Lightning SA MultiCom User manual

For Firmware 3.7 -10/19/04
MultiCom Firewall
User's Manual

ii MultiCom Firewall User’s Manual

MultiCom Firewall User’s Manual iii
User's Manual
Copyright © 2004 Lightning SA and Apliware SA. All Rights Reserved. No part
of this document may be reproduced in any forms by any means without the prior
written consent of Apliware SA.
LIGHTNING Instrumentation SA
Avenue des Boveresses 50
Lausanne, Vaud 1010
Switzerland
Phone +41.21.654.2000
Fax +41.21.654.2001
http://www.lightning.ch
APLIWARE SA
rue du Grand-Pré 70
1222 Geneva 2
Switzerland
Phone +41.22.918.3610
Fax +41.22.918.3695
http://www.apliware.com

iv MultiCom Firewall User’s Manual

MultiCom Firewall User’s Manual v
Copyright, Warranty, Liability
Copyright, Warranty,
Liability
Copyright
The technical information in this
document is proprietary to
LIGHNTING S.A. and APLIWARE
S.A. and the recipient has a personal,
non-exclusive and non-transferable
license to use this information solely
with the use of LIGHNTING S.A.
and APLIWARE S.A. products.
The information in this document is
subject to change without notice.
Revisions may be issued at any time.
Trademarks
MultiCom and Lightning are
registered trademarks of
LIGHTNING Instrumentation SA.
Stac LZS and Hi/fn are registered
trademarks of Hi/fn, Inc. All other
company, brand and product names
may be registered trademarks or
trademarks of their respective
companies and are hereby
recognized.
Revisions
This publication and the information
herein is furnished AS IS, subject to
change without notice, and should
not be construed as a commitment by
LIGHNTING S.A. and APLIWARE
S.A. Furthermore, LIGHNTING
S.A. and APLIWARE S.A. assumes
no responsibility or liability for any
errors or inaccuracies, makes no
warranty of any kind (express,
implied or statutory) with respect to
this publication, and expressly
disclaims any and all warranties of
merchantability, fitness for particular
purposes and noninfringement of
third-party right.
Warranty
NO WARRANTIES ARE
EXTENDED BY THIS
DOCUMENT. The only product
warranties made by LIGHNTING
S.A. and APLIWARE S.A., if any,
are set forth in the agreed terms and

Chapter Copyright, Warranty, Liability
vi MultiCom Firewall User’s Manual
conditions for the purchase of
LIGHNTING S.A. and APLIWARE
S.A. products. LIGHNTING S.A.
and APLIWARE S.A. declaims
liability for any and all direct and
indirect damages that may result
from publication or use of this
document and/or its contents.
LIGHNTING S.A. and APLIWARE
S.A. warrants all hardware products
of its manufacture to be free from
defects in material and workmanship
for 12 months from date of delivery.
Upon prompt notification by the
purchaser, LIGHNTING S.A. and
APLIWARE S.A. will correct,
within the warranty period, any
defects in equipment of its
manufacture either by repair at its
factory or by supply of replacement
parts to the purchaser.
LIGHNTING S.A. and APLIWARE
S.A. must decide to its own
satisfaction that the equipment is
defective and has not developed
malfunctions as a result of misuse,
modification, or abnormal conditions
of operation. Damages due to over
voltage (e.g. lightning strokes) or
wrong cabling on any interface are
expressly excluded from the
warranty. Opening the products also
voids the warranty. LIGHNTING
S.A. and APLIWARE S.A. assumes
no liability for consequential
damages, and its liability shall in no
case exceed the original purchase
price of the equipment.
The warranties set forth above are
the sole warranties applicable to
LIGHNTING S.A. and APLIWARE
S.A. products. THE IMPLIED
WARRANTY OF
MERCHANTABILITY AND ALL
OTHERWARRANTIES,EXPRESS
OR IMPLIED, ARE EXCLUDED.
Limitation of Liability
UNDER NO CIRCUMSTANCES,
INCLUDING NEGLIGENCE,
SHALL LIGHNTING S.A. AND
APLIWARE S.A. BE LIABLE FOR
LOSS OF USE, INTERRUPTION
OF BUSINESS, OR ANY
INDIRECT, SPECIAL,
INCIDENTAL, OR
CONSEQUENTIAL DAMAGES
OF ANY KIND (INCLUDING
LOST PROFITS) REGARDLESS
OF THE FORM OF ACTION
WHETHERIN CONTRACT, TORT
(INCLUDING NEGLIGENCE),
STRICT PRODUCT LIABILITY
OR OTHERWISE, EVEN IF
LIGHNTING S.A. AND
APLIWARE S.A. HAS BEEN
ADVISED OF THE POSSIBILITY
OF SUCH DAMAGES.
In no event shall LIGHNTING S.A.
and APLIWARE S.A. be liable for
costs of procurement of substitute
goods. The potential liability of
LIGHNTING S.A. and APLIWARE
S.A. arising out of this product is in

MultiCom Firewall User’s Manual vii
Software and Documentation License
any case limited to the purchase
price paid to LIGHNTING S.A. and
APLIWARE S.A. for its products.
Software and Documentation
License
The software and documentation
included in or with products of
LIGHNTING S.A. and APLIWARE
S.A. is subject to following licence.
Third-Party Software. A part of the
software used within the MultiCom
Ethernet series can be freely
distributed under the terms of the
GNU Public License and BSD
copyright. However, some
applications remain the property of
their owners, and require their
permission to redistribute. For a
complete listing of the software used
within the MultiCom Firewall, and
the terms under which it can be
distributed, refer to the LIGHTNING
Web site at http://www.lightning.ch/
and to the Appendix on Additional
Licenses and Copyrights.
Shareware and Freeware Software.
Your MultiCom Companion CD
contains shareware, freeware and
other 3rd Party software not
developed by LIGHNTING S.A. and
APLIWARE S.A. Such software is
neither warranteed or supported by
LIGHNTING S.A. and APLIWARE
S.A. and is not necessary to use
LIGHNTING S.A. and APLIWARE
S.A. products. If you wish to use it
be sure to check that it meets your
company's standards for reliability,
security and useability. Please check
with the developer of the software
for any necessary information about
the use or capabilities of such
included software.
While all included software on this
CD has been virus checked and
tested LIGHNTING S.A. and
APLIWARE S.A. does not provide
any guarantees concerning these
products. Be sure to use any virus
protection that is required by your
company before using the included
software. If you go to a website of
these software developers be sure to
virus check any software that you
download from them before using it
as well.
LIGHNTING S.A. and APLIWARE
S.A. cannot accept responsibility for
any disruption, damage and/or loss to
your data or computer system that
may occur while using these
programs. If you are unsure about
what you are doing check with your
network administrator before
installing any software.
License. The software, on any media,
including disk, read-only memory,
and flash memory and the products
related documentation are licensed to
you by LIGHNTING S.A. and
APLIWARE S.A.. You own the
media on which the LIGHNTING
S.A. and APLIWARE S.A. software
is recorded, but LIGHNTING S.A.
and APLIWARE S.A. and/or

Chapter Copyright, Warranty, Liability
viii MultiCom Firewall User’s Manual
LIGHNTING S.A. and APLIWARE
S.A.'s Licensor(s) retain title to the
LIGHNTING S.A. and APLIWARE
S.A. software and related
documentation. The license allows
you to use the LIGHNTING S.A.
and APLIWARE S.A. software on a
single LIGHNTING S.A. and
APLIWARE S.A. hardware product.
In the case of software on disk, you
are allowed to make one copy of
LIGHNTING S.A. and APLIWARE
S.A. software in machine-readable
form for backup purposes only. You
must reproduce on such copy the
LIGHNTING S.A. and APLIWARE
S.A. copyright notice and any other
proprietary legends that were on the
original copy of the disk containing
LIGHNTING S.A. and APLIWARE
S.A. software. You may also transfer
all your license rights in the
LIGHNTING S.A. and APLIWARE
S.A. software, together with the
associated hardware, the backup
copy, the related documentation, and
a copy of this license to another
party, provided the other party reads
and agrees to accept the terms and
conditions of this license.
Restrictions. The LIGHNTING S.A.
and APLIWARE S.A. software
contains copyrighted materials, trade
secrets, and other proprietary
materials and in order to protect
them you may not decompile,
reverse engineer, disassemble, or
otherwise reduce the LIGHNTING
S.A. and APLIWARE S.A. software
to a human-perceivable form. You
may not modify, network, rent, lease,
loan, distribute, or create derivative
works based upon the LIGHNTING
S.A. and APLIWARE S.A. software
in whole or in part. You may not
electronically transmit the
LIGHNTING S.A. and APLIWARE
S.A. software from one computer to
another or over a network.
Termination. This license is effective
until terminated. You may terminate
this license at any time by destroying
the LIGHNTING S.A. and
APLIWARE S.A. software, the
related hardware, related
documentation and all copies
thereof. The license will terminate
immediately without notice from
LIGHNTING S.A. and APLIWARE
S.A. if you fail to comply with any
provision of this license. Upon
termination you must destroy the
LIGHNTING S.A. and APLIWARE
S.A. software, the related hardware,
related documentation and all copies
thereof.
Limited Warranty on Media.
LIGHNTING S.A. and APLIWARE
S.A. warrants the media on which
the software is recorded as its
hardware materials, and limits the
liability as set for the hardware
material.
Disclaimer of warranty on
LIGHNTING S.A. and APLIWARE
S.A. software. You expressly
acknowledge and agree that use of

MultiCom Firewall User’s Manual ix
Software and Documentation License
the LIGHNTING S.A. and
APLIWARE S.A. software is at your
sole risk. The LIGHNTING S.A. and
APLIWARE S.A. software and
related documentation are provided
"AS IS" and without warranty of any
kind and LIGHNTING S.A. and
APLIWARE S.A. EXPRESSLY
DISCLAIM ALL WARRANTIES,
EXPRESS OR IMPLIED,
INCLUDING, BUT NOT LIMITED
TO, THE IMPLIED WARRANTIES
OF MERCHANTABILITY AND
FITNESS FOR A PARTICULAR
PURPOSE. LIGHNTING S.A. AND
APLIWARE S.A. DOES NOT
WARRANT THAT THE
FUNCTIONS CONTAINED IN
THE LIGHNTING S.A. AND
APLIWARE S.A. SOFTWARE
WILL MEET YOUR
REQUIREMENTS, OR THAT THE
OPERATION OF THE
LIGHNTING S.A. AND
APLIWARE S.A. SOFTWARE
WILL BE UNINTERRUPTED OR
ERROR-FREE, OR THAT
DEFECTS IN THE LIGHNTING
S.A. AND APLIWARE S.A.
SOFTWARE WILL BE
CORRECTED. FURTHERMORE,
LIGHNTING S.A. AND
APLIWARE S.A. DOES NOT
WARRANT OR MAKE ANY
REPRESENTATIONS
REGARDING THE USE OR THE
RESULTS OF THE USE OF THE
LIGHNTING S.A. AND
APLIWARE S.A. SOFTWARE OR
RELATEDDOCUMENTATIONIN
THE TERMS OF THEIR
CORRECTNESS, ACCURACY,
RELIABILITY, OR OTHERWISE.
NO ORAL OR WRITTEN
INFORMATION OR ADVICE
GIVEN BY LIGHNTING S.A. AND
APLIWARE S.A. OR A
LIGHNTING S.A. AND
APLIWARE S.A.-AUTHORIZED
REPRESENTATIVE SHALL
CREATE A WARRANTY OR IN
ANY WAY INCREASE THE
SCOPE OF THIS WARRANTY.
SHOULD THE LIGHNTING S.A.
AND APLIWARE S.A.
SOFTWARE PROVE DEFECTIVE,
YOU (AND NOT LIGHNTING
S.A. AND APLIWARE S.A. OR A
LIGHNTING S.A. AND
APLIWARE S.A. AUTHORIZED
REPRESENTATIVE) ASSUME
THE ENTIRE COST OF ALL
NECESSARY SERVICING,
REPAIR, OR CORRECTION. Some
jurisdictions do not allow the
exclusion of implied warranties, so
the above exclusion may not apply to
you.
Limitation of Liability. Conforming
to the general limitation of liability.
Controlling Law and Severability.
This license shall be governed by
and construded in accordance with
the laws of Switzerland and Canton
de Vaud, as applied to agreements
entered into and to be performed
entirely between Canton de Vaud
residents. If for any reason a court of
competent jurisdiction finds any

Chapter Copyright, Warranty, Liability
x MultiCom Firewall User’s Manual
provision of this license, or portions
thereof, to be unenforceable, that
provision of the license shall be
enforced to the maximum extent
permissible so as to effect the intent
of the parties, and the remainder of
this license shall continue in full
force and effect.
Complete agreement. The license
constitutes the entire agreement
between the parties with respect to
the use of the LIGHNTING S.A. and
APLIWARE S.A. software and
related documentation, and
supersedes all prior or
contemporaneous understandings or
agreements, written or oral,
regarding such subject matter. No
amendment to or modification of the
License will be binding unless in
writing and signed by a duly
authorized representative of
LIGHNTING S.A. and APLIWARE
S.A..
Export
Some versions and options of
LIGHNTING S.A. and APLIWARE
S.A.'s Software and Hardware,
including technical data, may be
subject to Swiss, E.U., U.S.
(including the U.S. Export
Administration Act) or other
countries export control laws, and
their associated regulations, and may
be subject to export or import
regulations in other countries.
Customer agrees to comply strictly
with all such regulations and
acknowledges that it has the
responsibility to obtain licenses to
export, re-export, or import Software
and Hardware.

Contents
MultiCom Firewall User’s Manual xi
Contents
Copyright, Warranty, Liability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v
Chapter 1 Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Your New MultiCom Firewall. . . . . . . . . . . . . . . . . 17
MultiCom Firewall Features. . . . . . . . . . . . . . . . . . . 17
Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
IPSec VPN Option . . . . . . . . . . . . . . . . . . . . . . . 21
SSH VPN Option . . . . . . . . . . . . . . . . . . . . . . . . 21
High Availability Option. . . . . . . . . . . . . . . . . . . 21
Network Monitoring Option . . . . . . . . . . . . . . . . 22
About This Manual. . . . . . . . . . . . . . . . . . . . . . . . . . 22
Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Packaging Contents . . . . . . . . . . . . . . . . . . . . . . . . . 24
If The Product Is Received Damaged. . . . . . . . . . . . 24
To Return The Product . . . . . . . . . . . . . . . . . . . . 24
Chapter 2 Introducing The MultiCom Firewalls . . . . . . . . . . . . 27
MultiCom Firewalls . . . . . . . . . . . . . . . . . . . . . . . . . 27
Introducing the Ethernet II . . . . . . . . . . . . . . . . . . . . 28
Back Panel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
Front Panel of the Ethernet II . . . . . . . . . . . . . . . 29

xii MultiCom Firewall User’s Manual
Introducing the Ethernet III . . . . . . . . . . . . . . . . . . . 30
Back Panel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
Front Panel of the Ethernet III. . . . . . . . . . . . . . . 31
Introducing the MultiCom SpeedSurf . . . . . . . . . . . 32
Back Panel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
Front Panel of the MultiCom SpeedSurf. . . . . . . 33
Introducing the Enterprise Ethernet . . . . . . . . . . . . . 34
Back Panel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
Front Panel of the Enterprise Ethernet . . . . . . . . 35
Network Requirements. . . . . . . . . . . . . . . . . . . . . . . 36
Advanced Configuration Software Requirements . . 36
Safety Precautions . . . . . . . . . . . . . . . . . . . . . . . . . . 37
Chapter 3 Getting Started. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39
Connecting the MultiCom Firewall . . . . . . . . . . . . . 40
Configuring Your Computers. . . . . . . . . . . . . . . . . . 42
Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43
Macintosh . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46
Linux . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48
Choosing the Internet Connection . . . . . . . . . . . . . . 48
Common Configurations. . . . . . . . . . . . . . . . . . . 48
Special Configurations . . . . . . . . . . . . . . . . . . . . 50
Configuration Checklist . . . . . . . . . . . . . . . . . . . 52
Plug & Play Configuration: DHCP . . . . . . . . . . . . . 54
Using the Easy Setup . . . . . . . . . . . . . . . . . . . . . . . . 55
Accessing the Easy Setup Web Server . . . . . . . . 56
WAN DHCP Easy Setup. . . . . . . . . . . . . . . . . . . 57
WAN PPPoE Easy Setup . . . . . . . . . . . . . . . . . . 58
WAN PPTP Easy Setup . . . . . . . . . . . . . . . . . . . 59
WAN Static IP Easy Setup . . . . . . . . . . . . . . . . . 61
LAN Easy Setup . . . . . . . . . . . . . . . . . . . . . . . . . 63
DMZ Easy Setup. . . . . . . . . . . . . . . . . . . . . . . . . 64
Easy Firewall Setup. . . . . . . . . . . . . . . . . . . . . . . 65
Saving The Configuration. . . . . . . . . . . . . . . . . . 66
Fine Tuning Your Configuration . . . . . . . . . . . . . . . 67
Activate Option Keys . . . . . . . . . . . . . . . . . . . . . 68
Configure Date And Time. . . . . . . . . . . . . . . . . . 68
Create New Privileged Administrator. . . . . . . . . 69

