Home > Netgear > Router > Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual

Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual

    Download as PDF Print this page Share this page

    Have a look at the manual Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 137 Netgear manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.

    Page
    of 691
    							Configure the IPv6 LAN Settings 
    200 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 
    9. Click the Apply button.
    Your settings are saved.
    Add an IPv6 DMZ Address Pool
    If you use a stateful DHCPv6 server for the DMZ, you must add local DHCP IPv6 address 
    pools so that the DHCPv6 server can control the allocation of IPv6 addresses in the DMZ.
    To add an IPv6 DMZ address pool:
    1. On your computer, launch an Internet browser.
    2. In the address field of your browser, enter the IP address that was assigned to the VPN 
    firewall during the installation process.
    The VPN firewall factory default IP address is 192.168.1.1.
    The NETGEAR Configuration Manager Login screen displays.
    3. In the Username field, type your user name and in the Password / Passcode field, type 
    your password.
    For the default administrative account, the default user name is admin and the default 
    password is password.
    Domain Name Enter the domain name of the DHCP server.
    Server Preference Enter the DHCP server preference value. The possible values are 0–255, with 
    255 as the default setting.
    This is an optional setting that specifies the server’s preference value in a 
    server advertise message. The client selects the server with the highest 
    preference value as the preferred server.
    DNS Server From the DNS Server menu, select a DNS server option:
    • Use DNS Proxy. The VPN firewall acts as a proxy for all DNS requests 
    and communicates with the ISP DNS servers that you configure. For 
    information about specifying the ISP DNS servers, see 
    Manually Configure 
    a Static IPv6 Internet Connection on page 94.
    • Use DNS from ISP. The VPN firewall uses the ISP DNS servers that you 
    configure. For information about specifying the ISP DNS servers, see 
    Manually Configure a Static IPv6 Internet Connection on page 94.
    • Use below. When you select this option, the Primary DNS Server and 
    Secondary DNS Server fields become available for you to enter IP 
    addresses:
    -  Primary DNS Server. Enter the IP address of the primary DNS server 
    for the DMZ.
    -  Secondary DNS Server. Enter the IP address of the secondary DNS 
    server for the DMZ.
    Lease/Rebind Time Enter the period after which the DHCP lease is renewed with the original DHCP 
    server or rebound with another DHCP server to extend the existing DHCP 
    lease. The default period is 86400  seconds (24 hours).
    SettingDescription 
    						
    							Configure the IPv6 LAN Settings 
    201  ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2
    4. If you changed the default domain or were assigned a domain, from the Domain menu, 
    select the domain.
    If you did not change the domain or were not assigned a domain, leave the menu 
    selection at geardomain.
    5. Click the Login button.
    The Router Status screen displays.
    6. Select Network Configuration > DMZ Setup.
    The DMZ Setup screen displays the IPv4 settings.
    7. In the upper right, select the IPv6 radio button. 
    The DMZ Setup screen displays the IPv6 settings. The following figure shows an 
    example.
    8. Under the List of IPv6 Address Pools table, click the Add button.
    The DMZ IPv6 Config screen displays. 
    						
    							Configure the IPv6 LAN Settings 
    202 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 
    9. Enter the settings as described in the following table.
    10. Click the Apply button.
    Your settings are saved. The new IPv6 address pool is added to the List of IPv6 Address 
    Pools table on the DMZ Setup (IPv6) screen.
    Change an IPv6 DMZ Address Pool
    The following procedure describes how to change an existing IPv6 DMZ address pool.
    To change an IPv6 DMZ address pool:
    1. On your computer, launch an Internet browser.
    2. In the address field of your browser, enter the IP address that was assigned to the VPN 
    firewall during the installation process.
    The VPN firewall factory default IP address is 192.168.1.1.
    The NETGEAR Configuration Manager Login screen displays.
    3. In the Username field, type your user name and in the Password / Passcode field, type 
    your password.
    For the default administrative account, the default user name is admin and the default 
    password is password.
    4. If you changed the default domain or were assigned a domain, from the Domain menu, 
    select the domain.
    If you did not change the domain or were not assigned a domain, leave the menu 
    selection at geardomain.
    SettingDescription
    Start IPv6 Address Enter the start IP address. This address specifies the first of the contiguous 
    addresses in the IP address pool. Any new DHCPv6 client joining the DMZ is 
    assigned an IP address between this address and the end IP address.
    End IPv6 Address Enter the end IP address. This address specifies the last of the contiguous 
    addresses in the IP address pool. Any new DHCPv6 client joining the DMZ is 
    assigned an IP address between the start IP address and this IP address.
    Prefix Length Enter the IPv6 prefix length, for example, 10 or 64. 
    						
