Sign In
Upload
Manuals
Brands
FireBrick Manuals
Network Router
FB2700
FireBrick FB2700 Manuals
Manuals and User Guides for FireBrick FB2700. We have
2
FireBrick FB2700 manuals available for free PDF download: User Manual, Quick Start Manual
FireBrick FB2700 User Manual (264 pages)
Brand:
FireBrick
| Category:
Network Router
| Size: 2 MB
Table of Contents
User Manual
1
Table of Contents
4
Preface
21
1 Introduction
22
The FB2700
22
Where Do I Start
22
What Can It Do
22
Ethernet Port Capabilities
23
Differences between the Devices in the Fb2X00 Series
23
Software Features
23
Migration from Previous Firebrick Models
23
About this Manual
24
Version
24
Intended Audience
24
Technical Details
24
Document Style
24
Document Conventions
25
Comments and Feedback
25
Additional Resources
25
Technical Support
25
IRC Channel
26
Application Notes
26
White Papers
26
Training Courses
26
2 Getting Started
27
IP Addressing
27
Accessing the Web-Based User Interface
27
IP Addresses to Access the Firebrick
27
Add a New User
28
Setting up a New User
29
Configuration Being Stored
29
3 Configuration
30
The Object Hierarchy
30
The Object Model
30
Formal Definition of the Object Model
31
Common Attributes
31
Configuration Methods
31
Web User Interface Overview
31
User Interface Layout
32
Customising the Layout
32
Main Menu
32
Config Pages and the Object Hierarchy
33
Configuration Categories
33
Object Settings
34
The "Setup" Category
34
Editing an "Interface" Object
35
Navigating Around the User Interface
36
Backing up / Restoring the Configuration
37
Configuration Using XML
37
Introduction to XML
37
Example XML Configuration
38
The Root Element - <Config
38
Viewing or Editing XML
38
Downloading/Uploading the Configuration
40
Download
40
Upload
41
4 System Administration
42
User Management
42
Login Level
42
Setting up a New User
42
Configuration Access Level
43
Login Idle Timeout
43
Restricting User Logins
43
Restrict by IP Address
43
User Login Levels
43
Configuration Access Levels
43
Logged in IP Address
44
Restrict by Profile
44
Password Change
44
One Time Password (OTP)
44
General System Settings
45
Administrative Details
45
Home Page Web Links
45
System Name (Hostname)
45
System-Level Event Logging Control
45
OTP Seed Hashing
46
Password Hashing
46
Software Upgrades
47
Breakpoint Releases
47
Software Release Types
47
Identifying Current Software Version
48
Internet-Based Upgrade Process
48
Manually Initiating Upgrades
48
Controlling Automatic Software Updates
49
Manual Upgrade
49
Software Upgrade Available Notification
49
Boot Process
50
LED Indications
50
Port Leds
50
Power LED Status Indications
50
5 Event Logging
51
Overview
51
Log Targets
51
Logging to Flash Memory
51
Logging to the Console
52
Enabling Logging
52
Logging to External Destinations
52
Syslog
52
Email
53
E-Mail Process Logging
54
Factory Reset Configuration Log Targets
54
Performance
54
Viewing Logs
54
Viewing Logs in the User Interface
54
Viewing Logs in the CLI Environment
55
System-Event Logging
55
Using Profiles
55
System-Event Logging Attributes
55
6 Interfaces and Subnets
56
Relationship between Interfaces and Physical Ports
56
Port Groups
56
Interfaces
56
Defining Port Groups
57
Defining an Interface
57
Defining Subnets
58
Source Filtering
59
Using DHCP to Configure a Subnet
59
Setting up DHCP Server Parameters
59
Fixed/Static DHCP Allocations
60
Restricted Allocations
61
Special DHCP Options
62
DHCP Relay Agent
62
Physical Port Settings
62
Disabling Auto-Negotiation
63
Setting Port Speed
63
Setting Duplex Mode
63
Defining Port LED Functions
63
Example Modified Port LED Functions
64
7 Session Handling
65
Routing Vs. Firewalling
65
Session Tracking
65
Session Termination
66
Session Rules
66
Overview
66
Processing Flow
67
Action Attribute Values
67
Processing Flow Chart for Rule-Sets and Session-Rules
