Creating a New Virtual System
|
Important:
|
You use the Virtual Systems Wizard to create a new Virtual System Virtual Device on a VSX Gateway or VSX Cluster Member that implements the functionality of a Security Gateway. Acronym: VS.. Modify the initial definition and configure advanced options after you complete the wizard.
To start the Virtual System wizard:
-
Connect with SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. to the Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. or Target Domain Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. used to manage the new Virtual System.
-
From the left navigation panel, click Gateways & Servers.
-
Create a new Virtual System object in one of these ways:
-
From the top toolbar, click the New (
) > VSX > New Virtual System.
-
In the top left corner, click Objects menu > More object types > Network Object > Gateways and Servers > VSX > New Virtual System.
-
In the top right corner, click Objects Pane > New > More > Network Object > Gateways and Servers > VSX > Virtual System.
The Virtual System Wizard opens.
-
Defining General Properties
The General Properties wizard page defines the Virtual System object and the hosting VSX Gateway Physical server that hosts VSX virtual networks, including all Virtual Devices that provide the functionality of physical network devices. It holds at least one Virtual System, which is called VS0..
These are the parameters in this page:
-
Name: Unique, alphanumeric for the Virtual System. The name cannot contain spaces or special characters except the underscore.
-
VSX Gateway / Cluster: Select the VSX
Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Security Gateways and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. Gateway that is hosting the Virtual System.
-
Bridge Mode: Select this option to create a Virtual System in the Bridge Mode
Security Gateway or Virtual System that works as a Layer 2 bridge device for easy deployment in an existing topology..
-
Override Creation Template: Select this option to override the creation template that was used for the initial configuration of the VSX Gateway.
Defining Network Configuration
In the Virtual System Network Configuration page, define internal and external interfaces and the IP address topology behind the internal interface. The process to define Virtual System network properties is different in different environments:
-
Use the VSX Gateway Creation template to define the VSX Gateway that contains the Virtual System.
-
If you choose to override the default VSX Gateway Creation template, you can use the Custom Configuration template.
-
You can create the Virtual System in Bridge Mode. Note - Bridge mode is not available for a Virtual System created with the Shared Interface template.
Shared Interface or Separate Interfaces
The Virtual System Network Configuration page for the Shared Interface and Separate Interfaces templates appears as shown.
To configure the external and internal interfaces:
-
Select the desired interfaces from the appropriate list.
-
If the selected Interface is a VLAN interface, enter the VLAN tag in the appropriate field. This field is not available for non-VLAN interfaces.
-
Enter the IP address and net mask in the appropriate fields. Optionally, enter a default gateway for the external interface.
Separate Interfaces in Bridge Mode
The Virtual System Network Configuration page for the Separate Interfaces template in the Bridge Mode opens.
To configure the external and internal interfaces:
-
Select the desired interfaces for the internal and external networks from the appropriate list.
If the selected Interface is a VLAN interface, enter the same VLAN tag in both the external and internal VLAN Tag fields. This field is not available for non-VLAN interfaces.
-
Define the topology for the internal interface:
-
Select Not Defined if you do not wish to define an IP address.
-
Select Specific and then select an IP address definition from the list. IP address definitions can be based on object groups or predefined networks that define the topology.
-
-
To create a new IP address definition:
-
Select Specific, and click New.
-
Select Group to define an object group, or Network to define network properties.
-
-
Enable Layer-3 bridge interface monitoring to enable Layer 3 network fault detection for this Virtual System.
Enter an IP address and subnet mask, which continuously monitors the specified network for faults or connectivity issues. The IP address/Subnet Mask define the network, on which the Virtual System resides.
Custom Configuration or Override - Non-Bridge Mode
If you used the Custom Configuration template when creating the VSX Gateway, or if you selected Override Creation Template, manually define the network interfaces and connections. The Virtual System Network Configuration page for Custom Configuration opens.
To configure the external and internal interfaces:
-
In the interface table, define the applicable interfaces.
You can add new interfaces and delete and change existing interfaces.
To add an interface, click Add. The Interface Properties window opens. Select an interface from the list and define its properties.
-
Select the Main IP Addressfrom the list.
This IP address is usually assigned to the external interface and specifies the Virtual System address used with NAT or VPN connections.
To make an external IP address routable, select the external interface IP address as the main IP address.
-
Define network routing for your deployment.
Some routes are automatically defined by the interface definitions. For example, you define a default gateway route leading to an external Virtual Router
Virtual Device on a VSX Gateway or VSX Cluster Member that functions as a physical router. Acronym: VR. or to the Virtual System external interface.
