Sign In
Upload
Manuals
Brands
FireBrick Manuals
Gateway
FB6402
FireBrick FB6402 Manuals
Manuals and User Guides for FireBrick FB6402. We have
2
FireBrick FB6402 manuals available for free PDF download: User Manual
FireBrick FB6402 User Manual (196 pages)
FB6000 series Versatile Network Appliance
Brand:
FireBrick
| Category:
Gateway
| Size: 1 MB
Table of Contents
User Manual
1
Table of Contents
4
Preface
17
1 Introduction
18
The FB6000
18
Where Do I Start
18
What Can It Do
18
FB6402 Gigabit Stateful Firewall
19
Ethernet Port Capabilities
19
Product Variants in the FB6000 Series
19
About this Manual
19
Version
19
Intended Audience
20
Technical Details
20
Document Style
20
Document Conventions
20
Comments and Feedback
21
Additional Resources
21
Technical Support
21
IRC Channel
21
Application Notes
21
White Papers
21
Training Courses
22
2 Getting Started
23
IP Addressing
23
Accessing the Web-Based User Interface
23
IP Addresses to Access the Firebrick
23
Add a New User
24
Configuration Being Stored
25
Setting up a New User
25
3 Configuration
26
The Object Hierarchy
26
The Object Model
26
Formal Definition of the Object Model
27
Common Attributes
27
Configuration Methods
27
Web User Interface Overview
27
User Interface Layout
28
Customising the Layout
28
Main Menu
28
Config Pages and the Object Hierarchy
29
Configuration Categories
29
Object Settings
30
The "Setup" Category
30
Editing an "Interface" Object
31
Navigating Around the User Interface
32
Backing up / Restoring the Configuration
33
Configuration Using XML
33
Introduction to XML
33
The Root Element - <Config
34
Viewing or Editing XML
34
Example XML Configuration
34
Downloading/Uploading the Configuration
36
Download
36
Upload
37
4 System Administration
38
User Management
38
Login Level
38
Setting up a New User
38
Configuration Access Level
39
Login Idle Timeout
39
Restricting User Logins
39
Configuration Access Levels
39
Restrict by IP Address
39
User Login Levels
39
Logged in IP Address
40
Restrict by Profile
40
Password Change
40
One Time Password (OTP)
40
General System Settings
41
System Name (Hostname)
41
Administrative Details
41
System-Level Event Logging Control
41
Home Page Web Links
41
Software Upgrades
42
Software Release Types
42
Breakpoint Releases
42
Identifying Current Software Version
43
Internet-Based Upgrade Process
43
Manually Initiating Upgrades
43
Software Upgrade Available Notification
43
Controlling Automatic Software Updates
44
Manual Upgrade
44
Boot Process
45
LED Indications
45
Port Leds
45
Power LED Status Indications
45
5 Event Logging
46
Overview
46
Log Targets
46
Logging to Flash Memory
46
Logging to the Console
47
Enabling Logging
47
Logging to External Destinations
47
Syslog
47
Email
48
E-Mail Process Logging
49
Factory Reset Configuration Log Targets
49
Performance
49
Viewing Logs
49
Viewing Logs in the User Interface
49
Viewing Logs in the CLI Environment
50
System-Event Logging
50
Using Profiles
50
System-Event Logging Attributes
50
6 Interfaces and Subnets
51
Relationship between Interfaces and Physical Ports
51
Port Groups
51
Interfaces
51
Defining an Interface
51
Defining Subnets
52
Source Filtering
53
Using DHCP to Configure a Subnet
53
Setting up DHCP Server Parameters
53
Fixed/Static DHCP Allocations
54
Restricted Allocations
55
Special DHCP Options
56
DHCP Relay Agent
56
Physical Port Settings
56
Setting Duplex Mode
57
Defining Port LED Functions
57
7 Session Handling
58
Routing Vs. Firewalling
58
Session Tracking
58
Session Termination
59
Session Rules
59
Overview
59
Processing Flow
60
Action Attribute Values
60
Processing Flow Chart for Rule-Sets and Session-Rules
62
Defining Rule-Sets and Rules
63
Recommended Method of Implementing Firewalling
64
Changes to Session Traffic
65
Configuring Session Time-Outs
66
Graphing and Traffic Shaping
66
Load Balancing
66
NAT-PMP / PCP (Port Control Protocol)
67
Network Address Translation
68
When to Use NAT
68
NAT Algs
68
Setting NAT in Rules
69
What NAT Does
69
NAT with Pppoe
69
NAT with Other Types of External Routing
70
Mixing NAT and Non NAT
70
Carrier Grade NAT
70
Using NAT Setting on Subnets
70
8 Routing
72
Routing Logic
72
Routing Targets
73
Subnet Routes
73
Routing to an IP Address (Gateway Route)
73
Special Targets
74
Dynamic Route Creation / Deletion
74
Routing Tables
74
Bonding
74
Route Overrides
75
9 Profiles
76
Overview
76
Creating/Editing Profiles
76
Timing Control
76
Tests
77
General Tests
77
Ping Tests
77
Time/Date Tests
77
Inverting Overall Test Result
77
Manual Override
78
10 Traffic Shaping
79
Graphs and Shapers
79
Graphs
79
Shapers
80
Ad Hoc Shapers
80
Long Term Shapers
80
Multiple Shapers
80
Basic Principles
81
11 Tunnels
82
Ipsec (IP Security)
82
Introduction
82
Encryption
82
Integrity Checking
82
Authentication
83
Ike
83
Manual Keying
83
Identities and the Authentication Mechanism
84
Setting up Ipsec Connections
84
Global Ipsec Parameters
84
IKE and Ipsec Proposal Lists
85
IKE Connection Mode and Type
85
IKE Connections
85
IKE Proposals
85
IKE Roaming IP Pools
85
Authentication and IKE Identities
86
IP Addresses
86
Other Parameters
87
Road Warrior Connections
87
Routing
87
Setting up Manual Keying
87
Algorithms and Keys
88
IP Endpoints
88
Mode
88
Routing
88
Other Parameters
89
Using EAP with Ipsec/Ike
89
Using Certificates with Ipsec/Ike
89
Creating Certificates
91
Choice of Algorithms
91
NAT Traversal
92
Configuring a Road Warrior Server
93
Connecting to Non-Firebrick Devices
94
Using Strongswan on Linux
94
Setting up a Road Warrior VPN on an Android Client
95
Manual Keying Using Linux Ipsec-Tools
96
Setting up a Road Warrior VPN on an Ios (Iphone/Ipad) Client
96
FB105 Tunnels
97
Tunnel Wrapper Packets
98
Setting up a Tunnel
98
Viewing Tunnel Status
99
Dynamic Routes
99
Tunnel Bonding
99
Tunnels and NAT
99
Another Device Doing NAT
100
FB6000 Doing NAT
100
Ether Tunnelling
100
12 System Services
102
Protecting the FB6000
102
Common Settings
102
List of System Services
102
HTTP Server Configuration
103
Access Control
103
Trusted Addresses
103
Telnet Server Configuration
103
Access Control
104
DNS Configuration
104
Blocking DNS Names
104
Local DNS Responses
104
Auto DHCP DNS
104
NTP Configuration
105
SNMP Configuration
105
13 Network Diagnostic Tools
106
Firewalling Check
106
Access Check
107
Packet Dumping
107
Dump Parameters
108
Security Settings Required
108
IP Address Matching
108
Packet Types
109
Snaplen Specification
109
Using the Web Interface
109
Using an HTTP Client
109
Example Using Curl and Tcpdump
110
14 Vrrp
111
Virtual Routers
111
Configuring VRRP
112
Advertisement Interval
112
Priority
112
Using a Virtual Router
112
VRRP Versions
112
VRRP Version 2
112
VRRP Version 3
113
Compatibility
113
15 Bgp
114
What Is BGP
114
BGP Setup
114
Overview
114
Standards
114
Simple Example Setup
115
Peer Type
115
Peer Types
115
Route Filtering
116
Action Attributes
116
Matching Attributes
116
Well Known Community Tags
117
Announcing Black Hole Routes
117
Announcing Dead End Routes
118
Bad Optional Path Attributes
118
Network> Element
118
Route>, <Subnet> and Other Elements
118
Route Feasibility Testing
118
Network Attributes
118
Diagnostics
119
Router Shutdown
119
TTL Security
119
16 Command Line Interface
120
CIDR and CIDR Notation
121
MAC Addresses Usage
123
Multiple MAC Addresses
123
How the Firebrick Allocates MAC Addresses
124
Base MAC
124
Interface
124
Pppoe
124
Subnet
124
Running out of Macs
125
MAC Address on Label
125
Using with a DHCP Server
126
Vlans : a Primer
127
Firebrick Specific SNMP Objects
128
Iso.3.6.1.4.1.24693.1
128
Iso.3.6.1.4.1.24693.179
128
E. Command Line Reference
130
E.1.8. Logout
131
E.2. Networking Commands
132
E.2.6. See DHCP Allocations
133
E.3. Firewalling Commands
134
E.5.4. Make Outbound Command Session
135
File Types
137
F. Constant Quality Monitoring - Technical Details
137
F.1.3. Authenticated Access
138
Other Colours and Spacing
139
Overnight Archiving
139
Full URL Format
140
Load Handling
140
URL Formats
140
Graph Scores
141
Creating Graphs, and Graph Names
141
Hashed Passwords
142
Password Hashing
142
Salt
142
One Time Password Seed Hashing
143
Configuration Objects
145
Top Level
145
Config: Top Level Config
145
Objects
146
System: System Settings
146
Link: Web Links
147
User: Admin Users
147
Eap: Attributes
148
Eap: User Access Controlled by EAP
148
Log-Syslog: Syslog Logger Settings
148
Log: Attributes
148
Log: Elements
148
Log: Log Target Controls
148
Log-Email: Email Logger Settings
149
Ntp-Service: NTP Service Settings
150
Services: System Services
150
Snmp-Service: SNMP Service Settings
150
Telnet-Service: Telnet Service Settings
151
Dns-Service: DNS Service Settings
152
Http-Service: HTTP Service Settings
152
Dns-Block: Fixed Local DNS Blocks
153
Dns-Host: Fixed Local DNS Host Settings
153
Ethernet: Physical Port Controls
154
Sampling: Packet Sampling Configuration
154
Interface: Port-Group/Vlan Interface Settings
155
Portdef: Port Grouping and Naming
155
Subnet: Subnet Settings
156
Vrrp: VRRP Settings
157
Dhcps: DHCP Server Settings
158
Dhcp-Attr-Hex: DHCP Server Attributes (Hex)
159
Dhcp-Attr-String: DHCP Server Attributes (String)
159
Dhcp-Attr-Ip: DHCP Server Attributes (IP)
160
Dhcp-Attr-Number: DHCP Server Attributes (Numeric)
160
Route: Static Routes
160
Blackhole: Dead End Networks
161
Network: Locally Originated Networks
161
Loopback: Locally Originated Networks
162
Namedbgpmap: Mapping and Filtering Rules of BGP Prefixes
162
Bgp: Overall BGP Settings
163
Bgprule: Individual Mapping/Filtering Rule
163
Bgppeer: BGP Peer Definitions
164
Bgpmap: Mapping and Filtering Rules of BGP Prefixes
165
Cqm: Constant Quality Monitoring Settings
166
Text
167
Fb105: FB105 Tunnel Definition
168
Text
168
Fb105-Route: FB105 Routes
169
Ipsec-Ike: Ipsec Configuration (Ikev2)
169
Ike-Connection: Connection Configuration
170
Ipsec-Route: Ipsec Tunnel Routes
171
Ike-Proposal: IKE Security Proposal
172
Ike-Roaming: IKE Roaming IP Pools
172
Ipsec-Manual: Peer Configuration
173
Ipsec-Proposal: Ipsec AH/ESP Proposal
173
Profile: Control Profile
174
Profile-Date: Test Passes if Within any of the Time Ranges Specified
175
Profile-Time: Test Passes if Within any of the Date/Time Ranges Specified
175
Profile-Ping: Test Passes if any Addresses Are Pingable
176
Shaper: Traffic Shaper
176
Ip-Group: IP Group
177
Shaper-Override: Traffic Shaper Override Based on Profile
177
Route-Override: Routing Override Rules
178
Session-Route-Rule: Routing Override Rule
178
Rule-Set: Firewall/Mapping Rule Set
179
Session-Route-Share: Route Override Load Sharing
179
Session-Rule: Firewall Rules
180
Session-Share: Firewall Load Sharing
181
Dhcp-Relay: DHCP Server Settings for Remote / Relayed Requests
182
Etun: Ether Tunnel
182
Data Types
183
Autoloadtype: Type of S/W Auto Load
183
Config-Access: Type of Access User Has to Config
183
Eap-Subsystem: Subsystem with EAP Access Control
183
User-Level: User Login Level
183
Eap-Method: EAP Access Method
184
Syslog-Facility: Syslog Facility
184
Syslog-Severity: Syslog Severity
184
Day: Day Name (3 Letter)
185
Month: Month Name (3 Letter)
185
Crossover: Crossover Configuration
186
Linkduplex: Physical Port Duplex Setting
186
Linkflow: Physical Port Flow Control Setting
186
Linkspeed: Physical Port Speed
186
Port: Physical Port
186
Linkclock: Physical Port Gigabit Clock Master/Slave Setting
187
Linkled-G: Green LED Setting
187
Linkled-Y: Yellow LED Setting
187
Linkpower: PHY Power Saving Options
187
Linkfault: Link Fault Type to Send
188
Ramode: Ipv6 Route Announce Level
188
Sampling-Protocol: Sampling Protocol
188
Trunk-Mode: Trunk Port more
188
Bgpmode: BGP Announcement Mode
189
Dhcpv6Control: Control for RA and Dhcpv6 Bits
189
Peertype: BGP Peer Type
189
Sampling-Mode: Sampling Mode
189
Sfoption: Source Filter Option
189
Ike-Authmethod: Authentication Method
190
Ike-Mode: Connection Setup Mode
190
Ipsec-Auth-Algorithm: Ipsec Authentication Algorithm
190
Ipsec-Type: Ipsec Encapsulation Type
190
Peertype: BGP Peer Type
190
Ike-DH: IKE Diffie-Hellman Group
191
Ike-ESN: IKE Sequence Number Support
191
Ike-PRF: IKE Pseudo-Random Function
191
Ipsec-Crypt-Algorithm: Ipsec Encryption Algorithm
191
Dynamic-Graph: Type of Dynamic Graph
192
Firewall-Action: Firewall Action
192
Ipsec-Encapsulation: Manually Keyed Ipsec Encapsulation Mode
192
Switch: Profile Manual Setting
192
Index
195
Advertisement
FireBrick FB6402 User Manual (148 pages)
Versatile Network Appliance
Brand:
FireBrick
| Category:
Network Hardware
| Size: 0 MB
Table of Contents
User Manual
1
Table of Contents
4
Preface
11
1 Introduction
12
The FB6000
12
Where Do I Start
12
What Can It Do
12
Ethernet Port Capabilities
13
Product Variants in the FB6000 Series
13
About this Manual
13
Version
13
Intended Audience
13
Document Style
14
Document Conventions
14
Comments and Feedback
14
Additional Resources
15
Technical Support
15
IRC Channel
15
Application Notes
15
White Papers
15
Training Courses
15
2 Getting Started
16
IP Addressing
16
Accessing the Web-Based User Interface
16
Add a New User
17
Setting up a New User
18
Configuration Being Stored
18
3 Configuration
20
The Object Hierarchy
20
The Object Model
20
Formal Definition of the Object Model
21
Common Attributes
21
Configuration Methods
21
Web User Interface Overview
21
User Interface Layout
22
Customising the Layout
22
Main Menu
22
Config Pages and the Object Hierarchy
23
Configuration Categories
23
Object Settings
24
The "Setup" Category
24
Navigating Around the User Interface
25
Backing up / Restoring the Configuration
26
Configuration Using XML
26
Introduction to XML
26
Special Character Sequences
27
The Root Element - <Config
28
Viewing or Editing XML
28
Example XML Configuration
28
Downloading/Uploading the Configuration
29
Download
29
Upload
30
4 System Administration
31
User Management
31
Setting up a New User
31
Login Level
32
Configuration Access Level
32
Login Idle Timeout
32
Restricting User Logins
32
Restrict by IP Address
32
Restrict by Profile
33
General System Settings
33
Administrative Details
33
Home Page Web Links
33
System Name (Hostname)
33
System-Level Event Logging Control
33
Software Upgrades
34
Breakpoint Releases
34
Software Release Types
34
Identifying Current Software Version
35
Internet-Based Upgrade Process
35
Manually Initiating Upgrades
35
Software Upgrade Available Notification
35
Controlling Automatic Software Updates
36
Manual Upgrade
36
Boot Process
37
LED Indications
37
Port Leds
37
Power LED Status Indications
37
5 Event Logging
38
Overview
38
Log Targets
38
Logging to Flash Memory
38
Logging to the Console
39
Enabling Logging
39
Logging to External Destinations
39
Syslog
39
Email
40
E-Mail Process Logging
41
Factory Reset Configuration Log Targets
41
Performance
41
Viewing Logs
41
Viewing Logs in the User Interface
41
Viewing Logs in the CLI Environment
42
System-Event Logging
42
Using Profiles
42
6 Interfaces and Subnets
43
Relationship between Interfaces and Physical Ports
43
Port Groups
43
Interfaces
43
Defining Port Groups
44
Defining an Interface
45
Defining Subnets
45
Using DHCP to Configure a Subnet
46
Setting up DHCP Server Parameters
46
Fixed/Static DHCP Allocations
47
Partial-MAC-Address Based Allocations
47
Physical Port Settings
47
Disabling Auto-Negotiation
48
Setting Port Speed
48
Setting Duplex Mode
48
Defining Port LED Functions
48
Example Modified Port LED Functions
49
7 Routing
50
Routing Logic
50
Routing Targets
51
Subnet Routes
51
Routing to an IP Address (Gateway Route)
51
Special Targets
51
Dynamic Route Creation / Deletion
52
Routing Tables
52
8 Profiles
53
Overview
53
Creating/Editing Profiles
53
Timing Control
53
Tests
54
General Tests
54
Ping Tests
54
Time/Date Tests
54
Inverting Overall Test Result
54
Manual Override
54
9 Traffic Shaping
56
Graphs and Shapers
56
Graphs
56
Shapers
56
10 Pppoe
58
Types of DSL Line and Router in the United Kingdom
58
Definining Pppoe Links
59
Ipv6
59
Additional Options
59
MTU and TCP Fix
59
Logging
60
Service and Ac-Name
60
Speed and Graphs
60
11 Tunnels
61
FB105 Tunnels
61
Tunnel Wrapper Packets
61
Setting up a Tunnel
61
Viewing Tunnel Status
62
Dynamic Routes
62
Tunnel Bonding
62
Tunnels and NAT
63
Another Device Doing NAT
63
FB6000 Doing NAT
63
12 System Services
65
HTTP Server Configuration
65
Access Control
65
Trusted Addresses
66
Telnet Server Configuration
66
Access Control
66
DNS Configuration
67
NTP Configuration
67
SNMP Configuration
67
13 Network Diagnostic Tools
68
Access Check
68
Packet Dumping
69
Dump Parameters
69
Security Settings Required
70
IP Address Matching
70
Packet Types
70
Snaplen Specification
71
Using the Web Interface
71
Using an HTTP Client
71
Example Using Curl and Tcpdump
71
14 Vrrp
73
Virtual Routers
73
Configuring VRRP
73
Advertisement Interval
74
Priority
74
Using a Virtual Router
74
VRRP Versions
74
VRRP Version 2
74
VRRP Version 3
74
Compatibility
75
15 Command Line Interface
76
Command Line Reference
77
Check Access
78
Clear Bgp
79
Clear Dhcp
80
Clear L2Tp All
81
Clear L2Tp Session
82
Clear L2Tp Tunnel
83
Clear Pppoe
84
Delete Config
85
Delete Data
86
Delete Image
87
Ethernet Reset
88
Ethernet Stall
89
Exit
90
Kill Command Session
91
Kill Session
92
Login
93
Logout
94
Panic
95
Ping
96
Quit
97
Reboot
98
Set Boot Block
99
Set Command Screen Width
100
Show Arp
101
Show Bgp
102
Show Bgp Nexthop
103
Show Bgp Peer
104
Show Bgp Routes
105
Show Bgp Summary
106
Show Boot Log
107
Show Command Sessions
108
Show Dhcp
109
Show Dns
110
Show Ethernet Counters
111
Show Ethernet Status
112
Show Fb105
113
Show Flash Contents
114
Show Flash Log
115
Show L2Tp
116
Show L2Tp Session
117
Show L2Tp Sessions
118
Show L2Tp Tunnel
119
Show L2Tp Tunnels
120
Show Log
121
Show Memory
122
Show Pppoe
123
Show Profiles
124
Show Radius
125
Show Route
126
Show Routes
127
Show Sessions
128
Show Status
129
Show Subnet
130
Show Subnets
131
Show Uptime
132
Show Tasks
133
Show Vrrp
134
Start Command Session
135
Traceroute
136
Troff
137
Tron
138
Uptime
139
Factory Reset Procedure
140
CIDR and CIDR Notation
142
MAC Addresses Usage
144
18 Information Provided by Show Fb105 Command
145
C.1. DHCP Client Names Used
145
Vlans : a Primer
146
Index
147
Advertisement
Related Products
FireBrick FB6502
FireBrick FB6602
FireBrick FB6102
FireBrick FB6302
FireBrick FB6202
FireBrick FB6000 Series
FireBrick FB2700
FireBrick Categories
Network Hardware
Gateway
Network Router
More FireBrick Manuals
Login
Sign In
OR
Sign in with Facebook
Sign in with Google
Upload manual
Upload from disk
Upload from URL