Waters Network Systems ProSwitch-Quad Series Especificações

Consulte online ou descarregue Especificações para Comutadores de rede Waters Network Systems ProSwitch-Quad Series. Waters Network Systems ProSwitch-Quad Series Specifications Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 0
350 East Plumeria Drive
San Jose, CA 95134
USA
April 2013
202-10536-05
ProSAFE Gigabit Quad WAN SSL
VPN Firewall SRX5308
Reference Manual
Vista de página 0
1 2 3 4 5 6 ... 468 469

Resumo do Conteúdo

Página 1 - VPN Firewall SRX5308

350 East Plumeria DriveSan Jose, CA 95134USAApril 2013202-10536-05ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Reference Manual

Página 2 - Revision History

10ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN to DMZ Logs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44

Página 3

LAN Configuration100ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 56. 2. Modify the settings as described in Table 17 on page 98.3. Clic

Página 4 - Contents

LAN Configuration101 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 57. 3. Select the radio button next to the group name that you want to c

Página 5 - Chapter 3 LAN Configuration

LAN Configuration102ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: The saved binding is also displayed on the IP/MAC Binding screen (see Figu

Página 6

LAN Configuration103 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCPv6 Server OptionsThe IPv6 clients in the LAN can autoconfigure their own IPv

Página 7

LAN Configuration104ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Stateful DHCPv6 ServerThe IPv6 clients in the LAN obtain an interface IP address

Página 8 - Chapter 10 Troubleshooting

LAN Configuration105 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Enter the settings as described in the following table. The IPv6 address pool

Página 9

LAN Configuration106ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your changes.IPv6 LAN Address PoolsIf you configure a sta

Página 10

LAN Configuration107 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 59. 2. Enter the settings as described in the following table:3. Click A

Página 11 - Introduction

LAN Configuration108ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Delegation table to enable the DHCPv6 server to assign these prefixes to its IPv

Página 12 - Key Features and Capabilities

LAN Configuration109 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the IPv6 Router Advertisement Daemon and Advertisement Prefixes for th

Página 13 - Balancing

1111. IntroductionThis chapter provides an overview of the features and capabilities of the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 and ex

Página 14

LAN Configuration110ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To configure the Router Advertisement Daemon for the LAN:1. Select Network Con

Página 15 - Extensive Protocol Support

LAN Configuration111 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Advertisement Prefixes for the LANYou need t

Página 16

LAN Configuration112ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 62. 2. Enter the settings as described in the following table:3. Click A

Página 17 - Hardware Features

LAN Configuration113 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. To delete one or more advertisement prefi

Página 18 - Table 1. LED descriptions

LAN Configuration114ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. In the Add Secondary LAN IP Address section of the screen, enter the followin

Página 19 - Rear Panel

LAN Configuration115 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308By default, the DMZ port and both inbound and outbound DMZ traffic are disabled.

Página 20 - Figure 3

LAN Configuration116ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 64. 2. Enter the settings as described in the following table: Table 23.

Página 21 - Log In to the VPN Firewall

LAN Configuration117 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCP for DMZ Connected ComputersDisable DHCP Server If another device on your ne

Página 22 - Figure 5

LAN Configuration118ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.DMZ Port for IPv6 TrafficThe DMZ Setup (IPv

Página 23

LAN Configuration119 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308For the DMZ, there are two DHCPv6 server options:• Stateless DHCPv6 server. The

Página 24 - Figure 8

Introduction12ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 What Is the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308?The ProSAFE Gigabit Quad

Página 25 - Figure 9

LAN Configuration120ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Enter the settings as described in the following table: Table 24. DMZ Setup

Página 26 - Settings

LAN Configuration121 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.IPv6 DMZ Address PoolsIf you configure a st

Página 27 -  Complete these tasks:

LAN Configuration122ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Enter the settings as described in the following table:3. Click Apply to save

Página 28

LAN Configuration123 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Hosts and routers in the LAN use NDP to determine the link-layer addresses and r

Página 29

LAN Configuration124ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 67. 4. Enter the settings as described in the following table:Table 27.

Página 30 - Classical Routing

LAN Configuration125 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Advertisement Prefixes for the DMZYou need t

Página 31 - Figure 11

LAN Configuration126ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 68. 2. Enter the settings as described in the following table:3. Click A

Página 32 - Figure 12

LAN Configuration127 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. To delete one or more advertisement prefi

Página 33

LAN Configuration128ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Click the Add table button under the Static Routes table. The Add Static Rout

Página 34 - Figure 14

LAN Configuration129 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308displays. This screen is identical to the Add Static Route screen (see the previ

Página 35 - Figure 15

Introduction13 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The VPN firewall provides the following key features and capabilities:• Four 10/100/10

Página 36 - Figure 16

LAN Configuration130ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Enter the settings as described in the following table: Table 30. RIP Config

Página 37 - Figure 17

LAN Configuration131 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.IPv4 Static Route ExampleIn this example, w

Página 38 - Figure 18

LAN Configuration132ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage Static IPv6 RoutingNETGEAR’s implementation of IPv6 does not support RIP

Página 39 - Figure 19

LAN Configuration133 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Enter the settings as described in the following table: 5. Click Apply to sav

Página 40 - Interfaces

13444. Firewall ProtectionThis chapter describes how to use the firewall features of the VPN firewall to protect your network. The chapter contains

Página 41 - IPv4 Interfaces

Firewall Protection135 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308About Firewall ProtectionA firewall protects one network (the trusted network,

Página 42 - Figure 21

Firewall Protection136ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Overview of Rules to Block or Allow Specific Kinds of Traffic• Outbound Rules

Página 43 - Figure 22

Firewall Protection137 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Bandwidth profiles. After you have a configured a bandwidth profile (see Cre

Página 44 -  To edit a protocol binding:

Firewall Protection138ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Select Schedule The time schedule (that is, Schedule1, Schedule2, or Schedule

Página 45

Firewall Protection139 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308QoS Profile or QoS PriorityThe priority assigned to IP packets of this service

Página 46 - Figure 24

Introduction14ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Advanced VPN Support for Both IPSec and SSLThe VPN firewall supports IPSec and SSL vir

Página 47

Firewall Protection140ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Inbound Rules (Port Forwarding)If you have enabled Network Address Translation

Página 48

Firewall Protection141 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: When the Block TCP Flood and Block UDP Flood check boxes are selected on

Página 49 - Configure Dynamic DNS

Firewall Protection142ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Send to LAN Server The LAN server address determines which computer on your ne

Página 50 -  To configure DDNS:

Firewall Protection143 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WAN Users The settings that determine which Internet locations are covered by

Página 51 - Figure 27

Firewall Protection144ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Some residential broadband ISP accounts do not allow you to run any serv

Página 52

Firewall Protection145 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308For any traffic attempting to pass through the firewall, the packet informatio

Página 53

Firewall Protection146ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To change an existing outbound or inbound service rule, in the Action column t

Página 54 - Figure 28

Firewall Protection147 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To enable, disable, or delete one or more IPv4 or IPv6 rules:1. Select the c

Página 55 - Connection

Firewall Protection148ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 77. 2. Enter the settings as described in Table 33 on page 137. In a

Página 56 - Figure 30

Firewall Protection149 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 78. 3. Enter the settings as described in Table 33 on page 137. In a

Página 57 - Figure 31

Introduction15 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Security FeaturesThe VPN firewall is equipped with several features designed to mainta

Página 58 - Figure 32

Firewall Protection150ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IPv4 LAN WAN Inbound Service Rules To create an IPv4 LAN WAN inbound rule:1.

