background image

 

 
 
 
 
 
 
 
 

 

 

 

 

 

 
  
 
 

LRE1030E 

User’s Manual 

 

Version Release 7.02 (FW:1.xx)

Updated July 28, 2008 

Summary of Contents for Firetunnel 30 LRE1030E

Page 1: ...LRE1030E User s Manual Version Release 7 02 FW 1 xx Updated July 28 2008...

Page 2: ...Black Box Corporation Published by Black Box Corporation All rights reserved Disclaimer Black Box does not assume any liability arising out of the application of use of any products or software descri...

Page 3: ...r cord and DO NOT place the power cord in an area where it can be stepped on DO NOT use Firetunnel 30 in environments with high humidity or high temperatures DO NOT use the same power source for Firet...

Page 4: ...12 1 3 2 Rear Panel 13 1 3 3 Rack Mounting 14 1 3 4 Cabling 14 Chapter 2 Router Applications 2 1 Overview 15 2 2 Bandwidth Management with QoS 15 2 2 1 QoS Technology 15 2 2 2 QoS Policies for Differe...

Page 5: ...ter 34 3 4 Configuring Your PC 35 3 5 Factory Default Settings 37 3 5 1 Username and Password 37 3 5 2 LAN and WAN Port Addresses 38 3 6 Information From Your ISP 38 3 6 1 Protocols 38 3 6 2 Configura...

Page 6: ...4 PPTP 59 4 4 2 1 5 Big Pond 61 4 4 2 2 Bandwidth Setting 62 4 4 2 3 WAN IP Alias 62 4 4 3 Dual WAN 63 4 4 3 1 General Settings 64 4 4 3 2 Outbound Load Balance 65 4 4 3 3 Inbound Load Balance 66 4 4...

Page 7: ...edule 110 4 5 Log E mail Alert 111 4 5 1 Log Configuration 111 4 5 2 System Log server 111 4 5 3 E mail Alert 112 4 6 Save Configuration To Flash 112 4 7 Logout 113 Chapter 5 Troubleshooting 5 1 Basic...

Page 8: ...n 1000 Park Drive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 8 5 4 ISP Connection 119 5 5 Problems with Date and Time 121 5 6 Restoring F...

Page 9: ...le 126 Appendix D Router Setup Examples D 1 Outbound Fail Over 130 D 2 Outbound Load Balancing 132 D 3 Inbound Fail Over 134 D 4 DNS Inbound Fail Over 137 D 5 DNS Inbound Load Balancing 140 D 6 Dynami...

Page 10: ...iretunnel 30 1 2 Product Highlights 1 2 1 Increased Bandwidth Scalability and Resilience With integrated Dual WAN ports Firetunnel 30 combines two broadband lines such as DSL or Cable into one Interne...

Page 11: ...addition Firetunnel 30 firewall can be configured to alert you via email should your network come under fire offering both tight network security and peace of mind 1 2 4 Intelligent Bandwidth Manageme...

Page 12: ...100M Lit green when connected at 100Mbps Not lit when connected at 10Mbps Link ACT Lit when device is connected Blinking when data is transmitting receiving WAN1 Lit when connected to an Ethernet dev...

Page 13: ...er the device is fully booted press and hold RESET until the Status LED begins to blink 2 WAN2 WAN2 10 100M Ethernet port with auto crossover support connect xDSL Cable modem here 3 WAN1 WAN1 10 100M...

Page 14: ...ow for a more detailed explanation 1 3 4 Cabling Most Ethernet networks currently use unshielded twisted pair UTP cabling The UTP cable contains eight conductors arranged in four twisted pairs and ter...

Page 15: ...ter can ensure that latency sensitive applications like voice bandwidth consuming data like gaming packets or even mission critical files efficiently move through the router even under a heavy load Yo...

Page 16: ...ica Asia South America Australia www blackbox eu 16 2 2 2 QoS Policies for Different Applications By setting different QoS policies according to the applications you are running you can use Firetunnel...

Page 17: ...ications The FTP server on the other hand has been given a maximum bandwidth cap to make sure that regular service to both VoIP and normal Internet applications is uninterrupted 2 2 3 Guaranteed Maxim...

Page 18: ...ed Traffic Shaping Policy Based Traffic Shaping allows you to apply specific traffic policies across a range of IP addresses or ports This is particularly useful for assigning different policies for d...

Page 19: ...ve either a higher or lower priority to traffic from this particular service Assigning a higher priority to an application ensures that it is processed ahead of applications with a lower priority and...

Page 20: ...lia www blackbox eu 20 2 2 7 DiffServ DSCP Marking DiffServ a k a DSCP Marking allows you to classify traffic based on IP DSCP values Other interfaces can match traffic based on the DSCP markings DSCP...

Page 21: ...QoS rule will only be applied to the packets whose DSCP field s IP header matches the criteria selected These markings can be used to identify traffic within the network 2 3 Outbound Traffic This sec...

Page 22: ...68 2 2 and PC 2 IP_192 168 2 3 are connected to the Internet via WAN1 IP_230 100 100 1 and WAN2 IP_213 10 10 2 on Firetunnel 30 You can configure Firetunnel 30 to balance the load of each WAN port wit...

Page 23: ...e connected to the Internet via WAN1 ftp xmple dyndns org on Firetunnel 30 A remote computer is trying to access these servers via the Internet Under normal circumstances the remote computer will gain...

Page 24: ...cess the servers via the Internet Using Inbound Load Balancing Firetunnel 30 can direct incoming requests to the correct WAN port based on group assignment For example a sales force can be directed to...

Page 25: ...he router via a remote PC Firetunnel 30 based on settings specified by the user will direct the requesting PC to the correct WAN port by replying the selected WAN IP address through the built in DNS s...

Page 26: ...ough WAN1 200 200 200 1 to the built in DNS server The DNS server will reply 200 200 200 1 because this is the only active WAN port Should WAN1 fail Firetunnel 30 will instead reply with WAN2 s IP add...

Page 27: ...ing algorithm Firetunnel 30 can direct incoming requests to either WAN port based on the amount of load each WAN port is currently experiencing If WAN2 is experiencing a heavy load Firetunnel 30 respo...

Page 28: ...WAN2 and decide which WAN IP to reply to the request 3 After the decision is made Firetunnel 30 will route the DNS reply to the user through WAN2 4 The user will receive the DNS reply with the IP add...

Page 29: ...Private Networking with Firetunnel 30 2 6 1 General VPN Setup There are typically three different VPN scenarios The first is a Gateway to Gateway setup where two remote gateways communicate over the I...

Page 30: ...2 6 2 VPN Planning Fail Over Configuring your VPN with Fail Over allows Firetunnel 30 to automatically default to WAN2 should WAN1 fail Because the dynamic domain name Firetunnel com is configured fo...

Page 31: ...ail Over provides added reliability to your VPN 2 6 3 Concentrator The VPN Concentrator provides an easy way for branch offices to connect to headquarter through a VPN tunnel All branch office traffic...

Page 32: ...al subnet 0 0 0 0 Local mask 0 0 0 0 Remote subnet 192 168 3 0 Remote mask 255 255 255 0 Local subnet 192 168 3 0 Local mask 255 255 255 0 Remote subnet 0 0 0 0 Remote mask 0 0 0 0 Local subnet 0 0 0...

Page 33: ...s and increase the efficiency of your network consider the following items before setting up your network for the first time 1 Plan your network Decide whether you are going to use one or both WAN por...

Page 34: ...nnecting Your Router Connecting Firetunnel 30 is an easy three step process 1 Connect Firetunnel 30 to your LAN by connecting Ethernet cables from your networked PCs to the LAN ports on the router Con...

Page 35: ...in the same subnet as the router The default IP address of Firetunnel 30 is 192 168 1 254 with a subnet mask of 255 255 255 0 Using the default configuration networked PCs must reside in the same subn...

Page 36: ...ox coming up for Windows 95 98 enter command Confirm by Pressing OK A new windows is coming up where you can enter commands Enter ipconfig Windows will respond Windows IP Configuration Ethernet adapte...

Page 37: ...P Client DHCP server DHCP server is enabled Start IP Address 192 168 1 100 End IP Address 192 168 1 199 3 5 1 User Name and Password The default user name and password are admin and admin respectively...

Page 38: ...6 1 Protocols Before configuring this device you have to check with your ISP Internet Service Provider to find out what kind of service is provided such as DHCP Static IP PPPoE or PPTP The following...

Page 39: ...retunnel 30 After the network and firewall are configured Firetunnel 30 will login automatically and you will no longer need to run the login program from your PC 3 6 2 Configuration Information If yo...

Page 40: ...face open your web browser enter the IP address of your router which by default is 192 168 1 254 and click Go A user name and password window prompt will appear Enter your user name and password the d...

Page 41: ...ngs will be erased if you power off or restart the device 2 Click SAVE CONFIG to save the current settings permanently to the device 3 Click RESTART to restart the device There are two options to rest...

Page 42: ...istics about your Firetunnel 30 In this menu you will find the following sections ARP Table Routing Table Session Table DHCP Table IPSec Status PPTP Status System Status System Log LAN Traffic Statist...

Page 43: ...connects to Static Static status of the ARP table entry NO indicates dynamically generated ARP table entries YES indicates static ARP table entries added by the user 4 2 2 Routing Table The Routing T...

Page 44: ...of the session From port source port of the session To IP Destination IP of the session To port Destination port of the session Sessions Filter when the presented field is filled please click Filter...

Page 45: ...omputer name of the client MAC Address The MAC address of client 4 2 5 IPSec Status The IPSec Status window displays the status of the IPSec Tunnels that are currently configured on your Firetunnel 30...

Page 46: ...hether the PPTP connection is currently Enable or Disable Status Whether the PPTP is Active Inactive or Disable Type Whether the Connection type is Remote Access or LAN to LAN Peer Network The Remote...

Page 47: ...ess in Configuration System Email Alert See the Email Alert section for more details 4 2 9 LAN Traffic Statistics This page displays the router s LAN Traffic Statistics entries Major events are logged...

Page 48: ...Settings and Big Pond Settings 4 3 1 DHCP The following is information regarding your ISP that you will need to enter in order to properly configure your Internet connection If you select to Obtain an...

Page 49: ...lish the PPPoE session when disconnected by the ISP select Always Connect If you want to establish a PPPoE session only when there is a packet requesting access to the Internet i e when a program on y...

Page 50: ...cted by the ISP select Always Connect If you want to establish a PPTP session only when there is a packet requesting access to the Internet i e when a program on your computer attempts to access the I...

Page 51: ...n The Configuration menu allows you to set many of the operating parameters of Firetunnel 30 In this menu you will find the following sections LAN WAN Dual WAN System Firewall VPN QoS Virtual Server A...

Page 52: ...efault RIP RIP v2 Broadcast and RIP v2 Multicast Check to enable RIP 4 4 1 2 DHCP Server In this menu you can disable or enable the Dynamic Host Configuration Protocol DHCP server The DHCP protocol al...

Page 53: ...nt when they request an IP address from the DHCP server Click Apply to enable this function Fixed Host allows specific computer network clients to have a reserved IP address IP Address Enter the IP ad...

Page 54: ...ss you would like to use Netmask Please input the Netmask you would like to use WAN IP Address Please click Candidates to select the WAN IP address you would like to use from WAN Alias list Click the...

Page 55: ...tings Bandwidth Settings and WAN IP Alias 4 4 2 1 Settings This WAN Service Table displays the different WAN connections that are configured on Firetunnel 30 To edit any of these connections click Edi...

Page 56: ...your MAC address in the blanks below Candidates You can also select the MAC address from the list in the Candidates DNS If your ISP requires you to manually setup DNS settings check the checkbox and e...

Page 57: ...ect the MAC address from the list in the Candidates Primary DNS Enter the primary DNS provided by your ISP Secondary DNS Enter the secondary DNS provided by your ISP RIP To activate RIP select Send Re...

Page 58: ...access the Internet select Trigger on Demand Idle Time Auto disconnect the router when there is no activity on the line for a predetermined period of time Select the idle time from the drop down menu...

Page 59: ...n Configuration Firewall Packet filter Click Apply to save your changes To reset to defaults click Reset 4 4 2 1 4 PPTP Username Enter your user name Password Enter your password Retype Password Retyp...

Page 60: ...you to another page for inputting the IP address information MAC Address If your ISP requires you to input a WAN Ethernet MAC check the checkbox and enter your MAC address in the blanks below Candidat...

