Watchguard Firebox X1000 User's Guide

Browse online or download User's Guide for Networking Watchguard Firebox X1000. Watchguard Firebox X1000 User guide User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 271
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 1 - User Guide

WatchGuard®Firebox® System User GuideWatchGuard Firebox System

Page 2 - Notice to Users

x WatchGuard Firebox SystemAdding Basic Services to Policy Manager ... 61Configuring Routes ...

Page 3 - User Guide iii

Chapter 7: Configuring Network Address Translation84 WatchGuard Firebox SystemAdding simple dynamic NAT entriesUsing built-in host aliases, you can qu

Page 4 - End-User License Agreement

Using Simple Dynamic NATUser Guide 855 Click OK.The new entry appears in the Dynamic NAT Entries list.Reordering simple dynamic NAT entriesTo reorder

Page 5 - User Guide v

Chapter 7: Configuring Network Address Translation86 WatchGuard Firebox SystemUsing Service-Based Dynamic NATUsing service-based dynamic NAT, you can

Page 6

Configuring a Service for Incoming Static NATUser Guide 87Disable NAT Disables dynamic NAT for outgoing packets using this service. Use this setting

Page 7 - Contents

Chapter 7: Configuring Network Address Translation88 WatchGuard Firebox SystemSetting static NAT for a serviceStatic NAT, like service-based NAT, is c

Page 8

Using 1-to-1 NATUser Guide 899 Click OK to close the Add Address dialog box. Click OK to close the services’s Properties dialog box.Using 1-to-1 NAT1-

Page 9 - User Guide ix

Chapter 7: Configuring Network Address Translation90 WatchGuard Firebox System2 Click Advanced.The Advanced NAT Settings dialog box appears.3 Click th

Page 10

Using 1-to-1 NATUser Guide 91Proxies and NATThis table identifies each proxy and what types of NAT it supports.Simple dynamicStatic Service-based 1-to

Page 11 - User Guide xi

Chapter 7: Configuring Network Address Translation92 WatchGuard Firebox System

Page 12

User Guide 93CHAPTER 8 Configuring Filtered ServicesYou add filtered services–in addition to proxied services–to control and monitor the flow of IP pa

Page 13 - User Guide xiii

User Guide xiEnabling simple dynamic NAT ... 83Adding simple dynamic NAT entries ... 8

Page 14

Chapter 8: Configuring Filtered Services94 WatchGuard Firebox SystemSelecting Services for your Security Policy ObjectivesThe WatchGuard Firebox Syste

Page 15 - User Guide xv

Adding and Configuring ServicesUser Guide 95• Allowing a service to the optional network is safer than allowing it to the trusted network.• Allowing i

Page 16

Chapter 8: Configuring Filtered Services96 WatchGuard Firebox SystemYou can also add unique or custom services. However, if you do, take steps to perm

Page 17 - Introduction

Adding and Configuring ServicesUser Guide 97Configurable parameters for servicesSeveral service parameters can be configured:Sources and DestinationsY

Page 18 - WatchGuard Control Center

Chapter 8: Configuring Filtered Services98 WatchGuard Firebox System2 Expand either the Packet Filters or Proxies folder by clicking the plus (+) sign

Page 19 - Minimum Requirements

Adding and Configuring ServicesUser Guide 995 (Optional) You can customize both the name and the comments that appear when the service is being config

Page 20 - Hardware requirements

Chapter 8: Configuring Filtered Services100 WatchGuard Firebox SystemCreating a new serviceIn addition to built-in filtered services provided by Watch

Page 21 - WatchGuard Options

Adding and Configuring ServicesUser Guide 101IgnoreSource port can be any number (0—65565). (If you are not sure which port setting to use, choose thi

Page 22 - SpamScreen

Chapter 8: Configuring Filtered Services102 WatchGuard Firebox System 11 Click OK.The Services dialog box appears with the new service displayed under

Page 23 - About this Guide

Defining Service PropertiesUser Guide 103Defining Service PropertiesYou use the service’s Properties dialog box to configure the incoming and outgoing

Page 24 - and .idx files

xii WatchGuard Firebox SystemAdding a proxy service for HTTP ... 121Configuring a caching proxy server ...

Page 25 - Service and Support

Chapter 8: Configuring Filtered Services104 WatchGuard Firebox SystemAdding service propertiesThe method used to add incoming and outgoing service pro

Page 26 - Broadcasts

Defining Service PropertiesUser Guide 105Working with wg_iconsService icons beginning with “wg_” are created automatically when you enable features su

Page 27 - Service

Chapter 8: Configuring Filtered Services106 WatchGuard Firebox SystemFrom the Properties dialog box:1 Click the Incoming tab.2 Click Logging.The Loggi

Page 28 - The Account page appears

Service PrecedenceUser Guide 107The remaining controls are active when you select the Send notification checkbox:EmailTriggers an email message when t

Page 29 - User Guide 13

Chapter 8: Configuring Filtered Services108 WatchGuard Firebox System“Multiservices” can contain subservices of more than one precedence group. “Filte

Page 30 - Online Help

Service PrecedenceUser Guide 109based on the specificity of targets, from most specific to least specific. The following order is used:IP refers to ex

Page 31 - Searching for topics

Chapter 8: Configuring Filtered Services110 WatchGuard Firebox System

Page 32 - Context-sensitive Help

User Guide 111CHAPTER 9 Configuring Proxied ServicesProxy filtering goes a step beyond packet filtering by examining a packet’s content, not just the

Page 33 - Assisted Support

Chapter 9: Configuring Proxied Services112 WatchGuard Firebox SystemConfiguring an SMTP Proxy ServiceThe SMTP proxy limits several potentially harmful

Page 34 - Firebox Installation Services

Configuring an SMTP Proxy ServiceUser Guide 113the Services Arena. (For information on how to add a service, see the previous chapter.) From the Servi

Page 35 - Training and Certification

User Guide xiiiSetting logging and notification for blocked ports ... 156Blocking Sites Temporarily with Service Settings ... 157Conf

Page 36 - 20 WatchGuard Firebox System

Chapter 9: Configuring Proxied Services114 WatchGuard Firebox SystemBlocking email content typesMIME stands for Multipurpose Internet Mail Extensions,

Page 37 - Getting Started

Configuring an SMTP Proxy ServiceUser Guide 115• A string is a wildcard pattern if it contains a question mark (?), an asterisk (*), or a right parent

Page 38 - Gathering Network Information

Chapter 9: Configuring Proxied Services116 WatchGuard Firebox System2 Select Allowed To from the Category drop list.3 In the text box to the left of t

Page 39 - Network addresses

Configuring an SMTP Proxy ServiceUser Guide 117• Accounting and auditing information.Configuring the Outgoing SMTP ProxyUse the Outgoing SMTP Proxy di

Page 40 - 24 WatchGuard Firebox System

Chapter 9: Configuring Proxied Services118 WatchGuard Firebox Systemmight be inside.salesdept.bigcompany.com, which would become the public address bi

Page 41 - User Guide 25

Configuring an FTP Proxy ServiceUser Guide 119Configuring an FTP Proxy ServiceThe FTP proxy service enables you to access another computer (on a separ

Page 42 - Routed configuration

Chapter 9: Configuring Proxied Services120 WatchGuard Firebox SystemSelecting an HTTP ServiceBecause of the extensive security implications of HTTP tr

Page 43 - Drop-in configuration

Selecting an HTTP ServiceUser Guide 121 NOTEThe WatchGuard service called “HTTP” is not to be confused with an HTTP caching proxy. An HTTP caching pr

Page 44 - 28 WatchGuard Firebox System

Chapter 9: Configuring Proxied Services122 WatchGuard Firebox SystemFor detailed information about the HTTP proxy, see the online support resources at

Page 45 - User Guide 29

Configuring the DNS Proxy ServiceUser Guide 123The Firebox communicates with proxy servers exactly the same way that clients normally do. Instead of a

Page 46 - 30 WatchGuard Firebox System

xiv WatchGuard Firebox SystemViewing the WSEP application ... 180Starting and stopping the WSEP ...

Page 47 - User Guide 31

Chapter 9: Configuring Proxied Services124 WatchGuard Firebox Systemattacks that cause a buffer overflow, which crash the targeted server and enable t

Page 48 - 32 WatchGuard Firebox System

Configuring the DNS Proxy ServiceUser Guide 1255 Click the Incoming tab. Use the Incoming DNS-Proxy connections are drop list to select Enabled and A

Page 49 - Cabling the Firebox

Chapter 9: Configuring Proxied Services126 WatchGuard Firebox System

Page 50 - 34 WatchGuard Firebox System

User Guide 127CHAPTER 10 Creating Aliases and Implementing AuthenticationAliases are shortcuts used to identify groups of hosts, networks, or users. T

Page 51 - Running the QuickSetup Wizard

Chapter 10: Creating Aliases and Implementing Authentication128 WatchGuard Firebox Systema user workstation may have several different IP addresses ov

Page 52 - Reference

Using AliasesUser Guide 1292 Click Add.3 In the Host Alias Name text box, enter the name used to identify the alias when configuring services and auth

Page 53 - Testing the connection

Chapter 10: Creating Aliases and Implementing Authentication130 WatchGuard Firebox System8 When you finish adding members, click OK.The Host Alias dia

Page 54 - Entering IP addresses

Authentication Server TypesUser Guide 131Enabling remote authenticationUse this procedure to allow remote users to authenticate from the External inte

Page 55 - What’s Next

Chapter 10: Creating Aliases and Implementing Authentication132 WatchGuard Firebox SystemTo specify authentication type:1 From Policy Manager, select

Page 56

Defining Firebox Users and Groups for AuthenticationUser Guide 133computers. As your organization changes, you can add or remove users or systems from

Page 57 - Firebox Basics

User Guide xvEditing an existing report ... 205Deleting a report ...

Page 58 - 42 WatchGuard Firebox System

Chapter 10: Creating Aliases and Implementing Authentication134 WatchGuard Firebox System4 To add a new user, click the Add button beneath the Users l

Page 59 - Opening a Configuration File

Configuring RADIUS Server AuthenticationUser Guide 1352 Click the NT Server tab.The information appears as shown in the following figure.3 To identify

Page 60 - 44 WatchGuard Firebox System

Chapter 10: Creating Aliases and Implementing Authentication136 WatchGuard Firebox Systemauthentication key that identifies it to the RADIUS server. N

Page 61 - Saving a Configuration File

Configuring CRYPTOCard Server AuthenticationUser Guide 1377 Click OK.8 Gather the IP address of the Firebox and the user or group aliases you want to

Page 62 - 46 WatchGuard Firebox System

Chapter 10: Creating Aliases and Implementing Authentication138 WatchGuard Firebox SystemProperties dialog box, and the IP address of the Firebox on t

Page 63 - Resetting Firebox Passphrases

Configuring SecurID AuthenticationUser Guide 139On the CRYPTOCard server:1 Add the IP address of the Firebox where appropriate according to CRYPTOCard

Page 64 - Setting the Firebox Model

Chapter 10: Creating Aliases and Implementing Authentication140 WatchGuard Firebox System3 Enter the IP address of the SecurID server.4 Enter or verif

Page 65 - Setting the Time Zone

User Guide 141CHAPTER 11 Protecting Your Network From AttacksThe WatchGuard Firebox System can protect your network from many types of attacks. In add

Page 66 - 50 WatchGuard Firebox System

Chapter 11: Protecting Your Network From Attacks142 WatchGuard Firebox SystemLogging options help you identify sites that exhibit suspicious behavior

Page 67 - Configure Your Network

Default Packet HandlingUser Guide 143that the packet apparently originated from a host that is trusted, and therefore doesn’t require validation or a

Page 68 - The Policy Manager appears

xvi WatchGuard Firebox SystemSetting privileges ... 223Creating WebBlocker exceptions ...

