Watchguard Firebox X20E Guide de l'utilisateur

Naviguer en ligne ou télécharger Guide de l'utilisateur pour Manuels des logiciels Watchguard Firebox X20E. Watchguard Firebox X20E User guide Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 232
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs

Résumé du contenu

Page 1 - User Guide

WatchGuard®Firebox® X EdgeUser GuideFirebox X Edge - Firmware Version 7.0

Page 2 - Certifications and Notices

x WatchGuard Firebox X EdgeTHEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY

Page 3 - VCCI Notice Class A ITE

Configuring Firewall Settings72 WatchGuard Firebox X Edge2 From the navigation bar at left, select Firewall => Options.The Firewall Options page ap

Page 4 - Declaration of Conformity

Configuring Firewall OptionsUser Guide 73SOCKS implementation for the Firebox X EdgeThe Firebox X Edge functions as a SOCKS network proxy server. An a

Page 5 - End-User License Agreement

Configuring Firewall Settings74 WatchGuard Firebox X Edge NOTEThe Firebox X Edge uses port 1080 to communicate with a computer that uses a SOCKS-comp

Page 6

Configuring Firewall OptionsUser Guide 752 Click Submit.Enabling the MAC address override If your ISP has previously registered your computer’s MAC ad

Page 7 - User Guide vii

Configuring Firewall Settings76 WatchGuard Firebox X EdgeCreating an Unrestricted Pass ThroughThe Firebox® X Edge can allow traffic to flow from the e

Page 8

User Guide 77CHAPTER 6 Configuring LoggingAn event is any single activity that occurs at the Firebox® X Edge, such as denying a packet from passing th

Page 9 - User Guide ix

Configuring Logging78 WatchGuard Firebox X Edgebecause of a packet handling violation, duplicate messages, return error messages, and IPSec messages.E

Page 10

Logging to a WatchGuard Security Event Processor Log HostUser Guide 79to do this, see the WatchGuard System Manager User Guide. Then follow these inst

Page 11 - User Guide xi

Configuring Logging80 WatchGuard Firebox X EdgeLogging to a Syslog HostSyslog is a logging interface, originally developed for UNIX, but now used by a

Page 12

Setting the System TimeUser Guide 81Setting the System TimeFor each log entry, the Firebox® X Edge records the time from its system clock. You can sel

Page 13 - User Guide xiii

Copyright, Trademark, and Patent InformationUser Guide xi1. This software is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY;

Page 14

Configuring Logging82 WatchGuard Firebox X Edge4 (Optional) Select the Adjust for daylight savings time checkbox.5 Select the method you want to set s

Page 15 - User Guide xv

User Guide 83CHAPTER 7 Configuring WebBlockerAllowing network users to access any Web site they choose can lead to problems. An obvious one is loss of

Page 16

Configuring WebBlocker84 WatchGuard Firebox X EdgeHow WebBlocker WorksWebBlocker uses a database of Web site addresses that is owned and maintained by

Page 17 - User Guide xvii

Creating WebBlocker ProfilesUser Guide 852 From the navigation bar at left, select WebBlocker => Settings.The WebBlocker Settings page appears.3 Se

Page 18

Configuring WebBlocker86 WatchGuard Firebox X EdgeAfter you define profiles, you can apply them to users when you set up user accounts, as described i

Page 19 - User Guide xix

WebBlocker CategoriesUser Guide 87WebBlocker CategoriesThe WebBlocker database contains 14 categories.A Web site is added to a category only if the co

Page 20 - Limited Hardware Warranty

Configuring WebBlocker88 WatchGuard Firebox X EdgeSatanic/cult Pictures or text advocating devil worship, an affinity for evil, wickedness, or the adv

Page 21 - User Guide xxi

Allowing Certain Sites to Bypass WebBlockerUser Guide 89Sexual ActsPictures or text exposing anyone or anything involved in explicit sexual acts and/o

Page 22

Configuring WebBlocker90 WatchGuard Firebox X EdgeNOTE NOTEThis WebBlocker feature is applicable only for outbound requests to access Web sites. Y

Page 23 - Contents

Blocking Additional Web SitesUser Guide 91is corrupted with hacker code. Using the Denied Sites feature, you can make sure your employees do not acces

Page 24

xii WatchGuard Firebox X Edgetoo, but we suggest you first think carefully about whether this license or the ordinary General Public License is the be

Page 25 - User Guide xxv

Configuring WebBlocker92 WatchGuard Firebox X EdgeAllowing Internal Hosts to Bypass WebBlockerYou can define a list of internal hosts that bypass WebB

Page 26

User Guide 93CHAPTER 8 Configuring Virtual Private NetworksA virtual private network (VPN) allows secure connections between computers or networks in

Page 27 - User Guide xxvii

Configuring Virtual Private Networks94 WatchGuard Firebox X Edge• The static IP address of each Firebox X Edge external interface, the network address

Page 28

What You Need to Create a VPNUser Guide 95If the devices that connect through the VPN tunnel are not config-ured correctly, the VPN tunnel will not fu

Page 29 - Network Security

Configuring Virtual Private Networks96 WatchGuard Firebox X EdgeSample VPN Address Information TableItem Description Assigned ByExternal IP AddressThe

