WatchGuard Technologies WatchGuard SOHO and SOHO | tc manual

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80

Go to page of

A good user manual

The rules should oblige the seller to give the purchaser an operating instrucion of WatchGuard Technologies WatchGuard SOHO and SOHO | tc, along with an item. The lack of an instruction or false information given to customer shall constitute grounds to apply for a complaint because of nonconformity of goods with the contract. In accordance with the law, a customer can receive an instruction in non-paper form; lately graphic and electronic forms of the manuals, as well as instructional videos have been majorly used. A necessary precondition for this is the unmistakable, legible character of an instruction.

What is an instruction?

The term originates from the Latin word „instructio”, which means organizing. Therefore, in an instruction of WatchGuard Technologies WatchGuard SOHO and SOHO | tc one could find a process description. An instruction's purpose is to teach, to ease the start-up and an item's use or performance of certain activities. An instruction is a compilation of information about an item/a service, it is a clue.

Unfortunately, only a few customers devote their time to read an instruction of WatchGuard Technologies WatchGuard SOHO and SOHO | tc. A good user manual introduces us to a number of additional functionalities of the purchased item, and also helps us to avoid the formation of most of the defects.

What should a perfect user manual contain?

First and foremost, an user manual of WatchGuard Technologies WatchGuard SOHO and SOHO | tc should contain:
- informations concerning technical data of WatchGuard Technologies WatchGuard SOHO and SOHO | tc
- name of the manufacturer and a year of construction of the WatchGuard Technologies WatchGuard SOHO and SOHO | tc item
- rules of operation, control and maintenance of the WatchGuard Technologies WatchGuard SOHO and SOHO | tc item
- safety signs and mark certificates which confirm compatibility with appropriate standards

Why don't we read the manuals?

Usually it results from the lack of time and certainty about functionalities of purchased items. Unfortunately, networking and start-up of WatchGuard Technologies WatchGuard SOHO and SOHO | tc alone are not enough. An instruction contains a number of clues concerning respective functionalities, safety rules, maintenance methods (what means should be used), eventual defects of WatchGuard Technologies WatchGuard SOHO and SOHO | tc, and methods of problem resolution. Eventually, when one still can't find the answer to his problems, he will be directed to the WatchGuard Technologies service. Lately animated manuals and instructional videos are quite popular among customers. These kinds of user manuals are effective; they assure that a customer will familiarize himself with the whole material, and won't skip complicated, technical information of WatchGuard Technologies WatchGuard SOHO and SOHO | tc.

Why one should read the manuals?

It is mostly in the manuals where we will find the details concerning construction and possibility of the WatchGuard Technologies WatchGuard SOHO and SOHO | tc item, and its use of respective accessory, as well as information concerning all the functions and facilities.

After a successful purchase of an item one should find a moment and get to know with every part of an instruction. Currently the manuals are carefully prearranged and translated, so they could be fully understood by its users. The manuals will serve as an informational aid.

Table of contents for the manual

  • Page 1

    W atchGuard SOHO and SOHO | t c W atchGuar d ® SOHO User Guide SOHO and SOHO|tc 2.3[...]

  • Page 2

    ii Regist ration and identific ation infor mation Ple ase use this area to e nter your SOHO information. The SOHO serial number is located on the bottom of t he SOHO. Y ou create a LiveSecurity user ID and password when you register y o u r W a t c h G u a r d S O H O o r S O H O | t c . T o r e g i s t e r, a f t e r y o u i n s t a l l your SOHO,[...]

  • Page 3

    User Guide 2.3 iii W atchGuard® SOHO End-User Licens e Agreement IMPORTANT - READ CAREF ULL Y B EFORE ACCESS ING WA TCH GUARD SO FT WARE This WatchG uard SOH O End-U ser Lice nse Agre ement (“EU L A ”) is a legal ag reemen t betwee n you (eithe r an ind iv id ual or a singl e en tit y) and WatchG uard T ech nologie s, Inc. (“WA TCHGUAR D”)[...]

