End-of-Sale and End-of-Life Products about:
Anti-Spam iCard/E-iCard (Anti-Spam License)
AV+IDP iCard/E-iCard (Anti-Virus+IDP License)
| Information | Beschreibung | Filename |
|
Firmware for ZyWALL-35 v4.04(WZ.8)
neu Firmware for ZyWALL-35 v4.04(WZ.7) Firmware for ZyWALL-35 v4.04(WZ.6) Modifications in V4.04(WZ.6)b2 | 10/07/2009 1. [FEATURE CHANGE] The registration and/or signature update will not be affected by SSL certificate renewal on the servers – customer can continue to do registration and/or signature update. |
zyw35_v4.04(WZ.8)c0.zip |
|
|
Firmware for ZyWALL-35 v4.04(WZ.5) Firmware for ZyWALL-35 v4.04(WZ.4) Firmware for ZyWALL-35 v4.04(WZ.3) Firmware for ZyWALL-35 v4.04(WZ.2) Firmware for ZyWALL-35 v4.04(WZ.1) How can send "Syslog" and "SMTP" through VPN ? Use following CI-Command to can use this: - ipsec swDevTri on |
zyw35_v4.04(WZ.5)c0.zip |
|
|
Support-Notes_4.03 |
Firmware for ZyWALL-35 v4.03(WZ.1) Firmware for ZyWALL-35 v4.03(WZ.0) - DL/Preview Entsprechend dazu die ZyNOS-News_4.03 |
|
|
Firmware for ZyWALL-35 v4.02(WZ.2) Firmware for ZyWALL-35 v4.02(WZ.1) Firmware for ZyWALL-35 v4.02(WZ.0) |
zyw35_v4.02(WZ.2)c0.zip |
|
|
Firmware for ZyWALL-35 v4.01(WZ.4) Firmware for ZyWALL-35 v4.01(WZ.3) Firmware for ZyWALL-35 v4.01(WZ.2) Firmware for ZyWALL-35 v4.01(WZ.1) Firmware for ZyWALL-35 v4.01(WZ.0) - DL/Preview |
zyw35_v4.01(WZ.4)c0.zip |
|
|
UserGuide_4.00 |
Firmware for ZyWALL-35 v4.00(WZ.11) Firmware for ZyWALL-35 v4.00(WZ.10) Firmware for ZyWALL-35 v4.00(WZ.9) Firmware for ZyWALL-35 v4.00(WZ.8) Firmware for ZyWALL-35 v4.00(WZ.7) Firmware for ZyWALL-35 v4.00(WZ.6) Firmware for ZyWALL-35 v4.00(WZ.5) Firmware for ZyWALL-35 v4.00(WZ.4) - DL/Preview |
zyw35_v4.00(WZ.11)c0.zip |
|
Firmware for ZyWALL-35 v3.64(WZ.5) Firmware for ZyWALL-35 v3.64(WZ.4) Firmware for ZyWALL-35 v3.64(WZ.2) - DL/Preview |
zyw35_v3.64(WZ.5)c0.zip |
| Firmware for ZyWALL-35 v3.63(WZ.3) |
| ZyWALL-35: 4 LAN/DMZ-Ports, 2 WAN-Ports, Wireless-LAN (Optional), 35 VPN, Firewall. |
>>>
Flashen
eines Prestige-Routers per Seriell <<<
>>>
Beispiel-Darstellung zur Einstellung von Safenet-Softremote/RemoteSecurityClient
(RSC) <<<
>>> Beispiel-Darstellung zur Einstellung von
Greenbow/ZyXEL IPSec VPN Client <<<
>>> Beispiel-Darstellung
ICQ Professional hinter NAT <<<
>>>
Beispiel Einrichtung eines ES-2108 für VDSL (T-Home) mit VLAN-ID 7 Tag. <<<
|
Aenderung zum VPN-Verhalten: Multiple VPN Clients which located behind same NAT Router [ENHANCEMENT] |
|
[RFC 2407]The INITIAL-CONTACT(IC) status message may be used when one side
wishes to inform the other that this is the first SA being established
with the remote system. The receiver of this Notification Message might then
elect to delete any existing SA's it has for the sending system under the
assumption that the sending system has rebooted and no longer has access
to the original SA's and their associated keying material.
The ZyWALL has two ways to delete SA when it receives IC, it is switched by
a global option 'ipsec initContactMode gateway/tunnel':
(1)ipsec initContactMode gateway
When the ZyWALL receives a IKE packets with IC, it deletes all tunnels with
the same secure gateway IP. It is default option because the ZyWALL is
site to site VPN device. Take the picture 1 as example, there are three
VPN tunnels are created between ZWA and ZWB, but ZWA reboots for some
reasons, and after rebooting, the ZWA will send a IKE with IC to the ZWB,
then the ZWB will delete all existing tunnels whose security gateway IP is
the same as this IKE's one and build a new VPN tunnel for the sender.
(2)ipsec initContactMode tunnel When the ZyWALL receives a IKE packets with IC, it deletes only one existing tunnel, whose security gateway IP is not only the same as this IKE's one and also its phase 2 ID(network policy) should match. It is suitable when your tunnel is created from a VPN peer to ZyWALL and there are more than two this kind of VPN peers build tunnels behind the same NAT router. Take the picture 2 as example, PC 1, PC2 and PC3 has it's own VPN software to create tunnels with ZW. Suppose that the PC1, PC2 and PC3 separately create different tunnels with ZW for the traffic to PC4, PC5 and PC6, once the PC1 reboots for some reasons, and after rebooting, the PC1 sends a IKE with IC to the ZWB, then the ZWB will only delete the tunnel which is used by PC1 and PC4 and build a new VPN tunnel for it. So other tunnels will not be disconnected.
|
|
Beispiele VPN-Konfiguration ab Firmware v4.xx |
||
|
All Data Through VPN: |
Gateway-Konfiguration Gateway-Konfiguration Gateway-Konfiguration Gateway-Konfiguration VPN Global Setting |
Network-Konfiguration Network-Konfiguration Network-Konfiguration Network-Konfiguration DNS Setting |
|
Aenderung zur VPN-Konfiguration ab Firmware v3.64 gegenueber v3.62/3.63 "Output Idle Timer",
"Input Idle Timer" und "Gateway Domain Name Updade Timer" ggf.
wie folgt einstellen:
VPN-Menu
Global Setting. |
|
DDNS-Update Problem Firmware v3.63 / Work´a´Round Derzeit ist es
scheinbar so, das nach einer 24-Stunden-Zwangstrennung der DDNS-Update nicht
initiiert zu werden scheint. |
Menu 26 - Schedule Setup
Schedule Schedule
Set # Name Set # Name
------ ----------------- ------ -----------------
1 Discon1 7 _______________
2 _______________ 8 _______________
3 _______________ 9 _______________
4 _______________ 10 _______________
5 _______________ 11 _______________
6 _______________ 12 _______________
Enter Schedule Set Number to Configure= 0
Edit Name= N/A
Press ENTER to Confirm or ESC to Cancel:
|
Menu 26.1 Schedule Set Setup
Active= Yes
How Often= Weekly
Start Date(yyyy-mm-dd)= 2007 - 01 - 01
Once:
Date(yyyy-mm-dd)= N/A
Weekdays:
Sunday= Yes
Monday= Yes
Tuesday= Yes
Wednesday= Yes
Thursday= Yes
Friday= Yes
Saturday= Yes
Start Time(hh:mm)= 04 : 55
Duration(hh:mm)= 00 : 02
Action= Forced Down
Press ENTER to Confirm or ESC to Cancel:
|
Menu 11.1 - Remote Node Profile
Rem Node Name= WAN 1 Route= IP
Active= Yes
Encapsulation= PPPoE Edit IP= No
Service Type= Standard Telco Option:
Service Name= Allocated Budget(min)= 0
Outgoing: Period(hr)= 0
My Login= 11111111111122222222222#0+ Schedules= 1
My Password= ******** Nailed-Up Connection= Yes
Retype to Confirm= ********
Authen= CHAP/PAP
Session Options:
Edit Filter Sets= No
Idle Timeout(sec)= N/A
Press ENTER to Confirm or ESC to Cancel:
|