WatchGuard Technologies WatchGuard Firebox SOHO Manual de usuario

Busca en linea o descarga Manual de usuario para Redes WatchGuard Technologies WatchGuard Firebox SOHO. WatchGuard Technologies WatchGuard Firebox SOHO User's Manual Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 118
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente

Indice de contenidos

Pagina 1 - SOHO User Guide

WatchGuard SOHO and SOHO | tcWatchGuard®SOHO User GuideSOHO and SOHO|tc version 5.0

Pagina 2

10WatchGuard® Limited Hardware WarrantyThis WatchGuard Limited Hardware Warranty (the "Warranty") applies to the enclosed WatchGuard hardwar

Pagina 3 - Using this guide

Step-by-step instructions for configuring a SOHO VPN tunnel100Obtaining the VPN upgradeIf you purchased a WatchGuard SOHO and would like to purchase t

Pagina 4 - Certifications and Notices

User Guide 5.0 101Frequently asked questionsdevice. To set up multiple VPN tunnels, you will need to have at least one WatchGuard Firebox configured w

Pagina 5 - VCCI Notice Class A ITE

Frequently asked questions102How do I connect three or four offices together?To connect more than two offices together, WatchGuard recommends designat

Pagina 6 - Declaration of Conformity

User Guide 5.0 103MUVPN ClientsHow do I enable a VPN Tunnel?Full instructions for enabling a VPN tunnel can be found online at:http://www.watchguard.c

Pagina 7 - End-User License Agreement

View the VPN Statistics104

Pagina 8

User Guide 5.0 105CHAPTER 9 ResourcesTroubleshootingThe following information is offered to help overcome any minor difficulties that might occur when

Pagina 9 - User Guide 5.0 9

Troubleshooting106 NOTEYou can also reboot by removing the power source for ten seconds, and then restoring power.What do the ON and MODE lights sign

Pagina 10 - Limited Hardware Warranty

User Guide 5.0 107Troubleshootingavailable. The first year of service is free with purchase of the SOHO. To register your SOHO:1 With your Web browser

Pagina 11 - User Guide 5.0 11

Troubleshooting108DSL router, the NAT feature of the DSL router should be set for bridge-only mode.How do I install a SOHO using a Macintosh?The proce

Pagina 12

User Guide 5.0 109TroubleshootingHow can I see the MAC address of my SOHO?A MAC (Medium Access Control) address is a unique number used to identify th

Pagina 13 - Table of Contents

User Guide 5.0 11OR IMPLIED, ARISING BY LAW OR OTHERWISE, WITH RESPECT TO ANY NONCONFORMANCE OR DEFECT IN THE HARDWARE PRODUCT (INCLUDING, BUT NOT LIM

Pagina 14

Troubleshooting110How do I change to a static trusted IP address?Before you can use a static IP address, you must have a base Trusted IP address and s

Pagina 15 - User Guide 5.0 15

User Guide 5.0 111Troubleshooting3 Enable the checkbox labeled Enable WebBlocker. Enter a Full Access password, and an Inactivity Timeout (in minutes)

Pagina 16

Troubleshooting1123 Beneath the Protocol Settings fields, select either TCP Port, UDP Port or Protocol from the drop list.The Custom Service page refr

Pagina 17 - Introduction

User Guide 5.0 113Troubleshooting• The same authentication method for each end (MD-5 or SHA-1).How do I set up my SOHO for VPN Manager Access?This req

Pagina 18 - How does a firewall work?

Contacting Technical support114Contacting Technical supportOnline Documenting and In-Depth FAQsWatchGuard maintains an extensive knowledge base consis

Pagina 19 - User Guide 5.0 19

User Guide 5.0 115Bblocked sitesin WebBlocker96BrowserNetscape 4.0disabling HTTP proxy31Browsers, supported 28CCables, required 27Cabling, new SOHO 32

Pagina 20 - Port number

116HHTTP proxydisabling30IICQ, enable with SOCKS 71ICQ, IRC, AOL Messenger 72Incoming servicecreating custom65Informationcopyright12patent 12Installat

Pagina 21 - Services

User Guide 5.0 117MMacintosh, setting TCP/IP 29Manual installation 28Masquerading 21NNetworkprivate network default factory settings22Network Address

Pagina 22 - The Default Factory Settings

118adding pre-configured 64creating custom incoming 65Services, introduction 21SOCKS 71and ICQ 72and IRC 72SOCKS and AOL Messenger 72Static IP address

Pagina 23 - User Guide 5.0 23

12Copyright and Patent InformationCopyright © 1999-2001 WatchGuard Technologies, Inc. All rights reserved.WatchGuard and LiveSecurity are either regis

Pagina 24 - Rebooting a WatchGuard SOHO

User Guide 2.4 13Table of ContentsCHAPTER 1 Introduction ...17Registration and Identification Informatio

Pagina 25 - User Guide 5.0 25

14Configuring Your Trusted Network ...47Configuring Static Routes ...49View the Network Stat

Pagina 26

User Guide 5.0 15Configuring the SOHO WebBlocker ...88WebBlocker categories ...93Searching

Pagina 28 - The Installation Process

User Guide 5.0 17CHAPTER 1 IntroductionWelcomeCongratulations on purchasing the ideal solution for providing secure access to the Internet–the WatchGu

Pagina 29 - User Guide 5.0 29

Registration and Identification Information18Registration and Identification InformationOnce you have installed and configured your SOHO following the

Pagina 30

User Guide 5.0 19How does a firewall work?these dangers. As is illustrated in the image below, the SOHO physically seperates your trusted network from

Pagina 32

How does information travel on the internet?20How does information travel on the internet?Each packet of information transported over the Internet mus

Pagina 33 - User Guide 5.0 33

User Guide 5.0 21How does the SOHO process this information?How does the SOHO process this information?ServicesA service is the combination of protoco

Pagina 34

The SOHO Home Page—System Status22The SOHO Home Page—System Status The System Status page is effectively the home page of the SOHO. A variety of info

Pagina 35 - User Guide 5.0 35

User Guide 5.0 23The Default Factory SettingsFirewall SettingsAll incoming services are blocked.An outgoing service allowing all outbound traffic.None

Pagina 36

Rebooting a WatchGuard SOHO24The Base Model SOHOThe base model SOHO comes with a ten seat license, that is ten computers have access to the Internet t

Pagina 37 - SOHO Network

User Guide 5.0 25Rebooting a WatchGuard SOHO• Send an FTP command to the remote SOHO device. Use an FTP application to connect to the SOHO device, the

Pagina 38

Rebooting a WatchGuard SOHO26

Pagina 39 - User Guide 5.0 39

User Guide 5.0 27CHAPTER 2 Getting StartedBefore you beginPre-installation checklistBefore installing your new WatchGuard SOHO please ensure that you

Pagina 40

The Installation Process28• An operational Internet connection. Setup of your SOHO requires access to the Internet. If your connection does not work,

Pagina 41 - User Guide 5.0 41

User Guide 5.0 29The Installation ProcessDetermine your current TCP/IP settingsFor your reference, record the computer’s current TCP/IP settings in th

Pagina 42

User Guide 5.0 3Using this guideThis guide assumes that you are familiar with your computer’s operating system. If you have questions about navigating

Pagina 43 - User Guide 5.0 43

The Installation Process303 Exit the TCP/IP configuration screen. NOTEIf you are connecting more than one computer to the trusted network behind the

Pagina 44

User Guide 5.0 31The Installation ProcessWith the HTTP proxy enabled, the browser automatically points itself to Web pages located on the Internet, an

Pagina 45 - User Guide 5.0 45

The Installation Process325 Verify that the Direct Connection to the Internet option is enabled.6Click OK to save the settings.Internet Explorer 5.0/5

Pagina 46

User Guide 5.0 33The Installation Process1 Complete the “Pre-installation checklist” on page 27.2 Shut down your computer and unplug the power from yo

Pagina 47 - The Routes page appears

The Installation Process346 Attach the power cord to the SOHO and plug it into an outlet.7 Restart your computer.8 For information on the factory defa

Pagina 48

User Guide 5.0 35The Installation Processexist on the network and communicate with each other, but only the first ten which attempt to access the Inte

Pagina 49 - Configuring Static Routes

The Installation Process36

Pagina 50 - View the Network Statistics

User Guide 5.0 37CHAPTER 3 Setting Up Your SOHO NetworkThe configuration instructions in this chapter assume that you are using Windows 98/ME. If this

Pagina 51 - Network Statistics

Configuring Your External Network38method to distribute IP addresses is to use Dynamic Host Configuration Protocol (DHCP). When you connect your compu

Pagina 52

User Guide 5.0 39Configuring Your External Network3 Scroll through the list of installed network components. Double-click the TCP/IP network component

Pagina 53 - Your Administrative

4Certifications and NoticesFCC CertificationThis device has been tested and found to comply with limits for a Class A digital device, pursuant to Part

Pagina 54 - Passphrase

Configuring Your External Network404 If “Obtain an IP Address Automatically” is selected, your computer is configured for dynamic DHCP. If “Obtain an

Pagina 55 - The System Security Page

User Guide 5.0 41Configuring Your External NetworkConfiguring the SOHO External network for static addressingIf you are assigned a static address, the

Pagina 56 - Setting up VPN Manager Access

Configuring Your External Network426 Save the changes.7 On most platforms, click OK until the Control Panel window closes. 8 Shut down and reboot the

Pagina 57 - These two settings

User Guide 5.0 43Configuring Your External Network4 From the Configuration Mode drop list, select Manual Configuration.5 Enter the TCP/IP settings you

Pagina 58 - Windows Platform

Configuring Your External Network44ISP to see if they use PPPoE. If you cannot find this information, contact your ISP and ask. You will need your PPP

Pagina 59 - The Upgrade page appears

User Guide 5.0 45Configuring Your External Network5 Enter the PPPoE login name supplied by your ISP.6 Enter the PPPoE password supplied by your ISP7Cl

Pagina 60

Configuring Your External Network46Release and renew the IP configurationRegardless of what type of addressing your computer used originally, it will

Pagina 61 - View the Configuration File

User Guide 5.0 47Configuring Your Trusted NetworkConfiguring Your Trusted NetworkOut of the box, the SOHO automatically uses DHCP to assign addresses

Pagina 62

Configuring Your Trusted Network483 Enter the IP address and the Subnet Mask in the appropriate fields.4 Disable the checkbox labeled Enable DHCP Serv

Pagina 63 - Firewall Settings

User Guide 5.0 49Configuring Static Routes(LAN). You can also mix computers with different operating systems on your network and they will pass traffi

Pagina 64 - Pre-configured Services

User Guide 5.0 5Taiwanese NoticeVCCI Notice Class A ITE

Pagina 65 - Creating a Custom Service

View the Network Statistics503Click the Add button.4 From the Type drop list, select either a Host or Network.5 Enter the IP address and the Gateway o

Pagina 66

User Guide 5.0 51View the Network StatisticsFollow these instructions to view this page:1 With your Web browser, go to the SOHO System Status page usi

Pagina 67 - Blocking External Sites

View the Network Statistics52

Pagina 68 - 207.68.172.246

User Guide 5.0 53CHAPTER 4 Your Administrative OptionsThe SOHO Administration page allows you to configure access to the unit, update the firmware fro

Pagina 69 - Firewall Options

The System Security Page54depth in the SOHO Remote Monument Guide located on our Web site:http://help.watchguard.com/documentation/default.aspSetting

Pagina 70 - 2Click the Submit button

User Guide 5.0 55The System Security PageFollow these steps to setup the SOHO System Passphrase:1 With your Web browser, go to the SOHO System Status

Pagina 71 - User Guide 5.0 71

Setting up VPN Manager Access567 Enter the System Passphrase again to confirm it in the appropriate field.8Click the Submit button.Setting up VPN Mana

Pagina 72 - attempt to make

User Guide 5.0 57Setting up VPN Manager Access3 Enable the checkbox labeled Enable VPN Manager Access.4 Enter the Status Passphrase in the appropriate

Pagina 73 - User Guide 5.0 73

Update Your Configuration from a Non-Windows Platform58Update Your Configuration from a Non-Windows PlatformIf you are managing your SOHO from a compu

Pagina 74 - Creating a virtual DMZ

User Guide 5.0 59Redeeming your SOHO upgrade certificatesthese software options is stored within the SOHO. Once you have purchased an upgrade option

Pagina 75 - 5Click the Submit button

6Declaration of Conformity

Pagina 76

Redeeming your SOHO upgrade certificates60Upgrade certificatesSeat LicensesThe SOHO can be upgraded to provide for more seats than are available with

Pagina 77 - What is Logging?

User Guide 5.0 61View the Configuration FileView the Configuration FileFrom this configuration page, you can view your SOHO configuration file as it a

Pagina 78 - Processor log host

View the Configuration File62

Pagina 79 - the Submit button

User Guide 5.0 63CHAPTER 5 Configuring Your Firewall SettingsFirewall settingsThe WatchGuard SOHO enables you to customize what is allowed both incomi

Pagina 80 - Setting a Syslog Host

Configuring Incoming and Outgoing Services64by the SOHO firewall. You can, however, selectively open your network to certain types of Internet connect

Pagina 81 - Setting the System Time

User Guide 5.0 65Configuring Incoming and Outgoing Services2 Locate the pre-configured service you wish to define, such as FTP, Web, or Telnet, then

Pagina 82

Configuring Incoming and Outgoing Services66custom service using either a TCP port, UDP port or specifying an IP protocol. You can also create a custo

Pagina 83 - User Guide 5.0 83

User Guide 5.0 67Blocking External Sites3 Beneath the Protocol Settings fields, select either TCP Port, UDP Port or Protocol from the drop list.The Cu

Pagina 84

Blocking External Sites68Follow these steps to configure blocked sites:1 From the navigation bar on the left side, select Firewall => Blocked Sites

Pagina 85 - WebBlocker

User Guide 5.0 69Firewall Options5Click the Submit button.Firewall OptionsThe SOHO firewall feature includes a few rule settings which are less specif

Pagina 86 - WebBlocker Users and Groups

User Guide 5.0 7WatchGuard® End-User License AgreementIMPORTANT - READ CAREFULLY BEFORE ACCESSING WATCHGUARD SOFTWAREThis WatchGuard End-User License

Pagina 87 - Bypassing the SOHO WebBlocker

Firewall Options70Ping requests received on the External NetworkYou can configure the SOHO to deny all ping packets which it may receive on the exter

Pagina 88

User Guide 5.0 71Firewall OptionsDenying FTP access to the Trusted Network interfaceYou can configure the SOHO to deny FTP access to Trusted interface

Pagina 89 - User Guide 5.0 89

Firewall Options72• SOHO supports SOCKS version 5 only.• It is a limited version of SOCKS and does not support authentication, nor does it support Dom

Pagina 90

User Guide 5.0 73Firewall Options• For the SOCKS proxy, enter the URL or IP address of the SOHO trusted network. The default IP address is 192.168.111

Pagina 91 - 4Click the Submit button

Creating a virtual DMZ74Follow these steps:1 Enable the checkbox labeled Log All Allowed Outbound Access.2Click the Submit button.Creating a virtual D

Pagina 92 - 7Click the Submit button

User Guide 5.0 75Creating a virtual DMZ3 Enable the checkbox labeled Enable pass through address.4 Enter the IP address to the pass through machine in

Pagina 93 - WebBlocker categories

Creating a virtual DMZ76

Pagina 94

User Guide 5.0 77CHAPTER 6 What is Logging?Logging is the act of recording “events” that occur at the SOHO interfaces. An event is any single activity

Pagina 95 - User Guide 5.0 95

Setting a WatchGuard Security Event Processor log host78The log messages may include time synchronizations between the SOHO and the WatchGuard Key Ser

Pagina 96 - Searching for blocked sites

User Guide 5.0 79Setting a WatchGuard Security Event Processor log host3 Enable the checkbox labeled Enable WatchGuard Security Event Processor Loggin