Page 30 - Connecting to the Internet

Using a DVCP server to manage your VPN tunnelsUser Guide 97Using a DVCP server to manage your VPN tunnelsDynamic VPN Configuration Protocol (DVCP) is

Page 31 - Protocols

Configuring Virtual Private Networks98 WatchGuard Firebox X EdgeSetting up management for a dynamic Edge deviceThis procedure is necessary for Edge de

Page 32 - Data packet

Setting Up Manual VPN TunnelsUser Guide 992 From the navigation bar at left, select VPN => Managed VPN.The Managed VPN page appears.3 Select the En

Page 33 - IP Addresses

Configuring Virtual Private Networks100 WatchGuard Firebox X Edge4 Type the Name and Shared Key for the VPN tunnel.The shared key is a passphrase used

Page 34 - Services

Setting Up Manual VPN TunnelsUser Guide 101NOTE NOTEThe Phase 1 settings must be the same on both devices.1 Select the negotiation mode for Phase

Page 35 - User Guide 7

Copyright, Trademark, and Patent InformationUser Guide xiiiThe precise terms and conditions for copying, distribution and modification follow. Pay cl

Page 36 - Firewalls

Configuring Virtual Private Networks102 WatchGuard Firebox X EdgeNOTE NOTEThe IKE Keep Alive feature is different from the VPN Keep Alive feature

Page 37 - X Edge and Your Network

VPN Keep AliveUser Guide 1037 Click Submit.VPN Keep AliveTo help keep the VPN tunnel open when there is no communication across it, enter the IP addre

Page 38 - 10 WatchGuard Firebox X Edge

Configuring Virtual Private Networks104 WatchGuard Firebox X Edge2 From the navigation bar at left, selectVPN => Keep Alive.The VPN Keep Alive page

Page 39 - Installing the

Frequently Asked QuestionsUser Guide 105addresses can change. A changing address prevents a connection between the two appliances. However, this issue

Page 40 - Installation Requirements

Configuring Virtual Private Networks106 WatchGuard Firebox X EdgeIs the Firebox X Edge compabtible with WatchGuard System Manager?Yes. The default Fir

Page 41 - User Guide 13

User Guide 107CHAPTER 9 Configuring the MUVPN ClientThe MUVPN client is a software application that is installed on a remote computer. This applicatio

Page 42 - Microsoft Windows NT

Configuring the MUVPN Client108 WatchGuard Firebox X EdgePreparing Remote Computers to Use the MUVPN ClientThe MUVPN client can be installed only on c

Page 43 - Macintosh

Preparing Remote Computers to Use the MUVPN ClientUser Guide 1092 Double-click the Network icon.The Network window appears.3 Make sure the Client for

Page 44 - Internet Explorer

Configuring the MUVPN Client110 WatchGuard Firebox X EdgeFrom the Windows desktop:1 Select Start => Settings => Control Panel.2 Double-click the

Page 45 - Connecting the Firebox X Edge

Preparing Remote Computers to Use the MUVPN ClientUser Guide 1117 Click the WINS Configuration tab and then select the Enable WINS Resolution checkbox

Page 46 - 18 WatchGuard Firebox X Edge

xiv WatchGuard Firebox X Edgethen this License, and its terms, do not apply to those sections when you distribute them as separate works. But when yo

Page 47 - User Guide 19

Configuring the MUVPN Client112 WatchGuard Firebox X Edgemodem is not available, you can select a serial cable between two computers.8 Select the mod

Page 48 - 20 WatchGuard Firebox X Edge

Preparing Remote Computers to Use the MUVPN ClientUser Guide 113From the Windows desktop:1 Select Start => Settings => Network and Dial-up Conne

Page 49 - 255.255.255.0

Configuring the MUVPN Client114 WatchGuard Firebox X EdgeConfiguring the WINS and DNS settingsThe remote computer must be able to communicate with the

Page 50 - 22 WatchGuard Firebox X Edge

Preparing Remote Computers to Use the MUVPN ClientUser Guide 115These components must be installed before the MUVPN Client will function correctly on

Page 51 - Entering PPPoE settings

Configuring the MUVPN Client116 WatchGuard Firebox X Edge2 Double-click the Client network component.The Select Network Protocol window appears.3 Sele

Page 52 - PPPoE Address Settings

Installing and Configuring the MUVPN ClientUser Guide 11711 Click Cancel to close the connection window.Installing and Configuring the MUVPN ClientThe

Page 53 - LiveSecurity Service

Configuring the MUVPN Client118 WatchGuard Firebox X Edge11 The InstallShield wizard searches for a user profile file. Click Next to skip this step. T

Page 54 - JavaScript enabled

Installing and Configuring the MUVPN ClientUser Guide 1194 Type a unique name for the new connection.If this will be a unique policy for a specific us

Page 55 - Management Basics

Configuring the MUVPN Client120 WatchGuard Firebox X EdgeUsing this option also allows the MUVPN client to access any networks across a VPN that the F

Page 56 - 1 Start Internet Explorer

Installing and Configuring the MUVPN ClientUser Guide 1213 Select Aggressive Mode. Make sure the Enable Perfect Forward Secrecy (PFS) checkbox is clea

Page 57 - Logging in for the first time

Copyright, Trademark, and Patent InformationUser Guide xvexecution displays copyright notices, you must include the copyright notice for the Library a

