Manuals
/
WatchGuard Technologies
/
Computer Equipment
/
Network Router
WatchGuard Technologies
FireboxTM System 4.6
manual
Service precedence
Models:
FireboxTM System 4.6
1
68
170
170
Download
170 pages
21.61 Kb
65
66
67
68
69
70
71
72
Install
Setting the default gateway
Connecting to a Firebox
Opening a configuration file
Known issues
Resetting Firebox passphrases
Adding remote access users
Select Setup =Time Zone
Setting privileges
What is
Page 68
Image 68
Service precedence
58
Page 67
Page 69
Page 68
Image 68
Page 67
Page 69
Contents
WatchGuard Firebox System User Guide
Disclaimer
Copyright and Patent Information
WatchGuard Firebox System WFS End-User License Agreement
Page
Declaration of Conformity
Watchguard
CSA Statement
FCC Certification
CE Notice
Table of Contents
Using the WatchGuard Control Center
Setting Up Network Address Translation
149
WatchGuard Firebox System components
Part I Introduction
Welcome to WatchGuard
WatchGuard security suite
WatchGuard Firebox
WatchGuard Control Center
LiveSecurity Service
Minimum requirements
Software requirements
Web browser requirements
Hardware requirements
CPU
Part II WatchGuard Services
LiveSecurity Service
WatchGuard Optional Features
Technical Support
Page
LiveSecurity Service
Software Update
LiveSecurity broadcasts
Information Alert
Activating the LiveSecurity Service
Editorial
Support Flash
Virus Alert
Minimize or close your Web browser
LiveSecurity broadcasts
Accessing frequently asked questions FAQ
Technical Support
Known issues
Click the LSS/SOHO Known Issues link on the left
Getting Internet technical support
Getting telephone support
Training
WatchGuard Interactive Training System Wits
Instructor-led courses
WatchGuard users group
Online Help
Starting WatchGuard Online Help
Searching for topics
Copying the Help system to additional platforms
Online Help system requirements
Context-sensitive Help
WatchGuard Options
Currently available options
VPN Manager
High Availability
SpamScreen
Obtaining WatchGuard options
Mobile User VPN
Part III Configuring a Security Policy
Connect with out-of-band management
Set up network address translation NAT
Set up logging and notification
What is a Firebox?
Firebox Basics
Placing a Firebox within a network
Opening a configuration file
Saving a configuration file
Opening a configuration from the Firebox
Opening a configuration from a local hard disk
Resetting Firebox passphrases
Saving a configuration to the local hard disk
Saving a configuration to the Firebox
Tips for creating secure passphrases
Setting the time zone
Reinitializing a misconfigured Firebox
Select Setup =Time Zone
Reinitialize the Firebox using the QuickSetup wizard
Booting from the system area
Using the WatchGuard Control Center
Starting the Control Center and connecting to a Firebox
Navigating the WatchGuard Control Center
Control Center components
Firebox and VPN tunnel status
QuickGuide
Front panel
IPSec
Remote VPN tunnels
Expanding and collapsing the display
Red exclamation point
Connecting to a Firebox
Setting the maximum number of log messages
Working with the Control Center
Traffic Monitor
Opening WatchGuard Firebox System tools
Policy Manager
Manipulating the Traffic Monitor
Changing the Policy Manager view
Firebox Monitors
LogViewer
LiveSecurity Event Processor
HostWatch
Historical Reports
LiveSecurity Event Processor
Configuring a Network
Running the QuickSetup wizard
Trusted
External
Setting up a drop-in network
Setting up a routed network
Select Network = Configuration
Adding a secondary network
Defining a network route
Select Network = Routes
Setting the default gateway
Select Network = Default Gateway
Defining a host route
Changing an interface IP address
Select Network = Configuration. Click the General tab
Select Network = Configuration. Click the Dhcp Server tab
Entering Wins and DNS server addresses
Defining a Firebox as a Dhcp server
Click the subnet to remove it. Click Remove Click OK
Modifying an existing subnet
Removing a Subnet
Defining a Firebox as a Dhcp server
Blocking Sites and Ports
Configuring default packet handling
Select Setup = Default Packet Handling
Blocking a site permanently
Removing a blocked site
Changing the auto-block duration
Logging and notification for blocked sites
Blocking a port permanently
Removing a blocked port
Logging and notification for blocked ports
Category list, click Blocked Sites
Viewing the Blocked Sites list
Blocking sites temporarily with service settings
Configuring a service to temporarily block sites
Click OK to close the Properties dialog box
Configuring Services
Adding an existing service
Creating a new service
Ignore
Secure
Port
Defining service properties
Adding incoming service properties
Working with wg icons
Adding outgoing service properties
Adding addresses to service properties
Configuring services for authentication
Modifying a service
Deleting a service
Under Internal Hosts, click Add
Setting up proxy services
Configuring an Smtp proxy service
Configuring the incoming Smtp proxy
Click Yes
Selecting content types
Adding address patterns
Protecting your mail server against relaying
Select headers to allow
Configuring an FTP proxy service
Configuring the outgoing Smtp proxy
Click Outgoing
Add masquerading options
Configuring an Http proxy service
Service precedence
From Rank Any List
Service precedence
Reverting to old WebBlocker databases
Controlling Web Traffic
How WebBlocker works
Configuring the WebBlocker service
Prerequisites to using WebBlocker
Logging and WebBlocker
Activating WebBlocker
Setting privileges
Scheduling operational and non-operational hours
Creating WebBlocker exceptions
Click the WebBlocker Controls tab
Manually downloading the WebBlocker database
Debug- Outputs debugging information
Setting Up Network Address Translation
What is dynamic NAT?
Using simple dynamic NAT
Select Setup = NAT
Enabling simple dynamic NAT
Adding dynamic NAT entries
Configuring service-based NAT exceptions
Using service-based NAT
Enabling service-based NAT
Configuring a service for incoming static NAT
Setting static NAT for a service
Select Network = Configuration. Click the External tab
Adding external IP addresses
Click OK to close the Add Static NAT dialog box
Enter the internal IP address
Checkbox
Configuring a service for incoming static NAT
Setting Up Logging Notification
Ensure logging with failover logging
LiveSecurity Event Processor
WatchGuard logging architecture
Designating Event Processors for a Firebox
Editing an Event Processor setting
Select Setup = Logging
Adding an Event Processor
Enabling Syslog logging
Removing an Event Processor
Reordering Event Processors
Synchronizing Event Processors
For Windows NT Event Processors
Setting up the LiveSecurity Event Processor
Installing the Event Processor program
Running an Event Processor on Windows
Running an Event Processor on Windows NT or Windows
As a Windows NT or Windows 2000 Service
Interactive mode from a DOS window
Viewing the Event Processor
Click WG LiveSecurity Event Processor. Click Startup
Setting global logging and notification preferences
Setting the log encryption key
Setting the interval for log rollover
Starting and stopping the Event Processor
Customizing logging and notification by service or option
Scheduling log reports
Controlling notification
Category
Setting logging and notification for a service
Setting Launch Interval and Repeat Count
Setting logging and notification for blocked sites and ports
Select Setup = Blocked Sites
Enabling the Management Station
Connecting a Firebox with OOB management
Connect with Out-of-Band Management
Install the modem
Configure the dial-up connection
Preparing a Windows NT Management Station for OOB
Preparing a Windows 95/98 Management Station for OOB
Configuring the Firebox for OOB
Select Network = Configuration. Click the OOB tab
Configuring PPP for connecting to a Firebox
Establishing an OOB connection
Establishing an OOB connection
Part IV Administering a Security Policy
Aliases and Authentication
Firebox Activity Monitors
Network Activity Reports
Page
Creating Aliases Implementing Authentication
Using host aliases
Removing a host alias
Adding a host alias
Modifying a host alias
How user authentication works
What is user authentication?
User authentication types
Configuring Firebox authentication
Configuring Windows NT Server authentication
Under Authentication Enabled Via, click the Firebox option
To close the Setup Remote User dialog box, click Close
Configuring Radius server authentication
Click the Windows NT Server tab
Configuring CRYPTOCard server authentication
Enter the administrator password
On the Radius Server
Enter or accept the time-out in seconds
Configuring SecurID authentication
Using authentication to define remote user VPN access
Example Configuring a service for Remote User VPN
Starting Firebox Monitors and connecting to a Firebox
Monitoring Firebox Activity
Setting Firebox Monitors view properties
ServiceWatch
Bandwidth Meter
StatusReport
Network configuration
Packet counts
Log and notification hosts
Blocked Sites list
Authentication host information
Logging options
Memory
Load average
Interface the Firebox uses for each destination address
Interfaces
Routes
ARP table
Authentication list
Blocked Sites list
Replaying a log file
HostWatch display
Select File = Connect
Select File = Open
Viewing authenticated users
Controlling the HostWatch display
Viewing specific hosts
Viewing specific ports
Modifying view properties
Add
HostWatch 102
Setting LogViewer preferences
Reviewing and Working with Log Files
Viewing files with LogViewer
Starting LogViewer and opening a log file
Searching for specific entries
Copying and exporting LogViewer data
Displaying and hiding fields
Working with log files
Consolidating logs from multiple locations
Setting log encryption keys
Copying log files
Forcing the rollover of log files
From LiveSecurity Event Processor
Working with log files 108
Generating Reports of Network Activity
Starting Historical Reports
Creating and editing reports
Viewing the reports list
Specifying report sections
Creating a new report
Editing an existing report
Deleting a report
Consolidating report sections
Setting report properties
Specifying a report time span
Exporting reports
Exporting reports to Html format
Exporting a report to WebTrends for Firewalls and VPNs
Enter the number of elements to rank in the table
Creating a new filter
Using report filters
Exporting a report to a text file
Scheduling and running reports
Editing a filter
Deleting a filter
Applying a filter
Report sections and consolidated sections
Manually running a report
Session Summary Packet Filtered
Time Summary Proxied Traffic
Host Summary Proxied Traffic
Proxy Summary
Consolidated Sections
118
Remote user virtual private network
Part V WatchGuard Virtual Private Networking
Branch office virtual private network
120
Configuring Branch Office Virtual Private Networking
Configuration checklist
Using Dvcp to connect to devices
How does Dvcp work?
Basic and Enhanced Dvcp
Creating a tunnel to a Soho or SOHOtc
Editing a tunnel to a device
Select Network = Branch Office VPN = Basic Dvcp
Telecommuter IP Address
Soho Private Network
Branch office VPN with IPSec
Removing a tunnel to a device
Defining a Firebox as an Enhanced Dvcp Client
Select the tunnel policy. Click Edit
Configuring a gateway
Select Network = Branch Office VPN = IPSec
Adding a gateway
Click Gateways
Configuring a tunnel with manual security
Incoming Settings for Outgoing checkbox
Using Encapsulated Security Protocol ESP
Removing a gateway
Configuring a tunnel with dynamic security
Using Authenticated Headers AH
Click Key. Enter a passphrase. Click OK
Click the Dynamic Security tab
Creating an IPSec policy
Block
Bypass
Dst Port field, enter the remote host port
Configuring services for branch office VPN with IPSec
Changing IPSec policy order
Src Port field, enter the local host port
Incoming
Configuring WatchGuard VPN
WatchGuard VPN configuration models
Setting up WatchGuard VPN
Allow VPN access to any services
Enable the Activate WatchGuard VPN checkbox
Changing remote network entries
Preventing IP spoofing with WatchGuard VPN
Enter the encryption key. Click Make Key
Configuring incoming services to allow VPN
Verifying successful WatchGuard VPN configuration
Mobile User VPN
Configuring the Firebox for Remote User VPN
Remote User Pptp
Adding a member to built-in Ruvpn user groups
Configuring shared servers for Ruvpn
Adding remote access users
Using the Any service
Configuring services to allow incoming Ruvpn
By individual service
Configuring the Firebox for Remote User Pptp
Activating Remote User Pptp
Entering IP addresses for Remote User sessions
Select Network = Remote User. Click the Pptp tab
Rules for valid Remote User Pptp addresses
Configuring the Firebox for Mobile User VPN
Purchasing a Mobile User VPN license
Preparing Mobile User VPN configuration files
Entering license keys
Defining a new mobile user
Select Network = Remote User. Click the Mobile User VPN tab
Saving the configuration to a Firebox
Distributing the software and configuration files
Modifying an existing Mobile User VPN entry
Select Network = Remote User
Debugging Remote User VPN Pptp
Configuring debugging options
Debugging Mobile User VPN
Preparing a Host for Remote User VPN
Preparing the client computers
Click the Identification tab
Remote host operating system
Windows 95/98 platform preparation
Windows NT platform preparation
Installing Client for Microsoft Networks
Installing Dial-Up Adapter #2 VPN Support
Setting up Ruvpn for Windows
Click Dial Out Only. Click Continue
Adding a domain name to a Windows NT workstation
Select Computer Browser
Configuring the remote host for Ruvpn with Pptp
Installing a VPN adapter on Windows 95/98
Initial Connection window that appears, click Yes
Click Obtain an IP Address Automatically. Click OK
Starting Remote User Pptp
Using Remote User Pptp
Installing a VPN adapter on Windows NT
Enter the remote client username and password
Running Remote User Pptp
Double-click the Ruvpn connection
Click Connect
Configuring debugging options 148
Index
150
User Guide 151
152
User Guide 153
154
User Guide 155
156
User Guide 157
158
User Guide 159
160
Top
Page
Image
Contents