Home
Draytek Vigor3300V
Contents
1. Tagged Tagged Untagged Port Setting P1 P2 P3 P4 Port VLANID 5 B f 6 Apply Reset Cancel 7 After applying the settings the web page will be redirected to reboot web page User can ignore it and continue to configure the Network setting After finishing Network setting you can execute the reboot procedure 8 After rebooting the tagged ports will communicate with 802 1Q tagged devices only 9 The network configuration is the same with A 2 1 Please refer to A 2 1 part Vigor3300 Series User s Guide 171 D r ay Te k 5 1 7 Example for Trunk Usage A company wants to separate the Engineer Department Sales Department Marketing Department and other departments to limit their communication with each other to ensure the security Many employees of the company use some switches supported 802 1Q VLAN to expand the network In this case we can define four VLANs that are VLAN5 VLANO VLAN7 and VLANS Each LAN port is Trunk port which supports multiple VLAN The subnet of VLANS is 192 168 1 0 the subnet of VLANO is 192 168 2 0 the subnet of VLAN7 is 192 168 3 0 and the subnet of VLANS is 192 168 4 0 LAN 192 168 1 0 192 168 2 0 192 168 3 0 192 168 4 0 VLANS VLANS VLANS VLANS VLANG VLANG VLAN6 VLAN6 VLANT VLANT LANT VLANT VLANS VLANS LANS VLANS aum hr FAR auri byrne aurgip byrne aum hp FAR B02 1Q B02 1Q Trun switch Trunk Sw
2. 35 INS VO SU o REN EE OUT 38 3 2 1 WAN and Internet Access Setup ssseesssssssseeeeeene nennen nennen nnns 38 2079 For si irie imoe M 47 o2 oA Lodd BSIdllGO cu tiende ott En PE ee ene ene nee um DEM Mn E ip MU UAE 49 coo d 49 3 2 4 High Availapility seeds dmideuense uU ccE EEEE UMEN USE 53 32 5 ai GNIS FIEzii o RET 55 3 2 6 Bandwidth Management cccsceccccsseeeeeceeeeeeeeeseeeseeseceseeeeeseeeeeesseeeessegeeesneeeeenseeeeeeas 56 SAN LAMM 11 011 MR 58 3 3 Advanced Setup ssssssssisssssseeeeeee nennen nnnnnnn nnn n nnns nnne enini riis sssaa sinn s riis s snas arisen rens 60 ee Ne UE FOLIO LU 9 REN CENTER TE 61 oL NAT o teres cis E EE E E E E E E E PH 62 oO ec re as E R E E E R 68 POPO BIO SEEN EE 70 2O DDNS SEUD T r sesanasaateasebe 70 Dr ay Tek iv Vigor3300 Series User s Guide 3 320 Gall Schedule STUD ERROR OPE Tm 73 3 3 7 WAN Port Mirroring Setup cccccccesscessececcecsseeeeesscseeeeeseceneeesscassneeesscaseeeeesscseeees 74 3 3 8 LAN Port Mirroring SOTU 6 iisceceinexmnataccnsdewsnnedsteisusonnntusdadsesnectunsnadtnddeenaeeneetanaedneabastadsiwouseres 76 aI FLANVLAN SGUD eo goss cose teats 76 eNO INI c E 79 3 4 Firewall Setup ccccccccssssecccccsseececceeeeeeecseausececc
3. Basic Profile Status Enable v Name Research Authentication Preshared Key v Preshared Key eeece Security Protocol ESP sj NAT Traversal Enable v Local Gateway WAN Interface WAN1 v Lacal Certificate Security Gateway default Network IP Subnet Mask 172 15 3 228 s 24 i Next hop default Remote Gateway Remote ID DHCP over IPSec OFF wv Security Gateway 1 2152 0 0 0 0 for dynamic client Network IP Subnet Mask 172 16 2 15 11132 0 0 0 0 32 for dynamic client Apply Cancel Profile Status Set the initialization of IPSec Tunnel with this profile settings Enable Choose this one to invoke this profile manually In addition to select Enable you have to click Initiate under the page of VPN IPSec Tunnel Policy Table Always On Choose this one to invoke this profile automatically by the system for every 30 seconds Disable Choose this one to inactivate this profile Pr file Status Enable Alwayz n Name The name for VPN connection ex VPN1 The maximum length of name is 20 characters including spaces Authentication The authentication to be used by PreShared Key or RSA Signature Authentication Prezhared Key Preshared Key RSA Signature PreShared Key The shared key for peer identification The maximum length is 40 characters includi
4. Member P1 Frame Tag Operation P2 P3 P4 Tagged Tagged Tagged Tagged Tagged Tagged Tagged Tagged Tagged Tagged Tagged Tagged Tagged _ Enable management port for P4 Port Setting P1 P2 P3 P4 Port VLANID 5 e 7 f8 Apply Reset Cancel 7 After applying the settings the web page will be redirect to reboot web page User can ignore it and continue to configure the Network setting After finishing Network setting you can execute the reboot procedure 8 After rebooting the tagged ports will communicate with 802 1Q tagged devices only 9 The network configuration is the same with A 2 1 Please refer to A 2 1 Dray Tek Vigor3300 Series User s Guide 169 5 1 6 Example for A Company and Guest A company wants to separate the Engineer Department Sales Department Marketing Department and guest to limit their communication with any department to ensure the security In this case we can define four VLANs that are VLAN5 VLAN6 VLAN and VLANS The subnet of VLANS is 192 168 1 0 the subnet of VLANO is 192 168 2 0 the subnet of VLAN7 is 192 168 3 0 and the subnet of VLANS is 192 168 4 0 However the notebook of guest does not support 802 1Q 192 168 1 0 192 168 2 0 192 168 3 0 192 168 4 0 COS sx z E Lz E 5 auri b Engineer Department sales Marketing Depa
5. Status Display current VoIP registering status and calling status VolP Status Pitiesh Cantine Fo ieren meae Salus Call Stans ED w CP Um e wh x g gt PS Packets Sri Dray Te k 182 550 13 P H H OS Oct Seni PR FEacheM Recbpwed COR Ochk Recened PL Pakete og Ji ieramen Fsbrraiermael LA Bag Ta Dr ebayi Vigor3300 Series User s Guide 5 2 5 VolP Examples There are many different kinds of applications about VoIP function Most of VoIP callings must be via a VoIP Server by registering except we can dial VoIP number by the IP address directly We will set up a basic configuration and registration as an example 1 The other examples might be revised based on this example The VoIP function mainly depends on the requirement and application All the examples are based on example 1 to revise configuration in accordance with the usage requirement and application Example 1 Basic Configuration and Registration Example 2 Basic Calling Method Example 3 VoIP over VPN Example 4 Practical Application of FXS Example 5 Practical Application of FXO 5 2 6 Example 1 Basic Configuration and Registration In this case 3300V uses a FXS card and a FXO card with four groups of iptel numbers and fwd numbers respectively The Codec is G 729A WAN IP address is 220 135 240 207 2900V has two VoIP Ports with an iptel number and the fwd number respectively The Codec is G 729A B WAN IP is 61
6. IP Made simply click Next to setup LAN interface Quick Setup LAN DHCP Relay LAN IP DHCP Fu IP Routing IP Configuration IP Address 182 158 1 1 Subnet Mask 255 255 255 0 DHCP Server Status SEnable ODisable Relay Agent Primary DNS Secondary OMS Lease Time thin 440 lll Gateway IPrOptional lt lt Previous Finish IP Address Assign an IP address for the LAN interface Subnet Mask Assign the subnet mask for the LAN interface Status Click Enable to use DHCP server click Disable to close DHCP server click Relay Agent to activate relay agent function Start IP Assign the start IP address of the IP pool that DHCP server can use for clients in LAN End IP Assign the end IP address of the IP pool that DHCP sever can use for clients in LAN Primary DNS Type the IP address for primary DNS Vigor3300 Series User s Guide 17 Dr ay Te k Secondary DNS Assign a private IP address to the secondary DNS Lease Time Min Set a lease time for the DHCP server The time unit is minute Gateway IP Optional Set a gateway IP address for the DHCP server Next click DHCP Relay Agent tab to set DHCP server if required Quick Setup LAN DHCP Relay Relay Agent WAN Interface VANI w DHCP Server IP Address Previous Finish WAN Interface Choose the WAN interface for such connection DHCP Server IP Address Assign an IP address for th
7. Outgoing Class Filter For the web pages for incoming class setup and outgoing class setup incoming class filter and outgoing class filter are similar they will be explained in the same sections 3 5 1 Incoming Outgoing Class Setup Incoming Outgoing Class Setup allows you to configure bandwidth percentage for data and voice signals transmission Click the QoS option and choose Incoming Class Setup Outgoing Class Setup There are eight queues that can be configured The total sum of bandwidth has to be 100 percent for all configured queues Any leftover bandwidth is assigned to eight queues to meet 100 percent totally QoS Incoming Class Setup O Disable 9 Enable Index Class Name Bandwidth 1 others oc Apply Cancel Clear All Disable Enable Click Disable to close this setting Click Enable to activate this setting Index It represents the number for each queue Class Name Please type the name for each queue Bandwidth Please type the usage percentage for each queue Apply Click this button to apply all the settings set in this page 3 5 2 Incoming Outgoing Class Filter Click the QoS option and choose Incoming Class Filter Outgoing Class Filter Dr ay Te k 98 Vigor3300 Series User s Guide QoS Incoming Class Filter Priority Source IP OO0oO0o000000909 Priority Source IP Destination IP Service Type Status DiffServ CodePoint Status Class Edit Delete Del
8. After restore the factory default setting you can configure the settings for the router again to fit your personal request 4 6 Contacting Your Dealer If the router settings are correct at all and the router still does not connect to internet please contact your ISP technical support representative to help you for configuration Also if the router still cannot work correctly please contact your dealer for help For any further questions please send e mail to support draytek com Dr ay Te k 156 Vigor3300 Series User s Guide 5 Application Notes 5 1 Application for 802 1 VLAN 5 1 1 Block LAN to LAN Communication To control the communication of PCs among different network segments effectively please adjust firewall setting to deny LAN to LAN communication from Firewall gt IP Filter Group Table Thus PCs that belong to various LANs will not connect with each other through the router To a company with several departments such feature is useful for it to determine data sharing among different departments 1 Open Firewall gt IP Filter Group Table to access into the following page Click Index 2 radio button Firewall IP Filter Group Table IP Filter Group Table Index Group Name Next Group Comment d Pass Black Group for pass rules O 2 Block none Group for block rules Add Edit Delete 2 Inthis page click Add Rule Choose Block as Next Group Name Firewall IP Filter Table Next G
9. Vigor3300B Ta i 1 n Ong M vigor3300 prey Ter vigor3300 A OvayTe Your reliable networking solutions partner User s Guide V3 0 Vigor 3300 Series Multi WAN Security Router User s Guide Version 3 0 Date 1 4 2009 Dr ay Te k ii Vigor3300 Series User s Guide Copyright Information Copyright Copyright 2009 AII rights reserved This publication contains information that is Declarations protected by copyright No part may be reproduced transmitted transcribed stored in a retrieval system or translated into any language without written permission from the copyright holders The scope of delivery and other details are subject to change without prior notice Trademarks The following trademarks are used in this document Microsoft is a registered trademark of Microsoft Corp e Windows Windows 95 95 Me NT 2000 XP and Explorer are trademarks of Microsoft Corp Apple and Mac OS are registered trademarks of Apple Inc Other products may be trademarks or registered trademarks of their respective manufacturers Vigor3300 Series User s Guide iii Dr ay Te k Table of Contents uite M c 1 1 1 LED Indicators and Connection seeeeeessssssssessesseseeeeeennnnn nennen nennen nennen nnn nnns 2 1 1 1 LED Indicators and Connectors for Vigor3300V ssseeeeeeessseeeeeeernnnneennnnnnn 2 1 1 2 LED I
10. Set other IP addresses binding in this interface You can set up to 32 sets of IP alias settings If you have typed addresses here you can see and choose it in later web page settings e g Advanced gt gt NAT gt gt Port Redirection DMZ Host Assign an interval time for detecting if the WAN connection is on or off 44 Vigor3300 Series User s Guide No Reply Count Apply Reset Assign detecting times to ensure the connection of the WAN After passing the times you set in this field and no reply received by the router the connection of WAN interface will be regarded as breaking down Click Apply to go back to the WAN Interface Configuration page To apply all settings click Apply on the WAN Interface Configuration page and reboot your router Click this button to clear all the configurations for this page PPTP with a DSL Modem Setup The service provider must provide the exact settings for this mode Static DHCP DMZ Configuration Configuration Configuration User Name 1234 hinet net PPTP Local Address 10 66 99 88 Password esce PPTP Subnet Mask 255 255 255 0 Authentication P P v PPTP Server Address 172 66 99 88 Service Name PPPoE IP Alias Enable MTU 4 442 IP Address Assignment Method IPCP Fixed IP 9 No Dynamic IP O Yes Fixed IP Address Connection Detection Detect Interval 40 No Reply Count 2 User Name
11. V3300 LAN 192 168 1 0 192 168 2 0 192 168 3 0 192 168 4 0 diri L sug by rog aue bp zog aung hr Company A Company B Company C Company D Procedure 1 Refer to A 1 to block LAN to LAN communication 2 Create VLANS VLAN6 VLAN7 and VLANS Groups 3 Inthe VLANS type 5 to VLAN ID In the Member field choose pl Then choose the Tagged for Frame Tag Operation in pl We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from the PC of company A 4 Inthe VLANO type 6 to VLAN ID In the Member field choose p2 Then choose the Tagged for Frame Tag Operation in p2 We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from company B 5 Inthe VLAN7 type 7 to VLAN ID In the Member field choose p3 Then choose the Dray Tek Tagged for Frame Tag Operation in p3 We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from the PC of company C 168 Vigor3300 Series User s Guide 6 In the VLANS type 8 to VLAN ID In the Member field choose p4 Then choose the Tagged for Frame Tag Operation in p4 We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from company D Advanced LAN VLAN Setting O Disable Port Base VLAN 9 802 10 VLAN Port Base 02 10 vian VLAN 802 1Q VLAN Group Index Active Name VLAN ID
12. RJ 45 Blue Ethernet switch or hub Held e Eg a O 9 Ethernet DMZ RJ 45 Blue Server Ethernet WANI RJ 45 Blue DSL Cable Fiber Modem Ethernet WAN2 RJ 45 Blue DSL Cable Fiber Modem Ethernet WAN3 RJ 45 Blue DSL Cable Fiber Modem Ethernet WANA RJ 45 Blue DSL Cable Fiber Modem Vigor3300 Series User s Guide 7 Dr ay Te k 1 2 Hardware Installation Before starting to configure the router you have to connect your devices correctly l Connect the power cord to the power port of Vigor3300 router on the rear panel and the other side into a wall outlet Power on the device by pressing the power switch on the rear panel The PWR LED should be ON The system starts to initiate After completing the system test the ACT LED will light up and start blinking Connect one end of an Ethernet cable RJ 45 to one of the LAN ports of Vigor3300 Connect the other end of the cable RJ 45 to the Ethernet port on your computer that device also can connect to other computers to form a small area network The LAN LED for that port on the front panel will light up Connect a server modem router depends on your requirement to any available WAN port of the device with Ethernet cable RJ 45 The WAN LED will light up Connect telephone sets to the FXS ports of Vigor3300V with telephone lines RJ 11 to RJ 11 For the users of Vigor3300 and Vigor3300B please skip this step Connect the FXO ports to
13. type any number here Network Interface Select an interface WANI to WANA to be forwarded to Strict Bind Packets fitting the above settings can be routed through the selected interface only Check this box to invoke this function Dr ay Te k 48 Vigor3300 Series User s Guide 3 2 3 Auto Load Balance Because the network between China Telecom and China CNC are disconnected such function is designed to do auto load balance and separate the packets among China Telecom China CNC and other regions via different WAN interfaces For example if you check WANI and WAN4 for China Telecom packets belong to China Telecom will pass through the specified WAN interfaces only and load balance will be done between WANI and WANA Network Auto Load Balance Auto Load Balance 9 Disable WAN1 China Telecom F China CNC F Other Traffic Auto Load Balance China Telecom China CNC Other Traffic 3 2 4 LAN O Enable WAN 2 WAN3 WAN4 CJ F d d Apply Cancel Choose Enable to invoke the auto load balance function for your devices A telecom company A telecom company Regions that are not belonged to China Telecom and China CNC In the Network group select LAN option The following page for LAN IP DHCP will be shown Vigor3300 Series User s Guide 49 Dr ay Tek Network LAN DHCP Relay LAN IP DHCP Been IP Configuration IP Routing IP Address 182 158 1 1 Subnet Mask 255 255 255
14. CSC Type the starting IP address The default group value is 192 168 1 224 28 Select the value of subnet mask for the Start IP Type the accessed IP address Select the value of subnet mask for the Accessed IP This page allows you to set up to 30 sets of accounts VPN User Profile Profile Status 9 09 9939 0909 9 Profile Status User Name Group Edit Vigor3300 Series User s Guide User Name Group 1 Edit Delete Delete All Display status disable or enable for this entry The user name for this entry The group for this entry Allow you to edit the selected group Type in user name and password then choose a proper group A B C or D that configured in VPN gt gt PPTP amp L2TP gt gt Group Table for this 123 Dray Tek entry Next click Apply VPN User Profile Edit Delete Allow you to remove the selected group Delete All Allow you to remove all of the groups When you finish the configuration please click Apply to invoke it Status This page displays some relevant information about PPTP connection It will refresh automatically every 10 seconds VPN Status CI p D H CNN UI MN m Q 1 5131162252 192 168 1 224 3300 1280 74 E Refresh Disconnect Index Display the index number of the tunnel Remote IP Display remote IP address of the tunnel Assigned IP Display IP address assigned by Vigor3300 User Display user account of this tunnel Byte In Display the by
15. routing information 3 2 Network Setup For Internet access it is necessary for you to set WAN and LAN interfaces for the router C WAN b Load Balance Policy Auto Load Balance c LAN 7 High Availability RIP Configuration Bandwidth Management k Limit Session 3 2 1 WAN and Internet Access Setup The Vigor3300 Series supports four WAN interfaces Static DHCP PPPoE and PPTP which share the same setting page In the Network group please click the WAN option The following page will be shown Note Vigor3300 3300V supports four WAN interfaces yet Vigor3300B supports three WAN interfaces That is WANZ4 will be disabled for Vigor3300B Dr ay Te k 38 Vigor3300 Series User s Guide Network WAN Load Balance ODisable 9 Enable Auto Weight Backup 9 Disable Enable Edit IP Mode Active Default Route LoadBalance Weight ee Backup Slave VolP WANT Static 50x WAN2 Static 30 vj O WANS PPPoE 20 v O WAN4 PPTP o Apply Cancel Load Balance Enables or disables the WAN load balance function The Auto Weight option becomes available if Enable mode is selected Load Balance allows the router distributing data in and out of the Internet by using different WAN interfaces at the same time Backup Enables or disables backup function for WAN interfaces If you enable this function the backup master backup slave will execute the job of master slave devic
16. s Guide In the Advanced group move to NAT option and choose DMZ Host to get the corresponding page Advanced NAT DMZ Host WAN Interface Private IP Use IP Alias IP Alias 1 WAN 192 168 1 10 Disable 2 3 06 4 0 P 6 7 8 O g 10 O 1 Edit Delete Delete All WAN Interface Display the WAN interface chosen for this entry Private IP Display the private IP address of this entry Use IP Alias Display the activation status enable or disable of this DMZ host IP Alias Display the WAN IP address Edit Allow users to edit the selected DMZ host settings Delete Delete All Remove one all the selected DMZ host settings To edit an item click the radio button of the item that you want to modify Then click Edit on the bottom of the page to add a new rule entry or modify an existed rule entry WAN Interface VAN1 w Private IP 20 1 1 1 Use IP Alias 9 Disable Enable IP Alias Apply Cancel WAN Interface Select a WAN interface as the channel for DMZ host Private IP Assign an IP address of DMZ server to be permitted for access from outside Use IP Alias Disable option uses WAN interface Enable option uses IP Alias addresses IP Alias Select an IP address which are set within the list of IP Alias configured in Network gt gt WAN interface Vigor3300 Series User s Guide 67 Dr ay Te k Apply Click Apply to reboot the system and apply the settings Common Ports List This page lists
17. IP Address Subnet Mask LAN Interface DHCP Relay IP Routing Enable O Disable Agent 110 1 1 3 255 255 255 0 O Enable 9 Disable OEnable 9 Disable O Enable 9 Disable Apply Cancel Click Enable or Disable to activate or close the IP routing of specific WAN interface Type an IP address for the WAN interface WANI WAN2 W AN3 W ANA Type the subnet mask for the WAN interface WANI WAN2 W AN3 W AN4 Select a proper LAN interface for WAN interface WANI WAN2 W AN3 W AN4 Note Vigor3300V supports four WAN interfaces yet Vigor3300 Vigor3300B support three WAN interfaces That is W ANA will be disabled for Vigor3300 Vigor3300B Dray Tek 52 Vigor3300 Series User s Guide 3 2 4 High Availability The High Availability HA feature refers to the awareness of component failure and the availability of backup resources The complexity of HA is determined by the availability needs and the tolerance of system interruptions Systems that provides nearly full time availability typically have redundant hardware and software that makes the system available despite failures The high availability of the V3300 Series is designed to avoid single points of failure When failures occur the failover process moves processing performed by the failed component the Master to the backup component the Slave This process remains sy
18. Location Unknown Device status This device is working properly IF yau are having problems with this device click Troubleshoot to start the troubleshooter Troubleshoot Device usage Use this device enable w Dr ay Te k 162 Vigor3300 Series User s Guide 11 Next time if you want to check VLAN setting again please open Settings tag to modify it Intel R PRO 100 S Desktop Adapter VLAN VLAN5 P 7 X General Settings Advanced Driver intel Virtual LAN Settings Remove WLAN VLAN Hame WLANE Untagged WYLAN Associated adapter IntellR PR07100 8 Desktop Adapter Properties VLAN ID Type a ney number for the YLAN in the VLAN ID box The VLAN ID must match the VLAN ID configured on the switch a HOTE 4 LAM ID of 1 is often reserved Check the g amp wvitch documentation for details Vigor3300 Series User s Guide 163 Dr ay Te k 5 1 3 Four VLANs for Different Departments in A Company A company wants to separate the Engineer Department Sales Department Marketing Department and Other Department to limit their communication with each other to ensure the security In this case we can define four VLANs that are VLAN5 VLAN6 VLAN7 and VLANS The subnet of VLANS is 192 168 1 0 the subnet of VLANO is 192 168 2 0 the subnet of VLAN7 is 192 168 3 0 and the subnet of VLANS is 192 168 4 0 However each PC in the company does not support 802 1Q 19
19. Port 1 FXS Disable Enable Username 1001 Password LIII Display Name 1001 Authentication ID 1001 Proxy Server none v Call without Registration 9 Disable Enable Play dial tone only when port o registered VoIP IP Address W N v Hotline Hatline Number to Internet Hotline Number to PBX PSTN p delay 1 8sec FXO Manual Disconnection Codec Preferred Codec G 729 8kbps v Single Codec Fi Codec Rate 20 v ms Codec VAD 9 Disable O Enable CAS Microphone Gain o Range 32 31 Speaker Gain D Range 32 31 FAX FAX Mode T 38 Relay v FAX Bypass Codec FAX Bypass Codec Rate ms DTMF DTMF Mode InBand OutBand RFC2833 SIPINFO Cisco DTMF Volume 27 Range 0 31 Call Forwarding Disable O Call forwarding all calls O Call forwarding busy Call forwarding no answer ater rings Range 1 10 SIP URL ti C SCSF Example 8001 iptel org Call Waiting 9 Disable Enable CLIP Display Disable 9 Enable Apply Cancel Port 1 FXS Click Enable to activate this port or Disable to close this port User Name Type the user name a number for each phone line Password Type the user password for each phone line Display Name Type the user name to be displayed on another phone terminal Authentication ID Type the cha
20. Role Virtrual IP Virtrual IP LANS LAN4 High Availability Disable O Enable High Availability Disable Enable Group Number Range 1 255 Group Number Range 1 255 Role Role Virtrual IP Virtrual IP Apply Cancel High Availability Disables or enables this function When the master device fails down the slave device will take its work over Group Number Assign a group number The range is from 1 to 255 PCs on the same group in LAN can support for each other Role Select a role for this device as Master or Slave Virtual IP Assign an IP address as a virtual IP Click Apply to reboot the system and apply the settings 3 2 5 RIP Configuration The Routing Information Protocol RIP is a dynamic routing protocol used in local and wide area networks The routing information packet will be sent out by web server or router periodically and can be used to communicate with other routers It will calculate the number of network nodes on the route to ensure there is no obstruction on the network routine In addition 1t will choose a correct route based on the method of Distance Vector Routing and use the Bellman Ford algorithm to calculate the routing table RIP can update the routing table automatically and find a route to send packet See the following figure as an example Vigor3300 Series User s Guide 55 Dr ay Te k Mg 000 ee Ges WAN1 WAN2 WANS or WAN4 EN JUNE geraauuv Support RIP S
21. There are several proposals offered in this page with combination of three types of algorithms Encryption algorithms DES 3DES AES Authentication algorithms MD5 SHA1 DH Diffie Hellman Group MODP768 MODP1024 MODP1536 Proposal dez mdb5 moadp 68 hal LLL LLL XX dez mdb5 moedmn h58 dez mdb5 moedp1ll za4 dez mdb5 moedpib538 dez zha modp 68 dez zha modpiu 4 dez zha modplb53 amp 3dez mdb5 modp amp 58 3dez mdb5 moedp1il z4 3dez mdb5 modpib38 Jdez zha modp amp 58 3dez zha modp1ll z4 jdez zha modplib536 aezlz8 mdb modp 858 aezlz8 mdb modpmpi 4 aezlz8 mdb modpib53 amp aezl28 sha modp amp 58 aezlz8 zha modpli 4 aezlz8 zha modpib53 amp Dr ay Te k 112 Vigor3300 Series User s Guide Key Lifetime quick The renegotiated period of the IKE Phase2 keying channel The acceptable range is from 5 to 1440 minutes 24 hours Proposal quick The proposed encryption and or authentication algorithms for IKE Phase2 negotiations There are 2 options Encryption algorithms NULL DES 3DES AES Authentication algorithms MD5 SHAI Accepted Proposal If you choose Only accept proposal listed above only the selected proposal will be accepted and applied by this device If you choose Accept all supported proposal all the proposals supported by this device will be accepted and applied Accepted Proposal Accept all supported proposal Only accept proposal listed above gt Accept all supported proposal
22. dPort Displaysthe destination port of the packet replied e Select Data Flow Monitor to get the following page This page displays the running procedure for the IP address monitored and refreshes the data in an interval of several seconds System Diagnostic Tools Data Flow Monitor 9 Disable Enable Refresh Seconds 10 Index IF Address TX rate Kbpaz 7 RX rate Kbpaz MAT sessions Action Hote Refresh 1 Click Block ta prevent specified PC from surfing Internet far 5 minutes 2 The IP blocked by the router will be shown in red and Action column will display the expire time lett Disable Enable Click Enable to invoke this function Index Display the number of the data flow IP Address Display the IP address of the monitored device Vigor3300 Series User s Guide 37 Dr ay Te k TX rate kbps Display the transmission speed of the monitored device RX rate kbps Display the receiving speed of the monitored device Sessions Display the session number that you specified in Limit Session web page Action Block can prevent specified PC accessing into Internet within 5 minutes Unblock the device with the IP address will be blocked in five minutes The remaining time will be shown on the session column Refresh Seconds Use the drop down list to choose the time interval of refreshing data flow that will be done by the system automatically Refresh Click Refresh to re display this web page for getting newest
23. i T Cii Maier Caes Panier Simi Time Ament RTP Pari KIP Saitetic T Perled wan Fri Note This page will automatically refresh every 6 second so as to display the latest status You may click Refresh button to renew immediately Configuration Example for Vigor2900V 1 Open the Web of 2900V and click VoIP Setup Vigor2900V Sen Firmecsre Verglon lt i 56 Broadband Se zt rt Build DaberTima Wed May 25E8 5423 55 2005 MHP Aer A LAN MSC Address DD 50 7F 28 T2 13 Basic Setup Quick Setup gt Quick Start Wizard gt Informal Accoss Satup Administrator Passwonl Setup Virtual TA Remote CAPI Setup LAN TCPAP and DHCP S amp tup ISOM Setup Advanced Setup System Management Dynamic DNS Setup Online Status Call Control and PPP MP Setup Call Schedule Satu NAT Setup i Log Mail Alert Seh RADIUS Setup Time Setup Static Route Setup Management Setup a IP Filter Firewall Setup Diagnostic Tools VPN and Remote Access Setup Reboot System UPNP Service Setup Firmware Upgrade TFTP Serve ValP Setup VLAN Rate Control QoS Control Setup Capgyrigiht 2 2004 Drayiok Cp Al Agit Eararcad Vigor3300 Series User s Guide 187 Dr ay Te k Dray Tek Click SIP Related Functions Setup Tone Settings Voice Call Status Setup Port and Port2 This page falls into two sections SIP Setup relevant SIP Servers used for registration respectively Ports Type account and pass
24. 0 DHCP Server Gateway IPrOptianal Status Enable ODisable O Relay Agent Primary DNS Secondary ONS Lease Time Min For LAN IP DHCP Apply Cancel In the Vigor3300 Series router there are some IP address settings for the LAN interface The IP address subnet mask is for private users or NAT users The IP address of the default gateway on other local PCs should be set as the Vigor3300 Series server IP address When the DSL connection between the DSL and the ISP has been established each local PC can directly route to the Internet The IP address subnet mask can also be used to connect to other private users PCs On this page you will see the private IP address defined in RFC 1918 Usually we use the 192 168 1 0 24 subnet for the route IP Address Subnet Mask Status Start IP End IP Primary DNS Secondary DNS Lease Time Min Gateway IP Optional Dray Tek Type the IP address for LAN DHCP Type the subnet mask for the LAN IP DHCP Click Enable the DHCP server click Disable to close DHCP server click Relay Agent to close DHCP sever and do the job of DHCP server Corresponding settings for Relay Agent can be configured in the page of DHCP Relay Agent Set the starting IP address of the IP address pool for DHCP Server Set the ending IP address of the IP address pool for DHCP server Set the private IP address of the primary DNS Set the private IP address of the secondary
25. 1 1 1 Basic settings in Vigor 3300V and 2900V 3300V 220 135 240 207 Pori Exs Issgs33 liie G 7294 Port2 FxS 888834 iper c 729A Por3 FxS e60533 fiwa cocoa IPort4tFXS 660534 lia G 7294 Ponsexo sessss iper c 729A eecexo ssss36 iper c 729A Port7 EXO 660525 lia G 7294 posxo esosoe twa oza NEN Codec iptel iptel org iptel org 5060 fwd pulver com fwd pulver com 5060 Vigor3300 Series User s Guide 183 Dr ay Te k Configuration Example for Vigor3300V l Dray Tek Enter VoIP Protocol page and configure related settings on SIP Configuration VolP Protocol F EO Ac Ce Pony Proxy Address Pray Peri Pagesirar Adi petra Enpias Dnieuin P ox FHI Sex z inte pil ang TEJ iptal org TEN 3 piel arng E fed Ma pubes Cm BET fend puhit caen An XX Len paler Cm Exampin ipial ipie org ple ery piston Apply Cancel Enter VoIP Port Settings page click the Edit icon of port 1 VoIP Port Settings Fas Act a igi I ed ed ES Priory Caie m Ma Fea m m m len Vie Enter the Port 1 page This page falls into six sections Port FXS Display the port type enable or disable the port setup the account etc Disable or Enable By default is Enable Username amp Password Type the registrar s account 888833 and password Display Name Display incoming call s information To facilitate ease differentiation please type 3300
26. A6 24 05 Al1 Add and Edit Mac Address Lj L LH Add Edit Remove Apply Cancel Enable Click this radio button to invoke this function However IP MAC which is not listed in IP Bind List also can connect to Internet Disable Click this radio button to disable this function All the settings on this page will be invalid Strict Bind Click this radio button to block the connection of the IPPMAC which is not listed in IP Bind List ARP Table This table is the LAN ARP table of this router The information for IP and MAC will be displayed in this field Each pair of IP and MAC address listed in ARP table can be selected and added to IP Bind List by clicking Add below Add and Edit IP Address Type the IP address that will be used for the specified MAC address Mac Address Type the MAC address that is used to bind with the assigned IP address Refresh It is used to refresh the ARP table When there is one new PC added to the LAN you can click this link to obtain the newly ARP table information IP Bind List It displays a list for the IP bind to MAC information Vigor3300 Series User s Guide 95 Dr ay Te k Add It allows you to add the one you choose from the ARP table or the IP MAC address typed in Add and Edit to the table of IP Bind List Edit It allows you to edit and modify the selected IP address and MAC address that you create before Remove You can remove any item listed in IP Bind List Simply cl
27. ARI IM e M e d l l un l lei m dla sleim O en 8 After you click OK the system will configure for the VLAN settings Please wait for several seconds New VLAN VLAN Name VLAN 5 Untagged VLAN VLAN ID Ctm PE Bi Configuring Please wait Cancel Vigor3300 Series User s Guide 161 D r ay Te k 9 When the configuration is finished the new VLAN settings with ID number and name will appear on previous dialog Desktop Adapter Properties Click OK to exit this dialog Intel R PRO 100 S Desktop Adapter Properties x Boot Agent Driver Resources Power Mana jement General Link Advanced Teaming VLANs intel Virtual LANs VLANs associated with this adapter VLAN Mame Status YLANS Enabled Remove Modify Allows you to configure up to 64 virtual LANs YLANS for an adapter Adapters with YLANs must be connected to network devices that support the IEEE 802 10 specification When you configure the WYLAN oS Packet Tagging is automatically enabled x NOTE After creating the VLAN the adapter associated withthe WYLAN briefly loses network connectivity 10 Now the Desktop Adapter VLAN dialog will appear as follows Please click OK Intel R PRO 100 5 Desktop Adapter VL AM VLAM5 P EE General Settings Advanced Driver Eu Intel R PR07100 5 Desktop Adapter WLAN VLAN5 Device type Network adapters Manufacturer Intel
28. Dray Tek Refresh Display the IP address of the static DHCP server Display the MAC address of the static DHCP server Display the remaining time for this IP address assigned by DHCP server When the time expired such IP address would not be kept for this client and might be assigned to other client Click Refresh to re display this web page for getting newest routing information 36 Vigor3300 Series User s Guide Select View NAT Active Sessions Table to get the following page This table can display about 30000 sessions with 20 pages System DIENOS Toons View MAT DeHv Sess EB 0000 unn top 591 ESTABLISHED 192 168 1 222 207 46 6 24 3435 1863 207 46 6 24 172 16 2 225 1863 34682 tcp 598 ESTABLISHED 132 168 1 222 207 466 153 3476 1863 207 466 153 172 16 2 2258 1863 34723 Page index 125 45578910 11 121919151617 16 18 20 Type Display the protocol used for the active session Expire in Display the remaining time second of this session State Display the condition of this session Source IP Display the source IP address of the packet transmitted Dest IP Display the destination IP address of the packet transmitted sPort Display the source port of the packet transmitted dPort Display the destination port of the packet transmitted Rep Source IP Display the source IP address of the packet replied Rep Dest IP Display the destination IP address of the packet replied sPort Display the source port of the packet replied
29. Enable management part far P4 S S S ws Port Setting P1 P2 P3 P4 Apply Reset Cancel 7 After applying the settings the web page will be redirected to reboot web page User can ignore it and continue to configure the Network setting After finishing Network setting you can execute the reboot procedure 8 After rebooting the tagged ports will communicate with 802 1C tagged devices only 9 The network configuration is the same with A 2 1 Please refer to A 2 1 part Vigor3300 Series User s Guide 173 Dr ay Te k 5 2 Application for VoIP 3300V has two expansion slots each slot can be plugged into one 4 port VoIP card The VoIP card involves two kinds of interface FXS and FXO You can deploy different VoIP applications according to the requirements 5 2 1 FXS and FXO FXS Foreign eXchange Station and FXO Foreign eXchange Office are assembled with a pair A telecommunications line from an FXO device must be connected to an FXS device similarly an FXS device must be connected to an FXO device For example PSTN is FXS equipment and a telephone is FXO equipment Telephone Telephone FXO FXO Dr ay Te k 174 Vigor3300 Series User s Guide As for the Private Branch Exchange PBX it is more special because it has both FXS and FXO devices at the same time Outside lines of the PBX are usually connected to the phone line at this case the PBX acts as FXO equipment inside lines of the
30. Guide 3 1 2 Time As an NTP Network Time Protocol client the router gets standard time from the time server Some time based functions such as Call Schedule and URL Content filtering cannot work properly until the system time functions run successfully Typically NTP achieves high accuracy and reliability with multiple redundant servers and diverse network paths The Vigor3300 Series supports synchronization with a specific NTP server or the remote PC host of the administrator In the System group click the Time option The Time page is shown below System Time NTP Server Time Zone GMT 00 00 Greenwich Mean Time Dublin v Daylight Saving Time 9 NotUse Ouse Update Interval 30 seconds v Apply Cancel Use Browser Time Click this option to use the browser time from the remote administrator PC host as router s system time Use NTP Time Click this option to use the time from an NTP server as router s system time NTP Server Assign a public IP address or domain name of the NTP server Time Zone Select the time zone where the Vigor3300 1s located Daylight Savings Time Select Use to activate this function This function is useful for some areas Update Interval Select a time interval for updating from the NTP server Apply Click Apply to save these settings Vigor3300 Series User s Guide 21 Dr ay Te k 3 1 3 Syslog The Vigor3300 Series supports a Syslog function to keep a record of abnor
31. M de spend De te JOS eee Lus Merc nun i Usaia dg Tone Seninge PC 100 My MAT Trees VW Ux roomy Cal Barring ty Du faris FX GA Sake Codec 7298 kite 3 TIBA Ships Y 720A Shes 3 T2BA Ships TIRA HE 2 F284 Shops TOI Skips T29A Gips Vigor3300 Series User s Guide Port Settings Port Edit Configure related VoIP settings for each port respectively VoIP Port Settings Porti Edit Part 1 FXO CT Dexabig 19 Enable Llame Patr Cimla Hamet Fico Doner WolP TP Aides Hetlin amp Hobies Hare ta Inigmet Hefte barier Ka Pier E PST FX hana Cisc n fia cl n Codec Figtasad Cadac Codec Fate Codec SAD CAS Enea Th Tan Fox Fax Mida FAX Ewzazs Cup FA Beror Caper AHE OTF OTF Frio Call Forwarding Diae CT Calfareardirg al cats 2 C cal fireardin busy Woot m nat nons mi TAH LU gt Damini 229A kbps am je iri r heahea C3 Fnahin n Flan pa 32 3t a janpe 53 31 Tin Heise w C Hrab W RFC2E33 CI Bl INFO ClCalfreandrngnpanzesrafer O O 5ngsiFange 1 10 SIP LIL Vigor3300 Series User s Guide Exam pee 3 DO d s pied og 179 Apply Canca Dray Tek Speed Dial Setup the Speed Dial Phone numbers this function is more convenient to dial extension number or IP address There are 150 entries available at most Quick Setup System Firewall Gof VPN Ad
32. Optional Set a gateway IP address for the DHCP server When you finished the above settings please click Finish A system reboot page will appear Dray Tek 22 Vigor3300 Series User s Guide 3 Adva nced Configuration After finished basic configuration of the router you can access Internet with ease For the user who wants to adjust more setting for suiting his her request please refer to this chapter for getting detailed information about the advanced configuration of this router 3 1 System setup For the system setup there are several items provided for you to configure Status Time Setup Syslog Setup Access Control Setup Reboot and Firmware Upgrade Setup Diagnostic Tools and Configuration Setup pa Access Control PA Change Password Configuration o Firmware Upgrade lt Reboot Diagnostic Tools 3 1 1 Status The online Status function provides some useful system information on the current status of the Vigor3300 Series A user can observe the system status on this Web page and determine which setting needed to be changed in corresponding web pages In the System group click the Status option The online Status Web page contains three parts Basic Status LAN Status and WAN Status Refresh Option Ho Refrezh v Refresh Ho Refresh Basic Status LAN Every 10 Seconds Every 20 Seconds Every 30 Seconds LY Model Wigor Refresh Option You can choose to refresh the Web page in
33. PABX with telephone lines RJ 11 to RJ 11 For the users of Vigor3300 and Vigor3300B please skip this step Below shows an outline of the hardware installation for your reference take Vigor3300V as an example 29 TT Power Cable H Vigor3300 V MultiService Security Uo P ML Dray Tek qm AS A FOMANIEAG B 90 0990909 9099 rm r ome OOOH OBOE End m 9 205009972029 Dy anA n ann ks zd DSL Cabel Fiber Modem DSL Cabel Fiber Modem DSL Cabel Fiber Modem ISPr Wizard Server 8 Vigor3300 Series User s Guide 1 2 1 Detailed Explanation for the Connector Here provides you detailed explanation for some specific connectors that you have to be familiar The RS232 Connector The RJ45 connection jet is used for CLI commands for system configuration and control functions in the Vigor3300 Series The jet is used for initialization of the Vigor3300 Series during preliminary installation The management cable as shown in Figure 1 5 converts the RJ45 to the RS232 interface The RJ45 jet connects to a console interface in the Vigor3300 Series while the RS232 DB9 connects to a console port on the computer The default setting of the console port is baud rate 57600 no parity and 8 bit with 1 stop bit DB 9 Connector RJ 45 Connector Standard 10 100 Base T Ethernet Interface Connector RJ45 jets provide 10 100 Base T Ethernet interfaces The interface supports MDI MDI
34. Port Redirection means port forwarding It may be used to expose internal servers to the public domain or open a specific port to internal hosts Internet hosts can use the WAN IP address to access internal network services such as FTP WWW and etc The internal FTP server is running on the local host addressed as 192 168 1 2 When other users send this type of request to your network through the Internet the router will direct these requests to an appropriate host inside A user can also translate the port to another port by configuration For example port number with 1024 can be transferred into IP address of 192 168 1 100 of LAN The packet is forwarded to a specific local host if the port number matches that defined in the table In the Advanced group move to NAT option and choose Port Redirection to get the corresponding page Advanced NAT Port Redirection Profile Public Port Public Port Private Private Use IP WAN Status E TET End PURUS Port Start PortEnd Alias Interface P Alias 1 Enable Test UDP 88 150 192 168 1 153 88 150 Disable WANT 2 O t 0 O 6 T O 9 10 1 Delete Delete All Profile Status Display the status enabled or disabled of this profile Comment Display the name of the entry Protocol Display the protocol used for the entry Public Port Start Display the start point in the range of public port Public Port End Display the end point in the range of public port Private IP Display the priva
35. Te k VPN Trunk Group Table Vigor3300 series allows users to configure policies In addition it also allows users to combine several policies into one group for VPN usage Each group can combine four policies for fitting different requirement of VPN application Simply click VPN gt gt VPN Trunk gt gt Group Table to access into the following page There are ten groups offered for users to configure VPN VPN Trunk Group Table Profile Status Name Local Subnet Remote Subnet 09000 0 0 00 65 10 1 Edit Delete Delete All Edit Configure an entry Clicking this button can guide you accessing into editing page for that group For detailed information refer to the following section of For Default Configuration Delete Delete a designated entry Delete All Delete all entries in the table To edit or add a group table please click one of the radio buttons and click Edit The default configuration will be shown as below Dr ay Te k 114 Vigor3300 Series User s Guide VPN VPN Trunk Group Table Edit Profile Status O Disable 9 Enable Mame Local Subnet Remote Subnet Tunnel 1 Tunnel 2 Tunnel 3 Tunnel 4 lt Backup Profile Status Name Local Subnet Remote Subnet Tunnel 1 Tunnel 4 Weight Active Master Slave Weight Weight Weight Weight Apply Cancel Set the initialization of IPSec Tunnel with this pr
36. The Vigor3300 Series supports the restore and upload functions of the configuration files In the System group click the Configuration Setup option And you can see the following page System Configuration Restore pO 1L 1 Backup Backup configuration file Push Backup button Backup Select a Configuration File Please click the Browse button to find out the location of the configuration file to be uploaded to the router and click Apply Backup Configuration File Download the configuration file to a local host The default Push Backup Button file name is v3300 cfg Dr ay Te k 30 Vigor3300 Series User s Guide 3 1 6 Firmware Upgrade Setup Vigor3300 Series allows users to upgrade firmware through a Web interface In the System group click the Firmware Upgrade option You can see the following page then Before you execute the firmware upgrade please download the newest firmware from Draytek s website www draytek com or FTP site ftp draytek com on the computer first System Firmware Upgrade Caution After an upgrade procedure a rebootis required Current Version Vigor3300V 2 5 8 7 EN Location 9Local O Remote Firmware TFTP Server IP Remote File Name Apply Cancel Caution Display a caution for your reference Current Version Display current firmware version that you are using Location Local means upgrade firmware from browser Remote means upgrade firmware from a remote TF
37. a port number for Trap server using Apply Click Apply to save this setting and return the previous page Dr ay Te k 82 Vigor3300 Series User s Guide 3 4 Firewall Setup The firewall controls the allowance and denial of packets through the router The Firewall Setup in the Vigor 3300 Series mainly consists of packet filtering Denial of Service DoS and URL Universal Resource Locator content filtering facilities These firewall filters help to protect your local network against attack from outsiders A firewall also provides a way of restricting users on the local network from accessing inappropriate Internet content and can filter out specific packets which may trigger unexpected outgoing connection such as a Trojan The following sections will explain how to configure the Firewall Users can select General Setup IP Filter DoS and URL Filter options from Firewall menu The DoS facility can detect and mitigate the DoS attacks The URL Filter can block inappropriate websites for SME IP Filter Dos ww URL Filter Bind IP to MAC General Setup c Group Table A IM P2P Blocking 3 4 1 IP Filter First you should create at least one Group in the IP Filter gt gt Group Table Then you can enable the Data Filter and select a Start Filter Group in General Setup The following sections explain IP Filter functions with details General Setup The page allows you to set general settings such as enab
38. address the VoIP traffics must pass through the upper layer NAT router User can enable STUN function in order to make VoIP function can work smoothly Ouick Setup ff yatem Hetarik Advanced Foewali Es VolP HAT Traversal k HAT Trawersal k E BL LM fo t t eh Cos RT a z Alii iad H i Ed F Addita is Th E ru ee TIL k JAT E i J c i i Symmetric Media 22 Disable ayrmmenetric ATP ani T Enahis severneiic ATP a HAT Status Ape Cancel Note The upper layer router must forward the UDP packets which port number are 5060 13456 13470 and 49170 49184 to the WAN IP address of 3300V Incoming Call Barring Set This function can receive or reject the specific VoIP calling via Internet The rules are based on the speed dial number or IP Domain Vigor3300 Series User s Guide 181 D r ay Te k oe tarini VoIP Incoming Call Barring Set T Mar h Method Disable Enable ham a Fan ted OR l Dhebie E sblb IPrDOom an Berni nd from xj T Mx Cancel Call History It can display 50 groups of calling information ar VoIP Call History m Petesh Option fc Befrech W Matre E fone Satia Member Type Hambar Mamba S Tana d Time Duration s si Type Pored VAD Palay PS Pockets Gert OS Octet Gert PE Pacues Bersed OF Oc eiz BFecereed PL Parker Mgr LA amp eg TE Claes Cee Tek My d Ceay Tek prades anctmrpsge nacwecsew paladan
39. and the following associate HTTP request will be blocked The system will discard any request which tries to retrieve the malicious code Notice that you must clear your browser cache first so that the URL content filter operates properly on a Web page that you visited before Dr ay Te k 90 Vigor3300 Series User s Guide The URL content filter consists of the following functions URL Access Control Content Filter Restrict Web Feature and Filter Schedule URL Access Control The URL Access Control controls Web site access by inspecting the URL string against user defined keywords In the Firewall group click the URL Filter option You will see the following page Firewall URL Filter Filter Schedule Block websites with matching keywords O Allow websites with matching keywords Keyword 000 Add Edit Delete O Disable 9 Enable URL Access l Content Filter Access Control by keyword Festrict veh Feature keyword List Block Direct IP Web Access Black Direct IP Web Access Exception List Enable Exception List PAddress Subnetmask Edit Delete Exceptian List MEM Apply Cancel Enable Disable Disable or Enable URL Filter function Keyword The keyword s used to filter URLs Keywords can be partial words or complete URLs The router will reject any Website which whole or partial URL matches any keywords Keyword List The list of keywords Block Direct IP Web D
40. by the router Zip rar arj ace cab sit Execution Files Activates the Block Executable file function to prevent from downloading of any executable file The following types of executable files are blocked by the router exe com scr pif bas bat inf reg Cookie Activates the Block Cookie function Cookies are used by many websites to create stateful sessions for tracking Internet users which would violate the users privacy The router will filter out all cookies related transmissions Proxy Activates the Block Proxy function The router will filter out all proxy related transmissions Multimedia Files Activates the Block Multimedia function The router will filter out multimedia from any website Vigor3300 Series User s Guide 93 Dr ay Te k Filter Schedule Filter Schedule function controls what times the URL content filter should be active It can specify what times the URL content filtering facility should be active Firewall URL Filter Restrict Web Fitter Schedule Feature Filter Schedule e jme 0 Day of Week Al Days Osun v Mon v Tue Mwea v Thu v Fri CO Sat ODisable 9 Enable URL Access Gent Content Filter Always Block Block only at Apply Cancel Always Block The URL content filtering facility is always active Block only at The URL content filtering facility is active during the specified times from H1 M1 to H2 M2 in one day
41. can select some weekdays to apply Select one specific WAN interface to be applied Click Apply to finish this setting Delete Call Schedule To delete an item click the radio button of the item that you want to delete Then click Delete on the bottom of the page to remove the entry Advanced Call Schedule E Status Date amp Time Action How often Week Option WAN 1 Enable 2000 1 26 00 00 Force On Once WANA C Microsoft Internet Explorer x d J Are you sure of deleting this item Cancel 1 Edit Delete Delete All Also users can click Delete All to remove all entries in the table 3 3 WAN Port Mirroring Setup Vigor 3300 Series supports port mirroring function in WAN interfaces Generally speaking this function copies traffic from one or more specific ports to a target port This mechanism helps manager track the network errors or abnormal packets transmission without interrupting Dray Tek 74 Vigor3300 Series User s Guide the flow of data access the network By the way user can apply this function to monitor all traffics which user needs to check There are some advantages supported in this feature Firstly it is more economical without other detecting equipments to be set up Secondly it may be able to view traffic on one or more ports within a VLAN at the same time Thirdly it can transfer all data traffics to be mirrored to one analyzer connect to the mirroring por
42. default speed of the upstream for each computer in LAN The default value is 1024 Default RX limit Define the default speed of the downstream for each computer in LAN The default value is 1024 Apply After finishing the configuration please click this button to Limitation Table invoke these settings This function allows users to set limitation for bandwidth management In the Network group choose Bandwidth Management and then Limitation Table You will get the following page Network Bandwidth Management Limitation Table Start IP O OOo O0 OO 00 OO 10 Start IP End IP Vigor3300 Series User s Guide End IP TX Limit RX Limit 1 Edit Delete Delete All Display the start IP address of bandwidth Display the End IP address of bandwidth 57 Dray Tek TX Limit Display the size limit for the transmitted packets RX Limit Display the size limit for the received packets Edit Click this button to open the edit page for adjusting the settings Delete Delete All Click this button to delete the selected setting or all settings A confirmation dialog box will appear Click OK to delete this entry from the Load Balance Policy table In addition click Delete All in the Load Balance Policy page to delete all of 10 entries on this page To edit an entry select it by clicking the radio button from 1 to 10 Then click the Edit button on the bottom to bring up the following Web page Network Bandw
43. find out the preset tone settings and caller ID type automatically Or you can adjust tone settings manually if you choose User Defined TOn1 TOffl TOn2 and TOff2 mean the cadence of the tone pattern TOnl and TOn2 represent sound on TOff1 and TOff2 represent the sound off VoIP Tone Settings Region UK v Caller ID Type ai TOn1 TOff1 TOn2 TOff2 Tone Classfication Low Frequency Hz High Frequency Hz 10msec 10msec 10msec 10msec Dial tone Ringing tone Busy tone Congestion tone Tone Timer Dial Tone 15 Busy Tone 30 Howler Tone 60 Ringing Tone 180 Special Dial Call Waiting Congestion T Tone 16 Tone 30 Tone 30 Reorder Tone 30 Apply Cancel Region Choose the country area that the Vigor3300 located for using VoIP feature Or select User Defined for proprietary settings Finland User Defined Australia Canada US China Denmark Finland France Germany Hong Kong Japan Hetherlandz Horway Singapore Taiwan UE Caller ID Type If User Defined is selected in the Region field users can select one of the supported values If a country is selected this field Dr ay Te k 136 Vigor3300 Series User s Guide will display ID type value automatically Caller ID Type DTMF v Dial tone A tone means the phone line is ready to make
44. for you to ask confirmation Click OK SNMP Traps In managed network by SNMP protocol agent will send a specific packet as an attention for administrator called Trap Trap is the only PDU Protocol data unit sent by an agent on its own initiative It is used to notify the management station of an unusual event that may demand further attention like a link down Choose SNMP Traps option to see the following page EMS SNMP Traps E Trap Server Trap Community Trap server port 2 3 O 4 0 5 6 O 7 8 Q 9 10 O 1 Edit Delete Delete All Trap Server Display the IP address of the trap server Trap Community Display the community string of the trap server Trap server port Display the port number used for the trap server Edit Allow users to edit the selected SNMP traps settings Delete Delete All Remove one all the selected SNMP traps settings A dialog will be prompted for you to ask confirmation Click OK To edit an item click the radio button of the item that you want to modify Then click Edit on the bottom of the page to add a new rule entry or modify an existed rule entry Vigor3300 Series User s Guide sl Dr ay Te k EMS SNMP Traps Edit 1 Trap server 192 168 1 100 Trap community public Trap server port 2048 Apply Cancel Trap server Assign an IP address of trap server Trap community Assign a community string for Trap packet using Trap server port Assign
45. is depicted in the following figure which illustrates interconnections among branch offices through the Internet via the Vigor3300 Series routers By combining with an existing PABX an Internet phone from a remote branch can also access any extension number on a local PABX or a traditional phone via PSTN In addition by combining load balancing data security and Internet phone features the company can benefit from reducing operation fees IPorATM Backbone A Virtual Private Network VPN is an extension of a private network that encompasses links across shared or public networks like an Intranet A VPN enables you to send data between two computers across a shared public Internet network in a manner that emulates the properties of a point to point private link The DrayTek Vigor3300 Series VPN router supports Internet industry standards technology to provide customers with open interoperable VPN solutions such as X 509 DHCP over Internet Protocol Security IPSec up to 200 tunnels and Point to Point Tunneling Protocol PPTP Internet Telephony also known as Voice over Internet Protocol VoIP is a technology that allows you to make telephone calls using a broadband Internet connection instead of a regular analog phone line Combining a PABX with a V3300V allows you to call anyone who has an Internet phone or a traditional telephone number including local long distance mobile and international numbers Internet Te
46. number is 0365432 The strip length is 2 and the append number is 886 Then the final phone number will be 886654321 Assign an IP address for the destination which the SIP message would be sent to A description for this entry This page includes RTP and T 38 Starting Port T 38 Redundancy Number VoIP ToS and FAX Ringing settings Dray Tek 134 Vigor3300 Series User s Guide VoIP Miscellaneous RTP Starting Port 13455 T 38 Starting Port 49170 T 38 Redundancy number m KR ange 0 4 Dialing Completion Timeout 4 sec Range 1 50 VoIP ToS Ox al Line Polarity Reversal as Callee on hook as Callee Answer FAO auto disconnection if no packet is received in 3 seconds Range 5 3600 O no auto disconnection FAS On hook Tip Ring Voltage Low w FXS Ringing Ringing Frequency 25 MHZ Ringing Cadence On 2000 msec Ringing Cadence Off 4000 m sec Apply Cancel RTP Starting Port The starting port number for RTP protocol packet The default setting is 13456 T 38 Starting Port The starting port number for T 38 protocol packet The default setting is 49170 T 38 Redundancy Number The redundancy number how many payloads attaching to the tail of the packet for T 38 protocol The default value is 1 Dialing Completion Users might dial with incomplete phone number and wait for Timeout several seconds but not finish the complete dialing The system will force to dial the incomplete nu
47. rules are matched Pass if no further match means to passes the packet if no further rules are matched Note It is recommended placing pass rules in pass group and block ones be in block group It indicates the next filter group If the option Block if no further match or Pass if no further match of Block or Pass parameter is selected the unmatched packets will be compared with rules in Next Group The option None must be chosen while Block or Pass is selected as Block or Pass Click this button to return to IP Filter Table setting page The new added rule information will be displayed on this page too Refer to the following graphic 87 Dray Tek Firewall IP Filter Table Group Name Next Group Name none Comment Skip this group Add Rule Apply Cancel IP Filter Table Index SourcelIP Subnet Mask Port Destination Subnet Mask Port Protocol Direction Block Active Even Py at PCR ERE c IC M eR pe LAN to Block 15S Pot flats poe ba 65 255 255 0 130 192 168 3 58 255 255 255 0 130 m e 1 s E ES uis LAN immediately Edit Rule Delete Rule The DoS function helps to detect and mitigates DoS attacks These include flooding type attacks and vulnerability attacks Flooding type attacks attempt to use up all your system s resources while vulnerability attacks try to paralyze the system by offending the vulnerabilities of the protocol or operation system In the Fir
48. the configurations for this page Vigor3300 Series User s Guide 43 Dr ay Te k PPPoE with a DSL Modem Setup Most DSL modem users will use this mode All the local users can share one PPPoE connection to access the Internet Static DHCP PPPoE PPTP Configuration Pieter TE UserName Password Authentication Service Name PPPoE IP Alias MTU Configuration 1234 hinet net PPTP Local Address DMZ PPTP Subnet Mask PAP a PPTP Server Address Enable 1442 IP Address Assignment Method IPCP Fixed IP Fixed IP Address Connection Detection Detect Interval No Reply Count IP Alias List Il n ca ho User Name Password Authentication Service Name PPPoE IP Alias Detect Interval Dray Tek 9 No Dynamic IP O Yes 10 2 10 1 1 100 2 10 1 1 101 10 1 1 102 Apply Reset Cancel Assign a specific valid user name provided by local ISP Assign a valid password provided by local ISP Select PAP CHAP MS CHAP or MS CHAP V2 protocol for PPP authentication according to the feature that your ISP provided for widest compatibility The default value is PAP The password will be encrypted in CHAP but not in PAP PAP PAP CHAP HS CHAP HS CHAF Vz Assign a service name required for some ISP services
49. the strip length of the entry Vigor3300 Series User s Guide 133 Dr ay Te k Append Destination Memo Edit Delete Delete All Display the appended number of the entry Display the IP address of the destination of the entry Display the brief description stated in memo field of the entry Click this button to access into the editing page of the speed dial Click this button to delete the selected setting or all settings To configure one entry please click Edit to open the following page VolP Advanced Speed Dial Edit Prefix Strip Length Append Destination Memo Prefix Strip Length Append Destination Memo 3 7 5 Miscellaneous B86 10 1 1 1 Momo0 Apply Cancel Assign a prefix for checking the phone number that users dial out If the prefix of the outgoing call matches to the number set in this field that outgoing call can apply the speed dial For example suppose that there are two outgoing calls with phone numbers of 03654321 and 04556890 In which 03654321 is suitable for this speed dial rule Assign the length of digit to be removed from the original phone number For example suppose the original phone number is 03654321 and the strip length is 2 The first two numbers 03 will be removed and the final phone number becomes 65432 Assign a new number to be added before the phone number after removing length of digit For example suppose the original phone
50. up the CA configuration Click the VPN gt gt IPSec gt gt Trust CA option It can make users loading double key certificate issued by trusted CA server VPN IPSec Trust CA Name Issuer 0 0 0 0 0 0 0 0 0 Q 1 Upload Delete View To upload a new Trust CA please select any one of the entry and click the Upload button The following page will appear VPN IPSec Trust CA 1 Upload Upload CA Certificate Apply Cancel Dr ay Te k 116 Vigor3300 Series User s Guide User Certificate This page allows you to set up the CA configuration to generate user s certificate Click the VPN gt gt IPSec gt gt User Certificate option VPN IPSec User Certificate i Status Hanne Import OF 3300CA_0804 Issuer ICSTWISTsHsin ChwL Houkol0 DrayteWOUSRDICNeprestofemailAddress pchomdraytek com tw fC TWwfiST Hsin 2 ELEM one ee ChuiL Houko O DrayteWOUSRD3 CN prestofemailAddress pcho draytek com tw 3 o import OK 3300CA_attel erat WoW soe UzRD3 CNzpresto email amp ddressz pchoiedraytek com tw 4 O Empty 5 Q Empty 6 Q Empty rj O Empty 8 Q Ernpty 9 Q Empty 1 Empty Generate Download Import Delete View 1 Generate Download Import Delete View Generate a new entry for user certification Download a certification file generated from router to be stored in local host Import a certificated file from the local host Delete an assigned entry Show configuration of t
51. 1 160 206 nw 230 207 146 UUIUUCTEEN MM IP PPPoE REM IP LANP IP 192 168 33 1 168 33 1 168 29 1 poen 168 22 1 Internal network 192 168 33 X Internal network 192 168 33 X 19216829 X 192 16822X Encryption DES SHAI method 3300 Preshared Key 1234 Pt wane PorNumber Phone Number Proxy codec soov p20135240207 Poicxs eeeess ora 2000v_l o1 31 167 135_l Porticexsy ses fora 200v 61 230 207 146 Port Fxs 888822 6 7294 About the VPN configurations please refer to VPN Example 3 three part communication About VoIP basic configuration please refer to VoIP Example 1 Basic Configuration and Registration The following examples are modified which based on these two examples Configuration Example for Vigor3300V 1 Enter the VoIP Protocol page Disable all the Active entries by removing the N box After configuration please click Apply to save the settings VoIP Protocol Miu i E 1L canhguratben Prog r id Ag al A 1 1 iiy q Eel Fl aay Raise Pari merci App Cael Dr ay Te k 198 Vigor3300 Series User s Guide Port 1 F15 i cha Aaa Pasar sss rne XXIV Port apte Fs Note In 3300V firmware v2 5 5 you can only choose WAN or LAN VPN The call can be received or dialed just in one direction WAN or LAN VPN Or select none as Proxy Server for each Port VolP Port Settings Port Edit Fort
52. 1 iFX58 Disable Enabie ame B3 ra mans Display N ama 3300V Porti piel Vel iP i Hotline ined proxy 2 Enter the VoIP Port Settings page now the Proxy entries all display Disable If you select none as Proxy Server for each Port the Proxy entries are blank VoIP Port Settings Typs Boer PLI Lent sain Pi day Codec E E 3 fl Es IS fs E I 3 Enter the VoIP Speed Dial page and input the first and second group of Speed Dial Phone Number Click Apply to save the settings Dray Tek Vigor3300 Series User s Guide 199 VoIP Speed Dial Sec Dial Pee Hibs Seed Anil Telnaes mapa 16828 SRA HIS 168 22 1 101 igietal org Apply Cameo Clea This Page Configuration Example for Vigor2900V l Enter VoIP Setup SIP Related Functions Setup page and change Register via from WAN to LAN VPN for Port and Port2 Press OK to save the settings SIP Port 1 Port 2 SIP Por Fe SIP Part ai rit Domain lipteL org Domain fwd pulver com Proxy liptel org Proxy fwd pulver com Outbound Proxy Outbound Proxy Ports Settin Purt 1 Port Register via LANAVEN Register via Display Name eangv Port ir Display Mame z300v Pont v Account Name fesas Account Name 60529 Authentication ID fesas Authentication ID 60529 Password esse Password sss Expiry Time thou Beo Expiry Time i how 650 sec Stun Serer Cancel Note Do no
53. 2 168 1 0 192 168 2 0 192 168 3 0 192 166 40 NS E Engineer Sales Vlarketing Other Department Department Department Department Procedure l Refer to A 1 to block LAN to LAN communication 2 Create VLAN5 VLAN6 VLAN7 and VLANS Groups 3 Inthe VLANS input 5 to VLAN ID In the Member field choose pl Then choose the Untagged for Frame Tag Operation in pl Configure the PVID to 5 for the device does not support 802 10 VLAN 4 Inthe VLANO input 6 to VLAN ID In the Member field choose p2 Then choose the Untagged for Frame Tag Operation in p2 Configure the PVID to 6 for the device does not support 802 1Q VLAN 5 Inthe VLANT input 7 to VLAN ID In the Member field choose p3 Then choose the Untagged for Frame Tag Operation in p3 Configure the PVID to 7 for the device does not support 802 1Q VLAN 6 Inthe VLANS input 8 to VLAN ID In the Member field choose p4 Then choose the Dray Tek Untagged for Frame Tag Operation in p4 Configure the PVID to 8 for the device does not support 802 10 VLAN 164 Vigor3300 Series User s Guide Advanced LAN VLAN Setting Disable Part Base VLAN 9 902 10 VLAN Port Base 902 10 VLAN VLAN 802 1Q VLAN Group Index Active Mame VLAN ID Member Frame Tag Operation P1 P4 P1 P2 P3 P4 VANS A wwe o n ww n A Tagged Wi Tazsei Wi Untasgei W Tessei ij wwe o Enable management part far P4 Port Setting P1 P2 P3
54. 3220 135 240 207 Y B8Bee33ipt el org US II iwd pulvercom w Note indicates termination of the phone number After pressing VoIP is immediately called out Or you may wait 3 seconds if you do not press Dr ay Tek 196 Vigor3300 Series User s Guide 5 2 8 Example 3 VoIP over VPN Based on the VoIP Example 1 Basic Configuration and Registration we will introduce how to dial the VoIP call through an encrypted VPN tunnel In this example 3300V acts as a bridge accepting incoming VPN connections from the other two routers 2900V and 2200V The VPN traffic between 2900V and 2200V are all passed through 3300V These three sites internal networks must be within the same subnet 192 168 X X Either site can ping the other two routers Then you can make a VoIP call through the encrypted VPN tunnel by directly dialing remote router s LAN IP Below shows the architecture graph Tarwan FXS 192 168 434 AENIL Internet cf F E F 1 L a m u F a i i fd 1 31 id LI 1 F 1 L I i i 1 a a a 1 F L 1 2900 FXS F 0V FXS 192 168 29 1 888829 192 168 22 1 888822 D Phone 2 China Shanghai Hong Kong Vigor3300 Series User s Guide 197 Dr ay Te k Configuration table sf 3300 Headquarters 3300V 3300V Headquarters 2900V Branch Offices Branch Offices 2200V Teleworker Teleworker 220 m 240 207 aap 31 167 135 PPPoE m IP PPPoE aap IP WAN IP 8
55. 72 66 99 88 Service Name Optional PPTP Local Address PPTP Subnet Mask PPTP Server Address Next gt gt Assign a local IP address of PPTP Assign a net mask value for IP address of PPTP Assign a remote IP address of PPTP server After setting up the PPTP click Next to setup the LAN interface continuously Vigor3300 Series User s Guide 21 Dray Tek Quick Setup LAN DHCP Relay LAN IP DHCP Agent IP Routing IP Configuration IP Address Subnet Mask DHCP Server Status Start IP End IP Primary DNS Secondary DNS Lease Time Min Gateway IP Optional IP Address Subnet Mask Status Start IP End IP Primary DNS Secondary DNS Lease Time Min 192 168 1 1 255 255 255 0 9Enable ODisable O Relay Agent 192 158 1 10 192 158 1 254 1440 lt lt Previous Assign an IP address for the LAN interface Assign the subnet mask for the LAN interface Click Enable to use DHCP server click Disable to close DHCP server click Relay Agent to activate relay agent function Assign the start IP address of the IP pool that DHCP server can use for clients in LAN Assign the end IP address of the IP pool that DHCP sever can use for clients in LAN Type the IP address for primary DNS Assign a private IP address to the secondary DNS Set a lease time for the DHCP server The time unit 1s minute Gateway IP
56. 8 1 3 00 00 5E 01 01 01 If Master Activated 192 168 1 1 O0 00 5E 01 01 01 192 192 168 1 2 00 50 7F 0A 0B 02 192 168 1 2 00 50 7F 0A 0B 02 If Slave Activated If Slave Activated 192 168 1 1 00 50 7F 0A OB 01 192 168 1 1 00 50 7F 0A 0B 01 192 168 1 2 00 00 5E 01 01 01 192 168 1 2 00 00 5E 01 01 01 ARP Table 192 168 1 3 00 00 5E 01 01 01 If Master Activated 2 168 1 1 00 00 5E 01 01 01 In the Network group click the High availability option High Availability Network LAN High Availability SES 802 10 Status High Availability 9 Disable Enable Group Number Range 1 255 Role Virtrual IP Apply Cancel Vigor3300 Series User s Guide Dr ay Tek 54 High Availability Disables or enables this function When the master device fails down the slave device will take its work over Group Number Assign a group number The range is from 1 to 255 PCs on the same group in LAN can support for each other Role Select a role for this device as Master or Slave Virtual IP Assign an IP address as a virtual IP Click Apply to reboot the system and apply the settings 802 1Q Status This page allows you to set High Availability for LAN ports 1 4 respectively Network LAN High Availability Basic Status 802 1Q Status LAN1 LAN2 High Availability Disable O Enable High Availability Disable Enable Group Number Range 1 255 Group Number Range 1 255 Role
57. Address 172 16 3 229 WAN IP Address 172 16 3 229 Apply Cancel Disables this function The feature is used if Vigor3300 has a public WAN IP address and not behind a NAT router NAT IP Address Type the IP address to be used as the NAT IP address The feature is used when Vigor 3300V is behind a NAT router and the NAT router uses a static WAN IP address This value is the same as the WAN IP of the front NAT router It is used when Vigor3300 is behind a NAT router and the NAT router uses a dynamic WAN IP address such as a DHCP or PPPoE client The Vigor3300 requires a STUN server for this option The STUN Simple Traversal of UDP through NATs server is an implementation of the STUN protocol that enables STUN functionality in SIP based systems It is an application layer protocol that can determine the public IP and nature of a NAT device sitting between the STUN client and STUN server Semi auto need to config NAT If you click this function the user needs to configure NAT information Full auto no need to config NAT only for SIP If you 139 Dray Tek Symmetric Media 3 7 9 Incoming Call Barring click this function the user does not configure NAT information STUN Local Port Type the port number of the STUN server STUN Server Address Type the IP address of the STUN server STUN Server Port Type the port number of the STUN Server Disable symmetric RTP and T 38 Cl
58. After getting through you will hear the Dial tone Press outside line 0 then press 87654321 Phone 3 calls Phone 1 gt Press 888835 After getting through you will hear the Dial tone then press the extension 101 Phone 3 call Phone 4 gt Press 888835 After getting through you will hear the Dial tone Press outside line 0 then press 87654321 Phone 4 calls Phone 2 gt Press 12345678 After getting through you will hear the auto reply from the PBX then press the extension 102 After getting through you will hear the Dial tone then press the VoIP number 8888334 Phone 4 calls Phone 3 gt Press 12345678 After getting through you will hear the auto reply from the PBX then press the extension 102 After getting through you will hear the Dial tone then press the VoIP number 8888291 Note indicates termination of the phone number After pressing VoIP is called out immediately Or you may wait 3 seconds if you do not press This example is intercommunication with one SIP Proxy Server For the applications of Direct IP Call and Intercommunication with different SIP Proxy Servers please refer to VoIP Example 2 Basic Calling Method The VoIP call can also wok with VPN please refer to VoIP Example 3 VoIP over VPN Vigor3300 Series User s Guide 207 Dr ay Te k
59. Assist me Apply Now Dray Tek 150 Vigor3300 Series User s Guide 4 3 Pinging the Router from Your Computer The default gateway IP address of the router is 192 168 1 1 For some reason you might need to use ping command to check the link status of the router The most important thing for this command is that the computer will receive a reply from 192 168 1 1 for correct link If not please check the IP address of your computer We suggest you setting the network connection as get IP automatically Please refer to the section 3 2 Please follow the steps below to ping the router correctly For Windows l 2 4 Open the Command Prompt window from Start menu gt gt Run Type command for Windows 95 98 ME or emd for Windows NT 2000 XP The DOS command dialog will appear ov Command Prompt Microsoft Windows HP Version 5 1 2688 lt C gt Copyright 1985 2001 Microsoft Corp D Documents and Settings faerping 192 168 1 1 Pinging 192 168 1 1 with 32 bytes of data Reply from 192 168 1 1 bytes 32 time lt ims TTL 255 Reply from 172 168 1 1 bytes 32 time lt ims TTL 255 Reply from 192 168 1 1 bytes 32 timesims TTL 255 Reply from 172 168 1 1 bytes 32 time lt ims TTL 255 Ping statistics for 192 168 1 1 Packets Sent 4 Received 4 Lost A f loss Approximate round trip times in milli seconds Minimum Hms Maximum ms Average Pms D Documents and Settings fae gt _ Ty
60. Cabel Fiber Modem 3 If not there must be something wrong with the hardware connection Simply back to 2 1 Hardware Installation to execute the hardware installation And then try again Vigor3300 Series User s Guide 147 Dr ay Te k 4 2 Checking If the Network Connection Settings on Your Computer Is OK or Not Sometimes the link failure occurs due to the wrong network connection settings After trying the above section if the link is stilled failed please do the steps listed below to make sure the network connection settings is OK For Windows Q The example is based on Windows XP As to the examples for other operation systems please refer to the similar steps or find support notes in www draytek com 1 Goto Control Panel and then double click on Network Connections Jeliuork Connectiaris 2 Right click on Local Area Connection and click on Properties Disable i Status Repair Bridge Connections Create Shortcut Rename Properties Dr ay Te k 148 Vigor3300 Series User s Guide 3 Select Internet Protocol TCP IP and then click Properties ethO Properties General Authentication Advanced Connect using lE ASUSTeK Broadcom 440x 10 100 Ir This connection uses the following items v IE Client for Microsoft Networks Ivi JB File and Printer Sharing for Microsoft Networks fl QoS Packet Scheduler Description Transmission Control Protocol Intemet Protocol The default wide are
61. DNS Set a lease time for the DHCP server The time unit is minute Set a gateway IP address for the DHCP server 50 Vigor3300 Series User s Guide Click Apply to reboot the system and apply the settings Note If both the Primary and Secondary DNS fields are left empty the router will assign its own IP Address to local users as a DNS proxy server and maintain a DNS cache If the IP address of a domain name is already in the DNS cache the router will resolve the domain name immediately Otherwise the router forwards the DNS query packet to the external DNS server by establishing a WAN e g DSL Cable connection For DHCP Relay Agent This page allows users to specify which subnet that DHCP server is located the relay agent should redirect the DHCP request to Network LAN DHCP Relay LAN IP DIHCP IP Routing Relay Agent WAN Interface DHCP Server IP Address Apply Cancel WAN Interface Choose the WAN interface for applying relay agent DHCP Server IP Address Type the IP address for the DHCP server Vigor3300 Series User s Guide 51 Dr ay Te k For IP Routing This page allows users to type in secondary IP address for connecting to a subnet You can set IP routing for each WAN interface respectively Network LAN LAN IP DHCP WAN 1 Status IP Address Subnet Mask WAN2 Status IP Address Subnet Mask WANS Status IP Address Subnet Mask WAN4 Status IP Address Subnet Mask Status
62. Delay The keep alive timer A Hello message will be emitted periodically when a tunnel is idle Use the value 0 to disable this function The recommended value is 2 seconds if enabled Timeout The timeout timer The peer will be declared dead once no acknowledge message is received after timeout value Use the value 0 to disable this function The recommended value is 4 seconds if enabled Auto GRE Key Check this box to automatically generate GRE key Or type the GRE key on the fields below manually GRE Key In This value is used for the router to authenticate the source of the packet The length is 4 bytes GRE Key Out This value is used for the remote client to authenticate the source of the packet The length is 4 bytes After finish the configuration click Apply to apply the IPSec policy setting into the policy table Significant fields will be summarized in the IPSec Table Operational Status reflects the current status of the tunnel UP means the IPSec tunnel has been established DOWN means no tunnel existing or termination status of the tunnel If user expects the local gateway to act as the IKE initiator 1 e emit the first IKE main mode message user can click the hyperlink Initiate to start the IKE negotiation or set admin status to be always on to automatically restart IKE negotiation During the negotiation you can press Refresh to show the latest status of all policies Vigor3300 Series User s Guide 113 D r ay
63. Dm 5E te OG s B B B i A Hi i n sector sector sector sector aoctor sector sector sector sector sector sector sector sector sector sector sector sector sec tor sector sector sector sector sector Updating flash block at bfBSBBHHB Cunnected 20345 bo detect regi O BRL 7 When set flash0 0 780000 800000 general appears it means the firmware downloading has been completed The router will reboot itself and you will see the Firmware version V2 X X Please wait about 20 seconds to relogin the router The procedure is finished now Vigor3300 Series User s Guide 33 Dray Tek Un Hyper Terminal Fia Edt Wee cal Trarefor Hp Cae SG 015 FF sector size 69096 sector amp 1 FA 6 rly sector size sector size slot B sector size Updating flash block set ethaddrH BB 50 7T 28 88 e3 ethaddri 88 50 7f 28 90 64 ethaddr 08 50 7T 28 88 e4 Wdefault nif wanl mac AD 5A 7f 20 AN Fr Hdefault nif wan mac H 58 7f 28 88 m nif wan mac 80 58 7f 28 80 default nif wani mac Bn 58 7f 28 88 27 V3 board for V3 GPIO contio have voip card Draytek login 3308 series Aubo dut act 5 TEL z M 1 3 1 7 Reboot The Vigor3300 Series system can be restarted from a Web browser Reboot screen can appear after you finish the changing of WAN and LAN settings You have to reboot the router to invoke the configur
64. MAC Uses a MAC address defined by users If you select this item you have to type the MAC address in the box below Downstream Rate Set downstream rate for this WAN interface The default value is 102400 kbps 100 Megabit Upstream Rate Set transmission rate for this WAN interface The default value is 102400 kbps 100 Megabit Type Set connection type for this WAN interface Physical Mode Set connection speed mode There are five options including Auto negotiation full duplex half duplex 10M and 100M IP Mode Set an IP Mode with Static fixed IP DHCP dynamic IP address PPPoE PPTP or DMZ and creates the IP group information Most cable modem users will use DHCP to get a globally reachable IP address from the cable head end system Different mode will lead different configuration and will be explained in later section Before you connect a broadband access device e g a DSL Cable modem to Vigor3300 Series you need to know what kind of Internet access your ISP provides The following sections introduce four widely used broadband access services Static PPPoE PPTP for DSL DHCP for Cable modem and DMZ In most cases you will get a DSL or cable modem from the broadband access service provider Vigor3300 Series is connected behind the broadband device 1 e DSL cable modem and works as a NAT or IP router for broadband connections Next we will introduce each WAN mode in detailed Static IP Setup It means that the IP grou
65. Mask 255 255 055 0 Port 100 200 Group Mame Protocol Direction Fragment Action Block ar Pass Next Group Mame Apply Cancel Source IP It means the source IP address Placing the symbol t before a particular IP address will prevent this rule from being applied to that IP address It is equal to the logical NOT operator Subnet Mask It means the subnet mask for the source IP Vigor3300 Series User s Guide 85 Dray Tek Source Port Destination IP Destination Mask Destination Port Group Name Protocol Direction Dray Tek It means the port for the source IP Type the values in the boxes of start port and end port As for the operators Port If the Start Port column is empty the Start Port and the End Port column will be ignored The filter rule will filter out any port number If the End Port column is empty the filter rule will set the port number to be the value of the Start Port column Otherwise the port number ranges from the Start Port to the End Port including the Start Port and the End Port If the End Port column is empty the port number is not equal to the value of the Start Port column Otherwise this port number is not between the Start Port and the End Port including the Start Port and End Port gt Specifies the port number is larger than or equal to the Start Port lt Specifies the port number is less than or equal to the Start Port Between Spec
66. O OO E OC Tassed Tagged w Tagged w Untagged w C Enable management port for P4 Port Setting P1 P2 P3 P4 Port VLANID 5 6 7 g Apply Reset Cancel 5 After applying the settings the web page will be redirected to reboot web page User can it and continue to configure the Network setting After finishing Network setting you can execute the reboot procedure 6 After rebooting the tagged ports will communicate with 802 1Q tagged devices only 7 In the Network setting type the subnet 192 168 1 0 to LAN For example the VLAN5 LAN IP is 192 168 1 1 and the Subnet Mask is 255 255 255 0 Then users in the Engineer Department can set IP address from 192 168 1 2 to 192 168 1 254 8 Inthe Network setting type the subnet 192 168 2 0 to LAN2 For example the VLAN6 LAN IP is 192 168 2 1 and the Subnet Mask is 255 255 255 0 Then users in the other departments can set IP address from 192 168 2 2 to 192 168 2 254 Vigor3300 Series User s Guide 167 Dr ay Te k 5 1 5 Example for the Companies in the Same Building There are four companies in the same building They share the broadband network and use the Vigor3300V router to achieve the load balance security and VoIP features In this case we can define four VLANs including VLAN5 VLAN6 VLAN7 and VLANS The subnet of VLANS is 192 168 1 0 the subnet of VLANO is 192 168 2 0 the subnet of VLAN7 is 192 168 3 0 and the subnet of VLANS is 192 168 4 0
67. P PPPoE PPTP Configuration Configuration User Name 1234 hinet net PPTP Local Address Password nae PPTP Subnet Mask Authentication PAP v PPTP Server Address Service Name Optional Next gt gt User Name Assign a specific valid user name provided by the ISP Password Assign a valid password provided by the ISP Authentication Select PAP CHAP MS CHAP or MS CHAP V2 protocol for PPP authentication The default value is PAP PAP PAP CHAP MS UCHAP MS CHAF V2 Service Name Assign a service name required from ISP service After setting up the PPPoE click Next to setup the LAN interface continuously Vigor3300 Series User s Guide 19 Dr ay Te k Quick Setup LAN DHCP Relay LAN IP DHCP Fach IP Configuration IP Routing IP Address 182 158 1 1 Subnet Mask 255 255 255 0 DHCP Server Status SEnable ODisable Relay Agent Primary DNS Secondary OMS Lease Time Min 1440 Gateway IPrOptioanal IP Address Subnet Mask Status Start IP End IP Primary DNS Secondary DNS Lease Time Min Gateway IP Optional lll lt lt Previous GaN Assign the subnet mask for the LAN interface Assign an IP address for the LAN interface Click Enable to use DHCP server click Disable to close DHCP server click Relay Agent to activate relay agent function Assign the start IP address of the IP pool that DHCP server can use for clients in LAN Assign the end I
68. P address of the IP pool that DHCP sever can use for clients in LAN Type the IP address for primary DNS Assign a private IP address to the secondary DNS Set a lease time for the DHCP server The time unit is minute Set a gateway IP address for the DHCP server When you finished the above settings please click Finish A system reboot page will appear Click Apply to activate the PPPoE mode configuration Dray Tek 20 Vigor3300 Series User s Guide 2 2 4 PPTP This mode lets user get the IP group information by a DSL modem with PPTP service from ISP Your service provider will give you user name password and authentication mode for a PPTP setting Quick Setup WAN MAC Address 9 Default MAC User Defined MAC Downstream Rate 102400 kbps Upstream Rate 102400 kbps Type Fast Ethernet v Physical Mode Auto Negotiat ion wa IP Mode O Static ODHCP OPPPoE 9 PPTP If your ISP offers you PPTP Point to Point Tunneling Protocol mode please select PPTP for this router Next enter the PPTP Subnet Mask e g 255 255 255 0 PPTP Local Address e g 10 66 99 88 and PPTP Server Address e g 172 66 99 88 provided by your ISP on the web page static DHCP PPPoE PPTP Configuration Configuration User Name 1234 hinet net PPTP Local Address 10 66 99 88 Password pem PPTP Subnet Mask 255 255 255 0 Authentication PAP l PPTP Server Address 1
69. P fragment function Any ICMP Fragment packets with fragmented bit sets are dropped Enable Block Unknown Activates the Block Unknown Protocol function The router Protocol will block any packets with unknown protocol types Click Apply to apply the settings when you finish the configuration 3 4 3 URL Filter The Internet contains a wide range of offenses or illegal materials Unlike traditional media the Internet does not have any obvious tools to segregate materials based on URL strings or content URL content filtering systems are seen as tools that would provide the cyberspace equivalent of the physical separations that are used to limit access to particular materials By rating a site as objectionable and refusing to display it on user s browser URL content filter can prevent employee on SME from accessing inappropriate Internet resources Instead of traditional firewall inspects packets based on the fields of TCP IP headers the URL content filter checks the URL strings or the payload of TCP IP packets Y Welcome to DrayTek Mozilla ioj x File Edit View Go Bookmarke Tools Window Help Home ef Bookmarks g The Mozilla Organization _g Latest Builds The URL content filter in the series of broadband security routers inspects every URL string in the HTTP requestt If the entire or part of the URL string for instance http www draytek com as shown above matches any activated rule the first
70. P4 Apply Reset Cancel 7 After applying the settings the web page will be redirected to reboot web page You can ignore it and continue to configure the Network setting After finishing Network setting you can execute the reboot procedure 8 After rebooting the tagged ports will communicate with 802 1Q tagged devices only 9 Inthe Network setting type the subnet 192 168 1 0 to LAN For example the VLANS5 LAN IP is 192 168 1 1 and the Subnet Mask is 255 255 255 0 Then users in the Engineer Department can set IP address from 192 168 1 2 to 192 168 1 254 10 In the Network setting type the subnet 192 168 2 0 to LAN2 For example the VLAN6 LAN IP is 192 168 2 1 and the Subnet Mask is 255 255 255 0 Then users in the Engineer Department can set IP address from 192 168 2 2 to 192 168 2 254 11 In the Network setting type the subnet 192 168 3 0 to LAN3 For example the VLAN7 LAN IP is 192 168 3 1 and the Subnet Mask is 255 255 255 0 Then users in the Engineer Department can set IP address from 192 168 3 2 to 192 168 3 254 12 In the Network setting type the subnet 192 168 4 0 to LAN4 For example the VLAN8 LAN IP is 192 168 4 1 and the Subnet Mask is 255 255 255 0 Then users in the Engineer Department can set IP address from 192 168 4 2 to 192 168 4 254 Vigor3300 Series User s Guide 165 Dr ay Te k 5 1 4 Two VLANs for Different Departments in A Company A company wants to separate the Engineer Department and O
71. PBX are usually connected to telephones so the PBX acts as FXS equipment PBX Outside Lines ir PBX Inside Lines FXS Telephone FXO FXO FXS equipment PSTN or inside lines of PBX FXO equipment Telephones FAX machines and outside lines of PBX Based on the characteristics described above that the FXS equipment and the FXO equipment must connect with each other please pay special attention when you use FXS card and FXO card FXS card This card can connect to the telephone FAX machine outside lines of PBX and FXO port on FXO card FXS Card Telephone FAX Machine PBX Outside Lines FXO Card Vigor3300 Series User s Guide 175 Dr ay Te k FXO card This card can connect to PSTN inside lines of PBX and FXS port on FXS cards FXO Card Dr ay Te k 176 Vigor3300 Series User s Guide 5 2 2 Practical Application of FXS card with PBX By combining the FXS with headquarters PBX it allows the internal telephones in headquarters to communicate with branch s telephones through the Internet For detailed configuration please refer to the part of Practical Application of FXS PRX Ohtaide Lines PIA inside Lines Telephone FAX Machine aivean 5 2 3 Practical Application of FXO card with PBX By combining the FXO with headquarters PBX it allows the branch s telephones to connect to Headquarters PBX via the Internet and communicate with the customers via the PBX A
72. Password Authentication Service Name PPTP Local Address PPTP Subnet Mask PPTP Remote Address Vigor3300 Series User s Guide Apply Reset Cancel Assign a specific valid user name provided by local ISP Assign a valid password provided by local ISP Select PAP CHAP MS CHAP or MS CHAP V2 protocol for PPP authentication according to the feature that your ISP provided for widest compatibility The default value is PAP The password will be encrypted in CHAP but not in PAP PAP PAP CHAF HS CHAP MS CHAF V2 Assign a service name required for some ISP services Assign a local IP address Assign a subnet mask value of IP address Assign a remote IP address of PPTP server 45 Dr ay Tek Detect Interval Assign an interval time for detecting if the WAN connection is on or off No Reply Count Assign detecting times to ensure the connection of the WAN After passing the times you set in this field and no reply received by the router the connection of WAN interface will be regarded as breaking down Apply Click Apply to go back to the WAN Interface Configuration age To apply all settings click Apply on the WAN Interface pag ppty 8 Configuration page and reboot your router Reset Click this button to clear all the configurations for this page DMZ Configuration In computer networks a DMZ De Militarized Zone is a computer host or small network inserted as a neutral zone between a company s priv
73. S SNMP Community Community Host mask Max Access 1 2 3 40 5 6 7 8 9 10 O 1 Edit Delete Delete All Community Display the community string used for the specified entry Host mask Display the mask address for the host Max Access Display the authority read only or read write for this entry Edit Allow users to edit the selected SNMP community settings Delete Delete All Remove one all the selected SNMP community settings A dialog will be prompted for you to ask confirmation Click OK To edit an item click the radio button of the item that you want to modify Then click Edit on the bottom of the page to add a new rule entry or modify an existed rule entry Advanced SNMP SNMP Community Edit Max Access 9 Read only Read vrite Apply Cancel Dr ay Te k 80 Vigor3300 Series User s Guide Community Type the community string e g public for SNMP Host mask Assign a value of subnet mask for host IP address Max Access Select the authority as Read only or Read Write Read only means user only can monitor managed devices Read Write means user can control managed devices including change the values of variable stored within managed devices Apply Click Apply to save this setting and return the previous page To delete an item click the radio button of the item that you want to delete Then click Delete on the bottom of the page to remove the entry A dialog will be prompted
74. SS 1lfLow Drop CLASS li Hedium Drop GLASS 1iHigh Drop CLASS 2 Loy Drop CLASS Medium Drop CLASS 2 High Drop CLASS 3fLow Drop CLASS 3 Hedium Drop CLASS 3rHigh Dropi CLASS 4fLow Drop CLASS 4 Hedium Drop CLASS 4 High Drop CLASS DiffServ CodePoint The number by hex mode to be applied Class Choose a filtering condition to be applied All the class names set in Incoming Outgoing Class Setup page will be displayed in this field and Remote Access Setup This page allows you to setup the configuration of VPN and Remote Access to create a virtual private network for security in the Internet FSec m General Setup PPTP amp L2TP M Policy Table VPN Trunk Loy Trust cA User Certificate Status A Virtual Private Network VPN is an extension of a private network that encompasses links across shared or public networks like the Intranet A VPN enables you to send data between two hosts across a shared or public network in a manner that emulates the properties of a point to point private link There are two types of VPN connections remote dial in access and LAN to LAN connection The Remote dial In Access facility allows a remote access node a NAT router or a single computer to dial into a VPN router through the Internet to access the network resources of the remote network The LAN to LAN Access facility connects two independent LANs for mutual sharing of network resources For example the head office n
75. TP server Firmware Specify the location of the firmware file if you want to upgrade the firmware locally TFTP Server IP If you want to upgrade the firmware of this router from remote side please type the IP address of the TFTP server Remote File Name The default filename will be shown here If you have use another name to save the firmware file please type the new name in this field Apply After finished your selection please click Apply to execute the firmware upgrade Firmware Upgrade from a Console Port Firmware upgrade can be done from a console port too The following example was run on a Windows environment 1 Download the newest firmware from the DrayTek Website www draytek com tw or FTP site ftp draytek com on your computer first 2 Connect the RJA5 connector of console cable to the console port on Vigor3300 and the DB connector of the console cable to the RS232 port on the PC Vigor3300 Series User s Guide 3 Dr ay Te k 2 Dray Tek 2 xl ou Ui oer Le I CUMI Properties Fort Settings ET Bits per second seo m Data bits je rl Parity None Stop bits iti H Flow control Restore Defaults Cancel Apply The default setting of the console port is baud rate 57600 no parity and 8 bit with 1 stop bit Power on Vigor3300 then press ENTER before the system reboots completely Open Hyper Terminal on the PC Now Vigor3300 can accept a TFTP dow
76. UserName Password DNS Server 9 Get DNS Server from LAN Setting Get DNS Server by Manual Setting primary DNS Secondary DNS Status L2TP Authentication User Authentication Enable Disable User Name Password Get DNS Server from LAN Setting Get DNS Server by Manual Setting Primary DNS Secondary DNS Group Table Apply Cancel Set the function to Active or Inactive Allow you to choose an authentication mode to be used The default setting is CHAP PAP CHAP HS CHAP H S CHAP V 2 Set user authentication to Local server or RADIUS server Enable or disable the Mutual Authentication function Type the user name that the other side provides for carrying out mutual authentication whenever you want Type the password that the other side provides for carrying out mutual authentication whenever you want Use DNS setting of LAN configuration If you click this radio button please type the primary DNS and secondary DNS IP address manually in the following fields Type the IP address for primary DNS Type the IP address for secondary DNS To create a VPN PPTP L2TP group table click VPN gt gt PPTP amp L2TP gt gt Group Table Dray Tek 122 Vigor3300 Series User s Guide VPN PPTP Group Table Group Start IP 8g sid c D tidC Start IP Subnet Mask Accessed IP Subnet Mask User Profile Subnet Mask Accessed IP Subnet Mask SY Cs
77. V Port1 iptel Proxy Server Select the SIP Server used for registration from the pull down menu There are None and three SIP Servers available which are set in the VoIP Protocol page Please select iptel FXO Dedicated settings for FXO card Incoming Pre Set Number The transfer number auto dialed after the FXO receives a call from the Internet 184 Vigor3300 Series User s Guide VolP Port Settings Port1 Edit Port 1 iFXS Disable 1 Enable ername B5B 3 Password oe Display Name 33XXJv Port iptel OF IP Address WAH hai Codec Setup the voice compression mode and transfer rate etc Preferred Codec Preferred voice compression mode It will affect the voice quality and the transferred data size By default is G 729A 8kbps Codec Rate Transfer rate of the voice packets By default is 20ms Codec VAD This feature can reduce the number of transmitted bits and packets during silence periods But it may slightly affect the voice quality By default is Disable CAS Adjust the volume of the conversation RX Gain The default value is 0 TX Gain The default value is 0 FAX Relevant settings used for FAX over VoIP FAX Mode Compression mode used for transferring FAX By default is T 38 Relay FAX Bypass Codec Select the compression mode when FAX Mode selects Bypass FAX Bypass Codec Rate Select the transfer rate of voice packets when FAX Mode selects Bypass DTMF DTMF are the audible sounds you hear
78. X auto detection of either straight or crossover RJ45 cables These cables are used on WAN LAN and DMZ interfaces Chassis Connections The Vigor3300 Series can be mounted on a rack by using standard brackets in a 19 inch rack or optional larger brackets on 23 inch rack not included The bracket for 19 and 23 inch racks are shown below Attach the brackets to the chassis of a 19 or a 23 inch rack as shown in the Figures 1 8 and 1 9 Repeat the above procedure for the second bracket which attaches the other side of the chassis Vigor3300 Series User s Guide 9 Dr ay Te k After the bracket installation the Vigor3300 Series chassis can be installed in a rack by using four screws for each side of the rack Desktop Type Installation Rubber pads are included with the Vigor3300 Series These rubber pads improve the air circulation and decrease unnecessary rubbing on the desktop Dray Te k 10 Vigor3300 Series User s Guide 2 Configuring Basic Settings For use the router properly it is necessary for you to change the password of web configuration for security and adjust primary basic settings This chapter explains how to setup a password for an administrator and how to adjust basic settings for accessing Internet successfully 2 1 Changing Password To change the password for this device you have to access into the web browser with default password first l Make sure your computer connects to the rou
79. X s inside lines and allows you to call not only the VoIP but also the PSTN line and PBX s extension Also the remote user can call you from the PSTN line and PBX s extension Internet N Phonc 4 87654371 Port5 FXO BASSAS O WV Portl FAS BERR2U BERRY e China cx Phone Phone 2 Shanghai Phone 3 LO Taiwan Dr ay Te k 206 Vigor3300 Series User s Guide Configuration table between 3300V and 2900V fwan PorNember Phone Number Proxy cose Suppose the number of PBX s Outside Line is 12345678 One Inside Line is connected to a telephone with the extension 101 If you want to use PSTN from the extension you must firstly press 0 and then dial the phone number The FXO Port5 on the 3300V is connected to PBX s Inside Line with the number 102 The number of another PSTN line is 87654321 About VoIP basic settings please refer to VoIP Example 1 Basic configuration and registration Start to dial by using telephones Phone calls Phone 2 gt Press extension 102 After getting through you will hear the dial tone then press the VoIP number 8888331 Phone 1 calls Phone 3 gt Press extension 102 After getting through you will hear the Dial tone then press the VoIP number 888829 Phone 2 calls Phone 1 gt Press 8888354 After getting through you will hear the Dial tone then press the extension 101 Phone 2 calls Phone 4 gt Press 888835
80. XO Relay Agent 192 168 1 10 192 168 1 254 1440 Gateway IP Optional lt lt Pr E Assign an IP address for the LAN interface Assign the subnet mask for the LAN interface Click Enable to use DHCP server click Disable to close DHCP server click Relay Agent to activate relay agent function Assign the start IP address of the IP pool that DHCP server can use for clients in LAN Assign the end IP address of the IP pool that DHCP sever can use for clients in LAN Type the IP address for primary DNS Assign a private IP address to the secondary DNS Set a lease time for the DHCP server The time unit is minute Set a gateway IP address for the DHCP server When you finished the above required settings please click Finish A system reboot page will appear Click Apply to activate the static mode configuration Dray Tek 16 Vigor3300 Series User s Guide 2 2 2 DHCP Mode DHCP allows a user to obtain an IP address automatically from a DHCP server on the Internet If you choose DHCP mode the DHCP server of your ISP will assign a dynamic IP address for Vigor3300 automatically It is not necessary for you to assign any setting Host Name and Domain Name are required for some ISPs Quick Setup WAN MAC Address 9 Default MAC User Defined MAC Downstream Rate 102400 kbps Upstream Rate 102400 kbps Type Fast Ethernet Physical Made
81. a call Ringing tone A tone means the call is ringing Busy tone A tone means the phone line is busy Congestion tone A tone means the network is busy Low Frequency Hz Type the low frequency number in Hertz High Frequency Hz Type the high frequency number in Hertz TOnl 10msec Type the duration of the first ring TOffl 10msec Type the silence duration after the first ring TOn2 10msec Type the duration of the next continuous ring TOff2 10msec Type the silence duration after the next continuous ring Tone Timer Determine the timeout for the tone invoked Vigor3300 Series User s Guide 137 Dr ay Te k 3 7 7 QoS This Quality of Service QoS function is only for the VoIP feature When this function is enabled the Vigor 3300 Series will set rate limitation for incoming and outgoing transmissions to ensure the best quality of service in VoIP VolP QoS Disable non guaranteed voice quality higher data throughput Enable guaranteed voice quality normal data throughput Advanced QoS Link Fragmentation and Interleaving Disable Enable Link Fragmentation and Interleaving Dray Tek For uplink bandwidth 768 kbps Apply Cancel Click this button to disable QoS function The voice quality cannot be guaranteed and the data throughput will be higher Click this button to invoke QoS function The voice quality can be good and the data throughput will be lower Each packet size is determ
82. a network protocol that provides communication across diverse interconnected networks Show icon in nolification area when connected Notify me when this connection has limited or no connectivity 4 Select Obtain an IP address automatically and Obtain DNS server address automatically Internet Protocol TCP IP Properties General Altemate Configuration You can get IP settings assigned automatically if your network supports this capabdity Di theresse you need to ask pour nebwork administrator for the appropriate F settings 5 Obtain an IP address automatically C Use the following IP address O Use the following DNS server addresses Preferred DNS server Vigor3300 Series User s Guide 149 Dr ay Te k For MacOs 1 Double click on the current used MacOs on the desktop 2 Open the Application folder and get into Network 3 On the Network screen select Using DHCP from the drop down list of Configure IPv4 aa Network amp ZH Show All Displays Sound Network Startup Disk Location Automatic Ke Show Built in Ethernet HH PPPoE AppleTalk Proxies Ethernet IP Address 192 168 1 10 Renew DHCP Lease Subnet Mask 255 255 255 0 DHCP Client ID If required Router 192 168 1 1 DNS Servers Optional Search Domains Optional IPv6 Address fe80 0000 0000 0000 020a 95ff fe8d 72e4 Configure IPv6 id Click the lock to prevent further changes
83. able Click this radio button to make the first available port in the port same group ringing while receiving incoming calls Rings by round robin Click this radio button to make the phone port ringing in sequence within the same group Dr ay Te k 132 Vigor3300 Series User s Guide Default Group Click this button to return to the factory group settings 3 7 3 Speed Dial This page allows you to set a simple way to dial a specific number Up to 150 numbers can be stored in Vigor3300V VolP Speed Dial Speed Dial Phone Number Speed Dial Destination Memo 1 1001 1001 iptel org dial 1 i 5 Example 101 101 iptel org Apply Cancel Clear This Page Speed Dial Phone Number Type the phone number to be used as quick dial Speed Dial Destination Type the destination address of the dial Memo Type a description for the specified number Apply Click this button to activate the page settings Clear This Page Click this button to remove all the settings in this page 3 7 4 Advanced Speed Dial Speed dial allows users to call out with simple buttons instead of dialing long numbers To set a speed dial with specified settings please open the following page VolP Advanced Speed Dial Prefix Strip Length Append Destination Memo 1 2 3 O0 4 0 5 6 7 8 O 9 10 1 Edit Delete Delete All Prefix Display the prefix number of the entry Strip Length Display
84. agement Access Control HTTP Allow Management fram the WAN 9 Disable M Enable Enable User Defined WAN IP Management Port 9 Default Ports HTTP Ported Telnet Port23 PING Restriction Disable PING from the LAM Disable PING from the WAN Management Method Allow Management from the WAN Management Port PING Restriction Vigor3300 Series User s Guide Q User Defined Ports HTTP Pot feo Telnet Port 23 SSH Part 2 j Apply Cancel There are three management methods provided here for you to choose for your router Check HTTP Telnet SSH for the router Disable Disable the management from the WAN interface Enable All Enable all management through HTTP Telnet SSH from the WAN interface Enable User Defined WAN IP System can be managed by these three IP addresses via WAN Allowed IP1 to 3 Type in IP address up to three for managing the system Default Ports Use the default ports for HTTP and Telnet if you choose HTTP and Telnet as management methods User Defined Ports Or you can assign new port numbers for HTTP Telnet and SSH respectively Disable PING from the LAN Choose this function to reject all ICMP packets from LAN side 29 Dray Tek Disable PING from the WAN Choose this function to reject all ICMP packets from WAN side 3 1 5 Configuration Setup Most of the settings can be saved locally as a configuration file and can be applied to another router
85. al GRE IP Remote Gateway Remote GRE IP Interface Profile Status Operational Status 000000000 9 1 Refresh Edit Delete Delete All Refresh Refresh the page information Edit Configure an entry Clicking this button can guide you accessing into editing page for that IPSec tunnel For detailed information refer to the following section of For Default Configuration Delete Delete a designated entry Delete All Delete all entries in the table Vigor3300 Series User s Guide 109 Dr ay Te k For Default Configuration To edit or add a policy please click one of the radio buttons and click Edit The following page of default configuration will be shown VPN IPSec VPN Trunk Policy Table Edit Basic Profile Status Enable Name Authentication Preshared Key w Preshared Key Security Protocol ESP NAT Traversal Enable v Local Gateway WAN Interface V N1 wj Local Certificate Security Gateway default Local GRE IP Next hop default Remote Gateway Remote ID Security Gateway Remote GRE IP Profile Status Name Authentication PreShared Key Security Protocol Dray Tek 0 0 0 0 for dynamic client Apply Cancel Set the initialization of IPSec Tunnel with this profile Enable Choose this one to active this profile Disable Choose this one to inactivate this pro
86. am header Activates the Block Land function A Land attack occurs when an attacker sends spoofed SYN packets with identical source address destination addresses and port number as those of the victim Activates the Block Smurf function The router will reject any ICMP echo request destined for the broadcast address Activates the Block trace route function The router will not forward any trace route packets Activates the Block SYN fragment function Any packets having the SYN flag and fragmented bit sets will be dropped Activates the Block fraggle Attack function Any broadcast UDP packets received from the Internet are blocked Activates the Block TCP flag scan function Any TCP packet with an anomalous flag setting is dropped These scanning 89 Dray Tek activities include no flag scan FIN without ACK scan SYN FIN scan Xmas scan and full Xmas scan Enable Tear Drop Activates the Block Tear Drop function This attack involves the perpetrator sending overlapping packets to the target hosts so that target host will hang once they re construct the packets The routers will block any packets resembling this attacking activity Enable Ping of Death Activates the Block Ping of Death function Many machines may crash when receiving an ICMP datagram that exceeds the maximum length The router will block any fragmented ICMP packets with a length greater than 1024 octets Enable Block ICMP Activates the Block ICM
87. ask Select a value of subnet mask for private IP address Click Apply to reboot the system and apply the settings By the way user can click Delete to remove one current existed NAT entry in the Advanced NAT Address Mapping page and click Delete All to remove all entries DMZ Host In computer networks a DMZ De Militarized Zone is a computer host or small network inserted as a neutral zone between a company s private network and the outside public network It prevents outside users from getting direct access to company network A DMZ is an optional and more secure approach to a firewall and effectively acts as a proxy server as well In a typical DMZ configuration for a small company a separate computer or host in network terms receives requests from users within the private network for access to Web sites or other companies accessible on the public network The DMZ host then initializes sessions for these requests on the public networks However the DMZ host is not able to initiate a session back into the private network It can only forward packets that have already been requested Users of the public network outside the company can access only the DMZ host The DMZ may typically also have the company s Web pages so these could be served to the outside world If an outside user penetrated the DMZ host s security only the Web pages will be corrupted but other company information would not be exposed Dr ay Te k 66 Vigor3300 Series User
88. ate network and the outside public network It prevents outside users from getting direct access to company network A DMZ is an optional and more secure approach to a firewall and effectively acts as a proxy server as well In a typical DMZ configuration for a small company a separate computer or host in network terms receives requests from users within the private network for access to Web sites or other companies accessible on the public network The DMZ host then initializes sessions for these requests on the public networks However the DMZ host is not able to initiate a session back into the private network It can only forward packets that have already been requested Users of the public network outside the company can access only the DMZ host The DMZ may typically also have the company s Web pages so these could be served to the outside world If an outside user penetrated the DMZ host s security only the Web pages will be corrupted but other company information would not be exposed The service provider must provide the exact settings for this mode FEET IS DMZ Configuration Eae a a otatic ODHCP Configuration OMZ Host Type Outgoing Interface DMZ Host IP List Only Routing Mode 3 Loo 4 tt ttstst iz Apply Reset Cancel IP Address Set the private IP address of WAN interface Subnet Mask Set the subnet mask value of WAN interface Dr ay Te k 46 Vigor3300 Series User s Guide DMZ Host Type Outgoing Inte
89. behind that port must support VLAN and are tagged with certain VLAN groups with specified ID numbers Untagged All the computers behind that port do not support VLAN feature Note It is recommended to group computers that do not support VLAN feature or support VLAN feature but their Untagged VLAN settings are checked in one port with untagged This device will tag proper port VLAN ID for untagged PC respectively for making them communicating with the router Enable Management Port It can help users to communicate with router still even though for P4 configuring the wrong setting in the 802 1Q VLAN tag The management port will lock index 4 We recommend that users enable the management port to fix the fourth VLAN settings unless users want to use the fourth VLAN and ensure the settings are correct You have to set Port VLAN ID for P4 previously before you check this box Port VALN ID Type the ID for each port used for identification on VLAN When the tag operation for each port representing for different computers connected to this router 1s marked by untagged to avoid conflict occurred the system will apply the ID listed in these boxes automatically for each port P1 to P4 to ensure proper and correct network operation 3 3 10 SNMP The Simple Network Management Protocol SNMP is an application layer protocol that facilitates the exchange of management information between network devices There is a set of protocols for mana
90. ble Block Trace Route Enable Block SYN Fragment Enable Block Fraggle Attack Enable TCP Flag Scan Vigor3300 Series User s Guide the subsequent TCP SYN packets within the user defined timeout period The default setting for threshold and timeout are 300 packets per second and 10 seconds respectively Activates the UDP flood defense function If the amount of UDP packets from the Internet exceeds the user defined threshold value the router will be forced to randomly discard the subsequent UDP packets within the user defined timeout period The default setting for threshold and timeout are 300 packets per second and 10 seconds respectively Activates the ICMP flood defense function If the amount of ICMP echo requests from the Internet exceeds the user defined threshold value the router will discard the subsequent echo requests within the user defined timeout period The default setting for threshold and timeout are 300 packets per second and 10 seconds respectively Activates the Port Scan detection function Port scan sends packets with different port numbers to find available services which respond The router will identify it and report a warning message if the port scanning rate in packets per second exceeds the user defined threshold value The default threshold is 300 pps packets per second Activates the Block IP options function The router will ignore any IP packets with IP option field appearing in the datagr
91. chanism VPN TRUNK Management is a backup mechanism which can set multiple VPN tunnels as backup tunnel It can assure the network connection not to be cut off due to network environment blocked by any reason gt VPN TRUNK VPN Backup mechanism can judge abnormal situation for the environment of VPN server and correct it to complete the backup of VPN Tunnel in real time VPN TRUNK VPN Backup mechanism is compliant with all WAN modes single multi gt The web page is simple to understand and easy to configure Filly compliant with VPN Server LAN Sit Single Multi Network Y gt Syslog support please refer to System gt gt SysLog for detailed configuration Features of VPN TRUNK VPN Load Balance Mechanism VPN Load Balance Mechanism can set multiple VPN tunnels for using as traffic load balance tunnel It can assist users to do effective load sharing for multiple VPN tunnels according to real line bandwidth The TCP Session transmitted by using VPN TRUNK VPN Load Balance mechanism will not be lost due to one of VPN Tunnels disconnected Users do not need to reconnect with setting TCP UDP Service Port again The VPN Load Balance function can keep the transmission for internal data on tunnel stably To create a VPN IPSec policy for VPN Trunk click the Policy Table option under the IPSec gt gt VPN Trunk menu Dr ay Te k 108 Vigor3300 Series User s Guide VPN IPSec VPN Trunk Policy Table Connection Name Loc
92. ck hook flash to pick up the waiting phone call CLIP Display Click Enable to display the call number Apply When you finish all the configurations please click this button to activate them For Group It is very important to provide a Group function for voice service within a company Customers can simultaneously call the same phone number When the Vigor3300 gets a phone call which is configured in the first port of a group from Internet it will ring all available ports belonging to this group to provide voice service at the same time It is easier for the customer to remember just one phone number corresponding to the company By enabling this function the 4 or 8 port VoIP will use the first enabled port phone setting on the table as their phone number Up to 8 groups can be configured and assigned a specific phone line Each phone line must be unique and cannot be overlapped as shown below VoIP Port Settings Group O Disable 9 Enable Group Port 1 2 3 4 5 6 7 8 1 O O O O O O O 2 O o O O O O O O O O O O O 4 0 O O O O 5 O O O O 9o O O O 6 86 7 O O O O O O O9 O 0 e o o 8 9 Incomming Call Rings 9 Rings all ports in the group O Rings the first available port O Rings by round robin Default Group Apply Cancel Rings all ports in the group Click this radio button to make all ports in the same group ringing while receiving incoming calls Rings the first avail
93. common ports used in Internet The information includes service application protocol for that service and port number of that service Advanced NAT Common Ports List Service Application Protocol Port Humber File Transfer Protocol FTP Ter 27 SSH Remote Login Protocol ex pcAmvhere LOOP 27 Telnet TEE 23 Simple Mail Transfer Protocol GG8MTP TEF 25 Domain Mame Server DNS EP 53 Wil Server HTTP TCR a0 Fost Office Protocol ver 3 POPS TCP 110 Metwork Mews Transfer Protocol MTP TOP 118 Point to Point Tunneling Protocol PPTF ee na pcANYVWWHERE data TCP 553 pcANYVWHERE stat UDP 5632 wine TCP 5900 3 3 3 RADIUS Setup A RADIUS Remote Authentication Dial In User Service is a security authentication client server protocol widely used by Internet service providers on other remote access service A RADIUS is the most common means of authenticating and authorizing dial up and tunneled network users The built in RADIUS client function allows you to extend the remote dial in user accounts to the RADIUS server Your user accounts will not be limited by built in accounts in VPN gt gt PPTP gt gt User Profile It also lets you centralize remote access authentication for network management Radius is a server for remote user authentication and accounting Its primary use is for Internet Service Providers though it may as well be used on any network that needs a centralized authentication and or accounting service A Radius support
94. cryption These objectives are met through the use of two traffic security protocols the Authentication Header AH and the Encapsulating Security Payload ESP and through the use of cryptographic key management procedures and protocols General Setup General Setup allows you to set MTU value for VPN The default number is 1400 VPN IPSec General Setup Apply Cancel Policy Table To create a VPN IPSec policy click the Policy Table option under the IPSec menu Dr ay Te k 102 Vigor3300 Series User s Guide VPN IPSec Policy Table Connection gen Profile tional Et i amp mane Local Subnet Remote Gateway Remote Subnet Interface Status Operational Status Action 1 e Research JR RC n e alae Id d 17216215532 WAMI enable down Initiate 2 0 3 Q0 O 5 O 6 i 8 O 3 1 O 1 Refresh it Delete Delete All Refresh Refresh the page information Edit Configure an entry Clicking this button can guide you accessing into editing page for that IPSec tunnel For detailed information refer to the following section of For Default Configuration Delete Delete a designated entry Delete All Delete all entries in the table To edit or add a policy table please click one of the radio buttons and click Edit Vigor3300 Series User s Guide 103 Dr ay Te k For Default Configuration Click Default tab The following page of default configuration will be shown VPN IPSec Tunnel
95. ct Protocol sip OMGCP SIP MGCP Configuration Configuration SIP Local Port 5060 Outbound Proxy Proxy Name Proxy Port D 2 i D Example iptel iptel org iptel org iptel org Registrar Expires Domain Port sec Active Proxy Address Registrar Addr Proxy User Agent Name 1 DrayTek Y3300 Y 1 0 0 2 DrayTek V3300V 1 0 0 DrayTek V33D0v 1 D 0 Apply Cancel For SIP Configuration SIP Local Port Active Outbound Proxy Proxy Name Proxy Address Proxy Port Registrar Address Registrar Port Expires Domain User Agent Name Dray Tek Type the port number for SIP protocol The default value is 50060 Click this box to activate this SIP proxy server setting Check this box to enable this function for sending SIP protocol packets to an SIP proxy server Type the name of the SIP proxy server Type the IP address of the SIP proxy server Type the port number of the SIP proxy server Type the IP address or domain name of the SIP registrar server Type the port number of the SIP registrar server Type the timeout value for SIP protocols The default value is 300 Type the IP address or domain name of the SIP Domain Realm You can set up to 3 sets of SIP configurations in this page 126 Vigor3300 Series User s Guide For MGCP Configuration VoIP Protocol Select Protocol Osi
96. d Domain Name are required for same ISPs Primary DNS 4689511 H secondary DNS r B8 95 192 1 IP Alias List 1 10 1 1 100 2 40 1 1 101 10 1 1 102 4 Next gt gt All the settings here are set by privately Your ISP will not provide these settings IP Address Assign a private IP address to the WAN interface Subnet Mask Assign a subnet mask value to the WAN interface Default Gateway Assign a private IP address to the gateway Primary DNS Assign a private IP address to the primary DNS Secondary DNS Assign a private IP address to the secondary DNS IP Alias List Assign other IP addresses to be bound to this interface This setting 1s optional If you have typed addresses here you can see and choose it in later web page settings e g Advanced gt gt NAT gt gt Port Redirection DMZ Host Thirty two IP addresses settings are allowed at one time After setting up the WAN interface the user can click Next to setup the LAN interface continuously Vigor3300 Series User s Guide 15 Dr ay Te k Quick Setup LAN DHCP Relay LAN IP DHCP Agent IP Routing IP Configuration IP Address 192 168 1 3 Subnet Mask 255 255 255 0 DHCP Server Status Start IP End IP Primary DNS Secondary DNS Lease Time Min Gateway IP Optional IP Address Subnet Mask Status Start IP End IP Primary DNS Secondary DNS Lease Time Min 9Enable ODisable
97. d a user certificate please click index number one with the status of Request Generated and click the Download button If not you might see the following dialog to warn you Microsoft Internet Explorer A You can download only when the status is Request Generated After you click the Download button the system will guide you to save the downloaded file newreq RD computer 1 pem to a place that you assign File Download Some les can ham pour computer f the fide information below looks suspicious or vou do not fully tust the source do not open or save this file in Desktop My Documents VJ My Computer VjMy Network Places 32 5 3 RC4 C3v2800v COVPN 200tunnel Network Connections File name newreg 3300CA 1 pem 35 0 File type From 192 163 1 1 Would you like to open the File or sve it to your computer A My Computer v Always ack before opening this type ol file 111 32900 cfg 3300 Desktop My Documents Moelnio My Network Save as type pem Document 118 Vigor3300 Series User s Guide To import a user certificate that you saved previously please click index number one with the status of Request Generated and click the Import button If not you might see the following dialog to warn you Microsoft Internet Explorer EN You can import only when the status is Request Crenrated After you click the Import button the system wil
98. dically when a tunnel is idle Use the value 0 to disable this function The recommended value is 30 seconds if enabled Timeout The timeout timer The peer will be declared dead once no acknowledge message is received after timeout value Use the value 0 to disable this function The recommended value is 120 seconds 1f enabled After finish the configuration click Apply to apply the IPSec policy setting into the policy table VPN IPSec Policy Table Connection Name Local Subnet Remote Gateway Remote Subnet Interface Admin Status Operational Status Action Research 172 16 3 228 32 a ee a a Be WANT enable down Initiate OO0000000090q 1 Refresh Edit Delete Delete All Significant fields will be summarized in the IPSec Table Operational Status reflects the current status of the tunnel UP means the IPSec tunnel has been established DOWN means no tunnel existing or termination status of the tunnel If user expects the local gateway to act as the IKE initiator 1 e emit the first IKE main mode message user can click the hyperlink Initiate to start the IKE negotiation or set Vigor3300 Series User s Guide 107 Dr ay Te k admin status to be always on to automatically restart IKE negotiation During the negotiation you can press Refresh to show the latest status of all policies VPN Trunk Policy Table VPN trunk includes two features VPN Backup and VPN load balance Features of VPN TRUNK VPN Backup Me
99. dit selected IP filter table Allow you to delete selected IP filter table configuration If this entry is assigned as the started filter group already it cannot be deleted To add a new group please click Add on the Group Table page to access into the following page In this page you can type in new group name and decide the next group name Also you can type in your comment for such group After you click Apply the new group will be added and you will see it from the drop down menu of Start Filter Group Firewall IP Filter Table Group ame Next Group Mame Comment Dray Tek none bud Apply Cancel 84 Vigor3300 Series User s Guide Group Name Type in the name of the group Next Group Name Select next group to filter packets Comment Type in your comment or description for the group To edit a select group please click the number link to open the following page You can change the next group name and modify the comment for your necessity When you finish the modification simply click Apply Firewall IP Filter Table Next Group Name Comment sroup for pass rules Add Rule Apply Cancel Besides you can add new filter rule for the group On the edit page of IP Filter Table click the Add Rule button The following page will be shown Firewall IP Filter Add Filter Rule Filter Condition Active Source IP Subnet Mask 255 255 255 0 Destination IP Subnet
100. dress or DDNS domain name The Vigor3300 Series supports up to 30 entries in the Deny List table When you choose Deny only calls from deny list as the Barring Class people listed in this list cannot call this router Vigor3300 Series User s Guide 141 Dray Tek VoIP Incoming Call Barring Deny List Name IP Domain 1 James 172 16 3 221 2 Steven arctel com 3 4 5 Example John 192 168 1 1 or iptel org 123456 Apply Cancel Name The name or number in the deny list IP Domain The IP address or domain name to be denied If the peer is registered in SIP proxy server use the domain name of the SIP proxy server Otherwise use the static IP address or DDNS domain name 3 7 10 Call History This page lists the call history through Vigor3300 You can click Refresh to get the latest history information for these VoIP phones Besides this page refreshes automatically every 10 seconds VoIP Call History Refresh Option Every 10 Seconds Refresh Port Call Caler Callee Start iii purati Release TER a RIP Codec Packet pp DTMF Number Type Number Number Time i Reason Address Port Statistic Type Period Relay PS Packets Sent 0S Octets Sent PR Packets Received OR Octets Received PL Packets Lost Ji Interarrival Jitter Estimate ime LA Avg TX Delayims Remote Port Caller Callee a Release Remote RTP RTP Codec Packet DTMF Number Call T
101. e IP Mode PPPoE Not Set Not Set Not Set Go to the web configuration GUI http 192 168 1 1 click Network gt gt WAN to check your ISP settings for IP modes Make sure the Active check box has been selected C Enable F Auto Weight C Enable Active Defat O m e m G E e Check if Username and Password are entered with correct values that you got from your ISP Check if the setting of Authentication is correct or not You may need to try both PAP and CHAP 152 Vigor3300 Series User s Guide 3 Check if Service Name optional is correct or not It is required by some ISPs Static DHCP Configuration PPPoE PPTP Configuration DMZ Configuration User Name 1234 hinet net PPTP Local Address Password esse PPTP Subnet Mask Authentication PAP PPTP Server Address Service Name PPPoE IP Alias Enable MTU 1442 IP Address Assignment Method IPCP Fixed IP 9 No Dynamic IP O Yes Fixed IP Address Connection Detection Detect Interval 10 Mo Reply Count 2 IP Alias List 1 10 1 1 100 2 10 1 1 101 3 10 1 1 102 4 5 6 7 8 a ho Apply Reset Cancel After finishing the settings go to System Status page and click WAN Status You will get a correct web page of WAN settings Basic Status LAN S
102. e DHCP server Next click IP Routing tab to set routing path for each WAN interface if required Quick Setup LAN LAN IP DHCP arcum WAN 1 Status QEnable Disable IP Address Subnet Mask WAN2 Status OEnable 9 Disable IP Address Subnet Mask WANS Status O Enable Disable IP Address Subnet Mask WAN4 Status OEnable 9 Disable IP Address Subnet Mask lt lt Previous When you finished the above settings please click Finish A system reboot page will appear Click Apply to activate the DHCP mode configuration Dr ay Te k 18 Vigor3300 Series User s Guide 2 2 3 PPPoE This mode is used for most of DSL modem users All local users can share one PPPoE connection to access the Internet Your service provider will give you the user name password and authentication mode for PPPoE settings Quick Setup WAN MAC Address Default MAC User Defined MAC Downstream Rate 102400 kbps Upstream Rate 102400 kbps Type Fast Ethernet Physical Mode u to Negot latioy IP Mode OStatic ODHCH 9 PPPoE D PPTP If your ISP provides you the PPPoE Point to Point Protocol over Ethernet connection please select PPPoE for this router to get the following page Enter the username and password provided by your ISP on the web page static DHC
103. e completed Please choose Port Base VLAN to open the following page Advanced LAN VLAN Setting O Disable 9 Port Base VLAN 902 10 VLAN Port Base P1 P2 P3 P4 VLANO E VLAN1 O C VLAN2 C 1 d VLAN3 O C Apply Reset Cancel P1 P4 Check the box to make the computer connecting to the port being grouped in the specified VLAN Be aware that each port can be grouped in different VLAN at the same time only if you check the box For example if you check the boxes of VLANO P1 and VLANI PI you can make P1 to be grouped under VLANO and VLANI simultaneously VLAN 0 3 This router allows you to set 4 groups of virtual LAN Apply After finishing the settings please click Apply Reset In addition you can click Reset to reset the VLAN setting as default A dialog will be prompted for you to ask confirmation Click OK Vigor3300 Series User s Guide TI Dr ay Te k For 802 1Q VLAN Another way to set VLAN is based on 802 1Q Please choose 802 1Q VLAN to open the following page This page is available only for the PCs with certain network cards which support 802 1Q VLAN feature It is useless for general network cards Advanced LAN VLAN Setting O Disable Port Base VLAN 9 802 10 VLAN Port Base VLAN 802 1Q VLAN Group Index Active Name VLAN ID Member Frame Tag Operation P1 P2 P3 P4 P1 P2 P3 P4 1 n A pm iilii resra ml md 2 o o ra w we pa zs wl 3 Tagged v tagged
104. e when the master slave device fails to work Edit Open the configuration page of this WAN interface IP Mode Display current mode of this WAN interface There are five options Static DHCP PPPoE PPTP and DHCP Active Activates closes this WAN interface Default Route Set this WAN interface as default route interface Load Balance Adds this WAN interface to the load balance group Weight Set the weight load 10 90 for this WAN interface for load balance This selection is available only when Auto Weight is unchecked Backup Master Set this WAN interface as a master interface WANI must be assigned as Master interface if Backup function is enabled Backup Slave Set this WAN interface as a slave interface VoIP Set this WAN interface as VoIP default interface Most users will use their routers primarily for Internet access The Vigor3300 Series supports broadband Internet access and provides multiple WAN interfaces The following sections will eive a detailed illustration to broadband access methods Click the Edit icon to bring up the WAN configuration page for the corresponding interface Vigor3300 Series User s Guide 39 Dr ay Te k Network WAN WAN1 Fast Ethernet MAC Address Default MAC User Defined MAC Downstream Rate 102400 kbps Upstream Rate 102400 kbps Physical Mode hut TJedqotiatiaon IP Made Static OpHcP PPPoE OPPTP Onpuz Default MAC Uses the default Mac address User Defined
