Waters Network Systems ProSwitch-Quad Series Specifikace

Procházejte online nebo si stáhněte Specifikace pro Síťové přepínače Waters Network Systems ProSwitch-Quad Series. Waters Network Systems ProSwitch-Quad Series Specifications Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 469
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 0
350 East Plumeria Drive
San Jose, CA 95134
USA
April 2013
202-10536-05
ProSAFE Gigabit Quad WAN SSL
VPN Firewall SRX5308
Reference Manual
Zobrazit stránku 0
1 2 3 4 5 6 ... 468 469

Shrnutí obsahu

Strany 1 - VPN Firewall SRX5308

350 East Plumeria DriveSan Jose, CA 95134USAApril 2013202-10536-05ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Reference Manual

Strany 2 - Revision History

10ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN to DMZ Logs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44

Strany 3

LAN Configuration100ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 56. 2. Modify the settings as described in Table 17 on page 98.3. Clic

Strany 4 - Contents

LAN Configuration101 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 57. 3. Select the radio button next to the group name that you want to c

Strany 5 - Chapter 3 LAN Configuration

LAN Configuration102ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: The saved binding is also displayed on the IP/MAC Binding screen (see Figu

Strany 6

LAN Configuration103 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCPv6 Server OptionsThe IPv6 clients in the LAN can autoconfigure their own IPv

Strany 7

LAN Configuration104ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Stateful DHCPv6 ServerThe IPv6 clients in the LAN obtain an interface IP address

Strany 8 - Chapter 10 Troubleshooting

LAN Configuration105 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Enter the settings as described in the following table. The IPv6 address pool

Strany 9

LAN Configuration106ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your changes.IPv6 LAN Address PoolsIf you configure a sta

Strany 10

LAN Configuration107 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 59. 2. Enter the settings as described in the following table:3. Click A

Strany 11 - Introduction

LAN Configuration108ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Delegation table to enable the DHCPv6 server to assign these prefixes to its IPv

Strany 12 - Key Features and Capabilities

LAN Configuration109 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the IPv6 Router Advertisement Daemon and Advertisement Prefixes for th

Strany 13 - Balancing

1111. IntroductionThis chapter provides an overview of the features and capabilities of the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 and ex

Strany 14

LAN Configuration110ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To configure the Router Advertisement Daemon for the LAN:1. Select Network Con

Strany 15 - Extensive Protocol Support

LAN Configuration111 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Advertisement Prefixes for the LANYou need t

Strany 16

LAN Configuration112ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 62. 2. Enter the settings as described in the following table:3. Click A

Strany 17 - Hardware Features

LAN Configuration113 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. To delete one or more advertisement prefi

Strany 18 - Table 1. LED descriptions

LAN Configuration114ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. In the Add Secondary LAN IP Address section of the screen, enter the followin

Strany 19 - Rear Panel

LAN Configuration115 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308By default, the DMZ port and both inbound and outbound DMZ traffic are disabled.

Strany 20 - Figure 3

LAN Configuration116ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 64. 2. Enter the settings as described in the following table: Table 23.

Strany 21 - Log In to the VPN Firewall

LAN Configuration117 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCP for DMZ Connected ComputersDisable DHCP Server If another device on your ne

Strany 22 - Figure 5

LAN Configuration118ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.DMZ Port for IPv6 TrafficThe DMZ Setup (IPv

Strany 23

LAN Configuration119 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308For the DMZ, there are two DHCPv6 server options:• Stateless DHCPv6 server. The

Strany 24 - Figure 8

Introduction12ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 What Is the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308?The ProSAFE Gigabit Quad

Strany 25 - Figure 9

LAN Configuration120ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Enter the settings as described in the following table: Table 24. DMZ Setup

Strany 26 - Settings

LAN Configuration121 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.IPv6 DMZ Address PoolsIf you configure a st

Strany 27 -  Complete these tasks:

LAN Configuration122ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Enter the settings as described in the following table:3. Click Apply to save

Strany 28

LAN Configuration123 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Hosts and routers in the LAN use NDP to determine the link-layer addresses and r

Strany 29

LAN Configuration124ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 67. 4. Enter the settings as described in the following table:Table 27.

Strany 30 - Classical Routing

LAN Configuration125 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Advertisement Prefixes for the DMZYou need t

Strany 31 - Figure 11

LAN Configuration126ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 68. 2. Enter the settings as described in the following table:3. Click A

Strany 32 - Figure 12

LAN Configuration127 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. To delete one or more advertisement prefi

Strany 33

LAN Configuration128ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Click the Add table button under the Static Routes table. The Add Static Rout

Strany 34 - Figure 14

LAN Configuration129 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308displays. This screen is identical to the Add Static Route screen (see the previ

Strany 35 - Figure 15

Introduction13 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The VPN firewall provides the following key features and capabilities:• Four 10/100/10

Strany 36 - Figure 16

LAN Configuration130ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Enter the settings as described in the following table: Table 30. RIP Config

Strany 37 - Figure 17

LAN Configuration131 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.IPv4 Static Route ExampleIn this example, w

Strany 38 - Figure 18

LAN Configuration132ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage Static IPv6 RoutingNETGEAR’s implementation of IPv6 does not support RIP

Strany 39 - Figure 19

LAN Configuration133 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Enter the settings as described in the following table: 5. Click Apply to sav

Strany 40 - Interfaces

13444. Firewall ProtectionThis chapter describes how to use the firewall features of the VPN firewall to protect your network. The chapter contains

Strany 41 - IPv4 Interfaces

Firewall Protection135 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308About Firewall ProtectionA firewall protects one network (the trusted network,

Strany 42 - Figure 21

Firewall Protection136ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Overview of Rules to Block or Allow Specific Kinds of Traffic• Outbound Rules

Strany 43 - Figure 22

Firewall Protection137 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Bandwidth profiles. After you have a configured a bandwidth profile (see Cre

Strany 44 -  To edit a protocol binding:

Firewall Protection138ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Select Schedule The time schedule (that is, Schedule1, Schedule2, or Schedule

Strany 45

Firewall Protection139 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308QoS Profile or QoS PriorityThe priority assigned to IP packets of this service

Strany 46 - Figure 24

Introduction14ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Advanced VPN Support for Both IPSec and SSLThe VPN firewall supports IPSec and SSL vir

Strany 47

Firewall Protection140ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Inbound Rules (Port Forwarding)If you have enabled Network Address Translation

Strany 48

Firewall Protection141 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: When the Block TCP Flood and Block UDP Flood check boxes are selected on

Strany 49 - Configure Dynamic DNS

Firewall Protection142ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Send to LAN Server The LAN server address determines which computer on your ne

Strany 50 -  To configure DDNS:

Firewall Protection143 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WAN Users The settings that determine which Internet locations are covered by

Strany 51 - Figure 27

Firewall Protection144ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Some residential broadband ISP accounts do not allow you to run any serv

Strany 52

Firewall Protection145 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308For any traffic attempting to pass through the firewall, the packet informatio

Strany 53

Firewall Protection146ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To change an existing outbound or inbound service rule, in the Action column t

Strany 54 - Figure 28

Firewall Protection147 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To enable, disable, or delete one or more IPv4 or IPv6 rules:1. Select the c

Strany 55 - Connection

Firewall Protection148ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 77. 2. Enter the settings as described in Table 33 on page 137. In a

Strany 56 - Figure 30

Firewall Protection149 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 78. 3. Enter the settings as described in Table 33 on page 137. In a

Strany 57 - Figure 31

Introduction15 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Security FeaturesThe VPN firewall is equipped with several features designed to mainta

Strany 58 - Figure 32

Firewall Protection150ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IPv4 LAN WAN Inbound Service Rules To create an IPv4 LAN WAN inbound rule:1.

