The technical information in this
document is proprietary to
LIGHNTING S.A. and APLIWARE
S.A. and the recipient has a personal,
non-exclusive and non-transferable
license to use this information solely
with the use of LIGHNTING S.A.
and APLIWARE S.A. products.
The information in this document is
subject to change without notice.
Revisions may be issued at any time.
Trademarks
MultiCom and Lightning are
registered trademarks of
LIGHTNING Instrumentation SA.
Stac LZS and Hi/fn are registered
trademarks of Hi/fn, Inc. All other
company, brand and product names
may be registered trademarks or
trademarks of their respective
companies and are hereby
recognized.
Revisions
This publication and the information
herein is furnished AS IS, subject to
change without notice, and should
not be construed as a commitment by
LIGHNTING S.A. and APLIWARE
S.A. Furthermore, LIGHNTING
S.A. and APLIWARE S.A. assumes
no responsibility or liability for any
errors or inaccuracies, makes no
warranty of any kind (express,
implied or statutory) with respect to
this publication, and expressly
disclaims any and all warranties of
merchantability, fitness for particular
purposes and noninfringement of
third-party right.
Warranty
NO WARRANTIES ARE
EXTENDED BY THIS
DOCUMENT. The only product
warranties made by LIGHNTING
S.A. and APLIWARE S.A., if any,
are set forth in the agreed terms and
MultiCom Firewall User’s Manual v
Page 6
Chapter Copyright, Warranty, Liability
conditions for the purchase of
LIGHNTING S.A. and APLIWARE
S.A. products. LIGHNTING S.A.
and APLIWARE S.A. declaims
liability for any and all direct and
indirect damages that may result
from publication or use of this
document and/or its contents.
LIGHNTING S.A. and APLIWARE
S.A. warrants all hardware products
of its manufacture to be free from
defects in material and workmanship
for 12 months from date of delivery.
Upon prompt notification by the
purchaser, LIGHNTING S.A. and
APLIWARE S.A. will correct,
within the warranty period, any
defects in equipment of its
manufacture either by repair at its
factory or by supply of replacement
parts to the purchaser.
LIGHNTING S.A. and APLIWARE
S.A. must decide to its own
satisfaction that the equipment is
defective and has not developed
malfunctions as a result of misuse,
modification, or abnormal conditions
of operation. Damages due to over
voltage (e.g. lightning strokes) or
wrong cabling on any interface are
expressly excluded from the
warranty. Opening the products also
voids the warranty. LIGHNTING
S.A. and APLIWARE S.A. assumes
no liability for consequential
damages, and its liability shall in no
case exceed the original purchase
price of the equipment.
The warranties set forth above are
the sole warranties applicable to
LIGHNTING S.A. and APLIWARE
S.A. products. THE IMPLIED
WARRANTY OF
MERCHANTABILITY AND ALL
OTHER WARRANTIES, EXPRESS
OR IMPLIED, ARE EXCLUDED.
Limitation of Liability
UNDER NO CIRCUMSTANCES,
INCLUDING NEGLIGENCE,
SHALL LIGHNTING S.A. AND
APLIWARE S.A. BE LIABLE FOR
LOSS OF USE, INTERRUPTION
OF BUSINESS, OR ANY
INDIRECT, SPECIAL,
INCIDENTAL, OR
CONSEQUENTIAL DAMAGES
OF ANY KIND (INCLUDING
LOST PROFITS) REGARDLESS
OF THE FORM OF ACTION
WHETHER IN CONTRACT, TORT
(INCLUDING NEGLIGENCE),
STRICT PRODUCT LIABILITY
OR OTHERWISE, EVEN IF
LIGHNTING S.A. AND
APLIWARE S.A. HAS BEEN
ADVISED OF THE POSSIBILITY
OF SUCH DAMAGES.
In no event shall LIGHNTING S.A.
and APLIWARE S.A. be liable for
costs of procurement of substitute
goods. The potential liability of
LIGHNTING S.A. and APLIWARE
S.A. arising out of this product is in
vi MultiCom Firewall User’s Manual
Page 7
Software and Documentation License
any case limited to the purchase
price paid to LIGHNTING S.A. and
APLIWARE S.A. for its products.
Software and Documentation
License
The software and documentation
included in or with products of
LIGHNTING S.A. and APLIWARE
S.A. is subject to following licence.
Third-Party Software. A part of the
software used within the MultiCom
Ethernet series can be freely
distributed under the terms of the
GNU Public License and BSD
copyright. However, some
applications remain the property of
their owners, and require their
permission to redistribute. For a
complete listing of the software used
within the MultiCom Firewall, and
the terms under which it can be
distributed, refer to the LIGHTNING
Web site at http://www.lightning.ch/
and to the Appendix on Additional
Licenses and Copyrights.
Shareware and Freeware Software.
Your MultiCom Companion CD
contains shareware, freeware and
other 3rd Party software not
developed by LIGHNTING S.A. and
APLIWARE S.A. Such software is
neither warranteed or supported by
LIGHNTING S.A. and APLIWARE
S.A. and is not necessary to use
LIGHNTING S.A. and APLIWARE
S.A. products. If you wish to use it
be sure to check that it meets your
company's standards for reliability,
security and useability. Please check
with the developer of the software
for any necessary information about
the use or capabilities of such
included software.
While all included software on this
CD has been virus checked and
tested LIGHNTING S.A. and
APLIWARE S.A. does not provide
any guarantees concerning these
products. Be sure to use any virus
protection that is required by your
company before using the included
software. If you go to a website of
these software developers be sure to
virus check any software that you
download from them before using it
as well.
LIGHNTING S.A. and APLIWARE
S.A. cannot accept responsibility for
any disruption, damage and/or loss to
your data or computer system that
may occur while using these
programs. If you are unsure about
what you are doing check with your
network administrator before
installing any software.
License. The software, on any media,
including disk, read-only memory,
and flash memory and the products
related documentation are licensed to
you by LIGHNTING S.A. and
APLIWARE S.A.. You own the
media on which the LIGHNTING
S.A. and APLIWARE S.A. software
is recorded, but LIGHNTING S.A.
and APLIWARE S.A. and/or
MultiCom Firewall User’s Manual vii
Page 8
Chapter Copyright, Warranty, Liability
LIGHNTING S.A. and APLIWARE
S.A.'s Licensor(s) retain title to the
LIGHNTING S.A. and APLIWARE
S.A. software and related
documentation. The license allows
you to use the LIGHNTING S.A.
and APLIWARE S.A. software on a
single LIGHNTING S.A. and
APLIWARE S.A. hardware product.
In the case of software on disk, you
are allowed to make one copy of
LIGHNTING S.A. and APLIWARE
S.A. software in machine-readable
form for backup purposes only. You
must reproduce on such copy the
LIGHNTING S.A. and APLIWARE
S.A. copyright notice and any other
proprietary legends that were on the
original copy of the disk containing
LIGHNTING S.A. and APLIWARE
S.A. software. You may also transfer
all your license rights in the
LIGHNTING S.A. and APLIWARE
S.A. software, together with the
associated hardware, the backup
copy, the related documentation, and
a copy of this license to another
party, provided the other party reads
and agrees to accept the terms and
conditions of this license.
Restrictions. The LIGHNTING S.A.
and APLIWARE S.A. software
contains copyrighted materials, trade
secrets, and other proprietary
materials and in order to protect
them you may not decompile,
reverse engineer, disassemble, or
otherwise reduce the LIGHNTING
S.A. and APLIWARE S.A. software
to a human-perceivable form. You
may not modify, network, rent, lease,
loan, distribute, or create derivative
works based upon the LIGHNTING
S.A. and APLIWARE S.A. software
in whole or in part. You may not
electronically transmit the
LIGHNTING S.A. and APLIWARE
S.A. software from one computer to
another or over a network.
Termination. This license is effective
until terminated. You may terminate
this license at any time by destroying
the LIGHNTING S.A. and
APLIWARE S.A. software, the
related hardware, related
documentation and all copies
thereof. The license will terminate
immediately without notice from
LIGHNTING S.A. and APLIWARE
S.A. if you fail to comply with any
provision of this license. Upon
termination you must destroy the
LIGHNTING S.A. and APLIWARE
S.A. software, the related hardware,
related documentation and all copies
thereof.
Limited Warranty on Media.
LIGHNTING S.A. and APLIWARE
S.A. warrants the media on which
the software is recorded as its
hardware materials, and limits the
liability as set for the hardware
material.
Disclaimer of warranty on
LIGHNTING S.A. and APLIWARE
S.A. software. You expressly
acknowledge and agree that use of
viii MultiCom Firewall User’s Manual
Page 9
Software and Documentation License
the LIGHNTING S.A. and
APLIWARE S.A. software is at your
sole risk. The LIGHNTING S.A. and
APLIWARE S.A. software and
related documentation are provided
"AS IS" and without warranty of any
kind and LIGHNTING S.A. and
APLIWARE S.A. EXPRESSLY
DISCLAIM ALL WARRANTIES,
EXPRESS OR IMPLIED,
INCLUDING, BUT NOT LIMITED
TO, THE IMPLIED WARRANTIES
OF MERCHANTABILITY AND
FITNESS FOR A PARTICULAR
PURPOSE. LIGHNTING S.A. AND
APLIWARE S.A. DOES NOT
WARRANT THAT THE
FUNCTIONS CONTAINED IN
THE LIGHNTING S.A. AND
APLIWARE S.A. SOFTWARE
WILL MEET YOUR
REQUIREMENTS, OR THAT THE
OPERATION OF THE
LIGHNTING S.A. AND
APLIWARE S.A. SOFTWARE
WILL BE UNINTERRUPTED OR
ERROR-FREE, OR THAT
DEFECTS IN THE LIGHNTING
S.A. AND APLIWARE S.A.
SOFTWARE WILL BE
CORRECTED. FURTHERMORE,
LIGHNTING S.A. AND
APLIWARE S.A. DOES NOT
WARRANT OR MAKE ANY
REPRESENTATIONS
REGARDING THE USE OR THE
RESULTS OF THE USE OF THE
LIGHNTING S.A. AND
APLIWARE S.A. SOFTWARE OR
RELATED DOCUMENTATION IN
THE TERMS OF THEIR
CORRECTNESS, ACCURACY,
RELIABILITY, OR OTHERWISE.
NO ORAL OR WRITTEN
INFORMATION OR ADVICE
GIVEN BY LIGHNTING S.A. AND
APLIWARE S.A. OR A
LIGHNTING S.A. AND
APLIWARE S.A.-AUTHORIZED
REPRESENTATIVE SHALL
CREATE A WARRANTY OR IN
ANY WAY INCREASE THE
SCOPE OF THIS WARRANTY.
SHOULD THE LIGHNTING S.A.
AND APLIWARE S.A.
SOFTWARE PROVE DEFECTIVE,
YOU (AND NOT LIGHNTING
S.A. AND APLIWARE S.A. OR A
LIGHNTING S.A. AND
APLIWARE S.A. AUTHORIZED
REPRESENTATIVE) ASSUME
THE ENTIRE COST OF ALL
NECESSARY SERVICING,
REPAIR, OR CORRECTION. Some
jurisdictions do not allow the
exclusion of implied warranties, so
the above exclusion may not apply to
you.
Limitation of Liability. Conforming
to the general limitation of liability.
Controlling Law and Severability.
This license shall be governed by
and construded in accordance with
the laws of Switzerland and Canton
de Vaud, as applied to agreements
entered into and to be performed
entirely between Canton de Vaud
residents. If for any reason a court of
competent jurisdiction finds any
MultiCom Firewall User’s Manual ix
Page 10
Chapter Copyright, Warranty, Liability
provision of this license, or portions
thereof, to be unenforceable, that
provision of the license shall be
enforced to the maximum extent
permissible so as to effect the intent
of the parties, and the remainder of
this license shall continue in full
force and effect.
Complete agreement. The license
constitutes the entire agreement
between the parties with respect to
the use of the LIGHNTING S.A. and
APLIWARE S.A. software and
related documentation, and
supersedes all prior or
contemporaneous understandings or
agreements, written or oral,
regarding such subject matter. No
amendment to or modification of the
License will be binding unless in
writing and signed by a duly
authorized representative of
LIGHNTING S.A. and APLIWARE
S.A..
with all such regulations and
acknowledges that it has the
responsibility to obtain licenses to
export, re-export, or import Software
and Hardware.
Export
Some versions and options of
LIGHNTING S.A. and APLIWARE
S.A.'s Software and Hardware,
including technical data, may be
subject to Swiss, E.U., U.S.
(including the U.S. Export
Administration Act) or other
countries export control laws, and
their associated regulations, and may
be subject to export or import
regulations in other countries.
Customer agrees to comply strictly
Congratulations on the purchase of your MultiCom Firewall. Your firewall ha s
been designed to offer security and high performance networking management,
all through an easy to use interface.
Whether you are connecting a single computer from home or managing a
company network you will find that the MultiCom Firewalls can help. You now
have access to many networking possibilities, for instance you can secure your
data, share your Internet connection with multiple computers and filter or receive
notifications of potential network attacks.
Chapter 1
For the latest release notes, documentation, firmware and software check the
Lightning website at http://www.lightning.ch/support.
MultiCom Firewall Features
Security
•Dual firewalls, using Stateful Packet Inspection (SPI) Filtering and/ or a NAT
based Firewall on each interface to protect against External Intrusions, Denial
MultiCom Firewall User’s Manual 17
Page 18
Chapter 1 Preface
of Service (DoS), Port Scanning, Spoofing Attacks and more
•URL Filtering to block or drop web connections based on URL or keywords.
•Intrusion Detection System (IDS) using SPI filtering & syslog
•Real time alerts and statistics using Syslog, SNMPv2, web-based Event
Monitor, email and more
•Up to 10 separate user accounts with passwords and access rights
•DMZ interface support giving extra security for network servers (Ethernet III
and Enterprise Ethernet only)
Internet Access
•Connect multiple computers and ethernet devices to the Internet using
Internet Sharing using Network Address Translation (NAT)
•Easy Setup & Easy Firewall wizards via the web interface or the
multi-platform Configurator software
•DNS Cache for faster Internet response
•Dynamic DNS supporting 9 different services for finding your computer even
if the IP address changes
•Multimedia (H.323, IRC, ICQ) and PPTP client pass through support with
NAT
•DHCP server (up to 1,000 clients) for automatic IP configuration to clients or
DHCP Relay on any Interface
•Ethernet parameter editing for MTU, MAC address, duplex and speed
•Integrated PPPoE client, for single or multiple concentrators (for ISP backup
purposes)
•Network traffic round-robin load sharing using NAT
•Virtual IP address support for one or more IP addresses using ARP Proxy and
Network Address Translation
•IP Port Redirection with NPAT Network Port & Address Translation
•Static and dynamic routing using RIP (V1 and v2)
Management
•Configurator software for configuring Virtual Private Networks, validating
configurations, managing all features and firewall rules. Available for
18 MultiCom Firewall User’s Manual
Page 19
MultiCom Firewall Features
Windows, Macintosh, and Linux. With secured remote access.
•Monitor software to manage status and restart services like PPP, IPSec,
VRRP, DHCP. Available for Windows, Macintosh, and Linux. With
secured remote access.
•Configuration scheduling for up to 6 configuration files based on day, hour or
minute.
•Telnet, console & ssh Command Line Interface (CLI) with powerful network
tools like ping, traceroute name server lookup. Ideal for scriptable
configuration changes using 3rd party software like CatTools for time based
and centralized management
•Quick Restore Button with LED feedback to load boot config, emergency
config (config 1), or the factory default configuration. Additional memory is
available on each device to store up to 6 different configurations.
•Centralized time management using the Network Time Protocol
•Transfer configurations to and from the device using the File Transfer
Protocol (FTP)
•Built-in Domain Name Server (DNS) to name local computers
•Multilingual with English, French and German built-in
•Upgradable flash memory
Software Add-on Options
•IPSec based Virtual Private Network (VPN) supporting Gateway, client and
point-to-point modes. Preshared, Manual and PKI x.509 Keys for central
management and 3rd party vendor compatibility. Support for multiple
world-class encryption ciphers such as AES (Rijndael), CAST 128, Twofish,
Blowfish, 3DES and more. Includes Dead Peer Detection (DPD), NAT
Traversal, DHCP over IPSec, Traffic filtering, Domain Name endpoints,
Connection testing support.
•SSH Port Forwarding VPN Gateway with public key or user based access,
using SSH v1 and v2. With unique authentication for up to 10 users.
•High Availability using the VRRP protocol with authentication
•Network Intrusion Detection System (NIDS) using SNORT for Enterprise
devices
•Network Monitoring Service for monitoring local and remote TCP servers.
•Certificate Manager software for generating, managing and deploying PKI
x.509 keys, certificates and certification authorities. Available for Windows,
MultiCom Firewall User’s Manual 19
Page 20
Chapter 1 Preface
Macintosh, and Linux.
•VPN Client software available
Network Hardware
•10/100 Mbit/s multi-interface Switch for high-speed communication within
your network (Ethernet III & Enterprise Ethernet only)
•10/100 Mbit/s autosensing LAN interface for your Local network
•DSL annex A integrated modem (Enterprise DSL only)
•802.11b WiFi with LAN Bridge (Enterprise WiFi only)
Options
Certain functionalities, such as IPSec VPN, SSH Port Forwarding VPN, High
Availability or Network Monitoring are not immediately available in the standard
firmware releases. These functions are called Options and need to be purchased
and activated to be useable.
Activation of Options currently requires the user to install a unique key file
(versions before 3.4 required a special firmware) containing the purchased
options and then reboot the MultiCom Firewall. Currently the options are
available IPSec VPN 2 tunnels, IPSec VPN 20 tunnels and unlimited IPSec VPN
tunnel options.
•IPSec VPN 2 Tunnels
•IPSec VPN 20 Tunnels
•IPSec VPN unlimited Tunnels
•SSH Port Forwarding VPN 10 Users
•High Availability (VRRP)
•Network Monitoring
Below are the requirements of this process:
•The option key or firmware is only valid on the machine for which it was
purchased.
•For machines using a Lightning Linux older than 3.2, you must either first
upgrade to the standard OS 3.2 and then apply the firmware with the option
or upgrade to at least OS 3.4 and apply the option key.
20 MultiCom Firewall User’s Manual
Page 21
IPSec VPN Option
Contact your distributor if you are interested in purchasing this option.
IPSec VPN Option
All existing MultiCom Firewalls offer Virtual Private Networks (VPN) using the
IPSec protocol when the IPSec option is purchased. This is a powerful Secure
Remote Access add-on to the standard MultiCom Firewall functionality. Using
IPSec the MultiCom Firewall becomes a security gateway, securing data transfers
between other IPSec capable devices or computers running IPSec software.
Simple IPSec configuration can be made using the web based wizard. Advanced
IPSec configurations require the use of the Configurator software (included on
the MultiCom Companion CDROM) in the Advanced Configuration mode.
Refer to the Lightning-Linux Reference Manual for information on configuring
this feature.
Optionally, the Certificate Manager can be purchased to manage and deploy PKI
Digital Authentication Certificates for more complex IPSec configurations.
For more information or to purchasing this option contact your distributor.
SSH VPN Option
All existing MultiCom Firewalls offer Virtual Private Networks (VPN) using the
SSH Port Forwarding protocol when the SSH option is purchased. This is a
powerful Secure Remote Access add-on for the standard MultiCom Firewall
functionality. Using SSH Port Forwarding the MultiCom Firewall also becomes
a security gateway, securing data transfers between remote SSH software on a
Macintosh, Windows, Linux, PDA or other computing platform.
All SSH Port Forwarding configurations require the use of the Configurator
software (included on the MultiCom Companion CDROM) in the Advanced
Configuration mode. Refer to the Lightning-Linux Reference Manual for
information on configuring this feature.
For more information or to purchasing this option contact your distributor.
High Availability Option
All existing MultiCom Firewalls support High Availability using the Virtual
Router Redundancy Protocol (VRRP) when the VRRP option is purchased.
VRRP allows 1 or more additional MultiCom Firewalls to be configured into a
MultiCom Firewall User’s Manual 21
Page 22
Chapter 1 Preface
redundant fail-safe backup in case of failure on the Master firewall. This High
Availability does not require dynamic routing or router discovery protocols to be
installed on local networking devices.
All VRRP configurations require the use of the Configurator software (included
on the MultiCom Companion CDROM) in the Advanced Configuration mode.
Refer to the Lightning-Linux Reference Manual for information on configuring
this feature.
For more information or to purchasing this option contact your distributor.
Network Monitoring Option
All existing MultiCom Firewalls support Network Monitoring when the Network
Monitoring Service (NMS) option is purchased. NMS allows the MultiCom
Firewall to maintain a list of TCP ports on local and re mote netwo rks and regul ar
intervals check if the connection is available and measure the delay time. The
results of these status checks are written to the internal log, optionally can be
emailed to selected email accounts, and is visible from the web interface and the
Monitor software.
All NMS configurations require the use of the Configurator software (included on
the MultiCom Companion CDROM) in the Advanced Configuration mode.
Refer to the Lightning-Linux Reference Manual for information on configuring
this feature.
For more information or to purchasing this option contact your distributor.
About This Manual
Putting together a solution to meet your networking needs is not always an easy
task. Whether you are a seasoned professional or a new home-user you will find
there are many possibilities you may have not have considered. This manual is
designed to get your firewall up and started as soon as possible. To better
understand the more advanced features of your firewall please refer to the
Lightning-Linux Reference Manual.
While every attempt has been made to explain the features and configuration
steps of your new firewall you should have some basic experience in the
following areas.
•familiarity with general computer usage
22 MultiCom Firewall User’s Manual
Page 23
Conventions
•understanding of basic networking (if not check out the technology overview
sections at the end of this manual first.)
•connecting to a network (you still need to have a working connection to
either the Internet or a local network: check with your local administrator or
Internet Service Provider for assistance in getting that connection up and
running.)
Working with the Internet requires knowing many technical acronyms. Please
refer to the “Glossary” on page 147 for short descriptions of many of these
buzzwords and technologies.
Conventions
The following tables describe the typefaces and symbols used in this manual.
Table 1: Typography
TypographyMeaning
Computer Outputis data generally displayed or presented by the
User Inputis text or commands that you type, contrasted with
Buttonis the text on a button, used to describe what
Menuindicates the name of a menu or tab that takes you
MENU > BUTTONdescribes which buttons to click and the order to
computer
onscreen computer output
button to click
to specific options
click on them for a specific action to occur: for
example
FILE > PRINT says to click on the menu
named “File” and then the Menu item named
“Print”.
Table 2: Symbols
SymbolMeaning
NOTE - Notes describe particular features which require
attention
CAUTION -Cautions explains conditions that may cause
TIP -Tips offer useful suggestions
unwanted results
MultiCom Firewall User’s Manual 23
Page 24
Chapter 1 Preface
Packaging Contents
•MultiCom Firewall
•Power supply
•Ethernet Networking cables (x1 blue crossed cable, x1 straight cable)
•Console cable (for the Ethernet III and SpeedSurf only)
•MultiCom Companion CD (including User's Manual, Lightning-Linux
Reference Manual, configuration software and miscellaneous shareware and
freeware)
•Quick Install Guide
If The Product Is Received
Damaged
Forward an immediate request to the delivering carrier to perform an inspection
and prepare a damage report. Save the container and packing material until
contents are verified.
Report the nature and extent of the damage to Customer Support so that action
can be initiated to repair or replace damaged items, or instructions issued for
returning items.
The responsibility of the manufacturer ends at the delivery to the first carrier.
ALL CLAIMS for loss, damage, or nondelivery must be made against the
delivering carrier WITHIN 8 DAYS OF RECEIPT of shipment.
To Return The Product
An Return Material Authorization (RMA) Number from Customer Support is
required before returning any item(s). Report the fault or deficiency along with
the model, type, and serial number of the item(s) to Customer Support. Upon
receipt of this information, Customer Support will provide service instructions or
shipping information. Clearly mark the RMA number, your address, and
shipping address on the original packaging, which has to be used for ship ments.
24 MultiCom Firewall User’s Manual
Page 25
To Return The Product
Products returned without an RMA number will be returned to the sender at the
sender’s expense. Improperly packaged products will not be covered under
warranty. For warranty repairs, please include a copy of a dated proof of
purchase.
MultiCom Firewall User’s Manual 25
Page 26
Chapter 1 Preface
26 MultiCom Firewall User’s Manual
Page 27
Introducing The
MultiCom
Firewalls
MultiCom Firewalls
MultiCom Firewalls are available in different hardware configurations to best
meet your needs. Each firewall uses Lightning-Linux to provide additional
features and options to the hardware. In all cases you can configure your firewall
either by using your Internet browser (for Easy Setup, Easy Firewall or Interface
configuration) or by using the Configurator software found on your MultiCom
Companion CD.
Chapter 2
MultiCom Firewall User’s Manual 27
Page 28
Chapter 2 Introducing The MultiCom Firewalls
Introducing the Ethernet II
Back Panel
The back panel of your Ethernet II firewall is where all of your cables will
connect to.
ConfigPush this button and let go when th e fron t LEDs are:
ORANGE to load the last saved boot configuration
GREEN to load the configuration in memory position 1
RED to load the factory default configuration.
PowerUse the Power interface to connect to the included MultiCom
power adapter.
LANUse the LAN (Local Area Network) interface to connect to
your network devices (workstations, printer servers, network
camera) or hub.
WANUse the WAN (Wide Area Network) interface to connect to
your Broadband modem (xDSL, Cable or Wireless Modem).
Kensington
Lock Slot
This connection is to physically secure your Ethernet firewall
with a Kensington Lock. It is the oblong whole on the right
of the back panel.
28 MultiCom Firewall User’s Manual
Page 29
Front Panel of the Ethernet II
Front Panel of the Ethernet II
The Front panel of your Ethernet II firewall is where LED lights will inform you
of the activity occurring in your firewall.
LANSteady GREEN when link is up
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
WANSteady GREEN when link is up
First
LED
left of
Power
LED
PowerSteady GREEN when power is on
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
GREEN when SecureWall is ON
ORANGE when filtering is ON and SecureWall is OFF
RED when SecureWall and Filtering are OFF
MultiCom Firewall User’s Manual 29
Page 30
Chapter 2 Introducing The MultiCom Firewalls
Introducing the Ethernet III
Back Panel
The back panel of your Ethernet III firewall is where all of your cables will
connect to.
ConfigPush this button and let go when th e fron t LEDs are:
ORANGE to load the last saved boot configuration
GREEN to load the configuration in memory position 1
RED to load the factory default configuration.
PowerUse the Power interface to connect to the included MultiCom
LAN 1-4Use the 4 LAN (Local Area Network) interfaces to connect
DMZUse the DMZ (Demilitarized Zone) interface to connect
WANUse the WAN (Wide Area Network) interface to connect to
ConsoleUse the console port with the included cable to connect to the
Kensington
Lock Slot
power adapter.
to your network devices (workstations, printer servers,
network camera).
public servers (www, ftp...). This port allows customized
security for these servers.
your Broadband modem (xDSL, Cable or Wireless Modem).
serial port of your workstation. This allows you direct access
to the CLI (Command Line Interface) an can be used to
configure the firewall.
This connection is to physically secure your Ethernet firewall
with a Kensington Lock. It is the oblong whole on the right
of the back panel.
30 MultiCom Firewall User’s Manual
Page 31
Front Panel of the Ethernet III
Front Panel of the Ethernet III
The Front panel of your Ethernet III firewall is where LED lights will inform you
of the activity occurring in your firewall.
