background image

FR328S Cable/DSL ProSafe Firewall with Dial Back-Up

C-12

Preparing Your Network

 

Restarting the Network

Once you’ve set up your computers to work with the firewall, you must reset the network for the 
devices to be able to communicate correctly. Restart any computer that is connected to the firewall.

After configuring all of your computers for TCP/IP networking and restarting them, and 
connecting them to the local network of your FR328S Firewall, you are ready to access and 
configure the firewall.

FR328S.book  Page 12  Monday, September 9, 2002  4:01 PM

Summary of Contents for ProSafe FR328S

Page 1: ...Sept 2002 NETGEAR Inc 4500 Great America Parkway Santa Clara CA 95054 USA Phone 1 888 NETGEAR FR328S Cable DSL ProSafe Firewall with Dial Back Up Reference Manual FR328S book Page i Monday September 9...

Page 2: ...tallation This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instructions may cause harmful interference to radio communications...

Page 3: ...r to the notes in the operating instructions Federal Office for Telecommunications Approvals has been notified of the placing of this equipment on the market and has been granted the right to test the...

Page 4: ...iv FR328S book Page iv Monday September 9 2002 4 01 PM...

Page 5: ...agement 1 3 What s in the Box 1 5 The Firewall s Front Panel 1 5 The Firewall s Rear Panel 1 6 Chapter 2 Connecting the Firewall to the Internet What You Will Need Before You Begin 2 1 LAN Hardware Re...

Page 6: ...e Example Blocking Instant Messenger 3 10 Order of Precedence for Rules 3 12 Services 3 13 Setting Times and Scheduling Firewall Services 3 14 Chapter 4 Managing Your Network Network Management Inform...

Page 7: ...ED Stays On 6 2 Local or Internet Port Link LEDs Not On 6 2 Troubleshooting the Web Configuration Interface 6 4 Troubleshooting the ISP Connection 6 5 Troubleshooting a TCP IP Network Using a Ping Uti...

Page 8: ...iguring Windows 95 98 and ME for TCP IP Networking C 2 Install or Verify Windows Networking Components C 2 Enabling DHCP to Automatically Configure TCP IP Settings C 4 Selecting Windows Internet Acces...

Page 9: ...Contents ix Obtaining ISP Configuration Information for Macintosh Computers C 11 Restarting the Network C 12 Glossary Index FR328S book Page ix Monday September 9 2002 4 01 PM...

Page 10: ...x Contents FR328S book Page x Monday September 9 2002 4 01 PM...

Page 11: ...rocedure 3 1 Changing the Built In Password 3 2 Procedure 3 1 Changing the Administrator Login Timeout 3 3 Procedure 3 2 Block Keywords and Sites 3 4 Procedure 3 3 Define Services 3 13 Procedure 3 4 S...

Page 12: ...xii FR328S book Page xii Monday September 9 2002 4 01 PM...

Page 13: ...s tutorial information is provided in the Appendices Typographical Conventions This guide uses the following typographical conventions italics Book titles and UNIX file command and directory names cou...

Page 14: ...frequently asked questions and a means for submitting technical questions online Note This format is used to highlight information of importance or special interest Procedure This format is used to le...

Page 15: ...FR328S Cable DSL ProSafe Firewall with Dial Back Up About This Manual xv FR328S book Page xv Monday September 9 2002 4 01 PM...

Page 16: ...FR328S book Page xvi Monday September 9 2002 4 01 PM...

Page 17: ...r connectivity through the serial port provides highly reliable Internet access for up to 253 users Key Features The FR328S offers the following features A Powerful True Firewall Unlike simple Interne...

Page 18: ...d the Internet WAN interfaces are autosensing and capable of full duplex or half duplex operation The firewall incorporates Auto UplinkTM technology Each LOCAL Ethernet port will automatically sense w...

Page 19: ...sers to find your network using a domain name when your IP address is not permanently assigned The firewall contains a client that can connect to many popular Dynamic DNS services to register your dyn...

Page 20: ...e firewall incorporates built in diagnostic functions such as Ping DNS lookup and remote reboot These functions allow you to test Internet connectivity and reboot the firewall You can use these diagno...

