Anda di halaman 1dari 114

Nebero

Adding intelligence to your network

Nebero Systems Pvt. Limited

Nebero Installation & Configuration Guide

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

nfiguration Guide

Nebero

Nebero Systems Pvt. Limited Contents

Adding intelligence to your network http://www.nebero.com

S.No 1

Description Quick Installation Guide 1.1 System Requirement 1.2 Installation 1.3 Initial Configuration Introduction

............................................. ............................................. .............................................

2.1 What is Nebero ............................................. 2.1 How to Manage Nebero ............................................. 2.3 Nebero Concept Bandwidth 3.1 Bandwidth Setting 3.2 Bandwidth Pool 4 Policies 4.1 Creating Policies 4.2 Modifiying Policy 4.3 Deleting a Policy

............................................. ............................................. ............................................. ............................................. ............................................. .............................................

4.4 Configuring Customized Ports ............................................. 4.5 Advance Firewall ............................................. Groups 5.1 Creating Group 5.2 Modifying a Group

............................................. .............................................

5.3 Deleting a Group ............................................. 5.4 Applying Time Policy on a Group ............................................. 5.5 Applying IP Restriction on Web ............................................. Group Users 6.1 Creating Users ............................................. 6.2 Modifying Users 6.3 Deleting Users 6.4 User Firewall 7 Surf Policy 7.1 Allowing a Site/Url 7.2 Blocking a Site/Url

............................................. ............................................. ............................................. ............................................. .............................................

Nebero Guide . 21.33.8

Page No.

5 5 6 6

7 7 10

11 12 13 14 15 17 18 19 20 20 21 22 23 24 26 26 27 28 29 30 30 31, 32 2

Nebero

Nebero Systems Pvt. Limited

Adding intelligence to your network http://www.nebero.com

7.3 Block Word 7.4 Requested Url 7.5 No Cache Sites Network/Firewall 8.1 DMZ 8.2 VLAN 8.3 Global Firewall 8.4 IP MAP . 8.5 S-NAT Services 9.1 DHCP 9.2 Anti Spam Nebero Config 10.1 Net Config 10.2 Active Directory 10.3 Monitor 10.4 Branding 10.5 Disk Usage 10.6 Backup/Restore

............................................. ............................................. .............................................

Please contact Nebero helpdesk on Chat/Email/Phone for more information

............................................. ............................................. ............................................. ............................................. ............................................. ............................................. .............................................


Please contact Nebero helpdesk on Chat/Email/Phone for more information

10

10.7 Recycle 10.8 Advance Utility

.............................................
Please contact Nebero helpdesk on Chat/Email/Phone for more information

11

10.9 Shutdown/Restart ............................................. Reports 11.1 User Web Access Reports ............................................. 11.2 Web Site User 11.3 Web Site Url

............................................. .............................................

11.4 Blocked User Web Access ............................................. 11.5 Blocked Web Site User ............................................. 11.6 Blocked Web Site URL ............................................. 11.7 Content type ............................................. 11.8 System Bandwidth usage .............................................

Nebero Guide . 21.33.8

33 33 35

36 36 38 38

38 39 40

41

41 42 42 46 47 48 52 53 54 54 3

Nebero

Nebero Systems Pvt. Limited


http://www.nebero.com

Adding intelligence to your network

11.9 User Bandwidth usage ............................................. 11.10 Connection Logs ............................................. 12 Admin 12.1 Admin Policy

12.2 Admin Users

Please contact Nebero helpdesk on Chat/Email/Phone for more information Please contact Nebero helpdesk on Chat/Email/Phone for more information 0.0

Nebero Help Desk : Email : Phone : Yahoo Messenger ID: Gtalk ID :

help@nebero.com +91-172-4318888 cyberix_helpdesk nebero.help

Nebero Guide . 21.33.8

55 56

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited Quick Installation Guide

Install Nebero with just 3 keystrokes This guide will help you to install Nebero on your PC quickly. One of the newest features introduced in this release is automatic installation. The installation process has been simplified and automated to the extent that besides 3 keystrokes no user interaction is required. The only effort needed from the user, during the whole installation process is that he/she just needs to press \"Enter\" three times. Yes, I know its too good to believe, but that is true, with only 3 keystrokes Nebero is up and running on your PC. Even this much user interaction has been left deliberately as a precautionary measure, so that user doesn't end up losing all his data inadvertently, due to auto partitioning. Backup your data first The first and the foremost thing is to backup your old data in case you are performing an upgrade or you are installing Nebero on an already used PC, as the installation process will erase all the partitions and thereafter no data will be recoverable. SO USERS ARE STRICTLY ADVISE BACKUP THEIR DATA FIRST BEFORE PERFORMING ANY ACTION. WE WILL NOT BE LIABLE FOR ANY DATA LOSS. You can call up our technical support executive, for the help on how to backup the existing data, in case your are upgrading. System Requirements: Minimum PROCESSOR: PIV / AMD 2.0 GHz RAM: 512 MB HDD: 40 GB ETHERNET CARDS: Two Ethernet cards required. Peripherals: Keyboard, Monitor, Mouse (not required). Recommended PROCESSOR: PIV / AMD 3.0 GHz RAM: 1 GB / 2 GB HDD: 80 GB / 160 GB ETHERNET CARDS: Three Ethernet cards required. Peripherals: Keyboard, Monitor, Mouse (not required).

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

of the newest features process has been simplified and tion is required. The only effort he/she just needs to press is true, with only 3 keystrokes ction has been left deliberately as s data inadvertently, due to auto

you are performing an upgrade ation process will erase all the SO USERS ARE STRICTLY ADVISED TO TION. WE WILL NOT BE LIABLE xecutive, for the help on how to

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited


http://www.nebero.com

Installation

Put in your latest Nebero installation disk in the CD-ROM/DVD drive of your PC and reboot. Make sure your CD-ROM/DVD drive is on the top priority in the boot order of your BIOS, otherwise your system won't boot from the CD-ROM/DVD drive. If needed, please change the boot order of your system, in BIOS setup and give your CDROM/DVD drive top priority.After rebooting you will be greeted by Nebero boot prompt. Please press \"Enter\" to boot from Nebero installation disk. You system will now boot from the Nebero installation disk and will perform the actions necessary for installation of Nebero. Nebero setup will automatically calculate the partitions required for installation and will inform you before actually creating the partitions through a red-colored popup window. It will wait patiently for your confirmation to proceed further. Only when you press \"Enter\" it will proceed further and will actually start creating the partitions for you. It will create the partitions and format them with required file system. And the installation will proceed further. Nebero setup will once again ask you to press \"enter\" this time the last one, when the installation process will finish. As you press enter, your PC will reboot into your newly installed Nebero. Initial Configuration After reboot, you will be taken to Nebero login prompt. Enter \"nebero\" as user name and \"nebero123\" as password and Nebero Setup Utility will flash up with its white border and blue background. Here you will define your network details and will tune Nebero according to your particular network scenario. Here you will need to define:-

INTERNAL IP ADDRESS: This IP address will be assigned to internal network card, the will have internal LAN cable terminated on it. All other PCs in your LAN will access internet thru it. So you will have to define this IP address in their network setup as gateway and primary DNS. EXTERNAL IP ADDRESS: This IP address will be assigned to external network card, the which will have external cable (cable from your ISPs router) terminated on it. It is your public IP, give to you by your ISP. GATEWAY: Gateway IP address given to you by your ISP. DNS: Primary and Secondary DNS given to you by your ISP. DMZ: IP address of your DMZ / Perimeter Area Network. If you don't have DMZ / Perimeter Are Network, don't leave this field blank, rather enter a fake IP address which doesn't clash with any of your existing network. Save and exit from \"Network configuration\". Nebero will take some time and will inform you when the configuration is done, with a pop \"Settings Successfully updated\". You can use \"Ping\" from the \"Utilities\" section in \"Nebero Setup Utility\" to confirm that both your internal and external network cards are functioning properly. Once you are sure both the cards are functioning properly, you can proceed further. Otherwise, go back to the \"Network Configuration\" section of \"Nebero Setup Utility\" and do the required modifications. Define Bandwidth settings, Policies, Groups and Users. Now you are ready to configure your bandwidth settings, make policies, define groups and users. We will do them step-by-step and will proceed gradually. 1. First, define Bandwidth Settings. 2. Second, define Policies. 3. Third, make Groups. 4. And at last populate your groups with users.

