NETGEAR, Inc
Technical Support
Trademarks
Statement of Conditions
EU Regulatory Compliance Statement
Bestätigung des Herstellers/Importeurs
Certificate of the Manufacturer/Importer
Voluntary Control Council for Interference Vcci Statement
Additional Copyrights
MD5
Product and Publication Details
Model Number
V1.1, August
Contents
Chapter LAN Configuration
Chapter Virtual Private Networking
Chapter VPN Firewall and Network Management
Appendix C Related Documents Index
Xii Contents
About This Manual
Conventions, Formats and Scope
How to Print This Manual
Revision History
Part Number Version Date Description
Settings screen see Manually Configuring Your Internet
Xvi About This Manual
Key Features
Chapter Introduction
Powerful, True Firewall with Content Filtering
Advanced VPN Support for IPsec
Security Features
Autosensing Ethernet Connections with Auto Uplink
Easy Installation and Management
Extensive Protocol Support
Package Contents
VPN Firewall Front and Rear Panels
LED Descriptions
Object Activity Description One WAN Port Active
Default IP Address, Login Name, and Password
LAN IP Address User Name Password
Qualified Web Browsers
Connecting the VPN Firewall to the Internet
Understanding the Connection Steps
Logging into the VPN Firewall
Navigating the Menus
Configuring the Internet Connection to Your ISP
Internet connection methods
Connection Data Required Method
Manually Configuring Your Internet Connection
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring the WAN Mode
Network Address Translation
Classical Routing
Configuring Dynamic DNS
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring the Advanced Broadband Options
Additional WAN Related Configuration
Chapter LAN Configuration
Choosing the VPN Firewall Dhcp Options
Configuring the LAN Setup Options
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Managing Groups and Hosts LAN Groups
Creating the Network Database
Group and individual control over PCs
Viewing the Network Database
Adding Devices to the Network Database
Setting Up Dhcp Address Reservation
Changing Group Names in the LAN Groups Database
Configuring Multi Home LAN IP Addresses
Configuring and Enabling the DMZ Port
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring Static Routes
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Static Route Example
Configuring Routing Information Protocol RIP
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Firewall Protection and Content Filtering
About Firewall Protection and Content Filtering
Using Rules to Block or Allow Specific Kinds of Traffic
Services-Based Rules
Outbound Rules Service Blocking
Outbound Rules
Or Allow Specific Traffic on
Inbound Rules Port Forwarding
Profile
Inbound Rules
Block always
Inbound Rules
Viewing Rules and Order of Precedence for Rules
Configuring LAN WAN Rules
LAN WAN Outbound Services Rules
LAN WAN Inbound Services Rules
Configuring DMZ WAN Rules
Configuring LAN DMZ Rules
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Inbound Rules Examples
LAN WAN Inbound Rule Hosting a Local Public Web Server
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
LAN WAN or DMZ WAN Inbound Rule Specifying an Exposed Host
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring Other Firewall Features
Outbound Rules Example
LAN WAN Outbound Rule Blocking Instant Messenger
Attack Checks
WAN Security Checks
LAN Security Checks
Setting Session Limits
Managing the Application Level Gateway for SIP Sessions
Creating Services, QoS Profiles, and Bandwidth Profiles
Adding Customized Services
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Specifying Quality of Service QoS Priorities
Modifying a Service
Creating Bandwidth Profiles
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Setting a Schedule to Block or Allow Specific Traffic
Blocking Internet Sites Content Filtering
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring Source MAC Filtering
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring IP/MAC Address Binding
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring Port Triggering
Outgoing Trigger Port Range fields
Incoming Response Port Range fields
Configuring UPnP Universal Plug and Play
Email Notifications of Event Logs and Alerts
Administrator Tips
Using the VPN Wizard for Client and Gateway Configurations
Chapter Virtual Private Networking
Creating Gateway to Gateway VPN Tunnels with the Wizard
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Use the VPN Wizard Configure the Gateway for a Client Tunnel
Creating a Client to Gateway VPN Tunnel
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Leave Virtual Adapter disabled
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Testing the Connections and Viewing Status Information
Netgear VPN Client Status and Log Information
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
System Tray Icon Status
VPN Firewall VPN Connection Status and Logs
Configuring IKE Policies
Managing VPN Policies
IKE Policies Screen
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Manually Adding or Editing an IKE Policy
Add IKE Policy Settings
Mode Config Record
Description or Subfield and Description
General
Local
Remote
IKE SA Parameters
Group 1 768 bit
Group 5 1536 bit
Information, see Configuring Radius Clients for Xauth
Configuring VPN Policies
VPN Policies Screen
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Manually Adding or Editing a VPN Policy
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Add VPN Policy Settings
Traffic Selection
Manual Policy Parameters
Auto Policy Parameters
Managing Certificates
Group 768 bit
Group 1536 bit
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Understanding the Certificates Screen
Viewing and Loading CA Certificates
Understanding and Viewing Active Self Certificates
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Obtaining a Self Certificate from a Certificate Authority
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Managing your Certificate Revocation List CRL
Configuring Extended Authentication Xauth
Configuring Xauth for VPN Clients
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring the User Database for Xauth
Configuring Radius Clients for Xauth
Enter the primary Radius Server IP Address
Assigning IP Addresses to Remote Users ModeConfig
Mode Config Operation
Configuring Mode Config Operation on the VPN Firewall
Configuring the Mode Config Screen
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring an IKE Policy for Mode Config Operation
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Configuring the ProSafe VPN Client for ModeConfig
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Enable Replay Detection should be checked
Configuring Keepalives and Dead Peer Detection
Configuring Keepalives
Testing the Mode Config Connection
Configuring Dead Peer Detection
Configuring NetBIOS Bridging with VPN
Click the Yes radio button to Enable Dead Peer Detection
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Performance Management
Bandwidth Capacity
VPN Firewall Features That Reduce Traffic
Service Blocking
Blocking Sites
VPN Firewall Features That Increase Traffic
Source MAC Filtering
Port Forwarding
Port Triggering
Using QoS to Shift the Traffic Mix
DMZ Port
VPN Tunnels
Changing Passwords and Settings
Tools for Traffic Management
Local Authentication Settings section of the screen
Adding External Users
Configuring an External Server for Authentication
Authentication Protocols
Authentication Description Protocol
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Enabling Remote Management Access
Check Allow Remote Management radio box
Using an Snmp Manager
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Managing the Configuration File
Backing Up Settings
Restoring Settings
Reverting to Factory Default Settings
Upgrading the Firmware
Configuring Date and Time Service
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Monitoring System Performance
Activating Notification of Events and Alerts
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Viewing the Logs
Enabling the Traffic Meter
Firewall Log Field Descriptions
Field Description
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Viewing the VPN Firewall Configuration and System Status
Router Status Fields
Monitoring VPN Firewall Statistics
Monitoring Broadband Port Status
Monitoring Attached Devices
Monitoring VPN Tunnel Connection Status
Known PCs and Devices options
Viewing the VPN Logs
IPsec Connection Status Fields
Viewing the Dhcp Log
Viewing Port Triggering Status
To view the most recent entries, click refresh
Port Triggering Status Data
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Chapter Troubleshooting
Basic Functions
Power LED Not On
LEDs Never Turn Off
LAN or Internet Port LEDs Not On
Troubleshooting the Web Configuration Interface
Troubleshooting the ISP Connection
Troubleshooting a TCP/IP Network Using a Ping Utility
Testing the LAN Path to Your VPN Firewall
Testing the Path from Your PC to a Remote Device
Ping -n 10 IP address
Restoring the Default Configuration and Password
Problems with Date and Time
Using the Diagnostics Utilities
Diagnostics
Through VPN tunnel
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Table A-1. VPN firewall Default Configuration Settings
Feature Default Behavior Router Login
Internet Connection
Local Network LAN
Table A-2. VPN firewall Technical Specifications
Feature Default Behavior Management
Power Adapter
Physical Specifications
Feature Specifications Environmental Specifications
Interface Specifications
Electromagnetic Emissions
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Why do I need Two-Factor Authentication?
What are the benefits of Two-Factor Authentication?
Netgear Two-Factor Authentication Solutions
What is Two-Factor Authentication
Figure B-1
Figure B-3
Appendix C Related Documents
Document Link
ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Index
Numerics
Index-2
Index-3
Index-4
Index-5
Index-6
Index-7
Index-8
Index-9
Index-10