 Save – Click this button to save the setting. – Click the icon to remove the selected entry. MTU/MRU It means Max Transmit Unit for packet. The default setting is 1500. Connection Detection Mode Select a detecting mode for this WAN interface.
Vigor2960 Series User’s Guide 43 Apply Click it to save the configuration and exit the dialog. Cancel Click it to exit the dialog without saving the configuration.
Vigor2960 Series User’s Guide 44 Connection Detection Host If you choose PING/HTTP as Connection Detection Mode, you have to specify the detection host address in this field. Use the default setting. Add – Click this button to have a field for adding a new IP address.
Vigor2960 Series User’s Guide 45 Cancel Click it to exit the dialog without saving the configuration. z If you choose PPTP as IPv4 protocol type, click the PPTP Tab to open the following page: Avail.
Vigor2960 Series User’s Guide 46 Connection Detection Host If you choose PING/HTTP as Connection Detection Mode, you have to specify the detection host address in this field. Use the default setting. Add – Click this button to have a field for adding a new IP address.
Vigor2960 Series User’s Guide 47 z If you choose Static as IPv6 protocol type, click the StaticV6 tab to open the following page: Available parameters are listed as follows: Item Description IPv6 Address Type the IP address for such protocol. IPv6 Prefix Length Type your IPv6 address prefix length.
Vigor2960 Series User’s Guide 48 z If you choose DHCP-IA_NA as IPv6 protocol type, click the DHCPV6 Tab to open the following page: Available parameters are listed as follows: Item Description DHCP (IA_NA) Gateway Address Type the gateway IP address for IPv6 DHCP IA_NA mode.
Vigor2960 Series User’s Guide 49 4 4 . . 1 1 . . 2 2 D D e e f f a a u u l l t t R R o o u u t t e e This page allows you to assign a WAN profile as the default route. Available parameters are listed as follows: Item Description WAN Profile /Load Balance Pool Name Display the WAN profiles for user to choose as a default route.
Vigor2960 Series User’s Guide 50 4 4 . . 1 1 . . 3 3 L L o o a a d d B B a a l l a a n n c c e e Vigor2960 supports a load balancing function. It can assign traffic with protocol type, IP address for specific host, a subnet of hosts, and port range to be allocated in WAN interface.
Vigor2960 Series User’s Guide 51 rule. Primary Profile Display the primary profile configured in Failover page for such profile. Backup Profile Display the backup profile configured in Failover page for such profile. There are two modes, Load_Balance and Failover , for you to choose as the Pool configuration.
Vigor2960 Series User’s Guide 52 3. Click the Load_Balance Tab. 4. Click Add . A new line for adding new entry will appear. Use the drop down list of Interface to choose one of the WAN profiles. Type the value (e.g., 20) for Weight . 5. Click Apply .
Vigor2960 Series User’s Guide 53 H H o o w w t t o o a a d d d d a a P P o o o o l l p p r r o o f f i i l l e e f f o o r r F F a a i i l l o o v v e e r r Such page allows you to set a backup profile which will be activated when the prim ary profile is invalid by any reason.
Vigor2960 Series User’s Guide 54 3. Click the Failover Tab. In default, the system will apply Primary Profile. If Primary Profile cannot be used any more, the Backup Profile will be used instead. 4. Use the drop down list to choose the one you need.
Vigor2960 Series User’s Guide 55 R R u u l l e e This page will make the packets be transmitte d with user defined profiles with IP address and protocol that is different with default route. Each item will be explained as follows: Item Description Add Add a new rule profile.
Vigor2960 Series User’s Guide 56 Destination Port End Display the destination port ending value for such rule. Load Balance Pool/WAN Profile Display the profile of load balance applied for such rule. H H o o w w t t o o a a d d d d a a n n e e w w r r u u l l e e f f o o r r L L o o a a d d B B a a l l a a n n c c e e 1.
Vigor2960 Series User’s Guide 57 Source IP Address Type a WAN IP address here as the source IP address for such rule. – Click the icon to clear the IP setting. Source Mask Use the drop down list on the right to choose a suitable mask for the source.
Vigor2960 Series User’s Guide 58 4 4 . . 2 2 L L A A N N Local Area Network (LAN) is a group of subnets regulated and ruled b y router . The design of network structure is related to what t ype of public IP addresses coming from your ISP . The most generic function of Vigor router is NAT.
Vigor2960 Series User’s Guide 59 G G e e n n e e r r a a l l S S e e t t u u p p This page allows you to enable the profile, gi ve a brief explanation for such profile, specify the VLAN ID, specify MAC address, and choose protocol type for such profile.
Vigor2960 Series User’s Guide 60 H H o o w w t t o o a a d d d d a a n n e e w w L L A A N N p p r r o o f f i i l l e e 1. Open LAN>>General Setup and click the General Setup tab. 2. Click the Add button to open the following dialog. Different protocol type selected will bring up different conf igur ation web page.
Vigor2960 Series User’s Guide 61 MAC Address If Default MAC address is disabled, please specify a MAC address manually. IPv4 Protocol Display the fixed type (static) for the IPv4 protocol for such profile. Mode Choose NAT or ROUTING as the operation mode for such profile.
Vigor2960 Series User’s Guide 62 DHCPv6 SLA WAN Interface If DHCP-SLA is chosen as IPv6 Protocol, please choose one of the WAN profiles in this field. DHCPv6 SLA ID The ID number set here is used by an individual organization to create its own local addressing hierarchy and to identify subnets.
Vigor2960 Series User’s Guide 63 D D H H C C P P In the Vigor2960 router, there are some IP address settings for the LAN interface. The IP address/subnet mask is for private users or NAT users. The IP address of the default gateway on other local PCs should be set as the Vigor2960 server IP address.
Vigor2960 Series User’s Guide 64 DNS Display the IP address for DNS. Routers In general, this box will be blank. It me ans Vigor2960 will be regarded as the gateway for the user. Lease Time Display the lease time for the DHCP server. Specify Remote Dial-in IP Display the status of remote dial-in function.
Vigor2960 Series User’s Guide 65 Item Description Profile Display the name of the LAN profile. Enable This Profile Check this box to enable this profile. Start IP Set the starting IP address of the IP address pool for DHCP server. End IP Set the ending IP address of the IP address pool for DHCP server.
Vigor2960 Series User’s Guide 66 D D H H C C P P R R e e l l a a y y This page allows users to specify which subne t that DHCP server is located that the relay agent should redirect the DHCP request to. Each item will be explained as follows: Item Description Edit Modify the selected LAN profile.
Vigor2960 Series User’s Guide 67 H H o o w w t t o o e e d d i i t t a a L L A A N N p p r r o o f f i i l l e e f f o o r r D D H H C C P P R R e e l l a a y y 1. Open LAN>>General Setup and click the DHCP Relay tab. 2. Choose one of the LAN profiles by clicking on it and click the Edit button to open the following dialog.
Vigor2960 Series User’s Guide 68 R R A A D D V V D D The router advertisement daemon (radvd) sends Router Advertisement messages, specified by RFC 2461, to a local Ethernet LAN periodi cally and when requested by a node sending a Router Solicitation message.
Vigor2960 Series User’s Guide 69 means enabled. Advertisement Lifetime Display the lifetime value. The lifetime associated with the default router in units of minutes, ranging from 10 ~ 150.
Vigor2960 Series User’s Guide 70 3. When you finish the above settings, please click Appl y to save the configuration and exit the dialog. 4. The LAN profile has been edited. D D H H C C P P 6 6 DHCP6 Server could assign IPv6 address to PC according to the Start/End IPv6 address configuration.
Vigor2960 Series User’s Guide 71 Enable This Profile Display the status of the prof ile. False means disabled; True means enabled. Start IP Display the starting IP address of the IP address pool for DHCP server. End IP Display the ending IP address of the IP address pool for DHCP server.
