Global Technology AssociatesメーカーGBWA200501-01の使用説明書/サービス説明書
ページ先へ移動 of 60
G B - W a r e S OFT W ARE F i re wa l l P roduc t Guide GBW A200501-01 powered by GNA T Bo x S y st e m So f t w ar e.
Copyright © 1996-2004, Global T echnology Associates, Incorporated (GTA). All rights reserved. Except as permitted under copyright law , no part of this manual may be reproduced or distributed in any form or by any means without the prior permission of Global T echnology Associates, Incorporated.
T able of Contents iii Contents 1 INTRODUCTION ............................................................................................... 1 About GT A Firewalls .....................................................................................
GB-Ware Firewall Product Guide iv Re-configuring Y our Computer ................................................................ 28 Accessing the Firewall ............................................................................ 28 Configuration Using GBAdmin .
1 - Introduction 1 1 Introduction About GT A Firewalls Global T echnology Associates, Inc. (GT A) has been designing and building Internet firewalls since 1994. In 1996, GT A developed the first truly affordable commercial-grade firewall, the GNA T Box ® .
GB-Ware Firewall Product Guide 2 • Dynamic DNS • DNS proxy • T ransparent and traditional web proxy with script blocking • DNS server (optional on 10 user version) • DHCP server • Web and .
1 - Introduction 3 Software Specifications Specification GB-W are 10 users GB-W are unrestricted users Concurrent connec- tions (standard) 1,000 128,000 Concurrent out- bound users (stan- dard) 10 Un.
GB-Ware Firewall Product Guide 4 configuration with full network speeds on all interfaces. The best possible performance can be obtained by using a Pentium class or higher CPU with PCI network cards. Network performance bottlenecks usually occur at the connection to the Internet when using DSL or T1 class connectivity .
1 - Introduction 5 Optional Components • 1-18 additional network cards (if using the Multi-Interface Option) • Async modem (PPP connections or pager only) • ISDN T A with RS-232 interface (PPP c.
GB-Ware Firewall Product Guide 6 Modem/ISDN T A Hardware GT A recommends configuring the modem or ISDN T A on another system before installing it on GB-W are. Most modems allow the storage of a user configuration and the recall of this configuration using a specific command (e.
1 - Introduction 7 Other avenues for assistance are available through authorized GT A Channel Partners, the GNA T Box Mailing List, or the GT A web site (www .gta.com). Upgrades Once registered, you can view available upgrades in the GT A online support center section of the GT A web site (www .
GB-Ware Firewall Product Guide 8 Additional Documentation For additional instructions on installation, registration and setup of a GT A product, see applicable Quick Guides, F AQs or technical papers. For optional features, see the appropriate feature guide.
2 – Installation 9 2 Installation Registration T o get technical support and software updates, you must register your GT A firewall. 1) T o register , go to www .gta.com. Click on SUPPORT and then the SUPPORT CENTER link to visit https://gta.com/support/center/login/.
GB-Ware Firewall Product Guide 10 Installing GB-W are on PC Hardware GB-W are software must be installed on x86 (Intel-compatible) computer hardware before you can use your firewall. The GB-W are installation CD will install the firewall software onto your computer hardware.
2 – Installation 1 1 Setup for GB-W are Installation The computer (either the intended firewall or an installation proxy computer) must be modified to boot using a CD-ROM drive. This enables the GNA T Box System Software installation CD to activate and install the GB-W are firewall software when powering on the PC.
GB-Ware Firewall Product Guide 12 Caution Inst alli ng GB -W are on a hard drive wil l era se its cont ents and replace them with GB-Ware. If you wish to keep the data on a hard drive, do not install GB-W are on it; instead, install GB-Ware on a dif ferent hard drive.
2 – Installation 13 GNA T Box System Softwar e Licensing Agr eement Selecting a GB-W are Runtime The GNA T Box System Software Runtime Installer screen will appear . If you are upgrading, verify that your configuration has been backed up to another location.
GB-Ware Firewall Product Guide 14 The serial version of the GB-Ware runtime installs factory default settin gs; a serial or temporary peer Ether net con necti on can be used to change these settings. If you prefer to perform initial firewall configuration over the web or with GBAdmin, choose this option.
2 – Installation 15 Note USB pen drives may appear , but should not be selected for installation as they are not IDE-bootable devices. CD-ROM or DVD- ROM dr ives will not be displayed by the GB- W are system ins tallat ion process, as they are not writable discs.
GB-Ware Firewall Product Guide 16 Disk Re-formatting W arning It may take several minutes for the runtime to install. A pipe indicator (|) will be animated while the system installs.
2 – Installation 17 attach the hardware key block to a prospective GB-W are firewall and boot the GB-W are disk..
GB-Ware Firewall Product Guide 18.
3 – Configuration 19 3 Configuration The following sections describe how to change GB-W are from the default configuration, in which all internal users are allowed outbound connections, but no unsolicited inbound connections are allowed.
GB-Ware Firewall Product Guide 20 During installation, you chose the video or the serial console version of the GNA T Box runtime. These methods can be used during setup, or when you have direct physical access to the firewall, or as a failsafe if the network is down and you can no longer administer your firewall remotely .
3 – Configuration 21 Requirements If using the web user interface, you will need: • 1 crossover Ethernet cable to connect with the computer directly , or 1 straight-through Ethernet cable to conne.
GB-Ware Firewall Product Guide 22 match the network address scheme. Then you may add the firewall to your network and connect remotely (by web or GBAdmin) through your normal network. 1) Use a crossover Ethernet cable to connect a computer to the fire- wall’s first network interface card.
3 – Configuration 23 T emporary Network Configuration for Connection with Fir ewall Defaults - Mac OS X 3) Reboot your computer if necessary to put your new network configu - ration into effect. Note Please refer to the GNAT Box System Softwar e User’ s Guide for specific information about editing network information.
GB-Ware Firewall Product Guide 24 Configuring Y our Firewall Y ou will need to configure your firewall to match your network scheme before installing it.
3 – Configuration 25 On Macintosh computers, GT A does not recommend using Microsoft Internet Explorer for Macintosh (Mac IE 5). OpenSSL encryption, used by the firewall, is known to be incompatible with Mac IE 5, and your browser will not allow you to continue past the security alert screen.
GB-Ware Firewall Product Guide 26 Entering the Default User ID and Passwor d Caution GT A recommends changing the default user ID and password to prevent unauthorized access. Entering Y our Network Information GB-W are requires entry of the serial number and activation code.
3 – Configuration 27 Caution Closing the browser without clicking SA VE will cause the entered data to be lost, and your firewall will remain in default configuration. Y ou will need to re-connect to the firewall and re-enter the network information.
GB-Ware Firewall Product Guide 28 Using CIDR-based or Slash (/) Notation CIDR (Classless Inter-Domain Routing) aggregates routes so that one IP address represents thousands served by a backbone provider . GNA T Box System Software uses CIDR-based notation as the default for subnet masks, instead of dotted decimal (e.
3 – Configuration 29 Caution Failure to change the default password is a serious security weakn ess. G T A r ecomm ends cha nging the defaul t user ID and password to prevent unauthorized access.
GB-Ware Firewall Product Guide 30 GBAdmin Network Information W indow Entering Y our Network Information GB-W are requires entry of the serial number and activation code. Click on Basic Configuration and expand the menu, then select F eatures . Enter the serial number and activation code, then click the SA V E button then the OK button.
3 – Configuration 31 Caution Closing GBAdm in without clic king SA VE will cause the entered data to be lost, and your firewall will remain in default configuration. Y ou will need to re-connect to the firewall and re-enter the network information.
GB-Ware Firewall Product Guide 32 1) On your computer , open terminal emulator software such as T era T erm or Microsoft HyperT erminal and enter the following settings for a new connection: E MULA TI.
3 – Configuration 33 2) If you specified the video console version during installation and your hardware was configured correctly , and the system did not encounter any problems, the Setup Wizard should now appear . Video Console Navigation There are three modes on the video console: log messages, the main inter- face and statistics.
GB-Ware Firewall Product Guide 34 Note If you cancel the Setup Wizard, go to Basic Configuration then Features to enter your serial number and activation code. Next, enter your initial configuration information in Basic Configuration then N etwo rk Information .
3 – Configuration 35 Run DHCP? 6c. IP Address Y ou will reach this option if you rejected use of dynamic IP address services. Enter the static IP address and subnet mask of the exter - nal network interface.
GB-Ware Firewall Product Guide 36 ment Numbers Authority (IANA) has specified network addresses in RFC 1918 that are designated exclusively for internal networks. IANA Private Network IP Address Rules Quantity of Addresses Available Network Class IP Address Range 1 A 10.
3 – Configuration 37 Accessing Y our GT A Firewall After completing the initial configuration in the setup wizard, your GT A firewall should be active and functioning in default security mode (all internal users are allowed outgoing connections, and no unsolicited connec- tions are allowed in).
GB-Ware Firewall Product Guide 38.
4 – T roubleshooting 39 4 T roubleshooting T roubleshooting Basics GT A Support recommends the following guidelines as a starting point when troubleshooting network problems: • Start with the simplest case of locally attached hosts. • Use IP addresses, not names.
GB-Ware Firewall Product Guide 40 • Have you added a static route on the firewall to tell it which router is used to reach the Internet? Have you set the router ’s default route to be the firewa.
4 – T roubleshooting 41 Note Distinguish between crossover cables and straight-through cables by comparing the connection ends. On a straight-through cable, the wire order matches; on a crossover cable, the first three of the four wires are in reverse order .
GB-Ware Firewall Product Guide 42 Installation of the USB Key Block 3. Enter the GB-W are serial number and activation code in the Basic Configuration then F eatures section of the GB-W are web interface or wizard.
4 – T roubleshooting 43 1 1. The warning message “Initializing runtime slice 2 failed; No space left on device” is displayed. 1. The Compact Flash card is too small; GT A only supports GT A-certi- fied Compact Flash cards. 2. The Compact Flash card no longer functions correctly; contact GT A or a GT A Channel Partner for hardware warranty .
GB-Ware Firewall Product Guide 44 13. How do I revert to my previous configuration after a version upgrade? The firewall’s Compact Flash or hard drive memory is in two sections (“slices”); one contains the current software version plus any saved configu- ration, the other contains the previous software version and configuration.
4 – T roubleshooting 45 1. If you have more than one CD-ROM drive installed, either discon- nect the additional CD-ROM drives and retry , or verify that the installation CD-ROM drive is detected first in the boot sequence, before other CD-ROM drives in the IDE controller ports.
GB-Ware Firewall Product Guide 46.
4 – T roubleshooting 47 Appendix Installing the Compact Flash Card If you are installing your GB-W are firewall on a Compact Flash card, use these instructions to install the Compact Flash card for your firewall.
GB-Ware Firewall Product Guide 48 Warning Improper grounding can damage your system or Compact Flash card, and may cause physical injury or death. Never service your GB-W are system while it is plugge.
4 – T roubleshooting 49 (Refer to the motherboard’ s user guide if you cannot locate the IDE controller ports.) Locating the Primary IDE Contr oller Port Mounting the Compact Flash Card Mount the .
GB-Ware Firewall Product Guide 50 Connecting the IDE Cable Insert one end of the IDE cable into the primary IDE controller port with the red-striped side of the cable lined up with pin #1 of the IDE controller port.
4 – T roubleshooting 51 Note Those upgrading from GNA T Box System Software version 2.x or lower should record all configuration data and use it as a guide to enter new configuration data manually . Y ou may use the web interface to print the configuration or manually record it.
GB-Ware Firewall Product Guide 52 4) GBAdmin will connect to the GB-W are firewall and prompt you for the user ID and password selected during installation; when suc- cessfully authenticated, GBAdmin will load the GB-W are configura - tion. 5) Merge the old configuration with the GB-W are firewall configuration.
4 – T roubleshooting 53 Note If your NIC is not listed, it’s possible that you are upgrading from an older version in which that NIC was supported. Please contact support with any questions. If you are placing the configuration on new hardware with different NICs, you will need to select your cards.
GB-Ware Firewall Product Guide 54.
Index 55 Index Symbols 4-pin power port 52. A activation code 34, 41, 47. adapter board 49. ADSL 5. asterisk. See wildcard symbol. auto-detect IDE 45. B Baud Rate 43. boot 39, 44. browsers Internet Explorer ii. C cable 40, 41, 43. cable modem 34. case-sensitive 43.
GB-Ware Firewall Product Guide 56 log 43. Login 26. login 43. lost 43. lost 43. lower case 43. M mailing list 8. memory 43, 44. memory slice 16, 43. Microsoft 40. modem 6, 43. mounting posts 49, 50. N network configuration 40. Note 9, 23. notes & warnings 4, 5, 6, 10, 35.
デバイスGlobal Technology Associates GBWA200501-01の購入後に(又は購入する前であっても)重要なポイントは、説明書をよく読むことです。その単純な理由はいくつかあります:
Global Technology Associates GBWA200501-01をまだ購入していないなら、この製品の基本情報を理解する良い機会です。まずは上にある説明書の最初のページをご覧ください。そこにはGlobal Technology Associates GBWA200501-01の技術情報の概要が記載されているはずです。デバイスがあなたのニーズを満たすかどうかは、ここで確認しましょう。Global Technology Associates GBWA200501-01の取扱説明書の次のページをよく読むことにより、製品の全機能やその取り扱いに関する情報を知ることができます。Global Technology Associates GBWA200501-01で得られた情報は、きっとあなたの購入の決断を手助けしてくれることでしょう。
Global Technology Associates GBWA200501-01を既にお持ちだが、まだ読んでいない場合は、上記の理由によりそれを行うべきです。そうすることにより機能を適切に使用しているか、又はGlobal Technology Associates GBWA200501-01の不適切な取り扱いによりその寿命を短くする危険を犯していないかどうかを知ることができます。
ですが、ユーザガイドが果たす重要な役割の一つは、Global Technology Associates GBWA200501-01に関する問題の解決を支援することです。そこにはほとんどの場合、トラブルシューティング、すなわちGlobal Technology Associates GBWA200501-01デバイスで最もよく起こりうる故障・不良とそれらの対処法についてのアドバイスを見つけることができるはずです。たとえ問題を解決できなかった場合でも、説明書にはカスタマー・サービスセンター又は最寄りのサービスセンターへの問い合わせ先等、次の対処法についての指示があるはずです。