Reference Manual for the ProSafe VPN Firewall FVS318v3
 EN 55 022 Declaration of Conformance
Trademarks
Statement of Conditions
 Voluntary Control Council for Interference Vcci Statement
Bestätigung des Herstellers/Importeurs
Certificate of the Manufacturer/Importer
 Product and Publication Details
 Contents
 Chapter Firewall Protection Content Filtering
 Chapter Advanced Virtual Private Networking
 Chapter Advanced Configuration
 Appendix C Virtual Private Networking
 Appendix D Preparing Your Network
 Glossary
 Xii Contents
 Manual Scope
Audience, Scope, Conventions, and Formats
Typographical Conventions
 How to Use This Manual
 Printing a Chapter
How to Print this Manual
Printing a Page in the Html View
Printing the Full Manual
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Key Features of the VPN Firewall
Chapter Introduction
 Powerful, True Firewall with Content Filtering
Security
 Autosensing Ethernet Connections with Auto Uplink
Extensive Protocol Support
 Easy Installation and Management
Maintenance and Support
 Package Contents
 FVS318v3 Rear Panel
LED Descriptions
 NETGEAR-Related Products
NETGEAR-Related Products
Netgear Product Registration, Support, and Documentation
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Prepare to Install Your FVS318v3 ProSafe VPN Firewall
First, Connect the FVS318v3
 Disconnect the Ethernet cable from the computer
Modem
 Restart Your Network in the Correct Sequence
 Now, Configure the FVS318v3 for Internet Access
Status lights
 Netgear Smart Wizard Configuration Assistant welcome screen
 Troubleshooting Tips
Be sure to restart your network in this sequence
 Make sure the network settings of the computer are correct
Make sure the Ethernet cables are securely plugged
 Overview of How to Access the FVS318v3 VPN Firewall
Ways to access the firewall
 Login URL
 How to Bypass the Configuration Assistant
Login result FVS318v3 home
 Using the Smart Setup Wizard
 How to Manually Configure Your Internet Connection
ISP Does Not Require Login
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 11 Basic Settings ISP list
 Chapter Firewall Protection Content Filtering
Firewall Protection and Content Filtering Overview
 Block Sites
Block Sites menu
 Using Rules to Block or Allow Specific Kinds of Traffic
Rules menu
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Inbound Rules Port Forwarding
Inbound Rule Example a Local Public Web Server
 Considerations for Inbound Rules
Rule example a videoconference from restricted addresses
 Outbound Rules Service Blocking
Outbound Rule Example Blocking Instant Messenger
 Default DMZ Server
Order of Precedence for Rules
 Click Default DMZ Server
Respond to Ping on Internet WAN Port
 Services
Services menu
 Add Custom Service menu
 Using a Schedule to Block or Allow Specific Traffic
Schedule
 Time Zone
 Getting E-Mail Notifications of Event Logs and Alerts
10 E-mail menu
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Viewing Logs of Web Access or Attempted Web Access
11 Logs menu
 Log action buttons
Syslog
Log entry descriptions
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Chapter Basic Virtual Private Networking
 VPN Tunnel
 PCs
 AES
 Configuration
 Configuring the Client-to-Gateway VPN Tunnel on the FVS318v3
 Summary screen below displays
 Vpnc Recommended Settings
 Configuring the Netgear ProSafe VPN Client on the Remote PC
 Security Policy Editor new connection
 10 Security Policy Editor connection settings
 11 Security Policy Editor Security Policy
 12 Security Policy Editor My Identity
 14 Security Policy Editor Authentication
 15 Security Policy Editor Key Exchange
 16 Running a Ping test to the LAN from the PC
 18 Log Viewer screen
 Select Export Security Policy from the File pulldown
Transferring a Security Policy to Another Client
Exporting a Security Policy
 Importing a Security Policy
Scenario1
 Basic
 Procedure to Configure a Gateway-to-Gateway VPN Tunnel
23 VPN Wizard start screen
 25 Remote IP
 27 VPN Wizard Summary
 28 VPN Recommended Settings
 30 VPN Status/Log screen
 VPN Tunnel Control
Start Using a VPN Tunnel to Activate It
Using the VPN Status Page to Activate a VPN Tunnel
Activating a VPN Tunnel
 Activate the VPN Tunnel by Pinging the Remote Endpoint
32 VPN Status/Log screen
 Type ping -t 192.168.3.1 and then click OK
Type ping
 Verifying the Status of a VPN Tunnel
36 Pinging test results
 Deactivating a VPN Tunnel
38 Current VPN Tunnels SAs screen
 Using the VPN Status Page to Deactivate a VPN Tunnel
39 VPN Policies
 Deleting a VPN Tunnel
41 Current VPN Tunnels SAs screen
 FVS318v3 VPN Firewall
 Using Policies to Manage VPN Traffic
Using Automatic Key Management
 IKE Policies’ Automatic Key and Authentication Management
IKE Policy Configuration Menu
 IKE Policy Configuration fields
Field Description General
 VPN Policy Configuration for Auto Key Negotiation
Field Description Remote
 VPN Auto Policy menu
 VPN Auto Policy Configuration Fields
VPN Auto Policy fields are defined in the following table
 Authenticating Header AH
 VPN Policy Configuration for Manual Key Exchange
Netbios Enable
 VPN Manual Policy menu
 VPN Manual Policy Configuration Fields
VPN Manual Policy fields are defined in the following table
 Value in its Authentication Algorithm Key Out field
 Netbios Enable
 Walk-Through of Configuration Scenarios on the FVS318v3
Certificate Revocation List CRL
 VPN Consortium Scenario
 Scenario 1 are Using IPv4
 WAN IP addresses
FVS318v3 Internet IP Address menu
 LAN IP Setup menu
 Set up the IKE Policy illustrated below on the FVS318v3
Scenario 1 IKE Policy
 Set up the FVS318v3 VPN -Auto Policy illustrated below
10 Scenario 1 VPN Auto Policy
 How to Check VPN Connections
Testing the Gateway a FVS318v3 LAN and the Gateway B LAN
 Create a certificate request for the FVS318v3
Install the trusted CA certificate for the Trusted Root CA
Obtain a root certificate
 11 Generate Self Certificate Request menu
 Highlight, copy and paste this data into a text file
12 Self Certificate Request data
 Click the Upload Certificate button
13 Self Certificate Requests table
 14 Self Certificates table
 Set up Certificate Revocation List CRL checking
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Viewing VPN Firewall Status Information
Router Status screen
 This screen shows the following parameters
FVS318v3 Status fields
 Connection Status fields
Connection Status action buttons
 Router Statistics screen
Router Statistics fields
 Viewing a List of Attached Devices
Upgrading the Firewall Software
 Router Upgrade menu
 Restoring the Configuration
Configuration File Management
Backing Up the Configuration
 Changing the Administrator Password
Erasing the Configuration
 Chapter Advanced Configuration
How to Configure Dynamic DNS
 Using the LAN IP Setup Options
 Configuring LAN TCP/IP Setup Parameters
 Using the Firewall as a Dhcp server
 Click Edit or Delete
Configuring Static Routes
Using Address Reservation
 Static Routes table
 Enabling Remote Management Access
Static Route Example
 Https//134.177.0.1238080
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Power LED Not On
Basic Functioning
 LEDs Never Turn Off
LAN or Internet Port LEDs Not On
 Troubleshooting the Web Configuration Interface
 Troubleshooting the ISP Connection
 Troubleshooting a TCP/IP Network Using a Ping Utility
Testing the LAN Path to Your Firewall
 Testing the Path from Your PC to a Remote Device
Ping -n 10 IP address
 Restoring the Default Configuration and Password
Problems with Date and Time
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Environmental Specifications
Power Adapter
Physical Specifications
Network Protocol and Standards Compatibility
 Interface Specifications
Electromagnetic Emissions
 Appendix B Network, Routing, and Firewall Basics
Related Publications Basic Router Concepts
 Routing Information Protocol
What is a Router?
IP Addresses and the Internet
 Figure B-1 Three Main Address Classes
 Netmask
Equals
 Subnet Addressing
Figure B-2 Example of Subnetting a Class B Address
 Table B-1 Netmask notation translation table for one octet
Table B-2. Netmask formats
 Private IP Addresses
Table B-2 Netmask formats
 Single IP Address Operation Using NAT
Figure B-3 Single IP Address Operation Using NAT
 Domain Name Server
MAC Addresses and Address Resolution Protocol
Related Documents
 IP Configuration by Dhcp
Internet Security and Firewalls
 Ethernet Cabling
What is a Firewall?
Denial of Service Attack
Stateful Packet Inspection
 Table B-3 UTP Ethernet cable wiring, straight-through
Category 5 Cable Quality
 Inside Twisted Pair Cables
Figure B-4 Straight-through twisted-pair cable
 Uplink Switches, Crossover Cables, and MDI/MDIX Switching
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 What is a VPN?
Appendix C Virtual Private Networking
 IPSec Components
What Is IPSec and How Does It Work?
IPSec Security Features
 Encapsulating Security Payload ESP
 Authentication Header AH
IKE Security Association
 Mode
 Understand the Process Before You Begin
Key Management
 VPN Process Overview
Addresses
 Table C-2 Subnet addressing
VPN Tunnel Between Gateways
Firewalls
 IPSec Security Association IKE
VPN Tunnel Negotiation Steps
 Vpnc IKE Phase I Parameters
Vpnc IKE Security Parameters
 Additional Reading
Testing and Troubleshooting
Vpnc IKE Phase II Parameters
 Relevant RFCs listed numerically
 Appendix D Preparing Your Network
Preparing Your Computers for TCP/IP Networking
 Configuring Windows 95, 98, and Me for TCP/IP Networking
Install or Verify Windows Networking Components
 Select Microsoft
 Enabling Dhcp to Automatically Configure TCP/IP Settings
Choose Settings, and then Control Panel
 Primary Network Logon is set to Windows logon
 Selecting Windows’ Internet Access Method
Verifying TCP/IP Properties
 Configuring Windows NT4, 2000 or XP for IP Networking
Double-click the Network and Dialup Connections icon
 Dhcp Configuration of TCP/IP in Windows XP
Locate your Network Neighborhood icon
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Dhcp Configuration of TCP/IP in Windows
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Obtain an IP address automatically is selected
 Dhcp Configuration of TCP/IP in Windows NT4
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Verifying TCP/IP Properties for Windows XP, 2000, and NT4
TCP/IP Properties dialog box now displays
 MacOS
Configuring the Macintosh for TCP/IP Networking
MacOS 8.6 or
 Verifying TCP/IP Properties for Macintosh Computers
 Verifying the Readiness of Your Internet Account
Are Login Protocols Used?
What Is Your Configuration Information?
 Select the IP Address tab
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Restarting the Network
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Case Study Overview
Gathering the Network Information
 Configure Log in to Use the VPN Wizard to
 To Figure E-3
 Verify the information example screen Example screen
 Figure E-4 Testing Flowchart
Activating the VPN Tunnel
 FVS318v3-to-FVS318v3 Case
Summary
 Use the VPN Wizard to configure the FVS318v3 at Gateway a
 Gateway a VPN Parameter Entry
Continue as shown in Figure E-3
 Viewing and Editing the VPN Parameters
Gateway a VPN Policy Parameters
 Gateway a IKE Parameters
 Initiating and Checking the VPN Connections
 VPN Status at Gateway a FVS318v3
VPN Status at Gateway B FVS318v3
 FVS318v3-to-FVS318v2 Case
 Use the VPN Wizard to configure the FVS318v3 at Gateway a
 Continue as shown in Figure E-3
 Viewing and Editing the VPN Parameters
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Initiating and Checking the VPN Connections
 IPSec Connection Status at Gateway B FVS318v2
Status of VPN tunnel to and from Gateway a
 FVS318v3-to-FVL328 Case
 Use the VPN Wizard to configure the FVS318v3 at Gateway a
 Continue as shown in Figure E-3
 Viewing and Editing the VPN Parameters
 Gateway a IKE Parameters
 Initiating and Checking the VPN Connections
 IPSec Connection Status at Gateway B FVL328
 Table E-4 Policy Summary
FVS318v3-to-VPN Client Case
Client-to-Gateway VPN Tunnel Overview
Table E-5 Differences between VPN tunnel types
 Configuring the VPN Tunnel
Connection Type a Remote VPN Client
 Figure E-20 VPN Wizard at Gateway a FVS318v3
 Figure E-21 VPN parameters at Gateway a FVS318v3
 Figure E-22 Adding and renaming a new connection
 Figure E-23 Scenario1 connection screen parameters
 Figure E-24 Scenario1 Security Policy screen parameters
 Figure E-25 Scenario1 My Identity screen parameters
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Choose Scenario1
Figure E-27 Scenario1 connection launch from VPN Client PC
 Select Connection Monitor
See Figure E-28for the resulting status screens
 Connection Monitor at Gateway B remote VPN Client
 List of Glossary Terms
Numeric
 Packet sent to all devices on a network
 Dhcp
 See Internet Control Message Protocol
 Ieee
 Internet service provider
 Megabits per second
 Set of rules for communication between devices on a network
 See Wide Area Network
 Wins