background image

 

Table of Contents iii

Copyright

© 1996-2003, Global Technology Associates, Incorporated (GTA). All rights reserved. 
Except as permitted under copyright law, no part of this manual may be reproduced or distrib-
uted in any form or by any means without the prior permission of Global Technology Associates, 
Incorporated.

GB-1200 Product Guide

                                                                    2/11/04 (rev.)  

July 2003

Technical Support

GTA includes 30 days installation support from the day you receive the initial shipment. GTA’s 
direct customers in the USA should call or email GTA using the telephone and email address 
below. International customers should contact a local GTA authorized channel partner.

Tel:  +1.407.482.6925 

Email:  support@gta.com

Disclaimer

Neither GTA, nor its distributors and dealers, make any warranties or representations, either 
expressed or implied, as to the software and documentation, including without limitation, the 
condition of software and implied warranties of its merchantability or fitness for a particular 
purpose. GTA shall not be liable for any lost profits or for any direct, indirect, incidental, conse-
quential or other damages suffered by licensee or others resulting from the use of the program 
or arising out of any breach of warranty. GTA further reserves the right to make changes to the 
specifications of the program and contents of the manual without obligation to notify any person 
or organization of such changes.
Mention of third-party products is for informational purposes only and constitutes neither an 
endorsement nor a recommendation for their use. GTA assumes no responsibility with regard to 
the performance or use of these products.
Every effort has been made to ensure that the information in this manual is accurate. GTA is not 
responsible for printing or clerical errors.

Trademarks

GNAT Box is a registered trademark of Global Technology Associates, Incorporated. RoBoX and 
Surf Sentinel are trademarks of Global Technology Associates, Incorporated. 
GTA acknowledges all trademarks appearing in this document. This product includes software 
developed by the University of California, Berkeley and its contributors. Netscape Navigator 
is a trademark of Netscape Communications Corporation. Internet Explorer is a trademark of 
Microsoft Corporation. 

 

WELF and WebTrends are trademarks of

 Net IQ. All other products are 

trademarks of their respective companies.

Global Technology Associates, Inc.

3505 Lake Lynda Drive, Suite 109 • Orlando, FL 32817 USA

Tel: +1.407.380.0220 • Fax: +1.407.380.6080 • Web: http://www.gta.com • Email: info@gta.com

Lead Development Team:

 Larry Baird, Richard Briley, Jim Silas, Brad Plank. 

Technical Consulting: 

David Brooks. 

Documentation: 

Mary Swanson.

Summary of Contents for GB-1200

Page 1: ... GB 1200 Firewall APPLIANCE Product Guide powered by GNAT Box System Software ...

Page 2: ... the right to make changes to the specifications of the program and contents of the manual without obligation to notify any person or organization of such changes Mention of third party products is for informational purposes only and constitutes neither an endorsement nor a recommendation for their use GTA assumes no responsibility with regard to the performance or use of these products Every effo...

Page 3: ...s Displays 7 Hardware Specifications 8 Mounting 9 2 INSTALLATION 11 Preinstallation 11 Install Utilities and Documentation 11 Temporarily Configure Workstation 11 LAN Using the Default IP Network 12 Connect the GB 1200 12 3 SET UP DEFAULT CONFIGURATION 13 Basic Configuration using Web Interface 13 Network Information 15 Re configure Workstation 16 Access the GB 1200 16 Basic Configuration using GB...

Page 4: ...GB 1200 Firewall Appliance Product Guide iv ...

Page 5: ... 500 and GB 200 and GTA s powerful software based products Requirements To connect the GB 1200 Firewall Appliance you will need A power cord Two Ethernet cables one for each required network A crossover cable to connect to a host or router or a straight through cable to connect to a hub or switch A power cord a yellow crossover cable and a grey straight through cable as well as a null modem cable ...

Page 6: ... a brief description of your problem in the body of the email Include the product serial number and your Support Center User ID in the message subject Activation Codes All commercial GTA Firewalls use activation codes to protect software For firewall appliances the required code is pre installed Additional features require separate feature activation codes Serial numbers and activation codes are p...

Page 7: ...uct s serial number and see the Product Details section to obtain the new activation code The section will also display previous activation codes Upgrades are also available in Support Center Downloads Only downloads for your version will be shown Caution Back up your configuration before upgrading About This Guide This Product Guide shows how to set up and install the GB 750 and change the factor...

Page 8: ... email or Microsoft Word format doc Documentation Map Products and Options GNAT Box System Software GNAT Box System Software User s Guide GTA Firewall Installation Product Guides Firewal Management GB Commanader User s Guide Reporting GTA Reporting Suite User s Guide Content Filtering Surf Sentinel Content Filtering Feature Guide High Availability H2 A High Availability Feature Guide Virtual Priva...

Page 9: ...100 Ethernet ports ICSA certified GNAT Box System Software IPSec VPN with 1 mobile user license Local Content List LCL filtering PPP PPPoE PPTP Secure Email Proxy SMTP Secure remote management Stateful Packet Inspection Time based filters Transparent NAT Network Address Translation Two DB 9 serial interfaces USB interface User authentication Optional Features H2 A High Availability Surf Sentinel S...

Page 10: ...300 Local Content Lists 250 User Authentication 500 VPN Objects 50 Hardware Design The GB 1200 Firewall Appliance is a 1RU appliance with two fans for cooling the CPU and power supply The system has four high speed 10 100 Ethernet interfaces to ensure high performance and network design flexibility and two multifunction DB 9 serial interfaces to provide access for a serial console and a dial up mo...

Page 11: ...ill void the warranty on the system Notes Default IP Address for fxp0 192 168 71 254 Serial Console 38 400 baud 8 bit 1 stop no parity GB 1200 Firewall Appliance Global Technology Associates Inc 3505 Lake Lynda Drive Suite 109 Orlando FL 32817 USA Com 2 Console USB 0 1 2 3 GB 1200 100 Mbps Active 0 1 2 3 Amber LEDs Green LEDs Power Indicator LED G Network Interface NIC Indicator LEDs Power Swich P...

Page 12: ...0 to 50 C Relative Humidity 10 80 Elevation 0 10 000 ft Storage Specifications Temperature 4 to 176 F 20 to 80 C Relative Humidity 10 95 Memory CPU 1 Ghz Celeron Memory 128 Mb Flash Memory 64 Mb I O Interfaces Specifications 4 10 100 Ethernet interfaces Ethernet 10Base T on UTP Cat 3 4 and 5 and Fast Ethernet 100Base TX on UTP Cat 5 Interfaces 0 1 2 and 3 are active and available 2 RS 232 DB 9 The...

Page 13: ...ting Use the supplied screws and mounting brackets to attach the system unit to a standard equipment rack Align the mounting bracket screw holes to the chassis screw holes insert the screws and tighten 19 Rackmount Bracket ...

Page 14: ...GB 1200 Firewall Appliance Product Guide 10 ...

Page 15: ...ws 95 98 NT Me XP or Windows 2000 there is an automated installer on the Installation CD that will install these files If the workstation is running a non Windows based OS e g Macintosh or Unix or an older version of Windows locate the directory on the CD ROM for your OS and use the Read Me docu ment to install the documentation and utility programs Temporarily Configure Workstation The factory ne...

Page 16: ...ver cable is included with hardware appliances Connect the GB 1200 Connect the GB 1200 to a hub or switch on your local area network using the Protected Network interface the first interface port 0 see illustration GB 1200 Rear Panel and a standard straight through network cable By default 0 is assigned the IP address 192 168 71 254 Use a crossover cable to connect the firewall directly to a host ...

Page 17: ...192 168 71 254 Note Web setup requires a browser that supports frames If your network and cables are configured correctly you will be prompted with a Security Alert dialog indicating that the Certificate Authority is not one you have chosen to trust that the security certificate date is valid and that the name on the security certificate does not match the name of the site Security Alert Select Ye...

Page 18: ...known to be incompatible with Internet Explorer 5 for Macintosh If your browser does not allow you to continue past the Security Alert screen in order to set up your new GB 1200 GTA recommends using another compatible browser such as Mozilla www mozilla org Netscape www netscape com or Opera www opera com to administer your firewall that allows you to use SSL encryption or using a compatible brows...

Page 19: ... in your DNS server Once you have completed Network Information apply the changes by clicking on the Save The GB 1200 will now be on a different logical network assuming you ve changed the default IP address for the Protected Network and you will not be able to access the GTA Firewall from your workstation since the firewall will now be on a different network The GB 1200 has four network interface...

Page 20: ...nctioning in default security mode all internal users are allowed outbound and no unsolicited inbound connec tions are allowed You can now perform any additional configuration tasks See the GNAT BOX SYSTEM SOFTWARE USER S GUIDE for more information Basic Configuration using GBAdmin Select GBAdmin GBAdmin exe from the program menu This opens a blank GBAdmin interface similar to the following screen...

Page 21: ...SYSTEM SOFTWARE USER S GUIDE for instructions Network Information The GB 1200 comes configured with factory settings which need to be changed to match our network settings Click on Basic Configuration and expand the menu to select Network Information On the Network Information screen Configure IP and netmasks expressed in either dotted decimal or CIDR notation for your External and Protected Netwo...

Page 22: ...ck Save on the Network Information screen you will not be able to access the GB 1200 from your workstation since the firewall will now be on a different network Re configure Workstation Re configure your workstation back to its original IP address now on the same network as the GTA Firewall Access the GB 1200 After re configuring your workstation you can access the GB 1200 using the new IP address...

Page 23: ...ceroute are very useful tools for testing connectivity 6 Make sure the network cabling is connected to the correct network interface Some useful guidelines are In a GB 1200 the port NIC numbers MAC addresses and logical names are listed on the Network Information screen and in the Configuration Report Use the trial and error method Connect one network cable and use the ping facility to reach a hos...

Page 24: ... route assigned incorrectly The default route must al ways be on the same subnet as the network interface of the host this is true for all hosts not just the GTA Firewall For a GB 1200 the default route must be an IP address on the network which is attached to the External Network interface Exception When using PPP PPTP or PPPoE the default route is not necessarily on the same subnet The route is ...

Page 25: ...cable the wire order matches on a crossover cable the first three of the four cables are in reverse order 7 I lost my user name and or password How can I log on to my firewall If login information has been irretrievably lost a firewall can be reset to factory defaults erasing all configuration data from the currently used memory parti tion and resetting the user name and password to gnatbox gnatbo...

Page 26: ...ation intact When the firewall is rebooted the updated memory slice will load by default To select a memory slice other than the default set up the console interface as described in Troubleshooting question 7 When the system boots up the memory slice information will load When the word Default appears immediately type the number of the slice you wish to load 1 GNAT Box slice 1 2 GNAT Box slice 2 D...

Page 27: ...ee parallel port DB 9 6 8 See RS 232 default configuration 3 13 route 15 17 defaults factory 21 22 default IP address 7 11 DHCP 15 17 DNS problem 19 Documentation additional 4 map 4 Drivers 4 E EIA standard See rack equipment email address support ii Ethernet 5 6 8 expansion 5 8 F factory defaults 21 22 Factory settings 3 11 15 17 AUTO connection type 20 Fast Ethernet 8 Fiber optic Gigabit Etherne...

Page 28: ...et to factory defaults 21 22 revert 22 RJ 45 network connector 7 Route default 15 17 RS 232 8 S Security certificate 13 Services inbound outbound 1 Slot PCI expansion 7 specifications hardware 6 specifications software 6 SSL 14 straight through cable 1 21 Support 2 7 Surf Sentinel ii switch 21 System software 11 T TCP IP 1 Technical support ii Temperature 8 terminal emulation 21 Terms 3 testing a ...

Reviews: