Jump to:navigation, search
Wiki





























Achtung: In der .lang-Datei werden je nach Parameter hw Varaiblen gesetzt für die Bezeichnung der Schnittstellen und ob dmz / dmz interface und wlan vorhanden sind




De.png
En.png
Fr.png









Set up Internet access of a UTM and import cloud backup

Last adaptation to the version: 14.0.1 (01.2025)

New:
notempty
This article refers to a Resellerpreview
Access: UTM-IP:Port or UTM-URL:Port
Port as configured at Network / Appliance Settings / Webserver
Default-Port: 11115
i.e.: https://utm.ttt-point.de:11115
Default: https://192.168.175.1:11115
Configuration  Area Installation wizard

Prefaces

  • Usually, the installation wizard appears during the initial setup of the UTM.
    This checks whether a configuration already exists that is marked as the boot configuration.

(Status )
If this is not the case, the wizard opens automatically.

  • It is not advisable to start the installation wizard later, as other settings made in the meantime may be overwritten.


Installation wizard

Step 1 - General

Caption Value Description Installation wizard UTMuser@firewall.name.fqdnConfiguration management UTM v14.0.1 Installationsassistent Schritt 1-en.pngStep 1
Firewall Name: firewall.ttt-point.local Any value
Any value can be entered here for a restore.
As soon as a configuration from the cloud backup has been activated, those settings will be applied.
Global contact person: Alina Admin Any value
Any value can be entered here for a restore.
As soon as a configuration from the cloud backup has been activated, those settings will be applied.
Global email address: admin@ttt-point.de Any value
Any value can be entered here for a restore.
As soon as a configuration from the cloud backup has been activated, those settings will be applied.
Language of reports: German
English
Leave default setting
For a restore the default setting can be left.
As soon as a configuration from the cloud backup has been activated, those settings will be applied.

Step 2 - Privacy

Anonymize all applications Yes Leave default setting
For a restore the default setting can be left.
As soon as a configuration from the cloud backup has been activated, those settings will be applied.
UTM v14.0.1 Installationsassistent Schritt 2-en.png
Step 2

Step 3 - Internal

Without WLAN module
Without WLAN module
Internal firewall IP address: 192.168.175.1/24
  • During a restore, the default address should be left as it is.
    This means that after setting up Internet access and the necessary reboot, the firewall is still accessible to the device from which the current configuration is being carried out in order to subsequently activate the cloud configuration.
  • UTM v14.0.1 Installationsassistent Schritt 3a-en.png
    Step 3 - without WLAN module
    Dynamically assign Client IP Addresses via DHCP: No Leave default setting
    For a restore the default setting can be left.
    As soon as a configuration from the cloud backup has been activated, those settings will be applied.
    Router Advertisement: Off If the UTM has received an IPv6 prefix, it can advertise the subnet via router advertisement in the network segment behind the interface. (See article IPv6 Prefix Delegation)
    With WLAN module
    With WLAN module
    Internal firewall IP address: 192.168.175.1/24
  • During a restore, the default address should be left as it is.
    This means that after setting up Internet access and the necessary reboot, the firewall is still accessible to the device from which the current configuration is being carried out in order to subsequently activate the cloud configuration.
  • UTM v14.0.1 Installationsassistent Schritt 3b-en.png
    Step 3 - with WLAN module
    Dynamically assign Client IP Addresses via DHCP: No Leave default setting
    For a restore the default setting can be left.
    As soon as a configuration from the cloud backup has been activated, those settings will be applied.
    Generate WLAN Bridge: No
    Default
    Any value
    Any value can be entered here for a restore.
    As soon as a configuration from the cloud backup has been activated, those settings will be applied.
    Generate portfilter rule:
    Shown when Generate WLAN Bridge is enabled
    No When activated, a port filter rule is automatically generated
    STP:
    Shown when Generate WLAN Bridge is enabled
    Off When activated, STP (Spanning Tree Protocol) is used
    STP Bridge Priority:
    Shown when Generate WLAN Bridge is enabled
    32768Link=
    Default
    The priority of the STP Bridge is set

    Step 4 - Internet

    This is where the Internet connection is configured on the external interface (A0).
    The following variations are available:

    Connection type PPPoE / VDSL
    Connection type: PPPoE / VDSL
    With this type, an ADSL or SDSL modem is connected to the external interface (A0). The connection is initiated by the UTM.
  • A router can only be used with this connection type if it can be set to modem mode and it can be guaranteed that the UTM will initiate the connection.
  • Username: (Shares ISP) The login information is provided by the ISP (Internet Service Provider). UTM v14.0.1 Installationsassistent Schritt 4a-en.png
    Step 4 with PPPoE / VDSL
    Password: (Shares ISP)
    PPPoE for VDSL/fiber optics: Off Check the box if PPPoE is connected via a VDSL modem or via fibre.
    VLAN ID:
    Shown when PPPoE for VDSL/fiber optics is enabled
    7 Die VLAN-ID wird in der Regel vom Netzbetreiber vorgegeben
    IPv6 Prefix Delegation: Off Allows an IPv6 network assigned by the Internet Service Provider to be split into /64 networks and assigned to individual interfaces via Router Advertisement.
    Example:
    Network assigned by ISP:
     2001:0db8:aaaa:bb::/56
    Networks distributed at internal interfaces via router adviertisement:
     2001:0db8:aaaa:bb00::/64
     2001:0db8:aaaa:bb01::/64
    notempty
    Die Option DNS-Server des Providers verwenden wurde in Schritt 5 verschoben
    Connection type Ethernet with static IP
    Connection type:Ethernet with static IP
    With this connection type, a router is connected to the external interface (A0), which itself initiates the connection to the Internet. The login information of the provider is stored in the preceding router and not on the UTM.
  • This connection type cannot be used with a modem or router in modem mode.
  • External IP address: 192.168.178.101/24 The IP address of the external interface (A0) and the IP address range for the external network (subnet mask in CIDR notation). The default is an already existing IP address, if applicable.
    The external interface receives an IP address via DHCP by default, provided a DHCP server is available in the external network.
    UTM v14.0.1 Installationsassistent Schritt 4b-en.png
    Step 4 with Ethernet with static IP
    Default Gateway: 192.168.178.1/---  IP address of the default gateway for the UTM so that it knows which is the closest router for all networks that are not on an internal interface: As a rule: the Internet.
    IPv6 Prefix Delegation: Off Allows an IPv6 network assigned by the Internet Service Provider to be split into /64 networks and assigned to individual interfaces via Router Advertisement.
    Example:
    Network assigned by ISP:
     2001:0db8:aaaa:bb::/56
    Networks distributed at internal interfaces via router adviertisement:
     2001:0db8:aaaa:bb00::/64
     2001:0db8:aaaa:bb01::/64
    Connection type Cable modem with DHCP
    Connection type: Cable modem with DHCP
    e.g.: DSL connection via telephone line with Fritzbox or Speedport router.
    Originally mostly devices that cable providers provided to their customers.
    Also with this connection type, a router is connected to the external interface (A0), which itself initiates the connection to the Internet. The login information of the provider is stored in the preceding router and not on the UTM.
  • This connection type cannot be used with a modem or router in modem mode.
  • UTM v14.0.1 Installationsassistent Schritt 4c-en.png
    Schritt 4 mit Kabelmodem mit DHCP
    DHCP Client: IPv4 Selection with which protocol the interface receives IP addresses from the preceding router with DHCP server.
    IPv6
    IPv4 & IPv6
    Use the provider's DNS server: Off When activated, the provider's DNS server is used.
    IPv6 Prefix Delegation: Off Allows an IPv6 network assigned by the Internet Service Provider to be split into /64 networks and assigned to individual interfaces via Router Advertisement.
    Example:
    Network assigned by ISP:
     2001:0db8:aaaa:bb::/56
    Networks distributed at internal interfaces via router adviertisement:
     2001:0db8:aaaa:bb00::/64
     2001:0db8:aaaa:bb01::/64
    Connection type LTE / others
    Connection type: LTE / others
    LTE connections or other connections are configured after the installation wizard is completed

    Schritt 5 - DNS Forwarding

    notempty
    Neuer Schritt ab v14.0.1

    Hier kann das DNS Forwarding des Nameservers konfiguriert werden. Es gibt die gleichen Optionen wie unter Applications Nameserver  Area DNS Forwarding. Für genauere Informationen siehe den Artikel zum Nameserver.

