Global Technology Associates GBWA200501-01 Manuale utente

GB-Ware
SOFTWARE
Firewall
Product Guide
GBWA200501-01
powered by
GNAT Box
System Software

Copyright
© 1996-2004, Global Technology Associates, Incorporated (GTA). All rights reserved.
Except as permitted under copyright law, no part of this manual may be reproduced or distributed in any form or by any
means without the prior permission of Global Technology Associates, Incorporated.
Technical Support
GTA includes 30 days “up and running” installation support from the date of purchase. See GTA’s web site for more
information. GTA’s direct customers in the USA should call or email GTA using the telephone and email address below.
International customers should contact a local GTA authorized channel partner.
Disclaimer
Neither GTA, nor its distributors and dealers, make any warranties or representations, either expressed or implied, as
to the software and documentation, including without limitation, the condition of software and implied warranties of its
merchantability or fitness for a particular purpose. GTA shall not be liable for any lost profits or for any direct, indirect,
incidental, consequential or other damages suffered by licensee or others resulting from the use of the program or
arising out of any breach of warranty. GTA further reserves the right to make changes to the specifications of the
program and contents of the manual without obligation to notify any person or organization of such changes.
Mention of third-party products is for informational purposes only and constitutes neither an endorsement nor a recom-
mendation for their use. GTA assumes no responsibility with regard to the performance or use of these products.
Every effort has been made to ensure that the information in this manual is accurate. GTA is not responsible for printing
or clerical errors.
Trademarks & Copyrights
GNAT Box, GB-Commander and Surf Sentinel are registered trademarks of Global Technology Associates, Incorporated.
RoBoX, GB-Ware and Firewall Control Center are trademarks of Global Technology Associates, Incorporated. Global
Technology Associates and GTA are registered service marks of Global Technology Associates, Incorporated.
Microsoft, Internet Explorer, Microsoft SQL and Windows are either trademarks or registered trademarks of Microsoft
Corporation in the United States and/or other countries.
Adobe and Adobe Acrobat Reader are either registered trademarks or trademarks of Adobe Systems Incorporated in the
United States and/or other countries.
UNIX is a registered trademark of The Open Group.
Linux is a registered trademark of Linus Torvalds.
BIND is a trademark of the Internet Systems Consortium, Incorporated and University of California, Berkeley.
WELF and WebTrends are trademarks of NetIQ.
Sun, Sun Microsystems, Solaris and Java are trademarks or registered trademarks of Sun Microsystems, Inc. in the
United States and other countries.
Java software may include software licensed from RSA Security, Inc.
Some products contain software licensed from IBM are available at http://oss.software.ibm.com/icu4j/.
SurfControl is a registered trademark of SurfControl plc. Some products contain technology
All other products are trademarks of their respective companies.
Global Technology Associates, Inc.
3505 Lake Lynda Drive, Suite 109 • Orlando, FL 32817 USA
Tel: +1.407.380.0220 • Fax: +1.407.380.6080 • Web: http://www.gta.com • Email: [email protected]

Table of Contents iii
Contents
1 INTRODUCTION ............................................................................................... 1
About GTA Firewalls ....................................................................................... 1
About GB-Ware ............................................................................................... 1
Features ..................................................................................................... 1
Additional Software Products ..................................................................... 2
Optional Features ....................................................................................... 2
Additional Options for 10-User Version ................................................... 2
Software Specifications .............................................................................. 3
Hardware Specifications ............................................................................. 3
System Requirements ............................................................................. 4
Optional Components ............................................................................. 5
Memory Recommendations .................................................................... 5
PPP Hardware ......................................................................................... 5
Support ............................................................................................................ 6
Support Options .......................................................................................... 6
Upgrades .................................................................................................... 7
About This Guide ............................................................................................ 7
Documentation Conventions ...................................................................... 7
Additional Documentation ........................................................................... 8
Mailing List .............................................................................................. 8
2 INSTALLATION ................................................................................................. 9
Registration ..................................................................................................... 9
Getting Your Activation Code ...................................................................... 9
Installing GB-Ware on PC Hardware ............................................................. 10
Requirements ............................................................................................. 10
Setup for GB-Ware Installation ................................................................... 11
Setting the Boot Sequence ..................................................................... 11
Installing the Compact Flash Card Reader or IDE Adapter ..................... 11
Selecting a GB-Ware Runtime ................................................................ 13
Selecting an Installation Disk .................................................................. 14
Installing the Runtime .............................................................................. 15
Completing Installation ............................................................................... 16
Attaching the Hardware Key Block .......................................................... 16
3 CONFIGURATION ............................................................................................. 19
Setting the Boot Sequence ............................................................................ 19
Loading the Correct Memory Slice (Partition) ............................................. 19
Selecting a User Interface .............................................................................. 19
Physically Connecting Your GB-Ware Firewall ............................................ 20
Requirements ............................................................................................. 21
Making a Temporary Peer Network Connection ......................................... 21
Making a Serial Connection ........................................................................ 23
Making a Video Connection ........................................................................ 23
Configuring Your Firewall .............................................................................. 24
Requirements ............................................................................................. 24
Browser Compatibility ............................................................................. 24
Configuration Using a Web Browser .......................................................... 25
Entering Your Network Information ......................................................... 26

GB-Ware Firewall Product Guideiv
Re-configuring Your Computer ................................................................ 28
Accessing the Firewall ............................................................................ 28
Configuration Using GBAdmin .................................................................... 29
Entering Your Network Information ......................................................... 30
Re-configuring Your Computer ................................................................ 31
Accessing the Firewall ............................................................................ 31
Configuration Using the Serial Console ...................................................... 31
Configuration Using the Video Console ...................................................... 32
Video Console Navigation ....................................................................... 33
Using the Setup Wizard .......................................................................... 33
Accessing Your GTA Firewall .................................................................. 37
4 TROUBLESHOOTING ...................................................................................... 39
Troubleshooting Basics ................................................................................. 39
Frequently Asked Questions (FAQ) ............................................................... 39
APPENDIX .............................................................................................................. 47
Installing the Compact Flash Card ................................................................ 47
Requirements ............................................................................................. 47
Assembling the Compact Flash IDE Adapter ............................................. 48
Installing the Compact Flash IDE Adapter .................................................. 48
Locating IDE Controller Ports .................................................................. 48
Mounting the Compact Flash Card ......................................................... 49
Connecting the IDE Cable ....................................................................... 50
Connecting the Power Supply ................................................................. 50
Moving an Old Configuration to GB-Ware .................................................... 50
Merging Configurations Using GBAdmin .................................................... 51
INDEX...................................................................................................................... 55

1 - Introduction 1
1 Introduction
About GTA Firewalls
Global Technology Associates, Inc. (GTA) has been designing and building
Internet firewalls since 1994. In 1996, GTA developed the first truly
affordable commercial-grade firewall, the GNAT Box®. Since then, ICSA-
certified GNAT Box System Software has become the engine that drives all
GTA hardware appliance and software firewall systems.
About GB-Ware
GB-Ware is a complete software firewall system that runs from a Compact
Flash module or hard drive installed on x86 (PC) hardware. After software
installation, GB-Ware must be configured for local network requirements
using either the setup wizard (video console) or manually (serial console,
GBAdmin or browser).
Features
• 10/100/1000 Mbps Ethernet WAN/LAN speed support
• ICSA-certified GNAT Box System Software (version 3.5 and higher)
• Stateful packet inspection
• User authentication (GTA, LDAP & RADIUS)
• SSL encrypted management
• DES, 3DES, AES, and Blowfish VPN encryption
• IPSec VPN with 1 mobile user license
• PPP, PPPoE and PPTP support
• SMTP email proxy
• Transparent NAT (network address translation)
• Async Modem and ISDN TA support
• RIP (Routing Information Protocol)
• Remote logging using WELF
• Gateway routing failover
• DMZ (PSN, Private Service Network; optional on 10 user version)

GB-Ware Firewall Product Guide2
• Dynamic DNS
• DNS proxy
• Transparent and traditional web proxy with script blocking
• DNS server (optional on 10 user version)
• DHCP server
• Web and GBAdmin user interfaces for remote management
• SNMP (read-only)
• Traffic shaping (bandwidth limiting)
• NTP (network time protocol) server
Additional Software Products
• GTA Reporting Suite™ (firewall log reporting)
• GB-Commander™ (firewall management)
Optional Features
• VPN hardware acceleration
• Additional mobile VPN clients
• Surf Sentinel® content filtering
• Mail Sentinel™ Anti-Spam email filtering
• Mail Sentinel™ Anti-Virus email filtering
• GTA-certified 512 MB Compact Flash disk
• Multi-Interface option (up to 20 network interfaces)
• Support contracts
Additional Options for 10-User Version
• 25, 50 or unlimited user license upgrades
• GB-Ware Plus Package (DNS Server and DMZ (PSN))

1 - Introduction 3
Software Specifications
Specification GB-Ware 10 users GB-Ware unrestricted users
Concurrent connec-
tions (standard)
1,000 128,000
Concurrent out-
bound users (stan-
dard)
10 Unrestricted
Network interfaces
(standard)
2 3
User authentication 50 750
Address objects 50 600
Aliases 5 300
Pass-through hosts 10 300
Filters, outbound
& remote access
objects
75 400
Traffic shaping
objects
5 50
Static outbound
maps
25 300
Static routes 10 300
Time groups 75 100
Tunnels 25 300
Protocols 255 255
URL access lists 10 300
Local content lists 25 250
DNS domains Optional 20
DNS hosts Optional 500
DNS networks Optional 80
VPN objects 5 100
VPN security asso-
ciations
20 600
Concurrent Mobile
VPN (max)
10 300
Hardware Specifications
The GB-Ware firewall is designed to operate efficiently on a broad spec-
trum of hardware, but the hardware you select will impact GB-Ware’s
performance. This is especially true when GB-Ware is used in an intranet

GB-Ware Firewall Product Guide4
configuration with full network speeds on all interfaces. The best possible
performance can be obtained by using a Pentium class or higher CPU with
PCI network cards.
Network performance bottlenecks usually occur at the connection to the
Internet when using DSL or T1 class connectivity. GB-Ware with 10 Mbps
Ethernet cards easily provides enough throughput for network connectivity
of up to T1 speeds (1.5 Mbps). However, when the WAN connectivity is a
T3 or faster, GTA recommends that 100 Mbps network cards be used.
If you encounter problems, check your motherboard and IRQ assignments.
Make sure any unused devices, such as IDE and SCSI controllers, sound
cards and serial ports are disabled. Scan the hardware configuration report
for error messages–often the cause of a problem is indicated in this report.
Note
Check gta.com for an up-to-date list of compatible network interface
cards and drivers.
System Requirements
• x86 architecture processor (Intel 486, Pentium, or Xeon; compatible
AMD or Cyrix CPUs); Pentium-class or faster CPU recommended
• 64 MB RAM (128 MB if using Mail Sentinel Anti-Virus and/or Mail
Sentinel Anti-Spam options)
• 512 MB ATA (IDE) compliant hard disk drive or 512 MB GTA-certi-
fied Compact Flash card with Compact Flash IDE adapter
• 2 compatible network cards (NICs)
• 1 Serial (RS-232/COM) port
• 1 USB port or parallel (printer) port on the motherboard (for hard-
ware key block installation)
Note
PCI cards with USB or parallel ports will not function correctly. The
USB or parallel ports must be located directly “on-board” (as an
integrated part of the motherboard).
• 1 ATAPI (IDE) CD-ROM (installation and recovery only)
• 1 Video card, 1 monitor and 1 keyboard (for video console use only;
keyboard may not be required for operation if the motherboard’s
BIOS supports booting without a keyboard)
• Ethernet cables: crossover cables for connections to routers or
computers; straight-through sables for connections to hubs or
switches
For installation requirements, see page 10.