Page 58 - Configuration Overview

Configuring the MUVPN Client122 WatchGuard Firebox X Edge6 Clear the Allow to Specify Internal Network Address checkbox. Click OK.It is not necessary

Page 59 - Network Page

Installing and Configuring the MUVPN ClientUser Guide 12310 Select Any from the Name drop-down list.This is the default setting.11 Click Pre-Shared Ke

Page 60 - Firebox Users Page

Configuring the MUVPN Client124 WatchGuard Firebox X EdgeEdge and must match exactly as described below. Phase 2 settings must match the settings of t

Page 61 - Administration Page

Installing and Configuring the MUVPN ClientUser Guide 1257 Select Diffie-Hellman Group 1 from the Key Group drop-down list.8 Expand Key Exchange (Phas

Page 62 - Firewall Page

Configuring the MUVPN Client126 WatchGuard Firebox X EdgeUninstalling the MUVPN clientFollow these directions to uninstall the MUVPN client. WatchGuar

Page 63 - Logging Page

Enabling MUVPN Access for a User AccountUser Guide 127Enabling MUVPN Access for a User Account1 Type the IP address of the trusted network in your bro

Page 64 - WebBlocker Page

Configuring the MUVPN Client128 WatchGuard Firebox X EdgeConfiguring the Firebox for MUVPN Clients Using Pocket PCTo create a MUVPN tunnel between the

Page 65 - Wizards Page

Connecting and Disconnecting the MUVPN ClientUser Guide 129The MUVPN Security Policy is deactivated. This icon may appear if the Windows operating sys

Page 66 - 5 Click Update

Configuring the MUVPN Client130 WatchGuard Firebox X EdgeThe MUVPN client has established at least one secure, MUVPN tunnel connection. The red and gr

Page 67 - Factory Default Settings

Monitoring the MUVPN Client ConnectionUser Guide 131From the New Program alert window:1 Select the Remember this answer the next time I use this progr

Page 68 - Rebooting the Firebox

xvi WatchGuard Firebox X Edgethese terms and conditions. You may not impose any further restrictions on the recipients' exercise of the rights g

Page 69 - Remote reboot

Configuring the MUVPN Client132 WatchGuard Firebox X Edge2 Select Log Viewer.The Log Viewer window appears.Using Connection MonitorThe Connection Moni

Page 70 - 42 WatchGuard Firebox X Edge

The ZoneAlarm Personal FirewallUser Guide 133• An animated black line underneath a key indicates that the client is processing secure IP traffic for t

Page 71 - Network Settings

Configuring the MUVPN Client134 WatchGuard Firebox X EdgeFor more information about the features and configuration of ZoneAlarm, refer to the ZoneAlar

Page 72 - 44 WatchGuard Firebox X Edge

The ZoneAlarm Personal FirewallUser Guide 135Shutting down ZoneAlarmFrom the Windows desktop system tray:1 Right-click the ZoneAlarm icon shown at rig

Page 73 - User Guide 45

Configuring the MUVPN Client136 WatchGuard Firebox X Edgecould be shared by other programs on the system. Click Yes to All to completely remove all of

Page 74 - 5 Click Submit

Troubleshooting TipsUser Guide 137tant that you enter this information correctly, just as you would at the office. Windows stores the information for

Page 75 - If your ISP uses PPPoE

Configuring the MUVPN Client138 WatchGuard Firebox X Edge4 Click OK.The mapped drive appears in the My Computer window. Even if you select the Reconne

Page 76 - 11 Click Submit

User Guide 139CHAPTER 10 Managing the Firebox® X EdgeFirebox® X Edge provides a number of ways for you to manage your network and users, such as:• Vie

Page 77 - User Guide 49

Managing the Firebox® X Edge140 WatchGuard Firebox X Edgetion on the sessions currently active on your Firebox. You can also see information on the us

Page 78 - 50 WatchGuard Firebox X Edge

Configuring Global SettingsUser Guide 141• The name of the user• Whether Internet access is allowed for the user• Whether the user has full administra

Page 79 - User Guide 51

Copyright, Trademark, and Patent InformationUser Guide xviiCopyright (C) 1989, 1991 Free Software Foundation, Inc. 59 Temple Place - Suite 330, Bosto

Page 80 - Assigning static IP addresses

Managing the Firebox® X Edge142 WatchGuard Firebox X Edge2 From the navigation bar at left, select Firebox => Settings.The Settings page appears.3

Page 81 - Enabling the optional network

Adding or Editing a User AccountUser Guide 143Preferred(Default value) If the virtual adapter is already in use or otherwise unavailable, address assi

Page 82 - 54 WatchGuard Firebox X Edge

Managing the Firebox® X Edge144 WatchGuard Firebox X Edge3 Under Local User Accounts, click Add. The New User page appears with the Settings tab visib

Page 83 - User Guide 55

Adding or Editing a User AccountUser Guide 145To create a read-only user account, edit the User Account. Use the Administrative Access drop-down list

Page 84 - 56 WatchGuard Firebox X Edge

Managing the Firebox® X Edge146 WatchGuard Firebox X Edge• the Firebox administrator uses the Firebox Users page to end the session;• the user ends th

Page 85 - Configuring Static Routes

Setting up VPN Manager AccessUser Guide 147Follow these instructions to use HTTP instead of HTTPS:1 Type the IP address of the trusted network in your

Page 86 - 6 Click Submit

Managing the Firebox® X Edge148 WatchGuard Firebox X Edge2 From the navigation bar at left, selectAdministration => VPN Manager Access.The VPN Mana

Page 87 - Viewing Network Statistics

Updating the FirmwareUser Guide 149must update your firmware with the second procedure because those operating systems cannot run Windows executable f

Page 88 - Dynamic DNS?