To manually add a default route to the Routes table, click Add Default Routes. Enter the default route IP address, or select the default Virtual Router. The Route Configurationwindow opens.
Custom Configuration or Override in Bridge Mode
If you used the Custom Configuration template to create the VSX Gateway, or if you selected the Override Creation Template option for a Virtual System in Bridge Mode, then manually define the network interfaces.
Interfaces: To configure the external and internal interfaces, define interfaces and links to devices in the Interfaces table. You can add, change, and remove interfaces. To add an interface, click Add. The Interface Properties window opens. Select an interface from the list and define is properties.
Completing the Definition
Click Next and then click Finish to create the Virtual System. Note that this may take several minutes to complete. A message appears indicating successful or unsuccessful completion of the process.
If the process ends unsuccessfully, click View Report to view the error messages. Refer to the VSX Diagnostics and Troubleshooting for further assistance.
After you create a Virtual System using the Virtual System Wizard, you can modify the topology and all other parameters (except the name of the Virtual System) using the Virtual System Propertieswindow.
Modifying a Virtual System
-
Connect with SmartConsole to the Security Management Server or Target Domain Management Server used to manage the Virtual System.
-
From the Gateways & Servers view or Object Explorer, double-click the Virtual System object.
Virtual System - General Properties
The General Properties page lets you specify the main IP address and to enable various Check Point products for a Virtual System.
Virtual System - Topology
The Topology page contains definitions for Virtual System interfaces, routes and Warp Links. Based on these interface settings, VSX automatically creates routes to Virtual Devices and the VSX Gateway.
|
Note - If you modify the topology for a specific Virtual System in a cluster |
-
Interfaces: The Interfaces table defines interfaces and links to devices. You can add new interfaces as well as delete and modify existing interfaces.
To add an interface, click Newand select one of these options:
-
Regular- Create a new interface
-
Leads toVirtual Router
-
Leads toVirtual Switch
The Interface Propertieswindow opens. Select the interface from the list and define the appropriate properties. The Working with Interface Definitions and the online help provides explanations of the various properties and options.
Click Actions> Copy to Clipboard to copy the Interfacestable in CSV format.
-
-
Routes: To add a default route to the Routes table, click Add Default Routes and either enter an IP address or select a Virtual Router. The Route Configuration window opens. Click Help for details regarding the various properties and options. You can also add, change and Routes.
-
Calculate topology automatically based on routing information:Enable this option to allow VSX to automatically calculate the network topology based on interface and routing definitions (enabled by default). VSX creates automatic links, or connectivity cloud objects linked to existing internal or external networks.
-
When this option is enabled, you cannot configure the topology using Topologytab in the Interface Properties window. These options are unavailable on the tab.
-
This option is not available in the Bridge Mode.
-
When employing dynamic routing, it is recommended to disable this option.
-
-
VPN Domain: The VPN Domain defines the set of hosts located behind a given Virtual System that communicate via a VPN tunnel with peer Virtual Systems. These options are only available if you selected VPN in the Check Point Products section on the General Properties page.
When including a Virtual Device
Logical object that emulates the functionality of a type of physical network object. Virtual Device can be on of these: Virtual Router, Virtual System, or Virtual Switch. as part of a VPN connection, you must specify a VPN Domain. The domain definition specifies Virtual System interfaces that are included in the VPN. You can define a VPN Domain in one of two ways by enabling the appropriate option:
-
All IP Addresses behindgateway based on topology information: Includes all hosts not located behind an external gateway cluster interface.
-
Manually Defined: Includes all hosts in the selected network or group.
Virtual System - NAT > Advanced
The NAT > Advancedpage lets you configure NAT rules for packets originating from a Virtual System.
To enable and configure NAT for a Virtual System:
-
Select Add Automatic Address Translation.
-
Select a translation method:
-
Hide: Hide NAT only allows connections originating from the internal network. Internal hosts can access internal destinations, the Internet and other external networks. External sources cannot initiate a connection to internal network addresses.
-
Static: Static NAT translates each private address to a corresponding public address.
-
-
If you select Hide, select one of these options:
-
Hide behind Gateway hides the real IP address behind the Virtual System external interface IP address,
or
-
Hide behind IP Address hides the real address behind a virtual IP address, which is a routable, public IP address that does not belongs to any real machine.
-
-
If you selected Static NAT, enter the static IP address in the appropriate field.
-
Select the VSX Gateway from the Install onGateway list.
In addition, see the Working with Network Address Translation section.
Deleting a Virtual System
To delete a Virtual System:
-
From the Gateways & Servers view or Object Explorer tree, right-click the Virtual System object and select Delete.
-
In the window that opens, click Yes.