Strany 59 - Figure 33

Firewall Protection151 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following configurations are optional:• Translate to Port Number• QoS Prof

Strany 60 - Figure 34

Firewall Protection152ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure DMZ WAN Rules• Create DMZ WAN Outbound Service Rules• Create LAN WAN

Strany 61 - Figure 35

Firewall Protection153 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To change an existing outbound or inbound service rule, in the Action column t

Strany 62 - Figure 36

Firewall Protection154ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To enable, disable, or delete one or more IPv4 or IPv6 rules:1. Select the c

Strany 63

Firewall Protection155 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in Table 33 on page 137. In addition to s

Strany 64

Firewall Protection156ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Unless your selection from the Action drop-down list is BLOCK always, you also

Strany 65 - Figure 37

Firewall Protection157 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in Table 34 on page 141. In addition to s

Strany 66 - Figure 39

Firewall Protection158ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Unless your selection from the Action drop-down list is BLOCK always, you also

Strany 67 - Figure 40

Firewall Protection159 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To change an existing outbound or inbound service rule, in the Action column t

Strany 68 - Figure 41

Introduction16ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • DNS proxy. When DHCP is enabled and no DNS addresses are specified, the VPN firewall

Strany 69 - Figure 42

Firewall Protection160ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Click one of the following table buttons:• Enable. Enables the rule or rule

Strany 70 - Figure 43

Firewall Protection161 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Unless your selection from the Action drop-down list is BLOCK always, you also

Strany 71 - Figure 44

Firewall Protection162ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create LAN DMZ Inbound Service RulesThe Inbound Services table lists all exist

Strany 72 - Figure 45

Firewall Protection163 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6 LAN DMZ Inbound Service Rules To create an IPv6 LAN DMZ inbound rule:1.

Strany 73 - Figure 46

Firewall Protection164ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Examples of Firewall Rules• Examples of Inbound Firewall Rules• Examples of Ou

Strany 74

Firewall Protection165 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 94. IPv4 LAN WAN or IPv4 DMZ WAN Inbound Rule: Set Up One-to-One NAT Ma

Strany 75

Firewall Protection166ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: If you arrange with your ISP to have more than one public IP address for

Strany 76 - Configure WAN QoS Profiles

Firewall Protection167 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308this address on the WAN2 Secondary Addresses screen (see Configure Secondary W

Strany 77 - Figure 47

Firewall Protection168ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:For security, NETGEAR strongly recommends that you avoid creating an e

Strany 78 - Figure 48

Firewall Protection169 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 98. IPv6 DMZ WAN Outbound Rule: Allow a Group of DMZ User to Access an

Strany 79

Introduction17 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Maintenance and SupportNETGEAR offers the following features to help you maximize your

Strany 80 - Figure 49

Firewall Protection170ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure Other Firewall Features• Attack Checks• Set Limits for IPv4 Sessions

Strany 81

Firewall Protection171 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:Table 35. Attack Ch

Strany 82 - What to Do Next

Firewall Protection172ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.IPv6 Attack Checks To enable IPv6 attack

Strany 83

Firewall Protection173 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Set Limits for IPv4 SessionsThe session limits feature allows you to specify t

Strany 84

Firewall Protection174ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings.Configure Multicast Pass-Through for IPv4

Strany 85 - Port-Based VLANs

Firewall Protection175 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 103. 2. In the Multicast Pass through section of the screen, select th

Strany 86 - Figure 50

Firewall Protection176ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To delete one or more multicast source addresses:1. In the Alternate Network

Strany 87 - VLAN DHCP Options

Firewall Protection177 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• QoS profiles and priorities. A Quality of Service (QoS) profile defines the

Strany 88 - Configure a VLAN Profile

Firewall Protection178ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 105. 2. In the Add Customer Service section of the screen, enter the s

Strany 89 - Figure 52

Firewall Protection179 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 106. 2. Modify the settings that you wish to change (see the previous

Strany 90

Introduction18ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The front panel also contains three groups of status indicator light-emitting diodes (

Strany 91

Firewall Protection180ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the Add New Custom IP Group section of the screen, do the following:• In

Strany 92

Firewall Protection181 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete an IP group:1. In the Custom IP Groups table, select the check box

Strany 93

Firewall Protection182ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 109. 2. Under the List of Bandwidth Profiles table, click the Add tabl

Strany 94

Firewall Protection183 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The new bandwidth profile is added to th

Strany 95 - Figure 54

Firewall Protection184ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create Quality of Service Profiles for IPv4 Firewall RulesA Quality of Service

Strany 96

Firewall Protection185 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 112. 3. Enter the settings as described in the following table.4. Clic

Strany 97 - Manage the Network Database

Firewall Protection186ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit a QoS profile:1. In the List of QoS Profiles table, click the Edit t

Strany 98

Firewall Protection187 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Several types of blocking are available:• Web component blocking. You can bloc

Strany 99

Firewall Protection188ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • If the keyword “.com” is specified, only websites with other domain suffixes

Strany 100 - Figure 56

Firewall Protection189 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. In the Web Components section of the screen, select the components that you

Strany 101 - Figure 57

Introduction19 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Rear PanelThe rear panel of the VPN firewall includes a console port, a Factory Defaul

Strany 102 - Manage the IPv6 LAN

Firewall Protection190ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To set a schedule:1. Select Security > Services > Schedule 1. The Sche

Strany 103 - DHCPv6 Server Options

Firewall Protection191 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: For additional ways of restricting outbound traffic, see Outbound Rules

Strany 104 - Configure the IPv6 LAN

Firewall Protection192ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:If you select Permit and Block the rest from the drop-down list but do

Strany 105 - LAN Configuration

Firewall Protection193 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Host 2 has changed its MAC address to 00:01:02:03:04:09. The packet has an I

Strany 106 - IPv6 LAN Address Pools

Firewall Protection194ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. In the IP/MAC Bindings sections of the screen, enter the settings as descri

Strany 107 - Figure 59

Firewall Protection195 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click the Set Interval button. Wait for the confirmation that the operation

Strany 108 -  To edit a prefix:

Firewall Protection196ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click the Add table button. The new IP/MAC rule is added to the IP/MAC Bind

Strany 109

Firewall Protection197 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Port TriggeringPort triggering allows some applications running on a

Strany 110 - Figure 61

Firewall Protection198ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 120. 2. In the Add Port Triggering Rule section, enter the settings as

Strany 111

Firewall Protection199 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To remove one or more port triggering rules from the table:1. Select the che

Strany 112 - Figure 62

2ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SupportThank you for selecting NETGEAR products. After installing your device, locate the serial nu

Strany 113 - Default VLAN

Introduction20ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Factory Defaults Reset button. Using a sharp object, press and hold this button for

Strany 114

Firewall Protection200ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The UPnP Portmap Table in the lower part of the screen shows the IP addresses

Strany 115 - DMZ Port for IPv4 Traffic

20155. Virtual Private Networking Using IPSec and L2TP ConnectionsThis chapter describes how to use the IP security (IPSec) virtual private networ

Strany 116 - Figure 64

Virtual Private Networking Using IPSec and L2TP Connections202ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Considerations for Dual WAN Port Syste

Strany 117

Virtual Private Networking Using IPSec and L2TP Connections203 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table summarizes the WAN

Strany 118 - DMZ Port for IPv6 Traffic

Virtual Private Networking Using IPSec and L2TP Connections204ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv4 Gateway-to-Gateway VPN

Strany 119 - Figure 65

Virtual Private Networking Using IPSec and L2TP Connections205 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To view the wizard default settings, c

Strany 120

Virtual Private Networking Using IPSec and L2TP Connections206ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: To ensure that tunnels stay activ

Strany 121 - IPv6 DMZ Address Pools

Virtual Private Networking Using IPSec and L2TP Connections207 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 128. 4. Configure a VPN policy

Strany 122

Virtual Private Networking Using IPSec and L2TP Connections208ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv6 Gateway-to-Gateway VPN

Strany 123

Virtual Private Networking Using IPSec and L2TP Connections209 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To view the wizard default settings, c

Strany 124 - Figure 67

Introduction21 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Use the Rack-Mounting KitUse the mounting kit for the VPN firewall to install the appl

Strany 125

Virtual Private Networking Using IPSec and L2TP Connections210ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: To ensure that tunnels stay activ

Strany 126 - Figure 68

Virtual Private Networking Using IPSec and L2TP Connections211 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 133. 5. Configure a VPN policy

Strany 127 - Manage Static IPv4 Routing

Virtual Private Networking Using IPSec and L2TP Connections212ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create an IPv4 Client-to-Gateway VPN T

Strany 128 - Figure 70

Virtual Private Networking Using IPSec and L2TP Connections213 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 136. To display the wizard def

Strany 129 - Figure 71

Virtual Private Networking Using IPSec and L2TP Connections214ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.

Strany 130

Virtual Private Networking Using IPSec and L2TP Connections215 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 137. Note: When you are using

Strany 131 - IPv4 Static Route Example

Virtual Private Networking Using IPSec and L2TP Connections216ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Perform these tasks from a compu

Strany 132 - Manage Static IPv6 Routing

Virtual Private Networking Using IPSec and L2TP Connections217 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 139. 3. Select the A router or

Strany 133

Virtual Private Networking Using IPSec and L2TP Connections218ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 141. 6. This screen is a summa

Strany 134 - Firewall Protection

Virtual Private Networking Using IPSec and L2TP Connections219 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308c. Specify the settings that are descr

Strany 135 - About Firewall Protection

Introduction22ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: The VPN firewall factory default IP address is 192.168.1.1. If you change the IP

Strany 136

Virtual Private Networking Using IPSec and L2TP Connections220ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 143. b. Specify the default li

Strany 137

Virtual Private Networking Using IPSec and L2TP Connections221 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the Authentication Settings

Strany 138

Virtual Private Networking Using IPSec and L2TP Connections222ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: This is the name for the authen

Strany 139

Virtual Private Networking Using IPSec and L2TP Connections223 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to use the new settings

Strany 140

Virtual Private Networking Using IPSec and L2TP Connections224ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 8. Click Apply to use the new settings

Strany 141

Virtual Private Networking Using IPSec and L2TP Connections225 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 148. 3. Specify the settings t

Strany 142

Virtual Private Networking Using IPSec and L2TP Connections226ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to use the new settings

Strany 143

Virtual Private Networking Using IPSec and L2TP Connections227 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Test the Connection and View Connectio

Strany 144 - Order of Precedence for Rules

Virtual Private Networking Using IPSec and L2TP Connections228ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 151. • Use the system-tray ico

Strany 145 - Configure LAN WAN Rules

Virtual Private Networking Using IPSec and L2TP Connections229 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308NETGEAR VPN Client Status and Log Info

Strany 146 - Figure 76

Introduction23 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Login. The web management interface displays, showing the Router Status scree

Strany 147 - IPv4 LAN WAN Outbound Rules

Virtual Private Networking Using IPSec and L2TP Connections230ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The Active IPSec SA(s) table lists eac

Strany 148 - IPv6 LAN WAN Outbound Rules

Virtual Private Networking Using IPSec and L2TP Connections231 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Manage IPSec VPN Policies• Manage IKE

Strany 149 - Figure 78

Virtual Private Networking Using IPSec and L2TP Connections232ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 158. Each policy contains the d

Strany 150 - Figure 79

Virtual Private Networking Using IPSec and L2TP Connections233 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: You cannot delete or edit an IKE

Strany 151 - IPv6 LAN WAN Inbound Rules

Virtual Private Networking Using IPSec and L2TP Connections234ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Complete the settings as described

Strany 152 - Configure DMZ WAN Rules

Virtual Private Networking Using IPSec and L2TP Connections235 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Identifier From the drop-down list, se

Strany 153 - Figure 82

Virtual Private Networking Using IPSec and L2TP Connections236ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Authentication Method Select one of th

Strany 154 - Figure 83

Virtual Private Networking Using IPSec and L2TP Connections237 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings.

Strany 155 - Figure 84

Virtual Private Networking Using IPSec and L2TP Connections238ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your changes. T

Strany 156 - Figure 85

Virtual Private Networking Using IPSec and L2TP Connections239 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 160. Each policy contains the d

Strany 157 - Figure 86

Introduction24ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The web management interface menu consists of the following components:• 1st level: Ma

Strany 158 - Configure LAN DMZ Rules

Virtual Private Networking Using IPSec and L2TP Connections240ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 For information about how to add or ed

Strany 159 - Figure 88

Virtual Private Networking Using IPSec and L2TP Connections241 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 162. Add New VPN Policy screen

Strany 160 - Figure 89

Virtual Private Networking Using IPSec and L2TP Connections242ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Policy Type From the drop-down list, s

Strany 161 - Figure 90

Virtual Private Networking Using IPSec and L2TP Connections243 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Traffic SelectionLocal IP From the dro

Strany 162 - Figure 91

Virtual Private Networking Using IPSec and L2TP Connections244ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Key-Out The encryption key for the out

Strany 163 - Figure 92

Virtual Private Networking Using IPSec and L2TP Connections245 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings.

Strany 164 - Examples of Firewall Rules

Virtual Private Networking Using IPSec and L2TP Connections246ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 requesting individual authentication i

Strany 165 - Figure 94

Virtual Private Networking Using IPSec and L2TP Connections247 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. In the Extended Authentication sect

Strany 166 - Figure 95

Virtual Private Networking Using IPSec and L2TP Connections248ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 name and password information. The gat

Strany 167 - Figure 96

Virtual Private Networking Using IPSec and L2TP Connections249 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.N

Strany 168 - Figure 97

Introduction25 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308When a screen includes a table, table buttons display to let you configure the table e

Strany 169 - FTP Site on the Internet

Virtual Private Networking Using IPSec and L2TP Connections250ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Assign IPv4 Addresses to Remote Users

Strany 170 - Attack Checks

Virtual Private Networking Using IPSec and L2TP Connections251 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To configure Mode Config on the VPN

Strany 171

Virtual Private Networking Using IPSec and L2TP Connections252ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Complete the settings as described

Strany 172 - IPv6 Attack Checks

Virtual Private Networking Using IPSec and L2TP Connections253 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.

Strany 173 - Set Limits for IPv4 Sessions

Virtual Private Networking Using IPSec and L2TP Connections254ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 166. 8. On the Add IKE Policy

Strany 174

Virtual Private Networking Using IPSec and L2TP Connections255 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 60. Add IKE Policy screen setti

Strany 175 - Figure 103

Virtual Private Networking Using IPSec and L2TP Connections256ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IKE SA ParametersNote: Generally, the

Strany 176 - Figure 104

Virtual Private Networking Using IPSec and L2TP Connections257 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53089. Click Apply to save your settings.

Strany 177 - Add Customized Services

Virtual Private Networking Using IPSec and L2TP Connections258ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Perform these tasks from a compu

Strany 178 -  To edit a service:

Virtual Private Networking Using IPSec and L2TP Connections259 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Change the name of the authenticati

Strany 179 - Create IP Groups

2622. IPv4 and IPv6 Internet and WAN SettingsThis chapter explains how to configure the IPv4 and IPv6 Internet and WAN settings. The chapter contain

Strany 180 -  To edit an IP group:

Virtual Private Networking Using IPSec and L2TP Connections260ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to use the new settings

Strany 181 - Create Bandwidth Profiles

Virtual Private Networking Using IPSec and L2TP Connections261 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53088. Click Apply to use the new settings

Strany 182 - Profile screen displays:

Virtual Private Networking Using IPSec and L2TP Connections262ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 171. 3. Specify the settings t

Strany 183

Virtual Private Networking Using IPSec and L2TP Connections263 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to use the new settings

Strany 184 - Figure 111

Virtual Private Networking Using IPSec and L2TP Connections264ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Specify the following default lifet

Strany 185 - Figure 112

Virtual Private Networking Using IPSec and L2TP Connections265 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Verify that the VPN firewall issued

Strany 186 - Configure Content Filtering

Virtual Private Networking Using IPSec and L2TP Connections266ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 keep-alive and Dead Peer Detection (DP

Strany 187

Virtual Private Networking Using IPSec and L2TP Connections267 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Enter the settings as described in

Strany 188 - Figure 113

Virtual Private Networking Using IPSec and L2TP Connections268ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 177. 4. In the IKE SA Paramete

Strany 189

Virtual Private Networking Using IPSec and L2TP Connections269 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Specify the IP version for which yo

Strany 190 - Enable Source MAC Filtering

IPv4 and IPv6 Internet and WAN Settings27 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet and WAN Configuration Tasks• Roadmap to Setting Up

Strany 191 - Figure 115

Virtual Private Networking Using IPSec and L2TP Connections270ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To enable the PPTP server and config

Strany 192 - Set Up IP/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections271 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.V

Strany 193 - IPv4/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections272ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure the L2TP ServerAs an alterna

Strany 194 - Figure 117

Virtual Private Networking Using IPSec and L2TP Connections273 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in

Strany 195 - IPv6/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections274ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 L2TP IP The IP address that is assigne

Strany 196 - Figure 119

27566. Virtual Private Networking Using SSL ConnectionsThe VPN firewall provides a hardware-based SSL VPN solution designed specifically to provide

Strany 197 - Configure Port Triggering

Virtual Private Networking Using SSL Connections276ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SSL VPN Portal OptionsThe VPN firewall’s SSL VPN

Strany 198 - Figure 120

Virtual Private Networking Using SSL Connections277 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308resources to which the users are granted access.

Strany 199 -  To configure UPnP:

Virtual Private Networking Using SSL Connections278ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 You apply portal layouts by selecting one from th

Strany 200

Virtual Private Networking Using SSL Connections279 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The List of Layouts table displays the following

Strany 201 - IPSec and L2TP Connections

IPv4 and IPv6 Internet and WAN Settings28ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. (Optional) Configure Dynamic DNS on the WAN interfaces.

Strany 202

Virtual Private Networking Using SSL Connections280ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Complete the settings as described in the foll

Strany 203 - Configurations

Virtual Private Networking Using SSL Connections281 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The new por

Strany 204 - Figure 126

Virtual Private Networking Using SSL Connections282ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 For information about how to configure domains, g

Strany 205 - Figure 127

Virtual Private Networking Using SSL Connections283 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. In the Add New Application for Port Forwarding

Strany 206

Virtual Private Networking Using SSL Connections284ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To add servers and host names for client name r

Strany 207 - Figure 129

Virtual Private Networking Using SSL Connections285 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Select whether you want to enable full-tunnel o

Strany 208 - Figure 131

Virtual Private Networking Using SSL Connections286ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 188. SSL VPN Client screen for IPv63. Com

Strany 209 - Figure 132

Virtual Private Networking Using SSL Connections287 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. VPN tunnel

Strany 210

Virtual Private Networking Using SSL Connections288ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 If VPN tunnel clients are already connected, disc

Strany 211 - Figure 134

Virtual Private Networking Using SSL Connections289 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 189. 2. In the Add New Resource section o

Strany 212 - Figure 135

IPv4 and IPv6 Internet and WAN Settings29 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. (Optional) Configure the WAN options. If necessary, chan

Strany 213 - Figure 136

Virtual Private Networking Using SSL Connections290ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 190. 4. Complete the settings as describe

Strany 214

Virtual Private Networking Using SSL Connections291 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The new con

Strany 215 - Figure 137

Virtual Private Networking Using SSL Connections292ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 includes the following addresses: 10.0.0.5–10.0.0

Strany 216 - Figure 138

Virtual Private Networking Using SSL Connections293 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Make your selection from the following Query o

Strany 217 - Figure 140

Virtual Private Networking Using SSL Connections294ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 .Figure 193. Add SSL VPN Policy screen for IPv64

Strany 218 - Figure 142

Virtual Private Networking Using SSL Connections295 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Apply Policy to? (continued)Network ResourcePolic

Strany 219

Virtual Private Networking Using SSL Connections296ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your settings. The policy

Strany 220 - Figure 143

Virtual Private Networking Using SSL Connections297 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more SSL VPN policies:1. On th

Strany 221 - Figure 145

Virtual Private Networking Using SSL Connections298ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. In the Portal URL field of the List of Layouts

Strany 222 - Figure 146

Virtual Private Networking Using SSL Connections299 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 198. The User Portal screen displays a si

Strany 223 - The Advanced pane displays:

3ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 202-10536-03 1.0 November 2011 Incorporated nontechnical edits only (there are no feature changes).

Strany 224

IPv4 and IPv6 Internet and WAN Settings30ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • If your ISP has provided you with multiple public IP addr

Strany 225 - Figure 148

Virtual Private Networking Using SSL Connections300ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 199. The active user’s name, group, and IP

Strany 226 - Figure 149

30177. Manage Users, Authentication, and VPN CertificatesThis chapter describes how to manage users, authentication, and security certificates for

Strany 227 - Information

Manage Users, Authentication, and VPN Certificates302ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The VPN Firewall’s Authentication Process and O

Strany 228 - Figure 154

Manage Users, Authentication, and VPN Certificates303 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Authentication Domains, Groups, and U

Strany 229 - Figure 156

Manage Users, Authentication, and VPN Certificates304ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Create Domains To create a domain:1. Select Us

Strany 230 - Figure 157

Manage Users, Authentication, and VPN Certificates305 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 202. 3. Complete the settings as descri

Strany 231 - Manage IPSec VPN Policies

Manage Users, Authentication, and VPN Certificates306ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The domai

Strany 232 - Figure 158

Manage Users, Authentication, and VPN Certificates307 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: A combination of local and external authe

Strany 233 - Figure 159

Manage Users, Authentication, and VPN Certificates308ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 IMPORTANT:When you create a domain on the Domai

Strany 234

Manage Users, Authentication, and VPN Certificates309 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: When you create a domain on the Domains

Strany 235

IPv4 and IPv6 Internet and WAN Settings31 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings. These settings apply

Strany 236

Manage Users, Authentication, and VPN Certificates310ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Edit GroupsFor groups that were automatically c

Strany 237 -  To edit an IKE policy:

Manage Users, Authentication, and VPN Certificates311 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Guest user. A user who can only view the VPN

Strany 238 - Manage VPN Policies

Manage Users, Authentication, and VPN Certificates312ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 206. 3. Enter the settings as described