  • Page 4

    iv 4. LIMITED WARRANTY . WA TCHGUARD make s the following limi ted warr anties for a per io d of ni n ety (90 ) days fr om the da t e you obt ai ned the SOFTWARE PRODUCT from WA TC H G UARD or an au thori ze d de al er ; (A) Media . The disks and do cument ati on wi ll be free fro m defe cts in materi als and wo r kmans hip un der norma l us e. If [...]

  • Page 5

    User Guide 2.3 v SUCH DAMAGES. THIS SHAL L BE TRUE EV EN IN THE EV ENT OF THE F AIL U RE OF AN AGREED REM EDY . 5. UNITE D STA TES GO VE RN ME NT REST RICTED RIG HTS. The enc lo sed S OFTWA RE PRODU CT and do cumenta tion ar e provide d with Restricted Right s. Use, duplica tion or di sclosure by the U.S Gov ernment or any age n cy or in s t r umen[...]

  • Page 6

    vi W atchGuard® Limited Har dwar e W arranty This WatchGuard Li m ited H ardw are War ran ty (the "Warranty " ) app li es to the enclo s ed WatchGuard h ardware pro duct (the "Hardwa re Product"). By usi ng the HARDWARE Product, you agree to the ter ms hereo f . If you do not agree to the se ter ms, please retur n this packa ge[...]

  • Page 7

    User Guide 2.3 vii NONCONFORMANCE OR DEFECT IN THE HARDWARE PRODUCT (INCL UDING, BUT N OT LIMITED TO, ANY IMPLIED WARRANTY OF MERCHANTABILITY OR FITNE SS FOR A P ART ICULAR P URPOSE, ANY IM PLIED WARRANTY ARISING FROM COU RSE OF PERFOR MAN CE , COUR S E OF DE AL ING, OR US AG E OF TRADE , ANY WARRANTY OF NONIN FRINGE MENT , A NY WARRANT Y OF U NINT[...]

  • Page 8

    viii We l c o m e Congrat ulations on purchasing the idea l solution for providi ng secure acces s to the Internet–the W atchG uard SOHO or W atchGuard SOHO|tc. Y our new security device will give you peace of mind when connecting to the Internet using a high-speed cable or DSL modem , a leased line, or ISDN. This User Guide applies to b oth the [...]

  • Page 9

    User Guide 2.3 ix Usi ng this guid e This manual assumes t hat you are fa miliar with your computer’s operating syst em. If you have questions about navigating in your computer’s envir on ment, pleas e refer to your system user manual . The following conventions are used throughout this g uide. Conve ntion Ind icati on Bold Bold Bold Bold type [...]

  • Page 10

    x[...]

  • Page 11

    User Guide 2.3 xi T able of Contents CHAP TER 1 Installation ............. .............. .............. ........... 1 Befor e you begin .......... ....................... .......... ........... 1 Performing manual installation ........ .... ..... ..... ........... 2 Physically con necting your SOHO ... .............. ........... 6 CHAP TER 2 Setti[...]

  • Page 12

    xii CHAP TER 3 Configuring Services for a SO HO ....... ..... 33 How does information travel on the inte rnet? ........ 33 Allowing incoming s ervices .............. .............. ......... 35 Blocking outgoing services .............. ....................... 40 CHAP TER 4 Configuring Virtu al Private Networking .. 43 Why cr eate a virtual private [...]

  • Page 13

    User Guide 2.3 1 CHAP TER 1 Installation Before you begin Pr e-insta llatio n c hecklis t Before instal ling your new W atchGuard SOHO please ensure that you have: • A 10BaseT Ethernet I/O network car d installed in your comp uter . • A cable or DSL modem with a 10BaseT port. • T w o Ethernet network cables with RJ45 connectors. These must no[...]

  • Page 14

    Performing ma nual instal lation 2 • An operational Internet connection. Setup of your SOHO requires ac cess to the Internet. If your connection does not work, please c ontact your Internet service provider (ISP). When your connection has been established, you ma y proceed wit h installation and setup. • If you have eit her a cable or DSL m ode[...]

  • Page 15

    User Guide 2.3 3 Performing manual instal lation Micr osoft Windows NT or 2000 1C l i c k Start => Pro grams => Command Prompt. 2 At the C: pr ompt, enter ipconfig/all . Press Enter . 3 Ent er y ou r cur ren t TCP/ IP s ett ing s in the cha rt prov id ed belo w . 4C l i c k Can cel . Micr osoft Wind ows 9 5 or 98 or M E 1C l i c k Start =>[...]

  • Page 16

    Performing ma nual instal lation 4 N OTE If you are connecting more than one computer to the pr ivate network behind the SOHO, obtain the configuration TCP/IP infor mation fo r each computer . Disable your browser’ s H TTP proxy T o configur e a W atchGuard SOHO a fter it is in stalled , you must be able to acc ess the specia l configurati on pag[...]

  • Page 17

    User Guide 2.3 5 Performing manual instal lation the browser to W eb pages locat ed in other places. Disab ling the HTTP will not prevent you from accessing your favorite W eb sites, but it will al low you to access the speci al configura tion pages that reside only on the SOHO. T o disable t he HTTP proxy in three commonly used br owsers, see the [...]

  • Page 18

    Physically connecting your SOHO 6 6C l i c k Configure at th e bo tt o m on th e Intern et Options scr een. 7 R e c o r d t h e U R L b o x i n f o r m a t i o n h e re : 8C l i c k OK to save setti ngs. Internet Explorer 5.0 1 Open Internet Explorer . 2C l i c k Tool s => Inter net Opti ons . The Internet Options screen displays. 3C l i c k t h[...]

  • Page 19

    User Guide 2.3 7 Physically connecting your SOHO 1 Complete t he “Pre-installat ion checklist” on page 1. 2 T ur n of f your computer . 3 Unplug the power fr om your cable or DSL modem. 4 Unplug the Ethernet cab le that i s c onnected f r om your ca ble or DSL modem to your computer . Connect it f rom your modem to the W AN port on the SOHO. Th[...]

  • Page 20

    Physically connecting your SOHO 8 6 T urn on the power to your cable or DSL mode m. W ait until the lights stop fla shing, indicating that the modem is ready. 7 Attach the power cor d to the SOHO and plug it into an outlet. 8 Restart your computer . 9 F or information on the factory default configur ation options, see “Default f actory settings?[...]

  • Page 21

    User Guide 2.3 9 Physically connecting your SOHO The SOHO and SOHO|tc ship with a “1 0-seat” license. In other words, the SOHO allows up to ten computers on a network behind the SOHO to access the Internet. More than ten computers can exist on the network and communicate with ea ch other , but only the first ten w hich attemtp to access the Int[...]

  • Page 22

    Physically connecting your SOHO 10 8 Attach the power cor d to the SOHO and plug it into an outlet. 9 Restart your computer .[...]

  • Page 23

    User Guide 2.3 11 CHAP TER 2 Setting Up Y our SOHO Network How does a firewall work? Fu ndamentally , a firewal l is a way of diff erentiating between, as well as pr otecting, “us” fr om “them”. On the public side of your SOHO firewall i s the entire Internet. The Internet has many resour ces that you want to be able to reach, such a s the [...]

  • Page 24

    Configuring your public network 12 N OTE The config uration ins tr uctions in this ch apter assume th at you are using Windows 95/98/ME. If this is not the case, see your operating system help or user guide to locate the equivalent options and comma nds. Config uring your publ ic network When you configure the public network, you establish how the [...]

  • Page 25

    User Guide 2.3 13 Configuring your public network of Ethernet and PPP by simulating a sta ndar d Dial-Up connection. It is popular among many ISP s because it enables them to use existing Dial- Up infrastructur e such as bill ing, authentication, and security for DSL and ca ble modems. Determining whethe r your ISP uses dy namic or static addressin[...]