Página 59 - Figure 33

Firewall Protection151 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following configurations are optional:• Translate to Port Number• QoS Prof

Página 60 - Figure 34

Firewall Protection152ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure DMZ WAN Rules• Create DMZ WAN Outbound Service Rules• Create LAN WAN

Página 61 - Figure 35

Firewall Protection153 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To change an existing outbound or inbound service rule, in the Action column t

Página 62 - Figure 36

Firewall Protection154ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To enable, disable, or delete one or more IPv4 or IPv6 rules:1. Select the c

Página 63

Firewall Protection155 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in Table 33 on page 137. In addition to s

Página 64

Firewall Protection156ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Unless your selection from the Action drop-down list is BLOCK always, you also

Página 65 - Figure 37

Firewall Protection157 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in Table 34 on page 141. In addition to s

Página 66 - Figure 39

Firewall Protection158ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Unless your selection from the Action drop-down list is BLOCK always, you also

Página 67 - Figure 40

Firewall Protection159 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To change an existing outbound or inbound service rule, in the Action column t

Página 68 - Figure 41

Introduction16ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • DNS proxy. When DHCP is enabled and no DNS addresses are specified, the VPN firewall

Página 69 - Figure 42

Firewall Protection160ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Click one of the following table buttons:• Enable. Enables the rule or rule

Página 70 - Figure 43

Firewall Protection161 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Unless your selection from the Action drop-down list is BLOCK always, you also

Página 71 - Figure 44

Firewall Protection162ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create LAN DMZ Inbound Service RulesThe Inbound Services table lists all exist

Página 72 - Figure 45

Firewall Protection163 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6 LAN DMZ Inbound Service Rules To create an IPv6 LAN DMZ inbound rule:1.

Página 73 - Figure 46

Firewall Protection164ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Examples of Firewall Rules• Examples of Inbound Firewall Rules• Examples of Ou

Página 74

Firewall Protection165 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 94. IPv4 LAN WAN or IPv4 DMZ WAN Inbound Rule: Set Up One-to-One NAT Ma

Página 75

Firewall Protection166ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: If you arrange with your ISP to have more than one public IP address for

Página 76 - Configure WAN QoS Profiles

Firewall Protection167 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308this address on the WAN2 Secondary Addresses screen (see Configure Secondary W

Página 77 - Figure 47

Firewall Protection168ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:For security, NETGEAR strongly recommends that you avoid creating an e

Página 78 - Figure 48

Firewall Protection169 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 98. IPv6 DMZ WAN Outbound Rule: Allow a Group of DMZ User to Access an

Página 79

Introduction17 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Maintenance and SupportNETGEAR offers the following features to help you maximize your

Página 80 - Figure 49

Firewall Protection170ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure Other Firewall Features• Attack Checks• Set Limits for IPv4 Sessions

Página 81

Firewall Protection171 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:Table 35. Attack Ch

Página 82 - What to Do Next

Firewall Protection172ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.IPv6 Attack Checks To enable IPv6 attack

Página 83

Firewall Protection173 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Set Limits for IPv4 SessionsThe session limits feature allows you to specify t

Página 84

Firewall Protection174ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings.Configure Multicast Pass-Through for IPv4

Página 85 - Port-Based VLANs

Firewall Protection175 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 103. 2. In the Multicast Pass through section of the screen, select th

Página 86 - Figure 50

Firewall Protection176ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To delete one or more multicast source addresses:1. In the Alternate Network

Página 87 - VLAN DHCP Options

Firewall Protection177 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• QoS profiles and priorities. A Quality of Service (QoS) profile defines the

Página 88 - Configure a VLAN Profile

Firewall Protection178ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 105. 2. In the Add Customer Service section of the screen, enter the s

Página 89 - Figure 52

Firewall Protection179 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 106. 2. Modify the settings that you wish to change (see the previous

Página 90

Introduction18ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The front panel also contains three groups of status indicator light-emitting diodes (

Página 91

Firewall Protection180ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the Add New Custom IP Group section of the screen, do the following:• In

Página 92

Firewall Protection181 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete an IP group:1. In the Custom IP Groups table, select the check box

Página 93

Firewall Protection182ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 109. 2. Under the List of Bandwidth Profiles table, click the Add tabl

Página 94

Firewall Protection183 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The new bandwidth profile is added to th

Página 95 - Figure 54

Firewall Protection184ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create Quality of Service Profiles for IPv4 Firewall RulesA Quality of Service

Página 96

Firewall Protection185 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 112. 3. Enter the settings as described in the following table.4. Clic

Página 97 - Manage the Network Database

Firewall Protection186ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit a QoS profile:1. In the List of QoS Profiles table, click the Edit t

Página 98

Firewall Protection187 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Several types of blocking are available:• Web component blocking. You can bloc

Página 99

Firewall Protection188ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • If the keyword “.com” is specified, only websites with other domain suffixes

Página 100 - Figure 56

Firewall Protection189 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. In the Web Components section of the screen, select the components that you

Página 101 - Figure 57

Introduction19 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Rear PanelThe rear panel of the VPN firewall includes a console port, a Factory Defaul

Página 102 - Manage the IPv6 LAN

Firewall Protection190ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To set a schedule:1. Select Security > Services > Schedule 1. The Sche

Página 103 - DHCPv6 Server Options

Firewall Protection191 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: For additional ways of restricting outbound traffic, see Outbound Rules

Página 104 - Configure the IPv6 LAN

Firewall Protection192ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:If you select Permit and Block the rest from the drop-down list but do

Página 105 - LAN Configuration

Firewall Protection193 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Host 2 has changed its MAC address to 00:01:02:03:04:09. The packet has an I

Página 106 - IPv6 LAN Address Pools

Firewall Protection194ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. In the IP/MAC Bindings sections of the screen, enter the settings as descri

Página 107 - Figure 59

Firewall Protection195 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click the Set Interval button. Wait for the confirmation that the operation

Página 108 -  To edit a prefix:

Firewall Protection196ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click the Add table button. The new IP/MAC rule is added to the IP/MAC Bind

Página 109

Firewall Protection197 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Port TriggeringPort triggering allows some applications running on a

Página 110 - Figure 61

Firewall Protection198ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 120. 2. In the Add Port Triggering Rule section, enter the settings as

Página 111

Firewall Protection199 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To remove one or more port triggering rules from the table:1. Select the che

Página 112 - Figure 62

2ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SupportThank you for selecting NETGEAR products. After installing your device, locate the serial nu

Página 113 - Default VLAN

Introduction20ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Factory Defaults Reset button. Using a sharp object, press and hold this button for

Página 114

Firewall Protection200ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The UPnP Portmap Table in the lower part of the screen shows the IP addresses

Página 115 - DMZ Port for IPv4 Traffic

20155. Virtual Private Networking Using IPSec and L2TP ConnectionsThis chapter describes how to use the IP security (IPSec) virtual private networ

Página 116 - Figure 64

Virtual Private Networking Using IPSec and L2TP Connections202ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Considerations for Dual WAN Port Syste

Página 117

Virtual Private Networking Using IPSec and L2TP Connections203 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table summarizes the WAN

Página 118 - DMZ Port for IPv6 Traffic

Virtual Private Networking Using IPSec and L2TP Connections204ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv4 Gateway-to-Gateway VPN

Página 119 - Figure 65

Virtual Private Networking Using IPSec and L2TP Connections205 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To view the wizard default settings, c

Página 120

Virtual Private Networking Using IPSec and L2TP Connections206ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: To ensure that tunnels stay activ

Página 121 - IPv6 DMZ Address Pools

Virtual Private Networking Using IPSec and L2TP Connections207 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 128. 4. Configure a VPN policy

Página 122

Virtual Private Networking Using IPSec and L2TP Connections208ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv6 Gateway-to-Gateway VPN

Página 123

Virtual Private Networking Using IPSec and L2TP Connections209 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To view the wizard default settings, c

Página 124 - Figure 67

Introduction21 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Use the Rack-Mounting KitUse the mounting kit for the VPN firewall to install the appl

Página 125

Virtual Private Networking Using IPSec and L2TP Connections210ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: To ensure that tunnels stay activ

Página 126 - Figure 68

Virtual Private Networking Using IPSec and L2TP Connections211 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 133. 5. Configure a VPN policy

Página 127 - Manage Static IPv4 Routing

Virtual Private Networking Using IPSec and L2TP Connections212ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv4 Client-to-Gateway VPN T

Página 128 - Figure 70

Virtual Private Networking Using IPSec and L2TP Connections213 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 136. To display the wizard def

Página 129 - Figure 71

Virtual Private Networking Using IPSec and L2TP Connections214ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.

Página 130

Virtual Private Networking Using IPSec and L2TP Connections215 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 137. Note: When you are using

Página 131 - IPv4 Static Route Example

Virtual Private Networking Using IPSec and L2TP Connections216ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Perform these tasks from a compu

Página 132 - Manage Static IPv6 Routing

Virtual Private Networking Using IPSec and L2TP Connections217 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 139. 3. Select the A router or

Página 133

Virtual Private Networking Using IPSec and L2TP Connections218ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 141. 6. This screen is a summa

Página 134 - Firewall Protection

Virtual Private Networking Using IPSec and L2TP Connections219 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308c. Specify the settings that are descr

Página 135 - About Firewall Protection

Introduction22ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: The VPN firewall factory default IP address is 192.168.1.1. If you change the IP

Página 136

Virtual Private Networking Using IPSec and L2TP Connections220ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 143. b. Specify the default li

Página 137

Virtual Private Networking Using IPSec and L2TP Connections221 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the Authentication Settings

Página 138

Virtual Private Networking Using IPSec and L2TP Connections222ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: This is the name for the authen

Página 139

Virtual Private Networking Using IPSec and L2TP Connections223 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to use the new settings

Página 140

Virtual Private Networking Using IPSec and L2TP Connections224ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 8. Click Apply to use the new settings

Página 141

Virtual Private Networking Using IPSec and L2TP Connections225 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 148. 3. Specify the settings t

Página 142

Virtual Private Networking Using IPSec and L2TP Connections226ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to use the new settings

Página 143

Virtual Private Networking Using IPSec and L2TP Connections227 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Test the Connection and View Connectio

Página 144 - Order of Precedence for Rules

Virtual Private Networking Using IPSec and L2TP Connections228ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 151. • Use the system-tray ico

Página 145 - Configure LAN WAN Rules

Virtual Private Networking Using IPSec and L2TP Connections229 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308NETGEAR VPN Client Status and Log Info

Página 146 - Figure 76

Introduction23 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Login. The web management interface displays, showing the Router Status scree

Página 147 - IPv4 LAN WAN Outbound Rules

Virtual Private Networking Using IPSec and L2TP Connections230ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The Active IPSec SA(s) table lists eac

Página 148 - IPv6 LAN WAN Outbound Rules

Virtual Private Networking Using IPSec and L2TP Connections231 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Manage IPSec VPN Policies• Manage IKE

Página 149 - Figure 78

Virtual Private Networking Using IPSec and L2TP Connections232ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 158. Each policy contains the d

Página 150 - Figure 79

Virtual Private Networking Using IPSec and L2TP Connections233 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: You cannot delete or edit an IKE

Página 151 - IPv6 LAN WAN Inbound Rules

Virtual Private Networking Using IPSec and L2TP Connections234ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Complete the settings as described

Página 152 - Configure DMZ WAN Rules

Virtual Private Networking Using IPSec and L2TP Connections235 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Identifier From the drop-down list, se

Página 153 - Figure 82

Virtual Private Networking Using IPSec and L2TP Connections236ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Authentication Method Select one of th

Página 154 - Figure 83

Virtual Private Networking Using IPSec and L2TP Connections237 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings.

Página 155 - Figure 84

Virtual Private Networking Using IPSec and L2TP Connections238ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your changes. T

Página 156 - Figure 85

Virtual Private Networking Using IPSec and L2TP Connections239 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 160. Each policy contains the d

Página 157 - Figure 86

Introduction24ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The web management interface menu consists of the following components:• 1st level: Ma

Página 158 - Configure LAN DMZ Rules

Virtual Private Networking Using IPSec and L2TP Connections240ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 For information about how to add or ed

Página 159 - Figure 88

Virtual Private Networking Using IPSec and L2TP Connections241 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 162. Add New VPN Policy screen

Página 160 - Figure 89

Virtual Private Networking Using IPSec and L2TP Connections242ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Policy Type From the drop-down list, s

Página 161 - Figure 90

Virtual Private Networking Using IPSec and L2TP Connections243 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Traffic SelectionLocal IP From the dro

Página 162 - Figure 91

Virtual Private Networking Using IPSec and L2TP Connections244ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Key-Out The encryption key for the out

Página 163 - Figure 92

Virtual Private Networking Using IPSec and L2TP Connections245 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings.

Página 164 - Examples of Firewall Rules

Virtual Private Networking Using IPSec and L2TP Connections246ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 requesting individual authentication i

Página 165 - Figure 94

Virtual Private Networking Using IPSec and L2TP Connections247 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. In the Extended Authentication sect

Página 166 - Figure 95

Virtual Private Networking Using IPSec and L2TP Connections248ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 name and password information. The gat

Página 167 - Figure 96

Virtual Private Networking Using IPSec and L2TP Connections249 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.N

Página 168 - Figure 97

Introduction25 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308When a screen includes a table, table buttons display to let you configure the table e

Página 169 - FTP Site on the Internet

Virtual Private Networking Using IPSec and L2TP Connections250ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Assign IPv4 Addresses to Remote Users

Página 170 - Attack Checks

Virtual Private Networking Using IPSec and L2TP Connections251 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To configure Mode Config on the VPN

Página 171

Virtual Private Networking Using IPSec and L2TP Connections252ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Complete the settings as described

Página 172 - IPv6 Attack Checks

Virtual Private Networking Using IPSec and L2TP Connections253 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.

Página 173 - Set Limits for IPv4 Sessions

Virtual Private Networking Using IPSec and L2TP Connections254ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 166. 8. On the Add IKE Policy

Página 174

Virtual Private Networking Using IPSec and L2TP Connections255 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 60. Add IKE Policy screen setti

Página 175 - Figure 103

Virtual Private Networking Using IPSec and L2TP Connections256ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IKE SA ParametersNote: Generally, the

Página 176 - Figure 104

Virtual Private Networking Using IPSec and L2TP Connections257 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53089. Click Apply to save your settings.

Página 177 - Add Customized Services

Virtual Private Networking Using IPSec and L2TP Connections258ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Perform these tasks from a compu

Página 178 -  To edit a service:

Virtual Private Networking Using IPSec and L2TP Connections259 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Change the name of the authenticati

Página 179 - Create IP Groups

2622. IPv4 and IPv6 Internet and WAN SettingsThis chapter explains how to configure the IPv4 and IPv6 Internet and WAN settings. The chapter contain

Página 180 -  To edit an IP group:

Virtual Private Networking Using IPSec and L2TP Connections260ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to use the new settings

Página 181 - Create Bandwidth Profiles

Virtual Private Networking Using IPSec and L2TP Connections261 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53088. Click Apply to use the new settings

Página 182 - Profile screen displays:

Virtual Private Networking Using IPSec and L2TP Connections262ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 171. 3. Specify the settings t

Página 183

Virtual Private Networking Using IPSec and L2TP Connections263 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to use the new settings

Página 184 - Figure 111

Virtual Private Networking Using IPSec and L2TP Connections264ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Specify the following default lifet

Página 185 - Figure 112

Virtual Private Networking Using IPSec and L2TP Connections265 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Verify that the VPN firewall issued

Página 186 - Configure Content Filtering

Virtual Private Networking Using IPSec and L2TP Connections266ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 keep-alive and Dead Peer Detection (DP

Página 187

Virtual Private Networking Using IPSec and L2TP Connections267 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Enter the settings as described in

Página 188 - Figure 113

Virtual Private Networking Using IPSec and L2TP Connections268ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 177. 4. In the IKE SA Paramete

Página 189

Virtual Private Networking Using IPSec and L2TP Connections269 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Specify the IP version for which yo

Página 190 - Enable Source MAC Filtering

IPv4 and IPv6 Internet and WAN Settings27 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet and WAN Configuration Tasks• Roadmap to Setting Up

Página 191 - Figure 115

Virtual Private Networking Using IPSec and L2TP Connections270ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To enable the PPTP server and config

Página 192 - Set Up IP/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections271 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.V

Página 193 - IPv4/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections272ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure the L2TP ServerAs an alterna

Página 194 - Figure 117

Virtual Private Networking Using IPSec and L2TP Connections273 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in

Página 195 - IPv6/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections274ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 L2TP IP The IP address that is assigne

Página 196 - Figure 119

27566. Virtual Private Networking Using SSL ConnectionsThe VPN firewall provides a hardware-based SSL VPN solution designed specifically to provide

Página 197 - Configure Port Triggering

Virtual Private Networking Using SSL Connections276ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SSL VPN Portal OptionsThe VPN firewall’s SSL VPN

Página 198 - Figure 120

Virtual Private Networking Using SSL Connections277 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308resources to which the users are granted access.

Página 199 -  To configure UPnP:

Virtual Private Networking Using SSL Connections278ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 You apply portal layouts by selecting one from th

Página 200

Virtual Private Networking Using SSL Connections279 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The List of Layouts table displays the following

Página 201 - IPSec and L2TP Connections

IPv4 and IPv6 Internet and WAN Settings28ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. (Optional) Configure Dynamic DNS on the WAN interfaces.

Página 202

Virtual Private Networking Using SSL Connections280ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Complete the settings as described in the foll

Página 203 - Configurations

Virtual Private Networking Using SSL Connections281 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The new por

Página 204 - Figure 126

Virtual Private Networking Using SSL Connections282ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 For information about how to configure domains, g

Página 205 - Figure 127

Virtual Private Networking Using SSL Connections283 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. In the Add New Application for Port Forwarding

Página 206

Virtual Private Networking Using SSL Connections284ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To add servers and host names for client name r

Página 207 - Figure 129

Virtual Private Networking Using SSL Connections285 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Select whether you want to enable full-tunnel o

Página 208 - Figure 131

Virtual Private Networking Using SSL Connections286ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 188. SSL VPN Client screen for IPv63. Com

Página 209 - Figure 132

Virtual Private Networking Using SSL Connections287 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. VPN tunnel

Página 210

Virtual Private Networking Using SSL Connections288ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 If VPN tunnel clients are already connected, disc

Página 211 - Figure 134

Virtual Private Networking Using SSL Connections289 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 189. 2. In the Add New Resource section o

Página 212 - Figure 135

IPv4 and IPv6 Internet and WAN Settings29 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. (Optional) Configure the WAN options. If necessary, chan

Página 213 - Figure 136

Virtual Private Networking Using SSL Connections290ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 190. 4. Complete the settings as describe

Página 214

Virtual Private Networking Using SSL Connections291 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The new con

Página 215 - Figure 137

Virtual Private Networking Using SSL Connections292ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 includes the following addresses: 10.0.0.5–10.0.0

Página 216 - Figure 138

Virtual Private Networking Using SSL Connections293 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Make your selection from the following Query o

Página 217 - Figure 140

Virtual Private Networking Using SSL Connections294ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 .Figure 193. Add SSL VPN Policy screen for IPv64

Página 218 - Figure 142

Virtual Private Networking Using SSL Connections295 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Apply Policy to? (continued)Network ResourcePolic

Página 219

Virtual Private Networking Using SSL Connections296ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your settings. The policy

Página 220 - Figure 143

Virtual Private Networking Using SSL Connections297 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more SSL VPN policies:1. On th

Página 221 - Figure 145

Virtual Private Networking Using SSL Connections298ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. In the Portal URL field of the List of Layouts

Página 222 - Figure 146

Virtual Private Networking Using SSL Connections299 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 198. The User Portal screen displays a si

Página 223 - The Advanced pane displays:

3ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 202-10536-03 1.0 November 2011 Incorporated nontechnical edits only (there are no feature changes).

Página 224

IPv4 and IPv6 Internet and WAN Settings30ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • If your ISP has provided you with multiple public IP addr

Página 225 - Figure 148

Virtual Private Networking Using SSL Connections300ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 199. The active user’s name, group, and IP

Página 226 - Figure 149

30177. Manage Users, Authentication, and VPN CertificatesThis chapter describes how to manage users, authentication, and security certificates for

Página 227 - Information

Manage Users, Authentication, and VPN Certificates302ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The VPN Firewall’s Authentication Process and O

Página 228 - Figure 154

Manage Users, Authentication, and VPN Certificates303 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Authentication Domains, Groups, and U

Página 229 - Figure 156

Manage Users, Authentication, and VPN Certificates304ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create Domains To create a domain:1. Select Us

Página 230 - Figure 157

Manage Users, Authentication, and VPN Certificates305 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 202. 3. Complete the settings as descri

Página 231 - Manage IPSec VPN Policies

Manage Users, Authentication, and VPN Certificates306ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The domai

Página 232 - Figure 158

Manage Users, Authentication, and VPN Certificates307 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: A combination of local and external authe

Página 233 - Figure 159

Manage Users, Authentication, and VPN Certificates308ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IMPORTANT:When you create a domain on the Domai

Página 234

Manage Users, Authentication, and VPN Certificates309 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: When you create a domain on the Domains

Página 235

IPv4 and IPv6 Internet and WAN Settings31 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. These settings apply

Página 236

Manage Users, Authentication, and VPN Certificates310ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Edit GroupsFor groups that were automatically c

Página 237 -  To edit an IKE policy:

Manage Users, Authentication, and VPN Certificates311 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Guest user. A user who can only view the VPN