Strany 239 - Figure 160

Manage Users, Authentication, and VPN Certificates313 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more user accounts:1. In the

Strany 240

Manage Users, Authentication, and VPN Certificates314ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: For security reasons, the Deny Login from

Strany 241 - Setting Description

Manage Users, Authentication, and VPN Certificates315 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. In the Add Defined Addresses section of the

Strany 242

Manage Users, Authentication, and VPN Certificates316ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 209. 5. In the Defined Addresses Status

Strany 243

Manage Users, Authentication, and VPN Certificates317 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more IPv6 addresses:1. In th

Strany 244

Manage Users, Authentication, and VPN Certificates318ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Firefox. Mozilla Firefox.• Mozilla. Other Moz

Strany 245 -  To edit a VPN policy:

Manage Users, Authentication, and VPN Certificates319 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 211. 3. Change the settings as describe

Strany 246

IPv4 and IPv6 Internet and WAN Settings32ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 12. 3. Click the Auto Detect button at the bottom o

Strany 247 - User Database Configuration

Manage Users, Authentication, and VPN Certificates320ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage Digital Certificates for VPN Connections

Strany 248 - Figure 163

Manage Users, Authentication, and VPN Certificates321 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Because a commercial CA takes steps to verify t

Strany 249

Manage Users, Authentication, and VPN Certificates322ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage VPN CA Certificates To view and upload

Strany 250 - Mode Config Operation

Manage Users, Authentication, and VPN Certificates323 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Manage VPN Self-Signed CertificatesInstead of o

Strany 251 - Figure 165

Manage Users, Authentication, and VPN Certificates324ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 214. Certificates, screen 2 of 32. In t

Strany 252

Manage Users, Authentication, and VPN Certificates325 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click the Generate table button. A new SCR i

Strany 253

Manage Users, Authentication, and VPN Certificates326ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 9. Select the check box next to the self-signed

Strany 254 - Figure 166

Manage Users, Authentication, and VPN Certificates327 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 216. Certificates, screen 3 of 3The Cer

Strany 255

32888. Network and System ManagementThis chapter describes the tools for managing the network traffic to optimize its performance and the system man

Strany 256

Network and System Management329 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Performance Management• Bandwidth Capacity• Features That Reduce Tra

Strany 257 - Operation

IPv4 and IPv6 Internet and WAN Settings33 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• If the autodetect process does not find a connection, you

Strany 258 - Figure 168

Network and System Management330ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Features That Reduce TrafficYou can adjust the following features of

Strany 259 - Figure 169

Network and System Management331 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• LAN users (or DMZ users). You can specify which computers on your

Strany 260

Network and System Management332ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 In order to reduce traffic, the VPN firewall provides the following

Strany 261

Network and System Management333 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Each rule lets you specify the desired action for the connections co

Strany 262 - Figure 171

Network and System Management334ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 - Address range. The rule applies to a range of Internet IP addresse

Strany 263 - Figure 172

Network and System Management335 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN, L2TP, and PPTP TunnelsThe VPN firewall supports site-to-site IP

Strany 264 - Figure 174

Network and System Management336ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Monitoring Tools for Traffic ManagementThe VPN firewall includes sev

Strany 265 - Figure 175

Network and System Management337 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 217. 2. In the Action column of the List of Users table, cli

Strany 266 - Configure Keep-Alives

Network and System Management338ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your settings.7. Repeat Step 1 through Step

Strany 267 - Configure Dead Peer Detection

Network and System Management339 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308continuing (see Change Passwords and Administrator and Guest Setting

Strany 268 - Figure 177

IPv4 and IPv6 Internet and WAN Settings34ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 13. The Connection Status screen should show a vali

Strany 269 - Configure the PPTP Server

Network and System Management340ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 220. Remote Management screen for IPv63. Enter the settings

Strany 270 - Figure 179

Network and System Management341 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WARNING:If you are remotely connected to the VPN firewall and you se

Strany 271 - View the Active PPTP Users

Network and System Management342ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: If you are using a Dynamic DNS service such as TZO, you can ide

Strany 272 - Configure the L2TP Server

Network and System Management343 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 221. The SNMPv3 Users table includes the default SNMPv3 user

Strany 273 - View the Active L2TP Users

Network and System Management344ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. To specify a new SNMP configuration, in the Create New SNMP Confi

Strany 274 - Item Description

Network and System Management345 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 222. 2. Modify the settings as described in the previous tab

Strany 275 - SSL Connections

Network and System Management346ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your changes. To configure the SNMP system i

Strany 276 - SSL VPN Portal Options

Network and System Management347 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:3. Click A

Strany 277 - Create the Portal Layout

Network and System Management348ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 225. Back Up SettingsThe backup feature saves all VPN firewal

Strany 278

Network and System Management349 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Restore SettingsWARNING:Restore only settings that were backed up fr

Strany 279 - Figure 185

IPv4 and IPv6 Internet and WAN Settings35 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The IPv4 WAN Settings table displays the following fields:•

Strany 280

Network and System Management350ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:When you press the hardware factory default Reset button or

Strany 281 -  To edit a portal layout:

Network and System Management351 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The newly installed firmware is the active firmware. The previously

Strany 282 - Add Servers and Port Numbers

Network and System Management352ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Select Monitoring. The Router Status screen displays, showing the

Strany 283 - Add a New Host Name

Network and System Management353 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Resolve IPv6 address for serversSelect this check box to force the u

Strany 284 - Configure the SSL VPN Client

Network and System Management354ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.Note: If you select the default

Strany 285

35599. Monitor System Access and PerformanceThis chapter describes the system-monitoring features of the VPN firewall. You can be alerted to importa

Strany 286

Monitor System Access and Performance356ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure and Enable the WAN Traffic MeterIf your ISP charge

Strany 287

Monitor System Access and Performance357 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 88. WAN1 Traffic Meter screen settings Setting Descri

Strany 288 - Add New Network Resources

Monitor System Access and Performance358ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.4. If you want to enabl

Strany 289 -  To edit network resources:

Monitor System Access and Performance359 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure and Enable the LAN Traffic MeterIf your ISP charge

Strany 290 - Figure 190

IPv4 and IPv6 Internet and WAN Settings36ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 16. 6. If your connection is PPTP or PPPoE, your IS

Strany 291

Monitor System Access and Performance360ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Traffic (MB). The traffic usage in MB.• State. The state t

Strany 292 - View Policies

Monitor System Access and Performance361 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. Click Apply to save your settings. The new account is add

Strany 293 -  To add an SSL VPN policy:

Monitor System Access and Performance362ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure Logging, Alerts, and Event NotificationsYou can co

Strany 294

Monitor System Access and Performance363 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as described in the following table:Ta

Strany 295

Monitor System Access and Performance364ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Enable E-mail LogsDo you want logs to be emailed to you?Sele

Strany 296 -  To edit an SSL VPN policy:

Monitor System Access and Performance365 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.Note: Enabling routing

Strany 297

Monitor System Access and Performance366ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 234. You can refresh the logs, clear the logs, or se

Strany 298 - Figure 197

Monitor System Access and Performance367 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308How to Send Syslogs over a VPN Tunnel between Sites To send

Strany 299 - Figure 198

Monitor System Access and Performance368ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. In the Traffic Selector section of the screen, make the f

Strany 300 - Figure 200

Monitor System Access and Performance369 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308View Status Screens• View the System Status• View the VPN Co

Strany 301 - VPN Certificates

IPv4 and IPv6 Internet and WAN Settings37 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53087. In the Internet (IP) Address section of the screen (see

Strany 302

Monitor System Access and Performance370ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 236. The following table explains the fields of the R

Strany 303 - Configure Domains

Monitor System Access and Performance371 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Router Statistics Screen To view the Router Statistics scre

Strany 304 - Create Domains

Monitor System Access and Performance372ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 237. The following table explains the fields of the

Strany 305 - Figure 202

Monitor System Access and Performance373 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 238.

Strany 306

Monitor System Access and Performance374ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The following table explains the fields of the Detailed Stat

Strany 307 - Configure Groups

Monitor System Access and Performance375 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ IPv6 ConfigurationIPv6 Address The IPv6 address and pref

Strany 308 - Create Groups

Monitor System Access and Performance376ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 VLAN Status ScreenThe VLAN Status screen displays informatio

Strany 309 - Figure 204

Monitor System Access and Performance377 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table explains the fields of the VLAN Status s

Strany 310 - Configure User Accounts

Monitor System Access and Performance378ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 View the VPN Connection Status, L2TP Users, and PPTP UsersTh

Strany 311 - Figure 205

Monitor System Access and Performance379 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The active user’s user name, group, and IP address are liste

Strany 312 - Figure 206

IPv4 and IPv6 Internet and WAN Settings38ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 8. In the Domain Name Server (DNS) Servers section of the s

Strany 313 - Set User Login Policies

Monitor System Access and Performance380ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The List of PPTP Active Users table lists each active connec

Strany 314 - Figure 208

Monitor System Access and Performance381 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 246. View the Port Triggering Status To view the sta

Strany 315

Monitor System Access and Performance382ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 248. The Port Triggering Status screen displays the

Strany 316 - Figure 209

Monitor System Access and Performance383 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 249. 2. In the Action column, click the Status butto

Strany 317 - Figure 210

Monitor System Access and Performance384ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Click Disconnect to disconnect the connection; click Connect

Strany 318

Monitor System Access and Performance385 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 252. The type of connection determines the informati

Strany 319 - Figure 211

Monitor System Access and Performance386ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 View the Attached Devices To view the attached devices on t

Strany 320

Monitor System Access and Performance387 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: If the VPN firewall is rebooted, the data in the Known

Strany 321 - VPN Certificates Screen

Monitor System Access and Performance388ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Diagnostics Utilities• Send a Ping Packet• Trace a Route• Lo

Strany 322 - Manage VPN CA Certificates

Monitor System Access and Performance389 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• IPv6. Select the IPv6 radio button. The Diagnostics screen

Strany 323 - Figure 213

IPv4 and IPv6 Internet and WAN Settings39 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53089. Click Apply to save your changes.10. Click Test to evalu

Strany 324

Monitor System Access and Performance390ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Trace a RouteA traceroute lists all routers between the sour

Strany 325 - Figure 215

Monitor System Access and Performance391 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Capture Packets in Real TimeCapturing packets can assist NET

Strany 326 -  To delete one or more SCRs:

3921010. TroubleshootingThis chapter provides troubleshooting tips and information for the VPN firewall. After each problem description, instruction

Strany 327 -  To delete one or more CRLs:

Troubleshooting393 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The VPN firewall’s diagnostic tools are described in Diagnostics Utilities o

Strany 328 - Network and System Management

Troubleshooting394ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  If all LEDs are still on more than several minutes minute after power-up, do the

Strany 329 - Performance Management

Troubleshooting395 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Make sure that you are using the SSL https://address login rather than the http:

Strany 330 - Features That Reduce Traffic

Troubleshooting396ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Troubleshoot the ISP ConnectionIf your VPN firewall is unable to access the Intern

Strany 331 - Content Filtering

Troubleshooting397 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308have to enter additional information. For more information, see Manually Configure

Strany 332 - Source MAC Filtering

Troubleshooting398ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 - Windows Server 2003, all versions- Windows Server 2003 R2, all versions- Linux a

Strany 333

Troubleshooting399 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308c. Click or double-click View status of this connection. The Local Area Connection

Strany 334 - Exposed Hosts

4ContentsChapter 1 IntroductionWhat Is the ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308? .12Key Features and Capabilities . . . . . . . . . . .

Strany 335 - Assign Bandwidth Profiles

IPv4 and IPv6 Internet and WAN Settings40ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: If your ISP requires MAC authentication and another M

Strany 336 - System Management

Troubleshooting400ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 f. Make sure that an IPv6 address shows. The previous figure does not show an IPv6

Strany 337 - Figure 218

Troubleshooting401 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Test the Path from Your Computer to a Remote DeviceAfter verifying that the LAN pa

Strany 338

Troubleshooting402ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 261. b. In the Backup / Restore Settings section of the screen, click the

Strany 339

Troubleshooting403 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Address Problems with Date and TimeThe System Date & Time screen displays the

Strany 340

404AA. Default Settings and Technical SpecificationsThis appendix provides the default settings and the physical and technical specifications of the

Strany 341 - About Remote Access

Default Settings and Technical Specifications405ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Factory Default SettingsYou can use the factory defau

Strany 342 -  To access the CLI:

Default Settings and Technical Specifications406ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv4 LAN, DMZ, and routing settingsLAN IPv4 address f

Strany 343 - Figure 221

Default Settings and Technical Specifications407ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Firewall and security settingsInbound LAN WAN rules (

Strany 344

Default Settings and Technical Specifications408ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308QoS priorities (for IPv6 firewall rules) Normal-Servi

Strany 345 - Figure 223

Default Settings and Technical Specifications409ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN IPsec Wizard: IKE policy settings for IPv4 gatewa

Strany 346 - Figure 224

IPv4 and IPv6 Internet and WAN Settings41 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Load Balancing Mode and Optional Protocol Binding

Strany 347 - Manage the Configuration File

Default Settings and Technical Specifications410ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Physical and Technical SpecificationsThe following ta

Strany 348 - Back Up Settings

Default Settings and Technical Specifications411ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table shows the IPSec VPN specification

Strany 349 - Restore Settings

Default Settings and Technical Specifications412ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following table shows the SSL VPN specifications

Strany 350 - Upgrade the Firmware

413BB. Network Planning for Multiple WAN PortsThis appendix describes the factors to consider when planning a network using a firewall that has more

Strany 351

Network Planning for Multiple WAN Ports414ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308What to Consider Before You Begin• Cabling and Computer Har

Strany 352 - Figure 226

Network Planning for Multiple WAN Ports415ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 262. b. Contact a Dynamic DNS service, and register

Strany 353

Network Planning for Multiple WAN Ports416ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet Configuration RequirementsDepending on how your IS

Strany 354

Network Planning for Multiple WAN Ports417ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Internet Connection InformationPrint this page with the Int

Strany 355 - Performance

Network Planning for Multiple WAN Ports418ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Overview of the Planning ProcessThe areas that require plan

Strany 356 - Figure 227

Network Planning for Multiple WAN Ports419ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Features such as multiple exposed hosts are not supported i

Strany 357

IPv4 and IPv6 Internet and WAN Settings42ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 b. From the corresponding drop-down list on the right, sele

Strany 358 - Figure 228

Network Planning for Multiple WAN Ports420ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 265. Inbound Traffic to a Dual WAN Port SystemThe IP

Strany 359 - Figure 230

Network Planning for Multiple WAN Ports421ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 267. Virtual Private Networks• VPN Road Warrior (Cli

Strany 360 - Figure 231

Network Planning for Multiple WAN Ports422ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308always changes. Therefore, the use of an FQDN is always req

Strany 361 - Figure 232

Network Planning for Multiple WAN Ports423ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Road Warrior: Single-Gateway WAN Port (Reference Case)I

Strany 362 - Figure 233

Network Planning for Multiple WAN Ports424ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 272. The purpose of the FQDN in this case is to togg

Strany 363

Network Planning for Multiple WAN Ports425ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Gateway-to-GatewayThe following situations exemplify th

Strany 364

Network Planning for Multiple WAN Ports426ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 275. The IP addresses of the gateway WAN ports can b

Strany 365

Network Planning for Multiple WAN Ports427ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 277. The IP addresses of the gateway WAN ports can b

Strany 366 - Figure 235

Network Planning for Multiple WAN Ports428ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The IP address of the gateway WAN port can be either fixed

Strany 367 - Configure Gateway 1 at Site 1

Network Planning for Multiple WAN Ports429ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Telecommuter: Dual-Gateway WAN Ports for Load Balancing

Strany 368 - Configure Gateway 2 at Site 2

IPv4 and IPv6 Internet and WAN Settings43 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• Destination Network. The Internet locations (based on the

Strany 369 - View Status Screens

430CC. System Logs and Error MessagesThis appendix provides examples and explanations of system logs and error message. When applicable, a recommend

Strany 370 - Figure 236

System Logs and Error Messages431ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Log Message TermsThis appendix uses the following log message terms.

Strany 371 - Router Statistics Screen

System Logs and Error Messages432ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This section describes log messages that belong to one of the follow

Strany 372 - Detailed Status Screen

System Logs and Error Messages433ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308System StartupThis section describes the log message generated durin

Strany 373 - Figure 238

System Logs and Error Messages434ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPSec RestartThis section describes logs that are generated when IPS

Strany 374

System Logs and Error Messages435ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Multicast/Broadcast LogsWAN StatusThis section describes the logs ge

Strany 375

System Logs and Error Messages436ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This section describes the logs generated when the WAN mode is set t

Strany 376 - VLAN Status Screen

System Logs and Error Messages437ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• PPPoE Idle Timeout Logs• PPTP Idle Timeout LogsTable 118. System

Strany 377 - Tunnel Status Screen

System Logs and Error Messages438ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• PPP Authentication LogsResolved DNS NamesThis section describes th

Strany 378 - Figure 242

System Logs and Error Messages439ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Log MessagesThis section explains logs that are generated by IPS

Strany 379 - Figure 244

IPv4 and IPv6 Internet and WAN Settings44ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your settings. The protocol binding

Strany 380 - View the VPN Logs

System Logs and Error Messages440ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Messages 22 and 23 Messages 24 and 25 2000 Jan 1 04:13:40 [SRX530

Strany 381 - Figure 247

System Logs and Error Messages441ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Explanation Message 1: Informational exchange for deleting the pay

Strany 382 - View the WAN Port Status

System Logs and Error Messages442ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Explanation Message 1–4: After receiving a request for phase 1 nego

Strany 383 - Figure 250

System Logs and Error Messages443ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SSL VPN LogsThis section describes the log messages that are generat

Strany 384 - IPv6 WAN Port Status

System Logs and Error Messages444ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Traffic Meter LogsRouting Logs• LAN to WAN Logs• LAN to DMZ Logs• DM

Strany 385 - Figure 252

System Logs and Error Messages445ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN to WAN LogsLAN to DMZ LogsDMZ to WAN LogsWAN to LAN LogsTable 13

Strany 386 - View the Attached Devices

System Logs and Error Messages446ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ to LAN LogsWAN to DMZ LogsOther Event Logs• Session Limit Logs•

Strany 387 - View the DHCP Log

System Logs and Error Messages447ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Source MAC Filter LogsBandwidth Limit LogsDHCP LogsThis section expl

Strany 388 - Diagnostics Utilities

System Logs and Error Messages448ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Table 143. DHCP logs Message 1 Message 2 Message 3 Message 4 Messag

Strany 389 - Send a Ping Packet

449DD. Two-Factor AuthenticationThis appendix provides an overview of two-factor authentication, and an example of how to implement the WiKID soluti

Strany 390 - Display the Routing Tables

IPv4 and IPv6 Internet and WAN Settings45 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the Auto-Rollover Mode and Failure Detection Meth

Strany 391 - Capture Packets in Real Time

Two-Factor Authentication450ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Why Do I Need Two-Factor Authentication?• What Are the Benefits of Two-Fa

Strany 392 - Troubleshooting

Two-Factor Authentication451ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308This appendix focuses on and discusses only the first two factors, someth

Strany 393 - Basic Functioning

Two-Factor Authentication452ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. A one-time passcode (something the user has) is generated.Figure 283.

Strany 394 - LAN or WAN Port LEDs Not On

453EE. Notification of ComplianceNETGEAR wired productsRegulatory Compliance InformationThis section includes user requirements for operating this p

Strany 395

Notification of Compliance454ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308FCC Radio Frequency Interference Warnings & InstructionsThis equipme

Strany 396

455IndexNumerics10BASE-T, 100BASE-T, and 1000BASE-T speeds 743322.org 49–526to4 tunnelsconfiguring globally 64DMZ, configuring for 126LAN, configuring

Strany 397

456ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6configuring 69described 68VPN IPSec 202, 206, 214autosensing port speed 74Bbacking up configur

Strany 398 - Figure 258

457ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ portIPv4 address and subnet mask 116IPv6 address and prefix length 120settings 115domain, user

Strany 399 - Figure 260

458ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SSL VPN settings 286server IPv6 addressesbroadband settings 59, 63DMZ settings 121LAN settings 106

Strany 400

459ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308global addresses, IPv6 65global IPv6 tunnelsDMZ, configuring for 126LAN, configuring for 112group

Strany 401

IPv4 and IPv6 Internet and WAN Settings46ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the Load Balancing Settings section of the screen, co

Strany 402 - Figure 261

460ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308DHCP, address pool 117DMZ port 116DNS servers 39, 91, 117dynamically assigned 38errors 25ISATAP tu

Strany 403

461ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308JJava, blocking 187Kkeep-alives, VPN tunnels 242, 266keyword blocking 187kit, rack-mounting 21know

Strany 404 - Specifications

462ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308management default settings 410maximum transmission unit (MTU)default 73IPv6 DMZ packets 125IPv6 L

Strany 405 - Factory Default Settings

463ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6DMZ-to-WAN rules 155LAN-to-DMZ rules 161LAN-to-WAN rules 148order of precedence 144overview 13

Strany 406

464ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308PPPoE (PPP over Ethernet)described 16IPv4 settings 33, 37IPv6 settings 62PPTP (Point-to-Point Tunn

Strany 407

465ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308remote users, assigning addresses (Mode Config) 250requirements, hardware 415reserved IPv4 address

Strany 408

466ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308SPI (stateful packet inspection) 14, 135split tunnel, SSL VPN 285spoofing MAC addresses 397SSL cer

Strany 409

467ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308rate-limiting 75reducing 330–332volume by protocol 358volume, limitingLAN 360WAN 357Transmission C

Strany 410

468ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308FQDNs 202–203, 421FQDNs, configuring endpoints 206, 210, 213, 235gateway-to-gatewayauto-rollover 4

Strany 411

469ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN WAN outbound rules, configuring 147, 330locking yourself outconfiguring an exposed host 167dis

Strany 412

IPv4 and IPv6 Internet and WAN Settings47 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The default time to roll over after the primary WAN i

Strany 413

IPv4 and IPv6 Internet and WAN Settings48ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 After you have configured secondary WAN addresses, these ad

Strany 414

IPv4 and IPv6 Internet and WAN Settings49 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 25. The List of Secondary WAN addresses table displ