  • Page 26

    Configuring your public network 14 4 If “Ob tain an IP Address Automati cally” is sel ected, your computer is configur ed for dynamic DHCP . If “Ob tain an IP Address Automati cally” is not check ed, your computer is configured for st atic addressing. The actual wor ding on the menu may diff er depending on your operating system , but all p[...]

  • Page 27

    User Guide 2.3 15 Configuring your public network Configuring t he SOHO pub lic network for dynami c a ddressin g Out of the box, the SOHO is configured to ob tain its public addr ess info rma tion auto ma tica lly , us in g dy nam ic DH CP . So if you r ISP assigns you an address automatically ( or dynamically), the SOHO itself will obtain all the[...]

  • Page 28

    Configuring your public network 16 Configuring t he SOHO publi c network for static addressing If you are ass igned a static addr ess, then you must transfer the permanent address assi gnment from your co mputer to the SOHO itself. Instead of communic ating directl y to your computer , the ISP will now communicate f irst through the SOHO. T o do th[...]

  • Page 29

    User Guide 2.3 17 Configuring your public network 7 On most platf orms, click OK until the Cont rol P anel window clos es . 8 Shut down and reboot the compute r . On the SOHO: 1 Open your W eb browser . Click Stop . At this point, the Inter net connection is not fully co nfigured, and the computer cannot loa d yo ur home page from the Internet. How[...]

  • Page 30

    Configuring your public network 18 5 Enter the T CP/IP sett ings you copi ed from the computer when you started the install process. 6C l i c k Submit . T o complete SOHO Publi c Network configurati on, see “Release and renew the IP configur ation” on page 19. Config u r ing SO HO public netw o rk for PPP o E While less common, PPP oE is anothe[...]

  • Page 31

    User Guide 2.3 19 Configuring your public network 5 Enable the che ckbox labelled Use PP P oE to obta in conf igurat ion . 6 Enter the PPP oE login name supplied by your ISP . 7 Enter the PPP oE password supplied by your ISP 8 Enter the Inacti vity T imeou t period in minutes. 9C l i c k Automatically restor e lost conne ctions. This ena bles a con[...]

  • Page 32

    Configuring your private network 20 2 At the C: pr ompt, enter winipcfg . Press Enter . The IP Conf igur ation dialo g bo x appea rs. 3 V e rify that the informati on is di splayed for "E thernet Adapter ," not for "PPP Adapter ," which would apply for a dial-up telephone modem. 4C l i c k t h e Release button. Then click the R[...]

  • Page 33

    User Guide 2.3 21 Configuring your private network N OTE T o disab le the SOHO DHCP ser ver and as sign addres ses stat ically on your privat e network, op en the SOHO Confi guration men u, click P r ivate Network, an d dis able t he checkbox l abelle d Enab l e DHCP Server . This is not recom mended for mo st SOHO users . Configure additional comp[...]

  • Page 34

    Changing the SOHO system name and password 22 Changing the S OHO system name and password P asswor ds are a b arrier between your computer and anyone trying to break in. They are the first line of defense in computer sec urity. They are, unfortunately , the mos t frequently overlook ed of all security measures . The SOHO system name and passwor d a[...]

  • Page 35

    User Guide 2.3 23 Default factory setti ngs 4C h e c k t h e Enable P assword ch eckbox. 5 Enter the system user name in the Name f ield. 6 Enter the system pa ssword in the Pa s s w o r d field. 7 Enter the system pa ssword again i n t he Retype P assword fie ld. 8C l i c k Submit . The config uration cha nge is saved to th e SOHO and a pass word [...]

  • Page 36

    Defa u lt fa ctory se tt in gs 24 • Public network settings use D HCP N OTE DHCP must be enabled for you to be able to access the SOHO device when it bo ots up . Private Network • Private network IP addr ess: 192.168.11 1 .1 . • All computers on t he private network automaticall y receive their addresses using dynamic DHCP . • T en seat lic[...]

