EasyManua.ls Logo

Secure Computing SG300 User Manual

Secure Computing SG300
341 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
Secure Computing SnapGear™
User Manual
Secure Computing
4810 Harwood Road
San Jose, CA 95124-5206
Email: support@au.securecomputing.com
Web: www.securecomputing.com
Revision 3.1.4
August 15
th
, 2006
Part Number 86-0945932-A

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Secure Computing SG300 and is the answer not in the manual?

Secure Computing SG300 Specifications

General IconGeneral
BrandSecure Computing
ModelSG300
CategoryGateway
LanguageEnglish

Summary

Introduction

SG Gateway Appliances (SG3xx, SG5xx Series)

Overview of SG gateway appliances, including models SG300-SG580 and their security features.

SG Rack Mount Appliances (SG7xx Series)

Details the SG7xx series as flagship products with high throughput and rack-optimized form factor.

SG PCI Appliances (SG6xx Series)

Describes SG PCI appliances as hardware firewalls/VPN servers for individual PCs.

Getting Started

SG Gateway Appliance Quick Setup Guide

Step-by-step instructions for unpacking and setting up the SG Gateway appliance.

SG Rack Mount Appliance Quick Setup Guide

Initial setup for SG Rack Mount appliances, including network settings.

SG PCI Appliance Quick Setup Guide

Setup instructions for SG PCI appliances, including installation and driver setup.

The SnapGear Management Console

How to access and navigate the device's management console for configuration.

Network Setup

Configuring Connections

Configuration of network interfaces (Ethernet, wireless, serial) for various connection types.

Direct Connection

Setup for direct IP connections to networks, configurable statically or via DHCP.

ADSL

Guide to connecting to the Internet using DSL and selecting ADSL connection type.

Failover, Load Balancing and High Availability

Configuring multiple Internet connections for redundancy and load distribution.

DMZ Network

Setting up a DMZ for hosting public servers, isolated from the LAN.

Guest Network

Configuring a separate network for guests, often requiring VPN for access.

Wireless

Configuring the wireless interface as an access point or guest connection.

Wireless security

Setting up encryption and authentication (WPA, WEP) for wireless networks.

Bridging

Configuring the unit to bridge network interfaces for seamless communication.

VLANs

Defining and creating virtual network interfaces on a single physical interface.

Port Based VLANs

Using port-based VLANs to control access between individual switch ports.

GRE Tunnels

Building GRE tunnels to other devices supporting the Generic Routing Encapsulating protocol.

Routes

Configuring static and policy routes for advanced network traffic management.

Web Cache

Using the proxy-cache server to reduce Internet access time and bandwidth.

Firewall

Incoming Access

Controls access to the SnapGear unit itself for remote administration.

Administration services

Manages web, Telnet, and SSH services, restricting access to specific interfaces.

Web Management

Configures the web management console, enabling/disabling protocols and setting ports.

Customizing the Firewall

Customizing firewall rules using Packet Filter and NAT configurations.

Definitions

Useful for defining services, addresses, and interfaces for use in packet filter or NAT rules.

Packet Filtering

Defining rules to allow or deny traffic based on source/destination, interface, and service.

Network Address Translation (NAT)

Modifying IP addresses and ports for traffic traversing the unit.

Port Forwarding

Allowing controlled external access to internal services by forwarding requests.

Connection Tracking

Tracks packets and their relationships for stateful filtering and NAT.

Intrusion Detection

Systems for detecting and preventing network attacks, including basic and advanced options.

Basic Intrusion Detection and Blocking (IDB)

Simple IDS that monitors and blocks connection attempts to dummy services.

Advanced Intrusion Detection and Prevention (Snort and IPS)

Utilizes Snort v2 for detecting and blocking a wide range of attacks.

Access Control and Content Filtering

Controlling Internet access based on web content, user, or workstation.

Script Management

Manages and tests installed NASL scripts for vulnerability checks.

Content filtering

Limits access to types of web-based content via licensing.

Antivirus

Shields the LAN from viruses in email, web, and FTP traffic.

Virtual Private Networking

PPTP and L2TP

Supports PPTP and L2TP VPN servers for secure remote Windows client connections.

PPTP VPN Server

Setting up a PPTP connection from remote Windows clients to the local network.

L2TP VPN Server

Configuring the L2TP VPN server for remote Windows XP clients.

IPSec

Setting up IPSec tunnels for site-to-site connections, including quick setup and advanced configuration.

Quick Setup

Guides through the simple, one-page process to connect two sites using IPSec.

IPSec Failover

Configuring IPSec tunnels for failover between primary and secondary Internet connections.

USB

USB Mass Storage Devices

Attaching USB storage for print spool or network attached storage (NAS).

Share the storage device

Sharing USB devices on the network, setting names, descriptions, and permissions.

USB Printers

Sharing attached USB printers with the LAN and setting up remote printing.

System

Date and Time

Setting the device's date and time, manually or via NTP server.

Backup/Restore Configuration

Backing up and restoring the unit's configuration to minimize downtime.

Users

Adding administrative and local users with specific access controls.

Diagnostics

Providing low-level diagnostic info and network tests for troubleshooting.

System log

Using the system log for debugging and monitoring operational status.

Appendix A – Terminology

ADSL

Asymmetric Digital Subscriber Line for high-speed data transfer over telephone lines.

Authentication

Verifying the identity of a communication partner to prevent impersonation.

DHCP

Dynamic Host Configuration Protocol for assigning IP addresses to network computers.

Firewall

A network gateway device protecting a private network from external users.

IPSec

Internet Protocol Security for protecting network communications.

NAT

Network Address Translation, modifying IP addresses for traffic traversing networks.

PPTP

Point to Point Tunneling Protocol, popular for VPN applications.

VPN

Virtual Private Networking, enabling secure communication across public networks.

x.509 Certificates

Certificates used to authenticate remote parties against a Certificate Authority.

Appendix B – System Log

Access Logging

Logging traffic, including dropped packets and custom rules for detailed analysis.

Creating Custom Log Rules

Configuring custom log rules for more detailed logging and analysis of traffic.

Appendix C – Firmware Upgrade Practices and Precautions

Firmware Upgrade Practices and Precautions

Essential practices and warnings to follow before performing firmware upgrades.

Appendix D – Recovering From a Failed Upgrade

Recovery using Netflash

Step-by-step guide for recovering the unit using the Netflash.exe program on Windows.

Appendix F – Null Modem Administration

Enable null modem dial-in on the SnapGear unit

Enabling unit administration from a local PC via a null modem serial cable.

Appendix G – Command Line Interface (CLI)

firewall

SnapGear firewall utility for managing firewall rules and settings.

ifconfig

Utility to configure and display network interface parameters.

iptables

Administration tool for IPv4 packet filtering and Network Address Translation (NAT).

netflash

Utility for upgrading firmware on uclinux-coldfire platforms.

Related product manuals