Appliance Configuration
Check Point 1400 Appliances Centrally Managed Administration Guide R77.20.85 | 68
3.
To configure Monitor Mode with user-defined networks:
> add monitor-mode-network ipv4-address
<IP>
subnet-mask <mask> > set
monitor-mode-configuration use-defined-networks true
4.
To see user-defined Internal networks:
> show monitor-mode-network
5.
To disable Anti-Spoofing:
> set antispoofing advanced-settings global-activation false
If you do not see the Monitor Mode option:
1.
Run this CLI command:
set monitor-mode-configuration allow-monitor-mode true
2.
Select an interface and click
Edit
.
Monitor Mode is now added to the options list.
For more information on monitor mode, see sk112572
http://supportcontent.checkpoint.com/solutions?id=sk112572
To edit a physical interface:
Configure the fields in the tabs. Note that for the DMZ there is an additional tab
Access Policy
:
Configuration tab
•
Assigned to
- Select the required option:
•
Unassigned
- The physical interface is not part of any network and cannot be used.
•
One of the existing configured
switches
or
bridges
•
Separate network -
When selecting a separate network configure this information:
IP address
Subnet mask
DHCP Server settings
Select one of the options:
Enabled
- Enter the IP address range and if necessary the IP address exclude range.
The appliance's own IP address is automatically excluded from this range. You can also
exclude or reserve specific IP addresses by defining network objects in the
Users &
Objects
>
Network Objects
page. Reserving specific IP addresses requires the MAC
address of the device.
Relay
- Enter the DHCP server IP address.
Disabled
Note
- When you create a switch, you cannot remove the first interface inside unless you delete
the switch.
Advanced tab
The options that are shown vary based on interface type and status. Configure the options that are
applicable:
•
Description
-
Enter an optional description. The description is shown in the local network table
next to the name.
•
MTU size -
Configure the Maximum Transmission Unit size for an interface. Note that in the
Check Point Appliance, the value is global for all physical LAN and DMZ ports.
Содержание L-71
Страница 122: ......