HotBrick VPN 6000 User manual

HotBrick VPN 6000 user manual
version 193 (2005-01-20)

Title HotBrick VPN 6000 user manual
Author Martijn Bakker
Revision 193 (05-01-20)
All rights reserved. No part of this publication may be reproduced, stored
in a retrieval system, or transmitted, in any form, or by any means,
electronic, mechanical, photocopying, recording or otherwise, without the
prior written consent of the publisher.
Microsoft® and Windows® are trademarks of Microsoft Corporation in the
United States and other countries.
Apple® and Mac OS® are trademarks of Apple Computer, Inc., registered in
the U.S. and other countries.


Table of Contents
1 Installation............................................................................ .................5
1.1 Requirements.......................................................................................................5
1.2 Getting to know your HotBrick VPN 6000.............................................................5
1.2.1 Front..............................................................................................................5
1.2.2 Back..............................................................................................................5
1.3 Hardware installation...........................................................................................5
1.4 Connecting to the management interface............................................................6
1.4.1 Configure a notebook or PC to use DHCP......................................................6
Enabling DHCP using Windows® 2000...............................................................6
Enabling DHCP using Windows® XP.................................................................10
Enabling DHCP using Mac OS® X.....................................................................12
1.4.2 Log in on the firewall management interface..............................................14
1.5 Entering a valid product key..............................................................................15
1.6 Running the “Quick install” wizard.....................................................................18
1.6.1 Setting up your LAN connection..................................................................18
1.6.2 Setting up your default internet connection................................................21
Setting up WAN1 using DHCP...........................................................................22
Setting up WAN1 using a Static/Nat connection...............................................22
Setting up WAN1 using a PPTP or PPPoE connection........................................23
1.6.3 Setting up your fallback internet connection...............................................23
1.6.4 Confirming and applying results..................................................................24
1.6.5 Connecting to the firewall's management interface....................................25
1.7 Backup sets........................................................................................................26
1.8 Changing the administrator's password.............................................................28
1.9 Setting the firewall's time and date...................................................................30
1.10 (Optionally) disable the firewall's DHCP server................................................31
1.11 Connecting LAN and WAN cables.....................................................................32
1.12 Errors and recovery..........................................................................................33

- HotBrick VPN 6000 user manual -
1 Installation
1.1 Requirements
To insure a smooth installation of your HotBrick VPN 6000, we should make sure to
have all the necessary equipment and information ready. To configure your firewall for
the first time we will need
1x HotBrick VPN 6000
1x Standard power cord (bundled with HotBrick VPN 6000)
2x UTP RJ45 cables (bundled with HotBrick VPN 6000)
1x PC or notebook computer
1x HotBrick VPN 6000 license key
If we are to set up your firewall to handle one or more Internet connections, we will
also need
Connection details provided by your Internet Service Provider (ISP)
1.2 Getting to know your HotBrick VPN 6000
1.2.1 Front
1.2.2 Back
1.3 Hardware insta ation
➔Use the power cord to connect the HotBrick VPN 6000's power socket (15) to a
standard wall power outlet.
➔Switch the firewall on, using the power switch (16), on the back of the device.
Booting the hardware for the first time may take up to 1 minute.
When the firewall is switched on and ready, you should hear 3 short beeps. If you have
not heard 3 beeps within 1 minute of switching on the device, please refer to section
1.12 ( Errors and recovery).
page 5 / 33 version 193 (05-01-20)
.1 LCD display
.2 Serial port
.3 WAN1 port
.4 WAN1 connection LED
.5 WAN2 port
.6 WAN2 connection LED
.7 FLEX1 port
.8 FLEX1 connection LED
.9 FLEX2 port
.10 FLEX2 connection LED
.11 FLEX3 port
.12 FLEX3 connection LED
.13 FLEX4 port
.14 FLEX4 connection LED
.15 Power socket
.16 Power switch
.17 More??

