164
Defining your security environment
Defining traffic endpoints with network entities
5
Click
OK
.
6
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
7
Use the domain name network entity to specify the source and/or destination of traffic in rules and
packet filters.
Related information
For further information related to this topic, see the following:
■
“Domain Name Network Entity Properties—General tab”
■
■
■
Creating security gateway network entities for use in tunnels
By definition, any host that acts as a secure entry or exit point for a network is a security gateway. You
create security gateway network entities to serve as the local or remote gateway for a VPN tunnel. To
establish gateway-to-gateway VPN tunnels, you must define security gateway entities for both the
local and remote systems that serve as the tunnel endpoints.
You can also use security gateway network entities to specify the source and destination of traffic in
rules and packet filters.
When you define security gateway entities, you can set up some basic characteristics of the endpoints,
such as whether IKE policies are used, and the use of certificates or shared secrets. The IP address you
assign to the security gateway entity is usually the publicly accessible address of the endpoint you are
defining.
Prerequisites
None.
To create security gateway network entities for use in tunnels
1
In the SGMI, in the left pane, under Assets, click
Network
.
2
In the right pane, on the Network Entities tab, click
New > Security Gateway Network Entity
.
3
In the Security Gateway Network Entity Properties dialog box, on the General tab, do the following:
4
On the Security Gateway tab, in the Address type drop-down list, select the type of endpoint the
security gateway entity represents when it is used as a tunnel endpoint. Your choices are:
■
Interface
This is useful for deployments where the security gateway is using a DHCP server on the
outside.
■
VIP
■
IP address
VIP is only available if the security gateway is a member of a cluster and a VIP has been
configured for it.
Name
Type a name for the security gateway network entity.
Caption
Type a brief description of the security gateway network entity.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...