Watchguard V10.0 Uživatelská příručka

Procházejte online nebo si stáhněte Uživatelská příručka pro Sítě Watchguard V10.0. Watchguard V10.0 User guide [en] Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 322
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 0
Firebox
®
Vclass
User Guide
Vcontroller
4.0
Notice to Users
Information in this guide is subject to change without notice. Companies, names, and data used in examples herein are
fictitious unless otherwise noted. No part of this guide may be reproduced or transmitted in any form or by any means,
electronic or mechanical, for any purpose, without the express written permission of WatchGuard Technologies, Inc.
Copyright, Trademark, and Patent Information
Copyright© 1998 - 2002 WatchGuard Technologies, Inc. All rights reserved.
VclassUserGuide.book Page i Friday, January 3, 2003 10:09 AM
Zobrazit stránku 0
1 2 3 4 5 6 ... 321 322

Shrnutí obsahu

Strany 1 - User Guide

Firebox® Vclass User Guide Vcontroller™ 4.0Notice to UsersInformation in this guide is subject to change without notice. Companies, names, and data us

Strany 2 - Notice to Users

x Vcontroller 4.01. Ownership and License. The SOFTWARE PRODUCT is protected by copyright laws and international copyright treaties, as well as other

Strany 3 - Firebox Vclass User Guide iii

80 Vcontroller 4.0Before initiating a certificate request, you must obtain the following:• The encryption key cosigning authority’s name and web site

Strany 4

Certificate ConfigurationFirebox Vclass User Guide 813 Type the following information: NameThe name of the Firebox Vclass appliance. This is the same

Strany 5 - Firebox Vclass User Guide v

82 Vcontroller 4.05 Fill in the following information and click Next.Subject NameThis field is automatically updated with processed data from your fir

Strany 6

Certificate ConfigurationFirebox Vclass User Guide 837 Select the text in the dialog box and then press Control+a.8 Click Copy.9 Open a Web browser an

Strany 7 - Firebox Vclass User Guide vii

84 Vcontroller 4.014 Review the information displayed in the Certificate Request dialog box, and then click Finish.The Certificate Request dialog box

Strany 8

Certificate ConfigurationFirebox Vclass User Guide 854 Click Copy/Close to return to the Review CSR dialog box.A copy of the CSR is sent to the clipbo

Strany 9 - Firebox Vclass User Guide ix

86 Vcontroller 4.05 When the certificate text is displayed, click Import Certificate.This imports the certificate into the Firebox Vclass appliance. A

Strany 10

LDAP Server ConfigurationFirebox Vclass User Guide 87LDAP Server ConfigurationUse the LDAP tab to set up a connection between a Firebox Vclass applian

Strany 11 - Firebox Vclass User Guide xi

88 Vcontroller 4.04 If the LDAP server is not using the default port number 389, type the correct port number in the appropriate field.When you have f

Strany 12

NTP Server ConfigurationFirebox Vclass User Guide 892 To enable NTP, click Yes.If you later decide to disable NTP, click No.3 Enter the IP address of

Strany 13 - Contents

Firebox Vclass User Guide xiNONINFRINGEMENT, ANY WARRANTY THAT THE SOFTWARE PRODUCT WILL MEET YOUR REQUIREMENTS, ANY WARRANTY OF UNINTERRUPTED OR ERRO

Strany 14

90 Vcontroller 4.02 Click Yes to restart NTP.When you have finished configuring the NTP server settings, click one of the following options:ResetTo re

Strany 15 - Firebox Vclass User Guide xv

Advanced ConfigurationFirebox Vclass User Guide 91The following global policy settings are displayed:TCP Syn CheckingThis option enables the inspectio

Strany 16

92 Vcontroller 4.0 - To ignore a DF bit (Don’t Fragment) during an IPSec transmission, click the Ignore DF for IPSec checkbox. - To allow IPSec traffi

Strany 17

Hacker Prevention OptionsFirebox Vclass User Guide 932 You can customize and apply the following two groups of options at this time:“Denial-of-service

Strany 18

94 Vcontroller 4.0ICMP Flood AttackSafeguards your network from a sustained flood of ICMP pings. After clicking the checkbox, enter the threshold numb

Strany 19 - Firebox Vclass User Guide xix

CPM Management ConfigurationFirebox Vclass User Guide 95Per Client QuotaRestricts the number of connection requests from a single client within a seco

Strany 20 - Configurations

96 Vcontroller 4.02 Click the Enable CPM Management checkbox.3 Type the CPM server IP address in the appropriate field.4 Type the CPM server port in t

Strany 21 - Introduction

Managing Software LicensesFirebox Vclass User Guide 976 Type the new password and retype it in the appropriate fields.7 Click OK.When you have finishe

Strany 22 - 2 Vcontroller 4.0

98 Vcontroller 4.0To import a new license, follow these steps:2 Click Add.The Import License dialog box appears.VclassUserGuide.book Page 98 Friday,

Strany 23 - Linux workstation

Managing Software LicensesFirebox Vclass User Guide 993 Click Load the license from a file.4 Locate and select the license file. NOTEIf you prefer, y

Strany 24 - Software License Keys

xii Vcontroller 4.0VclassUserGuide.book Page xii Friday, January 3, 2003 10:09 AM

Strany 25 - Mobile User VPN

100 Vcontroller 4.03 Review the license information.4 When you are finished, click Close.To see which features are currently active, follow these step

Strany 26 - About This Guide

VLAN Forwarding OptionFirebox Vclass User Guide 101VLAN forwarding, you can create security policies for VLAN traffic, but you must activate the relat

Strany 27 - Service and Support

102 Vcontroller 4.0 NOTEIf this tab is not visible, this Firebox Vclass appliance does not incorporate these VLAN-forwarding features.2 Click the che

Strany 28 - Broadcasts

High Availability ConfigurationFirebox Vclass User Guide 103High Availability ConfigurationUse the High Availability tab to configure all of the neces

Strany 29 - Service

104 Vcontroller 4.0VclassUserGuide.book Page 104 Friday, January 3, 2003 10:09 AM

Strany 30 - The Feature Key page appears

Firebox Vclass User Guide 105CHAPTER 6 Using Account ManagerThis chapter shows you how to create three separate types of access accounts.Admin and sup

Strany 31 - Self Help Tools

106 Vcontroller 4.0 NOTEVcontroller provides one default super admin account with primary master privileges. Only one user can be logged in as defaul

Strany 32 - Interactive Support Forum

Configuring AccountsFirebox Vclass User Guide 1072 Click Add.The account settings become active.3 Type an account name in the appropriate field.The ac

Strany 33 - Assisted Support

108 Vcontroller 4.09 Repeat this process to add more accounts.10 When you have finished, click Close.End-user accounts for authenticationYou can confi

Strany 34 - Gold Program

Configuring AccountsFirebox Vclass User Guide 109https://10.10.10.273 Press Return.A Security Alert dialog box should appear, according to the browser

Strany 35 - Training and Certification

Firebox Vclass User Guide xiiiContentsCHAPTER 1 Introduction ...1Welcome to WatchGuard® ...

Strany 36 - Using the Online Help

110 Vcontroller 4.0This hides the list of accounts from view, and replaces the minus box with a plus box.If you need to see all those accounts at a la

Strany 37 - Getting Started

External Access for Remote ManagementFirebox Vclass User Guide 1113 When you have finished, click Close to save your changes and close the Account Man

Strany 38 - Gathering Network Information

112 Vcontroller 4.0As for all other admin access accounts (which can only be used to check the status and clear new alarms), any number of account use

Strany 39 - Firebox Vclass User Guide 19

Firebox Vclass User Guide 113CHAPTER 7 About Security PoliciesThe purpose of a Firebox Vclass appliance is to determine whether data is to be passed o

Strany 40 - 20 Vcontroller 4.0

114 Vcontroller 4.0Security policy componentsEvery security policy is composed of two basic components: the traffic specifications and an action.Traff

Strany 41 - Firebox Vclass User Guide 21

About Security PoliciesFirebox Vclass User Guide 115• Encrypt and authenticate your data for secure transmission through insecure networks.• Enable va

Strany 42 - Cabling the Appliance

116 Vcontroller 4.0address behind an alias with SNAT, so that the alias is the only network ID visible to external users.Virtual IP load balancing use

Strany 43 - Using Appliance Discovery

Using Policy ManagerFirebox Vclass User Guide 117destination and then apply both an IPSec action and a load-balancing action.Not all actions can be co

Strany 44 - If no appliance is discovered

118 Vcontroller 4.0• Click Address Group to view the list of defined entries.The Address Group dialog box appears. - To create a new Address Group, cl

Strany 45 - If an appliance is discovered

Using Policy ManagerFirebox Vclass User Guide 119• Click QoS Action to view the list of defined entries.The QoS Action dialog box appears. - To create

Strany 46 - 26 Vcontroller 4.0

xiv Vcontroller 4.0Assisted Support ... 13LiveSecurity® Program ...

Strany 47 - Before You Begin

120 Vcontroller 4.0• To save the settings to the Management Station and apply them to the Firebox Vclass appliance when it is restarted, click OK.• To

Strany 48 - The Login dialog box appears

Using Policy ManagerFirebox Vclass User Guide 121Follow these steps to apply system-wide QoS port shaping:1 Click System QoS.The System QoS dialog box

Strany 49 - Edit the General information

122 Vcontroller 4.02 Type the IP address of the external device from which the expected source traffic will arrive in the Source field.3 Type the IP a

Strany 50 - 30 Vcontroller 4.0

Using Policy ManagerFirebox Vclass User Guide 123The Policy Checker starts at the top of the policy list and checks your test parameters against every

Strany 51 - Configure the Interfaces

124 Vcontroller 4.0• Click the Up or Down arrow key, as shown above, depending on which direction the move is to occur.• Continue to click until the s

Strany 52 - 32 Vcontroller 4.0

Defining a Security PolicyFirebox Vclass User Guide 125Defining a Security PolicyThe Insert Security Policy dialog box allows you to combine traffic s

Strany 53 - Installation Wizard

126 Vcontroller 4.0DMZ_PORT_IPThe IP address of the DMZ interface.DMZ2_PORT_IPThe IP address of the second DMZ interface.INTERFACE_IPSThe IP addresses

Strany 54 - Configure Routing

Defining a Security PolicyFirebox Vclass User Guide 1274 From the Type drop list, select the category of members that will be the source or destinatio

Strany 55 - Define the DNS servers

128 Vcontroller 4.06 When you are finished, click Done.The new member name is displayed in the Address Group Members list of the New Address Group dia

Strany 56 - 36 Vcontroller 4.0

Defining a Security PolicyFirebox Vclass User Guide 1292 Type a name and brief description for the service in the appropriate fields. The Description

Strany 57 - Firebox Vclass User Guide 37

Firebox Vclass User Guide xvCHAPTER 4 Firebox Vclass Basics ...45What is a Firebox Vclass Appliance? ...

Strany 58 - 38 Vcontroller 4.0

130 Vcontroller 4.0 - Select Single Service from the Type drop list. -From the Protocol drop list, make the appropriate selection. -In the Server Port

Strany 59 - Denial of service preventions

Using TenantsFirebox Vclass User Guide 131Defining the incoming interfaceThe final component of a traffic specification is the incoming interface, whi

Strany 60 - Change the Password

132 Vcontroller 4.0All Vclass security appliances support IEEE 802.1q VLAN packets, which allows a network administrator to create separate policies f

Strany 61 - Firebox Vclass User Guide 41

Using TenantsFirebox Vclass User Guide 133 NOTEThe current line of Firebox Vclass appliances recognize VLAN/802.1Q headers in data for routing purpos

Strany 62 - 4 Click Finish

134 Vcontroller 4.0Defining tenantsFollow these steps to create VLAN tenants:1 Click New next to the Tenant drop list.The New Tenant dialog box appear

Strany 63 - Firebox Vclass User Guide 43

Using TenantsFirebox Vclass User Guide 1352 Select the interface that connects to the VLAN network from the Interface drop list.3 In the VLAN IP field

Strany 64 - 44 Vcontroller 4.0

136 Vcontroller 4.09 In the Secondary RADIUS Secret field, type the password used by this Firebox to gain access to any available backup RADIUS system

Strany 65 - Firebox Vclass Basics

Using Quality of Service (QoS)Firebox Vclass User Guide 137PassPermits all qualifying external traffic through the firewall.BlockPrevents all qualifyi

Strany 66 - Firebox Vclass Features

138 Vcontroller 4.0For example, data exchanges between the corporate center and branch offices can be allotted a weight of 20 while Internet traffic i

Strany 67 - Vcontroller at

Using Quality of Service (QoS)Firebox Vclass User Guide 1392 Type a name and brief description for the QoS action in the appropriate fields. The Descr

Strany 68

xvi Vcontroller 4.0Importing a certificate or CRL file ... 85LDAP Server Configuration ...

Strany 69 - The Vcontroller Main Page

140 Vcontroller 4.02 Click one of the following TOS marking options: TOS Precedence, TOS Precedence and DTR, or DiffServe CodePoint.3 Enable either Fo

Strany 70 - Policy column buttons

About NATFirebox Vclass User Guide 141elsewhere only see outgoing packets from the Firebox Vclass appliance itself. You can improve security by mappin

Strany 71 - Firebox Vclass User Guide 51

142 Vcontroller 4.0Dynamic NATIf you have a number of employees or other private network users whose client computers have been assigned IP addresses

Strany 72 - 52 Vcontroller 4.0

Defining a NAT ActionFirebox Vclass User Guide 143Defining a NAT ActionTo create a Dynamic NAT action using a Public IP address:• Select Dynamic NAT f

Strany 73 - The status viewer

144 Vcontroller 4.08 Type the publicly routable IP address in the IP Address field.9 Click Done to close the New Mapping dialog box and return to the

Strany 74 - 2 Click Yes

Defining a Load-Balancing ActionFirebox Vclass User Guide 145Defining a Load-Balancing ActionFollow these steps to define a load-balancing action:1 Cl

Strany 75 - Shutting Down and Rebooting

146 Vcontroller 4.02 Enable one of these options and follow these instructions:Address GroupSelect an option from the drop list.IP AddressType the IP

Strany 76 - 56 Vcontroller 4.0

Using Policy SchedulesFirebox Vclass User Guide 147Defining a ScheduleFollow these steps to define a schedule:1 Click New from the right of the Schedu

Strany 77 - Restarting the appliance

148 Vcontroller 4.04 Click to select the checkbox labeled Period 1.5 Type the values in the From and To fields, or use the arrow buttons to adjust the

Strany 78 - 58 Vcontroller 4.0

Using the Advanced SettingsFirebox Vclass User Guide 1492 Click Edit Day Schedule.The Edit Day Schedule dialog box appears.3 Click to select the check

Strany 79 - The Upgrade History

Firebox Vclass User Guide xviiUsing Tenants ...131About VLANs and tenants ...

Strany 80 - 60 Vcontroller 4.0

150 Vcontroller 4.02 Click one of the following options:Use Global SettingsSelecting this option enables the ICMP error handling global policy setting

Strany 81 - System Configuration

Using the Advanced SettingsFirebox Vclass User Guide 1514 To enable the Firebox Vclass appliance to log for this particular security policy, click Ena

Strany 82 - 62 Vcontroller 4.0

152 Vcontroller 4.0VclassUserGuide.book Page 152 Friday, January 3, 2003 10:09 AM

Strany 83 - Interface Configuration

Firebox Vclass User Guide 153CHAPTER 8 Security Policy ExamplesThis chapter includes examples of Vclass Firewall policies, VLAN policies, Quality of S

Strany 84 - 64 Vcontroller 4.0

154 Vcontroller 4.0You would meet this objective by doing the following:1 Create two firewall policies with these parameters: 2 Have all the users in

Strany 85 - Configuring Interface 0

Firewall Policy ExamplesFirebox Vclass User Guide 155This example uses the pair of firewall policies created in Example 1. Dynamic NAT provides Intern

Strany 86 - 66 Vcontroller 4.0

156 Vcontroller 4.02 Create a schedule with these parameters:NAME9 to 5, Monday - FridayDESCRIPTIONSchedule for 9:00am - 5:00pm, Monday - FridayENABLE

Strany 87 - Configuring Interface 1

Firewall Policy ExamplesFirebox Vclass User Guide 157hours), only authorized users are allowed to gain external access. Unauthorized users are still b

Strany 88 - 68 Vcontroller 4.0

158 Vcontroller 4.0Example 4: Allowing communication between branch officesAppleby Incorporated has two branch offices, each with a separate Firebox V

Strany 89 - Configuring Interface 2 or 3

Firewall Policy ExamplesFirebox Vclass User Guide 159Address Group 1:Name: Branch_1, Member type: IP Network, Addresses: 128.100.1.0, Subnet mask: 255

Strany 90 - Configuring the HA Interfaces

xviii Vcontroller 4.0QoS Policy Examples ... 168Example 1: ...

Strany 91 - Firebox Vclass User Guide 71

160 Vcontroller 4.0Example 5: Defining policies for an ISPConnectYouUp.com is an ISP with a firewall that both protects all internal private network a

Strany 92 - Routing Configuration

Firewall Policy ExamplesFirebox Vclass User Guide 1612 Reconfigure all of the computers in the private network to use a default gateway corresponding

Strany 93 - Firebox Vclass User Guide 73

162 Vcontroller 4.0• Everyone from the outside world can send email to the Mail server (accessible through interface 2).1 Open the System Configuratio

Strany 94 - Configuring dynamic routing

Firewall Policy ExamplesFirebox Vclass User Guide 163Member typeIP Network AddressesAddress126.20.20.0Subnet mask255.255.255.04 Create a schedule call

Strany 95 - DNS Configuration

164 Vcontroller 4.0VLAN Policy ExamplesThe following figure shows how a Firebox Vclass appliance can manage traffic to and from a typical VLAN.This ex

Strany 96 - 1 Click Insert

VLAN Policy ExamplesFirebox Vclass User Guide 165Address groupsVLAN tenant entriesThe requisite VPN policies on “ASP” should have the following parame

Strany 97 - SNMP Configuration

166 Vcontroller 4.0Using a Firebox Vclass appliance in a VLAN setting If your SNMP management stations, DNS servers, OSPF routers, RADIUS servers, and

Strany 98 - 4 Click Add

VLAN Policy ExamplesFirebox Vclass User Guide 167An example of a user-domain policy in useAs noted previously, the key element in user-domain tenant p

Strany 99 - Log Configuration

168 Vcontroller 4.0QoS Policy ExamplesWhen using QoS actions within your policies to prioritize your network traffic, remember that any traffic stream

Strany 100 - 1 Click the Certificate tab

Static NAT Policy ExamplesFirebox Vclass User Guide 169Static NAT Policy ExamplesThe following sections describe different examples of static NAT appl

Strany 101 - 4 Click Next

Firebox Vclass User Guide xixCHAPTER 11 Monitoring the Firebox Vclass ...215Using the Real-Time Monitor ...

Strany 102 - 6 Click Next

170 Vcontroller 4.0The static NAT action would reflect these entries:static NAT_1Internal = Internal_netExternal = AliasExample 2: Preventing conflict

Strany 103 - The final step is displayed

Static NAT Policy ExamplesFirebox Vclass User Guide 171The policies in the Site A security appliance would include these settings:The policies in the

Strany 104 - 2 Click Detail

172 Vcontroller 4.0Load Balancing Policy ExamplesConfiguring Load Balancing for a Web Server1 After starting the Vcontroller application, click Securi

Strany 105 - Certificate Configuration

Load Balancing Policy ExamplesFirebox Vclass User Guide 1734 Type a name and brief description for the policy in the appropriate fields. The Descripti

Strany 106 - 86 Vcontroller 4.0

174 Vcontroller 4.0challenge is to evenly distribute each new data request to a different server, although the requests originally expect 128.100.0.2

Strany 107 - LDAP Server Configuration

Load Balancing Policy ExamplesFirebox Vclass User Guide 1758 When the New Server dialog box appears, select IP Address and type “127.10.10.2” in the a

Strany 108 - NTP Server Configuration

176 Vcontroller 4.0VclassUserGuide.book Page 176 Friday, January 3, 2003 10:09 AM

Strany 109 - 1 Click Restart

Firebox Vclass User Guide 177CHAPTER 9 Using Virtual Private Networks (VPN)The Internet is a technical and social development that puts a multitude of

Strany 110 - Advanced Configuration

178 Vcontroller 4.0Virtual private networking technology counters this threat by using the Internet’s vast capabilities while reducing its security ri

Strany 111 - Firebox Vclass User Guide 91

About VPN PoliciesFirebox Vclass User Guide 179policies that permit secure communications between a site and authorized clients.VPN policies and IPSec

Strany 112 - Hacker Prevention Options

ii Vcontroller 4.0Notice to UsersInformation in this guide is subject to change without notice. Companies, names, and data used in examples herein are

Strany 113 - Firebox Vclass User Guide 93

xx Vcontroller 4.0DHCP Server Information ... 262CHAPTER 15 Backing Up and Restoring Configurations...

Strany 114 - 94 Vcontroller 4.0

180 Vcontroller 4.0About Authentication and EncryptionThe Firebox Vclass security appliance supports the following algorithms:Authentication Header (A

Strany 115 - CPM Management Configuration

Defining an IKE PolicyFirebox Vclass User Guide 1812 Select an entry point among the list of policies and then click Insert.The Insert IKE Policy dial

Strany 116 - The default port is 7850

182 Vcontroller 4.04 Select a preconfigured address group from the Peer Address Group drop list or click New to create a new address group. For infor

Strany 117 - Managing Software Licenses

Defining an IKE PolicyFirebox Vclass User Guide 183 NOTEThis key will be shared among all participating peer IKE systems. If a remote peer does not u

Strany 118 - 2 Click Add

184 Vcontroller 4.0MainA slower mode that provides greater security. This is the recommended mode.AggressiveA faster, less secure mode. If you choose

Strany 119 - Firebox Vclass User Guide 99

Defining a VPN Security PolicyFirebox Vclass User Guide 18512 Type the maximum size in kilobytes in the Life Length field. This field is optional.13 C

Strany 120 - VLAN Forwarding Option

186 Vcontroller 4.0address group. For information on creating an address group, see “Defining an address group” on page 126.6 Select a preconfigured

Strany 121 - Firebox Vclass User Guide 101

Defining a VPN Security PolicyFirebox Vclass User Guide 1872 Type a name and brief description for the IPSec action in the appropriate fields. The Des

Strany 122 - 102 Vcontroller 4.0

188 Vcontroller 4.04 If you selected Tunnel, you have two options: - Click the Peer Tunnel Address Group option and then select the address group that

Strany 123 - Firebox Vclass User Guide 103

Defining a VPN Security PolicyFirebox Vclass User Guide 189Defining an automatic keyAutomatic key mode requires use of the Internet Key Exchange proto

Strany 124 - 104 Vcontroller 4.0

Firebox Vclass User Guide 1CHAPTER 1 IntroductionWelcome to WatchGuard®The WatchGuard Firebox Vclass series of security appliances brings high speed n

Strany 125 - Using Account Manager

190 Vcontroller 4.02 Type a name and brief description for the IPSec proposal in the appropriate fields. The Description field is optional.3 Select an

Strany 126 - 106 Vcontroller 4.0

Defining a VPN Security PolicyFirebox Vclass User Guide 1913 Type the number of hours or minutes a key will be in effect in the Lifetime field.If you

Strany 127 - Firebox Vclass User Guide 107

192 Vcontroller 4.011 When you are finished, click Done.Follow these steps to define an AH transform:1 Select the checkbox marked AH. Click New to ope

Strany 128 - 1 Launch a Web browser

Defining a VPN Security PolicyFirebox Vclass User Guide 193Defining a manual key Follow these steps to define a manual key:1 Select Automatic (IKE) fr

Strany 129 - Managing accounts

194 Vcontroller 4.010 Click to select the AH checkbox.11 Type a unique number between 256 and 65535 in the Local SPI (Security Parameter Index) field.

Strany 130 - 110 Vcontroller 4.0

Using Tunnel SwitchingFirebox Vclass User Guide 195A more efficient way to manage a complex corporate VPN with numbers of sites and remote users is to

Strany 131 - Account Access Conflicts

196 Vcontroller 4.0To make such a hub-and-spoke topology effective and efficient, Firebox Vclass security appliances provide tunnel switching capabili

Strany 132 - Resolving login conflicts

Using Tunnel SwitchingFirebox Vclass User Guide 197Enabling tunnel switchingBefore you set up individual VPN policies for site-to-site tunnel switchin

Strany 133 - About Security Policies

198 Vcontroller 4.0VclassUserGuide.book Page 198 Friday, January 3, 2003 10:09 AM

Strany 134 - Security policy components

Firebox Vclass User Guide 199CHAPTER 10 Creating a Remote User VPN PolicyWith easy access to the Internet from home offices or on the road, employees

Strany 135 - Types of policies

2 Vcontroller 4.0WatchGuard Firebox Vclass ComponentsAll Firebox Vclass models are fully IPSec-compliant, with built-in core software and management t

Strany 136 - 116 Vcontroller 4.0

200 Vcontroller 4.0• Remote users can be associated with different user groups through which network administrators can establish group-wide parameter

Strany 137 - Using Policy Manager

Configuring Remote UsersFirebox Vclass User Guide 201• To complete the VPN policy, you’ll need to create the specific IKE policy that will be used by

Strany 138 - 118 Vcontroller 4.0

202 Vcontroller 4.0To configure remote users, first define a user group profile:1 From the main Vcontroller page, click Remote Users.The RAS Configura

Strany 139 - Firebox Vclass User Guide 119

Configuring Remote UsersFirebox Vclass User Guide 203NoneRemote users belonging to this group will not be assigned an internal IP address when a conne

Strany 140 - 120 Vcontroller 4.0

204 Vcontroller 4.014 To flush any active connections that may be affected by the changes, click the appropriate checkbox and then click Commit.To con

Strany 141 - Using Policy Checker

Configuring Remote UsersFirebox Vclass User Guide 2054 Type the User Name in the appropriate field.User names are case-sensitive and must consist of 1

Strany 142 - 122 Vcontroller 4.0

206 Vcontroller 4.011 To flush any active connections that may be affected by the changes, click the appropriate checkbox and then click Commit.12 To

Strany 143 - Firebox Vclass User Guide 123

Configuring Remote UsersFirebox Vclass User Guide 207 NOTEDepending on how the RADIUS servers area is configured, you might encounter a situation whe

Strany 144 - Default policies

208 Vcontroller 4.0Reactivating an expired userAfter a remote user account has expired, you can reactivate it by resetting the account expiration.1 Cl

Strany 145 - Defining a Security Policy

Defining a IKE and Security Policies for Remote UsersFirebox Vclass User Guide 209unavailable–temporarily or permanently. In this situation, you shoul

Strany 146 - Defining an address group

Minimum Requirements for the WatchGuard VcontrollerFirebox Vclass User Guide 3 NOTEFor the most current information on Vclass hardware and operating

Strany 147 - Firebox Vclass User Guide 127

210 Vcontroller 4.0•The Destination will be only those network resources accessible by remote access users.•The Services will be limited to those that

Strany 148 - Defining a service

Monitoring Remote User ActivityFirebox Vclass User Guide 211Controlling a remote user’s access privilegesIn addition to authenticating remote users, F

Strany 149 - 3 Click New

212 Vcontroller 4.0You can also get a basic summary of a particular user’s recent connection history (not the current one) by opening the RAS Configur

Strany 150 - 130 Vcontroller 4.0

Monitoring Remote User ActivityFirebox Vclass User Guide 213• You can click Active Users to monitor currently active users. The System Information dia

Strany 151 - Using Tenants

214 Vcontroller 4.0VclassUserGuide.book Page 214 Friday, January 3, 2003 10:09 AM

Strany 152 - About VLANs and tenants

Firebox Vclass User Guide 215CHAPTER 11 Monitoring the Firebox VclassFor detailed status reports of the Firebox Vclass appliance you can use the Real-

Strany 153 - Firebox Vclass User Guide 133

216 Vcontroller 4.0From the main Vcontroller page, click Monitor.The Real-time Monitor window appears.The following categories of system activity can

Strany 154 - Defining tenants

Using the Real-Time MonitorFirebox Vclass User Guide 217InterfaceInterface probes observe and report on the activities of selected interfaces. For exa

Strany 155 - Firebox Vclass User Guide 135

218 Vcontroller 4.0monitor a specific policy, you may need to click Add to create an new probe.3 When the probe has been edited, you can test it. Clic

Strany 156 - Using the Firewall Options

Using the Real-Time MonitorFirebox Vclass User Guide 2193 Click Start Monitoring.After a brief pause, which reflects the Interval times previously sel

Strany 157 - Firebox Vclass User Guide 137

4 Vcontroller 4.0Processor speed500 MHz or fasterMemory64 MB minimum (128 MB is recommended)Input deviceCD-ROM or DVDHard disk space10 MB minimumNetwo

Strany 158 - Defining a QoS action

220 Vcontroller 4.0To conserve system resources, you can temporarily disable any probes until the next time you want to monitor that particular system

Strany 159 - Activating TOS marking

A Catalog of Real-time Monitor Probe CountersFirebox Vclass User Guide 221Interface 1(Public)Recv.(Packets)Number of packets received from Interface 1

Strany 160 - About NAT

222 Vcontroller 4.0Interface 2(DMZ)Recv.(Bytes)Number of bytes received from Interface 2 (bytes)Interface 2(DMZ)Sent(Bytes)Number of bytes sent from I

Strany 161 - Static NAT

A Catalog of Real-time Monitor Probe CountersFirebox Vclass User Guide 223Traffic Log Size (KB) Traffic log file size in KbytesAlarm Log Size (KB) Ala

Strany 162 - About Load Balancing

224 Vcontroller 4.0Interface 1(Public)Stream Req./secRate of incoming stream requests from Interface 1Interface 0(Private)Stream Req./secRate of incom

Strany 163 - Defining a NAT Action

A Catalog of Real-time Monitor Probe CountersFirebox Vclass User Guide 225Total IPSECTraffic (bytes)IPSEC traffic in bytesTotal IPSEC Packets IPSEC pa

Strany 164 - 144 Vcontroller 4.0

226 Vcontroller 4.0 Aggregate counters for all VPN end-point pairs IPSec counters per VPN end-point pair Counter Name Description of Counter’s Functi

Strany 165 - 1 Click New

A Catalog of Real-time Monitor Probe CountersFirebox Vclass User Guide 227Policy counters for all policiesOutbound Pkts/sec Traffic rate through outbo

Strany 166 - Using Policy Schedules

228 Vcontroller 4.0Policy counters per policyPackets Disc. at Interface 2(DMZ)(%)Percentage of packets discarded at Interface 2Packets Disc. by IPSEC

Strany 167 - Defining a Schedule

A Catalog of Real-time Monitor Probe CountersFirebox Vclass User Guide 229Decryption Error Rate (%) Decryption error rate of a policyAuthentication Er

Strany 168 - 148 Vcontroller 4.0

WatchGuard Firebox Vclass Appliance OptionsFirebox Vclass User Guide 5• Adding new functionality through optional products• Increasing the capacity of

Strany 169 - Using the Advanced Settings

230 Vcontroller 4.0VclassUserGuide.book Page 230 Friday, January 3, 2003 10:09 AM

Strany 170 - 3 Click the Log tab

Firebox Vclass User Guide 231CHAPTER 12 Using Alarm ManagerThe Vcontroller Alarm Manager allows you to define alarms that can alert the appropriate pa

Strany 171 - The traffic log setting

232 Vcontroller 4.02 Click the Alarm Definitions tab to view the current list of alarm definitions.This tab lists pre-defined default alarms along wit

Strany 172 - 152 Vcontroller 4.0

Alarm DefinitionsFirebox Vclass User Guide 2334 Type a name for the alarm in the appropriate field.5 Click the Severity slider and move it to the poin

Strany 173 - Security Policy Examples

234 Vcontroller 4.02 Select the appropriate option from the Probe Category drop list: System, Policy, or VPN End-point Pairs.The display changes depen

Strany 174 - 154 Vcontroller 4.0

Alarm DefinitionsFirebox Vclass User Guide 2355 Delete the text in the <threshold> field and type a number value for this counter. This value ca

Strany 175 - Firebox Vclass User Guide 155

236 Vcontroller 4.03 Click Add. The Select Condition dialog box appears.1 Click the text field where <counter> appears. This field acts as a but

Strany 176 - 156 Vcontroller 4.0

Alarm DefinitionsFirebox Vclass User Guide 2375 Delete the text in the <threshold> field, type the value (either a whole number or a percentage)

Strany 177 - Firebox Vclass User Guide 157

238 Vcontroller 4.010 To activate email notification, enable the Email Notification response option. Type the email address in the appropriate field.

Strany 178 - 158 Vcontroller 4.0

Responding to an Alarm NotificationFirebox Vclass User Guide 239To enable or disable an alarm:1 Open the Alarm Manager window. Click the Alarm Definit

Strany 179 - Firebox Vclass User Guide 159

6 Vcontroller 4.0About This GuideThe purpose of this guide is to help users of the WatchGuard Firebox Vclass appliance set up and configure a basic ne

Strany 180 - 160 Vcontroller 4.0

240 Vcontroller 4.0To view outstanding alarms:1 From the Vcontroller main page, click the animated alarm bell or click the Alarm button.The Alarm Mana

Strany 181 - Firebox Vclass User Guide 161

Responding to an Alarm NotificationFirebox Vclass User Guide 2413 Review the information displayed. This includes important information such as time,

Strany 182 - 162 Vcontroller 4.0

242 Vcontroller 4.0VclassUserGuide.book Page 242 Friday, January 3, 2003 10:09 AM

Strany 183 - Firebox Vclass User Guide 163

Firebox Vclass User Guide 243CHAPTER 13 Using Log ManagerThe Vcontroller can log an extensive array of system activities and save all logs into text f

Strany 184 - VLAN Policy Examples

244 Vcontroller 4.0Phase One SA and Phase Two SA logsRecords the creation and expiration histories for each phase of security associations pertaining

Strany 185 - Firebox Vclass User Guide 165

Viewing the LogsFirebox Vclass User Guide 2452 Click each tab to review the entries for that category.3 If the log has more than 500 entries, as noted

Strany 186 - 166 Vcontroller 4.0

246 Vcontroller 4.0 - Move the slider to the desired number and then click outside of the pop-up to close it.Filtering a current logWhen viewing a log

Strany 187 - Firebox Vclass User Guide 167

Log SettingsFirebox Vclass User Guide 247Log SettingsYou can use four separate log files to monitor and record almost any level of Firebox Vclass syst

Strany 188 - QoS Policy Examples

248 Vcontroller 4.04 To change the amount of information recorded in the Event log, click the Event Log Level options slider and move it to the loggin

Strany 189 - Static NAT Policy Examples

Log SettingsFirebox Vclass User Guide 2494 Select the Facility and Priority from the drop lists for each log category. To use the default settings, cl

Strany 190 - 170 Vcontroller 4.0

Firebox Vclass User Guide 7CHAPTER 2 Service and SupportNo Internet security solution is complete without systematic updates and security intelligence

Strany 191 - Firebox Vclass User Guide 171

250 Vcontroller 4.0Log ArchivingWhen your log files are sufficiently full, or if your organizational archiving policy dictates, you can archive your l

Strany 192 - 172 Vcontroller 4.0

Log ArchivingFirebox Vclass User Guide 2514 Click Archive Now to archive a file to the default directory location: C:\WatchGuard\Log\ or click Browse

Strany 193 - Firebox Vclass User Guide 173

252 Vcontroller 4.0VclassUserGuide.book Page 252 Friday, January 3, 2003 10:09 AM

Strany 194 - Web-load

Firebox Vclass User Guide 253CHAPTER 14 System InformationThe System Information dialog box provides accurate and up-to-date information on your syste

Strany 195 - Firebox Vclass User Guide 175

254 Vcontroller 4.0This tab allows you to access some general information, such as the model number, current system software version, serial number, c

Strany 196 - 176 Vcontroller 4.0

VPN Tunnel InformationFirebox Vclass User Guide 255By PoliciesDisplays a list of all policies you have created and the number of VPN tunnels establish

Strany 197 - Networks (VPN)

256 Vcontroller 4.0• Click Delete Tunnels to remove all established tunnels associated with this IPSec peer or policy and force the creation of new tu

Strany 198 - About VPN Policies

Traffic InformationFirebox Vclass User Guide 257The following information is displayed on the Traffic tab:Total PacketsTotal number of packets process

Strany 199 - Firebox Vclass User Guide 179

258 Vcontroller 4.0• When you are finished, click Close.Route InformationTo view the routing table information, follow these steps:1 Click the Routes

Strany 200 - Defining an IKE Policy

RAS User InformationFirebox Vclass User Guide 2592 Click Disconnect to break the selected user connection, including any established tunnels. If an in

Strany 201 - Firebox Vclass User Guide 181

8 Vcontroller 4.0Threat alerts and expert adviceAfter a new threat is identified, you’ll receive a LiveSecurity broadcast via an email message from ou

Strany 202 - 182 Vcontroller 4.0

260 Vcontroller 4.0The User Information and Statistics areas provide extensive information about this user and the current connection. The Tunnel List

Strany 203 - Defining an IKE action

Interface 1 (Public) InformationFirebox Vclass User Guide 261 - Click Refresh to update the Current SAs list with the most recent information. When yo

Strany 204 - 184 Vcontroller 4.0

262 Vcontroller 4.0DHCP Server InformationIf you have configured the Firebox Vclass appliance to act as a DHCP server, you can use this tab to view th

Strany 205 - Firebox Vclass User Guide 185

Firebox Vclass User Guide 263CHAPTER 15 Backing Up and Restoring ConfigurationsThe WatchGuard Vcontroller offers an array of built-in archiving and da

Strany 206 - Defining an IPSec action

264 Vcontroller 4.0Create a Backup File1 From the main Vcontroller page, click Back Up/Restore.The Backup/Restore dialog box appears.2 Click the Backu

Strany 207 - Firebox Vclass User Guide 187

Restoring an Archived ConfigurationFirebox Vclass User Guide 2655 Browse to the directory, type a file name of your choosing in the appropriate field,

Strany 208 - 188 Vcontroller 4.0

266 Vcontroller 4.03 Select the appropriate backup file and then click Select.The backup file name appears in the File Name field.4 Click Restore Now.

Strany 209 - Firebox Vclass User Guide 189

Exporting and Importing Configuration FilesFirebox Vclass User Guide 2672 Read the displayed text. If you want to complete the process, click Restore

Strany 210 - 190 Vcontroller 4.0

268 Vcontroller 4.0To export an XML file containing the complete configuration settings and policies:1 Click Export.A Save dialog box appears.2 Open t

Strany 211 - Firebox Vclass User Guide 191

Exporting and Importing Configuration FilesFirebox Vclass User Guide 269Importing a configuration file using Appliance DiscoveryInstead of the usual c

Strany 212 - 192 Vcontroller 4.0

LiveSecurity® BroadcastsFirebox Vclass User Guide 9Threat ResponseAfter a newly discovered threat is identified, the Rapid Response Team transmits an

Strany 213 - Firebox Vclass User Guide 193

270 Vcontroller 4.08 When the Devices Found dialog box reappears, click Cancel to close it.9 You can now use the Login dialog box to log in to this ap

Strany 214 - Using Tunnel Switching

Exporting and Importing Configuration FilesFirebox Vclass User Guide 271<password>rsgnJUYuNVmbw</password><description></descript

Strany 215 - Firebox Vclass User Guide 195

272 Vcontroller 4.0Encryption algorithmDES Authentication algorithmMD5 Lifetime8 hours VclassUserGuide.book Page 272 Friday, January 3, 2003 10:09

Strany 216 - 196 Vcontroller 4.0

Firebox Vclass User Guide 273CHAPTER 16 Using the Diagnostics/CLI FeatureThis chapter describes a variety of useful troubleshooting features that can

Strany 217 - Enabling tunnel switching

274 Vcontroller 4.02 Click the Connectivity tab.3 Type the IP address or DNS host name in the appropriate field.4 Click Ping.The Ping History table di

Strany 218 - 198 Vcontroller 4.0

Using the Support FeaturesFirebox Vclass User Guide 2755 If this test has verified that the device is responding to Ping packets from the Firebox Vcla

Strany 219 - Creating a Remote User VPN

276 Vcontroller 4.03 Click Configuration.The Debugging Support dialog box appears.4 Under the direction of technical support, move the sliders to the

Strany 220 - Requirements

Using the Support FeaturesFirebox Vclass User Guide 2777 Browse to the proper directory and then click Save.A confirmation dialog box appears.8 Click

Strany 221 - Configuring Remote Users

278 Vcontroller 4.03 Click Save Policy.The Select the file dialog box appears.4 Browse to the proper directory and click Select.A confirmation dialog

Strany 222 - 202 Vcontroller 4.0

Executing a CLI ScriptFirebox Vclass User Guide 2792 Click the CLI tab.3 Click Open.The Open dialog box appears.4 Browse to the proper directory and s

Strany 223 - Firebox Vclass User Guide 203

Firebox Vclass User Guide iiiThis product includes cryptographic software written by Eric Young ([email protected]). This product includes software w

Strany 224 - 204 Vcontroller 4.0

10 Vcontroller 4.0To activate the LiveSecurity Service through the Web:1 Be sure that you have the Firebox Vclass serial number handy. You will need t

Strany 225 - Firebox Vclass User Guide 205

280 Vcontroller 4.06 Click OK.The appliance reboots.Saving Diagnostic InformationSaving diagnostic information is helpful in troubleshooting possible

Strany 226 - 206 Vcontroller 4.0

Saving Diagnostic InformationFirebox Vclass User Guide 2814 Browse to the proper directory and select the appropriate file.5 Click Select.A confirmati

Strany 227 - Firebox Vclass User Guide 207

282 Vcontroller 4.0VclassUserGuide.book Page 282 Friday, January 3, 2003 10:09 AM

Strany 228 - Removing the backup server

Firebox Vclass User Guide 283CHAPTER 17 Setting Up a High Availability SystemIn a WatchGuard High Availability (HA) system, two Firebox Vclass applian

Strany 229 - 4 Click Apply

284 Vcontroller 4.0provides a seamless transition if one of the boxes fails and the other must take over. System configuration, policies and firewall,

Strany 230 - 210 Vcontroller 4.0

Connecting the AppliancesFirebox Vclass User Guide 285Connecting the AppliancesTo set up a high availability system, you must connect two Firebox Vcla

Strany 231 - Firebox Vclass User Guide 211

286 Vcontroller 4.03 Click the checkbox labeled Enable High Availability.4 Select the Active/Standby checkbox.The following HA options are displayed.V

Strany 232 - 212 Vcontroller 4.0

Configuring a Standby ApplianceFirebox Vclass User Guide 287These default HA settings include the following: - All of the appliance’s interfaces will

Strany 233 - Information” on page 258

288 Vcontroller 4.0 NOTEMake sure that the connection links both HA1 ports on the primary and secondary appliances, and that you are using a crossove

Strany 234 - 214 Vcontroller 4.0

Customizing HA System ParametersFirebox Vclass User Guide 289 NOTEThe first time you perform an HA Sync, the standby appliance must be in factory def

Strany 235 - Monitoring the Firebox Vclass

LiveSecurity® Self Help ToolsFirebox Vclass User Guide 1111 Click Continue. The Confirmation Web page appears. Importing LiveSecurity Feature KeyTo im

Strany 236 - 216 Vcontroller 4.0

290 Vcontroller 4.02 To activate monitoring through the HA ports, click to select the checkbox marked Enable HA on HA1 Port and/or Enable HA on HA2 Po

Strany 237 - Defining probes

Customizing HA System ParametersFirebox Vclass User Guide 291that uniquely identifies this system within the network context. (The number can range be

Strany 238 - Monitoring configured probes

292 Vcontroller 4.0Checking your HA System StatusThe HA monitor tells you which appliance you are logged into, whether it is Primary or Secondary, and

Strany 239 - 5 Click Close

Additional Preparation for FailoverFirebox Vclass User Guide 293Additional Preparation for FailoverMake sure, in anticipation of a failover, that you

Strany 240 - System Counters

294 Vcontroller 4.0VclassUserGuide.book Page 294 Friday, January 3, 2003 10:09 AM

Strany 241 - Firebox Vclass User Guide 221

Firebox Vclass User Guide 295IndexAaccess accounts. See accountsaccess privilegesadding110for remote users 211removing 110Account button 52Account Man

Strany 242 - 222 Vcontroller 4.0

296 Vcontroller 4.0configuration filesexporting, importing267importing using appliance discovery 269restoring 265context-sensitive help 13CPM-Vcontrol

Strany 243 - Firebox Vclass User Guide 223

Firebox Vclass User Guide 297Domain Name field 36dynamic NATdescribed142example firewall policy for 154dynamic NAT policiesuser-defined IP143dynamic r

Strany 244 - 224 Vcontroller 4.0

298 Vcontroller 4.0Active/Activedescribed283Active/Standbydescribed283prerequisites for 284additional preparation for failover 293checking system stat

Strany 245 - Firebox Vclass User Guide 225

Firebox Vclass User Guide 299logschanging number displayed245filtering entries 246types of 243viewing 244MManagement Stationdescribed18setting up 18ma

Strany 246 - 226 Vcontroller 4.0

12 Vcontroller 4.0Advanced FAQs (frequently asked questions) Detailed information about configuration options and interoperability.Known IssuesConfirm

Strany 247 - Firebox Vclass User Guide 227

300 Vcontroller 4.0examples of 168Quality-of-Service policies. See QoS policiesRRADIUS serverremoving appliance from backup208using for authentication

Strany 248 - Policy counters per policy

Firebox Vclass User Guide 301SNMP trap, setting alarm for 235, 237software requirements 2software upgrades, checking for 57Solaris, installing Vcontro

Strany 249 - Firebox Vclass User Guide 229

302 Vcontroller 4.0described 131, 132examples 164VPN Installation Services 15VPN policiesand IPSec actions179described 178encryption/authentication 17

Strany 250 - 230 Vcontroller 4.0

Product DocumentationFirebox Vclass User Guide 13WatchGuard engineers and Technical Support personnel. However, this forum should not be used for repo

Strany 251 - Using Alarm Manager

14 Vcontroller 4.0LiveSecurity® ProgramWatchGuard LiveSecurity Technical Support is included with every new Firebox Vclass. This support program is de

Strany 252 - 3 Click Add

Training and CertificationFirebox Vclass User Guide 15We target a one-hour maximum response time for all new incoming cases. If a technician is not im

Strany 253 - Firebox Vclass User Guide 233

16 Vcontroller 4.0Using the Online HelpOnline help is available from almost all WatchGuard Vcontroller windows. Because the online help uses Web brows

Strany 254 - 234 Vcontroller 4.0

Firebox Vclass User Guide 17CHAPTER 3 Getting StartedThe Firebox Vclass appliance acts as a barrier between your networks and the public Internet, pro

Strany 255 - Two condition options appear

18 Vcontroller 4.0installation and configuration process on a new factory-default appliance. For more information, see “Importing a Profile into a New

Strany 256

Setting up the Management StationFirebox Vclass User Guide 19 NOTEReview the release notes included with this package for information about Windows-J

Strany 257 - Firebox Vclass User Guide 237

iv Vcontroller 4.0AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL RALF S. ENGELSCHALL OR HIS CONTRIBUTORS BE LIABLE FOR ANY DI

Strany 258 - Managing alarm definitions

20 Vcontroller 4.0To install the Vcontroller, follow these steps: 1 Insert the WatchGuard CD into the CD-ROM. (Under Solaris, the CD should automatica

Strany 259 - Firebox Vclass User Guide 239

Setting up the Management StationFirebox Vclass User Guide 21 NOTEBe sure to review the release notes that were included in this package for informat

Strany 260 - Alarms tab

22 Vcontroller 4.0 NOTESome versions of the JRE and JDK for Linux may display fonts incorrectly. In addition, you may encounter a “font not found” er

Strany 261 - Firebox Vclass User Guide 241

Using Appliance DiscoveryFirebox Vclass User Guide 23• The Power LED• The Ready LED • One of the Private, Public, and DMZ interface speed indicator li

Strany 262 - 242 Vcontroller 4.0

24 Vcontroller 4.03 Click Find to start the process.If the Management Station has more than one NIC, you must select the IP address of the appropriate

Strany 263 - Using Log Manager

Using Appliance DiscoveryFirebox Vclass User Guide 25 - Verify that the appliance has been properly connected to the network. - Verify that all cable

Strany 264 - Viewing the Logs

26 Vcontroller 4.0You set the IP address of the Interface 0 as described in the following section. This is the task you perform with a new appliance.

Strany 265 - Firebox Vclass User Guide 245

Running the Vcontroller Installation WizardFirebox Vclass User Guide 277 Click Yes to proceed.The Result window appears.8 Wait for the Result window t

Strany 266 - Filtering a current log

28 Vcontroller 4.0• A domain name for this appliance• Any basic network routing information (static and dynamic)• The IP addresses of all DNS servers

Strany 267 - Log Settings

Running the Vcontroller Installation WizardFirebox Vclass User Guide 296 Read the qualifications and instructions.Edit the General information1 Click

Strany 268 - 3 Click Detail

Firebox Vclass User Guide v of this license document, but changing it is not allowed. Preamble The licenses for most software are designed to take

Strany 269 - 5 Click Done

30 Vcontroller 4.02 In the System Name field, type either the assigned DNS name for the appliance or another arbitrary name.3 In the System Location f

Strany 270 - Log Archiving

Running the Vcontroller Installation WizardFirebox Vclass User Guide 31Configure the Interfaces1 Click Next.The Interface Information screen appears.V

Strany 271 - 5 Click OK

32 Vcontroller 4.02 Enter the IP address and network mask for interface 0 (Private) in the appropriate fields.3 If you want to enable the appliance as

Strany 272 - 252 Vcontroller 4.0

Running the Vcontroller Installation WizardFirebox Vclass User Guide 337 To configure Interface 1 (Public) for Static, DHCP, or PPPoE addressing, enab

Strany 273 - System Information

34 Vcontroller 4.0Configure Routing1 From the Interface Information window, click Next.The Routing screen appears. NOTEAll entries made to configure

Strany 274 - VPN Tunnel Information

Running the Vcontroller Installation WizardFirebox Vclass User Guide 353 Type the destination IP address, network mask, and gateway of the route in th

Strany 275 - Firebox Vclass User Guide 255

36 Vcontroller 4.0 NOTEAll entries made to configure DNS servers are optional for completing the Installation Wizard, and will differ based on your n

Strany 276 - Traffic Information

Running the Vcontroller Installation WizardFirebox Vclass User Guide 37Define a Default Firewall Policy1 When you have finished listing the DNS server

Strany 277 - Firebox Vclass User Guide 257

38 Vcontroller 4.0Allow ping to the deviceAllows ping traffic to the private interface of this appliance from other workstations within the network.Al

Strany 278 - RAS User Information

Running the Vcontroller Installation WizardFirebox Vclass User Guide 39Denial of service preventionsThese options safeguard your servers from Denial o

Strany 279 - Firebox Vclass User Guide 259

vi Vcontroller 4.0means either the Program or any derivative work under copyright law:that is to say, a work containing the Program or a portion of it

Strany 280 - 260 Vcontroller 4.0

40 Vcontroller 4.0Per Client QuotaRestricts the number of connection requests from a single client in one second. Enable this option, then type the th

Strany 281 - Firebox Vclass User Guide 261

Running the Vcontroller Installation WizardFirebox Vclass User Guide 411 Type a new password in the appropriate field.Passwords must be between 6 and

Strany 282 - DHCP Server Information

42 Vcontroller 4.04 Click Finish.5 If you changed the IP address for interface 0 (Private), a window appears, asking if you want to restart the Firebo

Strany 283

Deploying the Firebox Vclass into your NetworkFirebox Vclass User Guide 43Deploying the Firebox Vclass into your NetworkAfter the appliance has reboot

Strany 284 - Create a Backup File

44 Vcontroller 4.0• Turn on the power switch on the back of the appliance.When the appliance has fully powered up, the Ready LED blinks while the init

Strany 285 - 2 Click Browse

Firebox Vclass User Guide 45CHAPTER 4 Firebox Vclass BasicsThis chapter provides an overview of the Firebox Vclass hardware and the companion Vcontrol

Strany 286 - A Warning dialog box appears

46 Vcontroller 4.0are defined, you can set up one or more actions that the Firebox Vclass appliance should take with any qualifying data.Firebox Vclas

Strany 287 - Firebox Vclass User Guide 267

Where the Information is StoredFirebox Vclass User Guide 47Where the Information is StoredWhen you use the Vcontroller to connect to a Firebox Vclass

Strany 288 - An Open dialog box appears

48 Vcontroller 4.0If you have used the Vcontroller before to access a Firebox Vclass appliance, the Server IP/Name field displays the IP address or ho

Strany 289 - Firebox Vclass User Guide 269

The Vcontroller Main PageFirebox Vclass User Guide 49The Vcontroller Main PageThis section describe the buttons displayed in the Vcontroller.Activitie

Strany 290 - 270 Vcontroller 4.0

Firebox Vclass User Guide viiyour rights to work written entirely by you; rather, the intent is toexercise the right to control the distribution of de

Strany 291 - Firebox Vclass User Guide 271

50 Vcontroller 4.0view newly triggered alarms, diagnose alarm conditions, and clear resolved alarms. For more information, see “Using Alarm Manager” o

Strany 292 - 272 Vcontroller 4.0

The Vcontroller Main PageFirebox Vclass User Guide 51IKE PolicyClick this button to open another view of the Policy Manager window that lists the curr

Strany 293 - Using the Diagnostics/CLI

52 Vcontroller 4.0Install WizardClick this button to reopen the Installation Wizard, which you can use to reestablish the basic configuration for a Fi

Strany 294 - 4 Click Ping

The Vcontroller Main PageFirebox Vclass User Guide 53Page-top buttonsThe page-top title area includes the Log Out and Help buttons, as well as an alar

Strany 295 - Using the Support Features

54 Vcontroller 4.0This panel is automatically refreshed every sixty seconds; however, you can click the blue star button to refresh manually.Logging o

Strany 296 - 5 Click Apply

Shutting Down and RebootingFirebox Vclass User Guide 553 To save the changes, click Yes.An Information dialog box appears indicating that the save was

Strany 297 - 2 Click the Support tab

56 Vcontroller 4.0 NOTEDo not disconnect the power before 30 seconds have elapsed. Disconnecting the appliance too quickly can cause serious damage.3

Strany 298 - Executing a CLI Script

Upgrading and Downgrading the Software VersionFirebox Vclass User Guide 57• Click Reboot the system and then click Yes.A status dialog box appears and

Strany 299 - 3 Click Open

58 Vcontroller 4.04 Click Check our Web site to verify whether a more recent version of the Vcontroller software is available.Your web browser appears

Strany 300 - Saving Diagnostic Information

Upgrading and Downgrading the Software VersionFirebox Vclass User Guide 592 Read the instructions on the screen and then click Downgrade Now.A confirm

Strany 301 - 6 Click OK

viii Vcontroller 4.0Program), you indicate your acceptance of this License to do so, andall its terms and conditions for copying, distributing or modi

Strany 302 - 282 Vcontroller 4.0

60 Vcontroller 4.0Transferring from the Vcontroller to WatchGuard CPMIf you need to transfer the management of the Firebox Vclass from the Vcontroller

Strany 303 - Firebox Vclass User Guide 283

Firebox Vclass User Guide 61CHAPTER 5 System ConfigurationUse the System Configuration dialog box to enter or edit system settings. This dialog box, a

Strany 304 - 284 Vcontroller 4.0

62 Vcontroller 4.0Configure the following system settings:System NameType a name to represent this appliance.System LocationType the location of your

Strany 305 - Connecting the Appliances

Interface ConfigurationFirebox Vclass User Guide 63System TimeDisplays the current date and time. To change the date and time currently displayed, cli

Strany 306 - 286 Vcontroller 4.0

64 Vcontroller 4.0• Click the Interface tab.The Interface settings are displayed. In this example, the interfaces for the V60 and V80 models are shown

Strany 307 - Firebox Vclass User Guide 287

Interface ConfigurationFirebox Vclass User Guide 65Interface 3Interface 3 should be assigned to any DMZ network traffic. This interface is not availab

Strany 308 - 288 Vcontroller 4.0

66 Vcontroller 4.02 Type the IP address and network mask in the appropriate fields. The interface Hardware Address (MAC address) is displayed beneath

Strany 309 - 1 Click Advanced

Interface ConfigurationFirebox Vclass User Guide 679 Click OK to close the Edit Interface dialog box and return to the Interface tab.Configuring Inter

Strany 310 - 290 Vcontroller 4.0

68 Vcontroller 4.0DHCPType the host name or the IP address of your DHCP server in the Host ID field.This option is not available when using High Avail

Strany 311 - Firebox Vclass User Guide 291

Interface ConfigurationFirebox Vclass User Guide 69This option is not available when using High Availability.2 Type a MTU to determine the maximum siz

Strany 312 - Detailed system status

Firebox Vclass User Guide ixeither of that version or of any later version published by the FreeSoftware Foundation. If the Program does not specify

Strany 313 - Firebox Vclass User Guide 293

70 Vcontroller 4.02 Type the IP address and network mask in the appropriate fields.The interface Hardware Address (MAC address) is displayed beneath t

Strany 314 - 294 Vcontroller 4.0

Interface ConfigurationFirebox Vclass User Guide 71To edit High Availability settings, follow these steps:1 Select the interface entry and then double

Strany 315

72 Vcontroller 4.0 - Click Yes to proceed.The appliance immediately restarts in order to apply the new interface configurations. The System Configurat

Strany 316

Routing ConfigurationFirebox Vclass User Guide 732 To configure a static route, click Add.The Add Route dialog box appears.3 Type the destination, net

Strany 317

74 Vcontroller 4.04 To modify an existing route, select the entry and click Edit.The Edit Route dialog box appears5 Click OK.Configuring dynamic routi

Strany 318

DNS ConfigurationFirebox Vclass User Guide 75ApplyTo immediately commit the settings to the Firebox Vclass appliance.A Warning dialog box appears. - C

Strany 319

76 Vcontroller 4.02 Type the domain name of the Firebox Vclass appliance in the appropriate field.To add a DNS server, follow these steps:1 Click Inse

Strany 320

SNMP ConfigurationFirebox Vclass User Guide 773 Click Add.The DNS Server dialog box closes and the new server IP address appears in the DNS Server lis

Strany 321

78 Vcontroller 4.0To configure SNMP traps, follow these steps:1 Click the SNMP tab.The SNMP settings are displayed.2 Click Add.The SNMP Management Sta

Strany 322

Log ConfigurationFirebox Vclass User Guide 795 Type the password that will identify the appliance to the Management Station or stations in the Communi

Komentáře k této Příručce

Žádné komentáře