Page 69 - For more information on

Chapter 11: Protecting Your Network From Attacks144 WatchGuard Firebox Systemwhich services are running on the hosts inside that network. From Policy

Page 70

Default Packet HandlingUser Guide 145They are stored in a backlog until they are completed or time out. When the server’s backlog is full, no new conn

Page 71 - Enabling static PPPoE

Chapter 11: Protecting Your Network From Attacks146 WatchGuard Firebox Systemrecorded. If these messages occur frequently when your server is not unde

Page 72 - Defining External IP Aliases

Integrating Intrusion DetectionUser Guide 147and either allow or deny packets. Little extra bandwidth is available to conduct sophisticated analysis o

Page 73 - Adding Secondary Networks

Chapter 11: Protecting Your Network From Attacks148 WatchGuard Firebox Systemadd_hostileThis command adds a site to the Auto-Blocked Site list, with t

Page 74 - From Policy Manager:

Blocking SitesUser Guide 149Example 2The IDS adds a message to the Firebox’s log stream:fbidsmate 10.0.0.1 secure1 add_log_message 3 "IDS system

Page 75 - User Guide 59

Chapter 11: Protecting Your Network From Attacks150 WatchGuard Firebox System• Permanently blocked sites–which are listed in the configuration file an

Page 76 - Modifying an existing subnet

Blocking SitesUser Guide 151From Policy Manager:1 On the toolbar, click the Blocked Sites icon (shown at right).You can also select Setup => Blocke

Page 77 - Removing a subnet

Chapter 11: Protecting Your Network From Attacks152 WatchGuard Firebox SystemCreating exceptions to the Blocked Sites listA blocked site exception is

Page 78 - Configuring Routes

Blocking PortsUser Guide 153Blocking PortsYou can block ports to explicitly disable external network services from accessing ports that are vulnerable

Page 79 - Defining a Host Route

User Guide 1CHAPTER 1 IntroductionWelcome to WatchGuard®In the past, a connected enterprise needed a complex set of tools, systems, and personnel for

Page 80 - 64 WatchGuard Firebox System

Chapter 11: Protecting Your Network From Attacks154 WatchGuard Firebox Systemintrusions can be difficult or impossible to detect by all but the most k

Page 81 - Control Center

Blocking PortsUser Guide 155port 0Port 0 is reserved by IANA, but many programs that scan ports start their search on port 0.port 1Port 1 is for the r

Page 82 - Control Center Components

Chapter 11: Protecting Your Network From Attacks156 WatchGuard Firebox SystemTo remove a blocked port, select the port to remove. Click Remove.Auto-bl

Page 83 - QuickGuide

Blocking Sites Temporarily with Service SettingsUser Guide 157Blocking Sites Temporarily with Service SettingsUse service properties to automatically

Page 84 - Front panel

Chapter 11: Protecting Your Network From Attacks158 WatchGuard Firebox System

Page 85 - Firebox and VPN tunnel status

User Guide 159CHAPTER 12 Monitoring Firebox ActivityAn important part of an effective network security policy is the monitoring of network events. Mon

Page 86 - Branch Office VPN Tunnels

Chapter 12: Monitoring Firebox Activity160 WatchGuard Firebox SystemStarting Firebox Monitors and connecting to a FireboxFrom Control Center:1 On the

Page 87 - Red exclamation point

Firebox MonitorsUser Guide 161BandwidthMeterThe BandwidthMeter tab on the Firebox Monitors display, shown in the following figure, shows real-time ban

Page 88 - Traffic Monitor

Chapter 12: Monitoring Firebox Activity162 WatchGuard Firebox SystemAdding services to ServiceWatchBy default, ServiceWatch graphs the SMTP, FTP, and

Page 89 - Working with Control Center

Firebox MonitorsUser Guide 163Log hostsThe IP addresses of the log host or hosts.Log host(s): 206.148.32.16Network configurationStatistics about the

Page 90 - Connecting to a Firebox

Chapter 1: Introduction2 WatchGuard Firebox SystemWatchGuard Firebox System ComponentsThe WatchGuard Firebox System has all of the components needed t

Page 91 - Changing the polling rate

Chapter 12: Monitoring Firebox Activity164 WatchGuard Firebox SystemMemoryStatistics on the memory usage of the currently running Firebox. Numbers sho

Page 92 - Getting Help on the Web

Firebox MonitorsUser Guide 165 73 fblightd S 464 308 3927:05.75 ( 5) 0 (nice) 74 /bin/logger S 1372 592 1:2

Page 93 - Manipulating Traffic Monitor

Chapter 12: Monitoring Firebox Activity166 WatchGuard Firebox SystemThe interfaces used in this section are as follows:eth0 - External (public) interf

Page 94 - Launching Policy Manager

HostWatchUser Guide 167Authentication listThe Authentication List tab displays the host IP addresses and user names of everyone currently authenticate

Page 95 - Launching Historical Reports

Chapter 12: Monitoring Firebox Activity168 WatchGuard Firebox SystemThe HostWatch display uses the logging settings configured with Policy Manager. Fo

Page 96 - 80 WatchGuard Firebox System

HostWatchUser Guide 169Connecting HostWatch to a Firebox:From HostWatch:1 Select File => Connect.Or, on the Hostwatch toolbar, click the Connect ic

Page 97 - Address Translation

Chapter 12: Monitoring Firebox Activity170 WatchGuard Firebox System3 To restart the display, click Continue (shown at right).4 To step through the di

Page 98 - Dynamic NAT

User Guide 171CHAPTER 13 Setting Up Logging and NotificationAn event is any single activity that occurs at the Firebox, such as denying a packet from

Page 99

Chapter 13: Setting Up Logging and Notification172 WatchGuard Firebox Systemboth flexible and powerful. You can configure your firewall to log and not

Page 100 - 1 Click Add

Developing Logging and Notification PoliciesUser Guide 173only by a small number of people in an organization. In that case you might want to log all

Page 101 - User Guide 85

Minimum RequirementsUser Guide 3Historical ReportsCreates HTML reports that display session types, most active hosts, most used services, URLs, and ot

Page 102 - 86 WatchGuard Firebox System

Chapter 13: Setting Up Logging and Notification174 WatchGuard Firebox SystemFailover LoggingWatchGuard uses failover logging to minimize the possibili

Page 103 - Adding external IP addresses

Designating Log Hosts for a FireboxUser Guide 175 - Set the log encryption key on each log host identical to the key set in Policy ManagerDesignating

Page 104 - 88 WatchGuard Firebox System

Chapter 13: Setting Up Logging and Notification176 WatchGuard Firebox System3 Enter the IP address to be used by the log host.When typing IP addresses

Page 105 - Using 1-to-1 NAT

Designating Log Hosts for a FireboxUser Guide 177Changing the log encryption keyEdit a log host entry to change the log encryption key. From Policy Ma

Page 106 - 90 WatchGuard Firebox System

Chapter 13: Setting Up Logging and Notification178 WatchGuard Firebox SystemThe Firebox sets its clock to the current log host. If the Firebox and the

Page 107 - Proxies and NAT

Setting up the WatchGuard Security Event ProcessorUser Guide 179By default, the WSEP application is installed to run as a Windows service, starting au

Page 108 - 92 WatchGuard Firebox System

Chapter 13: Setting Up Logging and Notification180 WatchGuard Firebox SystemAs a service, using the Command PromptIf the WSEP application was not inst

Page 109 - Configuring Filtered Services

Setting up the WatchGuard Security Event ProcessorUser Guide 181If the WatchGuard Security Event Processor icon is not in the tray, in Control Center,

Page 110 - Incoming service guidelines

Chapter 13: Setting Up Logging and Notification182 WatchGuard Firebox SystemFrom the WatchGuard Security Event Processor user interface:1 Select File

Page 111 - Outgoing service guidelines

Setting Global Logging and Notification PreferencesUser Guide 183entries in two weeks, whereas a large one with many services enabled might easily log

Page 112 - 96 WatchGuard Firebox System

ii WatchGuard Firebox SystemNotice to UsersInformation in this guide is subject to change without notice. Companies, names, and data used in examples

Page 113 - Adding a service

Chapter 1: Introduction4 WatchGuard Firebox SystemWindows NT requirements•Microsoft Windows NT 4.0• Microsoft Service Pack 4, Service Pack 5, or Servi

Page 114 - 4 Click Add

Chapter 13: Setting Up Logging and Notification184 WatchGuard Firebox SystemScheduling log reportsYou can use the WSEP application to schedule the aut

Page 115 - User Guide 99

Customizing Logging and Notification by Service or OptionUser Guide 185Setting a Firebox friendly name for log filesYou can give the Firebox a friendl

Page 116 - Creating a new service

Chapter 13: Setting Up Logging and Notification186 WatchGuard Firebox SystemCategoryThe event types that can be logged by the service or option. This

Page 117 - 10 Click OK

Customizing Logging and Notification by Service or OptionUser Guide 187 NOTEWatchGuard allows only one notification type per event.Setting Launch Int

Page 118 - Deleting a service

Chapter 13: Setting Up Logging and Notification188 WatchGuard Firebox SystemThe repeat count multiplied by the launch interval equals the amount of ti

Page 119 - Defining Service Properties

Customizing Logging and Notification by Service or OptionUser Guide 1892 Click Logging.3 Modify logging and notification properties according to your

Page 120 - Adding service properties

Chapter 13: Setting Up Logging and Notification190 WatchGuard Firebox System

Page 121 - Working with wg_icons

User Guide 191CHAPTER 14 Reviewing and Working with Log FilesLog files are a valuable tool for monitoring your network, identifying potential attacks,

Page 122 - 2 Click Logging

Chapter 14: Reviewing and Working with Log Files192 WatchGuard Firebox SystemThe log file to which the WSEP is currently writing records can be named

Page 123 - Service Precedence

Viewing Files with LogViewerUser Guide 193Searching for specific entriesLogViewer has a search tool to enable you to find specific transactions quickl

Page 124 - 108 WatchGuard Firebox System

WatchGuard OptionsUser Guide 5.WatchGuard OptionsThe WatchGuard Firebox System is enhanced by optional features designed to accommodate the needs of d

Page 125 - User Guide 109

Chapter 14: Reviewing and Working with Log Files194 WatchGuard Firebox SystemCopying log data1 Select the log entries you want to copy.Use the SHIFT k

Page 126 - 110 WatchGuard Firebox System

Displaying and Hiding FieldsUser Guide 195Displaying and Hiding FieldsThe following figure shows an example of the type of display you normally see in

Page 127 - Configuring Proxied Services

Chapter 14: Reviewing and Working with Log Files196 WatchGuard Firebox SystemTimeThe time the record entered the log file. Default = ShowThe Firebox r

Page 128 - 112 WatchGuard Firebox System

Working with Log FilesUser Guide 197IP header lengthLength, in octets, of the IP header for this packet. A header length that is not equal to 20 indic

Page 129 - User Guide 113

Chapter 14: Reviewing and Working with Log Files198 WatchGuard Firebox System• Right-click the WSEP icon (shown at right) in the Windows system tray a

Page 130 - Blocking email content types

Working with Log FilesUser Guide 199log rollover” on page 183. However, you may occasionally want to force the rollover of a log file.• From the WSEP

Page 131 - User Guide 115

Chapter 14: Reviewing and Working with Log Files200 WatchGuard Firebox SystemSending logs to a log host at another locationBecause they are encrypted

Page 132 - 116 WatchGuard Firebox System

Working with Log FilesUser Guide 2015 Save the new configuration to the remote office Firebox. On the log host:You must use the same log encryption ke

Page 133 - User Guide 117

Chapter 14: Reviewing and Working with Log Files202 WatchGuard Firebox System

Page 134 - 118 WatchGuard Firebox System

User Guide 203CHAPTER 15 Generating Reports of Network ActivityAccounting for Internet usage can be a challenging network administration task. One of

Page 135 - 4 Click OK

Chapter 1: Introduction6 WatchGuard Firebox SystemVPN Manager is bundled with the WFS software, but it is available for use only if you enable the VPN

Page 136 - Selecting an HTTP Service

Chapter 15: Generating Reports of Network Activity204 WatchGuard Firebox SystemCreating and Editing ReportsTo start Historical Reports, from Control C

Page 137 - User Guide 121

Specifying a Report Time SpanUser Guide 205Editing an existing report At any time, you can modify the properties of an existing report. From Historica

Page 138 - 122 WatchGuard Firebox System

Chapter 15: Generating Reports of Network Activity206 WatchGuard Firebox SystemSpecifying Report SectionsUse the Sections tab on the Report Properties

Page 139 - GET / HTTP/1.1

Setting Report PropertiesUser Guide 207Setting Report PropertiesReports contain either Summary sections or Detail sections. Each can be presented in d

Page 140 - Adding the DNS Proxy Service

Chapter 15: Generating Reports of Network Activity208 WatchGuard Firebox Systeminclude the name and time of the report. Each report is filed in one of

Page 141 - DNS file descriptor limit

Using Report FiltersUser Guide 209 NOTEWatchGuard HTTP proxy logging must be turned on to supply WebTrends the logging information required for its r

Page 142 - 126 WatchGuard Firebox System

Chapter 15: Generating Reports of Network Activity210 WatchGuard Firebox SystemHostFilter a report based on host IP address.PortFilter a report based

Page 143 - Implementing Authentication

Scheduling and Running ReportsUser Guide 211Deleting a report filterTo remove a filter from the list of available filters, highlight the filter. Click

Page 144 - Using Aliases

Chapter 15: Generating Reports of Network Activity212 WatchGuard Firebox System6 Click OK.Manually running a reportAt any time, you can run one or mor

Page 145 - User Guide 129

Report Sections and Consolidated SectionsUser Guide 213Time Summary – Packet FilteredA table, and optionally a graph, of all accepted connections dist

Page 146 - How User Authentication Works

About this GuideUser Guide 7SpamScreen is bundled with the WFS software, but it is available for use only if you enable the SpamScreen checkbox when i

Page 147 - Authentication Server Types

Chapter 15: Generating Reports of Network Activity214 WatchGuard Firebox SystemSession Summary – Proxied TrafficA table, and optionally a graph, of th

Page 148 - 132 WatchGuard Firebox System

Report Sections and Consolidated SectionsUser Guide 215Denied Incoming Packet DetailA list of denied incoming packets, sorted by time. The fields are

Page 149 - User Guide 133

Chapter 15: Generating Reports of Network Activity216 WatchGuard Firebox SystemService SummaryA table, and optionally a graph, of traffic for all serv

Page 150 - 134 WatchGuard Firebox System

User Guide 217CHAPTER 16 Controlling Web Site AccessWebBlocker is a feature of the WatchGuard Firebox System that works in conjunction with the HTTP

Page 151 - 5 Click OK

Chapter 16: Controlling Web Site Access218 WatchGuard Firebox SystemWFS under high load conditions, consider installing the WebBlocker server on a ded

Page 152 - 136 WatchGuard Firebox System

Getting Started with WebBlockerUser Guide 219• Install or remove the server• Start or stop the serverTo run the WebBlocker utility, select Start =>

Page 153 - User Guide 137

Chapter 16: Controlling Web Site Access220 WatchGuard Firebox System Configuring the WebBlocker ServiceWebBlocker is a built-in feature of several ser

Page 154 - 138 WatchGuard Firebox System

Configuring the WebBlocker ServiceUser Guide 2214 Next to the WebBlocker Servers box, click Add.5 In the dialog box that appears, type the IP address

Page 155 - User Guide 139

Chapter 16: Controlling Web Site Access222 WatchGuard Firebox SystemRequest for URL www.badsite.com denied by WebBlocker: host blocked for violence/pr

Page 156 - SecurID server

Configuring the WebBlocker ServiceUser Guide 223Setting privilegesWebBlocker differentiates URLs based on their content. Select the types of content a

Page 157 - From Attacks

Chapter 1: Introduction8 WatchGuard Firebox System• Code, messages, and file names appear in monospace font; for example: .wgl and .idx files• In comm

Page 158 - Default Packet Handling

Chapter 16: Controlling Web Site Access224 WatchGuard Firebox System NOTEYou cannot use WebBlocker exceptions to make an internal host exempt from We

Page 159 - User Guide 143

Managing the WebBlocker ServerUser Guide 2256 To remove an item from either the Allow or the Deny list, select the address. Click the corresponding Re

Page 160 - Stopping SYN Flood attacks

Chapter 16: Controlling Web Site Access226 WatchGuard Firebox Systemprocess called WebDBdownload.bat, which appears in your WatchGuard directory under

Page 161 - Changing SYN flood settings

Automating WebBlocker Database DownloadsUser Guide 227If the message “cannot find Windows Update Files on this computer” appears, open Internet Explor

Page 162 - 146 WatchGuard Firebox System

Chapter 16: Controlling Web Site Access228 WatchGuard Firebox System

Page 163 - User Guide 147

User Guide 229CHAPTER 17 Connecting with Out-of-Band ManagementThe WatchGuard Firebox System out-of-band (OOB) management feature enables the Manageme

Page 164 - Examples

Chapter 17: Connecting with Out-of-Band Management230 WatchGuard Firebox SystemEnabling the Management StationFor a dial-up PPP connection to work bet

Page 165 - Blocking Sites

Enabling the Management StationUser Guide 231Configure the dial-up connection1 From the Desktop, click My Network Places => Network and Dial-up Con

Page 166 - Blocking a site permanently

Chapter 17: Connecting with Out-of-Band Management232 WatchGuard Firebox System2 Click Next. Select Connect to the network at my workplace. Click Next

Page 167 - User Guide 151

Establishing an OOB ConnectionUser Guide 233can pass. After the connection is established, you can use Control Center and by specifying the dial-up PP

Page 168 - Option” on page 185

User Guide 9CHAPTER 2 Service and SupportNo Internet security solution is complete without systematic updates and security intelligence. From the late

Page 169 - Blocking Ports

Chapter 17: Connecting with Out-of-Band Management234 WatchGuard Firebox System

Page 170 - 154 WatchGuard Firebox System

User Guide 227APPENDIX A Troubleshooting Firebox ConnectivityThis chapter provides four ways of connecting to your Firebox should you lose connectivit

Page 171 - Blocking a port permanently

Appendix A: Troubleshooting Firebox Connectivity228 WatchGuard Firebox System2 Connect one end of the crossover cable to the Optional Interface and th

Page 172

Method 2: The Flash Disk Management UtilityUser Guide 22910 When the Firebox Flash Disk dialog box appears, as shown in the following figure, select t

Page 173 - Sites list appears

Appendix A: Troubleshooting Firebox Connectivity230 WatchGuard Firebox Systemsame network as the configuration file, preferably the Trusted network, s

Page 174 - 158 WatchGuard Firebox System

Method 3: Using the Reset Button - Firebox Models 500, 700, 1000, 2500, 4500User Guide 231configuration passphrase. Use the address you used as the te

Page 175 - Monitoring Firebox Activity

Appendix A: Troubleshooting Firebox Connectivity232 WatchGuard Firebox System4 Open a DOS prompt, and ping the Firebox with 192.168.253.1. You should

Page 176 - 160 WatchGuard Firebox System

Method 4: Serial Dongle (Firebox II only)User Guide 2333 Take out one end of the serial cable from the Firebox to break the loop effect.4 On the Manag

Page 177 - ServiceWatch

Appendix A: Troubleshooting Firebox Connectivity234 WatchGuard Firebox System

Page 178 - Status Report

User Guide 235Index.cfg files 43.ftr files 210.idx files 192.rep files 205.wgl files 192.wts files 2091-1 Mapping dialog box 901-to-1 NAT. See NAT, 1-

Page 179 - User Guide 163

Chapter 2: Service and Support10 WatchGuard Firebox SystemThreat alerts and expert adviceAfter a new threat is identified, you’ll receive a LiveSecuri

Page 180 - 164 WatchGuard Firebox System

236 WatchGuard Firebox Systemand Firebox interfaces 150and IDS applications 147auto-block duration 152auto-blocked 150blocking with service settings 1

Page 181 - Interfaces

User Guide 237setting up 59DHCP Server dialog box 59DHCP Subnet Properties dialog box 60DHCP support on External interface 31, 36, 54dialog boxes1-1 M

Page 182 - 166 WatchGuard Firebox System

238 WatchGuard Firebox SystemExternal interfacedescribed26dynamic addressing on 54external network 26, 43Ffailover 6failover logging 174FAQs 7, 13, 77

Page 183 - HostWatch

User Guide 239viewing uptime and version 162Flash Disk management tool 229FTPand Optional network43and security policy 94FTP proxyand NAT91configuring

Page 184 - HostWatch display

240 WatchGuard Firebox Systementering 38in example network 23netmask 69of authentication servers 163of Firebox interfaces 52of log hosts 163typing 74W

Page 185 - 1 Select File => Open

User Guide 241synchronizing NT log hosts 178logging and notificationconfiguring Firebox for174customizing by blocking option 185customizing by service

Page 186 - 170 WatchGuard Firebox System

242 WatchGuard Firebox Systemdescribed 81setting for a service 88typically used for 81types of 81types supported by proxies 91NAT Setup dialog box 83,

Page 187 - Notification

User Guide 243status 37tips for creating 48permanently blocked sites 150ping command for source of deny messages 72Policy Manageras view of configurat

Page 188 - Logging policy

244 WatchGuard Firebox Systemproxy summary 213reasons for generating 203running manually 212scheduling 211sections in 206, 212service summary 213sessi

Page 189 - Notification policy

User Guide 245rsh 154setting logging and notification for 188setting static NAT for 88viewing number of connections by 161wg_ 105X Font service 154X W

Page 190 - Failover Logging

LiveSecurity® BroadcastsUser Guide 11Threat ResponseAfter a newly discovered threat is identified, the Rapid Response Team transmits an update specifi

Page 191 - Adding a log host

246 WatchGuard Firebox Systemviewing status of 69Uunconnected network addresses 150user authentication. See authenticationusers, viewing in HostWatch

Page 192 - Enabling Syslog logging

User Guide 247and Firebox System requirements 4local and global groups 135preparing Management Station for out-of-band management230running log host o

Page 193 - Synchronizing log hosts

Chapter 2: Service and Support12 WatchGuard Firebox SystemTo activate the LiveSecurity Service through the Web:1 Be sure that you have the LiveSecurit

Page 194 - 2000, or Windows XP

LiveSecurity® Self Help ToolsUser Guide 13 NOTEYou must register for LiveSecurity Service before you can access the online support services.Advanced

Page 195 - User Guide 179

User Guide iii Hudson ([email protected]).© 1995-1998 Eric Young ([email protected]) All rights reserved. This package is an SSL implementation writte

Page 196 - Viewing the WSEP application

Chapter 2: Service and Support14 WatchGuard Firebox SystemTo access the online support services:1 From your Web browser, go to http://www.watchguard.c

Page 197 - User Guide 181

Online HelpUser Guide 15called Help. In addition, a “live,” continually updated version of Online Help is available at:http://help.watchguard.com/lss/

Page 198 - 182 WatchGuard Firebox System

Chapter 2: Service and Support16 WatchGuard Firebox SystemHelp directory from the WatchGuard installation directory on the Management Station. It is i

Page 199 - 1 Click the Log Files tab

Product DocumentationUser Guide 17Product DocumentationWatchGuard products are fully documented on our Web site at:http://help.watchguard.com/document

Page 200 - Reference Guide

Chapter 2: Service and Support18 WatchGuard Firebox SystemWeb Contacthttp://www.watchguard.com/supportResponse TimeFour (4) business hours maximum tar

Page 201 - 1 Select Setup => Name

Training and CertificationUser Guide 19VPN Installation ServicesWatchGuard Remote VPN Installation Services are designed to provide you with comprehen

Page 202 - 186 WatchGuard Firebox System

Chapter 2: Service and Support20 WatchGuard Firebox System

Page 203 - User Guide 187

User Guide 21CHAPTER 3 Getting StartedThe WatchGuard Firebox System acts as a barrier between your networks and the public Internet, protecting them f

Page 204

Chapter 3: Getting Started22 WatchGuard Firebox SystemBefore installing the WatchGuard Firebox System, check the package contents to make sure you hav

Page 205

Gathering Network InformationUser Guide 23Network addressesOne good way to set up your network is to create two worksheets: the first worksheet repres

Page 206 - 190 WatchGuard Firebox System

iv WatchGuard Firebox SystemTORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIB

Page 207 - Log Files

Chapter 3: Getting Started24 WatchGuard Firebox SystemAn example of a network before the Firebox is installed appears in the following figure. In this

Page 208 - Viewing Files with LogViewer

Selecting a Firewall Configuration ModeUser Guide 25In the example, the secondary network represents the local LAN. Because the Trusted Interface is b

Page 209 - User Guide 193

Chapter 3: Getting Started26 WatchGuard Firebox SystemExternal InterfaceConnects to the external network (typically the Internet) that presents the se

Page 210 - 194 WatchGuard Firebox System

Selecting a Firewall Configuration ModeUser Guide 27Characteristics of a routed configuration:• All interfaces of the Firebox must be on different net

Page 211 - Displaying and Hiding Fields

Chapter 3: Getting Started28 WatchGuard Firebox SystemCharacteristics of a drop-in configuration:• A single network that is not subdivided into smalle

Page 212 - 196 WatchGuard Firebox System

Selecting a Firewall Configuration ModeUser Guide 29Choosing a Firebox configurationThe decision between routed and drop-in mode is based on your curr

Page 213 - Working with Log Files

Chapter 3: Getting Started30 WatchGuard Firebox SystemWhen you add a secondary network, you map an IP address from the secondary network to the IP add

Page 214 - Copying log files

Selecting a Firewall Configuration ModeUser Guide 31Dynamic IP support on the External interfaceIf you are supporting dynamic IP addressing, you must

Page 215 - Setting log encryption keys

Chapter 3: Getting Started32 WatchGuard Firebox SystemSetting Up the Management StationThe Management Station runs the Control Center software, which

Page 216 - 200 WatchGuard Firebox System

Cabling the FireboxUser Guide 33more information on the WebBlocker databasem see Chapter 16, “Controlling Web Site Access.” Software encryption level

Page 217 - User Guide 201

User Guide v1. Ownership and License. The SOFTWARE PRODUCT is protected by copyright laws and international copyright treaties, as well as other inte

Page 218 - 202 WatchGuard Firebox System

Chapter 3: Getting Started34 WatchGuard Firebox System• Plug the power cord into the Firebox power input and into a power source.

Page 219 - Network Activity

Running the QuickSetup WizardUser Guide 35Using TCP/IPRefer to Firebox Rear Panel image on the previous page.• Use the red (crossover) cable to connec

Page 220 - Creating and Editing Reports

Chapter 3: Getting Started36 WatchGuard Firebox SystemManager, use wizard.cfg as the base file to which you make changes. For more information on chan

Page 221 - Specifying a Report Time Span

Running the QuickSetup WizardUser Guide 37Enter the Firebox Default Gateway(Not applicable if using DHCP or PPPoE on the External interface.) Enter th

Page 222 - Consolidating Report Sections

Chapter 3: Getting Started38 WatchGuard Firebox SystemYou can remove the blue serial cable from the Management Station and Firebox after the QuickSetu

Page 223 - The default is 100

Deploying the Firebox into Your NetworkUser Guide 39Deploying the Firebox into Your NetworkCongratulations! You have completed the installation of you

Page 224 - 208 WatchGuard Firebox System

Chapter 3: Getting Started40 WatchGuard Firebox Systemaddition to the ones listed in the previous section, are HTTP (Internet service) and SMTP (email

Page 225 - Using Report Filters

User Guide 41CHAPTER 4 Firebox Basics This chapter describes the basic tasks you perform to set up and maintain a Firebox:• Opening a configuration fi

Page 226 - Editing a report filter

Chapter 4: Firebox Basics42 WatchGuard Firebox System NOTEThere are no user-serviceable parts within the Firebox. If a user opens a Firebox case, it

Page 227 - Scheduling a report

Opening a Configuration FileUser Guide 43Trusted networkThe network behind the firewall that must be protected from the security challenge.External ne

Page 228 - Report sections

vi WatchGuard Firebox SystemOBLIGATION, LIABILITY, RIGHT, CLAIM OR REMEDY FOR LOSS OR DAMAGE TO, OR CAUSED BY OR CONTRIBUTED TO BY, THE SOFTWARE PRODU

Page 229 - User Guide 213

Chapter 4: Firebox Basics44 WatchGuard Firebox SystemOpening a configuration from the Firebox1 Select File => Open => Firebox.The Firebox drop l

Page 230 - 214 WatchGuard Firebox System

Saving a Configuration FileUser Guide 45Saving a Configuration FileAfter making changes to a configuration file, you can either save it directly to th

Page 231 - Consolidated sections

Chapter 4: Firebox Basics46 WatchGuard Firebox System5 Enable the checkbox marked Save To Firebox. If you want to make a backup of the current image,

Page 232 - 216 WatchGuard Firebox System

Resetting Firebox PassphrasesUser Guide 477 If you are making a backup, in the Backup Image field, enter the path where you want to save the backup of

Page 233 - Controlling Web Site Access

Chapter 4: Firebox Basics48 WatchGuard Firebox System3 Use the Firebox drop list to select a Firebox or enter the Firebox IP address. Enter the config

Page 234 - 218 WatchGuard Firebox System

Setting the Time ZoneUser Guide 49Setting the Time ZoneThe Firebox time zone determines the date and time stamp that appear on logs and that are displ

Page 235 - Configuring logging

Chapter 4: Firebox Basics50 WatchGuard Firebox System

Page 236 - Activating WebBlocker

User Guide 51CHAPTER 5 Using Policy Manager to Configure Your Network Normally, you incorporate the Firebox into your network when you run the QuickSe

Page 237 - User Guide 221

Chapter 5: Using Policy Manager to Configure Your Network52 WatchGuard Firebox SystemStarting a New Configuration FileTo start a new configuration fil

Page 238 - 1 Click the WB: Schedule tab

Setting IP Addresses of Firebox InterfacesUser Guide 53Setting addresses in drop-in modeIf you are using drop-in mode, all interfaces use the same IP

Page 239 - Setting privileges

User Guide viiContents CHAPTER 1 Introduction ... 1Welcome to WatchGuard® ...

Page 240 - 224 WatchGuard Firebox System

Chapter 5: Using Policy Manager to Configure Your Network54 WatchGuard Firebox SystemSetting addresses in routed modeIf you are using routed mode, the

Page 241 - User Guide 225

Setting DHCP or PPPoE Support on the External InterfaceUser Guide 55 2 Configure the properties in the dialog box. For a description of each control,

Page 242 - Installing Scheduled Tasks

Chapter 5: Using Policy Manager to Configure Your Network56 WatchGuard Firebox SystemConfiguring Drop-in ModeIf you selected drop-in mode, you can set

Page 243 - User Guide 227

Adding Secondary NetworksUser Guide 57Adding Secondary NetworksYour configuration may require that you add secondary networks to any of the Firebox in

Page 244 - 228 WatchGuard Firebox System

Chapter 5: Using Policy Manager to Configure Your Network58 WatchGuard Firebox SystemEntering WINS and DNS Server AddressesSeveral advanced features o

Page 245 - Management

Defining a Firebox as a DHCP ServerUser Guide 59Defining a Firebox as a DHCP ServerDynamic Host Configuration Protocol (DHCP) is an Internet protocol

Page 246 - 230 WatchGuard Firebox System

Chapter 5: Using Policy Manager to Configure Your Network60 WatchGuard Firebox SystemAdding a new subnetTo make available (private) IP addresses acces

Page 247 - User Guide 231

Adding Basic Services to Policy ManagerUser Guide 61Removing a subnetYou can remove an existing subnet; however, you should be aware that doing so can

Page 248 - 232 WatchGuard Firebox System

Chapter 5: Using Policy Manager to Configure Your Network62 WatchGuard Firebox SystemIf you need more detailed information on how to add services, see

Page 249 - OOB time-out disconnects

Configuring RoutesUser Guide 633 Click the Net option.4 Enter the network IP address.5 In the Gateway text box, enter the IP address of the router.Be

Page 250 - 234 WatchGuard Firebox System

viii WatchGuard Firebox SystemActivating the LiveSecurity® Service ... 11LiveSecurity® Self Help Tools ...

Page 251 - Connectivity

Chapter 5: Using Policy Manager to Configure Your Network64 WatchGuard Firebox System

Page 252

User Guide 65CHAPTER 6 Using the WatchGuard Control CenterThe WatchGuard Control Center combines access to WatchGuard Firebox System applications and

Page 253 - User Guide 229

Chapter 6: Using the WatchGuard Control Center66 WatchGuard Firebox System5 Click OK.Control Center ComponentsControl Center consists of:• A QuickGuid

Page 254

Control Center ComponentsUser Guide 67QuickGuideThe top part of the display just below the title bar is the QuickGuide. It contains buttons to:Open th

Page 255 - Armed: Steady

Chapter 6: Using the WatchGuard Control Center68 WatchGuard Firebox SystemPause the display (appears only when connected to Firebox)Connect to Firebox

Page 256 - Armed light: Steady

Control Center ComponentsUser Guide 69Firebox and VPN tunnel statusThe section in Control Center directly below the front panel shows the current stat

Page 257 - You should get a reply

Chapter 6: Using the WatchGuard Control Center70 WatchGuard Firebox System• MAC (Media Access Control) address of each interface• Number of packets se

Page 258

Control Center ComponentsUser Guide 71• The amount of data sent and received on the tunnel in both bytes and packets.• The time at which the key expir

Page 259

Chapter 6: Using the WatchGuard Control Center72 WatchGuard Firebox System(WSEP) or Management Station. A red exclamation point next to a tunnel listi

Page 260

Working with Control CenterUser Guide 73• To issue a traceroute command to a source or destination IP address of a deny message, right-click the messa

Page 261

User Guide ixCustomizing your security policy ... 39What to expect from LiveSecurity® Service ...

Page 262

Chapter 6: Using the WatchGuard Control Center74 WatchGuard Firebox SystemOpen the WatchGuard Security Event Processor interface. (See “Opening the WS

Page 263

Working with Control CenterUser Guide 75Changing the polling rateYou can change the interval of time (in seconds) at which Control Center polls the Fi

Page 264

Chapter 6: Using the WatchGuard Control Center76 WatchGuard Firebox System4 To change the color, click the arrow next to Text Color. Click one of the

Page 265

Manipulating Traffic MonitorUser Guide 77Home PageSelect to bring up the WatchGuard home page at:http://www.watchguard.comProduct SupportSelect to bri

Page 266

Chapter 6: Using the WatchGuard Control Center78 WatchGuard Firebox SystemMaximizeDouble-click the Traffic Monitor title bar to maximize the window.

Page 267

Using Control Center ApplicationsUser Guide 79Launching Firebox MonitorsFirebox Monitors combines an extensive set of WatchGuard monitoring tools into

Page 268

Chapter 6: Using the WatchGuard Control Center80 WatchGuard Firebox SystemOpening the WSEP user interfaceThe WatchGuard Security Event Processor (WSEP

Page 269

User Guide 81CHAPTER 7 Configuring Network Address TranslationNetwork address translation (NAT) protects your network by hiding its internal structure

Page 270

Chapter 7: Configuring Network Address Translation82 WatchGuard Firebox System1-to-1 NATThe Firebox uses private and public IP ranges that you specify

Page 271

Using Simple Dynamic NATUser Guide 83 NOTEMachines making incoming requests over a VPN connection are allowed to access masqueraded hosts by their ac

Comments to this Manuals

No comments