Monitor
The Port Statistics Screen
Use this screen to look at packet statistics for each Gigabit Ethernet port.
Monitor > Traffic Statistics > Port Statistics  
Label
Description
Poll Interval
Enter how often you want this window to be updated automatically, and click Set Interval.
Set Interval
Click this to set the Poll Interval the screen uses.
Stop
Click this to stop the window from updating automatically. You can start it again by setting the Poll Interval and clicking Set Interval.
Switch to Graphic View
Click this to display the port statistics as a line graph.
#
This field is a sequential value, and it is not associated with a specific port.
Port
This field displays the physical port number.
Status
This field displays the current status of the physical port.
Down - The physical port is not connected.
Speed / Duplex - The physical port is connected. This field displays the port speed and duplex setting (Full or Half).
TxPkts
This field displays the number of packets transmitted from the Zyxel Device on the physical port since it was last connected.
RxPkts
This field displays the number of packets received by the Zyxel Device on the physical port since it was last connected.
Collisions
This field displays the number of collisions on the physical port since it was last connected.
Tx B/s
This field displays the transmission speed, in bytes per second, on the physical port in the one-second interval before the screen updated.
Rx B/s
This field displays the reception speed, in bytes per second, on the physical port in the one-second interval before the screen updated.
Up Time
This field displays how long the physical port has been connected.
System Up Time
This field displays how long the Zyxel Device has been running since it last restarted or was turned on.
Port Statistics Graph
Use this screen to look at a line graph of packet statistics for each physical port.
Monitor > Traffic Statistics > Port Statistics > Switch to Graphic View 
Label
Description
Refresh Interval
Enter how often you want this window to be automatically updated.
Refresh Now
Click this to update the information in the window right away.
Port Selection
Select the number of the physical port for which you want to display graphics.
Switch to Grid View
Click this to display the port statistics as a table.
bps
The y-axis represents the speed of transmission or reception.
time
The x-axis shows the time period over which the transmission or reception occurred
TX
This line represents traffic transmitted from the Zyxel Device on the physical port since it was last connected.
RX
This line represents the traffic received by the Zyxel Device on the physical port since it was last connected.
Last Update
This field displays the date and time the information in the window was last updated.
Interface Status
This screen lists all of the Zyxel Device’s interfaces and gives packet statistics for them.
Monitor > Traffic Statistics > Interface Summary
Label
Description
Interface Status
If an Ethernet interface does not have any physical ports associated with it, its entry is displayed in light gray text.
Name
This field displays the name of each interface. If there is an Expand icon (plus-sign) next to the name, click this to look at the status of virtual interfaces on top of this interface.
Port/Binding
This field displays the physical port number.
Status
This field displays the current status of each interface. The possible values depend on what type of interface it is.
For Ethernet interfaces:
Inactive - The Ethernet interface is disabled.
Down - The Ethernet interface does not have any physical ports associated with it or the Ethernet interface is enabled but not connected.
Speed / Duplex - The Ethernet interface is enabled and connected. This field displays the port speed and duplex setting (Full or Half).
For cellular (mobile broadband) interfaces, see USB Storage Screen for the status that can appear.
For the auxiliary interface:
Inactive - The auxiliary interface is disabled.
Connected - The auxiliary interface is enabled and connected.
Disconnected - The auxiliary interface is not connected.
For virtual interfaces, this field always displays Up. If the virtual interface is disabled, it does not appear in the list.
For VLAN and bridge interfaces, this field always displays Up. If the VLAN or bridge interface is disabled, it does not appear in the list.
For PPP interfaces:
Connected - The PPP interface is connected.
Disconnected - The PPP interface is not connected.
If the PPP interface is disabled, it does not appear in the list.
For WLAN interfaces:
Up - The WLAN interface is enabled.
Down - The WLAN interface is disabled.
Zone
This field displays the zone to which the interface is assigned.
IP Addr/Netmask
This field displays the current IP address and subnet mask assigned to the interface. If the IP address and subnet mask are 0.0.0.0, the interface is disabled or did not receive an IP address and subnet mask via DHCP.
If this interface is a member of an active virtual router, this field displays the IP address it is currently using. This is either the static IP address of the interface (if it is the master) or the management IP address (if it is a backup).
IP Assignment
This field displays how the interface gets its IP address.
Static - This interface has a static IP address.
DHCP Client - This interface gets its IP address from a DHCP server.
Services
This field lists which services the interface provides to the network. Examples include DHCP relay, DHCP server, DDNS, RIP, and OSPF. This field displays n/a if the interface does not provide any services to the network.
Action
Use this field to get or to update the IP address for the interface. Click Renew to send a new DHCP request to a DHCP server. Click Connect to try to connect a PPPoE/PPTP interface. If the interface cannot use one of these ways to get or to update its IP address, this field displays n/a.
Tunnel Interface Status
This displays the details of the Zyxel Device’s configured tunnel interfaces.
Name
This field displays the name of the interface.
Status
The activate (light bulb) icon is lit when the entry is active and dimmed when the entry is inactive.
Zone
This field displays the zone to which the interface is assigned.
IP Address
This is the IP address of the interface. If the interface is active (and connected), the Zyxel Device tunnels local traffic sent to this IP address to the Remote Gateway Address.
My Address
This is the interface or IP address uses to identify itself to the remote gateway. The Zyxel Device uses this as the source for the packets it tunnels to the remote gateway.
Remote Gateway Address
This is the IP address or domain name of the remote gateway to which this interface tunnels traffic.
Mode
This field displays the tunnel mode that you are using.
IPv6 Interface Status
If an Ethernet interface does not have any physical ports associated with it, its entry is displayed in light gray text.
Name
This field displays the name of each interface. If there is an Expand icon (plus-sign) next to the name, click this to look at the status of virtual interfaces on top of this interface.
Port
This field displays the physical port number.
Status
This field displays the current status of each interface. The possible values depend on what type of interface it is.
For Ethernet interfaces:
Inactive - The Ethernet interface is disabled.
Down - The Ethernet interface does not have any physical ports associated with it or the Ethernet interface is enabled but not connected.
Speed / Duplex - The Ethernet interface is enabled and connected. This field displays the port speed and duplex setting (Full or Half).
For cellular (mobile broadband) interfaces, see USB Storage Screen for the status that can appear.
For the auxiliary interface:
Inactive - The auxiliary interface is disabled.
Connected - The auxiliary interface is enabled and connected.
Disconnected - The auxiliary interface is not connected.
For virtual interfaces, this field always displays Up. If the virtual interface is disabled, it does not appear in the list.
For VLAN and bridge interfaces, this field always displays Up. If the VLAN or bridge interface is disabled, it does not appear in the list.
For PPP interfaces:
Connected - The PPP interface is connected.
Disconnected - The PPP interface is not connected.
If the PPP interface is disabled, it does not appear in the list.
For WLAN interfaces:
Up - The WLAN interface is enabled.
Down - The WLAN interface is disabled.
Zone
This field displays the zone to which the interface is assigned.
IP Address
This field displays the current IPv6 address assigned to the interface. If the IPv6 address is ::, the interface is disabled or did not receive an IPv6 address via DHCP.
If this interface is a member of an active virtual router, this field displays the IPv6 address it is currently using. This is either the static IPv6 address of the interface (if it is the master) or the management IPv6 address (if it is a backup).
Services
This field lists which services the interface provides to the network. Examples include DHCP relay, DHCP server, DDNS, RIP, and OSPF. This field displays n/a if the interface does not provide any services to the network.
Action
Use this field to get or to update the IP address for the interface. Click Renew to send a new DHCP request to a DHCP server. Click Connect to try to connect a PPPoE/PPTP interface. If the interface cannot use one of these ways to get or to update its IP address, this field displays n/a.
Interface Statistics
This table provides packet statistics for each interface.
Refresh
Click this button to update the information on the screen.
Name
This field displays the name of each interface. If there is a Expand icon (plus-sign) next to the name, click this to look at the statistics for virtual interfaces on top of this interface.
Status
This field displays the current status of the interface.
Down - The interface is not connected.
Speed / Duplex - The interface is connected. This field displays the port speed and duplex setting (Full or Half).
This field displays Connected and the accumulated connection time (hh:mm:ss) when the PPP interface is connected.
TxPkts
This field displays the number of packets transmitted from the Zyxel Device on the interface since it was last connected.
RxPkts
This field displays the number of packets received by the Zyxel Device on the interface since it was last connected.
Tx B/s
This field displays the transmission speed, in bytes per second, on the interface in the one-second interval before the screen updated.
Rx B/s
This field displays the reception speed, in bytes per second, on the interface in the one-second interval before the screen updated.
Traffic Statistics
This screen provides basic information about the following for example:
Most-visited Web sites and the number of times each one was visited. This count may not be accurate in some cases because the Zyxel Device counts HTTP GET packets.
Most-used protocols or service ports and the amount of traffic on each one
LAN IP with heaviest traffic and how much traffic has been sent to and from each one
You use the Traffic Statistics screen to tell the Zyxel Device when to start and when to stop collecting information for these reports. You cannot schedule data collection; you have to start and stop it manually on the Traffic Statistics screen.
Monitor > Traffic Statistics > Traffic Statistics 
Label
Description
Data Collection
Collect Statistics
Select this to have the Zyxel Device collect data for the report. If the Zyxel Device has already been collecting data, the collection period displays to the right. The progress is not tracked here real-time, but you can click the Refresh button to update it.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
Statistics
Interface
Select the interface from which to collect information. You can collect information from Ethernet, VLAN, bridge and PPPoE/PPTP interfaces.
Sort By
Select the type of report to display. Choices are:
Host IP Address/User - displays the IP addresses or users with the most traffic and how much traffic has been sent to and from each one.
Service/Port - displays the most-used protocols or service ports and the amount of traffic for each one.
Web Site Hits - displays the most-visited Web sites and how many times each one has been visited.
Country - displays the countries with the most traffic and the amount of traffic for each one.
Each type of report has different information in the report (below).
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
 
These fields are available when the Traffic Type is Host IP Address/User.
#
This field is the rank of each record. The IP addresses and users are sorted by the amount of traffic.
Direction
This field indicates whether the IP address or user is sending or receiving traffic.
Ingress- traffic is coming from the IP address or user to the Zyxel Device.
Egress - traffic is going from the Zyxel Device to the IP address or user.
IP Address/User
This field displays the IP address or user in this record. The maximum number of IP addresses or users in this report is indicated in Maximum Values for Reports.
Amount
This field displays how much traffic was sent or received from the indicated IP address or user. If the Direction is Ingress, a red bar is displayed; if the Direction is Egress, a blue bar is displayed. The unit of measure is bytes, Kbytes, Mbytes or Gbytes, depending on the amount of traffic for the particular IP address or user. The count starts over at zero if the number of bytes passes the byte count limit.
 
These fields are available when the Traffic Type is Service/Port.
#
This field is the rank of each record. The protocols and service ports are sorted by the amount of traffic.
Service/Port
This field displays the service and port in this record.
Protocol
This field indicates what protocol the service was using.
Direction
This field indicates whether the indicated protocol or service port is sending or receiving traffic.
Ingress - traffic is coming into the Zyxel Devicethrough the interface
Egress - traffic is going out from the Zyxel Device through the interface
Amount
This field displays how much traffic was sent or received from the indicated service / port. If the Direction is Ingress, a red bar is displayed; if the Direction is Egress, a blue bar is displayed. The unit of measure is bytes, Kbytes, Mbytes, Gbytes, or Tbytes, depending on the amount of traffic for the particular protocol or service port. The count starts over at zero if the number of bytes passes the byte count limit.
 
These fields are available when the Traffic Type is Web Site Hits.
#
This field is the rank of each record. The domain names are sorted by the number of hits.
Web Site
This field displays the domain names most often visited. The Zyxel Device counts each page viewed on a Web site as another hit.
Hits
This field displays how many hits the Web site received. The Zyxel Device counts hits by counting HTTP GET packets. Many Web sites have HTTP GET references to other Web sites, and the Zyxel Device counts these as hits too. The count starts over at zero if the number of hits passes the hit count limit.
 
These fields are available when the Traffic Type is Country.
#
This field is the rank of each record. The country name is sorted by the amount of traffic.
Direction
This field indicates whether the indicated protocol or service port is sending or receiving traffic.
Ingress - traffic is coming into the Zyxel Devicethrough the interface
Egress - traffic is going out from the Zyxel Device through the interface
Country Name
This field displays the name of the country.
Country
This field displays the country code.
Amount
This field displays how much traffic was sent or received from the indicated country. If the Direction is Ingress, a red bar is displayed; if the Direction is Egress, a blue bar is displayed. The unit of measure is bytes, Kbytes, Mbytes, Gbytes, or Tbytes, depending on the amount of traffic for the particular protocol or service port. The count starts over at zero if the number of bytes passes the byte count limit.
Ingress - traffic is coming into the Zyxel Device from the country.
Egress - traffic is going from the Zyxel Device to the country.
The following table displays the maximum number of records shown in the report, the byte count limit, and the hit count limit.
Maximum Values for Reports 
Label
Description
Maximum Number of Records
20
Byte Count Limit
264 bytes; this is just less than 17 million terabytes.
Hit Count Limit
264 hits; this is over 1.8 x 1019 hits.
The Session Monitor Screen
The Session Monitor screen displays all established sessions that pass through the Zyxel Device for debugging or statistical analysis. It is not possible to manage sessions in this screen. The following information is displayed.
User who started the session
Protocol or service port used
Source address
Destination address
Number of bytes received (so far)
Number of bytes transmitted (so far)
Duration (so far)
You can look at all established sessions that passed through the Zyxel Device by user, service, source IP address, or destination IP address. You can also filter the information by user, protocol / service or service group, source address, and/or destination address and view it by user.
The following table describes the labels in this screen.
Monitor > Traffic Statistics > Session Monitor 
Label
Description
View
Select how you want the established sessions that passed through the Zyxel Device to be displayed. Choices are:
sessions by users - display all active sessions grouped by user
sessions by services - display all active sessions grouped by service or protocol
sessions by source IP - display all active sessions grouped by source IP address
session by source region - display all active sessions grouped by where the traffic is coming from by country
sessions by destination IP - display all active sessions grouped by destination IP address
sessions by destination region - display all active sessions grouped by where the traffic is going to by country
all sessions - filter the active sessions by the User, Service, Source Address, and Destination Address, and display each session individually (sorted by user).
Refresh
Click this button to update the information on the screen. The screen also refreshes automatically when you open and close the screen.
 
The User, Service, Source Address, Destination Address, Source Country and Destination Country fields display if you view all sessions. Select your desired filter criteria and click the Refresh button to filter the list of sessions.
User
This field displays when View is set to all sessions. Type the user whose sessions you want to view. It is not possible to type part of the user name or use wildcards in this field; you must enter the whole user name.
Service
This field displays when View is set to all sessions. Select the service or service group whose sessions you want to view. The Zyxel Device identifies the service by comparing the protocol and destination port of each packet to the protocol and port of each services that is defined.
Source Address
This field displays when View is set to all sessions. Type the source IP address whose sessions you want to view. You cannot include the source port.
Source Country
This field displays when View is set to all sessions. Select the country where the traffic is coming from.
Destination
Address
This field displays when View is set to all sessions. Type the destination IP address whose sessions you want to view. You cannot include the destination port.
Destination Country
This field displays when View is set to all sessions. Select the country where the traffic is going to.
Search
Click this to display all sessions in the table below according to the criteria you defined above.
Clear
Clear All
Administrators can use these buttons to forcibly terminate selected TCP/UDP connections. Select one or multiple connections and then click Clear; click Clear All to terminate all connections displayed. Cleared sessions display on the Log > View Log screen.
#
This field is the rank of each record. The names are sorted by the name of user in active session. You can use the pull down menu on the right to choose sorting method.
User
This field displays the user in each active session.
If you are looking at the sessions by users (or all sessions) report, click + or - to display or hide details about a user’s sessions.
Service
This field displays the protocol used in each active session.
If you are looking at the sessions by services report, click + or - to display or hide details about a protocol’s sessions.
Source
This field displays the source IP address and port in each active session.
If you are looking at the sessions by source IP report, click + or - to display or hide details about a source IP address’s sessions.
Source Country
This field displays the source country in each active session.
Destination
This field displays the destination IP address and port in each active session.
If you are looking at the sessions by destination IP report, click + or - to display or hide details about a destination IP address’s sessions.
Destination Country
This field displays the destination country in each active session.
Rx
This field displays the amount of information received by the source in the active session.
Tx
This field displays the amount of information transmitted by the source in the active session.
Duration
This field displays the length of the active session in seconds.
DHCP Table
Use this screen to look at a list of interfaces and their DHCP-assigned IP addresses.
The following table describes the labels in this screen.
Monitor > Network Status > DHCP Table 
Label
Description
Current DHCP List
 
Interface
Select a Zyxel Device interface that has DHCP enabled to show to which devices it has assigned DHCP IP addresses.
Keyword
Enter a keyword to display the interfaces and their information, such as IP addresses, MAC addresses and so on. The field is case-sensitive.
Search
Click to update the list of interfaces shown in the table below based on the search criteria.
Your search criteria is retained when navigating between screens.
Reset
Click to return this search criteria to the factory defaults and display all interfaces with DHCP enabled.
Release
Select an entry and click on this button to let other devices use the dynamic DHCP that is currently assigned to the selected entry.
Reserve
Select an entry and click on this button to set the entry as a static DHCP entry. The IP address will be reserved for the MAC address after you click this button.
Unreserve
Select an entry and click on this button to set the entry from a static DHCP entry to a dynamic DHCP entry. The IP address is assigned to a DHCP client.
Export
To export as a csv file on your computer, select them and click Export. Click Save in the file download dialogue box and then select a location and name for the file. You can edit the file after it is saved on your computer.
To import the file you export here to recover the settings you configure now later on the Zyxel Device, go to Configuration> Network> Interface> Ethernet/VLAN> DCHP Setting.
#
This field is a sequential value, and it is not associated with a specific entry.
Interface
This field identifies the interface that assigned an IP address to a DHCP client.
IP Address
This field displays the IP address currently assigned to a DHCP client or reserved for a specific MAC address. Click the column’s heading cell to sort the table entries by IP address. Click the heading cell again to reverse the sort order.
Host Name
This field displays the name used to identify this device on the network (the computer name). The Zyxel Device learns these from the DHCP client requests. “None” shows here for a static DHCP entry.
MAC Address
This field displays the MAC address to which the IP address is currently assigned or for which the IP address is reserved. Click the column’s heading cell to sort the table entries by MAC address. Click the heading cell again to reverse the sort order.
Expiration Time
This displays the date and time the DHCP-assigned address will be renewed.
Last Access
This is when the last time any traffic pass through the interface.
Description
For a static DHCP entry, the host name or the description you configured shows here. This field is blank for dynamic DHCP entries.
Static
This field displays if the address in the IP address field is reserved for the clients connected to this interface.
Yes means that the clients connected to the interface will always get the IP address shown in the table.
Device Insight
The Device Insight screen displays the status of the clients connected to the Zyxel Device, such as if a client is sending traffic to the Zyxel Device or if a client’s MAC address is in the CDR block list. See Collaborative Detection & Response for more information on CDR.
It also displays the basic information and the status of the clients. The clients show in this screen may include clients connected to the Zyxel Device:
A- Using wired connections.
B- Through access points (APs) using wired connections.
C- Through access points (APs) using WiFi connections.
 
The following table describes the labels in this screen.
Monitor > Device Insight 
label
description
Hide/Show Advanced Settings
Click this button to display a greater or lesser number of configuration fields.
Edit
Double-click an entry or select it and click Edit to modify the entry’s settings in the Description field.
Download
Select an entry and click Download to download the client’s basic information, such as MAC address or DHCP option, as a file to your computer. You may need to send this file to customer support for troubleshooting.
Add to block list
Select an entry and click Add to block list to stop the selected client from connecting to the Zyxel Device.
Remove from block list
Select an entry and click Remove from block list to allow the selected client to connect to the Zyxel Device.
#
This field is a sequential value, and it is not associated with a specific service.
Status
This field displays the status of the clients.
On line ()- The client is sending traffic to the Zyxel Device.
Off line ()- The client has not send traffic to the Zyxel Device for a certain period of time.
Block ()- The client is blocked from the connection to the Zyxel Device.
CDR Block ()- The client’s MAC address is blocked by CDR.
MAC Address
This field displays the MAC address of the client.
IP Address
This field displays the IP address of the client.
Hostname
This field displays the name used to identify this device on the network.
Manufacturer
This field displays the manufacturer of the client, such as Apple or Samsung.
Category
This field displays the type of the device of the client, such as printer or smart TV.
OS
This field displays the operating system of the client.
OS Version
This field displays the version of the operating system of the client.
Type
This field displays the model names of the client.
First-seen
This field displays the time when the client first sends traffic to the Zyxel Device.
Last-seen
This field displays the time when the client last sends traffic to the Zyxel Device.
User
This field displays the type of user account the client uses. See User/Group for more information the user account types.
Auth method
This field displays the authentication method that is used to authenticate the client.
TX rate (Kbps)
This field displays the maximum transmission rate of the client to which the Zyxel Device is connected.
RX rate (Kbps)
This field displays the maximum reception rate of the client to which the Zyxel Device is connected.
Connected to
This field displays if the client is connected directly to the Zyxel Device or to an AP that is connected to the Zyxel Device.
Description
This field displays the descriptive name of the client.
The Device Insight Edit Screen
Use this screen to edit the description for connected clients.
The following table describes the labels in this screen.
Monitor > Network Status > Device Insight > Edit
label
description
Description
Enter a descriptive name for this client. You can use up to 31 characters, spaces and underscores are allowed.
OK
Click OK to save your changes back to the Zyxel Device.
Cancel
Click Cancel to exit this screen without saving your changes.
Login Users
Use this screen to look at a list of the users currently logged into the Zyxel Device.
Monitor > Network Status > Login Users 
Label
Description
Force Logout
Select a user ID and click this icon to end a user’s session.
#
This field is a sequential value and is not associated with any entry.
User ID
This field displays the user name of each user who is currently logged in to the Zyxel Device.
Reauth/Lease Time
This field displays the amount of reauthentication time remaining and the amount of lease time remaining for each user
Session Timeout
This field displays the total account of time the account (authenticated by an external server) can use to log into the Zyxel Device or access the Internet through the Zyxel Device.
This shows unlimited for an administrator account.
Type
This field displays the way the user logged in to the Zyxel Device.
IP Address
This field displays the IP address of the computer used to log in to the Zyxel Device.
Country
The Internet Assigned Numbers Authority (IANA) has reserved the following blocks of Private IP addresses specifically for private networks:
10.0.0.0-10.255.255.255
172.16.0.0-172.31.255.255
192.168.0.0-192.168.255.255
224.0.0.0-239.255.255.255
MAC
This field displays the MAC address of the computer used to log in to the Zyxel Device.
User Info
This field displays the types of user accounts the Zyxel Device uses. If the user type is ext-user (external user), this field will show its external-group information when you move your mouse over it.
If the external user matches two external-group objects, both external-group object names will be shown.
Acct. Status
For a captive portal login, this field displays the accounting status of the account used to log into the Zyxel Device.
Accounting-on means accounting is being performed for the user login.
Accounting-off means accounting has stopped for this user login.
A “-” displays if accounting is not enabled for this login.
RADIUS Profile Name
This field displays the name of the RADIUS profile used to authenticate the login through the captive portal. N/A displays for logins that do not use the captive portal and RADIUS server authentication.
Refresh
Click this button to update the information on the screen.
Dynamic Guest
A dynamic guest account has a dynamically-created user name and password that allows a guest user to access the Internet or the Zyxel Device’s services in a specified period of time. Multiple dynamic guest accounts can be automatically generated at one time for guest users by using the web configurator and the guest-manager account. Guest users can log in with the dynamic accounts when connecting to an SSID for a specified time unit. Use this screen to look at a list of dynamic guest user accounts on the Zyxel Device’s local database.
The following table describes the labels in this screen.
Monitor > Network Status > Dynamic Guest 
Label
Description
Dynamic Guest List
Remove
Select an entry and click this button to remove it from the list.
*If you delete a valid user account which is in use, the Zyxel Device ends the user session.
#
This field is a sequential value and is not associated with any entry.
Status
This field displays whether the dynamic user account is active or not.
Username
This field displays the user name of the dynamic user account.
Create Time
This field displays when the dynamic user account was created.
Remaining Time
This field displays the amount of Internet access time remaining for each dynamic user account.
Time Period
This field displays the duration of Internet access for the dynamic user account.
Expiration Time
This field displays the date and time the Internet access becomes invalid. Once the time allocated to a dynamic account is used up or a dynamic account remains unused after the expiration time, the account is deleted from the account list.
Quota (T/U/D)
This field displays how much data in both directions (Total) or upstream data (Upload) and downstream data (Download) can be transmitted through the WAN interface before the Internet access expires.
Remaining Quota
This field displays how much more data can be transmitted through the WAN interface before the Internet access expires.
Bandwidth (U/D)
This field displays the maximum upstream (Upload) and downstream (Download) bandwidth allowed for the dynamic user account in kilobits per second.
Charge
This field displays access price per time unit.
Payment Info
This field displays the method of payment for each account.
Real Name
This field displays the user’s name of the account.
Email
This field displays the email address of the account.
Phone Number
This displays the user’s phone number.
User Role
This field displays the role of the account.
The following table describes the icons in this screen.
Monitor > Network Status > Dynamic Guest Icons 
Label
Description
This guest account is un-used.
This guest account is in use and online.
This guest account has been used but is offline now.
This guest account expired.
This guest account has been deleted.
IGMP Statistics
The Internet Group Management Protocol (IGMP) Statistics is used by Zyxel Device IP hosts to inform adjacent router about multicast group memberships. It can also be used for one-to-many networking applications such as online streaming video and gaming, distribution of company newsletters, updating address book of mobile computer users in the field allowing more efficient use of resources when supporting these types of applications.
Monitor > Network Status > IGMP Statistics
LABEL
Description
#
This field is a sequential value, and it is not associated with a specific I GMP Statistics.
Group
This field displays the group of devices in the IGMP.
Source IP
This field displays the host source IP information of the IGMP.
Incoming Interface
This field displays the incoming interface that’s connected on the IGMP.
Packet Count
This field displays the packet size of the data being transferred.
Bytes
This field displays the size of the data being transferred in Byes.
Outgoing Interface
This field displays the outgoing interface that’s connected on the IGMP.
Refresh
Click this button to update the information on the screen.
DDNS Status
The DDNS Status screen shows the status of the Zyxel Device’s DDNS domain names.
Monitor > Network Status > DDNS Status 
Label
Description
Update
Click this to have the Zyxel Device update the profile to the DDNS server. The Zyxel Device attempts to resolve the IP address for the domain name.
#
This field is a sequential value, and it is not associated with a specific DDNS server.
Profile Name
This field displays the descriptive profile name for this entry.
Domain Name
This field displays each domain name the Zyxel Device can route.
Effective IP
This is the (resolved) IP address of the domain name.
Last Update
This shows whether the last attempt to resolve the IP address for the domain name was successful or not. Updating means the Zyxel Device is currently attempting to resolve the IP address for the domain name.
Last Update Time
This shows when the last attempt to resolve the IP address for the domain name occurred (in year-month-day hour:minute:second format).
Refresh
Click this button to update the information on the screen.
IP/MAC Binding
This screen lists the devices that have received an IP address from Zyxel Device interfaces with IP/MAC binding enabled and have ever established a session with the Zyxel Device. Devices that have never established a session with the Zyxel Device do not display in the list.
Monitor > Network Status > IP/MAC Binding  
Label
Description
Interface
Select a Zyxel Device interface that has IP/MAC binding enabled to show to which devices it has assigned an IP address.
#
This field is a sequential value, and it is not associated with a specific IP/MAC binding entry.
IP Address
This is the IP address that the Zyxel Device assigned to a device.
Host Name
This field displays the name used to identify this device on the network (the computer name). The Zyxel Device learns these from the DHCP client requests.
MAC Address
This field displays the MAC address to which the IP address is currently assigned.
Last Access
This is when the device last established a session with the Zyxel Device through this interface.
Description
This field displays the description of the IP/MAC binding.
Refresh
Click this button to update the information on the screen.
Cellular Status
This screen displays your mobile broadband connection status.
Monitor > Network Status > Cellular Status 
Label
Description
Refresh
Click this button to update the information on the screen.
More Information
Click this to display more information on your mobile broadband, such as the signal strength, IMEA/ESN and IMSI. This is only available when the mobile broadband device attached and activated on your Zyxel Device.
#
This field is a sequential value, and it is not associated with any interface.
Extension Slot
This field displays where the entry’s cellular card is located.
Connected Device
This field displays the model name of the cellular card.
Status
No device - no mobile broadband device is connected to the Zyxel Device.
No Service - no mobile broadband network is available in the area; you cannot connect to the Internet.
Limited Service - returned by the service provider in cases where the SIM card is expired, the user failed to pay for the service and so on; you cannot connect to the Internet.
Device detected - displays when you connect a mobile broadband device.
Device error - a mobile broadband device is connected but there is an error.
Probe device fail - the Zyxel Device’s test of the mobile broadband device failed.
Probe device ok - the Zyxel Device’s test of the mobile broadband device succeeded.
Init device fail - the Zyxel Device was not able to initialize the mobile broadband device.
Init device ok - the Zyxel Device initialized the mobile broadband card.
Check lock fail - the Zyxel Device’s check of whether or not the mobile broadband device is locked failed.
Device locked - the mobile broadband device is locked.
SIM error - there is a SIM card error on the mobile broadband device.
SIM locked-PUK - the PUK is locked on the mobile broadband device’s SIM card.
SIM locked-PIN - the PIN is locked on the mobile broadband device’s SIM card.
Unlock PUK fail - Your attempt to unlock a WCDMA mobile broadband device’s PUK failed because you entered an incorrect PUK.
Unlock PIN fail - Your attempt to unlock a WCDMA mobile broadband device’s PIN failed because you entered an incorrect PIN.
Unlock device fail - Your attempt to unlock a CDMA2000 mobile broadband device failed because you entered an incorrect device code.
Device unlocked - You entered the correct device code and unlocked a CDMA2000 mobile broadband device.
Get dev-info fail - The Zyxel Device cannot get cellular device information.
Get dev-info ok - The Zyxel Device succeeded in retrieving mobile broadband device information.
Searching network - The mobile broadband device is searching for a network.
Get signal fail - The mobile broadband device cannot get a signal from a network.
Network found - The mobile broadband device found a network.
Apply config - The Zyxel Device is applying your configuration to the mobile broadband device.
Inactive - The mobile broadband interface is disabled.
Active - The mobile broadband interface is enabled.
Incorrect device - The connected mobile broadband device is not compatible with the Zyxel Device.
Correct device - The Zyxel Device detected a compatible mobile broadband device.
Set band fail - Applying your band selection was not successful.
Set band ok - The Zyxel Device successfully applied your band selection.
Set profile fail - Applying your ISP settings was not successful.
Set profile ok - The Zyxel Device successfully applied your ISP settings.
PPP fail - The Zyxel Device failed to create a PPP connection for the cellular interface.
Need auth-password - You need to enter the password for the mobile broadband card on the cellular edit screen.
Device ready - The Zyxel Device successfully applied all of your configuration and you can use the mobile broadband connection.
Service Provider
This displays the name of your network service provider. This shows Limited Service if the service provider has stopped service to the mobile broadband card. For example if the bill has not been paid or the account has expired.
Cellular System
This field displays what type of cellular network the mobile broadband connection is using. The network type varies depending on the mobile broadband card you inserted and could be UMTS, UMTS/HSDPA, GPRS or EDGE when you insert a GSM mobile broadband card, or 1xRTT, EVDO Rev.0 or EVDO Rev.A when you insert a CDMA mobile broadband card.
Signal Quality
This displays the strength of the signal. The signal strength mainly depends on the antenna output power and the distance between your Zyxel Device and the service provider’s base station.
More Information
This screen displays more information on your mobile broadband, such as the signal strength, IMEA/ESN and IMSI that helps identify your mobile broadband device and SIM card.
Note: This screen is only available when the mobile broadband device is attached to and activated on the Zyxel Device.
Monitor > Network Status > Cellular Status > More Information 
Label
Description
Extension Slot
This field displays where the entry’s cellular card is located.
Service Provider
This displays the name of your network service provider. This shows Limited Service if the service provider has stopped service to the mobile broadband card. For example if the bill has not been paid or the account has expired.
Cellular System
This field displays what type of cellular network the mobile broadband connection is using. The network type varies depending on the mobile broadband card you inserted and could be UMTS, UMTS/HSDPA, GPRS or EDGE when you insert a GSM mobile broadband card, or 1xRTT, EVDO Rev.0 or EVDO Rev.A when you insert a CDMA mobile broadband card.
Signal Strength
This is the Signal Quality measured in dBm.
Signal Quality
This displays the strength of the signal. The signal strength mainly depends on the antenna output power and the distance between your Zyxel Device and the service provider’s base station.
Device Manufacturer
This shows the name of the company that produced the mobile broadband device.
Device Model
This field displays the model name of the cellular card.
Device Firmware
This shows the software version of the mobile broadband device.
Device IMEI/ESN
IMEI (International Mobile Equipment Identity) is a 15-digit code in decimal format that identifies the mobile broadband device.
ESN (Electronic Serial Number) is an 8-digit code in hexadecimal format that identifies the mobile broadband device.
SIM Card IMSI
IMSI (International Mobile Subscriber Identity) is a 15-digit code that identifies the SIM card.
UPnP Port Status
Use this screen to look at the NAT port mapping rules that UPnP creates on the Zyxel Device.
Monitor > Network Status > UPnP Port Status 
Label
Description
Remove
Select an entry and click this button to remove it from the list.
#
This is the index number of the UPnP-created NAT mapping rule entry.
Remote Host
This field displays the source IP address (on the WAN) of inbound IP packets. Since this is often a wild-card, the field may be blank.
When the field is blank, the Zyxel Device forwards all traffic sent to the External Port on the WAN interface to the Internal Client on the Internal Port.
When this field displays an external IP address, the NAT rule has the Zyxel Device forward inbound packets to the Internal Client from that IP address only.
External Port
This field displays the port number that the Zyxel Device “listens” non the WAN port) for connection requests destined for the NAT rule’s Internal Port and Internal Client. The Zyxel Device forwards incoming packets (from the WAN) with this port number to the Internal Client on the Internal Port (on the LAN). If the field displays “0”, the Zyxel Device ignores the Internal Port value and forwards requests on all external port numbers (that are otherwise unmapped) to the Internal Client.
Protocol
This field displays the protocol of the NAT mapping rule (TCP or UDP).
Internal Port
This field displays the port number on the Internal Client to which the Zyxel Device should forward incoming connection requests.
Internal Client
This field displays the DNS host name or IP address of a client on the LAN. Multiple NAT clients can use a single port simultaneously if the internal client field is set to 255.255.255.255 for UDP mappings.
Internal Client Type
This field displays the type of the client application on the LAN.
Description
This field displays a text explanation of the NAT mapping rule.
Delete All
Click this to remove all mapping rules from the NAT table.
Refresh
Click this button to update the information on the screen.
USB Storage Screen
This screen displays information about a connected USB storage device.
Monitor > Network Status > USB Storage 
Label
Description
Device description
This is a basic description of the type of USB device.
Usage
This field displays how much of the USB storage device’s capacity is currently being used out of its total capacity and what percentage that makes.
Filesystem
This field displays what file system the USB storage device is formatted with. This field displays Unknown if the file system of the USB storage device is not supported by the Zyxel Device, such as NTFS.
Speed
This field displays the connection speed the USB storage device supports.
Status
Ready - you can have the Zyxel Device use the USB storage device.
Click Remove Now to stop the Zyxel Device from using the USB storage device so you can remove it.
Unused - the connected USB storage device was manually unmounted by using the Remove Now button or for some reason the Zyxel Device cannot mount it.
Click Use It to have the Zyxel Device mount a connected USB storage device. This button is grayed out if the file system is not supported (unknown) by the Zyxel Device.
none - no USB storage device is connected.
Detail
This field displays any other information the Zyxel Device retrieves from the USB storage device.
Deactivated - the use of a USB storage device is disabled (turned off) on the Zyxel Device.
OutofSpace - the available disk space is less than the disk space full threshold.
Mounting - the Zyxel Device is mounting the USB storage device.
Removing - the Zyxel Device is unmounting the USB storage device.
none - the USB device is operating normally or not connected.
Ethernet Neighbor Screen
The Ethernet Neighbor screen allows you to view the Zyxel Device’s neighboring devices in one place.
It uses Smart Connect, that is Link Layer Discovery Protocol (LLDP) for discovering and configuring LLDP-aware devices in the same broadcast domain as the Zyxel Device that you’re logged into using the web configurator.
LLDP is a layer-2 protocol that allows a network device to advertise its identity and capabilities on the local network. It also allows the device to maintain and store information from adjacent devices which are directly connected to the network device. This helps you discover network changes and perform necessary network reconfiguration and management.
Note: Enable Smart Connect on the System > ZON screen.
See also System > ZON for more information on the Zyxel One Network (ZON) utility that uses the Zyxel Discovery Protocol (ZDP) for discovering and configuring ZDP-aware Zyxel devices on the same network as the computer on which the ZON utility is installed.
Monitor > Network Status > Ethernet Neighbor
label
description
Local Port (Description)
This field displays the port of the Zyxel Device, on which the neighboring device is discovered.
For Zyxel Devices that support Port Role, if ports 3 to 5 are grouped together and there is a connection to P5 only, the Zyxel Device will display P3 as the interface port number (even though there is no connection to that port).
Model Name
This field displays the model name of the discovered device.
System Name
This field displays the system name of the discovered device.
Firmware Version
This field displays the firmware version of the discovered device.
Port (Description)
This field displays the first internal port on the discovered device. Internal is an interface type displayed on the Network > Interface > Ethernet > Edit screen. For example, if P1 and P2 are WAN, P3 to P5 are LAN, and P6 is DMZ, then Zyxel Device will display P3 as the first internal interface port number.
For Zyxel Devices that support Port Role, if ports 3 to 5 are grouped together and there is a connection to P5 only, the Zyxel Device will display P3 as the first internal interface port number (even though there is no connection to that port).
IP Address
This field displays the IP address of the discovered device.
MAC Address
This field displays the MAC address of the discovered device.
Refresh
Click this button to update the information on the screen.
FQDN Object
View FQDN-to-IP address mappings cached in this screen. An FQDN is resolved to its IP address using the DNS server configured on the Zyxel Device. If the Zyxel Device receives a DNS query for an FQDN and the Zyxel Device has an FQDN cache entry, the Zyxel Device can map the IP address in a DNS response without having to query a DNS name server. The Zyxel Device updates FQDN-to-IP address mappings when the TTL (Time To Live) setting expires.
You can configure FQDN objects in Configuration > Object > Address/Geo IP > Address or Configuration > Object > Address/Geo IP > Address Group.
FQDN can be used in Security Policy, Policy Route, BWM and Web Authentication profiles as source and destination criteria. FQDN with a wildcard (for example, *.zyxel.com) can be used in these profiles as destination criteria only.
Suppose you want to block certain users from going to a website with a dynamically updated IP address using DDNS. Create an FQDN object for the website in Object > Address, and then create a Security Policy in Security Policy > Policy Control > Add. Use the FQDN object to identify the website as a destination, and configure specific users to block. When a user tries to connect to the forbidden website, the Zyxel Device first checks the IP address - website mapping in response to the DNS query and then finds the FQDN object match. The Security Policy that has this FQDN object match can then block the configured users from accessing the website.
FQDN Object
label
description
IPv4 FQDN Object Cache List
You must first configure IPv4 FQDN objects in Configuration > Object > Address/Geo IP in the IPv4 Address Configuration field.
FQDN Object
Select a previously created object from the drop-down list box to display related FQDN object caches used in DNS queries.
#
This is the index number of the FQDN entry.
Name
This field displays the name of the selected FQDN object used in DNS queries.
FQDN
This field displays a host’s fully qualified domain name.
IP Address
This field displays the mapping of the FQDN to an IP address. This is the IP address of a host.
TTL
This field displays the number of seconds the Zyxel Device holds IP address - FQDN object mapping in its cache. The mapping is updated when the TTL (Time To Live) setting expires.
IPv6 FQDN Object Cache List
You must first configure IPv6 FQDN objects in Configuration > Object > Address/Geo IP in the IPv6 Address Configuration field.
FQDN Object
Select an object from the drop-down list box to display related IPv6 FQDN object caches used in DNS queries.
#
This is the index number of the IPv6 FQDN entry.
Name
This field displays the name of the selected IPv6 FQDN object used in DNS queries.
FQDN
This field displays a host’s fully qualified domain name.
IP Address
This field displays the mapping of the FQDN to an IPv6 address. This is the IPv6 address of a host.
TTL
This field displays the number of seconds the Zyxel Device holds IP address - FQDN object mapping in its cache. The mapping is updated when the TTL (Time To Live) setting expires.
Refresh
Click this button to update the information on the screen.
Virtual Server Load Balancing
Virtual server load balancing allows you to distribute incoming connection requests to a virtual server between multiple real (physical) servers. This helps reduce each server’s workload and to decrease virtual server response times.
Use this screen to view traffic statistics between a client and a real server. You can then assess if loading among real servers is balanced. If not, you may need to change the loading algorithm.
Please see Virtual Server Load Balancing for more information on virtual load balancing server.
The following table describes the labels in this screen.
Monitor > Network Status > Virtual Server LB 
Label
Description
View
Select how to view the virtual server load balancing traffic.
Traffic/Connections By Packets: This will display this number of connections and the number of bytes to/from a specific server.
Traffic/Connections By Rates: This will display this number of connections per second and the number of bytes per second to/from a specific server.
#
This is the index number of a table entry.
Server IP
This field displays the IP address of the real server to which the virtual server load balancing traffic is coming from/going to.
Server Port
This field displays the port number on the real server that identifies the service the client requested.
Status
This field displays the result of the health check. If the health check fails, it will display Off-line, if the health check is OK, it displays On-line.
The following fields display when you choose Traffic/Connections By Packets
Active Connection
This field displays the number of active connections between the real server and clients for the specified service.
Inactive Connection
This field displays the number of once active, but now idle connections between the real server and clients for the specified service.
Incoming Packets
This field displays the number of packets going to the real server from clients for the specified service.
Outgoing Packets
This field displays the number of packets coming from the real server to clients for the specified service.
Incoming Bytes
This field displays the number of bytes going to the real server from clients for the specified service.
Outgoing Bytes
This field displays the number of bytes coming from the real server to clients for the specified service.
The following fields display when you choose Traffic/Connections By Rates
Connections/s
This field displays the number of connections per second between the real server and clients for the specified service.
Incoming Packets/s
This field displays the number of packets per second going to the real server from clients for the specified service.
Outgoing Packets/s
This field displays the number of packets per second coming from the real server to clients for the specified service.
Incoming Bytes/s
This field displays the number of bytes per second going to the real server from clients for the specified service.
Outgoing Bytes/s
This field displays the number of bytes per second coming from the real server to clients for the specified service.
Refresh
Click this button to update the information on the screen.
AP Information: AP List
The AP Information menu contains AP List, Radio List, Top N APs and Single AP screens.
The following table describes the labels in this screen.
 
Label
Description
Filter
Click Show Advanced Settings to reveal Filter fields where you can display managed APs by status, keyword or those managed by the Nebula portal.
AP List
Select the type of APs you want to display.
Select All to show all kinds of APs that are currently or used to be connected to the Zyxel Device.
Select NebulaFlexPRO to show the APs that can work in Nebula cloud management mode.
Status
Select the status of APs you want to display.
You can display APs managed by the Zyxel Device according to the following:
Online All: APs that are online now + APs with configuration conflict + APs with non-supported features + APs that are now updating firmware
Online: APs that are online now
Conflict: APs with configurations in conflict with the Zyxel Device (see More Details)
Non Support: APs with features not supported by the Zyxel Device (see More Details)
Updating: APs that are have updated firmware and rebooted
Offline All: Offline + Offline for Firmware Update
Offline: The CAPWAP server did not receive keep-alive packets from these APs in the last 2 minutes (Offline All - Offline for Firmware Update)
Offline for Firmware Update: APs that were rebooted before updating firmware
Un-Mgmt: APs that are not managed by the Zyxel Device
Keyword
Enter a keyword to display the APs that include it in their AP information, such as model number, firmware version, MAC address and so on. This field is case-sensitive.
Search
Click this to update the list of APs based on the search criteria.
Your search criteria is retained when navigating between screens.
Reset
Click this to return the search criteria to the factory defaults and display all currently or previously connected APs without a filter.
Enable Column Freeze
Select this to lock the index columns in place while scrolling to the right.
Edit the selected rule
Select an AP and click this to change the selected AP’s properties, such as its group, radio, VLAN and port settings.
Add to Mgmt AP List
Select an AP and click this to add the selected AP to the managed AP list.
Reboot device
Select one or multiple APs and click this button to force the AP(s) to restart.
Remove the selected rule
Select one or multiple APs and click this button to remove the AP(s) from the manged AP list.
*If on the Configuration > Wireless > Controller screen you set the Registration Type to Always Accept, then as soon as you remove an AP from this list it reconnects.
DCS Now
Select one or multiple APs and click this button to use DCS (Dynamic Channel Selection) to allow the AP to automatically find a less-used channel in an environment where there are many APs and there may be interference.
*You should have enabled DCS in the applied AP radio profile before the APs can use DCS.
*DCS is not supported on the radio which is working in repeater AP mode.
More Information
Select an AP and click this to view a daily station count about the selected AP. The count records station activity on the AP over a consecutive 24 hour period.
Radio Information
Select an online AP and click this button to go to the Monitor > Wireless > AP Information > Radio List screen to view detailed information about the AP’s radios.
Query Controller Log
Select one or multiple APs and click this button to go to the Monitor > Log > View Log screen to view the selected AP’s current log messages.
Nebula
Select an AP and click this to open a screen where you can set whether the AP’s IP address and VLAN settings will be changed when it goes into Nebula cloud management mode. .
*The AP will be set to Nebula cloud management mode and removed from the managed AP list right after you click OK.
Upgrade Firmware Now
Select one or more APs and click this button to update the APs’ firmware version.
Suppression On
Select an AP and click this button to enable the AP’s LED suppression mode. All the LEDs of the AP will turn off after the AP is ready. This button is not available if the selected AP doesn’t support suppression mode.
Suppression Off
Select an AP and click this button to disable the AP’s LED suppression mode. The AP LEDs stay lit after the AP is ready. This button is not available if the selected AP doesn’t support suppression mode.
Locator On
Select an AP and click this button to run the locator feature. The AP’s Locator LED will start to blink for 10 minutes by default. It will show the actual location of the AP between several devices on the network.
#
This field is a sequential value, and it is not associated with any entry.
Status
This field displays the status of AP.
Online All: APs that are online now + APs with configuration conflict + APs with non-supported features + APs that are now updating firmware
Online: APs that are online now
Conflict: APs with configurations in conflict with the Zyxel Device (see More Details)
Non Support: APs with features not supported by the Zyxel Device (see More Details)
Updating: APs that are have updated firmware and rebooted
Offline All: Offline + Offline for Firmware Update
Offline: The CAPWAP server did not receive keep-alive packets from these APs in the last 2 minutes (Offline All - Offline for Firmware Update)
Offline for Firmware Update: APs that were rebooted before updating firmware
Un-Mgmt: APs that are not managed by the Zyxel Device
Description
This field displays the AP’s description, which you can configure by selecting the AP’s entry and clicking the Edit button.
CPU Usage
This field displays the CPU Usage of the AP.
IP Address
This field displays the IP address of the AP.
MAC Address
This field displays the MAC address of the AP.
Station 2.4G
This field displays the number of 2.4G wireless clients connected to the AP.
Station 5G
This field displays the number of 5G wireless clients connected to the AP.
Recent Online Time
This displays the most recent time the AP came on-line. N/A displays if the AP has not come on-line since the Zyxel Device last started up.
Power
This field displays the AP’s power status.
Full - the AP receives power using a power adapter and/or through a PoE switch/injector using IEEE 802.3at PoE plus. The PoE device that supports IEEE 802.3at PoE Plus can supply power of up to 30W per Ethernet port.
Limited - the AP receives power through a PoE switch/injector using IEEE 802.3af PoE even when it is also connected to a power source using a power adaptor. The PoE device that supports IEEE 802.3af PoE can supply power of up to 15.4W per Ethernet port.
When the AP is in limited power mode, the AP throughput decreases and has just one transmitting radio chain.
It always shows Full if the AP does not support power detection.
Type
This indicates whether the AP is on the managed AP list (Mgmt) or not (Un-Mgmt).
This displays Limited when the AP is configured by conflicted or unsupported setting(s).
Model
This field displays the AP’s hardware model information. It displays N/A (not applicable) only when the AP disconnects from the Zyxel Device and the information is unavailable as a result.
R1 Mode/ Profile/ ZyMesh Profile
This field displays the operating mode (AP, MON, rootap, or repeater), AP radio profile name and ZyMesh profile name for Radio1. It displays- for the ZyMesh profile for a radio not using a ZyMesh profile.
R2 Mode/ Profile/ ZyMesh Profile
This field displays the operating mode (AP, MON, rootap, or repeater), AP radio profile name and ZyMesh profile name for Radio2. It displays- for the ZyMesh profile for a radio not using a ZyMesh profile.
Version
This field displays the AP’s current firmware version.
Group
This displays the name of the AP group to which the AP belongs.
Mgnt. VLAN ID (AC/AP)
This displays the Access Controller (the Zyxel Device) and runtime management VLAN ID setting for the AP. VLAN Conflict displays if the AP’s management VLAN ID does not match the Mgmnt. VLAN ID(AC). This field displays n/a if the Zyxel Device cannot get VLAN information from the AP.
Last Off-line Time
This field displays the date and time that the AP was last logged out.
LED Status
This field displays the AP LED status.
N/A displays if the AP does not support LED suppression mode and/or have a locator LED to show the actual location of the AP.
A gray LED icon signifies that the AP LED suppression mode is enabled. All the LEDs of the AP will turn off after the AP is ready.
A green LED icon signifies that the AP LED suppression mode is disabled and the AP LEDs stay lit after the AP is ready.
A sun icon signifies that the AP’s locator LED is blinking.
A circle signifies that the AP’s locator LED is extinguished.
Ethernet Uplink
This field displays the AP’s uplink port speed and duplex mode (Full or Half).
Bluetooth
This field displays the AP’s Bluetooth Low Energy (BLE) capability. Bluetooth Low Energy, which is also known as Bluetooth Smart, transmits less data over a shorter distance and consumes less power than classic Bluetooth. APs communicate with other BLE enabled devices using advertisements.
N/A displays if the AP does not support BLE.
Unavailable displays if the AP supports Bluetooth, but there is no BLE USB dongle connected to the USB port of the AP. Some APs, such as the WAC5302D-S, need to have a supported BLE USB dongle attached to act as a beacon to broadcast packets.
Available displays if the AP supports Bluetooth, detects a BLE device and advertising is inactive.
Advertising displays if the AP supports Bluetooth, detects a BLE device and advertising is activated, which means the BLE device can broadcasts packets to every device around it.
Location
This field displays the AP’s location you configured.
Roaming Group
This field displays the name of roaming group to which the AP belongs.
Load Balancing Group
This field displays the AP’s load balance status when load balancing is enabled on the Zyxel Device. Otherwise, it shows nothing when load balancing is disabled or the radio is in monitor mode.
S/N
This field displays the serial number of the AP.
System Name
This field displays the system name to identify the AP on a network.
Apply
Click Apply to save your changes back to the Zyxel Device.
Refresh
Click Refresh to update the AP list.
AP List: More Information
Use this screen to look at station statistics for the connected AP. Use this screen to look at configuration information, port status and station statistics for the connected AP.
The following table describes the labels in this screen.
Monitor > Wireless > AP Information > AP List > More Information 
Label
Description
Configuration Status
This displays whether or not any of the AP’s configuration is in conflict with the Zyxel Device’s settings for the AP.
Conflict
If any of the AP’s configuration conflicts with the ZyWALL’s settings for the AP, this field displays which configuration conflicts. It displays n/a if none of the AP’s configuration conflicts with the ZyWALL’s settings for the AP.
Non Support
If any of the AP’s configuration conflicts with the Zyxel Device’s settings for the AP, this field displays which configuration conflicts. It displays n/a if none of the AP’s configuration conflicts with the Zyxel Device’s settings for the AP.
Port Status
 
Port
This shows the name of the physical Ethernet port on the Zyxel Device.
Status
This field displays the current status of each physical port on the AP.
Down - The port is not connected.
Speed / Duplex - The port is connected. This field displays the port speed and duplex setting (Full or Half).
PVID
This shows the port’s PVID.
A PVID (Port VLAN ID) is a tag that adds to incoming untagged frames received on a port so that the frames are forwarded to the VLAN group that the tag defines.
Up Time
This field displays how long the physical port has been connected.
Tx Bcast
This field displays the number of broadcast packets transmitted on the port.
Rx Bcast
This field displays the number of broadcast packets received on the port.
VLAN Configuration
 
Name
This shows the name of the VLAN.
Status
This displays whether or not the VLAN is activated.
VID
This shows the VLAN ID number.
Member
This field displays the Ethernet port(s) that is a member of this VLAN.
Ethernet Neighbor
 
Local Port (Description)
This field displays the port of the Zyxel Device, on which the neighboring device is discovered.
For Zyxel Devices that support Port Role, if ports 3 to 5 are grouped together and there is a connection to P5 only, the Zyxel Device will display P3 as the interface port number (even though there is no connection to that port).
Model Name
This field displays the model name of the discovered device.
System Name
This field displays the system name of the discovered device.
Firmware Version
This field displays the firmware version of the discovered device.
Port (Description)
This field displays the first internal port on the discovered device. Internal is an interface type displayed on the Network > Interface > Ethernet > Edit screen. For example, if P1 and P2 are WAN, P3 to P5 are LAN, and P6 is DMZ, then Zyxel Device will display P3 as the first internal interface port number.
For Zyxel Devices that support Port Role, if ports 3 to 5 are grouped together and there is a connection to P5 only, the Zyxel Device will display P3 as the first internal interface port number (even though there is no connection to that port).
IP Address
This field displays the IP address of the discovered device.
MAC Address
This field displays the MAC address of the discovered device.
Station Count
 
 
The y-axis represents the number of connected stations.
 
The x-axis shows the time over which a station was connected.
Last Update
This field displays the date and time the information in the window was last updated.
OK
Click OK to save your changes back to the Zyxel Device.
Cancel
Click Cancel to exit this screen without saving your changes.
AP List: Edit AP
Select an AP and click the Edit Selected Rule button in the Monitor > Wireless > AP Information > AP List table to display this screen.
Each field is described in the following table.
Monitor > Wireless > AP Information > AP List > Edit AP 
Label
Description
Create new Object
Use this menu to create a new Radio Profile object to associate with this AP.
MAC
This displays the MAC address of the selected AP.
Model
This field displays the AP’s hardware model information. It displays N/A (not applicable) only when the AP disconnects from the Zyxel Device and the information is unavailable as a result.
Description
Enter a description for this AP. You can use up to 31 characters, spaces and underscores allowed.
Group Setting
Select an AP group to which you want this AP to belong.
System Name
Enter a name to identify the AP on a network. This is usually the AP’s fully qualified domain name.
Location
Specify the name of the place where the AP is located.
Roaming Group
Specify the name of the roaming group to which the AP belongs. You can use up to 31 alphanumeric and @# characters. Dashes and underscores are also allowed. The name should start with a letter or digit.
The 802.11k neighbor list a client requests from the AP is generated according to the roaming group and RCPI (Received Channel Power Indicator) value of its neighbor APs.
When a client wants to roam from the current AP to another, other APs in the same roaming group or not in a roaming group will be candidates for roaming. Neighbor APs in a different roaming group will be excluded from the 802.11k neighbor lists even when the neighbor AP has the best signal strength.
If the AP’s roaming group is not configured, any neighbor APs can be candidates for roaming.
Load Balancing Group 1/2
Load balancing is only applied to APs within the same group. If a load balancing group is not assigned to an AP, it will belong to a default group.
Each AP can belong to up to two groups.
Radio 1/2 Setting
 
Override Group Radio Setting
Select this option to overwrite the AP radio settings with the settings you configure here.
Radio 1/2 OP Mode
Select the operating mode for radio 1 or radio 2.
AP Mode means the AP can receive connections from wireless clients and pass their data traffic through to the Zyxel Device to be managed (or subsequently passed on to an upstream gateway for managing).
MON Mode means the AP monitors the broadcast area for other APs, then passes their information on to the Zyxel Device where it can be determined if those APs are friendly or rogue. If an AP is set to this mode it cannot receive connections from wireless clients.
Radio 1/2 Profile
Select a profile from the list. If no profile exists, you can create a new one through the Create new Object menu.
Override Group Output Power Setting
Select this option to overwrite the AP output power setting with the setting you configure here.
Output Power
Set the output power of the AP.
Override Group SSID Setting
Select this option to overwrite the AP SSID profile setting with the setting you configure here.
This section allows you to associate an SSID profile with the radio.
Edit
Select an SSID and click this button to reassign it. The selected SSID becomes editable immediately upon clicking.
#
This is the index number of the SSID profile. You can associate up to eight SSID profiles with an AP radio.
SSID Profile
Indicates which SSID profile is associated with this radio profile.
IP Setting
 
Force Overwrite IP Setting
Select this to change the AP’s IP address setting to match the configuration in this screen.
Get Automatically
Select this to have the AP act as a DHCP client and automatically get the IP address, subnet mask, and gateway address from a DHCP server.
Used Fixed IP Address
Select this if you want to specify the IP address, subnet mask, gateway and DNS server address manually.
IP Address
Enter the IP address for the AP.
Subnet Mask
Enter the subnet mask of the AP in dot decimal notation. The subnet mask indicates what part of the IP address is the same for all devices in the network.
Gateway
Enter the IP address of the gateway. The AP sends packets to the gateway when it does not know how to route the packet to its destination. The gateway should be on the same network as the AP.
DNS Server IP Address
Enter the IP address of the DNS server.
VLAN Settings
 
Override Group VLAN Setting
Select this option to overwrite the AP VLAN setting with the setting you configure here.
Force Overwrite VLAN Config
Select this to have the Zyxel Device change the AP’s management VLAN to match the configuration in this screen.
Management VLAN ID
Enter a VLAN ID for this AP.
As Native VLAN
Select this option to treat this VLAN ID as a VLAN created on the Zyxel Device and not one assigned to it from outside the network.
Storm Control Setting
Traffic storm control limits the number of broadcast and/or multicast packets the Zyxel Device receives on the ports. When the maximum number of allowable broadcast and/or multicast packets is reached, the subsequent packets are discarded.
Select Broadcast Storm Control to enable broadcast storm control on the Zyxel Device. Enabling this will drop ingress broadcast traffic in the physical Ethernet port if it exceeds the maximum traffic rate.
Select Multicast Storm Control to enable multicast storm control on the Zyxel Device. Enabling this will drop ingress multicast traffic in the physical Ethernet port if it exceeds the maximum traffic rate.
Rogue AP Detection Setting
This feature allows the Zyxel Device to monitor the WiFi signals for other wireless APs. A rogue AP is a wireless access point operating in a network’s coverage area that is not under the control of the network administrator, and which can potentially open up holes in a network’s security.
Select this check box to detect Rogue APs in the network.
Antenna Setting
Select Wall if you mount the Zyxel Device to a wall. Select Ceiling if the Zyxel Device is mounted on a ceiling. You can switch from Wall to Ceiling if there are still wireless dead zones, and vice versa.
LED Suppression Mode Configuration
If the Suppression On check box is checked, the LEDs of yourZyxel Device will turn off after it’s ready.
If the check box is unchecked, the LEDs will stay lit after theZyxel Device is ready.
Power Setting
Select this check box if you are using a PoE injector that does not support PoE negotiation. Otherwise, the Zyxel Device cannot draw full power from the power sourcing equipment. Enable this power mode to improve the Zyxel Device’s performance in this situation.
*Ensure that the power sourcing equipment can supply enough power to the AP to avoid abnormal system reboots.
*Only enable this if you are using a passive PoE injector that is not IEEE 802.3at/bt compliant but can still provide full power.
Locator LED Configuration
Click Turn On button to activate the locator. The Locator function will show the actual location of the Zyxel Device between several devices in the network.
Otherwise, click Turn Off to disable the locator feature.
Automatically Extinguish After
Enter a time interval between 1 and 60 minutes to stop the locator LED from blinking. Default is 10 minutes.
Reset AP Configuration
Click Apply Factory Default to reset all of the AP settings to the factory defaults.
OK
Click OK to save your changes back to the Zyxel Device.
Cancel
Click Cancel to close the window with changes unsaved.
AP Information: Radio List
The following table describes the labels in this screen.
Monitor > Wireless > AP Information > Radio List
LABEL
DESCRIPTION
More Information
Click this icon to see the traffic statistics, station count, SSID, Security Mode and VLAN ID information on the AP.
Enable Column Freeze
Select this to lock the index columns in place while scrolling to the right.
#
This field is a sequential value, and it is not associated with a specific radio.
Loading
This indicates the AP’s load balance status (UnderLoad or OverLoad) when load balancing is enabled on the AP. Otherwise, it shows - when load balancing is disabled or the radio is in monitor mode.
AP Description
Enter a description for this AP. You can use up to 31 characters, spaces and underscores allowed.
Frequency Band
This field displays the WLAN frequency band using the IEEE 802.11 a/b/g/n standard of 2.4 or 5 GHz.
Channel ID
This field displays the WLAN channels using the IEEE 802.11 protocols.
Tx Power
This shows the radio’s output power (in dBm).
Station
This field displays the station count information.
Rx
This field displays the total number of bytes received by the radio.
Tx
This field displays the total number of bytes transmitted by the radio.
Model
This field displays the AP’s hardware model information. It displays N/A (not applicable) only when the AP disconnects from the Zyxel Device and the information is unavailable as a result.
MAC Address
This field displays the MAC address of the AP.
Radio
This field displays the Radio number. For example 1.
OP Mode
This field displays the operating mode of the AP. It displays n/a for the profile for a radio not using an AP profile.
AP Mode means the AP can receive connections from wireless clients and pass their data traffic through to the Zyxel Device to be managed (or subsequently passed on to an upstream gateway for managing).
AP / ZyMesh Profile
This indicates the AP radio and ZyMesh profile names to which the radio belongs.
Antenna
This indicates the antenna orientation for the radio (Wall or Ceiling).
This shows N/A if the AP does not allow you to adjust coverage depending on the orientation of the antenna for each radio using the web configurator or a physical switch.
Radio List: More Information
This screen allows you to view detailed information about a selected radio’s SSID(s), wireless traffic and wireless clients for the preceding 24 hours.
Monitor > Wireless > AP Information > Radio List > More Information 
Label
Description
MBSSID Detail
This list shows information about the SSID(s) that is associated with the radio over the preceding 24 hours.
#
This is the items sequential number in the list. It has no bearing on the actual data in this list.
SSID Name
This displays an SSID associated with this radio. There can be up to eight maximum.
BSSID
This displays the MAC address associated with the SSID.
Security Mode
This displays the security mode in which the SSID is operating.
Forwarding Mode
This field indicates the forwarding mode (Local Bridge or Tunnel) associated with the SSID profile.
VLAN
This displays the VLAN ID associated with the SSID.
Traffic Statistics
This graph displays the overall traffic information about the radio over the preceding 24 hours.
y-axis
This axis represents the amount of data moved across this radio in megabytes per second.
x-axis
This axis represents the amount of time over which the data moved across this radio.
Station Count
This graph displays information about all the wireless clients that have connected to the radio over the preceding 24 hours.
y-axis
The y-axis represents the number of connected wireless clients.
x-axis
The x-axis shows the time over which a wireless client was connected.
Last Update
This field displays the date and time the information in the window was last updated.
OK
Click this to close this window.
Cancel
Click this to close this window.
AP Information: Built-in AP
Use this screen to display the number of wireless clients connected to the built-in AP and their WiFi usage.
The following table describes the labels in this screen.
Monitor > Wireless > AP Information > Built-in AP
LABEL
DESCRIPTION
Single Station Status
 
Usage by
Select the measure unit in GB or MB to display the graph.
Traffic Usage
This graph displays traffic in the preceding 24 hours.
y-axis
The y-axis represents the amount of traffic in megabytes/gigabytes.
x-axis
The x-axis represents the time over which wireless traffic flows transmitting from/to the AP.
Station Count
This graph displays the number of wireless stations that have connected to the AP in the preceding 24 hours.
y-axis
The y-axis represents the number of connected wireless stations.
x-axis
The x-axis represents the time over which a wireless client was connected.
Refresh
Click Refresh to update this screen.
AP Information: Top N APs
Use this screen to view the top five or top ten wireless traffic usage and associated wireless stations for the preceding 24 hours.
The following table describes the labels in this screen.
Monitor > Wireless > AP Information > Top N APs
LABEL
DESCRIPTION
View
Select this to view the top five or top ten wireless traffic for the preceding 24 hours.
Usage by
If you view the data usage by Usage, select the frequency band and the measure unit in GB or MB to display the graph.
If you view the date usage by Station Number, select the measure unit in GB or MB to display the graph.
Traffic Usage
This graph displays the overall traffic information about the top five or top ten wireless traffic for the preceding 24 hours.
y-axis
The y-axis represents the amount of traffic in megabytes/gigabytes.
x-axis
The x-axis represents the time over which wireless traffic flows transmitting from/to the AP.
Station Count
This graph displays information about all the wireless stations that have connected to the AP for the preceding 24 hours.
y-axis
The y-axis represents the number of connected wireless stations.
x-axis
The x-axis represents the time over which a wireless client was connected.
Refresh
Click Refresh to update this screen.
AP Information: Single AP
Use this screen to view wireless traffic usage and wireless stations for a managed AP.
The following table describes the labels in this screen.
Monitor > Wireless > AP Information > Single AP
LABEL
DESCRIPTION
AP Selection
Select a managed AP from the drop-down list box to view its wireless traffic usage and wireless stations.
Usage by
Select the measure unit in GB or MB to display the graph.
Traffic Usage
This graph displays the overall traffic information about the AP you specified for the preceding 24 hours.
y-axis
The y-axis represents the amount of traffic in megabytes/gigabytes.
x-axis
The x-axis represents the time over which wireless traffic flows transmitting from/to the AP.
Station Count
This graph displays information about all the wireless stations that have connected to the AP for the preceding 24 hours.
y-axis
The y-axis represents the number of connected wireless stations.
x-axis
The x-axis represents the time over which a wireless client was connected.
Refresh
Click Refresh to update this screen.
ZyMesh
Use this screen to view the ZyMesh traffic statistics between the managed APs.
The following table describes the labels in this screen.
Monitor > Wireless > ZyMesh
LABEL
DESCRIPTION
#
This field displays the index number of the managed AP (in repeater mode) in this list.
Description
This field displays the descriptive name of the managed AP (in repeater mode).
IP Address
This field displays the IP address of the managed AP (in repeater mode).
Channel ID
This field displays the number of the channel used by the managed AP (in repeater mode).
Hop
This is the hop count of the managed AP. For example, “1” means the managed AP is connected to a root AP directly. “2” means there is another repeater AP between the managed AP and the root AP.
Uplink AP Info
This shows the role and descriptive name of the managed AP to which this managed AP is connected wirelessly.
SSID Name
This indicates the name of the wireless network (SSID) the managed AP uses to associated with another managed AP.
Signal Strength
Before the slash, this shows the signal strength the uplink AP (a root AP or a repeater) receives from this managed AP (in repeater mode).
After the slash, this shows the signal strength this managed AP (in repeater mode) receives from the uplink AP.
Link Up Time
This field displays the time the managed AP first associated with the root AP or repeater.
MAC Address
This field displays the MAC address of the managed AP (in repeater mode).
Tx Power
This field displays the output power of the managed AP (in repeater mode).
Root AP
This field displays the descriptive name of the root AP to which the managed AP is connected wirelessly.
Tx Rate
This field displays the maximum transmission rate of the root AP or repeater to which the managed AP is connected.
Rx Rate
This field displays the maximum reception rate of the root AP or repeater to which the managed AP is connected.
Refresh
Click Refresh to update this screen.
SSID Info
Use this screen to view the number of wireless clients currently connected to an SSID and the security type used by the SSID.
The following table describes the labels in this screen.
Monitor > Wireless > SSID Info
LABEL
DESCRIPTION
#
This is the SSID’s index number in this list.
SSID
This indicates the name of the wireless network to which the client is connected. A single AP can have multiple SSIDs or networks.
2.4GHz
This shows the number of wireless clients which are currently connected to the SSID using the 2.4 GHz frequency band, Click the number to go to the Station Info > Station List screen. See Station Info: Top N Stations.
5GHz
This shows the number of wireless clients which are currently connected to the SSID using the 5 GHz frequency band, Click the number to go to the Station Info > Station List screen. See Station Info: Top N Stations.
SSID Profile Name
This indicates the name of the SSID profile in which the SSID is defined,
Security Mode
This indicates which secure encryption methods is being used by the SSID.
Refresh
Click Refresh to update this screen.
Station Info: Station List
This screen displays information about connected wireless stations.
Monitor > Wireless > Station Info > Station List
LABEL
DESCRIPTION
Hide/Show Advanced Settings
Click this button to display a greater or lesser number of configuration fields.
Show Filter/ Hide Filer
Click this button to show or hide the filter settings.
Filter
 
IP Address
Enter the IP address of the station you want to display. This field is case-sensitive.
Associated AP
Select the AP(s) with which the stations you want to display associate.
SSID Name
Select the SSID(s) to which the stations you want to display are connected.
MAC Address
Enter the MAC address of the station you want to display. This field is case-sensitive.
Security Mode
Select the security mode(s) used by the stations you want to display.
Account
Enter the user account name of the station you want to display. This field is case-sensitive.
Login Type
Select the login method(s) used by the stations you want to display.
Band
Select the frequency band used by the stations you want to display.
Search
Click this to update the list of stations based on the search criteria.
Your search criteria is retained when navigating between screens.
Reset
Click this to return the search criteria to the factory defaults and display all connected stations without a filter.
Enable Column Freeze
Select this to lock the index columns in place while scrolling to the right.
Station List
 
#
This field is a sequential value, and it is not associated with a specific station.
MAC Address
This field displays the MAC address of the station.
SSID Name
This field displays the SSID names of the station.
Associated AP
This field displays the APs that are associated with the station.
IP Address
This field displays the IP address of the station.
Channel
This field displays the number of the channel used by the station to connect to the network.
Rx Rate
This field displays the receive data rate of the station.
Tx Rate
This field displays the transmit data rate of the station.
Signal Strength
This field displays the signal strength of the station.
Association Time
This field displays the time duration the station was online and offline.
Enterprise
This field displays the RADIUS server of the station.
Captive Portal
This displays whether the station logged into the network via the captive portal login page.
MAC Auth
This displays whether the station logged into the network via MAC authentication.
Band
This field displays the frequency band which is currently being used by the station.
Capability
This displays the supported standard currently being used by the station or the standards supported by the station.
802.11 Features
This displays whether the station supports IEEE802.11r, IEEE 802.11k, IEEE 802.11v or none of the above (N/A).
Security Mode
This field displays the security mode the station is using.
Download
This field displays the number of bytes received by the station.
Upload
This field displays the number of bytes transmitted from the station.
Refresh
Click Refresh to update this screen.
Station Info: Top N Stations
Use this screen to view the top five or top ten traffic statistics of the wireless stations.
Monitor > Wireless > Station Info > Top N Stations
LABEL
DESCRIPTION
View
Select this to view the top five or top ten traffic statistics of the wireless stations.
Usage by
Select the measure unit in GB or MB to display the graph.
Traffic Usage
This graph displays the overall traffic information about the stations for the preceding 24 hours.
y-axis
This axis represents the amount of data moved across stations in megabytes per second.
Refresh
Click Refresh to update this screen.
Station Info: Single Station
Use this screen to view traffic statistics of the wireless station you specified.
Monitor > Wireless > Station Info > Single Station
LABEL
DESCRIPTION
Station Selection
Select this to view the traffic statistics of the wireless station.
Usage by
Select the measure unit in GB or MB to display the graph.
Traffic Usage
This graph displays the overall traffic information about the station over the preceding 24 hours.
y-axis
This axis represents the amount of data moved across this station in megabytes per second.
Refresh
Click Refresh to update this screen.
Detected Device
Use this screen to view information about wireless devices detected by the AP.
Note: At least one radio of the APs connected to the Zyxel Device must be set to monitor mode (on the Configuration > Wireless > AP Management screen) in order to detect other wireless devices in its vicinity.
Monitor > Wireless > Detected Device 
Label
Description
Discovered APs
 
Rogue AP
This shows how many devices are detected as rogue APs.
Suspected rogue AP
This shows how many devices are detected as possible rogue APs.
Friendly AP
This shows how many devices are detected as friendly APs.
Un-Classified AP
This shows how many devices are detected, but have not been classified as either Rogue or Friendly by the Zyxel Device.
Detect now
Click this button for the Zyxel Device to scan for APs in the network.
Mark as Rogue AP
Click this button to mark the selected AP as a rogue AP. A rogue AP can be contained on the Configuration > Wireless > MON Mode screen.
Mark as Friendly AP
Click this button to mark the selected AP as a friendly AP. For more on managing friendly APs, see the Configuration > Wireless > MON Mode screen.
#
This is the station’s index number in this list.
Role
This indicates the detected device’s role (such as friendly or rogue).
Classified by
This indicates the detected device’s classification rule.
MAC Address
This indicates the detected device’s MAC address.
SSID Name
This indicates the detected device’s SSID.
Channel ID
This indicates the detected device’s channel ID.
802.11 Mode
This indicates the 802.11 mode (a/b/g/n) transmitted by the detected device.
Security
This indicates the encryption method (if any) used by the detected device.
Seen by
This indicates which AP detects the device.
If an AP in monitor mode detected this AP, this column will show “N/A”.
If an AP using Rogue AP Detection detected this device, it will show the name of the AP and the signal strength from the detected device. If the wireless device is detected by more than one AP, only the top 5 APs with the highest signal strength will be shown.
Group
This indicates which group the detected device belongs.
Description
This displays the detected device’s description. For more on managing friendly and rogue APs, see the Configuration > Wireless > MON Mode screen.
Last Seen
This indicates the last time the device was detected by the Zyxel Device.
Refresh
Click this to refresh the items displayed on this page.
Wireless Health
Use this screen to view the health or wireless networks for your APs and connected wireless clients.
The following table describes the labels in this screen.
Monitor > Wireless > Wireless Health 
Label
Description
Top 10 Alert Count
This chart shows the top 10 APs that are in poor states of wireless health for the most times.
Date
This field shows the current date in theZyxel Device.
Radio Alert Count
Select 2.4G or 5G to view the APs 2.4G or 5G radios wireless health.
y-axis
The y-axis represents the state of wireless health.
x-axis
The x-axis shows the time period over which the APs health states are recorded.
Station Alert Count
This chart shows how many times the client is in a poor state or wireless health.
y-axis
The y-axis represents the state of wireless health.
x-axis
The x-axis shows the time period over which the client health state is recorded.
Refresh
Click this to refresh the items displayed on this page.
The Printer Status Screen
This screen displays information about the connected statement printer.
The following table describes the labels in this screen.
Monitor > Printer Status 
Label
Description
#
This is the index number of the printer in the list.
IPv4 Address
This field displays the IP address of the printer that you configured in the screen.
Update Time
This field displays the date and time the Zyxel Device last synchronized with the printer.
This shows n/a when the printer status is sync fail.
Status
This field displays whether the Zyxel Device can connect to the printer and update the printer information.
Description
This field displays the descriptive name of the printer that you configured in the screen.
Nickname
This field displays the nickname of the printer that you configured in the Edit screen.
Firmware Version
This field displays the model number and firmware version of the printer.
This shows n/a when the printer status is sync fail.
MAC
This field displays the MAC address of the printer.
IPSec
You can use the IPSec Monitor screen to display and to manage active IPSec SAs. TClick a column’s heading cell to sort the table entries by that column’s criteria. Click the heading cell again to reverse the sort order.
Monitor > VPN Monitor > IPSec 
Label
Description
Name
Type the name of a IPSec SA here and click Search to find it (if it is associated). You can use a keyword or regular expression. Use up to 30 alphanumeric and _+-.()!$*^:?|{}[]<>/ characters. See Regular Expressions in Searching IPSec SAs for more details.
Policy
Type the IP address(es) or names of the local and remote policies for an IPSec SA and click Search to find it. You can use a keyword or regular expression. Use up to 30 alphanumeric and _+-.()!$*^:?|{}[]<>/ characters. See Regular Expressions in Searching IPSec SAs for more details.
Search
Click this button to search for an IPSec SA that matches the information you specified above.
Disconnect
Select an IPSec SA and click this button to disconnect it.
Connection Check
Select an IPSec SA and click this button to check the connection.
#
This field is a sequential value, and it is not associated with a specific SA.
User
This field only displays the client names if they’re using EAP or X-auth for authentication.
If a client is connected to the Zyxel Device without using Extended Authentication Protocol (EAP) or X-Auth, this field will be empty.
Serial Number
This field displays the serial number of this Zyxel Device.
System Name
This field displays the name used to identify the Zyxel Device.
Name
This field displays the name of the IPSec SA.
Policy
This field displays the content of the local and remote policies for this IPSec SA. The IP addresses, not the address objects, are displayed.
My Address
This field displays the IP address of local computer.
Secure Gateway
This field displays the secure gateway information.
Up Time
This field displays how many seconds the IPSec SA has been active. This field displays N/A if the IPSec SA uses manual keys.
Timeout
This field displays how many seconds remain in the SA life time, before the Zyxel Device automatically disconnects the IPSec SA. This field displays N/A if the IPSec SA uses manual keys.
Inbound (Bytes)
This field displays the amount of traffic that has gone through the IPSec SA from the remote IPSec router to the Zyxel Device since the IPSec SA was established.
Outbound (Bytes)
This field displays the amount of traffic that has gone through the IPSec SA from the Zyxel Device to the remote IPSec router since the IPSec SA was established.
Regular Expressions in Searching IPSec SAs
A question mark (?) lets a single character in the VPN connection or policy name vary. For example, use “a?c” (without the quotation marks) to specify abc, acc and so on.
Wildcards (*) let multiple VPN connection or policy names match the pattern. For example, use “*abc” (without the quotation marks) to specify any VPN connection or policy name that ends with “abc”. A VPN connection named “testabc” would match. There could be any number (of any type) of characters in front of the “abc” at the end and the VPN connection or policy name would still match. A VPN connection or policy name named “testacc” for example would not match.
A * in the middle of a VPN connection or policy name has the Zyxel Device check the beginning and end and ignore the middle. For example, with “abc*123”, any VPN connection or policy name starting with “abc” and ending in “123” matches, no matter how many characters are in between.
The whole VPN connection or policy name has to match if you do not use a question mark or asterisk.
SSL
The Zyxel Device keeps track of the users who are currently logged into the VPN SSL client.Use this screen to do the following:
View a list of active SSL VPN connections.
Log out individual users and delete related session information.
Once a user logs out, the corresponding entry is removed from the screen.
Monitor > VPN Monitor > SSL 
label
description
Disconnect
Select a connection and click this button to terminate the user’s connection and delete corresponding session information from the Zyxel Device.
Refresh
Click Refresh to update this screen.
#
This field is a sequential value, and it is not associated with a specific SSL.
User
This field displays the account user name used to establish this SSL VPN connection.
Access
This field displays the name of the SSL VPN application the user is accessing.
Login Address
This field displays the IP address the user used to establish this SSL VPN connection.
Connected Time
This field displays the time this connection was established.
Inbound (Bytes)
This field displays the number of bytes received by the Zyxel Device on this connection.
Outbound (Bytes)
This field displays the number of bytes transmitted by the Zyxel Device on this connection.
L2TP over IPSec
Use this screen to display and manage the Zyxel Device’s connected L2TP VPN sessions.
Monitor > VPN Monitor > L2TP over IPSec 
Label
Description
Disconnect
Select a connection and click this button to disconnect it.
Refresh
Click Refresh to update this screen.
#
This field is a sequential value, and it is not associated with a specific L2TP VPN session.
User Name
This field displays the remote user’s user name.
Hostname
This field displays the name of the computer that has this L2TP VPN connection with the Zyxel Device.
Assigned IP
This field displays the IP address that the Zyxel Device assigned for the remote user’s computer to use within the L2TP VPN tunnel.
Public IP
This field displays the public IP address that the remote user is using to connect to the Internet.
The Remote AP VPN Screen
You can use the Remote AP VPN Monitor screen to display and to manage active remote AP. Remote AP enables the Zyxel Device to connect to an Access Point (AP) through a secure VPN tunnel. See Remote AP VPN for more information. Click a column’s heading cell to sort the table entries by that column’s criteria. Click the heading cell again to reverse the sort order.
Each field is described in the following table.
Monitor > VPN Monitor > Remote AP VPN 
Label
Description
Name
Type the name of a remote AP here and click Search to find it (if it is associated). You can use a keyword or regular expression. Use up to 30 alphanumeric and _+-.()!$*^:?|{}[]<>/ characters. See Regular Expressions in Searching IPSec SAs for more details.
Policy
Type the IP address or name of the local and remote policies for a remote AP and click Search to find it. You can use a keyword or regular expression. Use up to 30 alphanumeric and _+-.()!$*^:?|{}[]<>/ characters. See Regular Expressions in Searching IPSec SAs for more details.
Search
Click this button to search for a remote AP that matches the information you specified above.
Disconnect
Select a remote AP and click this button to disconnect it.
#
This field is a sequential value, and it is not associated with a specific remote AP.
Remote AP Description
This fields displays the remote AP description, which you can configure in Configuration> Wireless> AP Management, see AP Management Screens for more information.
Assigned IP
This field displays the IP address the Zyxel Device assigns to the remote AP from the IP address pool you set in Configuration> VPN> Remote AP VPN. See Remote AP VPN for more information.
Policy
This field displays the content of the local and remote policies for this remote AP. The IP addresses, not the address objects, are displayed.
My Address
This field displays the IP address of the Zyxel Device.
Secure Gateway
This field displays the IP address of the remote AP.
Up Time
This field displays how many seconds the remote AP has been connected to the Zyxel Device.
Timeout
This field displays how many seconds remain before the Zyxel Device disconnects from the remote AP.
Inbound (Bytes)
This field displays the amount of traffic that has gone through the IPSec tunnel from the remote AP to the Zyxel Device since the remote AP was established.
Outbound (Bytes)
This field displays the amount of traffic that has gone through the IPSec tunnel from the Zyxel Device to the remote AP since the remote AP was established.
The App Patrol Screen
Application patrol provides a convenient way to manage the use of various applications on the network. It manages general protocols (for example, HTTP and FTP) and instant messenger (IM), peer-to-peer (P2P), Voice over IP (VoIP), and streaming (RSTP) applications. You can even control the use of a particular application’s individual features (like text messaging, voice, video conferencing, and file transfers).
Click Monitor > Security Statistics > App Patrol > Summary to display the following screen. This screen displays Application Patrol statistics based on the App Patrol profiles bound to Security Policy profiles.
Monitor > Security Statistics > App Patrol > Summary
The following table describes the labels in this screen.
Monitor > Security Statistics > App Patrol > Summary
label
description
Collect Statistics
Select this check box to have the Zyxel Device collect app patrol statistics.
The collection starting time displays after you click Apply. All of the statistics in this screen are for the time period starting at the time displayed here. The format is year, month, day and hour, minute, second. All of the statistics are erased if you restart the Zyxel Device or click Flush Data. Collecting starts over and a new collection start time displays.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
App Patrol Statistics
 
#
This field is a sequential value, and it is not associated with a specific App Patrol session.
Application
This is the protocol.
Forwarded Data (KB)
This is how much of the application’s traffic the Zyxel Device has sent (in kilobytes).
Dropped Data (KB)
This is how much of the application’s traffic the Zyxel Device has discarded without notifying the client (in kilobytes). This traffic was dropped because it matched an application policy set to “drop”.
Rejected Data (KB)
This is how much of the application’s traffic the Zyxel Device has discarded and notified the client that the traffic was rejected (in kilobytes). This traffic was rejected because it matched an application policy set to “reject”.
Matched Auto Connection
This is how much of the application’s traffic the Zyxel Device identified by examining the IP payload.
Inbound Kbps
This field displays the amount of the application’s traffic that has gone to the ZyWALL (in kilo bits per second).
Outbound Kbps
This field displays the amount of the application’s traffic that has gone from the ZyWALL (in kilo bits per second).
Content Filter
These screens display some basic statistics on web content filter and DNS content filer, such as the number of web pages and FQDNs inspected.
Web Content Filter
This screens display web content filter statistics.
The following table describes the labels in this screen.
Monitor > Security Statistics > Content Filter> Web Content Filter 
Label
Description
General Settings
Collect Statistics
Select this check box to have the Zyxel Device collect web content filtering statistics.
The collection starting time displays after you click Apply. All of the statistics in this screen are for the time period starting at the time displayed here. The format is year, month, day and hour, minute, second. All of the statistics are erased if you restart the Zyxel Device or click Flush Data. Collecting starts over and a new collection start time displays.
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
Summary
Total Web Page Inspected
This field displays the number of web pages that the Zyxel Device’s web content filter feature has checked.
Blocked
This is the number of web pages that the Zyxel Device blocked access.
Web Pages Blocked by Category Service
This is the number of web pages that matched an external database web content filtering category selected in the Zyxel Device and for which the Zyxel Device displayed a warning before allowing users access.
Web Page Blocked by Custom Service
This is the number of web pages to which the Zyxel Device did not allow access due to the web content filtering custom service configuration.
Restricted Web Features
This is the number of web pages to which the ZyWALL limited access or removed cookies due to the content filtering custom service's restricted web features configuration.
Forbidden Web Sites
This is the number of web pages to which the Zyxel Device did not allow access because they matched the content filtering custom service’s forbidden web sites list.
URL Keywords
This is the number of web pages to which the Zyxel Device did not allow access because they contained one of the content filtering custom service’s list of forbidden keywords.
Warned
This is the number of web pages for which the Zyxel Device displayed a warning message to the access requesters.
Passed
This is the number of web pages to which the Zyxel Device allowed access.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
DNS Content Filter
This screens display DNS content filter statistics.
The following table describes the labels in this screen.
Monitor > Security Statistics > Content Filter> DNS Content Filter 
Label
Description
General Settings
Collect Statistics
Select this check box to have the Zyxel Device collect DNS content filtering statistics.
The collection starting time displays after you click Apply. All of the statistics in this screen are for the time period starting at the time displayed here. The format is year, month, day and hour, minute, second. All of the statistics are erased if you restart the Zyxel Device or click Flush Data. Collecting starts over and a new collection start time displays.
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
Summary
Total DNS Inspected
This field displays the number of FQDNs that the Zyxel Device’s DNS content filter feature has checked.
Redirected
This is the number of FQDNs that the Zyxel Device redirects.
Passed
This is the number of FQDNs to which the Zyxel Device allowed access.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
The Anti-Malware Screen
This screen displays anti- statistics.
The following table describes the labels in this screen.
Monitor > Security Statistics > Anti-Malware > Summary: Virus Name  
Label
Description
Collect Statistics
Select this check box to have the Zyxel Device collect anti- statistics.
The collection starting time displays after you click Apply. All of the statistics in this screen are for the time period starting at the time displayed here. The format is year, month, day and hour, minute, second. All of the statistics are erased if you restart the Zyxel Device or click Flush Data. Collecting starts over and a new collection start time displays.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
Total Viruses Detected
This field displays the number of different viruses that the Zyxel Device has detected.
Top Entries By
Use this field to have the following (read-only) table display the top anti- log entries by Virus Name, Source IP, and Destination IP, Source IPv6 and Destination IPv6. This table displays the most common, recent virus logs. See the log screen for less common virus logs or use a syslog server to record all virus logs.
Select Virus Name to list the most common viruses that the Zyxel Device has detected.
Select Source IP to list the source IP addresses from which the Zyxel Device has detected the most virus-infected files.
Select Destination IP to list the most common destination IP addresses for virus-infected files that Zyxel Device has detected.
Select Source IPv6 to list the source IPv6 addresses from which the Zyxel Device has detected the most virus-infected files.
Select Destination IPv6 to list the most common destination IPv6 addresses for virus-infected files that Zyxel Device has detected.
Add to white list
Select an entry and click this to add it to the anti- white list.
Remove from white list
Select an entry and click this to remove it from the anti- white list.
#
This field displays the entry’s rank in the list of the top entries.
Virus name
This column displays when you display the entries by Virus Name. This displays the name of a detected virus.
Hash
This column displays a hash value, MD5 (Message Digest 5) and SHA (Secure Hash Algorithm), of the detected virus file.
MD5 and SHA are hash algorithms used to authenticate packet data.
Source IP
This column displays when you display the entries by Source IP. It shows the source IP address of virus-infected files that the Zyxel Device has detected.
Source IPv6
his column displays when you display the entries by Source IPv6. It shows the source IPv6 address of virus-infected files that the Zyxel Device has detected.
Destination IP
This column displays when you display the entries by Destination IP. It shows the destination IP address of virus-infected files that the Zyxel Device has detected.
Destination IPv6
This column displays when you display the entries by Destination IPv6. It shows the destination IPv6 address of virus-infected files that the Zyxel Device has detected.
Occurrences
This field displays how many times the Zyxel Device has detected the event described in the entry.
White List
Click this to add this signature to the anti- white list.
Click this to remove this signature from the anti- white list.
The Reputation Filter Screen
This screen displays Reputation Filter statistics.
The following table describes the labels in this screen.
Monitor > Security Statistics > Reputation Filter > Summary  
Label
Description
Collect Statistics
Select this check box to have the Zyxel Device collect anti- statistics.
The collection starting time displays after you click Apply. All of the statistics in this screen are for the time period starting at the time displayed here. The format is year, month, day and hour, minute, second. All of the statistics are erased if you restart the Zyxel Device or click Flush Data. Collecting starts over and a new collection start time displays.
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
Summary
IP Scanned
This field displays the total number of IPv4 addresses that have been scanned.
IP Hit Count
This field displays the total number of the hit counts on the scanned IPv4 addresses.
URL Scanned
This field displays the total number of URLs that have been scanned.
URL Hit Count
This field displays the total number of the hit counts on the scanned URLs.
IP Detected
Add to white list
Select an entry and click this to add it to the IP reputation white list.
Remove from white list
Select an entry and click this to remove it from the IP reputation white list.
Time
This field displays the date and time the entry was created.
Malicious IP
This field displays the IPv4 address with bad reputation.
Infected/Victim Host
This field displays the MAC address of the infected host.
Threat Category
This field displays the category of the entry.
Threat Level
This field displays the threat level of the entry.
URL Detected
Add to white list
Select an entry and click this to add it to the URL Threat filtering white list.
Remove from white list
Select an entry and click this to remove it from the URL Threat filtering white list.
Time
This field displays the date and time the entry was created.
Source IP
This field displays the source IP address of traffic that you want to trace.
Destination IP
This field displays the destination IP address of traffic.
Threat URL
This field displays the URL of an infected website or a botnet C&C server.
Threat Category
This field displays the category of the entry.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
The IPS Screen
This screen displays IPS (Intrusion Prevention System) statistics.
The following table describes the labels in this screen.
Monitor > Security Statistics > IPS > Summary 
Label
Description
Collect Statistics
Select this check box to have the Zyxel Device collect IPS statistics.
The collection starting time displays after you click Apply. All of the statistics in this screen are for the time period starting at the time displayed here. The format is year, month, day and hour, minute, second. All of the statistics are erased if you restart the Zyxel Device or click Flush Data. Collecting starts over and a new collection start time displays.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
Total Session Scanned
This field displays the number of sessions that the Zyxel Device has checked for intrusion characteristics.
Total Packet Dropped
The Zyxel Device can detect and drop malicious packets from network traffic. This field displays the number of packets that the Zyxel Device has dropped.
Total Packet Reset
The Zyxel Device can detect and drop malicious packets from network traffic. This field displays the number of packets that the Zyxel Device has reset.
Top Entries By
Use this field to have the following (read-only) table display the top IPS log entries by Signature Name, Source IP or Destination IP. This table displays the most common, recent IPS logs. See the log screen for less common IPS logs or use a syslog server to record all IPS logs.
Select Signature Name to list the most common signatures that the Zyxel Device has detected.
Select Source IP to list the source IP addresses from which the Zyxel Device has detected the most intrusion attempts.
Select Destination IP to list the most common destination IP addresses for intrusion attempts that the Zyxel Device has detected.
Add to white list
Select a signature and click this to add the selected signature to the IPS white list.
Remove from white list
Select a signature and click this to remove the selected signature from the IPS white list.
Statistics
 
#
This field displays the entry’s rank in the list of the top entries.
Signature Name
This column displays when you display the entries by Signature Name. The signature name identifies the type of intrusion pattern. Click the hyperlink for more detailed information on the intrusion.
Signature ID
This column displays when you display the entries by Signature Name. The signature ID is a unique value given to each intrusion detected.
Type
This column displays when you display the entries by Signature Name. It shows the categories of intrusions.
Severity
This column displays when you display the entries by Signature Name. It shows the level of threat that the intrusions may pose.
Source IP
This column displays when you display the entries by Source. It shows the source IP address of the intrusion attempts.
Destination IP
This column displays when you display the entries by Destination. It shows the destination IP address at which intrusion attempts were targeted.
Occurrences
This field displays how many times the Zyxel Device has detected the event described in the entry.
White List
Click this to add this signature to the IPS white list.
Click this to remove this signature from the IPS white list.
Rate Based Signatures Statistics
This table displays the rate based signatures statistics.
IPS signatures identify traffic packets with suspicious malicious patterns. The Zyxel Devicecan then respond instantaneously according to the action you define.
If you do not want the Zyxel Device to respond instantaneously for each suspicious packet detected, use rate based signatures. See What You Need To Know for more information on rate based signatures.
#
This field displays the entry’s rank in the list of the top entries.
Time
This column displays the date and time IPS blocked this IP address.
Signature ID
This column displays when you display the entries by Signature Name. The signature ID is a unique value given to each intrusion detected.
Signature Name
This column displays when you display the entries by Signature Name. The signature name identifies the type of intrusion pattern. Click the hyperlink for more detailed information on the intrusion.
Blocked IP
This field displays the IP address that is blocked by IPS.
Interactive/Victim Host
This field displays the IP address of the infected host.
Time Remaining
This field displays the amount of time left until the blocked IP address is released by IPS.
The Email Security Screens
Email Security Summary
This screen displays spam statistics.
The following table describes the labels in this screen.
Monitor > Security Statistics > Email Security > Summary 
Label
Description
Collect Statistics
Select this check box to have the Zyxel Device collect email security statistics.
The collection starting time displays after you click Apply. All of the statistics in this screen are for the time period starting at the time displayed here. The format is year, month, day and hour, minute, second. All of the statistics are erased if you restart the Zyxel Device or click Flush Data. Collecting starts over and a new collection start time displays.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
Email Summary
Total Mails Scanned
This field displays the number of emails that the Zyxel Device’s email security feature has checked.
Safe Mails
This is the number of emails that the Zyxel Device has determined to not be spam.
Safe Mails Detected by White list
This is the number of emails that matched an entry in the Zyxel Device’s email security white list.
Spam Mails
This is the number of emails that the Zyxel Device has determined to be spam.
Spam Mails Detected by Black List
This is the number of emails that matched an entry in the Zyxel Device’s email security black list.
Spam Mails Detected by Malicious Mail
This is the number of emails that the Zyxel Device has determined to have malicious contents.
Spam Mails Detected by DNSBL
The Zyxel Device can check the sender and relay IP addresses in an email’s header against DNS (Domain Name Service)-based spam Black Lists (DNSBLs). This is the number of emails that had a sender or relay IP address in the header which matched one of the DNSBLs that the Zyxel Device uses.
Query Timeout
This is how many queries that were sent to the Zyxel Device’s configured list of DNSBL domains or Mail Scan services and did not receive a response in time.
When mail session threshold is reached
Mail Sessions Forwarded
This is how many email sessions the Zyxel Device allowed because they exceeded the maximum number of email sessions that the email security feature can check at a time.
You can see the Zyxel Device’s threshold of concurrent email sessions on the Email Security > Status screen.
Use the Email Security > Summary screen to set whether the Zyxel Device forwards or drops sessions that exceed this threshold.
Mail Sessions Dropped
This is how many email sessions the Zyxel Device dropped because they exceeded the maximum number of email sessions that the email security feature can check at a time.
You can see the Zyxel Device’s threshold of concurrent email sessions on the Email Security > Status screen.
Use the Email Security > Summary screen to set whether the Zyxel Device forwards or drops sessions that exceed this threshold.
Statistics
Top Sender By
Use this field to list the top email or IP addresses from which the Zyxel Device has detected the most spam.
Select Sender IP to list the source IP addresses from which the Zyxel Device has detected the most spam.
Select Sender Email Address to list the top email addresses from which the Zyxel Device has detected the most spam.
#
This field displays the entry’s rank in the list of the top entries.
Sender IP
This column displays when you display the entries by Sender IP. It shows the source IP address of spam emails that the Zyxel Device has detected.
Sender Email Address
This column displays when you display the entries by Sender Email Address. This column displays the email addresses from which the Zyxel Device has detected the most spam.
Occurrence
This field displays how many spam emails the Zyxel Device detected from the sender.
The Email Security Status Screen
Use the Email Security Status screen to see how many email sessions the email security feature is scanning and statistics for the DNSBLs.
The following table describes the labels in this screen.
Monitor > Security Statistics > Email Security > Status
Label
Description
Resource Status
 
Concurrent Mail Session Scanning
The darker shaded part of the bar shows how much of the Zyxel Device’s total spam checking capability is currently being used.
The lighter shaded part of the bar and the pop-up show the historical high.
The first number to the right of the bar is how many email sessions the Zyxel Device is presently checking for spam. The second number is the maximum number of email sessions that the Zyxel Device can check at once. An email session is when an email client and email server (or two email servers) connect through the Zyxel Device.
Refresh
Click this button to update the information displayed on this screen.
Flush
Click this button to clear the DNSBL statistics. This also clears the concurrent mail session scanning bar’s historical high.
Mail Scan Statistics
These are the statistics for the service the Zyxel Device uses. These statistics are for when the Zyxel Device actually queries the service servers.
#
This is the entry’s index number in the list.
Service
This displays the name of the service.
Total Queries
This is the total number of queries the Zyxel Device has sent to this service.
Avg. Response Time (sec)
This is the average for how long it takes to receive a reply from this service.
No Response
This is how many queries the Zyxel Device sent to this service without receiving a reply.
DNSBL Statistics
These are the statistics for the DNSBL the Zyxel Device uses. These statistics are for when the Zyxel Device actually queries the DNSBL servers. Matches for DNSBL responses stored in the cache do not affect these statistics.
#
This is the entry’s index number in the list.
DNSBL Domain
These are the DNSBLs the Zyxel Device uses to check sender and relay IP addresses in emails.
Total Queries
This is the total number of DNS queries the Zyxel Device has sent to this DNSBL.
Avg. Response Time (sec)
This is the average for how long it takes to receive a reply from this DNSBL.
No Response
This is how many DNS queries the Zyxel Device sent to this DNSBL without receiving a reply.
Collaborative Detection & Response (CDR)
Collaborative Detection & Response (CDR) allows you to detect wired and WiFi clients that are sending malicious traffic in your network and then block or quarantine traffic coming from them. In this way, malicious traffic is not spread throughout the network. Secure policies can block malicious traffic for specific traffic flows, but CDR can block malicious traffic from the sender. Malicious traffic is identified using a combination of Web Filtering, Anti-Malware and IPS (IDP) signatures.
The following table describes the labels in this screen.
Monitor > Security Statistics > CDR > Containment List 
Label
Description
Containment List
This table displays up to 512 devices that CDR is blocking or quarantining. Containment list items remain even if the Zyxel Device or managed AP reboots.
Group by
Choose to sort security events for contained devices by IP Address or MAC Address. For example, if three security events occur for a client identified by IP address, then under Time, the IP address of the client is shown with the times the security events occurred beneath this IP address.
Wired clients are blocked based on IP address by default. You can change that to blocking based on MAC address using the cdr blocked-by mac command in configuration mode in the Command Line Interface (CLI). Note that if you have a switch between the client and the Zyxel Device, then blocking by MAC address could block all traffic from the switch if the client MAC address is not forwarded through the switch.
WiFi clients are blocked or quarantined based on MAC address by default.
Add to exempt list
Select a client and then click this to release this device from CDR containment and also bypass this device from future CDR checking. This device is then removed from this table and added to the History screen.
Release
Select a client and then click this to release this device from CDR containment. This device is then removed from this table and added to the History screen.
Time
This field displays the date and time CDR contained this client
IP Address
This field displays the IPv4 address of the client contained by CDR.
MAC Address
This field displays the MAC address of the client contained by CDR.
User
The field displays the user name of a client contained by CDR who has been authenticated for Internet access. The field is blank if user authentication is not required.
Security Events
This field displays details on the category of signature that triggered CDR: Web Filtering, Anti-Malware or IPS (IDP).
Containment
This field displays if the client is blocked, quarantined or just triggers an alert.
Time Remaining (Seconds)
This field displays the amount of time left until this client is released by CDR
Connect to
This field displays the description of the AP or the interface of the Zyxel Device that the contained client is connected to.
Refresh
Click this button to update the information on the screen.
CDR History
The following table describes the labels in this screen.
Monitor > Security Statistics > CDR> History 
Label
Description
History
This table displays up to 1024 devices that CDR has blocked or quarantined
Time
This field displays the date and time CDR contained this client
IP Address
This field displays the IPv4 address of the client contained by CDR.
MAC Address
This field displays the MAC address of the client contained by CDR.
User
The field displays the user name of a client contained by CDR who has been authenticated for Internet access. The field is blank if user authentication is not required.
Security Events
This field displays details on the category of signature that triggered CDR: Web Filtering, Anti-Malware or IPS (IDP).
Containment
This field displays if the client is blocked, quarantined or just triggers an alert.
Connect to
This field displays the description of the AP or the interface of the Zyxel Device that the contained client is connected to.
Refresh
Click this button to update the information on the screen.
The SSL Inspection Screens
The Zyxel Device uses SSL Inspection to decrypt SSL traffic, sends it to the Security Service engines for inspection, then encrypts traffic that passes inspection and forwards it. You must enable SSL Inspection if you want to use Content Filtering 2.0 Safe Search.
The following table describes the labels in this screen.
Monitor > Security Statistics > SSL Inspection > Summary 
Label
Description
Collect Statistics
Select this check box to have the Zyxel Device collect SSL Inspection statistics.
The collection starting time displays after you click Apply. All of the statistics in this screen are for the time period starting at the time displayed here. The format is year, month, day and hour, minute, second. All of the statistics are erased if you restart the Zyxel Device or click Flush Data. Collecting starts over and a new collection start time displays.
Apply
Click Apply to save your changes back to the Zyxel Device.
Reset
Click Reset to return the screen to its last-saved settings.
Refresh
Click this button to update the report display.
Flush Data
Click this button to discard all of the screen’s statistics and update the report display.
Status
 
Maximum Concurrent Sessions
This shows the maximum number of simultaneous SSL Inspection sessions allowed for your Zyxel Device model.
Concurrent Sessions
This shows the actual number of simultaneous SSL Inspection sessions in progress.
Summary
 
Total SSL Sessions
This is the total of SSL sessions inspected and number of sessions blocked and number of sessions passed since data was last flushed or the Zyxel Device last rebooted after Collect Statistics was enabled.
Sessions Inspected
This shows the total number of SSL sessions inspected since data was last flushed or the Zyxel Device last rebooted after Collect Statistics was enabled
Decrypted (Kbytes)
This shows the number of kilobytes (KB) of data that was decrypted for Security Service inspection.
Encrypted (Kbytes)
This shows the number of kilobytes (KB) of data that was re-encrypted after Security Service inspection and then forwarded.
Sessions Blocked
This shows the number of SSL sessions blocked.
Sessions Passed
This shows the number of SSL sessions passed.
Certificate Cache List
SSL traffic to a server to be excluded from SSL Inspection is identified by its certificate. Traffic in an Exclude List is not intercepted by SSL Inspection.
The following table describes the labels in this screen.
Monitor > Security Statistics > SSL Inspection > Certificate Cache List  
Label
Description
Certificate Cache List
 
Add to Exclude list
Select and item in the list and click this icon to add the common name (CN) to the Exclude List.
#
This field is a sequential value, and it is not associated with a specific entry.
In Exclude List
If any one of common name, DNS name, email address or IP address of the certificate is in the Exclude List, then traffic to the server identified by the certificate is excluded from inspection.
The icons here are defined as follows:
Gray: The identity of the certificate is not in the Exclude List
Green: The common name of the certificate is in the Exclude List
Yellow: The common name of certificate is not in the Exclude List but one of the DNS name, email address or IP address is.
Time
This is the latest date (yyyy-mm-dd) and time (hh-mm-ss) that the record in the certificate cache list was met.
Common Name
This displays the common name in the certificate of the SSL traffic destination server.
Server Name Indication
Server Name Indication (SNI) is the domain name entered in the browser, FTP client, etc. to begin the SSL session with the server. It allows multiple SSL sessions to the same IP address and port number with different certificates from different SNI. This field displays the SNI for this SSL session.
SSL Version
This field shows the SSL version. SSLv3/TLS1.0 is currently supported.
Destination
This displays the IP address and port number of the SSL traffic destination server.
Valid Time
This displays the cache item expiry time in seconds. The cache item is deleted when the remaining time expires.
Refresh
Click this button to update the information on the screen.
Log
Log messages are stored in two separate logs, one for regular log messages and one for debugging messages. In the regular log, you can look at all the log messages by selecting All Logs, or you can select a specific category of log messages (for example, security policy or user). You can also look at the debugging log by selecting Debug Log. All debugging messages have the same priority.
Note: When a log reaches the maximum number of log messages, new log messages automatically overwrite existing log messages, starting with the oldest existing log message first.
Events that generate an alert (as well as a log message) display in red. Regular logs display in black. Click a column’s heading cell to sort the table entries by that column’s criteria. Click the heading cell again to reverse the sort order.
Monitor > Log > View Log 
Label
Description
Show (Hide) Filter
Click this button to show or hide criteria that allow you to filter logs that will be displayed.
If the filter settings are hidden, the Category, Email Log Now, Refresh, and Clear fields are available.
If the filter settings are shown, the Category, Priority, Source Address, Destination Address, Source Interface, Destination Interface, Service, Keyword, Protocol and Search fields are available.
Category
Select the type of log message(s) you want to view. You can also view All Logs at one time, or you can view the Debug Log.
Priority
This displays when you show the filter. Select the priority of log messages to display. The log displays the log messages with this priority or higher. Choices are: any, emerg, alert, crit, error, warn, notice, and info, from highest priority to lowest priority. This field is grayed out if the Category is Debug Log.
Source Address
This displays when you show the filter. Type the source IP address of the incoming packet that generated the log message. Do not include the port in this filter.
Destination Address
This displays when you show the filter. Type the IP address of the destination of the incoming packet when the log message was generated. Do not include the port in this filter.
Source Interface
This displays when you show the filter. Type the source interface of the incoming packet that generated the log message.
Destination Interface
This displays when you show the filter. Type the interface of the destination of the incoming packet when the log message was generated.
Service
This displays when you show the filter. Select the service whose log messages you would like to see. The Web Configurator uses the protocol and destination port number(s) of the service to select which log messages you see.
Keyword
This displays when you show the filter. Type a keyword to look for in the Message, Source, Destination and Note fields. If a match is found in any field, the log message is displayed. You can use up to 63 alphanumeric characters and the underscore, as well as punctuation marks ()’ ,:;?! +-*/= #$% @ ; the period, double quotes, and brackets are not allowed.
Protocol
This displays when you show the filter. Select a service protocol whose log messages you would like to see.
Search
This displays when you show the filter. Click this button to update the log using the current filter settings.
Reset
Click Reset to return the screen to its last-saved settings.
Email Log Now
Click this button to send log message(s) to the Active email address(es) specified in the Send Log To field on the Log Settings page.
Refresh
Click this button to update the information on the screen.
Clear
Click this button to clear the whole log, regardless of what is currently displayed on the screen.
#
This field is a sequential value, and it is not associated with a specific log message.
Time
This field displays the time the log message was recorded.
Priority
This field displays the priority of the log message. It has the same range of values as the Priority field above.
Category
This field displays the log that generated the log message. It is the same value used in the Category field above.
Message
This field displays the reason the log message was generated. The text “[count=x]”, where x is a number, appears at the end of the Message field if log consolidation is turned on and multiple entries were aggregated to generate into this one.
Source
This field displays the source IP address and the port number in the event that generated the log message.
Destination
This field displays the destination IP address and the port number of the event that generated the log message.
Note
This field displays any additional information about the log message.
View AP Log
The following table describes the labels in this screen.
Monitor > Log > View AP Log 
Label
Description
Show Filter
Click this button to show or hide the filter settings.
If the filter settings are hidden, the Display, Email Log Now, Refresh, and Clear fields are available.
If the filter settings are shown, the Display, Priority, Source Address, Destination Address, Source Interface, Destination Interface, Service, Keyword, Protocol, and Search fields are available.
Select an AP
Click the pull down menu to choose an AP.
Query
Click Query to create a Query log.
Log Query Status
The field displays the
AP Information
This field displays the AP information. N/A is displayed when
Log File Status
This field displays how many logs are available. It will display Empty if there’s none.
Last Log Query Time
This field displays the most recent time a log query was solicited.
Display
Select the category of log message(s) you want to view. You can also view All Logs at one time, or you can view the Debug Log.
Priority
This displays when you show the filter. Select the priority of log messages to display. The log displays the log messages with this priority or higher. Choices are: any, emerg, alert, crit, error, warn, notice, and info, from highest priority to lowest priority. This field is read-only if the Category is Debug Log.
Source Address
Type the IP address of the source AP.
Destination Address
This displays when you show the filter. Type the IP address of the destination of the incoming packet when the log message was generated. Do not include the port in this filter.
Source Interface
This displays when you show the filter. Type the source interface of the incoming packet that generated the log message.
Destination Interface
This displays when you show the filter. Type the interface of the destination of the incoming packet when the log message was generated.
Service
Select a policy service available from Zyxel Device from the pull down menu.
Keyword
Type a keyword of the policy service available from Zyxel Device to search for a log.
Protocol
Select the protocol of the AP from the pull down menu.
Search
Click this to start the search.
Email Log Now
Click this button to send log message(s) to the Active email address(es) specified in the Send Log To field on the Log Settings page.
Refresh
Click this button to update the information on the screen.
Clear
Click this button to clear the whole log, regardless of what is currently displayed on the screen.
#
This field is a sequential value, and it is not associated with a specific log message.
Time
This field displays the time the log message was recorded.
Priority
This displays when you show the filter. Select the priority of log messages to display. The log displays the log messages with this priority or higher. Choices are: any, emerg, alert, crit, error, warn, notice, and info, from highest priority to lowest priority. This field is read-only if the Category is Debug Log.
Category
This field displays the log that generated the log message. It is the same value used in the Display and (other) Category fields.
Message
This field displays the message of the log.
Source
This displays the source IP address of the selected log message.
Destination
This displays the source IP address of the selected log message.
Note
This field displays any additional information about the log message.
Dynamic Users Log
Use this screen to view the Zyxel Device’s dynamic guest account log messages.
The following table describes the labels in this screen.
Monitor > Log > Dynamic Users Log 
Label
Description
Begin/End Date
Select the first and last dates to specify a time period. The Zyxel Device displays log messages only for the accounts created during the specified time period after you click Search.
Begin/End Time
Select the begin time of the first date and the end time of the last date to specify a time period. The Zyxel Device displays log messages only for the accounts created during the specified time period after you click Search.
Search
Click this button to update the information on the screen using the filter criteria in the date and time fields.
Refresh
Click this button to update the information in the screen.
Clear
Click this button to delete the log messages for invalid accounts.
#
This is the index number of the dynamic guest account in the list.
Status
This field displays whether an account expires or not.
Username
This field displays the user name of the account.
Create Time
This field displays when the account was created.
Remaining Time
This field displays the amount of Internet access time remaining for each account.
Time Period
This field displays the total account of time the account can use to access the Internet through the Zyxel Device.
Expiration Time
This field displays the date and time the account becomes invalid.
*Once the time allocated to a dynamic account is used up or a dynamic account remains un-used after the expiration time, the account is deleted from the account list.
Quota (T/U/D)
This field displays how much data in both directions (Total) or upstream data (Upload) and downstream data (Download) can be transmitted through the WAN interface before the account expires.
Remaining Quota (T/U/D)
This field displays the remaining amount of data that can be transmitted or received by each account. You can see the amount of either data in both directions (Total) or upstream data (Upload) and downstream data (Download).
Bandwidth (U/D)
This field displays the maximum upstream (Upload) and downstream (Download) bandwidth allowed for the user account in kilobits per second.
Real Name
This field displays the user’s name of the account.
Email
This field displays the email of the account.
Charge
This field displays the total cost of the account.
Payment Info
This field displays the method of payment for each account.
Phone Num
This field displays the telephone number for the user account.