WatchGuard Firebox System 7.0 User Guide
WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide
Chapter 3: Getting StartedWhen you add a secondary network, you map an IPaddress from the secondary network to the IP address ofthe Firebox interface. This is known as creating (or adding)an IP alias to the network interface. This IP alias becomesthe default gateway for all the machines on the secondarynetwork. The presence of a secondary network also tellsthe Firebox that another network resides on the Fireboxinterface wire.You add secondary networks in the following two ways:• The QuickSetup Wizard, which is part of theinstallation process, asks you to select the checkbox ifyou have “an additional private network behind theFirebox” when you are entering the IP addresses forthe Firebox interfaces. The additional private networkyou specify becomes the secondary network on thetrusted interface. For more information on theQuickSetup Wizard, see “Running the QuickSetupWizard” on page 40.34 WatchGuard Firebox System
Selecting a Firewall Configuration Mode• After you have finished with the installation, you canadd secondary networks to any interface using PolicyManager, as described in “Adding SecondaryNetworks” on page 64.Dynamic IP support on the external interfaceIf you are supporting dynamic IP addressing, you mustchoose routed configuration.If you choose the Dynamic Host Configuration Protocol(DHCP) option, the Firebox will request its IP address,gateway, and netmask from a DHCP server managed byyour Internet Service Provider (ISP). This server can alsoprovide WINS and DNS server information for your Firebox.If it does not, you must add it manually to your configuration,as described in “Entering WINS and DNSServer Addresses” on page 65. You can also change theWINS and DNS values provided by your ISP, if necessary.Point-to-Point Protocol over Ethernet (PPPoE) is also supported.As with DHCP, the Firebox initiates a PPPoE protocolconnection to your ISP’s PPPoE server, whichautomatically configures your IP address, gateway, andnetmask. However, PPPoE does not propagate DNS andWINS server information as DHCP does.If you are using PPPoE on the external interface, you willneed the PPP user name and password when you set upyour network. Both username and password each have a256-byte capacity.When the Firebox is configured such that it obtains its IPaddresses dynamically, the following functionality (whichrequires a static IP address) is not supported unless you arecertain that the dynamic IP settings sent by your ISP willnot change:• High Availability (not supported on Firebox 500)• Drop-in mode• 1-to-1 NATUser Guide 35
- Page 7 and 8: somewhere reasonably visible in you
- Page 9 and 10: (B) Use any backup or archival copy
- Page 11 and 12: 8.Miscellaneous Provisions. This AG
- Page 13 and 14: ContentsCHAPTER 1 Introduction ....
- Page 15 and 16: Testing the connection ............
- Page 17 and 18: Controlling the HostWatch display .
- Page 19 and 20: Detecting Man-in-the-Middle Attacks
- Page 21 and 22: Deleting a report .................
- Page 23 and 24: CHAPTER 1IntroductionWelcome to Wat
- Page 25 and 26: Minimum RequirementsHistorical Repo
- Page 27 and 28: .WatchGuard OptionsHardwarefeatureC
- Page 29 and 30: About this Guideallowed to enter yo
- Page 31 and 32: CHAPTER 2Service and SupportNo Inte
- Page 33 and 34: LiveSecurity® Broadcastsdivided in
- Page 35 and 36: LiveSecurity® Self Help Tools3 Com
- Page 37 and 38: WatchGuard Users GroupGuard Technic
- Page 39 and 40: Online Helpto display a list of top
- Page 41 and 42: Assisted Supportto assist you in ma
- Page 43 and 44: Training and Certificationto speed
- Page 45 and 46: CHAPTER 3Getting StartedThe WatchGu
- Page 47 and 48: Gathering Network InformationNetwor
- Page 49 and 50: .Gathering Network InformationThe f
- Page 51 and 52: Selecting a Firewall Configuration
- Page 53 and 54: Selecting a Firewall Configuration
- Page 55: Selecting a Firewall Configuration
- Page 59 and 60: Setting Up the Management Station4
- Page 61 and 62: Cabling the FireboxUser Guide 39
- Page 63 and 64: Running the QuickSetup WizardProvid
- Page 65 and 66: Entering IP addressesRunning the Qu
- Page 67 and 68: What’s Nextservices, in addition
- Page 69 and 70: CHAPTER 4Firebox BasicsThis chapter
- Page 71 and 72: Opening a Configuration FileTrusted
- Page 73 and 74: Saving a Configuration File3 From t
- Page 75 and 76: Resetting Firebox Passphrasesenter
- Page 77 and 78: Setting the Time Zone2 Select the m
- Page 79 and 80: CHAPTER 5Using PolicyManager toConf
- Page 81 and 82: Setting IP Addresses of Firebox Int
- Page 83 and 84: Setting DHCP or PPPoE Support on th
- Page 85 and 86: Defining External IP Aliases2 Confi
- Page 87 and 88: Entering WINS and DNS Server Addres
- Page 89 and 90: Defining a Firebox as a DHCP Server
- Page 91 and 92: Adding Basic Services to Policy Man
- Page 93 and 94: Configuring Routes3 Click the Net o
- Page 95 and 96: CHAPTER 6Managing andMonitoring the
- Page 97 and 98: Viewing Basic Firebox StatusThe top
- Page 99 and 100: Viewing Basic Firebox Statusbut the
- Page 101 and 102: Viewing Basic Firebox Status• The
- Page 103 and 104: Monitoring Firebox TrafficSetting t
- Page 105 and 106: Performing Basic Tasks with System
Selecting a Firewall Configuration Mode• After you have finished with the installation, you canadd secondary networks to any interface using PolicyManager, as described in “Adding SecondaryNetworks” on page 64.Dynamic IP support on the external interfaceIf you are supporting dynamic IP addressing, you mustchoose routed configuration.If you choose the Dynamic Host Configuration Protocol(DHCP) option, the <strong>Firebox</strong> will request its IP address,gateway, and netmask from a DHCP server managed byyour Internet Service Provider (ISP). This server can alsoprovide WINS and DNS server information for your <strong>Firebox</strong>.If it does not, you must add it manually to your configuration,as described in “Entering WINS and DNSServer Addresses” on page 65. You can also change theWINS and DNS values provided by your ISP, if necessary.Point-to-Point Protocol over Ethernet (PPPoE) is also supported.As with DHCP, the <strong>Firebox</strong> initiates a PPPoE protocolconnection to your ISP’s PPPoE server, whichautomatically configures your IP address, gateway, andnetmask. However, PPPoE does not propagate DNS andWINS server information as DHCP does.If you are using PPPoE on the external interface, you willneed the PPP user name and password when you set upyour network. Both username and password each have a256-byte capacity.When the <strong>Firebox</strong> is configured such that it obtains its IPaddresses dynamically, the following functionality (whichrequires a static IP address) is not supported unless you arecertain that the dynamic IP settings sent by your ISP willnot change:• High Availability (not supported on <strong>Firebox</strong> 500)• Drop-in mode• 1-to-1 NAT<strong>User</strong> <strong>Guide</strong> 35