6
ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308
Inbound Rules (Port Forwarding) . . . . . . . . . . . . . . . . . . . . . . . . . . . . .140
Order of Precedence for Rules. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .144
Configure LAN WAN Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .145
Create LAN WAN Outbound Service Rules . . . . . . . . . . . . . . . . . . . . .147
Create LAN WAN Inbound Service Rules . . . . . . . . . . . . . . . . . . . . . .149
Configure DMZ WAN Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .152
Create DMZ WAN Outbound Service Rules. . . . . . . . . . . . . . . . . . . . .154
Create DMZ WAN Inbound Service Rules . . . . . . . . . . . . . . . . . . . . . .156
Configure LAN DMZ Rules. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .158
Create LAN DMZ Outbound Service Rules . . . . . . . . . . . . . . . . . . . . .160
Create LAN DMZ Inbound Service Rules. . . . . . . . . . . . . . . . . . . . . . .162
Examples of Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .164
Examples of Inbound Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . . .164
Examples of Outbound Firewall Rules . . . . . . . . . . . . . . . . . . . . . . . . .168
Configure Other Firewall Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .170
Attack Checks. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .170
Set Limits for IPv4 Sessions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .173
Configure Multicast Pass-Through for IPv4 Traffic. . . . . . . . . . . . . . . .174
Manage the Application Level Gateway for SIP Sessions . . . . . . . . . .176
Services, Bandwidth Profiles, and QoS Profiles. . . . . . . . . . . . . . . . . . . .176
Add Customized Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .177
Create IP Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .179
Create Bandwidth Profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .181
Create Quality of Service Profiles for IPv4 Firewall Rules . . . . . . . . . .184
Quality of Service Priorities for IPv6 Firewall Rules . . . . . . . . . . . . . . .186
Configure Content Filtering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .186
Set a Schedule to Block or Allow Specific Traffic. . . . . . . . . . . . . . . . . . .189
Enable Source MAC Filtering. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .190
Set Up IP/MAC Bindings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .192
Configure Port Triggering. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .197
Configure Universal Plug and Play. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .199
Chapter 5
Virtual Private Networking Using
IPSec
and
L2TP Connections
Considerations for Dual WAN Port Systems . . . . . . . . . . . . . . . . . . . . . .202
Use the IPSec VPN Wizard for Client and Gateway Configurations . . . .203
Create an IPv4 Gateway-to-Gateway VPN Tunnel with the Wizard. . .204
Create an IPv6 Gateway-to-Gateway VPN Tunnel with the Wizard. . .208
Create an IPv4 Client-to-Gateway VPN Tunnel with the Wizard . . . . .212
Test the Connection and View Connection and Status Information. . . . .227
Test the NETGEAR VPN Client Connection . . . . . . . . . . . . . . . . . . . .227
NETGEAR VPN Client Status and Log Information . . . . . . . . . . . . . . .229
View the VPN Firewall IPSec VPN Connection Status. . . . . . . . . . . . .229
View the VPN Firewall IPSec VPN Log . . . . . . . . . . . . . . . . . . . . . . . .230
Manage IPSec VPN Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .231
Manage IKE Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .231
Manage VPN Policies. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .238