WatchGuard Firebox Soho User Guide
Following conventions are used in this guide
Using this Guide
FCC Certification
Certifications and Notices
CE Notice
Industry Canada
Vcci Notice Class a ITE
Declaration of Conformity
Watchguard Soho Software END-USER License Agreement
User Guide Vii
Viii WatchGuard Firebox Soho
Copyright, Trademark, and Patent Information
WatchGuard Firebox Soho
User Guide
Xii WatchGuard Firebox Soho
Contents
Configure the Network Interfaces
Configure the Firewall Settings
VPN-Virtual Private Networking
Index 117
Xviii WatchGuard Firebox Soho
Welcome
Introduction
Package Contents
How Does a Firewall Work?
IP addresses
How Does Information Travel on the Internet?
Protocol
How Does the Soho 6 Process Information?
Services
Port numbers
Network Address Translation
Soho 6 front and rear views
Soho 6 Hardware Description
Faster Processor
Ethernet ports
Link
Status
100
Mode
OPT port
Power input
Reset button
WAN port
Numbered ports
Introduction WatchGuard Firebox Soho
Installation
Click Start = Programs = Accessories = Command Prompt
Review and record your current TCP/IP settings
Before You Begin
Microsoft Windows 2000 and Windows XP
Microsoft Windows 95 or 98 or ME
Microsoft Windows NT
Macintosh
Other operating systems Unix, Linux
Exit the TCP/IP configuration screen
Disable the Http proxy setting of your Web browser
Click Edit = Preferences
Netscape
Click Start = Settings = Control Panel
Enable your computer for Dhcp
Internet Explorer 5.0, 5.5,
Click Tools = Internet Options
Click Properties
Physically connect the Soho
Cabling the Soho 6 for one to four appliances
Cabling the Soho 6 for more than four computers
Physically connect the Soho
Soho 6 is now connected to the Internet and your hub
Soho 6 Home Page-System Status
Soho 6 Basics
Soho 6 Basics
External Network
Default Factory Settings
Trusted Network
Firewall Settings
Reset a Soho 6 to factory default
Upgrade Options
System Security
Base model Soho
Register your Soho 6 and Activate the LiveSecurity Service
Reboot the Soho
Reboot the Soho
Soho 6 Basics WatchGuard Firebox Soho
Configure Your External Network
Configure Network Interfaces
Network addressing
Configure the Soho 6 External Network for dynamic addressing
Manual Configuration
Configure the Soho 6 External Network for static addressing
Network = External
Configure the Soho 6 External Network for PPPoE
Click Automatically restore lost connections
Configure Dhcp Server and Dhcp Relay
Configure the Trusted Network
Trusted Network Configuration page appears
Configure additional computers on the Trusted Network
Network = Trusted
Configure the Trusted Network with static addresses
Configure Static Routes
Click Add
Network = Network Statistics
View Network Statistics
Select the Enable Dynamic DNS client checkbox
Configure the Dynamic DNS Service
Network = DynamicDNS
Configure Dual ISP Port
Configure OPT Port Upgrades
Configure OPT Port Upgrades
Network = Dual ISP
Configure VPNforce Port
Network = Optional
Configure OPT Port Upgrades
Configure the Network Interfaces WatchGuard Firebox Soho
Administrative Options
System management
System Security
Administration = System Security
Soho Remote Management
Set up VPN Manager Access
Select Enable VPN Manager Access
Administration = VPN Manager Access
Administration = Update
Update Your Firmware
Redeem your Soho 6 Upgrade Options
Upgrade options
Administration = Upgrade
Seat Licenses
Dual ISP Port
LiveSecurity Service Subscription Renewals
VPNforce Port
IPSec Virtual Private Networking VPN
Administration = View Configuration File
View the Configuration File
Firewall Settings
Configure Firewall Settings
Pre-configured Services
Configure Incoming and Outgoing Services
Firewall = Incoming or Outgoing
Create a Custom Service
Custom Service page refreshes
Firewall = Custom Service
Block External Sites
Blocked Sites page appears
Firewall = Firewall Options
Firewall Options
Select Do not allow FTP access to Trusted Network
Denying FTP access to the Trusted Network interface
Ping requests received on the External Network
Socks implementation for the Soho
Configuring your Socks application
Disabling Socks on the Soho
Logging all allowed outbound traffic
Select Log All Allowed Outbound Access
Enable override MAC address for the External Network
Select Enable override MAC address for the External Network
Create an Unrestricted Pass Through
Select Enable pass through address
Firewall = Pass Through
Create an Unrestricted Pass Through
Configure the Firewall Settings WatchGuard Firebox Soho
Configure Logging
From the navigation bar on the left side, select Logging
View Soho 6 Log Messages
To have your log messages synchronize with your computer
Select Enable WatchGuard Security Event Processor Logging
Select Enable syslog output
Set up Logging to a Syslog Host
Logging = Syslog Logging
Select Include local time in syslog message
Set the System Time
Select a time zone from the drop list
Select Adjust for daylight savings time
Configure Logging WatchGuard Firebox Soho
VPN-Virtual Private Networking
Why Create a Virtual Private Network?
What You Need
IP Address Table example
Enable the VPN Upgrade
Why do I need a static external address?
Frequently Asked Questions
Special Considerations
How do I get a static external IP address?
How do I obtain a VPN upgrade license key?
Why is ping not working?
How do I enable a VPN Tunnel?
How do I troubleshoot the connection?
VPN = Manual VPN
Set Up Multiple SOHO-SOHO VPN Tunnels
Enter the Name, IPSec Gateway Address, and Shared Key for
Soho 6 you want to set up a VPN tunnel
Set Up Multiple SOHO-SOHO VPN Tunnels
Forward Secrecy
Muvpn Clients
Configure Split Tunneling
Statistics
View the VPN Statistics
How WebBlocker Works
Soho 6 WebBlocker
Web site in the WebBlocker database
Web site not in the WebBlocker database
WatchGuard WebBlocker database unavailable
WebBlocker users and groups
Purchase and Activate Soho 6 WebBlocker
Bypass the Soho 6 WebBlocker
Groups
WebBlocker = Settings
Configure the Soho 6 WebBlocker
Activate WebBlocker
Create WebBlocker Groups and Users
Select Enable WebBlocking
Click New to create a group name and profile
Click Submit
To the right of the Users field, click New
Alcohol/tobacco
WebBlocker Categories
Illegal Gambling
Drug Culture
Militant/extremist
Satanic/cult
Intolerance
Violence/profanity
Gross Depictions
Search Engines
Sports and Leisure
Full Nudity
Sexual Acts
Partial/artistic Nudity
Support Resources
Troubleshooting Tips
General
How do I restart my Soho 6?
How do I register my Soho 6 with the LiveSecurity Service?
Cant get a certain Soho 6 feature to work with a DSL modem
What is a Soho 6 Feature Key?
How does the seat limitation on the Soho 6 work?
110
Where are the Soho 6 settings stored?
Configuration
How do I set up Dhcp on the trusted network of the Soho 6?
Select Enable Dhcp Server and then click Submit
How do I set up and disable Webblocker?
Disable Enable Dhcp Server and then click Submit
How do I change to a static, trusted IP address?
Firewall = Incoming
VPN Management
How do I set up VPN to a Soho 6s?
How do I set up my Soho 6 for VPN Manager Access?
Contact Technical support
Online Documentation and In-Depth FAQs
Numerics
Index
WAN
Socks
Redeeming 57 types Upgrade page 58 upgrading
Processor WebBlocker
122