3 SET UP DEFAULT CONFIGURATION Basic Configuration using Web Interface ………………………………………… 13 Network Information ……………………………………………………………………… 15 Re-configure Workstation ……………………………………………………………… 16 Access the GB-1200 …………………………………………………………………… 16 Basic Configuration using GBAdmin ……………………………………………… 16 Network Information ……………………………………………………………………… 17 Re-configure Workstation ……………………………………………………………… 18 Access the GB-1200 …………………………………………………………………… 18...
1 – Introduction 1 1 Introduction GNAT Box Basics Global Technology Associates, Inc., has been designing and building Internet firewalls since 1994. In 1996, GTA developed the first truly affordable commercial-grade firewall, the GNAT Box . Since then, ICSA-certified ®...
GB-1200 Firewall Appliance Product Guide Registration To register, go to www.gta.com, click on Support and then the GTA Support Center link. If you already have an account, enter your user ID and password in the login screen; if not, click New Account, enter the profile information.
Upgrades Once registered, available upgrades can be found in the GTA Support Center. Free updates are available for the GB-1200 firewall appliance for three months after purchase. If the Action field in the Registered Products section indicates that there is an upgrade for your product, click on the Free Upgrade link.
GB-1200 Firewall Appliance Product Guide Additional Documentation For instructions on installation, registration and setup of a GTA Firewall in default configuration, see your GTA Firewall’s product guide; for optional features, see the appropriate Feature Guide. User’s Guides, Product Guides and Feature Guides are delivered with new GTA products; these manuals and other documentation for registered products can also be found on the GTA website, www.gta.com.
1 – Introduction 5 About GB-1200 The GB-1200 Firewall Appliance is a self-contained unit with the system software pre-installed. This guide describes and explains how to install and initially configure the GB-1200. For configuration options and field descrip- tions see the GNAT B ’...
• VPN Objects Hardware Design The GB-1200 Firewall Appliance is a 1RU appliance with two fans for cooling the CPU and power supply. The system has four high speed 10/100 Ethernet interfaces to ensure high performance and network design flexibility and two multifunction DB-9 serial interfaces to provide access for a serial console and a dial-up modem/ISDN TA.
When the red GTA logo on the front panel of the GB- 1200 is lit, the GB-1200 is powered on. Two groups of four LEDs, labeled 0, 1, 2 and 3, correspond to the network interfaces, with a three-letter prefix indicating the driver used by the NIC.
GB-1200 Firewall Appliance Product Guide Hardware Specifications Physical Specifications Chassis 1.75” h x 9” d x 17” w (4.445 cm x 22.86 cm x 43.18 cm) Weight 8 lbs (3.63 kg) Power Specifications MTBF (Mean Time Between Failure) 150,000 Hours...
1 – Introduction 9 Mounting Use the supplied screws and mounting brackets to attach the system unit to a standard equipment rack. Align the mounting bracket screw holes to the chassis screw holes, insert the screws and tighten. 19” Rackmount Bracket...
2 – Installation 11 2 Installation Preinstallation Installing the GB-1200 requires that the system be connected to your local area network (LAN). This allows the administrator to connect to the GB-1200, configure the network settings to match the local network address scheme and perform connectivity tests.
A yellow crossover cable is included with hardware appliances. Connect the GB-1200 Connect the GB-1200 to a hub or switch on your local area network using the Protected Network interface, (the first interface port 0, see illustration GB- 1200 Rear Panel) and a standard (straight-through) network cable. By default, 0 is assigned the IP address 192.168.71.254.
3 – Set Up Default Configuration 13 3 Set Up Default Configuration The following sections will describe how to set up your GB-1200 in the default configuration, in which all internal users are allowed outbound and no unsolicited inbound connections are allowed.
Page 18
GNAT Box System Software is known to be incompatible with Internet Explorer 5 for Macintosh. If your browser does not allow you to continue past the Security Alert screen in order to set up your new GB-1200, GTA recommends using another compatible browser such as Mozilla (www.mozilla.org), Netscape (www.netscape.com) or Opera...
Set the Host Name to that given to the firewall in your DNS server. Once you have completed Network Information, apply the changes by clicking on the Save. The GB-1200 will now be on a different logical network (assuming you’ve changed the default IP address for the Protected Network) and you will not be able to access the GTA Firewall from your workstation, since the firewall will now be on a different network.
After re-configuring your workstation, you can access the GB-1200 using the new IP address assigned to the Protected Network interface. The GB-1200 should now be active and functioning in default security mode, (all internal users are allowed outbound and no unsolicited inbound connec- tions are allowed).
Once you have completed the Network Information form, apply the changes to the GB-1200 by clicking on the single diskette icon on the tool bar to save the data. The GB-1200 will now be on a different logical network (assuming...
Network Information Once you click Save on the Network Information screen you will not be able to access the GB-1200 from your workstation, since the firewall will now be on a different network. Re-configure Workstation Re-configure your workstation back to its original IP address, now on the same network as the GTA Firewall.
6. Make sure the network cabling is connected to the correct network interface. Some useful guidelines are: • In a GB-1200, the port/NIC numbers, MAC addresses and logical names are listed on the Network Information screen and in the Configuration Report.
• Have you added a static route to the GB-1200 to tell it which router is used to reach the problem network? Have you set the router’s default route to be the GB-1200? Have you set the default route for hosts on the problem network to be the router? •...
Page 25
6. Why can't I see or ping the Protected Network interface? You may have the wrong cable for your connection. • For a direct connection (GB-1200 to host or router) you need a cross- over cable. • For a connection to a hub or switch you need a straight-through cable.
Page 26
A new GB-1200 has two identical slices. When the GB-1200 is upgraded to a new runtime, the upgrade process auto- matically overwrites the memory slice not in use with the new software version and the existing configuration, leaving the production firewall version and configuration intact.
Need help?
Do you have a question about the GB-1200 and is the answer not in the manual?
Questions and answers