Print Download PDF Send Feedback

Previous

Next

Saving the Multi-Domain Security Management IPS Configuration

When upgrading to R80.10, the previous Domain IPS configuration is overridden when you first assign a Global Policy.

Best Practice - Save each Domain IPS configuration, so that you can restore the settings after the upgrade:

  1. Connect with Multi-Domain Server to R7x Multi-Domain Server.
  2. Click Global Policies tab > Global Policies.
  3. Click the [+] near the Domain name.
  4. Right-click the Domain Management Server > click Configure Domain.
  5. Click the Global Policy tab.
  6. In the Revision Control section, select Create a database version before assigning global policy.
  7. Click OK.

Notes:

For more on IPS in Multi-Domain Server environment, see the R80.10 Multi-Domain Server Administration Guide.

Enabling IPv6 on Multi-Domain Security Management

If your Multi-Domain Security Management environment uses IPv6 addresses, you first must enable IPv6 support for the Multi-Domain Servers and for existing Domain Management Servers. It is not necessary to enable IPv6 support for Domain Management Servers that you create after IPv6 is enabled on the Multi-Domain Server, because this is handled automatically.

Important - You must assign an IPv4 address for each Multi-Domain Server, Multi-Domain Log Servers, Domain Management Server and Domain Log Server. The IPv6 address is optional.

Preliminary steps:

  1. Enable the IPv6 support in Gaia.
  2. Assign an IPv6 address and default gateway to the Leading Interface (typically, eth0).
  3. Assign an IPv6 address and default gateway to the management interfaces.
  4. Write down the Multi-Domain Server IPv6 address, the host names and IPv6 addresses for all Domain Management Servers.

    This is necessary because the system restarts after you enable IPv6 support.

To enable IPv6 support for the Multi-Domain Server:

  1. Connect to the command line on the Primary Multi-Domain Server over SSH or console.
  2. Log in to Gaia Clish or Expert mode.
  3. Run: mdsconfig
  4. Select IPv6 Support for the Multi-Domain Server.
  5. Enter y when prompted to change the IPv6 preferences.

    Enter y again to confirm.

  6. When prompted for the Leading Interface name, enter the name of the management interface (typically, eth0).
  7. When prompted, enter the management interface IPv6 address.
  8. Press y to restart Check Point services.

To enable IPv6 support for existing Domain Management Servers:

  1. Connect to the command line on the Primary Multi-Domain Server over SSH or console.
  2. Log in to Gaia Clish or Expert mode.
  3. Run: mdsconfig
  4. Select IPv6 Support for Existing Domain Management Servers.
  5. Enter y when asked to change the IPv6 preferences for Domain Management Servers.
  6. Enter a to add support to an existing Domain Management Server.
  7. Enter y to add support to all Domain Management Servers at once.

    Enter y again to confirm.

  8. Do one of these:
    • Enter m to manually add IPv6 addresses,
    • Press r to automatically assign IPv6 address from a specified range.
  9. Follow the instructions on the screen to enter the IPv6 addresses or a range of IPv6 addresses.

To manually enable IPv6 support for specified Domain Management Servers:

  1. Connect to the command line on the Primary Multi-Domain Server over SSH or console.
  2. Log in to Gaia Clish or Expert mode.
  3. Run: mdsconfig
  4. Select IPv6 Support for Existing Domain Management Servers.
  5. At the prompt, enter y to change the IPv6 preferences for Domain Management Servers.
  6. Enter a to add support to an existing Domain Management Server.
  7. Enter n when asked to enable IPv6 support for all Domain Management Servers at once.

    Enter y to confirm.

  8. At the prompt, enter the Domain Management Server name.

    The available Domain Management Servers show above prompt. You can copy and paste the name.

  9. Enter the IPv6 address.
  10. At the prompt, enter one of these:
    • Enter y to enable another Domain Management Server.
    • Enter n to complete the procedure.