MultiCom Firewall User’s Manual xiii
Quick Interface Configuration . . . . . . . . . . . . . . 69
Testing Your Configuration . . . . . . . . . . . . . . . . . . . 70
Testing Security. . . . . . . . . . . . . . . . . . . . . . . . . . 71
Testing Connection Speed. . . . . . . . . . . . . . . . . . 72
Registering Your Firewall . . . . . . . . . . . . . . . . . . . . 72
Chapter 4 Maintenance. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
Web Server Status Reports. . . . . . . . . . . . . . . . . . . . 74
Monitor Status Reports . . . . . . . . . . . . . . . . . . . . . . 76
Telnet/ Console Status Reports . . . . . . . . . . . . . . . . 79
Error Messages. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83
LED Light Messages. . . . . . . . . . . . . . . . . . . . . . 83
Syslog Messages . . . . . . . . . . . . . . . . . . . . . . . . . 84
SNMP Messages . . . . . . . . . . . . . . . . . . . . . . . . . 84
Configurator messages . . . . . . . . . . . . . . . . . . . . 85
Web Server Toolbox. . . . . . . . . . . . . . . . . . . . . . . . . 85
Web Server Advanced Tools . . . . . . . . . . . . . . . . . . 86
Backup Your Configuration. . . . . . . . . . . . . . . . . . . 87
Restoring A Configuration. . . . . . . . . . . . . . . . . . . . 88
Updating Your Firmware . . . . . . . . . . . . . . . . . . . . . 88
LED Status During Upgrade. . . . . . . . . . . . . . . . 92
Troubleshooting Firmware Upgrade. . . . . . . . . . 93
Chapter 5 Troubleshooting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95
Basic Things To Check . . . . . . . . . . . . . . . . . . . . . . 96
Common Local Network Problems . . . . . . . . . . . . . 97
DHCP Troubleshooting . . . . . . . . . . . . . . . . . . . . . . 98
DHCP To The Internet . . . . . . . . . . . . . . . . . . . . 98
DHCP On Your Local Network . . . . . . . . . . . . 100
PPPoE Troubleshooting . . . . . . . . . . . . . . . . . . . . . 101
Incorrect Password . . . . . . . . . . . . . . . . . . . . . . 102
PPPoE Server (ISP) Not Available . . . . . . . . . . 102
Some Web Sites Are Not Available . . . . . . . . . 102
Other Sources Of DSL Information . . . . . . . . . 103
PPTP Troubleshooting . . . . . . . . . . . . . . . . . . . . . . 104
Incorrect Password . . . . . . . . . . . . . . . . . . . . . . 104
PPTP Server Not Available. . . . . . . . . . . . . . . . 104
Incorrect IP configuration of WAN or LAN. . . 105
Resetting The Default Configuration . . . . . . . . . . . 105

xiv MultiCom Firewall User’s Manual
Chapter 6 Frequently Asked Questions. . . . . . . . . . . . . . . . . . . 107
Frequently Asked Questions. . . . . . . . . . . . . . . . . . 107
Software, Shareware and Freeware . . . . . . . . . . . . 111
General Utilities . . . . . . . . . . . . . . . . . . . . . . . . 111
Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 111
Macintosh OS Classic . . . . . . . . . . . . . . . . . . . . 112
Macintosh OSX. . . . . . . . . . . . . . . . . . . . . . . . . 113
Linux . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114
Appendix A Hardware Specifications. . . . . . . . . . . . . . . . . . . . . . 115
Ethernet II. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 116
Physical Specifications . . . . . . . . . . . . . . . . . . . 116
Declaration of Conformity . . . . . . . . . . . . . . . . 117
Ethernet III . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 118
Physical Specifications . . . . . . . . . . . . . . . . . . . 118
Declaration of Conformity . . . . . . . . . . . . . . . . 119
MultiCom SpeedSurf . . . . . . . . . . . . . . . . . . . . . . . 120
Physical Specifications . . . . . . . . . . . . . . . . . . . 120
Declaration of Conformity . . . . . . . . . . . . . . . . 121
Enterprise Ethernet. . . . . . . . . . . . . . . . . . . . . . . . . 122
Physical Specifications . . . . . . . . . . . . . . . . . . . 122
Declaration of Conformity . . . . . . . . . . . . . . . . 123
Pin Assignments. . . . . . . . . . . . . . . . . . . . . . . . . . . 124
Appendix B Additional Licenses and Copyrights . . . . . . . . . . . . 125
Licensing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125
Apache License . . . . . . . . . . . . . . . . . . . . . . . . . 125
BSD Copyright . . . . . . . . . . . . . . . . . . . . . . . . . 125
GNU General Public License . . . . . . . . . . . . . . 127
OpenSSL License . . . . . . . . . . . . . . . . . . . . . . . 133
Original SSLeay License. . . . . . . . . . . . . . . . . . 135
TCPD License. . . . . . . . . . . . . . . . . . . . . . . . . . 136
Login License . . . . . . . . . . . . . . . . . . . . . . . . . . 137
Cryptix General License . . . . . . . . . . . . . . . . . . 137
PureTls License. . . . . . . . . . . . . . . . . . . . . . . . . 138
Copyrights . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139
BSD Copyright . . . . . . . . . . . . . . . . . . . . . . . . . 139
Glossary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 147

MultiCom Firewall User’s Manual xv

xvi MultiCom Firewall User’s Manual

MultiCom Firewall User’s Manual 17
Chapter 1
Preface
Your New MultiCom Firewall
Congratulations on the purchase of your MultiCom Firewall. Your firewall has
been designed to offer security and high performance networking management,
all through an easy to use interface.
Whether you are connecting a single computer from home or managing a
company network you will find that the MultiCom Firewalls can help. You now
have access to many networking possibilities, for instance you can secure your
data, share your Internet connection with multiple computers and filter or receive
notifications of potential network attacks.
For the latest release notes, documentation, firmware and software check the
Lightning website at http://www.lightning.ch/support.
MultiCom Firewall Features
Security
• Dual firewalls, using Stateful Packet Inspection (SPI) Filtering and/ or a NAT
based Firewall on each interface to protect against External Intrusions, Denial

Chapter 1 Preface
18 MultiCom Firewall User’s Manual
of Service (DoS), Port Scanning, Spoofing Attacks and more
• URL Filtering to block or drop web connections based on URL or keywords.
• Intrusion Detection System (IDS) using SPI filtering & syslog
• Real time alerts and statistics using Syslog, SNMPv2, web-based Event
Monitor, email and more
• Up to 10 separate user accounts with passwords and access rights
• Secure SSL (HTTPS) & SSHv1-2 (telnet CLI) for remote access &
configuration
• DMZ interface support giving extra security for network servers (Ethernet III
and Enterprise Ethernet only)
Internet Access
• Connect multiple computers and ethernet devices to the Internet using
Internet Sharing using Network Address Translation (NAT)
• Easy Setup & Easy Firewall wizards via the web interface or the
multi-platform Configurator software
• DNS Cache for faster Internet response
• Dynamic DNS supporting 9 different services for finding your computer even
if the IP address changes
• Multimedia (H.323, IRC, ICQ) and PPTP client pass through support with
NAT
• DHCP server (up to 1,000 clients) for automatic IP configuration to clients or
DHCP Relay on any Interface
• Ethernet parameter editing for MTU, MAC address, duplex and speed
• Integrated PPPoE client, for single or multiple concentrators (for ISP backup
purposes)
• Network traffic round-robin load sharing using NAT
• Virtual IP address support for one or more IP addresses using ARP Proxy and
Network Address Translation
• IP Port Redirection with NPAT Network Port & Address Translation
• Static and dynamic routing using RIP (V1 and v2)
Management
• Configurator software for configuring Virtual Private Networks, validating
configurations, managing all features and firewall rules. Available for

MultiCom Firewall User’s Manual 19
MultiCom Firewall Features
Windows, Macintosh, and Linux. With secured remote access.
• Monitor software to manage status and restart services like PPP, IPSec,
VRRP, DHCP. Available for Windows, Macintosh, and Linux. With
secured remote access.
• Configuration scheduling for up to 6 configuration files based on day, hour or
minute.
• Telnet, console & ssh Command Line Interface (CLI) with powerful network
tools like ping, traceroute name server lookup. Ideal for scriptable
configuration changes using 3rd party software like CatTools for time based
and centralized management
• Quick Restore Button with LED feedback to load boot config, emergency
config (config 1), or the factory default configuration. Additional memory is
available on each device to store up to 6 different configurations.
• Centralized time management using the Network Time Protocol
• Transfer configurations to and from the device using the File Transfer
Protocol (FTP)
• Built-in Domain Name Server (DNS) to name local computers
• Multilingual with English, French and German built-in
• Upgradable flash memory
Software Add-on Options
• IPSec based Virtual Private Network (VPN) supporting Gateway, client and
point-to-point modes. Preshared, Manual and PKI x.509 Keys for central
management and 3rd party vendor compatibility. Support for multiple
world-class encryption ciphers such as AES (Rijndael), CAST 128, Twofish,
Blowfish, 3DES and more. Includes Dead Peer Detection (DPD), NAT
Traversal, DHCP over IPSec, Traffic filtering, Domain Name endpoints,
Connection testing support.
• SSH Port Forwarding VPN Gateway with public key or user based access,
using SSH v1 and v2. With unique authentication for up to 10 users.
• High Availability using the VRRP protocol with authentication
• Network Intrusion Detection System (NIDS) using SNORT for Enterprise
devices
• Network Monitoring Service for monitoring local and remote TCP servers.
• Certificate Manager software for generating, managing and deploying PKI
x.509 keys, certificates and certification authorities. Available for Windows,

Chapter 1 Preface
20 MultiCom Firewall User’s Manual
Macintosh, and Linux.
• VPN Client software available
Network Hardware
• 10/100 Mbit/s multi-interface Switch for high-speed communication within
your network (Ethernet III & Enterprise Ethernet only)
• 10/100 Mbit/s autosensing LAN interface for your Local network
• DSL annex A integrated modem (Enterprise DSL only)
• 802.11b WiFi with LAN Bridge (Enterprise WiFi only)
Options
Certain functionalities, such as IPSec VPN, SSH Port Forwarding VPN, High
Availability or Network Monitoring are not immediately available in the standard
firmware releases. These functions are called Options and need to be purchased
and activated to be useable.
Activation of Options currently requires the user to install a unique key file
(versions before 3.4 required a special firmware) containing the purchased
options and then reboot the MultiCom Firewall. Currently the options are
available IPSec VPN 2 tunnels, IPSec VPN 20 tunnels and unlimited IPSec VPN
tunnel options.
• IPSec VPN 2 Tunnels
• IPSec VPN 20 Tunnels
• IPSec VPN unlimited Tunnels
• SSH Port Forwarding VPN 10 Users
• High Availability (VRRP)
• Network Monitoring
Below are the requirements of this process:
• The option key or firmware is only valid on the machine for which it was
purchased.
• For machines using a Lightning Linux older than 3.2, you must either first
upgrade to the standard OS 3.2 and then apply the firmware with the option
or upgrade to at least OS 3.4 and apply the option key.
Table of contents
Popular Firewall manuals by other brands

Fortinet
Fortinet FortiMail-100 install guide

Fortinet
Fortinet FortiGate FortiGate-100A quick start guide

FEITIAN
FEITIAN MultiPass FIDO product manual

Fortinet
Fortinet FortiGate FortiGate-5001SX Security system guide

Cisco
Cisco IronPort C370 quick start guide

Ruijie
Ruijie RG-WALL1600-M6600 Hardware installation and reference guide