Page 21: ...anty and registration card Support information card If any of the parts are incorrect missing or damaged contact your NETGEAR dealer Keep the carton including the original packing materials in case yo...

Page 22: ...Label Activity Description POWER On Power is supplied to the firewall TEST On Off The system is initializing The system is ready and running MODEM On Blinking The port detected a link with the Interne...

Page 23: ...ive Internet service such as that provided by a DSL or Cable modem account 3 The Internet Service Provider ISP configuration information for your DSL or Cable modem account LAN Hardware Requirements T...

Page 24: ...ion information Your ISP should have provided you with all the information needed to connect to the Internet If you cannot locate this information you can ask your ISP to provide it or you can try one...

Page 25: ...______ ______ ______ ______ Gateway IP Address ______ ______ ______ ______ ISP DNS Server Addresses If you were given DNS server addresses fill in the following Primary DNS Server IP Address ______ _...

Page 26: ...ant to help you through this procedure Procedure 2 2 Connecting the Firewall to Your LAN There are three steps to connecting your firewall 1 Connect the firewall to your network 2 Log in to the firewa...

Page 27: ...to your Cable or DSL modem Figure 2 1 Disconnect the Cable or DSL Modem c Connect the Ethernet cable A from your Cable or DSL modem to the FR328S s Internet port Figure 2 2 Connect the Cable or DSL Mo...

Page 28: ...on This feature also eliminates the need to worry about crossover cables as Auto Uplink will accommodate either type of cable to make the right connection e Turn on the Cable or DSL modem and wait abo...

Page 29: ...is lit indicating a link has been established to the cable or DSL modem c Next use a browser like Internet Explorer or Netscape to log in to the firewall at its default address of http 192 168 0 1 Fi...

Page 30: ...tions on page 6 1 Connecting the FR328S Firewall to the Internet The firewall is now properly attached to your network You are now ready to configure your firewall to connect to the Internet There are...

Page 31: ...atically When the Wizard launches select Yes in the menu below to allow the firewall to automatically determine your connection Figure 2 7 Built in Web based Configuration Manager Setup Wizard Note If...

Page 32: ...e Setup Wizard determines that your Internet service account uses a login protocol such as PPP over Ethernet PPPoE you will be directed to a menu like the PPPoE menu in Figure 2 8 Figure 2 8 Setup Wiz...

Page 33: ...DNS Server If a Secondary DNS Server address is available enter it also If you enter an address here after you finish configuring the firewall reboot your PCs so that the settings take effect 4 Click...

Page 34: ...does not transfer an address you must obtain it from the ISP and enter it manually here If you enter an address here you should reboot your PCs after configuring the firewall 3 The Router s MAC Addre...

Page 35: ...you recorded in Record Your Internet Connection Information on page 2 3 2 Enter the IP address of your ISP s Primary DNS Server If a Secondary DNS Server address is available enter it also A DNS serve...

Page 36: ...firewall to your ISDN or dial up analog modem 2 Configure the firewall 3 Connect to the Internet Follow the steps below to configure a serial port Internet connection on your firewall 1 Connect the Fi...

Page 37: ...o Appendix C Preparing Your Network a Use a browser to log in to the firewall at http 192 168 0 1 with its default User Name of admin and default Password of password or using whatever Password you ha...

Page 38: ...f you want to enable a Idle Time disconnect check the box and enter a time in minutes To configure the TCP IP settings fill in whatever address parameters your ISP provided e Configure the Modem param...

Page 39: ...pying the modem string settings from the PC configuration and pasting them into the FR328S Modem Properties Initial String field For more information on this procedure please refer to the support area...

Page 40: ...nects to the Internet when one of your computers requires access It is not necessary to run a dialer or login application such as Dial Up Networking or Enternet to connect log in or disconnect These f...

Page 41: ...iguring Your Internet Connection You can manually configure your firewall using the menu below or you can allow the Setup Wizard to determine your configuration as described in the previous section Fi...

Page 42: ...nger need to launch the ISP s login program on your PC in order to access the Internet When you start an Internet application your firewall will automatically log you in 4 Internet IP Address If your...

