
Click on the interface in the list which is to be connected to the Internet. The properties for this
interface will now appear and the relevant settings can be entered or changed.
Press OK to save the changes. Although changes are remembered by CorePlus, the changed
configuration is not yet activated.
Remember that DHCP should not be enabled when using static IP addresses and also that the IP
address of the Default Gateway (which is the ISP's router) must be specified. As explained in more
detail later, specifying the Default Gateway also has the additional effect of automatically adding a
route for the gateway in the CorePlus routing table.
At this point, the connection to the Internet is configured but no traffic can flow to or from the
Internet since all traffic needs a minimum of the following two CorePlus configuration objects to
exist before it can flow through the Clavister Security Gateway:
•
An IP rule defined in a CorePlus IP rule set that explicitly allows traffic to flow from a given
source network and source interface to a given destination network and destination interface.
•
A route defined in a CorePlus routing table which specifies on which interface CorePlus can
find the traffic's destination IP address.
If multiple matching routes are found, CorePlus uses the route that has the smallest (in other
words, the narrowest) IP range.
We must therefore first define an IP rule that will allow traffic from a designated source interface
and source network. In this case let us assume we want to allow web surfers on the internal network
ge3_net connected to the interface ge3 to be able to access the public Internet.
To do this, we first go to Rules > IP Rule Sets > main in the navigation tree.
The empty main IP rule set will now appear. Press the Add button at the top left and select IP Rule
from the menu.
The properties for the new IP rule will appear. In this example, we will call the rule lan_to_wan.
The rule Action is set to NAT (this is explained further below) and the Service is set to http-all which
is suitable for most web surfing (it allows both HTTP and HTTPS connections). The interface and
network for the source and destinations are defined in the Address Filter section of the rule.
3.3. Manual Web Interface Setup
Chapter 3. CorePlus Configuration
36
Содержание SG4300 Series
Страница 7: ...1 1 Unpacking the Product Chapter 1 Product Overview 7...
Страница 11: ...1 3 The Keypad and Display Chapter 1 Product Overview 11...
Страница 19: ...2 4 Connecting Power Chapter 2 Installation 19...
Страница 58: ...3 6 Going Further with CorePlus Chapter 3 CorePlus Configuration 58...
Страница 62: ...Appendix B Declarations of Conformity 62...
Страница 63: ...Appendix B Declarations of Conformity 63...