Configuring the Local Network
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 79
To enable WAN as LAN:
1. Go to
Device
>
Advanced Settings
and select
OS advanced settings - Enable LAN on WAN
.
2. Click
Edit
to change the value to
true
.
The
Device
>
Local Network
page now shows WAN ports included in the list of LAN and DMZ (local
interfaces, switches, bridges, bonds and VLANs).
n
When used for WAN networks, the interface name of the WAN port is WAN.
n
When used for LAN networks, the interface name of the WAN port is LANW.
Configuration parameters for WAN as LAN are similar to DMZ.
Monitor Mode
Security Gateways can monitor traffic from a Mirror Port or Span Port on a switch.
With Monitor Mode, the appliance uses Automatic Learning or user-defined networks to identify internal and
external traffic, and to enforce policy.
Automatic Learning - The appliance automatically recognizes external networks by identifying the default
gateway's network from requests to the Internet (specifically, requests to Google). The rest of the networks
are considered internal.
User-Defined Networks - You can manually define internal networks. If a network is not defined as internal,
it is considered external.
In both Automatic Learning and user-defined networks:
n
Traffic to internal hosts is inspected by the Incoming/Internal/VPN Rule Base.
n
Traffic to external hosts is inspected by the Outgoing Rule Base.
n
Threat prevention's default configuration is optimized to inspect suspicious traffic from external hosts
to internal hosts.
To configure monitor mode in the WebUI:
1. Go to
Device
>
Local Network
.
2. Select an interface and double-click.
The
Edit
window opens in the
Configuration
tab.
3. In the
Assigned To
drop-down menu, select
Monitor Mode
.
The
Manually define internal networks
checkbox shows.
4. To use Automatic Learning, do not select
Manually define internal networks
and click
Apply
.
5. To use your own network definitions, select
Manually define internal networks
.
The network definition features and table show.
6. Click
New
.
7. Enter the network
IP address
.
8. Enter the
subnet
. An internal network can be a 255.255.255.255 subnet, for one host.