Vigor2960 Series User’s Guide 72 Available parameters are listed as follows: Item Description Profile Display the name of the LAN profile. Enable This Profile Check this box to enable this profile. Start IP Set the starting IP address of the IP address pool for DHCP server.
Vigor2960 Series User’s Guide 73 4 4 . . 2 2 . . 2 2 I I P P R R o o u u t t i i n n g g To make local device in LAN accessing into external network without passing NAT or let the remote device access into the local device without passing NAT behind the router, please use IP routing function to complete the work.
Vigor2960 Series User’s Guide 74 LAN Profile Display which LAN profile used for the local device. IP Display the private IP address for such profile. Mask Display the subnet mask for such profile. H H o o w w t t o o a a d d d d a a n n e e w w I I P P R R o o u u t t i i n n g g p p r r o o f f i i l l e e 1.
Vigor2960 Series User’s Guide 75 4. Enter all the settings and click Apply . The new profile will be added on the screen. 4 4 . . 2 2 . . 3 3 S S t t a a t t i i c c R R o o u u t t e e When there are several subnets in LAN, a more effective and quicker way for connection is static route rather than other methods.
Vigor2960 Series User’s Guide 76 S S t t a a t t i i c c R R o o u u t t e e Each item will be explained as follows: Item Description Add Add a new static route setting. Edit Modify the selected static route setting. To edit static route setting, simply select the one you want to modify and click the Edit button.
Vigor2960 Series User’s Guide 77 Metric Display the distance to the target. H H o o w w t t o o a a d d d d a a n n e e w w S S t t a a t t i i c c R R o o u u t t e e p p r r o o f f i i l l e e 1. Open LAN>>Static Routing and click the Static Route tab.
Vigor2960 Series User’s Guide 78 Metric Type the distance to the target (usually counted in hops). Apply Click it to save and exit the dialog. Cancel Click it to exit the dialog without saving anything. 5. Enter all the settings and click Apply . The new profile will be added on the screen.
Vigor2960 Series User’s Guide 79 selected rule. Delete Remove the selected static route setting. To delete a static route setting, simply select the one you want to delete and click the Delete button. Refresh Renew current web page. Rename Allow to modify the selected profile name.
Vigor2960 Series User’s Guide 80 Available parameters are listed as follows: Item Description Profile Name Type the name of the static route profile. Enable This Profile Check this box to enable such profile. Destination IP Address Type the IP address for such static route profile.
Vigor2960 Series User’s Guide 81 I I n n t t e e r r - - L L A A N N R R o o u u t t e e To make the users in different LAN communica ting with each other, please check the box to enable Inter-LAN route function.
Vigor2960 Series User’s Guide 82 4 4 . . 2 2 . . 3 3 S S w w i i t t c c h h This page allows you to configure Mirror ing Port, Mirrored Port, enable/disable LAN interface, and configure 802.1Q VLAN ID for different LAN interfaces, and so on. 8 8 0 0 2 2 .
Vigor2960 Series User’s Guide 83 selected rule. Delete Remove the selected VLAN ID setting. To delete a VLAN ID setting, simply select the one you want to delete and click the Delete button. Refresh Renew current web page. VLAN ID Display the VLAN ID number.
Vigor2960 Series User’s Guide 84 Member Determine which LAN interface can be used to access into Internet for such LAN profile with the VLAN ID number. Untag Determine if the packets transm itted to Internet through such LAN profile with the VLAN ID number is tagged or not.
Vigor2960 Series User’s Guide 85 4 4 . . 2 2 . . 4 4 B B i i n n d d I I P P t t o o M M A A C C This function is used to bind the IP and MAC address in LAN to have a strengthen control i n network. When this functi on is enabled, all the assigne d IP and MAC address binding together cannot be changed.
Vigor2960 Series User’s Guide 86 Edit It allows you to edit and modify the selected IP address and MAC address that you create before. Delete You can remove any item listed in IP Bind List . Simply click and select the one, and click Delete . The selected item will be removed from the IP Bind List .
Vigor2960 Series User’s Guide 87 3. Click Add to open the following dialog. Available parameters are listed as follows: Item Description Profile Type the name of the profile. IP Address Type the IP address that will be used for the specified MAC address.
Vigor2960 Series User’s Guide 88 RIP can update the routing table automatically and find a route to send packet. See the following figure as an example: Suppose A supports RIP on WAN1/WAN2/WAN3/WAN4, B supports RIP on WAN1 and WAN2, and C supports RIP on WAN1/WAN2/WAN3/WAN4.
Vigor2960 Series User’s Guide 89 Profile Choose one of the LAN profiles. Apply Click it to save the settings. Cancel Click it to exit the dialog without saving anything.
Vigor2960 Series User’s Guide 90 4. Use the drop down list of LAN Profile to choose the one you need. And specify the value of Area (either 0.0.0.0 ~ 255.255.255.255 or 0 ~ 4294967295) for that profile. If you are not satisfied the settings, simply click to remove the entry, and then re-type the settings.
Vigor2960 Series User’s Guide 91 4 4 . . 3 3 N N A A T T NAT (Network Address Translation) is a method of mapping one or more IP addresses and/or service ports into different specified services.
Vigor2960 Series User’s Guide 92 Item Description Add Add a new port redirect profile. Edit Modify the selected profile. To edit a profile, simply select the one you want to modif y and click the Edit button. The edit window will appear for you to modify the corresponding settings for the selected rule.
Vigor2960 Series User’s Guide 93 3. The following dialog will appear. Available parameters are listed as follows: Item Description Profile Type the name of the profile. Enable This Profile Check the box to enable this profile. Public IP Specify the WAN interface for such profile.
Vigor2960 Series User’s Guide 94 Single_Alias – You have to type one IP address used for IP Alias. All – All the IP address can be treated as IP Alias. Alias Type WAN IP address (es). Private IP Specify the private IP address of the internal host providing the service.
Vigor2960 Series User’s Guide 95 4 4 . . 3 3 . . 2 2 D D M M Z Z H H o o s s t t In computer networks, a DMZ (De-Militarized Zone) is a computer host or small network inserted as a neutral zone between a compa ny’s private network and the outside public network.
Vigor2960 Series User’s Guide 96 Before using such function, there is one profile existed at least. Profile Display the name of the profile. Enable The Profile Display the status of the prof ile. False means disabled; True means enabled. WAN Profile Display the WAN profile that such DMZ host profile will be applied to.
Vigor2960 Series User’s Guide 97 Available parameters are listed as follows: Item Description Profile Type the name of the profile. Enable This Profile Check the box to enable the DMZ Host profile. WAN Profile Choose a WAN profile for such entry. Private IP Type the private IP used for this entry.
Vigor2960 Series User’s Guide 98 4 4 . . 3 3 . . 3 3 A A d d d d r r e e s s s s M M a a p p p p i i n n g g This page is used to map specific pr ivate IP to specific WAN IP alias. If you have "a group of IP Addresses" and want to apply to the router, please use WAN IP alias function to record these IPs first.
Vigor2960 Series User’s Guide 99 means enabled. WAN Profile Display the WAN profile that such address mapping profile will be applied to. Private IP Display the private IP used for this entry. Private IP Subnet Mask Display the subnet mask used for this entry.
Vigor2960 Series User’s Guide 100 Enable This Profile Check the box to enable the Address Mapping profile. WAN Profile Choose a WAN profile for such entry. Private IP Type the private IP used for this entry. Private IP subnet Mask Type the subnet mask used for this entry.
Vigor2960 Series User’s Guide 101 4 4 . . 3 3 . . 4 4 S S I I P P A A L L G G SIP ALG means Session Initiation Protocol, Application Layer Gateway . This page allows you to choose LAN and WAN profiles to make SIP message and RTP packets of voice being transmitting and receiving correctly via NAT by Vigor router.
Vigor2960 Series User’s Guide 102 4 4 . . 4 4 . . 1 1 F F i i l l t t e e r r S S e e t t u u p p Vigor firewall will filter the packets based on the settings, including IP Filter, Application Filter and URL Filter configured under Firewall>>Filter Setup .