105. ed settings that you made before Besides you can select Reset to factory default to reboot the device and retrieve the default settings In the System group choose the Reboot option In the web page of Reboot a user must either keep the current configuration settings or use the default configuration after the Vigor3300 Series system has been rebooted System Reboot System rebooting will take 20 seconds Resetto factory default Apply Click Apply to reboot the whole system The rebooting procedure usually takes 20 or more seconds System is rebooting please wat seconds lett If your current interface or management port configuration has been changed please access with the new URL Dr ay Te k 34 Vigor3300 Series User s Guide 3 1 8 Diagnostic Tools In some cases a user may need to know some information about the router such as static or dynamic databases or other routing information The Vigor3300 Series supports four functions Routing Table ARP Cache Table DHCP Assignment Table and NAT Active Sessions Table for the user to review such information In the System group click the Diagnostic Tools option Diagnostic Tools k a View Routing Table view ARP Cache Table view DHCP Assignment Table a View MAT Active Sessions Table a Data Flow Monitor Select View Routing Table to get the following page System Diagnostic Tools View Routing Table Destination Ga teway Subne
106. eny any Web surfing activity that directly uses an IP Access address Enable Exception List Click it to allow specified IP addresses or subnets to be passed through IP Address The allowed IP address Subnet Mask The allowed subnet mask of IP address Vigor3300 Series User s Guide 91 Dray Tek Exception List The list of IP addresses where content filter rules are not applied Content Filter Content Filter can help to avoid your employees accessing into improper websites and affecting the work efficiency protect your children from viewing inappropriate websites and accessing chat rooms and monitor and control web access from all computers connected to your router Firewall URL Filter ODisable 9 Enable URL Access i Restrict Web Control Content Filter EEG Filter Schedule Access Control by Category Content Filter ODisable 9 Enable Select a Server asia site v Permitted Categories List Forbidden Categories List URL Option v Add Edit Delete Exception URL List Examples of UR bi II ite e e elf will be ere t ect II ite e i jire excludi e directory itself will be considers lar ite e or file will be considere Apply Cancel Server Enable or Disable Content Filter Select a Server The domain name is used to as a server The name should be filled when enable Server otherwise it will impact performance Permitted Categories List The permitted categories are
107. eseuseceeseeaaseeesseeageeeesssaeeeesseageeeesssagsseeeessaas 83 SEN le FILO RE m 83 CU XP 88 JAS URL LII T 90 3 44 azgehiapunc 95 QA SD INVPSEBIOCRIPIO casu dette identusb pu r FeUen td Duce sp drcum EEE 96 35 Qualy or Service SOLID semen p tema pus bdavasc coa i duc rna tuduieat aeu Eia 97 3 5 1 Incoming Outgoing Class Setup eeeeessssssssesssseeeeeeeennn nnne nnne nnns 98 3 5 2 Incoming Outgoing Class Filter cee cccccseeeecceeceeeeeeeeeeeeeeeeessseeseeeeeseaeeeeeseeaeeeesesaaaeeeess 98 3 6 VPN and Remote Access Setup cccccccecseecccceeeceeeeseeeeeeesseesseeeeeeeeesseeaaeeeeeeeesseaeeeeeeeeessaas 101 Coss 102 CUP And E S M CCS e cee ree eee ee eee 120 SN de o aae Li o PER IE TEE EEE AEE TOE E E T ET EEE A E AEE 125 CWE eE E E E E E E E 125 WAS FIOM OS io CERRO OE 128 oa Peed DIGE ECT 133 3 7 4 Advanced Speed Dial cccccccssssssecececcceeessseeceeecceeaseeeeeeeseeeeauseeeeeeessssaaeeeeeesessaaagsees 133 BT RES COMIC OUS siera e tdantEMD EMEN QUEM URSI xD DHLed nU INE dT ERE 134 a TONE 1109 ERN TE m m 136 a O H PPU 138 SW ONAT Ec NOTET T 139 3 7 9 Incoming Gall BANO sisses iien Raa Ea ilonauntanc
108. ess specified Action Choose Allow to make the packet passing through Choose Disallow to block the packet in or out IM VoIP P2P Check the boxes for different applications filtering by this rule 3 5 Quality of Service Setup The QoS Quality of Service guaranteed technology in the Vigor 3300 Series allows the network administrator to monitor analyze and allocate bandwidth for various types of network traffic in real time and or for business critical traffic Thus timing sensitive applications will not be impacted by web surfing traffic or other non critical applications such as file transfer Without QoS guaranteed control there would be virtually no way to prioritize users services or guarantee allocation of finite bandwidth resources to network or servers for supporting timing sensitive and mission critical network applications such as VoIP Voice over IP and online gaming applications Differentiated quality of service is therefore one of the most important issues over the Internet infrastructure In the Vigor 3300 Series DSCP Differentiated Service Code Point support is also taken into consideration in the design of theQoS guaranteed control module The QoS function handles incoming and outgoing classes independently Users can configure incoming or outgoing separately without any impact on the other Vigor3300 Series User s Guide 97 Dr ay Te k 7 Incoming Class Setup 7c Incoming Class Filter c Outgoing Class Setup
109. ete All Destination IP Service Type Status DiffServ CodePoint Status Class 1 Delete Delete Al You are allowed to set ten filters The priority for the filter of number 1 is the highest and the priority for number 10 is the lowest Display the source IP address for the filter Display the destination IP address for the filter Display the service type that you choose for the filter Display the setting for DiffServ CodePoint Display the class name that you specified for the incoming outgoing class filter Click this button to open the edit page for adjusting the settings Click this button to delete the selected setting or all settings To edit an incoming class filter please choose one of the radio buttons under Priority and click Edit The following page will be shown automatically QoS Incoming Class Filter Edit Source IP Destination IP Service Type Status Service Type Protocol Source Port Destination Port DiffServ CodePoint Status DiffSery CodePoint Type DiffServ CodePoint Class Vigor3300 Series User s Guide 10 1 1 1 724 10 1 2 1 7249 O Basic Advanced O None TCP v 80 150 80 to Basic O Advanced O None BE D k Hex undefined vj Apply Cancel 99 Dray Tek Source IP Type the source IP address with subnet mask value to be applied for this filter Destination IP Type t
110. etwork can access the branch office network and vice versa The VPN technology implemented in the Vigor3300 Series of broadband security routers supports Internet industry standards to provide customers with interoperable VPN solutions Vigor3300 Series User s Guide 101 Dr ay Te k such as X 509 and DHCP over Internet Protocol Security IPSec This VPN feature is only supported for Vigor 3300 Vigor3300V routers IPSec is the security architecture for IP networks IPSec provides security services at the IP layer by enabling a system to select required security protocols It determines the algorithms to use for the services and puts in place any cryptographic keys required to provide the requested services IPSec can be used to protect one or more paths between a pair of hosts between a pair of security gateways or between a security gateway and a host The Vigor3300 Series supports ESP Tunnel mode with IKE for key management Internet Key Exchange IKE Protocol a key protocol in the IPSec architecture is a hybrid protocol using part of Oakley and part of SKEME in conjunction with ISAKMP to obtain authenticated keying material for use with ISAKMP and for other security associations such as AH and ESP for the IPsec DOI 3 6 1 IPSec The IPSec services can provide access control connectionless integrity data origin authentication rejection of replayed packets that is a form of partial sequence integrity and confidentiality by en
111. ewall group click the DOS option You will see the following page The DoS Defense Engine inspects each incoming packet against the attack signature database Any packet that may paralyze the host in the security zone is blocked The DoS Defense Engine also monitors traffic behavior Any anomalous situation violating the DoS configuration is reported and the attack is mitigated Firewall DoS C Enable SYN flood defense LJ Enable UDP flood defense LJ Enable ICMP flood defense J Enable Port Scan detection Black IP options LJ Block Land C Block Smurf C Block trace route Cl Block SYN fragment Block Fraggle Attack DoS Defense Enable SYN Flood Defense Dray Tek Threshold Packetsisec Timeout jo sec Timeout fio lee Timeout jio sec Threshold Packetsisec Threshold Packetsfsec Hill Threshold Packets sec C Block TCP flag scan Block Tear Drop C Block Ping of Death Block ICMP fragment C Block Unknown Protocol Apply Cancel Enables or disables the DoS Defense function The default value is Disable Activates the SYN flood defense function If the amount of TCP SYN packets from the Internet exceeds the user defined threshold value the router will be forced to randomly discard 88 Vigor3300 Series User s Guide Enable UDP Flood Defense Enable ICMP Flood Defense Enable Port Scan Detection Enable Block IP Options Enable Block Land Enable Block Smurf Ena
112. file Frofile Status Enable The name for VPN connection ex VPNI The maximum length of name is 20 characters including spaces The authentication to be used by PreShared Key or RSA Prezhared Key w Signature Authentication Preshared Key RSA Signature The shared key for peer identification The maximum length is 40 characters including spaces AH Specify the IPSec protocol for the Authentication Header protocol The data will be authenticated but not be encrypted ESP Specify the PSec protocol for the Encapsulating Security Payload protocol The data will be encrypted and authenticated Security Protocol 110 Vigor3300 Series User s Guide NAT Traversal WAN Interface Local Certificate Security Gateway Local GRE IP Next Hop Remote ID Security Gateway Remote GRE IP Vigor3300 Series User s Guide Click Enable to let this IPSec tunnel pass through next router Click Disable to close this function MAT Traversal Enable The WAN interface to be used WAN Interface The local certificate is active for authentication if the RSA Signature option is selected in the Authentication field These options come from the user certificate file The IP address of the local gateway s public network interface The keyword default can be used to represent the IP Address of the selected WAN Interface The virtual IP address of the router specified for thi
113. formation automatically There are four options given as shown below No Refresh Static information page Every 10 Seconds Refreshes the page every 10 seconds 23 Dray Tek Vigor3300 Series User s Guide Basic Status Every 20 Seconds Refreshes the page every 20 seconds Every 30 Seconds Refreshes the page every 30 seconds General status of this router will be displayed in this page System Status Refresh Option Basic Status Model Hardware Version Firmware Version Build Date amp Time System Uptime CPU Usage Memory Size Memory Usage Current System Time LAN Status No Refresh w Refresh WAN Status Vigor3300 1 0 2 5 9 0 EN 2009 02 11 18 29 24 0 days 0 hours 0 minutes 22 seconds 47 230796 64 MBytes 2009 03 20 10 20 23 Model Hardware Version Firmware Version Build Date amp Time System Uptime CPU Usage Memory Size Memory Usage Current System Time Dray Tek Display the model name of the router Display the hardware version of the router Display the firmware version of the router Display the date and time of the current firmware build Display the amount of time that the router has been online Display the average percentage of the CPU used Display the size of the memory of this router Display the percentage of memory used Display the current local system time 24 Vigor3300 Series User s Guide LAN Status The status of LAN co
114. ging complex networks SNMP works by sending messages called protocol data units PDUs to different parts of a network SNMP enables network administrators to manage network performance find and solve network problems and plan for network growth A SNMP managed network consists of three key components managed devices agents and network management systems NMSs A managed device is a network node that contains an SNMP agent and that resides in a managed network Managed devices collect and store management information and make this information available to NMSs by using SNMP Managed devices sometimes called network elements can be routers and access servers switches and bridges computers hosts or printers Vigor3300 Series User s Guide 79 Dr ay Te k This function is to define a community string name An agent is a network management software module that resides in a managed device An agent has local knowledge of management information and translates that information into a form compatible with SNMP An NMS executes applications that monitor and control managed devices NMSs provide the bulk of the processing and memory resources required for network management One or more NMSs must exist on any managed network In the Advanced group click the SNMP option There are two items for SNMP SNMP Community and SNMP Traps SNMP Community In general NMSs in the community exist within the same administrative domain EM
115. gnal The status of VAD The status of DTMF 145 Dray Tek This page is left blank Dr ay Te k 146 Vigor3300 Series User s Guide Trouble Shooting This section will guide you to solve abnormal situations if you cannot access into the Internet after installing the router and finishing the web configuration Please follow below sections to check your basic installation stage by stage Checking if the hardware status is OK or not Checking if the Network Connection Settings on your computer is OK or not Pinging the Router from your computer Vv Vv V WV Checking if the ISP Settings are OK or not gt Backing to factory default setting if necessary If all above stages are done and the router still cannot run normally it is the time for you to contact with your dealer for advanced help 4 1 Checking If the Hardware Status Is OK or Not Follow the steps below to verify the hardware status 1 Check if the power line and WLAN LAN cable connections is OK If not refer to 2 1 Hardware Installation for reconnection 2 Turn on the router Make sure the ACT LED blinks once per second and the correspondent WAN LAN LED is bright p LAN oy WAN DMZ m vpn eo iN p e e 100 e e e E er ewr Q acr e aos e e rp e e o P1 P2 P3 P4 P1 P2 P3 P4 Power Cable Vigor3300V a ame Mul Sareie Security of on mo c9 er OeeerCeee Sit gees Doo 2992 999 TTT DSL
116. he Attack function is inactive QoS The QoS function is active Off The QoS function 1s inactive LNK The Ethernet link is established on corresponding port No Ethernet link is established MUN 100M On It means that a normal 100 Mbps connection is oye through its corresponding port Off It means that a normal 10 Mbps connection is through its corresponding port FDX On It means a full duplex connection on corresponding port Off It means a half duplex connection on corresponding port LNK The Ethernet link is established LAN The data transmission is done through the 1 2 3 4 corresponding port Off No Ethernet link 1s established It means that a normal 100Mbps connection is through its corresponding port Off It means that a normal 1OMbps connection is through its corresponding port FDX On It means a full duplex connection on corresponding port D OOO 8 7 7 5 Dr ay Te k 6 Vigor3300 Series User s Guide Status Explanation Off It means a half duplex connection on corresponding port cc wan WAN1 WAN2 WANS Interface Description Console LAN PI P4 WANI WAN3 Provided for technician use Connecter for local networked devices Connecter for remote networked devices Connecter Specification Auxiliary Type Connected to Remarks Cables Power Cord AC Outlet 90 264V AC Serial Console RS232 Grey PC RS232 port Ethernet LAN
117. he assigned entry To generate a user certificate please click one radio button to select the entry and click the Generate button VPN IPSec User Certificate 2 Generate Generate Certificate Signing Request Certification Name ID Type ID Value User Certificate Information Organization Unit Organization Locality City State Province Common Name Country e mail Key Size Certification Name Vigor3300 Series User s Guide 3300CA 0804 Domain Name RD3 Draytek Houko Hsin Chu abc Taiwan v abc draytek com tw Apply Cancel The name of the certification entry 117 Dray Tek Dray Tek ID Type ID Value Organization Unit Organization Locality City State Province Common Name Country E mail Key Size The ID type for this entry There are three types Domain Name Certificated by domain name IP Certificated by IP address Email Certificated by email address The ID value for this entry The unit value of this organization The value of this organization The local city name of this entry The state name of this entry The common name for this entry The country name of this entry The email address of this entry The key size for this entry There are 3 options 1024 Bits 1536 Bits and 2048 Bits When you finish the configuration please click Apply to invoke it To downloa
118. he destination IP address with subnet mask value to be applied for this filter Service Type Status There are three options for you to choose Basic Only the Service Type field is allowed to be configured Advanced The Protocol and Port fields are allowed to be configured None No field is allowed to be configured Service Type Select the service type that you want to use There are thirty five service types provided CU SEEME LO TCP UDP 7648 DNS TCP UDP 53 n IPSEC AH IP 51 IPSEC ESP IP 50 IRC TCP UDP 6667 NNTP TCP 119 PING IP 1 POP3 TCP 110 PPTP TCP 1723 RCMD TCP 512 REAL AUDIO TCP 7070 RTSP TCP UDP 554 SFTP TCP 115 SMIP TCP 25 SNMP TCP UDP 161 SNMP TRAPS TCP UDP 162 SOL NET TCP 1521 SoH TCP UDP 22 SYSLOG UDP 514 TELNET TCP 23 TFTP UDP 69 FTP TCP 20 21 v Protocol There are three options TCP UDP and TCP UDP Choose the one you need Source Destination Port Type the port range number for this filter DiffServ CodePoint Status There are three options Basic Only the DiffServ CodePoint Type field can be configured Advanced Only the DiffServ CodePoint field can be configured None No field allowed to be configured Dr ay Te k 100 Vigor3300 Series User s Guide 3 6 VPN DiffServ CodePoint Type There are twenty one types supported precendence precendence precendence precendence precendence precendence precendence CLA
119. he protocol used for this address mapping Public IP Display the public IP address selected for this entry Private IP Display the private IP set for this address mapping Mask Display the subnet mask selected fro this address mapping Edit Allow users to edit the selected address mapping settings Delete Delete All Remove one all the selected address mapping settings To edit an item click the radio button of the item that you want to modify Then click Edit on the bottom of the page to add a new rule entry or modify an existed rule entry Advanced NAT Address Mapping Edit Protocol TCP w Public IP 10 1 1 100 w Private IP 20 1 1 1 Subnet Mask 724 Apply Cancel Vigor3300 Series User s Guide 65 Dr ay Te k Protocol Select the transport layer protocol It could be TCP UDP or All for selection Public IP Select an IP address the selections provided here are set in IP Alias List of Network gt gt WAN interface Local host can use this IP to connect to Internet If you want to choose any on of the Public IP settings you must specify some IP addresses in the IP Alias List of the Static DHCP Configuration page first If you did not type in any IP address in the IP Alias List the Public IP setting will be empty in this field When you click Apply a message will appear to inform you Private IP Assign an IP address or a subnet to be compared with the source IP address for incoming packets Subnet M
120. he road warrior with a dynamic IP address The subnet behind the remote gateway If the remote gateway IP address is 0 0 0 0 this field can be omitted but you can specify it as 0 0 0 0 32 for clarity For Advanced Configuration Click Advanced tab The following page of default configuration will be shown Dray Tek Vigor3300 Series User s Guide 105 Dray Tek VPN IPSec Tunnel IKE Phaset main mode Key lifetime Proposal IKE Phase2 quick mode Key lifetime Proposal Accepted Proposal Dead Peer Detection Status Delay Timeout 480 minutes des nd5 nodp 68 des sha nodp 768 w 3des md5 nodp 68 w 3des md5 nodpl024 60 minutes des md5 v 3des nd5 v des v 3des v CI PFS Perfect Forward Secrecy ccept all supported proposal v O Disable 9 Enable s seconds 120 seconds Apply Cancel Key Lifetime main The rekey renegotiated period of the IKE Phase1 keying Proposal main channel of a connection The acceptable range is from 5 to 480 minutes 8 hours The proposed encryption and or authentication algorithms for IKE Phasel negotiation There are several proposals offered in this page with combination of three types of algorithms Encryption algorithms DES 3DES AES Authentication algorithms MD5 SHA1 DH Diffie Hellman Group MODP768 MODP1024 MODP1536 Proposal dez mdb5 modp 68 v LL LS dez mdb5 moedmnh58 dez mdb5 m
121. host dyndns org work click Enable to active this function MX stands for Mail Exchanger Mail Exchangers are used for directing mail to specific servers other than the one a hostname points at Assign an email address Click Apply to finish these settings and return to previous page Note 1 The Wildcard and Backup MX features are not supported for all Dynamic DNS providers You could get more detailed information from their websites 2 Backup MX provides a secondary mail server to hold your e mail if your main email server go offline for any reason Once you go back online your email will be delievered to you Dray Tek 72 Vigor3300 Series User s Guide 3 3 6 Call Schedule Setup These call schedule profiles will control the up or down time of the router s dialer or connection manager In order to do the proper call schedule function a user must have to setup time function and arrange schedules for specified Internet access profile or LAN to LAN profile Vigor3300 Series support lots of profiles for call schedule usage In the Advanced group click the Call Schedule option You will get the following page Advanced Call Schedule Status Date amp Time Action How often Week Option WAN 1 9 Enable 2006 4 18 00 00 Force On Once WANI 2 3 4 O gt 5 FO 8 4 10 O 1 Delete Delete All Status Display the activation status enable or disable for this entry Date amp Time Display the
122. ick and select the one and click Remove The selected item will be removed from the IP Bind List Note Before you select Strict Bind you have to bind one set of IP MAC address for one PC If not no one of the PCs can access into Internet And the web configurator of the router might not be accessed 3 4 5 IM P2P Blocking IM Blocking means instant messenger blocking P2P is the short name of peer to peer You will see a list of common P2P applications You can define blocking rules such as specified an IP address for passing through or blocking for IM Instant Messenger P2P Peer to Peer application Firewall IM P2P Blocking Source IF Subnet Mask Action Option oco moGooo o e i Delete Delete All To edit IM P2P blocking rule please choose one of the radio buttons under and click Edit The following page will be shown automatically Dr ay Te k 96 Vigor3300 Series User s Guide Firewall IM P2P Blocking Edit Action O Allow 9 Disallow IM MSN Yahoo Messenger F ice C alm aa E ichat F Google Talk CI web Ii http iia messenger neth nu NR VoIP jajah C Skype P2P Protocol Applications C SoulSeek SoulSeek eDonkey eDonkey eMule Shareaza FastTrack Kazaa iMesh Gnutella BearShare Limewire Shareaza BitTarrent BitTorrent Apply Cancel Source IP Specify an IP address for Vigor router to perform IM P2P blocking Subnet Mask Type the subnet mask for the IP addr
123. ick this button to make RTP and T 38 being not symmetrical Enable symmetric RTP and T 38 Click this button to make RTP and T 38 being symmetrical When Vigor3300 detects the IP address of the receiving packets differing with the address informed by remote end Vigor3300 will change the IP address automatically according to the real IP address of the packets to ensure the remote receiver can get the packets This feature is used to bar incoming VoIP calls from the Internet Barring classes can be specified to allow or deny incoming calls There are five barring classes on the device The default setting is Allow all incoming calls Set This page allows you to choose a barring class match method and set a range for speed dial entries for the incoming call barring VoIP Incoming Call Barring Set Barring Class Deny only Match Method Name IP Domain Speed Dial Entries From 1 v To 150 v Barring Class Dray Tek calls from deny list v O Enable Enable Apply Cancel There are five options for incoming calls from remote ends Choose either one of them to set the barring class Deny only calls from deny list ial Allow all incoming calls Allow only calls from allow list Allow only calls trom speed dial entries Deny only calls trom deny list Deny all incoming calls Allow all incoming calls All incoming calls from remote 140 Vigor3300 Series User s Guide Match Meth
124. idth Management Limitation Table Edit Start IP End IP TX Limit Kbps RX Limit Kbps Apply Cancel Start IP End IP Assign the IP range for the bandwidth management TX Limit Define the limitation for the speed of the upstream If you do not set the limit in this field the system will use the default speed for the specific limitation you set for each index RX Limit Define the limitation for the speed of the downstream If you do not set the limit in this field the system will use the default speed for the specific limitation you set for each index Apply After finishing the configuration please click this button to invoke these settings 3 2 7 Limit Session A PC with private IP address can access to the Internet via NAT router The router will generate the records of NAT sessions for such connection The P2P Peer to Peer applications e g BitTorrent always need many sessions for procession and they will occupy over resources which might result in important accesses impacted To solve the problem you can use limit session to limit the session procession for specified Hosts dz Limit Session Fo General Setup i HS Limitation Table Dr ay Te k 58 Vigor3300 Series User s Guide General Setup This function allows users to configure general settings for limit session In the Network group choose Limit Session and then General Setup You will get the following page Network Limit Sessio
125. ifies the port number is between the Start Port and End Port It means the destination IP address for this filter rule Placing 66g e the symbol before a particular IP address will prevent this rule from being applied to that IP address It is equal to the logical NOT operator It means the subnet mask for the destination IP It means the port for the destination IP It means the filter group for the current rule It is the protocol s for this filter rule any protocol Protocal The direction of packet flow VPN In is for incoming packets VPN Out is for outgoing packets and Any is for both 86 Vigor3300 Series User s Guide Fragments Block or Pass Next Group Name Apply Vigor3300 Series User s Guide directions LUN WAN to LAN It is the response to fragmented packets There are three options as below Fragment do not care unfragment fragment Do not care Specifies no fragment options Unfragment Applies the rule to unfragment packets Fragmented Applies the rule to fragmented packets The action to be taken when packets match the rule There are four options Block ar Pass Block immediately v Block immediately Pass immediately Block if no further match Pass if no further match Block immediately Block the packet immediately Pass immediately Pass the packet immediately Block if no further match means to locks the packet if no further
126. igor3300V TTD SIT 2000V Port FXS Port FXS BERKS ERRIO China d Shanghai Phone Taiwan Phone 2 Configuration table between 3300V and 2900V wan por Number Phone Number Proxy Codec The number of the PSTN line connected into the FXO Port 5 on the 3300V is 12345678 The number of another PSTN line is 87654321 Vigor3300 Series User s Guide 205 Dr ay Te k About VoIP basic settings please refer to VoIP Example 1 Basic configuration and registration Start to dial by using telephones Phone calls Phone 3 gt Press 888835 After getting through you will hear the dial tone then press the PSTN number 876543211 Phone 2 calls Phone 3 gt Press 8888354 After getting through you will hear the Dial tone then press the PSTN number 876543211 Phone 3 calls Phone 2 gt Press 12345678 After getting through you will hear the Dial tone then press the VoIP number 8888291 Phone 3 calls Phone 1 gt Press 12345678 After getting through you will hear the Dial tone then press the VoIP number 8888334 Note indicates termination of the phone number After pressing VoIP is immediately called out Or you may wait 3 seconds if you do not press Connect PBX s Inside Lines The usage is the same as that of common extension Different PBX has its own settings and required configuration by you By connecting 3300V s FXO Port5 to PBX s Inside Line VoIP is seamlessly integrated to PB
127. ill introduce three basic VoIP calling methods involving Direct IP Call Intercommunication with one SIP Proxy Server and Intercommunication with different SIP Proxy Servers All the settings are based on the VoIP Example I Basic Configuration and Registration Direct IP Call Call with each other without registration Connect a telephone into 3300V s Port 1 and 2900V s Port 1 respectively They can call with each other directly with IP addresses if only 3300V and 2900V both have public IP addresses and have set up the Phone Numbers Below shows a scenario architecture graph Internet 220 135 240 207 61 31 167 135 2000 V FXS FXS B88833 SBER2U ay China Shanghai Phone Phone 2 Taiwan Dr ay Te k 190 Vigor3300 Series User s Guide Configuration table O 220 135 240 20 l 3300V Portl FXS 888833 iptel G 729A 2900V 61 31 167 135 Porti FXS 688829 G 729A Furthermore do NOT enable the Outbound Proxy feature when you set up 3300V and 2900V to use Direct IP Call It is not active in the Example 1 please see Figure 30 2 shown below Otherwise even if you dial the IP address the call will be sent to the SIP Proxy Server still Besides if the SIP Proxy Server doesn t forward the call to remote VoIP user s WAN IP you can t do this action VolP Protocol SIP Pon 1 Port Selagi Protocc sr OMGCP oP Pod puo SP Por hen peri el ong Domain AGC SIP Configuratio
128. ined by the bandwidth of WAN interface The smaller the bandwidth is the smaller the packet will be Such activity can reduce the time delay of packet transmitting Meanwhile the VoIP packets will be inserted in the front of queue of signal for transmitting quickly and obtaining best audio quality Please check this box to invoke this function shrinking the packet for fast sending 138 Vigor3300 Series User s Guide 3 7 8 NAT Traversal NAT traversal is a challenge that all Service Providers looking to deliver public IP based voice and multimedia services must solve The goal of this function is to provide secure connection to subscribers behind NAT Network Address Translation devices and Firewalls Overcoming this traversal problem will lead to widespread deployment of profitable voice and multimedia over IP services to any subscriber with broadband connection VoIP NAT Traversal NAT Traversal Disable Manual ly Input NAT IP Address 9 Auto Discover NAT IP Address Symmetric Media 9 Disable symmetric RTP and T 38 NAT Status Disable Manually Input NAT IP Address Auto Discovery NAT IP Address Vigor3300 Series User s Guide NAT IP Address Q Semi auto need to config NAT STUN Local Port STUN Server Address 9 Full a uto no need to config NAT only for SIP 3478 stun fwdnet net 3478 STUN Server Port Enable symmetric RTP and T 38 NAT Type N A Local IP
129. interval period of time for each detecting The minimum value is 3 and no limit for maximum value Vigor3300 Series User s Guide 41 Dr ay Te k No Reply Count Assign detecting times to ensure the connection of the WAN After passing the times you set in this field and no reply received by the router the connection of WAN interface will be regarded as breaking down Detect Destination Host Assign an IP address or Domain name as a destination to be IP or Domain Name detected whether the host 1s active sending reply to the router or not If not the connection of WAN interface will be regarded as breaking down This function is available when Detect Type is set with Send PING or Send Http Request IP Alias List Set other IP addresses binding in this interface You can set up to 32 sets of IP alias settings If you have typed addresses here you can see and choose it in later web page settings e g Advanced gt gt NAT gt gt Port Redirection DMZ Host Apply Click Apply to go back to the WAN Interface Configuration page To apply all settings click Apply on the WAN Interface Configuration page and reboot your router Reset Click this button to clear all the configurations for this page Dr ay Te k 42 Vigor3300 Series User s Guide DHCP Client Setup If the WAN interface is set as a DHCP client the Vigor3300 Series will ask for IP network settings from the DHCP server or DSL modem automatically It is not necessary for user
130. ion Firmware Upgrade Reboot Diagnostic Tools Version 2Sa orf Ad 5 The following screen will appear VIGOROUS BROADBAND ACCESS Quick Setup System Network Advanced Firewall QoS VPN VoIP 10 01 40 System Change Password Old Password New Password Confirm Password Apply Cancel Dr ay Te k 12 Vigor3300 Series User s Guide 6 Enter the login password 1234 on the field of Old Password Type a new one in the field of New Password and retype it on the field of Confirm Password Then click Apply to continue 7 Now the password has been changed Next time use the new password to access the Web Configurator for this router 8 Next you will see the login screen after clicking Apply Please use new password to re enter the system configuration Connect to 172 16 2 775 Login to vigor 3300 User name draytek Password TTT Remember my password 2 2 Quick Setup Quick Setup is designed for configuring your broadband router accessing Internet with simply steps There are two phases of quick setup one is WAN configuration and the other is LAN configuration In the Quick Setup group you can configure the router to access the Internet with different modes such as Static DHCP PPPoE or PPTP modes For most users Internet access is the primary application The router supports the Ethernet WAN interface for Internet access The following sections wi
131. itch OOOO Procedure l Refer to A 1 to block LAN to LAN communication 2 Create VLANS VLAN6 VLAN7 and VLANS Groups 3 Inthe VLANS input 5 to VLAN ID In the Member field choose pl p2 p3 and p4 Then choose the Tagged for Frame Tag Operation in pl p2 p3 and p4 We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from the switch 4 Inthe VLANO type 6 to VLAN ID In the Member field choose pl p2 p3 and p4 Then choose the Tagged for Frame Tag Operation in pl p2 p3 and p4 We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from switch 5 Inthe VLAN7 type 7 to VLAN ID In the Member field choose pl p2 p3 and p4 Dray Tek Then choose the Tagged for Frame Tag Operation in pl p2 p3 and p4 We can ignore 172 Vigor3300 Series User s Guide the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from the switch 6 Inthe VLANS type 8 to VLAN ID In the Member field choose pl p2 p3 and p4 Then choose the Tagged for Frame Tag Operation in pl p2 p3 and p4 We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from some users Advanced LAN VLAN Setting Disable Port Base VLAN 9 802 13 VLAN Part Base S210 VLA VLAN 802 1Q VLAN Group Index Active Name VLAN ID Member Frame Tag Operation P1 wwe 6 e P4 P1 P2 P3 P4
132. k 1 LAN 10 1 1 50 182 158 1 100 124 Microsoft Internet Explorer 9 EE ec J 4re you sure of deleting this item L ox J cancel jJ 1 Edit Delete Delete All Click OK to delete the entry in static route table Users can click Delete All to remove all entries in static route table 3 3 2 NAT Setup NAT Network Address Translation is a method of mapping one or more IP addresses and or service ports into different specified services It allows the internal IP addresses of many computers on a LAN to be translated to one public address to save costs and resources of multiple public IP addresses It also plays a security role by obscuring the true IP addresses of important machines from potential hackers on the Internet The Vigor 3300 Series is NAT enabled by default and gets one globally routable IP addresses from the ISP by Static PPPoE or DHCP mechanism The Vigor3300 Series assigns private network IP addresses according to RFC 1918 protocol and translates the private network addresses to a globally routable IP address so that local hosts can communicate with the router and access the Internet In the Advanced group click the NAT option Dr ay Te k 62 Vigor3300 Series User s Guide E MAT H Port Redirection Address Mapping m DMZ Host e Common Ports List Pal he Lil There are four functions that NAT provides Port Redirection Address Mapping DMZ Host and Common Ports List Port Redirection
133. l The duration of the call The reason for the call termination The IP address of remote voice site The used port number of remote voice site The statistic of RTP with abbreviation will be shown in this field e g PS Packets Sent OS Octets Sent PR Packets Received OR Octets Received PL Packets Lost JI Interarrival Jitter Estimate ms LA Average TX Delay ms The Codec mode used for this phone calling The period of time for sampling on voice signal The status of VAD The status of DTMF This page allows you to upload tone settings such as G 711a Ping Prompt G 711a Pin Error G 729 Pin Prompt and G 729 Pin Error to Vigor3300 series Click Browse to choose the file and click Apply to upload it Vigor3300 Series User s Guide 143 Dray Tek VolP G 711 Tone Upload G 711a Pin Prompt Apply Cancel VolP G 711 Tone Upload G 711a Pin Error Browse Apply Cancel VolP G 729 Tone Upload G 729 Pin Prompt Browse Apply Cancel VoIP G 729 Tone Upload G 729 Pin Erro Apply Cancel When a user wants to dial out via FXO port a sound would be played to ask the user typing PIN code first If the PIN code is correct the user can dial out If not prompt sound of PIN Error would be played 3 7 12 Status This page displays the connection status for VoIP phone calls Refresh Option Dray Tek VoIP Status Refresh Option No Refresh v
134. l Area f Bridge Connections Create Shortcut Rename Properties 3 On the following dialog click Properties 4 Local Area Connection Status General Support Connection Status Connected D uration 00 10 52 Speed 100 0 Mbps Activity Received ey Packets 4 Click Configure to access into next screen Local Area Connection Properties i General Authentication Advanced Connect using Eg Intel H PR01100 5 Desktop Adapter This connection uses the Following items tClient for Microsoft Networks File and Printer Sharing tor Microsoft Networks QoS Packet Scheduler Intermet Protocol T CP IP Description Allows your computer to access resources on a Microsoft network Show icon in notification area when connected Notify me when this connection has limited or na conmectryity Vigor3300 Series User s Guide 159 Dray Tek 5 On this dialog box locate VLANS tag and click on it If you cannot find out VLANs tag that means your network card does not support VLAN feature Intel R PRO 100 S Desktop Adapter Properties EE Boot Agent Driver Resources Power Management General Link Advanced Teaming VLANs HH Intel R PR07100 5 Desktop Adapter Device type Network adapters Manufacturer Intel Location FCI Slot 2 PC bus 2 device 10 function U Device status This device is working properly IF you are having problems with this device click Troubleshoot to sta
135. l guide you to import a saved file to a place that you want VPN IPSec User Certificate 1 Import Import User Certificate Apply Cancel To delete a user certificate please click the index number that you want to delete and click the delete button A dialog box will appear to ask your confirmation Click OK to delete it or click Cancel to leave the dialog without deletion Microsoft Internet Explorer v Are you sure of deleting this User Certificate Item To view a user certificate please click the index number that you want to view the detailed information of the certificate and click the View button The following page will be shown for your reference VPN IPSec User Certificate 1 View Certificate Detail Information Certificate Name 3300CA 0804 Issuer iC TWWST Hsin ChwL Houko O DrayteWOU RD3 CN presto emailAddress pcho draytek com tw Subject iC TWiST HouKkol L Hsin Chu O RD3 0U DrayteWCN 3300CA_0804 emailAddress pcho draytek com Valid From Aug 4 11 57 40 2005 GMT Valid To Aug 4 11 57 40 2007 GMT Back Status This page will show the VPN connection status Vigor3300 Series User s Guide 119 Dr ay Te k VPN IPSec Status 8 Name Status Algorithm Remote IP Remote Subnet Packet pytein Packet Byte Uptime 1 2900v up DES_O HMAC_SHAI NO_PFS 61 230 211 232 192 168 29 0 24 13 16 12 BM 29 Refresh Disconnect Name Display the name of the IPSec tunnel Status Display the status of the tunnel
136. lay Name To facilitate ease differentiation please type 3300V Port1 IP SIP URL Cal lee s Number IP please type 888833 220 135 240 207 Index Mo 1 F Enable Phone Number 3 301 Display Name 3 300v Porti IP SIP URL E 88833 in 220 1 35 240 207 OK Dr ay Te k 192 Vigor3300 Series User s Guide 4 Confirm the settings are correct and then finish the configuration fot gt Advanced Setup gt VoIP Setup gt DialPlan Setup DialPlan Configuration Display Name SIP URL 3300V Parti IP 9983312220 135 240 207 Index Phone number i 30 ES o Y X 7 x X Start to dial by using telephones Phone 1 calls Phone 2 gt Press 2901 or 888829 61 31 167 1351f Phone 2 calls Phone 1 gt Press 33014 Note indicates termination of the phone number After pressing VoIP is immediately called out Or you may wait 3 seconds if you do not press With 2900V you can t only dial alphanumeric addresses or 9 symbols To dial an IP address start and end it with a hash replace the dots with star In this example you have to press 4220 135 240 207 t But 3300V can only receive the format of Number P So it is required to setup 3300V s number 888833 220 135 240 207 in the DialPlan entry Vigor3300 Series User s Guide 193 Dr ay Te k Intercommunication with one SIP Proxy Server registration Connect telephones into 3300V s Por
137. lephony offers features and services that are unavailable with a traditional phone at no additional cost Because Internet Telephony requires strictly minimal packet delay and jitter since voice quality is intolerant of packet loss the Vigor3300V integrates VoIP feature with QoS and packet loss concealment mechanisms to Vigor3300 Series User s Guide 1 Dr ay Te k effectively transport high priority voice traffic over IP with low latency Another feature is T 38 fax relay By enabling and configuring fax rate on a dial peer the originating and the terminating V3300V can enter fax relay transfer mode By using the T 38 function customers can also save on fax expenses Lastly by enabling the load balance feature on multiple WAN ports lease lines can be replaced to provide a cost effective method for network infrastructure 1 1 LED Indicators and Connection The Vigor3300V has 4 WAN interfaces and Vigor3300 3300B has 3 WAN interfaces that support load balancing This allows the system to reach peak performance and reduces the cost of maintaining a single high speed trunk by sharing the load amongst the multiple WAN interfaces Each interface can be connected to an individual Internet Service Provider The Vigor3300 Series also supports a backup function for WAN interfaces a user can select one WAN interface to be a backup interface If the master interface fails the backup interface will take the place of the master interface immediately La
138. ling the data filter function and choosing proper filter group Firewall General Setup Data Filter Disable 9 Enable Start Filter Group Apply Cancel Data Filter Disable or Enable the firewall function This firewall can only be enabled if at least one filter group exists The default is Disable Start Filter Group Default group names provided here are Pass and Block Select the first filter group to begin filtering mechanism The group in Vigor3300 Series User s Guide 83 Dr ay Te k Group Table this list must exist and had been pre configured The system provides three types of filter for you to choose in default The available settings provided here can be added or edited in Firewall gt gt IP Filter gt gt Group Table Group Table allows you to set definitions for different groups of the filters that will be applied for the function of IP filter Firewall IP Filter Group Table Index 1 2 Index Group Name Next Group Comment Add Edit Delete IP Filter Group Table Group Name Next Group Comment Block Group for pass rules ack none Group for block rules Add Edit Delete Allow you to change current IP filter table or add new rule for current group Click the number link to get into the IP filter table page for editing Display the group name Display next group name Display the notice for current group Allow you to add a new IP filter table Allow you to e
139. ll explain in more detail the various broadband access configurations All the settings in this section will be used in the first WANI interface Vigor3300 Series User s Guide 13 Dr ay Te k Quick Setup WAN MAC Address Default MAC User Defined MAC Downstream Rate 102400 kbps Upstream Rate 102400 kbps Type Fast Ethernet w Physical Mode uto Negotiation v IP Mode OStatic SO DHCP OPPPoE O PPTP Static DHCP BBEBEIJSETE Configuration Configuration IP Address Host Name Subnet Mask Domain Name Default Gateway Hast Name and Domain Name are required far some ISPs Primary DNS Secondary DNS IP Alias List i Next gt gt Now you have to select an appropriate WAN connection type for connecting to the Internet through this router according to the settings that your ISP provided MAC Address Downstream Rate Upstream Rate Type Physical Mode Dray Tek Default MAC Use the default Mac address stored originally in router User Defined MAC Use a MAC address defined by the user Assign the downstream rate for this WAN interface The default value is 102400 kbps 100 Megabit This setting is very important for Vigor3300 Series incoming buffer adjustment If you use a DSL subscriber service with a 2Mbps downstream please set the downstream rate setting with 2Mbps Assign the
140. m Untagged v 4 Enable management port for P4 Port Setting P1 P2 P3 P4 Port VLAN ID 5 6 7 Apply Reset Cancel Active Check this box to activate the settings of this entry If you check the Management Port box below Index 4 will be unchangeable and locked And you have to set Port VLAN ID for P4 previously before you check Management Port Name Specify the name for the four groups of VLAN VLAN ID Type a number used for identification on VLAN for your computer Later you have to type the same ID number for each PC which wants to be grouped within the same VLAN group In addition if you type wrong ID number the following message will appear to warn you Please type correct number Microsoft Internet Explorer By the way if you don t know how to configure a VLAN setting on your computer please refer to How to Check Edit VLAN ID on Your PC below for more detailed information Member To make the hosts with the same VLAN ID of different ports communicating with each other please check the port box P1 to P4 according to your necessity Frame Tag Operation Basically the default settings for tagged or untagged VLAN will be shown automatically when you type VLAN ID Name and check the Active box By the way you can modify the tag Dr ay Te k 78 Vigor3300 Series User s Guide operation for each VLAN in this page for obtaining proper control Use the drop down list to choose a tag operation for each port Tagged AII the computers
141. mal conditions The router will send Syslog packets to a Syslog server on the remote site The administrator can observe any abnormal events from Vigor3300 In the System group click the Syslog option The Syslog web page is shown below System Syslog O Disable 9 Enable Syslog Server IP 0 0 0 0 Syslog Server Port 51 4 User Access Log F Apply Cancel Disable Enable Click Enable to activate this function The router will send system log message for your reference If you click Disable the router will not send out any message about system log Syslog Server IP The IP address of the Syslog server If a user assigns an IP address of 0 0 0 0 the Syslog function will be disabled Then Vigor3300 will not send Syslog packets to the Syslog server Syslog Server Port Assign a port for the Syslog protocol User Access Log Check this box to record the user access log Such information will be seen in syslog server Apply Click Apply to save these settings Dr ay Te k 28 Vigor3300 Series User s Guide 3 1 4 Access Control This page allows you to determine which services HTTP Telnet SSH is used for the user to access Vigor3300 Series In addition you can also limit some hosts to access Vigor3300 Series with specified IP address In the System group click the Access Control option You will get the following page System Access Control Management Method Allow Management Methad v Telnet 88H Man
142. may wait 3 seconds if you do not press This example is the intercommunication with one SIP Proxy Server For the applications of Direct IP Call and Intercommunication with different SIP Proxy Servers please refer to VoIP Example 2 Basic Calling Method The VoIP call can also wok with VPN please refer to VoIP Example 3 VoIP over VPN Also you can set up the Speed Dial entry To accommodate the extension please set up 888829 to 291 888833 to 331 You may refer to the figures shown below and VoIP Example 2 Basic Calling Method VolP Speed Dial Spd Opal Phat Mumle Spec Dial Deestinaliiesgi zy sta Se wa sm 122456 Apply Came Che This Pay Index No 1 IV Enable Phone Number 331 Display Name 300v Pot SIP URL 888833 liptelorg OK Dr ay Te k 204 Vigor3300 Series User s Guide 5 2 10 Example 5 Practical Application of FXO Based on the VoIP Example 1 Basic Configuration and Registration we will introduce the practical application of FXO Generally the practical application of FXO falls into the following two sections Connect to PSTN line By connecting 3300V s FXO Port 5 to a PSTN line VoIP is seamlessly integrated to PSTN line and allows you to call not only the remote VoIP user but also the remote PSTN user Also the PSTN user can call the VoIP user Below shows a scenario architecture graph Internet Phone 3 8 654 37 1 12345678 Ports FXO SSS835 V
143. mber after the time you set in this field to finish that call For example the phone number is 03654321 and the dialing completion timeout is set to 4 secs The user dials with 036 and stops to dial After passing through 4 seconds the router will send out that phone call automatically VoIP ToS The ToS value in VoIP protocol packet The default setting is 0xa0 Line Polarity Reversal as Callee Answer Check this box to generate line polarity reversal while the remote user picks up the phone call as Callee on hook Check this box to generate line polarity reversal while the remote user hangs up the phone call FXO auto disconnection if Determine the time length for the FXO disconnecting no packet is received in X automatically when there is no packet received minutes FXS On hook Tip Ring Determine the voltage of FXS port on hook Choose Low to Voltage save the power Vigor3300 Series User s Guide 135 Dr ay Te k Ringing Frequency Please select a proper setting as the ringing frequency Ringing Cadence On Determine the length of the ringing time for incoming calls Ringing Cadence Off Determine the length for the incoming calls to stop ringing 3 7 6 Tone Settings This setting is provided for fitting the telecommunication custom for the local area of the router installed Wrong tone settings might cause inconvenience for users To set the sound pattern of the phone set simply choose a proper region to let the system
144. ments with codec rate 20ms is higher than 40ms Yet the bandwidth request for 40ms is less than 20ms DTMF Mode InBand Choose this one then the Vigor will send the DTMF tone as audio directly when you press the keypad on the phone OutBand RFC2833 Choose this one then the Vigor will capture the keypad number you pressed and transform it to digital form then send to the other side the receiver will generate the tone according to the digital form it receive This function is very useful when the network traffic congestion occurs and it still can remain the accuracy of DTMF tone SIP INFO Choose this one then the Vigor will capture the DTMF tone and transfer it into SIP form Then it will be sent to the remote end with SIP message DTMF Volume Determine the volume of DTMF voice signal The more the number 1s set the greater the sound is Disable Disable forwarding function Call forwarding all calls Forward all incoming calls to the specified SIP URL site Call forwarding busy Forward incoming calls to the specified SIP URL site when this line 1s busy Call forwarding no answer after Range 1 10 rings Forward incoming calls to the specified SIP URL site after 131 Dray Tek ringing the times that you set here SIP URL Assign a SIP URL site to receive forwarded calls Call Waiting Click Enable to invoke this function A notice sound will appear to tell the user new phone call is waiting for your response Cli
145. munication will be failed Codec Rate Type the rate value to be applied on this port Codec VAD Enable or Disable VAD Voice Activity Detection It can detect whether the voice activity is progressing or not If not RTP packets transmission will be stopped for saving more bandwidth Microphone Gain The gain value while transmitting voice The default value is 0 The range is from 32 to 31 Speaker Gain The gain value while receiving voice The default value is 0 The range is from 32 to 31 130 Vigor3300 Series User s Guide FAX DTMF Call Forwarding Vigor3300 Series User s Guide FAX Mode The FAX function mode There are several options Transparent FAX will be transmitted via voice channel no fax relay and no Codec change will be involved T 38 Relay Using T 38 Fax Relay This is the default value Bypass Once FAX is detected the Codec will automatically switch to a high bit rate type G 711a u or G 726 to make sure FAX can transmit successfully If this option is selected the Vigor3300 will apply these two following settings FAX Bypass Codec and FAX Bypass Codec Rate FAX Bypass Codec Select one option to be applied if FAX mode is configured as Bypass mode G lIIULPCHU 54kbps G 11U PCHU 54dkbpz 5 11A PCHA 54kbps FAX Bypass Codec Rate Select one option 20 or 40 to be applied if FAX mode is configured as Bypass mode The stability for the faxing result of docu
146. n General Setup Limit Session 9 Disable Enable Default Session Limit 4000 g Enable Disable Default Session Limit Apply Limitation Table Apply _ Cancel Disables or enables this function Defines the default session number used for each computer in LAN After finishing the configuration please click this button to invoke these settings This function allows users to set limitation for limit session In the Network group choose Limit Session and then Limitation Table You will get the following page Network Limit Session Limitation Table E Start IP S SS coucou Start IP End IP Session Number Edit Delete Delete All Vigor3300 Series User s Guide End IP Session Mumber 1 Edit Delete Delete All Display the start IP address Display the end IP address Display the session number Click this button to open the edit page for adjusting the settings Click this button to delete the selected setting or all settings A confirmation dialog box will appear Click OK to delete this 59 Dray Tek entry from the Load Balance Policy table In addition click Delete All in the Load Balance Policy page to delete all of 10 entries on this page To edit an entry select it by clicking the radio button from 1 to 10 Then click the Edit button on the bottom to bring up the following Web page Network Limit Session Limitation Table Edit session Number Apply Cancel Star
147. n entry number to get into edit mode Advanced DDNS Setting Status Ob Disable 9 Enable Interface VANI w Server Provider dyndns org www dyndns org k Server Type dynamic Domain Name abc dyndns org Login Name draytek Login Password IITIIIT Wild Card 9 Disable O Enable Backup MX 9 Disable O Enable Mail Extender dray draytek com Apply Cancel Status Click Disable to disable this function Click Enable to activate this function Interface Select a specific interface for registering on DDNS server The Interface should be any WAN port on V3300 series Server Provider Assign a provider name to support DDNS server The Vigor3300 supports 7 domain server providers as default Vigor3300 Series User s Guide 71 Dr ay Te k Server Type Domain Name Login Name Login Password Wild Card Backup MX Mail Extender dyndns org www dyndns org v dyndns org vwy dyndns orq no ip com www no ip com j DtDNS www dtdnz com ChangeIP com www changeinp com dyvnamic namezerver www dyvnamic namezserver com huagai net www ddnz cn www 3322 0rg Select Static Dynamic or Custom type for this entry of DDNS settings Assign a private domain name to be accessed Assign a name to login into DDNS server Assign a password to login into DDNS server If you want anything here yourhost dyndns org to work EX To make things like www your
148. n id MC k X i Ormiguratian Pro lpelog Proxy SIP Local Port SED Outbound Proxy Outbound Pros Chilli P oy Active Prey ux Proxy Mldress Posts Setting nil el iptel orng iss NE Peqister via WAN Register via S E AT nsplay Narre 2800 Post ip Display Name Li Account Name 3863029 Account Mame Example piel nigl arg Bssrinrir zin d apanon Adhom akin Configuration Example for Vigor3300V Enter VoIP Speed Dial page configure relevant settings for 2900V s Port Speed Dial Phone Number type 2901 Speed Dial Destination Cal lee s Number 9 IP type 888829 61 31 167 135 Memo To facilitate ease differentiation please type 2900V Port IP Click Apply to save the settings and finish the configuration VoIP Speed Dial Syed Dal Pee Kaba Sere Dia Das tiv om el ST se Ther 135 Apply Cancel Chan This Page Vigor3300 Series User s Guide 191 D r ay Te k Configuration Example for Vigor2900V 1 Click DialPlan Setup in the VoIP Setup page DialPlan Setup Voice Call Status 2 Click Index 1 gt Advanced Setup gt VolP Setup gt DialPlan Setup DialP lan Configuration e ln dex Phene number Display Name Status EHE L4 S S K X K EIL W K 3 Enter relevant settings for 3300V s Port 1 Click OK to save the settings Enable click N to activate the entry Phone Number type 3301 Disp
149. nation IP Display the destination IP of the static route Gateway IP Display the gateway address of the static route Mask Display the subnet mask of this route Edit Allow users to edit the selected static route settings Delete Delete All Removes one or all the selected static route settings The system allows users to set up to 10 static routes for the router Edit the Static Route To edit static route for certain item select the radio button of the item and click Edit on the bottom of the page The following web page will be displayed Advanced Static Route Edit Network Interface Destination IP Do subnet Mask Apply Cancel Vigor3300 Series User s Guide 61 Dr ay Te k Network Interface Select a network interface as a destination to be sent It includes LAN and WANI WANA Gateway IP Assign an IP address of the gateway for the interface selected above Destination IP Assign the IP address of the destination that data will be transferred to Packets ready to destination will be sent out through the network interface chosen in this page Subnet Mask Assign a value of subnet mask for destination IP address Click Apply to reboot the system and apply the settings Delete the Static Route Select the radio button of the item that you want to delete and click Delete on the bottom of the page The following web page will be displayed Advanced Static Route Network Interface Destination IP Gateway IP Mas
150. ndary DNS Allow you to choose an authentication mode to be used The default setting is CHAP PPTP Authentication PAP PAP CHAP HS UCHAP HS CHAP Vz Allow you to choose an encryption mode to be used If PPTP authentication mode is set to CHAP or PAP PPTP Encryption mode does not need to be set FFTFP Authentication HS5 UCHAP d PPTP Encryption Ho Encrvption MPPE 40 bits MPPE 40 bits 128 bits Set user authentication to Local server or RADIUS server Enables or disables the Mutual Authentication function Type the user name that the other side provides for carrying out mutual authentication whenever you want Type the password that the other side provides for carrying out mutual authentication whenever you want Use DNS setting of LAN configuration If you click this radio button please type the primary DNS and secondary DNS IP address manually in the following fields Type the IP address for primary DNS Type the IP address for secondary DNS When you finish the configuration please click Apply to invoke it L2TP General Setup To configure the general setup please click VPN gt gt PPTP amp L2TP gt gt General Setup gt gt L2TP General Setup Vigor3300 Series User s Guide 121 Dray Tek VPN L2TP General Setup Status 9 Active Inactive L2TP Authentication CHAP v User Authentication 9 Local O RADIUS Server Mutual Authentication Enable 9 Disable
151. ndicators and Connectors for Vigor3300 sseseeeessseeseeeeennnnennnn 4 1 1 3 LED Indicators and Connectors for Vigor3300B seeeeeeeessseeeeeeeernnneennnnnnn 6 1 2 Hardware Installation lleeeeessesesesesssessseseeeeeene nennen nnne nennen nnne 8 1 2 1 Detailed Explanation for the Connector eeeeeeeeesssssseeeeseeeeeeeenne nnne 9 Configuring Basic Settings assieme ini cedus dr inque cuiE dE sR Ucet UE cratered eu uvas ad veta udo nut lods 11 2 1 Changing P ASSW Ol RR UU 11 EAB o ao gt U o A NORTE 13 PPS A IOC a E E aseouesdecsas 15 2e e DAOP MOOG ea E E A E d E MN 17 PO Id rl dO T ee a DL 19 DARIN MU 21 Advanced Configuration 11 eccle Leee eei eeee sese rese enean nn nnn nnne 23 SN elc WUO A 23 ON ESCUUIMC D T eae 23 SNNT c eaysuaens 27 eM OS OG E A EEN E E E N E E E E E TE 28 3 1 4 ier R9 opio MI m 29 9 1 9 Colligurdlloni Sell D scs cu odedexescua sicose ce tesut o ini cuu Eo la tasa ce bus ut stad eame tebg cue aeo o Rene ebd eiue 30 3 1 6 Firmware Upgrade Setup cccccccccccccccssssseeceeeeeeceeeeeseceeeeseeeesseeeeeeesseueaseeeeeeeeessaaaeeeeees 31 Bole WACO NT LU c 34 Su WIA MOSIG WOOIS CC
152. network However VLANs are not limited by the hardware constraints that physically connect traditional LAN segments to a network As a result VLANs allow the network manager to segment the network with a logical hierarchical structure VLANs can define a network by application or department For instance in the enterprise a company might create one VLAN for multimedia users and another for e mail users or a company might have one VLAN for its Engineering Department another for its Marketing Department and another for its guest who can only use Internet not Intranet VLANs can also be set up according to the organization structure within a company For example the company president might have his own VLAN his executive staff might have a different VLAN and the remaining employees might have yet a different VLAN VLANs can also set up according to different company in the same building to save the money and reduce the device establishment This router supports Virtual LAN only in LAN site User can select some ports to add into a VLAN group In one VLAN group the port number can be single one or more The purpose of VLAN is to isolate traffic between different users and it can provide better security application Dr ay Te k 76 Vigor3300 Series User s Guide For Port Base VLAN In the Advanced group click the LAN VLAN option There are two VLAN settings offered here for you to configure If you click Disable no configuration can b
153. ng spaces Dr ay Te k 104 Vigor3300 Series User s Guide Security Protocol NAT Traversal WAN Interface Local Certificate Security Gateway Network IP Subnet Mask Next Hop Remote ID DHCP over IPSEC Security Gateway Network IP Subnet Mask AH Specify the IPSec protocol for the Authentication Header protocol The data will be authenticated but not be encrypted ESP Specify the IPSec protocol for the Encapsulating Security Payload protocol The data will be encrypted and authenticated Security Protocol ESP Click Enable to let multi IPSec tunnels passing through this router Click Disable to close this function Enable M MAT Traversal Enable The WAN interface to be used WAN Interface The local certificate is active for authentication if the RSA Signature option is selected in the Authentication field These options come from the user certificate file The IP address of the local gateway s public network interface The keyword default can be used to represent the IP Address of the selected WAN Interface The subnet behind the local gateway The IP address of the next hop The keyword default can be used to represent the gateway IP address of the selected WAN Interface The identification number for the remote gateway Turns this function ON or OFF The IP address of the remote client gateway This field is mandatory The setting for 0 0 0 0 is used for t
154. nge for this entry Dest Port End Display the end point specified in the Dest Port Range for this Vigor3300 Series User s Guide entry 47 Dr ay Tek Network Interface Display the interface specified for this entry Strict Bind Display the status of Strict Bind Edit Click this button to open the edit page for adjusting the settings Delete Delete All Click this button to delete the selected setting or all settings A confirmation dialog box will appear Click OK to delete this entry from the Load Balance Policy table In addition click Delete All in the Load Balance Policy page to delete all of 10 entries on this page To edit an entry select it by clicking the radio button from 1 to 10 Then click the Edit button on the bottom to bring up the following Web page Network Load Balance Policy Edit Protocol ALL v Source IP Subnet Mask J Dest IP Subnet Mask j Dest Port Range Network Interface WAN1 w Strict Bind F Apply Cancel Protocol Select the desired protocol for the selected entry Source IP Subnet Mask Assign a source IP address and subnet of certain host in LAN for applying load balance policy Dest IP Subnet Mask Assign a destination IP address and subnet of certain host in LAN for applying load balance policy Dest Port Range Assign a destination port number range The port range is from to 65535 If you choose All as the protocol you don t need to
155. nload and will display the following message OE Ee ee ee ee RE RE E E E E RE R E K K k k DrayTek V3300 Bootloader sse fefe fede dete tete pese ae ae tete fe tete ae ae ae ae ae ake kkk Press ENTER key within 5 sec to download image 2 Current LAN IP is 192 168 1 1 New IP Prepare downloading Type the path name of the firmware image and activate the TFTP Client from the PC to download the image The corresponding message is shown as follows TFTP i 192 168 1 1 PUT Vigor3300 image file name 32 Vigor3300 Series User s Guide z Comman Volume in drive C Ualume Serial Aunber Directory of GI ASA zm Ho EAD s H2 717272885 B21 2b 0271772005 0371572085 M6 14 7 005 tS tl tp d Prompt REN E HS 36 Bi 46 Bi 46 42 40 DEEP Hi 1H 48 B32 HS Ay 9 42 A Filetce 5 Diris DIA is PQA PCI XP_5G is 1882 8746 D 2A Aas 4 755 637 6 l DIRS lt DIR gt 399 a 4 959 905 lt DIR gt lt DIR gt Salt all AUTOEXEG BAaT GOMFIG 2V5 Documents and Settings Inet pub Packet lesterResult txt Program Filer U3K32255_en all vine mS UT NDBOUS 15 4 7 di7 hytac 22188 512 576 bytes free i U92 16H 1 1 put ctswikdedsob_en all 6 Now in the Console you will find the following information When Updating flash block at b amp X XX XXX appears it means the firmware is under downloading e 3300 HyperTerminal File Edk ew Cal Taer Help
156. nnection will be displayed in this page Simply click LAN Status tag to get the detailed System Status Refresh Option No Refresh Refresh Basic Status BUTTON WAN Status LAN1 IP Address 192 168 1 3 MAC Address 00 00 00 00 00 01 High Availability Status RX Packets 9902 TX Packets 1072 IP Address MAC Address High Availability Status RX Packets TX Packets Vigor3300 Series User s Guide Display the IP address of the LAN interface Display the MAC address of the LAN Interface The High Availability Status is shown when it 1s enabled in Network High Availability When there are two Vigor3300 devices in the same LAN one can be set as Master device and the other can be set as Slave device Master It means that Vigor3300 plays the Master role in high availability feature Slave It means that Vigor3300 plays the Slave role in high availability feature If there is only one Vigor3300 used in LAN this line will be blank Display the total number of received packets at the LAN interface Display the total transmitted packets at the LAN interface 25 Dray Tek WAN Status The status of WAN interface Static DHCP PPPoE PPTP or DMZ is shown in this page simply click WAN Status tag to get the detailed There are four sets of WAN status can be shown in this page at one time The sample below just lists one set of WAN status for only WANI interface is used System Sta
157. nother application is that you can call back to the Headquarters from outside and communicate with the branch via the Internet For detailed configuration please refer to Practical Application of FXO PRX Outside Lines E PBX Inside Lines elenhene lelephone FAX Machine Taiwan China Telephone FAX Machine Vigor3300 Series User s Guide 177 Dr ay Te k 5 2 4 VoIP Basic Protocol Select the communication protocol SIP or MGCP and the IP Address WAN or LAN VPN used by VoIP You need to configure relative settings at first Please refer to the figure below as an example of Vigor 3300V Quick Setup System VolP Protocol Netaork Advanced Firewall Salari Protocol Sor NGCP NL P Ccontigur ati 060 a Active peony aoe Prsoy Address o r1 oO Frirple ple piel ong Port Settings VPN Proxy Fori 4 one ed peed Coal sy Mtceterecue E Tore Ealing x ues lt MAT Trapar 77 meonsng Cal Bening de Ca Heaters Fede cimus piel any 3 49 19 F M E xp es isse Dona ial Org Apply Conca This page displays the basic settings for each port Click the Edit icon in the Phone Number page to enter the Edit page Then you can configure this port Quick Setup System VolP Port Settings Phone Number Group E id E Ed ES Ee Dd ER 3 Dray Tek Network Advance d Firewall Actie Gar oup 178 VPH Ve olas 4 08 SEP
158. obiuagsianduhddbextunntaeaetddese 140 TO O FESTO NE TET 142 SN Nee ocio RR UU m 143 OWENS 144 diia 147 4 1 Checking If the Hardware Status Is OK or Not cccccccecsssssseeeeeeeeeeeeeseeeeeeeeeeeeseeeeeeeeseaas 147 4 2 Checking If the Network Connection Settings on Your Computer Is OK or Not 148 4 3 Pinging the Router from Your Computer sssesesessesssseseeene nennen nnne 151 4 4 Checking If the ISP Settings Are OK or NOt 0 00 cccceeeeeeeeeeeeeeeeeeeaaaaeeeeeeeeeeeeeeeeeeeeeeaaaaaes 152 4 5 Backing to Factory Default Setting If Necessary seeeeeseeeeeeeeee 155 4 6 Contacting Your Dealer sssssesssessssssseeeee nennen nennen nhan nennen sns n nar n nnns nnns 156 Application Notes mme 157 9 1 ADDNCAON tor 8021 VLAN iasssscsenveknasesEruae eter udasy ne eua VR Tan a ERR Eaa kb veau wat Ee rdi 157 5 1 1 Block LAN to LAN Communication sseeeeeeeesseeeeeeenn nennen nennen nnns 157 5 1 2 How to Check Edit VLAN ID on Your PC seeessssssseeeeeeenennnn nnne 158 5 1 3 Four VLANs for Different Departments in A Company sees 164 5 1 4 Two VLANs for Different Departments in A Company eeeeeseeeeeereeneeen 166 Vigor3300 Series User s Guide V Dr ay Te k 5 1 5 Example for the Companies in the Same Building eese 168 5 1 6 E
159. obtained from the selected a SCIVCT Forbidden Categories List The forbidden categories are obtained from the selected a server URL The URL domain name Option Allow or Deny the selected URL Exception URL List The list of filtered URLs Dr ay Te k 92 Vigor3300 Series User s Guide Restrict Web Feature This feature blocks malicious codes hidden in Web pages such as Java Applet Active X Cookies Proxy compressed files and executable files It is also able to block all downloads of multimedia files from Web pages in order to control the bandwidth usage Malicious code may be embedded in some executable objects such as ActiveX Java Applet compressed files executable files Proxy and Multimedia For example an ActiveX object with malicious code may gain unlimited access to the system Firewall URL Filter ObDisable Enable Restrict Web i ae Content Filter Filter Schedule URL Access Control Java Cl Activex Ccom pressed Files Cookies C Execution Files CIP roxy C Multimedia Files Apply Cancel Java Activates the Block Java object function The router will discard Java objects from the Internet ActiveX Activates the Block ActiveX object function The router will discard ActiveX object from the Internet Compressed Files Activates the Block Compressed file function to prevent from downloading of any compressed file These following types of compressed files are blocked
160. od Speed Dial Entries Allow List ends are accepted by this router Allow only calls from allow list Only the calls listed in the Allow List page will be accepted by this router Allow only calls from speed dial entries Only the calls listed in the speed dial entries will be accepted by this router Deny only calls from deny list The calls listed on Deny List page will not be accepted by this router And others calls are accepted Deny all incoming calls All incoming calls from remote ends are not accepted by this router Name Enable or Disable this function to take value of Speed Dial Phone Number to be checked IP Domain Enable or Disable this function to take the value of Speed Dial Destination to be checked Type the range to be checked The default value is from 1 to 150 The Vigor3300 Series supports up to 30 entries in the Allow List table When you choose Allow only calls from allow list as the Barring Class only the people listed in this list can call this router VoIP Incoming Call Barring Allow List Name 1 Torn John Example John Name IP Domain Deny List IP Domain 192 158 1 5 iptel org 192 158 1 1 or iptel org 123456 Apply Cancel The name or number in the allow list The IP address or domain name to be allowed If the peer is registered in SIP proxy server use the domain name of the SIP proxy server Otherwise use the static IP ad
161. oedp1l za4 dez mdb5 moedpib538 dez zha modp 68 dez zha modpiu 4 dez zha modpilb53 amp 3dez mdb5 modp amp 58 3dez mdb5 moedp1il z4 3dez mdb5 modpib385 3Jdez zha modp amp 58 3dez zha modp1ll z4 jdez zha modplib536 aezlz8 mdb modp 858 aezlz8 mdb modpmpi 4 aezlz8 mdb modpib53 amp aezl28 zsha modp amp 58 aezlz8 zha modpli 4 aezlzB8 zha modpib53 amp Key Lifetime quick The rekey renegotiated period of the IKE Phase2 keying Proposal quick channel The acceptable range is from 5 to 1440 minutes 24 hours The proposed encryption and or authentication algorithms for IKE Phase2 negotiations There are 2 options 106 Vigor3300 Series User s Guide Encryption algorithms NULL DES 3DES AES Authentication algorithms MD5 SHA1 Accepted Proposal If you choose Only accept proposal listed above only the selected proposal will be accepted and applied by this device If you choose Accept all supported proposal all the proposals supported by this device will be accepted and applied Accepted Proposal Accept all supported proposal hal Only accept propozal lizted above Accep 15 tll ll Suppor ted proposal PFS Enables the PFS Perfect Forward Secrecy function A new Diffie Hellman Key Exchange is included every time an encryption and or authentication key are computed on PFS Status Enables or Disables the dead peer detection function Delay The keep alive timer A Hello message will be emitted perio
162. ofile Enable Choose this one to activate this profile Disable Choose this one to inactivate this profile Type a name for this group LAN subnet of this device LAN subnet of remote client Specify which tunnel will be included in this trunk You can choose up to four tunnels at one time Determine how many flow rates can pass through on this tunnel For example type 1 for tunnel 1 and type 4 for tunnel 2 If such device has 5 packets needing to send to the remote subnet it will send 4 packets through tunnel 2 and 1 packet through tunnel 1 Check this box to enable VPN tunnel backup Choose the master and salve roles for this backup configuration After finish the configuration click Apply to apply the group table setting Log At any time you can click VPN gt gt IPSec gt gt Log to monitor the VPN tunnel status The log is helpful for solving some setting problems The system will keep the 100 most recent messages Click Clear to clear the log Vigor3300 Series User s Guide 115 Dray Tek VPN IPSec Log z Date Time Description 1 04 37 06 12 08 connection 11 Research is deleted 2 4 35 47 12 08 connection 11 Research is added Date Time It displays the date and time for the operation of IPSec Description It displays the results of the IPSec operation Refresh It allows you to refresh the whole table Clear It allows you to clear all the table information Trust CA This page allows you to set
163. on of EXS Generally the practical application of FXS falls into the following two sections Connect the telephones Please refer to VoIP Example 1 Two VoIP equipments call with each other Connect PBX s Outside Lines The usage is the same as that of PSTN line Different PBX has its own settings and required configuration by you Below shows a scenario architecture graph Intemet Line Line 2 Port FAS AERR11 i e E O 2900W Port FAS SRRR2O larwan China Shanghai Mune I Phong 7 Configuration table between 3300V and 2900V wani Pon Number Phone Number Proxy Code _ Suppose there are two PSTN lines connected to PBX s Outside Lines The third Outside Line is connected to 3300V s FXS Port1 The Inside Line is connected to a telephone with the extension 101 If the extension wants to dial VoIP using Line 3 you must firstly press 3 and then dial the phone number Vigor3300 Series User s Guide 203 Dr ay Te k Example of lines connections ee Pax Phone Number Line3 3 888833 101 Start to dial by using telephones Phone calls Phone 2 gt Press 3 after hearing the dial tone press VoIP number 888829 Phone 2 calls Phone 1 gt Press 888833 after getting through you will hear the auto reply from the PBX Then press the extension 101 Note indicates termination of the phone number After pressing VoIP is immediately called out Or you
164. p 9 MGCP le MGCP SIP Configuration Configuration MGCP Local Port 2 427 MGCP Call Agent Address 192 168 100 100 MGCP Call Agent Port 2727 EndPoint Name Style 9 aaln ip_addr O mac_addr fip_addr O aaln t mac_addr Oa aln Logic ID Starting Number 1 Wild carded RSIP 9 Each endpoint sends its own RSIP Send only one wild RSIP Apply Cancel MGCP Local Port The UDP port number in MGCP local terminal MGCP Call Agent Address The IP address of the Call Agent server in MGCP MGCP Call Agent Port The UDP port number for the Call Agent server EndPoint Name Style Choose a proper name style for the VoIP settings There are Logic ID Starting Number Wild carded RSIP Vigor3300 Series User s Guide three options for you to choose aaln Q ip addr ex aaln 1 1 1 1 1 mac_addr ip_addr ex 000504030201 1 1 1 1 1 aaln 9 mac addr ex aaln 1 000504030201 aaln ex aaln 1 v3300 draytek com Determine the starting number for the endpoint name There are eight ports in Vigor3300 series The default name for endpoint will be aaln If you type 1 in this filed the endpoint name will be aaln 1 aaln 2 aaln 8 If you type 11 in this field the endpoint name will be aaln 11 aaln 12 aaln 18 etc simply keep the default value 1 For VoIP phone call with MGCP configuration each port will send RSIP to call agent for notifying that port is initiated or
165. p information for WAN interface is manually assigned by the user Dr ay Te k 40 Vigor3300 Series User s Guide Static DHCP PPPoESPPTP DMZ Auuu configuration Configuration IP Address 17216 3729 Host Mame OoOo Subnet Wask Domain Mame BEEN Hast Mame and Domain Name are required far some ISPs Default Gateway Primary DNS Secondary DNS B8 95 1982 1 MTU Connection Detection Detect Type Send ARP to Gateway Detect Interval sec Mo Reply Count Detect Destinatian Host ilP ar Domain Mamet Hh IH c Cc c Un OI Un ad c eu hJ CH ae Cn c th ES m E A t CI th em c IP Alias List 9 32 Apply Reset Cancel IP Address Set the private IP address of WAN interface Subnet Mask Set the subnet mask value of WAN interface Default Gateway Set the private IP address of gateway Primary DNS Set the private IP address of primary DNS Secondary DNS Set the private IP address of secondary DNS MTU Mean maximum transmission unit of one packet The default value is 1500 Host Name Some ISP may ask you to type your host name Please type in if necessary Domain Name Some ISP may ask you to type your domain name Please type in if necessary Detect Type Select a detecting type for this WAN interface There are three ways Send ARP to Gateway Send PING and Send HTTP Request supported in 3300 Send PING Send Http Request Detect Interval Sec Assign an
166. pe ping 192 168 1 1 and press Enter It the link is OK the line of Reply from 192 168 1 1 bytes 32 time 1ms TTL 255 will appear If the line does not appear please check the IP address setting of your computer For MacOs Terminal l 2 Double click on the current used MacOs on the desktop Open the Application folder and get into Utilities Double click Terminal The Terminal window will appear Type ping 192 168 1 1 and press Enter It the link is OK the line of 64 bytes from 192 168 1 1 icmp seq 0 ttl 255 time xxxx ms will appear Vigor3300 Series User s Guide 151 D r ay Te k Terminal bash 80x24 Last login Sat Jan 3 82 24 18 on ttypi Welcome to Darwin Vigori8 draytek ping 192 168 1 1 PING 192 168 1 1 192 168 1 1 56 data bytes 64 bytes 64 bytes 64 bytes 64 bytes 64 bytes AC from 192 168 1 1 from 192 168 1 1 from 192 168 1 1 from 192 168 1 1 from 192 168 1 1 icmp_seq 8 ttl 255 time 0 755 ms icmp_seg 1 ttl 255 time 6 697 ms icmp segz2 ttl 255 timezB 716 ms icmp_seg 3 ttl 255 timeszB 731 ms icmp_seg 4 ttl 255 timezB 72 ms 192 160 1 1 ping statistics 5 packets transmitted 5 packets received 8 packet loss round trip min avg max 8 697 8 723 0 755 ms Vigor1d draytek Jj 4 4 Checking If the ISP Settings Are OK or Not l 2 Network WAN Load Balance Backup WAN 1 WAN2 WANS WANA For PPPoE Mode l Dray Tek Disable Disabl
167. pressing VoIP is immediately called out Or you may wait 3 seconds if you do not press Vigor3300 Series User s Guide 195 Dr ay Te k Intercommunication with different SIP Proxy Servers Connect telephones into 3300V s Port 1 amp Port 3 and 2900V s Port 1 amp Port 2 respectively Each phone registers to the SIP Server The settings and scenario are the same as the above example But they must be set up in conjunction with the Speed Dial Configuration Example for Vigor3300V Enter the VoIP Speed Dial page and add the 4th and 5th group of Speed Dial number Then press Apply to save the settings and finish the configuration Speed Dial Spaad il Cert beares ae eet re 131 ie 135 BS BOace a tel org SSSA quifver con 101 Gustal ong Configuration Example for Vigor2900V I2800 Parti iP 200v Porti ou Port x 2600 Porti ipid 2900v Pon fed Apply Cancel Cea Thie Pase Click DialPlan Setup in the VoIP Setup page Then add the second and third group of Speed Dial number di gt Advanced Setup gt VelP Setup gt DialPlan Setup DialPlan Configuration index Phone number Display Name SIP URL Status L 33 3300V Porti IP 3300W Port iptel 3300V Port2 fwd Start to dial by using telephone Phone 1 call Phone 4 gt Press 29124 Phone 2 call Phone 3 gt Press 29111 Phone 3 call Phone 1 gt Press 3312 Phone 4 call Phone 2 gt Press 33111 88883
168. r3300 Series User s Guide 201 Dray Te k 3 Enter VoIP DialPlan page and the first and second group of Speed Dial Phone Number VolP gt gt DialPlan Setup Index Ns 1 M Eniko Phone Humier Lavtpbxy Mima SIP VEL Dag mrouy Becaup Phim Number UIP Belated bore be i CODEC RTE DTMS E Woke Tal Sisto Ps syle Mamina a Diaa ConEguradion TTL DESI Phone imie amber Display hana EIF UEL JIU AA POr L YAH HEHBEZR OI32 108 33 1 H i 2201 2900v Porti VPN 4990299 192 169 29 1 L T 3 i 2 After configuration please confirm that the VPNs are established and they can communicate with each other Please refer to VPN IPSec LAN to LAN Usage Example 2 Start to dial by using telephones Phone 1 call Phone 2 gt Press 2901 or 888829 192 168 29 1 Phone 1 call Phone 3 gt Press 2201 or 888822 192 168 22 1 Phone 2 call Phone 1 gt Press 3301 Phone 2 call Phone 3 gt Press 2201 or 192 168 22 1 Phone 3 call Phone 1 gt Press 3301 Phone 3 call Phone 2 gt Press 2901 or 192 168 29 1 Note indicates termination of the phone number After pressing VoIP is immediately called out Or you may wait 3 seconds if you do not press Dr ay Te k 202 Vigor3300 Series User s Guide 5 2 9 Example 4 Practical Application of FXS Based on the VoIP Example 1 Basic Configuration and Registration we will introduce the practical applicati
169. racters for authenticate this Dray Tek Vigor3300 Series User s Guide 129 Hotline FXO Codec CAS Dray Tek port Proxy Server Type the SIP proxy server to be applied on this port Call without Registration If the registration for this port is not successful click Enable to call via this port Play dial tone only when port registered If the registration for this port is not successful no dial tone appears when picking up the phone VoIP IP Address The interface is used to apply VoIP traffics There are two options WAN and LAN VPN If LAN VPN is selected VoIP can be applied through a VPN tunnel to create a high security voice phone Hotline Number to Internet Pre set a phone number to make the port dialing out to Internet automatically Hotline Number to PBX PSTN Pre set a phone number to make the port dialing out to PBX PSTN automatically Manual Disconnection Click Disconnect to disconnect this phone line manually Preferred Codec It can be applied on this port Vigor3300 supports five Codecs The default setting is G 729A You can choose another one as preferred Codec for outgoing calls 93 7294 B8kbps v G 711UrPCHI 64kbps G 711AiPCHM b4k bps 5 7294 kbps 3 723 1 6 3kbps 3 725 32kbps Single Codec If you checked this box only preferred codec will be used for outgoing and incoming calls And if the remote end does not support such Codec the VoIP com
170. re correct or not Both them are required for some ISPs jc Ji lee PPPOE PPTP DMZ een rene Configuration Configuration Default Gateway 21631 Host Name and Domain Name are required for same ISPs 2 If anything wrong please check and retype correct values Then try the network connection again 3 After finishing the settings go to System gt gt Status page and click WAN Status You will get a correct web page of WAN settings Dr ay Te k 154 Vigor3300 Series User s Guide Basic status LAN Status WAN Status WANT IP Address ires ees BTE MAC Address Ir 50 7f28 80 85 Primary DMS 172 16 100 1 Secondary OMS Gateway 172 16 100 1 EX Packets gb Ts Fackets 100 Connection Status connected Wp Time O days 0 hours 4 minutes 61 seconds For PPTP Mode 1 Check if the settings of Username and Password are correct or not 2 Check if the setting of Authentication is correct or not You may need to try both PAP and CHAP 3 Check if the value of PPTP Local Address PPTP Subnet Mask and PPTP Remote Address are correct or not ctatic DHCF Bada ieee DMZ Configuration Beet ete Configuration PPTP Local Address 10 0 0 150 Liser Name Password PPTP Subnet Mask Authentication PPTP Server Address Servite Nama Do 4 After finishing the settings go to System Status page and click WAN Status You will get a correct web page of WAN settings Basic Status LANsStau
171. restarted Each endpoint sends its own RSIP Each port must send one RSIP message e g aaln 1 9 172 16 3 5 to call agent respectively Send only one wild RSIP Only one RSIP message e g aaln 172 16 3 5 will be sent to call agent to indicate all ports are initiated restarted 127 Dray Tek 3 7 2 Port Settings Port Settings page allows users to set phone number and phone groups for different call receivers For Phone Number VoIP Port Settings Phone Number Group Edit Type Active 1 FXS 2 FXS FXS 4 FXS FXS 6 FXS 7 FXS FXS Edit Type Active Group Username Proxy Codec Group 1 Username 1001 1002 1003 1004 1005 1006 1007 1008 Codec G 729A 8kbps G 729A 8kbps G 729A 8kbps G 729A 8kbps G 729A 8kbps G 729A 8kbps G 7 29A 8kbps G 729A 8khps Click this button to access into the Edit page for each phone number Display the type of the VoIP connection Display the status active or not for the VoIP connection Display the group number of the VoIP connection Display the username that you typed for the VoIP connection Display the proxy information that you set on VoIP gt gt Protocol page for the VoIP connection Display the codec settings for the VoIP connection When you click Edit the following page will appear for you to configure Dray Tek 128 Vigor3300 Series User s Guide VolP Port Settings Port1 Edit
172. rface DMZ Host IP List 3 2 2 Load Balance Policy Choose NAT Mode or Routing Mode as the DMZ host type This setting is available when Routing Mode selected as DMZ host type When DMZ Host type is set as Routing Mode please type the IP address here to be chosen in IP Alias in Advanced gt gt NAT gt gt DMZ Host Vigor3300 Series supports a load balancing function It can assign traffic with protocol type IP address for specific host a subnet of hosts and port range to be allocated in WAN interface User can assign traffic category and force it to go to dedicate network interface based on the following web page setup VoIP and VPN traffic can also be assigned to specific WAN ports In the Network group click the Load Balance Policy option You will get the following page Network Load Balance Policy Dest Port Dest Port Network zi Protocol Source IP Subnet Mask Dest IP Subnet Mask Start End eTa Strict Bind TON 2 3 4 O 5 6 Q t O 8 O 9 10 1 Edit Delete Delete All Protocol Display the protocol used for this entry Source IP Display the source IP address specified for this entry Subnet Mask Display the subnet mask address specified for the source IP of this entry Dest IP Display the destination IP address specified for this entry Subnet Mask Display the subnet mask address specified for the destination IP of this entry Dest Port Start Display the start point specified in the Dest Port Ra
173. roup Name Comment Group far black rules Add Rule Apply Cancel 3 In the following page please set Block immediately as the action and click Apply Vigor3300 Series User s Guide 157 Dr ay Te k Firewall IP Filter Add Filter Rule Filter Condition Active SOUrCE IP any SubnetMask 255 255 2650 Fort v 0o Destination IP SubnetMask o O Fort w Group Mame Sloc Protocal Direction Fragment Action Black ar Pass Block immediately wt Mest Group Mame none 4 Now you will get the following page Firewall IP Filter Table Group Name Block Next Group Name Comment Group for block rules IP Filter Table Index SourcelP Subnet Mask Port Destination IP Subnet Mask Port Protocol 1 any 255 255 255 0 any 5 1 2 How to Check Edit VLAN ID on Your PC Apply Cancel Add Rule Apply Cancel Direction Block Active any protocol LAN to LAN Block immediately Edit Rule Delete Rule Not all the network cards support VLAN features If you cannot sure if the network card of your computer supports tagged VLAN or not please do the following steps to check or edit VLAN ID on your PC 1 Goto Control Panel and then double click on Network Connections Jeluark Connections Dray Tek 158 Vigor3300 Series User s Guide 2 Right click on Local Area Connection and click on Status us Disable Repair Loca
174. rt Block The Port Block function provides a user to set lots of proprietary port numbers Packets will be dropped if destination ports both TCP and UCP of packets with these assigned port numbers are on WAN and LAN The advantage of this feature is to filter some unnecessary packets or attacking packets on Internet environment or LAN network Vigor3300 Series supports ten port numbers to be blocked In the Advanced group click Port Block option You will get the following page Advanced Port Block Index Status Port Number il 9 Disable O Enable 9 Disable O Enable 9 Disable O Enable 4 9 Disable O Enable 9 Disable Enable B 9 Disable O Enable 9 Disable Enable 9 Disable O Enable 9 9 Disable O Enable 10 9 Disable O Enable Apply Cancel Index The number of each entry Status User can Disable or Enable this port to be blocked Port Number Assign a port number to be blocked in system Click Apply to finish this setting The default port setting for V3300B and 3300B 1s 135 3 3 5 DDNS Setup The Dynamic DNS function allows the router to update its online WAN IP address which assigned by ISP or other DHCP server to the specified Dynamic DNS server Once the router is online you will be able to use the registered domain name to access the router or internal virtual servers from the Internet DDNS is more popular on dynamic IP users who typically receive dynamic frequen
175. rt the troubleshooter Device usage Use this device enable wt 6 In this screen there is no VALN existed You can create a new one Please click the ew button Intel R PRO 100 5 Desktop Adapter Properties Boot Agent Driver Resources Fower Management General Link Advanced Teaming intel Virtual LANs VLANs associated with this adapter VLAN Mame Status Hew Allows you to configure up ta 64 virtual LANs sa ATE for an adapter Adapters with YLANs must be connected to network devices that support the IEEE 802 10 specification When you configure the WYLAN SoS Packet Tagging is automatically enabled Ux NOTE After creating the VLAN the adapter associated with the WYLAN briefly loses network connectivity Dr ay Te k 160 Vigor3300 Series User s Guide 7 In New VLAN dialog please type a number in the box of VLAN ID Here 5 is entered The corresponding VLAN Name will appear automatically Next click OK to create it New VLAN VLAN Mame VLAN z Untagged VLAN VLAN ID Enter the number of the SLAN assigned to the adapter in the VLAH ID box This VLAN ID number iz also configured on the switch Adapters with VLANs must be connected to network devices that support IEEE 802 10 oS Packet Tagging IEEE 8021 pii is automatically enabled on the adapter You can enter multiple YLAN IDs by entering two or more IDs separated by commas For example ta e L 2 JE
176. rtment Department Cuest Procedure 1 Refer to A 1 to block LAN to LAN communication 2 Create VLANS VLAN6 VLAN7 and VLANS Groups 3 Inthe VLANS type 5 to VLAN ID In the Member field choose pl Then choose the Tagged for Frame Tag Operation in pl We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from the PC of Engineer Department 4 Inthe VLANO type 6 to VLAN ID In the Member field choose p2 Then choose the Tagged for Frame Tag Operation in p2 We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from Engineer Department 5 Inthe VLANT type 7 to VLAN ID In the Member field choose p3 Then choose the Tagged for Frame Tag Operation in p3 We can ignore the PVID Port VLAN ID because 802 1q tag will be inserted to the frame from the PC of Engineer Department Dr ay Te k 170 Vigor3300 Series User s Guide 6 Inthe VLANS type 8 to VLAN ID In the Member field choose p4 Then choose the Untagged for Frame Tag Operation in p4 We should configure the PVID to 8 because the device does not support 802 1Q VLAN Advanced LAN VLAN Setting O Disable Port Base VLAN 9 802 1Q VLAN Port Base VLAN 802 1Q VLAN Group Index Active Name VLAN ID Member Frame Tag Operation P1 P4 Tagged agg Tagged Tagged agge Tagged Tagged Tagged Tagged
177. s MEETTUESTUTE WANT IP Address 51 230 208 202 MAC Address Dn 50 7528 80 e7 Primary OMS 184 109 5 55 Secondary ONS 194 96 0 4 Gateway 51 230 208 245 Ria Packets 341 Ts Packets ls Connection Status connected Up Time O days O hours 4 minutes 39 seconds Disconnect 4 5 Backing to Factory Default Setting If Necessary Sometimes a wrong connection can be improved by returning to the default settings Try to reset the router by software or hardware Vigor3300 Series User s Guide 155 Dr ay Te k Warning After pressing factory default setting you will lose all settings you did before Make sure you have recorded all useful settings before you pressing The password of the factory default is null Software Reset You can reset router to factory default via Web page Go to System gt gt Reboot on the web page The following screen will appear Choose Reset to factory default and click Apply After few seconds the router will return all the settings to the factory settings System Reboot Reset to factory default Apply Hardware Reset While the router is running ACT LED blinking press the RST button and hold for more than 5 seconds When you see the ACT LED blinks rapidly please release the button Then the router will restart with the default configuration Factory Reset an Du D 8 COS Ge Da B O09 3 Owe QE Sede Gon 0 B GO OE Baan Lu Fike Fees PI Pp FQ Piai Trier
178. s a wide variety of authentication schemes A user supplies his authentication data to the server either directly by answering the terminal server s login password prompts or using PAP of CHAP protocols The Vigor 3300 Series support Radius client function A user can configure some authentication information to do an authentication with Radius server In Vigor3300 Series it is only applied by VPN gt PPTP function In the Advanced group click the Radius option You will get the following page Dr ay Te k 68 Vigor3300 Series User s Guide Advanced RADIUS O Disable Enable Server IP Address 53 14 1001 m Destination Port 1812 Shared Secret LIII Confirm Shared Secret LIII WAN Interface V N1 w Apply Cancel Enable Disable Click Disable to disable this function Click Enable to activate this function Server IP Address Assign an IP address of a Radius server Destination Port Assign a destination port number used for Radius function Shared Secret Assign a code for authentication to server The RADIUS server and client share a secret which 1s used to authenticate the messages sent between them Both sides must be configured to use the same shared secret Confirm Shared Secret Confirm the code assigned in Shared Secret field WAN Interface Select one specific WAN interface to be used Click Apply to reboot the system and apply the settings Vigor3300 Series User s Guide 69 Dr ay Te k 3 3 4 Po
179. s established WAN DMZ The data transmission is done through the 1 2 3 4 corresponding port No Ethernet link is established 100 It means that a normal 100Mbps connection is through its corresponding port It means that a normal IOMbps connection is through its corresponding port FDX On It means a full duplex connection on corresponding port Off It means a half duplex connection on corresponding port FXS FXO BS EEUU Bee Ce CEN Console WAN DMZ P1 P2 Interface Description Console Provided for technician use LAN P1 P4 Connecter for local networked devices WAN DMZ P1 P4 Connecter for remote networked devices FXS Connecter for telephone set FXO Connecter for FXS interface of PABX Vigor3300 Series User s Guide 3 Dr ay Te k 1 1 2 LED Indicators and Connectors for Vigor3300 act VPN e Oo O 9 LNK Q Attack O amp e o 9 O0 O0 ioom OPWR GWLANG QoS e o 0 09 GO rbx WAN2 WAN3 WAN1 P1 P2 P3 P4 LAN LED Status Explanation PWR The router is powered on Off The router is powered off ACT The system is active The system is hanged WLAN Reserved for future use VPN The VPN tunnel is launched Off The VPN tunnel is closed Attack The Attack function is active The Attack function is inactive Qos The QoS function is active The QoS function is inactive LNK The Ethernet link is established on corresponding port Off No Ethernet link is established aN 100M On It means
180. s to manually configure the router Static DHCP eeu DMZ enue eee Configuration Configuration D efault Gateway 721631 Host Name and Domain Name are required for some ISPS TU 1500 Connection Detection Detect Interval sec Detect Destination Host SY HP or Domain Mame Apply Reset Cancel Detect Type Select a detecting type for this WAN interface There are three ways Send ARP to Gateway Send PING and Send HTTP Request supported in the router Send Http Request we Send ARP to Gateway Send PING Send Http Regu Detect Interval Sec Assign an interval period of time for each detecting The minimum value is 3 and no limit for maximum value No Reply Count Assign detecting times to ensure the connection of the WAN After passing the times you set in this field and no reply received by the router the connection of WAN interface will be regarded as breaking down Detect Destination Host Assign an IP address or Domain name as a destination to be IP or Domain Name detected whether the host is active sending reply to the router or not If not the connection of WAN interface will be regarded as breaking down This function is available when Detect Type is set with Send PING or Send Http Request Apply Click Apply to go back to the WAN Interface Configuration page To apply all settings click Apply on the WAN Interface Configuration page and reboot your router Reset Click this button to clear all
181. s tunnel The IP address of the next hop The keyword default can be used to represent the gateway IP address of the selected WAN Interface The identification number for the remote gateway The IP address of the remote client gateway This field is mandatory The setting for 0 0 0 0 is used for the road warrior with a dynamic IP address The virtual IP address of the remote client specified for this tunnel 111 Dray Tek For Advanced Configuration Click Advanced tab This page allows you to set advanced configuration for the specified policy The following page of default configuration will be shown VPN IPSec VPN Trunk Policy Table Edit IKE Phase1 main mode Key Lifetime 460 minutes Proposal des mdS modp768 v des sha modp 68 w 3des md5 modp 68 3des md5 modp1i024 v IKE Phase2 quick mode Key Lifetime 60 minutes Proposal dez mdb5 w 3des md5 w 3des J PFS Perfect Forward Secrecy Accepted Proposal Accept all supported proposal v Dead Peer Detection Delay 2 seconds Timeout a seconds GRE Header Key v Auto GRE Key GRE Key In 0x GRE Key Out 0x Apply Cancel Key Lifetime main The renegotiated period of the IKE Phasel keying channel of a connection The acceptable range is from 5 to 480 minutes 8 hours Proposal main The proposed encryption and or authentication algorithms for IKE Phasel negotiation
182. start date and time for this schedule Action Display the action that this schedule adopts How often Display the using frequency once or specific day in a week of this schedule Week Option Display the specific day in a week if you choose Weekdays as the How often setting WAN Display the WAN interface used for this entry Edit Allow users to edit the selected call schedule settings Delete Delete All Remove one all the selected call schedule settings Edit Call Schedule To edit an item click the radio button of the item that you want to modify Then click Edit on the bottom of the page to add a new rule entry or modify an existed rule entry Vigor3300 Series User s Guide 73 Dr ay Te k Advance Call Schedule Edit O Disable 9 Enable Start Date Start Time Action How often Network Interface Enable Disable Start Date Start Time Action How often Network Interface 2004 12 28 cvear month Date 00 o0 Hour Minute force down 9 force on 9 Once Weekdays Monday Tuesday Wednesday Thursday Friday Saturday Sunday Apply Cancel Click Disable to disable this function Click Enable to activate this function Assign a date for starting this profile Assign a time for starting this profile Force down means to inactivate the Network Interface Force up means to activate the Network Interface Once means only for one time Weekdays means that user
183. stem wide resources recovers partial of failed transactions and restores the system to normal within a matter of microseconds Take the following picture as an example The left V3300 Series 1s regarded as Master device the right V3300 Series is regarded as Slave device When Master V3300 Series is broken down the Slave device could replace the Master role to take over all jobs as soon as possible However once the original Master is working again the Slave would be changed to original role to stand by Vigor3300 Series User s Guide 53 Dr ay Te k Vigor3300V e wee Master Router Configurations LAN IP 192 168 1 1 LAN MAC 00 50 7F 0A OB 01 High Availability Enable Group Number 1 Role Master Virtual IP 192 168 1 3 Virtual MAC 00 00 5E 00 01 01 WAN Internet Vigor3300V Slave Router Configurations LAN IP 192 168 1 2 LAN MAC 00 50 7F 0A 0B 02 High Availability Enable Group Number 1 Role Slave Virtual IP 192 168 1 3 Virtual MAC 00 00 5E 00 01 01 Master and Slave must have the same Group Number and Virtual IP Virtual MAC will be generated automatically by assigned Group Number Host Network Configurations obtained via DHCP client IP 192 168 1 11 Subnet Mask 255 255 255 0 Default Gateway 192 168 1 3 C EIE Host Network Configurations obtained via DHCP client IF 192 168 1 12 Subnet Mask 255 255 255 0 Default Gateway 192 168 1 3 ARP Table 192 16
184. stly the Vigor3300V has a DMZ function can be applied to any LAN or WAN interface 1 1 1 LED Indicators and Connectors for Vigor3300V r LAN r WANIDMZ ven OG O OG OG 0 O Oe GFirewl O9 00 O O O O o QPwRGAa4crT QGoos OQ O OG O0 rx O O OG O Factory Reset P1 P2 P3 P4 P1 P2 P3 P4 Factory Reset Used to restore the default settings Turn on the router ACT LED is blinking Press the hole and hold for more than 5 seconds When you see the ACT LED begins to blink rapidly than usual release the button Then the router will restart with the factory default configuration LED Status Explanation PWR The router is powered on Off The router is powered off ACT The system is active The system is hanged VPN The VPN tunnel is launched The VPN tunnel is closed Firewall The Firewall function is active Off The Firewall function is inactive QoS The QoS function is active gt mr The QoS function is inactive Dr ay Te k 2 Vigor3300 Series User s Guide Status Explanation The Ethernet link 1s established on corresponding port No Ethernet link 1s established BEEN 100 On It means that a normal 100 Mbps connection is 1 2 5 4 through its corresponding port Off It means that a normal 10 Mbps connection is through its corresponding port FDX It means a full duplex connection on corresponding port Off It means a half duplex connection on corresponding port LNK The Ethernet link i
185. t Last it is more convenient and easy to configure in user s interface In the Advanced group click the WAN Port Mirroring option You will see the following page Advanced WAN Port Mirroring O Disable 9 Enable Mirroring Port Port 1 xv Mirrored Portis Port 1 Port 2 Port 3 Port 4 Enable Disable Mirroring Port Mirrored Port s Apply Cancel Click Disable to disable this function Click Enable to activate this function Select a port to view traffic sent from mirrored ports Click which ports are necessary to be mirrored After finishing the settings please click Apply Vigor3300 Series User s Guide 75 Dray Tek 3 3 8 LAN Port Mirroring Setup Port mirror can be applied for the users in LAN It has the same mechanism like WAN port mirroring In the Advanced group click the LAN Port Mirroring option Advanced LAN Port Mirroring Disable 9 Enable Mirroring Port Port 3 w Mirrored Port s Port 1 Pon 2 Port 3 Port 4 Apply Cancel Enable Disable Click Disable to disable this function Click Enable to activate this function Mirroring Port Select a port to view traffic sent from mirrored ports Mirrored Port s Click which ports are necessary to be mirrored After finishing the settings please click Apply 3 3 9 LAN VLAN Setup Virtual LANs VLANs are logical independent workgroups within a network These workgroups communicate as if they had a physical connection to the
186. t 1 amp Port 3 and 2900V s Port 1 amp Port 2 respectively Each port needs to register in the SIP Server Below shows a scenario architecture graph f iwd Proxy Server iptel Proxy Server 2000V Port FAS Port FX RRRRZ9 660529 iptel fwd Port FXS Port FXS BEERSS 660533 iptel fwd China Shanghai Taiwan Phone 1 Phone 2 Phone 3 Phone 4 Configurations between Vigor 3300V and 2900V wan Port Number Phone Number Proxy cose Port3 FXS 660533 fwd 1G 729A Portl FXS 888829 G 729A 2900V 61 31 167 135 Port2 FXS 660529 fwd 1G 729A You can also add Speed Dial numbers in Speed Dial to speed up the dialing or to accommodate the setup of company s extension numbers Dr ay Te k 194 Vigor3300 Series User s Guide Configuration Example for Vigor3300V Enter the VoIP Speed Dial page and add the second and third group of Speed Dial number Then click Apply to save the settings and finish the configuration VoIP Speed Dial peci nal Phesne ies Sap Lad Ee md brat kem SAS 31 157 135 z900wv Put IP 35070 2800 Fort sana aS V Part TIC Apel Cancel Clear This Page Start to dial by using telephones Phone 1 call Phone 3 gt Press 888829 or 291 Phone 2 call Phone 4 gt Press 660529 or 2924 Phone 3 call Phone 1 gt Press 8888334 Phone 4 call Phone 2 gt Press 660533 Note indicates termination of the phone number After
187. t IP Assign the start IP address for limit session End IP Assign the end IP address for limit session Session Number Assign the available session number for each host in the specific range of IP addresses If you do not set the session number in this field the system will use the default session limit for the specific limitation you set for each index Apply After finishing the configuration please click this button to invoke these settings 3 3 Advanced Setup In the Advanced menu there are several items offered here for you to adjust for the router Static Rote MAT gt Port Block DONS Call Schedule VOSA Port Mirroring LAM Port Mirroring e RADIUS gt 4 LAN VLAN SNMP Dr ay Te k 60 Vigor3300 Series User s Guide 3 3 1 Static Route Setup When you have several subnets in your LAN sometimes a more effective and quicker way for connection is the Static routes function rather than other methods You may simply set rules to forward data from one specified subnet to another specified subnet without the presence of RIP This function allows users to assign static routing information In the Advanced group choose Static Route You will get the following page Advanced Static Route Network Interface Destination IP Gateway IP Mask cn A to O00 0 0000 0 oo co 10 Edit Delete Delete All Network Interface Display the network interface LAN WANI 2 3 or 4 Desti
188. t Mask Flags Interface 172 16 2 0 255 255 255 0 U eth0 1 1 1 0 255 255 255 U vlanl 1 1 1 0 255 255 255 0 U ipsecl 127 0 0 0 255 0 0 0 U lo Refresh Destination Display the destination IP address for various routings Gateway Display the default gateway Subnet Mask Display the subnet mask for various routings Flags Display the status of the routing entries Interface Denoted by eth0 if it is a LAN interface and ethl if it is a WAN interface Refresh Click Refresh to re display this web page for getting newest routing information Vigor3300 Series User s Guide 35 Dr ay Te k Select View ARP Cache Table to get the following page System Diagnostic Tools View ARP Cache Table IP Address MAC Address Interface Refresh IP Address MAC Address Interface 192 168 1 1 00 50 7 7F 00 00 00 eth 192 168 1 10 00 0E 6 2 D5 1 eth Refresh Display the IP address for different ARP cache Display the MAC address for different ARP cache Denoted by eth0 if it is a LAN interface and ethl if it is a WAN interface Click Refresh to re display this web page for getting newest ARP information Select View DHCP Assignment Table to get the following page System Diagnostic Tools View DHCP Assienment Table Assigned IP MAC Address Time Left 192 168 1 10 00 00 00 00 00 00 expired 192 168 1 11 00 0E 5 2 D5 1 expired Assigned IP MAC Address Time Left Refresh
189. t number Disable option uses IP address of WAN interface Enable option uses IP alias addresses It is a pull down window user can select one specific WAN interface It is a pull down window user can select one specific IP address assigned in IP Alias group of WAN interfaces Click Apply to reboot the system and apply the settings Note The port forwarding function could redirect the Internet traffic which has the destination port within the public port range and has the same IP address as WAN Interface or Dray Tek 64 Vigor3300 Series User s Guide IP Alias that you set Please redirect only the ports that you have to forward rather than forward all ports Otherwise the intrinsic firewall type security of NAT facility will be affected By the way user can click Delete to remove one current existed NAT entry in the Advanced NAT Port Redirection page and click Delete All to remove all entries Address Mapping If you have a group of static IP addresses then you can use the address mapping feature to multiple open ports hosts in the Vigor3300 Series of broadband security routers The following session will show you how to setup address mapping feature In the Advanced group move to NAT option and choose Address Mapping to get the corresponding page Advanced NAT Address Mapping Protocol Public IP Private IP Mask O00 000000 9 1 Edit Delete Delete All Protocol Display t
190. t set up the Outbound Proxy and Stun Server when calling through VPN 2 Click DialPlan Setup in the VoIP Setup page and add the first and second group of Speed Dial Phone Number gt Advanced Setup gt VoIP Setup gt DialPlan Setup DialPlan Configuration Index Phone number Display Name l si Dr ay Te k 200 Vigor3300 Series User s Guide Note Do not set up the Display Name when calling through the VPN with 2900V firmware v2 5 6 Otherwise you can t get ring back and communicate with remote user after getting through Configuration Example for Vigor2200V l Enter 2200V s Web and click VoIP SIP Related Function page SIP related function of 2200V 2 Setup Port 1 This page falls into two sections SIP Set up the SIP Server used for registration Ports Set up the account details x Yio toto VG we 1 VPN VoIP outer VolP gt gt SIP Related Functions Setup Lhulck Star Wirard Conlin Siale liena etii LAH MAT Fire ali SI Poi Piegostrar Prax y Applications WPM and Bemais Artes Com amhaaln Stun ena Synem Haintenante LH agn etica uzplag Harre account Marce Aah en zatien User Fasso Expry Time After configuration please click OK to save the settings Note Do not set up the Proxy and Stun Server when calling through VPN While in 2200V firmware v2 5 5 4 the Proxy will be active if Use Registrar is enabled So make sure not click Use Registrar Vigo
191. tatus WAN Status WANT IP Address 718 158 228 27 MAC Address DD SD 7E 28 80 85 Primary DMS 168 495 1 1 secondary DNS Gateway 51 230 182 254 RA Packets g5 TA Packets 40 Connection Status cannected Up Time Odays hours 4 minutes 45 seconds Disconnect For Static Mode 1 Check if the values of IP Address Subnet Mask Gateway IP Address and Primary DNS that you got from ISP are set properly or not If you forget please contact with ISP for getting new ones Vigor3300 Series User s Guide 153 Dr ay Te k Static DHCP PPPOE FRPTP OMZ Menuet ariel configuration Configuration IP Address 172463 228 Hast Name Do O Subnet Mask 255 255 255 0 Domain Name o d Default Gateway 172 18 3 1 Hast Name and Domain Name are required for some ISPs Primary DNS 166 95 1 1 Secondary DNS 158 95 192 1 2 If anything wrong please retype correct values and try the network connection again 3 After finishing the settings go to System Status page and click WAN Status You will get a correct web page of WAN settings Basic Status LAN Status WAN Status WANT IP Address Panels cere n MAC Address Dn S0 7628 80 e4 Primary ONS 158 85 1 1 Secondary ONS Gateway 220 130 524 209 Ra Packets T8 TA Packets 384 Connection Status connected Up Time O days 0 hours 5 minutes 7 seconds For DHCP Mode 1 Check if Host Name optional and Domain Name optional a
192. te IP used for this entry Private Port Start Display the start point in the range of private port Vigor3300 Series User s Guide 63 Dr ay Te k Private Port End Use IP Alias WAN Interface IP Alias Edit Delete Delete All Display the end point in the range of private port Display the using status for WAN IP alias Display the WAN interface of this profile Display the selected WAN IP address Allow users to edit the selected port redirection settings Removes one all the selected port redirection settings To edit an item click the radio button of the item that you want to modify Then click Edit on the bottom of the page to add a new rule entry or modify an existed rule entry Advanced NAT Port Redirection Edit Profile Status O Disable 9 Enable Comment Protocol Public Port Range Private IP Private Port Range Use IP Alias WAN Interface IP Alias Profile Status Comment Protocol Public Port Range Private IP Private Port Range Use IP Alias WAN Interface IP Alias EJ Disable 9 Enable Apply Cancel Enable or disable this function Assign a name for this entry The maximum is 20 characters Assign the transport layer protocol with TCP or UDP Assign a port range from starting to end public port number The port range is from 1 to 65535 Assign a local IP address to be transferred into Assign a port range from starting to end private por
193. ter correctly Notice You may either simply set up your computer to get IP dynamically from the router or set up the IP address of the computer to be the same subnet as the default IP address of Vigor router 192 168 1 1 For the detailed information please refer to the later section Trouble Shooting of this guide 2 Open a web browser on your PC and type http 192 168 1 1 A pop up window will open to ask for username and password Please type default values on the window for the first time accessing The default value for user name is draytek and the password is 1234 Next click OK Connect to 172 16 2 225 Login to Vigor 3300 User name E draytek v Password ETT C Remember my password Vigor3300 Series User s Guide 11 Dr ay Te k 3 Now the Main Screen will pop up VIGOROUS BROADBAND ACCESS Quick Setup System Network Advanced Firewall Qos VPN VoIP 10 08 59 System Status Refresh Option No Refresh v Refresh LAN Status WAN Status Model Vigor3300 Hardware Version 1 0 Firmware Version 2 5 9 0 EN Build Date amp Time 2009 02 11 18 29 24 System Uptime 0 days 0 hours 0 minutes 22 seconds CPU Usage 47 230796 Memory Size 64 MBytes Memory Usage 30 8389 Current System Time 2009 03 20 10 20 23 DrayTek Corp 1997 2008 All rights reserved DrayTek Enterprise Network Solutions 4 Network status Time Syslog Access Control Change Password configurat
194. tes count received by this tunnel Byte Out Display the bytes count sent out by this tunnel Uptime Display the time duration since the tunnel is established Refresh Allow you to refresh current VPN status Disconnect Allow you to disconnect the select VPN connection Dr ay Te k 124 Vigor3300 Series User s Guide 3 7 VoIP Setup Voice over Internet Protocol VoIP is a technology that allows you to make telephone calls using a broadband Internet connection instead of a regular or analog phone line The Vigor3300 Vigor3300V provides cost effective voice solution for SME customers which can be explained with the following diagram RADIUS Data NMS Server Base Server 5 E Alarm message Cell Phone me BB Administrator A Server em Phone if j d CR P MSC BS 87 Base station z of Cordless Phone iii e g DECT Cell Phone Italy France Protocol Port Settings Speed Dial Advanced Speed Dial Miscellaneous lt e Tone Settings Gos e NAT Traversal Incoming Call Barring 7 Call History p Tone Upload S Status 3 7 1 Protocol There are two protocols can be used for VoIP SIP and MGCP You should click either one of buttons to set corresponding settings for VoIP phones Be aware that both sides local end and remote end should use same protocol for VoIP phones Vigor3300 Series User s Guide 125 Dr ay Te k VoIP Protocol Sele
195. that a normal 100 Mbps connection is 2 3 D through its corresponding port Off It means that a normal 10 Mbps connection is through its corresponding port FDX On It means a full duplex connection on corresponding port It means a half duplex connection on corresponding port The Ethernet link is established LAN The data transmission is done through the 1 2 3 4 corresponding port Off No Ethernet link is established On It means that a normal 100Mbps connection is through its corresponding port Dr ay Te k 4 Vigor3300 Series User s Guide Status Explanation Off It means a half duplex connection on corresponding It means that a normal 10Mbps connection is through its corresponding port FDX It means a full duplex connection on corresponding port port WAN DMZ ILL Console LAN EE Pi P2 P3 P4 Interface _ Description p Console Provided for technician use LAN P1 P4 Connecter for local networked devices WAN DMZ WANI WAN3 Connecter for remote networked devices Vigor3300 Series User s Guide 5 Dr ay Te k 1 1 3 LED Indicators and Connectors for Vigor3300B act T e Oo O LK Attack amp o0 O O 100m OPWR Qoos o0 Fox WAN2 WAN3 WAN1 P1 P2 P3 P4 LAN Status Explanation PWR The router is powered on Off The router is powered off ACT The system is active Off The system is hanged Attack The Attack function is active T
196. ther Departments to limit their communication to protect the engineering data In this case we can define two VLANs that are VLAN5 and VLANOG The subnet of VLANS is 192 168 1 0 and the subnet of VLANO is 192 168 2 0 LAN 192 168 1 0 192 168 1 0 192 168 4 0 192 168 2 0 COS i he x x L2 L2 dam dum z m e mo E c es sumiphr Engineer Department Engineer Department Other Departments Other Departments Procedure 1 Refer to A 1 to block LAN to LAN communication 2 Create VLANS5 and VLANO Groups 3 Inthe VLANS type 5 to VLAN ID In the Member field choose pl and p2 Then choose Tagged for Frame Tag Operation in pl and p2 We can ignore the PVID Port VLAN because 802 1q tag will be inserted to the frame from the PC of Engineer Department 4 Inthe VLAN6 type 6 to VLAN ID In the Member field choose p3 and p4 Then choose Tagged for Frame Tag Operation in p3 and p4 We can ignore the PVID Port VLAN because 802 1q tag will be inserted to the frame from other departments Dr ay Te k 166 Vigor3300 Series User s Guide Advanced LAN VLAN Setting O Disable Port Base VLAN 9 802 1 VLAN Port Base VLAN 802 1Q VLAN Group Index Active Name VLAN ID Member Frame Tag Operation P1 1 5 2 B OO 3 VLAN 7 gO O E C Tagged Tagged w Untagged Tagged v 4 VLANG B
197. tly changing IP addresses from their service provider Before you set up the Dynamic DNS function you have to subscribe free domain names from the Dynamic DNS service providers The router provides up to ten accounts for the function and supports the following providers www dynsns org www no ip com www dtdns com www changeip com www ddns cn You should visit their websites for registering your own domain name on the router In the Advanced group click DDNS option You will get the following page Dr ay Te k 70 Vigor3300 Series User s Guide Advanced DDNS E Domain Name Server Provider Server Type Active Status dyndns org dynamic Disable Not Connected 2 dyndns org dynamic Disable Not Connected 3 dyndns org dynamic Disable Not Connected 4 dyndns org dynamic Disable Not Connected 5 dyndns org dynamic Disable Not Connected 6 dyndns org dynamic Disable Not Connected z dyndns org dynamic Disable Not Connected 8 dyndns org dynamic Disable Not Connected 3 dyndns org dynamic Disable Not Connected 10 dyndns org dynamic Disable Not Connected Refresh Domain Name Display the domain name set for the entry Service Provider Display the service provider that supports DDNS Service Type Display the service type for the entry Active Display the activation status disable or enable for this entry Status Display the connection status of this entry Click Refresh to re display the whole page information To modify DDNS setting click a
198. transmission rate for this WAN interface The default value is 102400 kbps 100 Megabit This setting is very important for Vigor3300 Series outgoing buffer adjustment If you use a DSL subscriber service with a 256Kbps downstream please set the downstream rate setting with 256Kbps Select a connection type for this WAN interface Currently there is only one setting offered for you to choose Fast Ethernet Select connection speed mode for this WAN interface There are auto negotiation full duplex and half duplex of either 10M or 100M speed options for the WAN Interface 14 Vigor3300 Series User s Guide IP Mode Select an IP mode for this WAN interface There are four available modes for Internet access Static DHCP PPPoE and PPTP On this page you may configure the WAN interface to use Static fixed IP DHCP dynamic IP address PPPoE or PPTP Most of the cable users will use the DHCP mode to get a globally reachable IP address from the cable host system 2 2 1 Static Mode You can manually assign a static IP address to the WAN interface and complete the configuration by applying the settings and rebooting your router Choosing Static as the IP mode you will see the following page IP Mode Static JO DHCP OPPPoE O PPTP PPPDEPIPETP Configuration Configuration IP Address 172 16 3 229 Host Name Subnet Mask 255 255 255 0 Domain Name Default Gateway 172 16 3 1 Host Name an
199. tus Refresh Option Basic Status WAN1 IP Address MAC Address Primary DNS Secondary DNS Gateway RX Packets TX Packets Connection Status Up Time WANS IP Address MAC Address Primary DNS Secondary DNS Gateway RX Packets TX Packets Connection Status LAN Status No Refresh v Refresh 192 158 1 19 00 00 00 00 00 02 192 168 1 1 192 168 1 1 8794 3302 disconnected 00 00 00 00 00 04 WAN 2 IP Address MAC Address 00 00 00 00 00 03 Primary DNS Secondary DNS Gateway RX Packets TX Packets Connection Status Up Time WANA IP Address MAC Address 00 00 00 00 00 05 Primary DNS Secondary DNS Gateway RX Packets TX Packets Connection Status Up Time Up Time IP Address Display the IP address of the WAN interface MAC Address Display the MAC address of the WAN Interface Primary DNS Display the IP address of the primary DNS Secondary DNS Display the IP address of the secondary DNS Gateway Display the IP address of the default gateway RX Packets Display the total received packets for each WAN interface TX Packets Display the total transmitted packets for each WAN interface Connection Status Display the connection status of the WAN interface Up Time Display the total system uptime of the interface Connect Click this button to make a connection manually Dr ay Tek 26 Vigor3300 Series User s
200. up or down Algorithm Display the algorithm used by this IPSec Remote IP Display remote IP address of the tunnel Remote Subnet Display remote subnet mask of the tunnel Packet In Display the packets count received by this tunnel Byte In Display the bytes count received by this tunnel Packet Out Display the packets count sent out by this tunnel Byte Out Display the bytes count sent out by this tunnel Uptime Display the time duration since the tunnel is established Refresh Allow you to refresh current VPN status Disconnect Allow you to disconnect the select VPN connection 3 6 2 PPTP amp L2TP PPTP General Setup To configure the general setup please click VPN gt gt PPTP amp L2TP gt gt General Setup gt gt PPTP General Setup VPN PPTP General Setup Status 9 Active Inactive PPTP Authentication CHAP PPTP Encryption User Authentication Local O RADIUS Server Mutual Authentication O Enable 9 Disable User Name Password DNS Server 9 Get DNS Server from LAN Setting Get DNS Server by Manual Setting primary DNS Secondary DNS Apply Cancel Status Set the function to Active or Inactive Dr ay Te k 120 Vigor3300 Series User s Guide PPTP Authentication PPTP Encryption User Authentication Enable Disable User Name Password Get DNS Server from LAN Setting Get DNS Server by Manual Setting Primary DNS Seco
201. upport RIP Suppose Vigor3300 A supports RIP on WAN1 WAN2 WAN3 WAN4 Vigor3300 B supports RIP on WANI and WAN2 and Vigor3300 C supports RIP on WAN1 WAN2 WAN3 WAN4 Vigor3300 B will tell 3300 A if you want to send packets to Vigor3300 C please send it to me first then Vigor3300 A will create a routing rule to forward packet that destination is Vigor3300 C to Vigor3300 B In another direction Vigor3300 C will do the same thing Network RIP Configuration O Disable 9 Enable Enabled Interfacers WAN 1 WAN 2 WAN 3 WAN 4 Apply Cancel Enable Disable Disables or enables this function Enabled Interface Check the interface to apply the RIP configuration Apply After finishing the configuration please click this button to invoke these settings 3 2 6 Bandwidth Management This function is used to limit user bandwidth Bandwidth Management Fo General Setup Limit session TL ee ee 2 B Limitation Table Dr ay Te k 56 Vigor3300 Series User s Guide General Setup This function allows users to configure general settings for bandwidth management In the Network group choose Bandwidth Management and then General Setup You will get the following page Network Bandwidth Management General Setup Limit Bandwidth 9 Disable O Enable Default TX limit 1024 Kbps Default RX limit 4024 Kbps Apply Cancel Enable Disable Disables or enables this function Default TX Limit Define the
202. vanced 47 epu VoIP Speed Dial Li Syene Diod Poe Naniser Sure HI Destinations 1 3 a Emmpa 101 10 Sital an 123154174110 Apply Cancel Clem This Page Miscellaneous Other related VoIP settings Suick Setup System Network Advanced Firewall VoIP Miscellaneous PTF Staring P ori IE T 38i Haag P t 49170 T 3 Pecundancy number ange Od liy NAT Trwa Coding Compiehon Trregul 4 se Range 1 4 T7 incomeng Cal Berreg y Ca History ol Toe x a EY FAQ aule disconnection f no packets recep n rimis Range 14 Qn e aule disc enne goi Apply Cancel Tone Settings There are optional built in 14 groups of tone for different regions and a group of tone User Defined can be configured by users Ouikk Setup Pite Network Advanced Firewall Gof WPH 4 40 48 P du Sy Praes Boa Tahiraj VolP Tone Settings t s Seed De E Reancel Speed Da Regan UE w Cais 10 7 Tate Lat sfic ager Low Frauen ys i High Fragen ui i Mso TO ime TONA Pima Dial bar o e PAT Tri Pinging ra E recog Cal Bag b m Cil iio Bug tite a saat Creat n fona Reply Cancel Dr ay Te k 180 Vigor3300 Series User s Guide QoS Enable this function to ensure the quality of VoIP conversation The default value is Enable Guth Setup System MHatwork Advanced Fera val aos VP 44 Te Fo VolP O05 haa Cancel NAT Traversal When the WAN interface of 3300 is a private IP
203. when you press keys on your phone DTMF Relay By default is RFC2833 After configuration click Apply to save the settings Router will auto jump to the VoIP Port Settings page Vigor3300 Series User s Guide 185 Dr ay Te k Dray Tek VoIP Port Settings page Codec FAX Damara Cocke Rah DTMF Li THE Relay Disable i RAFO 10 mir Cali Forwarding Apply Cancel Set Port 2 Port 8 one by one in turn Type Port 1 Port 4 are FXS Port 5 Port 8 are FXO Active Port 1 Port 8 are all active v Enable Group Port 1 Port 8 are Group 1 Group 8 independently Username Phone Number of Port 1 Port 8 Proxy Port 1 2 5 and 6 are registered to iptel Proxy and Port 3 4 7 8 are registered to fwd Proxy Codec Port 1 Port 8 all prior use G 729A 8kbps VoIP Port Settings Prarie Aries Fili ea m m m T Actes TETTE d sied acit P pd Cnuibiec al led Ex Eg fag Enter the VoIP Status page wait one or two minutes The time depends on SIP Server s response speed and the network condition Register Status Display the register information from Port 1 Port 8 OK means this port is registered successfully Call Status Display calling information from Port 1 Port 8 Idle means there is no conversations on Port 1 Port 8 186 Vigor3300 Series User s Guide VolP Status Beber pbon Mo Rimfimakh Retesh Call F Resins FTE Anima Comer Pueckri Ci Tikal Cathey i
204. where H1 and H2 indicate the hours and M1 and M2 represent the minutes Days of Week The URL content filtering facility is active during the specified days of the week The default value is 8 00 to 18 00 from Monday to Friday Warning Page After the configuration of URL Filter is configured properly an alert page will appear in the browser when an HTTP request is denied Refer to the following graphic EE HTIP 420 CF Blocked Mozilla 5 x File Edit View Go Bookmarks Tools Window Help uA 3 Be mwiivwrwhitehowe com ga Search ch D tr Back Home of Bookmarks ag The Mozilla Organization af Latest Builds E The requested Web page is denied by system administrator Please contact with the administrator for further information ES Mozilla Project Imported IE Favorites Dr ay Te k 94 Vigor3300 Series User s Guide 3 4 4 Bind IP to MAC This function is used to bind the IP and MAC address in LAN to have a strengthen control in network When this function is enabled all the assigned IP and MAC address binding together cannot be changed If you modified the binding IP or MAC address it might cause you not access into the Internet Firewall Bind IP to MAC Enable 9 Disable Strict Bind Note If choose Strict Bind all IPs not bind ta MAC cannot gain access to internet ARP Table Select AI Sort Refresh IP Bind List Select All Sort IP Address Hac Address 192 168 1 10 OO 0F
205. word Fort 1 SIF For Domain Proxy Outbound Proxy Pert 1 Register wa Display Name Account Nama Authentic ation ID Password Expiry Time S060 iptel org liptal org WAN fi Hour 55 sec Stun Server Port 2 SIP Por w0 fia puleer com hed puhan com Domain Proxy Outbound Proxy Port 2 Register via eA 2300 Por f beb5 8 jesoses m Display Marne Account Mame Authentication ID Password Expiry Time Log p ce ihour 60 son After configuration please click OK to save the settings 2900V will go to VoIP Setup page automatically 188 Vigor3300 Series User s Guide 2 Click Voice Call Status DialPlan Setup Tone Settings Voice Call Status Wait one or two minutes The time depends on SIP Server s response speed and the network condition Channel R means Port 1 and Port 2 register successfully Status IDLE means there 1s no conversations on Port 1 Port 8 VOIP Connection Status Channel Volume 1 z gt gt Refresh Seconds 10 Refresh View Lag Connact Tx Rx Rx Rx Jitter li Qut Volume Gain Channel Status Codec PeerlD Time Pkt Pits Losts ms Calls Calls D D 0 D 0 5 iR IDLE 2 IDLE i 5 R Means you have registered your SIP sener Now the configuration is completed Vigor3300 Series User s Guide 189 Dr ay Te k 5 2 7 Example 2 Basic Calling Method We w
206. xample for A Company and Guest eeesessssssssesseeeeneeeennnnn nennen nnne nnns 170 ANA 2 cie msmiiisl e ac 172 5 2 Application for VOIP escranca nnne nnne nnne nnn nnn nnn nnn 174 s ESQ E 174 5 2 2 Practical Application of FXS card with PBX sss nennen 177 5 2 3 Practical Application of FXO card with PBX ccccccccsseseeeeeeeeseeeeesaeeeeeeseeaeeeeeesaaaaes 177 NU NOP Ba C eea a E 178 3 2 0 VOIP co C1 Sii TNR 183 5 2 6 Example 1 Basic Configuration and ReQistration ccccccsseseeeeeeeeeeeeeeeeeeeeeeeneaees 183 5 2 7 Example 2 Basic Calling Method essesseeeeeeeeseeeeeeeeennnnneennnnnnn 190 5 2 8 Example 3 VoIP over VPN sessssssessesseeenneeen nennen nenne nnne nnn nnns 197 5 2 9 Example 4 Practical Application of FXS ccccccccccceccseseeeeeeseeeseeesseeeeeesesaaseeeesaeaees 203 5 2 10 Example 5 Practical Application of FXO cccccccccssseeeeeeeeeseeeeeesaeeeeesseaaeseeeesaaaaes 205 Dr ay Te k vi Vigor3300 Series User s Guide T Preface The Vigor3300 Series integrates a rich suite of functions including NAT firewall VPN load balance bandwidth management and VoIP capability These products are very suitable for providing multi integrated solutions to SME markets An application scenario for the Vigor3300 Series
207. y Refresh Register Status Call Type Callee Number Caller Number Remote RTP Remote Address RTP Port DTMF Relay Codec Packet Type Period Call Status Start Time RTP Statistic Idle Idle Idle Idle Idle Idle Idle Idle co T c en c ER ho PS Packets Sent OS Octets Sent PR Packets Received OR Octets Received PL Packets Lost JI Interarrival Jitter Estimateims LA Avg TX Delay ms You can click Refresh to get the latest status information for these VoIP phones In addition you can set the time interval of refreshing Use the drop down list of Refresh Option to choose 144 Vigor3300 Series User s Guide Register Status Call Status Call Type Caller Number Callee Number Start Time Remote RTP Address Remote RTP Port Codec Type Packet Period VAD DTMF Relay Vigor3300 Series User s Guide an automatic refreshing setting If you choose No Refresh the system will not refresh this page until you click Refresh button Ho Refresh Every 10 Seconds Every 20 Seconds Every 30 Seconds The status of registering 1n proxy server The calling status The dialing direction for this call Incoming Outgoing The phone number of the caller The phone number of the receiver The starting time of the call The IP address of the remote voice site The used port number of the remote voice site The Codec mode used for this phone call The period of time for sampling on voice si
208. ype Number Number Start Time End Time Duration Reason Address xL Statistic Type Period VAD Relay PS 275 0S 5500 Fri Sep 23 FriSep 23 0 days PRz143 G 729A 1 5 Incoming 888846 888845 17 01 51 17 02 00 00h aan nas Normal Drop 61 230 213 114 13466 OR 2860 8kbps 20ms Off RFC2833 2005 2005 mE PL 0 uu JIz0 LA 0 PSz143 08 2860 Fri Sep 23 Fri Sep 23 0 days PR 144 G 729A 6 Outgoing 888846 888845 17 01 47 17 02 00 n nmea4s4 Normal Drop 61 230 213 114 13464 OR 2880 4 20ms Off RFC2833 DE 00h 00m 13s 8kbps 2005 2005 PL 0 JIz0 LA 0 Refresh Option You can click Refresh to get the latest status information for these VoIP phones In addition you can set the time interval of refreshing Use the drop down list of Refresh Option to choose an automatic refreshing setting If you choose No Refresh the Dr ay Te k 142 Vigor3300 Series User s Guide Port Number Call Type Caller Number Callee Number Start Time End Time Duration Release Reason Remote RTP Address Remote RTP Port RTP Statistic Codec Type Packet Period VAD DTMF Relay 3 7 11 Tone Upload system will not refresh this page until you click Refresh button Ho Refrezh v Refresh Ho Retresh Every 10 Seconds Every 20 Seconds Every 30 Seconds The port number of VoIP The dialing direction for this call Incoming Outgoing The phone number of the caller The phone number of the receiver The starting time of the call The ending time of the cal
Download Pdf Manuals
Related Search
Related Contents
Capture One DB Online Help Bottom-Mount Refrigerator Refrigerador con congelador en la parte MANUAL DE INSTALACIÓN Y PROGRAMACIÓN KITS MRT3 radio reloj estimado cliente características apariencia y Brother HL-5040 Network Router User Manual Osram DST TWIST 8W/840 E27 Benutzerhandbuch - Professional dictation solutions and voice inviatore di allarme bidirezionale a sintesi vocale mod Copyright © All rights reserved.
Failed to retrieve file