1 - Introduction 5
Optional Components
• 1-18 additional network cards (if using the Multi-Interface Option)
• Async modem (PPP connections or pager only)
• ISDN TA with RS-232 interface (PPP connections only)
• Cable modem
• Serial ports for COM 1-4 (1645x/1655x UARTs only)
Note
GTA recommends installing only the GB-Ware required or GB-Ware
optional components in the system. Devices such as SCSI controllers
and sound cards remain unused and may decrease performance.
Memory Recommendations
Adding RAM is an easy way to boost system performance. Using 64 MB
RAM, the physically possible maximum number of concurrent sessions is
32,765; using 128 MB RAM, the physically possible maximum is 128,000
connections. Generally, the more features that are being utilized (e.g. DNS
server or Mail Sentinel email proxy), the more RAM is recommended for
optimum performance.
Note
Some GB-Ware options may require additional RAM.
PPP Hardware
GNAT Box System Software supports the use of a PPP network connection
in place of a network interface card for the external network interface. The
PPP interface supports only a dial-up connection and a single remote system
configuration. Once of the following should be used:
• An external asynchronous modem. COM ports 1-4 are supported;
only COM ports based on the 1645x/1655x UARTs are supported.
• An internal asynchronous modem. Only modems that use
1645x/1655x compliant UARTs are supported.
• An ISDN external modem/terminal adapter. COM ports 1-4 are
supported; only COM ports based on the 1645x/1655x compliant
UARTs are supported.
• Network interface card (NIC) for use with PPPoE (ADSL) or PPTP.
Serial Port Hardware
Most serial ports will easily support any asynchronous modem or a single
BRI 64Kbps ISDN connection. If both channels of a BRI line are used to
achieve 128Kbps, throughput may be limited to 115Kbps due to serial port
limitations.

GB-Ware Firewall Product Guide6
Modem/ISDN TA Hardware
GTA recommends configuring the modem or ISDN TA on another system
before installing it on GB-Ware. Most modems allow the storage of a user
configuration and the recall of this configuration using a specific command
(e.g. ATZ). It is usually easiest to configure the modem before installa-
tion, and then to recall that configuration and set the modem with a few
commands.
Note
The default configuration for most modems will generally work with
GB-Ware.
You should configure the modem to use a fixed DTE speed (the speed
at which the computer talks to the modem). If the modem supports DTE
speeds of 38,400 or 57,600 baud, use whichever of these values will ensure
the highest throughput. Configure your serial port to the highest possible
speed when using an ISDN TA. Unless you wish to connect at a specific
speed, set DCE (the speed at which the modem talks to a remote modem) to
auto-negotiate.
Cable Modems and xDSL Hardware
Cable modems and DSL (ADSL etc.) configurations utilize a passive inter-
connection device (cable modem, xDSL box) that is typically connected
to an Ethernet network interface card via a special network patch cable
(crossover cable).
Support
Installation ("up and running") support is available to registered users. If
you have registered your product and need installation assistance during
the first 30 days, contact the GTA Support team by email to support@gta.
com. Include your product name, serial number, activation code, feature
activation code numbers for your optional/subscription features, and a
Configuration Report (available in Reports under Configuration in the web user
interface), if possible.
Installation support only covers installation and default configuration of the
firewall. For further assistance, contact an authorized GTA Channel Partner
or GTA Sales staff for information about support offerings.
Support Options
If you need support after installation and default configuration, a variety of
support contracts are available. Contact an authorized GTA Channel Partner
or GTA Sales staff for more information. Support ranges from support per
incident to annual contract coverage.
Questo manuale è adatto per i seguenti modelli
1
Indice
Manuali Software popolari di altre marche

PS Audio
PS Audio PowerPlay Manuale del proprietario

Brady
Brady LOCKOUT PRO 3.0 Manuale di servizio

Avaya
Avaya Interaction Center Manuale utente

Texas Instruments
Texas Instruments TI-83 Plus Silver Edition Manuale

Novell
Novell GROUPWISE 8 - INTERNET AGENT Manuale utente

Oracle
Oracle Application 9i Manuale utente

Acer
Acer RDM Manuale utente

Canon
Canon Vixia HF21 Manuale utente

Canon
Canon ZR950 Manuale utente

Samsung
Samsung Auto Backup Manuale utente

Polycom
Polycom Vortex EF2201 Istruzioni per l'installazione e il funzionamento

Brocade Communications Systems
Brocade Communications Systems Brocade 8/12c Manuale utente