Vigor2960 Series User’s Guide 103 Each item will be explained as follows: Item Description IP Filter Rule Group Add Add a new group profile for IP filter. Edit Modify the selected profile. To edit a profile, simply select the one you want to modif y and click the Edit button.
Vigor2960 Series User’s Guide 104 Item Description To edit a profile, simply select the one you want to modif y and click the Edit button. The edit window will appear for you to modify the corresponding settings for the selected rule. Delete Remove the selected profile.
Vigor2960 Series User’s Guide 105 3. The following dialog will appear. Available parameters are listed as follows: Item Description Group Type the name of the IP filter group. Enable This Profile Check the box to enable this profile. Comment Give a brief description for the profile.
Vigor2960 Series User’s Guide 106 7. The following page for configuration will appear. Available parameters are listed as follows:.
Vigor2960 Series User’s Guide 107 Item Description Rule Type the name of the IP filter rule. Enable This Profile Check the box to enable this profile. Time Profile Choose a schedule profile to be applied on such rule. You can click to create another new time object profile.
Vigor2960 Series User’s Guide 108 Apply Click it to save and exit the dialog. Cancel Click it to exit the dialog without saving anything. 8. Enter all the settings and click Apply . 9. A new IP filter rule has been added onto IP Filter Rules of Selected Group table.
Vigor2960 Series User’s Guide 109 A A p p p p l l i i c c a a t t i i o o n n F F i i l l t t e e r r Application Filter can integrate several applica tion objects within one profile for restricting the usage of application.
Vigor2960 Series User’s Guide 110 Item Description IM Block Display the IM object profile selected for such application profile. P2P Block Display the P2P object profile selected for such application profile. Protocol Block Display the protocol object profile selected for such application profile.
Vigor2960 Series User’s Guide 111 Available parameters are listed as follows: Item Description Profile Type the name of the Application filter profile. Enable This Profile Check the box to enable this profile. Time Profile Choose a schedule profile to be applied on such rule.
Vigor2960 Series User’s Guide 112 U U R R L L F F i i l l t t e e r r URL Filter can integrate URL, Keyword, File extension and WCF object profiles within one profile for restricting certain people accessing into Internet. Each item will be explained as follows: Item Description Add Add a new group profile for URL filter.
Vigor2960 Series User’s Guide 113 Item Description Keyword Block Display the keyword object profile selected for each rule which is not allowed to pass through the router. File Extension Block Display the file extension object profile selected for each rule which is not allowed to pass through the router.
Vigor2960 Series User’s Guide 114 Available parameters are listed as follows: Item Description Profile Type the name of the URL filter profile. Enable This Profile Check the box to enable this profile. Time Profile Choose a schedule profile to be applied on such rule.
Vigor2960 Series User’s Guide 115 Item Description Web Category Block Choose one or more WCF object profiles from the drop down list which will not be allowed to pass through the router. You can click to create another new WCF object profile. Apply Click it to save and exit the dialog.
Vigor2960 Series User’s Guide 116 4 4 . . 4 4 . . 2 2 D D o o S S D D e e f f e e n n s s e e The DoS function helps to detect and mitigat es DoS attacks.
Vigor2960 Series User’s Guide 117 Item Description If the amount of UDP packets from the Internet exceeds the user-defined threshold value, the router will be forced to randomly discard the subsequent UDP packets within the user-defined timeout period.
Vigor2960 Series User’s Guide 118 Item Description Apply Click it to save the configuration. Cancel Click it to discard the settings configured in this page. 4 4 . . 4 4 . . 3 3 M M A A C C B B l l o o c c k k MAC Block allows you to set lots of proprie tary MAC Address.
Vigor2960 Series User’s Guide 119 Item Description MAC Address Display the MAC address for such profile. H H o o w w t t o o c c r r e e a a t t e e a a n n e e w w M M A A C C B B l l o o c c k k p p r r o o f f i i l l e e 1. Open Firewall>>MAC Block .
Vigor2960 Series User’s Guide 120 5. A new MAC Block profile has been created. 4 4 . . 5 5 O O b b j j e e c c t t s s S S e e t t t t i i n n g g Vigor2960 allows users to set different filter pr o.
Vigor2960 Series User’s Guide 121 4 4 . . 5 5 . . 1 1 I I P P O O b b j j e e c c t t For IPs in a limited range usually will be app lied in configuring rout er’s settings, we can define them with objects and bind them with groups for using conveniently.
Vigor2960 Series User’s Guide 122 Item Description End IP Address Display the IP address of the ending point for such profile. It will be joint with Start IP Address only when you choose Range as the Address Type . Subnet Mask Display the subnet mask for such profile.
Vigor2960 Series User’s Guide 123 Item Description Address Type Choose the address type (Single / Range /Subnet) for such profile. Start IP Address Type the IP address of the starting point for such profile. End IP Address Type the IP address of the ending point for such profile if you choose Range as Address Type .
Vigor2960 Series User’s Guide 124 4 4 . . 5 5 . . 2 2 I I P P G G r r o o u u p p To manage conveniently, several IP object prof iles can be grouped under a group. Different IP group can contain different IP object profiles. Each item will be explained as follows: Item Description Add Add a new profile.
Vigor2960 Series User’s Guide 125 3. The following dialog will appear. Available parameters are listed as follows: Item Description Group Name Type the name of the object group. The number of the characters allowed to be typed here is 20. Interface Determine the category (any, source or destination) of this IP object.
Vigor2960 Series User’s Guide 126 5. A new IP Group profile has been created. 4 4 . . 5 5 . . 3 3 S S e e r r v v i i c c e e T T y y p p e e O O b b j j e e c c t t TCP and UDP service with specified port range can be saved with different service type object profiles.
Vigor2960 Series User’s Guide 127 Item Description Protocol Display the protocol selected for such profile. Source Port Start Display the starting source port for such profile. Source Port End Display the ending source port for such profile. Destination Port Start Display the starting destination port for such profile.
Vigor2960 Series User’s Guide 128 Item Description Source Port End It is available for TCP/UDP protocol. It can be ignored for ICMP. Type a port number (0 – 65535) as the ending source port. Destination Port Start It is available for TCP/UDP protocol.
Vigor2960 Series User’s Guide 129 Item Description Add Add a new profile. Edit Modify the selected profile. To edit a profile, simply select the one you want to modif y and click the Edit button. The edit window will appear for you to modify the corresponding settings for the selected rule.
Vigor2960 Series User’s Guide 130 Item Description Group Name Type the name of the service type object group. The number of the characters allowed to be typed here is 20. Group Name Type the name of the service type object group. The number of the characters allowed to be typed here is 20.
Vigor2960 Series User’s Guide 131 4 4 . . 5 5 . . 5 5 K K e e y y w w o o r r d d O O b b j j e e c c t t Keyword can be set as a filter rule to be applied in Firewall. Vigor2960 allows users to set keyword profile with several keywords. Even, it allows users to group several keyword profiles within a keyword group.
Vigor2960 Series User’s Guide 132 H H o o w w t t o o c c r r e e a a t t e e a a n n e e w w K K e e y y w w o o r r d d O O b b j j e e c c t t p p r r o o f f i i l l e e 1. Open Objects Setting>> Keyword Object. 2. Simply click the Add button.
Vigor2960 Series User’s Guide 133 Item Description Cancel Click it to exit the dialog without saving the configuration. 4. Enter all the settings and click Apply .
Vigor2960 Series User’s Guide 134 Item Description Profile Number Limit Display the total number (16) of the object profiles to be created. Group Name Display the name of the service type group. Description Display the brief explanation for such profile.
Vigor2960 Series User’s Guide 135 Item Description Cancel Click it to exit the dialog without saving the configuration. 4. Enter all the settings and click Apply .
