Installation
Check Point 1400 Appliances Centrally Managed Administration Guide R77.20.85 | 18
Workflow
1.
Associate a security zone object with an interface on the gateway object.
2.
Use the security zone object in a rule.
3.
Install policy.
To associate a security zone object with an interface on the gateway object:
1.
In SmartDashboard, from the
Network Objects
tree, double-click a Check Point Appliance
gateway object.
2.
From
Topology
, select the applicable interface and click
Edit
.
The Interface Properties window opens.
3.
Select one of the predefined
Security Zone
options.
4.
If you want to create a new zone, click
New
, fill in the details and click
OK.
5.
Click
OK
.
The Check Point Appliance Gateway General Properties is shown.
6.
Click
OK
.
To create a rule with a security zone:
After you associated a security zone object to the applicable interface on the gateway, you can use
it in a rule. To create a rule with a security zone, just add the security zone object to the Source or
Destination cell.
For example, to create a rule that allows internal users access to any external network, create a
rule with these fields:
Policy Field
Value
Source
InternalZone
Destination
ExternalZone
Action
accept
Install On
gateway object or SmartLSM profile
1.
Open the
Firewall
>
Policy
page.
2.
Use the
Add Rule
buttons to position the rule in the Rule Base.
3.
Enter a
Name
for the rule.
4.
In the
Source
field, right-click the
+
icon, click
Network Objects
, select
InternalZone
from the
list, and click
OK
.
5.
In the
Destination
field, right-click the
+
icon, click
Network Objects
, select
ExternalZone
from the list, and click
OK
.
6.
In the
Action
field, select
accept
.
7.
Right-click the
Install On
field, select
Add
>
Targets
, and select the gateway object or
SmartLSM profile.
Содержание L-71
Страница 122: ......