background image

GigaFast Ethernet

Section 2

Firewall capability to protect LAN PCs from outside intruder
access/attack

LAN user Access Privilege

Virtual Server (Port forwarding) function

DMZ (De-Militarized Zone) Host

Multi DMZ Host support

Auto 2-way applications

Dynamic DNS

Avoid unwanted packets from the WAN and provides a system event log to
record intrusion information. (Date/time, source IP address & port...)

Administrator can arrange interior LAN user’s access privilege to the Internet by
IP address, TCP/IP port service, URL name keyword, and 24-hour time zone

Internet servers (WWW, FTP, E-mail...) in LAN could be virtually exposed to
WAN for outside Internet user access. This is a useful and secure network
deployment for Internet servers

Administrator can completely expose a host PC in the LAN to the Internet
without any firewall protection mechanism. This option allows a full two-way
communication between the local host PC and remote Internet nodes. (ex. bi-
directional games, video/audio conferences...)

In static IP configuration with a range of legal IP addresses, the administrator
can completely expose several host PCs in the LAN to the Internet according to
LAN/WAN IP address mapping

Provides an automatic mechanism to support some specific applications which
need one or many incoming ports when they connect with application servers in
Internet. (Like Microsoft Game Zone, Battle.net…)

Via

DNS service provider, your registered domain name can

be updated automatically whenever the system’s WAN IP is changed

www.DynDns.org

Summary of Contents for WF711-APR

Page 1: ...GigaFast Ethernet WF711 APR User Manual Point 11Mbps Wireless Access Router ...

Page 2: ...language or transmitted in any form or by any means mechanical magnetic electronic optical photocopying manual or otherwise without prior written permission Trademark All product company and brand names are trademarks or registered trademarks of their respective companies They are used for identification purpose only Specifications are subject to be changed without prior notice C S ...

Page 3: ...Connection to LAN Network Setting in Administrator s computer 3 Device Administration Web Based Configuration Telnet Console Configuration 4 Firewall and Advanced Functions Access Control Service Time Allocation URL Keyword Blocking Virtual Server DMZ Multiple DMZ Host Auto 2 Way Applications Dynamic DNS 5 Troubleshooting Common Problems Solutions Frequently Asked Questions ...

Page 4: ...GigaFast Ethernet A TCP IP Well Known Port Appendix B Illustrated Typical Application C Cabling and Pin Assignment D Technical Support Warranty info Configure IP Manually Technical Information E F ...

Page 5: ...ork LAN Thus even a non technical person will easily configure it to meet the different applications This product does not only provide a complete solution to share the Internet bandwidth it also serves as an Internet Firewall to protect your LAN data from being accessed by outside intruders hackers Figure 1 1 Since all incoming data packets have been analyzed and monitored all unwanted packets ma...

Page 6: ...on the LAN and a DHCP Client on the WAN for most simple applications Connects multiple LAN PCs to the Internet with only one dynamicly assigned IP address NAT mode or a range of legal IP address NAT Routing mode Web based Configuring Allow Deny remote administration through WAN connection by Web browser Static IP for leased line or router router interconnect DHCP for most cable modem service PPPoE...

Page 7: ...s is a useful and secure network deployment for Internet servers Administrator can completely expose a host PC in the LAN to the Internet without any firewall protection mechanism This option allows a full two way communication between the local host PC and remote Internet nodes ex bi directional games video audio conferences In static IP configuration with a range of legal IP addresses the admini...

Page 8: ...e has failed Blinking There is wireless communication ON LAN PC device is connected correctly to the WirelessAccess Point Router Blinking There is data communication GigaFast Ethernet Section 2 Package Contents One 11Mbps WirelessAccess Point Router One power adapter One User Manual System Requirements One Ethernet based broadband Internet connection like cable ADSL modem or other router One PC wi...

Page 9: ... for connecting to Cable DSLmodem Reset to factory default settings button Hold down continuously for at least 5 seconds to reset the hardware The LAN IPbecomes 192 168 8 1 by default Flashes when the system is ready Plug in power cord here GigaFast Ethernet Section 2 WAN DC in RDY Reset 1 2 3 4 ...

Page 10: ...on 3 Installation Fig 2 1 The hardware connection of WAN interface for the Wireless Access Point Router Hardware Connection to WAN Attach the power cord into the inlet first and follow these sections to set up the WAN LAN connection Cable DSL Modem Internet ISP Hardware Connection to LAN Connect the network cable from your computer s Ethernet port to one of the Wireless Access Point Router s 4 LAN...

Page 11: ...fault condition Network Setting in Administrator s computer In order to configure the Wireless Router with a networked PC in LAN it is necessary for the administrator to have accurate network settings in this PC Then the communication between the Wireless Router and the administrator s PC is possible The following description assumes that the Wireless Router is in factory default condition If not ...

Page 12: ...or the administrator s computer is desired please refer to Appendix E Click Start button select Settings and then choose Control Panel Double click Network icon Choose the configuration tab Select the TCP IP protocol option which is associated with your network card adapter To installTCP IPprotocol first Step 1 ...

Page 13: ...ress tab Select Obtain an IPaddress automatically Press OK ro continue System may request to restart After restart the connection between the Wireless Access Point Router window is established Please check it as follows Start Control Panel Run Type winipcfg and then press ok button Windows 9x ME ...

Page 14: ...ndow and type ipconfig all to check Ethernet adapter information All Ethernet adapter information is shown in this window Check if you get an IP address like 192 168 8 x and the default gateway is the default IPof the WirelessAccess Point Router If all the steps are finished the network should be working now In case there is something wrong please refer to Chapter 5 for troubleshooting Windows XP ...

Page 15: ... one login session at a time This is in consideration of system database consistency If there is anyone else trying to login it would not be possible The Wireless Router will pop up an alert message The following description also assumes the Wireless Router is in factory default condition Web Based Configuration Open the web browser and type http 192 168 8 1 in the browser s address box This IPadd...

Page 16: ...Router s status at any time Type in the default Administrator password admin Then click enter to login After login the first page is the Device Information of the Wireless Router This page shows the detailed status of the Wireless Router and displays the current WAN s information about dial up duration and traffic bytes count Device Information ...

Page 17: ...4 Clicking the Clear button will clear the WAN traffic counter To update to the latest information click the Refresh button Click the Administration link on the left frame of this page to assign or change settings Administration ...

Page 18: ... Backup Restore only when both firmware versions are the same Otherwise the Wireless Access Point Router will deny the restore operation for reliability considerations Reset to Default Type in your old password and new password and confirm it Then press OK to send the request Auto Logout Whenever the administrator is idle for more than the specified time default is 300 seconds the Wireless Router ...

Page 19: ...ge stores lots of useful information such as system start time administrator log in log out history dial up activities and intrusion event records This function provides the administrator with a convenient diagnostic method for troubleshooting Furthermore it also provides detailed intruder hacker information You can click Refresh to upgrade these events and click Back to return to theAdministratio...

Page 20: ...e method at a time It can be changed later if your connection type changes The five connection types are described in the following Static connection is used when a fixed IP address is used Certain ISPs will assign a static or unchanging IP address Please check with your ISP to find out If you have a Static IP select the static option and fill in the blanks according to the information provided by...

Page 21: ...th the Gateway IP Address DNS Domain Name Server The ISP will provide this address The second DNS Click the Save Restart button DHCP Client connection means that the ISP will dynamically assign the Wireless Router IP address and other settings The Domain Name and Host Name are unused for most ISPs so keep them blank If they are needed for your Internet connection please contact your ISP for the co...

Page 22: ...PPoE option then fill in C PPPoE Connection Your and The may be optional depending on the ISP Choose this option The Wireless Access Point Router will attempt to connect with the ISP if 1 there is at least one LAN user trying to access the Internet and 2 the current WAN connection is disconnected fill in a time period in seconds if you want to disconnect automatically when your Internet connection...

Page 23: ...estart the assigned IP address can be checked on the Device Info page refer to 3 1 1 If something is wrong please browse the system event log to check the dial log in activity refer to 3 1 2 C PPTPConnection My IP address Server IP address My Gateway PPTPaccount PPTPpassword and are the Wireless Access Point Router s PPTPclient andADSLModem s PPTPserver IPaddresses respectively is optional if the ...

Page 24: ...ction is idle for more than that period of time PPTP connection ID Dial on Demand Auto disconnect when idle over _ sec EZ Setup LAN Click the EZ setup LAN link on the left frame to setup LAN The IP address of the WirelessAccess Point Router as it is seen by the internal LAN user If LAN IP is changed the administrator may lose the connection with the Wireless Router when they are not in the same LA...

Page 25: ...S automatically Whenever there is a request the DHCP server will offer unused IP s from the IP address pool to the requesting computer The end address must be greater than the start address Lease time Assign fixed IP to MAC the assigned IPwill be valid during the lease interval If there are some computers like web E mail server which will be assigned a fixed IP by DHCP server you can set those com...

Page 26: ...Fast Ethernet Section 5 Click the Save Restart button to save settings Disable DHCP Server function of the Wireless Router Fill in the LAN IP Address and click the Save Restart button 2 DHCPServer Disabled ...

Page 27: ... status Indicates the internal wireless 802 11b module s status Normally it shows If it says the wireless interface is unavailable Primary secondary Firmware Identification Displays the version identification for the internal wireless 802 11b module 802 11 MAC address Shows the MAC address of the internal wireless 802 11b module A The first TAB is the Wireless Info page OK Failed ...

Page 28: ... unique ID shared by the same group of wireless client PCs and one or more wirelessAccess Point Routers Channel The radio channel used by the wireless 802 11b module The allowed number of channels depends on the country because radio regulations are different in different countries eg US Europe and Japan The same SSID group means that all wireless client PCs and at least one or more Access Point A...

Page 29: ...receive Transmission rates Mbits s Select the rate adaptation mechanism Fixed Mbits s and are allowed The default is which optimizes the adaptation between performance and operating distance Preamble Type Choose preambles in the physical layer The default is long preamble Enter the WEB key and enable disable security feature 1 2 5 5 11 automatic automatic long short and both C The third TAB is the...

Page 30: ... Used to generate WEP 64 or WEP 128 key 1 4 automatically WEP key For WEP encryption A key of hexadecimal characters in length must be filled in For WEP encryption a key of hexadecimal characters in length must be filled in Be sure that the key in the Wireless Router is the same as all wireless client PCs Otherwise communication will not be possible WEP key to use Selects one of four key sets to b...

Page 31: ...on There are two mechanisms provided 1 Allow all wireless client PCs except the following MAC address stations 2 Deny all wireless client Pcs except the following MAC address stations The allowed denied list can be filled from the upper associated MAC list or keyed in manually ...

Page 32: ...to Apendix C 2 Telnet configuration can only be used via LAN Click Start and select Run Type telnet and when the window opens type open 192 168 8 1 The terminal parameters should be set to 115200 8 N 1 baud rate 115200 8 data bit No parity 1 stop bit Press the Enter key once In general theTelnet console configuration is menu driven Enter the password admin is the default and press Enter to login T...

Page 33: ...strator setup 1 Change administrator password Press 1 for this setting The system will ask you to enter your old password enter your new password and retype your new password to confirm 2 Upgrade new firmware Press 2 for this setting 3 Set Date Time Press 3 for this setting Set the date and time seperately You must use a telnet program with file transfer capability to upgrade your firmware Window ...

Page 34: ...reset B Whenever the administrator logs on via web browser the date time is calibrated automatically according to the login PC 4 Reset to factory default and restart 5 Restart System Select WAN setup to select the correct configuration Press 1 to select the WAN Connection type option menu WAN Setup ...

Page 35: ...SP will dynamically assign an IP address to the Wireless Router and all settings automatically so no other settings are required to be filled in If your Internet connection type is a DHCP client type such as a Cable modem you should select this option Static IP address DHCP Client When all settings are finished don t forget to type Y to restart the system WAN IPAddress WAN Subnet Mask WAN Gateway ...

Page 36: ...nnect with the ISP if 1 there is at least one LAN user trying to access the Internet and 2 the current WAN connection is disconnected Fill in a time period in seconds if you want to disconnect automatically when your Internet connection is idle for more than that period of time PPPoE account PPPoE password PPPoE Service Name Dial on Demand Auto disconnect when idled over sec My IP address My Serve...

Page 37: ...s changed the administrator may lose connection with the WirelessAccess Point Router when they are not in the same LAN segment so the administration will not work until they are in the same segment again This can be done by releasing and renewing the IP A Enable Disable DNS Proxy LAN computers get their DNS server from the Wireless Access Point Router first The Wireless Router will search the ISP ...

Page 38: ...sable and enable DHCPServer DHCPServer diabled Advanced function 1 Access control 2 User command Under the main menu typeAto enter into access control This is reserved for diagnostic purposes Allow Deny Respond to Ping from WAN Allow Deny Web Management from WAN Allow or Deny responding if there are any Ping packets sent to WAN of the Wireless Router This function allows the administrator to confi...

