FireBrick FB9000 User Manual

This User Manual documents Software version V2.06.025

The FireBrick config editor uses the OCR-B font designed by Matthew Anderson, which is licensed under a Creative Commons 4.0 Attribution License

Table of Contents

Preface
1. Introduction
1.1. The FB9000
1.1.1. Where do I start?
1.1.2. What can it do?
1.1.3. Ethernet port capabilities
1.2. About this Manual
1.2.1. Version
1.2.2. Intended audience
1.2.3. Technical details
1.2.4. Document style
1.2.5. Document conventions
1.2.6. Comments and feedback
1.3. Additional Resources
1.3.1. Technical Support
1.3.2. IRC Channel
1.3.3. Application Notes
1.3.4. Training Courses
2. Getting Started
2.1. IP addressing
2.2. Accessing the web-based user interface
2.2.1. Initial configuration
3. Configuration
3.1. The Object Hierarchy
3.2. The Object Model
3.2.1. Formal definition of the object model
3.2.2. Common attributes
3.3. Configuration Methods
3.4. Configuration upgrades and versioning
3.5. Data types
3.5.1. Sending and receiving values
3.5.2. Lists of values
3.5.3. Set of possible values
3.5.4. Dates, times, and durations
3.5.5. Colours
3.5.6. Passwords and secrets
3.5.7. IP addresses
3.5.7.1. Simple IP addresses
3.5.7.2. Subnets and prefixes
3.5.7.3. Ranges
3.5.7.4. Prefix filters
3.6. Default values
3.7. Web User Interface Overview
3.7.1. User Interface layout
3.7.2. Config pages and the object hierarchy
3.7.2.1. Configuration categories
3.7.2.2. Object settings
3.7.3. Navigating around the User Interface
3.7.4. Backing up / restoring the configuration
3.7.5. Customising the layout
3.8. Configuration using XML
3.8.1. Introduction to XML
3.8.2. The root element - <config>
3.8.3. Viewing or editing XML
3.8.4. Example XML configuration
3.9. Downloading/Uploading the configuration
3.9.1. Download
3.9.2. Upload
4. System Administration
4.1. User Management
4.1.1. Login level
4.1.2. Configuration access level
4.1.3. Login idle timeout
4.1.4. Restricting user logins
4.1.4.1. Restrict by IP address
4.1.4.2. Restrict by profile
4.1.5. Password change
4.1.6. One Time Password (OTP)
4.2. General System settings
4.2.1. System name (hostname)
4.2.2. Administrative details
4.2.3. System-level event logging control
4.2.4. Web interface settings
4.2.5. Home page web links
4.3. Software Upgrades
4.3.1. Software release types
4.3.1.1. Checkpoint releases
4.3.1.2. Configuration changes on upgrade
4.3.2. Identifying current software version
4.3.3. Internet-based upgrade process
4.3.3.1. Manually initiating upgrades
4.3.3.2. Controlling automatic software updates
4.3.4. Manual upgrade
4.4. Boot Process
4.4.1. LED indications
4.4.1.1. Status LED indications
4.4.1.2. Port LEDs
5. Event Logging
5.1. Overview
5.1.1. Log targets
5.1.1.1. Logging to Flash memory
5.1.1.2. Logging to the Console
5.2. Enabling logging
5.3. Logging to external destinations
5.3.1. Syslog
5.3.2. Email
5.3.2.1. E-mail process logging
5.4. Factory reset configuration log targets
5.5. Performance
5.6. Viewing logs
5.6.1. Viewing logs in the User Interface
5.6.2. Viewing logs in the CLI environment
5.7. System-event logging
5.8. Using Profiles
6. Automated Certificate Management Environment (ACME)
6.1. Overview
6.1.1. LetsEncrypt
6.1.2. Troubleshooting
6.1.3. More advanced usage
6.1.3.1. Using your own keys
6.1.3.2. Alternative ACME providers
6.1.3.3. Using an existing account
6.1.4. Further information about the renewal process
7. Interfaces and Subnets
7.1. Relationship between Interfaces and Physical Ports
7.1.1. Port groups
7.1.1.1. LACP
7.1.2. Interfaces
7.2. Defining port groups
7.3. Defining an interface
7.3.1. Defining subnets
7.3.1.1. Source filtering
7.3.1.2. Using DHCP to configure a subnet
7.3.1.3. Using SLAAC (IPv6 router announcements) to configure a subnet
7.3.1.4. Providing IPv6 addresses to devices on a network (IPv6 router announcements)
7.3.1.5. IPv6 prefix delegated subnets
7.3.2. Setting up DHCP v4 server parameters
7.3.2.1. Fixed/Static DHCP allocations
7.3.2.2. Restricted allocations
7.3.2.3. Sending NAKs
7.3.2.4. Special DHCP options
7.3.2.5. Logging
7.3.3. DHCP Relay Agent
7.4. Physical port settings
7.4.1. Disabling auto-negotiation
8. Session Handling
8.1. Routing vs. Firewalling
8.2. Session Tracking
8.2.1. Session termination
8.3. Session Rules
8.3.1. Overview
8.3.2. Processing flow
8.3.3. Defining Rule-Sets and Rules
8.3.3.1. Session rules depending on ARP/ND
8.3.3.2. Recommended method of implementing firewalling
8.3.3.3. Changes to session traffic
8.3.3.4. Obfuscation
8.3.3.5. Graphing and traffic shaping
8.3.3.6. Configuring session time-outs
8.3.3.7. Load balancing
8.3.3.8. Clashes
8.3.3.9. NAT-PMP / PCP (Port Control Protocol)
8.4. Network Address Translation
8.4.1. When to use NAT
8.4.2. NAT ALGs
8.4.3. Setting NAT in rules
8.4.4. What NAT does
8.4.5. NAT with PPPoE
8.4.6. NAT with other types of external routing
8.4.7. Mixing NAT and non NAT
8.4.8. Carrier grade NAT
8.4.9. Using NAT setting on subnets
9. Routing
9.1. Routing logic
9.2. Routing targets
9.2.1. Subnet routes
9.2.2. Routing to an IP address (gateway route)
9.2.3. Special targets
9.3. Dynamic route creation / deletion
9.4. Routing tables
9.5. Bonding
9.6. Route overrides
10. Profiles
10.1. Overview
10.2. Creating/editing profiles
10.2.1. Timing control
10.2.2. Tests
10.2.2.1. General tests
10.2.2.2. Time/date tests
10.2.2.3. Ping tests
10.2.3. Inverting overall test result
10.2.4. Manual override
10.2.4.1. Control Switches
10.2.5. Scripting
10.2.6. MQTT
11. IP Groups
11.1. Adding IPs and ranges
11.1.1. Direct definition
11.1.2. DNS
11.1.3. HTTP and HTTPS
11.1.4. User login
12. Traffic Shaping
12.1. Graphs and Shapers
12.1.1. Graphs
12.1.2. Shapers
12.1.3. Ad hoc shapers
12.1.4. Long term shapers
12.1.5. Shared shapers
12.2. Multiple shapers
12.3. Basic principles
13. PPPoE
13.1. PPPoE client
13.2. Types of DSL line and router in the United Kingdom
13.3. Definining PPPoE client links
13.3.1. IPv6
13.3.2. Additional options
13.3.2.1. MTU and TCP fix
13.3.2.2. Service and ac-name
13.3.2.3. Logging
13.3.2.4. Speed and graphs
13.4. PPPoE BRAS
13.4.1. Additional options
13.4.2. Steering and load balancing
13.4.2.1. Balance groups
13.4.2.2. MAC steering
14. MQTT
14.1. Limitations
14.2. Features
14.3. Integration with FireBrick operations
14.3.1. Profiles
14.3.2. VoIP
14.3.3. DHCP
14.3.4. RADIUS
15. Tunnels
15.1. IPsec (IP Security)
15.1.1. Introduction
15.1.1.1. Integrity checking
15.1.1.2. Encryption
15.1.1.3. Authentication
15.1.1.4. IKE
15.1.1.5. Manual Keying
15.1.1.6. Identities and the Authentication Mechanism
15.1.2. Setting up IPsec connections
15.1.2.1. Global IPsec parameters
15.1.2.2. IKE proposals
15.1.2.3. IKE roaming IP pools
15.1.2.4. IKE connections
15.1.2.4.1. IKE connection mode and type
15.1.2.4.2. IKE and IPsec proposal lists
15.1.2.4.3. Authentication and IKE identities
15.1.2.4.4. IP addresses
15.1.2.4.5. Road Warrior connections
15.1.2.4.6. Routing
15.1.2.4.7. Other parameters
15.1.2.5. Setting up Manual Keying
15.1.2.5.1. IP endpoints
15.1.2.5.2. Algorithms and keys
15.1.2.5.3. Routing
15.1.2.5.4. Mode
15.1.2.5.5. Other parameters
15.1.3. Using EAP with IPsec/IKE
15.1.4. Using certificates with IPsec/IKE
15.1.5. Choice of algorithms
15.1.6. NAT Traversal
15.1.7. Configuring a Road Warrior server
15.1.8. Connecting to non-FireBrick devices
15.1.8.1. Using StrongSwan on Linux
15.1.8.2. Setting up a Road Warrior VPN on an Android client
15.1.8.3. Setting up a Road Warrior VPN on an iOS (iPhone/iPad) client
15.1.8.4. Manual keying using Linux ipsec-tools
15.2. FB105 tunnels
15.2.1. Tunnel wrapper packets
15.2.2. Setting up a tunnel
15.2.3. Viewing tunnel status
15.2.4. Dynamic routes
15.2.5. Tunnel bonding
15.2.6. Tunnels and NAT
15.2.6.1. FB9000 doing NAT
15.2.6.2. Another device doing NAT
15.3. L2TP tunnelling
15.3.1. Incoming tunnel
15.3.2. Incoming session
15.3.3. Outgoing connection
15.3.4. High availability L2TP
15.3.4.1. Interpreting HA statistics
15.3.4.2. HA best practice
15.4. Ether tunnelling
16. System Services
16.1. Protecting the FB9000
16.2. Common settings
16.3. HTTP Server configuration
16.3.1. Access control
16.3.1.1. Trusted addresses
16.3.2. HTTPS access
16.4. Telnet Server configuration
16.4.1. Access control
16.5. TLS Serial Server configuration
16.5.1. Access control
16.5.2. Alternative clients
16.6. DNS configuration
16.6.1. Auto DHCP DNS
16.6.2. Local DNS responses
16.6.3. Blocking DNS names
16.7. NTP configuration
16.8. SNMP configuration
16.9. RADIUS configuration
16.9.1. RADIUS server (platform RADIUS)
16.9.2. RADIUS client
16.9.2.1. RADIUS client settings
16.9.2.2. Server blacklisting
17. Network Diagnostic Tools
17.1. Firewalling check
17.2. Access check
17.3. Packet Dumping
17.3.1. Dump parameters
17.3.2. Security settings required
17.3.3. IP address matching
17.3.4. Packet types
17.3.5. Snaplen specification
17.3.6. Using the web interface
17.3.7. Using an HTTP client
17.3.7.1. Example using curl and tcpdump
18. VRRP
18.1. Virtual Routers
18.2. Configuring VRRP
18.2.1. Advertisement Interval
18.2.2. Priority
18.3. Using a virtual router
18.4. VRRP versions
18.4.1. VRRP version 2
18.4.2. VRRP version 3
18.5. Compatibility
19. BGP
19.1. What is BGP?
19.2. BGP Setup
19.2.1. Overview
19.2.2. Standards
19.2.3. Simple example setup
19.2.4. Peer type
19.2.5. Route filtering
19.2.5.1. Matching attributes
19.2.5.2. Action attributes
19.2.6. Well known community tags
19.2.7. Announcing black hole routes
19.2.8. Grey holes
19.2.9. Announcing dead end routes
19.2.10. Bad optional path attributes
19.2.11. <network> element
19.2.12. <route>, <subnet> and other elements
19.2.13. Route feasibility testing
19.2.14. Status
19.2.15. Diagnostics
19.2.16. Router startup and shutdown
19.2.17. TTL security
20. Internet Service Providers
20.1. Background
20.1.1. How it all began
20.1.2. Point to Point Protocol
20.1.3. L2TP
20.1.4. Broadband
20.1.5. RADIUS
20.1.6. BGP
20.2. Incoming L2TP connections
20.3. The importance of CQM graphs
20.4. Authentication
20.5. Accounting
20.6. RADIUS Control messages
20.7. PPPoE
20.8. GTP
20.9. Typical configuration
20.9.1. Interlink subnet
20.9.2. BGP with carrier
20.9.3. RADIUS session steering
20.9.4. L2TP endpoints
20.9.5. ISP RADIUS
21. Command Line Interface
A. Factory Reset Procedure
B. CIDR and CIDR Notation
C. MAC Addresses usage
C.1. Multiple MAC addresses?
C.2. How the FireBrick allocates MAC addresses
C.2.1. Interface
C.2.2. Subnet
C.2.3. PPPoE
C.2.4. Running out of MACs
C.3. Forcing particular MAC addresses
C.4. MAC address on label
C.5. Using with a DHCP server
D. Scripted access
D.1. Tools
D.2. Access control
D.2.1. Username and password
D.2.2. OTP
D.2.3. Allow list
D.2.4. Allowed access
D.3. XML data for common functions
D.4. XML data from diagnostics and tests
D.4.1. Cross site scripting security
D.4.2. Arguments to scripts
D.5. Special URLs
D.6. Web sockets
E. VLANs : A primer
F. Supported L2TP Attribute/Value Pairs
F.1. Start-Control-Connection-Request
F.2. Start-Control-Connection-Reply
F.3. Start-Control-Connection-Connected
F.4. Stop-Control-Connection-Notification
F.5. Hello
F.6. Incoming-Call-Request
F.7. Incoming-Call-Reply
F.8. Incoming-Call-Connected
F.9. Outgoing-Call-Request
F.10. Outgoing-Call-Reply
F.11. Outgoing-Call-Connected
F.12. Call-Disconnect-Notify
F.13. WAN-Error-Notify
F.14. Set-Link-Info
F.15. Notes
F.15.1. BT specific notes
F.15.2. IP over LCP
G. Supported RADIUS Attribute/Value Pairs for L2TP operation
G.1. Authentication request
G.2. Authentication response
G.2.1. Accepted authentication
G.2.1.1. Prefix Delegation
G.2.2. Rejected authentication
G.3. Accounting Start
G.4. Accounting Interim
G.5. Accounting Stop
G.6. Disconnect
G.7. Change of Authorisation
G.8. Filter ID
G.9. Notes
G.9.1. L2TP relay
G.9.2. LCP echo and CQM graphs
G.9.2.1. Options and trade-offs for relayed L2TP and CQM
G.9.3. IP over LCP
G.9.4. Closed User Group
G.9.5. Routing table
H. FireBrick specific SNMP objects
H.1. Conventions
H.1.1. IP addresses as indices
H.2. Firebrick-specific structures for BGP
H.2.1. Structure definitions
H.2.1.1. The list of BGP peers for this Firebrick
H.2.2. Enum Definitions
H.3. Firebrick-specific structures for IPSec
H.3.1. Structure definitions
H.3.1.1. fbIPsecGeneral
H.3.1.2. The list of IPsec connections for this Firebrick
H.3.2. Enum Definitions
H.4. Firebrick-specific structures for L2TP
H.4.1. Structure definitions
H.4.1.1. fbL2tpGeneralTunnels
H.4.1.2. fbL2tpGeneralSessions
H.4.1.3. The list of L2TP peers for this Firebrick
H.5. FireBrick specific structures for GTP
H.5.1. Structure definitions
H.5.1.1. fbGtpGeneral
H.6. Firebrick CPU usage
H.6.1. Structure definitions
H.6.1.1. CPU usage for this Firebrick
H.7. Firebrick system stats
H.7.1. Structure definitions
H.7.1.1. The table of runtime stats for this Firebrick
H.8. Monitoring for general system features
H.8.1. Structure definitions
H.8.1.1. The list of readings for this Firebrick
H.9. System wide status
H.9.1. Structure definitions
H.9.1.1. fbGlobalMemory
H.9.1.2. fbGlobalBuffers
H.10. Firebrick profiles
H.10.1. Structure definitions
H.10.1.1. Profiles status
I. Command line reference
I.1. General commands
I.1.1. Trace off
I.1.2. Trace on
I.1.3. Set line buffered
I.1.4. Uptime
I.1.5. General status
I.1.6. Memory usage
I.1.7. Process/task usage
I.1.8. Login
I.1.9. Logout
I.1.10. See XML configuration
I.1.11. Load XML configuration
I.1.12. Enable nonlocal HTTP access
I.1.13. Show profile status
I.1.14. Enable profile control switch
I.1.15. Disable profile control switch
I.1.16. Show RADIUS servers
I.1.17. Show DNS resolvers
I.2. Networking commands
I.2.1. Subnets
I.2.2. Renegotiate DHCP for a subnet
I.2.3. Ping and trace
I.2.4. Show a route from the routing table
I.2.5. List routes
I.2.6. List routing next hops
I.2.7. See DHCP allocations
I.2.8. Clear DHCP allocations
I.2.9. Lock DHCP allocations
I.2.10. Unlock DHCP allocations
I.2.11. Name DHCP allocations
I.2.12. Show ARP/ND status
I.2.13. Show VRRP status
I.2.14. Send Wake-on-LAN packet
I.3. Firewalling commands
I.3.1. Check access to services
I.3.2. Check firewall logic
I.4. Logging commands
I.4.1. Show Log
I.5. BGP commands
I.5.1. Show BGP
I.5.2. Show BGP Peer
I.5.3. Show BGP Summary
I.5.4. Show BGP Routes
I.5.5. Compare BGP
I.5.6. Clear BGP
I.5.7. Refresh BGP
I.5.8. Refresh BGP
I.6. PPPoE commands
I.6.1. Show PPPoE
I.6.2. Show PPPoE
I.6.3. Clear PPPoE
I.7. L2TP commands
I.7.1. Show L2TP
I.7.2. Show L2TP Tunnels
I.7.3. Clear L2TP All
I.7.4. Show L2TP Tunnel
I.7.5. Show L2TP Tunnel
I.7.6. Show L2TP Sessions
I.7.7. Show L2TP Session
I.7.8. Clear L2TP Tunnel
I.7.9. Clear L2TP Tunnel
I.7.10. Clear L2TP Session
I.8. Advanced commands
I.8.1. Panic
I.8.2. Reboot
I.8.3. Screen width
I.8.4. Make outbound command session
I.8.5. Show command sessions
I.8.6. Kill command session
I.8.7. Flash memory list
I.8.8. Delete block from flash
I.8.9. Boot log
I.8.10. Flash log
J. Constant Quality Monitoring - technical details
J.1. Broadband back-haul providers
J.2. Tx/Rx direction
J.3. Access to graphs and csvs
J.3.1. Trusted access
J.3.2. Dated information
J.3.3. Authenticated access
J.4. Graph display options
J.4.1. Scaleable Vector Graphics
J.4.2. Data points
J.4.3. Additional text
J.4.4. Other colours and spacing
J.5. Overnight archiving
J.5.1. Full URL format
J.5.2. load handling
J.6. Graph scores
J.7. Creating graphs, and graph names
J.8. Ping
J.8.1. Automated ping control
J.8.2. Bulk ping configuration via a URL
J.8.3. Stopping Ping Graphs
K. Hashed passwords
K.1. Password hashing
K.1.1. Salt
K.2. One Time Password seed hashing
L. Configuration Objects
L.1. Top level
L.1.1. config: Top level config
L.2. Objects
L.2.1. system: System settings
L.2.2. system-logs: System log targets
L.2.3. auto-update: Automatic updates
L.2.4. acme-ca: ACME certificate settings
L.2.5. acme-certs: ACME certificate settings
L.2.6. web-ui-settings: Web interface customisation
L.2.7. link: Web links
L.2.8. routing-table: Default source IP for services using a given table
L.2.9. user: Admin users
L.2.10. eap: User access controlled by EAP
L.2.11. log: Log target controls
L.2.12. syslog-tls: TLS syslog settings
L.2.13. log-syslog: UDP syslog settings
L.2.14. log-email: Email logger settings
L.2.15. services: System services
L.2.16. http-service: Web service settings
L.2.17. dns-service: DNS service settings
L.2.18. dns-host: Fixed local DNS host settings
L.2.19. dns-block: Fixed local DNS blocks
L.2.20. radius-service: RADIUS service definition
L.2.21. radius-service-match: Matching rules for RADIUS service
L.2.22. radius-server: RADIUS server settings
L.2.23. mqtt-service: MQTT
L.2.24. mqtts-config: Secure MQTTS service
L.2.25. mqtt-config: Insecure MQTT service
L.2.26. mqtt-external: External MQTT/MQTTS connection
L.2.27. mqtt-map: MQTT message mapping
L.2.28. tls-serial: TLS serial settings
L.2.29. telnet-service: Telnet service settings
L.2.30. snmp-service: SNMP service settings
L.2.31. time-service: System time server settings
L.2.32. ethernet: Physical port controls
L.2.33. sampling: Packet sampling configuration
L.2.34. portdef: Port grouping and naming
L.2.35. interface: Port-group/VLAN interface settings
L.2.36. subnet: Subnet settings
L.2.37. subnet-template: Subnet option templates for RA
L.2.38. dhcp6-client: DHCPv6 Client
L.2.39. vrrp: VRRP settings
L.2.40. dhcps: DHCP server settings
L.2.41. dhcp-attr-hex: DHCP server attributes (hex)
L.2.42. dhcp-attr-string: DHCP server attributes (string)
L.2.43. dhcp-attr-number: DHCP server attributes (numeric)
L.2.44. dhcp-attr-ip: DHCP server attributes (IP)
L.2.45. pppoe: PPPoE settings
L.2.46. ppp-route: PPP routes
L.2.47. ppp-balance
L.2.48. balance-group: Balance group
L.2.49. gtp: GTP GGSN/PGW settings
L.2.50. route: Static routes
L.2.51. network: Locally originated networks
L.2.52. blackhole: Dead end networks
L.2.53. loopback: Locally originated networks
L.2.54. namedbgpmap: Mapping and filtering rules of BGP prefixes
L.2.55. bgprule: Individual mapping/filtering rule
L.2.56. bgp: Overall BGP settings
L.2.57. bgppeer: BGP peer definitions
L.2.58. bgpmap: Mapping and filtering rules of BGP prefixes
L.2.59. cqm: Constant Quality Monitoring settings
L.2.60. l2tp: L2TP settings
L.2.61. l2tp-outgoing: L2TP settings for outgoing L2TP connections
L.2.62. l2tp-incoming: L2TP settings for incoming L2TP connections
L.2.63. l2tp-relay: Relay and local authentication rules for L2TP
L.2.64. fb105: FB105 tunnel definition
L.2.65. fb105-route: FB105 routes
L.2.66. ipsec-ike: IPsec configuration (IKEv2)
L.2.67. ike-connection: connection configuration
L.2.68. ipsec-route: IPsec tunnel routes
L.2.69. ike-roaming: IKE roaming IP pools
L.2.70. ike-proposal: IKE security proposal
L.2.71. ipsec-proposal: IPsec AH/ESP proposal
L.2.72. ipsec-manual: peer configuration
L.2.73. ping: Ping/graph definition
L.2.74. profile: Control profile
L.2.75. profile-date: Test passes if within any of the time ranges specified
L.2.76. profile-time: Test passes if within any of the date/time ranges specified
L.2.77. profile-ping: Test passes if any addresses are pingable
L.2.78. shaper: Traffic shaper
L.2.79. shaper-override: Traffic shaper override based on profile
L.2.80. ip-group: IP Group
L.2.81. ip-group-dns: IP Group DNS
L.2.82. ip-group-url: IP Group URL
L.2.83. route-override: Routing override rules
L.2.84. session-route-rule: Routing override rule
L.2.85. session-route-share: Route override load sharing
L.2.86. rule-set: Firewall/mapping rule set
L.2.87. session-rule: Firewall rules
L.2.88. session-share: Firewall load sharing
L.2.89. etun: Ether tunnel
L.2.90. dhcp-relay: DHCP server settings for remote / relayed requests
L.3. Data types
L.3.1. ppp-dump: PPP dump format
L.3.2. autoloadtype: Update software
L.3.3. user-level: User login level
L.3.4. oldautoload
L.3.5. lacp-hot-standby: LACP hot standby mode
L.3.6. config-access: Type of access user has to config
L.3.7. eap-subsystem: Subsystem with EAP access control
L.3.8. eap-method: EAP access method
L.3.9. syslog-severity: Syslog severity
L.3.10. syslog-facility: Syslog facility
L.3.11. http-mode: HTTP/HTTPS security mode
L.3.12. radiuspriority: Options for controlling platform RADIUS response priority tagging
L.3.13. radiustype: Type of RADIUS server
L.3.14. mqtt-brokers: Select MQTT brokers
L.3.15. month: Month name (3 letter)
L.3.16. day: Day name (3 letter)
L.3.17. port: Physical port
L.3.18. LinkFlow: Physical port flow control setting
L.3.19. LinkClock: Physical port Gigabit clock master/slave setting
L.3.20. LinkFault: Link fault type to send
L.3.21. sampling-protocol: Sampling protocol
L.3.22. trunk-mode: Trunk port mode
L.3.23. ramode: IPv6 route announce level
L.3.24. bgpmode: BGP announcement mode
L.3.25. sampling-mode: Sampling mode
L.3.26. sfoption: Source filter option
L.3.27. pppoe-mode: Type of PPPoE connection
L.3.28. pppoe-calling: Additional prefix on PPPoE calling ID
L.3.29. pppoe-calling-suffix: Main calling ID
L.3.30. peertype: BGP peer type
L.3.31. ha-set: High availability set ID
L.3.32. radius-nas: NAS IP to report
L.3.33. ipsec-type: IPsec encapsulation type
L.3.34. ike-authmethod: authentication method
L.3.35. ike-mode: connection setup mode
L.3.36. ipsec-auth-algorithm: IPsec authentication algorithm
L.3.37. ipsec-crypt-algorithm: IPsec encryption algorithm
L.3.38. ike-PRF: IKE Pseudo-Random Function
L.3.39. ike-DH: IKE Diffie-Hellman group
L.3.40. ike-ESN: IKE Sequence Number support
L.3.41. ipsec-encapsulation: Manually keyed IPsec encapsulation mode
L.3.42. switch: Profile manual setting
L.3.43. chksum-action: Handling of TCP/UDP packet checksum
L.3.44. dynamic-graph: Type of dynamic graph
L.3.45. firewall-action: Firewall action
L.4. Basic types
Index

List of Figures

3.1. Icons for configuration categories
3.2. The "Setup" category
3.3. Editing an "Interface" object
3.4. Show hidden attributes
3.5. Attribute definitions
3.6. Navigation controls
4.1. Setting up a new user
8.1. Example sessions created by drop and reject actions
8.2. Processing flow chart for rule-sets and session-rules
C.1. Product label showing MAC address range

List of Tables

2.1. IP addresses for computer
2.2. IP addresses to access the FireBrick
2.3. IP addresses to access the FireBrick
3.1. Special character sequences
4.1. User login levels
4.2. Configuration access levels
4.3. General administrative details attributes
4.4. Attributes controlling auto-upgrades
4.5. Status LED indications
5.1. Logging attributes
5.2. System-Event Logging attributes
8.1. Default timeouts for session tracking
8.2. Action attribute values
8.3. obf-checksum values
9.1. Example route targets
15.1. IPsec algorithm key lengths
15.2. IKE / IPsec algorithm proposals
15.3. HA statistic definitions
16.1. List of system services
16.2. List of system services
17.1. Packet dump parameters
17.2. Packet types that can be captured
19.1. Peer types
19.2. Communities
19.3. Network attributes
C.1. DHCP client names used
D.1. Special URLs
D.2. Upgrade type numbers enum
F.1. SCCRQ
F.2. SCCRP
F.3. SCCCN
F.4. StopCCN
F.5. HELLO
F.6. ICRQ
F.7. ICRP
F.8. ICCN
F.9. OCRQ
F.10. OCRP
F.11. OCCN
F.12. CDN
F.13. WEN
F.14. SLI
G.1. Access-request
G.2. Access-Accept
G.3. Access-Accept - Vendor-Specific - Vendor-Id: FireBrick (24693)
G.4. Access-Reject
G.5. Accounting-Start
G.6. Accounting-Interim
G.7. Accounting-Stop
G.8. Disconnect
G.9. Change-of-Authorisation
G.10. Filter-ID
H.1. Indices
H.2. Fields
H.3. FbBgpPeerState - The state of a BGP peer
H.4. Fields
H.5. Indices
H.6. Fields
H.7. FbIPsecConState - The state of an IPsec connection
H.8. Fields
H.9. Fields
H.10. Indices
H.11. Fields
H.12. Fields
H.13. Indices
H.14. Fields
H.15. Indices
H.16. Fields
H.17. Indices
H.18. Fields
H.19. Fields
H.20. Fields
H.21. Indices
H.22. Fields
J.1. File types
J.2. Colours
J.3. Text
J.4. Text
J.5. URL formats
L.1. config: Attributes
L.2. config: Elements
L.3. system: Attributes
L.4. system: Elements
L.5. system-logs: Attributes
L.6. auto-update: Attributes
L.7. acme-ca: Attributes
L.8. acme-ca: Elements
L.9. acme-certs: Attributes
L.10. web-ui-settings: Attributes
L.11. web-ui-settings: Elements
L.12. link: Attributes
L.13. routing-table: Attributes
L.14. user: Attributes
L.15. eap: Attributes
L.16. log: Attributes
L.17. log: Elements
L.18. syslog-tls: Attributes
L.19. log-syslog: Attributes
L.20. log-email: Attributes
L.21. services: Attributes
L.22. services: Elements
L.23. http-service: Attributes
L.24. dns-service: Attributes
L.25. dns-service: Elements
L.26. dns-host: Attributes
L.27. dns-block: Attributes
L.28. radius-service: Attributes
L.29. radius-service: Elements
L.30. radius-service-match: Attributes
L.31. radius-server: Attributes
L.32. mqtt-service: Attributes
L.33. mqtt-service: Elements
L.34. mqtts-config: Attributes
L.35. mqtt-config: Attributes
L.36. mqtt-external: Attributes
L.37. mqtt-map: Attributes
L.38. tls-serial: Attributes
L.39. telnet-service: Attributes
L.40. snmp-service: Attributes
L.41. time-service: Attributes
L.42. ethernet: Attributes
L.43. sampling: Attributes
L.44. portdef: Attributes
L.45. interface: Attributes
L.46. interface: Elements
L.47. subnet: Attributes
L.48. subnet-template: Attributes
L.49. dhcp6-client: Attributes
L.50. vrrp: Attributes
L.51. dhcps: Attributes
L.52. dhcps: Elements
L.53. dhcp-attr-hex: Attributes
L.54. dhcp-attr-string: Attributes
L.55. dhcp-attr-number: Attributes
L.56. dhcp-attr-ip: Attributes
L.57. pppoe: Attributes
L.58. pppoe: Elements
L.59. ppp-route: Attributes
L.60. ppp-balance: Attributes
L.61. ppp-balance: Elements
L.62. balance-group: Attributes
L.63. gtp: Attributes
L.64. route: Attributes
L.65. network: Attributes
L.66. blackhole: Attributes
L.67. loopback: Attributes
L.68. namedbgpmap: Attributes
L.69. namedbgpmap: Elements
L.70. bgprule: Attributes
L.71. bgp: Attributes
L.72. bgp: Elements
L.73. bgppeer: Attributes
L.74. bgppeer: Elements
L.75. bgpmap: Attributes
L.76. bgpmap: Elements
L.77. cqm: Attributes
L.78. l2tp: Attributes
L.79. l2tp: Elements
L.80. l2tp-outgoing: Attributes
L.81. l2tp-outgoing: Elements
L.82. l2tp-incoming: Attributes
L.83. l2tp-incoming: Elements
L.84. l2tp-relay: Attributes
L.85. fb105: Attributes
L.86. fb105: Elements
L.87. fb105-route: Attributes
L.88. ipsec-ike: Attributes
L.89. ipsec-ike: Elements
L.90. ike-connection: Attributes
L.91. ike-connection: Elements
L.92. ipsec-route: Attributes
L.93. ike-roaming: Attributes
L.94. ike-proposal: Attributes
L.95. ipsec-proposal: Attributes
L.96. ipsec-manual: Attributes
L.97. ipsec-manual: Elements
L.98. ping: Attributes
L.99. profile: Attributes
L.100. profile: Elements
L.101. profile-date: Attributes
L.102. profile-time: Attributes
L.103. profile-ping: Attributes
L.104. shaper: Attributes
L.105. shaper: Elements
L.106. shaper-override: Attributes
L.107. ip-group: Attributes
L.108. ip-group: Elements
L.109. ip-group-dns: Attributes
L.110. ip-group-url: Attributes
L.111. route-override: Attributes
L.112. route-override: Elements
L.113. session-route-rule: Attributes
L.114. session-route-rule: Elements
L.115. session-route-share: Attributes
L.116. rule-set: Attributes
L.117. rule-set: Elements
L.118. session-rule: Attributes
L.119. session-rule: Elements
L.120. session-share: Attributes
L.121. etun: Attributes
L.122. dhcp-relay: Attributes
L.123. dhcp-relay: Elements
L.124. ppp-dump: PPP dump format
L.125. autoloadtype: Update software
L.126. user-level: User login level
L.127. oldautoload
L.128. lacp-hot-standby: LACP hot standby mode
L.129. config-access: Type of access user has to config
L.130. eap-subsystem: Subsystem with EAP access control
L.131. eap-method: EAP access method
L.132. syslog-severity: Syslog severity
L.133. syslog-facility: Syslog facility
L.134. http-mode: HTTP/HTTPS security mode
L.135. radiuspriority: Options for controlling platform RADIUS response priority tagging
L.136. radiustype: Type of RADIUS server
L.137. mqtt-brokers: Select MQTT brokers
L.138. month: Month name (3 letter)
L.139. day: Day name (3 letter)
L.140. port: Physical port
L.141. LinkFlow: Physical port flow control setting
L.142. LinkClock: Physical port Gigabit clock master/slave setting
L.143. LinkFault: Link fault type to send
L.144. sampling-protocol: Sampling protocol
L.145. trunk-mode: Trunk port mode
L.146. ramode: IPv6 route announce level
L.147. bgpmode: BGP announcement mode
L.148. sampling-mode: Sampling mode
L.149. sfoption: Source filter option
L.150. pppoe-mode: Type of PPPoE connection
L.151. pppoe-calling: Additional prefix on PPPoE calling ID
L.152. pppoe-calling-suffix: Main calling ID
L.153. peertype: BGP peer type
L.154. ha-set: High availability set ID
L.155. radius-nas: NAS IP to report
L.156. ipsec-type: IPsec encapsulation type
L.157. ike-authmethod: authentication method
L.158. ike-mode: connection setup mode
L.159. ipsec-auth-algorithm: IPsec authentication algorithm
L.160. ipsec-crypt-algorithm: IPsec encryption algorithm
L.161. ike-PRF: IKE Pseudo-Random Function
L.162. ike-DH: IKE Diffie-Hellman group
L.163. ike-ESN: IKE Sequence Number support
L.164. ipsec-encapsulation: Manually keyed IPsec encapsulation mode
L.165. switch: Profile manual setting
L.166. chksum-action: Handling of TCP/UDP packet checksum
L.167. dynamic-graph: Type of dynamic graph
L.168. firewall-action: Firewall action
L.169. Basic data types

List of Examples

H.1.
H.2.
/ ========================================================================== / ==========================================================================