Multitech RouteFinder RF650VPN User manual

RF650VPN
Internet Security Appliance
Quick Start Guide


Quick Start Guide
82013251 Revision B
RouteFinderVPN Model RF650VPN
This publication may not be reproduced, in whole or in part, without prior expressed written permission from
Multi-Tech Systems, Inc. All rights reserved.
Copyright © 2002, by Multi-Tech Systems, Inc.
Multi-Tech Systems, Inc. makes no representations or warranties with respect to the contents hereof and
specifically disclaims any implied warranties of merchantability or fitness for any particular purpose.
Furthermore, Multi-Tech Systems, Inc. reserves the right to revise this publication and to make changes from
time to time in the content hereof without obligation of Multi-Tech Systems, Inc. to notify any person or
organization of such revisions or changes.
Record of Revisions
Revision Date Description
A 9/5/01 Manual released for RouteFinder software version 1.92.
B1/8/02 Manual revised for RouteFinder software version 2.00.
Patents
This Product is covered by one or more of the following U.S. Patent Numbers: 5.301.274; 5.309.562;
5.355.365; 5.355.653; 5.452.289; 5.453.986. Other Patents Pending.
TRADEMARKS
Trademarks of Multi-Tech Systems, Inc.: Multi-Tech, the Multi-Tech logo and RouteFinder.
Windows is a registered trademark of Microsoft Corporation in the United States and other countries.
All products or technologies are the trademarks or registered trademarks of their respective holders.
Multi-Tech Systems, Inc.
2205 Woodale Drive
Mounds View, Minnesota 55112
(763) 785-3500 or (800) 328-9717
Fax 763-785-9874
Tech Support (800) 972-2439
Internet Address: http://www.multitech.com

iv

v
Contents
Chapter 1 – Introduction and Description
Introduction ......................................................................................... 7
Product Description .............................................................................. 7
About this Manual and Related Manuals ................................................ 7
Front Panel........................................................................................... 8
Back Panel............................................................................................ 9
Ship Kit Contents.................................................................................. 10
Chapter 2 – Installation
Introduction ......................................................................................... 11
Address Table....................................................................................... 12
Safety Warnings ................................................................................... 13
Unpacking............................................................................................ 13
Hardware Installation Procedure ........................................................... 14
Cabling Procedure................................................................................. 14
Software Configuration ........................................................................ 15
Configure the RF650VPN as a Firewall................................................ 17
Configure the RF650VPN as a PPTP Server for VPN Remote Cient Access........ 22
Configure the RF650VPN as an IPSec VPN Gateway............................ 23
IPSec VPN Gateway LAN to LAN Configuration ................................... 28
Login Using SSH and SCP .................................................................. 28
Chapter 3 - Application Examples
Introduction ......................................................................................... 29
Firewall and NAT................................................................................... 29
Firewall, NAT and DMZ.......................................................................... 30
Firewall, NAT and DNAT Virtual Server.................................................. 31
Firewall, NAT and PPTP Client Remote Access........................................ 32
Firewall, NAT and IPSec Client Remote Access ...................................... 33
Firewall, NAT and IPSec LAN to LAN...................................................... 34
Firewall, NAT and SMTP Proxy .............................................................. 36
Chapter 4 - Service, Warranty and Tech Support
Introduction ......................................................................................... 37
Limited Warranty.................................................................................. 37
On-line Warranty Registration............................................................... 37
Recording RouteFinder Information....................................................... 38
Contacting Tech Support via E-mail....................................................... 38
Service ................................................................................................ 39
Multi-Tech on the Internet.................................................................... 39
Ordering Accessories ............................................................................ 40

vi
Appendixes
Appendix A - Windows PPTP Client Setup .................. 41
Appendix B - SSH IPSec Client Setup.......................... 57
Appendix C - Regulatory Information......................... 69
Appendix D - License Agreements ...................................... 73

PN 82013251
7
Chapter 1 – Introduction and Description
Introduction
Welcome to Multi-Tech’s new RouteFinder, the RF650VPN. The RouteFinder Internet security
appliance is an integrated VPN gateway/firewall designed to maximize network security without
compromising network performance. It uses data encryption, user authentication and the Internet
to securely connect telecommuters, remote offices, customers or suppliers to the corporate office
while avoiding the cost of private leased lines or dial-up charges. The browser-based interface
eases VPN configuration and management. The VPN functionality is based on IPSec and PPTP
protocols and uses Triple DES 168-bit encryption to ensure that your information remains private.
The RouteFinder firewall security utilizes Stateful Packet Inspection, and provides optional email
anti-virus protection.
Product Description
The RF650VPN is a 1U rackmountable hardware/software solution that provides advanced
network firewall (Stateful Packet Inspection and NAT), application firewall (DMZ, proxies, filter,
optional virus protection), VPN gateway (IPSec, PPTP, 3DES, authentication), and full router
capabilities. The RouteFinder’s three 10/100 Ethernet ports can provide connectivity to the
user’s network, Internet access via router, DSL, cable or dedicated line, and DMZ.
The RouteFinder’s DMZ port permits connecting of Voice over IP gateways, like MultiVOIPs, and
public servers such as email and web to be safely connected. And its full-featured router
hardware allows the entire network to share an Internet link by connecting to an existing cable
modem, DSL modem or router.
The browser-based interface eases VPN configuration and management. The VPN functionality is
based on the IPSec and PPTP protocols and uses Triple DES 168-bit encryption to ensure that
your information remains private. In addition, the RF650VPN includes firewall security utilizing
Stateful Packet Inspection, and provides optional e-mail anti-virus protection. The optional virus
update feature includes protection against new virus types and security gaps with automatically
transferred updates.
About this Manual and Related Manuals
This Quick Start Guide manual contains four chapters and four appendixes, and is intended to
provide the experienced system administrator the information needed to quickly get the
RouteFinder up and running. The full User Guide manual is provided on the RouteFinder
RF650VPN System CD in Acrobat (.PDF) format. It provides additional operating,
troubleshooting, upgrade, regulatory agency, FAQs, and other RouteFinder information. It can be
viewed, printed, and searched (Ctl-F) effectively from Acrobat Reader 4 or 5. The Acrobat Reader
is provided on the System CD as well.
Please address comments about this manual to the Multi-Tech Publications Dept. Related
manuals may include add-on product documentation for options such as the IPSec SSH client, the
E-mail Anti-Virus Upgrade, etc.
Note: This document contains links to Internet sites which are owned and operated by third
parties. Multi-Tech Systems, Inc. is not responsible for the content of any such third-party site.

RF650VPN Quick Start Guide
8
Front Panel
The RF650VPN has 16 front panel LEDs to provide operating status.
The RF650VPN Front panel
The front panel LEDs are described below.
LED Description
LAN LEDs
LINK The LINK LED indicates link integrity for the LAN Ethernet port. If the Ethernet link
is valid at either 10 Mbps or 100Mbps, the Link LED is lit. If the Ethernet link is invalid, the
LINK LED is off.
ACT The ACT (Activity) LED indicates either transmit or receive activity on the LAN
Ethernet port. When activity is present on the LAN Ethernet port, theACT LED is lit. When
no activity is present on the LAN Ethernet port, the ACT LED is off.
100MB The 100MB LED indicates the speed of the LAN Ethernet port. The 100MB LED is
lit if the LAN Ethernet port is linked at 100Mbps. The 100MB LED is off at 10 Mbps.
WAN LEDs
LINK The LINK LED indicates link integrity for the WAN Ethernet port. If the link is valid
in either 10 Mbps or 100 Mbps, the LINK LED is on; if the WAN Ethernet link is invalid, the
LINK LED is off.
ACT The ACT (Activity) LED indicates either transmit or receive activity on the WAN
Ethernet port. When activity is present, the ACT LED is on; when no activity is present, the
ACT LED is off.
100MB The 100MB LED indicates the speed of the WAN Ethernet port. The100MB LED is
lit if the WAN Ethernet port is linked at 100 MBps. The 100MB LED is off at 10 Mbps.
DMZ LEDs
LINK The LINK LED indicates link integrity for the DMZ Ethernet port. If the link is valid
at either 10 Mbps or 100 Mbps, the LINK LED is lit. If the DMZ Ethernet port link is invalid,
the LINK LED is off.
ACT The ACT (Activity) LED indicates either transmit or receive activity on the DMZ
Ethernet port. When activity is present, the ACT LED is lit. When no DMZ Ethernet port
activity is present, the ACT LED is off.
100MB The 100MB LED indicates the speed of the DMZ Ethernet port. The 100MB LED is
lit if the DMZ Ethernet port is linked at 100 Mbps. The 100MB LED is off if the DMZ Ethernet
port is linked at 10 Mbps.
Modem LEDs (DCD, RD, DTR, TD): These LEDs are not used.
System LEDs
HDD ACT The HDD ACT (Hard Disk Drive Activity) LED lights when the RF650VPN hard disk
drive is accessed.
ALERT The ALERT LED is not used.
POWER The POWER LED is off when the RF650VPN is in a reset state. When the POWER
LED is lit, the RF650VPN is not in a reset state.