Managing the Firebox® X Edge150 WatchGuard Firebox X Edge3 From the navigation bar at left, select Administration => Update.The Administration Page

Page 89 - User Guide 61

Configuring Additional OptionsUser Guide 1517 From the navigation bar at left, select Administration => Upgrade.The Upgrade page appears.8 Paste th

Page 90 - 62 WatchGuard Firebox X Edge

xviii WatchGuard Firebox X EdgeYou may charge a fee for the physical act of transferring a copy, and you may at your option offer warranty protection

Page 91 - User Guide 63

Managing the Firebox® X Edge152 WatchGuard Firebox X EdgeManual VPNThe manual VPN feature allows you to set up VPN tunnels manually. For more informat

Page 92 - 64 WatchGuard Firebox X Edge

Viewing the Configuration FileUser Guide 153

Page 93 - Settings

Managing the Firebox® X Edge154 WatchGuard Firebox X Edge

Page 94 - 4 Click Submit

User Guide 155APPENDIX A Firebox® X Edge HardwareThe WatchGuard® Firebox® X Edge is a firewall for small businesses and branch or remote offices. Pac

Page 95 - User Guide 67

156 WatchGuard Firebox X Edge• An AC adapter (12 V)• One straight-through Ethernet cableHardware SpecificationsHardware DescriptionThe Firebox® X Edge

Page 96 - 68 WatchGuard Firebox X Edge

Hardware DescriptionUser Guide 157Front panelThe front panel of the Firebox X Edge has 24 indicator lights to pro-vide link and status information. Th

Page 97 - User Guide 69

158 WatchGuard Firebox X EdgeStatusIndicates that a management connection has been made. This light turns off a few minutes after you close the browse

Page 98 - Blocking External Sites

Hardware DescriptionUser Guide 159Power inputConnect the power input to a power supply using the 12-volt AC adapter supplied with the Firebox X Edge.

Page 99

160 WatchGuard Firebox X Edge

Page 100 - Responding to ping requests

User Guide 161APPENDIX B GlossaryThis glossary contains a list of terms, abbreviations, and acronyms fre-quently used when discussing networks, firewa

Page 101 - User Guide 73

Copyright, Trademark, and Patent InformationUser Guide xixIf distribution of executable or object code is made by offering access to copy from a desig

Page 102 - 74 WatchGuard Firebox X Edge

162 WatchGuard Firebox X Edgeaddress space probeAn intrusion measure in which a hacker sequentially attacks IP addresses. These probes are usually att

Page 103 - 3 Click Submit

User Guide 163asymmetric keysA separate but integrated user key pair, composed of one public key and one private key. Each key is one way, meaning tha

Page 104 - 76 WatchGuard Firebox X Edge

164 WatchGuard Firebox X Edgeblock cypherA symmetric cipher operating on blocks of plain text and cipher text, usually 64 bits.blocked portA security

Page 105 - Configuring Logging

User Guide 165cable segmentA section of network cable separated by hubs, routers, or bridges to create a subnet.cascadeA command that arranges windows

Page 106 - Processor Log Host

166 WatchGuard Firebox X EdgeCIDR (Classless Inter-Domain Routing)A routing mechanism designed to deal with the exhaustion of Class B network addresse

Page 107 - User Guide 79

User Guide 167compression functionA function that takes a fixed-size input and returns a shorter, fixed-sized output.connected enterpriseA company or

Page 108 - Logging to a Syslog Host

168 WatchGuard Firebox X EdgecryptanalysisThe art or science of transferring cipher text into plain text without initial knowledge of the key used to

Page 109 - Setting the System Time

User Guide 169defaultA predefined setting that is built into a program and is used when an alternative setting is not specified.default packet handlin

Page 110 - Setting time manually

170 WatchGuard Firebox X EdgedimmedThe grayed appearance of a command or option that is unavailable.disarmedThe state of a Firebox when it is not acti

Page 111 - WebBlocker

User Guide 171dynamic NAT(Also known as IP masquerading or port address translation) A method of hiding network addresses from hosts on the external o

Page 112 - How WebBlocker Works

ii WatchGuard Firebox X EdgeCertifications and NoticesFCC CertificationThis appliance has been tested and found to comply with limits for a Class A di

Page 113 - Creating WebBlocker Profiles

xx WatchGuard Firebox X Edgedecision will be guided by the two goals of preserving the free status of all derivatives of our free software and of prom

Page 114 - 86 WatchGuard Firebox X Edge

172 WatchGuard Firebox X Edgeexternal interfaceAn interface connected to the external network that presents the security challenge, typically the Inte

Page 115 - WebBlocker Categories

User Guide 173fingerprintA unique identifier for a key that is obtained by hashing specific portions of the key data.FIPS (Federal Information Process

Page 116 - Sexual Acts

174 WatchGuard Firebox X Edgehash codeA unique, mathematical summary of a document that serves to identify the document and its contents. Any change i

Page 117 - Smithsonian

User Guide 175host routeA setup in which an additional router is behind the Firebox and one host is behind that router. A host route must be configure

Page 118 - Blocking Additional Web Sites

176 WatchGuard Firebox X EdgeIKE (Internet Key Exchange)A protocol used with IPSec virtual private networks. Automates the process of negotiating keys

Page 119 - User Guide 91

User Guide 177Intrusion Detection System (IDS)A class of networking products devoted to detecting, monitoring, and blocking attacks from hackers. IDSs

Page 120 - 92 WatchGuard Firebox X Edge

178 WatchGuard Firebox X EdgeISAKMP (Internet Security Association Key Management Protocol)Defines the procedures for authenticating a communicating p

Page 121 - Private Networks

User Guide 179key managementThe process and procedure for safely storing and distributing accurate cryptographic keys; the overall process of generati

Page 122 - 94 WatchGuard Firebox X Edge

180 WatchGuard Firebox X Edgemanagement stationThe computer on which the WatchGuard Firebox System Manager and Policy Manager runs; sometimes referred

Page 123 - Special considerations

User Guide 181MD5 (Message Digest 5)An improved, more complex version of MD4, but still a 128-bit, one-way hash function.message digestA number that i

Page 124 - VPN Address Information Table

Limited Hardware WarrantyUser Guide xxiAND YOU HEREBY WAIVE, DISCLAIM AND RELEASE ANY AND ALL OTHER WARRANTIES, OBLIGATIONS AND LIABILITIES OF WATCHGU

Page 125

182 WatchGuard Firebox X Edgesubnetting is in effect. Some systems require the netmask to be an even number of bits.network adaptor, network interface

Page 126 - The Managed VPN page appears

User Guide 183optional interfaceAn interface that connects to a second secured network, typically any network of servers provided for public access.op

Page 127 - Setting Up Manual VPN Tunnels

184 WatchGuard Firebox X EdgePCMCIA (Personal Computer Memory Code International Association) cardA standard compact physical interface used in person

Page 128 - Phase 1 settings

User Guide 185PLIP (Parallel Line Internet Protocol)A protocol for exchanging IP packets over a parallel cable.Plug and PlayA standard in the personal

Page 129 - User Guide 101

186 WatchGuard Firebox X EdgePretty Good Privacy (PGP)An application and protocol (RFC 1991) for secure email and file encryption. PGP uses a variety

Page 130 - Phase 2 settings

User Guide 187pseudo-random numberA number that results from applying randomizing algorithms to input derived from the computing environment, such as

Page 131 - VPN Keep Alive

188 WatchGuard Firebox X Edgerelated networksNetworks on the same physical wire as the Firebox interfaces but with network addresses that belong to an

Page 132 - Frequently Asked Questions

User Guide 189scalable architectureSoftware and/or hardware constructed so that, after configuring a single machine, the same configuration can be pro

Page 133 - Why is ping not working?

190 WatchGuard Firebox X EdgesegmentOne or more nodes in a network. Segments are connected to subnets by hubs and repeaters.self-extracting fileA comp

Page 134 - System Manager?

User Guide 191signTo apply a signature.signatureA digital code created with a private key.single sign-onA sign-on in which one logon provides access t

Page 135 - MUVPN Client

xxii WatchGuard Firebox X EdgeAbbreviations Used in this Guide3DES Triple Data Encryption StandardBOVPN Branch Office Virtual Private NetworkDES Data

Page 136 - Windows 98/ME setup

192 WatchGuard Firebox X EdgeSSLSee Secure Sockets Layer.stanceThe policy of a firewall regarding the default handling of IP packets. Stance dictates

Page 137 - Installing Dial-Up Networking

User Guide 193syslogAn industry-standard protocol used for capturing log information for devices on a network. Syslog support is included in Unix-base

Page 138 - 110 WatchGuard Firebox X Edge

194 WatchGuard Firebox X EdgetooltipA name or phrase that appears when the mouse pointer pauses over a button or icon.topologyA wiring configuration u

Page 139 - Windows NT setup

User Guide 195URL (Universal Resource Locator)The user-friendly address that identifies the location of a Web site such as http://www.watchguard.com.v

Page 140 - Windows 2000 setup

196 WatchGuard Firebox X EdgeWebBlockerAn optional WatchGuard software module that blocks users behind the Firebox from accessing undesirable Web site

Page 141 - Networks

User Guide 197IndexAAdd Gateway page 99Add Route page 58Administration page 33administrator account 145Allowed Sites pages 90Automatically restore los

Page 142 - Windows XP setup

198 WatchGuard Firebox X EdgeDenied Sites page 91DHCPdescribed 5, 45setting the Firebox to use 22setting your computer to use 20DHCP address reservati

Page 143 - Component

User Guide 199Firewall Options page 72Firewall page 34firewalls, described 8firmware, updating 148FTP access, denying to the trusted interface 72Hhard

Page 144 - 116 WatchGuard Firebox X Edge

200 WatchGuard Firebox X Edgepreparing remote computers for 108–117troubleshooting 136–138uninstalling 126MUVPN Clients upgrade 151My Identity setting

Page 145 - Installing the MUVPN client

User Guide 201Upgrade 151VPN 37VPN Keep Alive 104VPN Manager Access 147, 148VPN Statistics 104WAN Failover 62WatchGuard Security Event Processor Loggi

Page 146 - Configuring the MUVPN client

User Guide xxiiiContentsCHAPTER 1 Introduction to Network Security ...1Network Security ...

