Also in the Options tab, we should specify the DNS address which is handed out with DHCP
leases. This could be set, for example, to be the IPv4 address object
dns1_address
.
Syslog Server Setup
Although logging may be enabled, no log messages are captured unless at least one log server is
set up to receive them and this is configured in cOS Core.
Syslog
is one of the most common
server types.
First we create an
IP4 Address
object called, for example,
syslog_ip
which is set to the IPv4 address
of the server. We then configure the sending of log messages to a Syslog server from cOS Core by
selecting System > Device > Log and Event Receivers and then choosing Add > Syslog
Receiver.
The Syslog server properties dialog will now appear. We give the server a name, for example
my_syslog
, and specify its IPv4 address as the
syslog_ip
object.
Tip: Address book object naming
The cOS Core address book is organized alphabetically so when choosing names for IP
address objects it is best to have the descriptive part of the name first. In this case, use
syslog_ip
as the name and not
ip_syslog
.
Allowing ICMP Ping Requests
As another example of setting up IP rule set entries, it can be useful to allow outgoing ICMP
ping
messages to pass through the firewall. To allow hosts on the internal network
G1_net
to send
ping messages to any hosts on the Internet, select Policies > Firewalling > Main IP Rules > Add
and enter the values shown below for an IP policy called
allow_ping_outbound
. This uses the
predefined service called
ping_outbound
.
Chapter 4: cOS Core Configuration
53
Summary of Contents for NetWall W20A
Page 12: ... i Orange when cOS Core is running normally Chapter 1 W20B Product Overview 12 ...
Page 14: ...Chapter 1 W20B Product Overview 14 ...
Page 31: ...Chapter 3 W20B Installation 31 ...
Page 70: ...Chapter 4 cOS Core Configuration 70 ...
Page 80: ...Appendix B Declarations of Conformity 80 ...