FVX538 Reference Manual
Page 11
ProSafe VPN Firewall 200 FVX538 Reference Manual Viewing Port Triggering Status 6-24 Viewing Router Configuration and System Status 6-25 Monitoring WAN Ports Status 6-26 Monitoring VPN Tunnel Connection Status 6-27 VPN Logs ...6-28 DHCP Log ...6-29 Performing Diagnostics 6-29 Chapter 7 Troubleshooting Basic... Troubleshooting a TCP/IP Network Using a Ping Utility 7-5 Testing the LAN Path to Your Firewall 7-5 Testing the Path from Your PC to a Remote Device 7-6 Restoring the Default Configuration and Password 7-7 Problems with Date and Time 7-7 Appendix A Default Settings and Technical ...
ProSafe VPN Firewall 200 FVX538 Reference Manual Viewing Port Triggering Status 6-24 Viewing Router Configuration and System Status 6-25 Monitoring WAN Ports Status 6-26 Monitoring VPN Tunnel Connection Status 6-27 VPN Logs ...6-28 DHCP Log ...6-29 Performing Diagnostics 6-29 Chapter 7 Troubleshooting Basic... Troubleshooting a TCP/IP Network Using a Ping Utility 7-5 Testing the LAN Path to Your Firewall 7-5 Testing the Path from Your PC to a Remote Device 7-6 Restoring the Default Configuration and Password 7-7 Problems with Date and Time 7-7 Appendix A Default Settings and Technical ...
FVX538 Reference Manual
Page 25
... screen displays, enter admin for the User Name and the password for Password. ProSafe VPN Firewall 200 FVX538 Reference Manual The Router's IP Address, Login Name, and Password Check the label on the bottom of the FVX538's enclosure if you forget the following factory default information: • IP Address: http://192.168.1.1 to reach the Web-based GUI from the...
... screen displays, enter admin for the User Name and the password for Password. ProSafe VPN Firewall 200 FVX538 Reference Manual The Router's IP Address, Login Name, and Password Check the label on the bottom of the FVX538's enclosure if you forget the following factory default information: • IP Address: http://192.168.1.1 to reach the Web-based GUI from the...
FVX538 Reference Manual
Page 30
... traffic meter for WAN2 ISP. Next click Auto Detect on page 4-10). The default is also referred to the Internet through your WAN1 ISP Settings: 1. To manually ...Note: At this point of the configuration process, you are now connected to as IP Addresses, account information, type of the dual WAN interface. This is set to ... a unique 48-bit local Ethernet address. Setting the Router's MAC Address Each computer or router on page 2-6. The configure the WAN2 ISP settings: 1. ProSafe VPN Firewall 200 FVX538 Reference Manual 4. See "Programming the Traffic Meter (if...
... traffic meter for WAN2 ISP. Next click Auto Detect on page 4-10). The default is also referred to the Internet through your WAN1 ISP Settings: 1. To manually ...Note: At this point of the configuration process, you are now connected to as IP Addresses, account information, type of the dual WAN interface. This is set to ... a unique 48-bit local Ethernet address. Setting the Router's MAC Address Each computer or router on page 2-6. The configure the WAN2 ISP settings: 1. ProSafe VPN Firewall 200 FVX538 Reference Manual 4. See "Programming the Traffic Meter (if...
FVX538 Reference Manual
Page 35
... are functional. The rule should match the desired traffic. From the Internet, there is the default setting. • Classical Routing. If you only have a single Internet IP address, you MUST use a redundant ISP link for backup purposes, ensure that the backup WAN port has already been configured. ... and System Status" on page 6-25) or look at the LEDs on the front panel (see "Router Front and Rear Panels" on your LAN to each PC on page 1-6). ProSafe VPN Firewall 200 FVX538 Reference Manual If you want to use NAT. To gain Internet access, each PC, you can choose Classical ...
... are functional. The rule should match the desired traffic. From the Internet, there is the default setting. • Classical Routing. If you only have a single Internet IP address, you MUST use a redundant ISP link for backup purposes, ensure that the backup WAN port has already been configured. ... and System Status" on page 6-25) or look at the LEDs on the front panel (see "Router Front and Rear Panels" on your LAN to each PC on page 1-6). ProSafe VPN Firewall 200 FVX538 Reference Manual If you want to use NAT. To gain Internet access, each PC, you can choose Classical ...
FVX538 Reference Manual
Page 36
... the WAN ISP pages (see "Configuring the Internet Connections to Your ISPs" on page 2-2). • DNS lookup using this IP address - ProSafe VPN Firewall 200 FVX538 Reference Manual When the router is configured in Auto-Rollover Mode, the router uses the WAN Failure Detection Method to check the connection of the following ways: • By using DNS queries... to this DNS Server (for Auto-Rollover 1. To configure the dual WAN ports for example, a public DNS Server) - Link failure is considered down menu. 4. The default test period is sent periodically after every test period.
... the WAN ISP pages (see "Configuring the Internet Connections to Your ISPs" on page 2-2). • DNS lookup using this IP address - ProSafe VPN Firewall 200 FVX538 Reference Manual When the router is configured in Auto-Rollover Mode, the router uses the WAN Failure Detection Method to check the connection of the following ways: • By using DNS queries... to this DNS Server (for Auto-Rollover 1. To configure the dual WAN ports for example, a public DNS Server) - Link failure is considered down menu. 4. The default test period is sent periodically after every test period.
FVX538 Reference Manual
Page 43
... for most Ethernet networks is rarely required, and should not be aliased to the same IP address as yourhost.dyndns.org 5. Connecting the FVX538 to access the WAN1 Advanced Options screen. ProSafe VPN Firewall 200 FVX538 Reference Manual For example, the wildcard feature will display. Configuring the Advanced WAN Options (...to return to save your ISP connection. If you haven't already, log in to the firewall at the default LAN address of http://192.168.1.1, default user name of admin, and default password of password (or whatever password and LAN address you want to reduce the MTU. ...
... for most Ethernet networks is rarely required, and should not be aliased to the same IP address as yourhost.dyndns.org 5. Connecting the FVX538 to access the WAN1 Advanced Options screen. ProSafe VPN Firewall 200 FVX538 Reference Manual For example, the wildcard feature will display. Configuring the Advanced WAN Options (...to return to save your ISP connection. If you haven't already, log in to the firewall at the default LAN address of http://192.168.1.1, default user name of admin, and default password of password (or whatever password and LAN address you want to reduce the MTU. ...
FVX538 Reference Manual
Page 45
...and 192.168.1.100, although you have defined. • Subnet Mask. • Gateway IP Address (the firewall's LAN IP address). For most applications, the default DHCP and TCP/IP settings of the firewall are available for both the LAN and DMZ settings. LAN Configuration 3-1 v1.0, March 2009... 3 LAN Configuration This chapter describes how to configure the advanced LAN features of your ProSafe VPN Firewall 200, including the following parameters to any LAN device that requests DHCP: • An IP Address from a pool of addresses specified in Appendix D, "Related Documents" for an ...
...and 192.168.1.100, although you have defined. • Subnet Mask. • Gateway IP Address (the firewall's LAN IP address). For most applications, the default DHCP and TCP/IP settings of the firewall are available for both the LAN and DMZ settings. LAN Configuration 3-1 v1.0, March 2009... 3 LAN Configuration This chapter describes how to configure the advanced LAN features of your ProSafe VPN Firewall 200, including the following parameters to any LAN device that requests DHCP: • An IP Address from a pool of addresses specified in Appendix D, "Related Documents" for an ...
FVX538 Reference Manual
Page 46
... diversity and failover. When disabled, all DNS requests and communicate with the IP where the DNS Proxy is particularly useful in the LAN. ProSafe VPN Firewall 200 FVX538 Reference Manual • Primary DNS Server (the firewall's LAN IP address). • WINS Server (if you entered a WINS server address...the active connection. The default values are different, then a link failure may render the DNS servers inaccessible. DHCP Relay options allow you to make requests to the router and the router, in turn, sends those requests to obtain IP addresses from the DHCP ...
... diversity and failover. When disabled, all DNS requests and communicate with the IP where the DNS Proxy is particularly useful in the LAN. ProSafe VPN Firewall 200 FVX538 Reference Manual • Primary DNS Server (the firewall's LAN IP address). • WINS Server (if you entered a WINS server address...the active connection. The default values are different, then a link failure may render the DNS servers inaccessible. DHCP Relay options allow you to make requests to the router and the router, in turn, sends those requests to obtain IP addresses from the DHCP ...
FVX538 Reference Manual
Page 47
...different subnets.) 3. Check the Enable DHCP Server radio button. LAN Configuration 3-3 v1.0, March 2009 Enter the IP Subnet Mask. Unless you will display. If Enabled is optional). The LAN Setup screen will manually configure all computers connected to... the router's LAN. Enter the Domain Name of the router (this is selected, enter the following parameters: a. Select Network Configuration from the primary menu and LAN Setup from the submenu. Enable DHCP Server is the default. ProSafe VPN Firewall 200 FVX538 Reference Manual 1.
...different subnets.) 3. Check the Enable DHCP Server radio button. LAN Configuration 3-3 v1.0, March 2009 Enter the IP Subnet Mask. Unless you will display. If Enabled is optional). The LAN Setup screen will manually configure all computers connected to... the router's LAN. Enter the Domain Name of the router (this is selected, enter the following parameters: a. Select Network Configuration from the primary menu and LAN Setup from the submenu. Enable DHCP Server is the default. ProSafe VPN Firewall 200 FVX538 Reference Manual 1.
FVX538 Reference Manual
Page 48
... IP address and log in LAN TCP/IP Setup section). For example, if you change the LAN IP address of the router (the IP Address in again. c. Enter the Ending IP Address. d. i. Note: If you change the default IP ...IP address. The IP address 192.168.1.2 is the default ending address. The IP address 192.168.1.100 is the default start address. Secondary DNS Server. (Optional) If an IP address is specified, the VPN firewall will provide this address and the Ending IP Address. ProSafe VPN Firewall 200 FVX538 Reference Manual b. If no address is specified, the VPN firewall...
... IP address and log in LAN TCP/IP Setup section). For example, if you change the LAN IP address of the router (the IP Address in again. c. Enter the Ending IP Address. d. i. Note: If you change the default IP ...IP address. The IP address 192.168.1.2 is the default ending address. The IP address 192.168.1.100 is the default start address. Secondary DNS Server. (Optional) If an IP address is specified, the VPN firewall will provide this address and the Ending IP Address. ProSafe VPN Firewall 200 FVX538 Reference Manual b. If no address is specified, the VPN firewall...
FVX538 Reference Manual
Page 50
...Secondary LAN IP: 192.168.20.1 with the IP addresses, gateway IP and DNS server IPs. Click Add. The Secondary LAN IP address will accept and respond to DHCP client requests from the Available Secondary LAN IPs table. ProSafe VPN Firewall 200 FVX538 Reference ...IP addresses cannot be manually configured with subnet 255.255.255.0 Managing Groups and Hosts (LAN Groups) The Known PCs and Devices table on the LAN screen) enabled is scanned using standard methods such as Unknown. 3-6 LAN Configuration v1.0, March 2009 The Network Database is created in this router. By default...
...Secondary LAN IP: 192.168.20.1 with the IP addresses, gateway IP and DNS server IPs. Click Add. The Secondary LAN IP address will accept and respond to DHCP client requests from the Available Secondary LAN IPs table. ProSafe VPN Firewall 200 FVX538 Reference ...IP addresses cannot be manually configured with subnet 255.255.255.0 Managing Groups and Hosts (LAN Groups) The Known PCs and Devices table on the LAN screen) enabled is scanned using standard methods such as Unknown. 3-6 LAN Configuration v1.0, March 2009 The Network Database is created in this router. By default...
FVX538 Reference Manual
Page 52
...IP address by default, to respond to DHCP requests from the router will not change. The Known PCs and Devices table lists the entries in the Network Database. If a computer is assigned a static IP address, you must to update this , leaving the DHCP Server feature enabled (on the LAN. ProSafe VPN Firewall 200 FVX538... Reference Manual Figure 3-3 The Network Database is created by: • Using the DHCP Server: The router's DHCP server is ...
...IP address by default, to respond to DHCP requests from the router will not change. The Known PCs and Devices table lists the entries in the Network Database. If a computer is assigned a static IP address, you must to update this , leaving the DHCP Server feature enabled (on the LAN. ProSafe VPN Firewall 200 FVX538... Reference Manual Figure 3-3 The Network Database is created by: • Using the DHCP Server: The router's DHCP server is ...
FVX538 Reference Manual
Page 53
...on the computer. • IP Address: The IP address that computer or device will reserve the IP address for example, 00:80:48:2a:8b:c0) • Group: The group to which the computer has to the first group (Group 1). ProSafe VPN Firewall 200 FVX538 Reference Manual • MAC Address...: The MAC address of the computer's network interface. • Group: Each PC or device can be outside of the DHCP Server pool. By default, a computer is Reserved (DHCP Client), the router will always receive the same IP address each...
...on the computer. • IP Address: The IP address that computer or device will reserve the IP address for example, 00:80:48:2a:8b:c0) • Group: The group to which the computer has to the first group (Group 1). ProSafe VPN Firewall 200 FVX538 Reference Manual • MAC Address...: The MAC address of the computer's network interface. • Group: Each PC or device can be outside of the DHCP Server pool. By default, a computer is Reserved (DHCP Client), the router will always receive the same IP address each...
FVX538 Reference Manual
Page 54
...to the LAN, has fewer firewall restrictions, by default. ProSafe VPN Firewall 200 FVX538 Reference Manual To reserve an IP address, use the Groups and Hosts screen under the Network Configuration menu, LAN Groups submenu (see "Router Front and Rear Panels" on page 1-6) and configure an IP address and Mask for safely providing... the PC or access its IP configuration and force a DHCP release and renew. radio box. 3. To enable and configure the DMZ port: 1. The eighth LAN port on the router can be assigned until the next time the PC contacts the firewall's DHCP server. In some ...
...to the LAN, has fewer firewall restrictions, by default. ProSafe VPN Firewall 200 FVX538 Reference Manual To reserve an IP address, use the Groups and Hosts screen under the Network Configuration menu, LAN Groups submenu (see "Router Front and Rear Panels" on page 1-6) and configure an IP address and Mask for safely providing... the PC or access its IP configuration and force a DHCP release and renew. radio box. 3. To enable and configure the DMZ port: 1. The eighth LAN port on the router can be assigned until the next time the PC contacts the firewall's DHCP server. In some ...
FVX538 Reference Manual
Page 56
... should configure static routes only for unusual cases such as multiple firewalls or multiple IP subnets located on page 1-6) will manually configure all devices, leave the Disable option (default) checked. The Add Static Route menu, shown below, will ...display. 2. Click Apply to your DMZ network will be the DHCP server, or if you do not need to configure additional static routes. To define the DMZ WAN Rules and LAN DMZ Rules, see "Router Front and Rear Panels" on your settings. ProSafe VPN Firewall 200 FVX538...
... should configure static routes only for unusual cases such as multiple firewalls or multiple IP subnets located on page 1-6) will manually configure all devices, leave the Disable option (default) checked. The Add Static Route menu, shown below, will ...display. 2. Click Apply to your DMZ network will be the DHCP server, or if you do not need to configure additional static routes. To define the DMZ WAN Rules and LAN DMZ Rules, see "Router Front and Rear Panels" on your settings. ProSafe VPN Firewall 200 FVX538...
FVX538 Reference Manual
Page 122
... consecutive packets. • Local. IP address (either a single address, range of the remote network. To Enable or Disable a Policy, check the radio box adjacent to the circle and click Enable or Disable, as described previously (Auto is specified by an "*" next to the policy name). ProSafe VPN Firewall 200 FVX538 Reference Manual VPN Policy Table Only one...
... consecutive packets. • Local. IP address (either a single address, range of the remote network. To Enable or Disable a Policy, check the radio box adjacent to the circle and click Enable or Disable, as described previously (Auto is specified by an "*" next to the policy name). ProSafe VPN Firewall 200 FVX538 Reference Manual VPN Policy Table Only one...
FVX538 Reference Manual
Page 232
... to 2-16 Dead Peer Detection 5-17 default configuration restoring 7-7 default IP Address 1-9 default password 1-9, 2-1 default user name 1-9, 2-1 denial of service attack 4-16, 4-17 Denial of 2-6 server IP address 3-4 DNS addresses 2-6 DNS lookup 2-10 DNS Proxy 1-4 DNS queries Auto-Rollover 2-10 Domain Name router 3-3 Domain Name Blocking 4-29 v1.0, March 2009 See DoS. ProSafe VPN Firewall 200 FVX538 Reference Manual Content Filtering 4-1 about...
... to 2-16 Dead Peer Detection 5-17 default configuration restoring 7-7 default IP Address 1-9 default password 1-9, 2-1 default user name 1-9, 2-1 denial of service attack 4-16, 4-17 Denial of 2-6 server IP address 3-4 DNS addresses 2-6 DNS lookup 2-10 DNS Proxy 1-4 DNS queries Auto-Rollover 2-10 Domain Name router 3-3 Domain Name Blocking 4-29 v1.0, March 2009 See DoS. ProSafe VPN Firewall 200 FVX538 Reference Manual Content Filtering 4-1 about...
FVX538 Reference Manual
Page 51
... Server radio button. Enter the Ending IP Address. Note: If you change the default IP address 192.168.1.1 to the router's LAN. Enter a WINS Server IP address. This address specifies the first of the router (this address and the Ending IP Address. Any new DHCP client joining the...LAN will manually configure all computers connected to 10.0.0.1, you will be disconnected. e. The IP address 192.168.1.100 is enabled. Check the Enable DNS Proxy radio box. d. ProSafe VPN Firewall 200 FVX538 Reference Manual 4. If another device on your network will be the DHCP server, or...
... Server radio button. Enter the Ending IP Address. Note: If you change the default IP address 192.168.1.1 to the router's LAN. Enter a WINS Server IP address. This address specifies the first of the router (this address and the Ending IP Address. Any new DHCP client joining the...LAN will manually configure all computers connected to 10.0.0.1, you will be disconnected. e. The IP address 192.168.1.100 is enabled. Check the Enable DNS Proxy radio box. d. ProSafe VPN Firewall 200 FVX538 Reference Manual 4. If another device on your network will be the DHCP server, or...
FVX538 Reference Manual
Page 115
... configuration). • Local. The Active IPSec (SA)s table also lists current data for the VPN header (VPN Wizard default is shown on the remote VPN Endpoint. The IP address on the IPSec Connection Status screen (accessed by this SA. • Endpoint. ProSafe VPN Firewall 200 FVX538 Reference Manual 3. This specifies the authentication protocol for each active IPSec SA (Security Association...
... configuration). • Local. The Active IPSec (SA)s table also lists current data for the VPN header (VPN Wizard default is shown on the remote VPN Endpoint. The IP address on the IPSec Connection Status screen (accessed by this SA. • Endpoint. ProSafe VPN Firewall 200 FVX538 Reference Manual 3. This specifies the authentication protocol for each active IPSec SA (Security Association...
FVX538 Reference Manual
Page 214
... providers links to 2-17 default configuration restoring 7-7 default IP Address 1-9 default password 1-9, 2-2 default user name 1-9, 2-2 denial of service attack 4-14, 4-15 Denial of 2-7 DNS addresses 2-7 DNS lookup 2-11 DNS Proxy 1-4 DNS queries Auto-Rollover 2-11 Domain Name router 3-3 Domain Name Blocking 4-25 Domain Name Servers. See DoS. DoS v1.0, August 2006 ProSafe VPN Firewall 200 FVX538 Reference Manual Content Filtering 4-1 about...
... providers links to 2-17 default configuration restoring 7-7 default IP Address 1-9 default password 1-9, 2-2 default user name 1-9, 2-2 denial of service attack 4-14, 4-15 Denial of 2-7 DNS addresses 2-7 DNS lookup 2-11 DNS Proxy 1-4 DNS queries Auto-Rollover 2-11 Domain Name router 3-3 Domain Name Blocking 4-25 Domain Name Servers. See DoS. DoS v1.0, August 2006 ProSafe VPN Firewall 200 FVX538 Reference Manual Content Filtering 4-1 about...