Networking-Blog

My WordPress Blog

Zyxel Configuration

Edit Zyxel Configuration

ras> sys edit autoexec

EDIT cmd: q(uit) x(save)d(delete)r(replace)

sys errctl 0
sys trcl level 5
sys trcl type 1180
sys trcp cr 64 96
sys trcl sw off
sys trcp sw off
ip tcp mss 512
ip tcp limit 2
ip tcp irtt 65000
ip tcp window 2
ip tcp ceiling 6000
ip rip activate
ipsec swSkipOverlapIp
swSkipOverlapIp on
ipsec timer chk_conn 0
ppp ipcp compress off
sys wdog sw on
ip icmp discovery enif
bridge mode 1
sys quick enable
wan adsl rate off
ether driver qroute 2
EOF

wan adsl rateadap on
Line-Rate Adaptive mechanism is for ADSL CPE system which try to
reach the maximum line rate that DSLAM can provide.

The drawback is ADSL CPE system has to force the line to drop and then sync up with
maximal rate. But actually the line rate is decided by DSLAM.
When this mechanism is turned on, CPE will monitor the line rate and
record maximum line rate. Once the line rate is lower than the
maximum value which CPE system recorded before, system will drop the
line and try to sync with better line rate.

Show Commands :

wan adsl opmode = DSL standard: ADSL_G.dmt
wan adsl driver setphy disp
wan adsl rateadap on
wan adsl chandata
wan adsl linedata near
wan adsl driver setphy disp
wan adsl driver info
wan adsl statuswan
wan adsl close
wan adsl open

DSL Operating Mode :

wan adsl opencmd gdmt
wan adsl opencmd adsl2
wan adsl opencmd adsl2+
wan adsl opencmd glite

Zyxel Noise Margin

you can also slightly tweak the target snr margin to connect a lower rate and increase stability.
With adslmax it only seems to work when increasing the snr.
 
wan adsl targetnoise X
 
where X is between 0xfa (-6) and 0x06 (+6) where each point is .5db of snr, so..
 
0xfa reduces the target by 3db,
0xfc reduces the target by 2db,
0x00 does nothing,
0x02 increases the target by 1db,

wan adsl targetnoise 0x06  =  command  is meant to increase the target SNR by 3db

wan adsl close
wan adsl driver dnmaxbits 10
wan adsl open

(where n is 0 to 15, 0 is slowest, 15 is fastest)

All the dnmaxbits 10 command seems to do is cap the rate per tone to “a” which affects the faster lower tones but not the higher ones which are probably the most marginal. What I really want to do is increase the SNR in exchange for a slower speed. The command  is meant to increase the target SNR by 3db but it makes no difference I can see.

wan adsl opmode ( check dsl standard status)
ADSL_G.dmt / ADSL2+

Depends on which ISP you are using.  you may need to change it to GDMT mode.

1 telnet to the zyxel = click ‘start’ then ‘run’ and type ‘telnet 192.168.1.1′
2 login (password is the same as the web interface)
3 type ’24’ – to access the system maintainence menu
4 type ‘8’ – to access the command line
5 type ‘wan adsl opencmd gdmt’ – sets the adsl to gdmt.
6 save, exit, then power off the modem and power it back on

Linux Zyxel Ipsec VPN Configuration

Zyxel Router Linux Config.

Phase 1 (IKE) = Lifetime   8Hrs
Phase 2 (IPSEC) = Keylife 24hrs

86400  = 24hrs = Seconds
28800  = 8hrs    = Seconds
1440     = 24hrs  = Minutes
480       = 8hrs     = Minutes

Linux Ipsec Directory Conf :

conn commtest
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
left= “Remote Peer Address”
leftsubnet= “Remote Subnet Address”
right=”Local Wan Address”
rightsubnet= “Local Subnet Address”
keyingtries=3
pfs=yes
rekey=yes
auto=start
keyexchange=ike
ikelifetime=8h
keylife=24h
dpdaction=restart
dpddelay=30
dpdtimeout=120

ipsec.secrets.conf

80.74.16.251 1.1.1.1 : PSK “commsvpn”
80.74.16.251 1.1.1.2 : PSK “commsvpn”
80.74.16.251 1.1.1.3 : PSK “commsvpn”
80.74.16.251 1.1.1.4 : PSK “commsvpn”
80.74.16.251 1.1.1.5 : PSK “commsvpn”

Rereadsecrets Command Forces OpenSWAN to reload the secrets from the ipsec.secrets file

sudo ipsec auto –rereadsecrets