Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual
Have a look at the manual Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 137 Netgear manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.
Customize Firewall Protection 280 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 •Manage Quality of Service Profiles for IPv4 Firewall Rules •Default Quality of Service Priorities for IPv6 Firewall Rules •Manage Bandwidth Profiles for IPv4 Traffic Firewall Objects When you create inbound and outbound firewall rules, you use firewall objects such as services, groups, schedules, QoS profiles, and bandwidth profiles to narrow down the firewall rules: •Services. A service narrows down a firewall rule to an application and a port number. For information about managing customized services, see Manage Customized Services on page 280. •Service Groups. A service groups narrows down a firewall rule to a group of services. For information about managing service groups, see Manage Service Groups on page 284. •IP groups. An IP group is a LAN group or a WAN group to which you add individual IP addresses. You can narrow down a firewall rule to such an IP group. For information about managing IP groups, Manage IP Address Groups on page 288. •Schedules. A schedule narrows down the period during which a firewall rule is applied. For information about managing schedules, see Define a Schedule on page 292. •QoS profiles and priorities. A Quality of Service (QoS) profile defines the relative priority of an IP packet for traffic that matches a firewall rule. For information about creating QoS profiles for IPv4 firewall rules, see Manage Quality of Service Profiles for IPv4 Firewall Rules on page 293. For information about predefined QoS priorities that are available for IPv6 firewall rules, see Default Quality of Service Priorities for IPv6 Firewall Rules on page 298. •Bandwidth profiles. A bandwidth profile allocates and limits traffic bandwidth for the LAN users to which an IPv4 firewall rule is applied. For information about creating bandwidth profiles, see Manage Bandwidth Profiles for IPv4 Traffic on page 299. Manage Customized Services Services are functions performed by server computers at the request of client computers. You can configure up to 124 custom services. The following sections provide information about managing customized services: •Services Overview •Add a Customized Service •Change a Customized Service •Remove One or More Customized Services
Customize Firewall Protection 281 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Services Overview Examples of web servers that provide web services include the following: web servers provide web pages, time servers provide time and date information, and game hosts provide data about players’ moves. When a computer on the Internet sends a request for service to a server computer, the requested service is identified by a service or port number. This number appears as the destination port number in the transmitted IP packets. For example, a packet that is sent with destination port number 80 is an HTTP (web server) request. The service numbers for many common protocols are defined by the Internet Engineering Task Force (IETF) and published in RFC 1700, Assigned Numbers. Service numbers for other applications are typically chosen from the range 1024 to 65535 by the authors of the application. However, on the VPN firewall you can select service numbers in the range from 1 to 65535. Although the VPN firewall already holds a list of many service port numbers, you are not limited to these choices. You can add additional services and applications for use in defining firewall rules. To define a new service, you must first determine which port number or range of numbers is used by the application. You can usually find this information by contacting the publisher of the application, user groups, or newsgroups. When you have the port number information, you can add the new service. Add a Customized Service The following procedure describes how to add a customized service that you then can use as an object for a firewall rule. To add a customized service: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays.
Customize Firewall Protection 282 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 6. Select Security > Services. The Services screen displays. The Custom Services Table shows the user-defined services. The following figure shows some examples. 7. In the Add Customer Service section, enter the settings as described in the following table. 8. Click the Apply button. Your settings are saved. The new custom service is added to the Custom Services table. Change a Customized Service The following procedure describes how to change an existing customized service. To change a service: 1. On your computer, launch an Internet browser. SettingDescription Name A descriptive name of the service for identification and management purposes. Type From the Type menu, select the Layer 3 protocol that the service uses as its transport protocol: TCP, UDP, ICMP, or ICMPv6. ICMP Type A numeric value that can range between 0 and 40. For a list of ICMP types, visit http://www.iana.org/assignments/icmp-parameters. Note:This field is enabled only when you select ICMP or ICMPv6 from the Type menu. Start Port The first TCP or UDP port of a range that the service uses. Note:This field is enabled only when you select TCP or UDP from the Type menu. Finish Port The last TCP or UDP port of a range that the service uses. If the service uses only a single port number, enter the same number in the Start Port and Finish Port fields. Note:This field is enabled only when you select TCP or UDP from the Type menu.
Customize Firewall Protection 283 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Security > Services. The Services screen displays. 7. In the Custom Services table, click the Edit button for the service that you want to change. The Edit Service screen displays. 8. Change the settings. For information about the settings, see Add a Customized Service on page 281. 9. Click the Apply button. Your settings are saved. The modified service displays in the Custom Services table on the Services screen. Remove One or More Customized Services The following procedure describes how to remove one or more customized services that you no longer need as objects for firewall rules.
Customize Firewall Protection 284 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 To remove one or more customized services: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Security > Services. The Services screen displays. 7. In the Custom Services table, select the check box to the left of each service that you want to remove, or click the Select All button to select all services. 8. Click the Delete button. The selected services are removed from the Custom Services table. Manage Service Groups You can combine default and customized services into service groups. The following sections provide information about managing customized services: •Service Groups Overview •Add a Service Group •Change a Service Group •Remove One or More Service Groups Service Groups Overview A service group can contain a collection of predefined and customized services. (TCP and UDP customized services can be included in a service group.) You use a service group as a firewall object to which you apply a firewall rule. One advantage of a service group is that you can create a single firewall object with multiple noncontiguous ports (for example ports 3000, 4000, and 5000) and apply the object in a
Customize Firewall Protection 285 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 single firewall rule. For example, in a configuration with 10 web servers, each of which requires the same three port-forwarding rules, you can create a service group for the port-forwarding rules and an IP group for the web servers (see Manage IP Address Groups on page 288) and then create only one firewall rule. Add a Service Group The following procedure describes how to add a service group that you then can use as an object for a firewall rule. To add a service group: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Security > Services > Service Groups. The Service Groups screen displays. The following figure shows an example. 7. Under the Custom Service Group table, click the Add button. The Add Service Group screen displays.
Customize Firewall Protection 286 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 8.In the Name field, enter a name for the service. 9.Specify the services for the group by use the move buttons (>) to move services between the Available Services field and the List of Selected Services field. Note:You cannot combine TCP and UDP services in the same group. 10. Click the Apply button. Your settings are saved. The new service group displays in the Custom Services Group table on the Service Groups screen. Change a Service Group The following procedure describes how to change an existing service group. To change a service group: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays.
Customize Firewall Protection 287 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 6. Select Network Security > Services > Service Groups. The Service Group screen displays. 7. In the Custom Service Group Table, click the Edit button for the service group that you want to change. The Edit Service Group screen displays. 8. Change the settings. For information about the settings, see Add a Service Group on page 285. 9. Click the Apply button. Your settings are saved. The modified service group displays in the Custom Service Group Table on the Service Group screen. Remove One or More Service Groups The following procedure describes how to remove one or more service groups that you no longer need as objects for firewall rules. To remove one or more service groups: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select Network Security > Services > Service Groups. The Service Groups screen displays. 7. In the Custom Service Group Table, select the check box to the left of each service group that you want to remove or click the Select All button to select all service groups. 8. Click the Delete button. The selected service groups are removed from the Custom Service Group Table.
Customize Firewall Protection 288 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Manage IP Address Groups You can combine individual IP addresses into IP address groups. The following sections provide information about managing IP address groups: •IP Address Groups Overview •Add an IP Address Group •Change an IP Address Group •Remove One or More IP Address Groups IP Address Groups Overview An IP address group, or just IP group, contains a collection of individual IP addresses that do not need to be within the same IP address range. You specify an IP group as either a LAN group or WAN group and use the group as a firewall object to which you apply a firewall rule. An example of how you can use an IP group is as follows: In a configuration with 10 web servers, each of which requires the same three port-forwarding rules, you can create a service group for the port-forwarding rules (see Manage Service Groups on page 284) and an IP group for the web servers, and then create only one firewall rule. Add an IP Address Group The following procedure describes how to add an IP group that you then can use as an object for a firewall rule. To add an IP group: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays.
Customize Firewall Protection 289 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 6. Select Security > Services > IP Groups. The IP Groups screen displays. The following figure shows two groups in the Custom IP Groups Table as examples. 7. In the Add New Custom IP Group section, do the following: •In the IP Group Name field, enter a name for the group. •From the IP Group Type menu, select LAN Group or WAN Group. 8. Click the Apply button. Your settings are saved. The new IP group is displayed in the Custom IP Groups Table. 9. In the Custom IP Groups Table, click the Edit button for the IP group that you just created. The Edit IP Group screen displays. The following figure shows two IP addresses in the IP Addresses Grouped table as examples. 10. In the IP Address field, type an IP address. 11. Click the Add button. The IP address is added to the IP Addresses Grouped table.