WANSteady GREEN when link is up
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
DMZSteady GREEN when link is up
LAN 1-4Steady GREEN when link is up
SecurityGREEN when SecureWall is ON
PowerSteady GREEN when power is on
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
ORANGE when filtering is ON and SecureWall is OFF
RED when SecureWall and Filtering are OFF
MultiCom Firewall User’s Manual 31
Page 32
Chapter 2 Introducing The MultiCom Firewalls
Introducing the MultiCom SpeedSurf
Back Panel
The back panel of your MultiCom SpeedSurf is where all of your cables will
connect to.
ConfigPush this button and let go when th e fron t LEDs are:
PowerUse the Power interface to connect to the included MultiCom
ConsoleUse the console port with the included cable to connect to the
LANUse the LAN (Local Area Network) interface to connect to
WANUse the WAN (Wide Area Network) interface to connect to
Kensington
Lock Slot
ORANGE to load the last saved boot configuration
GREEN to load the configuration in memory position 1
RED to load the factory default configuration.
power adapter.
serial port of your workstation. This allows you direct access
to the CLI (Command Line Interface) an can be used to
configure the firewall.
your network devices (workstations, printer servers, network
camera) or hub.
your Broadband modem (xDSL, Cable or Wireless Modem).
This connection is to physically secure your Ethernet firewall
with a Kensington Lock. It is the oblong hole on the right of
the back panel.
32 MultiCom Firewall User’s Manual
Page 33
Front Panel of the MultiCom SpeedSurf
Front Panel of the MultiCom SpeedSurf
The Front panel of your MultiCom SpeedSurf is where LED lights will inform
you of the activity occurring in your firewall.
LANSteady GREEN when link is up
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
WANSteady GREEN when link is up
SecurityGREEN when SecureWall is ON
PowerSteady GREEN when power is on
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
ORANGE when filtering is ON and SecureWall is OFF
RED when SecureWall and Filtering are OFF
MultiCom Firewall User’s Manual 33
Page 34
Chapter 2 Introducing The MultiCom Firewalls
Introducing the Enterprise Ethernet
Back Panel
The back panel of your Enterprise Ethernet firewall is where all of your cables
will connect to.
ConfigPush this button and let go when th e fron t LEDs are:
PowerUse the Power interface to connect to the included MultiCom
LAN 1-4Use the 4 LAN (Local Area Network) interfaces to connect
DMZUse the DMZ (Demilitarized Zone) interface to connect
WANUse the WAN (Wide Area Network) interface to connect to
ConsoleUse the console port with the included cable to connect to the
ORANGE to load the last saved boot configuration
GREEN to load the configuration in memory position 1
RED to load the factory default configuration.
power adapter.
to your network devices (workstations, printer servers,
network camera).
public servers (www, ftp...). This port allows customized
security for these servers.
your Broadband modem (xDSL, Cable or Wireless Modem).
serial port of your workstation. This allows you direct access
to the CLI (Command Line Interface) and can be used to
configure the firewall.
34 MultiCom Firewall User’s Manual
Page 35
Front Panel of the Enterprise Ethernet
Front Panel of the Enterprise Ethernet
The Front panel of your Enterprise Ethernet firewall is where LED lights will
inform you of the activity occurring in your firewall.
WANSteady GREEN when link is up
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
DMZSteady GREEN when link is up
LAN 1-4Steady GREEN when link is up
SecurityGREEN when SecureWall is ON
PowerSteady GREEN when power is on
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
Blinking ORANGE when traffic is passing
Blinking RED when packet collisions occur
Steady RED when link is down
ORANGE when filtering is ON and SecureWall is OFF
RED when SecureWall and Filtering are OFF
MultiCom Firewall User’s Manual 35
Page 36
Chapter 2 Introducing The MultiCom Firewalls
Network Requirements
•Internet Connection (typically a broadband DSL or cable modem) with a
10Mbps (10–base-T) or 10/100Mbps Autosensing Ethernet connection
•One computer with a 10Mbps, 100Mbps, or 10/100Mbps Autosensing
Ethernet interface
•TCP/IP networking protocol for each computer
•(Optionally) a hub or switch to connect more than one computer to your
firewall
•(Optionally) Netscape Navigator 4.0 or higher or Microsoft Internet Explorer
4.0 or higher for interaction with the MultiCom Firewalls administrative web
server.
NOTE — The Internet Connection can also be an office to office
connection such as an ADSL line between two offices and a modem on
each side to provide Ethernet connectivity.
Advanced Configuration Software
Requirements
For advanced configuration options you may install or run the Configurator
Software from your MultiCom Companion CD. Below are the requirements to
use this software.
•CD-ROM drive (if installing the Configuration software from CD-R OM)
•Mac OSX, Windows 98, ME, NT4.0, 2000, XP, 2003 or higher, Linux kernel
2.2 or higher, Solaris version 2 or higher
•Pentium CPU, PowerPC CPU or better
•SVGA monitor with at least 800x600 pixel display and 256 colors (more than
256 colors are recommended)
•64MB of RAM,
•40 MB of free hard disk space
36 MultiCom Firewall User’s Manual
Page 37
Safety Precautions
Safety Precautions
WARNING THERE ARE NO USER SERVICEABLE PARTS INSIDE THIS
EQUIPMENT. SERVICE MUST BE PERFORMED BY QUALIFIED
SERVICE PERSONNEL. OPENING CASE VOIDS GUARANTEE.
VORSICHT KEIN TEIL IM GEHÄUSE KANN VOM BENÜTZER SELBST
REPARIERT WERDEN. BITTE WENDEN SIE SICH AN QUALIFIZIERTES
WARTUNGSPERSONAL. DAS ÖFFNEN DES GERÄTES FÜHRT ZUM VERLUST DER GARANTIE.
ATTENTION CET APPAREIL NE CONTIENT AUCUN ELEMENT QUE
L'UTILISATEUR PUISSE REPARER. CONFIEZ LA MAINTENANCE AU
PERSONNEL TECHNIQUE QUALIFIE. L'OUVERTURE DE L'APPAREIL ANNULE LA GARANTIE.
MultiCom Firewall User’s Manual 37
Page 38
Chapter 2 Introducing The MultiCom Firewalls
38 MultiCom Firewall User’s Manual
Page 39
Getting Started
This chapter will explain the configuration steps necessary to get your MultiCom
Firewall up and running for most local network situations. This includes
configuring to connect to your Internet Service Provider through your existing
xDSL, cable or wireless modem, and configuring your computers to access the
MultiCom Firewall. When you are done you will also have finished setting up the
built-in NAT firewall and all of the computers on your local network will be able
to access the Internet through your firewall.
Be sure that you have asked your ISP how they expect you to connect to the their
services... using DHCP, PPPoE, PPTP, or a static IP Address.
Chapter 3
NOTE — The term “Internet” is used to describe the network that you
use the MultiCom Firewall to connect to. The MultiCom Firewall that
you can also use to connect to other remote computers or servers such
as those at another office site. To keep things simple we will refer to
the external or WAN network as the “Internet”.
Configuring your MultiCom Firewall can be done in 10 steps as shown below.
1. Connect the MultiCom Firewall
2. Configure your computer to communicate with the MultiCom Firewall
MultiCom Firewall User’s Manual 39
Page 40
Chapter 3 Getting Started
3. Activate any option keys
4. Configure the WAN interface to connect to the Internet, your ISP or your
broadband modem
5. Configure the Easy Firewall wizard and optionally redirect specific incoming
traffic to computers on your local network that will act as servers on the
Internet or need special access
6. Save the Configuration
7. Configure the correct date and time
8. Change the default username and password (be sure to pick a names that you
can remember since you cannot retrieve forgotten usernames or passwords)
9. Optionally configure URL Filtering, Stateful Packet Inspection, syslog and
email notifications, dynamic and internal DNS.
10. Register your MultiCom Firewall
Advanced configuration such as Syslog/ SNMP messaging, Dynamic DNS, Local
Name Server, Interface editing (such as MAC address or link speed), NTP, FTP,
customized and standard filters, requires the use of the Configuration Software
and is described in the Lightning-Linux Reference Manual. You will also find
information there on how to install and use the Configurator software.
Connecting the MultiCom Firewall
Following are the steps to connect your MultiCom Firewall to your existing
Ethernet devices. After this physical connection is successful you can begin
configuring the MultiCom Firewall.
1. Connect the WAN interface port to your xDSL, cable, wireless modem or
router with the included cross-wired cable.
2. Connect the LAN interface port to either your computer ethernet interface
(using the blue crossed cable) or to your network hub (using the gray straight
cable).
3. Connect the power cable to the MultiCom Firewall.
4. And finally connect the power transformer to th e w all outlet.
40 MultiCom Firewall User’s Manual
Page 41
Connecting the MultiCom Firewall
WARNING - If you are using an Ethernet III you must reverse the
LAN cable types. In this case the blue crossed cable is only for
connections to a hub and the gray straight cable is only to be connected
to your computer.
After this final step your MultiCom Firewall will power on. The boot process
will cause flashing lights for about 20 seconds. When the Power, LAN and WAN
lights are green then the Firewall is ready for configuration. If either the LAN
or WAN lights remain red then there is a problem with the cable type or the
connected Ethernet device is not turned on. Try using a different cable to
connect to the modem or computer and verify that the other device is turned
on.
The default boot process loads the “boot” configuration and the WAN interface
will begin to search for a DHCP server from your Internet Service Provider.
When the WAN and LAN interfaces turn a steady green to show they are
connected to a network device or blinking yellow to show that data is passing it
will be possible to reach the web server of the firewall. This does not mean that
you are connected to your ISP, only that the cable connection between the
MultiCom Firewall and the modem, router, computer or hub is good. If you have
problems at this point please check the troubleshooting section later in this
manual.
The LAN interface by default has an IP Address of 10.0.0.1, with a subnet
netmask of 255.0.0.0. This will be the IP Address that you use to communicate
and configure your MultiCom Firewall. Other computers using a DHCP client
(the default network configuration for most computers) on your LAN network
will be assigned an IP address between 10.0.0.17 to 10.0.0.254.
Configuration, diagnostics and status information are available from the
MultiCom’s web server at http://10.0.0.1/.
NOTE — The most common setup is when your network modem is
acting as a bridge between you and your Internet Service Provider. It is
possible that your xDSL, cable or wireless modem is acting as a DHCP
server for your network and getting an IP address itself from your
Internet Service Provider.
MultiCom Firewall User’s Manual 41
Page 42
Chapter 3 Getting Started
If this is the case then your MultiCom Firewall will receive its
configuration information directly from your modem. If you are unsure
ask whomever installed your xDSL/ Cable line whether your modem is
acting as a Bridge or as a DHCP Server.
Configuring Your Computers
To communicate with the MultiCom Firewall you will need to be sure that your
computer is configured to access it. There are two general paths for you to follow.
•Set each computer as a DHCP client to receive all necessary information
from the MultiCom Firewall each time you boot up your computer on the
local network.
•Manually choose IP addresses for each computer on your network between
10.0.0.2-10.255.255.255, with a subnet ma sk of 255.0.0.0 and enter in the IP
address of the MultiCom Firewall (10.0.0.1) as the default gateway and DNS
server used to reach the Internet.
The process to enter these settings into your computer varies depending on your
operating system. If you do not see your operating system represented in the
following sections please refer to your computer's user manual for explanations
on configuring your network settings.
Optionally you can make this configuration on only 1 computer to allow access to
the MultiCom Firewall. After you have network access to the MultiCom Firewall
you can reconfigure the LAN IP parameters to another subnet and also deactivate
the DHCP server if there is another being used on you r network.
CAUTION - Windows users who were previously connecting to the
Internet using an analog or built-in modem or special PPPoE software
may need to change their Internet Explorer settings.
Open Internet Explorer, choose Tools and select Internet Options.
Under the Connections tab verify that “Never dial a connection” and
“use local LAN” is selected. Otherwise every time you want to use the
Internet, Windows will try to use the modem.
42 MultiCom FirewallUser’s Manual
Page 43
Windows
Windows 9x
To reach the network control on a Windows 95, 98 machine click on
START > Parameters > Control Panel > Network Settings.
In your networking window you
should be in the Configuration
panel. Here you will see the
network devices (such as your
ethernet card/interface) and the
protocols installed for each
device.
Find the setting the says TCP/IP
-> (the name of your
ethernet card)
and double click on it to open
the TCP/IP properties window.
or just TCP/IP
Windows
NOTE — if you have scrolled down to the bottom of the list and do not
see either TCP/IP or the name of your ethernet card/interface then they
are not installed in your computer. Please check the instructions that
came with your ethernet card/interface to install that now.
To set your computer as a DHCP Client
1. choose the IP Address tab
2. click on Obtain IP address automatically.
3. click on OK
4. click on OK
5. follow the onscreen instructions (which will probably have you reboot
your computer)
6. if you have the option to select a DNS server choose Obtain DNS
MultiCom Firewall User’s Manual 43
Page 44
Chapter 3 Getting Started
automatically.
To manually set your computer's IP address
1. choose the IP address tab
2. choose specify an IP address
3. enter the IP address (10.0.0.2 for example) and Netmask for your
computer (the Netmask should be the same as is configured for the LAN
interface of the MultiCom Firewall, by default it is 255.0.0.0)
4. choose the Gateway tab
5. Under New Gateway, enter in the IP address of your MultiCom
Firewall's LAN interface (by default this is 10.0.0.1) and click add
6. click on OK to close and save the properties window
7. click on OK to close and apply the network controls for your computer
8. follow the onscreen instructions (which will probably have you reboot
your computer)
Windows IP Address PanelWindows Gateway Panel
Now you are finished configuring your Windows computer to access your
MultiCom Firewall. Please continue onto the next section to test your that
everything is set up correctly.
Windows 2000 or XP
To reach the network control on a Windows 2000 or XP machine click on
START > Control Panel > Network Connections.
44 MultiCom Firewall User’s Manual
Page 45
Windows 2000 or XP
Right click on your network
card and select “Properties.”
In your Properties window you
should see the protocols and
services installed for the
selected network device.
Find the setting the says
Internet Protocol (TCP/IP)
and double click on it to open
the TCP/IP properties window.
NOTE — if you have scrolled down to the bottom of the list and do not
see either TCP/IP or the name of your ethernet card/interface then they
are not installed in your computer. Please check the instructions that
came with your ethernet card/interface to install that now.
To set your computer as a DHCP Client
1. choose the General tab
2. click on Obtain IP address automatically.
3. click on Obtain DNS server address automatically
4. click on OK
5. follow the onscreen instructions (which might ask you to reboot your
computer)
To manually set your computer's IP address
1.choose the General tab
2.click on Use the following IP address
3.enter the IP address, Subnet mask, and Default gateway. Be sure that the
Subnet Mask and Default gateway match the settings of the MultiCom
Firewall’s LAN interface. For the first connection this should be IP
address 10.0.0.1, Subnet 255.0.0.0, Default gateway 10.0.0.1
MultiCom Firewall User’s Manual 45
Page 46
Chapter 3 Getting Started
4.click on Use the following DNS server addresses
5.Under Preferred DNS server, enter in the IP address of your MultiCom
Firewall's LAN interface (by default 10.0.0.1) or the Primary DNS
server of your ISP
6.Under Alternate DNS server, leave it blank or enter the Secondary
DNS server of your ISP
7.click on OK
8.follow the onscreen instructions (which might ask you to reboot your
computer)
Ethernet DHCP ClientEthernet Static IP Address
Now you are finished configuring your Windows computer to access your
MultiCom Firewall. Please continue onto the next section to verify that
everything is set up correctly.
Macintosh
To reach the network control panel on your Macintosh you need to choose on
your
Apple Menu > Control Panels > TCP/IP Panel. This is where you will find
the options to set your Macintosh to use a DHCP server on the network or to use
static IP addressing.
46 MultiCom Firewall User’s Manual
Page 47
Macintosh
These instructions use MacOS9. If you do not see a TCP/IP control panel or are
using an earlier version of the MacOS software please check the documentation
that came with your Macintosh Operating system for instructions on how to load
TCP/IP protocols into your computer.
To set your computer as a DHCP client
1. under Configure select “Using DHCP”
2. close the TCP/IP panel
3. choose “Save” when asked if you want to save your changes
To manually set your computer's IP address
1. under Configure select “Manually”
2. enter the IP address for your computer in the IP address field (10.0.0.2 for
example)
3. enter your network mask in the Network mask field (by default this should be
255.0.0.0)
4. enter your firewall IP address (the IP address of your MultiCom Firewall's
LAN interface, 10.0.0.1 by default) in the
firewall address field
5. enter the DNS server IP addresses in the Name server addr field (by default
this is 10.0.0.1)
6. enter your local domain (if you have one) in the Starting domain name field
7. close the TCP/IP panel
8. choose “Save” when asked if you want to save your changes
MultiCom Firewall User’s Manual 47
Page 48
Chapter 3 Getting Started
Linux
Configuring the network settings for your Linux-based computer will depend on
the type of graphical interface and Linux distribution that you have. Be sure
you've installed the TCP/IP options when you installed your version of Linux.
Otherwise please refer to the documentation that came with your system for the
method of configuring your particular networking options.
The following instructions were used on the Debian distribution by editing the
configuration file at
For configuration of the Ethernet interface to use DHCP services
iface eth0 inet dhcp
To manually set the IP address of the interface card
iface eth0 inet static
address 10.0.0.2
netmask 255.0.0.0
broadcast 10.255.255.255
firewall 10.0.0.1
/etc/network
Choosing the Internet Connection
Common Configurations
There are 5 common ways to configure your new MultiCom Firewall for use on
your network and they are listed below. These assume that your Broadband
modem can be (or already is) configured in “bridging” mode, allowing the
firewall direct access to your ISP network. The option you choose depends on
how your ISP has configured your Internet access. These options are available
using the Easy-Setup on the built-in web server or the Configurator software on
your MultiCom Companion CD.
1. DHCP: requires the ISP to have a DHCP server.
2. PPPoE: requires a PPPoE username, password, and that the broadband
modem is configured into “bridge” mode.
3. PPTP: requires a PPTP username, password and router/server IP addresses of
48 MultiCom Firewall User’s Manual
Page 49
Common Configurations
the Alcatel Modem ANT-1000.
4. Static IP: requires an IP address, subnet mask, default gateway and DNS
parameters.
5. Advanced Configuration where you can fully configure the MultiCom
Firewall to meet your networking needs.
CAUTION - This information must be exactly the same as received
from the ISP or communication to the Internet will not be possible.
Please check with your ISP if you have not received the Internet
Connection type or the connection’s required information. The factory
default setting activates DHCP on the WAN interface.
Option 1: Plug and Play with DHCP. This type of Internet connection is
typical for use with Cable Broadband modems. Does your our Internet Service
Provider uses DHCP to assign you your IP configuration parameters and your
computers are configured as DHCP clients? In this case you can simply plug in
the MultiCom Firewall immediately between your network and your xDSL,
cable or wireless modem to use the default configuration. If your broadband
modem is the DHCP server please read below for additional information.
Option 2: PPPoE is used when your Internet Service Provider requires you to
only have a username and password to access the In ternet. This type of Internet
connection is typical for use with DSL Broadband modems. In this cases you
enter the necessary information using the Easy Setup window of the built-in web
server of your firewall. Click save and you can start surfing the Internet.
Option 3: PPTP with an Alcatel Modem ANT-1000. This process also requires
a username and password. Saving a PPTP configuration using Easy-Setup will
change the default IP address of the MultiCom Firewall’s LAN interface. This
change requires you to reboot your computer after using the Easy-Setup wizard.
Option 4: Static IP Configuration. If your ISP gives you a static IP address you
can also enter this into the Easy-Setup of the MultiCom Firewall. You will also
use this option if you are configuring your MultiCom Firewall for use behind a
pre-existing router which will become your default gateway.
MultiCom Firewall User’s Manual 49
Page 50
Chapter 3 Getting Started
Option 5: Advanced Configuration for advanced users. This gives you access
to all of the parameters of your MultiCom Firewall. Setting these options
requires a good understanding of network terminology and the way your own
network is configured. Please refer to the Lightning-Linux Reference Manual for
a description of Advanced Configuration options.
Special Configurations
If your modem cannot be configured into “bridge” mode you will have to let the
Broadband Modem receive the actual IP parameters from the ISP and share it
with the MultiCom Firewall. In this case you have to make a special
configuration to use the MultiCom Firewall.
Only choose one of these configurations if you cannot use the Common
Configurations above.
1. Broadband Modem receives IP from ISP and is a DHCP server.
2. Broadband Modem receives IP from ISP and has a fixed IP on its LAN
interface.
3. Network router is between Modem and Firewall.
4. Network router is between Firewall and Local Network.
CAUTION - Because you will be creating 2 networks, one between the
MultiCom Firewall and the Broadband Modem and one between the
MultiCom Firewall and the local network you must be sure that both
are using different subnets. For example the default LAN interface
uses subnet 10.0.0.0/255.0.0.0 so if this was used in the final
configuration the WAN should have a different subnet.
When connecting the MultiCom Firewall to a network that is not directly on the
Internet the Firewall will rely on the functionality of the devices between it and
the Internet or between it and the Local Network. Some services might be limited
or require additional configuration as described below.
•the Network Address Translation (NAT) of the Broadband Modem may not
be as powerful as the MultiCom Firewall’s NAT
•if the Broadband modem is using NAT then redirection of incoming traffic to
reach internal servers requires NAT rules on BOTH the Broadband Modem
and the MultiCom Firewall (including configuration for remote access of the
50 MultiCom Firewall User’s Manual
Page 51
Special Configurations
Firewall itself)
•if the modem/ router is using IP addresses in the 10.0.0.0/255.0.0.0 subnet
then you will need to change the IP address and DHCP Server of the
Firewall’s LAN interface (because it uses this subnet by default.)
•if there is a router between the Firewall and the Modem then the router must
be configured correctly to reach the Internet through the Modem or some
other route
Option A: Broadband Modem is DHCP Server. The Broadband modem
receives all of the IP configuration directly from the ISP and uses its own
Network Address Translation to share the connection. In this case you can
simply plug in the MultiCom Firewall immediately between your network and
your xDSL, cable or wireless modem to use the default configuration. If the
Modem uses the 10.0.0.0/255.0.0.0 subnet then you will need to change the LAN
interface to a different subnet. For example you could configure the LAN
interface to use 192.168.0.1, subnet 255.255.255.0. If you change the IP address
of the LAN interface be sure to also change the IP addresses of the LAN’s DHCP
server, in this case to 192.168.0.17-192.168.0.117.
Option B: Static IP with Modem and Firewall. If the Broadband Modem does
not offer a DHCP server then you will need to use the Easy Setup’s Static IP
configuration to allow the MultiCom Firewall to reach it. Configure the WAN
interface of the Firewall to be on the same network as the Modem. For instance if
the Modem has an IP address of 192.168.0.1, subnet 255.255.255.0 then
configure the Firewall’s WAN IP address to be 192.168.0.2, subnet
255.255.255.0. The default gateway will be the IP address of the Modem, in this
example it is 192.168.0.1. The DNS parameters should be those of ISP.
Option C: Router between Modem and Firewall. In this case you will need to
use the Easy Setup’s Static IP configuration to allow the MultiCom Firewall to
reach the Router and the router must be configured to reach the Modem and/ or
Internet. Configure the WAN interface of the Firewall to be on the same network
as the router. For instance if the router has an IP address of 192.168.0.1, subnet
255.255.255.0 then configure the Firewall’s WAN IP address to be 192.168.0.2,
subnet 255.255.255.0. The default gateway will be the IP address of the router, in
this example it is 192.168.0.1. The DNS parameters should be those of ISP.
Option D: Router between Firewall and Local Network. In this case configure
the WAN interface using the Easy Setup for Internet Access. Then configure the
router to use the LAN interface of the MultiCom Firewall as the default gateway
MultiCom Firewall User’s Manual 51
Page 52
Chapter 3 Getting Started
for all Internet Traffic. Additionally, the MultiCom needs to know that the actual
Local Network is behind the router. This requires the use of the Configurator
software and is described in the Routing chapter of the Reference Manual.
Configuration Checklist
Before you start the configuration there is some required information needed for
your MultiCom Firewall to work correctly. If any of the following terms are
unfamiliar to you please check with your Internet Service Provider or the glossary
at the end of this book.
Below you can find the default configuration of the LAN side of your MultiCom
Firewall. This is the part of the MultiCom Firewall that is connected directly to
your local/home network. These settings can be changed by you during the Easy
Setup, visiting http://10.0.0.1/setup/lan/ or with the Configurator software.
Table 3: Pre-set configuration of MultiCom Firewall
Configuration QuestionsYour Choices
IP Address of the LAN interface10.0.0.1
Subnet Mask of your network255.0.0.0
Will you use DHCP on your LAN?Yes
IP address range for your internal network10.0.0.17 - 10.0.2.254
User name to configure the MultiCom Firewallmulticom
Password to configure the MultiCom Firewall(there is no password)
IP Configuration of the WAN interfaceDHCP Client
DNS Proxy and Cache Activated
NAT Firewall Activated
NOTE — When using the DHCP server of your firewall the necessary
IP parameters will be distributed to your LAN by the built-in DHCP
server. This saves you from having to manually configure each
computer. There can only be one DHCP server on any network.
If your ISP or your Broadband Modem uses DHCP please skip ahead to the next
section because you can use the Plug & Play Configuration.
If your Internet Service Provider does not provide DHCP configuration the
following information will be necessary for you to communicate through your
MultiCom Firewall. For PPTP connections this extra information is necessary
because you are forming two TCP/IP network links: between your Broadband
Modem <--> MultiCom Firewall and between the MultiCom Firewall <--> your
network.
If your ISP is using PPPoE or PPTP fill in either the PPPoE/PPTP configuration
checklist or the Static configuration checklist depending on how your Internet
Service Provider wants you to connect to the Internet.
Table 5: PPPoE/PPTP configuration checklist for WAN interface
ParametersInformation from your Internet
Service Provider
the username assigned to you by your
Internet Service Provider
the password assigned to you by your
Internet Service Provider
the domain name of your Internet
Service Provider or yours (optional)
PPTP Only: what is the IP Address of
your modem (default 10.0.0.138)
PPTP Only: what is the subnet mask
of your modem (default 255.0.0.0)
If you are not using DHCP, PPPoE, or PPTP then you will need to configure a
Static IP configuration. The table below is all of the information that you will
need from your ISP to successfully make a connection to the Internet.
MultiCom Firewall User’s Manual 53
Page 54
Chapter 3 Getting Started
If you have a pre-existing router between the broadband access modem and the
MultiCom Firewall you will also need to use the Static IP Configuration option of
the Easy-Setup. The Firewall WAN IP address parameters must match the subnet
of your router and the router IP address should be the default gateway. Be sure to
enter in your ISP’s DNS information as well.
Table 6: Static configuration checklist for WAN interface
ParametersInformation from your Internet
Service Provider
the IP address assigned to you by
your Internet Service Provider
the IP netmask used by your Internet
Service Provider
the default gateway of your Internet
Service Provider
the domain name of your Internet
Service Provider or yours
the primary IP address of the DNS of
your Internet Service Provider
the secondary DNS IP Address of
your Internet Service Provider
If you do not know this information check with your Internet Service Provider
support services or the documentation you received from them when you joined
them.
Plug & Play Configuration: DHCP
Here are the requirements necessary to install the MultiCom Firewall without
configuration.