PN 82013251
9
Back Panel
The RF650VPN back panel has a fan, a power plug, the Power Switch (| / o), an RJ-11 (LINE) jack,
a DB-9 (com1) jack, a DB-15 High-density DSUB (video) jack, two USB (Revision 1.1 compliant)
jacks, an RJ-45 (optional DMZ) jack, an RJ-45 (WAN) jack, and an RJ-45 (LAN) jack.
The RF650VPN back panel is illustrated and described below.
The RF650VPN Back panel
The back panel components are described in detail in the Cabling Procedure section in Chapter 2
of this manual.
Ship Kit Contents
The RF650VPN is shipped with the following:
•one RF650VPN
•one Power Cord
•one printed Quick Start Guide manual
•two Rack Mounting Brackets and four mounting screws
•one RF650VPN System CD with License key
If any of these items are missing, contact Multi-Tech Systems or your dealer or distributor.
Inspect the contents for signs of any shipping damage. If damage is observed, do not power up
the RF650VPN; contact Multi-Tech’s Tech Support for advice.

RF650VPN Quick Start Guide
10
Typical Applications
The RF650VPN combines VPN, firewall, and optional e-mail antivirus protection subscription in one
box. The RF650VPN is a cost-effective, manageable way for a small- to medium-sized business to
add Remote User VPN, Branch Office VPN, and/or Firewall Security applications to their network.
Remote User VPN. The client-to-LAN VPN application replaces traditional dial-in remote access
by allowing a remote user to connect to the corporate LAN through a secure tunnel over the
Internet. The advantage is that a remote user can make a local call to an Internet Service
Provider, without sacrificing the company’s security, as opposed to a long distance call to the
corporate remote access server.
Branch Office VPN. The LAN-to-LAN VPN application sends network traffic over the branch office
Internet connection instead of relying on dedicated leased line connections. This can save
thousands of dollars in line costs and reduce overall hardware and management expenses.
Firewall Security. As businesses shift from dial-up or leased line connections to always-on
broadband Internet connections, the network becomes more vulnerable to Internet hackers.
The RouteFinder provides a full-featured firewall based on Stateful Packet Inspection technology
and the NAT protocol to provide security from intruders attempting to access the office LAN.
The RF650VPN plugs in at the Internet connection of each office and provides three independent
network interfaces (LAN, WAN and DMZ) that separate the protected office network from the
Internet while providing an optional public network for hosting Web, e-mail or ftp servers.
Each network interface is independently monitored and visually displayed on the front of the
RouteFinder.

PN 82013251
11
Chapter 2 - Installation
Introduction
RF650VPN installation is divided into three parts:
•Hardware installation and cabling
•Software initial configuration
•Software configuration
Information about the functionality of the WebAdmin software can be found in the online Help. The
Help function is opened by clicking the Online Help button.
Note: Before installing, you should first plan your network and decide which computer is to have
access to which services. This simplifies the configuration and saves you a lot of time that you
would otherwise need for corrections and adjustments.
Note: Please use this document to fill in your specific RouteFinder and network information (e.g.,
the IP address used, e-mail lists, etc.). Enter the configuration information (e.g., the Default
Gateway and other IP addresses used) into the appropriate field of the Address Table later in this
chapter, and keep for future reference.
The following administrator requirements must be met before installing the RF650VPN software:
•Correct configuration of the Default Gateway
•An HTTPS capable browser (e.g., Microsoft Internet Explorer 4.0 or higher, or Netscape Communicator
4.0 or higher)
•JavaScript and Cascading Style Sheets must be activated
•No proxies may be entered in the browser
•If Secure Shell (SSH) is to be used, an SSH client program is required (e.g., Putty in Windows 2000, or
the bundled SSH client in most Linux packages).

RF650VPN Quick Start Guide
12
As shown below, the RouteFinder provides the connection between your internal network and the
external network.
RouteFinder Connections
Address Table
Enter the configuration information (e.g., the Default Gateway and other IP addresses used) into
the appropriate field of the Address Table below. Please print this document and use it to fill in
your specific RF650VPN and network information (e.g., the IP address used, e-mail lists, etc.) ,
and keep for future reference.
IP address Net mask Default Gateway
Network Card connected
to the internal network ___.___.___.___ ___.___.___.___
(LAN on eth0)
Network Card connected
to the external network ___.___.___.___ ___.___.___.___ ___.___.___.___
(WAN on eth1)
Network Card
connected to the DMZ ___.___.___.___ ___.___.___.___
(eth2)

PN 82013251
13
Safety Warnings
•Use this product only with UL- and CUL-listed computers.
•To reduce the risk of fire, use only 26 AWG or larger telephone wiring.
•Never install telephone wiring during a lightning storm.
•Never install a telephone jack in a wet location unless the jack is specifically designed for wet
locations.
•Never touch uninsulated telephone wires or terminals unless the telephone line has been
disconnected at the network interface.
•Use caution when installing or modifying telephone lines.
•Avoid using a telephone (other than a cordless type) during an electrical storm; there is a risk
of electrical shock from lightning.
•Do not use a telephone in the vicinity of a gas leak.
* Caution: Danger of explosion if battery is incorrectly replaced. A lithium battery on the
RF650VPN pc board provides backup power for the time-keeping capability. The battery has an
estimated life expectancy of ten years. When the battery starts to weaken, the date and time
may be incorrect. If the battery fails, the board must be sent back to Multi-Tech Systems for
battery replacement.
* Caution: The Phone and Ethernet ports are not designed to be connected to a Public
Telecommunication Network.
Unpacking
The shipping box contains the RF650VPN, one Power Cord, one printed Quick Start Guide manual,
two Rack Mounting Brackets, and one RF650VPN System CD with license key. Inspect the
contents for signs of any shipping damage. If damage is observed, do not power up the
RF650VPN; contact Multi-Tech’s Tech Support for advice. If no damage is observed, follow the
instructions below.
Safety Recommendations for Rack Installations
Ensure proper installation of the RF650VPN in a closed or multi-unit enclosure by following the
recommended installation as defined by the enclosure manufacturer. Do not place the RF650VPN
directly on top of other equipment or place other equipment directly on top of the RF650VPN.
If installing the RF650VPN in a closed or multi-unit enclosure, ensure adequate airflow within the
rack so that the maximum recommended ambient temperature is not exceeded.
Ensure that the RF650VPN is properly connected to earth ground via a grounded power cord. If a
power strip is used, ensure that the power strip provides adequate grounding of the attached
apparatus.
Ensure that the mains supply circuit is capable of handling the load of the RF650VPN. Refer to the
power label on the equipment for load requirements.
Maximum ambient temperature for the RF650VPN is 50 degrees Celsius (120 degrees Farenheit).
This equipment should only be installed by properly qualified service personnel.
Only connect like circuits. In other words, connect SELV (Secondary Extra Low Voltage) circuits to
SELV circuits and TN (Telecommunications Network) circuits to TN circuits.

RF650VPN Quick Start Guide
14
Hardware Installation Procedure
The RF650VPN is designed to install either on a desktop or in a standard EIA 19“ rack, and is
shipped with the mounting hardware to install the RF650VPN in the rack. If installing in a rack,
use the provided mounting hardware and follow the rack enclosure manufacturer’s instructions to
safely and securely mount the RF650VPN in the rack enclosure. Proceed to the cabling
procedure.
Cabling Procedure
Cabling your RF650VPN involves making the proper LINE, Power, USB, DMZ, WAN and LAN
connections as described and illustrated below.
RF650VPN Back Panel Connections
1. Using an RJ-45 cable, connect the DMZ RJ-45 jack to the DMZ (optional – e.g., a Voice over IP
gateway, like MultiVOIPs or a public server such as email or web).
2. Using an RJ-45 cable, connect the WAN RJ-45 jack to the external network.
3. Using an RJ-45 cable, connect the LAN RJ-45 jack to the internal network.
4. With the RF650VPN Power switch in the off (Ο) position and using the supplied power cord,
connect the RF650VPN power plug to a live power outlet.
5. Place the RF650VPN Power switch to the on (|) position to turn on the RF650VPN. Wait for the
RF650VPN to beep a few times, indicating that it is ready to be configured with a web browser.
Caution : Never switch off RouteFinder Power until after you have performed the Shut down
process. Refer to System|Shut down in Chapter 3 of the full User Guide manual). If the
RouteFinder is not properly shut down before switching off Power, the next start may take a little
longer, or in the worst case, data could be lost.
6. Proceed to the Software Configuration Procedure.

PN 82013251
15
Software Configuration
The RouteFinder software is pre-installed on your RF650VPN. Initial configuration is required in
order for you to run the WebAdmin software and begin operation.
Note: Read the legal information and license agreement at the beginning of the installation.
Caution: Use a safe Password! Your first name spelled backwards is not a sufficiently safe
password; a password such as xfT35$4 is better.
Software Configuration Procedure
1. Connect a workstation to the RF650VPN's LAN port via Ethernet.
2. Set the workstation IP address to 192.168.2.x subnet.
3. Connect to the Internet at the RF650VPN WAN port.
4. Make an Internet PUBLIC IP address so it can be assigned to the WAN port.
5. Turn on power to the RouteFinder. If you hear a continuous beep, cycle RouteFinder power,
connect an external monitor (refer to Chapter 5 of the User Guide manual), run BIOS and check
for the hard drive. If you hear 5 beeps, continue with step 6.
6. Bring up your web browser on the workstation. At the web browser's address line, type the
default Gateway address of https://192.168.2.1 and hit the Enter key. In some environments, one
or more Security Alert screen(s) display.
At the initial Security Alert screen, click Yes and follow any additional on-screen prompts.
The Login screen is displayed.
7. Type the default User: name of admin (all lower-case), tab to the Password: entry and type
the default Password of admin (all lower-case), and click on Login. The User: and Password:
entries are case-sensitive (both must be all lower-case), and can be up to 12 characters each.
You will later want to change the User and Password entries from the default (admin) to
something else.

RF650VPN Quick Start Guide
16
(If Windows displays the AutoComplete screen, for security reasons, you may want to click Noto
tell the Windows OS to not remember the Password.) The Welcome to WebAdmin screen is
displayed.
You can now configure the RouteFinder as any or all of the following:
•a Firewall,
•a PPTP server for VPN remote client access, and/or
•an IPSec VPN Gateway.
These configuration procedures are provided in the following sections. Note that many of the
menus and entry fields have onscreen status LEDs. A green status light next to a function
indicates that the function is enabled; to disable the function, click the Disable button next to the
green status light. A red status light next to a function indicates that the function is disabled; to
enable the function, click the Enable button next to the red status light.
Note that Appendix A of this manual contains application examples with additional information on
addressing, masking, and software setup.

PN 82013251
17
To Configure the RF650VPN to work as a Firewall
Use this procedure to configure the RF650VPN firewall function as illustrated below.
1. At the Welcome to WebAdmin screen, click on System | Settings.
a) Add your own email address for alerts and notification.
b) Remove the default email address.

RF650VPN Quick Start Guide
18
c) Optional: you can change the password on WebAdmin.
d) Set the System Time and Date to match your current location.
2. Click on Definitions | Networks.

PN 82013251
19
a) Define the IP network that is configured on the LAN port (the Private LAN on eth0).
For example:
Name = LAN
IP address = 192.168.2.0
Subnet mask = 255.255.255.0
3. Click on Network | Interfaces.
Required changes:
a) Change the Default gateway IP address; this is the IP address of the router that connects to
the Internet.
b) Change the Host name for the RouteFinder (can be anything).
c) Click Save on the Local host settings.
Optional changes:
d) Change the IP address on LAN port (eth0). If you change this IP address, you must change
the IP address on the workstation so it matches the new IP address of the RouteFinder in order
for you to configure the RouteFinder again.
You also need to reconfigure step 2 so your new IP network is defined.
e) Click Save on the Network card (eth0) settings.

RF650VPN Quick Start Guide
20
Required changes:
f) Change the IP address for the WAN port - Network card (eth1); this is the Public Static IP
address.
g) Click Save for the Network card (eth1) settings.
Optional changes:
h) Change the IP address on DMZ port - Network card (eth2). This is the DMZ zone's Public
Static IP address.
i) Click Save for the Network card (eth2) settings.
4. Click on Network | Masquerading.
Other manuals for RouteFinder RF650VPN
1
Table of contents