Appliance Configuration
Check Point 1400 Appliances Centrally Managed Administration Guide R77.20.85 | 70
The VPN tunnel and its properties are defined by the VPN community that contains the two
gateways. You must define the VPN community and its member Security Gateways before you can
create a VTI.
Configure the fields in the tab:
Configuration tab
•
VPN Tunnel ID
- A number identifying the VTI.
•
Peer
- The name of the remote VPN site. See Configuring VPN Sites.
The VPN tunnel interface can be numbered or unnumbered. Select the applicable option:
•
Numbered VTI
-
You configure a local and remote IP address for a numbered VTI:
•
Local IPv4 address
- The IP address to be used for the local point-to-point virtual interface.
•
Remote IP address
- The IP address to be used at the peer gateway’s point-to-point virtual
interface.
•
Unnumbered VTI
- When the VTI is unnumbered, it is not necessary to configure local and
remote IP addresses. You define a local interface to use as the source IP address for outbound
traffic.
•
Internet connection -
Select from the list.
•
Local bridge interface
- Select the local interface from the list.
To create/edit a bridge:
Configure the fields in the tabs:
Configuration tab
•
In
Bridge Configuration
, select the networks you want to be part of the bridge.
•
Enable Spanning Tree Protocol
- When Spanning Tree Protocol (STP - IEEE 802.1d) is enabled,
each bridge communicates with its neighboring bridges or switches to discover how they are
interconnected. This information is then used to eliminate loops, while providing optimal
routing of packets. STP also uses this information to provide fault tolerance, by re-computing
the topology in the event that a bridge or a network link fails.
•
Enter a
Name
for the bridge interface. Note that you can only enter "brN" where N is a number
between 0 and 9. For example, br2.
•
Choose the
IP address
and
Subnet mask
the switch uses.
•
Use Hotspot
- Select this checkbox to redirect users to the Hotspot portal before allowing
access from this interface. Hotspot configuration is defined in the
Device
>
Hotspot
page.
•
DHCP Server
Select one of the options:
•
Enabled
- Enter the IP address range and if necessary the IP address exclude range. The
appliance's own IP address is automatically excluded from this range. You can also exclude
or reserve specific IP addresses by defining network objects in the
Users & Objects
>
Network Objects
page. Reserving specific IP addresses requires the MAC address of the
device.
•
Relay
- Enter the DHCP server IP address.
•
Disabled
Содержание L-71
Страница 122: ......