1. Is your Internet Service Provider giving you your IP address, DNS server
address and default firewall configuration with a DHCP server?
2. Are all of your internal network (LAN) devices configured as DHCP Clients?
If your Internet Service Provider uses DHCP to assign you your IP configuration
parameters and your computers are configured as DHCP clients you can simply
plug in the MultiCom Firewall immediately between your network and your
xDSL, cable or wireless modem. In this case it will automatically be a firewall
protecting your internal network (LAN) and enable all of your LAN computers to
use the same Internet account.
54 MultiCom Firewall User’s Manual
Page 55
Using the Easy Setup
TIP - Instructions on configuring your computers to use DHCP is in
the “Configuring Your Computers” Section on page 42.
If you answered yes to the two above questions then you only need to plug in your
cables to the MultiCom Firewall. If a DHCP server is found on the WAN, your
MultiCom Firewall will be assigned an IP address by your Internet Service
Provider (or possibly your modem, see NOTE below). Additionally, all needed
information to communicate with the Internet Service Provider through the
modem will be passed to the MultiCom Firewall, which in turn passes it to the
DHCP client computers on your network so that they can access the Internet.
If no DHCP server is found the MultiCom Firewall will not be able to connect to
the Internet until a different configuration is loaded. If no DHCP service is
provided you will need to run the Easy-Setup from the built-in web server of the
MultiCom Firewall or use the Configurator software from the Companion CD to
properly configure your MultiCom Firewall.
CAUTION - Some Internet Service Providers that use DHCP also
require you to register the hardware MAC address of your computer’s
Ethernet card. If this was the case you will either have to ask them to
change the MAC address to the WAN interface of your MultiCom
Firewall (00:90:f4:xx:xx:xx where xx:xx:xx is the 6 digit/ letter serial
number of your Firewall) or use the Configurator software to change
the MAC address of your MultiCom Firewall. Please see the
Reference Manual for more information on this process.
Diagnostics and status information on this connection is available from the
MultiCom web server at http://10.0.0.1/status/wan/ and from the DHCP tab of
the Configurator software’s Monitor window. DHCP activity can also be logged
by activating Syslog using the Advanced Config option.
Using the Easy Setup
The built-in Easy Setup of your MultiCom Firewall’s web interface has been
designed to get your Internet connection started as quickly as possible. You will
need an Internet web browser installed to use this option. If you do not have one
MultiCom Firewall User’s Manual 55
Page 56
Chapter 3 Getting Started
you can install a web browser from the MultiCom Companion CD that came with
your firewall. Just go to the 3rd Party Software section and install Netscape,
Internet Explorer, Mozilla or Firefox.
To properly configure your firewall we will be using the information that you
have written in the Pre-Configuration Checklist. Please be sure that you have
filled in that information now before continuing.
Accessing the Easy Setup Web Server
For the following explanation we assume that you will be directly connected to
your firewall. Your computer must be configured as a DHCP client to configure
the MultiCom Firewall (optionally a computer with a static IP address between
10.0.0.2-10.255.255.255 and with a subnet mask of 255.0.0.0 can be used.) If
you are unsure how to do this see the previous section on Configuring Your
Computers.
CAUTION - if your MultiCom Firewall does not respond you may
need to reset it to its default settings. Refer to the Resetting Default
Settings section of the Troubleshooting chapter.
Open up a web browser and enter in the IP address of your MultiCom Firewall
(the factory default is http://10.0.0.1) You will be asked for the username and
password allowed to access the firewall. The default settings for the MultiCom
Firewalls is username=” multicom” and no password. Enter this information now
and click OK.
The next screen that you will see is the MultiCom Web Server window. Here you
select the Easy Setup option.
56 MultiCom Firewall User’s Manual
Page 57
WAN DHCP Easy Setup
CAUTION — Remember that you must be using a computer that
either is set as a DHCP Client or has a static IP Address (in the 10.x.x.x
range, for example 10.0.0.2) and a subnet mask of 255.0.0.0.
Otherwise you will not be able to communicate with the MultiCom
Firewall in its default settings.
The Easy Setup window (below) allows for fast configuration of your MultiCom
Firewall. After reading the warning click the “Next” button to start configuring
the WAN interface.
The next choice depends on how your Internet Service Provider connects you to
the Internet. You will see the WAN Configuration webpage where you can select
the Connection Type that your ISP has asked you to use. The next four sections
describe the 4 possibilities for configuring the WAN interface using DHCP,
PPPoE, PPTP or a static configuration.
WAN DHCP Easy Setup
If your Internet Service Provider connects you using a DHCP server you will not
have to configure any parameters with Easy Setup because this is the default
mode of the MultiCom Firewall. During the bootup of your firewall in its default
mode it will automatically search for the DHCP server and configure itself with
everything needed to reach the Internet Service Provider.
MultiCom Firewall User’s Manual 57
Page 58
Chapter 3 Getting Started
If you use the Easy Setup window to configure DHCP you will have the option to
configure the DHCP settings on your LAN interface. This allows you to
customize the IP addresses assigned by your firewall or to disable this
functionality. Please refer to the Lightning-Linux Reference Manual chapter on
DHCP for more information on using this option.
1. Select Dynamic (DHCP) in the Connection Type box to see the Easy Setup
configuration options.
2. Optionally give a name to your MultiCom Firewall.
3. Click the Next button and goto the Section “LAN Easy Setup” on page 63.
WAN PPPoE Easy Setup
If your Internet Service Provider connects you using a PPPoE server you need to
click the PPPoE option in the Easy Setup window (see the window above). This
window only requires a username and password to access your Internet Service
Provider. This information is available from your Internet Service Provider.
The PPPoE setting causes the MultiCom Firewall to automatically and regularly
demand its IP configuration from a PPPoE server connected through the WAN
interface using the username and password. All needed Internet parameters such
as the MultiCom Firewall’s IP address, IP subnet, default gateway, and external
DNS servers will be automatically requested directly from the ISP using the
PPPoE protocol. Below are the steps necessary to configure a PPPoE
connection.
1. Select PPPoE in the Connection Type box and click the “Next” button to see
the following Easy Setup configuration option page.
58 MultiCom Firewall User’s Manual
Page 59
WAN PPTP Easy Setup
2. Enter in the username that your Internet Service Provider gave to you.
3. Enter in the password that your Internet Service Provider gave to you.
4. Optionally enter in your local domain name. (This will become the default
suffix used for networking activity.)
5. Select the PPP connection mode that you wish to use: Permanent is an always
on connection, Dial on Demand only connects to the Internet when there is
network traffic, and Manual requires manually opening or closing the
Internet connection from the web interface.
6. Select the PPP connection idle time out if you are using Dial on Demand.
When there is no network activity this is the number of seconds before the
PPP connection is closed.
7. Optionally enable the TCP Frame Size Adaption as a troubleshooting step if
you are having problems connecting to your Internet Service Provider or
certain web pages.
8. Click the Next button and goto the Section “LAN Easy Setup” on page 63.
Diagnostics and status information on this connection is available from the
MultiCom web server at http://10.0.0.1/status/wan/ or from the PPP tab of the
Configurator software’s Monitor window. PPPoE activity can also be logged by
activating Syslog using the Advanced Config option. See the User’s Manual for
more instructions.
WAN PPTP Easy Setup
If your Internet Service Provider connects you using a PPTP server you need to
click the PPTP option in the Easy Setup window (see the main window above).
This window requires a username and password to access your Internet Service
MultiCom Firewall User’s Manual 59
Page 60
Chapter 3 Getting Started
Provider. Additionally you will need to enter the IP Address and Subnet Mask of
your broadband modem. This information is available from your Internet Service
Provider.
The PPTP setting causes the MultiCom Firewall to automatical ly and regularly
demand its IP configuration from a PPTP server connected through the WAN
interface using a username and password. All needed Internet parameters such as
the MultiCom Firewall’s IP address, IP subnet, default gateway, and external
DNS servers will be automatically requested directly from the ISP using the
PPTP protocol.
It is important to know the existing IP configuration of the modem offering a
PPTP server because the MultiCom Firewall WAN interface mst be on the same
subnetwork as the Ethernet interface of the modem. This creates 2 networks, one
between the MultiCom Firewall and the broadband modem and one between the
MultiCom Firewall and the local network. By default this PPTP Setup Panel
configures your WAN interface’s network to be 10.0.0.1/255.0.0.0, expects to
find the broadband modem at IP address 10.0.0.138, and changes the LAN
interface to 192.168.1.1/255.255.255.0. Although this is a very common
configuration it may not be the way your broadband modem is configured. Be
sure to verify
CAUTION - Saving a PPTP configuration using Easy-Setup will
change the default IP address of the MultiCom Firewall’s LAN
interface. This change requires you to reboot your computer after
using the Easy-Setup wizard
1. Select PPPoE in the Connection Type box and click the “Next” button to see
the following Easy Setup configuration option page. This is where you enter
in your username and password, modem IP Address, WAN IP Address and
Subnet Mask.
60 MultiCom Firewall User’s Manual
Page 61
WAN Static IP Easy Setup
2. Enter in the username that your Internet Service Provider gave to you.
3. Enter in the password that your Internet Service Provider gave to you.
4. Optionally enter in your local domain name. (This will become the default
suffix used for networking activity.)
5. Enter in the IP Address of the broadband modem that is your PPTP Server.
6. Enter in the IP Address for the WAN interface for the MultiCom Firewall.
This address must be on the same subnet as the IP Address of the broadband
modem. For instance if your modem 10.0.0.138 then your WAN interface
would probably have and IP Address of 10.0.0.1 .
7. Enter in the Subnet Mask of the broadband modem.
8. Click the Next button and goto the Section “LAN Easy Setup” on page 63.
WAN Static IP Easy Setup
In some cases your Internet Service Provider will have you configure all of the
necessary information manually. This is common when you are assigned a static
IP address that will not change. The needed configuration information is
available from your Internet Service Provider. Below are the steps necessary to
configure a Static connection.
In a Static IP connection all Internet parameters such as the MultiCom Firewall’s
IP address, IP subnet, default gateway, and external DNS servers must be
manually configured. If your ISP has told you to manually configure your WAN
interface this is where you will enter in the information that they send you.
MultiCom Firewall User’s Manual 61
Page 62
Chapter 3 Getting Started
TIP - If you have a pre-existing router in front of your MultiCom
Firewall you will use its IP Address as the default gateway and need to
be sure that your WAN interface is on the same subnet as the router.
1. Select Static in the Connection Type box and click the “Next” button to see
the following Easy Setup configuration option page. This is where you
manually enter in all of your WAN interface IP parameters. Your ISP should
have provided you with all of the information necessary to fill in this form.
2. Enter in the WAN IP Address that your MultiCom Firewall will be known as
(provided by your Internet Service Provider.)
3. Enter in the WAN Subnet Mask that will be used between the Internet
Service Provider and the MultiCom Firewall.
4. Enter in the Default Gateway address (otherwise known as the IP address of
the Internet Service Provider's firewall).
5. Optionally enter in your local domain name. (This will become the default
suffix used for networking activity.)
6. Enter in the IP addresses of your Internet Service Provider's Primary and
Secondary DNS servers.
7. Click the Next button and goto the Section “LAN Easy Setup” on page 63.
62 MultiCom Firewall User’s Manual
Page 63
LAN Easy Setup
LAN Easy Setup
After finishing the WAN configuration as instructed by your ISP you can
optionally change the default LAN configuration settings for your local network.
You should not normally change these settings unless you know what you are
doing and can just click the Next button to continue. For more information about
DHCP options refer to the DHCP Chapter of the Reference Manual.
1. Enter in the LAN IP Address that your MultiCom Firewall will be known as
(provided by your Internet Service Provider.) This cannot be on the same
subnet as the WAN interface.
2. Enter in the LAN Subnet Mask that will be used on your local network.
3. Choose to enable or disable the built-in DHCP server for managing your
network. By default this is enabled and should not be changed unless you
have another DHCP server on your network.
4. If you enabled the DHCP server, choose the first IP address that the
MultiCom Firewall should assign on your local network to DHCP clients.
This IP Address must be on the same subnet as the LAN IP Address.
5. If you enabled the DHCP server, choose the last IP address that the
MultiCom Firewall should assign on your local network to DHCP clients.
This IP Address must be on the same subnet as the LAN IP Address. All
addresses between the “From address” and the “To address” can be assigned
by the MultiCom Firewall to computers on your local network.
6. Click the Next button and goto the next Section.
MultiCom Firewall User’s Manual 63
Page 64
Chapter 3 Getting Started
DMZ Easy Setup
If your MultiCom Firewall has a DMZ interface this webpage will appear next. If
you do not have a DMZ interface you will immediately go to the Firewall Easy
Setup configuration webpage. If you want to leave the DMZ disabled just enter
0.0.0.0 for the IP address and 0.0.0.0 for the subnet mask. You can activate it
later.
1. Enter in the DMZ IP Address that your MultiCom Firewall will be known as
(provided by your Internet Service Provider.) This cannot be on the same
subnet as the WAN or LAN interfaces.
2. Enter in the DMZ Subnet Mask that will be used on your local network.
3. Choose to enable or disable the built-in DHCP server for managing your
network. By default this is enabled and should not be changed unless you
have another DHCP server on your network.
4. If you enabled the DHCP server, choose the first IP address that the
MultiCom Firewall should assign on your DMZ network to DHCP clien ts.
This IP Address must be on the same subnet as the DMZ IP Address.
5. If you enabled the DHCP server, choose the last IP address that the
MultiCom Firewall should assign on your DMZ network to DHCP clien ts.
This IP Address must be on the same subnet as the DMZ IP Address. All
addresses between the “From address” and the “To address” can be assigned
by the MultiCom Firewall to computers on your DMZ network.
