Manuale d’uso / di manutenzione del prodotto Vigor3200 del fabbricante Draytek
Vai alla pagina of 356
.
Vigor3200 Series User’s Guide ii Vigor3200 Series Multi-WAN Security Router User’s Guide Version: 1.5 Firmware Version: V3.3.7.2 (for future updat e, contact Dray Tek) Date: 17/09/2012.
Vigor3200 Series User’s Guide iii Copyright Information Copyright Declarations Copyright 2012 All rights reserved. This pub lication contains information th at is protected by copyright.
Vigor3200 Series User’s Guide iv European Community Declarations Manufacturer: DrayTek Corp. Address: No. 26, Fu Shing Road, HuKou Town ship, HsinChu Industrial Park, Hsin-Chu, Taiwan 303 Product: Vigor3200 Ser ies Router DrayTek Corp.
Vigor3200 Series User’s Guide v.
Vigor3200 Series User’s Guide vi T T a a b b l l e e o o f f C C o o n n t t e e n n t t s s Introduction ................................................................................................. 1 1.1 Web Conf iguration Bu ttons Explanation .
Vigor3200 Series User’s Guide vii 3.11.1 Creating an Account via Vigor Router .......................................................................... 80 3.11.2 Creating an Account via MyVigor Web Site..............................................
Vigor3200 Series User’s Guide viii 4.8.1 Sessio ns Limit ........................................................................................................... .... 201 4.8.2 Bandwid th Limit ....................................................
Vigor3200 Series User’s Guide ix 4.15.2 TR-069 .................................................................................................................. ...... 313 4.15.3 Administra tor Password .............................................
.
Vigor3200 Series User’s Guide 1 I I n n t t r r o o d d u u c c t t i i o o n n Vigor3200 Series, a broadband router, integrates IP layer QoS, NAT session/b andwidth management to help users control works well with large bandwidth.
Vigor3200 Series User’s Guide 2 1 1 . . 2 2 L L E E D D I I n n d d i i c c a a t t o o r r s s a a n n d d C C o o n n n n e e c c t t o o r r s s Before you use the Vigor router, please get acquainted with the LED indicators and connectors first. 1 1 .
Vigor3200 Series User’s Guide 3 Interface Description Factory Reset Restore the default settings. Usage: Turn on the router (ACT LED is blin king). Press the hole and keep for more than 5 seconds. When you see the ACT LED begins to blink rapid ly than usual, re lease the button.
Vigor3200 Series User’s Guide 4 1 1 . . 2 2 . . 2 2 F F o o r r V V i i g g o o r r 3 3 2 2 0 0 0 0 n n LED Status Explanation Blinking The router is powere d on and running normal ly. ACT (Activity) Off The router is powe red off. On USB device is connected and ready for use.
Vigor3200 Series User’s Guide 5 Interface Description Wireless LAN ON/OFF/WPS Press "Wireless LAN ON/OFF/WPS" butt on once to wait for client device making net work connection t hrough WPS. Press "Wireless LAN ON/OFF/WPS" butt on twice to enable (WLAN LED on) or disable ( WLAN LED off) wirel ess connect ion.
Vigor3200 Series User’s Guide 6 1 1 . . 3 3 H H a a r r d d w w a a r r e e I I n n s s t t a a l l l l a a t t i i o o n n Before starting to configure the router, you have to connect your devices correctly. 1. Connect the cable Modem/DSL Modem/Media Converter to any WAN port of router with Ethernet cable (RJ-45).
Vigor3200 Series User’s Guide 7 1 1 . . 4 4 P P r r i i n n t t e e r r I I n n s s t t a a l l l l a a t t i i o o n n You can install a printer onto the router for shar ing printing. All the PCs connected this router can print documents via the router.
Vigor3200 Series User’s Guide 8 3. Open File->Add Printer . A welcome dialog will appear. Please click Next . 4. Click Local printer attached to this computer and click Next. 5. In this dialog, choose Create a new port Type of port and use the drop down list to select Standard TCP/IP Port .
Vigor3200 Series User’s Guide 9 6. In the following dialog, type 192.168.1.1 (router’ s LAN IP) in the field of Printer Name or IP Address and type IP_192.168.1.1 as the port name. Then, click Next . 7. Click Standard and choose Generic Network Card.
Vigor3200 Series User’s Guide 10 9. Now, your system will ask you to choose right na me of the printer that you installed onto the router. Such step can make correct driver loaded onto your PC.
Vigor3200 Series User’s Guide 11 The printer can be used for printing now. Most of the printers with different manufacturers are compatible with vigor router. Note 1: Some printers with the fax/scanning or other additional fun ctions are not supported.
Vigor3200 Series User’s Guide 12 This page is left blank..
Vigor3200 Series User’s Guide 13 C C o o n n f f i i g g u u r r i i n n g g B B a a s s i i c c S S e e t t t t i i n n g g s s For using the router properly, it is necessar y for you to change the password of web configuration for security and adjust primary basic settings.
Vigor3200 Series User’s Guide 14 2 2 . . 2 2 C C h h a a n n g g i i n n g g P P a a s s s s w w o o r r d d No matter user mode operation or admin mode opera tion, please change the password for the original security of the router. 1. Open a web browser on your PC and type http://192.
Vigor3200 Series User’s Guide 15 Enter the login password on the field of Old Password . Type New Password and confirm the password. Then click OK to continue. 5. Now, the password has been changed. Next time, use the new password to access the Web Configurator for this router.
Vigor3200 Series User’s Guide 16 Note: There are five WAN selections available for you to choose. In which, WAN5 is selected for 3G USB modem connection. Refer to the following for detailed information. 2 2 . . 3 3 . . 1 1 F F o o r r W W A A N N 1 1 – – W W A A N N 4 4 Choose WAN1/WAN2/WAN3/WAN4 and click Next .
Vigor3200 Series User’s Guide 17 2. Click PPPoE as the Internet Access Type. Then click Next to open the following page. Available settings are explained as follows: Item Description User Name Assign a specific valid user name provided by the ISP. Password Assign a valid password provided by the ISP.
Vigor3200 Series User’s Guide 18 4. Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system status of this protocol will be shown.
Vigor3200 Series User’s Guide 19 2 2 . . 3 3 . . 1 1 . . 2 2 P P P P T T P P / / L L 2 2 T T P P 1. Choose WAN1/WAN2/WAN3/WAN4 as the WAN Interface and click the Next button. The following page will be open for you to specify Internet Access Type. 2.
Vigor3200 Series User’s Guide 20 WAN IP Configuration Obtain an IP address automatically – the router will get an IP address automatically from DHCP server. Specify an IP address – you have to type relational settings manually. IP Address - Type the IP address.
Vigor3200 Series User’s Guide 21 2 2 . . 3 3 . . 1 1 . . 3 3 S S t t a a t t i i c c I I P P 1. Choose WAN1/WAN2/WAN3/WAN4 as the WAN Interface and click the Next button. The following page will be open for you to specify Internet Access Type. 2. Click Static IP as the protocol.
Vigor3200 Series User’s Guide 22 Back Click it to return to previous setting page. Next Click it to get into the next setting page. Cancel Click it to give up the quick start wizard. 3. After finishing the settings in this page, click Next to see the following page.
Vigor3200 Series User’s Guide 23 2 2 . . 3 3 . . 1 1 . . 4 4 D D H H C C P P 1. Choose WAN1/WAN2/WAN3/WAN4 as the WAN Interface and click the Next button. The following page will be open for you to specify Internet Access Type. 2. Click DHCP as the protocol.
Vigor3200 Series User’s Guide 24 Cancel Click it to give up the quick start wizard. 3. After finishing the settings in this page, click Next to see the following page. 4. Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system status of this protocol will be shown.
Vigor3200 Series User’s Guide 25 2. Then, click Next to continue. 3. Click Finish. A page of Quick Start Wizard Setup OK!!! will appear. Then, the system status of this protocol will be shown.
Vigor3200 Series User’s Guide 26 2 2 . . 4 4 S S e e r r v v i i c c e e A A c c t t i i v v a a t t i i o o n n W W i i z z a a r r d d Service Activation Wizard can guide you to set WCF (Web Content Feature) with a quick and easy way.
Vigor3200 Series User’s Guide 27 3. In the following page, you can activate the Web content filter service at the same tim e or individually. When you finish the selection, please click Next . 4. Setting confirmation page will be displayed as follows, please click Next .
Vigor3200 Series User’s Guide 28 6. Now, the web page will display the service th at you have activated according to your selection(s). The valid time for the free trial of these services is one month.
Vigor3200 Series User’s Guide 29 2 2 . . 5 5 O O n n l l i i n n e e S S t t a a t t u u s s The online status shows the system status, WAN st atus, and other status related to this router within one page. If you select PPPoE as the protocol, you will fi nd out a link of Dial PPPoE or Drop PPPoE in the Online Status web page.
Vigor3200 Series User’s Guide 30 Item Description interface. WAN 1 Status ~ WAN 5 Status Line - Displays the physical connection of this interface. Name - Displays the name set in WAN1/WAN web page. Mode - Displays the type of WAN connection (e.g., PPPoE).
Vigor3200 Series User’s Guide 31 Click Support Area>>Application Note , the following web page will be displayed. Click Support Area>>FAQ , the following web page will be displayed. Click Support Area>>Product Registration , the following web page will be displayed.
Vigor3200 Series User’s Guide 32 2 2 . . 8 8 R R e e g g i i s s t t e e r r i i n n g g V V i i g g o o r r R R o o u u t t e e r r You have finished the configuration of Quick Start Wizard and you can surf the Internet at any time. Now it is the time to register your Vigor router to MyVigor website for getting more service.
Vigor3200 Series User’s Guide 33 3. A Login page will be shown on the screen. Please type the account and password that you created previously. And click Login . 4. The following page will be displayed after you logging in MyVigor. From this page, please click Add or Product Registration .
Vigor3200 Series User’s Guide 34 5. When the following page appears, please t ype in Nickname (for the router) and choose the right registration date from the popup calendar (it appears when you click o n the box of Registration Date). After adding the basic information for the router, please click Submit .
Vigor3200 Series User’s Guide 35 T T u u t t o o r r i i a a l l s s a a n n d d A A p p p p l l i i c c a a t t i i o o n n s s 3 3 . . 1 1 H H o o w w t t o o I I m m p p l l e e m m e e n n t t t.
Vigor3200 Series User’s Guide 36 3. Create LDAP server profiles. Click the Active Directory /LDAP tab to open the profile web page and click any one of the index number link. If we have two groups “ RD1 ” and “ SHRD ” on LDAP server, we can configure two LDAP server profiles with different Group Distinguished Name.
Vigor3200 Series User’s Guide 37 6. Then open User Management>>User Profile to create the user profile that will authenticate with LDAP server. 7. After above configurations, users belong to either “rd1” or “shrd” group can access Internet after inputting their credentials on LDAP server.
Vigor3200 Series User’s Guide 38 3 3 . . 2 2 H H o o w w t t o o i i m m p p l l e e m m e e n n t t t t h h e e A A D D / / L L D D A A P P a a u u t t h h e e n n t t i i c c a a t t i i o o n n f f o o r r S S S S L L A A p p p p l l i i c c a a t t i i o o n n ? ? Below shows the configuration steps: 1.
Vigor3200 Series User’s Guide 39 3. Click the Active Directory /LDAP tab to open the profile web page. 4. Click any one of the index numb er link to configure the proper Base Distinguished Name and Group Distinguished Name . Suppose that there are several departments in your company, e.