    DNS Forwarding hinzufügen
    notempty
    Neu im Installations-Assistenten ab v14.0.1
    DNSDoT Fügt DNS Forwarding hinzu.
    Es ist möglich klassisches DNS oder DNS over TLS (DoT) auszuwählen. Weitere Informationen im Artikel zum DNS Forwarding im Nameserver.

    DNS Forwarding hinzufügen UTMuser@firewall.name.fqdn Konfiguratinsverwaltung Installation wizard UTM v14.0 Anwendungen Nameserver DNS Forwarding hinzufügen DoT.png
    UTM v14.0.1 Installationsassistent Schritt 5-en.png
    Schritt 5
    Use the provider's DNS server: On When activated, the provider's DNS server is used.

    Step 6 - DMZ

    The Black Dwarf (G5) only has 2 interfaces.
    A second (wired) internal network is thus not possible.
    The DMZ setup step is therefore skipped.

    DMZ IP address: 192.168.176.1/24 Any value
    Any value can be entered here for a restore.
    As soon as a configuration from the cloud backup has been activated, those settings will be applied.
    UTM v14.0.1 Installationsassistent Schritt 6a-en.png
    Step 6 without WLAN
    Assign the IP addresses to the clients in this network via DHCP: No Leave default setting
    For a restore the default setting can be left.
    As soon as a configuration from the cloud backup has been activated, those settings will be applied.
    Autogenerated rules: No Leave default setting
    For a restore the default setting can be left.
    As soon as a configuration from the cloud backup has been activated, those settings will be applied.
    Router Advertisement: No If the UTM has received an IPv6 prefix, it can advertise the subnet via router advertisement in the network segment behind the interface. (See article IPv6 Prefix Delegation)
    Generate WLAN Bridge:
    Only if a WLAN module is present
    No Any value
    Any value can be entered here for a restore.
    As soon as a configuration from the cloud backup has been activated, those settings will be applied.

    Step 7 - WLAN

    In the delivery configuration, a WLAN module is installed in the Black Dwarf (G5).
    if the module has been removed, this step is skipped.

  • For long-term use of WLAN (>30 days) a special license is required
  • WLAN IP address:
    Not in bridge mode
    192.168.177.1/24 The IP address of the WLAN interface (wlan0) and the subnet mask (as CIDR notation) for the WLAN network.
    In bridge mode, the setting from the internal network in which bridge mode was activated is used here.
    UTM v14.0.1 Installationsassistent Schritt 7a-en.png
    Step 7: WLAN dialog without bridge configuration

    UTM v14.0.1 Installationsassistent Schritt 7b-en.png
    Step 7: WLAN dialog when using a bridge
    Country code: DE The country code is used to determine which frequencies and which signal strengths may be used.
    The frequencies used and the transmission power can be found in a Wikipedia article.
    SSID: TTT-POINT The Service Set Identifier (SSID) is the name under which the WLAN network is presented to the clients. This must be entered in any case.
    SSID Broadcast: On This option can be used to define whether the WLAN network can be seen by every client or whether the transmission of the SSID should be suppressed. (Off)
    Security Mode: WPA Is considered unsafe and only exists for backwards compatibility. (TKIP is used as encryption method)
    WPA2 Standard with enhanced security
    AES128 is used as encryption method: https://en.wikipedia.org/wiki/WPA2
    WPA3 Standard with highest available level of security
    AES256 and SAE are used as encryption methodes: https://en.wikipedia.org/wiki/WPA3
    Pre-Shared Key: Don'tcopythis:Ei)#W~X$… The base station and mobile device must have the same PSK (≙password). The security of the encryption depends directly on the length and complexity of the PSK!
  • Short or easily guessed PSKs compromise network security.
  • Automatically generates a very strong PSK
    Assign the IP addresses to the clients in this network via DHCP:
    Not in bridge mode
    Off When enabled, the UTM works as a DHCP server: All clients in the WLAN network receive an IP address via DHCP. This sets the UTM as the default gateway and DNS server for the clients.
    In bridge mode, the setting from the internal network in which bridge mode was activated is used here.
    Router Advertisement: No If the UTM has received an IPv6 prefix, it can advertise the subnet via router advertisement in the network segment behind the interface. (See article IPv6 Prefix Delegation)
    Generate rules for Internet access:
    Not in bridge mode
    Off Port filtering rules can be automatically created for this network, allowing traffic to the Internet on the interface to the external interface (A0). Likewise, rules are created that also allow data traffic from the internal network into the WLAN network.
  • These rules release all from this network to the Internet and other internal networks.
    notempty
    These any rules are intended for testing purposes and should be disabled and replaced with well-defined rules in production mode.

  • In bridge mode, the setting from the internal network in which bridge mode was activated is used here.

    Step 8 - Certificate

    Generate CA and server certificate: Yes
    Default
    If Yes is enabled, a CA and server certificate will be generated.
  • The boxes Country, Organization and Department are preset depending on the license entered, but can also be changed here.
  • UTM v14.0.1 Installationsassistent Schritt 8-en.png
    Step 8
    Key length: 3072 Select the bit length of the key
    Valid since: 2024/01/01 00:00:00
    Valid until: 2037/12/31 23:59:59
    Country: DE Detailed information is used to identify who issued the certificate
    State: Lower Saxony
    Organization: TTT Point
    Department: Support
    Email address: admin@ttt-point.de

    Step 9 - Administrator

    User admin The username admin cannot be changed at this point UTM v14.0.1 Installationsassistent Schritt 9-en.png
    Step 9
    Password: ••••••••••••••
































    Passwords must meet the following criteria:
    • at least 8 characters length
    • at least 3 of the following categories:
      • Upper case
      • Lower case
      • Special characters
      • Digits
    Confirm password: ••••••••••••••
    Done
    • The wizard is being completed
    • A new configuration is created with the name configuration-wizard-date-time
    • This configuration is set as the boot configuration
    • This configuration is set as the current configuration

    Reboot

    Restart

    Do you want to reboot the system now? Yes In order for the configuration changes to be applied, the respective services must be restarted in the correct order.
    This is achieved by a reboot of the device.
    UTM v12.6 Installationsassistent Neustart Dialog-en.png

    Configure interfaces

    notempty
    New as of v12.7.0
    Do you want to configure the interfaces now? Yes No This message appears if not all existing interfaces are configured correctly. However, it is recommended to do this to prevent possible problems. The Yes button opens the network configuration directly. UTM 12.7.0 Installationsassistent Meldung Schnittstellen konfigurieren-en.png
    Do not ask again Off If this message is not desired, it can be set here so that it is not displayed again the next time you log in.































    Import Cloud Backup

    Import cloud backup under Configuration
    As soon as the UTM has access to the Internet, those cloud backups that were created with this licence are displayed here.

    Download Cloud Backup

    Bereich Cloud-Backup

    Import configuration Loads the selected backup into the local configuration manager under the name backup-YYYY-DD-MM_HH:ii:ss , where the time of backup is included in the name.
    The servers only hold a certain number of configurations. The rotation is done according to the following scheme:
    • the latest 7 backups are kept (first in, first out)
    • after that 4 weekly backups are kept
    • after that 12 monthly backups are kept


    This rotation takes place separately for each license key.

    Set cloud backup as start configuration

    Bereich Lokale Konfiguration

    Als aktuelle Konfiguration setzen Legt die zurückgespielte Version als aktuelle Konfiguration fest
    Set as boot configuration Sets the restored version as the future start configuration