  • Page 37

    User Guide 2.3 25 T roubleshooting installation and network configuration Vir t u a l P r iv a t e N e tw or k in g • IPSec VPN is not installed. The SOHO|tc comes with the VPN F eature K ey , however you must first enable the VPN F eature K ey in order to configure virtual pr ivate networking. The SOHO d oes not come with the VPN F eature K ey; [...]

  • Page 38

    T roubleshoo ting installation and network configuration 26 GENERAL What do th e ON and MODE lights signify on th e SOHO? When the ON light is illuminated, the SOHO has power . When the MODE light is i lluminated, the SOHO i s operation al. How do I register my SOHO? Registering your W atchGuard SOHO ensures t hat you receive all LiveSecurity ale r[...]

  • Page 39

    User Guide 2.3 27 T roubleshooting installation and network configuration 5C l i c k Reboot and wait for the SOHO to fi nish rebooting. The MODE and ON light fl ash at diffe rent times during boot, which takes a bout a minute. How do I change to a static private IP address? Before you can use a static IP address, you must have a base Private IP add[...]

  • Page 40

    T roubleshoo ting installation and network configuration 28 C AUT ION This is a m ajor security ri sk. For instr uctio ns on how to a llow any incoming services, r efer to “ Adding the Any ser vice” on page 38 How do I allow incoming IP protocols? Y ou will need the IP address of the computer that will be receiving the incoming data and the I P[...]

  • Page 41

    User Guide 2.3 29 T roubleshooting installation and network configuration 3C l i c k Add a Service and then c lick the service you want to add. F or UDP , you will need to se lect UDP on the For w ar d drop list and enter the r ange of port numbers in the port fields. F or all other services, enter the IP address of the computer that needs the in c[...]

  • Page 42

    T roubleshoo ting installation and network configuration 30 3C l i c k VPN Configuration . 4C l i c k Configuring a SOHO to SOHO IPSec VPN T unnel . 5 Download and foll ow the instructions to configure y our VPN tunnel. TECHNICAL How do I reboot my SOHO? 1 Using y our W eb browser , go to http://192.168.111 .1 . 2C l i c k System Information . 3C l[...]

  • Page 43

    User Guide 2.3 31 T roubleshooting installation and network configuration factory defaults so con nect cables in or iginal configur ation and power up again. How does the seat limitatio n on the SOHO work? The default user license on the SOHO is 10. The first 10 computers on the network behind the SOHO to attemp t access are allowed through to the [...]

  • Page 44

    T roubleshoo ting installation and network configuration 32 the LAN Link lights. They tell you if the SOHO is connected to a computer or hub through that LAN port. If the li ghts are not illuminated, the SOHO i s not connected to the computer or hub. Check to mak e sure that both sides of the cable are connected a nd that the computer or hub has po[...]

  • Page 45

    User Guide 2.3 33 CHAP TER 3 Configuring Services for a SOHO How does information travel on the inte rnet? Each pack et of information tr anspor ted over the Internet must be packaged in a s pecial way to ensure th at it is abl e to travel f rom one computer to the next. A system ca lled Internet Protocol ( IP) takes c hunks of information and wr a[...]

  • Page 46

    How does information travel on the internet? 34 address of the W atchGuard sit e is 209.19 1 .160.60 while the domai n name is www .watchguard.com. Protocol A protocol defines how a pack et is bundled up and packaged for shipment across a network. The most commonly u sed protocols are T ransmissi on Control Prot ocol (TCP) and User Datagr am Protoc[...]

  • Page 47

    User Guide 2.3 35 Allowing incoming services Allowing in co ming services By default, the sec urity stance of the SOHO is to deny unsolicited incoming packets to computers on the private network protec ted by the SOHO firewal l. Y ou can, however , selectively open your network to certain types of Internet connectiv ity. For exampl e, if you would [...]

  • Page 48

    Allowing incoming services 36 violate the compute r , they are stopped cold at the SOHO, never learning the true address of the computer . Adding a pre-configured incoming service Each service is defined b y a combination of In ternet protocols a nd port numbers to uniquely identify the connecti on type to application s and servers on the Internet.[...]

  • Page 49

    User Guide 2.3 37 Allowing incoming services 7C l i c k Submit . The config uration cha nge i s saved to the SOHO and the Show Incomi ng R ules page a ppears. The inco ming ser vice r ules ar e identified by pr otocol, port, and destinat ion on the priva te network. Creating a custom incoming service In addition to the pre- configured services prov[...]

  • Page 50

    Allowing incoming services 38 9C l i c k Submit . The config uration change i s saved to the SOHO , and the Show Inco ming R ules pa ge appears. Adding an incomi ng s ervice with another type of protocol In addition to T CP and UDP , there are sever al other types of Internet protocols. T o allow incoming service to these protocols, you must define[...]

  • Page 51

    User Guide 2.3 39 Allowing incoming services C AUT ION Unfortu nately , the hole created us ing the Any service is indiscri minate. Any type of p acket can enter th rough this ser vice and be fo r warded automatically t o the private network address you pr ovide. For security reason s, Wa tchGuard does not recommend enabling t his featur e. 1 Using[...]

  • Page 52

    Blocking outgoing services 40 4C l i c k Remove a Service . A list of existing, incoming ser vices appears. Ser vices are identified by protoc ol, port number , and destin ation ad dress. 5 Enable the checkbox next to t he services you would like to rem ov e. Y ou can dis able multip le servi ces s imultaneou sly . 6C l i c k Submit . The selected [...]

  • Page 53

    User Guide 2.3 41 Blocking outgoing services 2 Select Se rvices . The Ser vices menu appears. 3 Select Block ed Outgoing Services . The Blocked Outgoing Services Menu appears . In additio n, a list of blocked out going ser vices is displayed b eneath the menu identified b y protoc ol and port number . 4C l i c k Block TCP or UDP Service . The Block[...]

  • Page 54

    Blocking outgoing services 42 6C l i c k Submit . The config uration change i s saved to the SOHO and the Blocked Ser vice List pag e appears. Removing a blocked outgoi ng s ervice At any time, you can reopen a service now required by your network. You should do this when you seek to open access to a particular type of outgoi ng traffi c as the rem[...]

  • Page 55

    User Guide 2.3 43 CHAP TER 4 Configuring Vi rtual Private Networking This chapter describ es an optional feature of the W atchGuard SOH O: v irtua l pri vate ne twor king wit h IPSec . N OTE The foll ow ing Wa tchGuard SOHOs supp ort IPSec tunn els: •W atchGuard SOH O with VPN F eature K ey •Wa tchGuard SOHO|tc Why create a virtual private netw[...]

  • Page 56

    What you will need 44 encrypted Internet connection, a VPN connection eliminates a ny significant ri sk of data being r ead or altered by outside users a s it tra verses the Internet. What you will need 1 One W atchGuard SOHO with VPN and an IPSec-com pliant device. While you can create a SOHO to SOHO VPN, you can also create a VPN with a W atchGua[...]

  • Page 57

    User Guide 2.3 45 What you will need IP Addr ess T able (example) Item De scri ption A ssigned By Public IP Address The IP ad dress that identi fi es the SOHO to the Inter net. ISP Site A : : : : 207 .16 8 .55. 2 Site B: 68.1 30. 44.15 Public Su bnet Mask The overlay of bits th at determines whic h part of the IP addr ess i denti fies your netwo rk[...]

  • Page 58

    What you will need 46 About Feature Keys When you purchase a SOHO, the software for all extended features is provided with that instal lation regar dless of whether you have actually purchased any of those f eatures. Once you ha ve purchased an extended fe ature, its F eature key all ows you to enable its software. Y ou must enable the Fe ature K e[...]

  • Page 59

    User Guide 2.3 47 Special considerations other IPSec-compliant de vices. T o download these instruct ions, open your W eb browser to: http://www .watchguar d.com/support/inter opvpn.asp Special considerations Con side r th e f ollo win g bef ore c o nf ig ur ing y o ur W at chG uard SOHO VPN network: • Y ou can connect only two devices together: [...]

  • Page 60

    Frequently asked questions 48 Frequently asked questions Why do I need a s tatic public address? T o create a VPN connection, one SOHO must be able to find its partner device. If the a ddresses were all owed to change, the SOHO could not find its remote computer . How do I get a static publi c IP ad dress? Contact your ISP . Some systems, lik e man[...]

  • Page 61

    User Guide 2.3 49 Frequently asked questions OK, ping is not working. If you cannot ping the local network address of the remote SOHO, take the f ollowing steps to classify the pr oblem: 1 Ping the public address of the remote SOHO. F or example, at Site A, ping 68.13 0.44.1 5 (Site B). Y o u should get a reply . I f not, verify the Public N etwork[...]

  • Page 62

    Frequently asked questions 50[...]

  • Page 63

    User Guide 2.3 51 CHAP TER 5 Additional SOHO Featur es SOCKS for SOHO SOCKS is a network proxy filt er th at works with SOCKS-aware application s such as ICQ. A typical SOCKS-de pendent a pplic ation requires that sever al socke ts be opened and made avai lable to the Internet. When a SOCKS-aware application (ICQ is SOCKS-aware) regist ers with the[...]

  • Page 64

    SOCKS for SOHO 52 SOHO SOCKS implementati on The SOHO SOCKS feature has the following c haracteristic s and lim itat io ns: • SOHO supports SOCKS version 5 only. • It is a limited version of SOCKS and does not support authentication, nor does it support Domain Name System (DNS ) reso lut io n. C AUT ION Configure the particular application so t[...]

  • Page 65

    User Guide 2.3 53 SOCKS for SOHO • If you can choos e different services or versi ons of SOCKS, choose SOCKS version 5.. • Select port 1080 for the application • F or the SOCKS proxy , enter the URL or IP addres s of the SOHO private network. The default IP addr ess is 192.168.111 .0. Disabli ng SOCKS on the SOHO Once you have used a SOCKS-co[...]

  • Page 66

    SOHO logging 54 5C l i c k Submit to register the cha nge. The SOHO is enabled aga in as a Pr oxy ser ver and read y to pass SOCKS packets. SOHO logging The W atchGuard SOHO genera tes an ongoing activity log stor ed on the SOHO. This l og stores a m aximum of 150 message s. When it reaches its maximum, the oldest message is deleted. The log messag[...]

  • Page 67

    User Guide 2.3 55 Rebooting a W atchGuard SOHO 2C l i c k System Administr ation . The Sy stem Adm inistra tion m enu appe ars. 3 Select Re mote Logging . The S ecure R em ote Lo ggin g page app ears. 4 Check the box la beled Enable Remote Loggi ng . 5 Enter the IP address of the W atchGuard log server that will be your remote se cure log host. 6I [...]

  • Page 68

    Rebooting a W atchGuard SOHO 56 • Send an FTP command to the remote SOHO device. U se an FTP application to connec to the SOHO device, then enter the command: quote r ebt[...]

  • Page 69

    User Guide 2.3 57 CHAP TER 6 W atchGuar d SOHO W ebBlocker W atchGuard SOHO W ebBlocker i s an optional feature of the W atchGuard SOHO and SOHO|tc that pr ovides W eb site filtering capabilit ies. It gives you preci se contr ol over the types of W eb sites users on your private network are all owed to view . How W ebBlocker works W ebBlocker r eli[...]

  • Page 70

    How W ebBlocker works 58 site, the SOHO queries the W atchGuard da tabase and determines whether or not to block the site. The SOHO considers the following conditions in determining whether or not to bl ock the site: W eb site not in W ebBlocke r database If the site is not in the W atchGuard W ebBlocker database , the W eb browser opens the page f[...]

  • Page 71

    User Guide 2.3 59 Purchasing and enabling SOHO W ebB locker those members of your private network who should be able bypass W ebBlocker . When a site is block ed or unavailable, the user has the option of entering t he full access passwor d. Wi th the password entered, t he browser displ ays the otherwise blocked si te. After the password is enter [...]

  • Page 72

    W ebBloc ker categories 60 4 Enable the che ckbox labeled Enable W eb Blocking . This tur ns on SOHO WebBlocker . 5 Enter the full a ccess passwor d. The full access password gives selected users a password that b ypasses otherwise blocked sit es. 6 Enter the password expiration dura tion in minutes. Setting t he full access password ex piration at[...]

  • Page 73

    User Guide 2.3 61 W ebBlocker categ ories N OTE In all of the categories sites to be blocked are selected by advocacy r ather than opini on or educati onal mater ial. F or example, the Drugs/Drug Cultur e categor y blocks s ites descr i bing how to g row and use mar ijuana but does not block sites discussing t he historical use of marijuana . Alcoh[...]

  • Page 74

    W ebBloc ker categories 62 their primary pu rpose to alter the individual’s state of min d, su ch as g lue s niff ing . Th is d oes not incl ude (th at is , if selected these si tes would not be W ebBlocked under this category) curr ently illegal drugs l egally prescribed f or medicinal purposes ( such as, drugs used to tr eat glaucoma or cancer)[...]

  • Page 75

    User Guide 2.3 63 W ebBlocker categ ories Sear ch Engines Search e ngine sites such as AltaV ista, InfoSeek , Y ahoo!, and We b C r a w l e r . Sports and Le isure Pictures or text des cribing spor ti ng events, spor ts figures, or other entertainment activities . Sex Educati on Pictures or text adv ocating the proper use of contra ceptives. T opic[...]

  • Page 76

    Searching for blocked sites 64 sites hosted by muse ums such as the Guggenheim, the Louvre, or the Museum of Modern Art. P artial /Artistic Nudity Pictur es exposing the female breast or full exposure of eith er m ale o r f e mal e bu ttoc ks ex cep t wh en ex po sing genitalia which is handled under the F ull Nudity category. T opic does not inclu[...]

  • Page 77

    User Guide 2.3 65 Index A Adding i ncoming services 37, 38 Allowing incoming se rvices 35 Any ser vice, adding 38 B Blocked outgoing service, removing 42 block ed si tes in WebB locker 64 Blockin g alternative prot oco ls 41 Blockin g outgoing s er vices 40 Browse r Internet Explo rer disab ling HTTP pr oxy 5 Net sca pe 4 .0 disab ling HTTP pr oxy [...]

  • Page 78

    66 Default gateway 44 Default IP address, SOHO 24 disa bling HT TP pr oxy 5 Disabling SOCKS 52 , 53 DNS ser vice primary IP ad dress 44 secondary IP address 44 Domain name 44 E Encr yption, SOHO 47 External Network, default fa ctor y settings 24 F F actor y settings, defa ult 24 F requently a sked questio ns 45 H HTTP p roxy disabl ing 4 I ICQ, ena[...]

  • Page 79

    User Guide 2.3 67 private net work defaul t factory settings 24 Networ k address 44 Networ k Address T rans lation 35 O Outgoing s er vices blocking 40 blocking T CP 40 blocking U DP 40 P P art numb er , SOHO ii Pa s s w o r d changing 22 savin g ii P atent In formation ii Ping 48 P o rt 1080, conf iguring for SOCKS 52 P ort number , introd uction [...]

  • Page 80

    68 T ro uble shoot ing 45 checking link LED 25 connecting more than tw o o ffices 48 pingin g 48 static IP addre ss 48 U UDP adding inco ming 37 blocking o utgoing 40 Unix, setting TCP/IP 3 URL data base 57 Using th e manual ix V Virtual Private Networking introductio n 43 W Web Blocker categories 60 sear chi ng fo r blo cked s ite s 64 The Lea rni[...]