XnetSolutions SX-GATE User manual

State: 2016-12-13, V7.0-2-0
User Guide

Table of content 2
1 Preface................................................................................................... 6
1.1 Guidelines.................................................................................................. 6
1.2 Trademarks................................................................................................ 8
2 Precautions and Guidelines................................................................ 9
2.1 Warning..................................................................................................... 9
2.2 For Your Safety....................................................................................... 10
2.3 The Power Plug....................................................................................... 11
2.4 Installation Site........................................................................................ 12
3 Preparing the new SX-GATE unit..................................................... 13
3.1 Packaging................................................................................................ 13
3.2 Accessories Provided.............................................................................. 14
3.3 Connecting the device............................................................................. 15
3.3.1 Connecting to ADSL dial-up lines.................................................... 15
3.3.2 Connecting to an external router / xDSL-leased line Internet
connection................................................................................................. 16
3.3.3 Connecting to the local network (LAN)............................................ 17
3.3.4 Connection with the power supply................................................... 18
4 Start-up................................................................................................ 19
4.1 Prerequisites............................................................................................ 19
4.2 Switching on and booting........................................................................ 20
4.3 Setting up SX-GATE's IP address........................................................... 21
4.3.1 Changing the IP address with the display........................................ 21
4.3.2 Changing the IP address with the web browser............................... 22
4.4 Check the connection to SX-GATE......................................................... 23
5 First settings....................................................................................... 24
5.1 Accessing the web administration interface............................................ 24
5.2 Basic configuration.................................................................................. 25
6 Configuring computers in the LAN.................................................. 26
6.1 Network parameters................................................................................ 26
6.2 Setting up the web browsers................................................................... 27
7 Home.................................................................................................... 28
7.1 Getting started......................................................................................... 29
7.2 Ressources.............................................................................................. 29
7.3 Network data rates.................................................................................. 29
7.4 Disk space............................................................................................... 29
7.5 Services................................................................................................... 30
7.6 SX-GATE info.......................................................................................... 30
7.7 SX-GATE status...................................................................................... 30
7.8 Ethernet Cards........................................................................................ 30
7.9 Live log.................................................................................................... 30
8 My Account......................................................................................... 32
8.1 Change password.................................................................................... 32
8.2 Email options........................................................................................... 33

Table of content 3
8.3 Web-Mail.................................................................................................. 39
8.4 Contact.................................................................................................... 40
9 Statistics.............................................................................................. 42
9.1 System load............................................................................................. 42
9.2 Network.................................................................................................... 43
9.2.1 Connections..................................................................................... 43
9.2.2 Throughput....................................................................................... 43
9.2.3 Bandwidth........................................................................................ 43
9.3 Firewall.................................................................................................... 45
9.3.1 Packet filter...................................................................................... 45
9.3.2 IDS/IPS............................................................................................ 45
9.4 Mail server............................................................................................... 46
9.5 Proxies..................................................................................................... 47
9.5.1 Web proxy........................................................................................ 47
9.5.2 Reverse proxy.................................................................................. 48
9.6 Web server.............................................................................................. 49
10 Monitoring......................................................................................... 50
10.1 Log files................................................................................................. 50
10.1.1 Settings.......................................................................................... 50
10.1.2 Search............................................................................................ 52
10.2 Network.................................................................................................. 57
10.2.1 Status............................................................................................. 57
10.2.2 Dial-up............................................................................................ 60
10.2.3 Tools.............................................................................................. 62
10.2.4 SNMP............................................................................................. 66
10.3 Mail server............................................................................................. 68
10.4 Web proxy............................................................................................. 72
11 Definitions......................................................................................... 74
11.1 IP objects............................................................................................... 74
11.2 Protocols................................................................................................ 78
11.3 Periods................................................................................................... 80
11.4 URL filter lists........................................................................................ 81
12 System............................................................................................... 85
12.1 Setup..................................................................................................... 85
12.2 Services................................................................................................. 93
12.3 User administration.............................................................................. 101
12.3.1 Settings........................................................................................ 102
12.3.2 Users............................................................................................ 107
12.3.3 Groups......................................................................................... 124
12.4 Certificates........................................................................................... 127
12.4.1 Root CA....................................................................................... 127
12.4.2 Certificates................................................................................... 131
12.5 Backup................................................................................................. 138
12.6 Update................................................................................................. 148
12.7 Shutdown / Reboot.............................................................................. 151

