NETGEAR is a trademark of NETGEAR, Inc.
Microsoft, Windows, andWindowsNT are registered trademarksof M icrosoft Corporation.
Other brand and product names are registered trademarks or trademarks of their respective holders.
Statement of Conditions
In the interest of improving internal design, operational function, and/or reliability, NETGEAR reserves the right to
make changes to the products described in this document without notice.
NETGEAR does not assume any liability that may occur due to the use or applicationof the product(s) or circuit
layout(s) described herein.
Federal Communications Commission (FCC) Com pliance Notice: Radio Frequency Notice
This equipment has been tested and found to comply with the limits for a Cl ass B digital device, pursuant to
part 15 of the FCC Rules. These limits are designed to provide reasonable protectionagainst harmful interferencein a
residential installation.This equipment generates, uses, and can radiate radio frequency energy and, if not installed and
used in accordance with the instructions,may cause harmful interferenceto radio communications. However,there is no
guaranteethat interferencewill not occur in a particular installation. If this equipmentdoescauseharmfulinterference to
radioor televisionreception,whichcan be determined by turningthe equipment off and on, the user is encouraged to try
to correct the interferenceby one or more of the following measures:
•Reorient or relocate the receiving antenna.
•Increasethe separation between the equipment and receiver.
•Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
•Consultthe dealer or an experiencedradio/TV technician for help.
EN 55 022 Declaration of Conformance
This is to certify that the Model FR314, FR318 and FV318 Cable/DSL Firewalland VPN Routers are shielded against
the generationof radio interference in accordance with the application of Council Directive 89/336/EEC, Article 4a.
Conformityis declared by t he application of EN 55 022 Class B (CISPR 22).
ii
Bestätigung des Herstellers/Importeurs
Es wird hiermit bestätigt, daß das M odel FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers gemäß der
im BMPT-AmtsblVfg 243/1991 und Vfg 46/1992 aufgeführten Bestimmungenentstörtist. Das vorschriftsmäßige
Betreibeneiniger Geräte (z.B. Testsender) kann jedoch gewissen Beschränkungen unterliegen. Lesen Sie dazu bitte die
Anmerkungen in der Betriebsanleitung.
Das Bundesamt für Zulassungen in der Telekommunikation wurde davon unterrichtet, daß dieses Gerät auf den Markt
gebracht wurde und es ist berechtigt, die Serie auf die Erfüllungder Vorschriften hin zu überprüfen.
Certificate of the Manufacturer/Importer
It is hereby certifiedthat the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers have been
suppressed in accordancewith the conditions set out in the BMPT-AmtsblVfg243/1991and Vfg 46/1992. The operation
of some equipment (for example,test transmitters)i n accordance with the regulations may,however, be subject to
certain restrictions. Please refer to the notes in the operating instructions.
FederalOffice for Telecommunications Approvals has been notified of the placing of this equipmenton the market
and has been granted the right to test the series for compliance with the regulations.
Voluntary Contro l Council for Interference (VCCI) Statement
This equipment is in the second category (informationequipment to be used in a residential area or an adjacent area
thereto)and conforms to the standards set by the Voluntary Control Council for Interference by Data Processing
Equipmentand Electronic Office Machines aimed at preventingradio interference in such residential areas.
When used near a radio or TV receiver, it may become the cause of radio interference.
Read instructions for correct handling.
Customer Support
Referto the Support Information Card that shippedwith your Model FR314, FR318 and FV318 Cable/DSL Firewall and
VPN Ro uters.
World Wide Web
NETGEAR maintains a WorldWide Webhome page that you can access at the universal resource locator (URL)
http://www.netgear.com. A direct connectionto the Internet and a Web browsersuch as Internet Explorer
or Netscape are required.
Congratulations on your purchase of the NETGEAR™Model FR314, F R318 or FV318 Cable/DSL
Firewall Router. The firewall router is a complete security solution that protects your network
from attacks and intrusions, filters objectionable Web content, and logs security threats.
This guide describes the features of the firewall router and provides installation and configuration
instructions.
Typographic al Conventions
This guide uses the following typographical conventions:
italicsBook titles and UNIX file, command, and directory names.
Initial CapsMenu titles and window and button names.
[Enter]Named keys in text are shown enclosed in square brackets. The notation
[Enter] is used for the Enter key and the Return key.
[Ctrl]+CTwo or more keys that must be pressed simultaneously are shown in text
linked with a plus (+) sign.
ALL CAPSDOS file and directory names.
About This G uidexv
Reference Guide for the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers
Special Message Formats
This guide uses the following formats to highlight special messages:
Note: This format is used to highlight information of importance or special interest.
Caution: This format is used to highlight information that will help you prevent
equipment failure or loss of data.
Warning: This format is used to highlight information about the possibility of injury or
equipment damage.
Danger: This format is used to alert you that there is the potential for incurring an
electrical shock if you mishandle the equipment.
Technical Support
For help with any technical issues, c ontact Customer Support at 1-888-NETGEAR, or visit us on
the Web a t www.NETGEAR.com. The NETGEAR Web site includes a n extensive knowledge
base, answers to frequently asked questions, and a means for submitting technical questions
online.
Related Publications
As you read this document, you may be directed to various RFC documents for further
information. An RFC is a Request For Comment (RFC) published by the I nternet Engineering
Task Force (IETF), an open organizationthat defines the architecture a nd operationof the Internet.
The RFC documents outline and define the standard protocols and procedures for the Internet. The
documents are listed on the World Wide Web at w ww.ietf.org and are mirrored and indexed at
many other sites worldwide.
xviAbout This Guide
Reference Guide for the Model FR314, FR318 and FV 318 Cable/DSL Firewall and VPN Routers
For more information about address assignment, refer to the IETF documents RFC 1597, Address
Allocation for Private Internets, and RFC 1466, Guidelines for Management of IP Address Space.
For more information about IP address translation, refer to RFC 1631, The IP Network Address
Translator (NAT).
About This Guidexvii
Chapter 1
Introduction
This chapter describes the features of the NETGEAR Model FR314, FR318 and FV318 Cable/
DSL Firewall and VPN R outers.
About the Ne tg ear Firewall/VPN Router
The Model FR314, FR318 or FV318 C able/DSL Firewall Router is a complete security solution
that protects your network from attacks and intrusions. The firewall router prevents theft,
destruction, and malicious tampering, filters objectionable Web content, and logs security threats.
Unlike simple Internet sharing routers, the firewall router uses stateful packet inspection, widely
considered as the most effective method of filtering IP traffic, to ensure secure f irewall filtering.
The Netgear Firewall/VPN Router is a flexible, high-performance, easy-to-use firewall router that
provides a secure and cost-effective solution for connecting your network of PCs to a single-user
broadband line, such as a cable modem or DSL modem. When personal computers (PCs) on the
LAN need to communicate with locations on the Internet, the PCs send requests to the firewall
router. The firewall r outer translates those requests so that the requests appear to originate from a
single PC, rather than from a network of PCs. The firewall router delivers the requests to the
external access device for transmission to the Internet.
The FR314 and FR318 Firewall Routers allow Internet access for up to eight users. Optional
upgrades may be purchased for a total of 20 users or 45 users. The FV318 VPN Router allows
Internet access for up to 20 users, with an optional upgrade available for a total of 45 users.
A VPN upgrade may be purchased to give the FR318 Firewall Router VPN capability for
establishing a single VPN connection. The FV318 VPN Router is capable of five VPN
connections.
Introduction1-1
Reference Guide for the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers
Key Features
The Netgear Firewall/VPN Router offers the following features.
A Powerful, True Firewall
Unlike simple Internet sharing routers, the Netgear Firewall/VPN Router is a true firewall, using
stateful packet inspection to defend against hacker attacks, and lets you define rules for Internet
access and content viewing. Its firewall features include:
•Denial of Service (DoS) protection
Automatically detects and thwarts Denial of Service ( D oS) attacks such as Ping of Death,
SYN Flood, LAND Attack and IP Spoofing.
•Blocks unwanted traffic from the Internet to your LAN.
•Blocks access from your LAN to Internet locations that you specify as off-limits
•Logs and reports attempted breaches of security or access restrictions.
Virtual Private Networking (VPN)
The FR318 (with optional VPN upgrade) and the FV318 provide secure, encrypted
communication between your local network and a remote network or client. Once you have
created a VP N Security Association to a remote site, the firewall router can automatically encrypt
data and send it over the Internetto the remote site, where it will be decrypted and forwarded to the
intended destination.
The FR318 and FV318 support the IPSec standard for VPNs, using up to 168 bit encryption for
maximum security.
Content Filtering
With its content filtering features, the Netgear Firewall/VPN Router prevents objectionable
content from reaching your PCs. Its content filtering features include:
1-2Introduction
Reference Guide for the Model FR314, FR318 and FV 318 Cable/DSL Firewall and VPN Routers
•Content filtering by subscription
The Netgear Firewall/VPN Router uses content filtering to enforce your network’s Internet
access policies. You can use the Content Filter List to block Web sites by category, such as
pornography or racial intolerance. Since content on the Internet is constantly changing, the
firewall router automatically updates the Content Filter List every week to ensure that access
restrictions to new and relocated sites are properly enforced.
•Content filtering by domain or keyword
In addition to filtering by the Content Filter List, the Netgear Firewall/VPN R outer allows you
to control access to Internet content by specifying Trusted or Forbidden domains, or by
screening for keywords within Web URLs.
•Protocol filtering
In addition to filtering access to Web sites, the Ne tgear Firewall/VPN Router can also block
ActiveX, Java, cookies, and Web proxies.
•Logging of security incidents and inappropriate use
You c an configure the Netgear Firewall/VPN Router to log and block access to objectional
Web sites, or to log inappropriate usage without blocking access. You can decide how often
you want to view the log, or direct the firewall router to send the log to you at a specified
e-mail address at specified intervals. You can configure the firewall router to send alert
messages to your e-mail address or e-mail pager whenever a high-priority event (including
attacks, system errors, and blocked Web sites) occurs.
Configurable Ethernet Connection
With its internal, 4-port (FR314) or 8-port (FR318 and FV318) 10/100 switch, the firewall router
can connect to either a 10 Mbps standard Ethernet network or a 100 Mbps Fast Ethernet network.
The local LAN interface is autosensing and is capable of full-duplex or half-duplex operation.
TM
The 8-port Netgear Firewall/VPN Routers incorporate Auto Uplink
Ethernet port will automatically sense whether the Ethernet c able plugged into the port should
have a 'normal' connection (e.g. connecting to a PC) or an 'uplink' connection (e.g. connecting to a
router, switch, or hub). That port will then configure itself to the correct configuration. This feature
also eliminates the need to wor ry about crossover cables, as Auto Uplink will accommodate either
type of cable to make the right connection.
technology. Each LOCAL
Protocol Support
The Netgear Firewall/VPN Router supports the Transmission Control Protocol/Internet Protocol
(TCP/IP) and Routing Information Protocol (RIP). Relevant features include:
Introduction1-3
Reference Guide for the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers
•IP address masquerading by dynamic NAT+
The firewall router allows several networked PCs to share an Internet account using only a
single IP address, which may be statically or dynamically assigned by your Internet service
provider (ISP). This technique, an extension of Network Address Translation (NAT), is also
known as IP address masquerading and allows the use of an inexpensive single-user ISP
account.
•Port forwarding (Public Servers)
The firewall router performs port-address translation. With this feature, you can direct
incoming traffic to be forwarded to specific local PCs, based on the service port of the
incoming request.
•Automatic configuration of attached P Cs by DHCP
The firewall router dynamically assigns network configuration information, including
IP, gateway, and domain name server (DNS) addresses, to attached PCs on the LAN using the
Dynamic Host Configuration Protocol (DHCP). This feature greatly simplifies configuration
of LAN-attached PCs.
•PPP over Ethernet
PPP over Ethernet (PPPoE) is a protocol for connecting remote hosts to the Internet over an
always-on connection by simulating a dial-up connection. The firewallrouter incorporates and
automatically launches a PPPoE client so that the user does not ne ed to manually log in for
Internet access.
Easy Installation and Management
You c an install, configure, and operate the Model FR314, FR318 or FV318 f irewall router within
minutes after connecting it to the network. The following fe atures sim plify installation and
management tasks:
•Browser-based management
Browser-based configuration allows you to easily configure your firewall router from almost
any type of personal computer, such as Windows, Macintosh, or Linux. A user-friendly Setup
Wizard is provided and online help documentation is built into the browser-based Web
Management Interface.
•Visua l monitoring
The firewall router’s front panel LEDs provide an easy way to monitor its status and activity.
Maintenance and Support
NETGEAR offers the following features to he lp you maximize your use of the firewall router:
1-4Introduction
Reference Guide for the Model FR314, FR318 and FV 318 Cable/DSL Firewall and VPN Routers
•Flash EPROM for firmware upgrade
•Five-year warranty, two years on power adapter
•Free technical support seven days a week, twenty-four hours a day
Introduction1-5
Reference Guide for the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers
1-6Introduction
Chapter 2
Setting Up the Hardware
This chapter describes the Netgear Firewall/VPN Router hardware and provides instructions for
installing it.
Package Contents
The product package should contain the following items:
•Model FR314, FR318 or FV318 Cable/DSL Firewall Router
•Model FR314, FR318 and FV318 Resource CD, including:
— This guide
— Application Notes
— Configuration and Troubleshooting Guides
•FR314, FR318 and FV318 Cable/DSL Firewall and VPN Router Installation Guide
•Registration and Warranty C ard
•Support Information Card
If any of the parts are incorrect, missing, or damaged, contact your NETGEAR dealer. Keep the
carton, including the original packing materials, in case you need to return the firewall router for
repair.
SettingUptheHardware2-1
Reference Guide for the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers
Local Network Hardware Requirements
The Netgear Firewall/VPN Router is intended for use in a network of pe rsonal computers (PCs)
that are interconnected by twisted-pair Ethernet cables.
PC Requirements
To install and run the firewall router over your network of PCs, each P C must ha ve the following:
•A connection to the network via a hub or switch. If all PCs on the network will not run at the
same speed (10 Mbps or 100 Mbps), you need to use a dual-speed hub or switch. The firewall
router provides a 4-port (FR314) or 8-port (FR318 and FV318) switch capable of either 10
Mbps or 100 Mbps operation. Links operating at 100 Mbps must be connected with Category
5cable.
Access Device Requirement
The shared broadband access device (cable modem or DSL modem) must provide a standard
10BASE-T Ethernet interface.
2-2Setting Up the Hardware
Reference Guide for the Model FR314, FR318 and FV 318 Cable/DSL Firewall and VPN Routers
The Firewall Router ’s Front Panel
The front panel of the Model FR314, FR318 or FV318 firewall router (Figure 2-1) contains status
LEDs.
Figure 2-1.FR314 Front Panel
You c an use some of the LEDs to verify connections. Table 2-1 lists and describes each LED on
the front panel of the firewall router. These LEDs are green when lit, e xcept for the TES T LED,
which is amber.
Table 2-1.LED Descriptions
LabelActivityDescription
POWEROnPower is supplied to the firewall router.
TESTOn
Off
INTERNET
LINKOnThe Internet port has detected a link with an attached device.
ACT (Activity)BlinkingData is being transmitted or received by the Internet port.
LOCAL
LINK/ACT
(Link/Activity)
100 (100 Mbps)On
On
Blinking
Off
The system is initializing.
The system is ready and running.
The Local port has detected a link with an attached device.
Data is being transmitted or received by the Local port.
The Local port is operating at 100 Mbps.
The Local port is operating at 10 Mbps.
SettingUptheHardware2-3
Reference Guide for the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers
The Firewall Router ’s Rear Panel
The rear panel of the FR314 is shown in Figure 2-2. The FR318 and FV318 differ only in the
number of ports and the absence of an Uplink switch. Refer to this diagram to identify the firewall
router ports before attempting to make any connections.
Figure 2-2.FR314 Rear Panel
Connecting the Firewall Router
Before using your firewall router, you need to do the f ollowing:
•Connect your local Ethernet network to the LOCAL port(s) of the firewall router (described
next).
•Connect your cable or DSL modem to the INTERNET port of the firewall router (see page
2-6).
•Connect the power adapter (see page 2-6).
2-4Setting Up the Hardware
Reference Guide for the Model FR314, FR318 and FV 318 Cable/DSL Firewall and VPN Routers
Connecting to Your Local Ethernet Network
Your local network attaches to the firewall router ports that are marked LOCAL. The LOCAL
ports of the firewall router are capable of ope ration at either 10 Mbps (10BASE-T) or 100 Mbps
(100BASE-TX), depending on the Ethernet interface of the attached PC, hub, or switch. If a ny
connection will operate at 100 Mbps, you must use a Category 5 (Cat 5) ra ted cable, such as the
Ethernet cable included with your firewall router.
The Netgear Firewall/VPN R outer incorporates a 4-port (FR314) or 8-port ( FR318 and FV318)
switch for connection to your local network.
To connect the firewall router to your LAN:
1.Connec t your PCs directly to any of the LOCAL ports of the firewall router using standard
Ethernet cables.
2.(FR314) Verify that the NORMAL/UPLINK switch of the last LOCAL port is set to
NORMAL.
If your local network consists of more hosts than LOCAL ports, you need to connect your firewall
router to another hub or switch. For the FR314, this can be done using either of the following
methods:
Connect the F R314’s last LOCAL port to any normal port of an Ethernet hub or switch using
standard Ethernet cable. Push in the NORMAL/UPLINK switch of the firewallrouter to select
UPLINK.
OR
Connect any LOC AL port of your FR314 to the UPLINK port of an Ethernet hub or switch.
For the FR318 and FV318, connect any LOCAL port of your f irewall router to any port of an
Ethernet hub or switch. The LOCAL port will automatically configure itself for the uplink
connection.
Note: The Netgear Firewall/VPN Router incorporates Auto Uplink
TM
technology. Each LOCAL
Ethernet port will automatically sense whether the Ethernet c able plugged into the port should
have a 'normal' connection (e.g. connecting to a PC) or an 'uplink' connection (e.g. connecting to a
router, switch, or hub). That port will then configure itself to the correct configuration. This feature
also eliminates the need to wor ry about crossover cables, as Auto Uplink will accommodate either
type of cable to make the right connection.
SettingUptheHardware2-5
Reference Guide for the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers
Connecting to Your Internet Access Device
To connect the firewall router to the Internet (or WAN):
1.Connec t the firewall router’s INTERNET port to the 10BASE-T Ethernet port on your existing
Internet access device (your cable modem or DSL modem).
Note: The a ttached modem device m ust provide a standard 10BASE-T Ethernet connection. The
firewall router does not include a cable for this connection. Instead, use the Ethernet cable
providedwith your access device or any other standard 10BASE-T Ethernet cable. If you are using
a DSL modem, the modem’s connection to the phone line remains unchanged.
Note: The Ethernet cable supplied by your ISP for connecting to your cable or DSL modem may
be an Ethernet crossover cable rather than a straight-through cable. I t is importantto use this cable
to connect the modem to your router, not to connect your PCs to your router.
Connecting the Power Adapter
To connect the firewall router to the power adapter:
1.Plug the connector of the power adapter into the 12 VDC adapter outlet on the rear panel of the
firewall router.
2.Plug the other end of the adapter into a standard wall outlet.
3.Turn the Power switch to the ON position.
4.Verify that the POWER LED on the firewall router is lit.
Ve rify ing Connections
After applying power to the f irewall router, complete the following steps to verify the connections
to it:
1.When power is first applied, verify that the POWER LED is on.
2.Verify that the TEST LED turns on within a few seconds.
3.After approximately 90 seconds, verify that:
a.The TEST LED has turned off.
b.TheLOCAL LINK/ACT LEDs are lit for any local ports that are connected.
c.The INTERNET LINK/ACT LED is lit.
2-6Setting Up the Hardware
Loading...
+ 129 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.