Página 238 - Manage VPN Policies

Manage Users, Authentication, and VPN Certificates312ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 206. 3. Enter the settings as described

Página 239 - Figure 160

Manage Users, Authentication, and VPN Certificates313 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more user accounts:1. In the

Página 240

Manage Users, Authentication, and VPN Certificates314ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: For security reasons, the Deny Login from

Página 241 - Setting Description

Manage Users, Authentication, and VPN Certificates315 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. In the Add Defined Addresses section of the

Página 242

Manage Users, Authentication, and VPN Certificates316ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 209. 5. In the Defined Addresses Status

Página 243

Manage Users, Authentication, and VPN Certificates317 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more IPv6 addresses:1. In th

Página 244

Manage Users, Authentication, and VPN Certificates318ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Firefox. Mozilla Firefox.• Mozilla. Other Moz

Página 245 -  To edit a VPN policy:

Manage Users, Authentication, and VPN Certificates319 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 211. 3. Change the settings as describe

Página 246

IPv4 and IPv6 Internet and WAN Settings32ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 12. 3. Click the Auto Detect button at the bottom o

Página 247 - User Database Configuration

Manage Users, Authentication, and VPN Certificates320ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage Digital Certificates for VPN Connections

Página 248 - Figure 163

Manage Users, Authentication, and VPN Certificates321 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Because a commercial CA takes steps to verify t

Página 249

Manage Users, Authentication, and VPN Certificates322ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage VPN CA Certificates To view and upload

Página 250 - Mode Config Operation

Manage Users, Authentication, and VPN Certificates323 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Manage VPN Self-Signed CertificatesInstead of o

Página 251 - Figure 165

Manage Users, Authentication, and VPN Certificates324ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 214. Certificates, screen 2 of 32. In t

Página 252

Manage Users, Authentication, and VPN Certificates325 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click the Generate table button. A new SCR i

Página 253

Manage Users, Authentication, and VPN Certificates326ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 9. Select the check box next to the self-signed

Página 254 - Figure 166

Manage Users, Authentication, and VPN Certificates327 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 216. Certificates, screen 3 of 3The Cer

Página 255

32888. Network and System ManagementThis chapter describes the tools for managing the network traffic to optimize its performance and the system man

Página 256

Network and System Management329 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Performance Management• Bandwidth Capacity• Features That Reduce Tra

Página 257 - Operation

IPv4 and IPv6 Internet and WAN Settings33 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• If the autodetect process does not find a connection, you

Página 258 - Figure 168

Network and System Management330ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Features That Reduce TrafficYou can adjust the following features of

Página 259 - Figure 169

Network and System Management331 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• LAN users (or DMZ users). You can specify which computers on your

Página 260

Network and System Management332ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 In order to reduce traffic, the VPN firewall provides the following

Página 261

Network and System Management333 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Each rule lets you specify the desired action for the connections co

Página 262 - Figure 171

Network and System Management334ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 - Address range. The rule applies to a range of Internet IP addresse

Página 263 - Figure 172

Network and System Management335 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN, L2TP, and PPTP TunnelsThe VPN firewall supports site-to-site IP

Página 264 - Figure 174

Network and System Management336ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Monitoring Tools for Traffic ManagementThe VPN firewall includes sev

Página 265 - Figure 175

Network and System Management337 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 217. 2. In the Action column of the List of Users table, cli

Página 266 - Configure Keep-Alives

Network and System Management338ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your settings.7. Repeat Step 1 through Step

Página 267 - Configure Dead Peer Detection

Network and System Management339 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308continuing (see Change Passwords and Administrator and Guest Setting

Página 268 - Figure 177

IPv4 and IPv6 Internet and WAN Settings34ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 13. The Connection Status screen should show a vali

Página 269 - Configure the PPTP Server

Network and System Management340ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 220. Remote Management screen for IPv63. Enter the settings

Página 270 - Figure 179

Network and System Management341 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WARNING:If you are remotely connected to the VPN firewall and you se

Página 271 - View the Active PPTP Users

Network and System Management342ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: If you are using a Dynamic DNS service such as TZO, you can ide

Página 272 - Configure the L2TP Server

Network and System Management343 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 221. The SNMPv3 Users table includes the default SNMPv3 user

Página 273 - View the Active L2TP Users

Network and System Management344ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. To specify a new SNMP configuration, in the Create New SNMP Confi

Página 274 - Item Description

Network and System Management345 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 222. 2. Modify the settings as described in the previous tab

Página 275 - SSL Connections

Network and System Management346ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your changes. To configure the SNMP system i

Página 276 - SSL VPN Portal Options

Network and System Management347 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:3. Click A

Página 277 - Create the Portal Layout

Network and System Management348ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 225. Back Up SettingsThe backup feature saves all VPN firewal

Página 278

Network and System Management349 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Restore SettingsWARNING:Restore only settings that were backed up fr

Página 279 - Figure 185

IPv4 and IPv6 Internet and WAN Settings35 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The IPv4 WAN Settings table displays the following fields:•

Página 280

Network and System Management350ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:When you press the hardware factory default Reset button or

Página 281 -  To edit a portal layout:

Network and System Management351 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The newly installed firmware is the active firmware. The previously

Página 282 - Add Servers and Port Numbers

Network and System Management352ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Select Monitoring. The Router Status screen displays, showing the

Página 283 - Add a New Host Name

Network and System Management353 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Resolve IPv6 address for serversSelect this check box to force the u

Página 284 - Configure the SSL VPN Client

Network and System Management354ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.Note: If you select the default

Página 285

35599. Monitor System Access and PerformanceThis chapter describes the system-monitoring features of the VPN firewall. You can be alerted to importa

Página 286

Monitor System Access and Performance356ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure and Enable the WAN Traffic MeterIf your ISP charge

Página 287

Monitor System Access and Performance357 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 88. WAN1 Traffic Meter screen settings Setting Descri

Página 288 - Add New Network Resources

Monitor System Access and Performance358ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.4. If you want to enabl

Página 289 -  To edit network resources:

Monitor System Access and Performance359 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure and Enable the LAN Traffic MeterIf your ISP charge

Página 290 - Figure 190

IPv4 and IPv6 Internet and WAN Settings36ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 16. 6. If your connection is PPTP or PPPoE, your IS

Página 291

Monitor System Access and Performance360ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Traffic (MB). The traffic usage in MB.• State. The state t

Página 292 - View Policies

Monitor System Access and Performance361 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. Click Apply to save your settings. The new account is add

Página 293 -  To add an SSL VPN policy:

Monitor System Access and Performance362ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure Logging, Alerts, and Event NotificationsYou can co

Página 294

Monitor System Access and Performance363 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:Ta

Página 295

Monitor System Access and Performance364ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Enable E-mail LogsDo you want logs to be emailed to you?Sele

Página 296 -  To edit an SSL VPN policy:

Monitor System Access and Performance365 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.Note: Enabling routing

Página 297

Monitor System Access and Performance366ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 234. You can refresh the logs, clear the logs, or se

Página 298 - Figure 197

Monitor System Access and Performance367 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308How to Send Syslogs over a VPN Tunnel between Sites To send

Página 299 - Figure 198

Monitor System Access and Performance368ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. In the Traffic Selector section of the screen, make the f

Página 300 - Figure 200

Monitor System Access and Performance369 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308View Status Screens• View the System Status• View the VPN Co

Página 301 - VPN Certificates

IPv4 and IPv6 Internet and WAN Settings37 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53087. In the Internet (IP) Address section of the screen (see

Página 302

Monitor System Access and Performance370ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 236. The following table explains the fields of the R

Página 303 - Configure Domains

Monitor System Access and Performance371 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Router Statistics Screen To view the Router Statistics scre

Página 304 - Create Domains

Monitor System Access and Performance372ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 237. The following table explains the fields of the

Página 305 - Figure 202

Monitor System Access and Performance373 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 238.

Página 306

Monitor System Access and Performance374ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The following table explains the fields of the Detailed Stat

Página 307 - Configure Groups

Monitor System Access and Performance375 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ IPv6 ConfigurationIPv6 Address The IPv6 address and pref

Página 308 - Create Groups

Monitor System Access and Performance376ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 VLAN Status ScreenThe VLAN Status screen displays informatio

Página 309 - Figure 204

Monitor System Access and Performance377 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table explains the fields of the VLAN Status s

Página 310 - Configure User Accounts

Monitor System Access and Performance378ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 View the VPN Connection Status, L2TP Users, and PPTP UsersTh

Página 311 - Figure 205

Monitor System Access and Performance379 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The active user’s user name, group, and IP address are liste

Página 312 - Figure 206

IPv4 and IPv6 Internet and WAN Settings38ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 8. In the Domain Name Server (DNS) Servers section of the s

Página 313 - Set User Login Policies

Monitor System Access and Performance380ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The List of PPTP Active Users table lists each active connec

Página 314 - Figure 208

Monitor System Access and Performance381 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 246. View the Port Triggering Status To view the sta

Página 315

Monitor System Access and Performance382ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 248. The Port Triggering Status screen displays the

Página 316 - Figure 209

Monitor System Access and Performance383 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 249. 2. In the Action column, click the Status butto

Página 317 - Figure 210

Monitor System Access and Performance384ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Click Disconnect to disconnect the connection; click Connect

Página 318

Monitor System Access and Performance385 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 252. The type of connection determines the informati

Página 319 - Figure 211

Monitor System Access and Performance386ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 View the Attached Devices To view the attached devices on t

Página 320

Monitor System Access and Performance387 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: If the VPN firewall is rebooted, the data in the Known

Página 321 - VPN Certificates Screen

Monitor System Access and Performance388ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Diagnostics Utilities• Send a Ping Packet• Trace a Route• Lo

Página 322 - Manage VPN CA Certificates

Monitor System Access and Performance389 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• IPv6. Select the IPv6 radio button. The Diagnostics screen

Página 323 - Figure 213

IPv4 and IPv6 Internet and WAN Settings39 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53089. Click Apply to save your changes.10. Click Test to evalu

Página 324

Monitor System Access and Performance390ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Trace a RouteA traceroute lists all routers between the sour

Página 325 - Figure 215

Monitor System Access and Performance391 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Capture Packets in Real TimeCapturing packets can assist NET

Página 326 -  To delete one or more SCRs:

3921010. TroubleshootingThis chapter provides troubleshooting tips and information for the VPN firewall. After each problem description, instruction

Página 327 -  To delete one or more CRLs:

Troubleshooting393 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The VPN firewall’s diagnostic tools are described in Diagnostics Utilities o

Página 328 - Network and System Management

Troubleshooting394ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  If all LEDs are still on more than several minutes minute after power-up, do the

Página 329 - Performance Management

Troubleshooting395 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Make sure that you are using the SSL https://address login rather than the http:

Página 330 - Features That Reduce Traffic

Troubleshooting396ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Troubleshoot the ISP ConnectionIf your VPN firewall is unable to access the Intern

Página 331 - Content Filtering

Troubleshooting397 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308have to enter additional information. For more information, see Manually Configure

Página 332 - Source MAC Filtering

Troubleshooting398ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 - Windows Server 2003, all versions- Windows Server 2003 R2, all versions- Linux a

Página 333

Troubleshooting399 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308c. Click or double-click View status of this connection. The Local Area Connection

Página 334 - Exposed Hosts

4ContentsChapter 1 IntroductionWhat Is the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308? .12Key Features and Capabilities . . . . . . . . . . .

Página 335 - Assign Bandwidth Profiles

IPv4 and IPv6 Internet and WAN Settings40ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: If your ISP requires MAC authentication and another M

Página 336 - System Management

Troubleshooting400ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 f. Make sure that an IPv6 address shows. The previous figure does not show an IPv6

Página 337 - Figure 218

Troubleshooting401 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Test the Path from Your Computer to a Remote DeviceAfter verifying that the LAN pa

Página 338

Troubleshooting402ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 261. b. In the Backup / Restore Settings section of the screen, click the

Página 339

Troubleshooting403 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Address Problems with Date and TimeThe System Date & Time screen displays the

Página 340

404AA. Default Settings and Technical SpecificationsThis appendix provides the default settings and the physical and technical specifications of the

Página 341 - About Remote Access

Default Settings and Technical Specifications405ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Factory Default SettingsYou can use the factory defau

Página 342 -  To access the CLI:

Default Settings and Technical Specifications406ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv4 LAN, DMZ, and routing settingsLAN IPv4 address f

Página 343 - Figure 221

Default Settings and Technical Specifications407ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Firewall and security settingsInbound LAN WAN rules (

Página 344

Default Settings and Technical Specifications408ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308QoS priorities (for IPv6 firewall rules) Normal-Servi

Página 345 - Figure 223

Default Settings and Technical Specifications409ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN IPsec Wizard: IKE policy settings for IPv4 gatewa

Página 346 - Figure 224

IPv4 and IPv6 Internet and WAN Settings41 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Load Balancing Mode and Optional Protocol Binding

Página 347 - Manage the Configuration File

Default Settings and Technical Specifications410ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Physical and Technical SpecificationsThe following ta

Página 348 - Back Up Settings

Default Settings and Technical Specifications411ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table shows the IPSec VPN specification

Página 349 - Restore Settings

Default Settings and Technical Specifications412ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table shows the SSL VPN specifications

Página 350 - Upgrade the Firmware

413BB. Network Planning for Multiple WAN PortsThis appendix describes the factors to consider when planning a network using a firewall that has more

Página 351

Network Planning for Multiple WAN Ports414ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308What to Consider Before You Begin• Cabling and Computer Har

Página 352 - Figure 226

Network Planning for Multiple WAN Ports415ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 262. b. Contact a Dynamic DNS service, and register

Página 353

Network Planning for Multiple WAN Ports416ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet Configuration RequirementsDepending on how your IS

Página 354

Network Planning for Multiple WAN Ports417ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet Connection InformationPrint this page with the Int

Página 355 - Performance

Network Planning for Multiple WAN Ports418ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Overview of the Planning ProcessThe areas that require plan

Página 356 - Figure 227

Network Planning for Multiple WAN Ports419ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Features such as multiple exposed hosts are not supported i

Página 357

IPv4 and IPv6 Internet and WAN Settings42ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 b. From the corresponding drop-down list on the right, sele

Página 358 - Figure 228

Network Planning for Multiple WAN Ports420ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 265. Inbound Traffic to a Dual WAN Port SystemThe IP

Página 359 - Figure 230

Network Planning for Multiple WAN Ports421ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 267. Virtual Private Networks• VPN Road Warrior (Cli

Página 360 - Figure 231

Network Planning for Multiple WAN Ports422ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308always changes. Therefore, the use of an FQDN is always req

