NETGEAR Prosafe VPN Firewall FVS318G V2 Reference Manual
Total Page:16
File Type:pdf, Size:1020Kb
NETGEAR ProSAFE VPN Firewall FVS318G v2 Reference Manual October 2014 202-11465-01 350 East Plumeria Drive San Jose, CA 95134 USA NETGEAR ProSAFE VPN Firewall FVS318G v2 Support Thank you for selecting NETGEAR products. After installing your device, locate the serial number on the label of your product and use it to register your product at https://my.netgear.com. You must register your product before you can use NETGEAR telephone support. NETGEAR recommends registering your product through the NETGEAR website. For product updates and web support, visit http://support.netgear.com. Phone (US & Canada only): 1-888-NETGEAR. Phone (Other Countries): Check the list of phone numbers at http://support.netgear.com/general/contact/default.aspx. Compliance For regulatory compliance information, visit http://www.netgear.com/about/regulatory. See the regulatory compliance document before connecting the power supply. Trademarks NETGEAR, the NETGEAR logo, and Connect with Innovation are trademarks and/or registered trademarks of NETGEAR, Inc. and/or its subsidiaries in the United States and/or other countries. Information is subject to change without notice. © NETGEAR, Inc. All rights reserved. Revision History Publication Version Publish Date Comments Part Number 202-11465-01 1.0 October 2014 First publication 2 Contents Chapter 1 Introduction What Is the NETGEAR ProSAFE VPN Firewall FVS318G v2? . .9 Key Features and Capabilities . .9 Advanced VPN Support for IPSec . 10 A Powerful, True Firewall . 10 Security Features . 10 Autosensing Ethernet Connections with Auto Uplink . 10 Extensive Protocol Support . 11 Easy Installation and Management. 11 Maintenance and Support . 12 Package Contents . 12 Hardware Features . 13 Front Panel. 13 Rear Panel . 16 Bottom Panel with Product Label. 17 Choose a Location for the VPN Firewall . 17 Wall-Mount the VPN Firewall with the Mounting Kit . 18 Log In to the VPN Firewall . 19 Web Management Interface Menu Layout . 21 Requirements for Entering IP Addresses. 22 IPv4 Addresses . 23 IPv6 Addresses . 23 Chapter 2 IPv4 and IPv6 Internet and Broadband Settings Internet and WAN Configuration Tasks . 25 IPv4 Internet Connections . 25 IPv6 Internet Connections . 25 Configure the IPv4 Internet Connection and WAN Settings . 26 Configure the IPv4 WAN Mode . 26 Let the VPN Firewall Automatically Detect and Configure an IPv4 Internet Connection . 28 Manually Configure an IPv4 Internet Connection . 31 Configure Dynamic DNS . 35 Configure the IPv6 Internet Connection and WAN Settings . 38 Configure the IPv6 Routing Mode . 39 Use a DHCPv6 Server to Configure an IPv6 Internet Connection . 40 Configure a Static IPv6 Internet Connection . 42 Configure a PPPoE IPv6 Internet Connection . 44 Configure 6to4 Automatic Tunneling . 47 3 NETGEAR ProSAFE VPN Firewall FVS318G v2 Configure ISATAP Automatic Tunneling . 48 View the Tunnel Status and IPv6 Addresses. 51 Configure Stateless IP/ICMP Translation . 51 Configure Advanced WAN Options and Other Tasks. 52 Additional WAN-Related Configuration Tasks . 55 Verify the Connection . 55 What to Do Next . 55 Chapter 3 LAN Configuration Manage IPv4 Virtual LANs and DHCP Options . 57 Port-Based VLANs . 57 Assign and Manage VLAN Profiles . 58 VLAN DHCP Options. 60 Configure a VLAN Profile. 61 Configure VLAN MAC Addresses and LAN Advanced Settings . 68 Configure IPv4 Multihome LAN IP Addresses on the Default VLAN . 69 Manage IPv4 Groups and Hosts (IPv4 LAN Groups) . 71 Manage the Network Database . 73 Change Group Names in the Network Database . 77 Set Up DHCP Address Reservation . 78 Manage the IPv6 LAN. 78 DHCPv6 Server Options . 79 Configure the IPv6 LAN. 80 Configure the IPv6 Router Advertisement Daemon and Advertisement Prefixes for the LAN . 88 Configure IPv6 Multihome LAN IP Addresses on the Default VLAN . 93 Enable and Configure the DMZ Port for IPv4 and IPv6 Traffic . 96 DMZ Port for IPv4 Traffic. 96 DMZ Port for IPv6 Traffic. 100 Configure the IPv6 Router Advertisement Daemon and Advertisement Prefixes for the DMZ . 106 Manage Static IPv4 Routing . 111 Configure Static IPv4 Routes . 111 Configure the Routing Information Protocol . 114 IPv4 Static Route Example . 116 Manage Static IPv6 Routing . 117 Configure Quality of Service. 120 Chapter 4 Firewall Protection About Firewall Protection . 126 Administrator Tips . 126 Overview of Rules to Block or Allow Specific Kinds of Traffic. 127 Outbound Rules. 128 Inbound Rules . 130 Order of Precedence for Rules. 134 Configure LAN WAN Rules . 134 Create LAN WAN Outbound Service Rules . 137 4 NETGEAR ProSAFE VPN Firewall FVS318G v2 Create LAN WAN Inbound Service Rules. 141 Configure DMZ WAN Rules . 144 Create DMZ WAN Outbound Service Rules . 147 Create DMZ WAN Inbound Service Rules . 150 Configure LAN DMZ Rules . 153 Create LAN DMZ Outbound Service Rules . 156 Create LAN DMZ Inbound Service Rules . 158 Examples of Firewall Rules. ..