Page 3
Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the software, please review the readme files, release notes, and the latest version of the applicable user documentation, which are available from the Trend Micro Web site http://www.trendmicro.com/download...
Page 4
Detailed information about how to use specific features within the software are available in the online help file and the online Knowledge Base at Trend Micro’s Web site. Trend Micro is always seeking to improve its documentation. Your feedback is always welcome.
Guide. This book contains basic information about the tasks you need to perform to deploy the device. It is intended for novice and advanced users of Network VirusWall who want to plan, deploy, and preconfigure Network VirusWall Enforcer 1200. This preface discusses the following topics: •...
The Online Help contains explanations about device components and features. • Upgrade Guide (UG)—PDF documentation that is accessible from the Solutions CD for Network VirusWall Enforcer 1200 or downloadable from the Trend Micro Web site. The UG contains explanations about upgrading from previous Network VirusWall 1200 versions to Network VirusWall Enforcer 1200.
Preface About This Getting Started Guide The Network VirusWall Enforcer 1200 Getting Started Guide discusses the following topics: • Introducing Trend Micro™ Network VirusWall™ Enforcer 1200—an overview of the device and its components • Getting Started—details of the actual device and its specifications, including instructions for mounting and powering on the device •...
Package Contents on page 1-2 After completing the procedures in this chapter, proceed by: • Conducting a Pilot Deployment on page 3-16 • Deploying Network VirusWall Enforcer 1200 on page 3-17 • Redefining Your Deployment Strategy on page 3-17 •...
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Package Contents Figure 1-1 illustrates the package contents. Ethernet Cable Power Cord Network VirusWall 1200 (RJ-45 Crossover) Rack Ears Console Cable (RS-232) Document Set 1-1. The package contents IGURE Table 1-1 to check whether the package is complete.
Page 15
Connects the device to the computer used during preconfiguration (length is 79 in/200 cm). 1 set Rack Ears Mounts a Network VirusWall Enforcer 1200 to a standard 19 in rack cabinet. 1 CD Trend Micro Solutions CD Contains patches, hot fix installers, tools, and for Network VirusWall documentation.
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Network VirusWall Enforcer 1200 Front Panel The front panel of Network VirusWall Enforcer 1200 contains a Liquid Crystal Display (LCD), panel, ports, and LEDs. LCD module and panel Port 1 Port 2...
1-3. Network VirusWall Enforcer 1200 LED indicators ABLE Port Indicators Network VirusWall Enforcer 1200 has two user-configurable copper-based Ethernet ports. Each Ethernet port has an indicator that allows you to determine the port’s current state. Figure 1-4 illustrates the indicators of a port.
Indicator 2– green, steady Port speed is 10 Mbps or 100 Mbps. 1-5. Network VirusWall Enforcer 1200 port indicators ABLE Network VirusWall Enforcer 1200 Back Panel The back panel of Network VirusWall Enforcer 1200 contains a power receptacle, power switch, and fan vents.
Exhaust cooling vent for the device. 1-6. Back panel description ABLE Dimensions and Weight The following specifications apply to Network VirusWall Enforcer 1200: Power Requirements and Environmental Specifications The following settings apply to Network VirusWall Enforcer 1200: LEMENT PECIFICATION AC input voltage...
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide LEMENT PECIFICATION Frequency 47 to 63 Hz (50/60 nominal) ORMAL OPERATING AMBIENT TEMPERATURE AT SEA LEVEL Minimum (operating and idle) 41 °F (5 °C) Maximum (operating, power supply on) 113 °F (45 °C) Maximum (idle, AC power supply on, 104 °F (40 °C)
Page 21
Chapter 2 Introducing Trend Micro™ Network VirusWall™ Enforcer 1200 This chapter introduces Trend Micro Network VirusWall Enforcer 1200 and provides an overview of its components and deployment. The topics discussed in this chapter include: • Network VirusWall Enforcer 1200 on page 2-2 •...
Failopen —a fault-tolerance solution, also known as LAN bypass, that allows the Network VirusWall Enforcer 1200 device to continue to pass traffic if a software or hardware failure occurs within the device.
Web Console The Network VirusWall Enforcer 1200 Web console provides central management for Network VirusWall Enforcer 1200 devices on your network. The Web console gives you the tools to configure and enforce security policies for an entire organization. This enables you to react quickly to network virus emergencies from nearly anywhere using the Web console.
Introducing Trend Micro™ Network VirusWall™ Enforcer 1200 Understanding Network VirusWall Enforcer Ports Network VirusWall Enforcer 1200 supports two ports— 2 copper Ethernet ports. Deployment Overview Network VirusWall Enforcer 1200 deployment consists of the following steps: Deciding on the deployment strategy Deploying Network VirusWall™...
Page 26
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide 2-2. Network VirusWall Enforcer 1200 after deployment IGURE Understanding Network VirusWall Enforcer 1200 of the Administrator’s Guide provides details about the following concepts: • Antivirus capabilities • Policy Enforcement using the first-match rule •...
Page 27
Deploying Network VirusWall™ Enforcer 1200 Before beginning to configure a Network VirusWall Enforcer 1200 device, plan how to integrate the device into your network. Determine which topology it will support. This chapter explains how to plan for the deployment of Network VirusWall Enforcer 1200 devices.
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Planning for Deployment To take advantage of the benefits Network VirusWall Enforcer 1200 can bring to your organization, you will need an understanding of the possible ways to deploy one or more devices. This section provides deployment overview and considerations.
Connecting to the Network page 5-18) Phase 3: Manage Network VirusWall Enforcer 1200 Devices During phase 3, manage Network VirusWall Enforcer 1200 devices from the Web console. You can perform the following tasks: • Create and manage policies to protect your network •...
100Mbps x full-duplex • Both the connected L2/L3 and Network VirusWall Enforcer 1200 devices should have the same interface setting and duplex mode. Otherwise, the half-duplex mode setting will take effect. To help guarantee the correct interface setting and duplex mode...
Deploying Network VirusWall™ Enforcer 1200 Identifying What to Protect Position Network VirusWall Enforcer 1200 between layer 2 (L2) or layer 3 (L3) devices. Identify segments of your network to protect by considering which kinds of endpoints may introduce viruses or violate security policies. Also, consider the location of resources that are critical to your organization.
Page 32
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Dial-up service deployment scenario IGURE Figure 3-1 illustrates a dialup connection between a home user and an organization’s internal network. A RAS server, the point where the dialup connection terminates, is...
Page 33
VPN connection is considered to be part of the internal network. Note: Network VirusWall Enforcer 1200 must be behind the VPN server, which encrypts and decrypts VPN traffic. The recommended settings for this scenario are the same as the settings for the...
Page 34
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide 3-3. Site to site VPN deployment scenario IGURE Figure 3-3 illustrates a VPN connection between two business units. As in the home user scenario, a VPN server is connected to a...
A wireless access point, switch, or hub is connected to the port (See EGULAR Introducing Network VirusWall Enforcer 1200-specific Terms on page 2-3 for information about different types of ports). This type of topology ensures that the device scans all traffic before it leaves the guest network segment and makes isolation of the guest segment possible in the event of a virus outbreak.
Page 36
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide 3-5. Key network segments scenario IGURE Key Network Segments/Important Network Assets on page 3-9 illustrates a segment of an internal network containing email and Web servers, including endpoints. An internal switch or hub is connected to a...
Deploying Network VirusWall™ Enforcer 1200 Dual-switch VLAN Environment Network VirusWall Enforcer 1200 must be placed in line on the physical network to be able to provide security. In most situations, this means between an upstream switch and one or more downstream switches.
Page 38
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide 3-6. Multiple VLAN segments with each device protecting one IGURE segment Figure 3-6, the devices are installed on an 802.1Q trunk line between two switches.
Page 39
Deploying Network VirusWall™ Enforcer 1200 3-7. Multiple VLAN segments with each device protecting all IGURE segments...
VLAN 20 is assigned to ports 1 and 2 on the switch • The upstream network is connected to port 2 on the switch • port on Network VirusWall Enforcer 1200 is connected to port 1 on REGULAR the switch 3-8.
Deploying Network VirusWall™ Enforcer 1200 Planning for Network Traffic The scenario presented in Key Network Segments/Important Network Assets on page 3-9 is also a good example of how to plan for network traffic. There is a strategic advantage to positioning the device in front of resources that endpoints access regularly, such as an email or Web server.
Creating a Contingency Plan Trend Micro recommends creating a contingency plan in case there are issues with the installation, operation, or upgrade of the device. Consider your network’s vulnerabilities and how you can retain a minimum level of security if issues arise.
Deploying Network VirusWall Enforcer 1200 This section provides an example of a few basic deployment scenarios (see page 3-18) and deployment strategies: Network VirusWall Enforcer 1200 Initial Tasks Tip: on page 4-2 for checklists on how to prepare a device for deployment.
The device can be installed on a network that contains Ethernet devices such as hubs, switches, and routers. Deploy Network VirusWall Enforcer 1200 between a switch that leads to the public network and a switch that protects a segment of the Local Area Network (LAN).
Page 45
Deploying Network VirusWall™ Enforcer 1200 Trend Micro recommends connecting Network VirusWall Enforcer 1200 to the switches using straight-through cables. Trend Micro recommends configuring the switches to use Rapid Spanning Tree Protocol (RSTP 802.1w) to lower the impact on the network when failopen occurs (under five seconds).
• Preparing for Preconfiguration on page 4-2 • Network VirusWall Enforcer 1200 Initial Tasks on page 4-2 Preconfiguring Network VirusWall Enforcer 1200 requires the completion of related tasks. To perform preconfiguration: Plan and determine the deployment strategy (see page 3-2).
Page 48
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Preparing for Preconfiguration Complete the following tasks before preconfiguring the device: • If you are upgrading from a previous version of Network VirusWall refer to the Network VirusWall Enforcer 1200 Upgrade Guide before continuing.
Performing Preconfiguration Using the LCD Module on page 5-16 • Connecting to the Network on page 5-18 Preconfiguring a Network VirusWall Enforcer 1200 device requires the completion of the following tasks: Select the console to use during preconfiguration (see page 5-3).
4-1), use the Preconfiguration console to proceed with preconfiguration. After the preconfiguration procedure of the device is complete, you can then administer Network VirusWall Enforcer 1200 using the Web console. Refer to Configuring Policy Enforcement and Device Settings of the Administrator’s Guide.
Preconfiguring Network VirusWall Enforcer 1200 Choosing the Preconfiguration Method Preconfigure the device through the: • Preconfiguration console • LCD module (also known as the LCM console) Using the Preconfiguration Console The Preconfiguration console is a terminal communications program that allows you to configure or view any preconfiguration setting.
Page 52
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide For a comparison of these two methods, see Table 5-1. RECONFIGURATION HAT YOU CAN DO CONSOLE ODULE Set the Network VirusWall Enforcer 1200 IP address, netmask, Gateway address, and DNS addresses...
Preconfiguring Network VirusWall Enforcer 1200 Performing Preconfiguration Using the Preconfiguration Console Preconfiguring the device using the Preconfiguration console requires the completion of the following tasks: Network VirusWall Enforcer 1200 Tip: Check whether you have completed the Initial Tasks before starting with the following steps.
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Preparing the Preconfiguration Console The computer you choose for preconfiguration must have terminal configuration software such as HyperTerminal for Windows. To prepare the Preconfiguration console: Connect one end of the included console cable to the CONSOLE port on the back panel of the device and the other end to the serial port (COM1, COM2, or other COM port) on a computer.
Preconfiguring Network VirusWall Enforcer 1200 Logging on the Preconfiguration Console After preparing the terminal application, you are ready to access the Preconfiguration console. To access the Preconfiguration console: Power on the device and wait for a welcome message to appear on the LCM panel (approximately 1-2 minutes).
Page 56
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Press ENTER. The User name logon prompt displays. If the screen does not display, type Ctrl + ’R’ or Ctrl + ’L’. 5-1. The Preconfiguration console logon prompt IGURE...
Page 57
Preconfiguring Network VirusWall Enforcer 1200 Type the default administrator user name and its corresponding password: User name: admin Password: admin Note: Change the default password to a secure password immediately after logging for the first time. Only administrators and power users can login to the Preconfiguration console.
Page 58
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide After logging on, the Main Menu appears. Note: The Preconfiguration console has a timeout value of 3 minutes. If the console is idle for three minutes, it automatically logs off the account. After 3 attempts to login, there will be a short time period before you can try again.
Device Settings menu to configure the Network VirusWall Enforcer 1200 host name that appears on the Web console and the Network VirusWall Enforcer 1200 network settings. To configure the device settings: On the Main Menu of the Preconfiguration console, type 2 to select Device Settings.
Page 60
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide WARNING! If there is a NAT device in your environment, Trend Micro recommends assigning a static IP address to the device. Because different port settings are assigned from your NAT, your device may not work properly if dynamic IP addresses are used.
Page 61
Note: System logs contain information useful for troubleshooting. If you experience issues with the device and contact Trend Micro support, you may be asked to view the system log. Refer to Viewing Status, Logs, and Summaries and Troubleshooting in the Administrator’s Guide for more details about...
Use the Preconfiguration console to configure the interface speed and duplex mode. Note: Both the connected L2/L3 and Network VirusWall Enforcer 1200 devices should have the same interface setting and duplex mode. Otherwise, the half-duplex mode setting will take effect. Apply 100Mbps x full-duplex for both the switch and Network VirusWall Enforcer 1200 device.
Preconfiguring Network VirusWall Enforcer 1200 Select the speed by using the space bar to scroll through the speed options. Select Return to the previous menu. The Interface Settings screen displays. Type 2 to select Interface setting. Use the down arrow to go to Port 3.
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Performing Preconfiguration Using the LCD Module With the LCD console, you can only configure the device’s IP address. Use the terminal interface for access to all preconfiguration options (see Comparison of available consoles for preconfiguration).
Page 65
Preconfiguring Network VirusWall Enforcer 1200 To configure the IP address through the LCD module: Press ENTER ( ). The Main Menu appears. Use the down arrow ( ) to select Configure NVW. A prompt displays asking if you want to change settings.
REGULAR to a segment of your network Power on the device (see page 5-7). Note: Network VirusWall Enforcer 1200 can handle various interface speed and duplex Setting the Interface Speed and Duplex Mode mode network traffic. See page 5-14.
Chapter 6 Configuring Network VirusWall Enforcer 1200 After preconfiguring Network VirusWall Enforcer 1200, you are ready to configure the device and commence network protection. Trend Micro recommends performing the following tasks after preconfiguring a device: • Configuring PEAgent Settings for Manual Deployment on page 6-2 •...
Configuring PEAgent Settings for Manual Deployment You can configure Network VirusWall Enforcer 1200 to use agentless or persistent agent mode. In persistent agent mode the PEAgent, which installs on the end-users’ client computer, communicates with Network VirusWall Enforcer 1200. You can configure the Network VirusWall Enforcer 1200 port which communicates with the PEAgents.
Page 69
Configuring Network VirusWall Enforcer 1200 To check the Windows Installer version: Click Start > Run..The Run dialog box appears. Type in the Open field. The Command Line Interface appears. msiexec Enter Type at the command prompt and press . The Windows Installer dialog box appears.
Page 70
Specify the port that the PEAgent uses to communicate with Network VirusWall Enforcer 1200 in the Client port field. Click OK. To configure the communication port for Network VirusWall Enforcer 1200: In the Network VirusWall Enforcer 1200 Web console, click Policy Enforcement > PEAgent Settings. The PEAgent Settings screen appears.
Page 71
• User does not allow ActiveX to run on their computers To customize the Performing Endpoint Assessment endpoint notification: In the Network VirusWall Enforcer 1200 Web console, click Policy Enforcement > Endpoint notifications. The Endpoint Notifications screen appears. Click Performing Endpoint Assessment under Web Notifications. The Performing Endpoint Assessment Endpoint Notification screen appears.
Page 72
Trend Micro™ Network VirusWall™ Enforcer 1200 Getting Started Guide Please wait while <%=PRODUCT_NAME%> performs an assessment of your computer. This may take a few minutes, depending on the current network traffic. </p> <p> <ul style="list-style: disc;" type=disc> <li><font size="2" color=#E70009 face="Verdana, Arial, Helvetica, sans-serif">...
Select the Component checkbox to update all components or select checkboxes to update individual components. Click Update. Use the Summary screen from the Network VirusWall Enforcer 1200 Web console to verify whether Network VirusWall Enforcer 1200 updates the selected components during manual update.
This chapter addresses troubleshooting issues that may arise during the device preconfiguration. Tip: Refer to the Network VirusWall Enforcer 1200 Administrator’s Guide in the Trend Micro Solutions CD for Network VirusWall Enforcer 1200 for additional FAQs and troubleshooting. This chapter contains the following topics: •...
Verify whether the LCD module configuration is set to ON. change settings Otherwise, the OFF LCD module configuration state will prevent you with the LCD from configuring Network VirusWall Enforcer 1200 through the LCD module panel module. In addition, to change settings with the LCD module panel, you must...
Troubleshooting Preconfiguration Contacting Technical Support If the issue still persists despite following the troubleshooting tips provided in Troubleshooting Preconfiguration, refer to Getting Support in the Administrator’s Guide for instructions on how obtain technical support.
Need help?
Do you have a question about the Network VirusWall Enforcer 1200 and is the answer not in the manual?
Questions and answers