Nebero Guide . 21.33.8

ve of your PC and reboot. Make er of your BIOS, otherwise your

setup and give your CDNebero boot prompt. Please will now boot from the Nebero ion of Nebero. Nebero setup will will inform you before actually ill wait patiently for your will proceed further and will actually format them with required file once again ask you to press nish. As you press enter, your PC

ero\" as user name and with its white border and blue e Nebero according to your

signed to internal network card, the one which LAN will access internet thru it. s gateway and primary DNS. igned to external network card, the one nated on it. It is your public IP,

you don't have DMZ / Perimeter Area s which doesn't clash with any of

me time and will inform you when

p Utility\" to confirm that both your e you are sure both the cards are to the \"Network Configuration\"

licies, define groups and users.

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited


INTRODUCTION Nebero Soft UTM

What is Nebero? Nebero is a Soft UTM. A UTM is an acronym to Unified Threat Management system. It is a single piece of defense against the unreliable Internet. It is a gateway level product that provides all the services expected out of a gateway product like Internet Firewall, Web proxy, Pop proxy, VPN, IPS/IDS, and so on. How to manage Nebero?

Nebero is a linux based distribution. It has two consoles for administration. NEBERO MANAGEMENT CONSOLE is a full-featured web based control, that allows administrators to manage and monitor it remotely. COMMAND LINE CONSOLE , which allows to configure the network settings on the nebero server.

What are the requirements for Nebero Management? Nebero management is platform independent. You can mange it from any Windows, Mac, Linux system. It just requires Mozilla Firefox for management. How to access Nebero Management Console ? Open Mozilla Firefox and enter the following url http://<nebero-local-ip>/nebero or https://<nebero-local-ip>/nebero

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

nagement system. It is a single vel product that provides all the Web proxy, Pop proxy, VPN,

d control, that allows the network settings on the nebero

rom any Windows, Mac, Linux

Nebero
Adding intelligence to your network

NEBERO LOGIN Open Nebero console in Mozilla Firefox (Web Browser), by entering the IP address of Nebero followed by /nebero in the address bar of the Browser e.g. 192.168.10.1/nebero ? Enter username and password for login in to nebero admin console. Default username is admin and password is admin123

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

ng the IP address of Nebero 92.168.10.1/nebero admin console. Default username

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

Once correct user name and password have been provided, summary page, as shown below will be displayed.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

mary page, as shown below will

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

NEBERO CONCEPT

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

10

Nebero
Adding intelligence to your network

Bandwidth settings : The Configuration starts with the bandwidth settings. Bandwidth settings includes setting up of assured and maximum bandwidth parameters as given by the ISP for your internet connection. Like for 2Mbps 1:1 leased line, the assured and maximum bandwidth is 2048Kbps.

For bandwidth settings in Nebero, following steps have to be taken Click Bandwidth, on the Menu provided on the left side of the screen. Here, will be shown, ? Click Setting . The following screen will be displayed:
?

Setup Incoming and Outgoing bandwidth settings for WAN1 that is the first ISP. Nebero enterprise has multiple ISP support for load sharing and automatic fail over. Extra Parameter Burst is for some ISP that supports bursts. Change only if you know about the burst parameters The QoS Bandwidth shaping is preconfigured to a optimal configuration. If you want to change any values, change and after that click on Save to save the settings.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

ettings includes setting up of for your internet connection. dth is 2048Kbps.

on the left side of the screen. Here, two options

s the first ISP. utomatic fail over.

ge only if you know about the

ration. If you want to change any

11

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

BANDWIDTH POOLS Bandwidth Pool : Next step is to create bandwidth pools. Bandwidth pools are the lowest level division of the total internet bandwidth, like dividing bandwidth among different departments. The bandwidth division has a tree structure, where each branch is a pool, which can further be divided into pools. Now click on B_Tree. It will show the ROOT bandwidth pool, Click on the Plus (+). It will show a form for creating new pool. Set the incoming and outgoing bandwidth values. This will create the bandwidth pool.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

andwidth, like dividing bandwidth tructure, where each branch is a

on the Plus (+). going bandwidth values.

12

Nebero
Adding intelligence to your network

POLICIES After setting up the bandwidth settings, now its time to setup the main action part of this system that is the POLICIES 0 What is a policy in Nebero? A policy is a collection of rule sets that define various kind of accesses, that a user will enjoy, to which this policy will apply. It consists of three components 1. BASIC FIREWALL 2. WEB PROXY 3. POP PROXY BASIC FIREWALL: Firewall is a kind of barrier between the external network and internal LAN. For security reasons, it has a restrictive default policy. It means that by default every port is blocked. To access any internet service like Web access, SMTP, POP, etc., we have to open that ports in the basic firewall. WEB PROXY: Web proxy provides web-filtering functions like blocking of sites, content-filtering functions like blocking binary, audio, video, etc , files, being downloaded through web. POP PROXY: Provides the scanning of mails for spams and viruses that are being accessed through an email (pop3) client like Microsoft Outlook, Mozilla Thunderbird, etc.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

main action part of this system

sses, that a user will enjoy, to

nal network and internal LAN. For y default every port is blocked. To e have to open that ports in the

cking of sites, content-filtering oaded through web.

es that are being accessed nderbird, etc.

13

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

CREATING POLICIES The various options provided in Policy>Add are Name of the Policy, Comment for the Policy. The check-boxes are provided for enabling/disabling Basic Firewall, Proxy or Pop Proxy.

Selecting Basic Firewall enables the firewall for this policy. Disabling Firewall will leave the system vulnerable to external attacks. Just check the options in Basic Firewall which you want to give access to the users. The Basic Firewall has three sub-parts, Basic Application (to enable/disable HTTP, HTTPS, SMTP, POP3, POP3S, FTP, SSH/SCP, TELNET, IMAP, IMAPS, LDAP, LDAPS options), Customized Application (to enable/disable ports being opened by the administrator using Policies > Configure ssht, ssho, plesk, yahoo, rdesktop, e.g.- sshf, dictionary options) and Chat (to enable/disable Gtalk/Jabber, MSN, Yahoo, AIM, mirc, ICQ, skype chat softwares). Selecting Proxy option makes logs of the users and restrict the checked sites. Disabling Proxy deactivates all sort of site restrictions and logs/reports will not be

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

he Policy, Comment for the Policy. ll, Proxy or Pop Proxy.

policy. Disabling Firewall will check the options in Basic

SMTP, POP3, POP3S, FTP,

g opened by the administrator sk, yahoo, rdesktop,

AIM, mirc, ICQ, skype chat

restrict the checked sites. s and logs/reports will not be

14

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited


available for members of this policy. Block Site too is divided into three parts, SiteCategory (this includes blocking many categories of sites like Ads, Social networking, Porn, Banking etc.), Block download of File Type (this includes blocking download of different kinds of files, like Word documents, Binary files, pdf files, Excel documents, Flash files, Archive files, Audio files, Images, Text files, Video files, Presentation files and Streaming) and Block Upload of all Files via web. Selecting Pop Proxy option, scans all the incoming mails for virus and spam, accessed by the user through an Email Client like Outlook/Thunderbird etc, through a pop server.

MODIFYING POLICIES

On the Main Menu, click Policy. Click Modify, and you will be redirected to a window, asking to Select a policy. The following screen will be shown:

It modifies the policies which have been made earlier. To MODIFY a policy select appropriate policy from the Dropdown list and click Show.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

divided into three parts, Sitesites like Ads, Social File Type (this includes blocking ents, Binary files, pdf files, s, Images, Text files, Video load of all Files via web. mails for virus and spam, utlook/Thunderbird etc, through

be redirected to a window, asking to

Y a policy select

15

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

It opens up a window displaying all the items, with selections according to earlier configuration of the policy. For example the following screen shows a policy named bloc created earlier by the administrator, comes up.

Changes can be made to the policy, by enabling/disabling the appropriate items and clicking Modify.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

lections according to earlier screen shows a policy named block ,

ropriate items and clicking

16

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

DELETING A POLICY
?

On the Main Menu, click Policy. Click Delete, and you will be redirected to a window, ask to Delete a policy. The following screen shows up:

This screen shows, all the created policies. To delete a policy, select the appropriate policy, earlier made in the firewall. Select the policy and type the following phrase in the box below: I understand this will irrevocably remove all the policies that have been checked (Note:The policy will only be deleted if you type the following phrase in the box below.)

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

u will be redirected to a window, asking

ect the appropriate policy, earlier e in the box below: been checked phrase in the box below.)

17

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

CONFIGURE (HOW TO OPEN A NEW PORT IN NEBERO ?)

On the Main Menu, click Policy. Click Configure, and a user is redirected to a window, asking to Configure a policy. The following screen shows up:

The screen asks for Adding extra services with their Port Numbers and shows services those are already added. To Add Extra service, enter Service Name and Port in the respective input boxes and click Add.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

irected to a window, asking to

s and shows services those are

ive input boxes and click Add.

18

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

Advanced firewall : On the Main Menu, click Policy. Click Advance Firewall, and a user is redirected to a window, asking to select a policy. After selecting appropriate policy, click Show. The following screen shows up (here block policy is selected as an example):

A Custom Rule can be added to a specified Policy. Here we can DROP, ACCEPT or REJECT the specified IP for making connection with a specified port using a specified Protocol.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

r is redirected to a window, how. The following screen shows

aking connection with a

19

Nebero
Adding intelligence to your network

GROUPS

In Nebero a group is a kind of container of users. It has two main attributes. Every group is attached to a bandwidth pool. Every group has a default nebero policy that will in turn affects the user bein that group. CREATE A GROUP

Click Group , on the Main Menu provided on the left side of the screen. Here, five option shown. The various options defined in Group are Add, Modify, Delete, Time Policy and IP Restriction. The various options are described below: Clicking Group>Add shows the following screen:

For Adding a new group, enter the Group Name, Group Color (different groups can be given different colors), Group Comment,

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

that will in turn affects the user being member of

side of the screen. Here, five options are ete, Time Policy and IP

ps can be given different colors),

20

Nebero
Adding intelligence to your network

Max Online User(maximum number of online users that can log Expiry Date(expiry date for a group), Group Type(select a group type, the various group types are S Group, using IP address to access the Internet, Web based Gr Authentication to access the Internet and Active Directory Use being used as nebero users.), Default Policy(select a policy defined earlier). Then, we have option to Select a Bandwidth Pool, where per user Bandwidth Allocation defined by you in the B_TREE can be done.

MODIFY A GROUP

Clicking Group >Modify shows a screen where a group is to be selected from the drop Click Go. The following screen shows up(HERE as an example, office group has been selected ) :

Here, required modifications can be made to the group.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

m number of online users that can login at a time),

type, the various group types are System based access the Internet, Web based Group, requiring e Internet and Active Directory Users being uses

cy defined earlier).

where per user Bandwidth Allocation from Pool REE can be done.

roup is to be selected from the dropdown and

up has been selected ) :

21

Nebero
Adding intelligence to your network

Delete a Group Clicking Group>Delete shows the following screen, asking to Delete a group:

IMPORTANT: GROUPS CAN ONLY BE DETETED IF EMPTY, LIKE POLICIES CAN ONLY BE DELETED IF IT IS NOT ATTACHED TO A GROUP. This screen shows, all the created groups. To delete a group, select the appropriate group. Select the group and type the following phrase in the box below:

I understand this will irrevocably remove all the group(s) that have been checked (Note:The group will only be deleted if you type the above phrase in the box

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

Delete a group:

KE POLICIES CAN ONLY BE

ect the appropriate group. Select

e been checked ou type the above phrase in the box..)

22

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

Time based Policies Time based policies in nebero provides a way to control the access to the users that they will enjoy at any particular instant of time. For example an administrator don't want to give social networking sites access and chatting during production hours to its users, also he doesn't want to restrict its users to enjoy that freedom during lunch hours, so he will create a default policy that restricts the user access of that sites, and create another policy that allows that access and apply that policy for that group from let's say 12:00 to 14:00 hours for weekdays. Clicking Group>Time Policy shows the following screen:

Create a time based policies as per your requirement.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

s to the users that they will enjoy 't want to give social networking o he doesn't want to restrict its a default policy that restricts the at access and apply that policy for

23

Nebero
Adding intelligence to your network

IP Restriction IP Restrictions are for addresses. Clicking Group>

web-based users IP Restriction

, to allow or restrict users to login from a range of shows the following screen:

When

Clicked to Enable show ... (next page) it will

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

strict users to login from a range of IP

lowing screen:

24

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

Add the range of IP Addresses and Click on Add to allow login access to that range, otherwise uncheck the Allow Login and click on Add to restrict users to login from this range.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

cess to that range, otherwise n from this range.

