Summary of the content on the page No. 1
CyberGuard SG
Firewall VPN Appliance
User Manual
Revision 2.0.1
June 7, 2004
CyberGuard
7984 South Welby Park Drive #101
Salt Lake City, Utah 84084
Email: support@snapgear.com
Web: www.cyberguard.com
Summary of the content on the page No. 2
Contents 1. Introduction...............................................................................................1 CyberGuard SG Gateway Appliances ...................................................................1 CyberGuard SG PCI Appliances ...........................................................................2 Document Conventions .........................................................................................4 Your CyberGuard SG Gateway Appliance .................
Summary of the content on the page No. 3
4. Dialin Setup.............................................................................................52 Dialin Setup .........................................................................................................53 Dialin User Accounts ...........................................................................................55 Account list ..........................................................................................................56 Remote User Configuration .
Summary of the content on the page No. 4
10. System...................................................................................................159 Date and Time ...................................................................................................159 Users .................................................................................................................161 Diagnostics ........................................................................................................163 Advanced...............
Summary of the content on the page No. 5
1. Introduction This chapter provides an overview of your CyberGuard SG appliance’s features and capabilities, and explains how to install and configure your CyberGuard SG appliance. This manual describes how to take advantage of the features of your CyberGuard SG appliance, including setting up network connections, a secure firewall and a VPN. It also describes how to set up the CyberGuard SG appliance on your existing or new network using the Web Management Console web administration pa
Summary of the content on the page No. 6
The following figure shows how your CyberGuard SG appliance interconnects. Figure 1-1 CyberGuard SG PCI Appliances The CyberGuard SG PCI appliance (SG630, SG635) is a hardware-based firewall and VPN server embedded in a 10/100 Ethernet PCI network interface card (NIC). It is installed into the host PC like a regular NIC, providing a transparent firewall to shield the host PC from malicious Internet traffic, and VPN services to allow secure remote access to the host PC. This appliance
Summary of the content on the page No. 7
This approach offers an increased measure of protection against internal threats as well as conventional Internet security concerns. You can update, configure and monitor the firewall and VPN connectivity of a workstation or server from any web browser. In the event of a breach, you have complete control over individual PCs' access policies independent of the host PC's operating system, even if the system has been subverted and is denying normal administrator access. All network filterin
Summary of the content on the page No. 8
Document Conventions This document uses different fonts and typefaces to show specific actions. Warning/Note Text like this highlights important issues. Bold text in procedures indicates text that you type, or the name of a screen object (e.g. a menu or button). 4 Introduction
Summary of the content on the page No. 9
Your CyberGuard SG Gateway Appliance CyberGuard SG gateway appliances include: • SG300 • SG530 • SG550 • SG570 • SG575 The following items are included with your CyberGuard SG gateway appliance: • Power adaptor • Installation CD • Printed Quick Install guide • Cabling including o 1 normal straight through UTP cable (blue color). o 1 crossover UTP cable (either gray or red color) Note The SG300 model includes two blue straight through UTP cables. Front panel LEDs The front and re
Summary of the content on the page No. 10
Note Not all the LEDs described below are present on all CyberGuard SG appliance models. Also, labels vary from model to model. Label Activity Description Power On Power is supplied to the CyberGuard SG appliance Heart Beat Flashing The CyberGuard SG appliance is operating correctly On If this LED is on and not flashing, an operating error has occurred LAN Activity Flashing Network traffic on the LAN network interface WAN Activity Flashing Network traffic on the Internet network int
Summary of the content on the page No. 11
CyberGuard SG Gateway Appliance Features Internet link features • 10/100baseT Ethernet port (Internet/WAN) • Serial port • Front panel serial status LEDs (for TX/RX) • Online status LEDs (for Internet/VPN) • Rear panel Ethernet link and activity status LEDs LAN link features • 10/100BaseT LAN port • 10/100BaseT 4 port LAN switch (SG300 model only) • Rear panel Ethernet link and activity status LEDs DMZ link features (SG570, SG575 only) • 10/100BaseT DMZ port • Real panel Ethernet l
Summary of the content on the page No. 12
Your CyberGuard SG PCI Appliance CyberGuard SG PCI appliances include: • PCI630 • PCI635 The following items are included with your CyberGuard SG PCI appliance: • Installation CD • Printed Quick Install guide LEDs The rear panel contains LEDs indicating status. The two LEDs closest to the network port are network activity (upper) and network link (lower). The two other LEDs are power (upper) and heart beat (lower). Figure 1-3 Label Activity Description On Power is supplied to th
Summary of the content on the page No. 13
CyberGuard SG PCI Appliance Features Network link features • 10/100baseT Ethernet port • Ethernet LEDs (link, activity) Environmental features • Status LEDs: Power, Heart Beat • Operating temperature between 0° C and 40° C • Storage temperature between -20° C and 70° C • Humidity between 0 to 95% (non-condensing) 9 Introduction
Summary of the content on the page No. 14
2. Getting Started This chapter provides step-by-step instructions for installing your CyberGuard SG appliance into your network and connecting to the Internet. This is a slightly more detailed version of the printed Quick Install Guide that shipped with your CyberGuard SG appliance. These instructions assume you have a PC running Microsoft Windows (95/98/Me/ 2000/XP for CyberGuard SG gateway appliances, 2000/XP only for CyberGuard SG PCI appliances). If you are installing a CyberGuard
Summary of the content on the page No. 15
CyberGuard SG Gateway Appliances Set up a PC to Connect to the Web Management Console The CyberGuard SG appliance ships with initial, static IP settings of: IP address: 192.168.0.1 Subnet mask: 255.255.255.0 Note The Internet/WAN and DMZ interfaces are by default inactive, i.e. there are no network services such as DHCP in operation, and no IP address is configured. The CyberGuard SG appliance’s LAN interface will always be initially reachable at 192.168.0.1. If you attach your
Summary of the content on the page No. 16
Connect the supplied power adapter to the CyberGuard SG appliance. If you are using the SG530, SG550, SG570 or SG575 model, connect the CyberGuard SG appliance’s LAN Ethernet port directly to your PC’s network interface card using the crossover cable (red or gray). If you are using the SG300 model, connect your PC’s network interface card directly to one of the ports on the CyberGuard SG appliance’s LAN Ethernet switch using a straight through cable (blue). Note It is recommended that yo
Summary of the content on the page No. 17
Next, you must modify your PC’s network settings to enable it to communicate with the CyberGuard SG appliance. Click Start -> Settings -> Control Panel and double click Network Connections (or in 95/98/Me, double click Network). Right click on Local Area Connection and select Properties. Note If there is more than one existing network connection, select the one corresponding to the network interface card to which the CyberGuard SG appliance is directly attached. Select Internet Protocol
Summary of the content on the page No. 18
Select Use the following IP address and enter the following details: IP address: 192.168.0.100 Subnet mask: 255.255.255.0 Default gateway: 192.168.0.1 Select Use the following DNS server addresses and enter: Preferred DNS server: 192.168.0.1 Note If you wish to retain your existing IP settings for this network connection, click Advanced and Add the secondary IP address of 192.168.0.100, subnet mask 255.255.255.0. Set up the Password and LAN Connection Settings Launch Internet Explore
Summary of the content on the page No. 19
Select Quick Setup Wizard from the center of the page. You will be prompted to log in. Enter the initial user name and password for your CyberGuard SG appliance: User name: root Password: default Note If you are unable to connect to the Management Console at 192.168.0.1, or the initial username and password are not accepted, press the black Reset/Erase button on the CyberGuard SG appliance’s rear panel twice, wait 20 – 30 seconds, and try again. Pressing this button twice within 2 s
Summary of the content on the page No. 20
The Quick Setup Wizard will display. Figure 2-3 Hostname: You may change the name the CyberGuard SG appliance knows itself by. This is not generally necessary. Manual configuration: Select this to manually specify your CyberGuard SG appliance’s LAN connection settings. Skip: LAN already configured: Select this if you wish to use the CyberGuard SG appliance’s initial network settings (IP address 192.168.0.1 and subnet mask 255.255.255.0) as a basis for your LAN settings. You may skip