Summary of Contents for Cisco RV016 - Small Business - 10/100 VPN Router
Page 1
ADMINISTRATION GUIDE Cisco Small Business RV0xx Series Routers RV042 Dual WAN VPN Router RV042G Gigabit Dual WAN VPN Router RV082 Dual WAN VPN Router RV016 Multi-WAN VPN Router...
Page 2
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
Setting Up Universal Plug and Play (UPnP) Setting Up One-to-One NAT Cloning a MAC Address for the Router Assigning a Dynamic DNS Host Name to a WAN Interface Setting Up Advanced Routing IPv6 Transition Cisco Small Business RV0xx Series Routers Administration Guide...
Page 4
Using Content Filters to Control Internet Access Chapter 8: Cisco ProtectLink Web Getting Started with Cisco ProtectLink Web Specifying the Global Settings for Approved URLs and Clients Approved URLs and Approved Clients Enabling Web Protection for URL Filtering Cisco Small Business RV0xx Series Routers Administration Guide...
Page 5
Setting Up the System Log and Alerts Viewing the System Log Chapter 11: Wizard Appendix A: Glossary Appendix B: Troubleshooting Appendix C: Cisco QuickVPN for Windows Introduction Cisco QuickVPN Client Installation and Configuration Using the Cisco QuickVPN Software Cisco Small Business RV0xx Series Routers Administration Guide...
Page 6
VPN Hub and Spoke Topology VPN Mesh Topology Other Design Considerations Configuring a VPN Tunnel on a Cisco RV0xx Series Router Example: Sites with Static WAN IP Addresses Example: Site with a Dynamic WAN IP Address Appendix E: IPSec NAT Traversal...
Features of the User Interface, page 18 RV0xx Series Router Features Cisco RV0xx Series dual WAN and multi-WAN VPN routers offer highly secure, high-performance, reliable connectivity. All of these routers can support a second Internet connection to ensure continuous connectivity or to increase available bandwidth and balance traffic.
Page 8
System Internet Mode 10/100 16-Port VPN Router RV016 Ports and Status Lights Cisco Small Business RV016 LAN/Act DIAG LAN/Act Internet Internet System Dual-Function Ports Internet/Act 10/100 Internet 2 Internet 1 16-Port VPN Cisco Small Business RV0xx Series Routers Administration Guide...
Use these numbered ports as LAN ports Function Ports (numbered 9-13) or configure them for use (RV016) as Internet ports (numbered 3-7). The status is shown on the corresponding status lights: LAN/Act 9-13 or Internet/Act 3-7. Cisco Small Business RV0xx Series Routers Administration Guide...
Flashing—There is network activity over the port. Internet/Act 3-7 Lit if the port is configured as an Internet (RV016) port. Steady—A device is connected to the port. Flashing—There is network activity over the port. Cisco Small Business RV0xx Series Routers Administration Guide...
RV042 and RV042G: Connect the provided power adapter to the power port on the side panel. • RV082 and RV016: Connect the provided AC power cable to the power port on the back panel. Cisco Small Business RV0xx Series Routers Administration Guide...
Mechanical Loading—Be sure that the router is level and stable to avoid any hazardous conditions. Desktop Placement Place the router on a flat surface near an electrical outlet. Do not place anything on top of the router; excessive weight could damage it. WARNING Cisco Small Business RV0xx Series Routers Administration Guide...
RV082 and RV016 5-5.5 mm 20-22 mm 6.5-7 mm 16.5-18.5 Insecure mounting might damage the router or cause injury. Cisco is not WARNING responsible for damages incurred by insecure wall-mounting. For safety, ensure that the heat dissipation holes are facing sideways. WARNING Drill two pilot holes into the surface.
Bus ines 16-P 10/1 DIAG Inter Syst Inter DM Z/In ter net Cis co Int ern Sm all Bu sin RV 082 16- Po 10/ 100 rt VP N Ro ute r Cisco Small Business RV0xx Series Routers Administration Guide...
Internet 2 Internet 1 16-Port VPN To connect a secondary Internet service: STEP 3 • RV042, RV042G, and RV082: Connect an Ethernet cable from the DMZ/ Internet port to a second broadband network device. Cisco Small Business RV0xx Series Routers Administration Guide...
Service Provider may require additional settings. On the System Summary page, check the WAN Status to see if the router was able to receive an IP Address. If not, continue to the next step. Cisco Small Business RV0xx Series Routers Administration Guide...
STEP 7 Cisco strongly recommends setting a strong administrator password to prevent unauthorized access to your router. For more information about all settings, refer to the online Help and the Cisco Small Business RV0xx Series VPN Router Administration Guide. Troubleshooting Tips...
Click a button to view more options. Click an option to open a configuration page. The selected page appears in the main window of the configuration utility. 1. Navigation tree 2. Configuration page Cisco Small Business RV0xx Series Routers Administration Guide...
Page 19
Logout To exit the configuration utility, click the Logout link near the top right corner of the configuration utility. The Login page appears. You can close the browser window. Cisco Small Business RV0xx Series Routers Administration Guide...
• Configuration, page 22 • Port Statistics, page 22 • WAN Status, page 24 • Firewall Setting Status, page 25 • VPN Setting Status, page 25 • Log Setting Status, page 25 Cisco Small Business RV0xx Series Routers Administration Guide...
Page 21
You can use the following buttons: • Go buy: Click this button to purchase a license to use this service. You will be redirected to a list of Cisco resellers on the Cisco website. Then follow the on-screen instructions. •...
