Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual
Have a look at the manual Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 137 Netgear manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.
Configure the IPv6 LAN Settings 200 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 9. Click the Apply button. Your settings are saved. Add an IPv6 DMZ Address Pool If you use a stateful DHCPv6 server for the DMZ, you must add local DHCP IPv6 address pools so that the DHCPv6 server can control the allocation of IPv6 addresses in the DMZ. To add an IPv6 DMZ address pool: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. Domain Name Enter the domain name of the DHCP server. Server Preference Enter the DHCP server preference value. The possible values are 0–255, with 255 as the default setting. This is an optional setting that specifies the server’s preference value in a server advertise message. The client selects the server with the highest preference value as the preferred server. DNS Server From the DNS Server menu, select a DNS server option: • Use DNS Proxy. The VPN firewall acts as a proxy for all DNS requests and communicates with the ISP DNS servers that you configure. For information about specifying the ISP DNS servers, see Manually Configure a Static IPv6 Internet Connection on page 94. • Use DNS from ISP. The VPN firewall uses the ISP DNS servers that you configure. For information about specifying the ISP DNS servers, see Manually Configure a Static IPv6 Internet Connection on page 94. • Use below. When you select this option, the Primary DNS Server and Secondary DNS Server fields become available for you to enter IP addresses: - Primary DNS Server. Enter the IP address of the primary DNS server for the DMZ. - Secondary DNS Server. Enter the IP address of the secondary DNS server for the DMZ. Lease/Rebind Time Enter the period after which the DHCP lease is renewed with the original DHCP server or rebound with another DHCP server to extend the existing DHCP lease. The default period is 86400 seconds (24 hours). SettingDescription
Configure the IPv6 LAN Settings 201 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > DMZ Setup. The DMZ Setup screen displays the IPv4 settings. 7. In the upper right, select the IPv6 radio button. The DMZ Setup screen displays the IPv6 settings. The following figure shows an example. 8. Under the List of IPv6 Address Pools table, click the Add button. The DMZ IPv6 Config screen displays.
Configure the IPv6 LAN Settings 202 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 9. Enter the settings as described in the following table. 10. Click the Apply button. Your settings are saved. The new IPv6 address pool is added to the List of IPv6 Address Pools table on the DMZ Setup (IPv6) screen. Change an IPv6 DMZ Address Pool The following procedure describes how to change an existing IPv6 DMZ address pool. To change an IPv6 DMZ address pool: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. SettingDescription Start IPv6 Address Enter the start IP address. This address specifies the first of the contiguous addresses in the IP address pool. Any new DHCPv6 client joining the DMZ is assigned an IP address between this address and the end IP address. End IPv6 Address Enter the end IP address. This address specifies the last of the contiguous addresses in the IP address pool. Any new DHCPv6 client joining the DMZ is assigned an IP address between the start IP address and this IP address. Prefix Length Enter the IPv6 prefix length, for example, 10 or 64.
Configure the IPv6 LAN Settings 203 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > DMZ Setup. The DMZ Setup screen displays the IPv4 settings. 7. In the upper right, select the IPv6 radio button. The DMZ Setup screen displays the IPv6 settings. 8. In List of IPv6 Address Pools table, click the Edit button for the address pool that you want to change. The DMZ IPv6 Config screen displays. 9. Change the settings. For information about the settings, see Add an IPv6 DMZ Address Pool on page 200. 10. Click the Apply button. Your settings are saved. The modified address pool displays in the List of IPv6 Address Pools table on the DMZ Setup screen. Remove One or More IPv6 DMZ Address Pools The following procedure describes how to remove one or more existing IPv6 DMZ address pools that you no longer need. To remove one or more IPv6 DMZ address pools: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > DMZ Setup. The DMZ Setup screen displays the IPv4 settings.
Configure the IPv6 LAN Settings 204 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 7. In the upper right, select the IPv6 radio button. The DMZ Setup screen displays the IPv6 settings. 8. In List of IPv6 Address Pools table, select the check box to the left of each address pool that you want to remove or click the Select All button to select all address pools. 9. Click the Delete button. The selected IPv6 address pools are removed from the List of IPv6 Address Pools table. Manage Static IPv6 Routing The following sections provide information about managing static IPv6 routing: •Add a Static IPv6 Route •Change a Static IPv6 Route •Remove One or More Static IPv6 Routes Note:NETGEAR’s implementation of IPv6 does not support RIP next generation (RIPng) to exchange routing information, and dynamic changes to IPv6 routes are not possible. To enable routers to exchange information over a static IPv6 route, you must manually configure the static route information on each router. Add a Static IPv6 Route The following procedure describes how to add an IPv6 static route to the VPN firewall. To add a static IPv6 route to the VPN firewall: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain.
Configure the IPv6 LAN Settings 205 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > Routing. The Static Routing screen displays the IPv4 settings. 7. In the upper right, select the IPv6 radio button. The Static Routing screen displays the IPv6 settings. The following figure contains an example. 8. Click the Add button under the Static Routes table. The IPv6 Static Routing screen displays. 9. Enter the settings as described in the following table. SettingDescription Route Name The route name for the static route (for purposes of identification and management). Active To make the static route effective, select the Active check box. Note:You can add a route to the table and make the route inactive if do not need it. This allows you to use routes as needed without deleting and re-adding the entries. IPv6 Destination The destination IPv6 address of the host or network to which the route leads. IPv6 Prefix Length The destination IPv6 prefix length of the host or network to which the route leads.
Configure the IPv6 LAN Settings 206 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 10. Click the Apply button. Your settings are saved. The new static route is added to the List of IPv6 Static Routes table on the Static Routing screen for IPv6. Change a Static IPv6 Route The following procedure describes how to change an existing IPv6 static route. To change an IPv6 static route: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > Routing. The Static Routing screen displays the IPv4 settings. 7. In the upper right, select the IPv6 radio button. The Static Routing screen displays the IPv6 settings. 8. In the List of IPv6 Static Routes table, click the Edit button for the route that you want to change. Interface From the menu, select the physical or virtual network interface (the WAN1 or WAN2 interface, a sit0 Tunnel, LAN interface, or DMZ interface) through which the route is accessible. IPv6 Gateway The gateway IPv6 address through which the destination host or network can be reached. Metric The priority of the route. Select a value between 2 and 15. If multiple routes to the same destination exist, the route with the lowest metric is used. SettingDescription
Configure the IPv6 LAN Settings 207 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 The Edit IPv6 Static Routing screen displays. 9. Change the settings. For information about the settings, see Add a Static IPv6 Route on page 204. 10. Click the Apply button. Your settings are saved. The modified route displays in the List of IPv6 Static Routes table on the Static Routes screen. Remove One or More Static IPv6 Routes The following procedure describes how to remove one or more existing IPv6 static routes that you no longer need. To remove one or more static IPv6 routes: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Configuration > Routing. The Static Routing screen displays the IPv4 settings. 7. In the upper right, select the IPv6 radio button. The Static Routing screen displays the IPv6 settings. 8. In the List of IPv6 Static Routes table, select the check box to the left of each route that you want to remove or click the Select All button to select all routes. 9. Click the Delete button. The selected routes are removed from the List of IPv6 Static Routes table.
208 6 6. Customize Firewall Protection This chapter describes how to use the firewall features of the VPN firewall to protect your network. The chapter contains the following sections: •Firewall Protection •Overview of Rules to Block or Allow Specific Kinds of Traffic •Change the Default Outbound Policy for LAN WAN Traffic •Add LAN WAN Rules •Add DMZ WAN Rules •Add LAN DMZ Rules •Manage Existing Firewall Rules •Examples of Firewall Rules •Configure Other Firewall Features •Manage Firewall Objects
Customize Firewall Protection 209 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Firewall Protection A firewall protects one network (the trusted network, such as your LAN) from another (the untrusted network, such as the Internet) while allowing communication between the two. You can further segment keyword blocking to certain known groups such as LAN groups and IP groups. For IPv4, a firewall incorporates the functions of a Network Address Translation (NAT) router, protects the trusted network from hacker intrusions or attacks, and controls the types of traffic that can flow between the Internet, DMZ, and LAN. Unlike simple NAT routers, a firewall uses a process called stateful packet inspection to protect your network from attacks and intrusions. NAT performs a limited stateful inspection in that it considers whether the incoming packet is in response to an outgoing request, but true stateful packet inspection goes far beyond NAT. For IPv6, which in itself provides stronger security than IPv4, a firewall in particular controls the exchange of traffic between the Internet, DMZ, and LAN. Although firewall rules (also refereed to as service rules) are the basic way of managing the traffic through your system (see Overview of Rules to Block or Allow Specific Kinds of Traffic on page 210), you can further refine your control by using the following features and capabilities of the VPN firewall: •Groups and hosts (see Manage IPv4 LAN Groups and Hosts on page 132) •Firewall objects (see Manage Firewall Objects on page 279) •Allowing or blocking sites (see Manage Content Filtering on page 306) •Source MAC filtering (see Enable Source MAC Filtering on page 312) •Port triggering (see Manage Port Triggering on page 325) Some firewall settings might affect the performance of the VPN firewall. For more information, see Performance Management on page 527. You can configure the VPN firewall to log and email denial of access, general attack, and other information to a specified email address. For information about how to configure logging and notifications, see Manage Logging, Alerts, and Event Notifications on page 567. WARNING: Make sure that you first configure the IPv4 WAN routing mode (see Manage the IPv4 WAN Routing Mode on page 30) before you configure custom firewall rules. If you change the IPv4 WAN routing mode, all LAN WAN and DMZ WAN inbound rules revert to default settings.