Table of ContentsPreviousNextIndexSearch Knowledge Base

Complete PDF manual


   Table of Contents

ProSafe VPN Firewall 200 FVX538 Reference Manual

About This Manual

Conventions, Formats and Scope

How to Use This Manual

How to Print this Manual

Revision History

Chapter 1 Introduction

Key Features

Dual WAN Ports for Increased Reliability or Outbound Load Balancing

A Powerful, True Firewall with Content Filtering

Security Features

Autosensing Ethernet Connections with Auto Uplink

Extensive Protocol Support

Trend Micro Integration

Easy Installation and Management

Maintenance and Support

Package Contents

Router Front Panel

Router Rear Panel

Rack Mounting Hardware

The Router's IP Address, Login Name, and Password

Default Log In Settings

Chapter 2 Connecting the FVX538 to the Internet

Logging into the VPN Firewall

Configuring the Internet Connections to Your ISPs

Setting the Router's MAC Address

Manually Configuring Your Internet Connection

Programming the Traffic Meter (if Desired)

Configuring the WAN Mode (Required for Dual WAN)

Setting Up Auto-Rollover Mode

Setting Up Load Balancing

Configuring Dynamic DNS (If Needed)

Configuring the Advanced WAN Options (If Needed)

Chapter 3 LAN Configuration

Using the Firewall as a DHCP server

Configuring the LAN Setup Options

Configuring Multi Home LAN IPs

Managing Groups and Hosts (LAN Groups)

Creating the Network Database

Setting Up Address Reservation

Configuring and Enabling the DMZ Port

Static Routes

Configuring Static Routes

Routing Information Protocol (RIP)

Static Route Example

Enabling Trend Micro Antivirus Enforcement

Chapter 4 Firewall Protection and Content Filtering

Using Rules to Block or Allow Specific Kinds of Traffic

Services-Based Rules

Outbound Rules (Service Blocking)

Inbound Rules (Port Forwarding)

Order of Precedence for Rules

Setting LAN WAN Rules

LAN WAN Outbound Services Rules

LAN WAN Inbound Services Rules

Setting DMZ WAN Rules

Setting LAN DMZ Rules

LAN DMZ Outbound Services Rules

LAN DMZ Inbound Services Rules

Attack Checks

Inbound Rules Examples

LAN WAN Inbound Rule: Hosting A Local Public Web Server

LAN WAN Inbound Rule: Allowing Videoconference from Restricted Addresses

LAN WAN or DMZ WAN Inbound Rule: Setting Up One-to-One NAT Mapping

LAN WAN or DMZ WAN Inbound Rule: Specifying an Exposed Host

Outbound Rules Example

LAN WAN Outbound Rule: Blocking Instant Messenger

Adding Customized Services

Setting Quality of Service (QoS) Priorities

Setting a Schedule to Block or Allow Specific Traffic

Setting Block Sites (Content Filtering)

Enabling Source MAC Filtering

Port Triggering

E-Mail Notifications of Event Logs and Alerts

Administrator Tips

Chapter 5 Virtual Private Networking

Dual WAN Port Systems

Setting up a VPN Connection using the VPN Wizard

Creating a VPN Tunnel to a Gateway

Creating a VPN Tunnel Connection to a VPN Client

VPN Tunnel Policies

IKE Policy

Managing IKE Policies

IKE Policy Table

VPN Policy

Managing VPN Policies

VPN Policy Table

VPN Tunnel Connection Status

Creating a VPN Gateway Connection: Between FVX538 and FVS338

Configuring the FVX538

Configuring the FVS338

Testing the Connection

Creating a VPN Client Connection: VPN Client to FVX538

Configuring the FVX538

Configuring the VPN Client

Testing the Connection

Certificate Authorities

Generating a Self Certificate Request

Uploading a Trusted Certificate

Managing your Certificate Revocation List (CRL)

Extended Authentication (XAUTH) Configuration

Configuring XAUTH for VPN Clients

User Database Configuration

RADIUS Client Configuration

Manually Assigning IP Addresses to Remote Users (ModeConfig)

Mode Config Operation

Configuring the VPN Firewall

Configuring the ProSafe VPN Client for ModeConfig

Chapter 6 Router and Network Management

Performance Management

Bandwidth Capacity

VPN Firewall Features That Reduce Traffic

Service Blocking

Block Sites

Source MAC Filtering

VPN Firewall Features That Increase Traffic

Port Forwarding

Port Triggering

DMZ Port

VPN Tunnels

Using QoS to Shift the Traffic Mix

Tools for Traffic Management

Administration

Changing Passwords and Settings

Enabling Remote Management Access

Using a SNMP Manager

Settings Backup and Firmware Upgrade

Backup and Restore Settings

Router Upgrade

Setting the Time Zone

Monitoring the Router

Enabling the Traffic Meter

Setting Login Failures and Attacks Notification

Monitoring Attached Devices

Viewing Port Triggering Status

Viewing Router Configuration and System Status

Monitoring WAN Ports Status

Monitoring VPN Tunnel Connection Status

VPN Logs

DHCP Log

Performing Diagnostics

Chapter 7 Troubleshooting

Basic Functions

Power LED Not On

LEDs Never Turn Off

LAN or Internet Port LEDs Not On

Troubleshooting the Web Configuration Interface

Troubleshooting the ISP Connection

Troubleshooting a TCP/IP Network Using a Ping Utility

Testing the LAN Path to Your Firewall

Testing the Path from Your PC to a Remote Device

Restoring the Default Configuration and Password

Problems with Date and Time

Appendix A Default Settings and Technical Specifications

Appendix B Related Documents

Appendix C Network Planning for Dual WAN Ports

What You Will Need to Do Before You Begin

Cabling and Computer Hardware Requirements

Computer Network Configuration Requirements

Internet Configuration Requirements

Where Do I Get the Internet Configuration Parameters?

Internet Connection Information Form

Overview of the Planning Process

Inbound Traffic

Virtual Private Networks (VPNs)

The Roll-over Case for Firewalls With Dual WAN Ports

The Load Balancing Case for Firewalls With Dual WAN Ports

Inbound Traffic

Inbound Traffic to Single WAN Port (Reference Case)

Inbound Traffic to Dual WAN Port Systems

Inbound Traffic: Dual WAN Ports for Improved Reliability

Inbound Traffic: Dual WAN Ports for Load Balancing

Virtual Private Networks (VPNs)

VPN Road Warrior (Client-to-Gateway)

VPN Road Warrior: Single Gateway WAN Port (Reference Case)

VPN Road Warrior: Dual Gateway WAN Ports for Improved Reliability

VPN Road Warrior: Dual Gateway WAN Ports for Load Balancing

VPN Gateway-to-Gateway

VPN Gateway-to-Gateway: Single Gateway WAN Ports (Reference Case)

VPN Gateway-to-Gateway: Dual Gateway WAN Ports for Improved Reliability

VPN Gateway-to-Gateway: Dual Gateway WAN Ports for Load Balancing

VPN Telecommuter (Client-to-Gateway Through a NAT Router)

VPN Telecommuter: Single Gateway WAN Port (Reference Case)

VPN Telecommuter: Dual Gateway WAN Ports for Improved Reliability

VPN Telecommuter: Dual Gateway WAN Ports for Load Balancing


NETGEAR, Inc.
http://www.netgear.com
Table of ContentsPreviousNextIndexSearch Knowledge Base