Manuale d’uso / di manutenzione del prodotto BEFSX41 del fabbricante Linksys
Vai alla pagina of 75
Instant Broadband ® Series EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Use this guide to install: BEFSX41 User Guide.
COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. Copyright © 2003 Linksys, All Rights Reserved. EtherFast, Instant Broadband, Linksys, and the Linksys logo ar e register ed trademarks of Linksys Group, Inc. Micr osoft, Windows, and the Windows logo are r eg- istered trademarks of Micr osoft Corporation.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint VPN 38 Pass w ord 51 Status 53 DHCP 55 Log 57 Help 59 Advanced 60 Filters 61 F orwarding 65 Dynamic Routing 70 Static Routing 71 .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 1 Chapter 1: Introduction The Linksys EtherFast ® Cable/DSL Router The Linksys Instant Broadband EtherF ast Cable/DSL F irew all.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 3 Instant Broadband ® Series 2 Dynamic IP Addresses A d ynamic IP addr ess is automatically assigned to a de vice on the netw ork, such as PCs and print servers. These IP addresses are called “dynamic” because they are onl y tempor arily assigned to the PC or device.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Chapter 2: Y our Virtual Private Network (VPN) Computer netw orking pro vides a flexibility not a v ailable w hen using an archa- ic, paper-based system. With this fle xibility , how ever , comes an increased risk in security .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint There are tw o basic w a ys to create a VPN connection: • Fire w all Router to Fire wall Router • Computer (using VPN client .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 9 Chapter 3: Getting to Know the EtherFast Cable/DSL Firewall Router The Router’ s ports, sho wn in Figure 3-1, are w here netw ork cables are con- nected WA N The WA N (W ide Area Netw ork) port is where you connect your cab le or DSL modem through an Ethernet cable.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 11 Instant Broadband ® Series 10 W AN and LAN LEDs Link/Act Gr een . The Link/Act LED serves tw o pur poses. If the LED is con- tinuously lit, the Router is successfull y connected to a device through the cor responding port (1, 2, 3 or 4/DMZ).
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 13 Instant Broadband ® Series 12 Repeat the abo v e step to connect more PCs or netw ork de vices to the Router . 3. Connect the Ether net cab le from your cab le or DSL modem to the WA N por t on the Router’ s back panel, as sho wn in F igure 4-3.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 1. Go to the Netw ork screen b y clicking the Start button. Click Settings and then Contr ol P anel . From there, double-click the Netw or k icon. 2. On the Conf iguration tab, shown in F igure 5-1, select the TCP/IP line for the applicable Ethernet adapter .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 1. Go to the Netw ork screen b y clicking the Start button. Click Settings and then Contr ol P anel .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint The follo wing instructions assume you are running W indo ws XP with the default interface. If you are using the Classic interface (where the icons and menus look like pre vious W indo ws versions), please follo w the instructions for W indo ws 2000.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 21 Instant Broadband ® Series 3. Select Internet Pr otocol (TCP/IP) , as sho wn in F igure 5-7, and click the Pr operties button.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Obtain an IP Addr ess A utomaticall y If your ISP sa ys that you are connecting through DHCP or a dynamic IP address from y our ISP , perfor m these steps: A . Select Obtain an IP A utomatically as the W AN Connection T ype.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint PPTP PPTP is a service used in Europe only . (Shown in F igure 6-8.) If you are using a PPTP connec- tion, check with your ISP for the necessary setup infor mation. When you are f inished with the Setup tab, proceed to step 5.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Chapter 7: The Cable/DSL Firewall Router’ s W eb-based Utility F or your con venience, use the Router’ s web-based utility to administer it. This chapter will explain all of the functions in this utility .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint • Device IP Addr ess and Subnet Mask The values for the Router’ s IP Address and Subnet Mask are sho wn here. The default values are 192.168.1.1 for the Device IP Address and 255.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 31 Instant Broadband ® Series 30 PPP oE Some DSL-based ISPs use PPP oE (P oint-to-P oint Protocol o v er Ethernet) to establish Internet connections for end-users. If you are connected to the Internet through a DSL line, check with your ISP to see if they use PPP oE.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 33 Instant Broadband ® Series 32 PPTP P oint to P oint T unneling Protocol (PPTP) is a service that applies to connec- tions in Europe only .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 35 Instant Broadband ® Series HBS The HeartBeat Signal (HBS) is a service that applies to connec- tions in Australia only . (Shown in Figure 7-9.) F or users in Australia, check with your ISP for setup informa- tion.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint PPTP P ass Through • P oint-to-P oint T unneling Protocol Pass Through is the method used to enable VPN sessions to a W indo ws NT 4.0 or 2000 ser ver . PPTP Pass Through is enabled b y default.