    							Configure the IPv6 LAN Settings 
    203  ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2
    5. Click the Login button.
    The Router Status screen displays.
    6. Select Network Configuration > DMZ Setup.
    The DMZ Setup screen displays the IPv4 settings.
    7. In the upper right, select the IPv6 radio button. 
    The DMZ Setup screen displays the IPv6 settings. 
    8. In List of IPv6 Address Pools table, click the Edit button for the address pool that you want 
    to change.
    The DMZ IPv6 Config screen displays.
    9. Change the settings.
    For information about the settings, see Add an IPv6 DMZ Address Pool on page 200.
    10. Click the Apply button.
    Your settings are saved. The modified address pool displays in the List of IPv6 Address 
    Pools table on the DMZ Setup screen.
    Remove One or More IPv6 DMZ Address Pools
    The following procedure describes how to remove one or more existing IPv6 DMZ address 
    pools that you no longer need.
    To remove one or more IPv6 DMZ address pools:
    1. On your computer, launch an Internet browser.
    2. In the address field of your browser, enter the IP address that was assigned to the VPN 
    firewall during the installation process.
    The VPN firewall factory default IP address is 192.168.1.1.
    The NETGEAR Configuration Manager Login screen displays.
    3. In the Username field, type your user name and in the Password / Passcode field, type 
    your password.
    For the default administrative account, the default user name is admin and the default 
    password is password.
    4. If you changed the default domain or were assigned a domain, from the Domain menu, 
    select the domain.
    If you did not change the domain or were not assigned a domain, leave the menu 
    selection at geardomain.
    5. Click the Login button.
    The Router Status screen displays.
    6. Select Network Configuration > DMZ Setup.
    The DMZ Setup screen displays the IPv4 settings. 
    						
    							Configure the IPv6 LAN Settings 
    204 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 
    7. In the upper right, select the IPv6 radio button. 
    The DMZ Setup screen displays the IPv6 settings. 
    8. In List of IPv6 Address Pools table, select the check box to the left of each address pool 
    that you want to remove or click the Select All button to select all address pools.
    9. Click the Delete button.
    The selected IPv6 address pools are removed from the List of IPv6 Address Pools table.
    Manage Static IPv6 Routing
    The following sections provide information about managing static IPv6 routing:
    •Add a Static IPv6 Route
    •Change a Static IPv6 Route
    •Remove One or More Static IPv6 Routes
    Note:NETGEAR’s implementation of IPv6 does not support RIP next 
    generation (RIPng) to exchange routing information, and dynamic 
    changes to IPv6 routes are not possible. To enable routers to 
    exchange information over a static IPv6 route, you must manually 
    configure the static route information on each router.
    Add a Static IPv6 Route
    The following procedure describes how to add an IPv6 static route to the VPN firewall.
    To add a static IPv6 route to the VPN firewall:
    1. On your computer, launch an Internet browser.
    2. In the address field of your browser, enter the IP address that was assigned to the VPN 
    firewall during the installation process.
    The VPN firewall factory default IP address is 192.168.1.1.
    The NETGEAR Configuration Manager Login screen displays.
    3. In the Username field, type your user name and in the Password / Passcode field, type 
    your password.
    For the default administrative account, the default user name is admin and the default 
    password is password.
    4. If you changed the default domain or were assigned a domain, from the Domain menu, 
    select the domain.
    If you did not change the domain or were not assigned a domain, leave the menu 
    selection at geardomain. 
    						
    							Configure the IPv6 LAN Settings 
    205  ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2
    5. Click the Login button.
    The Router Status screen displays.
    6. Select Network Configuration > Routing.
    The Static Routing screen displays the IPv4 settings.
    7. In the upper right, select the IPv6 radio button. 
    The Static Routing screen displays the IPv6 settings. The following figure contains an 
    example.
    8. Click the Add button under the Static Routes table.
    The IPv6 Static Routing screen displays.
    9. Enter the settings as described in the following table.
    SettingDescription
    Route Name The route name for the static route (for purposes of identification and 
    management).
    Active To make the static route effective, select the Active check box.
    Note:You can add a route to the table and make the route inactive if do not need 
    it. This allows you to use routes as needed without deleting and re-adding the 
    entries.
    IPv6 Destination The destination IPv6 address of the host or network to which the route leads.
    IPv6 Prefix Length The destination IPv6 prefix length of the host or network to which the route leads. 
    						
    							Configure the IPv6 LAN Settings 
    206 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 
    10. Click the Apply button.
    Your settings are saved. The new static route is added to the List of IPv6 Static Routes 
    table on the Static Routing screen for IPv6.
    Change a Static IPv6 Route
    The following procedure describes how to change an existing IPv6 static route.
    To change an IPv6 static route:
    1. On your computer, launch an Internet browser.
    2. In the address field of your browser, enter the IP address that was assigned to the VPN 
    firewall during the installation process.
    The VPN firewall factory default IP address is 192.168.1.1.
    The NETGEAR Configuration Manager Login screen displays.
    3. In the Username field, type your user name and in the Password / Passcode field, type 
    your password.
    For the default administrative account, the default user name is admin and the default 
    password is password.
    4. If you changed the default domain or were assigned a domain, from the Domain menu, 
    select the domain.
    If you did not change the domain or were not assigned a domain, leave the menu 
    selection at geardomain.
    5. Click the Login button.
    The Router Status screen displays.
    6. Select Network Configuration > Routing.
    The Static Routing screen displays the IPv4 settings.
    7. In the upper right, select the IPv6 radio button. 
    The Static Routing screen displays the IPv6 settings.
    8. In the List of IPv6 Static Routes table, click the Edit button for the route that you want to 
    change.
    Interface From the menu, select the physical or virtual network interface (the WAN1 or 
    WAN2 interface, a sit0 Tunnel, LAN interface, or DMZ interface) through which the 
    route is accessible.
    IPv6 Gateway The gateway IPv6 address through which the destination host or network can be 
    reached.
    Metric The priority of the route. Select a value between 2 and 15. If multiple routes to the 
    same destination exist, the route with the lowest metric is used.
    SettingDescription 
    						
    							Configure the IPv6 LAN Settings 
    207  ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2
    The Edit IPv6 Static Routing screen displays.
    9. Change the settings.
    For information about the settings, see Add a Static IPv6 Route on page 204.
    10. Click the Apply button.
    Your settings are saved. The modified route displays in the List of IPv6 Static Routes table 
    on the Static Routes screen.
    Remove One or More Static IPv6 Routes
    The following procedure describes how to remove one or more existing IPv6 static routes 
    that you no longer need.
    To remove one or more static IPv6 routes:
    1. On your computer, launch an Internet browser.
    2. In the address field of your browser, enter the IP address that was assigned to the VPN 
    firewall during the installation process.
    The VPN firewall factory default IP address is 192.168.1.1.
    The NETGEAR Configuration Manager Login screen displays.
    3. In the Username field, type your user name and in the Password / Passcode field, type 
    your password.
    For the default administrative account, the default user name is admin and the default 
    password is password.
    4. If you changed the default domain or were assigned a domain, from the Domain menu, 
    select the domain.
    If you did not change the domain or were not assigned a domain, leave the menu 
    selection at geardomain.
    5. Click the Login button.
    The Router Status screen displays.
    6. Select Network Configuration > Routing.
    The Static Routing screen displays the IPv4 settings.
    7. In the upper right, select the IPv6 radio button. 
    The Static Routing screen displays the IPv6 settings.
    8. In the List of IPv6 Static Routes table, select the check box to the left of each route that 
    you want to remove or click the Select All button to select all routes.
    9. Click the Delete button.
    The selected routes are removed from the List of IPv6 Static Routes table. 
    						
    							208
    6
    6.   Customize Firewall Protection
    This chapter describes how to use the firewall features of the VPN firewall to protect your 
    network. The chapter contains the following sections:
    •Firewall Protection
    •Overview of Rules to Block or Allow Specific Kinds of Traffic
    •Change the Default Outbound Policy for LAN WAN Traffic
    •Add LAN WAN Rules
    •Add DMZ WAN Rules
    •Add LAN DMZ Rules
    •Manage Existing Firewall Rules
    •Examples of Firewall Rules
    •Configure Other Firewall Features
    •Manage Firewall Objects 
    						
    							Customize Firewall Protection 
    209  ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2
    Firewall Protection 
    A firewall protects one network (the trusted network, such as your LAN) from another (the 
    untrusted network, such as the Internet) while allowing communication between the two. You 
    can further segment keyword blocking to certain known groups such as LAN groups and IP 
    groups.
    For IPv4, a firewall incorporates the functions of a Network Address Translation (NAT) router, 
    protects the trusted network from hacker intrusions or attacks, and controls the types of traffic 
    that can flow between the Internet, DMZ, and LAN. Unlike simple NAT routers, a firewall uses 
    a process called stateful packet inspection to protect your network from attacks and 
    intrusions. NAT performs a limited stateful inspection in that it considers whether the 
    incoming packet is in response to an outgoing request, but true stateful packet inspection 
    goes far beyond NAT.
    For IPv6, which in itself provides stronger security than IPv4, a firewall in particular controls 
    the exchange of traffic between the Internet, DMZ, and LAN.
    Although firewall rules (also refereed to as service rules) are the basic way of managing the 
    traffic through your system (see 
    Overview of Rules to Block or Allow Specific Kinds of Traffic 
    on page 210), you can further refine your control by using the following features and 
    capabilities of the VPN firewall:
    •Groups and hosts (see Manage IPv4 LAN Groups and Hosts on page 132) 
    •Firewall objects (see Manage Firewall Objects on page 279)
    •Allowing or blocking sites (see Manage Content Filtering on page 306)
    •Source MAC filtering (see Enable Source MAC Filtering on page 312)
    •Port triggering (see Manage Port Triggering on page 325)
    Some firewall settings might affect the performance of the VPN firewall. For more 
    information, see 
    Performance Management on page 527.
    You can configure the VPN firewall to log and email denial of access, general attack, and 
    other information to a specified email address. For information about how to configure 
    logging and notifications, see 
    Manage Logging, Alerts, and Event Notifications on page 567.
    WARNING:
    Make sure that you first configure the IPv4 WAN routing mode (see 
    Manage the IPv4 WAN Routing Mode on page 30) before you 
    configure custom firewall rules. If you change the IPv4 WAN routing 
    mode, all LAN WAN and DMZ WAN inbound rules revert to default 
    settings. 
    						
    All Netgear manuals Comments (0)

    Related Manuals for Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual