. LRT214/LRT224 Linksys’s VPN Routers for Small Business, LRT214 Gigabit VPN Router and LRT224 Dual WAN Gigabit VPN Router, support site-to-site VPN, which allows branch offices to connect with the central office, and client-to-site VPN, which allows employees to securely connect back to their offices while they are away .
Dual WAN settings, such as link failover or load balance, will be disabled when you configure the port as DMZ port . LRT214 LAN (1~4):Use the LAN ports to connect devices such as switching hubs, In this chapter we are going to introduce hardware interface as well as computers, printer servers, etc ., to the local network or intranet .
Off: Designated VPN tunnel down router on the wall, please ensure that the heat dissipation holes are facing Amber On: 10/100M link sideways as shown in the following picture for safety reasons . Linksys is not Amber Blinking: 10/100M activity Green/ Amber...
Linksys Getting Started with the Router Configuration Getting Started with the Router Configuration Follow the instructions to configure your router . Be sure your computer is connected to a LAN port on the router and set to receive an automatic IP address from the DHCP server .
Linksys Getting Started with the Router Configuration System Information This section includes the following information: Serial number of this router . • Serial Number: • Firmware Version: Current firmware version . Model name of the router . • Model Number: •...
Linksys Getting Started with the Router Configuration 10Base-T / 100 Base-TX / 1000 Base-TX . WAN IP address . Type: IP Address: Interface: LAN/WAN/DMZ . Default Gateway: Default gateway IP address . Up or down . IP address of the DNS server .
Linksys Getting Started with the Router Configuration Firewall Settings Log Setting Status This section displays the following information: This section displays the current firewall settings: Syslog Server: Indicates whether Syslog server is activated . SPI (Stateful Packet Inspection): Default configuration is On .
Page 11
Linksys Getting Started with the Router Configuration Quick Start (Setup Wizard) Click the Quick Start tab to access Basic Setup Wizard . The setup wizard will help you set up your network easily and finish basic network settings . Basic Setup Click Launch Now to run the Basic Setup Wizard .
Linksys Setup Network LAN Setting (Device IP address and subnets) Go to the Configuration > Setup > Network page to set up your LAN, WAN (Internet connections), and DMZ interface . NOTE Remember to click Save to save your settings before leaving the page .
Linksys Setup WAN Setting NOTE: A pop-up confirmation message will appear to remind you to log NOTE: in to the user Web GUI with the new device IP address . Click OK to Remember to click Save before leaving the page . You can also click confirm the change, or click Cancel to leave without applying the Cancel to undo the changes .
Page 15
Linksys Setup Obtain an Automatic IP automatically: Static IP: This mode is often used in the connection mode to obtain an automatic DHCP If an ISP issues a static IP (such as one IP or eight IP addresses, etc .), please select IP .
Page 16
Linksys Setup PPPoE: PPTP: This option is for an ADSL virtual dial-up connection (suitable for ADSL PPPoE) . The IP address to be configured could be one Specify WAN IP Address: issued by your ISP . (The IP address is usually provided by the ISP when the PC is installed .
Linksys Setup Transparent Bridge: DMZ Setting For some network environments, an independent configurable DMZ port The feature will come in handy in when a company wants to add a firewall or dual-WAN device without changing the IP addresses of the computers in its may be required to set up externally connected servers such as WEB and Mail intranet .
Linksys Setup Setting Password Range: If the DMZ and WAN are within same subnet: Use the Configuration > Setup > Password page to change the administrator username and password . It is strongly recommended to change the default IP Range: Input the IP range located at the DMZ port .
Linksys Setup Time Password Strength Meter: When enabling Minimum Password Complexity, the Password Strength Meter Go to Configuration > Setup > Time page to configure the system time . The appears and indicates the password exact time of event occurrences will be recorded in the System Log, as will the strength .
Linksys Setup DMZ Host Set the local time manually: When the NAT mode is activated, users may need to use applications Input date as yyyy .mm .dd, i .e ., 2013 .9 .30 . Date: that do not support virtual IP addresses, such as network games or video Time: Input current time as hh:mm:ss, i .e ., 08:50:00 .
Linksys Setup Port Range Forwarding Service Select the service . You can also add a new service from Service Management . Port forwarding can be used to set up public services on your network . When IP Address Input the LAN IP address of the virtual host .
Linksys Setup Port Triggering Some Internet applications use alternate ports to communicate between the server and LAN host . Port Triggering opens a port range for those services . The device will forward the incoming packets to the assigned LAN host .
Linksys Setup Port Address Translation Enter the name of the application . Application Name: Trigger Port Range: Input the starting and ending port numbers of Use the Setup > Port Address Translation . This feature allows Windows to the trigger port range .
Linksys Setup Service Select the service . You can also add a new service One-to-One NAT from Service Management . If your ISP issued more than one actual IP (such as eight ADSL static IP Name or IP Address Input the Intranet virtual IP address or host name .
Input the Public IP address for the Internet Public Range Begin: (MAC address: 00-xx-xx-xx-xx-xx) here . The Linksys LRT series router will adopt One-to-One NAT function . this MAC address registered to your ISP . Use the Configuration > Setup > MAC...
Linksys Setup Dynamic DNS Indicates the WAN port the user has selected . Interface: Service: Check the box to choose your service (DynDNS .org or With Dynamic Domain Name System (DDNS) service offers the function of 3322 .org) . dynamic web address transferred you can assign a domain name to a dynamic Username: Input the username for your DDNS account .
Linksys Setup Dynamic Routing Static Routing Enter the settings for dynamic routing by using Routing Information Protocol When there are more than one router and IP subnets, the routing mode for (RIP) the device should be configured as static routing . Static routing enables different network nodes to seek necessary paths automatically .
Linksys Setup IPv6 Transition IPv4 When Dual-Stack IP is enabled on the Setup > Network page, a 6to4 tunnel is enabled by default for IPv6 packets via 6to4 source/destination addressing exchange . This feature allows the router to establish auto-tunnel in IPv4 network (or a real IPv4 Internet connection) across two independent IPv6 networks .
Linksys DHCP DHCP DHCP Server IP Address: This is the current DHCP IP . Client lease Time: This is to set up a lease time for the IP address acquired by a PC . The default is 1,440 minutes (one day) . Users can change it according to their needs .
Linksys DHCP DHCP Status Router Advertisement (IPv6) This is an indication list of the current status and setup record of the DHCP PCs in the LAN can configure an IPv6 address through Router Advertisement server . The indications are for the administrator’s reference when a network function .
Linksys DHCP IP & MAC Binding • Set up IP & MAC Binding from IP & MAC Table Click Show unknown MAC addresses button, an IP address and MAC table will appear . Input a name for the device and check Enable box to bind the IP and MAC addresses .
Linksys DHCP DNS Local Database Static IP Address: Input a specified static IP address . You can also input 0 .0 .0 .0 in the boxes . The router will assign a static IP You can configure your router to function as a DNS server for your intranet address to the device .
Page 33
Linksys DHCP Input the domain name, i .e . abc .com . Host Name: IP Address: Input the IP address of the domain . Add the configuration or modification to the list . Add to list: Remove the selected entry from the list .
Linksys System Management System Management Mode You can configure two Internet connections by using the WAN and the WAN/DMZ port . Two modes can be selected: You can configure advanced setting in System Management category, please refer to following items: •...
Linksys System Management Protocol Binding (Only Dual-WAN Mode supports this Click to enable Network Service Detection . Enable Network Service Detection: function) Input the retry times for network service Retry count: Users can define specific IP addresses or specific application service ports detection .
Page 36
Linksys System Management Note The rules configured in Protocol Binding will be executed by the device Service: This is to select the Binding Service Port to be activated . according to their priorities too . The higher up on the list, the higher the priority The default (such as ALL-TCP&UDP 0~65535, WWW...
Linksys System Management Bandwidth Management Interface: Select on which WAN the QoS rule should be executed . It can be a single selection or You can configure upstream and downstream bandwidth and set Quality of multiple selections . Service (QoS) rules in this page .
Linksys System Management • Priority: Identify priority for specified services . Interface: Select on which WAN the QoS rule should be executed . It can be a single selection or multiple selections . Service: Select a service to manage . You can also click Service Management to add service items .
SNMP Enabled SNMP: Enable SNMP feature . Enabled is the default . Set the name of the device, e .g ., Linksys . System Name: Go to Configuration > System Management > SNMP page to set up SNMP Set the name of the person who manages the (Simple Network Management Protocol) .
Linksys System Management Certificate Management Generate New Certificate: Click Generate and click OK to creat a new SSL certificate . Export Certificate for Administrator: Click Export for Admin. Click Export for Client . Export Certificate for Client: Click Browse to choose a certificate Import Certificate: and click Import .
Linksys Port Management Port Management Enter the following settings, as needed: Check this box to disable a port . By default, all ports Disable: are enabled . Priority:(for LAN ports Use this setting to ensure Quality of Service by only) prioritizing the traffic for devices on particular ports .
Linksys Port Management Port Status For the selected port, the Statistics table displays the following: Port Receive Packet Count: The number of packets received Use the Configuration > Port Management > Port Status page to view information The number of packet bytes received .
Linksys Port Management 802.1Q 802.1Q LAN Status The router supports up to five sets of VLANs, which are used to divide networks into several segments . Dividing networks makes them easier to manage and Indicates VLAN ID (VID) . VLAN ID: enhances performance and security through isolation .
Linksys Port Management 802.1Q LAN Configuration You can click Edit to change an existing VLAN configuration or click Add to set up a new set of VLAN . VLAN ID: Input VID (range:2~4092) of the VLAN . Give a name to the VLAN .
Linksys Firewall Firewall Turn on/off the firewall . Firewall SPI (Stateful Packet Inspection) Enables packet automatic authentication detection technology . The firewall operates mainly at the network layer . By running the dynamic authentication for each connection, it Firewall General Settings will also perform an alarming function for application procedure .
Linksys Firewall Restrict Web Features It supports the block that is connected through: Java, Cookies, Active X, and HTTP Proxy access . Don’t Block Java / ActiveX When enabled, users can add trusted network or IP address into the trust domain .
Page 47
Linksys Firewall Adding or Editing access rules Priority Indicates the priority of the access rule; 1 being the highest . Select an option from the drop-down Click Add or Edit to enter Access Rules configuring page . list to change the priority . The default access rules NOTE Remember to click Save to save your settings before leaving the page .
Page 48
Linksys Firewall Scheduling (IPv4 Only) Allow: Permits the pass of packets compliant with this Action: control rule . Deny: Prevents the pass of packets not compliant with this control rule . Choose the service for this rule . You can also click Service Service: Management to add new services .
Linksys Firewall Content Filter The device supports two Web page restriction modes: one blocks certain forbidden domains; the other gives access to certain Web pages . Only one of these two modes can be selected . NOTE Remember to click Save before leaving the page . You can also click Cancel to undo the changes .
Page 50
Linksys Firewall Fill in the complete website such as to have it blocked . Scheduling Enter the websites to be controlled, such as www . g amble . c om . Add: Add to list: Click ”Add to list” to create a new website to be controlled .
Linksys Tunnel Status VPN (Virtual Private Network) is a technology that enables two private networks to establish a secure and encrypted connection across public network, such as the Internet . VPN allows remote user, say a branch office or employee at home, to access the company intranet and share files, video conference or access How many tunnels are enabled by the administrator .
Linksys VPN Client Status Add: Add a new tunnel and choose Gateway to Gateway or Client to Gateway . . This section identifies the VPN clients currently connected to the router . The ID number of the VPN client .
Page 53
Linksys Indicates the tunnel number . Entering the IP address is the Tunnel No.: IP Only: only way to access this tunnel . Displays the current VPN tunnel connection name, such as Tunnel Name: The WAN IP address will be XXX Office .
Linksys Allows only the IP address that is entered to build the IP Address: Input a number between 100~ffffffff as SPI (Security Incoming SPI: VPN tunnel . Parameter Index) . SPI is an identification tag for an IPSec association . The incoming SPI of this router...
Page 55
Linksys Phase 1 / Phase 2 SA Life Time: The lifetime for this exchange code is set to 28,800 seconds (8 hours) by default . This allows the automatic generation of other exchange passwords within the valid time of the VPN connection to guarantee security .
