WHG Product Training Oct 2011 For authorized partners only

Slides:



Advertisements
Similar presentations
Designing for Pervasive Network Security. Designing for Security Our aim in this section will be to concentrate on how campus Networks can be designed.
Advertisements

CY-SWR1100 Dual Band Wireless N Router
Application Guide For Mesh AP – MAP-3120
KX-TVM50 KX-TVM200 V2.0 (Edition 1.1 2nd November, 2007)
DSL-2730B, DSL-2740B, DSL-2750B.
Technical Overview July, 2004.
Hotspot Customization
DAP-1520 FAQ’s Wireless AC750 Dual Band Range Extender.
DNR-322L & DNR-326.
DSL-2870B How to Change ADSL Username and Password in your modem router How to Change Wireless Channel in your modem router How to Open Ports in your modem.
KX-NS1000 Initial Set Up For step by step : 16 May,
Module 5: Configuring Access for Remote Clients and Networks.
Nada Abdulla Ahmed.  SmoothWall Express is an open source firewall distribution based on the GNU/Linux operating system. Designed for ease of use, SmoothWall.
Hardware Firewalls: Advanced Feature © N. Ganesan, Ph.D.
Wi-Fi Structures.
Advanced Routers Opening Ports
DVG-N5402SP.
WiNG 5.3.
Designed By: Technical Training Department
What’s New in Fireware XTM v WatchGuard Training.
Technical Training: DIR-615
Technical Training: DAP-1360 Wireless N Access Point DAP-1360.
TAX-AIDE Network Router Setup Network Printer Setups July SMT/TCS Training - Dallas1.
Advanced Networking for DVRs
Week #10 Objectives: Remote Access and Mobile Computing Configure Mobile Computer and Device Settings Configure Remote Desktop and Remote Assistance for.
Login Screen This is the Sign In page for the Dashboard Enter Id and Password to sign In New User Registration.
Course 201 – Administration, Content Inspection and SSL VPN
DSL 305 Series ADSL Modem. Types of DSL305 series DSL305E ADSL Modem  PPP Half-Bridge (Default)  Transparent Bridge DSL305EU ADSL Router/Modem.
Worldwide Product Marketing Group United States - Spain - UK - France - Germany - Singapore - Taipei Barricade™ VPN Broadband Routers (4 and 8 port)
CHAPTER 2 PCs on the Internet Suraya Alias. The TCP/IP Suite of Protocols Internet applications – client/server applications The client requested data.
Classroom User Training June 29, 2005 Presented by:
DVG-G5402SP D-Link VoIP Wireless Router
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Altai Certification Training Backend Network Planning
Home Media Network Hard Drive Training for Update to 2.0 By Erik Collett Revised for Firmware Update.
Dual WAN Router Brand & Marketing MGMT Dept DrayTek Corp Vigor2912 Series 14 th Jan Based on f/w RC4.
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
Module 8 Configuring Mobile Computing and Remote Access in Windows® 7.
1 The Firewall Menu. 2 Firewall Overview The GD eSeries appliance provides multiple pre-defined firewall components/sections which you can configure uniquely.
Network Management Tool Amy Auburger. 2 Product Overview Made by Ipswitch Affordable alternative to expensive & complicated Network Management Systems.
DSL-2544N Dual Band Wireless N600 Gigabit ADSL2+ Modem Router
EMerge Browser Managed Security Platform Module 3: Startup eMerge Certification Course  Physical connection  TCP/IP Characteristics of PC  Initial connection.
Smart Switches FS526T / FS750T / GS748T / GS724T
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Four Windows Server 2008 Remote Desktop Services,
Cisco ASA 5505 Joseph Cicero Northeast Wisconsin Technical College.
Firewall Policies. Module Objectives By the end of this module participants will be able to: Identify the components used in a firewall policy Create.
DHP Agenda: How to Access Web Interface of the DHP-1320 on Access Point Mode How to Access Web Interface of the DHP-1320 on Router Mode How to Change.
NETGEAR CONFIDENTIAL FVS338 ProSafe VPN Firewall 50.
NETGEAR CONFIDENTIAL FVX538 ProSafe VPN Firewall 200.
What’s New in Fireware v WatchGuard Training.
© ExplorNet’s Centers for Quality Teaching and Learning 1 Install, configure, and deploy a SOHO wireless/wired router using appropriate settings. Objective.
Model: DS-600 5x 10/100/1000Mbps Ethernet Port Centralized WLAN management and Access Point Discovery Manages up to 50 APs with access setting control.
KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY IT375 Window Enterprise Administration Course Name – IT Introduction to Network Security Instructor.
Copyright ©2016 WatchGuard Technologies, Inc. All Rights Reserved WatchGuard Training What’s New in Fireware v
Product Introduction --QoS VPN Router G3 16/12/2015 Business WLAN
UTM Content Security Gateway
Integrated Management System
Configuring ALSMS Remote Navigation
Product Introduction --AP Controller M3 Yaojun 26/12/2015
Securing the Network Perimeter with ISA 2004
NetComm Wireless NB16WV-02 Training
What’s New in Fireware v12.1.1
IIS.
HC Hyper-V Module GUI Portal VPS Templates Web Console
UNIBOX CONTROLLER.
Windows Server Administration Fundamentals
Chapter 10: Advanced Cisco Adaptive Security Appliance
What’s New In WatchGuard Wi-Fi Cloud v8.6
Introduction to the WatchGuard AP Device
Presentation transcript:

WHG Product Training Oct 2011 For authorized partners only Secure WLAN Solution WHG Product Training Oct 2011 For authorized partners only

Agenda WHG Overview, Installation and Application EAP Overview, Installation and Application

Overview About WHG WHG Series is designed for wired and wireless network environments with multi-functional, enterprise-class, and high performance network management devices. Different models are suitable for different scale of WLAN (wireless local area network) environments. All models support Gigabit interface can manage a large number of users and services quickly and effectively. The product combines integrated management, security, data transfer, billing and payment functions, with a simple built-in web-based management interface for system administrators to monitor wired and wireless users effectively. With a centralized management interface from wireless AP management function, administrators can easily search, set, monitor and upgrade all managed AP devices.

Overview Product features-1 Customizable certification standards, including Web-based login (UAM) and 802.1X (RADIUS), customizable portal and Walled-Garden Ads. Establishment and management of user groups. Support for multiple authentication methods  (Local, On-demand, RADIUS, POP3, LDAP, NTDS). Virtual local area network (Service Zone) and Policy Management. On-demand Account (accounting by time or volume ) Integration of external payment gateways, including PayPal, Authorize.net, SecurePay and WorldPay. User account roaming

Overview Product features - 2 Support wireless roaming between APs and AP management. Virtual Private Network (VPN) tunneling technology. Support Quality of Service (QoS) Dual Uplink (WAN) to improve reliability and Load Balancing Firewall, DoS (Denial of Service) attack protection Status monitoring and reporting of network and on-line users Support as a network gateway, including NAT, DHCP, DMZ, Firewall and Port Forwarding

Overview System Overview - 1 WHG-401

Overview System Overview - 2 AAA Gateway Authentication, Authorization and Accounting Authentication: Support for internal or external database servers Authorization : User Group policy Accounting: User Account management and Billing Built-in multiple Service Zones AP centralized management system

Setup and Maintenance Instruction WHG support web management interface To access the web management interface, connect a PC to any LAN Port, and then launch a browser. Make sure you have set DHCP in TCP/IP of your PC to get an IP address automatically. The default gateway IP address is “http://192.168.1.254” Access the web management interface via LAN port

Setup and Maintenance Instruction For the first time, there will be a “Certificate Error”

Setup and Maintenance Instruction The administrator login page will appear.

Setup and Maintenance Instruction After a successful login, a System Home page will appear on the screen.

Setup and Maintenance Instruction Setup Wizard - 1 To quickly configure WHG311 by using the Setup Wizard to set up New Password, Time Zone, WAN1 Interface and Local User Account.

Setup and Maintenance Instruction Setup Wizard - 2

Setup and Maintenance Instruction Setup Wizard - 3

Setup and Maintenance Instruction Setup Wizard - 4

Setup and Maintenance Instruction System Overview An Integration of the overall status of the current system

Setup and Maintenance Instruction Quick Links page Provides administrator with frequently used links.

Setup and Maintenance Instruction System Main Menu

Setup and Maintenance Instruction Main Menu –System – WAN1 Static -1

Setup and Maintenance Instruction Main Menu – System – WAN1 Dynamic -1

Setup and Maintenance Instruction Main Menu –System – WAN1 PPPoE -1

Service Zone

The Concept of Service Zone 9 Service Zones in total A Service Zone is acting like a virtual Gateway. Multiple Service Zones are equal to multiple virtual Gateways.

The Concept of Service Zone Under LAN Port Mapping, there are two modes for Service Zone: Port-based Tag-based

LAN Port Configuration Port Based: For each LAN port, select a Service Zone to which the LAN port is to be mapped from the drop-down list box.

LAN Port Configuration Port-Based Application Example

LAN Port Configuration Configure LAN Port Mapping as Tag-Based

LAN Port Configuration Tag-Based: A Service Zone can be associated with multiple VLAN Tags

LAN Port Configuration Tag-Based Application Example

LAN Port Configuration *Deploy two Service Zones: Employee and Guest Service Zone 1 – Employee: SSID: SZ1-Employee VLAN Tag: 1111 Default Authentication: Radius server Applied Policy: #1 Service Zone 2 – Guest: SSID: SZ2-Guest VLAN Tag: 2222 Default Authentication: On-Demand User Applied Policy: #2 WHG-401 Requirements for this deployment example: 1. Regardless of the location in the office, all users should be divided into two groups (Employee and Guest) for the purpose of authentication differences. 2. Each service zone (VLAN) must setup its own SSID to let users to access the wireless network using the specific ID. The system will give a unique Session ID to authenticated users when they start new sessions. 3. Both groups, Employees and Guests, will be redirected to different login portal pages and will be authenticated against different authentication database. 4. Apply different access control policies to separated groups Employee and Guests. Configurations for the deployment example: Service Zone #1 (Employee): SSID: SZ1-Employee VLAN Tag: 1111 Default Authentication: Local Applied Policy: #1 Service Zone #2 (Guest): SSID: SZ2-Guest VLAN Tag: 2222 Default Authentication: On-Demand User Applied Policy: #2

Setup and Maintenance Instruction Configuration of Server Zone

Setup and Maintenance Instruction SZ1 - Basic Settings IP, DHCP, VLAN Tag Customize Login Page

Setup and Maintenance Instruction SZ1 - Basic Settings - 2 DHCP Server (Enable DHCP Server – DHCP Server Configuration)

Setup and Maintenance Instruction SZ1 - Authentication Settings Authentication Required For the Zone & Authentication Options

Setup and Maintenance Instruction SZ1 -Authentication Settings - 2 Custom Pages

Setup and Maintenance Instruction SZ1 - Authentication Settings -3 Login Page of Custom Pages (Default Page)

Setup and Maintenance Instruction SZ1 - Authentication Settings - 4 Login Page of Custom Pages (Template Page)

Setup and Maintenance Instruction SZ1 -Authentication Settings- 5 Login Page of Custom Pages (Upload Page)

Setup and Maintenance Instruction SZ1 -Authentication Settings - 6 Login Page of Custom Pages (External Page)

Setup and Maintenance Instruction SZ1 - Wireless Settings SSID Security Access Control

Setup and Maintenance Instruction SZ1 - Managed AP(s) in this Service Zone

Group & Policy

The Concept of Policy In addition to Global Policy, the Policy contains four functions of other Firewall Profile: Click Setting for Firewall Profile. The Firewall Configuration will appear. Click Predefined and Custom Service Protocols to edit the protocol list. Click Firewall Rules to edit the rules. Specific Route Profile: The default gateway of WAN1, WAN2, or a desired IP address can be defined in a policy. When Specific Default Route is enabled, all clients applied this policy will access the Internet through this default gateway. Schedule Profile: The Schedule table in a 7X24 format is used to control the clients’ login time. When Schedule is enabled, clients applied policies are only allowed to login the system at the time which is checked in the applied policy. Maximum Concurrent Sessions: Set the maximum concurrent sessions for each client .

The Concept of Policy Policy Configuration Page

The Concept of Group A Group which is allowed to access a Service Zone can be applied with a Policy within this zone. Group Configuration supports: QoS Profile: Configure QoS (Quality of Service ) Privilege Profile : When Change Password Privilege is enabled, the authenticated local users within this Group are allowed to change their password via the Login Success Page

The Concept of Group The relation between Group and Service Zone from the perspective of Group Group 1 users have 5 x Service Zone access (Service Zone 0, 1, 4, 6, 8). Policy 1 is applied to Service Zone 0, 6, 8 Policy 3 is applied to Service Zone 1 Policy 8 is applied to Service Zone 4

The Concept of Group Users have same authentication method are belong same group

The Concept of Group The relation between Group and Policy from the perspective of Service Zone

The Concept of Group This example indicates the Service Zone 1 can be access only from User Group 1 (policy 3), User Group 2 (policy 9) and User Group 3 (policy 11)

Case Study Any Perfect Solutions? Tom owns a SMB with 40 employees Environment: Wide wireless environment Questions: 1. How to prevent employees in the workplace spending too much time surfing on the internet rather then working? 2. The staff in Jimmy’s department have more authority than other departments.

Example #2 Requirements Policy Policy 1 Highest Authority Policy 2 Policy 3 Lower Authority Policy 4 Lowest Authority Firewall 1. Email allow 2. FTP 3. Web Browsing Specific Route WAN1 WAN2 Login Schedule Weekend Allow 2 hrs Weekday Office Hours Weekday Overtime Concurrent Sessions 10 ~ Unlimited 500 300 100 50 Access control policies: there are 4 kinds of priority for different users.

User Management – Policy Access Control Policy Options Max Concurrent Sessions Firewall Rules Routing Login Schedule Policy 1 Policy 2 Policy 3 All Users Policy 3 User Categorization and Policy-based Access Control User Group Controlled by Policy 3

Policy 1 Highest Priority Group 1 Group 2 Group 3 Group 4 Group 5 Group 6 Boss RD PM Finance Sales Guests Policy 1 Policy 1 Policy 4 Policy 1 Highest Priority Policy 2 Higher Priority Policy 3 Lower Priority Policy 4 Lowest Priority Guest Area SZ 6 Boss SZ 1 Policy 1 Policy 1 Policy 2 Policy 2 Policy 3 User Categorization and Policy-based Access Control: 1. Boss group users always enjoy the highest priority (Poicy 1) wherever they go. 2. Most employees have higher priority (Policy 2) in their department service zone; on the other hand, they will have lower priority (Policy 3) when they move to different service zone that does not belong to their department. 3. Guest users can only get online with the lowest priority (Policy 4) in the Guest zone. Policy 2 Policy 1 Policy 3 Policy 2 Policy 1 Policy 3 Sales Dep. SZ 5 RD Dep. SZ 2 PM Dep. SZ 3 Finance Dep. SZ 4

Authentication

Setup and Maintenance Instruction User Authentication – Local - 1

Setup and Maintenance Instruction User Authentication – Local - 2

Setup and Maintenance Instruction User Authentication – Local - 3

Setup and Maintenance Instruction User Authentication – Radius - 1

Setup and Maintenance Instruction User Authentication – Radius – 2

Setup and Maintenance Instruction User Authentication – Radius – 3 The usage of Postfix “.” Radius Server 有時擁有不只一組 domain name Postfix 設定成 “.” 再設定 Username Format 於 Leave Unmodified User 可以透過完整登入帳號 密碼 即可完成登入動作~

Setup and Maintenance Instruction User Authentication – LDAP - 1

Setup and Maintenance Instruction User Authentication – LDAP - 2

Setup and Maintenance Instruction User Authentication – On-demand – 1 On-demand Main Page

Setup and Maintenance Instruction User Authentication – On-demand – 2 Billing Plans

Setup and Maintenance Instruction User Authentication – On-demand – 3 On-Demand Account Creation

Setup and Maintenance Instruction Network – Privilege

Setup and Maintenance Instruction Network – Privilege - Privilege IP Address List

Setup and Maintenance Instruction Network – Privilege - Privilege MAC Address List

Setup and Maintenance Instruction Network – Monitor IP

Setup and Maintenance Instruction Network – Walled Garden Advertisement hyperlinks are displayed on the user’s login page. Clients who click on it will be redirected to the listed advertisement websites.

Setup and Maintenance Instruction Utilities – Password Change Change Admin, Manager & Operator’s password

Setup and Maintenance Instruction Utilities – Backup & Restore Backup System Settings : Click Backup to create a .db database backup file and save it on disk. Restore System Settings :click Restore to restore to the same settings at the time when the backup file was saved. (Keep WAN1 setting and Management IP Address List.) Reset to the Factory Default : Click Reset to load the factory default settings.

Setup and Maintenance Instruction Utilities – Restart : This function allows the administrator to safely restart

Setup and Maintenance Instruction Utilities – Network Utilities Wake-on-LAN : IPv4 : IPv4 Network Utilities (included Ping, Trace Route, ARPing & Show ARP Table) IPv6 : IPv6 Network Utilities (Included Ping6, Trace Route 6, Neighbor Discovery & Show Neighbor Cache) Sniff : Capture Packet in specified Interface Status : Display operation status Result : Display result

Setup and Maintenance Instruction Status System : System Status Interface : This section provides an overview of the interface for the administrator including WAN1, WAN2, SZ Default~8. Hardware : Hardware Status (CPU, Memory, Storage) Routing Table : All the Policy Route rules and Global Policy Route rules will be listed here. Online User : Online User’s information Non-Login Users : Non-Login User’s information Session List : Session information User Logs : User’s traffic history information Logs : Other traffic history (System & Web Logs) DHCP Lease : DHCP IP release record E-mail & SYSLOG : Receive System Status record information via E-mail, Syslog Server & FTP Server.

Setup and Maintenance Instruction

Setup and Maintenance Instruction Status - System

Setup and Maintenance Instruction Status – Interface Display WAN and nine Service Zones’ status interface.

Setup and Maintenance Instruction Status – Interface 1

Setup and Maintenance Instruction Status – Interface 2

Setup and Maintenance Instruction Status – Interface 3

Setup and Maintenance Instruction Status – Hardware Information Hardware Usage Information

Setup and Maintenance Instruction Status – Routing Table All the Policy Route rules and Global Policy Route rules will be listed here. Also it will show the System Route rules specified by each interface.

Setup and Maintenance Instruction Status – Online User Display Online User’s detailed information.

Setup and Maintenance Instruction Status – User Logs Users Log : User’s traffic history record On-demand Users Log : On-demand User’s access records Roaming Out User Log : Roaming Out User’s access records Roaming In User Log : Roaming In User’s access records SIP Call Usage Log : SIP User’s log-in/out record Monthly Network Usage of Local User : Monthly record of Local User’s log-in/out history Status – User Logs - Users Log

Setup and Maintenance Instruction Status – Logs System Logs: System Information Web Logs: Web record

Setup and Maintenance Instruction Status – DHCP Lease DHCP Logs Statistics List DHCP Lease Log DHCP Lease List

Setup and Maintenance Instruction Status – DHCP Lease - DHCP Logs Statistics List DHCP Lease Log

Setup and Maintenance Instruction Status – Report and Notification Main Menu > Status > Report and Notification SMTP Settings : Configure SMTP Server; Logs will be sent via E-mail SYSLOG Settings :Configure SYSLOG Server; Logs will be delivered to Syslog Server FTP Settings : Configure FTP Server; Logs will be delivered to Syslog Server Notification Settings: When the above setting is completed, needing more detailed configurations, and sending Logs by those three ways mentioned above. System Report: Graphical system report (1Hr, 1Day, 1Week etc…)

Console Connect to the Console Via Console Port (baud rate 9600) Via SSH (Link to GW IP and login with admin/admin)

Local Area AP Management

Local AP Management Interface Features: Reboot, Enable, Disable and Delete the checked AP if desired Apply Template Apply Service Zone Background AP Discovery Add AP Manually Firmware upgrade and management

Overview Page (signal radio) AP Type List AP number. Online AP number, Offline AP number and Number of Client.

AP Template Setting Template is a model that can be copied to every AP and not necessary to configure the AP individually. . General setting Wireless setting

AP Discovery Discovery Settings Factory Default (Auto) &Manual Background AP Discovery

AP Discovery Tag-based Can be applied to multiple Service Zones.

AP List AP status Change AP setting AP Status Change AP Setting

Wide Area AP Management

Wide AP Management System Interface Features: Detect and manage all of the APs in the network Show APs’ corresponding on Google Maps WDS Setup Adding APs manually Firmware Upgrade and Management GRE Tunnel setup and manage the User Traffic of Wide AP

Wide Area AP Management Main Menu

Wide Area AP Management Map - 1 Need to apply Google Maps API Key from Google Maps Then enter the Key

Wide Area AP Management Map - 2

Wide Area AP Management Map – 3 Google will provide the Google Maps API Key

Wide Area AP Management Map – 4 Click Main Menu -> Access Point -> Wide Area AP Management -> Map -> Edit this Map

Wide Area AP Management Map – 5 Enter the Google Maps API Key

Wide Area AP Management Discover Auto discover AP and list to Device Results

Wide Area AP Management List AP List Add to Map Restore Setting Firmware Upgrade Configuration GRE Tunnel Building

GRE Tunnel GRE Tunnel Setup Procedure - 1

GRE Tunnel GRE Tunnel Setup Procedure - 3

GRE Tunnel GRE Tunnel Setup Procedure – 4 Back to GRE Tunnel Editing page to configure VAP mapping.

AP Setup & Maintenance Interface

EAP Overview

Setup and Maintenance Instruction EAP including: System: System Setting Wireless: Wireless Setting Firewall: Layer2 Firewall Utilities: Password Setting, Backup/Restore Settings and upgrade etc Status: System Status

Thank You Email : sales@level1.com Website : www.level1.com