41 4 CONSOLE 41 4 POWER HDD CONSOLE ESC UP DOWN ENTER POWER HDD 01,0 05,06 17,18 19,0 5,6 1, 3,4 9,30 ESC UP DOWN ENTER 01,0 05,06 17,18 19,0 5,6 1, 3,4 9,30 03,04 09,10 07,08 13,14 7,8 33,34 31,3 37,38 03,04 09,10 07,08 13,14 7,8 33,34 31,3 37,38 11,1 15,16 35,36 39,40 11,1 15,16 35,36 39,40 W CR 1000iNG-XP W CR 500iNG-XP QUICK START GUIDE CR1000iNG-XP CR1500iNG-XP CR500iNG-XP Appliances Document Version: PL QSG1000iNG-XP,1500iNG-XP,500iNG-XP/ 96000-10.04.5.0.007/5011014
41 4 CONSOLE POWER HDD ESC UP DOWN ENTER 01,0 05,06 17,18 19,0 5,6 1, 3,4 9,30 03,04 09,10 07,08 13,14 7,8 33,34 31,3 37,38 11,1 15,16 35,36 39,40 DEFAULTS Default IP addresses Ethernet Port IP Address Zone 1 17.16.16.16/55.55.55.0 LAN IP via DHCP WAN Default Username & Password Web Admin Console * Username admin * Password admin Package Contents Checking the package contents - Check that the package contents are complete.! One Cyberoam Appliance! One Cyberoam Quick Start Guide! Two Power Cables! One Serial Cable! Rack Mount Kit! One Straight-through Ethernet Cable! One Cross-over Ethernet Cable CLI Console (SSH/Serial Connection) Quick Start Guide Power Cable Serial Cable * Password admin * Username and Password are case sensitive Rack Mount Kit Straight-through Ethernet Cable Cross-over Ethernet Cable If any items from the package are missing. please contact Cyberoam Support at support@cyberoam.com UNDERSTANDING THE APPLIANCE FRONT PANEL LCD Display (For future use) 1,,3,4,5,6,7,8 - Use these ports to connect the Appliance to Ethernet network. FleXi Ports Module 8-port 1 GbE Copper Module HDD1 W CR 500iNG-XP Slot 1* 8-port 1 GbE Fiber Module 4-port 10 GbE Fiber Module Console Port Console cable connects here Slot * USB Ports Slot 3* Slot 4* (For future use) * Refer to the Port Naming Table on Page3. BACK PANEL Power Supply Power Switch Fans Power connectors Power cables connect to power outlets System Fans As Cyberoam does not pre-configure any ports for LAN, WAN, DMZ networks, it is not necessary to use any particular port for them. Usage of ports depends on how the physical connection is required or planned.
FleXi PORTS SCENARIOS: Note: 1. It is mandatory to Power Off the Cyberoam Appliance and remove the Power Cable before inserting or swapping the FleXi Ports Module.. Maximum of 8 ports are available per FleXi Ports Slot. However, out of those 8 ports, actual number of ports available for use is dependent on the FleXi Ports Module you install i.e. 8-port Copper/Fiber or 4-port Fiber. For example, if you install 4-port Fiber Module in Slot 1 and 8-port Copper Module in Slot, available Ports for use in Slot 1 are Ports 13 to 16 (total 4 ports) and Slot are 17-4 (total 8 ports). Refer to the Port- Naming Table given below for detailed information. 3. In case of HA configuration, for optimal performance, use Fixed Ports in the member appliances to configure Dedicated HA Link Port. Port-Naming Table (For Flexi Ports Module): Selected FleXi Ports Slot Slot 1 Slot Slot 3 Slot 4 Available Ports for Use 9,10,11,1 (Upper row) 13,14,15,16 (Lower row) 17,18,19,0 (Upper row) 1,,3,4 (Lower row) 5,6,7,8 (Upper row) 9,30,31,3 (Lower row) 33,34,35,36 (Upper row) 37,38,39,40 (Lower row) Inserting a new FleXi Ports Module Step 1: Choose Slot i.e. Slot1/Slot/Slot3/Slot4 or All. For single Slot, it is recommended to use Slot1. Step : Remove the thumbscrew and remove the Blank Plate. Store the Blank Plate for future use. Step 3: Insert selected FleXi Ports Module in the selected Slot(s). Step 4: Restore the thumbscrew and Power ON the Appliance. Swapping an existing FleXi Ports Module Step 1: Remove the thumb screw and remove the FleXi Ports Module. Step : Insert new FleXi Ports Module or place the Blank plate. Step 3: Restore the thumbscrew and Power ON the Appliance. Note: Cyberoam will auto-detect the new FleXi Ports Module, without any manual intervention.
