Documente Academic
Documente Profesional
Documente Cultură
81
ZyWALL 5 (VPN)
Intrusion detection and Protection, IDPZyWALL 5
ZyWALL ZyWALL LAN
DMZZyWALL
1
2
3
4
5 DNS
6 NAT
7
8 VPN
9
ZyWALL
82
83
2
WAN
5 HOME
ZyWALL NATDHCP VPN
ZyWALL 3
1 192.168.1.1 (ZyWALL
IP )
9.1
IP
2 Login ( ) (
1234)
3 Apply ( )
4 Apply ( )ZyWALL
84
3
ZyWALL ZyWALL
6 Network Status
( )
WAN
Down ( )
IP
5
WAN
Down () (
IP )
Internet
Access (
) 4
WAN
85
4
1 Home Internet Access
86
PPP over Ethernet PPTP
Nailed-Up ( ) ( ISP
)
Idle Timeout ( ) ( )
Ethernet ( )
NETWORK WAN Roadrunner
( WAN )
87
2 Next myZyXEL.com
ZyXEL
ZyWALL
IDP
Skip Close
88
5 Return
Device Registration
6
Close
iCard PIN
REGISTRATION Service
5 DMZ
(DMZ) ( FTP )
DoS ( )
LAN ZyWALL DHCP TCP/IP DMZ IP
( DMZ IP ) DNS ZyWALL DMZ IP
ZyWALL DMZ
: DMZ7
1 NETWORK DMZ
2 DMZ IP
DMZ IP NAT
( 6)
IP WAN IP
DMZ IP
NATZyWALL DMZ
IP NAT
NAT
3 Apply ( )
89
6 NAT
NAT( - NATRFC 1631) IP IP
NAT Address Mapping (NAT) ZyWALLLAN ( DMZ) IP
IP
WAN DMZ HTTP ( ) IP
10.0.0.20
7
ZyWALL
ZyWALL LAN LAN
LANZyWALL WAN LAN DMZDMZ LAN
4 LAN/DMZ 1 4 l LAN
DMZ Port
Roles ( ) DMZ
Apply( )
1 ADVANCED
NAT Port
Forwarding ( )
2 Active ( )
3
4
5 HTTP IP
6 Apply ( )
90
ZyWALL9
8 VPN
VPN ()
VPN
IPSec
(
IPSec )
VPN
91
: Back ( )
2
Name( )
Remote Gateway Address ( )
IPSec IP
3
Active ( )
Name ( )
Single ( )IP IP
92
: IPSec
Negotiation Mode ():Main Mode () Aggressive
Mode ( ) IP
: SA ( )
Encryption Algorithm ( )3DES AES ( )
Authentication Algorithm ( )MD5 SHA-1 .
Key Group ( )DH2
SA Life Time (SA )ZyWALL IKE SA ( 180 )SA
VPN
Pre-Shared Key ()831ASCII1662 ("0-9""A-F")
"0x""0x" 16 62
Encapsulation Mode ( )Tunnel ( ) NAT Transport ( )
IPSec Protocol (IPSec )ESP NAT AH
Perfect Forward Secrecy (PFS) ( )None ( ) IPSec DH1
DH2
4 IKE ()
5 IPSec
93
8.1 VPN
VPN
"test" ( )VPN
LAN IP
( 10.0.0.23)
URLZyWALL VPN
SECURITY
VPNSA Monitor (SA )
VPN ("test" VPN
)
6 VPN Finish ( ) 7 Close ( )VPN
VPN
VPN
94
9
9.1 IP
Windows 2000Windows NT Windows XP IP
ZyWALL
1 Windows XP
Windows 2000/NT
2 Windows XP
Windows 2000/NT
3
4 Internet Protocol (TCP/IP) ( Win XP )
ZyWALL
LAN
ZyWALL
ZyWALL 1
LAN ping ZyWALL
( )
"ping" ZyWALL LAN IP ( 192.168.1.1)
ENTERZyWALL 9.1
ZyWALL RESET ( ) 10 (
PWR ) ZyWALL (
1234LAN IP 192.168.1.1 )
ZyWALL LAN WAN IP (Console Port)
SMT IP (Console Cable) CONSOLE
( )VT100
8 1 9600 bps
ZyWALL (
DSL )
WAN
VPN
95
1 http://www.zyxel.com.tw/
2 (ZyXEL)
3
5 Internet Protocol TCP/IP ( Win XP
)IP
DNS
6 Internet Protocol (TCP/IP)
7 ( Windows 2000/NT)
96
97
ZyWALL 5 ,
, , , ,
IDP (Intrusion Detection and Protection - ) .
,
ZyWALL. ZyWALL
DMZ (DeMilitarized Zone - ),
.
ZyWALL.
. .
.
.
1
2 Web-
3
4
5 DNS
6
7
8
(VPN)
9
98
1
.
.
1 LAN/DMZ Ethernet. Web-
DMZ LAN DMZ,
(web-, , FTP- .) LAN/DMZ
Ethernet.
ZyWALL Ethernet
99
2 Ethernet WAN Ethernet,
.
3 ZyWALL Turbo, IDP,
.
. ZyWALL Turbo.
. .
4
, .
5 . PWR . SYS ,
, , .
ACT, CARD, LAN/DMZ WAN , .
2 Web-
WAN .
1 Web-.
192.168.1.1 (IP- ZyWALL ).
, .
9.1 IP-
.
2 Login () (
1234 ).
100
5 HOME ( ).
ZyWALL .
, NAT, DHCP VPN, .
ZyWALL ,
3.
3 ,
Apply
().
4 Apply (),
ZyWALL
.
101
3
ZyWALL ,
. ZyWALL .
6
Network Status
( ).
WAN
Down (
)
IP-,
. 5.
WAN
Down (
)
IP-,
Internet
Access (
)
4
WAN.
102
4
1 HOME ( ) Internet Access ( ),
.
.
IP-, Static () IP
Address Assignment ( IP-) .
: ,
Encapsulation (). ,
- .
Apply ().
1
MAINTENANCE
()
Device Mode
( ).
2 Bridge ()
IP-,
IP-
LAN, WAN, DMZ
WLAN.
3 Apply
(). ZyWALL
.
,
, . 5.
103
PPP Ethernet PPTP
Nailed-Up (), (
, -
, ).
, ( )
Idle Timeout ( ).
Ethernet
Roadrunner
WAN NETWORK () (
WAN).
104
2 Next ()
,
ZyWALL
myZyXEL.com ( ZyXEL)
,
,
IDP.
, Skip
() Close ()
.
: IDP,
ZyWALL Turbo Card.
ZyWALL Turbo Card
ZyWALL.
3
myZyXEL.com, Existing
myZyXEL.com account (
myZyXEL.com)
.
, New
myZyXEL.com account (
myZyXEL.com)
, ,
ZyWALL.
Next ().
4 ,
.
105
5 ,
. Return
() Device
Registration ( )
.
6 Close (),
.
:
PIN
(
)
REGISTRATION Service
( ). . .
5 DMZ
DMZ (DeMilitarized Zone - )
(web-, , FTP- .)
DoS (Denial of Service -
).
, ZyWALL , DMZ,
TCP/IP DHCP. IP- (
, IP- DMZ) DNS. IP- DMZ ZyWALL
.
DMZ, ZyWALL , .
: DMZ , . 7.
106
1 NETWORK (), DMZ.
6 NAT
NAT (Network Address Translation - NAT, RFC 1631)
IP- IP- . NAT Address Mapping
( NAT) ZyWALL
IP- IP- ( DMZ).
2 IP-
DMZ.
IP- DMZ,
, NAT
(. 6).
IP-
, IP-
WAN. NAT
IP- DMZ
, ZyWALL
IP- DMZ
NAT. -
,
NAT.
3 Apply ().
4 LAN/DMZ 1- 4-
.
DMZ, Port
Roles ( ),
DMZ Apply
().
107
HTTP (web-) DMZ.
IP- 10.0.0.20.
7
ZyWALL , .
ZyWALL ,
. ,
. ZyWALL DMZ ,
DMZ .
ZyWALL , .
. 9.
1
ADVANCED (),
NAT Port Forwarding
( ).
2 Active
().
3 .
4 ,
.
5 IP- HTTP-.
6 Apply ().
108
8 (VPN)
VPN (Virtual Private
Network -
)
.
IPSec
VPN.
(
IPSec),
VPN.
.
1 VPN HOME ( ) ( ,
), VPN.
109
: Back (), .
2
.
Name ():
.
Remote Gateway Address (
): IP-
IPSec.
3
.
Active ()
.
Name ():
.
Single () IP-.
Range IP ( IP)
IP
IP-.
Subnet () IP-
IP-
.
110
: , IPSec
, .
: Main Mode ( ) .
Aggressive Mode ( ),
IP- .
: ,
.
Encryption Algorithm ( ) 3DES AES (
) .
Authentication Algorithm ( ) MD5
SHA-1 .
Key Group ( ): DH2 .
SA Life Time ( ): , ZyWALL
IKE ( 180 ).
, VPN
.
Pre-Shared Key ( ): 8 31 ASCII
16 62 ("0-9", "A-F").
"0x ( x), 16 - 62
.
Encapsulation Mode ( ): Tunnel () NAT,
Transport () .
IPSec Protocol ( IPSec): ESP NAT, AH .
Perfect Forward Secrecy (PFS) ( ): None ()
IPSec, DH1 DH2 .
111
4
IKE (Internet Key Exchange
- ).
5
IPSec.
6 VPN. Finish
() .
7 Close ()
VPN. VPN
VPN
.
112
8.1 VPN
VPN ,
, web- .
, , .
, VPN test
web-
. IP-
(10.0.0.23 ) URL
. ZyWALL
VPN,
.
SECURITY
(), VPN
SA Monitor ( )
VPN ( VPN
test).
9
.
, ZyWALL
. .
, , .
.
113
9.1 IP-
, IP-
Windows 2000, Windows NT Windows XP. ,
ZyWALL.
1 Windows XP Start (), Control Panel ( ).
Windows 2000/NT Start (), Settings (), Control Panel ( ).
2 Windows XP Network Connections ( ).
Windows 2000/NT Network and Dial-up Connections ( ).
ZyWALL
.
ZyWALL .
. 1.
ZyWALL
"ping". , Ethernet
.
Start (), (All) Programs (() ), Accessories
() Command Prompt ( ). Command
Prompt ( ) "ping", IP- ZyWALL
( 192.168.1.1) [ENTER]. ZyWALL .
, . 9.1.
ZyWALL, RESET.
10 ( PWR ), .
ZyWALL
( - 1234, IP- - 192.168.1.1 . .; .
).
IP- ZyWALL ,
IP- .
CONSOLE .
(, HyperTerminal) VT100,
, 8 , 1 -,
9600 /.
.
ZyWALL Ethernet,
. , (, DSL)
.
WAN .
VPN.
, ZyWALL IPSec
VPN. VPN .
- Web-, .
114
3 Local Area Connection ( )
Properties ().
4 Internet Protocol (TCP/IP) ( (TCP/IP)) ( General ()
WinXP) Properties ().
()
1 www.zyxel.ru.
2 ZyXEL
, .
3 .
5 Internet Protocol TCP/IP Properties
(: (TCP/IP)
( General () Windows XP).
Obtain an IP address automatically
( IP- ) Obtain DNS
server address automatically (
DNS ).
6 OK, Internet Protocol
(TCP/IP) Properties (:
(TCP/IP)).
7 Close () (OK Windows 2000/
NT), Local Area Connection
Properties (
).
8 Network Connections (
).