HotBrickメーカーVPN 800/8 Fの使用説明書/サービス説明書
ページ先へ移動 of 77
.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 1:I n tr o d u c ti o n Congra tulations on the purchase o f your ne w VPN 800/8 F Firewall. The VPN 800/8 F Firewall provides 2 up to 8 WAN ports selections – it als o provides Shared B roadband Internet Access for all LAN users.
HotBrick, Tel: 305 - 398 - 0888, Fa x: 305 - 398 - 5966 There are many load-balancing methods like Outbound load balance by least load(byte/packet/session/IP), Auto-learning, Priority, Round robin, Weight Round Robin, and Auto Backup Connection.
HotBrick, Tel: 305 - 3 98 - 0888, Fax: 305 - 398 - 5966 Oth er Featu r e s DHCP Serve r Suppor t Dy n am i c Ho s t Co n f i g u r at i o n Pr o t oc o l provides dynamic IP addresses to PCs and other devices upon request. The VPN 800/8 F Firewall can act as a DHCP Ser v er for devices on your local LAN.
H otBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Package Contents The following items should be i ncluded: The VPN 800/8 F Firew al l Unit Power Cord Quick Installation Guide CD - ROM containing the on - line manual. Note: I f any of the a bove item s a re damaged or missing, please contact your dealer immediately.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 So me Statu s an d Er r o r co n d i t i o n s ar e i n d i cated b y co mb i n ati o n s o f L ED’ s, as s h o w n b el o w L ED A c t i o n C.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Rear Panel Figure 1 - 3: Rear P anel A C 100V ~ 2 40V Connect to AC100~240 V / 50~60Hz with AC power cord.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Note: The supplied Window s TFTP utility also allows y ou to perform three (3) addition al operations: Save the current c onfiguration se ttings to your PC (use the " Save Config uration" button).
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 2: Quick Installation Overvie w Initial Basic Setup of your VPN 800/8 F Firewall inv olves the following steps: 1. Attach a PC to the VPN 800/8 F Firewall in port 3 ~ 1 4 , and configure your L AN.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 No Response? Is your PC using a Fixed IP address? If so, you must configure your PC to use an IP address within the range 192.168.1.2 to 192.168.1.254, with a Network Mask of 2 55.255.255 .0. See Appendix B – W indows TCP/IP Setup for details.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 8. Select LAN & DHCP f rom the menu. Y ou wil l see a screen l ike the exam ple below. Figure 2 - 3: LAN & DHCP Setup 9. If your LAN alre ady has a DHCP Server, and you wish to continue to use it, the following configuration is required.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Installing the Dual WAN VPN Firew all on your LAN Figure 2 - 4: In stallation D iagram 13. Ensure the V PN 800/8 F Firewall and the DSL/Cable modem are powered OFF. Leave the modem or modems connect ed to t heir data line.
HotBrick, Tel: 305 - 398 - 0888 , Fax: 305 - 398.
HotBrick, Tel: 305 - 398 - 0888 , Fax: 305 - 398 - 5966 3. Quick Installation - LAN & DHCP Select LAN & DHC P from the menu. You will see a screen like the exa mple below. Figure 3 - 1: LAN & DHCP Ensure these settings are suit able for your LAN .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 LAN IP Configuration: IP address - for the VPN 800/8 F Firewall, as seen from the l ocal LAN. Use the default value unless the address is al ready in use or y ou r LAN is using a different I P address range.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 DHCP Client List This table shows t he I P addresses that have been allocated b y the DHCP S erver. For each allocated add ress, the following information is displayed. Name – The ""hostname"" of the PC.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Quick insta ll ation - Prima r y setup Connection mode Enable Select t his i f you have connected a broadban d modem to this port. Disable – Select this if t her e is no bro adband modem c onnected to this port.