- HotBrick VPN 6000 user manual -
➔Use an UTP RJ45 cable to connect the firewall's FLEX1 port (7) to a network
connector on your PC or notebook.
➔Switch on the PC or notebook.
The FLEX1 connection LED above the FLEX1 port (8) should come on. If this LED does
not come on, please refer to section 1.12 ( Errors and recovery).
1.4 Connecting to the management interface
Your HotBrick VPN 6000 is highly configurable by means of a powerful management
interface. Once the device is properly set up you will be able to access this interface
from any machine in your local network (provided you know the right password). For
the initial setup of the firewall we will make use of the same management interface.
However, because the device is not set up to connect with a local network or Internet
connection, it must first be configured using a single PC or notebook.
1.4.1 Configure a notebook or PC to use DHCP
If you are to use the firewall's management interface from your notebook or PC, then
both are to be connected and using a common network setup. The fastest way to
effect this is to have your PC or Notebook computer configure it's network settings
automatically by means of DHCP (Dynamic Host Configuration Protocol). As this is
done in a slightly different manner by various operating systems, the following
sections will detail the procedure for enabling DHCP in Windows® 2000, Windows® XP
(or Windows® 2003) and Mac OS X® respectively.
Enab ing DHCP using Windows® 2000
➔Using the Windows® “Start” menu (and Settings sub menu), open the “Control
Panel”.
revision 193 (05-01-20) page 6 / 33

- HotBrick VPN 6000 user manual -
➔In the “Control panel”, double click the “Network and Dial-up Connections” icon.
The window “Network and Dial-up Connections” should open.
➔In the “Network and Dial-up Connections” window, double click the “Local Area
Connection” icon.
page 7 / 33 version 193 (05-01-20)

- HotBrick VPN 6000 user manual -
The “Local Area Connection Status” window should open.
➔In the “Local Area Connection Status” window, click the “Properties”button.
The “Local Area Connection Properties” window should open.
➔In this window, select “Internet Protocol (TCP/IP)” (the blue line in the example
below).
➔Click the “Properties” button.
revision 193 (05-01-20) page 8 / 33

- HotBrick VPN 6000 user manual -
The window “Internet Protocol (TCP/IP) Properties” should open.
➔Make sure settings in this window are as specified in the example above (check
“Obtain an IP address automatically” and “Obtain DNS server address
automatically”.
➔Click the “OK” button to confirm your changes.
➔To verify your settings, open a “Command Prompt” (From the “Start” menu,
through “Programs”, in the “Accessories” sub menu).
➔In the command prompt type
ipconfig
The output should look like this
page 9 / 33 version 193 (05-01-20)

- HotBrick VPN 6000 user manual -
➔If the “IP Address” line does not list an address starting with 192.168.99, please try
typing
ipconfig /renew
This should force the PC or Notebook to request a new network address. If you still fail
to get an “IP Address” in the correct range, please refer to section 1.12 ( Errors and
recovery).
Enab ing DHCP using Windows® XP
➔Using the Windows® “Start” menu (and Settings sub menu), open the “Control
Panel”.
➔In the “Control Panel”, double click the “Network Connections” icon.
The “Network Connections” window should open.
revision 193 (05-01-20) page 10 / 33

- HotBrick VPN 6000 user manual -
➔In the “Network Connections” window, double click the “Local Area Connection”
icon.
The “Local Area Connection Properties” window should open.
➔In the “Local Area Connection Properties” window, select “Internet Protocol (TCP/IP)
” (the blue line in the above example).
➔Then press “Properties”.
The “Internet Protocol (TCP/IP) Properties window should open.
page 11 / 33 version 193 (05-01-20)

- HotBrick VPN 6000 user manual -
➔In the “Internet Protocol (TCP/IP) Properties” window, make sure settings are as in
the above example (“Obtain an IP address automatically” and “Obtain DNS server
address automatically”are selected).
➔Press the “OK” button to confirm your new settings.
➔To verify your settings, open a “Command Prompt” (From the “Start” menu,
through “All Programs”, in the “Accessories” sub menu).
➔In the command prompt type
ipconfig
The output should look like this
➔If the “IP Address” line does not list an address starting with 192.168.99, please try
typing
ipconfig /renew
This should force the PC or Notebook to request a new network address. If you still fail
to get an “IP Address” in the correct range, please refer to section 1.12 ( Errors and
recovery).
revision 193 (05-01-20) page 12 / 33

