Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual
Have a look at the manual Netgear Netgar VPN FIrewall FVS336Gv2 Reference Manual online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 137 Netgear manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.
Set Up Virtual Private Networking with SSL Connections 449 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Create a Portal Layout The portal layout specifies the login screen that you present to an SSL VPN user and determines the type of access that you grant. To create a portal layout: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select VPN > SSL VPN > Portal Layouts. The Portal Layouts screen displays the IPv4 settings. The following figure shows the default IPv4 SSL portal (SSL-VPN) and a custom portal. Note:If you have enabled IPv6 (see Manage the IPv6 Routing Mode on page 88), when you create a portal with an IPv4 address, the same portal is automatically created with an IPv6 address. The List of Layouts table displays the following fields: •Layout Name. The descriptive name of the portal.
Set Up Virtual Private Networking with SSL Connections 450 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 •Description. The banner message that is displayed at the top of the portal. •Use Count. The number of authentication domains that use the portal. •Portal URL (IPv4). The IPv4 URL at which the portal can be accessed. The IPv4 address in the URL is the public WAN address of the VPN firewall (see Configure the IPv4 Internet Connection and WAN Settings on page 30). If you have enabled IPv6, you can see the IPv6 URL by selecting the IPv6 radio button. •Action. The buttons, which allow you to change the portal layout or set it as the default. 7. Under the List of Layouts table, click the Add button. The Add Portal Layout screen displays. The following figure shows an example. 8. Enter the settings as described in the following table. SettingDescription Portal Layout and Theme Name Portal Layout Name A descriptive name for the portal layout. This name is part of the path of the SSL VPN portal URL. Use only alphanumeric characters, hyphens (-), and underscores (_) in the Portal Layout Name field. If you enter other types of characters or spaces, the layout name is truncated before the first nonalphanumeric character, hyphen, or underscore. Unlike most other names in URLs, this name is case-sensitive. Note:To create a portal layout, you must enter a name other than SSL-VPN (the default portal name) in the Portal Layout Name field. Portal Site Title The title that displays at the top of the user’s web browser window, for example, Company Customer Support.
Set Up Virtual Private Networking with SSL Connections 451 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 9. Click the Apply button. Your settings are saved. The new portal layout is added to the List of Layouts table. For information about how to display the new portal layout, see Access a Custom SSL VPN Portal on page 440. Banner Title The banner title of a banner message that users see before they log in to the portal, for example, Welcome to Customer Support. Note:For an example, see Access a Custom SSL VPN Portal on page 440. The banner title is displayed in the orange header bar of the login screen that is shown in the procedure. Banner Message The text of a banner message that users see before they log in to the portal, for example, In case of log-in difficulty, call 123-456-7890. Enter a plain text message, or include HTML and JavaScript tags. The maximum length of the login screen message is 4096 characters. Note:You can enlarge the field (that is, the text box) by manipulating the lower right corner of the field (see the blue circle in the previous figure). Note:For an example, see Access a Custom SSL VPN Portal on page 440. The banner message text is displayed in the gray header bar of the login screen that is shown in the procedure. Display banner message on login pageSelect this check box to show the banner title and banner message text on the login screen. HTTP meta tags for cache control (recommended)Select this check box to apply HTTP meta tag cache control directives to this portal layout. Cache control directives include the following: Note:NETGEAR strongly recommends enabling HTTP meta tags for security reasons and to prevent out-of-date web pages, themes, and data being stored in a user’s web browser cache. ActiveX web cache cleanerSelect this check box to enable ActiveX cache control to be loaded when users log in to the SSL VPN portal. The web cache cleaner prompts the user to remove all temporary Internet files, cookies, and browser history when the user logs out or closes the web browser window. The ActiveX web cache control is ignored by web browsers that do not support ActiveX. SSL VPN Portal Pages to Display Note:Although you can select both, you typically select either the VPN Tunnel page check box or the Port Forwarding check box. VPN Tunnel page To provide full network connectivity, select this check box. Port Forwarding To provide access to specific defined network services, select this check box. For information about specifying network services, see Configure Applications for SSL VPN Port Forwarding on page 453. SettingDescription
Set Up Virtual Private Networking with SSL Connections 452 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Change a Portal Layout The following procedure describes how to change an existing portal layout. If you enabled IPv6 (see Manage the IPv6 Routing Mode on page 88), changes that you make to an IPv4 portal layout are automatically applied to the corresponding IPv6 portal layout, or the other way around. For this reason, the following procedure describes how to change an IPv4 portal layout only. To change a portal layout: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select VPN > SSL VPN > Portal Layouts. The Portal Layouts screen displays the IPv4 settings. 7. In the List of Layouts table, click the Edit button for the portal layout that you want to change. The Edit Portal Layout screen displays. 8. Change the settings. For more information about the settings, see Create a Portal Layout on page 449. 9. Click the Apply button. Your settings are saved to the IPV4 portal layout and the corresponding IPv6 portal layout. The modified portal layout displays in the List of Layouts table on the Portal Layouts screen. Remove One or More Portal Layouts The following procedure describes how to remove existing portal layouts. You cannot remove the default portal layout (SSL-VPN). If you enabled IPv6 (see Manage the IPv6 Routing Mode
Set Up Virtual Private Networking with SSL Connections 453 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 on page 88), if you remove an IPv4 portal layout, the corresponding IPv6 portal layout is removed automatically, and the other way around. If you remove an IPv6 portal layout, the corresponding IPv4 portal is removed automatically. For this reason, the following procedure describes the removal of IPv4 portal layouts only. To remove one or more portal layouts: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select VPN > SSL VPN > Portal Layouts. The Portal Layouts screen displays the IPv4 settings. 7. In the List of Layouts table, select the check box to the left of each portal layout that you want to remove or click the Select All button to select all layouts. 8. Click the Delete button. The selected IPv4 portal layouts and the corresponding IPv6 portal layouts are removed from the List of Layouts table. Configure Applications for SSL VPN Port Forwarding The following sections provide information about managing SSL port forwarding: •SSL VPN Port Forwarding Overview •Add a Server and Port Number for SSL Port Forwarding •Add a Host Name for SSL Port Forwarding •Remove a Server and Port Number Configuration for SSL Port Forwarding •Remove a Host Name for SSL Port Forwarding
Set Up Virtual Private Networking with SSL Connections 454 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 SSL VPN Port Forwarding Overview Note:SSL port forwarding does not apply if you configure full VPN tunnel capability for an SSL portal. SSL VPN port forwarding is supported for IPv4 connections only. Port forwarding provides access to specific defined network services. To define these services, you must specify the internal server addresses and port numbers for TCP applications that are intercepted by the port forwarding client on the user’s computer. This client reroutes the traffic to the VPN firewall. After you have configured port forwarding by defining the IP addresses of internal servers or host computers and the port number for TCP applications or services that are available to remote users, you can also specify host name-to-IP address resolution for the network servers as a convenience for users. Host name resolution allows users to access TCP applications at familiar addresses such as mail.example.com or ftp.customer.com, that is, fully qualified domain names (FQDNs), rather than by IP addresses. Any applications and services that you do not select for SSL port forwarding are not visible from the SSL VPN portal. However, if users know the IP address of an application or service, they can still access it unless you create SSL VPN access policies to prevent access to the application or service. The following table lists some commonly used TCP applications and port numbers that you could use for port forwarding. Table 8. Port forwarding applications and TCP port numbers TCP ApplicationPort Number FTP data (usually not needed) 20 FTP Control Protocol 21 SSH 22 a a. Users can specify the port number together with the host name or IP address. Telnet 23a SMTP (send mail) 25 HTTP (web) 80 POP3 (receive mail) 110 NTP (Network Time Protocol) 123 Citrix 1494 Terminal Services 3389 VNC (virtual network computing) 5900 or 5800
Set Up Virtual Private Networking with SSL Connections 455 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 Add a Server and Port Number for SSL Port Forwarding To configure port forwarding, you must define the IP addresses of the internal servers and the port number for TCP applications and services that are available to remote users. To add a server and port number for an SSL port forwarding application or service: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select VPN > SSL VPN > Port Forwarding. The Port Forwarding screen displays. The following figure shows examples.
Set Up Virtual Private Networking with SSL Connections 456 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 7. In the Add New Application for Port Forwarding section, complete the following fields: •IP Address. The IP address of an internal server or host computer on which a service or application runs to which you want to grant a remote user access. •TCP Port. The TCP port number of the service or application that is accessed through the SSL VPN tunnel. 8. In the Add New Application for Port Forwarding section, click the Add button. The application or service entry is added to the List of Configured Applications for Port Forwarding table. After logging in to the SSL VPN portal and launching port forwarding, remote users can securely access the network application or service. Add a Host Name for SSL Port Forwarding If a server or host computer that you want to name does not display in the List of Configured Applications for Port Forwarding table, you first must add it before you can name it (see Add a Server and Port Number for SSL Port Forwarding on page 455). To add a host name for client name resolution: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select VPN > SSL VPN > Port Forwarding. The Port Forwarding screen displays. The following figure shows examples.
Set Up Virtual Private Networking with SSL Connections 457 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 7. In the Add New Host Name for Port Forwarding section, specify information in the following fields: •Local Server IP Address. The IP address of the internal server or host computer that you want to name. You can name only IP addresses that are listed in the List of Configured Applications for Port Forwarding table. •Fully Qualified Domain Name. The full name of the internal server or host computer. 8. In the Add New Host Name for Port Forwarding section, click the Add button. The IP address and FQDN are added to the List of Configured Host Names for Port Forwarding table. Remove a Server and Port Number Configuration for SSL Port Forwarding The following procedure describes how to remove a server and port number configuration that you no longer need for an SSL port forwarding application or service. To remove a server and port number configuration: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password.
Set Up Virtual Private Networking with SSL Connections 458 ProSAFE Dual WAN Gigabit WAN SSL VPN Firewall FVS336Gv2 For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select VPN > SSL VPN > Port Forwarding. The Port Forwarding screen displays. 7. In the List of Configured Applications for Port Forwarding table, to the right of the application or service that you want to remove, click the corresponding Delete button. The IP address and port number are removed from the List of Configured Applications for Port Forwarding table. Remove a Host Name for SSL Port Forwarding The following procedure describes how to remove a host name that you no longer need. To remove a host name for SSL port forwarding: 1. On your computer, launch an Internet browser. 2. In the address field of your browser, enter the IP address that was assigned to the VPN firewall during the installation process. The VPN firewall factory default IP address is 192.168.1.1. The NETGEAR Configuration Manager Login screen displays. 3. In the Username field, type your user name and in the Password / Passcode field, type your password. For the default administrative account, the default user name is admin and the default password is password. 4. If you changed the default domain or were assigned a domain, from the Domain menu, select the domain. If you did not change the domain or were not assigned a domain, leave the menu selection at geardomain. 5. Click the Login button. The Router Status screen displays. 6. Select VPN > SSL VPN > Port Forwarding. The Port Forwarding screen displays.