3 : Loadbalancing This screen is only operational if using Internet connections on both WAN ports Figure 3 - 2: Load Balan ce Load balancing – Load Balancing Enable – Use this to enable your Load Balance settings. Unless this is checked, the other settings on this scre en ha ve no ef fe ct.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 4 : Advan ced W AN Port options Connec tion valida ti on Health Check – If disabled, the A l ive I ndi cator Check is no t performed.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Transparant b ridge option Bridge Mode – If set to Enable, this WAN port does not use NAT or the Load Balance function when both the LAN and WAN have real IP addresses on the s ame network segment.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 The screen is required in order to use multi ple PPPoE sessions on the same W AN port. It can also be us ed t o manu ally connect or disconn ect a P PPoE session.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Adv a nced WA N PPTP A d vanced W AN WAN Port - Select the desired WAN port (c lick d esired WAN on Connection Status). The data of the selected port will then be displa yed in the WAN IP Accoun t section.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 5 : A d vanced Configuration Adv a nced configuration – Host IP This feature is used in t he following si tuations: You have Multi- Session PPPoE, and wi sh to bind each se ss ion to a particu l ar PC on y our LAN.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Res erv e i n DHC P – S elect E nable to reserve a particular ( LAN) IP address for a particular PC on your LAN. This allows the PC to use D HCP (Wi ndows calls this " obtain an IP address automatically") while h aving an IP address that never changes.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Adv a nced configuration – Routing Routing This section is onl y re lev ant if your LAN has othe r Rout ers or Gateways. If you don't have other Routers or Gatewa ys on your LAN, you can ignore the S tatic Routing page completely .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Gateway – The IP Ad dress of the G ateway o r Router t hat the VPN 800/8 F Firewall must use to communicate with t he destination above. (NOT the router attached to the remote segment.) Interface – Select the correct int erface, usually "LAN".
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 For Router A 's Default Route Destination I P 0.0.0.0 Address Network Mask Network Mask 0.0.0.0 Gateway IP 192.168.2.80 Address Interface LAN Metric 3 Virtual Server This feature allows you to make Servers on your LAN accessible to Internet users.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Web Server (192.168.1.45) PC using FT P Server (ftp://205.20.45.34) FTP Server (192.168.1.20) 205.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 A d v an ced c o n fi g u r ati o n – v i r tu al s er v er Vi r t u al Ser v er Co n f i g u r at i o n En ab l e – The enable checkbox ena bles or disables each Virtual server as required.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Up d at e – Save any chang es you have m ade to the current entry. Can c el – Canc el any changes y ou have made since the last sav e operation. Vi r t u al Ser v er Li s t - This t able shows the detail for al l Custom Virtual Server configuration data.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 A d v an ced co n fi g u r ati o n - Sp ec i al Ap p l i cat i o n If you use Internet applications that use non -standard connections or port numbers, you may find that they do not function correctl y be c ause they are blocked by the VPN 800/8 F Firewall.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Special A ppli cation List - This list shows the detail s for all currently defined Special App l ications.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Dynamic DNS Service This pull -down menu can Enable/Disable the D ynamic DNS feature, and select the required service provider. Dis able – Dynamic DNS is not used. TZO – Select this to use the TZO service (www.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Advanced Configurati on - Multi DMZ This feature allows each WAN por t IP address to be associated with one (1) computer on your LAN. All outgoing traff ic from that PC will be asso cia ted with that W AN port I P add ress.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Advanced Co nfiguration - UPnP Setup With the UPnP ( Universal Plug & Play) function, it is easy t o setup and configure an entire network to enable discovery and control of netw orked devices and services.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Adv a nced Co nfiguration – NA T Setti ng NAT Conf igura tion NAT Routing – You can enable or disable NAT b y using the checkbox. If you disable the NAT checkbox, it will act as a brid ge or Static Router.
H otBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Adv a nced Configuration – Advanced F eature External Filters Conf iguration IDENT Port – Port 113 is ass ociated with the Internet's (Identification / Authentic at ion) service.
HotBrick, T el: 305 - 398 - 0888, Fax: 305 - 398 - 5966 settings to correct the problem. Enable - If enable d, the WAN port you specify will be used for a ll outgoing SMTP traffic. If disabled, either WAN port will be used. WAN – Select the desired WAN port to be bound.
6 – Security Management Security Management – Block URL This feature allows you to block access to undesirable Web sites. You can block by URL, IP address, or Keyword. You can also have different blocking settings for different groups of PCs. Every URL is searched to see if it matches or c ontains any of the URLs or keywords entered here.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Securit y Mana gement – A ccess Filter The network administrator can use the A ccess Filter to control the Internet acces s and applications available to LAN users. Five (5) user g r oups are availabl e, a nd each g roup can have different access r ights.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Port Blocking – T here are two possible settings : No Filtering - all ports are open Block A ll Access – A ll ports are closed. When you m ake a new rule, the port w ill be opened for that entry (maxim u m number of rules you enter a re 50 ).
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Sec u r i t y M an ag emen t – Sy stem Fi l ter Exe p ti o n Sy s f i l t er e x c ep t i o n - System Filter Exception – will reject every packet with an unrecognized port to avoid port s can programs run by hacke rs b ut this also incurs problems when servers (e.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 7 : VPN Con figurati on Virtual Private Network (VPN) uses encryption and authentication to create the connection between two end points (computers or networks).
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 VPN Configuration – Tunnel to HotBrick Unit VPN Tunnel List – here you can add a new tunnel or change an existing one from the list.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Tunnel to HotBrick Client – T his describes an IPSec tunnel from a t he VPN 8 00/ 8 F to the H ot Brick Client Software. VPN Tunnel List– allows you to add a new tunnel or change an existing one on the list .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 596 6 Tunnel Name– I n or der to distinguish the t unnel, you have to g ive the “ T unnel ” a unique name. PPPoE Session – If you ar e using PPPoE to make the connection, and your ISP offers multiple PPPoE session s , you can select these PPPoE sessions to constru ct VPN tunnels.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Key management Key – Key Type: there are two key t ypes (manual k ey and auto key) available fo r key exchange manag ement. Manual Key: I f m anual key is selected, no key negotiation is needed.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 IPSec policy options Tunnel Attribute – T he defined attributes for the tunnel . Dead Peer Detection - T his setting allows you to use a WAN port f or backup or for WAN failover in the event of a connection failure.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Set DF Flag - If this DF (Do not Fr agment) flag is set, it means the f ra gm enta tion of this packet at the IP level is not permitted.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 VPN Configuration – SA List VPN configuration – SA The list will display the details of all Policy Setup c onfig ur ation data that you have setup. You can modify it by mouse - clicking each row .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 VPN Configuration – VPN Log You can monitor the VPN status through the VPN log web page. The log le vel (priority) can be chosen from VPN IKE Global Setting web page. Message Status Time – This i ndicates when this message is created using the system t ime.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 8: QoS Configuration QoS Configuration – ove rview The V P N 800/8 F F i re wa l l p rov i de s Q oS , whic h s uppor ts h i g h qua l i ty ne twor k s e rvi c e .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 QoS Configura t ion – QoS Setup QoS Setup QoS Feature Enable QoS – T his will allow us ers t o enable the QoS function. Queuing Method - The method used to m anage your queue. Prio rity que uing is one of the first queuing solution s to be wi de ly implemented.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 P oli c y Na m e L i s t – Wh e n a ddi ng a ne w P o l i c y, i g nor e this l i s t. To e d i t a n e xi s ti ng e nt ry, s e l e c t i t f rom the l i s t a nd th e n c l i c k the " S e l e c t" bu tton.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 9 : M anagement Assist ant Management ass ist ant – A dmin Password Enter the desired password, re-enter it in the Ve rify Passwo rd field, then save it. When you connect to the Load Balancer with y our Browser, y ou will be pro mpted for the password as shown below.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Management Assistant – Email Alert This feature will send a warning Email to inform the system administrator that one of the WAN por ts is disconnected. Enable/Disable E mail A lert Enable – This enables E mail Alert to send a warning email when a WAN port disconne ct s.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Ping Before Notification - A thr e s ho l d va l ue f o r th e m a xi m u m P i ng s a l l ow e d t o e a c h i nt e rf a c e on this de vi c e i n a m i nut e . The va l i d va l ue s ra ng e f rom 0 to 9999.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Management A sssistant – Sy slog This feature can send real time system information on the web page or to the specifie d P C. Syslog Delivery Sending out – Check this, if you want to send sy s log messages to an other machine.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Management A ssistant - Upgrad e Firm w are 62.
HotBrick, Tel: 305 - 398 - 0888, Fax: 30 5 - 398 - 5966 10: Device Status Once both the VPN 800/8 F Firewall and t he PCs are configured, operation is automatic. However, some additional Internet configuration may be r equired for your specific network .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 DHCP Server – The status of the DHCP Server function - either "Enabled" or "Disabled". Device S tatus - W AN status NAT Statistics This section displays data for each WAN port.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Data – NAT Status LAN IP info IP Address – The LAN IP Address of the VPN 800/8 F Firewall. Mask Address – The Network Mask (Subnet Mask) for the IP Address above. A c tive W AN IP Info – There is one (1) row for each active connection.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Device informatio n – Device Information Device Information Firmware V ersion – Version of the Firmware c urrently inst alled. NAT – Status of the NAT feature – either “ Enab le” or “ Disable ” .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 If the "Restore Default Value" button on this screen is clicked: A l l your current s ettings wil l be erased. The default IP address, password and ALL other settings w ill be restored to the factory default values.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Appen dix A Specifications Model HotBrick VPN 8 00/ 8 F Firewall Dimensions 120mm (W) x 427mm (D) x 43.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Appen dix B Window s TCP/IP Setup Overvie w TCP/IP Settings If using the default Load Bala ncer s ettings, and the default Windows 95/98/ME/2000 settings, no c hanges need to be made.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Ensure your TCP/IP settings are correct, as follows: Using DHCP To use DHCP, select the radio button Obtain an IP Address automatically. This is the default Windows settings. Restart your PC to ensure it obt ains an IP Address from the VPN 800/8 F Firewall Router.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 On the DNS Configuration tab, ensure Enable DNS is selected. If the DNS Server Search Order list is empty, enter t he DNS address provided by your ISP in the fie l ds beside the Add button, then click Add.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Figure B -6: TCP/IP Properties ( Win 2000 ) Ensure your TCP/IP settings are correct. Using DHCP To use DHCP, select the radio button Obtain an IP Address automatically. This is the defa ult Windows setting.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Checking TCP/IP S ettings - Windows XP: 7. Sel ect Control Panel - Network Connection. Right click the Local Area Connection and choose Properties.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Figure B - 8: TC P/IP Propert ies (Windows X P) Ensure your TCP/IP settings are correct. Using DHCP To use DHCP, select the radio button obtain an IP A d d ress automatically. This is the default Windows setting.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Appen dix C Troubleshooting Overvie w T his chap ter covers som e comm on problem s that may be encount ered while using the V P N 800/8 F F i re wa l l a nd s om e pos s i ble s olut i onsf o r th e m .
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 Appen dix D : IPSec Tunnel Examples VPN Configurat ion – Examples Tunnel to HotB ri ck Unit The HotBrick units in the fol lowing example use registered IP addresses. You have to replace t hese addresses with I P addresses that are availab le t o you.
HotBrick, Tel: 305 - 398 - 0888, Fax: 305 - 398 - 5966 First we wil l make settings in th e VPN 80 0/ 8 F Next we will m ake settings for the LB-2 VPN Note : you need d ifferent subnets at bo th ends of the tunnel.
デバイスHotBrick VPN 800/8 Fの購入後に(又は購入する前であっても)重要なポイントは、説明書をよく読むことです。その単純な理由はいくつかあります:
HotBrick VPN 800/8 Fをまだ購入していないなら、この製品の基本情報を理解する良い機会です。まずは上にある説明書の最初のページをご覧ください。そこにはHotBrick VPN 800/8 Fの技術情報の概要が記載されているはずです。デバイスがあなたのニーズを満たすかどうかは、ここで確認しましょう。HotBrick VPN 800/8 Fの取扱説明書の次のページをよく読むことにより、製品の全機能やその取り扱いに関する情報を知ることができます。HotBrick VPN 800/8 Fで得られた情報は、きっとあなたの購入の決断を手助けしてくれることでしょう。
HotBrick VPN 800/8 Fを既にお持ちだが、まだ読んでいない場合は、上記の理由によりそれを行うべきです。そうすることにより機能を適切に使用しているか、又はHotBrick VPN 800/8 Fの不適切な取り扱いによりその寿命を短くする危険を犯していないかどうかを知ることができます。
ですが、ユーザガイドが果たす重要な役割の一つは、HotBrick VPN 800/8 Fに関する問題の解決を支援することです。そこにはほとんどの場合、トラブルシューティング、すなわちHotBrick VPN 800/8 Fデバイスで最もよく起こりうる故障・不良とそれらの対処法についてのアドバイスを見つけることができるはずです。たとえ問題を解決できなかった場合でも、説明書にはカスタマー・サービスセンター又は最寄りのサービスセンターへの問い合わせ先等、次の対処法についての指示があるはずです。