Vigor2960 Series User’s Guide 136 Item Description Refresh Renew current web page. Profile Number Limit Display the total number (8) of the object profiles to be created. Profile Display the name of the profile. Image Display the selected file extension of image.
Vigor2960 Series User’s Guide 137 Available parameters are listed as follows: Item Description Profile Type the name of the File Extension Object group. The number of the characters allowed to be typed here is 10. Image Several file extensions for Image offered for you to choose.
Vigor2960 Series User’s Guide 138 4 4 . . 5 5 . . 8 8 I I M M O O b b j j e e c c t t People like to use Instant Message to communicati on with friends on line just for fun or just because it is easy and convenient. However, it might reduce the productivity of employees to a company.
Vigor2960 Series User’s Guide 139 H H o o w w t t o o c c r r e e a a t t e e a a n n e e w w I I M M O O b b j j e e c c t t P P r r o o f f i i l l e e 1. Open Objects Setting>>IM Object. 2. Simply click the Add button. 3. The following dialog will appear.
Vigor2960 Series User’s Guide 140 Item Description WebIM It lists a package of IM application based on web page. You may check the box to include all of them. Apply Click it to save the configuration. Cancel Click it to exit the dialog without saving the configuration.
Vigor2960 Series User’s Guide 141 4 4 . . 5 5 . . 9 9 P P 2 2 P P O O b b j j e e c c t t Vigor2960 can block P2P application for users, especially for the ones who alway s upload or download improper files to Internet. P2P object setting lists all of the point to poi nt applic ation for you to choose to b lock.
Vigor2960 Series User’s Guide 142 H H o o w w t t o o c c r r e e a a t t e e a a n n e e w w P P 2 2 P P O O b b j j e e c c t t P P r r o o f f i i l l e e 1. Open Objects Setting>>P2P Object. 2. Simply click the Add button. 3. The following dialog will appear.
Vigor2960 Series User’s Guide 143 5. A new P2P Object profile has been created. 4 4 . . 5 5 . . 1 1 0 0 P P r r o o t t o o c c o o l l O O b b j j e e c c t t Network services, e.g., DNS, FTP, HTTP, POP3, for LAN users can be blocked by Vigor2960. Common services will be listed in th is function and can be selected to be blocked by the router.
Vigor2960 Series User’s Guide 144 Item Description Profile Number Limit Display the total number (32) of the object profiles to be created. Profile Display the name of the IM object profile. Member Display the protocol application specified in such profile.
Vigor2960 Series User’s Guide 145 Member Several protocols offered for you to choose. Check the one (s) you want to add for such profile. Apply Click it to save the configuration. Cancel Click it to exit the dialog without saving the configuration. 4.
Vigor2960 Series User’s Guide 146 Note: Web Content Filter (WCF) is not a built-in service of Vigor router but a service powered by Commtouch . If you want to use such service (trial or formal edition), you have to perform the procedure of activation first.
Vigor2960 Series User’s Guide 147 Item Description Add Add a new profile. Edit Modify the selected profile. To edit a profile, simply select the one you want to modif y and click the Edit button. The edit window will appear for you to modify the corresponding settings for the selected rule.
Vigor2960 Series User’s Guide 148 Available parameters are listed as follows: Item Description Profile Type the name of the web category object profile. The number of the characters allowed to be typed here is 10. Child Protection The web pages which are not suitable for children will be classified into different categories.
Vigor2960 Series User’s Guide 149 5. A new Web Category Object profile has been created. C C o o n n t t e e n n t t F F i i l l t t e e r r L L i i c c e e n n s s e e Move your mouse to the link of Activate URL and click it. The system will guide you to access into MyVigor website.
Vigor2960 Series User’s Guide 150 4 4 . . 5 5 . . 1 1 2 2 T T i i m m e e O O b b j j e e c c t t You restrict Internet access to certain hours so that users can connect to the Internet only during certain hours, say, business hours. The sche dule is also applicable to other functions, e.
Vigor2960 Series User’s Guide 151 Item Description Weekdays Display the frequency of such time object profile. H H o o w w t t o o c c r r e e a a t t e e a a n n e e w w T T i i m m e e O O b b j j e e c c t t P P r r o o f f i i l l e e 1. Open Objects Setting>> Time Object.
Vigor2960 Series User’s Guide 152 Weekdays Specify which days in one week should perform the schedule. Apply Click it to save the configuration. Cancel Click it to exit the dialog without saving the configuration. 4. Enter all the settings and click Apply .
Vigor2960 Series User’s Guide 153 Each item will be explained as follows: Item Description Add Add a new profile. Edit Modify the selected profile. To edit a profile, simply select the one you want to modif y and click the Edit button. The edit window will appear for you to modify the corresponding settings for the selected rule.
Vigor2960 Series User’s Guide 154 Available parameters are listed as follows: Item Description Profile Type the name of the time group. The number of the characters allowed to be typed here is 10. Description Make a brief explanation for such profile if the group name is set not clearly.
Vigor2960 Series User’s Guide 155 Available parameters will be explained as follows: Item Description Mode There are two modes offered here for you to choose.
Vigor2960 Series User’s Guide 156 Item Description Cancel Click it to discard the settings configured in this page. U U s s e e r r - - B B a a s s e e d d F F i i r r e e w w a a l l l l S S t t a .
Vigor2960 Series User’s Guide 157 Item Description IP Display the IP address of the user who logs into the WUI of Vigor2960. Allow Time Display the total network connection time allowed for the log-in user. Start Time Display the starting time of the network connection.
Vigor2960 Series User’s Guide 158 4 4 . . 6 6 . . 2 2 U U s s e e r r P P r r o o f f i i l l e e This function allows to configure all accounts (user profiles) in Vigor2960, inclu ding PPTP/L2TP, System user, and so on. Each item will be explained as follows: Item Description Add Add a new profile.
Vigor2960 Series User’s Guide 159 Item Description DHCP from Display the LAN profile that DHCP server used for assigning IP address(es). Static IP Address Display the IP address for such user profile which accesses Internet with PPTP/L2TP connection.
Vigor2960 Series User’s Guide 160 Available parameters are listed as follows: Item Description Username Type a name for such user profile (e.g., LAN_User_Group_1, WLAN_User_Group_A, WLAN_User_Group_B, etc). When a user tries to access Internet through this router, an authentication step must be performed first.
Vigor2960 Series User’s Guide 161 Password Type a password for such profile (e.g., lug123, wug123,wug456, etc). When a user tries to access Internet through this router, an authentication step must be performed first. The user has to type th e password specified here to pass the authentication.
Vigor2960 Series User’s Guide 162 SSL Application (RDP) It is available when System User is set with false . Choose one of the SSL Application profiles (RDP) for applying into this profile. Apply Click it to save the configuration. Cancel Click it to exit the dialog without saving the configuration.
Vigor2960 Series User’s Guide 163 4 4 . . 6 6 . . 3 3 U U s s e e r r G G r r o o u u p p The User Group can consist of several user profiles, which help the ad ministrator to manage a large number of users conveniently. Each item will be explained as follows: Item Description Add Add a new profile.
Vigor2960 Series User’s Guide 164 H H o o w w t t o o c c r r e e a a t t e e a a n n e e w w U U s s e e r r G G r r o o u u p p P P r r o o f f i i l l e e 1. Open User Management>>User Group. 2. Simply click the Add button. 3. The following dialog will appear.
Vigor2960 Series User’s Guide 165 4 4 . . 6 6 . . 4 4 R R A A D D I I U U S S Remote Authentication Dial-In User Servi ce (RADIUS) is a security authentication client/server protocol that supports authenti cation, authorization and accounting, which is widely used by Internet service providers.
Vigor2960 Series User’s Guide 166 4 4 . . 6 6 . . 5 5 L L D D A A P P / / A A c c t t i i v v e e D D i i r r e e c c t t o o r r y y Lightweight Directory Access Protocol (LDAP) is a communication protocol for using in TCP/IP network.
Vigor2960 Series User’s Guide 167 4 4 . . 7 7 A A p p p p l l i i c c a a t t i i o o n n Below shows the menu items for Applications. 4 4 . . 7 7 . . 1 1 D D y y n n a a m m i i c c D D N N S S The ISP often provides you with a dynamic IP address when you c onnect to the Internet via your ISP.
Vigor2960 Series User’s Guide 168 S S t t a a t t u u s s This page displays all the available DDNS profiles. Each item will be explained as follows: Item Description Refresh Renew current web page. Auto Refresh Specify the interval of refresh time to obtain the latest status.
Vigor2960 Series User’s Guide 169 S S e e t t t t i i n n g g This page allows you to configure DDNS server for your request. Each item will be explained as follows: Item Description Edit Modify the selected profile. To edit a profile, simply select the one you want to modif y and click the Edit button.
Vigor2960 Series User’s Guide 170 H H o o w w t t o o e e d d i i t t a a n n e e x x i i s s t t i i n n g g D D D D N N S S P P r r o o f f i i l l e e There are 10 sets of DDNS server offered for you to modify and configure. Ple ase choose any one of them and click Edit to open the following page for modification.
Vigor2960 Series User’s Guide 171 Service Type Select a service type (Dynamic, Custom or Static). If you choose Custom, you can modify the domain that is chosen in the Domain Name field. Domain Name Type in one domain name that you appli ed previously.
Vigor2960 Series User’s Guide 172 4 4 . . 7 7 . . 2 2 G G V V R R P P This function can define the method for the changing the VLAN information among devices. With supporting GVRP, the device can recei ve the VLAN information coming from other devices.
Vigor2960 Series User’s Guide 173 4 4 . . 7 7 . . 3 3 I I G G M M P P P P r r o o x x y y IGMP is the abbreviation of Internet Group Management Protocol . It is a communication protocol which is mainly used for managing the membership of Internet Protocol m ulticast groups.
Vigor2960 Series User’s Guide 174 Available parameters are listed as follows: Item Description Enable This Profile Check this box to enable UPnP function. Download Enter the maximum sustained WAN download speed in kilobits/second. Such informa tion can be requested by UPnP clients.
Vigor2960 Series User’s Guide 175 The UPnP facility on the router enables UPnP aware applications such as MSN Messenger to discover what are behind a NA T router . The application will also learn the external IP address and configure port mappings on the router .
Vigor2960 Series User’s Guide 176 The UPnP function dynamically adds port ma ppings on behalf of some UPnP-aware applications. When the applications terminate abnormally, these mappings may not be removed. 4 4 . . 7 7 . . 5 5 W W a a k k e e o o n n L L A A N N A PC client on LAN can be woken up by the router it connects.
Vigor2960 Series User’s Guide 177 4 4 . . 8 8 V V P P N N a a n n d d R R e e m m o o t t e e A A c c c c e e s s s s A Virtual Private Network (VPN) is the extension of a private network that encompasses links across shared or public networks like th e Internet.
Vigor2960 Series User’s Guide 178 H H o o w w t t o o c c r r e e a a t t e e L L A A N N - - t t o o - - L L A A N N p p r r o o f f i i l l e e f f o o r r V V P P N N c c l l i i e e n n t t ( ( d d i i a a l l - - o o u u t t ) ) 1. Open VPN and Remote Access >> VPN Client Wizard.
Vigor2960 Series User’s Guide 179 3. Specify the type. Click Create New VPN Profile and type the name of the profile. Then, click Next . 4. If you choose PPTP as the Type, you will get the following screen: Available parameters are listed as follows: Item Description Profile Display the name of the VPN profile.
Vigor2960 Series User’s Guide 180 Enable This Profile Check this box to enable such profile. Always On Click Enable to make router always keeping connection. Server IP Address Type the IP address of PPTP server. PPTP User Name Type a user name for authentication in PPTP connection.
Vigor2960 Series User’s Guide 181 data will be authenticated but not be encrypted. WAN Profile Choose a wan profile to be used by such profile. Local IP/Subnet Mask Type the IP address and subnet mask of local host. Local Next Hop Specify the gateway for WAN interface.
Vigor2960 Series User’s Guide 182 4 4 . . 8 8 . . 2 2 V V P P N N S S e e r r v v e e r r W W i i z z a a r r d d Such wizard is used to configure VPN settings for VPN server. Such wizard will guide to set the LAN-to-LAN profile for VPN dial in connec tion (from client to server) step by step.
Vigor2960 Series User’s Guide 183 Available parameters are listed as follows: Item Description Type Specify which protocol ( PPTP or IPSec ) will be used for such VPN profile. VPN Settings Via Select From Current Settings - Current VPN LAN to LAN profiles will be listed below such setting.
Vigor2960 Series User’s Guide 184 Certificate Choose a local certificate from the drop down list. Presared Key Type a pre-shared key for authentication if PSK is selected as Auth Type. Security Protocol Choose ESP to specify the IPSec protocol for the Encapsulating Security Payload protocol.
Vigor2960 Series User’s Guide 185 Available parameters are listed as follows: Item Description Enable This Profile Check this box to enable such profile. Authentication Protocol The router will authenticate the dial-in user with the protocol selected here.
Vigor2960 Series User’s Guide 186 3. Fill in the required information on this page and click Next to go t o next page. Available parameters are listed as follows: Item Description Profile Display the name of the profile. Enable This Profile Check this box to enable such profile.
Vigor2960 Series User’s Guide 187 5. Fill in the required information on this page and click Finish . Later, the new added VPN server profile will be displayed on the screen.
Vigor2960 Series User’s Guide 188 4 4 . . 8 8 . . 3 3 R R e e m m o o t t e e A A c c c c e e s s s s C C o o n n t t r r o o l l Enable the necessary VPN service as you need. If you intend to run a VPN server inside your LAN, you should disable the VPN service (e.
Vigor2960 Series User’s Guide 189 4 4 . . 8 8 . . 4 4 P P P P P P G G e e n n e e r r a a l l S S e e t t u u p p Remote users can connect to the site, host, server and etc. via VPN connection built between the router and the users by authentication procedure.
Vigor2960 Series User’s Guide 190 LAN Profile Choose a LAN profile for PPTP Server if RADIUS is selected as user authentication type. Apply Click it to save the configuration. Cancel Click it to discard the settings configured in this page. L L 2 2 T T P P This page display current status fo r VPN tunnel built with L2TP protocol.
Vigor2960 Series User’s Guide 191 LAN Profile Choose a LAN profile for L2TP Server if RADIUS is selected as user authentication type. Apply Click it to save the configuration. Cancel Click it to discard the settings configured in this page. 4 4 . . 8 8 .
Vigor2960 Series User’s Guide 192 4 4 . . 8 8 . . 6 6 V V P P N N P P r r o o f f i i l l e e s s Here you can manage LAN-to-LAN connections by maintaining a table of connection profiles.
Vigor2960 Series User’s Guide 193 Local IP / Subnet Mask Display the LAN IP address with subnet mask of this profile. Remote IP / Subnet Mask Display the WAN IP address with subnet mask of this profile. More Remote Subnet Display other LAN IP addresses with subnet mask which can be used of this profile.
Vigor2960 Series User’s Guide 194 Available parameters are listed as follows: Item Description Profile Type the name of the profile. Enable This Profile Check this box to enable this profile. Type There are three types offered here for you to choose.
Vigor2960 Series User’s Guide 195 4. After filling the required information for Basic , click the Advanced tab to open the following page. Available parameters are listed as follows: Item Description Aggressive Mode Enable – Click it to enable Aggressive Mode.
Vigor2960 Series User’s Guide 196 periodically when a tunnel is idle. Use the value 0 to disable this function. The recommended value is 30 seconds if enabled. DPD Timeout The timeout timer. The peer will be declared dead once no acknowledge message is received after timeout value.
