Watchguard Firebox X1000 Betriebsanweisung

Stöbern Sie online oder laden Sie Betriebsanweisung nach Vernetzung Watchguard Firebox X1000 herunter. Watchguard Firebox X1000 User guide Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 271
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - User Guide

WatchGuard®Firebox® System User GuideWatchGuard Firebox System

Seite 2 - Notice to Users

x WatchGuard Firebox SystemAdding Basic Services to Policy Manager ... 61Configuring Routes ...

Seite 3 - User Guide iii

Chapter 7: Configuring Network Address Translation84 WatchGuard Firebox SystemAdding simple dynamic NAT entriesUsing built-in host aliases, you can qu

Seite 4 - End-User License Agreement

Using Simple Dynamic NATUser Guide 855 Click OK.The new entry appears in the Dynamic NAT Entries list.Reordering simple dynamic NAT entriesTo reorder

Seite 5 - User Guide v

Chapter 7: Configuring Network Address Translation86 WatchGuard Firebox SystemUsing Service-Based Dynamic NATUsing service-based dynamic NAT, you can

Seite 6

Configuring a Service for Incoming Static NATUser Guide 87Disable NAT Disables dynamic NAT for outgoing packets using this service. Use this setting

Seite 7 - Contents

Chapter 7: Configuring Network Address Translation88 WatchGuard Firebox SystemSetting static NAT for a serviceStatic NAT, like service-based NAT, is c

Seite 8

Using 1-to-1 NATUser Guide 899 Click OK to close the Add Address dialog box. Click OK to close the services’s Properties dialog box.Using 1-to-1 NAT1-

Seite 9 - User Guide ix

Chapter 7: Configuring Network Address Translation90 WatchGuard Firebox System2 Click Advanced.The Advanced NAT Settings dialog box appears.3 Click th

Seite 10

Using 1-to-1 NATUser Guide 91Proxies and NATThis table identifies each proxy and what types of NAT it supports.Simple dynamicStatic Service-based 1-to

Seite 11 - User Guide xi

Chapter 7: Configuring Network Address Translation92 WatchGuard Firebox System

Seite 12

User Guide 93CHAPTER 8 Configuring Filtered ServicesYou add filtered services–in addition to proxied services–to control and monitor the flow of IP pa

Seite 13 - User Guide xiii

User Guide xiEnabling simple dynamic NAT ... 83Adding simple dynamic NAT entries ... 8

Seite 14

Chapter 8: Configuring Filtered Services94 WatchGuard Firebox SystemSelecting Services for your Security Policy ObjectivesThe WatchGuard Firebox Syste

Seite 15 - User Guide xv

Adding and Configuring ServicesUser Guide 95• Allowing a service to the optional network is safer than allowing it to the trusted network.• Allowing i

Seite 16

Chapter 8: Configuring Filtered Services96 WatchGuard Firebox SystemYou can also add unique or custom services. However, if you do, take steps to perm

Seite 17 - Introduction

Adding and Configuring ServicesUser Guide 97Configurable parameters for servicesSeveral service parameters can be configured:Sources and DestinationsY

Seite 18 - WatchGuard Control Center

Chapter 8: Configuring Filtered Services98 WatchGuard Firebox System2 Expand either the Packet Filters or Proxies folder by clicking the plus (+) sign

Seite 19 - Minimum Requirements

Adding and Configuring ServicesUser Guide 995 (Optional) You can customize both the name and the comments that appear when the service is being config

Seite 20 - Hardware requirements

Chapter 8: Configuring Filtered Services100 WatchGuard Firebox SystemCreating a new serviceIn addition to built-in filtered services provided by Watch

Seite 21 - WatchGuard Options

Adding and Configuring ServicesUser Guide 101IgnoreSource port can be any number (0—65565). (If you are not sure which port setting to use, choose thi

Seite 22 - SpamScreen

Chapter 8: Configuring Filtered Services102 WatchGuard Firebox System 11 Click OK.The Services dialog box appears with the new service displayed under

Seite 23 - About this Guide

Defining Service PropertiesUser Guide 103Defining Service PropertiesYou use the service’s Properties dialog box to configure the incoming and outgoing

Seite 24 - and .idx files

xii WatchGuard Firebox SystemAdding a proxy service for HTTP ... 121Configuring a caching proxy server ...

Seite 25 - Service and Support

Chapter 8: Configuring Filtered Services104 WatchGuard Firebox SystemAdding service propertiesThe method used to add incoming and outgoing service pro

Seite 26 - Broadcasts

Defining Service PropertiesUser Guide 105Working with wg_iconsService icons beginning with “wg_” are created automatically when you enable features su

Seite 27 - Service

Chapter 8: Configuring Filtered Services106 WatchGuard Firebox SystemFrom the Properties dialog box:1 Click the Incoming tab.2 Click Logging.The Loggi

Seite 28 - The Account page appears

Service PrecedenceUser Guide 107The remaining controls are active when you select the Send notification checkbox:EmailTriggers an email message when t

Seite 29 - User Guide 13

Chapter 8: Configuring Filtered Services108 WatchGuard Firebox System“Multiservices” can contain subservices of more than one precedence group. “Filte

Seite 30 - Online Help

Service PrecedenceUser Guide 109based on the specificity of targets, from most specific to least specific. The following order is used:IP refers to ex

Seite 31 - Searching for topics

Chapter 8: Configuring Filtered Services110 WatchGuard Firebox System

Seite 32 - Context-sensitive Help

User Guide 111CHAPTER 9 Configuring Proxied ServicesProxy filtering goes a step beyond packet filtering by examining a packet’s content, not just the

Seite 33 - Assisted Support

Chapter 9: Configuring Proxied Services112 WatchGuard Firebox SystemConfiguring an SMTP Proxy ServiceThe SMTP proxy limits several potentially harmful

Seite 34 - Firebox Installation Services

Configuring an SMTP Proxy ServiceUser Guide 113the Services Arena. (For information on how to add a service, see the previous chapter.) From the Servi

Seite 35 - Training and Certification

User Guide xiiiSetting logging and notification for blocked ports ... 156Blocking Sites Temporarily with Service Settings ... 157Conf

Seite 36 - 20 WatchGuard Firebox System

Chapter 9: Configuring Proxied Services114 WatchGuard Firebox SystemBlocking email content typesMIME stands for Multipurpose Internet Mail Extensions,

Seite 37 - Getting Started

Configuring an SMTP Proxy ServiceUser Guide 115• A string is a wildcard pattern if it contains a question mark (?), an asterisk (*), or a right parent

Seite 38 - Gathering Network Information

Chapter 9: Configuring Proxied Services116 WatchGuard Firebox System2 Select Allowed To from the Category drop list.3 In the text box to the left of t

Seite 39 - Network addresses

Configuring an SMTP Proxy ServiceUser Guide 117• Accounting and auditing information.Configuring the Outgoing SMTP ProxyUse the Outgoing SMTP Proxy di

Seite 40 - 24 WatchGuard Firebox System

Chapter 9: Configuring Proxied Services118 WatchGuard Firebox Systemmight be inside.salesdept.bigcompany.com, which would become the public address bi

Seite 41 - User Guide 25

Configuring an FTP Proxy ServiceUser Guide 119Configuring an FTP Proxy ServiceThe FTP proxy service enables you to access another computer (on a separ

Seite 42 - Routed configuration

Chapter 9: Configuring Proxied Services120 WatchGuard Firebox SystemSelecting an HTTP ServiceBecause of the extensive security implications of HTTP tr

Seite 43 - Drop-in configuration

Selecting an HTTP ServiceUser Guide 121 NOTEThe WatchGuard service called “HTTP” is not to be confused with an HTTP caching proxy. An HTTP caching pr

Seite 44 - 28 WatchGuard Firebox System

Chapter 9: Configuring Proxied Services122 WatchGuard Firebox SystemFor detailed information about the HTTP proxy, see the online support resources at

Seite 45 - User Guide 29

Configuring the DNS Proxy ServiceUser Guide 123The Firebox communicates with proxy servers exactly the same way that clients normally do. Instead of a

Seite 46 - 30 WatchGuard Firebox System

xiv WatchGuard Firebox SystemViewing the WSEP application ... 180Starting and stopping the WSEP ...

Seite 47 - User Guide 31

Chapter 9: Configuring Proxied Services124 WatchGuard Firebox Systemattacks that cause a buffer overflow, which crash the targeted server and enable t

Seite 48 - 32 WatchGuard Firebox System

Configuring the DNS Proxy ServiceUser Guide 1255 Click the Incoming tab. Use the Incoming DNS-Proxy connections are drop list to select Enabled and A

Seite 49 - Cabling the Firebox

Chapter 9: Configuring Proxied Services126 WatchGuard Firebox System

Seite 50 - 34 WatchGuard Firebox System

User Guide 127CHAPTER 10 Creating Aliases and Implementing AuthenticationAliases are shortcuts used to identify groups of hosts, networks, or users. T

Seite 51 - Running the QuickSetup Wizard

Chapter 10: Creating Aliases and Implementing Authentication128 WatchGuard Firebox Systema user workstation may have several different IP addresses ov

Seite 52 - Reference

Using AliasesUser Guide 1292 Click Add.3 In the Host Alias Name text box, enter the name used to identify the alias when configuring services and auth

Seite 53 - Testing the connection

Chapter 10: Creating Aliases and Implementing Authentication130 WatchGuard Firebox System8 When you finish adding members, click OK.The Host Alias dia

Seite 54 - Entering IP addresses

Authentication Server TypesUser Guide 131Enabling remote authenticationUse this procedure to allow remote users to authenticate from the External inte

Seite 55 - What’s Next

Chapter 10: Creating Aliases and Implementing Authentication132 WatchGuard Firebox SystemTo specify authentication type:1 From Policy Manager, select

Seite 56

Defining Firebox Users and Groups for AuthenticationUser Guide 133computers. As your organization changes, you can add or remove users or systems from

Seite 57 - Firebox Basics

User Guide xvEditing an existing report ... 205Deleting a report ...

Seite 58 - 42 WatchGuard Firebox System

Chapter 10: Creating Aliases and Implementing Authentication134 WatchGuard Firebox System4 To add a new user, click the Add button beneath the Users l

Seite 59 - Opening a Configuration File

Configuring RADIUS Server AuthenticationUser Guide 1352 Click the NT Server tab.The information appears as shown in the following figure.3 To identify

Seite 60 - 44 WatchGuard Firebox System

Chapter 10: Creating Aliases and Implementing Authentication136 WatchGuard Firebox Systemauthentication key that identifies it to the RADIUS server. N

Seite 61 - Saving a Configuration File

Configuring CRYPTOCard Server AuthenticationUser Guide 1377 Click OK.8 Gather the IP address of the Firebox and the user or group aliases you want to

Seite 62 - 46 WatchGuard Firebox System

Chapter 10: Creating Aliases and Implementing Authentication138 WatchGuard Firebox SystemProperties dialog box, and the IP address of the Firebox on t

Seite 63 - Resetting Firebox Passphrases

Configuring SecurID AuthenticationUser Guide 139On the CRYPTOCard server:1 Add the IP address of the Firebox where appropriate according to CRYPTOCard

Seite 64 - Setting the Firebox Model

Chapter 10: Creating Aliases and Implementing Authentication140 WatchGuard Firebox System3 Enter the IP address of the SecurID server.4 Enter or verif

Seite 65 - Setting the Time Zone

User Guide 141CHAPTER 11 Protecting Your Network From AttacksThe WatchGuard Firebox System can protect your network from many types of attacks. In add

Seite 66 - 50 WatchGuard Firebox System

Chapter 11: Protecting Your Network From Attacks142 WatchGuard Firebox SystemLogging options help you identify sites that exhibit suspicious behavior

Seite 67 - Configure Your Network

Default Packet HandlingUser Guide 143that the packet apparently originated from a host that is trusted, and therefore doesn’t require validation or a

Seite 68 - The Policy Manager appears

xvi WatchGuard Firebox SystemSetting privileges ... 223Creating WebBlocker exceptions ...

Seite 69 - For more information on

Chapter 11: Protecting Your Network From Attacks144 WatchGuard Firebox Systemwhich services are running on the hosts inside that network. From Policy

Seite 70

Default Packet HandlingUser Guide 145They are stored in a backlog until they are completed or time out. When the server’s backlog is full, no new conn

Seite 71 - Enabling static PPPoE

Chapter 11: Protecting Your Network From Attacks146 WatchGuard Firebox Systemrecorded. If these messages occur frequently when your server is not unde

Seite 72 - Defining External IP Aliases

Integrating Intrusion DetectionUser Guide 147and either allow or deny packets. Little extra bandwidth is available to conduct sophisticated analysis o

Seite 73 - Adding Secondary Networks

Chapter 11: Protecting Your Network From Attacks148 WatchGuard Firebox Systemadd_hostileThis command adds a site to the Auto-Blocked Site list, with t

Seite 74 - From Policy Manager:

Blocking SitesUser Guide 149Example 2The IDS adds a message to the Firebox’s log stream:fbidsmate 10.0.0.1 secure1 add_log_message 3 "IDS system

Seite 75 - User Guide 59

Chapter 11: Protecting Your Network From Attacks150 WatchGuard Firebox System• Permanently blocked sites–which are listed in the configuration file an

Seite 76 - Modifying an existing subnet

Blocking SitesUser Guide 151From Policy Manager:1 On the toolbar, click the Blocked Sites icon (shown at right).You can also select Setup => Blocke

Seite 77 - Removing a subnet

Chapter 11: Protecting Your Network From Attacks152 WatchGuard Firebox SystemCreating exceptions to the Blocked Sites listA blocked site exception is

Seite 78 - Configuring Routes

Blocking PortsUser Guide 153Blocking PortsYou can block ports to explicitly disable external network services from accessing ports that are vulnerable

Seite 79 - Defining a Host Route

User Guide 1CHAPTER 1 IntroductionWelcome to WatchGuard®In the past, a connected enterprise needed a complex set of tools, systems, and personnel for

Seite 80 - 64 WatchGuard Firebox System

Chapter 11: Protecting Your Network From Attacks154 WatchGuard Firebox Systemintrusions can be difficult or impossible to detect by all but the most k

Seite 81 - Control Center

Blocking PortsUser Guide 155port 0Port 0 is reserved by IANA, but many programs that scan ports start their search on port 0.port 1Port 1 is for the r

Seite 82 - Control Center Components

Chapter 11: Protecting Your Network From Attacks156 WatchGuard Firebox SystemTo remove a blocked port, select the port to remove. Click Remove.Auto-bl

Seite 83 - QuickGuide

Blocking Sites Temporarily with Service SettingsUser Guide 157Blocking Sites Temporarily with Service SettingsUse service properties to automatically

Seite 84 - Front panel

Chapter 11: Protecting Your Network From Attacks158 WatchGuard Firebox System

Seite 85 - Firebox and VPN tunnel status

User Guide 159CHAPTER 12 Monitoring Firebox ActivityAn important part of an effective network security policy is the monitoring of network events. Mon

Seite 86 - Branch Office VPN Tunnels

Chapter 12: Monitoring Firebox Activity160 WatchGuard Firebox SystemStarting Firebox Monitors and connecting to a FireboxFrom Control Center:1 On the

Seite 87 - Red exclamation point

Firebox MonitorsUser Guide 161BandwidthMeterThe BandwidthMeter tab on the Firebox Monitors display, shown in the following figure, shows real-time ban

Seite 88 - Traffic Monitor

Chapter 12: Monitoring Firebox Activity162 WatchGuard Firebox SystemAdding services to ServiceWatchBy default, ServiceWatch graphs the SMTP, FTP, and

Seite 89 - Working with Control Center

Firebox MonitorsUser Guide 163Log hostsThe IP addresses of the log host or hosts.Log host(s): 206.148.32.16Network configurationStatistics about the

Seite 90 - Connecting to a Firebox

Chapter 1: Introduction2 WatchGuard Firebox SystemWatchGuard Firebox System ComponentsThe WatchGuard Firebox System has all of the components needed t

Seite 91 - Changing the polling rate

Chapter 12: Monitoring Firebox Activity164 WatchGuard Firebox SystemMemoryStatistics on the memory usage of the currently running Firebox. Numbers sho

Seite 92 - Getting Help on the Web

Firebox MonitorsUser Guide 165 73 fblightd S 464 308 3927:05.75 ( 5) 0 (nice) 74 /bin/logger S 1372 592 1:2

Seite 93 - Manipulating Traffic Monitor

Chapter 12: Monitoring Firebox Activity166 WatchGuard Firebox SystemThe interfaces used in this section are as follows:eth0 - External (public) interf

Seite 94 - Launching Policy Manager

HostWatchUser Guide 167Authentication listThe Authentication List tab displays the host IP addresses and user names of everyone currently authenticate

Seite 95 - Launching Historical Reports

Chapter 12: Monitoring Firebox Activity168 WatchGuard Firebox SystemThe HostWatch display uses the logging settings configured with Policy Manager. Fo

Seite 96 - 80 WatchGuard Firebox System

HostWatchUser Guide 169Connecting HostWatch to a Firebox:From HostWatch:1 Select File => Connect.Or, on the Hostwatch toolbar, click the Connect ic

Seite 97 - Address Translation

Chapter 12: Monitoring Firebox Activity170 WatchGuard Firebox System3 To restart the display, click Continue (shown at right).4 To step through the di

Seite 98 - Dynamic NAT

User Guide 171CHAPTER 13 Setting Up Logging and NotificationAn event is any single activity that occurs at the Firebox, such as denying a packet from

Seite 99

Chapter 13: Setting Up Logging and Notification172 WatchGuard Firebox Systemboth flexible and powerful. You can configure your firewall to log and not

Seite 100 - 1 Click Add

Developing Logging and Notification PoliciesUser Guide 173only by a small number of people in an organization. In that case you might want to log all

Seite 101 - User Guide 85

Minimum RequirementsUser Guide 3Historical ReportsCreates HTML reports that display session types, most active hosts, most used services, URLs, and ot

Seite 102 - 86 WatchGuard Firebox System

Chapter 13: Setting Up Logging and Notification174 WatchGuard Firebox SystemFailover LoggingWatchGuard uses failover logging to minimize the possibili

Seite 103 - Adding external IP addresses

Designating Log Hosts for a FireboxUser Guide 175 - Set the log encryption key on each log host identical to the key set in Policy ManagerDesignating

Seite 104 - 88 WatchGuard Firebox System

Chapter 13: Setting Up Logging and Notification176 WatchGuard Firebox System3 Enter the IP address to be used by the log host.When typing IP addresses

Seite 105 - Using 1-to-1 NAT

Designating Log Hosts for a FireboxUser Guide 177Changing the log encryption keyEdit a log host entry to change the log encryption key. From Policy Ma

Seite 106 - 90 WatchGuard Firebox System

Chapter 13: Setting Up Logging and Notification178 WatchGuard Firebox SystemThe Firebox sets its clock to the current log host. If the Firebox and the

Seite 107 - Proxies and NAT

Setting up the WatchGuard Security Event ProcessorUser Guide 179By default, the WSEP application is installed to run as a Windows service, starting au

Seite 108 - 92 WatchGuard Firebox System

Chapter 13: Setting Up Logging and Notification180 WatchGuard Firebox SystemAs a service, using the Command PromptIf the WSEP application was not inst

Seite 109 - Configuring Filtered Services

Setting up the WatchGuard Security Event ProcessorUser Guide 181If the WatchGuard Security Event Processor icon is not in the tray, in Control Center,

Seite 110 - Incoming service guidelines

Chapter 13: Setting Up Logging and Notification182 WatchGuard Firebox SystemFrom the WatchGuard Security Event Processor user interface:1 Select File

Seite 111 - Outgoing service guidelines

Setting Global Logging and Notification PreferencesUser Guide 183entries in two weeks, whereas a large one with many services enabled might easily log

Seite 112 - 96 WatchGuard Firebox System

ii WatchGuard Firebox SystemNotice to UsersInformation in this guide is subject to change without notice. Companies, names, and data used in examples

Seite 113 - Adding a service

Chapter 1: Introduction4 WatchGuard Firebox SystemWindows NT requirements•Microsoft Windows NT 4.0• Microsoft Service Pack 4, Service Pack 5, or Servi

Seite 114 - 4 Click Add

Chapter 13: Setting Up Logging and Notification184 WatchGuard Firebox SystemScheduling log reportsYou can use the WSEP application to schedule the aut

Seite 115 - User Guide 99

Customizing Logging and Notification by Service or OptionUser Guide 185Setting a Firebox friendly name for log filesYou can give the Firebox a friendl

Seite 116 - Creating a new service

Chapter 13: Setting Up Logging and Notification186 WatchGuard Firebox SystemCategoryThe event types that can be logged by the service or option. This

Seite 117 - 10 Click OK

Customizing Logging and Notification by Service or OptionUser Guide 187 NOTEWatchGuard allows only one notification type per event.Setting Launch Int

Seite 118 - Deleting a service

Chapter 13: Setting Up Logging and Notification188 WatchGuard Firebox SystemThe repeat count multiplied by the launch interval equals the amount of ti

Seite 119 - Defining Service Properties

Customizing Logging and Notification by Service or OptionUser Guide 1892 Click Logging.3 Modify logging and notification properties according to your

Seite 120 - Adding service properties

Chapter 13: Setting Up Logging and Notification190 WatchGuard Firebox System

Seite 121 - Working with wg_icons

User Guide 191CHAPTER 14 Reviewing and Working with Log FilesLog files are a valuable tool for monitoring your network, identifying potential attacks,

Seite 122 - 2 Click Logging

Chapter 14: Reviewing and Working with Log Files192 WatchGuard Firebox SystemThe log file to which the WSEP is currently writing records can be named

Seite 123 - Service Precedence

Viewing Files with LogViewerUser Guide 193Searching for specific entriesLogViewer has a search tool to enable you to find specific transactions quickl

Seite 124 - 108 WatchGuard Firebox System

WatchGuard OptionsUser Guide 5.WatchGuard OptionsThe WatchGuard Firebox System is enhanced by optional features designed to accommodate the needs of d

Seite 125 - User Guide 109

Chapter 14: Reviewing and Working with Log Files194 WatchGuard Firebox SystemCopying log data1 Select the log entries you want to copy.Use the SHIFT k

Seite 126 - 110 WatchGuard Firebox System

Displaying and Hiding FieldsUser Guide 195Displaying and Hiding FieldsThe following figure shows an example of the type of display you normally see in

Seite 127 - Configuring Proxied Services

Chapter 14: Reviewing and Working with Log Files196 WatchGuard Firebox SystemTimeThe time the record entered the log file. Default = ShowThe Firebox r

Seite 128 - 112 WatchGuard Firebox System

Working with Log FilesUser Guide 197IP header lengthLength, in octets, of the IP header for this packet. A header length that is not equal to 20 indic

Seite 129 - User Guide 113

Chapter 14: Reviewing and Working with Log Files198 WatchGuard Firebox System• Right-click the WSEP icon (shown at right) in the Windows system tray a

Seite 130 - Blocking email content types

Working with Log FilesUser Guide 199log rollover” on page 183. However, you may occasionally want to force the rollover of a log file.• From the WSEP

Seite 131 - User Guide 115

Chapter 14: Reviewing and Working with Log Files200 WatchGuard Firebox SystemSending logs to a log host at another locationBecause they are encrypted

Seite 132 - 116 WatchGuard Firebox System

Working with Log FilesUser Guide 2015 Save the new configuration to the remote office Firebox. On the log host:You must use the same log encryption ke

Seite 133 - User Guide 117

Chapter 14: Reviewing and Working with Log Files202 WatchGuard Firebox System

Seite 134 - 118 WatchGuard Firebox System

User Guide 203CHAPTER 15 Generating Reports of Network ActivityAccounting for Internet usage can be a challenging network administration task. One of

Seite 135 - 4 Click OK

Chapter 1: Introduction6 WatchGuard Firebox SystemVPN Manager is bundled with the WFS software, but it is available for use only if you enable the VPN

Seite 136 - Selecting an HTTP Service

Chapter 15: Generating Reports of Network Activity204 WatchGuard Firebox SystemCreating and Editing ReportsTo start Historical Reports, from Control C

Seite 137 - User Guide 121

Specifying a Report Time SpanUser Guide 205Editing an existing report At any time, you can modify the properties of an existing report. From Historica

Seite 138 - 122 WatchGuard Firebox System

Chapter 15: Generating Reports of Network Activity206 WatchGuard Firebox SystemSpecifying Report SectionsUse the Sections tab on the Report Properties

Seite 139 - GET / HTTP/1.1

Setting Report PropertiesUser Guide 207Setting Report PropertiesReports contain either Summary sections or Detail sections. Each can be presented in d

Seite 140 - Adding the DNS Proxy Service

Chapter 15: Generating Reports of Network Activity208 WatchGuard Firebox Systeminclude the name and time of the report. Each report is filed in one of

Seite 141 - DNS file descriptor limit

Using Report FiltersUser Guide 209 NOTEWatchGuard HTTP proxy logging must be turned on to supply WebTrends the logging information required for its r

Seite 142 - 126 WatchGuard Firebox System

Chapter 15: Generating Reports of Network Activity210 WatchGuard Firebox SystemHostFilter a report based on host IP address.PortFilter a report based

Seite 143 - Implementing Authentication

Scheduling and Running ReportsUser Guide 211Deleting a report filterTo remove a filter from the list of available filters, highlight the filter. Click

Seite 144 - Using Aliases

Chapter 15: Generating Reports of Network Activity212 WatchGuard Firebox System6 Click OK.Manually running a reportAt any time, you can run one or mor

Seite 145 - User Guide 129

Report Sections and Consolidated SectionsUser Guide 213Time Summary – Packet FilteredA table, and optionally a graph, of all accepted connections dist

Seite 146 - How User Authentication Works

About this GuideUser Guide 7SpamScreen is bundled with the WFS software, but it is available for use only if you enable the SpamScreen checkbox when i

Seite 147 - Authentication Server Types

Chapter 15: Generating Reports of Network Activity214 WatchGuard Firebox SystemSession Summary – Proxied TrafficA table, and optionally a graph, of th

Seite 148 - 132 WatchGuard Firebox System

Report Sections and Consolidated SectionsUser Guide 215Denied Incoming Packet DetailA list of denied incoming packets, sorted by time. The fields are

Seite 149 - User Guide 133

Chapter 15: Generating Reports of Network Activity216 WatchGuard Firebox SystemService SummaryA table, and optionally a graph, of traffic for all serv

Seite 150 - 134 WatchGuard Firebox System

User Guide 217CHAPTER 16 Controlling Web Site AccessWebBlocker is a feature of the WatchGuard Firebox System that works in conjunction with the HTTP

Seite 151 - 5 Click OK

Chapter 16: Controlling Web Site Access218 WatchGuard Firebox SystemWFS under high load conditions, consider installing the WebBlocker server on a ded

Seite 152 - 136 WatchGuard Firebox System

Getting Started with WebBlockerUser Guide 219• Install or remove the server• Start or stop the serverTo run the WebBlocker utility, select Start =>

Seite 153 - User Guide 137

Chapter 16: Controlling Web Site Access220 WatchGuard Firebox System Configuring the WebBlocker ServiceWebBlocker is a built-in feature of several ser

Seite 154 - 138 WatchGuard Firebox System

Configuring the WebBlocker ServiceUser Guide 2214 Next to the WebBlocker Servers box, click Add.5 In the dialog box that appears, type the IP address

Seite 155 - User Guide 139

Chapter 16: Controlling Web Site Access222 WatchGuard Firebox SystemRequest for URL www.badsite.com denied by WebBlocker: host blocked for violence/pr

Seite 156 - SecurID server

Configuring the WebBlocker ServiceUser Guide 223Setting privilegesWebBlocker differentiates URLs based on their content. Select the types of content a

Seite 157 - From Attacks

Chapter 1: Introduction8 WatchGuard Firebox System• Code, messages, and file names appear in monospace font; for example: .wgl and .idx files• In comm

Seite 158 - Default Packet Handling

Chapter 16: Controlling Web Site Access224 WatchGuard Firebox System NOTEYou cannot use WebBlocker exceptions to make an internal host exempt from We

Seite 159 - User Guide 143

Managing the WebBlocker ServerUser Guide 2256 To remove an item from either the Allow or the Deny list, select the address. Click the corresponding Re

Seite 160 - Stopping SYN Flood attacks

Chapter 16: Controlling Web Site Access226 WatchGuard Firebox Systemprocess called WebDBdownload.bat, which appears in your WatchGuard directory under

Seite 161 - Changing SYN flood settings

Automating WebBlocker Database DownloadsUser Guide 227If the message “cannot find Windows Update Files on this computer” appears, open Internet Explor

Seite 162 - 146 WatchGuard Firebox System

Chapter 16: Controlling Web Site Access228 WatchGuard Firebox System

Seite 163 - User Guide 147

User Guide 229CHAPTER 17 Connecting with Out-of-Band ManagementThe WatchGuard Firebox System out-of-band (OOB) management feature enables the Manageme

Seite 164 - Examples

Chapter 17: Connecting with Out-of-Band Management230 WatchGuard Firebox SystemEnabling the Management StationFor a dial-up PPP connection to work bet

Seite 165 - Blocking Sites

Enabling the Management StationUser Guide 231Configure the dial-up connection1 From the Desktop, click My Network Places => Network and Dial-up Con

Seite 166 - Blocking a site permanently

Chapter 17: Connecting with Out-of-Band Management232 WatchGuard Firebox System2 Click Next. Select Connect to the network at my workplace. Click Next

Seite 167 - User Guide 151

Establishing an OOB ConnectionUser Guide 233can pass. After the connection is established, you can use Control Center and by specifying the dial-up PP

Seite 168 - Option” on page 185

User Guide 9CHAPTER 2 Service and SupportNo Internet security solution is complete without systematic updates and security intelligence. From the late

Seite 169 - Blocking Ports

Chapter 17: Connecting with Out-of-Band Management234 WatchGuard Firebox System

Seite 170 - 154 WatchGuard Firebox System

User Guide 227APPENDIX A Troubleshooting Firebox ConnectivityThis chapter provides four ways of connecting to your Firebox should you lose connectivit

Seite 171 - Blocking a port permanently

Appendix A: Troubleshooting Firebox Connectivity228 WatchGuard Firebox System2 Connect one end of the crossover cable to the Optional Interface and th

Seite 172

Method 2: The Flash Disk Management UtilityUser Guide 22910 When the Firebox Flash Disk dialog box appears, as shown in the following figure, select t

Seite 173 - Sites list appears

Appendix A: Troubleshooting Firebox Connectivity230 WatchGuard Firebox Systemsame network as the configuration file, preferably the Trusted network, s

Seite 174 - 158 WatchGuard Firebox System

Method 3: Using the Reset Button - Firebox Models 500, 700, 1000, 2500, 4500User Guide 231configuration passphrase. Use the address you used as the te

Seite 175 - Monitoring Firebox Activity

Appendix A: Troubleshooting Firebox Connectivity232 WatchGuard Firebox System4 Open a DOS prompt, and ping the Firebox with 192.168.253.1. You should

Seite 176 - 160 WatchGuard Firebox System

Method 4: Serial Dongle (Firebox II only)User Guide 2333 Take out one end of the serial cable from the Firebox to break the loop effect.4 On the Manag

Seite 177 - ServiceWatch

Appendix A: Troubleshooting Firebox Connectivity234 WatchGuard Firebox System

Seite 178 - Status Report

User Guide 235Index.cfg files 43.ftr files 210.idx files 192.rep files 205.wgl files 192.wts files 2091-1 Mapping dialog box 901-to-1 NAT. See NAT, 1-

Seite 179 - User Guide 163

Chapter 2: Service and Support10 WatchGuard Firebox SystemThreat alerts and expert adviceAfter a new threat is identified, you’ll receive a LiveSecuri

Seite 180 - 164 WatchGuard Firebox System

236 WatchGuard Firebox Systemand Firebox interfaces 150and IDS applications 147auto-block duration 152auto-blocked 150blocking with service settings 1

Seite 181 - Interfaces

User Guide 237setting up 59DHCP Server dialog box 59DHCP Subnet Properties dialog box 60DHCP support on External interface 31, 36, 54dialog boxes1-1 M

Seite 182 - 166 WatchGuard Firebox System

238 WatchGuard Firebox SystemExternal interfacedescribed26dynamic addressing on 54external network 26, 43Ffailover 6failover logging 174FAQs 7, 13, 77

Seite 183 - HostWatch

User Guide 239viewing uptime and version 162Flash Disk management tool 229FTPand Optional network43and security policy 94FTP proxyand NAT91configuring

Seite 184 - HostWatch display

240 WatchGuard Firebox Systementering 38in example network 23netmask 69of authentication servers 163of Firebox interfaces 52of log hosts 163typing 74W

Seite 185 - 1 Select File => Open

User Guide 241synchronizing NT log hosts 178logging and notificationconfiguring Firebox for174customizing by blocking option 185customizing by service

Seite 186 - 170 WatchGuard Firebox System

242 WatchGuard Firebox Systemdescribed 81setting for a service 88typically used for 81types of 81types supported by proxies 91NAT Setup dialog box 83,

Seite 187 - Notification

User Guide 243status 37tips for creating 48permanently blocked sites 150ping command for source of deny messages 72Policy Manageras view of configurat

Seite 188 - Logging policy

244 WatchGuard Firebox Systemproxy summary 213reasons for generating 203running manually 212scheduling 211sections in 206, 212service summary 213sessi

Seite 189 - Notification policy

User Guide 245rsh 154setting logging and notification for 188setting static NAT for 88viewing number of connections by 161wg_ 105X Font service 154X W

Seite 190 - Failover Logging

LiveSecurity® BroadcastsUser Guide 11Threat ResponseAfter a newly discovered threat is identified, the Rapid Response Team transmits an update specifi

Seite 191 - Adding a log host

246 WatchGuard Firebox Systemviewing status of 69Uunconnected network addresses 150user authentication. See authenticationusers, viewing in HostWatch

Seite 192 - Enabling Syslog logging

User Guide 247and Firebox System requirements 4local and global groups 135preparing Management Station for out-of-band management230running log host o

Seite 193 - Synchronizing log hosts

Chapter 2: Service and Support12 WatchGuard Firebox SystemTo activate the LiveSecurity Service through the Web:1 Be sure that you have the LiveSecurit

Seite 194 - 2000, or Windows XP

LiveSecurity® Self Help ToolsUser Guide 13 NOTEYou must register for LiveSecurity Service before you can access the online support services.Advanced

Seite 195 - User Guide 179

User Guide iii Hudson ([email protected]).© 1995-1998 Eric Young ([email protected]) All rights reserved. This package is an SSL implementation writte

Seite 196 - Viewing the WSEP application

Chapter 2: Service and Support14 WatchGuard Firebox SystemTo access the online support services:1 From your Web browser, go to http://www.watchguard.c

Seite 197 - User Guide 181

Online HelpUser Guide 15called Help. In addition, a “live,” continually updated version of Online Help is available at:http://help.watchguard.com/lss/

Seite 198 - 182 WatchGuard Firebox System

Chapter 2: Service and Support16 WatchGuard Firebox SystemHelp directory from the WatchGuard installation directory on the Management Station. It is i

Seite 199 - 1 Click the Log Files tab

Product DocumentationUser Guide 17Product DocumentationWatchGuard products are fully documented on our Web site at:http://help.watchguard.com/document

Seite 200 - Reference Guide

Chapter 2: Service and Support18 WatchGuard Firebox SystemWeb Contacthttp://www.watchguard.com/supportResponse TimeFour (4) business hours maximum tar

Seite 201 - 1 Select Setup => Name

Training and CertificationUser Guide 19VPN Installation ServicesWatchGuard Remote VPN Installation Services are designed to provide you with comprehen

Seite 202 - 186 WatchGuard Firebox System

Chapter 2: Service and Support20 WatchGuard Firebox System

Seite 203 - User Guide 187

User Guide 21CHAPTER 3 Getting StartedThe WatchGuard Firebox System acts as a barrier between your networks and the public Internet, protecting them f

Seite 204

Chapter 3: Getting Started22 WatchGuard Firebox SystemBefore installing the WatchGuard Firebox System, check the package contents to make sure you hav

Seite 205

Gathering Network InformationUser Guide 23Network addressesOne good way to set up your network is to create two worksheets: the first worksheet repres

Seite 206 - 190 WatchGuard Firebox System

iv WatchGuard Firebox SystemTORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIB

Seite 207 - Log Files

Chapter 3: Getting Started24 WatchGuard Firebox SystemAn example of a network before the Firebox is installed appears in the following figure. In this

Seite 208 - Viewing Files with LogViewer

Selecting a Firewall Configuration ModeUser Guide 25In the example, the secondary network represents the local LAN. Because the Trusted Interface is b

Seite 209 - User Guide 193

Chapter 3: Getting Started26 WatchGuard Firebox SystemExternal InterfaceConnects to the external network (typically the Internet) that presents the se

Seite 210 - 194 WatchGuard Firebox System

Selecting a Firewall Configuration ModeUser Guide 27Characteristics of a routed configuration:• All interfaces of the Firebox must be on different net

Seite 211 - Displaying and Hiding Fields

Chapter 3: Getting Started28 WatchGuard Firebox SystemCharacteristics of a drop-in configuration:• A single network that is not subdivided into smalle

Seite 212 - 196 WatchGuard Firebox System

Selecting a Firewall Configuration ModeUser Guide 29Choosing a Firebox configurationThe decision between routed and drop-in mode is based on your curr

Seite 213 - Working with Log Files

Chapter 3: Getting Started30 WatchGuard Firebox SystemWhen you add a secondary network, you map an IP address from the secondary network to the IP add

Seite 214 - Copying log files

Selecting a Firewall Configuration ModeUser Guide 31Dynamic IP support on the External interfaceIf you are supporting dynamic IP addressing, you must

Seite 215 - Setting log encryption keys

Chapter 3: Getting Started32 WatchGuard Firebox SystemSetting Up the Management StationThe Management Station runs the Control Center software, which

Seite 216 - 200 WatchGuard Firebox System

Cabling the FireboxUser Guide 33more information on the WebBlocker databasem see Chapter 16, “Controlling Web Site Access.” Software encryption level

Seite 217 - User Guide 201

User Guide v1. Ownership and License. The SOFTWARE PRODUCT is protected by copyright laws and international copyright treaties, as well as other inte

Seite 218 - 202 WatchGuard Firebox System

Chapter 3: Getting Started34 WatchGuard Firebox System• Plug the power cord into the Firebox power input and into a power source.

Seite 219 - Network Activity

Running the QuickSetup WizardUser Guide 35Using TCP/IPRefer to Firebox Rear Panel image on the previous page.• Use the red (crossover) cable to connec

Seite 220 - Creating and Editing Reports

Chapter 3: Getting Started36 WatchGuard Firebox SystemManager, use wizard.cfg as the base file to which you make changes. For more information on chan

Seite 221 - Specifying a Report Time Span

Running the QuickSetup WizardUser Guide 37Enter the Firebox Default Gateway(Not applicable if using DHCP or PPPoE on the External interface.) Enter th

Seite 222 - Consolidating Report Sections

Chapter 3: Getting Started38 WatchGuard Firebox SystemYou can remove the blue serial cable from the Management Station and Firebox after the QuickSetu

Seite 223 - The default is 100

Deploying the Firebox into Your NetworkUser Guide 39Deploying the Firebox into Your NetworkCongratulations! You have completed the installation of you

Seite 224 - 208 WatchGuard Firebox System

Chapter 3: Getting Started40 WatchGuard Firebox Systemaddition to the ones listed in the previous section, are HTTP (Internet service) and SMTP (email

Seite 225 - Using Report Filters

User Guide 41CHAPTER 4 Firebox Basics This chapter describes the basic tasks you perform to set up and maintain a Firebox:• Opening a configuration fi

Seite 226 - Editing a report filter

Chapter 4: Firebox Basics42 WatchGuard Firebox System NOTEThere are no user-serviceable parts within the Firebox. If a user opens a Firebox case, it

Seite 227 - Scheduling a report

Opening a Configuration FileUser Guide 43Trusted networkThe network behind the firewall that must be protected from the security challenge.External ne

Seite 228 - Report sections

vi WatchGuard Firebox SystemOBLIGATION, LIABILITY, RIGHT, CLAIM OR REMEDY FOR LOSS OR DAMAGE TO, OR CAUSED BY OR CONTRIBUTED TO BY, THE SOFTWARE PRODU

Seite 229 - User Guide 213

Chapter 4: Firebox Basics44 WatchGuard Firebox SystemOpening a configuration from the Firebox1 Select File => Open => Firebox.The Firebox drop l

Seite 230 - 214 WatchGuard Firebox System

Saving a Configuration FileUser Guide 45Saving a Configuration FileAfter making changes to a configuration file, you can either save it directly to th

Seite 231 - Consolidated sections

Chapter 4: Firebox Basics46 WatchGuard Firebox System5 Enable the checkbox marked Save To Firebox. If you want to make a backup of the current image,

Seite 232 - 216 WatchGuard Firebox System

Resetting Firebox PassphrasesUser Guide 477 If you are making a backup, in the Backup Image field, enter the path where you want to save the backup of

Seite 233 - Controlling Web Site Access

Chapter 4: Firebox Basics48 WatchGuard Firebox System3 Use the Firebox drop list to select a Firebox or enter the Firebox IP address. Enter the config

Seite 234 - 218 WatchGuard Firebox System

Setting the Time ZoneUser Guide 49Setting the Time ZoneThe Firebox time zone determines the date and time stamp that appear on logs and that are displ

Seite 235 - Configuring logging

Chapter 4: Firebox Basics50 WatchGuard Firebox System

Seite 236 - Activating WebBlocker

User Guide 51CHAPTER 5 Using Policy Manager to Configure Your Network Normally, you incorporate the Firebox into your network when you run the QuickSe

Seite 237 - User Guide 221

Chapter 5: Using Policy Manager to Configure Your Network52 WatchGuard Firebox SystemStarting a New Configuration FileTo start a new configuration fil

Seite 238 - 1 Click the WB: Schedule tab

Setting IP Addresses of Firebox InterfacesUser Guide 53Setting addresses in drop-in modeIf you are using drop-in mode, all interfaces use the same IP

Seite 239 - Setting privileges

User Guide viiContents CHAPTER 1 Introduction ... 1Welcome to WatchGuard® ...

Seite 240 - 224 WatchGuard Firebox System

Chapter 5: Using Policy Manager to Configure Your Network54 WatchGuard Firebox SystemSetting addresses in routed modeIf you are using routed mode, the

Seite 241 - User Guide 225

Setting DHCP or PPPoE Support on the External InterfaceUser Guide 55 2 Configure the properties in the dialog box. For a description of each control,

Seite 242 - Installing Scheduled Tasks

Chapter 5: Using Policy Manager to Configure Your Network56 WatchGuard Firebox SystemConfiguring Drop-in ModeIf you selected drop-in mode, you can set

Seite 243 - User Guide 227

Adding Secondary NetworksUser Guide 57Adding Secondary NetworksYour configuration may require that you add secondary networks to any of the Firebox in

Seite 244 - 228 WatchGuard Firebox System

Chapter 5: Using Policy Manager to Configure Your Network58 WatchGuard Firebox SystemEntering WINS and DNS Server AddressesSeveral advanced features o

Seite 245 - Management

Defining a Firebox as a DHCP ServerUser Guide 59Defining a Firebox as a DHCP ServerDynamic Host Configuration Protocol (DHCP) is an Internet protocol

Seite 246 - 230 WatchGuard Firebox System

Chapter 5: Using Policy Manager to Configure Your Network60 WatchGuard Firebox SystemAdding a new subnetTo make available (private) IP addresses acces

Seite 247 - User Guide 231

Adding Basic Services to Policy ManagerUser Guide 61Removing a subnetYou can remove an existing subnet; however, you should be aware that doing so can

Seite 248 - 232 WatchGuard Firebox System

Chapter 5: Using Policy Manager to Configure Your Network62 WatchGuard Firebox SystemIf you need more detailed information on how to add services, see

Seite 249 - OOB time-out disconnects

Configuring RoutesUser Guide 633 Click the Net option.4 Enter the network IP address.5 In the Gateway text box, enter the IP address of the router.Be

Seite 250 - 234 WatchGuard Firebox System

viii WatchGuard Firebox SystemActivating the LiveSecurity® Service ... 11LiveSecurity® Self Help Tools ...

Seite 251 - Connectivity

Chapter 5: Using Policy Manager to Configure Your Network64 WatchGuard Firebox System

Seite 252

User Guide 65CHAPTER 6 Using the WatchGuard Control CenterThe WatchGuard Control Center combines access to WatchGuard Firebox System applications and

Seite 253 - User Guide 229

Chapter 6: Using the WatchGuard Control Center66 WatchGuard Firebox System5 Click OK.Control Center ComponentsControl Center consists of:• A QuickGuid

Seite 254

Control Center ComponentsUser Guide 67QuickGuideThe top part of the display just below the title bar is the QuickGuide. It contains buttons to:Open th

Seite 255 - Armed: Steady

Chapter 6: Using the WatchGuard Control Center68 WatchGuard Firebox SystemPause the display (appears only when connected to Firebox)Connect to Firebox

Seite 256 - Armed light: Steady

Control Center ComponentsUser Guide 69Firebox and VPN tunnel statusThe section in Control Center directly below the front panel shows the current stat

Seite 257 - You should get a reply

Chapter 6: Using the WatchGuard Control Center70 WatchGuard Firebox System• MAC (Media Access Control) address of each interface• Number of packets se

Seite 258

Control Center ComponentsUser Guide 71• The amount of data sent and received on the tunnel in both bytes and packets.• The time at which the key expir

Seite 259

Chapter 6: Using the WatchGuard Control Center72 WatchGuard Firebox System(WSEP) or Management Station. A red exclamation point next to a tunnel listi

Seite 260

Working with Control CenterUser Guide 73• To issue a traceroute command to a source or destination IP address of a deny message, right-click the messa

Seite 261

User Guide ixCustomizing your security policy ... 39What to expect from LiveSecurity® Service ...

Seite 262

Chapter 6: Using the WatchGuard Control Center74 WatchGuard Firebox SystemOpen the WatchGuard Security Event Processor interface. (See “Opening the WS

Seite 263

Working with Control CenterUser Guide 75Changing the polling rateYou can change the interval of time (in seconds) at which Control Center polls the Fi

Seite 264

Chapter 6: Using the WatchGuard Control Center76 WatchGuard Firebox System4 To change the color, click the arrow next to Text Color. Click one of the

Seite 265

Manipulating Traffic MonitorUser Guide 77Home PageSelect to bring up the WatchGuard home page at:http://www.watchguard.comProduct SupportSelect to bri

Seite 266

Chapter 6: Using the WatchGuard Control Center78 WatchGuard Firebox SystemMaximizeDouble-click the Traffic Monitor title bar to maximize the window.

Seite 267

Using Control Center ApplicationsUser Guide 79Launching Firebox MonitorsFirebox Monitors combines an extensive set of WatchGuard monitoring tools into

Seite 268

Chapter 6: Using the WatchGuard Control Center80 WatchGuard Firebox SystemOpening the WSEP user interfaceThe WatchGuard Security Event Processor (WSEP

Seite 269

User Guide 81CHAPTER 7 Configuring Network Address TranslationNetwork address translation (NAT) protects your network by hiding its internal structure

Seite 270

Chapter 7: Configuring Network Address Translation82 WatchGuard Firebox System1-to-1 NATThe Firebox uses private and public IP ranges that you specify

Seite 271

Using Simple Dynamic NATUser Guide 83 NOTEMachines making incoming requests over a VPN connection are allowed to access masqueraded hosts by their ac

Kommentare zu diesen Handbüchern

Keine Kommentare