Pagina 97 - Private Networking

84. LIMITED WARRANTY. WATCHGUARD makes the following limited warranties for a period of ninety (90) days from the date you obtained the SOFTWARE P

Pagina 98 - What you will need

Setting a Syslog Host80Setting a Syslog HostThe SOHO can also be configured to transmit log entries to a Syslog host.Follow these steps to setup a Sys

Pagina 99 - IP Address Table (example):

User Guide 5.0 81Setting the System Time4 Enter the IP address of the Syslog server in the appropriate field.In our example, 206.253.208.100.5Click th

Pagina 100 - SOHO VPN tunnel

Setting the System Time82If you have decided to use the WatchGuard Time Server:3 Enable the option labeled Get Time From WatchGuard Time Server.Or, if

Pagina 101 - Frequently asked questions

User Guide 5.0 83Setting the System Time• Enable the checkbox labeled Set to GMT.If you want to have your log messages sync with your computer:• Click

Pagina 102

Setting the System Time84

Pagina 103 - View the VPN Statistics

User Guide 5.0 85CHAPTER 7 WatchGuard SOHO WebBlockerWatchGuard SOHO WebBlocker is an optional feature of the WatchGuard SOHO and SOHO|tc that provide

Pagina 104

How WebBlocker works86site, the SOHO queries the WatchGuard database and determines whether or not to block the site. The SOHO considers the following

Pagina 105 - Resources

User Guide 5.0 87Purchasing and enabling SOHO WebBlockerUsersThis feature allows you to create an individual user account, with a unique username and

Pagina 106 - Troubleshooting

Configuring the SOHO WebBlocker88Configuring the SOHO WebBlockerUse the WatchGuard SOHO Configuration pages to enable WebBlocker, create a full access

Pagina 107 - User Guide 5.0 107

User Guide 5.0 89Configuring the SOHO WebBlocker3 Enable the checkbox labeled Enable WebBlocking.4 Enter the full access password.The full access pass

Pagina 108

User Guide 5.0 9SUCH DAMAGES. THIS SHALL BE TRUE EVEN IN THE EVENT OF THE FAILURE OF AN AGREED REMEDY.5. UNITED STATES GOVERNMENT RESTRICTED RIGHTS.

Pagina 109 - Configuration

Configuring the SOHO WebBlocker90Create WebBlocker Groups and UsersFollow the instructions below to create WebBlocker Groups. If you wish to use a gl

Pagina 110

User Guide 5.0 91Configuring the SOHO WebBlocker4Click the Submit button.A new Groups page appears indicating the configuration changes have been acce

Pagina 111 - User Guide 5.0 111

Configuring the SOHO WebBlocker926 Enter a unique User name and Passphrase (remember to confirm the Passphrase). Use the Group drop down list to assi

Pagina 112 - VPN Management

User Guide 5.0 93WebBlocker categoriesWebBlocker categoriesWebBlocker relies on a URL database, the CyberNOT list, a service of CyberPatrol. The WebB

Pagina 113 - User Guide 5.0 113

WebBlocker categories94measures. Topic includes groups that advocate violence as a means to achieve their goals. It also includes pages devoted to “ho

Pagina 114 - Special Notices

User Guide 5.0 95WebBlocker categoriesof maiming, bloody figures, and indecent depiction of bodily functions.Violence/ProfanityPictures or text exposi

Pagina 115

Searching for blocked sites96adult personals, and sites devoted to selling pornographic CD-ROMs and videos.Full NudityPictures exposing any or all por

Pagina 116

User Guide 5.0 97CHAPTER 8 Configuring Virtual Private NetworkingThis chapter describes an optional feature of the WatchGuard SOHO: Virtual Private Ne

Pagina 117

What you will need98What you will need• One WatchGuard SOHO with VPN and an IPSec-compliant device. NOTEWhile you can create a SOHO to SOHO VPN, you

Pagina 118

User Guide 5.0 99What you will needIP Address Table (example):Item Description Assigned ByExternal IP AddressThe IP address that identifies the SOHO t

Comentarios a estos manuales

Sin comentarios