Page 61: ...lly setup DNS settings check the checkbox and enter your primary and secondary DNS RIP To activate RIP select Send Receive or Both from the drop down menu To disable RIP select Disable from the drop d...

Page 62: ...utbound bandwidth for each WAN port WAN1 Enter your ISP inbound and outbound bandwidth for WAN1 WAN2 Enter your ISP inbound and outbound bandwidth for WAN2 NOTE These values entered here are reference...

Page 63: ...would like to use Interface Please select the WAN Interface that you would like to add the additional WAN IP to Click the Apply button to add the configuration into the WAN IP Alias 4 4 3 Dual WAN In...

Page 64: ...ser is able to enable or disable it Connectivity Decision Establishes the number of times probing the connection has to fail before the connection is judged as failed Probe Cycle The number of seconds...

Page 65: ...the users use will not tell the difference of the WAN IP addresses some applications in the Internet need to identify the source IP address e g Back Forum Balance by Session Round Robin Balances sess...

Page 66: ...Uses an IP hash to balance traffic based on weight of link bandwidth capacity Balance by weight Uses an IP hash to balance traffic based on a ratio Enter the desired ratio into the blanks provided Cli...

Page 67: ...FQDN Primary Name Server The name assigned to the Primary Name Server e g aaa its FQDN is aaa abc com Admin Mail Box The administrator s email account e g admin abc com Serial Number It is the versio...

Page 68: ...click Create Domain Name The domain name of the local host Host URL The URL to be mapped Private IP Address The IP address of the local host Candidates You can also select the Candidates which are ref...

Page 69: ...Create button to create a new policy entry Policies entered would tell specific types of Internet traffic from a particular range of IPs to go to a particular range of IPs with ONE WAN port rather tha...

Page 70: ...here s where the subnet mask can be entered Destination IP Range All Destination IP Click it to specify all source IPs Specified Destination IP Click to specify a specific destination IP address and...

Page 71: ...System Log and E mail Alert 4 4 4 1 Time Zone Firetunnel does not use an onboard real time clock instead it uses the Network Time Protocol NTP to acquire the current time from an NTP server outside y...

Page 72: ...e Access To allow remote users to configure and manage Firetunnel 30 through the Internet select the Enable radio button To deactivate remote access select the Disable radio button This function also...

Page 73: ...lease specify the IP Address that is allowed to access PC from the subnet Please specify the subnet that is allowed to access 4 4 4 3 Firmware Upgrade Upgrading your Firetunnel 30 s firmware is a quic...

Page 74: ...t you have a backup handy It is advisable to backup your router s settings before making any significant changes to your router s configuration To backup your router s settings click Backup and select...

Page 75: ...figuration select the Current Settings radio button and click Restart If you wish to restart the router using the factory default settings select Factory Default Settings and click Restart to reboot F...

Page 76: ...ration interface it requires the administrator to login with a password You can change your password by entering your new password in both fields Click Apply to save your changes Click Reset to reset...

Page 77: ...tateful Packet Inspection SPI firewall for controlling Internet access from your LAN and preventing attacks from hackers Your router also acts as a natural Internet firewall when using Network Address...

Page 78: ...r Forward the packet specified in this filter entry Direction Incoming Packet Filter rules prevent unauthorized computers or applications accessing your local network from the Internet Outgoing Packet...

Page 79: ...application type you would like to apply for automatic input Schedule Click the Candidates and select what you need Log You can Disable Enable the log statistics 4 4 5 2 URL Filter The URL Filter is a...

Page 80: ...k Cookie to filter web access with Cookie components Click Block Surfing by IP Address to filter web access with an IP address as the domain name Exception List You can input a list of IP addresses as...

Page 81: ...d previously Restrict URL Features Use this to disable certain web features Select the options you want Block Java Applet Block ActiveX Block Web proxy Block Cookie Block Surfing by IP Address and cli...

Page 82: ...C Filter LAN Mac Filter can decide that Firetunnel will serve those devices at LAN side or not by MAC Address Default Rule Forward or Drop all LAN request Forward by default Create You can also input...

Page 83: ...tion When Matched Select to Drop or Forward the packet specified in this filter entry MAC Address The MAC Address you would like to apply Candidates You can also select the Candidates which are referr...

Page 84: ...tacks by preventing ping requests from the Internet Use this menu to enable or disable function 4 4 5 5 Intrusion Detection Intrusion Detection can prevent most common DoS attacks from the Internet or...

Page 85: ...to Firetunnel30 This function limits the number of connections on per user basis This is useful when controlling users who will use the applications which create a large number of connections such as...

Page 86: ...N2 Auto The device will automatically apply the tunnel to WAN1 or WAN2 depending on which WAN interface is active when the IPSec tunnel is being established Note Auto only applies to Fail Over mode Fo...

Page 87: ...remote router using Fixed Internet IP or domain name by using main mode Remote Secure Gateway Address or Host Name The IP address or hostname of the remote VPN gateway Remote Network The subnet of th...

Page 88: ...l Remote Network The subnet of the remote network Allows you to enter an IP address and netmask Back Back to the Previous page Next Go to the next page 3 LAN to Host Firetunnel would like to establish...

Page 89: ...emote gateway According to the input value the ID type will be auto defined as IP Address FQDN DNS or FQUN E mail Back Back to the Previous page Next Go to the next page 5 LAN to Host for Firetunnel V...

Page 90: ...Asia South America Australia www blackbox eu 90 After your configuration is done you will see a Configuration Summary Back Back to the Previous page Done Click Done to apply the rule 4 4 6 1 2 IPSec...

Page 91: ...el will apply to WAN1 Select interface WAN1 WAN2 Select interface WAN2 Auto The device will automatically apply the tunnel to WAN1 or WAN2 depending on which WAN interface is active when the IPSec tun...

Page 92: ...enter an IP address and netmask IP Range The IP Range of the local network Single Address The IP address of the local host Remote This section configures the remote host Secure Gateway Address or Doma...

Page 93: ...SP Encapsulating Security Payload Use ESP for greater security so that data will be encrypted and authenticated AH data will be authenticated but not encrypted Encryption Protocol Select the encryptio...

Page 94: ...of the IKE security association The value is in seconds eg 28800 seconds 8 hours Key Life Time Allows you to specify the timer interval for renegotiation of another key The value is in seconds eg 3600...

Page 95: ...nels to an organization s network via the Internet PPTP function Select Enable to activate PPTP Server Disable to deactivate PPTP Server function Auth Type The authentication type Pap or Chap PaP Chap...

Page 96: ...Retype Password Please repeat the same password as previous field Connection Type Select Remote Access for single user Select LAN to LAN for remote gateway Peer Network IP Please input the IP for remo...

Page 97: ...traffic WAN1 Inbound QoS Function QoS status for WAN1 inbound Select Enable to activate QoS for WAN1 s incoming traffic Select Disable to deactivate Max ISP Bandwidth The maximum bandwidth afforded by...

Page 98: ...raffic types follows the same process To make a new rule click Rule Table This will bring you to the Rule Table which displays the rules currently in effect Next click Create to open the QoS Rule Conf...

Page 99: ...ddresses this rule applies to Destination IP Address Range The range of destination IP Addresses this rule applies to Source Port Range The range of source ports this rule applies to Destination Port...

Page 100: ...Some ports have numbers that are pre assigned to them by the Internet Assigned Numbers Authority IANA and these are referred to as well known ports Servers follow the well known port assignments so cl...

Page 101: ...8 1 DMZ The DMZ Host is a local computer exposed to the Internet When setting a particular internal IP address as the DMZ Host all incoming packets will be checked by the Firewall and NAT algorithms t...

Page 102: ...ernal servers e g a web server FTP server Email server or game server the router can act as a virtual server You can set up a local server with a specific port number for the service to use e g web HT...

Page 103: ...e LAN server host IP address that the service request from the Internet will be sent to Candidates You can also select the Candidates which are referred from the ARP table for automatic input NOTE You...

Page 104: ...ement IGMP and VLAN Bridge 4 4 9 1 Static Route The static route settings enable the router to route IP packets to another network subnet The routing table stores the routing information so the router...

Page 105: ...P address to a static hostname allowing users whose ISP does not assign them a static IP address to use a domain name This is especially useful when hosting servers via your WAN connection so that any...

Page 106: ...ed and required Dynamic DNS Server Select the DDNS service you have established an account with Wildcard Select this check box to enable the DYNDNS Wildcard Domain Name Enter your registered domain na...

Page 107: ...fies their own IP address of 192 168 1 100 and sets the logout time to be 100 seconds The router will only allow User A access from the IP address 192 168 1 100 to logon to the Web GUI by typing http...

Page 108: ...ooping and IGMP proxy are functions to be used for home users who will access IPTV applications IGMP Snooping Please select enable or disable IGMP Snooping function IGMP Proxy Please select enable or...

Page 109: ...and specify the member VLAN Mode Select Disable to disable VLAN mode select Bridge Mode to use VLAN Bridge function and select Tagging Mode to use the VLAN Tagging mode option Click Create to create a...

Page 110: ...blackbox eu 110 this VLAN ID group Untagged Member port s Please check the interface that you would like to use in this VLAN ID group Click Apply to add this rule 4 4 9 6 Schedule You can configure th...

Page 111: ...me Click the Apply to complete the configuration or Cancel to return 4 5 Log E mail Alert You can configure the Log Statistics and E mail Alert options under this menu There re three section Log Confi...

Page 112: ...the IP address of your SMTP mail server Mail server Login If your mail server needs the account and password to login please check the Enable option Username Type in the username of your mail server P...

Page 113: ...at the router is restricted to only one PC accessing the web configuration interface at a time Once a PC has logged into the web interface other PCs cannot gain access until the current PC has logged...

Page 114: ...tlet Check that you are using the 12VDC power adapter supplied with this unit originally If the error persists you may have a hardware problem and should contact technical support 5 1 2 LEDs Never Tur...

Page 115: ...ry entering the default User Name and Password User Name admin Password admin Please note that both the User Name and Password are case sensitive If this fails you can restore your Firetunnel 30 to it...

Page 116: ...ion between the PC and the router Make sure your PC s IP address is on the same subnet as the router If your Firetunnel 30 s IP address has changed and you don t know the current IP address reset the...

Page 117: ...In Internet Explorer select Tools Internet Options 2 Under the Privacy tab clear the Block pop ups checkbox and click Apply to save your changes Enabling Pop up Blockers with Exceptions If you only wa...

Page 118: ...hat Scripting of Java applets is set to Enabled 5 Click OK to close the dialogue 5 2 3 3 Java Permissions The following Java Permissions should also be given for the Web Configuration Interface to dis...

Page 119: ...and passwords are case sensitive If your ISP requires MAC address authentication clone the MAC address from your PC on the LAN as Firetunnel 30 s WAN MAC address If your ISP requires host name authen...

Page 120: ...r DSL modem 4 When the modem has finished synchronizing with the ISP generally shown by LEDs on the modem turn on the power to your router If an IP address still cannot be obtained Your ISP may requir...

Page 121: ...PC may not have the router correctly configured as its TCP IP gateway 5 5 Problems with Date and Time If the date and time is not being displayed correctly be sure to set it for your Firetunnel 30 via...

Page 122: ...enever one connection should fail Virtual Private Network IPSec VPN supports up to 30 IPSec tunnels IPSec VPN performance is up to 30 Mbps PPTP VPN support up to 4 PPTP tunnels PPTP VPN performance is...

Page 123: ...on the Internet Java Applet Active X Cookie Blocking Quality of Service Control Supports DiffServ approach Traffic prioritization and bandwidth management based on IP protocol port number and IP or MA...

Page 124: ...Auto Crossover MDI MDIX Ethernet LAN 8 ports 10 100 Base T switch support Auto Crossover MDI MDIX Physical Specifications Dimensions 18 98 x 6 54 x 1 77 482mm x 166 mm x 45mm with Bracket 9 84 x 6 54...

Page 125: ...e limits are designed to provide reasonable protection against harmful interference in a commercial environment If this equipment does cause harmful interference to radio television reception which ca...

Page 126: ...initial message of ISAKMP Sending the first initial message of main mode phase I Done to exchange encryption algorithm hash algorithm and authentication method Send Aggressive mode initial message of...

Page 127: ...authentication Received Main mode third response message of ISAKMP Received the third response message of main mode Done for authentication Received Aggressive mode initial ISAKMP Message Received the...

Page 128: ...ode Phase II ISAKMP IKE Packet Indicates IKE packet ISAKMP Information Indicates Information packet ISAKMP Quick Mode Indicates quick mode packet Rejected IKE Messages NO PROPOSAL CHOSEN No acceptable...

Page 129: ...ID INFORMATION Initial Aggressive Mode packet claiming to be from ID on IP but no connection has been authorized IKE Negotiated Status Messages Received Delete SA payload and deleting IPSEC State int...

Page 130: ...box com EU Africa Asia South America Australia www blackbox eu 130 Appendix D Router Setup Examples D 1 Outbound Fail Over Step 1 Go to Configuration WAN ISP Settings Select WAN1 and WAN2 and click Ed...

Page 131: ...utton Under Connectivity Decision input the number of times Firetunnel 30 should probe the WAN before deciding that the ISP is in service or not 3 by default Next input the duration of the probe cycle...

Page 132: ...Save Config to save all changes to flash memory D 2 Outbound Load Balancing With Outbound Load Balancing you can improve upload performance by optimizing your connection via Dual WAN To do this follow...

Page 133: ...PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 133 Step 2 Configure your WAN2 ISP settings and click Apply Step 3 Go to Configuration Dual WAN General...

Page 134: ...ad Balance mechanism you want and click Apply Step 5 Click Save Config to save all changes to flash memory D 3 Inbound Fail Over Configuring your Firetunnel 30 for Inbound Fail Over is a great way to...

Page 135: ...USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 135 Step 1 From the Web Configuration Interface go to Configuration Dual WAN General Settings Select the Fail Over r...

Page 136: ...Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 136 Step 3 Go to Configuration Advanced Dynamic DNS Set the WAN1 DDNS settings Step 4 From the...

Page 137: ...Inbound Fail Over NOTE Before proceeding please ensure that both WAN1 and WAN2 are properly Built in DNS 192 168 2 2 192 168 2 3 FTP HTTP 200 200 200 1 www mydomain com 200 200 200 1 Authoritative Dom...

Page 138: ...ings provided by your ISP If not please refer to Chapter 4 2 2 1 ISP Settings for details on how to configure your WAN ports Step 1 Go to Configuration Dual WAN General Settings Select the Fail Over r...

Page 139: ...U Africa Asia South America Australia www blackbox eu 139 Step 3 Input DNS Server 1 settings and click Apply Step 4 Configure your Host URL Mapping for DNS Server 1 by clicking Edit to enter the Host...

Page 140: ...Step 1 Go to Configuration Dual WAN General Settings Select the Load Balance radio button Built in DNS 192 168 2 2 192 168 2 3 FTP HTTP 200 200 200 1 www mydomain com 200 200 200 1 Authoritative Domai...

Page 141: ...blackbox com EU Africa Asia South America Australia www blackbox eu 141 Step 2 Go to Configuration Dual WAN Inbound Load Balance Server Settings and configure DNS Server 1 Step 3 Go to Configuration D...

Page 142: ...00 Park Drive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 142 Step 4 Next configure your HTTP mapping Step 5 Click Save Config to save all...

Page 143: ...ustralia www blackbox eu 143 D 6 Dynamic DNS Inbound Load Balancing Step 1 Go to Configuration WAN Bandwidth Settings Configure your WAN inbound and outbound bandwidth www bbox2 dyndns org Remote Acce...

Page 144: ...tion or not Step 3 Go to Configuration Dual WAN Outbound Load Balance Choose your load balance policy and click Apply to apply your changes If you selected Based on session mechanism as your policy th...

Page 145: ...00 Park Drive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 145 Step 4 Go to Configuration Advanced Dynamic DNS and input the dynamic DNS se...

Page 146: ...Black Box Corporation 1000 Park Drive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 146 WAN1 WAN 2...

Page 147: ...n 1000 Park Drive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 147 Step 5 Go to Configuration Virtual Server and set up a virtual server fo...

Page 148: ...www blackbox com EU Africa Asia South America Australia www blackbox eu 148 Step 6 Click Save Config to save all changes to flash memory D 7 VPN Configuration This section outlines some concrete examp...

Page 149: ...work Any Local Address Any Local Address IP Address 192 168 0 0 192 168 1 0 Netmask 255 255 255 0 255 255 255 0 Remote Secure Gateway Address or Hostname 69 121 1 3 69 121 1 30 ID IP Address IP Addres...

Page 150: ...America Australia www blackbox eu 150 D 7 2 Host to LAN Single client Head Office Local ID IP Address IP Address Data 69 121 1 30 69 121 1 3 Network Any Local Address Any Local Address IP Address 0 0...

Page 151: ...America Australia www blackbox eu 151 ID IP Address IP Address Data 69 121 1 3 69 121 1 30 Network Subnet Single Address IP Address 192 168 1 0 69 121 1 30 Netmask 255 255 255 0 255 255 255 255 Propo...

Page 152: ...er Gateway to Gateway Step 1 Go to Configuration Dual WAN General Settings Enable Fail Over by selecting the Fail Over radio button Then configure your Fail Over policy Before Fail Over After Fail Ove...

Page 153: ...www blackbox com EU Africa Asia South America Australia www blackbox eu 153 Step 2 Go to Configuration Advanced Dynamic DNS and configure your dynamic DNS settings Both WAN1 and WAN2 Step 3 Go to Conf...

Page 154: ...al mask 0 0 0 0 Remote ID Type Subnet Remote subnet 192 168 3 0 Remote mask 255 255 255 0 Local ID Type Subnet Local subnet 192 168 3 0 Local mask 255 255 255 0 Remote ID Type Subnet Remote subnet 0 0...

Page 155: ...Africa Asia South America Australia www blackbox eu 155 Step 1 Go to Configuration VPN IPSec IPSec Policy and configure the link from Firetunnel 30 to Firetunnel 10 Branch A Step 2 Go to Configuration...

Page 156: ...e Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 156 Step 3 Go to Configuration VPN IPSec IPSec Policy and configure the connection from Fire...

Page 157: ...anada www blackbox com EU Africa Asia South America Australia www blackbox eu 157 Step 4 Go to Configuration VPN IPSec IPSec Policy and configure the connection from Firetunnel 10 Branch B to Firetunn...

Page 158: ...ww blackbox com EU Africa Asia South America Australia www blackbox eu 158 D 10 Protocol Binding Step 1 Go to Configuration Dual WAN General Settings Select the Load Balancing radio button Step 2 Go t...

Page 159: ...ckbox eu 159 Step 3 Go to Configuration Dual WAN Protocol Binding and configure settings for WAN2 Step 4 Click Save Config to save all changes to flash memory D 11 Intrusion Detection Internet Interne...

Page 160: ...ration Firewall Intrusion Detection and Enable the settings Step 2 Click Apply and then Save Config to save all changes to flash memory D 12 PPTP Remote Access by Windows XP Internet Internet Windows...

Page 161: ...ive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 161 Step1 Go to Configuration VPN PPTP and Enable the PPTP function Click Apply Step2 Clic...

Page 162: ...Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 162 Step3 Click Apply you can see the account is successfully created Step4 Click Save Config...

Page 163: ...Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 163 Step5 In Windows XP go Start Settings Network Connections Step6 In Network Tasks Click Cr...

Page 164: ...awrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 164 Step7 Select Connect to the network at my workplace and press Next Step8 Select Virtual Pri...

Page 165: ...Drive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 165 Step9 Input the user defined name for this connection and press Next Step10 Input PP...

Page 166: ...e PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 166 Step11 Please press Finish Step12 Double click the connection and input Username and Password tha...

Page 167: ...Corporation 1000 Park Drive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 167 PS You can also refer the Properties Security page as below b...

Page 168: ...Remote Access by Firetunnel Step1 Go to Configuration VPN PPTP and Enable the PPTP function then Click Apply Step2 Click Create to create a PPTP Account Internet Internet Internet Internet PPTP Tunnel...

Page 169: ...Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 169 Step3 Click Apply you can see the account is successfully created Step4 Click Save Config...

Page 170: ...ark Drive Lawrence PA 15055 1018 USA Canada www blackbox com EU Africa Asia South America Australia www blackbox eu 170 Step5 In another Firetunnel as Client Go to Configuration WAN ISP Settings Step6...

Reviews: