Appliance Configuration
Check Point 1400 Appliances Centrally Managed Administration Guide R77.20.85 | 69
•
Disable auto negotiation
- Select this option to manually configure the link speed of the
interface.
•
Override default MAC address
– This option is for local networks except those on VLANs and
wireless networks. Use this option to override the default MAC address of the network’s
interface, when the device has two separate local networks connected to the same external
switch.
Best Practice
- This is a rare configuration. Do not select this option unless you are sure you
need it.
•
Exclude from DNS proxy
– Select this checkbox for any network that you do not want exposed
to internal domains. In guest VAPs (wireless network for guests), this is selected by default.
Access Policy tab (only for DMZ)
These options create automatic rules that are shown in the
Access Policy
>
Firewall Policy
page.
•
Allow access from this network to local networks
•
Log traffic from this network to local networks
To create/edit a tag based VLAN:
You can create a new VLAN only if you have at least one physical interface that is not part of an
existing network (switch or bridge).
Note
- For more information on the maximum number of VLANs that you can configure for each
appliance, refer to sk113247
http://supportcontent.checkpoint.com/solutions?id=sk113247
Configure the fields in the tabs:
Configuration tab
•
VLAN ID
- Enter a number that is the virtual identifier.
•
Assigned to
- Select the physical interface where the new virtual network is created.
•
IP address
•
Subnet mask
•
Use Hotspot
- Select this checkbox to redirect users to the Hotspot portal before allowing
access from this interface. Hotspot configuration is defined in the
Device
>
Hotspot
page.
•
DHCP Server settings
Select one of the options:
•
Enabled
- Enter the IP address range and if necessary the IP address exclude range. The
appliance's own IP address is automatically excluded from this range. You can also exclude
or reserve specific IP addresses by defining network objects in the
Users & Objects
>
Network Objects
page. Reserving specific IP addresses requires the MAC address of the
device.
•
Relay
- Enter the DHCP server IP address.
•
Disabled
To create/edit a VPN Tunnel (VTI):
A Virtual Tunnel Interface (VTI) is a virtual interface on a Security Gateway that is related to an
existing, Route Based VPN tunnel. The Route Based VPN tunnel works as a point-to-point
connection between two peer Security Gateways in a VPN community. Each peer Security Gateway
has one VTI that connects to the tunnel.
Summary of Contents for L-71
Page 122: ......