Página 361 - Figure 232

Network Planning for Multiple WAN Ports423ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Road Warrior: Single-Gateway WAN Port (Reference Case)I

Página 362 - Figure 233

Network Planning for Multiple WAN Ports424ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 272. The purpose of the FQDN in this case is to togg

Página 363

Network Planning for Multiple WAN Ports425ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Gateway-to-GatewayThe following situations exemplify th

Página 364

Network Planning for Multiple WAN Ports426ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 275. The IP addresses of the gateway WAN ports can b

Página 365

Network Planning for Multiple WAN Ports427ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 277. The IP addresses of the gateway WAN ports can b

Página 366 - Figure 235

Network Planning for Multiple WAN Ports428ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The IP address of the gateway WAN port can be either fixed

Página 367 - Configure Gateway 1 at Site 1

Network Planning for Multiple WAN Ports429ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Telecommuter: Dual-Gateway WAN Ports for Load Balancing

Página 368 - Configure Gateway 2 at Site 2

IPv4 and IPv6 Internet and WAN Settings43 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Destination Network. The Internet locations (based on the

Página 369 - View Status Screens

430CC. System Logs and Error MessagesThis appendix provides examples and explanations of system logs and error message. When applicable, a recommend

Página 370 - Figure 236

System Logs and Error Messages431ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Log Message TermsThis appendix uses the following log message terms.

Página 371 - Router Statistics Screen

System Logs and Error Messages432ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This section describes log messages that belong to one of the follow

Página 372 - Detailed Status Screen

System Logs and Error Messages433ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308System StartupThis section describes the log message generated durin

Página 373 - Figure 238

System Logs and Error Messages434ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPSec RestartThis section describes logs that are generated when IPS

Página 374

System Logs and Error Messages435ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Multicast/Broadcast LogsWAN StatusThis section describes the logs ge

Página 375

System Logs and Error Messages436ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This section describes the logs generated when the WAN mode is set t

Página 376 - VLAN Status Screen

System Logs and Error Messages437ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• PPPoE Idle Timeout Logs• PPTP Idle Timeout LogsTable 118. System

Página 377 - Tunnel Status Screen

System Logs and Error Messages438ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• PPP Authentication LogsResolved DNS NamesThis section describes th

Página 378 - Figure 242

System Logs and Error Messages439ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Log MessagesThis section explains logs that are generated by IPS

Página 379 - Figure 244

IPv4 and IPv6 Internet and WAN Settings44ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your settings. The protocol binding

Página 380 - View the VPN Logs

System Logs and Error Messages440ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Messages 22 and 23 Messages 24 and 25 2000 Jan 1 04:13:40 [SRX530

Página 381 - Figure 247

System Logs and Error Messages441ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Explanation Message 1: Informational exchange for deleting the pay

Página 382 - View the WAN Port Status

System Logs and Error Messages442ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Explanation Message 1–4: After receiving a request for phase 1 nego

Página 383 - Figure 250

System Logs and Error Messages443ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SSL VPN LogsThis section describes the log messages that are generat

Página 384 - IPv6 WAN Port Status

System Logs and Error Messages444ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Traffic Meter LogsRouting Logs• LAN to WAN Logs• LAN to DMZ Logs• DM

Página 385 - Figure 252

System Logs and Error Messages445ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN to WAN LogsLAN to DMZ LogsDMZ to WAN LogsWAN to LAN LogsTable 13

Página 386 - View the Attached Devices

System Logs and Error Messages446ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ to LAN LogsWAN to DMZ LogsOther Event Logs• Session Limit Logs•

Página 387 - View the DHCP Log

System Logs and Error Messages447ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Source MAC Filter LogsBandwidth Limit LogsDHCP LogsThis section expl

Página 388 - Diagnostics Utilities

System Logs and Error Messages448ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 143. DHCP logs Message 1 Message 2 Message 3 Message 4 Messag

Página 389 - Send a Ping Packet

449DD. Two-Factor AuthenticationThis appendix provides an overview of two-factor authentication, and an example of how to implement the WiKID soluti

Página 390 - Display the Routing Tables

IPv4 and IPv6 Internet and WAN Settings45 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the Auto-Rollover Mode and Failure Detection Meth

Página 391 - Capture Packets in Real Time

Two-Factor Authentication450ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Why Do I Need Two-Factor Authentication?• What Are the Benefits of Two-Fa

Página 392 - Troubleshooting

Two-Factor Authentication451ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This appendix focuses on and discusses only the first two factors, someth

Página 393 - Basic Functioning

Two-Factor Authentication452ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. A one-time passcode (something the user has) is generated.Figure 283.

Página 394 - LAN or WAN Port LEDs Not On

453EE. Notification of ComplianceNETGEAR wired productsRegulatory Compliance InformationThis section includes user requirements for operating this p

Página 395

Notification of Compliance454ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308FCC Radio Frequency Interference Warnings & InstructionsThis equipme

Página 396

455IndexNumerics10BASE-T, 100BASE-T, and 1000BASE-T speeds 743322.org 49–526to4 tunnelsconfiguring globally 64DMZ, configuring for 126LAN, configuring

Página 397

456ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6configuring 69described 68VPN IPSec 202, 206, 214autosensing port speed 74Bbacking up configur

Página 398 - Figure 258

457ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ portIPv4 address and subnet mask 116IPv6 address and prefix length 120settings 115domain, user

Página 399 - Figure 260

458ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SSL VPN settings 286server IPv6 addressesbroadband settings 59, 63DMZ settings 121LAN settings 106

Página 400

459ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308global addresses, IPv6 65global IPv6 tunnelsDMZ, configuring for 126LAN, configuring for 112group

Página 401

IPv4 and IPv6 Internet and WAN Settings46ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the Load Balancing Settings section of the screen, co

Página 402 - Figure 261

460ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCP, address pool 117DMZ port 116DNS servers 39, 91, 117dynamically assigned 38errors 25ISATAP tu

Página 403

461ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308JJava, blocking 187Kkeep-alives, VPN tunnels 242, 266keyword blocking 187kit, rack-mounting 21know

Página 404 - Specifications

462ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308management default settings 410maximum transmission unit (MTU)default 73IPv6 DMZ packets 125IPv6 L

Página 405 - Factory Default Settings

463ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6DMZ-to-WAN rules 155LAN-to-DMZ rules 161LAN-to-WAN rules 148order of precedence 144overview 13

Página 406

464ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308PPPoE (PPP over Ethernet)described 16IPv4 settings 33, 37IPv6 settings 62PPTP (Point-to-Point Tunn

Página 407

465ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308remote users, assigning addresses (Mode Config) 250requirements, hardware 415reserved IPv4 address

Página 408

466ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SPI (stateful packet inspection) 14, 135split tunnel, SSL VPN 285spoofing MAC addresses 397SSL cer

Página 409

467ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308rate-limiting 75reducing 330–332volume by protocol 358volume, limitingLAN 360WAN 357Transmission C

Página 410

468ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308FQDNs 202–203, 421FQDNs, configuring endpoints 206, 210, 213, 235gateway-to-gatewayauto-rollover 4

Página 411

469ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN WAN outbound rules, configuring 147, 330locking yourself outconfiguring an exposed host 167dis

Página 412

IPv4 and IPv6 Internet and WAN Settings47 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The default time to roll over after the primary WAN i

Página 413

IPv4 and IPv6 Internet and WAN Settings48ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 After you have configured secondary WAN addresses, these ad

Página 414

IPv4 and IPv6 Internet and WAN Settings49 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 25. The List of Secondary WAN addresses table displ