Page 22
If you click a status in the Port Statistics table, the Port Information window appears. This window displays the latest information about the interface and the current activity. To update the displayed information, click the Refresh button. To close the window, click the Close button. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 23
Port Activity: The current activity on the port, either Port Enabled, Port Disabled, or Port Connected. Priority: The priority setting, High or Normal. Speed Status: The speed, 10Mbps or 100Mbps. Duplex Status: The duplex mode, Half or Full. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 24
WAN Status This section displays information for the WAN1 interface as well as DMZ or WAN2, depending on your configuration. On Cisco RV016, additional WAN interfaces may be configured. Use the tabs to view the IPv4 and IPv6 information. The IPv6 tab is available if Dual-Stack IP is enabled on the Setup > Network page.
Page 25
This section displays the following information: • Syslog Server: The status of the syslog server, On (green) or Off (red). • Email Log: The status of the email log, On (green) or Off (red). Cisco Small Business RV0xx Series Routers Administration Guide...
Cloning a MAC Address for the Router, page 53 • Assigning a Dynamic DNS Host Name to a WAN Interface, page 55 • Setting Up Advanced Routing, page 57 • IPv6 Transition, page 61 Cisco Small Business RV0xx Series Routers Administration Guide...
• Host Name: Keep the default setting or enter a host name specified by your ISP. • Domain Name: Keep the default setting or enter a domain name specified by your ISP. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 28
Settings section, click the IPv6 tab, and click the Edit icon for the WAN interface. Then enter the LAN IPv6 Address. For more information, see Setting (Internet connection), page Click Save to save your changes, or click Cancel to undo them. STEP 2 Cisco Small Business RV0xx Series Routers Administration Guide...
Page 29
Enabling multiple subnets (IPv4 only) Typically, a Cisco RV0xx Series router is used as an access router, with a single LAN subnet. By default, the firewall is pre-configured to deny LAN access if the source IP address is on a different subnet than the router’s LAN IP address.
Page 30
Add New to clear the text fields. • To delete a subnet: Click the subnet in the list, and then click Delete. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 31
• To change the number of WAN ports (Cisco RV016 only): Use the drop- down list to choose the number of WAN ports that you want to enable. The default selection is 2. If you configure additional WAN ports, the Dual- Function Ports are used for this purpose.
DMZ Setting On Cisco RV042, RV042G, and RV082, you can configure the Internet/DMZ port for use as a DMZ (De-Militarized Zone or De-Marcation Zone). Cisco RV016 has a dedicated DMZ port. A DMZ allows Internet traffic to access specified hosts on your network, such as FTP servers and web servers.
Page 33
For more information, see Editing a DMZ Connection, page 38. If you have not saved your settings, a warning appears. Click OK to save your settings, or click Cancel to close the window without saving. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 34
IP address. For example, most cable modem subscribers use this connection type. Your ISP will assign the settings, including the DNS server IP address. If you want to specify a DNS server, check the Use Cisco Small Business RV0xx Series Routers Administration Guide...
Page 35
If you enable this feature, also enter the Redial Period to specify how often the router verifies your Internet connection. The default period is 30 seconds. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 36
Optionally, enter a second DNS server. The first available DNS entry is used. Internal LAN IP Range: The internal LAN IP range that will be bridged. The WAN and LAN of transparent bridge will be at the same subnet. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 37
MTU: Set the MTU (Maximum Transmission Unit) in bytes (see the Glossary). Unless a change is required by your ISP, Cisco recommends that you use the default setting, Auto. To specify another value, select Manual, and then enter the size in bytes.
Page 38
WAN (default setting). Enter an IP address and subnet mask for the DMZ. • Range: Choose this option to place the DMZ on the same subnet as the WAN. Enter the range of IP addresses to reserve for the DMZ port. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 39
Specify DMZ IPv6 Address: Enter an IPv6 address for the DMZ. Replace the default double colon (::) with a valid IPv6 address for your DMZ. • Prefix Length: Enter the prefix length. The default value is 64. Cisco Small Business RV0xx Series Routers Administration Guide...
Changing the Administrator Username and Password Use the Setup > Password page to update the administrator username and password. You can keep the default username (admin) if you like. However, Cisco strongly recommends changing the default password (admin) to a strong password that is hard to guess.
Page 41
Password Aging Enforcement: Choose Disable if you do not want the password to expire. Choose Change the password after if you want the password to expire after the specified number of Days (default 180). Cisco Small Business RV0xx Series Routers Administration Guide...
Use mm.dd format, such as 6.25 for June 25. Also enter the End Date in the same format. NTP Server: Enter the URL or IP address of the NTP server. The default is time.nist.gov. Cisco Small Business RV0xx Series Routers Administration Guide...
Enter the IP address of the network device that you want to use as a DMZ host. Before navigating away from this page, click Save to save your settings, or click NOTE Cancel to undo them. Any unsaved changes are abandoned. Cisco Small Business RV0xx Series Routers Administration Guide...
IP address in order to properly run an Internet server.) For added security, Internet users will be able to communicate with the server, but they will not actually be connected. The packets will simply be forwarded through the router. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 45
To view the port range table: Click View, near the bottom of the page. Choose Port Range Forwarding or Port Triggering. To update the display, click Refresh. To return to the Forwarding page, click Close. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 46
Protocol: Choose the required protocol. Refer to the documentation for the service that you are hosting. Port Range: Enter the required port range. • To add another new service: Enter the information, and then click Add to list. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 47
Make the changes, and then click Update. If you do not need to make changes, you can click Add New to de- select the entry and clear the text fields. Cisco Small Business RV0xx Series Routers Administration Guide...
As a security precaution, disable UPnP unless you require it for your applications. • Before navigating away from this page, click Save to save your settings, or click Cancel to undo them. Any unsaved changes are abandoned. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 49
Refresh to update the data, or click Close to close the pop-up window. • To view the UPnP forwarding table: Click View, near the bottom of the page. To update the display, click Refresh. To return to the UPnP page, click Close. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 50
Protocol: Choose the required protocol. Refer to the documentation for the service that you are hosting. Port Range: Enter the required port range. • To add another new service: Enter the information, and then click Add to list. Cisco Small Business RV0xx Series Routers Administration Guide...
The first internal address is mapped to the first external address, the second IP internal IP address is mapped to the second external address, and so on. To open this page: Click Setup > One-to-One NAT in the navigation pane. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 52
Shift key, and then click the final entry in the block. To select individual entries, press the Ctrl key while clicking each entry. To de-select an entry, press the Ctrl key while clicking the entry. Cisco Small Business RV0xx Series Routers Administration Guide...
MAC address with your ISP, you can use the Setup > MAC Address Clone page to “clone” that address to your Cisco RV0xx Series router. By using this process, you don’t have to call your ISP to change the registered MAC address.
Page 54
MAC Address from this PC: To clone the MAC address of the computer you are currently using to configure the router, click this radio button. The MAC address of your PC is displayed automatically. Cisco Small Business RV0xx Series Routers Administration Guide...
This page displays the current settings. Click the Edit icon for the WAN interface to display the Edit Dynamic DNS Setup page. For more information, see Editing the Dynamic DNS Setup, page Cisco Small Business RV0xx Series Routers Administration Guide...
Page 56
Because it is dynamic, this setting will change. • Status: The status of the DDNS function. If the status information indicates an error, make sure you have correctly entered the information for your account with your DDNS service. Cisco Small Business RV0xx Series Routers Administration Guide...
To view current data: Click View near the bottom of the page. The Routing Table Entry List appears. You can click Refresh to update the data, or click Close to close the pop-up window. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 58
RIPv2 - Broadcast (recommended) broadcasts data in the entire subnet. RIPv2 - Multicast sends data to multicast addresses. RIPv2 - Multicast also helps to avoid unnecessary load by multicasting routing tables to adjacent routers rather than broadcasting to the entire network. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 59
Interface: Select the interface to use for this route. Select a WAN interface if this router provides Internet connectivity for your network. Select LAN if this router gets Internet connectivity from a gateway router on your LAN. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 60
To view current data: Click View near the bottom of the page. The Routing Table Entry List appears. You can click Refresh to update the data, or click Close to close the pop-up window. Cisco Small Business RV0xx Series Routers Administration Guide...
Cancel to undo them. Any unsaved changes are abandoned. Next steps: For a typical deployment, such as setting up a 6to4 tunnel between your RV0xx Series router and a Cisco RV Series router at another site, you also should complete the tasks listed below.
Page 62
Complete the required tasks on the router at the other end of the 6to4 tunnel. For detailed application notes, see the documentation links in Appendix H, “Where NOTE to Go From Here.” Cisco Small Business RV0xx Series Routers Administration Guide...
DHCP feature and enable DHCP Relay. For more information, see Enabling DHCP Server and DHCP Relay, page DHCP Relay is available only on the IPv4 tab. DHCPv6 Relay is not available. NOTE Cisco Small Business RV0xx Series Routers Administration Guide...
Page 64
DHCP discover broadcast packets to get IP addresses from the DHCP server. This router will act as DHCP Relay agent and send DHCP unicasts to DHCP server. Required: Enter the DHCP Server IP Address. Other sections of this page are optional. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 65
DNS server settings must be configured on the Internet Protocol (TCP/IP) page of the Windows operating system. Then the WINS IP address must be configured on the advanced TCP/IP page. (For more information, refer to Windows Help.) Cisco Small Business RV0xx Series Routers Administration Guide...
Page 66
Assigning static IP addresses by adding devices from a list Click Show unknown MAC addresses. The IP & MAC binding list appears. If the STEP 1 web browser displays a message about the pop-up window, allow the blocked content. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 67
Name: Enter a descriptive name for the device. Enable: Check this box to assign the static IP address to this device. • To add another new entry: Enter the information, and then click Add to list. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 68
Static IP list. This feature prevents unknown devices from accessing your network. Uncheck the box to allow access by any connected device that is configured with an IP address in the correct range. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 69
Shift key, and then click the final entry in the block. To select individual entries, press the Ctrl key while clicking each entry. To de-select an entry, press the Ctrl key while clicking the entry. Cisco Small Business RV0xx Series Routers Administration Guide...
Note: The IPv6 tab is available only if you enabled Dual-Stack IP on the Network > Setup page. • Client Host Name: The name assigned to a client host. • IP Address: The dynamic IP address assigned to a client. Cisco Small Business RV0xx Series Routers Administration Guide...
Interval, which is the interval at which Router Advertisement messages are sent. Enter any value between 10 and 1800 seconds. The default is 30 seconds. Unicast only: Select this option to send Router Advertisement messages only to well-known IPv6 addresses. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 72
1492 bytes. Unless your ISP requires a different setting, this setting should not be changed. • Router Lifetime: Enter the time in seconds that the Router Advertisement messages will exist on the route. The default is 3600 seconds. Cisco Small Business RV0xx Series Routers Administration Guide...
To open this page: Click System Management > Dual WAN (or Multi-WAN on RV016) in the navigation tree. Before navigating away from this page, click Save to save your settings, or click NOTE Cancel to undo them. Any unsaved changes are abandoned. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 74
Load Balance: Choose this mode to use both Internet connections simultaneously to increase the available bandwidth. The router balances the traffic between the two interfaces in a weighted round robin fashion. NOTE: DNS queries are not subject to load balancing. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 75
IP addresses. NOTE: The Router reserves at least one WAN port for non-IP Group users, so WAN1 will always be set to Intelligent Balancer (Auto Mode). Protocol binding is not available for WAN1. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 76
OK to close the message. Then click Save to save your changes. After saving your changes, click the Edit icon. Alternatively, when the warning appears, click Cancel to continue to the edit page without saving the changes. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 77
30 seconds. • When Fail: Choose the action that will be taken if a ping test fails. If you choose Generate the Error Condition in the System Log, the router Cisco Small Business RV0xx Series Routers Administration Guide...
Page 78
DNS Lookup host, enter a host name or domain name. Uncheck a box if you do not want to ping this device for network service detection. Protocol Binding (for Cisco RV016 only, when Load Balancer is selected): Use this feature to require this interface to be used for specified protocols and specified source and destination addresses.
Page 79
Add to List. You can have up to 30 services in the list. Service Name: Enter a short description. Protocol: Choose the required protocol. Refer to the documentation for the service that you are hosting. Port Range: Enter the required port range. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 80
To select a block of entries, click the first entry, hold down the Shift key, and click the final entry in the block. To select individual entries, hold down the Ctrl key while clicking. Click Delete. Cisco Small Business RV0xx Series Routers Administration Guide...
ISP. The default is 12 kbit/sec. Bandwidth Management Type Choose one of the following management options: • Rate Control: Choose this option to specify minimum (guaranteed) bandwidth and maximum (limited) bandwidth for each service or IP address. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 82
Shift key, and then click the final entry in the block. To select individual entries, press the Ctrl key while clicking each entry. To de-select an entry, press the Ctrl key while clicking the entry. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 83
Protocol: Choose the required protocol. Refer to the documentation for the service that you are hosting. Port Range: Enter the required port range. • To add another new service: Enter the information, and then click Add to list. Cisco Small Business RV0xx Series Routers Administration Guide...
To open this page: Click System Management > SNMP in the navigation tree. Before navigating away from this page, click Save to save your settings, or click NOTE Cancel to undo them. Any unsaved changes are abandoned. Cisco Small Business RV0xx Series Routers Administration Guide...
LAN. It may be required by network management systems that you use. When this feature is enabled, the router periodically multicasts Bonjour service records to its entire local network to advertise its existence. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 86
Enabling Device Discovery with Bonjour For discovery of Cisco Small Business products, Cisco provides a utility that works NOTE through a simple toolbar on the web browser. This utility discovers Cisco devices in the network and display basic information, such as serial numbers and IP addresses, to aid in the configuration and deployment.
Setup > Network page, or to look up an IP address that you want to use in the Ping test. In the Look up the name field, enter a host name, such as www.cisco.com. Do not include a prefix such as http://. Then click Go. If the test is successful, the IP address of the host appears.
Page 88
Packets: The number of packets transmitted, number of packets received, and percentage of packets lost in the ping test • Round Trip Time: The minimum, maximum, and average round trip times for the ping test Cisco Small Business RV0xx Series Routers Administration Guide...
Click Return to Factory Default Setting if you want to restore the router to its STEP 1 factory default settings. When the confirmation message appears, click OK to continue. If you do not want STEP 2 to restore the factory default settings, click Cancel. Cisco Small Business RV0xx Series Routers Administration Guide...
IP address in the browser address bar. If your PC cannot reconnect to the configuration utility, you may need to release and restore your IP address. Cisco Small Business RV0xx Series Routers Administration Guide...
Then perform the firmware upgrade as described above. Restarting the Router If you need to restart the router, Cisco recommends that you use the Restart tool Restart on this page. When you restart from the System Management >...
• Copying a Startup File or Mirror File, page 93 Restoring the Settings from a Configuration File If you want to revert to previously saved settings, you can import a configuration file. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 93
Copy the startup file to the mirror before making your changes. If you are dissatisfied with your changes, copy the mirror to the startup to restore the settings. NOTE • The startup configuration file is automatically copied to the mirror configuration file every 24 hours. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 94
After a short time, the router restarts. If your PC is unable to immediately reload the login page, re-enter the IP address for the configuration utility in the Address bar. Then log in. Cisco Small Business RV0xx Series Routers Administration Guide...
To open this page: Click Port Management > Port Setup in the navigation tree. Before navigating away from this page, click Save to save your settings, or click NOTE Cancel to undo them. Any unsaved changes are abandoned. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 96
Port Management Configuring the Port Settings For Cisco RV016 only, choose the number of WAN ports from the drop-down list, or keep the default number, 2. If you change the number, save your settings. (You Setup > Network can also change the number of WAN ports by using the page.)
Speed Status: The speed of the port, 10 Mbps or 100 Mbps • Duplex Status: The duplex mode: Half or Full. • Auto negotiation: The status of the feature • VLAN: The VLAN of the port Cisco Small Business RV0xx Series Routers Administration Guide...
Page 98
• Port Transmit Packet Count: The number of packets transmitted • Port Transmit Packet Byte Count: The number of packet bytes transmitted • Port Packet Error Count: The number of packet errors Cisco Small Business RV0xx Series Routers Administration Guide...
You also can restrict potentially risky website features such as Java and cookies. To open this page: Click Firewall > General in the navigation tree. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 100
Setup > Password configure a strong administrator password on the page. This precaution prevents an unauthorized user from accessing the router with the default password. If you enable this feature, you can keep the Cisco Small Business RV0xx Series Routers Administration Guide...
Page 101
Internet sites created using this programming language. As a compromise, you can check this box to block ActiveX on untrusted or unknown sites, while allowing ActiveX on trusted Cisco Small Business RV0xx Series Routers Administration Guide...
Page 102
To modify a domain in the trusted list: Click the domain. The information appears in the text field. Make changes, and then click Update. To remove a domain from the trusted list: Click the domain, and then click Delete. Cisco Small Business RV0xx Series Routers Administration Guide...
All traffic from the WAN to the LAN is denied. • All traffic from the LAN to the DMZ is allowed. • All traffic from the DMZ to the LAN is denied. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 104
Priority: The priority of the access rule, with 1 indicating the highest priority. To change the priority for a rule, select an option from the drop- down list. If there is a conflict between two access rules, then the higher Cisco Small Business RV0xx Series Routers Administration Guide...
Page 105
To delete an access rule: Click the Delete icon. When the confirmation message appears, click OK to continue, or click Cancel to close the message without deleting the rule. • To delete all custom rules: Click Restore to Default Rules. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 106
From the drop-down list, choose one of the following options: Single: This rule applies to a single IP address. Enter the IP address. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 107
Check the Everyday box if the rule is active on all days. To choose specific days, uncheck the Everyday box and then check the box for each day when the rule is active. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 108
Protocol: Choose the required protocol. Refer to the documentation for the service that you are hosting. Port Range: Enter the required port range. • To add another new service: Enter the information, and then click Add to list. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 109
Shift key, and click the final entry in the block. To select individual entries, hold down the Ctrl key while clicking. Click Delete. Cisco Small Business RV0xx Series Routers Administration Guide...
Website Blocking by Keywords, page 111 • Schedule, page 112 The content filter rules will be automatically disabled if the Cisco ProtectLink NOTE service is activated on the router. Instead configure the ProtectLink features to control Internet access. For more information, see Chapter 8, “Cisco ProtectLink...
Page 111
To modify an entry in the list: Click the entry that you want to modify. Make the changes, and then click Update. If you do not need to make changes, you can click Add New to de-select the entry and clear the text field. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 112
Check the Everyday box if the rule is active on all days. To choose specific days, uncheck the Everyday box and then check the box for each day when the rule is active. Cisco Small Business RV0xx Series Routers Administration Guide...
Getting Started with Cisco ProtectLink Web You can purchase, register, and activate the service by using the links on the Cisco ProtectLink Web page. To open this page: Click Cisco ProtectLink Web in the navigation tree.
Page 114
Choose the appropriate option: • Learn more about and request Free Trial for Cisco ProtectLink: Click this link to open the Cisco ProtectLink Security Solutions page on Cisco.com. You can read product information and get a 30-day trial for your RV router.
Specifying the Global Settings for Approved URLs and Clients Specifying the Global Settings for Approved URLs and Clients After you activate your service, you can use the Cisco ProtectLink Web > Global Settings page to configure the services on the router.
Specifying the Global Settings for Approved URLs and Clients Approved URLs and Approved Clients After you click the Add button on the Cisco ProtectLink Web > Global Settings page, the Configuration page appears. Before navigating away from this page, click Save to save your settings, or click NOTE Cancel to undo them.
Enabling Web Protection for URL Filtering Enabling Web Protection for URL Filtering Use the Cisco ProtectLink Web > Web Protection page to configure URL filtering and Web Reputation settings. To open this page: Click ProtectLink > Web Protection in the navigation tree.
Page 118
• Reset Counters: The router counts the number of attempted visits to a restricted URL. To reset the counter to zero, click the button. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 119
(legitimate sites that are classified as malicious). Medium is the recommended setting. • Low: This option blocks fewer potentially malicious websites, and therefore reduces the risk of false positives. Cisco Small Business RV0xx Series Routers Administration Guide...
To open this page: Click ProtectLink > License in the navigation tree. This page is available only if you activated your Cisco ProtectLink Web service. See NOTE Getting Started with Cisco ProtectLink Web, page 113.
Page 121
(one year after the service was activated) • Renew: For information about renewing your license, click Renew. After you purchase an extension key, you can register it and activate your service. Cisco Small Business RV0xx Series Routers Administration Guide...
Site to Site VPN (Gateway To Gateway), page 123 • Remote Access (Client To Gateway), page 123 • Remote Access with Cisco QuickVPN, page 125 • Remote Access with PPTP, page 125 Cisco Small Business RV0xx Series Routers Administration Guide...
VPN router. For this scenario, you can install third-party VPN client software on the users’ computers. Alternatively, a VPN tunnel can be accessed from any computer with the built-in IPSec Security Manager (Windows 2000, Windows XP, and Windows 7). Cisco Small Business RV0xx Series Routers Administration Guide...
Page 124
TheGreenbow. For instructions, see Setting Up a Remote Access Tunnel for VPN Clients (Client To Gateway), page 139. 2. Install the client software on the users’ computers. Cisco Small Business RV0xx Series Routers Administration Guide...
Management, page 148. 3. Install Cisco QuickVPN on the users’ computers. To get the software, go to www.cisco.com/go/software. Enter the router’s model number in the search box and then click Find. In the list of links, click Quick Virtual Private Network (QVPN) Utility.
Close to return to the VPN > Summary page. For each VPN tunnel, the No., Name, Status, Phase 2 Enc/Auth/Grp, Local Group, Remote Group, and Remote Gateway will be displayed. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 127
To create a tunnel for a remote site with a VPN router, choose Gateway to Gateway. The Gateway to Gateway page appears. See Setting Up a Gateway to Gateway (Site to Site) VPN, page 130. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 128
Use the Rows per page list at the top right corner of the table to choose the number of rules to display on each page. Use the Page list below the table to choose a particular page. Use the navigation buttons to view the first Cisco Small Business RV0xx Series Routers Administration Guide...
Page 129
Use the navigation buttons to view the first page, previous page, next page, or final page. Some buttons may be unavailable, depending on the number of pages and the current selection. Cisco Small Business RV0xx Series Routers Administration Guide...
Setting Up a Gateway to Gateway (Site to Site) VPN Use the VPN > Gateway to Gateway page to create a new tunnel between two VPN devices, such as a Cisco RV082 router at your office and a Cisco RV042 router at a remote office.
Page 131
Remote Security Gateway is on the other router. At least one of the routers must have either a static IP address or a dynamic DNS hostname to make a connection. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 132
VPN router, select IP by DNS Resolved, and then enter the real domain name of the router on the Internet. Cisco RV082 will get the IP address of remote VPN device by DNS Resolved, and IP address of remote VPN device will be displayed in the VPN Status section of the VPN >...
Page 133
IKE uses a preshared key to authenticate the remote IKE peer. This setting is recommended and is selected by default. Enter the required settings. For more information, see Required fields for IKE with Cisco Small Business RV0xx Series Routers Administration Guide...
Page 134
MD5 authentication, enter 32 hexadecimal values. If you selected SHA1, enter 40 hexadecimal values. If you do not enter enough hexadecimal values, then zeroes will be appended to the key to meet the required length. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 135
My_@123 or 4d795f40313233. Both ends of the VPN tunnel must use the same Preshared Key. It is strongly recommended that you change the Preshared Key periodically to maximize VPN security. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 136
Keep-Alive: This feature enables the router to attempt to automatically re-establish the VPN connection if it is dropped. Check the box to enable this feature, or uncheck the box to disable it. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 137
Dead Peer Detection is enabled. Remote Backup IP Address: Specify an alternative IP address for the remote peer, or re-enter the WAN IP address that was already set for the remote gateway. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 138
Optionally, specify a secondary DNS server in the DNS2 field. Domain Name 1 - Domain Name 4: Specify the domain names for these DNS servers. Requests for these domains will be passed to the specified DNS server(s). Cisco Small Business RV0xx Series Routers Administration Guide...
To open this page: Click VPN > Client to Gateway in the navigation tree. Alternatively, you can click the Add Tunnel button on the VPN > Summary page, in the Tunnel Status section. Then choose Client to Gateway. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 140
The current WAN IP address appears automatically. Enter any Email Address to use for authentication. Dynamic IP + Domain Name (FQDN) Authentication: Choose this option if this router has a dynamic IP address and a registered Dynamic Cisco Small Business RV0xx Series Routers Administration Guide...
Page 141
IP + Domain Name (FQDN) Authentication: Choose this option if this client has a static IP address and a registered domain name. Also enter a Domain Name to use for authentication. The domain name can only be used only for one tunnel connection. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 142
VPN client, select IP by DNS Resolved, and then enter the real domain name of the client on the Internet. Cisco RV082 will get the IP address of remote VPN client by DNS Resolved, and IP address of remote VPN device will be displayed in the VPN Status section of the Summary page.
Page 143
SHA1 is a one-way hashing algorithm that produces a 160-bit digest. SHA1 is recommended because it is more secure. Make sure that both ends of the VPN tunnel use the same authentication method. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 144
IKE Phase 2 negotiation will generate new key material for IP traffic encryption and authentication, so hackers using brute force to break encryption keys will not be able to obtain future IPSec keys. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 145
If the responders reject this proposal, then the router will not implement compression. When the device works as a responder, it will Cisco Small Business RV0xx Series Routers Administration Guide...
Page 146
IPsec exchanges. If your VPN router is behind a NAT gateway, check this box to enable NAT traversal. Uncheck the box to disable this feature. The same setting must be used on both ends of the tunnel. Cisco Small Business RV0xx Series Routers Administration Guide...
Use the VPN > VPN Client Access page to configure usernames and passwords for Cisco QuickVPN users and to generate the SSL certificates to install on their computers. You can add up to 50 users. First, export a certificate and use the exported client certificate for the Cisco QuickVPN Client.
Page 148
For example, if you reset the router to the factory default settings, you should first export the certificate. After you restart the router, you can import this file to restore the certificate. To export the Cisco Small Business RV0xx Series Routers Administration Guide...
VPN methods. VPN passthrough is enabled by default to allow VPN clients on the LAN of the router to reach the VPN server on the Internet. Cisco recommends enabling VPN Passthrough to allow VPN clients to pass through the router to connect to the VPN endpoint without problems. The administrator can disable the VPN Passthrough to block VPN clients from reaching the VPN endpoint on the Internet.
IP address for the router. This value needs to match the value that you enter on the VPN > PPTP Server page. The wizard guides the user to create a desktop shortcut, which can be used to launch the client. To connect, the Cisco Small Business RV0xx Series Routers Administration Guide...
Page 151
To add a user to the list: Enter the following information, and then click Add to list. Username: Enter a name for this user. New Password: Enter a password. Confirm New Password: Re-enter the password to confirm. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 152
Username: The name of the PPTP VPN client. • Remote Address: The WAN IP address of the PPTP VPN client. • PPTP IP Address: The LAN IP address that the PPTP server assigned to the client upon connection. Cisco Small Business RV0xx Series Routers Administration Guide...
Before navigating away from this page, click Save to save your settings, or click NOTE Cancel to undo them. Any unsaved changes are abandoned. This page has the following sections: • Syslog section, page 154 • E-mail section, page 154 Cisco Small Business RV0xx Series Routers Administration Guide...
Page 154
The default is 10. • Email Log Now: Click this button to immediately send a message to the specified email address, to test your settings. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 155
Log setting in the access rule configuration. For more information, see Configuring Firewall Access Rules, page 103. Configuration Changes: Instances when someone saved changes in the configuration. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 156
• Clear Log Now: Click this button to clear out your log without emailing it. Use this button only if you do not want to view the information again in the future. Cisco Small Business RV0xx Series Routers Administration Guide...
Received Packets: The number of packets received through this interface • Sent Packets: The number of packets sent through this interface • Total Packets: The total number of packets sent and received through this interface Cisco Small Business RV0xx Series Routers Administration Guide...
Page 158
• Error Packets Received: The number of error packets received through this interface • Dropped Packets Received: The number of received packets that were dropped due to issues such as error checksum. Cisco Small Business RV0xx Series Routers Administration Guide...
To open this page: Click Wizard in the navigation tree. Alternatively click Setup Wizard on the System Summary page. This page includes the following sections: • Basic Setup, page 160 • Access Rule Setup, page 160 Cisco Small Business RV0xx Series Routers Administration Guide...
Page 160
Use the Access Rule Setup Wizard to create firewall access rules. Click Launch Now to run the Access Rule Setup Wizard. The wizard provides information about the router’s default rules to help you get started. Follow the on-screen instructions to proceed. Cisco Small Business RV0xx Series Routers Administration Guide...
Indication Message) clients of the next window for listening to broadcast and multicast messages. When the Cisco RV220W has buffered broadcast or multicast messages for associated clients, it sends the next DTIM with a DTIM Interval value. Its clients hear the beacons and awaken to receive the broadcast and multicast messages.
Page 162
The traditional long preamble requires 192 μs for transmission. A short pream- ble requires only 96 μs. A long preamble is needed for compatibility with the legacy 802. 1 1 systems operating at 1 and 2 Mbps. Cisco RV220W Administration Guide...
Page 163
RIPv2 supports subnet masks, allows more information to be included in RIP packets, and provides a simple authentication mechanism that is not supported by RIP. Cisco RV220W Administration Guide...
Page 164
A VLAN is a group of endpoints in a network that are associated by function or other shared characteristics. Unlike LANs, which are usually geographically based, VLANs can group endpoints without regard to the physical location of the equipment or users. Cisco RV220W Administration Guide...
Check the cable connections. The computer should be connected to one of the ports numbered 1 to 4 on the router, and the modem must be connected to the Internet port on the router. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 166
The router does not replace your modem. You still need your cable modem in order to use the router. Connect your cable connection to the cable modem, insert the setup CD into your computer, and then follow the on-screen instructions. Cisco Small Business RV0xx Series Routers Administration Guide...
Cisco QuickVPN for Windows Cisco QuickVPN can be used for client access to a Client to Gateway tunnel that you configured on this router. Refer to these topics: • Introduction, page 167 • Cisco QuickVPN Client Installation and Configuration, page 168 •...
QuickVPN, but you will see a pop- up warning during this process. For each QuickVPN client, follow these instructions: Double-click the Cisco QuickVPN software icon on your desktop or in the system STEP 1 tray.
Page 169
Click OK to save your new password. Click Cancel to cancel your change. For STEP 7 information, click Help. You can change your password only if you have been granted that privilege by your NOTE system administrator. Cisco Small Business RV0xx Series Routers Administration Guide...
Tunnel Between RV0xx Series Routers This appendix explains how to set up a VPN between two RV0xx Series routers. You can then repeat the procedures to add tunnels to your other sites. A Cisco RV0xx Series router supports up to 100 VPN tunnels.
It works well if most traffic is from the remote sites to the main network and there is little traffic among the sites. Too much inter-site traffic may create bottlenecks at the hub. Cisco Small Business RV0xx Series Routers Administration Guide...
When the number of nodes in a full mesh topology increases, scalability may NOTE become an issue—the limiting factor being the number of tunnels that the devices can support at a reasonable CPU utilization. Cisco Small Business RV0xx Series Routers Administration Guide...
Dynamic IP addresses may change without warning. In this scenario, establishing a VPN tunnel is like trying to build a bridge between two unanchored boats. However, you can “anchor” Cisco Small Business RV0xx Series Routers Administration Guide...
Page 174
For example, if the LAN IP address of the RV0xx router at Site A is 192. 1 68. 1 5. 1 , Site B must use a different subnet, such as 192. 1 68.75. 1 . Cisco Small Business RV0xx Series Routers Administration Guide...
For the scenario illustrated in Figure configure three VPN tunnels on each router. Connect a computer to your Cisco RV0xx Series router (called Site A in the STEP 1 examples), and start the web-based configuration utility.
Configuring a Gateway-to-Gateway VPN Tunnel Between RV0xx Series Routers Configuring a VPN Tunnel on a Cisco RV0xx Series Router If the remote gateway (Site B) has a dynamic IP address and a Dynamic DNS hostname: Select Dynamic IP + Domain Name (FQDN) Authentication.
Page 177
Configuring a Gateway-to-Gateway VPN Tunnel Between RV0xx Series Routers Configuring a VPN Tunnel on a Cisco RV0xx Series Router Field Value IP Address 192. 1 68. 1 .0 Subnet Mask 255.255.255.0 Remote Group Setup Remote Security IP Only Gateway Type IP Address 209.
Page 178
Configuring a Gateway-to-Gateway VPN Tunnel Between RV0xx Series Routers Configuring a VPN Tunnel on a Cisco RV0xx Series Router Field Value Minimum Enabled Preshared Key Complexity Advanced Default settings Settings on the Site B Router: Field Values Local Group Setup...
Configuring a Gateway-to-Gateway VPN Tunnel Between RV0xx Series Routers Configuring a VPN Tunnel on a Cisco RV0xx Series Router Field Values Phase 1 Authentication Phase 1 SA Life 28800 Time Perfect Forward Enabled Secrecy Phase 2 DH Group 1 - 768 bit...
Page 180
Configuring a Gateway-to-Gateway VPN Tunnel Between RV0xx Series Routers Configuring a VPN Tunnel on a Cisco RV0xx Series Router Field Value Local Security Subnet Group Type IP Address 192. 1 68. 1 .0 Subnet Mask 255.255.255.0 Remote Group Setup Remote Security...
Page 181
Configuring a Gateway-to-Gateway VPN Tunnel Between RV0xx Series Routers Configuring a VPN Tunnel on a Cisco RV0xx Series Router Field Value Phase 2 SA Life 3600 Time Preshared Key 13572468#123456789 Minimum Enabled Preshared Key Complexity Advanced Default settings Settings on the Site B Router:...
Page 182
Configuring a Gateway-to-Gateway VPN Tunnel Between RV0xx Series Routers Configuring a VPN Tunnel on a Cisco RV0xx Series Router Field Values IPSec Setup Keying Mode IKE with Preshared Key Phase 1 Encryption Phase 1 Authentication Phase 1 SA Life 28800...
Page 184
Click Advanced Settings. STEP 11 Check the NAT Traversal box to enable this feature. STEP 12 Click Save. STEP 13 Proceed to the next section, Configuration of Router B, page 185. STEP 14 Cisco Small Business RV0xx Series Routers Administration Guide...
Page 185
13572468. STEP 10 Click Advanced Settings. STEP 11 Check the NAT Traversal box to enable this feature. STEP 12 Click Save. STEP 13 Cisco Small Business RV0xx Series Routers Administration Guide...
Click Add to List. STEP 8 Add a second service. Enter a name, such as Vonage 2, in the Service Name field. STEP 9 Protocol From the drop-down menu, select UDP. STEP 10 Cisco Small Business RV0xx Series Routers Administration Guide...
Downstream for inbound traffic. Min. Rate d. In the field, enter the minimum rate for the guaranteed bandwidth. For example, you can set a minimum rate of 40 kbit/sec. Cisco Small Business RV0xx Series Routers Administration Guide...
Page 188
80 kbit/sec. Select Enable to enable this rule. g. After you have set up the rule, click Add to list. Click Save. STEP 5 Cisco Small Business RV0xx Series Routers Administration Guide...
Status Lights (LEDs) System, Internet, DMZ/Internet, DMZ Mode, Diag, 1 to 4 Operating System Linux Performance NAT Throughput 100 Mbps IPSec Throughput 59 Mbps Security Firewall SPI Firewall Access Rules Up to 50 entries Cisco Small Business RV0xx Series Routers Administration Guide...
Page 190
50 QuickVPN users for remote client access PPTP Built-in PPTP server supporting 5 PPTP clients Encryption DES, 3DES, AES-128, AES-192, AES-256 Authentication MD5, SHA1 IPSec NAT-T Supported for gateway-to-gateway and client-to- gateway tunnels VPN Passthrough PPTP, L2TP, IPSec Cisco Small Business RV0xx Series Routers Administration Guide...
4 10/100/1000 RJ-45 ports, 1 10/100/1000 RJ-45 Internet port, 1 10/100/1000 RJ-45 DMZ/Internet port Button Reset Cabling Type Category 5 Ethernet Status Lights (LEDs) System, Internet, DMZ/Internet, DMZ Mode, Diag, 1 to 4 Cisco Small Business RV0xx Series Routers Administration Guide...
Page 192
Up to 30 entries Port Triggering Up to 30 entries URL Filtering Static list by domain or keywords (included) Note: Cisco ProtectLink Web service is not available on this model. Network Dual WANs Can be configured for Smartlink backup or load balance...
Page 193
FCC Class B, CE Class B Operating Temp. 0 to 40C (32 to 104F) Storage Temp. 0 to 70C (32 to 158F) Operating Humidity 10 to 85% noncondensing Storage Humidity 5 to 90% noncondensing Cisco Small Business RV0xx Series Routers Administration Guide...
Static list by domain or keywords (included), dynamic filtering through Cisco ProtectLink Web service (optional) Network Dual WANs Can be configured for Smartlink backup or load balance WAN Type DHCP, Static IP, PPPoE, PPTP, Dynamic DNS Cisco Small Business RV0xx Series Routers Administration Guide...
Page 195
Support Internet Key Exchange IPSec NAT-T Supported for gateway-to-gateway and client-to- gateway tunnels Advanced Options DPD, Split DNS, VPN Backup VPN Passthrough PPTP, L2TP, IPSec Management Web-Based HTTPS SNMP Supports SNMP v1 and v2c Cisco Small Business RV0xx Series Routers Administration Guide...
Reset Cabling Type Category 5 Ethernet Status Lights (LEDs) Diag, System, LAN/Act 1 to 13, Internet/Act 1 to 7, DMZ Operating System Linux Performance NAT Throughput 200 Mbps IPSec Throughput 97 Mbps Cisco Small Business RV0xx Series Routers Administration Guide...
Page 197
Upstream/downstream bandwidth can be configured per service Priority Each service can be mapped to one of the 3 priority levels IPSec 100 IPSec tunnels for branch office connectivity QuickVPN 50 QuickVPN users for remote client access Cisco Small Business RV0xx Series Routers Administration Guide...
Page 198
FCC Class B, CE Class A Operating Temp. 0 to 40C (32 to 104F) Storage Temp. 0 to 70C (32 to 158F) Operating Humidity 10 to 85% noncondensing Storage Humidity 5 to 90% noncondensing Cisco Small Business RV0xx Series Routers Administration Guide...
Where to Go From Here Cisco provides a wide range of resources to help you and your customer obtain the full benefits of your Cisco Small Business router. Support Cisco Small Business www.cisco.com/go/smallbizsupport Support Community Cisco Small Business www.cisco.com/go/smallbizhelp Support and Resources Cisco Small Business www.cisco.com/go/software...