Summary of the content on the page No. 1
®
Instant Broadband Series
®
EtherFast Cable/DSL Firewall
Router with 4-Port
Switch/VPN Endpoint
Use this guide to install:
BEFSX41
User Guide
Summary of the content on the page No. 2
COPYRIGHT & TRADEMARKS EC Declaration of Conformity (Europe) Specifications are subject to change without notice. Copyright © 2003 Linksys, All Rights Reserved. EtherFast, Instant Broadband, Linksys, and the Linksys logo are registered In compliance with the EMC Directive 89/336/EEC, Low Voltage Directive 73/23/EEC, and trademarks of Linksys Group, Inc. Microsoft, Windows, and the Windows logo are reg- Amendment Directive 93/68/EEC, this product meets the requirements of the following istered
Summary of the content on the page No. 3
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Table of Contents Chapter 1: Introduction 1 VPN 38 The Linksys EtherFast Cable/DSL Firewall Router with Password 51 4-Port Switch/VPN Endpoint 1 Status 53 Features 1 DHCP 55 An Introduction to LANs and WANs 2Log 57 IP Addresses 2Help 59 Network Setup Overview 4Advanced 60 Filters 61 Chapter 2: Your Virtual Private Network (VPN) 5 Forwarding 65 Why Do I Need a VPN? 5 Dynamic Routing 70 What is a Virtu
Summary of the content on the page No. 4
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Chapter 1: Introduction The Linksys EtherFast Cable/DSL Firewall Router with ® The Linksys EtherFast Cable/DSL Router Appendix F: Installing the TCP/IP Protocol 120 4-Port Switch/VPN Endpoint The Linksys Instant Broadband EtherFast Cable/DSL Firewall Router with 4- Appendix G: Finding the MAC Address and IP Port Switch/VPN Endpoint is the perfect solution for connecting a small group Address for You
Summary of the content on the page No. 5
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Note: Since the Router is a device that connects two networks, it An Introduction to LANs and WANs needs two IP addresses—one for the LAN side, and one for the WAN Simply put, a router is a network device that connects two networks together. side. In this User Guide, you’ll see references to the “WAN IP address” and the “LAN IP address.” In this instance, the Router connects your Local Area Network
Summary of the content on the page No. 6
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint By default, a DHCP server (LAN side) is enabled on the Router. If you already Chapter 2: Your Virtual Private have a DHCP server running on your network, you must disable one of the two DHCP servers. If you run more than one DHCP server on your network, you will experience network errors, such as conflicting IP addresses. To disable Network (VPN) DHCP on the Router, see the DHCP section in “Chapte
Summary of the content on the page No. 7
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 2) Data Sniffing There are two basic ways to create a VPN connection: Firewall Router to Firewall Router Data “sniffing” is a method used by hackers to obtain network data as it trav- Computer (using VPN client software that supports IPSec) to Firewall els through unsecured networks, such as the Internet. Tools for just this kind of Router activity, such as protocol analyzers and network diagnos
Summary of the content on the page No. 8
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Important: You must have at least one Firewall Router on one end of Chapter 3: Getting to Know the the VPN tunnel. At the other end of the VPN tunnel, you must have a second Firewall Router or a computer with VPN client software that supports IPSec. EtherFast Cable/DSL Firewall Router The Router’s Back Panel Computer (using VPN client software that supports IPSec) to Firewall The Router’s ports, show
Summary of the content on the page No. 9
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint * The Reset Button WAN and LAN LEDs Briefly pressing the Reset Button will refresh the Cable/DSL Firewall Router’s Link/Act Green. The Link/Act LED serves two purposes. If the LED is con- connections, potentially clearing any jammed links. tinuously lit, the Router is successfully connected to a device through the corresponding port (1, 2, 3 or 4/DMZ). If the LED is Pressing the Reset Button and hol
Summary of the content on the page No. 10
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Repeat the above step to connect Chapter 4: Connect the Router more PCs or network devices to the Router. Overview Unlike a hub or a switch, the Router’s setup consists of more than simply plug- ging hardware together. You will have to configure your networked PCs to Figure 4-2 accept the IP addresses that the Router assigns them (if applicable), and you will also have to configure the Router with
Summary of the content on the page No. 11
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Configuring Windows 95, 98, and Millennium PCs Chapter 5: Configure the PCs 1. Go to the Network screen by clicking the Start button. Click Settings and Overview then Control Panel. From there, double-click the Network icon. The instructions in this chapter will help you configure each of your comput- 2. On the Configuration tab, shown in Figure 5-1, select the TCP/IP line for ers to be able to commu
Summary of the content on the page No. 12
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 3. Click the IP Address tab and select Obtain an IP address automatically, Configuring Windows 2000 PCs as shown in Figure 5-2. 1. Go to the Network screen by clicking the Start button. Click Settings and then Control Panel. From there, double-click the Network and Dial-up Connections icon. 2. Select the Local Area Connection icon for the applicable Ethernet adapter (usually it is the first Local Ar
Summary of the content on the page No. 13
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 3. Select Internet Protocol (TCP/IP), shown in Figure 5-4, and click the Configuring Windows XP PCs Properties button. The following instructions assume you are running Windows XP with the default interface. If you are using the Classic interface (where the icons and menus look like previous Windows versions), please follow the instructions for Windows 2000. 1. Click to the Network screen by clicking
Summary of the content on the page No. 14
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 3. Select Internet Protocol (TCP/IP), as shown in Figure 5-7, and click the Chapter 6: Configure the Router Properties button. This chapter will show you how to configure the Router to function in your net- work and gain access to the Internet through your Internet Service Provider (ISP). Detailed description of the Router’s Web-based Utility can be found in “Chapter 7: The Cable/DSL Firewall Router’
Summary of the content on the page No. 15
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 3. The Router configuration screen will appear with the Setup tab selected. Obtain an IP Address Automatically Based on the setup instructions from your ISP, you may need to provide the following information. If your ISP says that you are connecting through DHCP or a Host Name and Domain Name: These fields allow you to provide a host dynamic IPaddress from your name and domain name for the Router. T
Summary of the content on the page No. 16
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint PPPoE PPTP If your DSL provider says that PPTP is a service used in Europe you are connecting through only. (Shown in Figure 6-8.) If PPPoE or if you normally enter you are using a PPTP connec- a user name and password to tion, check with your ISP for the access the Internet, perform necessary setup information. these steps: When you are finished with the A. Select PPPoE as the WAN Setup tab, proceed
Summary of the content on the page No. 17
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 5. If you haven’t already done so, click the Apply button and then the Chapter 7: The Cable/DSL Firewall Continue button to save your Setup settings. Close the web browser. 6. Reset the power on your cable or DSL modem. Router’s Web-based Utility 7. Restart your computers so that they can obtain the Router’s new settings. Overview If you need advanced setting information, please refer to “Chapter 7:
Summary of the content on the page No. 18
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint An Enter Network Password window, shown in Figure 7-2, will appear Device IP Address and Subnet Mask The values for the Router’s IP (Windows XP users will see a Connect to 192.168.1.1 window, shown in Figure Address and Subnet Mask are shown here. The default values are 7-3). Leave the User Name field blank, and enter admin in the Password field. 192.168.1.1 for the Device IP Address and 255.255.25
Summary of the content on the page No. 19
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Static IP PPPoE If you are Some DSL-based required to use ISPs use PPPoE a permanent IP (Point-to-Point address, then Protocol over select Static Ethernet) to establish IP, as shown in Internet connections Figure 7-5. for end-users. If you are connected to the Internet through a DSL line, check with your ISP to see if they use PPPoE. If they do, select the PPPoE connection Figure 7-6 type, as shown i
Summary of the content on the page No. 20
® ® Instant Broadband Series EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint RAS PPTP Point to Point Remote Access Tunneling Protocol Service (RAS) is a (PPTP) is a service service that applies to that applies to connec- connections in tions in Europe only. Singapore only Figure 7-8 shows a (shown in Figure 7- PPTP setup. 7). For users in Singapore, check with Singtel for Specify WANIP Address This is the IP information on RAS. address that the Router has, when seen from the