This document contains proprietary information that is protected by copyright. All
rights reserved. No part of this document may be photocopied, reproduced, or
translated into another language without prior expressed written consent from
Freedom9 Inc.
This equipment has been tested and found to comply with the regulations for a
Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are
designed to provide reasonable protection against harmful interference when the
equipment is operated in a commercial environment. This equipment generates,
uses, and can radiate radio frequency energy and, if not installed and used in
accordance with this user’s guide, may cause harmful interference to radio
communications. Operation of this equipment in a residential area is likely to cause
harmful interference, in which case the user will be required to correct the
interference at his/her own expense.
CE Mark Warning
This is a Class A product. In a domestic environment, this product may cause radio
interference, in which case the user may be required to take adequate measures.
VCCI Warning
This is a product of VCCI Class A Compliance.
UL Warning
a) Elevated Operating Ambient Temperature- If installed in a closed or multi-unit
rack assembly, the operating ambient temperature of the rack environment may be
greater than room ambient. Therefore, consideration should be given to installing
the equipment in an environment compatible with the manufacturer's maximum
rated ambient temperature (Tmra).
b) Reduced Air Flow- Installation of the equipment in a rack should be such that
the amount of air flow required for safe operation of the equipment is not
compromised.
c) Mechanical Loading- mounting of the equipment in the rack should be such that
a hazardous condition is not achieved due to uneven mechanical loading.
d) Circuit Overloading- Consideration should be given to the connection of the
equipment to the supply circuit and the effect that overloading of circuits might
have on over current protection and supply wiring. Appropriate consideration of
equipment nameplate ratings should be used when addressing this concern.
e) Reliable Earthing - Reliable earthing of rack-mounted equipment should be
maintained. Particular attention should be given to supply connections other than
direct connections to the branch circuit (e.g., use of power strips).
Figure 98, System Status............................................................................................... 99
Figure 99, System Status - Current Session.....................................................................101
Figure 100, System Status - Current Session Search.........................................................101
Figure 101, Status - Event Log.......................................................................................102
7
8
freeGuard Capture Appliance User’s Manual
1 Product Overview
Introduction
Thank you for purchasing the freeGuard Capture appliance, the Internet Content Recorder
and Email Archiver.
The freeGuard Capture appliance allows organizations to capture, track and report on
Internet activities, such as: browsed web pages, web mail, SMTP/POP3 and IMAP mail,
Instant Messaging applications (MSN, Yahoo messenger, ICQ, AIM), FTP and Telnet.
The freeGuard Capture appliance can work as a powerful Email archiver and an instant
messaging archiver.
The freeGuard Capture appliance provides valuable information about internal Internet
usage and surfing patterns to Network Administrators and employee supervisors. With the
reporting and management tools, it can quick and easy to limit the access to certain
services, and by monitoring employee activity, organizations can quickly improve their
productivity.
Feature highlights
Key features:
z Supports Sniffing and Bridge modes
z Will capture a record of HTTP, SMTP, POP3, IMAP, IM, Web mail, FTP and Telnet
contents
z Supports remote backup to maintain historical data as far back as needed
z Multi permission levels for group administrators, up to 36 groups on ICR2000, 12
groups on ICR appliance
z Instant alarm when a potential virus is detected
z Detailed and graphical reporting with user names binded to IP or MAC addresses
z Supports remote monitoring
z LAN to LAN recording for internal mail servers (such as Exchange, Groupwise*, etc)
z Use IM/P2P management to block Internet content (Bridge Mode)
z Easy-to-use Web Interface
z User based bandwidth usage analysis **
z Unlimited users
* Some mail server configurations may be required.
** Only available on certain models
9
2 Quick Installation
Appliance front panel
Interfaces and layout for the ICR appliance are listed below,
z Power Led
Green: the appliance is powered on.
z Hard Disk LED
Flashing: System is accessing data from the hard drive.
z Console Port
One DB9 console port for serial cable connection.
z WAN/LAN ports
RJ-45 ports allow you to connect to your WAN and/or LAN.
Front panel for ICR 1000
Figure 1, ICR1000 Front Panel
10
freeGuard Capture Appliance User’s Manual
Front Panel for ICR2000
Figure 2, ICR2000 Front Panel
11
System Deployment
There are two ways for ICR appliance deployment: Bridge mode or Sniffer mode.
Before you connect the ICR appliance into your live network, you may want to
configure it according to your network topology and requirement.
Please note, each ICR appliance from Freedom9 Inc has been pre-configured with IP address
and one administration account. The default IP address for the ICR appliance is 192.168.1.1
with subnet mask set to 255.255.255.0, please make necessary changes to avoid IP conflict in
your network.
Bridge Mode
Connect the WAN port on the ICR appliance to firewall or gateway in our network, and the
LAN port to the internal network via hub or switch.
Figure 3, Deployment - Bridge Mode
12
freeGuard Capture Appliance User’s Manual
Sniffer Mode
Link one of the internet recorder’s port to the mirror port of core switch or any port of the
hub.
Figure 4, Deployment - Sniffer Mode
13
Administration Login
Connecting the administration PC and ICR Appliance’s LAN port to the same Hub or Switch,
make sure the administration PC is in the same network segment as the ICR appliance.
The default IP address for ICR appliance is 192.168.1.1 with subnet mask 255.255.255.0.
Start the web browser IE or Netscape, browse to http://
Once you see the pop up login dialogue box, type in the correct User Name and
Password to login.
If it’s the first time of login, please use the default login:
z User name: admin
z Password:admin
Figure 5, Administration Login
192.168.1.1.
If you are using HTTPS to access the Web interface of ICR appliance, please click “Yes”
when you see the security alert dialogue box pops up.
Figure 6, Answer Yes to security alert for HTTPS on Web interface
14
freeGuard Capture Appliance User’s Manual
15
Setup Wizard
If it’s the first time that user log into the system, the Setup Wizard page will be displayed
automatically.
Setup Wizard will guide you through the basic configurations for the ICR appliance, please
follow the instructions on each page.
This page can also be found under System Æ Setup Wizard.
Figure 7, Setup Wizard
Setup Wizard will help you on the configurations on:
Choose display language for the Web interface
Choose the default HTML Character Encoding method
Figure 8, Choose default HTML character encoding method
For unknown character encoding from the contents captured, the “Default Character
Encoding” will be used for display and storage.
zChoose the way of user name bindings. User names can be eitherbinds to IP
address or binds to MAC Address
Figure 9, Choose name binding method
16
freeGuard Capture Appliance User’s Manual
Name Binding:
- Binding to IP addresses: When the system captures the network traffic, all the network packets
from one IP address, will be treated as the one user. This method is usually used for the
corporation with the static IP addresses implemented in their network.
- Binding to MAC addresses: When the system captures the network traffic, all the packets from the
one MAC address, will be treated as one user. This method is generally used in the network
that clients PC does not have a unique IP address, such as a network with DHCP implemented.
Setup Interface IP Address
If different IP addresses range has been used other than the default IP address of ICR
appliance, you can also setup in this page.
– Enter the valid IP for your internal network. A valid value for subnet mask,
default gateway and DNS server address are also required.
– If VLAN has been implemented in your network, you may want to enable the
VLAN for WAN port (port 1) and LAN port (port 2).
– Limitation to bandwidth of Downstream and Upstream can also be set.
Figure 10, Enter the settings in interface address
17
The management interface address must correspond to the company’s environment.
Set the IP in same subnet as LAN. If the LAN is not the segment of 192.168.1.x, for example,
the LAN is the segment of 172.16.x.x, then the interface IP needs to be changed to 172.16.x.x.
For your reference, you may configure your management address based on the subnet ranges
below:
10.0.0.0 ~ 10.255.255.255
172.16.0.0 ~ 172.31.255.255
192.168.0.0 ~ 192.168.255.255
Enter all the subnet information to be captured, and click Finish
You can have the ICR appliance to capture different subnet from your network at the same time,
also you can assign the name to the subnet, which is treated as a department or user group in ICR
appliance.
Figure 11, Enter the subnet to capture
18
freeGuard Capture Appliance User’s Manual
If the interface IP has been changed in previous steps, and the Finish button was clicked, you’ll
need to use the new IP address for your web browser, in order to log in again.
19
System Clock Synchronization
Under SystemÆDate/Time, select Enable synchronize with an internet time
Server (Please adjust the time lag depends on the time area) or click Synchronize
system clock with this client , in order to provide the current time for the system.
Figure 12, System clock synchronization
If the local area has the daylight saving time restriction, then select Enable daylight saving time
setting.
20
freeGuard Capture Appliance User’s Manual
User Groups Management
Under User List Æ Setting, you can use your own name for the user groups, the number
of supported user groups may vary depends on which model of ICR appliance you have.
Figure 13, Set the name of department or group
Under User List Æ Logged, system will display the latest user list it captures in all the
subnets that have been configured in previous steps.
Figure 14, User List / Logged
21
3 System
The ICR appliance is managed by the main system administrator. The main system
administrator can add or delete any system settings and monitor the system status.
The other group administrator have no competency to modify the system settings (the
administrator’s name is set by the system main administrator), only can monitor the
system status.
Administration tasks on the ICR appliance include system configuration changes, user
account management, client PC management, system status monitoring and firmware
updates.
Physical network interfaces work differently according to the deployment:
– Bridge mode:
WAN port and LAN port works individually
– Sniffer mode:
WAN port serves as a packet receiver, it can be connected to the mirror port of a
core switch or a network hub.
LAN port can be connected to any other port available on that core switch for
system management by the administrative PC.
Interface Overview
Once you login to the Web interface of ICR appliance, under System menu you’ll find more
sub menus as shown below,
Figure 15, Menu – System
z Admin, create/remove the administration accounts for the ICR appliance
z Interface IP, configure the IP address for the ICR appliance and the protocol to
access through Web
z Setting, email alert settings, backup/restore configuration files and other advanced
settings
z Date/Time, system clock configuration
22
freeGuard Capture Appliance User’s Manual
z Permitted IPs, list of IP addresses that can login to the Web interface
z Language, language used for page display
z Install Wizard, wizard for quick and easy configuration
z Logout, logout from the Web interface
z Software Update, upgrade the firmware of ICR appliance
E-mail Setting under System/Setting, once configured, email alerts or reports will be sent
out according to the settings.
23
Administrator Accounts
Each ICR appliance has a built-in user name for administrative purpose, it’s called “admin”
by default, and it can’t be changed nor removed. System administrator has the privileges
to add/remove a group administrator and manage its privileges of accessing the ICR
appliance through the web interface. Administrators with both read and write access may
configure the system settings and view the system status.
Administrators with merely the read access can do nothing but view the system status. It
can also give an account of the READ privileges to specific user group/department, or
change the IP address of the unit and all other related settings.
Admin Account
Under System/Admin, you can find all the existing administrative accounts for the ICR
appliance.
In order to administrate the ICR appliance, the administration account is required.
“Admin” is the default login name for system administration, and it can not be changed
nor removed.
You can add more administration accounts, and assign the necessary access rights to the
ICR appliance, it can be “READ” and/or “Write” privileges.
The default administration account for ICR appliance is “admin”, and the password is “admin”.
Read/Write Privileges
The administrative account which has the privileges to Read and Write, can change the
system configurations, view the system status, to create or remove other administration
accounts.
The administration account which has the privileges to read only, can only view the
system status, but no change anything in the configuration of ICR appliance.
Group Administrator
Group administrators with write access are not allowed to change other administrator’s
account or the settings of its own.
To create a group administrator, click the “New Group-Admin” button under the list of the
existing accounts list.
24
freeGuard Capture Appliance User’s Manual
Figure 16, Create a Group Administrator – 1
Figure 17, Create a Group Administrator – 2
25
Interface IP
Setup Interface IP Address
Setup the IP address for the network interface for ICR appliance.
Figure 18, Interface IP address setup
Ping response can be enabled on the unit, so the unit will send back the response to the
PING test from the administrative PC.
Administrator can determine whether to enable the HTTP and HTTPS access to the ICR
appliance.
26
Loading...
+ 77 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.