Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual
Have a look at the manual Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 137 Netgear manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.
Configure the IPv4 LAN Settings 130 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 The Available Secondary LAN IPs table displays the secondary LAN IP addresses that you added to the VPN firewall. 7. In the Add Secondary LAN IP Address section, enter the following settings: •IP Address. Enter the secondary address that you want to assign to the LAN ports. •Subnet Mask. Enter the subnet mask for the secondary IP address. 8. Click the Add button. The secondary IP address is added to the Available Secondary LAN IPs table. 9. Repeat Step 7 and Step 8 for each secondary IP address that you want to add to the Available Secondary LAN IPs table. Note:You cannot configure secondary IP addresses in the DHCP server. For the hosts on the secondary subnets, you must manually configure the IP addresses, gateway IP address, and DNS server IP addresses. Change a Secondary LAN IPv4 Address The following procedure describes how to change an existing secondary LAN IPv4 address. To change a secondary LAN IP address: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password.
Configure the IPv4 LAN Settings 131 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings > LAN Multi-homing. The LAN Multi-homing screen displays the IPv4 settings. 7. In the Available Secondary LAN IPs table, click the Edit button for the secondary IP address that you want to change. The Edit LAN Multi-homing screen displays. 8. Change the IP address, subnet mask, or both: •IP Address. Change the secondary address that you want to assign to the LAN ports. •Subnet Mask. Change the subnet mask for the secondary IP address. 9. Click the Apply button. Your settings are saved. The modified secondary IP address displays in the Available Secondary LAN IPs table on the LAN Multi-homing screen. Remove One or More Secondary LAN IPv4 Addresses The following procedure describes how to remove one or more existing secondary LAN IPv4 address that you no longer need. To remove one or more secondary LAN IP addresses: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button.
Configure the IPv4 LAN Settings 132 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 The Router Status screen displays. 6. Select Network Configuration > LAN Settings > LAN Multi-homing. The LAN Multi-homing screen displays the IPv4 settings. 7. In the Available Secondary LAN IPs table, select the check box to the left of each secondary IP address that you want to remove, or click the Select All button to select all secondary IP addresses. 8. Click the Delete button. The selected addresses are removed from the Available Secondary LAN IPs table. Manage IPv4 LAN Groups and Hosts The following sections provide information about managing IPv4 LAN groups and hosts: •Network Database •DHCP Address Reservation •Manage the Network Database •Change Group Names in the Network Database Network Database The VPN firewall contains a list of all computers and network devices to which it assigned dynamic IP addresses or that it discovered by other means. This list also contains all computers and network devices for which you entered IP addresses manually. Collectively, these entries make up the network database. The network database is updated by these methods: •DHCP client requests. When the DHCP server is enabled, it accepts and responds to DHCP client requests from computers and other network devices. These requests also generate an entry in the network database. This is an advantage of enabling the DHCP server feature. •Scanning the network. The local network is scanned using Address Resolution Protocol (ARP) requests. The ARP scan detects active devices that are not DHCP clients. However, if the VPN firewall receives a reply to an ARP request from a device with an active firewall that blocks the device name, the VPN firewall might not be able to determine the device name. Note:In large networks, scanning the network might generate unwanted traffic. •Manual entry. You can manually enter information about a network device. A network database has the following advantages: •Generally, you do not need to enter an IP address or a MAC address. Instead, you can select the name of the desired computer or device.
Configure the IPv4 LAN Settings 133 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 •You do not need to reserve an IP address for a computer in the DHCP server. All IP address assignments made by the DHCP server are maintained until the computer or device is removed from the network database, either by expiration (inactive for a long time) or by you. •You do not need to use a fixed IP address on a computer. Because the IP addresses that are allocated by the DHCP server never change, you do not need to assign a fixed IP address to a computer to ensure that it always has the same IP address. •A computer is identified by its MAC address—not its IP address. The network database uses the MAC address to identify each computer or device. Therefore, changing a computer’s IP address does not affect any restrictions applied to that computer. •You can assign control over computers to groups and individuals: -You can assign computers to groups (see Manage the Network Database on page 133) and apply restrictions (outbound rules and inbound rules) to each group (see Overview of Rules to Block or Allow Specific Kinds of Traffic on page 210). -You can select groups that are allowed access to URLs that you have blocked for other groups, or the other way around, block access to URLs that you have allowed access to for groups (see Manage Content Filtering on page 306). -You can create firewall rules to apply to a single computer (see Enable Source MAC Filtering on page 312). Because the MAC address is used to identify each computer, users cannot avoid these restrictions by changing their IP address. DHCP Address Reservation When you specify a reserved IP address for a device on the LAN and bind that IP address to the MAC address of the device, that device always receives the same IP address each time it accesses the VPN firewall’s DHCP server. Assign reserved IP addresses to servers and access points that require permanent IP address settings. A reserved IP address must be outside of the DHCP server pool. A reserved address is not assigned until the next time the device contacts the VPN firewall’s DHCP server. You can force the device to contact the VPN firewall’s DHCP server by rebooting the device or by releasing and renewing the DHCP connection of the device. For information about setting up address reservation with a binding, see View or Add Devices Manually to the Network Database on page 134. For information about how to display saved bindings, see View and Set Up an IPv4/MAC Binding on page 316 and View and Set Up IPv6/MAC Bindings on page 320. Manage the Network Database You can view the network database, manually add or remove database entries, and change database entries. The following sections provide information about managing the network database: •View or Add Devices Manually to the Network Database •Change Device Settings Manually in the Network Database
Configure the IPv4 LAN Settings 134 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 •Remove One or More Devices from the Network Database View or Add Devices Manually to the Network Database The following procedure describes how to view or add devices manually to the network database. To view or add devices manually to the network database: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings > LAN Groups. The LAN Groups screen displays. The following figure shows some manually added devices in the Known PCs and Devices table as an example.
Configure the IPv4 LAN Settings 135 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 The Known PCs and Devices table lists the entries in the network database. For each computer or device, the following fields display: •Check box. Allows you to select the computer or device in the table. •Name. The name of the computer or device. For computers that do not support the NetBIOS protocol, the name is displayed as Unknown (you can change the entry manually to add a meaningful name). If the computer or device was assigned an IP address by the DHCP server, the name is appended by an asterisk. •IP Address. The current IP address of the computer or device. For DHCP clients of the VPN firewall, this IP address does not change. If a computer or device is assigned a static IP address, you must update this entry manually after the IP address on the computer or device has changed. •MAC Address. The MAC address of the computer or device’s network interface. •Group. Each computer or device can be assigned to a single LAN group. By default, a computer or device is assigned to Group 1. However, you can select a different LAN group. •Profile Name. Each computer or device can be assigned to a single VLAN. By default, a computer or device is assigned to the default VLAN (VLAN 1). However, you can select a different VLAN. •Action. The Edit button, which provides access to the Edit Groups and Hosts screen. 7. In the Add Known PCs and Devices section, enter the settings as described in the following table. SettingDescription Name Enter the name of the computer or device. IP Address Type From the menu, select how the computer or device receives its IP address: • Fixed (set on PC). The IP address is statically assigned on the computer or device. • Reserved (DHCP Client). The DHCP server of the VPN firewall always assigns the specified IP address to this client during the DHCP negotiation (see also DHCP Address Reservation on page 133). Note:For both types of IP addresses, the VPN firewall reserves the IP address for the associated MAC address. IP Address Enter the IP address that this computer or device is assigned to: • If the IP address type is Fixed (set on PC), the IP address must be outside the address range that is allocated to the DHCP server pool to prevent the IP address from also being allocated by the DHCP server. • If the IP address type is Reserved (DHCP Client), the IP address can be inside or outside the address range that is allocated to the DHCP server pool. Note:Make sure that the IP address is in the IP subnet for the VLAN profile that you select from the Profile Name menu.
Configure the IPv4 LAN Settings 136 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 8. Click the Add button. The computer or device is added to the Known PCs and Devices table. 9. (Optional) Save the binding between the IP address and MAC address for the entry that you just added: a.Select the check box for the table entry. b. Click the Save Binding button. The binding is saved. Change Device Settings Manually in the Network Database The following procedure describes how to change the settings manually for a device in the network database. To change the settings for a device manually in the network database: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings > LAN Groups. MAC Address Enter the MAC address of the computer’s or device’s network interface. The MAC address format is six colon-separated pairs of hexadecimal characters (0–9 and a–f), such as 01:23:d2:6f:89:ab. Group From the menu, select the group to which the computer or device is assigned. (Group 1 is the default group.) Profile Name From the menu, select the name of the VLAN profile to which the computer or device is assigned. SettingDescription
Configure the IPv4 LAN Settings 137 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 The LAN Groups screen displays. The following figure shows some manually added devices in the Known PCs and Devices table as an example. 7. In the Known PCs and Devices table, click the Edit button for the device that you want to change. The Edit LAN Groups screen displays. The following figure shows an example. 8. Change the settings. For information about the settings, see View or Add Devices Manually to the Network Database on page 134. 9. Click the Apply button. Your settings are saved. The modified device displays in the Known PCs and Devices table on the LAN Groups screen.
Configure the IPv4 LAN Settings 138 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Remove One or More Devices from the Network Database The following procedure describes how to remove one or more devices from the network database. To remove one or more devices from the network database: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings > LAN Groups. The LAN Groups screen displays. 7. In the Known PCs and Devices table, select the check box to the left of each device that you want to remove or click the Select All button to select all devices. 8. Click the Delete button. The selected devices are removed from the Known PCs and Devices table. 9. If you remove IP and MAC addresses for which saved bindings exist, you also must remove the saved bindings: a.Select Security > Address Filter > IP/MAC Binding. The IP/MAC Binding screen displays the IPv4 settings. b. In the IP/MAC Bindings table, select the check box to the left of each IP/MAC binding that you want to remove or click the Select All button to select all bindings. c. Click the Delete button. The selected bindings are removed from the IP/MAC Bindings table.
Configure the IPv4 LAN Settings 139 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Change Group Names in the Network Database By default, the groups are named Group1 through Group8. You can change these group names to be more descriptive, for example, GlobalMarketing and GlobalSales. To change the name of one of the eight available groups: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > LAN Settings > LAN Groups. The LAN Groups screen displays. The following figure shows some manually added devices in the Known PCs and Devices table as an example. 7. Click the Edit Group Names option arrow. The following figure shows some examples.