Page 147 - 5 Select the Secure option

202 WatchGuard Firebox X Edgesystem configuration pages. See configuration pagessystem requirements 108System Security page 147System Status page 21,

Page 148 - Client” on page 108

User Guide 203WWAN Failoverconfiguring 62described 61, 152WAN Failover page 62WAN ports 158WAN1 port 61WAN2 port 61WatchGuard Security Event Processor

Page 149 - 4 Select My Identity

204 WatchGuard Firebox X Edge

Page 150 - 122 WatchGuard Firebox X Edge

xxiv WatchGuard Firebox X EdgeDisabling the HTTP Proxy Setting ...15Connecting the Firebox X Edge ...

Page 151 - 12 Click Enter Key

User Guide xxvChanging the IP address of the trusted network ...49Configuring the Firebox as a DHCP server ...

Page 152 - This is the default setting

xxvi WatchGuard Firebox X EdgeCHAPTER 7 Configuring WebBlocker ...83How WebBlocker Works ...

Page 153

User Guide xxviiDisconnecting the MUVPN client ...131Monitoring the MUVPN Client Connection ...

Page 154 - Uninstalling the MUVPN client

xxviii WatchGuard Firebox X EdgeIndex...197

Page 155 - User Guide 127

User Guide 1CHAPTER 1 Introduction to Network SecurityCongratulations on your purchase of the WatchGuard Firebox® X Edge. Your new security device pro

Page 156 - Pocket PC

Certifications and NoticesUser Guide iiiVCCI Notice Class A ITE

Page 157 - User Guide 129

Introduction to Network Security2 WatchGuard Firebox X EdgeComputer security must always be kept up-to-date. Intruders are always discovering new vuln

Page 158 - 130 WatchGuard Firebox X Edge

ProtocolsUser Guide 3share the same bandwidth. Because of this "shared-medium" topol-ogy, cable modem users might experience somewhat slower

Page 159 - Using Log Viewer

Introduction to Network Security4 WatchGuard Firebox X EdgeInternet, the file is divided into chunks of data. Each chunk, or packet, is separately num

Page 160 - Using Connection Monitor

IP AddressesUser Guide 5IP AddressesIP addresses are like street addresses—when you want to send some information to someone, you must first know his

Page 161 - User Guide 133

Introduction to Network Security6 WatchGuard Firebox X EdgeAbout PPPoESome ISPs assign the IP addresses through Point-to-Point Protocol over Ethernet

Page 162 - 134 WatchGuard Firebox X Edge

PortsUser Guide 7Although some services are essential, they can also be a security risk. To send and receive data, you must “open a door” in your comp

Page 163 - Uninstalling ZoneAlarm

Introduction to Network Security8 WatchGuard Firebox X EdgeFirewallsA firewall divides your internal network from the Internet to reduce this danger.

Page 164 - Troubleshooting Tips

Firebox® X Edge and Your NetworkUser Guide 9needs.Firewalls are implemented in both hardware and software, or a com-bination of both. Firewalls are fr

Page 165 - How do I map a network drive?

Introduction to Network Security10 WatchGuard Firebox X Edge

Page 166 - 4 Click OK

User Guide 11CHAPTER 2 Installing the Firebox® X EdgeTo install the WatchGuard® Firebox® X Edge in your network, use this procedure:• Identify and rec

Page 167 - Firebox® X Edge

iv WatchGuard Firebox X EdgeDeclaration of Conformity

Page 168 - 140 WatchGuard Firebox X Edge

Installing the Firebox® X Edge12 WatchGuard Firebox X EdgePackage ContentsMake sure that the Firebox® X Edge package includes:• The Firebox X Edge Qui

Page 169 - Configuring Global Settings

Identifying Your Network SettingsUser Guide 13• The Firebox X Edge serial number. Find this number on the bottom of the Firebox.You use the serial num

Page 170 - The Settings page appears

Installing the Firebox® X Edge14 WatchGuard Firebox X Edgenetwork address translation (NAT). You must get a public IP address and disable NAT on your

Page 171 - User Guide 143

Disabling the HTTP Proxy SettingUser Guide 15Microsoft Windows 98 or ME1 Click Start => Run. 2 At the MS-DOS prompt, type winipcfg and then press t

Page 172 - 144 WatchGuard Firebox X Edge

Installing the Firebox® X Edge16 WatchGuard Firebox X Edgeinformation. Many opensource browsers automatically disable the HTTP proxy feature by defaul

Page 173 - Resetting the user list

Connecting the Firebox X EdgeUser Guide 17Connecting the Firebox X EdgeUse this procedure to connect your Firebox® X Edge Ethernet and power cables:1

Page 174 - Management

Installing the Firebox® X Edge18 WatchGuard Firebox X Edge6 Find the AC adapter supplied with your Firebox. Connect the AC adapter to the Firebox and

