WatchGuard Technologies SOHO manual IP Address Table example

Page 99

What you will need

IP Address Table (example):

Item

Description

Assigned By

 

 

 

 

 

 

External IP

The IP address that identifies the SOHO to the Internet.

ISP

 

Address

 

 

 

 

 

Site A:

207.168.55.2

 

 

 

Site B:

68.130.44.15

 

 

External

The overlay of bits that determines which part of the IP

ISP

 

Subnet Mask

address identifies your network. For example, a Class C

 

 

 

address licenses 256 addresses and has a netmask of

 

 

 

255.255.255.0.

 

 

 

Site A:

255.255.255.0

 

 

 

Site B: 255.255.255.0

 

 

Local Network

A private network address used by an organization’s local

You

 

Address

network for identifying itself within the network. A local

 

 

 

network address cannot be used as a external IP address.

 

 

 

WatchGuard recommends using an address from one of the

 

 

 

reserved ranges:

 

 

 

10.0.0.0 — 255.0.0.0

 

 

 

172.16.0.0 — 255.240.0.0

 

 

 

192.168.0.0/16 — 255.255.0.0

 

 

 

Site A:

255.255.255.0

 

 

 

Site B: 255.255.255.0

 

 

Shared Secret

A phrase stored at both ends of the tunnel to authenticate

You

 

 

the transmission as being from the claimed origin. The

 

 

 

secret can be any phrase, but mixing numerical, special,

 

 

 

alphabetical, and uppercase characters improves security.

 

 

 

For example, “Gu4c4mo!3” is better than “guacamole”

 

 

 

Site A:

OurLittleSecret

 

 

 

Site B: OurLittleSecret

 

 

Encryption

Encryption method determines the length in bits of the key

You

 

Method

used to encrypt and decrypt communication packets. DES is

 

 

 

a 56-bit encryption; 3DES is 168-bit, and therefore much

 

 

 

more secure. It is also slower. Either 3DES or DES may be

 

 

 

selected as long as both sides use the same method.

 

 

 

Site A:

3DES

 

 

 

Site B: 3DES

 

 

Authentication

Both sides must use the same method.

You

 

 

Site A:

MD5

 

 

 

Site B: MD5

 

 

User Guide 5.0

99

Image 99
Contents WatchGuard Soho User Guide Page Following conventions are used throughout this guide Using this guideIndustry Canada Certifications and NoticesFCC Certification CE NoticeTaiwanese Notice Vcci Notice Class a ITE Declaration of Conformity WatchGuard End-User License Agreement Page User Guide WatchGuard Limited Hardware Warranty User Guide Copyright and Patent Information Table of Contents Your Administrative Options Configuring Virtual Private Networking Page Welcome IntroductionHow does a firewall work? Registration and Identification InformationHow does a firewall work? Port number How does information travel on the internet?IP Addresses ProtocolServices How does the Soho process this information?Network Address Translation NAT Soho Home Page-System Status Default Factory SettingsFirewall Settings Resetting a Soho to the Factory DefaultsBase Model Soho Rebooting a WatchGuard SohoRebooting a WatchGuard Soho Rebooting a WatchGuard Soho Before you begin Pre-installation checklistInstallation Process Macintosh Determine your current TCP/IP settingsMicrosoft Windows NT or Microsoft Windows 95 or 98 or MEExit the TCP/IP configuration screen Disable your browser’s Http proxyNetscape 6/6.1 NetscapePhysically connecting your Soho Internet Explorer 5.0/5.5Cabling the Soho for one to four devices Installation Process Cabling the Soho for more than four computers This creates a connection between the Soho and the modem Installation Process Network addressing Configuring Your External NetworkDouble-click the Network icon TCP/IP Properties dialog box appears Configuring the Soho External network for dynamic addressing On your computer Configuring the Soho External network for static addressingExternal On the SohoConfiguring the Soho external network for PPPoE From the Configuration Mode drop list, select PPPoE Client Click Automatically restore lost connections Release and renew the IP configuration Configuring Your Trusted Network Configure the Trusted network with static addressesRoutes Configure additional computers to the trusted network Configuring Static Routes View the Network Statistics Network Statistics View the Network Statistics System Security Your Administrative OptionsSetting a System Administrator Name and System Passphrase = System Security = VPN Manager Access Setting up VPN Manager AccessClick the Submit button Update Your Configuration from a Non- Windows Platform Redeeming your Soho upgrade certificates= Update = Upgrade Seat Licenses Upgrade certificates= View Configuration File View the Configuration FileView the Configuration File Configuring Incoming and Outgoing Services Firewall settingsIncoming or Outgoing Pre-configured ServicesCreating a Custom Service Custom Service TCP and UDP PortsIP Protocols Blocking External Sites Blocked Sites Firewall Options Firewall OptionsPing requests received on the External Network Socks implementation for the Soho Denying FTP access to the Trusted Network interfaceConfigure your Socks application Disabling Socks on the Soho Logging all allowed outbound trafficDMZ Creating a virtual DMZCreating a virtual DMZ Creating a virtual DMZ Viewing Soho log messages What is Logging?Wsep Logging Setting a WatchGuard Security Event Processor log hostOur example Syslog Logging Setting a Syslog HostSystem Time Setting the System TimeIf you have decided to use the WatchGuard Time Server Setting the System Time Setting the System Time How WebBlocker works WatchGuard Soho WebBlockerWebBlocker Users and Groups Web site not in WebBlocker databaseWeb site in WebBlocker database WatchGuard WebBlocker database unavailableBypassing the Soho WebBlocker Purchasing and enabling Soho WebBlockerConfiguring the Soho WebBlocker Enable WebBlockerSettings Enter the Inactivity Timeout in minutes Groups Create WebBlocker Groups and UsersTo the right of the Users field, click the New button Click the Submit button Alcohol/Tobacco WebBlocker categoriesDrug Culture Search Engines Click Check if the URL is on the CyberNOT List Searching for blocked sitesWhy create a virtual private network? Configuring Virtual Private NetworkingWhat you will need IP Address Table example Special considerations Step-by-step instructions for configuring a Soho VPN tunnelObtaining the VPN upgrade Enabling the VPN upgradeFrequently asked questions Why do I need a static external address?How do I get a static external IP address? How do I troubleshoot the connection? OK, why is ping not working?How do I obtain a VPN upgrade certificate? How do I connect three or four offices together?How do I enable a VPN Tunnel? Muvpn ClientsView the VPN Statistics View the VPN Statistics 104 Troubleshooting How do I reboot my SOHO?General How do I register my SOHO? What do the on and Mode lights signify on the SOHO?How does the seat limitation on the Soho work? Set a password on my unit, but I forgot it. Can you help?What is a Soho feature key? Cant get a certain Soho feature to work with a DSL modemHow do I install a Soho using a Macintosh? How do I change to a Dhcp trusted IP address? ConfigurationWhere are the Soho settings stored? How can I see the MAC address of my SOHO?How do I change to a static trusted IP address? How do I set up and disable Webblocker?Incoming WebBlockerVPN Management How do I set up VPN between two SOHOs? How do I set up my Soho for VPN Manager Access?Online Documenting and In-Depth FAQs Contacting Technical supportSpecial Notices Database WebBlocker Default gateway 98 DNS service 116 User Guide 117 Socks