Clavister SG3200 Series Getting Started Guide Clavister AB Sjögatan 6J SE-89160 Örnsköldsvik SWEDEN Phone: +46-660-299200 Fax: +46-660-12250 www.clavister.
Clavister SG3200 Series Getting Started Guide Published 2011-02-23 Copyright © 2011 Clavister AB Copyright Notice This publication, including all photographs, illustrations and software, is protected under international copyright laws, with all rights reserved. Neither this manual, nor any of the material contained herein, may be reproduced without the written consent of Clavister. Disclaimer The information in this document is subject to change without notice.
Table of Contents Preface ................................................................................................................ 5 1. Product Overview .............................................................................................. 7 1.1. Unpacking the Product ............................................................................ 7 1.2. Interfaces and Ports ................................................................................. 9 2. Installation ......................
List of Figures 1.1. An Unpacked Clavister SG3200 Series Appliance .................................................. 8 1.2. Front View of the Clavister SG3200 Series. ........................................................... 9 2.1. The SG3200 Series RS-232 Console Port ............................................................. 14 2.2. Rear View of the 3200A and 3200B .................................................................... 16 2.3. Rear View of the 3200C ....................................
Preface Target Audience The target audience for this guide is the administrator who has taken delivery of a packaged Clavister SG3200 Series appliance and is setting it up for the first time. The guide takes the user from unpacking and installation of the device through to power-up, including network connections and initial CorePlus configuration. The guide is for all models of the SG3200 Series. It covers the newer SG3200C as well as older versions of the 3200.
Preface Text links Where a "See section" link is provided in the main text, this can be clicked on to take the reader directly to that reference. For example, see Section 3.5, “Troubleshooting Setup”. Web links Web links included in the document are clickable. For example, http://www.clavister.com. Trademarks Certain names in this publication are the trademarks of their respective owners. CorePlus is the trademark of Clavister AB.
Chapter 1: Product Overview • Unpacking the Product, page 7 • Interfaces and Ports, page 9 1.1. Unpacking the Product This section details the unpacking of the SG3200 Series appliance. Open the packaging box used for shipping and carefully unpack the contents. The delivered product packaging should contain the following: 1. The Clavister SG3200 Series appliance. 2. A mounting kit for 19 inch racks. 3. An Ethernet cable. 4. A RS-232 null-modem cable. 5. A Power cord. 6. A CD-ROM containing: 7.
Chapter 1: Product Overview Figure 1.1. An Unpacked Clavister SG3200 Series Appliance Note: Missing items If any items are missing from your package, please contact your reseller or distributor. All documentation can be freely downloaded in PDF format from the Clavister website. End of Life Treatment The SG3200 Series appliance is marked with the European Waste Electrical and Electronic Equipment (WEEE) directive symbol which is shown below.
Chapter 1: Product Overview 1.2. Interfaces and Ports This section is an overview of the SG3200 Series product's external design. Note: Usage of the terms "interface" and "port" The terms Ethernet interface and Ethernet port are often used interchangeably. In this document, interface is used for Ethernet connections and port is used for non-Ethernet connections. Figure 1.2. Front View of the Clavister SG3200 Series.
Chapter 1: Product Overview i. Orange - Gigabit Ethernet link, 1000BaseT ii. Green - Fast Ethernet link, 100BaseTx iii.
Chapter 1: Product Overview 11
Chapter 2: Installation • Installation Guidelines, page 12 • Console Port Connection, page 14 • Connecting Power, page 16 2.1. Installation Guidelines Follow these guidelines when installing your Clavister SG3200 Series appliance: • Safety Take notice of the safety guidelines laid out in Chapter 5, Safety Precautions. These are specified in multiple languages.
Chapter 2: Installation • Temperature Do not install the appliance in an environment where the operating ambient temperature could exceed the specified operating range (see Appendix A, Specifications). The recommended operating temperature range is "room temperature". That is to say, the temperature most commonly found in a modern office and in which humans feel comfortable. This is usually considered to be between 20 and 25 degrees Celsius (68 to 77 degrees Fahrenheit).
Chapter 2: Installation 2.2. Console Port Connection The serial console port is a physical RS-232 port on the SG3200 Series hardware. This port allows direct management connection to the appliance, either from a separate computer running console emulation software or from a console terminal. Serial console access can then be used for both management of CorePlus with CLI commands or to enter the boot menu in order to access SG3200 Series firmware loader options.
Chapter 2: Installation The RS-232 console port need not be used if setup is done through a web browser as described in Section 3.2, “Web Interface and Wizard Setup”. If the RS-232 port is used for setup, no password is initially needed and the CLI commands required are described in Section 3.4, “CLI Setup”. Note: Setting a console password A serial console password need not be set. If this is the case, anyone with physical access to the serial console has full administrator rights.
Chapter 2: Installation 2.3. Connecting Power This section describes connecting power to the SG3200 Series. Only an AC power source is supported by the product. Important Please read the advisory information concerning electrical safety in Chapter 5, Safety Precautions. The Newer and Older 3200 Models are Different There is a difference between the rear layout of the newer 3200C model and the older 3200A and 3200B models. Figure 2.2.
Chapter 2: Installation 2. 3. Plug the other end of the power cord into a power outlet. The next step depends on the 3200 model: i. For older 3200 models, press the On/Off switch to apply power and begin boot up of the hardware. ii. For the newest 3200C model, there is no On/Off switch so the hardware will boot up immediately power is supplied. The SG3200 Series will boot up and CorePlus will start.
Chapter 2: Installation 18
Chapter 3: CorePlus Configuration • Management Workstation Connection, page 19 • Web Interface and Wizard Setup, page 24 • Manual Web Interface Setup, page 31 • CLI Setup, page 46 • Troubleshooting Setup, page 54 • Going Further with CorePlus, page 56 3.1. Management Workstation Connection CorePlus Starts after Power Up It is assumed you have now unpacked, positioned and powered up the SG3200 Series unit. If not, you should refer to the earlier chapters in this manual before continuing.
Chapter 3: CorePlus Configuration first time, a setup wizard runs automatically to guide a new user through key setup steps. The wizard can be closed if the administrator wishes to go directly to the Web Interface to perform setup manually. The wizard is recommended for its simplification of initial setup and is described in detail in Section 3.2, “Web Interface and Wizard Setup”. • Through a terminal console using CLI commands.
Chapter 3: CorePlus Configuration Using Crossover Cables Connection to the management interface from the workstation can be done directly without a switch. This is usually done by using a crossover cable. However, all the ge ports on the SG3200 Series support Automatic MDI-X and a crossover cable is not necessary.
Chapter 3: CorePlus Configuration • Enter the IP addresses given above and click OK. Note: DNS addresses can be entered later To browse the Internet from the management workstation via the security gateway then it is possible to go back to the last step's properties dialog later and enter DNS server IP addresses. For now, they are not required.
Chapter 3: CorePlus Configuration IP Setup on Other Platforms The following appendixes describe management workstation IP setup for other platforms: • Appendix C, Vista IP Setup. • Appendix D, Windows 7 IP Setup. • Appendix E, Apple Mac IP Setup.
Chapter 3: CorePlus Configuration 3.2. Web Interface and Wizard Setup This chapter describes the setup when accessing the CorePlus for the first time through a web browser. The user interface accessed in this way is called the Web Interface. Note: Screenshot images are edited Many of the screenshots in this section have had sections cut from the original image to aid readability. However, all of the relevant informational content has been preserved. Connect By Browsing to https://192.168.1.
Chapter 3: CorePlus Configuration The available Web Interface language options are selectable at the bottom of this dialog. This defaults to the language set for the browser if CorePlus supports that language. Logging In and the Setup Wizard Now login with the username admin and the password admin. The Web Interface will appear and the CorePlus setup wizard should begin automatically. The first wizard dialog is the wizard welcome screen which should appear as shown below.
Chapter 3: CorePlus Configuration The wizard makes setup easier because it automates what would otherwise be a more complex set of individual setup steps. It also reminds you to perform important tasks such as setting the date and time and configuring a log server. The steps that the wizard goes through after the welcome screen are listed next. Wizard step 1: Enter a new username and password You will be prompted to enter a new administration username and password as shown below.
Chapter 3: CorePlus Configuration Wizard step 4: Select the WAN interface settings This step selects how the WAN connection to the Internet will function. It can be one of Manual configuration, DHCP, PPPoE or PPTP as shown below. These four different connection options are discussed next in the following subsections 4A to 4D. • 4A. Static - manual configuration Information supplied by the ISP should be entered in the next wizard screen.
Chapter 3: CorePlus Configuration DNS servers are set automatically after connection with PPPoE. • 4D. PPTP settings The username and password supplied by your ISP for PPTP connection should be entered. If DHCP is to be used with the ISP then this should be selected, otherwise Static should be selected followed by entering the static IP address supplied by the ISP. DNS servers are set automatically after connection with PPTP.
Chapter 3: CorePlus Configuration Wizard step 6: Helper server settings Optional NTP and Syslog servers can be enabled here in the wizard or configured later. Network Time Protocol servers keep the system date and time accurate. Syslog servers can be used to receive and store log messages sent by CorePlus. For the default gateway, it is recommended to specify the IP address assigned to the internal network interface. In this setup, this corresponds to 192.168.1.1.
Chapter 3: CorePlus Configuration Running the Wizard Again Once the wizard has been successfully finished and activated, it cannot be run again. The exception to this is if the Clavister Security Gateway has its factory defaults restored in which case the appliance will behave as though it were being started for the first time. Uploading a License If the wizard has been run or not, the Web Interface can now be used to upload a valid license to the Clavister Security Gateway.
Chapter 3: CorePlus Configuration 3.3. Manual Web Interface Setup This section describes initial CorePlus configuration performed directly through the Web Interface, without using the setup wizard. Configuration is done as a series of individual steps, giving the administrator more direct control over the process. Even if the wizard is used, this section can also be read as a good introduction to using the Web Interface for configuring key aspects of CorePlus.
Chapter 3: CorePlus Configuration By pressing the Set Date and Time button, a dialog appears that allows the exact time to be set. A Network Time Protocol (NTP) servers can optionally be configured to maintain the accuracy of the system date and time and this will require public Internet access. Enabling this option is strongly recommended since it ensures the accuracy of the date and time. A typical NTP setup is shown below.
Chapter 3: CorePlus Configuration After clicking OK, CorePlus reconfiguration will take place and, after a short delay, the Web Interface will try and connect again to the security gateway. If no reconnection is detected by CorePlus within 30 seconds (this length of time is a setting that can be changed) then CorePlus will revert back to the original configuration. This is to ensure that the new configuration does not accidentally lock out the administrator.
Chapter 3: CorePlus Configuration The individual manual steps to configure these connection alternatives with the Web Interface are discussed next. A. Static - manual configuration Manual configuration means that there will be a direct connection to the ISP and all the relevant IP addresses for the connecting interface are fixed values provided by the ISP which are entered into CorePlus manually.
Chapter 3: CorePlus Configuration All the interface related address objects are gathered together in an address book folder called InterfaceAddresses. By clicking on this folder, we open it and can view the addresses it contains. The first few default addresses in the folder are shown below. By default on initial startup, two IP address objects are create automatically for each interface detected by CorePlus.
Chapter 3: CorePlus Configuration display a list of the physical interfaces. The first few lines of the interface list for the SG3200 Series are shown below. Click on the interface in the list which is to be connected to the Internet. The properties for this interface will now appear and the relevant settings can be entered or changed. Press OK to save the changes.
Chapter 3: CorePlus Configuration The rule Action is set to NAT (this is explained further below) and the Service is set to http-all which is suitable for most web browsing (it allows both HTTP and HTTPS connections). The interface and network for the source and destinations are defined in the Address Filter section of the rule. The destination network in the IP rule is specified as the predefined IP4 Address object all-nets.
Chapter 3: CorePlus Configuration This IP rule also specifies that the action for DNS requests is NAT so all DNS request traffic is sent out by CorePlus with the outgoing interface's IP address as the source IP. For the Internet connection to work, we also need a route defined so that CorePlus knows on which interface the web browsing traffic should leave the Clavister Security Gateway. This route will define the interface where the network all-nets (in other words, any network) will be found.
