D-Link DFL-1660 manuales

Manuales del propietario y guías del usuario para Los cortafuegos de hardware D-Link DFL-1660.
Ofrecemos 1 manuales en pdf D-Link DFL-1660 para descargar gratis por tipos de documentos: Manual de usuario


Tabla de contenidos

User Manual

1

Table of Contents

4

List of Figures

9

List of Examples

10

Example 1. Example Notation

12

1.1. Features

14

NetDefendOS Documentation

16

1.2. NetDefendOS Architecture

17

1.2.3. Basic Packet Flow

18

Apply Rules

23

2.1. Managing NetDefendOS

25

Setting the Workstation IP

27

Multi-language Support

27

The Web Browser Interface

28

Interface Layout

28

2.1.4. The CLI

30

The CLI Command History

31

Tab Completion

31

Tab Completion of Data

31

Object Categories

32

Selecting Object Categories

32

Inserting into Rule Lists

33

Referencing by Name

33

Using Unique Names

33

Using Hostnames in the CLI

33

Serial Console CLI Access

34

SSH (Secure Shell) CLI Access

34

Logging on to the CLI

35

Changing the CLI Prompt

35

2.1.5. CLI Scripts

36

Note: $0 is reserved

37

Saving Scripts

38

Listing Scripts

38

2.1.6. Secure Copy

39

Note on the password prompt

40

2.1.7. The Console Boot Menu

41

WebUI HTTP port

44

WebUI HTTPS port

44

HTTPS Certificate

44

Listing Modified Objects

47

Committing IPsec Changes

48

2.2. Events and Logging

49

2.2.3.1. Logging to Memlog

50

2.2.3.3. SNMP Traps

51

2.2.4. Advanced Log Settings

52

Default: 60 (one minute)

53

2.3. RADIUS Accounting

54

STOP Message Parameters

55

2.3.9. Limitations with NAT

57

Logout at shutdown

58

Maximum Radius Contexts

58

2.4. SNMP Monitoring

59

2.4.1. SNMP Advanced Settings

60

2.5. The pcapdump Command

62

Filter Expressions

63

Downloading the Output File

63

Combining Filters

64

Compatibility with Wireshark

64

2.6. Maintenance

65

End of Life Procedures

68

Chapter 3. Fundamentals

70

3.1.3. Ethernet Addresses

72

3.1.4. Address Groups

73

3.1.6. Address Book Folders

74

3.2. Services

75

Streaming Applications

76

Specifying Port Numbers

76

3.2.3. ICMP Services

78

3.3. Interfaces

80

3.3.2. Ethernet Interfaces

81

Note: Additional switch ports

82

Note: Interface enumeration

82

Example 3.10. Enabling DHCP

83

3.3.3. VLAN

85

Example 3.11. Defining a VLAN

86

3.3.4. PPPoE

87

The PPPoE interface

88

IP address information

88

User authentication

88

Dial-on-demand

88

Unnumbered PPPoE

88

3.3.5. GRE Tunnels

89

GRE Security and Performance

90

Setting Up GRE

90

GRE and the IP Rule Set

90

An Example GRE Scenario

91

3.3.6. Interface Groups

92

3.4. ARP

94

Flushing the ARP Cache

95

Size of the ARP Cache

95

Static ARP Entries

96

Published ARP Entries

96

Multicast and Broadcast

97

Unsolicited ARP Replies

97

ARP Requests

97

Changes to the ARP Cache

97

ARP cache size

100

ARP Hash Size

100

ARP Hash Size VLAN

100

ARP IP Collision

100

3.5. The IP Rule Set

101

3.5.2. IP Rule Evaluation

103

3.5.3. IP Rule Actions

104

3.5.5. IP Rule Set Folders

105

3.6. Schedules

107

3.7. Certificates

109

Important

110

3.8. Date and Time

113

Example 3.23. Enabling DST

114

Maximum Time Adjustment

116

Synchronization Intervals

117

D-Link Time Servers

117

Time Zone

117

DST Offset

117

DST Start Date

117

3.9. DNS

119

Dynamic DNS

120

Chapter 4. Routing

122

4.2. Static Routing

123

A Typical Routing Scenario

124

4.2.2. Static Routing

127

Displaying the Routing Table

128

Initial Static Routes

129

Core Routes

129

4.2.3. Route Failover

130

Setting Up Route Failover

131

Setting the Route Metric

131

Multiple Failover Routes

131

Failover Processing

132

Re-enabling Routes

132

Route Interface Grouping

132

Gratuitous ARP Generation

133

Overview

133

Enabling Host Monitoring

133

Specifying Hosts

134

4.2.5. Proxy ARP

135

4.3. Policy-based Routing

137

4.3.4. PBR Table Selection

138

4.3.5. The Ordering parameter

138

4.4. Route Load Balancing

141

RLB Resets

144

RLB Limitations

144

An RLB Scenario

144

Example 4.6. Setting Up RLB

145

RLB with VPN

146

4.5. Dynamic Routing

147

4.5.2. OSPF

148

OSPF Areas

149

Components of OSPF

149

The Designated Router

149

Neighbors

149

Aggregates

150

Virtual Links

150

A Partitioned Backbone

151

4.5.3. Dynamic Routing Policy

152

4.6. Multicast Routing

155

Web Interface

158

Figure 4.10. Multicast Snoop

160

Figure 4.11. Multicast Proxy

160

Advanced IGMP Settings

164

Default: 1,000

166

4.7. Transparent Mode

167

How Transparent Mode Works

168

Enabling Transparent Mode

169

Transparent Mode with VLANs

170

Transparent Mode with DHCP

171

Grouping IP Addresses

172

Using NAT

172

Scenario 1

173

Scenario 2

174

Implementing BPDU Relaying

177

CAM To L3 Cache Dest Learning

177

Null Enet Sender

179

Broadcast Enet Sender

179

Multicast Enet Sender

179

Relay Spanning-tree BPDUs

179

Relay MPLS

180

4.7.5. Advanced Settings for

181

Transparent Mode

181

Chapter 5. DHCP Services

182

5.2. DHCP Servers

183

5.3. Static DHCP Assignment

185

Auto Save Policy

186

Lease Store Interval

186

5.4. DHCP Relaying

187

Max lease Time

188

Max Transactions

188

Transaction Timeout

188

Max Hops

188

Max Auto Routes

189

Auto Save Interval

189

5.5. IP Pools

190

Using Prefetched Leases

191

6.1. Access Rules

193

6.1.3. Access Rule Settings

194

6.2. ALGs

196

6.2.2. The HTTP ALG

197

6.2.3. The FTP ALG

200

The Solution

201

Filetype Checking

201

Anti-Virus Scanning

201

FTP ALG with ZoneDefense

202

6.2.4. The TFTP ALG

206

6.2.5. The SMTP ALG

207

Enhanced SMTP and Extensions

209

6.2.5.1. DNSBL SPAM Filtering

210

Tagging SPAM

212

Adding X-SPAM Information

213

Verifying the Sender Email

213

Setup Summary

214

The dnsbl CLI Command

214

6.2.6. The POP3 ALG

216

6.2.7. The SIP ALG

216

SIP Components

217

SIP Media-related Protocols

217

NetDefendOS SIP Setup

217

SIP ALG Options

217

IP Rules for Media Data

218

SIP Usage Scenarios

219

Scenario 3

223

6.2.8. The H.323 ALG

226

H.323 Protocols

227

H.323 ALG features

227

H.323 ALG Configuration

228

6.2.9. The TLS ALG

239

Enabling TLS

240

URLs Delivered by Servers

241

NetDefendOS TLS Limitations

241

6.3. Web Content Filtering

242

Wildcarding

243

6.3.4.1. Overview

245

6.3.4.2. Setting Up WCF

246

Setting Fail Mode

247

Audit Mode

248

Allowing Override

249

Category 1: Adult Content

250

Category 2: News

251

Category 3: Job Search

251

Category 4: Gambling

251

Category 5: Travel / Tourism

251

Category 6: Shopping

251

Category 7: Entertainment

252

Category 8: Chatrooms

252

Category 9: Dating Sites

252

Category 10: Game Sites

252

Category 11: Investment Sites

252

Category 12: E-Banking

253

Category 15: Politics

253

Category 16: Sports

253

Category 23: Music Downloads

255

Category 26: Educational

255

Category 27: Advertising

255

Category 28: Drugs/Alcohol

256

Category 29: Computing/IT

256

Category 31: Spam

256

Category 32: Non-Managed

256

Uploading with SCP

257

HTML Page Parameters

258

6.4. Anti-Virus Scanning

259

6.4.4. The Signature Database

260

6.4.6. Anti-Virus Options

261

Verifying the MIME Type

262

Anti-Virus with ZoneDefense

263

6.5.1. Overview

265

IDP, IPS and IDS

266

6.5.3. IDP Rules

267

Initial Packet Processing

268

Checking Dropped Packets

268

Insertion Attacks

268

6.5.5. IDP Pattern Matching

269

6.5.6. IDP Signature Groups

270

6.5.7. IDP Actions

271

IDP Blacklisting

272

IDP ZoneDefense

272

6.6.1. Overview

276

6.6.2. DoS Attack Mechanisms

276

Boink and Nestea

277

6.6.6. The WinNuke attack

277

6.6.8. TCP SYN Flood Attacks

279

6.6.9. The Jolt2 Attack

279

Blacklisting Options

280

Whitelisting

280

The CLI blacklist Command

281

7.1. NAT

283

Applying NAT Translation

285

Protocols Handled by NAT

286

7.2. NAT Pools

288

Example 7.2. Using NAT Pools

289

7.3. SAT

291

Address (1:1)

292

Addresses (M:N)

296

7.3.4. Port Translation

297

7.3.7. SAT and FwdFast Rules

298

8.1. Overview

302

8.2. Authentication Setup

304

8.2.4. External LDAP Servers

305

Server Responses

307

LDAP Authentication and PPP

308

8.2.5. Authentication Rules

309

The XAuth Agent

310

Connection Timeouts

310

Multiple Logins

310

8.2.7. HTTP Authentication

311

Setting Up IP Rules

312

Forcing Users to a Login Page

312

8.3. Customizing HTML Pages

315

The %REDIRURL% Parameter

316

Chapter 9. VPN

319

9.1.2. VPN Encryption

320

9.1.3. VPN Planning

320

9.1.4. Key Distribution

321

9.2. VPN Quick Start

323

Interface Network Gateway

324

Configuring IPsec Clients

327

9.2.7. PPTP Roaming Clients

330

9.3. IPsec Components

332

IKE Negotiation

333

IKE and IPsec Lifetimes

333

IKE Algorithm Proposals

333

IKE Parameters

334

Diffie-Hellman Groups

337

9.3.3. IKE Authentication

338

Figure 9.1. The AH protocol

339

9.3.5. NAT Traversal

340

Changing Ports

341

UDP Encapsulation

341

NAT Traversal Configuration

341

9.3.7. Pre-shared Keys

342

9.3.8. Identification Lists

344

9.4. IPsec Tunnels

346

9.4.3. Roaming Clients

347

9.4.3.4. Using Config Mode

350

IP Validation

352

VPN Tunnel Negotiation

352

Using ikesnoop

352

The Client and the Server

353

Explanation of Values

355

Explanation of Above Values

357

Step 6. Server ID Response

357

IPsec Max Rules

360

IPsec Max Tunnels

360

IKE Send Initial Contact

360

IKE Send CRLs

360

DPD Keep Time

362

DPD Expire Time

362

9.5. PPTP/L2TP

363

9.5.2. L2TP Servers

364

L2TP Before Rules

368

PPTP Before Rules

368

Max PPP Resends

368

9.5.4. PPTP/L2TP Clients

369

Figure 9.3. PPTP Client Usage

370

9.6. CA Server Access

371

CA Server Access by Clients

372

Turning Off FQDN Resolution

373

9.7. VPN Troubleshooting

374

Troubleshooting IPsec Tunnels

375

10.1. Traffic Shaping

378

Pipe Rules

379

Using a Single Pipe

382

Using Two Pipes

382

10.1.6. Precedences

383

Allocating Precedence

384

Pipe Precedences

384

The Best Effort Precedence

384

10.1.7. Guarantees

385

10.1.9. Groups

387

10.1.10. Recommendations

388

Attacks on Bandwidth

389

Watching for Leaks

389

Troubleshooting

389

10.1.12. More Pipe Examples

390

Using Several Precedences

391

Pipe Chaining

392

A VPN Scenario

392

SAT with Pipes

393

10.2. IDP Traffic Shaping

394

10.2.3. Processing Flow

395

10.2.5. A P2P Scenario

396

Viewing Pipes

397

Pipe Naming

397

Pipes are Shared

397

10.2.8. Logging

398

10.3. Threshold Rules

399

10.3.6. Exempted Connections

400

10.4. Server Load Balancing

401

SLB Algorithm Selection

402

Usage Considerations

402

10.4.6. SLB_SAT Rules

405

Example 10.3. Setting up SLB

406

Chapter 11. High Availability

409

Load-sharing

410

Hardware Duplication

410

Extending Redundancy

410

11.2. HA Mechanisms

411

HA with Anti-Virus and IDP

412

11.3. HA Setup

413

11.4. HA Issues

417

11.5. HA Advanced Settings

418

Chapter 12. ZoneDefense

420

12.2. ZoneDefense Switches

421

12.3. ZoneDefense Operation

422

12.3.5. Limitations

424

Chapter 13. Advanced Settings

427

IP Reserved Flag

430

Strip DontFragment

430

Multicast Mismatch option

430

Min Broadcast TTL option

430

13.2. TCP Level Settings

431

Allow TCP Reopen

435

13.3. ICMP Level Settings

436

13.4. State Settings

437

Log Connection Usage

438

Dynamic Max Connections

438

Max Connections

438

Other Idle Lifetime

440

13.6. Length Limit Settings

441

13.7. Fragmentation Settings

443

Failed Fragment Reassembly

444

Dropped Fragments

444

Duplicate Fragments

444

Fragmented ICMP

445

Minimum Fragment Length

445

Reassembly Timeout

445

Max Reassembly Time Limit

445

Reassembly Done Limit

445

Reassembly Illegal Limit

446

Max Concurrent

447

Max Size

447

Large Buffers

447

13.9. Miscellaneous Settings

448

Introduction

450

Subscription renewal

450

Monitoring database updates

450

Database Console Commands

450

Querying Update Status

451

Querying Server Status

451

Deleting Local Databases

451

Appendix D. The OSI Framework

460

Alphabetical Index

463





Más productos y manuales para Los cortafuegos de hardware D-Link

Modelos Tipo de documento
DFL-80 Especificaciones   D-Link DFL-80 Specifications, 147 paginas
D DFL-500 DFL-500 Manual de usuario   D-Link D DFL-500 DFL-500 User`s manual [en] , 114 paginas
DFL-2560-IPS-12 Manual de usuario   Untitled - D-Link, 38 paginas
DFL-1100 - Security Appliance Manual de usuario   CLI Manual(1004152444) - D-Link [en] , 19 paginas
DFL-160 Manual de usuario   D-Link Corporation Firewall Specification Version 1.10, 7 paginas
DFL-500 Manual de usuario   D-Link DFL-500 User's Manual, 122 paginas
DFL-260E/ANB Ficha de datos   D-Link DFL-260E, 6 paginas
DFL-160/A Ficha de datos   D-Link DFL-160, 4 paginas
SSG-520M-SH-N-TAA Ficha de datos   Juniper SSG-520M, 12 paginas
DFL-2560 Ficha de datos   D-Link DFL-2560 firewall (hardware), 7 paginas
DFL-1000 Ficha de datos   D-Link WORKGROUP FIREWALL 1LAN, 3 paginas
DFL- 860 Manual de usuario   D-Link DFL-260, 355 paginas
DFL-2560G Network Security UTM Firewall Manual de usuario   D-Link DFL-2560G Network Security UTM Firewall, 483 paginas