Table of ContentsPreviousNextIndexSearch Knowledge Base

Complete PDF manual


   Table of Contents

ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual

About This Manual

Conventions, Formats, and Scope

How to Use This Manual

How to Print this Manual

Revision History

Chapter 1 Introduction

Key Features

Dual WAN Ports for Increased Reliability or Outbound Load Balancing

Advanced VPN Support for Both IPsec and SSL

A Powerful, True Firewall with Content Filtering

Autosensing Ethernet Connections with Auto Uplink

Extensive Protocol Support

Easy Installation and Management

Maintenance and Support

Package Contents

Front Panel Features

Rear Panel Features

Default IP Address, Login Name, and Password Location

Qualified Web Browsers

Chapter 2 Connecting the FVS336G to the Internet

Understanding the Connection Steps

Logging into the VPN Firewall Router

Navigating the Menus

Configuring the Internet Connections

Automatically Detecting and Connecting

Manually Configuring the Internet Connection

Configuring the WAN Mode (Required for Dual WAN)

Network Address Translation

Classical Routing

Configuring Auto-Rollover Mode

Configuring Load Balancing

Protocol binding

Configuring Dynamic DNS (Optional)

Configuring the Advanced WAN Options (Optional)

Additional WAN Related Configuration

Chapter 3 LAN Configuration

Using the VPN Firewall as a DHCP server

Configuring the LAN Setup Options

Managing Groups and Hosts (LAN Groups)

Viewing the LAN Groups Database

Changing Group Names in the LAN Groups Database

Configuring DHCP Address Reservation

Configuring Multi Home LAN IP Addresses

Configuring Static Routes

Configuring Static Routes

Configuring Routing Information Protocol (RIP)

Chapter 4 Firewall Protection and Content Filtering

About Firewall Protection and Content Filtering

Using Rules to Block or Allow Specific Kinds of Traffic

Services-Based Rules

Outbound Rules (Service Blocking)

Inbound Rules (Port Forwarding)

Order of Precedence for Rules

Setting the Default Outbound Policy

Creating a LAN WAN Outbound Services Rule

Creating a LAN WAN Inbound Services Rule

Modifying Rules

Attack Checks

Inbound Rules Examples

LAN WAN Inbound Rule: Hosting A Local Public Web Server

LAN WAN Inbound Rule: Allowing Videoconference from Restricted Addresses

LAN WAN Inbound Rule: Setting Up One-to-One NAT Mapping

LAN WAN Inbound Rule: Specifying an Exposed Host

Outbound Rules Example

LAN WAN Outbound Rule: Blocking Instant Messenger

Adding Customized Services

Modifying a Service

Setting Quality of Service (QoS) Priorities

Setting a Schedule to Block or Allow Specific Traffic

Setting Block Sites (Content Filtering)

Enabling Source MAC Filtering

Port Triggering

E-Mail Notifications of Event Logs and Alerts

Administrator Tips

Chapter 5 Virtual Private Networking Using IPsec

Considerations for Dual WAN Port Systems

Configuring an IPsec VPN Connection using the VPN Wizard

Creating a VPN Tunnel to a Gateway

Creating a VPN Tunnel Connection to a VPN Client

Managing VPN Tunnel Policies

About IKE

Managing IKE Policies

About the IKE Policy Table

VPN Policy

Managing VPN Policies

VPN Policy Table

VPN Tunnel Connection Status

Creating a VPN Client Connection: VPN Client to FVS336G

Configuring the FVS336G

Configuring the VPN Client

Testing the Connection

Manually Assigning IP Addresses to Remote Users (ModeConfig)

Mode Config Operation

Configuring the VPN Firewall

Configuring the ProSafe VPN Client for ModeConfig

Extended Authentication (XAUTH) Configuration

Configuring XAUTH for VPN Clients

User Database Configuration

RADIUS Client Configuration

Chapter 6 Virtual Private Networking Using SSL Connections

Understanding the Portal Options

Planning for SSL VPN

Creating the Portal Layout

Configuring Domains, Groups, and Users

Configuring Applications for Port Forwarding

Adding Servers

Adding A New Host Name

Configuring the SSL VPN Client

Configuring the Client IP Address Range

Adding Routes for VPN Tunnel Clients

Replacing and Deleting Client Routes

Using Network Resource Objects to Simplify Policies

Adding New Network Resources

Configuring User, Group, and Global Policies

Viewing Policies

Adding a Policy

Chapter 7 Managing Users, Authentication, and Certificates

Adding Authentication Domains, Groups, and Users

Creating a Domain

Creating a Group

Creating a New User Account

Setting User Login Policies

Managing Certificates

Viewing and Loading CA Certificates

Viewing Active Self Certificates

Obtaining a Self Certificate from a Certificate Authority

Managing your Certificate Revocation List (CRL)

Chapter 8 Router and Network Management

Performance Management

Bandwidth Capacity

Features That Reduce Traffic

Service Blocking

Services

Groups and Hosts

Schedule

Block Sites

Source MAC Filtering

Features That Increase Traffic

Port Forwarding

Port Triggering

VPN Tunnels

Using QoS to Shift the Traffic Mix

Tools for Traffic Management

Changing Passwords and Administrator Settings

Enabling Remote Management Access

Using an SNMP Manager

Settings Backup and Firmware Upgrade

Backup and Restore Settings

Router Upgrade

Configuring Date and Time Service

Chapter 9 Monitoring System Performance

Enabling the Traffic Meter

Activating Notification of Events and Alerts

Viewing Firewall Logs

Viewing Router Configuration and System Status

Monitoring the Status of WAN Ports

Monitoring Attached Devices

Reviewing the DHCP Log

Monitoring Active Users

Viewing Port Triggering Status

Monitoring VPN Tunnel Connection Status

Reviewing the VPN Logs

Chapter 10 Troubleshooting

Basic Functions

Power LED Not On

LEDs Never Turn Off

LAN or WAN Port LEDs Not On

Troubleshooting the Web Configuration Interface

Troubleshooting the ISP Connection

Troubleshooting a TCP/IP Network Using a Ping Utility

Testing the LAN Path to Your VPN Firewall

Testing the Path from Your PC to a Remote Device

Restoring the Default Configuration and Password

Problems with Date and Time

Diagnostics Functions

Appendix A Default Settings and Technical Specifications

Appendix B Related Documents

Appendix C Network Planning for Dual WAN Ports

What You Will Need to Do Before You Begin

Cabling and Computer Hardware Requirements

Computer Network Configuration Requirements

Internet Configuration Requirements

Where Do I Get the Internet Configuration Parameters?

Internet Connection Information Form

Overview of the Planning Process

Inbound Traffic

Virtual Private Networks (VPNs)

The Roll-over Case for Firewalls With Dual WAN Ports

The Load Balancing Case for Firewalls With Dual WAN Ports

Inbound Traffic

Inbound Traffic to Single WAN Port (Reference Case)

Inbound Traffic to Dual WAN Port Systems

Inbound Traffic: Dual WAN Ports for Improved Reliability

Inbound Traffic: Dual WAN Ports for Load Balancing

Virtual Private Networks (VPNs)

VPN Road Warrior (Client-to-Gateway)

VPN Road Warrior: Single Gateway WAN Port (Reference Case)

VPN Road Warrior: Dual Gateway WAN Ports for Improved Reliability

VPN Road Warrior: Dual Gateway WAN Ports for Load Balancing

VPN Gateway-to-Gateway

VPN Gateway-to-Gateway: Single Gateway WAN Ports (Reference Case)

VPN Gateway-to-Gateway: Dual Gateway WAN Ports for Improved Reliability

VPN Gateway-to-Gateway: Dual Gateway WAN Ports for Load Balancing

VPN Telecommuter (Client-to-Gateway Through a NAT Router)

VPN Telecommuter: Single Gateway WAN Port (Reference Case)

VPN Telecommuter: Dual Gateway WAN Ports for Improved Reliability

VPN Telecommuter: Dual Gateway WAN Ports for Load Balancing


NETGEAR, Inc.
http://www.netgear.com
Table of ContentsPreviousNextIndexSearch Knowledge Base