Open Frames Download Complete PDF Send Feedback Print This Page

Previous

Next

Automatic Distribution Configuration (Auto-Topology)

By default, the 61000/41000 Security System automatically configures the Distribution Mode. The optimal Distribution Mode is derived from the Gateway topology as defined in SmartDashboard.

The Distribution Mode is derived from these interfaces:

  • Physical, other than the management and sync.
  • VLAN
  • Bond
  • VLAN over bond
  • Bridge

These examples show how the distribution Mode can be automatically configured for each interface.

Physical Interfaces

Physical

Interface

Topology

SSM

Distribution Mode

eth1-01

Internal

1

User

eth1-02

Internal

eth2-01

External

2

Network

eth2-02

External

In this example ports on each SSM are either all Internal or all External. Therefore, the Distribution Mode for the two SSMs is automatically configured as User or Network.

Physical interfaces

Interface

Topology

SSM

Port

Distribution Mode

eth1-01

Internal

1

1

User

eth1-02

External

1

2

Network

eth2-01

External

2

1

Network

eth2-02

External

2

2

Network

On at least one of the SSMs, some ports are Internal and others are External. Therefore, the Distribution Mode for the SSMs is automatically configured as Per Port.

Physical and VLAN interfaces

Interface

Topology

SSM

Port

VLAN

Distribution Mode

eth1-01

External

1

1

NA

Network

eth1-01.100

Internal

1

1

100

User

eth1-01.200

External

1

1

200

Network

eth1-01.300

Internal

1

1

300

User

Three VLANs are defined on one SSM port. On at least one of the SSMs, some VLANs are Internal and others are External. Therefore, the Distribution Mode of the SSMs is automatically configured to be Per-Port.

Note: Not supported in SSM60. In an SSM60 the Distribution Mode of all the VLANs on each port must be the same as the Distribution Mode of the port.

VSX Virtual Systems

Interface

Topology

Distribution Mode

eth1-01

External

N/A

wrpj64

Internal

Network

wrpj128

Internal

Network

wrpj192

Internal

User

Because a Virtual Switch does not have topology, the Distribution Mode is calculated based on the topologies of the WARP interfaces connected to the Virtual Systems, as show. In this example, the Distribution Mode is calculated to be Network.

Bond interfaces

Interface

Topology

Slaves

SSM

Port

Distribution Mode

bond1

Internal

eth1-01

1

1

User

eth2-01

2

1

User

bond2

External

eth1-02

1

2

Network

eth2-02

2

2

Network

Bond interface bond1 is defined on two SSM1 and SSM2 ports. bond2 is defined on another two SSM1 and SSM2 ports. On at least one of the SSMs, some ports are Internal and others are External. Therefore, the Distribution Mode of the SSMs is automatically configured to be Per-Port.

VLAN over Bond Interfaces

Interface

Topology

Slaves

SSM

Port

VLAN

Distribution Mode

bond1.100

Internal

eth1-01

1

1

100

User

eth2-01

2

1

100

User

bond1.200

External

eth1-01

1

1

200

Network

eth2-01

2

1

200

Network

Interface bond1.100 is defined on two SSM1 and SSM2 VLANs. Interface bond1.200 is defined on the same SSM1 and SSM2 VLANs. On at least one of the SSMs, some VLANs are Internal and others are External. Therefore, the Distribution Mode is automatically configured to be Per-Port

Note: Not supported in SSM60. In an SSM60 the Distribution Mode of all the VLANs must be the same.

Bridge interfaces

If there is a Layer-2 Bridge Interface, the Distribution Mode of all the SSMs is automatically configured to be General.

Related Topics

SSM60 VLAN Legacy Support

Manual Distribution Configuration (Manual-General)

 
Top of Page ©2014 Check Point Software Technologies Ltd. All rights reserved. Download Complete PDF Send Feedback Print