
Configuring BaySecure FireWall-1
3-10
117384-D Rev 00
Activating the Firewall
Before the FireWall-1 security policy can take effect on the router, you must first
activate the firewall by booting the router using the Technician Interface on the
management station. Booting a router warm-starts every processor module in the
router. Pressing the Reset button on the front panel of the router performs the same
procedure.
For information about using the Technician Interface
boot
command, see Using
Technician Interface Software.
Defining a Firewall Security Policy
A security policy is a collection of rules that define the way the firewall operates.
The default FireWall-1 security policy drops all attempts at communication with
the router. This security policy goes into effect when you first activate the firewall
on the router.
You must establish a security policy that explicitly defines acceptable
communication to the router, based on the source address, destination address, and
type of service. For details about how to configure a security policy, see your
Check Point FireWall-1 documentation.
Note:
When you activate the firewall, the default security policy prevents all
interfaces supported by the firewall from communicating with the router. If the
firewalled router and management station are on different subnets, you must
establish a static route to enable communication between the router and the
management station before you activate the firewall. For information about
configuring a static route, see Configuring IP, ARP, RIP, and OSPF Services.
Kommentare zu diesen Handbüchern