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint V irtual Priv ate Netw orking (VPN) is a security measure that basically creates a secure connection betw een tw o remote locations. This connection is very specif ic as f ar as its settings are concerned; this is what creates the security .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 41 40 • IP Address - If you select IP Addr ess , onl y the computer with the spe- cif ic IP Address that you enter will be ab le to access the tunnel. In the example sho wn in Figure 7-13, onl y the computer with IP Address 192.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 43 42 Remote Security Gatew a y The Remote Security Gatew ay is the VPN device, such as a second F ire w all Router , on the remote end of the VPN tunnel. Under Remote Security Gatew a y , you ha ve three options: IP Address, FQDN , and Any .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Ke y Management In order for any encryption to occur , the tw o ends of the tunnel must ag ree on the type of encryption and the wa y the data will be decrypted. This is done b y sharing a “key” to the encryption code.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 47 46 On the VPN screen, the word Connected should appear beside Status if the connection is successful. The other f ields reflect the information that you entered on the VPN screen to make the connection.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 49 48 Encryption Select the length of the key used to encrypt/decrypt ESP packets. There are tw o choices: DES and 3DES. 3DES is recommended because it is more secure. A uthentication Select the method used to authenticate ESP packets.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 51 Phase 2 Group There are tw o Dif f ie-Hellman Groups to choose from: 768-bit and 1024-bit. Diff ie-Hellman refers to a cryptographic technique that uses public and pri v ate keys for encryption and decryption.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 53 Do not restore the factor y defaults unless you are ha ving diff iculties with the Router and ha ve e xhausted all other troubleshooting measures. Once the Router is reset, you will ha ve to re-enter all of your conf iguration data.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint From the DHCP screen, sho wn in Figure 7-28, y ou can conf igure the Router as a DHCP Server . A Dynamic Host Conf iguration Protocol (DHCP) server automaticall y assigns an IP address to each PC on your netw ork for you.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint The Log tab, sho wn in Figure 7-29, pro vides you with a lo g of all incoming and outgoing URLs or IP addresses for your Internet connection. T o access activity lo gs, select the Ena b le option next to Lo g.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 59 From the drop-do wn menu, select the log y ou wish to vie w: All (to view all logs), System Lo g, Access Lo g, Fire w all Lo g, or VPN Log.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint The Filters screen, sho wn in Figure 7-33, allo ws y ou to b lock or allo w specif ic kinds of Internet usage. Y ou can set up Inter net access policies for specif ic PCs. Internet Access P olicy Multiple f ilters can be sa ved as Internet Access P olicies.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 5. T o block w ebsites with specif ic URL addresses, enter each URL address in a W ebsite Blocking by URL Addr ess f ield.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 65 From the F orwarding tab, sho wn in Figure 7-37, y ou can set up public services on your netw ork, such as web servers, ftp servers, e-mail servers, or other spe- cialized Internet applications.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 67 66 • T elnet A terminal emulation protocol commonly used on Internet and TCP/IP-based net- w orks. It allo ws a user at a terminal or computer to log onto a remote device and run a program.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 69 68 5. Enter the IP address of the server that you w ant the Internet users to be able to access. T o f ind the IP address, go to “ Appendix G: Finding the MA C Address and IP Address for Y our Ether net Adapter .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 71 70 If the Router is connected to more than one netw ork, it ma y be necessary to set up a static route betw een them. This can be done from the Static Routing screen, sho wn in F igure 7-41.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 73 72 From the DMZ Host tab, sho wn in Figure 7-42, y ou can set P ort 4/DMZ to DMZ or LAN connection. Any user on the Internet can access incoming or out- going data from the DMZ host without the use of f irew all protection.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 75 Specify an IP Addr ess behind the DMZ P ort: If you ha ve multiple PCs connected to P ort 4/DMZ via a hub or switch, y ou can specify which PC is the DMZ host. T o expose a computer with a specif ic IP address, enter that computer’ s IP address in this f ield.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint DynDNS.org T o order DynDNS ser vice, click the appropriate link at the top of the DDNS screen. Username , Pass w ord , and Host Name Enter the Username, Passw ord , and Host Name of the account you set up with DynDNS.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 79 Instant Broadband ® Series TZO.com T o sign up for a free, 30-day trial of TZO ser vice, order TZO service, or man- age your TZO service, click the appropriate link at the top of the DDNS screen.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 81 Instant Broadband ® Series F or W indo ws 2000: A. Click Start , Settings , and Control P anel .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 83 Instant Broadband ® Series 82 C. In the command prompt, type ping 192.168.1.1 and press the Enter key . • If you get a repl y , the computer is communicating with the Router .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Y our VPN ma y require por t 500/UDP packets to be passed to the computer that is connecting to the IPSec server . Refer to “Problem #7, I need to set up online game hosting or use other Internet applications” for details.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 8. I can’t get the Internet game, ser ver , or application to work. If you are ha ving diff iculties getting an y Internet game, ser v er , or application to function properly , consider exposing one PC to the Inter net using DeMilitarized Zone (DMZ) hosting.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 13. The fir mware upgrade failed, and/or the Diag LED is flashing. The upgrade could hav e failed for a number of reasons. F ollo w these steps to upgrade the f irmware and/or make the Diag LED stop flashing: A.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 17. The Diag LED stays lit continuously . The Diag LED lights up when the de vice is f irst po w ered up.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 93 Instant Broadband ® Series 92 I set up an Unreal T our nament Server , but others on the LAN cannot join.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 95 Instant Broadband ® Series 94 Does the Router replace a modem? Is there a cable or DSL modem in the Router? No, this version of the Router must w ork in conjunction with a cable or DSL modem.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 97 Instant Broadband ® Series 96 As secure as the Fire w all Router makes y our data, there are still more w a ys to maximize security . The follo wing are a fe w suggestions on ho w to increase data security bey ond the F irew all Router .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 99 Instant Broadband ® Series 98 1. Click the Start button, select Run , and type secpol.msc in the Open f ield. The Local Security Setting screen will appear as sho wn in F igure C-1.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 101 Instant Broadband ® Series 100 3. The IP F ilter List screen should appear , as sho wn in F igure C-4. Enter an appropriate name, such as win->r outer , for the f ilter list, and de-select the Use Add Wizar d check box.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 103 Instant Broadband ® Series 102 8. The IP F ilter List screen should appear , as sho wn in F igure C-7. Enter an appropriate name, such as r outer ->win for the f ilter list, and de-select the Use Add Wizar d check box.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 105 Instant Broadband ® Series 104 T unnel 1: win->r outer 1. F rom the IP F ilter List tab, sho wn in F igure C- 10, click the f ilter list win->r outer . 2. Click the Filter Action tab (as in Figure C-11), and click the f ilter action Requir e Security radio button.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 107 Instant Broadband ® Series 106 5. Change the authentica- tion method to Use this string to pr otect the ke y e xchange (pr e- shar ed ke y) , as sho wn in Figure C-14, and enter the preshared key string, such as XYZ12345 .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 109 Instant Broadband ® Series 108 T unnel 2: r outer ->win 9. In the screen, sho wn in Figure C-18, mak e sure that “win -> router” is select and deselect the Use Add Wizar d check box.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 111 Instant Broadband ® Series 110 13. Change the authenti- cation method to Use this string to pr otect the ke y e xchange (pr eshar ed ke y) , and enter the preshared key string, such as XYZ12345 , as sho wn in F igure C- 22.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 113 Instant Broadband ® Series 112 17. F rom the Rules tab, sho wn in F igure C- 26, click the Close button to return to the secpol screen.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 115 Instant Broadband ® Series 114 8. Select IP Ad dr . from the pull-do wn menu beside Remote Security Gatew ay . This w ould be the IP Address of your Internet connection as seen from the Internet.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 117 Instant Broadband ® Series Appendix D: SNMP Functions SNMP ( S imple N etw ork M anagement P rotocol) is a widel y-used netw ork monitoring and control protocol.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 119 Instant Broadband ® Series 118 Step T wo: Pinging for a Web Addr ess While the IP address returned abo v e w ould work as y our e-mail server address, it ma y not be permanent.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 6. Find and double-click TCP/IP in the list to the right (see Figure F-2). 7. After a few seconds, the main Netw ork windo w will appear . The TCP/IP Protocol should no w be listed.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 3. Write do wn the Adapter Address as shown on y our computer screen (see Figure G-3). This is the MA C address for y our Ethernet adapter and will be sho wn as a series of numbers and letters.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint When entering information for MAC Address Cloning, type the 12-digit MA C addr ess (see F igure G-6). 125 Instant Broadband ® Series 2. In the command prompt, enter ipconf ig /all .
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Cab le Modem - A device that connects a computer to the cable tele vision net- w ork, w hich in turn connects to the Inter net. Once connected , cable modem users ha ve a continuous connection to the Internet.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint emplo ying unused bandwidth, still allo ws for nor mal phone usage. DSL pro- vides "al w a ys-on" operation, eliminating the need to dial in to the service.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Hub - The device that serves as the central location for attaching wires from w orkstations.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Multicasting - Sending data to a group of nodes instead of a single destination. NA T ( N etw ork A ddress T ranslation) - The translation of an Internet Protocol address (IP address) used within one netw ork to a dif ferent IP address kno wn within another netw ork.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint RIP ( R outing I nformation P rotocol) - A simple routing protocol that is par t of the TCP/IP protocol suite. It determines a route based on the smallest hop count betw een source and destination.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint TFTP ( T rivial F ile T ransfer P rotocol) - A version of the TCP/IP FTP protocol that has no directory or passw ord capability . Thr oughput - The amount of data mov ed successfull y from one place to another in a giv en time period.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 139 Appendix I: Specifications Model Number BEFSX41 Standards IEEE 802.3, IEEE 802.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Appendix K: Contact Information F or help with the installation or operation of the EtherF ast Cab le/DSL F irew all Router , contact Linksys T echnical Suppor t at one of the phone numbers or Internet addresses below .
© Copyright 2003 Linksys, All Rights Reserved. www .linksys.com.
Un punto importante, dopo l’acquisto del dispositivo (o anche prima di acquisto) è quello di leggere il manuale. Dobbiamo farlo per diversi motivi semplici:
Se non hai ancora comprato il Linksys BEFSX41 è un buon momento per familiarizzare con i dati di base del prodotto. Prime consultare le pagine iniziali del manuale d’uso, che si trova al di sopra. Dovresti trovare lì i dati tecnici più importanti del Linksys BEFSX41 - in questo modo è possibile verificare se l’apparecchio soddisfa le tue esigenze. Esplorando le pagine segenti del manuali d’uso Linksys BEFSX41 imparerai tutte le caratteristiche del prodotto e le informazioni sul suo funzionamento. Le informazioni sul Linksys BEFSX41 ti aiuteranno sicuramente a prendere una decisione relativa all’acquisto.
In una situazione in cui hai già il Linksys BEFSX41, ma non hai ancora letto il manuale d’uso, dovresti farlo per le ragioni sopra descritte. Saprai quindi se hai correttamente usato le funzioni disponibili, e se hai commesso errori che possono ridurre la durata di vita del Linksys BEFSX41.
Tuttavia, uno dei ruoli più importanti per l’utente svolti dal manuale d’uso è quello di aiutare a risolvere i problemi con il Linksys BEFSX41. Quasi sempre, ci troverai Troubleshooting, cioè i guasti più frequenti e malfunzionamenti del dispositivo Linksys BEFSX41 insieme con le istruzioni su come risolverli. Anche se non si riesci a risolvere il problema, il manuale d’uso ti mostrerà il percorso di ulteriori procedimenti – il contatto con il centro servizio clienti o il servizio più vicino.