Vigor2960 Series User’s Guide 197 GRE Out Key Type the hexadecimal number as GRE Out Key. This value is used for the remote client to authenticate the source of the packet. The length is 4 bytes. Apply Click it to save the configuration. Cancel Click it to exit the page without saving the configuration.
Vigor2960 Series User’s Guide 198 applied. acceptabove - When the VPN tunnel is established, only the selected proposal will be accepted and applied by this device. Apply Click it to save the configuration. Cancel Click it to exit the page without saving configuration.
Vigor2960 Series User’s Guide 199 3. The following dialog will appear. Available parameters are listed as follows: Item Description Profile Type the name of the profile. Enable This Profile Check this box to enable this profile. Type There are three types offered here for you to choose.
Vigor2960 Series User’s Guide 200 5. A new PPTP Dial-Out VPN profile has been created. H H o o w w t t o o c c r r e e a a t t e e a a P P P P T T P P D D i i a a l l - - I I n n V V P P N N p p r r o o f f i i l l e e Below will guide you to create a PPTP dial-in profile for VPN connection: 1.
Vigor2960 Series User’s Guide 201 Available parameters are listed as follows: Item Description Profile Display the name of the profile. Enable This Profile Check this box to enable this profile. Type There are three types offered here for you to choose.
Vigor2960 Series User’s Guide 202 Profile previously. You can click Set PPTP Dial-In For User Profile in this page to configure a new one for choosing. Local IP/Subnet Mask Type the IP address and subnet mask of local host. Remote IP / Subnet Mask Type the LAN IP address and LAN subnet mask for the remote host.
Vigor2960 Series User’s Guide 203 S S e e t t P P P P T T P P D D i i a a l l - - I I n n F F o o r r U U s s e e r r P P r r o o f f i i l l e e To set PPTP Dial-In connection, you have to create P.
Vigor2960 Series User’s Guide 204 4 4 . . 8 8 . . 7 7 V V P P N N T T r r u u n n k k M M a a n n a a g g e e m m e e n n t t VPN Load Balance Mechanism can set multiple VPN tunnels for using as traffic load balance tunnel. It can assist users to do eff ective load sharing for multiple VPN tunnels according to real line bandwidth.
Vigor2960 Series User’s Guide 205 L L o o a a d d B B a a l l a a n n c c e e R R u u l l e e To build VPN load balance connection with ot her router, you can define the load balance rule in this page. Each item will be explained as follows: Item Description Add Add a new profile.
Vigor2960 Series User’s Guide 206 Destination IP Address Display the destination IP addr ess specified for this entry. Destination Mask Display the subnet mask address specified for the destination IP of this entry. Destination Port Start Display the start point specified in the Dest Port Range for this entry.
Vigor2960 Series User’s Guide 207 Available parameters are listed as follows: Item Description Profile Type the name of the profile. Enable This Profile Check this box to enable such profile. Protocol Type the protocol configured by such profile. Source IP Address Type the source IP address specified for this profile.
Vigor2960 Series User’s Guide 208 L L o o a a d d B B a a l l a a n n c c e e P P o o o o l l This page allows the user to integrate several WAN profiles as a pool profile specified with the function of load balance or failover. Each item will be explained as follows: Item Description Add Add a new profile.
Vigor2960 Series User’s Guide 209 3. The following dialog will appear. Type the name of the profile (e.g., LB_Pool_1, within 10 characters including digit, letter, and underline) under the Mode tab. 4. Click the Load Balance tab to open the following dialog.
Vigor2960 Series User’s Guide 210 5. Enter all the settings and click Apply . 6. A new profile has been created. Refer to Chapter 3, How to Configure VPN Load Balance between Vigor2960 and Other Router for getting more detailed information about Load Balance application.
Vigor2960 Series User’s Guide 211 Type Display the connection type (PPTP or IPSec) for such VPN profile. Remote IP Display the remote IP configure by VPN profile. Virtual Network Display the virtual network established by such VPN profile. Up Time Display the connection time of this VPN tunnel.
Vigor2960 Series User’s Guide 212 4 4 . . 9 9 . . 1 1 L L o o c c a a l l C C e e r r t t i i f f i i c c a a t t e e This page allows users to generate certifi cate based on different work requests. Local certificate can be signed by itself or signed by a root CA (e.
Vigor2960 Series User’s Guide 213 H H o o w w t t o o b b u u i i l l d d a a l l o o c c a a l l c c e e r r t t i i f f i i c c a a t t e e 1. Open Certificate Management>> Local Certificate. 2. Simply click the Generate button. 3. The following dialog will appear.
Vigor2960 Series User’s Guide 214 Email : Certificated by email address. None : Do not enter an ID value. ID Value The ID value is determined by the ID Type selected for such certificate. For example, if you choose Domain_Name as the ID Type, please type the domain name in this field.
Vigor2960 Series User’s Guide 215 H H o o w w t t o o d d o o w w n n l l o o a a d d a a l l o o c c a a l l c c e e r r t t i i f f i i c c a a t t e e i i n n t t o o s s p p e e c c i i f f i i e e d d l l o o c c a a t t i i o o n n Vigor router allows you to generate a certifi cate request and submit it the CA server.
Vigor2960 Series User’s Guide 216 4 4 . . 9 9 . . 2 2 T T r r u u s s t t e e d d C C A A C C e e r r t t i i f f i i c c a a t t e e This page allows you to build a RootCA certificate for Vigor2960.
Vigor2960 Series User’s Guide 217 4 4 . . 1 1 0 0 S S S S L L V V P P N N An SSL VPN (Secure Sockets Layer virtual private network) is a form of VPN that can be used with a standard Web browser. There are two benefits that SSL VPN provides: ¾ It is not necessary for users to preinstall VPN client software for executing SSL VPN connection.
Vigor2960 Series User’s Guide 218 Delete Remove the selected profile. To delete a profile, simply select the one you want to delete and click the Delete button. Refresh Renew current web page. Profile Display the name of the profile that you create.
Vigor2960 Series User’s Guide 219 4. Enter all the settings and click Apply . 5. A new SSL Web Proxy profile has been created. 4 4 . . 1 1 0 0 . . 2 2 S S S S L L A A p p p p l l i i c c a a t t i i.
Vigor2960 Series User’s Guide 220 V V N N C C VNC stands for Virtual Network Computing. It allows you to access and control a remote PC through VNC protocol. Each item will be explained as follows: Item Description Add Add a new profile. Edit Modify the selected profile.
Vigor2960 Series User’s Guide 221 2. Simply click the Add button. 3. The following dialog will appear. Available parameters are listed as follows: Item Description Profile Type the name of the profile that you create. IP Address Type the IP address for this protocol.
Vigor2960 Series User’s Guide 222 5. A new SSL Application profile has been created. R R D D P P RDP stands for Remote Desktop Protocol. It allows you to access and control a remote PC through RDP protocol. Each item will be explained as follows: Item Description Add Add a new profile.
Vigor2960 Series User’s Guide 223 Refresh Renew current web page. Profile Display the name of the profile that you create. IP Address Display the IP address for this protocol. Port Display the port used for this protocol. Screen Size Display the screen size for such application.
Vigor2960 Series User’s Guide 224 5. A new SSL Application profile has been created. 4 4 . . 1 1 0 0 . . 3 3 O O n n l l i i n n e e U U s s e e r r S S t t a a t t u u s s If you have finished the configuration of SSL Web Proxy (server), users can find out corresponding settings when they access in to Draytek SSL VPN portal interface.
Vigor2960 Series User’s Guide 225 4 4 . . 1 1 1 1 B B a a n n d d w w i i d d t t h h M M a a n n a a g g e e m m e e n n t t Below shows the menu items for Bandwidth Management.
Vigor2960 Series User’s Guide 226 T T o o t t a a l l R R a a t t e e C C o o n n t t r r o o l l This page can set the total rate of incoming data for the QoS policer. Available parameters are listed as follows: Item Description Mode Click Enable to enable such function.
Vigor2960 Series User’s Guide 227 C C l l a a s s s s R R a a t t e e C C o o n n t t r r o o l l This page allows you to edit the incoming class rate for the QoS policer. Each item will be explained as follows: Item Description Edit Modify the selected policy.
Vigor2960 Series User’s Guide 228 H H o o w w t t o o e e d d i i t t t t h h e e i i n n c c o o m m i i n n g g c c l l a a s s s s r r a a t t e e f f o o r r t t h h e e Q Q o o S S p p o o l l i i c c e e r r 1. Open Bandwidth Management>> Incoming Class and click the Class Rate Control tab .
Vigor2960 Series User’s Guide 229 5. The QoS Policer profile has been modified. 4 4 . . 1 1 1 1 . . 2 2 I I n n c c o o m m i i n n g g F F i i l l t t e e r r There are 30 filter rules for incoming data that can be configured in such page. Each item will be explained as follows: Item Description Edit Modify the selected policy.
Vigor2960 Series User’s Guide 230 H H o o w w t t o o e e d d i i t t t t h h e e i i n n c c o o m m i i n n g g f f i i l l t t e e r r f f o o r r t t h h e e Q Q o o S S p p o o l l i i c c e e r r 1. Open Bandwidth Management>> Incoming Filter.
Vigor2960 Series User’s Guide 231 Available parameters are listed as follows: Item Description Filter Rule Display the profile name of the filter rule. Policer Choose the QoS Policer profile to apply to such filter rule. Drop Choose Enable to discard the packets which satisfy the condition of the filter rule.
Vigor2960 Series User’s Guide 232 Cancel Click it to exit the dialog without saving the configuration. 4. Enter all the settings and click Apply . 5.
Vigor2960 Series User’s Guide 233 T T o o t t a a l l R R a a t t e e C C o o n n t t r r o o l l This page can set the total rate of outgoing data for the QoS policer. Available parameters are listed as follows: Item Description Status Click Enable to enable such function.
Vigor2960 Series User’s Guide 234 C C l l a a s s s s R R a a t t e e C C o o n n t t r r o o l l This page allows you to edit the out going class rate for different QoS policer. Each item will be explained as follows: Item Description Edit Modify the selected policy.
Vigor2960 Series User’s Guide 235 H H o o w w t t o o e e d d i i t t t t h h e e o o u u t t g g o o i i n n g g c c l l a a s s s s r r a a t t e e f f o o r r t t h h e e Q Q o o S S p p o o l l i i c c e e r r 1. Open Bandwidth Management>> Outgoing Class and click the Class Rate Control tab .
Vigor2960 Series User’s Guide 236 5. The outgoing class rate for QoS Policer has been modified. O O u u t t g g o o i i n n g g Q Q u u e e u u e e 1 1 - - 5 5 W W e e i i g g h h t t There are several available outgoing queues, four shapers at varying levels, and five data queues with weights.
Vigor2960 Series User’s Guide 237 Weight Display the weight of the QoS queue. H H o o w w t t o o e e d d i i t t t t h h e e o o u u t t g g o o i i n n g g q q u u e e u u e e 1 1 - - 5 5 w w e e .
Vigor2960 Series User’s Guide 238 4 4 . . 1 1 1 1 . . 4 4 O O u u t t g g o o i i n n g g F F i i l l t t e e r r There are 30 filter rules for outgoing data that can be configured in such page. Each item will be explained as follows: Item Description Add Add a new filter profile.
Vigor2960 Series User’s Guide 239 Source IP Display the source IP address for the filter. Destination IP Display the destination IP address for the filter. Service Type Display the protocol used for such filter. Queue Number Display the queue number that such filter is categorized.
Vigor2960 Series User’s Guide 240 Service Type Choose one of the service types from the drop down li st. If you want to create a new service type, simply click to open the following dialog. Profile – type a new name for such service type. Protocol –There are two options: TCP , UDP and TCP/UDP .
Vigor2960 Series User’s Guide 241 4 4 . . 1 1 1 1 . . 5 5 S S e e s s s s i i o o n n s s L L i i m m i i t t A PC with private IP address can access to the Internet via NAT router. The router will generate the records of NAT sessions for su ch connection.
Vigor2960 Series User’s Guide 242 Administration Message session limit is reached. Apply Click it to save the configuration. Cancel Click it to discard the settings configured in this page.
Vigor2960 Series User’s Guide 243 Cancel Click it to exit the dialog without saving the configuration. 4. Enter all the settings and click Apply . 5.
Vigor2960 Series User’s Guide 244 and click the Delete button. Refresh Renew current web page. Rename Allow to modify the selected profile name. Profile Display the name of the bandwidth limitation profile. Enable This Profile Display the status of such profile.
Vigor2960 Series User’s Guide 245 Available parameters are listed as follows: Item Description Profile Type the name of the profile. Start IP Define the start IP address for limit bandwidth. End IP Define the end IP address for limit bandwidth. TX Limit Define the limitation for the speed of the upstream.
Vigor2960 Series User’s Guide 246 4 4 . . 1 1 2 2 S S y y s s t t e e m m M M a a i i n n t t e e n n a a n n c c e e For the system setup, there are several items that you have to know the way of c.
Vigor2960 Series User’s Guide 247 /Password Configuration Server user’s manual for detailed inform ation. WAN Profile Choose one of the WAN profiles which will be recognized by VigorACS. Port Type the port number for Vigor2960 which will be recognized by VigorACS.
Vigor2960 Series User’s Guide 248 Apply Click this button to save the configuration and exit the web page. 4 4 . . 1 1 2 2 . . 3 3 C C o o n n f f i i g g u u r r a a t t i i o o n n B B a a c c k k u u p p Most of the settings can be saved locally as a configuration file, and can be applied to another router.
Vigor2960 Series User’s Guide 249 R R e e s s t t o o r r e e Each item will be explained as follows: Item Description Decrypt Config Check this box to decrypt an encrypted configuration f ile. You can specify a password for decrypting the file for restoring it for use next time.
Vigor2960 Series User’s Guide 250 4 4 . . 1 1 2 2 . . 4 4 S S y y s s l l o o g g / / M M a a i i l l A A l l e e r r t t SysLog function is provided for users to monitor router. There is no bother to directly get into the Web Configurator of the router or borrow de bug equipments.
Vigor2960 Series User’s Guide 251 Item Description Status Choose one of the selections to determine current status for Syslog access. If you choose Local as Status, you don’t need to type any server IP and port. Just give a name for the router. Server IP Type the IP address of the Syslog server.
Vigor2960 Series User’s Guide 252 S S y y s s L L o o g g F F i i l l e e This page displays all the operation logs for the router. M M a a i i l l A A l l e e r r t t Available parameters are liste.
Vigor2960 Series User’s Guide 253 Enable This Profile Check the box to enable such profile. Mail From Type a mail address for the mail sender. Mail To Assign a mail address for the mail receiver. SMTP Port Type the port number for SMTP server. SMTP Server Type the IP address for SMTP server.
Vigor2960 Series User’s Guide 254 4 4 . . 1 1 2 2 . . 5 5 T T i i m m e e a a n n d d D D a a t t e e This page allows you to specify where the time of the router should be inquired from. As an NTP (Network Time Protocol) client, the router gets standard time from the time server.
Vigor2960 Series User’s Guide 255 4 4 . . 1 1 2 2 . . 6 6 A A c c c c e e s s s s C C o o n n t t r r o o l l This page allows you to open or close the web configurator ofVigor2960 by using Telnet, .
Vigor2960 Series User’s Guide 256 The former box indicates an IP address allowed to login to the router, and the later box indicates a subnet mask allowed to login to the router. Allow Ping from WAN Click Enable to allow system administrator to ping the router from WAN interface.
Vigor2960 Series User’s Guide 257 4 4 . . 1 1 2 2 . . 8 8 R R e e b b o o o o t t S S y y s s t t e e m m The Vigor router system can be restarted from a Web browser. You have to reboot the router to invoke the configured settings that you m ade before.
