Waters Network Systems ProSwitch-Quad Series Especificaciones Pagina 1

Busca en linea o descarga Especificaciones para Los conmutadores de red Waters Network Systems ProSwitch-Quad Series. Waters Network Systems ProSwitch-Quad Series Specifications Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 469
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 0
350 East Plumeria Drive
San Jose, CA 95134
USA
April 2013
202-10536-05
ProSAFE Gigabit Quad WAN SSL
VPN Firewall SRX5308
Reference Manual
Vista de pagina 0
1 2 3 4 5 6 ... 468 469

Indice de contenidos

Pagina 1 - VPN Firewall SRX5308

350 East Plumeria DriveSan Jose, CA 95134USAApril 2013202-10536-05ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Reference Manual

Pagina 2 - Revision History

10ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN to DMZ Logs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44

Pagina 3

LAN Configuration100ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 56. 2. Modify the settings as described in Table 17 on page 98.3. Clic

Pagina 4 - Contents

LAN Configuration101 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 57. 3. Select the radio button next to the group name that you want to c

Pagina 5 - Chapter 3 LAN Configuration

LAN Configuration102ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: The saved binding is also displayed on the IP/MAC Binding screen (see Figu

Pagina 6

LAN Configuration103 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCPv6 Server OptionsThe IPv6 clients in the LAN can autoconfigure their own IPv

Pagina 7

LAN Configuration104ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Stateful DHCPv6 ServerThe IPv6 clients in the LAN obtain an interface IP address

Pagina 8 - Chapter 10 Troubleshooting

LAN Configuration105 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Enter the settings as described in the following table. The IPv6 address pool

Pagina 9

LAN Configuration106ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your changes.IPv6 LAN Address PoolsIf you configure a sta

Pagina 10

LAN Configuration107 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 59. 2. Enter the settings as described in the following table:3. Click A

Pagina 11 - Introduction

LAN Configuration108ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Delegation table to enable the DHCPv6 server to assign these prefixes to its IPv

Pagina 12 - Key Features and Capabilities

LAN Configuration109 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the IPv6 Router Advertisement Daemon and Advertisement Prefixes for th

Pagina 13 - Balancing

1111. IntroductionThis chapter provides an overview of the features and capabilities of the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 and ex

Pagina 14

LAN Configuration110ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To configure the Router Advertisement Daemon for the LAN:1. Select Network Con

Pagina 15 - Extensive Protocol Support

LAN Configuration111 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Advertisement Prefixes for the LANYou need t

Pagina 16

LAN Configuration112ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 62. 2. Enter the settings as described in the following table:3. Click A

Pagina 17 - Hardware Features

LAN Configuration113 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. To delete one or more advertisement prefi

Pagina 18 - Table 1. LED descriptions

LAN Configuration114ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. In the Add Secondary LAN IP Address section of the screen, enter the followin

Pagina 19 - Rear Panel

LAN Configuration115 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308By default, the DMZ port and both inbound and outbound DMZ traffic are disabled.

Pagina 20 - Figure 3

LAN Configuration116ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 64. 2. Enter the settings as described in the following table: Table 23.

Pagina 21 - Log In to the VPN Firewall

LAN Configuration117 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCP for DMZ Connected ComputersDisable DHCP Server If another device on your ne

Pagina 22 - Figure 5

LAN Configuration118ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.DMZ Port for IPv6 TrafficThe DMZ Setup (IPv

Pagina 23

LAN Configuration119 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308For the DMZ, there are two DHCPv6 server options:• Stateless DHCPv6 server. The

Pagina 24 - Figure 8

Introduction12ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 What Is the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308?The ProSAFE Gigabit Quad

Pagina 25 - Figure 9

LAN Configuration120ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Enter the settings as described in the following table: Table 24. DMZ Setup

Pagina 26 - Settings

LAN Configuration121 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.IPv6 DMZ Address PoolsIf you configure a st

Pagina 27 -  Complete these tasks:

LAN Configuration122ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Enter the settings as described in the following table:3. Click Apply to save

Pagina 28

LAN Configuration123 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Hosts and routers in the LAN use NDP to determine the link-layer addresses and r

Pagina 29

LAN Configuration124ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 67. 4. Enter the settings as described in the following table:Table 27.

Pagina 30 - Classical Routing

LAN Configuration125 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Advertisement Prefixes for the DMZYou need t

Pagina 31 - Figure 11

LAN Configuration126ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 68. 2. Enter the settings as described in the following table:3. Click A

Pagina 32 - Figure 12

LAN Configuration127 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. To delete one or more advertisement prefi

Pagina 33

LAN Configuration128ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Click the Add table button under the Static Routes table. The Add Static Rout

Pagina 34 - Figure 14

LAN Configuration129 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308displays. This screen is identical to the Add Static Route screen (see the previ

Pagina 35 - Figure 15

Introduction13 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The VPN firewall provides the following key features and capabilities:• Four 10/100/10

Pagina 36 - Figure 16

LAN Configuration130ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Enter the settings as described in the following table: Table 30. RIP Config

Pagina 37 - Figure 17

LAN Configuration131 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.IPv4 Static Route ExampleIn this example, w

Pagina 38 - Figure 18

LAN Configuration132ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage Static IPv6 RoutingNETGEAR’s implementation of IPv6 does not support RIP

Pagina 39 - Figure 19

LAN Configuration133 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Enter the settings as described in the following table: 5. Click Apply to sav

Pagina 40 - Interfaces

13444. Firewall ProtectionThis chapter describes how to use the firewall features of the VPN firewall to protect your network. The chapter contains

Pagina 41 - IPv4 Interfaces

Firewall Protection135 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308About Firewall ProtectionA firewall protects one network (the trusted network,

Pagina 42 - Figure 21

Firewall Protection136ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Overview of Rules to Block or Allow Specific Kinds of Traffic• Outbound Rules

Pagina 43 - Figure 22

Firewall Protection137 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Bandwidth profiles. After you have a configured a bandwidth profile (see Cre

Pagina 44 -  To edit a protocol binding:

Firewall Protection138ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Select Schedule The time schedule (that is, Schedule1, Schedule2, or Schedule

Pagina 45

Firewall Protection139 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308QoS Profile or QoS PriorityThe priority assigned to IP packets of this service

Pagina 46 - Figure 24

Introduction14ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Advanced VPN Support for Both IPSec and SSLThe VPN firewall supports IPSec and SSL vir

Pagina 47

Firewall Protection140ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Inbound Rules (Port Forwarding)If you have enabled Network Address Translation

Pagina 48

Firewall Protection141 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: When the Block TCP Flood and Block UDP Flood check boxes are selected on

Pagina 49 - Configure Dynamic DNS

Firewall Protection142ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Send to LAN Server The LAN server address determines which computer on your ne

Pagina 50 -  To configure DDNS:

Firewall Protection143 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WAN Users The settings that determine which Internet locations are covered by

Pagina 51 - Figure 27

Firewall Protection144ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Some residential broadband ISP accounts do not allow you to run any serv

Pagina 52

Firewall Protection145 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308For any traffic attempting to pass through the firewall, the packet informatio

Pagina 53

Firewall Protection146ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To change an existing outbound or inbound service rule, in the Action column t

Pagina 54 - Figure 28

Firewall Protection147 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To enable, disable, or delete one or more IPv4 or IPv6 rules:1. Select the c

Pagina 55 - Connection

Firewall Protection148ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 77. 2. Enter the settings as described in Table 33 on page 137. In a

Pagina 56 - Figure 30

Firewall Protection149 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 78. 3. Enter the settings as described in Table 33 on page 137. In a

Pagina 57 - Figure 31

Introduction15 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Security FeaturesThe VPN firewall is equipped with several features designed to mainta

Pagina 58 - Figure 32

Firewall Protection150ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IPv4 LAN WAN Inbound Service Rules To create an IPv4 LAN WAN inbound rule:1.

Pagina 59 - Figure 33

Firewall Protection151 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following configurations are optional:• Translate to Port Number• QoS Prof

Pagina 60 - Figure 34

Firewall Protection152ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure DMZ WAN Rules• Create DMZ WAN Outbound Service Rules• Create LAN WAN

Pagina 61 - Figure 35

Firewall Protection153 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To change an existing outbound or inbound service rule, in the Action column t

Pagina 62 - Figure 36

Firewall Protection154ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To enable, disable, or delete one or more IPv4 or IPv6 rules:1. Select the c

Pagina 63

Firewall Protection155 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in Table 33 on page 137. In addition to s

Pagina 64

Firewall Protection156ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Unless your selection from the Action drop-down list is BLOCK always, you also

Pagina 65 - Figure 37

Firewall Protection157 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in Table 34 on page 141. In addition to s

Pagina 66 - Figure 39

Firewall Protection158ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Unless your selection from the Action drop-down list is BLOCK always, you also

Pagina 67 - Figure 40

Firewall Protection159 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To change an existing outbound or inbound service rule, in the Action column t

Pagina 68 - Figure 41

Introduction16ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • DNS proxy. When DHCP is enabled and no DNS addresses are specified, the VPN firewall

Pagina 69 - Figure 42

Firewall Protection160ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Click one of the following table buttons:• Enable. Enables the rule or rule

Pagina 70 - Figure 43

Firewall Protection161 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Unless your selection from the Action drop-down list is BLOCK always, you also

Pagina 71 - Figure 44

Firewall Protection162ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create LAN DMZ Inbound Service RulesThe Inbound Services table lists all exist

Pagina 72 - Figure 45

Firewall Protection163 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6 LAN DMZ Inbound Service Rules To create an IPv6 LAN DMZ inbound rule:1.

Pagina 73 - Figure 46

Firewall Protection164ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Examples of Firewall Rules• Examples of Inbound Firewall Rules• Examples of Ou

Pagina 74

Firewall Protection165 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 94. IPv4 LAN WAN or IPv4 DMZ WAN Inbound Rule: Set Up One-to-One NAT Ma

Pagina 75

Firewall Protection166ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: If you arrange with your ISP to have more than one public IP address for

Pagina 76 - Configure WAN QoS Profiles

Firewall Protection167 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308this address on the WAN2 Secondary Addresses screen (see Configure Secondary W

Pagina 77 - Figure 47

Firewall Protection168ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:For security, NETGEAR strongly recommends that you avoid creating an e

Pagina 78 - Figure 48

Firewall Protection169 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 98. IPv6 DMZ WAN Outbound Rule: Allow a Group of DMZ User to Access an

Pagina 79

Introduction17 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Maintenance and SupportNETGEAR offers the following features to help you maximize your

Pagina 80 - Figure 49

Firewall Protection170ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure Other Firewall Features• Attack Checks• Set Limits for IPv4 Sessions

Pagina 81

Firewall Protection171 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:Table 35. Attack Ch

Pagina 82 - What to Do Next

Firewall Protection172ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.IPv6 Attack Checks To enable IPv6 attack

Pagina 83

Firewall Protection173 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Set Limits for IPv4 SessionsThe session limits feature allows you to specify t

Pagina 84

Firewall Protection174ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings.Configure Multicast Pass-Through for IPv4

Pagina 85 - Port-Based VLANs

Firewall Protection175 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 103. 2. In the Multicast Pass through section of the screen, select th

Pagina 86 - Figure 50

Firewall Protection176ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To delete one or more multicast source addresses:1. In the Alternate Network

Pagina 87 - VLAN DHCP Options

Firewall Protection177 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• QoS profiles and priorities. A Quality of Service (QoS) profile defines the

Pagina 88 - Configure a VLAN Profile

Firewall Protection178ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 105. 2. In the Add Customer Service section of the screen, enter the s

Pagina 89 - Figure 52

Firewall Protection179 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 106. 2. Modify the settings that you wish to change (see the previous

Pagina 90

Introduction18ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The front panel also contains three groups of status indicator light-emitting diodes (

Pagina 91

Firewall Protection180ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the Add New Custom IP Group section of the screen, do the following:• In

Pagina 92

Firewall Protection181 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete an IP group:1. In the Custom IP Groups table, select the check box

Pagina 93

Firewall Protection182ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 109. 2. Under the List of Bandwidth Profiles table, click the Add tabl

Pagina 94

Firewall Protection183 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The new bandwidth profile is added to th

Pagina 95 - Figure 54

Firewall Protection184ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create Quality of Service Profiles for IPv4 Firewall RulesA Quality of Service

Pagina 96

Firewall Protection185 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 112. 3. Enter the settings as described in the following table.4. Clic

Pagina 97 - Manage the Network Database

Firewall Protection186ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit a QoS profile:1. In the List of QoS Profiles table, click the Edit t

Pagina 98

Firewall Protection187 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Several types of blocking are available:• Web component blocking. You can bloc

Pagina 99

Firewall Protection188ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • If the keyword “.com” is specified, only websites with other domain suffixes

Pagina 100 - Figure 56

Firewall Protection189 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. In the Web Components section of the screen, select the components that you

Pagina 101 - Figure 57

Introduction19 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Rear PanelThe rear panel of the VPN firewall includes a console port, a Factory Defaul

Pagina 102 - Manage the IPv6 LAN

Firewall Protection190ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To set a schedule:1. Select Security > Services > Schedule 1. The Sche

Pagina 103 - DHCPv6 Server Options

Firewall Protection191 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: For additional ways of restricting outbound traffic, see Outbound Rules

Pagina 104 - Configure the IPv6 LAN

Firewall Protection192ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:If you select Permit and Block the rest from the drop-down list but do

Pagina 105 - LAN Configuration

Firewall Protection193 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Host 2 has changed its MAC address to 00:01:02:03:04:09. The packet has an I

Pagina 106 - IPv6 LAN Address Pools

Firewall Protection194ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. In the IP/MAC Bindings sections of the screen, enter the settings as descri

Pagina 107 - Figure 59

Firewall Protection195 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click the Set Interval button. Wait for the confirmation that the operation

Pagina 108 -  To edit a prefix:

Firewall Protection196ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click the Add table button. The new IP/MAC rule is added to the IP/MAC Bind

Pagina 109

Firewall Protection197 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Port TriggeringPort triggering allows some applications running on a

Pagina 110 - Figure 61

Firewall Protection198ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 120. 2. In the Add Port Triggering Rule section, enter the settings as

Pagina 111

Firewall Protection199 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To remove one or more port triggering rules from the table:1. Select the che

Pagina 112 - Figure 62

2ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SupportThank you for selecting NETGEAR products. After installing your device, locate the serial nu

Pagina 113 - Default VLAN

Introduction20ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Factory Defaults Reset button. Using a sharp object, press and hold this button for

Pagina 114

Firewall Protection200ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The UPnP Portmap Table in the lower part of the screen shows the IP addresses

Pagina 115 - DMZ Port for IPv4 Traffic

20155. Virtual Private Networking Using IPSec and L2TP ConnectionsThis chapter describes how to use the IP security (IPSec) virtual private networ

Pagina 116 - Figure 64

Virtual Private Networking Using IPSec and L2TP Connections202ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Considerations for Dual WAN Port Syste

Pagina 117

Virtual Private Networking Using IPSec and L2TP Connections203 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table summarizes the WAN

Pagina 118 - DMZ Port for IPv6 Traffic

Virtual Private Networking Using IPSec and L2TP Connections204ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv4 Gateway-to-Gateway VPN

Pagina 119 - Figure 65

Virtual Private Networking Using IPSec and L2TP Connections205 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To view the wizard default settings, c

Pagina 120

Virtual Private Networking Using IPSec and L2TP Connections206ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: To ensure that tunnels stay activ

Pagina 121 - IPv6 DMZ Address Pools

Virtual Private Networking Using IPSec and L2TP Connections207 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 128. 4. Configure a VPN policy

Pagina 122

Virtual Private Networking Using IPSec and L2TP Connections208ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv6 Gateway-to-Gateway VPN

Pagina 123

Virtual Private Networking Using IPSec and L2TP Connections209 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To view the wizard default settings, c

Pagina 124 - Figure 67

Introduction21 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Use the Rack-Mounting KitUse the mounting kit for the VPN firewall to install the appl

Pagina 125

Virtual Private Networking Using IPSec and L2TP Connections210ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: To ensure that tunnels stay activ

Pagina 126 - Figure 68

Virtual Private Networking Using IPSec and L2TP Connections211 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 133. 5. Configure a VPN policy

Pagina 127 - Manage Static IPv4 Routing

Virtual Private Networking Using IPSec and L2TP Connections212ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv4 Client-to-Gateway VPN T

Pagina 128 - Figure 70

Virtual Private Networking Using IPSec and L2TP Connections213 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 136. To display the wizard def

Pagina 129 - Figure 71

Virtual Private Networking Using IPSec and L2TP Connections214ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.

Pagina 130

Virtual Private Networking Using IPSec and L2TP Connections215 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 137. Note: When you are using

Pagina 131 - IPv4 Static Route Example

Virtual Private Networking Using IPSec and L2TP Connections216ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Perform these tasks from a compu

Pagina 132 - Manage Static IPv6 Routing

Virtual Private Networking Using IPSec and L2TP Connections217 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 139. 3. Select the A router or

Pagina 133

Virtual Private Networking Using IPSec and L2TP Connections218ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 141. 6. This screen is a summa

Pagina 134 - Firewall Protection

Virtual Private Networking Using IPSec and L2TP Connections219 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308c. Specify the settings that are descr

Pagina 135 - About Firewall Protection

Introduction22ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: The VPN firewall factory default IP address is 192.168.1.1. If you change the IP

Pagina 136

Virtual Private Networking Using IPSec and L2TP Connections220ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 143. b. Specify the default li

Pagina 137

Virtual Private Networking Using IPSec and L2TP Connections221 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the Authentication Settings

Pagina 138

Virtual Private Networking Using IPSec and L2TP Connections222ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: This is the name for the authen

Pagina 139

Virtual Private Networking Using IPSec and L2TP Connections223 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to use the new settings

Pagina 140

Virtual Private Networking Using IPSec and L2TP Connections224ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 8. Click Apply to use the new settings

Pagina 141

Virtual Private Networking Using IPSec and L2TP Connections225 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 148. 3. Specify the settings t

Pagina 142

Virtual Private Networking Using IPSec and L2TP Connections226ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to use the new settings

Pagina 143

Virtual Private Networking Using IPSec and L2TP Connections227 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Test the Connection and View Connectio

Pagina 144 - Order of Precedence for Rules

Virtual Private Networking Using IPSec and L2TP Connections228ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 151. • Use the system-tray ico

Pagina 145 - Configure LAN WAN Rules

Virtual Private Networking Using IPSec and L2TP Connections229 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308NETGEAR VPN Client Status and Log Info

Pagina 146 - Figure 76

Introduction23 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Login. The web management interface displays, showing the Router Status scree

Pagina 147 - IPv4 LAN WAN Outbound Rules

Virtual Private Networking Using IPSec and L2TP Connections230ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The Active IPSec SA(s) table lists eac

Pagina 148 - IPv6 LAN WAN Outbound Rules

Virtual Private Networking Using IPSec and L2TP Connections231 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Manage IPSec VPN Policies• Manage IKE

Pagina 149 - Figure 78

Virtual Private Networking Using IPSec and L2TP Connections232ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 158. Each policy contains the d

Pagina 150 - Figure 79

Virtual Private Networking Using IPSec and L2TP Connections233 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: You cannot delete or edit an IKE

Pagina 151 - IPv6 LAN WAN Inbound Rules

Virtual Private Networking Using IPSec and L2TP Connections234ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Complete the settings as described

Pagina 152 - Configure DMZ WAN Rules

Virtual Private Networking Using IPSec and L2TP Connections235 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Identifier From the drop-down list, se

Pagina 153 - Figure 82

Virtual Private Networking Using IPSec and L2TP Connections236ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Authentication Method Select one of th

Pagina 154 - Figure 83

Virtual Private Networking Using IPSec and L2TP Connections237 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings.

Pagina 155 - Figure 84

Virtual Private Networking Using IPSec and L2TP Connections238ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your changes. T

Pagina 156 - Figure 85

Virtual Private Networking Using IPSec and L2TP Connections239 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 160. Each policy contains the d

Pagina 157 - Figure 86

Introduction24ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The web management interface menu consists of the following components:• 1st level: Ma

Pagina 158 - Configure LAN DMZ Rules

Virtual Private Networking Using IPSec and L2TP Connections240ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 For information about how to add or ed

Pagina 159 - Figure 88

Virtual Private Networking Using IPSec and L2TP Connections241 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 162. Add New VPN Policy screen

Pagina 160 - Figure 89

Virtual Private Networking Using IPSec and L2TP Connections242ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Policy Type From the drop-down list, s

Pagina 161 - Figure 90

Virtual Private Networking Using IPSec and L2TP Connections243 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Traffic SelectionLocal IP From the dro

Pagina 162 - Figure 91

Virtual Private Networking Using IPSec and L2TP Connections244ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Key-Out The encryption key for the out

Pagina 163 - Figure 92

Virtual Private Networking Using IPSec and L2TP Connections245 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings.

Pagina 164 - Examples of Firewall Rules

Virtual Private Networking Using IPSec and L2TP Connections246ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 requesting individual authentication i

Pagina 165 - Figure 94

Virtual Private Networking Using IPSec and L2TP Connections247 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. In the Extended Authentication sect

Pagina 166 - Figure 95

Virtual Private Networking Using IPSec and L2TP Connections248ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 name and password information. The gat

Pagina 167 - Figure 96

Virtual Private Networking Using IPSec and L2TP Connections249 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.N

Pagina 168 - Figure 97

Introduction25 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308When a screen includes a table, table buttons display to let you configure the table e

Pagina 169 - FTP Site on the Internet

Virtual Private Networking Using IPSec and L2TP Connections250ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Assign IPv4 Addresses to Remote Users

Pagina 170 - Attack Checks

Virtual Private Networking Using IPSec and L2TP Connections251 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To configure Mode Config on the VPN

Pagina 171

Virtual Private Networking Using IPSec and L2TP Connections252ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Complete the settings as described

Pagina 172 - IPv6 Attack Checks

Virtual Private Networking Using IPSec and L2TP Connections253 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.

Pagina 173 - Set Limits for IPv4 Sessions

Virtual Private Networking Using IPSec and L2TP Connections254ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 166. 8. On the Add IKE Policy

Pagina 174

Virtual Private Networking Using IPSec and L2TP Connections255 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 60. Add IKE Policy screen setti

Pagina 175 - Figure 103

Virtual Private Networking Using IPSec and L2TP Connections256ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IKE SA ParametersNote: Generally, the

Pagina 176 - Figure 104

Virtual Private Networking Using IPSec and L2TP Connections257 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53089. Click Apply to save your settings.

Pagina 177 - Add Customized Services

Virtual Private Networking Using IPSec and L2TP Connections258ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Perform these tasks from a compu

Pagina 178 -  To edit a service:

Virtual Private Networking Using IPSec and L2TP Connections259 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Change the name of the authenticati

Pagina 179 - Create IP Groups

2622. IPv4 and IPv6 Internet and WAN SettingsThis chapter explains how to configure the IPv4 and IPv6 Internet and WAN settings. The chapter contain

Pagina 180 -  To edit an IP group:

Virtual Private Networking Using IPSec and L2TP Connections260ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to use the new settings

Pagina 181 - Create Bandwidth Profiles

Virtual Private Networking Using IPSec and L2TP Connections261 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53088. Click Apply to use the new settings

Pagina 182 - Profile screen displays:

Virtual Private Networking Using IPSec and L2TP Connections262ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 171. 3. Specify the settings t

Pagina 183

Virtual Private Networking Using IPSec and L2TP Connections263 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to use the new settings

Pagina 184 - Figure 111

Virtual Private Networking Using IPSec and L2TP Connections264ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Specify the following default lifet

Pagina 185 - Figure 112

Virtual Private Networking Using IPSec and L2TP Connections265 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Verify that the VPN firewall issued

Pagina 186 - Configure Content Filtering

Virtual Private Networking Using IPSec and L2TP Connections266ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 keep-alive and Dead Peer Detection (DP

Pagina 187

Virtual Private Networking Using IPSec and L2TP Connections267 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Enter the settings as described in

Pagina 188 - Figure 113

Virtual Private Networking Using IPSec and L2TP Connections268ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 177. 4. In the IKE SA Paramete

Pagina 189

Virtual Private Networking Using IPSec and L2TP Connections269 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Specify the IP version for which yo

Pagina 190 - Enable Source MAC Filtering

IPv4 and IPv6 Internet and WAN Settings27 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet and WAN Configuration Tasks• Roadmap to Setting Up

Pagina 191 - Figure 115

Virtual Private Networking Using IPSec and L2TP Connections270ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To enable the PPTP server and config

Pagina 192 - Set Up IP/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections271 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.V

Pagina 193 - IPv4/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections272ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure the L2TP ServerAs an alterna

Pagina 194 - Figure 117

Virtual Private Networking Using IPSec and L2TP Connections273 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in

Pagina 195 - IPv6/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections274ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 L2TP IP The IP address that is assigne

Pagina 196 - Figure 119

27566. Virtual Private Networking Using SSL ConnectionsThe VPN firewall provides a hardware-based SSL VPN solution designed specifically to provide

Pagina 197 - Configure Port Triggering

Virtual Private Networking Using SSL Connections276ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SSL VPN Portal OptionsThe VPN firewall’s SSL VPN

Pagina 198 - Figure 120

Virtual Private Networking Using SSL Connections277 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308resources to which the users are granted access.

Pagina 199 -  To configure UPnP:

Virtual Private Networking Using SSL Connections278ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 You apply portal layouts by selecting one from th

Pagina 200

Virtual Private Networking Using SSL Connections279 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The List of Layouts table displays the following

Pagina 201 - IPSec and L2TP Connections

IPv4 and IPv6 Internet and WAN Settings28ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. (Optional) Configure Dynamic DNS on the WAN interfaces.

Pagina 202

Virtual Private Networking Using SSL Connections280ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Complete the settings as described in the foll

Pagina 203 - Configurations

Virtual Private Networking Using SSL Connections281 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The new por

Pagina 204 - Figure 126

Virtual Private Networking Using SSL Connections282ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 For information about how to configure domains, g

Pagina 205 - Figure 127

Virtual Private Networking Using SSL Connections283 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. In the Add New Application for Port Forwarding

Pagina 206

Virtual Private Networking Using SSL Connections284ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To add servers and host names for client name r

Pagina 207 - Figure 129

Virtual Private Networking Using SSL Connections285 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Select whether you want to enable full-tunnel o

Pagina 208 - Figure 131

Virtual Private Networking Using SSL Connections286ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 188. SSL VPN Client screen for IPv63. Com

Pagina 209 - Figure 132

Virtual Private Networking Using SSL Connections287 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. VPN tunnel

Pagina 210

Virtual Private Networking Using SSL Connections288ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 If VPN tunnel clients are already connected, disc

Pagina 211 - Figure 134

Virtual Private Networking Using SSL Connections289 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 189. 2. In the Add New Resource section o

Pagina 212 - Figure 135

IPv4 and IPv6 Internet and WAN Settings29 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. (Optional) Configure the WAN options. If necessary, chan

Pagina 213 - Figure 136

Virtual Private Networking Using SSL Connections290ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 190. 4. Complete the settings as describe

Pagina 214

Virtual Private Networking Using SSL Connections291 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The new con

Pagina 215 - Figure 137

Virtual Private Networking Using SSL Connections292ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 includes the following addresses: 10.0.0.5–10.0.0

Pagina 216 - Figure 138

Virtual Private Networking Using SSL Connections293 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Make your selection from the following Query o

Pagina 217 - Figure 140

Virtual Private Networking Using SSL Connections294ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 .Figure 193. Add SSL VPN Policy screen for IPv64

Pagina 218 - Figure 142

Virtual Private Networking Using SSL Connections295 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Apply Policy to? (continued)Network ResourcePolic

Pagina 219

Virtual Private Networking Using SSL Connections296ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your settings. The policy

Pagina 220 - Figure 143

Virtual Private Networking Using SSL Connections297 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more SSL VPN policies:1. On th

Pagina 221 - Figure 145

Virtual Private Networking Using SSL Connections298ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. In the Portal URL field of the List of Layouts

Pagina 222 - Figure 146

Virtual Private Networking Using SSL Connections299 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 198. The User Portal screen displays a si

Pagina 223 - The Advanced pane displays:

3ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 202-10536-03 1.0 November 2011 Incorporated nontechnical edits only (there are no feature changes).

Pagina 224

IPv4 and IPv6 Internet and WAN Settings30ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • If your ISP has provided you with multiple public IP addr

Pagina 225 - Figure 148

Virtual Private Networking Using SSL Connections300ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 199. The active user’s name, group, and IP

Pagina 226 - Figure 149

30177. Manage Users, Authentication, and VPN CertificatesThis chapter describes how to manage users, authentication, and security certificates for

Pagina 227 - Information

Manage Users, Authentication, and VPN Certificates302ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The VPN Firewall’s Authentication Process and O

Pagina 228 - Figure 154

Manage Users, Authentication, and VPN Certificates303 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Authentication Domains, Groups, and U

Pagina 229 - Figure 156

Manage Users, Authentication, and VPN Certificates304ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create Domains To create a domain:1. Select Us

Pagina 230 - Figure 157

Manage Users, Authentication, and VPN Certificates305 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 202. 3. Complete the settings as descri

Pagina 231 - Manage IPSec VPN Policies

Manage Users, Authentication, and VPN Certificates306ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The domai

Pagina 232 - Figure 158

Manage Users, Authentication, and VPN Certificates307 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: A combination of local and external authe

Pagina 233 - Figure 159

Manage Users, Authentication, and VPN Certificates308ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IMPORTANT:When you create a domain on the Domai

Pagina 234

Manage Users, Authentication, and VPN Certificates309 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: When you create a domain on the Domains

Pagina 235

IPv4 and IPv6 Internet and WAN Settings31 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. These settings apply

Pagina 236

Manage Users, Authentication, and VPN Certificates310ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Edit GroupsFor groups that were automatically c

Pagina 237 -  To edit an IKE policy:

Manage Users, Authentication, and VPN Certificates311 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Guest user. A user who can only view the VPN

Pagina 238 - Manage VPN Policies

Manage Users, Authentication, and VPN Certificates312ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 206. 3. Enter the settings as described

Pagina 239 - Figure 160

Manage Users, Authentication, and VPN Certificates313 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more user accounts:1. In the

Pagina 240

Manage Users, Authentication, and VPN Certificates314ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: For security reasons, the Deny Login from

Pagina 241 - Setting Description

Manage Users, Authentication, and VPN Certificates315 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. In the Add Defined Addresses section of the

Pagina 242

Manage Users, Authentication, and VPN Certificates316ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 209. 5. In the Defined Addresses Status

Pagina 243

Manage Users, Authentication, and VPN Certificates317 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more IPv6 addresses:1. In th

Pagina 244

Manage Users, Authentication, and VPN Certificates318ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Firefox. Mozilla Firefox.• Mozilla. Other Moz

Pagina 245 -  To edit a VPN policy:

Manage Users, Authentication, and VPN Certificates319 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 211. 3. Change the settings as describe

Pagina 246

IPv4 and IPv6 Internet and WAN Settings32ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 12. 3. Click the Auto Detect button at the bottom o

Pagina 247 - User Database Configuration

Manage Users, Authentication, and VPN Certificates320ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage Digital Certificates for VPN Connections

Pagina 248 - Figure 163

Manage Users, Authentication, and VPN Certificates321 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Because a commercial CA takes steps to verify t

Pagina 249

Manage Users, Authentication, and VPN Certificates322ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage VPN CA Certificates To view and upload

Pagina 250 - Mode Config Operation

Manage Users, Authentication, and VPN Certificates323 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Manage VPN Self-Signed CertificatesInstead of o

Pagina 251 - Figure 165

Manage Users, Authentication, and VPN Certificates324ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 214. Certificates, screen 2 of 32. In t

Pagina 252

Manage Users, Authentication, and VPN Certificates325 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click the Generate table button. A new SCR i

Pagina 253

Manage Users, Authentication, and VPN Certificates326ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 9. Select the check box next to the self-signed

Pagina 254 - Figure 166

Manage Users, Authentication, and VPN Certificates327 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 216. Certificates, screen 3 of 3The Cer

Pagina 255

32888. Network and System ManagementThis chapter describes the tools for managing the network traffic to optimize its performance and the system man

Pagina 256

Network and System Management329 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Performance Management• Bandwidth Capacity• Features That Reduce Tra

Pagina 257 - Operation

IPv4 and IPv6 Internet and WAN Settings33 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• If the autodetect process does not find a connection, you

Pagina 258 - Figure 168

Network and System Management330ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Features That Reduce TrafficYou can adjust the following features of

Pagina 259 - Figure 169

Network and System Management331 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• LAN users (or DMZ users). You can specify which computers on your

Pagina 260

Network and System Management332ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 In order to reduce traffic, the VPN firewall provides the following

Pagina 261

Network and System Management333 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Each rule lets you specify the desired action for the connections co

Pagina 262 - Figure 171

Network and System Management334ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 - Address range. The rule applies to a range of Internet IP addresse

Pagina 263 - Figure 172

Network and System Management335 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN, L2TP, and PPTP TunnelsThe VPN firewall supports site-to-site IP

Pagina 264 - Figure 174

Network and System Management336ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Monitoring Tools for Traffic ManagementThe VPN firewall includes sev

Pagina 265 - Figure 175

Network and System Management337 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 217. 2. In the Action column of the List of Users table, cli

Pagina 266 - Configure Keep-Alives

Network and System Management338ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your settings.7. Repeat Step 1 through Step

Pagina 267 - Configure Dead Peer Detection

Network and System Management339 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308continuing (see Change Passwords and Administrator and Guest Setting

Pagina 268 - Figure 177

IPv4 and IPv6 Internet and WAN Settings34ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 13. The Connection Status screen should show a vali

Pagina 269 - Configure the PPTP Server

Network and System Management340ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 220. Remote Management screen for IPv63. Enter the settings

Pagina 270 - Figure 179

Network and System Management341 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WARNING:If you are remotely connected to the VPN firewall and you se

Pagina 271 - View the Active PPTP Users

Network and System Management342ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: If you are using a Dynamic DNS service such as TZO, you can ide

Pagina 272 - Configure the L2TP Server

Network and System Management343 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 221. The SNMPv3 Users table includes the default SNMPv3 user

Pagina 273 - View the Active L2TP Users

Network and System Management344ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. To specify a new SNMP configuration, in the Create New SNMP Confi

Pagina 274 - Item Description

Network and System Management345 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 222. 2. Modify the settings as described in the previous tab

Pagina 275 - SSL Connections

Network and System Management346ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your changes. To configure the SNMP system i

Pagina 276 - SSL VPN Portal Options

Network and System Management347 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:3. Click A

Pagina 277 - Create the Portal Layout

Network and System Management348ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 225. Back Up SettingsThe backup feature saves all VPN firewal

Pagina 278

Network and System Management349 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Restore SettingsWARNING:Restore only settings that were backed up fr

Pagina 279 - Figure 185

IPv4 and IPv6 Internet and WAN Settings35 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The IPv4 WAN Settings table displays the following fields:•

Pagina 280

Network and System Management350ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:When you press the hardware factory default Reset button or

Pagina 281 -  To edit a portal layout:

Network and System Management351 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The newly installed firmware is the active firmware. The previously

Pagina 282 - Add Servers and Port Numbers

Network and System Management352ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Select Monitoring. The Router Status screen displays, showing the

Pagina 283 - Add a New Host Name

Network and System Management353 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Resolve IPv6 address for serversSelect this check box to force the u

Pagina 284 - Configure the SSL VPN Client

Network and System Management354ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.Note: If you select the default

Pagina 285

35599. Monitor System Access and PerformanceThis chapter describes the system-monitoring features of the VPN firewall. You can be alerted to importa

Pagina 286

Monitor System Access and Performance356ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure and Enable the WAN Traffic MeterIf your ISP charge

Pagina 287

Monitor System Access and Performance357 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 88. WAN1 Traffic Meter screen settings Setting Descri

Pagina 288 - Add New Network Resources

Monitor System Access and Performance358ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.4. If you want to enabl

Pagina 289 -  To edit network resources:

Monitor System Access and Performance359 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure and Enable the LAN Traffic MeterIf your ISP charge

Pagina 290 - Figure 190

IPv4 and IPv6 Internet and WAN Settings36ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 16. 6. If your connection is PPTP or PPPoE, your IS

Pagina 291

Monitor System Access and Performance360ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Traffic (MB). The traffic usage in MB.• State. The state t

Pagina 292 - View Policies

Monitor System Access and Performance361 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. Click Apply to save your settings. The new account is add

Pagina 293 -  To add an SSL VPN policy:

Monitor System Access and Performance362ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure Logging, Alerts, and Event NotificationsYou can co

Pagina 294

Monitor System Access and Performance363 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:Ta

Pagina 295

Monitor System Access and Performance364ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Enable E-mail LogsDo you want logs to be emailed to you?Sele

Pagina 296 -  To edit an SSL VPN policy:

Monitor System Access and Performance365 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.Note: Enabling routing

Pagina 297

Monitor System Access and Performance366ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 234. You can refresh the logs, clear the logs, or se

Pagina 298 - Figure 197

Monitor System Access and Performance367 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308How to Send Syslogs over a VPN Tunnel between Sites To send

Pagina 299 - Figure 198

Monitor System Access and Performance368ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. In the Traffic Selector section of the screen, make the f

Pagina 300 - Figure 200

Monitor System Access and Performance369 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308View Status Screens• View the System Status• View the VPN Co

Pagina 301 - VPN Certificates

IPv4 and IPv6 Internet and WAN Settings37 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53087. In the Internet (IP) Address section of the screen (see

Pagina 302

Monitor System Access and Performance370ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 236. The following table explains the fields of the R

Pagina 303 - Configure Domains

Monitor System Access and Performance371 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Router Statistics Screen To view the Router Statistics scre

Pagina 304 - Create Domains

Monitor System Access and Performance372ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 237. The following table explains the fields of the

Pagina 305 - Figure 202

Monitor System Access and Performance373 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 238.

Pagina 306

Monitor System Access and Performance374ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The following table explains the fields of the Detailed Stat

Pagina 307 - Configure Groups

Monitor System Access and Performance375 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ IPv6 ConfigurationIPv6 Address The IPv6 address and pref

Pagina 308 - Create Groups

Monitor System Access and Performance376ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 VLAN Status ScreenThe VLAN Status screen displays informatio

Pagina 309 - Figure 204

Monitor System Access and Performance377 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table explains the fields of the VLAN Status s

Pagina 310 - Configure User Accounts

Monitor System Access and Performance378ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 View the VPN Connection Status, L2TP Users, and PPTP UsersTh

Pagina 311 - Figure 205

Monitor System Access and Performance379 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The active user’s user name, group, and IP address are liste

Pagina 312 - Figure 206

IPv4 and IPv6 Internet and WAN Settings38ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 8. In the Domain Name Server (DNS) Servers section of the s

Pagina 313 - Set User Login Policies

Monitor System Access and Performance380ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The List of PPTP Active Users table lists each active connec

Pagina 314 - Figure 208

Monitor System Access and Performance381 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 246. View the Port Triggering Status To view the sta

Pagina 315

Monitor System Access and Performance382ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 248. The Port Triggering Status screen displays the

Pagina 316 - Figure 209

Monitor System Access and Performance383 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 249. 2. In the Action column, click the Status butto

Pagina 317 - Figure 210

Monitor System Access and Performance384ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Click Disconnect to disconnect the connection; click Connect

Pagina 318

Monitor System Access and Performance385 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 252. The type of connection determines the informati

Pagina 319 - Figure 211

Monitor System Access and Performance386ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 View the Attached Devices To view the attached devices on t

Pagina 320

Monitor System Access and Performance387 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: If the VPN firewall is rebooted, the data in the Known

Pagina 321 - VPN Certificates Screen

Monitor System Access and Performance388ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Diagnostics Utilities• Send a Ping Packet• Trace a Route• Lo

Pagina 322 - Manage VPN CA Certificates

Monitor System Access and Performance389 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• IPv6. Select the IPv6 radio button. The Diagnostics screen

Pagina 323 - Figure 213

IPv4 and IPv6 Internet and WAN Settings39 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53089. Click Apply to save your changes.10. Click Test to evalu

Pagina 324

Monitor System Access and Performance390ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Trace a RouteA traceroute lists all routers between the sour

Pagina 325 - Figure 215

Monitor System Access and Performance391 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Capture Packets in Real TimeCapturing packets can assist NET

Pagina 326 -  To delete one or more SCRs:

3921010. TroubleshootingThis chapter provides troubleshooting tips and information for the VPN firewall. After each problem description, instruction

Pagina 327 -  To delete one or more CRLs:

Troubleshooting393 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The VPN firewall’s diagnostic tools are described in Diagnostics Utilities o

Pagina 328 - Network and System Management

Troubleshooting394ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  If all LEDs are still on more than several minutes minute after power-up, do the

Pagina 329 - Performance Management

Troubleshooting395 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Make sure that you are using the SSL https://address login rather than the http:

Pagina 330 - Features That Reduce Traffic

Troubleshooting396ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Troubleshoot the ISP ConnectionIf your VPN firewall is unable to access the Intern

Pagina 331 - Content Filtering

Troubleshooting397 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308have to enter additional information. For more information, see Manually Configure

Pagina 332 - Source MAC Filtering

Troubleshooting398ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 - Windows Server 2003, all versions- Windows Server 2003 R2, all versions- Linux a

Pagina 333

Troubleshooting399 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308c. Click or double-click View status of this connection. The Local Area Connection

Pagina 334 - Exposed Hosts

4ContentsChapter 1 IntroductionWhat Is the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308? .12Key Features and Capabilities . . . . . . . . . . .

Pagina 335 - Assign Bandwidth Profiles

IPv4 and IPv6 Internet and WAN Settings40ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: If your ISP requires MAC authentication and another M

Pagina 336 - System Management

Troubleshooting400ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 f. Make sure that an IPv6 address shows. The previous figure does not show an IPv6

Pagina 337 - Figure 218

Troubleshooting401 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Test the Path from Your Computer to a Remote DeviceAfter verifying that the LAN pa

Pagina 338

Troubleshooting402ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 261. b. In the Backup / Restore Settings section of the screen, click the

Pagina 339

Troubleshooting403 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Address Problems with Date and TimeThe System Date & Time screen displays the

Pagina 340

404AA. Default Settings and Technical SpecificationsThis appendix provides the default settings and the physical and technical specifications of the

Pagina 341 - About Remote Access

Default Settings and Technical Specifications405ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Factory Default SettingsYou can use the factory defau

Pagina 342 -  To access the CLI:

Default Settings and Technical Specifications406ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv4 LAN, DMZ, and routing settingsLAN IPv4 address f

Pagina 343 - Figure 221

Default Settings and Technical Specifications407ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Firewall and security settingsInbound LAN WAN rules (

Pagina 344

Default Settings and Technical Specifications408ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308QoS priorities (for IPv6 firewall rules) Normal-Servi

Pagina 345 - Figure 223

Default Settings and Technical Specifications409ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN IPsec Wizard: IKE policy settings for IPv4 gatewa

Pagina 346 - Figure 224

IPv4 and IPv6 Internet and WAN Settings41 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Load Balancing Mode and Optional Protocol Binding

Pagina 347 - Manage the Configuration File

Default Settings and Technical Specifications410ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Physical and Technical SpecificationsThe following ta

Pagina 348 - Back Up Settings

Default Settings and Technical Specifications411ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table shows the IPSec VPN specification

Pagina 349 - Restore Settings

Default Settings and Technical Specifications412ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table shows the SSL VPN specifications

Pagina 350 - Upgrade the Firmware

413BB. Network Planning for Multiple WAN PortsThis appendix describes the factors to consider when planning a network using a firewall that has more

Pagina 351

Network Planning for Multiple WAN Ports414ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308What to Consider Before You Begin• Cabling and Computer Har

Pagina 352 - Figure 226

Network Planning for Multiple WAN Ports415ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 262. b. Contact a Dynamic DNS service, and register

Pagina 353

Network Planning for Multiple WAN Ports416ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet Configuration RequirementsDepending on how your IS

Pagina 354

Network Planning for Multiple WAN Ports417ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet Connection InformationPrint this page with the Int

Pagina 355 - Performance

Network Planning for Multiple WAN Ports418ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Overview of the Planning ProcessThe areas that require plan

Pagina 356 - Figure 227

Network Planning for Multiple WAN Ports419ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Features such as multiple exposed hosts are not supported i

Pagina 357

IPv4 and IPv6 Internet and WAN Settings42ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 b. From the corresponding drop-down list on the right, sele

Pagina 358 - Figure 228

Network Planning for Multiple WAN Ports420ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 265. Inbound Traffic to a Dual WAN Port SystemThe IP

Pagina 359 - Figure 230

Network Planning for Multiple WAN Ports421ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 267. Virtual Private Networks• VPN Road Warrior (Cli

Pagina 360 - Figure 231

Network Planning for Multiple WAN Ports422ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308always changes. Therefore, the use of an FQDN is always req

Pagina 361 - Figure 232

Network Planning for Multiple WAN Ports423ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Road Warrior: Single-Gateway WAN Port (Reference Case)I

Pagina 362 - Figure 233

Network Planning for Multiple WAN Ports424ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 272. The purpose of the FQDN in this case is to togg

Pagina 363

Network Planning for Multiple WAN Ports425ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Gateway-to-GatewayThe following situations exemplify th

Pagina 364

Network Planning for Multiple WAN Ports426ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 275. The IP addresses of the gateway WAN ports can b

Pagina 365

Network Planning for Multiple WAN Ports427ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 277. The IP addresses of the gateway WAN ports can b

Pagina 366 - Figure 235

Network Planning for Multiple WAN Ports428ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The IP address of the gateway WAN port can be either fixed

Pagina 367 - Configure Gateway 1 at Site 1

Network Planning for Multiple WAN Ports429ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Telecommuter: Dual-Gateway WAN Ports for Load Balancing

Pagina 368 - Configure Gateway 2 at Site 2

IPv4 and IPv6 Internet and WAN Settings43 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Destination Network. The Internet locations (based on the

Pagina 369 - View Status Screens

430CC. System Logs and Error MessagesThis appendix provides examples and explanations of system logs and error message. When applicable, a recommend

Pagina 370 - Figure 236

System Logs and Error Messages431ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Log Message TermsThis appendix uses the following log message terms.

Pagina 371 - Router Statistics Screen

System Logs and Error Messages432ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This section describes log messages that belong to one of the follow

Pagina 372 - Detailed Status Screen

System Logs and Error Messages433ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308System StartupThis section describes the log message generated durin

Pagina 373 - Figure 238

System Logs and Error Messages434ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPSec RestartThis section describes logs that are generated when IPS

Pagina 374

System Logs and Error Messages435ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Multicast/Broadcast LogsWAN StatusThis section describes the logs ge

Pagina 375

System Logs and Error Messages436ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This section describes the logs generated when the WAN mode is set t

Pagina 376 - VLAN Status Screen

System Logs and Error Messages437ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• PPPoE Idle Timeout Logs• PPTP Idle Timeout LogsTable 118. System

Pagina 377 - Tunnel Status Screen

System Logs and Error Messages438ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• PPP Authentication LogsResolved DNS NamesThis section describes th

Pagina 378 - Figure 242

System Logs and Error Messages439ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Log MessagesThis section explains logs that are generated by IPS

Pagina 379 - Figure 244

IPv4 and IPv6 Internet and WAN Settings44ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your settings. The protocol binding

Pagina 380 - View the VPN Logs

System Logs and Error Messages440ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Messages 22 and 23 Messages 24 and 25 2000 Jan 1 04:13:40 [SRX530

Pagina 381 - Figure 247

System Logs and Error Messages441ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Explanation Message 1: Informational exchange for deleting the pay

Pagina 382 - View the WAN Port Status

System Logs and Error Messages442ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Explanation Message 1–4: After receiving a request for phase 1 nego

Pagina 383 - Figure 250

System Logs and Error Messages443ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SSL VPN LogsThis section describes the log messages that are generat

Pagina 384 - IPv6 WAN Port Status

System Logs and Error Messages444ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Traffic Meter LogsRouting Logs• LAN to WAN Logs• LAN to DMZ Logs• DM

Pagina 385 - Figure 252

System Logs and Error Messages445ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN to WAN LogsLAN to DMZ LogsDMZ to WAN LogsWAN to LAN LogsTable 13

Pagina 386 - View the Attached Devices

System Logs and Error Messages446ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ to LAN LogsWAN to DMZ LogsOther Event Logs• Session Limit Logs•

Pagina 387 - View the DHCP Log

System Logs and Error Messages447ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Source MAC Filter LogsBandwidth Limit LogsDHCP LogsThis section expl

Pagina 388 - Diagnostics Utilities

System Logs and Error Messages448ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 143. DHCP logs Message 1 Message 2 Message 3 Message 4 Messag

Pagina 389 - Send a Ping Packet

449DD. Two-Factor AuthenticationThis appendix provides an overview of two-factor authentication, and an example of how to implement the WiKID soluti

Pagina 390 - Display the Routing Tables

IPv4 and IPv6 Internet and WAN Settings45 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the Auto-Rollover Mode and Failure Detection Meth

Pagina 391 - Capture Packets in Real Time

Two-Factor Authentication450ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Why Do I Need Two-Factor Authentication?• What Are the Benefits of Two-Fa

Pagina 392 - Troubleshooting

Two-Factor Authentication451ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This appendix focuses on and discusses only the first two factors, someth

Pagina 393 - Basic Functioning

Two-Factor Authentication452ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. A one-time passcode (something the user has) is generated.Figure 283.

Pagina 394 - LAN or WAN Port LEDs Not On

453EE. Notification of ComplianceNETGEAR wired productsRegulatory Compliance InformationThis section includes user requirements for operating this p

Pagina 395

Notification of Compliance454ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308FCC Radio Frequency Interference Warnings & InstructionsThis equipme

Pagina 396

455IndexNumerics10BASE-T, 100BASE-T, and 1000BASE-T speeds 743322.org 49–526to4 tunnelsconfiguring globally 64DMZ, configuring for 126LAN, configuring

Pagina 397

456ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6configuring 69described 68VPN IPSec 202, 206, 214autosensing port speed 74Bbacking up configur

Pagina 398 - Figure 258

457ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ portIPv4 address and subnet mask 116IPv6 address and prefix length 120settings 115domain, user

Pagina 399 - Figure 260

458ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SSL VPN settings 286server IPv6 addressesbroadband settings 59, 63DMZ settings 121LAN settings 106

Pagina 400

459ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308global addresses, IPv6 65global IPv6 tunnelsDMZ, configuring for 126LAN, configuring for 112group

Pagina 401

IPv4 and IPv6 Internet and WAN Settings46ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the Load Balancing Settings section of the screen, co

Pagina 402 - Figure 261

460ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCP, address pool 117DMZ port 116DNS servers 39, 91, 117dynamically assigned 38errors 25ISATAP tu

Pagina 403

461ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308JJava, blocking 187Kkeep-alives, VPN tunnels 242, 266keyword blocking 187kit, rack-mounting 21know

Pagina 404 - Specifications

462ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308management default settings 410maximum transmission unit (MTU)default 73IPv6 DMZ packets 125IPv6 L

Pagina 405 - Factory Default Settings

463ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6DMZ-to-WAN rules 155LAN-to-DMZ rules 161LAN-to-WAN rules 148order of precedence 144overview 13

Pagina 406

464ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308PPPoE (PPP over Ethernet)described 16IPv4 settings 33, 37IPv6 settings 62PPTP (Point-to-Point Tunn

Pagina 407

465ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308remote users, assigning addresses (Mode Config) 250requirements, hardware 415reserved IPv4 address

Pagina 408

466ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SPI (stateful packet inspection) 14, 135split tunnel, SSL VPN 285spoofing MAC addresses 397SSL cer

Pagina 409

467ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308rate-limiting 75reducing 330–332volume by protocol 358volume, limitingLAN 360WAN 357Transmission C

Pagina 410

468ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308FQDNs 202–203, 421FQDNs, configuring endpoints 206, 210, 213, 235gateway-to-gatewayauto-rollover 4

Pagina 411

469ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN WAN outbound rules, configuring 147, 330locking yourself outconfiguring an exposed host 167dis

Pagina 412

IPv4 and IPv6 Internet and WAN Settings47 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The default time to roll over after the primary WAN i

Pagina 413

IPv4 and IPv6 Internet and WAN Settings48ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 After you have configured secondary WAN addresses, these ad

Pagina 414

IPv4 and IPv6 Internet and WAN Settings49 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 25. The List of Secondary WAN addresses table displ

Pagina 415

5ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure a Static IPv6 Internet Connection. . . . . . . . . . . . . . . . . . . . . .58Configure a

Pagina 416

IPv4 and IPv6 Internet and WAN Settings50ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 After you have configured your account information on the V

Pagina 417

IPv4 and IPv6 Internet and WAN Settings51 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 26. 3. Click the Information option arrow in the up

Pagina 418 - Figure 263

IPv4 and IPv6 Internet and WAN Settings52ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Configure the DDNS service settings as described in the

Pagina 419 - Inbound Traffic

IPv4 and IPv6 Internet and WAN Settings53 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: You can configure only one WAN interface for IPv6. Th

Pagina 420 - Figure 266

IPv4 and IPv6 Internet and WAN Settings54ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 These are the options:• IPv4-only mode. The VPN firewall co

Pagina 421 - Virtual Private Networks

IPv4 and IPv6 Internet and WAN Settings55 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WARNING:Changing the IP routing mode causes the VPN firewal

Pagina 422 - Figure 269

IPv4 and IPv6 Internet and WAN Settings56ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The IPv6 WAN Settings table displays the following fields:•

Pagina 423 - Figure 271

IPv4 and IPv6 Internet and WAN Settings57 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. As an optional step: If you have selected the Stateless

Pagina 424 - Figure 273

IPv4 and IPv6 Internet and WAN Settings58ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure a Static IPv6 Internet ConnectionTo configure a s

Pagina 425 - VPN Gateway-to-Gateway

IPv4 and IPv6 Internet and WAN Settings59 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 33. 4. In the Internet Address section of the scree

Pagina 426 - Figure 276

6ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Inbound Rules (Port Forwarding) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 140Order o

Pagina 427 - Figure 278

IPv4 and IPv6 Internet and WAN Settings60ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your changes.7. Verify the connectio

Pagina 428 - Figure 280

IPv4 and IPv6 Internet and WAN Settings61 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure a PPPoE IPv6 Internet ConnectionTo configure a PP

Pagina 429 - Figure 281

IPv4 and IPv6 Internet and WAN Settings62ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 36. 4. In the Internet Address section of the scree

Pagina 430

IPv4 and IPv6 Internet and WAN Settings63 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. Click Apply to save your changes.7. Verify the connectio

Pagina 431 - System Log Messages

IPv4 and IPv6 Internet and WAN Settings64ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: If your ISP requires MAC authentication and another M

Pagina 432 - Login/Logout

IPv4 and IPv6 Internet and WAN Settings65 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 37. 2. Select the Enable Automatic Tunneling check

Pagina 433 - Firewall Restart

IPv4 and IPv6 Internet and WAN Settings66ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To configure an ISATAP tunnel:1. Select Network Configura

Pagina 434 - IPSec Restart

IPv4 and IPv6 Internet and WAN Settings67 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To edit an ISATAP tunnel:1. On the ISATAP Tunnels screen,

Pagina 435 - WAN Status

IPv4 and IPv6 Internet and WAN Settings68ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 a.b.c.d for part of the IPv6 address so that the IPv4-trans

Pagina 436 - PPP Logs

IPv4 and IPv6 Internet and WAN Settings69 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To use a redundant ISP link for backup purposes, ensure tha

Pagina 437 - • PPTP Idle T

7ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Extended Authentication (XAUTH) . . . . . . . . . . . . . . . . . . . . .245Configure XAU

Pagina 438 - Resolved DNS Names

IPv4 and IPv6 Internet and WAN Settings70ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Ensure that the backup WAN interface is configured be

Pagina 439 - VPN Log Messages

IPv4 and IPv6 Internet and WAN Settings71 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The default time to roll over after the primary WAN i

Pagina 440

IPv4 and IPv6 Internet and WAN Settings72ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 45. 3. Click the Advanced option arrow in the upper

Pagina 441

IPv4 and IPv6 Internet and WAN Settings73 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 46. 4. Enter the settings as described in the follo

Pagina 442

IPv4 and IPv6 Internet and WAN Settings74ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SpeedIn most cases, the VPN firewall can automatically dete

Pagina 443 - SSL VPN Logs

IPv4 and IPv6 Internet and WAN Settings75 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Failure Detection Metho

Pagina 444 - Routing Logs

IPv4 and IPv6 Internet and WAN Settings76ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:Depending on the changes that you made, when you cl

Pagina 445 - WAN to LAN Logs

IPv4 and IPv6 Internet and WAN Settings77 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: To configure and apply QoS profiles successfully, fam

Pagina 446 - Other Event Logs

IPv4 and IPv6 Internet and WAN Settings78ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Hosts. The IP address, IP addresses, or group to which th

Pagina 447 - DHCP Logs

IPv4 and IPv6 Internet and WAN Settings79 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Diffserv QoS Match Enter a DSCP value in the range of 0 thr

Pagina 448 - Table 143. DHCP logs

8ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Change Passwords and Other User Settings. . . . . . . . . . . . . . . . . . . .318Manage Digital Cer

Pagina 449 - Two-Factor Authentication

IPv4 and IPv6 Internet and WAN Settings80ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The profile is added

Pagina 450

IPv4 and IPv6 Internet and WAN Settings81 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The profile is added

Pagina 451 - Figure 282

IPv4 and IPv6 Internet and WAN Settings82ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit a QoS profile:1. In the List of QoS Profiles tabl

Pagina 452 - Figure 284

8333. LAN ConfigurationThis chapter describes how to configure the LAN features of your VPN firewall. The chapter contains the following sections:•

Pagina 453 - Notification of Compliance

LAN Configuration84ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage IPv4 Virtual LANs and DHCP Options• Port-Based VLANs • Assign and Manage V

Pagina 454

LAN Configuration85 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Port-Based VLANsThe VPN firewall supports port-based VLANs. Port-based VLANs help

Pagina 455 - Numerics

LAN Configuration86ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Assign and Manage VLAN Profiles To assign VLAN profiles to the LAN ports and man

Pagina 456

LAN Configuration87 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VLAN DHCP OptionsFor each VLAN, you need to specify the Dynamic Host Configuratio

Pagina 457

LAN Configuration88ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 firewall’s LAN IP address). When the DNS proxy option is disabled for a VLAN, all

Pagina 458

LAN Configuration89 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 52. 3. Enter the settings as described in the following table: Table 16.

Pagina 459

9ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN or WAN Port LEDs Not On . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .394Troublesho

Pagina 460

LAN Configuration90ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Port MembershipPort 1, Port 2, Port 3, Port 4 / DMZSelect one, several, or all po

Pagina 461

LAN Configuration91 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Enable DHCP Server Select the Enable DHCP Server radio button to enable the VPN f

Pagina 462

LAN Configuration92ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings.Note: Once you have completed the LAN setup,

Pagina 463

LAN Configuration93 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To edit a VLAN profile:1. On the LAN Setup screen for IPv4 (see Figure 51 on p

Pagina 464

LAN Configuration94ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 53. 3. From the MAC Address for VLANs drop-down list, select Unique. (The

Pagina 465

LAN Configuration95 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following is an example of correctly configured IPv4 addresses:• WAN IP addre

Pagina 466

LAN Configuration96ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Modify the IP address or subnet mask, or both.3. Click Apply to save your sett

Pagina 467

LAN Configuration97 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• There is no need to reserve an IP address for a computer in the DHCP server. Al

Pagina 468

LAN Configuration98ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The Known PCs and Devices table lists the entries in the network database. For ea

Pagina 469

LAN Configuration99 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Click the Add table button to add the computer or device to the Known PCs and

Comentarios a estos manuales

Sin comentarios