Reference Manual for the ProSafe VPN Firewall FVS318v3
EN 55 022 Declaration of Conformance
Trademarks
Statement of Conditions
Voluntary Control Council for Interference Vcci Statement
Bestätigung des Herstellers/Importeurs
Certificate of the Manufacturer/Importer
Product and Publication Details
Contents
Chapter Firewall Protection Content Filtering
Chapter Advanced Virtual Private Networking
Chapter Advanced Configuration
Appendix C Virtual Private Networking
Appendix D Preparing Your Network
Glossary
Xii Contents
Manual Scope
Audience, Scope, Conventions, and Formats
Typographical Conventions
How to Use This Manual
Printing a Chapter
How to Print this Manual
Printing a Page in the Html View
Printing the Full Manual
Reference Manual for the ProSafe VPN Firewall FVS318v3
Key Features of the VPN Firewall
Chapter Introduction
Powerful, True Firewall with Content Filtering
Security
Autosensing Ethernet Connections with Auto Uplink
Extensive Protocol Support
Easy Installation and Management
Maintenance and Support
Package Contents
FVS318v3 Rear Panel
LED Descriptions
NETGEAR-Related Products
NETGEAR-Related Products
Netgear Product Registration, Support, and Documentation
Reference Manual for the ProSafe VPN Firewall FVS318v3
Prepare to Install Your FVS318v3 ProSafe VPN Firewall
First, Connect the FVS318v3
Disconnect the Ethernet cable from the computer
Modem
Restart Your Network in the Correct Sequence
Now, Configure the FVS318v3 for Internet Access
Status lights
Netgear Smart Wizard Configuration Assistant welcome screen
Troubleshooting Tips
Be sure to restart your network in this sequence
Make sure the network settings of the computer are correct
Make sure the Ethernet cables are securely plugged
Overview of How to Access the FVS318v3 VPN Firewall
Ways to access the firewall
Login URL
How to Bypass the Configuration Assistant
Login result FVS318v3 home
Using the Smart Setup Wizard
How to Manually Configure Your Internet Connection
ISP Does Not Require Login
Reference Manual for the ProSafe VPN Firewall FVS318v3
11 Basic Settings ISP list
Chapter Firewall Protection Content Filtering
Firewall Protection and Content Filtering Overview
Block Sites
Block Sites menu
Using Rules to Block or Allow Specific Kinds of Traffic
Rules menu
Reference Manual for the ProSafe VPN Firewall FVS318v3
Inbound Rules Port Forwarding
Inbound Rule Example a Local Public Web Server
Considerations for Inbound Rules
Rule example a videoconference from restricted addresses
Outbound Rules Service Blocking
Outbound Rule Example Blocking Instant Messenger
Default DMZ Server
Order of Precedence for Rules
Click Default DMZ Server
Respond to Ping on Internet WAN Port
Services
Services menu
Add Custom Service menu
Using a Schedule to Block or Allow Specific Traffic
Schedule
Time Zone
Getting E-Mail Notifications of Event Logs and Alerts
10 E-mail menu
Reference Manual for the ProSafe VPN Firewall FVS318v3
Viewing Logs of Web Access or Attempted Web Access
11 Logs menu
Log action buttons
Syslog
Log entry descriptions
Reference Manual for the ProSafe VPN Firewall FVS318v3
Chapter Basic Virtual Private Networking
VPN Tunnel
PCs
AES
Configuration
Configuring the Client-to-Gateway VPN Tunnel on the FVS318v3
Summary screen below displays
Vpnc Recommended Settings
Configuring the Netgear ProSafe VPN Client on the Remote PC
Security Policy Editor new connection
10 Security Policy Editor connection settings
11 Security Policy Editor Security Policy
12 Security Policy Editor My Identity
14 Security Policy Editor Authentication
15 Security Policy Editor Key Exchange
16 Running a Ping test to the LAN from the PC
18 Log Viewer screen
Select Export Security Policy from the File pulldown
Transferring a Security Policy to Another Client
Exporting a Security Policy
Importing a Security Policy
Scenario1
Basic
Procedure to Configure a Gateway-to-Gateway VPN Tunnel
23 VPN Wizard start screen
25 Remote IP
27 VPN Wizard Summary
28 VPN Recommended Settings
30 VPN Status/Log screen
VPN Tunnel Control
Start Using a VPN Tunnel to Activate It
Using the VPN Status Page to Activate a VPN Tunnel
Activating a VPN Tunnel
Activate the VPN Tunnel by Pinging the Remote Endpoint
32 VPN Status/Log screen
Type ping -t 192.168.3.1 and then click OK
Type ping
Verifying the Status of a VPN Tunnel
36 Pinging test results
Deactivating a VPN Tunnel
38 Current VPN Tunnels SAs screen
Using the VPN Status Page to Deactivate a VPN Tunnel
39 VPN Policies
Deleting a VPN Tunnel
41 Current VPN Tunnels SAs screen
FVS318v3 VPN Firewall
Using Policies to Manage VPN Traffic
Using Automatic Key Management
IKE Policies’ Automatic Key and Authentication Management
IKE Policy Configuration Menu
IKE Policy Configuration fields
Field Description General
VPN Policy Configuration for Auto Key Negotiation
Field Description Remote
VPN Auto Policy menu
VPN Auto Policy Configuration Fields
VPN Auto Policy fields are defined in the following table
Authenticating Header AH
VPN Policy Configuration for Manual Key Exchange
Netbios Enable
VPN Manual Policy menu
VPN Manual Policy Configuration Fields
VPN Manual Policy fields are defined in the following table
Value in its Authentication Algorithm Key Out field
Netbios Enable
Walk-Through of Configuration Scenarios on the FVS318v3
Certificate Revocation List CRL
VPN Consortium Scenario
Scenario 1 are Using IPv4
WAN IP addresses
FVS318v3 Internet IP Address menu
LAN IP Setup menu
Set up the IKE Policy illustrated below on the FVS318v3
Scenario 1 IKE Policy
Set up the FVS318v3 VPN -Auto Policy illustrated below
10 Scenario 1 VPN Auto Policy
How to Check VPN Connections
Testing the Gateway a FVS318v3 LAN and the Gateway B LAN
Create a certificate request for the FVS318v3
Install the trusted CA certificate for the Trusted Root CA
Obtain a root certificate
11 Generate Self Certificate Request menu
Highlight, copy and paste this data into a text file
12 Self Certificate Request data
Click the Upload Certificate button
13 Self Certificate Requests table
14 Self Certificates table
Set up Certificate Revocation List CRL checking
Reference Manual for the ProSafe VPN Firewall FVS318v3
Viewing VPN Firewall Status Information
Router Status screen
This screen shows the following parameters
FVS318v3 Status fields
Connection Status fields
Connection Status action buttons
Router Statistics screen
Router Statistics fields
Viewing a List of Attached Devices
Upgrading the Firewall Software
Router Upgrade menu
Restoring the Configuration
Configuration File Management
Backing Up the Configuration
Changing the Administrator Password
Erasing the Configuration
Chapter Advanced Configuration
How to Configure Dynamic DNS
Using the LAN IP Setup Options
Configuring LAN TCP/IP Setup Parameters
Using the Firewall as a Dhcp server
Click Edit or Delete
Configuring Static Routes
Using Address Reservation
Static Routes table
Enabling Remote Management Access
Static Route Example
Https//134.177.0.1238080
Reference Manual for the ProSafe VPN Firewall FVS318v3
Reference Manual for the ProSafe VPN Firewall FVS318v3
Power LED Not On
Basic Functioning
LEDs Never Turn Off
LAN or Internet Port LEDs Not On
Troubleshooting the Web Configuration Interface
Troubleshooting the ISP Connection
Troubleshooting a TCP/IP Network Using a Ping Utility
Testing the LAN Path to Your Firewall
Testing the Path from Your PC to a Remote Device
Ping -n 10 IP address
Restoring the Default Configuration and Password
Problems with Date and Time
Reference Manual for the ProSafe VPN Firewall FVS318v3
Environmental Specifications
Power Adapter
Physical Specifications
Network Protocol and Standards Compatibility
Interface Specifications
Electromagnetic Emissions
Appendix B Network, Routing, and Firewall Basics
Related Publications Basic Router Concepts
Routing Information Protocol
What is a Router?
IP Addresses and the Internet
Figure B-1 Three Main Address Classes
Netmask
Equals
Subnet Addressing
Figure B-2 Example of Subnetting a Class B Address
Table B-1 Netmask notation translation table for one octet
Table B-2. Netmask formats
Private IP Addresses
Table B-2 Netmask formats
Single IP Address Operation Using NAT
Figure B-3 Single IP Address Operation Using NAT
Domain Name Server
MAC Addresses and Address Resolution Protocol
Related Documents
IP Configuration by Dhcp
Internet Security and Firewalls
Ethernet Cabling
What is a Firewall?
Denial of Service Attack
Stateful Packet Inspection
Table B-3 UTP Ethernet cable wiring, straight-through
Category 5 Cable Quality
Inside Twisted Pair Cables
Figure B-4 Straight-through twisted-pair cable
Uplink Switches, Crossover Cables, and MDI/MDIX Switching
Reference Manual for the ProSafe VPN Firewall FVS318v3
Reference Manual for the ProSafe VPN Firewall FVS318v3
What is a VPN?
Appendix C Virtual Private Networking
IPSec Components
What Is IPSec and How Does It Work?
IPSec Security Features
Encapsulating Security Payload ESP
Authentication Header AH
IKE Security Association
Mode
Understand the Process Before You Begin
Key Management
VPN Process Overview
Addresses
Table C-2 Subnet addressing
VPN Tunnel Between Gateways
Firewalls
IPSec Security Association IKE
VPN Tunnel Negotiation Steps
Vpnc IKE Phase I Parameters
Vpnc IKE Security Parameters
Additional Reading
Testing and Troubleshooting
Vpnc IKE Phase II Parameters
Relevant RFCs listed numerically
Appendix D Preparing Your Network
Preparing Your Computers for TCP/IP Networking
Configuring Windows 95, 98, and Me for TCP/IP Networking
Install or Verify Windows Networking Components
Select Microsoft
Enabling Dhcp to Automatically Configure TCP/IP Settings
Choose Settings, and then Control Panel
Primary Network Logon is set to Windows logon
Selecting Windows’ Internet Access Method
Verifying TCP/IP Properties
Configuring Windows NT4, 2000 or XP for IP Networking
Double-click the Network and Dialup Connections icon
Dhcp Configuration of TCP/IP in Windows XP
Locate your Network Neighborhood icon
Reference Manual for the ProSafe VPN Firewall FVS318v3
Dhcp Configuration of TCP/IP in Windows
Reference Manual for the ProSafe VPN Firewall FVS318v3
Obtain an IP address automatically is selected
Dhcp Configuration of TCP/IP in Windows NT4
Reference Manual for the ProSafe VPN Firewall FVS318v3
Verifying TCP/IP Properties for Windows XP, 2000, and NT4
TCP/IP Properties dialog box now displays
MacOS
Configuring the Macintosh for TCP/IP Networking
MacOS 8.6 or
Verifying TCP/IP Properties for Macintosh Computers
Verifying the Readiness of Your Internet Account
Are Login Protocols Used?
What Is Your Configuration Information?
Select the IP Address tab
Reference Manual for the ProSafe VPN Firewall FVS318v3
Restarting the Network
Reference Manual for the ProSafe VPN Firewall FVS318v3
Case Study Overview
Gathering the Network Information
Configure Log in to Use the VPN Wizard to
To Figure E-3
Verify the information example screen Example screen
Figure E-4 Testing Flowchart
Activating the VPN Tunnel
FVS318v3-to-FVS318v3 Case
Summary
Use the VPN Wizard to configure the FVS318v3 at Gateway a
Gateway a VPN Parameter Entry
Continue as shown in Figure E-3
Viewing and Editing the VPN Parameters
Gateway a VPN Policy Parameters
Gateway a IKE Parameters
Initiating and Checking the VPN Connections
VPN Status at Gateway a FVS318v3
VPN Status at Gateway B FVS318v3
FVS318v3-to-FVS318v2 Case
Use the VPN Wizard to configure the FVS318v3 at Gateway a
Continue as shown in Figure E-3
Viewing and Editing the VPN Parameters
Reference Manual for the ProSafe VPN Firewall FVS318v3
Initiating and Checking the VPN Connections
IPSec Connection Status at Gateway B FVS318v2
Status of VPN tunnel to and from Gateway a
FVS318v3-to-FVL328 Case
Use the VPN Wizard to configure the FVS318v3 at Gateway a
Continue as shown in Figure E-3
Viewing and Editing the VPN Parameters
Gateway a IKE Parameters
Initiating and Checking the VPN Connections
IPSec Connection Status at Gateway B FVL328
Table E-4 Policy Summary
FVS318v3-to-VPN Client Case
Client-to-Gateway VPN Tunnel Overview
Table E-5 Differences between VPN tunnel types
Configuring the VPN Tunnel
Connection Type a Remote VPN Client
Figure E-20 VPN Wizard at Gateway a FVS318v3
Figure E-21 VPN parameters at Gateway a FVS318v3
Figure E-22 Adding and renaming a new connection
Figure E-23 Scenario1 connection screen parameters
Figure E-24 Scenario1 Security Policy screen parameters
Figure E-25 Scenario1 My Identity screen parameters
Reference Manual for the ProSafe VPN Firewall FVS318v3
Choose Scenario1
Figure E-27 Scenario1 connection launch from VPN Client PC
Select Connection Monitor
See Figure E-28for the resulting status screens
Connection Monitor at Gateway B remote VPN Client
List of Glossary Terms
Numeric
Packet sent to all devices on a network
Dhcp
See Internet Control Message Protocol
Ieee
Internet service provider
Megabits per second
Set of rules for communication between devices on a network
See Wide Area Network
Wins