NETGEAR is a trademark of Netgear, Inc.
Microsoft, Windows, and Wi ndow s NT are registered trademar ks of Microsoft Corporation.
Other brand and product names are registered trademarks or trademarks of their respective holders.
Statement of Conditions
In the interest of improving internal design, operational function, and/or reliability, NETGEAR reserves the right to
make changes to the products described in this document without notice.
NETGEAR does not assume any liability that may occur due to the use or application of the product(s) or circuit
layout(s) described herein.
Federal Communications Commission (FCC) Compliance Notice: Radio Frequency Notice
This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to
part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a
residential installation. This equipment generates, uses, and can radiate radio frequency energy and, if not installed and
used in accordance with the instruct ions, may cause harmf ul interference to radio communications. However, there is no
guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to
radio or television reception, which can be determined by turning the equipment off and on, the user is encouraged to try
to correct the interference by one or more of the following measures:
•Reorient or relocate the receiving antenna.
•Increase the separation between the equipment and receiver.
•Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
•Consult the dealer or an experienced radio/TV technician for help.
EN 55 022 Declaration of Conformance
This is to certify that the FVS114 ProSa fe VPN Firewall is shielded against the generation of radio interference in
accordance with the application of Council Directive 89/336/EEC, Article 4a. Conformity is declared by the application
of EN 55 022 Class B (CISPR 22).
Certificate of the Manufacturer/Importer
It is hereby certified that the FVS114 ProSafe VPN Firewall has been suppressed in accordance with the conditions set
out in the BMPT-AmtsblVfg 243/1991 and Vfg 46/1992. The operation of some equipment (for example, test
transmitters) in accordance with the regulations may, however, be subject to certain restrictions. Please refer to the notes
in the operating instructions.
Federal Office for Telecommunications Approvals has been notified of the placing of this equipment on the market
and has been granted the right to test the series for compliance with the regulations.
ii
202-10098-01, April 2005
Product and Publication Details
Model Number:FVS114
Publication Date:April 2005
Product Family:Router
Product Name:FVS114 ProSafe VPN Firewall
Home or Business Product:Business
Language:English
202-10098-01, April 2005
iii
iv
202-10098-01, April 2005
Contents
Chapter 1
About This Manual
Audience, Scope, Conventions, and Formats ................................................................1-1
How to Use This Manual ................................................................................................1-2
How to Print this Manual .................................................................................................1-3
Chapter 2
Introduction
Key Features of the VPN Firewall ..................................................................................2-1
A Powerful, True Firewall with Content Filtering ......................................................2-2
R ..................................... ........................................................................... ....................G-9
S ....................................................................................................................................G-9
T ....................................................................................................................................G-9
U ..................................... ........................................................................... ..................G-10
W .................................................................................................................................G-10
Contentsxi
202-10098-01, April 2005
xiiContents
202-10098-01, April 2005
Chapter 1
About This Manual
This chapter describes the intended audience, scope, conventions, and formats of this manual.
Audience, Scope, Conventions, and Formats
This reference manual assumes that the reader has basic to intermediate computer and Internet
skills. However, basic computer network, Internet, firewall, and VPN technologies tutorial
information is provided in the Appendices and on the NETGEAR Web site.
This guide uses the following typographical conventions:
Table 1-1.Typographical Conventions
italicsEmphasis, books, CDs, URL names
boldUser input
fixed Screen text, file and server names, extensions, commands, IP addresses
This guide uses the following formats to highlight special messages:
Note: This format is used to highlight information of importance or special interest.
This manual is written for the FVS114 VPN Firewall according to these specifications.:
Note: Product updates are available on the NETGEAR, Inc. Web site at
http://kbserver.netgear.com/products/FVS114.asp.
About This Manual1-1
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
How to Use This Manual
The HTML version of this manual includes the following:
•Buttons, and , for browsing forwards or backwards through the manual one page
at a time
•A button that displays the table of contents and an button. Double-click on a
link in the table of contents or index to navigate directly to where the topic is described in the
manual.
•A button to access the full NETGEAR, Inc. online Knowledge Base for the
product model.
•Links to PDF versions of the full manual and individual chapters.
1-2About This Manual
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
How to Print this Manual
To print this manual you can choose one of the following several options, according to your needs.
•Printing a Page in the HTML View.
Each page in the HTML version of the manual is dedicated to a major topic. Use the Print
button on the browser toolbar to print the page contents.
•Printing a Chapter.
Use the PDF of This Chapter link at the top left of any page.
–Click the PDF of This Chapter link at the top right of any page in the chapter you want to
print. The PDF version of the chapter you were viewing opens in a browser window.
Note: Your computer must have the free Adobe Acrobat reader installed in order to view
and print PDF files. The Acrobat reader is available on the Adobe Web site at
http://www.adobe.com.
–Click the print icon in the upper left of the window.
Tip: If your printer supports printing two pages on a single sheet of paper, you can save
paper and printer ink by selecting this feature.
•Printing the Full Manual.
Use the Complete PDF Manua l link at the top left of any page.
–Click the Complete PDF Manual link at the top left of any page in the manual. The PDF
version of the complete manual opens in a browser window.
–Click the print icon in the upper left of the window.
Tip: If your printer supports printing two pages on a single sheet of paper, you can save
paper and printer ink by selecting this feature.
About This Manual1-3
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
1-4About This Manual
202-10098-01, April 2005
Chapter 2
Introduction
This chapter describes the features of the NETGEAR FVS114 ProSafe VPN Firewall.
Key Features of the VPN Firewall
The FVS114 ProSafe VPN Firewall with four-port switch connects your local area network (LAN)
to the Internet through an external access device such as a cable modem or DSL modem.
The FVS114 is a complete security solution that protects your network from attacks and intrusions.
Unlike simple Internet sharing firewalls that rely on Network Address Translation (NAT) for
security, the FVS114 uses stateful packet inspection for Denial of Service attack (DoS) protection
and intrusion detection. The FVS114 allows Internet access for up to 253 users. The FVS114 VPN
Firewall provides you with multiple W eb content filtering options, pl us browsing activity reporting
and instant alerts — both via e-mail. Parents and network administrators can establish restricted
access policies based on time-of-day, Web site addresses and address keywords, and share
high-speed cable/DSL Internet access for up to 253 personal computers. In addition to NAT, the
built-in firewall protects you from hackers.
With minimum setup, you can install and use the firewall within minutes.
The FVS114 VPN Firewall provides the following features:
•Easy, Web-based setup for installation and management.
•Content filtering and site blocking security.
•Built-in four-port 10/100 Mbps switch.
•Ethernet connection to a WAN device, such as a cable modem or DSL modem.
•Extensive protocol support.
•Login capability.
•Front panel LEDs for easy monitoring of status and activity.
•Flash memory for firmware upgrade.
Introduction2-1
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
A Powerful, True Firewall with Content Filtering
Unlike simple Internet sharing NAT firewalls, the FVS114 is a true firewall, using stateful packet
inspection to defend against hacker attacks. Its firewall features include:
•DoS protection.
Automatically detects and thwarts DoS attacks such as Ping of Death, SYN Flood, LAND
Attack, and IP Spoofing.
•Blocks unwanted traffic from the Internet to your LAN.
•Blocks access from your LAN to Internet locations or services that you specify as off-limits.
•Logs security incidents.
The FVS114 logs security events such as blocked incoming traffic, port scans, attacks, and
administrator logins. You can configure the firewall to email the log to you at specified
intervals. You can also configure the firewall to send immediate alert messages to your e-mail
address or email pager whenever a significant event occurs.
•With its content filtering feature, the FVS114 prevents objectionable content from reaching
your PCs. The firewall allows you to control access to Internet content by screening for
keywords within Web addresses. You can configure the firewall to log and report attempts to
access objectionable Internet sites.
Security
The FVS114 VPN Firewall is equipped with several features designed to maintain security, as
described in this section.
•PCs Hidden by NAT
NAT opens a temporary path to the Internet for requests originating from the local network.
Requests originating from outside the LAN are discarded, preventing users outside the LAN
from finding and directly accessing the PCs on the LAN.
•Port Forwarding with NAT
Although NAT prevents Internet locations from directly accessing the PCs on the LAN, the
firewall allows you to direct incoming traffic to specific PCs based on the service port number
of the incoming request, or to one designated “DNS” host computer. You can specify
forwarding of single ports or ranges of ports.
2-2Introduction
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
Autosensing Ethernet Connections with Auto Uplink
With its internal eight-port 10/100 switch, the FVS114 can connect to either a 10 Mbps standard
Ethernet network or a 100 Mbps Fast Ethernet network. Both the LAN and WAN interfaces are
autosensing and capable of full-duplex or half-duplex operation.
TM
The firewall incorporates Auto Uplink
technology. Each Ethernet port automatically senses
whether the Ethernet cable plugged into the port should have a normal connection such as to a PC
or an uplink connection such as to a switch or hub. That port then configures itself to the correct
configuration. This feature also eliminates the need to worry about crossover cables, as Auto
Uplink will accommodate either type of cable to make the right connection.
Extensive Protocol Support
The FVS114 VPN Firewall supports the Transmission Control Protocol/In ternet Protocol (TCP/IP)
and Routing Information Protocol
Appendix B, “Network, Routing, and Firewall Basics.”
•IP Address Sharing by NAT
The FVS114 VPN Firewall allows several networked PCs to share an Internet account using
only a single IP address, which may be statically or dynamically assigned by your Internet
service provider (ISP). This technique, known as NAT, allows the use of an inexpensive
single-user ISP account.
(RIP). For further information about TCP/IP, refer to
•Automatic Configuration of Attached PCs by DHCP
The FVS114 VPN Firewall dynamically assigns network configuration information, including
IP, gateway, and Domain Name Server (DNS) addresses, to attached PCs on the LAN using
the Dynamic Host Configuration Protocol (DHCP). This feature greatly simplifies
configuration of PCs on your local network.
•DNS Proxy
When DHCP is enabled and no DNS addresses are specified, the firewall provides its own
address as a DNS server to the attached PCs. The firewall obtains actual DNS addresses from
the ISP during connection setup and forwards DNS requests from the LAN.
•Point-to-Point Protocol over Ethernet (PPPoE)
PPPoE is a protocol for connecting remote hosts to the Internet over a DSL connection by
simulating a dial-up connection. This feature eliminates the need to run a login program such
as Entersys or WinPOET on your PC.
Introduction2-3
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
Easy Installation and Management
You can install, configure, and operate the FVS114 ProSafe VPN Firewall within minutes after
connecting it to the network. The following features simplify installation and management tasks:
•Browser-based management
Browser-based configuration allows you to easily configure your firewall from almost any
type of personal computer, such as Windows, Macintosh, or Linux. A user-friendly Setup
Wizard is provided and online help documentation is built into the browser-based Web
Management Interface.
•Smart Wizard
The FVS114 VPN Firewall automatically senses the type of Internet connection, asking you
only for the information required for your type of ISP account.
•Diagnostic functions
The firewall incorporates built-in diagnostic functions such as Ping, DNS lookup, and remote
reboot.
•Remote management
The firewall allows you to login to the Web Management Interface from a remote location on
the Internet. For security, you can limit remote management access to a specified remote IP
address or range of addresses, and you can choose a nonstandard port number.
•Visual monitoring
The FVS114 VPN Firewall’s front panel LEDs provide an easy way to monitor its status and
activity.
Maintenance and Support
NETGEAR offers the following features to help you maximize your use of the FVS114 VPN
Firewall:
•Flash memory for firmware upgrade.
•Free technical support seven days a week, 24 hours a day.
2-4Introduction
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
Package Contents
The product package should contain the following items:
•FVS114 ProSafe VPN Firewall.
•AC power adapter.
•Category 5 (Cat 5) Ethernet cable.
•Installation Guide.
•Resource CD (240-10207-01) for ProSafe VPN Firewall, including:
— This guide.
— Application Notes and other helpful information.
•Registration and Warranty Card.
If any of the parts are incorrect, missing, or damaged, contact your NETGEAR dealer. Keep the
carton, including the original packing materials, in case you need to return the firewall for repair.
The FVS114 Front Panel
The front panel of the FVS114 VPN Firewall contains the status LEDs described below.
PWR
Figure 2-1: FVS114 front panel
Test
Internet
LOCAL Ports
You can use some of the LEDs to verify connections. Viewed from left to right, Table 2-1
describes the LEDs on the front panel of the firewall. These LEDs are green when lit.
Introduction2-5
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
Table 2-1.LED Descriptions
LED LabelActivityDescription
PWROnPower is supplied to the firewall.
TESTOn
Off
INTERNET
100 (100 Mbps)On
Off
LINK/ACT
(Link/Activity)
LOCAL
100 (100 Mbps)On
LINK/ACT
(Link/Activity)
On
Blinking
Off
On
Blinking
The system is initializing.
The system is ready and running.
The Internet (WAN) port is operating at 100 Mbps.
The Internet (WAN) port is operating at 10 Mbps.
The Internet port has detected a link with an attached device.
Data is being transmitted or received by the Internet port.
The Local port is operating at 100 Mbps.
The Local port is operating at 10 Mbps.
The Local port has detected a link with an attached device.
Data is being transmitted or received by the Local port.
The FVS114 Rear Panel
The rear panel of the FVS114 VPN Firewall contains the port connections listed below.
FACTORY DEFAULTS
Reset Button
Figure 2-2: FVS1 14 rear panel
LOCAL
Ports
Port
DC PowerINTERNET
Viewed from left to right, the rear panel contains the following features:
•Factory default reset push button
•Eight Ethernet LAN ports
•Internet Ethernet WAN port for connecting the firewall to a cable or DSL modem
2-6Introduction
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
•DC power input
•ON/OFF switch
NETGEAR-Related Products
NETGEAR products related to the FVS114 are listed in the following table:
Table 2-2.NETGEAR-Related Products
CategoryWirelessWired
NotebooksWAG511 108 Mbps Dual Band PC Card
WG511T 108 Mbps PC Card
WG51 1 54 Mbps PC Card
WG111 54 Mbps USB 2.0 Adapter
MA521 802.11b PC Card
NETGEAR Product Registration, Support, and
Documentation
Register your product at http://www.NETGEAR.com/register. Registration is required before you
can use our telephone support service.
Product updates and Web support are always available by going to: http://kbserver.netgear.com.
Introduction2-7
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
Documentation is available on the Resource CD and at http://kbserver.netgear.com.
When the VPN firewall router is connected to the Internet, click the Knowledge Base or the
Documentation link under the Web Support menu to view support information or the
documentation for the VPN firewall router.
2-8Introduction
202-10098-01, April 2005
Chapter 3
Connecting the Firewall to the Internet
This chapter describes how to set up the firewall on your LAN, connect to the Internet, perform
basic configuration of your FVS114 ProSafe VPN Firewall using the Setup Wizard, or how to
manually configure your Internet connection.
Follow these instructions to set up your firewall.
Prepare to Install Your FVS114 ProSafe VPN Firewall
•For Cable Modem Service: When you perform the VPN firewall router setup steps be sure to
use the computer you first registered with your cable ISP.
•For DSL Service: You may need information such as the DSL login name/e-mail address and
password in order to complete the VPN firewall router setup.
Before proceeding with the VPN firewall router installation, familiarize yourself with the contents
of the Resource CD (240-10207-01) for ProSafe VPN Firewall, especially this manual and the
animated tutorials for configuring networking on PCs.
Reference Manual for the ProSafe VPN Firewall FVS114
Locate the Ethernet cable (Cable 1 in the diagram) that connects your PC to the modem.
c.
A
&DEOH
,QWHUQHW
&RPSXWHU
Figure 3-1: Disconnect the Ethernet cable from the computer
d.
Disconnect the cable at the computer end only, point A in the diagram.
e.Look at the label on the bottom of the VPN firewall router. Locate the Internet port.
Securely insert the Ethernet cable from your modem (Cable 1 in the diagram below) into
the Internet port of the VPN firewall router as shown in point B of the diagram.
0RGHP
B
Internet
port
Internet
VPN Firewall
Figure 3-2: Connect the VPN firewall router to the modem
3-2Connecting the Firewall to the Internet
202-10098-01, April 2005
Cable 1
Modem
Reference Manual for the ProSafe VPN Firewall FVS114
Securely insert the blue cable that came with your VPN firewall router (the blue
f.
NETGEAR cable in the diagram below) into a LOCAL port on the firewall such as
LOCAL port 4 (point C in the diagram), and the other end into the Ethernet port of your
computer (point D in the diagram).
Blue NETGEAR
D
Cable
C
Computer
Local Ports
Figure 3-3: Connect the computer to the VPN firewall router
Your network cables are connected and you are ready to restart your network.
VPN Firewall
Internet
Modem
2. RESTARTYOURNETWORKINTHECORRECTSEQUENCE
Warning: Failure to restart your network in the correct sequence could prevent you from
connecting to the Internet.
a.First, turn on the broadband modem and wait two minutes.
b.Now, plug in the power cord to your VPN firewall router and wait one minute.
c.Last, turn on your computer.
Note: For DSL customers, if software logs you in to the Internet, do not run that software. Y ou
may need to go to the Internet Explorer T ools menu, Internet Options, Connections tab page
where you can select “Never dial a connection.”
Connecting the Firewall to the Internet3-3
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
PowerInternetLocal Port 4Test
Figure 3-4: Status lights
d.
Check the VPN firewall router status lights to verify the following:
•PWR: The power light should turn solid green. If it does not, see “Troubleshooting
Tips” on page 3-6.
•TEST: The test light blinks when the firewall is first turned on then goes off. If after
two minutes it is still on, see “Troubleshooting Tips” on page 3-6.
•INTERNET: The Internet LINK/ACT light should be lit. If not, make sure the Ethernet
cable is securely attached to the VPN firewall router Internet port and the modem, and
the modem is powered on.
•LOCAL: A LOCAL light should be lit. Green on the 100 line indicates your computer
is communicating at 100 Mbps; off on the 100 line indicates 10 Mbps. If a LOCAL
light is not lit, check that the Ethernet cable from the computer to the firewall is
securely attached at both ends, and that the computer is turned on.
Now, Configure the FVS114 for Internet Access
1.From the Ethernet connected PC you just set up, open a browser such as Internet Explorer or
Netscape® Navigator.
3-4Connecting the Firewall to the Internet
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
With the VPN firewall router in its factory default state, your browser will automatically
display the NETGEAR Smart Wizard Configuration Assistant welcome page.
Note: If you do not see this page, type http://www.routerlogin.net in the browser address bar
and press Enter. If you still cannot see this screen, see “How to Bypass the Configuration
Assistant” on page 3-9.
If you cannot connect to the VPN firewall router, verify your computer networking setup. It
should be set to obtain both IP and DNS server addresses automatically, which is usually so.
For help with this, see Appendix D, “Preparing Your Network or the animated tutorials on the
Resource CD.
2.Click OK. Follow the prompts to proceed with the Smart Wizard Configuration Assistant to
connect to the Internet.
3.Click Done to finish. If you have trouble connecting to the Internet, see “Troubleshooting
Tips” on page 3-6 to correct basic problems.
Note: The Smart Wizard Configuration Assistant only ap pe a r s wh en the firewall is in its factory
default state. After you configure the VPN firewall router, it will not appear again. You can always
connect to the firewall to change its settings. To do so, open a browser such as Internet Explorer
and go to http://www.routerlogin.net. Then, when prompted, enter admin as the user name and password for the password both in lower case letters.
You are now connected to the Internet!
Connecting the Firewall to the Internet3-5
202-10098-01, April 2005
Reference Manual for the ProSafe VPN Firewall FVS114
Troubleshooting Tips
Here are some tips for correcting simple problems you may have.
Be sure to restart your network in this sequence:
1.Turn off the VPN firewall router, shut down the computer, and unplug and turn of f the modem.
2.Turn on the modem and wait two minutes
3.Turn on the VPN firewall router and wait one minute
4.Turn on the computer.
Make sure the Ethernet cables are securely plugged in.
•The Internet link light on the VPN firewall router will be lit if the Ethernet cable to the VPN
firewall router from the modem is plugged in securely and the modem and VPN firewall router
are turned on.
•For each powered on computer connected to the VPN firewall router with a securely plugged
in Ethernet cable, the corresponding VPN firewall router LOCAL port link light will be lit.
The labels on the front and back of the VPN firewall router identify the number of each
LOCAL port.
Make sure the network settings of the computer are correct.
•LAN connected computers must be configured to obtain an IP address automatically via
DHCP. Please see Appendix D, “Preparing Your Network or the animated tutorials on the Resource CD for help with this.
•Some cable modem ISPs require you to use the MAC address of the computer registered on
the account. If so, in the Router MAC Address section of the Basic Settings menu, select “Use
this Computer’s MAC Address.” The firewall will then capture and use the MAC address of
the computer that you are now using. You must be using the computer that is registered with
the ISP. Click Apply to save your settings. Restart the network in the correct sequence.
Use the status lights on the front of the FVS114 to verify correct firewall operation.
If the FVS114 power light does not turn solid green or if the test light does not go off within
two minutes after turning the firewall on, reset the firewall according to the instructions in
“Backing Up the Configuration” on page 7-7.
3-6Connecting the Firewall to the Internet
202-10098-01, April 2005
Loading...
+ 182 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.