Nokia IPSO 4.0 manual Configuration Rules for Check Point NGX FP2 and Later, 200

Models: IPSO 4.0

1 510
Download 510 pages 5.58 Kb
Page 200
Image 200

4

Source

Destination

Service

Action

cluster-all-ips

fwcluster-object

vrrp

Accept

mcast-224.0.0.18

igmp

Note

The object for VRRP is not the same as the gateway cluster object for HA. Accordingly, in this example, the gateway cluster object is designated fwcluster-object.

Where:

„cluster-all-ipsis the Workstation object you created with all IPs.

„fwcluster-objectis the Gateway Cluster object.

„mcast-224.0.0.18is a Workstation object with the IP address 224.0.0.18 and of the type host.

Configuration Rules for Check Point NGX FP2 and Later

Locate the following rule above the Stealth Rule:

Source

Destination

Service

Action

Firewalls

mcast-224.0.0.18

vrrp

Accept

fwcluster-object

 

igmp

 

 

Where:

„Firewalls is a Simple Group object containing the firewall objects.

„fwcluster-objectis the gateway cluster object.

„mcast-224.0.0.18is a Node Host object with the IP address 224.0.0.18.

Configuring Rules if You Are Using OSPF or DVMRP

All of the solutions in “Configuration Rule for Check Point NGX FP1” and “Configuration Rules for Check Point NGX FP2 and Later” are applicable for any multicast destination.

If your appliances are running routing protocols such as OSPF and DVMRP, create new rules for each multicast destination IP address.

Alternatively, you can create a Network object to represent all multicast network IP destinations by using the following values:

Name: MCAST.NET

IP: 224.0.0.0

Netmask: 240.0.0.0

You can use one rule for all multicast protocols you are willing to accept, as shown below:

200

Nokia Network Voyager for IPSO 4.0 Reference Guide

Page 200
Image 200
Nokia IPSO 4.0 Configuration Rules for Check Point NGX FP2 and Later, Configuring Rules if You Are Using Ospf or Dvmrp