Sign In
Upload
Manuals
Brands
Fido Manuals
Network Router
FireBrick FB2700
User Manuals: Fido FireBrick FB2700 Firewall Router
Manuals and User Guides for Fido FireBrick FB2700 Firewall Router. We have
1
Fido FireBrick FB2700 Firewall Router manual available for free PDF download: User Manual
Fido FireBrick FB2700 User Manual (264 pages)
Brand:
Fido
| Category:
Network Router
| Size: 2 MB
Table of Contents
User Manual
1
Table of Contents
4
Preface
21
1 Introduction
22
The FB2700
22
Where Do I Start
22
What Can It Do
22
Ethernet Port Capabilities
23
Differences between the Devices in the Fb2X00 Series
23
Software Features
23
Migration from Previous Firebrick Models
23
About this Manual
24
Version
24
Intended Audience
24
Technical Details
24
Document Style
24
Document Conventions
25
Comments and Feedback
25
Additional Resources
25
Technical Support
25
IRC Channel
26
Application Notes
26
White Papers
26
Training Courses
26
2 Getting Started
27
IP Addressing
27
Accessing the Web-Based User Interface
27
IP Addresses to Access the Firebrick
27
Add a New User
28
Setting up a New User
29
Configuration Being Stored
29
3 Configuration
30
The Object Hierarchy
30
The Object Model
30
Formal Definition of the Object Model
31
Common Attributes
31
Configuration Methods
31
Web User Interface Overview
31
User Interface Layout
32
Customising the Layout
32
Main Menu
32
Config Pages and the Object Hierarchy
33
Configuration Categories
33
Object Settings
34
The "Setup" Category
34
Editing an "Interface" Object
35
Navigating Around the User Interface
36
Backing up / Restoring the Configuration
37
Configuration Using XML
37
Introduction to XML
37
Example XML Configuration
38
The Root Element - <Config
38
Viewing or Editing XML
38
Downloading/Uploading the Configuration
40
Download
40
Upload
41
4 System Administration
42
User Management
42
Login Level
42
Setting up a New User
42
Configuration Access Level
43
Login Idle Timeout
43
Restricting User Logins
43
Restrict by IP Address
43
User Login Levels
43
Configuration Access Levels
43
Logged in IP Address
44
Restrict by Profile
44
One Time Password
44
General System Settings
45
Administrative Details
45
Home Page Web Links
45
System Name (Hostname)
45
System-Level Event Logging Control
45
Password Hashing
46
Software Upgrades
46
Breakpoint Releases
47
Identifying Current Software Version
47
Software Release Types
47
Controlling Automatic Software Updates
48
Internet-Based Upgrade Process
48
Manually Initiating Upgrades
48
Software Upgrade Available Notification
48
Manual Upgrade
49
Boot Process
49
LED Indications
49
Power LED Status Indications
49
Port Leds
50
5 Event Logging
51
Overview
51
Log Targets
51
Logging to Flash Memory
51
Logging to the Console
52
Enabling Logging
52
Logging to External Destinations
52
Syslog
52
Email
53
E-Mail Process Logging
54
Factory Reset Configuration Log Targets
54
Performance
54
Viewing Logs
54
Viewing Logs in the User Interface
54
Viewing Logs in the CLI Environment
55
System-Event Logging
55
Using Profiles
55
System-Event Logging Attributes
55
6 Interfaces and Subnets
56
Relationship between Interfaces and Physical Ports
56
Port Groups
56
Interfaces
56
Defining Port Groups
57
Defining an Interface
57
Defining Subnets
58
Source Filtering
59
Using DHCP to Configure a Subnet
59
Setting up DHCP Server Parameters
59
Fixed/Static DHCP Allocations
60
Restricted Allocations
61
Special DHCP Options
62
DHCP Relay Agent
62
Physical Port Settings
62
Disabling Auto-Negotiation
63
Setting Port Speed
63
Setting Duplex Mode
63
Defining Port LED Functions
63
Example Modified Port LED Functions
64
7 Session Handling
65
Routing Vs. Firewalling
65
Session Tracking
65
Session Termination
66
Session Rules
66
Overview
66
Processing Flow
67
Action Attribute Values
67
Processing Flow Chart for Rule-Sets and Session-Rules
69
Defining Rule-Sets and Rules
70
Recommended Method of Implementing Firewalling
71
Changes to Session Traffic
72
Configuring Session Time-Outs
73
Graphing and Traffic Shaping
73
Load Balancing
73
Network Address Translation
74
NAT Algs
74
When to Use NAT
74
NAT with Pppoe
75
Setting NAT in Rules
75
What NAT Does
75
Carrier Grade NAT
76
Mixing NAT and Non NAT
76
NAT with Dongles
76
NAT with Other Types of External Routing
76
Using NAT Setting on Subnets
77
8 Routing
78
Routing Logic
78
Routing Targets
79
Subnet Routes
79
Routing to an IP Address (Gateway Route)
79
Special Targets
80
Dynamic Route Creation / Deletion
80
Routing Tables
80
Bonding
81
Route Overrides
81
9 Profiles
83
Overview
83
Creating/Editing Profiles
83
Timing Control
83
Tests
84
General Tests
84
Ping Tests
84
Time/Date Tests
84
Inverting Overall Test Result
85
Manual Override
85
10 Traffic Shaping
86
Graphs and Shapers
86
Graphs
86
Shapers
87
Ad Hoc Shapers
87
Long Term Shapers
87
Multiple Shapers
88
Basic Principles
88
11 Pppoe
89
Types of DSL Line and Router in the United Kingdom
89
Definining Pppoe Links
90
Ipv6
90
Additional Options
90
MTU and TCP Fix
90
Logging
91
Service and Ac-Name
91
Speed and Graphs
91
12 Tunnels
92
Ipsec (IP Security)
92
Introduction
92
Encryption
92
Integrity Checking
92
Authentication
93
Ike
93
Manual Keying
93
Identities and the Authentication Mechanism
94
Setting up Ipsec Connections
94
Global Ipsec Parameters
94
IKE and Ipsec Proposal Lists
95
IKE Connection Mode and Type
95
IKE Connections
95
IKE Proposals
95
IKE Roaming IP Pools
95
Authentication and IKE Identities
96
IP Addresses
96
Other Parameters
97
Road Warrior Connections
97
Routing
97
Setting up Manual Keying
97
Algorithms and Keys
98
IP Endpoints
98
Mode
98
Routing
98
Other Parameters
99
Using EAP with Ipsec/Ike
99
Using Certificates with Ipsec/Ike
99
Creating Certificates
101
Choice of Algorithms
101
NAT Traversal
102
Configuring a Road Warrior Server
103
Connecting to Non-Firebrick Devices
104
Using Strongswan on Linux
104
Setting up a Road Warrior VPN on an Android Client
105
Manual Keying Using Linux Ipsec-Tools
106
Setting up a Road Warrior VPN on an Ios (Iphone/Ipad) Client
106
FB105 Tunnels
107
Tunnel Wrapper Packets
108
Setting up a Tunnel
108
Viewing Tunnel Status
109
Dynamic Routes
109
Tunnel Bonding
109
Tunnels and NAT
109
Another Device Doing NAT
110
FB2700 Doing NAT
110
Ether Tunnelling
110
13 USB Port
112
USB Configuration
112
Dongle Configuration
112
14 System Services
113
Protecting the FB2700
113
Common Settings
113
List of System Services
113
HTTP Server Configuration
114
Access Control
114
Trusted Addresses
114
List of System Services
114
Telnet Server Configuration
115
Access Control
115
DNS Configuration
115
Blocking DNS Names
115
Local DNS Responses
115
Auto DHCP DNS
116
NTP Configuration
116
SNMP Configuration
116
RADIUS Configuration
116
RADIUS Client
116
RADIUS Server (Platform RADIUS)
116
RADIUS Client Settings
117
Server Blacklisting
117
15 Network Diagnostic Tools
118
Firewalling Check
118
Access Check
119
Packet Dumping
119
Dump Parameters
120
Security Settings Required
120
IP Address Matching
121
Packet Types
121
Snaplen Specification
121
Using the Web Interface
121
Using an HTTP Client
122
Example Using Curl and Tcpdump
122
16 Vrrp
123
Virtual Routers
123
Configuring VRRP
124
Advertisement Interval
124
Priority
124
Using a Virtual Router
124
VRRP Versions
124
VRRP Version 2
124
VRRP Version 3
125
Compatibility
125
17 Voip
126
What Is Voip
126
Registration and Proxies
126
Registrar
126
Proxy
126
Home/Office Phone System
127
Network Address Translation
127
Number Plan
128
Telephone Handsets
128
Voip Call Carriers
129
Hunt Groups
130
Ring Type
130
Ring Order
131
Overflow
131
Out of Hours
131
Call Pickup/Steal
131
Busy Lamp Field
132
Using RADIUS
132
RADIUS Accounting
132
RADIUS Authentication
132
Call Routing by RADIUS
133
Call Recording
134
Access-Accept
134
Voicemail and IVR Services
135
Call Data Records
135
Technical Details
136
Custom Tones
136
Default Tones
136
18 Bgp
138
What Is BGP
138
BGP Setup
138
Overview
138
Standards
138
Simple Example Setup
139
Peer Type
139
Peer Types
139
Route Filtering
140
Action Attributes
140
Matching Attributes
140
Announcing Black Hole Routes
141
Well Known Community Tags
141
Announcing Dead End Routes
142
Bad Optional Path Attributes
142
Network> Element
142
Route Feasibility Testing
142
Route>, <Subnet> and Other Elements
142
Network Attributes
142
Diagnostics
143
Router Shutdown
143
TTL Security
143
19 Ospf
144
What Is OSPF
144
OSPF Setup
144
Overview
144
Standards
144
Simple Example Setup
145
Ospf> Configelement
145
20 Internet Service Providers
146
Background
146
How It All Began
146
Point to Point Protocol
146
L2Tp
146
Broadband
147
Radius
147
Bgp
147
Incoming L2TP Connections
147
The Importance of CQM Graphs
148
Authentication
148
Accounting
149
RADIUS Control Messages
149
Pppoe
149
Typical Configuration
149
Interlink Subnet
149
BGP with Carrier
150
RADIUS Session Steering
150
L2TP Endpoints
151
Isp Radius
151
21 Command Line Interface
152
Factory Reset Procedure
153
CIDR and CIDR Notation
155
MAC Addresses Usage
157
Multiple MAC Addresses
157
How the Firebrick Allocates MAC Addresses
158
Base MAC
158
Interface
158
Pppoe
158
Subnet
158
Running out of Macs
159
MAC Address on Label
159
Using with a DHCP Server
160
Vlans : a Primer
161
Supported L2TP Attribute/Value Pairs
162
Start-Control-Connection-Request
162
Start-Control-Connection-Reply
162
Start-Control-Connection-Connected
163
Stop-Control-Connection-Notification
163
Hello
163
Incoming-Call-Request
163
Incoming-Call-Reply
164
Incoming-Call-Connected
164
Outgoing-Call-Request
164
Outgoing-Call-Reply
165
Outgoing-Call-Connected
165
Call-Disconnect-Notify
165
WAN-Error-Notify
165
Set-Link-Info
165
Ocrp
165
Occn
165
Cdn
165
Wen
165
Sli
165
Notes
166
BT Specific Notes
166
IP over LCP
166
Supported RADIUS Attribute/Value Pairs for L2TP Operation
167
Authentication Request
167
Access-Request
167
Authentication Response
168
Accepted Authentication
168
Access-Accept
168
Prefix Delegation
169
Rejected Authentication
170
Accounting Start
170
Accounting-Start
170
Access-Reject
170
Accounting Interim
171
Accounting-Interim
171
Accounting Stop
172
Accounting-Stop
172
Disconnect
172
Change of Authorisation
172
Change-Of-Authorisation
172
Filter ID
173
Filter-ID
173
Notes
174
L2TP Relay
174
Closed User Group
175
IP over LCP
175
LCP Echo and CQM Graphs
175
Routing Table
175
Supported RADIUS Attribute/Value Pairs for Voip Operation
176
Authentication Request
176
Access-Request
176
Authentication Response
177
Accepted Authentication (Invite)
177
Accepted Authentication (Registration)
177
Challenge Authentication
177
Access-Accept
177
Rejected Authentication
178
Accounting Start
178
Accounting-Start
178
Accounting Interim
178
Accounting-Interim
178
Access-Reject
178
Accounting Stop
179
Accounting-Stop
179
Disconnect
179
Change of Authorisation
180
Change-Of-Authorisation
180
Firebrick Specific SNMP Objects
181
BGP Information
181
L2TP Information
181
Iso.3.6.1.4.1.24693.179
181
Iso.3.6.1.4.1.24693.1701
181
Monitoring Information
182
Command Line Reference
183
General Commands
183
General Status
183
Login
183
Memory Usage
183
Process/Task Usage
183
Trace off
183
Trace on
183
Uptime
183
Disable Profile Control Switch
184
Enable Profile Control Switch
184
Load XML Configuration
184
Logout
184
See XML Configuration
184
Show DNS Resolvers
184
Show Profile Status
184
Show RADIUS Servers
184
Networking Commands
185
List Routes
185
List Routing Next Hops
185
Ping and Trace
185
Show a Route from the Routing Table
185
Subnets
185
Clear DHCP Allocations
186
Lock DHCP Allocations
186
Name DHCP Allocations
186
See DHCP Allocations
186
Send Wake-On-LAN Packet
186
Show ARP/ND Status
186
Show VRRP Status
186
Unlock DHCP Allocations
186
Firewalling Commands
187
Check Access to Services
187
Check Firewall Logic
187
Usb/Dongle Commands
187
Reset Ppp/Dongle Data Connection
187
Reset USB Interface and All Attached Devices
187
Show Dongle Connectoons
187
L2TP Commands
187
BGP Commands
187
OSPF Commands
188
Pppoe Commands
188
Voip Commands
188
Dongle/Usb Commands
188
Advanced Commands
188
Panic
188
Reboot
188
Screen Width
188
Boot Log
189
Delete Block from Flash
189
Flash Log
189
Flash Memory List
189
Kill Command Session
189
Make Outbound Command Session
189
Show Command Sessions
189
Constant Quality Monitoring - Technical Details
190
Broadband Back-Haul Providers
190
Access to Graphs and Csvs
190
Trusted Access
190
File Types
190
Dated Information
191
Authenticated Access
191
Graph Display Options
191
Data Points
191
Additional Text
192
Other Colours and Spacing
192
Overnight Archiving
192
Full URL Format
193
Load Handling
193
Graph Scores
193
URL Formats
193
Creating Graphs, and Graph Names
194
Configuration Objects
195
Top Level
195
Config: Top Level Config
195
Objects
196
System: System Settings
196
Link: Web Links
197
User: Admin Users
197
Eap: User Access Controlled by EAP
198
Log: Log Target Controls
198
Eap: Attributes
198
Log: Attributes
198
Log: Elements
198
Log-Syslog: Syslog Logger Settings
199
Log-Email: Email Logger Settings
199
Services: System Services
200
Snmp-Service: SNMP Service Settings
200
Ntp-Service: NTP Service Settings
200
Telnet-Service: Telnet Service Settings
201
Http-Service: HTTP Service Settings
202
Dns-Service: DNS Service Settings
202
Dns-Host: Fixed Local DNS Host Settings
203
Dns-Block: Fixed Local DNS Blocks
203
Radius-Service: RADIUS Service Definition
204
Radius-Service-Match: Matching Rules for RADIUS Service
205
Radius-Service-Match: Attributes
205
Radius-Server: RADIUS Server Settings
206
Ethernet: Physical Port Controls
207
Portdef: Port Grouping and Naming
207
Interface: Port-Group/Vlan Interface Settings
208
Subnet: Subnet Settings
209
Vrrp: VRRP Settings
210
Dhcps: DHCP Server Settings
210
Dhcp-Attr-Hex: DHCP Server Attributes (Hex)
211
Dhcp-Attr-String: DHCP Server Attributes (String)
211
Dhcps: Elements
211
Dhcp-Attr-Number: DHCP Server Attributes (Numeric)
212
Dhcp-Attr-Ip: DHCP Server Attributes (IP)
212
Pppoe: Pppoe Settings
212
Dhcp-Attr-String: Attributes
212
Dhcp-Attr-Number: Attributes
212
Ppp-Route: PPP Routes
214
Usb: USB 3G/Dongle Settings
214
Dongle: 3G/Dongle Settings
214
Pppoe: Elements
214
Route: Static Routes
216
Network: Locally Originated Networks
216
Blackhole: Dead End Networks
217
Loopback: Locally Originated Networks
217
Ospf: Overall OSPF Settings
218
Namedbgpmap: Mapping and Filtering Rules of BGP Prefixes
219
Bgprule: Individual Mapping/Filtering Rule
219
Bgp: Overall BGP Settings
219
Bgppeer: BGP Peer Definitions
220
Bgpmap: Mapping and Filtering Rules of BGP Prefixes
222
Cqm: Constant Quality Monitoring Settings
222
L2Tp: L2TP Settings
224
L2Tp-Outgoing: L2TP Settings for Outgoing L2TP Connections
224
Text
224
Hello
225
L2Tp-Incoming: L2TP Settings for Incoming L2TP Connections
226
L2Tp-Relay: Relay and Local Authentication Rules for L2TP
227
Fb105: FB105 Tunnel Definition
228
Fb105-Route: FB105 Routes
229
Ipsec-Ike: Ipsec Configuration (Ikev2)
230
Ike-Connection: Connection Configuration
230
Ipsec-Route: Ipsec Tunnel Routes
232
Ike-Roaming: IKE Roaming IP Pools
232
Ike-Proposal: IKE Security Proposal
233
Ipsec-Proposal: Ipsec AH/ESP Proposal
233
Ipsec-Manual: Peer Configuration
233
K.78. Ipsec-Manual: Elements
234
Ping: Ping/Graph Definition
235
Profile: Control Profile
235
Profile-Date: Test Passes if Within any of the Time Ranges Specified
236
Profile-Time: Test Passes if Within any of the Date/Time Ranges Specified
236
Profile-Ping: Test Passes if any Addresses Are Pingable
237
Shaper: Traffic Shaper
237
Shaper-Override: Traffic Shaper Override Based on Profile
238
Ip-Group: IP Group
238
Route-Override: Routing Override Rules
238
Session-Route-Rule: Routing Override Rule
239
Session-Route-Share: Route Override Load Sharing
240
Rule-Set: Firewall/Mapping Rule Set
240
Session-Rule: Firewall Rules
241
Session-Share: Firewall Load Sharing
242
Voip: Voice over IP Config
242
K.99. Voip: Attributes
243
Carrier: Voip Carrier Details
244
Voip: Elements
244
Telephone: Voip Telephone Authentication User Details
245
Tone: Tone Definitions
246
Ringgroup: Ring Groups
246
Etun: Ether Tunnel
247
Dhcp-Relay: DHCP Server Settings for Remote / Relayed Requests
248
Data Types
248
Autoloadtype: Type of S/W Auto Load
248
Config-Access: Type of Access User Has to Config
249
Eap-Method: EAP Access Method
249
Eap-Subsystem: Subsystem with EAP Access Control
249
Syslog-Severity: Syslog Severity
249
User-Level: User Login Level
249
Month: Month Name (3 Letter)
250
Syslog-Facility: Syslog Facility
250
Day: Day Name (3 Letter)
251
Radiuspriority: Options for Controlling Platform RADIUS Response Priority Tagging
251
Crossover: Crossover Configuration
252
Linkduplex: Physical Port Duplex Setting
252
Linkspeed: Physical Port Speed
252
Port: Physical Port
252
Radiustype: Type of RADIUS Server
252
Linkclock: Physical Port Gigabit Clock Master/Slave Setting
253
Linkflow: Physical Port Flow Control Setting
253
Linkled: LED Settings
253
Linkfault: Link Fault Type to Send
254
Linkpower: PHY Power Saving Options
254
Ramode: Ipv6 Route Announce Level
254
Trunk-Mode: Trunk Port more
254
Bgpmode: BGP Announcement Mode
255
Dhcpv6Control: Control for RA and Dhcpv6 Bits
255
Pppoe-Mode: Type of Pppoe Connection
255
Sfoption: Source Filter Option
255
Ramode: Ipv6 Route Announce Level
255
Pdp-Context-Type: Type of IP Connection
256
Ipsec-Type: Ipsec Encapsulation Type
256
Ipsec-Auth-Algorithm: Ipsec Authentication Algorithm
256
Ipsec-Crypt-Algorithm: Ipsec Encryption Algorithm
256
Peertype: BGP Peer Type
257
Ike-Authmethod: Authentication Method
257
Ike-Mode: Connection Setup Mode
257
Ike-PRF: IKE Pseudo-Random Function
257
Ike-DH: IKE Diffie-Hellman Group
258
Ike-ESN: IKE Sequence Number Support
258
Ipsec-Encapsulation: Manually Keyed Ipsec Encapsulation Mode
258
Switch: Profile Manual Setting
258
Dynamic-Graph: Type of Dynamic Graph
258
Firewall-Action: Firewall Action
259
Voip-Format: Number Presentation Format
259
Uknumberformat: Number Formatting Option
259
Recordoption: Recording Option
259
Ring-Group-Order: Order of Ring
259
Ring-Group-Type: Type of Ring When One Call in Queue
260
Record-Beep-Option: Record Beep Option
260
Basic Types
260
Index
263
Advertisement
Advertisement
Related Products
Fido VinCSS FIDO2 Touch 1
Fido Categories
Security System
Network Router
More Fido Manuals
Login
Sign In
OR
Sign in with Facebook
Sign in with Google
Upload manual
Upload from disk
Upload from URL