+ All Categories

FVX538

Date post: 06-Jan-2016
Category:
Upload: addison
View: 42 times
Download: 0 times
Share this document with a friend
Description:
FVX538. ProSafe VPN Firewall 200. Main Features. 8 10/100 ports and 1 gigabit LAN port. One console port. SNMP support (optimized for NMS100) – SNMPv2. QoS traffic prioritization. Hardware DMZ. - PowerPoint PPT Presentation
71
NETGEAR CONFIDENTIAL FVX538 ProSafe VPN Firewall 200
Transcript
Page 1: FVX538

NETGEAR CONFIDENTIAL

FVX538

ProSafe VPN Firewall 200

Page 2: FVX538

NETGEAR CONFIDENTIAL

Main Features

• 8 10/100 ports and 1 gigabit LAN port.

• One console port.

• SNMP support (optimized for NMS100) – SNMPv2.

• QoS traffic prioritization.

• Hardware DMZ.

• Security co-processor for optimized throughput performance, 90+ Mbps WAN-LAN and up to 100 Mbps 3DES throughput.

• SPI Firewall and multi-NAT.

• Support 200 VPN tunnels.

• Includes VPN client software with 5-users license.

• Rack-mountable.

• Future upgradability to SSL VPN, IDS, Anti-virus, anti-spam and anti-spyware security measures.

Page 3: FVX538

NETGEAR CONFIDENTIAL

ProSafe Firewalls ComparisonFeature FVS318 v3 FVS338 FVL328 FVX538

VPN Tunnels 8 50 100 200WAN-to-LAN throughput 12. 5 Mbps 90+ Mbps 54 Mbps 90+ Mbps

3DES Throughput 1.2 Mbps 60+ Mbps 15 Mbps 90+ MbpsLAN Ports (8)10/100 LAN (8)10/100 LAN (8) 10/100 LAN (8) 10/100 LAN, (1) Gigabit LANWAN Ports (1)10/100Mbps WAN (1)10/100Mbps WAN (1)10/100Mbps WAN (2)10/100Mbps WANSerial port no yes, for analog backup no yes, console port for local mgmtEncryption DES, 3DES, AES DES, 3DES, AES DES, 3DES DES, 3DES, AES

Encryption Method Hardware for 3DES Hardware Hardware HardwareQoS no yes no yes

SNMP no yes no yesSIP aware no future upgrade no future upgradeSSL VPN no no no future upgrade

Digital Certificate Support yes yes yes yesNAT On/Off no yes yes yesMultNAT no yes yes yes

Other VPN01L included VPN05L includedCLI no yes no yes

Rack mountable no no no yesICSA Firewall yes in testing yes in testing

VPNC certifiable yes yes yes yesUS List Price $157 $278 $418 $557

Average Catalog $109 $199 $249 $399

Page 4: FVX538

NETGEAR CONFIDENTIAL

Front Panel

Page 5: FVX538

NETGEAR CONFIDENTIAL

Rear Panel

Page 6: FVX538

NETGEAR CONFIDENTIAL

Bottom Label

Page 7: FVX538

NETGEAR CONFIDENTIAL

Console - CLI

Page 8: FVX538

NETGEAR CONFIDENTIAL

GUI

Page 9: FVX538

NETGEAR CONFIDENTIAL

http://192.168.1.1

• Username: admin

• Password: password

Page 10: FVX538

NETGEAR CONFIDENTIAL

WAN Setup – WAN 1 ISP

Page 11: FVX538

NETGEAR CONFIDENTIAL

Setup Wizard

Page 12: FVX538

NETGEAR CONFIDENTIAL

WAN Status

Page 13: FVX538

NETGEAR CONFIDENTIAL

WAN Setup – WAN 2 ISP

Page 14: FVX538

NETGEAR CONFIDENTIAL

WAN Setup - Mode

Page 15: FVX538

NETGEAR CONFIDENTIAL

WAN Setup – Protocol Binding

Page 16: FVX538

NETGEAR CONFIDENTIAL

WAN Setup - Options

28Kbps to 100Mbps

Page 17: FVX538

NETGEAR CONFIDENTIAL

WAN Setup – Dynamic DNS

Page 18: FVX538

NETGEAR CONFIDENTIAL

WAN Setup – Traffic Meter

Page 19: FVX538

NETGEAR CONFIDENTIAL

WAN Setup – Traffic Meter

Statistic by Protocol

Page 20: FVX538

NETGEAR CONFIDENTIAL

Security – Groups and Hosts

Page 21: FVX538

NETGEAR CONFIDENTIAL

Security – Groups and Hosts

Add

Page 22: FVX538

NETGEAR CONFIDENTIAL

Security – Groups and Hosts

Edit Group Names

Page 23: FVX538

NETGEAR CONFIDENTIAL

Security – Source MAC Filter

Page 24: FVX538

NETGEAR CONFIDENTIAL

Security – Block Sites

Page 25: FVX538

NETGEAR CONFIDENTIAL

Security – Rules

Page 26: FVX538

NETGEAR CONFIDENTIAL

Security – Rules – Outbound Services

Page 27: FVX538

NETGEAR CONFIDENTIAL

Security – Rules – Inbound Services

Page 28: FVX538

NETGEAR CONFIDENTIAL

Security - Services

Page 29: FVX538

NETGEAR CONFIDENTIAL

Security - Schedule

Page 30: FVX538

NETGEAR CONFIDENTIAL

Security – Logs and Emails

Page 31: FVX538

NETGEAR CONFIDENTIAL

Security – View Log

Page 32: FVX538

NETGEAR CONFIDENTIAL

Security – Logs and Emails

Email Logs and Syslog

Page 33: FVX538

NETGEAR CONFIDENTIAL

VPN – VPN Wizard Box-to-box

Page 34: FVX538

NETGEAR CONFIDENTIAL

VPN – VPN Wizard Box-to-box

Result:

Page 35: FVX538

NETGEAR CONFIDENTIAL

VPN – VPN Wizard Client-to-box

Page 36: FVX538

NETGEAR CONFIDENTIAL

VPN – VPN Wizard Client-to-box

Page 37: FVX538

NETGEAR CONFIDENTIAL

VPN – VPN Status

Page 38: FVX538

NETGEAR CONFIDENTIAL

VPN – IKE Policies

Page 39: FVX538

NETGEAR CONFIDENTIAL

VPN – IKE Policies - Add

Page 40: FVX538

NETGEAR CONFIDENTIAL

VPN – VPN Policies

Page 41: FVX538

NETGEAR CONFIDENTIAL

VPN – VPN Policies – Add Auto Policy

Page 42: FVX538

NETGEAR CONFIDENTIAL

VPN – VPN Policies – Add Manual Policy

Page 43: FVX538

NETGEAR CONFIDENTIAL

VPN - CAs

Page 44: FVX538

NETGEAR CONFIDENTIAL

VPN - Certificates

Page 45: FVX538

NETGEAR CONFIDENTIAL

VPN - CRL

Page 46: FVX538

NETGEAR CONFIDENTIAL

Maintenance – Router Status

Page 47: FVX538

NETGEAR CONFIDENTIAL

Maintenance – Router Status

Show Statistics

Page 48: FVX538

NETGEAR CONFIDENTIAL

Maintenance – Set Password

Page 49: FVX538

NETGEAR CONFIDENTIAL

Maintenance – Remote management

Page 50: FVX538

NETGEAR CONFIDENTIAL

Maintenance - SNMP

Page 51: FVX538

NETGEAR CONFIDENTIAL

Maintenance - Diagnostics

Page 52: FVX538

NETGEAR CONFIDENTIAL

Maintenance – Backup Settings

Page 53: FVX538

NETGEAR CONFIDENTIAL

Maintenance – Router Upgrade

Page 54: FVX538

NETGEAR CONFIDENTIAL

Advanced – LAN Setup

Page 55: FVX538

NETGEAR CONFIDENTIAL

Advanced – LAN Setups

Multi-Home LAN IP Setups

Page 56: FVX538

NETGEAR CONFIDENTIAL

Advanced – DMZ Setups

Page 57: FVX538

NETGEAR CONFIDENTIAL

Port Triggering

Once configured, operation is as follows:

1. A PC makes an outgoing connection using a port number defined in the Port Triggering table.

2. This Router records this connection, opens the INCOMING port or ports associated with this entry in the Port Triggering table, and associates them with the PC.

3. The remote system receives the PCs request, and responds using a different port number.

4. This Router matches the response to the previous request, and forwards the response to the PC. (Without Port Triggering, this response would be treated as a new connection request rather than a response. As such, it would be handled in accordance with the Port Forwarding rules.)

Page 58: FVX538

NETGEAR CONFIDENTIAL

Port Triggering

Note

• Only 1 PC can use a "Port Triggering" application at any time.

• After a PC has finished using a "Port Triggering" application, there is a "Time-out" period before the application can be used by another PC. This is required because this Router cannot be sure when the application has terminated.

• Normally for games and chat.

Page 59: FVX538

NETGEAR CONFIDENTIAL

Advanced – Port Triggering

Page 60: FVX538

NETGEAR CONFIDENTIAL

Advanced – Static Routes

Page 61: FVX538

NETGEAR CONFIDENTIAL

Knowledge Base / Documentation

Page 62: FVX538

NETGEAR CONFIDENTIAL

Troubleshooting

Page 63: FVX538

NETGEAR CONFIDENTIAL

FAQ#1

• How does the FVX538 support QoS?

• The FVS538 prioritizes the routing of a packet through the router according to the TOS bit in the packet’s layer3 header. For a particular service, you can override the packet’s specified priority by selecting a different priority in the Services menu, Inbound rules or Outbound Rules. Changing the priority setting will affect the priority given to the packet by the router, but will not actually alter the TOS bits in the packet.

Page 64: FVX538

NETGEAR CONFIDENTIAL

FAQ#2

• When I use load balancing through two ISPs, I have problems sending email, getting DNS, or using my ISP’s news server.

• When your ISP provides services such as email, DNS, or newsgroups, it may require that requests for service originate from an IP address within its domain. If you require one of these services from a particular ISP, you should use your router’s Protocol Binding feature to make sure your requests always use the WAN port connected to that ISP.

Page 65: FVX538

NETGEAR CONFIDENTIAL

FAQ#3

• My ISP has provided me with a range of public IP addresses. How can I assign them to servers behind the FVX538?

• When you configure the ISP Settings of your router, assign one IP address as the WAN address to be used by your PCs as the main NAT address for general traffic. In the DMZ Setup menu, you can assign the additional public IP addresses to individual PCs on either your LAN or DMZ (if you have activated port 8 as your DMZ port). To allow inbound traffic to reach one of these PCs, you must create an Inbound Rule for the desired service and set the rule’s Destination Address to the public IP address assigned to that PC.

Page 66: FVX538

NETGEAR CONFIDENTIAL

FAQ#4

• My ISP has provided me with a range of public IP addresses. How can I assign them to servers behind the FVX538?

• When you configure the ISP Settings of your router, assign one IP address as the WAN address to be used by your PCs as the main NAT address for general traffic. In the DMZ Setup menu, you can assign the additional public IP addresses to individual PCs on either your LAN or DMZ (if you have activated port 8 as your DMZ port). To allow inbound traffic to reach one of these PCs, you must create an Inbound Rule for the desired service and set the rule’s Destination Address to the public IP address assigned to that PC. (This feature cannot be used when load balancing is selected.)

Page 67: FVX538

NETGEAR CONFIDENTIAL

FAQ#5

• Is the VPN policy created by the VPN Wizard compatible to other Netgear VPN routers?

• The VPN Wizard will create a compatible configuration with our other products when using fixed IP addresses. When using FQDN, some modifications will be necessary after running the wizard. Please refer to our VPN application notes for detailed information.

Page 68: FVX538

NETGEAR CONFIDENTIAL

Known Issues at initial release

• VPN performance is low (about 25M).• Can’t make VPN using WAN2 when PPPoE.• Dynamic DNS configuration does not save.• Sometimes DHCP server stop after change LAN IP. Need to

reboot.• VPN wizard not compatible with other models when using

FQDN. Policy generated need to be edited in order to work with FVS328, FVL328.

• Upon fail-over, no alert or log entry occurs to notify user.• DMZ Setup – user must visit Groups and Hosts menu first

before PC will display.• VPN status menu – connect and drop button do not work.• VPN in PPPoE environment – can’t ping gateway’s LAN IP.• VPN policies created with VPN Wizard will not work if the

remote side is FQDN.

Page 69: FVX538

NETGEAR CONFIDENTIAL

Known issues at initial release• Statistics window does not correctly show line up or down.

Always said WAN port is up. The LED is correct.• CLI not supported, won’t save settings (READ-only). Console

get Linux OS shell. Need to type “cli” to login. Separate KB articles.

• Can access CLI/GUI by telnet using guest/password, can’t change password.

• Client-to-box VPN – need to append one to three characters after policy name.

• Logging entries are not useful.• Sometimes last VPN policy does not appear in menu.• Setup Wizard and Apply button can’t reliably detect or apply in

DHCP ISP environment. Dynamic or static. Manual setup works.

• Load-balancing protocol binding does not work. Bind an application to a particular WAN.

Page 70: FVX538

NETGEAR CONFIDENTIAL

Known issue at initial release

• Disabling a VPN policy does not drop an active tunnel.

• Can’t edit VPN policy to change LAN subnet.

• An attempt to access a blocked site is not logged.

Page 71: FVX538

NETGEAR CONFIDENTIAL

Fixes with firmware v1.6.12

• VPN throughput increased.

• Number of simultaneous sessions increased.

• Guest password can now be changed separately.

• Default gateway is now shown in routing table.

• Fixed: When WAN2 is primary and in PPPoE mode, VPN tunnel can’t pass trafic.

• Fixed: VPN traffic stops under heavy traffic.

• Remove One-to-one NAT table and Exposed Host, since these functions can be performed with inbound rules.


Recommended