Vigor3200 Series User’s Guide 40 Press the button on this page to ke ep searching its sub-tree. In addition, means this item is an organization; means this item is an account. 5. Press certain item , its Base Distinguished Name (BDN) will be shown automatically in the AD/LDAP Disti nguished Nam e field box.
Vigor3200 Series User’s Guide 41 6. After finishing the AD/LDAP configuration, go to VPN and Remote Access >> PPP General Setup . Check the box of LDAP that you’ve enabled in Application >> Active Directory / LDAP . Note : Group Distinguished Name is not a MUST required option for the AD/LDAP configuration.
Vigor3200 Series User’s Guide 42 9. Setup two applications profiles (n amed PC1 and PC2) for SSL VPN. 10. Setup two SSL Web Proxy Servers prof iles (named google and baidu) for SSL VPN. 11. Go to SSL VPN >>User Group to setup two separate groups (named with g1 and g2) with different authorities and different authentication methods.
Vigor3200 Series User’s Guide 43 Set the user group profile (nam ed g2) for RD2 department:.
Vigor3200 Series User’s Guide 44 12. Once you’ve finished the configuration on Vigor router, try to login SSL portal with https://<IPAddress>/ . 13. Please type in the user name and password, and select the group that the account belongs to (In this case, the username is Caesar and the group it belongs to is g1 ).
Vigor3200 Series User’s Guide 45.
Vigor3200 Series User’s Guide 46 3 3 . . 3 3 H H o o w w t t o o C C o o n n f f i i g g u u r r e e M M u u l l t t i i - - S S u u b b n n e e t t By identifying the tagged message, Vigor3200 can divide the LAN Port into several VLAN groups. Such LAN port with tagged informati on will accept the packets only with VLAN ID number.
Vigor3200 Series User’s Guide 47 Configuration for Vigor3200 1. In the page of LAN >> VLAN Configuration , check the box of Enab le to enable the function of VLAN Configuration.
Vigor3200 Series User’s Guide 48 After finishing the above configuration, the equipm en t connecting to Vigor3200 LAN Port can get the corresponding IP address of the network segment. The equipment connecting to Vigor3200 L AN Port (LAN1) can get the IP address of 192.
Vigor3200 Series User’s Guide 49 7. To make any two of VLAN groups linked with each other, just check the boxes of the ones in the field of Inter-LAN Routing in the page of LAN >> General Setup . Refer to the following figure. LAN2 and LAN3 are linked.
Vigor3200 Series User’s Guide 50 4. After finishing the above configuration, the equipment connecting to VigorSwitch Port 15 , 16, 17 and 18 can get the corresponding IP address(es) of the network segment. The equipment connecting to VigorSwitch Port 15 can get the IP address of 192.
Vigor3200 Series User’s Guide 51 3 3 . . 4 4 H H o o w w t t o o C C u u s s t t o o m m i i z z e e Y Y o o u u r r L L o o g g i i n n P P a a g g e e Login page can be customized to fit the request of the adm inistrator. 1. Open User Management>>General Setup .
Vigor3200 Series User’s Guide 52 4. Open System Maintenance>>Login Customization . Check the box to enable this function. Type a brief description (e.g., Just for Carrie ) in the field of Login De scription which will be shown on the heading of the login dialog.
Vigor3200 Series User’s Guide 53 3 3 . . 5 5 C C r r e e a a t t e e a a L L A A N N - - t t o o - - L L A A N N C C o o n n n n e e c c t t i i o o n n B B e e t t w w e e e e n n R R e e m m o o t.
Vigor3200 Series User’s Guide 54 3. Go to LAN-to-LAN . Click on one index number to edit a profile. 4. Set Common Settings as shown below. You should enable both of VPN connections because any one of the parties may start the VPN connection.
Vigor3200 Series User’s Guide 55 5. Set Dial-Out Settings as shown below to dial to connect to Router B aggressively with the selected Dial-Out method. If an IPSec-based service is selected, you should further specify the remote peer IP Address, IKE Authentication Method and IPSec Security Method for this Dial-Out connection.
Vigor3200 Series User’s Guide 56 6. Set Dial-In settings to as shown below to allow Router B dial-in to build VPN connection. If an IPSec-based service is sele cted, you may further specify the remote peer IP Address, IKE Authentication Method and I PSec Security Method for this Dial-In connection.
Vigor3200 Series User’s Guide 57 7. At last, set the remote network IP/subnet in TCP/IP Network Settings so that Router A can direct the packets destined to the remote network to Router B via the VPN connection. Settings in Router B in the remote office: 1.
Vigor3200 Series User’s Guide 58 3. Go to LAN-to-LAN . Click on one index number to edit a profile. 4. Set Common Settings as shown below. You should enable both of VPN connections because any one of the parties may start the VPN connection.
Vigor3200 Series User’s Guide 59 If a PPP-based service is selected, y ou should further specify the remote peer IP Address, Username, Password, PPP Authentication and VJ Compression for this Dial-Out connection.
Vigor3200 Series User’s Guide 60 6. Set Dial-In settings to as shown below to allow Router A dial-in to build VPN connection. If an IPSec-based service is selected, y ou may further specify the remote peer IP Address, IKE Authentication Method and I PSec Security Method for this Dial-In connection.
Vigor3200 Series User’s Guide 61 7. At last, set the remote network IP/subnet in TCP/IP Network Settings so that Router B can direct the packets destined to the remote network to Router A via the VPN connection.
Vigor3200 Series User’s Guide 62 3 3 . . 6 6 C C r r e e a a t t e e a a R R e e m m o o t t e e D D i i a a l l - - i i n n U U s s e e r r C C o o n n n n e e c c t t i i o o n n B B e e t t w w e.
Vigor3200 Series User’s Guide 63 3. Go to Remote Dial-In User . Click on one index number to edit a profile. 4. Set Dial-In settings to as shown below to allow the remote user dial-in to build VPN connection.
Vigor3200 Series User’s Guide 64 Settings in the remote host: 1. For Win98/ME, you may use "Dial-up Networking" to create the PPTP tunnel t o Vigor router. For Win2000/XP, please use "Network and Dial-up connections" or “Smart VPN Client”, complimentary software to help you create PPTP, L2TP, and L2TP over IPSec tunnel.
Vigor3200 Series User’s Guide 65 3. In Step 2. Connect to VPN Server , click Insert button to add a new entry. If an IPSec-based service is selected as shown below, You may further specify the method you use to get IP, the security method, and authentication method.
Vigor3200 Series User’s Guide 66 then forwarded to Internet. This will make the remote host seem to be working i n the enterprise network. 4. Click Connect button to build connection. When the connection is successful, you will find a green light on the right down corner.
Vigor3200 Series User’s Guide 67 3 3 . . 7 7 Q Q o o S S S S e e t t t t i i n n g g E E x x a a m m p p l l e e Assume a teleworker someti mes works at hom e and takes care of children.
Vigor3200 Series User’s Guide 68 4. Return to previous page. Enter th e Name of Index Class 1 by clicking Edit link. T ype the name “ E-m ail ” for Class 1. 5. For this index, the user will set reserved bandwidth (e.g., 25%) for E-mail using protocol POP3 and SMTP .
Vigor3200 Series User’s Guide 69 7. Click Setup link for one of the W AN interface. 8. Check Enable UDP Bandwidth Control on t he bottom to prevent enormous UDP traf fic of influent other application.
Vigor3200 Series User’s Guide 70 9. If the worker has connected to the headquart er using host to host VPN tunnel. (Please refer to Chapter 3 VPN for detail instruction), he m ay set up an index for it. Enter the Class Name of Index 3. In this index, he will set reserved bandwidth for 1 VPN tunnel.
Vigor3200 Series User’s Guide 71 3 3 . . 8 8 U U p p g g r r a a d d e e F F i i r r m m w w a a r r e e f f o o r r Y Y o o u u r r R R o o u u t t e e r r U U s s i i n n g g F F i i r r m m w w a a r r e e U U p p g g r r a a d d e e U U t t i i l l i i t t y y Before upgrading your router firmware, you need to install the Router Tools.
Vigor3200 Series User’s Guide 72 5. Double click on the icon of router tool. The setup wizard will appear. 6. Follow the onscreen instructions to install the tool. Finally, click Finish to end the installation. 7. From the Start menu, open Programs and choose Router Tools XXX >> Firmware Upgrade Utility .
Vigor3200 Series User’s Guide 73 10. Click Send . 11. Now the firmware update is finished. U U s s i i n n g g W W e e b b P P a a g g e e The web page also can guide you to upgrade firm ware. Note that this example is running over Windows OS (Operating System).
Vigor3200 Series User’s Guide 74 3 3 . . 9 9 R R e e q q u u e e s s t t a a c c e e r r t t i i f f i i c c a a t t e e f f r r o o m m a a C C A A s s e e r r v v e e r r o o n n W W i i n n d d o o w w s s C C A A S S e e r r v v e e r r 1. Go to Certificate Management and choose Local Certificate .
Vigor3200 Series User’s Guide 75 2. You can click GENERATE button to start to edit a certificate request. Enter the information in the certificate request. 3. Copy and save the X509 Local Certificate Requet as a text file and save it for later use. 4.
Vigor3200 Series User’s Guide 76 Select Advanced request . Select Submit a certificate request a base64 encoded PKCS #10 file or a renewal request using a base64 encoded PKCS #7 file Import the X509 Local Certificate Requet text file. Select Router (Offline request) or IPSec (Offline request) below.
Vigor3200 Series User’s Guide 77 you will find the below window showin g “------BEGINE CERTIFICATE------.....” 6. You may review the detail informati on of the certificate by clicking View button.
Vigor3200 Series User’s Guide 78 3 3 . . 1 1 0 0 R R e e q q u u e e s s t t a a C C A A C C e e r r t t i i f f i i c c a a t t e e a a n n d d S S e e t t a a s s T T r r u u s s t t e e d d o o n n W W i i n n d d o o w w s s C C A A S S e e r r v v e e r r 1.
Vigor3200 Series User’s Guide 79 2. In Choose file to download , click CA Certificate Current and Base 64 encoded, and Download CA certificate to save the .cer. file. 3. Back to Vigor router, go to Trusted CA Certificate . Click IMPORT button and browse the file to import the certificate (.
Vigor3200 Series User’s Guide 80 3 3 . . 1 1 1 1 C C r r e e a a t t i i n n g g a a n n A A c c c c o o u u n n t t f f o o r r M M y y V V i i g g o o r r The website of MyVigor (a server located on http://myvigor.draytek.com ) provides several useful services (such as Anti-Spam, Web Content Filter, Anti-Intrusion, and etc.
Vigor3200 Series User’s Guide 81 4. Check to confirm that you accept the Agreement and click Accept . 5. Type your personal information in this page and then click Continue .
Vigor3200 Series User’s Guide 82 7. Now you have created an account successfully. Click START. 8. Check to see the confirmation email with the title of New Account Confirmation Letter from myvigor.draytek.com . 9. Click the Activate my Account link to enable the account that you created.
Vigor3200 Series User’s Guide 83 10. When you see the following page, please type in the account and password (that y ou just created) in the fields of UserName and Password . 11. Now, click Login . Your account has been activated. You can access into MyVigor server to activate the service (e.
Vigor3200 Series User’s Guide 84 2. Check to confirm that you accept the Agreement and click Accept . 3. Type your personal information in this page and then click Continue .
Vigor3200 Series User’s Guide 85 5. Now you have created an account successfully. Click START. 6. Check to see the confirmation email with the title of New Account Confirmation Letter from myvigor.draytek.com . 7. Click the Activate my Account link to enable the account that you created.
Vigor3200 Series User’s Guide 86 8. When you see the following page, please type in the account and password (that you just created) in the fields of UserName and Password . Then type the code in the box of Auth Code according to the value displayed on the right side of it.
Vigor3200 Series User’s Guide 87 3 3 . . 1 1 2 2 H H o o w w c c a a n n I I g g e e t t t t h h e e f f i i l l e e s s f f r r o o m m U U S S B B s s t t o o r r a a g g e e d d e e v v i i c c e.
Vigor3200 Series User’s Guide 88 3. Setup a user account for the FTP service by using USB Application >>USB User Management. Click Enable to enable FTP/Samba User account. Here we add a new account "user1" and assign authorities “Read”, “Write” and “List” to it.
Vigor3200 Series User’s Guide 89 5. When the following screen appears, it means the FTP service is running properly. 6. Return to USB Application >> USB Disk Status . The information for FTP server will be shown as below. 7. Now, users in LAN of Vigor3200 can access into the USB storage device by typing ftp://192.
Vigor3200 Series User’s Guide 90 3 3 . . 1 1 3 3 V V P P N N T T r r u u n n k k L L o o a a d d - - B B a a l l a a n n c c e e b b e e t t w w e e e e n n V V i i g g o o r r 3 3 2 2 0 0 0 0 a a n.
Vigor3200 Series User’s Guide 91 Settings for Vigor 3200: 1. Open VPN and Remote Access>>>LAN to LAN . Choose Index number 1 for configuring a VPN LAN to LAN profile. 2. In the following page, please configure the settings as the following figure.
Vigor3200 Series User’s Guide 92 3. Click OK to save the configuration and return to previous page. Choose Index n u mber 2 for configuring another VPN LAN to LAN profile.
Vigor3200 Series User’s Guide 93 5. Click OK to save the configuration. 6. Open VPN and Remote Access>>VPN TRUNK Management . Add these VPN profiles to the VPN Trunk and set Load Balance as the Attribute Mode . 7. Click Advanced for specifying Load Balance Algorithm .
Vigor3200 Series User’s Guide 94 8. When the VPN trunk is successfully connected , you may check the connection status by viewing the page of VPN and Remote Access >>Connection Management . Transferred packets (Tx Pkts) will keep increasing through bot h tunnels when outgoing packets sent to the remote VPN network.
Vigor3200 Series User’s Guide 95 2. In this page, please configure the settings as the following figure. 3. Click Apply to save the configuration and return to previous page. Choose Index 2 for configuring another VPN Trunk policy. 4. In this page, please configure the settings as the following figure.
Vigor3200 Series User’s Guide 96 5. Click Apply to save the configuration. 6. Open VPN>>VPN Trunk>>Group Table to group these two VPN policies. 7. Choose Index 1 and click Edit . Add these two VPN profiles (wan1 and wan2) to a VPN Trunk.
Vigor3200 Series User’s Guide 97 S S c c e e n n a a r r i i o o 2 2 : : T T w w o o - - p p a a i i r r V V P P N N T T r r u u n n k k Vigor3200 as VPN client (dial out site) LAN: 192.168.1.0/24 WAN 1 IP: 202.211.110.30 (My GRE IP, 10.0.0. 1, Peer GRE IP, 10.
Vigor3200 Series User’s Guide 98 3. Open VPN and Remote Access>>VPN TRUNK Management . Add these VPN profiles to the VPN Trunk and set Load Balance as the Attribute Mode . Setting configuration is the same as Scenario 1. Profile 1 and Profile 2 are one pair; Profile 3 and Profile 4 are the other pair.
Vigor3200 Series User’s Guide 99 Settings for Vigor3300: 1. Open Advanced>>LAN VLAN . Choose the tab of 802.1Q VLAN . Configure the settings as the following figure. 2. Next, open Network>>LAN . Set two LAN subnet: LAN1 192.168.33.0/24 and LAN2 192.
Vigor3200 Series User’s Guide 100 to configure the setting is the same as Scenario 1. 5. Open VPN>>VPN Trunk>>Group Table to group these VPN policies. Group two VPN policies as the following figure and then click Apply . The way to configure the setting is the same as Scenario 1.
Vigor3200 Series User’s Guide 101 A A d d v v a a n n c c e e d d W W e e b b C C o o n n f f i i g g u u r r a a t t i i o o n n This chapter will guide users to execute adva nced (full) configuration thr ough admin mode operation. As for other examples of application, please refer to chapter 5.
Vigor3200 Series User’s Guide 102 has reserved certain addresses that will never be registered publicly. These are known as private IP addresses, and are listed in the following ranges: From 10.0.0.0 to 10.255.255.255 From 172.16.0.0 to 172.31.255.255 From 192.
Vigor3200 Series User’s Guide 103 router. Besides, 3G USB Modem also can be used as backup device. Therefore, when other Ethernet WAN ports are not available, the r outer will use 3.5G for supporting automatically. The supported 3G USB Modem will be listed on DrayTek web site.
Vigor3200 Series User’s Guide 104 Index Click the WAN interface link under Index to access into the WAN configuration page. Enable V means such WAN interface is enabled and ready to be used. Physical Mode / Type Display the physical mode and physical type of such WAN interface.
Vigor3200 Series User’s Guide 105 Item Description Enable Choose Yes to invoke the settings for this WAN interface. Choose No to disable the settings for this WAN interface. Display Name Type the description for such WAN interface. Physical Mode Display the physical mode of such WAN interface.
Vigor3200 Series User’s Guide 106 When any WAN disconnect – WAN1 will be activated when any WAN interface disconnects. When all WAN disconnect – WAN1 will be activated when all the WAN interfaces disconnect. After finished the above settings, click OK to save the settings.
Vigor3200 Series User’s Guide 107 Active Mode Determine the WAN interface will be active for always ( Always On ) or be treated as a backup WAN interface ( Backup ). Backup Type - Determine the role of such WAN interface. It will be changed according to the Active Mode specified.
Vigor3200 Series User’s Guide 108 Each item is explained as follows: Item Description Index Display the WAN interface. Display Name It shows the name of the WAN1/WAN2/WAN3/WAN4/WAN5 that entered in general setup. Physical Mode It shows the physical connection for WAN1-WAN4 (Ethernet) /WAN5 (3G USB Modem) according to the real network connection.
Vigor3200 Series User’s Guide 109 D D e e t t a a i i l l s s P P a a g g e e f f o o r r P P P P P P o o E E i i n n W W A A N N 1 1 ~ ~ W W A A N N 4 4 To choose PPPoE as the accessing protocol of the internet, please select PPPoE from the Internet Access menu.
Vigor3200 Series User’s Guide 110 Item Description have to type IP address in this field for pinging. TTL (Time to Live) – Displays value for your reference. TTL value is set by telnet command. MTU It means Max Transmit Unit for packet. The default setting is 1442.
Vigor3200 Series User’s Guide 111 Item Description Fixed IP – Click Yes to use this function and type in a fixed IP address in the box of Fixed IP Address . Default MAC Address – You can use Default MAC Address or specify another MAC address by typing on the boxes of MAC Address for the router.
Vigor3200 Series User’s Guide 112 Available settings are explained as follows: Item Description Static or Dynamic IP Click Enable for activating this function. If you click Disable , this function will be closed and all the settings that you adjusted in this page will be invalid.
Vigor3200 Series User’s Guide 113 Item Description MTU It means Max Transmit Unit for packet. The default setting is 1442. RIP Protocol Routing Information Protoc ol is abbreviated as RIP(RFC1058) specifying how routers exchange routing tables information.
Vigor3200 Series User’s Guide 114 Item Description MAC address for the router. Specify a MAC Address : Some Cable service providers specify a specific MAC address fo r acc ess authentication. In such cases you need to click the Specify a MAC Address and enter the MAC address in the MAC Address field.
Vigor3200 Series User’s Guide 115 D D e e t t a a i i l l s s P P a a g g e e f f o o r r P P P P T T P P / / L L 2 2 T T P P i i n n W W A A N N 1 1 ~ ~ W W A A N N 4 4 To use PPTP/L2TP as the accessing protocol of the internet, please choose PPTP/L2TP from Internet Access menu.
Vigor3200 Series User’s Guide 116 Item Description after passing through the time without any action. IP Address Assignment Method(IPCP) Fixed IP - Usually ISP dynamically assigns IP address to you each time you connect to it and request. In some case, your ISP provides service to always assign you the same IP address whenever you request.
Vigor3200 Series User’s Guide 117 After finishing all the settings here, please click OK to activate them. D D e e t t a a i i l l s s P P a a g g e e f f o o r r P P P P P P i i n n W W A A N N 5 5 To use PPP (for 3G USB Modem) as the accessing protocol of the internet, please choose Internet Access from WAN menu.
Vigor3200 Series User’s Guide 118 Item Description ISP. PPP Username Type the PPP username (optional). PPP Password Type the PPP password (optional). Index (1-15) in Schedule Setup Set the PCs on LAN to work at certain time interval only. You can type in four sets of time schedule for your request.
Vigor3200 Series User’s Guide 119 4 4 . . 1 1 . . 4 4 L L o o a a d d - - B B a a l l a a n n c c e e P P o o l l i i c c y y This router supports the function of load balanci ng. It can assign traffic with protocol t y pe, IP address for specific host, a subnet of hosts, and port range to be allocated in WAN interface.
Vigor3200 Series User’s Guide 120 Click any Index number link to access into the following page for configuring load-balance policy. Each item is explained as follows: Item Description Enable Check this box to enable this policy. Protocol Use the drop-down menu to choose a proper protocol for the WAN interface.
Vigor3200 Series User’s Guide 121 passed through the WAN interface. After finishing all the settings here, please click OK to activate them. 4 4 . . 2 2 L L A A N N Local Area Network (LAN) is a group of subnets regulated and rul ed by router . The design of network structure is related to what type of public IP addresses coming from your ISP .
Vigor3200 Series User’s Guide 122 In some special case, you may have a public IP subnet from y our ISP such as 220.135.240.0/24. This m e ans th at you can set up a public subnet or call second subnet that each host is equipped with a public IP address.
Vigor3200 Series User’s Guide 123 W W h h a a t t a a r r e e V V i i r r t t u u a a l l L L A A N N s s a a n n d d R R a a t t e e C C o o n n t t r r o o l l Y ou can group local hosts by physical port and create up to 4 virtual LANs.
Vigor3200 Series User’s Guide 124 Each item is explained as follows: Item Description General Setup----- Allow to configure settings for each subnet respectively. Index - Display all of the LAN items, DMZ and IP Routed Subnet. Status- Check the box to enable such LAN configuration.
Vigor3200 Series User’s Guide 125 Inter-LAN Routing LAN 1 ~ LAN 4, DMZ PORT - Check the box to make the routing among LANs. After finishing all the settings here, please click OK to save the configuration. To configure LAN 1 ~ LAN 4, DMZ or IP Routed Subnet, simply click Details Page to open the settings page.
Vigor3200 Series User’s Guide 126 Item Description in the LAN. Disable Server - Let you manually assign IP address to every host in the LAN. Relay Agent - Specify which subnet that DHCP server is located the relay agent should redirect the DHCP requ est to.
