FireBrick Installation

FireBrick MaxBOND

Special Reset the Firebrick

1. Remove all network and power leads
2 Loop far left (single port) and second port in on the 4 port block Connect power and wait for green LED to flash
3. Remove network lead from 4 port block
4. Configure your PC with the following

IP Address    217.169.0.2
Subnet Mask     255.255.255.248
Default Gateway 217.169.0.1
Connect to the Firebrick on 217.169.0.1

5. Click Setup
6. Click Features

Go to Link : http://FireBrick.co.uk/1740/feature/.

Under : Key Used to Activate new Feature
Feature Token :

You have been provided with 3 Token Keys. Enter them here:

1st Key Assign   = Tunnel
2nd Key Assign = Reporting
3rd Key Assign = Bonding

You will be presented on the page slightly above with the current installation key for this FireBrick is:
??????????????????????????????????????????????????

Go back to the Firebrick Installation page.

Scroll down to Installing features and add the installation key and click install Once the features are installed,
You will see :

Features

The following features are available:- (those in green are already installed)

Extras Additional admin users, profiles, shaping rules, speed lanes, routes, filters, portmaps and tunnels
Shaping Traffic shaping/speed lanes
Profiles Ping scanning and time profiles
Tunnels Lightweight tunnelling protocol
Reporting Management reporting (SNMP, Email, Syslog)
Bonding Multiple gateway sharing
VLAN VLAN subnets
5Port Independent 5 port operation for multiple DMZ/servers

Tunnels/Reporting/Bonding will be highlighted green.

Now you will need to create the Admin user.

7. Click Users
8. Click Admin
9. Change the password to Passw0rd123 in the password and retype password fields
10. Allow from WAN, LAN and Tunnel
11. Click Save
12. Login using the admin user
13. Click Setup
14. Click Name/etc
15. Give the Firebrick a name

Domain should be comms.co.uk
Administrator Comms
Location Customer Premises
SNMP Community C0mm5

16. SNMP Options –> ifDesc as number unchecked
17. Click Save
18. DNS
Server IPs 194.168.4.100 and 194.168.8.100 (a DNS server specified by the customer)
19. Click Save

20. Click Subnets
Click 1
Name LAN
Security 1
Profile 24/7

21. Interface LAN
IP address (this is the LAN IP address on the customer CRF, if unknown just use 192.168.0.254 as this can be changed at a later date or on install)
Subnet mask (this is the LAN subnet mask on the customer CRF, if unknown just use /24 as this can be changed at a later date or on install)

Options NAT unchecked
Click Save

22. Click 2
Name WAN1
Security 1
Profile 24/7
Interface WAN
IP address (this is the WAN IP address of the Firebrick on Line 1.
Subnet mask Gateway (this is the WAN IP address of the router on line 1.
Options NAT unchecked
Click Save

Between the router and the Firebrick will be a /30 private IP range. Use 192.168.200.1 for the

router and 192.168.200.2 on the Firebrick for the first router, and 192.168.201.1 and 192.168.201.2 for the second, etc.

Repeat for 2,3 and 4 (depending on whether 2 or 4 lines) changing the names and IP addresses

23. Go back to Setup
Gateway
Gateway IP none
Interface WAN1
Click Save

24. Click IP grp
Click 2
Name WW Admin
Security 1
Add range 1.1.1.1-1.1.1.10 and 2.2.2.2
Click Set Name

25. Click 3
Name (Other end point Location)
Security 1
Add range (found on customer CRF, if this is unknown just use
10.10.10.0/24)

26. Click Set Name
Click 4
Name (location LAN)
Security 1
Add range (found on customer CRF, if this is unknown just use 10.10.20.0/24)
Click Set Name

27. Click Port Grp
Click 1
Protocol UDP
Target 1
Click Add new entry
Name FB unnel Traffic
Click set name

28. Click Routes
Subnets route should be at the top of the table
Click 2
Name (other end point Location)
Security 1
Profile 24/7
Source LAN
Send to Tunnel(Tunnel 1)
Click Save

Click Filters (this is the firewall and determines what traffic is allowed in and out)

The first filter should be for the Firebrick Internet Access

29. Click 1
Name Remote end routes
Security 1
Profile 24/7
Direction LAN-> Tunnel
Source LAN
Target (IP group for remote end location)
Action Allow
Click Save

30. Click 2
Name Tunnel Traffic
Security 1
Profile 24/7
Port Group FB Tunnel Traffic
Source All
Target All
Action Allow
Click Save

31. Click 3
Name SNMP
Security 1
Profile 24/7
Source All
Target Firebrick name
Action Allow
Target ports 161-162
Protocol UDP
Source IP group WW admin
Click Save

32. Click 4
Name Firebrick-Remote
Security 1
Profile 24/7
Source All
Target Firebrick name
Action Allow
Source IP group WW admin
Click Save

33. Click 5
Name Ping
Security 1
Profile 24/7
Source All
Target All
Action Allow
Source ports 8
Protocol ICMP
Click Save

34. Click Tunnel
Click 1
Name Tunnel 1
Security 1
Profile 24/7
IP at far end (optional) Public IP of Firebrick tunnel at other end
Tunnel ID at far end 1
OPtional Interface WAN(WAN1)
MTU 1500
Click Save

35. Click 2
Name Tunnel 2
Security 1
Profile 24/7
IP at far end (optional) Public IP of Firebrick tunnel at other end
Tunnel ID at far end 2
OPtional Interface WAN(WAN2)
MTU 1500
Click Save

If you are only using a single public IP then you will need a mapping rule as your access will come over on port 81.

36. Click Mapping
Name Admin
Security 2
Profile 24/7
Source WAN
Target (Firebrick name)
Map traffic to (Firebrick name)
Target ports 81
New target port 80
Click save