Chapter 3: CorePlus Configuration B. DHCP - automatic configuration All the required IP addresses for Internet connection can, alternatively, be automatically retrieved from an ISP's DHCP server by enabling the DHCP Client option for the interface connected to the ISP. We enable this option by first selecting Ethernet > Interfaces in the navigation tree to display a list of all the interfaces. Click the ge2 interface in the list to display its properties.
Chapter 3: CorePlus Configuration Your ISP will supply the correct values for pppoe_username and pppoe_password in the dialog above. The PPPoE tunnel interface can now be treated exactly like a physical interface by the policies defined in CorePlus rule sets. There also has to be a route associated with the PPPoE tunnel to allow traffic to flow through it, and this is automatically created in the main routing table when the tunnel is defined.
Chapter 3: CorePlus Configuration Your ISP will supply the correct values for pptp_username, pptp_password and the remote endpoint. An interface is not specified when defining the tunnel because this is determined by CorePlus looking up the Remote Endpoint IP address in its routing tables. The PPTP client tunnel interface can now be treated exactly like a physical interface by the policies defined in CorePlus rule sets.
Chapter 3: CorePlus Configuration In addition it is important to specify the Default gateway for the server. This will be handed out to DHCP clients on the internal networks so that they know where to find the public Internet. The default gateway is always the IP address of the interface on which the DHCP server is configured. In this case, ge3_ip. Also in the Options tab, we should specify the DNS address which is handed out with DHCP leases.
Chapter 3: CorePlus Configuration Allowing ICMP Ping Requests As a further example of setting up IP rules, it can be very useful to allow ICMP Ping requests to flow through the Clavister Security Gateway. As discussed earlier, the CorePlus will drop any traffic unless an IP rule explicitly allows it. Let us suppose that we wish to allow the pinging of external hosts with the ICMP protocol by computers on the internal ge3_net network.
Chapter 3: CorePlus Configuration all rule as the last rule in the main IP rule set. This rule has an Action of Drop with the source and destination network set to all-nets and the source and destination interface set to any. The service for this rule must also be specified and this should be set to all_services in order to capture all types of traffic. If the this rule us the only one defined, displaying the main IP rule set will be as shown below.
Chapter 3: CorePlus Configuration The rule now appears with a line scored through it. We can reverse the delete by right clicking the rule again and choosing Undo Delete. Uploading a License Without a valid license loaded, CorePlus operates in demonstration mode which means it will cease operations after 2 hours from startup. To remove this restriction, a valid license must be uploaded to the Clavister Security Gateway. To do this, download a license as described in the last part of Section 3.
Chapter 3: CorePlus Configuration 3.4. CLI Setup This chapter describes the setup steps using CLI commands instead of the setup wizard. The CLI is accessible in two ways: • Across the local network at default IP address 192.168.1.1 using an SSH (Secure Shell) client. The network connection setup is the same as that described in Section 3.
Chapter 3: CorePlus Configuration The new username/password combination should be remembered and the password should be composed in a way which makes it difficult to guess. The next step is to return the CLI to the default top level of object categories. Device:/AdminUsers> cc Device:/> Setting the Date and Time Many CorePlus functions rely on an accurate date and time, so it is important that this is set correctly using the time command.
Chapter 3: CorePlus Configuration Each installation's IP addresses will be different from these IP addresses but they are used here only to illustrate how setup is done. Also, these addresses are private IP addresses and in reality an ISP would use public IP addresses instead. We first add the gateway IP address object which we will call wan_gw: Device:/> add Address IP4Address wan_gw Address=10.5.4.1 This is the address of the ISP's gateway which is the first router hop towards the public Internet.
Chapter 3: CorePlus Configuration EthernetDevice: AutoSwitchRoute: AutoInterfaceNetworkRoute: AutoDefaultGatewayRoute: ReceiveMulticastTraffic: MemberOfRoutingTable: Comments: 0:ge2 1: No Yes Yes Auto All Setting the default gateway on the interface has the additional effect that CorePlus automatically creates a route in the default main routing table that has the network all-nets routed on the interface. This means that we do not need to explicitly create this route.
Chapter 3: CorePlus Configuration It is recommended that at least one DNS server is also defined in CorePlus. This DSN server or servers (a maximum of three can be configured) will be used when CorePlus itself needs to resolve URLs which is the case when a URL is specified in a configuration instead of an IP address.
Chapter 3: CorePlus Configuration and this is automatically created in the main routing table when the tunnel is defined. If the PPPoE tunnel object is deleted, this route is also automatically deleted. At this point, no traffic can flow through the tunnel since there is no IP rule defined that allows it.
Chapter 3: CorePlus Configuration setting that can be changed). DHCP Server Setup If the Clavister Security Gateway is to act as a DHCP server then this can be set up in the following way: First define an IP address object which has the address range that can be handed out. Here, we will use the IP range 192.168.1.10-192.168.1.20 as an example and this will be available on the ge3 interface which is connected to the protected internal network ge3_net.
Chapter 3: CorePlus Configuration Firstly, we must change the current CLI context to be the IPRuleSet called main using the command: Device:/> cc IPRuleSet main Now add an IP rule called allow_ping_outbound to allow ICMP pings to pass: Device:/main> add IPRule name=allow_ping_outbound Action=NAT SourceInterface=ge3 SourceNetwork=InterfaceAddresses/ge3_net DestinationInterface=ge2 DestinationNetwork=all-nets Service=ping-outbound The IP rule again has the NAT action and this is necessary if the protected
Chapter 3: CorePlus Configuration 3.5. Troubleshooting Setup This appendix deals with connection problems that might occur when connecting a management workstation to a Clavister Security Gateway. If the management interface does not respond after the Clavister Security Gateway has powered up and CorePlus has started, there are a number of simple steps to troubleshoot basic connection problems: 1. Check that the correct interface is being used.
Chapter 3: CorePlus Configuration A final diagnostic test is to try using the console command: Device:/> arpsnoop -all This will show the ARP packets being received on the different interfaces and confirm that the correct cables are connected to the correct interfaces.
Chapter 3: CorePlus Configuration 3.6. Going Further with CorePlus After initial setup is complete, the administrator is ready to go further with configuring CorePlus to suit the requirements of a particular networking scenario.
Chapter 3: CorePlus Configuration captures recent log messages in hardware memory. The administrator should review what events are important to them and at what severity. The CorePlus Log Reference Guide provides a complete listing of the log messages that CorePlus is capable of generating. The CLI Reference Guide The CLI Reference Guide provides a complete listing of the available CLI commands with their options. A CLI overview is also provided as part of the CorePlus Administrators Guide.
Chapter 3: CorePlus Configuration 58
Chapter 4: Warranty Service Limitation of Warranty Clavister warrants to the customer of the SG3200 Series Appliance that the Hardware components will be free from defects in material and workmanship under normal use for a period of two (2) years from the Start Date (as defined below).
Chapter 4: Warranty Service paid by the Purchaser. The address for shipping is: Clavister AB Sjögatan 6J 891 60 Örnsköldsvik SWEDEN If the product has not yet been registered with the Clavister through it's client web, a proof of purchase (such as a copy of the dated purchase invoice) must be provided with the shipped product. An RMA Number Must Be Obtained Before Shipping Any package returned to Clavister without an RMA number will be rejected and shipped back to the Purchaser at the Purchaser's expense.
Chapter 5: Safety Precautions Safety Precautions Clavister SG3200 Series devices are Safety Class I products and have protective ground terminals. There must be an uninterrupted safety earth ground from the main power source to the product’s input wiring terminals, power cord, or supplied power cord set. Whenever it is likely that the protection has been impaired, disconnect the power cord until the ground has been restored.
Chapter 5: Safety Precautions Informations concernant la sécurité Cet appareil est un produit de classe I et possède une borne de mise à la terre. La source d’alimentation principale doit être munie d’une prise de terre de sécurité installée aux bornes du câblage d’entree, sur le cordon d’alimentation ou le cordon de raccordement fourni avec le produit. Lorsque cette protection semble avoir été endommagée, débrancher le cordon d’alimentation jusqu’à ce que la mise à la terre ait été réparée.
Chapter 5: Safety Precautions • se la vostra LAN copre un’area servita da più di un sistema di distribuzione elettrica, accertatevi che i collegamenti a terra di sicurezza siano ben collegati fra loro; • i cavi LAN possono occasionalmente andare soggetti a pericolose tensioni transitorie (ad esempio, provocate da lampi o disturbi nella griglia d’alimentazione della società elettrica); siate cauti nel toccare parti esposte in metallo della rete.
Appendix A: Specifications Below are the key hardware specifications for Clavister SG3200 Series installation. Dimensions, Weight and MTBF - 3200A/B Height x Width x Depth (mm) 44 x 431 x 461 Hardware Weight 4.4 kg Hardware Form Factor 1U 19 inch Rack Mountable Yes MTBF 57,054 hours Dimensions, Weight and MTBF - 3200C Height x Width x Depth (mm) 44 x 431 x 370 Hardware Weight 7.
Appendix A: Specifications 3200C Power Specifications Power Supply (AC) 100-240V, 50-60 Hz, 5-3 Amps Typical Consumption (W) 70 W BTU 239 BTU PSU Rated Power (W) 220 W Further information For complete product specifications refer to: http://www.clavister.
Appendix B: Declarations of Conformity 66
Appendix B: Declarations of Conformity 67
Appendix C: Vista IP Setup If a PC running Microsoft Vista is being used as the CorePlus management workstation, the computer's Ethernet interface connected to the Clavister Security Gateway must be configured with an IP address which belongs to the network 192.168.1.0/24 and is different from the security gateway's address of 192.168.1.1. The IP address 192.168.1.30 will be used for this purpose and the steps to set this up with Vista are as follows: 1. Press the Windows Start button. 2.
Appendix C: Vista IP Setup Select and display the properties for Internet Protocol Version 4 (TCP/IPv4). 7. In the properties dialog, select the option Use the following IP address and enter the following values: • IP Address: 192.168.1.30 • Subnet mask: 255.255.255.0 • Default gateway: 192.168.1.1 DNS addresses can be entered later once Internet access is established. 8. Click OK to close this dialog and close all the other dialogs opened since step (1).
Appendix D: Windows 7 IP Setup If a PC running Microsoft Windows 7 is being used as the CorePlus management workstation, the computer's Ethernet interface connected to the Clavister Security Gateway must be configured with an IP address which belongs to the network 192.168.1.0/24 and is different from the security gateway's address of 192.168.1.1. The IP address 192.168.1.30 will be used for this purpose and the steps to set this up with Windows 7 are as follows: 1. Press the Windows Start button. 2.
Appendix D: Windows 7 IP Setup Select and display the properties for Internet Protocol Version 4 (TCP/IPv4). 7. In the properties dialog, select the option Use the following IP address and enter the following values: • IP Address: 192.168.1.30 • Subnet mask: 255.255.255.0 • Default gateway: 192.168.1.1 DNS addresses can be entered later once Internet access is established. 8. Click OK to close this dialog and close all the other dialogs opened since step (1).
Appendix E: Apple Mac IP Setup An Apple Mac can be used as the management workstation for initial setup of a Clavister Security Gateway. To do this, a selected Ethernet interface on the Mac must be configured correctly with a static IP. The setup steps for this with Mac OS X are: 1. Go to the Apple Menu and select System Preferences. 2. Click on Network. 3. Select Ethernet from the left sidebar menu. 4. Select Manually in the Configure pull down menu.
Appendix E: Apple Mac IP Setup 5. 6. Now set the following values: • IP Address: 192.168.1.30 • Subnet Mask: 255.255.255.0 • Router: 192.168.1.1 Click Apply to complete the static IP setup.
Clavister AB Sjögatan 6J SE-89160 Örnsköldsvik SWEDEN Phone: +46-660-299200 Fax: +46-660-12250 www.clavister.