Page 43: ...ddress of that PC This feature allows your firewall to masquerade as that PC by cloning its MAC address To change the MAC address select Use this Computer s MAC address The firewall will then capture...

Page 44: ...FR328S Cable DSL ProSafe Firewall with Dial Back Up 2 22 Connecting the Firewall to the Internet FR328S book Page 22 Monday September 9 2002 4 01 PM...

Page 45: ...er admin for the firewall User Name and password for the firewall Password You can use procedures below to change the firewall s password and the amount of time for the administrator s login timeout N...

Page 46: ...the Main Menu of the browser interface under the Maintenance heading select Set Password to bring up the menu shown in Figure 3 2 Figure 3 2 Set Password menu 3 To change the password first enter the...

Page 47: ...ety of options for blocking Internet based content and communications services With its content filtering feature the FR328S Firewall prevents objectionable content from reaching your PCs The FR328S a...

Page 48: ...User Name of admin default password of password or using whatever Password and LAN address you have chosen for the firewall 2 Click on the Block Sites link of the Security menu Figure 3 3 Block Sites...

Page 49: ...used to block or allow specific traffic passing through from one side to the other Inbound rules WAN to LAN restrict access by outsiders to private resources selectively allowing only specific outside...

Page 50: ...menu To edit an existing rule select its button on the left side of the table and click Edit To delete an existing rule select its button on the left side of the table and click Delete To move an exis...

Page 51: ...opens holes in your firewall Only enable those ports that are necessary for your network Following are two application examples of inbound rules Inbound Rule Example A Local Public Web Server If you...

Page 52: ...C or Server on your LAN which will receive the inbound traffic covered by this rule WAN Users These settings determine which packets are covered by the rule based on their source WAN IP address Select...

Page 53: ...mple Videoconference from Restricted Addresses Considerations for Inbound Rules If your external IP address is assigned dynamically by your ISP the IP address may change periodically as the DHCP lease...

Page 54: ...address the time of day the type of service being requested service port number Following is an application example of outbound rules Outbound Rule Example Blocking Instant Messenger If you want to b...

Page 55: ...ddresses are covered by this rule Address range If this option is selected you must enter the Start and Finish fields Single address Enter the required address in the Start fields WAN Users These sett...

Page 56: ...c attempting to pass through the firewall the packet information is subjected to the rules in the order shown in the Rules Table beginning at the top and proceeding to the default rules at the bottom...

Page 57: ...ineering Task Force IETF and published in RFC1700 Assigned Numbers Service numbers for other applications are typically chosen from the range 1024 to 65535 by the authors of the application Although t...

Page 58: ...ime Protocol NTP to obtain the current time and date from one of several Network Time Servers on the Internet In order to localize the time for your log entries you must select your Time Zone from the...

Page 59: ...your time zone is currently in daylight savings time Note If your region uses Daylight Savings Time you must manually check Adjust for Daylight Savings Time on the first day of Daylight Savings Time a...

Page 60: ...d and LAN address you have chosen for the firewall 2 Click on the Schedule link of the Security menu to display menu shown above in the Schedule Services menu 3 To block Internet services based on a s...

Page 61: ...ewall with Dial Back Up Network Management Information The FR328S provides a variety of status and usage information which is discussed below Viewing Router Status and Usage Statistics From the Main M...

Page 62: ...t DHCP If set to None the firewall is configured to use a fixed IP address on the WAN If set to Client the firewall is configured to obtain an IP address dynamically from the ISP IP Subnet Mask This f...

Page 63: ...e number of packets transmitted on this port since reset or manual clear RxPkts The number of packets received on this port since reset or manual clear Collisions The number of collisions on this port...

Page 64: ...under the Maintenance heading select Attached Devices to view the table shown in Figure 4 3 Figure 4 3 Attached Devices menu For each device the table shows the IP address NetBIOS Host Name if availab...

Page 65: ...and administrator logins If you enabled content filtering in the Block Sites menu the Logs page shows you when someone on your network tried to access a blocked site If you enabled e mail notification...

Page 66: ...e of event and what action was taken if any Source IP The IP address of the initiating device for this log entry Source port and interface The service port number of the initiating device and whether...

Page 67: ...nistrator logout IP 192 168 0 2 This entry shows an administrator logging in and out from IP address 192 168 0 2 Tue 2002 05 21 19 00 06 Login screen timed out IP 192 168 0 2 This entry shows a time o...

Page 68: ...rmation in the configuration menu of your e mail program If you leave this box blank log and alert messages will not be sent via e mail Send to this e mail address Enter the e mail address to which lo...

Page 69: ...t the log is cleared from the firewall s memory If the firewall cannot e mail the log file the log buffer may fill up In this case the firewall overwrites the log and discards its contents Backing Up...

Page 70: ...the Maintenance heading of the Main Menu select the Settings Backup menu as seen in Figure 4 7 Figure 4 7 Settings Backup menu 3 Click Backup to save a copy of the current settings 4 Store the cfg fi...

Page 71: ...the file to the firewall 5 The firewall will then reboot automatically Procedure 4 8 Erase the Configuration It is sometimes desirable to restore the firewall to the factory default settings This can...

Page 72: ...IP address to verify that the DNS server configuration is working Display the Routing Table to identify what other routers the router is communicating with Trace the Routing Path to identify any conn...

Page 73: ...a range of IP addresses on the Internet select IP address range Enter a beginning and ending IP address to define the allowed range c To allow access from a single IP address on the Internet select On...

Page 74: ...ile is compressed ZIP file you must first extract the binary BIN or IMG file before uploading it to the firewall Note The Web browser used to upload new firmware into the firewall must support HTTP up...

Page 75: ...mportant not to interrupt the Web browser by closing the window clicking a link or loading a new page If the browser is interrupted it may corrupt the software When the upload is complete your firewal...

Page 76: ...FR328S Cable DSL ProSafe Firewall with Dial Back Up 4 16 Managing Your Network FR328S book Page 16 Monday September 9 2002 4 01 PM...

Page 77: ...ult DMZ Server feature is helpful when using some online games and videoconferencing applications that are incompatible with NAT The firewall is programmed to recognize some of these applications and...

Page 78: ...ool since it allows your firewall to be discovered Don t check this box unless you have a specific reason to do so Configuring LAN IP Settings The LAN IP Setup menu allows configuration of LAN IP serv...

Page 79: ...router sends It recognizes both formats when receiving By default this is set for RIP 1 RIP 1 is universally supported RIP 1 is probably adequate for most networks unless you have an unusual network...

Page 80: ...r as DHCP server If another device on your network will be the DHCP server or if you will manually configure the network settings of all of your computers clear the Use router as DHCP server check box...

Page 81: ...rved IP addresses should be assigned to servers that require permanent IP settings To reserve an IP address 1 Click the Add button 2 In the IP Address box type the IP address to assign to the PC or se...

Page 82: ...IP MTU or DHCP parameters 4 Click Apply to save your changes Configuring Dynamic DNS If your network has a permanently assigned IP address you can register a domain name and have that name linked with...

Page 83: ...rs whose names appear in the Select Service Provider box and register for an account For example for dyndns org go to www dyndns org 4 Select the Use a dynamic DNS service check box 5 Select the name...

Page 84: ...gateway and a second static route was created to your local network for all 192 168 0 x addresses With this configuration if you attempt to access a device on the 134 177 0 0 network your firewall wi...

Page 85: ...all 2 From the Main Menu of the browser interface under Advanced click on Static Routes to view the Static Routes menu shown in Figure 5 2 Figure 5 2 Static Routes Table 3 To add or edit a Static Rout...

Page 86: ...ination If the destination is a single host type 255 255 255 255 g Type the Gateway IP Address which must be a router on the same LAN segment as the firewall h Type a number between 1 and 15 as the Me...

Page 87: ...wall but I can t access the Internet Go to Troubleshooting the ISP Connection on page 6 5 I can t remember the firewall s configuration password I want to clear the configuration and start over again...

Page 88: ...should contact technical support Test LED Never Turns On or Test LED Stays On When the firewall is turned on the Test LED turns on for about 10 seconds and then turns off If the Test LED does not turn...

Page 89: ...sure that power is turned on to the connected hub or PC Be sure you are using the correct cable When connecting the firewall s Internet port to a cable or DSL modem use the cable that was supplied wi...

Page 90: ...address is in this range check the connection from the PC to the firewall and reboot your PC If your firewall s IP address has been changed and you don t know the current IP address clear the firewal...

Page 91: ...ed to force your cable or DSL modem to recognize your new firewall by performing the following procedure 1 Turn off power to the cable or DSL modem 2 Turn off power to your firewall 3 Wait five minute...

Page 92: ...ng system documentation Your PC may not have the firewall configured as its TCP IP gateway If your PC obtains its information from the firewall by DHCP reboot the PC and verify the gateway address as...

Page 93: ...kstation are correct and that the addresses are on the same subnet Testing the Path from Your PC to a Remote Device After verifying that the LAN path works correctly test the path from your PC to a re...

Page 94: ...tings changing the firewall s administration password to password and the IP address to 192 168 0 1 You can erase the current configuration and restore factory defaults in two ways Use the Erase funct...

Page 95: ...the log is stamped with the date and time of day Problems with the date and time function can include Date shown is January 1 2000 Cause The firewall has not yet successfully reached a Network Time S...

Page 96: ...FR328S Cable DSL ProSafe Firewall with Dial Back Up 6 10 Troubleshooting FR328S book Page 10 Monday September 9 2002 4 01 PM...

Page 97: ...a and Routing Protocols TCP IP RIP 1 RIP 2 DHCP PPP over Ethernet PPPoE Power Adapter North America 120V 60 Hz input United Kingdom Australia 240V 50 Hz input Europe 230V 50 Hz input Japan 100V 50 60...

Page 98: ...140 F 0 to 40 C Operating humidity 90 maximum relative humidity noncondensing Electromagnetic Emissions Meets requirements of FCC Part 15 Class B VCCI Class B EN 55 022 CISPR 22 Class B Interface Spec...

Page 99: ...are listed on the World Wide Web at www ietf org and are mirrored and indexed at many other sites worldwide Basic Router Concepts Large amounts of bandwidth can be provided easily and relatively inex...

Page 100: ...ters periodically update one another and check for changes to add to the routing table The FVS318 VPN Firewall supports both the older RIP 1 and the newer RIP 2 protocols Among other improvements RIP...

Page 101: ...bit pattern which is used by the TCP IP software to identify the address class After the address class has been determined the software can correctly identify the host section of the address The foll...

Page 102: ...es is not assigned but is used as the broadcast address for simultaneously sending a packet to all hosts with the same network address Netmask In each of the address classes previously described the s...

Page 103: ...physical networks known as subnetworks Some of the node numbers are used as a subnet number instead A Class B address gives us 16 bits of node numbers translating to 64 000 nodes Most organizations d...

Page 104: ...ing table lists the additional subnet mask bits in dotted decimal notation To use the table write down the original class netmask and replace the 0 value octets with the dotted decimal value of the ad...

Page 105: ...e local and which are remote Private IP Addresses If your local network is isolated from the Internet for example when using NAT you can assign any IP addresses to the hosts without problems However t...

Page 106: ...P This type of Internet account is more costly than a single address account typically used by a single user with a modem rather than a router The FVS318 VPN Firewall employs an address sharing method...

Page 107: ...rs MAC Addresses and Address Resolution Protocol An IP address alone cannot be used to deliver data from one LAN device to another To send data between LAN devices you must convert the IP address of t...

Page 108: ...ormation about address assignment refer to the IETF documents RFC 1597 Address Allocation for Private Internets and RFC 1466 Guidelines for Management of IP Address Space For more information about IP...

Page 109: ...N connects to the Internet through a router an opportunity is created for outsiders to access or disrupt your network A NAT router provides some protection because by the very nature of the Network Ad...

Page 110: ...allowed to pass through or rejected Denial of Service Attack A hacker may be able to prevent your network from operating or communicating by launching a Denial of Service DoS attack The method used f...

Page 111: ...ectors Crossover cables are often unmarked as such and must be identified by comparing the two connectors Since the cable connectors are clear plastic it is easy to place them side by side and view th...

Page 112: ...Reference Manual for the Model FVS318 Cable DSL ProSafe VPN Firewall B 14 Networks Routing and Firewall Basics FR328S book Page 14 Monday September 9 2002 4 01 PM...

Page 113: ...need for networking with TCP IP Windows 95 or later includes the software components for establishing a TCP IP network Windows 3 1 does not include a TCP IP component You need to purchase a third part...

Page 114: ...l is shipped preconfigured as a DHCP server The firewall assigns the following TCP IP configuration information automatically when the PCs are rebooted PC or workstation IP addresses 192 168 0 2 throu...

Page 115: ...Adapter and then click Add c Select the manufacturer and model of your Ethernet adapter and then click OK If you need TCP IP a Click the Add button b Select Protocol and then click Add c Select Micro...

Page 116: ...ese steps 1 Connect all PCs to the firewall then restart the firewall and allow it to boot 2 On each attached PC open the Network control panel refer to the previous section and select the Configurati...

Page 117: ...g the default TCP IP settings that NETGEAR recommends The IP address is between 192 168 0 2 and 192 168 0 254 The subnet mask is 255 255 255 0 The default gateway is 192 168 0 1 Configuring Windows NT...

Page 118: ...Start button and then click Run The Run window opens 2 Type cmd and then click OK A command window opens 3 Type ipconfig all Your IP Configuration information will be listed and should match the valu...

Page 119: ...Using DHCP Server You can leave the DHCP Client ID box empty 4 Close the TCP IP Control Panel 5 Repeat this for each Macintosh on your network MacOS X 1 From the Apple menu choose System Preferences...

Page 120: ...n TCP IP The panel is updated to show your settings which should match the values below if you are using the default TCP IP settings that NETGEAR recommends The IP Address is between 192 168 0 2 and 1...

Page 121: ...and modem the firewall appears to be a single PC to the ISP The firewall then allows the PCs on the local network to masquerade as the single PC to access the Internet through the broadband modem The...

Page 122: ...Obtaining ISP Configuration Information for Windows Computers As mentioned above you may need to collect configuration information from your PC so that you can use this information when you configure...

Page 123: ...information when you configure the FR328S Firewall Following this procedure is only necessary when your ISP does not dynamically supply the account information To get the information you need to confi...

Page 124: ...eset the network for the devices to be able to communicate correctly Restart any computer that is connected to the firewall After configuring all of your computers for TCP IP networking and restarting...

Page 125: ...addresses on the Internet Domain names are of the form of a registered entity name plus one of a number of predefined top level suffixes such as com edu uk etc For example in the address mail NETGEAR...

Page 126: ...mation transmitted over public networks IPSec is a VPN method providing a higher level of security than PPTP ISP Internet service provider LAN See local area network local area network LAN A communica...

Page 127: ...onnection PPTP Point to Point Tunneling Protocol A method for establishing a virtual private network VPN by embedding Microsoft s network protocol into Internet packets PSTN Public Switched Telephone...

Page 128: ...ed with a 64 bit or 128 bit Shared Key for data encryption wide area network WAN A long distance link used to extend or connect remotely located local area networks The Internet is a large WAN Windows...

Page 129: ...ver 5 1 default reset button 6 8 Denial of Service DoS protection 1 1 3 3 denial of service attack B 12 DHCP 1 3 5 4 B 11 DHCP Client ID C 7 DHCP Setup field Ethernet Setup menu 4 2 DMZ Server 5 1 DNS...

Page 130: ...n Information C 11 masquerading C 9 metric 5 10 Modem 2 16 2 17 modem 1 3 1 6 2 14 MTU 5 3 multicasting 5 3 N NAT C 9 NAT See Network Address Translation NETGEAR contacting 1 xiv netmask translation t...

Page 131: ...3 10 service numbers 3 13 Setup Wizard 2 1 SMTP 4 8 spoof MAC address 6 6 stateful packet inspection 1 1 B 12 Static Routes 5 6 subnet addressing B 5 subnet mask B 6 C 10 C 11 Syslog 4 7 T TCP IP con...

Reviews: