Reference Manual for the ProSafe VPN Firewall FVS318v3
Statement of Conditions
Trademarks
EN 55 022 Declaration of Conformance
Certificate of the Manufacturer/Importer
Bestätigung des Herstellers/Importeurs
Voluntary Control Council for Interference Vcci Statement
Product and Publication Details
Contents
Chapter Firewall Protection Content Filtering
Chapter Advanced Virtual Private Networking
Chapter Advanced Configuration
Appendix C Virtual Private Networking
Appendix D Preparing Your Network
Glossary
Xii Contents
Typographical Conventions
Audience, Scope, Conventions, and Formats
Manual Scope
How to Use This Manual
Printing a Page in the Html View
How to Print this Manual
Printing a Chapter
Printing the Full Manual
Reference Manual for the ProSafe VPN Firewall FVS318v3
Chapter Introduction
Key Features of the VPN Firewall
Security
Powerful, True Firewall with Content Filtering
Extensive Protocol Support
Autosensing Ethernet Connections with Auto Uplink
Maintenance and Support
Easy Installation and Management
Package Contents
LED Descriptions
FVS318v3 Rear Panel
Netgear Product Registration, Support, and Documentation
NETGEAR-Related Products
NETGEAR-Related Products
Reference Manual for the ProSafe VPN Firewall FVS318v3
First, Connect the FVS318v3
Prepare to Install Your FVS318v3 ProSafe VPN Firewall
Modem
Disconnect the Ethernet cable from the computer
Restart Your Network in the Correct Sequence
Status lights
Now, Configure the FVS318v3 for Internet Access
Netgear Smart Wizard Configuration Assistant welcome screen
Be sure to restart your network in this sequence
Troubleshooting Tips
Make sure the Ethernet cables are securely plugged
Make sure the network settings of the computer are correct
Ways to access the firewall
Overview of How to Access the FVS318v3 VPN Firewall
Login URL
Login result FVS318v3 home
How to Bypass the Configuration Assistant
Using the Smart Setup Wizard
ISP Does Not Require Login
How to Manually Configure Your Internet Connection
Reference Manual for the ProSafe VPN Firewall FVS318v3
11 Basic Settings ISP list
Firewall Protection and Content Filtering Overview
Chapter Firewall Protection Content Filtering
Block Sites menu
Block Sites
Rules menu
Using Rules to Block or Allow Specific Kinds of Traffic
Reference Manual for the ProSafe VPN Firewall FVS318v3
Inbound Rule Example a Local Public Web Server
Inbound Rules Port Forwarding
Rule example a videoconference from restricted addresses
Considerations for Inbound Rules
Outbound Rule Example Blocking Instant Messenger
Outbound Rules Service Blocking
Order of Precedence for Rules
Default DMZ Server
Respond to Ping on Internet WAN Port
Click Default DMZ Server
Services menu
Services
Add Custom Service menu
Schedule
Using a Schedule to Block or Allow Specific Traffic
Time Zone
10 E-mail menu
Getting E-Mail Notifications of Event Logs and Alerts
Reference Manual for the ProSafe VPN Firewall FVS318v3
11 Logs menu
Viewing Logs of Web Access or Attempted Web Access
Log entry descriptions
Syslog
Log action buttons
Reference Manual for the ProSafe VPN Firewall FVS318v3
Chapter Basic Virtual Private Networking
VPN Tunnel
PCs
AES
Configuration
Configuring the Client-to-Gateway VPN Tunnel on the FVS318v3
Summary screen below displays
Vpnc Recommended Settings
Configuring the Netgear ProSafe VPN Client on the Remote PC
Security Policy Editor new connection
10 Security Policy Editor connection settings
11 Security Policy Editor Security Policy
12 Security Policy Editor My Identity
14 Security Policy Editor Authentication
15 Security Policy Editor Key Exchange
16 Running a Ping test to the LAN from the PC
18 Log Viewer screen
Exporting a Security Policy
Transferring a Security Policy to Another Client
Select Export Security Policy from the File pulldown
Scenario1
Importing a Security Policy
Basic
23 VPN Wizard start screen
Procedure to Configure a Gateway-to-Gateway VPN Tunnel
25 Remote IP
27 VPN Wizard Summary
28 VPN Recommended Settings
30 VPN Status/Log screen
Using the VPN Status Page to Activate a VPN Tunnel
Start Using a VPN Tunnel to Activate It
VPN Tunnel Control
Activating a VPN Tunnel
32 VPN Status/Log screen
Activate the VPN Tunnel by Pinging the Remote Endpoint
Type ping
Type ping -t 192.168.3.1 and then click OK
36 Pinging test results
Verifying the Status of a VPN Tunnel
38 Current VPN Tunnels SAs screen
Deactivating a VPN Tunnel
39 VPN Policies
Using the VPN Status Page to Deactivate a VPN Tunnel
41 Current VPN Tunnels SAs screen
Deleting a VPN Tunnel
FVS318v3 VPN Firewall
Using Automatic Key Management
Using Policies to Manage VPN Traffic
IKE Policy Configuration Menu
IKE Policies’ Automatic Key and Authentication Management
Field Description General
IKE Policy Configuration fields
Field Description Remote
VPN Policy Configuration for Auto Key Negotiation
VPN Auto Policy menu
VPN Auto Policy fields are defined in the following table
VPN Auto Policy Configuration Fields
Authenticating Header AH
Netbios Enable
VPN Policy Configuration for Manual Key Exchange
VPN Manual Policy menu
VPN Manual Policy fields are defined in the following table
VPN Manual Policy Configuration Fields
Value in its Authentication Algorithm Key Out field
Netbios Enable
Certificate Revocation List CRL
Walk-Through of Configuration Scenarios on the FVS318v3
VPN Consortium Scenario
Scenario 1 are Using IPv4
FVS318v3 Internet IP Address menu
WAN IP addresses
LAN IP Setup menu
Scenario 1 IKE Policy
Set up the IKE Policy illustrated below on the FVS318v3
10 Scenario 1 VPN Auto Policy
Set up the FVS318v3 VPN -Auto Policy illustrated below
Testing the Gateway a FVS318v3 LAN and the Gateway B LAN
How to Check VPN Connections
Obtain a root certificate
Install the trusted CA certificate for the Trusted Root CA
Create a certificate request for the FVS318v3
11 Generate Self Certificate Request menu
12 Self Certificate Request data
Highlight, copy and paste this data into a text file
13 Self Certificate Requests table
Click the Upload Certificate button
14 Self Certificates table
Set up Certificate Revocation List CRL checking
Reference Manual for the ProSafe VPN Firewall FVS318v3
Router Status screen
Viewing VPN Firewall Status Information
FVS318v3 Status fields
This screen shows the following parameters
Connection Status action buttons
Connection Status fields
Router Statistics fields
Router Statistics screen
Upgrading the Firewall Software
Viewing a List of Attached Devices
Router Upgrade menu
Backing Up the Configuration
Configuration File Management
Restoring the Configuration
Erasing the Configuration
Changing the Administrator Password
How to Configure Dynamic DNS
Chapter Advanced Configuration
Using the LAN IP Setup Options
Configuring LAN TCP/IP Setup Parameters
Using the Firewall as a Dhcp server
Using Address Reservation
Configuring Static Routes
Click Edit or Delete
Static Routes table
Static Route Example
Enabling Remote Management Access
Https//134.177.0.1238080
Reference Manual for the ProSafe VPN Firewall FVS318v3
Reference Manual for the ProSafe VPN Firewall FVS318v3
Basic Functioning
Power LED Not On
LAN or Internet Port LEDs Not On
LEDs Never Turn Off
Troubleshooting the Web Configuration Interface
Troubleshooting the ISP Connection
Testing the LAN Path to Your Firewall
Troubleshooting a TCP/IP Network Using a Ping Utility
Ping -n 10 IP address
Testing the Path from Your PC to a Remote Device
Problems with Date and Time
Restoring the Default Configuration and Password
Reference Manual for the ProSafe VPN Firewall FVS318v3
Physical Specifications
Power Adapter
Environmental Specifications
Network Protocol and Standards Compatibility
Electromagnetic Emissions
Interface Specifications
Related Publications Basic Router Concepts
Appendix B Network, Routing, and Firewall Basics
IP Addresses and the Internet
What is a Router?
Routing Information Protocol
Figure B-1 Three Main Address Classes
Equals
Netmask
Figure B-2 Example of Subnetting a Class B Address
Subnet Addressing
Table B-2. Netmask formats
Table B-1 Netmask notation translation table for one octet
Table B-2 Netmask formats
Private IP Addresses
Figure B-3 Single IP Address Operation Using NAT
Single IP Address Operation Using NAT
Related Documents
MAC Addresses and Address Resolution Protocol
Domain Name Server
Internet Security and Firewalls
IP Configuration by Dhcp
Denial of Service Attack
What is a Firewall?
Ethernet Cabling
Stateful Packet Inspection
Category 5 Cable Quality
Table B-3 UTP Ethernet cable wiring, straight-through
Figure B-4 Straight-through twisted-pair cable
Inside Twisted Pair Cables
Uplink Switches, Crossover Cables, and MDI/MDIX Switching
Reference Manual for the ProSafe VPN Firewall FVS318v3
Reference Manual for the ProSafe VPN Firewall FVS318v3
Appendix C Virtual Private Networking
What is a VPN?
IPSec Security Features
What Is IPSec and How Does It Work?
IPSec Components
Encapsulating Security Payload ESP
IKE Security Association
Authentication Header AH
Mode
Key Management
Understand the Process Before You Begin
Addresses
VPN Process Overview
Firewalls
VPN Tunnel Between Gateways
Table C-2 Subnet addressing
VPN Tunnel Negotiation Steps
IPSec Security Association IKE
Vpnc IKE Security Parameters
Vpnc IKE Phase I Parameters
Vpnc IKE Phase II Parameters
Testing and Troubleshooting
Additional Reading
Relevant RFCs listed numerically
Preparing Your Computers for TCP/IP Networking
Appendix D Preparing Your Network
Install or Verify Windows Networking Components
Configuring Windows 95, 98, and Me for TCP/IP Networking
Select Microsoft
Choose Settings, and then Control Panel
Enabling Dhcp to Automatically Configure TCP/IP Settings
Primary Network Logon is set to Windows logon
Verifying TCP/IP Properties
Selecting Windows’ Internet Access Method
Double-click the Network and Dialup Connections icon
Configuring Windows NT4, 2000 or XP for IP Networking
Locate your Network Neighborhood icon
Dhcp Configuration of TCP/IP in Windows XP
Reference Manual for the ProSafe VPN Firewall FVS318v3
Dhcp Configuration of TCP/IP in Windows
Reference Manual for the ProSafe VPN Firewall FVS318v3
Obtain an IP address automatically is selected
Dhcp Configuration of TCP/IP in Windows NT4
Reference Manual for the ProSafe VPN Firewall FVS318v3
TCP/IP Properties dialog box now displays
Verifying TCP/IP Properties for Windows XP, 2000, and NT4
MacOS 8.6 or
Configuring the Macintosh for TCP/IP Networking
MacOS
Verifying TCP/IP Properties for Macintosh Computers
What Is Your Configuration Information?
Are Login Protocols Used?
Verifying the Readiness of Your Internet Account
Select the IP Address tab
Reference Manual for the ProSafe VPN Firewall FVS318v3
Restarting the Network
Reference Manual for the ProSafe VPN Firewall FVS318v3
Gathering the Network Information
Case Study Overview
Configure Log in to Use the VPN Wizard to
To Figure E-3
Verify the information example screen Example screen
Activating the VPN Tunnel
Figure E-4 Testing Flowchart
Summary
FVS318v3-to-FVS318v3 Case
Use the VPN Wizard to configure the FVS318v3 at Gateway a
Continue as shown in Figure E-3
Gateway a VPN Parameter Entry
Gateway a VPN Policy Parameters
Viewing and Editing the VPN Parameters
Gateway a IKE Parameters
Initiating and Checking the VPN Connections
VPN Status at Gateway B FVS318v3
VPN Status at Gateway a FVS318v3
FVS318v3-to-FVS318v2 Case
Use the VPN Wizard to configure the FVS318v3 at Gateway a
Continue as shown in Figure E-3
Viewing and Editing the VPN Parameters
Reference Manual for the ProSafe VPN Firewall FVS318v3
Initiating and Checking the VPN Connections
Status of VPN tunnel to and from Gateway a
IPSec Connection Status at Gateway B FVS318v2
FVS318v3-to-FVL328 Case
Use the VPN Wizard to configure the FVS318v3 at Gateway a
Continue as shown in Figure E-3
Viewing and Editing the VPN Parameters
Gateway a IKE Parameters
Initiating and Checking the VPN Connections
IPSec Connection Status at Gateway B FVL328
Client-to-Gateway VPN Tunnel Overview
FVS318v3-to-VPN Client Case
Table E-4 Policy Summary
Table E-5 Differences between VPN tunnel types
Connection Type a Remote VPN Client
Configuring the VPN Tunnel
Figure E-20 VPN Wizard at Gateway a FVS318v3
Figure E-21 VPN parameters at Gateway a FVS318v3
Figure E-22 Adding and renaming a new connection
Figure E-23 Scenario1 connection screen parameters
Figure E-24 Scenario1 Security Policy screen parameters
Figure E-25 Scenario1 My Identity screen parameters
Reference Manual for the ProSafe VPN Firewall FVS318v3
Figure E-27 Scenario1 connection launch from VPN Client PC
Choose Scenario1
See Figure E-28for the resulting status screens
Select Connection Monitor
Connection Monitor at Gateway B remote VPN Client
Numeric
List of Glossary Terms
Packet sent to all devices on a network
Dhcp
See Internet Control Message Protocol
Ieee
Internet service provider
Megabits per second
Set of rules for communication between devices on a network
See Wide Area Network
Wins