EasyManua.ls Logo

Secure Computing SG560 - User Manual

Default Icon
341 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Loading...
Secure Computing SnapGearā„¢
User Manual
Secure Computing
4810 Harwood Road
San Jose, CA 95124-5206
Email: support@au.securecomputing.com
Web: www.securecomputing.com
Revision 3.1.4
August 15
th
, 2006
Part Number 86-0945932-A

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Secure Computing SG560 and is the answer not in the manual?

Summary

Document Conventions

Introduction

SG Gateway Appliances (SG3 xx, SG5 xx Series)

Overview of SG Gateway appliances, their features, and network security capabilities.

Front Panel LEDs

Details on front panel LEDs indicating the operating status of the SnapGear unit.

SG Rack Mount Appliances (SG7 xx Series)

Overview of SG Rack Mount appliances, their features, and role in connecting central sites.

SG PCI Appliances (SG6 xx Series)

Details on SG PCI appliances, their hardware-based firewall/VPN server, and bridged mode operation.

Getting Started

SG Gateway Appliance Quick Setup

Step-by-step instructions for unpacking and setting up the SnapGear Gateway appliance.

Setup Single PC Connection

Guide to configuring a single PC's network settings to communicate with the SnapGear unit.

Configure SnapGear Password and LAN

Steps to set the SnapGear unit's administrative password and LAN connection settings.

Quick Setup Wizard Configuration

Walkthrough of the Quick Setup wizard for configuring LAN connection and DHCP server.

Configure SnapGear Internet Connection

Instructions for setting up the SnapGear unit's connection type to the Internet.

Connect SnapGear to LAN

Steps to connect the SnapGear unit to the local area network after configuration.

SG Rack Mount Appliance Quick Setup

Instructions for unpacking and initial setup of SG Rack Mount appliances.

SG PCI Appliance Quick Setup

Guide to installing the SG PCI appliance into a host PC and setting up drivers.

Setup PC for Web Management Console

Configuring a PC to access the SnapGear unit's web management console in bridged mode.

Network Setup

Configuring Network Connections

How to configure SnapGear unit's Ethernet, wireless, and serial ports for network connectivity.

Multifunction vs. Fixed-function Ports

Differentiating between generically labeled multifunction ports and specifically labeled fixed-function ports.

Direct Connection Setup

Configuring a direct IP connection to a network, assigning settings statically or via DHCP.

ADSL Connection Setup

Connecting to the Internet using DSL by selecting ADSL from the Change Type menu.

Failover, Load Balancing, and High Availability

Configuring multiple Internet connections for failover, load balancing, and high availability.

DMZ Network Configuration

Setting up a physically separate LAN segment for hosting servers accessible from the Internet.

Guest Network Configuration

Configuring connections for a guest network, typically an untrusted LAN or wireless network.

Wireless Network Configuration

Configuring the SnapGear unit's wireless interface as an access point or guest connection.

VLAN Configuration

Creating multiple virtual network interfaces using a single physical network interface.

Port Based VLANs Configuration

Using port-based VLANs to control access between individual ports in a switch.

GRE Tunnels Configuration

Building GRE tunnels to other devices that support the Generic Routing Encapsulating protocol.

Firewall

Firewall Incoming Access Control

Controlling access to the SnapGear unit itself, such as for remote administration.

Firewall Administration Services

Managing access to web, Telnet, and SSH services for administrative users.

Firewall Web Management Configuration

Configuring the Management Console, enabling/disabling protocols, and setting certificates for HTTPS.

Customizing Firewall Rules

Accomplishing firewall customization through Packet Filter and Network Address Translation (NAT) rules.

Firewall Definitions for Rules

Defining services, addresses, and interfaces to be used in matching firewall or NAT packets.

Firewall Packet Filtering Rules

Creating rules to match and allow/disallow traffic based on source/destination, interface, and service.

Firewall Rate Limiting

Applying rate limiting settings to packet filtering rules to prevent service unavailability.

Network Address Translation (NAT)

Modifying IP address and/or port of traffic traversing the SnapGear unit.

Firewall Port Forwarding

Altering destination address/port of packets received by the SnapGear unit for controlled access.

Intrusion Detection Systems (IDS)

Utilizing intrusion detection systems to detect and prevent attacks on the network.

Access Control and Content Filtering

Controlling Internet access based on web content, user, or workstation.

Antivirus Scanning

Shielding the LAN from viruses propagating through email, web, and FTP.

Virtual Private Networking (VPN)

PPTP and L2 TP VPN Overview

Overview of PPTP and L2TP VPN servers allowing secure remote Windows client connections.

PPTP VPN Server Configuration

Setting up a PPTP connection from a remote Windows client to the SnapGear unit.

L2 TP VPN Server Configuration

Setting up an L2TP/IPSec connection from a remote Windows XP client to the SnapGear unit.

IPSec VPN Configuration

Establishing IPSec tunnels for secure, site-to-site network communication.

IPSec Tunnel List Management

Viewing and managing configured IPSec tunnels, including their status and remote party details.

USB Device Management

USB Mass Storage Device Setup

Attaching USB mass storage devices for use as print spool or network attached storage (NAS).

Share USB Storage Device

Configuring network shares for USB storage devices, setting share names and access permissions.

Partitioning USB Mass Storage Device

Step-by-step walkthrough for partitioning a USB mass storage device using Linux command-line tools.

USB Printer Sharing

Sharing attached USB printers with the LAN via the SnapGear unit's print server.

System Configuration

System Date and Time Configuration

Setting the SnapGear unit's clock to the correct date and time for logging and certificates.

Backup and Restore Configuration

Backing up and restoring the SnapGear unit's configuration to minimize downtime.

User Account Management

Adding and managing administrative and local user accounts for access control and VPN.

Remote Management Configuration

Enabling remote management via Secure Computing Global Command Center (GCC), CMS, or SNMP.

System Diagnostics and Testing

Accessing low-level diagnostic information and network tests to diagnose problems.

System Reboot and Reset

Rebooting the device or erasing configuration to restore factory default settings.

System Firmware Flash Upgrade

Loading new firmware versions onto the SnapGear unit to fix issues or add features.

Appendix C: Firmware Upgrade Practices and Precautions

Appendix D: Recovering From a Failed Upgrade

Recovery Using Netflash Program

Steps to recover the SnapGear unit using the Netflash.exe program on a Windows PC.

Recovery Using BOOTP Server

Procedure for recovering the unit via network booting using a BOOTP server and firmware files.

Appendix E: System Clock

System Units with Hardware Clock

How time and date are updated and maintained on units with a hardware clock.

System Units Without Hardware Clock

How date and time are maintained on units without a hardware clock (SG300).

Appendix F: Null Modem Administration

Enable Null Modem Dial-in

Configuring dial-in on the SnapGear unit using a null modem serial cable for administration.

Null Modem Connection Troubleshooting

Steps to troubleshoot connection issues related to serial port settings.

Appendix G: Command Line Interface (CLI)

Secure Computing SG560 Specifications

General IconGeneral
BrandSecure Computing
ModelSG560
CategoryGateway
LanguageEnglish

Related product manuals