69
Defining Rule-Sets and Rules
70
Recommended Method of Implementing Firewalling
71
Changes to Session Traffic
72
Configuring Session Time-Outs
73
Graphing and Traffic Shaping
73
Load Balancing
73
Network Address Translation
74
NAT Algs
74
When to Use NAT
74
NAT with Pppoe
75
Setting NAT in Rules
75
What NAT Does
75
Carrier Grade NAT
76
Mixing NAT and Non NAT
76
NAT with Dongles
76
NAT with Other Types of External Routing
76
Using NAT Setting on Subnets
77
8 Routing
78
Routing Logic
78
Routing Targets
79
Subnet Routes
79
Routing to an IP Address (Gateway Route)
79
Special Targets
80
Dynamic Route Creation / Deletion
80
Routing Tables
80
Bonding
80
Route Overrides
81
9 Profiles
82
Overview
82
Creating/Editing Profiles
82
Timing Control
82
Tests
83
General Tests
83
Ping Tests
83
Time/Date Tests
83
Inverting Overall Test Result
84
Manual Override
84
10 Traffic Shaping
85
Graphs and Shapers
85
Graphs
85
Shapers
86
Ad Hoc Shapers
86
Long Term Shapers
86
Multiple Shapers
87
Basic Principles
87
11 Pppoe
88
Types of DSL Line and Router in the United Kingdom
88
Definining Pppoe Links
89
Ipv6
89
Additional Options
89
MTU and TCP Fix
89
Logging
90
Service and Ac-Name
90
Speed and Graphs
90
12 Tunnels
91
Ipsec (IP Security)
91
Introduction
91
Encryption
91
Integrity Checking
91
Authentication
92
Ike
92
Manual Keying
92
Identities and the Authentication Mechanism
93
Setting up Ipsec Connections
93
Global Ipsec Parameters
93
IKE and Ipsec Proposal Lists
94
IKE Connection Mode and Type
94
IKE Connections
94
IKE Proposals
94
IKE Roaming IP Pools
94
Authentication and IKE Identities
95
IP Addresses
95
Other Parameters
96
Road Warrior Connections
96
Routing
96
Setting up Manual Keying
96
Algorithms and Keys
97
IP Endpoints
97
Mode
97
Routing
97
Other Parameters
98
Using EAP with Ipsec/Ike
98
Using Certificates with Ipsec/Ike
98
Creating Certificates
100
Choice of Algorithms
100
NAT Traversal
101
Configuring a Road Warrior Server
102
Connecting to Non-Firebrick Devices
103
Using Strongswan on Linux
103
Setting up a Road Warrior VPN on an Android Client
104
Manual Keying Using Linux Ipsec-Tools
105
Setting up a Road Warrior VPN on an Ios (Iphone/Ipad) Client
105
FB105 Tunnels
106
Tunnel Wrapper Packets
107
Setting up a Tunnel
107
Viewing Tunnel Status
108
Dynamic Routes
108
Tunnel Bonding
108
Tunnels and NAT
108
Another Device Doing NAT
109
FB2700 Doing NAT
109
Ether Tunnelling
109
13 USB Port
111
USB Configuration
111
Dongle Configuration
111
14 System Services
112
Protecting the FB2700
112
Common Settings
112
List of System Services
112
HTTP Server Configuration
113
Access Control
113
Trusted Addresses
113
List of System Services
113
Telnet Server Configuration
114
Access Control
114
DNS Configuration
114
Blocking DNS Names
114
Local DNS Responses
114
Auto DHCP DNS
115
NTP Configuration
115
SNMP Configuration
115
RADIUS Configuration
115
RADIUS Client
115
RADIUS Server (Platform RADIUS)
115
RADIUS Client Settings
116
Server Blacklisting
116
15 Network Diagnostic Tools
117
Firewalling Check
117
Access Check
118
Packet Dumping
118
Dump Parameters
119
Security Settings Required
119
IP Address Matching
120
Packet Types
120
Snaplen Specification
120
Using the Web Interface
120
Using an HTTP Client
121
Example Using Curl and Tcpdump
121
16 Vrrp
122
Virtual Routers
122
Configuring VRRP
123
Advertisement Interval
123
Priority
123
Using a Virtual Router
123
VRRP Versions
123
VRRP Version 2
123
VRRP Version 3
124
Compatibility
124
17 Voip
125
What Is Voip
125
Registration and Proxies
125
Registrar
125
Proxy
125
Home/Office Phone System
126
Network Address Translation
126
Number Plan
127
Telephone Handsets
127
Voip Call Carriers
128
Hunt Groups
129
Ring Type
129
Ring Order
130
Overflow
130
Out of Hours
130
Call Pickup/Steal
130
Busy Lamp Field
131
Using RADIUS
131
RADIUS Accounting
131
RADIUS Authentication
131
Call Routing by RADIUS
132
Call Recording
133
Access-Accept
133
Voicemail and IVR Services
134
Call Data Records
134
Technical Details
135
Custom Tones
135
Default Tones
135
18 Bgp
137
What Is BGP
137
BGP Setup
137
Overview
137
Standards
137
Simple Example Setup
138
Peer Type
138
Peer Types
138
Route Filtering
139
Action Attributes
139
Matching Attributes
139
Announcing Black Hole Routes
140
Well Known Community Tags
140
Announcing Dead End Routes
141
Bad Optional Path Attributes
141
Network> Element
141
Route Feasibility Testing
141
Route>, <Subnet> and Other Elements
141
Network Attributes
141
Diagnostics
142
Router Shutdown
142
TTL Security
142
19 Ospf
143
What Is OSPF
143
OSPF Setup
143
Overview
143
Standards
143
Simple Example Setup
144
Ospf> Configelement
144
20 Internet Service Providers
145
Background
145
How It All Began
145
Point to Point Protocol
145
L2Tp
145
Broadband
146
Radius
146
Bgp
146
Incoming L2TP Connections
146
The Importance of CQM Graphs
147
Authentication
147
Accounting
148
RADIUS Control Messages
148
Pppoe
148
Typical Configuration
148
Interlink Subnet
148
BGP with Carrier
149
RADIUS Session Steering
149
L2TP Endpoints
150
Isp Radius
150
21 Command Line Interface
151
Factory Reset Procedure
152
CIDR and CIDR Notation
154
MAC Addresses Usage
156
Multiple MAC Addresses
156
How the Firebrick Allocates MAC Addresses
157
Base MAC
157
Interface
157
Pppoe
157
Subnet
157
Running out of Macs
158
MAC Address on Label
158
Using with a DHCP Server
159
Vlans : a Primer
160
Supported L2TP Attribute/Value Pairs
161
Start-Control-Connection-Request
161
Start-Control-Connection-Reply
161
Start-Control-Connection-Connected
162
Stop-Control-Connection-Notification
162
Hello
162
Incoming-Call-Request
162
Incoming-Call-Reply
163
Incoming-Call-Connected
163
Outgoing-Call-Request
163
Outgoing-Call-Reply
164
Outgoing-Call-Connected
164
Call-Disconnect-Notify
164
WAN-Error-Notify
164
Set-Link-Info
164
Ocrp
164
Occn
164
Cdn
164
Wen
164
Sli
164
Notes
165
BT Specific Notes
165
IP over LCP
165
Supported RADIUS Attribute/Value Pairs for L2TP Operation
166
Authentication Request
166
Access-Request
166
Authentication Response
167
Accepted Authentication
167
Access-Accept
167
Prefix Delegation
168
Rejected Authentication
169
Accounting Start
169
Accounting-Start
169
Access-Reject
169
Accounting Interim
170
Accounting-Interim
170
Accounting Stop
171
Accounting-Stop
171
Disconnect
171
Change of Authorisation
171
Change-Of-Authorisation
171
Filter ID
172
Filter-ID
172
Notes
173
L2TP Relay
173
Closed User Group
174
IP over LCP
174
LCP Echo and CQM Graphs
174
Routing Table
174
Supported RADIUS Attribute/Value Pairs for Voip Operation
175
Authentication Request
175
Access-Request
175
Authentication Response
176
Accepted Authentication (Invite)
176
Accepted Authentication (Registration)
176
Challenge Authentication
176
Access-Accept
176
Rejected Authentication
177
Accounting Start
177
Accounting-Start
177
Accounting Interim
177
Accounting-Interim
177
Access-Reject
177
Accounting Stop
178
Accounting-Stop
178
Disconnect
178
Change of Authorisation
179
Change-Of-Authorisation
179
Firebrick Specific SNMP Objects
180
BGP Information
180
L2TP Information
180
Iso.3.6.1.4.1.24693.179
180
Iso.3.6.1.4.1.24693.1701
180
Monitoring Information
181
Command Line Reference
182
General Commands
182
General Status
182
Login
182
Memory Usage
182
Process/Task Usage
182
Trace off
182
Trace on
182
Uptime
182
Disable Profile Control Switch
183
Enable Profile Control Switch
183
Load XML Configuration
183
Logout
183
See XML Configuration
183
Show DNS Resolvers
183
Show Profile Status
183
Show RADIUS Servers
183
Networking Commands
184
List Routes
184
List Routing Next Hops
184
Ping and Trace
184
Show a Route from the Routing Table
184
Subnets
184
Clear DHCP Allocations
185
Lock DHCP Allocations
185
Name DHCP Allocations
185
See DHCP Allocations
185
Send Wake-On-LAN Packet
185
Show ARP/ND Status
185
Show VRRP Status
185
Unlock DHCP Allocations
185
Firewalling Commands
186
Check Access to Services
186
Check Firewall Logic
186
Usb/Dongle Commands
186
Reset Ppp/Dongle Data Connection
186
Reset USB Interface and All Attached Devices
186
Show Dongle Connectoons
186
L2TP Commands
186
BGP Commands
186
OSPF Commands
187
Pppoe Commands
187
Voip Commands
187
Dongle/Usb Commands
187
Advanced Commands
187
Panic
187
Reboot
187
Screen Width
187
Boot Log
188
Delete Block from Flash
188
Flash Log
188
Flash Memory List
188
Kill Command Session
188
Make Outbound Command Session
188
Show Command Sessions
188
Constant Quality Monitoring - Technical Details
189
Broadband Back-Haul Providers
189
Access to Graphs and Csvs
189
Trusted Access
189
File Types
189
Dated Information
190
Authenticated Access
190
Graph Display Options
190
Data Points
190
Additional Text
191
Other Colours and Spacing
191
Overnight Archiving
191
Full URL Format
192
Load Handling
192
Graph Scores
192
URL Formats
192
Creating Graphs, and Graph Names
193
Configuration Objects
194
Top Level
194
Config: Top Level Config
194
Objects
195
System: System Settings
195
Link: Web Links
196
User: Admin Users
196
Eap: User Access Controlled by EAP
197
Log: Log Target Controls
197
Eap: Attributes
197
Log: Attributes
197
Log: Elements
197
Log-Syslog: Syslog Logger Settings
198
Log-Email: Email Logger Settings
198
Services: System Services
199
Snmp-Service: SNMP Service Settings
199
Ntp-Service: NTP Service Settings
199
Telnet-Service: Telnet Service Settings
200
Http-Service: HTTP Service Settings
201
Dns-Service: DNS Service Settings
201
Dns-Host: Fixed Local DNS Host Settings
202
Dns-Block: Fixed Local DNS Blocks
202
Radius-Service: RADIUS Service Definition
203
Radius-Service-Match: Matching Rules for RADIUS Service
204
Radius-Service-Match: Attributes
204
Radius-Server: RADIUS Server Settings
205
Ethernet: Physical Port Controls
206
Sampling: Packet Sampling Configuration
206
Portdef: Port Grouping and Naming
207
Interface: Port-Group/Vlan Interface Settings
207
Subnet: Subnet Settings
208
Vrrp: VRRP Settings
209
Dhcps: DHCP Server Settings
210
Dhcp-Attr-Hex: DHCP Server Attributes (Hex)
211
Dhcp-Attr-String: DHCP Server Attributes (String)
211
Dhcps: Elements
211
Dhcp-Attr-String: Attributes
211
Dhcp-Attr-Number: DHCP Server Attributes (Numeric)
212
Dhcp-Attr-Ip: DHCP Server Attributes (IP)
212
Pppoe: Pppoe Settings
212
Dhcp-Attr-Number: Attributes
212
Ppp-Route: PPP Routes
213
Pppoe: Elements
213
Usb: USB 3G/Dongle Settings
214
Dongle: 3G/Dongle Settings
214
Route: Static Routes
215
Network: Locally Originated Networks
216
Blackhole: Dead End Networks
216
Loopback: Locally Originated Networks
217
Ospf: Overall OSPF Settings
217
Namedbgpmap: Mapping and Filtering Rules of BGP Prefixes
218
Bgprule: Individual Mapping/Filtering Rule
219
Bgp: Overall BGP Settings
219
Bgppeer: BGP Peer Definitions
220
K.56. Bgppeer: Elements
221
Bgpmap: Mapping and Filtering Rules of BGP Prefixes
222
Cqm: Constant Quality Monitoring Settings
222
L2Tp: L2TP Settings
224
L2Tp-Outgoing: L2TP Settings for Outgoing L2TP Connections
224
Text
224
L2Tp-Incoming: L2TP Settings for Incoming L2TP Connections
226
L2Tp-Relay: Relay and Local Authentication Rules for L2TP
227
Fb105: FB105 Tunnel Definition
228
Fb105-Route: FB105 Routes
229
Ipsec-Ike: Ipsec Configuration (Ikev2)
230
Ike-Connection: Connection Configuration
230
Ipsec-Route: Ipsec Tunnel Routes
232
Ike-Roaming: IKE Roaming IP Pools
232
Ike-Proposal: IKE Security Proposal
233
Ipsec-Proposal: Ipsec AH/ESP Proposal
233
Ipsec-Manual: Peer Configuration
233
Ping: Ping/Graph Definition
234
Profile: Control Profile
235
Profile-Date: Test Passes if Within any of the Time Ranges Specified
236
Profile-Time: Test Passes if Within any of the Date/Time Ranges Specified
236
Profile-Ping: Test Passes if any Addresses Are Pingable
237
Shaper: Traffic Shaper
237
Shaper-Override: Traffic Shaper Override Based on Profile
237
Ip-Group: IP Group
238
Route-Override: Routing Override Rules
238
Session-Route-Rule: Routing Override Rule
239
Session-Route-Share: Route Override Load Sharing
239
Rule-Set: Firewall/Mapping Rule Set
240
Session-Rule: Firewall Rules
241
Session-Share: Firewall Load Sharing
242
Voip: Voice over IP Config
242
Carrier: Voip Carrier Details
244
Voip: Elements
244
Telephone: Voip Telephone Authentication User Details
245
Tone: Tone Definitions
246
Ringgroup: Ring Groups
246
Etun: Ether Tunnel
247
Dhcp-Relay: DHCP Server Settings for Remote / Relayed Requests
248
Data Types
248
Autoloadtype: Type of S/W Auto Load
248
Config-Access: Type of Access User Has to Config
248
Eap-Method: EAP Access Method
249
Eap-Subsystem: Subsystem with EAP Access Control
249
Syslog-Severity: Syslog Severity
249
User-Level: User Login Level
249
Month: Month Name (3 Letter)
250
Syslog-Facility: Syslog Facility
250
Day: Day Name (3 Letter)
251
Radiuspriority: Options for Controlling Platform RADIUS Response Priority Tagging
251
Radiustype: Type of RADIUS Server
251
Crossover: Crossover Configuration
252
Linkduplex: Physical Port Duplex Setting
252
Linkflow: Physical Port Flow Control Setting
252
Linkspeed: Physical Port Speed
252
Port: Physical Port
252
Linkclock: Physical Port Gigabit Clock Master/Slave Setting
253
Linkled: LED Settings
253
Linkfault: Link Fault Type to Send
254
Linkpower: PHY Power Saving Options
254
Ramode: Ipv6 Route Announce Level
254
Sampling-Protocol: Sampling Protocol
254
Trunk-Mode: Trunk Port more
254
Bgpmode: BGP Announcement Mode
255
Dhcpv6Control: Control for RA and Dhcpv6 Bits
255
Sampling-Mode: Sampling Mode
255
Sfoption: Source Filter Option
255
Ipsec-Auth-Algorithm: Ipsec Authentication Algorithm
256
Ipsec-Crypt-Algorithm: Ipsec Encryption Algorithm
256
Ipsec-Type: Ipsec Encapsulation Type
256
Pdp-Context-Type: Type of IP Connection
256
Pppoe-Mode: Type of Pppoe Connection
256
Ike-Authmethod: Authentication Method
257
Ike-Mode: Connection Setup Mode
257
Ike-PRF: IKE Pseudo-Random Function
257
Peertype: BGP Peer Type
257
Dynamic-Graph: Type of Dynamic Graph
258
Ike-DH: IKE Diffie-Hellman Group
258
Ike-ESN: IKE Sequence Number Support
258
Ipsec-Encapsulation: Manually Keyed Ipsec Encapsulation Mode
258
Switch: Profile Manual Setting
258
Firewall-Action: Firewall Action
259
Recordoption: Recording Option
259
Ring-Group-Order: Order of Ring
259
Uknumberformat: Number Formatting Option
259
Voip-Format: Number Presentation Format
259
Record-Beep-Option: Record Beep Option
260
Ring-Group-Type: Type of Ring When One Call in Queue
260
Basic Types
260
Index
263
Advertisement
FireBrick FB2700 Quick Start Manual (2 pages)
Brand:
FireBrick
| Category:
Network Router
| Size: 0 MB
Table of Contents
Factory Reset
1
Getting Started
2
Accessing the Web-Based User Interface
2
Method 1 - Use the Firebrick's DHCP Server to Configure a Computer
2
Add a New User
2
Method 2 - Configure a Computer with a Fixed IP Address
2
Remove Temporary Subnets
2
Method 3 - Use an Existing DHCP Server to Configure the Firebrick
2
Advertisement
Related Products
FireBrick FB6502
FireBrick FB6602
FireBrick FB6402
FireBrick FB6102
FireBrick FB6302
FireBrick FB6202
FireBrick FB6000 Series
FireBrick 105
FireBrick Categories
Network Hardware
Gateway
Network Router
More FireBrick Manuals
Login
Sign In
OR
Sign in with Facebook
Sign in with Google
Upload manual
Upload from disk
Upload from URL