StatWatch Internet Router Configuration

Document Number: SW0332-0314

Last Updated: 02/01/18

Introduction

Product: SiteWatch StatWatch (.SW10950), TunnelWatch StatWatch (.TW90950)

This topic applies to sites using SiteWatch with or without TunnelWatch. It describes how to configure Internet routers to allow the Internet access required by StatWatch.

If the site bought its router from DRB in 2012 or later, the router may already have the configuration needed to use StatWatch. Use this document to verify and modify the configuration if needed.

Third-Party Router Configuration

1.    Because every router is different and may be configured differently, DRB cannot provide detailed configuration steps for third-party routers. However, this section should give a network specialist the information needed to configure your router.
2.    Configure the router to allow Web access to statwatch.com.

a.    The router should be configured to allow statwatch.com access over both HTTP (TCP port 80) and HTTPS (TCP port 443).

b.    If the content filtering service only scans HTTP traffic, be sure to allow access to statwatch.com over HTTPS in other places in the router configuration.

3.    Configure the router to allow StatWatch Data Collector access to statwatch.com over TCP port 9000.

SonicWALL TZ Series Router Configuration

1.    Open Internet Explorer.
2.    In the address bar, type 192.168.100.1 and press Enter. A SonicWALL Network Security Login screen appears. Note: If a certificate error appears, click Continue to this website (not recommended).
3.    In the Username field, type swadmin.
4.    In the Password field, enter the site-specific password. The password is recorded in Clientele under SiteWatch Profile>VPN Info>Router Password.
5.    Click Login. A SonicWALL Status screen appears.
6.    Allow the StatWatch Data Collector through the firewall.

a.    Click Firewall. The Firewall sub-menus are displayed.

b.    Click Access Rules. The Access Rules screen appears.

c.    Next to View Style, click All Rules. All access rules are displayed.

d.    Scroll down and search for a  LAN>WAN rule with a Service of StatWatch Data Collector. Click the pencil icon under the Configure column to edit the rule if it exists. An Edit Rule window appears.

e.    If a rule with a Service of StatWatch Data Collector does not exist, click Add. An Add Rule window appears.

f.      Configure the fields as follows:

i.      Action: Allow

ii.     From Zone: LAN

iii.   To Zone: WAN

iv.   Service: Select Create new service and configure the fields in the Add Service window as follows:

·       Name: StatWatch Data Collector

·       Protocol: TCP

·       Port Range: 9000

·       Click OK. A Please wait... message appears in the status bar at the bottom of the window, and then the window closes.

v.    Source: Any (If this field is set to SiteWatch Server or All SiteWatch Servers, change it to Any to allow the TunnelWatch Data Collector to upload information.)

vi.   Destination: Select Create new network and configure the fields in the Address Object dialog as follows:

·       Name: statwatch.com

·       Zone Assignment: WAN

·       Type: FQDN

·       FQDN: *.statwatch.com

·       Click OK. A Please Wait... message appears in the status bar at the bottom of the window, and then the window closes.

vii.  Users Allowed: All

viii.  Schedule: Always on

ix.   Comment: SW: required for StatWatch

x.    Enable Logging: Verify this option is not selected.

xi.   Allow Fragmented Packets: Leave this option selected.

g.    Configuring the Bandwidth Management for Firewall Rule.

i.      SonicWALL firmware versions after 5.9.1.0.

·       Click the BWM tab. The contents of the Bandwidth Management tab are displayed.

·       Select Enable Outbound Bandwidth Management.

·       For the Bandwidth Object, select Create new Bandwidth Object. The Add Bandwidth Object box opens.

·       Configure the following fields:

o     Name: Default StatWatch Priority 1

o     Guaranteed Bandwidth: 0 kbps

o     Maximum Bandwidth: 100000 kbps

o     Traffic Priority: 1 Highest

o     Violation Action: Delay

o     Comment: StatWatch Bandwidth

·       Click OK. The Add Bandwidth Object box closes and adds the Bandwidth object.

·       Select Enable Inbound Bandwidth Management and for the Bandwidth Object select the Bandwidth Object created in the previous step.

·       Click OK. The Edit Rule box closes.

ii.     SonicWALL firmware versions before 5.9.1.0.

·       Click the Ethernet BWM tab. The contents of the Ethernet Bandwidth Management tab are displayed.

·       Select Enable Outbound Bandwidth Management and Enable Inbound Bandwidth Management.

·       Set both Guaranteed Bandwidth fields to 0.

·       Set both Maximum Bandwidth fields to 100.

·       Set both Bandwidth Priority fields to 1.

h.    Click Add or OK. A Please wait... message appears in the status bar at the bottom of the window and then a Rule action done, please check rule table message appears.

i.      Click Close. The Add Rule window closes.

7.    Allow access to StatWatch via HTTP/HTTPS through the firewall.

a.    Attention: In older default configurations, these steps were only used to allow HTTPS access. Older configurations have a group of Allowed HTTPS Hosts instead of Allowed Web Hosts. In newer default configurations, these steps are used to allow both HTTP and HTTPS access.

b.    Click Network. The Network sub-menus are displayed.

c.    Click Address Objects. The Address Objects screen appears.

d.    Under Address Groups, find the row of the object named Allowed Web Hosts.

e.    Click the pencil icon to edit in the row for that group under the Configure column. An Edit Address Object Group window appears.

f.      In the list to the left, find and select statwatch.com.

g.    Click the arrow button to add it to the list to the right.

h.    Click OK. A Please wait... message appears in the status bar at the bottom of the window, and then the window closes.

8.    Allow StatWatch access via HTTP through content filtering.

a.    Attention: These steps only apply to older default configurations shipped before December 2010. In newer configurations, the Allowed Domains list is empty. Use step 7 above to configure HTTP on newer default configurations.

b.    Click Security Services. The Security Services sub-menus are displayed.

c.    Click Content Filtering. The Content Filtering screen appears.

d.    Click Configure. A SonicWALL Filter Properties window appears.

e.    Click Custom List. The contents of the Custom List tab are displayed.

f.      Under Allowed Domains, click Add. An Add Allowed Domain Entry window appears.

g.    Type statwatch.com and click OK. The Add Allowed Domain Entry window closes.

h.    Click OK. The SonicWALL Filter Properties window closes and the Allowed Domains list is saved.

SG560 Router Configuration

1.    Open Internet Explorer.
2.    Enter the IP address for the Internet router (usually 192.168.100.1). The CyberGuard Management Console screen opens.
3.    Under the FIREWALL heading, click Access Control. A login screen appears.
4.    Enter the router user name and password. Note: If the site does not know the user name and password, a DRB Support staff member can look it up in Clientele under the customer's VPN Info tab.
5.    Click the IP Lists tab. An IP access lists screen appears.
6.    Type statwatch.com into the Destination Host/ Allow List box.
7.    Click Apply to save changes.
8.    Click the Web Lists tab. A WWW access lists screen appears.
9.    Type statwatch.com into the Allow List box.
10.  Click Apply to save changes.

SnapGear SOHO+ and SME530

1.    Open Internet Explorer.
2.    Enter the IP address for the Internet router (usually 192.168.100.1). The SnapGear Management Console screen opens.
3.    Click Content Filtering. A login screen appears.
4.    Enter the router user name and password. Note: If the site does not know the user name and password, a DRB Support staff member can look it up in Clientele under the customer's VPN Info tab.
5.    On the Content Filtering screen, add statwatch.com to the Allow List.
6.    Click Apply to save the Allow List.

Related Topics

Bigger Picture

Installing StatWatch