background image

McAfee UTM Firewall

Quick Installation Guide

Rack Mount Model SG720

uf_SG720_qig_700-2240A00_en-us.fm  Page 1  Monday, October 12, 2009  11:56 AM

Summary of Contents for SG720

Page 1: ...McAfee UTM Firewall Quick Installation Guide Rack Mount Model SG720 uf_SG720_qig_700 2240A00_en us fm Page 1 Monday October 12 2009 11 56 AM ...

Page 2: ...ENSE GRANT OR PURCHASE ORDER DOCUMENTS THAT ACCOMPANY YOUR SOFTWARE PACKAGING OR THAT YOU HAVE RECEIVED SEPARATELY AS PART OF THE PURCHASE AS A BOOKLET A FILE ON THE PRODUCT CD OR A FILE AVAILABLE ON THE WEBSITE FROM WHICH YOU DOWNLOADED THE SOFTWARE PACKAGE IF YOU DO NOT AGREE TO ALL OF THE TERMS SET FORTH IN THE AGREEMENT DO NOT INSTALL THE SOFTWARE IF APPLICABLE YOU MAY RETURN THE PRODUCT TO MC...

Page 3: ...ght corner Support Visit mysupport mcafee com to find product documentation announcements and support Firmware updates Your device has been pre programmed with firmware current at the time of manufacture Should you want to upgrade the firmware you can obtain the latest version for your device from my securecomputing com Product specifications Power 100 240 V 50 60 Hz 0 52 0 21 A Operating temperat...

Page 4: ... up a single computer connection page 6 3 Set your password page 8 4 Set LAN connection settings page 10 5 Select a security level page 16 6 Connect to your LAN page 18 7 Set up computers on your LAN page 19 8 Set up the Internet connection page 23 9 Register your UTM Firewall device page 24 Before you begin this setup process make sure you have a computer running Microsoft Windows 2000 or later w...

Page 5: ...lashes when the UTM Firewall device is running Each of the network ports has two LEDs indicating link status and activity The four status LEDs flash when the device is in the factory default state NOTE If these LEDs do not behave in this manner before your UTM Firewall device is attached to the network perform a factory reset 1 Press the erase button on rear panel twice within three seconds 1 seco...

Page 6: ... ports are by default inactive that is they are not running any network services such as DHCP and they are not configured with an IP address 1 Connect the power cable to the power inlet on the rear panel of the UTM Firewall device 2 Turn on the rear panel power switch The power light turns on 3 Connect port A directly to your computer network interface card NIC using the supplied network cable 4 M...

Page 7: ...92 168 0 1 7 Select Use the following DNS server addresses 8 In the Preferred DNS Server field enter 192 168 0 1 9 Optional If you want to retain your existing IP settings for this network connection click Advanced and add the secondary IP address of 192 168 0 100 subnet mask 255 255 255 0 uf_SG720_qig_700 2240A00_en us fm Page 7 Monday October 12 2009 11 56 AM ...

Page 8: ...a Press the erase button on the UTM Firewall device s rear panel twice within 3 seconds 1 second apart This resets the UTM Firewall device to its factory default settings b Wait 20 30 seconds and then try browsing to 192 168 0 1 again 2 A logon prompt appears Enter the initial user name and password User name root Password default 3 Click OK The Set Administrative Password window appears Figure 3 ...

Page 9: ...ng the next step NOTE This is the password for the main administrative user root account on the UTM Firewall device It is important you choose a password hard that is hard to guess and keep it safe 5 Click Submit The Quick Setup Wizard Hostname window appears Figure 4 Figure 4 Hostname window uf_SG720_qig_700 2240A00_en us fm Page 9 Monday October 12 2009 11 56 AM ...

Page 10: ...odel number If you want to use a different host name type the new name in the Hostname field The name must begin with an alpha character 2 Click Next The LAN window appears Figure 5 Figure 5 LAN window uf_SG720_qig_700 2240A00_en us fm Page 10 Monday October 12 2009 11 56 AM ...

Page 11: ...address obtained from a server on the LAN DHCP NOTE Changes to the UTM Firewall device LAN configuration do not take effect until you complete the Quick Setup Wizard 4 Click Next Continue based on the option you selected in Step 3 Use a Fixed IP Go to step Step 5 on page 11 Skip Go to step Step 6 on page 13 Use an IP address obtained from a server on the LAN DHCP Go to step Step 6 on page 13 5 Con...

Page 12: ...cally obtain network settings are assigned an address from this range and use the UTM Firewall device as their gateway to the Internet and as their DNS server for Internet domain name resolution If you plan to use a DHCP server already on your LAN leave the field blank to leave the UTM Firewall device s DHCP server disabled c Click Next The ISP connection window appears Figure 7 uf_SG720_qig_700 2...

Page 13: ...og modem ADSL Connect using an ADSL modem Selecting ADSL will attempt automatic detection of your ADSL connection type Direct Connection Connect directly to the Internet for example over a leased line Skip Select this option to defer configuration or if your connection is already configured uf_SG720_qig_700 2240A00_en us fm Page 13 Monday October 12 2009 11 56 AM ...

Page 14: ... to Select a security level on page 16 Direct Connection Go to Step 7 on page 14 7 Conditional If you selected Direct Connection in Step 6 on page 13 select an option for ISP connection Figure 7 Figure 8 ISP connection WAN window Use an IP address obtained from a server on the Internet DHCP Select this option if you plan to use a DHCP server already in use on your LAN Recommended Use a fixed IP Se...

Page 15: ...IP in Step 7 on page 14 manually configure your WAN settings Figure 9 Figure 9 Internet WAN interface window a In the IP Address field enter the static IP address you want to apply to the WAN port of the appliance b Enter the Subnet Mask which defaults to 24 bits c Optional Set the default Gateway address d Optional Set the IP address of the DNS server e Click Next uf_SG720_qig_700 2240A00_en us f...

Page 16: ...trict access between different parts of your network Use the Firewall security level window to select a security level that will activate one or more packet filtering rules Figure 10 Figure 10 Firewall security level window uf_SG720_qig_700 2240A00_en us fm Page 16 Monday October 12 2009 11 56 AM ...

Page 17: ...affic to move through the firewall Denies other common traffic types Medium Common Internet access Allows VPN Dialin LAN HTTP HTTPS and most common types of traffic to move through the firewall Denies peer to peer P2P traffic unless that traffic is tunneled through another protocol such as P2P over HTTP Low All Internet access Allows all Internet traffic to pass through the firewall 2 Click Next T...

Page 18: ...s click Finish to activate the new configuration NOTE Depending on how you configured your LAN settings you may have to navigate to the UTM Firewall s new LAN IP address to access the Management Console 3 Connect computers and your LAN hub to port A on the UTM Firewall device uf_SG720_qig_700 2240A00_en us fm Page 18 Monday October 12 2009 11 56 AM ...

Page 19: ...on your LAN proceed to Use an existing DHCP server on page 21 If you do not want to use a DHCP server proceed to Manually configure LAN properties on page 22 Use the UTM Firewall DHCP server When you select Use a Fixed IP for the UTM Firewall LAN connection and supply the DHCP Server Address Range the UTM Firewall DHCP server is set up and running Each computer on your LAN must now be set up to au...

Page 20: ...lect the following options Obtain an IP address automatically Obtain DNS server address automatically 5 Click OK 6 Repeat steps 1 5 for each computer in your network uf_SG720_qig_700 2240A00_en us fm Page 20 Monday October 12 2009 11 56 AM ...

Page 21: ...dress for the existing DHCP server to hand out a Enter the UTM Firewall device LAN IP address as the DNS server IP address for the DHCP server to hand out 3 Make sure all computers on the network are set up to automatically obtain network configuration see Use the UTM Firewall DHCP server on page 19 then restart them Restarting the computers forces an update of their automatically configured netwo...

Page 22: ...nnection for example if you are using the default settings 192 168 0 2 192 168 0 254 Subnet mask Subnet mask of the UTM Firewall device LAN connection if using the default settings 255 255 255 0 Default gateway IP address of the UTM Firewall device LAN connection if you are using the default settings 192 168 0 1 Preferred DNS server IP address of the UTM Firewall device LAN connection if you are u...

Page 23: ...e UTM Firewall device for your primary Internet connection 2 For example attach Port D to your modem device or Internet connection medium 3 From the Network Setup menu select Network Setup The Connections window appears Figure 13 Figure 13 Connections window 4 In the row labeled Port D go to the Change Type column and use the drop down list to select your Internet connection type 5 Refer to the He...

Page 24: ...ivating add on features are provided in the McAfee UTM Firewall Administration Guide This completes the setup of your UTM Firewall Advanced configurations Use the menu in the UTM Firewall Web Management Console to configure more sophisticated security settings and networking features such as VPN Refer to the McAfee UTM Firewall Administration Guide the Help and the KnowledgeBase for further config...

Page 25: ...ted at 3965 Freedom Circle Santa Clara California 95054 USA if the Software is purchased in the United States Mexico Central America South America or the Caribbean b McAfee Ireland Limited with offices located at 11 Eastgate Business Park Little Island Cork Ireland if the Software is purchased in Canada Europe the Middle East Africa Asia or the Pacific Rim and c McAfee Co Ltd with offices located ...

Page 26: ...f you receive the Software bundled with other software the total number of your Computers on which all versions of the Software is installed may not exceed the Permitted Number If the Software is an Update to a previous version of the Software you must possess a valid license to such previous version in order to Use the Update You may continue to Use the previous version of the Software on your Co...

Page 27: ...s your information technology resources Managing Party you may transfer all your rights to Use the Software to such Managing Party provided that a the Managing Party only Uses the Software for your internal operations and not for the benefit of another third party b the Managing Party agrees to comply with the terms and conditions of this Agreement and c you provide McAfee with written notice that...

Page 28: ... DAMAGES FOR LOSS OF GOODWILL WORK STOPPAGE COMPUTER FAILURE OR MALFUNCTION OR FOR ANY OTHER DAMAGE OR LOSS IN NO EVENT SHALL MCAFEE OR ITS AUTHORIZED PARTNERS OR SUPPLIERS BE LIABLE FOR ANY DAMAGE IN EXCESS OF THE PRICE PAID FOR THE SOFTWARE IF ANY EVEN IF MCAFEE OR ITS AUTHORIZED PARTNERS OR SUPPLIERS SHALL HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES This limitation shall not apply to l...

Page 29: ...lic of Ireland shall apply unless another local law is required to be applied This Agreement will not be governed by the conflict of laws rules of any jurisdiction or the United Nations Convention on Contracts for the International Sale of Goods the application of which is expressly excluded The United States District Court for the Southern District of New York and the Courts of New York County Ne...

Page 30: ...n notice and shall occur no more than once per year unless otherwise required for compliance with the Sarbanes Oxley Act 18 Auto Boot Post Boot Mode McAfee shall have no liability to you for any damages resulting from the use of the Software in the auto boot or post boot mode You are advised that such tools are designed for product deployment purposes only and any other use does not provide adequa...

Page 31: ...31 uf_SG720_qig_700 2240A00_en us fm Page 31 Monday October 12 2009 11 56 AM ...

Page 32: ...700 2240A00 uf_SG720_qig_700 2240A00_en us fm Page 32 Monday October 12 2009 11 56 AM ...

Reviews: