Manuale d’uso / di manutenzione del prodotto RV120W del fabbricante Cisco
Vai alla pagina of 163
Cis c o Small Busine s s RV 120W W ir ele ss-N VPN Fi rewall ADMINISTR A TION GUIDE.
© 2011 Cisco Syst ems, Inc. All rights r es er ved. 78- 19307 -02 Revised June 2011 Cisco and th e Cisco Logo are tradem arks of Cisco Sy stems, I nc. and /or its a ffilia tes in th e U.S. and other count ries. A l isting of C isco' s tradem arks can be found at www .
Cisco RV 120W A dministration Guide 1 Co n t e n ts Chapter 1: Introduction 1 Product Overview 1 LAN Ethernet In terfaces 2 Wireless Access Point 2 Firewall and V PN Client Access 2 Wireless Distribut.
Cisco RV 120W A dministration Guide 2 Co n t e n ts Chapter 2: Configuring Network ing 19 Configuring the WAN (I nt ernet) Sett ings 19 Configu r ing the I Pv4 WAN (Internet) 20 Configuring Automatic .
Cisco RV 120W A dministration Guide 3 Co n t e n ts Configuring IPv6 42 Configuring the IP Mode 42 Configuring IPv6 WAN Se ttings 42 Configuring DHCPv6 42 Configuring a Static IP Address 43 Configurin.
Cisco RV 120W A dministration Guide 4 Co n t e n ts Chapter 4: Conf iguring the Firewa ll 65 Cisco RV120W Firewall Features 65 Configuring Access Rule s 67 Configuring the D efault Outb ound Policy 67.
Cisco RV 120W A dministration Guide 5 Co n t e n ts Configuring a B asic VPN 93 Viewing t he Default VPN Settings 94 Configuring Ad vanced VPN Parameters 94 Configuring IKE Policies 95 Configuring VPN.
Cisco RV 120W A dministration Guide 6 Co n t e n ts Configuring Netw ork Management 121 Configuring SNMP 121 Editing SNMPv3 Users 121 Adding SNMP Traps 122 Configuring Access Control Rules 122 Configu.
Cisco RV 120W A dministration Guide 7 Co n t e n ts Viewing Logs 145 Viewing Av ailable L AN Hosts 146 Viewing Port Triggering Status 147 Viewing Po rt St atis tics 148 Viewing Open Ports 149 Appendix.
1 Cisco RV 120W A dministration Guide 1 In tro duction This chapt er de scribes the fea tures of the Cisco RV 120W , guides you t hrough the installation pr oc es s , and gets you star ted using the Device Manager , a br owser - base d utility f or configuring the Cisco RV 120W.
In tro duction Pro duct O ve r view Cisco RV 120W Administration Guide 2 1 LA N E t h e r n e t I n t e rf a ce s The Cisco RV 120W provi des f our full- duple x 10/ 100 Ethernet LAN interfaces that can connect up t o f our devices . Wirele s s A c c e s s Point The wir eles s acc es s point suppor ts the 802.
In tro duction Pro duct O ve r view Cisco RV 120W Administration Guide 3 1 Secur ity The Cisco RV 120W implements WP A 2-PS K , WP A 2-ENT , and WEP encr yption, along with other securit y f eatures including the disabling of S SID b roadcasts, MAC-based filtering, and al lowing or denying “time of day” ac ces s p er S S ID .
In tro duction Ge tting to Know t he Cisco RV 120W Cisco RV 120W Administration Guide 4 1 The Cisco RV 120W also provi d es a setup wizard. The s etup wizar d allows y ou to easily configur e the Cisc o RV 120W’ s b asic settings .
In tro duction Ge tting to Know t he Cisco RV 120W Cisco RV 120W Administration Guide 5 1 Ba c k P an el RESET But ton — The Reset button has two function s : • If the Cisco RV 120W is ha ving pro.
In tro duction Moun ting the Cisc o RV 12 0W Cisco RV 120W Administration Guide 6 1 Moun ting the Cisc o R V 120W Y ou can place your Cisco RV 120W on a desktop or mount i t on a w all.
In tro duction Moun ting the Cisc o RV 12 0W Cisco RV 120W Administration Guide 7 1 STEP 3 Place the wall -mount slots over the scr ews and slide the device down until the screw s fit snugly int o the wall-mount slots .
In tro duction Connecting the Equipm ent Cisco RV 120W Administration Guide 8 1 C onn e c ting th e Equipment Bef or e you begin t he installation, make sur e that y ou ha ve the f ollowing equipment and se r vi ce s : Require d • Functional Internet Connection (Br o adband DS L or cable modem).
In tro duction Connecting the Equipm ent Cisco RV 120W Administration Guide 9 1 T o c onne ct yo ur firewall to the In ternet : STEP 1 Power off all equipment, including the cable or DS L modem, the P C you will use t o connect to the RV 120W, and the RV 120W.
In tro duction Connecting the Equipm ent Cisco RV 120W Administration Guide 10 1 STEP 3 Connect one end of a d iff erent Ethernet ca ble to one o f the L AN (Ethernet) ports on the back of the RV 120W. (In this example, the L AN 2 por t is us ed.) Conne ct the other end of the cable to an Ethernet port on the P C.
In tro duction Connecting the Equipm ent Cisco RV 120W Administration Guide 11 1 STEP 5 Connect the po wer adapte r to the Cisco RV 120W power po r t ( 12V DC) . ! CAU T IO N Use only the power adapter that is supplie d with the device. Using a diff erent powe r ada pt er cou ld da mage the de vice.
In tro duction Setting Up the Cis co RV 12 0 W Using the S etup W iz ard Cisco RV 120W Administration Guide 12 1 STEP 7 On the Cisco RV 120W, push in the ON/OFF power button. The power light on the fr ont panel is gr een when the power adapter is connected pr op erly and the unit is t urne d on.
In tro duction Using the Ge t ting Star ted Page Cisco RV 120W Administration Guide 13 1 STEP 4 Click Log In . The Setup Wizar d star ts . STEP 5 F ollow the Setup Wi z ard ’s on-s cr e en instruction s to set up the RV 120W. The Setup Wi zard tries t o aut omatically det ect and configure y our connection.
In tro duction Using the Ge t ting Star ted Page Cisco RV 120W Administration Guide 14 1 Initial Set tings Quick A c c e s s Run S e tup W izard Click th is link to la unch the Setup Wizar d. Configure W AN (Inter net ) S et ti ngs Click th is link to open the In ternet Setup page.
In tro duction Na viga ting thro ugh the P ages Cisco RV 120W Administration Guide 15 1 D evic e Status Oth er Reso ur ces Na viga ting thr ough the Page s Use the nav igation tree in the left pane t o op en the configuratio n page s. Dashbo ard Click th is link to open the Da shb o ard pag e.
In tro duction Na viga ting thro ugh the P ages Cisco RV 120W Administration Guide 16 1 Click a menu item on the left panel to ex pand it . Click the men u names displa ye d underneath t o per f orm an action or view a sub-menu.
In tro duction Sa ving Y our Changes Cisco RV 120W Administration Guide 17 1 S a ving Y our Changes When you finish making changes on a configuration page, click Sa ve to s ave t h e changes , or click Cancel to u ndo your cha nge s.
In tro duction V iewi ng the He lp Fil e s Cisco RV 120W Administration Guide 18 1 Viewing the H elp File s T o v iew m ore inf o rmat ion abo ut a c onf igur ati on pa ge, cl ick th e Help link nea r the to p right co rner of the page.
2 Cisco RV 120W Administration Guide 19 C onfiguring Net working The networking page allows y ou to configur e networking set tings. This chapter contains the f ollowing se ctions: • Configuring the.
C onf igu rin g N et w or kin g Configu ring the W AN (Int ernet) Settings Cisco RV 120W Administration Guide 20 2 C onfig urin g the IP v4 W AN (Inter net) STEP 1 Ch oose Netw orking > W AN (Int ernet) > IPV 4 W AN (Int ernet) . STEP 2 Choos e the type of Int ernet connection y ou hav e.
C onf igu rin g N et w or kin g Configu ring the W AN (Int ernet) Settings Cisco RV 120W Administration Guide 21 2 Configuring Static IP If your IS P as signed you a permanent IP addr es s , per f orm the f o llowing st ep s t o conf igure your W AN se t tings : STEP 1 Ch oose Net working > W AN (Interne t) > IP v4 WA N (Intern et) .
C onf igu rin g N et w or kin g Configu ring the W AN (Int ernet) Settings Cisco RV 120W Administration Guide 22 2 STEP 5 Ent er MAC Address inf orm ation.
C onf igu rin g N et w or kin g Configu ring the W AN (Int ernet) Settings Cisco RV 120W Administration Guide 23 2 STEP 5 Ent er MAC Address inf orm ation.
C onf igu rin g N et w or kin g Configu ring the W AN (Int ernet) Settings Cisco RV 120W Administration Guide 24 2 STEP 5 Ent er MAC Address inf orm ation.
C onf igu rin g N et w or kin g Configu ring the W AN (Int ernet) Settings Cisco RV 120W Administration Guide 25 2 T o configure the MAC addr e s s set tings : STEP 1 Ch oose Net working > W AN (Interne t) > IP v4 WA N (Intern et) .
C onf igu rin g N et w or kin g Configu ring the W AN (Int ernet) Settings Cisco RV 120W Administration Guide 26 2 STEP 4 Click Sa ve . The pr ofile is added to the Pr ofile T able . T o edi t a PP Po E pr of ile l ist ed in t he Pr ofile T able , sele ct the pr ofile and click Edit .
C onf igu rin g N et w or kin g Configu ring the L AN (Local Network) Settings Cisco RV 120W Administration Guide 27 2 C onfi gurin g the L AN (Lo c al Net w ork) S et tin gs If yo u have a n IP v 4 netw ork , use these se ctions t o configur e your LAN set tings.
C onf igu rin g N et w or kin g Configu ring the L AN (Local Network) Settings Cisco RV 120W Administration Guide 28 2 T o configure the IP address of the Cisc o RV 120W: STEP 1 Ch oose Net working > LA N (Loc al N et wo rk ) > IP v4 L AN (Lo cal Net work) .
C onf igu rin g N et w or kin g Configu ring the L AN (Local Network) Settings Cisco RV 120W Administration Guide 29 2 F or most applications, the def ault DHCP settings are satisf actory .
C onf igu rin g N et w or kin g Configu ring the L AN (Local Network) Settings Cisco RV 120W Administration Guide 30 2 T o configure the DNS pro x y ser ver f o r the Cisco RV 120W: STEP 1 Ch oose Net working > LA N (Loc al N et wo rk ) > IP v4 L AN (Lo cal Net work) .
C onf igu rin g N et w or kin g Configu ring the L AN (Local Network) Settings Cisco RV 120W Administration Guide 31 2 STEP 4 Enter a description f or the VL AN. STEP 5 T o enable r outing bet ween this and other VLANS, che ck the Inter VL AN Routing bo x.
C onf igu rin g N et w or kin g Configu ring the L AN (Local Network) Settings Cisco RV 120W Administration Guide 32 2 If you want t o edit the DHCP behavior of this V L AN: a. In the DHCP Section, in the DHCP Mode field, choose one of the f ollowing: • DHCP Ser ver —Choo se this to a llow the VLAN to act as the DH CP ser ver in the network .
C onf igu rin g N et w or kin g Configu ring the L AN (Local Network) Settings Cisco RV 120W Administration Guide 33 2 STEP 4 Ent er the MAC address of the device. The f ormat f or the MAC Address is XX :X X :X X:X X :X X:X X where X is a number from 0 to 9 (inclu sive) or an alphabetical lette r between A and F (i nclusive ) .
C onf igu rin g N et w or kin g Configuring Routing Cisco RV 120W Administration Guide 34 2 Adding a DHCP Clien t to C onfigura tion File Ma p This table displa ys the list of currently confi gured DHCP Client MAC addr es s to co nfig ura tion fil enam e ma pp ings .
C onf igu rin g N et w or kin g Configuring Routing Cisco RV 120W Administration Guide 35 2 The other r outing mode, “rout er ,” is used if your ISP has assigne d you m ultiple IP address es s o that you hav e an IP address for each endpoint on your n etw ork .
C onf igu rin g N et w or kin g Configuring Routing Cisco RV 120W Administration Guide 36 2 - Ga te way — U s e g a te w ay . - R—R e i n s t a te ro u te fo r d y n a m i c ro u t i n g . - D— Dynamically installed by daemon or r e direct . - M—Modified from r outing daemon or r edirect .
C onf igu rin g N et w or kin g Configuring Routing Cisco RV 120W Administration Guide 37 2 • Me tric — The dist ance to the t arg et (u sual ly cou nt ed in hops ). • Ref —Number of ref erences t o this rout e. • Use—Count of lookups f or the rout e.
C onf igu rin g N et w or kin g Configuring Routing Cisco RV 120W Administration Guide 38 2 STEP 7 In the IP Subnet Mask fi eld, enter the IPv 4 Subnet Mask f or the destination host or network . F or Clas s C IP domains, the Subnet Mask is 255.255.255 .
C onf igu rin g N et w or kin g Configuring Routing Cisco RV 120W Administration Guide 39 2 • Out On ly — The firewall b r o adcasts its r outing table periodically but does not accept RIP inf ormation from other r outers.
C onf igu rin g N et w or kin g Configuring P or t Management Cisco RV 120W Administration Guide 40 2 C onfigur ing P or t Man agement The Cisco RV 120W has f our L AN por t s. Y ou can enabl e or dis able por ts, c onfigur e if the port is half- or full-duplex, and set the por t spee d.
C onf igu rin g N et w or kin g Configuring Dy namic DNS ( DDNS) Cisco RV 120W Administration Guide 41 2 T o c onf igure D DN S: STEP 1 Ch oose Netw orking > Dynamic DNS . STEP 2 Select the Dynamic DNS Ser vice you ar e using. Selecting None dis ables this service.
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 42 2 Con f ig ur i ng IP v6 If you ha ve an IPv6 net work , see the f ollowing sections . C onfig urin g th e IP M o de T o configure IP v6 properties on the Cisco RV 120W, set the IP mode to IPv6: STEP 1 Ch oose Netw orking > IP v6 > IP Mode .
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 43 2 Configuring a Static IP A ddress If your IS P as signs you a fi xed addres s t o ac ces s the Intern et , cho ose this option. The inf ormation neede d f or configuring a static IP address can be obtaine d fr om you r IS P .
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 44 2 in the network hav e the identical initi al bits f or their IP v6 address ; the number of common initial bit s in the net work's addr es s es is set by the prefi x length fiel d.
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 45 2 Configuring IP v 6 Ad dres s Pools This f eature allows you to define t he IP v6 delegation pr efix f or a range of IP addr e s ses to be ser ved by the Cisco RV 120W’s DHCPv6 ser ver .
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 46 2 T o c onf igure R IPng : STEP 1 Sel ect Networking > IP v6 > Routi ng . STEP 2 Under RIPng , check Enable . STEP 3 Click Sa ve . C onfig urin g St atic Rout ing Y ou can configure static rout es to dir ect packets to the destinatio n net work .
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 47 2 • 6 to 4 T unnel —Uses the tunnel in terface to r out e traf fic fr om an IP v6 net work to other IP v6 net works over an IPv4 network . STEP 8 Ent er the IP Address of the gatewa y thr ough which the destination host or network can be r eached .
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 48 2 Configuring Intr a-Site Automatic T unnel A ddr e s sing Protocol (ISA T AP) Tu n n e l s Intra-sit e automat ic tunnel addr e s sing pr otocol (IS A T A P) is a method t o transmit IP v6 pack ets b etween dual-stack nodes over an IP v 4 network .
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 49 2 T o delet e an IS A T AP tunnel: STEP 1 Ch oose Netw orking > IP v6 > Tu n n e l i n g . STEP 2 Check the check boxes f or the tunnels y ou want to delet e.
C onf igu rin g N et w or kin g Configu ring IP v6 Cisco RV 120W Administration Guide 50 2 that do not i mplement rout er pr ef erence. This f eature is us eful if t here ar e other R ADVD-enabled device s on the LAN. The default is high. STEP 7 Ent er the MTU size.
3 Cisco RV 120W Administration Guide 51 C onfiguring the Wirele s s Net work This chapt er describes how t o c onfigur e your wireless network and incl ude s the f ollowing sections: • A Note About .
C onf ig urin g the Wi rele s s N et w ork A Note About Wir ele ss S e curit y Cisco RV 120W Administration Guide 52 3 Wire le s s S e curit y Tip s Since you ca nnot physical ly prev ent some one fro.
C onf ig urin g the Wi rele s s N et w ork A Note About Wir ele ss S e curit y Cisco RV 120W Administration Guide 53 3 • Enable encryption Encr yption pr otects data transmitt e d over a wir eles s network .
C onf ig urin g the Wi rele s s N et w ork Und erstanding the Cisc o RV 120W’ s W irel e ss Netwo rks Cisco RV 120W Administration Guide 54 3 Understanding the Cisc o R V 120W’ s Wir ele s s Net works The Cisco Small Business RV 120W Wir eles s-N VPN F irewall provides f our separate v ir tual wirel e s s networks .
C onf ig urin g the Wi rele s s N et w ork Configuring Basic W i reless Settings Cisco RV 120W Administration Guide 55 3 signal components above the carrier frequency constitu te the upper sideband (USB) and tho se below the carrier fr equency constitut e the lower sideband (L S B) .
C onf ig urin g the Wi rele s s N et w ork Configuring Basic W i reless Settings Cisco RV 120W Administration Guide 56 3 d. (Optional) Check the W ir ele ss I so la ti on wi th in SSID b ox to s e p a r ate t h is network from the other t hree networks on the Cisco RV 120W .
C onf ig urin g the Wi rele s s N et w ork Configuring Basic W i reless Settings Cisco RV 120W Administration Guide 57 3 personal authenticat ion is the preshar ed key (PSK) that is an alpha numeric passphrase shared with the wir ele s s peer . • WP A Enterprise —Allows you to use WP A with R ADIUS ser ver authenti cation.
C onf ig urin g the Wi rele s s N et w ork Configuring Basic W i reless Settings Cisco RV 120W Administration Guide 58 3 charact ers (or 26 hexadecimal charact ers) f or 128-bit WEP . V alid hexadecimal characters ar e “0” to “9” an d “ A ” to “F”.
C onf ig urin g the Wi rele s s N et w ork Configuring Basic W i reless Settings Cisco RV 120W Administration Guide 59 3 STEP 5 Under Connect ion Con trol , choo se one of the f ollowing: • Block f .
C onf ig urin g the Wi rele s s N et w ork Configuring Basic W i reless Settings Cisco RV 120W Administration Guide 60 3 the data pack et and the out put queue id entifies the outpu t queue in which the pack et is transmit ted: • V oice ( 4) or V ideo (3)—High priority queue, minimum dela y .
C onf ig urin g the Wi rele s s N et w ork Configuring Adv anc e d W ireless S ettings Cisco RV 120W Administration Guide 61 3 Co nfig uring Advance d Wir ele s s S et tings T o configure advance d wireless set tings on the Cisco RV 120W: STEP 1 Ch oose Wirele s s > Advan ced Settings .
C onf ig urin g the Wi rele s s N et w ork Configuring W i-Fi Pr otect e d S etup Cisco RV 120W Administration Guide 62 3 en vironment. This function boosts the Cisc o RV 120W’ s ability to catch all wir eles s transmissions but sever ely decrea s es p er f ormance.
C onf ig urin g the Wi rele s s N et w ork Configuring a W ireless Distribution Syst em ( WDS) Cisco RV 120W Administration Guide 63 3 T o set up a WPS-enabled device in the network : STEP 1 Ch oose Wirele s s > WPS .
C onf ig urin g the Wi rele s s N et w ork Configuring a W ireless Distribution Syst em ( WDS) Cisco RV 120W Administration Guide 64 3 Y ou can manually add WDS peers that can connect to the C isco RV 120W: STEP 1 In the WDS Peer T able , cli ck Add .
4 Cisco RV 120W Administration Guide 65 C onfiguring the F irewall This chapt er contains inf ormation about c onfiguring the f irewall pr oper ties of the Cisco R V 120W and includes the f ollowing s.
C onf ig urin g th e Firew all Ci s c o R V 1 2 0W Fi re wa ll Featu re s Cisco RV 120W Administration Guide 66 4 • Schedule s as t o when the r outer should a pply rules . • K ey w ords (in a domain name or on a URL of a web page) that the rout er should allow or blo ck .
C onf ig urin g th e Firew all Configuring Acc e ss Rules Cisco RV 120W Administration Guide 67 4 Configuring A c c e ss Rules Con figu re a ccess rul es t o cont ro l tr affi c t o and fr om yo ur ne twork. T o con fig ure a ccess ru l es, c ho ose Fire w al l > Access Ru les .
C onf ig urin g th e Firew all Configuring Acc e ss Rules Cisco RV 120W Administration Guide 68 4 STEP 4 Choos e the action: • Always Block —Al wa ys bl ock t he sel ect ed type of tr affi c. • Always Allow —Never block the select e d typ e of traffic.
C onf ig urin g th e Firew all Configuring Acc e ss Rules Cisco RV 120W Administration Guide 69 4 • PING • POP3 (P ost O f fi ce Pr ot ocol ) • PPTP (P oint-t o-P oint T unneling Pr otocol) • .
C onf ig urin g th e Firew all Configuring Acc e ss Rules Cisco RV 120W Administration Guide 70 4 STEP 6 In the Sou rce I P field, c onfigur e the IP addr e s s to which t he firewall rul e applies : • Any — The rule applies t o traffic originating fr om any IP addr es s in the local net wor k .
C onf ig urin g th e Firew all Configuring Attack Pr evention Cisco RV 120W Administration Guide 71 4 c. Under Rule Sta tus , choo se En abled or Disabled . Y ou may wa nt to config ure a ru le an d ch oose Disabl ed if y ou want to enable it at a lat er time.
C onf ig urin g th e Firew all Configuring Con tent Filtering Cisco RV 120W Administration Guide 72 4 LAN (Local Network) Security Checks • Blo ck UDP F lood —If this option is enabled, the r outer will not ac cept more than 2 5 simultaneous, active UDP connections f rom a sin g le comput er on the LAN.
C onf ig urin g th e Firew all Configuring Con tent Filtering Cisco RV 120W Administration Guide 73 4 Blo ck ing Web C om p one nts Cer tain commonly-used w eb components can be blocked f or increa s ed s ecurit y . Some of these comp onents can be used by malicious websites t o inf ect comp ut ers that access th em.
C onf ig urin g th e Firew all Configuring URL Blo cking Cisco RV 120W Administration Guide 74 4 Adding T ruste d D om ains Y ou can add a list of trust e d domains. Thes e domains are bypassed durin g k ey word fil tering. F or example, if “yaho o” is added t o the blocked ke y words list and w w w .
C onf ig urin g th e Firew all Configuring Por t T riggering Cisco RV 120W Administration Guide 75 4 C onfi guring P or t T riggeri ng Port triggering allows devices on the LAN to r eque st one or mor e p or ts to be f or warded t o them.
C onf ig urin g th e Firew all Configuring Por t F or warding Cisco RV 120W Administration Guide 76 4 traffic is made. If t he outgoing connection uses only one por t , then specify the sa me po rt n um be r in th e St a rt P ort a nd En d P ort fi e ld s.
C onf ig urin g th e Firew all Configuring Por t F or warding Cisco RV 120W Administration Guide 77 4 T o c onfi gure po r t forw arding : STEP 1 Ch oose Fire wa ll > P o rt F orw ar di n g . STEP 2 Click Add . STEP 3 Choos e the action: • Always Block —Al wa ys bl ock t he sel ect ed type of tr affi c.
C onf ig urin g th e Firew all Configuring Por t F or warding Cisco RV 120W Administration Guide 78 4 • NEWS • NFS (Network Fil e System ) • NNTP (Network News T ransf er Prot ocol) • PING •.
C onf ig urin g th e Firew all Configuring Por t F or warding Cisco RV 120W Administration Guide 79 4 • VDOLIVE (live web video deliver y) • SS H (secur e shell) • SI P - T CP o r SI P -U DP STEP 5 Sel ect t he Sou rce IP : • Any —Sp e ci fie s th at the r ul e be in g crea ted is f o r traf f ic f rom the give n endpoint .
C onf ig urin g th e Firew all Configuring a DMZ Host Cisco RV 120W Administration Guide 80 4 Con f ig ur i ng a D MZ Hos t The Cisco RV 120W supp orts D MZ options.
C onf ig urin g th e Firew all Configuring Adv anc e d Fir ewall Settings Cisco RV 120W Administration Guide 81 4 • Privat e Range Begin — The starting IP address in the private (L AN) IP add res s . • Public Range Be gin — The star ting IP addr e s s in the public (W AN) IP add res s .
C onf ig urin g th e Firew all Configuring Adv anc e d Fir ewall Settings Cisco RV 120W Administration Guide 82 4 T o enable MAC addr es s filt er ing: STEP 1 Ch oose Fire wa ll > Advanced Set tin gs > MAC F iltering . STEP 2 Check the En able box to enabl e M AC Addr e s s Fi ltering f or this device.
C onf ig urin g th e Firew all Configuring Adv anc e d Fir ewall Settings Cisco RV 120W Administration Guide 83 4 T o c onfig ure IP /MAC Addres s b inding : STEP 1 Ch oose Fire wa ll > Advanced Set tin gs > IP /MAC Binding . The table lists al l the currently defi n ed IP /MAC bind ing rules and allows several operations on the rul e s .
C onf ig urin g th e Firew all Configuring Adv anc e d Fir ewall Settings Cisco RV 120W Administration Guide 84 4 If you chose Othe r , enter the number of the pr otocol in the Pr otocol Number field. (F or example, if y ou ar e using RDP , ent er 27 in the pr otocol number field.
C onf ig urin g th e Firew all Configuring Adv anc e d Fir ewall Settings Cisco RV 120W Administration Guide 85 4 T o configure s es sion settings : STEP 1 Ch oose Fire wa ll > Advanced Set tin gs > Sessio n Setti ngs.
C onf ig urin g th e Firew all Configuring Adv anc e d Fir ewall Settings Cisco RV 120W Administration Guide 86 4 T o c onfi gure IGMP : STEP 1 Ch oose Fire wa ll > Advanced Set tin gs > IGMP Co nfigur ation . STEP 2 Check the Enable bo x to all ow IGMP c ommunication between the rout er and other node s in t he net wo rk .
C onf ig urin g th e Firew all Fir ewall Configur ation Examples Cisco RV 120W Administration Guide 87 4 T o cr eate a LAN Group: STEP 1 Ch oose Fire wa ll > Advanced Set tin gs > LAN (Local Network) Groups . STEP 2 Click Add . STEP 3 Ent er the group name; spaces and quotes are n ot suppor ted.
C onf ig urin g th e Firew all Fir ewall Configur ation Examples Cisco RV 120W Administration Guide 88 4 Cr eate an inbound rule as f ollows : Example 2: Allo w videoconferencing from range of out side IP addresses.
C onf ig urin g th e Firew all Fir ewall Configur ation Examples Cisco RV 120W Administration Guide 89 4 Example 3: Mult i-NAT Configuration In this e xample, you want t o c onfigure mu lti-NA T to suppor t multiple public IP addr e s ses on one W AN por t interface.
C onf ig urin g th e Firew all Fir ewall Configur ation Examples Cisco RV 120W Administration Guide 90 4 Example 4: Block tra f fic by schedule if generated from specifi c range of machines In this e .
C onf ig urin g th e Firew all Fir ewall Configur ation Examples Cisco RV 120W Administration Guide 91 4 Cr ea te an inbound ac ces s ru le with the f ollowing pa rameters: Parameter V alue Connection.
5 Cisco RV 120W Administration Guide 92 C onfiguring Vir tual Priva te Net w orks ( VPNs) and S e curit y This chapt er describes VPN configurat ion, beginning with the “C onfi guring VPNs ” s e ction on page 9 2 .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring a Basic VPN Cisco RV 120W Administration Guide 93 5 Creati ng Cis c o QuickVPN Client Users T o use the Cisco QuickVPN, you must do the f ollowing: STEP 1 Enable r emote management .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 94 5 STEP 6 Choo se the typ e of addr e s s f or the local gatewa y (the Cisco RV 120W ) : • IP Address —Ent er the IP address of the gatewa y in the box below .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 95 5 C onfig urin g IKE Po lici e s The Int ernet Ke y Exchange (IKE) pr otocol dynamically exchan ge s ke ys bet we en two IPse c hosts .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 96 5 STEP 6 If you chose FQDN , User -FQDN , or DER A S N 1 DN as the identifier type, enter the IP addr e s s or domain name in the Identifi er fi eld .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 97 5 NOTE Ensur e that the authenti cation algorithm is conf igured identicall y on both sides .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 98 5 Extended Au thentication ( XAUTH) Parameters Rather than c.
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 99 5 • Auto Po l ic y —Some parameters f or the VPN tunnel are generat ed aut omatically .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 100 5 STEP 3 In the End Addres s field, ent er the last IP address in the range. STEP 4 If you chose Subnet as the typ e, ent er the Subnet Mask of the ne t work .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 101 5 Manual Policy Para m eters If you chose manual as the policy type in Step 4 , configur e the manual policy paramet ers .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 102 5 Manual Policy E xample: Cr eating a VPN tunnel b et ween two rout ers : Router 1: WAN1=10.0.0.1 LAN=192.168.
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 103 5 NOTE When configuring a lif etime in kilobytes (also known as l if eby tes), be awar e that two S A s are cr eated f or each p olicy .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 104 5 The user database contains the list of VPN user accounts that are a uthorized to use a given V PN tunnel. Alt ernative ly VPN tunnel users can be authen ticated using a configur ed R ADIUS da tabas e.
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 105 5 The Active IPsec SA s table displa ys a list of activ e IPse c SA s. T able fields are as fo l l o w s : C onf igur ing VPN Us e rs T o view a li st of VPN users , choose VPN > IPs ec > VPN Users .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configuring Advance d VPN Para meters Cisco RV 120W Administration Guide 106 5 NOTE The starting IP of t he PPTP client IP ra nge is use.
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configu ring S ecurit y Cisco RV 120W Administration Guide 107 5 T o c onf igure V PN p as st hrough : STEP 1 Ch oose VPN > IPsec > VPN Passthr ough .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configu ring S ecurit y Cisco RV 120W Administration Guide 108 5 T o conf igur e cer ti fica tes, choose Sec urity > S S L Cer tificate .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configu ring S ecurit y Cisco RV 120W Administration Guide 109 5 STEP 1 Ch oose Secu rity > SSL C er tificate .
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configu ring S ecurit y Cisco RV 120W Administration Guide 110 5 • Ret ri e s — The number of retries f or the Cisc o RV 120W to r e-authenticat e with the R ADIUS s er ver . If the number of retries is e xceede d, authentication of this device with the RADIU S ser ver has failed.
Configuring Vir tual Private N et works ( VPNs) and S e curit y Configu ring S ecurit y Cisco RV 120W Administration Guide 111 5 STEP 4 Ent er the username and passw or d s ent by the Cisco RV 120W to the authenti cator f or authenti cation.
6 Cisco RV 120W Administration Guide 112 C onfiguring Qualit y of S er vic e (Q oS) The Cisco RV 120W lets you confi g ur e the f ollowing Quality of Ser vice (QoS) fe a t u re s : • Configuring W A.
Configuring Qualit y of Ser vic e (QoS) Configuring W AN Q oS Pro files Cisco RV 120W Administration Guide 113 6 F o r m ore in f o rma tio n, se e C onfiguring B andwidth Alloc ation Set tings, pag e 113 . STEP 3 When prompt ed to r eset the previous priority or rat e limit configuration, click OK .
Configuring Qualit y of Ser vic e (QoS) Configuring Pro file Binding Cisco RV 120W Administration Guide 114 6 STEP 3 Ent er t his inf ormation: STEP 4 Click Sa ve . STEP 5 T o bind the pr ofile to a traffic selector , s ee C onfiguring Profile Binding, page 114 .
Configuring Qualit y of Ser vic e (QoS) Configuring CoS S ettings Cisco RV 120W Administration Guide 115 6 STEP 5 Depending on the traffic selector y ou chos e, enter th is inf ormation: STEP 6 Click Sa ve . C onfi guring C oS S et tin gs Y ou can map CoS priorit y settings to the tr af fic f or warding qu eue on the RV 120W.
Configuring Qualit y of Ser vic e (QoS) Mapping C oS S et tings to DSCP V alue s Cisco RV 120W Administration Guide 116 6 T o r e stor e the default CoS settings , click Re stor e D e faul t and, when pr om pt e d, click OK .
7 Cisco RV 120W Administration Guide 117 Administering Y our Cis c o R V 120W This chapt er de scribe s the administration f eatures of the Cisco RV 120W , including creating us ers , conf igur ing net work m anagem ent , dia gnos tic s and loggi ng, date and time, and other set tings.
Administering Y our Cisc o R V 120W Configuring P assword Rules Cisco RV 120W Administration Guide 118 7 Co nfig uring Password Rules The Cisco RV 120W can enf orce rules f or pas swords selected by administ rators a nd use r s. T o c on fi gu r e p ass wo r d r ul es: STEP 1 Ch oose Administration > Pa s sw ord R u le s .
Administering Y our Cisc o R V 120W Usin g the Ma nage ment Inter fac e Cisco RV 120W Administration Guide 119 7 C onf igur ing Web Ac c e s s Y ou can enable acces s on the L AN int er face of the Cisco RV 120W . If a user connects a PC to the LAN po r t , w eb acce ss is then allowed using secure HTTP .
Administering Y our Cisc o R V 120W Usin g the Ma nage ment Inter fac e Cisco RV 120W Administration Guide 120 7 rem o te m e a n s to mo n i to r an d c o nt ro l n e t wo r k d e v ic e s , a nd to m a n a g e configurati ons , statistics collection, perf ormance, and securit y .
Administering Y our Cisc o R V 120W Configuring Network Management Cisco RV 120W Administration Guide 121 7 STEP 3 In the Guest Inactivit y T imeou t field, ent er the number , in m inut es , bef ore a guest logi n se s si on time s o ut du e to inact ivit y .
Administering Y our Cisc o R V 120W Configuring Network Management Cisco RV 120W Administration Guide 122 7 If y ou chos e Aut hP ri v , cho os e the typ e of privacy algorithm ( DES or AES ) and enter the privacy passwor d.
Administering Y our Cisc o R V 120W Confi gur in g th e W AN T raf fic Meter Cisco RV 120W Administration Guide 123 7 STEP 5 Choos e the acc es s t ype. The SNMP m anager or trap agent can either be allowed to read and modify all SNMP acces sible set tings ( rwc ommuni t y ) or b e given read- on ly acce s s ( r oc ommunit y ).
Administering Y our Cisc o R V 120W Confi gur in g th e W AN T raf fic Meter Cisco RV 120W Administration Guide 124 7 STEP 3 Choos e the typ e of traffic t o displa y : • No Limit — Displa y all traffic. • Downl oad Only —Only display tra f fic coming t o the Cisco RV 120W from the Internet .
Administering Y our Cisc o R V 120W Using Ne t work Diagnostic T o ols Cisco RV 120W Administration Guide 125 7 STEP 3 (Optional) C heck the box t o send an email alert when the traffic limit has been r eached and traffic is being blocked. STEP 4 Click Sa ve .
Administering Y our Cisc o R V 120W Cap turing and T racing Packets Cisco RV 120W Administration Guide 126 7 Per for m ing a DNS Lookup A DNS lookup can be per f ormed to retriev e the IP address of a W eb, FTP , Mail or an y other Ser ver on the Int ernet .
Administering Y our Cisc o R V 120W Configuring Logging Cisco RV 120W Administration Guide 127 7 Co nfiguri ng Lo gging Policies T o configure general logging policie s: STEP 1 Ch oose Admi nistra tion > Lo g g i n g > Logging Poli cie s . STEP 2 The L o gging Policy T able shows the types of logging that ar e c onfigured on the system.
Administering Y our Cisc o R V 120W Configuring Logging Cisco RV 120W Administration Guide 128 7 will be dropped and a mes sage will b e logged. (Make sur e the log option is set to a llow f or this fir ewall rule.) STEP 3 Under the type of system logs, sele ct the typ e of syst em events t o be logg ed.
Administering Y our Cisc o R V 120W Configuring Logging Cisco RV 120W Administration Guide 129 7 Configuring Email Lo gging STEP 1 Ch oose Admi nistra tion > Lo g g i n g > Remot e Loggin g Configuration . STEP 2 Select the check box t o enable e-mail logs.
Administering Y our Cisc o R V 120W Configu ring the Discover y Settings Cisco RV 120W Administration Guide 130 7 STEP 5 Under Lo g g i n g P o l i c y , choo se the t ype of logging policy . (Se e C onfiguring Lo gging Po licies , pa ge 127 .) By defaul t , only IPse c VPN logs are enabled.
Administering Y our Cisc o R V 120W Configu ring the Discover y Settings Cisco RV 120W Administration Guide 131 7 C onf igur ing UPnP STEP 1 Ch oose Admi nistra tion > Discover y S ettings > Dis cover y - UPnP . STEP 2 Check Enable to enable UPnP .
Administering Y our Cisc o R V 120W Configuring T ime Settings Cisco RV 120W Administration Guide 132 7 Configuring Time S et tings Y ou can configur e your time zone, whether or not to adjust f or Day light Savi ngs T ime, and with which Network T ime Prot o col (NTP) ser ver to synchr onize the date and time.
Administering Y our Cisc o R V 120W Backing Up and R e sto ring the System Cisco RV 120W Administration Guide 133 7 ! CAU T IO N During a rest ore operation, do not tr y to go online, turn off the rout er , shut down the PC, or do anyt hing else t o the rout er until the operation is complete.
Administering Y our Cisc o R V 120W Up grading Firmware Cisco RV 120W Administration Guide 134 7 Upgradin g F irmwar e ! CAU T IO N During a firm ware upgrade, do no t tr y to go online, turn off the device, shut dow n the PC, or interrupt the proce ss in any wa y until the o p eration is complete.
Administering Y our Cisc o R V 120W Restoring the Fact or y D efaults Cisco RV 120W Administration Guide 135 7 Re st orin g the F a ct or y D e fault s ! CAU T IO N During a rest ore operation, do not tr y to go online, turn off the rout er , shut down the PC, or do anyt hing else t o the rout er until the operation is complete.
8 Cisco RV 120W Administration Guide 136 Viewing the Cis c o R V 120W St a tus This chapt er de scribes how t o view real-time st atistics and other inf ormation about the Cisco RV 120W.
Viewing the Cisco R V 120W Status V iewi ng the Das hb oar d Cisco RV 120W Administration Guide 137 8 The view of the back pan el shows you which por ts are used (colored in gr een) and allows y ou to click the p ort to obt ain inf ormation about the connection.
Viewing the Cisco R V 120W Status V iewi ng the Das hb oar d Cisco RV 120W Administration Guide 138 8 T o view the logs, click details . F or more inf ormation s ee Vi ewing Lo gs , pa ge 145 . To m a n a g e l o g s , c l i c k manage loggin g . F or more inf ormation se e C onfiguring Lo gging, p a ge 126 .
Viewing the Cisco R V 120W Status V iewi ng the Sys tem S ummar y Cisco RV 120W Administration Guide 139 8 VPN Viewing the S ystem Summ ar y The Syst em Su mmar y page displa ys a summar y of the r outer ’ s s ettings . T o view a summar y of syst em set tings : STEP 1 Ch oose Sta tus > Sys tem Su mmar y .
Viewing the Cisco R V 120W Status V iewi ng the Sys tem S ummar y Cisco RV 120W Administration Guide 140 8 LAN (Local Network) Information MA C A ddres s The MA C addr e ss of the device. IP v4 A ddre ss The IP addr es s and subnet mask of the device.
Viewing the Cisco R V 120W Status V iewi ng the Sys tem S ummar y Cisco RV 120W Administration Guide 141 8 WAN (Int ernet) Informati on (IPv4) WAN (Int ernet) Informati on (IPv6) MA C A ddres s The MA C addr e ss of the W A N por t . Con n ecti on Ti m e The time duration f or which the conne ction is up.
Viewing the Cisco R V 120W Status V iewi ng the W ir eless Sta tis tics Cisco RV 120W Administration Guide 142 8 Wireless Inf orm ation Channel Viewing the Wirele s s St a tisti c s The Wireless Statistics page shows a cumulativ e total of r elevant wir eless statistics f or the radio on the device.
Viewing the Cisco R V 120W Status IPsec Connection Sta tus Cisco RV 120W Administration Guide 143 8 The Wireless Statistics page displa ys this inf ormation: NOTE The count ers are r es et when the device is r e star ted. IPse c C onne ction St a tus The IPse c C onnection Status page dis p la ys the status of IPsec conne ctions.
Viewing the Cisco R V 120W Status V iewing VPN Clie nt Conne cti on S ta tus Cisco RV 120W Administration Guide 144 8 Y ou can change the statu s of a conne ction t o either establish or disconnect the con figu r ed SAs (Secu rity Associa tio ns ).
Viewing the Cisco R V 120W Status Vi e w i n g L o g s Cisco RV 120W Administration Guide 145 8 The VPN Client Connec tion Sta tus page displays t his inf ormation: Viewing Lo gs The View Lo gs page allows y ou to vie w the Cisco RV 120W logs . T o view the logs: STEP 1 Ch oose Sta tus > View Logs .
Viewing the Cisco R V 120W Status Vi e w i n g Av a i l a b l e L A N H o s t s Cisco RV 120W Administration Guide 146 8 Viewing A vailable L AN Host s The A vailable L AN (Loc al Net work) Hosts page displays i nformati on about the devices c onnected t o the Cisc o RV 120W.
Viewing the Cisco R V 120W Status V iewing Port T riggering Status Cisco RV 120W Administration Guide 147 8 Viewing Po r t T rigger ing St a tus T o view the status of por t triggering: STEP 1 Ch oose Sta tus > Port T riggering St at us . STEP 2 Click Refres h to di s p la y th e l ate s t p o r t tr ig g e r in g i nfor m a t io n .
Viewing the Cisco R V 120W Status V iewing Port S ta tistics Cisco RV 120W Administration Guide 148 8 Viewing Po r t St a t istic s The Por t Stati stics page displa ys p or t statistics. T o v iew por t st atis tics: STEP 1 Ch oose Sta tus > Port Statist ic s .
Viewing the Cisco R V 120W Status Vi e w i n g O p e n P o r t s Cisco RV 120W Administration Guide 149 8 Viewing Op en Por t s The View Open Por ts page displays a listing of all open por ts . T o view open por ts, cho os e Stat us > View Open Por ts .
A Cisco RV 120W Administration Guide 150 Using Cis c o QuickVPN for Windows 7 , 2000, XP , or Vista Ov e r v i e w This appendix e xplains how t o install an d us e the Cisco QuickVP N s oft ware that can be downloaded from www . ci sc o. co m . QuickVPN works with compu ters running W indows 7 , 2000, XP , or V ista.
Using Cisc o QuickVPN for Windows 7 , 2000, XP , or Vista In stal ling the Cisco QuickVP N S oftwar e Cisco RV 120W Administration Guide 151 A Inst all ing the C is c o Qui ckVPN S o f t w are Installing f rom the CD -R OM STEP 1 Inser t the Cisc o RV 120W CD -ROM into y our CD -ROM drive.
Using Cisc o QuickVPN for Windows 7 , 2000, XP , or Vista Using the Cis c o QuickVPN Soft ware Cisco RV 120W Administration Guide 152 A Using the Cis c o QuickVP N S of t ware STEP 1 Double-click the Cisco QuickVPN softw ar e icon on your deskt op or in the system tray .
Using Cisc o QuickVPN for Windows 7 , 2000, XP , or Vista Using the Cis c o QuickVPN Soft ware Cisco RV 120W Administration Guide 153 A STEP 5 T o termin ate the VP N tunnel, click Disconne ct . T o change your passwor d, click Change Password . For inf orma tion, click Help .
B Cisco RV 120W Administration Guide 154 Wher e to Go F rom Her e Cisco provides a wide ra nge of resour c es to help y ou obtain the ful l b enefits of t he Cisco R V 120W. Produc t Re s ourc e s Supp or t Cisco Sma ll Business Suppor t Communit y w w w .
Un punto importante, dopo l’acquisto del dispositivo (o anche prima di acquisto) è quello di leggere il manuale. Dobbiamo farlo per diversi motivi semplici:
Se non hai ancora comprato il Cisco RV120W è un buon momento per familiarizzare con i dati di base del prodotto. Prime consultare le pagine iniziali del manuale d’uso, che si trova al di sopra. Dovresti trovare lì i dati tecnici più importanti del Cisco RV120W - in questo modo è possibile verificare se l’apparecchio soddisfa le tue esigenze. Esplorando le pagine segenti del manuali d’uso Cisco RV120W imparerai tutte le caratteristiche del prodotto e le informazioni sul suo funzionamento. Le informazioni sul Cisco RV120W ti aiuteranno sicuramente a prendere una decisione relativa all’acquisto.
In una situazione in cui hai già il Cisco RV120W, ma non hai ancora letto il manuale d’uso, dovresti farlo per le ragioni sopra descritte. Saprai quindi se hai correttamente usato le funzioni disponibili, e se hai commesso errori che possono ridurre la durata di vita del Cisco RV120W.
Tuttavia, uno dei ruoli più importanti per l’utente svolti dal manuale d’uso è quello di aiutare a risolvere i problemi con il Cisco RV120W. Quasi sempre, ci troverai Troubleshooting, cioè i guasti più frequenti e malfunzionamenti del dispositivo Cisco RV120W insieme con le istruzioni su come risolverli. Anche se non si riesci a risolvere il problema, il manuale d’uso ti mostrerà il percorso di ulteriori procedimenti – il contatto con il centro servizio clienti o il servizio più vicino.