Watchguard Firebox X5000 User's Guide

Browse online or download User's Guide for Networking Watchguard Firebox X5000. Watchguard Firebox X5000 User guide User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 78
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
WatchGuard
®
Fireware Migration Guide
WatchGuard Fireware v8.0
WatchGuard System Manager v8.0
Page view 0
1 2 3 4 5 6 ... 77 78

Summary of Contents

Page 1 - Fireware Migration Guide

WatchGuard®Fireware Migration GuideWatchGuard Fireware v8.0WatchGuard System Manager v8.0

Page 2 - Notice to Users

Comparing WFS and Fireware Pro6 WatchGuard System ManagerAuthentication Radius Yes No Almost No UI integration with the authentication server. D oes

Page 3 - Contents

Fireware Migration Guide 7Comparing WFS and Fireware ProIPSec P ass-throughYes Off by defaultYes • Turned off by default to push people towards using

Page 4 - User Guideii

Comparing WFS and Fireware Pro8 WatchGuard System ManagerTunnel Display/MonitorYes Yes Yes • Only tunnels that are “up” will display in the front pane

Page 5 - Manager with Fireware Pro

Fireware Migration Guide 9Planning Your MigrationPlanning Your MigrationAs with any major software migration, a well-designed plan for your upgrade fr

Page 6 - System Manager User Guide

Planning Your Migration10 WatchGuard System Manager

Page 7 - WatchGuard Servers

Migration Guide 11Documenting Your Security PolicyCHAPTER 2 Installing the WatchGuard System Manager softwareBefore you can operate a Firebox with Wat

Page 8 - WebBlocker Server

Installing the management station software12 WatchGuard System ManagerInstallation requirementsBefore you install WatchGuard System Manager, make sure

Page 9 - Fireware Migration Guide 5

Migration Guide 13Installing the management station softwareSaving the configuration fileYou can save the configuration file of a Firebox on the devic

Page 10 - 6 WatchGuard System Manager

Setting Up the Management Server14 WatchGuard System Manager2 Type the configuration passphrase. Click OK.3Select Make backup of current flash image b

Page 11 - Fireware Migration Guide 7

Migration Guide 15Setting Up the Management ServerWith WSM 8.0, we move the DVCP off the Firebox and on to a computer using the Windows operating syst

Page 12 - 8 WatchGuard System Manager

2 WatchGuard FirewareADDRESS:505 Fifth Avenue SouthSuite 500Seattle, WA 98104SUPPORT:www.watchguard.com/[email protected]. and Canada +

Page 13 - Planning Your Migration

Setting Up the Management Server16 WatchGuard System ManagerYou use the Management Server Setup Wizard to configure your Management Server. If you use

Page 14 - 10 WatchGuard System Manager

Migration Guide 17Migrating Basic DVCP Tunnels while setting up a Management ServerMigrating Basic DVCP Tunnels while setting up a Management ServerWa

Page 15 - Manager software

Migrating Basic DVCP Tunnels while setting up a Management Server18 WatchGuard System ManagerViewing the network with WatchGuard System ManagerAfter y

Page 16 - Installation requirements

Migration Guide 19Migrating Basic DVCP Tunnels while setting up a Management Server4 Expand the Management Server entry to see the Firebox clients man

Page 17 - Saving the configuration file

Setting Up the Log Server20 WatchGuard System ManagerSetting Up the Log ServerYou must also use Policy Manager define the Log Servers for each Firebox

Page 18 - Installing the software

Migration Guide 21Setting Up the WebBlocker ServerMerging log files from WFS 7.3 and before into the new XML formatWhen you migrate from a previous ve

Page 19 - Passwords and the Key Files

Setting Up the WebBlocker Server22 WatchGuard System ManagerThe first time you connect to the WebBlocker Server, it downloads the WebBlocker database.

Page 20 - 16 WatchGuard System Manager

Migration Guide 23Putting Fireware on the Firebox CHAPTER 3 Putting Fireware on the FireboxThere are two methods to put Fireware on a Firebox which ha

Page 21 - Procedure

Using the Quick Setup Wizard24 WatchGuard Firewarestation. Then make the cable connections you select. When you complete the connections, click Next.3

Page 22 - 18 WatchGuard System Manager

Migration Guide 25Putting Fireware on the Firebox 5 If your management station has more than one interface, you must select the interface you use to c

Page 23 - Device tab

User GuideiContentsCHAPTER 1 Introducing WatchGuard System Manager with Fireware Pro .1What is Fireware Pro? ...

Page 24 - Setting Up the Log Server

Using the Quick Setup Wizard26 WatchGuard Fireware7 Type the identifying information for the FireboxClick Next8 Add the license. Click Next.

Page 25 - 3 Click Merge

Migration Guide 27Putting Fireware on the Firebox 9 Select Static IP Addressing for this example. Click Next.10 Type the IP address and default gatewa

Page 26 - 2 Click Download

Using the Quick Setup Wizard28 WatchGuard Fireware11 Type the tristed interface IP address and the optiona interface address if you use one. Click Nex

Page 27 - Using the Quick Setup Wizard

Migration Guide 29Putting Fireware on the Firebox 13 Type and repeat the passphrases for the Firebox. Click Next.14 A temporary IP address is listed.

Page 28 - 24 WatchGuard Fireware

Using the Quick Setup Wizard30 WatchGuard Fireware15 This information screen appears while the wizard configures the Firebox.16 The process is complet

Page 29 - Migration Guide 25

Migration Guide 31Putting Fireware on the Firebox Connecting to the Firebox1 Open WatchGuard System Manager2 Click the connect to Device icon3 Type th

Page 30 - Add the license. Click Next

Using the Quick Setup Wizard32 WatchGuard Fireware4 Click the Policy Manager icon.5 The Fireware Policy Manager is where you make the configuration ch

Page 31 - Migration Guide 27

Migration Guide 33Putting Fireware on the Firebox Using fbxinstall.exeYou can also use the Fbxinstall.exe utility to install Fireware 8.0. fbxinstall.

Page 32 - 28 WatchGuard Fireware

Using fbxinstall.exe34 WatchGuard Fireware10 The installation completes. WFS 8.0 is installed. You now create a new configuration file using the Qui

Page 33 - Migration Guide 29

Migration Guide 35Making a Fireware Configuration CHAPTER 4 Making a Fireware ConfigurationAt this time, there is no configuration tool which automati

Page 34 - 30 WatchGuard Fireware

User GuideiiCHAPTER 3 Putting Fireware on the Firebox ...23Using the Quick Setup Wizard ...

Page 35 - Connecting to the Firebox

Basic Configuration Properties36 WatchGuard FirewareBasic Configuration PropertiesConnecting to a Firebox with Fireware Pro1 From WSM, click the Polic

Page 36 - 32 WatchGuard Fireware

Migration Guide 37Making a Fireware Configuration entry in Fireware Policy Manager by selecting the appropriate interface entry and clicking Configure

Page 37 - Using fbxinstall.exe

Basic Configuration Properties38 WatchGuard FirewareConfiguring your Network1 Select an interface from Fireware Policy Manager Network > Configurat

Page 38 - 34 WatchGuard Fireware

Migration Guide 39Making a Fireware Configuration 4 Select the interface type of truster, external, optional or disabled.5 Select static, DHCP pr PPPo

Page 39 - Migration Guide 35

Basic Configuration Properties40 WatchGuard Fireware3 Select the DHCP radio button and type the Host ID.4 Click OK.Note that with Fireware you must en

Page 40 - Working with Interfaces

Migration Guide 41Making a Fireware Configuration Intrusion Prevention/Default Packet HandlingMany of the same options are available in WFS Policy M

Page 41 - Migration Guide 37

Intrusion Prevention/Default Packet Handling42 WatchGuard Firewarethese (such as via a supernet), make certain to add a Blocked Sites Exceptions entry

Page 42 - Configuring your Network

Migration Guide 43Making a Fireware Configuration Network Address Translation (NAT)Dynamic NAT1-to-1 NAT Setup (Advanced)1 Select the 1-to-1 NAT tab f

Page 43 - DHCP Server

Network Address Translation (NAT)44 WatchGuard Fireware2 To add an entry click Add.3 Type the information and click OK.LoggingThe logging setup dialog

Page 44 - 4 Click OK

Migration Guide 45Making a Fireware Configuration 2 To add a log host click Configure.3 Type an encryption key and then confirm it.Encryption keys are

Page 45 - Blocked Sites

Fireware Migration Guide 1What is Fireware Pro?CHAPTER 1 Introducing WatchGuard System Manager with Fireware ProWatchGuard® System Manager (WSM) v8.0

Page 46 - 42 WatchGuard Fireware

Virtual Private Networking46 WatchGuard FirewareVirtual Private NetworkingFirebox Managed ClientsThe DVCP client only communicates with a WSM 8.0 mana

Page 47 - 1-to-1 NAT Setup (Advanced)

Migration Guide 47Making a Fireware Configuration Policies within Fireware are split into three sets, or arenas. The arenas are associated with either

Page 48 - 2 To add an entry click Add

Virtual Private Networking48 WatchGuard FirewareTunnelsFrom Policy Manager select VPN > Branch Office Tunnels. IPSec Routing Policies1 Adjust the A

Page 49 - Firewall Authentication

Migration Guide 49Making a Fireware Configuration 2 Click Add. 3 In the Addresses section of the New Tunnel dialog box click Add.4 Complete the inform

Page 50 - Virtual Private Networking

Services50 WatchGuard FirewareServicesFireware handles services in a completely different manner than in WFS. The biggest change is the lack of Incomi

Page 51 - Gateways

Migration Guide 51Making a Fireware Configuration differently than those provided by the global NAT tables, modify the Global NAT Rules on the Advance

Page 52 - IPSec Routing Policies

Services52 WatchGuard Fireware

Page 53 - 5 Click OK

Migration Guide 53Working with Proxies CHAPTER 5 Working with ProxiesFireware 8.0 proxy configuration offers new choices and more configuration possib

Page 54 - Services

Proxy Migration54 WatchGuard FirewareWith the removal of directionality, the default proxy actions are named so that they represent typical situations

Page 55 - Advanced tab

Migration Guide 55Working with Proxies The categories are typically separated into areas for general settings, some protocol specific items, and then

Page 56 - 52 WatchGuard Fireware

What’s New with WatchGuard System Manager?2 WatchGuard System ManagerUsing Fireware appliance software toolsWhen you install WatchGuard System Manager

Page 57 - Working with Proxies

Configuring the HTTP Proxy56 WatchGuard FirewareWFS 7.x Fireware 8.0Settings > Remove client connection info HTTP Request > Header Fields, strip

Page 58 - 54 WatchGuard Fireware

Migration Guide 57Working with Proxies WFS 7.x Fireware 8.0Settings > Deny submissions In HTTP Request > Request Methods, deny or allow the patt

Page 59 - Configuring the HTTP Proxy

Configuring the HTTP Proxy58 WatchGuard FirewareWFS 7.x Fireware 8.0Settings > Deny ActiveX applets In HTTP Response > Body Content Types, deny

Page 60 - 56 WatchGuard Fireware

Migration Guide 59Working with Proxies WFS 7.x Fireware 8.0Settings > Log accounting/auditing informationIn HTTP Request > General Setting

Page 61 - Migration Guide 57

Configuring the HTTP Proxy60 WatchGuard Fireware WFS 7.x Fireware 8.0Settings > Idle timeout In HTTP Request > General Settings, adjust the &q

Page 62 - 58 WatchGuard Fireware

Migration Guide 61Working with Proxies Configuring the Incoming SMTP ProxyThis section illustrates how various parameters are configured in the incomi

Page 63 - Migration Guide 59

Configuring the Incoming SMTP Proxy62 WatchGuard FirewareClone the SMTP-Incoming Proxy ActionGeneralSome of this information is available in General &

Page 64 - 60 WatchGuard Fireware

Migration Guide 63Working with Proxies Address PatternsIf there is a mixture of allowed and denied entries, you must change the ruleset view and apply

Page 65 - Migration Guide 61

Configuring the Incoming SMTP Proxy64 WatchGuard FirewareHeadersLoggingWFS 7.x Fireware 8.0WFS 7.x Fireware 8.0

Page 66 - WFS 7.x Fireware 8.0

Migration Guide 65Working with Proxies “Log accounting/auditing information" is the "Send a log message for each connection request" in

Page 67 - Address Patterns

Fireware Migration Guide 3What’s New with WatchGuard System Manager?• Interface independence• Signature-based intrusion prevention with stateful signa

Page 68

Outoing SMTP66 WatchGuard FirewareOutoing SMTPThis section illustrates how various parameters are configured in the outgoing SMTP proxy in WFS 7.x and

Page 69

Migration Guide 67Working with Proxies MasqueradingBuild Any patterns in the Address > Mail From ruleset under the "advanced view" (click

Page 70 - Outoing SMTP

Outoing SMTP68 WatchGuard Fireware"Masquerade Message IDs" is not fully available in Fireware. You can rewrite the user ID portion of the Me

Page 71 - Masquerading

Migration Guide 69Working with Proxies "Log domain masquerading" is available via the "Log" checkbox in the "Rule actions&quo

Page 72

FTP Proxy70 WatchGuard FirewareFTP ProxyThis section illustrates how various parameters are configured in the FTP proxy in WFS 7.x and Fireware 8.0. U

Page 73

Migration Guide 71Working with Proxies WFS 7.x Fireware 8.0Make connections ready only Make connections ready onlyWFS 7.x Fireware 8.0Deny incoming SI

Page 74 - FTP Proxy

FTP Proxy72 WatchGuard FirewareForce FTP session timeout is not available in Fireware. You cannot migrarte this option.“Log incoming accounting/auditi

Page 75

Migration Guide 73Working with Proxies WFS 7.x Fireware 8.0

Page 76

FTP Proxy74 WatchGuard Fireware

Page 77

Comparing WFS and Fireware Pro4 WatchGuard System Manager• Centralized management of VPN tunnel configurations• Certificate authority for distributing

Page 78 - 74 WatchGuard Fireware

Fireware Migration Guide 5Comparing WFS and Fireware ProDynam ic Routing Yes No N/A Basically sam e UI as in Vclass. We intend to make this user-frie

Comments to this Manuals

No comments