FireBrick Installation
FireBrick MaxBOND
Special Reset the Firebrick
1. Remove all network and power leads
2 Loop far left (single port) and second port in on the 4 port block Connect power and wait for green LED to flash
3. Remove network lead from 4 port block
4. Configure your PC with the following
IP Address 217.169.0.2
Subnet Mask 255.255.255.248
Default Gateway 217.169.0.1
Connect to the Firebrick on 217.169.0.1
5. Click Setup
6. Click Features
Go to Link : http://FireBrick.co.uk/1740/feature/.
Under : Key Used to Activate new Feature
Feature Token :
You have been provided with 3 Token Keys. Enter them here:
1st Key Assign = Tunnel
2nd Key Assign = Reporting
3rd Key Assign = Bonding
You will be presented on the page slightly above with the current installation key for this FireBrick is:
??????????????????????????????????????????????????
Go back to the Firebrick Installation page.
Scroll down to Installing features and add the installation key and click install Once the features are installed,
You will see :
Features
The following features are available:- (those in green are already installed)
| Extras | Additional admin users, profiles, shaping rules, speed lanes, routes, filters, portmaps and tunnels |
| Shaping | Traffic shaping/speed lanes |
| Profiles | Ping scanning and time profiles |
| Tunnels | Lightweight tunnelling protocol |
| Reporting | Management reporting (SNMP, Email, Syslog) |
| Bonding | Multiple gateway sharing |
| VLAN | VLAN subnets |
| 5Port | Independent 5 port operation for multiple DMZ/servers |
Tunnels/Reporting/Bonding will be highlighted green.
Now you will need to create the Admin user.
7. Click Users
8. Click Admin
9. Change the password to Passw0rd123 in the password and retype password fields
10. Allow from WAN, LAN and Tunnel
11. Click Save
12. Login using the admin user
13. Click Setup
14. Click Name/etc
15. Give the Firebrick a name
Domain should be comms.co.uk
Administrator Comms
Location Customer Premises
SNMP Community C0mm5
16. SNMP Options –> ifDesc as number unchecked
17. Click Save
18. DNS
Server IPs 194.168.4.100 and 194.168.8.100 (a DNS server specified by the customer)
19. Click Save
20. Click Subnets
Click 1
Name LAN
Security 1
Profile 24/7
21. Interface LAN
IP address (this is the LAN IP address on the customer CRF, if unknown just use 192.168.0.254 as this can be changed at a later date or on install)
Subnet mask (this is the LAN subnet mask on the customer CRF, if unknown just use /24 as this can be changed at a later date or on install)
Options NAT unchecked
Click Save
22. Click 2
Name WAN1
Security 1
Profile 24/7
Interface WAN
IP address (this is the WAN IP address of the Firebrick on Line 1.
Subnet mask Gateway (this is the WAN IP address of the router on line 1.
Options NAT unchecked
Click Save
Between the router and the Firebrick will be a /30 private IP range. Use 192.168.200.1 for the
router and 192.168.200.2 on the Firebrick for the first router, and 192.168.201.1 and 192.168.201.2 for the second, etc.
Repeat for 2,3 and 4 (depending on whether 2 or 4 lines) changing the names and IP addresses
23. Go back to Setup
Gateway
Gateway IP none
Interface WAN1
Click Save
24. Click IP grp
Click 2
Name WW Admin
Security 1
Add range 1.1.1.1-1.1.1.10 and 2.2.2.2
Click Set Name
25. Click 3
Name (Other end point Location)
Security 1
Add range (found on customer CRF, if this is unknown just use
10.10.10.0/24)
26. Click Set Name
Click 4
Name (location LAN)
Security 1
Add range (found on customer CRF, if this is unknown just use 10.10.20.0/24)
Click Set Name
27. Click Port Grp
Click 1
Protocol UDP
Target 1
Click Add new entry
Name FB unnel Traffic
Click set name
28. Click Routes
Subnets route should be at the top of the table
Click 2
Name (other end point Location)
Security 1
Profile 24/7
Source LAN
Send to Tunnel(Tunnel 1)
Click Save
Click Filters (this is the firewall and determines what traffic is allowed in and out)
The first filter should be for the Firebrick Internet Access
29. Click 1
Name Remote end routes
Security 1
Profile 24/7
Direction LAN-> Tunnel
Source LAN
Target (IP group for remote end location)
Action Allow
Click Save
30. Click 2
Name Tunnel Traffic
Security 1
Profile 24/7
Port Group FB Tunnel Traffic
Source All
Target All
Action Allow
Click Save
31. Click 3
Name SNMP
Security 1
Profile 24/7
Source All
Target Firebrick name
Action Allow
Target ports 161-162
Protocol UDP
Source IP group WW admin
Click Save
32. Click 4
Name Firebrick-Remote
Security 1
Profile 24/7
Source All
Target Firebrick name
Action Allow
Source IP group WW admin
Click Save
33. Click 5
Name Ping
Security 1
Profile 24/7
Source All
Target All
Action Allow
Source ports 8
Protocol ICMP
Click Save
34. Click Tunnel
Click 1
Name Tunnel 1
Security 1
Profile 24/7
IP at far end (optional) Public IP of Firebrick tunnel at other end
Tunnel ID at far end 1
OPtional Interface WAN(WAN1)
MTU 1500
Click Save
35. Click 2
Name Tunnel 2
Security 1
Profile 24/7
IP at far end (optional) Public IP of Firebrick tunnel at other end
Tunnel ID at far end 2
OPtional Interface WAN(WAN2)
MTU 1500
Click Save
If you are only using a single public IP then you will need a mapping rule as your access will come over on port 81.
36. Click Mapping
Name Admin
Security 2
Profile 24/7
Source WAN
Target (Firebrick name)
Map traffic to (Firebrick name)
Target ports 81
New target port 80
Click save