Netgear SRX5308 User Manual

Browse online or download User Manual for Routers Netgear SRX5308. Netgear SRX5308 User's Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 460
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 1 - SSL VPN Firewall SRX5308

350 East Plumeria DriveSan Jose, CA 95134USAJuly, 2012202-10536-04v1.0ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Reference Manual

Page 2 - Revision History

10ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ to LAN Logs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43

Page 3

LAN Configuration100ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Enter the settings as explained in the following table. The IPv6 address poo

Page 4 - Contents

LAN Configuration101 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your changes.IPv6 LAN Address PoolsIf you configure a st

Page 5 - Chapter 3 LAN Configuration

LAN Configuration102ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 56. 2. Enter the settings as explained in the following table:3. Click

Page 6

LAN Configuration103 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6 LAN Prefixes for Prefix DelegationIf you configure a stateless DHCPv6 serve

Page 7

LAN Configuration104ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure the IPv6 Router Advertisement Daemon and Advertisement Prefixes for th

Page 8 - Chapter 10 Troubleshooting

LAN Configuration105 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To configure the Router Advertisement Daemon for the LAN:1. Select Network Co

Page 9

LAN Configuration106ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your changes.Advertisement Prefixes for the LANYou need

Page 10

LAN Configuration107 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 59. 2. Enter the settings as explained in the following table:3. Click

Page 11 - Introduction

LAN Configuration108ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings. To delete one or more advertisement pref

Page 12 - Key Features and Capabilities

LAN Configuration109 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. In the Add Secondary LAN IP Address section of the screen, enter the followi

Page 13

1111. IntroductionThis chapter provides an overview of the features and capabilities of the ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 and ex

Page 14 - Security Features

LAN Configuration110ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 By default, the DMZ port and both inbound and outbound DMZ traffic are disabled.

Page 15 - Extensive Protocol Support

LAN Configuration111 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 61. 2. Enter the settings as explained in the following table: Table 22

Page 16 - Package Contents

LAN Configuration112ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 DHCP for DMZ Connected ComputersDisable DHCP Server If another device on your ne

Page 17 - Hardware Features

LAN Configuration113 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.DMZ Port for IPv6 TrafficThe DMZ Setup (IP

Page 18 - Table 1. LED descriptions

LAN Configuration114ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 • Stateful DHCPv6 server. The IPv6 clients in the DMZ obtain an interface IP add

Page 19 - Rear Panel

LAN Configuration115 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Enter the settings as explained in the following table: Table 23. DMZ Setup

Page 20 - Use the Rack-Mounting Kit

LAN Configuration116ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings.IPv6 DMZ Address PoolsIf you configure a s

Page 21 - Log In to the VPN Firewall

LAN Configuration117 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as explained in the following table:3. Click Apply to sa

Page 22 - Figure 6

LAN Configuration118ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Hosts and routers in the LAN use NDP to determine the link-layer addresses and r

Page 23

LAN Configuration119 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 64. 4. Enter the settings as explained in the following table:Table 26.

Page 24 - Figure 9

Introduction12ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 The VPN firewall is a security solution that protects your network from attacks and in

Page 25

LAN Configuration120ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your changes.Advertisement Prefixes for the DMZYou need

Page 26

LAN Configuration121 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 65. 2. Enter the settings as explained in the following table:3. Click

Page 27 -  Complete these tasks:

LAN Configuration122ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings. To delete one or more advertisement pref

Page 28 - Configure the IPv4 WAN Mode

LAN Configuration123 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 66. 2. Click the Add table button under the Static Routes table. The Ad

Page 29 - Classical Routing

LAN Configuration124ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The new static route is added to the Stat

Page 30 - Figure 11

LAN Configuration125 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 68. 3. Enter the settings as explained in the following table: Table 29

Page 31 - Figure 12

LAN Configuration126ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings.RIP Version By default, the RIP version is

Page 32

LAN Configuration127 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308IPv4 Static Route ExampleIn this example, we assume the following:• The VPN fire

Page 33 - Figure 14

LAN Configuration128ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 69. 3. Click the Add table button under the Static Routes table. The Ad

Page 34 - Figure 15

LAN Configuration129 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The new static route is added to the List

Page 35 - Figure 16

Introduction13 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308• One console port for local management.• SNMP support with SNMPv1, SNMPv2c, and SNMPv

Page 36 - Figure 17

13044. Firewall ProtectionThis chapter describes how to use the firewall features of the VPN firewall to protect your network. The chapter contains

Page 37 - Figure 18

Firewall Protection131 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308incoming packet is in response to an outgoing request, but true stateful packe

Page 38 - Figure 19

Firewall Protection132ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 A firewall has two default rules, one for inbound traffic and one for outbound

Page 39

Firewall Protection133 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Outbound Rules (Service Blocking)The VPN firewall allows you to block the use

Page 40 - Figure 20

Firewall Protection134ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 LAN Users The settings that determine which computers on your network are affe

Page 41 - Figure 21

Firewall Protection135 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Inbound Rules (Port Forwarding)If you have enabled Network Address Translation

Page 42 - Figure 22

Firewall Protection136ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Whether or not DHCP is enabled, how the computer accesses the server’s LAN add

Page 43 -  To edit a protocol binding:

Firewall Protection137 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Table 33. Inbound rules overview Setting Description Inbound RulesService Th

Page 44 - Figure 23

Firewall Protection138ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 LAN Users These settings apply to a LAN WAN inbound rule when the WAN mode is

Page 45

Firewall Protection139 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Note: Some residential broadband ISP accounts do not allow you to run any ser

Page 46

Introduction14ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 - Allows browser-based, platform-independent remote access through a number of popular

Page 47

Firewall Protection140ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 71. For any traffic attempting to pass through the firewall, the packet

Page 48 - Configure Dynamic DNS

Firewall Protection141 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 72. 2. From the Default Outbound Policy drop-down list, select Block

Page 49 -  To configure DDNS:

Firewall Protection142ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 73. 3. From the Default Outbound Policy drop-down list, select Block

Page 50 - Figure 26

Firewall Protection143 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Create LAN WAN Outbound Service RulesYou can define rules that specify excepti

Page 51

Firewall Protection144ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Unless your selection from the Action drop-down list is BLOCK always, you also

Page 52

Firewall Protection145 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Create LAN WAN Inbound Service RulesThe Inbound Services table lists all exist

Page 53 - Figure 27

Firewall Protection146ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Enter the settings as explained in Table 33 on page 137. In addition to se

Page 54 - Connection

Firewall Protection147 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Enter the settings as explained in Table 33 on page 137. In addition to se

Page 55 - Figure 29

Firewall Protection148ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 78. To change an existing outbound or inbound service rule, in the Acti

Page 56 - Figure 30

Firewall Protection149 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 79. To change an existing outbound or inbound service rule, in the Act

Page 57 - Figure 31

Introduction15 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308network, a 1000-Mbps Gigabit Ethernet network, or a combination of these networks. All

Page 58 - Figure 32

Firewall Protection150ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 IPv4 DMZ WAN Outbound Service Rules To create a new IPv4 DMZ WAN outbound rul

Page 59 - Figure 33

Firewall Protection151 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6 DMZ WAN Outbound Service Rules To create a new IPv6 DMZ WAN outbound rul

Page 60 - Figure 34

Firewall Protection152ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 IPv4 DMZ WAN Inbound Service Rules To create a new IPv4 DMZ WAN inbound rule:

Page 61 - Figure 35

Firewall Protection153 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6 DMZ WAN Inbound Service Rules To create a new IPv6 DMZ WAN inbound rule:

Page 62

Firewall Protection154ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 There is no drop-down list that lets you set the default outbound policy as th

Page 63

Firewall Protection155 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 85. To change an existing outbound or inbound service rule, in the Act

Page 64 - Figure 36

Firewall Protection156ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 IPv4 LAN DMZ Outbound Service Rules To create a new IPv4 LAN DMZ outbound rul

Page 65 - Figure 38

Firewall Protection157 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 87. 3. Enter the settings as explained in Table 32 on page 133. In ad

Page 66 - Figure 39

Firewall Protection158ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 88. 2. Enter the settings as explained in Table 33 on page 137. In ad

Page 67 - Figure 40

Firewall Protection159 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 89. 3. Enter the settings as explained in Table 33 on page 137. In ad

Page 68 - Figure 42

Introduction16ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 • Auto-detection of ISP. The VPN firewall automatically senses the type of Internet co

Page 69 - Figure 43

Firewall Protection160ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 90. IPv4 LAN WAN Inbound Rule: Allow a Videoconference from Restricted

Page 70

Firewall Protection161 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 91. IPv4 LAN WAN or IPv4 DMZ WAN Inbound Rule: Set Up One-to-One NAT Ma

Page 71 - SMTP might restart

Firewall Protection162ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: If you arrange with your ISP to have more than one public IP address for

Page 72 - Configure WAN QoS Profiles

Firewall Protection163 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308this address on the WAN2 Secondary Addresses screen (see Configure Secondary W

Page 73 - Figure 44

Firewall Protection164ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:For security, NETGEAR strongly recommends that you avoid creating an e

Page 74 - Figure 45

Firewall Protection165 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 95. IPv6 DMZ WAN Outbound Rule: Allow a Group of DMZ User to Access an

Page 75

Firewall Protection166ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure Other Firewall Features• Attack Checks• Set Limits for IPv4 Sessions

Page 76 - Figure 46

Firewall Protection167 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as explained in the following table:Table 34. Attack C

Page 77

Firewall Protection168ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.IPv6 Attack Checks To enable IPv6 attac

Page 78 - What to Do Next

Firewall Protection169 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308address. A ping can be used as a diagnostic tool. Keep this check box cleared

Page 79

Introduction17 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Hardware Features• Front Panel• Rear Panel• Bottom Panel with Product LabelThe front p

Page 80 - Port-Based VLANs

Firewall Protection170ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Enter the settings as explained in the following table:4. Click Apply to

Page 81 - Figure 47

Firewall Protection171 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Manage the Application Level Gateway for SIP SessionsThe application level gat

Page 82 - VLAN DHCP Options

Firewall Protection172ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: A schedule narrows down the period during which a firewall rule is appl

Page 83 - Configure a VLAN Profile

Firewall Protection173 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 101. 2. In the Add Customer Service section of the screen, enter the

Page 84 - Figure 49

Firewall Protection174ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 102. 2. Modify the settings that you wish to change (see the previous

Page 85

Firewall Protection175 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53082. In the Add New Custom IP Group section of the screen, do the following:•

Page 86

Firewall Protection176ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To delete an IP group:1. In the Custom IP Groups table, select the check bo

Page 87

Firewall Protection177 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 105. 2. Under the List of Bandwidth Profiles table, click the Add tab

Page 88 -  To edit a VLAN profile:

Firewall Protection178ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The new bandwidth profile is added to t

Page 89

Firewall Protection179 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Create Quality of Service Profiles for IPv4 Firewall RulesA Quality of Service

Page 90 - Figure 51

Introduction18ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Table 1. LED descriptions LED Activity DescriptionPower On (green) Power is supplied

Page 91

Firewall Protection180ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 108. 3. Enter the settings as explained in the following table.4. Cl

Page 92 - Manage the Network Database

Firewall Protection181 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To edit a QoS profile:1. In the List of QoS Profiles table, click the Edit

Page 93 - Figure 52

Firewall Protection182ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Several types of blocking are available:• Web component blocking. You can bloc

Page 94

Firewall Protection183 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308• If the keyword “.com” is specified, only websites with other domain suffixes

Page 95 - Figure 53

Firewall Protection184ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. In the Web Components section of the screen, select the components that yo

Page 96 - Figure 54

Firewall Protection185 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Set a Schedule to Block or Allow Specific TrafficSchedules define the time fra

Page 97 - Manage the IPv6 LAN

Firewall Protection186ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Enable Source MAC FilteringThe Source MAC Filter screen enables you to permit

Page 98 - DHCPv6 Server Options

Firewall Protection187 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The MAC Address field in the Add Source

Page 99 - Configure the IPv6 LAN

Firewall Protection188ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 There are three possible scenarios in relation to the addresses in the IP/MAC

Page 100 - LAN Configuration

Firewall Protection189 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your changes. 4. In the IP/MAC Bindings sections of t

Page 101 - IPv6 LAN Address Pools

Introduction19 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Rear PanelThe rear panel of the VPN firewall includes a console port, a Factory Defaul

Page 102 - Figure 56

Firewall Protection190ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Click the Stop button. Wait until the Poll Interval field becomes availabl

Page 103 -  To edit a prefix:

Firewall Protection191 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. In the IP/MAC Bindings sections of the screen, enter the settings as expla

Page 104

Firewall Protection192ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click the Set Interval button. Wait for the confirmation that the operatio

Page 105 - Figure 58

Firewall Protection193 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 116. 2. In the Add Port Triggering Rule section, enter the settings a

Page 106

Firewall Protection194ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To remove one or more port triggering rules from the table:1. Select the ch

Page 107 - Figure 59

Firewall Protection195 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The UPnP Portmap Table in the lower part of the screen shows the IP addresses

Page 108 - Default VLAN

19655. Virtual Private Networking Using IPSec and L2TP ConnectionsThis chapter describes how to use the IP security (IPSec) virtual private networki

Page 109

Virtual Private Networking Using IPSec and L2TP Connections197 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The following diagrams and table show

Page 110 - DMZ Port for IPv4 Traffic

Virtual Private Networking Using IPSec and L2TP Connections198ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Use the IPSec VPN Wizard for Client an

Page 111 - Figure 61

Virtual Private Networking Using IPSec and L2TP Connections199 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308following screen contains some example

Page 112

2ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 © 2010–2012 NETGEAR, Inc. All rights reserved.No part of this publication may be reproduced, trans

Page 113 - DMZ Port for IPv6 Traffic

Introduction20ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Choose a Location for the VPN FirewallThe VPN firewall is suitable for use in an offic

Page 114 - Figure 62

Virtual Private Networking Using IPSec and L2TP Connections200ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 123. 2. Complete the settings

Page 115

Virtual Private Networking Using IPSec and L2TP Connections201 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Tip: To ensure that tunnels stay acti

Page 116 - IPv6 DMZ Address Pools

Virtual Private Networking Using IPSec and L2TP Connections202ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 124. 4. Configure a VPN polic

Page 117

Virtual Private Networking Using IPSec and L2TP Connections203 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Create an IPv6 Gateway-to-Gateway VPN

Page 118

Virtual Private Networking Using IPSec and L2TP Connections204ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To view the wizard default settings, c

Page 119 - Figure 64

Virtual Private Networking Using IPSec and L2TP Connections205 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Tip: To ensure that tunnels stay acti

Page 120

Virtual Private Networking Using IPSec and L2TP Connections206ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Activate the IPSec VPN connection:

Page 121 - Figure 65

Virtual Private Networking Using IPSec and L2TP Connections207 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Use the VPN Wizard to Configure the Ga

Page 122 - Manage Static IPv4 Routing

Virtual Private Networking Using IPSec and L2TP Connections208ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.