Vigor3200 Series User’s Guide 127 Item Description external DNS server by establishing a W AN (e.g. DSL/Cable) connection. After finishing all the settings here, please click OK to save the configuration.
Vigor3200 Series User’s Guide 128 DHCP Server Configuration DHCP stands for Dynamic Host Configuration Protocol. The router by factory default acts a DHCP server for your network so it automatically dispatch related IP settings to any local user configured as a DHCP client.
Vigor3200 Series User’s Guide 129 For NAT Usage - Click this item to invoke NAT usage. For Routing Usage - Click this item to invoke Routing usage. IP Addr ess - T ype in private IP address for connecting to a local private network (Default: 192.168.
Vigor3200 Series User’s Guide 130 I I P P R R o o u u t t e e d d S S u u b b n n e e t t V igor router can serve as a DHCP server to route the request coming from LAN PC.
Vigor3200 Series User’s Guide 131 IP Pool Counts - Ente r the maxi mu m nu mber o f PC s t hat you want the DHCP server to assign IP addresses to. The default is 10. Use LAN Port – Specify an IP for IP Ro ute Subnet. If it is enabled, DHCP server will assign IP address automa tically for the clients coming from P1 and/or P2.
Vigor3200 Series User’s Guide 132 A A d d d d S S t t a a t t i i c c R R o o u u t t e e s s t t o o P P r r i i v v a a t t e e a a n n d d P P u u b b l l i i c c N N e e t t w w o o r r k k s s Here is an example of setting Static Route in Main Router so that user A and B locating in different subnet can talk to each other via th e router .
Vigor3200 Series User’s Guide 133 2. Click the LAN>> S tatic Route and click on the Index number 1. Please add a static route as shown below , which regulates all p ackets destined to 192.168.10.0 will be forwarded to 192.168.1.2. Click OK . 3.
Vigor3200 Series User’s Guide 134 4 4 . . 2 2 . . 4 4 V V L L A A N N Virtual LAN function provides you a very conve nient way to ma nage subnets by grouping them. Go to LAN page and select VLAN . The following page will appear. Click Enable to invoke VLAN function.
Vigor3200 Series User’s Guide 135 Subnet Choose one of them to make the selected VLAN mapping to the specified subnet only . For example, LAN1 is specified for VLAN0. It means that PCs grouped under VLAN0 can get the IP address (es) that specified by the subnet.
Vigor3200 Series User’s Guide 136 Strict Bind Click this radio button to block the connection of the I P/MAC which is not listed in IP Bind List. ARP Table This table is the LAN ARP table of this router. The information for IP and MAC will be displayed in this field.
Vigor3200 Series User’s Guide 137 Available settings are explained as follows: Item Description Port Mirror Check Enable to activate this function. Or, check Disable to close this function. Mirror Port Select a port to view traffic sent from mirrored ports.
Vigor3200 Series User’s Guide 138 4 4 . . 3 3 N N A A T T Usually, the router serves as an NAT (Network Address Translation) router. NAT is a mechanism that one or more private IP a ddresses can be mapped into a single public one. Public IP address is usually assigned by your ISP, for which you may get charged.
Vigor3200 Series User’s Guide 139 4 4 . . 3 3 . . 1 1 P P o o r r t t R R e e d d i i r r e e c c t t i i o o n n Port Redirection is usually set up for server related service inside the local network (LAN), such as web servers, FTP servers, E-mail servers etc.
Vigor3200 Series User’s Guide 140 Each item is explained as follows: Item Description Index Display the number of the profile. Service Name Display the description of the specific network service. Protocol Display the transport layer protocol (TCP or UDP).
Vigor3200 Series User’s Guide 141 Private IP Specify the private IP address of the internal host providing the service. If you choose Range as the port redirection mode, you will see two boxes on this field. Type a complete IP address in the first box (as the starting point) and the fourth digit s in the second box (as the end point).
Vigor3200 Series User’s Guide 142 4 4 . . 3 3 . . 2 2 D D M M Z Z H H o o s s t t As mentioned above, Port Redirection can redirect incoming TCP/UDP or othe r traffic on particular ports to the specific private IP address/port of host in the LAN.
Vigor3200 Series User’s Guide 143 Choose Private IP or Active True IP first. Active True IP selection is available for WAN1 only. Private IP Enter the private IP address of the DMZ host, or click Choose PC to select one. Choose PC Click this button and then a window will autom atically pop up, as depicted below.
Vigor3200 Series User’s Guide 144 If you previously have set up WAN Alias for PPPoE or Static or Dynamic IP mode in WAN2/WAN3/WAN4/WAN5 interface , you will find them in Aux. WAN IP for your selection. Available settings are explained as follows: Item Description Enable Check to enable the DMZ Host function.
Vigor3200 Series User’s Guide 145 4 4 . . 3 3 . . 3 3 O O p p e e n n P P o o r r t t s s Open Ports allows you to open a range of ports for the traffic of special applications. Common application of Open Ports includes P2 P application (e.g., BT, KaZaA, Gnutella, WinMX, eMule and others), Internet Camera etc.
Vigor3200 Series User’s Guide 146 Available settings are explained as follows: Item Description Enable Open Ports Check to enable this entry. Comment Make a name for the defined network application/service. WAN Interface Specify the WAN interface that w ill be used for this entry.
Vigor3200 Series User’s Guide 147 Internet. You can use address mapping functi on to achieve this demand. Sim ply type 192.168.1.10 as the Private IP; and t ype 86.
Vigor3200 Series User’s Guide 148 Item Description Enable Check to enable this entry. Protocol Specify the transport layer protocol. It could be TCP , UDP , or ALL for selection. WAN Interface Choose the WAN interface for such address mapping profile.
Vigor3200 Series User’s Guide 149 Available settings are explained as follows: Item Description Comment Display the text which memorizes the application of this rule. Triggering Protocol Display the protocol of the triggering packets. Triggering Port Display the port of the triggering packets.
Vigor3200 Series User’s Guide 150 Service Choose the predefined service to apply for such trigger profile. Comment Type the text to memorize the application of this rule. Triggering Protocol Select the protocol (TCP, UDP or TCP/UDP) for such triggering profile.
Vigor3200 Series User’s Guide 151 4 4 . . 4 4 F F i i r r e e w w a a l l l l 4 4 . . 4 4 . . 1 1 B B a a s s i i c c s s f f o o r r F F i i r r e e w w a a l l l l While the broadband users demand m ore bandwidth for multimedia, interactive applications, or distance learning, security has been always the most concerned.
Vigor3200 Series User’s Guide 152 S S t t a a t t e e f f u u l l P P a a c c k k e e t t I I n n s s p p e e c c t t i i o o n n ( ( S S P P I I ) ) Stateful inspection is a firewall architecture that works at the network layer.
Vigor3200 Series User’s Guide 153 4 4 . . 4 4 . . 2 2 G G e e n n e e r r a a l l S S e e t t u u p p General Setup allows you to adjust setti ngs of IP Filter and common options. Here you can enable or disable the Call Filter or Data Filter . Under some circumstance, your filter set can be linked to work in a serial manner.
Vigor3200 Series User’s Guide 154 Enable S trict Security Firewall For the sake of security , the router will execute strict security checking for data transmission. Such feature is enabled in de fault. All the packets, while transmitting through Vigor router , will be filtered by firewall.
Vigor3200 Series User’s Guide 155 Item Description section later . Load-Balance Policy Choose the W AN interface for applying Load-Balance Policy . User Management Such item is available only when Rule-Based is selected in User Management>>General Setup .
Vigor3200 Series User’s Guide 156 Item Description in CSM>> W eb Content Filter ) for applying with this router . Please set at least one profile for anti-virus in CSM>> W eb Content Filter web page first. Or choose [Cr eate New] from the drop down list in this pa ge to create a new profile.
Vigor3200 Series User’s Guide 157 Item Description best utilization of network resources. After finishing all the settings here, please click OK to save the configuration.
Vigor3200 Series User’s Guide 158 4 4 . . 4 4 . . 3 3 F F i i l l t t e e r r S S e e t t u u p p Click Firewall and click Filter Setup to open the setup page. To edit or add a filter, click on the set numbe r to edit the individual set. The following page will be shown.
Vigor3200 Series User’s Guide 159 To edit Filter Rule , click the Filter Rule index button to enter the Filter Rule setup page. After finishing all the settings here, please click OK to save the configuration. Item Description Check to enable the Filter Rule Check this box to enable the filter rule.
Vigor3200 Series User’s Guide 160 Item Description Note: RT means routing domain for 2nd subnet. Source/Destination IP Click Edit to access into the follo wing dialog to choose the source/destination IP or IP ranges.
Vigor3200 Series User’s Guide 161 Item Description Type. Protocol - Specify the protocol(s) which this filter rule will apply to. Source/Destination Port – (=) – when the first and last value ar.
Vigor3200 Series User’s Guide 162 Item Description configured in IP Object for Source IP and Destination IP be bound for applying such filter rule. No-Strict - no limitation. Quality of Service Choose one of the QoS rules to be applied as firewall rule.
Vigor3200 Series User’s Guide 163 Item Description Content Filter web page first. Or choose [Cr eate New] from the drop down list in this pa ge to create a new profile. For troubleshooting needs, you can specify to record inform ation for W eb Content Filter by checking the Log box.
Vigor3200 Series User’s Guide 164 Item Description will be. However , if the network is not stable, small value will be proper . Session timeout –Setting timeout for sessions can make the best utilization of network resources.
Vigor3200 Series User’s Guide 165 E E x x a a m m p p l l e e As stated before, all the traffic will be separate d and arbitrated using on of two IP filters: call filter or data filter. You may preset 12 call filters and data filters in Filter Setup and even link them in a serial manner.
Vigor3200 Series User’s Guide 166 4 4 . . 4 4 . . 4 4 D D o o S S D D e e f f e e n n s s e e As a sub-functionality of IP Filter/Firewall, th ere are 15 types of detect/ defense function in the DoS Defense setup. The DoS Defense functionality is disabled for default.
Vigor3200 Series User’s Guide 167 Item Description defense Similar to the UDP flood defense function, once if the Threshold of ICMP packets fro m Internet has exceeded the defined value, the router will discard the ICMP echo requests coming from the Internet.
Vigor3200 Series User’s Guide 168 Item Description fragmented ICMP packets with a length greater than 1024 octets. Block Ping of Death Check the box to activate the Block Ping of Death function.
Vigor3200 Series User’s Guide 169 4 4 . . 5 5 U U s s e e r r M M a a n n a a g g e e m m e e n n t t User Management is a security feature which disallows any IP traffic (except DHCP-related packets) from a particular host until that host has correctly supplied a valid username and password.
Vigor3200 Series User’s Guide 170 Item Description the filter rules configured in User Management>>User Profile to the users. Rule-Based –If you choose such mode, the router will apply the filter rules configured in Firewall>>General Setup and Filter Rule to the users.
Vigor3200 Series User’s Guide 171 Available settings are explained as follows: Item Description Enable this account Check this box to enable such user profile. User Name Type a name for such user profile (e.g., LAN_User_Group_1, WLAN_User_Group_A, WLAN_User_Group_B, etc).
Vigor3200 Series User’s Guide 172 Item Description Default – If you choose such item, the filter rules pre-configured in Firewall can be adopted for such user profile. Create New Policy – If you choose such item, the following page will be popped up for you t o de fine another filter rule as a new policy.
Vigor3200 Series User’s Guide 173 Item Description first. There are three ways offered by the router for the user to choose for authentication. Web – If it is selected, the use can type the URL of the router from any browser. Then, a login window will be popped up and ask the user to type the user name and password for authentication.
Vigor3200 Series User’s Guide 174 Please click any index number link to open the following page. Available settings are explained as follows: Item Description Name Type a name for this user group. Available User Objects You can gather user profiles (objects) from User Profile page within one user group.
Vigor3200 Series User’s Guide 175 3 3 . . 5 5 . . 4 4 U U s s e e r r O O n n l l i i n n e e S S t t a a t t u u s s This page displays the user(s) connected to the router and refreshes the connection status in an interval of several seconds.
Vigor3200 Series User’s Guide 176 4 4 . . 6 6 O O b b j j e e c c t t s s S S e e t t t t i i n n g g s s For IPs in a range and service ports in a limited range usually will be applied in configuri ng router’s settings, therefore we can define them with objects and bind them with groups for using conveniently.
Vigor3200 Series User’s Guide 177 Available settings are explained as follows: Item Description Name Type a name for this profile. Maximum 15 characters are allowed. Interface Choose a proper interface. For example, the Direction setting in Edit Filter Rule will ask you specify IP or IP range for WAN or LAN or any IP address.
Vigor3200 Series User’s Guide 178 Item Description Start IP Address Type the start IP address for Single Address type. End IP Address Type the end IP address if the Range Address type is selected. Subnet Mask Type the subnet mask if the Subnet Address type is selected.
Vigor3200 Series User’s Guide 179 Click the number under Index colu mn for settings in detail. Available settings are explained as follows: Item Description Name Type a name for this profile. Maximum 15 characters are allowed. Interface Choose WAN, LAN or Any to display all the available IP objects with the specified interface.
Vigor3200 Series User’s Guide 180 4 4 . . 6 6 . . 3 3 S S e e r r v v i i c c e e T T y y p p e e O O b b j j e e c c t t You can set up to 96 sets of Service Type Objects with different conditions. Available settings are explained as follows: Item Description Name Display a name for this profile.
Vigor3200 Series User’s Guide 181 Item Description Source/Destination Port Source Port and the Destination Port column are available for TCP/UDP protocol.
Vigor3200 Series User’s Guide 182 4 4 . . 6 6 . . 4 4 S S e e r r v v i i c c e e T T y y p p e e G G r r o o u u p p This page allows you to bind several service types into one group. Available settings are explained as follows: Item Description Name Display a name for this profile.
Vigor3200 Series User’s Guide 183 Click the number under Index co lumn for settings in detail. Available settings are explained as follows: Item Description Name Type a name for this profile.
Vigor3200 Series User’s Guide 184 4 4 . . 6 6 . . 5 5 K K e e y y w w o o r r d d O O b b j j e e c c t t You can set 200 keyword object profiles for choosing as black /white list in CSM >>U RL Web Content Filter Profile. Available settings are explained as follows: Item Description Name Display a name for this profile.
Vigor3200 Series User’s Guide 185 Item Description Name Type a name for this profile, e.g., game. Contents Type the content for such profile. For example, type gambling as Contents. When you browse th e web page, the page with gambling information will be watched out and be passed/blocked based on the conf iguration on Firewall settings.
Vigor3200 Series User’s Guide 186 Available settings are explained as follows: Item Description Name Type a name for this group. Available Keyword Objects You can gather keyword objects from Keyword Object page within one keyword group. All the available Keyword objects that you have created will be shown in this box.
Vigor3200 Series User’s Guide 187 Click the number under Profile column for configuration in details. Available settings are explained as follows: Item Description Profile Name Type a name for this profile. Type a name for such profile and check all the ite ms of file extension that will be processed in the router.
Vigor3200 Series User’s Guide 188 4 4 . . 7 7 C C S S M M P P r r o o f f i i l l e e C C o o n n t t e e n n t t S S e e c c u u r r i i t t y y M M a a n n a a g g e e m m e e n n t t ( ( C C S S .
Vigor3200 Series User’s Guide 189 4 4 . . 7 7 . . 1 1 A A P P P P E E n n f f o o r r c c e e m m e e n n t t P P r r o o f f i i l l e e You can define policy profiles for IM (Instan t Messenger)/P2P (Peer to Peer)/Protocol/Misc application. This page allows you to set 32 profiles for different requirements.
Vigor3200 Series User’s Guide 190 Below shows the items which are categorized under IM . Available settings are explained as follows: Item Description Profile Name Type a name for the CSM profile. Select All Click it to choose all of the items in this page.
Vigor3200 Series User’s Guide 191 Below shows the items which are categorized under Protocol ..
Vigor3200 Series User’s Guide 192 The items categorized under Misc..
Vigor3200 Series User’s Guide 193 4 4 . . 7 7 . . 2 2 U U R R L L C C o o n n t t e e n n t t F F i i l l t t e e r r P P r r o o f f i i l l e e To provide an appropriate cyberspace to users, Vigor.
Vigor3200 Series User’s Guide 194 Default Message You can type the message manually for your necessity or click this button to get the default message which will be displayed on the field of Administration Message . You can set eight profiles as URL content filter.
Vigor3200 Series User’s Guide 195 Item Description will process the packages with the conditions set below for web feature first, then URL second. Log None – There is no log file will be recorded for this profile. Pass – Only the log about Pass w ill be recorded in Syslog.
Vigor3200 Series User’s Guide 196 Item Description decline the connection request to the website whose URL string matched to any user-defined ke y word. It should be noticed that the more simplified the blocking ke y word list is, the more efficiently the Vigor router performs.
Vigor3200 Series User’s Guide 197 Item Description After finishing all the settings here, please click OK to save the configuration..
Vigor3200 Series User’s Guide 198 4 4 . . 7 7 . . 3 3 W W e e b b C C o o n n t t e e n n t t F F i i l l t t e e r r P P r r o o f f i i l l e e There are three ways to activate WCF on vigor router, using Service Activation Wizard , by means of CSM>>Web Content Filter Profile or via System Maintenance>>Activation .
Vigor3200 Series User’s Guide 199 Item Description searching when you type URL in browser based on the web content filter profile. Setup Test Server It is recommended for you to use the default setting, auto-selected. Find more Click it to open http://myvigor.
Vigor3200 Series User’s Guide 200 Available settings are explained as follows: Item Description Black/White List Enable – Activate white/black list function for such profile. Group/Object Selections – Click Edit to choose the group or object profile as the content of white/black list.
Vigor3200 Series User’s Guide 201 Item Description Pass – Only the log about Pass w ill be recorded in Syslog. Block – Only the log about Block will be recorded in Syslog. All – All the actions (Pass and Block) will be recorded in Syslog. After finishing all the settings here, please click OK to save the configuration.
Vigor3200 Series User’s Guide 202 To activate the function of limit session, simply click Enable and set the default session limit. Available settings are explained as follows: Item Description Enable Click this button to activate the function of limit session.
Vigor3200 Series User’s Guide 203 Item Description Delete Remove the selected settings existing on the limitation list. Administration Message Type the words which will be displayed when reaches the maximum number of Internet sessions permitted. Default Message Click this button to apply the default message offered by the router.
Vigor3200 Series User’s Guide 204 Bandwidth Limit Enable - Click this button to activate the function of li mit bandwidth. IP Routed Subnet – Check this box to apply the bandwidth limit to the second subnet specified in LAN>>General Setup . Disable - Click this button to close the function of limit bandwidth.
Vigor3200 Series User’s Guide 205 4 4 . . 8 8 . . 3 3 Q Q u u a a l l i i t t y y o o f f S S e e r r v v i i c c e e Deploying QoS (Quality of Service) management to guarantee that all applications.
Vigor3200 Series User’s Guide 206 However, each node may take different attitude toward packets with high priority marking since it may bind with the business deal of SLA among different DS domain owners.
Vigor3200 Series User’s Guide 207 Item Description SIP UDP Port – Set a port number used for SIP. This page displays the QoS settings result of the WAN interface. Click the Setup link to access into next page for the general setup of W AN interface.
Vigor3200 Series User’s Guide 208 G G e e n n e e r r a a l l S S e e t t u u p p f f o o r r W W A A N N I I n n t t e e r r f f a a c c e e When you click Setup , you can configure the bandwidth ratio for QoS of the WAN interface. There are four queues allowed for QoS control.
Vigor3200 Series User’s Guide 209 Item Description Reserved Bandwidth Ratio It is reserved for the group index in the form of ratio of reserved bandwidth to upstream speed and reserve d bandwidth to downstream speed . Enable UDP Bandwidth Control Check this and set the limited bandwidth ratio on the right field.
Vigor3200 Series User’s Guide 210 Available settings are explained as follows: Item Description ACT Check this box to invoke these settings. Ethernet Type Please specify which protocol (IPv4 or IPv6) will be used for this rule. Local Address Click the Edit button to set the local IP address (on LAN) for the rule.
Vigor3200 Series User’s Guide 211 4. After finishing all the settings here, please click OK to save the configuration. By the way, you can set up to 20 rules for one Class. If you want to edit an existed rule, please select the radio button of that one and clic k Edit to open the rule edit page for modification.
Vigor3200 Series User’s Guide 212 After you click the Edit link, you will see the following page. For adding a new service type, click Add to open the following pag e. E E d d i i t t t t h h e e S S e e r r v v i i c c e e T T y y p p e e f f o o r r C C l l a a s s s s R R u u l l e e 1.
Vigor3200 Series User’s Guide 213 3. For adding a new service type, click Add to open the following pag e. Available settings are explained as follows: Item Description Service Name Type in a new service for your request. Service Type Choose the type (TCP, UDP or TCP/UDP) for the new service.
Vigor3200 Series User’s Guide 214 4 4 . . 9 9 A A p p p p l l i i c c a a t t i i o o n n s s Below shows the menu items for Applications. 4 4 . . 9 9 . . 1 1 D D y y n n a a m m i i c c D D N N S S The ISP often provides you with a dynamic IP address when you c onnect to the Internet via your ISP.
Vigor3200 Series User’s Guide 215 Item Description Auto-Update interval Set the time for the router to perform auto update for DDNS service. View Log Display DDNS log status. Force Update Force the router updates its information to DDNS server. Index Click the number below Index to access into the setting page of DDNS setup to set account(s).
Vigor3200 Series User’s Guide 216 Item Description Service Provider Select the service provider for the DDNS account. Service Type Select a service type (Dynamic, Custom or Static). If you choose Custom, you can modify the domain that is chosen in the Domain Name field.
Vigor3200 Series User’s Guide 217 time. You can inquiry an NTP server (a time serv er) on the Internet to synchronize the router’s clock. This method can only be applied when the WAN connection has been built up. Each item is explained as follows: Item Description Set to Factory Default Clear all profiles and recover to factory settings.
Vigor3200 Series User’s Guide 218 2. The detailed settings of the call sche dule with index 1 are shown below . Available settings are explained as follows: Item Description Enable Schedule Setup Check to enable the schedule. Start Date (yyyy-mm-dd) Specify the starting date of the schedule.
Vigor3200 Series User’s Guide 219 Suppose you want to control the PPPoE Internet acce ss connection to be always on (Force On) from 9:00 to 18:00 for whole week. Other time the Internet access connection should be disconnected (Force Down). Office Hour: (Force On) Mon - Sun 9:00 am to 6:00 pm 1.
Vigor3200 Series User’s Guide 220 4 4 . . 9 9 . . 3 3 R R A A D D I I U U S S Remote Authentication Dial-In User Servi ce (RADIUS) is a security authentication client/server protocol that supports authenti cation, authorization and accounting, which is widely used by Internet service providers.
Vigor3200 Series User’s Guide 221 4 4 . . 9 9 . . 4 4 L L D D A A P P / / A A c c t t i i v v e e D D i i r r e e c c t t o o r r y y Lightweight Directory Access Protocol (LDAP) is a communication protocol for using in TCP/IP network.
Vigor3200 Series User’s Guide 222 The different is that, the server will firstly check if you have the search authority. For the regular mode, you’ll need to type in the Regular DN and Regular Password . Server IP Address Enter the IP address of LDAP server.
Vigor3200 Series User’s Guide 223 Item Description Name Type a name for such profile. Common Name Identifier Type or edit the common name identifier for the LDAP server.
Vigor3200 Series User’s Guide 224 your applications to operate. This has to manually set up port mappings or use other similar methods. The screenshots below show examples of this facility . The UPnP facility on the router enables UPnP awar e applications such as MSN Messenger to discover what are behind a NA T router .
Vigor3200 Series User’s Guide 225 The UPnP function dynamically adds port ma ppings on behalf of some UPnP-aware applications. When the applications terminate abnormally, these mappings may not be removed. 4 4 . . 9 9 . . 6 6 I I G G M M P P IGMP is the abbreviation of Internet Group Management Protocol .
Vigor3200 Series User’s Guide 226 4 4 . . 9 9 . . 7 7 W W a a k k e e o o n n L L A A N N A PC client on LAN can be woken up by the router it connects. When a user wants to wake up a specified PC through the router, he/she must type correct MAC address of the specified PC on this web page of Wake on LAN of this router.
Vigor3200 Series User’s Guide 227 4 4 . . 1 1 0 0 V V P P N N a a n n d d R R e e m m o o t t e e A A c c c c e e s s s s A Virtual Private Network (VPN) is the extension of a private network that encompasses links across shared or public networks like the Intern et.
Vigor3200 Series User’s Guide 228 Please choose a LAN-to-LAN Profile There are 32 VPN profiles for users to set. When you finish the mode and profile selection, please click Next to open the following page. In this page, you have to select suitable VPN type for the VPN client profile.
Vigor3200 Series User’s Guide 229 choices for the client profile, please click Next . You will see different configurations based on the selection(s) you made.
Vigor3200 Series User’s Guide 230 z When you choose L2TP , you will see the following graphic: z When you choose L2TP over IPSec (Nice to Have), you will see the following graphic:.
Vigor3200 Series User’s Guide 231 z When you choose L2TP over IPSec (Must), you will see the following graphic: Available settings are explained as follows: Item Description Profile Name Type a name for such profile. The length of the file is limited to 10 characters.
Vigor3200 Series User’s Guide 232 Digital Signature (X.509) Click Digital Signature to invoke this function. Use the drop down list to choose one of the certificates for using. You have to configure one certificate at least previously in Certificate Management >> Local Certificate.
Vigor3200 Series User’s Guide 233 Available settings are explained as follows: Item Description Go to the VPN Connection Management Click this radio button to access VPN and Remote Access>>Connection Management for viewing VPN Connection status.
Vigor3200 Series User’s Guide 234 Item Description Please choose a Dial-in User Accounts This item is available when you choose Remote Dial-in User (Teleworker) as VPN server mode. There are 32 VPN tunnels for users to set. Allowed Dial-in Type This item is available after you choose any one of dial-in user account profiles.
Vigor3200 Series User’s Guide 235 1. Here we take the example of choosing Remote-Dial-in User as the VPN Server Mode . 2. Check the Allowed Dial-in Type for the VPN server profile 3. After making the choices for the server profile, please click Next .
Vigor3200 Series User’s Guide 236 z When you check IPSec , you will see the following graphic: Available settings are explained as follows: Item Description Profile Name Type a name for such profile. The length of the file is limited to 10 characters.
Vigor3200 Series User’s Guide 237 Item Description of the remote host) for building VPN connection. Remote Network Mask Please type the network mask (according to the real location of the remote host) for building VPN connection. 4. After finishing the configuration, please click Next.
Vigor3200 Series User’s Guide 238 4 4 . . 1 1 0 0 . . 3 3 R R e e m m o o t t e e A A c c c c e e s s s s C C o o n n t t r r o o l l Enable the necessary VPN service as you need. If you intend to run a VPN server inside your LAN, you should disable the VPN service (e.
Vigor3200 Series User’s Guide 239 Item Description fall back to use the PAP protocol for authentication. Dial-In PPP Encryption (MPPE Optional MPPE Optional MPPE - This option represents that the MPPE encryption method will be optionally employed in the router for the remote dial-in user.
Vigor3200 Series User’s Guide 240 4 4 . . 1 1 0 0 . . 5 5 I I P P S S e e c c G G e e n n e e r r a a l l S S e e t t u u p p In IPSec General Setup, there are two major parts of configuration.
Vigor3200 Series User’s Guide 241 Item Description Pre-Shared Key - Currently only suppor t Pre-Shared Key authentication. Pre-Shared Key- Specify a key for IKE authentication Confirm Pre-Shared Key- Retype the characters to confirm the pre-shared key.
Vigor3200 Series User’s Guide 242 Click each index to edit one peer digital certificate. There are three security levels of digital signature authentication: Fill each necessary fi eld to authenticate the remote peer. The following explanation will guide you to fill all the necessary fields.
Vigor3200 Series User’s Guide 243 4 4 . . 1 1 0 0 . . 7 7 R R e e m m o o t t e e D D i i a a l l - - i i n n U U s s e e r r You can manage remote access by maintaining a table of remote user profile, so that users can be authenticated to dial-in via VPN connecti on.
Vigor3200 Series User’s Guide 244 Click each index to edit one remote user profile. Each Dial-In Type requires you to fill the different corresponding fields on the right. If the fields gray out, it means you may leave it untouched. The following explanation will gui de you to fill all the necessary fields.
Vigor3200 Series User’s Guide 245 Item Description policy can be viewed as one pure L2TP connection. z Nice to Have - Apply the IPSec policy first, if it is applicable during negotiation. Otherwise, the dial-in VPN connection becomes one pure L2TP connection.
Vigor3200 Series User’s Guide 246 Item Description Draytek SSL VPN portal interface. From the web page, you will see the message to indicate that you have the privilege for the SSL Web Proxy. If you haven’t set any SSL VPN web proxy profiles, you will a link here.
Vigor3200 Series User’s Guide 247 Item Description High-Encapsulating Security Payload (ESP) means payload (data) will be encrypted and authenticated. You may select encryption algorithm from Data Encryption Standard (DES), Triple DES (3DES), and AES.
Vigor3200 Series User’s Guide 248 Item Description View All – Click it to show all of profiles. Online/Offline – Click it to show the active/inactive profiles Trunk - Click it to show the prof ile which VPN tunnel is up. Name Indicate the name of the LAN-to-LAN profile.
Vigor3200 Series User’s Guide 249 Available settings are explained as follows: Item Description Profile Name Specify a name for the profile of the LAN-to-LAN connection. Enable this profile Check here to activate this profile. VPN Dial-Out Through Use the drop down menu to choose a proper WAN interface for this profile.
Vigor3200 Series User’s Guide 250 Item Description any one of VPN peers wants to disconnect the connection, it should follow a serial of packet exchange procedure to inform each other. However, if the remote peer disconnect without notice, Vigor router will by no where to know this situation.
Vigor3200 Series User’s Guide 251 Item Description mode. Local Certificate – Select one of the profiles set in Certificate Management>>Local Certificate . IPSec Security Method This group of fields is a must for IPSec Tunnels and L2TP with IPSec Policy.
Vigor3200 Series User’s Guide 252 Item Description suggest you select the combination that covers the most algorithms. IKE phase 1 key lifetime- For security reason, the lifetime of key should be defined. The default value is 28800 seconds. You may specify a value in between 900 and 86400 seconds.
Vigor3200 Series User’s Guide 253 Item Description connection through the Internet. You should set the U ser Name and Password of remote dial-in user below. IPSec Tunnel- Allow the remote dial-in user to trigger an IPSec VPN connection through Internet.
Vigor3200 Series User’s Guide 254 Item Description Certificate Management>>Local Certificate ) will be inspected first. IPSec Security Method This group of fields is a must for IPSec Tunnels and L2TP with IPSec Policy when you specify the remote node.
Vigor3200 Series User’s Guide 255 Item Description Local Network IP / Local Network Mask - Add a static route to direct all traffic destined to Local Network IP Address/Local Network Mask through the VPN connection.
Vigor3200 Series User’s Guide 256 ¾ Dial-out connection types contain IPSec, PPTP, L2TP, L2TP over IPSec and ISDN (depends on hardware specification) ¾ The web page is simple to understand and eas.
Vigor3200 Series User’s Guide 257 Available settings are explained as follows: Item Description Backup Profile List Set to Factory Default - Click to clear all VPN TRUNK-VPN Backup mechanism profile. No – The order of VPN TRUNK-VPN Backup mechanism profile.
Vigor3200 Series User’s Guide 258 Type (on Backup Profile field) - Display the connection type for that profile, such as IPSec, PPTP, L2TP, L2TP over IPSec (NICE), L2TP over IPSec(MUST) and so on. Member2 (on Backup Profile field) - Display the dial-out profile selected from the Member2 drop down list below.
Vigor3200 Series User’s Guide 259 Detailed information for this dialog, see later section - Advanced Load Balance and Backup . General Setup Status - After choosing one of the profile listed above, please click Enable to activate this profile.
Vigor3200 Series User’s Guide 260 Edit Click this button to save the changes to the Status (Enable or Disable), profile name, member1 or member2. Delete Click this button to delete the selected VPN TRUNK profile.
Vigor3200 Series User’s Guide 261 to indicate that they are fixed. If you delete the VPN TRUNK – VPN Backup/Load Balance mechanism profile, the selected LAN-to-LAN profiles will be released and expressed in black.
Vigor3200 Series User’s Guide 262 A A d d v v a a n n c c e e d d L L o o a a d d B B a a l l a a n n c c e e a a n n d d B B a a c c k k u u p p After setting profiles for load balance, you can choose any one of t h em and click Advance for more detailed configuration.
Vigor3200 Series User’s Guide 263 VPN Load Balance Policy Below shows the algorithm for Load Balance. Edit – Click this radio button for assign a blank table for configuring Binding Tunnel. After insert – Click this radio button to adding a new bindi ng tunnel table.
Vigor3200 Series User’s Guide 264 Detail Information This field will display detailed information for Binding Tunnel Policy. Below shows a successf ul binding tunnel policy for load balance: Note : To configure a successful binding tunnel, you have to: Type Binding Src IP range (Start and End) and Binding Des IP range (Start and End).
Vigor3200 Series User’s Guide 265 Item Description Member 1 will be the top priority for the system to do VPN connection. Detail Information This field will display detailed information for Environment Recovers Detection.
Vigor3200 Series User’s Guide 266 Dial - Click this button to execute dial out function. Refresh Seconds Choose the time for refresh the dial inform ation among 5, 10, and 30. Refresh Click this button to refresh the whole connection status. VPN Connection Status Display current connected VPN status.
Vigor3200 Series User’s Guide 267 4 4 . . 1 1 1 1 C C e e r r t t i i f f i i c c a a t t e e M M a a n n a a g g e e m m e e n n t t A digital certificate works as an electronic ID, which is issued by a certification authority (CA). It contains information such as your name , a serial number, expiration dates etc.
Vigor3200 Series User’s Guide 268 Note: Please be noted that “Common Name” must be configured with rotuer’s WAN IP or domain name. After clicking GENERATE , the generated information w ill be .
Vigor3200 Series User’s Guide 269 Available settings are explained as follows: Item Description Upload Local Certificate It allows users to import the certificate which is generated by vigor router and signed by CA server. If you have done well in certificate generation, the Status of the certificate will be shown as “ OK ”.
Vigor3200 Series User’s Guide 270 REFRESH Click this button to refresh the information listed below. View Click this button to view the detailed settings for certificate request. Note: You have to copy the certificate request information from above window.
Vigor3200 Series User’s Guide 271 4 4 . . 1 1 1 1 . . 2 2 T T r r u u s s t t e e d d C C A A C C e e r r t t i i f f i i c c a a t t e e Trusted CA certificate lists three sets of trusted CA certificate. To import a pre-saved trusted CA certificate, please click IMPORT to open the following window.
Vigor3200 Series User’s Guide 272 4 4 . . 1 1 1 1 . . 3 3 C C e e r r t t i i f f i i c c a a t t e e B B a a c c k k u u p p Local certificate and Trusted CA certificate for this router can be saved within one file. Please click Backup on the following screen to save them.
Vigor3200 Series User’s Guide 273 M M u u l l t t i i p p l l e e S S S S I I D D s s Vigor router supports four SSID settings for wireless connections. Each SSID can be defined with different name and download/upload rate for selecting by stations connected to the route r wirelessly.
Vigor3200 Series User’s Guide 274 Separate the Wireless and the Wired LAN- WLAN Isolation enables you to isolate your wireless LAN from wired LAN for either quaran tine or limit access reasons. To isolate means neither of the parties can access each other.
Vigor3200 Series User’s Guide 275 4 4 . . 1 1 2 2 . . 2 2 G G e e n n e e r r a a l l S S e e t t u u p p By clicking the General Settings , a new web page will appear so that you could configure the SSID and the wireless channel. Please refer to the following figure for more information.
Vigor3200 Series User’s Guide 276 Item Description In which, 802.11b/g operates on 2.4G ba nd, 802.11a operates on 5G band, and 802.11n operates on either 2.
Vigor3200 Series User’s Guide 277 Item Description Long Preamble This option is to define the length of t h e sync field in an 802.11 packet. Most modern wireless network uses short preamble with 56 bit sync field instead of lon g preamble with 128 bit sync field.
Vigor3200 Series User’s Guide 278 Item Description environment of the network. Rate Control It controls the data transmission rate through wireless connection. Upload – Check Enable and type the transmitting rate for data upload. Default value is 30,000 kbps.
Vigor3200 Series User’s Guide 279 4 4 . . 1 1 2 2 . . 3 3 S S e e c c u u r r i i t t y y This page allows you to set security with diffe rent modes for SSID 1, 2, 3 and 4 respectively. After configuring the correct settings, please click OK to save and invoke it.
Vigor3200 Series User’s Guide 280 Available settings are explained as follows: Item Description Mode There are several modes provided for you to choose. Note: You should also set RADIUS Server simultaneously if 802.1x mode is selected. Disable - Turn off the encryption mechanism.
Vigor3200 Series User’s Guide 281 Item Description as "0x321253abcde..."). WEP 64-Bit - For 64 bits WEP key, either 5 ASCII characters, such as 12345 (or 10 hexadecimal digitals leading by 0x, s uch as 0x4142434445.
Vigor3200 Series User’s Guide 282 Item Description Enable Mac Address Filter Select to enable the MAC Address filter for wireless LAN identified with SSID 1 to 4 respectively. All the clients (expressed by MAC addresses) listed in the box can be grouped under different wireless LAN.
Vigor3200 Series User’s Guide 283 There are two methods to do network conn ection through WPS between AP and Stations: pressing the Start PBC button or using PIN Code . z On the side of Vigor 3200 series which served as an AP, press WPS button once on the front panel of the router or click Start PBC on web configuration interface.
Vigor3200 Series User’s Guide 284 Available settings are explained as follows: Item Description Enable WPS Check this box to enable WPS setting. WPS Status Display related system information for WPS. If the wireless security (encryption) function of the router is properly configured, you can see ‘Configured’ message here.
Vigor3200 Series User’s Guide 285 4 4 . . 1 1 2 2 . . 6 6 W W D D S S WDS means Wireless Distribution System. It is a protocol for connecting two access points (AP) wirelessly. Usually, it can be used for the following application: y Provide bridge traffic between two LANs through the air.
Vigor3200 Series User’s Guide 286 The major difference between these two modes is that: while in Repeater mode, the packets received from one peer AP can be repeated to another peer AP through WDS links. Yet in Bridge mode, packets received from a WDS link will only be for warded to local wired or wireless hosts.
Vigor3200 Series User’s Guide 287 Available settings are explained as follows: Item Description Mode Choose the mode for WDS setting. Disable mode will not invoke any WDS setting. Bridge mode is designed to fulfill the first type of application. Repeat er mode is for the second one.
Vigor3200 Series User’s Guide 288 Item Description Key - Type 8 ~ 63 ASCII characters or 64 hexadecimal digits leading by “0x”. Bridge If you choose Bridge as the connecting mode, please type in the peer MAC address in these fields. Four peer MAC addresses are allowed to be entered in this page at one time.
Vigor3200 Series User’s Guide 289 Item Description 20/40 – the router will use 20Mhz or 40Mhz for data transmission and receiving according to the station capability. Such channel can increase the performance for data transit. Guard Interval It is to assure the safety of propagation delays and reflections for the sensitive digital data.
Vigor3200 Series User’s Guide 290 Item Description APSD Capable The default setting is Disable . Aifsn It controls how long the client waits for each data transmission. Please specify the value ranging from 1 to 15. Such parameter will influence the time delay for WMM accessing categories.
Vigor3200 Series User’s Guide 291 4 4 . . 1 1 2 2 . . 9 9 A A P P D D i i s s c c o o v v e e r r y y Vigor router can scan all regulatory channels and find working APs in the neighborhood. Based on the scanning result, users will know which channel is clean for usage.
Vigor3200 Series User’s Guide 292 4 4 . . 1 1 2 2 . . 1 1 0 0 S S t t a a t t i i o o n n L L i i s s t t Station List provides the knowledge of connecting wire less clients now along with its status code. There is a code summary belo w for explanation.
Vigor3200 Series User’s Guide 293 4 4 . . 1 1 2 2 . . 1 1 1 1 W W e e b b P P o o r r t t a a l l This page allows you to specify an URL fo r accessing into or display a message when a wireless user connects to Internet through this router.
Vigor3200 Series User’s Guide 294 4 4 . . 1 1 3 3 S S S S L L V V P P N N An SSL VPN (Secure Sockets Layer virtual private network) is a form of VPN that can be used with a standard Web browser. There are two benefits that SSL VPN provides: ¾ It is not necessary for users to preinstall VPN client software for executing SSL VPN connection.
Vigor3200 Series User’s Guide 295 After finishing all the settings here, please click OK to save the configuration. 4 4 . . 1 1 3 3 . . 2 2 S S S S L L W W e e b b P P r r o o x x y y SSL Web Proxy will allow the remote users to access the internal we b sites over SSL.
Vigor3200 Series User’s Guide 296 Disable – the profile will be inactive. If you choose Disable , all the web proxy profile appeared under VPN remote dial-in web page will disappear. Secured Port Redirection – such technique applies private port mapping to random WAN port.
Vigor3200 Series User’s Guide 297 4 4 . . 1 1 3 3 . . 3 3 S S S S L L A A p p p p l l i i c c a a t t i i o o n n It provides a secure and flexible solution fo r network resources, including VNC (Virtual Network Computer) /RDP (Remote Desktop Protoc ol) /SAMBA, to any remote user with access to Internet and a web browser.
Vigor3200 Series User’s Guide 298 this profile. Different application type will lead different web pages. Refer to the following: z Virtual Network Computing – Choose this item for accessing and controlling a rem ote PC through VNC protocol. IP Address - Type the IP address for this protocol.
Vigor3200 Series User’s Guide 299 z Samba Application - Any remote user can upload/download/delete certain files on a local samba server through web browser with this application Samba Path - Specify the path for this application. 4 4 . . 1 1 3 3 . .
Vigor3200 Series User’s Guide 300 However, if you have set several SSL Web Proxy Profiles in SSL VPN>> SSL Web Proxy web page: The SSL Web Proxy profile names will be disp layed (together with check box) as shown below.
Vigor3200 Series User’s Guide 301 4 4 . . 1 1 3 3 . . 5 5 U U s s e e r r G G r r o o u u p p There are 10 user group profiles which can be created for authentication by LDAP server. Such profiles will be used by applications such as User Manageme nt, VPN and etc.
Vigor3200 Series User’s Guide 302 Available settings are explained as follows: Item Description Enable Check this box to enable such profile. Group Name Type a name for such profile. Access Authority Specify the authority for such profile. Authentication Methods It can determine the authentication method used for such profile.
Vigor3200 Series User’s Guide 303 Next, users can open SSL VPN>> Online Status to view logging status of SSL VPN. Each item is explained as follows: Item Description Active User Display current user who visit SSL VPN server. Host IP Display the IP address for the host.
Vigor3200 Series User’s Guide 304 4 4 . . 1 1 4 4 U U S S B B A A p p p p l l i i c c a a t t i i o o n n USB diskette connected on Vigor router can be regarded as a server. By way of Vigor router, clients on LAN/WAN can access, write and read data stored in USB diskette with different applications.
Vigor3200 Series User’s Guide 305 Item Description Samba Service Settings Click Enable to invoke samba service via the router. Access Mode LAN Only – Users coming from internet cannot connect to the samba server of the router. LAN And WAN - Both LAN and WAN users can access samba server of the router.
Vigor3200 Series User’s Guide 306 Home Folder Display the home folder of this entry. Click index number to access into configuration page. Available settings are explained as follows: Item Description FTP/Samba User Enable – Click this button to activate this profile (account) for FTP service or Samba User service.
Vigor3200 Series User’s Guide 307 Item Description ON , you cannot type any new folder name in this field. Only “/” can be used in such case. You can click to open the following dialog to add any new folder which can be specified as the Home Folder.
Vigor3200 Series User’s Guide 308 4 4 . . 1 1 4 4 . . 3 3 F F i i l l e e E E x x p p l l o o r r e e r r File Explorer offers an easy way for users to review and manage the content of USB diskette connected on Vigor router. Available settings are explained as follows: Item Description Refresh Click this icon to refresh files list.
Vigor3200 Series User’s Guide 309 Each item is explained as follows: Item Description Connection Status If there is no USB storage disk connected to Vigor router, “ No Disk Connected ” will be shown here. Disk Capacity Display the total capacity of the USB storage disk.
Vigor3200 Series User’s Guide 310 Item Description Stop record when fulls – when the capacity of syslog is full, the system will stop recording. Always record the new event – only the newest events will be recorded by the system. Time Display the time of the event occurred.
Vigor3200 Series User’s Guide 311 4 4 . . 1 1 5 5 S S y y s s t t e e m m M M a a i i n n t t e e n n a a n n c c e e For the system setup, there are several items that you have to know the way of configuration: Status, Administrator Password, Configuration Backup, Syslog, Time setup, Reboot System, Firmware Upgrade.
Vigor3200 Series User’s Guide 312 Item Description Build Date/Time Display the date and time of the current firmware build. LAN MAC Address - Display the MAC address of the LAN Interface. IP Address - Display the IP address of the LAN interface. Subnet Mask - Display the subnet mask address of the LAN interface.
Vigor3200 Series User’s Guide 313 4 4 . . 1 1 5 5 . . 2 2 T T R R - - 0 0 6 6 9 9 This device supports TR-069 standard. It is very convenient for an administrator to m anage a TR-069 device through an Auto Configuration Server, e.
Vigor3200 Series User’s Guide 314 Item Description click Disable to close the mechanism of notification. STUN Settings The default is Disable . If you click Enable , please type the relational settings listed below: Server IP – Type the IP address of the STUN server.
Vigor3200 Series User’s Guide 315 4 4 . . 1 1 5 5 . . 4 4 U U s s e e r r P P a a s s s s w w o o r r d d Sometimes, you may want to access into User Mode to configure the web settings for some reason. Vigor router allows you to set new user password to login into the WUI t o fit your request.
Vigor3200 Series User’s Guide 316 3. The following screen will appear. Simply click OK . 4. Log out Vigor router Web Configurator. 5. The following window will be open to ask for username and password. Type the new user password in the filed of Password and click Login .
Vigor3200 Series User’s Guide 317 Settings to be configured in User Mode will be less than settings in Admin Mode. Only basic configuration settings will be available in User Mode. Setting in User Mode can be configured as same as in Admin Mode 4 4 .
Vigor3200 Series User’s Guide 318 Available settings are explained as follows: Item Description Enable Check this box to enable the login customization function. Login Description Type a brief description (e.g., Welcome to DrayTek) which will be shown on the heading of the login dialog.
Vigor3200 Series User’s Guide 319 4 4 . . 1 1 5 5 . . 6 6 C C o o n n f f i i g g u u r r a a t t i i o o n n B B a a c c k k u u p p B B a a c c k k u u p p t t h h e e C C o o n n f f i i g g u u r r a a t t i i o o n n Follow the steps below to backup your configuration .
Vigor3200 Series User’s Guide 320 4. Click Save button, the configuration will download a utomatically to your computer as a file named config.cfg . The above example is using W indows platform for demonstrating examples. The Mac or Linux platform will appear dif ferent windows, but the backup function is still available.
Vigor3200 Series User’s Guide 321 4 4 . . 1 1 5 5 . . 7 7 S S y y s s l l o o g g / / M M a a i i l l A A l l e e r r t t SysLog function is provided for users to monitor router. There is no bother to directly get into the Web Configurator of the router or borrow debug equipm ents.
Vigor3200 Series User’s Guide 322 Item Description Mail Alert Setup Check “ Enable ” to activate function of mail alert. Send a test e-mail Make a simple test for the e-mail address specified in this page. Please assign the mail address first and click this button to execute a test for verify the mail address is available or not.
Vigor3200 Series User’s Guide 323.
Vigor3200 Series User’s Guide 324 4 4 . . 1 1 5 5 . . 8 8 T T i i m m e e a a n n d d D D a a t t e e It allows you to specify where the time of the router should be inquired from. Available parameters are explained as follows: Item Description Current System Time Click Inquire Time to get the current time.
Vigor3200 Series User’s Guide 325 4 4 . . 1 1 5 5 . . 9 9 M M a a n n a a g g e e m m e e n n t t This page allows you to manage the setti ngs for access control, access list, port setup, and SMP setup. For example, as to management access control, the port number is used to send/receive SIP message for building a session.
Vigor3200 Series User’s Guide 326 Management Port Setup User Defined Ports - Check to specify user-defined port numbers for the Telnet, HTTP and FTP servers. Default Ports - Check to use standard port numbers for the Telnet and HTTP servers. SNMP Setup Enable SNMP Agent - Check it to enable this function.
Vigor3200 Series User’s Guide 327 4 4 . . 1 1 5 5 . . 1 1 1 1 F F i i r r m m w w a a r r e e U U p p g g r r a a d d e e Before upgrading your router firmware, you need to install the Router Tools. The Firmware Upgrade Utility is included in the tools.
Vigor3200 Series User’s Guide 328 4 4 . . 1 1 5 5 . . 1 1 2 2 A A c c t t i i v v a a t t i i o o n n There are three ways to activate WCF on vigor router, using Service Activation Wizard , by means of CSM>>Web Content Filter Profile or via System Maintenance>>Activation .
Vigor3200 Series User’s Guide 329 Below shows the successful activation of Web Content Filter: 4 4 . . 1 1 6 6 D D i i a a g g n n o o s s t t i i c c s s Diagnostic Tools provide a useful way to view or diagnose the status of your Vigor router. Below shows the menu items for Diagnostics.
Vigor3200 Series User’s Guide 330 4 4 . . 1 1 6 6 . . 1 1 D D i i a a l l - - o o u u t t T T r r i i g g g g e e r r Click Diagnostics and click Dial-out Trigger to open the web pag e. The internet connection (e.g., PPPoE) is triggered by a package sending from the source IP address.
Vigor3200 Series User’s Guide 331 4 4 . . 1 1 6 6 . . 3 3 A A R R P P C C a a c c h h e e T T a a b b l l e e Click Diagnostics and click ARP Cache Table to view the content of the ARP (Address Resolution Protocol) cache held in the router. Th e table shows a mapping between an Ethernet hardware address (MAC Address) and an IP address.
Vigor3200 Series User’s Guide 332 IP Address It displays the IP address assigned by this router for specified PC. MAC Address It displays the MAC address for the specified PC that DHCP assigned IP address for it. Leased Time It displays the leased time of the specified PC.
Vigor3200 Series User’s Guide 333 4 4 . . 1 1 6 6 . . 6 6 D D a a t t a a F F l l o o w w M M o o n n i i t t o o r r This page displays the running procedure for the IP address monitored and refreshes the data in an interval of several seconds. The IP address listed here is configured in Bandwidth Management.
Vigor3200 Series User’s Guide 334 Item Description automatically. Refresh Click this link to refr esh this page manually. Index Display the number of the data flow. IP Address Display the IP address of the monitored device. TX rate (kbps) Display the transmission speed of the monitored device.
Vigor3200 Series User’s Guide 335 4 4 . . 1 1 6 6 . . 7 7 T T r r a a f f f f i i c c G G r r a a p p h h Click Diagnostics and click Traffic Graph to open the web page. Choose WAN1/WAN2/WN3/WAN4/WAN5 Bandwidth, Sessions, daily or weekly for viewing different traffic graph.
Vigor3200 Series User’s Guide 336 4 4 . . 1 1 6 6 . . 8 8 P P i i n n g g D D i i a a g g n n o o s s i i s s Click Diagnostics and click Ping Diagnosis to pen the web page.
Vigor3200 Series User’s Guide 337 4 4 . . 1 1 6 6 . . 9 9 T T r r a a c c e e R R o o u u t t e e Click Diagnostics and click Trace Route to open the web page. This page allows you to trace the routes from router to the host. Simply type the IP address of the host in the box and click Run .
Vigor3200 Series User’s Guide 338 4 4 . . 1 1 7 7 E E x x t t e e r r n n a a l l D D e e v v i i c c e e s s Vigor router can be used to connect with many ty pes of external devices. In order to control or manage the external devices conveniently, open External Devices to make detailed configuration.
Vigor3200 Series User’s Guide 339 T T r r o o u u b b l l e e S S h h o o o o t t i i n n g g This section will guide you to solve abnormal s ituations if you cannot access into the Internet after installing the router and finishing the we b configuration.
Vigor3200 Series User’s Guide 340 5 5 . . 2 2 C C h h e e c c k k i i n n g g I I f f t t h h e e N N e e t t w w o o r r k k C C o o n n n n e e c c t t i i o o n n S S e e t t t t i i n n g g s s .
Vigor3200 Series User’s Guide 341 4. Select Obtain an IP address automatically and Obtain DNS server address automatically . F F o o r r M M a a c c O O S S 1. Double click on the current used Mac OS on the desktop. 2. Open the Application folder and get into Network .
Vigor3200 Series User’s Guide 342 5 5 . . 3 3 P P i i n n g g i i n n g g t t h h e e R R o o u u t t e e r r f f r r o o m m Y Y o o u u r r C C o o m m p p u u t t e e r r The default gateway IP address of the router is 192.168.1.1. For some reason, you might need to use “ping” command to check the link status of the router.
Vigor3200 Series User’s Guide 343 5 5 . . 4 4 C C h h e e c c k k i i n n g g I I f f t t h h e e I I S S P P S S e e t t t t i i n n g g s s a a r r e e O O K K o o r r N N o o t t Open WAN >> Internet Access page and then check whether the ISP settings are set correctly.
Vigor3200 Series User’s Guide 344 5 5 . . 5 5 P P r r o o b b l l e e m m s s f f o o r r 3 3 G G N N e e t t w w o o r r k k C C o o n n n n e e c c t t i i o o n n When you have trouble in using 3.
Vigor3200 Series User’s Guide 345 S S o o f f t t w w a a r r e e R R e e s s e e t t You can reset the router to factory default via Web page. Such function is available in Admin Mode only. Go to System Maintenance and choose Reboot System on the web page.
Vigor3200 Series User’s Guide 346 5 5 . . 7 7 C C o o n n t t a a c c t t i i n n g g Y Y o o u u r r D D e e a a l l e e r r If the router still cannot work correctly after trying many efforts, please contact your dealer for further help right away.
Un punto importante, dopo l’acquisto del dispositivo (o anche prima di acquisto) è quello di leggere il manuale. Dobbiamo farlo per diversi motivi semplici:
Se non hai ancora comprato il Draytek Vigor3200 è un buon momento per familiarizzare con i dati di base del prodotto. Prime consultare le pagine iniziali del manuale d’uso, che si trova al di sopra. Dovresti trovare lì i dati tecnici più importanti del Draytek Vigor3200 - in questo modo è possibile verificare se l’apparecchio soddisfa le tue esigenze. Esplorando le pagine segenti del manuali d’uso Draytek Vigor3200 imparerai tutte le caratteristiche del prodotto e le informazioni sul suo funzionamento. Le informazioni sul Draytek Vigor3200 ti aiuteranno sicuramente a prendere una decisione relativa all’acquisto.
In una situazione in cui hai già il Draytek Vigor3200, ma non hai ancora letto il manuale d’uso, dovresti farlo per le ragioni sopra descritte. Saprai quindi se hai correttamente usato le funzioni disponibili, e se hai commesso errori che possono ridurre la durata di vita del Draytek Vigor3200.
Tuttavia, uno dei ruoli più importanti per l’utente svolti dal manuale d’uso è quello di aiutare a risolvere i problemi con il Draytek Vigor3200. Quasi sempre, ci troverai Troubleshooting, cioè i guasti più frequenti e malfunzionamenti del dispositivo Draytek Vigor3200 insieme con le istruzioni su come risolverli. Anche se non si riesci a risolvere il problema, il manuale d’uso ti mostrerà il percorso di ulteriori procedimenti – il contatto con il centro servizio clienti o il servizio più vicino.