Vigor2960 Series User’s Guide 258 After choosing the configuration files, click Reboot . Reboot Click this button to execute the rebooting job. 4 4 . . 1 1 2 2 . . 9 9 F F i i r r m m w w a a r r e e U U p p g g r r a a d d e e The following web page will guide you to up grade firmware by using such page.
Vigor2960 Series User’s Guide 259 4 4 . . 1 1 3 3 D D i i a a g g n n o o s s t t i i c c s s In some cases, a user may need to know some information about the router, such as static or dynamic databases, or other routing informa tion.
Vigor2960 Series User’s Guide 260 Each item will be explained as follows: Item Description Refresh Renew the web page. Destination Display the destination IP address for various routings. Gateway Display the default gateway. Genmask Display the subnet mask for various routings.
Vigor2960 Series User’s Guide 261 I I P P v v 6 6 R R o o u u t t i i n n g g T T a a b b l l e e Display the information for each route with IPv6 protocol. Each item will be explained as follows: Item Description Refresh Renew the web page. Destination Display the destination IP address for various routings.
Vigor2960 Series User’s Guide 262 LAN/WAN profile). 4 4 . . 1 1 3 3 . . 2 2 A A R R P P C C a a c c h h e e T T a a b b l l e e Click Diagnostics and click ARP Cache Table to view the content of the ARP (Address Resolution Protocol) cache held in the rout er.
Vigor2960 Series User’s Guide 263 Each item will be explained as follows: Item Description Refresh Renew the web page. Clear All Remove all of the information from this page. IP Address Display the IP address for different ARP cache. HW type Display the hardware type of the address from RFC 826.
Vigor2960 Series User’s Guide 264 Item Description MAC Address Display the MAC address of the neighbor. Status Display the status for such neighbor. INCOMPLETE - Address resolution is in progress and the link-layer address of the neighbor has not yet been determined.
Vigor2960 Series User’s Guide 265 4 4 . . 1 1 3 3 . . 3 3 D D H H C C P P T T a a b b l l e e The facility provides information on IP address as signments. This information is helpful in diagnosing network problems, such as IP address conflicts, etc.
Vigor2960 Series User’s Guide 266 4 4 . . 1 1 3 3 . . 4 4 N N A A T T S S e e s s s s i i o o n n T T a a b b l l e e This table can display about 30000 sessions with 20 pages. Each item will be explained as follows: Item Description Refresh Renew the web page.
Vigor2960 Series User’s Guide 267 4 4 . . 1 1 3 3 . . 5 5 T T r r a a f f f f i i c c G G r r a a p p h h Click Diagnostics and click Traffic Graph to pen the web page. Specify LAN and WAN profiles to display corresponding graphs for CPU, Mem ory, LAN and WAN configurations.
Vigor2960 Series User’s Guide 268 Item Description operation about recent 24 hours. Recent 7 Days – Display the information of memory operation about recent 7 days. Recent 4 Weeks – Display the information of memory operation about recent 4 weeks.
Vigor2960 Series User’s Guide 269 4 4 . . 1 1 3 3 . . 6 6 W W e e b b C C o o n n s s o o l l e e Click Diagnostics and click Web Console to pen the web page for typing commands used in console connection. A remote user can ope rate Vigor2960 from this web page without installing and opening other connection utility.
Vigor2960 Series User’s Guide 270 4 4 . . 1 1 3 3 . . 8 8 D D a a t t a a F F l l o o w w M M o o n n i i t t o o r r This page displays the running procedure (such as IP address, session number, tr.
Vigor2960 Series User’s Guide 271 Item Description IP Address Display the IP address of the monitored device. TX rate (Kbps) Display the transmission speed of the monitored device. RX rate (Kbps) Display the receiving speed of the monitored device. Sessions Display the session number that you specified in Limit Session web page.
Vigor2960 Series User’s Guide 272 After checking the box of Enable External Devices, click Refresh . Later, the basic information of available devices will be displayed in this pag. 4 4 . . 1 1 5 5 P P r r o o d d u u c c t t R R e e g g i i s s t t r r a a t t i i o o n n Please refer to section 2.
Vigor2960 Series User’s Guide 273 C C h h a a p p t t e e r r 5 5 : : T T r r o o u u b b l l e e S S h h o o o o t t i i n n g g This section will guide you to solve abnormal s ituations if you cannot access into the Internet after installing the router and finishing the web configuration.
Vigor2960 Series User’s Guide 274 5 5 . . 2 2 C C h h e e c c k k i i n n g g I I f f t t h h e e N N e e t t w w o o r r k k C C o o n n n n e e c c t t i i o o n n S S e e t t t t i i n n g g s s .
Vigor2960 Series User’s Guide 275 4. Select Obtain an IP address automatically and Obtain DNS server address automatically . F F o o r r M M a a c c O O S S 1. Double click on the current used Mac OS on the desktop. 2. Open the Application folder and get into Network .
Vigor2960 Series User’s Guide 276 5 5 . . 3 3 P P i i n n g g i i n n g g t t h h e e R R o o u u t t e e r r f f r r o o m m Y Y o o u u r r C C o o m m p p u u t t e e r r The default gateway IP address of the router is 192.168.1.1. For so me reason, you might need to use “ping” command to check the link status of the router.
Vigor2960 Series User’s Guide 277 5 5 . . 4 4 C C h h e e c c k k i i n n g g I I f f t t h h e e I I S S P P S S e e t t t t i i n n g g s s a a r r e e O O K K o o r r N N o o t t Open Online Status to check current network status. Be careful to check if the settings coming from your ISP have been typed correctly or n ot.
Vigor2960 Series User’s Guide 278 If there is something wrong with the configuration, please go to WAN page and choose General Setup again to modify the WAN connection.
Ein wichtiger Punkt beim Kauf des Geräts Draytek Vigor2960F (oder sogar vor seinem Kauf) ist das durchlesen seiner Bedienungsanleitung. Dies sollten wir wegen ein paar einfacher Gründe machen:
Wenn Sie Draytek Vigor2960F noch nicht gekauft haben, ist jetzt ein guter Moment, um sich mit den grundliegenden Daten des Produkts bekannt zu machen. Schauen Sie zuerst die ersten Seiten der Anleitung durch, die Sie oben finden. Dort finden Sie die wichtigsten technischen Daten für Draytek Vigor2960F - auf diese Weise prüfen Sie, ob das Gerät Ihren Wünschen entspricht. Wenn Sie tiefer in die Benutzeranleitung von Draytek Vigor2960F reinschauen, lernen Sie alle zugänglichen Produktfunktionen kennen, sowie erhalten Informationen über die Nutzung. Die Informationen, die Sie über Draytek Vigor2960F erhalten, werden Ihnen bestimmt bei der Kaufentscheidung helfen.
Wenn Sie aber schon Draytek Vigor2960F besitzen, und noch keine Gelegenheit dazu hatten, die Bedienungsanleitung zu lesen, sollten Sie es aufgrund der oben beschriebenen Gründe machen. Sie erfahren dann, ob Sie die zugänglichen Funktionen richtig genutzt haben, aber auch, ob Sie keine Fehler begangen haben, die den Nutzungszeitraum von Draytek Vigor2960F verkürzen könnten.
Jedoch ist die eine der wichtigsten Rollen, die eine Bedienungsanleitung für den Nutzer spielt, die Hilfe bei der Lösung von Problemen mit Draytek Vigor2960F. Sie finden dort fast immer Troubleshooting, also die am häufigsten auftauchenden Störungen und Mängel bei Draytek Vigor2960F gemeinsam mit Hinweisen bezüglich der Arten ihrer Lösung. Sogar wenn es Ihnen nicht gelingen sollte das Problem alleine zu bewältigen, die Anleitung zeigt Ihnen die weitere Vorgehensweise – den Kontakt zur Kundenberatung oder dem naheliegenden Service.