Step-by-Step Guide to Installing Ruijie Firewall
In this guide, we will explain the basic installation steps of the Ruijie RG-WALL 1600 Z3200-S Next Generation Firewall device in a simple and understandable way.
1.n this guide, we will explain the basic installation steps of the Ruijie RG-WALL 1600 Z3200-S Next Generation Firewall device in a simple and understandabIn this guide, we will explain the basic installation steps of the Ruijie n this guide, we wn this guide, we will explain the basic installation steps of the Ruiguide, we will explain the basic installation steps of the Ruijie RG-WALL 1600 Z3200-S Next Generation Firewall device in a simple and understandable way.
1. First Access to the Device
Before starting the installation, you must connect your computer to the MGMT (management) port of the firewall device (GE 0/0).
Default Login Information:
IP Address: 192.168.1.200
User Name: admin
Password: firewall
You can log in to the interface by accessing this IP via the browser.
 Don't forget to update your password as a first step. After setting a new password, click on the “Confirm” button.
2. Local Area Network (LAN) Configuration
2. Local Area Network (LAN) Configuration
A. Bridge Interface Settings
1-
2. Local Area Network (LAN) Configuration
A. Bridge Interface
2. Local Area Network (LAN) Configuration
A. Bridge Interface Settings
1- From the left menu, go to Network > Bridge Interface tab.
2- Click the Edit button opposite the br0 interfa
2. Local Area Network (LAN) Configuration
A. Brid
2. Local Area Network (LAN) Configuration
A. Bridge Interface Settings
1- From the left menu, go to Network > Bridge Interface tab.
2- Click the Edit button opposite the br0 interface defined by default.
3- To remove the ports on this interface from bridge mode, remove all the ports in the Member Interface list and press the Save Button. Being in Bridge mode means that it remains in the Group structure. In this case, all ports will work in the same switching mode.
B. Creating a New LAN Interface
1- Switch to the Aggregate Interface tab and click the Create button.
2- Specify the interface name as “LocalLAN”, for example.
- Specify the interface name as “LocalLAN”, for example.
3- Create a new security zone by clicking the “Add Security Zone” button. The areas we Specify the interface name as “LocalLAN”, for example.
3- Create a new security zone by clicking the “Add Security Zone” button. The areas we define as Zones here will be useful for us when creating rules later on.
4- Select LAN Interface as the “Interface Type” and define the ports to be used. Here, the Interface Type determines the purpose of the port to be used.
5- Enter the IP address and subnet information. In the Access Management section, we specify the access methods from the relevant IP address. If we do not want access to be provided via the relevant IP or the interface we have created here, we need to remove the permissionsr the IP address and subnet i- Enter the IP address and subnet information. In the Access Management section, we specify the access methods from the relevant IP address. If we do not want access to be provided via the relevant IP or the interface we have created here, we need to remove the permissions.
3. Defining the WAN Interface
1- From the Physical Interface tab, for example, click the Edit button opposite the “Ge0/1” port.
2- To add a new Zone, use the Add Security Zone option. (By default, Zone options are Trust, Untrust and DMZ.)Generally, Untrust can be chosen as the Internet leg- To add a new Zone, use the Add Security Zone opo add a new Zone, use the Add Security Zone option. (By default, Zone options are , Untrust and DMZ.). Generally, Untrust can be chosen as the Internet leg. As an option, you caadd a new Zone, use the Add Security Zone option. (By default, Zone options are Trust, Untrust and DMZ.). Generally, Untrust can be chosen as the Internet leg. As an option, you can create a new zone yourself.
3- Configure according to your connection type: In our example, we will define the Metro Line. We define our Static IP address, Netmask and Gateway (Next-Hop Address) given by the ISP.
* For static IP: Enter the ”IP/Mask“ and ”Next-Hop Address" (gateway) information.
* For PPPoE: Enter the username and password information you received from your service provider.* For PPPoE: Enter the username and password information you received from your service provider.
When all the information is entered correctly, you *  For PPPoE: Enter the username and password information you received from your service provider.
PPPoE: Enter the username and password information you received from your service provider.
When all the information is entered cor For PPPoE: Enter the username and password information you received from your service provider.
When all the information is entered correctly, you can configure your WAN interface by pressing the Save button.
4. Creation of Security and NAT Policies
A. Defining a Security Policy
1-Enter the Policy > Security Policy field and click the Create button.
2- Thanks to the Simulation Space feature offered by Ruijie, we can test the rule we created before transferring it to the live environment. Since we are going to process for internet access directly, we click on the Create button directly.
3- After determining a Policy Name (rule name), we select ‘Default Policy Group’ from the Policy Group section. After determining a Policy Name (rule name), we select ‘Default Policy Group’ from tfter determining a Policy Name (rule name), we select ‘Default Policy Group’ from the Policy Group section.
4er determining a Policy Name (rule name), we select ‘Default Policy Group’ from the Policy Group section.
4-r determining a Policy Name (rule name), we select ‘Default Policy Group’ from the Policy Group section.
4- Src. As a Security Zone, we select our “LAN” line and click on the Confirm button.
5- We need to define the address in the ‘Src. Address’ section. To add an address, we click on the ‘Add Address’ option.
6- By giving a name to our address, we enter and save the Subnet information of our Local Network in the field below.
7- Src. We select the LOCALLAN we created as the address and press the Confirm button.
8- We select our WAN line in the Dest. Security Zone field and click the Confirm button We select our WAN line in the Dest. Security Zone field and cli8- We select our WAN line in the Dest. Security Zone field and click the Confirm button.
9- Dest. As the address, we select the ‘any’ option and continue.
10- If you leave the Service and App part blank, the system w- We select our WAN line in the Dest. Security Zone field and click the Confirm button.
9- Dest. As the address, we select the ‘any’ option and continue.
10- If you leave the Service and App part blank, the system will automatically assign 'any'. If you want, you can also activate features such as IPS, Virus Protection and URL Filter. Finally, we click the Save button and save the rule.
B. Defining a NAT Policy
1- We will create a NAT Policy at this stage. We come to NAT from the ’NAT Policy' section and click on the Create button.
2- We set a name, then move to the Packet Before NAT field below.- We set a name, then move to the Packet B- We set a name, then move to the Packet Before NAT field below.
3- Src. We- We set a name, then move to the Packet Before NAT field below.
We set a name, then move to the Pa2- We set a name, then move to the Packet Before NAT field bel- We set a name, then move to the Packet Before NAT field below.
3- Src. We choose LAN as the Security Zone.
4- We select the LOCALLAN that we created in the previous rule as the Source Address.
5- Dest. As a Security Zone, we select our WAN line and move forward.
6- We select any as the Dest. Address.
7- As a service, we select ‘any’ and press the Confirm button.
8- In the Packet After NAT field, select ‘Outbound Interface Address' and press the Save button.
9- If you are going to manage the DHCP Server via the Firewall, we enter the DHCP Server field in the Network > DHCP section and click the Create button.- If you are going to manage the DHCP Server via the Firewall, we enter the DHCP Server field in the Network > DHCP section and click If you are going to manage the DHCP Server via the Firewall, we enter the DHCP Server field in the Network > DHCP section and click the Create button.
10- We create a DHCP Server by entering your Local LAN information and DHCP December in the field below and pressing the Save button.
11- Basically, if we make these settings, the devices on the Local network will receive IP via DHCP and internet access will be provided. Finally, let's do our test.
In this guide, we have shared with you how to install the Ruijie Z3200-S Firewall step by step, all the basic settings and the configurations required for internet output. See you in the next guide!


 
                            
 WhatsApp
 WhatsApp