background image

 

INSTALLATION GUIDE 

7. INITIAL CONNECTION TO THE PRODUCT 

 
 

7.2  Configuration 

 
When  you  first  receive  your  firewall,  it  will  run  in  transparent  mode  and  will  have  the  IP  address 
10.0.0.254 with a subnetwork mask 255.0.0.0. 
These  parameters  do  not  match  your  network  configuration,  but  they  are  however  necessary  for 
the preconfiguration phase.  
If you do not know what these parameters mean, we strongly advise that you read up on TCP/IP in 
order to understand how to configure your NETASQ firewall.  
These are the intervals defined by the different classes of IP address:  

Class 

IP address range 

0.0.0.0 to 127.255.255.255 

128.0.0.0 to 191.255.255.255 

192.0.0.0 to 223.255.255.255 

224.0.0.0 to 239.255.255.255 

240.0.0.0 to 247.255.255.255 

 
 
Some parts of these address ranges are reserved for private networks:  

Class 

Reserved IP address ranges  

10.0.0.0 to 10.255.255.255 

172.16.0.0 to 172.31.255.255 

192.168.0.0 to 192.168.255.255 

 
Preconfiguring from a Windows workstation is the method that we recommend, which is what we 
will  be  using  for  our  illustrations.  The  workstation  can  either  be  di

rectly  linked  to  the  firewall’s 

internal interface, or connected to the local network, itself linked to the firewall’s internal interface. 
For a direct connection of the workstation to the firewall, use the crossover Ethernet cable, which 
has been delivered with the product. 
 

 

WARNING

 

Please refer to sectio

5.4: Connecting to the network

 for more information.  

 

To  connect  to  the  firewall,  you  need  to  use  a  workstation  with  an  IP  address  in  the  same 
subnetwork  as  the  firewall.    We  suggest  that  you  use  the  address  10.0.0.1  and  the  subnetwork 
address 255.0.0.0. 
 

 

Содержание NG1000-A

Страница 1: ...RODUCTS Reference naengde_product installation Date Version Author Details April 2010 V1 0 NETASQ Creation September 2010 V1 1 NETASQ Update November 2010 V1 2 NETASQ Update September 2011 V1 3 NETASQ...

Страница 2: ...l NETASQ be held liable for any loss of data or revenue or any special damage or incident resulting from or indirectly caused by the use of the product and its associated documentation The contents of...

Страница 3: ...straight cable 35 5 4 12 Using a crossover cable cable provided with the product 35 5 4 13 Antispoofing mechanism 36 6 PHYSICAL INSTALLATION OF THE APPLIANCE 42 6 1 Preparation before installation 42...

Страница 4: ...n database The NETASQ Firewall also manages port and address translation mechanisms These mechanisms provide security by masking your internal address range and flexibility by enabling the use of any...

Страница 5: ...WARNING NETASQ firewalls should not be installed in locations where the temperature may exceed 35 C The table below indicates the operating temperature storage temperature and humidity level for each...

Страница 6: ...A In residential environments these products may cause radioelectric disturbances in which case the user may be obliged to take the appropriate measures WARNING Ensure that you unplug ALL power cables...

Страница 7: ...ation matches your order IMPORTANT It is best that you have your serial number and web password given on the label on the underside of the product at hand before connecting or installing the firewall...

Страница 8: ...TY SEAL is affixed Check that there is such a seal on your product s packaging Below is the type of label or quality seal that you should expect to find Figure 4 Quality seal label Figure 5 Warranty b...

Страница 9: ...lements does not comply with its description 3 2 Contents of the packaging Keep the cardboard packaging safely in case you need it later for transporting the firewall It has been designed to give your...

Страница 10: ...e feet can be delivered already installed on the appliance for non rackable products U30 and U70 U6000 NG1000 A and NG5000 A appliances are delivered with racking rails sliding rails in addition to fr...

Страница 11: ...ls upon startup the LEDs light up in the following order Power Status Online The Power LED will light up first then Status then Online The Online LED which indicates that the product is running will l...

Страница 12: ...green LED goes off NOTE There is no internal fan on this appliance Point 2 the Power LED yellow indicates that the product has been plugged in If this is the only LED that lights up this means that t...

Страница 13: ...t of 600 Mbits s 100 000 concurrent connections 6 Gigabit interfaces 6 000 new sessions per second 1 Software shutdown button 2 LEDs from bottom to top Power Status Online 3 Serial port for connecting...

Страница 14: ...y the Online LED will light up intermittently for every second it lights up it will go off for 2 seconds This means that the appliance is in passive mode Points 3 4 and 5 these different ports enable...

Страница 15: ...ing down or being updated only the Status and Power LEDs will light up WARNING You are strongly advised against unplugging the product when the Status LED is starting shutting down or being updated Th...

Страница 16: ...nt 1 to shut down the software hold down the software shutdown button for 4 seconds until the Online green LED goes off NOTE The fan is directly linked to the power supply Point 2 the Power LED yellow...

