Network ips appliances, award-winning, next-generation intrusion prevention solution delivering best-in-class proactive prevention of zero-day and dos attacks, spyware, malware, botnets, and voip threats (5 pages)
Page 1 Monday, October 12, 2009 11:56 AM McAfee UTM Firewall Quick Installation Guide Rack Mount Model SG720...
Page 2
PROTECTIONPILOT, SECURE MESSAGING SERVICE, SECURITYALLIANCE, SITEADVISOR, THREATSCAN, TOTAL PROTECTION, VIREX, VIRUSSCAN, WEBSHIELD are registered trademarks or trademarks of McAfee, Inc. and/or its affiliates in the US and/or other countries. McAfee Red in connection with security is distinctive of McAfee brand products. All other registered and unregistered trademarks herein are the sole property of their respective owners.
This Quick Installation Guide walks you through the installation of your UTM Firewall device. This guide is intended for anyone who needs to set up an SG720 McAfee UTM Firewall device. You can find additional information at the following locations: •...
uf_SG720_qig_700-2240A00_en-us.fm Page 4 Monday, October 12, 2009 11:56 AM Installation overview Installing the UTM Firewall device into a well-planned network is quick and easy; however, network planning is outside the scope of this guide. Take some time to plan your network prior to installing your UTM Firewall device.
Page 5
The front panel of the UTM Firewall device has 2 10/100/1000 ports (A and B), 3 10/100 ports (C, D, and E), a serial port, status LEDs, and an Erase button (Appendix 1). Figure 1 SG720 front panel SG720 Secure Network Gateway...
Page 6
LAN settings. NOTE: Initial configuration is performed through port A. McAfee strongly recommends you do not connect the UTM Firewall device to your LAN until this guide instructs you to. If you attach port A directly...
Page 7
uf_SG720_qig_700-2240A00_en-us.fm Page 7 Monday, October 12, 2009 11:56 AM Figure 2 Internet Protocol (TCP/IP) Properties Select Use the following IP address, and type: • IP address – 192.168.0.100 • Subnet mask – 255.255.255.0 • Default gateway – 192.168.0.1 Select Use the following DNS server addresses. In the Preferred DNS Server field, enter 192.168.0.1.
Page 8
uf_SG720_qig_700-2240A00_en-us.fm Page 8 Monday, October 12, 2009 11:56 AM Set your password Launch your Web browser. The UTM Firewall Management Console window appears. NOTE: If the UTM Firewall Management Console window does not appear, navigate to 192.168.0.1. If you are unable to browse to the UTM Firewall device at 192.168.0.1, or if the initial username and password are not accepted: Press the erase button on the UTM Firewall device's rear panel...
Page 9
uf_SG720_qig_700-2240A00_en-us.fm Page 9 Monday, October 12, 2009 11:56 AM Enter and confirm a new password for your UTM Firewall device. The new password takes effect immediately. You are prompted to enter the new password when completing the next step. NOTE: This is the password for the main administrative user (root) account on the UTM Firewall device.
Page 10
uf_SG720_qig_700-2240A00_en-us.fm Page 10 Monday, October 12, 2009 11:56 AM Set LAN connection settings [Optional] The host name defaults to the model number. If you want to use a different host name, type the new name in the Hostname field. The name must begin with an alpha character. Click Next.
Page 11
uf_SG720_qig_700-2240A00_en-us.fm Page 11 Monday, October 12, 2009 11:56 AM Select an option for your LAN configuration: • [Recommended] To manually configure your LAN and enable the built-in DHCP server option which automatically configures the network settings of computers and other hosts on your LAN, select Use a Fixed IP.
Page 12
uf_SG720_qig_700-2240A00_en-us.fm Page 12 Monday, October 12, 2009 11:56 AM Figure 6 LAN Configuration window [Optional] To enable the UTM Firewall device's built-in DHCP server, enter a range of addresses in the DHCP Server Start Address and DHCP Server End Address fields. Computers and other hosts on your LAN set to automatically obtain network settings are assigned an address from this range, and use the UTM Firewall device as their gateway to the Internet,...
Page 13
uf_SG720_qig_700-2240A00_en-us.fm Page 13 Monday, October 12, 2009 11:56 AM Figure 7 ISP connection window Select an option for your Internet Port Configuration: • Cable Modem – Connect using a cable modem. • Modem – Connect using a regular analog modem. •...
Page 14
uf_SG720_qig_700-2240A00_en-us.fm Page 14 Monday, October 12, 2009 11:56 AM Click Next. Continue based on the option you selected. • Cable Modem, Modem, or ADSL – Configuration windows for those options are presented for you to complete. Refer to the on-screen instructions, the Help, and the UTM Firewall Administration Guide for more details.
Page 15
uf_SG720_qig_700-2240A00_en-us.fm Page 15 Monday, October 12, 2009 11:56 AM Click Next. Continue based on the option you selected. • Use an IP address obtained from a server on the Internet (DHCP) – Go to Select a security level on page •...
Page 16
uf_SG720_qig_700-2240A00_en-us.fm Page 16 Monday, October 12, 2009 11:56 AM Select a security level UTM Firewalls support packet filtering rules that can be used to restrict access between different parts of your network. Use the Firewall security level window to select a security level that will activate one or more packet filtering rules (Figure 10).
Page 17
uf_SG720_qig_700-2240A00_en-us.fm Page 17 Monday, October 12, 2009 11:56 AM Select a Firewall Configuration option: • Block Everything – Blocks all traffic that is not expressly allowed by a packet filtering rule. • Ultra / VPN access – Allows VPN, Dialin and LAN traffic to move through the firewall.
Page 18
uf_SG720_qig_700-2240A00_en-us.fm Page 18 Monday, October 12, 2009 11:56 AM Connect to your LAN Review your configuration selections (Figure 11). Figure 11 Confirm selections window If you are satisfied with your settings, click Finish to activate the new configuration. NOTE: Depending on how you configured your LAN settings, you may have to navigate to the UTM Firewall’s new LAN IP address to access the Management Console.
Page 19
uf_SG720_qig_700-2240A00_en-us.fm Page 19 Monday, October 12, 2009 11:56 AM Set up computers on your LAN Each computer on your LAN must now be assigned an appropriate IP address, and have the UTM Firewall device LAN IP address designated as its gateway and DNS server. A DHCP server allows computers to automatically obtain these network settings when they start up.
Page 20
uf_SG720_qig_700-2240A00_en-us.fm Page 20 Monday, October 12, 2009 11:56 AM Figure 12 IP Properties window Select the following options: • Obtain an IP address automatically • Obtain DNS server address automatically Click OK. Repeat steps 1-5 for each computer in your network.
Page 21
IP address obtained from a server on the LAN (DHCP) option (Step 3 on page 11), McAfee recommends you add a lease to your existing DHCP server to reserve the IP address you chose for the UTM Firewall device LAN connection.
Page 22
uf_SG720_qig_700-2240A00_en-us.fm Page 22 Monday, October 12, 2009 11:56 AM Manually configure LAN properties Click Start | (Settings |) Control Panel, then double-click Network Connections. Right-click Local Area Connection (or appropriate network connection), and select Properties. Select Internet Protocol (TCP/IP), and click Properties. Type the following: •...
Page 23
uf_SG720_qig_700-2240A00_en-us.fm Page 23 Monday, October 12, 2009 11:56 AM Set up the Internet connection If you skipped configuring connection settings, or have additional port connections to configure, continue with this procedure. Otherwise, go to Register your UTM Firewall device on page NOTE: If you changed the UTM Firewall device’s LAN connection settings...
Advanced configurations Use the menu in the UTM Firewall Web Management Console to configure more sophisticated security settings and networking features such as VPN. Refer to the McAfee UTM Firewall Administration Guide, the Help, and the KnowledgeBase for further configuration information.
Page 25
Term. This Agreement is effective for the term set forth in the purchase order issued by you and which is accepted by McAfee or, alternatively, as set forth in the product order form issued by McAfee (the “Term”). If you issue a purchase order...
Page 26
McAfee and its suppliers own and retain all right, title and interest in and to the Software, including all copyrights, patents, trade secret rights, trademarks and other intellectual property rights therein.
Page 27
Beta Software received from McAfee and to abide by the terms of the End User License Agreement for any such later versions of the Beta Software. Your Use of the Evaluation or Beta...
Page 28
Nothing contained in this Agreement limits McAfee’s liability to you for McAfee’s negligence or for the tort of fraud. McAfee is acting on behalf of its suppliers and Authorized Partners for the purpose of disclaiming, excluding and/or limiting obligations, warranties and liability as provided in this Agreement, but in no other respects and for no other purpose.
Page 29
Software or designated internet page. If any Free Software licenses require that McAfee provide rights to use, copy or modify a software program that are broader than the rights granted in this agreement, then such rights shall take precedence over the rights and restrictions herein.
Page 30
(4) times per year. In the event that McAfee requires a physical audit, such audit shall be preceded by thirty (30) days written notice and shall occur no more than once per year unless otherwise required for compliance with the Sarbanes-Oxley Act.
Need help?
Do you have a question about the SG720 and is the answer not in the manual?
Questions and answers