Strany 415

5ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure a Static IPv6 Internet Connection. . . . . . . . . . . . . . . . . . . . . .58Configure a

Strany 416

IPv4 and IPv6 Internet and WAN Settings50ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 After you have configured your account information on the V

Strany 417

IPv4 and IPv6 Internet and WAN Settings51 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 26. 3. Click the Information option arrow in the up

Strany 418 - Figure 263

IPv4 and IPv6 Internet and WAN Settings52ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Configure the DDNS service settings as described in the

Strany 419 - Inbound Traffic

IPv4 and IPv6 Internet and WAN Settings53 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: You can configure only one WAN interface for IPv6. Th

Strany 420 - Figure 266

IPv4 and IPv6 Internet and WAN Settings54ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 These are the options:• IPv4-only mode. The VPN firewall co

Strany 421 - Virtual Private Networks

IPv4 and IPv6 Internet and WAN Settings55 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308WARNING:Changing the IP routing mode causes the VPN firewal

Strany 422 - Figure 269

IPv4 and IPv6 Internet and WAN Settings56ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The IPv6 WAN Settings table displays the following fields:•

Strany 423 - Figure 271

IPv4 and IPv6 Internet and WAN Settings57 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. As an optional step: If you have selected the Stateless

Strany 424 - Figure 273

IPv4 and IPv6 Internet and WAN Settings58ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure a Static IPv6 Internet ConnectionTo configure a s

Strany 425 - VPN Gateway-to-Gateway

IPv4 and IPv6 Internet and WAN Settings59 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 33. 4. In the Internet Address section of the scree

Strany 426 - Figure 276

6ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Inbound Rules (Port Forwarding) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 140Order o

Strany 427 - Figure 278

IPv4 and IPv6 Internet and WAN Settings60ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your changes.7. Verify the connectio

Strany 428 - Figure 280

IPv4 and IPv6 Internet and WAN Settings61 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure a PPPoE IPv6 Internet ConnectionTo configure a PP

Strany 429 - Figure 281

IPv4 and IPv6 Internet and WAN Settings62ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 36. 4. In the Internet Address section of the scree

Strany 430

IPv4 and IPv6 Internet and WAN Settings63 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53086. Click Apply to save your changes.7. Verify the connectio

Strany 431 - System Log Messages

IPv4 and IPv6 Internet and WAN Settings64ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: If your ISP requires MAC authentication and another M

Strany 432 - Login/Logout

IPv4 and IPv6 Internet and WAN Settings65 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 37. 2. Select the Enable Automatic Tunneling check

Strany 433 - Firewall Restart

IPv4 and IPv6 Internet and WAN Settings66ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To configure an ISATAP tunnel:1. Select Network Configura

Strany 434 - IPSec Restart

IPv4 and IPv6 Internet and WAN Settings67 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To edit an ISATAP tunnel:1. On the ISATAP Tunnels screen,

Strany 435 - WAN Status

IPv4 and IPv6 Internet and WAN Settings68ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 a.b.c.d for part of the IPv6 address so that the IPv4-trans

Strany 436 - PPP Logs

IPv4 and IPv6 Internet and WAN Settings69 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308To use a redundant ISP link for backup purposes, ensure tha

Strany 437 - • PPTP Idle T

7ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Extended Authentication (XAUTH) . . . . . . . . . . . . . . . . . . . . .245Configure XAU

Strany 438 - Resolved DNS Names

IPv4 and IPv6 Internet and WAN Settings70ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Ensure that the backup WAN interface is configured be

Strany 439 - VPN Log Messages

IPv4 and IPv6 Internet and WAN Settings71 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The default time to roll over after the primary WAN i

Strany 440

IPv4 and IPv6 Internet and WAN Settings72ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 45. 3. Click the Advanced option arrow in the upper

Strany 441

IPv4 and IPv6 Internet and WAN Settings73 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 46. 4. Enter the settings as described in the follo

Strany 442

IPv4 and IPv6 Internet and WAN Settings74ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 SpeedIn most cases, the VPN firewall can automatically dete

Strany 443 - SSL VPN Logs

IPv4 and IPv6 Internet and WAN Settings75 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.Failure Detection Metho

Strany 444 - Routing Logs

IPv4 and IPv6 Internet and WAN Settings76ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:Depending on the changes that you made, when you cl

Strany 445 - WAN to LAN Logs

IPv4 and IPv6 Internet and WAN Settings77 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Note: To configure and apply QoS profiles successfully, fam

Strany 446 - Other Event Logs

IPv4 and IPv6 Internet and WAN Settings78ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 • Hosts. The IP address, IP addresses, or group to which th

Strany 447 - DHCP Logs

IPv4 and IPv6 Internet and WAN Settings79 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Diffserv QoS Match Enter a DSCP value in the range of 0 thr

Strany 448 - Table 143. DHCP logs

8ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Change Passwords and Other User Settings. . . . . . . . . . . . . . . . . . . .318Manage Digital Cer

Strany 449 - Two-Factor Authentication

IPv4 and IPv6 Internet and WAN Settings80ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The profile is added

Strany 450

IPv4 and IPv6 Internet and WAN Settings81 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The profile is added

Strany 451 - Figure 282

IPv4 and IPv6 Internet and WAN Settings82ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit a QoS profile:1. In the List of QoS Profiles tabl

Strany 452 - Figure 284

8333. LAN ConfigurationThis chapter describes how to configure the LAN features of your VPN firewall. The chapter contains the following sections:•

Strany 453 - Notification of Compliance

LAN Configuration84ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage IPv4 Virtual LANs and DHCP Options• Port-Based VLANs • Assign and Manage V

Strany 454

LAN Configuration85 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Port-Based VLANsThe VPN firewall supports port-based VLANs. Port-based VLANs help

Strany 455 - Numerics

LAN Configuration86ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Assign and Manage VLAN Profiles To assign VLAN profiles to the LAN ports and man

Strany 456

LAN Configuration87 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308VLAN DHCP OptionsFor each VLAN, you need to specify the Dynamic Host Configuratio

Strany 457

LAN Configuration88ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 firewall’s LAN IP address). When the DNS proxy option is disabled for a VLAN, all

Strany 458

LAN Configuration89 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 52. 3. Enter the settings as described in the following table: Table 16.

Strany 459

9ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308LAN or WAN Port LEDs Not On . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .394Troublesho

Strany 460

LAN Configuration90ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Port MembershipPort 1, Port 2, Port 3, Port 4 / DMZSelect one, several, or all po

Strany 461

LAN Configuration91 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308Enable DHCP Server Select the Enable DHCP Server radio button to enable the VPN f

Strany 462

LAN Configuration92ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings.Note: Once you have completed the LAN setup,

Strany 463

LAN Configuration93 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 To edit a VLAN profile:1. On the LAN Setup screen for IPv4 (see Figure 51 on p

Strany 464

LAN Configuration94ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 53. 3. From the MAC Address for VLANs drop-down list, select Unique. (The

Strany 465

LAN Configuration95 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308The following is an example of correctly configured IPv4 addresses:• WAN IP addre

Strany 466

LAN Configuration96ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Modify the IP address or subnet mask, or both.3. Click Apply to save your sett

Strany 467

LAN Configuration97 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308• There is no need to reserve an IP address for a computer in the DHCP server. Al

Strany 468

LAN Configuration98ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308 The Known PCs and Devices table lists the entries in the network database. For ea

Strany 469

LAN Configuration99 ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX53082. Click the Add table button to add the computer or device to the Known PCs and

Komentáře k této Příručce

Žádné komentáře