WatchGuard Technologies SOHO manual VPN Management

Page 112

Troubleshooting

3Beneath the Protocol Settings fields, select either TCP Port,

UDP Port or Protocol from the drop list.

The Custom Service page refreshes.

4Define a name for the service in the appropriate field.

5Enter the protocol number to allow in the Protocol field.

6Click the Submit button.

7From the navigation bar on the left side, select Firewall =>

Incoming.

The Firewall Incoming Traffic page appears.

8Towards the bottom of the page, under the Custom Service header, locate the service you created and select Allow from the drop list.

9Under the header Service Host, enter the IP address of the computer to which this traffic will be allowed.

10Click the Submit button.

VPN Management

Before setting up a VPN, you must have the following:

Two properly configured and working SOHOs or one SOHO and one Firebox with the latest version of firmware. Each SOHO must have the VPN option enabled.

The static external IP address, the network address, and the subnet masks of both devices. (The base trusted IP address of each SOHO must be static and unique.)

The DNS and WINS server IP address, if used.

The shared key (passphrase) for the tunnel.

The same encryption method for each end of the tunnel (DES or 3DES).

112

Image 112
Contents WatchGuard Soho User Guide Page Using this guide Following conventions are used throughout this guideCertifications and Notices FCC CertificationCE Notice Industry CanadaTaiwanese Notice Vcci Notice Class a ITE Declaration of Conformity WatchGuard End-User License Agreement Page User Guide WatchGuard Limited Hardware Warranty User Guide Copyright and Patent Information Table of Contents Your Administrative Options Configuring Virtual Private Networking Page Introduction WelcomeRegistration and Identification Information How does a firewall work?How does a firewall work? How does information travel on the internet? IP AddressesProtocol Port numberHow does the Soho process this information? ServicesNetwork Address Translation NAT Default Factory Settings Soho Home Page-System StatusResetting a Soho to the Factory Defaults Firewall SettingsRebooting a WatchGuard Soho Base Model SohoRebooting a WatchGuard Soho Rebooting a WatchGuard Soho Pre-installation checklist Before you beginInstallation Process Determine your current TCP/IP settings Microsoft Windows NT orMicrosoft Windows 95 or 98 or ME MacintoshDisable your browser’s Http proxy Exit the TCP/IP configuration screenNetscape Netscape 6/6.1Internet Explorer 5.0/5.5 Physically connecting your SohoCabling the Soho for one to four devices Installation Process Cabling the Soho for more than four computers This creates a connection between the Soho and the modem Installation Process Configuring Your External Network Network addressingDouble-click the Network icon TCP/IP Properties dialog box appears Configuring the Soho External network for dynamic addressing Configuring the Soho External network for static addressing On your computerOn the Soho ExternalConfiguring the Soho external network for PPPoE From the Configuration Mode drop list, select PPPoE Client Click Automatically restore lost connections Release and renew the IP configuration Configure the Trusted network with static addresses Configuring Your Trusted NetworkRoutes Configure additional computers to the trusted network Configuring Static Routes View the Network Statistics Network Statistics View the Network Statistics Your Administrative Options System SecuritySetting a System Administrator Name and System Passphrase = System Security Setting up VPN Manager Access = VPN Manager AccessClick the Submit button Redeeming your Soho upgrade certificates Update Your Configuration from a Non- Windows Platform= Update = Upgrade Upgrade certificates Seat LicensesView the Configuration File = View Configuration FileView the Configuration File Firewall settings Configuring Incoming and Outgoing ServicesPre-configured Services Incoming or OutgoingCreating a Custom Service TCP and UDP Ports Custom ServiceIP Protocols Blocking External Sites Blocked Sites Firewall Options Firewall OptionsPing requests received on the External Network Denying FTP access to the Trusted Network interface Socks implementation for the SohoConfigure your Socks application Logging all allowed outbound traffic Disabling Socks on the SohoCreating a virtual DMZ DMZCreating a virtual DMZ Creating a virtual DMZ What is Logging? Viewing Soho log messagesSetting a WatchGuard Security Event Processor log host Wsep LoggingOur example Setting a Syslog Host Syslog LoggingSetting the System Time System TimeIf you have decided to use the WatchGuard Time Server Setting the System Time Setting the System Time WatchGuard Soho WebBlocker How WebBlocker worksWeb site not in WebBlocker database Web site in WebBlocker databaseWatchGuard WebBlocker database unavailable WebBlocker Users and GroupsPurchasing and enabling Soho WebBlocker Bypassing the Soho WebBlockerEnable WebBlocker Configuring the Soho WebBlockerSettings Enter the Inactivity Timeout in minutes Create WebBlocker Groups and Users GroupsTo the right of the Users field, click the New button Click the Submit button WebBlocker categories Alcohol/TobaccoDrug Culture Search Engines Searching for blocked sites Click Check if the URL is on the CyberNOT ListConfiguring Virtual Private Networking Why create a virtual private network?What you will need IP Address Table example Step-by-step instructions for configuring a Soho VPN tunnel Obtaining the VPN upgradeEnabling the VPN upgrade Special considerationsWhy do I need a static external address? Frequently asked questionsHow do I get a static external IP address? OK, why is ping not working? How do I obtain a VPN upgrade certificate?How do I connect three or four offices together? How do I troubleshoot the connection?Muvpn Clients How do I enable a VPN Tunnel?View the VPN Statistics View the VPN Statistics 104 How do I reboot my SOHO? TroubleshootingGeneral What do the on and Mode lights signify on the SOHO? How do I register my SOHO?Set a password on my unit, but I forgot it. Can you help? What is a Soho feature key?Cant get a certain Soho feature to work with a DSL modem How does the seat limitation on the Soho work?How do I install a Soho using a Macintosh? Configuration Where are the Soho settings stored? How can I see the MAC address of my SOHO? How do I change to a Dhcp trusted IP address?How do I set up and disable Webblocker? How do I change to a static trusted IP address?WebBlocker IncomingVPN Management How do I set up my Soho for VPN Manager Access? How do I set up VPN between two SOHOs?Contacting Technical support Online Documenting and In-Depth FAQsSpecial Notices Database WebBlocker Default gateway 98 DNS service 116 User Guide 117 Socks