- HotBrick VPN 6000 user manual -
Enab ing DHCP using Mac OS® X
➔From the Apple® menu, choose “System Preferences”, then “Network”.
The Network window should open.
➔In the “Network” window, make sure the “Show” box is set to show “Active Network
Ports”.
➔Drag “Built-in Ethernet” to the top of the list.
➔Set the “Show” box to “Built-in Ethernet”.
page 13 / 33 version 193 (05-01-20)

- HotBrick VPN 6000 user manual -
➔Now select the “TCP/IP” tab.
➔Switch the “Configure” box to “Using DHCP”.
➔Verify that the “IP address”, “Subnet Mask” and “Router” settings are as shown
(192.168.99.101, 255.255.255.0 and 192.168.99.99 respectively).
➔Click “Apply Now” to confirm your changes.
1.4.2 Log in on the fire all management interface
➔Open a web browser on the PC or Notebook you have just configured
➔Enter the address “ https //192.168.99.99 12000”into the address bar.
➔When prompted for a user name and password, enter “admin” (user name) and
“password” (as password).
➔Click “OK”.
If you get a “timeout”, “not found” or “permission denied” error, please refer to
section 1.12 ( Errors and recovery).
revision 193 (05-01-20) page 14 / 33

- HotBrick VPN 6000 user manual -
1.5 Entering a va id product key
The factory defaults of your HotBrick VPN 6000 do not contain it's product key.
Without the product key, none of the changes you make in the firewall's management
interface can be applied. Therefore, it is essential that the very first thing we do after
establishing a connection is entering a valid product key.
Once you have logged in to the firewall's management interface, you should see the
following welcome screen.
A blue triangle in the upper left-hand corner of the screen indicates we are looking at
the “Current Status”(1) of the firewall. Tabs labeled “Control”(2), “HotView”(3),
“Logs”(4) and “Statistics”(4) provide access to other screens in the “Current Status”
context. The red warning message at the top of the screen (5) indicates the current
lack of a valid license key.
The system status on the left hand side of the screen, about half-way to the bottom
displays some statistics concerning the operation of your firewall's hardware. These
statistics are updated once every 10 seconds, to insure the accuracy of the
information.
Immediately left of the red warning text, in the upper left-hand corner of the screen is
an icon of a globe, fronted by a magic wand (6).
➔Click this icon (7) to enter your license key.
page 15 / 33 version 193 (05-01-20)

- HotBrick VPN 6000 user manual -
The “Setup License Keys” dialog window appears.
➔Enter the license key provided with your HotBrick VPN 6000.
➔Press “Next” to continue.
If you entered the license key correctly, the next window should allow you to confirm
the changes and return to the firewall management interface.
If you have incorrectly entered a license key, you will be asked to enter the license
key again. If the license key should fail repeatedly, the license key may not match
your hardware. Please refer to section 1.12 ( Errors and recovery).
revision 193 (05-01-20) page 16 / 33

- HotBrick VPN 6000 user manual -
After confirming your entered license key, you will see the following screen
Note the license key in the top left corner of the screen (now in black). The blue
triangle in the left of the screen indicates we are now looking at the “Configuration”
context. This has slightly different tabs from the “Current Status” context we saw
before (namely “Config”, “HotView”, “Mail” and “Proxy”).
The “Current Status” context will display information concerning the status of your
device, while we will use the “Configuration” context to make changes to it's intended
behavior.
The “Configuration” context has a number of “wizards” available, that can be used to
provide assistance performing common tasks. The list of wizards is found on the left
hand side of the screen, right below the red “Configuration” text. They are “Internet
Connections”, “Local Area Networks”, “Port forwarders (PNAT)”, “VPN IPSec tunnels”,
“VPN L2TP/PPTP users” and “DMZ setup”. The “Quick install” wizard is not listed here.
Instead, we start the “Quick install” wizard by clicking the red “Quick Install” text,
between the “Current Status” and “Configuration” context indicators.
The next step in setting up your HotBrick VPN 6000 is running the “Quick install”
wizard.
page 17 / 33 version 193 (05-01-20)

- HotBrick VPN 6000 user manual -
1.6 Running the “Quick insta ” wizard
The “Quick install” wizard was intended to allow you to quickly and efficiently tailor
the HotBrick VPN 6000 to match your network's needs and settings. Whenever you
start a “Quick install” wizard, all current configuration data will be lost.
At a first installation this should not pose a problem. However, if you ever feel you
should change important configuration data at a later stage, you are encouraged to
use the “Local Area Networks” or “Internet Connections” wizards from the
“Configuration” context instead.
You may start the “Quick install” wizard by pressing the red “Quick install” text, in the
left hand side of the screen, between “Current Status” and “Configuration”.
➔Start the “Quick install wizard”
When you start the “Quick install” wizard, a warning screen signals the start of this
wizard. The screen is there to prevent you from inadvertently starting the “Quick
install” wizard at a later time, thereby deleting all your current network settings.
However, for a first install, we do not consider this a problem.
➔Click “next”.
1.6.1 Setting up your LAN connection
The first step after starting the wizard is to set up your LAN (Local Area Network)
connection. This is the connection between the firewall and your local network. As a
firewall, the HotBrick VPN 6000 should serve as a buffer between your Internet
revision 193 (05-01-20) page 18 / 33

- HotBrick VPN 6000 user manual -
connections (WAN or Wide Area Network connections) and your local network (or
LAN).
The “Quick Install” wizard will allow you to enter network settings specific to your local
network. First we enter a label to use for the local network. Default setting is “lan”,
which seems sensible. In more complex network environments, with more than one
LAN you may opt to use a more descriptive name (like “public lan” or “accounting lan”
instead). In any case, make sure the names you use are unique throughout your
organization, to avoid confusion arising from identical network names for different
networks.
➔Enter a network name for your local network
The next values to enter are an internal IP Address for the firewall (in the context of
the LAN) and a net mask. Together, the IP Address and the net mask define a network
address for the local network. In our example we use an IP Address of 192.168.0.1,
with a net mask of 24 (bits). A net mask of 24 (=3*8) means that the first three
numbers from the IP Address will be part of the network address, so all addresses in
the network start with 192.168.0. If you already have a local network, then this
network address should have a predefined value (if uncertain, contact your network
administrator). In this case, please note that HotBrick VPN 6000 displays the net mask
as a number of bits, not in the 255.255.255.0 format.
If you do not have a local network, then you need to pick an address for your local
network first. There are a number of possible network addresses set aside for use in a
local network. The table below lists the possible IP addresses, their net masks and
uses
Firewa IP address Net mask Network Address Interna IP
addresses
maximum
addresses
192.168.x.z 24 192.168.x.0 192.168.x.n 254
172.16.x.z 24 172.16.x.0 192.168.x.n 254
10.x.y.z 8 10.0.0.0 10.n.m.p 16 million
Where x, y can denote any predefined number between 0 and 255, z can denote any predefined number
between 1 and 254, while n, m and p may be any number between 1 and 254.
Generally, a local network does not need over 254 IP addresses (per distinct local
network). We would therefore recommend you choose a 192.168.x or 172.16.x
network.
Users who intend to use the HotBrick VPN 6000 to connect their local network to
another LAN by means of a VPN tunnel (or indeed, anyone wishing to leave this option
open) will do well to choose a different network address for each LAN (for example
192.168.0.0, 192.168.1.0, 192.168.2.0 etc.).
page 19 / 33 version 193 (05-01-20)

- HotBrick VPN 6000 user manual -
As an example only, we will make use of a 192.168.0.0 network in this user manual.
We will set the firewall's internal IP address to 192.168.0.1 and the net mask value to
24 (as befits a 192.168.x.0 network).
➔Enter a firewall IP address.
➔Enter the corresponding net mask.
➔Write down the IP address and net mask values for later reference.
➔Click “next” to continue
revision 193 (05-01-20) page 20 / 33
Table of contents
Other HotBrick Network Router manuals