Страница 17: ...mbits s 2 LEDs that light up indicate a throughput of 100 mbits s and if the right LED lights up this indicates a throughput of 1000 mbits s One or two blinking LEDs on an IN interface indicate the pr...

Страница 18: ...ng down or being updated The Status LED will blink quick blinking every 250 milliseconds in the event of a major failure of the product hardware modification faulty network interface etc In this case...

Страница 19: ...ible Point 2 When the appliance is starting shutting down or being updated the Status LED will light up WARNING You are strongly advised against switching off the product when the Status LED is starti...

Страница 20: ...appliance on and off 9 4 additional RJ45 Ethernet ports for connecting network cables Point 8 The Power button serves to switch the appliance on and off To shut down the firewall hold down the button...

Страница 21: ...ine LED will light up intermittently for every second it lights up it will go off for 2 seconds This means that the appliance is in passive mode 4 8 1 Rear panel 1 Fan grating 2 Power socket for plugg...

Страница 22: ...t up intermittently for every second it lights up it will go off for 2 seconds This means that the appliance is in passive mode Point 2 The button for switching the appliance on and off is called the...

Страница 23: ...re advised to connect each power unit to a different mains power 2 Fan grating 3 Not in use 4 PS2 mini din port for plugging in a keyboard purple 5 2 USB ports for secure configurations and updates 6...

Страница 24: ...layouts Layout n 1 Layout n 2 1 Brackets on both ends of the firewall handles 2 LEDs in the hard disk racks indicate disk access blue lower LED and disk installation yellow upper LED 3 1 hard disk as...

Страница 25: ...a redundant power supply You are advised to connect each power unit to a different mains power and to use a power supply backed up by an inverter 2 Not in use 3 PS2 mini din port for plugging in a ke...

Страница 26: ...ayouts Layout n 1 Layout n 2 1 Brackets on both ends of the firewall handles 2 LEDs in the hard disk racks indicate disk access blue lower LED and disk installation yellow upper LED 3 2 hard disks as...

Страница 27: ...nteed 4 11 2 Rear panel 1 2 power sockets for plugging in 2 mains power cables The NG5000 A firewall is equipped with a redundant power supply You are advised to connect each power unit to a different...

Страница 28: ...is to say in a protected office or other premises with limited access In order to guarantee the integrity of the product and to avoid compromising the security of your installation all unauthorized a...

Страница 29: ...cable The numbers of the interfaces apply to the U30 U70 U120 U250 and U450 models The interface identified as 1 on the firewall corresponds to the EXTERNAL interface called OUT by default The interf...

Страница 30: ...ON GUIDE 5 CONNECTIONS 5 4 3 U120 Figure 9 U120 interfaces 5 4 4 U250 Figure 10 U250 interfaces 5 4 5 U450 Figure 11 U450 interfaces 5 4 6 U1100 Figure 12 U1100 interfaces 5 4 7 U1500 Figure 13 U1500...

Страница 31: ...INSTALLATION GUIDE 5 CONNECTIONS 5 4 8 U6000 Figure 14 U6000 interfaces 5 4 9 NG1000 A Figure 15 NG1000 A interfaces on the front panel Figure 16 NG1000 A administration interfaces at the back...

Страница 32: ...tween a firewall and a hub a switch or certain modems depending on the type of modem a straight or a crossover cable will be necessary 5 4 12 Using a crossover cable cable provided with the product A...

Страница 33: ...2 consecutive beeps indicate the end of the product s startup sequence 5 4 13 Antispoofing mechanism WARNING If you connect to an interface then unplug the cable to connect to another interface you wi...

Страница 34: ...ts s Category 5 twisted pair or higher RJ45 10 100 1000BaseT Ethernet port To run at 100Mbits s or 1000Mbits s Category 5 twisted pair or higher RJ45 1000FX Gigabit Ethernet port fiber cable Optic fib...

Страница 35: ...ration of internet access Before installing the NETASQ firewall ensure that the devices that connect to the internet if the firewall has to be connected with the internet network have been appropriate...

Страница 36: ...30 by special order Installation of the deck in the bay Screw the supporting deck to the lateral sides of the rack using the caged nuts Once the deck has been installed you will be able to place on or...

Страница 37: ...nel of the appliance and lateral supporting rails Setup of the supporting rails Screw the brackets to the appliance The lugs have to be placed at the front panel of the product Setup of the supporting...

Страница 38: ...ssible reserve several gigabites of space for the database depending on the activity of the connected firewall s Ethernet 100 or 1000 Mbps network card NETASQ supports the execution of the software in...

Страница 39: ...47 255 255 255 Some parts of these address ranges are reserved for private networks Class Reserved IP address ranges A 10 0 0 0 to 10 255 255 255 B 172 16 0 0 to 172 31 255 255 C 192 168 0 0 to 192 16...

Страница 40: ...Network and Internet connections Right click against Connect to the local network and select Properties Select Internet Protocol TCP IP from the list then Properties Select the option Obtain an IP add...

Страница 41: ...to update your product with the license that will allow you to use this card WARNING The NETASQ appliance has to be rebooted when a new license is activated on it Please refer to the procedure below...

Страница 42: ...ption that will activate the new network ports that you will be able to activate subsequently Next go to the General tab and look for the section License download First select the major version of you...

Страница 43: ...es When you click on the Licenses sub menu details of the installed license will appear if you have never installed a license on the product then this will be the product s temporary license Click on...

Страница 44: ...ting to the firewall Caution this operation will also reset the password For other products For other products resetting a NETASQ Firewall has to be done in console mode Several methods are possible t...

Страница 45: ...face PCI X Peripheral Component Interconnect eXtended This is an add on interconnection bus that is secondary to a PCI E Authorization It is mandatory to ask the technical support in order to be grant...

Страница 46: ...efault and 3 slots that allow for the insertion of additional network cards The initial order of the ports is as follows PCI E QUAD PCI E PCI E PCI X PCI X R A I D em2 dmz 1 em3 dmz 2 em4 dmz 3 em0 ou...

Страница 47: ...ly present on the firewall Enter the command reboot The firewall will restart When the firewall is rebooting go to the BIOS configuration by pressing Del or F2 Del is more widely used In the menu PnP...

Страница 48: ...t on the rear panel Slot 4 This is the PCI E port slot directly to the right of the 4 gigabit port QUAD card inserted by default The diagram below illustrates how a 6 port network card should be inser...

Страница 49: ...and on those that have just been installed The interface numbers for this card are added after the other interfaces that are already present The diagram below illustrates how a 6 port network card sho...

Страница 50: ...en a PCI X card is added As such the cables connected to these interfaces have to be rearranged accordingly The diagram below illustrates how a 6 port PCI X network card should be inserted PCI E QUAD...

Страница 51: ...t have been installed and their port numbers the scenarios below indicate the procedures to follow for plugging the cables into the appropriate interfaces There are as many scenarios as there are comb...

Страница 52: ...ation PCI E QUAD PCI E PCI E PCI X PCI X Initial configuration R A I D em2 dmz 1 em3 dmz 2 em4 dmz 3 em0 out em1 in em5 dmz 4 1 2 3 PCI E QUAD PCI E PCI E PCI X PCI X Initial configuration em2 dmz 1 R...

Страница 53: ...to a default configuration PCI E QUAD PCI E PCI E PCI X PCI X Initial configuration R A I D em2 dmz 1 em3 dmz 2 em4 dmz 3 em0 out em1 in em5 dmz 4 1 2 3 PCI E QUAD PCI E PCI E PCI X PCI X Initial con...

Страница 54: ...dmz 13 em3 dmz 2 em9 dmz 8 em15 dmz 14 em4 dmz 3 em10 dmz 9 em16 dmz 15 em0 out em1 in em5 dmz 4 em11 dmz 10 em17 dmz 16 1 2 3 4 5 PCI E QUAD PCI E PCI E PCI X PCI X Initial configuration em12 dmz 11...

Страница 55: ...ewall is 22 ports Description of the cards NG1000 A and NG5000 A appliances support the addition of one of the following extension modules 4 copper 1GbE ports P N NA NG 4GIG C E RJ45 IEEE 1000 100 10B...

Страница 56: ...ty per EN IEC 60825 laser safety standards 4 fiber 1GbE ports P N NA NG 4GIG F L E SFP Duplex LC IEEE 802 3z 1000BASE LX Optical wavelength 1310nm Max fiber length 10km on 9 125 m single mode fiber Cl...

Страница 57: ...e Step 3 Rebooting the firewall and connecting in console mode Step 4 Activating the RAID 1 Step 5 Inserting the hard disk and rebooting the firewall Step 6Building the RAID 1 Update the license with...

Страница 58: ...then enter the command reboot to reboot the NETASQ firewall Once the NG1000 A firewall has rebooted the RAID needs to be built meaning the data from the standard hard disk has to be duplicated to the...

Страница 59: ...us of the RAID can be monitored via the NETASQ REAL TIME MONITOR in the Hardware menu Step 1 Connect to the firewall in console mode keyboard monitor Step 2 Enter the command nraid r w During the reco...

Страница 60: ...nd 850 1900 2100 MHz Access Standards HSUPA 3GPP R6 up to 5 76Mbps max UL Category 4 HSDPA 3GPP R5 up to 7 2 Mbps max DL Category 8 WCDMA UMTS Up to 384 Kbps DL and UL EDGE EGPRS 3GPP Release4 class 1...

Страница 61: ...to the module NETWORK INTERFACES and in the menu Add Add a modem Refer to the documentation section INTERFACES Creating a modem in order to configure your modem WARNING The lowest firmware version ne...

Страница 62: ...m the CD ROM you will be able to Configure the network to define the network architecture in which your product will be located For more information on the subject of network connections please refer...

Страница 63: ...INSTALLATION GUIDE APPENDIX G INSTALLING VIA THE CD ROM documentation netasq com...

Отзывы: