Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual
Have a look at the manual Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 137 Netgear manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.
Configure the IPv4 LAN Settings 120 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Note:For information about how to manage VLANs, see Port-Based VLANs on page 11 6. The following sections provide information about managing VLAN profiles: •Add a VLAN Profile •Change a VLAN Profile •Enable, Disable, or Delete Existing VLAN Profiles Add a VLAN Profile The following procedure describes how to add a VLAN profile with an IP address, associate ports with the VLAN profile, and configure optional settings such as DHCP settings, a DNS proxy, and inter-VLAN routing. To add a VLAN profile: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings. The LAN submenu tabs display, with the LAN Setup screen in view, displaying the IPv4 settings. The following figure contains some VLAN profiles as an example.
Configure the IPv4 LAN Settings 121 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 7. Click the Add button. The Add VLAN Profile screen displays.
Configure the IPv4 LAN Settings 122 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 8. Enter the settings as described in the following table. SettingDescription VLAN Profile Profile Name Enter a unique name for the VLAN profile. VLAN ID Enter a unique ID number for the VLAN profile. No two VLANs can have the same VLAN ID number. Note:You can enter VLAN IDs from 2 to 4089. VLAN ID 1 is reserved for the default VLAN; VLAN ID 4094 is reserved for the DMZ interface. Port Membership Port 1, Port 2, Port 3, Port 4 / DMZSelect one, several, or all port check boxes to make the ports members of this VLAN. Note:A port that is defined as a member of a VLAN profile can send and receive data frames that are tagged with the VLAN ID. IP Setup IP Address Enter the IP address of the VPN firewall (the factory default address is 192.168.1.1). Note:Ensure that the LAN port IP address and DMZ port IP address are in different subnets. Note:If you change the LAN IP address of the VLAN while connected through the browser to the VLAN, you are disconnected. You then must open a new connection to the new IP address and log in again. For example, if you change the default IP address 192.168.1.1 to 10.0.0.1, you now must enter https://10.0.0.1 in your browser to reconnect to the web management interface. Subnet Mask Enter the IP subnet mask. The subnet mask specifies the network number portion of an IP address. Based on the IP address that you assign, the VPN firewall automatically calculates the subnet mask. Unless you are implementing subnetting, use 255.255.255.0 as the subnet mask (computed by the VPN firewall). DHCP Select one of the following radio buttons: • Disable DHCP Server. If another device in the LAN functions as the Dynamic Host Configuration Protocol (DHCP) server for the VLAN, or if you intend to manually configure the network settings of all computers in the VLAN, select the Disable DHCP Server radio button to disable the DHCP server. Except for the default VLAN for which the DHCP server is enabled, this is the default setting. • Enable DHCP Server. To enable the VPN firewall to function as the DHCP server for the VLAN, select the Enable DHCP Server radio button. (For the default VLAN, the DHCP server is enabled by default.) Complete the Start IP Address, End IP Address, and Lease Time fields. The Domain Name, Primary DNS Server, Secondary DNS Server, and WINS Server fields are optional, as is the Enable LDAP information check box and associated fields. • DHCP Relay. To use a DHCP server somewhere else in your network as the DHCP server for the VLAN, select the DHCP Relay radio button. In the Relay Gateway field, enter the IP address of the DHCP server.
Configure the IPv4 LAN Settings 123 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Domain Name This setting is optional. Enter the domain name of the VPN firewall. Start IP Address Enter the start IP address. This address specifies the first of the contiguous addresses in the IP address pool. Any new DHCP client joining the LAN is assigned an IP address between this address and the end IP address. For the default VLAN, the default start IP address is 192.168.1.100. End IP Address Enter the end IP address. This address specifies the last of the contiguous addresses in the IP address pool. Any new DHCP client joining the LAN is assigned an IP address between the start IP address and this IP address. For the default VLAN, the default end IP address is 192.168.1.254. The start and end DHCP IP addresses must be in the same network as the LAN IP address of the VPN firewall (that is, the IP address in the IP Setup section as described earlier in this table). Primary DNS Server This setting is optional. If an IP address is specified, the VPN firewall provides this address as the primary DNS server IP address. If no address is specified, the VPN firewall uses the VLAN IP address as the primary DNS server IP address. Secondary DNS Server This setting is optional. If an IP address is specified, the VPN firewall provides this address as the secondary DNS server IP address. WINS Server This setting is optional. Enter a WINS server IP address to specify the Windows NetBIOS server, if one is present in your network. Lease Time Enter a lease time. This specifies the duration for which IP addresses are leased to clients. Enable LDAP informationTo enable the DHCP server to provide Lightweight Directory Access Protocol (LDAP) server information, select the Enable LDAP information check box. Enter the following settings: • LDAP Server. The IP address or name of the LDAP server. • Search Base. The search objects that specify the location in the directory tree from which the LDAP search begins. You can specify multiple search objects, separated by commas. The search objects include the following: - CN (for common name) - OU (for organizational unit) - O (for organization) - C (for country) - DC (for domain) For example, to search the netgear.net domain for all last names of Johnson, enter the following objects: cn=Johnson,dc=Netgear,dc=net • Port. The port number for the LDAP server. The default setting is 0 (zero). DNS Proxy Enable DNS Proxy This setting is optional. To enable the VPN firewall to provide a LAN IP address for DNS address name resolution, select the Enable DNS Proxy check box. This feature is disabled by default. Note:If you clear the Enable DNS Proxy check box for the VLAN, all computers in the VLAN receive the DNS IP addresses of the ISP but without the DNS proxy IP address. SettingDescription
