ZyXEL Communications ZyWALL USG 2000 Uživatelský manuál

Procházejte online nebo si stáhněte Uživatelský manuál pro Hardwarové brány firewall ZyXEL Communications ZyWALL USG 2000. ZyWALL USG ZLD 2.21 Support Notes Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk

Shrnutí obsahu

Strany 1 - ZLD 2.21 Support Notes

ZyWALL USG ZLD 2.21 Support Notes Revision 1.00 August, 2010 Written by CSO

Strany 2 - Table of Contents

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 10 Step 10. User can check the 3G connection status

Strany 3

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 11 Step 13. Configure the trunk name and add the tw

Strany 4 - 1.1 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 12 Scenario 2 — WAN Load Balancing and Customized U

Strany 5

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 13 LLF — Least Load First When choosing LLF as the

Strany 6

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 14 Spill-over When choosing the Spill-over load bal

Strany 7

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 15 2.3 Application Scenario The company has two WAN

Strany 8

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 16 2.4 Configuration Guide Network Conditions: -

Strany 9

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 17 b. Go to CONFIGURATION > Network > Interf

Strany 10 - – ZyWALL USG Support Notes

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 18 b. Add WAN trunk for HTTP traffic — Set WAN2_pp

Strany 11

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 19 Step 3. Go to CONFIGURATION > Network > Ro

Strany 12 - Traffic

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 2 Table of Contents Scenario 1 — Connecting your U

Strany 13

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 20 b. Add a policy route for HTTP traffic: Source:

Strany 14

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 21 c. For all other traffic, use SYSTEM_DEFAULT_WA

Strany 15 - 2.3 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 22 Scenario 3 — How to configure NAT if you have In

Strany 16 - ZyNOS configuration

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 23 3.2 Configuration Guide Network Conditions: USG

Strany 17

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 24 Step 2. Click the Add button to create a mapping

Strany 18

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 25 Step 4. Click CONFIGURATION > Network > Fi

Strany 19

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 26 Step 7. Configure the rule to: - Allow access f

Strany 20

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 27 Scenario 4 — Secure site-to-site connections usi

Strany 21

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 28 4.2 Configuration Guide Network Conditions: USG

Strany 22 - 3.1 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 29 ZLD configuration ZyNOS configuration Step 1. Cl

Strany 23

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 3 Scenario 8 — Reserving Highest Bandwidth Manageme

Strany 24

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 30

Strany 25

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 31 Step 4. Click CONFIGURATION > VPN > IPSec

Strany 26

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 32

Strany 27 - 4.1 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 33 Step 6. After saving the network policy,

Strany 28 - 4.2 Configuration Guide

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 34 Step 7. After setting the rule, user can select

Strany 29

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 35 Scenario 5 — Secure client-to-site connections u

Strany 30

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 36 5.2 Configuration Guide Network Conditions: USG

Strany 31

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 37 ZLD configuration ZyNOS configuration Step 1. Cl

Strany 32

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 38

Strany 33

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 39 Step 4. Click CONFIGURATION > VPN > IPSec

Strany 34

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 4 Scenario 1 — Connecting your USG to the Internet

Strany 35 - 5.1 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 40

Strany 36 - 5.2 Configuration Guide

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 41 Step 6. After setting up the network pol

Strany 37

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 42 Step 7. Start the ZyXEL IPSec VPN Client. Fill i

Strany 38

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 43 Step 8. Configure the phase-2 parameters.

Strany 39

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 44 Step 9. Because it is a dynamic rule, user MUST

Strany 40

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 45 Scenario 6 — Deploying SSL VPN for Tele-workers

Strany 41

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 46 6.2 Configuration Guide Network Conditions: -

Strany 42

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 47 ZLD configuration ZyNOS configuration Step 1. Cr

Strany 43

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 48 Step 2. Go to Configuration > Object > Add

Strany 44

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 49 Step4. Go to Configuration > VPN > SSL VPN

Strany 45 - 6.1 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 5 1.2 Configuration Guide Network Conditions: USG-

Strany 46 - 6.2 Configuration Guide

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 50 Step5. Go to Configuration > VPN > SSL VPN

Strany 47

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 51 Check the created policies as below: Scenario

Strany 48

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 52 SSL VPN is established. You can see the VNC serv

Strany 49

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 53 b. Log in with user “Chris”: Open the USG login

Strany 50

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 54 You can check the client’s routing table after t

Strany 51 - Scenario Verification

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 55 Scenario 7 — Reserving Highest Bandwidth Managem

Strany 52

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 56 7.2 Configuration Guide Network Conditions: -

Strany 53

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 57 Step 2. Go to Configuration > App Patrol >

Strany 54

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 58 << ZyWALL USG20/20W configuration steps &g

Strany 55 - 7.1 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 59 Step3. Create a bandwidth management rule and co

Strany 56

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 6 Step 2. Fill in the PPPoE user name and passwor

Strany 57

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 60 Step4. Create a bandwidth management rule and co

Strany 58

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 61 Scenario 8 — Reserving Highest Bandwidth Managem

Strany 59

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 62 8.2 Configuration Guide Network Conditions: -

Strany 60

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 63 Step 2. Go to Configuration > Object > Sch

Strany 61 - Control Session per Host

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 64 Step3. Go to Configuration > App Patrol >

Strany 62

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 65 Add a policy to manage the manager’s http traffi

Strany 63

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 66 App Patrol BWM Direction NOTE To use App Patrol

Strany 64

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 67 Limit each user’s session number To prevent any

Strany 65

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 68 << ZyWALL USG20/20W configuration steps &g

Strany 66

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 69 Input Start Time and Stop Time, and choose the w

Strany 67

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 7 Step 4. Enable the interface and select the pre-c

Strany 68

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 70 Destination Port: 80 Schedule: the recurring sch

Strany 69

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 71 Scenario 9 — Using ZyWALL to Control Popular P2P

Strany 70

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 72 9.2 Configuration Guide Network Conditions: -

Strany 71 - 9.1 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 73 Step 2. Go to Configuration > App Patrol &g

Strany 72

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 74 Step3. Switch to Configuration > App Patrol &

Strany 73

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 75 Edit the default policy. Limit its bandwidth to

Strany 74

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 76 Add a policy to block thunder traffic during off

Strany 75

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 77 Scenario 10 — Deploying Content Filtering to Man

Strany 76

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 78 10.1 Introduction to ZSB (ZyXEL Safe Browsing)

Strany 77

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 79 10.3 Configuration Guide Network Conditions: -

Strany 78 - 10.2 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 8 Step 6. To check the PPPoE IP address, click the

Strany 79

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 80 Step 2. Go to Configuration > Object > Sch

Strany 80

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 81 Add a profile which allows users to serf all web

Strany 81

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 82 Add a profile for employees to surf only allowed

Strany 82

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 83 Step 4. Switch to Configuration > Anti-X >

Strany 83

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 84 Add an access policy for the employees during of

Strany 84

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 85 Check the created policies. Make sure their orde

Strany 85

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 86 Scenario 11 — Quick Setup for Allowing WLAN User

Strany 86 - 11.1 Application Scenario

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 87 11.2 Configuration Guide Goal to achieve: A qu

Strany 87

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 88 Step 2. You can add a new rule by clicking the A

Strany 88

ZyXEL – ZyWALL USG Support Notes All contents copyright (c) 2010 ZyXEL Communications Corporation. 9 Step 8. Fill in the 3G connection parameters: -

Komentáře k této Příručce

Žádné komentáře