Page 121 / 342 Scroll up to view Page 116 - 120
Configuring Static Routes
Nokia IP45 Security Platform User’s Guide v4.0
121
Configuring Static Routes
Note
You can define static routes only if it is required.
A static route is a setting that explicitly specifies the route for packets destined for a certain
subnet. Packets with a destination that does not match any defined static route is routed to the
default gateway.
The Static Routes page lists all existing routes, including the default, and indicates whether each
route is currently connected, or reachable, or not reachable.
To add a static route
1.
Choose Network from the main menu, and click the Routes tab.
The Static Routes page opens, with a listing of existing static routes.
2.
Click New Route.
3.
Complete the fields in the wizard by using the information given in
Table 20
on page 121.
4.
Click Apply.
The new static route is saved.
Table 20
Edit Route Page Fields
Field
Action
Destination
Network
Type the network address of the destination network.
Subnet Mask
Select the subnet mask.
Page 122 / 342
6
Managing your Local Area Network
122
Nokia IP45 Security Platform User’s Guide v4.0
To edit a static route
1.
Choose Network from the main menu, and click Routes tab.
The Static Routes page opens displaying the list of existing static routes.
2.
To edit the route details, do the following:
a.
Click the Edit
tab at the row of your preferred route.
b.
Edit the fields by using the information in
Table 20
on page 121.
c.
Click Finish.
The changes are saved.
To delete a static route
1.
Choose Network from the main menu, and click the Routes tab.
The Static Routes page opens displaying a list of existing static routes.
2.
In the preferred route row, click the Erase
tab.
A confirmation message appears.
3.
Click OK.
The route is deleted.
Configuring Source Routes
The Nokia IP45 security platform v4.0 supports source routing. In source routing, the next hop
route is selected based on both source and destination IP addresses, unlike in traditional routing
where only destination IP address is considered. All source routes takes priority over regular
routes.
Source routing allows the LAN network to use the primary Internet connection while the DMZ
network uses the secondary, thus balancing the load between the two networks.
Use the following procedure to configure source routes using GUI:
To configure source routes
1.
Choose Network from the main menu and select Routes.
2.
The Routes page opens.
Next Hop IP
Type the IP address of the gateway (next hop router) to which to
route the packets destined for this network.
Metric
Enter the metric value. Route with a lower metric value is
preferred.
Table 20
Edit Route Page Fields (
continued
)
Field
Action
Page 123 / 342
OSPF
Nokia IP45 Security Platform User’s Guide v4.0
123
3.
Click New Route.
The Source and Destination window opens.
4.
Select the Source and Destination options.
5.
If you select Specify Network, enter the values in Network and Netmask fields.
6.
Click Next.
7.
The Next Hop and Metric window opens. Enter the Next Hop IP and Metric Value.
The default value is 10.
8.
Click Finish.
For information about the command line interface, see the
Nokia IP45 Security Platform CLI
Reference Guide Version 4.0.
OSPF
Open Shortest Path First (OSPF) is a link state protocol. This widely used interior gateway
protocol distributes routing information between routers in a single autonomous system (AS).
OSPF chooses the least-cost path as the best path. It is suitable for complex networks with a
large number of routers because it provides equal-cost, multi-path routing, where packets to a
single destination can be sent through more than one interface simultaneously.
Page 124 / 342
6
Managing your Local Area Network
124
Nokia IP45 Security Platform User’s Guide v4.0
In a link-state protocol, each participating router maintains a database describing the entire AS
topology, which it builds out of the collected link state advertisements of all routers. Each router
distributes its local state throughout the AS by flooding.
Each multi-access network with atleast two attached routers has a designated router and a
backup designated router. The designated router floods a link state advertisement for the multi-
access network and has other special responsibilities. Using a designated router reduces the
number of adjacencies required on a multi-access network.
The great advantages of using dynamic routing are automatic distribution of routing tables
across the enterprise and automatic rerouting of traffic around failures for high resiliency.
The IP45 OSPF implementation is fully interoperable with the Check Point Advanced Routing
Suite, as well as with any other RFC compliant OSPF implementation.
The IP45 OSPF capabilities can be configured through the gateway’s command line interface.
For more information about configuring OSPF by using the command-line interface, see the
Nokia IP45 Security Platform CLI Reference Guide Version 4.0.
Managing Ports
By using the web GUI, you can manage the ports of your Nokia IP45 appliance. You can now
configure, edit and view the ports status by using GUI.
To assign ports
1.
Choose Network from the main menu.
The Network page opens.
2.
Click Ports.
The Ports page opens.
3.
To assign a port, click Edit at the corresponding port.
Page 125 / 342
Managing Ports
Nokia IP45 Security Platform User’s Guide v4.0
125
The Port Setup page opens.
4.
Select the values from the drop-down list by using the
Table 21
.
5.
Click Apply.
To edit and reset ports
1.
To edit a port, click Edit at the corresponding port.
The Port Setup page opens.
2.
Select the values from the drop-down list by using the
Table 21
.
3.
Click Apply.
4.
To reset ports to their default values, click Default at the bottom of the page.
Defining the Port Link Speed
The Nokia IP45 security platform v4.0 supports defining the Ethernet port link speed by using
GUI. In earlier releases this option could be set only by using the command-line interface.
By default, the link speed is automatically detected.
Table 21
Port Setup page fields
Field
Description
Assign to network
Specifies the network that is assigned to the selected port
Link Configuration
Specifies the link configuration of the port. You can choose
automatic detection to set the best configuration.
Options:
Automatic Detection
10 Mbps/Half Duplex
10 Mbps/Full Duplex
100 Mbps/Half Duplex
100 Mbps/Full Duplex
Port Security
Specifies the port security. It is recommended to use 802.1x
authentication standard for the security.
Options:
None
802.1x
Quarantine Network
Specifies the quarantine network. Clients that failed to
authenticate will be moved to this network.

Rate

3.5 / 5 based on 2 votes.

Popular Nokia Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top