
Configuring a Firewall on a Router
117384-D Rev 00
3-9
For example, the following command assigns the name “offsite” to the firewall on
IP interface 2.2.2.2/255.0.0.0:
firewall/2.2.2.2# firewall-name offsite
firewall/2.2.2.2#
Setting the Policy Index
The policy index allows multiple circuits to share the same instance of Firewall-1.
You can have up to 32 instances of Firewall-1, with many circuits making up each
Firewall-1 instance. All circuits in a grouping must share the same security policy.
By default, the policy index for a circuit is equal to the circuit number. If you are
using Firewall-1 on less than 33 circuits, you do not need to use policy indexes.
If you are using Firewall-1 on more than 32 circuits, group circuits that share the
same security policy. Then, set the policy index on each circuit in a group to the
same value. For example, suppose you want to use Firewall-1 on 40 circuits. The
first five circuits share one security policy; the next 35 share a different security
policy. Using the BCC, assign policy index 1 to the first five circuits and policy
index 2 to the next 35 circuits. You then have a total of 40 firewall circuits on the
router, with two policy index values and two security policies.
The CheckPoint log viewer treats circuits that share a policy index as one circuit.
To set the policy index value, navigate to the firewall prompt and enter:
policy-index <
value
>
value
is the index value from 1 through 1023.
For example, the following command sets the policy index to 1:
firewall/2.2.2.2#
#
policy-index 1
firewall/2.2.2.2#
Note:
If you do not use policy index values and you configure more than 32
circuits on the router, all IP forwarding is disabled on circuits after the 32nd. If
you use policy index values, but configure more than 32 policy index
groupings, all circuits assigned policy indexes after the 32nd will have all IP
forwarding disabled. The router logs warning messages that can help you
determine if you have any circuits on which all IP forwarding is disabled.
Comentários a estes Manuais