CR 1000iNG-XP 41 4 CONSOLE POWER HDD ESC UP DOWN ENTER 01,0 05,06 17,18 19,0 5,6 1, 3,4 9,30 03,04 09,10 07,08 13,14 7,8 33,34 31,3 37,38 11,1 15,16 35,36 39,40 3 MOUNTING THE APPLIANCE USING IMMOBILE BRACKETS This guide gives the instructions for mounting a Cyberoam Appliance onto a standard (one Rack Unit) Rack using immobile Rack Brackets. Sr No. Part Name Qty Description 1 Rack Bracket (L Type) Attaches the Appliance to the rack. Each Rack Bracket constitutes of Two () cavities (Type A and B). Cross/Plus Screw 110 Flat Machine, M3x8L(1U) Flat Machine, M4x8L(U) Appliance Specific Secures the Rack Brackets and the Appliance to the rack. The quantity is as follows: Appliance CR50iNG and CR100iNG CR00iNG/XP and CR300iNG/XP CR500iNG-XP and CR750iNG-XP CR1000iNG-XP, CR1500iNG-XP and CR500iNG-XP Quantity 6 10 6 14 3 U Handle Facilitates the easy handling of a U Appliance. INSTALLATION INSTRUCTIONS 1 Locate the cavities at the front left and front right of your Appliance and align the Rack Bracket cavities with the Appliance cavities. Attach the Rack Brackets to the Appliance using 110 Flat Machine (1U) or Flat Machine (U) screws with the help of a Cross Head / Plus type screwdriver (not included) as shown (Figure-1). (Figure - 1) 3 Align the U Handle with the Rack Bracket and secure the assembly using two () Flat Machine (U) screws with the help of a Cross Head / Plus type screwdriver (not included) as shown (Figure- ). Skip this step if you are mounting a 1U Appliance. (Figure - ) 4 Replicate the above steps with the second bracket. 5 Locate the position of the Appliance in your Network Rack and use Mounting Bracket screws (not included) on each side to secure the appliance on the rack through cavity B as shown. W (Figure - 3)
CR 1000iNG-XP 41 4 CONSOLE POWER HDD ESC UP DOWN ENTER 01,0 05,06 17,18 19,0 5,6 1, 3,4 9,30 03,04 09,10 07,08 13,14 7,8 33,34 31,3 37,38 11,1 15,16 35,36 39,40 4 MOUNTING THE APPLIANCE USING SLIDING RAILS This guide gives the instructions for mounting a Cyberoam Appliance onto a standard (One Rack Unit) Rack using Sliding Rails. Sr No. Part Name Qty Description 1 Inner Rail Supports the Appliance to facilitate its sliding over an Outer Rail. Rack Bracket Attaches the Appliance and the Inner Rails and secures it on the rack. Each Rack Bracket constitutes of two () cavities (Type A and B). 3 Cross/Plus Screw (I-head, M4x8L) 1(1U) 14(U) Secures the Bracket with the Appliance and Inner Rails. INSTALLATION INSTRUCTIONS 1 Locate the cavities at the right angled end of the inner rail and align the Rack Bracket cavities with the inner rail as shown in (Figure-1). Cavity B Cavity A (Rack Bracket) Locate the cavities at the front left and front right of your Appliance and attach it to the Rack Bracket and Inner Rail using I-head screws with a Cross Head / Plus type screwdriver (not included). Each side of the Appliance has Six (6) (1 U Appliances) or Eight (8) ( U Appliances) cavities. Two () (1 U Appliances) or Four (4) ( U Appliances) cavities align with the Rack Bracket and Four (4) align with the Inner Rail through Cavity A, as shown in (Figure-). (Figure - 1) 3 Replicate the above steps with the second rail. (Figure - ) 4 Locate and position the Appliance parallel to the Outer Rails (not included) and slide the Appliance on to the Network Rack. Use mounting bracket screws (not included) on each side to secure the appliance on the rack through Cavity B, as shown in (Figure-3). W This completes the mounting procedure. (Figure - 3)
5 PLANNING THE CONFIGURATION Before configuring, you need to plan the deployment mode of Cyberoam. Cyberoam can be placed in Bridge or Gateway/Route mode according to your requirement. To control the Internet access through Cyberoam the entire Internet bound traffic from the LAN network should pass through Cyberoam. Gateway Mode Configure as Gateway if you want to use Cyberoam as 1. A firewall or replace an existing Firewall. A gateway for routing traffic 3. Link load balancer and implement gateway failover functionality Apart from configuring Gateway IP address (IP address through which all the traffic will be routed), you must also configure LAN and WAN IP addresses. Internet WAN 61.10.15.17 61.10.15.18 10.10.10.1 Cyberoam in Gateway mode Gateway mode policies controlling traffic between LAN and WAN networks. 19.168.1.54 LAN Network 10.10.10. 10.10.10.3 Gateway mode policies controlling traffic between LAN & DMZ networks. DMZ Network Mail Server Web Server 19.168.1.9 19.168.1.5 Bridge Mode Configure as Bridge if 1. You have a private network behind an existing firewall or behind a router and you do not want to replace the firewall.. You are already masquerading outgoing traffic. Internet Cyberoam in Bridge mode LAN LAN Network 10.10.10.54 10.10.10.1 Management IP 10.10.10.5 Bridge mode policies controlling traffic between LAN and WAN networks You will be able to manage and monitor the entire Internet traffic passing through Cyberoam, control web access and apply bandwidth and application restrictions, apply antivirus and antispam policy and IPS policy in either of the modes.
6 GETTING CONFIGURATION INFORMATION Use the table given below to gather ISP (Internet Service Provider) information If Internet connection is via You are probably using Get information Cyberoam configuration from Network Configuration wizard Cable modem, DSL with a Router DHCP ----------- Select Obtain an IP from DHCP Home DSL/ADSL PPPoE Username Password Select Obtain an IP from PPPoE T1/E1, Static broadband, Cable or DSL with a static IP Static IP address Subnet mask Gateway IP address Primary DNS Secondary DNS Select Use Static IP How to get the information: From the PC connected to the Internet: open a command prompt window, type the command ipconfig. Use the tables given below to gather the information you need before proceeding to deploy the Appliance. Gateway Mode For all the required Ports Port 1 IP address... Zone Type LAN/WAN/DMZ Port IP address... Zone Type LAN/WAN/DMZ Port 7 IP address... Zone Type LAN/WAN/DMZ Port 8 IP address... Zone Type LAN/WAN/DMZ Port 3 IP address... Zone Type LAN/WAN/DMZ Port 4 IP address... Zone Type LAN/WAN/DMZ Port 41 IP address Subnet Mask Zone Type Port 4 IP address Subnet Mask Zone Type...... LAN/WAN/DMZ...... LAN/WAN/DMZ Port 5 IP address... Zone Type LAN/WAN/DMZ The LAN IP address and Subnet Mask must be valid for the respective networks. Port 6 IP address... Zone Type LAN/WAN/DMZ To configure extra FleXi Ports Module, please refer to the above table. Bridge Mode Bridge/Cyberoam Management IP address IP address...
GENERAL SETTINGS IP address of the Default Gateway A default gateway is required for Cyberoam to route connections to the Internet. DNS IP Address System Time Zone System Date and Time Email ID of the administrator where Cyberoam will send System Alerts...... 7 CONNECTING CYBEROAM Ethernet connection 1. Connect one end of the straight-through cable into Port 1 on the Back panel of the Appliance and the other end into the Ethernet Adapter port of Management computer. Change the IP address of the management computer to 17.16.16., Gateway and DNS Server address to 17.16.16.16 and the subnet mask to 55.55.55.0.. Connect one end of an Ethernet cable into Port on the Back panel of the Appliance and the other end to your Internet connection e.g. DSL modem or cable modem. It is possible that cable might already be connected between your computer and your modem. If so, disconnect it from your computer and connect into Port. Internet Switch (Optional) Management Computer 3. Connect the AC Power connector into the Back panel of the Appliance and the other end into a standard AC receptacle and turn the power switch ON. 4. Start your management computer. Following Appliance LEDs light up: Power - Green indicating that Appliance is ON CF/HDD - Red indicating that hard disk is Active Port 1, Port (Front panel) - Green indicating an active connection
From the management computer: 1. Browse to https://17.16.16.16. Log on to the Cyberoam Web Admin Console using default username admin and password admin. 3. Click Wizard icon to launch the Network Configuration wizard. Prerequisite 1. Ethernet connection between management computer and Cyberoam.. Internet Explorer 7+ or Mozilla Firefox 1.5+ is required to access Cyberoam Web Admin Console. Appliance LED Behavior LED Power CF/HDD Ports - A,B,C,D,E,F,G,H 1,,3,4,5,6,7,8,41,4 (Front Panel) State Green Off Flashing Red Off Flashing Green (L) Amber (Left) Amber Green (L), (Left) Flashing Green (R) Green (Right) Green (L), Flashing Off Amber (R) Off Description Cyberoam appliance is ON Cyberoam appliance is OFF Activity going on No activity Network Port is connected Activity at at the 10Mbps Port Correct Port is connected cable is used at 100Mbps and power is on port Port is connected at the 100Mbps Port is connected at 1000Mbps No link No link
8 CONFIGURING THE CYBEROAM APPLIANCE Network Configuration Wizard guides you step-by-step through the configuration of the network parameters like IP address, subnet mask, and default gateway for Cyberoam. Use the configuration settings you have noted in section 4. Click 'Start' to start the configuration. CONFIGURE MODE Screen 1 - Network Configuration Wizard Gateway mode To configure Cyberoam in Gateway mode, select the option Gateway Mode and click button. Follow the on-screen steps to: 1. Configure Interface: Configure IP Address, Subnet Mask and Zone for each port, where Zone is a logical grouping of Interfaces. By default, Cyberoam binds ports 1, and 3 to LAN, WAN and DMZ Zones respectively. For optimal performance, select ports from FleXi Ports Module to bind to the Zones. To enable interface for PPPoE, provide PPPoE details: Username and Password (only for WAN Zone). Click Next to repeat the steps given above for each port. Bridge mode To configure Cyberoam in Bridge mode, select the option Bridge Mode and click button. 1. Select the LAN and WAN ports to be bridged. By default, Port 1 is a member of LAN and Port is of WAN.. To manage the Cyberoam in your network, configure the IP Address and Subnet Mask. Provide the Gateway and DNS details to connect Cyberoam to the Internet. Refer to General Settings in Section 4.. Configure DNS server address: Click Obtain an IP from DHCP to override appliance DNS and use DNS received from the external DHCP server. Refer to the screen titled Screen - Gateway Mode: Zone and Network Configuration. Proceed to Configure Internet Access section on the next page.
Interface Configuration DNS Configuration CONFIGURE INTERNET ACCESS By default, Cyberoam applies 'General Internet Policy' as Internet access policy for LAN to WAN traffic. Do not change the default setting. Cyberoam provides 3 types of policies: Screen - Gateway Mode: Zone and Network Configuration 'Monitor Only' policy allows all LAN to WAN traffic 1 'General Internet' policy enables IPS and Virus scanning and allows LAN to WAN traffic except Unhealthy Web and Internet traffic as defined by Cyberoam. This will include sites related to Adult contents, Drugs, Crime and Suicide, Gambling, Militancy and Extremist, Violence, Weapons, Phishing and Fraud and URL Translation sites. 1 'Strict Internet' policy enables IPS and Virus scanning and allows only authenticated LAN to WAN traffic. Click button to configure the mail settings Screen 3 - Access Configuration 1 Until Intrusion Prevention System module is subscribed, IPS scanning will not be effective. Until Gateway Anti Virus module is subscribed, virus scanning will not be effective.