Page 39: ...eyword blocking virtual server DMZ and intrusion event log Recorded in the Wireless Access Point Router internal buffer please refer to 3 1 2 Access control allows you to control the WAN to LAN or LAN to WAN access capability Click the link in the left frame There you will see the 3 options shown below Access Control 1 Allow or Deny responding if there is any PING packet sent to WAN of the Wireles...

Page 40: ...s function allows the administrator to inhibit LAN users from using some Internet services for management purposes For example if the Wireless Router is used in a SOHO environment and the administrator wants to inhibit LAN users from using Telnet services like BBS on line chat then it is easily achieved by blocking all packets to service port 23 Another example would be blocking service port 110 P...

Page 41: ...isabled at any time This feature is implemented by two mechanisms One method is to specify the maximum continuous service period This is primarily used for parental control in home family applications It can protect children from surfing the Internet continuously for more than a pre defined period X Meanwhile the Wireless Router will still stop service until periodYis expired ...

Page 42: ...pecific websites the Wireless Router provides a function to perform such a filtering mechanism The administrator can enter the URL keywords of which websites are to be rejected Then the Wireless Router will reject any websites which have URL names that matched or partially match For example if the keyword is xyz then are all blocked Click the Save Restart button after listing the keywords www xyz ...

Page 43: ...ort number like WWW is 80 FTP is 21 any packets from the WAN which have a destination port number that matches a virtual server s ports then these packets will be forwarded to the pre defined LAN s IP The destination port number is also kept the same or mapped into another port for LAN TCP ports are always mapped into TCP ports For example if you have an FTP server port21 at 192 168 8 5 a mail ser...

Page 44: ...ultaneously like video and or audio conference on line gaming The Wireless Router provides this feature to allow some computers in the LAN to have unrestricted 2 way access privilege As a result those computers in the DMZ are more compatible with Internet applications Thus they seem to be dangerous in comparison with those other computers in the LAN The Wireless Router generally allows a computer ...

Page 45: ...y communication capability Most likely the multiple DMZ host are applied in a router to router inter connection SOHO environment please refer to Figure 4 2 It is less popular with home users due to the range of WAN IP address because IP addresses are important and expensive resources now Some ISPs provide leased line services DSL is a common one to subscribers and can offer a range of IP addresses...

Page 46: ...1 Bridging mode Unfortunately the multiple DMZ host will not work with the Fig 4 1 configuration because the Wireless Router can only handle one IP address packets not 5 IP address packets In such conditions the bridging mode option is available for Multiple DMZ The following Fig 4 2 is a typical Router to Router Multi DMZ configuration Fig 4 2 Routing mode Those DMZ hosts in the LAN are virtually...

Page 47: ...ave to perform the same setting again It is not an automatic method Some special applications like MS messenger MS game zone some VoIP devices always connect to an outside server with a fixed destination port so the server will communicate with the application in the LAN by using a predefined incoming port or a specific range of incoming ports In this case the Wireless Router can provide a fully a...

Page 48: ... WAN IP address when the Wireless Router connects with the Internet Whenever the Wireless Router s WAN connection type is PPPoE DHCP client or PPTP client then the Wireless Router WAN IPis obtained from the ISPside dynamically As a result it is very difficult to host a Web server or FTP server by using a dial up ADSL or Cable modem Fortunately there are some non profitable organizations like or co...

Page 49: ...other PC in the LAN to install the update client program This function can be disabled which is the default when the dynamic DNS is never used or another dynamic DNS service provider is preferred After 5 minutes an event update will occur whenever a new WAN IP is received To enable this function it is necessary to apply for a dynamic DNS account as your registered URLname Please visit for more det...

Page 50: ... are not sure initiate the DHCP function to let PC get an IP address from the Wireless Router automatically Make sure that the IP address of your PC is within the default range of 192 168 to 192 168 Check Subnet Mask It should be set to 255 255 255 0 to match the Wireless Router Check the cable connections to the Wireless Router LAN port and see if the Link Act LEDs on the front panel are working ...

Page 51: ...eset button down for at least 5 seconds The administrator s password will now become admin Re configure the Wireless Router according to your previous settings Check if the Wireless Router s wireless LED is lit Check your computer s wireless LAN settings like SSID channel number to see if it is the same as the Wireless Router s Check if the WEP 64 or WEP 128 is enabled or not If it is on the key m...

Page 52: ...occurs because your LAN client PC is no longer on the same subnet address as the Wireless Router Release your LAN client PC s IP address which is currently something like 192 168 8 17 and renew the IP address from the Wireless Router the IPaddress will then become something like 192 168 1 17 6 What type of firewall is the Wireless Router equipped with 7 What can I do if I am unable to access the w...

Page 53: ...s You can customize your own IPs through configuration of this router The advanced features of the router include Yes the followingALG functions are supported FTP passive mode and port command mode Conferencing MS NetMeeting H 323 pass though Instant Messenger MS Windows messenger XPmessenger Yahoo ICQ AOL L2 VPN PPTPclient mode PPTPpass through IP VPN IPSec ESP pass through Gaming AOE CS Star Cra...

Page 54: ...by the operating system when there is a request for service Port numbers for server applications are pre assigned by the Internet Assigned Numbers Authority IANA and do not change The following is a short list of some well known port numbers Table 0 1 Well Known TCPports Port No Name TCP Description 20 FTP DATA FTP data 21 FTP FTP command 23 TELNET Terminal Connection 25 SMTP SMTP 53 DOMAIN Name D...

Page 55: ...ironmentApplication Fig B 1 Home user application Fig B 2 SOHO environment application Fig B 3 SOHO environment application Fig B 4 SOHO environment application DSL Cable modem Simple IP Sharing DHCP Server in the Wireless Router DHCP Server in LAN Wireless Router Wireless Router Wireless Router Wgate2000 ...

Page 56: ... together with a straight through cable RJ 45 pin assignment There are 8 thin color coded wires inside running from one end of the cable to the other All 8 wires are used To determine which wire is wire number 1 hold the cable so that the end of the plastic RJ 45 tip the part that goes into a wall jack first is facing away from you Face the clip down so that the copper side faces up the springy cl...

Page 57: ...res 1 2 3 and 6 at the other end The straight through cable is used in connecting the NIC card and the hub In a crossover cable the orders of the wires change from one end to the other Wire 1 becomes 3 and 2 becomes 6 The crossover cable is used in connecting hubs directly Wire Becomes 1 1 2 2 3 3 6 6 Straight Through Cabling Wire Becomes 1 3 2 6 3 1 6 2 Crossover Cabling ...

Page 58: ...dress Type in your customized IP address The default IP address of this product is 192 168 8 1 so you can type in an IPAddress like 192 168 8 xxx where xxx can be numbers from 1 to 253 Set the Subnet Mask as 255 255 255 0 In the Gateway tab add the IP address of this router The default IP Address is 192 168 8 1 ...

Page 59: ...GigaFast Ethernet Appendix A Select the tab and enable DNS Add DNS values provided by your ISPinto the Click OK to finish DNS configuration DNS Server Search Order ...

Page 60: ...cabling UTPcategory 5 switched 10 100Mbps Wireless LAN IEEE802 11b supports 1 2 5 5 11Mbps LED Indication Power WAN LAN Link Act WLAN Reset Button Reset to factory default settings Power Input External DC 5V 2A Dimensions 7 3 x 4 5 x 1 inches Certification FCC Class B CE Mark OperatingTemperature 0 C to 40 C 32F to 104F StorageTemperature 20 C to 70 C 4F to 157F Operating Humidity 10 to 85 non con...

Page 61: ...e items if they are returned with the product Customers must contact GFE for a Return Material Authorization number prior to returning any product to GFE Proof of purchase may be required Any product returned to GFE without a valid Return Material Authorization RMA number clearly marked on the outside of the package will be returned to customer at customer s expense For warranty claims within Nort...

Page 62: ...ELLER HAS BEEN ADVISED OF THE POSSIBILITYOF SUCH DAMAGES SOME STATES DO NOTALLOW THE EXCLUSION OF IMPLIED WARRANTIES OR THE LIMITATION OF INCIDENTAL OR CONSEQUENTIAL DAMAGES FOR CONSUMER PRODUCTS SO THE ABOVE LIMITATIONS AND EXCLUSIONS MAY NOT APPLY TO YOU THIS WARRANTY GIVES YOU SPECIFIC LEGAL RIGHTS WHICH MAY VARY FROM STATE TO STATE NOTHING INTHIS WARRANTYSHALLBETAKENTOAFFECTYOUR STATUTORYRIGHT...

Reviews: