Cisco Unity, Collaboration Without Limitation, EtherFast, EtherSwitch, Event Center, Fast Step, Follow Me Browsing, FormShare, GigaDrive, HomeLink, Internet Quotient, IOS, iPhone, iQuick Study, IronPort, the IronPort logo, LightStream, Linksys, MediaTone, MeetingPlace, MeetingPlace Chime Sound, MGX, Networkers, Networking Academy, Network Registrar, PCNow, PIX, PowerPanels, ProConnect, ScriptShare, SenderBase, SMARTnet, Spectrum Expert, StackWise, The Fastest Way to Increase Your Internet Quotient, TransPath, WebEx, and the WebEx logo are registered trademarks of Cisco Systems, Inc.
Contents About This Document How to Use This Guide Organization Finding Information in PDF Files Finding Text in a PDF Finding Text in Multiple PDF Files Chapter 1: Introduction Chapter 2: Networking and Security Basics An Introduction to LANs The Use of IP Addresses The Intrusion Prevention System (IPS) Chapter 3: Planning Your Virtual Private Network (VPN) Why do I need a VPN?
Page 4
Contents Installing the Router Configuring the Router Chapter 5: Setting Up and Configuring the WRVS4400N Wireless-N Router Accessing the Web-Based Utility Navigating the Utility Setup Wireless Firewall ProtectLink Administration L2 Switch Status Setting Up Your Wireless-N Router Configuring Basic Setup Settings Displaying A Read-Only Summary of the Basic Router Information Configuring Internet Connection Settings Configuring Local Area Network (LAN) Settings...
Page 5
Contents Configuring VLAN & QoS Settings Configuring Router WDS Settings Configuring Firewall Settings Configuring Basic Settings Configuring IP Based ACL Editing IP ACL Rules Configuring Internet Access Policy Configuring Single Port Forwarding Configuring Port Range Forwarding Configuring Port Range Triggering Configuring the ProtectLink Gateway service Configuring the VPN Settings Displaying A VPN Status Summary of the IPSec Tunnel and Clients...
Page 6
Contents Configuring IPS Settings Configuring IPS Setting P2P/IM Policy Viewing Reports Viewing Protection Information Configuring the L2 Switch Settings Configuring Virtual LANs (VLANs) Configuring VLAN Membership and Port Assignment Configuring RADIUS Mode Configuring Port Settings Viewing Statistics Overview Mirroring Ports Configuring RSTP Viewing Status Viewing WAN/Gateway Status...
Page 7
Contents Appendix B: Using Cisco QuickVPN for Windows 2000, XP, or Vista Overview Before You Begin Installing the Cisco QuickVPN Software Installing from the CD-ROM Downloading and Installing from the Internet Using the Cisco QuickVPN Software Distributing Certificates to QuickVPN Users Appendix C: Configuring a Gateway-to-Gateway IPSec Tunnel Introduction Environment...
Page 8
Contents How to Use the Service ProtectLink > Web Protection ProtectLink > Email Protection ProtectLink > License Appendix F: Specifications General Performance Management Security Layer 2 Environmental Appendix G: Where to Go From Here Product Resources Related Documentation Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide viii...
Preface About This Document This guide describes the Cisco Small Business WRVS4400N Wireless-N Gigabit Security Router with VPN device and how to configure it. How to Use This Guide Look for the following items when reading this guide: This exclamation point indicates that caution should be used when performing a CAUTION step or a serious error may occur.
Page 10
Preface Chapter Title Description Chapter 5 Setting Up and Describes how to set up the product Configuring the software. WRVS4400N Wireless- N Router Chapter 6 Using the VPN Setup Describes how to configure a Wizard gateway-to-gateway VPN tunnel between two VPN routers. Appendix A Troubleshooting Provides solutions to problems that...
Preface Finding Information in PDF Files The Cisco WRVS4400N router documents are published as PDF files. The PDF Find/Search tool within Adobe® Reader® lets you find information quickly and easily online. You can perform the following tasks: • Search an individual PDF file. •...
Preface Finding Text in Multiple PDF Files Search window lets you search for terms in multiple PDF files that are stored on your computer or local network. The PDF files do not need to be open. Start Acrobat Professional or Adobe Reader. STEP 1 Find Choose Edit >...
Page 13
Preface d. Click Search. When the Results appear, click + to open a folder, and then click any link to open STEP 4 the file where the search terms appear. For more information about the Find and Search functions, see the Adobe Acrobat online help.
Introduction Thank you for choosing the Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN. The Wireless-N Gigabit Security Router with VPN is an advanced Internet-sharing network solution for your small business needs. WRVS4400N lets multiple computers in your office share an Internet connection through both wired and wireless connections.
Page 15
Introduction NAPT allows you to open specific TCP/UDP port numbers to the Internet to provide limited service while minimizing harmful traffic at the same time. The Virtual Private Network (VPN) capability is another security feature that creates encrypted “tunnels” through the Internet, allowing up to five remote offices and five traveling users to securely connect into your office network from off-site.
Networking and Security Basics This chapter describes networking and security basics. It includes the following sections: • “An Introduction to LANs” on page 16 • “The Use of IP Addresses” on page 17 • “The Intrusion Prevention System (IPS)” on page 19 An Introduction to LANs A router is a network device that connects two networks together.
Networking and Security Basics The Use of IP Addresses The second level router only forwards data packets through a wired network so you don’t have to use the Cisco WRVS4400N Wireless-N Gigabit Security Router. You can use any wired router in the Cisco family such as RVS4000 that has 4 LAN ports and 1 WAN port.
Page 18
Networking and Security Basics The Use of IP Addresses If you use the router to share your cable or DSL Internet connection, contact your ISP to find out if they have assigned a static IP address to your account. If so, you will need that static IP address when configuring the router.
Networking and Security Basics The Intrusion Prevention System (IPS) The Intrusion Prevention System (IPS) IPS is an advanced technology to protect your network from malicious attacks. IPS works together with your SPI Firewall, IP Based Access Control List (ACL), Network Address Port Translation (NAPT), and Virtual Private Network (VPN) to achieve the highest level of security.
Page 20
Networking and Security Basics The Intrusion Prevention System (IPS) Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Planning Your Virtual Private Network (VPN) This chapter provides information for planning your VPN and includes the following sections: • Why do I need a VPN?, page 21 • What is a VPN?, page 23 Why do I need a VPN? Computer networking provides a flexibility not available when using an archaic, paper-based system.
Planning Your Virtual Private Network (VPN) Why do I need a VPN? At this point, your data becomes open to hackers using a variety of methods to steal not only the data you are transmitting but also your network login and security data.
Planning Your Virtual Private Network (VPN) What is a VPN? What is a VPN? A VPN, or Virtual Private Network, is a connection between two endpoints—a VPN router, for instance—in different networks that allows private data to be sent securely over a shared or public network, such as the Internet. This establishes a private network that can send data securely between these two locations or networks.
Planning Your Virtual Private Network (VPN) What is a VPN? VPN Router to VPN Router An example of a VPN router-to-VPN router VPN would be as follows. At home, a telecommuter uses his VPN router for his always-on Internet connection. His router is configured with his office’s VPN settings.
Planning Your Virtual Private Network (VPN) What is a VPN? Computer to VPN Router The following is an example of a computer-to-VPN router VPN. In her hotel room, a traveling businesswoman connects to her ISP. Her notebook computer has the Cisco QuickVPN Client software, which is configured with her office’s IP address.
Getting Started with the WRVS4400N Router This chapter describes the physical features of the WRVS4400N router and provides information for installing the router. The following sections are included: • “Front Panel” on page 27 • “Back Panel” on page 28 •...
Getting Started with the WRVS4400N Router Front Panel Front Panel The LEDs are located on the front panel of the router. Front of Router POWER LED—Lights up green to indicate the router is powered on. The LED flashes when the router is running a diagnostic test. DIAG LED—If this light is off, the system is ready.
Getting Started with the WRVS4400N Router Back Panel Back Panel The Ethernet ports, Internet port, Reset button, and Power port are on the back panel of the router. RESET Button—The Reset button can be used in two ways: • If the router is having problems connecting to the Internet, press the Reset button for just a second with a paper clip or a pencil tip.
Getting Started with the WRVS4400N Router Placement Options Placement Options You can place the router horizontally on the rubber feet, mount it in the stand, or mount it on the wall. Desktop Option For desktop placement, place the Cisco WRVS4400N router horizontally on a surface so it sits on its four rubber feet.
Getting Started with the WRVS4400N Router Placement Options Stand Option To install the router vertically in the supplied stands, follow the steps below. To place the router vertically, follow these steps. Locate the left side panel of the router. STEP 1 With the two large prongs of one of the stands facing outward, insert the short STEP 2 prongs into the little slots in the router and push the stand upward until the stand...
Getting Started with the WRVS4400N Router Placement Options Repeat step 2 with the other stand. STEP 3 Wall Option To mount the Cisco WRVS4400N router on the wall, follow these steps. Determine where you want to mount the router and install two screws (not STEP 1 supplied) that are 2-9/16 in.
Getting Started with the WRVS4400N Router Installing the Router Installing the Router To prepare the router for installation do the following: • Obtain the setup information for your specific type of Internet connection from your Internet Service Provider (ISP). • Power off all of your network hardware, including the router, PCs, and cable modem or DSL modem.
Page 33
Getting Started with the WRVS4400N Router Installing the Router Connect an Ethernet network cable from your cable or DSL modem to the Internet STEP 3 port on the router’s back panel. Power on the cable or DSL modem. STEP 4 Connect the power adapter to the Power port on the router and plug the other end STEP 5 into an electrical outlet.
Getting Started with the WRVS4400N Router Configuring the Router Configuring the Router To configure the WRVS4400N router, plug a PC into the router and launch the web- based configuration utility as follows. Before setting up the router, make sure your PCs are configured to obtain an IP (or NOTE TCP/IP) address automatically from the router.
Page 35
Getting Started with the WRVS4400N Router Configuring the Router • Heartbeat Signal: Heartbeat Signal is used primarily in Australia. Check with your ISP for the necessary setup information. • L2TP: L2TP is used mostly in Europe. Check with your ISP for the necessary setup information.
Setting Up and Configuring the WRVS4400N Wireless-N Router The Wireless-N router works right out of the box with the default settings. However, to change these settings, you can use the router’s web-based configuration utility. You can access the web-based configuration utility via a web browser (such as Microsoft Internet Explorer or Mozilla Firefox) from a computer connected to the same network the router is connected to.
Setting Up and Configuring the WRVS4400N Wireless-N Router Accessing the Web-Based Utility Accessing the Web-Based Utility There are two ways to connect to your wireless router for the first time: • Physically connect your personal computer to one of the four LAN ports on the router.
Setting Up and Configuring the WRVS4400N Wireless-N Router Navigating the Utility Navigating the Utility The web-based utility consists of the following main windows: • Setup • Wireless • Firewall • ProtectLink • • • Administration • • L2 Switch • Status Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Setting Up and Configuring the WRVS4400N Wireless-N Router Navigating the Utility Additional windows branch out from these main windows. The following briefly describes the windows of the utility. Setup This window allows you to configure the router’s basic functionality and set its time through the following windows: •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Navigating the Utility Wireless This window allows you to enter a variety of wireless settings for the built-in access point of the router through the following windows: • Basic Settings—Chooses the wireless network mode (for example, B/G/N- Mixed), SSID, and radio channel.
Setting Up and Configuring the WRVS4400N Wireless-N Router Navigating the Utility ProtectLink This window allows you to check e-mail messages, filter website addresses (URLs), and block potentially malicious websites for the Trend Micro ProtectLink Gateway hosted service, thereby providing security for your network. This window allows you to configure VPN tunnels and accounts to establish a secured channel through the Internet through the following windows: •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Navigating the Utility Administration This window allows you to administer the router through the following windows: • Management—Allows you to alter the router’s password, its access privileges, SNMP settings, and UPnP settings. •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Navigating the Utility L2 Switch This window allows you to configure layer 2 switching features on the 4 port Ethernet switch (LAN ports only) through the following windows: • Create VLAN—Creates a Virtual Local Area Network (VLAN) assignment. •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Setting Up Your Wireless-N Router This section describes how to configure the general settings of your router: • “Configuring Basic Setup Settings” on page 45 • “Displaying A Read-Only Summary of the Basic Router Information” on page 46 •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Configuring Basic Setup Settings You can configure the following basic setup settings: • Click Setup > WAN and select the appropriate Internet connection type according to your ISP if connecting your WAN port to the WAN (DSL or cable modem).
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Displaying A Read-Only Summary of the Basic Router Information The Setup > Summary window displays read-only information about the router. To view the Setup > Summary window, follow these steps: Click Setup >...
Page 47
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • Port Statistics This section displays the following color-coded status information on the router's Ethernet ports: Green—Indicates that the port has a connection. Black (unlit)—Indicates that the port has no connection. •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • Log Setting Status E-mail—If this entry appears in the window, email cannot be sent because you have not specified an outbound SMTP server address. Click E-mail to display the Administration > Log window where you can configure the SMTP mail server.
Page 49
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router If required by your ISP, configure the following settings: STEP 5 • Host Name—Enter the host-name provided by your ISP if you have broadband/cable Internet service and your ISP requires you to use a host- name as network identification.
Page 50
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Automatic Configuration - DHCP Server To have the router automatically get its IP address from your ISP’s DHCP server, leave the connection type at its default setting of Automatic Configuration - DHCP Server.
Page 51
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Static IP To use a permanent IP address to connect to the Internet, select Static IP from the Internet Connection Type drop-down menu and fill in the following settings: •...
Page 52
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router PPPoE If your ISP is DSL-based and uses Point-to-Point Protocol over Ethernet (PPPoE) to establish Internet connections, select PPPoE from the Internet Connection Type drop-down menu to enable it, and do the following: •...
Page 53
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router and the default Redial Period is 30 seconds. Use this option to minimize your Internet connection response time as it is always connected. PPTP In Europe and Israel only, select PPTP from the Internet Connection Type drop- down menu if you wish to use the Point-to-Point Tunneling Protocol (PPTP) service, and enter the following: •...
Page 54
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • Connect on Demand: Max Idle Time—Configure the router to cut the Internet connection after it has been inactive for a specified period of time (Max Idle Time). If your Internet connection has been terminated due to inactivity, Connect on Demand enables the router to automatically re- establish your connection as soon as you attempt to access the Internet again.
Page 55
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Heart Beat Signal In Australia, select Heart Beat Signal from the Internet Connection Type drop- down menu to use this service. Check with your ISP for the necessary setup information, and enter the following: •...
Page 56
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • Keep Alive: Redial period—Select this option, to have the router periodically check your Internet connection. If you are disconnected, then the router automatically reestablishes your connection. To use this option, click the option next to Keep Alive.
Page 57
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • User Name and Password—Enter the user name and password provided by your ISP. • Connect on Demand: Max Idle Time—Configure the router to cut the Internet connection after it has been inactive for a specified period of time (Max Idle Time).
Page 58
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Configuring DDNS Service Settings DDNS lets you assign a fixed host and domain name to a dynamic Internet IP address. It is useful when you are hosting your own website, FTP server, or other server behind the router.
Page 59
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router To configure your router to use TZO.com: STEP 3 a. From the DDNS Service drop-down menu, select TZO.com. b. Configure the TZO.com settings: • E-mail Address, TZO Password, and Domain Name—Enter the E-mail address, password, and domain name of the account you set up with TZO.
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Configuring Local Area Network (LAN) Settings The Setup > LAN Setup window displays the router’s local network settings for the four Ethernet ports. To configure the LAN settings for the router, follow these steps: Click Setup >...
Page 61
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • Server Settings (DHCP)—Unless you already have a DHCP server, it is highly recommended that you leave the router enabled as a DHCP server. To use the router as your network’s DHCP (Dynamic Host Configuration Protocol) server, so that it automatically assigns an IP address to each personal computer on your network, Enable DHCP server.
Page 62
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router WINS—If you have a WINS server, enter that server's IP address in the field. Otherwise, leave this blank. The Windows Internet Naming Service (WINS) performs name resolution function (similar to DNS) in the Windows network environment.
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • DHCPv6—To enable the DHCP v6 feature, select Enable. To disable DHCP v6, select Disable. Lease time—Enter the lease time in minutes. DHCP address range start—Enter the starting DHCP v6 IP address. DHCP address range end—Enter the ending DHCP v6 IP address.
Page 64
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router To configure DMZ Hosting, follow these steps: Click Setup > DMZ STEP 1 Fill in the DMZ Hosting settings: STEP 2 • DMZ Hosting—To allow one local personal computer to be exposed to the Internet for use of a special-purpose service such as Internet gaming and video-conferencing, select Enable.
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Cloning Your Network Adapter’s MAC Address onto Your Router Some ISPs require that you register a MAC address. The Setup > MAC Address Clone window allows the cloning of your personal computer network adapter's MAC address onto the router, instead of you having to call your ISP again to now change the registered MAC address to that of the router.
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Click Save. STEP 3 Configuring the Router’s Advanced Settings The Setup > Advanced Routing window allows you to configure the router’s Operating Mode and settings for Dynamic Routing, Static Routing, and Inter-VLAN routing.
Page 67
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • To select the operating mode in which the router functions: Select Gateway to allow all devices on your LAN to share the same WAN (Internet) IP address, the normal mode of operation—in Gateway mode, the NAT (Network Address Translation) mechanism is enabled.
Page 68
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router c. For RIP Recv Packet Version, choose the version of RIP packets you want to receive from peers (RIPv1 or RIPv2) to match the version supported by other routers on your LAN.
Page 69
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router View the Routing Table if necessary to verify routing. STEP 5 To view the routing table established either through dynamic or static routing methods, click the Show Routing Table button. Enable Inter-VLAN Routing if needed.
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Changing the Router’s Time Settings The Setup > Time window allows you to either define your router’s time manually or automatically through the Time Server. The default is Automatically. To define your router’s time, follow these steps: Click Setup >...
Page 71
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • Set the local time using Network Time Protocol (NTP) Automatically—If you wish to use a Network Time Protocol server to set the time and date, select this option, then complete the following fields. Time Zone—Select the time zone for your location and your setting synchronizes over the Internet with public NTP (Network Time Protocol) Servers.
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Selecting IPv4 Mode or Dual Stack IPv4 And IPv6 Mode The Setup > IP Mode window allows you to choose IP Mode settings for the router. To configure IP Mode settings for the router, follow these steps: Click Setup >...
Page 73
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • 6to4 Tunnel—Allows your IPv6 network to connect to other IPv6 networks via tunnels through IPv4 (per RFC3056). The remote router also needs to support 6to4. Because the tunnel can be automatically formed based on traffic, there is no limit as to how many tunnels you can have.
Page 74
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router Block following sites—Prevent a limited set of 6to4 gateways from establishing tunnels with the router. Up to 20 sites can be configured. Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 75
Setting Up and Configuring the WRVS4400N Wireless-N Router Setting Up Your Wireless-N Router • Static 6to4 DNS entry—Allow users to configure static DNS entry to map hostname to IPv6 address. This provides a convenient way for users to access remote IPv6 hosts. Click Save.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings Configuring Wireless Settings This section describes how to configure the wireless settings of the router: • “Configuring Basic Settings” on page 76 • “Configuring Wireless Security” on page 80 •...
Page 77
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings Configure the basic wireless settings: STEP 2 • Wireless Network Mode—Select one of the following modes. The default is B/G/N-Mixed. B-Only—All the wireless client devices can be connected to the router at Wireless-B data rates with a maximum speed of 11Mbps.
Page 78
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings Disabled—To disable wireless connectivity completely. This might be useful during system maintenance. • Wireless Channel—Select the appropriate channel to be used between your wireless router and your client devices. The default is channel 6. You can also select Auto so that your router selects the channel with the lowest amount of wireless interference while the system is booting up.
Page 79
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • SSID Name—The SSID is the unique name shared between all devices in a wireless network. It is case-sensitive, must not exceed 32 alphanumeric characters, and may be any keyboard character. Make sure this setting is the same for all devices in your wireless network.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings Configuring Wireless Security The Wireless > Wireless Security window allows you to configure the wireless router’s wireless security settings. To change the router’s wireless security settings, follow these steps: Click Wireless >...
Page 81
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings The following section describes the detailed options for each Security Mode. • Disable—To disable wireless security completely, select Disable. Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 82
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • WEP—This security mode is defined in the original IEEE 802. 1 1. This mode is not recommended now due to its weak security protection. Users are urged to migrate to WPA or WPA2. Authentication Type—Choose the 802.
Page 83
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • WPA-Personal (also known as WPA-PSK) Encryption—WPA offers you two encryption methods, TKIP and AES for data encryption. Select the type of algorithm you want to use, TKIP or AES.
Page 84
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • WPA2-Personal Mixed—This security mode supports the transition from WPA-Personal to WPA2-Personal. You can have client devices that use either WPA-Personal or WPA2-Personal. The router automatically chooses the encryption algorithm used by each client device. Encryption—Mixed Mode automatically chooses TKIP or AES for data encryption.
Page 85
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • WPA-Enterprise—This option features WPA used in coordination with a RADIUS server for client authentication. (This should only be used when a RADIUS server is connected to the router.) Encryption—WPA offers you two encryption methods, TKIP and AES for data encryption.
Page 86
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • WPA2-Enterprise—This option features WPA2 used in coordination with a RADIUS server for client authentication. (This should only be used when a RADIUS server is connected to the router.) Encryption—WPA2 always uses AES for data encryption.
Page 87
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • WPA2-Enterprise Mixed—This security mode supports the transition from WPA-Enterprise to WPA2-Enterprise. You can have client devices that use either WPA-Enterprise or WPA2-Enterprise. The wireless router chooses the encryption algorithm used by each client device. Encryption—Mixed Mode automatically chooses TKIP or AES for data encryption.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings Configuring Connection Control The Wireless > Connection Control window displays the Connection Control settings for the router, giving you two ways to control the connection (association) of wireless client devices. You can either prevent specific devices from connecting to the router, or you can allow only specific client devices to connect to the router.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • Connection Control—Prevent or Allow specific MAC addresses access to the Wireless Network. Prevent—Denies connection to the Wireless Network through the router, for the MAC addresses specified below. Allow—Grants connection to the Wireless Network through the router, for the MAC addresses specified below.
Page 90
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings To configure advanced wireless settings for the router, follow these steps: Click Wireless > Advanced Settings. STEP 1 Configure the advanced wireless settings as needed by changing the following STEP 2 advanced parameters (some only for Wireless-N) for this router.
Page 91
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • CTS Protection Mode—CTS (Clear-To-Send) Protection Mode function boosts the router’s ability to catch all wireless transmissions, but severely decrease performance. Keep the default setting, Auto, so the router can use this feature as needed, when the Wireless-N/G products are not able to transmit to the router in an environment with heavy 802.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings Configuring VLAN & QoS Settings The Wireless > VLAN & QoS window displays the QoS and VLAN settings for the router’s Access Point. The QoS (Quality of Service) feature allows you specify priorities for different traffic.
Page 93
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • U-APSD(WMM Power Save)—Select Enabled or Disabled as required. WMM—Wi-Fi Multimedia is a QoS feature defined by WiFi Alliance before IEEE 802. 1 1e was finalized. Now it is part of IEEE 802. 1 1e. When it is enabled, it provides four priority queues for different types of traffic.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings Configuring Router WDS Settings The Wireless > WDS window displays the WDS (Wireless Distribution System) settings for the device. To configure the WDS settings for the router, follow these steps: Click Wireless >...
Page 95
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Wireless Settings • Remote Access Point's MAC Address—Either enter the MAC address directly, or, if the other access point is on-line, you can click the Site Survey button and select from a list of available access points. Click Save.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings Configuring Firewall Settings This section describes how to configure the Firewall settings of the router: • “Configuring Basic Settings” on page 97 • “Configuring IP Based ACL” on page 99 •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings Configuring Basic Settings The Firewall > Basic Settings window displays the firewall-specific settings of the router. To configure basic firewall settings for the router, follow these steps: Click Firewall > Basic Settings. STEP 1 Configure the basic firewall settings: STEP 2...
Page 98
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings • Multicast Pass-through—When enabled, the router allows IP Multicast traffic to come in from the Internet. The default is Disable. • SIP Application Layer Gateway—When enabled, the SIP Application Layer Gateway (ALG) allows Session Initiation Protocol (SIP) packets (used for Voice over IP) to traverse the NAT firewall.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings Configuring IP Based ACL The Firewall > IP Based ACL window displays a summary of the configured IP-based access control list. The access list restricts traffic going through the router either from WAN or LAN port.
Page 100
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings To configure the IP Based ACL for the router, follow these steps: Click Firewall > IP Based ACL. STEP 1 Configure the IP based ACL settings for the router: STEP 2 •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings • Page Selections—Select specific page of ACL list from the drop-down menu to be displayed. Or navigate them page by page through Previous Page and Next Page button. • Add New Rule—Click this button to enter the page to define a new ACL rule.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings • Log—If checked, this ACL rule is logged when a packet match happens. • Log Prefix—This string is attached in front of the log for the matched event. • Source Interface—Select LAN, WAN, or ANY interface.
Page 103
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings To configure Internet access policy for the router, follow these steps: Click Firewall > Internet Access Policy. STEP 1 Configure the router’s Internet access policy settings by creating, modifying, STEP 2 verifying, and deleting policies as appropriate.
Page 104
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings Creating a Policy To create an Internet access policy, follow these steps: Select a policy number from the Internet Access Policy drop-down menu. STEP 1 Enter a Policy Name in the field provided. STEP 2 Enable this policy by clicking the Enable option.
Page 105
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings If you wish to block access to Web sites, use the Website Blocking by URL STEP 7 Address or Website Blocking by Keyword feature. • Website Blocking by URL Address—Enter the URL or domain name of the web sites you wish to block.
Page 106
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings Deleting a Policy To delete a policy, select it from the drop-down menu, then click the Delete button. Viewing all Policies To view a summary of all the policies, click the Summary button. On the Summary window, the policies are listed with the following information: No., Policy Name, Days, Time, and a check box to delete (clear) the policy.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings Configuring Single Port Forwarding The Firewall > Single Port Forwarding window displays the specific port and other settings associated with each public service that uses just a single port. Single Port Forwarding is one of the NAPT features and allows users of the Internet to access this server by using the WAN port address and the matched external port number.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings • Internal Port—Port number used by the router when forwarding Internet traffic to the personal computer or server on your LAN and is usually the same as the External Port number. If it is different, the router performs a Port Translation, so that the port number used by Internet users is different from the port number used by the server or Internet application.
Page 109
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings To configure port range forwarding for the router, follow these steps: Click Firewall > Port Range Forwarding. STEP 1 Configure port range forwarding settings for the router: STEP 2 •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings Configuring Port Range Triggering The Firewall > Port Range Triggering window displays the configurations of triggered range and forwarded range of ports that are used by applications that request ports to be opened on demand. Port Range Triggering is an NAPT (Network Address Port Translation) feature.
Page 111
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring Firewall Settings • Application—Enter the name of the application you wish to configure. • Triggered Range—For each application, list the triggered port number range. These are the ports used by outgoing traffic. Check with the Internet application documentation for the port number(s) needed.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the ProtectLink Gateway service Configuring the ProtectLink Gateway service The Trend Micro ProtectLink Gateway service provides security for your network. It checks email messages, filters website addresses (URLs), and blocks potentially malicious websites.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Configuring the VPN Settings This section describes how to configure the VPN settings of the router: • “Displaying A VPN Status Summary of the IPSec Tunnel and Clients” on page 113 •...
Page 114
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings • Tunnel Status Tunnels(s) Used—Displays the number of tunnels used. Tunnel(s) Available—Displays the number of available tunnels. Detail button—Click Detail to display more tunnel information. No—Displays the number of the tunnel. Name—Displays the name of the tunnel, as defined by the Tunnel Name field on the VPN >...
Page 115
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Tunnel Test—Click Connect to verify the tunnel status; the test result is updated in the Status column. If the tunnel is connected, you can disconnect the IPSec VPN connection by clicking Disconnect. Config—Click Edit to change the tunnel's settings.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Configuring IPSec VPN The VPN > IPSec VPN window displays settings for configuring a VPN tunnel. Virtual Private Network (VPN) is a security measure that creates a secure connection between two remote locations.
Page 117
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Configure the settings in the following sections of the VPN > IPSec VPN window: STEP 3 • “Setting Up Local Groups” on page 118 • “Setting Up and Configuring Remote Groups” on page 119 •...
Page 118
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Setting Up Local Groups The Local Group Setup section of the VPN > IPSec VPN window displays settings for configuring the local groups of VPN tunnel connections. To configure local groups of VPN tunnel connections, do the following: Click VPN >...
Page 119
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Setting Up and Configuring Remote Groups The Remote Group Setup section of the VPN > IPSec VPN window displays settings for configuring the remote groups of VPN tunnel connections. To set up and configure a remote group, follow these steps: Click VPN >...
Page 120
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings IP Only—If you select IP Only, only the specific IP address that you enter can access the tunnel. It's the IP address of the remote VPN router or device which you wish to communicate.
Page 121
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Setting Up IPSec The IPSec Setup section of the VPN > IPSec VPN window displays the security parameters for configuring a VPN. To set up IPSec for the router, follow these steps: Click VPN >...
Page 122
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings • Encryption— The Encryption method determines the length of the key used to encrypt/decrypt ESP packets. 3DES is supported. Notice that both sides of the VPN tunnel must use the same Encryption method. •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Configuring VPN Client Accounts The VPN > VPN Client Accounts window displays the settings for administering your VPN Client users. Enter the information at the top of the window and the users you've entered appear in the list at the bottom, showing their status.
Page 124
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings • Allow User to Change Password—Determines whether the user is allowed to change their password. • VPN Client List Table No—Displays the user number. Active—When checked, the designated user can connect, otherwise the VPN client account is disabled.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the VPN Settings Configuring VPN Passthrough The VPN > VPN Passthrough window displays the settings needed to allow users to have the router pass through the traffic, using their own VPN algorithms to connect to their remote routers.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the QoS Settings • L2TP Passthrough—Layer 2 Tunneling Protocol is the similar to PPP but allows Layer 2 and the PPP session to terminate at different servers or locations. L2TP Passthrough is enabled by default. To disable L2TP Passthrough, select Disabled.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the QoS Settings Managing Bandwidth The QoS > Bandwidth Management window displays the settings for configuring bandwidth management for the router. To configure the bandwidth management settings, follow these steps: Click QoS > Bandwidth Management. STEP 1 Configure bandwidth management settings: STEP 2...
Page 128
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the QoS Settings • Priority Service—Select the service from the drop-down menu. If it does not contain the service you need, click Service Management to add the service. Direction—Select Upstream for outbound traffic or Downstream for inbound traffic from the drop-down menu.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the QoS Settings Configuring QoS The QoS > QoS Setup window displays the settings needed for users to configure QoS Trust Mode for each LAN port. To configure QoS setup window settings for the router, follow these steps: Click QoS >...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the QoS Settings Click Save. STEP 3 Configuring DSCP The QoS > DSCP Setup window displays the settings for configuring DSCP as the trust mode for QoS for each LAN port. To configure DSCP setup settings, follow these steps: Click QoS >...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Click Save. STEP 3 Configuring the Administration Settings This administration window allows you to configure the administration settings of the router: • “Configuring Management Settings” on page 132 •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Configuring Management Settings The Administration > Management window displays the settings for configuring the password and Simple Network Management Protocol (SNMP) for the router. To configure management settings for the router, follow these steps: Click Administration >...
Page 133
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Router Userlist—Select a user to configure from the drop-down menu. Router Username—Enter the user name. Router Password—Enter the password. Re-enter to Confirm—Retype the password in this field. • Access List—This section specifies which source IP addresses can manage the device.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Configuring System Logs The Administration > Log window displays the options for configuring the management of the router’s system logs. The wireless router provides four categories of event logging (Firewall, VPN, System, and ACL). You can configure the router to send the event log to you through e-mail, upload the log to syslog server, or view the log locally on the router.
Page 135
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings To configure System Logs for the router, follow these steps: Click Administration > Log. STEP 1 Configure the system logs for the router: STEP 2 • Log Setting Log Level—Select the log levels that the router should record.
Page 136
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Denial of Service Thresholds—Enter the number of DoS attacks that need to be detected (and blocked) by the software firewall before an e- mail alert is sent. The minimum value is 20, the maximum value is 100. Note that if IPS has been enabled, IPS blocks DoS attacks before they reach the firewall.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Diagnosing Router Problems The Administration > Diagnostics window displays information for configuring test parameters for diagnosing the wireless router using ping tests, traceroute tests, and cable diagnostics. To diagnose router problems, follow these steps: Click Administration >...
Page 138
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Ping Timeout—Enter the desired time period (in milliseconds). If a response is not received within the defined ping period, the ping is considered to have failed. Start Test—Click this button to begin the test. A new window appears and display the test results.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Backing Up and Restoring Configurations The Administration > Backup & Restore window lets you back up and restore router configuration information. To back up or restore administration configurations, follow these steps: Click Administration >...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Restoring Factory Default Settings The Administration > Factory Defaults window provides a means of restoring the configuration of the router to its factory defaults. To restore factory default settings for the router, follow these steps: Click Administration >...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Rebooting the Router The Administration > Reboot window provides means to reboot the router. To reboot the router, follow these steps: Click Administration > Reboot. STEP 1 Click Reboot to reboot the router. STEP 2 This operation does not cause the router to lose any of its stored settings.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the Administration Settings Upgrading the Router Firmware The Administration > Firmware Upgrade window allows you to upgrade router firmware from a downloaded file. To upgrade firmware, download the latest firmware upgrade file for the product from www.cisco.com, extract the file to your computer, and perform these steps: Click Browse to locate the file firmware upgrade.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring IPS Settings Configuring IPS Settings This section describes how to configure the Intrusion Prevention Systems for the router: • “Configuring IPS” on page 143 • “Setting P2P/IM Policy” on page 145 •...
Page 144
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring IPS Settings To configure general IPS settings: Click IPS > Configuration. STEP 1 In the IPS Function field, click Enable. STEP 2 In the Anomaly Detection section, configure the detection settings: STEP 3 •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring IPS Settings Setting P2P/IM Policy The IPS > P2P/IM window allows you to set up policies on using P2P or IM software across the Internet. To configure the P2P/IM policy settings, follow these steps: Click IPS >...
Page 146
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring IPS Settings DIRECTCONNECT PIGO WINMX • Instant Messenger Users might use IM software to chat with friends or transfer files, which can hog the bandwidth. Click Block to enable the blocking to the following IM software applications.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring IPS Settings Viewing Reports The IPS > Report window provides the network history status, including network traffic and attack counts, through diagram and tables. To view IPS reports follow these steps: Click IPS >...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring IPS Settings Viewing Protection Information The Administration > Information window displays information about the types of malicious threat that the router is protected against through its IPS features, the version of the signature pattern files and when the router was last updated. To view protection information, follow these steps: Click Administration >...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings Configuring the L2 Switch Settings This section describes how to configure the Layer 2 Switch settings of the router: • “Configuring Virtual LANs (VLANs)” on page 150 •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings Configuring Virtual LANs (VLANs) The L2 Switch > VLAN window displays the settings for creating and adding a VLAN to the router. VLANs are logical subgroups of a LAN created via software rather than defining a hardware solution.
Page 151
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings To configure Virtual LANS for the router, follow these steps: Click L2 Switch > Create VLAN. STEP 1 Configure Virtual LANS for the router: STEP 2 • VLAN ID—The VLAN ID number.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings Configuring VLAN Membership and Port Assignment The L2 Switch > VLAN & Port Assignment window displays the port settings and VLAN membership settings for configuring VLANs for the router. To configure VLAN membership and port assignments for the router, follow these steps: Click L2 Switch >...
Page 153
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings General—All frames can be tagged or untagged coming in to the switch. If untagged, the default PVID applies to the packet. Only the General mode users can choose the Acceptable Ingress Frame Type and PVID options.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings Configuring RADIUS Mode The L2 Switch > RADIUS window displays the settings for configuring and enabling the RADIUS mode for the router. The RADIUS mode provides authentication on devices connecting to the LAN ports.
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings • Administration State—Select one of the following options from the drop- down menu: Auto—Controlled port state is set by the RADIUS mode. Force Authorized—Controlled port state is set to Force-Authorized (forward traffic).
Page 156
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings To configure L2 switch port settings for the router, follow these steps: Click L2 Switch > Port Settings. STEP 1 Configure L2 switch port settings for the router: STEP 2 •...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings Mirroring Ports The L2 Switch > Port Mirroring window displays the settings for configuring port mirroring for the router. To configure L2 switch port mirroring, follow these steps: Click L2 Switch >...
Setting Up and Configuring the WRVS4400N Wireless-N Router Configuring the L2 Switch Settings Configuring RSTP The L2 Switch > RSTP window displays the settings for configuring Rapid Spanning Tree Protocol (RSTP) for the router. The RSTP protocol prevents loops in the network and dynamically reconfigures the physical links in a switch that should forward frames.
Setting Up and Configuring the WRVS4400N Wireless-N Router Viewing Status • Force Version—The default protocol version to use. Select Normal (uses RSTP) or Compatible (compatible with old STP). The default is Normal. • Protocol Enable—Check this box to enable RSTP on the associated port. The default is unchecked (RSTP disabled).
Setting Up and Configuring the WRVS4400N Wireless-N Router Viewing Status Viewing WAN/Gateway Status The Status > Gateway window displays the WAN / Gateway status of the router, providing some basic information on the router (for example, firmware version, time) and WAN port MAC/IP address and connection status. To view the WAN/Gateway status of the router, follow these steps: Click Status >...
Page 162
Setting Up and Configuring the WRVS4400N Wireless-N Router Viewing Status • Internet Connection Connection Mode—Displays the Internet connection type setting on WAN port. Interface—Displays the WAN port Interface status (Up or Down). IP Address—Displays the WAN port IP address. Subnet Mask—Displays the WAN port IP subnet mask. Default Gateway—Displays the default router to reach Internet or other networks from the WAN port.
Setting Up and Configuring the WRVS4400N Wireless-N Router Viewing Status Viewing Local Network Status The Status > Local Network window displays the LAN status of the router, providing some basic information on the LAN ports of this router. To view local network status, follow these steps: Click Status >...
Page 164
Setting Up and Configuring the WRVS4400N Wireless-N Router Viewing Status • Start IP Address—Displays the beginning of the range of IP addresses used by the DHCP Server. • End IP Address—Displays the end of the range of IP addresses used by the DHCP Server.
Setting Up and Configuring the WRVS4400N Wireless-N Router Viewing Status Viewing Wireless LAN Status The Status > Wireless LAN window displays the status of the wireless LAN of the router, providing some basic information on the Wireless LAN. To view the wireless LAN status for the router, follow these steps: Click Status >...
Setting Up and Configuring the WRVS4400N Wireless-N Router Viewing Status • Security—Displays the Wireless Security mode. • SSID Broadcast—Displays the setting on SSID Broadcast. Viewing System Performance The Status > System Performance window displays system performance of the router, such as data packet statistics on the LAN switch and Wireless LAN of the router.
Page 167
Setting Up and Configuring the WRVS4400N Wireless-N Router Viewing Status • Error Packets Received—Shows the number of error packets received. • Drop Received Packets—Shows the number of packets being dropped after they were received. The All LAN ports column shows the aggregate traffic statistics from all four LAN ports.
Using the VPN Setup Wizard This chapter describes using the VPN Setup Wizard and includes these sections: • VPN Setup Wizard, page 168 • Before You Begin, page 168 • Running the VPN Router Software Wizard, page 169 VPN Setup Wizard Now you can configure a gateway-to-gateway VPN tunnel between two VPN routers in a fast and efficient way by using the VPN Setup Wizard.
Using the VPN Setup Wizard Running the VPN Router Software Wizard Click Firewall > Basic Settings. STEP 1 Enable Remote Management and enter 8080 in the Port field. Please note that you STEP 2 cannot enter any other value if you want to use the VPN Wizard. Also, make sure that HTTPS has been selected.
Page 170
Using the VPN Setup Wizard Running the VPN Router Software Wizard Welcome Window An informational window discussing the VPN Wizard appears. When you are STEP 4 ready, click Next to proceed. Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 171
Using the VPN Setup Wizard Running the VPN Router Software Wizard Informational Window The Choose a way to build VPN window appears. STEP 5 • If your PC is local to one of the two routers, choose Build VPN connection from Local LAN port of one router, click Next, and continue with these instructions.
Page 172
Using the VPN Setup Wizard Running the VPN Router Software Wizard Build VPN Connection Remotely If you picked Build VPN connection from Local LAN port of one router, enter the STEP 6 required data in the Configure VPN Tunnel window and click Next to continue. Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 173
Using the VPN Setup Wizard Running the VPN Router Software Wizard Configure VPN Tunnel • Router 1 User Name: Enter the user name of the Router 1. • Router 1 Password: Enter the password of the Router 1. • Router 2 User Name: Enter the user name of the Router 2. •...
Page 174
Using the VPN Setup Wizard Running the VPN Router Software Wizard Check Router Configuration The Summary window appears. Use the Click box to view the VPNC Summary STEP 8 window. Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 175
Using the VPN Setup Wizard Running the VPN Router Software Wizard Summary Window The VPNC Summary window appears showing the settings that were made to STEP 9 industry standards. Click Close when you are ready to continue. VPNC Summary Window In the Summary window, if all your entries appear correct, click Go.
Page 176
Using the VPN Setup Wizard Running the VPN Router Software Wizard Configure the Router Click Testing to make sure the connection is successfully established. STEP 11 Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 177
Using the VPN Setup Wizard Running the VPN Router Software Wizard Test the Connection When testing is done, click Exit to end the Wizard. STEP 12 Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Using the VPN Setup Wizard Running the VPN Router Software Wizard Exit the Wizard Congratulations! Setup is now complete. You may now log into the Web Administrator Interface and see the results. Test Results Building Your VPN Connection Remotely This procedure continues from Step 5 on page 171.
Page 179
Using the VPN Setup Wizard Running the VPN Router Software Wizard Choose Build VPN connection from Internet remotely. Click Next to continue. STEP 1 Build VPN Connection Remotely Enter the required data in the Configure VPN Tunnel window and then click Next to STEP 2 continue.
Page 180
Using the VPN Setup Wizard Running the VPN Router Software Wizard Configure VPN Tunnel Window • Router 1 User Name: Enter the user name of the Router 1. • Router 1 Password: Enter the password of the Router 1. • Router 2 User Name: Enter the user name of the Router 2.
Page 181
Using the VPN Setup Wizard Running the VPN Router Software Wizard The router configuration is checked. STEP 3 Check Router Configuration The Summary window appears. Use the Click box to view the VPNC Summary STEP 4 window. Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 182
Using the VPN Setup Wizard Running the VPN Router Software Wizard Summary Window The VPNC Summary window appears showing the settings that were made to STEP 5 industry standards. Click Close when you are ready to continue. VPNC Summary Window In the Summary window, if all your entries appear correct, click Go.
Page 183
Using the VPN Setup Wizard Running the VPN Router Software Wizard Configure the Router Click Testing to make sure the connection is successfully established. STEP 7 Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 184
Using the VPN Setup Wizard Running the VPN Router Software Wizard Test the Connection When testing is done, click Exit to end the Wizard. STEP 8 Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 185
Using the VPN Setup Wizard Running the VPN Router Software Wizard Congratulations! Setup is now complete. You may now log into the Web Administrator Interface and see the results. View Test Results Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Troubleshooting This appendix provides solutions to problems that may occur during the installation and operation of the router. Read the descriptions below to help solve your problems. If you can’t find an answer here, check the Cisco website at www.cisco.com. I need to set a static IP address on a PC.
Page 187
Troubleshooting Select Use the following DNS server addresses, and enter the Preferred DNS STEP 7 server and Alternative DNS server (provided by your ISP). Contact your ISP or go on its website to find the information. Click OK in the Internet Protocol (TCP/IP) Properties window, and click OK in the STEP 8 Local Area Connection Properties window.
Page 188
Troubleshooting I want to test my Internet connection. Check your TCP/IP settings. STEP 1 Windows 2000 a. Click Start, Settings, and Control Panel. Double-click Network and Dial-Up Connections. b. Right-click the Local Area Connection that is associated with the Ethernet adapter you are using, and click Properties.
Page 189
Troubleshooting At the command prompt, type ping 192.168.1.1 and press Enter. STEP 3 • If you get a reply, the computer is communicating with the router. • If you do NOT get a reply, check the cable, and make sure Obtain an IP address automatically is selected in the TCP/IP settings for your Ethernet adapter.
Page 190
Troubleshooting Make sure the cable connecting from your cable or DSL modem is connected to STEP 5 the router’s Internet port. Verify that the Status page of the router’s web-based utility shows a valid IP address from your ISP. Turn off the computer, router, and cable/DSL modem. Wait 30 seconds, and then STEP 6 turn on the router, cable/DSL modem, and computer.
Page 191
Troubleshooting Change the router’s IP address through the Setup menu of the web-based utility. If you assigned a static IP address to any computer or network device on the network, you need to change its IP address accordingly to 192. 1 68.2.Y (Y being any number from 1 to 254).
Page 192
Troubleshooting I can’t get an Internet game, server, or application to work. If you are having difficulties getting any Internet game, server, or application to function properly, consider exposing one PC to the Internet using DeMilitarized Zone (DMZ) hosting. This option is available when an application requires too many ports or when you are not sure which port services to use.
Page 193
Troubleshooting Enter the IP Address of the server that you want the Internet users to access. For STEP 3 example, if the web server’s Ethernet adapter IP address is 192. 1 68. 1 . 1 00, you would enter 100 in the field provided. Then check the Enable checkbox for the entry.
Page 194
Troubleshooting I am a PPPoE user and I need to remove the proxy settings or the dial-up pop-up window. If you have proxy settings, you need to disable these on your computer. Because the router is the gateway for the Internet connection, the computer does not need any proxy settings to gain access.
Page 195
Troubleshooting I need to upgrade the firmware. In order to upgrade the firmware with the latest features, you need to go to the Cisco website and download the latest firmware. For the firmware download link, Appendix G, “Where to Go From Here.” Follow these steps: Go to the Cisco website and download the latest firmware.
Page 196
Troubleshooting My DSL service’s PPPoE is always disconnecting. PPPoE is not actually a dedicated or always-on connection. The DSL ISP can disconnect the service after a period of inactivity, just like a normal phone dial-up connection to the Internet. There is a setup option to “keep alive” the connection. This may not always work, so you may need to re-establish connection periodically.
Page 197
Troubleshooting I need to use port triggering. Port triggering looks at the outgoing port services used and will trigger the router to open a specific port, depending on which port an Internet application uses. Follow these steps: To connect to the router, go to the web browser, and enter http://192.168.1.1 or STEP 1 the IP address of the router.
Page 198
Troubleshooting When I enter a URL or IP address, I get a time-out error or am prompted to retry. • Check if other PCs work. If they do, ensure that your workstation’s IP settings are correct (IP Address, Subnet Mask, Default Gateway, and DNS). Restart the computer that is having a problem.
Troubleshooting Frequently Asked Questions Frequently Asked Questions Q. What is the maximum number of IP addresses that the router will support? The router will support up to 253 IP addresses. Q. Is IPSec Passthrough supported by the router? Yes, enable or disable IPSec Passthrough on the VPN > VPN Pass Through window.
Page 200
Troubleshooting Frequently Asked Questions Q. I set up an Unreal Tournament Server, but others on the LAN cannot join. What do I need to do? If you have a dedicated Unreal Tournament server running, you need to create a static IP for each of the LAN computers and forward ports 7777, 7778, 7779, 7780, 7781, and 27900 to the IP address of the server.
Page 201
Troubleshooting Frequently Asked Questions Q. If all else fails in the installation, what can I do? Reset the router by holding down the Reset button for ten seconds. Reset your cable or DSL modem by powering the unit off and then on. Obtain and flash the latest firmware release that is readily available on the Cisco website at www.cisco.com.
Page 202
Troubleshooting Frequently Asked Questions Q. Does the router pass PPTP packets or actively route PPTP sessions? The router allows PPTP packets to pass through. Q. Is the router cross-platform compatible? Any platform that supports Ethernet and TCP/IP is compatible with the router. Q.
Using Cisco QuickVPN for Windows 2000, XP, or Vista Overview This appendix explains how to install and use the Cisco QuickVPN software that can be downloaded from www.cisco.com. QuickVPN works with computers running Windows 2000, XP, or Vista. (Computers using other operating systems will have to use third-party VPN software.) For Windows Vista, QuickVPN Client version 1.2.5 or later is required.
Using Cisco QuickVPN for Windows 2000, XP, or Vista Before You Begin Before You Begin The QuickVPN program only works with a Cisco 4-Port Gigabit Security Router with VPN that is properly configured to accept a QuickVPN connection. Follow these instructions to configure the router’s VPN client settings: Click VPN >...
Using Cisco QuickVPN for Windows 2000, XP, or Vista Installing the Cisco QuickVPN Software Installing the Cisco QuickVPN Software Installing from the CD-ROM Insert the WRVS4400N CD-ROM into your CD-ROM drive. Go to the Start menu STEP 1 and then click Run. In the field provided, enter D:\VPN_Client.exe (if “D” is the letter of your CD-ROM drive).
Page 206
Using Cisco QuickVPN for Windows 2000, XP, or Vista Installing the Cisco QuickVPN Software Copying Files Finished Installing Files Click Finished to complete the installation. Proceed to “Using the Cisco STEP 3 QuickVPN Software,” on page 207. Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Using Cisco QuickVPN for Windows 2000, XP, or Vista Using the Cisco QuickVPN Software Downloading and Installing from the Internet Go to firmware download link in Appendix G, “Where to Go From Here.” STEP 1 From the firmware download link, click Download Software. STEP 2 Select Cisco Small Business Routers >...
Page 208
Using Cisco QuickVPN for Windows 2000, XP, or Vista Using the Cisco QuickVPN Software c. In the Server Address field, enter the IP address or domain name of the Cisco 4-Port Gigabit Security Router with VPN. d. In the Port For QuickVPN field, enter the port number that the QuickVPN client will use to communicate with the remote VPN router, or keep the default setting, Auto.
Page 209
Using Cisco QuickVPN for Windows 2000, XP, or Vista Using the Cisco QuickVPN Software QuickVPN Status To terminate the VPN tunnel, click Disconnect. To change your password, click Change Password. For information, click Help. If you clicked Change Password and have permission to change your own STEP 5 password, you will see the Connect Virtual Private Connection window.
Using Cisco QuickVPN for Windows 2000, XP, or Vista Distributing Certificates to QuickVPN Users You can change your password only if you have been granted that privilege NOTE by your system administrator. Distributing Certificates to QuickVPN Users The following explains how to export a certificate from the WRVS4400N for distribution to QuickVPN users, as well as how to install the certificate on the QuickVPN users’...
Configuring a Gateway-to-Gateway IPSec Tunnel This appendix describes configuring IPSec with a computer that is using Windows 2000 or Windows XP. It includes the following sections: • “Introduction” on page 211 • “Environment” on page 212 Introduction This appendix explains how to configure an IPSec VPN tunnel between two VPN routers by example.
Configuring a Gateway-to-Gateway IPSec Tunnel Environment Environment The following is a list of equipment you need: • Two Windows desktop PCs (each PC connects to a VPN Router) • Two VPN routers that are both connected to the Internet Configuring the VPN Settings for the VPN Routers •...
Configuring a Gateway-to-Gateway IPSec Tunnel Configuring the VPN Settings for the VPN Routers For the Remote Secure Group, select Subnet. Enter VPN Router 2’s local network STEP 8 settings in the IP Address and Mask fields. Note that the subnet of Router 2 must be different than the subnet of Router 1.
Configuring a Gateway-to-Gateway IPSec Tunnel Configuring the Key Management Settings Configuring the Key Management Settings • “Configuring the Key Management Settings for VPN Router 1” on page • “Configuring the Key Management Settings for VPN Router 2” on page Configuring the Key Management Settings for VPN Router 1 Following these instructions for VPN Router 1.
Configuring a Gateway-to-Gateway IPSec Tunnel Configuring PC 1 and PC 2 Configuring the Key Management Settings for VPN Router 2 For VPN Router 2, follow the same instructions as you did for configuring VPN Router 1. Configuring PC 1 and PC 2 Set PC 1 and PC 2 to be DHCP clients (refer to Windows Help for more STEP 1 information).
Finding Out MAC and IP Addresses This appendix describes how to find the MAC address for your computer’s Ethernet adapter so you can use the MAC address cloning feature of the router. You can also find the IP address of your computer’s Ethernet adapter. This IP address is used for the router’s filtering, forwarding, and/or DMZ features.
Finding Out MAC and IP Addresses Windows 2000 or XP Instructions Windows 2000 or XP Instructions Click Start and Run. In the Open field, enter cmd. Press the Enter key or click the STEP 1 OK button. At the command prompt, enter ipconfig /all. Then press the Enter key. STEP 2 Write down the Physical Address as shown on your computer screen.
Trend Micro ProtectLink Gateway Service Overview The optional Trend Micro ProtectLink Gateway service provides security for your network. It scans e-mail messages, filters website addresses (URLs), and blocks potentially malicious websites. ProtectLink is available for online purchase through online resellers such as CDW.com and PCConnection.com. This appendix explains how to use this service and includes the following sections: •...
Trend Micro ProtectLink Gateway Service How to Purchase, Register, or Activate the Service If the Remote Management feature on the Firewall > General window has NOTE been enabled, then users with administrative privileges can remotely access the web-based utility. Use http://<WAN IP address of the router>, or use https://<WAN IP address of the router>...
Page 220
Trend Micro ProtectLink Gateway Service How to Purchase, Register, or Activate the Service If the ProtectLink menu is not displayed, upgrade the router’s firmware. For NOTE the firmware download link, see Appendix G, “Where to Go From Here.” ProtectLink (Inactive) Follow the instructions for the appropriate option: •...
Page 221
Trend Micro ProtectLink Gateway Service How to Purchase, Register, or Activate the Service To have your e-mail checked, you will need to provide the domain name and NOTE IP address of your e-mail server. If you do not know this information, contact your ISP.
Trend Micro ProtectLink Gateway Service How to Use the Service How to Use the Service Configure the service to protect your network. You need to purchase a ProtectLink Gateway license to use the Web Protection NOTE and Email Protection features. If you do not have a license, you will be prompted to purchase a license when you click ProtectLink >...
Page 223
Trend Micro ProtectLink Gateway Service How to Use the Service ProtectLink > Web Protection Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...
Page 224
Trend Micro ProtectLink Gateway Service How to Use the Service Web Protection Enable URL Filtering To filter website addresses (URLs), select this option. Enable Web Reputation To block potentially malicious websites, select this option. URL Filtering Reset Counter The router counts the number of attempted visits to a restricted URL.
Page 225
Trend Micro ProtectLink Gateway Service How to Use the Service Approved URLs You can designate up to 20 trusted URLs that will always be accessible. Enable Approved URL list To set up a list of always accessible URLs, select this option.
Trend Micro ProtectLink Gateway Service How to Use the Service ProtectLink > Email Protection The Email Protection features are provided by an online service called IMHS, which stands for InterScan™ Messaging Hosted Security. It checks your e-mail messages so spam, viruses, and inappropriate content are filtered out. After you have configured the IMHS settings, your e-mail messages will be checked online before appropriate messages are forwarded to your network.
Page 227
Trend Micro ProtectLink Gateway Service How to Use the Service For example, if you provide the information needed for Email Protection one NOTE month after receiving the activation code for Web Protection, then you will receive only 11 months of Email Protection. On the License window, license information is displayed.
Specifications Layer 2 Layer 2 VLAN Support Port-based and 802. 1 Q Tag-based VLANs Number of VLANs 4 active VLANs (4094 range) SSID Broadcast SSID Broadcast Enable/Disable Multiple SSID Supports Multiple BSSIDs up to 4 Wireless VLAN Map Supports SSID to VLAN Mapping with Wireless Client Isolation Allow Wireless Signals to be Repeated by up to 2 Compatible Repeaters...
Where to Go From Here Cisco provides a wide range of resources to help you and your customer obtain the full benefits of the Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN. Product Resources Resource Location Technical http://www.cisco.com/en/US/products/ps9923/ Documentation tsd_products_support_series_home.html Firmware www.cisco.com/en/US/products/ps9923/index.html Downloads...
Where to Go From Here Related Documentation Cisco Small For hardware setup for the Cisco WRVS4400N router, see the Business Model WRVS4400N Wireless-N Gigabit Security Router with VPN Quick Start Guide For compliance and safety information, see the Regulatory Compliance and Safety Information for the Cisco Wired and Wireless Routers and Access Point Devices (EMC Class B Devices) Cisco WRVS4400N Wireless-N Gigabit Security Router with VPN Administration Guide...