Reference Manual for the ProSafe VPN Firewall FVS318v3
 EN 55 022 Declaration of Conformance
Trademarks
Statement of Conditions
 Voluntary Control Council for Interference Vcci Statement
Bestätigung des Herstellers/Importeurs
Certificate of the Manufacturer/Importer
 Product and Publication Details
 Contents
 Chapter Firewall Protection Content Filtering
 Chapter Advanced Virtual Private Networking
 Chapter Advanced Configuration
 Appendix C Virtual Private Networking
 Appendix D Preparing Your Network
 Glossary
 Xii Contents
 Manual Scope
Audience, Scope, Conventions, and Formats
Typographical Conventions
 How to Use This Manual
 Printing the Full Manual
How to Print this Manual
Printing a Page in the Html View
Printing a Chapter
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Chapter Introduction
Key Features of the VPN Firewall
 Security
Powerful, True Firewall with Content Filtering
 Extensive Protocol Support
Autosensing Ethernet Connections with Auto Uplink
 Maintenance and Support
Easy Installation and Management
 Package Contents
 LED Descriptions
FVS318v3 Rear Panel
 NETGEAR-Related Products
NETGEAR-Related Products
Netgear Product Registration, Support, and Documentation
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 First, Connect the FVS318v3
Prepare to Install Your FVS318v3 ProSafe VPN Firewall
 Modem
Disconnect the Ethernet cable from the computer
 Restart Your Network in the Correct Sequence
 Status lights
Now, Configure the FVS318v3 for Internet Access
 Netgear Smart Wizard Configuration Assistant welcome screen
 Be sure to restart your network in this sequence
Troubleshooting Tips
 Make sure the Ethernet cables are securely plugged
Make sure the network settings of the computer are correct
 Ways to access the firewall
Overview of How to Access the FVS318v3 VPN Firewall
 Login URL
 Login result FVS318v3 home
How to Bypass the Configuration Assistant
 Using the Smart Setup Wizard
 ISP Does Not Require Login
How to Manually Configure Your Internet Connection
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 11 Basic Settings ISP list
 Firewall Protection and Content Filtering Overview
Chapter Firewall Protection Content Filtering
 Block Sites menu
Block Sites
 Rules menu
Using Rules to Block or Allow Specific Kinds of Traffic
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Inbound Rule Example a Local Public Web Server
Inbound Rules Port Forwarding
 Rule example a videoconference from restricted addresses
Considerations for Inbound Rules
 Outbound Rule Example Blocking Instant Messenger
Outbound Rules Service Blocking
 Order of Precedence for Rules
Default DMZ Server
 Respond to Ping on Internet WAN Port
Click Default DMZ Server
 Services menu
Services
 Add Custom Service menu
 Schedule
Using a Schedule to Block or Allow Specific Traffic
 Time Zone
 10 E-mail menu
Getting E-Mail Notifications of Event Logs and Alerts
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 11 Logs menu
Viewing Logs of Web Access or Attempted Web Access
 Log action buttons
Syslog
Log entry descriptions
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Chapter Basic Virtual Private Networking
 VPN Tunnel
 PCs
 AES
 Configuration
 Configuring the Client-to-Gateway VPN Tunnel on the FVS318v3
 Summary screen below displays
 Vpnc Recommended Settings
 Configuring the Netgear ProSafe VPN Client on the Remote PC
 Security Policy Editor new connection
 10 Security Policy Editor connection settings
 11 Security Policy Editor Security Policy
 12 Security Policy Editor My Identity
 14 Security Policy Editor Authentication
 15 Security Policy Editor Key Exchange
 16 Running a Ping test to the LAN from the PC
 18 Log Viewer screen
 Select Export Security Policy from the File pulldown
Transferring a Security Policy to Another Client
Exporting a Security Policy
 Scenario1
Importing a Security Policy
 Basic
 23 VPN Wizard start screen
Procedure to Configure a Gateway-to-Gateway VPN Tunnel
 25 Remote IP
 27 VPN Wizard Summary
 28 VPN Recommended Settings
 30 VPN Status/Log screen
 Activating a VPN Tunnel
Start Using a VPN Tunnel to Activate It
Using the VPN Status Page to Activate a VPN Tunnel
VPN Tunnel Control
 32 VPN Status/Log screen
Activate the VPN Tunnel by Pinging the Remote Endpoint
 Type ping
Type ping -t 192.168.3.1 and then click OK
 36 Pinging test results
Verifying the Status of a VPN Tunnel
 38 Current VPN Tunnels SAs screen
Deactivating a VPN Tunnel
 39 VPN Policies
Using the VPN Status Page to Deactivate a VPN Tunnel
 41 Current VPN Tunnels SAs screen
Deleting a VPN Tunnel
 FVS318v3 VPN Firewall
 Using Automatic Key Management
Using Policies to Manage VPN Traffic
 IKE Policy Configuration Menu
IKE Policies’ Automatic Key and Authentication Management
 Field Description General
IKE Policy Configuration fields
 Field Description Remote
VPN Policy Configuration for Auto Key Negotiation
 VPN Auto Policy menu
 VPN Auto Policy fields are defined in the following table
VPN Auto Policy Configuration Fields
 Authenticating Header AH
 Netbios Enable
VPN Policy Configuration for Manual Key Exchange
 VPN Manual Policy menu
 VPN Manual Policy fields are defined in the following table
VPN Manual Policy Configuration Fields
 Value in its Authentication Algorithm Key Out field
 Netbios Enable
 Certificate Revocation List CRL
Walk-Through of Configuration Scenarios on the FVS318v3
 VPN Consortium Scenario
 Scenario 1 are Using IPv4
 FVS318v3 Internet IP Address menu
WAN IP addresses
 LAN IP Setup menu
 Scenario 1 IKE Policy
Set up the IKE Policy illustrated below on the FVS318v3
 10 Scenario 1 VPN Auto Policy
Set up the FVS318v3 VPN -Auto Policy illustrated below
 Testing the Gateway a FVS318v3 LAN and the Gateway B LAN
How to Check VPN Connections
 Create a certificate request for the FVS318v3
Install the trusted CA certificate for the Trusted Root CA
Obtain a root certificate
 11 Generate Self Certificate Request menu
 12 Self Certificate Request data
Highlight, copy and paste this data into a text file
 13 Self Certificate Requests table
Click the Upload Certificate button
 14 Self Certificates table
 Set up Certificate Revocation List CRL checking
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Router Status screen
Viewing VPN Firewall Status Information
 FVS318v3 Status fields
This screen shows the following parameters
 Connection Status action buttons
Connection Status fields
 Router Statistics fields
Router Statistics screen
 Upgrading the Firewall Software
Viewing a List of Attached Devices
 Router Upgrade menu
 Restoring the Configuration
Configuration File Management
Backing Up the Configuration
 Erasing the Configuration
Changing the Administrator Password
 How to Configure Dynamic DNS
Chapter Advanced Configuration
 Using the LAN IP Setup Options
 Configuring LAN TCP/IP Setup Parameters
 Using the Firewall as a Dhcp server
 Click Edit or Delete
Configuring Static Routes
Using Address Reservation
 Static Routes table
 Static Route Example
Enabling Remote Management Access
 Https//134.177.0.1238080
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Basic Functioning
Power LED Not On
 LAN or Internet Port LEDs Not On
LEDs Never Turn Off
 Troubleshooting the Web Configuration Interface
 Troubleshooting the ISP Connection
 Testing the LAN Path to Your Firewall
Troubleshooting a TCP/IP Network Using a Ping Utility
 Ping -n 10 IP address
Testing the Path from Your PC to a Remote Device
 Problems with Date and Time
Restoring the Default Configuration and Password
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Network Protocol and Standards Compatibility
Power Adapter
Physical Specifications
Environmental Specifications
 Electromagnetic Emissions
Interface Specifications
 Related Publications Basic Router Concepts
Appendix B Network, Routing, and Firewall Basics
 Routing Information Protocol
What is a Router?
IP Addresses and the Internet
 Figure B-1 Three Main Address Classes
 Equals
Netmask
 Figure B-2 Example of Subnetting a Class B Address
Subnet Addressing
 Table B-2. Netmask formats
Table B-1 Netmask notation translation table for one octet
 Table B-2 Netmask formats
Private IP Addresses
 Figure B-3 Single IP Address Operation Using NAT
Single IP Address Operation Using NAT
 Domain Name Server
MAC Addresses and Address Resolution Protocol
Related Documents
 Internet Security and Firewalls
IP Configuration by Dhcp
 Stateful Packet Inspection
What is a Firewall?
Denial of Service Attack
Ethernet Cabling
 Category 5 Cable Quality
Table B-3 UTP Ethernet cable wiring, straight-through
 Figure B-4 Straight-through twisted-pair cable
Inside Twisted Pair Cables
 Uplink Switches, Crossover Cables, and MDI/MDIX Switching
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Appendix C Virtual Private Networking
What is a VPN?
 IPSec Components
What Is IPSec and How Does It Work?
IPSec Security Features
 Encapsulating Security Payload ESP
 IKE Security Association
Authentication Header AH
 Mode
 Key Management
Understand the Process Before You Begin
 Addresses
VPN Process Overview
 Table C-2 Subnet addressing
VPN Tunnel Between Gateways
Firewalls
 VPN Tunnel Negotiation Steps
IPSec Security Association IKE
 Vpnc IKE Security Parameters
Vpnc IKE Phase I Parameters
 Additional Reading
Testing and Troubleshooting
Vpnc IKE Phase II Parameters
 Relevant RFCs listed numerically
 Preparing Your Computers for TCP/IP Networking
Appendix D Preparing Your Network
 Install or Verify Windows Networking Components
Configuring Windows 95, 98, and Me for TCP/IP Networking
 Select Microsoft
 Choose Settings, and then Control Panel
Enabling Dhcp to Automatically Configure TCP/IP Settings
 Primary Network Logon is set to Windows logon
 Verifying TCP/IP Properties
Selecting Windows’ Internet Access Method
 Double-click the Network and Dialup Connections icon
Configuring Windows NT4, 2000 or XP for IP Networking
 Locate your Network Neighborhood icon
Dhcp Configuration of TCP/IP in Windows XP
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Dhcp Configuration of TCP/IP in Windows
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Obtain an IP address automatically is selected
 Dhcp Configuration of TCP/IP in Windows NT4
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 TCP/IP Properties dialog box now displays
Verifying TCP/IP Properties for Windows XP, 2000, and NT4
 MacOS
Configuring the Macintosh for TCP/IP Networking
MacOS 8.6 or
 Verifying TCP/IP Properties for Macintosh Computers
 Verifying the Readiness of Your Internet Account
Are Login Protocols Used?
What Is Your Configuration Information?
 Select the IP Address tab
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Restarting the Network
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Gathering the Network Information
Case Study Overview
 Configure Log in to Use the VPN Wizard to
 To Figure E-3
 Verify the information example screen Example screen
 Activating the VPN Tunnel
Figure E-4 Testing Flowchart
 Summary
FVS318v3-to-FVS318v3 Case
 Use the VPN Wizard to configure the FVS318v3 at Gateway a
 Continue as shown in Figure E-3
Gateway a VPN Parameter Entry
 Gateway a VPN Policy Parameters
Viewing and Editing the VPN Parameters
 Gateway a IKE Parameters
 Initiating and Checking the VPN Connections
 VPN Status at Gateway B FVS318v3
VPN Status at Gateway a FVS318v3
 FVS318v3-to-FVS318v2 Case
 Use the VPN Wizard to configure the FVS318v3 at Gateway a
 Continue as shown in Figure E-3
 Viewing and Editing the VPN Parameters
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Initiating and Checking the VPN Connections
 Status of VPN tunnel to and from Gateway a
IPSec Connection Status at Gateway B FVS318v2
 FVS318v3-to-FVL328 Case
 Use the VPN Wizard to configure the FVS318v3 at Gateway a
 Continue as shown in Figure E-3
 Viewing and Editing the VPN Parameters
 Gateway a IKE Parameters
 Initiating and Checking the VPN Connections
 IPSec Connection Status at Gateway B FVL328
 Table E-5 Differences between VPN tunnel types
FVS318v3-to-VPN Client Case
Client-to-Gateway VPN Tunnel Overview
Table E-4 Policy Summary
 Connection Type a Remote VPN Client
Configuring the VPN Tunnel
 Figure E-20 VPN Wizard at Gateway a FVS318v3
 Figure E-21 VPN parameters at Gateway a FVS318v3
 Figure E-22 Adding and renaming a new connection
 Figure E-23 Scenario1 connection screen parameters
 Figure E-24 Scenario1 Security Policy screen parameters
 Figure E-25 Scenario1 My Identity screen parameters
 Reference Manual for the ProSafe VPN Firewall FVS318v3
 Figure E-27 Scenario1 connection launch from VPN Client PC
Choose Scenario1
 See Figure E-28for the resulting status screens
Select Connection Monitor
 Connection Monitor at Gateway B remote VPN Client
 Numeric
List of Glossary Terms
 Packet sent to all devices on a network
 Dhcp
 See Internet Control Message Protocol
 Ieee
 Internet service provider
 Megabits per second
 Set of rules for communication between devices on a network
 See Wide Area Network
 Wins