Página 415

5ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure a Static IPv6 Internet Connection. . . . . . . . . . . . . . . . . . . . . .58Configure a

Página 416

IPv4 and IPv6 Internet and WAN Settings50ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 After you have configured your account information on the V

Página 417

IPv4 and IPv6 Internet and WAN Settings51 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 26. 3. Click the Information option arrow in the up

Página 418 - Figure 263

IPv4 and IPv6 Internet and WAN Settings52ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Configure the DDNS service settings as described in the

Página 419 - Inbound Traffic

IPv4 and IPv6 Internet and WAN Settings53 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: You can configure only one WAN interface for IPv6. Th

Página 420 - Figure 266

IPv4 and IPv6 Internet and WAN Settings54ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 These are the options:• IPv4-only mode. The VPN firewall co

Página 421 - Virtual Private Networks

IPv4 and IPv6 Internet and WAN Settings55 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WARNING:Changing the IP routing mode causes the VPN firewal

Página 422 - Figure 269

IPv4 and IPv6 Internet and WAN Settings56ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The IPv6 WAN Settings table displays the following fields:•

Página 423 - Figure 271

IPv4 and IPv6 Internet and WAN Settings57 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. As an optional step: If you have selected the Stateless

Página 424 - Figure 273

IPv4 and IPv6 Internet and WAN Settings58ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure a Static IPv6 Internet ConnectionTo configure a s

Página 425 - VPN Gateway-to-Gateway

IPv4 and IPv6 Internet and WAN Settings59 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 33. 4. In the Internet Address section of the scree

Página 426 - Figure 276

6ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Inbound Rules (Port Forwarding) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 140Order o

Página 427 - Figure 278

IPv4 and IPv6 Internet and WAN Settings60ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your changes.7. Verify the connectio

Página 428 - Figure 280

IPv4 and IPv6 Internet and WAN Settings61 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure a PPPoE IPv6 Internet ConnectionTo configure a PP

Página 429 - Figure 281

IPv4 and IPv6 Internet and WAN Settings62ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 36. 4. In the Internet Address section of the scree

Página 430

IPv4 and IPv6 Internet and WAN Settings63 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. Click Apply to save your changes.7. Verify the connectio

Página 431 - System Log Messages

IPv4 and IPv6 Internet and WAN Settings64ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: If your ISP requires MAC authentication and another M

Página 432 - Login/Logout

IPv4 and IPv6 Internet and WAN Settings65 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 37. 2. Select the Enable Automatic Tunneling check

Página 433 - Firewall Restart

IPv4 and IPv6 Internet and WAN Settings66ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To configure an ISATAP tunnel:1. Select Network Configura

Página 434 - IPSec Restart

IPv4 and IPv6 Internet and WAN Settings67 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To edit an ISATAP tunnel:1. On the ISATAP Tunnels screen,

Página 435 - WAN Status

IPv4 and IPv6 Internet and WAN Settings68ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 a.b.c.d for part of the IPv6 address so that the IPv4-trans

Página 436 - PPP Logs

IPv4 and IPv6 Internet and WAN Settings69 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To use a redundant ISP link for backup purposes, ensure tha

Página 437 - • PPTP Idle T

7ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Extended Authentication (XAUTH) . . . . . . . . . . . . . . . . . . . . .245Configure XAU

Página 438 - Resolved DNS Names

IPv4 and IPv6 Internet and WAN Settings70ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Ensure that the backup WAN interface is configured be

Página 439 - VPN Log Messages

IPv4 and IPv6 Internet and WAN Settings71 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The default time to roll over after the primary WAN i

Página 440

IPv4 and IPv6 Internet and WAN Settings72ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 45. 3. Click the Advanced option arrow in the upper

Página 441

IPv4 and IPv6 Internet and WAN Settings73 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 46. 4. Enter the settings as described in the follo

Página 442

IPv4 and IPv6 Internet and WAN Settings74ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SpeedIn most cases, the VPN firewall can automatically dete

Página 443 - SSL VPN Logs

IPv4 and IPv6 Internet and WAN Settings75 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Failure Detection Metho

Página 444 - Routing Logs

IPv4 and IPv6 Internet and WAN Settings76ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:Depending on the changes that you made, when you cl

Página 445 - WAN to LAN Logs

IPv4 and IPv6 Internet and WAN Settings77 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: To configure and apply QoS profiles successfully, fam

Página 446 - Other Event Logs

IPv4 and IPv6 Internet and WAN Settings78ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Hosts. The IP address, IP addresses, or group to which th

Página 447 - DHCP Logs

IPv4 and IPv6 Internet and WAN Settings79 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Diffserv QoS Match Enter a DSCP value in the range of 0 thr

Página 448 - Table 143. DHCP logs

8ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Change Passwords and Other User Settings. . . . . . . . . . . . . . . . . . . .318Manage Digital Cer

Página 449 - Two-Factor Authentication

IPv4 and IPv6 Internet and WAN Settings80ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The profile is added

Página 450

IPv4 and IPv6 Internet and WAN Settings81 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The profile is added

Página 451 - Figure 282

IPv4 and IPv6 Internet and WAN Settings82ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit a QoS profile:1. In the List of QoS Profiles tabl

Página 452 - Figure 284

8333. LAN ConfigurationThis chapter describes how to configure the LAN features of your VPN firewall. The chapter contains the following sections:•

Página 453 - Notification of Compliance

LAN Configuration84ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage IPv4 Virtual LANs and DHCP Options• Port-Based VLANs • Assign and Manage V

Página 454

LAN Configuration85 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Port-Based VLANsThe VPN firewall supports port-based VLANs. Port-based VLANs help

Página 455 - Numerics

LAN Configuration86ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Assign and Manage VLAN Profiles To assign VLAN profiles to the LAN ports and man

Página 456

LAN Configuration87 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VLAN DHCP OptionsFor each VLAN, you need to specify the Dynamic Host Configuratio

Página 457

LAN Configuration88ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 firewall’s LAN IP address). When the DNS proxy option is disabled for a VLAN, all

Página 458

LAN Configuration89 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 52. 3. Enter the settings as described in the following table: Table 16.

Página 459

9ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN or WAN Port LEDs Not On . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .394Troublesho

Página 460

LAN Configuration90ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Port MembershipPort 1, Port 2, Port 3, Port 4 / DMZSelect one, several, or all po

Página 461

LAN Configuration91 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Enable DHCP Server Select the Enable DHCP Server radio button to enable the VPN f

Página 462

LAN Configuration92ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings.Note: Once you have completed the LAN setup,

Página 463

LAN Configuration93 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To edit a VLAN profile:1. On the LAN Setup screen for IPv4 (see Figure 51 on p

Página 464

LAN Configuration94ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 53. 3. From the MAC Address for VLANs drop-down list, select Unique. (The

Página 465

LAN Configuration95 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following is an example of correctly configured IPv4 addresses:• WAN IP addre

Página 466

LAN Configuration96ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Modify the IP address or subnet mask, or both.3. Click Apply to save your sett

Página 467

LAN Configuration97 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• There is no need to reserve an IP address for a computer in the DHCP server. Al

Página 468

LAN Configuration98ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The Known PCs and Devices table lists the entries in the network database. For ea

Página 469

LAN Configuration99 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Click the Add table button to add the computer or device to the Known PCs and

Comentários a estes Manuais

Sem comentários