FVS336G Reference Manual
Page 33
... This one-to-one address as explained in the following sections. ProSafe Dual WAN Gigabit Firewall with multiple public IP addresses, you can use a redundant ISP link for Internet access by your PCs, and you configure the WAN Failure Detection Method to support Auto-Rollover. • Load Balancing ...) to receive any private IP address range, and these IP addresses are functional. Connecting the FVS336G to the original primary link once the original primary link is only a single device (the VPN firewall) and a single IP address. The selected WAN interface is made primary and...
... This one-to-one address as explained in the following sections. ProSafe Dual WAN Gigabit Firewall with multiple public IP addresses, you can use a redundant ISP link for Internet access by your PCs, and you configure the WAN Failure Detection Method to support Auto-Rollover. • Load Balancing ...) to receive any private IP address range, and these IP addresses are functional. Connecting the FVS336G to the original primary link once the original primary link is only a single device (the VPN firewall) and a single IP address. The selected WAN interface is made primary and...
FVS336G Reference Manual
Page 36
...manually force traffic back on page 4-29). To configure the dual WAN ports for secure connections. ProSafe Dual WAN Gigabit Firewall with protocol binding: 1. The default time to roll over after the primary WAN interface fails is bound to a particular WAN port, all outbound HTTPS traffic from the computers on the...of traffic between links that protocol will automatically route all outgoing traffic of that are not of source IP address for load balancing with SSL & IPsec VPN FVS336G Reference Manual 6. The Failover default is brought up after count. For example, if the HTTPS ...
...manually force traffic back on page 4-29). To configure the dual WAN ports for secure connections. ProSafe Dual WAN Gigabit Firewall with protocol binding: 1. The default time to roll over after the primary WAN interface fails is bound to a particular WAN port, all outbound HTTPS traffic from the computers on the...of traffic between links that protocol will automatically route all outgoing traffic of that are not of source IP address for load balancing with SSL & IPsec VPN FVS336G Reference Manual 6. The Failover default is brought up after count. For example, if the HTTPS ...
FVS336G Reference Manual
Page 52
... been configured for unusual cases such as a gateway by computers on your VPN firewall. The Routing screen displays. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Tip: The secondary LAN IP address will be assigned to the LAN interface of the VPN firewall and can be used as multiple firewalls or multiple IP subnets located on the secondary subnet.
... been configured for unusual cases such as a gateway by computers on your VPN firewall. The Routing screen displays. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Tip: The secondary LAN IP address will be assigned to the LAN interface of the VPN firewall and can be used as multiple firewalls or multiple IP subnets located on the secondary subnet.
FVS336G Reference Manual
Page 53
...Active to the LAN only. Enter the Destination IP Address to the host or network to the ...multiple routes to save your settings. Click Add. Figure 3-6 3. The new static route will not be added to which the destination host or network can be reached (must be between 1 and 15). 11. ProSafe Dual WAN Gigabit Firewall... with the lowest metric is chosen (value must be a firewall on the same LAN segment as the firewall). 10. If the destination is displayed. Click Apply to the same destination exit, the route with SSL & IPsec VPN FVS336G...
...Active to the LAN only. Enter the Destination IP Address to the host or network to the ...multiple routes to save your settings. Click Add. Figure 3-6 3. The new static route will not be added to which the destination host or network can be reached (must be between 1 and 15). 11. ProSafe Dual WAN Gigabit Firewall... with the lowest metric is chosen (value must be a firewall on the same LAN segment as the firewall). 10. If the destination is displayed. Click Apply to the same destination exit, the route with SSL & IPsec VPN FVS336G...
FVS336G Reference Manual
Page 60
... the firewall. If multiple connections correspond to Groups. Outbound Rules (continued) Item Description Action (Select Schedule) LAN Users WAN Users QoS Priority Log Bandwidth Profile NAT IP NAT single IP is ...WAN interface only. 4-4 Firewall Protection and Content Filtering v1.0, March 2009 Select the desired option: • Any - Specifies which Internet locations are covered by this rule, whether it as Action. • Use schedule page to configure the time schedules (see "Setting a Schedule to the policy. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G...
... the firewall. If multiple connections correspond to Groups. Outbound Rules (continued) Item Description Action (Select Schedule) LAN Users WAN Users QoS Priority Log Bandwidth Profile NAT IP NAT single IP is ...WAN interface only. 4-4 Firewall Protection and Content Filtering v1.0, March 2009 Select the desired option: • Any - Specifies which Internet locations are covered by this rule, whether it as Action. • Use schedule page to configure the time schedules (see "Setting a Schedule to the policy. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G...
FVS336G Reference Manual
Page 69
...multiple public IP addresses on one WAN interface. WAN1 primary public IP address: 10.1.0.1 - WAN1 additional public IP address: 10.1.0.5 - LAN WAN Inbound Rule: Specifying an Exposed Host Specifying an exposed host allows you to set up a computer or server that you have configured multi-NAT to associate this address with SSL & IPsec VPN FVS336G... services that is used in Figure 4-6, we have not yet defined. LAN IP address 192.168.1.1 • Web server PC on the VPN firewall's LAN - ProSafe Dual WAN Gigabit Firewall with the Web server on the LAN (at 192.168.1.2).
...multiple public IP addresses on one WAN interface. WAN1 primary public IP address: 10.1.0.1 - WAN1 additional public IP address: 10.1.0.5 - LAN WAN Inbound Rule: Specifying an Exposed Host Specifying an exposed host allows you to set up a computer or server that you have configured multi-NAT to associate this address with SSL & IPsec VPN FVS336G... services that is used in Figure 4-6, we have not yet defined. LAN IP address 192.168.1.1 • Web server PC on the VPN firewall's LAN - ProSafe Dual WAN Gigabit Firewall with the Web server on the LAN (at 192.168.1.2).
FVS336G Reference Manual
Page 130
...is in Figure 6-5. 2. Make a new entry with SSL & IPsec VPN FVS336G Reference Manual VPN tunnel clients are now able to connect to reconnect and receive ... corporate network or if the corporate network has multiple subnets, you must also add a static route on your corporate firewall that the following networks are currently connected. Click...appropriate Subnet Mask. 4. ProSafe Dual WAN Gigabit Firewall with the correct specifications. 2. In the Configured Client Routes table, click the Delete button adjacent to the VPN firewall. If the assigned client IP address range is listed...
...is in Figure 6-5. 2. Make a new entry with SSL & IPsec VPN FVS336G Reference Manual VPN tunnel clients are now able to connect to reconnect and receive ... corporate network or if the corporate network has multiple subnets, you must also add a static route on your corporate firewall that the following networks are currently connected. Click...appropriate Subnet Mask. 4. ProSafe Dual WAN Gigabit Firewall with the correct specifications. 2. In the Configured Client Routes table, click the Delete button adjacent to the VPN firewall. If the assigned client IP address range is listed...
FVS336G Reference Manual
Page 131
But for multiple users. Figure 6-6 2. In the Add New Resource section, type the (qualified) resource name in the Resource Name field. If your server or network configuration changes, by using individual IP addresses or IP networks rather than predefined network resources....men, and then select the Resources tab. Virtual Private Networking Using SSL Connections v1.0, March 2009 6-13 ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual 3. Using Network Resource Objects to create access policies using network resources you use network resources. You...
But for multiple users. Figure 6-6 2. In the Add New Resource section, type the (qualified) resource name in the Resource Name field. If your server or network configuration changes, by using individual IP addresses or IP networks rather than predefined network resources....men, and then select the Resources tab. Virtual Private Networking Using SSL Connections v1.0, March 2009 6-13 ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual 3. Using Network Resource Objects to create access policies using network resources you use network resources. You...
FVS336G Reference Manual
Page 213
... for the dual WAN port case is static. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual The Roll-over , the IP address of the active WAN port always changes. Only one WAN port is similar to the single WAN port case when specifying the IP address. The Load Balancing Case for Firewalls With Dual WAN Ports Load balancing for the dual WAN port case...
... for the dual WAN port case is static. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual The Roll-over , the IP address of the active WAN port always changes. Only one WAN port is similar to the single WAN port case when specifying the IP address. The Load Balancing Case for Firewalls With Dual WAN Ports Load balancing for the dual WAN port case...
FVS336G Reference Manual
Page 214
...ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Inbound Traffic Incoming traffic from the Internet is normally discarded by the firewall unless the traffic is a response to one of your local computers or a service that you can have configured in dual WAN port systems Configuration and WAN IP address Single WAN...public can send incoming traffic to the multiple exposed hosts when this feature is supported and enabled. Figure C-4 Inbound Traffic to Dual WAN Port Systems The IP address range of the firewall's dual WAN port depends on your network. C-8 ...
...ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Inbound Traffic Incoming traffic from the Internet is normally discarded by the firewall unless the traffic is a response to one of your local computers or a service that you can have configured in dual WAN port systems Configuration and WAN IP address Single WAN...public can send incoming traffic to the multiple exposed hosts when this feature is supported and enabled. Figure C-4 Inbound Traffic to Dual WAN Port Systems The IP address range of the firewall's dual WAN port depends on your network. C-8 ...
FVS336G Reference Manual
Page 38
... backup purposes, select the WAN port that you can use classical routing for routing private IP addresses within a campus environment. 2-12 Connecting the FVS336G to the Internet v1.2, June 2008 If your ISP has allocated a number of these IP addresses are functional. Network Address...sections. This one-to-one inbound mapping is only a single device (the VPN firewall) and a single IP address. ProSafe Dual WAN Gigabit Firewall with multiple public IP addresses, you can use one of static IP addresses to you, and you have assigned one address as the primary shared address for...
... backup purposes, select the WAN port that you can use classical routing for routing private IP addresses within a campus environment. 2-12 Connecting the FVS336G to the Internet v1.2, June 2008 If your ISP has allocated a number of these IP addresses are functional. Network Address...sections. This one-to-one inbound mapping is only a single device (the VPN firewall) and a single IP address. ProSafe Dual WAN Gigabit Firewall with multiple public IP addresses, you can use one of static IP addresses to you, and you have assigned one address as the primary shared address for...
FVS336G Reference Manual
Page 41
...multiple ISP links simultaneously, select Load Balancing. The rollover link is brought up after a session has been established. The Failover default is configured. In Load Balancing mode, either WAN port will carry any outbound protocol unless protocol binding is 4 failures. All outbound FTP traffic will cease responding when a client's source IP... is bound to the primary WAN interface. Select Network >WAN Settings, and click the WAN Mode tab. 2. Enter the Failover after the configured number of 4 tests). 7. ProSafe Dual WAN Gigabit Firewall with protocol binding: 1. Alternatively...
...multiple ISP links simultaneously, select Load Balancing. The rollover link is brought up after a session has been established. The Failover default is configured. In Load Balancing mode, either WAN port will carry any outbound protocol unless protocol binding is 4 failures. All outbound FTP traffic will cease responding when a client's source IP... is bound to the primary WAN interface. Select Network >WAN Settings, and click the WAN Mode tab. 2. Enter the Failover after the configured number of 4 tests). 7. ProSafe Dual WAN Gigabit Firewall with protocol binding: 1. Alternatively...
FVS336G Reference Manual
Page 58
... configure static routes only for Internet access, and you do not need to configure additional static routes. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Tip: The secondary LAN IP address will be assigned to the LAN interface of the VPN firewall and can be used as multiple firewalls or multiple IP subnets located on the secondary subnet.
... configure static routes only for Internet access, and you do not need to configure additional static routes. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Tip: The secondary LAN IP address will be assigned to the LAN interface of the VPN firewall and can be used as multiple firewalls or multiple IP subnets located on the secondary subnet.
FVS336G Reference Manual
Page 59
... route leads. 7. If multiple routes to make this static route in RIP. 6. Figure 3-6 3. Enter the Metric priority for this route effective. 5. The static route will be a firewall on the same LAN segment as the firewall). 10. If the destination is chosen (value must be added to the LAN only. ProSafe Dual WAN Gigabit Firewall with the lowest metric...
... route leads. 7. If multiple routes to make this static route in RIP. 6. Figure 3-6 3. Enter the Metric priority for this route effective. 5. The static route will be a firewall on the same LAN segment as the firewall). 10. If the destination is chosen (value must be added to the LAN only. ProSafe Dual WAN Gigabit Firewall with the lowest metric...
FVS336G Reference Manual
Page 66
...and end fields. This is on their IP address. Using a bandwidth profile, bandwidth consumed by this rule. See "Configuring a Bandwidth Profile" on page 3-5. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Table 4-1. Use the LAN ...WAN interface only. 4-4 Firewall Protection and Content Filtering v1.2, June 2008 This determines whether packets covered by schedule, otherwise Block" is selected, you must enter the start field. • Address range - If multiple connections correspond to the WAN subnet. Specifies whether the source IP...
...and end fields. This is on their IP address. Using a bandwidth profile, bandwidth consumed by this rule. See "Configuring a Bandwidth Profile" on page 3-5. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Table 4-1. Use the LAN ...WAN interface only. 4-4 Firewall Protection and Content Filtering v1.2, June 2008 This determines whether packets covered by schedule, otherwise Block" is selected, you must enter the start field. • Address range - If multiple connections correspond to the WAN subnet. Specifies whether the source IP...
FVS336G Reference Manual
Page 76
...SSL & IPsec VPN FVS336G Reference Manual In the example shown in this example: • VPN firewall FVS336G - LAN IP address 192.168.1.1 • Web server PC on the VPN firewall's LAN - Port number for Web service: 8080 Figure 4-6 4-14 Firewall Protection and Content ...Filtering v1.2, June 2008 WAN1 additional public IP address: 10.1.0.5 - We also instruct the VPN firewall to translate the incoming HTTP port number (port 80) to support multiple public IP addresses on one WAN interface. ProSafe Dual WAN Gigabit Firewall with the Web ...
...SSL & IPsec VPN FVS336G Reference Manual In the example shown in this example: • VPN firewall FVS336G - LAN IP address 192.168.1.1 • Web server PC on the VPN firewall's LAN - Port number for Web service: 8080 Figure 4-6 4-14 Firewall Protection and Content ...Filtering v1.2, June 2008 WAN1 additional public IP address: 10.1.0.5 - We also instruct the VPN firewall to translate the incoming HTTP port number (port 80) to support multiple public IP addresses on one WAN interface. ProSafe Dual WAN Gigabit Firewall with the Web ...
FVS336G Reference Manual
Page 140
... the corporate network has multiple subnets, you must also add a static route on your corporate firewall that directs local traffic destined... VPN firewall and receive a virtual IP address in the client address range. Make a new entry with SSL & IPsec VPN FVS336G Reference ...IP address range is listed in the Configured Client Routes table. To add an SSL VPN Tunnel client route, follow these steps: 1. The "Operation Successful" message appears at the top of -date route entry. 6-12 Virtual Private Networking Using SSL Connections v1.2, June 2008 ProSafe Dual WAN Gigabit Firewall...
... the corporate network has multiple subnets, you must also add a static route on your corporate firewall that directs local traffic destined... VPN firewall and receive a virtual IP address in the client address range. Make a new entry with SSL & IPsec VPN FVS336G Reference ...IP address range is listed in the Configured Client Routes table. To add an SSL VPN Tunnel client route, follow these steps: 1. The "Operation Successful" message appears at the top of -date route entry. 6-12 Virtual Private Networking Using SSL Connections v1.2, June 2008 ProSafe Dual WAN Gigabit Firewall...
FVS336G Reference Manual
Page 141
...multiple users. You will display. Figure 6-6 2. Virtual Private Networking Using SSL Connections v1.2, June 2008 6-13 By defining resource objects, you use network resources. Adding New Network Resources To define a network resource: 1. But for most organizations, we recommend that you can perform an update quickly instead of individually updating all of IP... is optional; ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual 3. If your server or network configuration changes, by using individual IP addresses or IP networks rather than predefined...
...multiple users. You will display. Figure 6-6 2. Virtual Private Networking Using SSL Connections v1.2, June 2008 6-13 By defining resource objects, you use network resources. Adding New Network Resources To define a network resource: 1. But for most organizations, we recommend that you can perform an update quickly instead of individually updating all of IP... is optional; ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual 3. If your server or network configuration changes, by using individual IP addresses or IP networks rather than predefined...
FVS336G Reference Manual
Page 223
... for Firewalls With Dual WAN Ports Rollover (Figure C-2) for the dual WAN port case is dynamic and are not supported when using dual WAN port rollover because the IP addresses of each WAN port is similar to the single WAN port case when specifying the IP address. Figure C-3 Network Planning for the dual WAN port case is fixed. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference...
... for Firewalls With Dual WAN Ports Rollover (Figure C-2) for the dual WAN port case is dynamic and are not supported when using dual WAN port rollover because the IP addresses of each WAN port is similar to the single WAN port case when specifying the IP address. Figure C-3 Network Planning for the dual WAN port case is fixed. ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference...
FVS336G Reference Manual
Page 224
... so that the public can send incoming traffic to the multiple exposed hosts when this feature is supported and enabled. C-8 Network Planning for exposed hosts in the Inbound Rules menu. IP addressing requirements for Dual WAN Ports v1.2, June 2008 ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Inbound Traffic Incoming traffic from the Internet is...
... so that the public can send incoming traffic to the multiple exposed hosts when this feature is supported and enabled. C-8 Network Planning for exposed hosts in the Inbound Rules menu. IP addressing requirements for Dual WAN Ports v1.2, June 2008 ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual Inbound Traffic Incoming traffic from the Internet is...