Instrukcja obsługi Verizon MI424WR

Verizon router MI424WR

Przeczytaj poniżej 📖 instrukcję obsługi w języku polskim dla Verizon MI424WR (205 stron) w kategorii router. Ta instrukcja była pomocna dla 17 osób i została oceniona przez 2 użytkowników na średnio 4.5 gwiazdek

Strona 1/205
© 2011 Verizon. All Rights Reserved.
Wireless
Broadband
Router
MI424WR
rev. I
User Manual
Contents
FiOS Router User Manual
1
Introduction
1.0 Introduction
1.1 Package Contents
1.2 System Requirements
1.3 Features
1.4 Getting to Know the FiOS Router
2
Connecting the FiOS Router
2.0 Introduction
2.1 Setting Up the FiOS Router
2.2 Computer Network Configuration
2.3 Configuring the FiOS Router
2.4 Features
2.5 Main Screen
3
Setting Up a Wireless Network
3.0 Introduction
3.1 Overview
3.2 Connecting a Wireless Client
3.3 Wireless Status
3.4 Basic Security Settings
3.5 Advanced Security Settings
3.6 Setting Up a Wireless Client
4
Configuring My Network Settings
4.0 Introduction
4.1 Accessing My Network Settings
4.2 Using My Network Settings
Contents
FiOS Router User Manual (cont)
5
Using Network Connections
5.0 Introduction
5.1 Accessing Network Connections
5.2 Network (Home/Office) Connection
5.3 Ethernet/Coax Connection
5.4 Wireless Access Point Connection
5.5 Broadband Ethernet/Coax Connection
5.6 WAN PPPoE Connection
6
Configuring Security Settings
6.0 Introduction
6.1 Overview
6.2 Firewall
6.3 Access Control
6.4 Port Forwarding
6.5 DMZ Host
6.6 Port Triggering
6.7 Remote Administration
6.8 Static NAT
6.9 Advanced Filtering
6.10 Security Log
7
Parental Controls
7.0 Introduction
7.1 Activating Parental Controls
7.2 Rule Summary
Contents
FiOS Router User Manual (cont)
8
Configuring Advanced Settings
8.0 Introduction
8.1 Using Advanced Settings
8.2 Utilities
8.3 DNS Settings
8.4 Network Settings
8.5 Configuration Settings
8.6 Time Settings
8.7 Firmware Upgrade
8.8 Routing Settings
9
Monitoring the FiOS Router
9.0 Introduction
9.1 Router Status
9.2 Advanced Status
10
Troubleshooting
10.0 Introduction
10.1 Troubleshooting Tips
10.2 Frequently Asked Questions
A
Configuring Quality of Service
A.0 Introduction
A.1 Traffic Priority
A.2 Traffic Shaping
Contents
FiOS Router User Manual (cont)
B
Specifications
B.0 Introduction
B.1 General
B.2 LED Indicators
B.3 Environmental
C
Notices
C.0 Introduction
C.1 Regulatory Compliance Notices
C.2 Modifications
C.3 NEBS Requirements
C.4 GPL
6
© 2011 Verizon. All Rights Reserved.
1
Introduction
1.0 Introduction
1.1 Package Contents
1.2 System Requirements
1.3 Features
1.4 Getting to Know the FiOS
Router
7
© 2011 Verizon. All Rights Reserved.
The Verizon FiOS® Router lets you transmit
and distribute digital entertainment and
information to multiple devices via coaxial
cables. The FiOS Router also supports
Ethernet and Wi-Fi networking, making
it one of the most versatile and powerful
routers available.
Introduction
1.1 Package Content
1
8
© 2011 Verizon. All Rights Reserved.
1.1 Package Content
The following is a list of the items included with the FiOS Router:
Black Power adapter•
Yellow cable (Ethernet, • 6 ft.)
White cable (Ethernet, • 10 ft.)
Quick Start Guide•
Installation Guide•
User Manual • CD
Wireless Networking Guide•
Wall-mount template•
Vertical stand•
1.2 Minimum System Requirements
The FiOS Router must be used with the following systems and software:
Computer with Ethernet capability•
Microsoft Windows 2000, XP, Vista, or 7; Mac OS 10.1 or greater; •
Linux/BSD, Unix
Internet Explorer 5.0 or higher; Netscape Navigator 7.0 or higher•
TCP/IP network protocol installed on each computer•
FiOS Router User Manual
9
© 2011 Verizon. All Rights Reserved.
1.3 Features
The FiOS Router features:
Multiple networking standards support, including:•
WAN · - Ethernet and MoCA interfaces
LAN · - 802.11b/g/n, Ethernet, and MoCA interfaces
Integrated wired networking with • 4-port 10/100/1000 Mbps Ethernet switch
and MoCA
Integrated wireless networking with • 802.11b/g/n access point featuring:
802 · .11n enabled to support speeds up to 160 Mbps wirelessly
802 · .11g enabled to support speeds up to 54 Mbps wirelessly
802 · .11b compatibility, communicating with 802.11b wireless products at
speeds up to 11 Mbps
Enterprise-level security, including• :
Fully customizable firewall with Stateful Packet Inspection ·
Content filtering with · URL-keyword based filtering, parental control,
customizable filtering policies per computer, and E-mail notification
Denial of service protection against · IP spoofing attacks, intrusion and scanning
attacks, IP fragment overlap, ping of death, and fragmentation attacks
Event logging ·
Intrusion detection ·
MAC · address filtering
NAT ·
DMZ · hosting
Access control ·
Advanced wireless protection featuring · WPA, WPA2, WEP 64/128 bit
encryption, 802.1x authentication, and MAC address filtering
ICSA · certification
Introduction
1.3 Features
1
10
© 2011 Verizon. All Rights Reserved.
Other options, including:•
DHCP · server option
DHCP · server/PPPoE server auto-detection
DNS · server
LAN IP · and WAN IP address selection
MAC · address cloning
Port forwarding ·
PPP · oE support
Q · oS support (end to end layer 2/3) featuring Diffserv, 802.1p/q
prioritization, configurable upstream/downstream traffic shaping, random
early detection and pass-through of WAN-side DSCPs, PHBs, and queuing
to LAN-side devices
Remote management and secured remote management using · HTTPS
Reverse · NAT
Static · NAT
Static routing ·
Time zone support ·
VLAN · multicast support
VPN IPS · ec (VPN pass-through only)
FiOS Router User Manual
11
© 2011 Verizon. All Rights Reserved.
1.4 Getting to Know the FiOS Router
This section contains a quick description of the FiOS Routers lights (LEDs), ports,
etc. The FiOS Router has several indicator lights on its front panel, a sticker on its
bottom panel, and a series of ports and switches on its rear panel.
1.4a Front Panel
The front panel of the FiOS Router has a series of indicator lights: Power, WAN
Ethernet, WAN Coax, Internet, LAN Ethernet (4), LAN Coax, USB (2), and Wireless.
It also features a WPS button.
Front view – Verizon FiOS Router (rev. I)
Introduction
1.4 Getting to Know the FiOS Router
1
12
© 2011 Verizon. All Rights Reserved.
Power
The Power LED displays the FiOS Router’s current status. If the Power light glows
steadily green, the FiOS Router is receiving power and fully operational. When
the Power light flashes rapidly, the FiOS Router is initializing. If the Power light
is not illuminated when the Power cord is plugged in and the Power switch is
turned on, or if the Power light glows red for more than 3 minutes, the FiOS
Router has suffered a critical error and technical support should be contacted.
WAN Ethernet
The WAN Ethernet LED illuminates when the FiOS Router is connected to the
Internet via Ethernet. If flashing, data traffic is passing across the port.
WAN Coax
The WAN Coax LED glows steadily or flashes when the FiOS Router is connected
to the Internet via coaxial cable.
Internet
When the Internet LED glows steadily green, the FiOS Router is connected to the
ISP (Internet Service Provider). If it glows amber, there is a physical connection
to the ONT (Optical Network Terminator), but authentication has not taken place
(i.e., no IP address is present).
LAN Ethernet (1, 2, 3, 4)
The LAN Ethernet LEDs illuminate when the FiOS Router is connected to a local
network via one or more of its Ethernet ports. If flashing, data traffic is passing
across the port(s).
LAN Coax
The LAN Coax LED glows steadily or flashes when the FiOS Router is connected
to a local network via its Coax port.
FiOS Router User Manual
13
© 2011 Verizon. All Rights Reserved.
USB (1, 2)
The USB LEDs illuminate when the FiOS Router is connected to a device via one
of its USB ports. These ports are currently inoperational; they will be activated in
a future firmware update.
Wireless
The Wireless LED illuminates when the FiOS Routers wireless access point is
turned on. If flashing, data traffic is passing across the wireless connection.
Wi-Fi Protected Setup
WiFi Protected Setup (WPS) is an easier way to set up a wireless network. Instead
of entering passwords or multiple keys on each wireless client (laptop, printer,
external hard drive, etc.), the FiOS Router can create a wireless network that only
requires the pressing of buttons (one on the FiOS Router, and one on the client
[either built-in, or on a compatible wireless card]) to allow wireless clients to join
the FiOS Routers wireless network. Although the WPS button is included on
the FiOS Router, WPS functionality will not be enabled until a future firmware
release. The button is included so that WPS can be activated at a later date
without having to physically change the FiOS Router. The GUI does not include
the WPS option.
1.4b Bottom Panel
The bottom panel of the FiOS Router has a sticker that contains important
information about the FiOS Router, including default user name and password,
ESSID, wireless keys, etc.
Introduction
1.4 Getting to Know the FiOS Router
1
14
© 2011 Verizon. All Rights Reserved.
1.4c Rear Panel
The rear panel of the FiOS Router has eight ports (Coax, Power, LAN Ethernet
[4], WAN Ethernet, and USB), a Power switch, a Reset button, and two
wireless antennas.
On/Off
Coax
1234
100 100 100 100
10 10 10 10
LAN
WAN
100 10
Reset
Ethernet Cable
(from LAN Ethernet Port
to Computer/Device)
Ethernet Cable
(from WAN Port
to ISP Connection)
Power Adapter
(from Power Port
to Wall Outlet)
Coaxial Cable
(from Coax Port
to Device)
USB1
USB Cable
(from USB Port
to Device)
USB2
Rear view – Verizon FiOS Router (rev. I)
Coax Port
The Coax port connects the FiOS Router to the ISP or other devices using a
coaxial cable.
Power Port
The Power port connects the FiOS Router to an electrical wall outlet via the
Power cord.
Power Switch
The Power switch powers the FiOS Router on and off.
FiOS Router User Manual
15
© 2011 Verizon. All Rights Reserved.
Reset Button
To restore the FiOS Router’s factory default settings, press and hold the Reset
button for approximately ten seconds. The reset process will start about ten
seconds after releasing the button. When the FiOS Router resets, all the lights on
the front panel turn off, and then some of the lights start flashing. The FiOS Router
has completed its reset process when the Power light glows steadily green.
Caution! Do not unplug the Power cord from the FiOS Router during the
reset process. Doing so may result in the loss of the FiOS Router’s configuration
information. If this occurs, reset the FiOS Router again.
LAN Ethernet Ports (4)
The LAN Ethernet ports connect devices to the FiOS Router via Ethernet cables
to create a local area network (LAN). The LAN Ethernet ports are 10/100/1000
Mbps auto-sensing ports, and either a straight-through or crossover Ethernet
cable can be used when connecting devices to the ports.
WAN Ethernet Port
The WAN Ethernet port connects the FiOS Router to the ISP using an Ethernet cable.
USB Ports
The USB ports provide up to 500 mA at 5 VDC for attached devices (to charge a cell
phone, for example). In the future, with a firmware release upgrade, the USB host
functionality will be available for devices such as external storage and cameras.
Wireless Antenna
The FiOS Router’s wireless antenna is used to transmit a wireless signal to other
wireless devices on its wireless network.
16
© 2011 Verizon. All Rights Reserved.
2
Connecting
the FiOS
Router
2.0 Introduction
2.1 Setting up the FiOS Router
2.2 Computer Network
Conguration
2.3 Conguring the FiOS Router
2.4 Main Screen
17
© 2011 Verizon. All Rights Reserved.
Connecting the FiOS Router and accessing
its Graphical User Interface (GUI) are both
simple procedures. The latter procedure
may vary slightly, depending on the
computers operating system. However,
no conguration is necessary to access the
GUI when taking advantage of Universal
Plug-and-Play support.
Connecting the FiOS Router
2.1 Setting Up the FiOS Router
2
18
© 2011 Verizon. All Rights Reserved.
2.1 Setting Up the FiOS Router
There are three parts to setting up the FiOS Router: Connecting the Cables,
Configuring the Router, and Connecting Other Computers/Set Top Boxes.
2.1a Connecting the Cables
Note: If a different router was being used previously, disconnect it. Remove all
router components, including power supplies and cables, as they will not work
with the FiOS Router.
Get the FiOS Router and black Power cord from the box.1.
Plug the black Power cord in the black port on the back of the FiOS Router 2.
and then into a power outlet.
Turn the FiOS Router on.3.
The Power light on the front of the FiOS Router will glow red for 4.
approximately 1 minute during initialization; wait until the Power light glows
steadily green before proceeding to step 5.
Plug the yellow Ethernet cable from the box into one of the four yellow 5.
Ethernet ports on the back of the FiOS Router.
Make sure the computer is powered on, then plug the other end of the 6.
yellow Ethernet cable into an Ethernet port on the computer.
Make sure at least one of the Ethernet LAN lights on the front of the FiOS 7.
Router glows steadily green. This may take a few moments.
The phone company previously installed a high-speed wall jack somewhere 8.
in the house. Locate it and note its type (Ethernet or coaxial). If Ethernet,
follow steps 8a and 8b. If coaxial, follow steps 9a and 9b. Then, continue to
step 10.
a. If connecting via Ethernet, get the white Ethernet cable from the box and
plug one end in the white port on the back of the FiOS Router.
b. Plug the other end of the white Ethernet cable into the high-speed
Ethernet jack.
FiOS Router User Manual
19
© 2011 Verizon. All Rights Reserved.
a.9. If connecting via coaxial cable, get a coaxial cable and connect one end
to the red Coax port on the back of the FiOS Router.
b. Connect the other end of the coaxial cable to a coax jack.
Make sure the Ethernet WAN light (if connecting via Ethernet) or Coax WAN 10.
light (if connecting via coaxial cable) on the front of the FiOS Router glows
steadily green. If connecting via coaxial cable, this may take a few minutes.
Note: If the Ethernet WAN light or Coax WAN light does not illuminate, make
sure the cable (Ethernet or coaxial) is connected properly at both ends.
2.2 Computer Network Configuration
Each network interface on the computer should either be configured with a
statically defined IP address and DNS address, or instructed to automatically
obtain an IP address using the Network DHCP server. The FiOS Router is set up, by
default, with an active DHCP server, and we recommend leaving this setting as is.
2.2a Configuring Dynamic IP Addressing
To set up a computer to use dynamic IP addressing:
Windows 7
In the Control Panel, select 1. View Network Status and Tasks (below
“Network and Internet”).
Under “Connect or disconnect, click 2. Local Access Connection.
The “Local Area Connection Status” window appears. Click 3. Properties.
The “Local Area Connection Properties” window appears. Select 4. Internet
Protocol Version 4 (TCP/IPv4), then click Properties.
The “Internet Protocol Version 4 (TCP/IPv4) Properties window appears. 5.
Click the “Obtain an IP address automatically” radio button. 6.
Click the “Obtain DNS server address automatically” radio button. 7.
Click 8. OK in the Internet Protocol Version 4(TCP/IPv4) Properties window,
then click OK in the Local Area Connection Properties screen to save
the settings.
Connecting the FiOS Router
2.2 Computer Network Conguration
2
20
© 2011 Verizon. All Rights Reserved.
Windows Vista
Select 1. Network and Sharing in the Control Panel.
Click 2. View Status, then click Properties.
Click 3. Continue in the “User Account Control” window.
In the General” tab of the Local Area Connection Properties window select 4.
Internet Protocol Version 4 (TCP/IPv4), then click Properties.
The “Internet Protocol Version 4 (TCP/IPv4) Properties window appears. 5.
Click the “Obtain an IP address automatically” radio button. 6.
Click the “Obtain DNS server address automatically” radio button. 7.
Click 8. OK in the Internet Protocol Version 4(TCP/IPv4) Properties window,
then click OK in the “Local Area Connection Properties screen to save
the settings.
Windows XP
Select 1. Network Connections in the Control Panel.
Right-click 2. Ethernet Local Area Connection, then click Properties.
In the “General” tab, select 3. Internet Protocol (TCP/IP), then click Properties.
The “Internet Protocol (TCP/IP) Properties” window appears. 4.
Click the “Obtain an IP address automatically” radio button. 5.
Click the “Obtain DNS server address automatically” radio button. 6.
Click 7. OK in the “Internet Protocol (TCP/IP) Properties” screen, then click OK in
the “Local Area Connection Properties” screen to save the settings.
FiOS Router User Manual
21
© 2011 Verizon. All Rights Reserved.
Macintosh OS X
Click on the Apple icon in the top left corner of the desktop. 1.
From the menu that appears, select 2. System Preferences.
The “System Preferences window appears. Click 3. Network.
From the “Network” window, make sure “Ethernet” in the list on the left is 4.
highlighted and displays “Connected.
Click 5. Assist me.
From the tab that appears, click 6. Diagnostics.
Follow the instructions in the “Network Diagnostics assistant. 7.
Linux
Login into the system as a super-user by entering su at the prompt. 1.
Type ifconfig to display the network devices and allocated IPs. 2.
Type pump -i <dev>, where <dev> is the network device name. 3.
Type ifconfig again to view the newly allocated IP address. 4.
Make sure no firewall is active on device <dev>. 5.
Connecting the FiOS Router
2.3 Conguring the FiOS Router
2
22
© 2011 Verizon. All Rights Reserved.
2.3 Configuring the FiOS Router
Open a web browser on the computer connected to the FiOS Router. In the 1.
Address text box, type:
http://192.168.1.1
then press Enter on the keyboard.
The “Login screen appears. Enter admin in the “User Name text box. Enter 2.
the password that is printed next to Default Password on the label attached
to the bottom of the FiOS Router in the Password text box.
Click 3. OK.
The FiOS Router is now configured. The password can be changed after this
initial log in, but if the FiOS Router is subsequently reset to factory default
settings, the password printed on the label will be in effect.
FiOS Router User Manual
23
© 2011 Verizon. All Rights Reserved.
2.3a Connecting Other Computers/Set Top Boxes
The FiOS Router can connect to other computers or set top boxes in three ways:
via Ethernet, via wireless connection, or via coaxial cable.
Ethernet
Get an Ethernet cable and plug one end into one of the open yellow 1.
Ethernet ports on the back of the FiOS Router.
Plug the other end of the Ethernet cable into an Ethernet port on 2.
the computer.
Make sure the corresponding Ethernet LAN light on the front of the FiOS 3.
Router glows steadily green.
Repeat these steps for each computer to be connected to the FiOS Router 4.
via Ethernet.
Wireless
Make sure each computer to be connected wirelessly has built-in wireless or 1.
an attached wireless adapter.
Make sure the computer uses the same ESSID and WPA2 key as the FiOS 2.
Router by launching the computers wireless application
Enter the ESSID and WPA2 key found on the sticker on the bottom of the 3.
FiOS Router in the computers wireless settings and click Save.
Make sure the changes were implemented by surfing the Internet from 4.
the computer.
Repeat these steps for every other computer to be connected to the 5.
FiOS Router wirelessly.
Connecting the FiOS Router
2.4 Main Screen
2
24
© 2011 Verizon. All Rights Reserved.
Coaxial
Make sure all set top boxes are turned off.1.
Disconnect any adapter currently connected to the coaxial jack in the room 2.
where the FiOS Router is.
Connect one end of the coaxial cable to the coaxial wall jack, and the other 3.
end to the red Coax port on the back of the FiOS Router.
Power up the set top box.4.
Make sure the Coax LAN light on the front of the FiOS Router glows steadily 5.
green. This may take a few minutes. When it does, the set top box is
connected to the FiOS Router.
2.4 Main Screen
After logging into the FiOS Router’s GUI (see Configuring the FiOS Router” at the
beginning of this chapter), the “Main” screen appears.
FiOS Router User Manual
25
© 2011 Verizon. All Rights Reserved.
The Main screen has a menu occupying the top of the screen. Below that, the
screen is divided into three columns: “My Router, “My Network, and
Action Zone.
2.4a Menu
The Main screens menu contains links to all of the configuration options of
the FiOS Router: Wireless Settings (explained in chapter 3 of this manual), My
Network (chapter 5), Firewall Settings (chapter 6), Parental Controls (chapter
7), Advanced (chapter 8), and System Monitoring (chapter 9).
2.4b My Router
This section displays the status of the FiOS Router’s network and Internet
connection.
Broadband Connection
The “Broadband Connection section of the My Router column displays the state
of the FiOS Router’s broadband connection (“Connected” or “Disconnected”) for
the two connection options (“Coax Status and “Ethernet Status”), and the WAN
IP address of the broadband connection.
Quick Links
The “Quick Links section of the My Router column contains a list of frequently
accessed settings, including “Port Forwarding, “Change Wireless Settings,
“Change Login User Name/Password, Adding a Webcam, Verizon Help’
and “Logout.
Connecting the FiOS Router
2.4 Main Screen
2
26
© 2011 Verizon. All Rights Reserved.
2.4c My Network
The “My Network” column of the Main screen displays the connection type,
name, and IP address of all devices connected to the FiOS Router’s network.
The icon associated with the device will be displayed normally (signifying an
active device) or shaded (signifying the device has not been active for at least 60
seconds). The user can view the settings of each device by clicking on its icon.
2.4d Action Zone
This column contains links to various Verizon Web sites, and other informational
links. Clicking on the icon above “Go to Internet Now” connects the user to the
home page configured on the users web browser.
27
© 2011 Verizon. All Rights Reserved.
3
Setting Up
a Wireless
Network
3.0 Introduction
3.1 Overview
3.2 Connecting a Wireless Client
3.3 Wireless Status
3.4 Basic Security Settings
3.5 Advanced Security Settings
3.6 Setting Up a Wireless Client
28
© 2011 Verizon. All Rights Reserved.
Wireless networking enables you to free
yourself from wires and plugs, making
your devices more accessible and easier
to use. This chapter explains how to create
a wireless network using the FiOS Router,
including accessing and conguring
wireless security options.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
29
3.1 Overview
The FiOS Router provides the user with wireless connectivity over the 802.11b,
g, and n standards (the most common wireless standards). 802.11b has a
maximum data rate of 11 Mbps, 802.11g has a maximum data rate of 54 Mbps,
and 802.11n has a maximum data rate of 160 Mbps. All standards operate in the
2.4 GHz range.
The FiOS Router’s wireless feature is turned on, with wireless security activated, by
default. The level of security is WPA2, with a unique WPA2 key already entered. This
information is displayed on a sticker located on the bottom of the FiOS Router.
The FiOS Router integrates multiple layers of security. These include the IEEE
802.1x port-based authentication protocol, RADIUS client, EAP-MD5, EAP-TLS,
EAP-TTLS, EAP-PEAP, Wired Equivalent Privacy (WEP), Wi-Fi Protected Access
(WPA and WPA2) and firewall and VPN applications.
3.2 Connecting a Wireless Client
To connect a wireless client to the FiOS Router:
Note: The following procedure assumes the FiOS Router’s default wireless
settings are intact. If they have been changed, use the new ESSID and wireless
security settings. For more details, see the “Setting Up a Wireless Client section
of this chapter.
In the wireless client’s configuration interface, enter the FiOS Router’s 1.
ESSID (found on a sticker on the bottom of the FiOS Router’s case) in the
appropriate text box or field (this varies depending on the wireless client’s
manufacturer).
Enter the FiOS Router’s wireless key (also found on the sticker on the bottom 2.
of the FiOS Routers case) in the wireless client’s configuration interface.
Save the changes and exit the wireless client’s configuration interface. The 3.
client should now detect and join the FiOS Router’s wireless network. If not,
check the wireless clients documentation, or contact its manufacturer.
Setting Up a Wireless Network
3.3 Wireless Status
3
© 2011 Verizon. All Rights Reserved.
30
3.3 Wireless Status
Clicking on the Wireless Settings” icon from the Main screens menu generates
the Wireless Status screen, which displays the current status of the wireless
connection.
3.3a Radio Enabled
Displays whether the FiOS Routers wireless radio is active.
3.3b SSID
The SSID (Service Set Identifier) is the network name shared among all devices
on a particular wireless network. The SSID must be identical for all devices
on the wireless network. It is case-sensitive and cannot exceed 32 characters.
Make sure the SSID is the same for all devices to be connected to the wireless
network. The FiOS Router comes from the factory with an SSID already entered
and displayed here. The default SSID can also be found on a sticker on the
bottom of the FiOS Router.
3.3c Channel
Displays the channel to which the wireless connection is currently set.
All devices on the wireless network must be on the same channel to
function correctly.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
31
3.3d Security Enabled
Displays what kind of security is active on the wireless connection, and the
security encryption key.
3.3e SSID Broadcast
Displays whether the FiOS Router is broadcasting its SSID. If activated, the SSID
of the FiOS Routers wireless network is broadcast wirelessly.
3.3f MAC Authentication
Displays whether the FiOS Router is using MAC (Media Access Control) address
authentication to allow wireless devices to join the network.
3.3g Wireless Mode
Displays the types of wireless device that can join the network. Options include
802.11b, 802.11g, 802.11 n, or Mixed (allows 802.11b-, 802.11g-, and 802.11n-
equipped wireless devices to join the network).
3.3h WMM
Displays whether WMM is enabled on the FiOS Router.
3.3i Packets Received/Sent
Displays the number of packets received and sent since the FiOS Router’s
wireless capability was activated.
Setting Up a Wireless Network
3.4 Basic Security Settings
3
© 2011 Verizon. All Rights Reserved.
32
3.4 Basic Security Settings
To configure the FiOS Router’s wireless network for basic security, select “Basic
Security Settings from the menu on the left side of any Wireless Settings screen.
The “Basic Security Settings” screen appears.
Note: The FiOS Router’s default wireless security is WPA2. This section explains
how to activate WEP wireless security, which is a less robust security than WPA2.
To set up WPA2 wireless security, see WPA2” on page 38.
Click the On radio button to activate the FiOS Router’s wireless radio.1.
Enter the name of the wireless network in the “SSID” text box (the SSID name 2.
in the figure above is an example; enter a different name for the SSID).
Select the channel at which the FiOS Routers wireless radio communicates 3.
by selecting it from the “Channel” drop-down list.
To preserve the channel selection in the event of a FiOS Router power cycle, 4.
click in the box next to “Keep my channel selection during power cycle.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
33
Click the WEP” radio button to activate WEP (Wired Equivalent Privacy) 5.
security on the wireless network.
Select a WEP security level from the select a WEP Key” drop-down list 6.
(options include “64/40 bit or “128/104 bit”).
Enter the key code in the “Key Code text box. Each character must be a 7.
letter from A-F or a number from 0-9. If 64/40 bit was selected in step 5,
enter 10 characters. If 128/104 was selected, enter 26 characters.
Write down the wireless settings displayed on the screen. Other wireless 8.
devices must use these same settings when configuring the devices wireless
networking scheme to join the FiOS Routers wireless network.
Click 9. Apply to save the settings.
Setting Up a Wireless Network
3.5 Advanced Security Settings
3
© 2011 Verizon. All Rights Reserved.
34
3.5 Advanced Security Settings
To configure the FiOS Router’s advanced wireless network security settings,
select Advanced Security Settings” from the menu on the left side of any
Wireless Settings screen. The Advanced Security Settings” screen appears.
3.5a Level 1 (Wireless Security)
This section is used to configure different types of wireless security. Select
the type of wireless security to be applied to the wireless network by clicking
the appropriate radio button, then configure the security settings in the
subsequent screens.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
35
WEP
If WEP was selected in the Advanced Security Settings screen, the WEP
screen appears.
Select the appropriate WEP mode from the drop-down list. Options include 1.
WEP Only, or 802.1x. If selecting the latter, see the “802.1x section on the
next page.
Select the appropriate network authentication level from the drop-down list. 2.
Options include Open System Authentication, Shared Key Authentication,
or Both.
Activate WEP key 1 by clicking the radio button next to “1” on the left side.3.
Select the length of key 1 by selecting “64/40 bit” or 128/104 bit” from the 4.
appropriate drop-down list in the “Key Length column.
Select the type of key from the appropriate drop-down list in the “Entry 5.
Method” column. If “Hex” is selected, the key must be made up of
hexadecimal digits. If ASCII is selected, the key can be made up of
any characters.
Enter the key in the appropriate text box in the “Encryption Key column. 6.
If 64/40 bit was chosen in step 2, enter 10 characters. If 128/104 bit was
chosen, enter 24 characters. Depending on what option was selected in step
3, enter hexadecimal or ASCII characters.
Click 7. Apply to save changes.
Setting Up a Wireless Network
3.5 Advanced Security Settings
3
© 2011 Verizon. All Rights Reserved.
36
802.1x
If 802.1x was selected in step 1 of the previous procedure, another screen
appears, relating to settings for 802.1x WEP.
802.1x WEP is a robust security protocol that uses port control with dynamically
changing encryption keys automatically updated over the network. 802.1x WEP
uses a RADIUS (Remote Authentication Dial-in Service) server for authentication
purposes. This server must be physically connected to the FiOS Router. Also, the
user must enable the RADIUS client embedded in the FiOS Router (to do this,
see chapter 8, Advanced Settings”).
Select the WEP Mode from the “WEP Mode” drop-down list box.1.
Enter the RADIUS server IP address in the “Server IP” text boxes.2.
Enter the RADIUS servers port number in the “Server Port” text box.3.
Enter the RADIUS servers shared secret in the “Shared Secret text box.4.
Click 5. Apply to save changes.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
37
WPA
If WPA (Wi-Fi Protected Access) was selected, the “WPA Key screen appears.
Review the onscreen guide, “User Guidance on Password Selection.1.
Make sure the radio button next to Verizon Default Pre-Shared Key 2.
(Recommended)” is activated (blue). If not, click the button to activate.
Write the default pre-shared key down and keep it in a secure place. 3.
Select the proper encryption algorithm (TKIP, AES, or TKIP+AES). 4.
Click in the “Group Key Update Interval” check box to activate the group key 5.
update interval, and set the interval time in the text box to the right.
Click 6. Apply at the bottom of the screen to save changes.
Setting Up a Wireless Network
3.5 Advanced Security Settings
3
© 2011 Verizon. All Rights Reserved.
38
WPA2
If WPA2 was selected, the “WPA2 screen appears. Note that WPA2 is the FiOS
Routers default wireless security protocol.
Review the onscreen guide, “User Guidance on Password Selection.1.
Make sure the radio button next to Verizon Default Pre-Shared Key 2.
(Recommended)” is activated (blue). If not, click the button to activate.
Write the default pre-shared key down and keep it in a secure place. 3.
Select the proper encryption algorithm (TKIP, AES, or TKIP+AES). 4.
Click in the “Group Key Update Interval” check box to activate the group key 5.
update interval, and set the interval time in the text box to the right.
Click 6. Apply at the bottom of the screen to save changes.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
39
3.5b Level 2 (SSID Broadcast)
This section is used to configure the FiOS Router’s SSID broadcast capabilities.
Enabling this option allows any wireless device using an SSID of Any” to detect
the FiOS Router’s wireless network. Disabling “SSID Broadcast” allows only those
wireless users who know the SSID of the wireless network to detect and connect
to the network.
Selecting “SSID Broadcast” generates the “SSID Broadcast” screen.
Click the “Enable radio button to enable SSID broadcasting. If enabled, the SSID
of the FiOS Routers wireless network will be broadcast wirelessly. To disable
SSID broadcasting, click the “Disable” radio button.
Setting Up a Wireless Network
3.5 Advanced Security Settings
3
© 2011 Verizon. All Rights Reserved.
40
3.5c Level 3 (Limiting Access)
This option is used to limit access to the FiOS Router’s wireless network.
Wireless MAC Authentication
Wireless MAC authentication allows the user to allow or deny access to the
FiOS Router’s wireless network by a particular device’s MAC address. Selecting
“Wireless MAC Authentication from the Advanced Security Settings screen
generates the Wireless MAC Authentication screen.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
41
To set up wireless MAC authentication:
Click in the “Enable Access List” check box.1.
Select either Accept all devices listed below” or Deny all devices listed 2.
below” by clicking the appropriate radio button. Selecting Accept…
causes all devices listed by MAC address to access the FiOS Router’s wireless
network. Selecting “Deny causes all listed devices to be denied access.
Enter the MAC address of a device in the Client MAC address” text box.3.
Click 4. Add.
Repeat steps 3 and 4 to add more devices to the list.5.
When finished listing devices, click 6. Apply.
To remove a MAC address, select it from the “List” list box, then click Remove.
802.11b/g/n Mode
This option allows the user to select the wireless communication standard
compatible with the devices to be connected on the wireless network from the
drop-down list. Options include Compatibility (802.11b, g, and n devices can
connect) Legacy (only 802.11b and g devices can connect), and Performance
(only 802.11n devices can join).
Setting Up a Wireless Network
3.5 Advanced Security Settings
3
© 2011 Verizon. All Rights Reserved.
42
3.5d Other Advanced Wireless Options
Clicking Other Advanced Wireless Options at the bottom of the Advanced
Security Settings screen generates (after clicking through the “Warning screen)
another Advanced Wireless Options” screen.
Transmission Rate
Always set to Auto.
Transmit Power
Adjust the power of the FiOS Routers wireless signal by entering a percentage
in this text box.
CTS Protection Mode
Activating CTS (Clear to Send) Protection Mode allows mixed 802.11b/g/n
networks to operate at maximum efficiency. Select Auto from the drop-down
list to activate. Select None to deactivate .
CTS Protection Type
Select from the two options: cts-only (for mixed 802.11b/g/n networks) or
rts-cts (for 802.11a/b/g networks).
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
43
Frame Burst - Max Number
Frame Burst allows packet bursting, which increases overall network speed.
Enter the maximum number of frame bursts in this text box.
Frame Burst - Burst Time
Enter the burst time of the frame bursts in this text box.
Beacon Interval
Enter the time period of the beacon interval in this text box.
DTIM Interval
Enter the DTIM (Delivery Traffic Indication Message) interval value (in
milliseconds) in this text box. A DTIM is a countdown mechanism for the FiOS
Router, informing wireless network clients of the next window for listening to
broadcast and multicast messages.
Fragmentation Threshold
Setting the correct fragmentation threshold can increase the reliability of frame
transmissions on the wireless network. Enter the fragmentation threshold in this
text box.
RTS Threshold
Enter the RTS (Request to Send) threshold in this text box. This setting controls
what size data packet the low level RF protocol issues to an RTS packet.
MSDU Aggregation
Use these radio buttons to enable or disable MSDU aggregation.
MPDU Aggregation
Use these radio buttons to enable or disable MPDU aggregation.
Setting Up a Wireless Network
3.5 Advanced Security Settings
3
© 2011 Verizon. All Rights Reserved.
44
802.11 Guard Interval
Always set to “Dynamic.
3.5e WMM Settings
Clicking WMM Settings at the bottom of the Advanced Wireless Options
screen generates (after clicking through the “Warning screen) the Wireless QoS
(WMM) screen. This screen allows the user to prioritize the types of data coming
over the FiOS Routers wireless network.
Wireless QoS (WMM)
Click in the check box to enable/disable Wireless QoS.
WMM Power Save
Click in the check box to enable/disable WMM Power Save.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
45
Priority Table
The upper table in the Wireless QoS screen is the Priority Table.
Use the green up and down arrows to adjust the priority of a particular type of
wireless data. The data type at the top of the table has the highest priority on
the wireless network; at the bottom is the lowest. Additionally, the user can add
a custom type of data by clicking Add and, in the screen that appears, creating
a new type of data tag. Finally, clicking the Action icon in the row corresponding
to an existing type of data allows the user to modify that type of datas Tag and
WMM access.
Admission Control Table
The lower table in the Wireless QoS screen is the Admission Control Table.
This table allows the user to adjust a wireless data types admission control by
selecting Yes/No from the corresponding row’s drop-down list. Also, if needed,
enter a Quota amount in the appropriate Quota text box.
Setting Up a Wireless Network
3.6 Setting Up a Wireless Client
3
© 2011 Verizon. All Rights Reserved.
46
3.6 Setting Up a Wireless Client
If the computer has wireless capabilities and is running Windows XP, Vista,
or 7, it will automatically recognize the existing wireless network and try to
create a wireless connection. View this connection under Windows’
“Network Connections.
3.6a Setting Up a Wireless Windows Client (Windows 7)
If the computer has wireless capabilities and is running Windows 7, it will
automatically recognize the existing wireless network and try to create a wireless
connection. To manually connect to a wireless network:
Click the wireless icon the system tray (in the lower right corner of the 1.
desktop) and, from the menu that appears, click the FiOS Router’s wireless
network name from the list.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
47
When the “Connect button appears under the network’s name, click on it.2.
A “Connect to a Network” window appears. Enter the security key of the 3.
wireless network in the appropriate text box, then click OK.
Setting Up a Wireless Network
3.6 Setting Up a Wireless Client
3
© 2011 Verizon. All Rights Reserved.
48
The connection is made. To check the status of the connection, click on the 4.
wireless icon in the service tray again. In the example, the computer has
successfully joined the wireless network “DWYL7.
3.6b Setting Up a Wireless Windows Client (Windows Vista)
If the computer has wireless capabilities and is running Windows Vista, it will
automatically recognize the existing wireless network and try to create a wireless
connection. View this connection under Windows’ “Network Connections.
Click the wireless icon the system tray (in the lower right corner of the 1.
desktop) and, from the menu that appears, select Connect to a Network.
A “Connect to a Network” window appears. Select the FiOS Router’s 2.
wireless network.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
49
Another Connect to a Network window appears. Enter the WPA key of the 3.
network in the appropriate text box.
Click 4. Connect. A third Connect to a Network window appears, stating that
the connection was successful.
Setting Up a Wireless Network
3.6 Setting Up a Wireless Client
3
© 2011 Verizon. All Rights Reserved.
50
3.6c Setting Up a Wireless Windows Client (Windows XP)
This section assumes the FiOS Router’s wireless network is set up with
WPA security.
Click 1. Network Connections in the Control Panel. The “Network
Connections” window appears.
Double-click the wireless connection icon. The Wireless Network 2.
Connection screen appears, displaying the available wireless connections.
Select the FiOS Router’s network.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
51
Click the connection once to mark it, then click 3. Connect at the bottom of
the screen. The following login window appears, asking for a “Network Key,
which is the pre-shared key used when configuring the FiOS Router’s WPA
security (see the WPA section in this chapter).
Enter the network (WPA) key in both text boxes and click 4. Connect. After
the connection is established, its status will change to Connected, as
shown below.
An icon appears in the notification area, announcing the successful initiation
of the wireless connection.
Test the connection by disabling all other connections in the Network 5.
Connections window and surfing the Internet.
Setting Up a Wireless Network
3.6 Setting Up a Wireless Client
3
© 2011 Verizon. All Rights Reserved.
52
Manual Wireless Network Connection
If the login window shown in step 3 does not appear and the connection
attempt fails, configure the connection manually using the following procedure:
Click the connection once to mark it and then click 1. Change Advanced
Settings in the “Related Tasks box on the left part of the window.
The “Wireless Network Connection Properties window appears. Select 2.
Wireless Networks.
FiOS Router User Manual
© 2011 Verizon. All Rights Reserved.
53
Click the connection to highlight it, then click 3. Properties. The connections
“Properties Window” appears.
From the “Network Authentication drop-down list, select “Open.4.
From the “Data Encryption drop-down list, select WPA.5.
Enter the pre-shared key in both the “Network key” and the “Confirm 6.
network key” text boxes.
Click 7. OK, then OK again.
When attempting to connect to the wireless network, the login window 8.
appears, pre-populated with the pre-shared key. Press Connect to connect.
Since the network is now secured, only users who know the pre-shared key will
be able to connect.
54
© 2011 Verizon. All Rights Reserved.
4
Conguring
My Network
Settings
4.0 Introduction
4.1 Accessing the My Network
Settings
4.2 Using the My Network
Settings
55
© 2011 Verizon. All Rights Reserved.
Once the FiOS Router is physically
connected and the FiOS Routers Main
screen is displayed in a web browser, a list
of devices connected to the FiOS Routers
network appears in the “My Network
column of the screen. From here, basic
network settings can be congured.
Conguring My Network Settings
4.1 Accessing My Network Settings
4
© 2011 Verizon. All Rights Reserved.
56
4.1 Accessing My Network Settings
To access My Network, click “My Network” (at the top of the center column) in
the Main screen.
The “My Network” screen appears:
On the far right side of the screen, in the “Connected Devices section, is a list
of the devices currently connected to the FiOS Router’s network, sorted by
connection type and number. The rest of the screen contains the “My Network”
section, which displays each device connected to the FiOS Router’s network,
and a series of basic configuration settings for each device.
FiOS Router User Manual
57
© 2011 Verizon. All Rights Reserved.
4.2 Using My Network Settings
Various settings can be accessed for a particular device, as follows.
4.2a Access Device
For devices that can be accessed (such as Internet cameras and networked hard
drives), locate it in the My Network column, then click Access Devices to use
the device over the network.
4.2b Access Shared Files
To access the shared files on a particular device, locate the device in the My
Network column, then click Access Shared Files. A list of shared files appears
on the screen.
4.2c Website Blocking
Clicking Website Blocking generates the “Parental Control” screen. For
more information about using parental controls, see chapter 7, “Using
Parental Controls.
Conguring My Network Settings
4.2 Using My Network Settings
4
© 2011 Verizon. All Rights Reserved.
58
4.2d Block Internet Services
Internet services blocking is used to prevent a device on the network from
accessing particular services available on the Internet, such as receiving email
or downloading files from FTP sites. To set up Internet services blocking on a
networked device:
Locate the device in the My Network column, then click 1. Block Internet
Services. The Access Control” screen appears.
Click 2. Add in the “Networked Computer/Device column. The Add Access
Control Rule screen appears.
If this access control rule applies to all networked devices, select Any” from 3.
the “Networked Computer/Device list box.
Select the Internet protocol to be blocked from the Protocol” drop- 4.
down list.
FiOS Router User Manual
59
© 2011 Verizon. All Rights Reserved.
If this rule will be active continuously, select 5. Always from the “Schedule”
drop-down list. If the rule will only be active at certain times, select “User
Defined” and click Add. Then, add a schedule rule (for more details about
schedule rules, see the Advanced Settings” chapter of this manual).
Note: Make sure the FiOS Router’s date and time settings for your time zone are
set correctly for schedule rules to function properly.
Click 6. Apply to save the changes. The Access Control screen will display a
summary of the access control rule.
The user may disable an access control and the service made available without
having to remove the service from the Access Control table. This may be useful
to make the service available only temporarily, with the expectation that the
restriction will be reinstated later.
To temporarily disable an access control, clear the check box next to the •
network computer/device.
To reinstate the restriction at a later time, select the check box next to the •
network computer/device.
To remove an access restriction from the Access Control table, click • Remove
for the service. The service will be removed from the Access Control table.
Note: When Web Filtering is enabled, HTTP services cannot be blocked by
access control.
Conguring My Network Settings
4.2 Using My Network Settings
4
© 2011 Verizon. All Rights Reserved.
60
4.2e Port Forwarding
Activating “Port Forwarding allows the network to be exposed to the Internet
in certain limited and controlled ways, enabling some applications to work from
the local network (game, voice, and chat applications, for example), as well
as allowing Internet access to servers in the local network. To set this up on a
networked device, locate the device in the My Network column, then click Port
Forwarding. The “Port Forwarding screen appears.
To set up basic port forwarding:
Click the arrow next to “IP Address forward or select from menu to display 1.
a menu and either enter the IP address of the item to port forward from, or
choose an item from the drop-down menu.
Click the arrow next to Application to forward” and select a pre-configured 2.
application from the drop-down menu.
The selected applications forwarded port numbers appear at left, as shown 3.
in the figure below.
Click 4. Add. The new port forwarding rule appears in the Applied rules table
at the bottom of the screen.
Click 5. Apply at the bottom of the screen to apply the new rule.
FiOS Router User Manual
61
© 2011 Verizon. All Rights Reserved.
To set up advanced port forwarding:
Click the arrow next to “IP Address forward or select from menu to display 1.
a menu and either enter the IP address of the item to port forward from, or
choose an item from the drop-down menu.
Click the arrow next to Application to forward” and select a pre-configured 2.
application from the drop-down menu.
Click 3. Advanced. The advanced port forwarding options appear.
Select the connection with which this port forwarding rule will be active 4.
from the WAN Connection Type drop-down list.
To select a port to forward communications to (this is optional), select an 5.
option from the “Forward to Port” drop-down list. If a single port or range of
ports is selected, enter the port numbers in the text boxes that appear.
If this port will be active all the time, select Always from the “Schedule 6.
drop-down list. If the rule will only be active at certain times, select “User
Defined” and click Add. Then, add a schedule rule (for more details about
schedule rules, see the Advanced Settings” chapter of this manual).
Click 7. Add to save the changes. The new port forwarding rule appears in the
Applied rules” table at the bottom of the screen.
Conguring My Network Settings
4.2 Using My Network Settings
4
© 2011 Verizon. All Rights Reserved.
62
Click 8. Apply at the bottom of the screen to apply the new rule.
Note: Some applications, such as FTP, TFTP, PPTP, and H323, require the support
of special specific Application Level Gateway (ALG) modules to work inside the
local network. Data packets associated with the aforementioned applications
contain information that allows them to be routed correctly. An ALG is needed
to handle these packets and ensure they reach their intended destinations. The
FiOS Router is equipped with a robust list of ALG modules, enabling maximum
functionality in the local network. The ALG is automatically assigned based on
the destination port.
4.2f View Device Details
To view information about a networked device, or to test a devices connection,
locate the device in the My Network column, then click View Device Details.
The “Device Information screen appears.
Click 1. Test Connectivity. The “Diagnostics screen appears.
The FiOS Router automatically runs a ping test, and the results are displayed 2.
in the Diagnostics screen.
FiOS Router User Manual
63
© 2011 Verizon. All Rights Reserved.
4.2g Rename This Device
To rename a networked device, locate the device in the My Network column,
then click Rename This Device. The “Rename Device screen appears.
Enter the new name of the device in the “New Name text box and, if needed,
select a new icon for the device from the “New Icon drop-down list.
64
© 2011 Verizon. All Rights Reserved.
5
Using
Network
Connections
5.0 Introduction
5.1 Accessing Network
Connections
5.2 Network (Home/Oce)
Connection
5.3 Ethernet/Coax Connection
5.4 Wireless Access Point
Connection
5.5 Broadband Ethernet/
Coax Connection
5.6 WAN PPPoE Connection
65
© 2011 Verizon. All Rights Reserved.
The FiOS Router supports various local
area network (LAN) and wide area network
(WAN, or Internet) connections via
Ethernet or coaxial cables. The “Network
Connections screens are used to congure
the various aspects of the FiOS Routers
network and Internet connections, and
create new connections.
Using Network Connections
5.1 Accessing Network Connections
5
66
© 2011 Verizon. All Rights Reserved.
5.1 Accessing Network Connections
Caution! The settings covered in this chapter should be configured by
experienced network technicians only.
To access the FiOS Router’s network connections, in the “My Network” screen,
click Network Connections from the menu on the left side. The “Network
Connections” screen appears.
Click Advanced to expand the screen and display all connection entries.
To select a connection, click on its name. The rest of this chapter describes
the different network connections available on the FiOS Router, as well as the
connection types that can be created.
FiOS Router User Manual
67
© 2011 Verizon. All Rights Reserved.
5.2 Network (Home/Office) Connection
Select Network (Home/Office) in the Network Connections screen to generate
the “Network (Home/Office) Properties screen. This screen displays a list of
the local network’s properties. The only modifications that can be made from
this screen are disabling the connection (by clicking Disable) or renaming the
connection (by entering a new name in the “Rule Name” text box).
Note: When a network is disabled, its formerly underlying devices will not
be able to get the DHCP address from the network interface to which they
were connected.
The Network (Home/Office) connection is used to combine several network
devices under one virtual network. For example, a home/office network can be
created for Ethernet and other network devices.
Using Network Connections
5.2 Network (Home/Oce) Connection
5
68
© 2011 Verizon. All Rights Reserved.
5.2a Configuring the Home/Office Network
Click Settings in the “Network (Home/Office) Properties” screen to generate a
second “Network (Home/Office) Properties” screen.
General
The top part of the screen displays general communication parameters. We
recommend not changing the default values in this section unless familiar with
networking concepts.
Status Displays the connection status of the network.
When should this rule occur? Displays when the rule is active. To schedule
rules, see the Advanced Settings” chapter.
Network Select the type of connection being configured from the drop-down
list (options: Broadband Connection, Network [Home/Office], or DMZ).
Connection Type Displays the type of connection.
Physical Address Displays the physical address of the network card used for
the network.
MTU Maximum Transmission Unit (MTU) specifies the largest packet size
permitted for Internet transmission. Automatic” sets the MTU at 1500. Other
choices include Automatic by DHCP, which sets the MTU according to the DHCP
connection, and “Manual, which allows the MTU to be set manually.
FiOS Router User Manual
69
© 2011 Verizon. All Rights Reserved.
Internet Protocol
This section has three options: No IP Address, Obtain an IP Address
Automatically, and Use the Following IP Address.
No IP Address Select this option if the connection will have no IP address. This
is useful if the connection operates under a bridge.
Obtain an IP Address Automatically Select this option if the network
connection is required by the ISP to obtain an IP address automatically. The
server assigning the IP address also assigns a subnet mask address, which can
be overridden by entering another subnet mask address.
Use the Following IP Address Select this option if the network connection
uses a permanent (static) IP address, then the IP address and subnet
mask address.
Bridge
The “Bridge section of the Configure Network (Home/Office) screen is used
to configure the LAN devices connected to the FiOS Router. By default, the
Ethernet, Coax, and Wireless Access Point connections are activated. Do not
change these settings unless instructed to do so by the ISP.
Status The “Status column displays the connection status of a particular device.
STP Click in the devices “STP” check box to enable Spanning Tree Protocol
on the device. This protocol provides path redundancy while preventing
undesirable loops in the network.
Using Network Connections
5.2 Network (Home/Oce) Connection
5
70
© 2011 Verizon. All Rights Reserved.
Action The Action column contains an icon that, when clicked, generates the
configuration screen of the particular device.
DNS Server
Domain Name System (DNS) is the method by which website or domain names
are translated into IP addresses. Specify such an address manually, according to
the information provided by the ISP.
To manually configure DNS server addresses, select Use the Following DNS
Server Addresses. Specify up to two different DNS server addresses, one
primary, the other secondary.
IP Address Distribution
The “IP Address Distribution section of the Configure Network (Home/Office)
screen is used to configure the FiOS Router’s Dynamic Host Configuration
Protocol (DHCP) server parameters. DHCP automatically assigns IP addresses
to network devices. If enabled, make sure to configure the network devices as
“DHCP Clients. There are three options in this section: Disabled, DHCP Server,
and DHCP Relay.
Disabled Select this option if statically assigning IP addresses to the
network devices.
FiOS Router User Manual
71
© 2011 Verizon. All Rights Reserved.
DHCP Server To set up the network bridge to function as a DHCP server:
Select 1. DHCP Server.
Enter the IP address at which the FiOS Router starts issuing addresses in the 2.
“Start IP Address text boxes. Since the FiOS Router’s default IP address is
192.168.1.1, the Start IP Address should be 192.168.1.2.
Enter the end of the IP address range used to automatically issue IP 3.
addresses in the “End IP Address text boxes. The “maximum IP address that
can be entered here is 192.168.1.254.
Enter the subnet mask address in the “Subnet Mask text boxes. The subnet 4.
mask determines which portion of a destination LAN IP address is the
network portion, and which portion is the host portion.
If Windows Internet Naming Service (WINS) is being used, enter the WINS 5.
server address in the WINS Server text boxes.
Enter the amount of time a network device will be allowed to connect to the 6.
FiOS Router with its currently issued dynamic IP address in the “Lease Time
in Minutes text box.
Click in the “Provide Host Name If Not Specified by Client” check box to have 7.
the FiOS Router automatically assign network devices with a host name, in
case a host name is not provided by the user.
DHCP Relay Select this option to have the FiOS Router function as a DHCP
relay, and enter the IP address in the screen that appears.
Using Network Connections
5.2 Network (Home/Oce) Connection
5
72
© 2011 Verizon. All Rights Reserved.
Routing
The FiOS Router can be configured to use static or dynamic routing. Dynamic
routing automatically adjusts how packets travel on the network, while
static routing specifies a fixed routing path to neighboring destinations. To
configure routing, enter a device metric in the “Device Metric” text box. The
device metric is a value used by the FiOS Router to determine whether one
route is superior to another, considering parameters such as bandwidth and
delay time.
Routing Table
Clicking New Route generates the New Route window, where a new route can
be configured.
Additional IP Addresses
Clicking New IP Address generates the Additional IP Address Settings screen,
where additional IP addresses can be created to access the FiOS Router via the
Network (Home/Office) connection.
FiOS Router User Manual
73
© 2011 Verizon. All Rights Reserved.
5.3 Ethernet/Coax Connection
An Ethernet connection connects computers to the FiOS Router using Ethernet
cables, either directly or via network hubs and switches. A Coax connection
connects devices (such as set-top boxes) to the FiOS Router using a coaxial
cable. Click Ethernet/Coax in the Network Connections screen (if needed,
click Advanced at the bottom of the screen to reveal the “Ethernet/Coax link
below “Network [Home/Office]”) to generate the “Ethernet/Coax Properties”
screen. This screen displays a list of the local connections properties. The only
modifications that can be made from this screen are disabling the connection
(by clicking Disable) or renaming the connection (by entering a new name in
the “Rule Name text box).
Note: If disabling the connection, the FiOS Router must be rebooted for the
change to take effect.
Using Network Connections
5.3 Ethernet/Coax Connection
5
74
© 2011 Verizon. All Rights Reserved.
5.3a Configuring the Ethernet/Coax Connection
Click Settings at the bottom-right of the Ethernet/Coax Properties screen to
generate another “Ethernet/Coax Properties” screen.
General
The top part of the screen displays general communication parameters. We
recommend not changing the default values in this section unless familiar with
networking concepts.
Status Displays the connection status of the Ethernet switch.
When should this rule occur? Displays when the rule is active. To schedule
rules, see the Advanced Settings” chapter.
Network Select the type of connection being configured from the drop-down
list (Network [Home/Office], Broadband Connection, or DMZ).
Connection Type Displays the type of connection.
Physical Address Displays the physical address of the network card used for
the network.
FiOS Router User Manual
75
© 2011 Verizon. All Rights Reserved.
MTU Maximum Transmission Unit (MTU) specifies the largest packet size
permitted for Internet transmission. Automatic” sets the MTU at 1500. Other
choices include Automatic by DHCP, which sets the MTU according to the DHCP
connection, and “Manual, which allows the MTU to be set manually.
Coax Link
Set up the coax link options in this section of the Ethernet/Coax Properties
screen. Options include Channel, Privacy, and Password.
Channel Select the Channel from the drop-down list (select from 1-6,
or Automatic”).
Privacy Toggle “Privacy” by clicking in the “Enabled check box. If Privacy is
activated, all devices connected via coaxial cable must use the same password.
We recommend leaving the Privacy option deactivated.
Password Enter the Coax Link password in this text box.
CM Ratio Select the CM Ratio from the drop-down menu here.
Additional IP Addresses
Clicking New IP Address generates the Additional IP Address Settings screen,
where additional IP addresses can be created to access the FiOS Router via the
Ethernet connection.
Using Network Connections
5.3 Ethernet/Coax Connection
5
76
© 2011 Verizon. All Rights Reserved.
Coax Connection Status
Click Go to LAN Coax Stats to generate the “Coax Connection Status screen,
which gives an overview of all the devices connected to the FiOS Router via
coaxial cable.
HW Switch Ports
This section displays the connection status of the FiOS Router’s four
Ethernet ports and single coax port. Clicking on a connections Action icon (in
the column on the right) generates the “Port Settings screen, where ingress and
egress policies can be edited.
FiOS Router User Manual
77
© 2011 Verizon. All Rights Reserved.
5.4 Wireless Access Point Connection
A Wireless Access Point connection connects devices wirelessly. Click Wireless
Access Point in the Network Connections screen (if needed, click Advanced
at the bottom of the screen to reveal the Wireless Access Point” link below
“Network [Home/Office]”) to generate the Wireless Access Point Properties”
screen. This screen displays a list of the connections properties. The only
modifications that can be made from this screen are disabling the connection
(by clicking Disable) or renaming the connection (by entering a new name in
the “Name” text box).
Note: If disabling the connection, the FiOS Router must be rebooted for the
change to take effect.
5.4a Configure Wireless Access Point
Click Settings at the bottom-right of the Wireless Access Point Properties screen
generates a second “Wireless Access Point Properties” screen.
Using Network Connections
5.4 Wireless Access Point Connection
5
78
© 2011 Verizon. All Rights Reserved.
General
The top part of the screen displays general communication parameters. We
recommend not changing the default values in this section unless familiar with
networking concepts.
Status Displays the status of the wireless access point connection.
When should this rule occur? Displays when the rule is active. To schedule
rules, see the Advanced Settings” chapter.
Network Select the type of connection being configured from the drop-down
list (options: Network [Home/Office], Broadband Connection, or DMZ).
Connection Type Displays the type of connection.
Physical Address Displays the physical address of the network card used for
the network.
MTU Maximum Transmission Unit (MTU) specifies the largest packet size
permitted for Internet transmission. Automatic” sets the MTU at 1500. Other
choices include Automatic by DHCP, which sets the MTU according to the DHCP
connection, and “Manual, which allows the MTU to be set manually.
Additional IP Addresses
Clicking New IP Address generates the Additional IP Address Settings screen,
where additional IP addresses can be created to access the FiOS Router via the
Wireless Access Point connection.
Coax Link
Set up the coax link options in this section of the Configure Coax screen.
Options include Channel, Privacy, and Password.
Channel Select the Channel from the drop-down list (select from 1-6,
or Automatic”).
FiOS Router User Manual
79
© 2011 Verizon. All Rights Reserved.
Privacy Toggle “Privacy” by clicking in the “Enabled check box. If Privacy is
activated, all devices connected via coaxial cable must use the same password.
We recommend leaving the Privacy option deactivated.
Password Enter the Coax Link password in this text box.
CM Ratio Select the CM Ratio from the drop-down menu here.
Coax Connection Status
Click Go to LAN Coax Stats to generate the “Coax Connection Status screen,
which gives an overview of all the devices connected to the FiOS Router via
coaxial cable.
Using Network Connections
5.5 Broadband Ethernet/Coax Connection
5
80
© 2011 Verizon. All Rights Reserved.
5.5 Broadband Ethernet/Coax Connection
An Ethernet connection connects computers to the FiOS Router using Ethernet
cables, either directly or via network hubs and switches. A Coax connection
connects devices (such as set-top boxes) to the FiOS Router using a coaxial
cable. Click Broadband Connection (Ethernet/Coax) in the Network
Connections screen to generate the “Broadband Connection (Ethernet/Coax)
Properties screen. This screen displays a list of the connections properties.
The only modifications that can be made from this screen are disabling the
connection (by clicking Disable) or renaming the connection (by entering a
new name in the “Name” text box).
Note: If disabling the connection, the FiOS Router must be rebooted for the
change to take effect.
5.5a Configure Broadband Connection (Ethernet/Coax)
Click Settings at the bottom-right of the Broadband Connection (Ethernet/
Coax) Properties screen generates a second “Broadband Connection (Ethernet/
Coax) Properties” screen.
FiOS Router User Manual
81
© 2011 Verizon. All Rights Reserved.
General
The top part of the screen displays general communication parameters. We
recommend not changing the default values in this section unless familiar with
networking concepts.
Status Displays the status of the coax connection.
When should this rule occur? Displays when the rule is active. To schedule
rules, see the Advanced Settings” chapter.
Network Select the type of connection being configured from the drop-down
list (options: Network [Home/Office], Broadband Connection, or DMZ).
Connection Type Displays the type of connection.
Physical Address Displays the physical address of the network card used for
the network.
MTU Maximum Transmission Unit (MTU) specifies the largest packet size
permitted for Internet transmission. Automatic” sets the MTU at 1500. Other
choices include Automatic by DHCP, which sets the MTU according to the DHCP
connection, and “Manual, which allows the MTU to be set manually.
Coax Link
Set up the coax link options in this section of the Configure Coax screen.
Options include Channel, Privacy, and Password.
Auto Detection Turn on the FiOS Router’s ability to automatically detect a coax
connection by clicking in the appropriate radio button.
Channel Select the Channel from the drop-down list (select from 1-6,
or Automatic”).
Privacy Toggle “Privacy” by clicking in the “Enabled check box. If Privacy is
activated, all devices connected via coaxial cable must use the same password.
We recommend leaving the Privacy option deactivated.
Password Enter the Coax Link password in this text box.
CM Ratio Select the CM Ratio from the drop-down menu here.
WAN Connection Speeds Displays the Tx and Rx speeds of the connection.
Using Network Connections
5.5 Broadband Ethernet/Coax Connection
5
82
© 2011 Verizon. All Rights Reserved.
Internet Protocol
This section has three options: No IP Address, Obtain an IP Address
Automatically, and Use the Following IP Address.
No IP Address Select this option if the connection will have no IP address. This
is useful if the connection operates under a bridge.
Obtain an IP Address Automatically Select this option if the network
connection is required by the ISP to obtain an IP address automatically. The
server assigning the IP address also assigns a subnet mask address, which can
be overridden by entering another subnet mask address.
Use the Following IP Address Select this option if the network connection
uses a permanent (static) IP address, then the IP address and subnet
mask address.
DHCP Lease
Renew or release the current DHCP lease by clicking on the appropriate button.
DNS Server
The Domain Name System (DNS) is the method by which website or domain
names are translated into IP addresses. The connection can be set to
automatically obtain a DNS server address, or an address can be set manually,
according to information provided by the ISP.
To configure the connection to automatically obtain a DNS server address, select
Obtain DNS Server Address Automatically from the “DNS Server” drop-down
list. To manually configure DNS server addresses, select Use the Following
DNS Server Addresses. Specify up to two different DNS server addresses, one
primary, the other secondary.
FiOS Router User Manual
83
© 2011 Verizon. All Rights Reserved.
IP Address Distribution
The “IP Address Distribution section of the Configure Broadband Connection
(Coax) screen allows the user to configure the FiOS Routers Dynamic Host
Configuration Protocol (DHCP) server parameters. The DHCP automatically
assigns IP addresses to network devices. If enabled, make sure to configure
the network devices as “DHCP Clients. There are three options in this section:
Disabled, DHCP Server, and DHCP Relay.
Caution! We strongly recommend leaving this setting at “Disabled.
Disabled Select this option if statically assigning IP addresses to the
network devices.
DHCP Server To set up the Broadband Coax connection to function as a
DHCP server:
Select 1. DHCP Server.
Enter the IP address at which the FiOS Router starts issuing addresses in the 2.
“Start IP Address text boxes. Since the FiOS Router’s default IP address is
192.168.1.1, the Start IP Address must be 192.168.1.2.
Enter the end of the IP address range used to automatically issue IP 3.
addresses in the “End IP Address text boxes. The maximum IP address that
can be entered here is 192.168.1.254.
Enter the subnet mask address in the “Subnet Mask text boxes. The subnet 4.
mask determines which portion of a destination LAN IP address is the
network portion, and which portion is the host portion.
If a Windows Internet Naming Service (WINS) is being used, enter the WINS 5.
server address in the WINS Server text boxes.
Using Network Connections
5.5 Broadband Ethernet/Coax Connection
5
84
© 2011 Verizon. All Rights Reserved.
Enter the amount of time a network device will be allowed to connect to the 6.
FiOS Router with its currently issued dynamic IP address in the “Lease Time
in Minutes text box. Just before the time is up, the devices user will need to
make a request to extend the lease or get a new IP address.
Click in the “Provide Host Name If Not Specified by Client” check box to have 7.
the FiOS Router automatically assign network devices with a host name, in
case a host name is not provided by the user.
DHCP Relay Select this option to have the FiOS Router function as a DHCP
relay, and enter the IP address in the screen that appears.
Routing
Routing Mode Select one of the following two Routing modes:
Route• - Select this option to cause the FiOS Router to act as a router between
two networks.
NAPT• - Select this option to activate NAPT (Network Address and Port
Translation), which refers to network address translation involving the
mapping of port numbers and allows multiple machines to share a single IP
address. Use NAPT if the local network contains multiple devices, a topology
that necessitates port translation in addition to address translation.
Device Metric The device metric is a value used by the FiOS Router to
determine whether one route is superior to another, considering parameters
such as bandwidth, delay, and more.
Default Route Click in this check box to define the connection as a the
default route.
FiOS Router User Manual
85
© 2011 Verizon. All Rights Reserved.
Multicast - IGMP Proxy Default Click in this check box to enable the FiOS
Router to issue IGMP (Internet Group Management Protocol) host messages
on behalf of hosts the FiOS Router discovers through standard IGMP interfaces.
IGMP proxy enables the routing of multicast packets according to the IGMP
requests of local network devices asking to join multicast groups.
Internet Connection Firewall
Enable or disable the firewall for this interface. It is recommended to keep the
firewall enabled for all of the FiOS Router’s connection interfaces.
Additional IP Addresses
Click New IP Address to generate the Additional IP Address Settings” screen,
where additional IP addresses can be created to access the FiOS Router via
the connection.
Coax Connection Status
Click Go to WAN Coax Stats to generate the WAN Coax Connection Status”
screen, which gives an overview of all the devices connected to the FiOS Router
via coaxial cable.
Using Network Connections
5.6 WAN PPPoE Connection
5
86
© 2011 Verizon. All Rights Reserved.
5.6 WAN PPPoE Connection
WAN Point-to-Point Protocol over Ethernet (PPPoE) relies on two widely
accepted standards: Point-to-Point Protocol and Ethernet. PPPoE enables
Ethernet networked computers to exchange information with computers on the
Internet. PPPoE supports the protocol layers and authentication widely used in
PPP and enables a point-to-point connection to be established in the normally
multipoint architecture of Ethernet. A discovery process in PPPoE determines
the Ethernet MAC address of the remote device in order to establish a session.
Click WAN PPPoE in the Network Connections screen to generate the “WAN
PPPoE Properties” screen. This screen displays a list of the connection’s
properties. The only modifications that can be made from this screen are
disabling the connection (by clicking Disable) or renaming the connection (by
entering a new name in the “Name” text box).
FiOS Router User Manual
87
© 2011 Verizon. All Rights Reserved.
5.6a Configuring the WAN PPPoE Connection
Click Settings in the WAN PPPoE Properties screen to generate another “WAN
PPPoE Properties” screen.
Using Network Connections
5.6 WAN PPPoE Connection
5
88
© 2011 Verizon. All Rights Reserved.
General
The top part of the screen displays general communication parameters. We
recommend not changing the default values in this section unless familiar with
networking concepts.
Status Displays the connection status of the WAN PPPoE connection. (“Down,
“Disabled, “Connected, etc.)
When should this rule occur? Displays when the rule is active. To schedule
rules, see Advanced Settings” chapter.
Network Select the type of connection being configured from the drop-down
list (Broadband Connection, Network (Home/Office), or DMZ).
Connection Type Displays the type of connection. Since this is PPPoE
connection, “PPPoE” is displayed.
MTU MTU (Maximum Transmission Unit) specifies the largest packet size
permitted for Internet transmission. Automatic, sets the MTU at 1492. Other
choices include Automatic, which sets the MTU according to the connection to
the ISP, and “Manual, which allows the MTU to be set manually.
Underlying Connection Specify the underlying connection above which
the protocol initiates from the drop-down list, which displays all possible
underlying devices.
PPP Configuration
Point-to-Point Protocol (PPP) is the most popular method for transporting
packets between the user and the ISP.
Service Name Specify the networking peer’s service name, if provided by the
ISP, in this text box.
On-Demand To use PPP on demand to initiate the point-to-point protocol
session only when packets are actually sent over the Internet, click in this check
box. This option should be active on a limited basis
FiOS Router User Manual
89
© 2011 Verizon. All Rights Reserved.
Idle Time Before Hanging Up Enter the amount of idle time, in minutes,
before the PPP session automatically ends .
Time Between Reconnect Attempts In this text box, specify the duration
between PPP reconnect attempts, as provided by the ISP.
PPP Authentication
Point-to-Point Protocol (PPP) currently supports four authentication
protocols: Password Authentication Protocol (PAP), Challenge Handshake
Authentication Protocol (CHAP), and Microsoft CHAP versions 1 and 2. Select
the authentication protocols the FiOS Router may use when negotiating with a
PPTP server in this section. Select all the protocols if no information is available
about the server’s authentication methods. Note that encryption is performed
only if Microsoft CHAP, Microsoft CHAP version 2, or both are selected.
Warning: The PPP Authentication settings should not be changed unless
instructed to do so by your ISP.
Login User Name Enter the user name (provided by the ISP) in this text box.
Login Password Enter the password (provided by the ISP) in this text box.
Support Unencrypted Password (PAP) Password Authentication Protocol
(PAP) is a simple, plain-text authentication scheme. The user name and
password are requested by the networking peer in plain-text. PAP, however,
is not a secure authentication protocol. Man-in-the-middle attacks can easily
determine the remote access client’s password. PAP offers no protection against
replay attacks, remote client impersonation, or remote server impersonation.
Support Challenge Handshake Authentication (CHAP) Click in this check
box to activate CHAP, a challenge-response authentication protocol that uses
MD5 to hash the response to a challenge. CHAP protects against replay attacks
by using an arbitrary challenge string per authentication attempt.
Support Microsoft CHAP Click in this check box if communicating with a peer
that uses Microsoft CHAP authentication protocol.
Support Microsoft CHAP Version 2 Select this check box if communicating
with a peer that uses Microsoft CHAP Version 2 authentication protocol.
Using Network Connections
5.6 WAN PPPoE Connection
5
90
© 2011 Verizon. All Rights Reserved.
PPP Compression
The PPP Compression Control Protocol (CCP) is responsible for configuring,
enabling, and disabling data compression algorithms on both ends of the
point-to-point link. It is also used to signal a failure of the compression/
decompression mechanism in a reliable manner.
For each compression algorithm (BSD and Deflate), select one of the following
from the drop-down list:
Reject Selecting this option rejects PPP connections with peers that use the
compression algorithm. If Reject is activated, throughput may diminish.
Allow Selecting this option allows PPP connections with peers that use the
compression algorithm.
Require Selecting this option insures a connection with a peer using the
compression algorithm.
Internet Protocol
Select one of the following Internet Protocol options from the “Internet Protocol”
drop-down list:
Obtain an IP Address Automatically This option is selected by default.
Change only if required by the ISP. The server that assigns the FiOS Router with
an IP address also assigns a subnet mask. Override the dynamically assigned
subnet mask by selecting the “Override Subnet Mask” and entering a different
subnet mask.
Use the Following IP Address Select this option to configure the FiOS Router
to use a permanent (static) IP address. The ISP should provide this address.
FiOS Router User Manual
91
© 2011 Verizon. All Rights Reserved.
DNS Server
The Domain Name System (DNS) is the method by which website or domain
names are translated into IP addresses. The FiOS Router can be configured
to automatically obtain a DNS server address, or the address can be entered
manually, according to the information provided by the ISP.
To configure the connection to automatically obtain a DNS server address, select
Obtain DNS Server Address Automatically from the “DNS Server” drop-down
list. To manually configure DNS server addresses, select Use the Following DNS
Server Addresses from the “DNS Server drop-down list. Up to two different
DNS server addresses can be entered (Primary and Secondary).
Routing
Routing Mode Select one of the following two Routing modes:
Route• - Select this option to cause the FiOS Router to act as a router between
two networks.
NAPT• - Select this option to activate NAPT (Network Address and Port
Translation), which refers to network address translation involving the
mapping of port numbers and allows multiple machines to share a single IP
address. Use NAPT if the local network contains multiple devices, a topology
that necessitates port translation in addition to address translation.
Device Metric The device metric is a value used by the FiOS Router to
determine whether one route is superior to another, considering parameters
such as bandwidth, delay, and more.
Default Route Click in this check box to define the connection as the
default route.
Multicast - IGMP Proxy Default Click in this check box to enable the FiOS
Router to issue IGMP (Internet Group Management Protocol) host messages
on behalf of hosts the FiOS Router discovers through standard IGMP interfaces.
IGMP proxy enables the routing of multicast packets according to the IGMP
requests of local network devices asking to join multicast groups.
Using Network Connections
5.6 WAN PPPoE Connection
5
92
© 2011 Verizon. All Rights Reserved.
Routing Table
Clicking New Route generates the New Route screen, where a new route can
be configured.
Internet Connection Firewall
Click in the “Enabled” check box to activate the FiOS Routers firewall on the
WAN PPPoE connection.
93
© 2011 Verizon. All Rights Reserved.
6
Conguring
Security
Settings
6.0 Introduction
6.1 Overview
6.2 Firewall
6.3 Access Control
6.4 Port Forwarding
6.5 DMZ Host
6.6 Port Triggering
6.7 Remote Administration
6.8 Static NAT
6.9 Advanced Filtering
6.10 Security Log
94
© 2011 Verizon. All Rights Reserved.
The FiOS Routers security suite includes
comprehensive and robust security
services: Stateful Packet Inspection, rewall
security, user authentication protocols, and
password protection mechanisms. These
features help protect users’ computers
from security threats on the Internet.
FiOS Router User Manual
95
© 2011 Verizon. All Rights Reserved.