25

Nebero
Adding intelligence to your network

USERS

Click Users , on the Main Menu provided on the left side of the screen. Here, four option shown. The various options defined in Users are Add, Modify, Delete and User Firewall. The various options are described below: Creating New Users Clicking Users>Add shows the following screen:

or Adding a new user, enter the Full Name, User, Password, Group Name(to be selected dropdown), Expiry Date(expiry date for a user), IP address(only applicable for System based groups), Sex(male or female), E-mail, Phone, Address and click Create. (Note: fields marked * are compulsory.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

side of the screen. Here, four options are ete and User Firewall. The

shows the following screen:

ssword, Group Name(to be selected from applicable for System based )

26

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

Modify (to modify existing user)


Clicking Users>Modify screen opens up asking to Search a user. A search can be done, by ,a searching any of the given options. (As an example we search a user nicholas) The result shows the following screen:

Here, modifications can be made to the searched user. A Lock/Unlock option is also there, for Locking or Unlocking a user. Locked yours will no longer be able to access internet. Only when unlocked they will be able to enjoy internet access.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

user. A search can be done, by ser nicholas) The result shows

nlock option is also there, for

unlocked they will be able to

27

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

Delete (to delete a user)


Clicking Users>Deletea screen opens up asking to Search a user. A search can be done, by , searching any of the given options, to delete a user. (As an example we search a user nicholas) The result shows the following screen:

This screen shows, the searched user(s). To delete a user, select the appropriate user(s) and type the following phrase in the box below: I understand this will irrevocably remove all the user(s) that have been checked and click Delete. (Note: The group will only be deleted if you type the following phrase in the box below.)

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

user. A search can be done, by ple we search a user nicholas)

the appropriate user(s) and type

been checked and click Delete.

g phrase in the box below.)

28

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

User Firewall (to add customized Firewall Rule

Clicking Users>User Firewall, a screen opens up asking to Selecting a Policy. (As an example w search a group office and a user nicholas) The result shows the following screen:

Here, customized Firewall rule can be added to be applied on a particular user. User Firewall is used to deny or give some specific access to the specified user in a specified group.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

electing a Policy. (As an example we e following screen:

articular user. User Firewall is a specified group.

29

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

SURF POLICY
Although Nebero Policy has a comprehensive categories of sites that can be blocked, but at times you want to allow or block access to a particular site or url. Such settings can be done under Surf Policy. ALLOW SITE Clicking Surf Policy > Allow site , shows a screen as shown below Select the policy to which you want to allow the site access, Add the site you want to allow and click on the Allow Tab.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

hat can be blocked, but at times ettings can be done under Surf

he site you want to allow and

30

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

BLOCK SITE As a site is allowed in the previous section, similarly a site can be blocked

Clicking Surf Policy > Block site , shows a screen as shown below Select the policy to which you want to block the site access, Add the site you want to block and click on the Block Tab.

Allow URL As a site is allowed, in same manner a url can be allowed for a particular policy. Clicking Surf Policy > Allow URL, shows a screen as shown below Select the policy to which you want to allow the url access, Add the url you want to allow and click on the Allow Tab.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

he site you want to block and

rticular policy.

e url you want to allow and click

31

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

BLOCK URL As a url is allowed in the previous section, similarly a url can be blocked Clicking Surf Policy > Block URL, shows a screen as shown below Select the policy to which you want to block the url access, Add the url you want to block and click on the Block Tab

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

e url you want to block and click

32

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

BLOCK WORD Words can be blocked that when appear in the URL portion or query portion of a web request. Click on Surf Policy > Block Wordand it will show a screen, where you can select a policy and it will show the words already blocked. You can select search criterion, that is where to search the word URL or Query string You can also select among five options that allows what kind of search pattern you want. Anywhere (default) Anywhere in the line. Word Start Word End Complete Word Select the appropriate options and enter the word to be blocked and click on Block.

REQUESTED URLS If you have checked the ALLOW FEEDBACK in the Nebero Policies and a user gets a message like shown below on accessing a blocked site

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

ery portion of a web request. where you can select a policy and it

earch pattern you want.

nd click on Block.

es and a user gets a message

33

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

the user can request for that url access, stating the reason why he/she want that access. Such requests can be seen by the administrator under Surf Policy > Requested Url. Here administrators can allow access to such urls.

You can allow access to that particular URL only or you can allow access to the complete site.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

e/she want that access. Surf Policy > Requested Url.

access to the complete site.

34

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

No Cache Sites You can add here the sites for which you want no caching in the web proxy. Click Surf Policy > No Cache Sites, no cache site in the space provided and then click on add the the Add Tab.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

e space provided and then click on

35

Nebero
Adding intelligence to your network

SERVICES
Click on Services , it will show two services 1. DHCP 2. AntiSpam DHCP The Dynamic Host Configuration Protocol server can be configured using this section. Configure the global DHCP settings like Network, Subnet Mask, DNS, Gateway Default and Maximum Lease time for the hosts. Click on Save to save the settings.

ow you can add a range or a static IP that binds to a MAC Address.

ANTI SPAM Antispam can be configured in this section. You can enable or disable spam checking by checking/unchecking the checkbox and clicking on Save. You can setup Required Hits that is the value used by anti-spam for comparing the mail spam score with it. If the score is above the Required Hits, it will be marked as spam. You can increase it if you are getting lots of spams. You can select whether to Skip RBL checks that is the remote blacklist checks done by the antispam server.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

d using this section. DNS, Gateway Default and

MAC Address.

Spam Check Enabled

or comparing the mail spam ked as spam.

cklist checks done by the

36

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

You can also create blacklist and whitelist that will be used by the antispam to base its decision whether mails coming from a particular email id or domain is a spam or not. For example, you can add @rediffmail.com to blacklist to mark all mails coming from the rediffmail.com domain to be treated as spam. Similarly whitelists can be created.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

antispam to base its decision

ll mails coming from the

37

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

NEBERO CONFIG
This section can be used to configure the nebero system NETCONFIG Netconfig shows the network configurations of the nebero firewall. It has an Advanced Utilities Link that can be used for advanced uses like bulk user creation, restoring backup, etc.

MONITOR Monitor is a control panel for starting and stopping different services. Although every service is started when it is configured, yet you can enable/disable services at your own will.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

ses like bulk user creation,

es. Although every e services at your own

38

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

BRANDING In this section you can customize the look and feel of Nebero. You can set Login Screen Text, that is displayed when web-based users login into Neber You can set Error Screen Text that will be displayed when a user access a blocked site. You can also set Login Popup Window text, Site to be opened on login, Image to be displayed at login Page for Web-based Users.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

en web-based users login into Nebero. when a user access a blocked site. be opened on login, Image to be

39

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

DISK USAGE It shows the hard disk usage of the Nebero system, partition wise.

BACKUP You can setup a ftp server for taking backup of nebero. This backup of Nebero settings can be scheduled or can be taken manually. Setup the required fields and setup the time frequency when to take the backup.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

up of Nebero settings can be d setup the time frequency when

40

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

RECYCLE The proxy caches can be recycled by clicking on Now. You can setup the recycle rate for different reports like user web access report, IPS/IDS report, etc.

SHUTDOWN / REBOOT You can shutdown or reboot the nebero machine from this section. Just complete the phrase to confirm \"I understand I am going to shutdown/reboot the server\"

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

etup the recycle rate for different

n. Just complete the phrase to

41

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

NEBERO REPORTS Nebero UTM provides comprehensive reporting of the user's web activity. You can search for the user's websites access report for a particular duration. 1. For accessing the reports of the User Web Access, click on User Web Access link Reports. You can select the From Date and To date, the user name, group name and total number of records to be shown on the page and click on Search. Also you can directly click on Search without selecting any option.

This will give you user listing as the result. You can order users list by different columns, like for ordering users in the descending order of Bytes Download, just click on the Bytes Downloaded Title .

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

activity. You can search for the

under the ser name, group name and total Also you can directly click on

rs in the descending order of

42

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

This will display the users list starting from the user, who has downloaded maximum bytes till now For details of this usage just click on the username. Now, you get the list of websites being accessed by the user.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

nloaded maximum bytes till now the list of websites being

43

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

You can again arrange these sites according to the size of the sites being accessed, by clicking on the Bytes Download above. Title

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

es being accessed, by clicking on

44

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

For further information, you can click on the site to look at the urls being accessed of these websites. Just click on any site, it will display the url listing.

You can block these sites right from here by click on the checkbox and then click on block button.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

being accessed of these

x and then click on block button.

45

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

2. Similarly you can view the reports of Web sites User, that is which site has been accessed which users. For example to view which users have accessed the datastore.rediff.com site just click on this site.

This will list you all the users who have accessed this site with the listing of how much data has been downloaded and how many hits to this site has been done by this user.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

hat is which site has been accessed by datastore.rediff.com site just

listing of how much data has

46

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

3. Again you can view the Web Sites Url, is which urls of a site has been accessed by which that users and at what time. Just click on any site to view the listing of urls and users.

This will give you the required listing of URLs, user, ip, bytes and access time

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

as been accessed by which urls and users.

access time

47

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

4 Blocked User Web Access the users access reports can be viewed as described above As similarly you can view who has accessed the content that has been blocked as per the policy settings in Nebero. They are just anologous to the above reports, only the difference is that now the content is not accessed, but being blocked by Nebero.

Click on Blocked User Web Access. will list the users with the top ten sites as Graph. Also This you can view the graph of categories under which this content has been blocked.

Just click on the site graph icon before the user name. This will list the graph as shown on the next page.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

s can be viewed as described above, n blocked as per the policy

s that now the content is not

the top ten sites as Graph. Also s been blocked.

t the graph as shown on the next

48

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

If you click on the username, you will get the listing of the sites and access time. If you further click on sites , it will list the urls and again if you click any url, then it will show that url's content.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

d access time. If you further click l show that url's content.

49

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

50

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

Also you can look at the blocked content category graph, which will show you the categories under which the blocked content falls.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

will show you the categories under

51

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

5. Similarly you can view the blocked Web Site User

reports,

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

52

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

6. And the blocked

Web Site URL reports.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

53

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

7. You can view the reports of the content type that has been accessed through web by clicking on Content Type 0

8. You can view the Bandwidth System reports.

usage reports as daily, weekly, monthly and yearly

For example, to view the daily reports of System Bandwidth usage, just select the date by clicking on the calander icon, it will show you the popup calender, select date there. After that click on Show button, this will show the graph with red color as Incoming and blue as Outgoing Bandwidth usage.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

essed through web by clicking on

ekly, monthly and yearly

h usage, just select the date by select date there. After that click g and blue as Outgoing

54

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

9. Similarly, you can view the bandwidth usage report for individual users character of the username, it will show you the drop down list of users, select the user and then again the same options, that are there in the System Bandwidth, you will get the required graphs.

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

by writing the first sers, select the user and then you will get the required graphs.

55

Nebero
Adding intelligence to your network

Nebero Systems Pvt. Limited

10 Connection Nebero is a state machine, which means that you can view each and every Logs connection that is being made from your network to the outside world. You can see all the ports to which connections have been made and to what destination Ips with the amount of data that flows between the source and the destination IP's.

By using these reports, you can analyse the condition of your Network and can take appropriate steps to make the Network better and Secure by implementing various Nebero policies.

End of Nebero Guide 21.33.8 Nebero Help Desk : Email : Phone : Yahoo Messenger ID: Gtalk ID :

help@nebero.com +91-172-4318888 cyberix_helpdesk nebero.help

Nebero Guide . 21.33.8

Nebero Systems Pvt. Limited


http://www.nebero.com

s that you can view each and every orld. You can see all the ports to ith the amount of data that flows

work and can take appropriate rious Nebero policies.

56

Anda mungkin juga menyukai