Table of content 4
12.8 Licence................................................................................................ 152
13 Wizards............................................................................................ 153
13.1 LAN integration.................................................................................... 153
13.2 Internet access.................................................................................... 157
13.3 Proxy configuration.............................................................................. 166
13.4 Email configuration.............................................................................. 174
13.5 L2TP IPSec VPN................................................................................. 190
13.6 Support access.................................................................................... 195
14 Modules........................................................................................... 199
14.1 Network................................................................................................ 199
14.1.1 Settings........................................................................................ 199
14.1.2 Interfaces...................................................................................... 207
14.1.2.1 Ethernet (eth)............................................................................ 209
14.1.2.2 VLAN 802.1Q (vlan).................................................................. 222
14.1.2.3 ISDN syncPPP (ippp)................................................................ 231
14.1.2.4 ISDN HDLC-RawIP (isdn)......................................................... 243
14.1.2.5 ADSL/UMTS (adsl).................................................................... 252
14.1.2.6 L2TP.......................................................................................... 264
14.1.2.7 OpenVPN Client (ovpnc)........................................................... 265
14.1.2.8 OpenVPN Server (ovpns)......................................................... 268
14.1.2.9 OpenVPN Server (ovpns) - Per-client setup............................. 271
14.1.2.10 IPSec VPN (ipsec).................................................................. 272
14.1.2.11 IPSec VPN (ipsec) - Connections........................................... 275
14.1.2.11.1 Connection with Server........................................................ 276
14.1.2.11.2 Connection with Client......................................................... 284
14.1.2.11.3 Connection with XAuth Client.............................................. 289
14.1.2.11.4 Connection with L2TP Client................................................ 294
14.2 Firewall................................................................................................ 300
14.2.1 Settings........................................................................................ 300
14.2.2 Policies......................................................................................... 302
14.3 DHCP................................................................................................... 318
14.4 DNS..................................................................................................... 324
14.4.1 Settings........................................................................................ 324
14.4.2 Zones........................................................................................... 326
14.4.2.1 domain...................................................................................... 328
14.4.2.2 IPv4 reverse lookup zone......................................................... 332
14.4.2.3 IPv6 reverse lookup zone......................................................... 335
14.5 Mail Server.......................................................................................... 339
14.5.1 POP/IMAP server......................................................................... 339
14.5.2 SMTP settings.............................................................................. 340
14.5.3 SPAM/Virus/Malware................................................................... 351
14.5.4 TLS Encryption............................................................................ 374
14.5.5 Domains....................................................................................... 379
14.6 POP/IMAP Client................................................................................. 386
14.6.1 Settings........................................................................................ 386
14.6.2 Servers......................................................................................... 386

Table of content 5
14.7 Web proxy........................................................................................... 392
14.7.1 Settings........................................................................................ 392
14.7.2 URL filter...................................................................................... 405
14.7.3 Content filter................................................................................. 409
14.8 Reverse proxy..................................................................................... 418
14.9 More Proxies....................................................................................... 433
14.9.1 FTP proxy.................................................................................... 433
14.9.2 SIP proxy..................................................................................... 435
14.9.3 POP3/SMTP proxy....................................................................... 437
14.9.4 SOCKS proxy............................................................................... 439
14.10 HTTP server...................................................................................... 441
14.11 FTP server......................................................................................... 445
14.12 Virusscanner...................................................................................... 446
14.13 Time server........................................................................................ 451
15 Configuration of an L2TP IPSec VPN client................................. 453
15.1 Microsoft Windows............................................................................... 453
15.1.1 Automatic configuration................................................................ 454
15.1.2 Manual configuration.................................................................... 457
15.2 Mac OS X............................................................................................ 473
15.3 Apple iPhone....................................................................................... 474
16 Contact............................................................................................ 477
17 SX-GATE Support........................................................................... 478
18 Technical Specifications................................................................ 479
19 CE Statement of Conformity......................................................... 480

1 Preface 6
1 Preface
Thank you for choosing the SX-GATE product. This device includes a router, Internet
appliance server, firewall and e-mail server... and all concentrated in just one box! SX-
GATE also offers you a whole choice of other features, depending on the specific SX-
GATE model. In order for you to optimally use and operate this product, we have tried
to make this manual as easy as possible. Therefore please take the time to carefully
read through this manual as some sections relate to preceding chapters.
As the SX-GATE product is continually being developed, we recommend that you
obtain a service contract which will supply you with product updates and upgrades and
plenty of new functions, all free of charge. You should also register your product with
us so that we can quickly help you in cases of support.
Duetoconstantimprovements,certainpartsofthismanualmaynotbecomplete.Inthis
case please consult our homepage www.sx-gate.de to obtain any missing information.
If you experience problems configuring SX-GATE you cannot solve yourself, please
contact the support numbers. All information and contacts are provided in chapter
Contact [p.477].
1.1 Guidelines
This manual s composed with great care and accuracy. However, XnetSolutions
KG accepts absolutely no guarantee or liability regarding completeness and flawless
content.
Since this device provides the same functionality as a router, it is important, that all
settings are monitored and checked when first set up. For instance you can use the
dial-up monitor as described in "Monitoring →Network". A misconfigured device can
result to considerable connection costs. We hold no responsibility for this.
This handbook describes all versions of SX-GATE. Please take note that the
functionality of each version is different. If any functionality is missing on your device
which is described in this manual, it can be reordered as long as it depends on
software. In this situation please ask your sales partner (see chapter Contact [p.477]).
Depending on the hardware setup, some features may not work. Your sales partner
will also be able to advise you here.
XnetSolutions KG reserves the right to make technical alterations to the device without
advance notice.
This product includes software developed by Christos Zoulas
This product includes software developed by Craig Metz
This product includes software developed by David A. Holland

1.1 Guidelines 7
This product includes software developed by David Corcoran
This product includes software developed by Diego Rivera
This product includes software developed by Emmanuel Dreyfus
This product includes software developed by Gunnar Ritter and his contributors
This product includes software developed by IAIK of Graz University of Technology.
This product includes software developed by Inferno Nettverk A/S, Norway
This product includes software developed by Jim Paris
This product includes software developed by Lars Fenneberg
This product includes software developed by Marko Myllynen
This product includes software developed by Paul Mackerras
This product includes software developed by Pedro Roque
This product includes software developed by Pedro Roque Marques
This product includes software developed by Reuben Hawkins
This product includes cryptographic software written by Eric Young
This product includes data from The Université Toulouse 1 Capitole "Blacklist UT1",
maintained by Fabrice Prigent (http://dsi.ut-capitole.fr/blacklists/), available under the
Creative Commons Attribution-ShareAlike 4.0 license. The data used in this product is
available from http://update.linogate.de/blacklists/.
This product includes software developed by Daisuke Okajima and Kohsuke
Kawaguchi (http://relaxngcc.sf.net/).
This product includes software developed by Tommi Komulainen
This product includes software developed by the OpenSSL Project for use in the
OpenSSL Toolkit
This product includes software developed by the University of California, Berkeley and
its contributors
This product includes software developed by the University of California, Lawrence
Berkeley Laboratory and its contributors

1.2 Trademarks 8
1.2 Trademarks
All companies and products that are named in this document are registered trademarks
of their respective owners. SX-GATE is a registered trademark of XnetSolutions KG.
The naming of unlisted trademarks does not necessarily mean their free availability.
Copyright ©, XnetSolutions KG

2.2 For Your Safety 10
2.2 For Your Safety
Do not open the device casing or try to operate it while open under any circumstances,
since this may cause an electrical shock. Furthermore, serious damage may be caused
to the device itself. There are no parts inside the device which should be tampered with
by non-specialists. Please refer to customer service with regard to upgrades or repairs.

2.4 Installation Site 12
2.4 Installation Site
Avoid installation in direct sunlight, near hot objects or in areas with a high temperature
(morethan 35°C), or areasthat are moist (morethan 90%) and dusty.Do not try andset
up the device where vibrations may be present. Use a flat surface, otherwise the inside
of the device will be prone to damage. Keep SX-GATE away from magnetic areas or
areas that contain magnet, e.g. Speakers.

3 Preparing the new SX-GATE unit 13
3 Preparing the new SX-GATE unit
3.1 Packaging
Removethedevicecarefullyfromthe packaging. Keep the cartonwithallthepackaging
material for later transportation. If the device is exposed to extreme temperature
fluctuations (e.g. from a cold vehicle to a heated room), wait approx. 1 hour so it can
become acclimatised. This is advisable since condensation may have built up in the
device which can cause serious damage.

3.3 Connecting the device 15
3.3 Connecting the device
The connection methods described in the following chapters assume, that SX-GATE
and the installation environment provide these connection sockets. The configuration
of the device may vary in different stages of extension.
3.3.1 Connecting to ADSL dial-up lines
SX-GATE supports the following ADSL connections:
•ADSL / VDSL with PPP-over-Ethernet (PPPoE), also via VLAN
•ADSL with PPP-over-ATM (PPPoA) via modem with PPtP-to-PPPoA-Relay
The connection to an ADSL dial-up has to be set up via an
externalDSL modem. Asuitable modem willbe provided byyour
ISP. If a router with integrated DSL modem has been provided,
it is recommended to put the router into modem mode (PPPoE
passthrough).
We recommend to connect the DSL modem directly through an otherwise unused
network interface of SX-GATE. For the Internet connection usually a second network
interface is provided in the system. The interface is called "eth1" and may also be
labeled with the acronyms "DSL" or "WAN".

3.3.2 Connecting to an external router / xDSL-leased line Internet connection 16
3.3.2 Connecting to an external router / xDSL-leased line Internet
connection
Usually, the second built-in network interface is provided for an Internet connection.
The interface is called "eth1" and may also be labeled with the acronyms "DSL" or
"WAN". Connect this interface directly with the external router. This might require a
crossover network cable which is not included. Alternatively you can connect via an
additional switch. Please use a dedicated switch and not the LAN switch in this case.

3.3.3 Connecting to the local network (LAN) 17
3.3.3 Connecting to the local network (LAN)
SX-GATE is connected to your LAN via the first network interface of the system. The
interface is called "eth0" and may also be labeled with the acronym "LAN". Connect
this interface with an unused port of your LAN switch.
Make sure that you do not reverse the interfaces! Confusing can
result in SX-GATE not being addressable!

3.3.4 Connection with the power supply 18
3.3.4 Connection with the power supply
Use the supplied network cable to connect the device to the power supply. Please note,
that operation of the device is only possible at 230 volts alternating current (AC).
We recommend to connect the device with an uninterruptible power supply (UPS)
unit. Otherwise, in case of a sudden power failure, the SX-GATE configuration and
respective hardware components could be affected.

4 Start-up 19
4 Start-up
4.1 Prerequisites
As all SX-GATE settings are made via web interface, a computer device with a web
browser like for example Microsoft Internet Explorer or Mozilla Firefox is required.
This device must be able to access SX-GATEs LAN interface via network. It might be
necessary to temporarily change the device's IP configuration.

4.2 Switching on and booting 20
4.2 Switching on and booting
Push the power button on the front of the device. The boot process takes about two
minutes. Please wait for this period before you continue!
Some SX-GATE models include an LCD display in the front panel. It indicates that the
device is ready when the boot message is replaced by a status display.
Table of contents
Popular Network Router manuals by other brands

H3C
H3C H3C S7500E Series Command manual

Cisco
Cisco 12010 series Maintenance manual

Longshine
Longshine FS6108 user manual

TRENDnet
TRENDnet TPE-S44 - Switch Specifications

3Com
3Com 3C6002A - NETBuilder II Extended Router datasheet

NETGEAR
NETGEAR ME101 - Wireless EN Bridge Network Converter installation guide