6.1 Overview
This chapter covers the following security features:
Firewall• - select the security level for the firewall.
Access• Control - restrict access from the local network to the Internet.
Port• Forwarding - enable access from the Internet to specified services
provided by computers on the local network.
DMZ• Host - configure a network host to receive all traffic arriving at the FiOS
Router which does not belong to a known session.
Port• Triggering - define port triggering entries to dynamically open the
firewall for some protocols or ports.
Remote• Administration - enable remote configuration of the FiOS Router
from any Internet-accessible computer.
Static• NAT - allow multiple static NAT IP addresses to be designated to
devices on the network.
Advanced• Filtering - control the firewalls settings and rules.
Security• Log - view and configure the security log.
Conguring Security Settings
6.2 Firewall
6
96
© 2011 Verizon. All Rights Reserved.
6.2 Firewall
The FiOS Router’s firewall is the cornerstone of the FiOS Router’s security suite.
It has been exclusively tailored to the needs of the residential/office user and is
pre-configured to provide optimum security.
The firewall provides both the security and flexibility home and office users seek. It
provides a managed, professional level of network security while enabling the safe
use of interactive applications, such as Internet gaming and video-conferencing.
Additional features, including surfing restrictions and access control, can also
be configured locally through the FiOS Router’s GUI, or remotely by a
service provider.
The firewall also supports advanced filtering, designed to allow comprehensive
control over the firewall’s behavior. Specific input and output rules can be
defined, the order of logically similar sets of rules can be controlled, and
distinctions between rules that apply to Internet and local network devices can
be made.
The firewall regulates the flow of data between the local network and the
Internet. Both incoming and outgoing data are inspected and then either
accepted (allowed to pass through the FiOS Router) or rejected (barred from
passing through the FiOS Router) according to a flexible and configurable set of
rules. These rules are designed to prevent unwanted intrusions from the outside,
while allowing local network users access to required Internet services.
The firewall rules specify what types of services available on the Internet can
be accessed from the local network and what types of services available in the
local network can be accessed from the Internet. Each request for a service
the firewall receives, whether originating in the Internet or from a computer in
the local network, is checked against the firewall rules to determine whether
the request should be allowed to pass through the firewall. If the request is
permitted to pass, all subsequent data associated with this request (a session”)
will also be allowed to pass, regardless of its direction.
FiOS Router User Manual
97
© 2011 Verizon. All Rights Reserved.
For example, when accessing a website on the Internet, a request is sent out to
the Internet for this site. When the request reaches the FiOS Router, the firewall
identifies the request type and origin (HTTP and a specific computer in the local
network, in this case). Unless the FiOS Router is configured to block requests of
this type from this computer, the firewall allows this request to pass out onto
the Internet. When the website is returned from the web server, the firewall will
associate it with this session and allow it to pass, regardless of whether HTTP
access from the Internet to the local network is blocked or permitted.
Note that it is the origin of the request, not subsequent responses to this
request, which determines whether a session can be established or not.
6.2a General Screen
The “General” screen is used to configure the FiOS Router’s basic firewall settings.
Conguring Security Settings
6.2 Firewall
6
98
© 2011 Verizon. All Rights Reserved.
The FiOS Router features three pre-defined firewall security levels: Maximum,
Typical, and Minimum. The table below summarizes the behavior of the FiOS
Router for each of the three security levels.
Security Level
Internet requests
(incoming traffic)
Local network requests
(outgoing traffic)
Maximum
Security
Blocked - No access
to local network from
Internet, except as
configured in the Port
Forwarding, DMZ host, and
Remote Access screens.
Limited - Only commonly
used services, such as
web browsing and email,
are permitted.
Typical Security
Blocked - No access
to local network from
Internet, except as
configured in the Port
Forwarding, DMZ host, and
Remote Access screens.
Unrestricted - All
services are permitted,
except as configured in
the Access Control screen.
Minimum
Security
Unrestricted - Permits
full access from Internet
to local network; all
connection attempts
are permitted.
Unrestricted - All services
are permitted, except as
configured in the Access
Control screen.
These services include Telnet, FTP, HTTP, HTTPS, DNS, IMAP, POP3 and SMTP.
Note: Some applications (such as some Internet messengers and peer-to-peer
client applications) tend to use these ports if they cannot connect with their
own default ports. When applying this behavior, these applications will not be
blocked outbound, even at the Maximum Security level.
FiOS Router User Manual
99
© 2011 Verizon. All Rights Reserved.
To configure the FiOS Router’s firewall security settings:
From the General screen, select a security level by clicking the appropriate 1.
radio button. Using the Minimum Security setting may expose the local
network to significant security risks, and thus should only be used for short
periods of time.
Check the “Block IP Fragments box to protect the local network from 2.
a common type of hacker attack that uses fragmented data packets to
sabotage the network. Note that VPN over IPSec and some UDP-based
services make legitimate use of IP fragments. IP fragments must be allowed
to pass into the local network to use these services.
Click 3. Apply to save changes.
6.3 Access Control
Access control is used to block specific computers within the local network (or
even the whole network) from accessing certain services on the Internet. For
example, one computer can be prohibited from surfing the Internet, another
computer from transferring files using FTP, and the whole network from
receiving incoming email.
Access control defines restrictions on the types of requests that can pass from
the local network out to the Internet, and thus may block traffic flowing in both
directions. In the email example given above, computers in the local network
can be prevented from receiving email by blocking their outgoing requests to
POP3 servers on the Internet.
Access control also incorporates a list of preset services in the form of
applications and common port settings.
Conguring Security Settings
6.3 Access Control
6
100
© 2011 Verizon. All Rights Reserved.
6.3a Allow or Restrict Services
To view and allow/restrict these services:
Select 1. Access Control from the left side of any Security screen. The Access
Control screen appears.
Note: The Allowed” section is only visible when the firewall is set to “Maximum.
Click 2. Add. The Add Access Control Rule screen appears.
Note: To block a service, click Add in the “Blocked” section of the Access Control
screen. To allow outgoing traffic, click Add in the Allowed” section of the screen.
FiOS Router User Manual
101
© 2011 Verizon. All Rights Reserved.
If this access control rule applies to all networked devices, select 3. Any from
the “Networked Computer/Device list box. If this rule applies to certain
devices only, select User Defined and click Add. Then, create and add a
network object (for more details about adding network objects, see the
Advanced Settings” chapter of this manual).
Select the Internet protocol to be allowed or blocked from the “Protocol” 4.
drop-down list.
If the rule will be active all the time, select 5. Always from the When should
this rule occur?” drop-down list. If the rule will only be active at certain times,
select User Defined and click Add. Then, add a schedule rule (for more
details about schedule rules, see the Advanced Settings” chapter of
this manual).
Click 6. Apply to save the changes. The Access Control screen will display a
summary of the new access control rule.
Note: To block a service not included in the list, select User Defined from the
Protocol drop-down menu. The “Edit Service screen appears. Define the service,
then click OK. The service will then be automatically added to the top section of
the Add Access Control Rule screen, and will be selectable.
An access control can be disabled and the service made available without
having to remove the service from the Access Control table. This may be
useful to make the service available temporarily, with the expectation that the
restriction will be reinstated later.
To temporarily disable an access control, clear the check box next to the •
service name.
To reinstate the restriction at a later time, select the check box next to the •
service name.
To remove an access restriction from the Access Control table, click • Remove
for the service. The service will be removed from the Access Control table.
Conguring Security Settings
6.4 Port Forwarding
6
102
© 2011 Verizon. All Rights Reserved.
6.4 Port Forwarding
Activating “Port Forwarding allows the network to be exposed to the Internet
in certain limited and controlled ways, enabling some applications to work from
the local network (game, voice, and chat applications, for example), as well
as allowing Internet access to servers in the local network. To set this up on a
networked device, locate the device in the My Network column, then click Port
Forwarding. The “Port Forwarding screen appears.
To set up basic port forwarding:
Click the arrow next to “IP Address forward or select from menu to display 1.
a menu and either enter the IP address of the item to port forward from, or
choose an item from the drop-down menu.
Click the arrow next to Application to forward” and select a pre-configured 2.
application from the drop-down menu.
The selected applications forwarded port numbers appear at left, as shown 3.
in the figure below.
Click 4. Add. The new port forwarding rule appears in the Applied rules table
at the bottom of the screen.
Click 5. Apply at the bottom of the screen to apply the new rule.
FiOS Router User Manual
103
© 2011 Verizon. All Rights Reserved.
To set up advanced port forwarding:
Click the arrow next to “IP Address forward or select from menu to display 1.
a menu and either enter the IP address of the item to port forward from, or
choose an item from the drop-down menu.
Click the arrow next to Application to forward” and select a pre-configured 2.
application from the drop-down menu.
Click 3. Advanced. The advanced port forwarding options appear.
Select the connection with which this port forwarding rule will be active 4.
from the WAN Connection Type drop-down list.
To select a port to forward communications to (this is optional), select an 5.
option from the “Forward to Port” drop-down list. If a single port or range of
ports is selected, enter the port numbers in the text boxes that appear.
If this port will be active all the time, select Always from the “Schedule 6.
drop-down list. If the rule will only be active at certain times, select “User
Defined” and click Add. Then, add a schedule rule (for more details about
schedule rules, see the Advanced Settings” chapter of this manual).
Conguring Security Settings
6.5 DMZ Host
6
104
© 2011 Verizon. All Rights Reserved.
Click 7. Add to save the changes. The new port forwarding rule appears in the
Applied rules” table at the bottom of the screen.
Click 8. Apply at the bottom of the screen to apply the new rule.
Note: Some applications, such as FTP, TFTP, PPTP, and H323, require the support
of special specific Application Level Gateway (ALG) modules to work inside the
local network. Data packets associated with the aforementioned applications
contain information that allows them to be routed correctly. An ALG is needed
to handle these packets and ensure they reach their intended destinations. The
FiOS Router is equipped with a robust list of ALG modules, enabling maximum
functionality in the local network. The ALG is automatically assigned based on
the destination port.
6.5 DMZ Host
The DMZ (De-Militarized Zone) host feature allows one device on the network to
operate outside the firewall. Designate a DMZ host:
To use an Internet service, such as an online game or video-conferencing •
program, not present in the Port Forwarding list and for which no port range
information is available.
To expose one computer to all services without restriction or security. •
Warning: A DMZ host is not protected by the firewall and may be vulnerable
to attack. Designating a DMZ host may also put other computers in the
local network at risk. When designating a DMZ host, consider the security
implications and protect it if necessary.
To designate a local computer as a DMZ host:
Select 1. DMZ Host from the left side of any Security screen. The “DMZ Host
screen appears.
FiOS Router User Manual
105
© 2011 Verizon. All Rights Reserved.
Click in the “DMZ Host IP Address check box, then enter the IP address of 2.
the computer to be designated as a DMZ host. Note that only one network
computer can be a DMZ host at any time.
Click 3. Apply.
Click in the “DMZ Host IP Address check box again to disable the DMZ host.
6.6 Port Triggering
Port triggering can be described as dynamic port forwarding. By setting port
triggering rules, inbound traffic will be allowed to arrive at a specific network
host using ports different than those used for outbound traffic. When using port
triggering, the outbound traffic triggers the ports at which inbound traffic
is directed.
For example, a gaming server is accessed using UDP protocol on port 2222. The
gaming server then responds by connecting the user using UDP on port 3333
when a gaming session is initiated. In this case, port triggering must be used,
since it conflicts with the following default firewall settings:
The firewall blocks inbound traffic by default. •
The server replies to the FiOS Router’s IP, and the connection is not sent back •
to the host, since it is not part of a session.
To resolve the conflict, a port triggering entry must be defined, which allows
inbound traffic on UDP port 3333 only after a network host generated traffic to
UDP port 2222. This results in the FiOS Router accepting the inbound traffic from
the gaming server, and sending it back to the network host which originated
the outgoing traffic to UDP port 2222.
Conguring Security Settings
6.8 Static NAT
6
108
© 2011 Verizon. All Rights Reserved.
6.7b Web Management
Web Management is used to obtain access to the FiOS Routers GUI and gain
access to all settings and parameters, using a web browser. Both secure (HTTPS)
and non-secure (HTTP) access is available. Select the port to be used by clicking
in the appropriate text box, then click Apply.
Note: Telnet and Web Management remote administration access may be used
to modify or disable firewall settings. Local IP addresses and other settings can
also be changed, making it difficult or impossible to access the FiOS Router from
the local network. Therefore, remote administration access to Telnet or Web
Management services should be activated only when absolutely necessary.
6.7c Diagnostic Tools
Diagnostic Tools are used for troubleshooting and remote system management
by a user or the ISP.
Note: Encrypted remote administration is performed using a secure SSL
connection, and requires an SSL certificate. When accessing the FiOS Router
for the first time using encrypted remote administration, a warning appears
regarding certificate authentication because the FiOS Router’s SSL certificate is
self-generated. When encountering this message under these circumstances,
ignore it and continue. Even though this message appears, the self-generated
certificate is safe and provides a secure SSL connection.
6.8 Static NAT
Static NAT allows devices behind a firewall and configured with private IP
addresses appear to have public IP addresses on the Internet. This allows an
internal host, such as a web server, to have an unregistered (private) IP address
and still be accessible over the Internet. To configure static NAT:
Select 1. Static NAT from any Security screen. The “Static NAT screen appears.
FiOS Router User Manual
109
© 2011 Verizon. All Rights Reserved.
Click 2. Add. The Add NAT/NAPT Rule” screen appears.
Select a source address from the “Specify Address drop-down list in the 3.
“Local Host row, or enter a IP address in the text box to the right.
Enter the public IP address in the “Public IP Address text boxes.4.
Select the WAN connection type from the WAN Connection Type drop-5.
down list.
If using port forwarding, activate the “Enable Port Forwarding check box, 6.
then select a protocol from the “Protocol” drop-down menu.
Repeat these steps to add more static IP addresses from the network.
Conguring Security Settings
6.9 Advanced Filtering
6
110
© 2011 Verizon. All Rights Reserved.
6.9 Advanced Filtering
Advanced filtering is designed to allow comprehensive control over the firewalls
behavior. Specific input and output rules can be defined, the order of logically
similar sets of rules controlled, and distinctions made between rules that apply
to the Internet and rules that apply to local network devices.
To access, select Advanced Filtering from any Security screen. The Advanced
Filtering” screen appears.
Two sets of rules can be configured: input rules and output rules. Following is a
description of the set ordering for inbound and outbound packets.
FiOS Router User Manual
111
© 2011 Verizon. All Rights Reserved.
6.9a Inbound/Outbound Packets - Rule Sets
There are numerous rules automatically inserted by the firewall to provide
improved security and block harmful attacks. The pre-populated rules displayed
are required for operation on the Verizon network.
To configure advanced filtering rules, click Add next to the rule title. The Add
Advanced Filter screen appears.
To add an advanced filtering rule, define the following rule parameters:
6.9c Matching
To apply a firewall rule, a match must be made between IP addresses or ranges
and ports. Use the “Source Address and Destination Address drop-down lists
to define the coupling of source and destination traffic. Port matching will
be defined when selecting a protocol from the Protocol” drop-down list.. For
example, if the FTP protocol is selected, port 21 will be checked for matching
traffic flow between the defined source and destination IPs. If applicable,
activate the “DSCP, “Priority, and “Length check boxes.
Conguring Security Settings
6.9 Advanced Filtering
6
112
© 2011 Verizon. All Rights Reserved.
6.9d Operation
This is where the action the rule will take is defined. Select one of the following
radio buttons:
Drop• - Deny access to packets that match the source and destination IP
addresses and VCP reset to the origination peer.
Accept• - Allow access to packets that match the source and destination IP
addresses and protocol ports defined in upper section of the screen. The data
transfer session will be handled using Stateful Packet Inspection (SPI).
Accept Connection• - Allow access to connections that match the source and
destination IP addresses and protocol ports defined in upper section of
the screen.
Accept Packet• - Allow access to packets that match the source and
destination IP addresses and protocol ports defined in upper section of
the screen. The data transfer session will not be handled using Stateful
Packet Inspection (SPI), so other packets that match this rule will not be
automatically allowed access. This setting is useful when creating rules that
allow broadcasting.
6.9e Logging
Click in this check box to add entries relating to this rule to the security log.
6.9f Scheduler (When should this rule occur?)
If advanced filtering needs to be active constantly, select Always from the
“When should this rule occur?” drop-down list. If the rule will only be active at
certain times, select User Defined and click Add. Then, add a schedule rule (for
more details about schedule rules, see the Advanced Settings” chapter of
this manual)
FiOS Router User Manual
113
© 2011 Verizon. All Rights Reserved.
6.10 Security Log
The security log displays a list of firewall-related events, including attempts
to establish inbound and outbound connections, attempts to authenticate at
an administrative interface (the FiOS Router’s GUI or Telnet terminal), firewall
configuration, and system start-up.
To access the security log, select Security Log from any Security screen. The
“Security Log screen appears.
6.10a Time
The time (based on the FiOS Router’s date and time settings) the event occurred.
6.10b Event
There are three kinds of events listed in the system log: Firewall Info, Firewall
Setup, and System Log.
Conguring Security Settings
6.10 Security Log
6
114
© 2011 Verizon. All Rights Reserved.
6.10c Event-Type
The “Details column displays more information about the packet or the event,
such as protocol, IP addresses, ports, etc. The following are the available event
types that can be recorded in the security log:
802.1Q• - a 802.1Q (VLAN) packet has been accepted.
Access• control - a packet has been accepted/blocked because of an access
control rule.
Advanced Filter Rule• - a packet has been accepted/blocked because of an
advanced filter rule.
ARP• - an ARP packet has been accepted.
AUTH:113 request• - an outbound packet for AUTH protocol has been
accepted (for maximum security level).
Broadcast/Multicast protection • - a packet with a broadcast/multicast
source IP has been blocked.
Connection closed - • debug message regarding connection.
Connection opened• - debug message regarding connection.
Default• policy - a packet has been accepted/blocked according to the
default policy.
Defragmentation failed• - the fragment has been stored in memory and
blocked until all fragments have arrived and defragmentation can be
performed.
DHCP• relay agent - a DHCP relay packet has been received (depends on
the distribution)
DHCP• request - the FiOS Router sent a DHCP request (depends on
the distribution)
DHCP• response - the FiOS Router received a DHCP response (depends on
the distribution)
DMZ• network packet - a packet from a demilitarized zone network has
been blocked.
FiOS Router User Manual
115
© 2011 Verizon. All Rights Reserved.
Echo/Chargen/Quote/Snork protection• - a packet has been blocked due to
Echo/Chargen/Quote/Snork protection.
Error: No memory• - a new connection has not been established because of
lack of memory.
Firewall internal• - from the firewall internal mechanism, in case this event-
type is recorded, an accompanying explanation will be added.
Firewall rules were changed• - the firewall rule set has been modified.
Firewall status changed• - the firewall changed status from up to down or
the vice versa, as specified in the event type description.
First packet in connection is not a SYN packet• - a packet has been blocked
due to a TCP connection that started without a SYN packet.
Fragmented packet• - a fragment has been rejected.
Fragmented packet, bad align• - a packet has been blocked because, after
defragmentation, the packet was badly aligned.
Fragmented packet, header too big• - a packet has been blocked because,
after defragmentation, the header was too big.
Fragmented packet, header too small• - a packet has been blocked
because, after defragmentation, the header was too small.
Fragmented packet, no memory• - a fragmented packet has been blocked
because there is no memory for fragments.
Fragmented packet, overlapped• - a packet has been blocked because, after
defragmentation, there were overlapping fragments.
Fragmented packet, packet exceeds• - a packet has been blocked because,
after defragmentation, the packet exceeded.
Fragmented packet, packet too big• - a packet has been blocked because,
after defragmentation, the packet was too big.
FTP port request to 3rd party is forbidden (Possible bounce attack)• -
a packet has been blocked.
Conguring Security Settings
6.10 Security Log
6
116
© 2011 Verizon. All Rights Reserved.
ICMP Flood Protection• - a packet has been blocked, stopping an
ICMP (Internet Control Message Protocol) flood.
ICMP protection• - a broadcast ICMP message has been blocked.
ICMP redirect protection• - an ICMP redirected message has been blocked.
ICMP replay• - an ICMP replay message has been blocked.
IGMP• packet - an IGMP packet has been accepted.
Illegal packet options• - the options field in the packets header is either
illegal or forbidden.
IP Version 6• - an IPv6 packet has been accepted.
IPV6 over IPV4• - an IPv6 over IPv4 packet has been accepted.
Malformed packet: Failed parsing• - a packet has been blocked because it
is malformed.
Maximum security enabled service• - a packet has been accepted because
it belongs to a permitted service in the maximum security level.
Multicast• IGMP connection - a multicast packet has been accepted.
NAT Error: Connection pool is full. No connection created• - a connection
has not been created because the connection pool is full.
NAT Error: Conflict Mapping already exists• - a conflict occurred because
the NAT mapping already exists, so NAT failed.
NAT Error: No free NAT IP• - no free NAT IP, so NAT has failed.
NAT out• failed - NAT failed for this packet.
Outbound Auth1X• - an outbound Auth1X packet has been accepted.
Packet invalid in connection• - an invalid connection packet has been
blocked.
Parental• control - a packet has been blocked because of parental control.
Passive attack on ftp-server: Client attempted to open Server ports• - a
packet has been blocked.
FiOS Router User Manual
117
© 2011 Verizon. All Rights Reserved.
PPP Discover• - a PPP discover packet has been accepted.
PPP Session• - a PPP session packet has been accepted.
PPTP• connection - a packet inquiring whether the FiOS Router is ready to
receive a PPTP connection has been accepted.
Remote• administration - a packet designated for the FiOS Router
management has been accepted/blocked.
Router initiated traffic• - all traffic the FiOS Router initiates is recorded.
Service• - a packet has been accepted because of a certain service, as
specified in the event type.
Spoofing protection• - a packet from the Internet with a source IP belonging
the local network has been blocked.
STP packet• - an STP (Spanning Tree Protocol) packet has been
accepted/rejected.
SynCookies Protection• - a SynCookies packet has been blocked.
Trusted• device - a packet from a trusted device has been accepted.
UDP Flood Protection• - a packet has been blocked, stopping a UDP flood.
User• authentication - a message arrived during login time, including both
successful and failed authentication.
Wildcard connection hooked• - debug message regarding connection.
Wildcard connection opened• - debug message regarding connection.
WinNuke protection• - a WinNuke attack has been blocked.
Conguring Security Settings
6.10 Security Log
6
118
© 2011 Verizon. All Rights Reserved.
6.10d Details
Displays a textual description of the event.
6.10e Log Settings
The “Log Settings screen allows the user to modify the types of events that
appear in the FiOS Router’s Security Log. Note that these settings correspond to
event logging, not to the events themselves (i.e., disabling an event log removes
the event from the Security Log; the event itself will continue to occur).
To view or change the security log settings:
Click 1. Settings in the Security Log screen. The “Security Log Settings”
screen appears.
Select the type of activities that will generate a log message:2.
Accepted Incoming Connections• - activating this check box generates a log
message for each successful attempt to establish an inbound connection to
the local network.
Accepted Outgoing Connections• - activating this check box generates a
log message for each successful attempt to establish an outgoing connection
to the public network.
FiOS Router User Manual
119
© 2011 Verizon. All Rights Reserved.
Select the type of blocked events to be listed in the log:3.
All Blocked Connection Attempts• - activating this check box generates log
messages for all blocked events.
Other Blocked Events• - if All Blocked Connection Attempts is un-checked,
select specific blocked events from this list to generate log messages.
Click in the “Remote Administration Attempts check box to write a log 4.
message for each remote-administration connection attempt, whether
successful or not.
Click in the “Connection States check box to track connection handling by 5.
the firewall and Application Level Gateways (ALGs).
Click 6. Apply to save changes.
120
© 2011 Verizon. All Rights Reserved.
7
Using
Parental
Controls
7.0 Introduction
7.1 Activating Parental Controls
7.2 Rule Summary
121
© 2011 Verizon. All Rights Reserved.
The abundance of harmful information on
the Internet poses a serious challenge for
employers and parents alike: “How can I
regulate what my employee or child does
on the Internet?” With that question in
mind, the FiOS Routers Parental Controls
were designed to allow control of Internet
access on all locally networked devices.
Using Parental Controls
7.1 Activating Parental Controls
7
122
© 2011 Verizon. All Rights Reserved.
7.1 Activating Parental Controls
To create a basic access policy for a computer on the FiOS Router’s network, click
Parental Control from the top of the Home screen and follow these instructions:
The “Parental Control” screen appears. From the “Networked Computer/1.
Device list box, select a computer/device, then click Add. The computer/
device appears in the “Selected Devices” list box.
In the “Limit Access by section, select one of the following options:2.
Block the following Websites and Embedded Keywords within a Website•
- blocks all websites or keywords (see step 3) from being accessed on the
computers/devices selected in step 1.
A• llow the following Websites and Embedded Keywords within a
Website - allows access only to the websites or keywords (see step 3) on the
computers/devices selected in step 1.
Blocking ALL Internet Access• - blocks all Internet access on the computers/
devices selected in step 1.
FiOS Router User Manual
123
© 2011 Verizon. All Rights Reserved.
Enter the URL address of a website and, if applicable, the embedded 3.
keyword within the website. Click Add. The websites and/or keywords
selected will appear in the textbox to the right. If you make a mistake, or
wish to delete a previously entered website/keyword, select it, then
click Remove.
If needed, you can create a schedule for when you want the rule to be active, 4.
or inactive. In the “Create Schedule section, select the affected days.
Select whether the rule will be active or inactive during the schedule you 5.
created by clicking the radio button next to the appropriate option.
Using Parental Controls
7.2 Rule Summary
7
124
© 2011 Verizon. All Rights Reserved.
If you want more precise control over the schedule, set up an hourly 6.
schedule by entering the start and end times in the appropriate text boxes.
Make sure to specify AM or PM.
Note: The hourly schedule only affects the days selected in step 4. For example,
if you select Saturday and Sunday, a start time of 10 a.m., and an end time of 3
p.m., the scheduled time will be Saturday/Sunday, 10 a.m. to 3 p.m.
In the Create Rule Name section, enter a rule name and description in the 7.
appropriate text boxes.
Click 8. Apply to save and apply the new rule.
7.2 Rule Summary
Clicking Rule Summary from the menu on the left side generates the Rule
Summary” screen.
The Rule Summary screen displays a list of all rules created for the FiOS Router.
Additionally, the rule can be viewed by clicking the magnifying glass in the
View Rule” column, or edited by clicking on the icon in the “Edit Rule column.
125
© 2010 Verizon. All Rights Reserved.
8
Conguring
Advanced
Settings
8.0 Introduction
8.1 Using Advanced Settings
8.2 Utilities
8.3 DNS Settings
8.4 Network Settings
8.5 Conguration Settings
8.6 Time Settings
8.7 Firmware Upgrade
8.8 Routing Settings
126
© 2010 Verizon. All Rights Reserved.
The FiOS Routers Advanced Settings
cover a wide range of sophisticated
congurations available for the Routers
rmware and network. Changes to any of
the Advanced Settings could adversely
aect the operation of the FiOS Router and
the local network, and should be made
with caution by experienced network
technicians only.
FiOS Router User Manual
127
© 2010 Verizon. All Rights Reserved.
8.1 Using Advanced Settings
To access the FiOS Routers Advanced Settings, click Advanced at the top of
the Home screen. Click Yes in the Warning screen, and the Advanced”
screen appears.
The following settings are explained in this chapter:
Diagnostics• - perform diagnostic tests on the FiOS Router
Restore• Defaults - reset the FiOS Router to its default settings
Reboot• Router - restart the FiOS Router
MAC• Cloning - clone MAC addresses
ARP• Table - display active devices and their IP and MAC addresses, etc.
Users• - create and manage remote users
Quality of Service (QoS)• - explained in Appendix A of this manual
Local Administration• - allows the user to grant local Telnet access
Remote Administration• - explained in chapter 4 of this manual
Dynamic DNS• - configure Dynamic DNS settings
DNS Server• - manage the local (LAN) network for host name and IP address
Conguring Advanced Settings
8.1 Using Advanced Settings
8
128
© 2010 Verizon. All Rights Reserved.
Network Objects• - configure network object settings
Universal Plug and Play• - configure Universal Plug and Play settings
SIP ALG• - manage SIP ALG settings
MGCP ALG• - manage MGCP ALG settings
IGMP Proxy• - manage IGMP Proxy settings
Port Forwarding Rules• - manage and create open ports for various Internet
protocols or customize an application
Configuration File• - manage configuration files
System Settings• - modify the FiOS Routers system settings
Port Configuration• - configure the FiOS Routers ports
Date and Time• - configure the FiOS Routers clock and calendar
Scheduler Rules• - schedule firewall activation
Firmware Upgrade• - download and install new versions of the FiOS
Routers firmware
Firmware Restore• - install an older version of the FiOS Router’s firmware, or
reisntall the current firmware version
Routing• - manage routing policies
IP Address Distribution• - manage the IP addresses of devices on
the network
Conguring Advanced Settings
8.2 Utilities
8
130
© 2010 Verizon. All Rights Reserved.
8.2b Restore Defaults
If the FiOS Router’s factory default settings need to be restored (to build a new
network from the beginning, for example), use the following procedure:
Click 1. Restore Defaults in the Advanced screen. The Attention
screen appears.
If needed, click 2. Save Configuration File to save the FiOS Router’s current
configuration to a file. The FiOS Router’s current settings can then be
reapplied after restoring default settings (see “Configuration File in this
chapter for more information).
Click 3. Restore Defaults. The FiOS Router will restart, and factory default
settings will be applied
Note: All of the FiOS Router’s settings and parameters will be restored to their
default values after performing the Restore Default procedure. This includes the
administrator password; a user-specified password will no longer be valid.
8.2c Reboot the FiOS Router
To reboot the FiOS Router:
Click 1. Reboot Router in the Advanced screen. The “Reboot Router
screen appears.
Click 2. OK to restart the FiOS Router. This may take up to one minute.
To reenter the FiOS Router’s GUI after restarting the FiOS Router, click the web
browser’s “Refresh button.
FiOS Router User Manual
131
© 2010 Verizon. All Rights Reserved.
8.2d MAC Cloning
A MAC (Media Access Control) address is a hexadecimal code that identifies a
device on a network. All networkable devices have a unique MAC address. When
replacing another network device with the FiOS Router, the installation process
can be simplified by copying the MAC address of the existing computer to the
FiOS Router. To do this:
Click 1. MAC Cloning in the Advanced screen. The “MAC Cloning”
screen appears.
Enter the MAC address to be cloned in the To Physical Address text boxes. 2.
Click 3. Clone My MAC Address to capture the MAC address of the computer
currently accessing the FiOS Router’s GUI. The FiOS Router will now have the
new MAC address.
8.2e ARP (Address Resolution Protocol) Table
Clicking ARP Table in the Advanced screen generates the ARP Table screen.
This screen displays the IP and MAC addresses of each DHCP connection.
Conguring Advanced Settings
8.2 Utilities
8
132
© 2010 Verizon. All Rights Reserved.
8.2f Users
This screeen allows you to manage individual users. Additionally, you can enter
the maximum number of unsuccessful successive login attempts that can
be made before the FiOS Router temporarily disallows all login entries (enter
number in the appropriate text box).
To further manage users:
Click 1. Users in the Advanced screen, which generates the “Users” screen.
Click 2. New User, which generates the “User Settings screen.
FiOS Router User Manual
133
© 2010 Verizon. All Rights Reserved.
Specify the following parameters in the General” section of the screen: 3.
Full Name• - The users full name.
User Name• - The name a remote user will use to access the home or office
network. This entry is case-sensitive.
New Password/Retype New Password• - The password for the user (enter
again to confirm).
Permissions• - The level of access the user is allowed. Options include
Administrator or Limited.
E-mail Notification4. - Email notification can be used to receive indications
of system events for a predefined severity classification. The available types
of events are “System or “Security” events. The available severity of events
are Error, Warning, and Information. To configure email notification for a
specific user:
Make sure an outgoing mail server has been configured in “System Settings. 5.
If not, click Click Here to Configure Notification Mail Server to configure
the outgoing mail server.
Enter the user’s email address in the “Notification Address text box. 6.
Select the “System and “Security” notification levels in the “System Notify 7.
Level and “Security Notify Level” drop-down lists.
Note: Changing any of the user parameters will prompt the connection
associated with the user to terminate. For changes to take effect, activate the
connection manually after modifying user parameters.
8.2g Quality of Service
The FiOS Router’s QoS (Quality of Service) capabilities are covered in detail in
appendix A of this manual.
Conguring Advanced Settings
8.2 Utilities
8
134
© 2010 Verizon. All Rights Reserved.
8.2h Local Administration
Clicking Local Administration in the Advanced screen generates the “Local
Administration screen. This screen allows the user to grant local Telnet access
using a particular Telnet port.
To use, select a Telnet port by clicking in the appropriate check box, then
click Apply.
8.2i Remote Administration
The FiOS Router’s Remote Administration capabilities are covered in detail in the
chapter 6 of this manual.
FiOS Router User Manual
135
© 2010 Verizon. All Rights Reserved.
8.3 DNS Settings
The second section of the Advanced window is the DNS (Domain Name System)
settings section, which includes “Dynamic DNS” and “DNS Server.
8.3a Dynamic DNS
Dynamic DNS creates a dynamic IP address that is aliased to a static hostname,
allowing a computer on the network to be more easily accessible from the
Internet. Typically, when connecting to the Internet, the service provider assigns
an unused IP address from a pool of IP addresses, and this address is used only
for the duration of a specific connection. Dynamically assigning addresses
extends the usable pool of available IP addresses, while maintaining a constant
domain name. This allows the user to access a device (a camera, for example)
from a remote location, since the device will always have the same IP address.
When using Dynamic DNS, each time the IP address provided by the ISP
changes, the DNS database changes accordingly to reflect the change. In this
way, even though the IP address of the computer changes often, its domain
name remains constant and accessible.
Setting up Dynamic DNS
To set up Dynamic DNS on the FiOS Router, click Dynamic DNS in the Advanced
screen. When the “Dynamic DNS” screen appears, click New Dynamic
DNS Entry.
Conguring Advanced Settings
8.3 DNS Settings
8
136
© 2010 Verizon. All Rights Reserved.
Another Dynamic DNS screen appears.
Configure the following parameters:
Host Name
Enter the full Dynamic DNS domain in this text box.
Connection
Select the connection with which to couple the Dynamic DNS service. Options
include Broadband Connection (Ethernet), Broadband Connection (Coax),
and WAN PPPoE.
Provider
Select the FiOS Router’s Dynamic DNS account provider from the drop-down list.
User Name
Enter the Dynamic DNS user name in this text box.
Password
Enter the Dynamic DNS password in this text box.
FiOS Router User Manual
137
© 2010 Verizon. All Rights Reserved.
Dynamic DNS System
Select one of the options from the drop-down list.
Wildcard
Select the Wildcard” check box to allow any URL that includes the domain
name (“here.yourhost.dyndns.org, for example) to connect.
Mail Exchanger
Enter the mail exchange server address. This will redirect all emails arriving at
the Dynamic DNS address to the mail server.
Backup MX
Select this check box to designate the mail exchange server to be a
backup server.
Offline
Disable the Dynamic DNS feature by clicking this check box. This feature is
available only to users who have purchased some type of upgrade credit from
the Dynamic DNS provider. Note that changing the redirection URL can only be
performed via the Dynamic DNS provider’s website.
Conguring Advanced Settings
8.3 DNS Settings
8
138
© 2010 Verizon. All Rights Reserved.
SSL Mode
If the Dynamic DNS service chosen supports SSL, select the SSL mode from the
drop-down menu (options: None, Chain, Direct).
To edit the host name or IP address of an entry:
Click the appropriate “Edit” icon in the Action column. The “DNS Entry 1.
screen appears.
If the host was manually added to the DNS Table, its host name and/or IP 2.
address can be modified. Otherwise, only modify its host name.
Click 3. Apply to save the changes.
To remove a host from the DNS table, click the appropriate “Delete icon in the
Action column. The entry will be removed from the table.
8.3b DNS Server
The Domain Name System (DNS) translates domain names into IP addresses,
and vice versa. The FiOS Router’s DNS server is an auto-learning DNS, which
means that when a new computer is connected to the network, the DNS server
learns its name and automatically adds it to the DNS table. Other network users
can immediately communicate with this computer using either its name or its
IP address.
The FiOS Routers DNS also provides the following services:
shares a common database of domain names and IP addresses with the •
DHCP server;
supports multiple subnets within the local network simultaneously;•
automatically appends a domain name to unqualified names; •
FiOS Router User Manual
139
© 2010 Verizon. All Rights Reserved.
allows new domain names to be added to the database using the FiOS •
Router’s GUI;
permits a computer to have multiple host names; •
and permits a host name to have multiple IPs (needed if a host has multiple •
network cards).
The DNS server does not require configuration. However, the list of computers
known by the DNS can be viewed or a new computer can be added to the list.
DNS Table
To view the list of computers stored in the DNS table, click DNS Server in the
Advanced screen. The “DNS Server screen appears.
To add a new entry to the list:
Click 1. Add DNS Entry in the DNS Server screen. The “DNS Entry
screen appears.
Enter the computer’s host name in the “Host Name text box.2.
Enter the computer’s IP address in the IP Address text boxes. 3.
Click 4. Apply to save the changes.
Conguring Advanced Settings
8.4 Network Settings
8
140
© 2010 Verizon. All Rights Reserved.
8.4 Network Settings
The Network Settings section of the Advanced screen includes settings that
affect the FiOS Routers network.
8.4a Network Objects
Network objects is used to define a part of the FiOS Routers network (a group
of computers, for example) by MAC addresses, IP addresses, and/or host names.
The defined part becomes a “network object, and settings, such as configuring
system rules, can be applied to all devices defined as part of the network object
at once. For example, instead of setting the same website filtering configuration
to five computers one at a time, the computers can be defined as a network
object, and website filtering configuration can then be applied to all the
computers simultaneously.
Network objects can be used to apply security rules based on host names
instead of IP addresses. This may be useful, since IP addresses change from
time to time. Moreover, it is possible to define network objects according to
MAC addresses, making rule application more persistent against network
configuration settings. To define a network object:
Click 1. Network Objects in the Advanced screen. The “Network Objects”
screen appears.
FiOS Router User Manual
141
© 2010 Verizon. All Rights Reserved.
Click 2. Add. The “Edit Network Object” screen appears.
Specify a name for the network object in the “Description” text box. 3.
Click 4. Add. The “Edit Item screen appears.
Select the type of network object type from the “Network Object Type list 5.
box. Options include IP address, IP Subnet, IP Range, MAC Address, Host
Name, and DHCP Option.
Repeat to create other network objects, if needed. When finished, click 6.
Apply to save all created network objects.
Conguring Advanced Settings
8.4 Network Settings
8
142
© 2010 Verizon. All Rights Reserved.
8.4b Universal Plug and Play (UPnP)
To access the UPnP settings, perform the following:
Click 1. Universal Plug and Play in the Advanced screen. The “Universal Plug
and Play settings screen appears.
Click in the Allow Other Network Users to Control Wireless Broadband 2.
FiOS Router’s Network Features check box to enable UPnP and allow UPnP
services to be defined on any of the network hosts.
Click in the “Enable Automatic Cleanup of Old Unused UPnP Services check 3.
box to enable automatic cleanup of invalid rules. When enabled, this feature
checks validity of all the UPnP services and rules every five minutes. Any
old and unused UPnP defined service is removed, unless a user defined rule
depends on it. Since there is a maximum limitation on the number of UPnP
defined services (256), enable the cleanup feature if the limit is in danger of
being exceeded.
If applicable, in the “WAN Connection Publication drop-down list, select 4.
one of the publishing options (Publish Only the Main WAN Connection or
Publish All WAN Connections)
UPnP services are not deleted when disconnecting a computer without proper
shutdown of the UPnP application (e.g., messenger). Thus, services may often
not be deleted,. This will eventually lead to exhaustion of rules and services, and
no new services can be defined. In this scenario, the cleanup feature will find the
invalid services and remove them, preventing services exhaustion.
FiOS Router User Manual
143
© 2010 Verizon. All Rights Reserved.
8.4c SIP ALG
This screen allows the user to enable/disable SIP ALG. It is disabled by default.
Do not enable this option unless instructed to do so by the ISP.
8.4d MGCP ALG
This screen allows the user to enable/disable MGCP ALG. It is disabled by
default. Do not enable this option unless instructed to do so by the ISP.
Conguring Advanced Settings
8.4 Network Settings
8
144
© 2010 Verizon. All Rights Reserved.
8.4e IGMP Proxy
This screen allows the user to configure various IGMP proxy settings.
IGMP Proxy (Enable/Disable)
Activate or deactivate IGMP Proxy by clicking on the down arrow and selecting
Enabled or Disabled.
IGMP Version
Select the IGMP Proxy version by clicking on the down arrow and selecting
IGMPv1, IGMPv2, or IGMPv3.
Fast Leave
Activate or deactivate Fast Leave by clicking on the down arrow and selecting
Enabled or Disabled.
Robustness
Select the level of robustness by entering a number greater than or equal to 1.
FiOS Router User Manual
145
© 2010 Verizon. All Rights Reserved.
IGMP Proxy (Enable/Disable)
Activate or deactivate IGMP Proxy by clicking on the down arrow and selecting
Enable or Disabled.
Query Interval
Set the query interval here. The entered time period (in seconds) must be
greater than or equal to 1.
Query Response Interval
Set the query response interval here. The entered time period (in seconds) must
be greater than or equal to 1.
Unsolicited Report Interval
Set the unsolicited report interval here. The entered time period (in seconds)
must be between 1 and 25.
Persistent Join Interval
Set the persistent join interval here. The entered time period (in seconds) must
be between 1 and 25.
Interface Multicast Filtering
Clicking Interface Multicast Filtering from the menu on the left side of any
IGMP Proxy screen generates the Interface Multicast Filtering screen. Set the
Interface Multicast Filtering options for each listed interface (Ethernet, Coax, and
Wireless Access Point). When finished, click Apply.
Conguring Advanced Settings
8.4 Network Settings
8
146
© 2010 Verizon. All Rights Reserved.
Host Multicast Filtering
Clicking Host Multicast Filtering from the menu on the left side of any
IGMP Proxy screen generates the Host Multicast Filtering screen. Set the Host
Multicast Filtering options here. Clicking on the Action icon generates another
screen in which the host entry options can be entered. When finished,
click Apply.
ACL Multicast Filtering
Clicking ACL Multicast Filtering from the menu on the left side of any IGMP
Proxy screen generates the ACL Multicast Filtering screen. Set the ACL Multicast
Filtering options in this screen, including activating whitelists and/or blacklists.
Clicking Add generates a new screen in which additional addresses can be
added to the list(s). When finished, click Apply.
Conguring Advanced Settings
8.4 Network Settings
8
148
© 2010 Verizon. All Rights Reserved.
8.4f Port Forwarding Rules
Port forwarding rules include a list of preset and user-defined applications and
common port settings. These rules can be used in various security features, such
as Access Control and Port Forwarding. New rules can be added to support new
applications or existing ones can be edited when needed. Additionally, clicking
Advanced on the bottom of the “Port Forwarding Rules screen reveals a list
of preconfigured protocols that can be activated with a single click. To define a
port forwarding rule:
Click 1. Port Forwarding Rules in the Advanced screen. The “Port Forwarding
Rules screen appears.
Click 2. Add at the bottom of the screen. The “Edit Service screen appears.
FiOS Router User Manual
149
© 2010 Verizon. All Rights Reserved.
Name the service in the “Service Name text box and, if needed, enter a 3.
description of the service in the “Service Description text box, then click
Add Service Ports. The “Edit Service Server Ports screen appears.
Select a protocol from the “Protocol” drop-down list. To create a new 4.
protocol, select “Other. After selecting a protocol, the screen will refresh,
displaying the relevant text boxes needed to edit the particular protocol.
Click 5. Apply to save the changes.


Specyfikacje produktu

Marka: Verizon
Kategoria: router
Model: MI424WR

Potrzebujesz pomocy?

Jeśli potrzebujesz pomocy z Verizon MI424WR, zadaj pytanie poniżej, a inni użytkownicy Ci odpowiedzą




Instrukcje router Verizon

Instrukcje router

Najnowsze instrukcje dla router