Firewall

Aus TERRA CLOUD WIKI

Diese Seite ist eine übersetzte Version der Seite Firewall und die Übersetzung ist zu 100 % abgeschlossen sowie aktuell.
Sprachen:

Private Cloud Strategy

Basically, every private cloud package from the TERRA CLOUD is delivered with a virtual Securepoint UTM appliance.
This starter guide serves as the basis for setting up a VPN tunnel and accessing the firewall's web interface.

Requirements for access

OpenVPN Client:

VPN configuration file:
The VPN data for administrator access can be found in the Cloud Center below the respective order within the service information, see also Service-Information.

The point "to the download area" takes you to a central share in Terra Drive, where all your VPN data for the booked virtual environments in the Terra Cloud is located. The prerequisite for this is the access data for your Drive NFR account.
Please note that the central share only contains the VPN data of the environments that you have booked in the Terra Cloud Center.

VLAN Requirements

Every virtual SecurePoint UTM has 2x virtual network interfaces.
One of them communicates with the Internet, the other communicates with the systems in the package.
Since a Hyper-V VM can have a maximum of 8x network cards attached, we can provide a maximum of 6x additional VLANs.

Connect to the firewall

An existing VPN tunnel is required for the connection to the firewall.
Before establishing the connection, please check whether the standard port 1194 is enabled for VPN connections on your local firewall.
If port 1194 is blocked, establishing the VPN tunnel will fail.

Initial setup of the VPN connection in the Securepoint VPN Client

  • Install the respective VPN client, in this example we are assuming the Securepoint VPN client.
  • Open the VPN client and click the gear at the bottom right to open the settings menu..

Open VPN client settings

  • In the context menu under Source file, click on the three dots to select the source file that was previously downloaded from the Cloud Portal.

Importing the configuration

  • Select the opvn file from the previously extracted zip file and click “Import”.
  • Optionally, the configuration can be assigned a name under “Import as:” under which the configuration will later be visible in the VPN client.
  • Use the arrow button to start establishing the VPN connection

Connect
The required initial access data is:
User: ssluser-admin
Password: ChanTroFar93!


Connection to the firewall web interface

After the VPN connection has been successfully established, access the following address in any browser:
https://<firewall IP address>:11115

The IP address of the firewall was assigned by you when ordering the environment and can be accessed subsequently in the Cloud Center
can be viewed below the respective order within the service information, see also Service Information.

FW_Login

The required initial access data is:
User: fwadmin
Password: Terra001

Initial access to the firewall web interface

Note:
The WebGUI has changed visually since firmware version 12.6.2.
However, with a few exceptions, all points are still called the same, so you can continue to follow all the steps using the following instructions.

The first time you open the firewall web interface, a few things need to be done:

Assign firewall name

Firewallname_given
Please enter a firewall name, which must correspond to an FQDN, e.g. myfirewall.local.
The firewall name must not contain any umlauts, special characters or capital letters.

Then click on the Complete button.

Firmware Update

Depending on the preinstalled firmware version, you will receive a message that a newer firmware is available.
In this example we assume that version 11.8.9 is preinstalled.

Firmwareupdate_available

This query should be answered with Yes when the environment is commissioned for the first time.
You will then receive a view of the available new firmware, which will be imported using the “Start test run” button.

Available_Firmwares

In order to use the new firmware, several license agreements must be checked and accepted.
Firewall License Agreement

Finally, a restart must be carried out. This can take up to 5 minutes.
You can follow the restart via the console connection via the Technical Center (https://manage.terracloud.de).

Firmware_Reboot

After the firewall has successfully restarted and you have logged in again, the new firmware must be confirmed as the new standard firmware.

Firewall-Firmware-ReleaseNotes

Confirm virus scanner message

If you have booked the firewall with only one vCore, you will receive a message that the number of virus scanners on the firewall has been reduced for stability and performance reasons.
This message is normal and needs to be confirmed.
Virus scanner message

Set cloud backup password

Please enter a password to back up your firewall configuration in the Securepoint cloud.
This gives you the opportunity to import the firewall configuration from the Securepoint Cloud after reinstalling the firewall.
Cloudbackup-Password

Your firewall will then be completely set up.

Firewall-WebGUI

Change of initial passwords

We recommend changing the initial passwords after handover.

  • In the firewall interface, open the Authentication --> Users menu item


Change_password

  • Click on the configuration symbol (wrench) behind the respective user and enter the new password in the Password and Confirm Password fields.
  • Finally click Save.


Overview

Change_password

The user "admin" cannot be customized by you.
This is an administrative account that is only used in the background for the firewall services.
Instructions and information on configuring the firewall can be found at:
http://wiki.securepoint.de/index.php/Howtos-V11

Email protection: spam filter with anti-virus package (optional)

Protection is implemented directly on the firewall included in the cloud environment.
The following options can be set:


Internet protection: Content filter with anti-virus package (optional)

Internet protection is implemented on the cloud firewall in your cloud environment. The following options can be set:


Change of internal IP address

To change the internal IP address without losing access to the firewall,
The new IP address must first be added, the VPN settings adjusted and only then the old IP address deleted.

  • First the network object “Internal Interface” is adjusted. To do this, open the port filter under the “Firewall” tab.

Note: In the new WebGUI this point is called packet filter.

Portfilter

  • Under “Network objects” you will find the “internal-interface” object. Open the settings of the network object by clicking on the “wrench”.

Edit Network Object

  • Regardless of the initial state, select “eth1” under “Interface”

Edit network object

Note: In the newer firewall version, the interface field was renamed to target and eth1 to lan2.

  • The new IP network will then be allocated. Open the network configuration under the “Network” tab in the firewall web interface.

Network Configuration

  • On the right side, click on the "wrench" of eth1 for configuration.

Edit ETH1

  • Add the new IP address under the “IP addresses” tab.

Add IP address
Add IP address

  • If you only want to change the host address, it is sufficient to enter the new address here, delete the old address using the small x and complete this using the “Save” button.

Add IP address

  • However, if you also want to change the subnet, further settings for the VPN tunnel must be made before deleting the old IP address.

Add IP address

  • Open the SSL-VPN configuration under the “VPN” tab in the firewall web interface.

SSL-VPN

  • Click on the wrench on the right to edit the SSL VPN connection.

Edit SSL VPN

  • You can then share the address range of the server networks. After adding, click Save and then click Restart.
Please note that this will cause all tunnels to be interrupted and the tunnel will have to be rebuilt!


Edit SSL VPN
SSL-VPN edit

SSL-VPN edit

  • We then remove the old, no longer needed network from the eth1
    interface

Edit interface

SSL-VPN edit