6. Click the Next button and goto the next Section.
64 MultiCom Firewall User’s Manual
Page 65
Easy Firewall Setup
Easy Firewall Setup
Although the SecureWall blocks all incoming traffic arriving at the WAN
interface except the traffic which is a response to a data request from the LAN or
DMZ networks you may wish to allow customized remote access to your
MultiCom Firewall or your local network.
The Easy Firewall Setup is part of the Easy Setup wizard of the Web Interface but
it can also be used separately on the MultiCom Firewall by using a web browser
to go to http://10.0.0.1/setup/fw/ (where 10.0.0.1 is the IP address of the LAN
interface of the Firewall.). Additional options are provided by the next 2
webpages.
Firewall Filters
The first part of the Firewall Easy Setup webpages allows you to enable or
disable the Stateful Packet Inspection Firewall to work along with the
SecureWall firewall. When filtering is enabled all traffic from the DMZ
network (if available) to the LAN is blocked. Additionally you can choose
to block NetBIOS traffic directed to the WAN interface or coming from
the LAN interface.
Additional rules can be customized using the Configurator software and is
described in the Lightning-Linux Reference Manual chapter on Filtering. When
you are finished click the “Next” button.
Host Mapping
If you make servers on your local network available to users on the
Internet (for instance a web or email server) you may enter the IP address
on your local network of those servers. Rules will be made to allow access
to these servers in the SecureWall and Stateful Filtering Firewall. External
users will use the IP address of the WAN interface and be redirected to
these internal servers.
MultiCom Firewall User’s Manual 65
Page 66
Chapter 3 Getting Started
To activate services not in the list, use the Easy Firewall of the Configurator
software. When you are finished click the “Next” button.
NOTE - to make secure remote access to your MultiCom Firewall for
configuration simply enter in the IP address of the LAN interface (by
default 10.0.0.1) in the “SecureWeb - HTTPS (TCP 443)” and or the
“Secure Shell - SSH (TCP 22)” server fields.
Saving The Configuration
1. Finally you have a summary of your chosen configuration and the choice of
how to save it. You can either choose Apply Configuration to save the
configuration to the temporary memory and start using it right away or you
can choose Apply Configuration and Save as Boot config. The second option
makes your changes permanent, in case you need to reboot your firewall or
there is a power outage. The second option is the recommended option.
66 MultiCom Firewall User’s Manual
Page 67
Fine Tuning Your Configuration
NOTE — Choosing Apply Configuration and Save as Boot
activates and saves the configuration changes you have made
config
so that when the MultiCom Firewall is rebooted your changes will still
be there. If you choose
activated but the next time you reboot your MultiCom Firewall these
changes will also be deleted.
2. When the configuration has been successfully saved using the Apply
Configuration button you will see the following screen. Your Easy Setup
configuration is now finished.
3. If you saved your configuration using the Apply Configuration and Save as
Boot config button you will see the following screen. Your Easy Setup
configuration is now finished.
Apply Configuration then the changes will be
Fine Tuning Your Configuration
The default configuration that you have just set up enables the basic features of
your MultiCom Firewall such as Internet Connection Sharing and the SecureWall
to protect your network. For more advanced features please refer to the
Lightning-Linux Reference Manual for your firmware version.
MultiCom Firewall User’s Manual 67
Page 68
Chapter 3 Getting Started
Activate Option Keys
If you have received an Option Key you will need to enter it into the MultiCom
Firewall for the new features to be activated. The Option key is a text file that is
usually received in an email. You can either save the attached text message to
your computer or you can make a new, empty text file and copy and paste the
contents of the key into it.
To reach the key activation window on the MultiCom Firewall web interface you
will need to use a web browser to goto http://10.0.0.1/tools/options/ (where
10.0.0.1 is the IP address of the LAN interface of the Firewall.)
Finally, click on the browse button to where the Option Key text file has been
saved. Finally click the button “Update Options Key”.
Configure Date And Time
To set the correct date and time on the MultiCom Firewall you will need to use a
web browser to goto the LAN interface http://10.0.0.1/tools/date/ (where 10.0.0.1
is the IP address of the LAN interface of the Firewall).
Enter in the correct date, the current time and optionally choose a timezone if you
plan to use the NTP functionality as described in the Reference Manual. The
Timezone files are stored in the zoneinfo directory of your Configurator
installation or the MultiCom Companion CD. When you are done click “Submit
Values”.
68 MultiCom Firewall User’s Manual
Page 69
Create New Privileged Administrator
Create New Privileged Administrator
Although the SecureWall firewall is activated by default, blocking access to the
Firewall for configuration from the Internet, it is a good idea to change the default
username of “multicom”.
To change the Administrator Username and Password on the MultiCom Firewall
you will need to use a web browser to goto http://10.0.0.1/advanced/user/create/
(where 10.0.0.1 is the IP address of the LAN interface of the Firewall). Enter in a
new Username and Password and select the User Rights “Privileged” with CLI
Access enabled. When you are finished click “Submit Values”.
When the new “Privileged” user is created, the default user “multicom” is
disabled. This means that only the new user will have the right to configure the
MultiCom Firewall. If you forget your username and password, you will have to
reset the MultiCom Firewall back into its default configuration and reload the
configuration file from a backup copy.
NOTE - When the first new Privileged user is created the multicom
user will be deactivated and you will need to authenticate again using
the new username and password that you created.
The Reference Manual has descriptions of all user and permission options.
Quick Interface Configuration
If you want to make a quick change to an interface’s configuration you will need
to use a web browser to go to the LAN interface (by default http://10.0.0.1).
Select interface from the menu (WAN, LAN, DMZ, DSL, WLAN) and change
the configuration on the following pages. When you are finished you will have
the option to either
MultiCom Firewall User’s Manual 69
Page 70
Chapter 3 Getting Started
•'Apply Configuration' to test a new configuration but not save it. Rebooting
the Firewall will return the Firewall to its previous configuration.
•'Apply Configuration and Save as Boot config' to activate and permanently
save your configuration
Testing Your Configuration
The process of communication to the Internet works as follows when your
MultiCom Firewall and workstation computers are configured properly.
1. Your computer makes a request to reach the Internet or a service from the
Internet.
2. This request is sent to the network through your ethernet card/interface.
3. Your ethernet card/interface forwards this information to the MultiCom
Firewall
4. Your MultiCom Firewall takes this info rm ation and forwards it to your
modem or directly to the ISP if the modem is in “bridge” mode
5. your modem, unless already connected will dial your Internet Service
Provider, authenticate your user name and password and then send
information request to the Internet
The information that you requested will follow the same route back (in the
opposite order) to reach the computer making the request. In most cases you will
either get the information that you received, get a response that it was not found,
or because of network congestion be told that your request has timed-out and was
dropped.
To test that your connections are working correctly you can open your preferred
Internet browser (Netscape Navigator or Microsoft's Internet Explorer) and type
in a web address.
NOTE — please hit the refresh page on your browser to be sure that
you are getting information from the Internet directly instead of from a
web page saved to your hard disk. You should also notice the lights on
your MultiCom Firewall blinking.
70 MultiCom Firewall User’s Manual
Page 71
Testing Security
Unless your modem is already connected it will make the phone call now and
retrieve the information that your computer requested. If you are able to reach the
Internet then everything is working properly. If you have problems first check
that everything is plugged in, go over this chapter again, check the
Troubleshooting chapter, and finally consider calling the Technical Support of
where you purchased your MultiCom Firewall.
Diagnostics and status information on this connection is available from the
MultiCom web server at http://10.0.0.1/status/wan/ and from the DHCP or PPP
tab of the Configurator software’s Monitor window.
Don't forget to register your MultiCom Firewall and consider reading up on the
more advanced options available.
CAUTION — A request to the Internet may be made without your
being aware of it. These requests could inadvertently open your
network connection and cause you additional phone. Check the
Troubleshooting chapter for more information on Internet connections
For more detailed testing suggestions for your configuration and firewall check
the Lightning-Linux Reference Manual.
Testing Security
Here are some web sites that offer free security scanning of your Intern et
connection. There are many such sites available on the Internet.
Registering your firewall allows you to keep up to date with the latest
developments for your product. Additionally registration takes away the burden
of keeping proofs of purchase (for upgrades or repairs) as our database will take
care of that for you. Now is a good time to do it while you have your receipts and
serial number readily available.
For online registration go to http://www.lightning.ch/register.html
72 MultiCom FirewallUser’s Manual
Page 73
Maintenance
While basic security is enabled as soon as you plug your MultiCom Firewall
firewall between your modem and your network, a well running network requires
regular maintenance. A poorly maintained network may suffer from network
performance loss or worse such as network failure (especially when you need it
most.)
Any number of factors can affect the way your network runs — new software
installations, misconfigurations of hardware, and even electromagnetic
interference can all cause serious changes in the way data travels through your
network.
Chapter 4
Just as with any emergency, preparation will minimize the effect on your business
and peace-of mind. Your MultiCom Firewall has been equipped with numerous
tools to assist in your maintenance needs.
•Checking System Status
—Using the Configurator software
—Using the built-in web server
—Using shell commands to directly log into the firewall
•Configuration
—Backup the Configuration
MultiCom Firewall User’s Manual 73
Page 74
Chapter 4 Maintenance
—Restoring the Configuration
•Keep up to date
—update the firmware
—read about current networking exploits
Web Server Status Reports
By using a web browser you can get status information of ARP and routing
tables, interfaces, memory and CPU loads, uptime and more. You just type in the
IP address of the firewalls LAN or WAN interface (by default http://10.0.0.1),
enter any necessary user names and passwords (by default user=“multicom” and
there is no password). You can print this information out using your web
browser's print functions.
Starting in Lightning-Linux 3.4 the web server provides direct status information
of the Firewall, services, interfaces, and logged events. Simply select the
STATUS link in the menu. This page is shown below.
ToolsFunction
System StatusShows system firmware version, device type, serial
number, installed options, system uptime and CPU
load
Services StatusShows the status of the ARP Proxy, DNS Proxy,
DynDNS, FTP, NTP, RIP, SNMP and Syslog
services.
74 MultiCom Firewall User’s Manual
Page 75
Web Server Status Reports
ToolsFunction
DNS StatusShows the current Domain Name Servers
ADSL StatusShows ADSL connection diagnostics and PPP
configuration on the ADSL interface
WAN StatusShows WAN interface diagnostics such as MAC
address, ethernet speed, and IP parameters. If the
interface is a DHCP client you will have a button to
renew the DHCP lease. If it is a PPPoE Manual/ Dial
on Demand connection you will have the option to
Connect or Disconnect.
LAN StatusShows LAN interface diagnostics such as MAC
address, ethernet speed, and IP parameters. It will
also show if a DHCP server is active on the interface
and offer the option to see existing DHCP Leases.
DMZ StatusShows DMZ interface diagnostics such as MAC
address, ethernet speed, and IP parameters. It will
also show if a DHCP server is active on the interface
and offer the option to see existing DHCP Leases.
Wireless LAN
Status
VRRP StatusIf the High Availability option has been installed this
IPSec StatusShows a table of existing IPSec connections and
Test IPSec
Connection
Network
Monitoring
Service
LOG MessagesEvent log of activities occurring on the MultiCom
All of the web servers status screens are shown in the Web Server Screens
Appendix in the Reference Manual.
Shows the Wireless Interface diagnostics. This is the
window where the user can see the WLAN status and
state of each hardware interface, the current
configuration of the selected interface, the broadcast
level.
table shows the status of VRRP on each interface.
statistics about each connection when the IPSec
Option is installed.
Allows the testing of each active IPSec connection
when the IPSec Option is installed.
Shows a table of TCP networking services that are
being monitored by the MultiCom Firewall when the
Network Monitoring Option is installed.
Firewall such as loading new configurations,
activation or deactivation of IP services, errors. This
is the same event log as can be seen in the Monitor
software.
MultiCom Firewall User’s Manual 75
Page 76
Chapter 4 Maintenance
Below are some of the direct web links to commonly used diagnostic information
in older firmware versions. The following examples use the firewall’s default IP
address of 10.0.0.1. If your firewall is using a different IP address use that in
place of the 10.0.0.1.
Table 7: Common web server diagnostics pages for firmware 3.0-3.3
MultiCom Serial numberhttp://10.0.0.1/config/system/hardware/
Software versionhttp://10.0.0.1/config/system/software/
LAN statushttp://10.0.0.1/config/interface/ethernet[LAN]/stat
LAN DHCP server leaseshttp://10.0.0.1/config/interface/ethernet[LAN]/ip/d
WAN statushttp://10.0.0.1/config/interface/ethernet[WAN]/stat
WAN DHCP client statushttp://10.0.0.1/config/interface/ethernet[WAN]/ip/
PPPoE statushttp://10.0.0.1/config/i nterface/ppp[PPPoE]/status/
PPPoE IP statushttp://10.0.0.1/config/interface/ppp[PPPoE]/ipcp/st
PPPoE Link statushttp://10.0.0.1/config/interface/ppp[PPPoE]/lcp/sta
Available PPPoE servershttp://10.0.0.1/config/interface/ppp[PPPoE]/pppoe/
PPTP Statushttp://10.0.0.1/config/interface/ppp[PPTP]/status/
PPTP Link statushttp://10.0.0.1/config/interface/ppp[PPTP]/lcp/stat
ARP entrieshttp://10.0.0.1/config/arp/status/arp_entry/
DNS servers usedhttp://10.0.0.1/config/ip/dns/status/nameserver/
us/
hcp/server/status/leases/
us/
dhcp/client/status/
atus/
tus/
server_list/
us/
Using the above links will help you to find where a problem may be. For
example, if you have checked the WAN status or the PPPoE status and they both
have IP addresses assigned to them they are functioning normally and your
problem is probably somewhere else.
Monitor Status Reports
The Configurator software for your MultiCom Firewall includes detailed
monitoring windows. These diagnostic utilities give you the current st ate of your
firewall whether it is on a local or remote network.
76 MultiCom Firewall User’s Manual
Page 77
Monitor Status Reports
CAUTION - when accessing remote MultiCom Firewalls on the
Internet it is recommended to always use the Configurator in
“Secured” mode to protect the information exchanges.
With the monitoring options you will be able to get information on the System
status, ARP tables, DNS, each interface, DHCP services, installed routes and
more.
Optionally you could also have a syslog server set to listen for info level
announcements from the MultiCom Firewall and watch for alerts, warnings,
notices and other information.
1. To reach the monitoring screens of the Configurator you will need to first
start the Configurator from CD, hard disk or a remote drive. (see the section
on Starting Easy Setup or Installing the Configuration Software if you need
assistance in starting the Configurator).
2. Click search to search for the MultiCom Firewall on your local netw ork or
just enter the IP address of the firewall you wish to monitor
3. Be sure “Online” and “Secured” buttons are checked and click on the
Monitor button
4. You should now have arrived at the screen titled Monitor. Depending on
what sort of diagnostics you are looking for, go to the appropriate screen.
MultiCom Firewall User’s Manual 77
Page 78
Chapter 4 Maintenance
You should now have arrived at the screen titled Monitor. Depending on what
sort of diagnostics you are looking for, go to the appropriate screen.
PanelsAvailable Information
SystemGeneral information about the hardware, firmware
and work load of your MultiCom Firewall.
ARPThe currently active ARP table in the firewall
DNSThe currently active DNS servers for the firewall
Dynamic DNSThe current status of a Dynamic DNS configuration if
InterfacesStatus of each interface port (LAN/WAN), identifying
DHCPClient Window— shows all of the configuration data
PPPDescribes current status of PPPoE interfaces if they
RoutesThe currently active routes in your firewall
BridgesDisplays information about the LAN-WLAN bridge
78 MultiCom FirewallUser’s Manual
one exists
information, and data traffic reports
received from a DHCP server
Server Window — shows currently assigned IP
addresses and their lease times.
are active
of your MultiCom Firewall when the Bridge is
activated.
Page 79
Telnet/ Console Status Reports
PanelsAvailable Information
IPSecStatus of selected IPSec connections and summary of
all IPSec connections (when IPSec options are
installed)
PKIStatus of PKI Keys, Certificates and Certificate
VRRPStatus of High Availability on each interface (when
MonitorStatus and delay of each listed service host (when
Event LogEvents being generated by the MultiCom Firewall
Revocation Lists installed on the Firewall (when
IPSec optionsa are installed)
the High Availability option is installed)
Network Monitoring options are installed)
Telnet/ Console Status Reports
By logging into the Firewall’s telnet, SSH telnet or console interface (check your
User’s Manual to see if your firewall has a console interface) you can run the
“info” commands to get a text status information of particular parts of the
MultiCom Firewall and its software.
This used with telnet scripting utilities (such as the Expect software for Linux and
Windows, or CatTools for Windows at http://www.kiwisyslog.com) for reports
and automated management of the MultiCom Firewalls.
Table 8: Common telnet/ console diagnostics
DescriptionCommandsSample output
last error
causing reboot
MultiCom
Serial number
Software
version
LAN status/: info interface ethernet LAN
LAN IP
Address
/: backtraceonly available in 3.5+
/: info system hardware
serial_number
/: info system software firmwarefirmware = 3.6
status status
/: info interface ethernet LAN
status ip_address
serial_number =
LI-MU7-CH-0200D2
status = UP RUNNING
ip_address = 10.0.0.1
LAN DHCP
Mode
/: info interface ethernet LAN ip
netmask
/: info interface ethernet LAN ip
dhcp mode
MultiCom Firewall User’s Manual 79
netmask = 255.0.0.0
mode = server
Page 80
Chapter 4 Maintenance
DescriptionCommandsSample output
LAN DHCP
server leases
WAN status/: info interface ethernet WAN
WAN DHCP
client status
PPPoE status/: info interface ppp PPPoE status
PPPoE IP
address
PPPoE IPCP
info
PPPoE Link
status
/: info interface ethernet LAN ip
dhcp server status leases
/: info interface ethernet LAN ip
dhcp server status leases 0 ip
/: info interface ethernet LAN ip
dhcp server status leases 0
hw_address
/: info interface ethernet LAN ip
dhcp server status leases 0 starts
/: info interface ethernet LAN ip
dhcp server status leases 0 ends
/: info interface ethernet LAN ip
dhcp server status leases 0
hostname
status status
/: info interface ethernet WAN ip
dhcp client status state
status
/: info interface ppp PPPoE status
ip_address
/: info interface ppp PPPoE ipcp
status state
/: info interface ppp PPPoE lcp
status info
indexes: 0 1 2 3
ip = 10.0.0.17
hw_address =
00:c0:f0:4c:a7:90
starts = 4 2001/06/28
13:24:06
ends = 4 2001/06/28
14:24:06
hostname =
"NT-workstation"
status = UP RUNNING
state = Assigned
status = UP RUNNING
ip_address =
212.147.17.76
state = UP
state = DOWN
info = ""
info = CHAP
authentication failed
PPPoE DNS
assigned
servers
80 MultiCom FirewallUser’s Manual
/: info interface ppp PPPoE ipcp
status primary
/: info interface ppp PPPoE ipcp
status secondary
info = Timeout sending
Config-Requests
info = Endpoint not
connected
primary =
212.147.10.10
secondary =
212.147.0.1
Page 81
Telnet/ Console Status Reports
DescriptionCommandsSample output
Available
PPPoE servers
ARP entries/: info arp status arp_entryindexes: 0 1 2
DNS servers
used
The console interface is useful if you may have blocked your Ethernet interface
access or think there may be a problem with your Ethernet network (your
computer’s Ethernet interface, a hub/ switch, cabling). Simply configure your
workstations serial port according to the Console Configuration in the Hardware
Specification chapter and plug in the serial cable to your MultiCom Firewall and
workstation’s 9pin serial port. This gives direct access to the firewall.
/: info interface ppp PPPoE pppoe
server_list
/: info interface ppp PPPoE pppoe
server_list 0
access_concentrator_name
/: info interface ppp PPPoE pppoe
server_list 0 service_name
/: info arp status arp_entry 0
hw_address
/: info arp status arp_entry 1
hw_address
/: info ip dns status nameserver 0
ip
/: info ip dns status nameserver 1 ipip = 192.168.1.116
indexes: 0 1 2
access_concentrator_na
me = ipc-lsp690-r-l c-01
service_name = Any
hw_address =
00:C0:F0:57:4A:6D
hw_address =
00:C0:F0:4C:A7:90
ip = 192.168.1.115
MultiCom Firewall User’s Manual 81
Page 82
Chapter 4 Maintenance
Table 9: Common telnet/ console commands
DescriptionCommands
ENABLE IPSEC set security ipsec enabled=true
saveconfig current
DISABLE IPSEC set security ipsec enabled=false
SEE IPSEC
CONNECTIONS
STOP AN IPSEC
CONNECTION
START AN IPSEC
CONNECTION
ENABLE
SECUREWALL
DISABLE
SECUREWALL
ENABLE FILTERINGset ip filtering enabled=true
DISABLE
FILTERING
ENABLE FILTERING
OBJECTS
DISABLE
FILTERING
OBJECTS
ENABLE DNS
PROXY
DISABLE DNS
PROXY
ENABLE RIPset routing ip rip enabled=true
DISABLE RIPset routing ip rip enabled=false
ENABLE FTPset ip ftp server enabled=true
DISABLE FTPset ip ftp server enabled=false
ADD SYSLOG
SERVER
ENABLE SYSLOG
DEBUG OUTPUT
saveconfig current
ipsec
ipsec terminate <connection name>
ipsec initiate <connection name>
set interface ethernet WAN ip nat securewall=true
saveconfig current
set interface ethernet WAN ip nat securewall=false
saveconfig current
saveconfig current
set ip filtering enabled=false
saveconfig current
set ip filtering_objects enabled=true
saveconfig current
set ip filtering_objects enabled=false
saveconfig current
set ip dns proxy enabled=true
saveconfig current
set ip dns proxy enabled=false
saveconfig current
saveconfig current
saveconfig current
saveconfig current
saveconfig current
add ip syslog server 0
set ip syslog server 0 address=10.0.0.2 level=debug
saveconfig current
In addition to the Web server, Monitor and Telnet/ Console Status reports, the
MultiCom Firewall has 3 other methods for informing you what is happening and
if something is wrong.
•LED light messages
•Syslog messages
•SNMP messages
LED Light Messages
The LED lights on the front of your MultiCom Firewall are designed to give you
a quick update on the current status of your firewall. Some of the things you can
find out from your Interface LED lights (labeled LAN, WAN or DMZ) are
•If an ethernet interface is properly connected (a solid green light)
•If an interface is not connected (a solid red light)
•If data is traversing the interface (when the active port blinks orange, data is
traveling through that interface)
•If there are collisions occurring on the firewall (the light blinks red)
Starting with Lightning-Linux 3.3 the Security LED is also functional and will
show:
MultiCom Firewall User’s Manual 83
Page 84
Chapter 4 Maintenance
•If SecureWall is activated (a solid green light)
•If SecureWall is deactivated but SPI Filtering is activated (a solid orange
light)
•If both SecureWall and Filtering are deactivated (a solid red light)
Syslog Messages
Syslog messages can be configured to be sent from the firewall to a syslog server.
Please refer to the SNMP & Syslog chapter of the Reference Manual if you wish
to use this functionality.
Some common, Syslog messages are:
•Telnet, ssh, and web logins, logouts and failures
•Failed and successful attempts to save a configuration file to the firewall
•IPSec activity
•Network Monitoring activity
•Network Monitoring activity
•Email activity
•DHCP activity
•PPPoE activity
•PPTP activity
•Stateful Packet Inspection (SPI) activity
•SecureWall dropped packets
•Startup of firewall
SNMP Messages
The MultiCom firewall can be configured to respond to SNMP requests from
SNMP client software. Please refer to the SNMP & Syslog chapter of the
Reference Manual if you wish to use this functionality.
Some common SNMP requests will show:
•Hostname and Linux firmware version
•Uptime
•Customizable location and contact information
•detailed information on each Ethernet interface
84 MultiCom Firewall User’s Manual
Page 85
Configurator messages
•detailed IP/UDP/ICMP packet statistics
•connection state for ports on the MultiCom Firewall and IP address of who is
using that port (for instance for telnet or SSH CLI access)
•statistics on SNMP data requests
•route and ARP data stored on the MultiCom Firewall
Configurator messages
If you choose to use the Configurator Software, it also has a log window that lists
successful activity and errors of the Configurator software. These error messages
will explain if anything has gone wrong while using the Configurator software
and will help identify what is causing the problem. The information in this
window can be cut and paste for printing or emailing to Technical Support.
To see the Log window click on the Tools Menu and select the Show Log
command.
The error messages from the Configurator allow you to cut and paste the text in
most operating systems. Check with your operating system for it’s method of
cutting and pasting text into different windows.
Web Server Toolbox
The MultiCom Firewall offers a live toolbox for common maintenance activities.
You just type in the IP address of the firewalls LAN or WAN interface (by default
http://10.0.0.1), enter any necessary user names and passwords (by default
user=“multicom” and there is no password), and click on the Toolbox menu item.
The following tools are available:
Choose which language to see the web interface in or
choose AUTO to select the language based on the
language the web browser is configured to use.
Enter the new date and time for the MultiCom
Firewall
T ells the MultiCom Firewall where the upgrade
firmware is and to start the upgrade process.
Reboots the MultiCom Firewall using the
configuration in the “boot” memory position
This will delete all passwords, security parameters,
option keys and configuration files and reboot with
the factory default configuration
features like Virtual Private Networks using IPSec or
SSH Port Forwarding.
Web Server Advanced Tools
The MultiCom Firewall offers an configuration window for advanced
maintenance activities. You just type in the IP address of the firewalls LAN or
WAN interface (by default http://10.0.0.1), enter any necessary user names and
passwords (by default user=“multicom” and there is no password), and click on
the Advanced menu item. The following tools are available:
ToolsFunction
Configuration
Tools
Firewall
Configuration
Status
86 MultiCom FirewallUser’s Manual
Edit a live configuration, upload a new configuration
from a text file, or save the current configuration to a
text file.
Advanced statistics about IP Services, Interfaces,
Security, ARP, Routing, and the current system
hardware and software.
Page 87
Backup Your Configuration
ToolsFunction
User
Configuration
Manage IPSec
Connections
SecurityEdit a live security configuration, upload a new
URL Filtering
List
Create, edit or delete users and permissions on the
MultiCom Firewall. Additionally you can login as a
different user from this window. See the Reference
Manual chapter on Concepts for explanations on the
different users and rights.
Enable, disable or remove IPSec connections.
Requires an IPSec option to be installed.
security configuration from a text file, or save the
current security configuration to a text file. The
security configuration contains the keys for creating
IPSec tunnels. Additionally configure IPSec PKI
keys and certificates here.
Enable or disable URL Filtering and directly edit the
URL keyword list. Additional options are available
when using the Configurator software.
Backup Your Configuration
It is important to maintain a backup of your configuration file in case of
emergencies. This can easily be done with the built-in web server.
1. Start web browser software and go to http://10.0.0.1/advanced/config/ where
10.0.0.1 is the IP Address of the MultiCom Firewall’s LAN interface.
2. Click on “Save current configuration” (if a question appears asking what to
do with the file select “Save this file to disk”.)
3. Enter in the name you want to save the configuration backup under and the
directory location.
4. Click Ok
The file saved is a text file that you can save to a floppy or attach to an email.
MultiCom Firewall User’s Manual 87
Page 88
Chapter 4 Maintenance
Restoring A Configuration
When you need to restore a saved configuration file to your MultiCom Firewall
firewall you will use the built in web server or the included Configurator
software.
1. Start web browser software and go to http://10.0.0.1/advanced/config/upload/
where 10.0.0.1 is the IP Address of the MultiCom Firewall.
2. Enter the directory and name where the saved configuration file resides.
Optionally use the Browse... button to search for the file on your hard disk.
3. Click Submit Values
NOTE - During the application of a new configuration or while an
MultiCom Firewall is loading a new configuration during bootup the
routing table is blocked. This allows all of the rules to be loaded
before traffic can move through the firewall.
Updating Your Firmware
Because your MultiCom Firewall has been equipped with flash memory it is
possible for you to update it with a newer operating system (also known as
firmware) than was available when you purchased it.
NOTE — Contact your distributor or check the Lightning web site for
notifications on the latest firmware. Additional charges may apply.
Upgrading the firmware on your MultiCom Firewall requires you to access the
web server on the firewall. Your configuration files will remain untouched
however the factory default configuration may change (this configuration is
accessed when rebooting the Firewall while holding down the config button.)
Your MultiCom Firewall will reboot and be offline for up to 5 minutes during the
upgrade process. Be sure that your network can afford to be without Internet
access for at least 5 minutes and that there are no important data transfers
occurring during this time.
88 MultiCom Firewall User’s Manual
Page 89
Updating Your Firmware
CAUTION - Please note, that if the power is interrupted during the
upgrade process your MultiCom Firewall could become unusable and
require repairs from your local distributor. Continue at your own risk.
To install the latest firmware follow the steps below. Please check the Support
website for the latest version of the MultiCom Firmware Upgrade instructions.
MultiCom Firewall User’s Manual 89
Page 90
Chapter 4 Maintenance
Table 10: Steps to Upgrade MultiCom Firmware
1. Download the latest firmware
to your computer
2. Access the MultiCom Firewall
web server. Simply type in the
IP Address of the MultiCom
Firewall into an Internet
browser which is connected to
the same network as the
MultiCom (usually this is the
LAN interface).
3. Type in your username and
password (by default the
username is "multicom" and
there is no password.)
4. Select Toolbox (or MultiCom
Tools in firmware versions
before 3.4)
5. Select Update the Firmware
6. Type in the location of the new
firmware file or click
Browse to
find the file on your hard disk.
If you use
Browse you may
need to choose “All Files (*.*)
in the Type: box if you cannot
see the firmware.
7. Select Update Firmware after
you have selected the firmware
file to update with.
90 MultiCom FirewallUser’s Manual
Page 91
8. The Web server will verify that
the firmware is indeed valid
before writing it to the device.
If it is valid you will see the
button
Write New Firmware,
press this button. Otherwise
you are asked to reload the
firmware.
If the web server gives you an
error or does nothing then try
using a different web browser or
check with your distributor for
another copy of the firmware.
NOTE - this step is skipped in
firmware versions 3.1 and
higher. If the firmware is
good you will jump to step 9
and write the new firmware. If
the firmware is bad your router
will reboot with the previous
firmware.
Steps to Upgrade MultiCom Firmware
MultiCom Firewall User’s Manual 91
Page 92
Chapter 4 Maintenance
9. The MultiCom Firewall now
begins the process of erasing
the old firmware and writing
the new firmware. Wait for
the MultiCom Firewall to
reboot with the new firmware
upgrade. The lights on the
front of the device will change
colors during the upgrade
process and will stop blinking
after the MultiCom Firewall
has rebooted.
WARNING - While the firmware
upgrade is being written do not
interrupt the power to the
MultiCom Firewall!
10. You are finished. Verify that
your new version of
Lightning-Linux firmware is
currently installed in your
MultiCom Firewall. In your
web browser go to
http://10.0.0.1/config/system/so
ftware/ where 10.0.0.1 is the IP
Address of your MultiCom
Firewall.
LED Status During Upgrade
Starting with Lightning-Linux 3.1 the leds on the front of your MultiCom
Firewall indicate the status of the firmware upgrade according to the table below.
92 MultiCom Firewall User’s Manual
Page 93
LED Status during upgrade
Table 11: LED Status during upgrade
StatusDescription
Checking the validity of the
firmware
Erasing existing flash
memory
Writing the new firmware
into the flash memory
Error while erasing the
existing flash memory
Error while writing the new
firmware to flash memory
All of the leds are lit green except the power
led which is blinking green and black.
All of the leds are lit green except the power
led which is blinking orange and black.
All of the leds are lit green except the power
led which is blinking orange and green.
All of the leds are blinking red and orange.
All of the leds are blinking red and black.
Troubleshooting Firmware Upgrade
If power is interrupted during the flash upgrade process the existing firmware
could become corrupted. Normally this will be evident because the lights are
frozen every time you reboot the MultiCom Firewall and it will not respond to
normal networking activity. To recover from this please contact your local
distributor. If after a reboot you have the same firmware version that was
previously installed then there was a problem with the firmware upgrade. Try
reinstalling it again, rebooting the MultiCom Firewall into the default
configuration and then try reinstalling again, download or contact your distributor
for another copy of the firmware.
Remember that you will need to upgrade the Config urat or software to the same
version of the firmware that you just installed.
MultiCom Firewall User’s Manual 93
Page 94
Chapter 4 Maintenance
94 MultiCom Firewall User’s Manual
Page 95
Troubleshooting
When you are running a network (whether one computer connected directly to the
Internet or many) it is possible that problems can come up. Maybe the network is
giving you slow responses, some devices or computers are not reachable, you are
reaching the wrong computer or your filters do not seem to be working. This
chapter will help you fix some common networking issues.
To correctly fix the problem the source of it must be found. In networking this is
especially true because the problem may not necessarily point you toward the
answer (for instance a bad DNS server would stop you from reaching web
addresses but not if you only used the IP address.)
Chapter 5
There are two questions you must always check...
1. Were the instructions followed correctly
2. Has anything recently changed before the problem occurred? (for instance
are you using new network drivers, new workstation on the network...)
If these two questions do not help you find the problem then it is time to do some
troubleshooting with the firewall itself.
MultiCom Firewall User’s Manual 95
Page 96
Chapter 5 Troubleshooting
Basic Things To Check
Always check that your cabling and basic connections are functioning correctly
for the ports you are using. If there is a problem moving your data back and forth
at this level then higher level troubleshooting will be ineffective.
•Are the cables correct (crossed cable versus straight cable.)
•Are the interface lights (LAN, WAN, DMZ) on the firewall green when the
cables are plugged into your ethernet card/interface or xDSL, cable or
wireless modems?
•Are the lights on the hub or ethernet interface of the device green where the
firewall cable is plugged in.
These answers must be yes before you do any more in-depth troubleshooting. If
there are problems here and you are using a hub, be sure to verify that you are not
using the uplink port. Otherwise try verifying the ethernet device is functioning
correctly and try switching the ethernet cable to one that you know is good.
If all of the physical connections are good (as tested above) the next steps is to
verify that you can:
1. from your computer, communicate with the LAN interface of the MultiCom
Firewall
2. from the MultiCom Firewall, communicate with your ISP
3. from your computer, communicate with the Internet
TIP - A simple troubleshooting step is to reboot the MultiCom Firewall
and try again. If all else fails, reset the Firewall into the default mode
as described in the “Resetting the Default Configuration” Section on
page 105. Then reconfigure it using the Easy-Setup.
After checking these basic issues please continue to the Common Network
Problems on the next page which describe some common problems that may
occur on your Local Network.
Finally, look at the sections below that corresponds to the type of connection that
your ISP uses - DHCP, PPPoE, PPTP. These sections will explain common
problems on the Remote Network that connects you to your ISP and the Internet.
If you are still having problems consider calling technical support.
96 MultiCom Firewall User’s Manual
Page 97
Common Local Network Problems
Common Local Network Problems
Please look over these common reasons for networking problems. Additionally,
please check the section below relating specifically to your type of connection
(DHCP, PPPoE, PPTP, Static IP addresses.)
Once you know that your cabling is okay it is time to ask some more detailed
questions.
•Is the modem working? (check the diagnostics that came with the modem,
maybe you can check LED displays or communicate directly with the
modem)
•Is TCP/IP installed on your computer? (if you can ping 127.0.0.1 in a telnet
window/ DOS window TCP is installed)
•Is the firewall reachable? (using the ping command for instance in a telnet
window/ DOS window and try PING 10.0.0.1 where 10.0.0.1 is the IP
Address of your MultiCom Firewall’s LAN interface.) Sometimes a Filter or
recent configuration change can block access to the Firewall.
•Did you try using an IP address (such as http://193.247.134.2) to reach a web
site. If it does then your DNS is not reachable and you should check with
your Internet Service Provider.
•Is there another DHCP server on your Local Network in addition to the one
on the MultiCom Firewall? If so you can only have one so you must disable
one of them.
•Were you using an analogue modem before connecting the Broadband
modem? Maybe you forgot to change the Internet Options of Windows. Be
sure that under the Control Panels>Internet Connections>Connections the
“Never dial a connection” is activated or your computer will keep trying to
use the modem.
•If you are using more than one Ethernet card on your computer be sure that
you do not have more than one default route.
•Are there other devices on your network using the same IP Address as the
MultiCom Firewall’s LAN interface (10.0.0.1) the IP Addresses being given
by the Firewall’s DHCP server?
•If you are using a Static IP on your Local Network make sure that each of
your workstations are configured to be on the same subnet as the MultiCom
Firewall and use the Firewall as their default Gateway.
MultiCom Firewall User’s Manual 97
Page 98
Chapter 5 Troubleshooting
DHCP Troubleshooting
DHCP To The Internet
With DHCP configured for your WAN interface your MultiCom Firewall sends
out discovery packets looking for a DHCP server to give it an IP configuration. If
a DHCP server is not found then the WAN interface is not enabled (i.e. you
cannot reach the Internet.)
Some common connection problems are...
•DHCP is not being used by your Internet Service Provider
•your cabling is incorrect
•your modem is not configured as a bridge
•you changed the time on the MultiCom Firewall but did not reboot
•your WAN and LAN interfaces are using the same IP address range
To check the status of your WAN interface using DHCP visit the WAN DHCP
client status web page using the web server diagnostic pages (found at “Web
Server Status Reports” on page 74.) Also be sure to check the IP configurat ion
received by your workstations and that the firewall IP address received is the IP
address of your MultiCom Firewall (the default setting is 10.0.0.1).
Table 12: WAN DHCP client status states
State of the interfacePossible problem
DisabledDHCP is not enabled for this interface.
ExpiredThe existing IP configuration has expired without it
being renewed. Check that firewall was rebooted
after changing the time.
Trying to get addressThe firewall is in the process of trying to get an IP
configuration from the Internet Service Provider.
FailedThe attempt to contact a DHCP server failed, check
all troubleshooting steps.
AssignedThe DHCP interface is functioning correctly.
RebindNormal DHCP activity, check back soon to see if
the state is Assigned or Failed.
RenewNormal DHCP activity, check back soon to see if
the state is Assigned or Failed.
DHCP is not being used by your Internet
98 MultiCom Firewall User’s Manual
Page 99
Your cabling is incorrect
Service Provider
Verify that your Internet Service Provider uses DHCP to configure your
connection to them. Other possible connections may be PPPoE or a static IP
configuration.
State: Trying to get address or State: failed or State: Assigned or State:
Expired
Your cabling is incorrect
Be sure that the WAN interface light on your MultiCom Firewall is green.
If it is not you either have the wrong cable, a faulty cable or the broadband
modem is not plugged in. Try switching cables and verify that the modem is
indeed turned on.
Your modem is not configured as a bridge
Your broadband modem must be configured as a bridge for you to connect
directly to your Internet Service Provider. Verify with the instruction
manual of your modem that it is indeed configured as a bridge. If the two
above steps are not showing a problem this may be your problem.
You changed the time on your firewall but did
not reboot.
The default date of your MultiCom Firewall is January 1970. DHCP works
on a lease system where IP configurations are good for a specified amount
of time. When the original lease runs out your MultiCom Firewall will
attempt to renew its IP configuration information but will erroneously report
that the IP configuration has expired (since the current date is now more
then 30 years in the future.) The easiest fix for this is to reboot the
MultiCom Firewall and it will make a fresh request using the new time.
Your WAN and LAN interfaces are using the
same IP address range
This will normally only happen office to office connections since the default
IP range of 10.0.x.x for your LAN network is never used on the Internet.
Check that the WAN network is not assigning address in the 10.0.x.x range
MultiCom Firewall User’s Manual 99
Page 100
Chapter 5 Troubleshooting
and if it is change either the LAN or the WAN network so that one of them
uses a different range of IP addresses. For example, reconfigure your LAN
address range to be from 192.168.0.2-192.168.0.100.
DHCP On Your Local Network
Using DHCP on to manage your own network’s IP addresses makes
administration convenient. The most common problem is that a device is unable
to receive an IP configuration from the DHCP server (normally your MultiCom
Firewall. Below are some reasons this might happen.
•your workstations are not configured as DHCP clients
•there are not enough IP addresses for your computers
•there is another DHCP server on your network
•there is another device on your network with the same IP address as your
firewall
•you changed the time on the MultiCom Firewall but did not reboot
Be sure to check the LAN DHCP server leases page to see what IP addresses have
been assigned and their status. These require using the web server diagnostic
pages found at “Web Server Status Reports” on page 74.
Your workstations are not configured as
DHCP clients
Check that each workstation is configured as a DHCP client. For some
operating systems setting this configuration requires you to reboot your
workstation. Please refer to the section on Configuring your Computers or
to the manuals that came with your computer for instructions on configuring
this setting.
There are not enough IP addresses for your
computers
The default setting of the MultiCom Firewalls allows for up to 1,000 DHCP
clients. If you either need more than this or have customized your settings
please refer to the Lightning-Linux manual for more information.
There is another DHCP server on your
100 MultiCom Firewall User’s Manual
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.