Page 175 - Setting up VPN Manager Access

Connecting to the System Configuration PagesUser Guide 19• A straight-through Ethernet cable to connect each hub to the Firebox X Edge.To connect more

Page 176 - Updating the Firmware

Installing the Firebox® X Edge20 WatchGuard Firebox X EdgeA factory default Firebox allows HTTP traffic on port 80. After you set the administrator pa

Page 177 - Method 2

Connecting to the System Configuration PagesUser Guide 21use DHCP. You must use an IP address on the same network as the Firebox X Edge trusted interf

Page 178 - Activating Upgrade Options

Notice to UsersUser Guide vNotice to UsersInformation in this guide is subject to change without notice. Companies, names, and data used in examples h

Page 179 - Upgrade options

Installing the Firebox® X Edge22 WatchGuard Firebox X Edge2 In the Address bar, type the Firebox trusted interface IP address which is https://192.168

Page 180 - 152 WatchGuard Firebox X Edge

Configuring the External InterfaceUser Guide 232 From the navigation bar on the left side, click the + symbol to the left of Network. Click External.3

Page 181 - User Guide 153

Installing the Firebox® X Edge24 WatchGuard Firebox X EdgePPPoE Address SettingsFor more information in PPPoE, see “About PPPoE” on page 6. To configu

Page 182 - 154 WatchGuard Firebox X Edge

Registering Your Firebox and Activating LiveSecurity ServiceUser Guide 255 Type the PPPoE login name and domain as well as the PPPoE password supplied

Page 183 - Hardware

Installing the Firebox® X Edge26 WatchGuard Firebox X Edgehttp://www.watchguard.com/activateNOTE NOTETo activate the LiveSecurity Service, your br

Page 184 - Hardware Description

User Guide 27CHAPTER 3 Configuration and Management BasicsConfiguration is the process of customizing the WatchGuard® Firebox® X Edge to meet the spec

Page 185 - Front panel

Configuration and Management Basics28 WatchGuard Firebox X Edge“Type the IP address of the trusted network in your browser window to connect to the Sy

Page 186 - Back view

Navigating the Configuration PagesUser Guide 29Using the navigation barOn the left side of the System Status page is a navigation bar that provides ac

Page 187 - Side panels

Configuration and Management Basics30 WatchGuard Firebox X EdgeConfiguration OverviewThe Firebox X Edge system configuration pages are grouped by func

Page 188 - 160 WatchGuard Firebox X Edge

Configuration OverviewUser Guide 31Network PageThe Network page shows the configuration of each network inter-face. It also shows any configured route

Page 189 - Glossary

vi WatchGuard Firebox X Edge(C) In addition to the copies described in Section 2(A), you may make a single copy of the SOFTWARE PRODUCT for backup or

Page 190 - Address Resolution Protocol

Configuration and Management Basics32 WatchGuard Firebox X EdgeFirebox Users PageThe Firebox Users page shows statistics on the active sessions and de

Page 191 - User Guide 163

Configuration OverviewUser Guide 33Administration PageThe Administration page shows whether the Firebox uses HTTP or HTTPS for its configuration pages

Page 192 - Web browser

Configuration and Management Basics34 WatchGuard Firebox X EdgeFirewall PageThe Firewall page shows the incoming and outgoing services, blocked sites,

Page 193 - User Guide 165

Configuration OverviewUser Guide 35Logging PageThe Logging page shows the current event log, status of WSEP and Syslog logging, and the system time. I

Page 194 - Internet address class

Configuration and Management Basics36 WatchGuard Firebox X EdgeWebBlocker PageThe WebBlocker page shows the WebBlocker settings, profiles, allowed sit

Page 195 - System Manager

Configuration OverviewUser Guide 37VPN PageThe VPN page shows information on managed VPNs, manual VPN gateways, and echo hosts along with buttons to c

Page 196 - 168 WatchGuard Firebox X Edge

Configuration and Management Basics38 WatchGuard Firebox X EdgeUpdating Firebox X Edge SoftwareOne benefit of your LiveSecurity® Service is ongoing so

Page 197 - Triple DES

Factory Default SettingsUser Guide 39Factory Default SettingsThe term factory default settings refers to how the Firebox® X Edge is configured when yo

Page 198 - 170 WatchGuard Firebox X Edge

Configuration and Management Basics40 WatchGuard Firebox X EdgeResetting the Firebox to the factory default settingsYou may have occasion to reset the

Page 199 - User Guide 171

Rebooting the FireboxUser Guide 41Using the Web browser1 Type the IP address of the trusted network in your browser window to connect to the System St

Page 200 - 172 WatchGuard Firebox X Edge

Copyright, Trademark, and Patent InformationUser Guide viiINABILITY TO USE THE SOFTWARE PRODUCT, EVEN IF WATCHGUARD HAS BEEN ADVISED OF THE POSSIBILIT

Page 201 - Control Center

Configuration and Management Basics42 WatchGuard Firebox X Edge

Page 202 - 174 WatchGuard Firebox X Edge

User Guide 43CHAPTER 4 Changing Your Network SettingsA primary task in setting up your WatchGuard® Firebox® X Edge is configuring the network interfac

Page 203 - Intrusion Detection System

Changing Your Network Settings44 WatchGuard Firebox X EdgeThe Network Interface Wizard consists of the following steps:Step 1: WelcomeThe first screen

Page 204 - 176 WatchGuard Firebox X Edge

Configuring the External NetworkUser Guide 45Step 9: SummaryThe wizard’s last screen displays a summary of the settings you have made using the wizard

Page 205 - See dynamic NAT

Changing Your Network Settings46 WatchGuard Firebox X EdgeIf your service provider uses DHCPThe default configuration sets the Firebox X Edge to get t

Page 206 - 178 WatchGuard Firebox X Edge

Configuring the External NetworkUser Guide 47If your ISP uses PPPoEIf your ISP assigns IP addresses through PPPoE, your PPPoE login name and password

Page 207 - User Guide 179

Changing Your Network Settings48 WatchGuard Firebox X Edge7 Type the PPPoE password supplied by your ISP.8 Type the time delay before inactive TCP con

Page 208 - Bandwidth Meter

Configuring the Trusted NetworkUser Guide 49Changing the IP address of the trusted networkSometimes it is necessary to change the trusted network addr

Page 209 - User Guide 181

Changing Your Network Settings50 WatchGuard Firebox X EdgeTo configure the Firebox as a DHCP server:1 If you have not already done so, use your browse

Page 210 - 182 WatchGuard Firebox X Edge

Configuring the Trusted NetworkUser Guide 51Setting DHCP Address ReservationsYou can bind a static IP address to a specific hardware device by way of

Page 211 - User Guide 183

viii WatchGuard Firebox X EdgeRealNetworks, RealAudio, and RealVideo are either a registered trademark or trademark of RealNetworks, Inc. in the Unite

Page 212 - Public Key Infrastructure

Changing Your Network Settings52 WatchGuard Firebox X EdgeTo configure the Firebox as a DHCP relay agent:1 If you have not already done so, use your b

Page 213

Configuring the Optional NetworkUser Guide 53over the same LAN. If you mix computers with different operating systems on your network, they pass traff

Page 214 - 186 WatchGuard Firebox X Edge

Changing Your Network Settings54 WatchGuard Firebox X Edge2 From the navigation bar at left, select Network => Optional.The Optional Network Config

Page 215

Configuring the Optional NetworkUser Guide 55Configuring DHCP on the optional networkJust as with the trusted network, you can use the Firebox as eith

Page 216 - 188 WatchGuard Firebox X Edge

Changing Your Network Settings56 WatchGuard Firebox X Edge4 Type the WINS Server address, DNS Server primary address, DNS Server secondary address, an

Page 217 - User Guide 189

Configuring Static RoutesUser Guide 57NOTE NOTEAll changes to the Optional Network Configuration page require that you click Submit and then reboo

Page 218 - 190 WatchGuard Firebox X Edge

Changing Your Network Settings58 WatchGuard Firebox X Edge2 From the navigation bar at left, select Network => Routes.The Routes page appears.3 Cli

Page 219 - User Guide 191

Viewing Network StatisticsUser Guide 59Viewing Network StatisticsThe Firebox® X Edge Network Statistics page gives information about network performan

Page 220 - Secure Sockets Layer

Changing Your Network Settings60 WatchGuard Firebox X EdgeOr, see the following FAQs on the WatchGuard Technical Support site at: https://www.watchgu

Page 221 - Transport Layer Security

Enabling the WAN Failover OptionUser Guide 61Enabling the WAN Failover OptionThe WAN Failover option adds redundant support for the external interface

Page 222 - 194 WatchGuard Firebox X Edge

Copyright, Trademark, and Patent InformationUser Guide ix 1. Redistributions of source code must retain the copyright notice, this list of conditions

Page 223 - User Guide 195

Changing Your Network Settings62 WatchGuard Firebox X Edgeis used. If the WAN1 port is not available, the Firebox connects through the WAN2 port.To co

Page 224 - 196 WatchGuard Firebox X Edge

Enabling the WAN Failover OptionUser Guide 634 Select the Enable failover using the Ethernet (WAN2) interface checkbox.5 From the drop-down list, sele

Page 225

Changing Your Network Settings64 WatchGuard Firebox X Edge

Page 226

User Guide 65CHAPTER 5 Configuring Firewall SettingsThe firewall configuration settings of the WatchGuard® Firebox® X Edge control the flow of traffic

Page 227

Configuring Firewall Settings66 WatchGuard Firebox X Edgepare the value of access to each service against the security risk caused by that service.Whe

Page 228

Configuring Incoming and Outgoing ServicesUser Guide 67Creating a custom service using the wizardIf you need to allow a service that is not listed in

Page 229

Configuring Firewall Settings68 WatchGuard Firebox X Edgeto expose a service such as HTTP (a Web server) to the external network.Step 6: SummaryThe wi

Page 230

Filtering Outgoing Traffic to the Optional NetworkUser Guide 695 In the fields separated by the word To, either type a port number and leave the secon

Page 231

Configuring Firewall Settings70 WatchGuard Firebox X Edge4 Click Submit.You can also select the Disable traffic filters checkbox to allow all services

Page 232 - 204 WatchGuard Firebox X Edge

Configuring Firewall OptionsUser Guide 71• Prevents the transmission of all packets from the external network to the trusted networkYou can change the

Commentaires sur ces manuels

Pas de commentaire