Page 123 - Figure 67

Virtual Private Networking Using IPSec and L2TP Connections209 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 133. Note: When you are using

Page 124

Introduction21 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Log In to the VPN FirewallNote: To connect the VPN firewall physically to your networ

Page 125 - Figure 68

Virtual Private Networking Using IPSec and L2TP Connections210ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Perform these tasks from a comp

Page 126

Virtual Private Networking Using IPSec and L2TP Connections211 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 135. 3. Select the A router o

Page 127 - Manage Static IPv6 Routing

Virtual Private Networking Using IPSec and L2TP Connections212ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 137. 6. This screen is a summ

Page 128 - Figure 70

Virtual Private Networking Using IPSec and L2TP Connections213 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308c. Specify the settings that are expl

Page 129

Virtual Private Networking Using IPSec and L2TP Connections214ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 139. b. Specify the default l

Page 130 - Firewall Protection

Virtual Private Networking Using IPSec and L2TP Connections215 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Configure the Authentication Settings

Page 131 - Administrator Tips

Virtual Private Networking Using IPSec and L2TP Connections216ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: This is the name for the authen

Page 132

Virtual Private Networking Using IPSec and L2TP Connections217 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to use the new setting

Page 133

Virtual Private Networking Using IPSec and L2TP Connections218ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 8. Click Apply to use the new setting

Page 134

Virtual Private Networking Using IPSec and L2TP Connections219 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 144. 3. Specify the settings

Page 135

Introduction22ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: The first time that you remotely connect to the VPN firewall with a browser thr

Page 136

Virtual Private Networking Using IPSec and L2TP Connections220ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to use the new setting

Page 137

Virtual Private Networking Using IPSec and L2TP Connections221 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Test the Connection and View Connectio

Page 138

Virtual Private Networking Using IPSec and L2TP Connections222ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 147. • Use the system-tray ico

Page 139 - Order of Precedence for Rules

Virtual Private Networking Using IPSec and L2TP Connections223 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308NETGEAR VPN Client Status and Log Info

Page 140 - Configure LAN WAN Rules

Virtual Private Networking Using IPSec and L2TP Connections224ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 interval period, enter a new value in

Page 141 - Figure 72

Virtual Private Networking Using IPSec and L2TP Connections225 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Manage IPSec VPN Policies• Manage IKE

Page 142 - Figure 73

Virtual Private Networking Using IPSec and L2TP Connections226ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 examples.) To display the IPv6 setting

Page 143 - IPv4 LAN WAN Outbound Rules

Virtual Private Networking Using IPSec and L2TP Connections227 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Note: You cannot delete or edit an IK

Page 144 - IPv6 LAN WAN Outbound Rules

Virtual Private Networking Using IPSec and L2TP Connections228ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Complete the settings as explained

Page 145 - Figure 76

Virtual Private Networking Using IPSec and L2TP Connections229 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Identifier From the drop-down list, se

Page 146 - IPv6 LAN WAN Inbound Rules

Introduction23 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Web Management Interface Menu LayoutThe following figure shows the menu at the top the

Page 147 - Configure DMZ WAN Rules

Virtual Private Networking Using IPSec and L2TP Connections230ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Authentication Method Select one of th

Page 148 - Figure 78

Virtual Private Networking Using IPSec and L2TP Connections231 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings.

Page 149 - Figure 79

Virtual Private Networking Using IPSec and L2TP Connections232ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 endpoints (the local ID endpoint and t

Page 150 - Figure 80

Virtual Private Networking Using IPSec and L2TP Connections233 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Each policy contains the data that are

Page 151 - Figure 81

Virtual Private Networking Using IPSec and L2TP Connections234ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Specify the IP version for which y

Page 152 - Figure 82

Virtual Private Networking Using IPSec and L2TP Connections235 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 158. Add New VPN Policy screen

Page 153 - Configure LAN DMZ Rules

Virtual Private Networking Using IPSec and L2TP Connections236ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Policy Type From the drop-down list, s

Page 154 - Figure 84

Virtual Private Networking Using IPSec and L2TP Connections237 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Traffic SelectionLocal IP From the dro

Page 155 - Figure 85

Virtual Private Networking Using IPSec and L2TP Connections238ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Key-Out The encryption key for the out

Page 156 - Figure 86

Virtual Private Networking Using IPSec and L2TP Connections239 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings.

Page 157 - Figure 87

Introduction24ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 - The IPv6 button is operational but the IPv4 button is disabled. You can configure

Page 158 - Figure 88

Virtual Private Networking Using IPSec and L2TP Connections240ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 requesting individual authentication i

Page 159 - Examples of Firewall Rules

Virtual Private Networking Using IPSec and L2TP Connections241 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. In the Extended Authentication sec

Page 160 - Addresses

Virtual Private Networking Using IPSec and L2TP Connections242ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 user name and password information. Th

Page 161 - Figure 91

Virtual Private Networking Using IPSec and L2TP Connections243 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.

Page 162 - Figure 92

Virtual Private Networking Using IPSec and L2TP Connections244ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Assign IPv4 Addresses to Remote Users

Page 163 - Figure 93

Virtual Private Networking Using IPSec and L2TP Connections245 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To configure Mode Config on the VPN

Page 164 - Single LAN User

Virtual Private Networking Using IPSec and L2TP Connections246ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Complete the settings as explained

Page 165 - Site on the Internet

Virtual Private Networking Using IPSec and L2TP Connections247 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.

Page 166 - Attack Checks

Virtual Private Networking Using IPSec and L2TP Connections248ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 162. 8. On the Add IKE Policy

Page 167

Virtual Private Networking Using IPSec and L2TP Connections249 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Table 59. Add IKE Policy screen setti

Page 168 - IPv6 Attack Checks

Introduction25 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Requirements for Entering IP AddressesTo connect to the VPN firewall, your computer ne

Page 169 - Set Limits for IPv4 Sessions

Virtual Private Networking Using IPSec and L2TP Connections250ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 IKE SA ParametersNote: Generally, the

Page 170 - to save your settings

Virtual Private Networking Using IPSec and L2TP Connections251 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53089. Click Apply to save your settings.

Page 171 - Figure 100

Virtual Private Networking Using IPSec and L2TP Connections252ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: Perform these tasks from a comp

Page 172 - Add Customized Services

Virtual Private Networking Using IPSec and L2TP Connections253 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Change the name of the authenticat

Page 173 -  To edit a service:

Virtual Private Networking Using IPSec and L2TP Connections254ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to use the new setting

Page 174 - Create IP Groups

Virtual Private Networking Using IPSec and L2TP Connections255 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53088. Click Apply to use the new setting

Page 175 -  To edit an IP group:

Virtual Private Networking Using IPSec and L2TP Connections256ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 167. 3. Specify the settings

Page 176 - Create Bandwidth Profiles

Virtual Private Networking Using IPSec and L2TP Connections257 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to use the new setting

Page 177 - Profile screen displays:

Virtual Private Networking Using IPSec and L2TP Connections258ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 2. Specify the following default life

Page 178

Virtual Private Networking Using IPSec and L2TP Connections259 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 171. 3. From the client compu

Page 179 - Figure 107

2622. IPv4 and IPv6 Internet and WAN SettingsThis chapter explains how to configure the IPv4 and IPv6 Internet and WAN settings. The chapter contain

Page 180 - 4. Click Appl

Virtual Private Networking Using IPSec and L2TP Connections260ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 For DPD to function, the peer VPN devi

Page 181 - Configure Content Filtering

Virtual Private Networking Using IPSec and L2TP Connections261 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Enter the settings as explained in

Page 182

Virtual Private Networking Using IPSec and L2TP Connections262ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 173. 4. In the IKE SA Paramet

Page 183 - Figure 109

Virtual Private Networking Using IPSec and L2TP Connections263 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53082. Specify the IP version for which y

Page 184

Virtual Private Networking Using IPSec and L2TP Connections264ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To enable the PPTP server and config

Page 185 - Figure 110

Virtual Private Networking Using IPSec and L2TP Connections265 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The List of PPTP Active Users table li

Page 186 - Enable Source MAC Filtering

Virtual Private Networking Using IPSec and L2TP Connections266ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 177. 2. Enter the settings as

Page 187 - Set Up IP/MAC Bindings

Virtual Private Networking Using IPSec and L2TP Connections267 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The List of L2TP Active Users table li

Page 188 - IPv4/MAC Bindings

26866. Virtual Private Networking Using SSL ConnectionsThe VPN firewall provides a hardware-based SSL VPN solution designed specifically to provide

Page 189 - Figure 113

Virtual Private Networking Using SSL Connections269 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The SSL VPN client provides a point-to-point (PPP

Page 190 - IPv6/MAC Bindings

IPv4 and IPv6 Internet and WAN Settings27 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Tasks to Set Up IPv4 Internet Connections to Your ISPs Com

Page 191 - Figure 115

Virtual Private Networking Using SSL Connections270ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Because you need to assign a group when creating

Page 192 - Configure Port Triggering

Virtual Private Networking Using SSL Connections271 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308You can define individual layouts for the SSL VPN

Page 193 - Figure 116

Virtual Private Networking Using SSL Connections272ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 • Portal URL:- Portal URL (IPv4). The IPv4 URL at

Page 194 - Figure 118

Virtual Private Networking Using SSL Connections273 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Complete the settings as explained in the fol

Page 195

Virtual Private Networking Using SSL Connections274ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your settings. The new po

Page 196 - Virtual Private Networking

Virtual Private Networking Using SSL Connections275 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308access policies. When you create a group, you nee

Page 197

Virtual Private Networking Using SSL Connections276ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the Add New Application for Port Forwardin

Page 198 - Configurations

Virtual Private Networking Using SSL Connections277 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To add servers and host names for client name r

Page 199 - Figure 122

Virtual Private Networking Using SSL Connections278ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 • Select whether you want to enable full-tunnel o

Page 200 - Figure 123

Virtual Private Networking Using SSL Connections279 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 184. SSL VPN Client screen for IPv63. Co

Page 201

IPv4 and IPv6 Internet and WAN Settings28ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Configure the IPv6 tunnels. Enable 6to4 tunnels and con

Page 202 - Figure 125

Virtual Private Networking Using SSL Connections280ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. VPN tunnel

Page 203 - Figure 127

Virtual Private Networking Using SSL Connections281 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308If VPN tunnel clients are already connected, disc

Page 204 - Figure 128

Virtual Private Networking Using SSL Connections282ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 185. 2. In the Add New Resource section

Page 205 - Figure 129

Virtual Private Networking Using SSL Connections283 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6, this screen is identical to the screen for

Page 206 - Figure 131

Virtual Private Networking Using SSL Connections284ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 5. Click Apply to save your settings. The new co

Page 207 - Figure 132

Virtual Private Networking Using SSL Connections285 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Assuming that no conflicting user or group polici

Page 208

Virtual Private Networking Using SSL Connections286ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click the Display action button. The List of

Page 209 - Figure 133

Virtual Private Networking Using SSL Connections287 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308.Figure 189. Add SSL VPN Policy screen for IPv64

Page 210 - Figure 134

Virtual Private Networking Using SSL Connections288ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Apply Policy to? (continued)IP Address Policy Nam

Page 211 - Figure 136

Virtual Private Networking Using SSL Connections289 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The policy

Page 212 - Figure 138

IPv4 and IPv6 Internet and WAN Settings29 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Note the following about NAT:• The VPN firewall uses NAT to

Page 213

Virtual Private Networking Using SSL Connections290ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Access the New SSL Portal Login ScreenAll screens

Page 214 - Figure 139

Virtual Private Networking Using SSL Connections291 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 192. 4. Enter a user name and password t

Page 215 - Figure 141

Virtual Private Networking Using SSL Connections292ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 194. The User Portal screen displays a si

Page 216 - Figure 142

Virtual Private Networking Using SSL Connections293 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 195. The active user’s name, group, and IP

Page 217 - 6. Click the Advan

29477. Manage Users, Authentication, and VPN CertificatesThis chapter describes how to manage users, authentication, and security certificates for I

Page 218

Manage Users, Authentication, and VPN Certificates295 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Except in the case of IPSec VPN users, when you

Page 219 - Figure 144

Manage Users, Authentication, and VPN Certificates296ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure Authentication Domains, Groups, and U

Page 220 - Figure 145

Manage Users, Authentication, and VPN Certificates297 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The List of Domains table displays the domains

Page 221 - Information

Manage Users, Authentication, and VPN Certificates298ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Authentication Type (continued)Note: If you se

Page 222 - Figure 150

Manage Users, Authentication, and VPN Certificates299 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The doma

Page 223 - Figure 152

3ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 202-10536-02 1.0 July 2011 Added new features that are documented in the following sections:• Confi

Page 224 - To display the IPSec VPN log:

IPv4 and IPv6 Internet and WAN Settings30ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the NAT (Network Address Translation) section of the

Page 225 - Manage IPSec VPN Policies

Manage Users, Authentication, and VPN Certificates300ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Edit Domains To edit a domain:1. Select Users

Page 226 - Figure 154

Manage Users, Authentication, and VPN Certificates301 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Create Groups To create a VPN group:1. Select

Page 227 - Figure 155

Manage Users, Authentication, and VPN Certificates302ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Complete the settings as explained in the f

Page 228

Manage Users, Authentication, and VPN Certificates303 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Configure User AccountsWhen you create a user a

Page 229

Manage Users, Authentication, and VPN Certificates304ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 201. The List of Users table displays t

Page 230

Manage Users, Authentication, and VPN Certificates305 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Enter the settings as explained in the foll

Page 231 - Manage VPN Policies

Manage Users, Authentication, and VPN Certificates306ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Set User Login PoliciesYou can restrict the abi

Page 232 - VPN Policies Screen

Manage Users, Authentication, and VPN Certificates307 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Login Restrictions Based on IPv4 Addr

Page 233

Manage Users, Authentication, and VPN Certificates308ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 6. In the Add Defined Addresses section of the

Page 234

Manage Users, Authentication, and VPN Certificates309 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 205. 5. In the Defined Addresses Statu

Page 235

IPv4 and IPv6 Internet and WAN Settings31 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308You can set the failure detection method for each WAN inter

Page 236

Manage Users, Authentication, and VPN Certificates310ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To delete one or more IPv6 addresses:1. In t

Page 237

Manage Users, Authentication, and VPN Certificates311 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53086. In the Add Defined Browser section of the s

Page 238

Manage Users, Authentication, and VPN Certificates312ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To modify user settings, including passwords:

Page 239 -  To edit a VPN policy:

Manage Users, Authentication, and VPN Certificates313 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.Manage Di

Page 240

Manage Users, Authentication, and VPN Certificates314ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 both the IPSec VPN certificate repository and t

Page 241 - User Database Configuration

Manage Users, Authentication, and VPN Certificates315 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308• Self Certificate Requests table. Contains the

Page 242 - Figure 159

Manage Users, Authentication, and VPN Certificates316ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 2. In the Upload Trusted Certificates section

Page 243

Manage Users, Authentication, and VPN Certificates317 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308VPN firewall. The CSR is a file that contains i

Page 244 - Mode Config Operation

Manage Users, Authentication, and VPN Certificates318ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click the Generate table button. A new SCR

Page 245 - Figure 161

Manage Users, Authentication, and VPN Certificates319 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53086. Submit your SCR to a CA:a. Connect to the w

Page 246

IPv4 and IPv6 Internet and WAN Settings32ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 • If the autodetect process senses a connection method that

Page 247

Manage Users, Authentication, and VPN Certificates320ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Manage the VPN Certificate Revocation ListA Cer

Page 248 - Table 53 on page 228

32188. Network and System ManagementThis chapter describes the tools for managing the network traffic to optimize its performance and the system man

Page 249

Network and System Management322ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 In practice, the WAN-side bandwidth capacity is much lower when DSL

Page 250

Network and System Management323 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The following section summarizes the various criteria that you can a

Page 251

Network and System Management324ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 For information about how to define bandwidth profiles, see Create B

Page 252 - Figure 164

Network and System Management325 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308ON the LAN WAN screen, if you have not defined any rules, only the d

Page 253 - Figure 165

Network and System Management326ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 addresses to groups. For more information, see Create IP Groups on p

Page 254 - 6. Click the

Network and System Management327 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Exposed HostsSpecifying an exposed host allows you to set up a compu

Page 255

Network and System Management328ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 method for allocating and limiting traffic, thus allocating LAN user

Page 256 - Figure 167

Network and System Management329 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 213. 2. In the Action column of the List of Users table, cl

Page 257 - Figure 168

IPv4 and IPv6 Internet and WAN Settings33 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 13. The Connection Status screen should show a vali

Page 258 - Figure 170

Network and System Management330ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your settings.7. Repeat Step 1 through Step

Page 259 - Figure 171

Network and System Management331 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308misuse it in many ways, NETGEAR highly recommends that you change th

Page 260 - Configure Keep-Alives

Network and System Management332ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 216. Remote Management screen for IPv63. Enter the settings

Page 261 - Configure Dead Peer Detection

Network and System Management333 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308WARNING:If you are remotely connected to the VPN firewall and you se

Page 262 - Figure 173

Network and System Management334ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Tip: If you are using a Dynamic DNS service such as TZO, you can id

Page 263 - Configure the PPTP Server

Network and System Management335 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To configure the SNMP settings:1. Select Administration > SNMP

Page 264 - View the Active PPTP Users

Network and System Management336ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 2. To specify a new SNMP configuration, in the Create New SNMP Conf

Page 265 - Configure the L2TP Server

Network and System Management337 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To delete one or more SNMP configurations:1. On the SNMP screen (

Page 266 - View the Active L2TP Users

Network and System Management338ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your changes. To configure the SNMP system

Page 267

Network and System Management339 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Manage the Configuration FileThe configuration settings of the VPN f

Page 268 - Using SSL Connections

IPv4 and IPv6 Internet and WAN Settings34ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 The IPv4 WAN Settings table displays the following fields:•

Page 269

Network and System Management340ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Back Up SettingsThe backup feature saves all VPN firewall settings t

Page 270 - Create the Portal Layout

Network and System Management341 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308WARNING:Once you start restoring settings, do not interrupt the proc

Page 271

Network and System Management342ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Upgrade the FirmwareYou can install a different version of the VPN f

Page 272 - Figure 181

Network and System Management343 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Select the Firmware and Reboot the VPN FirewallAfter you have upgrad

Page 273

Network and System Management344ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To set time, date, and NTP servers:1. Select Administration >

Page 274 -  To edit a portal layout:

Network and System Management345 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Select NTP Mode In all three NTP modes, the VPN firewall functions b

Page 275 - Add Servers and Port Numbers

Network and System Management346ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 3. Click Apply to save your settings.Note: If you select the defau

Page 276 - Add a New Host Name

34799. Monitor System Access and PerformanceThis chapter describes the system-monitoring features of the VPN firewall. You can be alerted to importa

Page 277 - Configure the SSL VPN Client

Monitor System Access and Performance348ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 223. 2. Enter the settings for the WAN1 interface a

Page 278

Monitor System Access and Performance349 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.4. If you want to ena

Page 279

IPv4 and IPv6 Internet and WAN Settings35 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 16. 6. If your connection is PPTP or PPPoE, your I

Page 280

Monitor System Access and Performance350ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 screen displays the traffic meter’s start and end dates. If

Page 281 - Add New Network Resources

Monitor System Access and Performance351 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Click the LAN Traffic Meter tab. The LAN Traffic Meter s

Page 282 -  To edit network resources:

Monitor System Access and Performance352ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your settings. The new account is ad

Page 283 - Figure 186

Monitor System Access and Performance353 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 228. To edit a LAN traffic meter account:1. In the

Page 284

Monitor System Access and Performance354ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 229.

Page 285 - View Policies

Monitor System Access and Performance355 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53082. Enter the settings as explained in the following table:T

Page 286 -  To add an SSL VPN policy:

Monitor System Access and Performance356ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Enable E-mail LogsDo you want logs to be emailed to you?Sele

Page 287

Monitor System Access and Performance357 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Click Apply to save your settings.Note: Enabling routin

Page 288

Monitor System Access and Performance358ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 230. You can refresh the logs, clear the logs, or se

Page 289 -  To edit an SSL VPN policy:

Monitor System Access and Performance359 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308How to Send Syslogs over a VPN Tunnel between Sites To send

Page 290

IPv4 and IPv6 Internet and WAN Settings36ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 7. In the Internet (IP) Address section of the screen (see

Page 291 - Figure 193

Monitor System Access and Performance360ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. In the Traffic Selector section of the screen, make the

Page 292 - Figure 194

Monitor System Access and Performance361 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308View Status Screens• View the System Status• View the VPN Co

Page 293 - Figure 196

Monitor System Access and Performance362ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Router Status Screen To view the Router Status screen:Selec

Page 294 - VPN Certificates

Monitor System Access and Performance363 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308LAN (VLAN) IPv4 InformationFor each of the four LAN ports, t

Page 295 - VPN firewall

Monitor System Access and Performance364ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Router Statistics Screen To view the Router Statistics scre

Page 296 - Configure Domains

Monitor System Access and Performance365 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Detailed Status ScreenTo view the Detailed Status screen, se

Page 297 - Figure 198

Monitor System Access and Performance366ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 The following table explains the fields of the Detailed Stat

Page 298

Monitor System Access and Performance367 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ IPv6 ConfigurationIPv6 Address The IPv6 address and pref

Page 299

Monitor System Access and Performance368ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 VLAN Status ScreenThe VLAN Status screen displays informatio

Page 300 - Configure Groups

Monitor System Access and Performance369 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The following table explains the fields of the VLAN Status s

Page 301 - Create Groups

IPv4 and IPv6 Internet and WAN Settings37 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53088. In the Domain Name Server (DNS) Servers section of the

Page 302 - Edit Groups

Monitor System Access and Performance370ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 The IPv6 Tunnel Status table shows the following fields:• Tu

Page 303 - Configure User Accounts

Monitor System Access and Performance371 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 238. The active user’s user name, group, and IP addre

Page 304 - Figure 202

Monitor System Access and Performance372ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 240. The List of PPTP Active Users table lists each a

Page 305

Monitor System Access and Performance373 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To display the SSL VPN log:Select Monitoring > VPN Logs

Page 306 - Set User Login Policies

Monitor System Access and Performance374ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 244. The Port Triggering Status screen displays the

Page 307 - Figure 204

Monitor System Access and Performance375 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 245. 2. In the Action column, click the Status butt

Page 308

Monitor System Access and Performance376ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Click Disconnect to disconnect the connection; click Connect

Page 309 - Figure 205

Monitor System Access and Performance377 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 248. The type of connection determines the informati

Page 310 - Figure 206

Monitor System Access and Performance378ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 View the Attached Devices To view the attached devices on t

Page 311

Monitor System Access and Performance379 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Note: If the VPN firewall is rebooted, the data in the Know

Page 312 - Figure 207

IPv4 and IPv6 Internet and WAN Settings38ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 9. Click Apply to save your changes.10. Click Test to eval

Page 313

Monitor System Access and Performance380ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Diagnostics Utilities• Send a Ping Packet• Trace a Route• Lo

Page 314 - VPN Certificates Screen

Monitor System Access and Performance381 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 252. The various tasks that you can perform on the D

Page 315 - Manage VPN CA Certificates

Monitor System Access and Performance382ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To send a traceroute:1. On the Diagnostics screen for IPv

Page 316 - Figure 209

Monitor System Access and Performance383 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 253. 2. From the Select Network drop-down list, sel

Page 317

3841010. TroubleshootingThis chapter provides troubleshooting tips and information for the VPN firewall. After each problem description, instruction

Page 318 - Figure 211

Troubleshooting385 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The VPN firewall’s diagnostic tools are explained in Diagnostics Utilities

Page 319 -  To delete one or more SCRs:

Troubleshooting386ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  If all LEDs are still on more than several minutes minute after power-up, do the

Page 320 -  To delete one or more CRLs:

Troubleshooting387 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308• Make sure that you are using the SSL https://address login rather than the http:

Page 321 - Network and System Management

Troubleshooting388ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Troubleshoot the ISP ConnectionIf your VPN firewall is unable to access the Intern

Page 322 - Features That Reduce Traffic

Troubleshooting389 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308assigned domain name or workgroup name in the Domain Name field, and you might hav

Page 323

IPv4 and IPv6 Internet and WAN Settings39 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Configure Load Balancing or Auto-RolloverThe VPN firewall c

Page 324 - Source MAC Filtering

Troubleshooting390ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 - Windows Server 2008 R2, all versions- Windows Server 2003, all versions- Windows

Page 325

Troubleshooting391 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308c. Click or double-click View status of this connection. The Local Area Connectio

Page 326 - DMZ Port

Troubleshooting392ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 f. Make sure that an IPv6 address shows. The previous figure does not show an IPv

Page 327 - Assign Bandwidth Profiles

Troubleshooting393 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Test the Path from Your Computer to a Remote DeviceAfter verifying that the LAN pa

Page 328 - System Management

Troubleshooting394ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 257. b. In the Backup / Restore Settings section of the screen, click the

Page 329 - Figure 214

Troubleshooting395 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Address Problems with Date and TimeThe System Date & Time screen displays the

Page 330

396AA. Default Settings and Technical SpecificationsThis appendix provides the default settings and the physical and technical specifications of the

Page 331

Default Settings and Technical Specifications397ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308WAN settingsWAN IPv4 mode (all WAN interfaces) NATWAN

Page 332

Default Settings and Technical Specifications398ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ DHCP IPv4 starting address 176.16.2.100DMZ DHCP I

Page 333 - About Remote Access

Default Settings and Technical Specifications399ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Session limits DisabledTCP time-out 1200 secondsUDP t

Page 334 -  To access the CLI:

4ContentsChapter 1 IntroductionWhat Is the ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308? . .11Key Features and Capabilities . . . . . . . . . .

Page 335 - Figure 217

IPv4 and IPv6 Internet and WAN Settings40ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Protocol binding addresses two issues:• Segregation of

Page 336 - Figure 218

Default Settings and Technical Specifications400ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Authentication method Pre-shared KeyKey group DH-Grou

Page 337 - Figure 219

Default Settings and Technical Specifications401ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308RADIUS settingsPrimary RADIUS server Disabled and non

Page 338 - Figure 220

Default Settings and Technical Specifications402ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Physical and Technical SpecificationsThe following ta

Page 339 - Manage the Configuration File

Default Settings and Technical Specifications403ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The following table shows the IPSec VPN specification

Page 340 - Restore Settings

404BB. Network Planning for Multiple WAN Ports (IPv4 Only)This appendix describes the factors to consider when planning a network using a firewall t

Page 341

Network Planning for Multiple WAN Ports (IPv4 Only)405 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308• Protocol binding.- For auto-rollover mode, p

Page 342 - Upgrade the Firmware

Network Planning for Multiple WAN Ports (IPv4 Only)406ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Cabling and Computer Hardware RequirementsFor

Page 343

Network Planning for Multiple WAN Ports (IPv4 Only)407 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308After you have located your Internet configura

Page 344 - Figure 222

Network Planning for Multiple WAN Ports (IPv4 Only)408ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Overview of the Planning ProcessThe areas that

Page 345

Network Planning for Multiple WAN Ports (IPv4 Only)409 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Features such as multiple exposed hosts are no

Page 346

IPv4 and IPv6 Internet and WAN Settings41 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308connection to the Internet could be made on the WAN3 interf

Page 347

Network Planning for Multiple WAN Ports (IPv4 Only)410ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 261. Inbound Traffic to a Dual WAN Port

Page 348 - Figure 223

Network Planning for Multiple WAN Ports (IPv4 Only)411 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 263. Virtual Private Networks• VPN Road

Page 349

Network Planning for Multiple WAN Ports (IPv4 Only)412ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 • Dual WAN ports in auto-rollover mode. A gate

Page 350 - Figure 225

Network Planning for Multiple WAN Ports (IPv4 Only)413 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Road Warrior: Single-Gateway WAN Port (Ref

Page 351 - Figure 227

Network Planning for Multiple WAN Ports (IPv4 Only)414ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 268. The purpose of the FQDN in this ca

Page 352

Network Planning for Multiple WAN Ports (IPv4 Only)415 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Gateway-to-GatewayThe following situations

Page 353 - Figure 228

Network Planning for Multiple WAN Ports (IPv4 Only)416ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 271. The IP addresses of the gateway WA

Page 354 - Figure 229

Network Planning for Multiple WAN Ports (IPv4 Only)417 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 273. The IP addresses of the gateway WA

Page 355

Network Planning for Multiple WAN Ports (IPv4 Only)418ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 The IP address of the gateway WAN port can be

Page 356

Network Planning for Multiple WAN Ports (IPv4 Only)419 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Telecommuter: Dual-Gateway WAN Ports for L

Page 357

IPv4 and IPv6 Internet and WAN Settings42ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 22. 4. Configure the protocol binding settings as

Page 358 - Figure 231

420CC. System Logs and Error MessagesThis appendix provides examples and explanations of system logs and error message. When applicable, a recommend

Page 359 - Configure Gateway 1 at Site 1

System Logs and Error Messages421ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308System Log Messages• NTP• Login/Logout• System Startup• Reboot• Fire

Page 360 - Configure Gateway 2 at Site 2

System Logs and Error Messages422ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Login/LogoutThis section describes logs generated by the administrat

Page 361 - View Status Screens

System Logs and Error Messages423ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308RebootThis section describes the log message generated during system

Page 362 - Router Status Screen

System Logs and Error Messages424ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308ICMP Redirect LogsMulticast/Broadcast LogsWAN StatusThis section des

Page 363

System Logs and Error Messages425ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Auto-RolloverWhen the WAN mode is configured for auto-rollover, the

Page 364 - Router Statistics Screen

System Logs and Error Messages426ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308PPP LogsThis section describes the WAN PPP connection logs. The PPP

Page 365 - Detailed Status Screen

System Logs and Error Messages427ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308• PPTP Idle Timeout LogsExplanation Message 1: PPPoE connection star

Page 366

System Logs and Error Messages428ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308• PPP Authentication LogsResolved DNS NamesThis section describes th

Page 367

System Logs and Error Messages429ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Table 121. System logs: IPSec VPN tunnel, tunnel establishment Mess

Page 368 - VLAN Status Screen

IPv4 and IPv6 Internet and WAN Settings43 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your settings. The protocol binding

Page 369 - Tunnel Status Screen

System Logs and Error Messages430ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Table 122. System logs: IPSec VPN tunnel, SA lifetime (150 sec in p

Page 370 - Figure 237

System Logs and Error Messages431ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Table 123. System logs: IPSec VPN tunnel, SA lifetime (150 sec in p

Page 371 - Figure 239

System Logs and Error Messages432ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Table 125. System logs: IPSec VPN tunnel, Dead Peer Detection and

Page 372 - View the VPN Logs

System Logs and Error Messages433ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308SSL VPN LogsThis section describes the log messages that are generat

Page 373 - Figure 243

System Logs and Error Messages434ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Traffic Meter LogsRouting Logs• LAN to WAN Logs• LAN to DMZ Logs• DM

Page 374 - View the WAN Port Status

System Logs and Error Messages435ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308LAN to WAN LogsLAN to DMZ LogsDMZ to WAN LogsWAN to LAN LogsTable 13

Page 375 - Figure 246

System Logs and Error Messages436ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308DMZ to LAN LogsWAN to DMZ LogsOther Event Logs• Session Limit Logs•

Page 376 - IPv6 WAN Port Status

System Logs and Error Messages437ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Source MAC Filter LogsBandwidth Limit LogsDHCP LogsThis section expl

Page 377 - Figure 248

System Logs and Error Messages438ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Table 142. DHCP logs Message 1 Message 2 Message 3 Message 4 Messag

Page 378 - View the Attached Devices

439DD. Two-Factor AuthenticationThis appendix provides an overview of two-factor authentication, and an example of how to implement the WiKID soluti

Page 379 - View the DHCP Log

IPv4 and IPv6 Internet and WAN Settings44ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure the Auto-Rollover Mode and Failure Detection Meth

Page 380 - Diagnostics Utilities

Two-Factor Authentication440ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308• Quick to deploy and manage. The WiKID solution integrates seamlessly wi

Page 381 - Trace a Route

Two-Factor Authentication441ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Here is an example of how WiKID works: To use WiKID (for end users):1.

Page 382 - Capture Packets in Real Time

Two-Factor Authentication442ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Proceed to the 2 Factor Authentication login screen, and enter the on

Page 383 -  To reboot the VPN firewall:

443EE. Notification of Compliance (Wired)NETGEAR Wired ProductsRegulatory Compliance InformationThis section includes user requirements for operatin

Page 384 - Troubleshooting

Notification of Compliance (Wired)444ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308FCC Radio Frequency Interference Warnings & InstructionsThis

Page 385 - Basic Functioning

Notification of Compliance (Wired)445ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Additional CopyrightsAES Copyright (c) 2001, Dr. Brian Gladman,

Page 386 - LAN or WAN Port LEDs Not On

Notification of Compliance (Wired)446ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308MD5 Copyright (C) 1990, RSA Data Security, Inc. All rights rese

Page 387

447IndexNumerics10BASE-T, 100BASE-T, and 1000BASE-T speeds 703322.org 48–516to4 tunnelsconfiguring globally 63DMZ, configuring for 121LAN, configuring

Page 388

448ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Bbacking up configuration file 340bandwidth allocation, WAN traffic 72–76bandwidth capacity 321ban

Page 389

449ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308firewall rules 132group, users 300idle time-out periodsgroups 302L2TP server 266PPTP server 264use

Page 390 - Figure 254

IPv4 and IPv6 Internet and WAN Settings45 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53082. In the Load Balancing Settings section of the screen, c

Page 391 - Figure 256

450ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Domain Name Server. See DNS.domain name, PPTP and PPPoE connections 35domains for authentication 2

Page 392

451ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Hhardwarefront panel ports 17rear panel components 19requirements 406Help button (web management i

Page 393

452ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308resources, configuring 283static or permanent 32, 37subnet mask, default 85subnet mask, DMZ port 1

Page 394 - Figure 257

453ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308bandwidth capacity 321default port MAC addresses 366default settings 398groups, assigning and mana

Page 395

454ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308metricstatic IPv4 routes 124static IPv6 routes 129MIAS (Microsoft Internet Authentication Service)

Page 396 - Specifications

455ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308WiKIDpass-through, multicast 168passwordschanging 311, 328default 22restoring 393Perfect Forward S

Page 397

456ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308LAN advertisements 107prefixes, IPv66to4 tunnel 63DMZ advertisements 121ISATAP tunnel 65LAN advert

Page 398

457ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308IPv6 (IPv4-only and IPv4/IPv6) 52routing tableadding static IPv4 routes 122adding static IPv6 rout

Page 399

458ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308stateless and stateful IPv6 addresses, autoconfiguration 54, 100, 115Stateless IP/ICMP Translation

Page 400

459ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308UUDP (User Datagram Protocol) 193UDP flood, blocking 167UDP time-out 170unicast packets, IPv6DMZ,

Page 401

IPv4 and IPv6 Internet and WAN Settings46ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: The default time to roll over after the primary WAN

Page 402

460ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308pre-shared keyclient-to-gateway tunnel 208gateway-to-gateway tunnel 200, 204IKE policy settings 23

Page 403

IPv4 and IPv6 Internet and WAN Settings47 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308After you have configured secondary WAN addresses, these ad

Page 404 - Ports (IPv4 Only)

IPv4 and IPv6 Internet and WAN Settings48ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 24. The List of Secondary WAN addresses table displ

Page 405

IPv4 and IPv6 Internet and WAN Settings49 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308domain, and restores DNS requests for the resulting fully q

Page 406

5ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Configure a Static IPv6 Internet Connection. . . . . . . . . . . . . . . . . . . . . .57Configure a

Page 407

IPv4 and IPv6 Internet and WAN Settings50ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 25. 3. Click the Information option arrow in the u

Page 408 - Figure 259

IPv4 and IPv6 Internet and WAN Settings51 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. Configure the DDNS service settings as explained in the

Page 409 - Inbound Traffic

IPv4 and IPv6 Internet and WAN Settings52ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Note: You can configure only one WAN interface for IPv6. T

Page 410 - Figure 262

IPv4 and IPv6 Internet and WAN Settings53 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308These are the options:• IPv4-only mode. The VPN firewall co

Page 411 - Virtual Private Networks

IPv4 and IPv6 Internet and WAN Settings54ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 WARNING:Changing the IP routing mode causes the VPN firewal

Page 412 - Figure 265

IPv4 and IPv6 Internet and WAN Settings55 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308The IPv6 WAN Settings table displays the following fields:•

Page 413 - Figure 267

IPv4 and IPv6 Internet and WAN Settings56ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 6. As an optional step: If you have selected the Stateless

Page 414 - Figure 269

IPv4 and IPv6 Internet and WAN Settings57 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Configure a Static IPv6 Internet ConnectionTo configure a s

Page 415 - VPN Gateway-to-Gateway

IPv4 and IPv6 Internet and WAN Settings58ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 32. 4. In the Internet Address section of the scre

Page 416 - Figure 272

IPv4 and IPv6 Internet and WAN Settings59 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53086. Click Apply to save your changes.7. Verify the connect

Page 417 - Figure 274

6ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Order of Precedence for Rules. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139Config

Page 418 - Figure 276

IPv4 and IPv6 Internet and WAN Settings60ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Configure a PPPoE IPv6 Internet ConnectionTo configure a PP

Page 419 - Figure 277

IPv4 and IPv6 Internet and WAN Settings61 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 35. 4. In the Internet Address section of the scre

Page 420

IPv4 and IPv6 Internet and WAN Settings62ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 6. Click Apply to save your changes.7. Verify the connect

Page 421 - 0.140254 sec

IPv4 and IPv6 Internet and WAN Settings63 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Note: If your ISP requires MAC authentication and another

Page 422 - System Startup

IPv4 and IPv6 Internet and WAN Settings64ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 36. 2. Select the Enable Automatic Tunneling check

Page 423 - IPSec Restart

IPv4 and IPv6 Internet and WAN Settings65 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To configure an ISATAP tunnel:1. Select Network Configur

Page 424 - WAN Status

IPv4 and IPv6 Internet and WAN Settings66ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit an ISATAP tunnel:1. On the ISATAP Tunnels screen

Page 425 - Auto-Rollover

IPv4 and IPv6 Internet and WAN Settings67 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308SIIT functions with IPv4-translated addresses, which are ad

Page 426 - PPP Logs

IPv4 and IPv6 Internet and WAN Settings68ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To configure advanced WAN options:1. Select Network Conf

Page 427 - • PPTP Idle Timeout Logs

IPv4 and IPv6 Internet and WAN Settings69 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Click the Advanced option arrow in the upper right of t

Page 428 - VPN Log Messages

7ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308User Database Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .241RADIUS

Page 429

IPv4 and IPv6 Internet and WAN Settings70ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 SpeedIn most cases, the VPN firewall can automatically dete

Page 430

IPv4 and IPv6 Internet and WAN Settings71 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53085. Click Apply to save your changes.WARNING:Depending on t

Page 431

IPv4 and IPv6 Internet and WAN Settings72ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 If you want to configure the advanced settings for an addit

Page 432

IPv4 and IPv6 Internet and WAN Settings73 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 44. 2. To enable QoS, select the Yes radio button.

Page 433 - SSL VPN Logs

IPv4 and IPv6 Internet and WAN Settings74ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 45. 3. Enter the settings as explained in the foll

Page 434 - Routing Logs

IPv4 and IPv6 Internet and WAN Settings75 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Congestion Priority From the drop-down list, select the pri

Page 435 - WAN to LAN Logs

IPv4 and IPv6 Internet and WAN Settings76ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 4. Click Apply to save your settings. The profile is added

Page 436 - Other Event Logs

IPv4 and IPv6 Internet and WAN Settings77 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings. The profile is added

Page 437 - DHCP Logs

IPv4 and IPv6 Internet and WAN Settings78ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit a QoS profile:1. In the List of QoS Profiles tab

Page 438 - Table 142. DHCP logs

7933. LAN ConfigurationThis chapter describes how to configure the LAN features of your VPN firewall. The chapter contains the following sections:•

Page 439 - Two-Factor Authentication

8ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308VPN Certificates Screen. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 314Ma

Page 440

LAN Configuration80ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 a single VLAN, they can share resources and bandwidth as if they were connected t

Page 441 - Figure 279

LAN Configuration81 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308packets. Untagged packets that enter these LAN ports are assigned to the default

Page 442 - Figure 280

LAN Configuration82ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 For each VLAN profile, the following fields display in the VLAN Profiles table: •

Page 443 - NETGEAR Wired Products

LAN Configuration83 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308DHCP RelayDHCP relay options allow you to make the VPN firewall a DHCP relay agen

Page 444

LAN Configuration84ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Figure 48. 2. Click the Add table button under the VLAN Profiles table. The Add

Page 445 - Additional Copyrights

LAN Configuration85 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53083. Enter the settings as explained in the following table: Table 15. Add VLAN P

Page 446

LAN Configuration86ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Enable DHCP Server Select the Enable DHCP Server radio button to enable the VPN f

Page 447 - Numerics

LAN Configuration87 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX53084. Click Apply to save your settings.Note: Once you have completed the LAN setu

Page 448

LAN Configuration88ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit a VLAN profile:1. On the LAN Setup screen for IPv4 (see Figure 48 on p

Page 449

LAN Configuration89 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 50. 3. From the MAC Address for VLANs drop-down list, select Unique. (Th

Page 450

9ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308When You Enter a URL or IP Address, a Time-Out Error Occurs . . . . . .387Troubleshoot the ISP Conne

Page 451

LAN Configuration90ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 The following is an example of correctly configured IPv4 addresses:• WAN IP addre

Page 452

LAN Configuration91 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 To edit a secondary LAN IP address:1. On the LAN Multi-homing screen for IPv4

Page 453

LAN Configuration92ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 These are some advantages of the network database:• Generally, you do not need to

Page 454

LAN Configuration93 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Figure 52. The Known PCs and Devices table lists the entries in the network datab

Page 455

LAN Configuration94ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Add Computers or Devices to the Network Database To add computers or devices man

Page 456

LAN Configuration95 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Edit Computers or Devices in the Network Database To edit computers or devices m

Page 457

LAN Configuration96ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308  To edit the name of one of the eight available groups:1. Select Network Config

Page 458

LAN Configuration97 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Note: The reserved address is not assigned until the next time the computer or d

Page 459

LAN Configuration98ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 DHCPv6 Server OptionsThe IPv6 clients in the LAN can autoconfigure their own IPv6

Page 460

LAN Configuration99 ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308Stateful DHCPv6 ServerThe IPv6 clients in the LAN obtain an interface IP address,

Comments to this Manuals

No comments