Configure the IPv4 LAN Settings 124 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 9. Click the Apply button. Your settings are saved. Change a VLAN Profile The following procedure describes how to change an existing VLAN profile. To change a VLAN profile: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings. The LAN submenu tabs display, with the LAN Setup screen in view, displaying the IPv4 settings. 7. In the VLAN profiles table, click the Edit button for the VLAN profile that you want to change. The Edit VLAN Profile screen displays. 8. Change the settings. For information about the settings, see Add a VLAN Profile on page 120. Inter VLAN Routing Enable Inter VLAN RoutingThis setting is optional. To ensure that traffic is routed only to VLANs for which inter-VLAN routing is enabled, select the Enable Inter VLAN Routing check box. This feature is disabled by default. When you clear the Enable Inter VLAN Routing check box, traffic from this VLAN is not routed to other VLANs, and traffic from other VLANs is not routed to this VLAN. SettingDescription
Configure the IPv4 LAN Settings 125 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 9. Click the Apply button. Your settings are saved. The modified VLAN profile displays in the VLAN Profiles table on the LAN Setup screen. Enable, Disable, or Delete Existing VLAN Profiles The following procedure describes how to enable or disable existing VLAN profiles or remove VLAN profiles that you no longer need. To enable, disable, or remove one or more VLAN profiles: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings. The LAN submenu tabs display, with the LAN Setup screen in view, displaying the IPv4 settings. 7. In the VLAN Profiles table, select the check box to the left of each VLAN profile that you want to enable, disable, or remove or click the Select All button to select all profiles. Note:You cannot select the default VLAN profile, that is, you cannot disable or remove the default VLAN profile. 8. Click one of the following buttons: •Enable. Enables the selected VLAN profiles. The ! status icons change from gray circles to green circles, indicating that the selected profiles are enabled. By default, when you add a profile to the table, the profile is automatically enabled. •Disable. Disables the selected VLAN profiles.
Configure the IPv4 LAN Settings 126 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 The ! status icons change from green circles to gray circles, indicating that the selected profiles are disabled. •Delete. Removes the selected VLAN profiles. The selected profiles are removed from the VLAN Profiles table. Configure Unique VLAN MAC Addresses By default, all configured VLAN profiles share the same single MAC address as the LAN ports. (All LAN ports share the same MAC address.) However, you can change the VLAN MAC settings to allow up to 16 VLANs to each be assigned a unique MAC address. To configure VLANs to have a unique MAC address: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings. The LAN submenu tabs display, with the LAN Setup screen in view, displaying the IPv4 settings. 7. Click the Advanced option arrow in the upper right. The IPv4 LAN Advanced screen displays.
Configure the IPv4 LAN Settings 127 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 8. From the MAC Address for VLANs menu, select Unique. The default setting is Same. 9. Click the Apply button. Your settings are saved. VLANs have unique MAC addresses. Note:If you attempt to configure more than 16 VLANs, the MAC addresses that are assigned to each VLAN might no longer be distinct. Disable the Broadcast of ARP Packets for the Default VLAN You can disable the broadcast of Address Resolution Protocol (ARP) packets for the default VLAN. If the broadcast of ARP packets is enabled, IP addresses can be mapped to physical addresses (that is, MAC addresses). By default, the broadcast of ARP packets is enabled for the default VLAN. To disable the broadcast of ARP packets for the default VLAN: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain.
Configure the IPv4 LAN Settings 128 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings. The LAN submenu tabs display, with the LAN Setup screen in view, displaying the IPv4 settings. 7. Click the Advanced option arrow in the upper right. The IPv4 LAN Advanced screen displays. 8. Clear the Enable ARP Broadcast check box. 9. Click the Apply button. Your settings are saved. The broadcast of ARP packets for the default VLAN is disabled. Manage IPv4 Multihome LAN IP Addresses on the Default VLAN The following sections provide information about managing IPv4 multihome LAN IP addresses on the default VLAN: •IPv4 Multihome LAN IP Addresses •Add a Secondary LAN IPv4 Address •Change a Secondary LAN IPv4 Address •Remove One or More Secondary LAN IPv4 Addresses IPv4 Multihome LAN IP Addresses If computers use different IPv4 networks in the LAN (for example, 172.124.10.0 and 192.168.200.0), you can add aliases to the LAN ports and give computers on those networks
Configure the IPv4 LAN Settings 129 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 access to the Internet, but you can do so only for the default VLAN. The IP address that is assigned as a secondary IP address must be unique and cannot be assigned to a VLAN. Make sure that any secondary LAN addresses are different from the primary LAN, WAN, and DMZ IP addresses and subnet addresses that are already configured on the VPN firewall. The following is an example of correctly configured IPv4 addresses: •WAN IP address. 10.0.0.1 with subnet 255.0.0.0 •DMZ IP address. 176.16.2.1 with subnet 255.255.255.0 •Primary LAN IP address. 192.168.1.1 with subnet 255.255.255.0 •Secondary LAN IP address. 192.168.20.1 with subnet 255.255.255.0 Add a Secondary LAN IPv4 Address The following procedure describes how to add a secondary LAN IPv4 address. To add a secondary LAN IPv4 address: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings > LAN Multi-homing. The LAN Multi-homing screen displays the IPv4 settings. The following figure shows one example.