CONFIGURE MAIL SETTINGS 1. Specify Administrator Email ID. Specify Mail server IP address 3. Specify email address that should be used to send the System Alerts 4. Click Authentication Required to enable SMTP authentication, if required and specify username and password. Click button for Date and Time zone configuration CONFIGURE DATE AND TIME ZONE Set time zone and current date Screen 4 - Mail Settings Enable clock synchronization with NTP server to tune Cyberoam's clock using global time servers. Screen 5 - Date and Time Configuration Click button to view the configured details. Copy the configured details for future use. Click 'Finish'. It will take a few minutes to save the configuration details.
Configuring Gateway Mode Please wait... Screen 6 - Network Configuration Wizard On successful configuration the following page is displayed. https://10.10.10.1 Click to Access Web Admin Console After a few seconds, click the URL to access the Web Admin Console. Click Close button to close the Network Configuration Wizard window. Note: If you change the LAN IP address (Gateway mode) or Bridge IP address (Bridge mode), you must use this address to reconnect to the Web Admin Console. You might also have to change the IP address of the management computer to be on the same subnet as the new IP address. Refer to the Guides section on http://docs.cyberoam.com for information on how to Control Traffic, and how to configure Anti-Virus Protection, Content Filtering, Spam Filtering, Intrusion Prevention System (IPS), and Virtual Private Networking (VPN). Congratulations!!! This finishes the basic configuration of Cyberoam. Screen 7 - Network Configuration Wizard Your network is now protected from Internet-based threats and access to Adult contents, Drugs, Crime and Suicide, Gambling, Militancy and Extremist, Violence, Weapons, Phishing and Fraud and URLTranslation sites are blocked.
9 EXPLORING THE LCD INTERFACE To navigate through this menu/submenu on the LCD panel, following keys and their respective functionality is described in table below: Sr No. 1 3 4 Key Up Arrow Down Arrow Enter ESC Functionality Navigates and displays the previous item on the menu. If Up Key is pressed while being on the first item of the menu, the same item will be displayed on LCD. Navigates and displays the next item on the menu. If Down Key is pressed while being on the last item of the menu, the same item will be displayed on LCD. To enter in the sub-menu of the item or to display the content of the item. To go back to the previous menu. If ESC key is pressed while being on main menu, Cyberoam banner will be displayed. LCD MENU 1. Home Screen The active Firmware on the Appliance is displayed. Press enter to navigate to the Main Menu. Use the <up>/<down> buttons to view the available features listed in the Main Menu. System Menu Network Menu Firmware Menu HA Info. System Menu On the home screen, press Enter and select the first option that appears. The System Menu displays the following Cyberoam parameters: System Date Total Uptime CPU Usage Memory Usage Load Average Detailed Hard Disk Usage Live Users.1 System Date From the System Menu, select the Show Date option. The day, date and time zone configured in the system is displayed.. Show Uptime Navigate to option (two) of the System Menu, select the Show Uptime option. The time since last reboot is displayed..3 Show CPU Navigate to option 3 (three) of the System Menu, select the Show CPU option. The System CPU usage is displayed in percentage..4 Show Memory Navigate to option 4 (four) of the System Menu, select the Show Memory option. The System RAM usage is displayed in percentage..5 Show Load Average Navigate to option 5 (five) of the System Menu, select the Show Load Average option. The Average Load on the System measured at instances of 1 (one), 5 (five) and 15 (fifteen) minutes is displayed as a fraction of 1 (one)..6 Show Disk Navigate to option 6 (six) of the System Menu, select the Show Disk option. Navigate to option 1 (one) of Show Disk, and select the Total Usage option. The overall System Hard Disk usage is displayed in percentage.
Navigate to option (one) of Show Disk, and select the Detail Usage option. Detailed System Hard Disk usage of root and temporary files is displayed in percentage..7 Live Users Navigate to option 7 (seven) of the System Menu, select the Live Users option. The number of Live users connected to Cyberoam is displayed. Note Press <Esc> to return to System Menu. Press <Esc> for the second time to return to Main Menu. 3. Network Menu On the home screen, press Enter and select the second option that appears. The Network Menu displays the following Cyberoam parameters: Show Port A Show Port B Show Port X Show All 3.1 Show Port A-C From the Network Menu, select the Show Port A option. The Port Name, Zone and its IP Address is displayed. Navigate to option (two) of the Network Menu, select the Show Port B option to display above mentioned information for Port B. Similar navigation can be done upto Port C. 3. Show All Navigate to the last of the Network Menu, select the Show All option. A cumulative list of configuration information for all ports can be viewed by using the <up> and <down> buttons. Note Press <Esc> to return to Network Menu. Press <Esc> for the second time to return to Main Menu. 4. Firmware Menu On the home screen, press Enter and select the third option that appears. The Firmware Menu displays the following Cyberoam parameters: Show Firmware Factory Reset Appliance Shut Down Appliance Reboot Appliance 4.1 Show Firmware From the Firmware Menu, select the Show Firmware option. The Firmware Version of the uploaded firmware is displayed. Use <up>/<down> keys to navigate. 4. Factory Reset Navigate to option (two) of the Firmware Menu, select the Factory Reset option. Resetting Cyberoam to Factory Default Configuration removes all user custom configuration from the Appliance and boots it with factory default settings. Press enter to confirm. 4.3 Shut Down Navigate to option 3 (three) of the Firmware Menu, select the Shut Down option. Press enter to Shut Down the Appliance. Press enter to confirm. 4.4 Reboot Navigate to option 4 (four) of the Firmware Menu, select the Reboot option. Press enter to Hard Reboot the Appliance. Press enter to confirm. Note Press <Esc> to return to Firmware Menu. Press <Esc> for the second time to to return to Main Menu. 5. HA Info On the home screen, press Enter and select the fourth option that appears. The HA Info displays the member port configuration details if Cyberoam is configured in High Availability (HA). A Not Configured message is displayed if HA is not configured in Cyberoam. Note Press <Esc> to return to Main Menu.
10 WHAT NEXT? 1. Create Customer Account and register Appliance Browse to http://customer.cyberoam.com and click Register and follow the on-screen steps. It creates your customer account as well as register your appliance. To subscribe for free 15-days trial subscription of Web and Application Filtering, IPS, Anti Virus and Anti Spam, browse to http://customer.cyberoam.com and login with the credentials provided at the time of account creation.. Access Cyberoam Web Admin Console Browse to https://<ip address of cyberoam> and log on using the default username (admin) and password (admin). Note: Internet Explorer 7+ or Mozilla Firefox 1.5+ is required to access the Cyberoam Web Admin Console. 3. Go to menu System Maintenance Licensing page and synchronize the registration details. Registration and subscription details are displayed only after synchronization. 4. Configure the correct firewall rule for your Domain Name Server (DNS). You may not be able to access Internet if not configured properly. 5. Go to Firewall Rule Rule and edit default firewall rules to enable virus scanning. 6. Set authentication parameters Go to Identity Authentication Authentication Server to define the authentication parameters. 7. Access Help For accessing online help, click the Help button or F1 key on any of the screens to access the corresponding topic's help. Use the Contents and Index options to navigate through the entire online help. Additional Resources Visit following links for more information to configure Cyberoam Technical Documentation - http://docs.cyberoam.com Cyberoam Knowledge Base - http://kb.cyberoam.com Cyberoam Security Center - http://csc.cyberoam.com Cyberoam Upgrades - http://download.cyberoam.com Important Notice Cyberoam Technologies Pvt. Ltd. has supplied this Information believing it to be accurate and reliable at the time of printing, but is presented without warranty of any kind, expressed or implied. Users must take full responsibility for their application of any products. Cyberoam Technologies Pvt. Ltd. assumes no responsibility for any errors that may appear in this document. Cyberoam Technologies Pvt. Ltd. reserves the right, without notice to make changes in product design or specifications. Information is subject to change without notice. USER S LICENSE Use of this product is subject to acceptance of the terms and conditions of Cyberoam End User License Agreement (EULA) and Warranty Policy for Cyberoam Security Appliances. You will find the copy of the EULA at http://www.cyberoam.com/documents/eula.html and the Warranty Policy for Cyberoam Security Appliances at http://kb.cyberoam.com RESTRICTED RIGHTS Copyright 1999-014 Cyberoam Technologies Private Ltd. All rights reserved. Cyberoam, Cyberoam logo are trademark of Cyberoam Technologies Pvt. Ltd. Toll Free Numbers USA : +1-800-686-360 India : 1-800-301-00013 APAC/MEA : +1-877-777-0368 Europe : +44-808-10-3958 Visit: www.cyberoam.com Contact: sales@cyberoam.com