Page 56
Linksys Adopted by remote devices to enhance the Aggressive Mode: security control if dynamic IP is used for connection . Reduces the size of IP datagrams . The Compress (Support IP Payload Compression router will compress IP datagram size when initiating a tunnel .
Linksys VPN Tunnel Backup Idle Time: If the primary tunnel doesn’t work within configured period, the backup tunnel will be connected . The default value is 30 seconds . The router can send DNS requests to one DNS Split DNS: server and other DNS requests to another DNS server .
Page 58
Linksys Must enter the IP address to gain access IP Only: to this tunnel . The WAN IP address will be automatically filled into this space . No further settings necessary . The WAN IP address will be automatically IP + Domain Name (FQDN) Authentication: filled into this field .
Linksys Enter the settings for manual mode . Be sure to enter the same settings when Enter a domain name to use for authenticating remote Domain configuring the other end router for this tunnel . users . The domain name must be unique for each...
Page 60
Linksys The lifetime for this exchange code is set to 28,800 Phase 1 / Phase 2 seconds (8 hours) by default . This allows the automatic SA Life Time: generation of other exchange passwords within the valid time of the VPN connection to guarantee security .
Page 61
Linksys Ensures the passage of NetBIOS broadcast NetBIOS Broadcast: packets . This facilitates the easy connection with other Microsoft network, but it also increases the amount of traffic using this VPN tunnel . Allows IPSec traffic to pass through NAT Traversal: devices that don’t support IPSec packets .
Linksys VPN Passthrough IP Address Range Enable VPN passthrough to allow VPN clients to pass through the router . You can also disable the VPN passthrough to block VPN connection . Use the Device Configuration > VPN > VPN Passthrough page to enable or disable VPN passthrough .
Linksys Connection List Enter the information identified in NOTE (below), To add a user to the list: and click Add to list . The following read-only information appears . You can click Refresh to update To add another new user: Enter the information identified in NOTE (below), the data .
Linksys OpenVPN OpenVPN OpenVPN Client Status You can use the Rows per page list at the top right corner of the table to decide the number of rules to display on each page and use the Page list to choose a particular page .
Linksys OpenVPN NOTE Remember to click Save before leaving the page . You can also click Cancel Advanced Configure Setting to undo the changes . Global Configuration Setting Tunnel Mode Split Tunnel and Full Tunnel . Configure allowable subnet for OpenVPN clients .
Page 66
State or Province Name (ST) Locality Name (L) Input locality name (city, town or other municipal jurisdiction) . Input organization name . Example: Linksys LLC . O r g a n i z a t i o n Name (O)
Linksys OpenVPN OpenVPN Client Certificate Setting If you select Certificate or Password+Certificate as authentication type, you Go to OpenVPN > OpenVPN Client to add a new client configuration . have to configure the certificate here . (* indicates required field) You can also click the edit icon or Add button in summary page to get into setting page .
Page 68
Input state or province name . (ST) Locality Name (L) Input locality name (city, town or other municipal jurisdiction) . Organization Name (O) Input organization name . Example: Linksys LLC . Input organization unit . Example: Accounting . Organizational Unit Name (OU) Input a common name for the certificate .
Linksys Email Alert Enable email alerts to send logs to a specified email address . The router has the real-time surveillance management feature that provides information about current system operation . From the log management and look up, we can see the relevant operation status and traffic statistics . Setup error and attack alerts here .
Linksys Log Setting Records when remote users enter the system Allow Policies: through successful authentication . Records changes in the system’s configuration . Configuration Changes: Authorized Login: Records authorized logins . Four buttons for interaction with the system log online .
Linksys System Statistics Number of received error packets . Error Packets Received Dropped Packets Received Number of received dropped packets . Go to Configuration > Log > System Statistics page to view statistics of all router interfaces Click Refresh button to update the statistics .
Users may directly upgrade the device firmware on the Firmware Upgrade automatically . page . First download the firmware file from Linksys .com . Go to Maintenance > Firmware Upgrade . Please confirm all information about the software version Restore Startup Configuration in advance .
Linksys support team . Product Website Click Launch Now to visit product website to get more information about the router . Linksys Support Website Click Launch Now to visit Linksys support website to get more support for the router .
Need help?
Do you have a question about the LRT214 and is the answer not in the manual?
Questions and answers