WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide WatchGuard Firebox System 4.6 User Guide

watchguard.com
from watchguard.com More from this publisher
13.07.2015 Views

What is a Firebox?Placing a Firebox within a networkThe most common location for a Firebox is directly behind the Internet router, aspictured below:InternetThe Security ChallengeRouterEvent ProcessorFirebox IIManagementStationTrusted NetworkOptional NetworkSMTP ServerHTTP ServerFTP ServerOther parts of the network are as follows:Management StationThe computer on which you install and run the WatchGuard LiveSecurity ControlCenter.Event ProcessorThe computer that receives and stores log messages and sends alerts andnotifications. You can configure the Management Station to also serve as the EventProcessor.Trusted networkThe network behind the firewall that must be protected from the securitychallenge.External networkThe network presenting the security challenge, typically the Internet.Optional networkA network protected by the firewall but still accessible from the trusted and theexternal networks. Typically, the optional network is used for public servers suchas an FTP or Web server.22

Opening a configuration fileOpening a configuration filePolicy Manager is a comprehensive software tool for creating, modifying, and savingconfiguration files. A configuration file, with the extension .cfg, contains all thesettings, options, addresses, and information that together constitute your Fireboxsecurity policy. You can open and edit a configuration file residing on either yourlocal hard disk or in the primary area of the Firebox flash disk. From Policy Manager:1 Select Start => Programs => WatchGuard => Control Center.2 If you are prompted to run the Quick Setup wizard, click Continue.3 If you are prompted to connect to the Firebox, click Cancel.4 From within the WatchGuard Control Center (or WatchGuard VPNManager if you purchased this option), click the Policy Manager icon(shown at right).Opening a configuration from the FireboxFrom Policy Manager in the Advanced view:1 Click File => Open => Firebox.2 Use the Firebox drop list to select a Firebox.You can also type the IP address or DNS name of the Firebox.3 In the Passphrase text box, type the Firebox monitoring passphrase. Click OK.You can use either the monitoring (read-only) or configuration (read-write) passphrase. However,to save the configuration to the Firebox you must use the configuration passphrase. Theconfiguration file stored on the primary area of the Firebox flash disk opens, and configuredservices appear in the Services Arena.Opening a configuration from a local hard diskFrom Policy Manager in the Advanced View:1 Select File => Open => Configuration File.To bring up the Advanced view of Policy Manager, select View => Advanced. A checkmark willappear next to the menu option.2 Locate and select the configuration file to open. Click Open.The configuration file opens and configured services appear in the Services Arena.Saving a configuration fileAfter making changes to a configuration file, you must save it to a local hard disk.When you save a new configuration directly to a Firebox, Policy Manager promptsyou to restart that Firebox so that it will use the new configuration. The new policy isnot active until the Firebox finishes rebooting. Some tasks, such as adding newFirebox users and changing certain IPSec settings, do not require a restart in order totake effect.VPN Manager Guide 23

Opening a configuration fileOpening a configuration filePolicy Manager is a comprehensive software tool for creating, modifying, and savingconfiguration files. A configuration file, with the extension .cfg, contains all thesettings, options, addresses, and information that together constitute your <strong>Firebox</strong>security policy. You can open and edit a configuration file residing on either yourlocal hard disk or in the primary area of the <strong>Firebox</strong> flash disk. From Policy Manager:1 Select Start => Programs => <strong>WatchGuard</strong> => Control Center.2 If you are prompted to run the Quick Setup wizard, click Continue.3 If you are prompted to connect to the <strong>Firebox</strong>, click Cancel.4 From within the <strong>WatchGuard</strong> Control Center (or <strong>WatchGuard</strong> VPNManager if you purchased this option), click the Policy Manager icon(shown at right).Opening a configuration from the <strong>Firebox</strong>From Policy Manager in the Advanced view:1 Click File => Open => <strong>Firebox</strong>.2 Use the <strong>Firebox</strong> drop list to select a <strong>Firebox</strong>.You can also type the IP address or DNS name of the <strong>Firebox</strong>.3 In the Passphrase text box, type the <strong>Firebox</strong> monitoring passphrase. Click OK.You can use either the monitoring (read-only) or configuration (read-write) passphrase. However,to save the configuration to the <strong>Firebox</strong> you must use the configuration passphrase. Theconfiguration file stored on the primary area of the <strong>Firebox</strong> flash disk opens, and configuredservices appear in the Services Arena.Opening a configuration from a local hard diskFrom Policy Manager in the Advanced View:1 Select File => Open => Configuration File.To bring up the Advanced view of Policy Manager, select View => Advanced. A checkmark willappear next to the menu option.2 Locate and select the configuration file to open. Click Open.The configuration file opens and configured services appear in the Services Arena.Saving a configuration fileAfter making changes to a configuration file, you must save it to a local hard disk.When you save a new configuration directly to a <strong>Firebox</strong>, Policy Manager promptsyou to restart that <strong>Firebox</strong> so that it will use the new configuration. The new policy isnot active until the <strong>Firebox</strong> finishes rebooting. Some tasks, such as adding new<strong>Firebox</strong> users and changing certain IPSec settings, do not require a restart in order totake effect.VPN Manager <strong>Guide</strong> 23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!