
If the Clavister Security Gateway is to act as a DHCP server then this can be set up in the following
way:
First define an IP address object which has the address range that can be handed out. Here, we will
use the IP range 192.168.1.10-192.168.1.20 as an example and this will be available on the ge3
interface which is connected to the protected internal network ge3_net.
Device:/> add Address IP4Address dhcp_range
Address=192.168.1.10-192.168.1.20
The DHCP server is then configured with this IP address object on the appropriate interface. In this
case we will call the created DHCP server object dhcp_lan and assume the DHCP server will be
available on the ge3 interface:
Device:/> add DHCPServer dhcp_lan IPAddressPool=dhcp_range
Interface=ge3 Netmask=255.255.255.0
DefaultGateway=InterfaceAddresses/ge3_ip
DNS1=dns1_address
It is important to specify the Default gateway for the DHCP server since this will be handed out to
DHCP clients on the internal network so that they know where to find the public Internet. The
default gateway is always the IP address of the interface on which the DHCP server is configured. In
this case, ge3_ip.
NTP Server Setup
Network Time Protocol (NTP) servers can optionally be configured to maintain the accuracy of the
system date and time. The command below sets up synchronization with the two NTP servers at
hostname pool.ntp.org and IP address 10.5.4.76:
Device:/> set DateTime TimeSyncEnable=Yes
TimeSyncServer1=dns:pool.ntp.org
TimeSyncServer2=10.5.4.76
The prefix dns: is added to the hostname to identify that it must resolved to an IP address by a DNS
server (this is a convention used in the CLI with some commands).
Syslog Server Setup
Although logging may be enabled, no log messages are captured unless a server is set up to receive
them and Syslog is the most common server type. If the Syslog server's address is 195.11.22.55 then
the command to create a log receiver object called my_syslog which enables logging is:
Device:/> add LogReceiverSyslog my_syslog IPAddress=195.11.22.55
Allowing ICMP Ping Requests
As a further example of setting up IP rules, it can be useful to allow ICMP Ping requests to flow
through the Clavister Security Gateway. As discussed earlier, the CorePlus will drop any traffic
unless an IP rule explicitly allows it. Let us suppose that we wish to allow the pinging of external
hosts with the ICMP protocol by computers on the internal ge3_net network. The commands to
allow this are as follows.
Firstly, we must change the current CLI context to be the IPRuleSet called main using the
command:
Device:/> cc IPRuleSet main
3.4. CLI Setup
Chapter 3. CorePlus Configuration
52
Содержание SG4300 Series
Страница 7: ...1 1 Unpacking the Product Chapter 1 Product Overview 7...
Страница 11: ...1 3 The Keypad and Display Chapter 1 Product Overview 11...
Страница 19: ...2 4 Connecting Power Chapter 2 Installation 19...
Страница 58: ...3 6 Going Further with CorePlus Chapter 3 CorePlus Configuration 58...
Страница 62: ...Appendix B Declarations of Conformity 62...
Страница 63: ...Appendix B Declarations of Conformity 63...