Manuals
/
SonicWALL
/
Household Appliance
/
Home Security System
SonicWALL
3
manual
Firewall, 177
Models:
3
1
196
348
348
Download
348 pages
8.9 Kb
193
194
195
196
197
198
199
200
<
>
Install
Password
Flexible Default Route
Login
System Administration
Part 5 Wireless
Warranty
Configuring WAN Settings
Reset Data
System Diagnostics
Page 196
Image 196
P
7
A R T
Firewall
S
ONIC
WALL S
ONIC
OS S
TANDARD
3.0 A
DMINISTRATOR
’
S
G
UIDE
177
Page 195
Page 197
Page 196
Image 196
Page 195
Page 197
Contents
SonicOS Standard Administrators Guide
Table of Contents
Part 2 System
Part 3 Network
Part 4 Modem
Part 5 Wireless
Part 8 VPN
Configuring Site to Site VPN Policies Using
Vii
Part 9 Users
Viii
Part 11 Log
Index
Copyright Notice
Preface
Trademarks
Limited Warranty
Xii
Page
Organization of this Guide
Part 10 Security Services
Part 9 Users
Part 11 Log
About this Guide
Guide Conventions
Icons Used in this Manual
More Information on SonicWALL Products and Services
SonicWALL Technical Support
North America Telephone Support
International Telephone Support
Current Documentation
Xviii
Introduction
Sonicwall Sonicos Standard 3.0 ADMINISTRATOR’S Guide
Introduction
What’s New in SonicOS Standard
SonicWALL Management Interface
Navigating the Management Interface
SonicWALL Management Interface
Applying Changes
Status Bar
Navigating Tables
Getting Help
Common Icons in the Management Interface
Logging Out
Introduction
Basic SonicWALL Security Appliance Setup
SonicWALL Security Appliance Configuration Steps
Internet Service Provider ISP Information
Collecting Required ISP Information
Other Information
If You Have DSL
If You Have a Static IP Address
SonicWALL Management Interface
Using the SonicWALL Setup Wizard
SonicWALL TZ 170 SP
SonicWALL TZ 50 Wireless/TZ 150 Wireless/TZ 170 Wireless
Configuring a Static IP Address Internet Connection
Using the SonicWALL Setup Wizard
Configuring a Dhcp Internet Connection
Configuring a PPPoE Internet Connection
Configuring Pptp Internet Connectivity
Sonicwall Sonicos Standard 3.0 ADMINISTRATOR’S Guide
Configuring the TZ 170 SP using the Setup Wizard
Welcome to the SonicWALL Setup Wizard
Changing the Password
Configuring the WAN Network Mode
Selecting the Deployment Scenario
Configuring WAN Settings
Configuring LAN Settings
Configuring LAN Dhcp Settings
Configuring Wlan 802.11b/g Settings
Configuring the LAN Dhcp Settings
Configuring the LAN Settings
Configuring Wlan 802.11b Settings
Configuring the WAN Network Mode
Configuring the TZ 170 Wireless as a Secure Wireless Bridge
Configuring Wlan Network Setting
Configuring Secure Wireless Bridge Settings
Registering Your SonicWALL Security Appliance
Before You Register
Registering Your SonicWALL Security Appliance
Registering Your SonicWALL Security Appliance
Sonicwall Sonicos Standard 3.0 ADMINISTRATOR’S Guide
System
Sonicwall Sonicos Standard 3.0 ADMINISTRATOR’S Guide
System Status
Viewing System Status Information
System Status
System Messages
Wizards
System Information
Security Services
Latest Alerts
SonicWALL TZ 50 Wireless
SonicWALL TZ 150 Wireless
Network Interfaces
SonicWALL Security Appliance Model Interfaces SonicWALL TZ
System Licenses
System Licenses
System Licenses
Currently Licensed Nodes
Node License Status
Node License Exclusion List
Security Services Summary
Manage Security Services Online Manual Upgrade
Manual Upgrade for Closed Environments
From a Computer Connected to the Internet
System Licenses
System Administration
Using System Administration
System Administration
Login Security
Name/Password
Firewall Name
Web Management Settings
Enable Snmp
Advanced Management
Four addresses or host names can be used
Click OK
Enable Management Using SonicWALL GMS
Using System Administration
Setting System Time
System Time
Set Time
System Time
NTP Settings
Setting the SonicWALL Security Appliance Time
Configuring System Settings
System Settings
Settings
Import Settings
Export Settings
Click Export Settings
Firmware Management
New Firmware
Firmware Management Settings
SafeMode Rebooting the SonicWALL Security Appliance
System Information
Firmware Management
System Diagnostics
System Diagnostics
Tech Support Report
Generating a Tech Support Report
Active Connections Monitor Settings
Diagnostic Tools
Active Connections Monitor
CPU Monitor
DNS Name Lookup
Find Network Path
Packet Trace
Select Packet Trace from the Diagnostic tool menu
Ping
Reverse Name Resolution
Process Monitor
System Restart
Network
Sonicwall Sonicos Standard 3.0 ADMINISTRATOR’S Guide
Network Settings
Configuring Network Settings
Network Settings
Setup Wizard
Interfaces
DNS Settings
Interface Options by SonicWALL Security Appliance
Configuring the WAN Interface
Configuring Transparent Mode
Configuration Example
Configuring the WAN Interface
Configuring NAT Enabled
Configuring NAT with Dhcp Client
Configuring NAT with PPPoE Client
Configuring NAT with L2TP Client
Configuring NAT with Pptp Client
Configuring Ethernet Settings in WAN Properties
Configuring the WAN Interface
Basic LAN Configuration
Configuring the LAN Interface
Configuring Multiple LAN Subnets
Configuring Ethernet Settings
Configuring the OPT Interface
Configuring the OPT Interface
Configuring Transparent Mode
Configuring the DMZ Interface
Configuring NAT Mode
Configuring the DMZ Interface
Select OPT in NAT Mode
Configuring Transparent Mode
Configuring the Modem Interface TZ 170 SP
Configuring the Modem Interface TZ 170 SP
Select DMZ in NAT Mode
Modem Settings
Profiles
Select Enable WAN Failover
Failover
Advanced
Activating the Modem
Sonicwall Sonicos Standard 3.0 ADMINISTRATOR’S Guide
Sonicwall Sonicos Standard 3.0 ADMINISTRATOR’S Guide
Configuring One-to-One NAT
Select the Enable One-to-One NAT check box
Network One-to-One NAT
Network One-to-One NAT
Select Enable One-to-One NAT
One-to-One NAT Configuration Example
Click Firewall, then Access Rules
Allow Service Http Source WAN
Configuring One-to-One NAT
Network Web Proxy
Configuring Web Proxy Settings
Network Web Proxy
Bypass Proxy Servers Upon Proxy Failure
Configuring Automatic Web Proxy Forwarding
Forward OPT/DMZ/WLAN Client Requests to Proxy Server
Network Intranet
Configuring Intranet Settings
Network Intranet
Installation
Intranet Settings
Specified address ranges are attached to the LAN link
Specified address ranges are attached to the WAN link
Network Routing
Configuring Static Routes
Network Routing
Static Route Configuration Example
Static Routes
Key terms
SonicWALL LAN IP Address
Route Advertisement Configuration
Route Advertisement
Routing Table
Network ARP
Configuring Address Resolution Protocol Settings
Network ARP
Static ARP Entries
Adding a Secondary Subnet using the Static ARP Method
Secondary Subnets with Static ARP
Network ARP
Prohibit Dynamic ARP Entries
Navigating and Sorting the ARP Cache Table
Flushing the ARP Cache
Configuring Address Resolution Protocol Settings
Configuring the Dhcp Server
Dhcp Server Settings
Network Dhcp Server
Network Dhcp Server
Configuring Dhcp Server for Dynamic Ranges
Dhcp Server Lease Scopes
Configuring Static Dhcp Entries
101
Current Dhcp Leases
Configuring Dynamic DNS
Network Dynamic DNS
Supported Ddns Providers
Network Dynamic DNS
Additional Services offered by Dynamic DNS Providers
Configuring Dynamic DNS
105
106
Dynamic DNS Settings Table
107
108
Modem
109
110
Viewing Modem Status
Modem Status
Modem Status
111
Modem Status
Configuring Modem Settings
Modem Settings
Modem Settings
113
Configuring Profile and Modem Settings
Configuring Modem Failover
Modem Failover Settings
Modem Failover
Modem Failover
Configuring Modem Failover
Modem Advanced
Modem Advanced
117
Configuring Advanced Modem Settings
Configuring Modem Dialup Properties
Modem Dialup Profiles
Dial-Up Profiles
Modem Dialup Profiles
Modem Dialup Profiles Modem Profile Configuration
Configuring a Dialup Profile
Modem Dialup Profiles Modem Profile Configuration
121
122
Chat Scripts
123
Custom Chat Scripts
Wireless
125
126
LAN WAN
127
Considerations for Using Wireless Connections
Optimal Wireless Performance Recommendations
Wireless Guest Services WGS
Optimal Wireless Performance Recommendations
129
WiFiSec Enforcement
Wireless Node Count Enforcement
MAC Filter List
Using the Wireless Wizard
Welcome to the SonicWALL Wireless Configuration Wizard
Wlan Network Settings
Using the Wireless Wizard
Wlan 802.11b Settings
Wlan Security Settings
Wireless Guest Services
WiFiSec VPN Client User Authentication
133
Wireless Configuration Summary
Updating the TZ 50 Wireless/TZ 150 Wireless/TZ 170 Wireless
Wireless Status
Configuring Additional Wireless Features
Wireless Status
135
Wlan Settings
Access Point Status
Station Status
Wlan Statistics
137
138
Configuring Wireless Settings
Wireless Settings
Wireless Radio Mode
Wireless Settings
Wireless Settings
Secure Wireless Bridging TZ 170 Only
141
Configuring a Secure Wireless Bridge
Wireless Bridging without WiFiSec
Network Settings for the Example Network
143
Advanced Configuration for both VPN Policies
Select LAN for VPN Terminated at
Wireless Bridge VPN Policy
145
146
Configuring WEP and WPA Encryption
Wireless WEP/WPA Encryption
Wireless WEP/WPA Encryption
147
WPA Encryption Settings
WEP Encryption Settings
WEP Encryption Keys
WPA-EAP Settings
WPA-PSK Settings
149
WPA Settings
Wireless Advanced
Wireless Advanced
Beaconing & Ssid Controls
151
Advanced Radio Settings
Wireless Client Communications
Configurable Antenna Diversity TZ 170 Wireless
153
154
Configuring the MAC Filter List
Wireless MAC Filter List
Wireless MAC Filter List
155
156
Configuring Wireless IDS
Wireless IDS
Wireless Bridge IDS
Wireless IDS
Access Point IDS
Enable Client Null Probing
Rogue Access Point Detection
Association Flood Detection
Authorizing Access Points on Your Network
159
160
Wireless Guest Services
161
162
WGS Status
WGS Status
163
Viewing Wireless Guest Services Status
Configuring Wireless Guest Services
WGS Settings
WGS Settings
165
Enable Dynamic Address Translation DAT
Bypass Guest Authentication
Bypass Filters for Guest Accounts
Enable Smtp Redirect
Enable URL Allow List for Authenticated Users
Enable IP Address Deny List for Authenticated Users
167
Customize Login
Check the Customize Login Page box
Custom Post Authentication Redirect
Maximum Concurrent Guests
WGS Account Profiles
To add a profile
Account Lifetime
Managing Wireless Guest Accounts
WGS Accounts
Working with Guest Accounts
WGS Accounts
Automatically Generating Guest Accounts
Manually Configuring Wireless Guests
Account Detail Printing
Account Profile
173
Flexible Default Route
Secure Access Point with Virtual Adapter Support
Secure Access Point with Wireless Guest Services
175
176
Firewall
177
178
Configuring Network Access Rules
Network Access Rules Overview
Network Access Rules Overview
179
Using Bandwidth Management with Access Rules
Firewall Access Rules
Restoring Default Network Access Rules
Adding Rules using the Network Access Rule Wizard
Configuring a Public Server Rule
Navigating and Sorting the Access Rules Table Entries
Configuring a General Network Access Rule
183
Adding Rules Using the Add Rule Window
185
Configuring Network Access Rules Click the Bandwidth tab
Blocking LAN Access for Specific Services
Rule Examples
Enabling Ping
Select WAN from the Destination Ethernet menu
188
Configuring Advanced Rule Options
Access Rules Advanced
Windows Networking NetBIOS Broadcast Pass Through
Access Rules Advanced
TCP Connection Inactivity Timeout
Access Rule Service Options
Detection Prevention
Source Routed Packets
Configuring Custom Services
Firewall Services
User Defined Custom Services
Firewall Services
Predefined Services
Configuring VoIP
Firewall VoIP
VoIP Protocols
Firewall VoIP
323
SIP
Configuring the VoIP Settings
SIP Settings
Settings
195
196
Monitoring Active Firewall Connections
Firewall Connections Monitor
Firewall Connections Monitor
197
Setting Filter Logic
Using Group Filters
Click Apply Filters
Source IP Priority && Category && Source && Destination
VPN
199
200
Configuring VPN Settings
SonicWALL VPN Options Overview
SonicWALL VPN Options Overview
201
VPN Global Settings
VPN Settings
VPN Policies
Configuring GroupVPN Policy on the SonicWALL
Configuring GroupVPN Policy on the SonicWALL
Currently Active VPN Tunnels
Navigating and Sorting the VPN Policies Entries
Configuring IKE Preshared Secret
205
206
207
Configuring GroupVPN with IKE 3rd Party Certificates
209
210
211
212
Site to Site VPN Configurations
Site to Site VPN Configurations
Export a GroupVPN Client Policy
Site-to-Site VPN Deployments
VPN Planning Sheet for Site-to-Site VPN Policies
Site a
Router
Additional Information
215
Creating a Typical IKE Preshared Secret VPN Policy
Creating a Custom VPN Policy IKE with Preshared Secret
217
Creating a Manual Key VPN Policy with the VPN Policy Wizard
219
220
Tip The Shared Secret must be a minimum of four characters
Configuring a VPN Policy IKE with Preshared Secret
221
222
223
Configuring a VPN Policy using Manual Key
Select Manual Key from the IPSec Keying Mode menu
General tab, select IKE using 3rd Party Certificates
Configuring a VPN Policy with IKE 3rd Party Certificate
225
226
227
228
Configuring Advanced VPN Settings
Advanced VPN Settings
VPN Advanced
VPN Advanced
VPN User Authentication Settings
VPN Bandwidth Management
Select Enable VPN Bandwidth Management
231
Configuring Advanced VPN Settings
Configuring Dhcp Over VPN
Dhcp Relay Mode
VPN Dhcp over VPN
VPN Dhcp over VPN
Configuring the Central Gateway for Dhcp Over VPN
Configuring Dhcp over VPN Remote Gateway
235
Click OK to exit the Dhcp over VPN Configuration window
Device Configuration
Current Dhcp over VPN Leases
Configuring L2TP Server Settings
VPN L2TP Server
VPN L2TP Server
237
IP Address Settings
L2TP Server Settings
Adding L2TP Clients to the SonicWALL
Currently Active L2TP Sessions
239
Configuring L2TP Server Settings
Managing Certificates
Digital Certificates Overview
SonicWALL Third-Party Digital Certificate Support
Digital Certificates Overview
Importing Certificate with Private Key
VPN Local Certificates
Certificate Details
Generating a Certificate Signing Request
Delete This Certificate
VPN Local Certificates
Select Add New Local Certificate from the Certificates menu
Importing CA Certificates into the SonicWALL
VPN CA Certificates
Select Add New CA Certificate
Automatic CRL Update
Certificate Revocation List CRL
Importing a CRL List
Click Browse for Please select a file to import
246
Users
247
248
User Level Authentication Overview
User Level Authentication Overview
Users Status
249
Authentication Method
Users Settings
Active User Sessions
Global User Settings
Internet Authentication Exclusions
Users Settings
251
Acceptable Use Policy
Select Use Radius for user authentication
Configuring Radius Authentication
253
254
255
256
Configuring Local Users
Users Local Users
Users Local Users
257
Adding a Local User
Security Services
259
260
SonicWALL Security Services
SonicWALL Security Services
MySonicWALL.com
Activating Free Trials
Security Services Summary
Security Services Summary Manage Licenses
Security Services Summary
263
Security Services Information
Security Services Settings
If Your SonicWALL Security Appliance is Not Registered
SonicWALL Content Filtering Service
SonicWALL Content Filtering Service
265
Content Filter Status
Security Services Content Filter
Activating SonicWALL Content Filtering Service
Security Services Content Filter
Activating a SonicWALL Content Filtering Service
267
Content Filter Type
Restrict Web Features
Configuring SonicWALL Filter Properties
Message to Display when Blocking
Configuring SonicWALL Filter Properties
Trusted Domains
Allowed/Forbidden Domains
Custom List
Keyword Blocking
Disable all Web traffic except for Allowed Domains
271
Consent
Mandatory Filtered IP Addresses
Consent Page URL mandatory filtering
Adding a New Address
273
274
SonicWALL Network Anti-Virus Overview
SonicWALL Network Anti-Virus Overview
275
Security Services Anti-Virus
Activating SonicWALL Network Anti-Virus
Activating a SonicWALL Network Anti-Virus Free Trial
Security Services Anti-Virus
277
Security Services E-Mail Filter
Configuring SonicWALL Network Anti-Virus
Managing SonicWALL Gateway Anti-Virus Service
SonicWALL Gateway Anti-Virus Overview
SonicWALL Gateway Anti-Virus Overview
279
SonicWALL Gateway Anti-Virus/Intrusion Prevention Features
Activating SonicWALL Gateway Anti-Virus
281
Activating SonicWALL Gateway Anti-Virus
Activating the SonicWALL Gateway Anti-Virus
Configuring SonicWALL Gateway Anti-Virus
Configuring SonicWALL Gateway Anti-Virus
283
284
Managing SonicWALL Intrusion Prevention Service
SonicWALL Intrusion Prevention Service
SonicWALL IPS Features
SonicWALL Intrusion Prevention Service
SonicWALL Deep Packet Inspection
How SonicWALL’s Deep Packet Inspection Architecture Works
287
Security Services Intrusion Prevention
Activating SonicWALL IPS
Activating the SonicWALL IPS Free Trial
Security Services Intrusion Prevention
289
290
Managing SonicWALL Global Security Client
SonicWALL Global Security Client
SonicWALL Global Security Client
291
How SonicWALL Global Security Client Works
Global Security Client Features
SonicWALL Global Security Client Activation
Activating SonicWALL Global Security Client
293
294
Log
295
296
Viewing Log Events
SonicOS Log Event Messages Overview
SonicOS Log Event Messages Overview
297
Log View
Navigating and Sorting Log View Table Entries
SonicOS Log Entries
Refresh
Clear Log
Mail Log
300
Log Categories
Specifying Log Categories
Log Categories
Alerts & Snmp Traps
Configuring Log Automation
Log Automation
Log Automation
303
Mail
Syslog Servers
305
306
Configuring Name Resolution
Log Name Resolution
Log Name Resolution
307
Name Resolution Method list, select
Selecting Name Resolution Settings
Specifying the DNS Server
Reset Data
Generating and Viewing Log Reports
Log Reports
Data Collection
Bandwidth Usage by Service
View Data
Web Site Hits
Bandwidth Usage by IP Address
Log ViewPoint
SonicWALL ViewPoint
Log ViewPoint
311
Generating and Viewing Log Reports
SonicSetup
SonicSetup
313
Introduction and Discovery
Device Selection
Diagnostics
Diagnostics
315
SonicROM Recovery
Diagnostic Results
SonicOS Recovery
SonicOS Recovery
317
Restoring Factory Defaults
Address Synchronization
Address Synchronization
319
320
SonicWALL SafeMode
SonicWALL SafeMode
321
322
Upgrading SonicOS Firmware
Upgrading SonicOS Firmware
323
324
Index
Numerics
326
VPN
327
WPA, see WiFiSec Protected Access
232- 000609- 00 Rev E 02/05
Top
Page
Image
Contents